From patchwork Tue Jan 6 18:28:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: ValentinBoudevin X-Patchwork-Id: 78104 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0F17CCEFCEC for ; Tue, 6 Jan 2026 18:28:32 +0000 (UTC) Received: from mail-qk1-f176.google.com (mail-qk1-f176.google.com [209.85.222.176]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.96837.1767724106188108216 for ; Tue, 06 Jan 2026 10:28:26 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20230601 header.b=SUdRgNYx; spf=pass (domain: gmail.com, ip: 209.85.222.176, mailfrom: valentin.boudevin@gmail.com) Received: by mail-qk1-f176.google.com with SMTP id af79cd13be357-8b29aebdf3cso23540485a.1 for ; Tue, 06 Jan 2026 10:28:26 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1767724105; x=1768328905; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=lVE4nLj+3BtCLTmQkJXQCdG9/ceCHtDUVYkwlyOryAk=; b=SUdRgNYxFgBwXOpEaosYBtEu2HF1iJvPL1p4ic8lgDjSJLZGi8oy103gVKSsYPItRC GC4pSHk7Y3X4/MU8dpN0Ec6VLMU2hzeNkO/NdId6RVa78gCWIw170fEZQz0MEJjweSpU d84Dmt7GCqP59qLpoezZJpOzsT32foVJSRZzQYct4Cpq52gm4+srMKcg6rfhwIEUirF4 Zj1YDR8jcfdINQY4b3Cmv6kzigHew6yL8lJOxLsSRywwmfaJCJcmg2N/sGhDzrgxU/Ar gapGFH7obiGMTMonzNdLr7F8e8sByowfJ4v/mXRgg04Sqg4TLoAIOp6pHsD60rGq5dz7 00mQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1767724105; x=1768328905; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=lVE4nLj+3BtCLTmQkJXQCdG9/ceCHtDUVYkwlyOryAk=; b=OhaM+sokUSL3ZaPZQbSbCjmhgRZSzXQPls3MmxMiURoQKP9d5O62VGvqfPR6PHFpZA 52Hfx0qa27BNMSGZFaA8aNFEcL8Z/ApcAofhplkkQ2kIaUVQI92jPSf+Jzvr9P3VI/mv w5QIntbJ81TPLLwgkux0gTTjwOegYLKkt61ZNrdXTjqKBk+vKAqxaM7RL+K9+Z6XP0Rl castKbn9oiRTGm0x3+B9wYi5vVUDG4+Q6iKaivfoNYpdIr55BIuM8M0cS2hE5G4p1tPY Xh8PbS1xyyffV6YQhDmYl1W/XzKv+Bls+y1nXRp+1KkLv6AiJMs8tMBUzZICEG2MKk5C guIg== X-Gm-Message-State: AOJu0YwLUgKQ0WmmIqgB+8/9HDaTjgiTOI9QKGy9ZH/r8cDoXkC9IiEZ r5Gzu/9d3RBB7TMvnugTvAi6Z0CvjEQ/1WL1Sl87/RaDJuoyWlZ2d0xdP4A5S8+WDpk= X-Gm-Gg: AY/fxX67KM7vwINJWCcab7Skl8mHbJszVZB0nVRJIXlq0HBjJu37gbwKebncyMOx4j7 ui+KkBKia+A8kT759+9l9Nxd5pJCb5MjYTUP6si49DolAujO6oVjl1J80x6hvigTixtVdg9uOlP kZ2EVtegNSyxBYtrk/r2NuYgNRx2I1uElI4y3hr+4VnO3wIKHGlxUmEmt1UdUqIMwgcMsnMKCUh /UXFoWBMVmaYfn/+97khfsddHGvKmljlW2/FH7zy36YDqDceoKd/OieXb8/N5jz1K+RQ/JnZaus qpJSlkKK0q0zC/4s4muE6yPVUN7F7hwISyGLpBQQ+EZ1O5VgLF6iyPuXbi+26CXK/KML7Lw2Liq x6Cvvl7uRjAb2Dz18ZHjRHISyHZKM/shQF046WzFysmL9CieZZkd5DZq7XDeGZuWT4Goh8tL5Kd dmXm7keLeC3RKUBuh39lSnA5hRvo32q8852eMPKm3WOyVl++05/9iPWkM= X-Google-Smtp-Source: AGHT+IGNKCYeVwO8BuQyQNZvt1R3GGtg2YXQKW2Ch2t09TL+RzOTopq1Rye07UfZrw9zduUkB+y7mQ== X-Received: by 2002:a05:620a:29c1:b0:89d:4a69:1502 with SMTP id af79cd13be357-8c37eb76e90mr392816985a.3.1767724104946; Tue, 06 Jan 2026 10:28:24 -0800 (PST) Received: from vboudevin-pc.mtl.sfl (mtl.savoirfairelinux.net. [208.88.110.46]) by smtp.gmail.com with ESMTPSA id af79cd13be357-8c37f4a97fesm214003185a.4.2026.01.06.10.28.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 06 Jan 2026 10:28:24 -0800 (PST) From: ValentinBoudevin To: openembedded-core@lists.openembedded.org Cc: ValentinBoudevin Subject: [PATCH 1/4] generate-cve-exclusions: Add --output-json option Date: Tue, 6 Jan 2026 13:28:19 -0500 Message-ID: <20260106182822.3377881-1-valentin.boudevin@gmail.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 06 Jan 2026 18:28:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/228909 This option "--output-json" can be used to return a json file instead of the standard .inc file provided. The JSON file can easily be manipulated contrary to the .inc file. Example output structure of the JSON file: ```json { "cve_status": { "CVE-2019-25160": { "active": false, "message": "fixed-version: Fixed from version 5.0" }, "CVE-2019-25162": { "active": false, "message": "fixed-version: Fixed from version 6.0" }, ... ``` Also, this commit doesn't affect or modify any existing behaviour of the script. --- .../linux/generate-cve-exclusions.py | 64 +++++++++++++++---- 1 file changed, 50 insertions(+), 14 deletions(-) diff --git a/meta/recipes-kernel/linux/generate-cve-exclusions.py b/meta/recipes-kernel/linux/generate-cve-exclusions.py index dfc16663a5..5a0a947e06 100755 --- a/meta/recipes-kernel/linux/generate-cve-exclusions.py +++ b/meta/recipes-kernel/linux/generate-cve-exclusions.py @@ -91,6 +91,7 @@ def main(argp=None): parser = argparse.ArgumentParser() parser.add_argument("datadir", type=pathlib.Path, help="Path to a clone of https://github.com/CVEProject/cvelistV5 or https://git.kernel.org/pub/scm/linux/security/vulns.git") parser.add_argument("version", type=Version, help="Kernel version number to generate data for, such as 6.1.38") + parser.add_argument("--output-json", action="store_true", help="Return CVE_STATUS mapping as JSON") args = parser.parse_args(argp) datadir = args.datadir.resolve() @@ -99,7 +100,10 @@ def main(argp=None): data_version = subprocess.check_output(("git", "describe", "--tags", "HEAD"), cwd=datadir, text=True) - print(f""" + cve_status = {} + + if not args.output_json: + print(f""" # Auto-generated CVE metadata, DO NOT EDIT BY HAND. # Generated at {datetime.datetime.now(datetime.timezone.utc)} for kernel version {version} # From {datadir.name} {data_version} @@ -131,26 +135,58 @@ do_cve_check[prefuncs] += "check_kernel_cve_status_version" continue first_affected, fixed, backport_ver = get_fixed_versions(cve_info, base_version) if not fixed: - print(f"# {cve} has no known resolution") + cve_status[cve] = { + "active": True, + "message": "no known resolution" + } + if not args.output_json: + print(f"# {cve} has no known resolution") elif first_affected and version < first_affected: - print(f'CVE_STATUS[{cve}] = "fixed-version: only affects {first_affected} onwards"') + cve_status[cve] = { + "active": False, + "message": f"fixed-version: only affects {first_affected} onwards" + } + if not args.output_json: + print(f'CVE_STATUS[{cve}] = "fixed-version: only affects {first_affected} onwards"') elif fixed <= version: - print( - f'CVE_STATUS[{cve}] = "fixed-version: Fixed from version {fixed}"' - ) + cve_status[cve] = { + "active": False, + "message": f"fixed-version: Fixed from version {fixed}" + } + if not args.output_json: + print(f'CVE_STATUS[{cve}] = "fixed-version: Fixed from version {fixed}"') else: if backport_ver: if backport_ver <= version: - print( - f'CVE_STATUS[{cve}] = "cpe-stable-backport: Backported in {backport_ver}"' - ) + cve_status[cve] = { + "active": False, + "message": f"cpe-stable-backport: Backported in {backport_ver}" + } + if not args.output_json: + print(f'CVE_STATUS[{cve}] = "cpe-stable-backport: Backported in {backport_ver}"') else: - print(f"# {cve} may need backporting (fixed from {backport_ver})") + cve_status[cve] = { + "active": True, + "message": f"May need backporting (fixed from {backport_ver})" + } + if not args.output_json: + print(f"# {cve} may need backporting (fixed from {backport_ver})") else: - print(f"# {cve} needs backporting (fixed from {fixed})") - - print() - + cve_status[cve] = { + "active": True, + "message": f"#Needs backporting (fixed from {fixed})" + } + if not args.output_json: + print(f"# {cve} needs backporting (fixed from {fixed})") + + if not args.output_json: + print() + + # Emit structured output if --ret-struct was requested + if args.output_json: + print(json.dumps({ + "cve_status": cve_status, + }, indent=2)) if __name__ == "__main__": main() From patchwork Tue Jan 6 18:28:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: ValentinBoudevin X-Patchwork-Id: 78103 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0E097CEFCEB for ; Tue, 6 Jan 2026 18:28:32 +0000 (UTC) Received: from mail-qk1-f195.google.com (mail-qk1-f195.google.com [209.85.222.195]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.96787.1767724109558161467 for ; Tue, 06 Jan 2026 10:28:29 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20230601 header.b=fTGzmJtj; spf=pass (domain: gmail.com, ip: 209.85.222.195, mailfrom: valentin.boudevin@gmail.com) Received: by mail-qk1-f195.google.com with SMTP id af79cd13be357-8b2da4fb076so20306185a.2 for ; Tue, 06 Jan 2026 10:28:29 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1767724108; x=1768328908; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=oy/zyFrUZHh3XWg7UTuLp4q/9dgFFbI4+nRFp9/3xKI=; b=fTGzmJtjRBZkfXeIBvKnvza6PcAnn7mGOFTRx42CDIt1ZNsZEbPJoZU2XwONe6U0eU INGslm5bkkW/yB1m5plhgUUyKrKJSbCphgU3ZiqEpCaLWhg/9W0/hHoLrKe0PqVTJs/O R6AU3UGN0X4zoX/zxETveityamfTTAOTfBs4tSEUOHqL+IW+2bCkLqQLSYg8bdUst0HG nP2ykRpHMlhwwP817s08f3DxIPdlXfraHhu5Kqg2q0soIet+XOyrE70z7Ed47zgSoFuI gdOVnic2z3ZgF0N6/BycifDyOAQOr/O6i6svMnMkV2EhIN1TUCrqJBWyMT7lLO0Imyi/ ZraQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1767724108; x=1768328908; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=oy/zyFrUZHh3XWg7UTuLp4q/9dgFFbI4+nRFp9/3xKI=; b=QqBUo3o8m9jIk2gHvcJRodNtfXEUvVZvMDrXw0vOm9sdcon8RN2ZTFcTXFtD6YcWXA yvh7JuFfC69edMk/8par52s/npi9Xcigf12tjYAte31QUNcno0oljGSISR5C0n/5BUCP zIAgOWQVBnhxIjrcu4NU3mBPmrdo1AAy8YOxM+Z0URrkzSxE0AYP11HbeYrVz98M++ML +VaWRhmZIOxSmhMeKi+kHTQaxKsY7Oc3bg32SmWSNHAKoi5hw/mmIO6PxhQAb5YoV+QM euJKfcGr8b64TaXfy7UfTHUkU8/pe/6oqE30T97RmogiUKDFjdX5WFMYBL8tNlI38Jox g2Gw== X-Gm-Message-State: AOJu0YzF8mOTjlRSAurQ5Z9IhG/0sm/13IpGwHmSE+4l2EkK5UyD/xC+ X+mhGi3fZM4B+JV1N5LD9Kdl1koGoRl5QaWs5r0ms9PfGz8SWWXWlFbRtiXFhCe13xUgkw== X-Gm-Gg: AY/fxX5+/tup10pTxOIPg9oV39dnSDGB9EgmNvCaCZ7aW99hr9ctkcdguWuow+/yQ9O 3Ey6wknmk1bzPLCB9bfI4d+DVLnfqmlocm6whVt1UNWHWXDSEepZ5Y2V0f+VxvN62aHP3G9aMtp Xyf6NUYWw+QEI/4qAol6CCuOAwhGg+zCx/uH/pu0eoLHX6yRx7tkBPP2iXeYVxDrWiJXmsiFS6P eIN2AGY/ape/opaDpEemHqyhnPqje+zKcQgs9dbAj9Y+oA1t8d7UV0Otzr99ZIi3tz3u2IpfS4u nliYv+5eZDGkmEUp+0oRHeMB7UPFEPjEjF/nNOirBidSaS0FiFdTXIT8Gp0D8aAiQoyPABg84m+ +3HcizCA77bxNWAvoDUtMUE5FJWiNpx3TeGYun28jSg0nyOm5W/nwxjqZNOSpPL2O6qJ84ELgVH IqFrkKUnL93c4mpWf9PEGYtxHHimED0x4pfkI2l7h8o9aHRB3QwgT3eCk= X-Google-Smtp-Source: AGHT+IHJ3cIOZQBxU0q3TjGGAPnFvJ9kQcchxv9GpERmsCoD9JOaETom2KWJr1lFAT08IL91ZVuLog== X-Received: by 2002:a05:620a:1917:b0:8b2:e177:ddb2 with SMTP id af79cd13be357-8c37ebc6664mr390980085a.6.1767724108510; Tue, 06 Jan 2026 10:28:28 -0800 (PST) Received: from vboudevin-pc.mtl.sfl (mtl.savoirfairelinux.net. [208.88.110.46]) by smtp.gmail.com with ESMTPSA id af79cd13be357-8c37f4a97fesm214003185a.4.2026.01.06.10.28.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 06 Jan 2026 10:28:28 -0800 (PST) From: ValentinBoudevin To: openembedded-core@lists.openembedded.org Cc: ValentinBoudevin Subject: [PATCH 2/4] generate-cve-exclusions: Add a .bbclass Date: Tue, 6 Jan 2026 13:28:20 -0500 Message-ID: <20260106182822.3377881-2-valentin.boudevin@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260106182822.3377881-1-valentin.boudevin@gmail.com> References: <20260106182822.3377881-1-valentin.boudevin@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 06 Jan 2026 18:28:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/228910 Add a .bbclass to generate-cve-exclusions to use this script at every run. This class needs to be inherit by the linux kernel recipe. This class contains several methods: *do_clone_cvelistV5: Clone the cvelistV5 repo in ${WORKDIR}/cvelistV5/git (e.g. bitbake-builds/poky-master/build/tmp/work/qemux86_64-poky-linux/ linux-yocto/6.18.1+git/cvelistV5/git) *do_generate_cve_exclusions: Use the script generate-cve-exclusions.py. It uses the new "--output-json" argument to generate a JSON file as an output stored in ${WORKDIR}/cvelistV5//cve-exclusion_${LINUX_VERSION}.json *do_cve_check:prepend: Parse the previously generated JSON file to set the variable CVE_STATUS corretly --- meta/classes/generate-cve-exclusions.bbclass | 67 ++++++++++++++++++++ 1 file changed, 67 insertions(+) create mode 100644 meta/classes/generate-cve-exclusions.bbclass diff --git a/meta/classes/generate-cve-exclusions.bbclass b/meta/classes/generate-cve-exclusions.bbclass new file mode 100644 index 0000000000..3e34ba563d --- /dev/null +++ b/meta/classes/generate-cve-exclusions.bbclass @@ -0,0 +1,67 @@ +CVE_EXCLUSIONS_WORKDIR ?= "${WORKDIR}/cvelistV5" +CVELISTV5_PATH ?= "${CVE_EXCLUSIONS_WORKDIR}/git" + +python do_clone_cvelistV5() { + import subprocess + import shutil, os + rootdir = d.getVar("CVELISTV5_PATH") + d.setVar("SRC_URI", "git://github.com/CVEProject/cvelistV5.git;branch=main;protocol=https") + d.setVar("SRCREV", "${AUTOREV}") + src_uri = (d.getVar('SRC_URI') or "").split() + # Fetch the kernel vulnerabilities sources + fetcher = bb.fetch2.Fetch(src_uri, d) + fetcher.download() + # Unpack into the standard work directory + fetcher.unpack(rootdir) + # Remove the folder ${PN} set by unpack + subdirs = [d for d in os.listdir(rootdir) if os.path.isdir(os.path.join(rootdir, d))] + if len(subdirs) == 1: + srcdir = os.path.join(rootdir, subdirs[0]) + for f in os.listdir(srcdir): + shutil.move(os.path.join(srcdir, f), rootdir) + shutil.rmtree(srcdir) + bb.note("Vulnerabilities repo unpacked into: %s" % rootdir) +} +do_clone_cvelistV5[network] = "1" +do_clone_cvelistV5[nostamp] = "1" +do_clone_cvelistV5[doc] = "Clone CVE information from the CVE Project: https://github.com/CVEProject/cvelistV5.git" +addtask clone_cvelistV5 after do_fetch before do_generate_cve_exclusions + +do_generate_cve_exclusions() { + generate_cve_exclusions_script=$(find ${COREBASE} -name "generate-cve-exclusions.py") + if [ -z "${generate_cve_exclusions_script}" ]; then + bbfatal "generate-cve-exclusions.py not found in ${COREBASE}." + fi + python3 "${generate_cve_exclusions_script}" \ + ${CVELISTV5_PATH} \ + ${LINUX_VERSION} \ + --output-json > ${CVE_EXCLUSIONS_WORKDIR}/cve-exclusion_${LINUX_VERSION}.json +} +do_generate_cve_exclusions[nostamp] = "1" +do_generate_cve_exclusions[doc] = "Generate CVE exclusions for the kernel build. (e.g., cve-exclusion_6.12.inc)" +addtask generate_cve_exclusions after do_clone_cvelistV5 before do_cve_check + +python do_cve_check:prepend() { + import os + import json + + workdir = d.getVar("CVE_EXCLUSIONS_WORKDIR") + kernel_version = d.getVar("LINUX_VERSION") + json_input_file = os.path.join(workdir, "cve-exclusion_%s.json" % kernel_version) + + # Parse JSON + with open(json_input_file, 'r', encoding='utf-8') as f: + cve_data = json.load(f) + + cve_status_dict = cve_data.get("cve_status", {}) + + if os.path.exists(json_input_file): + count = 0 + for cve_id, info in cve_status_dict.items(): + if info.get("active", True): + # Skip active CVEs + continue + d.setVarFlag("CVE_STATUS", cve_id, info.get("message", "")) + count += 1 + bb.note("Loaded %d CVE_STATUS entries from JSON output for kernel %s" % (count, kernel_version)) +} \ No newline at end of file From patchwork Tue Jan 6 18:28:21 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: ValentinBoudevin X-Patchwork-Id: 78105 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 106C7C47BE1 for ; Tue, 6 Jan 2026 18:28:32 +0000 (UTC) Received: from mail-qk1-f177.google.com (mail-qk1-f177.google.com [209.85.222.177]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.96788.1767724110987184282 for ; Tue, 06 Jan 2026 10:28:31 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20230601 header.b=UvZBSmkz; spf=pass (domain: gmail.com, ip: 209.85.222.177, mailfrom: valentin.boudevin@gmail.com) Received: by mail-qk1-f177.google.com with SMTP id af79cd13be357-8b1c0dcb3b3so22047485a.2 for ; Tue, 06 Jan 2026 10:28:30 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1767724110; x=1768328910; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=EWZrLXB7XnOemrKbUqKB1ln7FbdLPw/WfamWIxS2D54=; b=UvZBSmkzzmVm8+ernC66YdMfuJRNOQmyp6YasTsm1WFa7igguu7Eehbf+j/eWKcaUs 3zxoLFE9rKKYm3ZNDiZKu0+OcwKzvB+CYZUYwm+EdhuvvGoEPmcR5cHUFxHhDDyZvTKf u/1ZGpXMkFk8fj9154leJI4f8y1Ponju2TQAP3M9a26QhVW1bA+p/krze0WtyQzed3aZ Zxy7i5J3oLkjK2XPQljqPBoek3j/Y1t4LUSyiuK2ZGBGx7TVpRyenHNbb9iQsW19bpYL pRohQjIplRVj6n56mA9wAxGl85ztOV+ofofhEYozriSmrH6vVGjyYpflhCENYfbefm9g 25Rg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1767724110; x=1768328910; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=EWZrLXB7XnOemrKbUqKB1ln7FbdLPw/WfamWIxS2D54=; b=TjXTD8lPj9e8hTjj03ecI7+BUUcAmhCAdzaDvEB0PZT1tfevpayI2R1pezmAzr2mSN 3wiUdTHyynzQgGtipTt125WGiGko24fKdLNRxC4ImAIek3/l/DnMNCdjtNu8g2XkanJw MBgxQlg8eiSoCdPG8YLH+Se4IsrTZJrhQAk1AA4+PKqaWEhp2Uk8WeH9V3qGKK/yQ/wS ZNBBNATnyrgZikHnT8tec5PubwC38KJMyB9QW/oqXgrSyXQRLwyH85qjDDDvp5jeOLyO /HAPlv24tPLZMMuPILxvBGR8wuJXv2xhp4trxVOeir2kzYwq23kD0Pg+DErsQ9aE2803 eTEQ== X-Gm-Message-State: AOJu0YwhHnhlcWXQcH4gr1UbAwq5x4Co6ouUw2ImNucwxJ8GyPelhV+p wL+y0/0AJp1rqnlGc49myht3snnHWDgT8SqLSkMVgOc2sqqjpwaCyTtiGfcGxNRJhOg= X-Gm-Gg: AY/fxX4phrq5ShCB53GpIgxnO0Pr1HpwHeg4r9RdkEIi2bFQPnoVhKnhH/nJ6+dQ1+l RIiJmMYFafvjw0MULyB30ghb8P4aCdkLdeRBrYe3m2I7qhH3qecJ86tDnvp5qAYPHgZ6iBykhn2 wx0sFzo9kkrb93eOlHehq1n/u0ZfOyGgyhZNQRdCbpIwETAXk+nl4+sS+xzVpw/raqqZ+kiWc0s 7K8smuhiqb7wAEhfQhUW0+OsSJXFUzk9HedOCdrdvt89lMM4anmSGpDgY1wZ/FOhx0tivIl24AP FunUfq2YAHqwSkHy3y8Sh5t23/pko5qHYDARZneFzWVNy1G8y+Tz3Sya5NRfGQQCSp9nHW9hI5B DI+uawqr0vnOyQ3rugxjUM+qM+x2spgaevKd2Q/KoJCmQ1m32iSgMleDYeVkQ84DTBq1PSkxZli IrThNKrZvEhYXomdhXAZzvjc9tdX8f+g9zb6dWwNMg2Fe+6HX+B4ThlNU= X-Google-Smtp-Source: AGHT+IH2z98lg7+FlwkfXNkWtyqCe1u9wXHyDt7fhTYr8lgj1oHIRS+4q6mO+Ra0rfKbAyXPFomeUg== X-Received: by 2002:a05:620a:4690:b0:8a5:2246:bc29 with SMTP id af79cd13be357-8c37ebc1922mr370601785a.8.1767724109871; Tue, 06 Jan 2026 10:28:29 -0800 (PST) Received: from vboudevin-pc.mtl.sfl (mtl.savoirfairelinux.net. [208.88.110.46]) by smtp.gmail.com with ESMTPSA id af79cd13be357-8c37f4a97fesm214003185a.4.2026.01.06.10.28.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 06 Jan 2026 10:28:29 -0800 (PST) From: ValentinBoudevin To: openembedded-core@lists.openembedded.org Cc: ValentinBoudevin Subject: [PATCH 3/4] generate-cve-exclusions: Move python script Date: Tue, 6 Jan 2026 13:28:21 -0500 Message-ID: <20260106182822.3377881-3-valentin.boudevin@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260106182822.3377881-1-valentin.boudevin@gmail.com> References: <20260106182822.3377881-1-valentin.boudevin@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 06 Jan 2026 18:28:32 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/228911 The script should be located with other scripts in scripts/contrib instead of staying in meta/classes/. Update the new .bbclass to match this modification --- meta/classes/generate-cve-exclusions.bbclass | 2 +- .../linux => scripts/contrib}/generate-cve-exclusions.py | 0 2 files changed, 1 insertion(+), 1 deletion(-) rename {meta/recipes-kernel/linux => scripts/contrib}/generate-cve-exclusions.py (100%) diff --git a/meta/classes/generate-cve-exclusions.bbclass b/meta/classes/generate-cve-exclusions.bbclass index 3e34ba563d..4f539ee4c5 100644 --- a/meta/classes/generate-cve-exclusions.bbclass +++ b/meta/classes/generate-cve-exclusions.bbclass @@ -28,7 +28,7 @@ do_clone_cvelistV5[doc] = "Clone CVE information from the CVE Project: https://g addtask clone_cvelistV5 after do_fetch before do_generate_cve_exclusions do_generate_cve_exclusions() { - generate_cve_exclusions_script=$(find ${COREBASE} -name "generate-cve-exclusions.py") + generate_cve_exclusions_script=${COREBASE}/scripts/contrib/generate-cve-exclusions.py if [ -z "${generate_cve_exclusions_script}" ]; then bbfatal "generate-cve-exclusions.py not found in ${COREBASE}." fi diff --git a/meta/recipes-kernel/linux/generate-cve-exclusions.py b/scripts/contrib/generate-cve-exclusions.py similarity index 100% rename from meta/recipes-kernel/linux/generate-cve-exclusions.py rename to scripts/contrib/generate-cve-exclusions.py From patchwork Tue Jan 6 18:28:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: ValentinBoudevin X-Patchwork-Id: 78106 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E5695CEFCEB for ; Tue, 6 Jan 2026 18:28:41 +0000 (UTC) Received: from mail-qk1-f169.google.com (mail-qk1-f169.google.com [209.85.222.169]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.96791.1767724112277846896 for ; Tue, 06 Jan 2026 10:28:32 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20230601 header.b=TGAkYre1; spf=pass (domain: gmail.com, ip: 209.85.222.169, mailfrom: valentin.boudevin@gmail.com) Received: by mail-qk1-f169.google.com with SMTP id af79cd13be357-8b1bb9c3c04so24231085a.3 for ; Tue, 06 Jan 2026 10:28:32 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1767724111; x=1768328911; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=yCNmqatRkTI5xpbleR5UbIQzoEXgsWdlPXf0o/X528s=; b=TGAkYre1BllQKpX0AHHPQ96IzVablLCs0ugUX3ByVlabLMbYtBMUbawyyLBNXhBXWs hJtyp8SOyiKYm6fYQ9uiL/zp7J/fjhMvCr8pMcqZvYoTbXXx7pgp7fF4INzFJp2B+foi 8LNeX4Tof1xXjPtrSaJGEUryoPRMF5HsiurBwljaV0N69H63STJo1CJObnDyFknhyREp wQzszyBBDzKD1qJSmE6Jx5uGmM/unVtG5pZvR02zH1gEB3+WgsPHOLHOw2sLYFiQjBhG axoJY7N5sWw45VlLRDo59lTeppcsdZljrChA3WVxpIRHVC+plPPIt76pHnsdV1wsk1tW ddzg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1767724111; x=1768328911; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=yCNmqatRkTI5xpbleR5UbIQzoEXgsWdlPXf0o/X528s=; b=HKk4bZsNRJ4b1jIKYK8zMhdHhrRDrr3d20ysA3znXI9nZ8BrDoU05DMO3hQ6fg1/X4 zI+yd1BbR5kuAfLnV9FdRfPsRdpBLOVBbJg7gDsOS5r1wsJl2CCmfR1EthvDR6Vl4nZz zxFpQla4L3fSvCeJ6Ons6/+rPIr8wYq4s66Bc4QijZ7eOUvMx51dSH7WhKAseRj0vGj8 nlikJLXocvzc6Krl4Dj8D5Npy/MHfcBcF6jmWSnJisnmwaaIoaISthXUtczjEJyZveTI qhjs+myT+GyILYBtwyfzcQVSSRUAFWkvX9ydCVG0PiQo42Zoiuay79x0NBw6o9oyk1UD dyYg== X-Gm-Message-State: AOJu0Yym9KH+wVIsWL7Q4iw1mjnFvZwXUsgFmrBoM4vX2m4f7y+JYp25 OF4ZyYuMtAhosY0Hx3UfCys1KTiFEvLoibUu0XoBUUY7Dx55RziyuYwborA3SFQekJM= X-Gm-Gg: AY/fxX6yo8LLwtUQVojDL7EQA+duir74SmFqBTs5Mv4uS9wmOKRAyVFztdWeJoPs7fm z3LG8bUHP2ZZsKs/AnZvxy4b6cx0GggeMWWYNagZQBY2IECQHJPx+8wQYr7zSPAbR4pgLJtIhuM HFibznjbg0CWJ1bcWanU8Gm+mzB0Nb5NiRH0d9bcovnwmesDOz8mJloaUA2mLYldRhtKpltBjs2 2k6bvvXrO5/iVzGxpGNIgXO6kiYNU3b7ZLah16ePrAlfdlEgKtILgI3DkpjIP4UYjaVgwHnsShW cc4/kfK4K4AbkoJYMqzB3YXK33GAF1kWDLGk2KoVKVsotodk2imtFE7Wbsss5Om54dnO0PIcYdG KrOvh1MGl/fM3RBb6Fg+yRbQ53jGVuYLXnhmZItMf5yhdi1FretReoIYyAdtq2CDAlp2AKAbpU0 0URcHW3ZF1riNmYe0APNMqqFi06IOHn+AqnqQyURRdOTVwBEhfMaBiPVM= X-Google-Smtp-Source: AGHT+IFSvKNcNB0hzZBLdEFoiTXCh6Wq0G/Jgfax2RhNHncCxznIpz6ADelhHREZBOSIZHgDSmu3Vw== X-Received: by 2002:a05:620a:708a:b0:8a3:d644:6930 with SMTP id af79cd13be357-8c37eb78784mr390554785a.5.1767724111191; Tue, 06 Jan 2026 10:28:31 -0800 (PST) Received: from vboudevin-pc.mtl.sfl (mtl.savoirfairelinux.net. [208.88.110.46]) by smtp.gmail.com with ESMTPSA id af79cd13be357-8c37f4a97fesm214003185a.4.2026.01.06.10.28.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 06 Jan 2026 10:28:30 -0800 (PST) From: ValentinBoudevin To: openembedded-core@lists.openembedded.org Cc: ValentinBoudevin Subject: [PATCH 4/4] linux: Add inherit on generate-cve-exclusions Date: Tue, 6 Jan 2026 13:28:22 -0500 Message-ID: <20260106182822.3377881-4-valentin.boudevin@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260106182822.3377881-1-valentin.boudevin@gmail.com> References: <20260106182822.3377881-1-valentin.boudevin@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Tue, 06 Jan 2026 18:28:41 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/228912 All kernel recipes can use generate-cve-exclusions class to perform CVE exclusions. --- meta/recipes-kernel/linux/linux-yocto-rt_6.12.bb | 3 +++ meta/recipes-kernel/linux/linux-yocto-rt_6.16.bb | 3 +++ meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb | 3 +++ meta/recipes-kernel/linux/linux-yocto-tiny_6.12.bb | 3 +++ meta/recipes-kernel/linux/linux-yocto-tiny_6.16.bb | 3 +++ meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb | 3 +++ meta/recipes-kernel/linux/linux-yocto_6.12.bb | 3 +++ meta/recipes-kernel/linux/linux-yocto_6.16.bb | 3 +++ meta/recipes-kernel/linux/linux-yocto_6.18.bb | 3 +++ 9 files changed, 27 insertions(+) diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.12.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.12.bb index 9ac8507f9f..5cc735ae93 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.12.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.12.bb @@ -5,6 +5,9 @@ require recipes-kernel/linux/linux-yocto.inc # CVE exclusions include recipes-kernel/linux/cve-exclusion_6.12.inc +# Generate Dynamic CVE Exclusions +inherit generate-cve-exclusions + # Skip processing of this recipe if it is not explicitly specified as the # PREFERRED_PROVIDER for virtual/kernel. This avoids errors when trying # to build multiple virtual/kernel providers, e.g. as dependency of diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.16.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.16.bb index 1230e4e805..53532b4e7e 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.16.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.16.bb @@ -5,6 +5,9 @@ require recipes-kernel/linux/linux-yocto.inc # CVE exclusions include recipes-kernel/linux/cve-exclusion_6.16.inc +# Generate Dynamic CVE Exclusions +inherit generate-cve-exclusions + # Skip processing of this recipe if it is not explicitly specified as the # PREFERRED_PROVIDER for virtual/kernel. This avoids errors when trying # to build multiple virtual/kernel providers, e.g. as dependency of diff --git a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb index 32ed29f25e..e95264d99d 100644 --- a/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-rt_6.18.bb @@ -5,6 +5,9 @@ require recipes-kernel/linux/linux-yocto.inc # CVE exclusions include recipes-kernel/linux/cve-exclusion_6.18.inc +# Generate Dynamic CVE Exclusions +inherit generate-cve-exclusions + # Skip processing of this recipe if it is not explicitly specified as the # PREFERRED_PROVIDER for virtual/kernel. This avoids errors when trying # to build multiple virtual/kernel providers, e.g. as dependency of diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.12.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.12.bb index 940561352c..6b17c2ff7f 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.12.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.12.bb @@ -8,6 +8,9 @@ require recipes-kernel/linux/linux-yocto.inc # CVE exclusions include recipes-kernel/linux/cve-exclusion_6.12.inc +# Generate Dynamic CVE Exclusions +inherit generate-cve-exclusions + LINUX_VERSION ?= "6.12.62" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.16.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.16.bb index ffa15b0c1b..02e502faed 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.16.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.16.bb @@ -8,6 +8,9 @@ require recipes-kernel/linux/linux-yocto.inc # CVE exclusions include recipes-kernel/linux/cve-exclusion_6.16.inc +# Generate Dynamic CVE Exclusions +inherit generate-cve-exclusions + LINUX_VERSION ?= "6.16.11" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb index 2afdc02467..e36a7fb028 100644 --- a/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto-tiny_6.18.bb @@ -8,6 +8,9 @@ require recipes-kernel/linux/linux-yocto.inc # CVE exclusions include recipes-kernel/linux/cve-exclusion_6.18.inc +# Generate Dynamic CVE Exclusions +inherit generate-cve-exclusions + LINUX_VERSION ?= "6.18.1" LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.12.bb b/meta/recipes-kernel/linux/linux-yocto_6.12.bb index 84419f8c78..b6ac5f9b90 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.12.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.12.bb @@ -6,6 +6,9 @@ require recipes-kernel/linux/linux-yocto.inc include recipes-kernel/linux/cve-exclusion.inc include recipes-kernel/linux/cve-exclusion_6.12.inc +# Generate Dynamic CVE Exclusions +inherit generate-cve-exclusions + # board specific branches KBRANCH:qemuarm ?= "v6.12/standard/arm-versatile-926ejs" KBRANCH:qemuarm64 ?= "v6.12/standard/base" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.16.bb b/meta/recipes-kernel/linux/linux-yocto_6.16.bb index 408f14b451..947de4186e 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.16.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.16.bb @@ -6,6 +6,9 @@ require recipes-kernel/linux/linux-yocto.inc include recipes-kernel/linux/cve-exclusion.inc include recipes-kernel/linux/cve-exclusion_6.16.inc +# Generate Dynamic CVE Exclusions +inherit generate-cve-exclusions + # board specific branches KBRANCH:qemuarm ?= "v6.16/standard/arm-versatile-926ejs" KBRANCH:qemuarm64 ?= "v6.16/standard/base" diff --git a/meta/recipes-kernel/linux/linux-yocto_6.18.bb b/meta/recipes-kernel/linux/linux-yocto_6.18.bb index 562a997020..66320f7123 100644 --- a/meta/recipes-kernel/linux/linux-yocto_6.18.bb +++ b/meta/recipes-kernel/linux/linux-yocto_6.18.bb @@ -6,6 +6,9 @@ require recipes-kernel/linux/linux-yocto.inc include recipes-kernel/linux/cve-exclusion.inc include recipes-kernel/linux/cve-exclusion_6.18.inc +# Generate Dynamic CVE Exclusions +inherit generate-cve-exclusions + # board specific branches KBRANCH:qemuarm ?= "v6.18/standard/arm-versatile-926ejs" KBRANCH:qemuarm64 ?= "v6.18/standard/base"