From patchwork Fri Jan 16 19:05:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: ValentinBoudevin X-Patchwork-Id: 78967 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 042D0C982F3 for ; Fri, 16 Jan 2026 19:12:57 +0000 (UTC) Received: from mail-qt1-f195.google.com (mail-qt1-f195.google.com [209.85.160.195]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5245.1768590771225402927 for ; Fri, 16 Jan 2026 11:12:51 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20230601 header.b=e43tN0s3; spf=pass (domain: gmail.com, ip: 209.85.160.195, mailfrom: valentin.boudevin@gmail.com) Received: by mail-qt1-f195.google.com with SMTP id d75a77b69052e-5014501ba93so3385561cf.2 for ; Fri, 16 Jan 2026 11:12:51 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1768590770; x=1769195570; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=dRT8r2i3a5t6omSLB10XNVu77c4TvDHGSPBgsb/7Vok=; b=e43tN0s3+c4FzKNt5nYqkrcWX2iyw6Qs773BQOvdIivJV2tclZBqp3AZ4nFxtsmW+M VBV3YUwY6qLZuiO9TAdoGEGqefh//cDHYNiDi4zP0hLtkiUm4eIoB/7ARGSVSXjZHFNm aHNGo79PSX5g9pRiiEI8IgYAiuKJnhbaUGsXBfH8tZF8Vn1DMGTpQYVzZXlbtU5mi7zO ccqZ5zDuIWdme1t8X001uy4LOF2OkP5eGoyBGVH+sl920mzoJlACbTjHKIZypdk3yalz ZGwQL4iS9aI6CC/i+JbxsjTPpXKpNs3FRp6U44qgc11JWWvj8CbCz5JGn87oj0unW0oH qevg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1768590770; x=1769195570; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=dRT8r2i3a5t6omSLB10XNVu77c4TvDHGSPBgsb/7Vok=; b=HKmwzEy0KcyFhOWhoHYRWPq7NFHmZKI90CCVD634lASvj9SaKloNx9TvdHDUnUXxAS rkFb78dm21PGc9RB4TcNeYeZAXtbJV4wIdxnKkcBGxvJifYHi6ILeB+x5TCZTTS4rbeK 382KBX3fhL1VNsCaMToqkC86Yx9HAzZ6LaJ3ZGrzoqxAJ5CUNe0fjsKpn9Xri0ylNJNV KOYHmOQB6K6VmUwNWSm9iTfCS+kTrE/tzk4kNufoqlTQ+myEARmJ+xz3f7SqTSGm0IhY lAnwU3gMmAfu7W0/6jy9UqRceboIhNnynYt8E3QFOtt/GjRdOWDHfTd1ztqTsRln/y0Z uEwg== X-Gm-Message-State: AOJu0YwRFQBsR5t8Ckd/AG+gVxYPib2QOSkIQr2mpJJ1eTw3UaP91MFI qwqf/qtvsAklgD7QILdMX1BejEhOBGhgr1UAnBbgcSBsnSEMjqlmDP3UfCe/YhQjPw6cIw== X-Gm-Gg: AY/fxX7BnrxakIGIJme9ur1u97KHfFJSM9RSqJCkgFXxvFI/5vMsB8l1EfInYJhutxI pUdOE4CS7miCCEg6fWBowHuUC0wL+MzfC55XHLNMYzbrFcjfvG2a1hxPf6yn8WXR8ubz/VzKM+W /NdMZcIeptNb8a8g7u+Kdy9G62vKXQRU9cHjnhmzKj44JLW2mbc5FFRRA6WwhRqQS+Ac5TzHB8e 4OvrgCsZBgID9EoMVnwJ0LihYdeNShbcxyFgLixbEvXmrf+1aQC2O2tueCfn82gZkVfFvIYD3Jj 7Ui11XKkypVSuCQyTx6VRcN2InVTMMbVBzuSdUmhA9yTbaybWxWtpLUPy3oN/Y43+p9ydQbq6Ks BgiBDsHE/xrWUBM51U4I2eXH8cFLwPQD7f9Vs6F3RhNyMvzCLUjCpBzAK4bYEt6pQu6vmOTaMAw xRxjF8QwiSz2dfPAeNadCzNQAKa7roF1AqmzwwBuruTTEAAkFQlu65q+Z5wY1gJJyW5A== X-Received: by 2002:a05:620a:2947:b0:8b2:ec2f:cb3d with SMTP id af79cd13be357-8c6a67cb0bbmr423073385a.10.1768590770017; Fri, 16 Jan 2026 11:12:50 -0800 (PST) Received: from vboudevin-pc.mtl.sfl (mtl.savoirfairelinux.net. [208.88.110.46]) by smtp.gmail.com with ESMTPSA id af79cd13be357-8c6a71bf2b0sm287446685a.12.2026.01.16.11.12.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 16 Jan 2026 11:12:49 -0800 (PST) From: ValentinBoudevin To: openembedded-core@lists.openembedded.org Cc: daniel.turull@ericsson.com, jerome.oufella@savoirfairelinux.com, antonin.godard@bootlin.com, ValentinBoudevin Subject: [PATCH 1/1] improve_kerne_cve_report: Add a bbclass support Date: Fri, 16 Jan 2026 14:05:15 -0500 Message-ID: <20260116190520.118714-1-valentin.boudevin@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <188AFCD98EA3E578.3200434@lists.openembedded.org> References: <188AFCD98EA3E578.3200434@lists.openembedded.org> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 16 Jan 2026 19:12:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/229557 The script improve_kernel_cve_report.py doesn't have a bbclass. It can be usefull to have one to generate improved cve-check files at every run. This new class can be used to generate a new file in tmp/deploy/images with a .scouted.json in addition to the existing .json cve-check file. The new .scouted.json is based on the cve-check file and the SBOM (SPDX3 mandatory) to generate this improved cve-check file with extra entries found by the script improve_kernel_cve_report.py. It only requires an inherit on an image recipe (e.g. "inherit improve_kernel_cve_report" in core-image-minimal). It can be add to core-image-minimal in a second step if revelant. Signed-off-by: Valentin Boudevin --- .../classes/improve_kernel_cve_report.bbclass | 71 +++++++++++++++++++ 1 file changed, 71 insertions(+) create mode 100644 meta/classes/improve_kernel_cve_report.bbclass diff --git a/meta/classes/improve_kernel_cve_report.bbclass b/meta/classes/improve_kernel_cve_report.bbclass new file mode 100644 index 0000000000..5c496252b4 --- /dev/null +++ b/meta/classes/improve_kernel_cve_report.bbclass @@ -0,0 +1,71 @@ +python do_clean:append() { + import os, glob + if bb.utils.contains('INHERIT', 'create-spdx-2.2', 'false', 'true', d): + deploy_dir = d.expand('${DEPLOY_DIR_IMAGE}') + for f in glob.glob(os.path.join(deploy_dir, '*scouted.json')): + bb.note("Removing " + f) + os.remove(f) +} + +python do_clone_kernel_cve() { + import subprocess + import shutil, os + check_spdx = d.getVar("INHERIT") + rootdir = os.path.join(d.getVar("WORKDIR"), "vulns") + # Check if the feature is enabled and if SPDX 2.2 is not used + if "create-spdx-2.2" not in check_spdx: + d.setVar("SRC_URI", "git://git.kernel.org/pub/scm/linux/security/vulns.git;branch=master;protocol=https") + d.setVar("SRCREV", "${AUTOREV}") + src_uri = (d.getVar('SRC_URI') or "").split() + # Fetch the kernel vulnerabilities sources + fetcher = bb.fetch2.Fetch(src_uri, d) + fetcher.download() + # Unpack into the standard work directory + fetcher.unpack(rootdir) + # Remove the folder ${PN} set by unpack + subdirs = [d for d in os.listdir(rootdir) if os.path.isdir(os.path.join(rootdir, d))] + if len(subdirs) == 1: + srcdir = os.path.join(rootdir, subdirs[0]) + for f in os.listdir(srcdir): + shutil.move(os.path.join(srcdir, f), rootdir) + shutil.rmtree(srcdir) + bb.note("Vulnerabilities repo unpacked into: %s" % rootdir) + elif "create-spdx-2.2" in check_spdx: + bb.warn(f"improve_kernel_cve_report: Extra Kernel CVEs Scouting is desactivate because incompatible with SPDX 2.2.") +} +do_clone_kernel_cve[network] = "1" +do_clone_kernel_cve[nostamp] = "1" +do_clone_kernel_cve[doc] = "Clone the latest kernel vulnerabilities from https://git.kernel.org/pub/scm/linux/security/vulns.git" +addtask clone_kernel_cve after + +do_scout_extra_kernel_vulns() { + spdx_file="${SPDXIMAGEDEPLOYDIR}/${IMAGE_LINK_NAME}.spdx.json" + original_cve_check_file="${DEPLOY_DIR_IMAGE}/${IMAGE_LINK_NAME}.json" + new_cve_report_file="${DEPLOY_DIR_IMAGE}/${IMAGE_NAME}.scouted.json" + improve_kernel_cve_script="${COREBASE}/scripts/contrib/improve_kernel_cve_report.py" + + if ${@bb.utils.contains('INHERIT', 'create-spdx-2.2', 'true', 'false', d)}; then + bbwarn "improve_kernel_cve_report: Skipping extra kernel vulnerabilities scouting because incompatible with SPDX 2." + return 0 + elif [ ! -f "${spdx_file}" ]; then + bbwarn "improve_kernel_cve_report: SPDX file not found: ${spdx_file}. Skipping extra kernel vulnerabilities scoutings." + return 0 + elif [ ! -f "${original_cve_check_file}" ]; then + bbwarn "improve_kernel_cve_report: CVE_CHECK file not found: ${original_cve_check_file}. Skipping extra kernel vulnerabilities scouting." + return 0 + fi + + #Launch the new script to improve the cve report + python3 "${improve_kernel_cve_script}" \ + --spdx "${spdx_file}" \ + --old-cve-report "${original_cve_check_file}" \ + --new-cve-report "${new_cve_report_file}" \ + --datadir "${WORKDIR}/vulns" + bbplain "Improve CVE report with extra kernel cves: ${new_cve_report_file}" + + #Create a symlink as every other JSON file in tmp/deploy/images + ln -sf ${DEPLOY_DIR_IMAGE}/${IMAGE_NAME}.scouted.json ${DEPLOY_DIR_IMAGE}/${IMAGE_BASENAME}${IMAGE_MACHINE_SUFFIX}${IMAGE_NAME_SUFFIX}.scouted.json +} +do_scout_extra_kernel_vulns[nostamp] = "1" +do_scout_extra_kernel_vulns[doc] = "Scout extra kernel vulnerabilities and create a new enhanced version of the cve_check file in the deploy directory" +addtask scout_extra_kernel_vulns after do_create_image_sbom_spdx before do_build \ No newline at end of file From patchwork Fri Jan 16 19:05:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: ValentinBoudevin X-Patchwork-Id: 78968 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 017CBC982F6 for ; Fri, 16 Jan 2026 19:12:57 +0000 (UTC) Received: from mail-qt1-f193.google.com (mail-qt1-f193.google.com [209.85.160.193]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5021.1768590776223785141 for ; Fri, 16 Jan 2026 11:12:56 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20230601 header.b=b3Xx8zs2; spf=pass (domain: gmail.com, ip: 209.85.160.193, mailfrom: valentin.boudevin@gmail.com) Received: by mail-qt1-f193.google.com with SMTP id d75a77b69052e-5014501ba93so3385671cf.2 for ; Fri, 16 Jan 2026 11:12:56 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1768590775; x=1769195575; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=G3r4vCAmVb1yuth0uHEXvy90JjcKpbBBXHoapIEFApI=; b=b3Xx8zs2BvLwLpGKl2B/wgyV56i0zDYKQTfS4Xbo2ooetLW3TuPKTmwlNWwqfRyxc4 kkib5BoTNAmFm+hz+RpwZ0ZUCkkXyWMYo0rrKf0o3vINg0+9JTWMMmu7gxn+RTyZlS5y AZPuUrjDGisefU0NrK7mt8k5CLBU1ZnjC54SCMs8ihLTn8msoySSBsWkEPDiCJEoAbzH gR0jXOAfEsZCQp5uYNodF8y4vwL1PDnUl5WvRH5DMVmxkXVybMBCmDyRrxyR8jVwct4C SxeXDf42xY/3MiTohc8f9xdrtKjv4GF26Dgfc0Mq9EOzQdD3vqKAOI6za+xaUIe0Z6d+ k3OQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1768590775; x=1769195575; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=G3r4vCAmVb1yuth0uHEXvy90JjcKpbBBXHoapIEFApI=; b=PhxGLWd77DmyoI2X5jYtJwmcsXTVsqLd3zqzPHWMnY0sgiqiopxJlnDSH4mIwdrI49 J6qSPuPmLqM84+q4XBfGYZ8D9BiIeX8jNp0hcndY/EEiA2IxDFItOLSj1zN5CQWjDLFA 52BIH8Hg6KhkwcV/S6G3X55Z5ScbzBYTyOHGFMA1aKnhwcx+zK73irORatZup+cGA5n7 OCP1ErBUFyYMwdYSX7J/aEFdq1/x2NGuiFlb/a2qkVfbFGLxWn3cYLAq9QyIwU45S8NG jmPElT0ZG5LujCQ4cZU6GnotIT2njO6jIFBLcqa03OWEiakR2kJjTS1D3qSaC4RoqxjS nBng== X-Gm-Message-State: AOJu0YylfPu6HRAFBOZQcqtXRW5N+ktp72senLiDNdcSJs/oWN6P8aqS VprXo5LHfQt+75egALVwPmZiHx1+csUQeGdQ6l66NyJDSWWcz8zgA6A7BCofOho6Iak2OQ== X-Gm-Gg: AY/fxX4LotuImotSWFGehnBr9WWg6RCBhAZNzgHNGeSwp3SeE3T3BKhWLWxRv+i8b8r RDaWUylORciSDylR5hI+IMhuepNiGJU8zlijCNZcGABhcOXPnVqkKCxymgePofWUpGAjtQa02KG 9dUqn8fCGyJ3PqZv1xqF5GwmxfJ3zf/HTEohOijh78SaMrSZZoNEK98OeBpd57V4jY7fxnQoh1Z g/4XTL7AOZgFdk3QNidkbyA6yOqITvGkY74vdD60ju70rm3mZN+QlNQo0zTfHWcURVhennhvN0B vEcPrwzkicC6Np4WtmOzpwx70OO/xXF4GjhTDZyHE1xdRlqIXGI+sx+aIzJqvd1UcmK4/3+6vaE jUxLuWZeTvP5OkIYCWtER+rTTLTBvZnXzfbnCjxERN56ND/IV/gyYu6Ie3KGMdSA671KdLOC7F8 B/wFPXGaFFwIhvKRw3OSoUP82+/bK3UAjUldXufjtcPSFqZy50i6Tmi4E= X-Received: by 2002:ac8:7fc3:0:b0:4ec:f9c2:c200 with SMTP id d75a77b69052e-502a1735f4fmr49166441cf.11.1768590775087; Fri, 16 Jan 2026 11:12:55 -0800 (PST) Received: from vboudevin-pc.mtl.sfl (mtl.savoirfairelinux.net. [208.88.110.46]) by smtp.gmail.com with ESMTPSA id af79cd13be357-8c6a71bf2b0sm287446685a.12.2026.01.16.11.12.54 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 16 Jan 2026 11:12:54 -0800 (PST) From: ValentinBoudevin To: openembedded-core@lists.openembedded.org Cc: daniel.turull@ericsson.com, jerome.oufella@savoirfairelinux.com, antonin.godard@bootlin.com, ValentinBoudevin Subject: [PATCH v5 2/4] generate-cve-exclusions: Add a .bbclass Date: Fri, 16 Jan 2026 14:05:18 -0500 Message-ID: <20260116190520.118714-4-valentin.boudevin@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260116190520.118714-1-valentin.boudevin@gmail.com> References: <188AFCD98EA3E578.3200434@lists.openembedded.org> <20260116190520.118714-1-valentin.boudevin@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 16 Jan 2026 19:12:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/229560 Add a new class named kernel-generate-cve-exclusions.bbclass to generate-cve-exclusions to use this script at every run. Two steps for testing: 1) Inherit this class in the kernel recipe with "inherit kernel-generate-cve-exclusions.bbclass" 2) Turn the variable ENABLE_KERNEL_CVE_EXCLUSIONS to "1". 3) Use the following command to generate a cvelistV5 entry with a JSON file in in ${WORKDIR}/cvelistV5/ : "bitbake linux-yocto -c generate-cve-exclusions" The JSON file can then be parsed in the following run by cve-check. This class contains several methods: *do_clone_cvelistV5: Clone the cvelistV5 repo in ${WORKDIR}/cvelistV5/git (e.g. bitbake-builds/poky-master/build/tmp/work/qemux86_64-poky-linux/ linux-yocto/6.18.1+git/cvelistV5/git) *do_generate_cve_exclusions: Use the script generate-cve-exclusions.py. It uses the new "--output-json" argument to generate a JSON file as an output stored in ${WORKDIR}/cvelistV5//cve-exclusion_${LINUX_VERSION}.json *do_cve_check:prepend: Parse the previously generated JSON file to set the variable CVE_STATUS corretly The class also provides some variables: *ENABLE_KERNEL_CVE_EXCLUSIONS: Enable/Disable this class (off by default to not affect linux-yocto OE example) *GENERATE_CVE_EXCLUSIONS_SRC_URI and GENERATE_CVE_EXCLUSIONS_SRCREV can be used to change the source repository or fix a commit with SRCREV (usefull for deterministic testing) *GENERATE_CVE_EXCLUSIONS_NETWORK can be set to 0 to provide an offline mode based on DL_DIR directory. *GENERATE_CVE_EXCLUSIONS_WORKDIR path used as a working directory for this class *GENERATE_CVE_EXCLUSIONS_DESTSUFFIX suffix used for the git unpack *GENERATE_CVE_EXCLUSIONS_UNPACK_DIR path of the unpack for the git repository Signed-off-by: Valentin Boudevin --- .../kernel-generate-cve-exclusions.bbclass | 135 ++++++++++++++++++ 1 file changed, 135 insertions(+) create mode 100644 meta/classes/kernel-generate-cve-exclusions.bbclass diff --git a/meta/classes/kernel-generate-cve-exclusions.bbclass b/meta/classes/kernel-generate-cve-exclusions.bbclass new file mode 100644 index 0000000000..cd81cc5899 --- /dev/null +++ b/meta/classes/kernel-generate-cve-exclusions.bbclass @@ -0,0 +1,135 @@ +# Generate CVE exclusions for the kernel build (set to "1" to enable) +ENABLE_KERNEL_CVE_EXCLUSIONS ?= "0" + +# CVE exclusions source repository settings +GENERATE_CVE_EXCLUSIONS_SRC_URI ?= "git://github.com/CVEProject/cvelistV5.git;branch=main;protocol=https" +GENERATE_CVE_EXCLUSIONS_SRCREV ?= "${@bb.fetch2.get_autorev(d)}" +GENERATE_CVE_EXCLUSIONS_NETWORK ?= "1" +GENERATE_CVE_EXCLUSIONS_WORKDIR ?= "${WORKDIR}/cvelistV5" +GENERATE_CVE_EXCLUSIONS_DESTSUFFIX ?= "git" +GENERATE_CVE_EXCLUSIONS_UNPACK_DIR ?= "${GENERATE_CVE_EXCLUSIONS_WORKDIR}/${GENERATE_CVE_EXCLUSIONS_DESTSUFFIX}" + +python __anonymous() { + # Only run if CVE exclusions are enabled + if d.getVar("ENABLE_KERNEL_CVE_EXCLUSIONS", True) == "1": + srcrev = d.getVar("GENERATE_CVE_EXCLUSIONS_SRCREV", True) or "" + network = d.getVar("GENERATE_CVE_EXCLUSIONS_NETWORK", True) or "0" + # Check offline mode with AUTOREV-like SRCREV + if network == "0" and srcrev.strip() in ("${AUTOREV}", "AUTOINC", "INVALID"): + bb.fatal("generate-cve-exclusions: Offline mode but SRCREV is set to AUTOREV/AUTOINC/INVALID. " + "Cannot proceed without network access or use a fixed SRCREV.") + d.appendVar("SRC_URI", " ${GENERATE_CVE_EXCLUSIONS_SRC_URI};name=generate-cve-exclusions;destsuffix=${GENERATE_CVE_EXCLUSIONS_DESTSUFFIX}") + d.setVar("SRCREV_generate-cve-exclusions", d.getVar("GENERATE_CVE_EXCLUSIONS_SRCREV")) +} + +python do_clone_cvelistV5() { + import subprocess + import shutil, os + # Only run if CVE exclusions are enabled + if not d.getVar("ENABLE_KERNEL_CVE_EXCLUSIONS") == "1": + return + network_allowed = d.getVar("GENERATE_CVE_EXCLUSIONS_NETWORK") == "1" + workdir = d.getVar("GENERATE_CVE_EXCLUSIONS_WORKDIR") + unpack_dir = d.getVar("GENERATE_CVE_EXCLUSIONS_UNPACK_DIR") + # Remove existing unpacked directory if any + if os.path.exists(workdir): + shutil.rmtree(workdir) + # Prepare fetcher + src_uri_list = (d.getVar('SRC_URI') or "").split() + cve_uris = [] + for uri in src_uri_list: + if "name=generate-cve-exclusions" in uri: + cve_uris.append(uri) + if not cve_uris: + bb.note("No CVE exclusions SRC_URI found, skipping fetch") + return + fetcher = bb.fetch2.Fetch(cve_uris, d) + # Clone only if network is allowed + if network_allowed: + fetcher.download() + else: + # Offline mode without network access + bb.note("GENERATE_CVE_EXCLUSIONS_NETWORK=0: Skipping online fetch. Checking local downloads in DL_DIR...") + have_sources = False + dl_dir = d.getVar("DL_DIR") + srcrev = d.getVar("SRCREV_generate-cve-exclusions") + bb.note(f"Checking for sources for SRCREV: {srcrev}") + # Check SRCREV is NOT set to AUTOREV + if srcrev.strip() in ("${AUTOREV}", "AUTOINC", "INVALID"): + bb.fatal("generate-cve-exclusions: Offline mode but SRCREV is set to AUTOREV/AUTOINC/INVALID. Cannot proceed without network access or use a fixed SRCREV.") + return + # Loop through the fetcher's expanded URL data + for ud in fetcher.expanded_urldata(): + ud.setup_localpath(d) + # Check mirror tarballs first + for mirror_fname in ud.mirrortarballs: + mirror_path = os.path.join(dl_dir, mirror_fname) + if os.path.exists(mirror_path): + bb.note(f"Found mirror tarball: {mirror_path}") + have_sources = True + break + # If no mirror, check original download path + if not have_sources and ud.localpath and os.path.exists(ud.localpath): + bb.note(f"Found local download: {ud.localpath}") + have_sources = True + if not have_sources: + bb.fatal("generate-cve-exclusions: Offline mode but required source is missing.\n"f"SRC_URI = {ud.url}") + return + # Unpack into the standard work directory + fetcher.unpack(unpack_dir) + # Remove the folder ${PN} set by unpack + subdirs = [d for d in os.listdir(unpack_dir) if os.path.isdir(os.path.join(unpack_dir, d))] + if len(subdirs) == 1: + srcdir = os.path.join(unpack_dir, subdirs[0]) + for f in os.listdir(srcdir): + shutil.move(os.path.join(srcdir, f), unpack_dir) + shutil.rmtree(srcdir) + bb.note("Vulnerabilities repo unpacked into: %s" % unpack_dir) +} +do_clone_cvelistV5[network] = "${GENERATE_CVE_EXCLUSIONS_NETWORK}" +do_clone_cvelistV5[nostamp] = "1" +do_clone_cvelistV5[doc] = "Clone CVE information from the CVE Project: https://github.com/CVEProject/cvelistV5.git" +addtask clone_cvelistV5 before do_generate_cve_exclusions + +do_generate_cve_exclusions() { + # Only run if CVE exclusions are enabled + if [ "${ENABLE_KERNEL_CVE_EXCLUSIONS}" != "1" ]; then + return 0 + fi + generate_cve_exclusions_script=${COREBASE}/scripts/contrib/generate-cve-exclusions.py + if [ ! -f "${generate_cve_exclusions_script}" ]; then + bbwarn "generate-cve-exclusions.py not found in ${COREBASE}." + return 0 + fi + if [ ! -d "${GENERATE_CVE_EXCLUSIONS_UNPACK_DIR}" ]; then + bbwarn "CVE exclusions source directory not found in ${GENERATE_CVE_EXCLUSIONS_UNPACK_DIR}." + return 0 + fi + python3 "${generate_cve_exclusions_script}" \ + "${GENERATE_CVE_EXCLUSIONS_UNPACK_DIR}" \ + ${LINUX_VERSION} \ + --output-json > ${GENERATE_CVE_EXCLUSIONS_WORKDIR}/cve-exclusion_${LINUX_VERSION}.json + bbplain "CVE exclusions generated for kernel version ${LINUX_VERSION} at ${GENERATE_CVE_EXCLUSIONS_WORKDIR}/cve-exclusion_${LINUX_VERSION}.json." +} +do_generate_cve_exclusions[nostamp] = "1" +do_generate_cve_exclusions[doc] = "Generate CVE exclusions for the kernel build. (e.g., cve-exclusion_6.12.inc)" +addtask generate_cve_exclusions after do_clone_cvelistV5 before do_cve_check + +python do_cve_check:prepend() { + import os + import json + workdir = d.getVar("GENERATE_CVE_EXCLUSIONS_WORKDIR") + kernel_version = d.getVar("LINUX_VERSION") + json_input_file = os.path.join(workdir, "cve-exclusion_%s.json" % kernel_version) + if os.path.exists(json_input_file): + with open(json_input_file, 'r', encoding='utf-8') as f: + cve_data = json.load(f) + cve_status_dict = cve_data.get("cve_status", {}) + count = 0 + for cve_id, info in cve_status_dict.items(): + if info.get("active", True): + continue + d.setVarFlag("CVE_STATUS", cve_id, info.get("message", "")) + count += 1 + bb.note("Loaded %d CVE_STATUS entries from JSON output for kernel %s" % (count, kernel_version)) +} \ No newline at end of file From patchwork Fri Jan 16 19:05:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: ValentinBoudevin X-Patchwork-Id: 78970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 08A58C982F7 for ; Fri, 16 Jan 2026 19:13:07 +0000 (UTC) Received: from mail-qt1-f172.google.com (mail-qt1-f172.google.com [209.85.160.172]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.5023.1768590777573358065 for ; Fri, 16 Jan 2026 11:12:57 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20230601 header.b=aqXpDdWR; spf=pass (domain: gmail.com, ip: 209.85.160.172, mailfrom: valentin.boudevin@gmail.com) Received: by mail-qt1-f172.google.com with SMTP id d75a77b69052e-502a7f20dd2so1436511cf.1 for ; Fri, 16 Jan 2026 11:12:57 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1768590776; x=1769195576; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=zjxYzvvWf4Cu4hPx/VkxvgapdI94Oxv2FhCFriptyZY=; b=aqXpDdWRPO5K9sXbWzrv5bWc00Rgmxx2j9TfLb7MaNrBn1mkNmTbMtlrUPK+9kKT+8 d9hxjeCr0fssNiS0s77A1NTHG0E5NrGrVypPT3Cq2k/PJH/PWirzeHak3cnNXrOnmHhr zTCIygec/BL7DVaVKQV+rEKR372AXFrL5xT5AVuTDRbs9gOrBgKkDaCQnk+r6ZcfE9BF D8tfjecJyDAKKp33G946fRyGyGP8xKsxVCUs2DhQD/Vx+OVpSspTelUTkMv/QiwAyeKP Gy9Zc662EDmTl29tIzxKCmVUo9BEtDIdwCvPrQtsJTOE+lFksZAroEhqvUEcbW2XWx3t VkLQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1768590776; x=1769195576; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=zjxYzvvWf4Cu4hPx/VkxvgapdI94Oxv2FhCFriptyZY=; b=nKDnfRQcrk6nE8dMj8QZ1N3hYOFLPHeWjCRaTzHjRYg7ZI5CVBcUvh68TduuM6HPkZ F7HKpeGdnhlN7EPO6Z0TvPnfeCo5W+bUd6A6nn9Oo8d8Eg+Xm9Bcs2S9NStGpwjFMi9O MV37Gn7Ww/2RYvYf/KAx9IOJYSsS84QjO8ZrjpEzKa3+0SITDjfBLpuKTQ40wyNCHrBU SD+8uecJZJKE20p23gRVrbq19BbkVHTDT1htSdRKbQjm3fqAWaOVW7w71WaKUS0VcPSR NrCX7iMXuRAsP6d1SZMAQliwElORYlmrw6CVe/LQeFccmgmaqTe5LNzRNXI91GSuThL2 RZRQ== X-Gm-Message-State: AOJu0YyKrXTjk6exwYKwddlb5BFbWg6k10JSwRHSbs1IAPncxqNvmHWM cSCL6FFzq+YQUIghqWvrqWEfKtC5BFsm53+xgrVjbB60icMtTqboDzA3u7vzut9ffLQ= X-Gm-Gg: AY/fxX5/qib3Z8HjKhwqsynhGOO+5eMDj4xU6zPBUiv4Ztl2IMFnFi9/P7bB5uUlKjZ TbDNfPQnnpGOZmgF/nV124UPLWqcZrZeRgJyKVjl3sJRHgDqs50FUCKdBJr+eXBi5VcDMK8qrBv Q3lT6CeURm//TDcDiEvPH6aV7EyzvtYvbOszjtm8oMgYvrUGFJSwcUBW/8CVoI7rRBeb2DraCe2 vYnM30CbxoWFlR0Q9BnrgioDKFb+7cPq553Bl6ekkbCSnyeOOf/k1NNFUvqVEIKwuCgirwbn4se UAUzWPM7ETXTwfz5pqRVCFuqGZiYbUblr+mxB2/VraR6oQzzsYm+OHWQr+T+GvxAuE/SHC6Fv1n R2jLHzYVIEKDYhCq2Muyfnt0/XO0VD9/l6eUab4UQQpFaYNo3ZjwB1rjh8dhl+SM92lDOye03DI aidvya8iLabr1pmkR4E5Hu49RlPQivuE11D9MaC9iESnP5Bwll5pjo/bU= X-Received: by 2002:a05:620a:1a1e:b0:8c0:cec5:148c with SMTP id af79cd13be357-8c6a67d8224mr396474085a.11.1768590776533; Fri, 16 Jan 2026 11:12:56 -0800 (PST) Received: from vboudevin-pc.mtl.sfl (mtl.savoirfairelinux.net. [208.88.110.46]) by smtp.gmail.com with ESMTPSA id af79cd13be357-8c6a71bf2b0sm287446685a.12.2026.01.16.11.12.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 16 Jan 2026 11:12:56 -0800 (PST) From: ValentinBoudevin To: openembedded-core@lists.openembedded.org Cc: daniel.turull@ericsson.com, jerome.oufella@savoirfairelinux.com, antonin.godard@bootlin.com, ValentinBoudevin Subject: [PATCH v5 3/4] generate-cve-exclusions: Move python script Date: Fri, 16 Jan 2026 14:05:19 -0500 Message-ID: <20260116190520.118714-5-valentin.boudevin@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260116190520.118714-1-valentin.boudevin@gmail.com> References: <188AFCD98EA3E578.3200434@lists.openembedded.org> <20260116190520.118714-1-valentin.boudevin@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 16 Jan 2026 19:13:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/229561 The script should be located with other scripts in scripts/contrib instead of staying in meta/classes/. Update the new .bbclass to match this modification Signed-off-by: Valentin Boudevin --- .../linux => scripts/contrib}/generate-cve-exclusions.py | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename {meta/recipes-kernel/linux => scripts/contrib}/generate-cve-exclusions.py (100%) diff --git a/meta/recipes-kernel/linux/generate-cve-exclusions.py b/scripts/contrib/generate-cve-exclusions.py similarity index 100% rename from meta/recipes-kernel/linux/generate-cve-exclusions.py rename to scripts/contrib/generate-cve-exclusions.py From patchwork Fri Jan 16 19:05:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: ValentinBoudevin X-Patchwork-Id: 78971 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 093CFC982F8 for ; Fri, 16 Jan 2026 19:13:17 +0000 (UTC) Received: from mail-qk1-f179.google.com (mail-qk1-f179.google.com [209.85.222.179]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.5257.1768590788867432055 for ; Fri, 16 Jan 2026 11:13:09 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20230601 header.b=Z+Z5uAEr; spf=pass (domain: gmail.com, ip: 209.85.222.179, mailfrom: valentin.boudevin@gmail.com) Received: by mail-qk1-f179.google.com with SMTP id af79cd13be357-8c532f0c317so45012985a.1 for ; Fri, 16 Jan 2026 11:13:08 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1768590788; x=1769195588; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=rJztdStxg7wwAM3hZuMHgzV4ybGDlyVuhYYNDMUfcBs=; b=Z+Z5uAEruDHkmI1eSrxDrIyP+rJ/K6LsGdcS+ywmQafxdwR8cYg36bvl8gaW2FWXFD oqZcoBToNePrB3y0rZpTp7UPY99ywHmLo+MWUPKN9zdl/onBT4IJH9n6uqLN9fMuLpUw T+66CzInDWZOLuQKKivIQ+vXfqbBusHkUP5SQccQFeEs9UCOrbp39Spv5EPAwPnRQXnx R4FJi2ykuOMe9ohJWcadSe2YvEEJlTZ0VOkcPAuNuXJfajVHII3cHbaaUHkQ02t9Wrx/ /KutHB6uNNYAmky4e4WprlQJKxyfpXuqoQGiaEH7G6wr5EKbgk7T6z1+2HqOnv+jpIxO p+0g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1768590788; x=1769195588; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=rJztdStxg7wwAM3hZuMHgzV4ybGDlyVuhYYNDMUfcBs=; b=WFmlpV95J1gO754dRpP3FVH98Ops/tPiXo3YU/mdxJykR9zGqbt5K4cqwxAvihU687 hI2WX8ENAzg6FRAFfDJ0H83UjkbukShKDmVSPY9J2/OIlUidB7543J30Y6AGZm4wJ4vX nZnwG5hQeC/U2eNcmvCOr6g6Rz86W3jr7YG66SykomNz6FF/97z5erMcuql3+z5YZkZy Dcb8h6xhO+ko3xlh9lP3mItD5K3zAiSqifbGaLMn2/33soSX1l4kh2fGxvQzz+7HV/CQ +P+x1NRGQ0eMOhqzhNUgNDKvbEfAPfCtgVlz2llFz07TfzNRsz4sm/+TiahL1F0j+udX TGRg== X-Gm-Message-State: AOJu0YzVX96Cu/v0FBZ+cv6/8gdfbIEYnsuzmf0LERc2VC6iJ/spbnBq s4klupL+X9rCCADY2PX0rhSXmi9DHZQfAsOLQCJWzdwnukwbPfnGPlNBWlwOiglHi8U= X-Gm-Gg: AY/fxX4C1+i2+KCwCqP1le6LoSbUlBTyIvnrFJVqxKtvAOx3X4cEY0TLE76jAgX6tNj eNgLaQhLwmanzRVmi03sSUe94JSw76iqourPz2pCArKO2EokuhbAaShtQTxipKEbmQzoz+sdFZ9 jM0vF498nPfw4cMc6bDlDhwH/Njz6ftvQ4pYiV7XCUkWvRt9KLl75X6AqiVb9J2m/A0ZEEg/3IV vWAudsSu8aREpyf81oftAUJDKPKGnhFjOfIkg0k3d0rwM2HQBLtvCwCVgKXdAWxuh5DF2ZgWu0O Hv5W74xBXgPYfIk/xzWVXcrkEaLnL+6Gc0o5c7wjGfdmqMGZzZV843o3VwFt7g2PT1yJPFUZCk1 8ibl9YSearbF5pYg0X01vRwNiP9+kEkenYC0+tngFuser/F7oZyD4h6yLMXpgpFdweiVidozJIU MpLE2CdX9JPoNuWn+QVqr6aZIIN61hnNbXACcZUkPa6OTpIN2bEyuGseM= X-Received: by 2002:a05:620a:a215:b0:8c6:a719:d16f with SMTP id af79cd13be357-8c6a719d1a9mr372317085a.4.1768590787691; Fri, 16 Jan 2026 11:13:07 -0800 (PST) Received: from vboudevin-pc.mtl.sfl (mtl.savoirfairelinux.net. [208.88.110.46]) by smtp.gmail.com with ESMTPSA id af79cd13be357-8c6a71bf2b0sm287446685a.12.2026.01.16.11.13.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 16 Jan 2026 11:13:07 -0800 (PST) From: ValentinBoudevin To: openembedded-core@lists.openembedded.org Cc: daniel.turull@ericsson.com, jerome.oufella@savoirfairelinux.com, antonin.godard@bootlin.com, ValentinBoudevin Subject: [PATCH v5 4/4] linux: Add inherit on generate-cve-exclusions Date: Fri, 16 Jan 2026 14:05:20 -0500 Message-ID: <20260116190520.118714-6-valentin.boudevin@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260116190520.118714-1-valentin.boudevin@gmail.com> References: <188AFCD98EA3E578.3200434@lists.openembedded.org> <20260116190520.118714-1-valentin.boudevin@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Fri, 16 Jan 2026 19:13:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-core/message/229562 Update linux-yocto.inc to inherit the new kernel-generate-cve-exclusions class. Signed-off-by: Valentin Boudevin --- meta/recipes-kernel/linux/linux-yocto.inc | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta/recipes-kernel/linux/linux-yocto.inc b/meta/recipes-kernel/linux/linux-yocto.inc index 4d0a726bb6..d627afa3a5 100644 --- a/meta/recipes-kernel/linux/linux-yocto.inc +++ b/meta/recipes-kernel/linux/linux-yocto.inc @@ -5,6 +5,9 @@ HOMEPAGE = "https://www.yoctoproject.org/" LIC_FILES_CHKSUM ?= "file://COPYING;md5=d7810fab7487fb0aad327b76f1be7cd7" +# Generate Dynamic CVE Exclusions +inherit kernel-generate-cve-exclusions + UPSTREAM_CHECK_GITTAGREGEX = "(?P\d+\.\d+(\.\d+)*)" RECIPE_NO_UPDATE_REASON = "Recipe is updated through a separate process"