From patchwork Wed Aug 26 20:57:35 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96484 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 687A1C61DC6 for ; Wed, 26 Aug 2026 20:58:53 +0000 (UTC) Received: from mail-qv1-f47.google.com (mail-qv1-f47.google.com [209.85.219.47]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.22624.1787777925570356585 for ; Wed, 26 Aug 2026 13:58:45 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=Jbr6wrs6; spf=pass (domain: konsulko.com, ip: 209.85.219.47, mailfrom: scott.murray@konsulko.com) Received: by mail-qv1-f47.google.com with SMTP id 6a1803df08f44-8eeadbc5e21so8649596d6.3 for ; Wed, 26 Aug 2026 13:58:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777924; x=1788382724; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=r/WtVM/JK/oVq31hslkMIBTM/smJnS9JZn7b3/qPMiA=; b=Jbr6wrs6LEqZxwA6YR0hxMOcyo5y8Q7arWuzeQl3PCgmyEzaMwWubkW3wGVO7qOWzT vjR2xFqni8v4fiYLKZvWoiDtR6g/a3xJoeGyv6w6645O7KPTCHtZT5bSOA/0VMxFD2jt 7P3GO7UCsZmGHDyNpy8lJdw9GdrwFd5By2xug= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777924; x=1788382724; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=r/WtVM/JK/oVq31hslkMIBTM/smJnS9JZn7b3/qPMiA=; b=eqj+8gmuCbgYCRXAKhtmbq7jvYwD07oHqXDe6fuD1nHhnhbr3XyKlYTVP3rP6MqBCo EhrTZimvMZQKTfVxxMtIT4jxZXMilS9/msSPMb9A/2XIpu2RFbpQK+iAxBxM12qaCjqZ 4Jzc4FkEM9+gUlYZLm9RFom9J5h8E8oAwv3PCi6Ink6oENnWHIGHClUjh3+XkMWmocgR xfIG+6hVW/L9Biygr0bSn1hwS91QBMlbDVGTAIokJVJerMXDak2AkCOQCT//PJqE0R+W thnzc1Xq/+GU7e1FUPEj3J9I/k2qECsuIXrWjCIYYp5MNcUwzzGhHxWOHIxIu/Cn3KnL jnkg== X-Gm-Message-State: AFuF++nKdM6gRKsU0EH4bFCAI2KpnYAuTLyB5E40PrWZ49yYte34/5tL aSVIcDnxnEf3IjcXsSeEhxHypjpTmDMidyitUyVbMwNPjtML4nKWJa1R4Y1H5yfEgHDcF3KM0eN Xd/PX X-Gm-Gg: AR+sD11YC8lG2kH+JH/G9QEZBduPPB0pZSd+pMxm6jqgBMS/Pvrb8+Q+1xmUH727q+L NuqCn5iXFxlmUhnuh6LBlwuAy0xgIBmt66MzYis1vRm9fKc6DzMF7bEEylvbm9dt+iubGc8Auxf 1794XYSXAaKERQmsQBHYua9tMMQTt7If2wRNqPdANqMS8iQgUZxiqBicUhJTna+b866eqG1Dkb8 T5ACT4rSl8KiK0VrILH5wZCSfFV+VprEO/uAoW05OmB6Pz8A4pCfDzZZloe5NMMmU9JVAKh5L4U qqKU3sw7WcdSEgmkUi5AtKaJ8wIY6PtDmYlXJbHMUWm2a/cEV6TahYIrLbRmOIcIzKItk5E7zF8 EDCI+dU6iN0XHFHNsvP6+DVVKu7kec7loTnpItRnEj59KjnV4XC89GYKQF3H1/OnfH9pUs3AIBK 8G4sqdTwBGPY7X0W7rVC3olYGaTssXggR6sQfqj28r7W5nST5WpWusM3bpnl1hWmyeONfFWmDum oXC2lGfdtEE6ZHYExOwcW+3czsqgl9Dd01AOGqK02XESsrhIDn94+ZdRd/g1y/Axs/jf7mWdxDs FZuLV404jthxpPlnnK85hiZMcg== X-Received: by 2002:ad4:5f0c:0:b0:90c:5a71:f857 with SMTP id 6a1803df08f44-90cc79af7ecmr106082636d6.14.1787777924182; Wed, 26 Aug 2026 13:58:44 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.43 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:43 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 01/15] aide: Fix compilation with nettle 4.x Date: Wed, 26 Aug 2026 16:57:35 -0400 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:58:53 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4693 Backport unreleased change from upstream to handle building with nettle 4.x now that openembedded-core has upgraded to it. Signed-off-by: Scott Murray --- .../0002-Support-build-with-nettle-4.patch | 53 +++++++++++++++++++ recipes-ids/aide/aide_0.19.3.bb | 1 + 2 files changed, 54 insertions(+) create mode 100644 recipes-ids/aide/aide/0002-Support-build-with-nettle-4.patch diff --git a/recipes-ids/aide/aide/0002-Support-build-with-nettle-4.patch b/recipes-ids/aide/aide/0002-Support-build-with-nettle-4.patch new file mode 100644 index 0000000..d9c6fad --- /dev/null +++ b/recipes-ids/aide/aide/0002-Support-build-with-nettle-4.patch @@ -0,0 +1,53 @@ +From 84936cec8ddb7151327563800d752d1d20e39224 Mon Sep 17 00:00:00 2001 +From: Hannes von Haugwitz +Date: Tue, 26 May 2026 21:41:52 +0200 +Subject: [PATCH] Support build with nettle 4 + +* closes: #218 + +Upstream-Status: Backport [https://github.com/aide/aide/commit/61130addb02a58d7de95d6b8f344ab9b6151d6aa] +Signed-off-by: Scott Murray +--- + ChangeLog | 3 +++ + src/md.c | 6 ++++++ + 2 files changed, 9 insertions(+) + +diff --git a/ChangeLog b/ChangeLog +index 89905e3..5b3963e 100644 +--- a/ChangeLog ++++ b/ChangeLog +@@ -1,3 +1,6 @@ ++2026-05-26 Hannes von Haugwitz ++ * Support build with nettle 4 (closes: #218) ++ + 2026-01-31 Hannes von Haugwitz + * Release aide 0.19.3 + +diff --git a/src/md.c b/src/md.c +index e4e66ad..1aec9d9 100644 +--- a/src/md.c ++++ b/src/md.c +@@ -47,6 +47,8 @@ + #include + #include + ++#include ++ + typedef struct { + nettle_hash_init_func *init; + nettle_hash_update_func *update; +@@ -166,7 +168,11 @@ int close_md(struct md_container* md, md_hashsums * hs, const char *filename, co + for (HASHSUM i = 0 ; i < num_hashes ; ++i) { + DB_ATTR_TYPE h = ATTR(hashsums[i].attribute); + if (h&md->calc_attr) { ++#if NETTLE_VERSION_MAJOR < 4 + nettle_functions[i].digest(&md->ctx[i].md5, hashsums[i].length, hs->hashsums[i]); ++#else ++ nettle_functions[i].digest(&md->ctx[i].md5, hs->hashsums[i]); ++#endif + } + } + #endif +-- +2.47.3 + diff --git a/recipes-ids/aide/aide_0.19.3.bb b/recipes-ids/aide/aide_0.19.3.bb index 68e3bfa..8d4efbb 100644 --- a/recipes-ids/aide/aide_0.19.3.bb +++ b/recipes-ids/aide/aide_0.19.3.bb @@ -7,6 +7,7 @@ DEPENDS = "bison-native libpcre2" SRC_URI = "https://github.com/aide/aide/releases/download/v${PV}/${BPN}-${PV}.tar.gz \ file://0001-Fixes-build-issues.patch \ + file://0002-Support-build-with-nettle-4.patch \ file://aide.conf \ " From patchwork Wed Aug 26 20:57:36 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96487 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 77D0FC61DCD for ; Wed, 26 Aug 2026 20:58:53 +0000 (UTC) Received: from mail-qk1-f177.google.com (mail-qk1-f177.google.com [209.85.222.177]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.22625.1787777926411811081 for ; Wed, 26 Aug 2026 13:58:46 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=FqaHBFjC; spf=pass (domain: konsulko.com, ip: 209.85.222.177, mailfrom: scott.murray@konsulko.com) Received: by mail-qk1-f177.google.com with SMTP id af79cd13be357-936cda0e3fbso105319285a.3 for ; Wed, 26 Aug 2026 13:58:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777925; x=1788382725; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=V89ZoqbV/9M7Aiv0Mcy7UNb/UquGwm9FfQy8p3qeYWg=; b=FqaHBFjCrxYkUdpBxbUotS6w8sH0DNOSyl3qJfdO3N2obYp4G4iFJvUEB7kR6b5yft wvzdJmXmfyb484qgZFhEPMU5RgWucXVAo7Ln9TEeB1yPiCCms5PmggkyaiONTGJfy5fO qcenVq3gRk1Ujxh9qrK2BqBbhmU4jJdIOQVfI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777925; x=1788382725; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=V89ZoqbV/9M7Aiv0Mcy7UNb/UquGwm9FfQy8p3qeYWg=; b=Judg2tzC1GlqAws3f03iiqubpsZfSWl41JxEFv97Uo8TPzk1rIs0yAVlQhva2zoCoz KsF22orUlIk3Se4SuZkaoBFqW8PmG2xbcgxu3geExA6oYkZdwDzGck2UYKlLQAxYWOj9 eMfTAvf0k84bZjJnii2n6SlVqsxBiMRLR3PDd9jmRGXERadIT3XGw80T6BZ6Xy1EPMdk WxvEsDP8yBrnkG/TIOsqPi9VeSSe1JUr5fx0DZd2b4N4RsszOxKlNS39zFZ5VbusaITv GP7psYT+zLjSrbHZAPl6JcBbf78GCmMnNg2k/XpiaJwRNhHTtjoeVbGclKFUcYaZtmDp ZxuA== X-Gm-Message-State: AFuF++l4seqYqdoAl+LmblRLwDH9RmtlXEJV9/H8gDzufdormg1k7AO3 a6v+Zz7MHNGP5ukBgUmpT5TxxJbGYsP9fz2bBVU9qaLcOU2xb9cjjkvO81A4hLeFvE0kXEC6xyL QIale X-Gm-Gg: AR+sD10fG8sxsnqNDFIJhJroJl8pM+dGA3svyOh2Qmra6ckEHoLi7IL2mHP+NhT2SPZ QMrlXZ8nf4B4o8ePa4bz3KZAbIJnUtzoEuheCsvEQaJHsnaQGHB3s/NGDjV87mQE6cyZtRLjNU4 clADZ1e7D3oR9T2rUTbEQO7lqkRILojXSm9cPBiGLyiofquhWMBY/SAo35Dvb5ZFUWwnkyJHJc9 rY8XAVzkSZ2wamzvIy/cxE8KafHkBKZFFtXxpExc/V0dhMsJofaD9t4/LYx4qf1P7sbVMM1Oq/U So/EkPjrwZrKieMYL3JOos9lQXHDnPa/axShrjqxscF0IldwTtzB5EI+lCzGFYnxNfAEFLzH5ZC 1y+KWPjQ0zRz45VZ//53aKY9w5MOvu9ZgGjWyU8AzAjRC+QhYykngcD41eHHhWfm5UABsxbX6RM 2yPXCXjaYdnE46zsHO/WdDazdeyc7n93mrRqQHuldkgG18tyei1himzWBMMZk1QrVetNhY9Tubr FbvmaZ0FKbDiGlgLzORPcqDC09s47BpAvk2P9urlyDJKkFtgbdpZxzJykTmPWHgY5ZcSJzckCr9 csS7/tJHnYsK7R/ODe2iF9HxuQ== X-Received: by 2002:ae9:c213:0:b0:92e:5b92:98bb with SMTP id af79cd13be357-9378016e8d7mr863071285a.14.1787777924952; Wed, 26 Aug 2026 13:58:44 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.44 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:44 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 02/15] suricata: handle oe_cargo_build removal Date: Wed, 26 Aug 2026 16:57:36 -0400 Message-ID: <74e55cf4fb2e4a6f58a487ede7d4fe39d6101448.1787777775.git.scott.murray@konsulko.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:58:53 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4694 Handle upstream removal of oe_cargo_build function in oe-core commit a64ac03a61 by renaming our local override to cargo_do_compile to get the same effect. Signed-off-by: Scott Murray --- recipes-ids/suricata/suricata_8.0.4.bb | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/recipes-ids/suricata/suricata_8.0.4.bb b/recipes-ids/suricata/suricata_8.0.4.bb index b3ab261..5ae0d97 100644 --- a/recipes-ids/suricata/suricata_8.0.4.bb +++ b/recipes-ids/suricata/suricata_8.0.4.bb @@ -86,12 +86,17 @@ CFLAGS += "-Wno-error=incompatible-pointer-types \ # breaks building this recipe. Providing a copy of the original function # Armin 2025/04/01 # -oe_cargo_build () { +# 08/2026 note - oe_cargo_build function inlined into cargo_do_compile +# upstream in openembedded-core commit a64ac03a61, handle by renaming +# our forked function to cargo_do_compile to override it directly. +# This still works since before a64ac03a61 cargo_do_compile did nothing +# but call oe_cargo_build. +cargo_do_compile () { export RUSTFLAGS="${RUSTFLAGS}" bbnote "Using rust targets from ${RUST_TARGET_PATH}" bbnote "cargo = $(which ${CARGO})" - bbnote "${CARGO} build ${CARGO_BUILD_FLAGS}$@" - "${CARGO}" build ${CARGO_BUILD_FLAGS}"$@" + bbnote "${CARGO} build ${CARGO_BUILD_FLAGS} $@" + "${CARGO}" build ${CARGO_BUILD_FLAGS} "$@" } do_compile () { From patchwork Wed Aug 26 20:57:37 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96488 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9202BC61DD2 for ; Wed, 26 Aug 2026 20:58:53 +0000 (UTC) Received: from mail-qv1-f49.google.com (mail-qv1-f49.google.com [209.85.219.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.22427.1787777927143719938 for ; Wed, 26 Aug 2026 13:58:47 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=H2HWcfy5; spf=pass (domain: konsulko.com, ip: 209.85.219.49, mailfrom: scott.murray@konsulko.com) Received: by mail-qv1-f49.google.com with SMTP id 6a1803df08f44-8f186025973so15746016d6.0 for ; Wed, 26 Aug 2026 13:58:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777926; x=1788382726; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ZjUklekn3p4wfNF11Ta3lX2pRZer0AqIYF2dRtozSbA=; b=H2HWcfy5HLnGg5teyISLZgtqJEaANuYQrjFmyDK+Yob3b+Fubje9MdCXhhgqXW58qe on8VSHu2b8VxAsFbsHiIWymFUF0ISohPYdLYkkNhKWch0qDb212XG5SEHh6pAfGw+hiM odCOvLMsLM/ScoNrARSEAPm5wmdjR9o3FIzSU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777926; x=1788382726; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=ZjUklekn3p4wfNF11Ta3lX2pRZer0AqIYF2dRtozSbA=; b=RE30/Kj7ifkpX4raZgDcBnSJh8FxfNlRFU4xGpaawzMZVH9W8nlnzSJCuiV+uBzOvu 5PHxAgWwznVSlF9NBB9/SRobxB3f93f19dvX7UlodOsLORr0nNko7M1aOTo+G5f9RXZY ODPRNtEHXvO0xgJ96N8whJb6wVFfAB26z7cKI9UZZRg+HtJNHmrq6aUl67XHmGNeYr2M brF/XmI1h0i5nPpnmmcASpFI1qLGFm+V93qdjM2s8j9y7IjuegCpfPid3njp89xzCO2g C5N20RJLnM/Af+7sv2JsXMWYTCuHxd3b6RcX7QflXzs4yvFCyD4P4DIwp+SXYjqe+wVH vUOg== X-Gm-Message-State: AFuF++nyvtgI1uEgTgRV2nLQ1Gq0syRsj4plkQHKRAR0xNwtBDAh++TX 9t+doRFoHf1Gr0UMA/zEhs0Ajnb2Z4kFgKWMdq3YO/3WueDx3MuvUCbpFO0BVvGWuPg6HD+ldji uSc6t X-Gm-Gg: AR+sD13mnpiEmkn+y2aFcR0ARdEs3FEaMuWDGY5lzokuWhKVQAm+3xpM0rpbOY5+tL6 yHU+0zkntbuDHko3JD4McAmlOQEXwMn8u1/vm9JTy6U4F4ernDx5t5qRq5SLZ9BKzoVKHVZc8fb z79tMcuJqEoEux1U560uQvf1uYeeHxHBA8o+hmEqPf5DGN02MCJ58/3BqYJNNI06JdTZVW7B6i/ dGZ7Wkwwumm8MBawl04TBRITDxFngw7XbI2Ospkd8e7T+ry3eM1eCmIJH9AF0/NoRU2AbxeHyck QqJ/fhKDN05fRf5oa1hqA15X4Twk44o6xENUvVVW8pvIk15XZM52wRMpWf77weaPcCf14AgRkAg tVCdYT3i/DFkmfCdWF20R3Z7HxIcReF35AZh2f6zI1029g/MPoqJQ4h+aq3m32Js87IGc4huNHI SJksjgkBa28MmUOVWnQ2IhlokcvbypwoG440890F9qEISZ0nY/3sWA8TX3B7SW88DGBC9E/HpR0 f+D1R4m2lA9RZ6/Z2TkkTa4pvs+LGs+qCxEm0JoUQHRpUoJxFXBqKAOTAAETH4X6ON/F0pqA9T4 74xy8VmG2OKj0jOFgnimDPul1w== X-Received: by 2002:a05:6214:5783:b0:90c:c0c6:4584 with SMTP id 6a1803df08f44-90cc7884dd5mr126713196d6.1.1787777925856; Wed, 26 Aug 2026 13:58:45 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.45 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:45 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 03/15] samhain: fix server startup failure on systemd-based systems Date: Wed, 26 Aug 2026 16:57:37 -0400 Message-ID: <1c04ed220b78436856149d96f1a378a7360b9563.1787777775.git.scott.murray@konsulko.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:58:53 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4695 From: Bin Cao Fix two issues preventing samhain-server (yule) from starting: 1. The compiled-in PID file path /var/run/samhain.pid fails because /var/run is a symlink to /run on systemd-based systems, and samhain's security check rejects symlinks for PID directories. Add SetLockfilePath = /run/yule.pid to yulerc.template, following the same approach used in 0004-Set-the-PID-Lock-path-for-samhain.pid for the standalone/client configuration. 2. The init scripts unconditionally source /etc/default/rcS which does not exist on systemd-based systems, producing a confusing error message. Source it conditionally instead. Signed-off-by: Bin Cao (adapted against prior 4.5.3 upgrade) Signed-off-by: Scott Murray --- ...-set-SetLockfilePath-to-run-yule.pid.patch | 41 +++++++++++++++++++ recipes-ids/samhain/files/samhain-client.init | 3 +- recipes-ids/samhain/files/samhain-server.init | 3 +- recipes-ids/samhain/samhain.inc | 1 + 4 files changed, 46 insertions(+), 2 deletions(-) create mode 100644 recipes-ids/samhain/files/0013-yulerc-set-SetLockfilePath-to-run-yule.pid.patch diff --git a/recipes-ids/samhain/files/0013-yulerc-set-SetLockfilePath-to-run-yule.pid.patch b/recipes-ids/samhain/files/0013-yulerc-set-SetLockfilePath-to-run-yule.pid.patch new file mode 100644 index 0000000..889fd9b --- /dev/null +++ b/recipes-ids/samhain/files/0013-yulerc-set-SetLockfilePath-to-run-yule.pid.patch @@ -0,0 +1,41 @@ +From 7070832b4652f3cdaa2e37325fc6f9456859cb5d Mon Sep 17 00:00:00 2001 +From: Bin Cao +Date: Mon, 25 May 2026 14:55:37 +0800 +Subject: [PATCH] yulerc: set SetLockfilePath to /run/yule.pid + +On systemd-based systems, /var/run is a symlink to /run. Samhain's +security-hardened code uses lstat() to verify the PID file directory +is a real directory and rejects symlinks. This causes yule (the samhain +server) to fail to start with "Path of PID directory refers to a +non-directory object". + +Set SetLockfilePath explicitly to /run/yule.pid to bypass the +compiled-in default of /var/run/samhain.pid. + +This is the same approach used in 0004-Set-the-PID-Lock-path-for- +samhain.pid.patch for the standalone/client configuration. + +Upstream-Status: Inappropriate [OE-specific configuration] +Signed-off-by: Bin Cao +--- + yulerc.template | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/yulerc.template b/yulerc.template +index 512bc0d..24b437c 100644 +--- a/yulerc.template ++++ b/yulerc.template +@@ -173,6 +173,10 @@ Daemon=yes + # SetLoopTime = 60 + SetLoopTime = 600 + ++## Path to the PID file ++# ++SetLockfilePath = /run/yule.pid ++ + ## Normally, client messages are regarded as data within a + ## server message of fixed severity. The following two + ## options cause the server to use the original severity/class +-- +2.34.1 + diff --git a/recipes-ids/samhain/files/samhain-client.init b/recipes-ids/samhain/files/samhain-client.init index d5fabed..c714f8c 100644 --- a/recipes-ids/samhain/files/samhain-client.init +++ b/recipes-ids/samhain/files/samhain-client.init @@ -13,7 +13,8 @@ DAEMON=/usr/sbin/samhain RETVAL=0 PIDFILE=/var/run/samhain.pid -. /etc/default/rcS +# Source rcS only if it exists (not present on systemd-based systems) +[ -f /etc/default/rcS ] && . /etc/default/rcS . /etc/default/samhain-client diff --git a/recipes-ids/samhain/files/samhain-server.init b/recipes-ids/samhain/files/samhain-server.init index c456e51..49a28de 100644 --- a/recipes-ids/samhain/files/samhain-server.init +++ b/recipes-ids/samhain/files/samhain-server.init @@ -13,7 +13,8 @@ DAEMON=/usr/sbin/yule RETVAL=0 PIDFILE=/var/run/yule.pid -. /etc/default/rcS +# Source rcS only if it exists (not present on systemd-based systems) +[ -f /etc/default/rcS ] && . /etc/default/rcS . /etc/default/samhain-server diff --git a/recipes-ids/samhain/samhain.inc b/recipes-ids/samhain/samhain.inc index 95413cb..85359cd 100644 --- a/recipes-ids/samhain/samhain.inc +++ b/recipes-ids/samhain/samhain.inc @@ -20,6 +20,7 @@ SRC_URI = "https://la-samhna.de/archive/samhain_signed-${PV}.tar.gz \ file://0009-fix-build-with-new-version-attr.patch \ file://0010-Fix-initializer-element-is-not-constant.patch \ file://0001-Format-test-output-to-match-Automake-standards.patch \ + file://0013-yulerc-set-SetLockfilePath-to-run-yule.pid.patch \ " SRC_URI[sha256sum] = "e7837adfde3d59a23c59e1bf3ebacdf71bce018619194cfad938cd30cbb9d15b" From patchwork Wed Aug 26 20:57:38 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96490 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9FEEBC61DD4 for ; Wed, 26 Aug 2026 20:58:53 +0000 (UTC) Received: from mail-qv1-f43.google.com (mail-qv1-f43.google.com [209.85.219.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.22627.1787777927858962967 for ; Wed, 26 Aug 2026 13:58:48 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=h/Emfi0n; spf=pass (domain: konsulko.com, ip: 209.85.219.43, mailfrom: scott.murray@konsulko.com) Received: by mail-qv1-f43.google.com with SMTP id 6a1803df08f44-90cc39e06bdso11121076d6.0 for ; Wed, 26 Aug 2026 13:58:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777927; x=1788382727; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=PgoYRivC98VWlnEnM/gDp3PQObMpW8IZE8KmclouLz4=; b=h/Emfi0n9uz+ndb+jCW6c8dtvYTH99Qm859Hc6pI3iGAxiFYgzzSCmvDogQo3esq82 I7jaVjMQ0SfLM4obYl3k50vbqVIWK1hXdik8Zmqq4OXo5bUlTUfk6MJmDjs2bi77BxWv GTpPqK7HM2xrzeavGGmdDMVyiwK5tzwJtvHW0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777927; x=1788382727; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=PgoYRivC98VWlnEnM/gDp3PQObMpW8IZE8KmclouLz4=; b=dd0m7wrdxVC19uc/ZSFrH4Vp7rZrJ7ns21RHDC9pmVM3WwWdZ8H7V0tk5yUUuQoK0H tWXs4hvJSdxBAwPtlS7YILcR0yUwI1pC0HUq0pT2TmknxsYACLoJSvnEOAiK0P/q0UQ6 evkpUbNDTimM4Farf/i3QLv2AbW4UGq9Z3Jk6AhwrC+PNUXxyoliiUhj/mAPmDH9j+O0 tMI6mFcNy0gGwVgET/x7+iZYEkBo6jhFvyZP89ravU1bRD0nx1M7HokeRMk36GiuRCzO M0H6htYcMk0/NJzQ+2GNUWAxmXllefmKn6wVEUW3evW0d6SujTq5PlBwKpwYwQtaelZl ctLA== X-Gm-Message-State: AFuF++mJNw684DuOw6W3DuJLKz1Q7/Z8GkqSBfHLMPZFEh2ZtDHugmFy H1DruqUgDrY5FYkrsi7yHcg6324fl67L6yVMmKhGYRn22prMsdS7SotbI+HhcknRBszRRs280kl 85ynH X-Gm-Gg: AR+sD12VF5lnQr3RS/1uFcsiHDyg2yF+gNYDlvu7gXAQuhXZk0zrLYSxThSngChOfP6 hJS8gEBtGJJlLysENKnyKBo1hla5qdydRAPL/hnqF7F1Oniu94a8Nax/9ePtryMiGfEMRoLK9Vr uCVHfdnsmm/zIJAM5/qe3RiD4fd1BmX4QiG7TBNJrIrq27P71jAZ04qWxjB2xTylXgwORuhx6LY 7DIDnolA+JEco83rqO3ArSHhrcfMuNR46sgnIWQ27JOhPweJDQ8Z72X8ivYbpDGeHEyuM/kSJq/ D8+fNCQKqwn9TzKkCKM5P2ftYDYorfXhvP+gKUnct33+Wog4YbqQM5YLE5EHOUhSDF6FSVi6r6y E4RvK0tWfaRIqZOgGCSkR8+t6qhTm819ozx25OpZACqbt3jVg7GhwLaBfr7dFY71EXEJ44TdEKR h6BmvIgMrMoxFUaHIr63N7qr2kNNp49ux/6djH85coa+2vwYWzoiPi2mloWMsElnRvAqulrK9w5 Hhv9b5mzDbtBbNoWrrTe7WNUbJCP76VhDPriRLY8NCNCfOJu5Tfw1qx8PD0L9jX7wyz2O2Hbv7c GBDLtkIcOFu8GzKVXsXE2Cr1XCA= X-Received: by 2002:a05:6214:dcb:b0:90a:7fbd:ea89 with SMTP id 6a1803df08f44-90cc790ca01mr102565966d6.1.1787777926639; Wed, 26 Aug 2026 13:58:46 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.46 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:46 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 04/15] README: fix broken URLs in meta-integrity and ccs-tools Date: Wed, 26 Aug 2026 16:57:38 -0400 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:58:53 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4696 From: Sandeep J Update TOMOYO documentation URL: http://tomoyo.sourceforge.jp/1.8/index.html.en to: https://tomoyo.sourceforge.net/1.8/index.html.en Replace dead gmane.org permalink references with mail-archive.com copies of the original Tizen dev mailing list messages: http://permalink.gmane.org/gmane.comp.handhelds.tizen.devel/6281 to: https://www.mail-archive.com/dev@lists.tizen.org/msg06106.html http://permalink.gmane.org/gmane.comp.handhelds.tizen.devel/6275 to: https://www.mail-archive.com/dev@lists.tizen.org/msg06100.html Signed-off-by: Sandeep J Signed-off-by: Scott Murray --- meta-integrity/README.md | 4 ++-- recipes-mac/ccs-tools/README | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/meta-integrity/README.md b/meta-integrity/README.md index 92d24f8..9dcd518 100644 --- a/meta-integrity/README.md +++ b/meta-integrity/README.md @@ -270,5 +270,5 @@ No package manager is integrated with IMA/EVM. When updating packages, files will end up getting installed without correct IMA/EVM attributes and thus will not be usable when appraisal is turned on. -[1] http://permalink.gmane.org/gmane.comp.handhelds.tizen.devel/6281 -[2] http://permalink.gmane.org/gmane.comp.handhelds.tizen.devel/6275 +[1] https://www.mail-archive.com/dev@lists.tizen.org/msg06106.html +[2] https://www.mail-archive.com/dev@lists.tizen.org/msg06100.html diff --git a/recipes-mac/ccs-tools/README b/recipes-mac/ccs-tools/README index 0381814..dffb933 100644 --- a/recipes-mac/ccs-tools/README +++ b/recipes-mac/ccs-tools/README @@ -1,5 +1,5 @@ Documentation: -http://tomoyo.sourceforge.jp/1.8/index.html.en +https://tomoyo.sourceforge.net/1.8/index.html.en To start via command line add: From patchwork Wed Aug 26 20:57:39 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96483 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 9CCBEC61DBE for ; Wed, 26 Aug 2026 20:58:52 +0000 (UTC) Received: from mail-qt1-f170.google.com (mail-qt1-f170.google.com [209.85.160.170]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.22429.1787777928918428590 for ; Wed, 26 Aug 2026 13:58:49 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=DNIcpbsL; spf=pass (domain: konsulko.com, ip: 209.85.160.170, mailfrom: scott.murray@konsulko.com) Received: by mail-qt1-f170.google.com with SMTP id d75a77b69052e-52b6543169fso9910051cf.2 for ; Wed, 26 Aug 2026 13:58:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777928; x=1788382728; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=JW9cq2/7lJJhkkeG450SgmPQn9n6p2wP/mvleS1h/zg=; b=DNIcpbsLELbatirPf27Dlk6N/VXWEks5mXmPGxzVGOngvwH/j5ZtQHzMhNuwNm885h iv0VxF/PywNUSUaOi4qdBTrXI8DhgdRpsrxWv6Vi9wo4lUkm/3KpEAeSULlIXN3X6Osa 9rGjUknAJRjry82avJpuMMBdj1eKI7ynHxFlc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777928; x=1788382728; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=JW9cq2/7lJJhkkeG450SgmPQn9n6p2wP/mvleS1h/zg=; b=Xd6iSExZ5xkquQAH0oEdiKE/8g7UttMmGuNPZ86pO90VOZgucdbXVpvmrdcrzd6bGf ovq+n7B6Vk+2U3J8NdiSW+BZFDM41vpoetddcfAb4cDPd1Gd+hCWiJ1ssu9MDsR/sH17 5gUXszjRp02DKVXkAB7cnUhtr4TE2+dv3bKcXeg1cu/8zDJNZeKj/26La+iuJ7Uabpod KtdDBlzm6vYBzp8lCQz2dUVpVS5ozZnXoLhXPjoCghWouca4xb3E3UmX/zwyAy8qXd8X 6ErOQI+AL1AMm7Vm4GtBg/7IItk1TFAnniDlqoSa9cR7+j3LdII8cXzkYlQ7pziStJcY t0LA== X-Gm-Message-State: AFuF++kMVPVCOOnGoRXtpL43BiW11G9WxjNOfZvjvCZ2e49JdYnKA1aS /3sdkFgEWwRvszmfUhIfu3+IOeVqstEfoHYkpv5HHBqYyj+1Z2WLdE958TvDWoX6+ylQO6aVbVO CHmuH X-Gm-Gg: AR+sD13NRtVtbIJ+LgQq+aFX9pEe0RP7+VwDCLxUG76Fe1URfetVCUkXPE3qwClY/uv RDYFUFP1/eCB/b+I5NGA5sTfTOoOk2Qyo52ASBObShyhCQov+3ozP9s+l8hOdZuLbSi+tDMWoBJ 1O+2GwrGiGW3isqJFQeupOZWLWNuVry43t7fWDd72hiWxIMVwwIyB3mCKpB5GerCUkf8NUC01gB BRlQDHFREQnywNCZ2RJB5Vf1YM6GcGVXRD0Xjgw4RLp91SCuADZsFjXL3ZLsLVsIex7FhWuklrN HiO3GdngFsu5uepg8mqieBewEJHSjiTnHUUtAkxJg5HdLQYHiDMFo4kofdSMD4Y3SCZtg1pep4S NAAtRdaz4HRyUc+40tWWZqXewkp6ksbe8VNXpdRX5Jpgukp+NgnWcTDlvdgKvDxpO+H0RooDSFJ PdjEdda0TwOoUB7FrUO7GLBPdpchvqDZd/rp+oRbDDDKx9GWXbYMMEPC9WEXmB2FxVHknz+4p84 hgMBW3SmBVL6vQxettTJ9P/yojNJdyYeObVlT5pPp07+7S03IyDFybbTYQ4KOUQ7ju1ODM0YRak yb9BCa650458WeQzLhmBKYmKMqg= X-Received: by 2002:a05:622a:2605:b0:528:3157:7a8e with SMTP id d75a77b69052e-52e4222de28mr114531271cf.9.1787777927461; Wed, 26 Aug 2026 13:58:47 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.46 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:47 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 05/15] meta-tpm: Add missing recipe metadata (HOMEPAGE/SUMMARY) Date: Wed, 26 Aug 2026 16:57:39 -0400 Message-ID: <3ef6b7cc57f537e8612b02ee2389782689e95881.1787777775.git.scott.murray@konsulko.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:58:52 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4697 From: Shreejit C Several meta-tpm recipes were missing HOMEPAGE and/or SUMMARY entries, tripping the missing-metadata recipe QA check that is enabled for core-layer recipes. The warnings surface whenever do_recipe_qa actually runs (a fresh build with no sstate hit), e.g.: WARNING: tpm2-tss-4.1.3-r0 do_recipe_qa: QA Issue: Recipe tpm2-tss in .../tpm2-tss_4.1.3.bb does not contain a HOMEPAGE. Please add an entry. [missing-metadata] Add the upstream project URL as HOMEPAGE, and a SUMMARY where absent: - tpm2-tss: add HOMEPAGE - tpm2-tools: add HOMEPAGE - tpm2-openssl: add HOMEPAGE - tpm2-abrmd: add HOMEPAGE - tpm2-pkcs11: add HOMEPAGE - tpm2-tss-engine: add HOMEPAGE - python3-tpm2-pytss: add SUMMARY - packagegroup-security-tpm2: add SUMMARY Signed-off-by: Shreejit C Signed-off-by: Scott Murray --- meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb | 1 + meta-tpm/recipes-tpm2/tpm2-abrmd/tpm2-abrmd_3.0.0.bb | 1 + meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb | 1 + meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb | 1 + meta-tpm/recipes-tpm2/tpm2-pytss/python3-tpm2-pytss_2.3.0.bb | 1 + meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb | 1 + meta-tpm/recipes-tpm2/tpm2-tss-engine/tpm2-tss-engine_1.2.0.bb | 1 + meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb | 1 + 8 files changed, 8 insertions(+) diff --git a/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb b/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb index b986097..b04851f 100644 --- a/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb +++ b/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb @@ -1,3 +1,4 @@ +SUMMARY = "TPM2 packagegroup for Security" DESCRIPTION = "TPM2 packagegroup for Security" LICENSE = "MIT" LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302 \ diff --git a/meta-tpm/recipes-tpm2/tpm2-abrmd/tpm2-abrmd_3.0.0.bb b/meta-tpm/recipes-tpm2/tpm2-abrmd/tpm2-abrmd_3.0.0.bb index 1b8eff1..b829a68 100644 --- a/meta-tpm/recipes-tpm2/tpm2-abrmd/tpm2-abrmd_3.0.0.bb +++ b/meta-tpm/recipes-tpm2/tpm2-abrmd/tpm2-abrmd_3.0.0.bb @@ -5,6 +5,7 @@ is implemented using Glib and the GObject system. In this documentation and \ in the code we use `tpm2-abrmd` and `tabrmd` interchangeably. \ " SECTION = "security/tpm" +HOMEPAGE = "https://github.com/tpm2-software/tpm2-abrmd" LICENSE = "BSD-2-Clause" LIC_FILES_CHKSUM = "file://${S}/LICENSE;md5=500b2e742befc3da00684d8a1d5fd9da" diff --git a/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb b/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb index ed756b1..e97a208 100644 --- a/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb +++ b/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb @@ -1,4 +1,5 @@ SUMMARY = "Provider for integration of TPM 2.0 to OpenSSL 3.0" +HOMEPAGE = "https://github.com/tpm2-software/tpm2-openssl" LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://LICENSE;md5=3f4b4cb00f4d0d6807a0dc79759a57ac" diff --git a/meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb b/meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb index 3d04e5b..1a671bc 100644 --- a/meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb +++ b/meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb @@ -1,6 +1,7 @@ SUMMARY = "A PKCS#11 interface for TPM2 hardware" DESCRIPTION = "PKCS #11 is a Public-Key Cryptography Standard that defines a standard method to access cryptographic services from tokens/ devices such as hardware security modules (HSM), smart cards, etc. In this project we intend to use a TPM2 device as the cryptographic token." SECTION = "security/tpm" +HOMEPAGE = "https://github.com/tpm2-software/tpm2-pkcs11" LICENSE = "BSD-2-Clause" LIC_FILES_CHKSUM = "file://LICENSE;md5=0fc19f620a102768d6dbd1e7166e78ab" diff --git a/meta-tpm/recipes-tpm2/tpm2-pytss/python3-tpm2-pytss_2.3.0.bb b/meta-tpm/recipes-tpm2/tpm2-pytss/python3-tpm2-pytss_2.3.0.bb index 63ed8cf..44c6ed2 100644 --- a/meta-tpm/recipes-tpm2/tpm2-pytss/python3-tpm2-pytss_2.3.0.bb +++ b/meta-tpm/recipes-tpm2/tpm2-pytss/python3-tpm2-pytss_2.3.0.bb @@ -1,3 +1,4 @@ +SUMMARY = "Python bindings for the TPM2 Software Stack (TSS2)" DESCRIPTION = "TPM2 TSS Python bindings for Enhanced System API (ESYS), Feature API (FAPI), Marshaling (MU), TCTI Loader (TCTILdr), TCTIs, policy, and RC Decoding (rcdecode) libraries" HOMEPAGE = "https://github.com/tpm2-software/tpm2-pytss" LICENSE = "BSD-2-Clause" diff --git a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb index e1a0c5d..04ada78 100644 --- a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb +++ b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb @@ -1,5 +1,6 @@ SUMMARY = "Tools for TPM2." DESCRIPTION = "tpm2-tools" +HOMEPAGE = "https://github.com/tpm2-software/tpm2-tools" LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://docs/LICENSE;md5=a846608d090aa64494c45fc147cc12e3" SECTION = "tpm" diff --git a/meta-tpm/recipes-tpm2/tpm2-tss-engine/tpm2-tss-engine_1.2.0.bb b/meta-tpm/recipes-tpm2/tpm2-tss-engine/tpm2-tss-engine_1.2.0.bb index 6bc44ef..e620995 100644 --- a/meta-tpm/recipes-tpm2/tpm2-tss-engine/tpm2-tss-engine_1.2.0.bb +++ b/meta-tpm/recipes-tpm2/tpm2-tss-engine/tpm2-tss-engine_1.2.0.bb @@ -1,5 +1,6 @@ SUMMARY = "The tpm2-tss-engine project implements a cryptographic engine for OpenSSL." DESCRIPTION = "The tpm2-tss-engine project implements a cryptographic engine for OpenSSL for Trusted Platform Module (TPM 2.0) using the tpm2-tss software stack that follows the Trusted Computing Groups (TCG) TPM Software Stack (TSS 2.0). It uses the Enhanced System API (ESAPI) interface of the TSS 2.0 for downwards communication. It supports RSA decryption and signatures as well as ECDSA signatures." +HOMEPAGE = "https://github.com/tpm2-software/tpm2-tss-engine" LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://LICENSE;md5=7b3ab643b9ce041de515d1ed092a36d4" diff --git a/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb b/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb index 67a51e4..f8e87a5 100644 --- a/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb +++ b/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb @@ -1,5 +1,6 @@ SUMMARY = "Software stack for TPM2." DESCRIPTION = "OSS implementation of the TCG TPM2 Software Stack (TSS2) " +HOMEPAGE = "https://github.com/tpm2-software/tpm2-tss" LICENSE = "BSD-2-Clause" LIC_FILES_CHKSUM = "file://LICENSE;md5=500b2e742befc3da00684d8a1d5fd9da" SECTION = "tpm" From patchwork Wed Aug 26 20:57:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96486 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id EE101C61DC4 for ; Wed, 26 Aug 2026 20:58:52 +0000 (UTC) Received: from mail-qv1-f49.google.com (mail-qv1-f49.google.com [209.85.219.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.22430.1787777929745230859 for ; Wed, 26 Aug 2026 13:58:49 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=ClMmUUGE; spf=pass (domain: konsulko.com, ip: 209.85.219.49, mailfrom: scott.murray@konsulko.com) Received: by mail-qv1-f49.google.com with SMTP id 6a1803df08f44-90cd4631090so2795316d6.1 for ; Wed, 26 Aug 2026 13:58:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777929; x=1788382729; darn=lists.yoctoproject.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=iwGb7IfXmzwXKCAT2zQ4MK4glKNTE+PJxtde1KfEQ8A=; b=ClMmUUGE3ROGF5hvLSQxNxzarWN/GjbwtDAVGhFMfi3/4MnEhSEBohKPOFRjMb8UdC BrrfGnetgxo7LfAZo3QQzT2SnXVYhE9Qx9K0G3mKcWIQLiIOwQN/pVDwwcKIL8Rx3UrI GtN81KZNwcxsgUnQtZ0qH8h5vlmglLo/619Ck= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777929; x=1788382729; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=iwGb7IfXmzwXKCAT2zQ4MK4glKNTE+PJxtde1KfEQ8A=; b=gJIBPn6Zt0MBdsogc0VY6urzGLn13l8TyTBDcJwSmcbfbdlK2fW2M3MCJt+jg+mkMr 1zfT7qwezpwP45128o5DZS0MoSgQqDZq2sQHpVPQE0FXP6CoNssV9vqntqI/39cWpN6J fZV2ZCkbPfYnGDvoyMjSncl9QHJc668w0w+CkMHMAM7ltJB1lfsL5aNkNClEn4KymPPt q3Z3U8NUrHOuKHvLXAsDrgs8Aj6NxOYlgLx1MDdt/3l7RSbeg6aCAb21y3HIstU7IZun GtVcKP3yvSsNwF5AkU2TiRZ5jDn050Dw9M6H07cgZDOGyJYN/1pGHMD1SmnfaoVa2VZS rJRg== X-Gm-Message-State: AFuF++mQ6PdTmY8qgsZL2xrhcDgiUVruytkAlLDGbBrLu4jgInPv+6Uq jujsfh3F5nGe5PpDcWxcOKap7L9Rzr8vtEA4A4jTSFCYHa9nvfJHbNp/idC3jxcjuebKatBaOym sSH6v X-Gm-Gg: AR+sD11mYWsJUOlfEYyTjlOv9OETMJ2H7eAOxAFk606jj+gLKyxw3ycfnsYLP1+zpTG xxLg/N3kDdcUq7FwSy+nrcNPHQGCY0rSSum3DBXIUuRp4v2vXcT9wGALoBKa3gdSKM94D5U7qc/ MLPVHoWzS0gxCy2AUBjfgdpxYToazPK6PphJiJ6fGNhgbcfijZYRbfnL1cXvTwZ1oG13Dn4uPqH HNGmuST4STWMFoz+pU6fwOFjDTqL91qu0SKoh3Lt4izCg0CVAfvN9fXpcTM6q8+jEzO47XWVD47 7B6plrhvco5c0FiUbvJ/9gPoaD+OUI9IEut9oNMGqSEyf1xrz7Pic9T2Bj0iv6rHwY88tqOkWzy 5CJRhhi/0EW75yhzHyRtuJNHtmyvYU3dfGuk5AwIxL0Ago+cyCzkFONwdEtKFy8ot8ixRET8YIp 52gYj7VAbisxL5H14u9vUuXwXnmUf2nIJucACdwSUkIlpla6wNfqpPinXQiesgDP8J63De76xsY 4tDDDjoHVWjX3vkXSOWqX1KvbNWjwaVu2PV6zGAefeI8A1Ss/ioocMHdRfh8WUvjDm9enVsMAB3 MbuWyLWiOltx0GbgrXp27rA2dg== X-Received: by 2002:a05:6214:5d05:b0:90c:d1c3:534f with SMTP id 6a1803df08f44-90cd4369161mr28070926d6.4.1787777928553; Wed, 26 Aug 2026 13:58:48 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.47 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:47 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 06/15] dm-verity: remove unused variable Date: Wed, 26 Aug 2026 16:57:40 -0400 Message-ID: <013ac8517413fd8fe96a303ffccd084853d1aa03.1787777775.git.scott.murray@konsulko.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:58:52 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4698 From: Gaël PORTAY This removes unused variable that was dropped by commit d80cd2ba6a ("dm-verity: Set the IMAGE_FSTYPES correctly when dm-verity is enabled"). Signed-off-by: Gaël PORTAY Signed-off-by: Scott Murray --- classes/dm-verity-img.bbclass | 1 - 1 file changed, 1 deletion(-) diff --git a/classes/dm-verity-img.bbclass b/classes/dm-verity-img.bbclass index 48557e9..619cda8 100644 --- a/classes/dm-verity-img.bbclass +++ b/classes/dm-verity-img.bbclass @@ -202,7 +202,6 @@ IMAGE_FSTYPES += "${@get_verity_fstypes(d)}" python __anonymous() { verity_image = d.getVar('DM_VERITY_IMAGE') verity_type = d.getVar('DM_VERITY_IMAGE_TYPE') - verity_hash = d.getVar('DM_VERITY_SEPARATE_HASH') image_fstypes = d.getVar('IMAGE_FSTYPES') pn = d.getVar('PN') From patchwork Wed Aug 26 20:57:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96485 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 62382C61DC7 for ; Wed, 26 Aug 2026 20:58:53 +0000 (UTC) Received: from mail-qt1-f177.google.com (mail-qt1-f177.google.com [209.85.160.177]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.22431.1787777931099831138 for ; Wed, 26 Aug 2026 13:58:51 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=LNO1tm6e; spf=pass (domain: konsulko.com, ip: 209.85.160.177, mailfrom: scott.murray@konsulko.com) Received: by mail-qt1-f177.google.com with SMTP id d75a77b69052e-52eaeddc837so4957971cf.2 for ; Wed, 26 Aug 2026 13:58:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777930; x=1788382730; darn=lists.yoctoproject.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=xdlFyYrGKG5jHyZuV87d9EKl7RH3zmWbK3/ikF3Iy8A=; b=LNO1tm6ezRM2656oPte2UE4dDdoxAxMmJBuLKPtdgd1/LAN1ErtIjDXTrKiYLgVpp9 U35Ti4pZRN+0n6Ty+2LOU3BSDFg3nsy1jifwSs5iZIpWNXuMBzqzmQNXBNjY0F8OmDpu GOtdBkpKqBDpNXFS0dp7VRJs8uiWFyL+8HJB4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777930; x=1788382730; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=xdlFyYrGKG5jHyZuV87d9EKl7RH3zmWbK3/ikF3Iy8A=; b=Shl44Cb3C8godBQhdWgLRXRY4xvyHiJ6cj4IuTcUVzVGDJXUHi8IGY4gsNxqZN1a3g N82NMS9lU6P6DIVi/HjOQOD7nbB00Z5H4a03UAaH7ZEJBwHmnT0cYftpi+pDV3m7LyW2 SUvzjUNrufICnqD98epPKdX4G2r2uVoD9jDYM3K25P78fNe6yfBplmlazwsqEQN7iaWj 8KF0Bwm3atJbyJNK/NnuhDn6fgHxyQe3b3FQol6s5ITjp8xBfI47Gw24P3dhLjRasUcj nI+tVOSdTlV0eVHJfJEf+nbdhW4WEh2tUifybp7E5HzIL08KmN59LzrmuB24slM7h63c eFZg== X-Gm-Message-State: AFuF++l9PJfI8FqxwYmoFpB6jDOgybqZQNCt/FDJEaLO6AD+lAIkQScX mKchkdslKRw5wenJCH2y1CfDN47iZizulRUA4MS0e5y+kYQ+tquDvbDIAye92p7FJlU9ESvkglE d4OaL X-Gm-Gg: AR+sD10XC+LCVw7txvRtQv1sBIy458cpFKIqNRdfKe1UyoJiupTLvi/aJ3kiMP2U0oZ 27VewK+e/5nW0Six+MXaLGAg5hdZfpzkZVcBFkDDsAh2nGuaeuNPckZ5OkxeWVbH5AO9Dva9kya L2/8ZSku9KFXKpCfLtPdho1DEyz7hhwg/Hxf3F7zAo41o1bylZpcqYCnV3YkR19MWuoWTXDcO+l xTRFbCoXMG3k0IvS94UUgBdzpN1GHl1L2uMRfBMoQIplV5AuNeLo9AQiTTzWO1NMrjoL7qzMaP3 J+vAPNiR/Olzk4fXeXdrYjX4WLvNTZJ62J4i+pLR1MT09ov8gCF7m/U6t0bDYfwrQqHp1ELy5mS +TGlY+Bh6jeoXMBl8dSCwzmDKbQ32QLf0UiZyJoziF2JfvFuJ4A6ErWKaNU60aroWBQ3UTkpZGx uGQrR2ArdSSjvbbGNb1as2swW4//P199rN9K65Ui4RQZ4aTdRiJCiioEziVlGnofzV+RUs2aYsu abYUv5DSs/HNBRJpT/tYOh9dX5MW7tsl7jK89w3NJwMGXQd1p/IDudkKumYzpnUCFwI0CQt2nr0 GJVkP4L0Hu91F9JwtmMu/I7J/UZaNL1b6QkT X-Received: by 2002:a05:622a:50e:b0:51c:b900:513f with SMTP id d75a77b69052e-52e4226d3f4mr90549291cf.10.1787777929973; Wed, 26 Aug 2026 13:58:49 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.48 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:48 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 07/15] wic: document the meta-intel dependency in the dm-verity hash example Date: Wed, 26 Aug 2026 16:57:41 -0400 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:58:53 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4699 From: Gaël PORTAY The dependency might not be obvious to everyone, so leave a hint as in commit 2fbeebc18c ("dm-verity: document the meta-intel dependency in the systemd example"). Signed-off-by: Gaël PORTAY Signed-off-by: Scott Murray --- files/wic/systemd-bootdisk-dmverity-hash.wks.in | 1 + 1 file changed, 1 insertion(+) diff --git a/files/wic/systemd-bootdisk-dmverity-hash.wks.in b/files/wic/systemd-bootdisk-dmverity-hash.wks.in index e400593..67abaa6 100644 --- a/files/wic/systemd-bootdisk-dmverity-hash.wks.in +++ b/files/wic/systemd-bootdisk-dmverity-hash.wks.in @@ -6,6 +6,7 @@ # Based on OE-core's systemd-bootdisk.wks and meta-security's beaglebone-yocto-verity.wks.in file # # This .wks only works with the dm-verity-img class and separate hash data. (DM_VERITY_SEPARATE_HASH) +# Also note that the use of microcode.cpio introduces a meta-intel layer dependency. part /boot --source bootimg-efi --sourceparams="loader=systemd-boot,initrd=microcode.cpio" --ondisk sda --label msdos --active --align 1024 --use-uuid From patchwork Wed Aug 26 20:57:42 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96489 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D3E01C61DD3 for ; Wed, 26 Aug 2026 20:58:53 +0000 (UTC) Received: from mail-qv1-f53.google.com (mail-qv1-f53.google.com [209.85.219.53]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.22433.1787777932577897642 for ; Wed, 26 Aug 2026 13:58:52 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=uP4RCwGL; spf=pass (domain: konsulko.com, ip: 209.85.219.53, mailfrom: scott.murray@konsulko.com) Received: by mail-qv1-f53.google.com with SMTP id 6a1803df08f44-8f0e5e36912so7432886d6.2 for ; Wed, 26 Aug 2026 13:58:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777931; x=1788382731; darn=lists.yoctoproject.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=suvlxoiVkJqP3aL3PCzZ0h8UjC9cFDalTjK7ybF8dKw=; b=uP4RCwGLCzGW2/Rwu5vOPIXPAYcYGsbE3Bl36LKos05oMjZFqgo26lRAZPAP7WH8NU 8qsvdHZ/DF9wV+iIMup17WjMBSYhUV/inwbmOWCWjxwddCpbjNjWg3MhCo2JazFYz/+Y L9uVIOD+nqwoOnbTRhqZqWTtJKedSlqI5TIN4= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777931; x=1788382731; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=suvlxoiVkJqP3aL3PCzZ0h8UjC9cFDalTjK7ybF8dKw=; b=Hv9JjOMiUpPktwCJ1eK+ju68mZPIqJUNF+LwNKwHHPJbFOfEH5ySc22o5QAbNr1Qgh MJ8LvCvDOaRzk9veOGG4r0ugzktC1fPZvL/1rXLhzHDPHvpHN98J4qBghRADapAcaGrA M3f3eGhMDtahYScgWW6ffaAjwsb6cCnnRXynvsXddd4fCwfjmCGBguYv+Yo34S5PzM0Q 5COsEQh2+2S+N71GsmzJhu/sEcYu+y/1eMiY+LjEtf9C2bOlc0pamm8JzwG9RDxv+l+a 38q2xW24doxJ1dgaSrDt15THYeUdvrXdM9ByMN1ETHY7nLY8XEb/GBnEu9XOipCQKidR vGXA== X-Gm-Message-State: AFuF++nhJlLSu6YWFVRRKw8dxHHK43bEUh4VWE4AQCxWf6qg3nzpyASL rHsjGu8zElh+eXcd8ZPlaE5hmnuM/dM84VV8XQHrVftYBGxH0a6B3vWbLom4xdhIgEqLYPslBHB 2F3GM X-Gm-Gg: AR+sD13RBM1tc+YsYiaNywEgH/wevhIHxmzFSA8RrLLDW/fDm/AyrLbpaQctdTnbidP FSOoboNT0/s4GoGZ3MZBAPGm3eiuoSjG2wbBV7FUFhXp0Xa/KgkhL4AbXeE1EFS5yeNFZlXHxyu 0YVVcbdXmqhC0hMHAs05xmAyGLGJ8GxIJvUCcnhgfzczQUt8wxL3JfS6CWu7BGnyP8MgBsYL34E fqXhB3JEzGB28rVTgg9C4pjn8YgDcit+HYzFt5S/yzzEUpXpt+NcM72fSmNxTst6y611GzkG0e2 mgOijI38mEPGbC7Nj9g4ZFJYN0wJU5LT6KWSKsFCt0R9mjxtoiW394U/dnOGh4RVrUW4yF4KYbd HU+SPzOCdh4cSBBfKuHMKgLfvqG1JIgo/M1sk01TcgkhSW2K/pUVYcL4EPNx6rouqYdECg9W1O2 1pyGr1Els3uBjr/hJl3A3ZNIWlGkVNwghPQjTuXYG85n5xEUSqzPQDqwiwu45npI3BUBpNNKSkS EjZEDrLZFaPDO9rCFSwCpYtaQloDoK+gycAsA7CDC32E1BZw2vCuWynnnSCupLr04qZb+beytx9 KpeHlTY3egaladn5StJGMP0ESg== X-Received: by 2002:a05:6214:2c13:b0:907:5ad6:ed0c with SMTP id 6a1803df08f44-90cc78a848dmr117710286d6.7.1787777931296; Wed, 26 Aug 2026 13:58:51 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.50 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:50 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 08/15] docs: update path of wic files Date: Wed, 26 Aug 2026 16:57:42 -0400 Message-ID: <79b0dbd8f7c76c358d87b900082c95a0a26d329e.1787777775.git.scott.murray@konsulko.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:58:53 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4700 From: Gaël PORTAY The wic files were moved from wic/ to files/wic since commit 596b966a0d ("wic: wic need to be moved to files/wic within the layer to be found/used"). This updates the path of wic files in the documentation. Signed-off-by: Gaël PORTAY Signed-off-by: Scott Murray --- docs/dm-verity-systemd-x86-64.txt | 6 +++--- docs/dm-verity.txt | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/dm-verity-systemd-x86-64.txt b/docs/dm-verity-systemd-x86-64.txt index a47b02c..5d759a5 100644 --- a/docs/dm-verity-systemd-x86-64.txt +++ b/docs/dm-verity-systemd-x86-64.txt @@ -14,8 +14,8 @@ writing (kernel v6.1) the resulting qemux86-64 build can also be booted successfully on physical hardware, but if you don't intend to use qemu, you might instead want to choose "genericx86-64" -This will make use of wic/systemd-bootdisk-dmverity.wks.in -- note that it -contains a dependency on the meta-intel layer for microcode, so you'll need +This will make use of files/wic/systemd-bootdisk-dmverity.wks.in -- note that +it contains a dependency on the meta-intel layer for microcode, so you'll need to fetch and add that layer in addition to the meta-security related layers. In addition to the basic dm-verity settings, choose systemd in local.conf: @@ -56,7 +56,7 @@ The following build artifacts were used to create the image(s): NATIVE_SYSROOT: /home/paul/poky/build-qemu-x86_64/tmp/work/core2-64-poky-linux/wic-tools/1.0-r0/recipe-sysroot-native INFO: The image(s) were created using OE kickstart file: - /home/paul/poky/meta-security/wic/systemd-bootdisk-dmverity.wks.in + /home/paul/poky/meta-security/files/wic/systemd-bootdisk-dmverity.wks.in build-qemu-x86_64$ ------------------------------ diff --git a/docs/dm-verity.txt b/docs/dm-verity.txt index a538fa2..dca3df6 100644 --- a/docs/dm-verity.txt +++ b/docs/dm-verity.txt @@ -115,7 +115,7 @@ The following build artifacts were used to create the image(s): NATIVE_SYSROOT: /home/paul/poky/build-bbb-verity/tmp/work/cortexa8hf-neon-poky-linux-gnueabi/wic-tools/1.0-r0/recipe-sysroot-native INFO: The image(s) were created using OE kickstart file: - /home/paul/poky/meta-security/wic/beaglebone-yocto-verity.wks.in + /home/paul/poky/meta-security/files/wic/beaglebone-yocto-verity.wks.in ---------------------- The "direct" image contains the partition table, bootloader, and dm-verity From patchwork Wed Aug 26 20:57:43 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96491 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B3F17C61DBE for ; Wed, 26 Aug 2026 20:59:03 +0000 (UTC) Received: from mail-qv1-f46.google.com (mail-qv1-f46.google.com [209.85.219.46]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.22435.1787777933493548057 for ; Wed, 26 Aug 2026 13:58:53 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=D9ZqBbsY; spf=pass (domain: konsulko.com, ip: 209.85.219.46, mailfrom: scott.murray@konsulko.com) Received: by mail-qv1-f46.google.com with SMTP id 6a1803df08f44-9087fb771d3so8864786d6.0 for ; Wed, 26 Aug 2026 13:58:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777932; x=1788382732; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=d2K+A9aMaJzVR8BxiZn+zkAAp7c2uRwXNlQwTYVyD84=; b=D9ZqBbsY95hKugnLp/Abdr95N1upT+QspVt/Pq8gMUTE3ax9kCfTk6bTY16DCtaS+s tx2HHAJV+AQvafISv8ei0syOc3QgJEv/Eya845KAMnLlUoo0JID/FtArxVsW/Q/jGnEU wLPrUwKy4WkUbI7RqhGY3MPiIML901NyOhA24= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777932; x=1788382732; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=d2K+A9aMaJzVR8BxiZn+zkAAp7c2uRwXNlQwTYVyD84=; b=qyMqpNrrC7B7XfCOfntqgofl4JzwENHJ25tc/QbfvSbssfd55ga1hatx4VhM4UEsbq vLANYy16yYQVOTdSlxIb/BJiwwPCCQX+2HQJKBfq4996kTu3l6o8gIqjbe+kjwfFiOzc eMpEoyZwobjE+QNdTWrRYYA/JHab3idW151gplgG8qsrTgR/aNQVsWqmKL/FGh2uphRt 2K8+Rr/oJD67duVHMmFeE14TK1MYXO+MzF+1GfEFmazL+mG7L/hRtVQUbj8L4doJO7Mb OkPFyYQh3wyKq+Gso9PcijQEmCTd3jaW3c3QFJn6jb8BKIP1bM8o9B4PJW2x4jHV14Mo xKAw== X-Gm-Message-State: AFuF++k6OIRcoZZRa02OwuKADPGaYkZmgHGwSxQxWa9sRL42Tuzb0BHC tZcMLENdNYyemEkwrExu84drbZh+VpXLbhXjG/bTu1/FaklUn4FTB+m7uVVEMADt2c/7Sg81h4g jdzqW X-Gm-Gg: AR+sD12hTl3hqyDZlwnIipP8vx4CM9Vviist+KBpDDhNa0x3R0sx88UlLpjyWnaCePX vPaxCypWxO9b/QGPOl18+jmDzwuWB62fQDIQ99EL3HxmGq+5M7lkoH95qtbyqkJS2X1HOxoPvV/ YEVoXL+kajYQkoiA++Pv3PegUDOM/imxOEDKe36S0sKrEz8c5yjR9BNRw5EOYVQHOujx9UFJwou Tg1T813rV4fYBo2bOgI7tM3zXjOE1Ks9mlQPlRSR7LVDdU1Ow5NaXBj9wZ0YjlbObgP2bSgUY4A gYbiGbkY6Nj3CQ/9i79AWZLMcwn0jRbFbwrAJ+3/M8+MJv17sPZHzBmOy5hOGgHIojVHmyM6fnw +nrgZpJP083SXMbHt8D/N+xiadiN1dV22YsecQXF33FZodSjFGJ/Yl7qIbCrC5Gpx4ithzH2dYl hLRBFs3Naem784pSt2S9xBOwfirfGjOx47RASBQ3HuBx9aecR/uvVk+EnpMOnatPR8+Gdaqaa2C AkuOnM+q6GfaJdzHArBJqNh5B+L/5NaYO1pP0MvNN7tt3TfFUcSpXQZYvcoROODQFJ5R38r+jRi 3krLMZtVnA+ymi8XWN6iWKFh7g== X-Received: by 2002:a05:6214:460a:b0:908:9045:217a with SMTP id 6a1803df08f44-90cc7a7126fmr121844346d6.29.1787777932351; Wed, 26 Aug 2026 13:58:52 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.51 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:51 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 09/15] tpm2-tools: set status for CVE-2017-7524 and CVE-2024-29039 Date: Wed, 26 Aug 2026 16:57:43 -0400 Message-ID: <603cd3ff492a2e53897774569b20f544c8f4ff49.1787777775.git.scott.murray@konsulko.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:59:03 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4701 From: Peter Marko CVE-2017-7524 is a historical CVE and new cve-check does not undestand fixed version data. Debian report [1] shows fix commit which can be linked to release information. CVE-2024-29039 is per Debian report [2] fixed in 5.7. [1] https://security-tracker.debian.org/tracker/CVE-2017-7524 [2] https://security-tracker.debian.org/tracker/CVE-2024-29039 Signed-off-by: Peter Marko Signed-off-by: Scott Murray --- meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb index 04ada78..5c968dd 100644 --- a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb +++ b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb @@ -19,3 +19,6 @@ PACKAGECONGIG ??= "efivar" PACKAGECONFIG[efivar] = "--with-efivar,--without-efivar,efivar" BBCLASSEXTEND = "native nativesdk" + +CVE_STATUS[CVE-2017-7524] = "fixed-version: Fixed since version 3.0.0" +CVE_STATUS[CVE-2024-29039] = "fixed-version: Fixed since version 5.7" From patchwork Wed Aug 26 20:57:44 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96493 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 36562C61DC6 for ; Wed, 26 Aug 2026 20:59:04 +0000 (UTC) Received: from mail-qt1-f177.google.com (mail-qt1-f177.google.com [209.85.160.177]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.22437.1787777934430968616 for ; Wed, 26 Aug 2026 13:58:54 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=XJiKyUjD; spf=pass (domain: konsulko.com, ip: 209.85.160.177, mailfrom: scott.murray@konsulko.com) Received: by mail-qt1-f177.google.com with SMTP id d75a77b69052e-52e2d1bdbc0so10469721cf.0 for ; Wed, 26 Aug 2026 13:58:54 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777933; x=1788382733; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=pn1ziw/2Ct0AV93+LleKcaEf4OfiR5j3sKq4oZLw3Ag=; b=XJiKyUjDjDDOS5Rm/fGiEuWRe3IzahB8b+hE1UMHWhetvPB7nQou75DMcz2PTyo64T x6hLN4V3WM33eK7R+BzCteUDuHqr9vFXwtbdJoWqDwBcjj/5ZfLzs8gq9K8K7AtGYBwf 5hS8HEx3jrXcOwajLBsNaIBulqhFzEEfLQUkQ= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777933; x=1788382733; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=pn1ziw/2Ct0AV93+LleKcaEf4OfiR5j3sKq4oZLw3Ag=; b=A5g1rmbjU2JPD4esk9Co74lr453BaR7DdC5anaJh7GN/gcxpR0+vyXNnNNUlepPF6e EXKpukzDVQsp3ksE5m1o67yKahGpVhAEkrWxa4oHaWAvVRRr7PGS2vnmKieuRuPuLXmX CrJBjJH4j803dbbOtCsKb/G70Gd4vbyk+sEQ6eWEbaPC1PnO9gwvqWDgmJIO81XyTGCj Oxdk/cfckFbehNXoB/G8phUzw/SRE1VgnM+MxQUQ7PoBwTzwOsH1xE63dsfAzoPEhrlP 2N+DTb7IDI2m+4/GtEEBl6s2jBq0uhEVFGHX98jkQytEVSnOnl3+La5wC5b9z6dMRmzp zgQQ== X-Gm-Message-State: AFuF++m+ELrZ0PSHi+vzmr0qhYusQgc+Vdp7AmnsTGM6TdxKBDsMP4YS umdXPXFK9U2Y8E74aBOPmcr3hixVfYg76etpOkWf3buV7SCEzAS2ethLDJ/qSetdOXT0aTIdDxM E4+pb X-Gm-Gg: AR+sD13fP0xWSdgoLbXBkePeQ/yFWX3KTxfQItLWcaC2G+jNa4hYgeA/XSRAazc1t3d +xQLFHL7EPFIh4Bg/BLFSaF4P/E9I5JXaxx2c5+CoYAcRiWwMiDM+K4nVEj9Z7yl6xcvwDzEyaf Fb7uXIkfgZJIGVHk5Ny8/1l38Nt0/TOmA7gT14uS7JcZYs1jM1A/y+xfJKEXYblGm8IQ5GaLFrM b6O0jNkbHcty3iSjvxQIYmCXUBUfK5Pjjvmu+5N8dBDwQfHQpYvaQQUUifLL0/nK2tQ5rQ/p0WB gfA2Z0ZJ8QvoboKd5ERThUVHvskucNAg+idhFvtyuOBfAafUQXU+CqOVwIihas89oU54Clt8C2w CCjk29Y3ug4ThbUv/oebsiZxv52F8Rt/XocZB7AFcYhspTlYU/qW34usQ7G742UyOUZjwccUUCl R2dG5eQXwwH7xEjSojBsEQe0k4DGkthiSNNJDjzCb4VrOBjU0NeUdRdLrYzFaekxL1UlRsrTVdW 2RuhPeezZCzTjkEYzFB9FT7sq29yg905EfgMTOEe0P5SxCYjpF0Z27WSaEH1+dQD1PdNn/Rjg3u NYZ8YFERacFJsE1nnQZxG3otc94= X-Received: by 2002:a05:622a:8e0a:b0:52f:a0b3:bcb2 with SMTP id d75a77b69052e-52fa0b42525mr30240751cf.35.1787777933262; Wed, 26 Aug 2026 13:58:53 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.52 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:52 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 10/15] tpm2-tss: set status for CVE-2024-29040 Date: Wed, 26 Aug 2026 16:57:44 -0400 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:59:04 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4702 From: Peter Marko CVE-2024-29040 is per Debian report [2] fixed in 4.1.0. [1] https://security-tracker.debian.org/tracker/CVE-2024-29040 Signed-off-by: Peter Marko Signed-off-by: Scott Murray --- meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb b/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb index f8e87a5..30e984e 100644 --- a/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb +++ b/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb @@ -94,3 +94,5 @@ FILES:${PN} = "\ ${sysconfdir}/sysusers.d" BBCLASSEXTEND = "native nativesdk" + +CVE_STATUS[CVE-2024-29040] = "fixed-version: Fixed since version 4.1.0" From patchwork Wed Aug 26 20:57:45 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96494 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4768CC61DC7 for ; Wed, 26 Aug 2026 20:59:04 +0000 (UTC) Received: from mail-qv1-f49.google.com (mail-qv1-f49.google.com [209.85.219.49]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.22439.1787777935486617786 for ; Wed, 26 Aug 2026 13:58:55 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=ui0gBouR; spf=pass (domain: konsulko.com, ip: 209.85.219.49, mailfrom: scott.murray@konsulko.com) Received: by mail-qv1-f49.google.com with SMTP id 6a1803df08f44-90cd3aaf01bso3127736d6.2 for ; Wed, 26 Aug 2026 13:58:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777934; x=1788382734; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=I31Vdyl6cARUirtJO4XD3a1m7dRZ6vcf3KuG8CoR+vg=; b=ui0gBouRYAhQduyrvkH75uYiD88oq+q4+mXfG4Fa3Reg8BBA93jNv76iZ8XKt+dA5M S9TgbSkYIFlV1+zqT0MOeGQAUU9DoGIpG0fNmfiEw/iFkFEw/kLvh9cxUXfdIUq/9EcB TJX9Ggd1O2QPUZlZQAjv3mIv5Xk+sNAk7CUN0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777934; x=1788382734; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=I31Vdyl6cARUirtJO4XD3a1m7dRZ6vcf3KuG8CoR+vg=; b=CDFKLwBlE395H8F8LLl/4wHehIe4l+u2g0U6m66XOZvgTRgA1G3F01glh5oUwHdtde BbNpGj7fKZGuul4Jr/ADnCtsKSvkkNAGPq6O64kKuURACOA1HEvF2AN2XugbOvRJBTfS kctFxA8XFv6JtGyCrVDTIBuPIORhqruo+7FgpDYoEt8ZYxT9eJFpfJ2QV1+77WpI0FH0 dCJzRujws8xWTSNmKRsrnryS26xP+8QYxZg+ViJPci2layoAwp39bgPbaDK+MSMlEJSi XNsskqOO9R+MXo5HPX2ZUTUY2oaAwC9B7uO4DzdTzv1YmvM0rPpimIq9WgbQ9EfjQagS RVaw== X-Gm-Message-State: AFuF++l1/H5m3JlrJ+3sUWw2g7OddFcGWaLBURudk4rocjjYJ7EYdJvH hQuMREnOgkoJaUL7kkoeI42eKIAGUgoFvIiXJ7LiRjETQ9uPnNM86dhQImp6h8MKvdQW/K/s0bC or/uJ X-Gm-Gg: AR+sD11rWz8M3DPL8e70IPhSVIjJ65VkdUSHWoLm3KpP761utRhRxMoYpnS7AQupWL8 jS+V8qPE3R26Gw/Dy3ff7EKWC9yM0FuGVk5hQkHoE8OCOIGGJQzhHyMfub9uVcADByNC63p1aJV OL4UsvbADDR/xTI0LO4VcFJ84dxdKXkFNn28zuG1V0vcIY40b4xAucIBjYI0XktNFi3wMKkHI+t 5PVPPRqPU317s+TbZXv+zB1bDnfsO6NySCW8TQERnp1x8+d1+BESH1GEbLF4GE0I40tVgTFL41D CyK+vZlQvic+Ba5aKDSaPiQ6gY4bIsruJKM56K+rV5dGl8vpgVXPG982zQ1NxRxOtR9a0QOKY/0 pYpcXCrJ+EBLJ4fRch21AQG71PjH1PNiK8U2vQVlL3wXcZHPXYmslrt+71evJbyBaBd8CejeuUk NNqneHX2JJHGtzK5fwBT9H4p6tVffgHv10o7XoNRyWwvcggWpjDJcPcnhKW3hnw8uFDpLQxP5UR 5vE47TYFaAKkH+dHr1b5hXI3+dl2yHbHevLPDDmB8Rz2o7gIuuZXPMlalHSv4+QKldzeGdSD3ow oBZe+Ik68VRlOrAWcbuEWzjPQ2+3+y/lzb/z X-Received: by 2002:a05:6214:4606:b0:907:64a4:ca00 with SMTP id 6a1803df08f44-90cc7958781mr127615176d6.10.1787777934219; Wed, 26 Aug 2026 13:58:54 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.53 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:53 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 11/15] tpm2-tools: fix PACKAGECONFIG typo Date: Wed, 26 Aug 2026 16:57:45 -0400 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:59:04 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4703 From: Krupal Ka Patel Correct the misspelled PACKAGECONFIG variable so efivar is enabled by default as intended by commit cdb4e444acbb2b9df467d716241a206c9ea6d3b0. Signed-off-by: Krupal Ka Patel Signed-off-by: Scott Murray --- meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb index 5c968dd..7c5d156 100644 --- a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb +++ b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb @@ -15,7 +15,7 @@ UPSTREAM_CHECK_URI = "https://github.com/tpm2-software/${BPN}/releases" inherit autotools pkgconfig bash-completion -PACKAGECONGIG ??= "efivar" +PACKAGECONFIG ??= "efivar" PACKAGECONFIG[efivar] = "--with-efivar,--without-efivar,efivar" BBCLASSEXTEND = "native nativesdk" From patchwork Wed Aug 26 20:57:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96496 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5897FC61DD2 for ; Wed, 26 Aug 2026 20:59:04 +0000 (UTC) Received: from mail-qt1-f182.google.com (mail-qt1-f182.google.com [209.85.160.182]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.22628.1787777936469636589 for ; Wed, 26 Aug 2026 13:58:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=Ik1EII2N; spf=pass (domain: konsulko.com, ip: 209.85.160.182, mailfrom: scott.murray@konsulko.com) Received: by mail-qt1-f182.google.com with SMTP id d75a77b69052e-52fa6005224so403331cf.1 for ; Wed, 26 Aug 2026 13:58:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777935; x=1788382735; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=VGV7O+F4SRTRkABEgWl0cRqj1h0m1muH60y/rE/OVms=; b=Ik1EII2NONEtn7q9BmVbaEXFxfMEnE1mh/pUa2iswMJOTp1sR+qtn9DfujcpNn28F5 rMzWQVRdZWxZAVuIeOb2ymGv3MetdD+9iL1LPzfK5V6RxkQ+kk62wvIVb3KZOBRADQi9 t60WQ5DDZ381UdWadh24K7p8s6Y6lrZ9seUUI= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777935; x=1788382735; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=VGV7O+F4SRTRkABEgWl0cRqj1h0m1muH60y/rE/OVms=; b=ODNPhb+yHvXnvGgs2v0lf2xVwcs/u/led1FjRckCqQM3rmxmB7V0413kmNeGUkgp74 k5qsDgyFBAzLiA85ODJK5AofC5wgsUpMbrbcUbzLsOxx4++AwYY29nD6lPf+asrmKCaH RzrNPWvMN8NDpuVcUBdLXR6t90/YHO8FmScQb/fZmYg5u+ec1DYe3mSP0nvIoH1JFTfz uKcddv18IScGTv5IfwhsjwlA/uBb4KmEml7J7dimWl4Z/l7NjEhjRn7Lr+xCuHKYGgsm YBIP/xgdqiyMEO3Coy34R8bq+GZI8XsshdXorv4xma7dIYodJqlD2Pc8zYU6X8JbthrV JoRQ== X-Gm-Message-State: AFuF++nyaAkQZUxX+OlbbqT3hSf0TkFWRlHT3NQf995ba7gkgA4Fwhj9 tFpM9vcX7XMCh/aaaUbaBsp3puDFPjIXuQjw7TdflbYoiBEdXODJ217c2SZQdhkaDGA6XZbPhWs P49fJ X-Gm-Gg: AR+sD11K+CWd0mRIK7g7qyIdhsNd8oBRV0hcKJoNgfZJEtlAMyo3F3cpKRwIkCiOLBJ CzM8yLiHhme2wo25/x1PQcQdpLdKeY9mHYbETj+mrYnZSytSsqEfYQ2wzjEvoWNLQv92KKqvYRV SNdXKgfIFPIolSWf7H4lwLoO2O3hIQPvWyFx0XxYZ+tErmSH0OsHDaMsi0eo7glptT1lR0s3rbs WS92xOeUkEayl5tJb5BO4thGQndo3NV6zt+uBXkMrvqWzWiB5fnWE3WCEjLmCbcywFSn+7sJjdo tJn+jOo99Hoc4OkSEBB8Zqr+bm/xOeuB0ypAFeCNXKO4CQVriwCkknNjvuzxTQvm0Uyy1bd84mw hqe1ulBvrGBgOugKo0gfOda6RXez7Kd/Qodwr/GPcwHsZu7lSb13x3xxe8/WWh5qXT7SxcZEN2O 9Xr2tI++zVBuSNS8pT1eiAWIV8wa5XpqfuucF6LHRXKVKoP+6A1jMOVgcEd6pDIquK0OshrNpuz dmMpT9KBSg9if4Yu8w8Nr8oHuA0CNrG5YK0HxC+3+/Culug6cJx2TQXk8WDs/lNIPeWeMQ30yJE un2BAjEnVZj3dX0nPstSooYokw== X-Received: by 2002:a05:622a:844c:10b0:52f:a2c0:1451 with SMTP id d75a77b69052e-52fa2c02c03mr13838551cf.7.1787777935134; Wed, 26 Aug 2026 13:58:55 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.54 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:54 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 12/15] fix LICENSE variable syntax to suppress QA warning Date: Wed, 26 Aug 2026 16:57:46 -0400 Message-ID: X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:59:04 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4704 From: Wang Mingyu Signed-off-by: Wang Mingyu Signed-off-by: Scott Murray --- recipes-ids/crowdsec/crowdsec-licenses.inc | 2 +- recipes-ids/crowdsec/crowdsec_1.7.7.bb | 2 +- recipes-mac/AppArmor/apparmor_4.0.3.bb | 2 +- recipes-perl/perl/lib-perl_0.63.bb | 2 +- recipes-perl/perl/libwhisker2-perl_2.5.bb | 2 +- recipes-scanners/clamav/clamav_1.4.4.bb | 4 ++-- recipes-security/libgssglue/libgssglue_0.9.bb | 2 +- 7 files changed, 8 insertions(+), 8 deletions(-) diff --git a/recipes-ids/crowdsec/crowdsec-licenses.inc b/recipes-ids/crowdsec/crowdsec-licenses.inc index cb45b10..92f5dc6 100644 --- a/recipes-ids/crowdsec/crowdsec-licenses.inc +++ b/recipes-ids/crowdsec/crowdsec-licenses.inc @@ -4,7 +4,7 @@ # Do not modify it by hand, as the contents will be replaced when # running the update-modules task. -LICENSE += "& Apache-2.0 & BSD-2-Clause & BSD-3-Clause & ISC & MIT & MPL-2.0 & WTFPL" +LICENSE += "AND Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND ISC AND MIT AND MPL-2.0 AND WTFPL" LIC_FILES_CHKSUM += "\ file://pkg/mod/ariga.io/atlas@v0.31.1-0.20250212144724-069be8033e83/LICENSE;md5=175792518e4ac015ab6696d16c4f607e;spdx=Apache-2.0 \ diff --git a/recipes-ids/crowdsec/crowdsec_1.7.7.bb b/recipes-ids/crowdsec/crowdsec_1.7.7.bb index 0697022..356c227 100644 --- a/recipes-ids/crowdsec/crowdsec_1.7.7.bb +++ b/recipes-ids/crowdsec/crowdsec_1.7.7.bb @@ -1,7 +1,7 @@ SUMMARY = "CrowdSec is a free, modern & collaborative behavior detection engine, coupled with a global IP reputation network." DESCRIPTION = "Open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI." HOMEPAGE = "https://www.crowdsec.net" -LICENSE = "MIT & CC0-1.0" +LICENSE = "MIT AND CC0-1.0" LIC_FILES_CHKSUM = "file://src/${GO_IMPORT}/LICENSE;md5=1e58fe4126ce0b50677f3aa6ba8e13c2 \ file://src/${GO_IMPORT}/build/windows/Chocolatey/crowdsec/tools/LICENSE.txt;md5=4d249f04094c9fb4d2b6fd2b1127e219 \ file://src/${GO_IMPORT}/test/lib/bats-assert/LICENSE;md5=7bae63a234e80ee7c6427dce9fdba6cc \ diff --git a/recipes-mac/AppArmor/apparmor_4.0.3.bb b/recipes-mac/AppArmor/apparmor_4.0.3.bb index 9983157..76025bd 100644 --- a/recipes-mac/AppArmor/apparmor_4.0.3.bb +++ b/recipes-mac/AppArmor/apparmor_4.0.3.bb @@ -8,7 +8,7 @@ DESCRIPTION = "user-space parser utility for AppArmor \ HOMEPAGE = "http://apparmor.net/" SECTION = "admin" -LICENSE = "GPL-2.0-only & GPL-2.0-or-later & BSD-3-Clause & LGPL-2.1-or-later" +LICENSE = "GPL-2.0-only AND GPL-2.0-or-later AND BSD-3-Clause AND LGPL-2.1-or-later" LIC_FILES_CHKSUM = "file://${S}/LICENSE;md5=fd57a4b0bc782d7b80fd431f10bbf9d0" DEPENDS = "bison-native apr autoconf-archive-native gettext-native coreutils-native swig-native" diff --git a/recipes-perl/perl/lib-perl_0.63.bb b/recipes-perl/perl/lib-perl_0.63.bb index f0d6832..c0fb43a 100644 --- a/recipes-perl/perl/lib-perl_0.63.bb +++ b/recipes-perl/perl/lib-perl_0.63.bb @@ -5,7 +5,7 @@ will find modules which are not located in the default search path." SECTION = "libs" HOMEPAGE = "https://metacpan.org/dist/lib" -LICENSE = "Artistic-1.0 | GPL-1.0-or-later" +LICENSE = "Artistic-1.0 OR GPL-1.0-or-later" PR = "r0" LIC_FILES_CHKSUM = "file://README;beginline=26;endline=30;md5=94b119f1a7b8d611efc89b5d562a1a50" diff --git a/recipes-perl/perl/libwhisker2-perl_2.5.bb b/recipes-perl/perl/libwhisker2-perl_2.5.bb index e16e5f2..94b2384 100644 --- a/recipes-perl/perl/libwhisker2-perl_2.5.bb +++ b/recipes-perl/perl/libwhisker2-perl_2.5.bb @@ -1,7 +1,7 @@ DESCRIPTION = "Libwhisker is a Perl module geared specificly for HTTP testing." SECTION = "libs" -LICENSE = "Artistic-1.0 | GPL-1.0-or-later" +LICENSE = "Artistic-1.0 OR GPL-1.0-or-later" LIC_FILES_CHKSUM = "file://LICENSE;md5=254b8e29606fce6d1c1a4c9e32354573" diff --git a/recipes-scanners/clamav/clamav_1.4.4.bb b/recipes-scanners/clamav/clamav_1.4.4.bb index e9c2aca..b3f14cd 100644 --- a/recipes-scanners/clamav/clamav_1.4.4.bb +++ b/recipes-scanners/clamav/clamav_1.4.4.bb @@ -1,8 +1,8 @@ SUMMARY = "ClamAV anti-virus utilities and scanner tools" -DESCRIPTION = "ClamAV is an open source antivirus engine for detecting trojans, viruses, malware & other malicious threats." +DESCRIPTION = "ClamAV is an open source antivirus engine for detecting trojans, viruses, malware AND other malicious threats." HOMEPAGE = "http://www.clamav.net/index.html" SECTION = "security" -LICENSE = "GPL-2.0-only & LGPL-2.1-only & BSD-2-Clause & Zlib & Apache-2.0-with-LLVM-exception" +LICENSE = "GPL-2.0-only AND LGPL-2.1-only AND BSD-2-Clause AND Zlib AND Apache-2.0-with-LLVM-exception" LIC_FILES_CHKSUM = "file://COPYING.txt;md5=2c0b5770a62017a3121c69bb9f680b0c \ file://COPYING/COPYING.LGPL;md5=2d5025d4aa3495befef8f17206a5b0a1 \ file://COPYING/COPYING.bzip2;md5=ae8d555c34b656ff864ea9437a10d3a0 \ diff --git a/recipes-security/libgssglue/libgssglue_0.9.bb b/recipes-security/libgssglue/libgssglue_0.9.bb index 0952ed1..9b33ce9 100644 --- a/recipes-security/libgssglue/libgssglue_0.9.bb +++ b/recipes-security/libgssglue/libgssglue_0.9.bb @@ -8,7 +8,7 @@ depending on the mechanism. \ HOMEPAGE = "https://gitlab.com/gsasl/libgssglue" SECTION = "libs" -LICENSE = "BSD-3-Clause | HPND" +LICENSE = "BSD-3-Clause OR HPND" #Copyright (c) 1996, by Sun Microsystems, Inc. HPND #Copyright (c) 2007 The Regents of the University of Michigan. BSD-3-Clause From patchwork Wed Aug 26 20:57:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96497 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 816AEC61DCD for ; Wed, 26 Aug 2026 20:59:04 +0000 (UTC) Received: from mail-qt1-f174.google.com (mail-qt1-f174.google.com [209.85.160.174]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.22440.1787777937337291707 for ; Wed, 26 Aug 2026 13:58:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=jx8UHgzL; spf=pass (domain: konsulko.com, ip: 209.85.160.174, mailfrom: scott.murray@konsulko.com) Received: by mail-qt1-f174.google.com with SMTP id d75a77b69052e-52f9fc510e1so2282461cf.0 for ; Wed, 26 Aug 2026 13:58:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777936; x=1788382736; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=uIzjFyKAE+nT/7IgPCDo0Ild3McayTNNgUw+l2eC7hk=; b=jx8UHgzLxMENm8jkNhLkd73QJ+U8tbzQnpRb/3jfRyAgT5s4kWang43PC89galCv87 S6hntftY4lKsDRMH41jNBB2X+4aqWBRtciStkthN0Sv7+rumdk0OycrnhImBhVrbuJvF EyTtCS2NsNgngyx2yjKSeCMGRg54laCjO7Eeg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777936; x=1788382736; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=uIzjFyKAE+nT/7IgPCDo0Ild3McayTNNgUw+l2eC7hk=; b=jGZTBT08UahGxh7hxzzF86se+6dAFMvkAkfsHemsCR+8fycDPJd73Q3/Eg7PFazd/l TcVtPrhfJBRNihVI2Jdj7+ECTnHAAotS48L+YMFmSM6dasjs2FLbd/fbNvTsbWBOJjH1 2wSLOkBGgDE8q9FfcUkUfoPVv7g9yYf5N2hIMu9KP35eyicNBHNiBcNWF8czIUUPIF1v MDw51ndWyc6gV5zQZxE6sPAHAEk5FYQZyPln7WLH85X2I13ZCkqOs3HaPz75xkMopWTp l/lYcDT9QU7LwXoeWVBFvLHcGqqCJIXA4XKznOHoIPgda3jr6sU6jWCnWbb58t+CxGcb ZyeA== X-Gm-Message-State: AFuF++mQiXBGi5xel6gTv16tZZJIzzymVmsQVkdMYHF+pB1nP8DSQZui vtWe7Bwi3mur4swJCbrnwrx4zHlXzRJYGlUXQL7TTA/R8Uho+CSYP6prZbs3vNkYhAnY8iegNY+ IDI8x X-Gm-Gg: AR+sD114XML+zAVDyAqHaP5pUxdDNa0VcO/VJL3eGv8rEWuzMEf3uxWY6PL/bp8r5G6 eJNSkCzP1aO81UrClOumljSZOKX2oKCyYI5MSbE1N9096k784NwCC2RoCzqgkj/AYM9+3OlZsXf pl8oz1UWOueAU7bXWI1bL0aFy7eePgl9EZCKAbU2pW7Qx/plVA3TXN5ORlaIi9OIyH928HzYEZg Fp3yjuGv5ljXP7E7mqjB/lSWU6wftDSzDGXjZEoCgnzrOKv46TRsF4IOCffnf+bsXsp+owduBLq Zm5IraKSKnWt1/ixuGIEOA9ZCWbxct79VFn5grJ738kII5NF4er8tppQSyi+htyX/nlRgus0rkf SMbtWA6J/dBQwA1Up0F/184qWC5U6QPzpvuU+8C/9+qWLIZJLayqFxm1svd6/1n9m4VA8ONzqK8 ROoWDdID+VDM1u48XlKk9tOEkSR2xZtp0/DHq2cKLBVUUB9w3pz9lqjM4nvizuPKeF8ML4GDOe0 G0DMY00HcIhqGxOVkBrUnKhdOyh8TGlJymPkZf5LGDj0Trdmq1T0XovRxEvJzoUUHhU9KQvfESt ITGWIoHZQNSI5fimBj13fReGcw== X-Received: by 2002:ac8:6906:0:b0:50e:474a:47e1 with SMTP id d75a77b69052e-52fa1bb79c7mr28764641cf.10.1787777936142; Wed, 26 Aug 2026 13:58:56 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.55 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:55 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 13/15] meta-integrity: Fix ima-evm-utils LICENSE Date: Wed, 26 Aug 2026 16:57:47 -0400 Message-ID: <91c2bfdcc2565d197d3c57e44a895b3c97631375.1787777775.git.scott.murray@konsulko.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:59:04 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4705 Update for upstream switch to SPDX syntax for LICENSE to silence QA warning. Signed-off-by: Scott Murray --- .../recipes-security/ima-evm-utils/ima-evm-utils_1.5.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/meta-integrity/recipes-security/ima-evm-utils/ima-evm-utils_1.5.bb b/meta-integrity/recipes-security/ima-evm-utils/ima-evm-utils_1.5.bb index ac0a383..c382cf4 100644 --- a/meta-integrity/recipes-security/ima-evm-utils/ima-evm-utils_1.5.bb +++ b/meta-integrity/recipes-security/ima-evm-utils/ima-evm-utils_1.5.bb @@ -1,5 +1,5 @@ DESCRIPTION = "IMA/EVM control utility" -LICENSE = "GPL-2.0-with-OpenSSL-exception" +LICENSE = "LicenseRef-GPL-2.0-with-OpenSSL-exception" LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263" DEPENDS += "openssl attr keyutils" From patchwork Wed Aug 26 20:57:48 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96495 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id C132AC61DC4 for ; Wed, 26 Aug 2026 20:59:03 +0000 (UTC) Received: from mail-qt1-f179.google.com (mail-qt1-f179.google.com [209.85.160.179]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.22441.1787777938153970882 for ; Wed, 26 Aug 2026 13:58:58 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=aY0kRg+N; spf=pass (domain: konsulko.com, ip: 209.85.160.179, mailfrom: scott.murray@konsulko.com) Received: by mail-qt1-f179.google.com with SMTP id d75a77b69052e-52d8748cde5so140011cf.0 for ; Wed, 26 Aug 2026 13:58:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777937; x=1788382737; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=drO7TWnsD5dKGC67T9fihFMC8uJ6JAn7tdAET4ohkRE=; b=aY0kRg+NzH8/bGZsG+0u7tcC6MUjmULb5hiZgAsX3tbZ9AjRrp2lcS9MsKe2AA0Cpu UJ0OmQXKyfwUNJSF+9uCz/Fc6KrWguf6pbZiMZru2LYnkJRt2KrfrpOrwiWCYPnfgIcj E5u6hdORxE5+9spD574RjyuuEr7PUocotHy+I= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777937; x=1788382737; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=drO7TWnsD5dKGC67T9fihFMC8uJ6JAn7tdAET4ohkRE=; b=jdG+2gWm0Hgg2Oj1s62sWyiAdWYVFLpyXGc8x9t7xWhWRKDnjgET3GGF+jEnLpIn9C SPFyxg/BqulhNbyy9pbRHq0JGMq0jKPFnWjth76OTTXFvjJWmEImAEVnQudkFBYQbPrH /Xdat1g1PrFmvj8M7fjXz28aEzgqsd895uJPMUpcwACWxpSyka2LdM4IutKzN+ibgtuq eskWs/dgHjJ3UO6jWeODEKZPPWPOqMSvRUT33h8OKlNfecq3DRBzHE/t2ATy9Daiaz3h fA2kS5if5mmxbJOoohNJGVzXoqtrg71TpC+Nr/y09I/RB3wz45PZuchy4jgLPGgJy58A xBOg== X-Gm-Message-State: AFuF++lu7uyK5IC9u+XyM+O0Z3RC8yw8EM5+Ie9nhycEd7Ys+aPvtwxR 0+MVxtfQyDnDT7acRf5nbX2G44pFWHab/Pgb8930+gmBkKCxg3KxURq5oPzcvpeE7zEENbT09ET wtgf6 X-Gm-Gg: AR+sD10uKhe9y6exhp4QYt6k0521/1oWjrZeru5A4jpCyFpQzXwppVgjjTAsyDc/EqX D7Do7+pj3koSiz0mBOiods3WzssaUUftqUhOBt2QG/2FqMajRSJpgByJDQRsICg7Vlh6195vYQG o1TvN24W5+/Hc0Vr6UnLLjt/5qAmBLvDEBEB6sVRBR5ijoEMPWhqjR3yV9C/ayR/IMA3a5Tri0i soTme5oJ1hJxlVzgOhHn/GJUf0yAaznySqT7F+3h+xMt6muEI+Fcg0gGDS0qGJc5SpVSCltLOOL YDVeGkUSFl9rDt8YqAkXjTlfezf3vue2d7Vk8+239FLlucVJyq9GIvF3b3a+3fBDWrdgA2A+qnP ems9c7VqR9XfhkM8RKbYTj20IrCD/MQTOsVplImlCLbZBvL4yyRssLJ1D8KXlDbdCpoTs5FCAQR 5rQsvWilrYZXmz/oo9Mzj8EuKZXCnzbCX6Etm5fjH7WRYZ0hDIlVLsCDv/A6CS9zmTmYZpC8ubb jOQZURJEda7qsb1SId5WkLf63pDABgIFEvagKDlzOxbq1geIlTTao6HcNo3VzitvlTptXG/UxFm 41S9zGlTNzdLlUwu1302Uvn8iHnR/rRhZZfu X-Received: by 2002:a05:622a:aa8c:10b0:52e:f046:d669 with SMTP id d75a77b69052e-52ef046e209mr32329391cf.14.1787777936845; Wed, 26 Aug 2026 13:58:56 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.56 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:56 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 14/15] meta-tpm: Fix SUMMARY/HOMEPAGE in affected recipes Date: Wed, 26 Aug 2026 16:57:48 -0400 Message-ID: <06a36993a0fd196b1a281042c46b4f2f4165e1cb.1787777775.git.scott.murray@konsulko.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:59:03 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4706 To quiet the missing metadata warnings, switch DESCRIPTION to SUMMARY in the following recipes: - security-tpm-image - security-tpm2-image - packagegroup-security-tpm - openssl-tpm-engine and add HOMEPAGE to these recipes: - libtpms - swtpm - tpm-tools Signed-off-by: Scott Murray --- meta-tpm/recipes-core/images/security-tpm-image.bb | 2 +- meta-tpm/recipes-core/images/security-tpm2-image.bb | 2 +- meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm.bb | 2 +- meta-tpm/recipes-tpm/libtpm/libtpms_0.10.0.bb | 1 + meta-tpm/recipes-tpm/swtpm/swtpm_0.10.0.bb | 1 + .../recipes-tpm1/openssl-tpm-engine/openssl-tpm-engine_0.5.0.bb | 2 +- meta-tpm/recipes-tpm1/tpm-tools/tpm-tools_1.3.9.2.bb | 1 + 7 files changed, 7 insertions(+), 4 deletions(-) diff --git a/meta-tpm/recipes-core/images/security-tpm-image.bb b/meta-tpm/recipes-core/images/security-tpm-image.bb index dbdd309..c6d25a2 100644 --- a/meta-tpm/recipes-core/images/security-tpm-image.bb +++ b/meta-tpm/recipes-core/images/security-tpm-image.bb @@ -1,4 +1,4 @@ -DESCRIPTION = "A small image for building a tpm image for testing" +SUMMARY = "A small image for building a tpm image for testing" IMAGE_FEATURES += "ssh-server-openssh" diff --git a/meta-tpm/recipes-core/images/security-tpm2-image.bb b/meta-tpm/recipes-core/images/security-tpm2-image.bb index 941a661..117d34e 100644 --- a/meta-tpm/recipes-core/images/security-tpm2-image.bb +++ b/meta-tpm/recipes-core/images/security-tpm2-image.bb @@ -1,4 +1,4 @@ -DESCRIPTION = "A small image for building a tpm2 image for testing" +SUMMARY = "A small image for building a tpm2 image for testing" IMAGE_FEATURES += "ssh-server-openssh" diff --git a/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm.bb b/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm.bb index a1d4d44..f92bf01 100644 --- a/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm.bb +++ b/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm.bb @@ -1,4 +1,4 @@ -DESCRIPTION = "Security packagegroup for Poky" +SUMMARY = "Security packagegroup for Poky" LICENSE = "MIT" LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302 \ file://${COREBASE}/meta/COPYING.MIT;md5=3da9cfbcb788c80a0384361b4de20420" diff --git a/meta-tpm/recipes-tpm/libtpm/libtpms_0.10.0.bb b/meta-tpm/recipes-tpm/libtpm/libtpms_0.10.0.bb index 7f00216..2b6f670 100644 --- a/meta-tpm/recipes-tpm/libtpm/libtpms_0.10.0.bb +++ b/meta-tpm/recipes-tpm/libtpm/libtpms_0.10.0.bb @@ -1,4 +1,5 @@ SUMMARY = "LIBPM - Software TPM Library" +HOMEPAGE = "https://github.com/stefanberger/libtpms" LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://LICENSE;md5=e73f0786a936da3814896df06ad225a9" diff --git a/meta-tpm/recipes-tpm/swtpm/swtpm_0.10.0.bb b/meta-tpm/recipes-tpm/swtpm/swtpm_0.10.0.bb index d5470f4..8472f02 100644 --- a/meta-tpm/recipes-tpm/swtpm/swtpm_0.10.0.bb +++ b/meta-tpm/recipes-tpm/swtpm/swtpm_0.10.0.bb @@ -1,4 +1,5 @@ SUMMARY = "SWTPM - Software TPM Emulator" +HOMEPAGE = "https://github.com/stefanberger/swtpm" LICENSE = "BSD-3-Clause" LIC_FILES_CHKSUM = "file://LICENSE;md5=fe8092c832b71ef20dfe4c6d3decb3a8" SECTION = "apps" diff --git a/meta-tpm/recipes-tpm1/openssl-tpm-engine/openssl-tpm-engine_0.5.0.bb b/meta-tpm/recipes-tpm1/openssl-tpm-engine/openssl-tpm-engine_0.5.0.bb index b792151..13f0d0d 100644 --- a/meta-tpm/recipes-tpm1/openssl-tpm-engine/openssl-tpm-engine_0.5.0.bb +++ b/meta-tpm/recipes-tpm1/openssl-tpm-engine/openssl-tpm-engine_0.5.0.bb @@ -1,4 +1,4 @@ -DESCRIPTION = "OpenSSL secure engine based on TPM hardware" +SUMMARY = "OpenSSL secure engine based on TPM hardware" HOMEPAGE = "https://github.com/mgerstner/openssl_tpm_engine" SECTION = "security/tpm" diff --git a/meta-tpm/recipes-tpm1/tpm-tools/tpm-tools_1.3.9.2.bb b/meta-tpm/recipes-tpm1/tpm-tools/tpm-tools_1.3.9.2.bb index 6d911c9..97a7aef 100644 --- a/meta-tpm/recipes-tpm1/tpm-tools/tpm-tools_1.3.9.2.bb +++ b/meta-tpm/recipes-tpm1/tpm-tools/tpm-tools_1.3.9.2.bb @@ -1,4 +1,5 @@ SUMMARY = "The tpm-tools package contains commands to allow the platform administrator the ability to manage and diagnose the platform's TPM." +HOMEPAGE = "https://sourceforge.net/p/trousers/tpm-tools" DESCRIPTION = " \ The tpm-tools package contains commands to allow the platform administrator \ the ability to manage and diagnose the platform's TPM. Additionally, the \ From patchwork Wed Aug 26 20:57:49 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Scott Murray X-Patchwork-Id: 96492 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B2288C5DF97 for ; Wed, 26 Aug 2026 20:59:03 +0000 (UTC) Received: from mail-qt1-f172.google.com (mail-qt1-f172.google.com [209.85.160.172]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.22442.1787777938925603796 for ; Wed, 26 Aug 2026 13:58:59 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@konsulko.com header.s=google header.b=G9EmSUSR; spf=pass (domain: konsulko.com, ip: 209.85.160.172, mailfrom: scott.murray@konsulko.com) Received: by mail-qt1-f172.google.com with SMTP id d75a77b69052e-52d590ce5cdso107551cf.1 for ; Wed, 26 Aug 2026 13:58:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=konsulko.com; s=google; t=1787777938; x=1788382738; darn=lists.yoctoproject.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=5YsrYyLH1PtsYrEVzvnEREoheTcl8kBBgPoyHGeW8xI=; b=G9EmSUSRANa3e8GKxL6LV6tCKGfX98r5PhqYciN5KTsdSsVjzpbDQ6Z0kPO5zGjuws nwsBFw6e9ZVyZWrJiXPvGhWegOUskClzaPRBUzpTz3CjLod+JWpnGzOqnlWhuY51QC/2 DQUY68HLnpBEVVaIMYbofDvXa84+a4F9yEiww= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787777938; x=1788382738; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=5YsrYyLH1PtsYrEVzvnEREoheTcl8kBBgPoyHGeW8xI=; b=CGsWczFIGtZ9ih494GtNbuffUPZp2NJ4xTKTDfypUXhkikyYbWR7b4KnnxsgCp0YzC aaxxI0+rsykQiqQI+M+L6lwYEO5o08KFPcE8xaPb4uBuCvsPAVbEEOgYUDIREbrE3Ahx F1ZjYugj8nPSJLVDDQDdcGzzzERrpD/sfcPo/+s2Bnyd0OJMj+o6Y0W9RrNh7qBIuNu8 qyLqfomTt0f3H3b8/73qtQHS7dMjs4doj07svkd0p4/E5EZ/GPEukwQPNf4c+Varb3M8 nkBgnf5dOWVo/6V74OhAtBVKwEeMJhexrZkpLkMTBxVh9huR2xcP73aThas3E8d+OI/C i5ow== X-Gm-Message-State: AFuF++n9jzqN8VlG+jctgpWR7QhXAUYG3IC5ReuIjkLlk8v45XboTTvK 7YDy1bJcyE1Hkym4BLZJLmcjZpM4HAU6UX0fU3xm5j1ATbhddS3/Cg14G1x13UcH+3hhcqAyBhr K1llO X-Gm-Gg: AR+sD10vcjTvE6+v/oSvSbXKNQ4UcgIxILvd2JJNINSl1tHo3YxWUyqRz2sdrIakFOW x6Ezm3uUw3mDLcmBmgp8tgdYoBLhDkWc12JtakkQh+CGEXGm+PoCwQSOv0H7rY5/JsxMdHt8n8+ cBswNC6Hi+9Mm6V6EahXY/ffPaHt4+RfhxOr6YKMNJu2HZy2BQ6Ky7Pz2qp6wVybWa0PxDa/0Pc t5hoZR4aRlFhqNFDVi7lxMCYbJp0r1ZtQMR1Mz06kHjkT787W7xJDjqJYd1Tuwgzv9XsGFfflf6 vH8NAEuiP9ce5hUbzaMr3F8pyvYvWOZoUc1cwg7PUblgCP/0c0hObxhoLgw3UxH3AJzGhg+7bmC 15uhHLK2OOhaIRRdoX5kRiRb5doe/FoIdwVMM01ICHNIb/PxYR+fESOFioh2U/bOxg4cHHsF+YX ceLNMeZ51eHHdlG4Zq27YmxBuWwuJBEIP6Pu3SqgbtBoofSG3bmsbuYSzkg5sH+EWEBaghc61tM khJAK3jN9+Bb1fOdHpSN/bEKHPKWTGfbIuT4cfB0lGCGVHd7Tkewr9A+/waY3EIuaxlNWY0Gg2K f3S6V/vOpP/Q7veVnBlVJbE+cwp42KFIHTzw X-Received: by 2002:a05:622a:1303:b0:50d:e471:2d1e with SMTP id d75a77b69052e-52e42371acamr106692221cf.35.1787777937677; Wed, 26 Aug 2026 13:58:57 -0700 (PDT) Received: from ghidorah.spiteful.org (107-179-213-3.cpe.teksavvy.com. [107.179.213.3]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90cc65093d5sm35135856d6.26.2026.08.26.13.58.57 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 26 Aug 2026 13:58:57 -0700 (PDT) From: Scott Murray To: yocto-patches@lists.yoctoproject.org Subject: [meta-security][PATCH 15/15] aide: Fix unstable install task hash Date: Wed, 26 Aug 2026 16:57:49 -0400 Message-ID: <0339b65f63877ed36fcffa44953e57c3bb969ca9.1787777775.git.scott.murray@konsulko.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Wed, 26 Aug 2026 20:59:03 -0000 X-Groupsio-URL: https://lists.yoctoproject.org/g/yocto-patches/message/4707 From: Esa Jaaskela The installation task hash for the aide is marked as nostamp. This is done because the native task installs files outside the sysroot, to the Aide staging directory. Those files are not captured by do_populate_sysroot, so they are missing whenever the task is skipped or restored from sstate. Install the required native contents to the sysroot, and then customise and deploy the configuration file in the aide_init_db rootfs postprocess function that utilizes the files. The configuration file needs to be reset every time the function is run to avoid using stale configurations. Staging the native files through the sysroot makes the nostamp unnecessary, so remove it along with the unstable task hash it caused. Signed-off-by: Esa Jaaskela Signed-off-by: Scott Murray --- classes/aide-db-init.bbclass | 11 +++++++++-- recipes-ids/aide/aide_0.19.3.bb | 13 ++++--------- 2 files changed, 13 insertions(+), 11 deletions(-) diff --git a/classes/aide-db-init.bbclass b/classes/aide-db-init.bbclass index 800006f..3fe2c27 100644 --- a/classes/aide-db-init.bbclass +++ b/classes/aide-db-init.bbclass @@ -31,6 +31,13 @@ inherit aide-base aide_init_db() { + install -d ${STAGING_AIDE_DIR}/lib/logs + rm -f ${STAGING_AIDE_DIR}/aide.conf ${STAGING_AIDE_DIR}/lib/aide.db ${STAGING_AIDE_DIR}/lib/aide.db.gz ${STAGING_AIDE_DIR}/lib/logs/aide.log + install ${STAGING_DATADIR_NATIVE}/aide/aide.conf ${STAGING_AIDE_DIR}/ + + sed -i -s "s:\@\@define DBDIR.*:\@\@define DBDIR ${STAGING_AIDE_DIR}/lib:" ${STAGING_AIDE_DIR}/aide.conf + sed -i -e "s:\@\@define LOGDIR.*:\@\@define LOGDIR ${STAGING_AIDE_DIR}/lib/logs:" ${STAGING_AIDE_DIR}/aide.conf + for dir in ${AIDE_INCLUDE_DIRS}; do echo "${IMAGE_ROOTFS}${dir} NORMAL" >> ${STAGING_AIDE_DIR}/aide.conf done @@ -39,7 +46,7 @@ aide_init_db() { done - ${STAGING_AIDE_DIR}/bin/aide -c ${STAGING_AIDE_DIR}/aide.conf --init + ${STAGING_BINDIR_NATIVE}/aide -c ${STAGING_AIDE_DIR}/aide.conf --init gunzip ${STAGING_AIDE_DIR}/lib/aide.db.gz # strip out native path sed -i -e 's:${IMAGE_ROOTFS}::' ${STAGING_AIDE_DIR}/lib/aide.db @@ -47,6 +54,6 @@ aide_init_db() { cp -f ${STAGING_AIDE_DIR}/lib/aide.db.gz ${IMAGE_ROOTFS}${libdir}/aide } -EXTRA_IMAGEDEPENDS:append = " aide-native" +do_rootfs[depends] += "aide-native:do_populate_sysroot" ROOTFS_POSTPROCESS_COMMAND:append = " aide_init_db;" diff --git a/recipes-ids/aide/aide_0.19.3.bb b/recipes-ids/aide/aide_0.19.3.bb index 8d4efbb..c352583 100644 --- a/recipes-ids/aide/aide_0.19.3.bb +++ b/recipes-ids/aide/aide_0.19.3.bb @@ -32,8 +32,6 @@ PACKAGECONFIG[e2fsattrs] = "--with-e2fsattrs, --without-e2fsattrs, e2fsprogs, e2 PACKAGECONFIG[capabilities] = "--with-capabilities, --without-capabilities, libcap, libcap" PACKAGECONFIG[posix-acl] = "--with-posix-acl, --without-posix-acl, acl, acl" -do_install[nostamp] = "1" - do_install:append () { install -d ${D}${libdir}/${PN}/logs install -d ${D}${sysconfdir} @@ -48,14 +46,11 @@ do_install:append () { } do_install:class-native () { - install -d ${STAGING_AIDE_DIR}/bin - install -d ${STAGING_AIDE_DIR}/lib/logs - - install ${B}/aide ${STAGING_AIDE_DIR}/bin - install ${UNPACKDIR}/aide.conf ${STAGING_AIDE_DIR}/ + install -d ${D}${bindir} + install -d ${D}${datadir}/${BPN} - sed -i -s "s:\@\@define DBDIR.*:\@\@define DBDIR ${STAGING_AIDE_DIR}/lib:" ${STAGING_AIDE_DIR}/aide.conf - sed -i -e "s:\@\@define LOGDIR.*:\@\@define LOGDIR ${STAGING_AIDE_DIR}/lib/logs:" ${STAGING_AIDE_DIR}/aide.conf + install ${B}/aide ${D}${bindir} + install ${UNPACKDIR}/aide.conf ${D}${datadir}/${BPN}/ } CONF_FILE = "${sysconfdir}/aide.conf"