[yocto] Next Zeus Dot release in May

2020-04-28 Thread akuster
Our next bot release is coming up so this is a call for patches. Please have them on the list by this Friday. Planned upcoming dot releases: * YP 3.0.3 build date 2020/5/4 * YP 3.0.3 release date 2020/5/15 -=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Rep

Re: [yocto] [bitbake-devel] [poky] Thud community support

2020-04-29 Thread akuster
he community maintainer selection process. The ultimate decision will always be on the Repo maintainer which in this case is Richard. - armin > https://wiki.yoctoproject.org/wiki/Releases still says Community support. > > Thanks > > On Tue, Mar 17, 2020 at 10:13 PM akuster <mailt

[yocto] 3.2 (Gatesgarth ) assistance

2020-05-10 Thread akuster
Hello, The Yocto Project and OE bug triage are seeking some assistance on tasks we hope to addressed into 3.2. The first milestone for 3.2 is targeted for 2020/6/16.   If anyone is interested in helping or seeking a new  challenge, please  take a look in the list below to see if anything interest

Re: [yocto] QA notification for completed autobuilder build (yocto-2.7.4.rc2)

2020-05-27 Thread akuster
ct.org > Cc: ota...@ossystems.com.br; yi.z...@windriver.com; apoorv.san...@intel.com; > ee.peng.y...@intel.com; aaron.chun.yew.c...@intel.com; > richard.pur...@linuxfoundation.org; akuster...@gmail.com; > sjolley.yp...@gmail.com; sangeeta.j...@intel.com > Subject: [yocto] QA notification

Re: [yocto] QA notification for completed autobuilder build (yocto-2.7.4.rc2)

2020-05-28 Thread akuster
; >> -Original Message- >> From: yocto@lists.yoctoproject.org On Behalf >> Of pokybu...@ubuntu1804-ty-1.yocto.io >> Sent: Wednesday, 27 May, 2020 8:09 PM >> To: yocto@lists.yoctoproject.org >> Cc: ota...@ossystems.com.br; yi.z...@windriver.com; San

Re: [yocto] QA completion for completed autobuilder build (yocto-2.7.4.rc2)

2020-06-01 Thread akuster
On 6/1/20 12:25 AM, Jain, Sangeeta wrote: > Hello all, > > This is the full report for yocto-2.7.4.rc2: > https://git.yoctoproject.org/cgit/cgit.cgi/yocto-testresults-contrib/tree/?h=intel-yocto-testresults Thank you. - Armin > > === Summary > No high milestone defects. > No ne

[yocto] Stable Warrior branch

2020-06-04 Thread akuster
Hello, The Warrior branch of Poky has had its last official dot release. It will be moving to Community support and EOL within 6 weeks if no one steps up. If someone is interested in taking on the responsibilities of maintaining the "Warrior" branch moving forward, please email this list. Please

[yocto] Meta-security layer LTS statement

2020-06-12 Thread akuster
Hello all, As the  maintainer for meta-security layer, I will be aligning  with the LTS policy the Yocto Project has defined and the Dunfell branch of meta-security will have the same life cycle of 2 years. Best regards, Armin -=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this g

[yocto] [meta-security][PATCH 6/6] openscap: update to 1.3.3

2020-06-12 Thread akuster
5,8 +5,8 @@ SUMARRY = "NIST Certified SCAP 1.2 toolkit with OE changes" include openscap.inc -SRCREV = "4bbdb46ff651f809d5b38ca08d769790c4bfff90" +SRCREV = "a85943eee400fdbe59234d1c4a02d8cf710c4625" SRC_URI = "git://github.com/akuster/openscap.git;br

[yocto] [meta-security][PATCH 3/6] tpm2-tss-engine: add branch to SRC_URI & update to tip

2020-06-12 Thread akuster
LICENSE changed to BSD 3 Signed-off-by: Armin Kuster --- .../recipes-tpm2/tpm2-tss-engine/tpm2-tss-engine_1.0.1.bb | 8 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/meta-tpm/recipes-tpm2/tpm2-tss-engine/tpm2-tss-engine_1.0.1.bb b/meta-tpm/recipes-tpm2/tpm2-tss-engine/t

[yocto] [meta-security][PATCH 2/6] tpm2-tss: update to 2.4.1

2020-06-12 Thread akuster
Signed-off-by: Armin Kuster --- .../tpm2-tss/{tpm2-tss_2.3.2.bb => tpm2-tss_2.4.1.bb} | 7 ++- 1 file changed, 2 insertions(+), 5 deletions(-) rename meta-tpm/recipes-tpm2/tpm2-tss/{tpm2-tss_2.3.2.bb => tpm2-tss_2.4.1.bb} (82%) diff --git a/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_2.3.

[yocto] [meta-security][PATCH 1/6] tpm2-tools: update to 4.1.3

2020-06-12 Thread akuster
LICENSE changed to BSD3 Signed-off-by: Armin Kuster --- .../recipes-tpm2/tpm2-tools/tpm2-tools_4.1.1.bb | 17 - .../recipes-tpm2/tpm2-tools/tpm2-tools_4.1.3.bb | 13 + 2 files changed, 13 insertions(+), 17 deletions(-) delete mode 100644 meta-tpm/recipes-tpm2/tpm2-to

[yocto] [meta-security][PATCH 4/6] tpm2-pkcs11: update 1.2.0

2020-06-12 Thread akuster
add yaml package Updated LICNESE Signed-off-by: Armin Kuster --- .../{tpm2-pkcs11_0.9.9.bb => tpm2-pkcs11_1.2.0.bb}| 11 +-- 1 file changed, 5 insertions(+), 6 deletions(-) rename meta-tpm/recipes-tpm2/tpm2-pkcs11/{tpm2-pkcs11_0.9.9.bb => tpm2-pkcs11_1.2.0.bb} (67%) diff --git a/m

[yocto] [meta-security][PATCH 5/6] libtpm: update to 0.7.2

2020-06-12 Thread akuster
Signed-off-by: Armin Kuster --- .../recipes-tpm/libtpm/{libtpm_0.7.0.bb => libtpm_0.7.2.bb} | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) rename meta-tpm/recipes-tpm/libtpm/{libtpm_0.7.0.bb => libtpm_0.7.2.bb} (86%) diff --git a/meta-tpm/recipes-tpm/libtpm/libtpm_0.7.0.bb b/meta-

[yocto] [meta-security][PATCH] tpm2-tcti-uefi: drop patch no longer needed

2020-06-14 Thread akuster
drop tpm2-get-caps-fixed.patch, tss update negated the need for this change. Signed-off-by: Armin Kuster --- .../files/tpm2-get-caps-fixed.patch | 23 --- .../tpm2-tcti-uefi/tpm2-tcti-uefi_0.9.9.bb| 4 ++-- 2 files changed, 2 insertions(+), 25 deletions(-) delete

[yocto] [meta-security][zeus][PATCH] tpm2-tss-engine: License changed

2020-06-24 Thread akuster
Fixes this error: ERROR: tpm2-tss-engine-1.0.1-r0 do_populate_lic: QA Issue: tpm2-tss-engine: The LIC_FILES_CHKSUM does not match for file://LICENSE;md5=3fb0047fd29391478a71e8e6101c76eb tpm2-tss-engine: The new md5 checksum is 7b3ab643b9ce041de515d1ed092a36d4 tpm2-tss-engine: Here is the selecte

Re: [yocto] [meta-security][master|dunfell][PATCH 1/2] apparmor: pull in coreutils/findutils only when not using systemd as init manager

2020-07-02 Thread akuster
On 7/2/20 5:00 PM, Jeremy Puhlman wrote: > From: Alexander Kanavin > > The utilities from those packages (xargs, comm) are only used in sysvinit > scripts, and so there is no need to pull them in when systemd is in use. > Both are gpl3 licensed, so this is beneficial for builds where gpl3 is not

Re: [yocto] [meta-security][master|dunfell][PATCH] clamav: Fix issue when yara_grammar.h is regenerated.

2020-07-03 Thread akuster
On 7/2/20 5:01 PM, Jeremy Puhlman wrote: > From: Jeremy Puhlman > > Somewhere a long the line someone hand modified the yara_grammar.h file > but didn't add code to generate the same code. The result is if the > file is regenerated from the .y file it complains about a missing > definition of YR

Re: [yocto] [meta-security][master|dunfell][PATCH] clamav: Fix issue when yara_grammar.h is regenerated.

2020-07-03 Thread akuster
On 7/3/20 9:43 AM, Jeremy Puhlman wrote: > > On 7/2/20 5:01 PM, Jeremy Puhlman wrote: >>> From: Jeremy Puhlman >>> >>> Somewhere a long the line someone hand modified the yara_grammar.h file >>> but didn't add code to generate the same code. The result is if the >>> file is regenerated from the

Re: [yocto] [meta-security][master|dunfell][PATCH] clamav: Fix issue when yara_grammar.h is regenerated.

2020-07-03 Thread akuster
On 7/3/20 9:43 AM, Jeremy Puhlman wrote: > > On 7/2/20 5:01 PM, Jeremy Puhlman wrote: >>> From: Jeremy Puhlman >>> >>> Somewhere a long the line someone hand modified the yara_grammar.h file >>> but didn't add code to generate the same code. The result is if the >>> file is regenerated from the

[yocto] [meta-security][PATCH] suricata: update to 4.1.8

2020-07-05 Thread akuster
Signed-off-by: Armin Kuster --- recipes-ids/suricata/{libhtp_0.5.32.bb => libhtp_0.5.33.bb} | 0 recipes-ids/suricata/suricata.inc| 5 ++--- .../suricata/{suricata_4.1.6.bb => suricata_4.1.8.bb}| 0 3 files changed, 2 insertions(+), 3 deletions(-) rename reci

[yocto] [meta-security][PATCH] packagegroup-core-security-ptest: update fail2ban ptest pkg name

2020-07-05 Thread akuster
Signed-off-by: Armin Kuster --- .../packagegroup/packagegroup-core-security-ptest.bb| 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/recipes-security/packagegroup/packagegroup-core-security-ptest.bb b/recipes-security/packagegroup/packagegroup-core-security-ptest.b

[yocto] [meta-security][PATCH 2/5] python3-qrcode: add recipe

2020-07-05 Thread akuster
Signed-off-by: Armin Kuster --- recipes-python/python/python3-qrcode_6.1.bb | 9 + 1 file changed, 9 insertions(+) create mode 100644 recipes-python/python/python3-qrcode_6.1.bb diff --git a/recipes-python/python/python3-qrcode_6.1.bb b/recipes-python/python/python3-qrcode_6.1.bb new f

[yocto] [meta-security][PATCH 1/5] python3-oauth2client: add recipe

2020-07-05 Thread akuster
Signed-off-by: Armin Kuster --- recipes-python/python/python3-oauth2client_4.1.3.bb | 9 + 1 file changed, 9 insertions(+) create mode 100644 recipes-python/python/python3-oauth2client_4.1.3.bb diff --git a/recipes-python/python/python3-oauth2client_4.1.3.bb b/recipes-python/python/pyt

[yocto] [meta-security][PATCH 4/5] python3-ecdsa: add recipe

2020-07-05 Thread akuster
Signed-off-by: Armin Kuster --- recipes-python/python/python3-ecdsa_0.15.bb | 10 ++ 1 file changed, 10 insertions(+) create mode 100644 recipes-python/python/python3-ecdsa_0.15.bb diff --git a/recipes-python/python/python3-ecdsa_0.15.bb b/recipes-python/python/python3-ecdsa_0.15.bb ne

[yocto] [meta-security][PATCH 3/5] python3-rsa: add recipe

2020-07-05 Thread akuster
Signed-off-by: Armin Kuster --- recipes-python/python/python3-rsa_3.4.2.bb | 44 ++ 1 file changed, 44 insertions(+) create mode 100644 recipes-python/python/python3-rsa_3.4.2.bb diff --git a/recipes-python/python/python3-rsa_3.4.2.bb b/recipes-python/python/python3-rsa_3.4

[yocto] [meta-security][PATCH 5/5] python3-privacyidea: add a mfa support

2020-07-05 Thread akuster
Signed-off-by: Armin Kuster --- .../mfa/python3-privacyidea_3.3.bb| 48 +++ 1 file changed, 48 insertions(+) create mode 100644 recipes-security/mfa/python3-privacyidea_3.3.bb diff --git a/recipes-security/mfa/python3-privacyidea_3.3.bb b/recipes-security/mfa/python

[yocto] [meta-security][PATCH] isafw.bbclass: typo in layer name

2020-07-05 Thread akuster
move class to proper layer Signed-off-by: Armin Kuster --- .../classes/isafw.bbclass | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename {meta-security-isfafw => meta-security-isafw}/classes/isafw.bbclass (100%) diff --git a/meta-security-isfafw

Re: [yocto] [meta-security][PATCH 1/5] python3-oauth2client: add recipe

2020-07-06 Thread akuster
    'pyasn1-modules>=0.0.5', >     'rsa>=3.1.4', >     'six>=1.6.1', > ] > > same applies to the other added recipes of this series hmm, OK. I did not run into issues for the main app I am after supporting.  Thanks for the feedback. -armin > >

Re: [yocto] [meta-security][master|dunfell][PATCH 1/2] cryptsetup-tpm-incubator: RPROVIDES cryptsetup and cryptsetup-dev

2020-07-14 Thread akuster
On 7/13/20 9:00 PM, Jeremy Puhlman wrote: > From: Jeremy Puhlman > > Without this we get weird conflict when you include dev packages: > rror: Transaction check error: > file /usr/include/libcryptsetup.h conflicts between attempted installs of > cryptsetup-tpm-incubator-dev-0.9.9-r0.corei7_64

Re: [yocto] [meta-security][PATCH] bastille: Deleted redundant inherit to fix error when enable multilib.

2020-07-14 Thread akuster
merged On 7/10/20 12:04 AM, zhengruoqin wrote: > There is no need to inherit module-base. Because this inherit will stop > bastille to build to lib32-bastille. > > Signed-off-by: Zheng Ruoqin > --- > recipes-security/bastille/bastille_3.2.1.bb | 2 -- > 1 file changed, 2 deletions(-) > > diff --

Re: [yocto] [meta-security][PATCH] ccs-tools:Fix build error when enable multilib.

2020-07-14 Thread akuster
On 7/6/20 10:30 PM, zhengruoqin wrote: > ERROR: lib32-ccs-tools-1.8.4-r0 do_install: oe_runmake failed > ERROR: lib32-ccs-tools-1.8.4-r0 do_install: Execution of > '/build-armv8/tmp/work/armv7ahf-neon-mllib32-linux-gnueabi/lib32-ccs-tools/1.8.4-r0/temp/run.do_install.22368' > failed with exit cod

[yocto] [meta-security][PATCH 4/6] layer.conf: add dynamic-layer for strongswan

2020-07-16 Thread akuster
Signed-off-by: Armin Kuster --- meta-tpm/conf/layer.conf | 4 1 file changed, 4 insertions(+) diff --git a/meta-tpm/conf/layer.conf b/meta-tpm/conf/layer.conf index c3372c7..46d0279 100644 --- a/meta-tpm/conf/layer.conf +++ b/meta-tpm/conf/layer.conf @@ -15,3 +15,7 @@ LAYERDEPENDS_tpm-layer

[yocto] [meta-security][PATCH 2/6] python3-privacyidea: adding initial support for mfa

2020-07-16 Thread akuster
Signed-off-by: Armin Kuster --- recipes-security/mfa/python3-privacyidea_3.3.bb | 40 + 1 file changed, 40 insertions(+) create mode 100644 recipes-security/mfa/python3-privacyidea_3.3.bb diff --git a/recipes-security/mfa/python3-privacyidea_3.3.bb b/recipes-security/mf

[yocto] [meta-security][PATCH 5/6] strongswan: Add bbappends for ima changes

2020-07-16 Thread akuster
Signed-off-by: Armin Kuster --- .../recipes-support/strongswan/strongswan-ima.inc | 61 ++ .../strongswan/strongswan_5.%.bbappend | 1 + 2 files changed, 62 insertions(+) create mode 100644 meta-integrity/dynamic-layers/meta-networking/recipes-support/strongswa

[yocto] [meta-security][PATCH 3/6] strongswan: add bbappends for tpm changes

2020-07-16 Thread akuster
Signed-off-by: Armin Kuster --- ...01-xfrmi-Only-build-if-libcharon-is-built.patch | 38 ++ .../recipes-support/strongswan/strongswan-tpm.inc | 12 +++ .../strongswan/strongswan_5.%.bbappend | 1 + 3 files changed, 51 insertions(+) create mode 100644 meta-t

[yocto] [meta-security][PATCH 6/6] meta-integrity: add dynamic-layer for strongswan

2020-07-16 Thread akuster
Signed-off-by: Armin Kuster --- meta-integrity/conf/layer.conf | 4 1 file changed, 4 insertions(+) diff --git a/meta-integrity/conf/layer.conf b/meta-integrity/conf/layer.conf index b4edac3..f905b0b 100644 --- a/meta-integrity/conf/layer.conf +++ b/meta-integrity/conf/layer.conf @@ -26,3 +

[yocto] [meta-security][PATCH 1/6] python3-oauth2client: add recipe

2020-07-16 Thread akuster
Signed-off-by: Armin Kuster --- [V2] Add missing rdepends --- recipes-python/python/python3-oauth2client_4.1.3.bb | 11 +++ 1 file changed, 11 insertions(+) create mode 100644 recipes-python/python/python3-oauth2client_4.1.3.bb diff --git a/recipes-python/python/python3-oauth2client_4.

[yocto] [meta-security][PATCH] add gitlab framework and qemu machine

2020-07-18 Thread akuster
Machines: qemux86 qemux86-64 qemuarm qemuarm64 qemuppc qemumips84 qemuriscv64 Signed-off-by: Armin Kuster --- .gitlab-ci.yml| 56 +++ kas/kas-security-base.yml | 52 kas/qemuarm.yml | 6 + kas/qem

[yocto] [meta-security][PATCH] kas: add ima, tpm and tpm2 build configs

2020-07-19 Thread akuster
for qemux86, qemux86-64 and qemuarm64 Signed-off-by: Armin Kuster --- .gitlab-ci.yml| 32 kas/kas-security-base.yml | 4 kas/qemuarm64-ima.yml | 10 ++ kas/qemuarm64-tpm2.yml| 10 ++ kas/qemuarm64.yml | 2 +- kas

[yocto] [meta-security][PATCH] lynis: update to 3.0.0

2020-07-19 Thread akuster
Signed-off-by: Armin Kuster --- .../recipes-auditors/lynis/{lynis_2.7.5.bb => lynis_3.0.0.bb} | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) rename meta-security-compliance/recipes-auditors/lynis/{lynis_2.7.5.bb => lynis_3.0.0.bb} (89%) diff --git a/meta-security-compliance/recipes-a

Re: [yocto] error about cve_check after a 'do_populate_sdk: Succeeded' on poky master since 20 july on ubuntu18.04/Debian 10/Debian 9.12

2020-07-24 Thread akuster
This error has been reported earlier. I am working on a fix . -armin On 7/24/20 5:25 AM, vygu via lists.yoctoproject.org wrote: > Hello, > > We observe this following error about cve_check after a populate_sdk: > > ERROR: Execution of event handler 'cve_save_summary_handler' failed > Traceback (

[yocto] [meta-security][PATCH] drop ci-build: it is hiding errors

2020-07-24 Thread akuster
call kas from .gitlab-ci fix typos add missing mips64 file add main layer workaround Signed-off-by: Armin Kuster --- .gitlab-ci.yml| 32 +++- kas/kas-security-base.yml | 1 + kas/qemumips64.yml| 6 ++ scripts/ci-build.sh | 10 --

[yocto] [meta-security][PATCH 1/3] security packagegroups: move to recipes-core

2020-07-24 Thread akuster
Signed-off-by: Armin Kuster --- .../packagegroup/packagegroup-core-security-ptest.bb | 0 .../packagegroup/packagegroup-core-security.bb| 0 2 files changed, 0 insertions(+), 0 deletions(-) rename {recipes-security => recipes-core}/packagegroup/packagegroup-core

[yocto] [meta-security][PATCH 3/3] packagegroup-core-security: remove clamav for riscv*

2020-07-24 Thread akuster
Signed-off-by: Armin Kuster --- recipes-core/packagegroup/packagegroup-core-security.bb | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/recipes-core/packagegroup/packagegroup-core-security.bb b/recipes-core/packagegroup/packagegroup-core-security.bb index e0a9d05..bb790b4

[yocto] [meta-security][PATCH 2/3] packagegroup-security-tpm: add more packages for building

2020-07-24 Thread akuster
Signed-off-by: Armin Kuster --- .../recipes-core/packagegroup/packagegroup-security-tpm.bb | 5 + 1 file changed, 5 insertions(+) diff --git a/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm.bb b/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm.bb index 25126ef..3

[yocto] [meta-security][PATCH 2/2] packagegroup-core-security: remove libseccomp for riscv*

2020-07-25 Thread akuster
Signed-off-by: Armin Kuster --- recipes-core/packagegroup/packagegroup-core-security.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/recipes-core/packagegroup/packagegroup-core-security.bb b/recipes-core/packagegroup/packagegroup-core-security.bb index bb790b4..539ea2a 100

[yocto] [meta-security][PATCH 1/2] libsecomp: rv32/rv64 target builds are not supported yet

2020-07-25 Thread akuster
Signed-off-by: Armin Kuster --- recipes-security/libseccomp/libseccomp_2.4.3.bb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/recipes-security/libseccomp/libseccomp_2.4.3.bb b/recipes-security/libseccomp/libseccomp_2.4.3.bb index 9ca41e6..37d3573 100644 --- a/recipes-security/libseccomp

Re: [yocto] [meta-security][PATCH] ibmswtpm2: upgrade 1563 -> 1628

2020-07-25 Thread akuster
On 7/21/20 8:24 PM, Yi Zhao wrote: > Signed-off-by: Yi Zhao > --- > .../recipes-tpm2/ibmswtpm2/ibmswtpm2_1563.bb | 27 --- > .../recipes-tpm2/ibmswtpm2/ibmswtpm2_1628.bb | 26 ++ > 2 files changed, 26 insertions(+), 27 deletions(-) > delete mode 100644 meta-tp

[yocto] [meta-security][PATCH 1/2] libseccomp: update to 2.5.0

2020-07-25 Thread akuster
Notable changes: Add support for the 64-bit RISC-V architecture Update the syscall tables to Linux v5.8.0-rc5 Python bindings and build now default to Python 3.x for more info see: https://github.com/seccomp/libseccomp/blob/master/CHANGELOG Signed-off-by: Armin Kuster --- .../{libseccomp_2.4.3.

[yocto] [meta-security][PATCH 2/2] packagegroup-core-security: restore riscv64 for libssecomp

2020-07-25 Thread akuster
Signed-off-by: Armin Kuster --- recipes-core/packagegroup/packagegroup-core-security.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/recipes-core/packagegroup/packagegroup-core-security.bb b/recipes-core/packagegroup/packagegroup-core-security.bb index 539ea2a..c6342fd 100

[yocto] [meta-security][meta-hardening][PATCH] meta-harden: Add a layer to demo harding OE/YP

2020-07-26 Thread akuster
Signed-off-by: Armin Kuster --- meta-hardening/README | 86 +++ meta-hardening/conf/distro/harden.conf| 11 +++ meta-hardening/conf/layer.conf| 13 +++ .../openssh/openssh_%.bbappend| 13 +++ .../base-files/base-files

Re: [bitbake-devel] [yocto] Stable Warrior branch

2020-07-27 Thread akuster
Adrian, On 7/21/20 1:53 AM, Richard Purdie wrote: > On Tue, 2020-07-14 at 16:56 +0300, Adrian Bunk wrote: >> On Thu, Jun 04, 2020 at 09:28:00PM -0700, akuster wrote: >>> Hello, >>> >>> The Warrior branch of Poky has had its last official dot release. >>&g

Re: [yocto] QA notification for completed autobuilder build (yocto-3.1.2.rc1)

2020-07-29 Thread akuster
2020 3:58 PM >> To: yocto@lists.yoctoproject.org >> Cc: ota...@ossystems.com.br; yi.z...@windriver.com; Sangal, Apoorv >> ; Yeoh, Ee Peng ; Chan, >> Aaron Chun Yew ; >> richard.pur...@linuxfoundation.org; akuster...@gmail.com; >> sjolley.yp...@gmail.com; Jain, Sangeeta ;

Re: [yocto] [meta-security] Clamav libclammspack.so missing from image

2020-07-29 Thread akuster
On 7/29/20 12:34 PM, yoc wrote: > Hi, > > I am adding clamav to my custom image. > > I have added the target clamav-libclamav to my image and libclamav.so > is added, as expected, to /usr/lib but libclammspack.so is not added > to /usr/lib > > How to I make sure that libclammspack.so is include i

Re: [yocto] [meta-security][meta-hardening][PATCH] meta-harden: Add a layer to demo harding OE/YP

2020-08-02 Thread akuster
n having it separately I need a DISTRO_FEATURE to have this work with the layer this work came from.  I have a DISTRO_FEATURE support almost working. > > Regards > Konrad > > On 26.07.20 22:10, akuster wrote: >> diff --git a/meta-hardening/README b/meta-hardening/README >> new

Re: [yocto] Yocto build failure -- supposedly due to opkg-4.2 download

2020-08-04 Thread akuster
On 8/4/20 12:00 PM, Alex G. wrote: > Hi, > > I'm trying to get started with yocto builds. My builds keep failing > trying to build the qemu-x86 image. If I am not mistaken, many of the servers are down including downloads.yoctoproject.org. -armin > > Here's what I did: > > 1. I got poky from gi

[yocto] [meta-security][PATCH] trousers: Several Security fixes

2020-08-17 Thread akuster
From: Armin Kuster Fixes: CVE-2020-24332 CVE-2020-24330 CVE-2020-24331 Signed-off-by: Armin Kuster --- ...-security-issues-that-are-present-if.patch | 94 +++ meta-tpm/recipes-tpm/trousers/trousers_git.bb | 1 + 2 files changed, 95 insertions(+) create mode 100644 meta-tpm/r

[yocto] [meta-security][dunfel][PATCH] trousers: Several Security fixes

2020-08-24 Thread akuster
From: Armin Kuster Source: meta-security MR: 105088 Type: Security Fix Disposition: Backport from http://git.yoctoproject.org/cgit/cgit.cgi/meta-security/commit/?id=787ba6faeaa8823a4d87e5edd15581cb4e12fa70 ChangeID: b55bccb002b9eb2c49dfe380406e2597bb1ade90 Description: Fixes: CVE-2020-24332 CV

[yocto] [meta-security][PATCH] trousers: update to tip

2020-08-27 Thread akuster
Many for compile issue now being seen. rpc/tcstp/.libs/libtspi_la-rpc_cmk.o:/usr/src/debug/trousers/0.3.14+gitAUTOINC+4b9a70d578-r0/build/src/tspi/../../../git/src/include/tcsd.h:169: multiple definition of `tcsd_sa_int'; .libs/libtspi_la-tspi_context.o:/usr/src/debug/trousers/0.3.14+gitAUTOINC+

[yocto] [meta-security][PATCH 3/3] .gitlab: send error reports

2020-08-28 Thread akuster
Signed-off-by: Armin Kuster --- .gitlab-ci.yml | 11 ++- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index 132eb78..37db49c 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -5,17 +5,18 @@ stages: stage: build image: crops/poky

[yocto] [meta-security][PATCH 2/3] kas/kas-security-base.yml: lets enable error reporting

2020-08-28 Thread akuster
Signed-off-by: Armin Kuster --- kas/kas-security-base.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/kas/kas-security-base.yml b/kas/kas-security-base.yml index 768390e..2cf056f 100644 --- a/kas/kas-security-base.yml +++ b/kas/kas-security-base.yml @@ -37,6 +37,8 @@ local_conf_header:

[yocto] [meta-security][PATCH 1/3] upload-error-report: add script to upload errors

2020-08-28 Thread akuster
Signed-off-by: Armin Kuster --- scripts/upload-error-report | 26 ++ 1 file changed, 26 insertions(+) create mode 100755 scripts/upload-error-report diff --git a/scripts/upload-error-report b/scripts/upload-error-report new file mode 100755 index 000..56bd24e --- /de

[yocto] [meta-security][PATCH] cryptsetup-tpm-incubator: drop recipe

2020-08-29 Thread akuster
The upstream package appears to tbe dead so drop it. Signed-off-by: Armin Kuster --- .../cryptsetup-tpm-incubator_0.9.9.bb | 47 --- .../files/configure_fix.patch | 16 --- 2 files changed, 63 deletions(-) delete mode 100644 meta-tpm/recipes-tpm2/cry

Re: [yocto] [meta-security][PATCH] libseccomp: fix cross compile error for mips

2020-08-29 Thread akuster
On 8/2/20 11:21 PM, kai wrote: > From: Kai Kang > > Backport patch to fix cross compile error for mips: > > | syscalls.h:44:6: error: expected identifier or '(' before numeric constant > |44 | int mips; > | | ^~~~ Merged. thanks > > Signed-off-by: Kai Kang > --- > .../files/f

[yocto] [meta-security][PATCH] cryptsetup-tpm-incubator: remove reference from other files

2020-08-30 Thread akuster
Signed-off-by: Armin Kuster --- meta-tpm/conf/distro/include/maintainers.inc| 1 - .../recipes-core/packagegroup/packagegroup-security-tpm2.bb | 2 -- 2 files changed, 3 deletions(-) diff --git a/meta-tpm/conf/distro/include/maintainers.inc b/meta-tpm/conf/distro/include

Re: [yocto][meta-security][PATCH] dhcp: remove bbappend file

2020-09-07 Thread akuster
This patch set is for meta-selinux -armin On 9/6/20 10:14 PM, Chen Qi wrote: > dhcp has been removed, thus removing its bbappend file. > > Signed-off-by: Chen Qi > --- > recipes-connectivity/dhcp/dhcp_%.bbappend | 1 - > recipes-connectivity/dhcp/dhcp_selinux.inc | 3 -- > recipes-connect

Re: [yocto] poky dhcpcd failed build

2020-09-08 Thread akuster
May I suggest opening a Yocto bug on this with steps to reproduce the failure. - armin On 9/8/20 7:45 AM, Yocto wrote: > > > On 9/8/20 9:41 PM, Paul Barker wrote: >> On Tue, 8 Sep 2020 at 15:17, Yocto wrote: >>> On 9/8/20 7:57 PM, Paul Barker wrote: >>> >>> On Tue, 8 Sep 2020 at 07:26, Yocto wr

[yocto] Warrior and Thud stable branches

2020-09-08 Thread akuster
Hello, A few words regarding the older stable releases, Thud and Warrior. Thud no longer has an active Community Maintainer so this release with be move to the  EOL state.  Warrior did have a volunteer but no activity to date and this branch will also move to the EOL state. This will take affect

[yocto] Warrior and Thud stable branches

2020-09-08 Thread akuster
Sorry. still have the old email address in my contacts. re-sending. Forwarded Message Subject:[yocto] Warrior and Thud stable branches Date: Tue, 8 Sep 2020 21:39:28 -0700 From: akuster via lists.yoctoproject.org Reply-To: akuster...@gmail.com To

[yocto] Yocto Zeus stable branch

2020-09-08 Thread akuster
Hello, The Zeus branch was defined as a transitional branch with a 9 month stable cycle since LTS was created. The 3.0.4 was the last Zeus dot release. We have since added several Build stabilization changes and last minute backports . We intend on doing on last formal build cycle but no QA so no

Re: [yocto] Outreachy internship project - license tracing enhancement

2020-09-09 Thread akuster
On 9/9/20 3:51 AM, Paul Eggleton via lists.yoctoproject.org wrote: > Hi folks > > I'd like to propose we put forward the following project proposal for an > Outreachy internship (https://www.outreachy.org/communities/cfp/). I'm > prepared to be the mentor for the project and Microsoft will prov

[yocto] [meta-security][PATCH] packagegroup-core-security: dont include suricata on riscv or ppc

2020-09-11 Thread akuster
Signed-off-by: Armin Kuster --- recipes-core/packagegroup/packagegroup-core-security.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/recipes-core/packagegroup/packagegroup-core-security.bb b/recipes-core/packagegroup/packagegroup-core-security.bb index c6342fd..6aa0d6c 100

Re: [yocto] [meta-security][PATCH 0/6] Some small dm-verity improvements

2020-09-12 Thread akuster
On 9/7/20 10:35 AM, Bartosz Golaszewski wrote: > On Mon, Sep 7, 2020 at 7:17 PM Niko Mauno wrote: >> This set of patches addresses some small issues in dm-verity rootfs >> facility, which were observed while making use of dm-verity-img.bbclass >> to generate dm-verity rootfs images for real arm-

Re: [yocto] [meta-security][PATCH 0/6] Some small dm-verity improvements

2020-09-12 Thread akuster
On 9/7/20 10:17 AM, Niko Mauno wrote: > This set of patches addresses some small issues in dm-verity rootfs > facility, which were observed while making use of dm-verity-img.bbclass > to generate dm-verity rootfs images for real arm-based hardware. For > purposes of establishing this changeset, t

Re: [yocto] [meta-security][PATCH] sssd: Make manpages buildable

2020-09-12 Thread akuster
merged thanks On 8/25/20 5:01 AM, Jonatan Pålsson wrote: > Some XML related fixes are needed to make the sssd manpages buildable > > Signed-off-by: Jonatan Pålsson > --- > ...AC_CHECK_FILE-when-building-manpages.patch | 34 +++ > recipes-security/sssd/sssd_1.16.4.bb |

Re: [yocto] [meta-security][PATCH] trousers: Fix the problem that do_package fails when multilib is enabled.

2020-09-12 Thread akuster
merged thanks On 9/7/20 10:28 PM, zhengruoqin wrote: > The following error will occur when multilib is enabled: > ERROR: trousers-0.3.14+gitAUTOINC+e74dd1d967-r0 do_package: QA Issue: > trousers: Files/directories were installed but not shipped in any package: > /lib > /lib/systemd > /lib/s

Re: [yocto][meta-security][PATCH] nss: update patch to fix do_patch error

2020-09-12 Thread akuster
merged, thanks On 9/8/20 1:20 AM, Chen Qi wrote: > Currently sssd's do_patch task fails. Update the patch to fix this problem. > > Signed-off-by: Chen Qi > --- > ...s-Collision-with-external-nss-symbol.patch | 155 +- > 1 file changed, 78 insertions(+), 77 deletions(-) > > diff -

Re: [yocto] [meta-security][PATCH v2] ibmswtpm2: update to 1637

2020-09-12 Thread akuster
merged. thanks On 9/11/20 12:34 AM, Jens Rehsack wrote: > From: Jens Rehsack > > Update ibmswtpm2 from 1628 to 1637. Build 1637 Includes: > * Increase NV memory size to match PC Client RSA 3072 requirements > * Add and fix ACT support > * Update Visual Studio files to 2019. > > Signed-off-by: Jen

Re: [yocto] [meta-security][PATCH] ibmtpm2tss: add recipe

2020-09-13 Thread akuster
merged thanks On 9/11/20 12:37 AM, Jens Rehsack wrote: > From: Jens Rehsack > > Add recipe for companion of IBM Software TPM 2.0 - IBM's TPM 2.0 TSS. > It's a user space TSS for TPM 2.0. > > Signed-off-by: Jens Rehsack > --- > ...efile.am-expand-wildcards-in-prereqs.patch | 125 +++

Re: [yocto] [meta-security][dunfell][PATCH] clamav: add INSTALL_CLAMAV_CVD flag to do_install

2020-09-13 Thread akuster
merged On 9/10/20 6:53 AM, Charlie Davies wrote: > Recipe provides INSTALL_CLAMAV_CVD flag to bypass clamav > cvd db creation. During do_install this flag should be > used to conditionally skip install of cvd db if needed. > > Signed-off-by: Charlie Davies > --- > recipes-scanners/clamav/clamav_

Re: [yocto] [meta-security][master][dunfell][PATCH] clamav: update SO_VER to 9.0.4

2020-09-13 Thread akuster
merged to both. thanks On 9/10/20 7:11 AM, Charlie Davies wrote: > Signed-off-by: Charlie Davies > --- > recipes-scanners/clamav/clamav_0.101.5.bb | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/recipes-scanners/clamav/clamav_0.101.5.bb > b/recipes-scanners/clamav/clam

[yocto] [meta-security][PATCH 1/2] packagegroup-core-security: add more pkgs to base group

2020-09-15 Thread akuster
Signed-off-by: Armin Kuster --- .../packagegroup/packagegroup-core-security.bb | 17 + 1 file changed, 13 insertions(+), 4 deletions(-) diff --git a/recipes-core/packagegroup/packagegroup-core-security.bb b/recipes-core/packagegroup/packagegroup-core-security.bb index 6aa0d6c..

[yocto] [meta-security][PATCH 2/2] apparmor: exclude mips, not supported

2020-09-15 Thread akuster
Signed-off-by: Armin Kuster --- recipes-mac/AppArmor/apparmor_2.13.4.bb | 2 ++ 1 file changed, 2 insertions(+) diff --git a/recipes-mac/AppArmor/apparmor_2.13.4.bb b/recipes-mac/AppArmor/apparmor_2.13.4.bb index 552cac7..dcdc1f7 100644 --- a/recipes-mac/AppArmor/apparmor_2.13.4.bb +++ b/recipe

Re: [yocto] [meta-security][PATCH 2/2] apparmor: exclude mips, not supported

2020-09-16 Thread akuster
On 9/15/20 10:11 PM, Khem Raj wrote: > title says mips but it actually is for mips64 only it seems. right. easy to fix when I commit. Have not built qemumip so its unknown at this time. -armin > > On Tue, Sep 15, 2020 at 8:12 PM akuster wrote: >> Signed-off-by: Armin Kuster >

[yocto] [meta-security][PATCH 2/2] packagegroup-core-security: add softHSM

2020-09-27 Thread akuster
Signed-off-by: Armin Kuster --- recipes-core/packagegroup/packagegroup-core-security.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/recipes-core/packagegroup/packagegroup-core-security.bb b/recipes-core/packagegroup/packagegroup-core-security.bb index 1d01800..4d98631 100644 --- a/recipe

[yocto] [meta-security][PATCH 1/2] softHSM: add pkg

2020-09-27 Thread akuster
Signed-off-by: Armin Kuster --- recipes-security/softHSM/softhsm_2.6.1.bb | 30 +++ 1 file changed, 30 insertions(+) create mode 100644 recipes-security/softHSM/softhsm_2.6.1.bb diff --git a/recipes-security/softHSM/softhsm_2.6.1.bb b/recipes-security/softHSM/softhsm_2.6.1.

[yocto] [meta-security][PATCH 1/2] libest: add recipe

2020-09-28 Thread akuster
Signed-off-by: Armin Kuster --- recipes-security/libest/libest_3.2.0.bb | 23 +++ 1 file changed, 23 insertions(+) create mode 100644 recipes-security/libest/libest_3.2.0.bb diff --git a/recipes-security/libest/libest_3.2.0.bb b/recipes-security/libest/libest_3.2.0.bb new f

[yocto] [meta-security][PATCH 2/2] packagegroup-core-security: add libest package

2020-09-28 Thread akuster
Signed-off-by: Armin Kuster --- recipes-core/packagegroup/packagegroup-core-security.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/recipes-core/packagegroup/packagegroup-core-security.bb b/recipes-core/packagegroup/packagegroup-core-security.bb index 4d98631..c69e3b3 100644 --- a/recipe

[yocto] [meta-security][PATCH] opendnssec: add recipe

2020-09-28 Thread akuster
Signed-off-by: Armin Kuster --- .../opendnssec/files/fix_fprint.patch | 25 ++ .../opendnssec/files/libdns_conf_fix.patch| 217 ++ .../opendnssec/files/libxml2_conf.patch | 112 + .../opendnssec/opendnssec_2.1.6.bb| 37 +++ 4 files changed,

[yocto] [meta-security][PATCH] packagegroup-core-security: add opendnssec to pkg grp

2020-09-29 Thread akuster
Signed-off-by: Armin Kuster --- recipes-core/packagegroup/packagegroup-core-security.bb | 1 + 1 file changed, 1 insertion(+) diff --git a/recipes-core/packagegroup/packagegroup-core-security.bb b/recipes-core/packagegroup/packagegroup-core-security.bb index c69e3b3..789f4ea 100644 --- a/recipe

Re: [yocto] [meta-security][master][dunfell][PATCH] gitignore added

2020-09-29 Thread akuster
On 9/22/20 11:25 PM, Adrian Freihofer wrote: > After running testimage there are some python left overs at > lib/oeqa/runtime/cases/__pycache__/ > > Signed-off-by: Adrian Freihofer merged thanks > --- > .gitignore | 7 +++ > 1 file changed, 7 insertions(+) > create mode 100644 .gitignore >

[yocto] [meta-security][PATCH 3/4] security-test-image: simplify

2020-09-30 Thread akuster
Signed-off-by: Armin Kuster --- recipes-core/images/security-test-image.bb| 26 ++- .../packagegroup-core-security.bb | 14 ++ 2 files changed, 16 insertions(+), 24 deletions(-) diff --git a/recipes-core/images/security-test-image.bb b/recipes-core/images

[yocto] [meta-security][PATCH 2/4] packagegroup-core-security-ptest: remove keyutils-ptest

2020-09-30 Thread akuster
Signed-off-by: Armin Kuster --- recipes-core/packagegroup/packagegroup-core-security-ptest.bb | 1 - 1 file changed, 1 deletion(-) diff --git a/recipes-core/packagegroup/packagegroup-core-security-ptest.bb b/recipes-core/packagegroup/packagegroup-core-security-ptest.bb index cf34ded..75b816a 10

[yocto] [meta-security][PATCH 1/4] libseccomp: fix ptest failures.

2020-09-30 Thread akuster
Fixes: BusyBox v1.32.0 () multi-call binary. Usage: dd [if=FILE] [of=FILE] [bs=N] [count=N] [skip=N] Don't use Busybox dd, not compatable. Use coreutils Signed-off-by: Armin Kuster --- recipes-security/libseccomp/libseccomp_2.5.0.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --

[yocto] [meta-security][PATCH 4/4] packagegroup-core-security-ptest: remove

2020-09-30 Thread akuster
Signed-off-by: Armin Kuster --- .../packagegroup-core-security-ptest.bb | 27 --- 1 file changed, 27 deletions(-) delete mode 100644 recipes-core/packagegroup/packagegroup-core-security-ptest.bb diff --git a/recipes-core/packagegroup/packagegroup-core-security-ptest.bb b

[yocto] [meta-security][PATCH 1/2] apparmor: fix build issue with ptest enabled.

2020-10-02 Thread akuster
minor spacing cleanup Signed-off-by: Armin Kuster --- recipes-mac/AppArmor/apparmor_2.13.4.bb | 181 +- ...-Don-t-build-syscall_sysctl-if-missi.patch | 96 ++ 2 files changed, 186 insertions(+), 91 deletions(-) create mode 100644 recipes-mac/AppArmor/files/0001-r

[yocto] [meta-security][PATCH 2/2] security-test-image: tweak to get more tests to runn

2020-10-02 Thread akuster
Signed-off-by: Armin Kuster --- recipes-core/images/security-test-image.bb | 9 - 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/recipes-core/images/security-test-image.bb b/recipes-core/images/security-test-image.bb index babe3fd..54d8978 100644 --- a/recipes-core/images/s

[yocto] [meta-security][PATCH 2/3] packagegroup-core-security: apparmor 3.0 ptest does not build

2020-10-06 Thread akuster
for now skip apparmor ptest Signed-off-by: Armin Kuster --- recipes-core/packagegroup/packagegroup-core-security.bb | 1 - 1 file changed, 1 deletion(-) diff --git a/recipes-core/packagegroup/packagegroup-core-security.bb b/recipes-core/packagegroup/packagegroup-core-security.bb index 9546e0f.

[yocto] [meta-security][PATCH 3/3] suricata: fix compiling on gcc10

2020-10-06 Thread akuster
Signed-off-by: Armin Kuster --- recipes-ids/suricata/suricata_4.1.8.bb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/recipes-ids/suricata/suricata_4.1.8.bb b/recipes-ids/suricata/suricata_4.1.8.bb index 9b7122b..135871c 100644 --- a/recipes-ids/suricata/suricata_4.1.8.bb ++

  1   2   3   >