Hi all,

Any update/comment ?

Thanks,
Sanjay

-----Original Message-----
From: Sanjay Chitroda <[email protected]> 
Sent: Friday, May 12, 2023 7:12 PM
To: [email protected]
Cc: Sanjaykumar kantibhai Chitroda -X (schitrod - E-INFO CHIPS INC at Cisco) 
<[email protected]>
Subject: [meta-selinux][PATCH] selinux: Set CVE_PRODUCT

The CVE product name for selinux-* package is (usually) the selinux (and not 
our recipe name), so use selinux as the default.

See also:
http://lists.openembedded.org/pipermail/openembedded-core/2017-July/139897.html

"Results from cve-check are not very good at the moment.
One of the reasons for this is that component names used in CVE database differ 
from yocto recipe names. This series fixes several of those name mapping 
problems by setting the CVE_PRODUCT correctly in the recipes. To check this 
mapping with after a build, I'm exporting LICENSE and CVE_PRODUCT variables to 
buildhistory for recipes and packages."

Value added is based on:
https://nvd.nist.gov/vuln/search/results?results_type=overview&search_type=all&cpe_product=cpe%3A%2F%3Akernel%3Aselinux

Signed-off-by: Sanjay Chitroda <[email protected]>
---
 recipes-security/selinux/selinux_common.inc | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/recipes-security/selinux/selinux_common.inc 
b/recipes-security/selinux/selinux_common.inc
index 383f62d..cd51a86 100644
--- a/recipes-security/selinux/selinux_common.inc
+++ b/recipes-security/selinux/selinux_common.inc
@@ -15,3 +15,5 @@ do_install() {
             SHLIBDIR="${base_libdir}" \
             SYSTEMDDIR="${systemd_unitdir}"
 }
+
+CVE_PRODUCT ?= "kernel:selinux"
--
2.35.6

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#60131): https://lists.yoctoproject.org/g/yocto/message/60131
Mute This Topic: https://lists.yoctoproject.org/mt/98902885/21656
Group Owner: [email protected]
Unsubscribe: https://lists.yoctoproject.org/g/yocto/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Sanjaykumar kantibhai Chitroda -X (schitrod - E-INFO CHIPS INC at Cisco) via lists.yoctoproject.org
    • ... Sanjaykumar kantibhai Chitroda -X (schitrod - E-INFO CHIPS INC at Cisco) via lists.yoctoproject.org
    • ... Sanjaykumar kantibhai Chitroda -X (schitrod - E-INFO CHIPS INC at Cisco) via lists.yoctoproject.org

Reply via email to