|
[isar-cip-core 1/3] cip-security: Add packages for IEC-62443-4-2 evaluation
From: Kazuhiro Hayashi <kazuhiro3.hayashi@...>
Identified security packages are added to the target image
and that will be used for IEC-62443-4-2 evaluation
Signed-off-by: Kazuhiro Hayashi
From: Kazuhiro Hayashi <kazuhiro3.hayashi@...>
Identified security packages are added to the target image
and that will be used for IEC-62443-4-2 evaluation
Signed-off-by: Kazuhiro Hayashi
|
By
Venkata Pyla
·
#5021
·
|
|
[isar-cip-core 0/3] Security Branch patches
From: Venkata Pyla <venkata.pyla@...>
Patch series for Security changes for IEC-62443-4-2 evaluation
Kazuhiro Hayashi (1):
cip-security: Add packages for IEC-62443-4-2
From: Venkata Pyla <venkata.pyla@...>
Patch series for Security changes for IEC-62443-4-2 evaluation
Kazuhiro Hayashi (1):
cip-security: Add packages for IEC-62443-4-2
|
By
Venkata Pyla
·
#5020
·
|
|
Re: The security of NTP
Daniel, Pavel:
Thanks for the feedback. Is tlsdate a better alternative (https://github.com/ioerror/tlsdate/)? The only caveat if using tlsdate (or any sort of time mechanism that relies on a
Daniel, Pavel:
Thanks for the feedback. Is tlsdate a better alternative (https://github.com/ioerror/tlsdate/)? The only caveat if using tlsdate (or any sort of time mechanism that relies on a
|
By
Mohammed Billoo <mab@...>
·
#5019
·
|
|
FW: Final call to participate in the LTS survey
FYI
Kind regards, Chris
By
Chris Paterson
·
#5018
·
|
|
[cip core] license compliance for CIP core image releases
Hello,
During the last CIP Core meeting we discussed about license compliance for CIP core image releases.
In particular, we talked about how to make sure that users can get exactly the same source
Hello,
During the last CIP Core meeting we discussed about license compliance for CIP core image releases.
In particular, we talked about how to make sure that users can get exactly the same source
|
By
Daniel Sangorrin <daniel.sangorrin@...>
·
#5017
·
|
|
Re: [PATCH 1/3] cip-security: Add packages for IEC-62443-4-2 Evaluation.
Hi Jan,
Patches give you greater visibility (all cip-dev members), but I can see some benefits in using MRs as well:
* merge when the pipeline succeeds
* map issues with the patches that close them
*
Hi Jan,
Patches give you greater visibility (all cip-dev members), but I can see some benefits in using MRs as well:
* merge when the pipeline succeeds
* map issues with the patches that close them
*
|
By
Daniel Sangorrin <daniel.sangorrin@...>
·
#5016
·
|
|
The security of NTP
Hi Pavel,
*I renamed the subject and added cip-security to Cc
Hi Pavel,
*I renamed the subject and added cip-security to Cc
|
By
Daniel Sangorrin <daniel.sangorrin@...>
·
#5015
·
|
|
[ANNOUNCE] Release v4.19.134-cip31
Hi,
CIP kernel team has released Linux kernel v4.19.134-cip31.
The linux-4.19.y-cip tree has been updated base version from v4.19.132
to v4.19.134,
In addition, the rcar-du and display features have
Hi,
CIP kernel team has released Linux kernel v4.19.134-cip31.
The linux-4.19.y-cip tree has been updated base version from v4.19.132
to v4.19.134,
In addition, the rcar-du and display features have
|
By
Nobuhiro Iwamatsu
·
#5014
·
|
|
[ANNOUNCE] v4.4.231-cip47-rt30
Hi!
v4.4.231-cip47-rt30 should be available at kernel.org.
Trees are available
Hi!
v4.4.231-cip47-rt30 should be available at kernel.org.
Trees are available
|
By
Pavel Machek
·
#5013
·
|
|
Re: [PATCH 4.9 18/22] x86/fpu: Disable bottom halves while loading FPU registers
The conflict was due to a missing rename back in 4.4: e4a81bfcaae1
("x86/fpu: Rename fpu::fpstate_active to fpu::initialized").
I've fixed up the patch and queued it for 4.4, thanks for pointing
The conflict was due to a missing rename back in 4.4: e4a81bfcaae1
("x86/fpu: Rename fpu::fpstate_active to fpu::initialized").
I've fixed up the patch and queued it for 4.4, thanks for pointing
|
By
Sasha Levin <sashal@...>
·
#5012
·
|
|
Re: [PATCH 4.9 18/22] x86/fpu: Disable bottom halves while loading FPU registers
You are asking about something we did back in 2018. I can't remember
what I did last week :)
If you provide a backport that works, I'll be glad to take it. The
current patch does not apply cleanly
You are asking about something we did back in 2018. I can't remember
what I did last week :)
If you provide a backport that works, I'll be glad to take it. The
current patch does not apply cleanly
|
By
Greg Kroah-Hartman <gregkh@...>
·
#5011
·
|
|
Re: [PATCH 4.9 18/22] x86/fpu: Disable bottom halves while loading FPU registers
Any reason why the backport stopped back than at 4.9? I just debugged this out of a 4.4 kernel, and it is needed there as well. I'm happy to propose a backport, would just appreciate a hint if the BH
Any reason why the backport stopped back than at 4.9? I just debugged this out of a 4.4 kernel, and it is needed there as well. I'm happy to propose a backport, would just appreciate a hint if the BH
|
By
Jan Kiszka
·
#5010
·
|
|
[isar-cip-core PATCH v3 6/6] doc: Add README for secureboot
From: Quirin Gylstorff <quirin.gylstorff@...>
Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...>
---
doc/README.secureboot.md | 229 +++++++++++++++++++++++++++++++++++++++
1
From: Quirin Gylstorff <quirin.gylstorff@...>
Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...>
---
doc/README.secureboot.md | 229 +++++++++++++++++++++++++++++++++++++++
1
|
By
Quirin Gylstorff
·
#5009
·
|
|
[isar-cip-core PATCH v3 5/6] secure-boot: Add Debian snakeoil keys for ease-of-use
From: Quirin Gylstorff <quirin.gylstorff@...>
Use the Debian snakeoil keys to have a demo case available without
the OVMF setup. Copy the used keys from the build to the deploy
directory to
From: Quirin Gylstorff <quirin.gylstorff@...>
Use the Debian snakeoil keys to have a demo case available without
the OVMF setup. Copy the used keys from the build to the deploy
directory to
|
By
Quirin Gylstorff
·
#5008
·
|
|
[isar-cip-core PATCH v3 4/6] secure-boot: Add secure boot with unified kernel image
From: Quirin Gylstorff <quirin.gylstorff@...>
A unified kernel image contains the os-release, kernel,
kernel commandline, initramfs and efi-stub in one binary.
This binary can be boot by
From: Quirin Gylstorff <quirin.gylstorff@...>
A unified kernel image contains the os-release, kernel,
kernel commandline, initramfs and efi-stub in one binary.
This binary can be boot by
|
By
Quirin Gylstorff
·
#5007
·
|
|
[isar-cip-core PATCH v3 3/6] secure-boot: select boot partition in initramfs
From: Quirin Gylstorff <quirin.gylstorff@...>
As the usage of a unified kernel image freeze the kernel commmandline
during build time the rootfs selection for swupdate can no longer be
done
From: Quirin Gylstorff <quirin.gylstorff@...>
As the usage of a unified kernel image freeze the kernel commmandline
during build time the rootfs selection for swupdate can no longer be
done
|
By
Quirin Gylstorff
·
#5006
·
|
|
[isar-cip-core PATCH v3 0/6] secureboot with efibootguard
From: Quirin Gylstorff <quirin.gylstorff@...>
This patchset adds secureboot with efibootguard to cip-core.
The image build signs the efibootguard bootloader (bootx64.efi) and generates
a
From: Quirin Gylstorff <quirin.gylstorff@...>
This patchset adds secureboot with efibootguard to cip-core.
The image build signs the efibootguard bootloader (bootx64.efi) and generates
a
|
By
Quirin Gylstorff
·
#5005
·
|
|
[isar-cip-core PATCH v3 2/6] isar-patch: Add initramfs-config patch
From: Quirin Gylstorff <quirin.gylstorff@...>
Adapt the initramfs generation to set for example the root device
in the initramfs
Signed-off-by: Quirin Gylstorff
From: Quirin Gylstorff <quirin.gylstorff@...>
Adapt the initramfs generation to set for example the root device
in the initramfs
Signed-off-by: Quirin Gylstorff
|
By
Quirin Gylstorff
·
#5004
·
|
|
[isar-cip-core PATCH v3 1/6] kernel: add fat for qemu-amd64
From: Quirin Gylstorff <quirin.gylstorff@...>
Add a fat configuration to access FAT Partitions on the qemu-amd64
target.
Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...>
---
From: Quirin Gylstorff <quirin.gylstorff@...>
Add a fat configuration to access FAT Partitions on the qemu-amd64
target.
Signed-off-by: Quirin Gylstorff <quirin.gylstorff@...>
---
|
By
Quirin Gylstorff
·
#5003
·
|
|
[isar-cip-core PATCH v3 3/5] recipes-core: add swupdate
From: Quirin Gylstorff <quirin.gylstorff@...>
Add swupdate for A/B software updates. Currently the Round Robin
handler in lua supports efibootguard as bootloader. The u-boot
implementation is
From: Quirin Gylstorff <quirin.gylstorff@...>
Add swupdate for A/B software updates. Currently the Round Robin
handler in lua supports efibootguard as bootloader. The u-boot
implementation is
|
By
Quirin Gylstorff
·
#5002
·
|