|
Re: [isar-cip-core]RFC v2 6/9] Create systemd mount units for a etc overlay
You right thats the better solution. Will test it and add it in a v3.
After testing in the current cip-core-image i don't need it.
Quirin
You right thats the better solution. Will test it and add it in a v3.
After testing in the current cip-core-image i don't need it.
Quirin
|
By
Quirin Gylstorff
·
#6954
·
|
|
Re: [isar-cip-core]RFC v2 5/9] Create an read-only rootfs with dm-verity
I will make it configurable in the next version.
According my testing and [1] if /tmp is mount a in /etc/fstab. systemd mounts before the local-fs.target.
In the cip-core-image /tmp is not need
I will make it configurable in the next version.
According my testing and [1] if /tmp is mount a in /etc/fstab. systemd mounts before the local-fs.target.
In the cip-core-image /tmp is not need
|
By
Quirin Gylstorff
·
#6953
·
|
|
Re: New kernel patches review management
Hi Pavel,
Agree. I have a question.
What are the triggers for creating pages for management?
Perhaps I think each LTS version and RC release will be the trigger. And a page will be created for each
Hi Pavel,
Agree. I have a question.
What are the triggers for creating pages for management?
Perhaps I think each LTS version and RC release will be the trigger. And a page will be created for each
|
By
Nobuhiro Iwamatsu
·
#6952
·
|
|
Re: New kernel patches review management
Hi Ulrich,
I agree.
Thanks!
Best regards,
Nobuhiro
________________________________________
差出人: Ulrich Hecht <uli@...>
送信日時: 2021年11月11日 18:04
宛先:
Hi Ulrich,
I agree.
Thanks!
Best regards,
Nobuhiro
________________________________________
差出人: Ulrich Hecht <uli@...>
送信日時: 2021年11月11日 18:04
宛先:
|
By
Nobuhiro Iwamatsu
·
#6951
·
|
|
CIP IRC weekly meeting today on libera.chat
Hi all,
Kindly be reminded to attend the weekly meeting through IRC to discuss
technical topics with CIP kernel today.
Please note that we moved from Freenode to libera.chat. Our channel is
the
Hi all,
Kindly be reminded to attend the weekly meeting through IRC to discuss
technical topics with CIP kernel today.
Please note that we moved from Freenode to libera.chat. Our channel is
the
|
By
Jan Kiszka
·
#6950
·
|
|
FYI: meta-spdxscanner with meta-debian/deby
Hello !
I modified meta-spdxscanner warrior branch[1] to work with meta-debian.
I tested meta-debian and deby(cip-core/deby). I could build without
errors building core-image-minimal with do_spdx
Hello !
I modified meta-spdxscanner warrior branch[1] to work with meta-debian.
I tested meta-debian and deby(cip-core/deby). I could build without
errors building core-image-minimal with do_spdx
|
By
Masami Ichikawa
·
#6949
·
|
|
New CVE entries in this week
Hi !
It's this week's CVE report.
This week reported two new CVEs. They have not been fixed in the mainline yet.
* New CVEs
CVE-2021-43975: atlantic: Fix OOB read and write in
Hi !
It's this week's CVE report.
This week reported two new CVEs. They have not been fixed in the mainline yet.
* New CVEs
CVE-2021-43975: atlantic: Fix OOB read and write in
|
By
Masami Ichikawa
·
#6948
·
|
|
Re: New kernel patches review management
Hi!
This looks good.
I believe this is too simple. We should include patch titles, so that
it is easier to review whole series. I also believe we should include
related patches from 4.19/4.4, so
Hi!
This looks good.
I believe this is too simple. We should include patch titles, so that
it is easier to review whole series. I also believe we should include
related patches from 4.19/4.4, so
|
By
Pavel Machek
·
#6947
·
|
|
Re: [isar-cip-core]RFC v2 4/9] Create a initrd with support for dm-verity
Hm, so you explicitly enumerate all scripts except for cryptroot so that
you run (hopefully right?) thereafter.
Isn't it sufficient to make cryptroot dependent on this?
Looks too verbose and
Hm, so you explicitly enumerate all scripts except for cryptroot so that
you run (hopefully right?) thereafter.
Isn't it sufficient to make cryptroot dependent on this?
Looks too verbose and
|
By
Christian Storm
·
#6946
·
|
|
Re: [isar-cip-core]RFC v2 5/9] Create an read-only rootfs with dm-verity
Hm, shouldn't size be configurable?
Is this the right point in time? Isn't /tmp needed before this?
Kind regards,
Christian
--
Dr. Christian Storm
Siemens AG, Technology, T RDA IOT
Hm, shouldn't size be configurable?
Is this the right point in time? Isn't /tmp needed before this?
Kind regards,
Christian
--
Dr. Christian Storm
Siemens AG, Technology, T RDA IOT
|
By
Christian Storm
·
#6945
·
|
|
Re: [isar-cip-core]RFC v2 6/9] Create systemd mount units for a etc overlay
Hm, why do you replace/create those services instead of augmenting the
current default ones via conf.d'lets?
Why is this one here dependent on network?
Why does this differ that much from upstream
Hm, why do you replace/create those services instead of augmenting the
current default ones via conf.d'lets?
Why is this one here dependent on network?
Why does this differ that much from upstream
|
By
Christian Storm
·
#6944
·
|
|
Re: [isar-cip-core]RFC v2 8/9] kas: Patch isar for correct permissions in var and home
I will add a link to the discussion of the Patch on the ISAR mailing list[1] in the next version.
[1]: https://groups.google.com/g/isar-users/c/wlanc7f7UnQ
Kind regards
Quirin
I will add a link to the discussion of the Patch on the ISAR mailing list[1] in the next version.
[1]: https://groups.google.com/g/isar-users/c/wlanc7f7UnQ
Kind regards
Quirin
|
By
Quirin Gylstorff
·
#6943
·
|
|
Re: [isar-cip-core]RFC v2 9/9] swupdate: Backport patches from SWUpdate Master
The build of SWUpdate uses dpkg-gbp to follow the Debian build of SWUpdate with sources from [1].
As Debian only follows fixed release , currently 2021.04, I patched the version.
This patchset is no
The build of SWUpdate uses dpkg-gbp to follow the Debian build of SWUpdate with sources from [1].
As Debian only follows fixed release , currently 2021.04, I patched the version.
This patchset is no
|
By
Quirin Gylstorff
·
#6942
·
|
|
[isar-cip-core v2 1/3] cip-core-image-security: remove unnecessary dependency package names
From: venkata pyla <venkata.pyla@...>
It is not necessary to mention the dependency package names in the recipe
because their names are changed when different distribution version
is
From: venkata pyla <venkata.pyla@...>
It is not necessary to mention the dependency package names in the recipe
because their names are changed when different distribution version
is
|
By
Venkata Pyla
·
#6941
·
|
|
[isar-cip-core v2 3/3] Kconfig: Enable Security extensions for bullseye image
From: venkata pyla <venkata.pyla@...>
Signed-off-by: venkata pyla <venkata.pyla@...>
---
Kconfig | 1 -
1 file changed, 1 deletion(-)
diff --git a/Kconfig b/Kconfig
index
From: venkata pyla <venkata.pyla@...>
Signed-off-by: venkata pyla <venkata.pyla@...>
---
Kconfig | 1 -
1 file changed, 1 deletion(-)
diff --git a/Kconfig b/Kconfig
index
|
By
Venkata Pyla
·
#6940
·
|
|
[isar-cip-core v2 2/3] cip-core-image-security: Install packages based on DISTRO version
From: venkata pyla <venkata.pyla@...>
Package names like below have different names in different DISTRO versions
and those packages should be installed based on the Distro version
From: venkata pyla <venkata.pyla@...>
Package names like below have different names in different DISTRO versions
and those packages should be installed based on the Distro version
|
By
Venkata Pyla
·
#6939
·
|
|
[isar-cip-core v2 0/3] Security extensions for bullseye image
From: venkata pyla <venkata.pyla@...>
This patch series enable security extension for bullseye image.
It fixes the below two problems
- package not found due to dependency package names
From: venkata pyla <venkata.pyla@...>
This patch series enable security extension for bullseye image.
It fixes the below two problems
- package not found due to dependency package names
|
By
Venkata Pyla
·
#6938
·
|
|
Re: [isar-cip-core]RFC v2 9/9] swupdate: Backport patches from SWUpdate Master
Why not upgrade to a newer version of SWUpdate instead of backporting
stuff? There's no real advantage to stay on a "release" as SWUpdate
follows rolling releases -- granted, you have to do the
Why not upgrade to a newer version of SWUpdate instead of backporting
stuff? There's no real advantage to stay on a "release" as SWUpdate
follows rolling releases -- granted, you have to do the
|
By
Christian Storm
·
#6937
·
|
|
Re: [isar-cip-core]RFC v2 8/9] kas: Patch isar for correct permissions in var and home
A note where this comes from, where it's supposed to go in oder to get
rid of this patch here eventually would be helpful.
Kind regards,
Christian
--
Dr. Christian Storm
Siemens AG, Technology,
A note where this comes from, where it's supposed to go in oder to get
rid of this patch here eventually would be helpful.
Kind regards,
Christian
--
Dr. Christian Storm
Siemens AG, Technology,
|
By
Christian Storm
·
#6936
·
|
|
[isar-cip-core]RFC v2 9/9] swupdate: Backport patches from SWUpdate Master
From: Quirin Gylstorff <quirin.gylstorff@...>
Backport the following patches to detect the correct partition to
update.
388f1777 util: Add get_root source /proc/self/mountinfo
3914d2b7 util:
From: Quirin Gylstorff <quirin.gylstorff@...>
Backport the following patches to detect the correct partition to
update.
388f1777 util: Add get_root source /proc/self/mountinfo
3914d2b7 util:
|
By
Quirin Gylstorff
·
#6935
·
|