|
[isar-cip-core][PATCH v2 10/13] efibootguard: Add support for embedding DTBs into unified kernel images
From: Jan Kiszka <jan.kiszka@...>
Pick up the DTBs specified via DTB_FILES and embed them into the unified
kernel image that the wic plugin can generate. This does not work for
normal
From: Jan Kiszka <jan.kiszka@...>
Pick up the DTBs specified via DTB_FILES and embed them into the unified
kernel image that the wic plugin can generate. This does not work for
normal
|
By
Jan Kiszka
·
#8264
·
|
|
[isar-cip-core][PATCH v2 12/13] Enable SWUpdate with and w/o secure boot for QEMU arm64
From: Jan Kiszka <jan.kiszka@...>
Hook up the new U-Boot recipe, provide new wks files and disable the
watchdog for EFI Boot Guard - that's all what's need to allow offering
SWUpdate and
From: Jan Kiszka <jan.kiszka@...>
Hook up the new U-Boot recipe, provide new wks files and disable the
watchdog for EFI Boot Guard - that's all what's need to allow offering
SWUpdate and
|
By
Jan Kiszka
·
#8263
·
|
|
[isar-cip-core][PATCH v2 04/13] Rework secure boot key handling and signing recipes
From: Jan Kiszka <jan.kiszka@...>
Simplify the signing recipe to a single, generic one. Instead, provide
secure-boot-secrets packages that contain the used image key and
certificate at a
From: Jan Kiszka <jan.kiszka@...>
Simplify the signing recipe to a single, generic one. Instead, provide
secure-boot-secrets packages that contain the used image key and
certificate at a
|
By
Jan Kiszka
·
#8262
·
|
|
[isar-cip-core][PATCH v2 07/13] efibootguard: Update to 0.11 release
From: Jan Kiszka <jan.kiszka@...>
This version bring the new unified kernel stub and script to generate
unified kernel images from that.
That script requires python3, so we need to expand
From: Jan Kiszka <jan.kiszka@...>
This version bring the new unified kernel stub and script to generate
unified kernel images from that.
That script requires python3, so we need to expand
|
By
Jan Kiszka
·
#8261
·
|
|
[isar-cip-core][PATCH v2 03/13] initramfs-abrootfs-hook: Remove obsolete patch
From: Jan Kiszka <jan.kiszka@...>
Forgotten to remove in f1e559498116.
Signed-off-by: Jan Kiszka <jan.kiszka@...>
---
.../files/debian-local-patch | 103
From: Jan Kiszka <jan.kiszka@...>
Forgotten to remove in f1e559498116.
Signed-off-by: Jan Kiszka <jan.kiszka@...>
---
.../files/debian-local-patch | 103
|
By
Jan Kiszka
·
#8260
·
|
|
[isar-cip-core][PATCH v2 00/13] Fixes and improvements for SWUpdate images, kernel/config update
Changes in v2:
- add plugin fix for empty command line case
Various update and enhancement I try to summarize here:
- qemu-arm64 enabling for SWUpdate/secure boot using the UEFI pattern
- update to
Changes in v2:
- add plugin fix for empty command line case
Various update and enhancement I try to summarize here:
- qemu-arm64 enabling for SWUpdate/secure boot using the UEFI pattern
- update to
|
By
Jan Kiszka
·
#8259
·
|
|
[isar-cip-core][PATCH v2 05/13] linux-cip: Update cip-kernel-config for QEMU and ipc227e
From: Jan Kiszka <jan.kiszka@...>
Needed for iTCO under -rt kernels, swupdate support on arm64 and xattr
for squashfs in swupudate scenarios.
Signed-off-by: Jan Kiszka
From: Jan Kiszka <jan.kiszka@...>
Needed for iTCO under -rt kernels, swupdate support on arm64 and xattr
for squashfs in swupudate scenarios.
Signed-off-by: Jan Kiszka
|
By
Jan Kiszka
·
#8258
·
|
|
[isar-cip-core][PATCH v2 06/13] linux-cip: Update to 4.19.239-cip72 and 5.10.112-cip6
From: Jan Kiszka <jan.kiszka@...>
Signed-off-by: Jan Kiszka <jan.kiszka@...>
---
...{linux-cip_4.19.235-cip70.bb => linux-cip_4.19.239-cip72.bb} | 2 +-
From: Jan Kiszka <jan.kiszka@...>
Signed-off-by: Jan Kiszka <jan.kiszka@...>
---
...{linux-cip_4.19.235-cip70.bb => linux-cip_4.19.239-cip72.bb} | 2 +-
|
By
Jan Kiszka
·
#8257
·
|
|
[isar-cip-core][PATCH v2 02/13] initramfs-etc-overlay-hook: Install overlay module
From: Jan Kiszka <jan.kiszka@...>
Needed in case overlay support is built as kernel module.
Signed-off-by: Jan Kiszka <jan.kiszka@...>
---
.../files/etc-overlay.hook
From: Jan Kiszka <jan.kiszka@...>
Needed in case overlay support is built as kernel module.
Signed-off-by: Jan Kiszka <jan.kiszka@...>
---
.../files/etc-overlay.hook
|
By
Jan Kiszka
·
#8256
·
|
|
[isar-cip-core][PATCH v2 01/13] initramfs-etc-overlay-hook: Improve error reporting of script
From: Jan Kiszka <jan.kiszka@...>
Fail loudly in case the overlay cannot be mounted.
Signed-off-by: Jan Kiszka <jan.kiszka@...>
---
From: Jan Kiszka <jan.kiszka@...>
Fail loudly in case the overlay cannot be mounted.
Signed-off-by: Jan Kiszka <jan.kiszka@...>
---
|
By
Jan Kiszka
·
#8255
·
|
|
linux-4.4.y-cip-rebase: patches in wrong order?
Hi!
In previous linux-4.4.y-cip-rebases, order of patches was:
git log:
[CIP patches]
[Greg's stable tree]
[Linus tree]
With start of self-maintainance, we now have:
git log:
[-st patches]
[CIP
Hi!
In previous linux-4.4.y-cip-rebases, order of patches was:
git log:
[CIP patches]
[Greg's stable tree]
[Linus tree]
With start of self-maintainance, we now have:
git log:
[-st patches]
[CIP
|
By
Pavel Machek
·
#8254
·
|
|
CIP IRC weekly meeting today on libera.chat
Hi all,
Kindly be reminded to attend the weekly meeting through IRC to discuss
technical topics with CIP kernel today. Our channel is the following:
irc:irc.libera.chat:6667/cip
The IRC meeting
Hi all,
Kindly be reminded to attend the weekly meeting through IRC to discuss
technical topics with CIP kernel today. Our channel is the following:
irc:irc.libera.chat:6667/cip
The IRC meeting
|
By
Jan Kiszka
·
#8253
·
|
|
New CVE entries this week
Hi !
It's this week's CVE report.
This week reported 4 new CVEs and 2 updated CVEs.
There were no critical vulnerabilities this week.
* New CVEs
CVE-2022-1508 : io_uring: reexpand under-reexpanded
Hi !
It's this week's CVE report.
This week reported 4 new CVEs and 2 updated CVEs.
There were no critical vulnerabilities this week.
* New CVEs
CVE-2022-1508 : io_uring: reexpand under-reexpanded
|
By
Masami Ichikawa
·
#8252
·
|
|
[isar-cip-core][PATCH 12/12] start-qemu.sh: Add support for SWUpdate and secure boot mode to arm64
From: Jan Kiszka <jan.kiszka@...>
We just need to pick up the newly deployed firmware.bin as -bios,
analogously to the x86's OVMF, and switch to a disk image. A separate
key storage is not
From: Jan Kiszka <jan.kiszka@...>
We just need to pick up the newly deployed firmware.bin as -bios,
analogously to the x86's OVMF, and switch to a disk image. A separate
key storage is not
|
By
Jan Kiszka
·
#8251
·
|
|
[isar-cip-core][PATCH 11/12] Enable SWUpdate with and w/o secure boot for QEMU arm64
From: Jan Kiszka <jan.kiszka@...>
Hook up the new U-Boot recipe, provide new wks files and disable the
watchdog for EFI Boot Guard - that's all what's need to allow offering
SWUpdate and
From: Jan Kiszka <jan.kiszka@...>
Hook up the new U-Boot recipe, provide new wks files and disable the
watchdog for EFI Boot Guard - that's all what's need to allow offering
SWUpdate and
|
By
Jan Kiszka
·
#8250
·
|
|
[isar-cip-core][PATCH 08/12] efibootguard: Use new unified kernel image generation
From: Jan Kiszka <jan.kiszka@...>
Switch to the unified kernel image and its generator script that EFI
Boot Guard now provides. So far this only simplifies the generation
process. But it will
From: Jan Kiszka <jan.kiszka@...>
Switch to the unified kernel image and its generator script that EFI
Boot Guard now provides. So far this only simplifies the generation
process. But it will
|
By
Jan Kiszka
·
#8249
·
|
|
[isar-cip-core][PATCH 06/12] linux-cip: Update to 4.19.239-cip72 and 5.10.112-cip6
From: Jan Kiszka <jan.kiszka@...>
Signed-off-by: Jan Kiszka <jan.kiszka@...>
---
...{linux-cip_4.19.235-cip70.bb => linux-cip_4.19.239-cip72.bb} | 2 +-
From: Jan Kiszka <jan.kiszka@...>
Signed-off-by: Jan Kiszka <jan.kiszka@...>
---
...{linux-cip_4.19.235-cip70.bb => linux-cip_4.19.239-cip72.bb} | 2 +-
|
By
Jan Kiszka
·
#8248
·
|
|
[isar-cip-core][PATCH 07/12] efibootguard: Update to 0.11 release
From: Jan Kiszka <jan.kiszka@...>
This version bring the new unified kernel stub and script to generate
unified kernel images from that.
That script requires python3, so we need to expand
From: Jan Kiszka <jan.kiszka@...>
This version bring the new unified kernel stub and script to generate
unified kernel images from that.
That script requires python3, so we need to expand
|
By
Jan Kiszka
·
#8247
·
|
|
[isar-cip-core][PATCH 10/12] u-boot-qemu-arm64: Add recipe for customized version based on 2022.04
From: Jan Kiszka <jan.kiszka@...>
This will be used for booting via UEFI, both in open and locked-down
secure mode. The secure mode variations can be selected by adding
"secureboot" to
From: Jan Kiszka <jan.kiszka@...>
This will be used for booting via UEFI, both in open and locked-down
secure mode. The secure mode variations can be selected by adding
"secureboot" to
|
By
Jan Kiszka
·
#8246
·
|
|
[isar-cip-core][PATCH 09/12] efibootguard: Add support for embedding DTBs into unified kernel images
From: Jan Kiszka <jan.kiszka@...>
Pick up the DTBs specified via DTB_FILES and embed them into the unified
kernel image that the wic plugin can generate. This does not work for
normal
From: Jan Kiszka <jan.kiszka@...>
Pick up the DTBs specified via DTB_FILES and embed them into the unified
kernel image that the wic plugin can generate. This does not work for
normal
|
By
Jan Kiszka
·
#8245
·
|