aboutsummaryrefslogtreecommitdiffstats
AgeCommit message (Collapse)Author
2021-12-25clamav: fix useradd warningArmin Kuster
WARNING: security-build-image-1.0-r0 do_rootfs: [log_check] security-build-image: found 2 warning messages in the logfile: [log_check] warning: user clamav does not exist - using root [log_check] warning: group clamav does not exist - using root clamav-freshclam is the package needing to have its user/group set. Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-12-25libest: does not build with openssl 3.xArmin Kuster
blacklist for now. Remove from pkg grp Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-12-25tpm2-pkcs11: update to 1.7.0Armin Kuster
drop patch now included. Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-11-28meta-parsec/README.md: fix for append operator combined with +=Yi Zhao
Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-11-28openssl-tpm-engine: fix warning for append operator combined with +=Yi Zhao
Fixes: WARNING: openssl-tpm-engine_0.5.0.bb: CFLAGS:append += is not a recommended operator combination, please replace it. Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-11-28apparmor: fix warning of remove operator combined with +=Kai Kang
Fix warning for apparmor: | WARNING: /path/to/meta-security/recipes-mac/AppArmor/apparmor_3.0.1.bb: | RDEPENDS:${PN}:remove += is not a recommended operator combination, | please replace it. Signed-off-by: Kai Kang <kai.kang@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-11-07python3-fail2ban: remove /runArmin Kuster
Fixes: ERROR: python3-fail2ban-0.11.2-r0 do_package_qa: QA Issue: python3-fail2ban installs files in /run, but it is expected to be empty [empty-dirs] Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-11-07bastille: Create /var/log/Bastille in runtimeArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-11-07sssd: Create /var/log/sssd in runtimeArmin Kuster
/var/log is normally a link to /var/volatile/log and /var/volatile is a tmpfs mount. So anything created in /var/log will not be available when the tmpfs is mounted. [Thanks to Peter Kjellerstedt for example] Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-11-07tpm2-tss: fix fapi package configStefan Mueller-Klieser
When enabling fapi, the build breaks with: | configure: error: Package requirements (libcurl) were not met: | No package 'libcurl' found This adds the missing dependency and bundles the additional config files in the base package. Signed-off-by: Stefan Müller-Klieser <s.mueller-klieser@phytec.de> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-11-04recipes: Update SRC_URI branch and protocolsArmin Kuster
This patch updates SRC_URIs using git to include branch=master if no branch is set and also to use protocol=https for github urls as generated by the conversion script in OE-Core. Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-10-26tpm2-pkcs11: update to 1.7.0Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-10-26tpm2-openssl: add new pkgArmin Kuster
openssl 3.x support for tpm2 tss function found in tpm2-ssl Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-10-26openssl-tpm-engine: fix build issue with openssl 3Armin Kuster
ERROR: openssl-tpm-engine-0.5.0-r0 do_package: QA Issue: openssl-tpm-engine: Files/directories were installed but not shipped in any package: /usr/lib/engines-3/tpm.so fix engine locations Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-10-26tpm2-tools: update to 5.2Armin Kuster
openssl 3.0 support see https://github.com/tpm2-software/tpm2-tools/releases/tag/5.2 Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-10-26apparmor: Add a python 3.10 compatability patchArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-10-24opendnssec: blacklist do to ldns being blacklistedArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-10-24Parsec service. Update PACKAGECONFIG definitions and README.mdAnton Antonov
Signed-off-by: Anton Antonov <Anton.Antonov@arm.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-10-24meta-parsec/README: remove rust layer req.Armin Kuster
Rust is now in core. No need to include the layer referenece. Drop Priority and ref from repo definition. Not used Signed-off-by: Armin Kuster <akuster808@gmail.com> [v2] fixup mailing list
2021-10-18sssd: re-package to fix QA issuesKai Kang
It packages all file in ${libdir} to package sssd, including the .so symlink files. Then it causes QA issues: | ERROR: QA Issue: sssd rdepends on dbus-dev [dev-deps] | ERROR: QA Issue: sssd rdepends on ding-libs-dev [dev-deps] So re-package sssd then the .so symlink files and .pc files are packaged to sssd-dev which should be. File ${libdir}/libsss_sudo.so is not a symlink file but packaged to sssd-dev too. Then causes another QA issue: | ERROR: sssd-2.5.2-r0 do_package_qa: QA Issue: -dev package sssd-dev contains non-symlink .so '/usr/lib/libsss_sudo.so' [dev-elf] So create a new sub-package libsss-sudo to package file libsss_sudo.so and make sssd rdepends on it. Signed-off-by: Kai Kang <kai.kang@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-10-18python3-fail2ban: fix build failure and cleanupArmin Kuster
Fixes: error in fail2ban setup command: use_2to3 is invalid. ERROR: 'python3 setup.py build ' execution failed. drop custom fail2ban_setup.py remove pyhton-fail2ban as its a symlink to python3 Update to tip for 11.2 branch Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-10-18recipes-security/chipsec: platform security assessment frameworkLiwei Song
Add chipsec, tools to dump and analyzing hardware, system firmware components, like PCH register, ioport or iomem configuration space. Signed-off-by: Liwei Song <liwei.song@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-10-18swtpm: update to 0.6.1Kristian Klausen
swtpm no longer depends on Python[1] so the dependencies have been removed. "inherit perlnative" has been added due to (in oe-core): deda455b3c ("bitbake.conf: drop pod2man from hosttools") Some leftover dependencies have also been removed, ex: tpm-tools required in the past by swtpm_setup.sh (<0.4.0)[2]. [1] https://github.com/stefanberger/swtpm/issues/437 [2] https://github.com/stefanberger/swtpm/commit/eee8cb5dfb13f87140dddda38f65bf61aff19508 Signed-off-by: Kristian Klausen <kristian@klausen.dk> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-28Upgrade parsec-service 0.8.1 and parsec-tool 0.4.0Anton Antonov
Signed-off-by: Anton Antonov <Anton.Antonov@arm.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-28libtpm: update to 0.8.7Kristian Klausen
Signed-off-by: Kristian Klausen <kristian@klausen.dk> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-28clamav: Set clamav:clamav ownership on /var/lib/clamav in do_installZoltán Böszörményi
Also, rearrange the runtime-dependencies a little so clamav-freshclam is installed later than clamav. The issue is that clamav-freshclam ships /var/lib/clamav and the main clamav package uses chown in pkg_postinst to set the ownership of this directory. But pkg_postinst is not marked as "ontarget" so this chown only took effect when upgrading or reinstalling the package. So when clamav is part of an OS image out of the box, freshclamd cannot populate this directory since it's running under the clamav user. Fix this by creating /var/lib/clamav with the proper ownership in do_install and rearrange runtime-dependencies, so clamav-freshclam RDEPENDS on clamav and clamav relaxes its runtime-dependency into RRECOMMENDS so clamav-freshclam is installed later than clamav, avoiding these warnings: Installing : clamav-freshclam-... 487/1954 warning: user clamav does not exist - using root warning: group clamav does not exist - using root Signed-off-by: Zoltán Böszörményi <zboszor@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-28dmverity: Make use of DATA_BLOCK_SIZE variable in initrdscript.Christer Fletcher
DATA_BLOCK_SIZE variable was set in dm-verity-img.bbclass at build time but the initrdscript was not updated to pass the DATA_BLOCK_SIZE to the veritysetup. Now the functionality is complete. Signed-off-by: Paulo Neves <paulo.neves1@inter.ikea.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-28recipes-security/fscrypt: Add fscrypt .bb fileBhupesh Sharma
fscrypt is a high-level tool for the management of Linux filesystem encryption. fscrypt manages metadata, key generation, key wrapping, PAM integration, and provides a uniform interface for creating and modifying encrypted directories. Add recipe for the same in 'recipes-security'. Signed-off-by: Bhupesh Sharma <bhupesh.sharma@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-28chkrootkit: update to 0.55Armin Kuster
changes: Umbreon Linux Rootkit detection Kinsing.A Backdoor RotaJakito Backdoor Minor bug fixes Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-16tpm-quote-tools: Update SRC_URIArmin Kuster
The wget now asks for user info so git clone. Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-15isic: set precise BSD licenseArmin Kuster
"BSD" is ambiguous, use the precise licenses BSD-2-Clause Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-15checksec: set precise BSD licenseArmin Kuster
"BSD" is ambiguous, use the precise licenses BSD-3-Clause Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-15opendnssec: set precise BSD licenseArmin Kuster
"BSD" is ambiguous, use the precise licenses BSD-2-Clause Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-15ibmswtpm2: set precise BSD licenseArmin Kuster
"BSD" is ambiguous, use the precise licenses BSD-2-Clause Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-15ibmtpm2tss: set precise BSD licenseArmin Kuster
"BSD" is ambiguous, use the precise licenses BSD-2-Clause Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-15trousers: set precise BSD licenseArmin Kuster
"BSD" is ambiguous, use the precise licenses BSD-3-Clause Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-15cryfs: drop recipeArmin Kuster
it was accidently pushed and is incmomplete Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-10sssd: 2.5.1 -> 2.5.2Kai Kang
SSSD 2.5.2 Highlights * General information - originalADgidNumber attribute in the SSSD cache is now indexed * New features - Debug messages in data provider include a unique request ID that can be used to track the request from its start to its end (requires libtevent >= 0.11.0) * Important fixes - Update large files in the files provider in batches to avoid timeouts * Configuration changes - Add new config option fallback_to_nss Full release notes: * https://sssd.io/release-notes/sssd-2.5.2.html And backport patch to fix CVE-2021-3621. CVE: CVE-2021-3621 Signed-off-by: Kai Kang <kai.kang@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-09-06dm-verity-img.bbclass: Expose --data-block-size for configurationChrister Fletcher
Add DM_VERITY_IMAGE_DATA_BLOCK_SIZE to be able to set the --data-block-size used in veritysetup. Tuning this value effects the performance and size of the resulting image. Signed-off-by: Christer Fletcher <christer.fletcher@inter.ikea.com> Signed-off-by: Paulo Neves <paulo.neves1@inter.ikea.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-08-29meta: Fix typosGeorge Liu
Fix the variable spelling errors s/SKIP_META_SECUIRTY_SANITY_CHECK/SKIP_META_SECURITY_SANITY_CHECK Signed-off-by: George Liu <liuxiwei@inspur.com> Acked-by: Martin Jansa <Martin.Jansa@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-08-27kas: remove rust layersArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-08-26harden-image-minimal: fix useradd inheritArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-08-26layer.conf: drop meta-rustArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-08-26layer.conf: drop dynamic-layerArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-08-26suricata: rust is in coreArmin Kuster
drop dynamic-layer Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-08-26krill: Rust is in core nowArmin Kuster
drop dynamic-layer Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-08-26dm-verity-img.bbclass: more overided fixupsArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-08-26meta-integrity: kernel-modsign: Change weak default valueDaiane Angolini
Assign a weak default value for MODSIGN_KEY_DIR so the other layers can set a default value for them as well. Signed-off-by: Daiane Angolini <daiane.angolini@foundries.io> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-08-26README: fix mailing lists and a typoMarta Rybczynska
A number of typo fixes: - tmp->tpm in the DISTRO_FEATURES - update the mailing list address as it was out of date - update the distro name in the subject Signed-off-by: Marta Rybczynska <rybczynska@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2021-08-26README: fix mailing listsMarta Rybczynska
The address included in the meta-hardening documentation does not work and was changed in other places in 2019. Signed-off-by: Marta Rybczynska <rybczynska@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>