Skip to content

Move efitools & sbsigntool recipes from meta-secure-core#883

Open
jetm wants to merge 2 commits into
openembedded:masterfrom
jetm:add-efitools-sbsigntool
Open

Move efitools & sbsigntool recipes from meta-secure-core#883
jetm wants to merge 2 commits into
openembedded:masterfrom
jetm:add-efitools-sbsigntool

Conversation

@jetm

@jetm jetm commented Oct 11, 2024

Copy link
Copy Markdown

efitools is coming from meta-secure-code. There are many cases where meta-secure-code is added just to use efitools, like Wind-River/meta-secure-core#26

efitools has a dependency on sbsigntool.

Javier Tia added 2 commits October 11, 2024 17:10
sbsigntool is used for signing UEFI binaries for use with secure boot.
It's part of efitools, which is coming from meta-secure-code. There are
many cases where meta-secure-code is added just to use efitools. 

Signed-off-by: Javier Tia <javier.tia@linaro.org>
Tools to support reading and manipulating the UEFI signature database.

efitools is coming from meta-secure-code. There are many cases where
meta-secure-code is added just to use efitools.

Signed-off-by: Javier Tia <javier.tia@linaro.org>
@jetm

jetm commented Oct 11, 2024

Copy link
Copy Markdown
Author

Tagging @yizhao1 to keep it in the loop

@quaresmajose quaresmajose left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@kraj

kraj commented Oct 17, 2024

Copy link
Copy Markdown
Contributor

I would like to see some activity on the patches, there are many in these recipes and none of them are upstream or on its way to upstream, its quite a bit to carry if we apply it here, since it has a chance to fall back on maintainers back. Please submit these patches upstream and get some feedback

@jetm

jetm commented Nov 6, 2024

Copy link
Copy Markdown
Author

Sending meta-secure-core efitool patches to efitool upstream to get feedback from efitool maintainer

kraj pushed a commit to YoeDistro/meta-openembedded that referenced this pull request Jul 8, 2026
Changelog:
===========
- Fix size_t overflow in 'amqp_decode_bytes' bounds check leading to
  out-of-bounds read (GHSA-jgjf-7fwf-f3c7, openembedded#888)
- Fix heap buffer overflow in 'amqp_frame_to_bytes' for oversized body frames
  (GHSA-hfjv-vcp3-39wh, openembedded#892)
- 'librabbitmq-tools' fall back to the 'AMQP_URL' environment variable when no
  connection options are given on the command line (openembedded#887)
- Fix undefined behavior in 'amqp_decode_properties' when decoding
  content-header property flags (openembedded#883, openembedded#885)
- Fix 'ioctlsocket' type mismatch on Windows (openembedded#890)
- Document buffer lifetime requirement of 'amqp_decode_table''s encoded buffer
  to prevent use-after-free misuse (openembedded#895)
- 'librabbitmq-tools' now enable default SSL certificate verification paths
  unless '--no-default-cert-paths' is passed (fixes openembedded#868, openembedded#893)
- Building the tools now requires POPT v1.14 or newer

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants