From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 57A73C64EC4 for ; Sun, 19 Feb 2023 02:51:01 +0000 (UTC) Received: from list by lists.xenproject.org with outflank-mailman.497652.768520 (Exim 4.92) (envelope-from ) id 1pTZmO-0002WO-3r; Sun, 19 Feb 2023 02:50:20 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version Received: by outflank-mailman (output) from mailman id 497652.768520; Sun, 19 Feb 2023 02:50:20 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1pTZmN-0002WG-V2; Sun, 19 Feb 2023 02:50:19 +0000 Received: by outflank-mailman (input) for mailman id 497652; Sun, 19 Feb 2023 02:50:18 +0000 Received: from se1-gles-sth1-in.inumbo.com ([159.253.27.254] helo=se1-gles-sth1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1pTZmM-0002Vk-Cb for xen-devel@lists.xenproject.org; Sun, 19 Feb 2023 02:50:18 +0000 Received: from wout4-smtp.messagingengine.com (wout4-smtp.messagingengine.com [64.147.123.20]) by se1-gles-sth1.inumbo.com (Halon) with ESMTPS id 22412452-b000-11ed-933d-83870f6b2ba8; Sun, 19 Feb 2023 03:50:16 +0100 (CET) Received: from compute6.internal (compute6.nyi.internal [10.202.2.47]) by mailout.west.internal (Postfix) with ESMTP id 8BCAF32004AE; Sat, 18 Feb 2023 21:50:11 -0500 (EST) Received: from mailfrontend1 ([10.202.2.162]) by compute6.internal (MEProxy); Sat, 18 Feb 2023 21:50:12 -0500 Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sat, 18 Feb 2023 21:50:08 -0500 (EST) X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: 22412452-b000-11ed-933d-83870f6b2ba8 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= invisiblethingslab.com; h=cc:cc:content-transfer-encoding:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:sender:subject:subject:to:to; s=fm1; t= 1676775011; x=1676861411; bh=Jd5MY4VF+HfxIL9l1Qbaez8l8BHoBek9uNF wPZ67yiU=; b=QKQ/J0vQkX9MbHGacr4wEPdWAr5xl/9SNjvecRhMzMdM96RZxg8 6CQYia4YHkA0l991Y+WrZyF+3Ek9IBUAmDqojZYjpyAsQTip6VzvNLSo4umvV66x uO3xh6O9Nqi8RnGkdebJkCDSrLYXi+UkEl3cr3Ocec5X79fV9e8oGu7FnSStnMGS b3bR1y9k5/KxKeSlZcJmxRTRkvmXzftizxjFkBdghphttYjWEUTeInl+Dhuer882 Sc9vFK412HkxgwlD+TafJqJtfm/j4FnWMx8Y5m4wKYOSwQGAX/i+wgSNDx/TyMZW /LLVo3vobkZbDcf3oAE16u6GDU6vEgwATjA== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:sender:subject :subject:to:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm1; t=1676775011; x=1676861411; bh=Jd5MY4VF+HfxI L9l1Qbaez8l8BHoBek9uNFwPZ67yiU=; b=DbZN6PnltLkBRh47q6kh75A3JytDW cWI9a0pEjFlKzmMTVoHlD9dMOlnlkSIifswQfcrtZLPkxX13wN5GBSY2bzXhMbOh qRn7tayFQ82UC7cSL8DgJVdbmPjsOQYv6ZqJFgp47azsAfJeyTUZ5G+EAG+Fha53 b7NA/pNZIjVAGJ81leMBb4mE56HR1IGfPGGwe12+UcFsieuHbP0fUdhU9gNsLOzA UwcBj5yIQzh3Vwip6K3P0h2ONLJwgtl204PlJH65CuJ1UEucgVQtOt8YejjtZEZo nP3/a7hlJIz2zAC2jS7Km6JDUqbP/gm/UMauXS8c1u6v839wXA+RnwJ6w== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvhedrudejvddghedtucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhephffvvefufffkofgjfhgggfestdekredtredttdenucfhrhhomhepffgvmhhi ucforghrihgvucfqsggvnhhouhhruceouggvmhhisehinhhvihhsihgslhgvthhhihhngh hslhgrsgdrtghomheqnecuggftrfgrthhtvghrnheptefhhfdtkefhkefgjeduffehuedt gfduveejiedvffdvgeevledttdegvefhueegnecuffhomhgrihhnpeigvghnrdhorhhgpd gtohhnfhhighdrmhhknecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghi lhhfrhhomhepuggvmhhisehinhhvihhsihgslhgvthhhihhnghhslhgrsgdrtghomh X-ME-Proxy: Feedback-ID: iac594737:Fastmail From: Demi Marie Obenour To: xen-devel@lists.xenproject.org Cc: Demi Marie Obenour , =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?= , Andrew Cooper , George Dunlap , Jan Beulich , Julien Grall , Stefano Stabellini , Wei Liu , Konrad Rzeszutek Wilk , Ross Lagerwall , Samuel Thibault , Anthony PERARD , Doug Goldstein Subject: [PATCH v4 0/3] Stop using insecure transports Date: Sat, 18 Feb 2023 21:46:12 -0500 Message-Id: X-Mailer: git-send-email 2.39.1 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Obtaining code over an insecure transport is a terrible idea for blatently obvious reasons. Even for non-executable data, insecure transports are considered deprecated. Changes since v3: - Drop patch 4, which is an unrelated removal of unused code. - Do not fail with an error if one tries to build the I/O emulator, vTPM, or vTPM manager stubdomains and passes --enable-extfiles. The user may have provided alternate download URLs via environment variables. Changes since v2: - Drop patches 5 and 6, which changed links not used by automated tools. These patches are the least urgent and hardest to review. - Ensure that no links are broken, and fail with an error instead of trying to use links that *are* broken. Demi Marie Obenour (3): Use HTTPS for all xenbits.xen.org Git repos Build system: Replace git:// and http:// with https:// Automation and CI: Replace git:// and http:// with https:// Config.mk | 20 ++++++-------------- README | 4 ++-- automation/build/centos/CentOS-7.2.repo | 8 ++++---- automation/build/debian/stretch-llvm-8.list | 4 ++-- automation/build/debian/unstable-llvm-8.list | 4 ++-- automation/scripts/qemu-smoke-dom0-arm32.sh | 2 +- docs/misc/livepatch.pandoc | 2 +- docs/process/xen-release-management.pandoc | 2 +- scripts/get_maintainer.pl | 2 +- stubdom/configure | 18 +++++++++--------- stubdom/configure.ac | 18 +++++++++--------- tools/firmware/etherboot/Makefile | 6 +----- 12 files changed, 39 insertions(+), 51 deletions(-) -- Sincerely, Demi Marie Obenour (she/her/hers) Invisible Things Lab