* [meta-security][PATCH 00/15] Assorted updates 08/26
@ 2026-08-26 20:57 Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 01/15] aide: Fix compilation with nettle 4.x Scott Murray
` (15 more replies)
0 siblings, 16 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
My apologies for being slow in getting this out, this patch series rolls
up the contributed patches from the past few months along with some
other fixes from myself. These changes are queued on the master-next
branch if you would like to check them out to test yourself. I intend
to merge these to master branch Friday evening (EDT, August 28) unless
there are objections. I should have the relevant backports to wrynose
and scarthgap out for early next week.
Scott
Bin Cao (1):
samhain: fix server startup failure on systemd-based systems
Esa Jaaskela (1):
aide: Fix unstable install task hash
Gaël PORTAY (3):
dm-verity: remove unused variable
wic: document the meta-intel dependency in the dm-verity hash example
docs: update path of wic files
Krupal Ka Patel (1):
tpm2-tools: fix PACKAGECONFIG typo
Peter Marko (2):
tpm2-tools: set status for CVE-2017-7524 and CVE-2024-29039
tpm2-tss: set status for CVE-2024-29040
Sandeep J (1):
README: fix broken URLs in meta-integrity and ccs-tools
Scott Murray (4):
aide: Fix compilation with nettle 4.x
suricata: handle oe_cargo_build removal
meta-integrity: Fix ima-evm-utils LICENSE
meta-tpm: Fix SUMMARY/HOMEPAGE in affected recipes
Shreejit C (1):
meta-tpm: Add missing recipe metadata (HOMEPAGE/SUMMARY)
Wang Mingyu (1):
fix LICENSE variable syntax to suppress QA warning
classes/aide-db-init.bbclass | 11 +++-
classes/dm-verity-img.bbclass | 1 -
docs/dm-verity-systemd-x86-64.txt | 6 +--
docs/dm-verity.txt | 2 +-
.../wic/systemd-bootdisk-dmverity-hash.wks.in | 1 +
meta-integrity/README.md | 4 +-
.../ima-evm-utils/ima-evm-utils_1.5.bb | 2 +-
.../recipes-core/images/security-tpm-image.bb | 2 +-
.../images/security-tpm2-image.bb | 2 +-
.../packagegroup/packagegroup-security-tpm.bb | 2 +-
.../packagegroup-security-tpm2.bb | 1 +
meta-tpm/recipes-tpm/libtpm/libtpms_0.10.0.bb | 1 +
meta-tpm/recipes-tpm/swtpm/swtpm_0.10.0.bb | 1 +
.../openssl-tpm-engine_0.5.0.bb | 2 +-
.../tpm-tools/tpm-tools_1.3.9.2.bb | 1 +
.../tpm2-abrmd/tpm2-abrmd_3.0.0.bb | 1 +
.../tpm2-openssl/tpm2-openssl_1.3.0.bb | 1 +
.../tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb | 1 +
.../tpm2-pytss/python3-tpm2-pytss_2.3.0.bb | 1 +
.../recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb | 6 ++-
.../tpm2-tss-engine/tpm2-tss-engine_1.2.0.bb | 1 +
.../recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb | 3 ++
.../0002-Support-build-with-nettle-4.patch | 53 +++++++++++++++++++
recipes-ids/aide/aide_0.19.3.bb | 14 ++---
recipes-ids/crowdsec/crowdsec-licenses.inc | 2 +-
recipes-ids/crowdsec/crowdsec_1.7.7.bb | 2 +-
...-set-SetLockfilePath-to-run-yule.pid.patch | 41 ++++++++++++++
recipes-ids/samhain/files/samhain-client.init | 3 +-
recipes-ids/samhain/files/samhain-server.init | 3 +-
recipes-ids/samhain/samhain.inc | 1 +
recipes-ids/suricata/suricata_8.0.4.bb | 11 ++--
recipes-mac/AppArmor/apparmor_4.0.3.bb | 2 +-
recipes-mac/ccs-tools/README | 2 +-
recipes-perl/perl/lib-perl_0.63.bb | 2 +-
recipes-perl/perl/libwhisker2-perl_2.5.bb | 2 +-
recipes-scanners/clamav/clamav_1.4.4.bb | 4 +-
recipes-security/libgssglue/libgssglue_0.9.bb | 2 +-
37 files changed, 159 insertions(+), 38 deletions(-)
create mode 100644 recipes-ids/aide/aide/0002-Support-build-with-nettle-4.patch
create mode 100644 recipes-ids/samhain/files/0013-yulerc-set-SetLockfilePath-to-run-yule.pid.patch
--
2.55.0
^ permalink raw reply [flat|nested] 17+ messages in thread
* [meta-security][PATCH 01/15] aide: Fix compilation with nettle 4.x
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 02/15] suricata: handle oe_cargo_build removal Scott Murray
` (14 subsequent siblings)
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
Backport unreleased change from upstream to handle building with nettle
4.x now that openembedded-core has upgraded to it.
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
.../0002-Support-build-with-nettle-4.patch | 53 +++++++++++++++++++
recipes-ids/aide/aide_0.19.3.bb | 1 +
2 files changed, 54 insertions(+)
create mode 100644 recipes-ids/aide/aide/0002-Support-build-with-nettle-4.patch
diff --git a/recipes-ids/aide/aide/0002-Support-build-with-nettle-4.patch b/recipes-ids/aide/aide/0002-Support-build-with-nettle-4.patch
new file mode 100644
index 0000000..d9c6fad
--- /dev/null
+++ b/recipes-ids/aide/aide/0002-Support-build-with-nettle-4.patch
@@ -0,0 +1,53 @@
+From 84936cec8ddb7151327563800d752d1d20e39224 Mon Sep 17 00:00:00 2001
+From: Hannes von Haugwitz <hannes@vonhaugwitz.com>
+Date: Tue, 26 May 2026 21:41:52 +0200
+Subject: [PATCH] Support build with nettle 4
+
+* closes: #218
+
+Upstream-Status: Backport [https://github.com/aide/aide/commit/61130addb02a58d7de95d6b8f344ab9b6151d6aa]
+Signed-off-by: Scott Murray <scott.murray@konsulko.com>
+---
+ ChangeLog | 3 +++
+ src/md.c | 6 ++++++
+ 2 files changed, 9 insertions(+)
+
+diff --git a/ChangeLog b/ChangeLog
+index 89905e3..5b3963e 100644
+--- a/ChangeLog
++++ b/ChangeLog
+@@ -1,3 +1,6 @@
++2026-05-26 Hannes von Haugwitz <hannes@vonhaugwitz.com>
++ * Support build with nettle 4 (closes: #218)
++
+ 2026-01-31 Hannes von Haugwitz <hannes@vonhaugwitz.com>
+ * Release aide 0.19.3
+
+diff --git a/src/md.c b/src/md.c
+index e4e66ad..1aec9d9 100644
+--- a/src/md.c
++++ b/src/md.c
+@@ -47,6 +47,8 @@
+ #include <nettle/gosthash94.h>
+ #include <nettle/streebog.h>
+
++#include <nettle/version.h>
++
+ typedef struct {
+ nettle_hash_init_func *init;
+ nettle_hash_update_func *update;
+@@ -166,7 +168,11 @@ int close_md(struct md_container* md, md_hashsums * hs, const char *filename, co
+ for (HASHSUM i = 0 ; i < num_hashes ; ++i) {
+ DB_ATTR_TYPE h = ATTR(hashsums[i].attribute);
+ if (h&md->calc_attr) {
++#if NETTLE_VERSION_MAJOR < 4
+ nettle_functions[i].digest(&md->ctx[i].md5, hashsums[i].length, hs->hashsums[i]);
++#else
++ nettle_functions[i].digest(&md->ctx[i].md5, hs->hashsums[i]);
++#endif
+ }
+ }
+ #endif
+--
+2.47.3
+
diff --git a/recipes-ids/aide/aide_0.19.3.bb b/recipes-ids/aide/aide_0.19.3.bb
index 68e3bfa..8d4efbb 100644
--- a/recipes-ids/aide/aide_0.19.3.bb
+++ b/recipes-ids/aide/aide_0.19.3.bb
@@ -7,6 +7,7 @@ DEPENDS = "bison-native libpcre2"
SRC_URI = "https://github.com/aide/aide/releases/download/v${PV}/${BPN}-${PV}.tar.gz \
file://0001-Fixes-build-issues.patch \
+ file://0002-Support-build-with-nettle-4.patch \
file://aide.conf \
"
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 02/15] suricata: handle oe_cargo_build removal
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 01/15] aide: Fix compilation with nettle 4.x Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 03/15] samhain: fix server startup failure on systemd-based systems Scott Murray
` (13 subsequent siblings)
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
Handle upstream removal of oe_cargo_build function in oe-core commit
a64ac03a61 by renaming our local override to cargo_do_compile to get
the same effect.
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
recipes-ids/suricata/suricata_8.0.4.bb | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/recipes-ids/suricata/suricata_8.0.4.bb b/recipes-ids/suricata/suricata_8.0.4.bb
index b3ab261..5ae0d97 100644
--- a/recipes-ids/suricata/suricata_8.0.4.bb
+++ b/recipes-ids/suricata/suricata_8.0.4.bb
@@ -86,12 +86,17 @@ CFLAGS += "-Wno-error=incompatible-pointer-types \
# breaks building this recipe. Providing a copy of the original function
# Armin 2025/04/01
#
-oe_cargo_build () {
+# 08/2026 note - oe_cargo_build function inlined into cargo_do_compile
+# upstream in openembedded-core commit a64ac03a61, handle by renaming
+# our forked function to cargo_do_compile to override it directly.
+# This still works since before a64ac03a61 cargo_do_compile did nothing
+# but call oe_cargo_build.
+cargo_do_compile () {
export RUSTFLAGS="${RUSTFLAGS}"
bbnote "Using rust targets from ${RUST_TARGET_PATH}"
bbnote "cargo = $(which ${CARGO})"
- bbnote "${CARGO} build ${CARGO_BUILD_FLAGS}$@"
- "${CARGO}" build ${CARGO_BUILD_FLAGS}"$@"
+ bbnote "${CARGO} build ${CARGO_BUILD_FLAGS} $@"
+ "${CARGO}" build ${CARGO_BUILD_FLAGS} "$@"
}
do_compile () {
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 03/15] samhain: fix server startup failure on systemd-based systems
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 01/15] aide: Fix compilation with nettle 4.x Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 02/15] suricata: handle oe_cargo_build removal Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 04/15] README: fix broken URLs in meta-integrity and ccs-tools Scott Murray
` (12 subsequent siblings)
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
From: Bin Cao <bin.cao.cn@windriver.com>
Fix two issues preventing samhain-server (yule) from starting:
1. The compiled-in PID file path /var/run/samhain.pid fails because
/var/run is a symlink to /run on systemd-based systems, and
samhain's security check rejects symlinks for PID directories.
Add SetLockfilePath = /run/yule.pid to yulerc.template, following
the same approach used in 0004-Set-the-PID-Lock-path-for-samhain.pid
for the standalone/client configuration.
2. The init scripts unconditionally source /etc/default/rcS which does
not exist on systemd-based systems, producing a confusing error
message. Source it conditionally instead.
Signed-off-by: Bin Cao <bin.cao.cn@windriver.com>
(adapted against prior 4.5.3 upgrade)
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
...-set-SetLockfilePath-to-run-yule.pid.patch | 41 +++++++++++++++++++
recipes-ids/samhain/files/samhain-client.init | 3 +-
recipes-ids/samhain/files/samhain-server.init | 3 +-
recipes-ids/samhain/samhain.inc | 1 +
4 files changed, 46 insertions(+), 2 deletions(-)
create mode 100644 recipes-ids/samhain/files/0013-yulerc-set-SetLockfilePath-to-run-yule.pid.patch
diff --git a/recipes-ids/samhain/files/0013-yulerc-set-SetLockfilePath-to-run-yule.pid.patch b/recipes-ids/samhain/files/0013-yulerc-set-SetLockfilePath-to-run-yule.pid.patch
new file mode 100644
index 0000000..889fd9b
--- /dev/null
+++ b/recipes-ids/samhain/files/0013-yulerc-set-SetLockfilePath-to-run-yule.pid.patch
@@ -0,0 +1,41 @@
+From 7070832b4652f3cdaa2e37325fc6f9456859cb5d Mon Sep 17 00:00:00 2001
+From: Bin Cao <bin.cao.cn@windriver.com>
+Date: Mon, 25 May 2026 14:55:37 +0800
+Subject: [PATCH] yulerc: set SetLockfilePath to /run/yule.pid
+
+On systemd-based systems, /var/run is a symlink to /run. Samhain's
+security-hardened code uses lstat() to verify the PID file directory
+is a real directory and rejects symlinks. This causes yule (the samhain
+server) to fail to start with "Path of PID directory refers to a
+non-directory object".
+
+Set SetLockfilePath explicitly to /run/yule.pid to bypass the
+compiled-in default of /var/run/samhain.pid.
+
+This is the same approach used in 0004-Set-the-PID-Lock-path-for-
+samhain.pid.patch for the standalone/client configuration.
+
+Upstream-Status: Inappropriate [OE-specific configuration]
+Signed-off-by: Bin Cao <bin.cao.cn@windriver.com>
+---
+ yulerc.template | 4 ++++
+ 1 file changed, 4 insertions(+)
+
+diff --git a/yulerc.template b/yulerc.template
+index 512bc0d..24b437c 100644
+--- a/yulerc.template
++++ b/yulerc.template
+@@ -173,6 +173,10 @@ Daemon=yes
+ # SetLoopTime = 60
+ SetLoopTime = 600
+
++## Path to the PID file
++#
++SetLockfilePath = /run/yule.pid
++
+ ## Normally, client messages are regarded as data within a
+ ## server message of fixed severity. The following two
+ ## options cause the server to use the original severity/class
+--
+2.34.1
+
diff --git a/recipes-ids/samhain/files/samhain-client.init b/recipes-ids/samhain/files/samhain-client.init
index d5fabed..c714f8c 100644
--- a/recipes-ids/samhain/files/samhain-client.init
+++ b/recipes-ids/samhain/files/samhain-client.init
@@ -13,7 +13,8 @@ DAEMON=/usr/sbin/samhain
RETVAL=0
PIDFILE=/var/run/samhain.pid
-. /etc/default/rcS
+# Source rcS only if it exists (not present on systemd-based systems)
+[ -f /etc/default/rcS ] && . /etc/default/rcS
. /etc/default/samhain-client
diff --git a/recipes-ids/samhain/files/samhain-server.init b/recipes-ids/samhain/files/samhain-server.init
index c456e51..49a28de 100644
--- a/recipes-ids/samhain/files/samhain-server.init
+++ b/recipes-ids/samhain/files/samhain-server.init
@@ -13,7 +13,8 @@ DAEMON=/usr/sbin/yule
RETVAL=0
PIDFILE=/var/run/yule.pid
-. /etc/default/rcS
+# Source rcS only if it exists (not present on systemd-based systems)
+[ -f /etc/default/rcS ] && . /etc/default/rcS
. /etc/default/samhain-server
diff --git a/recipes-ids/samhain/samhain.inc b/recipes-ids/samhain/samhain.inc
index 95413cb..85359cd 100644
--- a/recipes-ids/samhain/samhain.inc
+++ b/recipes-ids/samhain/samhain.inc
@@ -20,6 +20,7 @@ SRC_URI = "https://la-samhna.de/archive/samhain_signed-${PV}.tar.gz \
file://0009-fix-build-with-new-version-attr.patch \
file://0010-Fix-initializer-element-is-not-constant.patch \
file://0001-Format-test-output-to-match-Automake-standards.patch \
+ file://0013-yulerc-set-SetLockfilePath-to-run-yule.pid.patch \
"
SRC_URI[sha256sum] = "e7837adfde3d59a23c59e1bf3ebacdf71bce018619194cfad938cd30cbb9d15b"
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 04/15] README: fix broken URLs in meta-integrity and ccs-tools
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
` (2 preceding siblings ...)
2026-08-26 20:57 ` [meta-security][PATCH 03/15] samhain: fix server startup failure on systemd-based systems Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 05/15] meta-tpm: Add missing recipe metadata (HOMEPAGE/SUMMARY) Scott Murray
` (11 subsequent siblings)
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
From: Sandeep J <Sandeep.J@windriver.com>
Update TOMOYO documentation URL:
http://tomoyo.sourceforge.jp/1.8/index.html.en
to:
https://tomoyo.sourceforge.net/1.8/index.html.en
Replace dead gmane.org permalink references with mail-archive.com
copies of the original Tizen dev mailing list messages:
http://permalink.gmane.org/gmane.comp.handhelds.tizen.devel/6281
to:
https://www.mail-archive.com/dev@lists.tizen.org/msg06106.html
http://permalink.gmane.org/gmane.comp.handhelds.tizen.devel/6275
to:
https://www.mail-archive.com/dev@lists.tizen.org/msg06100.html
Signed-off-by: Sandeep J <Sandeep.J@windriver.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
meta-integrity/README.md | 4 ++--
recipes-mac/ccs-tools/README | 2 +-
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/meta-integrity/README.md b/meta-integrity/README.md
index 92d24f8..9dcd518 100644
--- a/meta-integrity/README.md
+++ b/meta-integrity/README.md
@@ -270,5 +270,5 @@ No package manager is integrated with IMA/EVM. When updating packages,
files will end up getting installed without correct IMA/EVM attributes
and thus will not be usable when appraisal is turned on.
-[1] http://permalink.gmane.org/gmane.comp.handhelds.tizen.devel/6281
-[2] http://permalink.gmane.org/gmane.comp.handhelds.tizen.devel/6275
+[1] https://www.mail-archive.com/dev@lists.tizen.org/msg06106.html
+[2] https://www.mail-archive.com/dev@lists.tizen.org/msg06100.html
diff --git a/recipes-mac/ccs-tools/README b/recipes-mac/ccs-tools/README
index 0381814..dffb933 100644
--- a/recipes-mac/ccs-tools/README
+++ b/recipes-mac/ccs-tools/README
@@ -1,5 +1,5 @@
Documentation:
-http://tomoyo.sourceforge.jp/1.8/index.html.en
+https://tomoyo.sourceforge.net/1.8/index.html.en
To start via command line add:
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 05/15] meta-tpm: Add missing recipe metadata (HOMEPAGE/SUMMARY)
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
` (3 preceding siblings ...)
2026-08-26 20:57 ` [meta-security][PATCH 04/15] README: fix broken URLs in meta-integrity and ccs-tools Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 06/15] dm-verity: remove unused variable Scott Murray
` (10 subsequent siblings)
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
From: Shreejit C <shreejit.c@emerson.com>
Several meta-tpm recipes were missing HOMEPAGE and/or SUMMARY entries,
tripping the missing-metadata recipe QA check that is enabled for
core-layer recipes. The warnings surface whenever do_recipe_qa actually
runs (a fresh build with no sstate hit), e.g.:
WARNING: tpm2-tss-4.1.3-r0 do_recipe_qa: QA Issue: Recipe tpm2-tss in
.../tpm2-tss_4.1.3.bb does not contain a HOMEPAGE. Please add an entry.
[missing-metadata]
Add the upstream project URL as HOMEPAGE, and a SUMMARY where absent:
- tpm2-tss: add HOMEPAGE
- tpm2-tools: add HOMEPAGE
- tpm2-openssl: add HOMEPAGE
- tpm2-abrmd: add HOMEPAGE
- tpm2-pkcs11: add HOMEPAGE
- tpm2-tss-engine: add HOMEPAGE
- python3-tpm2-pytss: add SUMMARY
- packagegroup-security-tpm2: add SUMMARY
Signed-off-by: Shreejit C <shreejit.c@emerson.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb | 1 +
meta-tpm/recipes-tpm2/tpm2-abrmd/tpm2-abrmd_3.0.0.bb | 1 +
meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb | 1 +
meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb | 1 +
meta-tpm/recipes-tpm2/tpm2-pytss/python3-tpm2-pytss_2.3.0.bb | 1 +
meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb | 1 +
meta-tpm/recipes-tpm2/tpm2-tss-engine/tpm2-tss-engine_1.2.0.bb | 1 +
meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb | 1 +
8 files changed, 8 insertions(+)
diff --git a/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb b/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb
index b986097..b04851f 100644
--- a/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb
+++ b/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm2.bb
@@ -1,3 +1,4 @@
+SUMMARY = "TPM2 packagegroup for Security"
DESCRIPTION = "TPM2 packagegroup for Security"
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302 \
diff --git a/meta-tpm/recipes-tpm2/tpm2-abrmd/tpm2-abrmd_3.0.0.bb b/meta-tpm/recipes-tpm2/tpm2-abrmd/tpm2-abrmd_3.0.0.bb
index 1b8eff1..b829a68 100644
--- a/meta-tpm/recipes-tpm2/tpm2-abrmd/tpm2-abrmd_3.0.0.bb
+++ b/meta-tpm/recipes-tpm2/tpm2-abrmd/tpm2-abrmd_3.0.0.bb
@@ -5,6 +5,7 @@ is implemented using Glib and the GObject system. In this documentation and \
in the code we use `tpm2-abrmd` and `tabrmd` interchangeably. \
"
SECTION = "security/tpm"
+HOMEPAGE = "https://github.com/tpm2-software/tpm2-abrmd"
LICENSE = "BSD-2-Clause"
LIC_FILES_CHKSUM = "file://${S}/LICENSE;md5=500b2e742befc3da00684d8a1d5fd9da"
diff --git a/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb b/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb
index ed756b1..e97a208 100644
--- a/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb
+++ b/meta-tpm/recipes-tpm2/tpm2-openssl/tpm2-openssl_1.3.0.bb
@@ -1,4 +1,5 @@
SUMMARY = "Provider for integration of TPM 2.0 to OpenSSL 3.0"
+HOMEPAGE = "https://github.com/tpm2-software/tpm2-openssl"
LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE;md5=3f4b4cb00f4d0d6807a0dc79759a57ac"
diff --git a/meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb b/meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb
index 3d04e5b..1a671bc 100644
--- a/meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb
+++ b/meta-tpm/recipes-tpm2/tpm2-pkcs11/tpm2-pkcs11_1.9.2.bb
@@ -1,6 +1,7 @@
SUMMARY = "A PKCS#11 interface for TPM2 hardware"
DESCRIPTION = "PKCS #11 is a Public-Key Cryptography Standard that defines a standard method to access cryptographic services from tokens/ devices such as hardware security modules (HSM), smart cards, etc. In this project we intend to use a TPM2 device as the cryptographic token."
SECTION = "security/tpm"
+HOMEPAGE = "https://github.com/tpm2-software/tpm2-pkcs11"
LICENSE = "BSD-2-Clause"
LIC_FILES_CHKSUM = "file://LICENSE;md5=0fc19f620a102768d6dbd1e7166e78ab"
diff --git a/meta-tpm/recipes-tpm2/tpm2-pytss/python3-tpm2-pytss_2.3.0.bb b/meta-tpm/recipes-tpm2/tpm2-pytss/python3-tpm2-pytss_2.3.0.bb
index 63ed8cf..44c6ed2 100644
--- a/meta-tpm/recipes-tpm2/tpm2-pytss/python3-tpm2-pytss_2.3.0.bb
+++ b/meta-tpm/recipes-tpm2/tpm2-pytss/python3-tpm2-pytss_2.3.0.bb
@@ -1,3 +1,4 @@
+SUMMARY = "Python bindings for the TPM2 Software Stack (TSS2)"
DESCRIPTION = "TPM2 TSS Python bindings for Enhanced System API (ESYS), Feature API (FAPI), Marshaling (MU), TCTI Loader (TCTILdr), TCTIs, policy, and RC Decoding (rcdecode) libraries"
HOMEPAGE = "https://github.com/tpm2-software/tpm2-pytss"
LICENSE = "BSD-2-Clause"
diff --git a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb
index e1a0c5d..04ada78 100644
--- a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb
+++ b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb
@@ -1,5 +1,6 @@
SUMMARY = "Tools for TPM2."
DESCRIPTION = "tpm2-tools"
+HOMEPAGE = "https://github.com/tpm2-software/tpm2-tools"
LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://docs/LICENSE;md5=a846608d090aa64494c45fc147cc12e3"
SECTION = "tpm"
diff --git a/meta-tpm/recipes-tpm2/tpm2-tss-engine/tpm2-tss-engine_1.2.0.bb b/meta-tpm/recipes-tpm2/tpm2-tss-engine/tpm2-tss-engine_1.2.0.bb
index 6bc44ef..e620995 100644
--- a/meta-tpm/recipes-tpm2/tpm2-tss-engine/tpm2-tss-engine_1.2.0.bb
+++ b/meta-tpm/recipes-tpm2/tpm2-tss-engine/tpm2-tss-engine_1.2.0.bb
@@ -1,5 +1,6 @@
SUMMARY = "The tpm2-tss-engine project implements a cryptographic engine for OpenSSL."
DESCRIPTION = "The tpm2-tss-engine project implements a cryptographic engine for OpenSSL for Trusted Platform Module (TPM 2.0) using the tpm2-tss software stack that follows the Trusted Computing Groups (TCG) TPM Software Stack (TSS 2.0). It uses the Enhanced System API (ESAPI) interface of the TSS 2.0 for downwards communication. It supports RSA decryption and signatures as well as ECDSA signatures."
+HOMEPAGE = "https://github.com/tpm2-software/tpm2-tss-engine"
LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE;md5=7b3ab643b9ce041de515d1ed092a36d4"
diff --git a/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb b/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb
index 67a51e4..f8e87a5 100644
--- a/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb
+++ b/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb
@@ -1,5 +1,6 @@
SUMMARY = "Software stack for TPM2."
DESCRIPTION = "OSS implementation of the TCG TPM2 Software Stack (TSS2) "
+HOMEPAGE = "https://github.com/tpm2-software/tpm2-tss"
LICENSE = "BSD-2-Clause"
LIC_FILES_CHKSUM = "file://LICENSE;md5=500b2e742befc3da00684d8a1d5fd9da"
SECTION = "tpm"
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 06/15] dm-verity: remove unused variable
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
` (4 preceding siblings ...)
2026-08-26 20:57 ` [meta-security][PATCH 05/15] meta-tpm: Add missing recipe metadata (HOMEPAGE/SUMMARY) Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 07/15] wic: document the meta-intel dependency in the dm-verity hash example Scott Murray
` (9 subsequent siblings)
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
From: Gaël PORTAY <gael.portay+rtone@gmail.com>
This removes unused variable that was dropped by commit d80cd2ba6a
("dm-verity: Set the IMAGE_FSTYPES correctly when dm-verity is
enabled").
Signed-off-by: Gaël PORTAY <gael.portay+rtone@gmail.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
classes/dm-verity-img.bbclass | 1 -
1 file changed, 1 deletion(-)
diff --git a/classes/dm-verity-img.bbclass b/classes/dm-verity-img.bbclass
index 48557e9..619cda8 100644
--- a/classes/dm-verity-img.bbclass
+++ b/classes/dm-verity-img.bbclass
@@ -202,7 +202,6 @@ IMAGE_FSTYPES += "${@get_verity_fstypes(d)}"
python __anonymous() {
verity_image = d.getVar('DM_VERITY_IMAGE')
verity_type = d.getVar('DM_VERITY_IMAGE_TYPE')
- verity_hash = d.getVar('DM_VERITY_SEPARATE_HASH')
image_fstypes = d.getVar('IMAGE_FSTYPES')
pn = d.getVar('PN')
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 07/15] wic: document the meta-intel dependency in the dm-verity hash example
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
` (5 preceding siblings ...)
2026-08-26 20:57 ` [meta-security][PATCH 06/15] dm-verity: remove unused variable Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 08/15] docs: update path of wic files Scott Murray
` (8 subsequent siblings)
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
From: Gaël PORTAY <gael.portay+rtone@gmail.com>
The dependency might not be obvious to everyone, so leave a hint as in
commit 2fbeebc18c ("dm-verity: document the meta-intel dependency in the
systemd example").
Signed-off-by: Gaël PORTAY <gael.portay+rtone@gmail.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
files/wic/systemd-bootdisk-dmverity-hash.wks.in | 1 +
1 file changed, 1 insertion(+)
diff --git a/files/wic/systemd-bootdisk-dmverity-hash.wks.in b/files/wic/systemd-bootdisk-dmverity-hash.wks.in
index e400593..67abaa6 100644
--- a/files/wic/systemd-bootdisk-dmverity-hash.wks.in
+++ b/files/wic/systemd-bootdisk-dmverity-hash.wks.in
@@ -6,6 +6,7 @@
# Based on OE-core's systemd-bootdisk.wks and meta-security's beaglebone-yocto-verity.wks.in file
#
# This .wks only works with the dm-verity-img class and separate hash data. (DM_VERITY_SEPARATE_HASH)
+# Also note that the use of microcode.cpio introduces a meta-intel layer dependency.
part /boot --source bootimg-efi --sourceparams="loader=systemd-boot,initrd=microcode.cpio" --ondisk sda --label msdos --active --align 1024 --use-uuid
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 08/15] docs: update path of wic files
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
` (6 preceding siblings ...)
2026-08-26 20:57 ` [meta-security][PATCH 07/15] wic: document the meta-intel dependency in the dm-verity hash example Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 09/15] tpm2-tools: set status for CVE-2017-7524 and CVE-2024-29039 Scott Murray
` (7 subsequent siblings)
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
From: Gaël PORTAY <gael.portay+rtone@gmail.com>
The wic files were moved from wic/ to files/wic since commit 596b966a0d
("wic: wic need to be moved to files/wic within the layer to be
found/used").
This updates the path of wic files in the documentation.
Signed-off-by: Gaël PORTAY <gael.portay+rtone@gmail.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
docs/dm-verity-systemd-x86-64.txt | 6 +++---
docs/dm-verity.txt | 2 +-
2 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/docs/dm-verity-systemd-x86-64.txt b/docs/dm-verity-systemd-x86-64.txt
index a47b02c..5d759a5 100644
--- a/docs/dm-verity-systemd-x86-64.txt
+++ b/docs/dm-verity-systemd-x86-64.txt
@@ -14,8 +14,8 @@ writing (kernel v6.1) the resulting qemux86-64 build can also be booted
successfully on physical hardware, but if you don't intend to use qemu,
you might instead want to choose "genericx86-64"
-This will make use of wic/systemd-bootdisk-dmverity.wks.in -- note that it
-contains a dependency on the meta-intel layer for microcode, so you'll need
+This will make use of files/wic/systemd-bootdisk-dmverity.wks.in -- note that
+it contains a dependency on the meta-intel layer for microcode, so you'll need
to fetch and add that layer in addition to the meta-security related layers.
In addition to the basic dm-verity settings, choose systemd in local.conf:
@@ -56,7 +56,7 @@ The following build artifacts were used to create the image(s):
NATIVE_SYSROOT: /home/paul/poky/build-qemu-x86_64/tmp/work/core2-64-poky-linux/wic-tools/1.0-r0/recipe-sysroot-native
INFO: The image(s) were created using OE kickstart file:
- /home/paul/poky/meta-security/wic/systemd-bootdisk-dmverity.wks.in
+ /home/paul/poky/meta-security/files/wic/systemd-bootdisk-dmverity.wks.in
build-qemu-x86_64$
------------------------------
diff --git a/docs/dm-verity.txt b/docs/dm-verity.txt
index a538fa2..dca3df6 100644
--- a/docs/dm-verity.txt
+++ b/docs/dm-verity.txt
@@ -115,7 +115,7 @@ The following build artifacts were used to create the image(s):
NATIVE_SYSROOT: /home/paul/poky/build-bbb-verity/tmp/work/cortexa8hf-neon-poky-linux-gnueabi/wic-tools/1.0-r0/recipe-sysroot-native
INFO: The image(s) were created using OE kickstart file:
- /home/paul/poky/meta-security/wic/beaglebone-yocto-verity.wks.in
+ /home/paul/poky/meta-security/files/wic/beaglebone-yocto-verity.wks.in
----------------------
The "direct" image contains the partition table, bootloader, and dm-verity
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 09/15] tpm2-tools: set status for CVE-2017-7524 and CVE-2024-29039
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
` (7 preceding siblings ...)
2026-08-26 20:57 ` [meta-security][PATCH 08/15] docs: update path of wic files Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 10/15] tpm2-tss: set status for CVE-2024-29040 Scott Murray
` (6 subsequent siblings)
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
From: Peter Marko <peter.marko@siemens.com>
CVE-2017-7524 is a historical CVE and new cve-check does not undestand
fixed version data. Debian report [1] shows fix commit which can be
linked to release information.
CVE-2024-29039 is per Debian report [2] fixed in 5.7.
[1] https://security-tracker.debian.org/tracker/CVE-2017-7524
[2] https://security-tracker.debian.org/tracker/CVE-2024-29039
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb | 3 +++
1 file changed, 3 insertions(+)
diff --git a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb
index 04ada78..5c968dd 100644
--- a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb
+++ b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb
@@ -19,3 +19,6 @@ PACKAGECONGIG ??= "efivar"
PACKAGECONFIG[efivar] = "--with-efivar,--without-efivar,efivar"
BBCLASSEXTEND = "native nativesdk"
+
+CVE_STATUS[CVE-2017-7524] = "fixed-version: Fixed since version 3.0.0"
+CVE_STATUS[CVE-2024-29039] = "fixed-version: Fixed since version 5.7"
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 10/15] tpm2-tss: set status for CVE-2024-29040
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
` (8 preceding siblings ...)
2026-08-26 20:57 ` [meta-security][PATCH 09/15] tpm2-tools: set status for CVE-2017-7524 and CVE-2024-29039 Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 11/15] tpm2-tools: fix PACKAGECONFIG typo Scott Murray
` (5 subsequent siblings)
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
From: Peter Marko <peter.marko@siemens.com>
CVE-2024-29040 is per Debian report [2] fixed in 4.1.0.
[1] https://security-tracker.debian.org/tracker/CVE-2024-29040
Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb | 2 ++
1 file changed, 2 insertions(+)
diff --git a/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb b/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb
index f8e87a5..30e984e 100644
--- a/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb
+++ b/meta-tpm/recipes-tpm2/tpm2-tss/tpm2-tss_4.1.3.bb
@@ -94,3 +94,5 @@ FILES:${PN} = "\
${sysconfdir}/sysusers.d"
BBCLASSEXTEND = "native nativesdk"
+
+CVE_STATUS[CVE-2024-29040] = "fixed-version: Fixed since version 4.1.0"
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 11/15] tpm2-tools: fix PACKAGECONFIG typo
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
` (9 preceding siblings ...)
2026-08-26 20:57 ` [meta-security][PATCH 10/15] tpm2-tss: set status for CVE-2024-29040 Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 12/15] fix LICENSE variable syntax to suppress QA warning Scott Murray
` (4 subsequent siblings)
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
From: Krupal Ka Patel <krkapate@cisco.com>
Correct the misspelled PACKAGECONFIG variable so efivar is enabled by
default as intended by commit cdb4e444acbb2b9df467d716241a206c9ea6d3b0.
Signed-off-by: Krupal Ka Patel <krkapate@cisco.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb
index 5c968dd..7c5d156 100644
--- a/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb
+++ b/meta-tpm/recipes-tpm2/tpm2-tools/tpm2-tools_5.7.bb
@@ -15,7 +15,7 @@ UPSTREAM_CHECK_URI = "https://github.com/tpm2-software/${BPN}/releases"
inherit autotools pkgconfig bash-completion
-PACKAGECONGIG ??= "efivar"
+PACKAGECONFIG ??= "efivar"
PACKAGECONFIG[efivar] = "--with-efivar,--without-efivar,efivar"
BBCLASSEXTEND = "native nativesdk"
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 12/15] fix LICENSE variable syntax to suppress QA warning
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
` (10 preceding siblings ...)
2026-08-26 20:57 ` [meta-security][PATCH 11/15] tpm2-tools: fix PACKAGECONFIG typo Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 13/15] meta-integrity: Fix ima-evm-utils LICENSE Scott Murray
` (3 subsequent siblings)
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
From: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
recipes-ids/crowdsec/crowdsec-licenses.inc | 2 +-
recipes-ids/crowdsec/crowdsec_1.7.7.bb | 2 +-
recipes-mac/AppArmor/apparmor_4.0.3.bb | 2 +-
recipes-perl/perl/lib-perl_0.63.bb | 2 +-
recipes-perl/perl/libwhisker2-perl_2.5.bb | 2 +-
recipes-scanners/clamav/clamav_1.4.4.bb | 4 ++--
recipes-security/libgssglue/libgssglue_0.9.bb | 2 +-
7 files changed, 8 insertions(+), 8 deletions(-)
diff --git a/recipes-ids/crowdsec/crowdsec-licenses.inc b/recipes-ids/crowdsec/crowdsec-licenses.inc
index cb45b10..92f5dc6 100644
--- a/recipes-ids/crowdsec/crowdsec-licenses.inc
+++ b/recipes-ids/crowdsec/crowdsec-licenses.inc
@@ -4,7 +4,7 @@
# Do not modify it by hand, as the contents will be replaced when
# running the update-modules task.
-LICENSE += "& Apache-2.0 & BSD-2-Clause & BSD-3-Clause & ISC & MIT & MPL-2.0 & WTFPL"
+LICENSE += "AND Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND ISC AND MIT AND MPL-2.0 AND WTFPL"
LIC_FILES_CHKSUM += "\
file://pkg/mod/ariga.io/atlas@v0.31.1-0.20250212144724-069be8033e83/LICENSE;md5=175792518e4ac015ab6696d16c4f607e;spdx=Apache-2.0 \
diff --git a/recipes-ids/crowdsec/crowdsec_1.7.7.bb b/recipes-ids/crowdsec/crowdsec_1.7.7.bb
index 0697022..356c227 100644
--- a/recipes-ids/crowdsec/crowdsec_1.7.7.bb
+++ b/recipes-ids/crowdsec/crowdsec_1.7.7.bb
@@ -1,7 +1,7 @@
SUMMARY = "CrowdSec is a free, modern & collaborative behavior detection engine, coupled with a global IP reputation network."
DESCRIPTION = "Open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI."
HOMEPAGE = "https://www.crowdsec.net"
-LICENSE = "MIT & CC0-1.0"
+LICENSE = "MIT AND CC0-1.0"
LIC_FILES_CHKSUM = "file://src/${GO_IMPORT}/LICENSE;md5=1e58fe4126ce0b50677f3aa6ba8e13c2 \
file://src/${GO_IMPORT}/build/windows/Chocolatey/crowdsec/tools/LICENSE.txt;md5=4d249f04094c9fb4d2b6fd2b1127e219 \
file://src/${GO_IMPORT}/test/lib/bats-assert/LICENSE;md5=7bae63a234e80ee7c6427dce9fdba6cc \
diff --git a/recipes-mac/AppArmor/apparmor_4.0.3.bb b/recipes-mac/AppArmor/apparmor_4.0.3.bb
index 9983157..76025bd 100644
--- a/recipes-mac/AppArmor/apparmor_4.0.3.bb
+++ b/recipes-mac/AppArmor/apparmor_4.0.3.bb
@@ -8,7 +8,7 @@ DESCRIPTION = "user-space parser utility for AppArmor \
HOMEPAGE = "http://apparmor.net/"
SECTION = "admin"
-LICENSE = "GPL-2.0-only & GPL-2.0-or-later & BSD-3-Clause & LGPL-2.1-or-later"
+LICENSE = "GPL-2.0-only AND GPL-2.0-or-later AND BSD-3-Clause AND LGPL-2.1-or-later"
LIC_FILES_CHKSUM = "file://${S}/LICENSE;md5=fd57a4b0bc782d7b80fd431f10bbf9d0"
DEPENDS = "bison-native apr autoconf-archive-native gettext-native coreutils-native swig-native"
diff --git a/recipes-perl/perl/lib-perl_0.63.bb b/recipes-perl/perl/lib-perl_0.63.bb
index f0d6832..c0fb43a 100644
--- a/recipes-perl/perl/lib-perl_0.63.bb
+++ b/recipes-perl/perl/lib-perl_0.63.bb
@@ -5,7 +5,7 @@ will find modules which are not located in the default search path."
SECTION = "libs"
HOMEPAGE = "https://metacpan.org/dist/lib"
-LICENSE = "Artistic-1.0 | GPL-1.0-or-later"
+LICENSE = "Artistic-1.0 OR GPL-1.0-or-later"
PR = "r0"
LIC_FILES_CHKSUM = "file://README;beginline=26;endline=30;md5=94b119f1a7b8d611efc89b5d562a1a50"
diff --git a/recipes-perl/perl/libwhisker2-perl_2.5.bb b/recipes-perl/perl/libwhisker2-perl_2.5.bb
index e16e5f2..94b2384 100644
--- a/recipes-perl/perl/libwhisker2-perl_2.5.bb
+++ b/recipes-perl/perl/libwhisker2-perl_2.5.bb
@@ -1,7 +1,7 @@
DESCRIPTION = "Libwhisker is a Perl module geared specificly for HTTP testing."
SECTION = "libs"
-LICENSE = "Artistic-1.0 | GPL-1.0-or-later"
+LICENSE = "Artistic-1.0 OR GPL-1.0-or-later"
LIC_FILES_CHKSUM = "file://LICENSE;md5=254b8e29606fce6d1c1a4c9e32354573"
diff --git a/recipes-scanners/clamav/clamav_1.4.4.bb b/recipes-scanners/clamav/clamav_1.4.4.bb
index e9c2aca..b3f14cd 100644
--- a/recipes-scanners/clamav/clamav_1.4.4.bb
+++ b/recipes-scanners/clamav/clamav_1.4.4.bb
@@ -1,8 +1,8 @@
SUMMARY = "ClamAV anti-virus utilities and scanner tools"
-DESCRIPTION = "ClamAV is an open source antivirus engine for detecting trojans, viruses, malware & other malicious threats."
+DESCRIPTION = "ClamAV is an open source antivirus engine for detecting trojans, viruses, malware AND other malicious threats."
HOMEPAGE = "http://www.clamav.net/index.html"
SECTION = "security"
-LICENSE = "GPL-2.0-only & LGPL-2.1-only & BSD-2-Clause & Zlib & Apache-2.0-with-LLVM-exception"
+LICENSE = "GPL-2.0-only AND LGPL-2.1-only AND BSD-2-Clause AND Zlib AND Apache-2.0-with-LLVM-exception"
LIC_FILES_CHKSUM = "file://COPYING.txt;md5=2c0b5770a62017a3121c69bb9f680b0c \
file://COPYING/COPYING.LGPL;md5=2d5025d4aa3495befef8f17206a5b0a1 \
file://COPYING/COPYING.bzip2;md5=ae8d555c34b656ff864ea9437a10d3a0 \
diff --git a/recipes-security/libgssglue/libgssglue_0.9.bb b/recipes-security/libgssglue/libgssglue_0.9.bb
index 0952ed1..9b33ce9 100644
--- a/recipes-security/libgssglue/libgssglue_0.9.bb
+++ b/recipes-security/libgssglue/libgssglue_0.9.bb
@@ -8,7 +8,7 @@ depending on the mechanism. \
HOMEPAGE = "https://gitlab.com/gsasl/libgssglue"
SECTION = "libs"
-LICENSE = "BSD-3-Clause | HPND"
+LICENSE = "BSD-3-Clause OR HPND"
#Copyright (c) 1996, by Sun Microsystems, Inc. HPND
#Copyright (c) 2007 The Regents of the University of Michigan. BSD-3-Clause
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 13/15] meta-integrity: Fix ima-evm-utils LICENSE
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
` (11 preceding siblings ...)
2026-08-26 20:57 ` [meta-security][PATCH 12/15] fix LICENSE variable syntax to suppress QA warning Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 14/15] meta-tpm: Fix SUMMARY/HOMEPAGE in affected recipes Scott Murray
` (2 subsequent siblings)
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
Update for upstream switch to SPDX syntax for LICENSE to silence QA
warning.
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
.../recipes-security/ima-evm-utils/ima-evm-utils_1.5.bb | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/meta-integrity/recipes-security/ima-evm-utils/ima-evm-utils_1.5.bb b/meta-integrity/recipes-security/ima-evm-utils/ima-evm-utils_1.5.bb
index ac0a383..c382cf4 100644
--- a/meta-integrity/recipes-security/ima-evm-utils/ima-evm-utils_1.5.bb
+++ b/meta-integrity/recipes-security/ima-evm-utils/ima-evm-utils_1.5.bb
@@ -1,5 +1,5 @@
DESCRIPTION = "IMA/EVM control utility"
-LICENSE = "GPL-2.0-with-OpenSSL-exception"
+LICENSE = "LicenseRef-GPL-2.0-with-OpenSSL-exception"
LIC_FILES_CHKSUM = "file://COPYING;md5=b234ee4d69f5fce4486a80fdaf4a4263"
DEPENDS += "openssl attr keyutils"
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 14/15] meta-tpm: Fix SUMMARY/HOMEPAGE in affected recipes
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
` (12 preceding siblings ...)
2026-08-26 20:57 ` [meta-security][PATCH 13/15] meta-integrity: Fix ima-evm-utils LICENSE Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 15/15] aide: Fix unstable install task hash Scott Murray
2026-08-27 14:52 ` [yocto-patches] [meta-security][PATCH 00/15] Assorted updates 08/26 Marta Rybczynska
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
To quiet the missing metadata warnings, switch DESCRIPTION to SUMMARY
in the following recipes:
- security-tpm-image
- security-tpm2-image
- packagegroup-security-tpm
- openssl-tpm-engine
and add HOMEPAGE to these recipes:
- libtpms
- swtpm
- tpm-tools
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
meta-tpm/recipes-core/images/security-tpm-image.bb | 2 +-
meta-tpm/recipes-core/images/security-tpm2-image.bb | 2 +-
meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm.bb | 2 +-
meta-tpm/recipes-tpm/libtpm/libtpms_0.10.0.bb | 1 +
meta-tpm/recipes-tpm/swtpm/swtpm_0.10.0.bb | 1 +
.../recipes-tpm1/openssl-tpm-engine/openssl-tpm-engine_0.5.0.bb | 2 +-
meta-tpm/recipes-tpm1/tpm-tools/tpm-tools_1.3.9.2.bb | 1 +
7 files changed, 7 insertions(+), 4 deletions(-)
diff --git a/meta-tpm/recipes-core/images/security-tpm-image.bb b/meta-tpm/recipes-core/images/security-tpm-image.bb
index dbdd309..c6d25a2 100644
--- a/meta-tpm/recipes-core/images/security-tpm-image.bb
+++ b/meta-tpm/recipes-core/images/security-tpm-image.bb
@@ -1,4 +1,4 @@
-DESCRIPTION = "A small image for building a tpm image for testing"
+SUMMARY = "A small image for building a tpm image for testing"
IMAGE_FEATURES += "ssh-server-openssh"
diff --git a/meta-tpm/recipes-core/images/security-tpm2-image.bb b/meta-tpm/recipes-core/images/security-tpm2-image.bb
index 941a661..117d34e 100644
--- a/meta-tpm/recipes-core/images/security-tpm2-image.bb
+++ b/meta-tpm/recipes-core/images/security-tpm2-image.bb
@@ -1,4 +1,4 @@
-DESCRIPTION = "A small image for building a tpm2 image for testing"
+SUMMARY = "A small image for building a tpm2 image for testing"
IMAGE_FEATURES += "ssh-server-openssh"
diff --git a/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm.bb b/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm.bb
index a1d4d44..f92bf01 100644
--- a/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm.bb
+++ b/meta-tpm/recipes-core/packagegroup/packagegroup-security-tpm.bb
@@ -1,4 +1,4 @@
-DESCRIPTION = "Security packagegroup for Poky"
+SUMMARY = "Security packagegroup for Poky"
LICENSE = "MIT"
LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302 \
file://${COREBASE}/meta/COPYING.MIT;md5=3da9cfbcb788c80a0384361b4de20420"
diff --git a/meta-tpm/recipes-tpm/libtpm/libtpms_0.10.0.bb b/meta-tpm/recipes-tpm/libtpm/libtpms_0.10.0.bb
index 7f00216..2b6f670 100644
--- a/meta-tpm/recipes-tpm/libtpm/libtpms_0.10.0.bb
+++ b/meta-tpm/recipes-tpm/libtpm/libtpms_0.10.0.bb
@@ -1,4 +1,5 @@
SUMMARY = "LIBPM - Software TPM Library"
+HOMEPAGE = "https://github.com/stefanberger/libtpms"
LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE;md5=e73f0786a936da3814896df06ad225a9"
diff --git a/meta-tpm/recipes-tpm/swtpm/swtpm_0.10.0.bb b/meta-tpm/recipes-tpm/swtpm/swtpm_0.10.0.bb
index d5470f4..8472f02 100644
--- a/meta-tpm/recipes-tpm/swtpm/swtpm_0.10.0.bb
+++ b/meta-tpm/recipes-tpm/swtpm/swtpm_0.10.0.bb
@@ -1,4 +1,5 @@
SUMMARY = "SWTPM - Software TPM Emulator"
+HOMEPAGE = "https://github.com/stefanberger/swtpm"
LICENSE = "BSD-3-Clause"
LIC_FILES_CHKSUM = "file://LICENSE;md5=fe8092c832b71ef20dfe4c6d3decb3a8"
SECTION = "apps"
diff --git a/meta-tpm/recipes-tpm1/openssl-tpm-engine/openssl-tpm-engine_0.5.0.bb b/meta-tpm/recipes-tpm1/openssl-tpm-engine/openssl-tpm-engine_0.5.0.bb
index b792151..13f0d0d 100644
--- a/meta-tpm/recipes-tpm1/openssl-tpm-engine/openssl-tpm-engine_0.5.0.bb
+++ b/meta-tpm/recipes-tpm1/openssl-tpm-engine/openssl-tpm-engine_0.5.0.bb
@@ -1,4 +1,4 @@
-DESCRIPTION = "OpenSSL secure engine based on TPM hardware"
+SUMMARY = "OpenSSL secure engine based on TPM hardware"
HOMEPAGE = "https://github.com/mgerstner/openssl_tpm_engine"
SECTION = "security/tpm"
diff --git a/meta-tpm/recipes-tpm1/tpm-tools/tpm-tools_1.3.9.2.bb b/meta-tpm/recipes-tpm1/tpm-tools/tpm-tools_1.3.9.2.bb
index 6d911c9..97a7aef 100644
--- a/meta-tpm/recipes-tpm1/tpm-tools/tpm-tools_1.3.9.2.bb
+++ b/meta-tpm/recipes-tpm1/tpm-tools/tpm-tools_1.3.9.2.bb
@@ -1,4 +1,5 @@
SUMMARY = "The tpm-tools package contains commands to allow the platform administrator the ability to manage and diagnose the platform's TPM."
+HOMEPAGE = "https://sourceforge.net/p/trousers/tpm-tools"
DESCRIPTION = " \
The tpm-tools package contains commands to allow the platform administrator \
the ability to manage and diagnose the platform's TPM. Additionally, the \
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* [meta-security][PATCH 15/15] aide: Fix unstable install task hash
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
` (13 preceding siblings ...)
2026-08-26 20:57 ` [meta-security][PATCH 14/15] meta-tpm: Fix SUMMARY/HOMEPAGE in affected recipes Scott Murray
@ 2026-08-26 20:57 ` Scott Murray
2026-08-27 14:52 ` [yocto-patches] [meta-security][PATCH 00/15] Assorted updates 08/26 Marta Rybczynska
15 siblings, 0 replies; 17+ messages in thread
From: Scott Murray @ 2026-08-26 20:57 UTC (permalink / raw)
To: yocto-patches
From: Esa Jaaskela <esa.jaaskela@suomi24.fi>
The installation task hash for the aide is marked as nostamp. This is
done because the native task installs files outside the sysroot, to the
Aide staging directory. Those files are not captured by
do_populate_sysroot, so they are missing whenever the task is skipped or
restored from sstate.
Install the required native contents to the sysroot, and then customise
and deploy the configuration file in the aide_init_db rootfs postprocess
function that utilizes the files. The configuration file needs to be
reset every time the function is run to avoid using stale
configurations.
Staging the native files through the sysroot makes the nostamp
unnecessary, so remove it along with the unstable task hash it caused.
Signed-off-by: Esa Jaaskela <esa.jaaskela@suomi24.fi>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
---
classes/aide-db-init.bbclass | 11 +++++++++--
recipes-ids/aide/aide_0.19.3.bb | 13 ++++---------
2 files changed, 13 insertions(+), 11 deletions(-)
diff --git a/classes/aide-db-init.bbclass b/classes/aide-db-init.bbclass
index 800006f..3fe2c27 100644
--- a/classes/aide-db-init.bbclass
+++ b/classes/aide-db-init.bbclass
@@ -31,6 +31,13 @@
inherit aide-base
aide_init_db() {
+ install -d ${STAGING_AIDE_DIR}/lib/logs
+ rm -f ${STAGING_AIDE_DIR}/aide.conf ${STAGING_AIDE_DIR}/lib/aide.db ${STAGING_AIDE_DIR}/lib/aide.db.gz ${STAGING_AIDE_DIR}/lib/logs/aide.log
+ install ${STAGING_DATADIR_NATIVE}/aide/aide.conf ${STAGING_AIDE_DIR}/
+
+ sed -i -s "s:\@\@define DBDIR.*:\@\@define DBDIR ${STAGING_AIDE_DIR}/lib:" ${STAGING_AIDE_DIR}/aide.conf
+ sed -i -e "s:\@\@define LOGDIR.*:\@\@define LOGDIR ${STAGING_AIDE_DIR}/lib/logs:" ${STAGING_AIDE_DIR}/aide.conf
+
for dir in ${AIDE_INCLUDE_DIRS}; do
echo "${IMAGE_ROOTFS}${dir} NORMAL" >> ${STAGING_AIDE_DIR}/aide.conf
done
@@ -39,7 +46,7 @@ aide_init_db() {
done
- ${STAGING_AIDE_DIR}/bin/aide -c ${STAGING_AIDE_DIR}/aide.conf --init
+ ${STAGING_BINDIR_NATIVE}/aide -c ${STAGING_AIDE_DIR}/aide.conf --init
gunzip ${STAGING_AIDE_DIR}/lib/aide.db.gz
# strip out native path
sed -i -e 's:${IMAGE_ROOTFS}::' ${STAGING_AIDE_DIR}/lib/aide.db
@@ -47,6 +54,6 @@ aide_init_db() {
cp -f ${STAGING_AIDE_DIR}/lib/aide.db.gz ${IMAGE_ROOTFS}${libdir}/aide
}
-EXTRA_IMAGEDEPENDS:append = " aide-native"
+do_rootfs[depends] += "aide-native:do_populate_sysroot"
ROOTFS_POSTPROCESS_COMMAND:append = " aide_init_db;"
diff --git a/recipes-ids/aide/aide_0.19.3.bb b/recipes-ids/aide/aide_0.19.3.bb
index 8d4efbb..c352583 100644
--- a/recipes-ids/aide/aide_0.19.3.bb
+++ b/recipes-ids/aide/aide_0.19.3.bb
@@ -32,8 +32,6 @@ PACKAGECONFIG[e2fsattrs] = "--with-e2fsattrs, --without-e2fsattrs, e2fsprogs, e2
PACKAGECONFIG[capabilities] = "--with-capabilities, --without-capabilities, libcap, libcap"
PACKAGECONFIG[posix-acl] = "--with-posix-acl, --without-posix-acl, acl, acl"
-do_install[nostamp] = "1"
-
do_install:append () {
install -d ${D}${libdir}/${PN}/logs
install -d ${D}${sysconfdir}
@@ -48,14 +46,11 @@ do_install:append () {
}
do_install:class-native () {
- install -d ${STAGING_AIDE_DIR}/bin
- install -d ${STAGING_AIDE_DIR}/lib/logs
-
- install ${B}/aide ${STAGING_AIDE_DIR}/bin
- install ${UNPACKDIR}/aide.conf ${STAGING_AIDE_DIR}/
+ install -d ${D}${bindir}
+ install -d ${D}${datadir}/${BPN}
- sed -i -s "s:\@\@define DBDIR.*:\@\@define DBDIR ${STAGING_AIDE_DIR}/lib:" ${STAGING_AIDE_DIR}/aide.conf
- sed -i -e "s:\@\@define LOGDIR.*:\@\@define LOGDIR ${STAGING_AIDE_DIR}/lib/logs:" ${STAGING_AIDE_DIR}/aide.conf
+ install ${B}/aide ${D}${bindir}
+ install ${UNPACKDIR}/aide.conf ${D}${datadir}/${BPN}/
}
CONF_FILE = "${sysconfdir}/aide.conf"
--
2.55.0
^ permalink raw reply related [flat|nested] 17+ messages in thread
* Re: [yocto-patches] [meta-security][PATCH 00/15] Assorted updates 08/26
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
` (14 preceding siblings ...)
2026-08-26 20:57 ` [meta-security][PATCH 15/15] aide: Fix unstable install task hash Scott Murray
@ 2026-08-27 14:52 ` Marta Rybczynska
15 siblings, 0 replies; 17+ messages in thread
From: Marta Rybczynska @ 2026-08-27 14:52 UTC (permalink / raw)
To: yocto-patches
[-- Attachment #1: Type: text/plain, Size: 660 bytes --]
On Wed, 26 Aug 2026, 22:58 Scott Murray via lists.yoctoproject.org,
<scott.murray=konsulko.com@lists.yoctoproject.org> wrote:
> My apologies for being slow in getting this out, this patch series rolls
> up the contributed patches from the past few months along with some
> other fixes from myself. These changes are queued on the master-next
> branch if you would like to check them out to test yourself. I intend
> to merge these to master branch Friday evening (EDT, August 28) unless
> there are objections. I should have the relevant backports to wrynose
> and scarthgap out for early next week.
>
> Scott
>
Looks good to me.
Kind regards
Marta
>
>
[-- Attachment #2: Type: text/html, Size: 1355 bytes --]
^ permalink raw reply [flat|nested] 17+ messages in thread
end of thread, other threads:[~2026-08-27 14:53 UTC | newest]
Thread overview: 17+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-26 20:57 [meta-security][PATCH 00/15] Assorted updates 08/26 Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 01/15] aide: Fix compilation with nettle 4.x Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 02/15] suricata: handle oe_cargo_build removal Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 03/15] samhain: fix server startup failure on systemd-based systems Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 04/15] README: fix broken URLs in meta-integrity and ccs-tools Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 05/15] meta-tpm: Add missing recipe metadata (HOMEPAGE/SUMMARY) Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 06/15] dm-verity: remove unused variable Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 07/15] wic: document the meta-intel dependency in the dm-verity hash example Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 08/15] docs: update path of wic files Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 09/15] tpm2-tools: set status for CVE-2017-7524 and CVE-2024-29039 Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 10/15] tpm2-tss: set status for CVE-2024-29040 Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 11/15] tpm2-tools: fix PACKAGECONFIG typo Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 12/15] fix LICENSE variable syntax to suppress QA warning Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 13/15] meta-integrity: Fix ima-evm-utils LICENSE Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 14/15] meta-tpm: Fix SUMMARY/HOMEPAGE in affected recipes Scott Murray
2026-08-26 20:57 ` [meta-security][PATCH 15/15] aide: Fix unstable install task hash Scott Murray
2026-08-27 14:52 ` [yocto-patches] [meta-security][PATCH 00/15] Assorted updates 08/26 Marta Rybczynska
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.