public inbox for openembedded-core@lists.openembedded.org
 help / color / mirror / Atom feed
From: ValentinBoudevin <valentin.boudevin@gmail.com>
To: openembedded-core@lists.openembedded.org
Cc: daniel.turull@ericsson.com, jerome.oufella@savoirfairelinux.com,
	antonin.godard@bootlin.com,
	ValentinBoudevin <valentin.boudevin@gmail.com>
Subject: [PATCH v5 2/4] generate-cve-exclusions: Add a .bbclass
Date: Fri, 16 Jan 2026 14:05:18 -0500	[thread overview]
Message-ID: <20260116190520.118714-4-valentin.boudevin@gmail.com> (raw)
In-Reply-To: <20260116190520.118714-1-valentin.boudevin@gmail.com>

Add a new class named kernel-generate-cve-exclusions.bbclass to
generate-cve-exclusions to use this script at every run.

Two steps for testing:
1) Inherit this class in the kernel recipe with "inherit
   kernel-generate-cve-exclusions.bbclass"
2) Turn the variable ENABLE_KERNEL_CVE_EXCLUSIONS to "1".
3) Use the following command to generate a cvelistV5 entry with a JSON
   file in in ${WORKDIR}/cvelistV5/ :
   "bitbake linux-yocto -c generate-cve-exclusions"

The JSON file can then be parsed in the following run by cve-check.

This class contains several methods:

*do_clone_cvelistV5: Clone the cvelistV5 repo in
${WORKDIR}/cvelistV5/git

(e.g. bitbake-builds/poky-master/build/tmp/work/qemux86_64-poky-linux/
linux-yocto/6.18.1+git/cvelistV5/git)

*do_generate_cve_exclusions: Use the script generate-cve-exclusions.py.
It uses the new "--output-json" argument to generate a JSON file as an
output stored in ${WORKDIR}/cvelistV5//cve-exclusion_${LINUX_VERSION}.json

*do_cve_check:prepend: Parse the previously generated JSON file to set
the variable CVE_STATUS corretly

The class also provides some variables:
*ENABLE_KERNEL_CVE_EXCLUSIONS: Enable/Disable this class (off by default
to not affect linux-yocto OE example)
*GENERATE_CVE_EXCLUSIONS_SRC_URI and GENERATE_CVE_EXCLUSIONS_SRCREV can
be used to change the source repository or fix a commit with SRCREV
(usefull for deterministic testing)
*GENERATE_CVE_EXCLUSIONS_NETWORK can be set to 0 to provide an offline
mode based on DL_DIR directory.
*GENERATE_CVE_EXCLUSIONS_WORKDIR path used as a working directory for
this class
*GENERATE_CVE_EXCLUSIONS_DESTSUFFIX suffix used for the git unpack
*GENERATE_CVE_EXCLUSIONS_UNPACK_DIR path of the unpack for the git
repository

Signed-off-by: Valentin Boudevin <valentin.boudevin@gmail.com>
---
 .../kernel-generate-cve-exclusions.bbclass    | 135 ++++++++++++++++++
 1 file changed, 135 insertions(+)
 create mode 100644 meta/classes/kernel-generate-cve-exclusions.bbclass

diff --git a/meta/classes/kernel-generate-cve-exclusions.bbclass b/meta/classes/kernel-generate-cve-exclusions.bbclass
new file mode 100644
index 0000000000..cd81cc5899
--- /dev/null
+++ b/meta/classes/kernel-generate-cve-exclusions.bbclass
@@ -0,0 +1,135 @@
+# Generate CVE exclusions for the kernel build (set to "1" to enable)
+ENABLE_KERNEL_CVE_EXCLUSIONS ?= "0"
+
+# CVE exclusions source repository settings
+GENERATE_CVE_EXCLUSIONS_SRC_URI ?= "git://github.com/CVEProject/cvelistV5.git;branch=main;protocol=https"
+GENERATE_CVE_EXCLUSIONS_SRCREV ?= "${@bb.fetch2.get_autorev(d)}"
+GENERATE_CVE_EXCLUSIONS_NETWORK ?= "1"
+GENERATE_CVE_EXCLUSIONS_WORKDIR ?= "${WORKDIR}/cvelistV5"
+GENERATE_CVE_EXCLUSIONS_DESTSUFFIX ?= "git"
+GENERATE_CVE_EXCLUSIONS_UNPACK_DIR ?= "${GENERATE_CVE_EXCLUSIONS_WORKDIR}/${GENERATE_CVE_EXCLUSIONS_DESTSUFFIX}"
+
+python __anonymous() {
+    # Only run if CVE exclusions are enabled
+    if d.getVar("ENABLE_KERNEL_CVE_EXCLUSIONS", True) == "1":
+        srcrev = d.getVar("GENERATE_CVE_EXCLUSIONS_SRCREV", True) or ""
+        network = d.getVar("GENERATE_CVE_EXCLUSIONS_NETWORK", True) or "0"
+        # Check offline mode with AUTOREV-like SRCREV
+        if network == "0" and srcrev.strip() in ("${AUTOREV}", "AUTOINC", "INVALID"):
+            bb.fatal("generate-cve-exclusions: Offline mode but SRCREV is set to AUTOREV/AUTOINC/INVALID. "
+                     "Cannot proceed without network access or use a fixed SRCREV.")
+        d.appendVar("SRC_URI", " ${GENERATE_CVE_EXCLUSIONS_SRC_URI};name=generate-cve-exclusions;destsuffix=${GENERATE_CVE_EXCLUSIONS_DESTSUFFIX}")
+        d.setVar("SRCREV_generate-cve-exclusions", d.getVar("GENERATE_CVE_EXCLUSIONS_SRCREV"))
+}
+
+python do_clone_cvelistV5() {
+    import subprocess
+    import shutil, os
+    # Only run if CVE exclusions are enabled
+    if not d.getVar("ENABLE_KERNEL_CVE_EXCLUSIONS") == "1":
+        return
+    network_allowed = d.getVar("GENERATE_CVE_EXCLUSIONS_NETWORK") == "1"
+    workdir = d.getVar("GENERATE_CVE_EXCLUSIONS_WORKDIR")
+    unpack_dir = d.getVar("GENERATE_CVE_EXCLUSIONS_UNPACK_DIR")
+    # Remove existing unpacked directory if any
+    if os.path.exists(workdir):
+        shutil.rmtree(workdir)
+    # Prepare fetcher
+    src_uri_list = (d.getVar('SRC_URI') or "").split()
+    cve_uris = []
+    for uri in src_uri_list:
+        if "name=generate-cve-exclusions" in uri:
+            cve_uris.append(uri)
+    if not cve_uris:
+        bb.note("No CVE exclusions SRC_URI found, skipping fetch")
+        return
+    fetcher = bb.fetch2.Fetch(cve_uris, d)
+    # Clone only if network is allowed
+    if network_allowed:
+        fetcher.download()
+    else:
+        # Offline mode without network access
+        bb.note("GENERATE_CVE_EXCLUSIONS_NETWORK=0: Skipping online fetch. Checking local downloads in DL_DIR...")
+        have_sources = False
+        dl_dir = d.getVar("DL_DIR")
+        srcrev = d.getVar("SRCREV_generate-cve-exclusions")
+        bb.note(f"Checking for sources for SRCREV: {srcrev}")
+        # Check SRCREV is NOT set to AUTOREV
+        if srcrev.strip() in ("${AUTOREV}", "AUTOINC", "INVALID"):
+            bb.fatal("generate-cve-exclusions: Offline mode but SRCREV is set to AUTOREV/AUTOINC/INVALID. Cannot proceed without network access or use a fixed SRCREV.")
+            return
+        # Loop through the fetcher's expanded URL data
+        for ud in fetcher.expanded_urldata():
+            ud.setup_localpath(d)
+            # Check mirror tarballs first
+            for mirror_fname in ud.mirrortarballs:
+                mirror_path = os.path.join(dl_dir, mirror_fname)
+                if os.path.exists(mirror_path):
+                    bb.note(f"Found mirror tarball: {mirror_path}")
+                    have_sources = True
+                    break
+            # If no mirror, check original download path
+            if not have_sources and ud.localpath and os.path.exists(ud.localpath):
+                bb.note(f"Found local download: {ud.localpath}")
+                have_sources = True
+            if not have_sources:
+                bb.fatal("generate-cve-exclusions: Offline mode but required source is missing.\n"f"SRC_URI = {ud.url}")
+                return
+    # Unpack into the standard work directory
+    fetcher.unpack(unpack_dir)
+    # Remove the folder ${PN} set by unpack
+    subdirs = [d for d in os.listdir(unpack_dir) if os.path.isdir(os.path.join(unpack_dir, d))]
+    if len(subdirs) == 1:
+        srcdir = os.path.join(unpack_dir, subdirs[0])
+        for f in os.listdir(srcdir):
+            shutil.move(os.path.join(srcdir, f), unpack_dir)
+        shutil.rmtree(srcdir)
+    bb.note("Vulnerabilities repo unpacked into: %s" % unpack_dir)
+}
+do_clone_cvelistV5[network] = "${GENERATE_CVE_EXCLUSIONS_NETWORK}"
+do_clone_cvelistV5[nostamp] = "1"
+do_clone_cvelistV5[doc] = "Clone CVE information from the CVE Project: https://github.com/CVEProject/cvelistV5.git"
+addtask clone_cvelistV5 before do_generate_cve_exclusions
+
+do_generate_cve_exclusions() {
+    # Only run if CVE exclusions are enabled
+    if [ "${ENABLE_KERNEL_CVE_EXCLUSIONS}" != "1" ]; then
+        return 0
+    fi
+    generate_cve_exclusions_script=${COREBASE}/scripts/contrib/generate-cve-exclusions.py
+    if [ ! -f "${generate_cve_exclusions_script}" ]; then
+        bbwarn "generate-cve-exclusions.py not found in ${COREBASE}."
+        return 0
+    fi
+    if [ ! -d "${GENERATE_CVE_EXCLUSIONS_UNPACK_DIR}" ]; then
+        bbwarn "CVE exclusions source directory not found in ${GENERATE_CVE_EXCLUSIONS_UNPACK_DIR}."
+        return 0
+    fi
+    python3 "${generate_cve_exclusions_script}" \
+        "${GENERATE_CVE_EXCLUSIONS_UNPACK_DIR}" \
+        ${LINUX_VERSION} \
+        --output-json > ${GENERATE_CVE_EXCLUSIONS_WORKDIR}/cve-exclusion_${LINUX_VERSION}.json
+    bbplain "CVE exclusions generated for kernel version ${LINUX_VERSION} at ${GENERATE_CVE_EXCLUSIONS_WORKDIR}/cve-exclusion_${LINUX_VERSION}.json."
+}
+do_generate_cve_exclusions[nostamp] = "1"
+do_generate_cve_exclusions[doc] = "Generate CVE exclusions for the kernel build. (e.g., cve-exclusion_6.12.inc)"
+addtask generate_cve_exclusions after do_clone_cvelistV5 before do_cve_check
+
+python do_cve_check:prepend() {
+    import os
+    import json
+    workdir = d.getVar("GENERATE_CVE_EXCLUSIONS_WORKDIR")
+    kernel_version = d.getVar("LINUX_VERSION")
+    json_input_file = os.path.join(workdir, "cve-exclusion_%s.json" % kernel_version)
+    if os.path.exists(json_input_file):
+        with open(json_input_file, 'r', encoding='utf-8') as f:
+            cve_data = json.load(f)
+        cve_status_dict = cve_data.get("cve_status", {})
+        count = 0
+        for cve_id, info in cve_status_dict.items():
+            if info.get("active", True):
+                continue
+            d.setVarFlag("CVE_STATUS", cve_id, info.get("message", ""))
+            count += 1
+        bb.note("Loaded %d CVE_STATUS entries from JSON output for kernel %s" % (count, kernel_version))
+}
\ No newline at end of file


  parent reply	other threads:[~2026-01-16 19:12 UTC|newest]

Thread overview: 21+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <188AFCD98EA3E578.3200434@lists.openembedded.org>
2026-01-16 19:05 ` [PATCH 1/1] improve_kerne_cve_report: Add a bbclass support ValentinBoudevin
2026-01-16 19:05   ` [PATCH v5 0/4] generate-cve-exclusions: Add a .bbclass ValentinBoudevin
2026-01-19 10:44     ` Daniel Turull
2026-01-16 19:05   ` [PATCH v5 1/4] generate-cve-exclusions: Add --output-json option ValentinBoudevin
2026-01-16 19:05   ` ValentinBoudevin [this message]
2026-01-17 13:36     ` [OE-core] [PATCH v5 2/4] generate-cve-exclusions: Add a .bbclass Peter Kjellerstedt
2026-01-19 10:40       ` Daniel Turull
2026-01-16 19:05   ` [PATCH v5 3/4] generate-cve-exclusions: Move python script ValentinBoudevin
2026-01-16 19:05   ` [PATCH v5 4/4] linux: Add inherit on generate-cve-exclusions ValentinBoudevin
2026-01-17 13:38     ` [OE-core] " Peter Kjellerstedt
2026-01-19  9:35   ` [PATCH 1/1] improve_kerne_cve_report: Add a bbclass support Daniel Turull
2026-01-29 21:10 ` [PATCH v6 0/4] generate-cve-exclusions: Add a .bbclass ValentinBoudevin
2026-01-29 21:10   ` [PATCH v6 1/4] generate-cve-exclusions: Add output format option ValentinBoudevin
2026-01-29 21:10   ` [PATCH v6 2/4] cvelistv5: add a new recipe ValentinBoudevin
2026-02-01 11:56     ` [OE-core] " Mathieu Dubois-Briand
2026-02-01 15:12     ` Richard Purdie
2026-02-02 13:48       ` vboudevin
2026-02-02 14:04         ` [OE-core] " Marta Rybczynska
2026-02-02 19:54           ` vboudevin
2026-01-29 21:10   ` [PATCH v6 3/4] kernel-generate-cve-exclusions: Add a .bbclass ValentinBoudevin
2026-01-29 21:10   ` [PATCH v6 4/4] generate-cve-exclusions: Move python script ValentinBoudevin

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260116190520.118714-4-valentin.boudevin@gmail.com \
    --to=valentin.boudevin@gmail.com \
    --cc=antonin.godard@bootlin.com \
    --cc=daniel.turull@ericsson.com \
    --cc=jerome.oufella@savoirfairelinux.com \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox