Skip to content

Commit

Permalink
Release 2.3.0 (#24)
Browse files Browse the repository at this point in the history
* README: add n1sdp to the list of supported targets

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- aec2db8 base: optee-os-fio: 3.10: bump to ebc153ed7
- 5be99f0 base: fioconfig: switch to go-mod bbclass
- 66329fc base: class: go-mod: export proxies for mod download
- 24066c0 initrdscripts: Preload compose-apps if present

Signed-off-by: Ricardo Salveti <[email protected]>

* setup-environment-internal: add BB_LOGCONFIG to BB_ENV_EXTRAWHITE

Allow bitbake logconfig to be provided by the build environment.

Signed-off-by: Ricardo Salveti <[email protected]>

* setup-environment-internal: add BB_CONSOLELOG to BB_ENV_EXTRAWHITE

Allow bitbake console log to be provided by the build environment.

Signed-off-by: Ricardo Salveti <[email protected]>

* Dockerfile: install jsonFormatter

Used by the custom bitbake log config file.

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-updater layer

Relevant changes:
- 8350960 aktualizr: Don't put unused configs in the image.
- 2b4f422 aktualizr: Upgrade to 2020.10 release

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-clang layer

Relevant changes:
- 4edfb8e bpftrace: Update to 0.11.4 release
- 9ef0b21 clang: Update to latest on 11.x release

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update openembedded-core layer

Relevant changes:
- d11ab9cb77 build-appliance-image: Update to gatesgarth head revision
- feb77e322f build-appliance: Correct branch to gatesgarth
- e525592e83 build-appliance-image: Update to gatesgarth head revision

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-arm layer

Relevant changes:
- e8cc037 arm/qemuarm64-secureboot: don't use -dev kernel
- 4cae9fe arm-autonomy/xen-tools: update vif hostname fix patch status
- 784ef62 Add experimental CI using Kas+GitLab

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-freescale layer

Relevant changes:
- 646ce62b linux-fslc-imx: update to v5.4.81
- 9d5db778 linux-fslc: update to v5.4.81
- d050309e linux-fslc-imx: update to v5.4.80
- c1a004e3 linux-fslc: update to v5.4.80
- f8ae8106 linux-fslc-imx: update to v5.4.79
- 95c03eb8 linux-fslc: update to v5.4.79
- af828259 linux-fslc-imx: update to v5.4.78
- 1616074c linux-fslc: update to v5.4.78
- 3c160a3b atf: Use space instead of +=
- 9793fac8 linux-imx: Backport to fix perf compilation problems

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-freescale-3rdparty layer

Relevant changes:
- 0a3dcb1 u-boot-toradex: Update to version 2020.07

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-yocto layer

Relevant changes:
- be61a72 poky.conf: bump version for 3.2.1 release

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-xilinx layer

Relevant changes:
- a902513 meta-toolchain: Ensure that a baremetal toolchain can finish building
- b3e37df gdb: Fix on-target GDB compilation
- ed3fc52 newlib: Upstream now disabled builtin symbols
- 699d986 libgcc.bbappend: Clear empty lib directory
- d8d50ea machine/aarch64-tc.conf: Fix incorrect ilp32 pkgarch
- ba66cc1 newlib: update to early gatesgarth version
- b097355 gcc: update to early gatesgarth version
- c9bf136 gdb: update to early gatesgarth version
- 64c6e9b binutils: update to early gatesgarth version
- 3d886fe pmu-firmware: Latest toolchain always treats 'assert' as a macro
- 4aa4cb1 Uprev standalone toolchain bbappends
- 44d2470 meta-microblaze: Move gcc patch that was missed in the prior work

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- 44ddff1 base: lmp: use docker-moby as default docker provider
- 11221ee base: lmp: also enable seccomp on docker-moby
- 6f01936 base: docker: update docker.service based on latest from docker-ce-packaging
- 4d9fe0d base: containerd-opencontainers: use upstream systemd service file
- d1d06e1 base: docker-moby: update to the final 20.10.1 tag
- c18549f base: aktualizr-lite: bump to c43d5b0
- dca8f33 base: lmp: bump version for 3.2.1 yocto release
- 5dcc7f3 bsp: linux-lmp-xlnx: bump to rev 61e889430e4c7
- 543c35e bsp: linux-lmp-rpi: update to v5.4.81
- f14f8c6 bsp: linux-lmp-toradex-imx: bump to rev d4d4c7a935764
- 85edbe1 bsp: linux-lmp-fslc-imx: update to v5.4.81
- 5136f6d base: linux-lmp-lts: update to v5.4.82
- 1cd505f base: aktualizr-lite: bump to 9ca8284

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- c40f5d8 base: linux-lmp: update to v5.10.1
- 33c2467 base: preload: shortlist apps
- 8a1bd24 base: preload: preload apps along with their images

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update openembedded-core layer

Relevant changes:
- a2eebe92da apr-util: Only specify --with-dbm=gdbm if gdbm support is enabled
- f75dd73e76 valgrind: exclude bar_bad/bar_bad_xml from ptests
- 2d1b47a4aa archiver.bbclass: Fix --runall=deploy_archives for images
- 071b3aa630 minicom: RDEPENDS on ncurses-terminfo-base
- 6ecf1704f4 ncurses: Make ncurses-tools depend on ncurses-terminfo-base
- 5ce0102ca7 gcc: Add patch to resolve i*86 tune configuration overrides
- 7fa9d5719a go.bbclass: Use external linker for native packages
- 87479f0e63 go: Update 1.15.5 -> 1.15.6
- 4b923dc9e7 go: Update to 1.15.5
- 7a0f56c2c9 go: upgrade 1.15.2 -> 1.15.3
- 1b3a8230af timezone: upgrade to 2020d
- 7537bdc5d7 kea: fix reproducibility
- ea9615d82b man-db: Avoid reproducibility failures after fixing groff-native
- e300796a78 groff: Fix reproducibility issue
- bd6495ba96 u-boot-tools: Fix reproducibility issue
- d10ea68968 ffmpeg: fix reproducibility
- 2aa9abce9b ruby: fix reproducibility
- 784ca95f7e perl: fix installation failure because of shell issue
- 27b2aca75a parted: Make readline dependency optional
- 2f8da84311 glibc: Make adjtime() for 32 bit support being called with delta == NULL
- 6f191f8039 glibc: CVE-2020-29562 and CVE-2020-29573
- 6d1169d2c0 lttng-modules: fix build against v5.10+
- 96756f56ab linux-yocto/5.4: update to v5.4.80
- 043d6b0910 linux-yocto-rt/5.4: update to -rt44
- 5d758a1568 grub: Add second fix for determinism issue
- c494d69efb grub: Fix build reproducibility issue
- 7acb6701df cups: Mark CVE-2008-1033 as a non-issue
- 16f70caa23 cups: Mark CVE-2009-0032 as a non-issue
- 2b611ac044 cups: whitelist CVE-2018-6553
- e4092d18f9 linux-firmware: package firmware for Lontium lt9611uxc bridge
- 07d66526cd linux-firmware: upgrade 20201118 -> 20201218
- 1382957d25 linux-firmware: package ath11k firmware
- 27983f070c linux-firmware: upgrade 20201022 -> 20201118
- 75d3022554 linux-firmware: upgrade 20200817 -> 20201022
- 18642d02ec wireless-regdb: upgrade 2020.04.29 -> 2020.11.20
- d3ec2ecdf8 uninative: Don't use single sstate for pseudo-native
- 6cc93de69f kernel-module-split.bbclass: fix kernel modules getting marked as CONFFILES
- b76b2b3043 coreutils: add SUSE-specific issues to CVE whitelist
- b1f2ad7b46 webkitgtk: fix reproducibility
- 5b9b559ceb llvm: fix reproducibility
- 9010bd4457 meta/lib/oe/reproducible.py: gitsm:// works just as fine as git:// for timestamps
- c59ffcc4ba populate_sdk_ext: use SDK_CUSTOM_TEPLATECONF variable to enable custom templateconf.cfg
- b1a1e93616 meta/lib/oeqa/manual/oe-core.json: Update test_bitbake_devshell
- af9e9945ac qemu: CVE-2020-25624
- 22c7bbdaec image_types: remove obsolete tar comment
- 383fec3f31 image_types: sort tarball file listings
- 0a9a9a4d52 qemu: CVE-2020-29129 CVE-2020-29130
- bae9a74f4f oeqa/devtool: use Yocto mirror for pv-1.5.3 tarball
- e18c593d57 lz4: Use the new branch naming from upstream
- 417bb4b013 buildtools-tarball: add wic dependency into extended buildtools
- 9d67dd5a63 sudo: fix multilib conflict
- 4116c4bbc8 cve-update-db-native: handle all-wildcard versions
- bcc2df0f95 libsdl2: Add directfb to PACKAGECONFIG rdepends

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- f0c5d95 base: tini: add 0.19.0
- 94f939d base: docker-moby: update to v20.10.2
- b27398c base: lmp-feature-wifi: use rpidistro fw if rpi
- 5a03451 base: linux-lmp: update to v5.10.5
- 9321ea5 base: linux-lmp-lts: update to v5.4.87
- 6d0726d base: go.bbclass: Use external linker for native packages
- 646f58e base: fioconfig: Add EnvironmentFile possibility

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- 5ecaa8e base: optee-os-fio: 3.10: bump to 9ca46e6b9
- 6e9a756 base: optee-sks: bump to c5e0ae74
- 72a8197 lmp-device-register: Bump version
- 9d9fdee base: optee-os-fio: 3.10: bump to fb3e7853a
- b29bf42 base: aktualizr-lite: bump to 3c2aa5b
- 0638f53 base: u-boot-fio: 2020.04: bump to 74cbbe21aeb
- 7f31378 bsp: meta-arm: docker: move override to docker-moby

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- e234fe2 base: fioconfig: bump rev to c96f5c3
- 28756a7 base: lmp-image-common: sudoers: disable lecture by default
- 068d3b3 base: lmp-image-common: prepend 50 to the lmp sudoers fragment
- 1e14807 bsp: optee-os-fio: 3.10.0: apalis-imx6: enable CFG_CORE_DYN_SHM
- 2f2966b base: u-boot-fio: 2020.04: bump to 881a8e04d1c

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- 56d7e96 base: linux-lmp: update to v5.10.9
- d354508 base: linux-lmp-lts: update to v5.4.91
- ea7e62f base: fioconfig: bump rev to 8b316d0

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- ba64f62 base: kmeta-linux-lmp-5.4.y: bump to 4ef2600a
- 95c695d bsp: device-tree: uz3eg-iocc: only drop axi_intc_0
- b25c96f bsp: u-boot-ostree-scr-fit: uz: add fpga load support
- b42aabc bsp: uz3eg-iocc: add bitstream as fit loadable
- 2c8e09e bsp: linux-lmp-xlnx: depend on bitstream-extraction deploy
- 322270c bsp: bitstream-extraction: generate and deploy bit.bin
- 09bf2ae base: dockerd: patch to reload images on signal
- 81418fe base: aktualizr-lite: bump to 0d050b4
- ce239a4 base: kmeta-linux-lmp-5.4.y: bump to 8da49138
- fd19552 bsp: uz3eg-iocc: sync dts from meta-avnet
- 8e62b8a bsp: uz3eg-iocc: update system.xsa from 2020.2
- de738c6 bsp: linux-lmp-xlnx: update to v5.4.91
- fd58132 meta-lmp-bsp: conf: set bitstream packages as machine specific
- c9aa0e2 meta-lmp: xilinx-tools: bitstream-extraction: Add bitstream support
- 7dd131f base: fioconfig: bump rev to 67c71aa

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update openembedded-core layer

Relevant changes:
- 4e8022635f linuxloader: Avoid confusing string concat errors
- e02c02459b flex: Fix --noline option behavior
- 9a1bcf47f0 devtool: Fix source extraction for gcc shared source
- 5ea3c65c6b toolchain-shar-relocate.sh: Fix handling files with colons
- a56b9dbfeb wic: Optimise fstab modification for ext2/3/4 and msdos partitions
- 39f98ef8c1 wic: Copy rootfs dir if fstab needs updating
- 9f33aa6f1d wic: Update pseudo db when excluding content from rootfs
- 28d2e13155 image_types_wic: Move wic working directory
- 00474d9901 wic: Allow exec_native_cmd to run HOSTTOOLS
- 365b10a95a wic: Ensure internal workdir is not reused
- 6136e1312f wic: Add workdir argument
- ef87c3609e gcc: Backport patch to resolve i*86 tune configuration overrides
- 7ee65c50f7 lib/oe/utils: Return empty string in parallel_make
- 9504a975c7 meta: toolchain-shar-relocate.sh: Filter out post-relocate-setup script
- b97f2901c6 meta: toolchain-shar-relocate.sh: Do not use $target_sdk_dir as regex
- f097519cb5 binutils: Fix CVE-2020-35448
- c6dac9e737 boost: drop arm-intrinsics.patch
- f4fd434292 systemd.bbclass: improve error message when a service unit specified in SYSTEMD_SERVICE is not found
- 7d17f26134 toolchain-shar-extract.sh: Handle special characters in script path
- ebc71592b5 scripts: oe-run-native, fix *-native directories
- f0314a6937 zip: whitelist CVE-2018-13410 and CVE-2018-13684
- c7bf9aebd0 systemd: upgrade 246.6 -> 246.9
- fbb752ea3b binutils: upgrade 2.35 -> 2.35.1
- 9d49791d06 linux-yocto/5.4: update to v5.4.87
- efe5a17b8f ffmpeg: Fix CVE-2020-35964, CVE-2020-35965
- b067f78a11 glibc: CVE-2019-25013
- d813abdb91 mobile-broadband-provider-info: upgrade 20190618 ->20201225
- 50b2695919 pseudo: Update for arm host and memleak fixes/cleanup
- cac0ad6f82 pseudo: Add lchmod wrapper
- ee6832529b pseudo: Drop patches merged into upstream branch
- f3f88700ee pseudo: Update to print PSEUDO_LOGFILE in abort message on path mismatches
- 604899b3c8 bitbake.conf: Add /run/ to PSEUDO_IGNORE_PATHS
- f41c17a155 selftest: Add argument to keep build dir
- f1a0ea55c0 curl: Fix CVE-2020-8284, CVE-2020-8285, CVE-2020-8286
- d850874e86 license.bbclass: Add COMMON_LICENSE_DIR and LICENSE_PATH dirs to PSEUDO_IGNORE_PATHS
- 7aa1ae139b bitbake.conf: Prevent pyc file generation in pseudo context
- 9aec2fdda1 wic: Pass canonicalized paths in PSEUDO_IGNORE_PATHS
- c54646582b bitbake.conf: Canonicalize paths in PSEUDO_IGNORE_PATHS
- 5c9931e0ff lib/oe/path: Add canonicalize()
- 8d7f1c1574 oeqa/commands: Ensure sync can be found regardless of PATH
- 4297245219 initscripts: use quotes for shell variable comparision
- 9be8187878 coreutils: enable xattrs by default for nativesdk
- cec30244d9 diffstat: point the license checksum at the license
- 2f13e9ab05 linux-yocto/5.4: update to v5.4.85
- d554dd1909 linux-yocto/5.4/cfg: fix FIRMWARE_LOADER warnings
- 90e5a7a917 linux-yocto/5.4/cfg: fix -tiny warnings
- ec3efb1fca linux-yocto/5.8/cfg: fix -tiny warnings
- d68875f690 linux-yocto/5.4: update to v5.4.83
- c14616fe27 linux-yocto/cfg: qemuarm64-gfx.cfg: add CONFIG_INPUT_UINPUT
- e3069eda0e linux-yocto/5.4: update to v5.4.82
- 6f20e6c12f linux-yocto/cfg: qemuppc: set CONFIG_SCSI to '=y'
- 7f9c55651c timezone: upgrade to 2020f
- a89f40038f qemu: CVE-2020-28916
- cb41f66566 qemu: CVE-2020-25723
- ba0797130d man-db: Fix reproducibility issue
- e71365fe12 wic/direct/kparser: ensure fsuuid for vfat and msdos align with format
- c0f96eadf9 grub: Further reproducibility fix
- b364688110 patch: fix CVE-2019-20633
- f8aa7314f9 grub: fix "CVE:" line in one of the patches
- debcb0c398 libexif: fix CVE-2020-0198; CVE-2020-0452
- 086584d5e6 devtool: gitsm:// should be handled same as git:// in upgrades
- 9b291019c1 timezone: upgrade to 2020e
- 122f93d68e glib-2.0: fix CVE-2020-35457
- ee8e0c07a5 openssl: Update to 1.1.1i
- d8bdee355b oeqa/selftest/cases/devtool.py: fix typo in ignore_patterns call

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-security layer

Relevant changes:
- 6053e8b tpm2-pkcs11: build and package python tools
- 3b81fca .gitlab-ci: drop script
- d2ceb5e kas-security-base: Don't create local SSTATE mirror
- 080778c scap-security-guide: fix build with Python 3.9
- c40e8f8 samhain: update to 4.4.2
- ab133ef clamav: unify volatiles file name
- 97cac84 suricata: unify volatiles file name
- e8c9e69 gitlab-ci: add building meta-security-compliance pkgs
- 9a4de56 gitlab-ci: add meta-hardening build image
- 58c17d0 meta-security: Add gatesgarth to LAYERSERIES_COMPAT
- 8bcc4d7 layer.conf: use += instead of := to update BBFILES

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-virtualization layer

Relevant changes:
- b8aa31c ceph: uprev v15.2.0 -> v15.2.8
- 1ebde9b xen, linux-yocto-dev, RPi4: weaker assign for KBRANCH and KMACHINE
- cf5a9a9 moby: update to v19.03.14
- 35b9016 docker-ce: update to v19.03.14
- 8c53147 containerd: bump to v1.4.3
- 6049f9a k8s: update to 1.20 release candidate
- fbfced3 linux-yocto: add cgroup-hugetlb config
- 08b5de4 libvirt: fix host gcc can't recognized option -fmacro-prefix-map
- 968e411 nagios-core: fix do_install during cross builds

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-openembedded layer

Relevant changes:
- 6ff4bd4f3 postgresql: Update to 12.5
- fd7dc3487 fuse: set CVE_PRODUCT to "fuse_project:fuse"
- 25285ded6 gupnp: Upgrade to 1.2.2 -> 1.2.4
- e788d4673 gssdp: Upgrade to 1.2.2 -> 1.2.3
- 27626b4ee libsdl2-mixer: set --disable-music-ogg-shared to link statically
- af0c3a62d libsdl2-mixer: Fix ogg/vorbis support in libsdl2-mixer
- ac6bc96e7 nodejs: 12.19.1 -> 12.20.1
- a10ea62a1 wireshark: Several securtiy fixes
- a5d1580a4 lmbench: Fix setting LDLIBS failure
- 6313a640a tclap: fix branch
- 461b240e7 tclap: align version to tag v1.2.2
- 8d5dddb88 postgresql: Use /dev/urandom when openssl is not used
- 5e492d19e nanopb: move to dynamic-layers
- 243f73385 spdlog: Fix recipe so other recipes can use spdlog with external fmt.
- 165ad9ad4 networkmanager: Fix reallocarray check in meson and configure
- c920ef3de sdbus-c++-libsystemd: Fix reallocarray check in meson
- 4cdd3b13d pidgin-sipe: Do not add native libdir to pkgconfig search path
- f7a7fce11 colord: fix installed-vs-shipped error
- f091dc42d openct: use upstream SRC_URI
- 197b47c45 fbset: use DEBIAN_MIRROR in SRC_URI
- 817c4aeb3 liboop: use upstream SRC_URI
- 89d0acd96 python3-aiohttp: added missing RDEPENDs
- db892b5e6 lockfile-progs: use DEBIAN_MIRROR in SRC_URI
- f5324e4cd ebtables: do not install /etc/ethertypes
- d6d0ef5ca multipath-tools: fix error handling for udev_monitor_set_receive_buffer_size
- 387f40ce8 nodejs: 12.19.0 -> 12.19.1
- 992e09f09 php: CVE-2020-7069
- 09f5a2ac5 php: CVE-2020-7070
- 81d14a863 samba: CVE-2020-14383 Security Advisory
- 38beb6fe9 samba: CVE-2020-14318 Security Advisory
- d9911b087 zabbix: CVE-2020-15803 Security Advisory
- 81874b239 mcpp: Normalize the patch format of CVE
- dba54c19f Revert "gnome-calendar: update to 3.38.1, add libhandy 1.x support"
- 1f4b2a1af pcsc-lite: provide pcsc-lite-lib-native explicitly for native build
- a82e2fbdf dlt-daemon: add upstream patch to fix CVE-2020-29394
- 5e4601a3f tcpdump: Patch for CVE-2020-8037
- f6338892d php: remove the failing ${D}/${TMPDIR} code
- f79843641 minifi-cpp: depend on nettle and lz4
- 699e85e56 lvm2.inc: switch branch master to main

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-xilinx layer

Relevant changes:
- eb4ba06 picozed-zynq7.dts: add marvell,88e1510 to eth phy
- e1748ff meta-xilinx-bsp: Move uboot-device-tree to meta-xilinx-tools layer
- d156c17 linux-xlnx: Fix build with patch from upstream kernel for gcc-10.
- d1102df u-boot-xlnx: Fix build error by applying patch from upstream u-boot.
- 3743215 qemu-xilinx: Fix patch puzz warning during do_patch
- f8c4ca0 Cleanup QB_MACHINE for xilinx machines
- 7f9e158 linux-xlnx.inc: Update overlay config fragments
- a6a46f2 zcu102-zynqmp.conf: Fix qemuboot for zcu102-zynqmp
- d803f4c ultra96: Using BOARD level hiearchy for ultra96 overrides
- 56c9755 Adding BOARD and BOARD_VARIANT level hierarchy
- 742c57c weston: Update the weston patches to comply with weston-9.0
- 609425b Update LICENSE_CHECKSUM for kernel-module-hdmi
- 7b092ed xilinx-board.inc: fixing BOARD_ARCH and BOARDVARIANT_ARCH names

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-xilinx-tools layer

Relevant changes:
- 37e0988 uboot-device-tree.bb: Move uboot-device-tree from meta-xilinx-bsp layer
- d29d8fc ultra96: Using BOARD level hiearchy for ultra96 overrides
- a4647e0 fpgamanger: Putting artifacts one layer deeper (/lib/firmware/xilinx)
- d1ad5ac machine-xilinx-versal.inc: Adding psm to xilinx-bootbin bif
- 9296dc3 imgsel_git.bb: Update xis_config.h file as per SOM requirement

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-arm layer

Relevant changes:
- 932d35b arm-autonomy/documentation: Remove references to meta-kernel
- d12eada arm-autonomy/juno-firmware: add compressed kernel support
- e45752a arm-autonomy/autonomy-host: add user defined partition to wic image
- a365b3b arm-autonomy/juno-image-customization: add host wks file
- 7b82307 arm-autonomy/arm-autonomy-host-image-minimal: Added multiconfig support
- a72b89c arm-bsp: fix sgi575 kernel compile warning
- 1cd14b3 ci: fail any build that emits warnings
- 27ed22b ci: make bootstrap just another kas overlay
- b97016f kas: remove redundant env settings
- eff9e62 gitlab-ci: force git updates
- 892c968 arm-bsp: fix missing stable kernels

Signed-off-by: Ricardo Salveti <[email protected]>

* bblayers-bsp.inc: drop meta-kernel removal from meta-arm-bsp

Not needed anymore as meta-arm-bsp is now using linux-yocto instead.

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-freescale layer

Relevant changes:
- 9975fcce linux-fslc-qoriq: update to LSDK-20.12 & 5.4.92
- 748f8b79 xf86-video-armada: Fix no more working SRC_URI
- f0b79a6a imx-gst1.0-plugin: update to NXP's MM_04.05.06_2008_L5.4.47 branch
- ffbfe1e5 gstreamer1.0-plugins-bad: update to NXP's MM_04.05.06_2008_L5.4.47 branch
- 45349f7c gstreamer1.0-plugins-good: update to NXP's MM_04.05.06_2008_L5.4.47 branch
- 40f79721 gstreamer1.0-plugins-base: update to NXP's MM_04.05.06_2008_L5.4.47 branch
- 42e25c54 gstreamer1.0: update to NXP's MM_04.05.06_2008_L5.4.47 branch
- 166e1dbc imx-vpuwrap: update to NXP's MM_04.05.06_2008_L5.4.47 branch
- 350232b3 linux-fslc: update to v5.4.82
- a29e031c vulkan-loader: Add runtime dependency for libvulkan-imx
- cf196954 imx-dpu-g2d: Upgrade to 1.8.9
- 46674b74 imx-gpu-g2d: Upgrade to 6.4.3.p0.0
- 44b65425 kernel-module-imx-gpu-viv: Upgrade to 6.4.3.p0.0
- 4b27ea1f imx-gpu-viv: Update install for improved packaging design
- 377e223a imx-gpu-viv: Fix rootfs conflict with libvulkan-dev
- 7acedfd1 imx-gpu-viv: Upgrade to 6.4.3.p0.0
- 858dbd02 EULA: Update to LA_OPT_NXP_Software_License v15 August 2020
- ae040295 conf/layer.conf: Add hardknott to LAYERSERIES_COMPAT
- de1e47a2 optee-test_3.7.0.imx: fix optee-test build

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-freescale-3rdparty layer

Relevant changes:
- 21b6997 linux-fslc-qoriq: apply SolidRun patches for LSDK-20.12
- 1c84ff5 linux-boundary: bump version to 5.4 2.2.0
- 6cbb85e u-boot-boundary: bump version to 2020.10
- 516db73 imx-atf-boundary: bump version to 2.2

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-intel layer

Relevant changes:
- 50f0a4f4 linux-intel-rt/5.10: fix config warnings
- 39f3772a linux-intel/5.10: fix config warnings
- 7a21b1ad linux-intel-rt/5.10: add recipe
- c7ddf7bb linux-intel/5.10: add recipe
- fb180e2c linux-intel-rt/5.4: update to v5.4.78
- 7b9d05d4 linux-intel/5.4: update to v5.4.81

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-updater layer

Relevant changes:
- c8327e1 Merge pull request #796 from ricardosalveti/master
- 0e753b0 Merge pull request #797 from liuming50/fix-race-problems-of-ostreecommit-ota-tasks
- ddb1b5d Merge pull request #798 from wilddom/fix-image_repo_manifest
- d3a832f image_types_ostree.bbclass: get lock before accessing OSTREE_REPO
- 41ff3f9 image_repo_manifest.bbclass: Improvement for builds outside the .repo directory
- 910243a image_types_ota.bbclass: use standard ext4 features
- 0168549 Merge pull request #791 from shr-project/jansa/master
- 3e717a0 image_types_ota.bbclass: pass -t ext4 to mke2fs
- 8be7b8c Merge pull request #787 from liuming50/refactor-ota-ext4-task
- e5c4bc3 Merge pull request #788 from advancedtelematic/fix/python3-for-repo
- 6ea7917 Use python3 to get repo working again.
- 4d34fa5 image_types_ota.bbclass: add metadata_csum mkfs option
- 45dc621 image_types_ota.bbclass: call oe_mkext234fs to make ota-ext4 image

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- 9d06b90 base: docker-moby: drop support for old .dockercfg
- fde02bc base: wireguard-module: update to v1.0.20210124
- d379d19 bsp: linux-lmp-fslc-imx: update to v5.4.93
- ba9bf42 bsp: linux-lmp-toradex-imx: bump to rev 1266d0110fced
- 7c1ba91 base: linux-lmp: update to v5.10.11
- 982cf1b bsp: linux-lmp-xlnx: update to v5.4.93
- 6c11a8e base: linux-lmp-lts: update to v5.4.93
- c575c68 base: add sudo 1.9.5p2
- 147c087 base: containerd-opencontainers: drop version update
- cac9aad conf/layer.conf: add hardknott to LAYERSERIES_COMPAT
- df90dab base: lmp.inc: drop linux-stable bbmasks

Signed-off-by: Ricardo Salveti <[email protected]>

* setup-environment-internal: use imx_hab4 from lmp-tools

imx_hab4 was migrated to lmp-tools (same keys), so link as before when
executing setup-environment-internal.

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-clang layer

Relevant changes:
- 04a1194 compiler-rt: Disable sanitizer builds
- 67a7cad clang/llvm: Upgrade to 11.1.0-rc2
- d4d55a3 clang: Replace mtune with mcpu to match oe-core
- f7b5498 clang.bbclass: Set CCACHE_COMPILERCHECK as default value
- 39e9ec6 clang: for x86_64, set Yocto GCC install search path
- dca6dd4 Add the target option to the CLANG environment variables.
- e2d2a02 qemu: Link with latomic on clang/x86
- 1eef983 ppp: Mark non-clangable
- b5a7b58 clang.bbclass: Remove -mcpu option for the octeontx2 core
- 216da5f clang: Update to 11.0.1 rc2
- 11ad388 pulseaudio: Remove -Qunused-arguments with clang
- fbb032b yoe.yml: Use actions/checkout at v2
- e1e452a redis: Mark non-clangable as of now
- c271c50 rpm: Use gcc for building rpm on all mips arches
- 24d254a luajit: Add -no-integrated-as

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-openembedded layer

Relevant changes:
- cef93b7b0 openldap: upgrade 2.4.56 -> 2.4.57
- e615c6fce openldap: upgrade 2.4.51 -> 2.4.56
- bdb79efab zram: fix sourcing of zram parameters
- 4e6de3045 giflib: apply patch for CVE-2019-15133 and set CVE_PRODUCT
- b5b2f9777 flatbuffers: whitelist CVE-2020-35864
- ba3c1dcf1 sip3: simplify recipe
- 46ea93dc4 iscsi-initiator-utils: upgrade 2.1.2 -> 2.1.3
- 027407dfd xmlsec1: Fix configure QA error caused by host lookup path
- 2ed77abf1 xterm: provide virtual/x-terminal-emulator
- a65323839 xterm: install xterm and uxterm desktop files

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-security layer

Relevant changes:
- 4583ab9 kas-security-base: Don't create local SSTATE mirror
- 1a450e8 scap-security-guide: fix build with Python 3.9
- d0adcba samhain: update to 4.4.2
- 5351607 clamav: unify volatiles file name
- 9abb002 suricata: unify volatiles file name
- a67a0cb gitlab-ci: add building meta-security-compliance pkgs
- faf9a2c gitlab-ci: add meta-hardening build image
- e780c32 meta-security: Add gatesgarth to LAYERSERIES_COMPAT
- 63e1cf3 layer.conf: use += instead of := to update BBFILES

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update openembedded-core layer

Relevant changes:
- f74d1ea018 python3targetconfig.bbclass: Make py3 dep and tasks only for target recipes
- 9a39776026 gpgme: use python3targetconfig
- 94a8eff9a9 meta: drop _PYTHON_SYSCONFIGDATA_NAME hacks
- 37caed2ec6 distutils3-base.bbclass: use python3targetconfig
- 23884b5839 python3-pycairo: use python3targetconfig
- 386c5d3f22 python3: split python target configuration into own class
- 2b0577ae97 uninative: Upgrade to 2.10
- 4a28f22f9d pseudo: Update to work with glibc 2.33
- c7717df8a9 openssh: Backport a fix to fix with glibc 2.33 on some platforms
- 8aa2cd230d systemd: change /bin/nologin to /sbin/nologin
- a378ec0fc2 license_image.bbclass: Don't attempt to symlink to the same file
- 09127557fd image_types.bbclass: tar: use posix format instead of gnu
- 5fbf670ec5 libcroco: Added CVE
- 461579e032 libgcrypt: Whitelisted CVEs
- 2f6c7aae83 sudo: fix CVE-2021-3156
- 98470df92d sudo: fix CVE-2021-23240
- a5974d2bda qemu.inc: Should depend on qemu-system-native, not qemu-native
- 327317d016 kernel.bbclass: fix deployment for initramfs images
- 68e17e21f5 package: Ensure do_packagedata is cleaned correctly
- d0a7383ca3 wic/selftest: test_permissions also test bitbake image
- cadaa2d126 openssl: set CVE_VERSION_SUFFIX
- ca324a6fef sstatesig: Add descriptive error message to getpwuid/getgrgid "uid/gid not found" KeyError
- 79368ef09e sanity.bbclass: Check if PSEUDO_IGNORE_PATHS and paths under pseudo control overlap
- 9799854c25 linux-yocto/5.4: update to v5.4.94
- 173f235084 linux-yocto-rt/5.4: fix 5.4-stable caused build breakage
- 859e0453c6 linux-yocto/5.4: update to v5.4.90
- 064b38c295 staging: Clean up files installed into the sysroot
- 653f8b1a8a python3: Avoid installing test data into recipe-sysroot
- cb254debc3 ncurses: Don't put terminfo into the sysroot
- 6559f16646 glibc: update to latest release/2.32/master branch
- 5cc15f53d5 npm.bbclass: use python3 for npm config
- 6bcd2e242e recipetool: create: only add npmsw url if required
- 2c17be4712 npm.bbclass: make shrinkwrap file optional
- a9b4a1e82e image_types: Ensure tar archives are reproducible
- c63feb7e06 strace: increase ptest timeout duration 120->240s
- 9adacc27c5 ovmf-shell-image: image is only buildable on x86-64
- e2222ddd8b core-image-sato-sdk-ptest: these images need ptest
- 68ac3f3f93 dtc: improve reproducibility
- 782f7f4f73 python3: Use addtask statement instead of task dependencies
- 1dadeb58e8 lib/oe/patch.py: Don't return command stderr from runcmd function
- 73f8c25a44 cve_check: add CVE_VERSION_SUFFIX to indicate suffix in versioning
- 02a44b507a cve-check: replace Looseversion with custom version class
- 5e86b84955 ca-certificates: upgrade 20200601 -> 20210119
- 0fc140e6ae pseudo: Update to include passwd and file renaming fixes
- 3f56b2666f gobject-introspection: Fix variable override order
- 83ee03a6f0 buildhistory.bbclass: avoid exception for empty BUILDHISTORY_FEATURES variable
- 6d8a58b111 externalsrc: Detect code changes in submodules
- 59de426a62 sanity.bbclass: sanity check for if bitbake is present in PATH
- 35f3e08c52 sanity: Verify that user isn't building in PSEUDO_IGNORE_PATHS
- c34b143207 timezone: upgrade to 2021a
- f9f4191a6f gstreamer1.0: fix failing ptest
- a6a4e1350c devtool: Fix file:// fetcher symlink directory structure
- c925b83cbd oeqa/selftest/cases/tinfoil.py: increase timeout 10->60s test_wait_event
- 1da57e9281 externalsrc: Fix parsing error with devtool non-git sources
- f500435958 p11-kit: upgrade 0.23.21 -> 0.23.22
- c3f2e4ed9c gdk-pixbuf: fix CVE-2020-29385
- ed8e858fc3 sudo: fix CVE-2021-23239
- 25d1cae49e python3: fix CVE-2021-3177

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-freescale layer

Relevant changes:
- d05c5c66 linux-fslc: update to v5.4.94
- 1da9c2d5 linux-fslc: update to v5.4.93
- 478d4a55 linux-fslc-imx: update to v5.4.94
- 2dacd52e linux-fslc-imx: update to v5.4.93
- f72efdcd linux-fslc: update to v5.4.92
- a02b896c linux-fslc: update to v5.4.91
- c6b1ec79 linux-fslc: update to v5.4.90
- a6a1455c linux-fslc: update to v5.4.89
- b7837e5c linux-fslc-imx: update to v5.4.92
- f90c9105 linux-fslc-imx: update to v5.4.91
- 5467c213 linux-fslc-imx: update to v5.4.90
- 78db7cdc linux-fslc-imx: update to v5.4.89
- 7ccbffe0 linux-fslc: update to v5.4.88
- 07736c68 linux-fslc: update to v5.4.87
- f2ee54bb linux-fslc: update to v5.4.86
- f7beff23 linux-fslc-imx: update to v5.4.88
- efaef01a linux-fslc-imx: update to v5.4.87
- fe13bb19 linux-fslc-imx: update to v5.4.86
- 592e5682 linux-fslc-imx: update to v5.4.85
- 1cdc3ca2 linux-fslc: update to v5.4.85
- 4fc26369 linux-fslc: update to v5.4.83
- d612ac66 linux-fslc-imx: update to v5.4.83
- 620e8ba1 linux-fslc-imx: update to v5.4.82
- 8d141c73 Provide u-boot-mfgtool and linux-mfgtool for fslc distros
- 6e6b68c5 restool: compiling with optimization (-O2)
- 2396d154 restool: update to 8ddbe4c

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-freescale-3rdparty layer

Relevant changes:
- b6da6dd nitrogen8mn: add uboot binary and upgrade script to boot part
- 5c23c77 nitrogen8mm: add uboot binary and upgrade script to boot part
- 3bae408 nitrogen8m: add uboot binary and upgrade script to boot part
- 883d062 nitrogen8mn: add BOUNDARY_DEVICES_UBOOT_DEFCONFIG variable
- 7127d4d nitrogen8mm: add BOUNDARY_DEVICES_UBOOT_DEFCONFIG variable
- f111ec7 nitrogen8m: add BOUNDARY_DEVICES_UBOOT_DEFCONFIG variable
- 537903c nitrogen8mm: update uboot binary to rev2

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-intel layer

Relevant changes:
- 1d866c58 runtime/cases/mkl_dnn: change package name
- ecee468b runtime/miutils/tests/mkl_dnn_test: update test test_mkldnn_rnn_api
- 4bcf2d76 intel-graphics-compiler: set preferred LLVM version to 11.1.0
- 8f1dd0a2 opencl-clang: set preferred LLVM version to 11.1.0

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- 28eccb7 bsp: optee-os-fio: 3.12.0: add initial bsp bbappend
- 1525003 bsp: optee-client: qemuarm64: enable rpmb emulation
- 1add19a base: optee: add 3.12.0 release
- f7e7d66 base: optee-fiovb: leverage optee.inc
- 11c34a9 base: optee-sks: leverage optee.inc
- a125546 base: optee-test: consolidate recipes
- e090594 base: optee-examples: consolidate recipes
- 1e07d8b base: optee-os-fio: consolidate recipes
- 4d628d1 base: optee-client: consolidate recipes
- 669e8be base: docker-moby: update to v20.10.3
- 24ca6e5 bsp: linux-lmp-fslc-imx: update to v5.4.97
- 2389962 base: linux-lmp: update to v5.10.15
- 4c3ebff bsp: linux-lmp-xlnx: update to v5.4.97
- 83c8314 base: linux-lmp-lts: update to v5.4.97
- b107f22 bsp: lmp-machine-custom: make SOTA_CLIENT_FEATURES machine specific
- 7e8a36a base: kmeta-linux-lmp-5.4.y: bump to 58c846df
- 741f6db bsp: linux-lmp-fslc-imx: patch fix for QCA9377 SDIO hw params
- 6988789 base: preload: prepare for ostree-based preloading

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- e9f4da9 bsp: lmp-machine-custom: mx8mm: changes for imx-boot and uboot-fitmage class
- b1f2745 bsp: imx-atf: add compatibility and deployment to use uboot-fitimage generation
- 85c8110 bsp: mfgtool-files: flash separated imx-boot and U-Boot FIT
- 59395ff bsp: mfgtool-files: mx8mm: deploy u-boot.itb and kernel fit-image
- 5f340aa bsp: wic: sdimage-imx8-sota: fix comment to match reality
- 792cce3 bsp: wic: imx8: introduce a separate SPL image layout
- f25b241 bsp: u-boot-fio: imx8mmevk: lmp.cfg: enable signature verification in SPL
- 8ed4e82 bsp: u-boot: mfgtool-files: install spl-nodtb and UBOOT_MACHINE artifacts
- 71bba9e bsp: u-boot-fio: install spl-nodtb and UBOOT_MACHINE artifacts
- f4963f5 bsp: imx-mkimage: imx8mm: support SPL-only build
- 6d92695 base: u-boot-fio: 2020.04: bump to f0e3fc69

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- 05bda0b base: aktualizr-lite: bump to be4532f

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- 9919138 base: linux-lmp: update to v5.10.17

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- 7f92e5a base: optee-os-fio: 3.10: bump to 915ee978d
- 3b3442f bsp: lmp-machine-custom: mx8mm: fix lmp-base settings
- fea32d7 bsp: u-boot-fio: lmp-base: add SPL_DM support
- 9919ac2 bsp: imx-mkimage: mx8mm: guard deploy steps with IMXBOOT_TARGETS check

Signed-off-by: Ricardo Salveti <[email protected]>

* Change meta-layers back to dev after merging back master

* lmp-base: update meta-lmp layer

Relevant changes:
- 8c2b23f base: add linux-lmp-rt recipe
- ccd13dc base: wireguard-module: skip if kernel is linux-lmp-rt
- c9cce55 base: kmeta-linux-lmp-5.10.y: bump to 61f04b47

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-arm layer

Relevant changes:
- ac9f59c CI: don't retry jobs
- fb196ba kas: meta-kernel is no longer needed
- 6e3e298 arm-autonomy: Fix xenbus probe for guest kernels < 5.4.99
- d235d4b arm-autonomy: Fix XenStore initialisation for host kernels < 5.4.95
- 5207074 arm-autonomy/linux-arm-autonomy: apply runstate fix to kernels older than 5.10
- 7185d29 arm-toolchain: Fix potential runtime crash

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-intel layer

Relevant changes:
- 8e72e716 intel-microcode: fix the license md5sum
- df4745c7 intel-microcode: upgrade 20201118 -> 20210216
- 68ec3d57 linux-intel-rt/5.10: update to v5.10.4-rt22
- 3f5e50de linux-intel/5.10: update to v5.10.8
- 5f559c07 linux-intel/5.10: fix build with binutils 2.36
- b9ffc6d4 linux-intel-rt/5.4: update to v5.4.87
- a96a3af0 linux-intel/5.4: update to v5.4.90
- b47d2737 linux-intel/5.4: fix FIRMWARE_LOADER warnings
- 3d02bb6d microcode.py: updated test to read microcode for exact signature

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-riscv layer

Relevant changes:
- b022614 musl: Add bits/reg.h for riscv32
- 9d10fd4 python3-matplotlib,smem: Enable builds for rv32
- 7ca3cc6 README.md: Document Yoe distro as supporting risc-v architecture
- ad99b75 packagegroup-meta-multimedia: Ignore from world builds
- 8d1b5e1 packagegroup-self-hosted,packagegroup-core-eclipse-debug: Adjust for riscv32
- a2a2532 meta-gnome: Disable gnome-control-center
- 487f265 layer.conf: Additional set of packages to disable on rv32
- 7d9553a riscv32: Enable recipes which are now buildable with latest OE
- 38cbe72 perf: Fix build on rv32
- 11df9a2 ltp: Make 64bit time_t futex patch generic
- 142e779 layer.conf: Add 3.3 release series to LAYERSERIES_COMPAT
- f4107d9 layer.conf: Drop older releases from supported LAYERSERIES_COMPAT
- e9e1990 qtbase: Ignore textrels for rv32
- 1a8261c musl: Refresh patch on top of latest musl

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-bsp: update meta-yocto layer

Relevant changes:
- ac4a956 poky.conf: Bump version for 3.2.2 gatesgarth release
- 79d4859 linux-yocto: update genericx86 to v5.4.87

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update bitbake to 1.48.2

Relevant changes:
- 0a3bf681 lib/bb/fetch2/__init__.py: drop _PYTHON_SYSCONFIGDATA_NAME unsetting
- c73f8f2f fetch/git: download LFS content too during do_fetch
- cb7277e7 data_smart: Ensure hash reflects vardepvalue flags correctly

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-openembedded layer

Relevant changes:
- 945f062ff meta-oe/README: add Ubuntu prerequisite information
- fbe2e79ab python3-pykwalify: Do not unset _PYTHON_SYSCONFIGDATA_NAME
- c3a9e5b99 python-grpcio-tools: Add missing space for append
- 572d41482 postgresql: Inherit python3targetconfig
- a0c26ca2b libplist: Inherit python3targetconfig
- 59d3d64e9 openipmi: Inherit python3targetconfig
- 4a5719ffb gedit: Inherit python3targetconfig
- f95028681 wireguard-module: remove PKG assignment
- 5eb538cd5 dnsmasq: upgrade 2.82 -> 2.84
- 695068434 minifi-cpp: set PSEUDO_CONSIDER_PATHS
- 3ebf00ee3 mariadb: upgrade to 10.5.8
- e892991f8 mariadb: add package config zstd
- 5765b957e mariadb: Fix build on 32bit arches with 64bit time_t
- 83842c915 dnsmasq: Fix systemd service
- 1de0f4c33 celt051: update SRC_URI
- 57d742a83 python3-sh: remove python3-tests from RDEPENDS
- 25c29224f lua: update to 5.3.6
- 11875c1f4 enca: Fix SRC_URI

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-security layer

Relevant changes:
- adcd7c4 scap-security-guide: Inherit python3targetconfig
- be7f9bd openscap: Inherit python3targetconfig
- 8f51c5b python3-suricata-update: Inherit python3targetconfig
- 725526e apparmor: Inherit python3targetconfig
- 6612bf7 ima-evm-rootfs.bbclass: avoid generating /etc/fstab for wic
- ffab25f initramfs-framework-ima: let ima_enabled return 0
- 4dc646c README.md: update according to the refactoring in ima-evm-rootfs.bbclass
- 76d1e3e meta: refactor IMA/EVM sign rootfs
- 52bfc65 initramfs-framework-ima: RDEPENDS on ima-evm-keys
- f70207e ima-evm-keys: add recipe
- 0f34b25 initramfs-framework-ima: fix a wrong path
- ca1c208 ima-evm-utils: set native REQUIRED_DISTRO_FEATURES to empty
- f13c3fb softhsm: drop pkg as meta-oe has it
- 16ee730 scap-security-guide: Fix openembedded platform tests and build
- 0a3c0f3 ibmswtpm2: disable camellia algorithm
- 6053e8b tpm2-pkcs11: build and package python tools
- 3b81fca .gitlab-ci: drop script
- d2ceb5e kas-security-base: Don't create local SSTATE mirror
- 080778c scap-security-guide: fix build with Python 3.9
- c40e8f8 samhain: update to 4.4.2
- ab133ef clamav: unify volatiles file name
- 97cac84 suricata: unify volatiles file name
- e8c9e69 gitlab-ci: add building meta-security-compliance pkgs
- 9a4de56 gitlab-ci: add meta-hardening build image
- 58c17d0 meta-security: Add gatesgarth to LAYERSERIES_COMPAT
- 8bcc4d7 layer.conf: use += instead of := to update BBFILES

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-updater layer

Relevant changes:
- 070d291 Merge pull request #802 from advancedtelematic/fix/ostree-kernel-initramfs-mit
- fb97768 ostree-kernel-initramfs: Use MIT license.
- b2970f1 Merge pull request #799 from advancedtelematic/fix/python3-repo-bitbake
- 91abc98 Update dockerfiles to use Debian Buster.

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-virtualization layer

Relevant changes:
- a4439b7 libvirt-python: inherit python3targetconfig

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- 582922e base: dnsmasq: update append version to 2.84
- e5abc95 base: lmp: bump version for 3.2.2 yocto release
- f56b7ee base: u-boot-fio: 2020.04: bump to afd2cfe434c
- 95cde3e imx-boot: add support for SPL-only boot image with HDMI fw
- add9e7c bsp: lmp-machine-custom: mx8mq: changes for imx-boot and uboot-fitmage class
- cde814a bsp: mfgtool-files: imx8mq: flash separated imx-boot and U-Boot FIT
- 8f89d04 imx-boot: support spl-only builds for all imx8m
- c4ffaa8 mfgtool: extend deploy task for mx8m
- b40b434 bsp: u-boot-fio: imx8mqevk: lmp.cfg: enable signature verification in SPL

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- 7ac388d bsp: optee-os-fio: 3.10: imx6ullevk: enable rng_pta
- 4fc55e6 base: optee-os-fio: 3.10: bump to 01ed34ee1

Signed-off-by: Ricardo Salveti <[email protected]>

* lmp-base: update meta-lmp layer

Relevant changes:
- b70cd39 bsp: u-boot-fio: imx8mmevk: lmp.cfg: disable SPL_DM_MMC and SPL_BLK
- 1aafcbb base: collectd: add default configuration for lmp
- 04367f4 base: rrdtool: disable rrd_graph and fix perl install
- 23c9fc7 base: optee-os-fio: 3.6: bump to c67d7defe31
- a90fcd3 base: u-boot-fio: 2020.04: bump to f5ef084e7cb

Signed-off-by: Ricardo Salveti <[email protected]>

* Defining VOLATILE_LOG_DIR="no" in lmp config file

Persistent logging is required for Journald's Forware Secure Sealing (FSS)
feature.

* Leave an extra line at the end of the file for user to append configuration

* Added layers to add Parsec support in Pelion Edge (#13)

Added meta-rust, meta-tpm and meta-parsec layers

Co-authored-by: Yash Goyal <[email protected]>

* Updated PelionIoT meta layers to 2.3-rc1 SHA

* Future PR to revert ssh to https once meta-parsec is public

* Use PelionIoT remote to pull meta-parsec

* Updated PelionIoT project SHA to latest of dev

* Updated meta-parsec sha to 2.3-rc3

* changes SHA to support 2.3-RC4

* latest SHA for RC5

* Prepare 2.3.0 release

* updated to SHA's

* Pelion.xml - refer to 2.3.0 tags

Co-authored-by: Ricardo Salveti <[email protected]>
Co-authored-by: Esa Jaaskela <[email protected]>
Co-authored-by: Ari Parkkila <[email protected]>
Co-authored-by: Yash Goyal <[email protected]>
Co-authored-by: Yash Goyal <[email protected]>
Co-authored-by: Travis McCollum <[email protected]>
Co-authored-by: Travis McCollum <[email protected]>
  • Loading branch information
8 people authored Apr 6, 2021
1 parent d5f8cad commit 8c57ce0
Show file tree
Hide file tree
Showing 31 changed files with 43 additions and 1,094 deletions.
3 changes: 2 additions & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,8 @@ RUN apt-get update \
libmath-prime-util-perl libsdl1.2-dev libssl-dev locales \
openjdk-11-jre openssh-client perl-modules python3 python3-requests \
make patch repo sudo texinfo vim-tiny wget whiptail libelf-dev git-lfs \
socket corkscrew curl xz-utils tcl libtinfo5 device-tree-compiler \
socket corkscrew curl xz-utils tcl libtinfo5 device-tree-compiler python3-pip python3-dev \
&& pip3 --no-cache-dir install jsonFormatter \
&& apt-get autoremove -y \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/* \
Expand Down
1 change: 1 addition & 0 deletions conf/bblayers-base.inc
Original file line number Diff line number Diff line change
Expand Up @@ -12,4 +12,5 @@ BASELAYERS = " \
${OEROOT}/layers/meta-clang \
${OEROOT}/layers/meta-updater \
${OEROOT}/layers/meta-security \
${OEROOT}/layers/meta-security/meta-tpm \
"
4 changes: 0 additions & 4 deletions conf/bblayers-bsp.inc
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,3 @@ BSPLAYERS = " \
${OEROOT}/layers/meta-xilinx-tools \
${OEROOT}/layers/meta-lmp/meta-lmp-bsp \
"

# Remove layer dependencies that are not used/required by LMP
## LMP provides its own kernel recipes
LAYERDEPENDS_meta-arm-bsp_remove = "meta-kernel"
2 changes: 2 additions & 0 deletions conf/bblayers.conf
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,8 @@ BBLAYERS += " \
${OEROOT}/layers/meta-pelion-edge \
${OEROOT}/layers/meta-pelion-edge/meta-lmp-support \
${OEROOT}/layers/meta-mbed-edge \
${OEROOT}/layers/meta-rust \
${OEROOT}/layers/meta-parsec \
${OEROOT}/layers/meta-yocto/meta-poky/ \
${OEROOT}/layers/meta-arm/meta-arm-autonomy \
"
76 changes: 0 additions & 76 deletions conf/imx_hab4/00.pem

This file was deleted.

76 changes: 0 additions & 76 deletions conf/imx_hab4/01.pem

This file was deleted.

15 changes: 0 additions & 15 deletions conf/imx_hab4/CSF_1.req

This file was deleted.

76 changes: 0 additions & 76 deletions conf/imx_hab4/CSF_1_crt.pem

This file was deleted.

27 changes: 0 additions & 27 deletions conf/imx_hab4/CSF_1_key.pem

This file was deleted.

15 changes: 0 additions & 15 deletions conf/imx_hab4/IMG_1.req

This file was deleted.

Loading

0 comments on commit 8c57ce0

Please sign in to comment.