<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-security.git, branch master-next</title>
<subtitle>Mirror of git.yoctoproject.org/meta-security.git</subtitle>
<id>https://git.enea.com/cgit/linux/meta-security.git/atom?h=master-next</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-security.git/atom?h=master-next'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/'/>
<updated>2026-05-25T14:11:19+00:00</updated>
<entry>
<title>tpm2-pkcs11: upgrade 1.9.1 -&gt; 1.9.2</title>
<updated>2026-05-25T14:11:19+00:00</updated>
<author>
<name>Peter Marko</name>
<email>peter.marko@siemens.com</email>
</author>
<published>2026-05-05T14:13:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=226839ac408223f8041cde1b1d8b762d6fbc8050'/>
<id>urn:sha1:226839ac408223f8041cde1b1d8b762d6fbc8050</id>
<content type='text'>
This contains fix for building native recipe with security flags
enabled:
* https://github.com/tpm2-software/tpm2-pkcs11/commit/be97b21ae641303ce83a8fbb54002701c1aede31

Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>samhain: upgrade 4.5.2 -&gt; 4.5.3</title>
<updated>2026-05-17T14:45:41+00:00</updated>
<author>
<name>Bin Cao</name>
<email>bin.cao.cn@windriver.com</email>
</author>
<published>2026-05-13T08:57:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=dc0a7622e4a60c8729d281b5f909119c781e8a67'/>
<id>urn:sha1:dc0a7622e4a60c8729d281b5f909119c781e8a67</id>
<content type='text'>
Update samhain-client, samhain-server, and samhain-standalone to 4.5.3.

Release notes: https://www.la-samhna.de/samhain/archive.html

Signed-off-by: Bin Cao &lt;bin.cao.cn@windriver.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>aide: fix pkg_postinst_ontarget shell script</title>
<updated>2026-05-17T14:45:41+00:00</updated>
<author>
<name>jason.lau</name>
<email>Haitao.Liu@windriver.com</email>
</author>
<published>2026-04-28T09:19:42+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=9d749026dd1054104a946565710152b50c6330ea'/>
<id>urn:sha1:9d749026dd1054104a946565710152b50c6330ea</id>
<content type='text'>
- Fix conditional checks for AIDE_SCAN_POSTINIT and AIDE_RESCAN_POSTINIT:
  '[ 0 ]' always evaluates to true since it's a non-empty string.
  Use string comparison '= "1"' instead.
- Fix invalid use of '&amp;&amp;' inside '[ ]' test brackets. Use separate
  test expressions joined by shell '&amp;&amp;'.

Signed-off-by: Haitao Liu &lt;haitao.liu@windriver.com&gt;
(reworked for 0.19.3, fixed indentation)
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>aide-base.bbclass: correct STAGING_AIDE_DIR</title>
<updated>2026-05-17T14:45:41+00:00</updated>
<author>
<name>Li Zhou</name>
<email>li.zhou@windriver.com</email>
</author>
<published>2026-04-27T02:48:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=b4c43ad77ad7eedab05d48dcbd32e4ef96b21c83'/>
<id>urn:sha1:b4c43ad77ad7eedab05d48dcbd32e4ef96b21c83</id>
<content type='text'>
Fix the typo "aida" to "aide" in STAGING_AIDE_DIR.

Signed-off-by: Li Zhou &lt;li.zhou@windriver.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>arpwatch: fix typos</title>
<updated>2026-05-17T14:44:55+00:00</updated>
<author>
<name>Yi Zhao</name>
<email>yi.zhao@eng.windriver.com</email>
</author>
<published>2026-05-07T15:21:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=797df6dca9cbcf735afe92a49bb27e5a3637ba77'/>
<id>urn:sha1:797df6dca9cbcf735afe92a49bb27e5a3637ba77</id>
<content type='text'>
APRWATCH_FROM -&gt; ARPWATCH_FROM
ARPWATH_REPLY -&gt; ARPWATCH_REPLY
CONFFILE_FILES -&gt; CONFFILES:${PN}

Signed-off-by: Yi Zhao &lt;yi.zhao@windriver.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>tpm2-tools: make efivar optional</title>
<updated>2026-05-17T14:44:55+00:00</updated>
<author>
<name>Peter Marko</name>
<email>peter.marko@siemens.com</email>
</author>
<published>2026-05-07T08:39:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=cdb4e444acbb2b9df467d716241a206c9ea6d3b0'/>
<id>urn:sha1:cdb4e444acbb2b9df467d716241a206c9ea6d3b0</id>
<content type='text'>
Previous commit made this a hard dependency because it's autodetected.
Instead of that, make it configurable so it can be disabled (roughtly
equivalent to behavior before that commit).

Signed-off-by: Peter Marko &lt;peter.marko@siemens.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>parsec-service: update TS group name</title>
<updated>2026-05-17T14:44:55+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2026-05-05T15:44:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=921b75fa4aceaeeef388acdd1a3a8e35b5afc4cc'/>
<id>urn:sha1:921b75fa4aceaeeef388acdd1a3a8e35b5afc4cc</id>
<content type='text'>
meta-arm recently changed the group name that is used by TS[1], so update
the group name to match.

[1] meta-arm 595cb0f1a0 ("arm/trusted-services: fix udev management in libts")

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>parsec-service: do group membership modifications in useradd</title>
<updated>2026-05-17T14:44:55+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2026-05-05T15:44:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=a9384af621c5dd1b80bf3999bd3993190e8348f7'/>
<id>urn:sha1:a9384af621c5dd1b80bf3999bd3993190e8348f7</id>
<content type='text'>
Instead of calling groupmems after creating the user, we can tell useradd
to do the group membership when creating the user.  There are several
reasons for this:

1) Consolidation of the calls into a single call means creation is atomic,
   it either worked or it did not.
2) The existing logic doesn't work if both TPM and TS were enabled.
3) GROUPMEMS_PARAM is broken in oe-core master[1] and this will not be
   fixed as groupmems has been removed from shadow[2].

Instead, construct a list of groups that parsec needs to be a member of,
and pass them to useradd.

[1] https://bugzilla.yoctoproject.org/show_bug.cgi?id=16277
[2] shadow 388ce70 "*/: groupmems(8): Remove program"

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>parsec-service: assign PACKAGECONFIG in one line</title>
<updated>2026-05-17T14:44:55+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2026-05-05T15:44:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=58ac5eda9a6e142fc7871cf5bd79becb58b010f5'/>
<id>urn:sha1:58ac5eda9a6e142fc7871cf5bd79becb58b010f5</id>
<content type='text'>
By :appending the TPM option we make it impossible for distros to simply
assign to PACKAGECONFIG.

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>meta-parsec: Do not run Parsec CI jobs on 32bit platforms.</title>
<updated>2026-05-17T14:44:55+00:00</updated>
<author>
<name>Anton Antonov</name>
<email>anton.antonov@arm.com</email>
</author>
<published>2026-05-01T16:18:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=677294c158242331d844650b9e6c4a8fd4eef4d4'/>
<id>urn:sha1:677294c158242331d844650b9e6c4a8fd4eef4d4</id>
<content type='text'>
Signed-off-by: Anton Antonov &lt;Anton.Antonov@arm.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
</feed>
