<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-security.git/meta-parsec, branch master-next</title>
<subtitle>Mirror of git.yoctoproject.org/meta-security.git</subtitle>
<id>https://git.enea.com/cgit/linux/meta-security.git/atom?h=master-next</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-security.git/atom?h=master-next'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/'/>
<updated>2026-05-17T14:44:55+00:00</updated>
<entry>
<title>parsec-service: update TS group name</title>
<updated>2026-05-17T14:44:55+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2026-05-05T15:44:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=921b75fa4aceaeeef388acdd1a3a8e35b5afc4cc'/>
<id>urn:sha1:921b75fa4aceaeeef388acdd1a3a8e35b5afc4cc</id>
<content type='text'>
meta-arm recently changed the group name that is used by TS[1], so update
the group name to match.

[1] meta-arm 595cb0f1a0 ("arm/trusted-services: fix udev management in libts")

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>parsec-service: do group membership modifications in useradd</title>
<updated>2026-05-17T14:44:55+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2026-05-05T15:44:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=a9384af621c5dd1b80bf3999bd3993190e8348f7'/>
<id>urn:sha1:a9384af621c5dd1b80bf3999bd3993190e8348f7</id>
<content type='text'>
Instead of calling groupmems after creating the user, we can tell useradd
to do the group membership when creating the user.  There are several
reasons for this:

1) Consolidation of the calls into a single call means creation is atomic,
   it either worked or it did not.
2) The existing logic doesn't work if both TPM and TS were enabled.
3) GROUPMEMS_PARAM is broken in oe-core master[1] and this will not be
   fixed as groupmems has been removed from shadow[2].

Instead, construct a list of groups that parsec needs to be a member of,
and pass them to useradd.

[1] https://bugzilla.yoctoproject.org/show_bug.cgi?id=16277
[2] shadow 388ce70 "*/: groupmems(8): Remove program"

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>parsec-service: assign PACKAGECONFIG in one line</title>
<updated>2026-05-17T14:44:55+00:00</updated>
<author>
<name>Ross Burton</name>
<email>ross.burton@arm.com</email>
</author>
<published>2026-05-05T15:44:21+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=58ac5eda9a6e142fc7871cf5bd79becb58b010f5'/>
<id>urn:sha1:58ac5eda9a6e142fc7871cf5bd79becb58b010f5</id>
<content type='text'>
By :appending the TPM option we make it impossible for distros to simply
assign to PACKAGECONFIG.

Signed-off-by: Ross Burton &lt;ross.burton@arm.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>parsec-service: Update Parsec service version.</title>
<updated>2026-05-17T14:44:55+00:00</updated>
<author>
<name>Anton Antonov</name>
<email>anton.antonov@arm.com</email>
</author>
<published>2026-05-01T15:24:30+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=e6538dbad1656fc12634a910c098ba2b3fd7126e'/>
<id>urn:sha1:e6538dbad1656fc12634a910c098ba2b3fd7126e</id>
<content type='text'>
This update adds compatibility with clang 22.1 in oe-core.

Signed-off-by: Anton Antonov &lt;Anton.Antonov@arm.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>layer.conf: Update to wrynose (6.0) release</title>
<updated>2026-03-22T14:24:23+00:00</updated>
<author>
<name>Marta Rybczynska</name>
<email>marta.rybczynska@ygreky.com</email>
</author>
<published>2026-03-19T13:12:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=8028c573db6923525c2918724f2bd36d4a420e0b'/>
<id>urn:sha1:8028c573db6923525c2918724f2bd36d4a420e0b</id>
<content type='text'>
Update LAYERSERIES_COMPAT in all layer.conf files with the exception
of meta-parsec to wrynose.  For meta-parsec, added wrynose to the list
of supported versions.

Signed-off-by: Marta Rybczynska &lt;marta.rybczynska@ygreky.com&gt;
</content>
</entry>
<entry>
<title>meta-parsec: Remove meta-clang dependency</title>
<updated>2026-01-07T14:49:29+00:00</updated>
<author>
<name>Scott Murray</name>
<email>scott.murray@konsulko.com</email>
</author>
<published>2026-01-06T16:08:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=7d0ae0d688d34c1574530cb93c12323ac48f1bb3'/>
<id>urn:sha1:7d0ae0d688d34c1574530cb93c12323ac48f1bb3</id>
<content type='text'>
Since clang is in openembedded-core now, meta-parsec no longer needs
meta-clang.  Also updated maintainers in meta-parsec README.md since
it had previously been missed.

Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>parsec-service: update PACKAGECONFIG options as lists of cargo build features</title>
<updated>2025-07-04T16:41:20+00:00</updated>
<author>
<name>Anton Antonov</name>
<email>anton.antonov@arm.com</email>
</author>
<published>2025-05-19T08:45:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=b1f1c7a304de33916040928ea7182c03580efb28'/>
<id>urn:sha1:b1f1c7a304de33916040928ea7182c03580efb28</id>
<content type='text'>
After commit 7a2b9acef2 "cargo: pass PACKAGECONFIG_CONFARGS to cargo build"
we don't need to include Parsec cargo build features into CARGO_BUILD_FLAGS.
Let's update PACKAGECONFIG options as lists of features.

A small fix in readme.md as well.

Signed-off-by: Anton Antonov &lt;Anton.Antonov@arm.com&gt;
Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>layer.conf: Update to whinlatter (5.3) release</title>
<updated>2025-07-04T16:41:20+00:00</updated>
<author>
<name>Scott Murray</name>
<email>scott.murray@konsulko.com</email>
</author>
<published>2025-07-02T22:38:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=ea67ceefdca42da806f3312c6703eff769463b8b'/>
<id>urn:sha1:ea67ceefdca42da806f3312c6703eff769463b8b</id>
<content type='text'>
Update LAYERSERIES_COMPAT in all layer.conf files with the exception
of meta-parsec to whinlatter.  For meta-parsec, whinlatter has been
added, and the EOL releases removed, as an initial update.

Signed-off-by: Scott Murray &lt;scott.murray@konsulko.com&gt;
</content>
</entry>
<entry>
<title>Remove self as Maintainer</title>
<updated>2025-06-23T20:14:41+00:00</updated>
<author>
<name>Armin Kuster</name>
<email>akuster808@gmail.com</email>
</author>
<published>2025-06-23T20:14:41+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=c5ce0b7e469fbee4ca630d3adefba63e3fefb3fe'/>
<id>urn:sha1:c5ce0b7e469fbee4ca630d3adefba63e3fefb3fe</id>
<content type='text'>
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
<entry>
<title>meta-security: Remove True option to getVar calls</title>
<updated>2025-02-03T02:11:12+00:00</updated>
<author>
<name>akash hadke</name>
<email>akash.hadke27@gmail.com</email>
</author>
<published>2025-01-09T10:43:48+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-security.git/commit/?id=8fcbc47b9c56fe405a7a6d51ff0d8e2b756818ea'/>
<id>urn:sha1:8fcbc47b9c56fe405a7a6d51ff0d8e2b756818ea</id>
<content type='text'>
getVar() now defaults to expanding by default, thus remove the True
option from getVar() calls with a regex search and replace.

Signed-off-by: Akash Hadke &lt;akash.hadke27@gmail.com&gt;
Signed-off-by: Armin Kuster &lt;akuster808@gmail.com&gt;
</content>
</entry>
</feed>
