81 Commits

Author SHA1 Message Date
Qiumiao Zhang
3a1730cddc lib/libtasn1: Fix ETYPE_OK off by one array size check
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
2024-06-04 07:27:37 +00:00
chenyuanfeng
ace74e71fc add support ppc64le 2024-03-14 15:05:40 +08:00
Qiumiao Zhang
90f546b2c1 fix CVE-2024-1048 and backport some patches from upstream
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit e62f9657ab28a168cd5badeccf75370414ad34f5)
2024-03-04 21:27:17 +08:00
Yingkun Meng
aa0f959a9a loongarch: Disable relaxation relocations
Signed-off-by: Yingkun Meng <mengyingkun@loongson.cn>
(cherry picked from commit 54048ecd9ee186a9272c3e45899436d356eca8c6)
2023-12-28 09:54:47 +08:00
Qiumiao Zhang
62a410e532 skip verification when not loading grub.cfg
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit 1a70c89178317faf0fe5fe4a7402ce5c1f301084)
2023-12-22 15:30:09 +08:00
Qiumiao Zhang
56201aa169 change the name of module tpcm to tpcm_kunpeng
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit a5fc32e5290b5fd2231cad4ed738d840460e0133)
2023-12-11 14:44:58 +08:00
Qiumiao Zhang
980c48e6f4 add TPCM support with ipmi channel
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit bf5379d84f0bd61d407e87d2e4a1dd90528e2e1d)
2023-12-11 10:10:14 +08:00
Qiumiao Zhang
f12502316e support openEuler signature
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit ff7aab7c6032ca8c05300ebc886d3d6c8c58af2f)
2023-11-16 16:52:46 +08:00
Qiumiao Zhang
43b2baebc9 fix CVE-2023-4692 and CVE-2023-4693
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit 0d987655f0db571a164710f35bb81fa1b07e6838)
2023-10-09 14:56:36 +08:00
Qiumiao Zhang
60f34b87b7 backport some patches from upstream
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit fbde2eddf82f03439a1017ddfb43a384c4d0021c)
2023-09-16 16:18:29 +08:00
ouuleilei
2039ad485d add a patch to fix build error
(cherry picked from commit 034249d78b3b98f504dfc921f47ff47c4d99d6c4)
2023-09-15 15:36:04 +08:00
Qiumiao Zhang
9cf660d79e backport some patches from upstream
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit fa477f729e0fc02d397956eea132683ab70c3186)
2023-08-17 20:23:57 +08:00
Yingkun Meng
26e4ccb15e loongarch: Fix the initrd parameter passing
Signed-off-by: Yingkun Meng <mengyingkun@loongson.cn>
(cherry picked from commit 1eae189350080a9fa1e95072c13a92f1975e3699)
2023-08-17 17:38:08 +08:00
Qiumiao Zhang
288f337f09 remove the items of unsupported filesystems in fs.lst
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit 526de9571a987c632b280f63c6f4cff504733ebb)
2023-08-08 15:16:42 +08:00
Qiumiao Zhang
bc57e9a414 Override the linker and force noexecstack stacks
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit 794af19021640f0a0a6e8fd3d8b7be813c8387d4)
2023-07-17 16:36:24 +08:00
Qiumiao Zhang
efcfc54e35 use xsdt_addr if present
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit 2252eb370e4bee28b0ecc1f06405777e5f13adf0)
2023-07-04 09:57:19 +08:00
Qiumiao Zhang
9aa8fdb4af Revert "EFI: allocate kernel in EFI_RUNTIME_SERVICES_CODE instead of EFI_LOADER_DATA."
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit 581a5d3a1dc42d71afbc0d9cc6fae11a5d42084a)
2023-06-16 09:27:28 +08:00
Qiumiao Zhang
3612da6663 Read /etc/default/grub.d/*.cfg after /etc/default/grub
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit 36491a7d0e0d89b64f6c4cf1e3d0c3c734a114e8)
2023-06-08 20:07:10 +08:00
Qiumiao Zhang
5ae0b5fe32 backport some patches from upstream
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit 1857bf1c82987ea12d9a3ba541931390ee015b79)
2023-04-17 11:37:22 +08:00
mengyingkun
ef34dd4d6a LoongArch: Implement cache synchronization operation
Signed-off-by: mengyingkun <mengyingkun@loongson.cn>
(cherry picked from commit 60c48504c262606c75540c014de0c4c5a9ef65bd)
2023-03-23 11:34:42 +08:00
mengyingkun
92c919907d LoongArch: Force initrd load address 64KiB alignment
Signed-off-by: mengyingkun <mengyingkun@loongson.cn>
(cherry picked from commit 49bab1d9ae8b2a13648c414a8cc31b113873e17c)
2023-03-21 14:25:39 +08:00
Qiumiao Zhang
0a37a1ef49 Fix missing declaration of strchrnul in rpm-sort
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit 2f4cce557532c26c2cc6310f0286bb7a082ba5a8)
2023-03-11 16:43:28 +08:00
mengyingkun
7f375fd04f LoongArch: Add support for new efi screen info GUID
Signed-off-by: mengyingkun <mengyingkun@loongson.cn>
(cherry picked from commit 722a77ccf7c3d61301d934b3347b8938ba54d033)
2023-03-10 14:19:18 +08:00
mengyingkun
aac1da67f5 loongarch: Add support for v4.0 interface
Signed-off-by: mengyingkun <mengyingkun@loongson.cn>
(cherry picked from commit 048b61123f321de2f517f3a0aebc6c65f38f66f6)
2023-02-13 17:14:45 +08:00
mengyingkun
c29e5cec08 loongarch: Add EFI frame buffer support
Signed-off-by: mengyingkun <mengyingkun@loongson.cn>
(cherry picked from commit f4711e7975394ab53bc6691b8ec0c4ee41c3fd95)
2023-02-08 10:27:00 +08:00
Qiumiao Zhang
992ad95fca backport some patches from upstream
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit 3e10ca701e80f20fbf573377a138992d34ee4d68)
2023-02-07 09:36:47 +08:00
mengyingkun
b548958034 LoongArch: modify the location where initrd is loaded into memory
(cherry picked from commit cad0e769c463c78e5fd9cdb8321a81adcf30ea59)
2023-02-06 11:32:15 +08:00
Qiumiao Zhang
a99b16c57a disable some unsupported filesystems
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit 928a9962cfce3b17c554c6fe136859a4354bcca3)
2023-02-02 15:08:03 +08:00
mengyingkun
b30906733a Add LoongArch support
Signed-off-by: mengyingkun <mengyingkun@loongson.cn>
(cherry picked from commit e9acecfb21878c4ffa6baf3e9ed914ff3b0edede)
2023-01-13 11:02:19 +08:00
Qiumiao Zhang
180f7e295d modify the permissions of the files which under /usr/lib/systemd/system directory in grub2-tools to 644
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit bab0667802b1463ab9caefb0e0f9250b2a2d16de)
2022-12-19 10:04:31 +08:00
Qiumiao Zhang
7d55722f63 enable -fPIE compilation options
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit ecd9bbc8c2e077dca2b53a2a65f94f0281c4b85c)
2022-12-13 16:36:39 +08:00
zhangqiumiao
e72e4d297c fix CVE-2022-2601 and CVE-2022-3775
Signed-off-by: zhangqiumiao <zhangqiumiao1@huawei.com>
(cherry picked from commit 0eeb9d64d1375f1855789e7307b75378aaf0131f)
2022-11-18 14:41:05 +08:00
chenhaixing
d5554f9a9d add the source file of config_for_secure
(cherry picked from commit 0581c6fd5b71da492416a32b0ae171e42a95f568)
2022-11-16 10:31:52 +08:00
Qiumiao Zhang
fbf533a749 backport some patches from upstream
Signed-off-by: Qiumiao Zhang <zhangqiumiao1@huawei.com>
(cherry picked from commit cf4cdab72f0c328c29aa28ba4e5f22c8a5df2477)
2022-10-24 10:07:11 +08:00
wanglu210
079b40b6e1 backport patches from upstream 2022-08-30 19:46:33 +08:00
zhangqiumiao
0381eda69d fix compressed kernel verification failed
(cherry picked from commit 552b2e73ce02cbbb2fd5fc1c6e55fc8cbca062e7)
2022-07-29 10:48:30 +08:00
Qiumiao Zhang
6128eb4f91 add tpm in efi_modules of aarch64
(cherry picked from commit 5d6515ca47b7c87ef466409d065eee0057ba203c)
2022-06-29 17:04:31 +08:00
sun_hai_10
78c071e584 fix CVE-2021-3697 CVE-2022-28735 CVE-2022-28736 CVE-2022-28734 CVE-2022-28733 CVE-2021-3695 CVE-2021-3696
(cherry picked from commit b7658c3bed02672cb927576a609eee3d3e44c893)
2022-06-25 16:55:45 +08:00
sunh
fbc50e423e fix-null-pointer-dereference-when-paring-ICMP6_ROUTE_ADVERTISE messages
(cherry picked from commit ca2e356735821b85cdee855dae8a17ef633fc085)
2022-06-25 16:13:05 +08:00
Qiumiao Zhang
a82622ff0d modify the file permissions of grub-boot-indeterminate.service and 10-grub2-logind-service.conf to 644 2022-04-24 19:16:10 +08:00
吕晓倩
d67cdcb09f update grub.macros for riscv
(cherry picked from commit 40fba7bed91782960116a906a636bd433b61bd25)
2022-04-22 10:15:49 +08:00
zhangqiumiao
d97f925042 fix grub2 password setting does not take effect 2022-04-14 16:21:15 +08:00
Qiumiao Zhang
ee1698c650 enable sbat and don't verify kernels twice 2022-03-25 16:09:31 +08:00
Qiumiao Zhang
1b21eb86cf remove 08_fallback_counting.in apply grubby and disable emu arch
(cherry picked from commit 237808c8a4ddbc4604911fd239bb46f8ec9a37de)
2022-03-24 15:38:11 +08:00
t.feng
9db1d6c5d1 fix setupmode variable not exit in some machine 2022-03-22 22:30:15 +08:00
zhangqiumiao
8e795509c9 update to version 2.06 2022-03-22 17:36:06 +08:00
zhangqiumiao
d5e445ba3c use product_family macro(if defined) to set efi_vendor 2022-03-21 15:13:18 +08:00
zhangqiumiao
d8be91e9c6 modify some file permissions 2022-03-18 15:17:15 +08:00
xihaochen
17a445ed58 Fix CVE-2021-3981
(cherry picked from commit 3c38566f8b71e0c6d9bff0f208c6dee16b58769e)
2022-03-17 14:53:58 +08:00
yanan-rock
3f1947bb45 Fix arm64 kernel image not aligned on 64k boundary
* backport-arm64-Fix-EFI-loader-kernel-image-allocation.patch
  * backport-Arm-check-for-the-PE-magic-for-the-compiled-arch.patch

Signed-off-by: yanan-rock <yanan@huawei.com>
(cherry picked from commit 213914bf725818c72c2e685d5f3a39b64fea9a85)
2022-02-28 10:29:16 +08:00