[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [PATCH v6 0/5] Stop using insecure transports
Obtaining code over an insecure transport is a terrible idea for blatently obvious reasons. Even for non-executable data, insecure transports are considered deprecated. Changes since v5: - Rebase on top of the staging branch. - Do not replace a xenbits.xenproject.org link with a xenbits.xen.org link. Changes since v4: - Remove known-broken links entirely. They only mislead users into believing the code can be obtained there when it cannot. Changes since v3: - Drop patch 4, which is an unrelated removal of unused code. - Do not fail with an error if one tries to build the I/O emulator, vTPM, or vTPM manager stubdomains and passes --enable-extfiles. The user may have provided alternate download URLs via environment variables. Changes since v2: - Drop patches 5 and 6, which changed links not used by automated tools. These patches are the least urgent and hardest to review. - Ensure that no links are broken, and fail with an error instead of trying to use links that *are* broken. Demi Marie Obenour (5): Use HTTPS for all xenbits.xen.org Git repos Change remaining xenbits.xen.org link to HTTPS Build system: Do not try to use broken links Build system: Replace git:// and http:// with https:// Automation and CI: Replace git:// and http:// with https:// Config.mk | 20 ++++--------- README | 4 +-- automation/build/debian/stretch-llvm-8.list | 4 +-- docs/misc/livepatch.pandoc | 2 +- docs/process/xen-release-management.pandoc | 2 +- m4/stubdom.m4 | 5 ++-- scripts/get_maintainer.pl | 2 +- stubdom/configure | 33 ++++++--------------- stubdom/configure.ac | 18 +++++------ tools/firmware/etherboot/Makefile | 6 +--- 10 files changed, 35 insertions(+), 61 deletions(-) -- Sincerely, Demi Marie Obenour (she/her/hers) Invisible Things Lab
|
Lists.xenproject.org is hosted with RackSpace, monitoring our |