From nobody Mon Feb 9 06:33:11 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1675831928444584.5496295303666; Tue, 7 Feb 2023 20:52:08 -0800 (PST) Received: from list by lists.xenproject.org with outflank-mailman.491523.760703 (Exim 4.92) (envelope-from ) id 1pPcQb-0005fQ-AR; Wed, 08 Feb 2023 04:51:29 +0000 Received: by outflank-mailman (output) from mailman id 491523.760703; Wed, 08 Feb 2023 04:51:29 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1pPcQb-0005dU-73; Wed, 08 Feb 2023 04:51:29 +0000 Received: by outflank-mailman (input) for mailman id 491523; Wed, 08 Feb 2023 04:51:27 +0000 Received: from se1-gles-sth1-in.inumbo.com ([159.253.27.254] helo=se1-gles-sth1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1pPcQZ-0005Mi-EL for xen-devel@lists.xenproject.org; Wed, 08 Feb 2023 04:51:27 +0000 Received: from out1-smtp.messagingengine.com (out1-smtp.messagingengine.com [66.111.4.25]) by se1-gles-sth1.inumbo.com (Halon) with ESMTPS id 3d28f1e8-a76c-11ed-933c-83870f6b2ba8; Wed, 08 Feb 2023 05:51:26 +0100 (CET) Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.nyi.internal (Postfix) with ESMTP id 180585C0096; Tue, 7 Feb 2023 23:51:24 -0500 (EST) Received: from mailfrontend1 ([10.202.2.162]) by compute3.internal (MEProxy); Tue, 07 Feb 2023 23:51:24 -0500 Received: by mail.messagingengine.com (Postfix) with ESMTPA; Tue, 7 Feb 2023 23:51:23 -0500 (EST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: 3d28f1e8-a76c-11ed-933c-83870f6b2ba8 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= invisiblethingslab.com; h=cc:cc:content-transfer-encoding:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:sender:subject:subject:to:to; s=fm3; t= 1675831884; x=1675918284; bh=YjlH9X1VyXgKgkGafsk0dvpHNT7Xq4V4f4f mb7TTmQY=; b=gKUzfZSMSCQtZOKag+iELqMmfZhsasxn73CsNjmkRH/iAn1Km8p Ts+Wm430rpzCnxzHsnTbkUUNRzQIEojLTrU7QCHQbSeACTs7/CvdbwFvRpRU9NJA D8NcUZLi/NeTf3wnEBInAilwUWMwGlPWHdCJhu6yThfks2/GMHnH3R2u3Y7D8AeY CAfOj/dyqv4nV+p9Scl0foniYDo7xc4uAcbaloR/AA5r6u9ivMx9gWKVptz57237 zqMS+Ib5PX961CR0xKvaOHm0kh5NhtXazpzIv8wDNB9XREYzBFxKakac9yG73cs2 g27/lbHnF70UosycHRZcoyP88aIoZbJOcSQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:sender:subject :subject:to:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm3; t=1675831884; x=1675918284; bh=YjlH9X1VyXgKg kGafsk0dvpHNT7Xq4V4f4fmb7TTmQY=; b=NMx4qk795RswMLjEiZLoBJkeUZfXp ahQC2we/9mUlVcWQrNl09IsgrAaefnPn7CGkLscbmDr7BGUPAEWr0U/lue2bSTx9 YIOD/AkSWia8G0klz+P1E0pXguZuuLJWAYiCEDsYmck0REJYzdtgmaF1b17ODx4q nZnl0nc955b314uQT0H37vMDTlQBtSkOqdcPH+etWhqVmKu4Lb5oURE9b0oEvJcL xXUoLy18/VV7g9nbxye5xQ8J4meMYynYcjoKSu1qcQVRIAUDQ1tCFUsYV6a4vudU 8CVew9fBB350c2pnyna+enY0eu9oCA7RnI08nPvANf3AqEWolagXxKAAQ== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvhedrudegledgjeegucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhephffvvefufffkofgjfhgggfestdekredtredttdenucfhrhhomhepffgvmhhi ucforghrihgvucfqsggvnhhouhhruceouggvmhhisehinhhvihhsihgslhgvthhhihhngh hslhgrsgdrtghomheqnecuggftrfgrthhtvghrnhepteduueehgeeujeegudeiffffveel teeljeevudeileffieetgfegffeitedvkeeunecuffhomhgrihhnpehphihthhhonhdroh hrghdpihhnthgvlhdrtghomhdptggvnhhtohhsrdhorhhgpdhllhhvmhdrohhrghdpuggv sghirghnrdhorhhgpdgrlhhpihhnvghlihhnuhigrdhorhhgnecuvehluhhsthgvrhfuih iivgeptdenucfrrghrrghmpehmrghilhhfrhhomhepuggvmhhisehinhhvihhsihgslhgv thhhihhnghhslhgrsgdrtghomh X-ME-Proxy: Feedback-ID: iac594737:Fastmail From: Demi Marie Obenour To: xen-devel@lists.xenproject.org Cc: Demi Marie Obenour , Andrew Cooper , George Dunlap , Jan Beulich , Julien Grall , Stefano Stabellini , Wei Liu , Doug Goldstein Subject: [PATCH 2/4] Automation and CI: Replace git:// and http:// with https:// Date: Tue, 7 Feb 2023 23:51:05 -0500 Message-Id: <4dcc09d2621f5ae319e9a01895287bacbc4d6c86.1675829867.git.demi@invisiblethingslab.com> X-Mailer: git-send-email 2.39.1 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ZM-MESSAGEID: 1675831930786100001 Content-Type: text/plain; charset="utf-8" Obtaining code over an insecure transport is a terrible idea for blatently obvious reasons. Even for non-executable data, insecure transports are considered deprecated. This patch enforces the use of secure transports in automation and CI. Signed-off-by: Demi Marie Obenour --- README | 4 ++-- automation/build/centos/CentOS-7.2.repo | 8 ++++---- automation/build/debian/stretch-llvm-8.list | 4 ++-- automation/build/debian/unstable-llvm-8.list | 4 ++-- automation/scripts/qemu-smoke-dom0-arm32.sh | 2 +- 5 files changed, 11 insertions(+), 11 deletions(-) diff --git a/README b/README index 755b3d8eaf8f7a58a945b7594e68a3fe455a7bdf..f8cc426f78d690f37e013242e81= d4e440556c330 100644 --- a/README +++ b/README @@ -181,7 +181,7 @@ Python Runtime Libraries Various tools, such as pygrub, have the following runtime dependencies: =20 * Python 2.6 or later. - URL: http://www.python.org/ + URL: https://www.python.org/ Debian: python =20 Note that the build system expects `python` to be available. If your system @@ -197,7 +197,7 @@ Intel(R) Trusted Execution Technology Support Intel's technology for safer computing, Intel(R) Trusted Execution Technol= ogy (Intel(R) TXT), defines platform-level enhancements that provide the build= ing blocks for creating trusted platforms. For more information, see -http://www.intel.com/technology/security/. +https://www.intel.com/technology/security/. =20 Intel(R) TXT support is provided by the Trusted Boot (tboot) module in conjunction with minimal logic in the Xen hypervisor. diff --git a/automation/build/centos/CentOS-7.2.repo b/automation/build/cen= tos/CentOS-7.2.repo index 4da27faeb5fa863fd4e140cbeaad308b9a543b86..8e37da1a03f839c486eb9bd0af4= 6716cfb9086e0 100644 --- a/automation/build/centos/CentOS-7.2.repo +++ b/automation/build/centos/CentOS-7.2.repo @@ -6,28 +6,28 @@ =20 [base] name=3DCentOS-7.2.1511 - Base -baseurl=3Dhttp://vault.centos.org/7.2.1511/os/$basearch/ +baseurl=3Dhttps://vault.centos.org/7.2.1511/os/$basearch/ gpgcheck=3D1 gpgkey=3Dfile:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-7 =20 #released updates=20 [updates] name=3DCentOS-7.2.1511 - Updates -baseurl=3Dhttp://vault.centos.org/7.2.1511/updates/$basearch/ +baseurl=3Dhttps://vault.centos.org/7.2.1511/updates/$basearch/ gpgcheck=3D1 gpgkey=3Dfile:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-7 =20 #additional packages that may be useful [extras] name=3DCentOS-7.2.1511 - Extras -baseurl=3Dhttp://vault.centos.org/7.2.1511/extras/$basearch/ +baseurl=3Dhttps://vault.centos.org/7.2.1511/extras/$basearch/ gpgcheck=3D1 gpgkey=3Dfile:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-7 =20 #additional packages that extend functionality of existing packages [centosplus] name=3DCentOS-7.2.1511 - Plus -baseurl=3Dhttp://vault.centos.org/7.2.1511/centosplus/$basearch/ +baseurl=3Dhttps://vault.centos.org/7.2.1511/centosplus/$basearch/ gpgcheck=3D1 gpgcheck=3D1 enabled=3D0 diff --git a/automation/build/debian/stretch-llvm-8.list b/automation/build= /debian/stretch-llvm-8.list index 09fe843fb2a31ae38f752d7c8c71cf97f5b14513..590001ca81e826ab624ba918542= 3adf4b0c51a21 100644 --- a/automation/build/debian/stretch-llvm-8.list +++ b/automation/build/debian/stretch-llvm-8.list @@ -1,3 +1,3 @@ # Strech LLVM 8 repos -deb http://apt.llvm.org/stretch/ llvm-toolchain-stretch-8 main -deb-src http://apt.llvm.org/stretch/ llvm-toolchain-stretch-8 main +deb https://apt.llvm.org/stretch/ llvm-toolchain-stretch-8 main +deb-src https://apt.llvm.org/stretch/ llvm-toolchain-stretch-8 main diff --git a/automation/build/debian/unstable-llvm-8.list b/automation/buil= d/debian/unstable-llvm-8.list index dc119fa0b4df1bd6e742c42776710abcd6deaa86..1db1598997429d7a14d3fcd8f0f= 8152aa6d40b8a 100644 --- a/automation/build/debian/unstable-llvm-8.list +++ b/automation/build/debian/unstable-llvm-8.list @@ -1,3 +1,3 @@ # Unstable LLVM 8 repos -deb http://apt.llvm.org/unstable/ llvm-toolchain-8 main -deb-src http://apt.llvm.org/unstable/ llvm-toolchain-8 main +deb https://apt.llvm.org/unstable/ llvm-toolchain-8 main +deb-src https://apt.llvm.org/unstable/ llvm-toolchain-8 main diff --git a/automation/scripts/qemu-smoke-dom0-arm32.sh b/automation/scrip= ts/qemu-smoke-dom0-arm32.sh index 98e4d481f65c2b29ac935ddf6247132ddf94fa1d..6163eeeda623527d0620fb20a23= b589b1168a896 100755 --- a/automation/scripts/qemu-smoke-dom0-arm32.sh +++ b/automation/scripts/qemu-smoke-dom0-arm32.sh @@ -4,7 +4,7 @@ set -ex =20 cd binaries # Use the kernel from Debian -curl --fail --silent --show-error --location --output vmlinuz http://http.= us.debian.org/debian/dists/bullseye/main/installer-armhf/current/images/net= boot/vmlinuz +curl --fail --silent --show-error --location --output vmlinuz https://deb.= debian.org/debian/dists/bullseye/main/installer-armhf/current/images/netboo= t/vmlinuz # Use a tiny initrd based on busybox from Alpine Linux curl --fail --silent --show-error --location --output initrd.tar.gz https:= //dl-cdn.alpinelinux.org/alpine/v3.15/releases/armhf/alpine-minirootfs-3.15= .1-armhf.tar.gz =20 --=20 Sincerely, Demi Marie Obenour (she/her/hers) Invisible Things Lab