From nobody Mon Feb 9 14:00:49 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1677357500280382.21257441617786; Sat, 25 Feb 2023 12:38:20 -0800 (PST) Received: from list by lists.xenproject.org with outflank-mailman.501874.773706 (Exim 4.92) (envelope-from ) id 1pW1Is-0000LY-6r; Sat, 25 Feb 2023 20:37:58 +0000 Received: by outflank-mailman (output) from mailman id 501874.773706; Sat, 25 Feb 2023 20:37:58 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1pW1Is-0000LP-3a; Sat, 25 Feb 2023 20:37:58 +0000 Received: by outflank-mailman (input) for mailman id 501874; Sat, 25 Feb 2023 20:37:56 +0000 Received: from se1-gles-flk1-in.inumbo.com ([94.247.172.50] helo=se1-gles-flk1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1pW1Iq-0007yc-Ov for xen-devel@lists.xenproject.org; Sat, 25 Feb 2023 20:37:56 +0000 Received: from wout1-smtp.messagingengine.com (wout1-smtp.messagingengine.com [64.147.123.24]) by se1-gles-flk1.inumbo.com (Halon) with ESMTPS id 4778e5b4-b54c-11ed-a82a-c9ca1d2f71af; Sat, 25 Feb 2023 21:37:55 +0100 (CET) Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailout.west.internal (Postfix) with ESMTP id 1F2353200201; Sat, 25 Feb 2023 15:37:53 -0500 (EST) Received: from mailfrontend1 ([10.202.2.162]) by compute3.internal (MEProxy); Sat, 25 Feb 2023 15:37:53 -0500 Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sat, 25 Feb 2023 15:37:52 -0500 (EST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: 4778e5b4-b54c-11ed-a82a-c9ca1d2f71af DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= invisiblethingslab.com; h=cc:cc:content-transfer-encoding:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:sender:subject:subject:to:to; s=fm1; t= 1677357472; x=1677443872; bh=eE9rMkFJ8SK3XCHPmE4xntol477kdYevv8F tOH7Fe3I=; b=lyoz5gWVWeiiUc9rXtuLY6HQZk+S71tzEU5vht4aAPID/MtcUjh ni2VxOvFbRVXFE13LTvx7BF8M3DpvI+aPJs17J0yZu3JcInyKUgf/V5WMnrJOOJb ljMxH66EqTZtD9o6GDyr9fQRdspuh2b/tz7SaUeJUHgkClYETBCtIvj7Fqvu/Cbc F9XYESLX9cppZWSb34IHJqy1Tq0JmFkIlrX4q7yZXthZtfKODOljpRDcfZ+SCHzO lphOtzVYaS+Hpbzp2x+jL9g01kAtdbsnjjtpFwaYPmkMJNXpgQ0kqAw5lM3qZxUo xLDgx8qXDlkQs1Ur4I2Cr6J/mtqSsumAIDg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:sender:subject :subject:to:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm1; t=1677357472; x=1677443872; bh=eE9rMkFJ8SK3X CHPmE4xntol477kdYevv8FtOH7Fe3I=; b=a5d9p7LzmKi+Oo2B82T/0f6CIyjC5 Lt08s1uRrJjJTbF/qoE/MKcIHiCoL8tcAwwpPfQcceLzUj8a+OzoaQaJdLUuWJ3B jLQ2lSgqAseUDQlCeFg8cd0gQOzaGLZMKeWXOdj5I7ZbgGI7Lbx8ntkss6XYSLHP esAPLQZifeLXlLvRe+HY6e/CxqpQQ3jzmd2EnJrELeTDM8xR/Isxr0KypiSQKQzC 2+0HVNiB3905fg+oDf4DIP3hkSPPBZjIwWbAKSEVihmIaHSgn/jLLrINZFNGJD1a Km4W/rzrw8Xoj6CvarMxdtP3aAF9sYIrwbc+xh5a2k0TAMp+CvJrw9z0w== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvhedrudekiedgjeeiucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhephffvvefufffkofgjfhgggfestdekredtredttdenucfhrhhomhepffgvmhhi ucforghrihgvucfqsggvnhhouhhruceouggvmhhisehinhhvihhsihgslhgvthhhihhngh hslhgrsgdrtghomheqnecuggftrfgrthhtvghrnhepuedtueeutedtfefgkedtueefteeu ffdvuedtudekkedvhffgfffhheefgeeutdejnecuffhomhgrihhnpehkvghrnhgvlhdroh hrghdprhgvughhrghtrdgtohhmpdhsohhurhgtvgifrghrvgdrohhrghdpghhnuhdrohhr ghdpihhnrhhirgdrfhhrpdhgmhhplhhisgdrohhrghdpihhpgigvrdhorhhgpdhgihhthh husgdrtghomhenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfhhr ohhmpeguvghmihesihhnvhhishhisghlvghthhhinhhgshhlrggsrdgtohhm X-ME-Proxy: Feedback-ID: iac594737:Fastmail From: Demi Marie Obenour To: xen-devel@lists.xenproject.org Cc: Demi Marie Obenour , =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?= , Samuel Thibault , Wei Liu , Anthony PERARD Subject: [PATCH v5 4/5] Build system: Replace git:// and http:// with https:// Date: Sat, 25 Feb 2023 15:37:14 -0500 Message-Id: <85a65c8c5cbd7cab3b9eb57aed27a59443c7a6ff.1677356813.git.demi@invisiblethingslab.com> X-Mailer: git-send-email 2.39.2 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ZM-MESSAGEID: 1677357501830100001 Content-Type: text/plain; charset="utf-8" Obtaining code over an insecure transport is a terrible idea for blatently obvious reasons. Even for non-executable data, insecure transports are considered deprecated. This patch enforces the use of secure transports in the build system. Some URLs returned 301 or 302 redirects, so I replaced them with the URLs that were redirected to. Signed-off-by: Demi Marie Obenour --- stubdom/configure | 12 ++++++------ stubdom/configure.ac | 12 ++++++------ tools/firmware/etherboot/Makefile | 6 +----- 3 files changed, 13 insertions(+), 17 deletions(-) diff --git a/stubdom/configure b/stubdom/configure index 4ea95baa9192f3b319349ac2a14a3055a21ce705..540e9cd331888449b0e24c1aa97= 4bc22c5bcab54 100755 --- a/stubdom/configure +++ b/stubdom/configure @@ -3545,7 +3545,7 @@ if test "x$LIBPCI_URL" =3D "x"; then : if test "x$extfiles" =3D "xy"; then : LIBPCI_URL=3D\$\(XEN_EXTFILES_URL\) else - LIBPCI_URL=3D"http://www.kernel.org/pub/software/utils/pciutils" + LIBPCI_URL=3D"https://mirrors.edge.kernel.org/pub/software/utils/pciutil= s" fi =20 fi @@ -3560,7 +3560,7 @@ if test "x$NEWLIB_URL" =3D "x"; then : if test "x$extfiles" =3D "xy"; then : NEWLIB_URL=3D\$\(XEN_EXTFILES_URL\) else - NEWLIB_URL=3D"ftp://sources.redhat.com/pub/newlib" + NEWLIB_URL=3D"https://sourceware.org/ftp/newlib" fi =20 fi @@ -3575,7 +3575,7 @@ if test "x$LWIP_URL" =3D "x"; then : if test "x$extfiles" =3D "xy"; then : LWIP_URL=3D\$\(XEN_EXTFILES_URL\) else - LWIP_URL=3D"http://download.savannah.gnu.org/releases/lwip" + LWIP_URL=3D"https://download.savannah.gnu.org/releases/lwip" fi =20 fi @@ -3590,7 +3590,7 @@ if test "x$GRUB_URL" =3D "x"; then : if test "x$extfiles" =3D "xy"; then : GRUB_URL=3D\$\(XEN_EXTFILES_URL\) else - GRUB_URL=3D"http://alpha.gnu.org/gnu/grub" + GRUB_URL=3D"https://alpha.gnu.org/gnu/grub" fi =20 fi @@ -3602,7 +3602,7 @@ GRUB_VERSION=3D"0.97" =20 if test "x$OCAML_URL" =3D "x"; then : =20 - OCAML_URL=3D"http://caml.inria.fr/pub/distrib/ocaml-4.02" + OCAML_URL=3D"https://caml.inria.fr/pub/distrib/ocaml-4.02" =20 fi OCAML_VERSION=3D"4.02.0" @@ -3616,7 +3616,7 @@ if test "x$GMP_URL" =3D "x"; then : if test "x$extfiles" =3D "xy"; then : GMP_URL=3D\$\(XEN_EXTFILES_URL\) else - GMP_URL=3D"ftp://ftp.gmplib.org/pub/gmp-4.3.2" + GMP_URL=3D"https://gmplib.org/download/gmp/archive" fi =20 fi diff --git a/stubdom/configure.ac b/stubdom/configure.ac index c648b1602c227ed5fe63b9fbdf3fa52fd2e1654b..471e371e14a82aedc10314c95bc= af39ce9f89f90 100644 --- a/stubdom/configure.ac +++ b/stubdom/configure.ac @@ -56,12 +56,12 @@ AX_DEPENDS_PATH_PROG([vtpm], [CMAKE], [cmake]) =20 # Stubdom libraries version and url setup AX_STUBDOM_LIB([ZLIB], [zlib], [1.2.3]) -AX_STUBDOM_LIB([LIBPCI], [libpci], [2.2.9], [http://www.kernel.org/pub/sof= tware/utils/pciutils]) -AX_STUBDOM_LIB([NEWLIB], [newlib], [1.16.0], [ftp://sources.redhat.com/pub= /newlib]) -AX_STUBDOM_LIB([LWIP], [lwip], [1.3.0], [http://download.savannah.gnu.org/= releases/lwip]) -AX_STUBDOM_LIB([GRUB], [grub], [0.97], [http://alpha.gnu.org/gnu/grub]) -AX_STUBDOM_LIB_NOEXT([OCAML], [ocaml], [4.02.0], [http://caml.inria.fr/pub= /distrib/ocaml-4.02]) -AX_STUBDOM_LIB([GMP], [libgmp], [4.3.2], [ftp://ftp.gmplib.org/pub/gmp-4.3= .2]) +AX_STUBDOM_LIB([LIBPCI], [libpci], [2.2.9], [https://mirrors.edge.kernel.o= rg/pub/software/utils/pciutils]) +AX_STUBDOM_LIB([NEWLIB], [newlib], [1.16.0], [https://sourceware.org/ftp/n= ewlib]) +AX_STUBDOM_LIB([LWIP], [lwip], [1.3.0], [https://download.savannah.gnu.org= /releases/lwip]) +AX_STUBDOM_LIB([GRUB], [grub], [0.97], [https://alpha.gnu.org/gnu/grub]) +AX_STUBDOM_LIB_NOEXT([OCAML], [ocaml], [4.02.0], [https://caml.inria.fr/pu= b/distrib/ocaml-4.02]) +AX_STUBDOM_LIB([GMP], [libgmp], [4.3.2], [https://gmplib.org/download/gmp/= archive]) AX_STUBDOM_LIB([POLARSSL], [polarssl], [1.1.4]) AX_STUBDOM_LIB([TPMEMU], [berlios tpm emulator], [0.7.4]) =20 diff --git a/tools/firmware/etherboot/Makefile b/tools/firmware/etherboot/M= akefile index 4bc3633ba3d67ff9f52a9cb7923afea73c861da9..6ab9e5bc6b4cc750f2e802128fb= c71e9150397b1 100644 --- a/tools/firmware/etherboot/Makefile +++ b/tools/firmware/etherboot/Makefile @@ -4,11 +4,7 @@ XEN_ROOT =3D $(CURDIR)/../../.. include $(XEN_ROOT)/tools/Rules.mk include Config =20 -ifeq ($(GIT_HTTP),y) -IPXE_GIT_URL ?=3D http://git.ipxe.org/ipxe.git -else -IPXE_GIT_URL ?=3D git://git.ipxe.org/ipxe.git -endif +IPXE_GIT_URL ?=3D https://github.com/ipxe/ipxe.git =20 # put an updated tar.gz on xenbits after changes to this variable IPXE_GIT_TAG :=3D 3c040ad387099483102708bb1839110bc788cefb --=20 Sincerely, Demi Marie Obenour (she/her/hers) Invisible Things Lab