From nobody Sun Feb 8 21:42:15 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1675889950146127.23838745717774; Wed, 8 Feb 2023 12:59:10 -0800 (PST) Received: from list by lists.xenproject.org with outflank-mailman.491994.761379 (Exim 4.92) (envelope-from ) id 1pPrWe-00080g-5h; Wed, 08 Feb 2023 20:58:44 +0000 Received: by outflank-mailman (output) from mailman id 491994.761379; Wed, 08 Feb 2023 20:58:44 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1pPrWe-00080Z-2m; Wed, 08 Feb 2023 20:58:44 +0000 Received: by outflank-mailman (input) for mailman id 491994; Wed, 08 Feb 2023 20:58:42 +0000 Received: from se1-gles-flk1-in.inumbo.com ([94.247.172.50] helo=se1-gles-flk1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1pPrWc-0007kX-Ko for xen-devel@lists.xenproject.org; Wed, 08 Feb 2023 20:58:42 +0000 Received: from out4-smtp.messagingengine.com (out4-smtp.messagingengine.com [66.111.4.28]) by se1-gles-flk1.inumbo.com (Halon) with ESMTPS id 5d433fe9-a7f3-11ed-93b5-47a8fe42b414; Wed, 08 Feb 2023 21:58:40 +0100 (CET) Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.nyi.internal (Postfix) with ESMTP id 0C1455C013E; Wed, 8 Feb 2023 15:58:40 -0500 (EST) Received: from mailfrontend2 ([10.202.2.163]) by compute4.internal (MEProxy); Wed, 08 Feb 2023 15:58:40 -0500 Received: by mail.messagingengine.com (Postfix) with ESMTPA; Wed, 8 Feb 2023 15:58:38 -0500 (EST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: 5d433fe9-a7f3-11ed-93b5-47a8fe42b414 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= invisiblethingslab.com; h=cc:cc:content-transfer-encoding:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:sender:subject:subject:to:to; s=fm3; t= 1675889920; x=1675976320; bh=YjlH9X1VyXgKgkGafsk0dvpHNT7Xq4V4f4f mb7TTmQY=; b=jaEcFfmHc3jC4mYccFTIPr09qO7jo80ZccMUmV7ONnH7Y13AcC1 J0mqLLxFgjaQ7taNYM/UqrQ1pUVcB5eGD1QXvpm75yZEyliVvM99ErUNaFdhkFCT GLBQEbceYawOVVStZOfeU7ZJVvRXToWHeouzAh7mpopV169AweJxZRa2PxXk8a+r jOAHpX4+aWWmrQau5OkCA/UANUQsGoVeCFZf7+t9JTXJliuJ2E3oOCSh1hSutPhf Fz6N7NArDclx7i2KcIuh+qYRACQUnHubGyBHWoq6g59kJF1gu5dOZngWMOz0VUoq p5NekZSxz0CXEWDMEFgB5CldR83ZC6dO0Rw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:sender:subject :subject:to:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm1; t=1675889920; x=1675976320; bh=YjlH9X1VyXgKg kGafsk0dvpHNT7Xq4V4f4fmb7TTmQY=; b=epZVL0unkdc7f5L0bOAadoCipddZY oDZp2lKBJaGzoNwWCywg+liuQqg1MZlPBLE+bWlQtPeCEFWoI3Oeba7XhrAiQXW6 hZcx6twW/Nxxs61YTlagFpQ7ACJCOdmL9Rb0GGQeT6c3Vgtws0gPh7YrO6bhorEd PxjLp5KN3fRSyjYQN8yZFgK0CMBp9XhnKf8bBGovIaFeWZsT8Y5Xtu1LKYLyMAUM N4Juxc6hTSY9ctAH+xX5tfjRebTilxhBzhRzexd/qX5rLBo+j58GbwWymSVfIARx ytuY6eQ9CtziUqaT1vK5wff7YAP0b6vgw6hAH2ofBr3bZ6FfTtworH71A== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvhedrudehuddgkedtucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhephffvvefufffkofgjfhgggfestdekredtredttdenucfhrhhomhepffgvmhhi ucforghrihgvucfqsggvnhhouhhruceouggvmhhisehinhhvihhsihgslhgvthhhihhngh hslhgrsgdrtghomheqnecuggftrfgrthhtvghrnhepteduueehgeeujeegudeiffffveel teeljeevudeileffieetgfegffeitedvkeeunecuffhomhgrihhnpehphihthhhonhdroh hrghdpihhnthgvlhdrtghomhdptggvnhhtohhsrdhorhhgpdhllhhvmhdrohhrghdpuggv sghirghnrdhorhhgpdgrlhhpihhnvghlihhnuhigrdhorhhgnecuvehluhhsthgvrhfuih iivgeptdenucfrrghrrghmpehmrghilhhfrhhomhepuggvmhhisehinhhvihhsihgslhgv thhhihhnghhslhgrsgdrtghomh X-ME-Proxy: Feedback-ID: iac594737:Fastmail From: Demi Marie Obenour To: xen-devel@lists.xenproject.org Cc: Demi Marie Obenour , Andrew Cooper , George Dunlap , Jan Beulich , Julien Grall , Stefano Stabellini , Wei Liu , Doug Goldstein Subject: [PATCH v2 2/4] Automation and CI: Replace git:// and http:// with https:// Date: Wed, 8 Feb 2023 15:58:22 -0500 Message-Id: <8a3d0ce9747e486e91ad5b47777c80293e0fd168.1675889602.git.demi@invisiblethingslab.com> X-Mailer: git-send-email 2.39.1 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ZM-MESSAGEID: 1675889952555100001 Content-Type: text/plain; charset="utf-8" Obtaining code over an insecure transport is a terrible idea for blatently obvious reasons. Even for non-executable data, insecure transports are considered deprecated. This patch enforces the use of secure transports in automation and CI. Signed-off-by: Demi Marie Obenour --- README | 4 ++-- automation/build/centos/CentOS-7.2.repo | 8 ++++---- automation/build/debian/stretch-llvm-8.list | 4 ++-- automation/build/debian/unstable-llvm-8.list | 4 ++-- automation/scripts/qemu-smoke-dom0-arm32.sh | 2 +- 5 files changed, 11 insertions(+), 11 deletions(-) diff --git a/README b/README index 755b3d8eaf8f7a58a945b7594e68a3fe455a7bdf..f8cc426f78d690f37e013242e81= d4e440556c330 100644 --- a/README +++ b/README @@ -181,7 +181,7 @@ Python Runtime Libraries Various tools, such as pygrub, have the following runtime dependencies: =20 * Python 2.6 or later. - URL: http://www.python.org/ + URL: https://www.python.org/ Debian: python =20 Note that the build system expects `python` to be available. If your system @@ -197,7 +197,7 @@ Intel(R) Trusted Execution Technology Support Intel's technology for safer computing, Intel(R) Trusted Execution Technol= ogy (Intel(R) TXT), defines platform-level enhancements that provide the build= ing blocks for creating trusted platforms. For more information, see -http://www.intel.com/technology/security/. +https://www.intel.com/technology/security/. =20 Intel(R) TXT support is provided by the Trusted Boot (tboot) module in conjunction with minimal logic in the Xen hypervisor. diff --git a/automation/build/centos/CentOS-7.2.repo b/automation/build/cen= tos/CentOS-7.2.repo index 4da27faeb5fa863fd4e140cbeaad308b9a543b86..8e37da1a03f839c486eb9bd0af4= 6716cfb9086e0 100644 --- a/automation/build/centos/CentOS-7.2.repo +++ b/automation/build/centos/CentOS-7.2.repo @@ -6,28 +6,28 @@ =20 [base] name=3DCentOS-7.2.1511 - Base -baseurl=3Dhttp://vault.centos.org/7.2.1511/os/$basearch/ +baseurl=3Dhttps://vault.centos.org/7.2.1511/os/$basearch/ gpgcheck=3D1 gpgkey=3Dfile:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-7 =20 #released updates=20 [updates] name=3DCentOS-7.2.1511 - Updates -baseurl=3Dhttp://vault.centos.org/7.2.1511/updates/$basearch/ +baseurl=3Dhttps://vault.centos.org/7.2.1511/updates/$basearch/ gpgcheck=3D1 gpgkey=3Dfile:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-7 =20 #additional packages that may be useful [extras] name=3DCentOS-7.2.1511 - Extras -baseurl=3Dhttp://vault.centos.org/7.2.1511/extras/$basearch/ +baseurl=3Dhttps://vault.centos.org/7.2.1511/extras/$basearch/ gpgcheck=3D1 gpgkey=3Dfile:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-7 =20 #additional packages that extend functionality of existing packages [centosplus] name=3DCentOS-7.2.1511 - Plus -baseurl=3Dhttp://vault.centos.org/7.2.1511/centosplus/$basearch/ +baseurl=3Dhttps://vault.centos.org/7.2.1511/centosplus/$basearch/ gpgcheck=3D1 gpgcheck=3D1 enabled=3D0 diff --git a/automation/build/debian/stretch-llvm-8.list b/automation/build= /debian/stretch-llvm-8.list index 09fe843fb2a31ae38f752d7c8c71cf97f5b14513..590001ca81e826ab624ba918542= 3adf4b0c51a21 100644 --- a/automation/build/debian/stretch-llvm-8.list +++ b/automation/build/debian/stretch-llvm-8.list @@ -1,3 +1,3 @@ # Strech LLVM 8 repos -deb http://apt.llvm.org/stretch/ llvm-toolchain-stretch-8 main -deb-src http://apt.llvm.org/stretch/ llvm-toolchain-stretch-8 main +deb https://apt.llvm.org/stretch/ llvm-toolchain-stretch-8 main +deb-src https://apt.llvm.org/stretch/ llvm-toolchain-stretch-8 main diff --git a/automation/build/debian/unstable-llvm-8.list b/automation/buil= d/debian/unstable-llvm-8.list index dc119fa0b4df1bd6e742c42776710abcd6deaa86..1db1598997429d7a14d3fcd8f0f= 8152aa6d40b8a 100644 --- a/automation/build/debian/unstable-llvm-8.list +++ b/automation/build/debian/unstable-llvm-8.list @@ -1,3 +1,3 @@ # Unstable LLVM 8 repos -deb http://apt.llvm.org/unstable/ llvm-toolchain-8 main -deb-src http://apt.llvm.org/unstable/ llvm-toolchain-8 main +deb https://apt.llvm.org/unstable/ llvm-toolchain-8 main +deb-src https://apt.llvm.org/unstable/ llvm-toolchain-8 main diff --git a/automation/scripts/qemu-smoke-dom0-arm32.sh b/automation/scrip= ts/qemu-smoke-dom0-arm32.sh index 98e4d481f65c2b29ac935ddf6247132ddf94fa1d..6163eeeda623527d0620fb20a23= b589b1168a896 100755 --- a/automation/scripts/qemu-smoke-dom0-arm32.sh +++ b/automation/scripts/qemu-smoke-dom0-arm32.sh @@ -4,7 +4,7 @@ set -ex =20 cd binaries # Use the kernel from Debian -curl --fail --silent --show-error --location --output vmlinuz http://http.= us.debian.org/debian/dists/bullseye/main/installer-armhf/current/images/net= boot/vmlinuz +curl --fail --silent --show-error --location --output vmlinuz https://deb.= debian.org/debian/dists/bullseye/main/installer-armhf/current/images/netboo= t/vmlinuz # Use a tiny initrd based on busybox from Alpine Linux curl --fail --silent --show-error --location --output initrd.tar.gz https:= //dl-cdn.alpinelinux.org/alpine/v3.15/releases/armhf/alpine-minirootfs-3.15= .1-armhf.tar.gz =20 --=20 Sincerely, Demi Marie Obenour (she/her/hers) Invisible Things Lab