From nobody Sun Feb 8 19:59:08 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1677357503328362.00137895908153; Sat, 25 Feb 2023 12:38:23 -0800 (PST) Received: from list by lists.xenproject.org with outflank-mailman.501880.773717 (Exim 4.92) (envelope-from ) id 1pW1Iw-0000nL-Jh; Sat, 25 Feb 2023 20:38:02 +0000 Received: by outflank-mailman (output) from mailman id 501880.773717; Sat, 25 Feb 2023 20:38:02 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1pW1Iw-0000nA-Fw; Sat, 25 Feb 2023 20:38:02 +0000 Received: by outflank-mailman (input) for mailman id 501880; Sat, 25 Feb 2023 20:38:01 +0000 Received: from se1-gles-flk1-in.inumbo.com ([94.247.172.50] helo=se1-gles-flk1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1pW1Iv-0007yc-Kw for xen-devel@lists.xenproject.org; Sat, 25 Feb 2023 20:38:01 +0000 Received: from wout1-smtp.messagingengine.com (wout1-smtp.messagingengine.com [64.147.123.24]) by se1-gles-flk1.inumbo.com (Halon) with ESMTPS id 4a402e81-b54c-11ed-a82a-c9ca1d2f71af; Sat, 25 Feb 2023 21:37:59 +0100 (CET) Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by mailout.west.internal (Postfix) with ESMTP id 806CA320027A; Sat, 25 Feb 2023 15:37:57 -0500 (EST) Received: from mailfrontend1 ([10.202.2.162]) by compute5.internal (MEProxy); Sat, 25 Feb 2023 15:37:58 -0500 Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sat, 25 Feb 2023 15:37:56 -0500 (EST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: 4a402e81-b54c-11ed-a82a-c9ca1d2f71af DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= invisiblethingslab.com; h=cc:cc:content-transfer-encoding:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:sender:subject:subject:to:to; s=fm1; t= 1677357477; x=1677443877; bh=aeHQ0E9NgzibaZKiBNAkgq+kKk4grLArxug vf6LHwOg=; b=D6N1DVw74iEbjkNOvY2tQon8e7KjPb/cJNu/aVwlZ75ZCzkiLW0 2+94ASDCQZSRTD5JQcUX7H5YouCHLbFdqwct3iLrFezVQxcJSx1htoSFTadmszec KLU/gwAV3M0KZOa8QwuB6WEeplmPzpLUJ9/Sa+EZTv7bJ6RgjsR456KaB9wGTb+j hvWbcewzbLcwxs8K5F6JAwkXNPXhDmsI+jJkj243AjQ2x4/wHYRDUTK8KlviwJZB kW1z5mevFOuJSomWpXudNqjrl+oxNhJvvK/62jpchQRKKDPlUF4fgTq0eaY7zqVL Mjna/9HruhbeoyJ9rPmgRN4sgw2U0vtLLmg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:sender:subject :subject:to:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm1; t=1677357477; x=1677443877; bh=aeHQ0E9Ngziba ZKiBNAkgq+kKk4grLArxugvf6LHwOg=; b=m0jDBj19PfIQ6V2R7GErPlwkEJzi8 dpTq9O4poS7zCXRu9SFMWC5Fc2KrvID8OhrSMIB+7Z0nmQFgJuV1LHZzWkMr6Efv MJUY1LZhMYKOkHsmuelUSPeY2Yq4lAgGZHXwbjUHvkzV9BgD+UIqrb9KMvWe1/O7 4B9pzA+CvnCWzkjIOPUygFkqRuPfWTNmsTPbehNlkl4z7bQKywA8YYQtKRi835Mf NpidjeSZDhiIpecFBTpTTo+w3EyOmvcGacNMqzqq+wJilmRqEntQd614QTs0ksM6 FU5oppYRWjRSd68lKtpAvRN2SbORB3KTdAyFTe3nz035OAmSz76ayoJdA== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvhedrudekiedgjeeiucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhephffvvefufffkofgjfhgggfestdekredtredttdenucfhrhhomhepffgvmhhi ucforghrihgvucfqsggvnhhouhhruceouggvmhhisehinhhvihhsihgslhgvthhhihhngh hslhgrsgdrtghomheqnecuggftrfgrthhtvghrnhepteffheeiudduhefhffeigfegiedv leehhfdtvdduhffhudelkeefvdduueejkeevnecuffhomhgrihhnpehphihthhhonhdroh hrghdpihhnthgvlhdrtghomhdplhhlvhhmrdhorhhgpdguvggsihgrnhdrohhrghdprghl phhinhgvlhhinhhugidrohhrghenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmh epmhgrihhlfhhrohhmpeguvghmihesihhnvhhishhisghlvghthhhinhhgshhlrggsrdgt ohhm X-ME-Proxy: Feedback-ID: iac594737:Fastmail From: Demi Marie Obenour To: xen-devel@lists.xenproject.org Cc: Demi Marie Obenour , =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?= , Andrew Cooper , George Dunlap , Jan Beulich , Julien Grall , Stefano Stabellini , Wei Liu , Doug Goldstein Subject: [PATCH v5 5/5] Automation and CI: Replace git:// and http:// with https:// Date: Sat, 25 Feb 2023 15:37:15 -0500 Message-Id: <8ca85b30b903512fc07e95cf4e07ea4b0623ba99.1677356813.git.demi@invisiblethingslab.com> X-Mailer: git-send-email 2.39.2 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ZM-MESSAGEID: 1677357503834100003 Content-Type: text/plain; charset="utf-8" Obtaining code over an insecure transport is a terrible idea for blatently obvious reasons. Even for non-executable data, insecure transports are considered deprecated. This patch enforces the use of secure transports in automation and CI. All URLs are known to work. Signed-off-by: Demi Marie Obenour --- README | 4 ++-- automation/build/debian/stretch-llvm-8.list | 4 ++-- automation/scripts/qemu-smoke-dom0-arm32.sh | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/README b/README index 755b3d8eaf8f7a58a945b7594e68a3fe455a7bdf..f8cc426f78d690f37e013242e81= d4e440556c330 100644 --- a/README +++ b/README @@ -181,7 +181,7 @@ Python Runtime Libraries Various tools, such as pygrub, have the following runtime dependencies: =20 * Python 2.6 or later. - URL: http://www.python.org/ + URL: https://www.python.org/ Debian: python =20 Note that the build system expects `python` to be available. If your system @@ -197,7 +197,7 @@ Intel(R) Trusted Execution Technology Support Intel's technology for safer computing, Intel(R) Trusted Execution Technol= ogy (Intel(R) TXT), defines platform-level enhancements that provide the build= ing blocks for creating trusted platforms. For more information, see -http://www.intel.com/technology/security/. +https://www.intel.com/technology/security/. =20 Intel(R) TXT support is provided by the Trusted Boot (tboot) module in conjunction with minimal logic in the Xen hypervisor. diff --git a/automation/build/debian/stretch-llvm-8.list b/automation/build= /debian/stretch-llvm-8.list index 09fe843fb2a31ae38f752d7c8c71cf97f5b14513..590001ca81e826ab624ba918542= 3adf4b0c51a21 100644 --- a/automation/build/debian/stretch-llvm-8.list +++ b/automation/build/debian/stretch-llvm-8.list @@ -1,3 +1,3 @@ # Strech LLVM 8 repos -deb http://apt.llvm.org/stretch/ llvm-toolchain-stretch-8 main -deb-src http://apt.llvm.org/stretch/ llvm-toolchain-stretch-8 main +deb https://apt.llvm.org/stretch/ llvm-toolchain-stretch-8 main +deb-src https://apt.llvm.org/stretch/ llvm-toolchain-stretch-8 main diff --git a/automation/scripts/qemu-smoke-dom0-arm32.sh b/automation/scrip= ts/qemu-smoke-dom0-arm32.sh index 98e4d481f65c2b29ac935ddf6247132ddf94fa1d..950ad3a0daa63d66fc8647c0a39= 0ff59c2f22b1a 100755 --- a/automation/scripts/qemu-smoke-dom0-arm32.sh +++ b/automation/scripts/qemu-smoke-dom0-arm32.sh @@ -4,7 +4,7 @@ set -ex =20 cd binaries # Use the kernel from Debian -curl --fail --silent --show-error --location --output vmlinuz http://http.= us.debian.org/debian/dists/bullseye/main/installer-armhf/current/images/net= boot/vmlinuz +curl --fail --silent --show-error --location --output vmlinuz https://ftp.= debian.org/debian/dists/bullseye/main/installer-armhf/current/images/netboo= t/vmlinuz # Use a tiny initrd based on busybox from Alpine Linux curl --fail --silent --show-error --location --output initrd.tar.gz https:= //dl-cdn.alpinelinux.org/alpine/v3.15/releases/armhf/alpine-minirootfs-3.15= .1-armhf.tar.gz =20 --=20 Sincerely, Demi Marie Obenour (she/her/hers) Invisible Things Lab