Commit Graph

15 Commits

Author SHA1 Message Date
Daniel P. Berrangé
7ec194d0a3 Fix pccs npm security flaws
Sync patches from Fedora 43, to fix multiple pccs npm security flaws,
and fix typo in pccsadmin help text.

CVE-2026-23745, CVE-2026-23950, CVE-2026-24842, CVE-2025-13465, CVE-2025-15284

Resolves: RHEL-142527, RHEL-145054, RHEL-144307, RHEL-138123, RHEL-140109
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2026-02-05 09:41:34 +00:00
Daniel P. Berrangé
109f4bc2ff Port to pycryptography and pyasn1 and make keyring optional
pyOpenSSL 24.0.0 removed several APIs required by pccsadmin, so
porting to pycryptography is required on Fedora. Since RHEL does
not ship pyOpenSSL, the port is useful here too.

Using pyasn1 instead of asn1 gives stronger validation during
parsing and brings compatibility with RHEL that lacks python3-asn1

The keyring package needs to be optional on RHEL which lacks this
module (currently).

Also drop the inappropriate pccs port number change

Related: https://issues.redhat.com/browse/RHEL-127046
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-12-10 11:22:41 +00:00
Daniel P. Berrangé
6b585471aa Sync specfile changes from Fedora
Related: https://issues.redhat.com/browse/RHEL-127046
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-12-10 11:22:39 +00:00
Daniel P. Berrangé
434648245a Drop sgx-mpa dep from sgx-pccs
While pccs can be run node-local, a typical deployment would
have pccs on the LAN to cache certs across many hosts. As
such a dep on sgx-mpa is inappropriate, and tdx-qgs already
has a weak dep for this.

Related: https://issues.redhat.com/browse/RHEL-127046
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-12-10 11:22:37 +00:00
Daniel P. Berrangé
e7e1e7c4ec Add scriptlets for PCCS
Related: https://issues.redhat.com/browse/RHEL-127046
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-12-10 11:22:35 +00:00
Daniel P. Berrangé
ed4ba1f539 Enable pccsadmin everywhere
Since pccs was reintroduced the pccsadmin tool is now relevant on
both RHEL and Fedora

Related: https://issues.redhat.com/browse/RHEL-127046
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-12-10 11:22:20 +00:00
Daniel P. Berrangé
2c1f338978 Update to SGX 2.26 / DCAP 1.23, adding PCCS service
Resolves: https://issues.redhat.com/browse/RHEL-127046
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-11-18 18:31:07 +00:00
Daniel P. Berrangé
09fb06843c Trigger udev to set perms on /dev/sgx_provision
This ensures that if qgs is started, without a reboot after install,
it will have permissions to access /dev/sgx_provision

Resolves: https://issues.redhat.com/browse/RHEL-129059
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-11-17 16:35:37 +00:00
Daniel P. Berrangé
c568ed9156 Temporarily disable automatic tier1 gating
QE is not ready to do automatic gating testing of TDX functionality
at this time, and once ready, will require a difference test suite
name to be used.

Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-06-16 13:51:23 +01:00
Daniel P. Berrangé
d050136e53 Adapt qgs.service for SELinux policy and sock perms
Changes to qgs.service to make it more amenable to writing a strict
SELinux policy.

Also add patch to allow control over socket perms so QEMU can get
access to the socket.

Related: https://issues.redhat.com/browse/RHELPLAN-171791
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-06-09 13:57:03 +01:00
Daniel P. Berrangé
ca443f650f Honour CFLAGS/CXXFLAGS/LDFLAGS for host software
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-04-16 16:50:30 +01:00
Daniel P. Berrangé
c71163ae01 Fix paths to binaries in service files
RHEL-9 does not have the bin+sbin merge that Fedora recently did.

Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-04-01 10:28:00 +01:00
Daniel P. Berrangé
9d8460aaa1 Add basic gating config
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-03-19 17:11:38 +00:00
Daniel P. Berrangé
a8cda4b77a Initial import
Resolves: https://issues.redhat.com/browse/RHELPLAN-171791
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-03-19 17:09:18 +00:00
Release Configuration Management
4f191b98b6 New branch setup 2025-03-19 05:24:57 -04:00