Commit Graph

6 Commits

Author SHA1 Message Date
Daniel P. Berrangé
7ec194d0a3 Fix pccs npm security flaws
Sync patches from Fedora 43, to fix multiple pccs npm security flaws,
and fix typo in pccsadmin help text.

CVE-2026-23745, CVE-2026-23950, CVE-2026-24842, CVE-2025-13465, CVE-2025-15284

Resolves: RHEL-142527, RHEL-145054, RHEL-144307, RHEL-138123, RHEL-140109
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2026-02-05 09:41:34 +00:00
Daniel P. Berrangé
109f4bc2ff Port to pycryptography and pyasn1 and make keyring optional
pyOpenSSL 24.0.0 removed several APIs required by pccsadmin, so
porting to pycryptography is required on Fedora. Since RHEL does
not ship pyOpenSSL, the port is useful here too.

Using pyasn1 instead of asn1 gives stronger validation during
parsing and brings compatibility with RHEL that lacks python3-asn1

The keyring package needs to be optional on RHEL which lacks this
module (currently).

Also drop the inappropriate pccs port number change

Related: https://issues.redhat.com/browse/RHEL-127046
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-12-10 11:22:41 +00:00
Daniel P. Berrangé
2c1f338978 Update to SGX 2.26 / DCAP 1.23, adding PCCS service
Resolves: https://issues.redhat.com/browse/RHEL-127046
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-11-18 18:31:07 +00:00
Daniel P. Berrangé
d050136e53 Adapt qgs.service for SELinux policy and sock perms
Changes to qgs.service to make it more amenable to writing a strict
SELinux policy.

Also add patch to allow control over socket perms so QEMU can get
access to the socket.

Related: https://issues.redhat.com/browse/RHELPLAN-171791
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-06-09 13:57:03 +01:00
Daniel P. Berrangé
ca443f650f Honour CFLAGS/CXXFLAGS/LDFLAGS for host software
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-04-16 16:50:30 +01:00
Daniel P. Berrangé
a8cda4b77a Initial import
Resolves: https://issues.redhat.com/browse/RHELPLAN-171791
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
2025-03-19 17:09:18 +00:00