From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 9E03DC7EE23 for ; Sat, 25 Feb 2023 20:38:01 +0000 (UTC) Received: from list by lists.xenproject.org with outflank-mailman.501867.773666 (Exim 4.92) (envelope-from ) id 1pW1IV-0007PT-2F; Sat, 25 Feb 2023 20:37:35 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version Received: by outflank-mailman (output) from mailman id 501867.773666; Sat, 25 Feb 2023 20:37:35 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1pW1IU-0007PM-Va; Sat, 25 Feb 2023 20:37:34 +0000 Received: by outflank-mailman (input) for mailman id 501867; Sat, 25 Feb 2023 20:37:33 +0000 Received: from se1-gles-sth1-in.inumbo.com ([159.253.27.254] helo=se1-gles-sth1.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1pW1IT-0007PG-41 for xen-devel@lists.xenproject.org; Sat, 25 Feb 2023 20:37:33 +0000 Received: from wout1-smtp.messagingengine.com (wout1-smtp.messagingengine.com [64.147.123.24]) by se1-gles-sth1.inumbo.com (Halon) with ESMTPS id 37a18c7e-b54c-11ed-88bb-e56d68cac8db; Sat, 25 Feb 2023 21:37:30 +0100 (CET) Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by mailout.west.internal (Postfix) with ESMTP id 27EDA32004AE; Sat, 25 Feb 2023 15:37:25 -0500 (EST) Received: from mailfrontend1 ([10.202.2.162]) by compute5.internal (MEProxy); Sat, 25 Feb 2023 15:37:26 -0500 Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sat, 25 Feb 2023 15:37:23 -0500 (EST) X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" X-Inumbo-ID: 37a18c7e-b54c-11ed-88bb-e56d68cac8db DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= invisiblethingslab.com; h=cc:cc:content-transfer-encoding:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:sender:subject:subject:to:to; s=fm1; t= 1677357444; x=1677443844; bh=O4/IZ+LuGJRHMvCUTkXEoOEx+FGHNfoNKJ2 om9c4VdI=; b=p4aDnP7hxbRCNULXC4DzXv88OAYlhDVPgE9EVhuOV21Kiv9sDeV 5HMuOC2Z0uDkqvIaNtgjd+ny56W6xXBp8m3ETEz64zhe+umkX2R7PSJADMzcliY5 iuag9poAMqs0dxmpCyeGrcvx5XXGcmD12jcO4oFYTxw4UwkETjekidSuPqW23W6T 69JlPwPxMd6AMsFrkMEp3+AdifgcSErpW5zxUqGD6Q91JyWcFCxEIQ83plVAZZD6 SFLHWC0R4hlwpm5yUUbHE9p9yWyi3pr6PxbB1BU32GF1j0VLybM9ACxR/JGQYf0e ucJwBsQbQDHPsYIVctJ7D8qKnTKJb5sitTg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:sender:subject :subject:to:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm1; t=1677357444; x=1677443844; bh=O4/IZ+LuGJRHM vCUTkXEoOEx+FGHNfoNKJ2om9c4VdI=; b=KZmEalqhO1cvpS90Baj8dKWVZLual pHZv799zyBj4NtiFiW8WrhJPskGlBGySAbOVe5ghvu3KfL9HXCyTY0KhUHRacImI H89+kEU1/hcsSK/fTU584jCdqIBIRZl7+xo+5aDsGC3+bC1pDA5cwNbm69SAOMS4 HlIha9NX8ZBpDC4dmw6A+IkBwPJVPEoGi18+qjuS8BTQ+UP4MYGKIBRNeylknC7U 1W5Ngt6CPGVuBQXFA/a1FJB9uoGAyrTrm1Fppl8c/Ohsq8Lq1humz5buBLv3nspB FD7X4Y9Oupo3aCgILdZWjYQi/g1NOePZXENNA+RiTUB2f0/J5kUAR9tHQ== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvhedrudekiedgjeehucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurhephffvvefufffkofgjfhgggfestdekredtredttdenucfhrhhomhepffgvmhhi ucforghrihgvucfqsggvnhhouhhruceouggvmhhisehinhhvihhsihgslhgvthhhihhngh hslhgrsgdrtghomheqnecuggftrfgrthhtvghrnheptefhhfdtkefhkefgjeduffehuedt gfduveejiedvffdvgeevledttdegvefhueegnecuffhomhgrihhnpeigvghnrdhorhhgpd gtohhnfhhighdrmhhknecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghi lhhfrhhomhepuggvmhhisehinhhvihhsihgslhgvthhhihhnghhslhgrsgdrtghomh X-ME-Proxy: Feedback-ID: iac594737:Fastmail From: Demi Marie Obenour To: xen-devel@lists.xenproject.org Cc: Demi Marie Obenour , =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?= , Andrew Cooper , George Dunlap , Jan Beulich , Julien Grall , Stefano Stabellini , Wei Liu , Konrad Rzeszutek Wilk , Ross Lagerwall , Anthony PERARD , Samuel Thibault , Doug Goldstein Subject: [PATCH v5 0/5] Stop using insecure transports Date: Sat, 25 Feb 2023 15:37:10 -0500 Message-Id: X-Mailer: git-send-email 2.39.2 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Obtaining code over an insecure transport is a terrible idea for blatently obvious reasons. Even for non-executable data, insecure transports are considered deprecated. Changes since v4: - Remove known-broken links entirely. They only mislead users into believing the code can be obtained there when it cannot. Changes since v3: - Drop patch 4, which is an unrelated removal of unused code. - Do not fail with an error if one tries to build the I/O emulator, vTPM, or vTPM manager stubdomains and passes --enable-extfiles. The user may have provided alternate download URLs via environment variables. Changes since v2: - Drop patches 5 and 6, which changed links not used by automated tools. These patches are the least urgent and hardest to review. - Ensure that no links are broken, and fail with an error instead of trying to use links that *are* broken. Demi Marie Obenour (5): Use HTTPS for all xenbits.xen.org Git repos Change remaining xenbits.xen.org links to HTTPS Build system: Do not try to use broken links Build system: Replace git:// and http:// with https:// Automation and CI: Replace git:// and http:// with https:// Config.mk | 20 ++++--------- README | 4 +-- automation/build/debian/stretch-llvm-8.list | 4 +-- automation/scripts/qemu-smoke-dom0-arm32.sh | 2 +- docs/misc/livepatch.pandoc | 2 +- docs/process/xen-release-management.pandoc | 2 +- m4/stubdom.m4 | 5 ++-- scripts/get_maintainer.pl | 2 +- stubdom/configure | 33 ++++++--------------- stubdom/configure.ac | 18 +++++------ tools/firmware/etherboot/Makefile | 6 +--- tools/misc/mkrpm | 2 +- 12 files changed, 37 insertions(+), 63 deletions(-) -- Sincerely, Demi Marie Obenour (she/her/hers) Invisible Things Lab