Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upxen: get rid of the downloadable *unsigned* components #48
Comments
marmarek
assigned
rootkovska
Mar 8, 2015
marmarek
added this to the Release 1 Beta 1 milestone
Mar 8, 2015
marmarek
added
bug
C: core
P: major
labels
Mar 8, 2015
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
|
Modified by joanna on 4 Jul 2010 15:19 UTC |
marmarek
added
C: xen
and removed
C: core
labels
Mar 8, 2015
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
|
Modified by joanna on 1 Mar 2011 09:34 UTC |
marmarek
modified the milestones:
Release 1 Beta 2,
Release 1 Beta 1
Mar 8, 2015
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
|
Comment by joanna on 11 Apr 2011 12:04 UTC |
marmarek
added
the
R: duplicate
label
Mar 8, 2015
marmarek
closed this
Mar 8, 2015
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
|
Modified by joanna on 2 May 2011 11:46 UTC |
marmarek
removed
the
R: duplicate
label
Mar 8, 2015
marmarek
reopened this
Mar 8, 2015
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
marmarek
Mar 8, 2015
Member
Comment by joanna on 2 May 2011 11:46 UTC
We should really get rid of all the wgets in the Xen Makefile, not just hoping that if we provide pre-downloaded and verified tgzs then those wgets wouldn't download anything.
|
Comment by joanna on 2 May 2011 11:46 UTC |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
marmarek
Mar 8, 2015
Member
Comment by marmarek on 12 May 2011 16:23 UTC
Added patch to remove wget invokes (only left in some tests, which isn't run during building).
Also added some more files to download (but looks as unused in our configuration).
|
Comment by marmarek on 12 May 2011 16:23 UTC |
marmarek commentedMar 8, 2015
Reported by joanna on 30 Jun 2010 10:11 UTC
Xen Makefile downloads and builds some unsigned code, that we don't even use in Qubes (qemu, etc). Those files are downloaded over plaintext connection, so subject to easy subversion by an attacker in the middle. Such an attack might result in a compromised package or developers machine.
It's silly to have a signed xen package, that uses unsigned packages...
Migrated-From: https://wiki.qubes-os.org/ticket/48