Check for changes relevant for security certifications
Bug #1945989 reported by
Marcelo Cerri
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | ||
---|---|---|---|---|---|---|
linux (Ubuntu) | Status tracked in Mantic | |||||
Bionic |
Fix Released
|
Undecided
|
Marcelo Cerri | |||
Focal |
Fix Released
|
Undecided
|
Marcelo Cerri | |||
Impish |
Fix Released
|
Undecided
|
Marcelo Cerri | |||
Jammy |
Fix Committed
|
Undecided
|
Magali Lemes do Sacramento | |||
Mantic |
Fix Released
|
Undecided
|
Magali Lemes do Sacramento |
Bug Description
[Impact]
When producing a new version of some kernels, we need to check for changes that might affect FIPS or other certs and justify why a commit was kept or removed.
To simplify this process we can add an automated check that will abort the kernel preparation and build when such changes exist without a justification.
[Test Plan]
Check if the kernel preparation fails (cranky close) when one of a security certification changes is added.
[Where problems could occur]
No kernels should be affected until we enable this check on each one. Even when enabled, that only affects the kernel preparation and not the resulting kernel.
CVE References
Changed in linux (Ubuntu Bionic): | |
assignee: | nobody → Marcelo Cerri (mhcerri) |
Changed in linux (Ubuntu Impish): | |
assignee: | nobody → Marcelo Cerri (mhcerri) |
Changed in linux (Ubuntu Focal): | |
assignee: | nobody → Marcelo Cerri (mhcerri) |
summary: |
- Check for changes relevant for security certification + Check for changes relevant for security certifications |
Changed in linux (Ubuntu Bionic): | |
status: | Incomplete → Fix Committed |
Changed in linux (Ubuntu Focal): | |
status: | Incomplete → Fix Committed |
Changed in linux (Ubuntu Mantic): | |
assignee: | Marcelo Cerri (mhcerri) → nobody |
status: | Fix Released → New |
Changed in linux (Ubuntu Jammy): | |
assignee: | nobody → Magali Lemes do Sacramento (magalilemes) |
Changed in linux (Ubuntu Mantic): | |
assignee: | nobody → Magali Lemes do Sacramento (magalilemes) |
Changed in linux (Ubuntu Jammy): | |
status: | Incomplete → Fix Committed |
Changed in linux (Ubuntu Mantic): | |
status: | Incomplete → Fix Committed |
To post a comment you must log in.
This bug is missing log files that will aid in diagnosing the problem. While running an Ubuntu kernel (not a mainline or third-party kernel) please enter the following command in a terminal window:
apport-collect 1945989
and then change the status of the bug to 'Confirmed'.
If, due to the nature of the issue you have encountered, you are unable to run this command, please add a comment stating that fact and change the bug status to 'Confirmed'.
This change has been made by an automated script, maintained by the Ubuntu Kernel Team.