From 2bd48852e24bace7737c381883b0086f3370e57f Mon Sep 17 00:00:00 2001 From: Yi Zhao Date: Thu, 18 Nov 2021 10:15:38 +0800 Subject: [PATCH] meta-secure-core: fix wrong operator combination Operations like XXX:append += "YYY" are almost always wrong and this is a common mistake made in the metadata. Improve them to use the standard format. Signed-off-by: Yi Zhao --- .../recipes-base/packagegroups/packagegroup-efi-secure-boot.bb | 2 +- meta-integrity/conf/layer.conf | 2 +- meta-integrity/recipes-core/util-linux/util-linux-integrity.inc | 2 +- meta-integrity/recipes-devtools/rpm/rpm-integrity.inc | 2 +- meta-signing-key/conf/layer.conf | 2 +- meta-signing-key/recipes-devtools/sbsigntool/sbsigntool_git.bb | 2 +- 6 files changed, 6 insertions(+), 6 deletions(-) diff --git a/meta-efi-secure-boot/recipes-base/packagegroups/packagegroup-efi-secure-boot.bb b/meta-efi-secure-boot/recipes-base/packagegroups/packagegroup-efi-secure-boot.bb index 61afc93..90633f3 100644 --- a/meta-efi-secure-boot/recipes-base/packagegroups/packagegroup-efi-secure-boot.bb +++ b/meta-efi-secure-boot/recipes-base/packagegroups/packagegroup-efi-secure-boot.bb @@ -29,4 +29,4 @@ kmods = "\ RRECOMMENDS:${PN}:x86 += "${kmods}" RRECOMMENDS:${PN}:x86-64 += "${kmods}" -IMAGE_INSTALL:remove += "grub" +IMAGE_INSTALL:remove = "grub" diff --git a/meta-integrity/conf/layer.conf b/meta-integrity/conf/layer.conf index 8be64f6..64a950d 100644 --- a/meta-integrity/conf/layer.conf +++ b/meta-integrity/conf/layer.conf @@ -24,7 +24,7 @@ LAYERRECOMMENDS_integrity = "\ tpm \ " -BB_HASHBASE_WHITELIST:append += "\ +BB_HASHBASE_WHITELIST:append = " \ RPM_FSK_PATH \ " diff --git a/meta-integrity/recipes-core/util-linux/util-linux-integrity.inc b/meta-integrity/recipes-core/util-linux/util-linux-integrity.inc index 59cca65..68b09ce 100644 --- a/meta-integrity/recipes-core/util-linux/util-linux-integrity.inc +++ b/meta-integrity/recipes-core/util-linux/util-linux-integrity.inc @@ -1,4 +1,4 @@ -CFLAGS:remove += "-pie -fpie" +CFLAGS:remove = "-pie -fpie" # We need -no-pie in case the default is to generate pie code. # diff --git a/meta-integrity/recipes-devtools/rpm/rpm-integrity.inc b/meta-integrity/recipes-devtools/rpm/rpm-integrity.inc index b34a2fe..20d4103 100644 --- a/meta-integrity/recipes-devtools/rpm/rpm-integrity.inc +++ b/meta-integrity/recipes-devtools/rpm/rpm-integrity.inc @@ -5,7 +5,7 @@ PACKAGECONFIG:append = " \ " # IMA signing support is provided by RPM plugin. -EXTRA_OECONF:remove += "\ +EXTRA_OECONF:remove = "\ --disable-plugins \ " EXTRA_OECONF:append:class-native = " --disable-inhibit-plugin --with-audit=no" diff --git a/meta-signing-key/conf/layer.conf b/meta-signing-key/conf/layer.conf index 77507b2..331fb19 100644 --- a/meta-signing-key/conf/layer.conf +++ b/meta-signing-key/conf/layer.conf @@ -64,7 +64,7 @@ RPM_GPG_PASSPHRASE ??= "SecureCore" BOOT_GPG_NAME ??= "SecureBootCore" BOOT_GPG_PASSPHRASE ??= "SecureCore" -BB_HASHBASE_WHITELIST:append += "\ +BB_HASHBASE_WHITELIST:append = " \ SYSTEM_TRUSTED_KEYS_DIR \ SECONDARY_TRUSTED_KEYS_DIR \ MODSIGN_KEYS_DIR \ diff --git a/meta-signing-key/recipes-devtools/sbsigntool/sbsigntool_git.bb b/meta-signing-key/recipes-devtools/sbsigntool/sbsigntool_git.bb index de605d4..46a0167 100644 --- a/meta-signing-key/recipes-devtools/sbsigntool/sbsigntool_git.bb +++ b/meta-signing-key/recipes-devtools/sbsigntool/sbsigntool_git.bb @@ -41,7 +41,7 @@ def efi_arch(d): # Avoids build breaks when using no-static-libs.inc #DISABLE_STATIC:class-target = "" -#EXTRA_OECONF:remove:class-target += "\ +#EXTRA_OECONF:remove:class-target = "\ # --with-libtool-sysroot \ #"