Commit Graph

1750 Commits

Author SHA1 Message Date
Esa Jaaskela 0339b65f63 aide: Fix unstable install task hash
The installation task hash for the aide is marked as nostamp. This is
done because the native task installs files outside the sysroot, to the
Aide staging directory. Those files are not captured by
do_populate_sysroot, so they are missing whenever the task is skipped or
restored from sstate.

Install the required native contents to the sysroot, and then customise
and deploy the configuration file in the aide_init_db rootfs postprocess
function that utilizes the files. The configuration file needs to be
reset every time the function is run to avoid using stale
configurations.

Staging the native files through the sysroot makes the nostamp
unnecessary, so remove it along with the unstable task hash it caused.

Signed-off-by: Esa Jaaskela <esa.jaaskela@suomi24.fi>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-26 23:54:46 +03:00
Scott Murray 06a36993a0 meta-tpm: Fix SUMMARY/HOMEPAGE in affected recipes
To quiet the missing metadata warnings, switch DESCRIPTION to SUMMARY
in the following recipes:
- security-tpm-image
- security-tpm2-image
- packagegroup-security-tpm
- openssl-tpm-engine

and add HOMEPAGE to these recipes:
- libtpms
- swtpm
- tpm-tools

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-26 23:54:46 +03:00
Scott Murray 91c2bfdcc2 meta-integrity: Fix ima-evm-utils LICENSE
Update for upstream switch to SPDX syntax for LICENSE to silence QA
warning.

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-26 23:54:46 +03:00
Wang Mingyu d4afe52355 fix LICENSE variable syntax to suppress QA warning
Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-26 23:54:46 +03:00
Krupal Ka Patel c6025730f6 tpm2-tools: fix PACKAGECONFIG typo
Correct the misspelled PACKAGECONFIG variable so efivar is enabled by
default as intended by commit cdb4e444ac.

Signed-off-by: Krupal Ka Patel <krkapate@cisco.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-26 23:54:43 +03:00
Peter Marko aa594ecd24 tpm2-tss: set status for CVE-2024-29040
CVE-2024-29040 is per Debian report [2] fixed in 4.1.0.

[1] https://security-tracker.debian.org/tracker/CVE-2024-29040

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-26 23:54:37 +03:00
Peter Marko 603cd3ff49 tpm2-tools: set status for CVE-2017-7524 and CVE-2024-29039
CVE-2017-7524 is a historical CVE and new cve-check does not undestand
fixed version data. Debian report [1] shows fix commit which can be
linked to release information.

CVE-2024-29039 is per Debian report [2] fixed in 5.7.

[1] https://security-tracker.debian.org/tracker/CVE-2017-7524
[2] https://security-tracker.debian.org/tracker/CVE-2024-29039

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-26 23:54:04 +03:00
Gaël PORTAY 79b0dbd8f7 docs: update path of wic files
The wic files were moved from wic/ to files/wic since commit 596b966a0d
("wic: wic need to be moved to files/wic within the layer to be
found/used").

This updates the path of wic files in the documentation.

Signed-off-by: Gaël PORTAY <gael.portay+rtone@gmail.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-26 23:53:53 +03:00
Gaël PORTAY d2c9a6194f wic: document the meta-intel dependency in the dm-verity hash example
The dependency might not be obvious to everyone, so leave a hint as in
commit 2fbeebc18c ("dm-verity: document the meta-intel dependency in the
systemd example").

Signed-off-by: Gaël PORTAY <gael.portay+rtone@gmail.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-11 20:38:47 +03:00
Gaël PORTAY 013ac85174 dm-verity: remove unused variable
This removes unused variable that was dropped by commit d80cd2ba6a
("dm-verity: Set the IMAGE_FSTYPES correctly when dm-verity is
enabled").

Signed-off-by: Gaël PORTAY <gael.portay+rtone@gmail.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-11 20:38:32 +03:00
Shreejit C 3ef6b7cc57 meta-tpm: Add missing recipe metadata (HOMEPAGE/SUMMARY)
Several meta-tpm recipes were missing HOMEPAGE and/or SUMMARY entries,
tripping the missing-metadata recipe QA check that is enabled for
core-layer recipes. The warnings surface whenever do_recipe_qa actually
runs (a fresh build with no sstate hit), e.g.:

  WARNING: tpm2-tss-4.1.3-r0 do_recipe_qa: QA Issue: Recipe tpm2-tss in
  .../tpm2-tss_4.1.3.bb does not contain a HOMEPAGE. Please add an entry.
  [missing-metadata]

Add the upstream project URL as HOMEPAGE, and a SUMMARY where absent:

  - tpm2-tss:                   add HOMEPAGE
  - tpm2-tools:                 add HOMEPAGE
  - tpm2-openssl:               add HOMEPAGE
  - tpm2-abrmd:                 add HOMEPAGE
  - tpm2-pkcs11:                add HOMEPAGE
  - tpm2-tss-engine:            add HOMEPAGE
  - python3-tpm2-pytss:         add SUMMARY
  - packagegroup-security-tpm2: add SUMMARY

Signed-off-by: Shreejit C <shreejit.c@emerson.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-11 20:37:45 +03:00
Sandeep J f25a1bf10c README: fix broken URLs in meta-integrity and ccs-tools
Update TOMOYO documentation URL:
   http://tomoyo.sourceforge.jp/1.8/index.html.en
to:
   https://tomoyo.sourceforge.net/1.8/index.html.en

Replace dead gmane.org permalink references with mail-archive.com
copies of the original Tizen dev mailing list messages:
   http://permalink.gmane.org/gmane.comp.handhelds.tizen.devel/6281
to:
   https://www.mail-archive.com/dev@lists.tizen.org/msg06106.html

   http://permalink.gmane.org/gmane.comp.handhelds.tizen.devel/6275
to:
   https://www.mail-archive.com/dev@lists.tizen.org/msg06100.html

Signed-off-by: Sandeep J <Sandeep.J@windriver.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-11 20:37:28 +03:00
Bin Cao 1c04ed220b samhain: fix server startup failure on systemd-based systems
Fix two issues preventing samhain-server (yule) from starting:

1. The compiled-in PID file path /var/run/samhain.pid fails because
   /var/run is a symlink to /run on systemd-based systems, and
   samhain's security check rejects symlinks for PID directories.
   Add SetLockfilePath = /run/yule.pid to yulerc.template, following
   the same approach used in 0004-Set-the-PID-Lock-path-for-samhain.pid
   for the standalone/client configuration.

2. The init scripts unconditionally source /etc/default/rcS which does
   not exist on systemd-based systems, producing a confusing error
   message. Source it conditionally instead.

Signed-off-by: Bin Cao <bin.cao.cn@windriver.com>
(adapted against prior 4.5.3 upgrade)
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-11 20:36:24 +03:00
Scott Murray 74e55cf4fb suricata: handle oe_cargo_build removal
Handle upstream removal of oe_cargo_build function in oe-core commit
a64ac03a61 by renaming our local override to cargo_do_compile to get
the same effect.

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-11 20:30:32 +03:00
Scott Murray c4c37c0074 aide: Fix compilation with nettle 4.x
Backport unreleased change from upstream to handle building with nettle
4.x now that openembedded-core has upgraded to it.

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-08-11 20:30:21 +03:00
Peter Marko 226839ac40 tpm2-pkcs11: upgrade 1.9.1 -> 1.9.2
This contains fix for building native recipe with security flags
enabled:
* https://github.com/tpm2-software/tpm2-pkcs11/commit/be97b21ae641303ce83a8fbb54002701c1aede31

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-25 17:11:19 +03:00
Bin Cao dc0a7622e4 samhain: upgrade 4.5.2 -> 4.5.3
Update samhain-client, samhain-server, and samhain-standalone to 4.5.3.

Release notes: https://www.la-samhna.de/samhain/archive.html

Signed-off-by: Bin Cao <bin.cao.cn@windriver.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-17 17:45:41 +03:00
jason.lau 9d749026dd aide: fix pkg_postinst_ontarget shell script
- Fix conditional checks for AIDE_SCAN_POSTINIT and AIDE_RESCAN_POSTINIT:
  '[ 0 ]' always evaluates to true since it's a non-empty string.
  Use string comparison '= "1"' instead.
- Fix invalid use of '&&' inside '[ ]' test brackets. Use separate
  test expressions joined by shell '&&'.

Signed-off-by: Haitao Liu <haitao.liu@windriver.com>
(reworked for 0.19.3, fixed indentation)
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-17 17:45:41 +03:00
Li Zhou b4c43ad77a aide-base.bbclass: correct STAGING_AIDE_DIR
Fix the typo "aida" to "aide" in STAGING_AIDE_DIR.

Signed-off-by: Li Zhou <li.zhou@windriver.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-17 17:45:41 +03:00
Yi Zhao 797df6dca9 arpwatch: fix typos
APRWATCH_FROM -> ARPWATCH_FROM
ARPWATH_REPLY -> ARPWATCH_REPLY
CONFFILE_FILES -> CONFFILES:${PN}

Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-17 17:44:55 +03:00
Peter Marko cdb4e444ac tpm2-tools: make efivar optional
Previous commit made this a hard dependency because it's autodetected.
Instead of that, make it configurable so it can be disabled (roughtly
equivalent to behavior before that commit).

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-17 17:44:55 +03:00
Ross Burton 921b75fa4a parsec-service: update TS group name
meta-arm recently changed the group name that is used by TS[1], so update
the group name to match.

[1] meta-arm 595cb0f1a0 ("arm/trusted-services: fix udev management in libts")

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-17 17:44:55 +03:00
Ross Burton a9384af621 parsec-service: do group membership modifications in useradd
Instead of calling groupmems after creating the user, we can tell useradd
to do the group membership when creating the user.  There are several
reasons for this:

1) Consolidation of the calls into a single call means creation is atomic,
   it either worked or it did not.
2) The existing logic doesn't work if both TPM and TS were enabled.
3) GROUPMEMS_PARAM is broken in oe-core master[1] and this will not be
   fixed as groupmems has been removed from shadow[2].

Instead, construct a list of groups that parsec needs to be a member of,
and pass them to useradd.

[1] https://bugzilla.yoctoproject.org/show_bug.cgi?id=16277
[2] shadow 388ce70 "*/: groupmems(8): Remove program"

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-17 17:44:55 +03:00
Ross Burton 58ac5eda9a parsec-service: assign PACKAGECONFIG in one line
By :appending the TPM option we make it impossible for distros to simply
assign to PACKAGECONFIG.

Signed-off-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-17 17:44:55 +03:00
Anton Antonov 677294c158 meta-parsec: Do not run Parsec CI jobs on 32bit platforms.
Signed-off-by: Anton Antonov <Anton.Antonov@arm.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-17 17:44:55 +03:00
Anton Antonov e6538dbad1 parsec-service: Update Parsec service version.
This update adds compatibility with clang 22.1 in oe-core.

Signed-off-by: Anton Antonov <Anton.Antonov@arm.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-17 17:44:55 +03:00
jason.lau 7a505194a8 google-authenticator-libpam: update 1.0.9 -> 1.11
Changes from 1.09 to 1.10:
  - Shorten syslog name to work with rsyslog (#172)
  - Update config file with grace period in all cases (#193)
  - Remove printing QR code using Google Charts URL (service shut down)

  Changes from 1.10 to 1.11:
  - Change secret key bits from 128 to 160 bits (#266, #271)
  - Add support for black & white terminals (#268, #270)
  - Fix grace_period for IPv6 link-local addresses (#265)

  Also fix the .bb recipe:
  - Fix typo: RDEPNEDS -> RDEPENDS
  - Use new override syntax: RDEPENDS:pam-google-authenticator
    (replaces old underscore style RDEPENDS_pam-google-authenticator)

Signed-off-by: Haitao Liu <haitao.liu@windriver.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-17 17:44:55 +03:00
Li Zhou 07ea3222db layer.conf: correct WARN_QA
Fix the typo "tmp-layer" in "WARN_QA:append".
The right name for this layer in OVERRIDES is layer-tpm-layer
by checking "bitbake -e <recipe_name> | grep ^OVERRIDES=".

Signed-off-by: Li Zhou <li.zhou@windriver.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-17 17:44:55 +03:00
Li Zhou 1608741508 firejail: fix COMPATIBLE_MACHINE setting
Because "x86_64" and "arm64" aren't valid in bitbake OVERRIDES,
they should be corrected to "x86-64" and "aarch64".
On the other side, "x86_64" and "arch64" aren't valid MACHINE
name.
So correct the way to "only allow x86-64 and arm64 to build":
COMPATIBLE_MACHINE = "(-)"          => disallow all machine first
COMPATIBLE_MACHINE:aarch64 = "(.*)" => when arch "aarch64" in
OVERRIDES, allow all machines.
COMPATIBLE_MACHINE:x86-64 = "(.*)"  => when arch "x84-64" in
OVERRIDES, allow all machines.

Fix 1dd076d3a7 ("firejail: only allow x86-64 and arm64 to build")

Signed-off-by: Li Zhou <li.zhou@windriver.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-05-13 08:21:04 +03:00
Marta Rybczynska 9265f142f3 README: update CI links
Update CI links for meta-security

Signed-off-by: Marta Rybczynska <marta.rybczynska@ygreky.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-27 21:47:27 +03:00
Scott Murray 5bcd679c2c packagegroup-core-security: remove python3-privacyidea
To work around an install conflict between python3-cryptography and
python3-pyrad and unblock CI runs, remove python3-privacyidea from
the packagegroup dynamic bbappend temporarily.

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-27 21:47:27 +03:00
Scott Murray 5a333f4646 packagegroup-core-security: Add missing packages
Add aircrack-ng, crowdsec, ncrack, and opendnssec where appropriate
now that they have been updated to build again.

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-27 21:47:27 +03:00
Scott Murray 07439815e7 ncrack: Update
Bump to HEAD of ncrack's master branch to pick up build fixes for
newer gcc's.  PV has been updated to indicate that we are now
building something newer than the 0.7 tagged commit.

License-Update: copyright years refreshed

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-27 21:47:27 +03:00
Scott Murray ffdbb6dffd libmhash: Remove
Remove libmhash, as it is no longer required to build aide.

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-27 21:47:27 +03:00
Scott Murray 203087eb70 aide: Upgrade to 0.19.3
Release notes:
https://github.com/aide/aide/releases/tag/v0.19
https://github.com/aide/aide/releases/tag/v0.19.1
https://github.com/aide/aide/releases/tag/v0.19.2
https://github.com/aide/aide/releases/tag/v0.19.3

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-27 21:47:27 +03:00
Scott Murray 90049242e6 clamav: Upgrade to 1.4.4
Release notes:
https://github.com/Cisco-Talos/clamav/releases/tag/clamav-1.4.4

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-27 21:47:27 +03:00
Scott Murray d0386f2844 libmspack: Remove
Remove libmspack recipe, and remove it from clamav's DEPENDS.
clamav now vendors its own substantially modified copy, so there's
no reason to carry a recipe for it.

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-27 21:47:27 +03:00
Scott Murray 8e4092ad8d opendnssec: Upgrade to 2.1.14
Upgrade to 2.1.14 and add some patches from the github PR queue to
fix compilation.

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-27 21:47:27 +03:00
Scott Murray 1792ae2762 aircrack-ng: Upgrade to 1.7
Upgrade to the latest release, 1.7, and rework recipe so that it
actually builds again.  Note that the extra scripts are no longer
installed by default as they seem somewhat stale and likely further
work is required to have any of them work.  A PACKAGECONFIG option,
"ext-scripts" has been added to enable installing them if they are
required for some reason.

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-27 21:47:27 +03:00
Scott Murray cd05fe6992 crowdsec: Upgrade to v1.7.7
The crowdsec recipes has seemingly been broken since soon after its
addition, rewrite it to build the latest version with the go-mod
bbclass.

Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-27 21:47:27 +03:00
Clayton Casciato 1dcf90fa42 suricata: update 7.0.13 -> 8.0.4
8.0.0 [1]:
Increased Rust use (including libhtp, suricatactl, and suricatasc)
More protocols
Lua sandboxed and available by default

8.0.4 [2]: security, performance, accuracy, and stability fixes

Resolve startup warning [3]:
W: af-packet: eth0: AF_PACKET tpacket-v3 is recommended for non-inline
operation

Add "ja4" option for fingerprinting TLS and QUIC clients [4]

CFLAGS modification for (see [5]):
do_package_qa: QA Issue: File /usr/bin/.debug/suricata in package
suricata-dbg contains reference to TMPDIR [buildpaths]

SURICATA_LUA_SYS_HEADER_DST [6]

[1] https://suricata.io/2025/07/08/suricata-8-0-0-released/
[2] https://suricata.io/2026/03/17/suricata-8-0-4-and-7-0-15-released/
[3] https://docs.suricata.io/en/suricata-8.0.4/upgrade.html#id1
[4] https://github.com/OISF/suricata/pull/10836
[5] https://git.openembedded.org/openembedded-core/commit/?id=3239961e35434592c06ec2cae2885ab464d35744
[6] https://github.com/OISF/suricata/commit/3a7eef812198118fa0b96059e70074bec5a8cdbe

Signed-off-by: Clayton Casciato <majortomtosourcecontrol@gmail.com>
(added musl libunwind fix)
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-27 21:46:41 +03:00
Wenlin Kang 731c5fc0b8 krill: fix missing dollar sign in FILES
{sysconfdir} -> ${sysconfdir}

Signed-off-by: Wenlin Kang <wenlin.kang@windriver.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-25 00:48:55 +03:00
Haiqing Bai bd6927e1df isic: fix RDEPNEDS typo
Fix typo: RDEPNEDS -> RDEPENDS

Signed-off-by: Haiqing Bai <haiqing.bai@windriver.com>
(fixed RDEPENDS:${PN})
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-15 00:18:23 +03:00
Zhang Peng c3ddb212cf meta-security: fix incorrect HOMEPAGE variable names
Several recipes used non-standard variable names for the homepage
URL (HOME_PAGE, HOME_URL, HOMEDIR) which are not recognized by
bitbake. Rename them all to the correct HOMEPAGE variable.

Affected recipes:
- glome: HOME_PAGE -> HOMEPAGE
- google-authenticator-libpam: HOME_PAGE -> HOMEPAGE
- arpwatch: HOME_PAGE -> HOMEPAGE
- openscap: HOME_URL -> HOMEPAGE
- scap-security-guide: HOME_URL -> HOMEPAGE
- lynis: HOMEDIR -> HOMEPAGE

Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-15 00:18:23 +03:00
Peter Marko d975a55a65 tpm2-pkcs11: fix build failure
Use patch submitted upstream to fix build error:
| src/lib/tpm.c: In function ‘tpm_unseal’:
| src/lib/tpm.c:1040:16: error: incompatible types when returning type ‘_Bool’ but ‘twist’ {aka ‘const char *’} was expected
|  1040 |         return false;
|       |                ^~~~~

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-15 00:18:23 +03:00
Khem Raj 596b966a0d wic: wic need to be moved to files/wic within the layer to be found/used
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-15 00:18:23 +03:00
Yi Zhao 1ed57b9ee1 openscap: upgrade 1.4.2 -> 1.4.3
ChangeLog:
https://github.com/OpenSCAP/openscap/releases/tag/1.4.3

Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-15 00:18:23 +03:00
Yi Zhao f276fa1cca scap-security-guide: upgrade 0.1.78 -> 0.1.80
ChangeLog:
https://github.com/ComplianceAsCode/content/releases/tag/v0.1.80

Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-15 00:18:23 +03:00
Peter Marko 62a62bc7c0 libtpms: fix build with glibc 2.43
Backport patch stable-0.10 branch (not tagged yet).

Signed-off-by: Peter Marko <peter.marko@siemens.com>
Signed-off-by: Scott Murray <scott.murray@konsulko.com>
2026-04-14 22:43:53 +03:00
Marta Rybczynska 8028c573db layer.conf: Update to wrynose (6.0) release
Update LAYERSERIES_COMPAT in all layer.conf files with the exception
of meta-parsec to wrynose.  For meta-parsec, added wrynose to the list
of supported versions.

Signed-off-by: Marta Rybczynska <marta.rybczynska@ygreky.com>
2026-03-22 15:24:23 +01:00