[Bug debuginfod/28204] extend webapi / verification with forthcoming signed-contents archives

2021-08-12 Thread fche at redhat dot com via Elfutils-devel
https://sourceware.org/bugzilla/show_bug.cgi?id=28204 --- Comment #1 from Frank Ch. Eigler --- https://bugzilla.redhat.com/show_bug.cgi?id=1896046#c10 (private, sorry) contains instructions on generating IMA-signed RPMs via % rpm --addsign --signfiles --fskpath=FOO.pem foo.rpm -- You are recei

[PATCH] debuginfod: PR27917 - protect against federation loops

2021-08-12 Thread Di Chen via Elfutils-devel
>From a726d9868f4e02d390b9071180b0c3728da3750e Mon Sep 17 00:00:00 2001 From: Di Chen Date: Sun, 8 Aug 2021 16:57:12 +0800 Subject: [PATCH] debuginfod: PR27917 - protect against federation loops If someone misconfigures a debuginfod federation to have loops, and a nonexistent buildid lookup is at