Divested-Mobile / DivestOS-Build

Everything needed to build DivestOS, a more private and more secure aftermarket mobile operating system.
https://divestos.org/index.php?page=build
Other
227 stars 31 forks source link

lineage-17.1 patches incomplete #260

Closed SirRGB closed 1 year ago

SirRGB commented 1 year ago

https://github.com/Flamefire/android_device_sony_lilac/tree/lineage-17.1/patches/asb-2023-08/platform_system_ca-certificates https://github.com/Flamefire/android_device_sony_lilac/tree/lineage-17.1/patches/asb-2023-07/platform_tools_apksig

These are not uploaded to gerrit due to missing forks within the lineage org.

10-2023 will require these additional non-forked repos

https://github.com/Flamefire/android_device_sony_lilac/tree/lineage-17.1/patches/asb-2023-10/platform_external_libxml2 https://github.com/Flamefire/android_device_sony_lilac/tree/lineage-17.1/patches/asb-2023-10/platform_external_webp

There might be more patches, that I missed.

SkewedZeppelin commented 1 year ago

Please look at the actual scripts...

SkewedZeppelin commented 1 year ago

Please also understand I send the 17.1 ASB backports to flamefire after I do them first, ie. most of those backports were done by me:

I do however see this one: https://github.com/Flamefire/android_device_sony_lilac/blob/lineage-17.1/patches/asb-2023-10/android_packages_providers_MediaProvider/0001-Fix-path-traversal-vulnerabilities-in-MediaProvider.patch which I will pull in for next cycle as I usually do.

SirRGB commented 1 year ago

My bad, only https://review.lineageos.org/q/topic:%22CVE-2023-5217%22 is missing then. Applied fine for me without any additional patches. Thanks for the clarification and work on android 10 security patches, I really apreciate it.

SkewedZeppelin commented 1 year ago

CVE-2023-5217 is not missing, again, I made that backport and sent it to LineageOS on 2023-09-28:

SkewedZeppelin commented 1 year ago

If you're going to use my patches/backports, and I do encourage/want you to, please go through the scripts, and don't hesitate to ask me where something is. Just please don't assume it is missing :slightly_smiling_face:

SirRGB commented 1 year ago

Just noticed this one is implemented as well, sry again