meta-security: subtree update:d6baccc068..4c2f7ffd49

Adrian (1):
      gitignore added

Armin Kuster (31):
      kas: build with ptest. remove apparmor
      softHSM: add pkg
      packagegroup-core-security: add softHSM
      libest: add recipe
      packagegroup-core-security: add libest package
      opendnssec: add recipe
      packagegroup-core-security:  add opendnssec to pkg grp
      gitlab-ci: allow test to fail
      libseccomp: fix ptest failures.
      packagegroup-core-security-ptest: remove keyutils-ptest
      security-test-image: simplify
      packagegroup-core-security-ptest: remove
      apparmor: fix build issue with ptest enabled.
      security-test-image: tweak to get more tests to runn
      apparmor: update to 3.0
      packagegroup-core-security: apparmor 3.0 ptest does not build
      suricata: fix compiling on gcc10
      qemux86-test: add apparmor back
      apparmor: fix build for on musl
      ecryptfs-utils: fix musl build
      libest: fix musl build.
      sssd: update to latest ltm 1.16.5
      packagegroup-core-security: remove clamav from musl image
      suricata: update to 4.1.9
      kas: fixup alt configs
      gitlab-ci: add qemux86 and qemuarm64 musl builds
      tpm2-tss: update to 2.4.3
      tpm2-totp: update to 0.2.1
      tpm2-abrmd: update to 2.3.3
      tpm2-tools: update to 4.3.0
      tpm2-pkcs11: update to 1.4.0

Mingli Yu (1):
      scap-security-guide: add expat-native to DEPENDS

Naveen Saini (3):
      initramfs-framework/dmverity: add retry loop for slow boot devices
      wic: add wks.in for intel dm-verity
      linux-%/5.x: Add dm-verity fragment as needed

Signed-off-by: Andrew Geissler <geissonator@yahoo.com>
Change-Id: If3a721fdd99bb6e35c82cf4e7485f06cebaef905
diff --git a/meta-security/kas/kas-security-alt.yml b/meta-security/kas/kas-security-alt.yml
new file mode 100644
index 0000000..309acaa
--- /dev/null
+++ b/meta-security/kas/kas-security-alt.yml
@@ -0,0 +1,8 @@
+header:
+    version: 9
+    includes: 
+        - kas-security-base.yml
+
+local_conf_header:
+  alt: |
+      DISTRO_FEATURES_append = " apparmor pam smack systemd"
diff --git a/meta-security/kas/kas-security-base.yml b/meta-security/kas/kas-security-base.yml
index cd87d1d..6a77af5 100644
--- a/meta-security/kas/kas-security-base.yml
+++ b/meta-security/kas/kas-security-base.yml
@@ -42,8 +42,7 @@
     INHERIT += "testimage"
     TEST_QEMUBOOT_TIMEOUT = "1500"
     EXTRA_IMAGE_FEATURES ?= "debug-tweaks"
-    DISTRO_FEATURES_remove = " ptest"
-    PACKAGE_CLASSES = "package_rpm"
+    PACKAGE_CLASSES = "package_ipk"
 
 
   diskmon: |
diff --git a/meta-security/kas/qemuarm64-alt.yml b/meta-security/kas/qemuarm64-alt.yml
index d23e38e..48e688c 100644
--- a/meta-security/kas/qemuarm64-alt.yml
+++ b/meta-security/kas/qemuarm64-alt.yml
@@ -1,10 +1,6 @@
 header:
   version: 8
   includes:
-    - kas-security-base.yml
-
-local_conf_header:
-  alt: |
-      DISTRO_FEATURES_append = " apparmor pam systemd"
+    - kas-security-alt.yml
 
 machine: qemuarm64
diff --git a/meta-security/kas/qemuarm64-musl.yml b/meta-security/kas/qemuarm64-musl.yml
new file mode 100644
index 0000000..b353eb4
--- /dev/null
+++ b/meta-security/kas/qemuarm64-musl.yml
@@ -0,0 +1,10 @@
+header:
+  version: 8
+  includes:
+    - kas-security-base.yml
+
+local_conf_header:
+    musl: |
+        TCLIBC = "musl"
+
+machine: qemuarm64
diff --git a/meta-security/kas/qemux86-64-alt.yml b/meta-security/kas/qemux86-64-alt.yml
index 4364bf5..f0d6b27 100644
--- a/meta-security/kas/qemux86-64-alt.yml
+++ b/meta-security/kas/qemux86-64-alt.yml
@@ -1,10 +1,6 @@
 header:
   version: 8
   includes:
-    - kas-security-base.yml
-
-local_conf_header:
-  alt: |
-    DISTRO_FEATURES_append = " apparmor pam systmed"
+    - kas-security-alt.yml
 
 machine: qemux86-64
diff --git a/meta-security/kas/qemux86-musl.yml b/meta-security/kas/qemux86-musl.yml
new file mode 100644
index 0000000..61d9572
--- /dev/null
+++ b/meta-security/kas/qemux86-musl.yml
@@ -0,0 +1,10 @@
+header:
+  version: 8
+  includes:
+    - kas-security-base.yml
+
+local_conf_header:
+    musl: |
+        TCLIBC = "musl"
+
+machine: qemux86
diff --git a/meta-security/kas/qemux86-test.yml b/meta-security/kas/qemux86-test.yml
index 823a8b2..7b5f451 100644
--- a/meta-security/kas/qemux86-test.yml
+++ b/meta-security/kas/qemux86-test.yml
@@ -6,6 +6,6 @@
 
 local_conf_header:
   meta-security: |
-      DISTRO_FEATURES_append = " ptest apparmor pam"
+      DISTRO_FEATURES_append = " apparmor smack pam"
 
 machine: qemux86