diff --git a/.gitignore b/.gitignore index 6d559b3..d1d52cf 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,4 @@ -/ima-evm-utils-*.tar.gz -prepare_sources_result*/ +/ima-evm-utils-0.6.tar.gz +/ima-evm-utils-0.9.tar.gz +/ima-evm-utils-1.0.tar.gz +/ima-evm-utils-1.1.tar.gz diff --git a/.packit.yaml b/.packit.yaml deleted file mode 100644 index a97cb7f..0000000 --- a/.packit.yaml +++ /dev/null @@ -1,34 +0,0 @@ -# See the documentation for more information: -# https://packit.dev/docs/configuration/ - -specfile_path: ima-evm-util.spec - -# add or remove files that should be synced -files_to_sync: - - .packit.yaml - -# name in upstream package repository or registry (e.g. in PyPI) -upstream_package_name: ima-evm-utils -# downstream (Fedora) RPM package name -downstream_package_name: ima-evm-utils - -jobs: - # This is triggered by https://release-monitoring.org/ - - job: pull_from_upstream - trigger: release - dist_git_branches: - - fedora-all - - # This is triggered at Fedora dist-git for creating koji build after - # PR in src.fedoraproject.org been merged. - - job: koji_build - trigger: commit - allowed_pr_authors: ["all_committers", "packit"] - dist_git_branches: - - fedora-all - - # This is triggered at Fedora messaging bus about koji build finished. - - job: bodhi_update - trigger: commit - allowed_builders: ["all_committers", "packit"] - dist_git_branches: diff --git a/docbook-xsl-path.patch b/docbook-xsl-path.patch new file mode 100644 index 0000000..e4ee8e5 --- /dev/null +++ b/docbook-xsl-path.patch @@ -0,0 +1,12 @@ +diff -urNp ima-evm-utils-1.0-orig/Makefile.am ima-evm-utils-1.0/Makefile.am +--- ima-evm-utils-1.0-orig/Makefile.am 2015-07-30 15:28:53.000000000 -0300 ++++ ima-evm-utils-1.0/Makefile.am 2017-11-20 16:20:04.245591165 -0200 +@@ -24,7 +24,7 @@ rpm: $(tarname) + rpmbuild -ba --nodeps $(SPEC) + + # requires asciidoc, xslproc, docbook-xsl +-MANPAGE_DOCBOOK_XSL = /usr/share/xml/docbook/stylesheet/docbook-xsl/manpages/docbook.xsl ++MANPAGE_DOCBOOK_XSL = /usr/share/sgml/docbook/xsl-stylesheets/manpages/docbook.xsl + + evmctl.1.html: README + @asciidoc -o $@ $< diff --git a/dracut-98-integrity.conf b/dracut-98-integrity.conf deleted file mode 100644 index 0996b9a..0000000 --- a/dracut-98-integrity.conf +++ /dev/null @@ -1 +0,0 @@ -add_dracutmodules+=" integrity " diff --git a/ima-add-sigs.sh b/ima-add-sigs.sh deleted file mode 100755 index f0e9dd0..0000000 --- a/ima-add-sigs.sh +++ /dev/null @@ -1,141 +0,0 @@ -#!/bin/bash -# -# This script add IMA signatures to installed RPM package files -usage() { - echo "Add IMA signatures to installed packages." - cat <reinstall_threshold (=20 by default) packages in the RPM - DB missing IMA signatures, reinstalling the packages to add IMA - signatures to the packages. By default, IMA sigatures will be obtained - from the RPM DB. However the RPM DB may not have the signatures. Dectect - this case by checking if there are >reinstall_threshold package missing - IMA signatures. - - --ima_cert - With the signing IMA cert path specified, it will also try to verify the - added IMA signature. - -EOF - exit 1 -} - -for _opt in "$@"; do - case "$_opt" in - --reinstall_threshold=*) - reinstall_threshold=${_opt#*=} - ;; - --package=*) - package=${_opt#*=} - ;; - --ima_cert=*) - ima_cert=${_opt#*=} - ;; - *) - [[ -n $1 ]] && usage - ;; - esac -done - -if [[ -z $package ]] || [[ $package == ALL ]]; then - package="--all" -fi - -abort() { - echo "$1" - exit 1 -} - -get_system_ima_key() { - source /etc/os-release - local -A name_map=(['Fedora Linux']="fedora" ['Red Hat Enterprise Linux']="redhatimarelease" ['CentOS Stream']='centosimarelease') - local version_id - key_name=${name_map[$NAME]} - version_id=${VERSION_ID/.?/} - - [[ $key_name == fedora ]] && name_suffix=-ima - key_path=/etc/keys/ima/${key_name}-${version_id}${name_suffix}.der - if [[ ! -e $key_path ]]; then - echo "Failed to get system IMA code verification key" - exit 1 - fi - - echo -n "$key_path" -} - -# Add IMA signatures from RPM database -add_from_rpm_db() { - if ! command -v setfattr &>/dev/null; then - abort "Please install attr" - fi - - if [[ -e "$ima_cert" ]]; then - verify_ima_cert=$ima_cert - else - verify_ima_cert=$(get_system_ima_key) - fi - - # use "|" as deliminator since it won't be used in a filename or signature - while IFS="|" read -r path sig; do - # [[ -z "$sig" ]] somehow doesn't work for some files that don't have IMA - # signatures. This may be a issue of rpm - if [[ "$sig" != "0"* ]]; then - continue - fi - - # Skip directory, soft links, non-existent files and vfat fs - if [[ -d "$path" || -L "$path" || ! -f "$path" || "$path" == "/boot/efi/EFI/"* ]]; then - continue - fi - - # Skip some files that are created on the fly - if [[ $path == "/usr/share/mime/"* || $path == "/etc/pki/ca-trust/extracted/"* ]]; then - continue - fi - - if ! setfattr -n security.ima "$path" -v "0x$sig"; then - echo "Failed to add IMA sig for $path" - fi - - if ! evmctl ima_verify -k "$verify_ima_cert" "$path" &>/dev/null; then - setfattr -x security.ima "$path" - # When ima_cert is set, shows the verfication result for users - [[ -e "$ima_cert" ]] && "Failed to verify $path" - continue - fi - - done < <(rpm -q --queryformat "[%{FILENAMES}|%{FILESIGNATURES}\n]" "$package") -} - -# Add IMA signatures by reinstalling all packages -add_by_reinstall() { - [[ $package == "--all" ]] && package='*' - dnf reinstall "$package" -yq >/dev/null -} - -if [[ -z $reinstall_threshold ]]; then - if [[ $package == "--all" ]]; then - reinstall_threshold=20 - else - if ! rpm -q --quiet "$package"; then - dnf install "$package" -yq >/dev/null - exit 0 - fi - reinstall_threshold=1 - fi -fi - -unsigned_packages_in_rpm_db=$(rpm -q --queryformat "%{RSAHEADER}\n" "$package" | grep -c "^(none)$") - -if [[ $unsigned_packages_in_rpm_db -ge $reinstall_threshold ]]; then - add_by_reinstall -else - add_from_rpm_db -fi diff --git a/ima-evm-utils.spec b/ima-evm-utils.spec index 29915ec..4754e51 100644 --- a/ima-evm-utils.spec +++ b/ima-evm-utils.spec @@ -1,47 +1,22 @@ -# If the soname gets bumped we need to ship a compat library to be able -# to bootstrap and rebuild rpm else we end up with chicken and egg problem. -%global bootstrap 0 - -%if 0%{bootstrap} -%global compat_soversion 4 -%endif - -Name: ima-evm-utils -Version: 1.6.2 -Release: 7%{?dist} Summary: IMA/EVM support utilities -License: GPL-2.0-or-later -Url: https://github.com/linux-integrity/ -Source0: %{url}/ima-evm-utils/releases/download/v%{version}/%{name}-%{version}.tar.gz - -# IMA setup tools -Source2: dracut-98-integrity.conf -Source3: ima-add-sigs.sh -Source4: ima-setup.sh -Source100: policy-01-appraise-executable-and-lib-signatures -Source101: policy-02-keylime-remote-attestation -Source200: policy_list - -%if 0%{bootstrap} -# compat source and patches -Source10: ima-evm-utils-1.5.tar.gz -BuildRequires: openssl-devel-engine -%endif - -BuildRequires: asciidoc +Name: ima-evm-utils +Version: 1.1 +Release: 4%{?dist} +License: GPLv2 +Url: http://linux-ima.sourceforge.net/ +Source: http://sourceforge.net/projects/linux-ima/files/ima-evm-utils/%{name}-%{version}.tar.gz BuildRequires: autoconf BuildRequires: automake -BuildRequires: gcc -BuildRequires: keyutils-libs-devel BuildRequires: libtool +BuildRequires: m4 +BuildRequires: asciidoc BuildRequires: libxslt -BuildRequires: make BuildRequires: openssl-devel -BuildRequires: tpm2-tss-devel -Requires: %{name}-libs = %{version}-%{release} -Requires: rpm-plugin-ima -Requires: keyutils -Requires: attr +BuildRequires: keyutils-libs-devel +# upstream already solved both issues addressed by patch1 and 2, but it's +# still queued for next release +Patch1: docbook-xsl-path.patch +Patch2: remove-libattr-dependency.patch %description The Trusted Computing Group(TCG) run-time Integrity Measurement Architecture @@ -51,229 +26,42 @@ systems extended attributes. The Extended Verification Module (EVM) prevents unauthorized changes to these extended attributes on the file system. ima-evm-utils is used to prepare the file system for these extended attributes. -%package libs -Summary: Libraries for %{name} -License: LGPL-2.0-or-later - -# to avoid ima-evm-utils and rpm-plugin-ima being installed on upgrade -# to Fedora 41 - https://bugzilla.redhat.com/show_bug.cgi?id=2319827 -Obsoletes: ima-evm-utils < 1.6 - -%description libs -This package contains the libraries for applications to use -ima-evm-utils functionality. - %package devel Summary: Development files for %{name} -Requires: %{name} = %{version}-%{release} -Requires: %{name}-libs = %{version}-%{release} %description devel This package provides the header files for %{name} %prep -%autosetup -p1 - -%if 0%{bootstrap} -mkdir compat/ -pushd compat/ -tar -zxf %{SOURCE10} --strip-components=1 -popd -%endif +%setup -q +%patch1 -p1 +%patch2 -p1 %build -autoreconf -vif -%configure --disable-static --disable-engine -%make_build - -%if 0%{bootstrap} -pushd compat/ -autoreconf -vif -%configure --disable-static --disable-engine -%make_build -popd -%endif +mkdir -p m4 +autoreconf -f -i +%configure --disable-static +make %{?_smp_mflags} %install -%make_install -find %{buildroot} -type f -name "*.la" -delete - -%if 0%{bootstrap} -pushd compat/src/.libs/ -install -p libimaevm.so.%{compat_soversion}.0.0 %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion}.0.0 -ln -s -f %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion}.0.0 %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion} -popd -%endif +make DESTDIR=%{buildroot} install +find %{buildroot}%{_libdir} -type f -name "*.la" -print -delete %ldconfig_scriptlets -# IMA setup tools -install -D -m 644 %{SOURCE2} $RPM_BUILD_ROOT%{_datadir}/ima/dracut-98-integrity.conf - -mkdir -p -m 755 $RPM_BUILD_ROOT%{_datadir}/ima/policies -while IFS= read -r policy_file -do - install -m 644 %{_sourcedir}/policy-"$policy_file" $RPM_BUILD_ROOT%{_datadir}/ima/policies/"$policy_file" -done < %{SOURCE200} - -install -D %{SOURCE3} $RPM_BUILD_ROOT%{_bindir}/ima-add-sigs -install -D %{SOURCE4} $RPM_BUILD_ROOT%{_bindir}/ima-setup - -%files -%license LICENSES.txt COPYING -%doc NEWS README AUTHORS -%{_bindir}/evmctl -%{_mandir}/man1/evmctl* - -# IMA setup tools -%{_datadir}/ima/policies -%{_datadir}/ima/dracut-98-integrity.conf -%{_bindir}/ima-add-sigs -%{_bindir}/ima-setup - -%files libs -%license LICENSES.txt COPYING.LGPL -# if you need to bump the soname version, coordinate with dependent packages -%{_libdir}/libimaevm.so.5* -%if 0%{bootstrap} -%{_libdir}/libimaevm.so.%{compat_soversion}* -%endif - %files devel %{_pkgdocdir}/*.sh -%{_includedir}/imaevm.h +%{_includedir}/* %{_libdir}/libimaevm.so +%files +%doc ChangeLog README AUTHORS +%license COPYING +%{_bindir}/* +%{_libdir}/libimaevm.so.* +%{_mandir}/man1/* + %changelog -* Thu Oct 16 2025 Coiby Xu - 1.6.2-7 -- ima-add-sigs: Use RSAHEADER to tell if a package has been signed - -* Thu Jul 24 2025 Fedora Release Engineering - 1.6.2-6 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild - -* Mon Mar 03 2025 Coiby Xu - 1.6.2-5 -- release 1.6.2-5 - -* Fri Jan 17 2025 Fedora Release Engineering - 1.6.2-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild - -* Thu Oct 31 2024 Coiby Xu - 1.6.2-3 -- Skip unsupported file systems for sample appraisal rule - -* Fri Oct 18 2024 Adam Williamson - 1.6.2-2 -- ima-evm-utils-libs obsoletes ima-evm-utils < 1.6 for rhbz#2319827 - -* Sat Aug 31 2024 Peter Robinson - 1.6.2-1 -- Update to 1.6.2 - -* Fri Aug 30 2024 Peter Robinson - 1.6.1-2 -- Fix sign_hash when built without openssl engine support (rhbz#2297927) - -* Thu Aug 29 2024 Peter Robinson - 1.6.1-1 -- Update to 1.6.1 -- Update project URLs - -* Thu Jul 18 2024 Fedora Release Engineering - 1.6-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild - -* Thu Jul 04 2024 Peter Robinson - 1.6-1 -- Update to 1.6 - -* Wed Jul 03 2024 Peter Robinson - 1.6-0 -- Bootstrap 1.6 -- Update license for new details -- Spec file updates - -* Thu Jun 06 2024 Coiby Xu - 1.5-5 -- add ima-evm-utils-libs subpackage (rpm-sign-libs can depend on ima-evm-utils-libs instead) -- add some IMA setup tools - -* Wed Jan 24 2024 Fedora Release Engineering - 1.5-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Sat Jan 20 2024 Fedora Release Engineering - 1.5-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Thu Jul 20 2023 Fedora Release Engineering - 1.5-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild - -* Thu Jun 08 2023 Peter Robinson - 1.5-1 -- Disable bootstrap - -* Wed Jun 07 2023 Peter Robinson - 1.5-0.1 -- Update to 1.5 -- Streamline bootstrap process a little -- Bootstrap mode -- Update download URL - -* Thu Jan 19 2023 Fedora Release Engineering - 1.4-7 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild - -* Thu Jul 21 2022 Fedora Release Engineering - 1.4-6 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild - -* Thu Jan 20 2022 Fedora Release Engineering - 1.4-5 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild - -* Thu Jan 20 2022 Björn Esser - 1.4-4 -- Build without compat bootstrap sub package - -* Thu Jan 20 2022 Björn Esser - 1.4-3 -- Build with compat bootstrap sub package - -* Tue Jan 18 2022 Peter Robinson - 1.4-2 -- Add compat bootstrap sub package - -* Mon Nov 08 2021 Peter Robinson - 1.4-1 -- Update to 1.4 - -* Tue Sep 14 2021 Sahana Prasad - 1.3.2-4 -- Rebuilt with OpenSSL 3.0.0 - -* Thu Jul 22 2021 Fedora Release Engineering - 1.3.2-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild - -* Tue Jan 26 2021 Fedora Release Engineering - 1.3.2-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild - -* Wed Oct 28 2020 Bruno Meneguele - 1.3.2-1 -- Rebase to new upstream v1.3.2 minor release - -* Tue Aug 11 2020 Bruno Meneguele - 1.3.1-1 -- Rebase to new upstream v1.3.1 minor release - -* Tue Jul 28 2020 Fedora Release Engineering - 1.3-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild - -* Sun Jul 26 2020 Peter Robinson - 1.3-2 -- Fix devel deps - -* Sun Jul 26 2020 Peter Robinson - 1.3-1 -- Update to 1.3 -- Use tpm2-tss instead of tss2 -- Minor spec cleanups - -* Mon Jul 13 2020 Tom Stellard - 1.2.1-4 -- Use make macros -- https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro - -* Wed Jan 29 2020 Fedora Release Engineering - 1.2.1-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild - -* Wed Jul 31 2019 Bruno E. O. Meneguele - 1.2.1-2 -- Add pull request to correct lib soname version, wich was bumped to 1.0.0 - -* Wed Jul 31 2019 Bruno E. O. Meneguele - 1.2.1-1 -- Rebase to upstream v1.2.1 -- Remove both patches that were already solved in upstream version -- Add runtime dependency of tss2 to retrieve PCR bank data from TPM2.0 - -* Thu Jul 25 2019 Fedora Release Engineering - 1.1-6 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild - -* Fri Feb 01 2019 Fedora Release Engineering - 1.1-5 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild - * Fri Jul 20 2018 Bruno E. O. Meneguele - 1.1-4 - Add patch to remove dependency from libattr-devel package diff --git a/ima-setup.sh b/ima-setup.sh deleted file mode 100755 index 1450c0a..0000000 --- a/ima-setup.sh +++ /dev/null @@ -1,134 +0,0 @@ -#!/bin/bash -# -# This script helps set up IMA. -# -IMA_SYSTEMD_POLICY=/etc/ima/ima-policy -IMA_POLICY_SYSFS=/sys/kernel/security/ima/policy - -usage() { - echo "Set up IMA." - cat <reinstall_threshold packages in the RPM DB missing IMA - signatures, reinstalling the packages to add IMA signatures to the - packages. By default, IMA sigatures will be obtained from the RPM DB. - However the RPM DB may not have the signatures. Dectect this case by - checking if there are >reinstall_threshold package missing IMA - signatures. - -EOF - exit 1 -} - -for _opt in "$@"; do - case "$_opt" in - --policy=*) - ima_policy_path=${_opt#*=} - if [[ ! -e $ima_policy_path ]]; then - echo "$ima_policy_path doesn't exist" - exit 1 - fi - ;; - --reinstall_threshold=*) - reinstall_threshold=${_opt#*=} - ;; - *) - usage - ;; - esac -done - -if [[ $# -eq 0 ]]; then - usage -fi - -# Add IMA signatures -if test -f /run/ostree-booted; then - echo "You are using OSTree, please enable IMA signatures as part of the OSTree creation process." -else - echo "Adding IMA signatures to installed package files" - if ! ima-add-sigs --reinstall_threshold="$reinstall_threshold"; then - echo "Failed to add IMA signatures, abort" - exit 1 - fi -fi - -load_ima_keys() { - local _key_loaded - - if line=$(keyctl describe %keyring:.ima); then - _ima_id=${line%%:*} - else - echo "Failed to get ID of the .ima keyring" - exit 1 - fi - - for i in /etc/keys/ima/*; do - if [ ! -f "${i}" ]; then - echo "No IMA key exist" - exit 1 - fi - - if ! evmctl import "${i}" "${_ima_id}" &>/dev/null; then - echo "Failed to load IMA key ${i}" - else - _key_loaded=yes - fi - done - - if [[ $_key_loaded != yes ]]; then - echo "No IMA key loaded" - exit 1 - fi -} - -load_ima_policy() { - local ima_policy_path - - ima_policy_path=$1 - - if ! test -f "$ima_policy_path"; then - echo "$ima_policy_path doesn't exist" - return 1 - fi - if ! echo "$ima_policy_path" >"$IMA_POLICY_SYSFS"; then - echo "$ima_policy_path can't be loaded" - return 1 - fi - # Let systemd load the IMA policy which will load LSM rules first so IMA - # policy containing rules like "appraise obj_type=ifconfig_exec_t" can be - # loaded - [[ -e /etc/ima ]] || mkdir -p /etc/ima/ - if ! cp --preserve=xattr "$ima_policy_path" "$IMA_SYSTEMD_POLICY"; then - echo "Failed to copy $ima_policy_path to $IMA_SYSTEMD_POLICY" - return 1 - fi -} - -echo "Loading IMA keys" -load_ima_keys - -# Include the dracut integrity module to load the IMA keys and policy -# automatically when there is a system reboot -if ! lsinitrd --mod | grep -q integrity; then - cp --preserve=xattr /usr/share/ima/dracut-98-integrity.conf /etc/dracut.conf.d/98-integrity.conf - echo "Regenerating all initramfs images to include the dracut integrity module" - if ! dracut -f --regenerate-all; then - echo "Failed to Regenerate all initramfs images" - exit 1 - fi - [[ $(uname -m) == s390x ]] && zipl &> /dev/null -fi - -if ! load_ima_policy "$ima_policy_path"; then - echo "Failed to load IMA policy $ima_policy_path!" - exit 1 -fi diff --git a/openssl1-1-interface.patch b/openssl1-1-interface.patch new file mode 100644 index 0000000..e00fb2f --- /dev/null +++ b/openssl1-1-interface.patch @@ -0,0 +1,224 @@ +diff -urNp ima-evm-utils-1.0-orig/src/libimaevm.c ima-evm-utils-1.0/src/libimaevm.c +--- ima-evm-utils-1.0-orig/src/libimaevm.c 2015-07-30 15:28:53.000000000 -0300 ++++ ima-evm-utils-1.0/src/libimaevm.c 2017-12-01 12:01:28.008705290 -0200 +@@ -269,7 +269,7 @@ int ima_calc_hash(const char *file, uint + { + const EVP_MD *md; + struct stat st; +- EVP_MD_CTX ctx; ++ EVP_MD_CTX *ctx; + unsigned int mdlen; + int err; + +@@ -286,25 +286,30 @@ int ima_calc_hash(const char *file, uint + return 1; + } + +- err = EVP_DigestInit(&ctx, md); ++ ctx = EVP_MD_CTX_new(); ++ if (!ctx) { ++ log_err("EVP_MD_CTX_new() failed\n"); ++ return 1; ++ } ++ err = EVP_DigestInit_ex(ctx, md, NULL); + if (!err) { +- log_err("EVP_DigestInit() failed\n"); ++ log_err("EVP_DigestInit_ex() failed\n"); + return 1; + } + + switch (st.st_mode & S_IFMT) { + case S_IFREG: +- err = add_file_hash(file, &ctx); ++ err = add_file_hash(file, ctx); + break; + case S_IFDIR: +- err = add_dir_hash(file, &ctx); ++ err = add_dir_hash(file, ctx); + break; + case S_IFLNK: +- err = add_link_hash(file, &ctx); ++ err = add_link_hash(file, ctx); + break; + case S_IFIFO: case S_IFSOCK: + case S_IFCHR: case S_IFBLK: +- err = add_dev_hash(&st, &ctx); ++ err = add_dev_hash(&st, ctx); + break; + default: + log_errno("Unsupported file type"); +@@ -314,11 +319,12 @@ int ima_calc_hash(const char *file, uint + if (err) + return err; + +- err = EVP_DigestFinal(&ctx, hash, &mdlen); ++ err = EVP_DigestFinal_ex(ctx, hash, &mdlen); + if (!err) { +- log_err("EVP_DigestFinal() failed\n"); ++ log_err("EVP_DigestFinal_ex() failed\n"); + return 1; + } ++ EVP_MD_CTX_free(ctx); + + return mdlen; + } +@@ -547,6 +553,7 @@ int key2bin(RSA *key, unsigned char *pub + { + int len, b, offset = 0; + struct pubkey_hdr *pkh = (struct pubkey_hdr *)pub; ++ const BIGNUM *n, *e; + + /* add key header */ + pkh->version = 1; +@@ -556,18 +563,19 @@ int key2bin(RSA *key, unsigned char *pub + + offset += sizeof(*pkh); + +- len = BN_num_bytes(key->n); +- b = BN_num_bits(key->n); ++ RSA_get0_key(key, &n, &e, NULL); ++ len = BN_num_bytes(n); ++ b = BN_num_bits(n); + pub[offset++] = b >> 8; + pub[offset++] = b & 0xff; +- BN_bn2bin(key->n, &pub[offset]); ++ BN_bn2bin(n, &pub[offset]); + offset += len; + +- len = BN_num_bytes(key->e); +- b = BN_num_bits(key->e); ++ len = BN_num_bytes(e); ++ b = BN_num_bits(e); + pub[offset++] = b >> 8; + pub[offset++] = b & 0xff; +- BN_bn2bin(key->e, &pub[offset]); ++ BN_bn2bin(e, &pub[offset]); + offset += len; + + return offset; + +diff -urNp ima-evm-utils-1.0-orig/src/evmctl.c ima-evm-utils-1.0/src/evmctl.c +--- ima-evm-utils-1.0-orig/src/evmctl.c 2015-07-30 15:28:53.000000000 -0300 ++++ ima-evm-utils-1.0/src/evmctl.c 2017-12-01 12:00:39.683306265 -0200 +@@ -305,7 +305,7 @@ static int calc_evm_hash(const char *fil + struct stat st; + int err; + uint32_t generation = 0; +- EVP_MD_CTX ctx; ++ EVP_MD_CTX *ctx; + unsigned int mdlen; + char **xattrname; + char xattr_value[1024]; +@@ -345,9 +345,14 @@ static int calc_evm_hash(const char *fil + return -1; + } + +- err = EVP_DigestInit(&ctx, EVP_sha1()); ++ ctx = EVP_MD_CTX_new(); ++ if (!ctx) { ++ log_err("EVP_MD_CTX_new() failed\n"); ++ return 1; ++ } ++ err = EVP_DigestInit_ex(ctx, EVP_sha1(), NULL); + if (!err) { +- log_err("EVP_DigestInit() failed\n"); ++ log_err("EVP_DigestInit_ex() failed\n"); + return 1; + } + +@@ -364,7 +369,7 @@ static int calc_evm_hash(const char *fil + /*log_debug("name: %s, value: %s, size: %d\n", *xattrname, xattr_value, err);*/ + log_info("name: %s, size: %d\n", *xattrname, err); + log_debug_dump(xattr_value, err); +- err = EVP_DigestUpdate(&ctx, xattr_value, err); ++ err = EVP_DigestUpdate(ctx, xattr_value, err); + if (!err) { + log_err("EVP_DigestUpdate() failed\n"); + return 1; +@@ -412,7 +417,7 @@ static int calc_evm_hash(const char *fil + log_debug("hmac_misc (%d): ", hmac_size); + log_debug_dump(&hmac_misc, hmac_size); + +- err = EVP_DigestUpdate(&ctx, &hmac_misc, hmac_size); ++ err = EVP_DigestUpdate(ctx, &hmac_misc, hmac_size); + if (!err) { + log_err("EVP_DigestUpdate() failed\n"); + return 1; +@@ -423,18 +428,19 @@ static int calc_evm_hash(const char *fil + if (err) + return -1; + +- err = EVP_DigestUpdate(&ctx, (const unsigned char *)uuid, sizeof(uuid)); ++ err = EVP_DigestUpdate(ctx, (const unsigned char *)uuid, sizeof(uuid)); + if (!err) { + log_err("EVP_DigestUpdate() failed\n"); + return 1; + } + } + +- err = EVP_DigestFinal(&ctx, hash, &mdlen); ++ err = EVP_DigestFinal_ex(ctx, hash, &mdlen); + if (!err) { + log_err("EVP_DigestFinal() failed\n"); + return 1; + } ++ EVP_MD_CTX_free(ctx); + + return mdlen; + } +@@ -844,7 +850,7 @@ static int calc_evm_hmac(const char *fil + struct stat st; + int err = -1; + uint32_t generation = 0; +- HMAC_CTX ctx; ++ HMAC_CTX *ctx; + unsigned int mdlen; + char **xattrname; + unsigned char xattr_value[1024]; +@@ -900,10 +906,15 @@ static int calc_evm_hmac(const char *fil + goto out; + } + +- err = !HMAC_Init(&ctx, evmkey, sizeof(evmkey), EVP_sha1()); ++ ctx = HMAC_CTX_new(); ++ if (!ctx) { ++ log_err("HMAC_MD_CTX_new() failed\n"); ++ goto out; ++ } ++ err = !HMAC_Init_ex(ctx, evmkey, sizeof(evmkey), EVP_sha1(), NULL); + if (err) { + log_err("HMAC_Init() failed\n"); +- goto out; ++ goto out_ctx_cleanup; + } + + for (xattrname = evm_config_xattrnames; *xattrname != NULL; xattrname++) { +@@ -919,7 +930,7 @@ static int calc_evm_hmac(const char *fil + /*log_debug("name: %s, value: %s, size: %d\n", *xattrname, xattr_value, err);*/ + log_info("name: %s, size: %d\n", *xattrname, err); + log_debug_dump(xattr_value, err); +- err = !HMAC_Update(&ctx, xattr_value, err); ++ err = !HMAC_Update(ctx, xattr_value, err); + if (err) { + log_err("HMAC_Update() failed\n"); + goto out_ctx_cleanup; +@@ -960,16 +971,16 @@ static int calc_evm_hmac(const char *fil + log_debug("hmac_misc (%d): ", hmac_size); + log_debug_dump(&hmac_misc, hmac_size); + +- err = !HMAC_Update(&ctx, (const unsigned char *)&hmac_misc, hmac_size); ++ err = !HMAC_Update(ctx, (const unsigned char *)&hmac_misc, hmac_size); + if (err) { + log_err("HMAC_Update() failed\n"); + goto out_ctx_cleanup; + } +- err = !HMAC_Final(&ctx, hash, &mdlen); ++ err = !HMAC_Final(ctx, hash, &mdlen); + if (err) + log_err("HMAC_Final() failed\n"); + out_ctx_cleanup: +- HMAC_CTX_cleanup(&ctx); ++ HMAC_CTX_free(ctx); + out: + free(key); + return err ?: mdlen; diff --git a/policy-01-appraise-executable-and-lib-signatures b/policy-01-appraise-executable-and-lib-signatures deleted file mode 100644 index 53feed5..0000000 --- a/policy-01-appraise-executable-and-lib-signatures +++ /dev/null @@ -1,28 +0,0 @@ -# Skip some unsupported filesystems -# This list of the filesystems can be found on -# https://www.kernel.org/doc/Documentation/ABI/testing/ima_policy -# PROC_SUPER_MAGIC -dont_appraise fsmagic=0x9fa0 -# SYSFS_MAGIC -dont_appraise fsmagic=0x62656572 -# DEBUGFS_MAGIC -dont_appraise fsmagic=0x64626720 -# TMPFS_MAGIC -dont_appraise fsmagic=0x01021994 -# RAMFS_MAGIC -dont_appraise fsmagic=0x858458f6 -# DEVPTS_SUPER_MAGIC -dont_appraise fsmagic=0x1cd1 -# BINFMTFS_MAGIC -dont_appraise fsmagic=0x42494e4d -# SECURITYFS_MAGIC -dont_appraise fsmagic=0x73636673 -# SELINUX_MAGIC -dont_appraise fsmagic=0xf97cff8c -# CGROUP_SUPER_MAGIC -dont_appraise fsmagic=0x27e0eb -# NSFS_MAGIC -dont_appraise fsmagic=0x6e736673 - -appraise func=MMAP_CHECK mask=MAY_EXEC appraise_type=imasig -appraise func=BPRM_CHECK appraise_type=imasig diff --git a/policy-02-keylime-remote-attestation b/policy-02-keylime-remote-attestation deleted file mode 100644 index 5210734..0000000 --- a/policy-02-keylime-remote-attestation +++ /dev/null @@ -1,37 +0,0 @@ -# PROC_SUPER_MAGIC -dont_measure fsmagic=0x9fa0 -# SYSFS_MAGIC -dont_measure fsmagic=0x62656572 -# DEBUGFS_MAGIC -dont_measure fsmagic=0x64626720 -# TMPFS_MAGIC -dont_measure fsmagic=0x01021994 -# DEVPTS_SUPER_MAGIC -dont_measure fsmagic=0x1cd1 -# BINFMTFS_MAGIC -dont_measure fsmagic=0x42494e4d -# SECURITYFS_MAGIC -dont_measure fsmagic=0x73636673 -# SELINUX_MAGIC -dont_measure fsmagic=0xf97cff8c -# SMACK_MAGIC -dont_measure fsmagic=0x43415d53 -# CGROUP_SUPER_MAGIC -dont_measure fsmagic=0x27e0eb -# CGROUP2_SUPER_MAGIC -dont_measure fsmagic=0x63677270 -# NSFS_MAGIC -dont_measure fsmagic=0x6e736673 -# EFIVARFS_MAGIC -dont_measure fsmagic=0xde5e81e4 -# OVERLAYFS_MAGIC -# when containers are used we almost always want to ignore them -dont_measure fsmagic=0x794c7630 - - -# Measure and log keys loaded onto the .ima keyring -measure func=KEY_CHECK keyrings=.ima -# Measure and log executables -measure func=BPRM_CHECK -# Measure and log shared libraries -measure func=FILE_MMAP mask=MAY_EXEC diff --git a/policy_list b/policy_list deleted file mode 100644 index af81a74..0000000 --- a/policy_list +++ /dev/null @@ -1,2 +0,0 @@ -01-appraise-executable-and-lib-signatures -02-keylime-remote-attestation diff --git a/remove-libattr-dependency.patch b/remove-libattr-dependency.patch new file mode 100644 index 0000000..0c7a5a0 --- /dev/null +++ b/remove-libattr-dependency.patch @@ -0,0 +1,29 @@ +diff --git a/configure.ac b/configure.ac +index 0497eb7..a5b4288 100644 +--- a/configure.ac ++++ b/configure.ac +@@ -30,7 +30,7 @@ AC_SUBST(OPENSSL_LIBS) + AC_CHECK_HEADER(unistd.h) + AC_CHECK_HEADERS(openssl/conf.h) + +-AC_CHECK_HEADERS(attr/xattr.h, , [AC_MSG_ERROR([attr/xattr.h header not found. You need the libattr development package.])]) ++AC_CHECK_HEADERS(sys/xattr.h, , [AC_MSG_ERROR([sys/xattr.h header not found. You need the c-library development package.])]) + AC_CHECK_HEADERS(keyutils.h, , [AC_MSG_ERROR([keyutils.h header not found. You need the libkeyutils development package.])]) + + #debug support - yes for a while +diff --git a/src/evmctl.c b/src/evmctl.c +index 2ffee78..3fbcd33 100644 +--- a/src/evmctl.c ++++ b/src/evmctl.c +@@ -49,7 +49,7 @@ + #include + #include + #include +-#include ++#include + #include + #include + #include +-- +2.14.4 + diff --git a/sources b/sources index f312ac6..baf9168 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (ima-evm-utils-1.6.2.tar.gz) = dfd82ba7c48c14fd31d687214a2b0cfcf269bdea42d4a0ebc872a72205f880c509ed5c5cd55dec7e94444e6f3bdc3c071ec6c2e3eba1e6579edb8ef11aa158a1 +SHA512 (ima-evm-utils-1.1.tar.gz) = fc7efc890812233db888eef210dc4357bee838b56fd95efd9a9e141d684b0b354670a3c053dd93a94a1402dd826074d4a83a4637c8e6c1d90ead3132354a5776