From e9b8bb75770e1636cb8ee22ceb7f4072ca8ae91e Mon Sep 17 00:00:00 2001 From: Jeremy Cline Date: Tue, 18 Feb 2020 16:37:53 -0500 Subject: [PATCH 01/70] pesign: Apparently opensc got updated and the token name changed All the kernel builds started failing yesterday because the signing token could not be found. Update the token name in the macro shipped by pesign. --- 0028-rpm-Make-the-client-signer-use-the-fedora-values-unl.patch | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/0028-rpm-Make-the-client-signer-use-the-fedora-values-unl.patch b/0028-rpm-Make-the-client-signer-use-the-fedora-values-unl.patch index 3f0b2e1..793fe6c 100644 --- a/0028-rpm-Make-the-client-signer-use-the-fedora-values-unl.patch +++ b/0028-rpm-Make-the-client-signer-use-the-fedora-values-unl.patch @@ -17,7 +17,7 @@ index 69280e9..22a3ee6 100644 %__pesign_token %{nil}%{?pe_signing_token:-t "%{pe_signing_token}"} %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} -+%__pesign_client_token %{!?pe_signing_token:"Fedora Signer (OpenSC Card)"}%{?pe_signing_token:"%{pe_signing_token}"} ++%__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} +%__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} + %_pesign /usr/bin/pesign From f4cb5bfd7e6f20dbae8c9e8accdc0b96a9b81caa Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 18 Feb 2020 17:27:22 -0500 Subject: [PATCH 02/70] Rebuild to match OpenSC's token name mangling change. Signed-off-by: Peter Jones --- pesign.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index 134921a..c29c84f 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 0.112 -Release: 28%{?dist} +Release: 29%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -178,6 +178,9 @@ exit 0 %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Feb 18 2020 Peter Jones - 0.112-29 +- Rebuild to match OpenSC's token name mangling change. + * Thu Jan 30 2020 Fedora Release Engineering - 0.112-28 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild From 6a21c3cf8a8cc92001c0a7fde08bd197dce84d6e Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 18 Feb 2020 17:33:22 -0500 Subject: [PATCH 03/70] Backport a minor fix. Signed-off-by: Peter Jones --- 0031-pesigcheck-Fix-a-wrong-assignment.patch | 49 ++++++++++++++++++++ pesign.spec | 1 + 2 files changed, 50 insertions(+) create mode 100644 0031-pesigcheck-Fix-a-wrong-assignment.patch diff --git a/0031-pesigcheck-Fix-a-wrong-assignment.patch b/0031-pesigcheck-Fix-a-wrong-assignment.patch new file mode 100644 index 0000000..7df5f0b --- /dev/null +++ b/0031-pesigcheck-Fix-a-wrong-assignment.patch @@ -0,0 +1,49 @@ +From c555fd74c009242c3864576bd5f17a1f8f4fdffd Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Tue, 18 Feb 2020 16:28:56 -0500 +Subject: [PATCH] pesigcheck: Fix a wrong assignment + +gcc says: + + pesigcheck.c: In function 'check_signature': + pesigcheck.c:321:17: error: implicit conversion from 'enum ' to 'enum ' [-Werror=enum-conversion] + 321 | reason->type = siBuffer; + | ^ + pesigcheck.c:333:17: error: implicit conversion from 'enum ' to 'enum ' [-Werror=enum-conversion] + 333 | reason->type = siBuffer; + | ^ + cc1: all warnings being treated as errors + +And indeed, that line of code makes no sense at all - it was supposed to +be reason->sig.type. + +Signed-off-by: Peter Jones +--- + src/pesigcheck.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/pesigcheck.c b/src/pesigcheck.c +index 524cce307bf..8fa0f1ad03d 100644 +--- a/src/pesigcheck.c ++++ b/src/pesigcheck.c +@@ -318,7 +318,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons, + reason->type = SIGNATURE; + reason->sig.data = data; + reason->sig.len = datalen; +- reason->type = siBuffer; ++ reason->sig.type = siBuffer; + nreason += 1; + is_invalid = true; + } +@@ -330,7 +330,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons, + reason->type = SIGNATURE; + reason->sig.data = data; + reason->sig.len = datalen; +- reason->type = siBuffer; ++ reason->sig.type = siBuffer; + nreason += 1; + has_valid_cert = true; + } +-- +2.24.1 + diff --git a/pesign.spec b/pesign.spec index c29c84f..4a74aa2 100644 --- a/pesign.spec +++ b/pesign.spec @@ -71,6 +71,7 @@ Patch0027: 0027-Make-pesign-users-groups-static-in-the-repo.patch Patch0028: 0028-rpm-Make-the-client-signer-use-the-fedora-values-unl.patch Patch0029: 0029-Make-macros.pesign-error-in-kojibuilder-if-we-don-t-.patch Patch0030: 0030-efikeygen-Fix-the-build-with-nss-3.44.patch +Patch0031: 0031-pesigcheck-Fix-a-wrong-assignment.patch %description This package contains the pesign utility for signing UEFI binaries as From 9664ede71ce8198c996d8ac2008d8c1fd24aaeba Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 24 Feb 2020 12:48:21 -0500 Subject: [PATCH 04/70] Make sure the patch for -29 is actually in the build in f32, and synchronize with master. Signed-off-by: Peter Jones --- pesign.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index 4a74aa2..f75e1ef 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 0.112 -Release: 29%{?dist} +Release: 30%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -179,6 +179,10 @@ exit 0 %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Mon Feb 24 2020 Peter Jones - 0.112-30 +- Make sure the patch for -29 is actually in the build in f32, and + synchronize with master. + * Tue Feb 18 2020 Peter Jones - 0.112-29 - Rebuild to match OpenSC's token name mangling change. From 6076214dedc6bf9206a8bd43066301728ca9dff5 Mon Sep 17 00:00:00 2001 From: Javier Martinez Canillas Date: Mon, 8 Jun 2020 15:54:08 +0200 Subject: [PATCH 05/70] Switch default NSS database to SQLite format Resolves: rhbz#1827902 Signed-off-by: Javier Martinez Canillas --- ...e-nss-database-everywhere-by-default.patch | 104 ++++++++++++++++++ pesign.spec | 10 +- sources | 4 +- 3 files changed, 115 insertions(+), 3 deletions(-) create mode 100644 0032-Use-sql-type-nss-database-everywhere-by-default.patch diff --git a/0032-Use-sql-type-nss-database-everywhere-by-default.patch b/0032-Use-sql-type-nss-database-everywhere-by-default.patch new file mode 100644 index 0000000..cab7653 --- /dev/null +++ b/0032-Use-sql-type-nss-database-everywhere-by-default.patch @@ -0,0 +1,104 @@ +From c2f2c8845b3ed34da0a76806ec81bc5ad60179ef Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 12 Mar 2018 10:51:24 -0400 +Subject: [PATCH] Use sql-type nss database everywhere by default. + +Signed-off-by: Peter Jones +--- + src/authvar.c | 2 ++ + src/client.c | 3 +++ + src/efikeygen.c | 2 ++ + src/efisiglist.c | 2 ++ + src/pesigcheck.c | 2 ++ + src/pesign.c | 2 ++ + 6 files changed, 13 insertions(+) + +diff --git a/src/authvar.c b/src/authvar.c +index 03e0c47f61c..47a73d12eaa 100644 +--- a/src/authvar.c ++++ b/src/authvar.c +@@ -272,6 +272,8 @@ main(int argc, char *argv[]) + + int action = 0; + ++ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); ++ + rc = authvar_context_init(ctxp); + if (rc < 0) { + fprintf(stderr, "Could not initialize context: %m\n"); +diff --git a/src/client.c b/src/client.c +index 575c873fb70..64e7bbb7689 100644 +--- a/src/client.c ++++ b/src/client.c +@@ -22,6 +22,7 @@ + #include + #include + #include ++#include + #include + #include + #include +@@ -628,6 +629,8 @@ main(int argc, char *argv[]) + POPT_TABLEEND + }; + ++ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); ++ + optCon = poptGetContext("pesign", argc, (const char **)argv, options,0); + + rc = poptReadDefaultConfig(optCon, 0); +diff --git a/src/efikeygen.c b/src/efikeygen.c +index 93905782c0c..ad34970a62d 100644 +--- a/src/efikeygen.c ++++ b/src/efikeygen.c +@@ -595,6 +595,8 @@ int main(int argc, char *argv[]) + POPT_TABLEEND + }; + ++ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); ++ + optCon = poptGetContext("pesign", argc, (const char **)argv, options,0); + + int rc = poptReadDefaultConfig(optCon, 0); +diff --git a/src/efisiglist.c b/src/efisiglist.c +index a7ed528ca13..b88c4a06ded 100644 +--- a/src/efisiglist.c ++++ b/src/efisiglist.c +@@ -177,6 +177,8 @@ main(int argc, char *argv[]) + POPT_TABLEEND + }; + ++ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); ++ + optCon = poptGetContext("pesign", argc, (const char **)argv, options,0); + + rc = poptReadDefaultConfig(optCon, 0); +diff --git a/src/pesigcheck.c b/src/pesigcheck.c +index c8e10860855..535999ca7fa 100644 +--- a/src/pesigcheck.c ++++ b/src/pesigcheck.c +@@ -464,6 +464,8 @@ main(int argc, char *argv[]) + POPT_TABLEEND + }; + ++ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); ++ + rc = pesigcheck_context_init(ctxp); + if (rc < 0) { + fprintf(stderr, "pesigcheck: Could not initialize context: %m\n"); +diff --git a/src/pesign.c b/src/pesign.c +index 6ceda34f797..bc12e4d920a 100644 +--- a/src/pesign.c ++++ b/src/pesign.c +@@ -416,6 +416,8 @@ main(int argc, char *argv[]) + char *certdir = "/etc/pki/pesign"; + char *signum = NULL; + ++ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); ++ + rc = pesign_context_new(&ctxp); + if (rc < 0) { + fprintf(stderr, "Could not initialize context: %m\n"); +-- +2.26.2 + diff --git a/pesign.spec b/pesign.spec index f75e1ef..c5f1044 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 0.112 -Release: 30%{?dist} +Release: 31%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -72,6 +72,7 @@ Patch0028: 0028-rpm-Make-the-client-signer-use-the-fedora-values-unl.patch Patch0029: 0029-Make-macros.pesign-error-in-kojibuilder-if-we-don-t-.patch Patch0030: 0030-efikeygen-Fix-the-build-with-nss-3.44.patch Patch0031: 0031-pesigcheck-Fix-a-wrong-assignment.patch +Patch0032: 0032-Use-sql-type-nss-database-everywhere-by-default.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -145,6 +146,9 @@ exit 0 %postun %systemd_postun_with_restart pesign.service + +%posttrans +certutil -d /etc/pki/pesign/ -X -L > /dev/null %endif %files @@ -179,6 +183,10 @@ exit 0 %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Mon Jun 08 2020 Javier Martinez Canillas - 0.112-31 +- Switch default NSS database to SQLite format (pjones) + Resolves: rhbz#1827902 + * Mon Feb 24 2020 Peter Jones - 0.112-30 - Make sure the patch for -29 is actually in the build in f32, and synchronize with master. diff --git a/sources b/sources index c2671ea..a337e1e 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -e377e0bc924287ee09356a239c5f51a8 certs.tar.xz -eae1d66e160be744ff310ad7592ae31e pesign-0.112.tar.bz2 +SHA512 (certs.tar.xz) = ddac535c786d1a23074534323c4ce89f907d4f82b19c5d3a9c814b145fbac1599cd2386cf20c28d22aee7d5c4db441f052bab9ee655de756117a0a0bc99b525f +SHA512 (pesign-0.112.tar.bz2) = 96bff27ce5059f1ea299c21ac88998a0c17851b8b06ba2f3e286de5cd4d73651b670ac00ca035481faf9c963338527c89120c63ec891a95ce9ecb9130fbc5e5c From 8f36a7851d1f1311e8f94642fbb9b778034e5852 Mon Sep 17 00:00:00 2001 From: Javier Martinez Canillas Date: Thu, 11 Jun 2020 12:03:24 +0200 Subject: [PATCH 06/70] Update to 113 release Resolves: rhbz#1708773 Signed-off-by: Javier Martinez Canillas --- ...e_integer-it-doesn-t-build-on-i686-a.patch | 72 --- ...fikeygen-Fix-the-build-with-nss-3.44.patch | 0 0002-Fix-command-line-parsing.patch | 73 --- ...02-pesigcheck-Fix-a-wrong-assignment.patch | 0 ...gcc-don-t-error-on-stuff-in-includes.patch | 26 -- 0004-Fix-certficate-argument-name.patch | 39 -- ...ion-of-ascii-armor-option-in-manpage.patch | 26 -- ...ke-ascii-work-since-we-documented-it.patch | 22 - ...ient-to-also-accept-token-cert-macro.patch | 32 -- ...fy-with-the-cert-as-an-object-signer.patch | 25 -- ...sigcheck-make-certfile-actually-work.patch | 47 -- ...-make-sure-err-is-always-initialized.patch | 27 -- ...make-pesign-h-tell-you-the-file-name.patch | 26 -- 0012-Add-coverity-build-scripts.patch | 104 ----- 0013-Document-implicit-fallthrough.patch | 25 -- ...cl-each-directory-of-our-key-storage.patch | 50 --- ..._MODULE_SIGNING_ONLY-and-fix-our-arr.patch | 59 --- 0016-efikeygen-add-modsign.patch | 197 -------- ...y-even-harder-to-pick-a-reasonable-v.patch | 121 ----- 0018-show-which-db-we-re-checking.patch | 137 ------ 0019-more-about-the-time.patch | 97 ---- 0020-try-to-say-why-something-fails.patch | 419 ------------------ ...ix-race-condition-in-SEC_GetPassword.patch | 34 -- ...eate-the-socket-directory-at-runtime.patch | 27 -- ...-Better-authorization-scripts.-Again.patch | 217 --------- ...also-try-to-give-better-errors-on-EP.patch | 95 ---- 0025-certdb-fix-PRTime-printfs-for-i686.patch | 31 -- ...-Clean-up-gcc-command-lines-a-little.patch | 41 -- ...sign-users-groups-static-in-the-repo.patch | 54 --- ...ent-signer-use-the-fedora-values-unl.patch | 43 -- ...gn-error-in-kojibuilder-if-we-don-t-.patch | 39 -- ...e-nss-database-everywhere-by-default.patch | 104 ----- pesign.spec | 50 +-- sources | 2 +- 34 files changed, 12 insertions(+), 2349 deletions(-) delete mode 100644 0001-cms-kill-generate_integer-it-doesn-t-build-on-i686-a.patch rename 0030-efikeygen-Fix-the-build-with-nss-3.44.patch => 0001-efikeygen-Fix-the-build-with-nss-3.44.patch (100%) delete mode 100644 0002-Fix-command-line-parsing.patch rename 0031-pesigcheck-Fix-a-wrong-assignment.patch => 0002-pesigcheck-Fix-a-wrong-assignment.patch (100%) delete mode 100644 0003-gcc-don-t-error-on-stuff-in-includes.patch delete mode 100644 0004-Fix-certficate-argument-name.patch delete mode 100644 0005-Fix-description-of-ascii-armor-option-in-manpage.patch delete mode 100644 0006-Make-ascii-work-since-we-documented-it.patch delete mode 100644 0007-Switch-pesign-client-to-also-accept-token-cert-macro.patch delete mode 100644 0008-pesigcheck-Verify-with-the-cert-as-an-object-signer.patch delete mode 100644 0009-pesigcheck-make-certfile-actually-work.patch delete mode 100644 0010-signerInfos-make-sure-err-is-always-initialized.patch delete mode 100644 0011-pesign-make-pesign-h-tell-you-the-file-name.patch delete mode 100644 0012-Add-coverity-build-scripts.patch delete mode 100644 0013-Document-implicit-fallthrough.patch delete mode 100644 0014-Actually-setfacl-each-directory-of-our-key-storage.patch delete mode 100644 0015-oid-add-SHIM_EKU_MODULE_SIGNING_ONLY-and-fix-our-arr.patch delete mode 100644 0016-efikeygen-add-modsign.patch delete mode 100644 0017-check_cert_db-try-even-harder-to-pick-a-reasonable-v.patch delete mode 100644 0018-show-which-db-we-re-checking.patch delete mode 100644 0019-more-about-the-time.patch delete mode 100644 0020-try-to-say-why-something-fails.patch delete mode 100644 0021-Fix-race-condition-in-SEC_GetPassword.patch delete mode 100644 0022-sysvinit-Create-the-socket-directory-at-runtime.patch delete mode 100644 0023-Better-authorization-scripts.-Again.patch delete mode 100644 0024-Make-the-daemon-also-try-to-give-better-errors-on-EP.patch delete mode 100644 0025-certdb-fix-PRTime-printfs-for-i686.patch delete mode 100644 0026-Clean-up-gcc-command-lines-a-little.patch delete mode 100644 0027-Make-pesign-users-groups-static-in-the-repo.patch delete mode 100644 0028-rpm-Make-the-client-signer-use-the-fedora-values-unl.patch delete mode 100644 0029-Make-macros.pesign-error-in-kojibuilder-if-we-don-t-.patch delete mode 100644 0032-Use-sql-type-nss-database-everywhere-by-default.patch diff --git a/0001-cms-kill-generate_integer-it-doesn-t-build-on-i686-a.patch b/0001-cms-kill-generate_integer-it-doesn-t-build-on-i686-a.patch deleted file mode 100644 index 0c82dcf..0000000 --- a/0001-cms-kill-generate_integer-it-doesn-t-build-on-i686-a.patch +++ /dev/null @@ -1,72 +0,0 @@ -From 33bcca8303cad962606df3bfc6a031a9b0626375 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Thu, 21 Apr 2016 10:47:34 -0400 -Subject: [PATCH 01/29] cms: kill generate_integer(), it doesn't build on i686 - and it's unused. - -Signed-off-by: Peter Jones ---- - src/cms_common.c | 34 ---------------------------------- - src/cms_common.h | 1 - - 2 files changed, 35 deletions(-) - -diff --git a/src/cms_common.c b/src/cms_common.c -index b19bc62..6a4e6a7 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -641,40 +641,6 @@ generate_string(cms_context *cms, SECItem *der, char *str) - return 0; - } - --static SEC_ASN1Template IntegerTemplate[] = { -- {.kind = SEC_ASN1_INTEGER, -- .offset = 0, -- .sub = NULL, -- .size = sizeof(long), -- }, -- { 0 }, --}; -- --int --generate_integer(cms_context *cms, SECItem *der, unsigned long integer) --{ -- void *ret; -- -- uint32_t u32; -- -- SECItem input = { -- .data = (void *)&integer, -- .len = sizeof(integer), -- .type = siUnsignedInteger, -- }; -- -- if (integer < 0x100000000) { -- u32 = integer & 0xffffffffUL; -- input.data = (void *)&u32; -- input.len = sizeof(u32); -- } -- -- ret = SEC_ASN1EncodeItem(cms->arena, der, &input, IntegerTemplate); -- if (ret == NULL) -- cmsreterr(-1, cms, "could not encode data"); -- return 0; --} -- - int - generate_time(cms_context *cms, SECItem *encoded, time_t when) - { -diff --git a/src/cms_common.h b/src/cms_common.h -index 7d77faf..c7d7268 100644 ---- a/src/cms_common.h -+++ b/src/cms_common.h -@@ -117,7 +117,6 @@ extern int generate_object_id(cms_context *ctx, SECItem *encoded, - SECOidTag tag); - extern int generate_empty_sequence(cms_context *ctx, SECItem *encoded); - extern int generate_time(cms_context *ctx, SECItem *encoded, time_t when); --extern int generate_integer(cms_context *cms, SECItem *der, unsigned long integer); - extern int generate_string(cms_context *cms, SECItem *der, char *str); - extern int wrap_in_set(cms_context *cms, SECItem *der, SECItem **items); - extern int wrap_in_seq(cms_context *cms, SECItem *der, --- -2.13.4 - diff --git a/0030-efikeygen-Fix-the-build-with-nss-3.44.patch b/0001-efikeygen-Fix-the-build-with-nss-3.44.patch similarity index 100% rename from 0030-efikeygen-Fix-the-build-with-nss-3.44.patch rename to 0001-efikeygen-Fix-the-build-with-nss-3.44.patch diff --git a/0002-Fix-command-line-parsing.patch b/0002-Fix-command-line-parsing.patch deleted file mode 100644 index 9c03eeb..0000000 --- a/0002-Fix-command-line-parsing.patch +++ /dev/null @@ -1,73 +0,0 @@ -From 5be0515dee24308fd7e270bf2e0fb5e5a7a78f32 Mon Sep 17 00:00:00 2001 -From: Julien Cristau -Date: Thu, 9 Jun 2016 14:30:37 +0200 -Subject: [PATCH 02/29] Fix command line parsing - -The gettext translation domain should be passed as .arg, not .descrip, -otherwise popt won't process any of the command line options (it stops -looping over the struct poptOption array when an entry has unset -longName, shortName and arg). - -Signed-off-by: Julien Cristau ---- - src/client.c | 2 +- - src/efikeygen.c | 2 +- - src/efisiglist.c | 2 +- - src/pesigcheck.c | 2 +- - 4 files changed, 4 insertions(+), 4 deletions(-) - -diff --git a/src/client.c b/src/client.c -index 028419f..575c873 100644 ---- a/src/client.c -+++ b/src/client.c -@@ -555,7 +555,7 @@ main(int argc, char *argv[]) - - struct poptOption options[] = { - {.argInfo = POPT_ARG_INTL_DOMAIN, -- .descrip = "pesign" }, -+ .arg = "pesign" }, - {.longName = "token", - .shortName = 't', - .argInfo = POPT_ARG_STRING|POPT_ARGFLAG_SHOW_DEFAULT, -diff --git a/src/efikeygen.c b/src/efikeygen.c -index 6278849..8a515a5 100644 ---- a/src/efikeygen.c -+++ b/src/efikeygen.c -@@ -486,7 +486,7 @@ int main(int argc, char *argv[]) - poptContext optCon; - struct poptOption options[] = { - {.argInfo = POPT_ARG_INTL_DOMAIN, -- .descrip = "pesign" }, -+ .arg = "pesign" }, - /* global nss-ish things */ - {.longName = "dbdir", - .shortName = 'd', -diff --git a/src/efisiglist.c b/src/efisiglist.c -index cd3f1ae..40d6a93 100644 ---- a/src/efisiglist.c -+++ b/src/efisiglist.c -@@ -126,7 +126,7 @@ main(int argc, char *argv[]) - - struct poptOption options[] = { - {.argInfo = POPT_ARG_INTL_DOMAIN, -- .descrip = "pesign" }, -+ .arg = "pesign" }, - {.longName = "infile", - .shortName = 'i', - .argInfo = POPT_ARG_STRING, -diff --git a/src/pesigcheck.c b/src/pesigcheck.c -index 1328fe9..0d49c1a 100644 ---- a/src/pesigcheck.c -+++ b/src/pesigcheck.c -@@ -214,7 +214,7 @@ main(int argc, char *argv[]) - poptContext optCon; - struct poptOption options[] = { - {.argInfo = POPT_ARG_INTL_DOMAIN, -- .descrip = "pesign" }, -+ .arg = "pesign" }, - {.longName = "dbfile", - .shortName = 'D', - .argInfo = POPT_ARG_CALLBACK|POPT_CBFLAG_POST, --- -2.13.4 - diff --git a/0031-pesigcheck-Fix-a-wrong-assignment.patch b/0002-pesigcheck-Fix-a-wrong-assignment.patch similarity index 100% rename from 0031-pesigcheck-Fix-a-wrong-assignment.patch rename to 0002-pesigcheck-Fix-a-wrong-assignment.patch diff --git a/0003-gcc-don-t-error-on-stuff-in-includes.patch b/0003-gcc-don-t-error-on-stuff-in-includes.patch deleted file mode 100644 index cf4e61d..0000000 --- a/0003-gcc-don-t-error-on-stuff-in-includes.patch +++ /dev/null @@ -1,26 +0,0 @@ -From 6de291458cbab99bcc317e282c16e1523d6de9b8 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Wed, 10 Aug 2016 17:12:39 -0400 -Subject: [PATCH 03/29] gcc: don't error on stuff in includes. - -Signed-off-by: Peter Jones ---- - Make.defaults | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/Make.defaults b/Make.defaults -index c97b452..3511080 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -19,7 +19,7 @@ PKG_CONFIG = $(CROSS_COMPILE)pkg-config - CC := $(if $(filter default,$(origin CC)),$(CROSS_COMPILE)gcc,$(CC)) - CCLD := $(if $(filter undefined,$(origin CCLD)),$(CC),$(CCLD)) - CFLAGS ?= -O0 -g3 -fvar-tracking -fvar-tracking-assignments \ -- -Wall -Werror -Wextra -+ -Wall -Werror -Wextra -Wno-error=cpp - AS := $(CROSS_COMPILE)as - AR := $(CROSS_COMPILE)gcc-ar - RANLIB := $(CROSS_COMPILE)gcc-ranlib --- -2.13.4 - diff --git a/0004-Fix-certficate-argument-name.patch b/0004-Fix-certficate-argument-name.patch deleted file mode 100644 index 08509ff..0000000 --- a/0004-Fix-certficate-argument-name.patch +++ /dev/null @@ -1,39 +0,0 @@ -From b20fc54c08e8afe1365e56cacade3ec39984da8d Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 18 Apr 2017 19:00:34 -0400 -Subject: [PATCH 04/29] Fix "certficate" argument name. - -This fixes our typoed argument name by making the incorrectly spelled -version be a popt alias, and fixing the real implementation to be -spelled right in pesign.c . - -Signed-off-by: Peter Jones ---- - src/pesign.c | 2 +- - src/pesign.popt | 1 + - 2 files changed, 2 insertions(+), 1 deletion(-) - -diff --git a/src/pesign.c b/src/pesign.c -index af374b6..279a17a 100644 ---- a/src/pesign.c -+++ b/src/pesign.c -@@ -438,7 +438,7 @@ main(int argc, char *argv[]) - .arg = &ctxp->outfile, - .descrip = "specify output file", - .argDescrip = "" }, -- {.longName = "certficate", -+ {.longName = "certificate", - .shortName = 'c', - .argInfo = POPT_ARG_STRING, - .arg = &certname, -diff --git a/src/pesign.popt b/src/pesign.popt -index 7b3385d..5a97748 100644 ---- a/src/pesign.popt -+++ b/src/pesign.popt -@@ -1,2 +1,3 @@ - pesign alias --cert --certificate -+pesign alias --certficate --certificate - pesign alias --daemon --daemonize --- -2.13.4 - diff --git a/0005-Fix-description-of-ascii-armor-option-in-manpage.patch b/0005-Fix-description-of-ascii-armor-option-in-manpage.patch deleted file mode 100644 index 6a5b02d..0000000 --- a/0005-Fix-description-of-ascii-armor-option-in-manpage.patch +++ /dev/null @@ -1,26 +0,0 @@ -From 7bc8e8b04c74be5c4e0ebf211affc37cf9f5db37 Mon Sep 17 00:00:00 2001 -From: Julien Cristau -Date: Mon, 27 Jun 2016 15:38:38 +0200 -Subject: [PATCH 05/29] Fix description of --ascii-armor option in manpage - -The --ascii option does not exist. ---- - src/pesign.1 | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/pesign.1 b/src/pesign.1 -index 47d1aec..29ae060 100644 ---- a/src/pesign.1 -+++ b/src/pesign.1 -@@ -81,7 +81,7 @@ Export the public key specified by \-\-certificate to \fIoutkey\fR - Export the certificate specified by \-\-certificate to \fIoutcert\fR - - .TP --\fB-\-ascii\fR -+\fB-\-ascii\-armor\fR - Use ascii armoring on exported certificates. - - .TP --- -2.13.4 - diff --git a/0006-Make-ascii-work-since-we-documented-it.patch b/0006-Make-ascii-work-since-we-documented-it.patch deleted file mode 100644 index d0165f9..0000000 --- a/0006-Make-ascii-work-since-we-documented-it.patch +++ /dev/null @@ -1,22 +0,0 @@ -From 9f411f4e797e983d2e8cb51dc5b9ab8db250c2e3 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 18 Apr 2017 19:05:40 -0400 -Subject: [PATCH 06/29] Make --ascii work, since we documented it. - -Signed-off-by: Peter Jones ---- - src/pesign.popt | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/src/pesign.popt b/src/pesign.popt -index 5a97748..5ae0c5c 100644 ---- a/src/pesign.popt -+++ b/src/pesign.popt -@@ -1,3 +1,4 @@ - pesign alias --cert --certificate - pesign alias --certficate --certificate - pesign alias --daemon --daemonize -+pesign alias --ascii --ascii-armor --- -2.13.4 - diff --git a/0007-Switch-pesign-client-to-also-accept-token-cert-macro.patch b/0007-Switch-pesign-client-to-also-accept-token-cert-macro.patch deleted file mode 100644 index faa78ec..0000000 --- a/0007-Switch-pesign-client-to-also-accept-token-cert-macro.patch +++ /dev/null @@ -1,32 +0,0 @@ -From d618de733865eab359890b4e677c368a133dad99 Mon Sep 17 00:00:00 2001 -From: Pat Riehecky -Date: Mon, 7 Nov 2016 11:37:08 -0600 -Subject: [PATCH 07/29] Switch pesign client to also accept token/cert macros - rather than use hard coded values - ---- - src/macros.pesign | 6 +++--- - 1 file changed, 3 insertions(+), 3 deletions(-) - -diff --git a/src/macros.pesign b/src/macros.pesign -index 18e5b5e..69280e9 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -41,11 +41,11 @@ - --certdir ${nss} -c signer %{-o} \ - rm -rf ${sattrs} ${sattrs}.sig ${nss} \ - elif [ -S /var/run/pesign/socket ]; then \ -- %{_pesign_client} -t "OpenSC Card (Fedora Signer)" \\\ -- -c "/CN=Fedora Secure Boot Signer" \\\ -+ %{_pesign_client} -t %{__pesign_token} \\\ -+ -c %{__pesign_cert} \\\ - %{-i} %{-o} %{-e} %{-s} %{-C} \ - else \ -- %{_pesign} %{__pesign_token} -c %{__pesign_cert} \\\ -+ %{_pesign} -t %{__pesign_token} -c %{__pesign_cert} \\\ - --certdir ${_pesign_nssdir} \\\ - %{-i} %{-o} %{-e} %{-s} %{-C} \ - fi \ --- -2.13.4 - diff --git a/0008-pesigcheck-Verify-with-the-cert-as-an-object-signer.patch b/0008-pesigcheck-Verify-with-the-cert-as-an-object-signer.patch deleted file mode 100644 index 2226498..0000000 --- a/0008-pesigcheck-Verify-with-the-cert-as-an-object-signer.patch +++ /dev/null @@ -1,25 +0,0 @@ -From 2cd211bcc612ad8cb99c778461ca02a9f3e5e44b Mon Sep 17 00:00:00 2001 -From: David Michael -Date: Thu, 16 Feb 2017 15:08:30 -0800 -Subject: [PATCH 08/29] pesigcheck: Verify with the cert as an object signer - ---- - src/certdb.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/certdb.c b/src/certdb.c -index 2a08042..b7c99bb 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -339,7 +339,7 @@ check_cert(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - } - /* Verify the signature */ - result = SEC_PKCS7VerifyDetachedSignatureAtTime(cinfo, -- certUsageSSLServer, -+ certUsageObjectSigner, - digest, HASH_AlgSHA256, - PR_FALSE, atTime); - if (!result) { --- -2.13.4 - diff --git a/0009-pesigcheck-make-certfile-actually-work.patch b/0009-pesigcheck-make-certfile-actually-work.patch deleted file mode 100644 index 8b77417..0000000 --- a/0009-pesigcheck-make-certfile-actually-work.patch +++ /dev/null @@ -1,47 +0,0 @@ -From e0238e2363f9668aee07b2e44a8f358e694551c0 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 24 Apr 2017 15:18:10 -0400 -Subject: [PATCH 09/29] pesigcheck: make --certfile actually work - -Signed-off-by: Peter Jones ---- - src/pesigcheck.c | 9 +++++++-- - 1 file changed, 7 insertions(+), 2 deletions(-) - -diff --git a/src/pesigcheck.c b/src/pesigcheck.c -index 0d49c1a..d7be542 100644 ---- a/src/pesigcheck.c -+++ b/src/pesigcheck.c -@@ -130,7 +130,7 @@ check_signature(pesigcheck_context *ctx) - cert_iter iter; - - generate_digest(ctx->cms_ctx, ctx->inpe, 1); -- -+ - if (check_db_hash(DBX, ctx) == FOUND) - return -1; - -@@ -225,6 +225,11 @@ main(int argc, char *argv[]) - .argInfo = POPT_ARG_CALLBACK|POPT_CBFLAG_POST, - .arg = (void *)callback, - .descrip = (void *)ctxp }, -+ {.longName = "certfile", -+ .shortName = 'c', -+ .argInfo = POPT_ARG_CALLBACK|POPT_CBFLAG_POST, -+ .arg = (void *)callback, -+ .descrip = (void *)ctxp }, - {.longName = "in", - .shortName = 'i', - .argInfo = POPT_ARG_STRING, -@@ -258,7 +263,7 @@ main(int argc, char *argv[]) - .shortName = 'c', - .argInfo = POPT_ARG_STRING, - .arg = &certfile, -- .descrip = "the certificate (in DER form) for verification ", -+ .descrip = "import certfile (in DER encoding) for allowed certificate", - .argDescrip = "" }, - POPT_AUTOALIAS - POPT_AUTOHELP --- -2.13.4 - diff --git a/0010-signerInfos-make-sure-err-is-always-initialized.patch b/0010-signerInfos-make-sure-err-is-always-initialized.patch deleted file mode 100644 index 08d1da7..0000000 --- a/0010-signerInfos-make-sure-err-is-always-initialized.patch +++ /dev/null @@ -1,27 +0,0 @@ -From 799808b265ac6f82fa1268fd696d70357acce69c Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 25 Apr 2017 16:15:07 -0400 -Subject: [PATCH 10/29] signerInfos: make sure err is always initialized - -Signed-off-by: Peter Jones ---- - src/signed_data.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/src/signed_data.c b/src/signed_data.c -index 721db90..9e0af23 100644 ---- a/src/signed_data.c -+++ b/src/signed_data.c -@@ -132,7 +132,8 @@ int - generate_signerInfo_list(cms_context *cms, SpcSignerInfo ***signerInfo_list_p, SignerInfoType type) - { - SpcSignerInfo **signerInfo_list; -- int err, rc; -+ int err = 0; -+ int rc; - - if (!signerInfo_list_p) - return -1; --- -2.13.4 - diff --git a/0011-pesign-make-pesign-h-tell-you-the-file-name.patch b/0011-pesign-make-pesign-h-tell-you-the-file-name.patch deleted file mode 100644 index 3e15617..0000000 --- a/0011-pesign-make-pesign-h-tell-you-the-file-name.patch +++ /dev/null @@ -1,26 +0,0 @@ -From 868b42b338d919917ea31cfbf0f96e9586947eaf Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 25 Apr 2017 16:23:36 -0400 -Subject: [PATCH 11/29] pesign: make "pesign -h" tell you the file name. - -Signed-off-by: Peter Jones ---- - src/pesign.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/pesign.c b/src/pesign.c -index 279a17a..5879cfc 100644 ---- a/src/pesign.c -+++ b/src/pesign.c -@@ -387,7 +387,7 @@ print_digest(pesign_context *pctx) - if (!ctx) - return; - -- printf("hash: "); -+ printf("%s ", pctx->infile); - int j = ctx->selected_digest; - for (unsigned int i = 0; i < ctx->digests[j].pe_digest->len; i++) - printf("%02x", --- -2.13.4 - diff --git a/0012-Add-coverity-build-scripts.patch b/0012-Add-coverity-build-scripts.patch deleted file mode 100644 index f3f0a89..0000000 --- a/0012-Add-coverity-build-scripts.patch +++ /dev/null @@ -1,104 +0,0 @@ -From 95327e6d9bd4f70980acd8fd6c9524265990dc4d Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Wed, 10 May 2017 10:49:57 -0400 -Subject: [PATCH 12/29] Add coverity build scripts - -Signed-off-by: Peter Jones ---- - .gitignore | 1 + - Make.coverity | 37 +++++++++++++++++++++++++++++++++++++ - Make.defaults | 2 ++ - Make.rules | 4 ++++ - Makefile | 1 + - 5 files changed, 45 insertions(+) - create mode 100644 Make.coverity - -diff --git a/.gitignore b/.gitignore -index 1635ba2..847e172 100644 ---- a/.gitignore -+++ b/.gitignore -@@ -12,3 +12,4 @@ - *.tar.* - *.rpm - core.* -+cov-int -diff --git a/Make.coverity b/Make.coverity -new file mode 100644 -index 0000000..b80b091 ---- /dev/null -+++ b/Make.coverity -@@ -0,0 +1,37 @@ -+include $(TOPDIR)/Make.version -+include $(TOPDIR)/Make.rules -+include $(TOPDIR)/Make.defaults -+ -+COV_EMAIL=$(call get-config,coverity.email) -+COV_TOKEN=$(call get-config,coverity.token) -+COV_URL=$(call get-config,coverity.url) -+COV_FILE=$(NAME)-coverity-$(VERSION)-$(COMMIT_ID).tar.bz2 -+ -+cov-int : clean -+ cov-build --dir cov-int make all -+ -+cov-clean : -+ @rm -vf $(NAME)-coverity-*.tar.* -+ @if [[ -d cov-int ]]; then rm -rf cov-int && echo "removed 'cov-int'"; fi -+ -+cov-file : | $(COV_FILE) -+ -+$(COV_FILE) : cov-int -+ tar caf $@ cov-int -+ -+cov-upload : -+ @if [[ -n "$(COV_URL)" ]] && \ -+ [[ -n "$(COV_TOKEN)" ]] && \ -+ [[ -n "$(COV_EMAIL)" ]] ; \ -+ then \ -+ echo curl --form token=$(COV_TOKEN) --form email="$(COV_EMAIL)" --form file=@"$(COV_FILE)" --form version=$(VERSION).1 --form description="$(COMMIT_ID)" "$(COV_URL)" ; \ -+ curl --form token=$(COV_TOKEN) --form email="$(COV_EMAIL)" --form file=@"$(COV_FILE)" --form version=$(VERSION).1 --form description="$(COMMIT_ID)" "$(COV_URL)" ; \ -+ else \ -+ echo Coverity output is in $(COV_FILE) ; \ -+ fi -+ -+coverity : cov-file cov-upload -+ -+clean : | cov-clean -+ -+.PHONY : coverity cov-upload cov-clean cov-file -diff --git a/Make.defaults b/Make.defaults -index 3511080..39b78f0 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -1,3 +1,5 @@ -+NAME = pesign -+COMMIT_ID ?= $(shell git log -1 --pretty=%H 2>/dev/null || echo master) - prefix ?= /usr/ - prefix := $(abspath $(prefix))/ - libdir ?= $(prefix)lib64/ -diff --git a/Make.rules b/Make.rules -index af5ecfe..5e3c83d 100644 ---- a/Make.rules -+++ b/Make.rules -@@ -79,3 +79,7 @@ endef - - $(TOPDIR)/libdpe/%.a $(TOPDIR)/libdpe/% : - $(MAKE) -C $(TOPDIR)/libdpe $(notdir $@) -+ -+define get-config = -+$(shell git config --local --get "$(NAME).$(1)") -+endef -diff --git a/Makefile b/Makefile -index db8eb7e..ca1a359 100644 ---- a/Makefile -+++ b/Makefile -@@ -4,6 +4,7 @@ TOPDIR = $(realpath .) - include $(TOPDIR)/Make.version - include $(TOPDIR)/Make.rules - include $(TOPDIR)/Make.defaults -+include $(TOPDIR)/Make.coverity - - SUBDIRS := include libdpe src - --- -2.13.4 - diff --git a/0013-Document-implicit-fallthrough.patch b/0013-Document-implicit-fallthrough.patch deleted file mode 100644 index 3731a3f..0000000 --- a/0013-Document-implicit-fallthrough.patch +++ /dev/null @@ -1,25 +0,0 @@ -From 4b9e7cf3e869de36daf2ea705b9efef55ae87ef8 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Sat, 8 Jul 2017 16:31:18 -0400 -Subject: [PATCH 13/29] Document implicit fallthrough. - -Signed-off-by: Peter Jones ---- - src/authvar.c | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/src/authvar.c b/src/authvar.c -index ad659ca..03e0c47 100644 ---- a/src/authvar.c -+++ b/src/authvar.c -@@ -511,6 +511,7 @@ main(int argc, char *argv[]) - case IMPORT|SET: - case IMPORT|SIGN|SET: - fprintf(stderr, "authvar: not implemented\n"); -+ /* fallthrough. */ - case IMPORT|SIGN|EXPORT: - default: - fprintf(stderr, "authvar: invalid flags: "); --- -2.13.4 - diff --git a/0014-Actually-setfacl-each-directory-of-our-key-storage.patch b/0014-Actually-setfacl-each-directory-of-our-key-storage.patch deleted file mode 100644 index 4b62cb3..0000000 --- a/0014-Actually-setfacl-each-directory-of-our-key-storage.patch +++ /dev/null @@ -1,50 +0,0 @@ -From a95e28e5cb10d417c81c8720e8521eb63793da37 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 16 May 2016 15:25:53 -0400 -Subject: [PATCH 14/29] Actually setfacl /each/ directory of our key storage. - -Signed-off-by: Peter Jones ---- - src/pesign-authorize-groups | 6 +++--- - src/pesign-authorize-users | 6 +++--- - 2 files changed, 6 insertions(+), 6 deletions(-) - -diff --git a/src/pesign-authorize-groups b/src/pesign-authorize-groups -index a4f895e..cf51fb6 100644 ---- a/src/pesign-authorize-groups -+++ b/src/pesign-authorize-groups -@@ -18,10 +18,10 @@ if [ -r /etc/pesign/groups ]; then - setfacl -m g:${group}:rw /var/run/pesign/socket - fi - fi -- for x in /etc/pki/pesign* ; do -+ for x in /etc/pki/pesign*/ ; do - if [ -d ${x} ]; then -- setfacl -m g:${group}:rx /etc/pki/pesign -- for y in ${x}/{cert8,key3,secmod}.db ; do -+ setfacl -m g:${group}:rx ${x} -+ for y in ${x}{cert8,key3,secmod}.db ; do - setfacl -m g:${group}:rw ${y} - done - fi -diff --git a/src/pesign-authorize-users b/src/pesign-authorize-users -index 8b9a885..940138e 100644 ---- a/src/pesign-authorize-users -+++ b/src/pesign-authorize-users -@@ -18,10 +18,10 @@ if [ -r /etc/pesign/users ]; then - setfacl -m g:${username}:rw /var/run/pesign/socket - fi - fi -- for x in /etc/pki/pesign* ; do -+ for x in /etc/pki/pesign*/ ; do - if [ -d ${x} ]; then -- setfacl -m g:${username}:rx /etc/pki/pesign -- for y in ${x}/{cert8,key3,secmod}.db ; do -+ setfacl -m g:${username}:rx ${x} -+ for y in ${x}{cert8,key3,secmod}.db ; do - setfacl -m g:${username}:rw ${y} - done - fi --- -2.13.4 - diff --git a/0015-oid-add-SHIM_EKU_MODULE_SIGNING_ONLY-and-fix-our-arr.patch b/0015-oid-add-SHIM_EKU_MODULE_SIGNING_ONLY-and-fix-our-arr.patch deleted file mode 100644 index d5428b5..0000000 --- a/0015-oid-add-SHIM_EKU_MODULE_SIGNING_ONLY-and-fix-our-arr.patch +++ /dev/null @@ -1,59 +0,0 @@ -From a3cc2ad5d49ed61187527281da351e80d8f76a89 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 22 Aug 2016 13:31:38 -0400 -Subject: [PATCH 15/29] oid: add SHIM_EKU_MODULE_SIGNING_ONLY and fix our array - indices. - -That was all kinds of wrong. - -Signed-off-by: Peter Jones ---- - src/oid.c | 10 +++++++--- - src/oid.h | 1 + - 2 files changed, 8 insertions(+), 3 deletions(-) - -diff --git a/src/oid.c b/src/oid.c -index 9d8154f..7037e1e 100644 ---- a/src/oid.c -+++ b/src/oid.c -@@ -33,6 +33,7 @@ static uint8_t oiddata[] = { - 0x2b, 0x06, 0x01, 0x04, 0x01, 0x82, 0x37, 0x02, 0x01, 0x0f, - 0x2b, 0x06, 0x01, 0x04, 0x01, 0x82, 0x37, 0x02, 0x01, 0x15, - 0x2b, 0x06, 0x01, 0x04, 0x01, 0x82, 0x37, 0x15, 0x01, -+ 0x2b, 0x06, 0x01, 0x04, 0x01, 0x92, 0x08, 0x10, 0x01, 0x02, - }; - - #define OID(num, desc_s, oidtype, length, value) \ -@@ -53,11 +54,14 @@ static struct { - OID(SPC_STATEMENT_TYPE_OBJID, "Statement Type", siDEROID, 10, - &oiddata[10]), - OID(SPC_PE_IMAGE_DATA_OBJID, "PE Image Data", siDEROID, 10, -- &oiddata[30]), -+ &oiddata[20]), - OID(SPC_INDIVIDUAL_SP_KEY_PURPOSE_OBJID, "Individual Key", siDEROID, -- 10, &oiddata[40]), -+ 10, &oiddata[30]), - OID(szOID_CERTSRV_CA_VERSION, "Certification server CA version", -- siAsciiString, 9, &oiddata[50]), -+ siAsciiString, 9, &oiddata[40]), -+ OID(SHIM_EKU_MODULE_SIGNING_ONLY, -+ "Certificate is used for kernel modules only", siDEROID, 10, -+ &oiddata[49]), - { .oid = END_OID_LIST } - }; - -diff --git a/src/oid.h b/src/oid.h -index 599f49d..0e00781 100644 ---- a/src/oid.h -+++ b/src/oid.h -@@ -25,6 +25,7 @@ typedef enum { - SPC_PE_IMAGE_DATA_OBJID, /* 1.3.6.1.4.1.311.2.1.15 */ - SPC_INDIVIDUAL_SP_KEY_PURPOSE_OBJID, /* 1.3.6.1.4.1.311.2.1.21 */ - szOID_CERTSRV_CA_VERSION, /* 1.3.6.1.4.1.311.21.1 */ -+ SHIM_EKU_MODULE_SIGNING_ONLY, /* 1.3.6.1.4.1.2312.16.1.2 */ - END_OID_LIST - } ms_oid_t; - --- -2.13.4 - diff --git a/0016-efikeygen-add-modsign.patch b/0016-efikeygen-add-modsign.patch deleted file mode 100644 index 8324334..0000000 --- a/0016-efikeygen-add-modsign.patch +++ /dev/null @@ -1,197 +0,0 @@ -From 9b4b12928c0450ac69d83293e179eec439465c03 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 22 Aug 2016 13:43:56 -0400 -Subject: [PATCH 16/29] efikeygen: add --modsign - ---- - src/cms_common.c | 29 ++++++++++++++++++++++++++++ - src/cms_common.h | 1 + - src/efikeygen.c | 59 ++++++++++++++++++++++++++++++++++++++++++++------------ - 3 files changed, 77 insertions(+), 12 deletions(-) - -diff --git a/src/cms_common.c b/src/cms_common.c -index 6a4e6a7..2df2cfe 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -715,6 +715,35 @@ make_context_specific(cms_context *cms, int ctxt, SECItem *encoded, - return 0; - } - -+static SEC_ASN1Template EKUOidSequence[] = { -+ { -+ .kind = SEC_ASN1_OBJECT_ID, -+ .offset = 0, -+ .sub = &SEC_AnyTemplate, -+ .size = sizeof (SECItem), -+ }, -+ { 0 } -+}; -+ -+int -+make_eku_oid(cms_context *cms, SECItem *encoded, SECOidTag oid_tag) -+{ -+ void *rv; -+ SECOidData *oid_data; -+ -+ oid_data = SECOID_FindOIDByTag(oid_tag); -+ if (!oid_data) -+ cmsreterr(-1, cms, "could not encode eku oid data"); -+ -+ rv = SEC_ASN1EncodeItem(cms->arena, encoded, &oid_data->oid, -+ EKUOidSequence); -+ if (rv == NULL) -+ cmsreterr(-1, cms, "could not encode eku oid data"); -+ -+ encoded->type = siBuffer; -+ return 0; -+} -+ - int - generate_octet_string(cms_context *cms, SECItem *encoded, SECItem *original) - { -diff --git a/src/cms_common.h b/src/cms_common.h -index c7d7268..7a31273 100644 ---- a/src/cms_common.h -+++ b/src/cms_common.h -@@ -123,6 +123,7 @@ extern int wrap_in_seq(cms_context *cms, SECItem *der, - SECItem *items, int num_items); - extern int make_context_specific(cms_context *cms, int ctxt, SECItem *encoded, - SECItem *original); -+extern int make_eku_oid(cms_context *cms, SECItem *encoded, SECOidTag oid_tag); - extern int generate_validity(cms_context *cms, SECItem *der, time_t start, - time_t end); - extern int generate_common_name(cms_context *cms, SECItem *der, char *cn); -diff --git a/src/efikeygen.c b/src/efikeygen.c -index 8a515a5..9390578 100644 ---- a/src/efikeygen.c -+++ b/src/efikeygen.c -@@ -49,6 +49,7 @@ - #include - - #include "cms_common.h" -+#include "oid.h" - #include "util.h" - - typedef struct { -@@ -249,20 +250,34 @@ add_basic_constraints(cms_context *cms, void *extHandle) - } - - static int --add_extended_key_usage(cms_context *cms, void *extHandle) -+add_extended_key_usage(cms_context *cms, int modsign_only, void *extHandle) - { -- SECItem value = { -- .data = (unsigned char *)"\x30\x0a\x06\x08\x2b\x06\x01" -- "\x05\x05\x07\x03\x03", -- .len = 12, -- .type = siBuffer -- }; -+ SECItem values[2]; -+ SECItem wrapped = { 0 }; -+ SECStatus status; -+ SECOidTag tag; -+ int rc; -+ -+ if (modsign_only < 1 || modsign_only > 2) -+ cmsreterr(-1, cms, "could not encode extended key usage"); - -+ rc = make_eku_oid(cms, &values[0], SEC_OID_EXT_KEY_USAGE_CODE_SIGN); -+ if (rc < 0) -+ cmsreterr(-1, cms, "could not encode extended key usage"); -+ -+ tag = find_ms_oid_tag(SHIM_EKU_MODULE_SIGNING_ONLY); -+ printf("tag: %d\n", tag); -+ rc = make_eku_oid(cms, &values[1], tag); -+ if (rc < 0) -+ cmsreterr(-1, cms, "could not encode extended key usage"); -+ -+ rc = wrap_in_seq(cms, &wrapped, values, modsign_only); -+ if (rc < 0) -+ cmsreterr(-1, cms, "could not encode extended key usage"); - -- SECStatus status; - - status = CERT_AddExtension(extHandle, SEC_OID_X509_EXT_KEY_USAGE, -- &value, PR_FALSE, PR_TRUE); -+ &wrapped, PR_FALSE, PR_TRUE); - if (status != SECSuccess) - cmsreterr(-1, cms, "could not encode extended key usage"); - -@@ -294,7 +309,7 @@ static int - add_extensions_to_crq(cms_context *cms, CERTCertificateRequest *crq, - int is_ca, int is_self_signed, SECKEYPublicKey *pubkey, - SECKEYPublicKey *spubkey, -- char *url) -+ char *url, int modsign_only) - { - void *mark = PORT_ArenaMark(cms->arena); - -@@ -319,7 +334,7 @@ add_extensions_to_crq(cms_context *cms, CERTCertificateRequest *crq, - if (rc < 0) - cmsreterr(-1, cms, "could not generate certificate extensions"); - -- rc = add_extended_key_usage(cms, extHandle); -+ rc = add_extended_key_usage(cms, modsign_only, extHandle); - if (rc < 0) - cmsreterr(-1, cms, "could not generate certificate extensions"); - -@@ -469,6 +484,7 @@ int main(int argc, char *argv[]) - { - int is_ca = 0; - int is_self_signed = -1; -+ int modsign_only = 0; - char *tokenname = "NSS Certificate DB"; - char *signer = NULL; - char *nickname = NULL; -@@ -522,6 +538,18 @@ int main(int argc, char *argv[]) - .descrip = "Generate a self-signed certificate" }, - - /* stuff about the generated key */ -+ {.longName = "kernel", -+ .shortName = 'k', -+ .argInfo = POPT_ARG_VAL|POPT_ARGFLAG_OR, -+ .arg = &modsign_only, -+ .val = 1, -+ .descrip = "Generate a kernel-signing certificate" }, -+ {.longName = "module", -+ .shortName = 'm', -+ .argInfo = POPT_ARG_VAL|POPT_ARGFLAG_OR, -+ .arg = &modsign_only, -+ .val = 2, -+ .descrip = "Generate a module-signing certificate" }, - {.longName = "nickname", - .shortName = 'n', - .argInfo = POPT_ARG_STRING, -@@ -628,6 +656,9 @@ int main(int argc, char *argv[]) - liberr(1, "could not allocate cms context"); - } - -+ if (modsign_only < 1 || modsign_only > 2) -+ errx(1, "either --kernel or --module must be used"); -+ - SECStatus status = NSS_InitReadWrite(dbdir); - if (status != SECSuccess) - nsserr(1, "could not initialize NSS"); -@@ -639,6 +670,10 @@ int main(int argc, char *argv[]) - SECKEYPublicKey *pubkey = NULL; - SECKEYPrivateKey *privkey = NULL; - -+ status = register_oids(cms); -+ if (status != SECSuccess) -+ nsserr(1, "Could not register OIDs"); -+ - PK11SlotInfo *slot = NULL; - if (pubfile) { - rc = get_pubkey_from_file(pubfile, &pubkey); -@@ -713,7 +748,7 @@ int main(int argc, char *argv[]) - crq = CERT_CreateCertificateRequest(name, spki, &attributes); - - rc = add_extensions_to_crq(cms, crq, is_ca, is_self_signed, pubkey, -- spubkey, url); -+ spubkey, url, modsign_only); - if (rc < 0) - exit(1); - --- -2.13.4 - diff --git a/0017-check_cert_db-try-even-harder-to-pick-a-reasonable-v.patch b/0017-check_cert_db-try-even-harder-to-pick-a-reasonable-v.patch deleted file mode 100644 index acebc3a..0000000 --- a/0017-check_cert_db-try-even-harder-to-pick-a-reasonable-v.patch +++ /dev/null @@ -1,121 +0,0 @@ -From 0456758e0c0873d1251bdf77d27f0f6175cbf289 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 25 Apr 2017 16:25:02 -0400 -Subject: [PATCH 17/29] check_cert_db(): try even harder to pick a reasonable - validation time. - -Signed-off-by: Peter Jones ---- - src/certdb.c | 75 ++++++++++++++++++++++++++++++++++++++++++++++++++++-------- - 1 file changed, 66 insertions(+), 9 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index b7c99bb..1a4baf1 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -250,12 +250,53 @@ check_db_hash(db_specifier which, pesigcheck_context *ctx) - return check_db(which, ctx, check_hash, NULL, 0); - } - --static PRTime --determine_reasonable_time(CERTCertificate *cert) -+static void -+find_cert_times(SEC_PKCS7ContentInfo *cinfo, -+ PRTime *notBefore, PRTime *notAfter) - { -- PRTime notBefore, notAfter; -- CERT_GetCertTimes(cert, ¬Before, ¬After); -- return notBefore; -+ CERTCertDBHandle *defaultdb, *certdb; -+ SEC_PKCS7SignedData *sdp; -+ CERTCertificate **certs = NULL; -+ SECItem **rawcerts; -+ int i, certcount; -+ SECStatus rv; -+ -+ if (cinfo->contentTypeTag->offset != SEC_OID_PKCS7_SIGNED_DATA) { -+err: -+ *notBefore = 0; -+ *notAfter = 0x7fffffffffffffff; -+ return; -+ } -+ -+ sdp = cinfo->content.signedData; -+ rawcerts = sdp->rawCerts; -+ -+ defaultdb = CERT_GetDefaultCertDB(); -+ -+ certdb = defaultdb; -+ if (certdb == NULL) -+ goto err; -+ -+ certcount = 0; -+ if (rawcerts != NULL) { -+ for (; rawcerts[certcount] != NULL; certcount++) -+ ; -+ } -+ rv = CERT_ImportCerts(certdb, certUsageObjectSigner, certcount, -+ rawcerts, &certs, PR_FALSE, PR_FALSE, NULL); -+ if (rv != SECSuccess) -+ goto err; -+ -+ for (i = 0; i < certcount; i++) { -+ PRTime nb = 0, na = 0x7fffffffffff; -+ CERT_GetCertTimes(certs[i], &nb, &na); -+ if (*notBefore < nb) -+ *notBefore = nb; -+ if (*notAfter > na) -+ *notAfter = na; -+ } -+ -+ CERT_DestroyCertArray(certs, certcount); - } - - static db_status -@@ -271,6 +312,8 @@ check_cert(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - PRBool result; - SECStatus rv; - db_status status = NOT_FOUND; -+ PRTime earlyNow = 0, lateNow = 0x7fffffffffffffff; -+ PRTime notBefore = 0, notAfter = 0x7fffffffffffffff; - - efi_guid_t efi_x509 = efi_guid_x509_cert; - -@@ -327,16 +370,30 @@ check_cert(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - } - cert->timeOK = PR_TRUE; - -+ find_cert_times(cinfo, ¬Before, ¬After); -+ if (earlyNow < notBefore) -+ earlyNow = notBefore; -+ if (lateNow > notAfter) -+ lateNow = notAfter; -+ - SECItem *eTime; - PRTime atTime; - // atTime = determine_reasonable_time(cert); - eTime = SEC_PKCS7GetSigningTime(cinfo); - if (eTime != NULL) { -- if (DER_DecodeTimeChoice (&atTime, eTime) != SECSuccess) -- atTime = determine_reasonable_time(cert); -- } else { -- atTime = determine_reasonable_time(cert); -+ if (DER_DecodeTimeChoice (&atTime, eTime) == SECSuccess) { -+ if (earlyNow < atTime) -+ earlyNow = atTime; -+ if (lateNow > atTime) -+ lateNow = atTime; -+ } - } -+ -+ if (lateNow < earlyNow) -+ printf("Impossible time constraints: %ld <= %ld\n", -+ earlyNow / 1000000, lateNow / 1000000); -+ atTime = earlyNow / 2 + lateNow / 2; -+ - /* Verify the signature */ - result = SEC_PKCS7VerifyDetachedSignatureAtTime(cinfo, - certUsageObjectSigner, --- -2.13.4 - diff --git a/0018-show-which-db-we-re-checking.patch b/0018-show-which-db-we-re-checking.patch deleted file mode 100644 index 2b92f83..0000000 --- a/0018-show-which-db-we-re-checking.patch +++ /dev/null @@ -1,137 +0,0 @@ -From 01b89fb7a191f4639a93c5a7c47a80752118ba95 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 25 Apr 2017 16:58:50 -0400 -Subject: [PATCH 18/29] show which db we're checking - ---- - src/certdb.c | 35 ++++++++++++++++++++++++++++++++++- - src/pesigcheck_context.c | 2 ++ - src/pesigcheck_context.h | 1 + - 3 files changed, 37 insertions(+), 1 deletion(-) - -diff --git a/src/certdb.c b/src/certdb.c -index 1a4baf1..673e074 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -18,6 +18,7 @@ - */ - - #include -+#include - #include - #include - #include -@@ -42,17 +43,33 @@ add_db_file(pesigcheck_context *ctx, db_specifier which, const char *dbfile, - return -1; - - db->type = type; -- - db->fd = open(dbfile, O_RDONLY); - if (db->fd < 0) { - save_errno(free(db)); - return -1; - } - -+ char *path = strdup(dbfile); -+ if (!path) { -+ save_errno(close(db->fd); -+ free(db)); -+ return -1; -+ } -+ -+ db->path = basename(path); -+ db->path = strdup(db->path); -+ free(path); -+ if (!db->path) { -+ save_errno(close(db->fd); -+ free(db)); -+ return -1; -+ } -+ - struct stat sb; - int rc = fstat(db->fd, &sb); - if (rc < 0) { - save_errno(close(db->fd); -+ free(db->path); - free(db)); - return -1; - } -@@ -65,6 +82,7 @@ add_db_file(pesigcheck_context *ctx, db_specifier which, const char *dbfile, - rc = read_file(db->fd, (char **)&db->map, &sz); - if (rc < 0) { - save_errno(close(db->fd); -+ free(db->path); - free(db)); - return -1; - } -@@ -133,6 +151,7 @@ add_cert_file(pesigcheck_context *ctx, const char *filename) - #define DB_PATH "/sys/firmware/efi/efivars/db-d719b2cb-3d3a-4596-a3bc-dad00e67656f" - #define MOK_PATH "/sys/firmware/efi/efivars/MokListRT-605dab50-e046-4300-abb6-3dd810dd8b23" - #define DBX_PATH "/sys/firmware/efi/efivars/dbx-d719b2cb-3d3a-4596-a3bc-dad00e67656f" -+#define MOKX_PATH "/sys/firmware/efi/efivars/MokListXRT-605dab50-e046-4300-abb6-3dd810dd8b23" - - void - init_cert_db(pesigcheck_context *ctx, int use_system_dbs) -@@ -167,6 +186,18 @@ init_cert_db(pesigcheck_context *ctx, int use_system_dbs) - "database \"%s\": %m\n", DBX_PATH); - exit(1); - } -+ -+ rc = add_db_file(ctx, DBX, MOKX_PATH, DB_EFIVAR); -+ if (rc < 0 && errno != ENOENT) { -+ fprintf(stderr, "pesigcheck: Could not add key database " -+ "\"%s\": %m\n", MOKX_PATH); -+ exit(1); -+ } -+ -+ if (ctx->dbx == NULL) { -+ fprintf(stderr, "pesigcheck: warning: " -+ "No key recovation database available\n"); -+ } - } - - typedef db_status (*checkfn)(pesigcheck_context *ctx, SECItem *sig, -@@ -187,6 +218,8 @@ check_db(db_specifier which, pesigcheck_context *ctx, checkfn check, - sig.type = siBuffer; - - while (dbl) { -+ printf("Searching %s %s\n", which == DB ? "db" : "dbx", -+ dbl->path); - EFI_SIGNATURE_LIST *certlist; - EFI_SIGNATURE_DATA *cert; - size_t dbsize = dbl->datalen; -diff --git a/src/pesigcheck_context.c b/src/pesigcheck_context.c -index b934cbe..5a355b1 100644 ---- a/src/pesigcheck_context.c -+++ b/src/pesigcheck_context.c -@@ -87,6 +87,7 @@ pesigcheck_context_fini(pesigcheck_context *ctx) - munmap(db->map, db->size); - close(db->fd); - ctx->db = db->next; -+ free(db->path); - free(db); - } - while (ctx->dbx) { -@@ -95,6 +96,7 @@ pesigcheck_context_fini(pesigcheck_context *ctx) - if (db->type == DB_CERT) - free(db->data); - munmap(db->map, db->size); -+ free(db->path); - close(db->fd); - ctx->dbx = db->next; - free(db); -diff --git a/src/pesigcheck_context.h b/src/pesigcheck_context.h -index 1b916e3..7b5cc89 100644 ---- a/src/pesigcheck_context.h -+++ b/src/pesigcheck_context.h -@@ -34,6 +34,7 @@ typedef enum { - - struct dblist { - db_f_type type; -+ char *path; - int fd; - struct dblist *next; - size_t size; --- -2.13.4 - diff --git a/0019-more-about-the-time.patch b/0019-more-about-the-time.patch deleted file mode 100644 index 2570bf8..0000000 --- a/0019-more-about-the-time.patch +++ /dev/null @@ -1,97 +0,0 @@ -From 713e61448a6ffa3e6029a7c89fad61b8cb08c9ff Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 25 Apr 2017 17:00:46 -0400 -Subject: [PATCH 19/29] more about the time - ---- - src/certdb.c | 59 +++++++++++++++++++++++++++++++++-------------------------- - 1 file changed, 33 insertions(+), 26 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index 673e074..1078a8a 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -345,8 +345,10 @@ check_cert(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - PRBool result; - SECStatus rv; - db_status status = NOT_FOUND; -+ PRTime atTime = PR_Now(); -+ SECItem *eTime; - PRTime earlyNow = 0, lateNow = 0x7fffffffffffffff; -- PRTime notBefore = 0, notAfter = 0x7fffffffffffffff; -+ PRTime notBefore, notAfter; - - efi_guid_t efi_x509 = efi_guid_x509_cert; - -@@ -358,6 +360,36 @@ check_cert(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - if (!cinfo) - goto out; - -+ notBefore = earlyNow; -+ notAfter = lateNow; -+ find_cert_times(cinfo, ¬Before, ¬After); -+ if (earlyNow < notBefore) -+ earlyNow = notBefore; -+ if (lateNow > notAfter) -+ lateNow = notAfter; -+ -+ // atTime = determine_reasonable_time(cert); -+ eTime = SEC_PKCS7GetSigningTime(cinfo); -+ if (eTime != NULL) { -+ if (DER_DecodeTimeChoice (&atTime, eTime) == SECSuccess) { -+ if (earlyNow < atTime) -+ earlyNow = atTime; -+ if (lateNow > atTime) -+ lateNow = atTime; -+ } -+ } -+ -+ if (lateNow < earlyNow) -+ printf("Signature has impossible time constraint: %ld <= %ld\n", -+ earlyNow / 1000000, lateNow / 1000000); -+ atTime = earlyNow / 2 + lateNow / 2; -+ -+ -+ cinfo = SEC_PKCS7DecodeItem(pkcs7sig, NULL, NULL, NULL, NULL, NULL, -+ NULL, NULL); -+ if (!cinfo) -+ goto out; -+ - /* Generate the digest of contentInfo */ - /* XXX support only sha256 for now */ - digest = SECITEM_AllocItem(NULL, NULL, 32); -@@ -401,31 +433,6 @@ check_cert(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - PORT_ErrorToString(PORT_GetError())); - goto out; - } -- cert->timeOK = PR_TRUE; -- -- find_cert_times(cinfo, ¬Before, ¬After); -- if (earlyNow < notBefore) -- earlyNow = notBefore; -- if (lateNow > notAfter) -- lateNow = notAfter; -- -- SECItem *eTime; -- PRTime atTime; -- // atTime = determine_reasonable_time(cert); -- eTime = SEC_PKCS7GetSigningTime(cinfo); -- if (eTime != NULL) { -- if (DER_DecodeTimeChoice (&atTime, eTime) == SECSuccess) { -- if (earlyNow < atTime) -- earlyNow = atTime; -- if (lateNow > atTime) -- lateNow = atTime; -- } -- } -- -- if (lateNow < earlyNow) -- printf("Impossible time constraints: %ld <= %ld\n", -- earlyNow / 1000000, lateNow / 1000000); -- atTime = earlyNow / 2 + lateNow / 2; - - /* Verify the signature */ - result = SEC_PKCS7VerifyDetachedSignatureAtTime(cinfo, --- -2.13.4 - diff --git a/0020-try-to-say-why-something-fails.patch b/0020-try-to-say-why-something-fails.patch deleted file mode 100644 index 96bdd60..0000000 --- a/0020-try-to-say-why-something-fails.patch +++ /dev/null @@ -1,419 +0,0 @@ -From 81583146602bba96728fa7544c8e856b32c22ee4 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 25 Apr 2017 17:01:13 -0400 -Subject: [PATCH 20/29] try to say why something fails - -Signed-off-by: Peter Jones ---- - src/certdb.c | 15 ++- - src/certdb.h | 2 +- - src/pesigcheck.c | 244 ++++++++++++++++++++++++++++++++++++++++++----- - src/pesigcheck_context.h | 1 + - 4 files changed, 233 insertions(+), 29 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index 1078a8a..fae80af 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -205,7 +205,7 @@ typedef db_status (*checkfn)(pesigcheck_context *ctx, SECItem *sig, - - static db_status - check_db(db_specifier which, pesigcheck_context *ctx, checkfn check, -- void *data, ssize_t datalen) -+ void *data, ssize_t datalen, SECItem *match) - { - SECItem pkcs7sig, sig; - dblist *dbl = which == DB ? ctx->db : ctx->dbx; -@@ -241,8 +241,12 @@ check_db(db_specifier which, pesigcheck_context *ctx, checkfn check, - found = check(ctx, &sig, - &certlist->SignatureType, - &pkcs7sig); -- if (found == FOUND) -+ if (found == FOUND) { -+ if (match) -+ memcpy(match, &sig, -+ sizeof(sig)); - return FOUND; -+ } - cert = (EFI_SIGNATURE_DATA *)((uint8_t *)cert + - certlist->SignatureSize); - } -@@ -280,7 +284,7 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - db_status - check_db_hash(db_specifier which, pesigcheck_context *ctx) - { -- return check_db(which, ctx, check_hash, NULL, 0); -+ return check_db(which, ctx, check_hash, NULL, 0, NULL); - } - - static void -@@ -459,7 +463,8 @@ out: - } - - db_status --check_db_cert(db_specifier which, pesigcheck_context *ctx, void *data, ssize_t datalen) -+check_db_cert(db_specifier which, pesigcheck_context *ctx, -+ void *data, ssize_t datalen, SECItem *match) - { -- return check_db(which, ctx, check_cert, data, datalen); -+ return check_db(which, ctx, check_cert, data, datalen, match); - } -diff --git a/src/certdb.h b/src/certdb.h -index ccf3c87..8402299 100644 ---- a/src/certdb.h -+++ b/src/certdb.h -@@ -43,7 +43,7 @@ typedef struct { - - extern db_status check_db_hash(db_specifier which, pesigcheck_context *ctx); - extern db_status check_db_cert(db_specifier which, pesigcheck_context *ctx, -- void *data, ssize_t datalen); -+ void *data, ssize_t datalen, SECItem *match); - - extern void init_cert_db(pesigcheck_context *ctx, int use_system_dbs); - extern int add_cert_db(pesigcheck_context *ctx, const char *filename); -diff --git a/src/pesigcheck.c b/src/pesigcheck.c -index d7be542..c8e1086 100644 ---- a/src/pesigcheck.c -+++ b/src/pesigcheck.c -@@ -17,7 +17,9 @@ - * Author(s): Peter Jones - */ - -+#include - #include -+#include - #include - #include - #include -@@ -88,7 +90,8 @@ check_inputs(pesigcheck_context *ctx) - } - - static int --cert_matches_digest(pesigcheck_context *ctx, void *data, ssize_t datalen) -+cert_matches_digest(pesigcheck_context *ctx, void *data, ssize_t datalen, -+ SECItem *digest_out) - { - SECItem sig, *pe_digest, *content; - uint8_t *digest; -@@ -109,6 +112,12 @@ cert_matches_digest(pesigcheck_context *ctx, void *data, ssize_t datalen) - pe_digest = ctx->cms_ctx->digests[0].pe_digest; - content = cinfo->content.signedData->contentInfo.content.data; - digest = content->data + content->len - pe_digest->len; -+ if (digest_out) { -+ digest_out->data = malloc(pe_digest->len); -+ digest_out->len = pe_digest->len; -+ digest_out->type = pe_digest->type; -+ memcpy(digest_out->data, digest, pe_digest->len); -+ } - if (memcmp(pe_digest->data, digest, pe_digest->len) != 0) - goto out; - -@@ -120,22 +129,149 @@ out: - return ret; - } - -+struct reason { -+ enum { -+ WHITELISTED = 0, -+ INVALID = 1, -+ BLACKLISTED = 2, -+ NO_WHITELIST = 3, -+ } reason; -+ enum { -+ NONE = 0, -+ DIGEST = 1, -+ SIGNATURE = 2, -+ } type; -+ union { -+ struct { -+ SECItem digest; -+ }; -+ struct { -+ SECItem sig; -+ SECItem db_cert; -+ }; -+ }; -+}; -+ -+static void -+print_digest(SECItem *digest) -+{ -+ char buf[digest->len * 2 + 2]; -+ -+ for (unsigned int i = 0; i < digest->len; i++) -+ snprintf(buf + i * 2, digest->len * 2, "%02x", -+ digest->data[i]); -+ buf[digest->len * 2] = '\0'; -+ printf("%s\n", buf); -+} -+ -+static void -+print_certificate(SECItem *cert) -+{ -+ printf("put a breakpoint at %s:%d\n", __FILE__, __LINE__); -+ printf("cert: %p\n", cert); -+} -+ -+static void -+print_signatures(SECItem *database_cert, SECItem *signature) -+{ -+ printf("put a breakpoint at %s:%d\n", __FILE__, __LINE__); -+ print_certificate(database_cert); -+ print_certificate(signature); -+} -+ -+static void -+print_reason(struct reason *reason) -+{ -+ switch (reason->reason) { -+ case WHITELISTED: -+ printf("Whitelist entry: "); -+ if (reason->type == DIGEST) -+ print_digest(&reason->digest); -+ else if (reason->type == SIGNATURE) -+ print_signatures(&reason->sig, &reason->db_cert); -+ else -+ errx(1, "Unknown data type %d\n", reason->type); -+ break; -+ case INVALID: -+ if (reason->type == DIGEST) { -+ printf("Invalid digest: "); -+ print_digest(&reason->digest); -+ } else if (reason->type == SIGNATURE) { -+ printf("Invalid signature: "); -+ print_signatures(&reason->sig, &reason->db_cert); -+ } else { -+ errx(1, "Unknown data type %d\n", reason->type); -+ } -+ break; -+ case BLACKLISTED: -+ if (reason->type == DIGEST) { -+ printf("Invalid digest: "); -+ print_digest(&reason->digest); -+ } else if (reason->type == SIGNATURE) { -+ printf("Invalid signature: "); -+ print_signatures(&reason->sig, &reason->db_cert); -+ } else { -+ errx(1, "Unknown data type %d\n", reason->type); -+ } -+ break; -+ case NO_WHITELIST: -+ if (reason->type == NONE) -+ printf("No matching whitelist entry.\n"); -+ else -+ errx(1, "Invalid data type %d\n", reason->type); -+ break; -+ default: -+ errx(1, "Unknown reason type %d\n", reason->reason); -+ break; -+ } -+} -+ -+static void -+get_digest(pesigcheck_context *ctx, SECItem *digest) -+{ -+ struct cms_context *cms = ctx->cms_ctx; -+ struct digest *cms_digest = &cms->digests[cms->selected_digest]; -+ -+ memcpy(digest, cms_digest->pe_digest, sizeof (*digest)); -+} -+ - static int --check_signature(pesigcheck_context *ctx) -+check_signature(pesigcheck_context *ctx, int *nreasons, -+ struct reason **reasons) - { -- int has_valid_cert = 0; -- int has_invalid_cert = 0; -+ bool has_valid_cert = false; -+ bool is_invalid = false; -+ struct reason *reasonps = NULL, *reason; -+ int num_reasons = 16; -+ int nreason = 0; - int rc = 0; -+ int ret = -1; - - cert_iter iter; - -+ reasonps = calloc(sizeof(struct reason), 512); -+ if (!reasonps) -+ err(1, "check_signature"); -+ - generate_digest(ctx->cms_ctx, ctx->inpe, 1); - -- if (check_db_hash(DBX, ctx) == FOUND) -- return -1; -+ if (check_db_hash(DBX, ctx) == FOUND) { -+ reason = &reasonps[nreason]; -+ reason->reason = BLACKLISTED; -+ reason->type = DIGEST; -+ get_digest(ctx, &reason->digest); -+ reason += 1; -+ is_invalid = true; -+ } - -- if (check_db_hash(DB, ctx) == FOUND) -- has_valid_cert = 1; -+ if (check_db_hash(DB, ctx) == FOUND) { -+ reason = &reasonps[nreason]; -+ reason->reason = WHITELISTED; -+ reason->type = DIGEST; -+ get_digest(ctx, &reason->digest); -+ nreason += 1; -+ has_valid_cert = true; -+ } - - rc = cert_iter_init(&iter, ctx->inpe); - if (rc < 0) -@@ -145,32 +281,81 @@ check_signature(pesigcheck_context *ctx) - ssize_t datalen; - - while (1) { -+ /* -+ * Make sure we always have enough for this iteration of the -+ * loop, plus one "NO_WHITELIST" entry at the end. -+ */ -+ if (nreason >= num_reasons - 4) { -+ struct reason *new_reasons; -+ -+ num_reasons += 16; -+ -+ new_reasons = calloc(sizeof(struct reason), num_reasons); -+ if (!new_reasons) -+ err(1, "check_signature"); -+ reasonps = new_reasons; -+ } -+ - rc = next_cert(&iter, &data, &datalen); - if (rc <= 0) - break; - -- if (cert_matches_digest(ctx, data, datalen) < 0) { -- has_invalid_cert = 1; -- break; -+ reason = &reasonps[nreason]; -+ if (cert_matches_digest(ctx, data, datalen, -+ &reason->digest) < 0) { -+ reason->reason = INVALID; -+ reason->type = DIGEST; -+ nreason += 1; -+ is_invalid = true; - } - -- if (check_db_cert(DBX, ctx, data, datalen) == FOUND) { -- has_invalid_cert = 1; -- break; -+ reason = &reasonps[nreason]; -+ if (check_db_cert(DBX, ctx, data, datalen, -+ &reason->db_cert) == FOUND) { -+ reason->reason = INVALID; -+ reason->type = SIGNATURE; -+ reason->sig.data = data; -+ reason->sig.len = datalen; -+ reason->type = siBuffer; -+ nreason += 1; -+ is_invalid = true; - } - -- if (check_db_cert(DB, ctx, data, datalen) == FOUND) -- has_valid_cert = 1; -+ reason = &reasonps[nreason]; -+ if (check_db_cert(DB, ctx, data, datalen, -+ &reason->db_cert) == FOUND) { -+ reason->reason = WHITELISTED; -+ reason->type = SIGNATURE; -+ reason->sig.data = data; -+ reason->sig.len = datalen; -+ reason->type = siBuffer; -+ nreason += 1; -+ has_valid_cert = true; -+ } - } - - err: -- if (has_invalid_cert) -- return -1; -+ if (has_valid_cert != true) { -+ if (is_invalid != true) { -+ reason = &reasonps[nreason]; -+ reason->reason = NO_WHITELIST; -+ reason->type = NONE; -+ nreason += 1; -+ } -+ is_invalid = true; -+ } - -- if (has_valid_cert) -- return 0; -+ if (is_invalid == false) -+ ret = 0; - -- return -1; -+ if (nreasons && reasons) { -+ *nreasons = nreason; -+ *reasons = reasonps; -+ } else { -+ free(reasonps); -+ } -+ -+ return ret; - } - - void -@@ -204,6 +389,9 @@ main(int argc, char *argv[]) - - pesigcheck_context ctx, *ctxp = &ctx; - -+ struct reason *reasons = NULL; -+ int nreasons = 0; -+ - char *dbfile = NULL; - char *dbxfile = NULL; - char *certfile = NULL; -@@ -242,6 +430,12 @@ main(int argc, char *argv[]) - .arg = &ctx.quiet, - .val = 1, - .descrip = "return only; no text output." }, -+ {.longName = "verbose", -+ .shortName = 'v', -+ .argInfo = POPT_BIT_SET, -+ .arg = &ctx.verbose, -+ .val = 1, -+ .descrip = "print reasons for success and failure." }, - {.longName = "no-system-db", - .shortName = 'n', - .argInfo = POPT_ARG_INT, -@@ -308,12 +502,16 @@ main(int argc, char *argv[]) - exit(1); - } - -- rc = check_signature(ctxp); -+ rc = check_signature(ctxp, &nreasons, &reasons); - -- close_input(ctxp); -+ if (!ctx.quiet && ctx.verbose) { -+ for (int i = 0; i < nreasons; i++) -+ print_reason(&reasons[i]); -+ } - if (!ctx.quiet) - printf("pesigcheck: \"%s\" is %s.\n", ctx.infile, - rc >= 0 ? "valid" : "invalid"); -+ close_input(ctxp); - pesigcheck_context_fini(&ctx); - - NSS_Shutdown(); -diff --git a/src/pesigcheck_context.h b/src/pesigcheck_context.h -index 7b5cc89..aec415e 100644 ---- a/src/pesigcheck_context.h -+++ b/src/pesigcheck_context.h -@@ -61,6 +61,7 @@ typedef struct pesigcheck_context { - Pe *inpe; - - int quiet; -+ int verbose; - - hashlist *hashes; - --- -2.13.4 - diff --git a/0021-Fix-race-condition-in-SEC_GetPassword.patch b/0021-Fix-race-condition-in-SEC_GetPassword.patch deleted file mode 100644 index 3088923..0000000 --- a/0021-Fix-race-condition-in-SEC_GetPassword.patch +++ /dev/null @@ -1,34 +0,0 @@ -From a40c584691ae071e93e8adf4e5c05bcd90c68159 Mon Sep 17 00:00:00 2001 -From: Julien Cristau -Date: Sat, 6 May 2017 22:45:34 +0200 -Subject: [PATCH 21/29] Fix race condition in SEC_GetPassword - -A side effect of echoOff is to discard unread input, so if we print the -prompt before echoOff, the user (or process) at the other end might -react to it by writing the password in between those steps, which is -then discarded. This bit me when trying to drive pesign with an expect -script. - -Signed-off-by: Julien Cristau ---- - src/password.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/password.c b/src/password.c -index cd1c07e..d4eae0d 100644 ---- a/src/password.c -+++ b/src/password.c -@@ -71,9 +71,9 @@ static char *SEC_GetPassword(FILE *input, FILE *output, char *prompt, - for (;;) { - /* Prompt for password */ - if (isTTY) { -+ echoOff(infd); - fprintf(output, "%s", prompt); - fflush (output); -- echoOff(infd); - } - - fgets ( phrase, sizeof(phrase), input); --- -2.13.4 - diff --git a/0022-sysvinit-Create-the-socket-directory-at-runtime.patch b/0022-sysvinit-Create-the-socket-directory-at-runtime.patch deleted file mode 100644 index 06980ee..0000000 --- a/0022-sysvinit-Create-the-socket-directory-at-runtime.patch +++ /dev/null @@ -1,27 +0,0 @@ -From 27afa5a4ea8de1679603f5871935096280d0b12e Mon Sep 17 00:00:00 2001 -From: David Michael -Date: Tue, 13 Jun 2017 13:20:16 -0700 -Subject: [PATCH 22/29] sysvinit: Create the socket directory at runtime - -This better supports non-systemd configurations with tmpfs on /run. ---- - src/pesign.sysvinit.in | 3 +++ - 1 file changed, 3 insertions(+) - -diff --git a/src/pesign.sysvinit.in b/src/pesign.sysvinit.in -index d8fffca..dc508d8 100644 ---- a/src/pesign.sysvinit.in -+++ b/src/pesign.sysvinit.in -@@ -20,6 +20,9 @@ RETVAL=0 - - start(){ - echo -n "Starting pesign: " -+ mkdir /var/run/pesign 2>/dev/null && -+ chown pesign:pesign /var/run/pesign && -+ chmod 0770 /var/run/pesign - daemon /usr/bin/pesign --daemonize - RETVAL=$? - echo --- -2.13.4 - diff --git a/0023-Better-authorization-scripts.-Again.patch b/0023-Better-authorization-scripts.-Again.patch deleted file mode 100644 index c778c94..0000000 --- a/0023-Better-authorization-scripts.-Again.patch +++ /dev/null @@ -1,217 +0,0 @@ -From 31560e2784722b986b8a73cc28e3510870180b07 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 8 Aug 2017 15:44:44 -0400 -Subject: [PATCH 23/29] Better authorization scripts. Again. - -Signed-off-by: Peter Jones ---- - src/Makefile | 12 ++++++---- - src/pesign-authorize | 56 +++++++++++++++++++++++++++++++++++++++++++++ - src/pesign-authorize-groups | 30 ------------------------ - src/pesign-authorize-users | 30 ------------------------ - src/pesign.service.in | 3 +-- - src/pesign.sysvinit.in | 3 +-- - 6 files changed, 65 insertions(+), 69 deletions(-) - create mode 100755 src/pesign-authorize - delete mode 100644 src/pesign-authorize-groups - delete mode 100644 src/pesign-authorize-users - -diff --git a/src/Makefile b/src/Makefile -index 654b792..84ad130 100644 ---- a/src/Makefile -+++ b/src/Makefile -@@ -7,7 +7,7 @@ include $(TOPDIR)/Make.defaults - - BINTARGETS=authvar client efikeygen efisiglist pesigcheck pesign - SVCTARGETS=pesign.sysvinit pesign.service --TARGETS=$(BINTARGETS) $(SVCTARGETS) -+TARGETS=$(BINTARGETS) $(SVCTARGETS) pesign-users pesign-groups - - all : deps $(TARGETS) - -@@ -65,6 +65,9 @@ install_sysvinit: pesign.sysvinit - $(INSTALL) -d -m 755 $(INSTALLROOT)/etc/rc.d/init.d/ - $(INSTALL) -m 755 pesign.sysvinit $(INSTALLROOT)/etc/rc.d/init.d/pesign - -+pesign-users pesign-groups : -+ echo pesign > $@ -+ - install : - $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign/ - $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign-rh-test/ -@@ -88,10 +91,9 @@ install : - $(INSTALL) -d -m 755 $(INSTALLROOT)/etc/rpm/ - $(INSTALL) -m 644 macros.pesign $(INSTALLROOT)/etc/rpm/ - $(INSTALL) -d -m 755 $(INSTALLROOT)$(libexecdir)/pesign/ -- $(INSTALL) -m 750 pesign-authorize-users $(INSTALLROOT)$(libexecdir)/pesign/ -- $(INSTALL) -m 750 pesign-authorize-groups $(INSTALLROOT)$(libexecdir)/pesign/ -+ $(INSTALL) -m 750 pesign-authorize $(INSTALLROOT)$(libexecdir)/pesign/ - $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pesign -- $(INSTALL) -m 600 /dev/null $(INSTALLROOT)/etc/pesign/users -- $(INSTALL) -m 600 /dev/null $(INSTALLROOT)/etc/pesign/groups -+ $(INSTALL) -m 600 pesign-users $(INSTALLROOT)/etc/pesign/users -+ $(INSTALL) -m 600 pesign-groups $(INSTALLROOT)/etc/pesign/groups - - .PHONY: all deps clean install -diff --git a/src/pesign-authorize b/src/pesign-authorize -new file mode 100755 -index 0000000..a496f60 ---- /dev/null -+++ b/src/pesign-authorize -@@ -0,0 +1,56 @@ -+#!/bin/bash -+set -e -+set -u -+ -+# -+# With /run/pesign/socket on tmpfs, a simple way of restoring the -+# acls for specific users is useful -+# -+# Compare to: http://infrastructure.fedoraproject.org/cgit/ansible.git/tree/roles/bkernel/tasks/main.yml?id=17198dadebf59d8090b7ed621bc8ab22152d2eb6 -+# -+ -+# License: GPLv2 -+declare -a fileusers=() -+declare -a dirusers=() -+for user in $(cat /etc/pesign/users); do -+ dirusers[${#dirusers[@]}]=-m -+ dirusers[${#dirusers[@]}]="u:$user:rwx" -+ fileusers[${#fileusers[@]}]=-m -+ fileusers[${#fileusers[@]}]="u:$user:rw" -+done -+ -+declare -a filegroups=() -+declare -a dirgroups=() -+for group in $(cat /etc/pesign/groups); do -+ dirgroups[${#dirgroups[@]}]=-m -+ dirgroups[${#dirgroups[@]}]="g:$group:rwx" -+ filegroups[${#filegroups[@]}]=-m -+ filegroups[${#filegroups[@]}]="g:$group:rw" -+done -+ -+update_subdir() { -+ subdir=$1 && shift -+ -+ setfacl -bk "${subdir}" -+ setfacl "${dirusers[@]}" "${dirgroups[@]}" "${subdir}" -+ for x in "${subdir}"* ; do -+ if [ -d "${x}" ]; then -+ setfacl -bk ${x} -+ setfacl "${dirusers[@]}" "${dirgroups[@]}" ${x} -+ update_subdir "${x}/" -+ elif [ -e "${x}" ]; then -+ setfacl -bk ${x} -+ setfacl "${fileusers[@]}" "${filegroups[@]}" ${x} -+ else -+ :; -+ fi -+ done -+} -+ -+for x in /var/run/pesign/ /etc/pki/pesign*/ ; do -+ if [ -d "${x}" ]; then -+ update_subdir "${x}" -+ else -+ :; -+ fi -+done -diff --git a/src/pesign-authorize-groups b/src/pesign-authorize-groups -deleted file mode 100644 -index cf51fb6..0000000 ---- a/src/pesign-authorize-groups -+++ /dev/null -@@ -1,30 +0,0 @@ --#!/bin/bash --set -e -- --# --# With /run/pesign/socket on tmpfs, a simple way of restoring the --# acls for specific groups is useful --# --# Compare to: http://infrastructure.fedoraproject.org/cgit/ansible.git/tree/roles/bkernel/tasks/main.yml?id=17198dadebf59d8090b7ed621bc8ab22152d2eb6 --# -- --# License: GPLv2 -- --if [ -r /etc/pesign/groups ]; then -- for group in $(cat /etc/pesign/groups); do -- if [ -d /var/run/pesign ]; then -- setfacl -m g:${group}:rx /var/run/pesign -- if [ -e /var/run/pesign/socket ]; then -- setfacl -m g:${group}:rw /var/run/pesign/socket -- fi -- fi -- for x in /etc/pki/pesign*/ ; do -- if [ -d ${x} ]; then -- setfacl -m g:${group}:rx ${x} -- for y in ${x}{cert8,key3,secmod}.db ; do -- setfacl -m g:${group}:rw ${y} -- done -- fi -- done -- done --fi -diff --git a/src/pesign-authorize-users b/src/pesign-authorize-users -deleted file mode 100644 -index 940138e..0000000 ---- a/src/pesign-authorize-users -+++ /dev/null -@@ -1,30 +0,0 @@ --#!/bin/bash --set -e -- --# --# With /run/pesign/socket on tmpfs, a simple way of restoring the --# acls for specific users is useful --# --# Compare to: http://infrastructure.fedoraproject.org/cgit/ansible.git/tree/roles/bkernel/tasks/main.yml?id=17198dadebf59d8090b7ed621bc8ab22152d2eb6 --# -- --# License: GPLv2 -- --if [ -r /etc/pesign/users ]; then -- for username in $(cat /etc/pesign/users); do -- if [ -d /var/run/pesign ]; then -- setfacl -m g:${username}:rx /var/run/pesign -- if [ -e /var/run/pesign/socket ]; then -- setfacl -m g:${username}:rw /var/run/pesign/socket -- fi -- fi -- for x in /etc/pki/pesign*/ ; do -- if [ -d ${x} ]; then -- setfacl -m g:${username}:rx ${x} -- for y in ${x}{cert8,key3,secmod}.db ; do -- setfacl -m g:${username}:rw ${y} -- done -- fi -- done -- done --fi -diff --git a/src/pesign.service.in b/src/pesign.service.in -index aaa408e..c75a000 100644 ---- a/src/pesign.service.in -+++ b/src/pesign.service.in -@@ -6,5 +6,4 @@ PrivateTmp=true - Type=forking - PIDFile=/var/run/pesign.pid - ExecStart=/usr/bin/pesign --daemonize --ExecStartPost=@@LIBEXECDIR@@/pesign/pesign-authorize-users --ExecStartPost=@@LIBEXECDIR@@/pesign/pesign-authorize-groups -+ExecStartPost=@@LIBEXECDIR@@/pesign/pesign-authorize -diff --git a/src/pesign.sysvinit.in b/src/pesign.sysvinit.in -index dc508d8..b0e0f84 100644 ---- a/src/pesign.sysvinit.in -+++ b/src/pesign.sysvinit.in -@@ -27,8 +27,7 @@ start(){ - RETVAL=$? - echo - touch /var/lock/subsys/pesign -- @@LIBEXECDIR@@/pesign/pesign-authorize-users -- @@LIBEXECDIR@@/pesign/pesign-authorize-groups -+ @@LIBEXECDIR@@/pesign/pesign-authorize - } - - stop(){ --- -2.13.4 - diff --git a/0024-Make-the-daemon-also-try-to-give-better-errors-on-EP.patch b/0024-Make-the-daemon-also-try-to-give-better-errors-on-EP.patch deleted file mode 100644 index 8f4a380..0000000 --- a/0024-Make-the-daemon-also-try-to-give-better-errors-on-EP.patch +++ /dev/null @@ -1,95 +0,0 @@ -From a7b0f7e1ce2de1acea9a8c286a0ff3dd9bc245cb Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 8 Aug 2017 17:28:19 -0400 -Subject: [PATCH 24/29] Make the daemon also try to give better errors on - -EPERM etc. - -Basically 6796e5f but also for the daemon. This also tries to fix them -up to save errno better, for more accurate reporting. - -Signed-off-by: Peter Jones ---- - src/daemon.c | 27 +++++++++++++++++++++++++-- - src/pesign.c | 8 ++++++-- - 2 files changed, 31 insertions(+), 4 deletions(-) - -diff --git a/src/daemon.c b/src/daemon.c -index 7f694b2..942d576 100644 ---- a/src/daemon.c -+++ b/src/daemon.c -@@ -19,6 +19,7 @@ - - #include - #include -+#include - #include - #include - #include -@@ -1104,10 +1105,32 @@ daemonize(cms_context *cms_ctx, char *certdir, int do_fork) - "pesignd starting (pid %d)", ctx.pid); - - SECStatus status = NSS_Init(certdir); -+ int error = errno; - if (status != SECSuccess) { -+ char *globpattern = NULL; -+ rc = asprintf(&globpattern, "%s/cert*.db", -+ certdir); -+ if (rc > 0) { -+ glob_t globbuf; -+ memset(&globbuf, 0, sizeof(globbuf)); -+ rc = glob(globpattern, GLOB_ERR, NULL, -+ &globbuf); -+ if (rc != 0) { -+ errno = error; -+ ctx.backup_cms->log(ctx.backup_cms, -+ ctx.priority|LOG_NOTICE, -+ "Could not open NSS database (\"%s\"): %m", -+ PORT_ErrorToString(PORT_GetError())); -+ exit(1); -+ } -+ } -+ } -+ if (status != SECSuccess) { -+ errno = error; - ctx.backup_cms->log(ctx.backup_cms, ctx.priority|LOG_NOTICE, -- "Could not initialize nss: %s\n", -- PORT_ErrorToString(PORT_GetError())); -+ "Could not initialize nss.\n" -+ "NSS says \"%s\" errno says \"%m\"\n", -+ PORT_ErrorToString(PORT_GetError())); - exit(1); - } - -diff --git a/src/pesign.c b/src/pesign.c -index 5879cfc..6ceda34 100644 ---- a/src/pesign.c -+++ b/src/pesign.c -@@ -660,10 +660,12 @@ main(int argc, char *argv[]) - - if (!daemon) { - SECStatus status; -+ int error; - if (need_db) { - status = NSS_Init(certdir); - if (status != SECSuccess) { - char *globpattern = NULL; -+ error = errno; - rc = asprintf(&globpattern, "%s/cert*.db", - certdir); - if (rc > 0) { -@@ -680,8 +682,10 @@ main(int argc, char *argv[]) - } else - status = NSS_NoDB_Init(NULL); - if (status != SECSuccess) { -- errx(1, "Could not initialize nss. NSS says \"%s\" errno says \"%m\"\n", -- PORT_ErrorToString(PORT_GetError())); -+ errno = error; -+ errx(1, "Could not initialize nss.\n" -+ "NSS says \"%s\" errno says \"%m\"\n", -+ PORT_ErrorToString(PORT_GetError())); - } - - status = register_oids(ctxp->cms_ctx); --- -2.13.4 - diff --git a/0025-certdb-fix-PRTime-printfs-for-i686.patch b/0025-certdb-fix-PRTime-printfs-for-i686.patch deleted file mode 100644 index 0fc2ad8..0000000 --- a/0025-certdb-fix-PRTime-printfs-for-i686.patch +++ /dev/null @@ -1,31 +0,0 @@ -From bc1043bf2b428971e29a61a341da9a57595bada5 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Wed, 9 Aug 2017 17:40:33 -0400 -Subject: [PATCH 25/29] certdb: fix PRTime printfs for i686 - -Signed-off-by: Peter Jones ---- - src/certdb.c | 5 ++--- - 1 file changed, 2 insertions(+), 3 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index fae80af..29c9502 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -384,11 +384,10 @@ check_cert(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - } - - if (lateNow < earlyNow) -- printf("Signature has impossible time constraint: %ld <= %ld\n", -- earlyNow / 1000000, lateNow / 1000000); -+ printf("Signature has impossible time constraint: %lld <= %lld\n", -+ earlyNow / 1000000LL, lateNow / 1000000LL); - atTime = earlyNow / 2 + lateNow / 2; - -- - cinfo = SEC_PKCS7DecodeItem(pkcs7sig, NULL, NULL, NULL, NULL, NULL, - NULL, NULL); - if (!cinfo) --- -2.13.4 - diff --git a/0026-Clean-up-gcc-command-lines-a-little.patch b/0026-Clean-up-gcc-command-lines-a-little.patch deleted file mode 100644 index 928d62d..0000000 --- a/0026-Clean-up-gcc-command-lines-a-little.patch +++ /dev/null @@ -1,41 +0,0 @@ -From a44115c9b4f43a1a7219f897bd33555e653d2e20 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Thu, 10 Aug 2017 10:02:38 -0400 -Subject: [PATCH 26/29] Clean up gcc command lines a little - -Signed-off-by: Peter Jones ---- - Make.defaults | 9 ++++----- - 1 file changed, 4 insertions(+), 5 deletions(-) - -diff --git a/Make.defaults b/Make.defaults -index 39b78f0..b6c0381 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -20,8 +20,7 @@ CROSS_COMPILE ?= $(bindir) - PKG_CONFIG = $(CROSS_COMPILE)pkg-config - CC := $(if $(filter default,$(origin CC)),$(CROSS_COMPILE)gcc,$(CC)) - CCLD := $(if $(filter undefined,$(origin CCLD)),$(CC),$(CCLD)) --CFLAGS ?= -O0 -g3 -fvar-tracking -fvar-tracking-assignments \ -- -Wall -Werror -Wextra -Wno-error=cpp -+CFLAGS ?= -O0 -g3 -fvar-tracking -fvar-tracking-assignments -Wno-error=cpp - AS := $(CROSS_COMPILE)as - AR := $(CROSS_COMPILE)gcc-ar - RANLIB := $(CROSS_COMPILE)gcc-ranlib -@@ -36,10 +35,10 @@ ARCH := $(shell uname -m | sed s,i[3456789]86,ia32,) - - SOFLAGS = -shared - clang_cflags = --gcc_cflags = -Wmaybe-uninitialized -+gcc_cflags = -Wmaybe-uninitialized -grecord-gcc-switches - cflags = $(CFLAGS) $(ARCH3264) \ -- -Wall -Werror -Wno-cpp -Wsign-compare -Wno-unused-result \ -- -Wno-unused-function\ -+ -Wall -Werror -Wextra -Wsign-compare -Wno-unused-result \ -+ -Wno-unused-function -Wsign-compare \ - -std=gnu11 -fshort-wchar -fPIC -flto -fno-strict-aliasing \ - -fno-merge-constants -fkeep-inline-functions \ - -D_GNU_SOURCE -DCONFIG_$(ARCH) -I${TOPDIR}/include \ --- -2.13.4 - diff --git a/0027-Make-pesign-users-groups-static-in-the-repo.patch b/0027-Make-pesign-users-groups-static-in-the-repo.patch deleted file mode 100644 index 4131de3..0000000 --- a/0027-Make-pesign-users-groups-static-in-the-repo.patch +++ /dev/null @@ -1,54 +0,0 @@ -From a133d051c3f8acf3e058e92711eb528c3c0f41f9 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Thu, 10 Aug 2017 10:03:37 -0400 -Subject: [PATCH 27/29] Make pesign-{users,groups} static in the repo. - -Signed-off-by: Peter Jones ---- - src/Makefile | 5 +---- - src/pesign-groups | 1 + - src/pesign-users | 1 + - 3 files changed, 3 insertions(+), 4 deletions(-) - create mode 100644 src/pesign-groups - create mode 100644 src/pesign-users - -diff --git a/src/Makefile b/src/Makefile -index 84ad130..7d68fa1 100644 ---- a/src/Makefile -+++ b/src/Makefile -@@ -7,7 +7,7 @@ include $(TOPDIR)/Make.defaults - - BINTARGETS=authvar client efikeygen efisiglist pesigcheck pesign - SVCTARGETS=pesign.sysvinit pesign.service --TARGETS=$(BINTARGETS) $(SVCTARGETS) pesign-users pesign-groups -+TARGETS=$(BINTARGETS) $(SVCTARGETS) - - all : deps $(TARGETS) - -@@ -65,9 +65,6 @@ install_sysvinit: pesign.sysvinit - $(INSTALL) -d -m 755 $(INSTALLROOT)/etc/rc.d/init.d/ - $(INSTALL) -m 755 pesign.sysvinit $(INSTALLROOT)/etc/rc.d/init.d/pesign - --pesign-users pesign-groups : -- echo pesign > $@ -- - install : - $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign/ - $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign-rh-test/ -diff --git a/src/pesign-groups b/src/pesign-groups -new file mode 100644 -index 0000000..7f57cc5 ---- /dev/null -+++ b/src/pesign-groups -@@ -0,0 +1 @@ -+pesign -diff --git a/src/pesign-users b/src/pesign-users -new file mode 100644 -index 0000000..7f57cc5 ---- /dev/null -+++ b/src/pesign-users -@@ -0,0 +1 @@ -+pesign --- -2.13.4 - diff --git a/0028-rpm-Make-the-client-signer-use-the-fedora-values-unl.patch b/0028-rpm-Make-the-client-signer-use-the-fedora-values-unl.patch deleted file mode 100644 index 793fe6c..0000000 --- a/0028-rpm-Make-the-client-signer-use-the-fedora-values-unl.patch +++ /dev/null @@ -1,43 +0,0 @@ -From 025eb8aea94761fdc45507b6192aafdef80d4842 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Wed, 9 Aug 2017 17:31:31 -0400 -Subject: [PATCH 28/29] rpm: Make the client signer use the fedora values - unless overridden - -Signed-off-by: Peter Jones ---- - src/macros.pesign | 9 ++++++--- - 1 file changed, 6 insertions(+), 3 deletions(-) - -diff --git a/src/macros.pesign b/src/macros.pesign -index 69280e9..22a3ee6 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -9,6 +9,9 @@ - %__pesign_token %{nil}%{?pe_signing_token:-t "%{pe_signing_token}"} - %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} - -+%__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} -+%__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} -+ - %_pesign /usr/bin/pesign - %_pesign_client /usr/bin/pesign-client - -@@ -41,11 +44,11 @@ - --certdir ${nss} -c signer %{-o} \ - rm -rf ${sattrs} ${sattrs}.sig ${nss} \ - elif [ -S /var/run/pesign/socket ]; then \ -- %{_pesign_client} -t %{__pesign_token} \\\ -- -c %{__pesign_cert} \\\ -+ %{_pesign_client} -t %{__pesign_client_token} \\\ -+ -c %{__pesign_client_cert} \\\ - %{-i} %{-o} %{-e} %{-s} %{-C} \ - else \ -- %{_pesign} -t %{__pesign_token} -c %{__pesign_cert} \\\ -+ %{_pesign} %{__pesign_token} -c %{__pesign_cert} \\\ - --certdir ${_pesign_nssdir} \\\ - %{-i} %{-o} %{-e} %{-s} %{-C} \ - fi \ --- -2.13.4 - diff --git a/0029-Make-macros.pesign-error-in-kojibuilder-if-we-don-t-.patch b/0029-Make-macros.pesign-error-in-kojibuilder-if-we-don-t-.patch deleted file mode 100644 index 753afe8..0000000 --- a/0029-Make-macros.pesign-error-in-kojibuilder-if-we-don-t-.patch +++ /dev/null @@ -1,39 +0,0 @@ -From 86a6b02e4b95ab3629446e71895cc5e57ad4482f Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 14 Aug 2017 11:37:43 -0400 -Subject: [PATCH 29/29] Make macros.pesign error in kojibuilder if we don't - have perms on the socket - ---- - src/macros.pesign | 9 +++++++++ - 1 file changed, 9 insertions(+) - -diff --git a/src/macros.pesign b/src/macros.pesign -index 22a3ee6..1665b4c 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -43,6 +43,21 @@ - %{_pesign} -R ${sattrs}.sig -I ${sattrs} %{-i} \\\ - --certdir ${nss} -c signer %{-o} \ - rm -rf ${sattrs} ${sattrs}.sig ${nss} \ -+ elif [ "%{vendor}" == "Fedora Project" -a \\\ -+ "$(id -un)" == "mockbuild" -a \\\ -+ "$(uname -m)" == "x86_64" ] && \\\ -+ grep -q ID=fedora /etc/os-release && \\\ -+ [[ "%{_buildhost}" =~ ^bkernel.* ]] && \\\ -+ ! [ -S /var/run/pesign/socket ]; then \ -+ echo "No socket even though this is %{_buildhost}" \ -+ ls -ld /var/run/pesign || : \ -+ getfacl /var/run/pesign || : \ -+ ls -l /var/run/pesign/socket || : \ -+ getfacl /var/run/pesign/socket || : \ -+ echo =========== env ============== \ -+ set \ -+ echo =========== env ============== \ -+ exit 1 \ - elif [ -S /var/run/pesign/socket ]; then \ - %{_pesign_client} -t %{__pesign_client_token} \\\ - -c %{__pesign_client_cert} \\\ --- -2.13.4 - diff --git a/0032-Use-sql-type-nss-database-everywhere-by-default.patch b/0032-Use-sql-type-nss-database-everywhere-by-default.patch deleted file mode 100644 index cab7653..0000000 --- a/0032-Use-sql-type-nss-database-everywhere-by-default.patch +++ /dev/null @@ -1,104 +0,0 @@ -From c2f2c8845b3ed34da0a76806ec81bc5ad60179ef Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 12 Mar 2018 10:51:24 -0400 -Subject: [PATCH] Use sql-type nss database everywhere by default. - -Signed-off-by: Peter Jones ---- - src/authvar.c | 2 ++ - src/client.c | 3 +++ - src/efikeygen.c | 2 ++ - src/efisiglist.c | 2 ++ - src/pesigcheck.c | 2 ++ - src/pesign.c | 2 ++ - 6 files changed, 13 insertions(+) - -diff --git a/src/authvar.c b/src/authvar.c -index 03e0c47f61c..47a73d12eaa 100644 ---- a/src/authvar.c -+++ b/src/authvar.c -@@ -272,6 +272,8 @@ main(int argc, char *argv[]) - - int action = 0; - -+ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); -+ - rc = authvar_context_init(ctxp); - if (rc < 0) { - fprintf(stderr, "Could not initialize context: %m\n"); -diff --git a/src/client.c b/src/client.c -index 575c873fb70..64e7bbb7689 100644 ---- a/src/client.c -+++ b/src/client.c -@@ -22,6 +22,7 @@ - #include - #include - #include -+#include - #include - #include - #include -@@ -628,6 +629,8 @@ main(int argc, char *argv[]) - POPT_TABLEEND - }; - -+ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); -+ - optCon = poptGetContext("pesign", argc, (const char **)argv, options,0); - - rc = poptReadDefaultConfig(optCon, 0); -diff --git a/src/efikeygen.c b/src/efikeygen.c -index 93905782c0c..ad34970a62d 100644 ---- a/src/efikeygen.c -+++ b/src/efikeygen.c -@@ -595,6 +595,8 @@ int main(int argc, char *argv[]) - POPT_TABLEEND - }; - -+ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); -+ - optCon = poptGetContext("pesign", argc, (const char **)argv, options,0); - - int rc = poptReadDefaultConfig(optCon, 0); -diff --git a/src/efisiglist.c b/src/efisiglist.c -index a7ed528ca13..b88c4a06ded 100644 ---- a/src/efisiglist.c -+++ b/src/efisiglist.c -@@ -177,6 +177,8 @@ main(int argc, char *argv[]) - POPT_TABLEEND - }; - -+ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); -+ - optCon = poptGetContext("pesign", argc, (const char **)argv, options,0); - - rc = poptReadDefaultConfig(optCon, 0); -diff --git a/src/pesigcheck.c b/src/pesigcheck.c -index c8e10860855..535999ca7fa 100644 ---- a/src/pesigcheck.c -+++ b/src/pesigcheck.c -@@ -464,6 +464,8 @@ main(int argc, char *argv[]) - POPT_TABLEEND - }; - -+ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); -+ - rc = pesigcheck_context_init(ctxp); - if (rc < 0) { - fprintf(stderr, "pesigcheck: Could not initialize context: %m\n"); -diff --git a/src/pesign.c b/src/pesign.c -index 6ceda34f797..bc12e4d920a 100644 ---- a/src/pesign.c -+++ b/src/pesign.c -@@ -416,6 +416,8 @@ main(int argc, char *argv[]) - char *certdir = "/etc/pki/pesign"; - char *signum = NULL; - -+ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); -+ - rc = pesign_context_new(&ctxp); - if (rc < 0) { - fprintf(stderr, "Could not initialize context: %m\n"); --- -2.26.2 - diff --git a/pesign.spec b/pesign.spec index c5f1044..9d4932b 100644 --- a/pesign.spec +++ b/pesign.spec @@ -2,8 +2,8 @@ Name: pesign Summary: Signing utility for UEFI binaries -Version: 0.112 -Release: 31%{?dist} +Version: 113 +Release: 1%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -37,42 +37,12 @@ ExclusiveArch: %{ix86} x86_64 ia64 aarch64 %{arm} BuildRequires: rh-signing-tools >= 1.20-2 %endif -Source0: https://github.com/vathpela/pesign/releases/download/%{version}/pesign-%{version}.tar.bz2 +Source0: https://github.com/rhboot/pesign/releases/download/%{version}/pesign-%{version}.tar.bz2 Source1: certs.tar.xz Source2: pesign.py -Patch0001: 0001-cms-kill-generate_integer-it-doesn-t-build-on-i686-a.patch -Patch0002: 0002-Fix-command-line-parsing.patch -Patch0003: 0003-gcc-don-t-error-on-stuff-in-includes.patch -Patch0004: 0004-Fix-certficate-argument-name.patch -Patch0005: 0005-Fix-description-of-ascii-armor-option-in-manpage.patch -Patch0006: 0006-Make-ascii-work-since-we-documented-it.patch -Patch0007: 0007-Switch-pesign-client-to-also-accept-token-cert-macro.patch -Patch0008: 0008-pesigcheck-Verify-with-the-cert-as-an-object-signer.patch -Patch0009: 0009-pesigcheck-make-certfile-actually-work.patch -Patch0010: 0010-signerInfos-make-sure-err-is-always-initialized.patch -Patch0011: 0011-pesign-make-pesign-h-tell-you-the-file-name.patch -Patch0012: 0012-Add-coverity-build-scripts.patch -Patch0013: 0013-Document-implicit-fallthrough.patch -Patch0014: 0014-Actually-setfacl-each-directory-of-our-key-storage.patch -Patch0015: 0015-oid-add-SHIM_EKU_MODULE_SIGNING_ONLY-and-fix-our-arr.patch -Patch0016: 0016-efikeygen-add-modsign.patch -Patch0017: 0017-check_cert_db-try-even-harder-to-pick-a-reasonable-v.patch -Patch0018: 0018-show-which-db-we-re-checking.patch -Patch0019: 0019-more-about-the-time.patch -Patch0020: 0020-try-to-say-why-something-fails.patch -Patch0021: 0021-Fix-race-condition-in-SEC_GetPassword.patch -Patch0022: 0022-sysvinit-Create-the-socket-directory-at-runtime.patch -Patch0023: 0023-Better-authorization-scripts.-Again.patch -Patch0024: 0024-Make-the-daemon-also-try-to-give-better-errors-on-EP.patch -Patch0025: 0025-certdb-fix-PRTime-printfs-for-i686.patch -Patch0026: 0026-Clean-up-gcc-command-lines-a-little.patch -Patch0027: 0027-Make-pesign-users-groups-static-in-the-repo.patch -Patch0028: 0028-rpm-Make-the-client-signer-use-the-fedora-values-unl.patch -Patch0029: 0029-Make-macros.pesign-error-in-kojibuilder-if-we-don-t-.patch -Patch0030: 0030-efikeygen-Fix-the-build-with-nss-3.44.patch -Patch0031: 0031-pesigcheck-Fix-a-wrong-assignment.patch -Patch0032: 0032-Use-sql-type-nss-database-everywhere-by-default.patch +Patch0001: 0001-efikeygen-Fix-the-build-with-nss-3.44.patch +Patch0002: 0002-pesigcheck-Fix-a-wrong-assignment.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -138,9 +108,6 @@ exit 0 %post %systemd_post pesign.service -#%%posttrans -#%%{_libexecdir}/pesign/pesign-authorize - %preun %systemd_preun pesign.service @@ -148,7 +115,8 @@ exit 0 %systemd_postun_with_restart pesign.service %posttrans -certutil -d /etc/pki/pesign/ -X -L > /dev/null +certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null +%{_libexecdir}/pesign/pesign-authorize %endif %files @@ -183,6 +151,10 @@ certutil -d /etc/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Thu Jun 11 2020 Javier Martinez Canillas - 113-1 +- Update to 113 release + Resolves: rhbz#1708773 + * Mon Jun 08 2020 Javier Martinez Canillas - 0.112-31 - Switch default NSS database to SQLite format (pjones) Resolves: rhbz#1827902 diff --git a/sources b/sources index a337e1e..d0199f7 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ SHA512 (certs.tar.xz) = ddac535c786d1a23074534323c4ce89f907d4f82b19c5d3a9c814b145fbac1599cd2386cf20c28d22aee7d5c4db441f052bab9ee655de756117a0a0bc99b525f -SHA512 (pesign-0.112.tar.bz2) = 96bff27ce5059f1ea299c21ac88998a0c17851b8b06ba2f3e286de5cd4d73651b670ac00ca035481faf9c963338527c89120c63ec891a95ce9ecb9130fbc5e5c +SHA512 (pesign-113.tar.bz2) = 89c5e33bf6ac8f8dc4b65192e5fd4bf1fea285106d1de2a6ea02a8c5090f2ec5976b1d80c60e57f74fa56dc25b174a4dd5682292db44ab9aeab69ea992dfef36 From edca44f2a281929721b0c1681e7b0fea69b603f8 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Thu, 11 Jun 2020 16:26:40 -0400 Subject: [PATCH 07/70] Fix a signing protocol bug we introduced in 113 that makes the fedora kernel builders fail. Related: rhbz#1708773 Signed-off-by: Peter Jones --- ...t-and-server-work-with-the-113-proto.patch | 317 ++++++++++++++++++ pesign.spec | 8 +- 2 files changed, 324 insertions(+), 1 deletion(-) create mode 100644 0003-Make-0.112-client-and-server-work-with-the-113-proto.patch diff --git a/0003-Make-0.112-client-and-server-work-with-the-113-proto.patch b/0003-Make-0.112-client-and-server-work-with-the-113-proto.patch new file mode 100644 index 0000000..e639675 --- /dev/null +++ b/0003-Make-0.112-client-and-server-work-with-the-113-proto.patch @@ -0,0 +1,317 @@ +From 84547e6b7173e4b10a1931fd25f329ea9a8f68b0 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Thu, 11 Jun 2020 16:23:14 -0400 +Subject: [PATCH] Make 0.112 client and server work with the 113 protocol and + vise versa + +This makes the version of the sign API that takes a file type optional, +and makes the client attempt to negotiate which version it's getting. +It also leaves the server able to still handle the version from before +the file type was added. + +Signed-off-by: Peter Jones +--- + src/client.c | 74 +++++++++++++++++++++++++++++++++++++--------------- + src/daemon.c | 63 +++++++++++++++++++++++++++++--------------- + src/daemon.h | 2 ++ + 3 files changed, 97 insertions(+), 42 deletions(-) + +diff --git a/src/client.c b/src/client.c +index aa373abd981..57bcc09cbe8 100644 +--- a/src/client.c ++++ b/src/client.c +@@ -11,6 +11,7 @@ + #include + #include + #include ++#include + #include + #include + #include +@@ -84,8 +85,8 @@ connect_to_server(void) + static int32_t + check_response(int sd, char **srvmsg); + +-static void +-check_cmd_version(int sd, uint32_t command, char *name, int32_t version) ++static int ++check_cmd_version(int sd, uint32_t command, char *name, int32_t version, bool do_exit) + { + struct msghdr msg; + struct iovec iov[1]; +@@ -104,7 +105,7 @@ check_cmd_version(int sd, uint32_t command, char *name, int32_t version) + ssize_t n; + n = sendmsg(sd, &msg, 0); + if (n < 0) { +- fprintf(stderr, "check-cmd-version: kill daemon failed: %m\n"); ++ fprintf(stderr, "check-cmd-version: sendmsg failed: %m\n"); + exit(1); + } + +@@ -120,11 +121,17 @@ check_cmd_version(int sd, uint32_t command, char *name, int32_t version) + + char *srvmsg = NULL; + int32_t rc = check_response(sd, &srvmsg); +- if (rc < 0) ++ ++ if (do_exit && rc < 0) + errx(1, "command \"%s\" not known by server", name); +- if (rc != version) ++ ++ if (do_exit && rc != version) + errx(1, "command \"%s\": client version %d, server version %d", + name, version, rc); ++ ++ if (rc < 0) ++ return rc; ++ return rc == version; + } + + static void +@@ -134,7 +141,7 @@ send_kill_daemon(int sd) + struct iovec iov; + pesignd_msghdr pm; + +- check_cmd_version(sd, CMD_KILL_DAEMON, "kill-daemon", 0); ++ check_cmd_version(sd, CMD_KILL_DAEMON, "kill-daemon", 0, true); + + pm.version = PESIGND_VERSION; + pm.command = CMD_KILL_DAEMON; +@@ -276,7 +283,7 @@ unlock_token(int sd, char *tokenname, char *pin) + + uint32_t size1 = pesignd_string_size(pin); + +- check_cmd_version(sd, CMD_UNLOCK_TOKEN, "unlock-token", 0); ++ check_cmd_version(sd, CMD_UNLOCK_TOKEN, "unlock-token", 0, true); + + pm.version = PESIGND_VERSION; + pm.command = CMD_UNLOCK_TOKEN; +@@ -353,7 +360,7 @@ is_token_unlocked(int sd, char *tokenname) + + uint32_t size0 = pesignd_string_size(tokenname); + +- check_cmd_version(sd, CMD_IS_TOKEN_UNLOCKED, "is-token-unlocked", 0); ++ check_cmd_version(sd, CMD_IS_TOKEN_UNLOCKED, "is-token-unlocked", 0, true); + + pm.version = PESIGND_VERSION; + pm.command = CMD_IS_TOKEN_UNLOCKED; +@@ -452,6 +459,9 @@ static void + sign(int sd, char *infile, char *outfile, char *tokenname, char *certname, + int attached, uint32_t format) + { ++ int rc; ++ bool add_file_type; ++ + int infd = open(infile, O_RDONLY); + if (infd < 0) { + fprintf(stderr, "pesign-client: could not open input file " +@@ -481,12 +491,28 @@ oom: + exit(1); + } + +- check_cmd_version(sd, attached ? CMD_SIGN_ATTACHED : CMD_SIGN_DETACHED, +- attached ? "sign-attached" : "sign-detached", 0); ++ rc = check_cmd_version(sd, ++ attached ? CMD_SIGN_ATTACHED_WITH_FILE_TYPE ++ : CMD_SIGN_DETACHED_WITH_FILE_TYPE, ++ attached ? "sign-attached" : "sign-detached", ++ 0, format == FORMAT_KERNEL_MODULE); ++ if (rc >= 0) { ++ add_file_type = true; ++ } else { ++ add_file_type = false; ++ check_cmd_version(sd, attached ? CMD_SIGN_ATTACHED ++ : CMD_SIGN_DETACHED, ++ attached ? "sign-attached" : "sign-detached", ++ 0, true); ++ } + ++ printf("add_file_type:%d\n", add_file_type); + pm->version = PESIGND_VERSION; +- pm->command = attached ? CMD_SIGN_ATTACHED : CMD_SIGN_DETACHED; +- pm->size = size0 + size1 + sizeof(format); ++ pm->command = attached ? (add_file_type ? CMD_SIGN_ATTACHED_WITH_FILE_TYPE ++ : CMD_SIGN_ATTACHED) ++ : (add_file_type ? CMD_SIGN_DETACHED_WITH_FILE_TYPE ++ : CMD_SIGN_DETACHED); ++ pm->size = size0 + size1 + (add_file_type ? sizeof(format) : 0); + iov[0].iov_base = pm; + iov[0].iov_len = sizeof (*pm); + +@@ -503,25 +529,31 @@ oom: + } + + char *buffer; +- buffer = malloc(size0 + size1); ++ buffer = malloc(pm->size); + if (!buffer) + goto oom; + +- iov[0].iov_base = &format; +- iov[0].iov_len = sizeof(format); ++ int pos = 0; ++ ++ if (add_file_type) { ++ iov[pos].iov_base = &format; ++ iov[pos].iov_len = sizeof(format); ++ pos++; ++ } + + pesignd_string *tn = (pesignd_string *)buffer; + pesignd_string_set(tn, tokenname); +- iov[1].iov_base = tn; +- iov[1].iov_len = size0; ++ iov[pos].iov_base = tn; ++ iov[pos].iov_len = size0; ++ pos++; + + pesignd_string *cn = pesignd_string_next(tn); + pesignd_string_set(cn, certname); +- iov[2].iov_base = cn; +- iov[2].iov_len = size1; ++ iov[pos].iov_base = cn; ++ iov[pos].iov_len = size1; + + msg.msg_iov = iov; +- msg.msg_iovlen = 3; ++ msg.msg_iovlen = add_file_type ? 3 : 2; + + n = sendmsg(sd, &msg, 0); + if (n < 0) { +@@ -535,7 +567,7 @@ oom: + send_fd(sd, outfd); + + char *srvmsg = NULL; +- int rc = check_response(sd, &srvmsg); ++ rc = check_response(sd, &srvmsg); + if (rc < 0) { + fprintf(stderr, "pesign-client: signing failed: \"%s\"\n", + srvmsg); +diff --git a/src/daemon.c b/src/daemon.c +index 9374d59be30..494beb9af72 100644 +--- a/src/daemon.c ++++ b/src/daemon.c +@@ -12,6 +12,7 @@ + #include + #include + #include ++#include + #include + #include + #include +@@ -561,7 +562,7 @@ out: + + static void + handle_signing(context *ctx, struct pollfd *pollfd, socklen_t size, +- int attached) ++ int attached, bool with_file_type) + { + struct msghdr msg; + struct iovec iov; +@@ -585,8 +586,12 @@ oom: + + n = recvmsg(pollfd->fd, &msg, MSG_WAITALL); + +- file_format = *((uint32_t *) buffer); +- n -= sizeof(uint32_t); ++ if (with_file_type) { ++ file_format = *((uint32_t *) buffer); ++ n -= sizeof(uint32_t); ++ } else { ++ file_format = FORMAT_PE_BINARY; ++ } + + pesignd_string *tn = (pesignd_string *)(buffer + sizeof(uint32_t)); + if (n < (long long)sizeof(tn->size)) { +@@ -666,34 +671,44 @@ finish: + teardown_digests(ctx->cms); + } + ++static inline void ++handle_sign_helper(context *ctx, struct pollfd *pollfd, socklen_t size, ++ int attached, bool with_file_type) ++{ ++ int rc = cms_context_alloc(&ctx->cms); ++ if (rc < 0) ++ return; ++ ++ steal_from_cms(ctx->backup_cms, ctx->cms); ++ ++ handle_signing(ctx, pollfd, size, attached, with_file_type); ++ ++ hide_stolen_goods_from_cms(ctx->cms, ctx->backup_cms); ++ cms_context_fini(ctx->cms); ++} ++ + static void + handle_sign_attached(context *ctx, struct pollfd *pollfd, socklen_t size) + { +- int rc = cms_context_alloc(&ctx->cms); +- if (rc < 0) +- return; ++ handle_sign_helper(ctx, pollfd, size, 1, false); ++} + +- steal_from_cms(ctx->backup_cms, ctx->cms); +- +- handle_signing(ctx, pollfd, size, 1); +- +- hide_stolen_goods_from_cms(ctx->cms, ctx->backup_cms); +- cms_context_fini(ctx->cms); ++static void ++handle_sign_attached_with_file_type(context *ctx, struct pollfd *pollfd, socklen_t size) ++{ ++ handle_sign_helper(ctx, pollfd, size, 1, true); + } + + static void + handle_sign_detached(context *ctx, struct pollfd *pollfd, socklen_t size) + { +- int rc = cms_context_alloc(&ctx->cms); +- if (rc < 0) +- return; ++ handle_sign_helper(ctx, pollfd, size, 0, false); ++} + +- steal_from_cms(ctx->backup_cms, ctx->cms); +- +- handle_signing(ctx, pollfd, size, 0); +- +- hide_stolen_goods_from_cms(ctx->cms, ctx->backup_cms); +- cms_context_fini(ctx->cms); ++static void ++handle_sign_detached_with_file_type(context *ctx, struct pollfd *pollfd, socklen_t size) ++{ ++ handle_sign_helper(ctx, pollfd, size, 0, true); + } + + static void +@@ -725,6 +740,12 @@ cmd_table_t cmd_table[] = { + { CMD_UNLOCK_TOKEN, handle_unlock_token, "unlock-token", 0 }, + { CMD_SIGN_ATTACHED, handle_sign_attached, "sign-attached", 0 }, + { CMD_SIGN_DETACHED, handle_sign_detached, "sign-detached", 0 }, ++ { CMD_SIGN_ATTACHED_WITH_FILE_TYPE, ++ handle_sign_attached_with_file_type, ++ "sign-attached-with-file-type", 0 }, ++ { CMD_SIGN_DETACHED_WITH_FILE_TYPE, ++ handle_sign_detached_with_file_type, ++ "sign-detached-with-file-type", 0 }, + { CMD_RESPONSE, NULL, "response", 0 }, + { CMD_IS_TOKEN_UNLOCKED, handle_is_token_unlocked, + "is-token-unlocked", 0 }, +diff --git a/src/daemon.h b/src/daemon.h +index dd430512f1a..834d62c72d0 100644 +--- a/src/daemon.h ++++ b/src/daemon.h +@@ -33,6 +33,8 @@ typedef enum { + CMD_RESPONSE, + CMD_IS_TOKEN_UNLOCKED, + CMD_GET_CMD_VERSION, ++ CMD_SIGN_ATTACHED_WITH_FILE_TYPE, ++ CMD_SIGN_DETACHED_WITH_FILE_TYPE, + CMD_LIST_END + } pesignd_cmd; + +-- +2.26.2 + diff --git a/pesign.spec b/pesign.spec index 9d4932b..93351d0 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 1%{?dist} +Release: 2%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -43,6 +43,7 @@ Source2: pesign.py Patch0001: 0001-efikeygen-Fix-the-build-with-nss-3.44.patch Patch0002: 0002-pesigcheck-Fix-a-wrong-assignment.patch +Patch0003: 0003-Make-0.112-client-and-server-work-with-the-113-proto.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -151,6 +152,11 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Thu Jun 11 2020 Peter Jones - 113-2 +- Fix a signing protocol bug we introduced in 113 that makes the fedora + kernel builders fail. + Related: rhbz#1708773 + * Thu Jun 11 2020 Javier Martinez Canillas - 113-1 - Update to 113 release Resolves: rhbz#1708773 From 9b526cffa9cced6e2cb6ef1f6823579b1377b3a7 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Fri, 12 Jun 2020 11:52:32 -0400 Subject: [PATCH 08/70] Fix the signer name for fedora and some other minor nits Related: rhbz#1708773 Related: rhbz#1678146 Signed-off-by: Peter Jones --- 0004-Rename-var-run-to-run.patch | 46 +++++++++++++++++++ ...c-got-updated-and-the-token-name-cha.patch | 30 ++++++++++++ pesign.spec | 14 ++++-- 3 files changed, 85 insertions(+), 5 deletions(-) create mode 100644 0004-Rename-var-run-to-run.patch create mode 100644 0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch diff --git a/0004-Rename-var-run-to-run.patch b/0004-Rename-var-run-to-run.patch new file mode 100644 index 0000000..593761b --- /dev/null +++ b/0004-Rename-var-run-to-run.patch @@ -0,0 +1,46 @@ +From f886b7088dfea224e28c03b097c85c9bc20f5441 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Fri, 12 Jun 2020 11:49:44 -0400 +Subject: [PATCH] Rename /var/run/ to /run/ + +Signed-off-by: Peter Jones +--- + src/macros.pesign | 12 ++++++------ + src/tmpfiles.conf | 2 +- + 2 files changed, 7 insertions(+), 7 deletions(-) + +diff --git a/src/macros.pesign b/src/macros.pesign +index 56f75cafbc4..5a6da1c6809 100644 +--- a/src/macros.pesign ++++ b/src/macros.pesign +@@ -45,14 +45,14 @@ + rm -rf ${sattrs} ${sattrs}.sig ${nss} \ + elif [ "$(id -un)" == "kojibuilder" -a \\\ + grep -q ID=fedora /etc/os-release -a \\\ +- ! -S /var/run/pesign/socket ]; then \ ++ ! -S /run/pesign/socket ]; then \ + echo "No socket even though this is kojibuilder" 1>&2 \ +- ls -ld /var/run/pesign 1>&2 \ +- ls -l /var/run/pesign/socket 1>&2 \ +- getfacl /var/run/pesign 1>&2 \ +- getfacl /var/run/pesign/socket 1>&2 \ ++ ls -ld /run/pesign 1>&2 \ ++ ls -l /run/pesign/socket 1>&2 \ ++ getfacl /run/pesign 1>&2 \ ++ getfacl /run/pesign/socket 1>&2 \ + exit 1 \ +- elif [ -S /var/run/pesign/socket ]; then \ ++ elif [ -S /run/pesign/socket ]; then \ + %{_pesign_client} -t %{__pesign_client_token} \\\ + -c %{__pesign_client_cert} \\\ + %{-i} %{-o} %{-e} %{-s} %{-C} \ +diff --git a/src/tmpfiles.conf b/src/tmpfiles.conf +index c1cf35597d8..3375ad52a44 100644 +--- a/src/tmpfiles.conf ++++ b/src/tmpfiles.conf +@@ -1 +1 @@ +-D /var/run/pesign 0770 pesign pesign - ++D /run/pesign 0770 pesign pesign - +-- +2.26.2 + diff --git a/0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch b/0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch new file mode 100644 index 0000000..2b47880 --- /dev/null +++ b/0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch @@ -0,0 +1,30 @@ +From 56eaa15e986d808c670381ca375216eb3abd1588 Mon Sep 17 00:00:00 2001 +From: Jeremy Cline +Date: Tue, 18 Feb 2020 16:37:53 -0500 +Subject: [PATCH] Apparently opensc got updated and the token name changed + +All the kernel builds started failing yesterday because the signing +token could not be found. Update the token name in the macro shipped by +pesign. + +Signed-off-by: Peter Jones +--- + src/macros.pesign | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/macros.pesign b/src/macros.pesign +index 7c5cba170e9..56f75cafbc4 100644 +--- a/src/macros.pesign ++++ b/src/macros.pesign +@@ -9,7 +9,7 @@ + %__pesign_token %{nil}%{?pe_signing_token:-t "%{pe_signing_token}"} + %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} + +-%__pesign_client_token %{!?pe_signing_token:"Fedora Signer (OpenSC Card)"}%{?pe_signing_token:"%{pe_signing_token}"} ++%__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} + %__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} + + %_pesign /usr/bin/pesign +-- +2.26.2 + diff --git a/pesign.spec b/pesign.spec index 93351d0..70704d7 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 2%{?dist} +Release: 3%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -44,6 +44,8 @@ Source2: pesign.py Patch0001: 0001-efikeygen-Fix-the-build-with-nss-3.44.patch Patch0002: 0002-pesigcheck-Fix-a-wrong-assignment.patch Patch0003: 0003-Make-0.112-client-and-server-work-with-the-113-proto.patch +Patch0004: 0004-Rename-var-run-to-run.patch +Patch0005: 0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -61,9 +63,6 @@ git am %{patches} /dev/null || groupadd -r pesign getent passwd pesign >/dev/null || \ - useradd -r -g pesign -d /var/run/pesign -s /sbin/nologin \ + useradd -r -g pesign -d /run/pesign -s /sbin/nologin \ -c "Group for the pesign signing daemon" pesign exit 0 @@ -152,6 +151,11 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Fri Jun 12 2020 Peter Jones - 113-3 +- Fix the signer name for fedora and some other minor nits + Related: rhbz#1708773 + Related: rhbz#1678146 + * Thu Jun 11 2020 Peter Jones - 113-2 - Fix a signing protocol bug we introduced in 113 that makes the fedora kernel builders fail. From 4f2a0b0969fd62646a6eadda696c9c3bdeb04773 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 14:00:27 -0400 Subject: [PATCH 09/70] Attempt to fix kernel signing failures caused by -3... Signed-off-by: Peter Jones --- ...ros.pesign-to-pesign-rpmbuild-helper.patch | 263 ++++++++++++++++++ pesign.spec | 6 +- 2 files changed, 268 insertions(+), 1 deletion(-) create mode 100644 0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch diff --git a/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch new file mode 100644 index 0000000..12f9113 --- /dev/null +++ b/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch @@ -0,0 +1,263 @@ +From 873345b4970a28c7c590ca0c4e04bf88dd19e3b5 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 6 Jul 2020 13:54:35 -0400 +Subject: [PATCH] Move most of macros.pesign to pesign-rpmbuild-helper + +Signed-off-by: Peter Jones +--- + src/Makefile | 1 + + src/macros.pesign | 71 +++++------------- + src/pesign-rpmbuild-helper | 143 +++++++++++++++++++++++++++++++++++++ + 3 files changed, 163 insertions(+), 52 deletions(-) + create mode 100644 src/pesign-rpmbuild-helper + +diff --git a/src/Makefile b/src/Makefile +index 74327ba13f3..af8bef6d9ff 100644 +--- a/src/Makefile ++++ b/src/Makefile +@@ -94,6 +94,7 @@ install : + $(INSTALL) -m 644 macros.pesign $(INSTALLROOT)/etc/rpm/ + $(INSTALL) -d -m 755 $(INSTALLROOT)$(libexecdir)/pesign/ + $(INSTALL) -m 750 pesign-authorize $(INSTALLROOT)$(libexecdir)/pesign/ ++ $(INSTALL) -m 750 pesign-rpmbuild-helper $(INSTALLROOT)$(libexecdir)/pesign/ + $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pesign + $(INSTALL) -m 600 pesign-users $(INSTALLROOT)/etc/pesign/users + $(INSTALL) -m 600 pesign-groups $(INSTALLROOT)/etc/pesign/groups +diff --git a/src/macros.pesign b/src/macros.pesign +index 5a6da1c6809..104586beca5 100644 +--- a/src/macros.pesign ++++ b/src/macros.pesign +@@ -6,7 +6,7 @@ + # %pesign -s -i shim.orig -o shim.efi + # And magically get the right thing. + +-%__pesign_token %{nil}%{?pe_signing_token:-t "%{pe_signing_token}"} ++%__pesign_token %{nil}%{?pe_signing_token:"%{pe_signing_token}"} + %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} + + %__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} +@@ -24,54 +24,21 @@ + # -a # rhel only + # -s # perform signing + %pesign(i:o:C:e:c:n:a:s) \ +- _pesign_nssdir=/etc/pki/pesign \ +- if [ %{__pesign_cert} = "Red Hat Test Certificate" ]; then \ +- _pesign_nssdir=/etc/pki/pesign-rh-test \ +- fi \ +- if [ -x %{_pesign} ] && \\\ +- [ "%{_target_cpu}" == "x86_64" -o \\\ +- "%{_target_cpu}" == "aarch64" ]; then \ +- if [ "0%{?rhel}" -ge "7" -a -f /usr/bin/rpm-sign ]; then \ +- nss=$(mktemp -p $PWD -d) \ +- echo > ${nss}/pwfile \ +- certutil -N -d ${nss} -f ${nss}/pwfile \ +- certutil -A -n "ca" -t "CT,C," -i %{-a*} -d ${nss} \ +- certutil -A -n "signer" -t ",c," -i %{-c*} -d ${nss} \ +- sattrs=$(mktemp -p $PWD --suffix=.der) \ +- %{_pesign} %{-i} -E ${sattrs} --certdir ${nss} --force \ +- rpm-sign --key "%{-n*}" --rsadgstsign ${sattrs} \ +- %{_pesign} -R ${sattrs}.sig -I ${sattrs} %{-i} \\\ +- --certdir ${nss} -c signer %{-o} \ +- rm -rf ${sattrs} ${sattrs}.sig ${nss} \ +- elif [ "$(id -un)" == "kojibuilder" -a \\\ +- grep -q ID=fedora /etc/os-release -a \\\ +- ! -S /run/pesign/socket ]; then \ +- echo "No socket even though this is kojibuilder" 1>&2 \ +- ls -ld /run/pesign 1>&2 \ +- ls -l /run/pesign/socket 1>&2 \ +- getfacl /run/pesign 1>&2 \ +- getfacl /run/pesign/socket 1>&2 \ +- exit 1 \ +- elif [ -S /run/pesign/socket ]; then \ +- %{_pesign_client} -t %{__pesign_client_token} \\\ +- -c %{__pesign_client_cert} \\\ +- %{-i} %{-o} %{-e} %{-s} %{-C} \ +- else \ +- %{_pesign} %{__pesign_token} -c %{__pesign_cert} \\\ +- --certdir ${_pesign_nssdir} \\\ +- %{-i} %{-o} %{-e} %{-s} %{-C} \ +- fi \ +- else \ +- if [ -n "%{-i*}" -a -n "%{-o*}" ]; then \ +- mv %{-i*} %{-o*} \ +- elif [ -n "%{-i*}" -a -n "%{-e*}" ]; then \ +- touch %{-e*} \ +- fi \ +- fi \ +- if [ ! -s %{-o} ]; then \ +- if [ -e "%{-o*}" ]; then \ +- rm -f %{-o*} \ +- fi \ +- exit 1 \ +- fi ; +- ++ %{_libexecdir}/pesign/pesign-rpmbuild-helper \\\ ++ "%{_target_cpu}" \\\ ++ "%{_pesign}" \\\ ++ "%{_pesign_client}" \\\ ++ %{?__pesign_client_token?--client-token "%{__pesign_client_token}"} \\\ ++ %{?__pesign_client_cert?--client-cert "%{__pesign_client_cert}"} \\\ ++ %{?__pesign_token?--token "%{__pesign_token}"} \\\ ++ %{?__pesign_cert?--cert "%{__pesign_cert}"} \\\ ++ %{?_rhel:--rhelver "%{_rhel}"} \\\ ++ %{?-a*:--cafile "%{-a*}"} \\\ ++ %{?-c*:--certfile "%{-c*}"} \\\ ++ %{?-n*:--certname "%{-n*}"} \\\ ++ %{?-C*:--certout "%{-C*}"} \\\ ++ %{?-e*:--sattrout "%{-e*}"} \\\ ++ %{?-i*:--in "%{i*}"} \\\ ++ %{?-o*:--out "%{o*}"} \\\ ++ %{?-s:--sign} \\\ ++%{nil} +diff --git a/src/pesign-rpmbuild-helper b/src/pesign-rpmbuild-helper +new file mode 100644 +index 00000000000..69b430940ec +--- /dev/null ++++ b/src/pesign-rpmbuild-helper +@@ -0,0 +1,143 @@ ++#!/bin/sh ++ ++set -eu ++ ++main() { ++ local target_cpu="${1}" && shift ++ local bin="${1}" && shift ++ local client="${1}" && shift ++ ++ local cafile="" || : ++ local certfile="" || : ++ local certname="" || : ++ ++ local certout=() || : ++ local sattrout=() || : ++ local input=() || : ++ local output=() || : ++ local client_token=() || : ++ local client_cert=() || : ++ local token=() || : ++ local cert=() || : ++ local rhelver=0 || : ++ local sign="" || : ++ ++ while [[ $# -ge 2 ]] ; do ++ case " ${1} " in ++ " --cafile ") ++ cafile="${2}" ++ ;; ++ " --certfile ") ++ certfile="${2}" ++ ;; ++ " --certname ") ++ certname="${2}" ++ ;; ++ " --certout ") ++ certout=(-C "${2}") ++ ;; ++ " --sattrout ") ++ sattrout=(-e "${2}") ++ ;; ++ " --client-token ") ++ client_token=(-t "${2}") ++ ;; ++ " --client-cert ") ++ client_cert=(-c "${2}") ++ ;; ++ " --token ") ++ token=(-t "${2}") ++ ;; ++ " --cert ") ++ cert=(-c "${2}") ++ ;; ++ " --in ") ++ input=(-i "${2}") ++ ;; ++ " --out ") ++ output=(-o "${2}") ++ ;; ++ " --rhelver ") ++ rhelver="${2}" ++ ;; ++ *) ++ break ++ ;; ++ esac ++ shift ++ shift ++ done ++ if [ $# -ge 1 -a "${1}" = --sign ] ; then ++ sign=-s ++ shift ++ fi ++ ++ local nssdir=/etc/pki/pesign ++ if [ "${cert}" == "Red Hat Test Certificate" ] ; then ++ nssdir=/etc/pki/pesign-rh-test ++ fi ++ ++ if [ -x "${bin}" ] && ++ [ "${target_cpu}" != "x86_64" -a "${target_cpu}" != "aarch64" ] ; then ++ if [ -n "${input[*]}" -a -n "${output[*]}" ] ; then ++ mv -v "${input[1]}" "${output[1]}" ++ elif [ -n "${input[*]}" -a -n "${sattrout[*]}" ] ; then ++ touch "${sattrout[1]}" ++ fi ++ ++ # if there's a 0-sized output file, delete it and error out ++ if [ ! -s "${output[1]}" ] ; then ++ if [ -e "${output[1]}" ] ; then ++ rm -f "${output[1]}" ++ fi ++ exit 1 ++ fi ++ return 0 ++ fi ++ ++ if grep -q ID=fedora /etc/os-release && ++ [ "${rhelver}" -lt 7 ] && ++ [ "$(id -un)" = "kojibuilder" -o ++ "$(id -un)" = "mockbuilder" ] && ++ ! [ -S /run/pesign/socket ]; then ++ echo "Warning: no socket even though this is $(id -un)" 1>&2 ++ echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 ++ ls -ld /run/pesign 1>&2 ++ ls -l /run/pesign/socket 1>&2 ++ getfacl /run/pesign /run/pesign/socket 1>&2 ++ fi ++ ++ if [ "${rhelver}" -ge 7 ] ; then ++ nssdir=$(mktemp -p $PWD -d) ++ echo > ${nssdir}/pwfile ++ certutil -N -d ${nssdir} -f ${nssdir}/pwfile ++ certutil -A -n "ca" -t "CTu,CTu,CTu" -i "${cafile}" -d ${nssdir} ++ certutil -A -n "signer" -t "CTu,CTu,CTu" -i "${certfile}" -d ${nssdir} ++ sattrs="$(mktemp -p $PWD --suffix=.der)" ++ "${bin}" -E "${sattrs}" --certdir "${nssdir}" \ ++ ${input[@]} --force ++ rpm-sign --key "${certname}" --rsadgstsign "${sattrs}" ++ "${bin}" -R "${sattrs}.sig" -I "${sattrs}" \ ++ --certdir "${nssdir}" -c signer \ ++ ${input[@]} ${output[@]} ++ rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" ++ elif [ -S /run/pesign/socket ] ; then ++ "${client}" ${client_token[@]} ${client_cert[@]} \ ++ ${sattrout[@]} ${certout[@]} \ ++ ${sign} ${input[@]} ${output[@]} ++ else ++ "${bin}" --certdir "${nssdir}" ${token[@]} ${cert[@]} \ ++ ${sign} ${sattrout[@]} ${certout[@]} \ ++ ${input[@]} ${output[@]} ++ fi ++ ++ # if there's a 0-sized output file, delete it and error out ++ if [ ! -s "${output[1]}" ] ; then ++ if [ -e "${output[1]}" ] ; then ++ rm -f "${output[1]}" ++ fi ++ exit 1 ++ fi ++} ++ ++main "${@}" +-- +2.26.2 + diff --git a/pesign.spec b/pesign.spec index 70704d7..ec9cba2 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 3%{?dist} +Release: 4%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -46,6 +46,7 @@ Patch0002: 0002-pesigcheck-Fix-a-wrong-assignment.patch Patch0003: 0003-Make-0.112-client-and-server-work-with-the-113-proto.patch Patch0004: 0004-Rename-var-run-to-run.patch Patch0005: 0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch +Patch0006: 0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -151,6 +152,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Mon Jul 06 2020 Peter Jones - 113-4 +- Attempt to fix kernel signing failures caused by -3... + * Fri Jun 12 2020 Peter Jones - 113-3 - Fix the signer name for fedora and some other minor nits Related: rhbz#1708773 From 35ff4c5da10c930726682b897596ea5fb2d437e4 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 14:06:04 -0400 Subject: [PATCH 10/70] Fix missing file... Signed-off-by: Peter Jones --- pesign.spec | 1 + 1 file changed, 1 insertion(+) diff --git a/pesign.spec b/pesign.spec index ec9cba2..b882b38 100644 --- a/pesign.spec +++ b/pesign.spec @@ -136,6 +136,7 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %dir %attr(0775,pesign,pesign) %{_sysconfdir}/pki/pesign-rh-test/ %config(noreplace) %attr(0664,pesign,pesign) %{_sysconfdir}/pki/pesign-rh-test/* %{_libexecdir}/pesign/pesign-authorize +%{_libexecdir}/pesign/pesign-rpmbuild-helper %config(noreplace)/%{_sysconfdir}/pesign/users %config(noreplace)/%{_sysconfdir}/pesign/groups %{_sysconfdir}/popt.d/pesign.popt From b61c40cec64b6795fadb25e10726839f4ff58704 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 16:43:27 -0400 Subject: [PATCH 11/70] another test build Signed-off-by: Peter Jones --- ...ros.pesign-to-pesign-rpmbuild-helper.patch | 58 +++++++------ ...-run-and-var-run-for-the-socket-path.patch | 86 +++++++++++++++++++ pesign.spec | 3 +- 3 files changed, 122 insertions(+), 25 deletions(-) create mode 100644 0007-client-try-run-and-var-run-for-the-socket-path.patch diff --git a/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch index 12f9113..2a687b9 100644 --- a/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ b/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch @@ -1,30 +1,30 @@ -From 873345b4970a28c7c590ca0c4e04bf88dd19e3b5 Mon Sep 17 00:00:00 2001 +From 853167a32574ce175c7de2ee730afc1a835191f4 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 13:54:35 -0400 -Subject: [PATCH] Move most of macros.pesign to pesign-rpmbuild-helper +Subject: [PATCH 6/7] Move most of macros.pesign to pesign-rpmbuild-helper Signed-off-by: Peter Jones --- src/Makefile | 1 + - src/macros.pesign | 71 +++++------------- - src/pesign-rpmbuild-helper | 143 +++++++++++++++++++++++++++++++++++++ - 3 files changed, 163 insertions(+), 52 deletions(-) - create mode 100644 src/pesign-rpmbuild-helper + src/macros.pesign | 72 +++++------------- + src/pesign-rpmbuild-helper | 152 +++++++++++++++++++++++++++++++++++++ + 3 files changed, 173 insertions(+), 52 deletions(-) + create mode 100755 src/pesign-rpmbuild-helper diff --git a/src/Makefile b/src/Makefile -index 74327ba13f3..af8bef6d9ff 100644 +index 74327ba13f3..c9e9cc6cd1b 100644 --- a/src/Makefile +++ b/src/Makefile @@ -94,6 +94,7 @@ install : $(INSTALL) -m 644 macros.pesign $(INSTALLROOT)/etc/rpm/ $(INSTALL) -d -m 755 $(INSTALLROOT)$(libexecdir)/pesign/ $(INSTALL) -m 750 pesign-authorize $(INSTALLROOT)$(libexecdir)/pesign/ -+ $(INSTALL) -m 750 pesign-rpmbuild-helper $(INSTALLROOT)$(libexecdir)/pesign/ ++ $(INSTALL) -m 755 pesign-rpmbuild-helper $(INSTALLROOT)$(libexecdir)/pesign/ $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pesign $(INSTALL) -m 600 pesign-users $(INSTALLROOT)/etc/pesign/users $(INSTALL) -m 600 pesign-groups $(INSTALLROOT)/etc/pesign/groups diff --git a/src/macros.pesign b/src/macros.pesign -index 5a6da1c6809..104586beca5 100644 +index 5a6da1c6809..4caf0ba9c8d 100644 --- a/src/macros.pesign +++ b/src/macros.pesign @@ -6,7 +6,7 @@ @@ -36,7 +36,7 @@ index 5a6da1c6809..104586beca5 100644 %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} %__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} -@@ -24,54 +24,21 @@ +@@ -24,54 +24,22 @@ # -a # rhel only # -s # perform signing %pesign(i:o:C:e:c:n:a:s) \ @@ -108,13 +108,14 @@ index 5a6da1c6809..104586beca5 100644 + %{?-i*:--in "%{i*}"} \\\ + %{?-o*:--out "%{o*}"} \\\ + %{?-s:--sign} \\\ ++ ; \ +%{nil} diff --git a/src/pesign-rpmbuild-helper b/src/pesign-rpmbuild-helper -new file mode 100644 -index 00000000000..69b430940ec +new file mode 100755 +index 00000000000..24514aa0b5d --- /dev/null +++ b/src/pesign-rpmbuild-helper -@@ -0,0 +1,143 @@ +@@ -0,0 +1,152 @@ +#!/bin/sh + +set -eu @@ -139,6 +140,8 @@ index 00000000000..69b430940ec + local rhelver=0 || : + local sign="" || : + ++ local username="$(id -un)" ++ + while [[ $# -ge 2 ]] ; do + case " ${1} " in + " --cafile ") @@ -212,16 +215,23 @@ index 00000000000..69b430940ec + return 0 + fi + -+ if grep -q ID=fedora /etc/os-release && -+ [ "${rhelver}" -lt 7 ] && -+ [ "$(id -un)" = "kojibuilder" -o -+ "$(id -un)" = "mockbuilder" ] && -+ ! [ -S /run/pesign/socket ]; then -+ echo "Warning: no socket even though this is $(id -un)" 1>&2 -+ echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 -+ ls -ld /run/pesign 1>&2 -+ ls -l /run/pesign/socket 1>&2 -+ getfacl /run/pesign /run/pesign/socket 1>&2 ++ local socket="" || : ++ if grep -q ID=fedora /etc/os-release && [ "${rhelver}" -lt 7 ] && ++ [ "${username}" = "kojibuilder" -o "${username}" = "mockbuilder" ] ; then ++ if [ -S /run/pesign/socket ] ; then ++ socket=/run/pesign/socket ++ elif [ -S /var/run/pesign/socket ]; then ++ socket=/var/run/pesign/socket ++ else ++ echo "Warning: no pesign socket even though user is ${username}" 1>&2 ++ echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 ++ ls -ld /run/pesign 1>&2 ++ ls -l /run/pesign/socket 1>&2 ++ getfacl /run/pesign /run/pesign/socket 1>&2 ++ ls -ld /var/run/pesign 1>&2 ++ ls -l /var/run/pesign/socket 1>&2 ++ getfacl /var/run/pesign /var/run/pesign/socket 1>&2 ++ fi + fi + + if [ "${rhelver}" -ge 7 ] ; then @@ -238,7 +248,7 @@ index 00000000000..69b430940ec + --certdir "${nssdir}" -c signer \ + ${input[@]} ${output[@]} + rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" -+ elif [ -S /run/pesign/socket ] ; then ++ elif [ -n "${socket}" ] ; then + "${client}" ${client_token[@]} ${client_cert[@]} \ + ${sattrout[@]} ${certout[@]} \ + ${sign} ${input[@]} ${output[@]} diff --git a/0007-client-try-run-and-var-run-for-the-socket-path.patch b/0007-client-try-run-and-var-run-for-the-socket-path.patch new file mode 100644 index 0000000..984805c --- /dev/null +++ b/0007-client-try-run-and-var-run-for-the-socket-path.patch @@ -0,0 +1,86 @@ +From 7ca77cc1d498db72fd6ea6103defaf7d76f4e946 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 6 Jul 2020 16:13:09 -0400 +Subject: [PATCH 7/7] client: try /run and /var/run for the socket path. + +Signed-off-by: Peter Jones +--- + src/client.c | 40 +++++++++++++++++++++++++++++----------- + 1 file changed, 29 insertions(+), 11 deletions(-) + +diff --git a/src/client.c b/src/client.c +index 2119ef33bf8..a38383415d5 100644 +--- a/src/client.c ++++ b/src/client.c +@@ -49,24 +49,24 @@ print_flag_name(FILE *f, int flag) + } + + static int +-connect_to_server(void) ++connect_to_server_helper(const char * const sockpath) + { +- int rc = access(SOCKPATH, R_OK); ++ int rc = access(sockpath, R_OK); + if (rc != 0) { +- fprintf(stderr, "pesign-client: could not connect to server: " +- "%m\n"); +- exit(1); ++ warn("could not access socket \"%s\"", sockpath); ++ return rc; + } + + struct sockaddr_un addr_un = { + .sun_family = AF_UNIX, +- .sun_path = SOCKPATH, + }; ++ strncpy(addr_un.sun_path, sockpath, sizeof(addr_un.sun_path)); ++ addr_un.sun_path[sizeof(addr_un.sun_path)-1] = '\0'; + + int sd = socket(AF_UNIX, SOCK_STREAM, 0); + if (sd < 0) { +- fprintf(stderr, "pesign-client: could not open socket: %m\n"); +- exit(1); ++ warn("could not open socket \"%s\"", sockpath); ++ return sd; + } + + socklen_t len = strlen(addr_un.sun_path) + +@@ -74,14 +74,32 @@ connect_to_server(void) + + rc = connect(sd, (struct sockaddr *)&addr_un, len); + if (rc < 0) { +- fprintf(stderr, "pesign-client: could not connect to daemon: " +- "%m\n"); +- exit(1); ++ warn("could not connect to daemon"); ++ return sd; + } + + return sd; + } + ++static int ++connect_to_server(void) ++{ ++ int rc, i; ++ const char * const sockets[] = { ++ "/run/pesign/socket", ++ "/var/run/pesign/socket", ++ NULL ++ }; ++ ++ for (i = 0; sockets[i] != NULL; i++) { ++ rc = connect_to_server_helper(sockets[i]); ++ if (rc >= 0) ++ return rc; ++ } ++ ++ exit(1); ++} ++ + static int32_t + check_response(int sd, char **srvmsg); + +-- +2.26.2 + diff --git a/pesign.spec b/pesign.spec index b882b38..4f7424e 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 4%{?dist} +Release: 5~1%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -47,6 +47,7 @@ Patch0003: 0003-Make-0.112-client-and-server-work-with-the-113-proto.patch Patch0004: 0004-Rename-var-run-to-run.patch Patch0005: 0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch Patch0006: 0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +Patch0007: 0007-client-try-run-and-var-run-for-the-socket-path.patch %description This package contains the pesign utility for signing UEFI binaries as From a74165d1435d0404fd3d53693c27345c75656a73 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 16:43:27 -0400 Subject: [PATCH 12/70] another test build Signed-off-by: Peter Jones --- ...ove-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch | 5 +++-- pesign.spec | 2 +- 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch index 2a687b9..8ae2207 100644 --- a/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ b/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch @@ -115,7 +115,7 @@ new file mode 100755 index 00000000000..24514aa0b5d --- /dev/null +++ b/src/pesign-rpmbuild-helper -@@ -0,0 +1,152 @@ +@@ -0,0 +1,153 @@ +#!/bin/sh + +set -eu @@ -193,7 +193,8 @@ index 00000000000..24514aa0b5d + fi + + local nssdir=/etc/pki/pesign -+ if [ "${cert}" == "Red Hat Test Certificate" ] ; then ++ if [ "${certname}" == "Red Hat Test Certificate" ] || ++ [ "${#cert[@]}" -eq 2 -a "${cert[1]}" == "Red Hat Test Certificate" ] ; then + nssdir=/etc/pki/pesign-rh-test + fi + diff --git a/pesign.spec b/pesign.spec index 4f7424e..9847ffe 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 5~1%{?dist} +Release: 5~2%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign From 15d1a5085dd9bfd7024455d7935512400f01b17d Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 16:43:27 -0400 Subject: [PATCH 13/70] another test build Signed-off-by: Peter Jones --- ...ros.pesign-to-pesign-rpmbuild-helper.patch | 45 +++---- ...-run-and-var-run-for-the-socket-path.patch | 119 +++++++++++++++++- pesign.spec | 2 +- 3 files changed, 138 insertions(+), 28 deletions(-) diff --git a/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch index 8ae2207..d948caa 100644 --- a/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ b/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch @@ -1,4 +1,4 @@ -From 853167a32574ce175c7de2ee730afc1a835191f4 Mon Sep 17 00:00:00 2001 +From 8499f7b340e4f6fbb5701db21fbabc25b8883c54 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 13:54:35 -0400 Subject: [PATCH 6/7] Move most of macros.pesign to pesign-rpmbuild-helper @@ -6,9 +6,9 @@ Subject: [PATCH 6/7] Move most of macros.pesign to pesign-rpmbuild-helper Signed-off-by: Peter Jones --- src/Makefile | 1 + - src/macros.pesign | 72 +++++------------- - src/pesign-rpmbuild-helper | 152 +++++++++++++++++++++++++++++++++++++ - 3 files changed, 173 insertions(+), 52 deletions(-) + src/macros.pesign | 73 +++++------------- + src/pesign-rpmbuild-helper | 153 +++++++++++++++++++++++++++++++++++++ + 3 files changed, 174 insertions(+), 53 deletions(-) create mode 100755 src/pesign-rpmbuild-helper diff --git a/src/Makefile b/src/Makefile @@ -24,19 +24,23 @@ index 74327ba13f3..c9e9cc6cd1b 100644 $(INSTALL) -m 600 pesign-users $(INSTALLROOT)/etc/pesign/users $(INSTALL) -m 600 pesign-groups $(INSTALLROOT)/etc/pesign/groups diff --git a/src/macros.pesign b/src/macros.pesign -index 5a6da1c6809..4caf0ba9c8d 100644 +index 5a6da1c6809..e3a0de9c2f4 100644 --- a/src/macros.pesign +++ b/src/macros.pesign -@@ -6,7 +6,7 @@ +@@ -6,10 +6,10 @@ # %pesign -s -i shim.orig -o shim.efi # And magically get the right thing. -%__pesign_token %{nil}%{?pe_signing_token:-t "%{pe_signing_token}"} -+%__pesign_token %{nil}%{?pe_signing_token:"%{pe_signing_token}"} ++%__pesign_token %{nil}%{?pe_signing_token:--token "%{pe_signing_token}"} %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} - %__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} -@@ -24,54 +24,22 @@ +-%__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} ++%__pesign_client_token --token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} + %__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} + + %_pesign /usr/bin/pesign +@@ -24,54 +24,21 @@ # -a # rhel only # -s # perform signing %pesign(i:o:C:e:c:n:a:s) \ @@ -95,24 +99,23 @@ index 5a6da1c6809..4caf0ba9c8d 100644 + "%{_target_cpu}" \\\ + "%{_pesign}" \\\ + "%{_pesign_client}" \\\ -+ %{?__pesign_client_token?--client-token "%{__pesign_client_token}"} \\\ -+ %{?__pesign_client_cert?--client-cert "%{__pesign_client_cert}"} \\\ -+ %{?__pesign_token?--token "%{__pesign_token}"} \\\ -+ %{?__pesign_cert?--cert "%{__pesign_cert}"} \\\ ++ %{?__pesign_client_token:--client-token %{__pesign_client_token}} \\\ ++ %{?__pesign_client_cert:--client-cert %{__pesign_client_cert}} \\\ ++ %{?__pesign_token:%{__pesign_token}} \\\ ++ %{?-n:--cert "%{-n*}"}%{?!-n:--cert "%{__pesign_cert}"} \\\ + %{?_rhel:--rhelver "%{_rhel}"} \\\ -+ %{?-a*:--cafile "%{-a*}"} \\\ -+ %{?-c*:--certfile "%{-c*}"} \\\ -+ %{?-n*:--certname "%{-n*}"} \\\ -+ %{?-C*:--certout "%{-C*}"} \\\ -+ %{?-e*:--sattrout "%{-e*}"} \\\ -+ %{?-i*:--in "%{i*}"} \\\ -+ %{?-o*:--out "%{o*}"} \\\ ++ %{?-a:--cafile "%{-a*}"} \\\ ++ %{?-c:--certfile "%{-c*}"} \\\ ++ %{?-C:--certout "%{-C*}"} \\\ ++ %{?-e:--sattrout "%{-e*}"} \\\ ++ %{?-i:--in "%{-i*}"} \\\ ++ %{?-o:--out "%{-o*}"} \\\ + %{?-s:--sign} \\\ + ; \ +%{nil} diff --git a/src/pesign-rpmbuild-helper b/src/pesign-rpmbuild-helper new file mode 100755 -index 00000000000..24514aa0b5d +index 00000000000..fd385d1625d --- /dev/null +++ b/src/pesign-rpmbuild-helper @@ -0,0 +1,153 @@ diff --git a/0007-client-try-run-and-var-run-for-the-socket-path.patch b/0007-client-try-run-and-var-run-for-the-socket-path.patch index 984805c..e9e89e5 100644 --- a/0007-client-try-run-and-var-run-for-the-socket-path.patch +++ b/0007-client-try-run-and-var-run-for-the-socket-path.patch @@ -1,18 +1,19 @@ -From 7ca77cc1d498db72fd6ea6103defaf7d76f4e946 Mon Sep 17 00:00:00 2001 +From c98b16d890a1e4651b3683853acb69fedd5a10dd Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 16:13:09 -0400 Subject: [PATCH 7/7] client: try /run and /var/run for the socket path. Signed-off-by: Peter Jones --- - src/client.c | 40 +++++++++++++++++++++++++++++----------- - 1 file changed, 29 insertions(+), 11 deletions(-) + src/client.c | 40 ++++++++++++++++++++-------- + src/pesign-rpmbuild-helper | 54 ++++++++++++++++++++++---------------- + 2 files changed, 61 insertions(+), 33 deletions(-) diff --git a/src/client.c b/src/client.c -index 2119ef33bf8..a38383415d5 100644 +index a4f1d1dbbe7..0082be1f597 100644 --- a/src/client.c +++ b/src/client.c -@@ -49,24 +49,24 @@ print_flag_name(FILE *f, int flag) +@@ -61,24 +61,24 @@ print_flag_name(FILE *f, int flag) } static int @@ -45,7 +46,7 @@ index 2119ef33bf8..a38383415d5 100644 } socklen_t len = strlen(addr_un.sun_path) + -@@ -74,14 +74,32 @@ connect_to_server(void) +@@ -86,14 +86,32 @@ connect_to_server(void) rc = connect(sd, (struct sockaddr *)&addr_un, len); if (rc < 0) { @@ -81,6 +82,112 @@ index 2119ef33bf8..a38383415d5 100644 static int32_t check_response(int sd, char **srvmsg); +diff --git a/src/pesign-rpmbuild-helper b/src/pesign-rpmbuild-helper +index fd385d1625d..68b53ddf022 100755 +--- a/src/pesign-rpmbuild-helper ++++ b/src/pesign-rpmbuild-helper +@@ -1,6 +1,7 @@ + #!/bin/sh + + set -eu ++set -x + + main() { + local target_cpu="${1}" && shift +@@ -32,32 +33,41 @@ main() { + " --certfile ") + certfile="${2}" + ;; +- " --certname ") +- certname="${2}" +- ;; + " --certout ") +- certout=(-C "${2}") ++ certout[0]=-C ++ certout[1]="${2}" + ;; + " --sattrout ") +- sattrout=(-e "${2}") ++ sattrout[0]=-e ++ sattrout[1]="${2}" + ;; + " --client-token ") +- client_token=(-t "${2}") ++ client_token[0]=-t ++ client_token[1]="${2}" + ;; + " --client-cert ") +- client_cert=(-c "${2}") ++ client_cert[0]=-c ++ client_cert[1]="${2}" + ;; + " --token ") +- token=(-t "${2}") ++ token[0]=-t ++ token="${2}" + ;; + " --cert ") +- cert=(-c "${2}") ++ cert[0]=-c ++ cert[1]="${2}" ++ ;; ++ " --certname ") ++ cert[0]=-c ++ cert[1]="${2}" + ;; + " --in ") +- input=(-i "${2}") ++ input[0]=-i ++ input[1]="${2}" + ;; + " --out ") +- output=(-o "${2}") ++ output[0]=-o ++ output[1]="${2}" + ;; + " --rhelver ") + rhelver="${2}" +@@ -75,8 +85,8 @@ main() { + fi + + local nssdir=/etc/pki/pesign +- if [ "${certname}" == "Red Hat Test Certificate" ] || +- [ "${#cert[@]}" -eq 2 -a "${cert[1]}" == "Red Hat Test Certificate" ] ; then ++ if [ "${#cert[@]}" -eq 2 ] && ++ [ "${cert[1]}" == "Red Hat Test Certificate" ] ; then + nssdir=/etc/pki/pesign-rh-test + fi + +@@ -125,20 +135,20 @@ main() { + certutil -A -n "signer" -t "CTu,CTu,CTu" -i "${certfile}" -d ${nssdir} + sattrs="$(mktemp -p $PWD --suffix=.der)" + "${bin}" -E "${sattrs}" --certdir "${nssdir}" \ +- ${input[@]} --force +- rpm-sign --key "${certname}" --rsadgstsign "${sattrs}" ++ "${input[@]}" --force ++ rpm-sign --key "${cert[1]}" --rsadgstsign "${sattrs}" + "${bin}" -R "${sattrs}.sig" -I "${sattrs}" \ + --certdir "${nssdir}" -c signer \ +- ${input[@]} ${output[@]} ++ "${input[@]}" "${output[@]}" + rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" + elif [ -n "${socket}" ] ; then +- "${client}" ${client_token[@]} ${client_cert[@]} \ +- ${sattrout[@]} ${certout[@]} \ +- ${sign} ${input[@]} ${output[@]} ++ "${client}" "${client_token[@]}" "${client_cert[@]}" \ ++ "${sattrout[@]}" "${certout[@]}" \ ++ ${sign} "${input[@]}" "${output[@]}" + else +- "${bin}" --certdir "${nssdir}" ${token[@]} ${cert[@]} \ +- ${sign} ${sattrout[@]} ${certout[@]} \ +- ${input[@]} ${output[@]} ++ "${bin}" --certdir "${nssdir}" "${token[@]}" \ ++ "${cert[@]}" ${sign} "${sattrout[@]}" \ ++ "${certout[@]}" "${input[@]}" "${output[@]}" + fi + + # if there's a 0-sized output file, delete it and error out -- 2.26.2 diff --git a/pesign.spec b/pesign.spec index 9847ffe..40bff5d 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 5~2%{?dist} +Release: 5~3%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign From 38e8425bf80f012c095921af7fc344c4a6dc930f Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 16:43:27 -0400 Subject: [PATCH 14/70] another test build Signed-off-by: Peter Jones --- ...-run-and-var-run-for-the-socket-path.patch | 86 ++++++++ ...ros.pesign-to-pesign-rpmbuild-helper.patch | 77 ++++--- ...-run-and-var-run-for-the-socket-path.patch | 193 ------------------ pesign.spec | 6 +- 4 files changed, 132 insertions(+), 230 deletions(-) create mode 100644 0006-client-try-run-and-var-run-for-the-socket-path.patch rename 0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch => 0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch (84%) delete mode 100644 0007-client-try-run-and-var-run-for-the-socket-path.patch diff --git a/0006-client-try-run-and-var-run-for-the-socket-path.patch b/0006-client-try-run-and-var-run-for-the-socket-path.patch new file mode 100644 index 0000000..337faab --- /dev/null +++ b/0006-client-try-run-and-var-run-for-the-socket-path.patch @@ -0,0 +1,86 @@ +From c662ad097eaa0d8c3691a22254f5d0e9622b26b7 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 6 Jul 2020 16:13:09 -0400 +Subject: [PATCH 6/7] client: try /run and /var/run for the socket path. + +Signed-off-by: Peter Jones +--- + src/client.c | 40 +++++++++++++++++++++++++++++----------- + 1 file changed, 29 insertions(+), 11 deletions(-) + +diff --git a/src/client.c b/src/client.c +index 2119ef33bf8..a38383415d5 100644 +--- a/src/client.c ++++ b/src/client.c +@@ -49,24 +49,24 @@ print_flag_name(FILE *f, int flag) + } + + static int +-connect_to_server(void) ++connect_to_server_helper(const char * const sockpath) + { +- int rc = access(SOCKPATH, R_OK); ++ int rc = access(sockpath, R_OK); + if (rc != 0) { +- fprintf(stderr, "pesign-client: could not connect to server: " +- "%m\n"); +- exit(1); ++ warn("could not access socket \"%s\"", sockpath); ++ return rc; + } + + struct sockaddr_un addr_un = { + .sun_family = AF_UNIX, +- .sun_path = SOCKPATH, + }; ++ strncpy(addr_un.sun_path, sockpath, sizeof(addr_un.sun_path)); ++ addr_un.sun_path[sizeof(addr_un.sun_path)-1] = '\0'; + + int sd = socket(AF_UNIX, SOCK_STREAM, 0); + if (sd < 0) { +- fprintf(stderr, "pesign-client: could not open socket: %m\n"); +- exit(1); ++ warn("could not open socket \"%s\"", sockpath); ++ return sd; + } + + socklen_t len = strlen(addr_un.sun_path) + +@@ -74,14 +74,32 @@ connect_to_server(void) + + rc = connect(sd, (struct sockaddr *)&addr_un, len); + if (rc < 0) { +- fprintf(stderr, "pesign-client: could not connect to daemon: " +- "%m\n"); +- exit(1); ++ warn("could not connect to daemon"); ++ return sd; + } + + return sd; + } + ++static int ++connect_to_server(void) ++{ ++ int rc, i; ++ const char * const sockets[] = { ++ "/run/pesign/socket", ++ "/var/run/pesign/socket", ++ NULL ++ }; ++ ++ for (i = 0; sockets[i] != NULL; i++) { ++ rc = connect_to_server_helper(sockets[i]); ++ if (rc >= 0) ++ return rc; ++ } ++ ++ exit(1); ++} ++ + static int32_t + check_response(int sd, char **srvmsg); + +-- +2.26.2 + diff --git a/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch similarity index 84% rename from 0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch rename to 0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch index d948caa..020d468 100644 --- a/0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ b/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch @@ -1,15 +1,15 @@ -From 8499f7b340e4f6fbb5701db21fbabc25b8883c54 Mon Sep 17 00:00:00 2001 +From 22658f290fcf66213ca6237e37ae97bba39a8a0b Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 13:54:35 -0400 -Subject: [PATCH 6/7] Move most of macros.pesign to pesign-rpmbuild-helper +Subject: [PATCH] Move most of macros.pesign to pesign-rpmbuild-helper Signed-off-by: Peter Jones --- src/Makefile | 1 + - src/macros.pesign | 73 +++++------------- - src/pesign-rpmbuild-helper | 153 +++++++++++++++++++++++++++++++++++++ - 3 files changed, 174 insertions(+), 53 deletions(-) - create mode 100755 src/pesign-rpmbuild-helper + src/macros.pesign | 73 +++++------------ + src/pesign-rpmbuild-helper | 163 +++++++++++++++++++++++++++++++++++++ + 3 files changed, 184 insertions(+), 53 deletions(-) + create mode 100644 src/pesign-rpmbuild-helper diff --git a/src/Makefile b/src/Makefile index 74327ba13f3..c9e9cc6cd1b 100644 @@ -102,7 +102,7 @@ index 5a6da1c6809..e3a0de9c2f4 100644 + %{?__pesign_client_token:--client-token %{__pesign_client_token}} \\\ + %{?__pesign_client_cert:--client-cert %{__pesign_client_cert}} \\\ + %{?__pesign_token:%{__pesign_token}} \\\ -+ %{?-n:--cert "%{-n*}"}%{?!-n:--cert "%{__pesign_cert}"} \\\ ++ %{?-n:--cert "\"%{-n*}\""}%{?!-n:--cert "\"%{__pesign_cert}\""} \\\ + %{?_rhel:--rhelver "%{_rhel}"} \\\ + %{?-a:--cafile "%{-a*}"} \\\ + %{?-c:--certfile "%{-c*}"} \\\ @@ -114,14 +114,15 @@ index 5a6da1c6809..e3a0de9c2f4 100644 + ; \ +%{nil} diff --git a/src/pesign-rpmbuild-helper b/src/pesign-rpmbuild-helper -new file mode 100755 -index 00000000000..fd385d1625d +new file mode 100644 +index 00000000000..f3d66320bcc --- /dev/null +++ b/src/pesign-rpmbuild-helper -@@ -0,0 +1,153 @@ +@@ -0,0 +1,162 @@ +#!/bin/sh + +set -eu ++set -x + +main() { + local target_cpu="${1}" && shift @@ -130,7 +131,6 @@ index 00000000000..fd385d1625d + + local cafile="" || : + local certfile="" || : -+ local certname="" || : + + local certout=() || : + local sattrout=() || : @@ -153,32 +153,41 @@ index 00000000000..fd385d1625d + " --certfile ") + certfile="${2}" + ;; -+ " --certname ") -+ certname="${2}" -+ ;; + " --certout ") -+ certout=(-C "${2}") ++ certout[0]=-C ++ certout[1]="${2}" + ;; + " --sattrout ") -+ sattrout=(-e "${2}") ++ sattrout[0]=-e ++ sattrout[1]="${2}" + ;; + " --client-token ") -+ client_token=(-t "${2}") ++ client_token[0]=-t ++ client_token[1]="${2}" + ;; + " --client-cert ") -+ client_cert=(-c "${2}") ++ client_cert[0]=-c ++ client_cert[1]="${2}" + ;; + " --token ") -+ token=(-t "${2}") ++ token[0]=-t ++ token="${2}" + ;; + " --cert ") -+ cert=(-c "${2}") ++ cert[0]=-c ++ cert[1]="${2}" ++ ;; ++ " --certname ") ++ cert[0]=-c ++ cert[1]="${2}" + ;; + " --in ") -+ input=(-i "${2}") ++ input[0]=-i ++ input[1]="${2}" + ;; + " --out ") -+ output=(-o "${2}") ++ output[0]=-o ++ output[1]="${2}" + ;; + " --rhelver ") + rhelver="${2}" @@ -196,8 +205,8 @@ index 00000000000..fd385d1625d + fi + + local nssdir=/etc/pki/pesign -+ if [ "${certname}" == "Red Hat Test Certificate" ] || -+ [ "${#cert[@]}" -eq 2 -a "${cert[1]}" == "Red Hat Test Certificate" ] ; then ++ if [ "${#cert[@]}" -eq 2 ] && ++ [ "${cert[1]}" == "Red Hat Test Certificate" ] ; then + nssdir=/etc/pki/pesign-rh-test + fi + @@ -246,24 +255,24 @@ index 00000000000..fd385d1625d + certutil -A -n "signer" -t "CTu,CTu,CTu" -i "${certfile}" -d ${nssdir} + sattrs="$(mktemp -p $PWD --suffix=.der)" + "${bin}" -E "${sattrs}" --certdir "${nssdir}" \ -+ ${input[@]} --force -+ rpm-sign --key "${certname}" --rsadgstsign "${sattrs}" ++ "${input[@]}" --force ++ rpm-sign --key "${cert[1]}" --rsadgstsign "${sattrs}" + "${bin}" -R "${sattrs}.sig" -I "${sattrs}" \ + --certdir "${nssdir}" -c signer \ -+ ${input[@]} ${output[@]} ++ "${input[@]}" "${output[@]}" + rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" + elif [ -n "${socket}" ] ; then -+ "${client}" ${client_token[@]} ${client_cert[@]} \ -+ ${sattrout[@]} ${certout[@]} \ -+ ${sign} ${input[@]} ${output[@]} ++ "${client}" "${client_token[@]}" "${client_cert[@]}" \ ++ "${sattrout[@]}" "${certout[@]}" \ ++ ${sign} "${input[@]}" "${output[@]}" + else -+ "${bin}" --certdir "${nssdir}" ${token[@]} ${cert[@]} \ -+ ${sign} ${sattrout[@]} ${certout[@]} \ -+ ${input[@]} ${output[@]} ++ "${bin}" --certdir "${nssdir}" "${token[@]}" \ ++ "${cert[@]}" ${sign} "${sattrout[@]}" \ ++ "${certout[@]}" "${input[@]}" "${output[@]}" + fi + + # if there's a 0-sized output file, delete it and error out -+ if [ ! -s "${output[1]}" ] ; then ++ if [ "${#output[@]}" -eq 2 ] && ! [ -s "${output[1]}" ] ; then + if [ -e "${output[1]}" ] ; then + rm -f "${output[1]}" + fi diff --git a/0007-client-try-run-and-var-run-for-the-socket-path.patch b/0007-client-try-run-and-var-run-for-the-socket-path.patch deleted file mode 100644 index e9e89e5..0000000 --- a/0007-client-try-run-and-var-run-for-the-socket-path.patch +++ /dev/null @@ -1,193 +0,0 @@ -From c98b16d890a1e4651b3683853acb69fedd5a10dd Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 6 Jul 2020 16:13:09 -0400 -Subject: [PATCH 7/7] client: try /run and /var/run for the socket path. - -Signed-off-by: Peter Jones ---- - src/client.c | 40 ++++++++++++++++++++-------- - src/pesign-rpmbuild-helper | 54 ++++++++++++++++++++++---------------- - 2 files changed, 61 insertions(+), 33 deletions(-) - -diff --git a/src/client.c b/src/client.c -index a4f1d1dbbe7..0082be1f597 100644 ---- a/src/client.c -+++ b/src/client.c -@@ -61,24 +61,24 @@ print_flag_name(FILE *f, int flag) - } - - static int --connect_to_server(void) -+connect_to_server_helper(const char * const sockpath) - { -- int rc = access(SOCKPATH, R_OK); -+ int rc = access(sockpath, R_OK); - if (rc != 0) { -- fprintf(stderr, "pesign-client: could not connect to server: " -- "%m\n"); -- exit(1); -+ warn("could not access socket \"%s\"", sockpath); -+ return rc; - } - - struct sockaddr_un addr_un = { - .sun_family = AF_UNIX, -- .sun_path = SOCKPATH, - }; -+ strncpy(addr_un.sun_path, sockpath, sizeof(addr_un.sun_path)); -+ addr_un.sun_path[sizeof(addr_un.sun_path)-1] = '\0'; - - int sd = socket(AF_UNIX, SOCK_STREAM, 0); - if (sd < 0) { -- fprintf(stderr, "pesign-client: could not open socket: %m\n"); -- exit(1); -+ warn("could not open socket \"%s\"", sockpath); -+ return sd; - } - - socklen_t len = strlen(addr_un.sun_path) + -@@ -86,14 +86,32 @@ connect_to_server(void) - - rc = connect(sd, (struct sockaddr *)&addr_un, len); - if (rc < 0) { -- fprintf(stderr, "pesign-client: could not connect to daemon: " -- "%m\n"); -- exit(1); -+ warn("could not connect to daemon"); -+ return sd; - } - - return sd; - } - -+static int -+connect_to_server(void) -+{ -+ int rc, i; -+ const char * const sockets[] = { -+ "/run/pesign/socket", -+ "/var/run/pesign/socket", -+ NULL -+ }; -+ -+ for (i = 0; sockets[i] != NULL; i++) { -+ rc = connect_to_server_helper(sockets[i]); -+ if (rc >= 0) -+ return rc; -+ } -+ -+ exit(1); -+} -+ - static int32_t - check_response(int sd, char **srvmsg); - -diff --git a/src/pesign-rpmbuild-helper b/src/pesign-rpmbuild-helper -index fd385d1625d..68b53ddf022 100755 ---- a/src/pesign-rpmbuild-helper -+++ b/src/pesign-rpmbuild-helper -@@ -1,6 +1,7 @@ - #!/bin/sh - - set -eu -+set -x - - main() { - local target_cpu="${1}" && shift -@@ -32,32 +33,41 @@ main() { - " --certfile ") - certfile="${2}" - ;; -- " --certname ") -- certname="${2}" -- ;; - " --certout ") -- certout=(-C "${2}") -+ certout[0]=-C -+ certout[1]="${2}" - ;; - " --sattrout ") -- sattrout=(-e "${2}") -+ sattrout[0]=-e -+ sattrout[1]="${2}" - ;; - " --client-token ") -- client_token=(-t "${2}") -+ client_token[0]=-t -+ client_token[1]="${2}" - ;; - " --client-cert ") -- client_cert=(-c "${2}") -+ client_cert[0]=-c -+ client_cert[1]="${2}" - ;; - " --token ") -- token=(-t "${2}") -+ token[0]=-t -+ token="${2}" - ;; - " --cert ") -- cert=(-c "${2}") -+ cert[0]=-c -+ cert[1]="${2}" -+ ;; -+ " --certname ") -+ cert[0]=-c -+ cert[1]="${2}" - ;; - " --in ") -- input=(-i "${2}") -+ input[0]=-i -+ input[1]="${2}" - ;; - " --out ") -- output=(-o "${2}") -+ output[0]=-o -+ output[1]="${2}" - ;; - " --rhelver ") - rhelver="${2}" -@@ -75,8 +85,8 @@ main() { - fi - - local nssdir=/etc/pki/pesign -- if [ "${certname}" == "Red Hat Test Certificate" ] || -- [ "${#cert[@]}" -eq 2 -a "${cert[1]}" == "Red Hat Test Certificate" ] ; then -+ if [ "${#cert[@]}" -eq 2 ] && -+ [ "${cert[1]}" == "Red Hat Test Certificate" ] ; then - nssdir=/etc/pki/pesign-rh-test - fi - -@@ -125,20 +135,20 @@ main() { - certutil -A -n "signer" -t "CTu,CTu,CTu" -i "${certfile}" -d ${nssdir} - sattrs="$(mktemp -p $PWD --suffix=.der)" - "${bin}" -E "${sattrs}" --certdir "${nssdir}" \ -- ${input[@]} --force -- rpm-sign --key "${certname}" --rsadgstsign "${sattrs}" -+ "${input[@]}" --force -+ rpm-sign --key "${cert[1]}" --rsadgstsign "${sattrs}" - "${bin}" -R "${sattrs}.sig" -I "${sattrs}" \ - --certdir "${nssdir}" -c signer \ -- ${input[@]} ${output[@]} -+ "${input[@]}" "${output[@]}" - rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" - elif [ -n "${socket}" ] ; then -- "${client}" ${client_token[@]} ${client_cert[@]} \ -- ${sattrout[@]} ${certout[@]} \ -- ${sign} ${input[@]} ${output[@]} -+ "${client}" "${client_token[@]}" "${client_cert[@]}" \ -+ "${sattrout[@]}" "${certout[@]}" \ -+ ${sign} "${input[@]}" "${output[@]}" - else -- "${bin}" --certdir "${nssdir}" ${token[@]} ${cert[@]} \ -- ${sign} ${sattrout[@]} ${certout[@]} \ -- ${input[@]} ${output[@]} -+ "${bin}" --certdir "${nssdir}" "${token[@]}" \ -+ "${cert[@]}" ${sign} "${sattrout[@]}" \ -+ "${certout[@]}" "${input[@]}" "${output[@]}" - fi - - # if there's a 0-sized output file, delete it and error out --- -2.26.2 - diff --git a/pesign.spec b/pesign.spec index 40bff5d..fa2ac3c 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 5~3%{?dist} +Release: 5~5%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -46,8 +46,8 @@ Patch0002: 0002-pesigcheck-Fix-a-wrong-assignment.patch Patch0003: 0003-Make-0.112-client-and-server-work-with-the-113-proto.patch Patch0004: 0004-Rename-var-run-to-run.patch Patch0005: 0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch -Patch0006: 0006-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch -Patch0007: 0007-client-try-run-and-var-run-for-the-socket-path.patch +Patch0006: 0006-client-try-run-and-var-run-for-the-socket-path.patch +Patch0007: 0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch %description This package contains the pesign utility for signing UEFI binaries as From e29d99c4d1f493b00d7c670487bc01260e543c78 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 16:43:27 -0400 Subject: [PATCH 15/70] another test build Signed-off-by: Peter Jones --- 0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch | 2 +- pesign.spec | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch index 020d468..c4156a2 100644 --- a/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ b/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch @@ -230,7 +230,7 @@ index 00000000000..f3d66320bcc + + local socket="" || : + if grep -q ID=fedora /etc/os-release && [ "${rhelver}" -lt 7 ] && -+ [ "${username}" = "kojibuilder" -o "${username}" = "mockbuilder" ] ; then ++ [ "${username}" = "kojibuilder" -o "${username}" = "mockbuild" ] ; then + if [ -S /run/pesign/socket ] ; then + socket=/run/pesign/socket + elif [ -S /var/run/pesign/socket ]; then diff --git a/pesign.spec b/pesign.spec index fa2ac3c..eb84640 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 5~5%{?dist} +Release: 5~6%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign From 392ac74b011a3845807f530df31d3bee2ae1938b Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 16:43:27 -0400 Subject: [PATCH 16/70] another test build Signed-off-by: Peter Jones --- ...macros.pesign-to-pesign-rpmbuild-helper.patch | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch index c4156a2..15ccc09 100644 --- a/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ b/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch @@ -118,7 +118,7 @@ new file mode 100644 index 00000000000..f3d66320bcc --- /dev/null +++ b/src/pesign-rpmbuild-helper -@@ -0,0 +1,162 @@ +@@ -0,0 +1,164 @@ +#!/bin/sh + +set -eu @@ -238,12 +238,14 @@ index 00000000000..f3d66320bcc + else + echo "Warning: no pesign socket even though user is ${username}" 1>&2 + echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 -+ ls -ld /run/pesign 1>&2 -+ ls -l /run/pesign/socket 1>&2 -+ getfacl /run/pesign /run/pesign/socket 1>&2 -+ ls -ld /var/run/pesign 1>&2 -+ ls -l /var/run/pesign/socket 1>&2 -+ getfacl /var/run/pesign /var/run/pesign/socket 1>&2 ++ ls -ld /run/pesign 1>&2 ||: ++ ls -l /run/pesign/socket 1>&2 ||: ++ getfacl /run/pesign 1>&2 || : ++ getfacl /run/pesign/socket 1>&2 ||: ++ ls -ld /var/run/pesign 1>&2 ||: ++ ls -l /var/run/pesign/socket 1>&2 ||: ++ getfacl /var/run/pesign 1>&2 || : ++ getfacl /var/run/pesign/socket 1>&2 || : + fi + fi + From 50819c8ebf7364b0287e67e1fec9dfd0487be8c1 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 16:43:27 -0400 Subject: [PATCH 17/70] another test build Signed-off-by: Peter Jones --- pesign.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index eb84640..84b1dad 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 5~6%{?dist} +Release: 5~7%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign From bad9f464438daac7a1983ff0cb5d83102b67bdae Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 7 Jul 2020 12:59:52 -0400 Subject: [PATCH 18/70] Make pesign require nss-tools for the posttrans scriptlet Signed-off-by: Peter Jones --- pesign.spec | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pesign.spec b/pesign.spec index 84b1dad..60e05b7 100644 --- a/pesign.spec +++ b/pesign.spec @@ -28,6 +28,7 @@ BuildRequires: systemd-rpm-macros %endif Requires: nspr Requires: nss +Requires: nss-tools Requires: nss-util Requires: popt Requires: rpm @@ -154,6 +155,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Jul 07 2020 Peter Jones +- Make pesign require nss-tools for the posttrans scriptlet + * Mon Jul 06 2020 Peter Jones - 113-4 - Attempt to fix kernel signing failures caused by -3... From 6a576773ff11a00fe5f066b835aa9fc4a714424f Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 7 Jul 2020 13:05:37 -0400 Subject: [PATCH 19/70] Make pesign require nss-tools for the posttrans scriptlet Move most of macros.pesign to /usr/libexec/pesign/pesign-rpmbuild-helper Signed-off-by: Peter Jones --- pesign.spec | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pesign.spec b/pesign.spec index 60e05b7..5c948c8 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 5~7%{?dist} +Release: 5%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -28,7 +28,7 @@ BuildRequires: systemd-rpm-macros %endif Requires: nspr Requires: nss -Requires: nss-tools +Requires: nss-tools >= 3.53 Requires: nss-util Requires: popt Requires: rpm @@ -155,8 +155,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog -* Tue Jul 07 2020 Peter Jones +* Tue Jul 07 2020 Peter Jones - 113-5 - Make pesign require nss-tools for the posttrans scriptlet +- Move most of macros.pesign to /usr/libexec/pesign/pesign-rpmbuild-helper * Mon Jul 06 2020 Peter Jones - 113-4 - Attempt to fix kernel signing failures caused by -3... From 9dfdddd33a312f5488607adae76fe74007d5a8b3 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 7 Jul 2020 13:36:52 -0400 Subject: [PATCH 20/70] Disable the pesign-authorize call in posttrans, until we can figure out a better way to deal with that in the fedora kernel builder chroot setup Signed-off-by: Peter Jones --- pesign.spec | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/pesign.spec b/pesign.spec index 5c948c8..82923b5 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 5%{?dist} +Release: 7%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -119,7 +119,13 @@ exit 0 %posttrans certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null -%{_libexecdir}/pesign/pesign-authorize + +# this is disabled currently because it breaks the fedora kernel build root +# generation - because we don't currently have a good way of populating +# /etc/pesign/{users,groups} before the buildroot is installed, or +# populating them and re-running pesign-authorize afterwards but before the +# package build of e.g. kernel +#%%{_libexecdir}/pesign/pesign-authorize %endif %files @@ -155,6 +161,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Jul 07 2020 Peter Jones - 113-6 +- Disable the pesign-authorize call in posttrans, until we can figure out a + better way to deal with that in the fedora kernel builder chroot setup + * Tue Jul 07 2020 Peter Jones - 113-5 - Make pesign require nss-tools for the posttrans scriptlet - Move most of macros.pesign to /usr/libexec/pesign/pesign-rpmbuild-helper From 1702b23026963782097875ec6359d0799e88137a Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 7 Jul 2020 14:36:34 -0400 Subject: [PATCH 21/70] More kernel build debugging... Signed-off-by: Peter Jones --- ...ove-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch | 3 +-- pesign.spec | 5 ++++- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch index 15ccc09..660962f 100644 --- a/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ b/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch @@ -35,8 +35,7 @@ index 5a6da1c6809..e3a0de9c2f4 100644 +%__pesign_token %{nil}%{?pe_signing_token:--token "%{pe_signing_token}"} %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} --%__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} -+%__pesign_client_token --token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} + %__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} %__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} %_pesign /usr/bin/pesign diff --git a/pesign.spec b/pesign.spec index 82923b5..31d1e87 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 7%{?dist} +Release: 8~1%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -161,6 +161,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Jul 07 2020 Peter Jones - 113-8 +- More kernel build debugging... + * Tue Jul 07 2020 Peter Jones - 113-6 - Disable the pesign-authorize call in posttrans, until we can figure out a better way to deal with that in the fedora kernel builder chroot setup From 658f5fea05c8e65424599928a40533e565f0101a Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 7 Jul 2020 15:24:12 -0400 Subject: [PATCH 22/70] More kernel build debugging... Signed-off-by: Peter Jones --- 0008-remove-debug-print.patch | 25 +++++++++++++++++++++++++ pesign.spec | 3 ++- 2 files changed, 27 insertions(+), 1 deletion(-) create mode 100644 0008-remove-debug-print.patch diff --git a/0008-remove-debug-print.patch b/0008-remove-debug-print.patch new file mode 100644 index 0000000..996f92a --- /dev/null +++ b/0008-remove-debug-print.patch @@ -0,0 +1,25 @@ +From 722d60568a1aba99a39918c187b7331e2c368b29 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Tue, 7 Jul 2020 15:23:36 -0400 +Subject: [PATCH] remove debug print + +Signed-off-by: Peter Jones +--- + src/client.c | 1 - + 1 file changed, 1 deletion(-) + +diff --git a/src/client.c b/src/client.c +index 0082be1f597..c9966295e5f 100644 +--- a/src/client.c ++++ b/src/client.c +@@ -536,7 +536,6 @@ oom: + 0, true); + } + +- printf("add_file_type:%d\n", add_file_type); + pm->version = PESIGND_VERSION; + pm->command = attached ? (add_file_type ? CMD_SIGN_ATTACHED_WITH_FILE_TYPE + : CMD_SIGN_ATTACHED) +-- +2.26.2 + diff --git a/pesign.spec b/pesign.spec index 31d1e87..7086dce 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 8~1%{?dist} +Release: 8%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -49,6 +49,7 @@ Patch0004: 0004-Rename-var-run-to-run.patch Patch0005: 0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch Patch0006: 0006-client-try-run-and-var-run-for-the-socket-path.patch Patch0007: 0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +Patch0008: 0008-remove-debug-print.patch %description This package contains the pesign utility for signing UEFI binaries as From 2335e6390fa7ff09b1d3dee491bc74f8c95c4903 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 7 Jul 2020 15:24:12 -0400 Subject: [PATCH 23/70] More kernel build debugging... Signed-off-by: Peter Jones --- ...ros.pesign-to-pesign-rpmbuild-helper.patch | 287 -------------- ...7-client-remove-an-extra-debug-print.patch | 6 +- ...ros.pesign-to-pesign-rpmbuild-helper.patch | 375 ++++++++++++++++++ 0009-pesign-authorize-shellcheck.patch | 60 +++ ...ize-don-t-setfacl-etc-pki-pesign-foo.patch | 26 ++ 0011-kernel-building-hack.patch | 40 ++ pesign.spec | 12 +- 7 files changed, 513 insertions(+), 293 deletions(-) delete mode 100644 0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch rename 0008-remove-debug-print.patch => 0007-client-remove-an-extra-debug-print.patch (76%) create mode 100644 0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch create mode 100644 0009-pesign-authorize-shellcheck.patch create mode 100644 0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch create mode 100644 0011-kernel-building-hack.patch diff --git a/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch deleted file mode 100644 index 660962f..0000000 --- a/0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ /dev/null @@ -1,287 +0,0 @@ -From 22658f290fcf66213ca6237e37ae97bba39a8a0b Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 6 Jul 2020 13:54:35 -0400 -Subject: [PATCH] Move most of macros.pesign to pesign-rpmbuild-helper - -Signed-off-by: Peter Jones ---- - src/Makefile | 1 + - src/macros.pesign | 73 +++++------------ - src/pesign-rpmbuild-helper | 163 +++++++++++++++++++++++++++++++++++++ - 3 files changed, 184 insertions(+), 53 deletions(-) - create mode 100644 src/pesign-rpmbuild-helper - -diff --git a/src/Makefile b/src/Makefile -index 74327ba13f3..c9e9cc6cd1b 100644 ---- a/src/Makefile -+++ b/src/Makefile -@@ -94,6 +94,7 @@ install : - $(INSTALL) -m 644 macros.pesign $(INSTALLROOT)/etc/rpm/ - $(INSTALL) -d -m 755 $(INSTALLROOT)$(libexecdir)/pesign/ - $(INSTALL) -m 750 pesign-authorize $(INSTALLROOT)$(libexecdir)/pesign/ -+ $(INSTALL) -m 755 pesign-rpmbuild-helper $(INSTALLROOT)$(libexecdir)/pesign/ - $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pesign - $(INSTALL) -m 600 pesign-users $(INSTALLROOT)/etc/pesign/users - $(INSTALL) -m 600 pesign-groups $(INSTALLROOT)/etc/pesign/groups -diff --git a/src/macros.pesign b/src/macros.pesign -index 5a6da1c6809..e3a0de9c2f4 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -6,10 +6,10 @@ - # %pesign -s -i shim.orig -o shim.efi - # And magically get the right thing. - --%__pesign_token %{nil}%{?pe_signing_token:-t "%{pe_signing_token}"} -+%__pesign_token %{nil}%{?pe_signing_token:--token "%{pe_signing_token}"} - %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} - - %__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} - %__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} - - %_pesign /usr/bin/pesign -@@ -24,54 +24,21 @@ - # -a # rhel only - # -s # perform signing - %pesign(i:o:C:e:c:n:a:s) \ -- _pesign_nssdir=/etc/pki/pesign \ -- if [ %{__pesign_cert} = "Red Hat Test Certificate" ]; then \ -- _pesign_nssdir=/etc/pki/pesign-rh-test \ -- fi \ -- if [ -x %{_pesign} ] && \\\ -- [ "%{_target_cpu}" == "x86_64" -o \\\ -- "%{_target_cpu}" == "aarch64" ]; then \ -- if [ "0%{?rhel}" -ge "7" -a -f /usr/bin/rpm-sign ]; then \ -- nss=$(mktemp -p $PWD -d) \ -- echo > ${nss}/pwfile \ -- certutil -N -d ${nss} -f ${nss}/pwfile \ -- certutil -A -n "ca" -t "CT,C," -i %{-a*} -d ${nss} \ -- certutil -A -n "signer" -t ",c," -i %{-c*} -d ${nss} \ -- sattrs=$(mktemp -p $PWD --suffix=.der) \ -- %{_pesign} %{-i} -E ${sattrs} --certdir ${nss} --force \ -- rpm-sign --key "%{-n*}" --rsadgstsign ${sattrs} \ -- %{_pesign} -R ${sattrs}.sig -I ${sattrs} %{-i} \\\ -- --certdir ${nss} -c signer %{-o} \ -- rm -rf ${sattrs} ${sattrs}.sig ${nss} \ -- elif [ "$(id -un)" == "kojibuilder" -a \\\ -- grep -q ID=fedora /etc/os-release -a \\\ -- ! -S /run/pesign/socket ]; then \ -- echo "No socket even though this is kojibuilder" 1>&2 \ -- ls -ld /run/pesign 1>&2 \ -- ls -l /run/pesign/socket 1>&2 \ -- getfacl /run/pesign 1>&2 \ -- getfacl /run/pesign/socket 1>&2 \ -- exit 1 \ -- elif [ -S /run/pesign/socket ]; then \ -- %{_pesign_client} -t %{__pesign_client_token} \\\ -- -c %{__pesign_client_cert} \\\ -- %{-i} %{-o} %{-e} %{-s} %{-C} \ -- else \ -- %{_pesign} %{__pesign_token} -c %{__pesign_cert} \\\ -- --certdir ${_pesign_nssdir} \\\ -- %{-i} %{-o} %{-e} %{-s} %{-C} \ -- fi \ -- else \ -- if [ -n "%{-i*}" -a -n "%{-o*}" ]; then \ -- mv %{-i*} %{-o*} \ -- elif [ -n "%{-i*}" -a -n "%{-e*}" ]; then \ -- touch %{-e*} \ -- fi \ -- fi \ -- if [ ! -s %{-o} ]; then \ -- if [ -e "%{-o*}" ]; then \ -- rm -f %{-o*} \ -- fi \ -- exit 1 \ -- fi ; -- -+ %{_libexecdir}/pesign/pesign-rpmbuild-helper \\\ -+ "%{_target_cpu}" \\\ -+ "%{_pesign}" \\\ -+ "%{_pesign_client}" \\\ -+ %{?__pesign_client_token:--client-token %{__pesign_client_token}} \\\ -+ %{?__pesign_client_cert:--client-cert %{__pesign_client_cert}} \\\ -+ %{?__pesign_token:%{__pesign_token}} \\\ -+ %{?-n:--cert "\"%{-n*}\""}%{?!-n:--cert "\"%{__pesign_cert}\""} \\\ -+ %{?_rhel:--rhelver "%{_rhel}"} \\\ -+ %{?-a:--cafile "%{-a*}"} \\\ -+ %{?-c:--certfile "%{-c*}"} \\\ -+ %{?-C:--certout "%{-C*}"} \\\ -+ %{?-e:--sattrout "%{-e*}"} \\\ -+ %{?-i:--in "%{-i*}"} \\\ -+ %{?-o:--out "%{-o*}"} \\\ -+ %{?-s:--sign} \\\ -+ ; \ -+%{nil} -diff --git a/src/pesign-rpmbuild-helper b/src/pesign-rpmbuild-helper -new file mode 100644 -index 00000000000..f3d66320bcc ---- /dev/null -+++ b/src/pesign-rpmbuild-helper -@@ -0,0 +1,164 @@ -+#!/bin/sh -+ -+set -eu -+set -x -+ -+main() { -+ local target_cpu="${1}" && shift -+ local bin="${1}" && shift -+ local client="${1}" && shift -+ -+ local cafile="" || : -+ local certfile="" || : -+ -+ local certout=() || : -+ local sattrout=() || : -+ local input=() || : -+ local output=() || : -+ local client_token=() || : -+ local client_cert=() || : -+ local token=() || : -+ local cert=() || : -+ local rhelver=0 || : -+ local sign="" || : -+ -+ local username="$(id -un)" -+ -+ while [[ $# -ge 2 ]] ; do -+ case " ${1} " in -+ " --cafile ") -+ cafile="${2}" -+ ;; -+ " --certfile ") -+ certfile="${2}" -+ ;; -+ " --certout ") -+ certout[0]=-C -+ certout[1]="${2}" -+ ;; -+ " --sattrout ") -+ sattrout[0]=-e -+ sattrout[1]="${2}" -+ ;; -+ " --client-token ") -+ client_token[0]=-t -+ client_token[1]="${2}" -+ ;; -+ " --client-cert ") -+ client_cert[0]=-c -+ client_cert[1]="${2}" -+ ;; -+ " --token ") -+ token[0]=-t -+ token="${2}" -+ ;; -+ " --cert ") -+ cert[0]=-c -+ cert[1]="${2}" -+ ;; -+ " --certname ") -+ cert[0]=-c -+ cert[1]="${2}" -+ ;; -+ " --in ") -+ input[0]=-i -+ input[1]="${2}" -+ ;; -+ " --out ") -+ output[0]=-o -+ output[1]="${2}" -+ ;; -+ " --rhelver ") -+ rhelver="${2}" -+ ;; -+ *) -+ break -+ ;; -+ esac -+ shift -+ shift -+ done -+ if [ $# -ge 1 -a "${1}" = --sign ] ; then -+ sign=-s -+ shift -+ fi -+ -+ local nssdir=/etc/pki/pesign -+ if [ "${#cert[@]}" -eq 2 ] && -+ [ "${cert[1]}" == "Red Hat Test Certificate" ] ; then -+ nssdir=/etc/pki/pesign-rh-test -+ fi -+ -+ if [ -x "${bin}" ] && -+ [ "${target_cpu}" != "x86_64" -a "${target_cpu}" != "aarch64" ] ; then -+ if [ -n "${input[*]}" -a -n "${output[*]}" ] ; then -+ mv -v "${input[1]}" "${output[1]}" -+ elif [ -n "${input[*]}" -a -n "${sattrout[*]}" ] ; then -+ touch "${sattrout[1]}" -+ fi -+ -+ # if there's a 0-sized output file, delete it and error out -+ if [ ! -s "${output[1]}" ] ; then -+ if [ -e "${output[1]}" ] ; then -+ rm -f "${output[1]}" -+ fi -+ exit 1 -+ fi -+ return 0 -+ fi -+ -+ local socket="" || : -+ if grep -q ID=fedora /etc/os-release && [ "${rhelver}" -lt 7 ] && -+ [ "${username}" = "kojibuilder" -o "${username}" = "mockbuild" ] ; then -+ if [ -S /run/pesign/socket ] ; then -+ socket=/run/pesign/socket -+ elif [ -S /var/run/pesign/socket ]; then -+ socket=/var/run/pesign/socket -+ else -+ echo "Warning: no pesign socket even though user is ${username}" 1>&2 -+ echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 -+ ls -ld /run/pesign 1>&2 ||: -+ ls -l /run/pesign/socket 1>&2 ||: -+ getfacl /run/pesign 1>&2 || : -+ getfacl /run/pesign/socket 1>&2 ||: -+ ls -ld /var/run/pesign 1>&2 ||: -+ ls -l /var/run/pesign/socket 1>&2 ||: -+ getfacl /var/run/pesign 1>&2 || : -+ getfacl /var/run/pesign/socket 1>&2 || : -+ fi -+ fi -+ -+ if [ "${rhelver}" -ge 7 ] ; then -+ nssdir=$(mktemp -p $PWD -d) -+ echo > ${nssdir}/pwfile -+ certutil -N -d ${nssdir} -f ${nssdir}/pwfile -+ certutil -A -n "ca" -t "CTu,CTu,CTu" -i "${cafile}" -d ${nssdir} -+ certutil -A -n "signer" -t "CTu,CTu,CTu" -i "${certfile}" -d ${nssdir} -+ sattrs="$(mktemp -p $PWD --suffix=.der)" -+ "${bin}" -E "${sattrs}" --certdir "${nssdir}" \ -+ "${input[@]}" --force -+ rpm-sign --key "${cert[1]}" --rsadgstsign "${sattrs}" -+ "${bin}" -R "${sattrs}.sig" -I "${sattrs}" \ -+ --certdir "${nssdir}" -c signer \ -+ "${input[@]}" "${output[@]}" -+ rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" -+ elif [ -n "${socket}" ] ; then -+ "${client}" "${client_token[@]}" "${client_cert[@]}" \ -+ "${sattrout[@]}" "${certout[@]}" \ -+ ${sign} "${input[@]}" "${output[@]}" -+ else -+ "${bin}" --certdir "${nssdir}" "${token[@]}" \ -+ "${cert[@]}" ${sign} "${sattrout[@]}" \ -+ "${certout[@]}" "${input[@]}" "${output[@]}" -+ fi -+ -+ # if there's a 0-sized output file, delete it and error out -+ if [ "${#output[@]}" -eq 2 ] && ! [ -s "${output[1]}" ] ; then -+ if [ -e "${output[1]}" ] ; then -+ rm -f "${output[1]}" -+ fi -+ exit 1 -+ fi -+} -+ -+main "${@}" --- -2.26.2 - diff --git a/0008-remove-debug-print.patch b/0007-client-remove-an-extra-debug-print.patch similarity index 76% rename from 0008-remove-debug-print.patch rename to 0007-client-remove-an-extra-debug-print.patch index 996f92a..b094ea5 100644 --- a/0008-remove-debug-print.patch +++ b/0007-client-remove-an-extra-debug-print.patch @@ -1,7 +1,7 @@ -From 722d60568a1aba99a39918c187b7331e2c368b29 Mon Sep 17 00:00:00 2001 +From ea81cec14d31cd0b0dbde5b42414bfae9daec9b8 Mon Sep 17 00:00:00 2001 From: Peter Jones -Date: Tue, 7 Jul 2020 15:23:36 -0400 -Subject: [PATCH] remove debug print +Date: Tue, 14 Jul 2020 16:44:09 -0400 +Subject: [PATCH 07/11] client: remove an extra debug print Signed-off-by: Peter Jones --- diff --git a/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch new file mode 100644 index 0000000..4b782ed --- /dev/null +++ b/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch @@ -0,0 +1,375 @@ +From 25981d57c4d56c53128d561bbe29593a6a20b259 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 6 Jul 2020 13:54:35 -0400 +Subject: [PATCH 08/11] Move most of macros.pesign to pesign-rpmbuild-helper + +Signed-off-by: Peter Jones +--- + Make.defaults | 1 + + src/Makefile | 8 +- + src/macros.pesign | 73 ++++-------- + src/pesign-rpmbuild-helper.in | 216 ++++++++++++++++++++++++++++++++++ + 4 files changed, 245 insertions(+), 53 deletions(-) + create mode 100644 src/pesign-rpmbuild-helper.in + +diff --git a/Make.defaults b/Make.defaults +index 0bacafe0d01..302da50efb5 100644 +--- a/Make.defaults ++++ b/Make.defaults +@@ -16,6 +16,7 @@ INSTALLROOT = $(DESTDIR) + + INSTALL ?= install + CROSS_COMPILE ?= ++EFI_ARCHES ?= aa64 ia32 x64 + + PKG_CONFIG = $(CROSS_COMPILE)pkg-config + CC := $(if $(filter default,$(origin CC)),$(CROSS_COMPILE)gcc,$(CC)) +diff --git a/src/Makefile b/src/Makefile +index 74327ba13f3..a7ca89159c6 100644 +--- a/src/Makefile ++++ b/src/Makefile +@@ -5,7 +5,7 @@ include $(TOPDIR)/Make.version + include $(TOPDIR)/Make.rules + include $(TOPDIR)/Make.defaults + +-BINTARGETS=authvar client efikeygen efisiglist pesigcheck pesign ++BINTARGETS=authvar client efikeygen efisiglist pesigcheck pesign pesign-rpmbuild-helper + SVCTARGETS=pesign.sysvinit pesign.service + TARGETS=$(BINTARGETS) $(SVCTARGETS) + +@@ -49,6 +49,11 @@ pesign : $(call objects-of,$(PESIGN_SOURCES) $(COMMON_SOURCES) $(COMMON_PE_SOURC + pesign : LDLIBS+=$(TOPDIR)/libdpe/libdpe.a + pesign : PKGS=efivar nss nspr popt + ++pesign-rpmbuild-helper: pesign-rpmbuild-helper.in ++ sed \ ++ -e "s/@@EFI_ARCHES@@/$(EFI_ARCHES)/g" \ ++ $^ > $@ ++ + deps : PKGS=efivar nss nspr popt uuid + deps : $(ALL_SOURCES) + $(MAKE) -f $(TOPDIR)/Make.deps \ +@@ -94,6 +99,7 @@ install : + $(INSTALL) -m 644 macros.pesign $(INSTALLROOT)/etc/rpm/ + $(INSTALL) -d -m 755 $(INSTALLROOT)$(libexecdir)/pesign/ + $(INSTALL) -m 750 pesign-authorize $(INSTALLROOT)$(libexecdir)/pesign/ ++ $(INSTALL) -m 755 pesign-rpmbuild-helper $(INSTALLROOT)$(libexecdir)/pesign/ + $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pesign + $(INSTALL) -m 600 pesign-users $(INSTALLROOT)/etc/pesign/users + $(INSTALL) -m 600 pesign-groups $(INSTALLROOT)/etc/pesign/groups +diff --git a/src/macros.pesign b/src/macros.pesign +index 5a6da1c6809..730d3bc449c 100644 +--- a/src/macros.pesign ++++ b/src/macros.pesign +@@ -6,7 +6,7 @@ + # %pesign -s -i shim.orig -o shim.efi + # And magically get the right thing. + +-%__pesign_token %{nil}%{?pe_signing_token:-t "%{pe_signing_token}"} ++%__pesign_token %{nil}%{?pe_signing_token:--token "%{pe_signing_token}"} + %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} + + %__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} +@@ -24,54 +24,23 @@ + # -a # rhel only + # -s # perform signing + %pesign(i:o:C:e:c:n:a:s) \ +- _pesign_nssdir=/etc/pki/pesign \ +- if [ %{__pesign_cert} = "Red Hat Test Certificate" ]; then \ +- _pesign_nssdir=/etc/pki/pesign-rh-test \ +- fi \ +- if [ -x %{_pesign} ] && \\\ +- [ "%{_target_cpu}" == "x86_64" -o \\\ +- "%{_target_cpu}" == "aarch64" ]; then \ +- if [ "0%{?rhel}" -ge "7" -a -f /usr/bin/rpm-sign ]; then \ +- nss=$(mktemp -p $PWD -d) \ +- echo > ${nss}/pwfile \ +- certutil -N -d ${nss} -f ${nss}/pwfile \ +- certutil -A -n "ca" -t "CT,C," -i %{-a*} -d ${nss} \ +- certutil -A -n "signer" -t ",c," -i %{-c*} -d ${nss} \ +- sattrs=$(mktemp -p $PWD --suffix=.der) \ +- %{_pesign} %{-i} -E ${sattrs} --certdir ${nss} --force \ +- rpm-sign --key "%{-n*}" --rsadgstsign ${sattrs} \ +- %{_pesign} -R ${sattrs}.sig -I ${sattrs} %{-i} \\\ +- --certdir ${nss} -c signer %{-o} \ +- rm -rf ${sattrs} ${sattrs}.sig ${nss} \ +- elif [ "$(id -un)" == "kojibuilder" -a \\\ +- grep -q ID=fedora /etc/os-release -a \\\ +- ! -S /run/pesign/socket ]; then \ +- echo "No socket even though this is kojibuilder" 1>&2 \ +- ls -ld /run/pesign 1>&2 \ +- ls -l /run/pesign/socket 1>&2 \ +- getfacl /run/pesign 1>&2 \ +- getfacl /run/pesign/socket 1>&2 \ +- exit 1 \ +- elif [ -S /run/pesign/socket ]; then \ +- %{_pesign_client} -t %{__pesign_client_token} \\\ +- -c %{__pesign_client_cert} \\\ +- %{-i} %{-o} %{-e} %{-s} %{-C} \ +- else \ +- %{_pesign} %{__pesign_token} -c %{__pesign_cert} \\\ +- --certdir ${_pesign_nssdir} \\\ +- %{-i} %{-o} %{-e} %{-s} %{-C} \ +- fi \ +- else \ +- if [ -n "%{-i*}" -a -n "%{-o*}" ]; then \ +- mv %{-i*} %{-o*} \ +- elif [ -n "%{-i*}" -a -n "%{-e*}" ]; then \ +- touch %{-e*} \ +- fi \ +- fi \ +- if [ ! -s %{-o} ]; then \ +- if [ -e "%{-o*}" ]; then \ +- rm -f %{-o*} \ +- fi \ +- exit 1 \ +- fi ; +- ++ %{_libexecdir}/pesign/pesign-rpmbuild-helper \\\ ++ "%{_target_cpu}" \\\ ++ "%{_pesign}" \\\ ++ "%{_pesign_client}" \\\ ++ %{?__pesign_client_token:--client-token %{__pesign_client_token}} \\\ ++ %{?__pesign_client_cert:--client-cert %{__pesign_client_cert}} \\\ ++ %{?__pesign_token:%{__pesign_token}} \\\ ++ %{?__pesign_cert:--cert %{__pesign_cert}} \\\ ++ %{?vendor:--vendor %{vendor}} \\\ ++ %{?_rhel:--rhelver "%{_rhel}"} \\\ ++ %{?-n:--rhelcert "%{-n*}"}%{?!-n:--rhelcert "%{__pesign_cert}"} \\\ ++ %{?-a:--rhelcafile "%{-a*}"} \\\ ++ %{?-c:--rhelcertfile "%{-c*}"} \\\ ++ %{?-C:--certout "%{-C*}"} \\\ ++ %{?-e:--sattrout "%{-e*}"} \\\ ++ %{?-i:--in "%{-i*}"} \\\ ++ %{?-o:--out "%{-o*}"} \\\ ++ %{?-s:--sign} \\\ ++ ; \ ++%{nil} +diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in +new file mode 100644 +index 00000000000..cb53550121f +--- /dev/null ++++ b/src/pesign-rpmbuild-helper.in +@@ -0,0 +1,219 @@ ++#!/bin/bash ++# shellcheck shell=bash ++ ++set -eu ++set -x ++ ++usage() { ++ local status="${1}" && shift ++ local out ++ if [[ "${status}" -eq 0 ]] ; then ++ out=/dev/stdout ++ else ++ out=/dev/stderr ++ fi ++ ++ if [[ $# -gt 0 ]] ; then ++ echo "${0}: error: $*" >>"${out}" ++ fi ++ echo "usage: ${0} TARGET_CPU PESIGN_BINARY PESIGN_CLIENT_BINARY [OPTIONS]" >>"${out}" ++ exit "${status}" ++} ++ ++is_efi_arch() { ++ local arch="${1}" ++ local arches=(@@EFI_ARCHES@@) ++ local x ++ for x in "${arches[@]}" ; do ++ if [[ "${arch}" = "${x}" ]] ; then ++ return 0 ++ fi ++ done ++ return 1 ++} ++ ++error_on_empty() { ++ local f="${1}" ++ if [[ ! -s "${f}" ]] ; then ++ if [[ -e "${f}" ]] ; then ++ rm -f "${f}" ++ fi ++ echo "${0}: error: empty result file \"${f}\"">>/dev/stderr ++ exit 1 ++ fi ++} ++ ++main() { ++ if [[ $# -lt 3 ]] ; then ++ usage 1 not enough arguments ++ fi ++ local target_cpu="${1}" && shift ++ local bin="${1}" && shift ++ local client="${1}" && shift ++ ++ local rhelcafile="" || : ++ local rhelcertfile="" || : ++ ++ local certout=() || : ++ local sattrout=() || : ++ local input=() || : ++ local output=() || : ++ local client_token=() || : ++ local client_cert=() || : ++ local token=() || : ++ local cert=() || : ++ local rhelcert=() || : ++ local rhelver=0 || : ++ local sign="" || : ++ local arch="" || : ++ local vendor="" || : ++ ++ while [[ $# -ge 2 ]] ; do ++ case " ${1} " in ++ " --rhelcafile ") ++ rhelcafile="${2}" ++ ;; ++ " --rhelcertfile ") ++ rhelcertfile="${2}" ++ ;; ++ " --certout ") ++ certout[0]=-C ++ certout[1]="${2}" ++ ;; ++ " --sattrout ") ++ sattrout[0]=-e ++ sattrout[1]="${2}" ++ ;; ++ " --client-token ") ++ client_token[0]=-t ++ client_token[1]="${2}" ++ ;; ++ " --client-cert ") ++ client_cert[0]=-c ++ client_cert[1]="${2}" ++ ;; ++ " --token ") ++ token[0]=-t ++ token[1]="${2}" ++ ;; ++ " --cert ") ++ cert[0]=-c ++ cert[1]="${2}" ++ ;; ++ " --rhelcert ") ++ rhelcert[0]=-c ++ rhelcert[1]="${2}" ++ ;; ++ " --in ") ++ input[0]=-i ++ input[1]="${2}" ++ ;; ++ " --out ") ++ output[0]=-o ++ output[1]="${2}" ++ ;; ++ " --rhelver ") ++ rhelver="${2}" ++ ;; ++ " --vendor ") ++ vendor="${2}" ++ ;; ++ *) ++ break ++ ;; ++ esac ++ shift ++ shift ++ done ++ if [[ $# -ge 1 ]] && [[ "${1}" = --sign ]] ; then ++ sign=-s ++ shift ++ fi ++ ++ if [[ -z "${target_cpu}" ]] ; then ++ target_cpu="$(uname -m)" ++ fi ++ ++ target_cpu="${target_cpu/i?86/ia32}" ++ target_cpu="${target_cpu/x86_64/x64}" ++ target_cpu="${target_cpu/aarch64/aa64}" ++ target_cpu="${target_cpu/arm*/arm/}" ++ ++ local nssdir=/etc/pki/pesign ++ if [[ "${#cert[@]}" -eq 2 ]] && ++ [[ "${cert[1]}" == "Red Hat Test Certificate" ]] ; then ++ nssdir=/etc/pki/pesign-rh-test ++ fi ++ ++ # is_efi_arch is ultimately returning "is pesign configured to sign these ++ # using the rpm macro", so if it isn't, we're just copying the input to ++ # the output ++ if [[ -x "${bin}" ]] && ! is_efi_arch "${target_cpu}" ; then ++ if [[ -n "${input[*]}" ]] && [[ -n "${output[*]}" ]] ; then ++ cp -v "${input[1]}" "${output[1]}" ++ elif [[ -n "${input[*]}" ]] && [[ -n "${sattrout[*]}" ]] ; then ++ touch "${sattrout[1]}" ++ fi ++ ++ # if there's a 0-sized output file, delete it and error out ++ error_on_empty "${output[1]}" ++ return 0 ++ fi ++ ++ USERNAME="${USERNAME:-$(id -un)}" ++ HOSTNAME="${HOSTNAME:-$(hostname)}" ++ ++ local socket="" || : ++ if grep -q ID=fedora /etc/os-release \ ++ && [[ "${rhelver}" -lt 7 ]] \ ++ && [[ "${USERNAME}" = "mockbuild" ]] \ ++ && [[ "${vendor}" == "Fedora Project" ]] \ ++ && [[ "${HOSTNAME}" =~ bkernel.* ]] ++ then ++ if [[ -S /run/pesign/socket ]] ; then ++ socket=/run/pesign/socket ++ elif [[ -S /var/run/pesign/socket ]]; then ++ socket=/var/run/pesign/socket ++ else ++ echo "Warning: no pesign socket even though user is ${USERNAME}" 1>&2 ++ echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 ++ ls -ld /run/pesign /var/run/pesign 1>&2 ||: ++ ls -l /run/pesign/socket /var/run/pesign/socket 1>&2 ||: ++ getfacl /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: ++ getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: ++ fi ++ fi ++ ++ if [[ "${rhelver}" -ge 7 ]] ; then ++ nssdir="$(mktemp -p "${PWD}" -d)" ++ echo > "${nssdir}/pwfile" ++ certutil -N -d "${nssdir}" -f "${nssdir}/pwfile" ++ certutil -A -n "ca" -t "CTu,CTu,CTu" -i "${rhelcafile}" -d "${nssdir}" ++ certutil -A -n "signer" -t "CTu,CTu,CTu" -i "${rhelcertfile}" -d "${nssdir}" ++ sattrs="$(mktemp -p "${PWD}" --suffix=.der)" ++ "${bin}" -E "${sattrs}" --certdir "${nssdir}" \ ++ "${input[@]}" --force ++ rpm-sign --key "${rhelcert[1]}" --rsadgstsign "${sattrs}" ++ "${bin}" -R "${sattrs}.sig" -I "${sattrs}" \ ++ --certdir "${nssdir}" -c signer \ ++ "${input[@]}" "${output[@]}" ++ rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" ++ elif [[ -n "${socket}" ]] ; then ++ "${client}" "${client_token[@]}" "${client_cert[@]}" \ ++ "${sattrout[@]}" "${certout[@]}" \ ++ ${sign} "${input[@]}" "${output[@]}" ++ else ++ "${bin}" --certdir "${nssdir}" "${token[@]}" \ ++ "${cert[@]}" ${sign} "${sattrout[@]}" \ ++ "${certout[@]}" "${input[@]}" "${output[@]}" ++ fi ++ ++ # if there's a 0-sized output file, delete it and error out ++ if [[ "${#output[@]}" -eq 2 ]] ; then ++ error_on_empty "${output[1]}" ++ fi ++} ++ ++main "${@}" ++ ++# vim:filetype=sh:fenc=utf-8:tw=78:sts=4:sw=4 +-- +2.26.2 + diff --git a/0009-pesign-authorize-shellcheck.patch b/0009-pesign-authorize-shellcheck.patch new file mode 100644 index 0000000..8a8f7c9 --- /dev/null +++ b/0009-pesign-authorize-shellcheck.patch @@ -0,0 +1,60 @@ +From 91d45fea14dfce71f79534b0df276cf8175c0565 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Tue, 14 Jul 2020 15:07:32 -0400 +Subject: [PATCH 09/11] pesign-authorize: shellcheck + +Signed-off-by: Peter Jones +--- + src/pesign-authorize | 16 ++++++++-------- + 1 file changed, 8 insertions(+), 8 deletions(-) + +diff --git a/src/pesign-authorize b/src/pesign-authorize +index a496f601ab4..55cd5c4e55b 100755 +--- a/src/pesign-authorize ++++ b/src/pesign-authorize +@@ -12,21 +12,21 @@ set -u + # License: GPLv2 + declare -a fileusers=() + declare -a dirusers=() +-for user in $(cat /etc/pesign/users); do ++while read -r user ; do + dirusers[${#dirusers[@]}]=-m + dirusers[${#dirusers[@]}]="u:$user:rwx" + fileusers[${#fileusers[@]}]=-m + fileusers[${#fileusers[@]}]="u:$user:rw" +-done ++done +Date: Tue, 14 Jul 2020 15:08:15 -0400 +Subject: [PATCH 10/11] pesign-authorize: don't setfacl /etc/pki/pesign-foo/ + +Signed-off-by: Peter Jones +--- + src/pesign-authorize | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/pesign-authorize b/src/pesign-authorize +index 55cd5c4e55b..c5448329c2c 100755 +--- a/src/pesign-authorize ++++ b/src/pesign-authorize +@@ -47,7 +47,7 @@ update_subdir() { + done + } + +-for x in /var/run/pesign/ /etc/pki/pesign*/ ; do ++for x in /var/run/pesign/ /etc/pki/pesign/ ; do + if [ -d "${x}" ]; then + update_subdir "${x}" + else +-- +2.26.2 + diff --git a/0011-kernel-building-hack.patch b/0011-kernel-building-hack.patch new file mode 100644 index 0000000..532b098 --- /dev/null +++ b/0011-kernel-building-hack.patch @@ -0,0 +1,40 @@ +From 43d1c74b391485178da1d38722da0f28ece8b336 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Tue, 14 Jul 2020 16:42:39 -0400 +Subject: [PATCH 11/11] kernel building hack + +Signed-off-by: Peter Jones +--- + src/pesign-rpmbuild-helper.in | 16 ++++++++++++++++ + 1 file changed, 16 insertions(+) + +diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in +index d9236035928..2666c74a9ba 100644 +--- a/src/pesign-rpmbuild-helper.in ++++ b/src/pesign-rpmbuild-helper.in +@@ -195,6 +195,22 @@ main() { + "${input[@]}" "${output[@]}" + rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" + elif [[ -n "${socket}" ]] ; then ++ ### welcome haaaaack city ++ if [[ "${client_token[1]}" = "/CN=Fedora Secure Boot Signer" ]] ; then ++ if [[ "${input[1]}" =~ (/|^)vmlinuz($|[_.-]) ]] \ ++ || [[ "${input[1]}" =~ (/|^)bzImage($|[_.-]) ]] ; then ++ if [[ "${rhelcertfile}" =~ redhatsecureboot501.* ]] \ ++ || [[ "${rhelcertfile}" =~ centossecureboot201.* ]] ; then ++ client_token[1]=kernel-signer ++ elif [[ "${rhelcertfile}" =~ redhatsecureboot502.* ]] \ ++ || [[ "${rhelcertfile}" =~ centossecureboot202.* ]] ; then ++ client_token[1]=grub2-signer ++ elif [[ "${rhelcertfile}" =~ redhatsecureboot503.* ]] \ ++ || [[ "${rhelcertfile}" =~ centossecureboot203.* ]] ; then ++ client_token[1]=fwupd-signer ++ fi ++ fi ++ fi + "${client}" "${client_token[@]}" "${client_cert[@]}" \ + "${sattrout[@]}" "${certout[@]}" \ + ${sign} "${input[@]}" "${output[@]}" +-- +2.26.2 + diff --git a/pesign.spec b/pesign.spec index 7086dce..d2f310c 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 8%{?dist} +Release: 9%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -48,8 +48,11 @@ Patch0003: 0003-Make-0.112-client-and-server-work-with-the-113-proto.patch Patch0004: 0004-Rename-var-run-to-run.patch Patch0005: 0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch Patch0006: 0006-client-try-run-and-var-run-for-the-socket-path.patch -Patch0007: 0007-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch -Patch0008: 0008-remove-debug-print.patch +Patch0007: 0007-client-remove-an-extra-debug-print.patch +Patch0008: 0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +Patch0009: 0009-pesign-authorize-shellcheck.patch +Patch0010: 0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch +Patch0011: 0011-kernel-building-hack.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -162,6 +165,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Thu Jul 16 2020 Peter Jones - 113-9 +- Even more kernel build debugging... + * Tue Jul 07 2020 Peter Jones - 113-8 - More kernel build debugging... From 00ec5834e33dfebc08c5e7993e64ce732744a9b8 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Thu, 16 Jul 2020 10:54:54 -0400 Subject: [PATCH 24/70] Make the bkernel hack even more load bearing... --- 0011-kernel-building-hack.patch | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/0011-kernel-building-hack.patch b/0011-kernel-building-hack.patch index 532b098..fc12aa6 100644 --- a/0011-kernel-building-hack.patch +++ b/0011-kernel-building-hack.patch @@ -12,7 +12,7 @@ diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in index d9236035928..2666c74a9ba 100644 --- a/src/pesign-rpmbuild-helper.in +++ b/src/pesign-rpmbuild-helper.in -@@ -195,6 +195,22 @@ main() { +@@ -195,6 +195,23 @@ main() { "${input[@]}" "${output[@]}" rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" elif [[ -n "${socket}" ]] ; then @@ -21,6 +21,7 @@ index d9236035928..2666c74a9ba 100644 + if [[ "${input[1]}" =~ (/|^)vmlinuz($|[_.-]) ]] \ + || [[ "${input[1]}" =~ (/|^)bzImage($|[_.-]) ]] ; then + if [[ "${rhelcertfile}" =~ redhatsecureboot501.* ]] \ ++ || [[ "${rhelcertfile}" =~ redhatsecureboot401.* ]] ; then + || [[ "${rhelcertfile}" =~ centossecureboot201.* ]] ; then + client_token[1]=kernel-signer + elif [[ "${rhelcertfile}" =~ redhatsecureboot502.* ]] \ From c43a6a24738b4c1bb979cffe691ec4ebcf842d87 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Thu, 16 Jul 2020 12:01:15 -0400 Subject: [PATCH 25/70] ... and fix its copy pasta syntax bug --- 0011-kernel-building-hack.patch | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/0011-kernel-building-hack.patch b/0011-kernel-building-hack.patch index fc12aa6..49f0486 100644 --- a/0011-kernel-building-hack.patch +++ b/0011-kernel-building-hack.patch @@ -21,7 +21,7 @@ index d9236035928..2666c74a9ba 100644 + if [[ "${input[1]}" =~ (/|^)vmlinuz($|[_.-]) ]] \ + || [[ "${input[1]}" =~ (/|^)bzImage($|[_.-]) ]] ; then + if [[ "${rhelcertfile}" =~ redhatsecureboot501.* ]] \ -+ || [[ "${rhelcertfile}" =~ redhatsecureboot401.* ]] ; then ++ || [[ "${rhelcertfile}" =~ redhatsecureboot401.* ]] \ + || [[ "${rhelcertfile}" =~ centossecureboot201.* ]] ; then + client_token[1]=kernel-signer + elif [[ "${rhelcertfile}" =~ redhatsecureboot502.* ]] \ From a52f86ee5934e94f7f228a545ed8f158e39da68d Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Thu, 16 Jul 2020 12:06:08 -0400 Subject: [PATCH 26/70] Add a dep on hostname Signed-off-by: Peter Jones --- pesign.spec | 1 + 1 file changed, 1 insertion(+) diff --git a/pesign.spec b/pesign.spec index d2f310c..804e97e 100644 --- a/pesign.spec +++ b/pesign.spec @@ -26,6 +26,7 @@ BuildRequires: python3 %if 0%{?rhel} >= 7 || 0%{?fedora} >= 17 BuildRequires: systemd-rpm-macros %endif +Requires: hostname Requires: nspr Requires: nss Requires: nss-tools >= 3.53 From 1f469180cd95d94f030f17a7534e30c9f9c11713 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Thu, 16 Jul 2020 12:34:10 -0400 Subject: [PATCH 27/70] Solve the hostname problem a different way. Signed-off-by: Peter Jones --- ...ros.pesign-to-pesign-rpmbuild-helper.patch | 28 +++++++++++-------- 0009-pesign-authorize-shellcheck.patch | 2 +- ...ize-don-t-setfacl-etc-pki-pesign-foo.patch | 2 +- 0011-kernel-building-hack.patch | 10 +++---- pesign.spec | 1 - 5 files changed, 23 insertions(+), 20 deletions(-) diff --git a/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch index 4b782ed..d216883 100644 --- a/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ b/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch @@ -1,4 +1,4 @@ -From 25981d57c4d56c53128d561bbe29593a6a20b259 Mon Sep 17 00:00:00 2001 +From 6cab63b9b01533f82067ac15b9cc426937c8e48b Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 13:54:35 -0400 Subject: [PATCH 08/11] Move most of macros.pesign to pesign-rpmbuild-helper @@ -7,13 +7,13 @@ Signed-off-by: Peter Jones --- Make.defaults | 1 + src/Makefile | 8 +- - src/macros.pesign | 73 ++++-------- - src/pesign-rpmbuild-helper.in | 216 ++++++++++++++++++++++++++++++++++ - 4 files changed, 245 insertions(+), 53 deletions(-) + src/macros.pesign | 74 ++++-------- + src/pesign-rpmbuild-helper.in | 222 ++++++++++++++++++++++++++++++++++ + 4 files changed, 252 insertions(+), 53 deletions(-) create mode 100644 src/pesign-rpmbuild-helper.in diff --git a/Make.defaults b/Make.defaults -index 0bacafe0d01..302da50efb5 100644 +index 0bacafe0d01..d4cd626c11e 100644 --- a/Make.defaults +++ b/Make.defaults @@ -16,6 +16,7 @@ INSTALLROOT = $(DESTDIR) @@ -58,7 +58,7 @@ index 74327ba13f3..a7ca89159c6 100644 $(INSTALL) -m 600 pesign-users $(INSTALLROOT)/etc/pesign/users $(INSTALL) -m 600 pesign-groups $(INSTALLROOT)/etc/pesign/groups diff --git a/src/macros.pesign b/src/macros.pesign -index 5a6da1c6809..730d3bc449c 100644 +index 5a6da1c6809..2e984b4eeb3 100644 --- a/src/macros.pesign +++ b/src/macros.pesign @@ -6,7 +6,7 @@ @@ -70,7 +70,7 @@ index 5a6da1c6809..730d3bc449c 100644 %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} %__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} -@@ -24,54 +24,23 @@ +@@ -24,54 +24,24 @@ # -a # rhel only # -s # perform signing %pesign(i:o:C:e:c:n:a:s) \ @@ -133,7 +133,8 @@ index 5a6da1c6809..730d3bc449c 100644 + %{?__pesign_client_cert:--client-cert %{__pesign_client_cert}} \\\ + %{?__pesign_token:%{__pesign_token}} \\\ + %{?__pesign_cert:--cert %{__pesign_cert}} \\\ -+ %{?vendor:--vendor %{vendor}} \\\ ++ %{?_buildhost:--hostname "%{_buildhost}"} \\\ ++ %{?vendor:--vendor "%{vendor}"} \\\ + %{?_rhel:--rhelver "%{_rhel}"} \\\ + %{?-n:--rhelcert "%{-n*}"}%{?!-n:--rhelcert "%{__pesign_cert}"} \\\ + %{?-a:--rhelcafile "%{-a*}"} \\\ @@ -147,10 +148,10 @@ index 5a6da1c6809..730d3bc449c 100644 +%{nil} diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in new file mode 100644 -index 00000000000..cb53550121f +index 00000000000..c5287c27e0c --- /dev/null +++ b/src/pesign-rpmbuild-helper.in -@@ -0,0 +1,219 @@ +@@ -0,0 +1,222 @@ +#!/bin/bash +# shellcheck shell=bash + @@ -220,6 +221,7 @@ index 00000000000..cb53550121f + local sign="" || : + local arch="" || : + local vendor="" || : ++ local HOSTNAME="" || : + + while [[ $# -ge 2 ]] ; do + case " ${1} " in @@ -229,6 +231,9 @@ index 00000000000..cb53550121f + " --rhelcertfile ") + rhelcertfile="${2}" + ;; ++ " --hostname ") ++ HOSTNAME="${2}" ++ ;; + " --certout ") + certout[0]=-C + certout[1]="${2}" @@ -314,13 +319,12 @@ index 00000000000..cb53550121f + fi + + USERNAME="${USERNAME:-$(id -un)}" -+ HOSTNAME="${HOSTNAME:-$(hostname)}" + + local socket="" || : + if grep -q ID=fedora /etc/os-release \ + && [[ "${rhelver}" -lt 7 ]] \ + && [[ "${USERNAME}" = "mockbuild" ]] \ -+ && [[ "${vendor}" == "Fedora Project" ]] \ ++ && [[ "${vendor}" = "Fedora Project" ]] \ + && [[ "${HOSTNAME}" =~ bkernel.* ]] + then + if [[ -S /run/pesign/socket ]] ; then diff --git a/0009-pesign-authorize-shellcheck.patch b/0009-pesign-authorize-shellcheck.patch index 8a8f7c9..119b45a 100644 --- a/0009-pesign-authorize-shellcheck.patch +++ b/0009-pesign-authorize-shellcheck.patch @@ -1,4 +1,4 @@ -From 91d45fea14dfce71f79534b0df276cf8175c0565 Mon Sep 17 00:00:00 2001 +From a2c286c5b420b0f398221fb777eab5932c728f02 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 14 Jul 2020 15:07:32 -0400 Subject: [PATCH 09/11] pesign-authorize: shellcheck diff --git a/0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch b/0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch index 153f69e..49286fd 100644 --- a/0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch +++ b/0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch @@ -1,4 +1,4 @@ -From 34efa71e9837bcf2e4c52234bc472e554c24c567 Mon Sep 17 00:00:00 2001 +From 14d8f7c1952f4f707b94e52a2985fe26c7426374 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 14 Jul 2020 15:08:15 -0400 Subject: [PATCH 10/11] pesign-authorize: don't setfacl /etc/pki/pesign-foo/ diff --git a/0011-kernel-building-hack.patch b/0011-kernel-building-hack.patch index 49f0486..f001c0a 100644 --- a/0011-kernel-building-hack.patch +++ b/0011-kernel-building-hack.patch @@ -1,18 +1,18 @@ -From 43d1c74b391485178da1d38722da0f28ece8b336 Mon Sep 17 00:00:00 2001 +From e1bcbd2040dbf9633771bf4330f7e046e77a2d20 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 14 Jul 2020 16:42:39 -0400 Subject: [PATCH 11/11] kernel building hack Signed-off-by: Peter Jones --- - src/pesign-rpmbuild-helper.in | 16 ++++++++++++++++ - 1 file changed, 16 insertions(+) + src/pesign-rpmbuild-helper.in | 17 +++++++++++++++++ + 1 file changed, 17 insertions(+) diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in -index d9236035928..2666c74a9ba 100644 +index c5287c27e0c..1fd0c2fc117 100644 --- a/src/pesign-rpmbuild-helper.in +++ b/src/pesign-rpmbuild-helper.in -@@ -195,6 +195,23 @@ main() { +@@ -202,6 +202,23 @@ main() { "${input[@]}" "${output[@]}" rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" elif [[ -n "${socket}" ]] ; then diff --git a/pesign.spec b/pesign.spec index 804e97e..d2f310c 100644 --- a/pesign.spec +++ b/pesign.spec @@ -26,7 +26,6 @@ BuildRequires: python3 %if 0%{?rhel} >= 7 || 0%{?fedora} >= 17 BuildRequires: systemd-rpm-macros %endif -Requires: hostname Requires: nspr Requires: nss Requires: nss-tools >= 3.53 From 2cab315fd4ecb50ceb25605de6a5b6b4df2a27c7 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Thu, 16 Jul 2020 13:42:13 -0400 Subject: [PATCH 28/70] this one seems to work in my mock setup Signed-off-by: Peter Jones --- ...-macros.pesign-to-pesign-rpmbuild-helper.patch | 15 ++++++++++----- 0009-pesign-authorize-shellcheck.patch | 2 +- ...thorize-don-t-setfacl-etc-pki-pesign-foo.patch | 2 +- 0011-kernel-building-hack.patch | 12 ++++++------ 4 files changed, 18 insertions(+), 13 deletions(-) diff --git a/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch index d216883..77b2fec 100644 --- a/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ b/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch @@ -1,4 +1,4 @@ -From 6cab63b9b01533f82067ac15b9cc426937c8e48b Mon Sep 17 00:00:00 2001 +From e05840efa8dc9d0a9ff3104b9fa6e5736e0ec549 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 13:54:35 -0400 Subject: [PATCH 08/11] Move most of macros.pesign to pesign-rpmbuild-helper @@ -7,9 +7,9 @@ Signed-off-by: Peter Jones --- Make.defaults | 1 + src/Makefile | 8 +- - src/macros.pesign | 74 ++++-------- + src/macros.pesign | 76 ++++-------- src/pesign-rpmbuild-helper.in | 222 ++++++++++++++++++++++++++++++++++ - 4 files changed, 252 insertions(+), 53 deletions(-) + 4 files changed, 253 insertions(+), 54 deletions(-) create mode 100644 src/pesign-rpmbuild-helper.in diff --git a/Make.defaults b/Make.defaults @@ -58,10 +58,10 @@ index 74327ba13f3..a7ca89159c6 100644 $(INSTALL) -m 600 pesign-users $(INSTALLROOT)/etc/pesign/users $(INSTALL) -m 600 pesign-groups $(INSTALLROOT)/etc/pesign/groups diff --git a/src/macros.pesign b/src/macros.pesign -index 5a6da1c6809..2e984b4eeb3 100644 +index 5a6da1c6809..cb066b35f4a 100644 --- a/src/macros.pesign +++ b/src/macros.pesign -@@ -6,7 +6,7 @@ +@@ -6,11 +6,11 @@ # %pesign -s -i shim.orig -o shim.efi # And magically get the right thing. @@ -70,6 +70,11 @@ index 5a6da1c6809..2e984b4eeb3 100644 %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} %__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} +-%__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} ++%__pesign_client_cert %{!?pe_signing_cert:"Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} + + %_pesign /usr/bin/pesign + %_pesign_client /usr/bin/pesign-client @@ -24,54 +24,24 @@ # -a # rhel only # -s # perform signing diff --git a/0009-pesign-authorize-shellcheck.patch b/0009-pesign-authorize-shellcheck.patch index 119b45a..3597f5f 100644 --- a/0009-pesign-authorize-shellcheck.patch +++ b/0009-pesign-authorize-shellcheck.patch @@ -1,4 +1,4 @@ -From a2c286c5b420b0f398221fb777eab5932c728f02 Mon Sep 17 00:00:00 2001 +From 3107894285164a3d25ca215a76593ebb6d4bc84c Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 14 Jul 2020 15:07:32 -0400 Subject: [PATCH 09/11] pesign-authorize: shellcheck diff --git a/0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch b/0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch index 49286fd..d4a7b31 100644 --- a/0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch +++ b/0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch @@ -1,4 +1,4 @@ -From 14d8f7c1952f4f707b94e52a2985fe26c7426374 Mon Sep 17 00:00:00 2001 +From 24bb6e1471b16b6be82f13b5b5a302b4e98c1b4d Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 14 Jul 2020 15:08:15 -0400 Subject: [PATCH 10/11] pesign-authorize: don't setfacl /etc/pki/pesign-foo/ diff --git a/0011-kernel-building-hack.patch b/0011-kernel-building-hack.patch index f001c0a..69ffc56 100644 --- a/0011-kernel-building-hack.patch +++ b/0011-kernel-building-hack.patch @@ -1,4 +1,4 @@ -From e1bcbd2040dbf9633771bf4330f7e046e77a2d20 Mon Sep 17 00:00:00 2001 +From 0b9048cbcc1cfc2afd9cbf781732882736cbe965 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 14 Jul 2020 16:42:39 -0400 Subject: [PATCH 11/11] kernel building hack @@ -9,7 +9,7 @@ Signed-off-by: Peter Jones 1 file changed, 17 insertions(+) diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in -index c5287c27e0c..1fd0c2fc117 100644 +index c5287c27e0c..27b8261bc17 100644 --- a/src/pesign-rpmbuild-helper.in +++ b/src/pesign-rpmbuild-helper.in @@ -202,6 +202,23 @@ main() { @@ -17,19 +17,19 @@ index c5287c27e0c..1fd0c2fc117 100644 rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" elif [[ -n "${socket}" ]] ; then + ### welcome haaaaack city -+ if [[ "${client_token[1]}" = "/CN=Fedora Secure Boot Signer" ]] ; then ++ if [[ "${client_token[1]}" = "OpenSC Card (Fedora Signer)" ]] ; then + if [[ "${input[1]}" =~ (/|^)vmlinuz($|[_.-]) ]] \ + || [[ "${input[1]}" =~ (/|^)bzImage($|[_.-]) ]] ; then + if [[ "${rhelcertfile}" =~ redhatsecureboot501.* ]] \ + || [[ "${rhelcertfile}" =~ redhatsecureboot401.* ]] \ + || [[ "${rhelcertfile}" =~ centossecureboot201.* ]] ; then -+ client_token[1]=kernel-signer ++ client_cert[1]=kernel-signer + elif [[ "${rhelcertfile}" =~ redhatsecureboot502.* ]] \ + || [[ "${rhelcertfile}" =~ centossecureboot202.* ]] ; then -+ client_token[1]=grub2-signer ++ client_cert[1]=grub2-signer + elif [[ "${rhelcertfile}" =~ redhatsecureboot503.* ]] \ + || [[ "${rhelcertfile}" =~ centossecureboot203.* ]] ; then -+ client_token[1]=fwupd-signer ++ client_cert[1]=fwupd-signer + fi + fi + fi From 885ef5ef5ee42d065e7465dbf279417308078f2e Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Thu, 16 Jul 2020 15:14:49 -0400 Subject: [PATCH 29/70] I really cannot figure out why bkernel01 thinks the certificate nickname starts with /CN=, but it does, so I'm gonna stop fighting with the sand. Signed-off-by: Peter Jones --- ...ve-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch | 3 +-- pesign.spec | 6 +++++- 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch index 77b2fec..0a96bdb 100644 --- a/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ b/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch @@ -70,8 +70,7 @@ index 5a6da1c6809..cb066b35f4a 100644 %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} %__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} --%__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} -+%__pesign_client_cert %{!?pe_signing_cert:"Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} + %__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} %_pesign /usr/bin/pesign %_pesign_client /usr/bin/pesign-client diff --git a/pesign.spec b/pesign.spec index d2f310c..b84c5c7 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 9%{?dist} +Release: 10%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -165,6 +165,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Thu Jul 16 2020 Peter Jones - 113-10 +- I really cannot figure out why bkernel01 thinks the certificate nickname + starts with /CN=, but it does, so I'm gonna stop fighting with the sand. + * Thu Jul 16 2020 Peter Jones - 113-9 - Even more kernel build debugging... From 92fa0a36af298d9fa0d353a7c8ae28ae1c36edb9 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Tue, 28 Jul 2020 20:31:11 +0000 Subject: [PATCH 30/70] - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pesign.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index b84c5c7..2040fab 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 10%{?dist} +Release: 11%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -165,6 +165,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Jul 28 2020 Fedora Release Engineering - 113-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + * Thu Jul 16 2020 Peter Jones - 113-10 - I really cannot figure out why bkernel01 thinks the certificate nickname starts with /CN=, but it does, so I'm gonna stop fighting with the sand. From 9dddf18b1015d90ef2c0873836d1ea3a60894812 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Thu, 30 Jul 2020 22:45:37 -0400 Subject: [PATCH 31/70] Try to make kernel and fwupd both work at the same time. Signed-off-by: Peter Jones --- 0012-one-more-glorious-hack.patch | 25 +++++++++++++++++++++++++ pesign.spec | 6 +++++- 2 files changed, 30 insertions(+), 1 deletion(-) create mode 100644 0012-one-more-glorious-hack.patch diff --git a/0012-one-more-glorious-hack.patch b/0012-one-more-glorious-hack.patch new file mode 100644 index 0000000..4ca15ec --- /dev/null +++ b/0012-one-more-glorious-hack.patch @@ -0,0 +1,25 @@ +From ca1fb1982b237aad86ef0adfc2f1a7bc60606701 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Thu, 30 Jul 2020 22:44:11 -0400 +Subject: [PATCH] one more glorious hack + +--- + src/macros.pesign | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/macros.pesign b/src/macros.pesign +index 730d3bc449c..b4fa04a7192 100644 +--- a/src/macros.pesign ++++ b/src/macros.pesign +@@ -34,7 +34,7 @@ + %{?__pesign_cert:--cert %{__pesign_cert}} \\\ + %{?vendor:--vendor %{vendor}} \\\ + %{?_rhel:--rhelver "%{_rhel}"} \\\ +- %{?-n:--rhelcert "%{-n*}"}%{?!-n:--rhelcert "%{__pesign_cert}"} \\\ ++ %{?-n:--rhelcert %{-n*}}%{?!-n:--rhelcert %{__pesign_cert}} \\\ + %{?-a:--rhelcafile "%{-a*}"} \\\ + %{?-c:--rhelcertfile "%{-c*}"} \\\ + %{?-C:--certout "%{-C*}"} \\\ +-- +2.26.2 + diff --git a/pesign.spec b/pesign.spec index 2040fab..eb68d02 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 11%{?dist} +Release: 12%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -53,6 +53,7 @@ Patch0008: 0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch Patch0009: 0009-pesign-authorize-shellcheck.patch Patch0010: 0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch Patch0011: 0011-kernel-building-hack.patch +Patch0012: 0012-one-more-glorious-hack.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -165,6 +166,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Thu Jul 30 2020 Peter Jones - 113-12 +- Try to make kernel and fwupd both work at the same time. + * Tue Jul 28 2020 Fedora Release Engineering - 113-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild From e69b8ee7151d99a02ebdd42dd0a16ffe200d2af1 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 3 Aug 2020 11:00:39 -0400 Subject: [PATCH 32/70] Try to make kernel and fwupd both work at the same time. Signed-off-by: Peter Jones --- ...ros.pesign-to-pesign-rpmbuild-helper.patch | 18 ++++++------- 0012-one-more-glorious-hack.patch | 25 ------------------- pesign.spec | 3 +-- 3 files changed, 8 insertions(+), 38 deletions(-) delete mode 100644 0012-one-more-glorious-hack.patch diff --git a/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch index 0a96bdb..3a62cf6 100644 --- a/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ b/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch @@ -1,15 +1,15 @@ -From e05840efa8dc9d0a9ff3104b9fa6e5736e0ec549 Mon Sep 17 00:00:00 2001 +From 6c16b978fd33f3611e9f7aaf4f9c44bce1679485 Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 6 Jul 2020 13:54:35 -0400 -Subject: [PATCH 08/11] Move most of macros.pesign to pesign-rpmbuild-helper +Subject: [PATCH] Move most of macros.pesign to pesign-rpmbuild-helper Signed-off-by: Peter Jones --- Make.defaults | 1 + src/Makefile | 8 +- - src/macros.pesign | 76 ++++-------- + src/macros.pesign | 74 ++++-------- src/pesign-rpmbuild-helper.in | 222 ++++++++++++++++++++++++++++++++++ - 4 files changed, 253 insertions(+), 54 deletions(-) + 4 files changed, 252 insertions(+), 53 deletions(-) create mode 100644 src/pesign-rpmbuild-helper.in diff --git a/Make.defaults b/Make.defaults @@ -58,10 +58,10 @@ index 74327ba13f3..a7ca89159c6 100644 $(INSTALL) -m 600 pesign-users $(INSTALLROOT)/etc/pesign/users $(INSTALL) -m 600 pesign-groups $(INSTALLROOT)/etc/pesign/groups diff --git a/src/macros.pesign b/src/macros.pesign -index 5a6da1c6809..cb066b35f4a 100644 +index 5a6da1c6809..2e984b4eeb3 100644 --- a/src/macros.pesign +++ b/src/macros.pesign -@@ -6,11 +6,11 @@ +@@ -6,7 +6,7 @@ # %pesign -s -i shim.orig -o shim.efi # And magically get the right thing. @@ -70,10 +70,6 @@ index 5a6da1c6809..cb066b35f4a 100644 %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} %__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} - %__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} - - %_pesign /usr/bin/pesign - %_pesign_client /usr/bin/pesign-client @@ -24,54 +24,24 @@ # -a # rhel only # -s # perform signing @@ -140,7 +136,7 @@ index 5a6da1c6809..cb066b35f4a 100644 + %{?_buildhost:--hostname "%{_buildhost}"} \\\ + %{?vendor:--vendor "%{vendor}"} \\\ + %{?_rhel:--rhelver "%{_rhel}"} \\\ -+ %{?-n:--rhelcert "%{-n*}"}%{?!-n:--rhelcert "%{__pesign_cert}"} \\\ ++ %{?-n:--rhelcert %{-n*}}%{?!-n:--rhelcert %{__pesign_cert}} \\\ + %{?-a:--rhelcafile "%{-a*}"} \\\ + %{?-c:--rhelcertfile "%{-c*}"} \\\ + %{?-C:--certout "%{-C*}"} \\\ diff --git a/0012-one-more-glorious-hack.patch b/0012-one-more-glorious-hack.patch deleted file mode 100644 index 4ca15ec..0000000 --- a/0012-one-more-glorious-hack.patch +++ /dev/null @@ -1,25 +0,0 @@ -From ca1fb1982b237aad86ef0adfc2f1a7bc60606701 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Thu, 30 Jul 2020 22:44:11 -0400 -Subject: [PATCH] one more glorious hack - ---- - src/macros.pesign | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/macros.pesign b/src/macros.pesign -index 730d3bc449c..b4fa04a7192 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -34,7 +34,7 @@ - %{?__pesign_cert:--cert %{__pesign_cert}} \\\ - %{?vendor:--vendor %{vendor}} \\\ - %{?_rhel:--rhelver "%{_rhel}"} \\\ -- %{?-n:--rhelcert "%{-n*}"}%{?!-n:--rhelcert "%{__pesign_cert}"} \\\ -+ %{?-n:--rhelcert %{-n*}}%{?!-n:--rhelcert %{__pesign_cert}} \\\ - %{?-a:--rhelcafile "%{-a*}"} \\\ - %{?-c:--rhelcertfile "%{-c*}"} \\\ - %{?-C:--certout "%{-C*}"} \\\ --- -2.26.2 - diff --git a/pesign.spec b/pesign.spec index eb68d02..4d44d0d 100644 --- a/pesign.spec +++ b/pesign.spec @@ -53,7 +53,6 @@ Patch0008: 0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch Patch0009: 0009-pesign-authorize-shellcheck.patch Patch0010: 0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch Patch0011: 0011-kernel-building-hack.patch -Patch0012: 0012-one-more-glorious-hack.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -166,7 +165,7 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog -* Thu Jul 30 2020 Peter Jones - 113-12 +* Mon Aug 03 2020 Peter Jones - 113-12 - Try to make kernel and fwupd both work at the same time. * Tue Jul 28 2020 Fedora Release Engineering - 113-11 From 2ee3400b3c6ed63e365a4361219b79a833cd76ea Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Mon, 3 Aug 2020 16:30:11 -0400 Subject: [PATCH 33/70] Add the rundir related stuff that was staged on my f32 checkout. Signed-off-by: Peter Jones --- 0012-Use-run-not-var-run.patch | 105 +++++++++++++++++++++++++++++++++ pesign.spec | 12 ++-- 2 files changed, 113 insertions(+), 4 deletions(-) create mode 100644 0012-Use-run-not-var-run.patch diff --git a/0012-Use-run-not-var-run.patch b/0012-Use-run-not-var-run.patch new file mode 100644 index 0000000..1b4e0c6 --- /dev/null +++ b/0012-Use-run-not-var-run.patch @@ -0,0 +1,105 @@ +From db4c6e8cc57271dce6d204a3144982e544e55025 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Thu, 16 Jul 2020 16:28:26 -0400 +Subject: [PATCH] Use /run not /var/run + +Signed-off-by: Peter Jones +--- + src/daemon.h | 4 ++-- + src/Makefile | 2 +- + src/pesign-authorize | 2 +- + src/pesign.service.in | 2 +- + src/pesign.sysvinit.in | 10 +++++----- + 5 files changed, 10 insertions(+), 10 deletions(-) + +diff --git a/src/daemon.h b/src/daemon.h +index 0368dc9256c..5fcd97ea717 100644 +--- a/src/daemon.h ++++ b/src/daemon.h +@@ -51,8 +51,8 @@ typedef enum { + } pesignd_cmd; + + #define PESIGND_VERSION 0x2a9edaf0 +-#define SOCKPATH "/var/run/pesign/socket" +-#define PIDFILE "/var/run/pesign.pid" ++#define SOCKPATH "/run/pesign/socket" ++#define PIDFILE "/run/pesign.pid" + + static inline uint32_t UNUSED + pesignd_string_size(char *buffer) +diff --git a/src/Makefile b/src/Makefile +index a7ca89159c6..f7fb5fc9ee5 100644 +--- a/src/Makefile ++++ b/src/Makefile +@@ -78,7 +78,7 @@ install_sysvinit: pesign.sysvinit + install : + $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign/ + $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign-rh-test/ +- $(INSTALL) -d -m 770 $(INSTALLROOT)/var/run/pesign/ ++ $(INSTALL) -d -m 770 $(INSTALLROOT)/run/pesign/ + $(INSTALL) -d -m 755 $(INSTALLROOT)$(bindir) + $(INSTALL) -m 755 authvar $(INSTALLROOT)$(bindir) + $(INSTALL) -m 755 pesign $(INSTALLROOT)$(bindir) +diff --git a/src/pesign-authorize b/src/pesign-authorize +index c5448329c2c..2381302440c 100755 +--- a/src/pesign-authorize ++++ b/src/pesign-authorize +@@ -47,7 +47,7 @@ update_subdir() { + done + } + +-for x in /var/run/pesign/ /etc/pki/pesign/ ; do ++for x in /run/pesign/ /var/run/pesign/ /etc/pki/pesign/ ; do + if [ -d "${x}" ]; then + update_subdir "${x}" + else +diff --git a/src/pesign.service.in b/src/pesign.service.in +index c75a000892a..4ac2199bce2 100644 +--- a/src/pesign.service.in ++++ b/src/pesign.service.in +@@ -4,6 +4,6 @@ Description=Pesign signing daemon + [Service] + PrivateTmp=true + Type=forking +-PIDFile=/var/run/pesign.pid ++PIDFile=/run/pesign.pid + ExecStart=/usr/bin/pesign --daemonize + ExecStartPost=@@LIBEXECDIR@@/pesign/pesign-authorize +diff --git a/src/pesign.sysvinit.in b/src/pesign.sysvinit.in +index b0e0f84ff0b..bf8edec8ff3 100644 +--- a/src/pesign.sysvinit.in ++++ b/src/pesign.sysvinit.in +@@ -4,7 +4,7 @@ + # + # chkconfig: - 50 50 + # processname: /usr/bin/pesign +-# pidfile: /var/run/pesign.pid ++# pidfile: /run/pesign.pid + ### BEGIN INIT INFO + # Provides: pesign + # Default-Start: +@@ -20,9 +20,9 @@ RETVAL=0 + + start(){ + echo -n "Starting pesign: " +- mkdir /var/run/pesign 2>/dev/null && +- chown pesign:pesign /var/run/pesign && +- chmod 0770 /var/run/pesign ++ mkdir /run/pesign 2>/dev/null && ++ chown pesign:pesign /run/pesign && ++ chmod 0770 /run/pesign + daemon /usr/bin/pesign --daemonize + RETVAL=$? + echo +@@ -32,7 +32,7 @@ start(){ + + stop(){ + echo -n "Stopping pesign: " +- killproc -p /var/run/pesign.pid pesignd ++ killproc -p /run/pesign.pid pesignd + RETVAL=$? + echo + rm -f /var/lock/subsys/pesign +-- +2.26.2 + diff --git a/pesign.spec b/pesign.spec index 4d44d0d..76c6a72 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 12%{?dist} +Release: 13%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -53,6 +53,7 @@ Patch0008: 0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch Patch0009: 0009-pesign-authorize-shellcheck.patch Patch0010: 0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch Patch0011: 0011-kernel-building-hack.patch +Patch0012: 0012-Use-run-not-var-run.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -154,9 +155,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{_sysconfdir}/popt.d/pesign.popt %{macrosdir}/macros.pesign %{_mandir}/man*/* -%dir %attr(0770, pesign, pesign) %{_localstatedir}/run/%{name} -%ghost %attr(0660, -, -) %{_localstatedir}/run/%{name}/socket -%ghost %attr(0660, -, -) %{_localstatedir}/run/%{name}/pesign.pid +%dir %attr(0770, pesign, pesign) %{_rundir}/%{name} +%ghost %attr(0660, -, -) %{_rundir}/%{name}/socket +%ghost %attr(0660, -, -) %{_rundir}/%{name}/pesign.pid %if 0%{?rhel} >= 7 || 0%{?fedora} >= 17 %{_tmpfilesdir}/pesign.conf %{_unitdir}/pesign.service @@ -165,6 +166,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Mon Aug 03 2020 Peter Jones - 113-13 +- Add the rundir related stuff that was staged on my f32 checkout. + * Mon Aug 03 2020 Peter Jones - 113-12 - Try to make kernel and fwupd both work at the same time. From f7bf001e4566378fc6095e299e01951d1c99dfda Mon Sep 17 00:00:00 2001 From: Jeff Law Date: Mon, 16 Nov 2020 12:31:41 -0700 Subject: [PATCH 34/70] - Turn off -Wfree-nonheap-object --- 0013-Turn-off-free-nonheap-object.patch | 35 +++++++++++++++++++++++++ pesign.spec | 6 ++++- 2 files changed, 40 insertions(+), 1 deletion(-) create mode 100644 0013-Turn-off-free-nonheap-object.patch diff --git a/0013-Turn-off-free-nonheap-object.patch b/0013-Turn-off-free-nonheap-object.patch new file mode 100644 index 0000000..3e62bd8 --- /dev/null +++ b/0013-Turn-off-free-nonheap-object.patch @@ -0,0 +1,35 @@ +From 59428daf4863f192419eee4afec15cd099e99c9b Mon Sep 17 00:00:00 2001 +From: Jeff Law +Date: Mon, 16 Nov 2020 12:07:59 -0700 +Subject: [PATCH] Turn off -Wfree-nonheap-object + +authvar.c has a call to free (tokenname) where tokenname is set to a string constant +and never changed. That triggers GCC to issue a diagnostic that the value should not +be passed to free. + +This is a false positive from GCC as the call is guarded by a suitable condition that +always happens to be false. But pesign is being built without optimization and thus +the condition and free call are not optimized away. + +This patch just disables the warning. A better solution would be to fix the sources +or build with the optimizer enabled. +--- + Make.defaults | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/Make.defaults b/Make.defaults +index d4cd626..705cc3a 100644 +--- a/Make.defaults ++++ b/Make.defaults +@@ -40,7 +40,7 @@ gcc_cflags = -Wmaybe-uninitialized -grecord-gcc-switches -flto + cflags = $(CFLAGS) $(ARCH3264) \ + -Wall -Wextra -Wsign-compare -Wno-unused-result \ + -Wno-unused-function -Wno-missing-field-initializers \ +- -Werror -Wno-error=cpp \ ++ -Werror -Wno-error=cpp -Wno-free-nonheap-object \ + -std=gnu11 -fshort-wchar -fPIC -fno-strict-aliasing \ + -D_GNU_SOURCE -DCONFIG_$(ARCH) -I${TOPDIR}/include \ + $(if $(filter $(CC),clang),$(clang_cflags), ) \ +-- +2.28.0 + diff --git a/pesign.spec b/pesign.spec index 76c6a72..a2bdb04 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 13%{?dist} +Release: 14%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -54,6 +54,7 @@ Patch0009: 0009-pesign-authorize-shellcheck.patch Patch0010: 0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch Patch0011: 0011-kernel-building-hack.patch Patch0012: 0012-Use-run-not-var-run.patch +Patch0013: 0013-Turn-off-free-nonheap-object.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -166,6 +167,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Mon Nov 16 2020 Jeff Law - 113-14 +- Turn off -Wfree-nonheap-object + * Mon Aug 03 2020 Peter Jones - 113-13 - Add the rundir related stuff that was staged on my f32 checkout. From 6f2919a23cfc63515c8066b0dc2f000fdb3af6d4 Mon Sep 17 00:00:00 2001 From: Tom Stellard Date: Fri, 8 Jan 2021 19:09:25 +0000 Subject: [PATCH 35/70] Add BuildRequires: make https://fedoraproject.org/wiki/Changes/Remove_make_from_BuildRoot --- pesign.spec | 1 + 1 file changed, 1 insertion(+) diff --git a/pesign.spec b/pesign.spec index a2bdb04..a7f872f 100644 --- a/pesign.spec +++ b/pesign.spec @@ -8,6 +8,7 @@ License: GPLv2 URL: https://github.com/vathpela/pesign Obsoletes: pesign-rh-test-certs <= 0.111-7 +BuildRequires: make BuildRequires: gcc BuildRequires: git BuildRequires: nspr From 53bd735c5462e322e521360ac53db7c0896aee98 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Wed, 27 Jan 2021 06:14:58 +0000 Subject: [PATCH 36/70] - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pesign.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index a7f872f..773ad0c 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 14%{?dist} +Release: 15%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -168,6 +168,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Wed Jan 27 2021 Fedora Release Engineering - 113-15 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + * Mon Nov 16 2020 Jeff Law - 113-14 - Turn off -Wfree-nonheap-object From 28f91e739af8cffc434099d86b4188bdb094021a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Tue, 2 Mar 2021 16:13:04 +0100 Subject: [PATCH 37/70] Rebuilt for updated systemd-rpm-macros See https://pagure.io/fesco/issue/2583. --- pesign.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index 773ad0c..07aecfb 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 15%{?dist} +Release: 16%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -168,6 +168,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Mar 02 2021 Zbigniew JÄ™drzejewski-Szmek - 113-16 +- Rebuilt for updated systemd-rpm-macros + See https://pagure.io/fesco/issue/2583. + * Wed Jan 27 2021 Fedora Release Engineering - 113-15 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild From 6816587aa8d3410c9f6e8f17ed663c74e19b21d6 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 23 Jul 2021 01:25:42 +0000 Subject: [PATCH 38/70] - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pesign.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index 07aecfb..c1a004f 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 16%{?dist} +Release: 17%{?dist} License: GPLv2 URL: https://github.com/vathpela/pesign @@ -168,6 +168,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Fri Jul 23 2021 Fedora Release Engineering - 113-17 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + * Tue Mar 02 2021 Zbigniew JÄ™drzejewski-Szmek - 113-16 - Rebuilt for updated systemd-rpm-macros See https://pagure.io/fesco/issue/2583. From 3c1a1c50645d863d6fcf8a347d31f9858c51b4e0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 5 Oct 2021 13:05:06 -0400 Subject: [PATCH 39/70] Add rpminspect configuration (no code changes) Signed-off-by: Robbie Harwood --- rpminspect.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 rpminspect.yaml diff --git a/rpminspect.yaml b/rpminspect.yaml new file mode 100644 index 0000000..4c08189 --- /dev/null +++ b/rpminspect.yaml @@ -0,0 +1,13 @@ +--- +inspections: + # Not a Java package + javabytecode: off + + # These just flag when things change "too much" + changedfiles: off + filesize: off + patches: off + upstream: off + + # https://bugzilla.redhat.com/show_bug.cgi?id=2010936 + annocheck: off From 409a7cdd41746c8ff3d957f52fcdaf3eef6f6b21 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 14 Dec 2021 13:51:22 -0500 Subject: [PATCH 40/70] Fix upstream URL; no code changes Signed-off-by: Robbie Harwood --- pesign.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index c1a004f..6383411 100644 --- a/pesign.spec +++ b/pesign.spec @@ -5,7 +5,7 @@ Summary: Signing utility for UEFI binaries Version: 113 Release: 17%{?dist} License: GPLv2 -URL: https://github.com/vathpela/pesign +URL: https://github.com/rhboot/pesign Obsoletes: pesign-rh-test-certs <= 0.111-7 BuildRequires: make From 98a054d3eb2938d5c338d676268031c38183191b Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 21 Jan 2022 07:08:24 +0000 Subject: [PATCH 41/70] - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pesign.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index 6383411..e688936 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 17%{?dist} +Release: 18%{?dist} License: GPLv2 URL: https://github.com/rhboot/pesign @@ -168,6 +168,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Fri Jan 21 2022 Fedora Release Engineering - 113-18 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + * Fri Jul 23 2021 Fedora Release Engineering - 113-17 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild From c7c4e0f825f288b0355f8ed81f9744ebead8e8ad Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 1 Feb 2022 19:52:01 +0000 Subject: [PATCH 42/70] New upstream version (114) Signed-off-by: Robbie Harwood --- ...fikeygen-Fix-the-build-with-nss-3.44.patch | 45 --- 0002-pesigcheck-Fix-a-wrong-assignment.patch | 49 --- ...t-and-server-work-with-the-113-proto.patch | 317 --------------- 0004-Rename-var-run-to-run.patch | 46 --- ...c-got-updated-and-the-token-name-cha.patch | 30 -- ...-run-and-var-run-for-the-socket-path.patch | 86 ---- 0007-client-remove-an-extra-debug-print.patch | 25 -- ...ros.pesign-to-pesign-rpmbuild-helper.patch | 379 ------------------ 0009-pesign-authorize-shellcheck.patch | 60 --- ...ize-don-t-setfacl-etc-pki-pesign-foo.patch | 26 -- 0011-kernel-building-hack.patch | 41 -- 0012-Use-run-not-var-run.patch | 105 ----- 0013-Turn-off-free-nonheap-object.patch | 35 -- pesign.spec | 41 +- sources | 2 +- 15 files changed, 16 insertions(+), 1271 deletions(-) delete mode 100644 0001-efikeygen-Fix-the-build-with-nss-3.44.patch delete mode 100644 0002-pesigcheck-Fix-a-wrong-assignment.patch delete mode 100644 0003-Make-0.112-client-and-server-work-with-the-113-proto.patch delete mode 100644 0004-Rename-var-run-to-run.patch delete mode 100644 0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch delete mode 100644 0006-client-try-run-and-var-run-for-the-socket-path.patch delete mode 100644 0007-client-remove-an-extra-debug-print.patch delete mode 100644 0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch delete mode 100644 0009-pesign-authorize-shellcheck.patch delete mode 100644 0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch delete mode 100644 0011-kernel-building-hack.patch delete mode 100644 0012-Use-run-not-var-run.patch delete mode 100644 0013-Turn-off-free-nonheap-object.patch diff --git a/0001-efikeygen-Fix-the-build-with-nss-3.44.patch b/0001-efikeygen-Fix-the-build-with-nss-3.44.patch deleted file mode 100644 index e583369..0000000 --- a/0001-efikeygen-Fix-the-build-with-nss-3.44.patch +++ /dev/null @@ -1,45 +0,0 @@ -From b535d1ac5cbcdf18a97d97a92581e38080d9e521 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 14 May 2019 11:28:38 -0400 -Subject: [PATCH] efikeygen: Fix the build with nss 3.44 - -NSS 3.44 adds some certificate types, which changes a type and makes -some encoding stuff weird. As a result, we get: - -gcc8 -I/wrkdirs/usr/ports/sysutils/pesign/work/pesign-0.110/include -O2 -pipe -fstack-protector-strong -Wl,-rpath=/usr/local/lib/gcc8 -isystem /usr/local/include -fno-strict-aliasing -g -O0 -g -O0 -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants --std=gnu99 -D_GNU_SOURCE -Wno-unused-result -Wno-unused-function -I../include/ -I/usr/local/include/nss -I/usr/local/include/nss/nss -I/usr/local/include/nspr -Werror -fPIC -isystem /usr/local/include -DCONFIG_amd64 -DCONFIG_amd64 -c efikeygen.c -o efikeygen.o -In file included from /usr/local/include/nss/nss/cert.h:22, - from efikeygen.c:39: -efikeygen.c: In function 'add_cert_type': -/usr/local/include/nss/nss/certt.h:445:5: error: unsigned conversion from 'int' to 'unsigned char' changes value from '496' to '240' [-Werror=overflow] - (NS_CERT_TYPE_SSL_CLIENT | NS_CERT_TYPE_SSL_SERVER | NS_CERT_TYPE_EMAIL | \ - ^ -efikeygen.c:208:23: note: in expansion of macro 'NS_CERT_TYPE_APP' - unsigned char type = NS_CERT_TYPE_APP; - ^~~~~~~~~~~~~~~~ -cc1: all warnings being treated as errors - -This is fixed by just making it an int. - -Fixes github issue #48. - -Signed-off-by: Peter Jones ---- - src/efikeygen.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/efikeygen.c b/src/efikeygen.c -index ede76ef0b48..2cd953e9781 100644 ---- a/src/efikeygen.c -+++ b/src/efikeygen.c -@@ -208,7 +208,7 @@ static int - add_cert_type(cms_context *cms, void *extHandle, int is_ca) - { - SECItem bitStringValue; -- unsigned char type = NS_CERT_TYPE_APP; -+ int type = NS_CERT_TYPE_APP; - - if (is_ca) - type |= NS_CERT_TYPE_SSL_CA | --- -2.23.0 - diff --git a/0002-pesigcheck-Fix-a-wrong-assignment.patch b/0002-pesigcheck-Fix-a-wrong-assignment.patch deleted file mode 100644 index 7df5f0b..0000000 --- a/0002-pesigcheck-Fix-a-wrong-assignment.patch +++ /dev/null @@ -1,49 +0,0 @@ -From c555fd74c009242c3864576bd5f17a1f8f4fdffd Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 18 Feb 2020 16:28:56 -0500 -Subject: [PATCH] pesigcheck: Fix a wrong assignment - -gcc says: - - pesigcheck.c: In function 'check_signature': - pesigcheck.c:321:17: error: implicit conversion from 'enum ' to 'enum ' [-Werror=enum-conversion] - 321 | reason->type = siBuffer; - | ^ - pesigcheck.c:333:17: error: implicit conversion from 'enum ' to 'enum ' [-Werror=enum-conversion] - 333 | reason->type = siBuffer; - | ^ - cc1: all warnings being treated as errors - -And indeed, that line of code makes no sense at all - it was supposed to -be reason->sig.type. - -Signed-off-by: Peter Jones ---- - src/pesigcheck.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/pesigcheck.c b/src/pesigcheck.c -index 524cce307bf..8fa0f1ad03d 100644 ---- a/src/pesigcheck.c -+++ b/src/pesigcheck.c -@@ -318,7 +318,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons, - reason->type = SIGNATURE; - reason->sig.data = data; - reason->sig.len = datalen; -- reason->type = siBuffer; -+ reason->sig.type = siBuffer; - nreason += 1; - is_invalid = true; - } -@@ -330,7 +330,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons, - reason->type = SIGNATURE; - reason->sig.data = data; - reason->sig.len = datalen; -- reason->type = siBuffer; -+ reason->sig.type = siBuffer; - nreason += 1; - has_valid_cert = true; - } --- -2.24.1 - diff --git a/0003-Make-0.112-client-and-server-work-with-the-113-proto.patch b/0003-Make-0.112-client-and-server-work-with-the-113-proto.patch deleted file mode 100644 index e639675..0000000 --- a/0003-Make-0.112-client-and-server-work-with-the-113-proto.patch +++ /dev/null @@ -1,317 +0,0 @@ -From 84547e6b7173e4b10a1931fd25f329ea9a8f68b0 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Thu, 11 Jun 2020 16:23:14 -0400 -Subject: [PATCH] Make 0.112 client and server work with the 113 protocol and - vise versa - -This makes the version of the sign API that takes a file type optional, -and makes the client attempt to negotiate which version it's getting. -It also leaves the server able to still handle the version from before -the file type was added. - -Signed-off-by: Peter Jones ---- - src/client.c | 74 +++++++++++++++++++++++++++++++++++++--------------- - src/daemon.c | 63 +++++++++++++++++++++++++++++--------------- - src/daemon.h | 2 ++ - 3 files changed, 97 insertions(+), 42 deletions(-) - -diff --git a/src/client.c b/src/client.c -index aa373abd981..57bcc09cbe8 100644 ---- a/src/client.c -+++ b/src/client.c -@@ -11,6 +11,7 @@ - #include - #include - #include -+#include - #include - #include - #include -@@ -84,8 +85,8 @@ connect_to_server(void) - static int32_t - check_response(int sd, char **srvmsg); - --static void --check_cmd_version(int sd, uint32_t command, char *name, int32_t version) -+static int -+check_cmd_version(int sd, uint32_t command, char *name, int32_t version, bool do_exit) - { - struct msghdr msg; - struct iovec iov[1]; -@@ -104,7 +105,7 @@ check_cmd_version(int sd, uint32_t command, char *name, int32_t version) - ssize_t n; - n = sendmsg(sd, &msg, 0); - if (n < 0) { -- fprintf(stderr, "check-cmd-version: kill daemon failed: %m\n"); -+ fprintf(stderr, "check-cmd-version: sendmsg failed: %m\n"); - exit(1); - } - -@@ -120,11 +121,17 @@ check_cmd_version(int sd, uint32_t command, char *name, int32_t version) - - char *srvmsg = NULL; - int32_t rc = check_response(sd, &srvmsg); -- if (rc < 0) -+ -+ if (do_exit && rc < 0) - errx(1, "command \"%s\" not known by server", name); -- if (rc != version) -+ -+ if (do_exit && rc != version) - errx(1, "command \"%s\": client version %d, server version %d", - name, version, rc); -+ -+ if (rc < 0) -+ return rc; -+ return rc == version; - } - - static void -@@ -134,7 +141,7 @@ send_kill_daemon(int sd) - struct iovec iov; - pesignd_msghdr pm; - -- check_cmd_version(sd, CMD_KILL_DAEMON, "kill-daemon", 0); -+ check_cmd_version(sd, CMD_KILL_DAEMON, "kill-daemon", 0, true); - - pm.version = PESIGND_VERSION; - pm.command = CMD_KILL_DAEMON; -@@ -276,7 +283,7 @@ unlock_token(int sd, char *tokenname, char *pin) - - uint32_t size1 = pesignd_string_size(pin); - -- check_cmd_version(sd, CMD_UNLOCK_TOKEN, "unlock-token", 0); -+ check_cmd_version(sd, CMD_UNLOCK_TOKEN, "unlock-token", 0, true); - - pm.version = PESIGND_VERSION; - pm.command = CMD_UNLOCK_TOKEN; -@@ -353,7 +360,7 @@ is_token_unlocked(int sd, char *tokenname) - - uint32_t size0 = pesignd_string_size(tokenname); - -- check_cmd_version(sd, CMD_IS_TOKEN_UNLOCKED, "is-token-unlocked", 0); -+ check_cmd_version(sd, CMD_IS_TOKEN_UNLOCKED, "is-token-unlocked", 0, true); - - pm.version = PESIGND_VERSION; - pm.command = CMD_IS_TOKEN_UNLOCKED; -@@ -452,6 +459,9 @@ static void - sign(int sd, char *infile, char *outfile, char *tokenname, char *certname, - int attached, uint32_t format) - { -+ int rc; -+ bool add_file_type; -+ - int infd = open(infile, O_RDONLY); - if (infd < 0) { - fprintf(stderr, "pesign-client: could not open input file " -@@ -481,12 +491,28 @@ oom: - exit(1); - } - -- check_cmd_version(sd, attached ? CMD_SIGN_ATTACHED : CMD_SIGN_DETACHED, -- attached ? "sign-attached" : "sign-detached", 0); -+ rc = check_cmd_version(sd, -+ attached ? CMD_SIGN_ATTACHED_WITH_FILE_TYPE -+ : CMD_SIGN_DETACHED_WITH_FILE_TYPE, -+ attached ? "sign-attached" : "sign-detached", -+ 0, format == FORMAT_KERNEL_MODULE); -+ if (rc >= 0) { -+ add_file_type = true; -+ } else { -+ add_file_type = false; -+ check_cmd_version(sd, attached ? CMD_SIGN_ATTACHED -+ : CMD_SIGN_DETACHED, -+ attached ? "sign-attached" : "sign-detached", -+ 0, true); -+ } - -+ printf("add_file_type:%d\n", add_file_type); - pm->version = PESIGND_VERSION; -- pm->command = attached ? CMD_SIGN_ATTACHED : CMD_SIGN_DETACHED; -- pm->size = size0 + size1 + sizeof(format); -+ pm->command = attached ? (add_file_type ? CMD_SIGN_ATTACHED_WITH_FILE_TYPE -+ : CMD_SIGN_ATTACHED) -+ : (add_file_type ? CMD_SIGN_DETACHED_WITH_FILE_TYPE -+ : CMD_SIGN_DETACHED); -+ pm->size = size0 + size1 + (add_file_type ? sizeof(format) : 0); - iov[0].iov_base = pm; - iov[0].iov_len = sizeof (*pm); - -@@ -503,25 +529,31 @@ oom: - } - - char *buffer; -- buffer = malloc(size0 + size1); -+ buffer = malloc(pm->size); - if (!buffer) - goto oom; - -- iov[0].iov_base = &format; -- iov[0].iov_len = sizeof(format); -+ int pos = 0; -+ -+ if (add_file_type) { -+ iov[pos].iov_base = &format; -+ iov[pos].iov_len = sizeof(format); -+ pos++; -+ } - - pesignd_string *tn = (pesignd_string *)buffer; - pesignd_string_set(tn, tokenname); -- iov[1].iov_base = tn; -- iov[1].iov_len = size0; -+ iov[pos].iov_base = tn; -+ iov[pos].iov_len = size0; -+ pos++; - - pesignd_string *cn = pesignd_string_next(tn); - pesignd_string_set(cn, certname); -- iov[2].iov_base = cn; -- iov[2].iov_len = size1; -+ iov[pos].iov_base = cn; -+ iov[pos].iov_len = size1; - - msg.msg_iov = iov; -- msg.msg_iovlen = 3; -+ msg.msg_iovlen = add_file_type ? 3 : 2; - - n = sendmsg(sd, &msg, 0); - if (n < 0) { -@@ -535,7 +567,7 @@ oom: - send_fd(sd, outfd); - - char *srvmsg = NULL; -- int rc = check_response(sd, &srvmsg); -+ rc = check_response(sd, &srvmsg); - if (rc < 0) { - fprintf(stderr, "pesign-client: signing failed: \"%s\"\n", - srvmsg); -diff --git a/src/daemon.c b/src/daemon.c -index 9374d59be30..494beb9af72 100644 ---- a/src/daemon.c -+++ b/src/daemon.c -@@ -12,6 +12,7 @@ - #include - #include - #include -+#include - #include - #include - #include -@@ -561,7 +562,7 @@ out: - - static void - handle_signing(context *ctx, struct pollfd *pollfd, socklen_t size, -- int attached) -+ int attached, bool with_file_type) - { - struct msghdr msg; - struct iovec iov; -@@ -585,8 +586,12 @@ oom: - - n = recvmsg(pollfd->fd, &msg, MSG_WAITALL); - -- file_format = *((uint32_t *) buffer); -- n -= sizeof(uint32_t); -+ if (with_file_type) { -+ file_format = *((uint32_t *) buffer); -+ n -= sizeof(uint32_t); -+ } else { -+ file_format = FORMAT_PE_BINARY; -+ } - - pesignd_string *tn = (pesignd_string *)(buffer + sizeof(uint32_t)); - if (n < (long long)sizeof(tn->size)) { -@@ -666,34 +671,44 @@ finish: - teardown_digests(ctx->cms); - } - -+static inline void -+handle_sign_helper(context *ctx, struct pollfd *pollfd, socklen_t size, -+ int attached, bool with_file_type) -+{ -+ int rc = cms_context_alloc(&ctx->cms); -+ if (rc < 0) -+ return; -+ -+ steal_from_cms(ctx->backup_cms, ctx->cms); -+ -+ handle_signing(ctx, pollfd, size, attached, with_file_type); -+ -+ hide_stolen_goods_from_cms(ctx->cms, ctx->backup_cms); -+ cms_context_fini(ctx->cms); -+} -+ - static void - handle_sign_attached(context *ctx, struct pollfd *pollfd, socklen_t size) - { -- int rc = cms_context_alloc(&ctx->cms); -- if (rc < 0) -- return; -+ handle_sign_helper(ctx, pollfd, size, 1, false); -+} - -- steal_from_cms(ctx->backup_cms, ctx->cms); -- -- handle_signing(ctx, pollfd, size, 1); -- -- hide_stolen_goods_from_cms(ctx->cms, ctx->backup_cms); -- cms_context_fini(ctx->cms); -+static void -+handle_sign_attached_with_file_type(context *ctx, struct pollfd *pollfd, socklen_t size) -+{ -+ handle_sign_helper(ctx, pollfd, size, 1, true); - } - - static void - handle_sign_detached(context *ctx, struct pollfd *pollfd, socklen_t size) - { -- int rc = cms_context_alloc(&ctx->cms); -- if (rc < 0) -- return; -+ handle_sign_helper(ctx, pollfd, size, 0, false); -+} - -- steal_from_cms(ctx->backup_cms, ctx->cms); -- -- handle_signing(ctx, pollfd, size, 0); -- -- hide_stolen_goods_from_cms(ctx->cms, ctx->backup_cms); -- cms_context_fini(ctx->cms); -+static void -+handle_sign_detached_with_file_type(context *ctx, struct pollfd *pollfd, socklen_t size) -+{ -+ handle_sign_helper(ctx, pollfd, size, 0, true); - } - - static void -@@ -725,6 +740,12 @@ cmd_table_t cmd_table[] = { - { CMD_UNLOCK_TOKEN, handle_unlock_token, "unlock-token", 0 }, - { CMD_SIGN_ATTACHED, handle_sign_attached, "sign-attached", 0 }, - { CMD_SIGN_DETACHED, handle_sign_detached, "sign-detached", 0 }, -+ { CMD_SIGN_ATTACHED_WITH_FILE_TYPE, -+ handle_sign_attached_with_file_type, -+ "sign-attached-with-file-type", 0 }, -+ { CMD_SIGN_DETACHED_WITH_FILE_TYPE, -+ handle_sign_detached_with_file_type, -+ "sign-detached-with-file-type", 0 }, - { CMD_RESPONSE, NULL, "response", 0 }, - { CMD_IS_TOKEN_UNLOCKED, handle_is_token_unlocked, - "is-token-unlocked", 0 }, -diff --git a/src/daemon.h b/src/daemon.h -index dd430512f1a..834d62c72d0 100644 ---- a/src/daemon.h -+++ b/src/daemon.h -@@ -33,6 +33,8 @@ typedef enum { - CMD_RESPONSE, - CMD_IS_TOKEN_UNLOCKED, - CMD_GET_CMD_VERSION, -+ CMD_SIGN_ATTACHED_WITH_FILE_TYPE, -+ CMD_SIGN_DETACHED_WITH_FILE_TYPE, - CMD_LIST_END - } pesignd_cmd; - --- -2.26.2 - diff --git a/0004-Rename-var-run-to-run.patch b/0004-Rename-var-run-to-run.patch deleted file mode 100644 index 593761b..0000000 --- a/0004-Rename-var-run-to-run.patch +++ /dev/null @@ -1,46 +0,0 @@ -From f886b7088dfea224e28c03b097c85c9bc20f5441 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Fri, 12 Jun 2020 11:49:44 -0400 -Subject: [PATCH] Rename /var/run/ to /run/ - -Signed-off-by: Peter Jones ---- - src/macros.pesign | 12 ++++++------ - src/tmpfiles.conf | 2 +- - 2 files changed, 7 insertions(+), 7 deletions(-) - -diff --git a/src/macros.pesign b/src/macros.pesign -index 56f75cafbc4..5a6da1c6809 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -45,14 +45,14 @@ - rm -rf ${sattrs} ${sattrs}.sig ${nss} \ - elif [ "$(id -un)" == "kojibuilder" -a \\\ - grep -q ID=fedora /etc/os-release -a \\\ -- ! -S /var/run/pesign/socket ]; then \ -+ ! -S /run/pesign/socket ]; then \ - echo "No socket even though this is kojibuilder" 1>&2 \ -- ls -ld /var/run/pesign 1>&2 \ -- ls -l /var/run/pesign/socket 1>&2 \ -- getfacl /var/run/pesign 1>&2 \ -- getfacl /var/run/pesign/socket 1>&2 \ -+ ls -ld /run/pesign 1>&2 \ -+ ls -l /run/pesign/socket 1>&2 \ -+ getfacl /run/pesign 1>&2 \ -+ getfacl /run/pesign/socket 1>&2 \ - exit 1 \ -- elif [ -S /var/run/pesign/socket ]; then \ -+ elif [ -S /run/pesign/socket ]; then \ - %{_pesign_client} -t %{__pesign_client_token} \\\ - -c %{__pesign_client_cert} \\\ - %{-i} %{-o} %{-e} %{-s} %{-C} \ -diff --git a/src/tmpfiles.conf b/src/tmpfiles.conf -index c1cf35597d8..3375ad52a44 100644 ---- a/src/tmpfiles.conf -+++ b/src/tmpfiles.conf -@@ -1 +1 @@ --D /var/run/pesign 0770 pesign pesign - -+D /run/pesign 0770 pesign pesign - --- -2.26.2 - diff --git a/0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch b/0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch deleted file mode 100644 index 2b47880..0000000 --- a/0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch +++ /dev/null @@ -1,30 +0,0 @@ -From 56eaa15e986d808c670381ca375216eb3abd1588 Mon Sep 17 00:00:00 2001 -From: Jeremy Cline -Date: Tue, 18 Feb 2020 16:37:53 -0500 -Subject: [PATCH] Apparently opensc got updated and the token name changed - -All the kernel builds started failing yesterday because the signing -token could not be found. Update the token name in the macro shipped by -pesign. - -Signed-off-by: Peter Jones ---- - src/macros.pesign | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/macros.pesign b/src/macros.pesign -index 7c5cba170e9..56f75cafbc4 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -9,7 +9,7 @@ - %__pesign_token %{nil}%{?pe_signing_token:-t "%{pe_signing_token}"} - %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} - --%__pesign_client_token %{!?pe_signing_token:"Fedora Signer (OpenSC Card)"}%{?pe_signing_token:"%{pe_signing_token}"} -+%__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} - %__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} - - %_pesign /usr/bin/pesign --- -2.26.2 - diff --git a/0006-client-try-run-and-var-run-for-the-socket-path.patch b/0006-client-try-run-and-var-run-for-the-socket-path.patch deleted file mode 100644 index 337faab..0000000 --- a/0006-client-try-run-and-var-run-for-the-socket-path.patch +++ /dev/null @@ -1,86 +0,0 @@ -From c662ad097eaa0d8c3691a22254f5d0e9622b26b7 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 6 Jul 2020 16:13:09 -0400 -Subject: [PATCH 6/7] client: try /run and /var/run for the socket path. - -Signed-off-by: Peter Jones ---- - src/client.c | 40 +++++++++++++++++++++++++++++----------- - 1 file changed, 29 insertions(+), 11 deletions(-) - -diff --git a/src/client.c b/src/client.c -index 2119ef33bf8..a38383415d5 100644 ---- a/src/client.c -+++ b/src/client.c -@@ -49,24 +49,24 @@ print_flag_name(FILE *f, int flag) - } - - static int --connect_to_server(void) -+connect_to_server_helper(const char * const sockpath) - { -- int rc = access(SOCKPATH, R_OK); -+ int rc = access(sockpath, R_OK); - if (rc != 0) { -- fprintf(stderr, "pesign-client: could not connect to server: " -- "%m\n"); -- exit(1); -+ warn("could not access socket \"%s\"", sockpath); -+ return rc; - } - - struct sockaddr_un addr_un = { - .sun_family = AF_UNIX, -- .sun_path = SOCKPATH, - }; -+ strncpy(addr_un.sun_path, sockpath, sizeof(addr_un.sun_path)); -+ addr_un.sun_path[sizeof(addr_un.sun_path)-1] = '\0'; - - int sd = socket(AF_UNIX, SOCK_STREAM, 0); - if (sd < 0) { -- fprintf(stderr, "pesign-client: could not open socket: %m\n"); -- exit(1); -+ warn("could not open socket \"%s\"", sockpath); -+ return sd; - } - - socklen_t len = strlen(addr_un.sun_path) + -@@ -74,14 +74,32 @@ connect_to_server(void) - - rc = connect(sd, (struct sockaddr *)&addr_un, len); - if (rc < 0) { -- fprintf(stderr, "pesign-client: could not connect to daemon: " -- "%m\n"); -- exit(1); -+ warn("could not connect to daemon"); -+ return sd; - } - - return sd; - } - -+static int -+connect_to_server(void) -+{ -+ int rc, i; -+ const char * const sockets[] = { -+ "/run/pesign/socket", -+ "/var/run/pesign/socket", -+ NULL -+ }; -+ -+ for (i = 0; sockets[i] != NULL; i++) { -+ rc = connect_to_server_helper(sockets[i]); -+ if (rc >= 0) -+ return rc; -+ } -+ -+ exit(1); -+} -+ - static int32_t - check_response(int sd, char **srvmsg); - --- -2.26.2 - diff --git a/0007-client-remove-an-extra-debug-print.patch b/0007-client-remove-an-extra-debug-print.patch deleted file mode 100644 index b094ea5..0000000 --- a/0007-client-remove-an-extra-debug-print.patch +++ /dev/null @@ -1,25 +0,0 @@ -From ea81cec14d31cd0b0dbde5b42414bfae9daec9b8 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 14 Jul 2020 16:44:09 -0400 -Subject: [PATCH 07/11] client: remove an extra debug print - -Signed-off-by: Peter Jones ---- - src/client.c | 1 - - 1 file changed, 1 deletion(-) - -diff --git a/src/client.c b/src/client.c -index 0082be1f597..c9966295e5f 100644 ---- a/src/client.c -+++ b/src/client.c -@@ -536,7 +536,6 @@ oom: - 0, true); - } - -- printf("add_file_type:%d\n", add_file_type); - pm->version = PESIGND_VERSION; - pm->command = attached ? (add_file_type ? CMD_SIGN_ATTACHED_WITH_FILE_TYPE - : CMD_SIGN_ATTACHED) --- -2.26.2 - diff --git a/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch deleted file mode 100644 index 3a62cf6..0000000 --- a/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ /dev/null @@ -1,379 +0,0 @@ -From 6c16b978fd33f3611e9f7aaf4f9c44bce1679485 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 6 Jul 2020 13:54:35 -0400 -Subject: [PATCH] Move most of macros.pesign to pesign-rpmbuild-helper - -Signed-off-by: Peter Jones ---- - Make.defaults | 1 + - src/Makefile | 8 +- - src/macros.pesign | 74 ++++-------- - src/pesign-rpmbuild-helper.in | 222 ++++++++++++++++++++++++++++++++++ - 4 files changed, 252 insertions(+), 53 deletions(-) - create mode 100644 src/pesign-rpmbuild-helper.in - -diff --git a/Make.defaults b/Make.defaults -index 0bacafe0d01..d4cd626c11e 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -16,6 +16,7 @@ INSTALLROOT = $(DESTDIR) - - INSTALL ?= install - CROSS_COMPILE ?= -+EFI_ARCHES ?= aa64 ia32 x64 - - PKG_CONFIG = $(CROSS_COMPILE)pkg-config - CC := $(if $(filter default,$(origin CC)),$(CROSS_COMPILE)gcc,$(CC)) -diff --git a/src/Makefile b/src/Makefile -index 74327ba13f3..a7ca89159c6 100644 ---- a/src/Makefile -+++ b/src/Makefile -@@ -5,7 +5,7 @@ include $(TOPDIR)/Make.version - include $(TOPDIR)/Make.rules - include $(TOPDIR)/Make.defaults - --BINTARGETS=authvar client efikeygen efisiglist pesigcheck pesign -+BINTARGETS=authvar client efikeygen efisiglist pesigcheck pesign pesign-rpmbuild-helper - SVCTARGETS=pesign.sysvinit pesign.service - TARGETS=$(BINTARGETS) $(SVCTARGETS) - -@@ -49,6 +49,11 @@ pesign : $(call objects-of,$(PESIGN_SOURCES) $(COMMON_SOURCES) $(COMMON_PE_SOURC - pesign : LDLIBS+=$(TOPDIR)/libdpe/libdpe.a - pesign : PKGS=efivar nss nspr popt - -+pesign-rpmbuild-helper: pesign-rpmbuild-helper.in -+ sed \ -+ -e "s/@@EFI_ARCHES@@/$(EFI_ARCHES)/g" \ -+ $^ > $@ -+ - deps : PKGS=efivar nss nspr popt uuid - deps : $(ALL_SOURCES) - $(MAKE) -f $(TOPDIR)/Make.deps \ -@@ -94,6 +99,7 @@ install : - $(INSTALL) -m 644 macros.pesign $(INSTALLROOT)/etc/rpm/ - $(INSTALL) -d -m 755 $(INSTALLROOT)$(libexecdir)/pesign/ - $(INSTALL) -m 750 pesign-authorize $(INSTALLROOT)$(libexecdir)/pesign/ -+ $(INSTALL) -m 755 pesign-rpmbuild-helper $(INSTALLROOT)$(libexecdir)/pesign/ - $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pesign - $(INSTALL) -m 600 pesign-users $(INSTALLROOT)/etc/pesign/users - $(INSTALL) -m 600 pesign-groups $(INSTALLROOT)/etc/pesign/groups -diff --git a/src/macros.pesign b/src/macros.pesign -index 5a6da1c6809..2e984b4eeb3 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -6,7 +6,7 @@ - # %pesign -s -i shim.orig -o shim.efi - # And magically get the right thing. - --%__pesign_token %{nil}%{?pe_signing_token:-t "%{pe_signing_token}"} -+%__pesign_token %{nil}%{?pe_signing_token:--token "%{pe_signing_token}"} - %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} - - %__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} -@@ -24,54 +24,24 @@ - # -a # rhel only - # -s # perform signing - %pesign(i:o:C:e:c:n:a:s) \ -- _pesign_nssdir=/etc/pki/pesign \ -- if [ %{__pesign_cert} = "Red Hat Test Certificate" ]; then \ -- _pesign_nssdir=/etc/pki/pesign-rh-test \ -- fi \ -- if [ -x %{_pesign} ] && \\\ -- [ "%{_target_cpu}" == "x86_64" -o \\\ -- "%{_target_cpu}" == "aarch64" ]; then \ -- if [ "0%{?rhel}" -ge "7" -a -f /usr/bin/rpm-sign ]; then \ -- nss=$(mktemp -p $PWD -d) \ -- echo > ${nss}/pwfile \ -- certutil -N -d ${nss} -f ${nss}/pwfile \ -- certutil -A -n "ca" -t "CT,C," -i %{-a*} -d ${nss} \ -- certutil -A -n "signer" -t ",c," -i %{-c*} -d ${nss} \ -- sattrs=$(mktemp -p $PWD --suffix=.der) \ -- %{_pesign} %{-i} -E ${sattrs} --certdir ${nss} --force \ -- rpm-sign --key "%{-n*}" --rsadgstsign ${sattrs} \ -- %{_pesign} -R ${sattrs}.sig -I ${sattrs} %{-i} \\\ -- --certdir ${nss} -c signer %{-o} \ -- rm -rf ${sattrs} ${sattrs}.sig ${nss} \ -- elif [ "$(id -un)" == "kojibuilder" -a \\\ -- grep -q ID=fedora /etc/os-release -a \\\ -- ! -S /run/pesign/socket ]; then \ -- echo "No socket even though this is kojibuilder" 1>&2 \ -- ls -ld /run/pesign 1>&2 \ -- ls -l /run/pesign/socket 1>&2 \ -- getfacl /run/pesign 1>&2 \ -- getfacl /run/pesign/socket 1>&2 \ -- exit 1 \ -- elif [ -S /run/pesign/socket ]; then \ -- %{_pesign_client} -t %{__pesign_client_token} \\\ -- -c %{__pesign_client_cert} \\\ -- %{-i} %{-o} %{-e} %{-s} %{-C} \ -- else \ -- %{_pesign} %{__pesign_token} -c %{__pesign_cert} \\\ -- --certdir ${_pesign_nssdir} \\\ -- %{-i} %{-o} %{-e} %{-s} %{-C} \ -- fi \ -- else \ -- if [ -n "%{-i*}" -a -n "%{-o*}" ]; then \ -- mv %{-i*} %{-o*} \ -- elif [ -n "%{-i*}" -a -n "%{-e*}" ]; then \ -- touch %{-e*} \ -- fi \ -- fi \ -- if [ ! -s %{-o} ]; then \ -- if [ -e "%{-o*}" ]; then \ -- rm -f %{-o*} \ -- fi \ -- exit 1 \ -- fi ; -- -+ %{_libexecdir}/pesign/pesign-rpmbuild-helper \\\ -+ "%{_target_cpu}" \\\ -+ "%{_pesign}" \\\ -+ "%{_pesign_client}" \\\ -+ %{?__pesign_client_token:--client-token %{__pesign_client_token}} \\\ -+ %{?__pesign_client_cert:--client-cert %{__pesign_client_cert}} \\\ -+ %{?__pesign_token:%{__pesign_token}} \\\ -+ %{?__pesign_cert:--cert %{__pesign_cert}} \\\ -+ %{?_buildhost:--hostname "%{_buildhost}"} \\\ -+ %{?vendor:--vendor "%{vendor}"} \\\ -+ %{?_rhel:--rhelver "%{_rhel}"} \\\ -+ %{?-n:--rhelcert %{-n*}}%{?!-n:--rhelcert %{__pesign_cert}} \\\ -+ %{?-a:--rhelcafile "%{-a*}"} \\\ -+ %{?-c:--rhelcertfile "%{-c*}"} \\\ -+ %{?-C:--certout "%{-C*}"} \\\ -+ %{?-e:--sattrout "%{-e*}"} \\\ -+ %{?-i:--in "%{-i*}"} \\\ -+ %{?-o:--out "%{-o*}"} \\\ -+ %{?-s:--sign} \\\ -+ ; \ -+%{nil} -diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in -new file mode 100644 -index 00000000000..c5287c27e0c ---- /dev/null -+++ b/src/pesign-rpmbuild-helper.in -@@ -0,0 +1,222 @@ -+#!/bin/bash -+# shellcheck shell=bash -+ -+set -eu -+set -x -+ -+usage() { -+ local status="${1}" && shift -+ local out -+ if [[ "${status}" -eq 0 ]] ; then -+ out=/dev/stdout -+ else -+ out=/dev/stderr -+ fi -+ -+ if [[ $# -gt 0 ]] ; then -+ echo "${0}: error: $*" >>"${out}" -+ fi -+ echo "usage: ${0} TARGET_CPU PESIGN_BINARY PESIGN_CLIENT_BINARY [OPTIONS]" >>"${out}" -+ exit "${status}" -+} -+ -+is_efi_arch() { -+ local arch="${1}" -+ local arches=(@@EFI_ARCHES@@) -+ local x -+ for x in "${arches[@]}" ; do -+ if [[ "${arch}" = "${x}" ]] ; then -+ return 0 -+ fi -+ done -+ return 1 -+} -+ -+error_on_empty() { -+ local f="${1}" -+ if [[ ! -s "${f}" ]] ; then -+ if [[ -e "${f}" ]] ; then -+ rm -f "${f}" -+ fi -+ echo "${0}: error: empty result file \"${f}\"">>/dev/stderr -+ exit 1 -+ fi -+} -+ -+main() { -+ if [[ $# -lt 3 ]] ; then -+ usage 1 not enough arguments -+ fi -+ local target_cpu="${1}" && shift -+ local bin="${1}" && shift -+ local client="${1}" && shift -+ -+ local rhelcafile="" || : -+ local rhelcertfile="" || : -+ -+ local certout=() || : -+ local sattrout=() || : -+ local input=() || : -+ local output=() || : -+ local client_token=() || : -+ local client_cert=() || : -+ local token=() || : -+ local cert=() || : -+ local rhelcert=() || : -+ local rhelver=0 || : -+ local sign="" || : -+ local arch="" || : -+ local vendor="" || : -+ local HOSTNAME="" || : -+ -+ while [[ $# -ge 2 ]] ; do -+ case " ${1} " in -+ " --rhelcafile ") -+ rhelcafile="${2}" -+ ;; -+ " --rhelcertfile ") -+ rhelcertfile="${2}" -+ ;; -+ " --hostname ") -+ HOSTNAME="${2}" -+ ;; -+ " --certout ") -+ certout[0]=-C -+ certout[1]="${2}" -+ ;; -+ " --sattrout ") -+ sattrout[0]=-e -+ sattrout[1]="${2}" -+ ;; -+ " --client-token ") -+ client_token[0]=-t -+ client_token[1]="${2}" -+ ;; -+ " --client-cert ") -+ client_cert[0]=-c -+ client_cert[1]="${2}" -+ ;; -+ " --token ") -+ token[0]=-t -+ token[1]="${2}" -+ ;; -+ " --cert ") -+ cert[0]=-c -+ cert[1]="${2}" -+ ;; -+ " --rhelcert ") -+ rhelcert[0]=-c -+ rhelcert[1]="${2}" -+ ;; -+ " --in ") -+ input[0]=-i -+ input[1]="${2}" -+ ;; -+ " --out ") -+ output[0]=-o -+ output[1]="${2}" -+ ;; -+ " --rhelver ") -+ rhelver="${2}" -+ ;; -+ " --vendor ") -+ vendor="${2}" -+ ;; -+ *) -+ break -+ ;; -+ esac -+ shift -+ shift -+ done -+ if [[ $# -ge 1 ]] && [[ "${1}" = --sign ]] ; then -+ sign=-s -+ shift -+ fi -+ -+ if [[ -z "${target_cpu}" ]] ; then -+ target_cpu="$(uname -m)" -+ fi -+ -+ target_cpu="${target_cpu/i?86/ia32}" -+ target_cpu="${target_cpu/x86_64/x64}" -+ target_cpu="${target_cpu/aarch64/aa64}" -+ target_cpu="${target_cpu/arm*/arm/}" -+ -+ local nssdir=/etc/pki/pesign -+ if [[ "${#cert[@]}" -eq 2 ]] && -+ [[ "${cert[1]}" == "Red Hat Test Certificate" ]] ; then -+ nssdir=/etc/pki/pesign-rh-test -+ fi -+ -+ # is_efi_arch is ultimately returning "is pesign configured to sign these -+ # using the rpm macro", so if it isn't, we're just copying the input to -+ # the output -+ if [[ -x "${bin}" ]] && ! is_efi_arch "${target_cpu}" ; then -+ if [[ -n "${input[*]}" ]] && [[ -n "${output[*]}" ]] ; then -+ cp -v "${input[1]}" "${output[1]}" -+ elif [[ -n "${input[*]}" ]] && [[ -n "${sattrout[*]}" ]] ; then -+ touch "${sattrout[1]}" -+ fi -+ -+ # if there's a 0-sized output file, delete it and error out -+ error_on_empty "${output[1]}" -+ return 0 -+ fi -+ -+ USERNAME="${USERNAME:-$(id -un)}" -+ -+ local socket="" || : -+ if grep -q ID=fedora /etc/os-release \ -+ && [[ "${rhelver}" -lt 7 ]] \ -+ && [[ "${USERNAME}" = "mockbuild" ]] \ -+ && [[ "${vendor}" = "Fedora Project" ]] \ -+ && [[ "${HOSTNAME}" =~ bkernel.* ]] -+ then -+ if [[ -S /run/pesign/socket ]] ; then -+ socket=/run/pesign/socket -+ elif [[ -S /var/run/pesign/socket ]]; then -+ socket=/var/run/pesign/socket -+ else -+ echo "Warning: no pesign socket even though user is ${USERNAME}" 1>&2 -+ echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 -+ ls -ld /run/pesign /var/run/pesign 1>&2 ||: -+ ls -l /run/pesign/socket /var/run/pesign/socket 1>&2 ||: -+ getfacl /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: -+ getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: -+ fi -+ fi -+ -+ if [[ "${rhelver}" -ge 7 ]] ; then -+ nssdir="$(mktemp -p "${PWD}" -d)" -+ echo > "${nssdir}/pwfile" -+ certutil -N -d "${nssdir}" -f "${nssdir}/pwfile" -+ certutil -A -n "ca" -t "CTu,CTu,CTu" -i "${rhelcafile}" -d "${nssdir}" -+ certutil -A -n "signer" -t "CTu,CTu,CTu" -i "${rhelcertfile}" -d "${nssdir}" -+ sattrs="$(mktemp -p "${PWD}" --suffix=.der)" -+ "${bin}" -E "${sattrs}" --certdir "${nssdir}" \ -+ "${input[@]}" --force -+ rpm-sign --key "${rhelcert[1]}" --rsadgstsign "${sattrs}" -+ "${bin}" -R "${sattrs}.sig" -I "${sattrs}" \ -+ --certdir "${nssdir}" -c signer \ -+ "${input[@]}" "${output[@]}" -+ rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" -+ elif [[ -n "${socket}" ]] ; then -+ "${client}" "${client_token[@]}" "${client_cert[@]}" \ -+ "${sattrout[@]}" "${certout[@]}" \ -+ ${sign} "${input[@]}" "${output[@]}" -+ else -+ "${bin}" --certdir "${nssdir}" "${token[@]}" \ -+ "${cert[@]}" ${sign} "${sattrout[@]}" \ -+ "${certout[@]}" "${input[@]}" "${output[@]}" -+ fi -+ -+ # if there's a 0-sized output file, delete it and error out -+ if [[ "${#output[@]}" -eq 2 ]] ; then -+ error_on_empty "${output[1]}" -+ fi -+} -+ -+main "${@}" -+ -+# vim:filetype=sh:fenc=utf-8:tw=78:sts=4:sw=4 --- -2.26.2 - diff --git a/0009-pesign-authorize-shellcheck.patch b/0009-pesign-authorize-shellcheck.patch deleted file mode 100644 index 3597f5f..0000000 --- a/0009-pesign-authorize-shellcheck.patch +++ /dev/null @@ -1,60 +0,0 @@ -From 3107894285164a3d25ca215a76593ebb6d4bc84c Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 14 Jul 2020 15:07:32 -0400 -Subject: [PATCH 09/11] pesign-authorize: shellcheck - -Signed-off-by: Peter Jones ---- - src/pesign-authorize | 16 ++++++++-------- - 1 file changed, 8 insertions(+), 8 deletions(-) - -diff --git a/src/pesign-authorize b/src/pesign-authorize -index a496f601ab4..55cd5c4e55b 100755 ---- a/src/pesign-authorize -+++ b/src/pesign-authorize -@@ -12,21 +12,21 @@ set -u - # License: GPLv2 - declare -a fileusers=() - declare -a dirusers=() --for user in $(cat /etc/pesign/users); do -+while read -r user ; do - dirusers[${#dirusers[@]}]=-m - dirusers[${#dirusers[@]}]="u:$user:rwx" - fileusers[${#fileusers[@]}]=-m - fileusers[${#fileusers[@]}]="u:$user:rw" --done -+done -Date: Tue, 14 Jul 2020 15:08:15 -0400 -Subject: [PATCH 10/11] pesign-authorize: don't setfacl /etc/pki/pesign-foo/ - -Signed-off-by: Peter Jones ---- - src/pesign-authorize | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/pesign-authorize b/src/pesign-authorize -index 55cd5c4e55b..c5448329c2c 100755 ---- a/src/pesign-authorize -+++ b/src/pesign-authorize -@@ -47,7 +47,7 @@ update_subdir() { - done - } - --for x in /var/run/pesign/ /etc/pki/pesign*/ ; do -+for x in /var/run/pesign/ /etc/pki/pesign/ ; do - if [ -d "${x}" ]; then - update_subdir "${x}" - else --- -2.26.2 - diff --git a/0011-kernel-building-hack.patch b/0011-kernel-building-hack.patch deleted file mode 100644 index 69ffc56..0000000 --- a/0011-kernel-building-hack.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 0b9048cbcc1cfc2afd9cbf781732882736cbe965 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 14 Jul 2020 16:42:39 -0400 -Subject: [PATCH 11/11] kernel building hack - -Signed-off-by: Peter Jones ---- - src/pesign-rpmbuild-helper.in | 17 +++++++++++++++++ - 1 file changed, 17 insertions(+) - -diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in -index c5287c27e0c..27b8261bc17 100644 ---- a/src/pesign-rpmbuild-helper.in -+++ b/src/pesign-rpmbuild-helper.in -@@ -202,6 +202,23 @@ main() { - "${input[@]}" "${output[@]}" - rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" - elif [[ -n "${socket}" ]] ; then -+ ### welcome haaaaack city -+ if [[ "${client_token[1]}" = "OpenSC Card (Fedora Signer)" ]] ; then -+ if [[ "${input[1]}" =~ (/|^)vmlinuz($|[_.-]) ]] \ -+ || [[ "${input[1]}" =~ (/|^)bzImage($|[_.-]) ]] ; then -+ if [[ "${rhelcertfile}" =~ redhatsecureboot501.* ]] \ -+ || [[ "${rhelcertfile}" =~ redhatsecureboot401.* ]] \ -+ || [[ "${rhelcertfile}" =~ centossecureboot201.* ]] ; then -+ client_cert[1]=kernel-signer -+ elif [[ "${rhelcertfile}" =~ redhatsecureboot502.* ]] \ -+ || [[ "${rhelcertfile}" =~ centossecureboot202.* ]] ; then -+ client_cert[1]=grub2-signer -+ elif [[ "${rhelcertfile}" =~ redhatsecureboot503.* ]] \ -+ || [[ "${rhelcertfile}" =~ centossecureboot203.* ]] ; then -+ client_cert[1]=fwupd-signer -+ fi -+ fi -+ fi - "${client}" "${client_token[@]}" "${client_cert[@]}" \ - "${sattrout[@]}" "${certout[@]}" \ - ${sign} "${input[@]}" "${output[@]}" --- -2.26.2 - diff --git a/0012-Use-run-not-var-run.patch b/0012-Use-run-not-var-run.patch deleted file mode 100644 index 1b4e0c6..0000000 --- a/0012-Use-run-not-var-run.patch +++ /dev/null @@ -1,105 +0,0 @@ -From db4c6e8cc57271dce6d204a3144982e544e55025 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Thu, 16 Jul 2020 16:28:26 -0400 -Subject: [PATCH] Use /run not /var/run - -Signed-off-by: Peter Jones ---- - src/daemon.h | 4 ++-- - src/Makefile | 2 +- - src/pesign-authorize | 2 +- - src/pesign.service.in | 2 +- - src/pesign.sysvinit.in | 10 +++++----- - 5 files changed, 10 insertions(+), 10 deletions(-) - -diff --git a/src/daemon.h b/src/daemon.h -index 0368dc9256c..5fcd97ea717 100644 ---- a/src/daemon.h -+++ b/src/daemon.h -@@ -51,8 +51,8 @@ typedef enum { - } pesignd_cmd; - - #define PESIGND_VERSION 0x2a9edaf0 --#define SOCKPATH "/var/run/pesign/socket" --#define PIDFILE "/var/run/pesign.pid" -+#define SOCKPATH "/run/pesign/socket" -+#define PIDFILE "/run/pesign.pid" - - static inline uint32_t UNUSED - pesignd_string_size(char *buffer) -diff --git a/src/Makefile b/src/Makefile -index a7ca89159c6..f7fb5fc9ee5 100644 ---- a/src/Makefile -+++ b/src/Makefile -@@ -78,7 +78,7 @@ install_sysvinit: pesign.sysvinit - install : - $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign/ - $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign-rh-test/ -- $(INSTALL) -d -m 770 $(INSTALLROOT)/var/run/pesign/ -+ $(INSTALL) -d -m 770 $(INSTALLROOT)/run/pesign/ - $(INSTALL) -d -m 755 $(INSTALLROOT)$(bindir) - $(INSTALL) -m 755 authvar $(INSTALLROOT)$(bindir) - $(INSTALL) -m 755 pesign $(INSTALLROOT)$(bindir) -diff --git a/src/pesign-authorize b/src/pesign-authorize -index c5448329c2c..2381302440c 100755 ---- a/src/pesign-authorize -+++ b/src/pesign-authorize -@@ -47,7 +47,7 @@ update_subdir() { - done - } - --for x in /var/run/pesign/ /etc/pki/pesign/ ; do -+for x in /run/pesign/ /var/run/pesign/ /etc/pki/pesign/ ; do - if [ -d "${x}" ]; then - update_subdir "${x}" - else -diff --git a/src/pesign.service.in b/src/pesign.service.in -index c75a000892a..4ac2199bce2 100644 ---- a/src/pesign.service.in -+++ b/src/pesign.service.in -@@ -4,6 +4,6 @@ Description=Pesign signing daemon - [Service] - PrivateTmp=true - Type=forking --PIDFile=/var/run/pesign.pid -+PIDFile=/run/pesign.pid - ExecStart=/usr/bin/pesign --daemonize - ExecStartPost=@@LIBEXECDIR@@/pesign/pesign-authorize -diff --git a/src/pesign.sysvinit.in b/src/pesign.sysvinit.in -index b0e0f84ff0b..bf8edec8ff3 100644 ---- a/src/pesign.sysvinit.in -+++ b/src/pesign.sysvinit.in -@@ -4,7 +4,7 @@ - # - # chkconfig: - 50 50 - # processname: /usr/bin/pesign --# pidfile: /var/run/pesign.pid -+# pidfile: /run/pesign.pid - ### BEGIN INIT INFO - # Provides: pesign - # Default-Start: -@@ -20,9 +20,9 @@ RETVAL=0 - - start(){ - echo -n "Starting pesign: " -- mkdir /var/run/pesign 2>/dev/null && -- chown pesign:pesign /var/run/pesign && -- chmod 0770 /var/run/pesign -+ mkdir /run/pesign 2>/dev/null && -+ chown pesign:pesign /run/pesign && -+ chmod 0770 /run/pesign - daemon /usr/bin/pesign --daemonize - RETVAL=$? - echo -@@ -32,7 +32,7 @@ start(){ - - stop(){ - echo -n "Stopping pesign: " -- killproc -p /var/run/pesign.pid pesignd -+ killproc -p /run/pesign.pid pesignd - RETVAL=$? - echo - rm -f /var/lock/subsys/pesign --- -2.26.2 - diff --git a/0013-Turn-off-free-nonheap-object.patch b/0013-Turn-off-free-nonheap-object.patch deleted file mode 100644 index 3e62bd8..0000000 --- a/0013-Turn-off-free-nonheap-object.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 59428daf4863f192419eee4afec15cd099e99c9b Mon Sep 17 00:00:00 2001 -From: Jeff Law -Date: Mon, 16 Nov 2020 12:07:59 -0700 -Subject: [PATCH] Turn off -Wfree-nonheap-object - -authvar.c has a call to free (tokenname) where tokenname is set to a string constant -and never changed. That triggers GCC to issue a diagnostic that the value should not -be passed to free. - -This is a false positive from GCC as the call is guarded by a suitable condition that -always happens to be false. But pesign is being built without optimization and thus -the condition and free call are not optimized away. - -This patch just disables the warning. A better solution would be to fix the sources -or build with the optimizer enabled. ---- - Make.defaults | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/Make.defaults b/Make.defaults -index d4cd626..705cc3a 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -40,7 +40,7 @@ gcc_cflags = -Wmaybe-uninitialized -grecord-gcc-switches -flto - cflags = $(CFLAGS) $(ARCH3264) \ - -Wall -Wextra -Wsign-compare -Wno-unused-result \ - -Wno-unused-function -Wno-missing-field-initializers \ -- -Werror -Wno-error=cpp \ -+ -Werror -Wno-error=cpp -Wno-free-nonheap-object \ - -std=gnu11 -fshort-wchar -fPIC -fno-strict-aliasing \ - -D_GNU_SOURCE -DCONFIG_$(ARCH) -I${TOPDIR}/include \ - $(if $(filter $(CC),clang),$(clang_cflags), ) \ --- -2.28.0 - diff --git a/pesign.spec b/pesign.spec index e688936..992b822 100644 --- a/pesign.spec +++ b/pesign.spec @@ -2,28 +2,29 @@ Name: pesign Summary: Signing utility for UEFI binaries -Version: 113 -Release: 18%{?dist} -License: GPLv2 +Version: 114 +Release: 1%{?dist} +License: GPL-2.0-only URL: https://github.com/rhboot/pesign Obsoletes: pesign-rh-test-certs <= 0.111-7 -BuildRequires: make +BuildRequires: efivar-devel >= 31-1 BuildRequires: gcc BuildRequires: git +BuildRequires: libuuid-devel +BuildRequires: make +BuildRequires: mandoc BuildRequires: nspr +BuildRequires: nspr-devel >= 4.9.2-1 BuildRequires: nss +BuildRequires: nss-devel >= 3.13.6-1 +BuildRequires: nss-tools BuildRequires: nss-util BuildRequires: popt-devel -BuildRequires: nss-tools -BuildRequires: nspr-devel >= 4.9.2-1 -BuildRequires: nss-devel >= 3.13.6-1 -BuildRequires: efivar-devel >= 31-1 -BuildRequires: libuuid-devel +BuildRequires: python3 +BuildRequires: python3-rpm-macros BuildRequires: tar BuildRequires: xz -BuildRequires: python3-rpm-macros -BuildRequires: python3 %if 0%{?rhel} >= 7 || 0%{?fedora} >= 17 BuildRequires: systemd-rpm-macros %endif @@ -43,20 +44,6 @@ Source0: https://github.com/rhboot/pesign/releases/download/%{version}/pesign-%{ Source1: certs.tar.xz Source2: pesign.py -Patch0001: 0001-efikeygen-Fix-the-build-with-nss-3.44.patch -Patch0002: 0002-pesigcheck-Fix-a-wrong-assignment.patch -Patch0003: 0003-Make-0.112-client-and-server-work-with-the-113-proto.patch -Patch0004: 0004-Rename-var-run-to-run.patch -Patch0005: 0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch -Patch0006: 0006-client-try-run-and-var-run-for-the-socket-path.patch -Patch0007: 0007-client-remove-an-extra-debug-print.patch -Patch0008: 0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch -Patch0009: 0009-pesign-authorize-shellcheck.patch -Patch0010: 0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch -Patch0011: 0011-kernel-building-hack.patch -Patch0012: 0012-Use-run-not-var-run.patch -Patch0013: 0013-Turn-off-free-nonheap-object.patch - %description This package contains the pesign utility for signing UEFI binaries as well as other associated tools. @@ -141,7 +128,6 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %doc README TODO %{_bindir}/authvar %{_bindir}/efikeygen -%{_bindir}/efisiglist %{_bindir}/pesigcheck %{_bindir}/pesign %{_bindir}/pesign-client @@ -168,6 +154,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Feb 01 2022 Robbie Harwood - 114-1 +- New upstream version (114) + * Fri Jan 21 2022 Fedora Release Engineering - 113-18 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild diff --git a/sources b/sources index d0199f7..3522848 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ SHA512 (certs.tar.xz) = ddac535c786d1a23074534323c4ce89f907d4f82b19c5d3a9c814b145fbac1599cd2386cf20c28d22aee7d5c4db441f052bab9ee655de756117a0a0bc99b525f -SHA512 (pesign-113.tar.bz2) = 89c5e33bf6ac8f8dc4b65192e5fd4bf1fea285106d1de2a6ea02a8c5090f2ec5976b1d80c60e57f74fa56dc25b174a4dd5682292db44ab9aeab69ea992dfef36 +SHA512 (pesign-114.tar.bz2) = 5465c002db6f59ab59799ec79504ed96662bc5da2310282d2e85fc1f03c938343d88927e764e595bf21c3501e599e529a4752281349097cdc74e616535179b3c From ed9353e1df400caadda12228ecbc534e4d6cb846 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 1 Feb 2022 22:38:47 +0000 Subject: [PATCH 43/70] Fix build for 32-bit arches Signed-off-by: Robbie Harwood --- ...Fix-format-strings-for-32-bit-arches.patch | 112 ++++++++++++++++++ pesign.spec | 2 + 2 files changed, 114 insertions(+) create mode 100644 0001-Fix-format-strings-for-32-bit-arches.patch diff --git a/0001-Fix-format-strings-for-32-bit-arches.patch b/0001-Fix-format-strings-for-32-bit-arches.patch new file mode 100644 index 0000000..2b71a0e --- /dev/null +++ b/0001-Fix-format-strings-for-32-bit-arches.patch @@ -0,0 +1,112 @@ +From 1f8d0985d59ed41e291398f937d32493898bd711 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 1 Feb 2022 17:37:14 -0500 +Subject: [PATCH] Fix format strings for 32-bit arches + +Sadly, in 2022, this remains a thing. + +Signed-off-by: Robbie Harwood +--- + src/cms_pe_common.c | 16 +++++++++------- + src/password.c | 7 ++++--- + 2 files changed, 13 insertions(+), 10 deletions(-) + +diff --git a/src/cms_pe_common.c b/src/cms_pe_common.c +index 964f0d9..3a3921b 100644 +--- a/src/cms_pe_common.c ++++ b/src/cms_pe_common.c +@@ -49,7 +49,7 @@ check_pointer_and_size(cms_context *cms, Pe *pe, void *ptr, size_t size) + + if (p + size > m + map_size) + cmsreterr(0, cms, +- "pointer %p is above mmap end at %p (%lu is %lu bytes past EOF at %lu)", ++ "pointer %p is above mmap end at %p (%lu is %lu bytes past EOF at %zu)", + (void *)((uintptr_t)p + size), + (void *)((uintptr_t)m + map_size), + p + size - m, +@@ -189,7 +189,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + if (!check_pointer_and_size(cms, pe, hash_base, hash_size)) + cmsgotoerr(error, cms, "PE header is invalid"); + dprintf("beginning of hash"); +- dprintf("digesting %lx + %lx", hash_base - map, hash_size); ++ dprintf("digesting %tx + %zx", hash_base - map, hash_size); + generate_digest_step(cms, hash_base, hash_size); + + /* 5. Skip over the image checksum +@@ -209,7 +209,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + cmsgotoerr(error, cms, "PE data directory is invalid"); + + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %lx + %lx", hash_base - map, hash_size); ++ dprintf("digesting %tx + %zx", hash_base - map, hash_size); + + /* 8. Skip over the crt dir + * 9. Hash everything up to the end of the image header. */ +@@ -222,7 +222,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + cmsgotoerr(error, cms, "PE relocations table is invalid"); + + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %lx + %lx", hash_base - map, hash_size); ++ dprintf("digesting %tx + %zx", hash_base - map, hash_size); + + /* 10. Set SUM_OF_BYTES_HASHED to the size of the header. */ + hashed_bytes = pe32opthdr ? pe32opthdr->header_size +@@ -265,7 +265,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + } + + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %lx + %lx", hash_base - map, hash_size); ++ dprintf("digesting %tx + %zx", hash_base - map, hash_size); + + hashed_bytes += hash_size; + } +@@ -285,10 +285,12 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + memset(tmp_array, '\0', tmp_size); + memcpy(tmp_array, hash_base, hash_size); + generate_digest_step(cms, tmp_array, tmp_size); +- dprintf("digesting %lx + %lx", (unsigned long)tmp_array, tmp_size); ++ dprintf("digesting %tx + %zx", (ptrdiff_t)tmp_array, ++ tmp_size); + } else { + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %lx + %lx", hash_base - map, hash_size); ++ dprintf("digesting %tx + %zx", hash_base - map, ++ hash_size); + } + } + dprintf("end of hash"); +diff --git a/src/password.c b/src/password.c +index 644f362..05add9a 100644 +--- a/src/password.c ++++ b/src/password.c +@@ -213,7 +213,7 @@ parse_pwfile_line(char *start, struct token_pass *tp) + dprintf("non-whitespace span is %zd", span); + + if (line[span] == '\0') { +- dprintf("returning %ld", (line + span) - start); ++ dprintf("returning %td", (line + span) - start); + return (line + span) - start; + } + line[span] = '\0'; +@@ -241,7 +241,7 @@ parse_pwfile_line(char *start, struct token_pass *tp) + dprintf("Setting token pass %p to { %p, %p }", tp, tp->token, tp->pass); + dprintf("token:\"%s\"", tp->token); + dprintf("pass:\"%s\"", tp->pass); +- dprintf("returning %ld", (line + span) - start); ++ dprintf("returning %td", (line + span) - start); + return (line + span) - start; + } + +@@ -330,7 +330,8 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) + if (c != '\0') + span++; + start += span; +- dprintf("start is file[%ld] == '\\x%02hhx'", start - file, start[0]); ++ dprintf("start is file[%td] == '\\x%02hhx'", start - file, ++ start[0]); + } + + qsort(phrases, nphrases, sizeof(struct token_pass), token_pass_cmp); +-- +2.34.1 + diff --git a/pesign.spec b/pesign.spec index 992b822..a42dddf 100644 --- a/pesign.spec +++ b/pesign.spec @@ -44,6 +44,8 @@ Source0: https://github.com/rhboot/pesign/releases/download/%{version}/pesign-%{ Source1: certs.tar.xz Source2: pesign.py +Patch0001: 0001-Fix-format-strings-for-32-bit-arches.patch + %description This package contains the pesign utility for signing UEFI binaries as well as other associated tools. From 534c97e8edb95c66a9c00f844c936ec3bed8df25 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 2 Feb 2022 21:11:44 +0000 Subject: [PATCH 44/70] Attempt to fix signing parsing by dropping pesign_args Signed-off-by: Robbie Harwood --- 0001-Revert-Move-license-to-GPLv3.patch | 969 ++++++++++++++++++ ...Fix-format-strings-for-32-bit-arches.patch | 4 +- 0003-macros-drop-_pesign_args.patch | 47 + pesign.spec | 9 +- 4 files changed, 1025 insertions(+), 4 deletions(-) create mode 100644 0001-Revert-Move-license-to-GPLv3.patch rename 0001-Fix-format-strings-for-32-bit-arches.patch => 0002-Fix-format-strings-for-32-bit-arches.patch (97%) create mode 100644 0003-macros-drop-_pesign_args.patch diff --git a/0001-Revert-Move-license-to-GPLv3.patch b/0001-Revert-Move-license-to-GPLv3.patch new file mode 100644 index 0000000..4b8931c --- /dev/null +++ b/0001-Revert-Move-license-to-GPLv3.patch @@ -0,0 +1,969 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Tue, 1 Feb 2022 15:04:30 -0500 +Subject: [PATCH 1/3] Revert "Move license to GPLv3+" + +This was done too soon. It's missing some pieces and we need buy-in on +a couple of source files. + +This reverts commit 735650258c7956525b7ecf4b67483d025f0500e8. +--- + COPYING | 881 +++++++++++++++++--------------------------------------- + 1 file changed, 272 insertions(+), 609 deletions(-) + +diff --git a/COPYING b/COPYING +index 4432540..d159169 100644 +--- a/COPYING ++++ b/COPYING +@@ -1,627 +1,285 @@ ++ GNU GENERAL PUBLIC LICENSE ++ Version 2, June 1991 + +- GNU GENERAL PUBLIC LICENSE +- Version 3, 29 June 2007 +- +- Copyright (C) 2007 Free Software Foundation, Inc. ++ Copyright (C) 1989, 1991 Free Software Foundation, Inc., ++ 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA + Everyone is permitted to copy and distribute verbatim copies + of this license document, but changing it is not allowed. + +- Preamble ++ Preamble + +- The GNU General Public License is a free, copyleft license for +-software and other kinds of works. +- +- The licenses for most software and other practical works are designed +-to take away your freedom to share and change the works. By contrast, +-the GNU General Public License is intended to guarantee your freedom to +-share and change all versions of a program--to make sure it remains free +-software for all its users. We, the Free Software Foundation, use the +-GNU General Public License for most of our software; it applies also to +-any other work released this way by its authors. You can apply it to ++ The licenses for most software are designed to take away your ++freedom to share and change it. By contrast, the GNU General Public ++License is intended to guarantee your freedom to share and change free ++software--to make sure the software is free for all its users. This ++General Public License applies to most of the Free Software ++Foundation's software and to any other program whose authors commit to ++using it. (Some other Free Software Foundation software is covered by ++the GNU Lesser General Public License instead.) You can apply it to + your programs, too. + + When we speak of free software, we are referring to freedom, not + price. Our General Public Licenses are designed to make sure that you + have the freedom to distribute copies of free software (and charge for +-them if you wish), that you receive source code or can get it if you +-want it, that you can change the software or use pieces of it in new +-free programs, and that you know you can do these things. ++this service if you wish), that you receive source code or can get it ++if you want it, that you can change the software or use pieces of it ++in new free programs; and that you know you can do these things. + +- To protect your rights, we need to prevent others from denying you +-these rights or asking you to surrender the rights. Therefore, you have +-certain responsibilities if you distribute copies of the software, or if +-you modify it: responsibilities to respect the freedom of others. ++ To protect your rights, we need to make restrictions that forbid ++anyone to deny you these rights or to ask you to surrender the rights. ++These restrictions translate to certain responsibilities for you if you ++distribute copies of the software, or if you modify it. + + For example, if you distribute copies of such a program, whether +-gratis or for a fee, you must pass on to the recipients the same +-freedoms that you received. You must make sure that they, too, receive +-or can get the source code. And you must show them these terms so they +-know their rights. ++gratis or for a fee, you must give the recipients all the rights that ++you have. You must make sure that they, too, receive or can get the ++source code. And you must show them these terms so they know their ++rights. + +- Developers that use the GNU GPL protect your rights with two steps: +-(1) assert copyright on the software, and (2) offer you this License +-giving you legal permission to copy, distribute and/or modify it. ++ We protect your rights with two steps: (1) copyright the software, and ++(2) offer you this license which gives you legal permission to copy, ++distribute and/or modify the software. + +- For the developers' and authors' protection, the GPL clearly explains +-that there is no warranty for this free software. For both users' and +-authors' sake, the GPL requires that modified versions be marked as +-changed, so that their problems will not be attributed erroneously to +-authors of previous versions. ++ Also, for each author's protection and ours, we want to make certain ++that everyone understands that there is no warranty for this free ++software. If the software is modified by someone else and passed on, we ++want its recipients to know that what they have is not the original, so ++that any problems introduced by others will not reflect on the original ++authors' reputations. + +- Some devices are designed to deny users access to install or run +-modified versions of the software inside them, although the manufacturer +-can do so. This is fundamentally incompatible with the aim of +-protecting users' freedom to change the software. The systematic +-pattern of such abuse occurs in the area of products for individuals to +-use, which is precisely where it is most unacceptable. Therefore, we +-have designed this version of the GPL to prohibit the practice for those +-products. If such problems arise substantially in other domains, we +-stand ready to extend this provision to those domains in future versions +-of the GPL, as needed to protect the freedom of users. +- +- Finally, every program is threatened constantly by software patents. +-States should not allow patents to restrict development and use of +-software on general-purpose computers, but in those that do, we wish to +-avoid the special danger that patents applied to a free program could +-make it effectively proprietary. To prevent this, the GPL assures that +-patents cannot be used to render the program non-free. ++ Finally, any free program is threatened constantly by software ++patents. We wish to avoid the danger that redistributors of a free ++program will individually obtain patent licenses, in effect making the ++program proprietary. To prevent this, we have made it clear that any ++patent must be licensed for everyone's free use or not licensed at all. + + The precise terms and conditions for copying, distribution and + modification follow. + +- TERMS AND CONDITIONS +- +- 0. Definitions. +- +- "This License" refers to version 3 of the GNU General Public License. +- +- "Copyright" also means copyright-like laws that apply to other kinds of +-works, such as semiconductor masks. +- +- "The Program" refers to any copyrightable work licensed under this +-License. Each licensee is addressed as "you". "Licensees" and +-"recipients" may be individuals or organizations. +- +- To "modify" a work means to copy from or adapt all or part of the work +-in a fashion requiring copyright permission, other than the making of an +-exact copy. The resulting work is called a "modified version" of the +-earlier work or a work "based on" the earlier work. +- +- A "covered work" means either the unmodified Program or a work based +-on the Program. +- +- To "propagate" a work means to do anything with it that, without +-permission, would make you directly or secondarily liable for +-infringement under applicable copyright law, except executing it on a +-computer or modifying a private copy. Propagation includes copying, +-distribution (with or without modification), making available to the +-public, and in some countries other activities as well. +- +- To "convey" a work means any kind of propagation that enables other +-parties to make or receive copies. Mere interaction with a user through +-a computer network, with no transfer of a copy, is not conveying. +- +- An interactive user interface displays "Appropriate Legal Notices" +-to the extent that it includes a convenient and prominently visible +-feature that (1) displays an appropriate copyright notice, and (2) +-tells the user that there is no warranty for the work (except to the +-extent that warranties are provided), that licensees may convey the +-work under this License, and how to view a copy of this License. If +-the interface presents a list of user commands or options, such as a +-menu, a prominent item in the list meets this criterion. +- +- 1. Source Code. +- +- The "source code" for a work means the preferred form of the work +-for making modifications to it. "Object code" means any non-source +-form of a work. +- +- A "Standard Interface" means an interface that either is an official +-standard defined by a recognized standards body, or, in the case of +-interfaces specified for a particular programming language, one that +-is widely used among developers working in that language. +- +- The "System Libraries" of an executable work include anything, other +-than the work as a whole, that (a) is included in the normal form of +-packaging a Major Component, but which is not part of that Major +-Component, and (b) serves only to enable use of the work with that +-Major Component, or to implement a Standard Interface for which an +-implementation is available to the public in source code form. A +-"Major Component", in this context, means a major essential component +-(kernel, window system, and so on) of the specific operating system +-(if any) on which the executable work runs, or a compiler used to +-produce the work, or an object code interpreter used to run it. +- +- The "Corresponding Source" for a work in object code form means all +-the source code needed to generate, install, and (for an executable +-work) run the object code and to modify the work, including scripts to +-control those activities. However, it does not include the work's +-System Libraries, or general-purpose tools or generally available free +-programs which are used unmodified in performing those activities but +-which are not part of the work. For example, Corresponding Source +-includes interface definition files associated with source files for +-the work, and the source code for shared libraries and dynamically +-linked subprograms that the work is specifically designed to require, +-such as by intimate data communication or control flow between those +-subprograms and other parts of the work. +- +- The Corresponding Source need not include anything that users +-can regenerate automatically from other parts of the Corresponding +-Source. +- +- The Corresponding Source for a work in source code form is that +-same work. +- +- 2. Basic Permissions. +- +- All rights granted under this License are granted for the term of +-copyright on the Program, and are irrevocable provided the stated +-conditions are met. This License explicitly affirms your unlimited +-permission to run the unmodified Program. The output from running a +-covered work is covered by this License only if the output, given its +-content, constitutes a covered work. This License acknowledges your +-rights of fair use or other equivalent, as provided by copyright law. +- +- You may make, run and propagate covered works that you do not +-convey, without conditions so long as your license otherwise remains +-in force. You may convey covered works to others for the sole purpose +-of having them make modifications exclusively for you, or provide you +-with facilities for running those works, provided that you comply with +-the terms of this License in conveying all material for which you do +-not control copyright. Those thus making or running the covered works +-for you must do so exclusively on your behalf, under your direction +-and control, on terms that prohibit them from making any copies of +-your copyrighted material outside their relationship with you. +- +- Conveying under any other circumstances is permitted solely under +-the conditions stated below. Sublicensing is not allowed; section 10 +-makes it unnecessary. +- +- 3. Protecting Users' Legal Rights From Anti-Circumvention Law. +- +- No covered work shall be deemed part of an effective technological +-measure under any applicable law fulfilling obligations under article +-11 of the WIPO copyright treaty adopted on 20 December 1996, or +-similar laws prohibiting or restricting circumvention of such +-measures. +- +- When you convey a covered work, you waive any legal power to forbid +-circumvention of technological measures to the extent such circumvention +-is effected by exercising rights under this License with respect to +-the covered work, and you disclaim any intention to limit operation or +-modification of the work as a means of enforcing, against the work's +-users, your or third parties' legal rights to forbid circumvention of +-technological measures. +- +- 4. Conveying Verbatim Copies. +- +- You may convey verbatim copies of the Program's source code as you +-receive it, in any medium, provided that you conspicuously and +-appropriately publish on each copy an appropriate copyright notice; +-keep intact all notices stating that this License and any +-non-permissive terms added in accord with section 7 apply to the code; +-keep intact all notices of the absence of any warranty; and give all +-recipients a copy of this License along with the Program. +- +- You may charge any price or no price for each copy that you convey, +-and you may offer support or warranty protection for a fee. +- +- 5. Conveying Modified Source Versions. +- +- You may convey a work based on the Program, or the modifications to +-produce it from the Program, in the form of source code under the +-terms of section 4, provided that you also meet all of these conditions: +- +- a) The work must carry prominent notices stating that you modified +- it, and giving a relevant date. +- +- b) The work must carry prominent notices stating that it is +- released under this License and any conditions added under section +- 7. This requirement modifies the requirement in section 4 to +- "keep intact all notices". +- +- c) You must license the entire work, as a whole, under this +- License to anyone who comes into possession of a copy. This +- License will therefore apply, along with any applicable section 7 +- additional terms, to the whole of the work, and all its parts, +- regardless of how they are packaged. This License gives no +- permission to license the work in any other way, but it does not +- invalidate such permission if you have separately received it. +- +- d) If the work has interactive user interfaces, each must display +- Appropriate Legal Notices; however, if the Program has interactive +- interfaces that do not display Appropriate Legal Notices, your +- work need not make them do so. +- +- A compilation of a covered work with other separate and independent +-works, which are not by their nature extensions of the covered work, +-and which are not combined with it such as to form a larger program, +-in or on a volume of a storage or distribution medium, is called an +-"aggregate" if the compilation and its resulting copyright are not +-used to limit the access or legal rights of the compilation's users +-beyond what the individual works permit. Inclusion of a covered work +-in an aggregate does not cause this License to apply to the other +-parts of the aggregate. +- +- 6. Conveying Non-Source Forms. +- +- You may convey a covered work in object code form under the terms +-of sections 4 and 5, provided that you also convey the +-machine-readable Corresponding Source under the terms of this License, +-in one of these ways: +- +- a) Convey the object code in, or embodied in, a physical product +- (including a physical distribution medium), accompanied by the +- Corresponding Source fixed on a durable physical medium +- customarily used for software interchange. +- +- b) Convey the object code in, or embodied in, a physical product +- (including a physical distribution medium), accompanied by a +- written offer, valid for at least three years and valid for as +- long as you offer spare parts or customer support for that product +- model, to give anyone who possesses the object code either (1) a +- copy of the Corresponding Source for all the software in the +- product that is covered by this License, on a durable physical +- medium customarily used for software interchange, for a price no +- more than your reasonable cost of physically performing this +- conveying of source, or (2) access to copy the +- Corresponding Source from a network server at no charge. +- +- c) Convey individual copies of the object code with a copy of the +- written offer to provide the Corresponding Source. This +- alternative is allowed only occasionally and noncommercially, and +- only if you received the object code with such an offer, in accord +- with subsection 6b. +- +- d) Convey the object code by offering access from a designated +- place (gratis or for a charge), and offer equivalent access to the +- Corresponding Source in the same way through the same place at no +- further charge. You need not require recipients to copy the +- Corresponding Source along with the object code. If the place to +- copy the object code is a network server, the Corresponding Source +- may be on a different server (operated by you or a third party) +- that supports equivalent copying facilities, provided you maintain +- clear directions next to the object code saying where to find the +- Corresponding Source. Regardless of what server hosts the +- Corresponding Source, you remain obligated to ensure that it is +- available for as long as needed to satisfy these requirements. +- +- e) Convey the object code using peer-to-peer transmission, provided +- you inform other peers where the object code and Corresponding +- Source of the work are being offered to the general public at no +- charge under subsection 6d. +- +- A separable portion of the object code, whose source code is excluded +-from the Corresponding Source as a System Library, need not be +-included in conveying the object code work. +- +- A "User Product" is either (1) a "consumer product", which means any +-tangible personal property which is normally used for personal, family, +-or household purposes, or (2) anything designed or sold for incorporation +-into a dwelling. In determining whether a product is a consumer product, +-doubtful cases shall be resolved in favor of coverage. For a particular +-product received by a particular user, "normally used" refers to a +-typical or common use of that class of product, regardless of the status +-of the particular user or of the way in which the particular user +-actually uses, or expects or is expected to use, the product. A product +-is a consumer product regardless of whether the product has substantial +-commercial, industrial or non-consumer uses, unless such uses represent +-the only significant mode of use of the product. +- +- "Installation Information" for a User Product means any methods, +-procedures, authorization keys, or other information required to install +-and execute modified versions of a covered work in that User Product from +-a modified version of its Corresponding Source. The information must +-suffice to ensure that the continued functioning of the modified object +-code is in no case prevented or interfered with solely because +-modification has been made. +- +- If you convey an object code work under this section in, or with, or +-specifically for use in, a User Product, and the conveying occurs as +-part of a transaction in which the right of possession and use of the +-User Product is transferred to the recipient in perpetuity or for a +-fixed term (regardless of how the transaction is characterized), the +-Corresponding Source conveyed under this section must be accompanied +-by the Installation Information. But this requirement does not apply +-if neither you nor any third party retains the ability to install +-modified object code on the User Product (for example, the work has +-been installed in ROM). +- +- The requirement to provide Installation Information does not include a +-requirement to continue to provide support service, warranty, or updates +-for a work that has been modified or installed by the recipient, or for +-the User Product in which it has been modified or installed. Access to a +-network may be denied when the modification itself materially and +-adversely affects the operation of the network or violates the rules and +-protocols for communication across the network. +- +- Corresponding Source conveyed, and Installation Information provided, +-in accord with this section must be in a format that is publicly +-documented (and with an implementation available to the public in +-source code form), and must require no special password or key for +-unpacking, reading or copying. +- +- 7. Additional Terms. +- +- "Additional permissions" are terms that supplement the terms of this +-License by making exceptions from one or more of its conditions. +-Additional permissions that are applicable to the entire Program shall +-be treated as though they were included in this License, to the extent +-that they are valid under applicable law. If additional permissions +-apply only to part of the Program, that part may be used separately +-under those permissions, but the entire Program remains governed by +-this License without regard to the additional permissions. +- +- When you convey a copy of a covered work, you may at your option +-remove any additional permissions from that copy, or from any part of +-it. (Additional permissions may be written to require their own +-removal in certain cases when you modify the work.) You may place +-additional permissions on material, added by you to a covered work, +-for which you have or can give appropriate copyright permission. +- +- Notwithstanding any other provision of this License, for material you +-add to a covered work, you may (if authorized by the copyright holders of +-that material) supplement the terms of this License with terms: +- +- a) Disclaiming warranty or limiting liability differently from the +- terms of sections 15 and 16 of this License; or +- +- b) Requiring preservation of specified reasonable legal notices or +- author attributions in that material or in the Appropriate Legal +- Notices displayed by works containing it; or +- +- c) Prohibiting misrepresentation of the origin of that material, or +- requiring that modified versions of such material be marked in +- reasonable ways as different from the original version; or +- +- d) Limiting the use for publicity purposes of names of licensors or +- authors of the material; or +- +- e) Declining to grant rights under trademark law for use of some +- trade names, trademarks, or service marks; or +- +- f) Requiring indemnification of licensors and authors of that +- material by anyone who conveys the material (or modified versions of +- it) with contractual assumptions of liability to the recipient, for +- any liability that these contractual assumptions directly impose on +- those licensors and authors. +- +- All other non-permissive additional terms are considered "further +-restrictions" within the meaning of section 10. If the Program as you +-received it, or any part of it, contains a notice stating that it is +-governed by this License along with a term that is a further +-restriction, you may remove that term. If a license document contains +-a further restriction but permits relicensing or conveying under this +-License, you may add to a covered work material governed by the terms +-of that license document, provided that the further restriction does +-not survive such relicensing or conveying. +- +- If you add terms to a covered work in accord with this section, you +-must place, in the relevant source files, a statement of the +-additional terms that apply to those files, or a notice indicating +-where to find the applicable terms. +- +- Additional terms, permissive or non-permissive, may be stated in the +-form of a separately written license, or stated as exceptions; +-the above requirements apply either way. +- +- 8. Termination. +- +- You may not propagate or modify a covered work except as expressly +-provided under this License. Any attempt otherwise to propagate or +-modify it is void, and will automatically terminate your rights under +-this License (including any patent licenses granted under the third +-paragraph of section 11). +- +- However, if you cease all violation of this License, then your +-license from a particular copyright holder is reinstated (a) +-provisionally, unless and until the copyright holder explicitly and +-finally terminates your license, and (b) permanently, if the copyright +-holder fails to notify you of the violation by some reasonable means +-prior to 60 days after the cessation. +- +- Moreover, your license from a particular copyright holder is +-reinstated permanently if the copyright holder notifies you of the +-violation by some reasonable means, this is the first time you have +-received notice of violation of this License (for any work) from that +-copyright holder, and you cure the violation prior to 30 days after +-your receipt of the notice. +- +- Termination of your rights under this section does not terminate the +-licenses of parties who have received copies or rights from you under +-this License. If your rights have been terminated and not permanently +-reinstated, you do not qualify to receive new licenses for the same +-material under section 10. +- +- 9. Acceptance Not Required for Having Copies. +- +- You are not required to accept this License in order to receive or +-run a copy of the Program. Ancillary propagation of a covered work +-occurring solely as a consequence of using peer-to-peer transmission +-to receive a copy likewise does not require acceptance. However, +-nothing other than this License grants you permission to propagate or +-modify any covered work. These actions infringe copyright if you do +-not accept this License. Therefore, by modifying or propagating a +-covered work, you indicate your acceptance of this License to do so. +- +- 10. Automatic Licensing of Downstream Recipients. +- +- Each time you convey a covered work, the recipient automatically +-receives a license from the original licensors, to run, modify and +-propagate that work, subject to this License. You are not responsible +-for enforcing compliance by third parties with this License. +- +- An "entity transaction" is a transaction transferring control of an +-organization, or substantially all assets of one, or subdividing an +-organization, or merging organizations. If propagation of a covered +-work results from an entity transaction, each party to that +-transaction who receives a copy of the work also receives whatever +-licenses to the work the party's predecessor in interest had or could +-give under the previous paragraph, plus a right to possession of the +-Corresponding Source of the work from the predecessor in interest, if +-the predecessor has it or can get it with reasonable efforts. +- +- You may not impose any further restrictions on the exercise of the +-rights granted or affirmed under this License. For example, you may +-not impose a license fee, royalty, or other charge for exercise of +-rights granted under this License, and you may not initiate litigation +-(including a cross-claim or counterclaim in a lawsuit) alleging that +-any patent claim is infringed by making, using, selling, offering for +-sale, or importing the Program or any portion of it. +- +- 11. Patents. +- +- A "contributor" is a copyright holder who authorizes use under this +-License of the Program or a work on which the Program is based. The +-work thus licensed is called the contributor's "contributor version". +- +- A contributor's "essential patent claims" are all patent claims +-owned or controlled by the contributor, whether already acquired or +-hereafter acquired, that would be infringed by some manner, permitted +-by this License, of making, using, or selling its contributor version, +-but do not include claims that would be infringed only as a +-consequence of further modification of the contributor version. For +-purposes of this definition, "control" includes the right to grant +-patent sublicenses in a manner consistent with the requirements of ++ GNU GENERAL PUBLIC LICENSE ++ TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION ++ ++ 0. This License applies to any program or other work which contains ++a notice placed by the copyright holder saying it may be distributed ++under the terms of this General Public License. The "Program", below, ++refers to any such program or work, and a "work based on the Program" ++means either the Program or any derivative work under copyright law: ++that is to say, a work containing the Program or a portion of it, ++either verbatim or with modifications and/or translated into another ++language. (Hereinafter, translation is included without limitation in ++the term "modification".) Each licensee is addressed as "you". ++ ++Activities other than copying, distribution and modification are not ++covered by this License; they are outside its scope. The act of ++running the Program is not restricted, and the output from the Program ++is covered only if its contents constitute a work based on the ++Program (independent of having been made by running the Program). ++Whether that is true depends on what the Program does. ++ ++ 1. You may copy and distribute verbatim copies of the Program's ++source code as you receive it, in any medium, provided that you ++conspicuously and appropriately publish on each copy an appropriate ++copyright notice and disclaimer of warranty; keep intact all the ++notices that refer to this License and to the absence of any warranty; ++and give any other recipients of the Program a copy of this License ++along with the Program. ++ ++You may charge a fee for the physical act of transferring a copy, and ++you may at your option offer warranty protection in exchange for a fee. ++ ++ 2. You may modify your copy or copies of the Program or any portion ++of it, thus forming a work based on the Program, and copy and ++distribute such modifications or work under the terms of Section 1 ++above, provided that you also meet all of these conditions: ++ ++ a) You must cause the modified files to carry prominent notices ++ stating that you changed the files and the date of any change. ++ ++ b) You must cause any work that you distribute or publish, that in ++ whole or in part contains or is derived from the Program or any ++ part thereof, to be licensed as a whole at no charge to all third ++ parties under the terms of this License. ++ ++ c) If the modified program normally reads commands interactively ++ when run, you must cause it, when started running for such ++ interactive use in the most ordinary way, to print or display an ++ announcement including an appropriate copyright notice and a ++ notice that there is no warranty (or else, saying that you provide ++ a warranty) and that users may redistribute the program under ++ these conditions, and telling the user how to view a copy of this ++ License. (Exception: if the Program itself is interactive but ++ does not normally print such an announcement, your work based on ++ the Program is not required to print an announcement.) ++ ++These requirements apply to the modified work as a whole. If ++identifiable sections of that work are not derived from the Program, ++and can be reasonably considered independent and separate works in ++themselves, then this License, and its terms, do not apply to those ++sections when you distribute them as separate works. But when you ++distribute the same sections as part of a whole which is a work based ++on the Program, the distribution of the whole must be on the terms of ++this License, whose permissions for other licensees extend to the ++entire whole, and thus to each and every part regardless of who wrote it. ++ ++Thus, it is not the intent of this section to claim rights or contest ++your rights to work written entirely by you; rather, the intent is to ++exercise the right to control the distribution of derivative or ++collective works based on the Program. ++ ++In addition, mere aggregation of another work not based on the Program ++with the Program (or with a work based on the Program) on a volume of ++a storage or distribution medium does not bring the other work under ++the scope of this License. ++ ++ 3. You may copy and distribute the Program (or a work based on it, ++under Section 2) in object code or executable form under the terms of ++Sections 1 and 2 above provided that you also do one of the following: ++ ++ a) Accompany it with the complete corresponding machine-readable ++ source code, which must be distributed under the terms of Sections ++ 1 and 2 above on a medium customarily used for software interchange; or, ++ ++ b) Accompany it with a written offer, valid for at least three ++ years, to give any third party, for a charge no more than your ++ cost of physically performing source distribution, a complete ++ machine-readable copy of the corresponding source code, to be ++ distributed under the terms of Sections 1 and 2 above on a medium ++ customarily used for software interchange; or, ++ ++ c) Accompany it with the information you received as to the offer ++ to distribute corresponding source code. (This alternative is ++ allowed only for noncommercial distribution and only if you ++ received the program in object code or executable form with such ++ an offer, in accord with Subsection b above.) ++ ++The source code for a work means the preferred form of the work for ++making modifications to it. For an executable work, complete source ++code means all the source code for all modules it contains, plus any ++associated interface definition files, plus the scripts used to ++control compilation and installation of the executable. However, as a ++special exception, the source code distributed need not include ++anything that is normally distributed (in either source or binary ++form) with the major components (compiler, kernel, and so on) of the ++operating system on which the executable runs, unless that component ++itself accompanies the executable. ++ ++If distribution of executable or object code is made by offering ++access to copy from a designated place, then offering equivalent ++access to copy the source code from the same place counts as ++distribution of the source code, even though third parties are not ++compelled to copy the source along with the object code. ++ ++ 4. You may not copy, modify, sublicense, or distribute the Program ++except as expressly provided under this License. Any attempt ++otherwise to copy, modify, sublicense or distribute the Program is ++void, and will automatically terminate your rights under this License. ++However, parties who have received copies, or rights, from you under ++this License will not have their licenses terminated so long as such ++parties remain in full compliance. ++ ++ 5. You are not required to accept this License, since you have not ++signed it. However, nothing else grants you permission to modify or ++distribute the Program or its derivative works. These actions are ++prohibited by law if you do not accept this License. Therefore, by ++modifying or distributing the Program (or any work based on the ++Program), you indicate your acceptance of this License to do so, and ++all its terms and conditions for copying, distributing or modifying ++the Program or works based on it. ++ ++ 6. Each time you redistribute the Program (or any work based on the ++Program), the recipient automatically receives a license from the ++original licensor to copy, distribute or modify the Program subject to ++these terms and conditions. You may not impose any further ++restrictions on the recipients' exercise of the rights granted herein. ++You are not responsible for enforcing compliance by third parties to + this License. + +- Each contributor grants you a non-exclusive, worldwide, royalty-free +-patent license under the contributor's essential patent claims, to +-make, use, sell, offer for sale, import and otherwise run, modify and +-propagate the contents of its contributor version. +- +- In the following three paragraphs, a "patent license" is any express +-agreement or commitment, however denominated, not to enforce a patent +-(such as an express permission to practice a patent or covenant not to +-sue for patent infringement). To "grant" such a patent license to a +-party means to make such an agreement or commitment not to enforce a +-patent against the party. +- +- If you convey a covered work, knowingly relying on a patent license, +-and the Corresponding Source of the work is not available for anyone +-to copy, free of charge and under the terms of this License, through a +-publicly available network server or other readily accessible means, +-then you must either (1) cause the Corresponding Source to be so +-available, or (2) arrange to deprive yourself of the benefit of the +-patent license for this particular work, or (3) arrange, in a manner +-consistent with the requirements of this License, to extend the patent +-license to downstream recipients. "Knowingly relying" means you have +-actual knowledge that, but for the patent license, your conveying the +-covered work in a country, or your recipient's use of the covered work +-in a country, would infringe one or more identifiable patents in that +-country that you have reason to believe are valid. +- +- If, pursuant to or in connection with a single transaction or +-arrangement, you convey, or propagate by procuring conveyance of, a +-covered work, and grant a patent license to some of the parties +-receiving the covered work authorizing them to use, propagate, modify +-or convey a specific copy of the covered work, then the patent license +-you grant is automatically extended to all recipients of the covered +-work and works based on it. +- +- A patent license is "discriminatory" if it does not include within +-the scope of its coverage, prohibits the exercise of, or is +-conditioned on the non-exercise of one or more of the rights that are +-specifically granted under this License. You may not convey a covered +-work if you are a party to an arrangement with a third party that is +-in the business of distributing software, under which you make payment +-to the third party based on the extent of your activity of conveying +-the work, and under which the third party grants, to any of the +-parties who would receive the covered work from you, a discriminatory +-patent license (a) in connection with copies of the covered work +-conveyed by you (or copies made from those copies), or (b) primarily +-for and in connection with specific products or compilations that +-contain the covered work, unless you entered into that arrangement, +-or that patent license was granted, prior to 28 March 2007. +- +- Nothing in this License shall be construed as excluding or limiting +-any implied license or other defenses to infringement that may +-otherwise be available to you under applicable patent law. +- +- 12. No Surrender of Others' Freedom. +- +- If conditions are imposed on you (whether by court order, agreement or ++ 7. If, as a consequence of a court judgment or allegation of patent ++infringement or for any other reason (not limited to patent issues), ++conditions are imposed on you (whether by court order, agreement or + otherwise) that contradict the conditions of this License, they do not +-excuse you from the conditions of this License. If you cannot convey a +-covered work so as to satisfy simultaneously your obligations under this +-License and any other pertinent obligations, then as a consequence you may +-not convey it at all. For example, if you agree to terms that obligate you +-to collect a royalty for further conveying from those to whom you convey +-the Program, the only way you could satisfy both those terms and this +-License would be to refrain entirely from conveying the Program. ++excuse you from the conditions of this License. If you cannot ++distribute so as to satisfy simultaneously your obligations under this ++License and any other pertinent obligations, then as a consequence you ++may not distribute the Program at all. For example, if a patent ++license would not permit royalty-free redistribution of the Program by ++all those who receive copies directly or indirectly through you, then ++the only way you could satisfy both it and this License would be to ++refrain entirely from distribution of the Program. + +- 13. Use with the GNU Affero General Public License. ++If any portion of this section is held invalid or unenforceable under ++any particular circumstance, the balance of the section is intended to ++apply and the section as a whole is intended to apply in other ++circumstances. + +- Notwithstanding any other provision of this License, you have +-permission to link or combine any covered work with a work licensed +-under version 3 of the GNU Affero General Public License into a single +-combined work, and to convey the resulting work. The terms of this +-License will continue to apply to the part which is the covered work, +-but the special requirements of the GNU Affero General Public License, +-section 13, concerning interaction through a network will apply to the +-combination as such. ++It is not the purpose of this section to induce you to infringe any ++patents or other property right claims or to contest validity of any ++such claims; this section has the sole purpose of protecting the ++integrity of the free software distribution system, which is ++implemented by public license practices. Many people have made ++generous contributions to the wide range of software distributed ++through that system in reliance on consistent application of that ++system; it is up to the author/donor to decide if he or she is willing ++to distribute software through any other system and a licensee cannot ++impose that choice. + +- 14. Revised Versions of this License. ++This section is intended to make thoroughly clear what is believed to ++be a consequence of the rest of this License. + +- The Free Software Foundation may publish revised and/or new versions of +-the GNU General Public License from time to time. Such new versions will ++ 8. If the distribution and/or use of the Program is restricted in ++certain countries either by patents or by copyrighted interfaces, the ++original copyright holder who places the Program under this License ++may add an explicit geographical distribution limitation excluding ++those countries, so that distribution is permitted only in or among ++countries not thus excluded. In such case, this License incorporates ++the limitation as if written in the body of this License. ++ ++ 9. The Free Software Foundation may publish revised and/or new versions ++of the General Public License from time to time. Such new versions will + be similar in spirit to the present version, but may differ in detail to + address new problems or concerns. + +- Each version is given a distinguishing version number. If the +-Program specifies that a certain numbered version of the GNU General +-Public License "or any later version" applies to it, you have the +-option of following the terms and conditions either of that numbered +-version or of any later version published by the Free Software +-Foundation. If the Program does not specify a version number of the +-GNU General Public License, you may choose any version ever published +-by the Free Software Foundation. ++Each version is given a distinguishing version number. If the Program ++specifies a version number of this License which applies to it and "any ++later version", you have the option of following the terms and conditions ++either of that version or of any later version published by the Free ++Software Foundation. If the Program does not specify a version number of ++this License, you may choose any version ever published by the Free Software ++Foundation. + +- If the Program specifies that a proxy can decide which future +-versions of the GNU General Public License can be used, that proxy's +-public statement of acceptance of a version permanently authorizes you +-to choose that version for the Program. ++ 10. If you wish to incorporate parts of the Program into other free ++programs whose distribution conditions are different, write to the author ++to ask for permission. For software which is copyrighted by the Free ++Software Foundation, write to the Free Software Foundation; we sometimes ++make exceptions for this. Our decision will be guided by the two goals ++of preserving the free status of all derivatives of our free software and ++of promoting the sharing and reuse of software generally. + +- Later license versions may give you additional or different +-permissions. However, no additional obligations are imposed on any +-author or copyright holder as a result of your choosing to follow a +-later version. ++ NO WARRANTY + +- 15. Disclaimer of Warranty. ++ 11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY ++FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN ++OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES ++PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED ++OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF ++MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS ++TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE ++PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, ++REPAIR OR CORRECTION. + +- THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY +-APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT +-HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY +-OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, +-THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR +-PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM +-IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF +-ALL NECESSARY SERVICING, REPAIR OR CORRECTION. ++ 12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING ++WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR ++REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, ++INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING ++OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED ++TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY ++YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER ++PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE ++POSSIBILITY OF SUCH DAMAGES. + +- 16. Limitation of Liability. ++ END OF TERMS AND CONDITIONS + +- IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING +-WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS +-THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY +-GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE +-USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF +-DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD +-PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), +-EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF +-SUCH DAMAGES. +- +- 17. Interpretation of Sections 15 and 16. +- +- If the disclaimer of warranty and limitation of liability provided +-above cannot be given local legal effect according to their terms, +-reviewing courts shall apply local law that most closely approximates +-an absolute waiver of all civil liability in connection with the +-Program, unless a warranty or assumption of liability accompanies a +-copy of the Program in return for a fee. +- +- END OF TERMS AND CONDITIONS +- +- How to Apply These Terms to Your New Programs ++ How to Apply These Terms to Your New Programs + + If you develop a new program, and you want it to be of the greatest + possible use to the public, the best way to achieve this is to make it +@@ -629,15 +287,15 @@ free software which everyone can redistribute and change under these terms. + + To do so, attach the following notices to the program. It is safest + to attach them to the start of each source file to most effectively +-state the exclusion of warranty; and each file should have at least ++convey the exclusion of warranty; and each file should have at least + the "copyright" line and a pointer to where the full notice is found. + + + Copyright (C) + +- This program is free software: you can redistribute it and/or modify ++ This program is free software; you can redistribute it and/or modify + it under the terms of the GNU General Public License as published by +- the Free Software Foundation, either version 3 of the License, or ++ the Free Software Foundation; either version 2 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, +@@ -645,32 +303,37 @@ the "copyright" line and a pointer to where the full notice is found. + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU General Public License for more details. + +- You should have received a copy of the GNU General Public License +- along with this program. If not, see . ++ You should have received a copy of the GNU General Public License along ++ with this program; if not, write to the Free Software Foundation, Inc., ++ 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. + + Also add information on how to contact you by electronic and paper mail. + +- If the program does terminal interaction, make it output a short +-notice like this when it starts in an interactive mode: ++If the program is interactive, make it output a short notice like this ++when it starts in an interactive mode: + +- Copyright (C) +- This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'. ++ Gnomovision version 69, Copyright (C) year name of author ++ Gnomovision comes with ABSOLUTELY NO WARRANTY; for details type `show w'. + This is free software, and you are welcome to redistribute it + under certain conditions; type `show c' for details. + + The hypothetical commands `show w' and `show c' should show the appropriate +-parts of the General Public License. Of course, your program's commands +-might be different; for a GUI interface, you would use an "about box". ++parts of the General Public License. Of course, the commands you use may ++be called something other than `show w' and `show c'; they could even be ++mouse-clicks or menu items--whatever suits your program. + +- You should also get your employer (if you work as a programmer) or school, +-if any, to sign a "copyright disclaimer" for the program, if necessary. +-For more information on this, and how to apply and follow the GNU GPL, see +-. ++You should also get your employer (if you work as a programmer) or your ++school, if any, to sign a "copyright disclaimer" for the program, if ++necessary. Here is a sample; alter the names: + +- The GNU General Public License does not permit incorporating your program +-into proprietary programs. If your program is a subroutine library, you +-may consider it more useful to permit linking proprietary applications with +-the library. If this is what you want to do, use the GNU Lesser General +-Public License instead of this License. But first, please read +-. ++ Yoyodyne, Inc., hereby disclaims all copyright interest in the program ++ `Gnomovision' (which makes passes at compilers) written by James Hacker. + ++ , 1 April 1989 ++ Ty Coon, President of Vice ++ ++This General Public License does not permit incorporating your program into ++proprietary programs. If your program is a subroutine library, you may ++consider it more useful to permit linking proprietary applications with the ++library. If this is what you want to do, use the GNU Lesser General ++Public License instead of this License. +-- +2.34.1 + diff --git a/0001-Fix-format-strings-for-32-bit-arches.patch b/0002-Fix-format-strings-for-32-bit-arches.patch similarity index 97% rename from 0001-Fix-format-strings-for-32-bit-arches.patch rename to 0002-Fix-format-strings-for-32-bit-arches.patch index 2b71a0e..3a5ece2 100644 --- a/0001-Fix-format-strings-for-32-bit-arches.patch +++ b/0002-Fix-format-strings-for-32-bit-arches.patch @@ -1,7 +1,7 @@ -From 1f8d0985d59ed41e291398f937d32493898bd711 Mon Sep 17 00:00:00 2001 +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 1 Feb 2022 17:37:14 -0500 -Subject: [PATCH] Fix format strings for 32-bit arches +Subject: [PATCH 2/3] Fix format strings for 32-bit arches Sadly, in 2022, this remains a thing. diff --git a/0003-macros-drop-_pesign_args.patch b/0003-macros-drop-_pesign_args.patch new file mode 100644 index 0000000..0511bfa --- /dev/null +++ b/0003-macros-drop-_pesign_args.patch @@ -0,0 +1,47 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 2 Feb 2022 16:07:46 -0500 +Subject: [PATCH 3/3] macros: drop %{_pesign_args} + +Effectively reverts 30b488682a92c524bb9c0d450c34e9abc0b56de9 + +Also, make our argument parser fail on extra arguments to make it easier +to debug when this kind of thing happens again. + +Signed-off-by: Robbie Harwood +--- + src/macros.pesign | 1 - + src/pesign-rpmbuild-helper.in | 5 +++++ + 2 files changed, 5 insertions(+), 1 deletion(-) + +diff --git a/src/macros.pesign b/src/macros.pesign +index 519a8a3..34af57c 100644 +--- a/src/macros.pesign ++++ b/src/macros.pesign +@@ -27,7 +27,6 @@ + %{_libexecdir}/pesign/pesign-rpmbuild-helper \\\ + "%{_target_cpu}" \\\ + "%{_pesign}" \\\ +- "%{_pesign_args}" \\\ + "%{_pesign_client}" \\\ + %{?__pesign_client_token:--client-token %{__pesign_client_token}} \\\ + %{?__pesign_client_cert:--client-cert %{__pesign_client_cert}} \\\ +diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in +index 27b8261..0a845d2 100644 +--- a/src/pesign-rpmbuild-helper.in ++++ b/src/pesign-rpmbuild-helper.in +@@ -133,6 +133,11 @@ main() { + sign=-s + shift + fi ++ if [[ $# -ge 1 ]] ; then ++ echo "$# extra unparsed arguments!">>/dev/stderr ++ echo "Cowardly refusing to run">>/dev/stderr ++ exit 1 ++ fi + + if [[ -z "${target_cpu}" ]] ; then + target_cpu="$(uname -m)" +-- +2.34.1 + diff --git a/pesign.spec b/pesign.spec index a42dddf..3282110 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 114 -Release: 1%{?dist} +Release: 2%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -44,7 +44,9 @@ Source0: https://github.com/rhboot/pesign/releases/download/%{version}/pesign-%{ Source1: certs.tar.xz Source2: pesign.py -Patch0001: 0001-Fix-format-strings-for-32-bit-arches.patch +Patch0001: 0001-Revert-Move-license-to-GPLv3.patch +Patch0002: 0002-Fix-format-strings-for-32-bit-arches.patch +Patch0003: 0003-macros-drop-_pesign_args.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -156,6 +158,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Wed Feb 02 2022 Robbie Harwood - 114-2 +- Attempt to fix signing parsing by dropping pesign_args + * Tue Feb 01 2022 Robbie Harwood - 114-1 - New upstream version (114) From eb423047cd0f8267a17756af3b1cfe7eed09974c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 9 Feb 2022 14:35:36 -0500 Subject: [PATCH 45/70] Bump efivar minimum version for clarity Signed-off-by: Robbie Harwood --- pesign.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index 3282110..33f6f80 100644 --- a/pesign.spec +++ b/pesign.spec @@ -8,7 +8,7 @@ License: GPL-2.0-only URL: https://github.com/rhboot/pesign Obsoletes: pesign-rh-test-certs <= 0.111-7 -BuildRequires: efivar-devel >= 31-1 +BuildRequires: efivar-devel >= 38-1 BuildRequires: gcc BuildRequires: git BuildRequires: libuuid-devel From 840c1cffff634fea64c4497986a720903ff503fb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Feb 2022 21:10:49 +0000 Subject: [PATCH 46/70] Fix explicit NULL deref when daemonizing Signed-off-by: Robbie Harwood --- 0001-Revert-Move-license-to-GPLv3.patch | 4 +- ...Fix-format-strings-for-32-bit-arches.patch | 4 +- 0003-macros-drop-_pesign_args.patch | 4 +- ...andle-NULL-pwdata-in-cms_set_pw_data.patch | 55 +++++++++++++++++++ 0005-fcf-protection-is-arch-specific.patch | 46 ++++++++++++++++ pesign.spec | 7 ++- 6 files changed, 113 insertions(+), 7 deletions(-) create mode 100644 0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch create mode 100644 0005-fcf-protection-is-arch-specific.patch diff --git a/0001-Revert-Move-license-to-GPLv3.patch b/0001-Revert-Move-license-to-GPLv3.patch index 4b8931c..4e4bec5 100644 --- a/0001-Revert-Move-license-to-GPLv3.patch +++ b/0001-Revert-Move-license-to-GPLv3.patch @@ -1,7 +1,7 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From fc20530a0ef666b49e6276c983d2d16517d3839b Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 1 Feb 2022 15:04:30 -0500 -Subject: [PATCH 1/3] Revert "Move license to GPLv3+" +Subject: [PATCH 1/5] Revert "Move license to GPLv3+" This was done too soon. It's missing some pieces and we need buy-in on a couple of source files. diff --git a/0002-Fix-format-strings-for-32-bit-arches.patch b/0002-Fix-format-strings-for-32-bit-arches.patch index 3a5ece2..1aaab2d 100644 --- a/0002-Fix-format-strings-for-32-bit-arches.patch +++ b/0002-Fix-format-strings-for-32-bit-arches.patch @@ -1,7 +1,7 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From df8783ed4ed87fef850268098690985049916ee9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 1 Feb 2022 17:37:14 -0500 -Subject: [PATCH 2/3] Fix format strings for 32-bit arches +Subject: [PATCH 2/5] Fix format strings for 32-bit arches Sadly, in 2022, this remains a thing. diff --git a/0003-macros-drop-_pesign_args.patch b/0003-macros-drop-_pesign_args.patch index 0511bfa..40a7bf5 100644 --- a/0003-macros-drop-_pesign_args.patch +++ b/0003-macros-drop-_pesign_args.patch @@ -1,7 +1,7 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From 389decab7b9bcba307e52709b00741a19405f02b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 2 Feb 2022 16:07:46 -0500 -Subject: [PATCH 3/3] macros: drop %{_pesign_args} +Subject: [PATCH 3/5] macros: drop %{_pesign_args} Effectively reverts 30b488682a92c524bb9c0d450c34e9abc0b56de9 diff --git a/0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch b/0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch new file mode 100644 index 0000000..f36d1e0 --- /dev/null +++ b/0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch @@ -0,0 +1,55 @@ +From 4d1ead068248b56ecaeb437f0c0b59f9d89b9748 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 14 Feb 2022 15:46:25 -0500 +Subject: [PATCH 4/5] Handle NULL pwdata in cms_set_pw_data() + +When 12f16710ee44ef64ddb044a3523c3c4c4d90039a rewrote this function, it +didn't handle the NULL pwdata invocation from daemon.c. This leads to a +explicit NULL dereference and crash on all attempts to daemonize pesign. + +Signed-off-by: Robbie Harwood +(cherry picked from commit b879dda52f8122de697d145977c285fb0a022d76) +--- + src/cms_common.c | 18 ++++++++++++------ + 1 file changed, 12 insertions(+), 6 deletions(-) + +diff --git a/src/cms_common.c b/src/cms_common.c +index 332999e..ca37e6a 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -313,7 +313,7 @@ void cms_set_pw_data(cms_context *cms, secuPWData *pwdata) + + case PW_FROMFD: + if (cms->pwdata.intdata >= 0 && +- !(pwdata->source == PW_FROMFD && ++ !(pwdata && pwdata->source == PW_FROMFD && + cms->pwdata.intdata == pwdata->intdata)) + close(cms->pwdata.intdata); + break; +@@ -330,12 +330,18 @@ void cms_set_pw_data(cms_context *cms, secuPWData *pwdata) + xfree(cms->pwdata.data); + break; + } +- memmove(&cms->pwdata, pwdata, sizeof(*pwdata)); + +- dprintf("pwdata:%p", pwdata); +- dprintf("pwdata->source:%d", pwdata->source); +- dprintf("pwdata->data:%p (\"%s\")", pwdata->data, +- pwdata->data ? pwdata->data : "(null)"); ++ if (!pwdata) { ++ cms->pwdata.source = PW_SOURCE_INVALID; ++ dprintf("pwdata:NULL"); ++ } else { ++ memmove(&cms->pwdata, pwdata, sizeof(*pwdata)); ++ dprintf("pwdata:%p", pwdata); ++ dprintf("pwdata->source:%d", pwdata->source); ++ dprintf("pwdata->data:%p (\"%s\")", pwdata->data, ++ pwdata->data ? pwdata->data : "(null)"); ++ } ++ + egress(); + } + +-- +2.34.1 + diff --git a/0005-fcf-protection-is-arch-specific.patch b/0005-fcf-protection-is-arch-specific.patch new file mode 100644 index 0000000..84093bf --- /dev/null +++ b/0005-fcf-protection-is-arch-specific.patch @@ -0,0 +1,46 @@ +From f03c5fbe6b4327b9ecd781bfdf64147e1b68e6c1 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 9 Feb 2022 15:23:27 -0500 +Subject: [PATCH 5/5] -fcf-protection is arch-specific + +Signed-off-by: Robbie Harwood +(cherry picked from commit c48df510144de3b1187001bc3b5491509da1c58f) +--- + Make.defaults | 10 ++++++---- + 1 file changed, 6 insertions(+), 4 deletions(-) + +diff --git a/Make.defaults b/Make.defaults +index fdb961a..130c1ee 100644 +--- a/Make.defaults ++++ b/Make.defaults +@@ -22,11 +22,16 @@ EFI_ARCHES ?= aa64 ia32 x64 + + enabled = $(if $(filter undefined,$(origin $(1))),$(3),$(2)) + ++HOSTARCH = $(shell uname -m | sed s,i[3456789]86,ia32,) ++ARCH := $(shell uname -m | sed s,i[3456789]86,ia32,) ++ ++ + PKG_CONFIG ?= $(CROSS_COMPILE)pkg-config + CC := $(if $(filter default,$(origin CC)),$(CROSS_COMPILE)gcc,$(CC)) + CCLD := $(if $(filter undefined,$(origin CCLD)),$(CC),$(CCLD)) + CFLAGS ?= -O2 -g3 -pipe -fPIE -fstack-protector-all \ +- -fstack-clash-protection -fcf-protection=full ++ -fstack-clash-protection \ ++ $(if $(filter x86_64 ia32,$(ARCH)),-fcf-protection=full,) + DIAGFLAGS ?= -fmessage-length=0 \ + -fdiagnostics-color=always \ + -fdiagnostics-format=text \ +@@ -42,9 +47,6 @@ INSTALL ?= $(CROSS_COMPILE)install + + PKGS = efivar nspr nss nss-util uuid + +-HOSTARCH = $(shell uname -m | sed s,i[3456789]86,ia32,) +-ARCH := $(shell uname -m | sed s,i[3456789]86,ia32,) +- + SOFLAGS ?= -shared + clang_cflags = + gcc_cflags = -Wmaybe-uninitialized -grecord-gcc-switches \ +-- +2.34.1 + diff --git a/pesign.spec b/pesign.spec index 33f6f80..4905201 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 114 -Release: 2%{?dist} +Release: 3%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -47,6 +47,8 @@ Source2: pesign.py Patch0001: 0001-Revert-Move-license-to-GPLv3.patch Patch0002: 0002-Fix-format-strings-for-32-bit-arches.patch Patch0003: 0003-macros-drop-_pesign_args.patch +Patch0004: 0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch +Patch0005: 0005-fcf-protection-is-arch-specific.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -158,6 +160,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Mon Feb 14 2022 Robbie Harwood - 114-3 +- Fix explicit NULL deref when daemonizing + * Wed Feb 02 2022 Robbie Harwood - 114-2 - Attempt to fix signing parsing by dropping pesign_args From 2638a1181b39da5df436d33ac17799ab62f4368f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Feb 2022 22:29:12 +0000 Subject: [PATCH 47/70] Disable -fanalyzer since it's broken and pragmas don't work See-also: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=104370 Signed-off-by: Robbie Harwood --- 0006-Disable-analyzer-until-it-works.patch | 26 ++++++++++++++++++++++ pesign.spec | 6 ++++- 2 files changed, 31 insertions(+), 1 deletion(-) create mode 100644 0006-Disable-analyzer-until-it-works.patch diff --git a/0006-Disable-analyzer-until-it-works.patch b/0006-Disable-analyzer-until-it-works.patch new file mode 100644 index 0000000..4ed8cbf --- /dev/null +++ b/0006-Disable-analyzer-until-it-works.patch @@ -0,0 +1,26 @@ +From 288b05dcd5a3b48836c4904e38b14e38a0cdfa07 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 14 Feb 2022 17:26:19 -0500 +Subject: [PATCH] Disable analyzer until it works + +See-also: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=104370 +Signed-off-by: Robbie Harwood +--- + Make.defaults | 1 - + 1 file changed, 1 deletion(-) + +diff --git a/Make.defaults b/Make.defaults +index 130c1ee..5e56a76 100644 +--- a/Make.defaults ++++ b/Make.defaults +@@ -36,7 +36,6 @@ DIAGFLAGS ?= -fmessage-length=0 \ + -fdiagnostics-color=always \ + -fdiagnostics-format=text \ + -fdiagnostics-show-cwe \ +- -fanalyzer \ + $(call enabled,ENABLE_LEAK_CHECKER,-Wno-analyzer-malloc-leak,) + AS ?= $(CROSS_COMPILE)as + AR ?= $(CROSS_COMPILE)$(if $(filter $(CC),clang),llvm-ar,$(notdir $(CC))-ar) +-- +2.34.1 + diff --git a/pesign.spec b/pesign.spec index 4905201..583c18b 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 114 -Release: 3%{?dist} +Release: 4%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -160,6 +160,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Mon Feb 14 2022 Robbie Harwood - 114-4 +- Disable -fanalyzer since it's broken and pragmas don't work +- See-also: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=104370 + * Mon Feb 14 2022 Robbie Harwood - 114-3 - Fix explicit NULL deref when daemonizing From 57b330e9051da6dfb54bc60c512cd7d98adc52f3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Feb 2022 22:44:36 +0000 Subject: [PATCH 48/70] Disable distro build flags No. Signed-off-by: Robbie Harwood --- pesign.spec | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pesign.spec b/pesign.spec index 583c18b..d534229 100644 --- a/pesign.spec +++ b/pesign.spec @@ -1,5 +1,8 @@ %global macrosdir %(d=%{_rpmconfigdir}/macros.d; [ -d $d ] || d=%{_sysconfdir}/rpm; echo $d) +# No. I have enough trouble already. +%undefine _auto_set_build_flags + Name: pesign Summary: Signing utility for UEFI binaries Version: 114 From bdccb8412c5020d7e3ca4c3ad598d7dcfcce8bea Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 8 Mar 2022 17:54:45 +0000 Subject: [PATCH 49/70] New upstream version (115) Signed-off-by: Robbie Harwood --- 0001-Revert-Move-license-to-GPLv3.patch | 969 ------------------ ...daemon-remove-always-true-comparison.patch | 24 + ...Fix-format-strings-for-32-bit-arches.patch | 112 -- 0003-macros-drop-_pesign_args.patch | 47 - ...andle-NULL-pwdata-in-cms_set_pw_data.patch | 55 - 0005-fcf-protection-is-arch-specific.patch | 46 - 0006-Disable-analyzer-until-it-works.patch | 26 - pesign.spec | 13 +- sources | 2 +- 9 files changed, 31 insertions(+), 1263 deletions(-) delete mode 100644 0001-Revert-Move-license-to-GPLv3.patch create mode 100644 0001-daemon-remove-always-true-comparison.patch delete mode 100644 0002-Fix-format-strings-for-32-bit-arches.patch delete mode 100644 0003-macros-drop-_pesign_args.patch delete mode 100644 0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch delete mode 100644 0005-fcf-protection-is-arch-specific.patch delete mode 100644 0006-Disable-analyzer-until-it-works.patch diff --git a/0001-Revert-Move-license-to-GPLv3.patch b/0001-Revert-Move-license-to-GPLv3.patch deleted file mode 100644 index 4e4bec5..0000000 --- a/0001-Revert-Move-license-to-GPLv3.patch +++ /dev/null @@ -1,969 +0,0 @@ -From fc20530a0ef666b49e6276c983d2d16517d3839b Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 1 Feb 2022 15:04:30 -0500 -Subject: [PATCH 1/5] Revert "Move license to GPLv3+" - -This was done too soon. It's missing some pieces and we need buy-in on -a couple of source files. - -This reverts commit 735650258c7956525b7ecf4b67483d025f0500e8. ---- - COPYING | 881 +++++++++++++++++--------------------------------------- - 1 file changed, 272 insertions(+), 609 deletions(-) - -diff --git a/COPYING b/COPYING -index 4432540..d159169 100644 ---- a/COPYING -+++ b/COPYING -@@ -1,627 +1,285 @@ -+ GNU GENERAL PUBLIC LICENSE -+ Version 2, June 1991 - -- GNU GENERAL PUBLIC LICENSE -- Version 3, 29 June 2007 -- -- Copyright (C) 2007 Free Software Foundation, Inc. -+ Copyright (C) 1989, 1991 Free Software Foundation, Inc., -+ 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA - Everyone is permitted to copy and distribute verbatim copies - of this license document, but changing it is not allowed. - -- Preamble -+ Preamble - -- The GNU General Public License is a free, copyleft license for --software and other kinds of works. -- -- The licenses for most software and other practical works are designed --to take away your freedom to share and change the works. By contrast, --the GNU General Public License is intended to guarantee your freedom to --share and change all versions of a program--to make sure it remains free --software for all its users. We, the Free Software Foundation, use the --GNU General Public License for most of our software; it applies also to --any other work released this way by its authors. You can apply it to -+ The licenses for most software are designed to take away your -+freedom to share and change it. By contrast, the GNU General Public -+License is intended to guarantee your freedom to share and change free -+software--to make sure the software is free for all its users. This -+General Public License applies to most of the Free Software -+Foundation's software and to any other program whose authors commit to -+using it. (Some other Free Software Foundation software is covered by -+the GNU Lesser General Public License instead.) You can apply it to - your programs, too. - - When we speak of free software, we are referring to freedom, not - price. Our General Public Licenses are designed to make sure that you - have the freedom to distribute copies of free software (and charge for --them if you wish), that you receive source code or can get it if you --want it, that you can change the software or use pieces of it in new --free programs, and that you know you can do these things. -+this service if you wish), that you receive source code or can get it -+if you want it, that you can change the software or use pieces of it -+in new free programs; and that you know you can do these things. - -- To protect your rights, we need to prevent others from denying you --these rights or asking you to surrender the rights. Therefore, you have --certain responsibilities if you distribute copies of the software, or if --you modify it: responsibilities to respect the freedom of others. -+ To protect your rights, we need to make restrictions that forbid -+anyone to deny you these rights or to ask you to surrender the rights. -+These restrictions translate to certain responsibilities for you if you -+distribute copies of the software, or if you modify it. - - For example, if you distribute copies of such a program, whether --gratis or for a fee, you must pass on to the recipients the same --freedoms that you received. You must make sure that they, too, receive --or can get the source code. And you must show them these terms so they --know their rights. -+gratis or for a fee, you must give the recipients all the rights that -+you have. You must make sure that they, too, receive or can get the -+source code. And you must show them these terms so they know their -+rights. - -- Developers that use the GNU GPL protect your rights with two steps: --(1) assert copyright on the software, and (2) offer you this License --giving you legal permission to copy, distribute and/or modify it. -+ We protect your rights with two steps: (1) copyright the software, and -+(2) offer you this license which gives you legal permission to copy, -+distribute and/or modify the software. - -- For the developers' and authors' protection, the GPL clearly explains --that there is no warranty for this free software. For both users' and --authors' sake, the GPL requires that modified versions be marked as --changed, so that their problems will not be attributed erroneously to --authors of previous versions. -+ Also, for each author's protection and ours, we want to make certain -+that everyone understands that there is no warranty for this free -+software. If the software is modified by someone else and passed on, we -+want its recipients to know that what they have is not the original, so -+that any problems introduced by others will not reflect on the original -+authors' reputations. - -- Some devices are designed to deny users access to install or run --modified versions of the software inside them, although the manufacturer --can do so. This is fundamentally incompatible with the aim of --protecting users' freedom to change the software. The systematic --pattern of such abuse occurs in the area of products for individuals to --use, which is precisely where it is most unacceptable. Therefore, we --have designed this version of the GPL to prohibit the practice for those --products. If such problems arise substantially in other domains, we --stand ready to extend this provision to those domains in future versions --of the GPL, as needed to protect the freedom of users. -- -- Finally, every program is threatened constantly by software patents. --States should not allow patents to restrict development and use of --software on general-purpose computers, but in those that do, we wish to --avoid the special danger that patents applied to a free program could --make it effectively proprietary. To prevent this, the GPL assures that --patents cannot be used to render the program non-free. -+ Finally, any free program is threatened constantly by software -+patents. We wish to avoid the danger that redistributors of a free -+program will individually obtain patent licenses, in effect making the -+program proprietary. To prevent this, we have made it clear that any -+patent must be licensed for everyone's free use or not licensed at all. - - The precise terms and conditions for copying, distribution and - modification follow. - -- TERMS AND CONDITIONS -- -- 0. Definitions. -- -- "This License" refers to version 3 of the GNU General Public License. -- -- "Copyright" also means copyright-like laws that apply to other kinds of --works, such as semiconductor masks. -- -- "The Program" refers to any copyrightable work licensed under this --License. Each licensee is addressed as "you". "Licensees" and --"recipients" may be individuals or organizations. -- -- To "modify" a work means to copy from or adapt all or part of the work --in a fashion requiring copyright permission, other than the making of an --exact copy. The resulting work is called a "modified version" of the --earlier work or a work "based on" the earlier work. -- -- A "covered work" means either the unmodified Program or a work based --on the Program. -- -- To "propagate" a work means to do anything with it that, without --permission, would make you directly or secondarily liable for --infringement under applicable copyright law, except executing it on a --computer or modifying a private copy. Propagation includes copying, --distribution (with or without modification), making available to the --public, and in some countries other activities as well. -- -- To "convey" a work means any kind of propagation that enables other --parties to make or receive copies. Mere interaction with a user through --a computer network, with no transfer of a copy, is not conveying. -- -- An interactive user interface displays "Appropriate Legal Notices" --to the extent that it includes a convenient and prominently visible --feature that (1) displays an appropriate copyright notice, and (2) --tells the user that there is no warranty for the work (except to the --extent that warranties are provided), that licensees may convey the --work under this License, and how to view a copy of this License. If --the interface presents a list of user commands or options, such as a --menu, a prominent item in the list meets this criterion. -- -- 1. Source Code. -- -- The "source code" for a work means the preferred form of the work --for making modifications to it. "Object code" means any non-source --form of a work. -- -- A "Standard Interface" means an interface that either is an official --standard defined by a recognized standards body, or, in the case of --interfaces specified for a particular programming language, one that --is widely used among developers working in that language. -- -- The "System Libraries" of an executable work include anything, other --than the work as a whole, that (a) is included in the normal form of --packaging a Major Component, but which is not part of that Major --Component, and (b) serves only to enable use of the work with that --Major Component, or to implement a Standard Interface for which an --implementation is available to the public in source code form. A --"Major Component", in this context, means a major essential component --(kernel, window system, and so on) of the specific operating system --(if any) on which the executable work runs, or a compiler used to --produce the work, or an object code interpreter used to run it. -- -- The "Corresponding Source" for a work in object code form means all --the source code needed to generate, install, and (for an executable --work) run the object code and to modify the work, including scripts to --control those activities. However, it does not include the work's --System Libraries, or general-purpose tools or generally available free --programs which are used unmodified in performing those activities but --which are not part of the work. For example, Corresponding Source --includes interface definition files associated with source files for --the work, and the source code for shared libraries and dynamically --linked subprograms that the work is specifically designed to require, --such as by intimate data communication or control flow between those --subprograms and other parts of the work. -- -- The Corresponding Source need not include anything that users --can regenerate automatically from other parts of the Corresponding --Source. -- -- The Corresponding Source for a work in source code form is that --same work. -- -- 2. Basic Permissions. -- -- All rights granted under this License are granted for the term of --copyright on the Program, and are irrevocable provided the stated --conditions are met. This License explicitly affirms your unlimited --permission to run the unmodified Program. The output from running a --covered work is covered by this License only if the output, given its --content, constitutes a covered work. This License acknowledges your --rights of fair use or other equivalent, as provided by copyright law. -- -- You may make, run and propagate covered works that you do not --convey, without conditions so long as your license otherwise remains --in force. You may convey covered works to others for the sole purpose --of having them make modifications exclusively for you, or provide you --with facilities for running those works, provided that you comply with --the terms of this License in conveying all material for which you do --not control copyright. Those thus making or running the covered works --for you must do so exclusively on your behalf, under your direction --and control, on terms that prohibit them from making any copies of --your copyrighted material outside their relationship with you. -- -- Conveying under any other circumstances is permitted solely under --the conditions stated below. Sublicensing is not allowed; section 10 --makes it unnecessary. -- -- 3. Protecting Users' Legal Rights From Anti-Circumvention Law. -- -- No covered work shall be deemed part of an effective technological --measure under any applicable law fulfilling obligations under article --11 of the WIPO copyright treaty adopted on 20 December 1996, or --similar laws prohibiting or restricting circumvention of such --measures. -- -- When you convey a covered work, you waive any legal power to forbid --circumvention of technological measures to the extent such circumvention --is effected by exercising rights under this License with respect to --the covered work, and you disclaim any intention to limit operation or --modification of the work as a means of enforcing, against the work's --users, your or third parties' legal rights to forbid circumvention of --technological measures. -- -- 4. Conveying Verbatim Copies. -- -- You may convey verbatim copies of the Program's source code as you --receive it, in any medium, provided that you conspicuously and --appropriately publish on each copy an appropriate copyright notice; --keep intact all notices stating that this License and any --non-permissive terms added in accord with section 7 apply to the code; --keep intact all notices of the absence of any warranty; and give all --recipients a copy of this License along with the Program. -- -- You may charge any price or no price for each copy that you convey, --and you may offer support or warranty protection for a fee. -- -- 5. Conveying Modified Source Versions. -- -- You may convey a work based on the Program, or the modifications to --produce it from the Program, in the form of source code under the --terms of section 4, provided that you also meet all of these conditions: -- -- a) The work must carry prominent notices stating that you modified -- it, and giving a relevant date. -- -- b) The work must carry prominent notices stating that it is -- released under this License and any conditions added under section -- 7. This requirement modifies the requirement in section 4 to -- "keep intact all notices". -- -- c) You must license the entire work, as a whole, under this -- License to anyone who comes into possession of a copy. This -- License will therefore apply, along with any applicable section 7 -- additional terms, to the whole of the work, and all its parts, -- regardless of how they are packaged. This License gives no -- permission to license the work in any other way, but it does not -- invalidate such permission if you have separately received it. -- -- d) If the work has interactive user interfaces, each must display -- Appropriate Legal Notices; however, if the Program has interactive -- interfaces that do not display Appropriate Legal Notices, your -- work need not make them do so. -- -- A compilation of a covered work with other separate and independent --works, which are not by their nature extensions of the covered work, --and which are not combined with it such as to form a larger program, --in or on a volume of a storage or distribution medium, is called an --"aggregate" if the compilation and its resulting copyright are not --used to limit the access or legal rights of the compilation's users --beyond what the individual works permit. Inclusion of a covered work --in an aggregate does not cause this License to apply to the other --parts of the aggregate. -- -- 6. Conveying Non-Source Forms. -- -- You may convey a covered work in object code form under the terms --of sections 4 and 5, provided that you also convey the --machine-readable Corresponding Source under the terms of this License, --in one of these ways: -- -- a) Convey the object code in, or embodied in, a physical product -- (including a physical distribution medium), accompanied by the -- Corresponding Source fixed on a durable physical medium -- customarily used for software interchange. -- -- b) Convey the object code in, or embodied in, a physical product -- (including a physical distribution medium), accompanied by a -- written offer, valid for at least three years and valid for as -- long as you offer spare parts or customer support for that product -- model, to give anyone who possesses the object code either (1) a -- copy of the Corresponding Source for all the software in the -- product that is covered by this License, on a durable physical -- medium customarily used for software interchange, for a price no -- more than your reasonable cost of physically performing this -- conveying of source, or (2) access to copy the -- Corresponding Source from a network server at no charge. -- -- c) Convey individual copies of the object code with a copy of the -- written offer to provide the Corresponding Source. This -- alternative is allowed only occasionally and noncommercially, and -- only if you received the object code with such an offer, in accord -- with subsection 6b. -- -- d) Convey the object code by offering access from a designated -- place (gratis or for a charge), and offer equivalent access to the -- Corresponding Source in the same way through the same place at no -- further charge. You need not require recipients to copy the -- Corresponding Source along with the object code. If the place to -- copy the object code is a network server, the Corresponding Source -- may be on a different server (operated by you or a third party) -- that supports equivalent copying facilities, provided you maintain -- clear directions next to the object code saying where to find the -- Corresponding Source. Regardless of what server hosts the -- Corresponding Source, you remain obligated to ensure that it is -- available for as long as needed to satisfy these requirements. -- -- e) Convey the object code using peer-to-peer transmission, provided -- you inform other peers where the object code and Corresponding -- Source of the work are being offered to the general public at no -- charge under subsection 6d. -- -- A separable portion of the object code, whose source code is excluded --from the Corresponding Source as a System Library, need not be --included in conveying the object code work. -- -- A "User Product" is either (1) a "consumer product", which means any --tangible personal property which is normally used for personal, family, --or household purposes, or (2) anything designed or sold for incorporation --into a dwelling. In determining whether a product is a consumer product, --doubtful cases shall be resolved in favor of coverage. For a particular --product received by a particular user, "normally used" refers to a --typical or common use of that class of product, regardless of the status --of the particular user or of the way in which the particular user --actually uses, or expects or is expected to use, the product. A product --is a consumer product regardless of whether the product has substantial --commercial, industrial or non-consumer uses, unless such uses represent --the only significant mode of use of the product. -- -- "Installation Information" for a User Product means any methods, --procedures, authorization keys, or other information required to install --and execute modified versions of a covered work in that User Product from --a modified version of its Corresponding Source. The information must --suffice to ensure that the continued functioning of the modified object --code is in no case prevented or interfered with solely because --modification has been made. -- -- If you convey an object code work under this section in, or with, or --specifically for use in, a User Product, and the conveying occurs as --part of a transaction in which the right of possession and use of the --User Product is transferred to the recipient in perpetuity or for a --fixed term (regardless of how the transaction is characterized), the --Corresponding Source conveyed under this section must be accompanied --by the Installation Information. But this requirement does not apply --if neither you nor any third party retains the ability to install --modified object code on the User Product (for example, the work has --been installed in ROM). -- -- The requirement to provide Installation Information does not include a --requirement to continue to provide support service, warranty, or updates --for a work that has been modified or installed by the recipient, or for --the User Product in which it has been modified or installed. Access to a --network may be denied when the modification itself materially and --adversely affects the operation of the network or violates the rules and --protocols for communication across the network. -- -- Corresponding Source conveyed, and Installation Information provided, --in accord with this section must be in a format that is publicly --documented (and with an implementation available to the public in --source code form), and must require no special password or key for --unpacking, reading or copying. -- -- 7. Additional Terms. -- -- "Additional permissions" are terms that supplement the terms of this --License by making exceptions from one or more of its conditions. --Additional permissions that are applicable to the entire Program shall --be treated as though they were included in this License, to the extent --that they are valid under applicable law. If additional permissions --apply only to part of the Program, that part may be used separately --under those permissions, but the entire Program remains governed by --this License without regard to the additional permissions. -- -- When you convey a copy of a covered work, you may at your option --remove any additional permissions from that copy, or from any part of --it. (Additional permissions may be written to require their own --removal in certain cases when you modify the work.) You may place --additional permissions on material, added by you to a covered work, --for which you have or can give appropriate copyright permission. -- -- Notwithstanding any other provision of this License, for material you --add to a covered work, you may (if authorized by the copyright holders of --that material) supplement the terms of this License with terms: -- -- a) Disclaiming warranty or limiting liability differently from the -- terms of sections 15 and 16 of this License; or -- -- b) Requiring preservation of specified reasonable legal notices or -- author attributions in that material or in the Appropriate Legal -- Notices displayed by works containing it; or -- -- c) Prohibiting misrepresentation of the origin of that material, or -- requiring that modified versions of such material be marked in -- reasonable ways as different from the original version; or -- -- d) Limiting the use for publicity purposes of names of licensors or -- authors of the material; or -- -- e) Declining to grant rights under trademark law for use of some -- trade names, trademarks, or service marks; or -- -- f) Requiring indemnification of licensors and authors of that -- material by anyone who conveys the material (or modified versions of -- it) with contractual assumptions of liability to the recipient, for -- any liability that these contractual assumptions directly impose on -- those licensors and authors. -- -- All other non-permissive additional terms are considered "further --restrictions" within the meaning of section 10. If the Program as you --received it, or any part of it, contains a notice stating that it is --governed by this License along with a term that is a further --restriction, you may remove that term. If a license document contains --a further restriction but permits relicensing or conveying under this --License, you may add to a covered work material governed by the terms --of that license document, provided that the further restriction does --not survive such relicensing or conveying. -- -- If you add terms to a covered work in accord with this section, you --must place, in the relevant source files, a statement of the --additional terms that apply to those files, or a notice indicating --where to find the applicable terms. -- -- Additional terms, permissive or non-permissive, may be stated in the --form of a separately written license, or stated as exceptions; --the above requirements apply either way. -- -- 8. Termination. -- -- You may not propagate or modify a covered work except as expressly --provided under this License. Any attempt otherwise to propagate or --modify it is void, and will automatically terminate your rights under --this License (including any patent licenses granted under the third --paragraph of section 11). -- -- However, if you cease all violation of this License, then your --license from a particular copyright holder is reinstated (a) --provisionally, unless and until the copyright holder explicitly and --finally terminates your license, and (b) permanently, if the copyright --holder fails to notify you of the violation by some reasonable means --prior to 60 days after the cessation. -- -- Moreover, your license from a particular copyright holder is --reinstated permanently if the copyright holder notifies you of the --violation by some reasonable means, this is the first time you have --received notice of violation of this License (for any work) from that --copyright holder, and you cure the violation prior to 30 days after --your receipt of the notice. -- -- Termination of your rights under this section does not terminate the --licenses of parties who have received copies or rights from you under --this License. If your rights have been terminated and not permanently --reinstated, you do not qualify to receive new licenses for the same --material under section 10. -- -- 9. Acceptance Not Required for Having Copies. -- -- You are not required to accept this License in order to receive or --run a copy of the Program. Ancillary propagation of a covered work --occurring solely as a consequence of using peer-to-peer transmission --to receive a copy likewise does not require acceptance. However, --nothing other than this License grants you permission to propagate or --modify any covered work. These actions infringe copyright if you do --not accept this License. Therefore, by modifying or propagating a --covered work, you indicate your acceptance of this License to do so. -- -- 10. Automatic Licensing of Downstream Recipients. -- -- Each time you convey a covered work, the recipient automatically --receives a license from the original licensors, to run, modify and --propagate that work, subject to this License. You are not responsible --for enforcing compliance by third parties with this License. -- -- An "entity transaction" is a transaction transferring control of an --organization, or substantially all assets of one, or subdividing an --organization, or merging organizations. If propagation of a covered --work results from an entity transaction, each party to that --transaction who receives a copy of the work also receives whatever --licenses to the work the party's predecessor in interest had or could --give under the previous paragraph, plus a right to possession of the --Corresponding Source of the work from the predecessor in interest, if --the predecessor has it or can get it with reasonable efforts. -- -- You may not impose any further restrictions on the exercise of the --rights granted or affirmed under this License. For example, you may --not impose a license fee, royalty, or other charge for exercise of --rights granted under this License, and you may not initiate litigation --(including a cross-claim or counterclaim in a lawsuit) alleging that --any patent claim is infringed by making, using, selling, offering for --sale, or importing the Program or any portion of it. -- -- 11. Patents. -- -- A "contributor" is a copyright holder who authorizes use under this --License of the Program or a work on which the Program is based. The --work thus licensed is called the contributor's "contributor version". -- -- A contributor's "essential patent claims" are all patent claims --owned or controlled by the contributor, whether already acquired or --hereafter acquired, that would be infringed by some manner, permitted --by this License, of making, using, or selling its contributor version, --but do not include claims that would be infringed only as a --consequence of further modification of the contributor version. For --purposes of this definition, "control" includes the right to grant --patent sublicenses in a manner consistent with the requirements of -+ GNU GENERAL PUBLIC LICENSE -+ TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION -+ -+ 0. This License applies to any program or other work which contains -+a notice placed by the copyright holder saying it may be distributed -+under the terms of this General Public License. The "Program", below, -+refers to any such program or work, and a "work based on the Program" -+means either the Program or any derivative work under copyright law: -+that is to say, a work containing the Program or a portion of it, -+either verbatim or with modifications and/or translated into another -+language. (Hereinafter, translation is included without limitation in -+the term "modification".) Each licensee is addressed as "you". -+ -+Activities other than copying, distribution and modification are not -+covered by this License; they are outside its scope. The act of -+running the Program is not restricted, and the output from the Program -+is covered only if its contents constitute a work based on the -+Program (independent of having been made by running the Program). -+Whether that is true depends on what the Program does. -+ -+ 1. You may copy and distribute verbatim copies of the Program's -+source code as you receive it, in any medium, provided that you -+conspicuously and appropriately publish on each copy an appropriate -+copyright notice and disclaimer of warranty; keep intact all the -+notices that refer to this License and to the absence of any warranty; -+and give any other recipients of the Program a copy of this License -+along with the Program. -+ -+You may charge a fee for the physical act of transferring a copy, and -+you may at your option offer warranty protection in exchange for a fee. -+ -+ 2. You may modify your copy or copies of the Program or any portion -+of it, thus forming a work based on the Program, and copy and -+distribute such modifications or work under the terms of Section 1 -+above, provided that you also meet all of these conditions: -+ -+ a) You must cause the modified files to carry prominent notices -+ stating that you changed the files and the date of any change. -+ -+ b) You must cause any work that you distribute or publish, that in -+ whole or in part contains or is derived from the Program or any -+ part thereof, to be licensed as a whole at no charge to all third -+ parties under the terms of this License. -+ -+ c) If the modified program normally reads commands interactively -+ when run, you must cause it, when started running for such -+ interactive use in the most ordinary way, to print or display an -+ announcement including an appropriate copyright notice and a -+ notice that there is no warranty (or else, saying that you provide -+ a warranty) and that users may redistribute the program under -+ these conditions, and telling the user how to view a copy of this -+ License. (Exception: if the Program itself is interactive but -+ does not normally print such an announcement, your work based on -+ the Program is not required to print an announcement.) -+ -+These requirements apply to the modified work as a whole. If -+identifiable sections of that work are not derived from the Program, -+and can be reasonably considered independent and separate works in -+themselves, then this License, and its terms, do not apply to those -+sections when you distribute them as separate works. But when you -+distribute the same sections as part of a whole which is a work based -+on the Program, the distribution of the whole must be on the terms of -+this License, whose permissions for other licensees extend to the -+entire whole, and thus to each and every part regardless of who wrote it. -+ -+Thus, it is not the intent of this section to claim rights or contest -+your rights to work written entirely by you; rather, the intent is to -+exercise the right to control the distribution of derivative or -+collective works based on the Program. -+ -+In addition, mere aggregation of another work not based on the Program -+with the Program (or with a work based on the Program) on a volume of -+a storage or distribution medium does not bring the other work under -+the scope of this License. -+ -+ 3. You may copy and distribute the Program (or a work based on it, -+under Section 2) in object code or executable form under the terms of -+Sections 1 and 2 above provided that you also do one of the following: -+ -+ a) Accompany it with the complete corresponding machine-readable -+ source code, which must be distributed under the terms of Sections -+ 1 and 2 above on a medium customarily used for software interchange; or, -+ -+ b) Accompany it with a written offer, valid for at least three -+ years, to give any third party, for a charge no more than your -+ cost of physically performing source distribution, a complete -+ machine-readable copy of the corresponding source code, to be -+ distributed under the terms of Sections 1 and 2 above on a medium -+ customarily used for software interchange; or, -+ -+ c) Accompany it with the information you received as to the offer -+ to distribute corresponding source code. (This alternative is -+ allowed only for noncommercial distribution and only if you -+ received the program in object code or executable form with such -+ an offer, in accord with Subsection b above.) -+ -+The source code for a work means the preferred form of the work for -+making modifications to it. For an executable work, complete source -+code means all the source code for all modules it contains, plus any -+associated interface definition files, plus the scripts used to -+control compilation and installation of the executable. However, as a -+special exception, the source code distributed need not include -+anything that is normally distributed (in either source or binary -+form) with the major components (compiler, kernel, and so on) of the -+operating system on which the executable runs, unless that component -+itself accompanies the executable. -+ -+If distribution of executable or object code is made by offering -+access to copy from a designated place, then offering equivalent -+access to copy the source code from the same place counts as -+distribution of the source code, even though third parties are not -+compelled to copy the source along with the object code. -+ -+ 4. You may not copy, modify, sublicense, or distribute the Program -+except as expressly provided under this License. Any attempt -+otherwise to copy, modify, sublicense or distribute the Program is -+void, and will automatically terminate your rights under this License. -+However, parties who have received copies, or rights, from you under -+this License will not have their licenses terminated so long as such -+parties remain in full compliance. -+ -+ 5. You are not required to accept this License, since you have not -+signed it. However, nothing else grants you permission to modify or -+distribute the Program or its derivative works. These actions are -+prohibited by law if you do not accept this License. Therefore, by -+modifying or distributing the Program (or any work based on the -+Program), you indicate your acceptance of this License to do so, and -+all its terms and conditions for copying, distributing or modifying -+the Program or works based on it. -+ -+ 6. Each time you redistribute the Program (or any work based on the -+Program), the recipient automatically receives a license from the -+original licensor to copy, distribute or modify the Program subject to -+these terms and conditions. You may not impose any further -+restrictions on the recipients' exercise of the rights granted herein. -+You are not responsible for enforcing compliance by third parties to - this License. - -- Each contributor grants you a non-exclusive, worldwide, royalty-free --patent license under the contributor's essential patent claims, to --make, use, sell, offer for sale, import and otherwise run, modify and --propagate the contents of its contributor version. -- -- In the following three paragraphs, a "patent license" is any express --agreement or commitment, however denominated, not to enforce a patent --(such as an express permission to practice a patent or covenant not to --sue for patent infringement). To "grant" such a patent license to a --party means to make such an agreement or commitment not to enforce a --patent against the party. -- -- If you convey a covered work, knowingly relying on a patent license, --and the Corresponding Source of the work is not available for anyone --to copy, free of charge and under the terms of this License, through a --publicly available network server or other readily accessible means, --then you must either (1) cause the Corresponding Source to be so --available, or (2) arrange to deprive yourself of the benefit of the --patent license for this particular work, or (3) arrange, in a manner --consistent with the requirements of this License, to extend the patent --license to downstream recipients. "Knowingly relying" means you have --actual knowledge that, but for the patent license, your conveying the --covered work in a country, or your recipient's use of the covered work --in a country, would infringe one or more identifiable patents in that --country that you have reason to believe are valid. -- -- If, pursuant to or in connection with a single transaction or --arrangement, you convey, or propagate by procuring conveyance of, a --covered work, and grant a patent license to some of the parties --receiving the covered work authorizing them to use, propagate, modify --or convey a specific copy of the covered work, then the patent license --you grant is automatically extended to all recipients of the covered --work and works based on it. -- -- A patent license is "discriminatory" if it does not include within --the scope of its coverage, prohibits the exercise of, or is --conditioned on the non-exercise of one or more of the rights that are --specifically granted under this License. You may not convey a covered --work if you are a party to an arrangement with a third party that is --in the business of distributing software, under which you make payment --to the third party based on the extent of your activity of conveying --the work, and under which the third party grants, to any of the --parties who would receive the covered work from you, a discriminatory --patent license (a) in connection with copies of the covered work --conveyed by you (or copies made from those copies), or (b) primarily --for and in connection with specific products or compilations that --contain the covered work, unless you entered into that arrangement, --or that patent license was granted, prior to 28 March 2007. -- -- Nothing in this License shall be construed as excluding or limiting --any implied license or other defenses to infringement that may --otherwise be available to you under applicable patent law. -- -- 12. No Surrender of Others' Freedom. -- -- If conditions are imposed on you (whether by court order, agreement or -+ 7. If, as a consequence of a court judgment or allegation of patent -+infringement or for any other reason (not limited to patent issues), -+conditions are imposed on you (whether by court order, agreement or - otherwise) that contradict the conditions of this License, they do not --excuse you from the conditions of this License. If you cannot convey a --covered work so as to satisfy simultaneously your obligations under this --License and any other pertinent obligations, then as a consequence you may --not convey it at all. For example, if you agree to terms that obligate you --to collect a royalty for further conveying from those to whom you convey --the Program, the only way you could satisfy both those terms and this --License would be to refrain entirely from conveying the Program. -+excuse you from the conditions of this License. If you cannot -+distribute so as to satisfy simultaneously your obligations under this -+License and any other pertinent obligations, then as a consequence you -+may not distribute the Program at all. For example, if a patent -+license would not permit royalty-free redistribution of the Program by -+all those who receive copies directly or indirectly through you, then -+the only way you could satisfy both it and this License would be to -+refrain entirely from distribution of the Program. - -- 13. Use with the GNU Affero General Public License. -+If any portion of this section is held invalid or unenforceable under -+any particular circumstance, the balance of the section is intended to -+apply and the section as a whole is intended to apply in other -+circumstances. - -- Notwithstanding any other provision of this License, you have --permission to link or combine any covered work with a work licensed --under version 3 of the GNU Affero General Public License into a single --combined work, and to convey the resulting work. The terms of this --License will continue to apply to the part which is the covered work, --but the special requirements of the GNU Affero General Public License, --section 13, concerning interaction through a network will apply to the --combination as such. -+It is not the purpose of this section to induce you to infringe any -+patents or other property right claims or to contest validity of any -+such claims; this section has the sole purpose of protecting the -+integrity of the free software distribution system, which is -+implemented by public license practices. Many people have made -+generous contributions to the wide range of software distributed -+through that system in reliance on consistent application of that -+system; it is up to the author/donor to decide if he or she is willing -+to distribute software through any other system and a licensee cannot -+impose that choice. - -- 14. Revised Versions of this License. -+This section is intended to make thoroughly clear what is believed to -+be a consequence of the rest of this License. - -- The Free Software Foundation may publish revised and/or new versions of --the GNU General Public License from time to time. Such new versions will -+ 8. If the distribution and/or use of the Program is restricted in -+certain countries either by patents or by copyrighted interfaces, the -+original copyright holder who places the Program under this License -+may add an explicit geographical distribution limitation excluding -+those countries, so that distribution is permitted only in or among -+countries not thus excluded. In such case, this License incorporates -+the limitation as if written in the body of this License. -+ -+ 9. The Free Software Foundation may publish revised and/or new versions -+of the General Public License from time to time. Such new versions will - be similar in spirit to the present version, but may differ in detail to - address new problems or concerns. - -- Each version is given a distinguishing version number. If the --Program specifies that a certain numbered version of the GNU General --Public License "or any later version" applies to it, you have the --option of following the terms and conditions either of that numbered --version or of any later version published by the Free Software --Foundation. If the Program does not specify a version number of the --GNU General Public License, you may choose any version ever published --by the Free Software Foundation. -+Each version is given a distinguishing version number. If the Program -+specifies a version number of this License which applies to it and "any -+later version", you have the option of following the terms and conditions -+either of that version or of any later version published by the Free -+Software Foundation. If the Program does not specify a version number of -+this License, you may choose any version ever published by the Free Software -+Foundation. - -- If the Program specifies that a proxy can decide which future --versions of the GNU General Public License can be used, that proxy's --public statement of acceptance of a version permanently authorizes you --to choose that version for the Program. -+ 10. If you wish to incorporate parts of the Program into other free -+programs whose distribution conditions are different, write to the author -+to ask for permission. For software which is copyrighted by the Free -+Software Foundation, write to the Free Software Foundation; we sometimes -+make exceptions for this. Our decision will be guided by the two goals -+of preserving the free status of all derivatives of our free software and -+of promoting the sharing and reuse of software generally. - -- Later license versions may give you additional or different --permissions. However, no additional obligations are imposed on any --author or copyright holder as a result of your choosing to follow a --later version. -+ NO WARRANTY - -- 15. Disclaimer of Warranty. -+ 11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY -+FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN -+OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES -+PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED -+OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF -+MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS -+TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE -+PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, -+REPAIR OR CORRECTION. - -- THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY --APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT --HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY --OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, --THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR --PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM --IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF --ALL NECESSARY SERVICING, REPAIR OR CORRECTION. -+ 12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING -+WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR -+REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, -+INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING -+OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED -+TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY -+YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER -+PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE -+POSSIBILITY OF SUCH DAMAGES. - -- 16. Limitation of Liability. -+ END OF TERMS AND CONDITIONS - -- IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING --WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS --THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY --GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE --USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF --DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD --PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), --EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF --SUCH DAMAGES. -- -- 17. Interpretation of Sections 15 and 16. -- -- If the disclaimer of warranty and limitation of liability provided --above cannot be given local legal effect according to their terms, --reviewing courts shall apply local law that most closely approximates --an absolute waiver of all civil liability in connection with the --Program, unless a warranty or assumption of liability accompanies a --copy of the Program in return for a fee. -- -- END OF TERMS AND CONDITIONS -- -- How to Apply These Terms to Your New Programs -+ How to Apply These Terms to Your New Programs - - If you develop a new program, and you want it to be of the greatest - possible use to the public, the best way to achieve this is to make it -@@ -629,15 +287,15 @@ free software which everyone can redistribute and change under these terms. - - To do so, attach the following notices to the program. It is safest - to attach them to the start of each source file to most effectively --state the exclusion of warranty; and each file should have at least -+convey the exclusion of warranty; and each file should have at least - the "copyright" line and a pointer to where the full notice is found. - - - Copyright (C) - -- This program is free software: you can redistribute it and/or modify -+ This program is free software; you can redistribute it and/or modify - it under the terms of the GNU General Public License as published by -- the Free Software Foundation, either version 3 of the License, or -+ the Free Software Foundation; either version 2 of the License, or - (at your option) any later version. - - This program is distributed in the hope that it will be useful, -@@ -645,32 +303,37 @@ the "copyright" line and a pointer to where the full notice is found. - MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the - GNU General Public License for more details. - -- You should have received a copy of the GNU General Public License -- along with this program. If not, see . -+ You should have received a copy of the GNU General Public License along -+ with this program; if not, write to the Free Software Foundation, Inc., -+ 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. - - Also add information on how to contact you by electronic and paper mail. - -- If the program does terminal interaction, make it output a short --notice like this when it starts in an interactive mode: -+If the program is interactive, make it output a short notice like this -+when it starts in an interactive mode: - -- Copyright (C) -- This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'. -+ Gnomovision version 69, Copyright (C) year name of author -+ Gnomovision comes with ABSOLUTELY NO WARRANTY; for details type `show w'. - This is free software, and you are welcome to redistribute it - under certain conditions; type `show c' for details. - - The hypothetical commands `show w' and `show c' should show the appropriate --parts of the General Public License. Of course, your program's commands --might be different; for a GUI interface, you would use an "about box". -+parts of the General Public License. Of course, the commands you use may -+be called something other than `show w' and `show c'; they could even be -+mouse-clicks or menu items--whatever suits your program. - -- You should also get your employer (if you work as a programmer) or school, --if any, to sign a "copyright disclaimer" for the program, if necessary. --For more information on this, and how to apply and follow the GNU GPL, see --. -+You should also get your employer (if you work as a programmer) or your -+school, if any, to sign a "copyright disclaimer" for the program, if -+necessary. Here is a sample; alter the names: - -- The GNU General Public License does not permit incorporating your program --into proprietary programs. If your program is a subroutine library, you --may consider it more useful to permit linking proprietary applications with --the library. If this is what you want to do, use the GNU Lesser General --Public License instead of this License. But first, please read --. -+ Yoyodyne, Inc., hereby disclaims all copyright interest in the program -+ `Gnomovision' (which makes passes at compilers) written by James Hacker. - -+ , 1 April 1989 -+ Ty Coon, President of Vice -+ -+This General Public License does not permit incorporating your program into -+proprietary programs. If your program is a subroutine library, you may -+consider it more useful to permit linking proprietary applications with the -+library. If this is what you want to do, use the GNU Lesser General -+Public License instead of this License. --- -2.34.1 - diff --git a/0001-daemon-remove-always-true-comparison.patch b/0001-daemon-remove-always-true-comparison.patch new file mode 100644 index 0000000..cbb5d32 --- /dev/null +++ b/0001-daemon-remove-always-true-comparison.patch @@ -0,0 +1,24 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 8 Mar 2022 12:59:34 -0500 +Subject: [PATCH] daemon: remove always-true comparison + +Signed-off-by: Robbie Harwood +--- + src/daemon.c | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +diff --git a/src/daemon.c b/src/daemon.c +index 0a66deb..ff88210 100644 +--- a/src/daemon.c ++++ b/src/daemon.c +@@ -221,8 +221,7 @@ malformed: + if (!ctx->cms->tokenname) + goto oom; + +- if (!tp->value) +- pin = strndup((char *)tp->value, tp->size); ++ pin = strndup((char *)tp->value, tp->size); + if (!pin) + goto oom; + diff --git a/0002-Fix-format-strings-for-32-bit-arches.patch b/0002-Fix-format-strings-for-32-bit-arches.patch deleted file mode 100644 index 1aaab2d..0000000 --- a/0002-Fix-format-strings-for-32-bit-arches.patch +++ /dev/null @@ -1,112 +0,0 @@ -From df8783ed4ed87fef850268098690985049916ee9 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 1 Feb 2022 17:37:14 -0500 -Subject: [PATCH 2/5] Fix format strings for 32-bit arches - -Sadly, in 2022, this remains a thing. - -Signed-off-by: Robbie Harwood ---- - src/cms_pe_common.c | 16 +++++++++------- - src/password.c | 7 ++++--- - 2 files changed, 13 insertions(+), 10 deletions(-) - -diff --git a/src/cms_pe_common.c b/src/cms_pe_common.c -index 964f0d9..3a3921b 100644 ---- a/src/cms_pe_common.c -+++ b/src/cms_pe_common.c -@@ -49,7 +49,7 @@ check_pointer_and_size(cms_context *cms, Pe *pe, void *ptr, size_t size) - - if (p + size > m + map_size) - cmsreterr(0, cms, -- "pointer %p is above mmap end at %p (%lu is %lu bytes past EOF at %lu)", -+ "pointer %p is above mmap end at %p (%lu is %lu bytes past EOF at %zu)", - (void *)((uintptr_t)p + size), - (void *)((uintptr_t)m + map_size), - p + size - m, -@@ -189,7 +189,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - if (!check_pointer_and_size(cms, pe, hash_base, hash_size)) - cmsgotoerr(error, cms, "PE header is invalid"); - dprintf("beginning of hash"); -- dprintf("digesting %lx + %lx", hash_base - map, hash_size); -+ dprintf("digesting %tx + %zx", hash_base - map, hash_size); - generate_digest_step(cms, hash_base, hash_size); - - /* 5. Skip over the image checksum -@@ -209,7 +209,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - cmsgotoerr(error, cms, "PE data directory is invalid"); - - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %lx + %lx", hash_base - map, hash_size); -+ dprintf("digesting %tx + %zx", hash_base - map, hash_size); - - /* 8. Skip over the crt dir - * 9. Hash everything up to the end of the image header. */ -@@ -222,7 +222,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - cmsgotoerr(error, cms, "PE relocations table is invalid"); - - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %lx + %lx", hash_base - map, hash_size); -+ dprintf("digesting %tx + %zx", hash_base - map, hash_size); - - /* 10. Set SUM_OF_BYTES_HASHED to the size of the header. */ - hashed_bytes = pe32opthdr ? pe32opthdr->header_size -@@ -265,7 +265,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - } - - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %lx + %lx", hash_base - map, hash_size); -+ dprintf("digesting %tx + %zx", hash_base - map, hash_size); - - hashed_bytes += hash_size; - } -@@ -285,10 +285,12 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - memset(tmp_array, '\0', tmp_size); - memcpy(tmp_array, hash_base, hash_size); - generate_digest_step(cms, tmp_array, tmp_size); -- dprintf("digesting %lx + %lx", (unsigned long)tmp_array, tmp_size); -+ dprintf("digesting %tx + %zx", (ptrdiff_t)tmp_array, -+ tmp_size); - } else { - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %lx + %lx", hash_base - map, hash_size); -+ dprintf("digesting %tx + %zx", hash_base - map, -+ hash_size); - } - } - dprintf("end of hash"); -diff --git a/src/password.c b/src/password.c -index 644f362..05add9a 100644 ---- a/src/password.c -+++ b/src/password.c -@@ -213,7 +213,7 @@ parse_pwfile_line(char *start, struct token_pass *tp) - dprintf("non-whitespace span is %zd", span); - - if (line[span] == '\0') { -- dprintf("returning %ld", (line + span) - start); -+ dprintf("returning %td", (line + span) - start); - return (line + span) - start; - } - line[span] = '\0'; -@@ -241,7 +241,7 @@ parse_pwfile_line(char *start, struct token_pass *tp) - dprintf("Setting token pass %p to { %p, %p }", tp, tp->token, tp->pass); - dprintf("token:\"%s\"", tp->token); - dprintf("pass:\"%s\"", tp->pass); -- dprintf("returning %ld", (line + span) - start); -+ dprintf("returning %td", (line + span) - start); - return (line + span) - start; - } - -@@ -330,7 +330,8 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) - if (c != '\0') - span++; - start += span; -- dprintf("start is file[%ld] == '\\x%02hhx'", start - file, start[0]); -+ dprintf("start is file[%td] == '\\x%02hhx'", start - file, -+ start[0]); - } - - qsort(phrases, nphrases, sizeof(struct token_pass), token_pass_cmp); --- -2.34.1 - diff --git a/0003-macros-drop-_pesign_args.patch b/0003-macros-drop-_pesign_args.patch deleted file mode 100644 index 40a7bf5..0000000 --- a/0003-macros-drop-_pesign_args.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 389decab7b9bcba307e52709b00741a19405f02b Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 2 Feb 2022 16:07:46 -0500 -Subject: [PATCH 3/5] macros: drop %{_pesign_args} - -Effectively reverts 30b488682a92c524bb9c0d450c34e9abc0b56de9 - -Also, make our argument parser fail on extra arguments to make it easier -to debug when this kind of thing happens again. - -Signed-off-by: Robbie Harwood ---- - src/macros.pesign | 1 - - src/pesign-rpmbuild-helper.in | 5 +++++ - 2 files changed, 5 insertions(+), 1 deletion(-) - -diff --git a/src/macros.pesign b/src/macros.pesign -index 519a8a3..34af57c 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -27,7 +27,6 @@ - %{_libexecdir}/pesign/pesign-rpmbuild-helper \\\ - "%{_target_cpu}" \\\ - "%{_pesign}" \\\ -- "%{_pesign_args}" \\\ - "%{_pesign_client}" \\\ - %{?__pesign_client_token:--client-token %{__pesign_client_token}} \\\ - %{?__pesign_client_cert:--client-cert %{__pesign_client_cert}} \\\ -diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in -index 27b8261..0a845d2 100644 ---- a/src/pesign-rpmbuild-helper.in -+++ b/src/pesign-rpmbuild-helper.in -@@ -133,6 +133,11 @@ main() { - sign=-s - shift - fi -+ if [[ $# -ge 1 ]] ; then -+ echo "$# extra unparsed arguments!">>/dev/stderr -+ echo "Cowardly refusing to run">>/dev/stderr -+ exit 1 -+ fi - - if [[ -z "${target_cpu}" ]] ; then - target_cpu="$(uname -m)" --- -2.34.1 - diff --git a/0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch b/0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch deleted file mode 100644 index f36d1e0..0000000 --- a/0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch +++ /dev/null @@ -1,55 +0,0 @@ -From 4d1ead068248b56ecaeb437f0c0b59f9d89b9748 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 14 Feb 2022 15:46:25 -0500 -Subject: [PATCH 4/5] Handle NULL pwdata in cms_set_pw_data() - -When 12f16710ee44ef64ddb044a3523c3c4c4d90039a rewrote this function, it -didn't handle the NULL pwdata invocation from daemon.c. This leads to a -explicit NULL dereference and crash on all attempts to daemonize pesign. - -Signed-off-by: Robbie Harwood -(cherry picked from commit b879dda52f8122de697d145977c285fb0a022d76) ---- - src/cms_common.c | 18 ++++++++++++------ - 1 file changed, 12 insertions(+), 6 deletions(-) - -diff --git a/src/cms_common.c b/src/cms_common.c -index 332999e..ca37e6a 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -313,7 +313,7 @@ void cms_set_pw_data(cms_context *cms, secuPWData *pwdata) - - case PW_FROMFD: - if (cms->pwdata.intdata >= 0 && -- !(pwdata->source == PW_FROMFD && -+ !(pwdata && pwdata->source == PW_FROMFD && - cms->pwdata.intdata == pwdata->intdata)) - close(cms->pwdata.intdata); - break; -@@ -330,12 +330,18 @@ void cms_set_pw_data(cms_context *cms, secuPWData *pwdata) - xfree(cms->pwdata.data); - break; - } -- memmove(&cms->pwdata, pwdata, sizeof(*pwdata)); - -- dprintf("pwdata:%p", pwdata); -- dprintf("pwdata->source:%d", pwdata->source); -- dprintf("pwdata->data:%p (\"%s\")", pwdata->data, -- pwdata->data ? pwdata->data : "(null)"); -+ if (!pwdata) { -+ cms->pwdata.source = PW_SOURCE_INVALID; -+ dprintf("pwdata:NULL"); -+ } else { -+ memmove(&cms->pwdata, pwdata, sizeof(*pwdata)); -+ dprintf("pwdata:%p", pwdata); -+ dprintf("pwdata->source:%d", pwdata->source); -+ dprintf("pwdata->data:%p (\"%s\")", pwdata->data, -+ pwdata->data ? pwdata->data : "(null)"); -+ } -+ - egress(); - } - --- -2.34.1 - diff --git a/0005-fcf-protection-is-arch-specific.patch b/0005-fcf-protection-is-arch-specific.patch deleted file mode 100644 index 84093bf..0000000 --- a/0005-fcf-protection-is-arch-specific.patch +++ /dev/null @@ -1,46 +0,0 @@ -From f03c5fbe6b4327b9ecd781bfdf64147e1b68e6c1 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 9 Feb 2022 15:23:27 -0500 -Subject: [PATCH 5/5] -fcf-protection is arch-specific - -Signed-off-by: Robbie Harwood -(cherry picked from commit c48df510144de3b1187001bc3b5491509da1c58f) ---- - Make.defaults | 10 ++++++---- - 1 file changed, 6 insertions(+), 4 deletions(-) - -diff --git a/Make.defaults b/Make.defaults -index fdb961a..130c1ee 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -22,11 +22,16 @@ EFI_ARCHES ?= aa64 ia32 x64 - - enabled = $(if $(filter undefined,$(origin $(1))),$(3),$(2)) - -+HOSTARCH = $(shell uname -m | sed s,i[3456789]86,ia32,) -+ARCH := $(shell uname -m | sed s,i[3456789]86,ia32,) -+ -+ - PKG_CONFIG ?= $(CROSS_COMPILE)pkg-config - CC := $(if $(filter default,$(origin CC)),$(CROSS_COMPILE)gcc,$(CC)) - CCLD := $(if $(filter undefined,$(origin CCLD)),$(CC),$(CCLD)) - CFLAGS ?= -O2 -g3 -pipe -fPIE -fstack-protector-all \ -- -fstack-clash-protection -fcf-protection=full -+ -fstack-clash-protection \ -+ $(if $(filter x86_64 ia32,$(ARCH)),-fcf-protection=full,) - DIAGFLAGS ?= -fmessage-length=0 \ - -fdiagnostics-color=always \ - -fdiagnostics-format=text \ -@@ -42,9 +47,6 @@ INSTALL ?= $(CROSS_COMPILE)install - - PKGS = efivar nspr nss nss-util uuid - --HOSTARCH = $(shell uname -m | sed s,i[3456789]86,ia32,) --ARCH := $(shell uname -m | sed s,i[3456789]86,ia32,) -- - SOFLAGS ?= -shared - clang_cflags = - gcc_cflags = -Wmaybe-uninitialized -grecord-gcc-switches \ --- -2.34.1 - diff --git a/0006-Disable-analyzer-until-it-works.patch b/0006-Disable-analyzer-until-it-works.patch deleted file mode 100644 index 4ed8cbf..0000000 --- a/0006-Disable-analyzer-until-it-works.patch +++ /dev/null @@ -1,26 +0,0 @@ -From 288b05dcd5a3b48836c4904e38b14e38a0cdfa07 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 14 Feb 2022 17:26:19 -0500 -Subject: [PATCH] Disable analyzer until it works - -See-also: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=104370 -Signed-off-by: Robbie Harwood ---- - Make.defaults | 1 - - 1 file changed, 1 deletion(-) - -diff --git a/Make.defaults b/Make.defaults -index 130c1ee..5e56a76 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -36,7 +36,6 @@ DIAGFLAGS ?= -fmessage-length=0 \ - -fdiagnostics-color=always \ - -fdiagnostics-format=text \ - -fdiagnostics-show-cwe \ -- -fanalyzer \ - $(call enabled,ENABLE_LEAK_CHECKER,-Wno-analyzer-malloc-leak,) - AS ?= $(CROSS_COMPILE)as - AR ?= $(CROSS_COMPILE)$(if $(filter $(CC),clang),llvm-ar,$(notdir $(CC))-ar) --- -2.34.1 - diff --git a/pesign.spec b/pesign.spec index d534229..764f6a6 100644 --- a/pesign.spec +++ b/pesign.spec @@ -5,8 +5,8 @@ Name: pesign Summary: Signing utility for UEFI binaries -Version: 114 -Release: 4%{?dist} +Version: 115 +Release: 1%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -47,11 +47,7 @@ Source0: https://github.com/rhboot/pesign/releases/download/%{version}/pesign-%{ Source1: certs.tar.xz Source2: pesign.py -Patch0001: 0001-Revert-Move-license-to-GPLv3.patch -Patch0002: 0002-Fix-format-strings-for-32-bit-arches.patch -Patch0003: 0003-macros-drop-_pesign_args.patch -Patch0004: 0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch -Patch0005: 0005-fcf-protection-is-arch-specific.patch +Patch0001: 0001-daemon-remove-always-true-comparison.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -163,6 +159,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Mar 08 2022 Robbie Harwood - 115-1 +- New upstream version (115) + * Mon Feb 14 2022 Robbie Harwood - 114-4 - Disable -fanalyzer since it's broken and pragmas don't work - See-also: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=104370 diff --git a/sources b/sources index 3522848..b6ddc75 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ SHA512 (certs.tar.xz) = ddac535c786d1a23074534323c4ce89f907d4f82b19c5d3a9c814b145fbac1599cd2386cf20c28d22aee7d5c4db441f052bab9ee655de756117a0a0bc99b525f -SHA512 (pesign-114.tar.bz2) = 5465c002db6f59ab59799ec79504ed96662bc5da2310282d2e85fc1f03c938343d88927e764e595bf21c3501e599e529a4752281349097cdc74e616535179b3c +SHA512 (pesign-115.tar.bz2) = 0091d70e286326b1ed74418ca8c5a2a63d42e6aa3eccdfc4f09a34241b2addfe878af17d1d74648b7da79d6cd7158fcca0f3a52f4a82a57cacae4617b42b1faa From b201f43f63402fcf484416060ab0a4dbbf79e261 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 24 Mar 2022 21:24:15 +0000 Subject: [PATCH 50/70] Add support for non-koji signing in macros Resolves: #1880858 Signed-off-by: Robbie Harwood --- ...ned-kernels-on-setups-other-than-koj.patch | 55 +++++++++++++++++++ pesign.patches | 2 + pesign.spec | 10 +++- 3 files changed, 65 insertions(+), 2 deletions(-) create mode 100644 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch create mode 100644 pesign.patches diff --git a/0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch b/0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch new file mode 100644 index 0000000..920eb6a --- /dev/null +++ b/0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch @@ -0,0 +1,55 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Julian Sikorski +Date: Wed, 23 Mar 2022 20:54:03 +0100 +Subject: [PATCH] Fix building signed kernels on setups other than koji + +Thanks to Will Springer for the idea. Details at +https://bugzilla.redhat.com/show_bug.cgi?id=1880858 + +Signed-off-by: Julian Sikorski +Suggested-by: Will Springer +(cherry picked from commit 9969b1757a1941c9f57081b308026d687f6c0943) +--- + src/pesign-rpmbuild-helper.in | 24 +++++++++++------------- + 1 file changed, 11 insertions(+), 13 deletions(-) + +diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in +index 0a845d2..c9d5570 100644 +--- a/src/pesign-rpmbuild-helper.in ++++ b/src/pesign-rpmbuild-helper.in +@@ -172,24 +172,22 @@ main() { + USERNAME="${USERNAME:-$(id -un)}" + + local socket="" || : +- if grep -q ID=fedora /etc/os-release \ ++ if [[ -S /run/pesign/socket ]] ; then ++ socket=/run/pesign/socket ++ elif [[ -S /var/run/pesign/socket ]]; then ++ socket=/var/run/pesign/socket ++ elif grep -q ID=fedora /etc/os-release \ + && [[ "${rhelver}" -lt 7 ]] \ + && [[ "${USERNAME}" = "mockbuild" ]] \ + && [[ "${vendor}" = "Fedora Project" ]] \ + && [[ "${HOSTNAME}" =~ bkernel.* ]] + then +- if [[ -S /run/pesign/socket ]] ; then +- socket=/run/pesign/socket +- elif [[ -S /var/run/pesign/socket ]]; then +- socket=/var/run/pesign/socket +- else +- echo "Warning: no pesign socket even though user is ${USERNAME}" 1>&2 +- echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 +- ls -ld /run/pesign /var/run/pesign 1>&2 ||: +- ls -l /run/pesign/socket /var/run/pesign/socket 1>&2 ||: +- getfacl /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: +- getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: +- fi ++ echo "Warning: no pesign socket even though user is ${USERNAME}" 1>&2 ++ echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 ++ ls -ld /run/pesign /var/run/pesign 1>&2 ||: ++ ls -l /run/pesign/socket /var/run/pesign/socket 1>&2 ||: ++ getfacl /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: ++ getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: + fi + + if [[ "${rhelver}" -ge 7 ]] ; then diff --git a/pesign.patches b/pesign.patches new file mode 100644 index 0000000..3126bdf --- /dev/null +++ b/pesign.patches @@ -0,0 +1,2 @@ +Patch0001: 0001-daemon-remove-always-true-comparison.patch +Patch0002: 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch diff --git a/pesign.spec b/pesign.spec index 764f6a6..8ca1139 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 1%{?dist} +Release: 2%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -46,8 +46,10 @@ BuildRequires: rh-signing-tools >= 1.20-2 Source0: https://github.com/rhboot/pesign/releases/download/%{version}/pesign-%{version}.tar.bz2 Source1: certs.tar.xz Source2: pesign.py +Source3: pesign.patches -Patch0001: 0001-daemon-remove-always-true-comparison.patch +# generate with tool +%include %{SOURCE3} %description This package contains the pesign utility for signing UEFI binaries as @@ -159,6 +161,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Thu Mar 24 2022 Robbie Harwood - 115-2 +- Add support for non-koji signing in macros +- Resolves: #1880858 + * Tue Mar 08 2022 Robbie Harwood - 115-1 - New upstream version (115) From c324cc0c6c5c0cd77a22f79def3472c268d6a6cd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 25 Mar 2022 19:02:31 +0000 Subject: [PATCH 51/70] Add -D_GLIBCXX_ASSERTIONS to CPPFLAGS Signed-off-by: Robbie Harwood --- ...Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch | 23 +++++++++++++++++++ pesign.patches | 1 + pesign.spec | 5 +++- 3 files changed, 28 insertions(+), 1 deletion(-) create mode 100644 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch diff --git a/0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch b/0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch new file mode 100644 index 0000000..0dca694 --- /dev/null +++ b/0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch @@ -0,0 +1,23 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 25 Mar 2022 15:01:54 -0400 +Subject: [PATCH] Add -D_GLIBCXX_ASSERTIONS to CPPFLAGS + +Signed-off-by: Robbie Harwood +--- + Make.defaults | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/Make.defaults b/Make.defaults +index 130c1ee..4b0e77c 100644 +--- a/Make.defaults ++++ b/Make.defaults +@@ -79,7 +79,7 @@ ccldflags = $(cflags) $(CCLDFLAGS) $(LDFLAGS) \ + $(call pkg-config-ccldflags) + efi_cflags = $(cflags) + ASFLAGS ?= $(ARCH3264) +-CPPFLAGS ?= -D_FORTIFY_SOURCE=2 ++CPPFLAGS ?= -D_FORTIFY_SOURCE=2 -D_GLIBCXX_ASSERTIONS + RANLIBFLAGS ?= $(if $(filter $(CC),gcc),-D) + ARFLAGS ?= $(if $(filter $(CC),gcc),-Dcvqs)$(if $(filter $(CC),clang),-cqvs) + diff --git a/pesign.patches b/pesign.patches index 3126bdf..98cdf7c 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1,2 +1,3 @@ Patch0001: 0001-daemon-remove-always-true-comparison.patch Patch0002: 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch +Patch0003: 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch diff --git a/pesign.spec b/pesign.spec index 8ca1139..8e803f9 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 2%{?dist} +Release: 3%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,6 +161,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Fri Mar 25 2022 Robbie Harwood - 115-3 +- Add -D_GLIBCXX_ASSERTIONS to CPPFLAGS + * Thu Mar 24 2022 Robbie Harwood - 115-2 - Add support for non-koji signing in macros - Resolves: #1880858 From 1d2597d20dab3c18d0b62cc7ce74173758747353 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 1 Apr 2022 19:28:29 +0000 Subject: [PATCH 52/70] Correctly handle rhel and centos macros Signed-off-by: Robbie Harwood --- ...handle-centos-like-rhel-with-rhelver.patch | 25 +++++++++++++++++++ pesign.patches | 1 + pesign.spec | 5 +++- 3 files changed, 30 insertions(+), 1 deletion(-) create mode 100644 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch diff --git a/0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch b/0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch new file mode 100644 index 0000000..62d1936 --- /dev/null +++ b/0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch @@ -0,0 +1,25 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Tue, 10 Aug 2021 12:39:08 -0400 +Subject: [PATCH] macros.pesign: handle centos like rhel with --rhelver + +Signed-off-by: Peter Jones +(cherry picked from commit a1bc65c8b0fc20dbe9c9714ee3a31937184ba7f6) +--- + src/macros.pesign | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/src/macros.pesign b/src/macros.pesign +index 34af57c..b7d6af1 100644 +--- a/src/macros.pesign ++++ b/src/macros.pesign +@@ -34,7 +34,8 @@ + %{?__pesign_cert:--cert %{__pesign_cert}} \\\ + %{?_buildhost:--hostname "%{_buildhost}"} \\\ + %{?vendor:--vendor "%{vendor}"} \\\ +- %{?_rhel:--rhelver "%{_rhel}"} \\\ ++ %{?rhel:--rhelver "%{rhel}"} \\\ ++ %{?centos:--rhelver "%{centos}"} \\\ + %{?-n:--rhelcert %{-n*}}%{?!-n:--rhelcert %{__pesign_cert}} \\\ + %{?-a:--rhelcafile "%{-a*}"} \\\ + %{?-c:--rhelcertfile "%{-c*}"} \\\ diff --git a/pesign.patches b/pesign.patches index 98cdf7c..62ae005 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1,3 +1,4 @@ Patch0001: 0001-daemon-remove-always-true-comparison.patch Patch0002: 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch Patch0003: 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch +Patch0004: 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch diff --git a/pesign.spec b/pesign.spec index 8e803f9..dd5df45 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 3%{?dist} +Release: 4%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,6 +161,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Fri Apr 01 2022 Robbie Harwood - 115-4 +- Correctly handle rhel and centos macros + * Fri Mar 25 2022 Robbie Harwood - 115-3 - Add -D_GLIBCXX_ASSERTIONS to CPPFLAGS From 3bf806fd9f75943a3693e9afaaedb41e86e4447f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 4 Apr 2022 18:52:40 +0000 Subject: [PATCH 53/70] Detect presence of rpm-sign when checking for rhel-ness Signed-off-by: Robbie Harwood --- ...nce-of-rpm-sign-when-checking-for-rh.patch | 26 +++++++++++++++++++ pesign.patches | 1 + pesign.spec | 5 +++- 3 files changed, 31 insertions(+), 1 deletion(-) create mode 100644 0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch diff --git a/0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch b/0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch new file mode 100644 index 0000000..0baddd6 --- /dev/null +++ b/0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch @@ -0,0 +1,26 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 4 Apr 2022 14:45:29 -0400 +Subject: [PATCH] Detect the presence of rpm-sign when checking for "rhel"-ness + +Signed-off-by: Peter Jones +[rharwood: manually reapply to main] +Signed-off-by: Robbie Harwood +(cherry picked from commit 17e5878cb087e0a766722d3c487f87c41b318f9a) +--- + src/pesign-rpmbuild-helper.in | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in +index c9d5570..9dee56e 100644 +--- a/src/pesign-rpmbuild-helper.in ++++ b/src/pesign-rpmbuild-helper.in +@@ -190,7 +190,7 @@ main() { + getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: + fi + +- if [[ "${rhelver}" -ge 7 ]] ; then ++ if [[ "${rhelver}" -ge 7 ]] && which rpm-sign >&/dev/null ; then + nssdir="$(mktemp -p "${PWD}" -d)" + echo > "${nssdir}/pwfile" + certutil -N -d "${nssdir}" -f "${nssdir}/pwfile" diff --git a/pesign.patches b/pesign.patches index 62ae005..848483a 100644 --- a/pesign.patches +++ b/pesign.patches @@ -2,3 +2,4 @@ Patch0001: 0001-daemon-remove-always-true-comparison.patch Patch0002: 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch Patch0003: 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch Patch0004: 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch +Patch0005: 0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch diff --git a/pesign.spec b/pesign.spec index dd5df45..483a42d 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 4%{?dist} +Release: 5%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,6 +161,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Mon Apr 04 2022 Robbie Harwood - 115-5 +- Detect presence of rpm-sign when checking for rhel-ness + * Fri Apr 01 2022 Robbie Harwood - 115-4 - Correctly handle rhel and centos macros From fbf8f35ae7fa4ad1edf325877df1f07bce3078e4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 7 Jul 2022 21:06:42 +0000 Subject: [PATCH 54/70] Fix formatting of man pages Resolves: #2104778 --- ...oc-invocation-to-not-produce-garbage.patch | 32 +++++++++++++++++++ pesign.patches | 1 + pesign.spec | 6 +++- 3 files changed, 38 insertions(+), 1 deletion(-) create mode 100644 0006-Fix-mandoc-invocation-to-not-produce-garbage.patch diff --git a/0006-Fix-mandoc-invocation-to-not-produce-garbage.patch b/0006-Fix-mandoc-invocation-to-not-produce-garbage.patch new file mode 100644 index 0000000..fb105df --- /dev/null +++ b/0006-Fix-mandoc-invocation-to-not-produce-garbage.patch @@ -0,0 +1,32 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 7 Jul 2022 16:56:41 -0400 +Subject: [PATCH] Fix mandoc invocation to not produce garbage + +Bizarrely, mandoc doesn't default to outputting man - the default is +"locale", which is either ASCII or UTF-8 (by locale). This output is +supposed to be some kind of plain-text, but it's formatted so strangely +I'm not sure what the purpose is. Regardless, it doesn't go well to +feed this into man(1). + +Tell mandoc explicitly to produce man pages. + +Signed-off-by: Robbie Harwood +(cherry picked from commit 102c3d1d81c090750abb3815481d5cfd3e596677) +--- + Make.rules | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/Make.rules b/Make.rules +index 12e322b..f6bf5fa 100644 +--- a/Make.rules ++++ b/Make.rules +@@ -54,7 +54,7 @@ define substitute-version = + endef + + %.1 : %.1.mdoc +- @mandoc -man -Ios=Linux $^ > $@ ++ @mandoc -man -T man -Ios=Linux $^ > $@ + + % : %.in + @$(call substitute-version,$<,$@) diff --git a/pesign.patches b/pesign.patches index 848483a..9b257c3 100644 --- a/pesign.patches +++ b/pesign.patches @@ -3,3 +3,4 @@ Patch0002: 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch Patch0003: 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch Patch0004: 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch Patch0005: 0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch +Patch0006: 0006-Fix-mandoc-invocation-to-not-produce-garbage.patch diff --git a/pesign.spec b/pesign.spec index 483a42d..b850722 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 5%{?dist} +Release: 6%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,6 +161,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Thu Jul 07 2022 Robbie Harwood - 115-6 +- Fix formatting of man pages +- Resolves: #2104778 + * Mon Apr 04 2022 Robbie Harwood - 115-5 - Detect presence of rpm-sign when checking for rhel-ness From f1d5690e2e72c9755529f40822322bd0a4124270 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 22 Jul 2022 13:02:33 +0000 Subject: [PATCH 55/70] Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pesign.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index b850722..3787b15 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 6%{?dist} +Release: 7%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,6 +161,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Fri Jul 22 2022 Fedora Release Engineering +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + * Thu Jul 07 2022 Robbie Harwood - 115-6 - Fix formatting of man pages - Resolves: #2104778 From c2da1bf6da1aa7e3b031e5425aad9b74521a0169 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Aug 2022 10:32:50 -0400 Subject: [PATCH 56/70] Revert "Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild" This reverts commit f1d5690e2e72c9755529f40822322bd0a4124270. Signed-off-by: Robbie Harwood --- pesign.spec | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/pesign.spec b/pesign.spec index 3787b15..b850722 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 7%{?dist} +Release: 6%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,9 +161,6 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog -* Fri Jul 22 2022 Fedora Release Engineering -- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild - * Thu Jul 07 2022 Robbie Harwood - 115-6 - Fix formatting of man pages - Resolves: #2104778 From 4b458cfe9f2fab0c0618736998da4e34a7b541e3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Aug 2022 14:34:06 +0000 Subject: [PATCH 57/70] Rebuild for python bytecode change See-also: #2107826 Signed-off-by: Robbie Harwood --- noautobuild | 0 pesign.spec | 6 +++++- 2 files changed, 5 insertions(+), 1 deletion(-) create mode 100644 noautobuild diff --git a/noautobuild b/noautobuild new file mode 100644 index 0000000..e69de29 diff --git a/pesign.spec b/pesign.spec index b850722..118b151 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 6%{?dist} +Release: 8%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,6 +161,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Aug 02 2022 Robbie Harwood - 115-8 +- Rebuild for python bytecode change +- See-also: #2107826 + * Thu Jul 07 2022 Robbie Harwood - 115-6 - Fix formatting of man pages - Resolves: #2104778 From bb3aaa1ba23053c22907afc0153eefb2de91127d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 31 Aug 2022 21:06:34 +0000 Subject: [PATCH 58/70] Roll up to pjones's smartcard/cms fixes Signed-off-by: Robbie Harwood --- ...ndle-some-gcc-Wanalyzer-flags-better.patch | 40 ++ 0003-Rename-dprintf-to-dbgprintf.patch | 664 ++++++++++++++++++ ...add-compile_commands.json-and-.cache.patch | 30 + ...ests-before-filenames-like-sha256sum.patch | 31 + ...sum-an-authenticode-digest-generator.patch | 318 +++++++++ ...ned-kernels-on-setups-other-than-koj.patch | 1 - ...Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch | 2 +- ...handle-centos-like-rhel-with-rhelver.patch | 1 - ...nce-of-rpm-sign-when-checking-for-rh.patch | 1 - 0011-Rename-README-README.md.patch | 17 + 0012-README.md-show-off-a-bit-more.patch | 56 ++ 0013-Fix-missing-line-in-README.md.patch | 23 + 0014-Fix-typo-in-efikeygen-command.patch | 23 + ...pesigcheck-Fix-crash-on-digest-match.patch | 53 ++ ...e-digest-as-pointer-instead-of-index.patch | 272 +++++++ ...oc-invocation-to-not-produce-garbage.patch | 1 - ...being-obnoxiously-incompatible-with-.patch | 41 ++ ...sthrough-handle-the-callback-context.patch | 51 ++ ...ly-prune-CR-NL-from-the-end-of-the-f.patch | 47 ++ ...e-digest-as-pointer-instead-of-index.patch | 276 ++++++++ 0022-CMS-add-some-minor-cleanups.patch | 149 ++++ ...e-cms-selected_digest-an-index-again.patch | 291 ++++++++ pesign.patches | 27 +- pesign.spec | 8 +- 24 files changed, 2411 insertions(+), 12 deletions(-) create mode 100644 0002-make-handle-some-gcc-Wanalyzer-flags-better.patch create mode 100644 0003-Rename-dprintf-to-dbgprintf.patch create mode 100644 0004-.gitignore-add-compile_commands.json-and-.cache.patch create mode 100644 0005-pesign-print-digests-before-filenames-like-sha256sum.patch create mode 100644 0006-Add-pesum-an-authenticode-digest-generator.patch rename 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch => 0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch (97%) rename 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch => 0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch (96%) rename 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch => 0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch (93%) rename 0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch => 0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch (93%) create mode 100644 0011-Rename-README-README.md.patch create mode 100644 0012-README.md-show-off-a-bit-more.patch create mode 100644 0013-Fix-missing-line-in-README.md.patch create mode 100644 0014-Fix-typo-in-efikeygen-command.patch create mode 100644 0015-pesigcheck-Fix-crash-on-digest-match.patch create mode 100644 0016-cms-store-digest-as-pointer-instead-of-index.patch rename 0006-Fix-mandoc-invocation-to-not-produce-garbage.patch => 0017-Fix-mandoc-invocation-to-not-produce-garbage.patch (93%) create mode 100644 0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch create mode 100644 0019-get_password_passthrough-handle-the-callback-context.patch create mode 100644 0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch create mode 100644 0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch create mode 100644 0022-CMS-add-some-minor-cleanups.patch create mode 100644 0023-CMS-make-cms-selected_digest-an-index-again.patch diff --git a/0002-make-handle-some-gcc-Wanalyzer-flags-better.patch b/0002-make-handle-some-gcc-Wanalyzer-flags-better.patch new file mode 100644 index 0000000..5bee588 --- /dev/null +++ b/0002-make-handle-some-gcc-Wanalyzer-flags-better.patch @@ -0,0 +1,40 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Fri, 11 Mar 2022 12:45:28 -0500 +Subject: [PATCH] make: handle some gcc -Wanalyzer flags better + +This makes it so we won't use the -Wanalyzer / -fanalyzer flags by +default, because they're still pretty overzealous. + +Signed-off-by: Peter Jones +--- + Make.defaults | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/Make.defaults b/Make.defaults +index 130c1ee..1c18904 100644 +--- a/Make.defaults ++++ b/Make.defaults +@@ -32,11 +32,11 @@ CCLD := $(if $(filter undefined,$(origin CCLD)),$(CC),$(CCLD)) + CFLAGS ?= -O2 -g3 -pipe -fPIE -fstack-protector-all \ + -fstack-clash-protection \ + $(if $(filter x86_64 ia32,$(ARCH)),-fcf-protection=full,) +-DIAGFLAGS ?= -fmessage-length=0 \ ++DIAGFLAGS ?= $(call enabled,ENABLE_GCC_ANALYZER,-fmessage-length=0 \ + -fdiagnostics-color=always \ + -fdiagnostics-format=text \ + -fdiagnostics-show-cwe \ +- -fanalyzer \ ++ -fanalyzer) \ + $(call enabled,ENABLE_LEAK_CHECKER,-Wno-analyzer-malloc-leak,) + AS ?= $(CROSS_COMPILE)as + AR ?= $(CROSS_COMPILE)$(if $(filter $(CC),clang),llvm-ar,$(notdir $(CC))-ar) +@@ -59,7 +59,7 @@ endif + cflags = $(CFLAGS) $(ARCH3264) \ + -Wall -Wextra -Wsign-compare -Wno-unused-result \ + -Wno-unused-function -Wno-missing-field-initializers \ +- -Wno-analyzer-malloc-leak \ ++ $(call enabled,ENABLE_LEAK_CHECKER,-Wno-analyzer-malloc-leak,) \ + -Werror -Wno-error=cpp -Wno-free-nonheap-object \ + -std=gnu11 -fshort-wchar -fPIC -fno-strict-aliasing \ + -D_GNU_SOURCE -DCONFIG_$(ARCH) -I${TOPDIR}/include \ diff --git a/0003-Rename-dprintf-to-dbgprintf.patch b/0003-Rename-dprintf-to-dbgprintf.patch new file mode 100644 index 0000000..dac8401 --- /dev/null +++ b/0003-Rename-dprintf-to-dbgprintf.patch @@ -0,0 +1,664 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Fri, 11 Mar 2022 12:46:16 -0500 +Subject: [PATCH] Rename "dprintf' to "dbgprintf" + +stdio defines a dprintf() macro now, so using dprintf() for our debug +printer gets obnoxious warnings. This renames it to dbgprintf(). + +Signed-off-by: Peter Jones +--- + src/cms_common.c | 73 +++++++++++++++++++++++++++++------------------------ + src/cms_pe_common.c | 20 +++++++-------- + src/efikeygen.c | 16 ++++++------ + src/file_pe.c | 6 +++-- + src/password.c | 68 ++++++++++++++++++++++++------------------------- + src/pesign.c | 10 ++++---- + src/util.h | 26 +++++++++---------- + 7 files changed, 114 insertions(+), 105 deletions(-) + +diff --git a/src/cms_common.c b/src/cms_common.c +index ca37e6a..86341ca 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -333,13 +333,13 @@ void cms_set_pw_data(cms_context *cms, secuPWData *pwdata) + + if (!pwdata) { + cms->pwdata.source = PW_SOURCE_INVALID; +- dprintf("pwdata:NULL"); ++ dbgprintf("pwdata:NULL"); + } else { + memmove(&cms->pwdata, pwdata, sizeof(*pwdata)); +- dprintf("pwdata:%p", pwdata); +- dprintf("pwdata->source:%d", pwdata->source); +- dprintf("pwdata->data:%p (\"%s\")", pwdata->data, +- pwdata->data ? pwdata->data : "(null)"); ++ dbgprintf("pwdata:%p", pwdata); ++ dbgprintf("pwdata->source:%d", pwdata->source); ++ dbgprintf("pwdata->data:%p (\"%s\")", pwdata->data, ++ pwdata->data ? pwdata->data : "(null)"); + } + + egress(); +@@ -382,7 +382,7 @@ is_valid_cert(CERTCertificate *cert, void *data) + + errnum = PORT_GetError(); + if (errnum == SEC_ERROR_EXTENSION_NOT_FOUND) { +- dprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); ++ dbgprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); + PORT_SetError(0); + errnum = 0; + } +@@ -415,7 +415,7 @@ is_valid_cert_without_private_key(CERTCertificate *cert, void *data) + + errnum = PORT_GetError(); + if (errnum == SEC_ERROR_EXTENSION_NOT_FOUND) { +- dprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); ++ dbgprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); + PORT_SetError(0); + errnum = 0; + } +@@ -467,23 +467,23 @@ unescape_html_in_place(char *s) + size_t pos = 0; + char *s1; + +- dprintf("unescaping pos:%zd sz:%zd \"%s\"", pos, sz, s); ++ dbgprintf("unescaping pos:%zd sz:%zd \"%s\"", pos, sz, s); + do { + s1 = strchrnul(&s[pos], '%'); + if (s1[0] == '\0') + break; +- dprintf("s1 is \"%s\"", s1); ++ dbgprintf("s1 is \"%s\"", s1); + if ((size_t)(s1 - s) < (size_t)(sz - 3)) { + int c; + + c = (hexchar_to_bin(s1[1]) << 4) + | (hexchar_to_bin(s1[2]) & 0xf); +- dprintf("replacing %%%c%c with 0x%02hhx", s1[1], s1[2], (char)c); ++ dbgprintf("replacing %%%c%c with 0x%02hhx", s1[1], s1[2], (char)c); + s1[0] = c; + memmove(&s1[1], &s1[3], sz - (&s1[3] - s)); + sz -= 2; + pos = &s1[1] - s; +- dprintf("new pos:%zd sz:%zd s:\"%s\"", pos, sz, s); ++ dbgprintf("new pos:%zd sz:%zd s:\"%s\"", pos, sz, s); + } + } while (pos < sz); + } +@@ -499,7 +499,7 @@ resolve_pkcs11_token_in_place(char *tokenname) + char c = *cp; + *cp = '\0'; + +- dprintf("ntn:\"%s\"", ntn); ++ dbgprintf("ntn:\"%s\"", ntn); + if (!strncmp(&ntn[pos], "token=", 6)) { + ntn += 6; + memmove(tokenname, ntn, cp - ntn + 1); +@@ -510,13 +510,13 @@ resolve_pkcs11_token_in_place(char *tokenname) + ntn = cp + (c ? 1 : 0); + } + unescape_html_in_place(tokenname); +- dprintf("token name is \"%s\"", tokenname); ++ dbgprintf("token name is \"%s\"", tokenname); + } + + #define resolve_token_name(tn) ({ \ + char *s_ = tn; \ + if (!strncmp(tn, "pkcs11:", 7)) { \ +- dprintf("provided token name is pkcs11 uri; parsing"); \ ++ dbgprintf("provided token name is pkcs11 uri; parsing");\ + s_ = strdupa(tn+7); \ + resolve_pkcs11_token_in_place(s_); \ + } \ +@@ -528,7 +528,8 @@ unlock_nss_token(cms_context *cms) + { + char *tokenname = resolve_token_name(cms->tokenname); + +- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); ++ dbgprintf("setting password function to %s", ++ cms->func ? "cms->func" : "SECU_GetModulePassword"); + PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); + + PK11SlotList *slots = NULL; +@@ -592,7 +593,8 @@ find_certificate(cms_context *cms, int needs_private_key) + return -1; + } + +- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); ++ dbgprintf("setting password function to %s", ++ cms->func ? "cms->func" : "SECU_GetModulePassword"); + PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); + + PK11SlotList *slots = NULL; +@@ -610,10 +612,10 @@ find_certificate(cms_context *cms, int needs_private_key) + } + + while (psle) { +- dprintf("looking for token \"%s\", got \"%s\"", +- tokenname, PK11_GetTokenName(psle->slot)); ++ dbgprintf("looking for token \"%s\", got \"%s\"", ++ tokenname, PK11_GetTokenName(psle->slot)); + if (!strcmp(tokenname, PK11_GetTokenName(psle->slot))) { +- dprintf("found token \"%s\"", tokenname); ++ dbgprintf("found token \"%s\"", tokenname); + break; + } + +@@ -673,8 +675,9 @@ find_certificate(cms_context *cms, int needs_private_key) + psle->slot, is_valid_cert, &cbd); + errnum = PORT_GetError(); + if (errnum) +- dprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", +- PORT_ErrorToName(errnum), PORT_ErrorToString(errnum)); ++ dbgprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", ++ PORT_ErrorToName(errnum), ++ PORT_ErrorToString(errnum)); + } else { + status = PK11_TraverseCertsForNicknameInSlot(&nickname, + psle->slot, +@@ -682,28 +685,30 @@ find_certificate(cms_context *cms, int needs_private_key) + &cbd); + errnum = PORT_GetError(); + if (errnum) +- dprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", +- PORT_ErrorToName(errnum), PORT_ErrorToString(errnum)); ++ dbgprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", ++ PORT_ErrorToName(errnum), ++ PORT_ErrorToString(errnum)); + } +- dprintf("status:%d cbd.cert:%p", status, cbd.cert); ++ dbgprintf("status:%d cbd.cert:%p", status, cbd.cert); + if (status == SECSuccess && cbd.cert != NULL) { + if (cms->cert) + CERT_DestroyCertificate(cms->cert); + cms->cert = CERT_DupCertificate(cbd.cert); + } else { + errnum = PORT_GetError(); +- dprintf("token traversal %s; cert %sfound:%s:%s", +- status == SECSuccess ? "succeeded" : "failed", +- cbd.cert == NULL ? "not" : "", +- PORT_ErrorToName(errnum), PORT_ErrorToString(errnum)); ++ dbgprintf("token traversal %s; cert %sfound:%s:%s", ++ status == SECSuccess ? "succeeded" : "failed", ++ cbd.cert == NULL ? "not" : "", ++ PORT_ErrorToName(errnum), ++ PORT_ErrorToString(errnum)); + } + + save_port_err() { +- dprintf("Destroying cert list"); ++ dbgprintf("Destroying cert list"); + CERT_DestroyCertList(certlist); +- dprintf("Destroying slot list element"); ++ dbgprintf("Destroying slot list element"); + PK11_DestroySlotListElement(slots, &psle); +- dprintf("Destroying slot list"); ++ dbgprintf("Destroying slot list"); + PK11_FreeSlotList(slots); + cms->psle = NULL; + } +@@ -723,7 +728,8 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot) + + char *tokenname = resolve_token_name(cms->tokenname); + +- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); ++ dbgprintf("setting password function to %s", ++ cms->func ? "cms->func" : "SECU_GetModulePassword"); + PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); + + PK11SlotList *slots = NULL; +@@ -792,7 +798,8 @@ find_certificate_by_callback(cms_context *cms, + return -1; + } + +- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); ++ dbgprintf("setting password function to %s", ++ cms->func ? "cms->func" : "SECU_GetModulePassword"); + PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); + + PK11SlotList *slots = NULL; +diff --git a/src/cms_pe_common.c b/src/cms_pe_common.c +index 3a3921b..fb90ecb 100644 +--- a/src/cms_pe_common.c ++++ b/src/cms_pe_common.c +@@ -188,8 +188,8 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + } + if (!check_pointer_and_size(cms, pe, hash_base, hash_size)) + cmsgotoerr(error, cms, "PE header is invalid"); +- dprintf("beginning of hash"); +- dprintf("digesting %tx + %zx", hash_base - map, hash_size); ++ dbgprintf("beginning of hash"); ++ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); + generate_digest_step(cms, hash_base, hash_size); + + /* 5. Skip over the image checksum +@@ -209,7 +209,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + cmsgotoerr(error, cms, "PE data directory is invalid"); + + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %tx + %zx", hash_base - map, hash_size); ++ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); + + /* 8. Skip over the crt dir + * 9. Hash everything up to the end of the image header. */ +@@ -222,7 +222,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + cmsgotoerr(error, cms, "PE relocations table is invalid"); + + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %tx + %zx", hash_base - map, hash_size); ++ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); + + /* 10. Set SUM_OF_BYTES_HASHED to the size of the header. */ + hashed_bytes = pe32opthdr ? pe32opthdr->header_size +@@ -256,16 +256,16 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + char *name = shdrs[i].name; + if (name && name[0] == '/') + name = get_str(cms, pe, name + 1); +- dprintf("section:\"%s\"", name ? name : "(null)"); ++ dbgprintf("section:\"%s\"", name ? name : "(null)"); + if (name && !strcmp(name, ".vendor_cert")) { +- dprintf("skipping .vendor_cert section"); ++ dbgprintf("skipping .vendor_cert section"); + hashed_bytes += hash_size; + continue; + } + } + + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %tx + %zx", hash_base - map, hash_size); ++ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); + + hashed_bytes += hash_size; + } +@@ -285,15 +285,15 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + memset(tmp_array, '\0', tmp_size); + memcpy(tmp_array, hash_base, hash_size); + generate_digest_step(cms, tmp_array, tmp_size); +- dprintf("digesting %tx + %zx", (ptrdiff_t)tmp_array, ++ dbgprintf("digesting %tx + %zx", (ptrdiff_t)tmp_array, + tmp_size); + } else { + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %tx + %zx", hash_base - map, ++ dbgprintf("digesting %tx + %zx", hash_base - map, + hash_size); + } + } +- dprintf("end of hash"); ++ dbgprintf("end of hash"); + + rc = generate_digest_finish(cms); + if (rc < 0) +diff --git a/src/efikeygen.c b/src/efikeygen.c +index 940fdf5..dd40502 100644 +--- a/src/efikeygen.c ++++ b/src/efikeygen.c +@@ -1067,9 +1067,9 @@ int main(int argc, char *argv[]) + + errno = 0; + timeul = strtoul(not_valid_before, &endptr, 0); +- dprintf("not_valid_before:%lu", timeul); ++ dbgprintf("not_valid_before:%lu", timeul); + if (errno == 0 && endptr && *endptr == 0) { +- dprintf("not_valid_before:%lu", timeul); ++ dbgprintf("not_valid_before:%lu", timeul); + not_before = (PRTime)timeul * PR_USEC_PER_SEC; + } else { + prstatus = PR_ParseTimeString(not_valid_before, +@@ -1078,7 +1078,7 @@ int main(int argc, char *argv[]) + "could not parse date \"%s\"", + not_valid_before); + } +- dprintf("not_before:%"PRId64, not_before); ++ dbgprintf("not_before:%"PRId64, not_before); + } + + if (not_valid_after) { +@@ -1086,11 +1086,11 @@ int main(int argc, char *argv[]) + char *endptr; + + errno = 0; +- dprintf("not_valid_after:%s", not_valid_after); ++ dbgprintf("not_valid_after:%s", not_valid_after); + timeul = strtoul(not_valid_after, &endptr, 0); +- dprintf("not_valid_after:%lu", timeul); ++ dbgprintf("not_valid_after:%lu", timeul); + if (errno == 0 && endptr && *endptr == 0) { +- dprintf("not_valid_after:%lu", timeul); ++ dbgprintf("not_valid_after:%lu", timeul); + not_after = (PRTime)timeul * PR_USEC_PER_SEC; + } else { + prstatus = PR_ParseTimeString(not_valid_after, PR_TRUE, +@@ -1102,10 +1102,10 @@ int main(int argc, char *argv[]) + } else { + // Mon Jan 19 03:14:07 GMT 2037, aka 0x7fffffff minus 1 year. + time_t time = 0x7ffffffful - 60ul * 60 * 24 * 365; +- dprintf("not_valid_after:%lu", time); ++ dbgprintf("not_valid_after:%lu", time); + not_after = (PRTime)time * PR_USEC_PER_SEC; + } +- dprintf("not_after:%"PRId64, not_after); ++ dbgprintf("not_after:%"PRId64, not_after); + + CERTValidity *validity = NULL; + validity = CERT_CreateValidity(not_before, not_after); +diff --git a/src/file_pe.c b/src/file_pe.c +index fa97b89..fed6edb 100644 +--- a/src/file_pe.c ++++ b/src/file_pe.c +@@ -264,7 +264,8 @@ pe_handle_action(pesign_context *ctxp, int action, int padding) + /* generate a signature and save it in a separate file */ + case EXPORT_SIGNATURE|GENERATE_SIGNATURE: + perr = PORT_GetError(); +- dprintf("PORT_GetError():%s:%s", PORT_ErrorToName(perr), PORT_ErrorToString(perr)); ++ dbgprintf("PORT_GetError():%s:%s", ++ PORT_ErrorToName(perr), PORT_ErrorToString(perr)); + PORT_SetError(0); + rc = find_certificate(ctxp->cms_ctx, 1); + conderrx(rc < 0, 1, "Could not find certificate %s", +@@ -281,7 +282,8 @@ pe_handle_action(pesign_context *ctxp, int action, int padding) + case IMPORT_SIGNATURE|GENERATE_SIGNATURE: + check_inputs(ctxp); + perr = PORT_GetError(); +- dprintf("PORT_GetError():%s:%s", PORT_ErrorToName(perr), PORT_ErrorToString(perr)); ++ dbgprintf("PORT_GetError():%s:%s", ++ PORT_ErrorToName(perr), PORT_ErrorToString(perr)); + rc = find_certificate(ctxp->cms_ctx, 1); + conderrx(rc < 0, 1, "Could not find certificate %s", + ctxp->cms_ctx->certname); +diff --git a/src/password.c b/src/password.c +index 05add9a..18c32ed 100644 +--- a/src/password.c ++++ b/src/password.c +@@ -167,7 +167,7 @@ SECU_GetPasswordString(void *arg UNUSED, char *prompt) + char *ret; + ingress(); + ret = get_password(stdin, stdout, prompt, NULL); +- dprintf("password:\"%s\"", ret ? ret : "(null)"); ++ dbgprintf("password:\"%s\"", ret ? ret : "(null)"); + egress(); + return ret; + } +@@ -194,7 +194,7 @@ parse_pwfile_line(char *start, struct token_pass *tp) + size_t offset = 0; + + span = strspn(line, whitespace_and_eol_chars); +- dprintf("whitespace span is %zd", span); ++ dbgprintf("whitespace span is %zd", span); + if (span == 0 && line[span] == '\0') + return -1; + line += span; +@@ -210,17 +210,17 @@ parse_pwfile_line(char *start, struct token_pass *tp) + offset += escspan + 2; + } while(escspan < span); + span += offset; +- dprintf("non-whitespace span is %zd", span); ++ dbgprintf("non-whitespace span is %zd", span); + + if (line[span] == '\0') { +- dprintf("returning %td", (line + span) - start); ++ dbgprintf("returning %td", (line + span) - start); + return (line + span) - start; + } + line[span] = '\0'; + + line += span + 1; + span = strspn(line, whitespace_and_eol_chars); +- dprintf("whitespace span is %zd", span); ++ dbgprintf("whitespace span is %zd", span); + line += span; + tp->token = tp->pass; + tp->pass = line; +@@ -233,15 +233,15 @@ parse_pwfile_line(char *start, struct token_pass *tp) + offset += escspan + 2; + } while(escspan < span); + span += offset; +- dprintf("non-whitespace span is %zd", span); ++ dbgprintf("non-whitespace span is %zd", span); + if (line[span] != '\0') + line[span++] = '\0'; + + resolve_escapes(tp->token); +- dprintf("Setting token pass %p to { %p, %p }", tp, tp->token, tp->pass); +- dprintf("token:\"%s\"", tp->token); +- dprintf("pass:\"%s\"", tp->pass); +- dprintf("returning %td", (line + span) - start); ++ dbgprintf("Setting token pass %p to { %p, %p }", tp, tp->token, tp->pass); ++ dbgprintf("token:\"%s\"", tp->token); ++ dbgprintf("pass:\"%s\"", tp->pass); ++ dbgprintf("returning %td", (line + span) - start); + return (line + span) - start; + } + +@@ -260,7 +260,7 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) + char *path; + + ingress(); +- dprintf("token_name: %s", token_name); ++ dbgprintf("token_name: %s", token_name); + if (cms->pwdata.source != PW_FROMFILEDB) { + cms->log(cms, LOG_ERR, + "Got to %s() but no file is specified.\n", +@@ -289,8 +289,8 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) + if (rc < 0 || file_len < 1) + goto err_file; + file[file_len-1] = '\0'; +- dprintf("file_len:%zd", file_len); +- dprintf("file:\"%s\"", file); ++ dbgprintf("file_len:%zd", file_len); ++ dbgprintf("file:\"%s\"", file); + + unbreak_line_continuations(file, file_len); + } +@@ -314,23 +314,23 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) + #pragma GCC diagnostic pop + + span = strspn(start, whitespace_and_eol_chars); +- dprintf("whitespace span is %zd", span); ++ dbgprintf("whitespace span is %zd", span); + start += span; + span = strcspn(start, eol_chars); +- dprintf("non-whitespace span is %zd", span); ++ dbgprintf("non-whitespace span is %zd", span); + + c = start[span]; + start[span] = '\0'; +- dprintf("file:\"%s\"", file); ++ dbgprintf("file:\"%s\"", file); + rc = parse_pwfile_line(start, &phrases[nphrases++]); +- dprintf("parse_pwfile_line returned %d", rc); ++ dbgprintf("parse_pwfile_line returned %d", rc); + if (rc < 0) + goto err_phrases; + + if (c != '\0') + span++; + start += span; +- dprintf("start is file[%td] == '\\x%02hhx'", start - file, ++ dbgprintf("start is file[%td] == '\\x%02hhx'", start - file, + start[0]); + } + +@@ -359,7 +359,7 @@ err_file: + err_phrases: + xfree(phrases); + err: +- dprintf("ret:\"%s\"", ret ? ret : "(null)"); ++ dbgprintf("ret:\"%s\"", ret ? ret : "(null)"); + egress(); + return ret; + } +@@ -412,10 +412,10 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) + ingress(); + + if (PK11_ProtectedAuthenticationPath(slot)) { +- dprintf("prompting for PW_DEVICE data"); ++ dbgprintf("prompting for PW_DEVICE data"); + pwdata = &pwxtrn; + } else { +- dprintf("using pwdata from cms"); ++ dbgprintf("using pwdata from cms"); + pwdata = &cms->pwdata; + } + +@@ -423,17 +423,17 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) + pwdata->source >= PW_SOURCE_MAX || + pwdata->orig_source <= PW_SOURCE_INVALID || + pwdata->orig_source >= PW_SOURCE_MAX) { +- dprintf("pwdata is invalid"); ++ dbgprintf("pwdata is invalid"); + return NULL; + } + +- dprintf("pwdata:%p retry:%d", pwdata, retry); +- dprintf("pwdata->source:%s (%d) orig:%s (%d)", +- pw_source_names[pwdata->source], pwdata->source, +- pw_source_names[pwdata->orig_source], pwdata->orig_source); +- dprintf("pwdata->data:%p (\"%s\")", pwdata->data, +- pwdata->data ? pwdata->data : "(null)"); +- dprintf("pwdata->intdata:%ld", pwdata->intdata); ++ dbgprintf("pwdata:%p retry:%d", pwdata, retry); ++ dbgprintf("pwdata->source:%s (%d) orig:%s (%d)", ++ pw_source_names[pwdata->source], pwdata->source, ++ pw_source_names[pwdata->orig_source], pwdata->orig_source); ++ dbgprintf("pwdata->data:%p (\"%s\")", pwdata->data, ++ pwdata->data ? pwdata->data : "(null)"); ++ dbgprintf("pwdata->intdata:%ld", pwdata->intdata); + + if (retry) { + warnx("Incorrect password/PIN entered."); +@@ -470,7 +470,7 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) + + case PW_FROMFILEDB: + case PW_DATABASE: +- dprintf("pwdata->source:%s", pw_source_names[pwdata->source]); ++ dbgprintf("pwdata->source:%s", pw_source_names[pwdata->source]); + /* Instead of opening and closing the file every time, get the pw + * once, then keep it in memory (duh). + */ +@@ -480,17 +480,17 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) + return pw; + + case PW_FROMENV: +- dprintf("pwdata->source:PW_FROMENV"); ++ dbgprintf("pwdata->source:PW_FROMENV"); + if (!pwdata || !pwdata->data) + break; + pw = get_env(pwdata->data); +- dprintf("env:%s pw:%s", pwdata->data, pw ? pw : "(null)"); ++ dbgprintf("env:%s pw:%s", pwdata->data, pw ? pw : "(null)"); + pwdata->data = pw; + pwdata->source = PW_PLAINTEXT; + goto PW_PLAINTEXT; + + case PW_FROMFILE: +- dprintf("pwdata->source:PW_FROMFILE"); ++ dbgprintf("pwdata->source:PW_FROMFILE"); + in = fopen(pwdata->data, "r"); + if (!in) + return NULL; +@@ -501,7 +501,7 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) + goto PW_PLAINTEXT; + + case PW_FROMFD: +- dprintf("pwdata->source:PW_FROMFD"); ++ dbgprintf("pwdata->source:PW_FROMFD"); + rc = pwdata->intdata; + in = fdopen(pwdata->intdata, "r"); + if (!in) +diff --git a/src/pesign.c b/src/pesign.c +index c2ff35f..f548d81 100644 +--- a/src/pesign.c ++++ b/src/pesign.c +@@ -333,7 +333,7 @@ main(int argc, char *argv[]) + while ((rc = poptGetNextOpt(optCon)) > 0) { + switch (rc) { + case POPT_RET_PWDB: +- dprintf("POPT_RET_PWDB:\"%s\"", pwdata.data ? pwdata.data : "(null)"); ++ dbgprintf("POPT_RET_PWDB:\"%s\"", pwdata.data ? pwdata.data : "(null)"); + if (pwdata.source != PW_SOURCE_INVALID) + errx(1, "only one password/pin method can be used at a time"); + if (pwdata.data == NULL) +@@ -346,7 +346,7 @@ main(int argc, char *argv[]) + continue; + + case POPT_RET_ENV: +- dprintf("POPT_RET_ENV:\"%s\"", pwdata.data ? pwdata.data : "(null)"); ++ dbgprintf("POPT_RET_ENV:\"%s\"", pwdata.data ? pwdata.data : "(null)"); + if (pwdata.source != PW_SOURCE_INVALID) + errx(1, "only one password/pin method can be used at a time"); + if (pwdata.data == NULL) +@@ -359,7 +359,7 @@ main(int argc, char *argv[]) + continue; + + case POPT_RET_PINFD: +- dprintf("POPT_RET_PINFD:\"%s\"", pwdata.data ? pwdata.data : "(null)"); ++ dbgprintf("POPT_RET_PINFD:\"%s\"", pwdata.data ? pwdata.data : "(null)"); + if (pwdata.source != PW_SOURCE_INVALID) + errx(1, "only one password/pin method can be used at a time"); + if (pwdata.data == NULL) +@@ -373,7 +373,7 @@ main(int argc, char *argv[]) + continue; + + case POPT_RET_PINFILE: +- dprintf("POPT_RET_PINFILE:\"%s\"", pwdata.data ? pwdata.data : "(null)"); ++ dbgprintf("POPT_RET_PINFILE:\"%s\"", pwdata.data ? pwdata.data : "(null)"); + if (pwdata.source != PW_SOURCE_INVALID) + errx(1, "only one password/pin method can be used at a time"); + if (pwdata.data == NULL) +@@ -387,7 +387,7 @@ main(int argc, char *argv[]) + } + } + +- dprintf("pwdata.source:%d %schecking for PESIGN_TOKEN_PIN", ++ dbgprintf("pwdata.source:%d %schecking for PESIGN_TOKEN_PIN", + pwdata.source, + pwdata.source == PW_SOURCE_INVALID ? "" : "not "); + if (pwdata.source == PW_SOURCE_INVALID && secure_getenv("PESIGN_TOKEN_PIN")) { +diff --git a/src/util.h b/src/util.h +index ba8c621..6616011 100644 +--- a/src/util.h ++++ b/src/util.h +@@ -269,28 +269,28 @@ proxy_fd_mode(int fd, char *infile, mode_t *outmode, size_t *inlength) + + extern long verbosity(void); + +-#define dprintf_(tv, file, func, line, fmt, args...) ({ \ +- struct timeval tv; \ +- gettimeofday(&tv, NULL); \ +- warnx("%ld.%lu %s:%s():%d: " fmt, \ +- tv.tv_sec, tv.tv_usec, \ +- file, func, line, ##args); \ ++#define dbgprintf_(tv, file, func, line, fmt, args...) ({ \ ++ struct timeval tv; \ ++ gettimeofday(&tv, NULL); \ ++ warnx("%ld.%lu %s:%s():%d: " fmt, \ ++ tv.tv_sec, tv.tv_usec, \ ++ file, func, line, ##args); \ + }) + #if defined(PESIGN_DEBUG) +-#define dprintf(fmt, args...) \ +- dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ +- __FILE__, __func__, __LINE__ - 2, fmt, ##args) ++#define dbgprintf(fmt, args...) \ ++ dbgprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ ++ __FILE__, __func__, __LINE__ - 2, fmt, ##args) + #else +-#define dprintf(fmt, args...) ({ \ ++#define dbgprintf(fmt, args...) ({ \ + if (verbosity() > 1) \ +- dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ ++ dbgprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ + __FILE__, __func__, __LINE__ - 3, \ + fmt, ##args); \ + 0; \ + }) + #endif +-#define ingress() dprintf("ingress"); +-#define egress() dprintf("egress"); ++#define ingress() dbgprintf("ingress"); ++#define egress() dbgprintf("egress"); + + #endif /* PESIGN_UTIL_H */ + // vim:fenc=utf-8:tw=75:noet diff --git a/0004-.gitignore-add-compile_commands.json-and-.cache.patch b/0004-.gitignore-add-compile_commands.json-and-.cache.patch new file mode 100644 index 0000000..fb7e7a4 --- /dev/null +++ b/0004-.gitignore-add-compile_commands.json-and-.cache.patch @@ -0,0 +1,30 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Fri, 11 Mar 2022 12:47:20 -0500 +Subject: [PATCH] .gitignore: add compile_commands.json and .cache/ + +These are used by bear/cnc/clangd/etc, but there's no reason to trip +over them all the time. + +Signed-off-by: Peter Jones +--- + .gitignore | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/.gitignore b/.gitignore +index bf0617b..7425432 100644 +--- a/.gitignore ++++ b/.gitignore +@@ -1,3 +1,4 @@ ++.cache/ + .*.d + .*.P + .*.sw? +@@ -26,6 +27,7 @@ + /*.rpm + *-8be4df61-93ca-11d2-aa0d-00e098032b8c + *-d719b2cb-3d3a-4596-a3bc-dad00e67656f ++compile_commands.json + core.* + cov-int/ + pwfile diff --git a/0005-pesign-print-digests-before-filenames-like-sha256sum.patch b/0005-pesign-print-digests-before-filenames-like-sha256sum.patch new file mode 100644 index 0000000..dbce340 --- /dev/null +++ b/0005-pesign-print-digests-before-filenames-like-sha256sum.patch @@ -0,0 +1,31 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Fri, 11 Mar 2022 12:44:46 -0500 +Subject: [PATCH] pesign: print digests before filenames like sha256sum does + +Most digest tools print the digest before the filename, there's no +reason pesign needs to be different. + +Signed-off-by: Peter Jones +--- + src/file_pe.c | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +diff --git a/src/file_pe.c b/src/file_pe.c +index fed6edb..805e614 100644 +--- a/src/file_pe.c ++++ b/src/file_pe.c +@@ -121,12 +121,11 @@ print_digest(pesign_context *pctx) + if (!ctx) + return; + +- printf("%s ", pctx->infile); + int j = ctx->selected_digest; + for (unsigned int i = 0; i < ctx->digests[j].pe_digest->len; i++) + printf("%02x", + (unsigned char)ctx->digests[j].pe_digest->data[i]); +- printf("\n"); ++ printf(" %s\n", pctx->infile); + } + + void diff --git a/0006-Add-pesum-an-authenticode-digest-generator.patch b/0006-Add-pesum-an-authenticode-digest-generator.patch new file mode 100644 index 0000000..10d6fb4 --- /dev/null +++ b/0006-Add-pesum-an-authenticode-digest-generator.patch @@ -0,0 +1,318 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Fri, 11 Mar 2022 12:54:39 -0500 +Subject: [PATCH] Add 'pesum', an authenticode digest generator. + +Signed-off-by: Peter Jones +--- + src/pesum.c | 195 +++++++++++++++++++++++++++++++++++++++++++++++++++++++ + src/.gitignore | 1 + + src/Makefile | 12 +++- + src/pesum.1.mdoc | 38 +++++++++++ + 4 files changed, 244 insertions(+), 2 deletions(-) + create mode 100644 src/pesum.c + create mode 100644 src/pesum.1.mdoc + +diff --git a/src/pesum.c b/src/pesum.c +new file mode 100644 +index 0000000..e4ddaf8 +--- /dev/null ++++ b/src/pesum.c +@@ -0,0 +1,195 @@ ++// SPDX-License-Identifier: GPLv2 ++/* ++ * pesum.c - pesum command line tool ++ * Copyright Peter Jones ++ */ ++ ++#include "fix_coverity.h" ++ ++#include ++#include ++ ++#include ++#include ++ ++#include "pesign.h" ++#include "pesign_standalone.h" ++ ++static struct { ++ int flag; ++ const char *name; ++} flag_names[] = { ++ {DAEMONIZE, "daemonize"}, ++ {GENERATE_DIGEST, "hash"}, ++ {GENERATE_SIGNATURE, "sign"}, ++ {IMPORT_RAW_SIGNATURE, "import-raw-sig"}, ++ {IMPORT_SIGNATURE, "import-sig"}, ++ {IMPORT_SATTRS, "import-sattrs" }, ++ {EXPORT_SATTRS, "export-sattrs" }, ++ {EXPORT_SIGNATURE, "export-sig"}, ++ {EXPORT_PUBKEY, "export-pubkey"}, ++ {EXPORT_CERT, "export-cert"}, ++ {REMOVE_SIGNATURE, "remove"}, ++ {LIST_SIGNATURES, "list"}, ++ {FLAG_LIST_END, NULL}, ++}; ++ ++void ++print_flag_name(FILE *f, int flag) ++{ ++ for (int i = 0; flag_names[i].flag != FLAG_LIST_END; i++) { ++ if (flag_names[i].flag == flag) ++ fprintf(f, "%s ", flag_names[i].name); ++ } ++} ++ ++static long *verbose; ++ ++long ++verbosity(void) ++{ ++ if (!verbose) ++ return 0; ++ return *verbose; ++} ++ ++int ++main(int argc, char *argv[]) ++{ ++ int rc; ++ SECStatus status; ++ ++ char *digest_name = "sha256"; ++ char *orig_digest_name = digest_name; ++ int padding = 1; ++ long verbose_cmd_line = 0; ++ const char *infile; ++ ++ int action = GENERATE_DIGEST|PRINT_DIGEST; ++ file_format fmt = FORMAT_PE_BINARY; ++ ++ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); ++ ++ verbose = &verbose_cmd_line; ++ ++ poptContext optCon; ++ struct poptOption options[] = { ++ {.argInfo = POPT_ARG_INTL_DOMAIN, ++ .arg = "pesum" }, ++ {.longName = "verbose", ++ .shortName = 'v', ++ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL, ++ .arg = &verbose_cmd_line, ++ .val = 1, ++ .descrip = "be more verbose" }, ++ {.longName = "debug", ++ .shortName = '\0', ++ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL, ++ .arg = &verbose_cmd_line, ++ .val = 2, ++ .descrip = "be very verbose" }, ++ {.longName = "digest-type", ++ .shortName = 'd', ++ .argInfo = POPT_ARG_STRING|POPT_ARGFLAG_SHOW_DEFAULT, ++ .arg = &digest_name, ++ .descrip = "digest type to use for pe hash" }, ++ {.longName = "digest_type", ++ .shortName = '\0', ++ .argInfo = POPT_ARG_STRING|POPT_ARGFLAG_DOC_HIDDEN, ++ .arg = &digest_name, ++ .descrip = "digest type to use for pe hash" }, ++ {.longName = "padding", ++ .shortName = 'P', ++ .argInfo = POPT_ARG_VAL, ++ .arg = &padding, ++ .val = 1, ++ .descrip = "pad data section (default)" }, ++ {.longName = "nopadding", ++ .shortName = 'p', ++ .argInfo = POPT_ARG_VAL, ++ .arg = &padding, ++ .val = 0, ++ .descrip = "do not pad the data section" }, ++ POPT_AUTOALIAS ++ POPT_AUTOHELP ++ POPT_TABLEEND ++ }; ++ ++ optCon = poptGetContext("pesum", argc, (const char **)argv, options,0); ++ ++ rc = poptReadDefaultConfig(optCon, 0); ++ if (rc < 0 && !(rc == POPT_ERROR_ERRNO && errno == ENOENT)) ++ errx(1, "poptReadDefaultConfig failed: %s", poptStrerror(rc)); ++ ++ while ((rc = poptGetNextOpt(optCon)) > 0) { ++ ; ++ } ++ ++ if (rc < -1) ++ errx(1, "Invalid argument: %s: %s", ++ poptBadOption(optCon, 0), poptStrerror(rc)); ++ ++ if (!poptPeekArg(optCon)) ++ errx(1, "nothing to do"); ++ ++ status = NSS_NoDB_Init(NULL); ++ if (status != SECSuccess) ++ errx(1, "Could not initialize nss.\n" ++ "NSS says \"%s\" errno says \"%m\"\n", ++ PORT_ErrorToString(PORT_GetError())); ++ ++ while ((infile = poptGetArg(optCon)) != NULL) { ++ pesign_context *ctxp = NULL; ++ ++ char *ext = strrchr(infile, '.'); ++ if (ext && strcmp(ext, ".ko") == 0) ++ fmt = FORMAT_KERNEL_MODULE; ++ ++ rc = pesign_context_new(&ctxp); ++ if (rc < 0) ++ err(1, "Could not initialize context"); ++ ++ ctxp->verbose = verbose_cmd_line; ++ ++ ctxp->hash = 1; ++ ctxp->infile = strdup(infile); ++ if (!ctxp->infile) ++ err(1, "Could not allocate memory"); ++ ++ rc = set_digest_parameters(ctxp->cms_ctx, digest_name); ++ int is_help = strcmp(digest_name, "help") ? 0 : 1; ++ if (rc < 0) { ++ if (!is_help) { ++ fprintf(stderr, "Digest \"%s\" not found.\n", ++ digest_name); ++ } ++ exit(!is_help); ++ } ++ ++ errno = 0; ++ switch (fmt) { ++ case FORMAT_PE_BINARY: ++ pe_handle_action(ctxp, action, padding); ++ break; ++ case FORMAT_KERNEL_MODULE: ++ kmod_handle_action(ctxp, action); ++ break; ++ } ++ ++ pesign_context_free(ctxp); ++ } ++ ++ poptFreeContext(optCon); ++ ++ if (digest_name && digest_name != orig_digest_name) ++ free(digest_name); ++ ++ status = NSS_Shutdown(); ++ if (status != SECSuccess) ++ errx(1, "could not shut down NSS: %s", ++ PORT_ErrorToString(PORT_GetError())); ++ ++ return 0; ++} ++ ++// vim:fenc=utf-8:tw=75:noet +diff --git a/src/.gitignore b/src/.gitignore +index 64ce217..f8f6d66 100644 +--- a/src/.gitignore ++++ b/src/.gitignore +@@ -5,6 +5,7 @@ client + efikeygen + efidbtool + pesigcheck ++pesum + peverify + pesign.service + pesign.sysvinit +diff --git a/src/Makefile b/src/Makefile +index 7010514..79cf09e 100644 +--- a/src/Makefile ++++ b/src/Makefile +@@ -6,7 +6,7 @@ include $(TOPDIR)/Make.rules + include $(TOPDIR)/Make.defaults + + BINTARGETS=authvar client efikeygen pesigcheck pesign \ +- pesign-rpmbuild-helper pesign-authorize ++ pesign-rpmbuild-helper pesign-authorize pesum + CFGTARGETS=tmpfiles.conf + SVCTARGETS=pesign.sysvinit pesign.service + MAN1TARGETS=authvar.1 efikeygen.1 pesigcheck.1 pesign-client.1 pesign.1 +@@ -29,9 +29,12 @@ EFIKEYGEN_SOURCES = efikeygen.c + PESIGCHECK_SOURCES = pesigcheck.c pesigcheck_context.c certdb.c + PESIGN_SOURCES = pesign.c pesign_context.c actions.c daemon.c \ + file_pe.c file_kmod.c pesign_kmod.c ++PESUM_SOURCES = pesum.c pesign_context.c actions.c \ ++ file_pe.c file_kmod.c pesign_kmod.c + + ALL_SOURCES=$(COMMON_SOURCES) $(AUTHVAR_SORUCES) $(CLIENT_SOURCES) \ +- $(EFIKEYGEN_SOURCES) $(PESIGCHECK_SOURCES) $(PESIGN_SOURCES) ++ $(EFIKEYGEN_SOURCES) $(PESIGCHECK_SOURCES) $(PESIGN_SOURCES) \ ++ $(PESUM_SOURCES) + -include $(call deps-of,$(ALL_SOURCES)) + + authvar : $(call objects-of,$(AUTHVAR_SOURCES) $(COMMON_SOURCES)) +@@ -53,6 +56,10 @@ pesign : $(call objects-of,$(PESIGN_SOURCES) $(COMMON_SOURCES) $(COMMON_PE_SOURC + pesign : LDLIBS+=$(TOPDIR)/libdpe/libdpe.a + pesign : PKGS=efivar nss nspr popt + ++pesum : $(call objects-of,$(PESUM_SOURCES) $(COMMON_SOURCES) $(COMMON_PE_SOURCES)) ++pesum : LDLIBS+=$(TOPDIR)/libdpe/libdpe.a ++pesum : PKGS=efivar nss nspr popt ++ + deps : PKGS=efivar nss nspr popt uuid + deps : $(ALL_SOURCES) + $(MAKE) -f $(TOPDIR)/Make.deps \ +@@ -81,6 +88,7 @@ install : + $(INSTALL) -d -m 755 $(INSTALLROOT)$(bindir) + $(INSTALL) -m 755 authvar $(INSTALLROOT)$(bindir) + $(INSTALL) -m 755 pesign $(INSTALLROOT)$(bindir) ++ $(INSTALL) -m 755 pesum $(INSTALLROOT)$(bindir) + $(INSTALL) -m 755 client $(INSTALLROOT)$(bindir)pesign-client + $(INSTALL) -m 755 efikeygen $(INSTALLROOT)$(bindir) + $(INSTALL) -m 755 pesigcheck $(INSTALLROOT)$(bindir) +diff --git a/src/pesum.1.mdoc b/src/pesum.1.mdoc +new file mode 100644 +index 0000000..edd08ce +--- /dev/null ++++ b/src/pesum.1.mdoc +@@ -0,0 +1,38 @@ ++.Dd $Mdocdate: Mar 11 2022$ ++.Dt PESUM 1 ++.Os Linux ++.Sh NAME ++.Nm pesum ++.Nd tool for generating Authenticode digests ++.Sh SYNOPSIS ++.Nm ++.Bk -words ++.Ar file0.efi ++.Op Ar file1.efi ... ++.Sh DESCRIPTION ++.Nm ++is a command line tool to generate Authenticode digests of PE binaries. ++.Sh EXAMPLES ++.Ss Getting the Authenticode digest of some files ++host:$ \fBpesum shimx64.efi grubx64.efi\fR ++8c5806e66bb5b052ebf860e1722474269cff3dde588610df21dbe8cf12c08390\ shimx64.efi ++546a71319c22da1d81879383c4c74be06d1c374bdecfafc9fcc80bd541802bfc\ grubx64.efi ++.Sh STANDARDS ++.Rs ++.%B Portable Executable ++.%I Microsoft ++.%D August 26, 2019 ++.%U https://docs.microsoft.com/en-us/windows/win32/debug/pe-format\ \& ++.Re ++ ++.Rs ++.%B Windows Authenticode Portable Executable Signature Format ++.%I Microsoft ++.%D March 21, 2008 ++.%U https://web.archive.org/web/20130518222430/http://download.microsoft.com/download/9/c/5/9c5b2167-8017-4bae-9fde-d599bac8184a/Authenticode_PE.docx\ \& ++.Re ++.Sh SEE ALSO ++.Xr pesign 1 ++.LP ++.Sh AUTHORS ++.An Peter Jones diff --git a/0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch b/0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch similarity index 97% rename from 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch rename to 0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch index 920eb6a..b342876 100644 --- a/0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch +++ b/0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch @@ -8,7 +8,6 @@ https://bugzilla.redhat.com/show_bug.cgi?id=1880858 Signed-off-by: Julian Sikorski Suggested-by: Will Springer -(cherry picked from commit 9969b1757a1941c9f57081b308026d687f6c0943) --- src/pesign-rpmbuild-helper.in | 24 +++++++++++------------- 1 file changed, 11 insertions(+), 13 deletions(-) diff --git a/0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch b/0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch similarity index 96% rename from 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch rename to 0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch index 0dca694..187a623 100644 --- a/0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch +++ b/0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch @@ -9,7 +9,7 @@ Signed-off-by: Robbie Harwood 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Make.defaults b/Make.defaults -index 130c1ee..4b0e77c 100644 +index 1c18904..05aadd0 100644 --- a/Make.defaults +++ b/Make.defaults @@ -79,7 +79,7 @@ ccldflags = $(cflags) $(CCLDFLAGS) $(LDFLAGS) \ diff --git a/0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch b/0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch similarity index 93% rename from 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch rename to 0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch index 62d1936..68cbe5f 100644 --- a/0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch +++ b/0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch @@ -4,7 +4,6 @@ Date: Tue, 10 Aug 2021 12:39:08 -0400 Subject: [PATCH] macros.pesign: handle centos like rhel with --rhelver Signed-off-by: Peter Jones -(cherry picked from commit a1bc65c8b0fc20dbe9c9714ee3a31937184ba7f6) --- src/macros.pesign | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch b/0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch similarity index 93% rename from 0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch rename to 0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch index 0baddd6..bb4bef2 100644 --- a/0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch +++ b/0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch @@ -6,7 +6,6 @@ Subject: [PATCH] Detect the presence of rpm-sign when checking for "rhel"-ness Signed-off-by: Peter Jones [rharwood: manually reapply to main] Signed-off-by: Robbie Harwood -(cherry picked from commit 17e5878cb087e0a766722d3c487f87c41b318f9a) --- src/pesign-rpmbuild-helper.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/0011-Rename-README-README.md.patch b/0011-Rename-README-README.md.patch new file mode 100644 index 0000000..ff10b8d --- /dev/null +++ b/0011-Rename-README-README.md.patch @@ -0,0 +1,17 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 13 May 2022 15:53:05 -0400 +Subject: [PATCH] Rename README -> README.md + +Rich text will let me compact links. + +Signed-off-by: Robbie Harwood +--- + README => README.md | 0 + 1 file changed, 0 insertions(+), 0 deletions(-) + rename README => README.md (100%) + +diff --git a/README b/README.md +similarity index 100% +rename from README +rename to README.md diff --git a/0012-README.md-show-off-a-bit-more.patch b/0012-README.md-show-off-a-bit-more.patch new file mode 100644 index 0000000..9d624f2 --- /dev/null +++ b/0012-README.md-show-off-a-bit-more.patch @@ -0,0 +1,56 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 13 May 2022 16:09:12 -0400 +Subject: [PATCH] README.md: show off a bit more + +Prominently mention efikeygen and add examples of usage for it and +pesign proper. + +Signed-off-by: Robbie Harwood +--- + README.md | 36 ++++++++++++++++++++++++++++++++---- + 1 file changed, 32 insertions(+), 4 deletions(-) + +diff --git a/README.md b/README.md +index d70bc53..e9f0cb7 100644 +--- a/README.md ++++ b/README.md +@@ -1,6 +1,34 @@ +-Signing tool for PE-COFF binaries, hopefully at least vaguely compliant with +-the PE and Authenticode specifications. ++# pesign + efikeygen + +-This is vaguely analogous to the tool described by +-http://msdn.microsoft.com/en-us/library/8s9b9yaz%28v=vs.80%29.aspx ++Signing tools for PE-COFF binaries. Compliant with the PE and Authenticode ++specifications. + ++(These serve a similar purpose to Microsoft's ++[SignTool.exe](http://msdn.microsoft.com/en-us/library/8s9b9yaz%28v=vs.80%29.aspx), ++except for Linux.) ++ ++## Examples ++ ++Generate a key for use with pesign, stored on disk: ++ ++``` ++efikeyen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' ++``` ++ ++For more complex and secure use cases (e.g., hardware tokens), see ++efikeygen man page (`man efikeygen`). ++ ++Sign a UEFI application using that key: ++ ++``` ++pesign -i grubx64.efi -o grubx64.efi.signed -c 'Custom Secureboot' -s ++``` ++ ++Show signatures on a UEFI application: ++ ++``` ++pesign -i grubx64.efi.signed -S ++``` ++ ++For more signing/verification operations, see the pesign man page (`man ++pesign`). diff --git a/0013-Fix-missing-line-in-README.md.patch b/0013-Fix-missing-line-in-README.md.patch new file mode 100644 index 0000000..185bcc3 --- /dev/null +++ b/0013-Fix-missing-line-in-README.md.patch @@ -0,0 +1,23 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 16 May 2022 15:31:25 -0400 +Subject: [PATCH] Fix missing line in README.md + +Signed-off-by: Robbie Harwood +--- + README.md | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/README.md b/README.md +index e9f0cb7..7bbd6dd 100644 +--- a/README.md ++++ b/README.md +@@ -15,6 +15,8 @@ Generate a key for use with pesign, stored on disk: + efikeyen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' + ``` + ++(where TYPE is m if you're only signing kernel modules, and k otherwise). ++ + For more complex and secure use cases (e.g., hardware tokens), see + efikeygen man page (`man efikeygen`). + diff --git a/0014-Fix-typo-in-efikeygen-command.patch b/0014-Fix-typo-in-efikeygen-command.patch new file mode 100644 index 0000000..82d228d --- /dev/null +++ b/0014-Fix-typo-in-efikeygen-command.patch @@ -0,0 +1,23 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Matt Bernhard +Date: Fri, 27 May 2022 14:40:49 -0400 +Subject: [PATCH] Fix typo in efikeygen command + +Signed-off-by: Matt Bernhard +--- + README.md | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/README.md b/README.md +index 7bbd6dd..b6949a2 100644 +--- a/README.md ++++ b/README.md +@@ -12,7 +12,7 @@ except for Linux.) + Generate a key for use with pesign, stored on disk: + + ``` +-efikeyen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' ++efikeygen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' + ``` + + (where TYPE is m if you're only signing kernel modules, and k otherwise). diff --git a/0015-pesigcheck-Fix-crash-on-digest-match.patch b/0015-pesigcheck-Fix-crash-on-digest-match.patch new file mode 100644 index 0000000..c948558 --- /dev/null +++ b/0015-pesigcheck-Fix-crash-on-digest-match.patch @@ -0,0 +1,53 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Visa Hankala +Date: Fri, 10 Jun 2022 13:25:13 +0000 +Subject: [PATCH] pesigcheck: Fix crash on digest match + +Set selected_digest when the digest is found in db or dbx. +This fixes the following crash of pesigcheck: + + Program received signal SIGSEGV, Segmentation fault. + 0x00005555555597fa in memcpy (__len=24, __src=0x31, + __dest=0x55555558d908) + at /usr/include/x86_64-linux-gnu/bits/string_fortified.h:34 + 34 return __builtin___memcpy_chk (__dest, __src, __len, __bos0 (__dest)); + (gdb) bt + #0 0x00005555555597fa in memcpy (__len=24, __src=0x31, + __dest=0x55555558d908) + at /usr/include/x86_64-linux-gnu/bits/string_fortified.h:34 + #1 get_digest (digest=digest@entry=0x55555558d908, + ctx=, ctx=) at pesigcheck.c:226 + #2 0x00005555555592fd in check_signature ( + reasons=, nreasons=, + ctx=0x7fffffffded0) at pesigcheck.c:262 + #3 main (argc=, argv=) + at pesigcheck.c:512 + +Signed-off-by: Visa Hankala +--- + src/certdb.c | 8 ++++++-- + 1 file changed, 6 insertions(+), 2 deletions(-) + +diff --git a/src/certdb.c b/src/certdb.c +index e013b9d..69d5daf 100644 +--- a/src/certdb.c ++++ b/src/certdb.c +@@ -267,12 +267,16 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, + + if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { + digest = ctx->cms_ctx->digests[0].pe_digest->data; +- if (memcmp (digest, sig->data, 32) == 0) ++ if (memcmp (digest, sig->data, 32) == 0) { ++ ctx->cms_ctx->selected_digest = 0; + return FOUND; ++ } + } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { + digest = ctx->cms_ctx->digests[1].pe_digest->data; +- if (memcmp (digest, sig->data, 20) == 0) ++ if (memcmp (digest, sig->data, 20) == 0) { ++ ctx->cms_ctx->selected_digest = 1; + return FOUND; ++ } + } + + return NOT_FOUND; diff --git a/0016-cms-store-digest-as-pointer-instead-of-index.patch b/0016-cms-store-digest-as-pointer-instead-of-index.patch new file mode 100644 index 0000000..a7fc4dd --- /dev/null +++ b/0016-cms-store-digest-as-pointer-instead-of-index.patch @@ -0,0 +1,272 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 10 Jun 2022 14:40:33 -0400 +Subject: [PATCH] cms: store digest as pointer instead of index + +Storage as an index is problematic because the sentinel value -1 was +used, but accesses were unchecked, leading to crashes like that in +3b1031a6b779cb80c11b34eec84c5a0cc215efed ("pesigcheck: Fix crash on +digest match"). By storing a pointer, we get an explicit NULL +dereference: still a crash, but preferred since it's clearer. + +Since the index was previously also used for retrieving digest +parameters, include a pointer to the relevant struct digest_param in the +struct digest. + +Signed-off-by: Robbie Harwood +--- + src/certdb.c | 15 ++++++++------- + src/cms_common.c | 34 ++++++++++------------------------ + src/content_info.c | 4 ++-- + src/file_kmod.c | 2 +- + src/file_pe.c | 9 +++++---- + src/pesigcheck.c | 4 +--- + src/cms_common.h | 13 ++++++++++++- + 7 files changed, 39 insertions(+), 42 deletions(-) + +diff --git a/src/certdb.c b/src/certdb.c +index 69d5daf..f512824 100644 +--- a/src/certdb.c ++++ b/src/certdb.c +@@ -263,18 +263,19 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, + { + efi_guid_t efi_sha256 = efi_guid_sha256; + efi_guid_t efi_sha1 = efi_guid_sha1; +- void *digest; ++ void *digest_data; ++ struct digest *digests = ctx->cms_ctx->digests; + + if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { +- digest = ctx->cms_ctx->digests[0].pe_digest->data; +- if (memcmp (digest, sig->data, 32) == 0) { +- ctx->cms_ctx->selected_digest = 0; ++ digest_data = digests[0].pe_digest->data; ++ if (memcmp (digest_data, sig->data, 32) == 0) { ++ ctx->cms_ctx->selected_digest = &digests[0]; + return FOUND; + } + } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { +- digest = ctx->cms_ctx->digests[1].pe_digest->data; +- if (memcmp (digest, sig->data, 20) == 0) { +- ctx->cms_ctx->selected_digest = 1; ++ digest_data = digests[1].pe_digest->data; ++ if (memcmp (digest_data, sig->data, 20) == 0) { ++ ctx->cms_ctx->selected_digest = &digests[1]; + return FOUND; + } + } +diff --git a/src/cms_common.c b/src/cms_common.c +index 86341ca..2275f67 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -33,15 +33,6 @@ + + #include "hex.h" + +-struct digest_param { +- char *name; +- SECOidTag digest_tag; +- SECOidTag signature_tag; +- SECOidTag digest_encryption_tag; +- const efi_guid_t *efi_guid; +- int size; +-}; +- + static struct digest_param digest_params[] = { + {.name = "sha256", + .digest_tag = SEC_OID_SHA256, +@@ -65,29 +56,25 @@ static int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); + SECOidTag + digest_get_digest_oid(cms_context *cms) + { +- int i = cms->selected_digest; +- return digest_params[i].digest_tag; ++ return cms->selected_digest->digest_params->digest_tag; + } + + SECOidTag + digest_get_encryption_oid(cms_context *cms) + { +- int i = cms->selected_digest; +- return digest_params[i].digest_encryption_tag; ++ return cms->selected_digest->digest_params->digest_encryption_tag; + } + + SECOidTag + digest_get_signature_oid(cms_context *cms) + { +- int i = cms->selected_digest; +- return digest_params[i].signature_tag; ++ return cms->selected_digest->digest_params->signature_tag; + } + + int + digest_get_digest_size(cms_context *cms) + { +- int i = cms->selected_digest; +- return digest_params[i].size; ++ return cms->selected_digest->digest_params->size; + } + + void +@@ -142,8 +129,6 @@ cms_context_init(cms_context *cms) + if (!cms->arena) + cnreterr(-1, cms, "could not create cryptographic arena"); + +- cms->selected_digest = -1; +- + INIT_LIST_HEAD(&cms->pk12_ins); + cms->pk12_out.fd = -1; + cms->db_out = cms->dbx_out = cms->dbt_out = -1; +@@ -226,7 +211,7 @@ cms_context_fini(cms_context *cms) + memset(&cms->newsig, '\0', sizeof (cms->newsig)); + } + +- cms->selected_digest = -1; ++ cms->selected_digest = NULL; + + if (cms->ci_digest) { + free_poison(cms->ci_digest->data, cms->ci_digest->len); +@@ -351,7 +336,7 @@ set_digest_parameters(cms_context *cms, char *name) + if (strcmp(name, "help")) { + for (int i = 0; i < n_digest_params; i++) { + if (!strcmp(name, digest_params[i].name)) { +- cms->selected_digest = i; ++ cms->selected_digest = &cms->digests[i]; + return 0; + } + } +@@ -1279,6 +1264,7 @@ generate_digest_begin(cms_context *cms) + cngotoerr(err, cms, "could not create digest context"); + + PK11_DigestBegin(digests[i].pk11ctx); ++ digests[i].digest_params = &digest_params[i]; + } + + cms->digests = digests; +@@ -1351,11 +1337,11 @@ generate_signature(cms_context *cms) + { + int rc = 0; + +- if (cms->digests[cms->selected_digest].pe_digest == NULL) ++ if (cms->selected_digest->pe_digest == NULL) + cnreterr(-1, cms, "PE digest has not been allocated"); + +- if (content_is_empty(cms->digests[cms->selected_digest].pe_digest->data, +- cms->digests[cms->selected_digest].pe_digest->len)) ++ if (content_is_empty(cms->selected_digest->pe_digest->data, ++ cms->selected_digest->pe_digest->len)) + cnreterr(-1, cms, "PE binary has not been digested"); + + SECItem sd_der; +diff --git a/src/content_info.c b/src/content_info.c +index 9684850..777aa28 100644 +--- a/src/content_info.c ++++ b/src/content_info.c +@@ -181,8 +181,8 @@ generate_spc_digest_info(cms_context *cms, SECItem *dip) + if (generate_algorithm_id(cms, &di.digestAlgorithm, + digest_get_digest_oid(cms)) < 0) + return -1; +- int i = cms->selected_digest; +- memcpy(&di.digest, cms->digests[i].pe_digest, sizeof (di.digest)); ++ memcpy(&di.digest, cms->selected_digest->pe_digest, ++ sizeof(di.digest)); + + if (content_is_empty(di.digest.data, di.digest.len)) { + cms->log(cms, LOG_ERR, "got empty digest"); +diff --git a/src/file_kmod.c b/src/file_kmod.c +index 6880cda..c8875fc 100644 +--- a/src/file_kmod.c ++++ b/src/file_kmod.c +@@ -60,7 +60,7 @@ ssize_t + kmod_write_signature(cms_context *cms, int outfd) + { + SEC_PKCS7ContentInfo *cinfo; +- SECItem *digest = cms->digests[cms->selected_digest].pe_digest; ++ SECItem *digest = cms->selected_digest->pe_digest; + SECStatus rv; + struct write_sig_info info = { + .outfd = outfd, +diff --git a/src/file_pe.c b/src/file_pe.c +index 805e614..c22b2af 100644 +--- a/src/file_pe.c ++++ b/src/file_pe.c +@@ -114,6 +114,8 @@ check_inputs(pesign_context *ctx) + static void + print_digest(pesign_context *pctx) + { ++ unsigned int i; ++ + if (!pctx) + return; + +@@ -121,10 +123,9 @@ print_digest(pesign_context *pctx) + if (!ctx) + return; + +- int j = ctx->selected_digest; +- for (unsigned int i = 0; i < ctx->digests[j].pe_digest->len; i++) +- printf("%02x", +- (unsigned char)ctx->digests[j].pe_digest->data[i]); ++ unsigned char *ddata = ctx->selected_digest->pe_digest->data; ++ for (i = 0; i < ctx->selected_digest->pe_digest->len; i++) ++ printf("%02x", ddata[i]); + printf(" %s\n", pctx->infile); + } + +diff --git a/src/pesigcheck.c b/src/pesigcheck.c +index 6dc67f7..ebb404d 100644 +--- a/src/pesigcheck.c ++++ b/src/pesigcheck.c +@@ -221,9 +221,7 @@ static void + get_digest(pesigcheck_context *ctx, SECItem *digest) + { + struct cms_context *cms = ctx->cms_ctx; +- struct digest *cms_digest = &cms->digests[cms->selected_digest]; +- +- memcpy(digest, cms_digest->pe_digest, sizeof (*digest)); ++ memcpy(digest, cms->selected_digest->pe_digest, sizeof(*digest)); + } + + static int +diff --git a/src/cms_common.h b/src/cms_common.h +index c7acbcf..c7d4f69 100644 +--- a/src/cms_common.h ++++ b/src/cms_common.h +@@ -12,6 +12,7 @@ + #include + + #include ++#include + #include + #include + #include +@@ -57,9 +58,19 @@ + goto errlabel; \ + }) + ++struct digest_param { ++ char *name; ++ SECOidTag digest_tag; ++ SECOidTag signature_tag; ++ SECOidTag digest_encryption_tag; ++ const efi_guid_t *efi_guid; ++ int size; ++}; ++ + struct digest { + PK11Context *pk11ctx; + SECItem *pe_digest; ++ struct digest_param *digest_params; + }; + + typedef struct pk12_file { +@@ -133,7 +144,7 @@ typedef struct cms_context { + int db_out, dbx_out, dbt_out; + + struct digest *digests; +- int selected_digest; ++ struct digest *selected_digest; + int omit_vendor_cert; + + SECItem newsig; diff --git a/0006-Fix-mandoc-invocation-to-not-produce-garbage.patch b/0017-Fix-mandoc-invocation-to-not-produce-garbage.patch similarity index 93% rename from 0006-Fix-mandoc-invocation-to-not-produce-garbage.patch rename to 0017-Fix-mandoc-invocation-to-not-produce-garbage.patch index fb105df..648055e 100644 --- a/0006-Fix-mandoc-invocation-to-not-produce-garbage.patch +++ b/0017-Fix-mandoc-invocation-to-not-produce-garbage.patch @@ -12,7 +12,6 @@ feed this into man(1). Tell mandoc explicitly to produce man pages. Signed-off-by: Robbie Harwood -(cherry picked from commit 102c3d1d81c090750abb3815481d5cfd3e596677) --- Make.rules | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch b/0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch new file mode 100644 index 0000000..3d0fd63 --- /dev/null +++ b/0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch @@ -0,0 +1,41 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 29 Aug 2022 15:31:52 -0400 +Subject: [PATCH] Work around GCC being obnoxiously incompatible with GCC + +GCC added and then later removed the diagnostic flag +"-Wanalyzer-use-of-uninitialized-value", and so this doesn't work with +newer versions of GCC. + +This patch removes the previous workaround for when it didn't work well. +I really wish any of our compilers had any sense of rigor with this +stuff at all. + +Signed-off-by: Peter Jones +--- + src/daemon.c | 5 ----- + 1 file changed, 5 deletions(-) + +diff --git a/src/daemon.c b/src/daemon.c +index ff88210..d66dd50 100644 +--- a/src/daemon.c ++++ b/src/daemon.c +@@ -917,10 +917,6 @@ do_shutdown(context *ctx, int nsockets, struct pollfd *pollfds) + free(pollfds); + } + +-/* GCC -fanalyzer has trouble with realloc +- * https://bugzilla.redhat.com/show_bug.cgi?id=2047926 */ +-#pragma GCC diagnostic push +-#pragma GCC diagnostic ignored "-Wanalyzer-use-of-uninitialized-value" + static int + handle_events(context *ctx) + { +@@ -999,7 +995,6 @@ shutdown: + } + return 0; + } +-#pragma GCC diagnostic pop + + static int + get_uid_and_gid(context *ctx, char **homedir) diff --git a/0019-get_password_passthrough-handle-the-callback-context.patch b/0019-get_password_passthrough-handle-the-callback-context.patch new file mode 100644 index 0000000..3240a32 --- /dev/null +++ b/0019-get_password_passthrough-handle-the-callback-context.patch @@ -0,0 +1,51 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 29 Aug 2022 14:21:44 -0400 +Subject: [PATCH] get_password_passthrough(): handle the callback context right + +Right now, we have a few callback functions for PK11_Authenticate(), and +they take different arguments. This is incorrect; none of the callers +ever pass anything through except our CMS context. + +This fixes get_password_passthrough() to correctly accept the CMS +context and get the passthrough data from cms->pwdata instead of trying +to treat the CMS context as the pwdata. + +Related: rhbz#2122777 + +Signed-off-by: Peter Jones +--- + src/password.c | 16 +++++++++++++--- + 1 file changed, 13 insertions(+), 3 deletions(-) + +diff --git a/src/password.c b/src/password.c +index 18c32ed..8eb1c33 100644 +--- a/src/password.c ++++ b/src/password.c +@@ -365,13 +365,23 @@ err: + } + + char * +-get_password_passthrough(PK11SlotInfo *slot UNUSED, +- PRBool retry, void *arg) ++get_password_passthrough(PK11SlotInfo *slot UNUSED, PRBool retry, void *arg) + { ++ cms_context *cms; ++ secuPWData *pwdata; ++ ++ dbgprintf("ctx:%p", arg); ++ + if (retry || !arg) + return NULL; + +- char *ret = strdup(arg); ++ cms = (cms_context *)arg; ++ pwdata = &cms->pwdata; ++ ++ if (pwdata->source != PW_PLAINTEXT) ++ return NULL; ++ ++ char *ret = strdup(pwdata->data); + if (!ret) + err(1, "Could not allocate memory"); + diff --git a/0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch b/0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch new file mode 100644 index 0000000..b69d5ff --- /dev/null +++ b/0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch @@ -0,0 +1,47 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 29 Aug 2022 15:22:10 -0400 +Subject: [PATCH] read_password(): only prune CR/NL from the end of the file + +Right now, when we read the password/PIN from a file, we're pruning the +end of the string from the file we read indiscriminately. If you don't +have a newline, that means we're cutting off the final digits of the +text. + +This changes it to prune only common special characters from the +pinfile, but also to prune /all/ of them. + +Related: rhbz#2122777 +Signed-off-by: Peter Jones +--- + src/password.c | 10 +++++++++- + 1 file changed, 9 insertions(+), 1 deletion(-) + +diff --git a/src/password.c b/src/password.c +index 8eb1c33..ac1866e 100644 +--- a/src/password.c ++++ b/src/password.c +@@ -79,6 +79,7 @@ read_password(FILE *in, FILE *out, char *buf, size_t bufsz) + int infd = fileno(in); + struct termios tio; + char *ret; ++ int len; + + ingress(); + ret = fgets(buf, bufsz, in); +@@ -96,7 +97,14 @@ read_password(FILE *in, FILE *out, char *buf, size_t bufsz) + if (ret == NULL) + return -1; + +- buf[strlen(buf)-1] = '\0'; ++ len = strlen(buf); ++ while (len > 0 && (buf[len-1] == '\r' || buf[len-1] == '\n')) { ++ buf[len-1] = '\0'; ++ len--; ++ } ++ if (len == 0) ++ return -1; ++ + egress(); + return 0; + } diff --git a/0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch b/0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch new file mode 100644 index 0000000..ac9bdfd --- /dev/null +++ b/0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch @@ -0,0 +1,276 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 29 Aug 2022 16:22:18 -0400 +Subject: [PATCH] Revert "cms: store digest as pointer instead of index" + +In 926782c216532a83f9ff864dee39d2349d61fd23, we switched +cms->selected_digest to be a pointer to the member of the digests array +rather than an index. Unfortunately this is just as bad, because the +bugs that come up wind up setting pointers to NULL+(selected*offset), +i.e. 0x10, and that doesn't get us any closer to actually finding any +problem. + +For now, the new approach is going to be to make it an index again, but +to default it to 0 (sha256) rather than -1, so if it isn't set at the +correct part of the lifecycle it'll just default to the (nearly always) +correct choice. + +This reverts commit 926782c216532a83f9ff864dee39d2349d61fd23. + +Signed-off-by: Peter Jones +--- + src/certdb.c | 15 +++++++-------- + src/cms_common.c | 34 ++++++++++++++++++++++++---------- + src/content_info.c | 4 ++-- + src/file_kmod.c | 2 +- + src/file_pe.c | 9 ++++----- + src/pesigcheck.c | 4 +++- + src/cms_common.h | 13 +------------ + 7 files changed, 42 insertions(+), 39 deletions(-) + +diff --git a/src/certdb.c b/src/certdb.c +index f512824..69d5daf 100644 +--- a/src/certdb.c ++++ b/src/certdb.c +@@ -263,19 +263,18 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, + { + efi_guid_t efi_sha256 = efi_guid_sha256; + efi_guid_t efi_sha1 = efi_guid_sha1; +- void *digest_data; +- struct digest *digests = ctx->cms_ctx->digests; ++ void *digest; + + if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { +- digest_data = digests[0].pe_digest->data; +- if (memcmp (digest_data, sig->data, 32) == 0) { +- ctx->cms_ctx->selected_digest = &digests[0]; ++ digest = ctx->cms_ctx->digests[0].pe_digest->data; ++ if (memcmp (digest, sig->data, 32) == 0) { ++ ctx->cms_ctx->selected_digest = 0; + return FOUND; + } + } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { +- digest_data = digests[1].pe_digest->data; +- if (memcmp (digest_data, sig->data, 20) == 0) { +- ctx->cms_ctx->selected_digest = &digests[1]; ++ digest = ctx->cms_ctx->digests[1].pe_digest->data; ++ if (memcmp (digest, sig->data, 20) == 0) { ++ ctx->cms_ctx->selected_digest = 1; + return FOUND; + } + } +diff --git a/src/cms_common.c b/src/cms_common.c +index 2275f67..86341ca 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -33,6 +33,15 @@ + + #include "hex.h" + ++struct digest_param { ++ char *name; ++ SECOidTag digest_tag; ++ SECOidTag signature_tag; ++ SECOidTag digest_encryption_tag; ++ const efi_guid_t *efi_guid; ++ int size; ++}; ++ + static struct digest_param digest_params[] = { + {.name = "sha256", + .digest_tag = SEC_OID_SHA256, +@@ -56,25 +65,29 @@ static int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); + SECOidTag + digest_get_digest_oid(cms_context *cms) + { +- return cms->selected_digest->digest_params->digest_tag; ++ int i = cms->selected_digest; ++ return digest_params[i].digest_tag; + } + + SECOidTag + digest_get_encryption_oid(cms_context *cms) + { +- return cms->selected_digest->digest_params->digest_encryption_tag; ++ int i = cms->selected_digest; ++ return digest_params[i].digest_encryption_tag; + } + + SECOidTag + digest_get_signature_oid(cms_context *cms) + { +- return cms->selected_digest->digest_params->signature_tag; ++ int i = cms->selected_digest; ++ return digest_params[i].signature_tag; + } + + int + digest_get_digest_size(cms_context *cms) + { +- return cms->selected_digest->digest_params->size; ++ int i = cms->selected_digest; ++ return digest_params[i].size; + } + + void +@@ -129,6 +142,8 @@ cms_context_init(cms_context *cms) + if (!cms->arena) + cnreterr(-1, cms, "could not create cryptographic arena"); + ++ cms->selected_digest = -1; ++ + INIT_LIST_HEAD(&cms->pk12_ins); + cms->pk12_out.fd = -1; + cms->db_out = cms->dbx_out = cms->dbt_out = -1; +@@ -211,7 +226,7 @@ cms_context_fini(cms_context *cms) + memset(&cms->newsig, '\0', sizeof (cms->newsig)); + } + +- cms->selected_digest = NULL; ++ cms->selected_digest = -1; + + if (cms->ci_digest) { + free_poison(cms->ci_digest->data, cms->ci_digest->len); +@@ -336,7 +351,7 @@ set_digest_parameters(cms_context *cms, char *name) + if (strcmp(name, "help")) { + for (int i = 0; i < n_digest_params; i++) { + if (!strcmp(name, digest_params[i].name)) { +- cms->selected_digest = &cms->digests[i]; ++ cms->selected_digest = i; + return 0; + } + } +@@ -1264,7 +1279,6 @@ generate_digest_begin(cms_context *cms) + cngotoerr(err, cms, "could not create digest context"); + + PK11_DigestBegin(digests[i].pk11ctx); +- digests[i].digest_params = &digest_params[i]; + } + + cms->digests = digests; +@@ -1337,11 +1351,11 @@ generate_signature(cms_context *cms) + { + int rc = 0; + +- if (cms->selected_digest->pe_digest == NULL) ++ if (cms->digests[cms->selected_digest].pe_digest == NULL) + cnreterr(-1, cms, "PE digest has not been allocated"); + +- if (content_is_empty(cms->selected_digest->pe_digest->data, +- cms->selected_digest->pe_digest->len)) ++ if (content_is_empty(cms->digests[cms->selected_digest].pe_digest->data, ++ cms->digests[cms->selected_digest].pe_digest->len)) + cnreterr(-1, cms, "PE binary has not been digested"); + + SECItem sd_der; +diff --git a/src/content_info.c b/src/content_info.c +index 777aa28..9684850 100644 +--- a/src/content_info.c ++++ b/src/content_info.c +@@ -181,8 +181,8 @@ generate_spc_digest_info(cms_context *cms, SECItem *dip) + if (generate_algorithm_id(cms, &di.digestAlgorithm, + digest_get_digest_oid(cms)) < 0) + return -1; +- memcpy(&di.digest, cms->selected_digest->pe_digest, +- sizeof(di.digest)); ++ int i = cms->selected_digest; ++ memcpy(&di.digest, cms->digests[i].pe_digest, sizeof (di.digest)); + + if (content_is_empty(di.digest.data, di.digest.len)) { + cms->log(cms, LOG_ERR, "got empty digest"); +diff --git a/src/file_kmod.c b/src/file_kmod.c +index c8875fc..6880cda 100644 +--- a/src/file_kmod.c ++++ b/src/file_kmod.c +@@ -60,7 +60,7 @@ ssize_t + kmod_write_signature(cms_context *cms, int outfd) + { + SEC_PKCS7ContentInfo *cinfo; +- SECItem *digest = cms->selected_digest->pe_digest; ++ SECItem *digest = cms->digests[cms->selected_digest].pe_digest; + SECStatus rv; + struct write_sig_info info = { + .outfd = outfd, +diff --git a/src/file_pe.c b/src/file_pe.c +index c22b2af..805e614 100644 +--- a/src/file_pe.c ++++ b/src/file_pe.c +@@ -114,8 +114,6 @@ check_inputs(pesign_context *ctx) + static void + print_digest(pesign_context *pctx) + { +- unsigned int i; +- + if (!pctx) + return; + +@@ -123,9 +121,10 @@ print_digest(pesign_context *pctx) + if (!ctx) + return; + +- unsigned char *ddata = ctx->selected_digest->pe_digest->data; +- for (i = 0; i < ctx->selected_digest->pe_digest->len; i++) +- printf("%02x", ddata[i]); ++ int j = ctx->selected_digest; ++ for (unsigned int i = 0; i < ctx->digests[j].pe_digest->len; i++) ++ printf("%02x", ++ (unsigned char)ctx->digests[j].pe_digest->data[i]); + printf(" %s\n", pctx->infile); + } + +diff --git a/src/pesigcheck.c b/src/pesigcheck.c +index ebb404d..6dc67f7 100644 +--- a/src/pesigcheck.c ++++ b/src/pesigcheck.c +@@ -221,7 +221,9 @@ static void + get_digest(pesigcheck_context *ctx, SECItem *digest) + { + struct cms_context *cms = ctx->cms_ctx; +- memcpy(digest, cms->selected_digest->pe_digest, sizeof(*digest)); ++ struct digest *cms_digest = &cms->digests[cms->selected_digest]; ++ ++ memcpy(digest, cms_digest->pe_digest, sizeof (*digest)); + } + + static int +diff --git a/src/cms_common.h b/src/cms_common.h +index c7d4f69..c7acbcf 100644 +--- a/src/cms_common.h ++++ b/src/cms_common.h +@@ -12,7 +12,6 @@ + #include + + #include +-#include + #include + #include + #include +@@ -58,19 +57,9 @@ + goto errlabel; \ + }) + +-struct digest_param { +- char *name; +- SECOidTag digest_tag; +- SECOidTag signature_tag; +- SECOidTag digest_encryption_tag; +- const efi_guid_t *efi_guid; +- int size; +-}; +- + struct digest { + PK11Context *pk11ctx; + SECItem *pe_digest; +- struct digest_param *digest_params; + }; + + typedef struct pk12_file { +@@ -144,7 +133,7 @@ typedef struct cms_context { + int db_out, dbx_out, dbt_out; + + struct digest *digests; +- struct digest *selected_digest; ++ int selected_digest; + int omit_vendor_cert; + + SECItem newsig; diff --git a/0022-CMS-add-some-minor-cleanups.patch b/0022-CMS-add-some-minor-cleanups.patch new file mode 100644 index 0000000..dfff3f5 --- /dev/null +++ b/0022-CMS-add-some-minor-cleanups.patch @@ -0,0 +1,149 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 29 Aug 2022 17:02:46 -0400 +Subject: [PATCH] CMS: add some minor cleanups + +We reverted 926782c216532a83f9ff864dee39d2349d61fd23 so that a future +patch can try a different approach, but that commit also had a few +cleanups that are worthwhile on their own. + +This patch re-introduces the cleanup to move "struct digest_param" to a +more reasonable place and the cleanup to check_hash(), and takes it just +a bit farther. + +Signed-off-by: Peter Jones +--- + src/certdb.c | 26 +++++++++++++++----------- + src/cms_common.c | 39 ++++++++++++++++----------------------- + src/cms_common.h | 16 ++++++++++++++++ + 3 files changed, 47 insertions(+), 34 deletions(-) + +diff --git a/src/certdb.c b/src/certdb.c +index 69d5daf..eb5221f 100644 +--- a/src/certdb.c ++++ b/src/certdb.c +@@ -263,20 +263,24 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, + { + efi_guid_t efi_sha256 = efi_guid_sha256; + efi_guid_t efi_sha1 = efi_guid_sha1; +- void *digest; ++ void *digest_data; ++ struct digest *digests = ctx->cms_ctx->digests; ++ int selected_digest = -1; ++ size_t size; + + if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { +- digest = ctx->cms_ctx->digests[0].pe_digest->data; +- if (memcmp (digest, sig->data, 32) == 0) { +- ctx->cms_ctx->selected_digest = 0; +- return FOUND; +- } ++ selected_digest = DIGEST_PARAM_SHA256; + } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { +- digest = ctx->cms_ctx->digests[1].pe_digest->data; +- if (memcmp (digest, sig->data, 20) == 0) { +- ctx->cms_ctx->selected_digest = 1; +- return FOUND; +- } ++ selected_digest = DIGEST_PARAM_SHA1; ++ } else { ++ return NOT_FOUND; ++ } ++ ++ digest_data = digests[selected_digest].pe_digest->data; ++ size = digest_params[selected_digest].size; ++ if (memcmp (digest_data, sig->data, size) == 0) { ++ ctx->cms_ctx->selected_digest = selected_digest; ++ return FOUND; + } + + return NOT_FOUND; +diff --git a/src/cms_common.c b/src/cms_common.c +index 86341ca..7bddedf 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -33,34 +33,27 @@ + + #include "hex.h" + +-struct digest_param { +- char *name; +- SECOidTag digest_tag; +- SECOidTag signature_tag; +- SECOidTag digest_encryption_tag; +- const efi_guid_t *efi_guid; +- int size; +-}; +- +-static struct digest_param digest_params[] = { +- {.name = "sha256", +- .digest_tag = SEC_OID_SHA256, +- .signature_tag = SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION, +- .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, +- .efi_guid = &efi_guid_sha256, +- .size = 32 ++const struct digest_param digest_params[] = { ++ [DIGEST_PARAM_SHA256] = { ++ .name = "sha256", ++ .digest_tag = SEC_OID_SHA256, ++ .signature_tag = SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION, ++ .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, ++ .efi_guid = &efi_guid_sha256, ++ .size = 32 + }, + #if 1 +- {.name = "sha1", +- .digest_tag = SEC_OID_SHA1, +- .signature_tag = SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION, +- .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, +- .efi_guid = &efi_guid_sha1, +- .size = 20 ++ [DIGEST_PARAM_SHA1] = { ++ .name = "sha1", ++ .digest_tag = SEC_OID_SHA1, ++ .signature_tag = SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION, ++ .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, ++ .efi_guid = &efi_guid_sha1, ++ .size = 20 + }, + #endif + }; +-static int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); ++const int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); + + SECOidTag + digest_get_digest_oid(cms_context *cms) +diff --git a/src/cms_common.h b/src/cms_common.h +index c7acbcf..e45402c 100644 +--- a/src/cms_common.h ++++ b/src/cms_common.h +@@ -12,6 +12,7 @@ + #include + + #include ++#include + #include + #include + #include +@@ -62,6 +63,21 @@ struct digest { + SECItem *pe_digest; + }; + ++#define DIGEST_PARAM_SHA256 0 ++#define DIGEST_PARAM_SHA1 1 ++ ++struct digest_param { ++ char *name; ++ SECOidTag digest_tag; ++ SECOidTag signature_tag; ++ SECOidTag digest_encryption_tag; ++ const efi_guid_t *efi_guid; ++ int size; ++}; ++ ++extern const struct digest_param digest_params[2]; ++extern const int n_digest_params; ++ + typedef struct pk12_file { + char *path; + int fd; diff --git a/0023-CMS-make-cms-selected_digest-an-index-again.patch b/0023-CMS-make-cms-selected_digest-an-index-again.patch new file mode 100644 index 0000000..6e19cd1 --- /dev/null +++ b/0023-CMS-make-cms-selected_digest-an-index-again.patch @@ -0,0 +1,291 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Tue, 30 Aug 2022 15:42:15 -0400 +Subject: [PATCH] CMS: make cms->selected_digest an index (again) + +In 926782c216532a83f9ff864dee39d2349d61fd23, we switched +cms->selected_digest to be a pointer to the entry in cms->digests. + +Because cms->digests is lazily allocated, setting the selected_digest +pointer has to be done at the right part of the CMS context life cycle, +and in some cases it clearly is not: + +==334217== Command: ./src/pesign -n tmp -s --pinfile tmp/pinfile -t OpenSC\ Card\ (testcard) -c kernel-signer -i tmp/unsigned.efi -o tmp/signed.efi --force +==334217== +==334217== Invalid read of size 8 +==334217== at 0x115E7D: digest_get_digest_oid (cms_common.c:59) +==334217== by 0x11CF41: generate_algorithm_id_list (signed_data.c:33) +==334217== by 0x11D348: generate_spc_signed_data (signed_data.c:279) +==334217== by 0x11EDFD: calculate_signature_space (wincert.c:297) +==334217== by 0x11467D: pe_handle_action (file_pe.c:298) +==334217== by 0x10F962: main (pesign.c:585) +==334217== Address 0x10 is not stack'd, malloc'd or (recently) free'd +==334217== +==334217== +==334217== Process terminating with default action of signal 11 (SIGSEGV): dumping core +==334217== Access not within mapped region at address 0x10 +==334217== at 0x115E7D: digest_get_digest_oid (cms_common.c:59) +==334217== by 0x11CF41: generate_algorithm_id_list (signed_data.c:33) +==334217== by 0x11D348: generate_spc_signed_data (signed_data.c:279) +==334217== by 0x11EDFD: calculate_signature_space (wincert.c:297) +==334217== by 0x11467D: pe_handle_action (file_pe.c:298) +==334217== by 0x10F962: main (pesign.c:585) +==334217== If you believe this happened as a result of a stack +==334217== overflow in your program's main thread (unlikely but +==334217== possible), you can try to increase the size of the +==334217== main thread stack using the --main-stacksize= flag. +==334217== The main thread stack size used in this run was 8388608. +==334217== +==334217== HEAP SUMMARY: +==334217== in use at exit: 588,544 bytes in 4,388 blocks +==334217== total heap usage: 8,568 allocs, 4,180 frees, 2,077,115 bytes allocated +==334217== +==334217== LEAK SUMMARY: +==334217== definitely lost: 25 bytes in 1 blocks +==334217== indirectly lost: 0 bytes in 0 blocks +==334217== possibly lost: 51,378 bytes in 166 blocks +==334217== still reachable: 537,141 bytes in 4,221 blocks +==334217== of which reachable via heuristic: +==334217== length64 : 321,312 bytes in 590 blocks +==334217== suppressed: 0 bytes in 0 blocks +==334217== Rerun with --leak-check=full to see details of leaked memory +==334217== +==334217== For lists of detected and suppressed errors, rerun with: -s +==334217== ERROR SUMMARY: 1 errors from 1 contexts (suppressed: 0 from 0) +Segmentation fault (core dumped) + +There is also a similar issue in the daemon code, and how to fix it +there is not immediately clear to me. + +Currently, we realistically only support using sha256 digests, so for +now I've chosen to paper over the issue by switching back to +cms->selected_digest be an index into both ctx->digests and +digest_params, but switching the default value from -1 to 0, aka +DIGEST_PARAM_SHA256. We can revisit this issue later whenever we add +sha384 support (or whichever other digest). + +Signed-off-by: Peter Jones +--- + src/certdb.c | 2 +- + src/cms_common.c | 41 +++++++++++++++++++++++------------------ + src/content_info.c | 2 +- + src/cms_common.h | 5 +++-- + 4 files changed, 28 insertions(+), 22 deletions(-) + +diff --git a/src/certdb.c b/src/certdb.c +index eb5221f..467a01d 100644 +--- a/src/certdb.c ++++ b/src/certdb.c +@@ -265,7 +265,7 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, + efi_guid_t efi_sha1 = efi_guid_sha1; + void *digest_data; + struct digest *digests = ctx->cms_ctx->digests; +- int selected_digest = -1; ++ unsigned int selected_digest; + size_t size; + + if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { +diff --git a/src/cms_common.c b/src/cms_common.c +index 7bddedf..1c54c90 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -33,6 +33,10 @@ + + #include "hex.h" + ++/* ++ * Note that cms->selected_digest defaults to 0, which means the first ++ * entry of this array is the default digest. ++ */ + const struct digest_param digest_params[] = { + [DIGEST_PARAM_SHA256] = { + .name = "sha256", +@@ -53,33 +57,33 @@ const struct digest_param digest_params[] = { + }, + #endif + }; +-const int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); ++const unsigned int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); + + SECOidTag + digest_get_digest_oid(cms_context *cms) + { +- int i = cms->selected_digest; ++ unsigned int i = cms->selected_digest; + return digest_params[i].digest_tag; + } + + SECOidTag + digest_get_encryption_oid(cms_context *cms) + { +- int i = cms->selected_digest; ++ unsigned int i = cms->selected_digest; + return digest_params[i].digest_encryption_tag; + } + + SECOidTag + digest_get_signature_oid(cms_context *cms) + { +- int i = cms->selected_digest; ++ unsigned int i = cms->selected_digest; + return digest_params[i].signature_tag; + } + + int + digest_get_digest_size(cms_context *cms) + { +- int i = cms->selected_digest; ++ unsigned int i = cms->selected_digest; + return digest_params[i].size; + } + +@@ -91,7 +95,7 @@ teardown_digests(cms_context *ctx) + if (!digests) + return; + +- for (int i = 0; i < n_digest_params; i++) { ++ for (unsigned int i = 0; i < n_digest_params; i++) { + if (digests[i].pk11ctx) { + PK11_Finalize(digests[i].pk11ctx); + PK11_DestroyContext(digests[i].pk11ctx, PR_TRUE); +@@ -135,7 +139,7 @@ cms_context_init(cms_context *cms) + if (!cms->arena) + cnreterr(-1, cms, "could not create cryptographic arena"); + +- cms->selected_digest = -1; ++ cms->selected_digest = DEFAULT_DIGEST_PARAM; + + INIT_LIST_HEAD(&cms->pk12_ins); + cms->pk12_out.fd = -1; +@@ -219,7 +223,7 @@ cms_context_fini(cms_context *cms) + memset(&cms->newsig, '\0', sizeof (cms->newsig)); + } + +- cms->selected_digest = -1; ++ cms->selected_digest = DEFAULT_DIGEST_PARAM; + + if (cms->ci_digest) { + free_poison(cms->ci_digest->data, cms->ci_digest->len); +@@ -342,7 +346,7 @@ int + set_digest_parameters(cms_context *cms, char *name) + { + if (strcmp(name, "help")) { +- for (int i = 0; i < n_digest_params; i++) { ++ for (unsigned int i = 0; i < n_digest_params; i++) { + if (!strcmp(name, digest_params[i].name)) { + cms->selected_digest = i; + return 0; +@@ -350,7 +354,7 @@ set_digest_parameters(cms_context *cms, char *name) + } + } else { + printf("Supported digests: "); +- for (int i = 0; digest_params[i].name != NULL; i++) { ++ for (unsigned int i = 0; digest_params[i].name != NULL; i++) { + printf("%s ", digest_params[i].name); + } + printf("\n"); +@@ -1265,7 +1269,7 @@ generate_digest_begin(cms_context *cms) + cnreterr(-1, cms, "could not allocate digest context"); + } + +- for (int i = 0; i < n_digest_params; i++) { ++ for (unsigned int i = 0; i < n_digest_params; i++) { + digests[i].pk11ctx = PK11_CreateDigestContext( + digest_params[i].digest_tag); + if (!digests[i].pk11ctx) +@@ -1278,7 +1282,7 @@ generate_digest_begin(cms_context *cms) + return 0; + + err: +- for (int i = 0; i < n_digest_params; i++) { ++ for (unsigned int i = 0; i < n_digest_params; i++) { + if (digests[i].pk11ctx) + PK11_DestroyContext(digests[i].pk11ctx, PR_TRUE); + } +@@ -1290,7 +1294,7 @@ err: + void + generate_digest_step(cms_context *cms, void *data, size_t len) + { +- for (int i = 0; i < n_digest_params; i++) ++ for (unsigned int i = 0; i < n_digest_params; i++) + PK11_DigestOp(cms->digests[i].pk11ctx, data, len); + } + +@@ -1299,7 +1303,7 @@ generate_digest_finish(cms_context *cms) + { + void *mark = PORT_ArenaMark(cms->arena); + +- for (int i = 0; i < n_digest_params; i++) { ++ for (unsigned int i = 0; i < n_digest_params; i++) { + SECItem *digest = PORT_ArenaZAlloc(cms->arena,sizeof (SECItem)); + if (digest == NULL) + cngotoerr(err, cms, "could not allocate memory"); +@@ -1326,7 +1330,7 @@ generate_digest_finish(cms_context *cms) + PORT_ArenaUnmark(cms->arena, mark); + return 0; + err: +- for (int i = 0; i < n_digest_params; i++) { ++ for (unsigned int i = 0; i < n_digest_params; i++) { + if (cms->digests[i].pk11ctx) + PK11_DestroyContext(cms->digests[i].pk11ctx, PR_TRUE); + } +@@ -1343,12 +1347,13 @@ int + generate_signature(cms_context *cms) + { + int rc = 0; ++ int i = cms->selected_digest; + +- if (cms->digests[cms->selected_digest].pe_digest == NULL) ++ if (cms->digests[i].pe_digest == NULL) + cnreterr(-1, cms, "PE digest has not been allocated"); + +- if (content_is_empty(cms->digests[cms->selected_digest].pe_digest->data, +- cms->digests[cms->selected_digest].pe_digest->len)) ++ if (content_is_empty(cms->digests[i].pe_digest->data, ++ cms->digests[i].pe_digest->len)) + cnreterr(-1, cms, "PE binary has not been digested"); + + SECItem sd_der; +diff --git a/src/content_info.c b/src/content_info.c +index 9684850..900974c 100644 +--- a/src/content_info.c ++++ b/src/content_info.c +@@ -181,7 +181,7 @@ generate_spc_digest_info(cms_context *cms, SECItem *dip) + if (generate_algorithm_id(cms, &di.digestAlgorithm, + digest_get_digest_oid(cms)) < 0) + return -1; +- int i = cms->selected_digest; ++ unsigned int i = cms->selected_digest; + memcpy(&di.digest, cms->digests[i].pe_digest, sizeof (di.digest)); + + if (content_is_empty(di.digest.data, di.digest.len)) { +diff --git a/src/cms_common.h b/src/cms_common.h +index e45402c..35a128a 100644 +--- a/src/cms_common.h ++++ b/src/cms_common.h +@@ -65,6 +65,7 @@ struct digest { + + #define DIGEST_PARAM_SHA256 0 + #define DIGEST_PARAM_SHA1 1 ++#define DEFAULT_DIGEST_PARAM DIGEST_PARAM_SHA256 + + struct digest_param { + char *name; +@@ -76,7 +77,7 @@ struct digest_param { + }; + + extern const struct digest_param digest_params[2]; +-extern const int n_digest_params; ++extern const unsigned int n_digest_params; + + typedef struct pk12_file { + char *path; +@@ -149,7 +150,7 @@ typedef struct cms_context { + int db_out, dbx_out, dbt_out; + + struct digest *digests; +- int selected_digest; ++ unsigned int selected_digest; + int omit_vendor_cert; + + SECItem newsig; diff --git a/pesign.patches b/pesign.patches index 9b257c3..0b756e9 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1,6 +1,23 @@ Patch0001: 0001-daemon-remove-always-true-comparison.patch -Patch0002: 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch -Patch0003: 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch -Patch0004: 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch -Patch0005: 0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch -Patch0006: 0006-Fix-mandoc-invocation-to-not-produce-garbage.patch +Patch0002: 0002-make-handle-some-gcc-Wanalyzer-flags-better.patch +Patch0003: 0003-Rename-dprintf-to-dbgprintf.patch +Patch0004: 0004-.gitignore-add-compile_commands.json-and-.cache.patch +Patch0005: 0005-pesign-print-digests-before-filenames-like-sha256sum.patch +Patch0006: 0006-Add-pesum-an-authenticode-digest-generator.patch +Patch0007: 0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch +Patch0008: 0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch +Patch0009: 0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch +Patch0010: 0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch +Patch0011: 0011-Rename-README-README.md.patch +Patch0012: 0012-README.md-show-off-a-bit-more.patch +Patch0013: 0013-Fix-missing-line-in-README.md.patch +Patch0014: 0014-Fix-typo-in-efikeygen-command.patch +Patch0015: 0015-pesigcheck-Fix-crash-on-digest-match.patch +Patch0016: 0016-cms-store-digest-as-pointer-instead-of-index.patch +Patch0017: 0017-Fix-mandoc-invocation-to-not-produce-garbage.patch +Patch0018: 0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch +Patch0019: 0019-get_password_passthrough-handle-the-callback-context.patch +Patch0020: 0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch +Patch0021: 0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch +Patch0022: 0022-CMS-add-some-minor-cleanups.patch +Patch0023: 0023-CMS-make-cms-selected_digest-an-index-again.patch diff --git a/pesign.spec b/pesign.spec index 118b151..4c835d0 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 8%{?dist} +Release: 9%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -132,12 +132,13 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %files %{!?_licensedir:%global license %%doc} %license COPYING -%doc README TODO +%doc README.md TODO %{_bindir}/authvar %{_bindir}/efikeygen %{_bindir}/pesigcheck %{_bindir}/pesign %{_bindir}/pesign-client +%{_bindir}/pesum %dir %{_libexecdir}/pesign/ %dir %attr(0770,pesign,pesign) %{_sysconfdir}/pki/pesign/ %config(noreplace) %attr(0660,pesign,pesign) %{_sysconfdir}/pki/pesign/* @@ -161,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Wed Aug 31 2022 Robbie Harwood - 115-9 +- Roll up to pjones's smartcard/cms fixes + * Tue Aug 02 2022 Robbie Harwood - 115-8 - Rebuild for python bytecode change - See-also: #2107826 From 0b14fad476cc2b12dedda1d477285de909a2c94b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 31 Jan 2023 15:03:53 +0000 Subject: [PATCH 59/70] New upstream release (116) Resolves: CVE-2022-3560 Signed-off-by: Robbie Harwood --- ...daemon-remove-always-true-comparison.patch | 24 - ...ndle-some-gcc-Wanalyzer-flags-better.patch | 40 -- 0003-Rename-dprintf-to-dbgprintf.patch | 664 ------------------ ...add-compile_commands.json-and-.cache.patch | 30 - ...ests-before-filenames-like-sha256sum.patch | 31 - ...sum-an-authenticode-digest-generator.patch | 318 --------- ...ned-kernels-on-setups-other-than-koj.patch | 54 -- ...Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch | 23 - ...handle-centos-like-rhel-with-rhelver.patch | 24 - ...nce-of-rpm-sign-when-checking-for-rh.patch | 25 - 0011-Rename-README-README.md.patch | 17 - 0012-README.md-show-off-a-bit-more.patch | 56 -- 0013-Fix-missing-line-in-README.md.patch | 23 - 0014-Fix-typo-in-efikeygen-command.patch | 23 - ...pesigcheck-Fix-crash-on-digest-match.patch | 53 -- ...e-digest-as-pointer-instead-of-index.patch | 272 ------- ...oc-invocation-to-not-produce-garbage.patch | 31 - ...being-obnoxiously-incompatible-with-.patch | 41 -- ...sthrough-handle-the-callback-context.patch | 51 -- ...ly-prune-CR-NL-from-the-end-of-the-f.patch | 47 -- ...e-digest-as-pointer-instead-of-index.patch | 276 -------- 0022-CMS-add-some-minor-cleanups.patch | 149 ---- ...e-cms-selected_digest-an-index-again.patch | 291 -------- pesign.patches | 23 - pesign.spec | 8 +- sources | 2 +- 26 files changed, 7 insertions(+), 2589 deletions(-) delete mode 100644 0001-daemon-remove-always-true-comparison.patch delete mode 100644 0002-make-handle-some-gcc-Wanalyzer-flags-better.patch delete mode 100644 0003-Rename-dprintf-to-dbgprintf.patch delete mode 100644 0004-.gitignore-add-compile_commands.json-and-.cache.patch delete mode 100644 0005-pesign-print-digests-before-filenames-like-sha256sum.patch delete mode 100644 0006-Add-pesum-an-authenticode-digest-generator.patch delete mode 100644 0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch delete mode 100644 0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch delete mode 100644 0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch delete mode 100644 0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch delete mode 100644 0011-Rename-README-README.md.patch delete mode 100644 0012-README.md-show-off-a-bit-more.patch delete mode 100644 0013-Fix-missing-line-in-README.md.patch delete mode 100644 0014-Fix-typo-in-efikeygen-command.patch delete mode 100644 0015-pesigcheck-Fix-crash-on-digest-match.patch delete mode 100644 0016-cms-store-digest-as-pointer-instead-of-index.patch delete mode 100644 0017-Fix-mandoc-invocation-to-not-produce-garbage.patch delete mode 100644 0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch delete mode 100644 0019-get_password_passthrough-handle-the-callback-context.patch delete mode 100644 0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch delete mode 100644 0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch delete mode 100644 0022-CMS-add-some-minor-cleanups.patch delete mode 100644 0023-CMS-make-cms-selected_digest-an-index-again.patch diff --git a/0001-daemon-remove-always-true-comparison.patch b/0001-daemon-remove-always-true-comparison.patch deleted file mode 100644 index cbb5d32..0000000 --- a/0001-daemon-remove-always-true-comparison.patch +++ /dev/null @@ -1,24 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 8 Mar 2022 12:59:34 -0500 -Subject: [PATCH] daemon: remove always-true comparison - -Signed-off-by: Robbie Harwood ---- - src/daemon.c | 3 +-- - 1 file changed, 1 insertion(+), 2 deletions(-) - -diff --git a/src/daemon.c b/src/daemon.c -index 0a66deb..ff88210 100644 ---- a/src/daemon.c -+++ b/src/daemon.c -@@ -221,8 +221,7 @@ malformed: - if (!ctx->cms->tokenname) - goto oom; - -- if (!tp->value) -- pin = strndup((char *)tp->value, tp->size); -+ pin = strndup((char *)tp->value, tp->size); - if (!pin) - goto oom; - diff --git a/0002-make-handle-some-gcc-Wanalyzer-flags-better.patch b/0002-make-handle-some-gcc-Wanalyzer-flags-better.patch deleted file mode 100644 index 5bee588..0000000 --- a/0002-make-handle-some-gcc-Wanalyzer-flags-better.patch +++ /dev/null @@ -1,40 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Fri, 11 Mar 2022 12:45:28 -0500 -Subject: [PATCH] make: handle some gcc -Wanalyzer flags better - -This makes it so we won't use the -Wanalyzer / -fanalyzer flags by -default, because they're still pretty overzealous. - -Signed-off-by: Peter Jones ---- - Make.defaults | 6 +++--- - 1 file changed, 3 insertions(+), 3 deletions(-) - -diff --git a/Make.defaults b/Make.defaults -index 130c1ee..1c18904 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -32,11 +32,11 @@ CCLD := $(if $(filter undefined,$(origin CCLD)),$(CC),$(CCLD)) - CFLAGS ?= -O2 -g3 -pipe -fPIE -fstack-protector-all \ - -fstack-clash-protection \ - $(if $(filter x86_64 ia32,$(ARCH)),-fcf-protection=full,) --DIAGFLAGS ?= -fmessage-length=0 \ -+DIAGFLAGS ?= $(call enabled,ENABLE_GCC_ANALYZER,-fmessage-length=0 \ - -fdiagnostics-color=always \ - -fdiagnostics-format=text \ - -fdiagnostics-show-cwe \ -- -fanalyzer \ -+ -fanalyzer) \ - $(call enabled,ENABLE_LEAK_CHECKER,-Wno-analyzer-malloc-leak,) - AS ?= $(CROSS_COMPILE)as - AR ?= $(CROSS_COMPILE)$(if $(filter $(CC),clang),llvm-ar,$(notdir $(CC))-ar) -@@ -59,7 +59,7 @@ endif - cflags = $(CFLAGS) $(ARCH3264) \ - -Wall -Wextra -Wsign-compare -Wno-unused-result \ - -Wno-unused-function -Wno-missing-field-initializers \ -- -Wno-analyzer-malloc-leak \ -+ $(call enabled,ENABLE_LEAK_CHECKER,-Wno-analyzer-malloc-leak,) \ - -Werror -Wno-error=cpp -Wno-free-nonheap-object \ - -std=gnu11 -fshort-wchar -fPIC -fno-strict-aliasing \ - -D_GNU_SOURCE -DCONFIG_$(ARCH) -I${TOPDIR}/include \ diff --git a/0003-Rename-dprintf-to-dbgprintf.patch b/0003-Rename-dprintf-to-dbgprintf.patch deleted file mode 100644 index dac8401..0000000 --- a/0003-Rename-dprintf-to-dbgprintf.patch +++ /dev/null @@ -1,664 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Fri, 11 Mar 2022 12:46:16 -0500 -Subject: [PATCH] Rename "dprintf' to "dbgprintf" - -stdio defines a dprintf() macro now, so using dprintf() for our debug -printer gets obnoxious warnings. This renames it to dbgprintf(). - -Signed-off-by: Peter Jones ---- - src/cms_common.c | 73 +++++++++++++++++++++++++++++------------------------ - src/cms_pe_common.c | 20 +++++++-------- - src/efikeygen.c | 16 ++++++------ - src/file_pe.c | 6 +++-- - src/password.c | 68 ++++++++++++++++++++++++------------------------- - src/pesign.c | 10 ++++---- - src/util.h | 26 +++++++++---------- - 7 files changed, 114 insertions(+), 105 deletions(-) - -diff --git a/src/cms_common.c b/src/cms_common.c -index ca37e6a..86341ca 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -333,13 +333,13 @@ void cms_set_pw_data(cms_context *cms, secuPWData *pwdata) - - if (!pwdata) { - cms->pwdata.source = PW_SOURCE_INVALID; -- dprintf("pwdata:NULL"); -+ dbgprintf("pwdata:NULL"); - } else { - memmove(&cms->pwdata, pwdata, sizeof(*pwdata)); -- dprintf("pwdata:%p", pwdata); -- dprintf("pwdata->source:%d", pwdata->source); -- dprintf("pwdata->data:%p (\"%s\")", pwdata->data, -- pwdata->data ? pwdata->data : "(null)"); -+ dbgprintf("pwdata:%p", pwdata); -+ dbgprintf("pwdata->source:%d", pwdata->source); -+ dbgprintf("pwdata->data:%p (\"%s\")", pwdata->data, -+ pwdata->data ? pwdata->data : "(null)"); - } - - egress(); -@@ -382,7 +382,7 @@ is_valid_cert(CERTCertificate *cert, void *data) - - errnum = PORT_GetError(); - if (errnum == SEC_ERROR_EXTENSION_NOT_FOUND) { -- dprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); -+ dbgprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); - PORT_SetError(0); - errnum = 0; - } -@@ -415,7 +415,7 @@ is_valid_cert_without_private_key(CERTCertificate *cert, void *data) - - errnum = PORT_GetError(); - if (errnum == SEC_ERROR_EXTENSION_NOT_FOUND) { -- dprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); -+ dbgprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); - PORT_SetError(0); - errnum = 0; - } -@@ -467,23 +467,23 @@ unescape_html_in_place(char *s) - size_t pos = 0; - char *s1; - -- dprintf("unescaping pos:%zd sz:%zd \"%s\"", pos, sz, s); -+ dbgprintf("unescaping pos:%zd sz:%zd \"%s\"", pos, sz, s); - do { - s1 = strchrnul(&s[pos], '%'); - if (s1[0] == '\0') - break; -- dprintf("s1 is \"%s\"", s1); -+ dbgprintf("s1 is \"%s\"", s1); - if ((size_t)(s1 - s) < (size_t)(sz - 3)) { - int c; - - c = (hexchar_to_bin(s1[1]) << 4) - | (hexchar_to_bin(s1[2]) & 0xf); -- dprintf("replacing %%%c%c with 0x%02hhx", s1[1], s1[2], (char)c); -+ dbgprintf("replacing %%%c%c with 0x%02hhx", s1[1], s1[2], (char)c); - s1[0] = c; - memmove(&s1[1], &s1[3], sz - (&s1[3] - s)); - sz -= 2; - pos = &s1[1] - s; -- dprintf("new pos:%zd sz:%zd s:\"%s\"", pos, sz, s); -+ dbgprintf("new pos:%zd sz:%zd s:\"%s\"", pos, sz, s); - } - } while (pos < sz); - } -@@ -499,7 +499,7 @@ resolve_pkcs11_token_in_place(char *tokenname) - char c = *cp; - *cp = '\0'; - -- dprintf("ntn:\"%s\"", ntn); -+ dbgprintf("ntn:\"%s\"", ntn); - if (!strncmp(&ntn[pos], "token=", 6)) { - ntn += 6; - memmove(tokenname, ntn, cp - ntn + 1); -@@ -510,13 +510,13 @@ resolve_pkcs11_token_in_place(char *tokenname) - ntn = cp + (c ? 1 : 0); - } - unescape_html_in_place(tokenname); -- dprintf("token name is \"%s\"", tokenname); -+ dbgprintf("token name is \"%s\"", tokenname); - } - - #define resolve_token_name(tn) ({ \ - char *s_ = tn; \ - if (!strncmp(tn, "pkcs11:", 7)) { \ -- dprintf("provided token name is pkcs11 uri; parsing"); \ -+ dbgprintf("provided token name is pkcs11 uri; parsing");\ - s_ = strdupa(tn+7); \ - resolve_pkcs11_token_in_place(s_); \ - } \ -@@ -528,7 +528,8 @@ unlock_nss_token(cms_context *cms) - { - char *tokenname = resolve_token_name(cms->tokenname); - -- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); -+ dbgprintf("setting password function to %s", -+ cms->func ? "cms->func" : "SECU_GetModulePassword"); - PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); - - PK11SlotList *slots = NULL; -@@ -592,7 +593,8 @@ find_certificate(cms_context *cms, int needs_private_key) - return -1; - } - -- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); -+ dbgprintf("setting password function to %s", -+ cms->func ? "cms->func" : "SECU_GetModulePassword"); - PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); - - PK11SlotList *slots = NULL; -@@ -610,10 +612,10 @@ find_certificate(cms_context *cms, int needs_private_key) - } - - while (psle) { -- dprintf("looking for token \"%s\", got \"%s\"", -- tokenname, PK11_GetTokenName(psle->slot)); -+ dbgprintf("looking for token \"%s\", got \"%s\"", -+ tokenname, PK11_GetTokenName(psle->slot)); - if (!strcmp(tokenname, PK11_GetTokenName(psle->slot))) { -- dprintf("found token \"%s\"", tokenname); -+ dbgprintf("found token \"%s\"", tokenname); - break; - } - -@@ -673,8 +675,9 @@ find_certificate(cms_context *cms, int needs_private_key) - psle->slot, is_valid_cert, &cbd); - errnum = PORT_GetError(); - if (errnum) -- dprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", -- PORT_ErrorToName(errnum), PORT_ErrorToString(errnum)); -+ dbgprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", -+ PORT_ErrorToName(errnum), -+ PORT_ErrorToString(errnum)); - } else { - status = PK11_TraverseCertsForNicknameInSlot(&nickname, - psle->slot, -@@ -682,28 +685,30 @@ find_certificate(cms_context *cms, int needs_private_key) - &cbd); - errnum = PORT_GetError(); - if (errnum) -- dprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", -- PORT_ErrorToName(errnum), PORT_ErrorToString(errnum)); -+ dbgprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", -+ PORT_ErrorToName(errnum), -+ PORT_ErrorToString(errnum)); - } -- dprintf("status:%d cbd.cert:%p", status, cbd.cert); -+ dbgprintf("status:%d cbd.cert:%p", status, cbd.cert); - if (status == SECSuccess && cbd.cert != NULL) { - if (cms->cert) - CERT_DestroyCertificate(cms->cert); - cms->cert = CERT_DupCertificate(cbd.cert); - } else { - errnum = PORT_GetError(); -- dprintf("token traversal %s; cert %sfound:%s:%s", -- status == SECSuccess ? "succeeded" : "failed", -- cbd.cert == NULL ? "not" : "", -- PORT_ErrorToName(errnum), PORT_ErrorToString(errnum)); -+ dbgprintf("token traversal %s; cert %sfound:%s:%s", -+ status == SECSuccess ? "succeeded" : "failed", -+ cbd.cert == NULL ? "not" : "", -+ PORT_ErrorToName(errnum), -+ PORT_ErrorToString(errnum)); - } - - save_port_err() { -- dprintf("Destroying cert list"); -+ dbgprintf("Destroying cert list"); - CERT_DestroyCertList(certlist); -- dprintf("Destroying slot list element"); -+ dbgprintf("Destroying slot list element"); - PK11_DestroySlotListElement(slots, &psle); -- dprintf("Destroying slot list"); -+ dbgprintf("Destroying slot list"); - PK11_FreeSlotList(slots); - cms->psle = NULL; - } -@@ -723,7 +728,8 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot) - - char *tokenname = resolve_token_name(cms->tokenname); - -- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); -+ dbgprintf("setting password function to %s", -+ cms->func ? "cms->func" : "SECU_GetModulePassword"); - PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); - - PK11SlotList *slots = NULL; -@@ -792,7 +798,8 @@ find_certificate_by_callback(cms_context *cms, - return -1; - } - -- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); -+ dbgprintf("setting password function to %s", -+ cms->func ? "cms->func" : "SECU_GetModulePassword"); - PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); - - PK11SlotList *slots = NULL; -diff --git a/src/cms_pe_common.c b/src/cms_pe_common.c -index 3a3921b..fb90ecb 100644 ---- a/src/cms_pe_common.c -+++ b/src/cms_pe_common.c -@@ -188,8 +188,8 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - } - if (!check_pointer_and_size(cms, pe, hash_base, hash_size)) - cmsgotoerr(error, cms, "PE header is invalid"); -- dprintf("beginning of hash"); -- dprintf("digesting %tx + %zx", hash_base - map, hash_size); -+ dbgprintf("beginning of hash"); -+ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); - generate_digest_step(cms, hash_base, hash_size); - - /* 5. Skip over the image checksum -@@ -209,7 +209,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - cmsgotoerr(error, cms, "PE data directory is invalid"); - - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %tx + %zx", hash_base - map, hash_size); -+ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); - - /* 8. Skip over the crt dir - * 9. Hash everything up to the end of the image header. */ -@@ -222,7 +222,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - cmsgotoerr(error, cms, "PE relocations table is invalid"); - - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %tx + %zx", hash_base - map, hash_size); -+ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); - - /* 10. Set SUM_OF_BYTES_HASHED to the size of the header. */ - hashed_bytes = pe32opthdr ? pe32opthdr->header_size -@@ -256,16 +256,16 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - char *name = shdrs[i].name; - if (name && name[0] == '/') - name = get_str(cms, pe, name + 1); -- dprintf("section:\"%s\"", name ? name : "(null)"); -+ dbgprintf("section:\"%s\"", name ? name : "(null)"); - if (name && !strcmp(name, ".vendor_cert")) { -- dprintf("skipping .vendor_cert section"); -+ dbgprintf("skipping .vendor_cert section"); - hashed_bytes += hash_size; - continue; - } - } - - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %tx + %zx", hash_base - map, hash_size); -+ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); - - hashed_bytes += hash_size; - } -@@ -285,15 +285,15 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - memset(tmp_array, '\0', tmp_size); - memcpy(tmp_array, hash_base, hash_size); - generate_digest_step(cms, tmp_array, tmp_size); -- dprintf("digesting %tx + %zx", (ptrdiff_t)tmp_array, -+ dbgprintf("digesting %tx + %zx", (ptrdiff_t)tmp_array, - tmp_size); - } else { - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %tx + %zx", hash_base - map, -+ dbgprintf("digesting %tx + %zx", hash_base - map, - hash_size); - } - } -- dprintf("end of hash"); -+ dbgprintf("end of hash"); - - rc = generate_digest_finish(cms); - if (rc < 0) -diff --git a/src/efikeygen.c b/src/efikeygen.c -index 940fdf5..dd40502 100644 ---- a/src/efikeygen.c -+++ b/src/efikeygen.c -@@ -1067,9 +1067,9 @@ int main(int argc, char *argv[]) - - errno = 0; - timeul = strtoul(not_valid_before, &endptr, 0); -- dprintf("not_valid_before:%lu", timeul); -+ dbgprintf("not_valid_before:%lu", timeul); - if (errno == 0 && endptr && *endptr == 0) { -- dprintf("not_valid_before:%lu", timeul); -+ dbgprintf("not_valid_before:%lu", timeul); - not_before = (PRTime)timeul * PR_USEC_PER_SEC; - } else { - prstatus = PR_ParseTimeString(not_valid_before, -@@ -1078,7 +1078,7 @@ int main(int argc, char *argv[]) - "could not parse date \"%s\"", - not_valid_before); - } -- dprintf("not_before:%"PRId64, not_before); -+ dbgprintf("not_before:%"PRId64, not_before); - } - - if (not_valid_after) { -@@ -1086,11 +1086,11 @@ int main(int argc, char *argv[]) - char *endptr; - - errno = 0; -- dprintf("not_valid_after:%s", not_valid_after); -+ dbgprintf("not_valid_after:%s", not_valid_after); - timeul = strtoul(not_valid_after, &endptr, 0); -- dprintf("not_valid_after:%lu", timeul); -+ dbgprintf("not_valid_after:%lu", timeul); - if (errno == 0 && endptr && *endptr == 0) { -- dprintf("not_valid_after:%lu", timeul); -+ dbgprintf("not_valid_after:%lu", timeul); - not_after = (PRTime)timeul * PR_USEC_PER_SEC; - } else { - prstatus = PR_ParseTimeString(not_valid_after, PR_TRUE, -@@ -1102,10 +1102,10 @@ int main(int argc, char *argv[]) - } else { - // Mon Jan 19 03:14:07 GMT 2037, aka 0x7fffffff minus 1 year. - time_t time = 0x7ffffffful - 60ul * 60 * 24 * 365; -- dprintf("not_valid_after:%lu", time); -+ dbgprintf("not_valid_after:%lu", time); - not_after = (PRTime)time * PR_USEC_PER_SEC; - } -- dprintf("not_after:%"PRId64, not_after); -+ dbgprintf("not_after:%"PRId64, not_after); - - CERTValidity *validity = NULL; - validity = CERT_CreateValidity(not_before, not_after); -diff --git a/src/file_pe.c b/src/file_pe.c -index fa97b89..fed6edb 100644 ---- a/src/file_pe.c -+++ b/src/file_pe.c -@@ -264,7 +264,8 @@ pe_handle_action(pesign_context *ctxp, int action, int padding) - /* generate a signature and save it in a separate file */ - case EXPORT_SIGNATURE|GENERATE_SIGNATURE: - perr = PORT_GetError(); -- dprintf("PORT_GetError():%s:%s", PORT_ErrorToName(perr), PORT_ErrorToString(perr)); -+ dbgprintf("PORT_GetError():%s:%s", -+ PORT_ErrorToName(perr), PORT_ErrorToString(perr)); - PORT_SetError(0); - rc = find_certificate(ctxp->cms_ctx, 1); - conderrx(rc < 0, 1, "Could not find certificate %s", -@@ -281,7 +282,8 @@ pe_handle_action(pesign_context *ctxp, int action, int padding) - case IMPORT_SIGNATURE|GENERATE_SIGNATURE: - check_inputs(ctxp); - perr = PORT_GetError(); -- dprintf("PORT_GetError():%s:%s", PORT_ErrorToName(perr), PORT_ErrorToString(perr)); -+ dbgprintf("PORT_GetError():%s:%s", -+ PORT_ErrorToName(perr), PORT_ErrorToString(perr)); - rc = find_certificate(ctxp->cms_ctx, 1); - conderrx(rc < 0, 1, "Could not find certificate %s", - ctxp->cms_ctx->certname); -diff --git a/src/password.c b/src/password.c -index 05add9a..18c32ed 100644 ---- a/src/password.c -+++ b/src/password.c -@@ -167,7 +167,7 @@ SECU_GetPasswordString(void *arg UNUSED, char *prompt) - char *ret; - ingress(); - ret = get_password(stdin, stdout, prompt, NULL); -- dprintf("password:\"%s\"", ret ? ret : "(null)"); -+ dbgprintf("password:\"%s\"", ret ? ret : "(null)"); - egress(); - return ret; - } -@@ -194,7 +194,7 @@ parse_pwfile_line(char *start, struct token_pass *tp) - size_t offset = 0; - - span = strspn(line, whitespace_and_eol_chars); -- dprintf("whitespace span is %zd", span); -+ dbgprintf("whitespace span is %zd", span); - if (span == 0 && line[span] == '\0') - return -1; - line += span; -@@ -210,17 +210,17 @@ parse_pwfile_line(char *start, struct token_pass *tp) - offset += escspan + 2; - } while(escspan < span); - span += offset; -- dprintf("non-whitespace span is %zd", span); -+ dbgprintf("non-whitespace span is %zd", span); - - if (line[span] == '\0') { -- dprintf("returning %td", (line + span) - start); -+ dbgprintf("returning %td", (line + span) - start); - return (line + span) - start; - } - line[span] = '\0'; - - line += span + 1; - span = strspn(line, whitespace_and_eol_chars); -- dprintf("whitespace span is %zd", span); -+ dbgprintf("whitespace span is %zd", span); - line += span; - tp->token = tp->pass; - tp->pass = line; -@@ -233,15 +233,15 @@ parse_pwfile_line(char *start, struct token_pass *tp) - offset += escspan + 2; - } while(escspan < span); - span += offset; -- dprintf("non-whitespace span is %zd", span); -+ dbgprintf("non-whitespace span is %zd", span); - if (line[span] != '\0') - line[span++] = '\0'; - - resolve_escapes(tp->token); -- dprintf("Setting token pass %p to { %p, %p }", tp, tp->token, tp->pass); -- dprintf("token:\"%s\"", tp->token); -- dprintf("pass:\"%s\"", tp->pass); -- dprintf("returning %td", (line + span) - start); -+ dbgprintf("Setting token pass %p to { %p, %p }", tp, tp->token, tp->pass); -+ dbgprintf("token:\"%s\"", tp->token); -+ dbgprintf("pass:\"%s\"", tp->pass); -+ dbgprintf("returning %td", (line + span) - start); - return (line + span) - start; - } - -@@ -260,7 +260,7 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) - char *path; - - ingress(); -- dprintf("token_name: %s", token_name); -+ dbgprintf("token_name: %s", token_name); - if (cms->pwdata.source != PW_FROMFILEDB) { - cms->log(cms, LOG_ERR, - "Got to %s() but no file is specified.\n", -@@ -289,8 +289,8 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) - if (rc < 0 || file_len < 1) - goto err_file; - file[file_len-1] = '\0'; -- dprintf("file_len:%zd", file_len); -- dprintf("file:\"%s\"", file); -+ dbgprintf("file_len:%zd", file_len); -+ dbgprintf("file:\"%s\"", file); - - unbreak_line_continuations(file, file_len); - } -@@ -314,23 +314,23 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) - #pragma GCC diagnostic pop - - span = strspn(start, whitespace_and_eol_chars); -- dprintf("whitespace span is %zd", span); -+ dbgprintf("whitespace span is %zd", span); - start += span; - span = strcspn(start, eol_chars); -- dprintf("non-whitespace span is %zd", span); -+ dbgprintf("non-whitespace span is %zd", span); - - c = start[span]; - start[span] = '\0'; -- dprintf("file:\"%s\"", file); -+ dbgprintf("file:\"%s\"", file); - rc = parse_pwfile_line(start, &phrases[nphrases++]); -- dprintf("parse_pwfile_line returned %d", rc); -+ dbgprintf("parse_pwfile_line returned %d", rc); - if (rc < 0) - goto err_phrases; - - if (c != '\0') - span++; - start += span; -- dprintf("start is file[%td] == '\\x%02hhx'", start - file, -+ dbgprintf("start is file[%td] == '\\x%02hhx'", start - file, - start[0]); - } - -@@ -359,7 +359,7 @@ err_file: - err_phrases: - xfree(phrases); - err: -- dprintf("ret:\"%s\"", ret ? ret : "(null)"); -+ dbgprintf("ret:\"%s\"", ret ? ret : "(null)"); - egress(); - return ret; - } -@@ -412,10 +412,10 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) - ingress(); - - if (PK11_ProtectedAuthenticationPath(slot)) { -- dprintf("prompting for PW_DEVICE data"); -+ dbgprintf("prompting for PW_DEVICE data"); - pwdata = &pwxtrn; - } else { -- dprintf("using pwdata from cms"); -+ dbgprintf("using pwdata from cms"); - pwdata = &cms->pwdata; - } - -@@ -423,17 +423,17 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) - pwdata->source >= PW_SOURCE_MAX || - pwdata->orig_source <= PW_SOURCE_INVALID || - pwdata->orig_source >= PW_SOURCE_MAX) { -- dprintf("pwdata is invalid"); -+ dbgprintf("pwdata is invalid"); - return NULL; - } - -- dprintf("pwdata:%p retry:%d", pwdata, retry); -- dprintf("pwdata->source:%s (%d) orig:%s (%d)", -- pw_source_names[pwdata->source], pwdata->source, -- pw_source_names[pwdata->orig_source], pwdata->orig_source); -- dprintf("pwdata->data:%p (\"%s\")", pwdata->data, -- pwdata->data ? pwdata->data : "(null)"); -- dprintf("pwdata->intdata:%ld", pwdata->intdata); -+ dbgprintf("pwdata:%p retry:%d", pwdata, retry); -+ dbgprintf("pwdata->source:%s (%d) orig:%s (%d)", -+ pw_source_names[pwdata->source], pwdata->source, -+ pw_source_names[pwdata->orig_source], pwdata->orig_source); -+ dbgprintf("pwdata->data:%p (\"%s\")", pwdata->data, -+ pwdata->data ? pwdata->data : "(null)"); -+ dbgprintf("pwdata->intdata:%ld", pwdata->intdata); - - if (retry) { - warnx("Incorrect password/PIN entered."); -@@ -470,7 +470,7 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) - - case PW_FROMFILEDB: - case PW_DATABASE: -- dprintf("pwdata->source:%s", pw_source_names[pwdata->source]); -+ dbgprintf("pwdata->source:%s", pw_source_names[pwdata->source]); - /* Instead of opening and closing the file every time, get the pw - * once, then keep it in memory (duh). - */ -@@ -480,17 +480,17 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) - return pw; - - case PW_FROMENV: -- dprintf("pwdata->source:PW_FROMENV"); -+ dbgprintf("pwdata->source:PW_FROMENV"); - if (!pwdata || !pwdata->data) - break; - pw = get_env(pwdata->data); -- dprintf("env:%s pw:%s", pwdata->data, pw ? pw : "(null)"); -+ dbgprintf("env:%s pw:%s", pwdata->data, pw ? pw : "(null)"); - pwdata->data = pw; - pwdata->source = PW_PLAINTEXT; - goto PW_PLAINTEXT; - - case PW_FROMFILE: -- dprintf("pwdata->source:PW_FROMFILE"); -+ dbgprintf("pwdata->source:PW_FROMFILE"); - in = fopen(pwdata->data, "r"); - if (!in) - return NULL; -@@ -501,7 +501,7 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) - goto PW_PLAINTEXT; - - case PW_FROMFD: -- dprintf("pwdata->source:PW_FROMFD"); -+ dbgprintf("pwdata->source:PW_FROMFD"); - rc = pwdata->intdata; - in = fdopen(pwdata->intdata, "r"); - if (!in) -diff --git a/src/pesign.c b/src/pesign.c -index c2ff35f..f548d81 100644 ---- a/src/pesign.c -+++ b/src/pesign.c -@@ -333,7 +333,7 @@ main(int argc, char *argv[]) - while ((rc = poptGetNextOpt(optCon)) > 0) { - switch (rc) { - case POPT_RET_PWDB: -- dprintf("POPT_RET_PWDB:\"%s\"", pwdata.data ? pwdata.data : "(null)"); -+ dbgprintf("POPT_RET_PWDB:\"%s\"", pwdata.data ? pwdata.data : "(null)"); - if (pwdata.source != PW_SOURCE_INVALID) - errx(1, "only one password/pin method can be used at a time"); - if (pwdata.data == NULL) -@@ -346,7 +346,7 @@ main(int argc, char *argv[]) - continue; - - case POPT_RET_ENV: -- dprintf("POPT_RET_ENV:\"%s\"", pwdata.data ? pwdata.data : "(null)"); -+ dbgprintf("POPT_RET_ENV:\"%s\"", pwdata.data ? pwdata.data : "(null)"); - if (pwdata.source != PW_SOURCE_INVALID) - errx(1, "only one password/pin method can be used at a time"); - if (pwdata.data == NULL) -@@ -359,7 +359,7 @@ main(int argc, char *argv[]) - continue; - - case POPT_RET_PINFD: -- dprintf("POPT_RET_PINFD:\"%s\"", pwdata.data ? pwdata.data : "(null)"); -+ dbgprintf("POPT_RET_PINFD:\"%s\"", pwdata.data ? pwdata.data : "(null)"); - if (pwdata.source != PW_SOURCE_INVALID) - errx(1, "only one password/pin method can be used at a time"); - if (pwdata.data == NULL) -@@ -373,7 +373,7 @@ main(int argc, char *argv[]) - continue; - - case POPT_RET_PINFILE: -- dprintf("POPT_RET_PINFILE:\"%s\"", pwdata.data ? pwdata.data : "(null)"); -+ dbgprintf("POPT_RET_PINFILE:\"%s\"", pwdata.data ? pwdata.data : "(null)"); - if (pwdata.source != PW_SOURCE_INVALID) - errx(1, "only one password/pin method can be used at a time"); - if (pwdata.data == NULL) -@@ -387,7 +387,7 @@ main(int argc, char *argv[]) - } - } - -- dprintf("pwdata.source:%d %schecking for PESIGN_TOKEN_PIN", -+ dbgprintf("pwdata.source:%d %schecking for PESIGN_TOKEN_PIN", - pwdata.source, - pwdata.source == PW_SOURCE_INVALID ? "" : "not "); - if (pwdata.source == PW_SOURCE_INVALID && secure_getenv("PESIGN_TOKEN_PIN")) { -diff --git a/src/util.h b/src/util.h -index ba8c621..6616011 100644 ---- a/src/util.h -+++ b/src/util.h -@@ -269,28 +269,28 @@ proxy_fd_mode(int fd, char *infile, mode_t *outmode, size_t *inlength) - - extern long verbosity(void); - --#define dprintf_(tv, file, func, line, fmt, args...) ({ \ -- struct timeval tv; \ -- gettimeofday(&tv, NULL); \ -- warnx("%ld.%lu %s:%s():%d: " fmt, \ -- tv.tv_sec, tv.tv_usec, \ -- file, func, line, ##args); \ -+#define dbgprintf_(tv, file, func, line, fmt, args...) ({ \ -+ struct timeval tv; \ -+ gettimeofday(&tv, NULL); \ -+ warnx("%ld.%lu %s:%s():%d: " fmt, \ -+ tv.tv_sec, tv.tv_usec, \ -+ file, func, line, ##args); \ - }) - #if defined(PESIGN_DEBUG) --#define dprintf(fmt, args...) \ -- dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ -- __FILE__, __func__, __LINE__ - 2, fmt, ##args) -+#define dbgprintf(fmt, args...) \ -+ dbgprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ -+ __FILE__, __func__, __LINE__ - 2, fmt, ##args) - #else --#define dprintf(fmt, args...) ({ \ -+#define dbgprintf(fmt, args...) ({ \ - if (verbosity() > 1) \ -- dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ -+ dbgprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ - __FILE__, __func__, __LINE__ - 3, \ - fmt, ##args); \ - 0; \ - }) - #endif --#define ingress() dprintf("ingress"); --#define egress() dprintf("egress"); -+#define ingress() dbgprintf("ingress"); -+#define egress() dbgprintf("egress"); - - #endif /* PESIGN_UTIL_H */ - // vim:fenc=utf-8:tw=75:noet diff --git a/0004-.gitignore-add-compile_commands.json-and-.cache.patch b/0004-.gitignore-add-compile_commands.json-and-.cache.patch deleted file mode 100644 index fb7e7a4..0000000 --- a/0004-.gitignore-add-compile_commands.json-and-.cache.patch +++ /dev/null @@ -1,30 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Fri, 11 Mar 2022 12:47:20 -0500 -Subject: [PATCH] .gitignore: add compile_commands.json and .cache/ - -These are used by bear/cnc/clangd/etc, but there's no reason to trip -over them all the time. - -Signed-off-by: Peter Jones ---- - .gitignore | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/.gitignore b/.gitignore -index bf0617b..7425432 100644 ---- a/.gitignore -+++ b/.gitignore -@@ -1,3 +1,4 @@ -+.cache/ - .*.d - .*.P - .*.sw? -@@ -26,6 +27,7 @@ - /*.rpm - *-8be4df61-93ca-11d2-aa0d-00e098032b8c - *-d719b2cb-3d3a-4596-a3bc-dad00e67656f -+compile_commands.json - core.* - cov-int/ - pwfile diff --git a/0005-pesign-print-digests-before-filenames-like-sha256sum.patch b/0005-pesign-print-digests-before-filenames-like-sha256sum.patch deleted file mode 100644 index dbce340..0000000 --- a/0005-pesign-print-digests-before-filenames-like-sha256sum.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Fri, 11 Mar 2022 12:44:46 -0500 -Subject: [PATCH] pesign: print digests before filenames like sha256sum does - -Most digest tools print the digest before the filename, there's no -reason pesign needs to be different. - -Signed-off-by: Peter Jones ---- - src/file_pe.c | 3 +-- - 1 file changed, 1 insertion(+), 2 deletions(-) - -diff --git a/src/file_pe.c b/src/file_pe.c -index fed6edb..805e614 100644 ---- a/src/file_pe.c -+++ b/src/file_pe.c -@@ -121,12 +121,11 @@ print_digest(pesign_context *pctx) - if (!ctx) - return; - -- printf("%s ", pctx->infile); - int j = ctx->selected_digest; - for (unsigned int i = 0; i < ctx->digests[j].pe_digest->len; i++) - printf("%02x", - (unsigned char)ctx->digests[j].pe_digest->data[i]); -- printf("\n"); -+ printf(" %s\n", pctx->infile); - } - - void diff --git a/0006-Add-pesum-an-authenticode-digest-generator.patch b/0006-Add-pesum-an-authenticode-digest-generator.patch deleted file mode 100644 index 10d6fb4..0000000 --- a/0006-Add-pesum-an-authenticode-digest-generator.patch +++ /dev/null @@ -1,318 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Fri, 11 Mar 2022 12:54:39 -0500 -Subject: [PATCH] Add 'pesum', an authenticode digest generator. - -Signed-off-by: Peter Jones ---- - src/pesum.c | 195 +++++++++++++++++++++++++++++++++++++++++++++++++++++++ - src/.gitignore | 1 + - src/Makefile | 12 +++- - src/pesum.1.mdoc | 38 +++++++++++ - 4 files changed, 244 insertions(+), 2 deletions(-) - create mode 100644 src/pesum.c - create mode 100644 src/pesum.1.mdoc - -diff --git a/src/pesum.c b/src/pesum.c -new file mode 100644 -index 0000000..e4ddaf8 ---- /dev/null -+++ b/src/pesum.c -@@ -0,0 +1,195 @@ -+// SPDX-License-Identifier: GPLv2 -+/* -+ * pesum.c - pesum command line tool -+ * Copyright Peter Jones -+ */ -+ -+#include "fix_coverity.h" -+ -+#include -+#include -+ -+#include -+#include -+ -+#include "pesign.h" -+#include "pesign_standalone.h" -+ -+static struct { -+ int flag; -+ const char *name; -+} flag_names[] = { -+ {DAEMONIZE, "daemonize"}, -+ {GENERATE_DIGEST, "hash"}, -+ {GENERATE_SIGNATURE, "sign"}, -+ {IMPORT_RAW_SIGNATURE, "import-raw-sig"}, -+ {IMPORT_SIGNATURE, "import-sig"}, -+ {IMPORT_SATTRS, "import-sattrs" }, -+ {EXPORT_SATTRS, "export-sattrs" }, -+ {EXPORT_SIGNATURE, "export-sig"}, -+ {EXPORT_PUBKEY, "export-pubkey"}, -+ {EXPORT_CERT, "export-cert"}, -+ {REMOVE_SIGNATURE, "remove"}, -+ {LIST_SIGNATURES, "list"}, -+ {FLAG_LIST_END, NULL}, -+}; -+ -+void -+print_flag_name(FILE *f, int flag) -+{ -+ for (int i = 0; flag_names[i].flag != FLAG_LIST_END; i++) { -+ if (flag_names[i].flag == flag) -+ fprintf(f, "%s ", flag_names[i].name); -+ } -+} -+ -+static long *verbose; -+ -+long -+verbosity(void) -+{ -+ if (!verbose) -+ return 0; -+ return *verbose; -+} -+ -+int -+main(int argc, char *argv[]) -+{ -+ int rc; -+ SECStatus status; -+ -+ char *digest_name = "sha256"; -+ char *orig_digest_name = digest_name; -+ int padding = 1; -+ long verbose_cmd_line = 0; -+ const char *infile; -+ -+ int action = GENERATE_DIGEST|PRINT_DIGEST; -+ file_format fmt = FORMAT_PE_BINARY; -+ -+ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); -+ -+ verbose = &verbose_cmd_line; -+ -+ poptContext optCon; -+ struct poptOption options[] = { -+ {.argInfo = POPT_ARG_INTL_DOMAIN, -+ .arg = "pesum" }, -+ {.longName = "verbose", -+ .shortName = 'v', -+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL, -+ .arg = &verbose_cmd_line, -+ .val = 1, -+ .descrip = "be more verbose" }, -+ {.longName = "debug", -+ .shortName = '\0', -+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL, -+ .arg = &verbose_cmd_line, -+ .val = 2, -+ .descrip = "be very verbose" }, -+ {.longName = "digest-type", -+ .shortName = 'd', -+ .argInfo = POPT_ARG_STRING|POPT_ARGFLAG_SHOW_DEFAULT, -+ .arg = &digest_name, -+ .descrip = "digest type to use for pe hash" }, -+ {.longName = "digest_type", -+ .shortName = '\0', -+ .argInfo = POPT_ARG_STRING|POPT_ARGFLAG_DOC_HIDDEN, -+ .arg = &digest_name, -+ .descrip = "digest type to use for pe hash" }, -+ {.longName = "padding", -+ .shortName = 'P', -+ .argInfo = POPT_ARG_VAL, -+ .arg = &padding, -+ .val = 1, -+ .descrip = "pad data section (default)" }, -+ {.longName = "nopadding", -+ .shortName = 'p', -+ .argInfo = POPT_ARG_VAL, -+ .arg = &padding, -+ .val = 0, -+ .descrip = "do not pad the data section" }, -+ POPT_AUTOALIAS -+ POPT_AUTOHELP -+ POPT_TABLEEND -+ }; -+ -+ optCon = poptGetContext("pesum", argc, (const char **)argv, options,0); -+ -+ rc = poptReadDefaultConfig(optCon, 0); -+ if (rc < 0 && !(rc == POPT_ERROR_ERRNO && errno == ENOENT)) -+ errx(1, "poptReadDefaultConfig failed: %s", poptStrerror(rc)); -+ -+ while ((rc = poptGetNextOpt(optCon)) > 0) { -+ ; -+ } -+ -+ if (rc < -1) -+ errx(1, "Invalid argument: %s: %s", -+ poptBadOption(optCon, 0), poptStrerror(rc)); -+ -+ if (!poptPeekArg(optCon)) -+ errx(1, "nothing to do"); -+ -+ status = NSS_NoDB_Init(NULL); -+ if (status != SECSuccess) -+ errx(1, "Could not initialize nss.\n" -+ "NSS says \"%s\" errno says \"%m\"\n", -+ PORT_ErrorToString(PORT_GetError())); -+ -+ while ((infile = poptGetArg(optCon)) != NULL) { -+ pesign_context *ctxp = NULL; -+ -+ char *ext = strrchr(infile, '.'); -+ if (ext && strcmp(ext, ".ko") == 0) -+ fmt = FORMAT_KERNEL_MODULE; -+ -+ rc = pesign_context_new(&ctxp); -+ if (rc < 0) -+ err(1, "Could not initialize context"); -+ -+ ctxp->verbose = verbose_cmd_line; -+ -+ ctxp->hash = 1; -+ ctxp->infile = strdup(infile); -+ if (!ctxp->infile) -+ err(1, "Could not allocate memory"); -+ -+ rc = set_digest_parameters(ctxp->cms_ctx, digest_name); -+ int is_help = strcmp(digest_name, "help") ? 0 : 1; -+ if (rc < 0) { -+ if (!is_help) { -+ fprintf(stderr, "Digest \"%s\" not found.\n", -+ digest_name); -+ } -+ exit(!is_help); -+ } -+ -+ errno = 0; -+ switch (fmt) { -+ case FORMAT_PE_BINARY: -+ pe_handle_action(ctxp, action, padding); -+ break; -+ case FORMAT_KERNEL_MODULE: -+ kmod_handle_action(ctxp, action); -+ break; -+ } -+ -+ pesign_context_free(ctxp); -+ } -+ -+ poptFreeContext(optCon); -+ -+ if (digest_name && digest_name != orig_digest_name) -+ free(digest_name); -+ -+ status = NSS_Shutdown(); -+ if (status != SECSuccess) -+ errx(1, "could not shut down NSS: %s", -+ PORT_ErrorToString(PORT_GetError())); -+ -+ return 0; -+} -+ -+// vim:fenc=utf-8:tw=75:noet -diff --git a/src/.gitignore b/src/.gitignore -index 64ce217..f8f6d66 100644 ---- a/src/.gitignore -+++ b/src/.gitignore -@@ -5,6 +5,7 @@ client - efikeygen - efidbtool - pesigcheck -+pesum - peverify - pesign.service - pesign.sysvinit -diff --git a/src/Makefile b/src/Makefile -index 7010514..79cf09e 100644 ---- a/src/Makefile -+++ b/src/Makefile -@@ -6,7 +6,7 @@ include $(TOPDIR)/Make.rules - include $(TOPDIR)/Make.defaults - - BINTARGETS=authvar client efikeygen pesigcheck pesign \ -- pesign-rpmbuild-helper pesign-authorize -+ pesign-rpmbuild-helper pesign-authorize pesum - CFGTARGETS=tmpfiles.conf - SVCTARGETS=pesign.sysvinit pesign.service - MAN1TARGETS=authvar.1 efikeygen.1 pesigcheck.1 pesign-client.1 pesign.1 -@@ -29,9 +29,12 @@ EFIKEYGEN_SOURCES = efikeygen.c - PESIGCHECK_SOURCES = pesigcheck.c pesigcheck_context.c certdb.c - PESIGN_SOURCES = pesign.c pesign_context.c actions.c daemon.c \ - file_pe.c file_kmod.c pesign_kmod.c -+PESUM_SOURCES = pesum.c pesign_context.c actions.c \ -+ file_pe.c file_kmod.c pesign_kmod.c - - ALL_SOURCES=$(COMMON_SOURCES) $(AUTHVAR_SORUCES) $(CLIENT_SOURCES) \ -- $(EFIKEYGEN_SOURCES) $(PESIGCHECK_SOURCES) $(PESIGN_SOURCES) -+ $(EFIKEYGEN_SOURCES) $(PESIGCHECK_SOURCES) $(PESIGN_SOURCES) \ -+ $(PESUM_SOURCES) - -include $(call deps-of,$(ALL_SOURCES)) - - authvar : $(call objects-of,$(AUTHVAR_SOURCES) $(COMMON_SOURCES)) -@@ -53,6 +56,10 @@ pesign : $(call objects-of,$(PESIGN_SOURCES) $(COMMON_SOURCES) $(COMMON_PE_SOURC - pesign : LDLIBS+=$(TOPDIR)/libdpe/libdpe.a - pesign : PKGS=efivar nss nspr popt - -+pesum : $(call objects-of,$(PESUM_SOURCES) $(COMMON_SOURCES) $(COMMON_PE_SOURCES)) -+pesum : LDLIBS+=$(TOPDIR)/libdpe/libdpe.a -+pesum : PKGS=efivar nss nspr popt -+ - deps : PKGS=efivar nss nspr popt uuid - deps : $(ALL_SOURCES) - $(MAKE) -f $(TOPDIR)/Make.deps \ -@@ -81,6 +88,7 @@ install : - $(INSTALL) -d -m 755 $(INSTALLROOT)$(bindir) - $(INSTALL) -m 755 authvar $(INSTALLROOT)$(bindir) - $(INSTALL) -m 755 pesign $(INSTALLROOT)$(bindir) -+ $(INSTALL) -m 755 pesum $(INSTALLROOT)$(bindir) - $(INSTALL) -m 755 client $(INSTALLROOT)$(bindir)pesign-client - $(INSTALL) -m 755 efikeygen $(INSTALLROOT)$(bindir) - $(INSTALL) -m 755 pesigcheck $(INSTALLROOT)$(bindir) -diff --git a/src/pesum.1.mdoc b/src/pesum.1.mdoc -new file mode 100644 -index 0000000..edd08ce ---- /dev/null -+++ b/src/pesum.1.mdoc -@@ -0,0 +1,38 @@ -+.Dd $Mdocdate: Mar 11 2022$ -+.Dt PESUM 1 -+.Os Linux -+.Sh NAME -+.Nm pesum -+.Nd tool for generating Authenticode digests -+.Sh SYNOPSIS -+.Nm -+.Bk -words -+.Ar file0.efi -+.Op Ar file1.efi ... -+.Sh DESCRIPTION -+.Nm -+is a command line tool to generate Authenticode digests of PE binaries. -+.Sh EXAMPLES -+.Ss Getting the Authenticode digest of some files -+host:$ \fBpesum shimx64.efi grubx64.efi\fR -+8c5806e66bb5b052ebf860e1722474269cff3dde588610df21dbe8cf12c08390\ shimx64.efi -+546a71319c22da1d81879383c4c74be06d1c374bdecfafc9fcc80bd541802bfc\ grubx64.efi -+.Sh STANDARDS -+.Rs -+.%B Portable Executable -+.%I Microsoft -+.%D August 26, 2019 -+.%U https://docs.microsoft.com/en-us/windows/win32/debug/pe-format\ \& -+.Re -+ -+.Rs -+.%B Windows Authenticode Portable Executable Signature Format -+.%I Microsoft -+.%D March 21, 2008 -+.%U https://web.archive.org/web/20130518222430/http://download.microsoft.com/download/9/c/5/9c5b2167-8017-4bae-9fde-d599bac8184a/Authenticode_PE.docx\ \& -+.Re -+.Sh SEE ALSO -+.Xr pesign 1 -+.LP -+.Sh AUTHORS -+.An Peter Jones diff --git a/0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch b/0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch deleted file mode 100644 index b342876..0000000 --- a/0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch +++ /dev/null @@ -1,54 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Julian Sikorski -Date: Wed, 23 Mar 2022 20:54:03 +0100 -Subject: [PATCH] Fix building signed kernels on setups other than koji - -Thanks to Will Springer for the idea. Details at -https://bugzilla.redhat.com/show_bug.cgi?id=1880858 - -Signed-off-by: Julian Sikorski -Suggested-by: Will Springer ---- - src/pesign-rpmbuild-helper.in | 24 +++++++++++------------- - 1 file changed, 11 insertions(+), 13 deletions(-) - -diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in -index 0a845d2..c9d5570 100644 ---- a/src/pesign-rpmbuild-helper.in -+++ b/src/pesign-rpmbuild-helper.in -@@ -172,24 +172,22 @@ main() { - USERNAME="${USERNAME:-$(id -un)}" - - local socket="" || : -- if grep -q ID=fedora /etc/os-release \ -+ if [[ -S /run/pesign/socket ]] ; then -+ socket=/run/pesign/socket -+ elif [[ -S /var/run/pesign/socket ]]; then -+ socket=/var/run/pesign/socket -+ elif grep -q ID=fedora /etc/os-release \ - && [[ "${rhelver}" -lt 7 ]] \ - && [[ "${USERNAME}" = "mockbuild" ]] \ - && [[ "${vendor}" = "Fedora Project" ]] \ - && [[ "${HOSTNAME}" =~ bkernel.* ]] - then -- if [[ -S /run/pesign/socket ]] ; then -- socket=/run/pesign/socket -- elif [[ -S /var/run/pesign/socket ]]; then -- socket=/var/run/pesign/socket -- else -- echo "Warning: no pesign socket even though user is ${USERNAME}" 1>&2 -- echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 -- ls -ld /run/pesign /var/run/pesign 1>&2 ||: -- ls -l /run/pesign/socket /var/run/pesign/socket 1>&2 ||: -- getfacl /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: -- getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: -- fi -+ echo "Warning: no pesign socket even though user is ${USERNAME}" 1>&2 -+ echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 -+ ls -ld /run/pesign /var/run/pesign 1>&2 ||: -+ ls -l /run/pesign/socket /var/run/pesign/socket 1>&2 ||: -+ getfacl /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: -+ getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: - fi - - if [[ "${rhelver}" -ge 7 ]] ; then diff --git a/0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch b/0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch deleted file mode 100644 index 187a623..0000000 --- a/0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch +++ /dev/null @@ -1,23 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 25 Mar 2022 15:01:54 -0400 -Subject: [PATCH] Add -D_GLIBCXX_ASSERTIONS to CPPFLAGS - -Signed-off-by: Robbie Harwood ---- - Make.defaults | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/Make.defaults b/Make.defaults -index 1c18904..05aadd0 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -79,7 +79,7 @@ ccldflags = $(cflags) $(CCLDFLAGS) $(LDFLAGS) \ - $(call pkg-config-ccldflags) - efi_cflags = $(cflags) - ASFLAGS ?= $(ARCH3264) --CPPFLAGS ?= -D_FORTIFY_SOURCE=2 -+CPPFLAGS ?= -D_FORTIFY_SOURCE=2 -D_GLIBCXX_ASSERTIONS - RANLIBFLAGS ?= $(if $(filter $(CC),gcc),-D) - ARFLAGS ?= $(if $(filter $(CC),gcc),-Dcvqs)$(if $(filter $(CC),clang),-cqvs) - diff --git a/0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch b/0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch deleted file mode 100644 index 68cbe5f..0000000 --- a/0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch +++ /dev/null @@ -1,24 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 10 Aug 2021 12:39:08 -0400 -Subject: [PATCH] macros.pesign: handle centos like rhel with --rhelver - -Signed-off-by: Peter Jones ---- - src/macros.pesign | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/src/macros.pesign b/src/macros.pesign -index 34af57c..b7d6af1 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -34,7 +34,8 @@ - %{?__pesign_cert:--cert %{__pesign_cert}} \\\ - %{?_buildhost:--hostname "%{_buildhost}"} \\\ - %{?vendor:--vendor "%{vendor}"} \\\ -- %{?_rhel:--rhelver "%{_rhel}"} \\\ -+ %{?rhel:--rhelver "%{rhel}"} \\\ -+ %{?centos:--rhelver "%{centos}"} \\\ - %{?-n:--rhelcert %{-n*}}%{?!-n:--rhelcert %{__pesign_cert}} \\\ - %{?-a:--rhelcafile "%{-a*}"} \\\ - %{?-c:--rhelcertfile "%{-c*}"} \\\ diff --git a/0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch b/0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch deleted file mode 100644 index bb4bef2..0000000 --- a/0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch +++ /dev/null @@ -1,25 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 4 Apr 2022 14:45:29 -0400 -Subject: [PATCH] Detect the presence of rpm-sign when checking for "rhel"-ness - -Signed-off-by: Peter Jones -[rharwood: manually reapply to main] -Signed-off-by: Robbie Harwood ---- - src/pesign-rpmbuild-helper.in | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in -index c9d5570..9dee56e 100644 ---- a/src/pesign-rpmbuild-helper.in -+++ b/src/pesign-rpmbuild-helper.in -@@ -190,7 +190,7 @@ main() { - getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: - fi - -- if [[ "${rhelver}" -ge 7 ]] ; then -+ if [[ "${rhelver}" -ge 7 ]] && which rpm-sign >&/dev/null ; then - nssdir="$(mktemp -p "${PWD}" -d)" - echo > "${nssdir}/pwfile" - certutil -N -d "${nssdir}" -f "${nssdir}/pwfile" diff --git a/0011-Rename-README-README.md.patch b/0011-Rename-README-README.md.patch deleted file mode 100644 index ff10b8d..0000000 --- a/0011-Rename-README-README.md.patch +++ /dev/null @@ -1,17 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 13 May 2022 15:53:05 -0400 -Subject: [PATCH] Rename README -> README.md - -Rich text will let me compact links. - -Signed-off-by: Robbie Harwood ---- - README => README.md | 0 - 1 file changed, 0 insertions(+), 0 deletions(-) - rename README => README.md (100%) - -diff --git a/README b/README.md -similarity index 100% -rename from README -rename to README.md diff --git a/0012-README.md-show-off-a-bit-more.patch b/0012-README.md-show-off-a-bit-more.patch deleted file mode 100644 index 9d624f2..0000000 --- a/0012-README.md-show-off-a-bit-more.patch +++ /dev/null @@ -1,56 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 13 May 2022 16:09:12 -0400 -Subject: [PATCH] README.md: show off a bit more - -Prominently mention efikeygen and add examples of usage for it and -pesign proper. - -Signed-off-by: Robbie Harwood ---- - README.md | 36 ++++++++++++++++++++++++++++++++---- - 1 file changed, 32 insertions(+), 4 deletions(-) - -diff --git a/README.md b/README.md -index d70bc53..e9f0cb7 100644 ---- a/README.md -+++ b/README.md -@@ -1,6 +1,34 @@ --Signing tool for PE-COFF binaries, hopefully at least vaguely compliant with --the PE and Authenticode specifications. -+# pesign + efikeygen - --This is vaguely analogous to the tool described by --http://msdn.microsoft.com/en-us/library/8s9b9yaz%28v=vs.80%29.aspx -+Signing tools for PE-COFF binaries. Compliant with the PE and Authenticode -+specifications. - -+(These serve a similar purpose to Microsoft's -+[SignTool.exe](http://msdn.microsoft.com/en-us/library/8s9b9yaz%28v=vs.80%29.aspx), -+except for Linux.) -+ -+## Examples -+ -+Generate a key for use with pesign, stored on disk: -+ -+``` -+efikeyen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' -+``` -+ -+For more complex and secure use cases (e.g., hardware tokens), see -+efikeygen man page (`man efikeygen`). -+ -+Sign a UEFI application using that key: -+ -+``` -+pesign -i grubx64.efi -o grubx64.efi.signed -c 'Custom Secureboot' -s -+``` -+ -+Show signatures on a UEFI application: -+ -+``` -+pesign -i grubx64.efi.signed -S -+``` -+ -+For more signing/verification operations, see the pesign man page (`man -+pesign`). diff --git a/0013-Fix-missing-line-in-README.md.patch b/0013-Fix-missing-line-in-README.md.patch deleted file mode 100644 index 185bcc3..0000000 --- a/0013-Fix-missing-line-in-README.md.patch +++ /dev/null @@ -1,23 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 16 May 2022 15:31:25 -0400 -Subject: [PATCH] Fix missing line in README.md - -Signed-off-by: Robbie Harwood ---- - README.md | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/README.md b/README.md -index e9f0cb7..7bbd6dd 100644 ---- a/README.md -+++ b/README.md -@@ -15,6 +15,8 @@ Generate a key for use with pesign, stored on disk: - efikeyen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' - ``` - -+(where TYPE is m if you're only signing kernel modules, and k otherwise). -+ - For more complex and secure use cases (e.g., hardware tokens), see - efikeygen man page (`man efikeygen`). - diff --git a/0014-Fix-typo-in-efikeygen-command.patch b/0014-Fix-typo-in-efikeygen-command.patch deleted file mode 100644 index 82d228d..0000000 --- a/0014-Fix-typo-in-efikeygen-command.patch +++ /dev/null @@ -1,23 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Matt Bernhard -Date: Fri, 27 May 2022 14:40:49 -0400 -Subject: [PATCH] Fix typo in efikeygen command - -Signed-off-by: Matt Bernhard ---- - README.md | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/README.md b/README.md -index 7bbd6dd..b6949a2 100644 ---- a/README.md -+++ b/README.md -@@ -12,7 +12,7 @@ except for Linux.) - Generate a key for use with pesign, stored on disk: - - ``` --efikeyen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' -+efikeygen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' - ``` - - (where TYPE is m if you're only signing kernel modules, and k otherwise). diff --git a/0015-pesigcheck-Fix-crash-on-digest-match.patch b/0015-pesigcheck-Fix-crash-on-digest-match.patch deleted file mode 100644 index c948558..0000000 --- a/0015-pesigcheck-Fix-crash-on-digest-match.patch +++ /dev/null @@ -1,53 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Visa Hankala -Date: Fri, 10 Jun 2022 13:25:13 +0000 -Subject: [PATCH] pesigcheck: Fix crash on digest match - -Set selected_digest when the digest is found in db or dbx. -This fixes the following crash of pesigcheck: - - Program received signal SIGSEGV, Segmentation fault. - 0x00005555555597fa in memcpy (__len=24, __src=0x31, - __dest=0x55555558d908) - at /usr/include/x86_64-linux-gnu/bits/string_fortified.h:34 - 34 return __builtin___memcpy_chk (__dest, __src, __len, __bos0 (__dest)); - (gdb) bt - #0 0x00005555555597fa in memcpy (__len=24, __src=0x31, - __dest=0x55555558d908) - at /usr/include/x86_64-linux-gnu/bits/string_fortified.h:34 - #1 get_digest (digest=digest@entry=0x55555558d908, - ctx=, ctx=) at pesigcheck.c:226 - #2 0x00005555555592fd in check_signature ( - reasons=, nreasons=, - ctx=0x7fffffffded0) at pesigcheck.c:262 - #3 main (argc=, argv=) - at pesigcheck.c:512 - -Signed-off-by: Visa Hankala ---- - src/certdb.c | 8 ++++++-- - 1 file changed, 6 insertions(+), 2 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index e013b9d..69d5daf 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -267,12 +267,16 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - - if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { - digest = ctx->cms_ctx->digests[0].pe_digest->data; -- if (memcmp (digest, sig->data, 32) == 0) -+ if (memcmp (digest, sig->data, 32) == 0) { -+ ctx->cms_ctx->selected_digest = 0; - return FOUND; -+ } - } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { - digest = ctx->cms_ctx->digests[1].pe_digest->data; -- if (memcmp (digest, sig->data, 20) == 0) -+ if (memcmp (digest, sig->data, 20) == 0) { -+ ctx->cms_ctx->selected_digest = 1; - return FOUND; -+ } - } - - return NOT_FOUND; diff --git a/0016-cms-store-digest-as-pointer-instead-of-index.patch b/0016-cms-store-digest-as-pointer-instead-of-index.patch deleted file mode 100644 index a7fc4dd..0000000 --- a/0016-cms-store-digest-as-pointer-instead-of-index.patch +++ /dev/null @@ -1,272 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 10 Jun 2022 14:40:33 -0400 -Subject: [PATCH] cms: store digest as pointer instead of index - -Storage as an index is problematic because the sentinel value -1 was -used, but accesses were unchecked, leading to crashes like that in -3b1031a6b779cb80c11b34eec84c5a0cc215efed ("pesigcheck: Fix crash on -digest match"). By storing a pointer, we get an explicit NULL -dereference: still a crash, but preferred since it's clearer. - -Since the index was previously also used for retrieving digest -parameters, include a pointer to the relevant struct digest_param in the -struct digest. - -Signed-off-by: Robbie Harwood ---- - src/certdb.c | 15 ++++++++------- - src/cms_common.c | 34 ++++++++++------------------------ - src/content_info.c | 4 ++-- - src/file_kmod.c | 2 +- - src/file_pe.c | 9 +++++---- - src/pesigcheck.c | 4 +--- - src/cms_common.h | 13 ++++++++++++- - 7 files changed, 39 insertions(+), 42 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index 69d5daf..f512824 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -263,18 +263,19 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - { - efi_guid_t efi_sha256 = efi_guid_sha256; - efi_guid_t efi_sha1 = efi_guid_sha1; -- void *digest; -+ void *digest_data; -+ struct digest *digests = ctx->cms_ctx->digests; - - if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { -- digest = ctx->cms_ctx->digests[0].pe_digest->data; -- if (memcmp (digest, sig->data, 32) == 0) { -- ctx->cms_ctx->selected_digest = 0; -+ digest_data = digests[0].pe_digest->data; -+ if (memcmp (digest_data, sig->data, 32) == 0) { -+ ctx->cms_ctx->selected_digest = &digests[0]; - return FOUND; - } - } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { -- digest = ctx->cms_ctx->digests[1].pe_digest->data; -- if (memcmp (digest, sig->data, 20) == 0) { -- ctx->cms_ctx->selected_digest = 1; -+ digest_data = digests[1].pe_digest->data; -+ if (memcmp (digest_data, sig->data, 20) == 0) { -+ ctx->cms_ctx->selected_digest = &digests[1]; - return FOUND; - } - } -diff --git a/src/cms_common.c b/src/cms_common.c -index 86341ca..2275f67 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -33,15 +33,6 @@ - - #include "hex.h" - --struct digest_param { -- char *name; -- SECOidTag digest_tag; -- SECOidTag signature_tag; -- SECOidTag digest_encryption_tag; -- const efi_guid_t *efi_guid; -- int size; --}; -- - static struct digest_param digest_params[] = { - {.name = "sha256", - .digest_tag = SEC_OID_SHA256, -@@ -65,29 +56,25 @@ static int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); - SECOidTag - digest_get_digest_oid(cms_context *cms) - { -- int i = cms->selected_digest; -- return digest_params[i].digest_tag; -+ return cms->selected_digest->digest_params->digest_tag; - } - - SECOidTag - digest_get_encryption_oid(cms_context *cms) - { -- int i = cms->selected_digest; -- return digest_params[i].digest_encryption_tag; -+ return cms->selected_digest->digest_params->digest_encryption_tag; - } - - SECOidTag - digest_get_signature_oid(cms_context *cms) - { -- int i = cms->selected_digest; -- return digest_params[i].signature_tag; -+ return cms->selected_digest->digest_params->signature_tag; - } - - int - digest_get_digest_size(cms_context *cms) - { -- int i = cms->selected_digest; -- return digest_params[i].size; -+ return cms->selected_digest->digest_params->size; - } - - void -@@ -142,8 +129,6 @@ cms_context_init(cms_context *cms) - if (!cms->arena) - cnreterr(-1, cms, "could not create cryptographic arena"); - -- cms->selected_digest = -1; -- - INIT_LIST_HEAD(&cms->pk12_ins); - cms->pk12_out.fd = -1; - cms->db_out = cms->dbx_out = cms->dbt_out = -1; -@@ -226,7 +211,7 @@ cms_context_fini(cms_context *cms) - memset(&cms->newsig, '\0', sizeof (cms->newsig)); - } - -- cms->selected_digest = -1; -+ cms->selected_digest = NULL; - - if (cms->ci_digest) { - free_poison(cms->ci_digest->data, cms->ci_digest->len); -@@ -351,7 +336,7 @@ set_digest_parameters(cms_context *cms, char *name) - if (strcmp(name, "help")) { - for (int i = 0; i < n_digest_params; i++) { - if (!strcmp(name, digest_params[i].name)) { -- cms->selected_digest = i; -+ cms->selected_digest = &cms->digests[i]; - return 0; - } - } -@@ -1279,6 +1264,7 @@ generate_digest_begin(cms_context *cms) - cngotoerr(err, cms, "could not create digest context"); - - PK11_DigestBegin(digests[i].pk11ctx); -+ digests[i].digest_params = &digest_params[i]; - } - - cms->digests = digests; -@@ -1351,11 +1337,11 @@ generate_signature(cms_context *cms) - { - int rc = 0; - -- if (cms->digests[cms->selected_digest].pe_digest == NULL) -+ if (cms->selected_digest->pe_digest == NULL) - cnreterr(-1, cms, "PE digest has not been allocated"); - -- if (content_is_empty(cms->digests[cms->selected_digest].pe_digest->data, -- cms->digests[cms->selected_digest].pe_digest->len)) -+ if (content_is_empty(cms->selected_digest->pe_digest->data, -+ cms->selected_digest->pe_digest->len)) - cnreterr(-1, cms, "PE binary has not been digested"); - - SECItem sd_der; -diff --git a/src/content_info.c b/src/content_info.c -index 9684850..777aa28 100644 ---- a/src/content_info.c -+++ b/src/content_info.c -@@ -181,8 +181,8 @@ generate_spc_digest_info(cms_context *cms, SECItem *dip) - if (generate_algorithm_id(cms, &di.digestAlgorithm, - digest_get_digest_oid(cms)) < 0) - return -1; -- int i = cms->selected_digest; -- memcpy(&di.digest, cms->digests[i].pe_digest, sizeof (di.digest)); -+ memcpy(&di.digest, cms->selected_digest->pe_digest, -+ sizeof(di.digest)); - - if (content_is_empty(di.digest.data, di.digest.len)) { - cms->log(cms, LOG_ERR, "got empty digest"); -diff --git a/src/file_kmod.c b/src/file_kmod.c -index 6880cda..c8875fc 100644 ---- a/src/file_kmod.c -+++ b/src/file_kmod.c -@@ -60,7 +60,7 @@ ssize_t - kmod_write_signature(cms_context *cms, int outfd) - { - SEC_PKCS7ContentInfo *cinfo; -- SECItem *digest = cms->digests[cms->selected_digest].pe_digest; -+ SECItem *digest = cms->selected_digest->pe_digest; - SECStatus rv; - struct write_sig_info info = { - .outfd = outfd, -diff --git a/src/file_pe.c b/src/file_pe.c -index 805e614..c22b2af 100644 ---- a/src/file_pe.c -+++ b/src/file_pe.c -@@ -114,6 +114,8 @@ check_inputs(pesign_context *ctx) - static void - print_digest(pesign_context *pctx) - { -+ unsigned int i; -+ - if (!pctx) - return; - -@@ -121,10 +123,9 @@ print_digest(pesign_context *pctx) - if (!ctx) - return; - -- int j = ctx->selected_digest; -- for (unsigned int i = 0; i < ctx->digests[j].pe_digest->len; i++) -- printf("%02x", -- (unsigned char)ctx->digests[j].pe_digest->data[i]); -+ unsigned char *ddata = ctx->selected_digest->pe_digest->data; -+ for (i = 0; i < ctx->selected_digest->pe_digest->len; i++) -+ printf("%02x", ddata[i]); - printf(" %s\n", pctx->infile); - } - -diff --git a/src/pesigcheck.c b/src/pesigcheck.c -index 6dc67f7..ebb404d 100644 ---- a/src/pesigcheck.c -+++ b/src/pesigcheck.c -@@ -221,9 +221,7 @@ static void - get_digest(pesigcheck_context *ctx, SECItem *digest) - { - struct cms_context *cms = ctx->cms_ctx; -- struct digest *cms_digest = &cms->digests[cms->selected_digest]; -- -- memcpy(digest, cms_digest->pe_digest, sizeof (*digest)); -+ memcpy(digest, cms->selected_digest->pe_digest, sizeof(*digest)); - } - - static int -diff --git a/src/cms_common.h b/src/cms_common.h -index c7acbcf..c7d4f69 100644 ---- a/src/cms_common.h -+++ b/src/cms_common.h -@@ -12,6 +12,7 @@ - #include - - #include -+#include - #include - #include - #include -@@ -57,9 +58,19 @@ - goto errlabel; \ - }) - -+struct digest_param { -+ char *name; -+ SECOidTag digest_tag; -+ SECOidTag signature_tag; -+ SECOidTag digest_encryption_tag; -+ const efi_guid_t *efi_guid; -+ int size; -+}; -+ - struct digest { - PK11Context *pk11ctx; - SECItem *pe_digest; -+ struct digest_param *digest_params; - }; - - typedef struct pk12_file { -@@ -133,7 +144,7 @@ typedef struct cms_context { - int db_out, dbx_out, dbt_out; - - struct digest *digests; -- int selected_digest; -+ struct digest *selected_digest; - int omit_vendor_cert; - - SECItem newsig; diff --git a/0017-Fix-mandoc-invocation-to-not-produce-garbage.patch b/0017-Fix-mandoc-invocation-to-not-produce-garbage.patch deleted file mode 100644 index 648055e..0000000 --- a/0017-Fix-mandoc-invocation-to-not-produce-garbage.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 7 Jul 2022 16:56:41 -0400 -Subject: [PATCH] Fix mandoc invocation to not produce garbage - -Bizarrely, mandoc doesn't default to outputting man - the default is -"locale", which is either ASCII or UTF-8 (by locale). This output is -supposed to be some kind of plain-text, but it's formatted so strangely -I'm not sure what the purpose is. Regardless, it doesn't go well to -feed this into man(1). - -Tell mandoc explicitly to produce man pages. - -Signed-off-by: Robbie Harwood ---- - Make.rules | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/Make.rules b/Make.rules -index 12e322b..f6bf5fa 100644 ---- a/Make.rules -+++ b/Make.rules -@@ -54,7 +54,7 @@ define substitute-version = - endef - - %.1 : %.1.mdoc -- @mandoc -man -Ios=Linux $^ > $@ -+ @mandoc -man -T man -Ios=Linux $^ > $@ - - % : %.in - @$(call substitute-version,$<,$@) diff --git a/0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch b/0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch deleted file mode 100644 index 3d0fd63..0000000 --- a/0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 29 Aug 2022 15:31:52 -0400 -Subject: [PATCH] Work around GCC being obnoxiously incompatible with GCC - -GCC added and then later removed the diagnostic flag -"-Wanalyzer-use-of-uninitialized-value", and so this doesn't work with -newer versions of GCC. - -This patch removes the previous workaround for when it didn't work well. -I really wish any of our compilers had any sense of rigor with this -stuff at all. - -Signed-off-by: Peter Jones ---- - src/daemon.c | 5 ----- - 1 file changed, 5 deletions(-) - -diff --git a/src/daemon.c b/src/daemon.c -index ff88210..d66dd50 100644 ---- a/src/daemon.c -+++ b/src/daemon.c -@@ -917,10 +917,6 @@ do_shutdown(context *ctx, int nsockets, struct pollfd *pollfds) - free(pollfds); - } - --/* GCC -fanalyzer has trouble with realloc -- * https://bugzilla.redhat.com/show_bug.cgi?id=2047926 */ --#pragma GCC diagnostic push --#pragma GCC diagnostic ignored "-Wanalyzer-use-of-uninitialized-value" - static int - handle_events(context *ctx) - { -@@ -999,7 +995,6 @@ shutdown: - } - return 0; - } --#pragma GCC diagnostic pop - - static int - get_uid_and_gid(context *ctx, char **homedir) diff --git a/0019-get_password_passthrough-handle-the-callback-context.patch b/0019-get_password_passthrough-handle-the-callback-context.patch deleted file mode 100644 index 3240a32..0000000 --- a/0019-get_password_passthrough-handle-the-callback-context.patch +++ /dev/null @@ -1,51 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 29 Aug 2022 14:21:44 -0400 -Subject: [PATCH] get_password_passthrough(): handle the callback context right - -Right now, we have a few callback functions for PK11_Authenticate(), and -they take different arguments. This is incorrect; none of the callers -ever pass anything through except our CMS context. - -This fixes get_password_passthrough() to correctly accept the CMS -context and get the passthrough data from cms->pwdata instead of trying -to treat the CMS context as the pwdata. - -Related: rhbz#2122777 - -Signed-off-by: Peter Jones ---- - src/password.c | 16 +++++++++++++--- - 1 file changed, 13 insertions(+), 3 deletions(-) - -diff --git a/src/password.c b/src/password.c -index 18c32ed..8eb1c33 100644 ---- a/src/password.c -+++ b/src/password.c -@@ -365,13 +365,23 @@ err: - } - - char * --get_password_passthrough(PK11SlotInfo *slot UNUSED, -- PRBool retry, void *arg) -+get_password_passthrough(PK11SlotInfo *slot UNUSED, PRBool retry, void *arg) - { -+ cms_context *cms; -+ secuPWData *pwdata; -+ -+ dbgprintf("ctx:%p", arg); -+ - if (retry || !arg) - return NULL; - -- char *ret = strdup(arg); -+ cms = (cms_context *)arg; -+ pwdata = &cms->pwdata; -+ -+ if (pwdata->source != PW_PLAINTEXT) -+ return NULL; -+ -+ char *ret = strdup(pwdata->data); - if (!ret) - err(1, "Could not allocate memory"); - diff --git a/0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch b/0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch deleted file mode 100644 index b69d5ff..0000000 --- a/0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 29 Aug 2022 15:22:10 -0400 -Subject: [PATCH] read_password(): only prune CR/NL from the end of the file - -Right now, when we read the password/PIN from a file, we're pruning the -end of the string from the file we read indiscriminately. If you don't -have a newline, that means we're cutting off the final digits of the -text. - -This changes it to prune only common special characters from the -pinfile, but also to prune /all/ of them. - -Related: rhbz#2122777 -Signed-off-by: Peter Jones ---- - src/password.c | 10 +++++++++- - 1 file changed, 9 insertions(+), 1 deletion(-) - -diff --git a/src/password.c b/src/password.c -index 8eb1c33..ac1866e 100644 ---- a/src/password.c -+++ b/src/password.c -@@ -79,6 +79,7 @@ read_password(FILE *in, FILE *out, char *buf, size_t bufsz) - int infd = fileno(in); - struct termios tio; - char *ret; -+ int len; - - ingress(); - ret = fgets(buf, bufsz, in); -@@ -96,7 +97,14 @@ read_password(FILE *in, FILE *out, char *buf, size_t bufsz) - if (ret == NULL) - return -1; - -- buf[strlen(buf)-1] = '\0'; -+ len = strlen(buf); -+ while (len > 0 && (buf[len-1] == '\r' || buf[len-1] == '\n')) { -+ buf[len-1] = '\0'; -+ len--; -+ } -+ if (len == 0) -+ return -1; -+ - egress(); - return 0; - } diff --git a/0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch b/0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch deleted file mode 100644 index ac9bdfd..0000000 --- a/0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch +++ /dev/null @@ -1,276 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 29 Aug 2022 16:22:18 -0400 -Subject: [PATCH] Revert "cms: store digest as pointer instead of index" - -In 926782c216532a83f9ff864dee39d2349d61fd23, we switched -cms->selected_digest to be a pointer to the member of the digests array -rather than an index. Unfortunately this is just as bad, because the -bugs that come up wind up setting pointers to NULL+(selected*offset), -i.e. 0x10, and that doesn't get us any closer to actually finding any -problem. - -For now, the new approach is going to be to make it an index again, but -to default it to 0 (sha256) rather than -1, so if it isn't set at the -correct part of the lifecycle it'll just default to the (nearly always) -correct choice. - -This reverts commit 926782c216532a83f9ff864dee39d2349d61fd23. - -Signed-off-by: Peter Jones ---- - src/certdb.c | 15 +++++++-------- - src/cms_common.c | 34 ++++++++++++++++++++++++---------- - src/content_info.c | 4 ++-- - src/file_kmod.c | 2 +- - src/file_pe.c | 9 ++++----- - src/pesigcheck.c | 4 +++- - src/cms_common.h | 13 +------------ - 7 files changed, 42 insertions(+), 39 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index f512824..69d5daf 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -263,19 +263,18 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - { - efi_guid_t efi_sha256 = efi_guid_sha256; - efi_guid_t efi_sha1 = efi_guid_sha1; -- void *digest_data; -- struct digest *digests = ctx->cms_ctx->digests; -+ void *digest; - - if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { -- digest_data = digests[0].pe_digest->data; -- if (memcmp (digest_data, sig->data, 32) == 0) { -- ctx->cms_ctx->selected_digest = &digests[0]; -+ digest = ctx->cms_ctx->digests[0].pe_digest->data; -+ if (memcmp (digest, sig->data, 32) == 0) { -+ ctx->cms_ctx->selected_digest = 0; - return FOUND; - } - } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { -- digest_data = digests[1].pe_digest->data; -- if (memcmp (digest_data, sig->data, 20) == 0) { -- ctx->cms_ctx->selected_digest = &digests[1]; -+ digest = ctx->cms_ctx->digests[1].pe_digest->data; -+ if (memcmp (digest, sig->data, 20) == 0) { -+ ctx->cms_ctx->selected_digest = 1; - return FOUND; - } - } -diff --git a/src/cms_common.c b/src/cms_common.c -index 2275f67..86341ca 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -33,6 +33,15 @@ - - #include "hex.h" - -+struct digest_param { -+ char *name; -+ SECOidTag digest_tag; -+ SECOidTag signature_tag; -+ SECOidTag digest_encryption_tag; -+ const efi_guid_t *efi_guid; -+ int size; -+}; -+ - static struct digest_param digest_params[] = { - {.name = "sha256", - .digest_tag = SEC_OID_SHA256, -@@ -56,25 +65,29 @@ static int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); - SECOidTag - digest_get_digest_oid(cms_context *cms) - { -- return cms->selected_digest->digest_params->digest_tag; -+ int i = cms->selected_digest; -+ return digest_params[i].digest_tag; - } - - SECOidTag - digest_get_encryption_oid(cms_context *cms) - { -- return cms->selected_digest->digest_params->digest_encryption_tag; -+ int i = cms->selected_digest; -+ return digest_params[i].digest_encryption_tag; - } - - SECOidTag - digest_get_signature_oid(cms_context *cms) - { -- return cms->selected_digest->digest_params->signature_tag; -+ int i = cms->selected_digest; -+ return digest_params[i].signature_tag; - } - - int - digest_get_digest_size(cms_context *cms) - { -- return cms->selected_digest->digest_params->size; -+ int i = cms->selected_digest; -+ return digest_params[i].size; - } - - void -@@ -129,6 +142,8 @@ cms_context_init(cms_context *cms) - if (!cms->arena) - cnreterr(-1, cms, "could not create cryptographic arena"); - -+ cms->selected_digest = -1; -+ - INIT_LIST_HEAD(&cms->pk12_ins); - cms->pk12_out.fd = -1; - cms->db_out = cms->dbx_out = cms->dbt_out = -1; -@@ -211,7 +226,7 @@ cms_context_fini(cms_context *cms) - memset(&cms->newsig, '\0', sizeof (cms->newsig)); - } - -- cms->selected_digest = NULL; -+ cms->selected_digest = -1; - - if (cms->ci_digest) { - free_poison(cms->ci_digest->data, cms->ci_digest->len); -@@ -336,7 +351,7 @@ set_digest_parameters(cms_context *cms, char *name) - if (strcmp(name, "help")) { - for (int i = 0; i < n_digest_params; i++) { - if (!strcmp(name, digest_params[i].name)) { -- cms->selected_digest = &cms->digests[i]; -+ cms->selected_digest = i; - return 0; - } - } -@@ -1264,7 +1279,6 @@ generate_digest_begin(cms_context *cms) - cngotoerr(err, cms, "could not create digest context"); - - PK11_DigestBegin(digests[i].pk11ctx); -- digests[i].digest_params = &digest_params[i]; - } - - cms->digests = digests; -@@ -1337,11 +1351,11 @@ generate_signature(cms_context *cms) - { - int rc = 0; - -- if (cms->selected_digest->pe_digest == NULL) -+ if (cms->digests[cms->selected_digest].pe_digest == NULL) - cnreterr(-1, cms, "PE digest has not been allocated"); - -- if (content_is_empty(cms->selected_digest->pe_digest->data, -- cms->selected_digest->pe_digest->len)) -+ if (content_is_empty(cms->digests[cms->selected_digest].pe_digest->data, -+ cms->digests[cms->selected_digest].pe_digest->len)) - cnreterr(-1, cms, "PE binary has not been digested"); - - SECItem sd_der; -diff --git a/src/content_info.c b/src/content_info.c -index 777aa28..9684850 100644 ---- a/src/content_info.c -+++ b/src/content_info.c -@@ -181,8 +181,8 @@ generate_spc_digest_info(cms_context *cms, SECItem *dip) - if (generate_algorithm_id(cms, &di.digestAlgorithm, - digest_get_digest_oid(cms)) < 0) - return -1; -- memcpy(&di.digest, cms->selected_digest->pe_digest, -- sizeof(di.digest)); -+ int i = cms->selected_digest; -+ memcpy(&di.digest, cms->digests[i].pe_digest, sizeof (di.digest)); - - if (content_is_empty(di.digest.data, di.digest.len)) { - cms->log(cms, LOG_ERR, "got empty digest"); -diff --git a/src/file_kmod.c b/src/file_kmod.c -index c8875fc..6880cda 100644 ---- a/src/file_kmod.c -+++ b/src/file_kmod.c -@@ -60,7 +60,7 @@ ssize_t - kmod_write_signature(cms_context *cms, int outfd) - { - SEC_PKCS7ContentInfo *cinfo; -- SECItem *digest = cms->selected_digest->pe_digest; -+ SECItem *digest = cms->digests[cms->selected_digest].pe_digest; - SECStatus rv; - struct write_sig_info info = { - .outfd = outfd, -diff --git a/src/file_pe.c b/src/file_pe.c -index c22b2af..805e614 100644 ---- a/src/file_pe.c -+++ b/src/file_pe.c -@@ -114,8 +114,6 @@ check_inputs(pesign_context *ctx) - static void - print_digest(pesign_context *pctx) - { -- unsigned int i; -- - if (!pctx) - return; - -@@ -123,9 +121,10 @@ print_digest(pesign_context *pctx) - if (!ctx) - return; - -- unsigned char *ddata = ctx->selected_digest->pe_digest->data; -- for (i = 0; i < ctx->selected_digest->pe_digest->len; i++) -- printf("%02x", ddata[i]); -+ int j = ctx->selected_digest; -+ for (unsigned int i = 0; i < ctx->digests[j].pe_digest->len; i++) -+ printf("%02x", -+ (unsigned char)ctx->digests[j].pe_digest->data[i]); - printf(" %s\n", pctx->infile); - } - -diff --git a/src/pesigcheck.c b/src/pesigcheck.c -index ebb404d..6dc67f7 100644 ---- a/src/pesigcheck.c -+++ b/src/pesigcheck.c -@@ -221,7 +221,9 @@ static void - get_digest(pesigcheck_context *ctx, SECItem *digest) - { - struct cms_context *cms = ctx->cms_ctx; -- memcpy(digest, cms->selected_digest->pe_digest, sizeof(*digest)); -+ struct digest *cms_digest = &cms->digests[cms->selected_digest]; -+ -+ memcpy(digest, cms_digest->pe_digest, sizeof (*digest)); - } - - static int -diff --git a/src/cms_common.h b/src/cms_common.h -index c7d4f69..c7acbcf 100644 ---- a/src/cms_common.h -+++ b/src/cms_common.h -@@ -12,7 +12,6 @@ - #include - - #include --#include - #include - #include - #include -@@ -58,19 +57,9 @@ - goto errlabel; \ - }) - --struct digest_param { -- char *name; -- SECOidTag digest_tag; -- SECOidTag signature_tag; -- SECOidTag digest_encryption_tag; -- const efi_guid_t *efi_guid; -- int size; --}; -- - struct digest { - PK11Context *pk11ctx; - SECItem *pe_digest; -- struct digest_param *digest_params; - }; - - typedef struct pk12_file { -@@ -144,7 +133,7 @@ typedef struct cms_context { - int db_out, dbx_out, dbt_out; - - struct digest *digests; -- struct digest *selected_digest; -+ int selected_digest; - int omit_vendor_cert; - - SECItem newsig; diff --git a/0022-CMS-add-some-minor-cleanups.patch b/0022-CMS-add-some-minor-cleanups.patch deleted file mode 100644 index dfff3f5..0000000 --- a/0022-CMS-add-some-minor-cleanups.patch +++ /dev/null @@ -1,149 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 29 Aug 2022 17:02:46 -0400 -Subject: [PATCH] CMS: add some minor cleanups - -We reverted 926782c216532a83f9ff864dee39d2349d61fd23 so that a future -patch can try a different approach, but that commit also had a few -cleanups that are worthwhile on their own. - -This patch re-introduces the cleanup to move "struct digest_param" to a -more reasonable place and the cleanup to check_hash(), and takes it just -a bit farther. - -Signed-off-by: Peter Jones ---- - src/certdb.c | 26 +++++++++++++++----------- - src/cms_common.c | 39 ++++++++++++++++----------------------- - src/cms_common.h | 16 ++++++++++++++++ - 3 files changed, 47 insertions(+), 34 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index 69d5daf..eb5221f 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -263,20 +263,24 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - { - efi_guid_t efi_sha256 = efi_guid_sha256; - efi_guid_t efi_sha1 = efi_guid_sha1; -- void *digest; -+ void *digest_data; -+ struct digest *digests = ctx->cms_ctx->digests; -+ int selected_digest = -1; -+ size_t size; - - if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { -- digest = ctx->cms_ctx->digests[0].pe_digest->data; -- if (memcmp (digest, sig->data, 32) == 0) { -- ctx->cms_ctx->selected_digest = 0; -- return FOUND; -- } -+ selected_digest = DIGEST_PARAM_SHA256; - } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { -- digest = ctx->cms_ctx->digests[1].pe_digest->data; -- if (memcmp (digest, sig->data, 20) == 0) { -- ctx->cms_ctx->selected_digest = 1; -- return FOUND; -- } -+ selected_digest = DIGEST_PARAM_SHA1; -+ } else { -+ return NOT_FOUND; -+ } -+ -+ digest_data = digests[selected_digest].pe_digest->data; -+ size = digest_params[selected_digest].size; -+ if (memcmp (digest_data, sig->data, size) == 0) { -+ ctx->cms_ctx->selected_digest = selected_digest; -+ return FOUND; - } - - return NOT_FOUND; -diff --git a/src/cms_common.c b/src/cms_common.c -index 86341ca..7bddedf 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -33,34 +33,27 @@ - - #include "hex.h" - --struct digest_param { -- char *name; -- SECOidTag digest_tag; -- SECOidTag signature_tag; -- SECOidTag digest_encryption_tag; -- const efi_guid_t *efi_guid; -- int size; --}; -- --static struct digest_param digest_params[] = { -- {.name = "sha256", -- .digest_tag = SEC_OID_SHA256, -- .signature_tag = SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION, -- .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, -- .efi_guid = &efi_guid_sha256, -- .size = 32 -+const struct digest_param digest_params[] = { -+ [DIGEST_PARAM_SHA256] = { -+ .name = "sha256", -+ .digest_tag = SEC_OID_SHA256, -+ .signature_tag = SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION, -+ .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, -+ .efi_guid = &efi_guid_sha256, -+ .size = 32 - }, - #if 1 -- {.name = "sha1", -- .digest_tag = SEC_OID_SHA1, -- .signature_tag = SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION, -- .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, -- .efi_guid = &efi_guid_sha1, -- .size = 20 -+ [DIGEST_PARAM_SHA1] = { -+ .name = "sha1", -+ .digest_tag = SEC_OID_SHA1, -+ .signature_tag = SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION, -+ .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, -+ .efi_guid = &efi_guid_sha1, -+ .size = 20 - }, - #endif - }; --static int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); -+const int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); - - SECOidTag - digest_get_digest_oid(cms_context *cms) -diff --git a/src/cms_common.h b/src/cms_common.h -index c7acbcf..e45402c 100644 ---- a/src/cms_common.h -+++ b/src/cms_common.h -@@ -12,6 +12,7 @@ - #include - - #include -+#include - #include - #include - #include -@@ -62,6 +63,21 @@ struct digest { - SECItem *pe_digest; - }; - -+#define DIGEST_PARAM_SHA256 0 -+#define DIGEST_PARAM_SHA1 1 -+ -+struct digest_param { -+ char *name; -+ SECOidTag digest_tag; -+ SECOidTag signature_tag; -+ SECOidTag digest_encryption_tag; -+ const efi_guid_t *efi_guid; -+ int size; -+}; -+ -+extern const struct digest_param digest_params[2]; -+extern const int n_digest_params; -+ - typedef struct pk12_file { - char *path; - int fd; diff --git a/0023-CMS-make-cms-selected_digest-an-index-again.patch b/0023-CMS-make-cms-selected_digest-an-index-again.patch deleted file mode 100644 index 6e19cd1..0000000 --- a/0023-CMS-make-cms-selected_digest-an-index-again.patch +++ /dev/null @@ -1,291 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 30 Aug 2022 15:42:15 -0400 -Subject: [PATCH] CMS: make cms->selected_digest an index (again) - -In 926782c216532a83f9ff864dee39d2349d61fd23, we switched -cms->selected_digest to be a pointer to the entry in cms->digests. - -Because cms->digests is lazily allocated, setting the selected_digest -pointer has to be done at the right part of the CMS context life cycle, -and in some cases it clearly is not: - -==334217== Command: ./src/pesign -n tmp -s --pinfile tmp/pinfile -t OpenSC\ Card\ (testcard) -c kernel-signer -i tmp/unsigned.efi -o tmp/signed.efi --force -==334217== -==334217== Invalid read of size 8 -==334217== at 0x115E7D: digest_get_digest_oid (cms_common.c:59) -==334217== by 0x11CF41: generate_algorithm_id_list (signed_data.c:33) -==334217== by 0x11D348: generate_spc_signed_data (signed_data.c:279) -==334217== by 0x11EDFD: calculate_signature_space (wincert.c:297) -==334217== by 0x11467D: pe_handle_action (file_pe.c:298) -==334217== by 0x10F962: main (pesign.c:585) -==334217== Address 0x10 is not stack'd, malloc'd or (recently) free'd -==334217== -==334217== -==334217== Process terminating with default action of signal 11 (SIGSEGV): dumping core -==334217== Access not within mapped region at address 0x10 -==334217== at 0x115E7D: digest_get_digest_oid (cms_common.c:59) -==334217== by 0x11CF41: generate_algorithm_id_list (signed_data.c:33) -==334217== by 0x11D348: generate_spc_signed_data (signed_data.c:279) -==334217== by 0x11EDFD: calculate_signature_space (wincert.c:297) -==334217== by 0x11467D: pe_handle_action (file_pe.c:298) -==334217== by 0x10F962: main (pesign.c:585) -==334217== If you believe this happened as a result of a stack -==334217== overflow in your program's main thread (unlikely but -==334217== possible), you can try to increase the size of the -==334217== main thread stack using the --main-stacksize= flag. -==334217== The main thread stack size used in this run was 8388608. -==334217== -==334217== HEAP SUMMARY: -==334217== in use at exit: 588,544 bytes in 4,388 blocks -==334217== total heap usage: 8,568 allocs, 4,180 frees, 2,077,115 bytes allocated -==334217== -==334217== LEAK SUMMARY: -==334217== definitely lost: 25 bytes in 1 blocks -==334217== indirectly lost: 0 bytes in 0 blocks -==334217== possibly lost: 51,378 bytes in 166 blocks -==334217== still reachable: 537,141 bytes in 4,221 blocks -==334217== of which reachable via heuristic: -==334217== length64 : 321,312 bytes in 590 blocks -==334217== suppressed: 0 bytes in 0 blocks -==334217== Rerun with --leak-check=full to see details of leaked memory -==334217== -==334217== For lists of detected and suppressed errors, rerun with: -s -==334217== ERROR SUMMARY: 1 errors from 1 contexts (suppressed: 0 from 0) -Segmentation fault (core dumped) - -There is also a similar issue in the daemon code, and how to fix it -there is not immediately clear to me. - -Currently, we realistically only support using sha256 digests, so for -now I've chosen to paper over the issue by switching back to -cms->selected_digest be an index into both ctx->digests and -digest_params, but switching the default value from -1 to 0, aka -DIGEST_PARAM_SHA256. We can revisit this issue later whenever we add -sha384 support (or whichever other digest). - -Signed-off-by: Peter Jones ---- - src/certdb.c | 2 +- - src/cms_common.c | 41 +++++++++++++++++++++++------------------ - src/content_info.c | 2 +- - src/cms_common.h | 5 +++-- - 4 files changed, 28 insertions(+), 22 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index eb5221f..467a01d 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -265,7 +265,7 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - efi_guid_t efi_sha1 = efi_guid_sha1; - void *digest_data; - struct digest *digests = ctx->cms_ctx->digests; -- int selected_digest = -1; -+ unsigned int selected_digest; - size_t size; - - if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { -diff --git a/src/cms_common.c b/src/cms_common.c -index 7bddedf..1c54c90 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -33,6 +33,10 @@ - - #include "hex.h" - -+/* -+ * Note that cms->selected_digest defaults to 0, which means the first -+ * entry of this array is the default digest. -+ */ - const struct digest_param digest_params[] = { - [DIGEST_PARAM_SHA256] = { - .name = "sha256", -@@ -53,33 +57,33 @@ const struct digest_param digest_params[] = { - }, - #endif - }; --const int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); -+const unsigned int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); - - SECOidTag - digest_get_digest_oid(cms_context *cms) - { -- int i = cms->selected_digest; -+ unsigned int i = cms->selected_digest; - return digest_params[i].digest_tag; - } - - SECOidTag - digest_get_encryption_oid(cms_context *cms) - { -- int i = cms->selected_digest; -+ unsigned int i = cms->selected_digest; - return digest_params[i].digest_encryption_tag; - } - - SECOidTag - digest_get_signature_oid(cms_context *cms) - { -- int i = cms->selected_digest; -+ unsigned int i = cms->selected_digest; - return digest_params[i].signature_tag; - } - - int - digest_get_digest_size(cms_context *cms) - { -- int i = cms->selected_digest; -+ unsigned int i = cms->selected_digest; - return digest_params[i].size; - } - -@@ -91,7 +95,7 @@ teardown_digests(cms_context *ctx) - if (!digests) - return; - -- for (int i = 0; i < n_digest_params; i++) { -+ for (unsigned int i = 0; i < n_digest_params; i++) { - if (digests[i].pk11ctx) { - PK11_Finalize(digests[i].pk11ctx); - PK11_DestroyContext(digests[i].pk11ctx, PR_TRUE); -@@ -135,7 +139,7 @@ cms_context_init(cms_context *cms) - if (!cms->arena) - cnreterr(-1, cms, "could not create cryptographic arena"); - -- cms->selected_digest = -1; -+ cms->selected_digest = DEFAULT_DIGEST_PARAM; - - INIT_LIST_HEAD(&cms->pk12_ins); - cms->pk12_out.fd = -1; -@@ -219,7 +223,7 @@ cms_context_fini(cms_context *cms) - memset(&cms->newsig, '\0', sizeof (cms->newsig)); - } - -- cms->selected_digest = -1; -+ cms->selected_digest = DEFAULT_DIGEST_PARAM; - - if (cms->ci_digest) { - free_poison(cms->ci_digest->data, cms->ci_digest->len); -@@ -342,7 +346,7 @@ int - set_digest_parameters(cms_context *cms, char *name) - { - if (strcmp(name, "help")) { -- for (int i = 0; i < n_digest_params; i++) { -+ for (unsigned int i = 0; i < n_digest_params; i++) { - if (!strcmp(name, digest_params[i].name)) { - cms->selected_digest = i; - return 0; -@@ -350,7 +354,7 @@ set_digest_parameters(cms_context *cms, char *name) - } - } else { - printf("Supported digests: "); -- for (int i = 0; digest_params[i].name != NULL; i++) { -+ for (unsigned int i = 0; digest_params[i].name != NULL; i++) { - printf("%s ", digest_params[i].name); - } - printf("\n"); -@@ -1265,7 +1269,7 @@ generate_digest_begin(cms_context *cms) - cnreterr(-1, cms, "could not allocate digest context"); - } - -- for (int i = 0; i < n_digest_params; i++) { -+ for (unsigned int i = 0; i < n_digest_params; i++) { - digests[i].pk11ctx = PK11_CreateDigestContext( - digest_params[i].digest_tag); - if (!digests[i].pk11ctx) -@@ -1278,7 +1282,7 @@ generate_digest_begin(cms_context *cms) - return 0; - - err: -- for (int i = 0; i < n_digest_params; i++) { -+ for (unsigned int i = 0; i < n_digest_params; i++) { - if (digests[i].pk11ctx) - PK11_DestroyContext(digests[i].pk11ctx, PR_TRUE); - } -@@ -1290,7 +1294,7 @@ err: - void - generate_digest_step(cms_context *cms, void *data, size_t len) - { -- for (int i = 0; i < n_digest_params; i++) -+ for (unsigned int i = 0; i < n_digest_params; i++) - PK11_DigestOp(cms->digests[i].pk11ctx, data, len); - } - -@@ -1299,7 +1303,7 @@ generate_digest_finish(cms_context *cms) - { - void *mark = PORT_ArenaMark(cms->arena); - -- for (int i = 0; i < n_digest_params; i++) { -+ for (unsigned int i = 0; i < n_digest_params; i++) { - SECItem *digest = PORT_ArenaZAlloc(cms->arena,sizeof (SECItem)); - if (digest == NULL) - cngotoerr(err, cms, "could not allocate memory"); -@@ -1326,7 +1330,7 @@ generate_digest_finish(cms_context *cms) - PORT_ArenaUnmark(cms->arena, mark); - return 0; - err: -- for (int i = 0; i < n_digest_params; i++) { -+ for (unsigned int i = 0; i < n_digest_params; i++) { - if (cms->digests[i].pk11ctx) - PK11_DestroyContext(cms->digests[i].pk11ctx, PR_TRUE); - } -@@ -1343,12 +1347,13 @@ int - generate_signature(cms_context *cms) - { - int rc = 0; -+ int i = cms->selected_digest; - -- if (cms->digests[cms->selected_digest].pe_digest == NULL) -+ if (cms->digests[i].pe_digest == NULL) - cnreterr(-1, cms, "PE digest has not been allocated"); - -- if (content_is_empty(cms->digests[cms->selected_digest].pe_digest->data, -- cms->digests[cms->selected_digest].pe_digest->len)) -+ if (content_is_empty(cms->digests[i].pe_digest->data, -+ cms->digests[i].pe_digest->len)) - cnreterr(-1, cms, "PE binary has not been digested"); - - SECItem sd_der; -diff --git a/src/content_info.c b/src/content_info.c -index 9684850..900974c 100644 ---- a/src/content_info.c -+++ b/src/content_info.c -@@ -181,7 +181,7 @@ generate_spc_digest_info(cms_context *cms, SECItem *dip) - if (generate_algorithm_id(cms, &di.digestAlgorithm, - digest_get_digest_oid(cms)) < 0) - return -1; -- int i = cms->selected_digest; -+ unsigned int i = cms->selected_digest; - memcpy(&di.digest, cms->digests[i].pe_digest, sizeof (di.digest)); - - if (content_is_empty(di.digest.data, di.digest.len)) { -diff --git a/src/cms_common.h b/src/cms_common.h -index e45402c..35a128a 100644 ---- a/src/cms_common.h -+++ b/src/cms_common.h -@@ -65,6 +65,7 @@ struct digest { - - #define DIGEST_PARAM_SHA256 0 - #define DIGEST_PARAM_SHA1 1 -+#define DEFAULT_DIGEST_PARAM DIGEST_PARAM_SHA256 - - struct digest_param { - char *name; -@@ -76,7 +77,7 @@ struct digest_param { - }; - - extern const struct digest_param digest_params[2]; --extern const int n_digest_params; -+extern const unsigned int n_digest_params; - - typedef struct pk12_file { - char *path; -@@ -149,7 +150,7 @@ typedef struct cms_context { - int db_out, dbx_out, dbt_out; - - struct digest *digests; -- int selected_digest; -+ unsigned int selected_digest; - int omit_vendor_cert; - - SECItem newsig; diff --git a/pesign.patches b/pesign.patches index 0b756e9..e69de29 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1,23 +0,0 @@ -Patch0001: 0001-daemon-remove-always-true-comparison.patch -Patch0002: 0002-make-handle-some-gcc-Wanalyzer-flags-better.patch -Patch0003: 0003-Rename-dprintf-to-dbgprintf.patch -Patch0004: 0004-.gitignore-add-compile_commands.json-and-.cache.patch -Patch0005: 0005-pesign-print-digests-before-filenames-like-sha256sum.patch -Patch0006: 0006-Add-pesum-an-authenticode-digest-generator.patch -Patch0007: 0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch -Patch0008: 0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch -Patch0009: 0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch -Patch0010: 0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch -Patch0011: 0011-Rename-README-README.md.patch -Patch0012: 0012-README.md-show-off-a-bit-more.patch -Patch0013: 0013-Fix-missing-line-in-README.md.patch -Patch0014: 0014-Fix-typo-in-efikeygen-command.patch -Patch0015: 0015-pesigcheck-Fix-crash-on-digest-match.patch -Patch0016: 0016-cms-store-digest-as-pointer-instead-of-index.patch -Patch0017: 0017-Fix-mandoc-invocation-to-not-produce-garbage.patch -Patch0018: 0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch -Patch0019: 0019-get_password_passthrough-handle-the-callback-context.patch -Patch0020: 0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch -Patch0021: 0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch -Patch0022: 0022-CMS-add-some-minor-cleanups.patch -Patch0023: 0023-CMS-make-cms-selected_digest-an-index-again.patch diff --git a/pesign.spec b/pesign.spec index 4c835d0..3a44093 100644 --- a/pesign.spec +++ b/pesign.spec @@ -5,8 +5,8 @@ Name: pesign Summary: Signing utility for UEFI binaries -Version: 115 -Release: 9%{?dist} +Version: 116 +Release: 1%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -162,6 +162,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Jan 31 2023 Robbie Harwood - 116-1 +- New upstream release (116) +- Resolves: CVE-2022-3560 + * Wed Aug 31 2022 Robbie Harwood - 115-9 - Roll up to pjones's smartcard/cms fixes diff --git a/sources b/sources index b6ddc75..f7edcc4 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ SHA512 (certs.tar.xz) = ddac535c786d1a23074534323c4ce89f907d4f82b19c5d3a9c814b145fbac1599cd2386cf20c28d22aee7d5c4db441f052bab9ee655de756117a0a0bc99b525f -SHA512 (pesign-115.tar.bz2) = 0091d70e286326b1ed74418ca8c5a2a63d42e6aa3eccdfc4f09a34241b2addfe878af17d1d74648b7da79d6cd7158fcca0f3a52f4a82a57cacae4617b42b1faa +SHA512 (pesign-116.tar.bz2) = be3e1083f5e9f889cb8f7c50a8ebe723542fb2f6d1de8de9b04a9f21526ebaa8ab1efc7d4be11bcb0bc9862fa4bc6f78ee35e4d3496dd3b8927170b97795d25c From 04f02e8cd7210749cf49f1a6ab12f9daf60b8f13 Mon Sep 17 00:00:00 2001 From: Nicolas Frayer Date: Mon, 20 Feb 2023 18:20:00 +0100 Subject: [PATCH 60/70] cms_common: Fixed Segmentation fault Signed-off-by: Nicolas Frayer --- ...-cms_common-Fixed-Segmentation-fault.patch | 27 +++++++++++++++++++ pesign.patches | 1 + pesign.spec | 5 +++- 3 files changed, 32 insertions(+), 1 deletion(-) create mode 100644 0001-cms_common-Fixed-Segmentation-fault.patch diff --git a/0001-cms_common-Fixed-Segmentation-fault.patch b/0001-cms_common-Fixed-Segmentation-fault.patch new file mode 100644 index 0000000..4464ed0 --- /dev/null +++ b/0001-cms_common-Fixed-Segmentation-fault.patch @@ -0,0 +1,27 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Nicolas Frayer +Date: Mon, 20 Feb 2023 15:26:20 +0100 +Subject: [PATCH] cms_common: Fixed Segmentation fault + +When running efikeygen, the binary crashes with a segfault due +to dereferencing a **ptr instead of a *ptr. + +Signed-off-by: Nicolas Frayer +(cherry picked from commit 227435af461f38fc4abeafe02884675ad4b1feb4) +--- + src/cms_common.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/cms_common.c b/src/cms_common.c +index 24576f2..89d946a 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -956,7 +956,7 @@ find_certificate_by_issuer_and_sn(cms_context *cms, + if (!ias) + cnreterr(-1, cms, "invalid issuer and serial number"); + +- return find_certificate_by_callback(cms, match_issuer_and_serial, &ias, cert); ++ return find_certificate_by_callback(cms, match_issuer_and_serial, ias, cert); + } + + int diff --git a/pesign.patches b/pesign.patches index e69de29..2ca4433 100644 --- a/pesign.patches +++ b/pesign.patches @@ -0,0 +1 @@ +Patch0001: 0001-cms_common-Fixed-Segmentation-fault.patch diff --git a/pesign.spec b/pesign.spec index 3a44093..6d73398 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 1%{?dist} +Release: 2%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -162,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Mon Feb 20 2023 Nicolas Frayer - 116-2 +- cms_common: Fixed Segmentation fault + * Tue Jan 31 2023 Robbie Harwood - 116-1 - New upstream release (116) - Resolves: CVE-2022-3560 From 634e8088934852b8fbf2f421f1c077807f71bcad Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Fri, 2 Feb 2024 13:28:25 -0500 Subject: [PATCH 61/70] Fix incorrect calloc() invocations caught by -Wcalloc-transposed-args Signed-off-by: Peter Jones --- 0002-Fix-reversed-calloc-arguments.patch | 41 ++++++++++++++++++++++++ pesign.patches | 1 + pesign.spec | 5 ++- 3 files changed, 46 insertions(+), 1 deletion(-) create mode 100644 0002-Fix-reversed-calloc-arguments.patch diff --git a/0002-Fix-reversed-calloc-arguments.patch b/0002-Fix-reversed-calloc-arguments.patch new file mode 100644 index 0000000..861993c --- /dev/null +++ b/0002-Fix-reversed-calloc-arguments.patch @@ -0,0 +1,41 @@ +From 1f9e2fa0b4d872fdd01ca3ba81b04dfb1211a187 Mon Sep 17 00:00:00 2001 +From: Stephen Gallagher +Date: Fri, 2 Feb 2024 09:32:48 -0500 +Subject: [PATCH] Fix reversed calloc() arguments + +The prototype is "void *calloc(size_t nelem, size_t elsize);" + +These two instances had them reversed, almost certainly leading to +buffer overflow issues. This was detected by +-Werror=calloc-transposed-args on gcc. + +Signed-off-by: Stephen Gallagher +--- + src/pesigcheck.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/pesigcheck.c b/src/pesigcheck.c +index 6dc67f76a81..8119cf10a7b 100644 +--- a/src/pesigcheck.c ++++ b/src/pesigcheck.c +@@ -240,7 +240,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons, + + cert_iter iter; + +- reasonps = calloc(sizeof(struct reason), 512); ++ reasonps = calloc(512, sizeof(struct reason)); + if (!reasonps) + err(1, "check_signature"); + +@@ -281,7 +281,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons, + + num_reasons += 16; + +- new_reasons = calloc(sizeof(struct reason), num_reasons); ++ new_reasons = calloc(num_reasons, sizeof(struct reason)); + if (!new_reasons) + err(1, "check_signature"); + reasonps = new_reasons; +-- +2.41.0 + diff --git a/pesign.patches b/pesign.patches index 2ca4433..fa7478f 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1 +1,2 @@ Patch0001: 0001-cms_common-Fixed-Segmentation-fault.patch +Patch0002: 0002-Fix-reversed-calloc-arguments.patch diff --git a/pesign.spec b/pesign.spec index 6d73398..de9c1ce 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 2%{?dist} +Release: 3%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -162,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Fri Feb 02 2024 Peter Jones - 116-3 +- Fix incorrect calloc() invocations caught by -Wcalloc-transposed-args + * Mon Feb 20 2023 Nicolas Frayer - 116-2 - cms_common: Fixed Segmentation fault From 74685e918a559dcd0c40d28ba96d7a2ecba89f85 Mon Sep 17 00:00:00 2001 From: JasenChao Date: Tue, 5 Mar 2024 20:44:59 +0800 Subject: [PATCH 62/70] Add riscv64 support. --- pesign.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/pesign.spec b/pesign.spec index de9c1ce..0bccb2f 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 3%{?dist} +Release: 4%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -38,7 +38,7 @@ Requires: nss-util Requires: popt Requires: rpm Requires(pre): shadow-utils -ExclusiveArch: %{ix86} x86_64 ia64 aarch64 %{arm} +ExclusiveArch: %{ix86} x86_64 ia64 aarch64 %{arm} riscv64 %if 0%{?rhel} == 7 BuildRequires: rh-signing-tools >= 1.20-2 %endif @@ -162,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Mar 05 2024 Liu Yang - 116-4 +- Add riscv64. + * Fri Feb 02 2024 Peter Jones - 116-3 - Fix incorrect calloc() invocations caught by -Wcalloc-transposed-args From 58d5697b85b8a09a7560c916b36eed6ee8eafa42 Mon Sep 17 00:00:00 2001 From: Stephen Gallagher Date: Wed, 10 Jul 2024 10:07:44 -0400 Subject: [PATCH 63/70] Add package.cfg for ELN Starting with fedpkg 1.45, we can now have `fedpkg build` automatically trigger both the Rawhide and ELN build of this package, since it cannot be rebuilt by the normal ELN auto-rebuild service due to the restricted nature of this package. By adding this file, the maintainer does not need to remember to build it for both releases manually. Signed-off-by: Stephen Gallagher --- package.cfg | 3 +++ 1 file changed, 3 insertions(+) create mode 100644 package.cfg diff --git a/package.cfg b/package.cfg new file mode 100644 index 0000000..0cf8855 --- /dev/null +++ b/package.cfg @@ -0,0 +1,3 @@ +[koji] +targets = rawhide eln + From df4c12aec8bbcd45f1e82eb67ca0d968820578c2 Mon Sep 17 00:00:00 2001 From: Kevin Fenzi Date: Tue, 12 Nov 2024 14:05:21 -0800 Subject: [PATCH 64/70] Rebuild to pick up riscv64 change --- pesign.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index 0bccb2f..6c5e788 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 4%{?dist} +Release: 5%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -162,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Nov 12 2024 Kevin Fenzi - 116-5 +- Rebuild to pick up riscv64 change + * Tue Mar 05 2024 Liu Yang - 116-4 - Add riscv64. From c938656c1214c9eb5edfecbc33febe543c96754a Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Thu, 21 Nov 2024 14:02:44 -0500 Subject: [PATCH 65/70] Work around OpenSC token name changes Signed-off-by: Peter Jones --- pesign.patches | 1 + pesign.spec | 5 ++++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/pesign.patches b/pesign.patches index fa7478f..50d9486 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1,2 +1,3 @@ Patch0001: 0001-cms_common-Fixed-Segmentation-fault.patch Patch0002: 0002-Fix-reversed-calloc-arguments.patch +Patch0003: 0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch diff --git a/pesign.spec b/pesign.spec index 6c5e788..723bab8 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 5%{?dist} +Release: 6%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -162,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Thu Nov 21 2024 Peter Jones - 116-6 +- Work around OpenSC token name changes + * Tue Nov 12 2024 Kevin Fenzi - 116-5 - Rebuild to pick up riscv64 change From 8b1bcf2332ace11c2c4afc264fe44a2ec7b2044d Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Thu, 21 Nov 2024 14:02:44 -0500 Subject: [PATCH 66/70] Work around OpenSC token name changes Signed-off-by: Peter Jones --- ...SC-changing-token-names-on-fedora-bu.patch | 61 +++++++++++++++++++ 1 file changed, 61 insertions(+) create mode 100644 0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch diff --git a/0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch b/0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch new file mode 100644 index 0000000..663f4c4 --- /dev/null +++ b/0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch @@ -0,0 +1,61 @@ +From dc17b1d248c705073a5160e7c871a52aa9ce6e99 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Thu, 21 Nov 2024 13:58:05 -0500 +Subject: [PATCH] Work around OpenSC changing token names on fedora builders + *again*. + +Once again OpenSC has changed how token names work in an incompatible +way, and we need to work around it even harder on the Fedora kernel +builders. + +Reviewed-by: Kevin Fenzi +Reviewed-by: Justin Forbes +Signed-off-by: Peter Jones +--- + src/macros.pesign | 3 ++- + src/pesign-rpmbuild-helper.in | 15 ++++++++++++++- + 2 files changed, 16 insertions(+), 2 deletions(-) + +diff --git a/src/macros.pesign b/src/macros.pesign +index b7d6af1f6f5..47e3f19f8ed 100644 +--- a/src/macros.pesign ++++ b/src/macros.pesign +@@ -9,7 +9,8 @@ + %__pesign_token %{nil}%{?pe_signing_token:--token "%{pe_signing_token}"} + %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} + +-%__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} ++# See the comment in pesign-rpmbuild-helper.in about the token name here. ++%__pesign_client_token %{!?pe_signing_token:"OpenSC Card"}%{?pe_signing_token:"%{pe_signing_token}"} + %__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} + + %_pesign /usr/bin/pesign +diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in +index 30d5441207b..42de1a1e002 100644 +--- a/src/pesign-rpmbuild-helper.in ++++ b/src/pesign-rpmbuild-helper.in +@@ -214,7 +214,20 @@ main() { + rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" + elif [[ -n "${socket}" ]] ; then + ### welcome haaaaack city +- if [[ "${client_token[1]}" = "OpenSC Card (Fedora Signer)" ]] ; then ++ ### different versions of the opensc library name the token different ++ ### things, and as of this commit: ++ ### https://github.com/OpenSC/OpenSC/commit/259decf656a77a6d1bd3e944d6f198ed70832ff5 ++ ### that includes just not including the token label unless there's ++ ### more than one token. Unfortunately this is both for the displayed ++ ### info and for the token name you specify to /use/ the token, so we ++ ### have to handle all of those options here, and change the name to ++ ### match whatever the current version of opensc is using in the rpm ++ ### macro where we're setting it. Thankfully this is just a "is this ++ ### Fedora" check for us, and if it's RHEL we're not using OpenSC at ++ ### all. ++ if [[ "${client_token[1]}" = "OpenSC Card (Fedora Signer)" ]] \ ++ || [[ "${client_token[1]}" = "Fedora Signer" ]] \ ++ || [[ "${client_token[1]}" = "OpenSC Card" ]] ; then + if [[ "${input[1]}" =~ (/|^)vmlinuz($|[_.-]) ]] \ + || [[ "${input[1]}" =~ (/|^)bzImage($|[_.-]) ]] ; then + if [[ "${rhelcertfile}" =~ redhatsecureboot501.* ]] \ +-- +2.47.0 + From 93c64f2a0d041912609f8660c9eb09ec2e5b5d5b Mon Sep 17 00:00:00 2001 From: Luca Boccassi Date: Fri, 10 Jan 2025 20:40:35 +0000 Subject: [PATCH 67/70] Backport patch to skip auth on friendly slot Allow attaching a signature to a binary, needed for signing RPM packages in the SUSE Open Build Service. Upstream PR: https://github.com/rhboot/pesign/pull/101 Signed-off-by: Luca Boccassi --- ...-authentication-on-the-Friendly-slot.patch | 41 +++++++++++++++++++ pesign.patches | 1 + pesign.spec | 5 ++- 3 files changed, 46 insertions(+), 1 deletion(-) create mode 100644 0004-cms_common-skip-authentication-on-the-Friendly-slot.patch diff --git a/0004-cms_common-skip-authentication-on-the-Friendly-slot.patch b/0004-cms_common-skip-authentication-on-the-Friendly-slot.patch new file mode 100644 index 0000000..d13e454 --- /dev/null +++ b/0004-cms_common-skip-authentication-on-the-Friendly-slot.patch @@ -0,0 +1,41 @@ +From 616ec5f25adbde1a4bd78cdcacd6dcd7ecfa5a5c Mon Sep 17 00:00:00 2001 +From: Gary Lin +Date: Thu, 22 Dec 2022 13:49:34 +0800 +Subject: [PATCH] cms_common: skip authentication on the 'Friendly' slot + +When finding a certificate in a 'Friendly' slot without the need of the +private key, it is not necessary to authenticate the slot. + +For example, when the signed attributes and the raw signature are +created in a server and the user has the certificate, signkey.x509, and +tries to import them into myapp.efi: + + $ certutil -N -d nssdb -f passwd + $ certutil -A -d nssdb -f passwd -n signkey -t CT,CT,CT \ + -i signkey.x509 + $ pesign -n nssdb -c signkey -i myapp.efi -o myapp.efi.signed \ + -d sha256 -I myapp.sattr -R myapp.sig + +Since the "signkey" is 'Friendly', i.e. publicly readable, and the +private key is not needed, we can just skip the authentication and find +"signkey" in the slot. + +Signed-off-by: Gary Lin +--- + src/cms_common.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/src/cms_common.c b/src/cms_common.c +index cf572ca..44e5cca 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -628,7 +628,8 @@ find_certificate(cms_context *cms, int needs_private_key) + + int errnum; + SECStatus status; +- if (PK11_NeedLogin(psle->slot) && !PK11_IsLoggedIn(psle->slot, cms)) { ++ if ((needs_private_key || !PK11_IsFriendly(psle->slot)) && ++ (PK11_NeedLogin(psle->slot) && !PK11_IsLoggedIn(psle->slot, cms))) { + status = PK11_Authenticate(psle->slot, PR_TRUE, cms); + if (status != SECSuccess) { + save_port_err() { diff --git a/pesign.patches b/pesign.patches index 50d9486..d5f5f82 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1,3 +1,4 @@ Patch0001: 0001-cms_common-Fixed-Segmentation-fault.patch Patch0002: 0002-Fix-reversed-calloc-arguments.patch Patch0003: 0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch +Patch0004: 0004-cms_common-skip-authentication-on-the-Friendly-slot.patch diff --git a/pesign.spec b/pesign.spec index 723bab8..eaef8eb 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 6%{?dist} +Release: 7%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -162,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Wed Jan 29 2025 Nicolas Frayer - 116-7 +- Backport patch to skip auth on friendly slot + * Thu Nov 21 2024 Peter Jones - 116-6 - Work around OpenSC token name changes From d06a6e72e4d5bcd168f77540735124e0d79518c0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Tue, 11 Feb 2025 15:53:30 +0100 Subject: [PATCH 68/70] Add sysusers.d config file to allow rpm to create users/groups automatically See https://fedoraproject.org/wiki/Changes/RPMSuportForSystemdSysusers. --- pesign.spec | 20 ++++++++++++-------- 1 file changed, 12 insertions(+), 8 deletions(-) diff --git a/pesign.spec b/pesign.spec index eaef8eb..9daa276 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 7%{?dist} +Release: 8%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -37,7 +37,6 @@ Requires: nss-tools >= 3.53 Requires: nss-util Requires: popt Requires: rpm -Requires(pre): shadow-utils ExclusiveArch: %{ix86} x86_64 ia64 aarch64 %{arm} riscv64 %if 0%{?rhel} == 7 BuildRequires: rh-signing-tools >= 1.20-2 @@ -67,6 +66,11 @@ git am %{patches} pesign.sysusers.conf </dev/null || groupadd -r pesign -getent passwd pesign >/dev/null || \ - useradd -r -g pesign -d /run/pesign -s /sbin/nologin \ - -c "Group for the pesign signing daemon" pesign -exit 0 +install -m0644 -D pesign.sysusers.conf %{buildroot}%{_sysusersdir}/pesign.conf + %if 0%{?rhel} >= 7 || 0%{?fedora} >= 17 %post @@ -160,8 +160,12 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %endif %{python3_sitelib}/mockbuild/plugins/*/pesign.* %{python3_sitelib}/mockbuild/plugins/pesign.* +%{_sysusersdir}/pesign.conf %changelog +* Tue Feb 11 2025 Zbigniew JÄ™drzejewski-Szmek +- Add sysusers.d config file to allow rpm to create users/groups automatically + * Wed Jan 29 2025 Nicolas Frayer - 116-7 - Backport patch to skip auth on friendly slot From 0fec26534d262708d3132b88f37d9e1e9b62f5c7 Mon Sep 17 00:00:00 2001 From: Yaakov Selkowitz Date: Fri, 20 Jun 2025 16:13:03 -0400 Subject: [PATCH 69/70] Remove package.cfg This did not consistently work as intended, and the ELN automation can now build this properly. --- package.cfg | 3 --- 1 file changed, 3 deletions(-) delete mode 100644 package.cfg diff --git a/package.cfg b/package.cfg deleted file mode 100644 index 0cf8855..0000000 --- a/package.cfg +++ /dev/null @@ -1,3 +0,0 @@ -[koji] -targets = rawhide eln - From cd8477a2ebae2f3fdc82adffdd217d0da0aade6e Mon Sep 17 00:00:00 2001 From: Nicolas Frayer Date: Mon, 22 Jun 2026 21:04:52 +0200 Subject: [PATCH 70/70] Fix a FTBFS issue caused by a missing const qualifier Resolves: #2491392 Signed-off-by: Nicolas Frayer --- 0005-Add-const-qualifier-to-variable.patch | 25 ++++++++++++++++++++++ pesign.patches | 1 + pesign.spec | 6 +++++- 3 files changed, 31 insertions(+), 1 deletion(-) create mode 100644 0005-Add-const-qualifier-to-variable.patch diff --git a/0005-Add-const-qualifier-to-variable.patch b/0005-Add-const-qualifier-to-variable.patch new file mode 100644 index 0000000..20669f0 --- /dev/null +++ b/0005-Add-const-qualifier-to-variable.patch @@ -0,0 +1,25 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Nicolas Frayer +Date: Mon, 22 Jun 2026 20:58:03 +0200 +Subject: [PATCH] Add const qualifier to variable + +Add const to a variable initialized with using strrchr. + +Signed-off-by: Nicolas Frayer +--- + src/pesum.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/pesum.c b/src/pesum.c +index e4ddaf86d7fa..5d7dcb929eec 100644 +--- a/src/pesum.c ++++ b/src/pesum.c +@@ -141,7 +141,7 @@ main(int argc, char *argv[]) + while ((infile = poptGetArg(optCon)) != NULL) { + pesign_context *ctxp = NULL; + +- char *ext = strrchr(infile, '.'); ++ const char *ext = strrchr(infile, '.'); + if (ext && strcmp(ext, ".ko") == 0) + fmt = FORMAT_KERNEL_MODULE; + diff --git a/pesign.patches b/pesign.patches index d5f5f82..9981c26 100644 --- a/pesign.patches +++ b/pesign.patches @@ -2,3 +2,4 @@ Patch0001: 0001-cms_common-Fixed-Segmentation-fault.patch Patch0002: 0002-Fix-reversed-calloc-arguments.patch Patch0003: 0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch Patch0004: 0004-cms_common-skip-authentication-on-the-Friendly-slot.patch +Patch0005: 0005-Add-const-qualifier-to-variable.patch diff --git a/pesign.spec b/pesign.spec index 9daa276..9785b6b 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 8%{?dist} +Release: 9%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -163,6 +163,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{_sysusersdir}/pesign.conf %changelog +* Mon Jun 22 2026 Nicolas Frayer - 116-9 +- Fix a FTBFS issue caused by a missing const qualifier +- Resolves: #2491392 + * Tue Feb 11 2025 Zbigniew JÄ™drzejewski-Szmek - Add sysusers.d config file to allow rpm to create users/groups automatically