From 3c1a1c50645d863d6fcf8a347d31f9858c51b4e0 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 5 Oct 2021 13:05:06 -0400 Subject: [PATCH 01/32] Add rpminspect configuration (no code changes) Signed-off-by: Robbie Harwood --- rpminspect.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+) create mode 100644 rpminspect.yaml diff --git a/rpminspect.yaml b/rpminspect.yaml new file mode 100644 index 0000000..4c08189 --- /dev/null +++ b/rpminspect.yaml @@ -0,0 +1,13 @@ +--- +inspections: + # Not a Java package + javabytecode: off + + # These just flag when things change "too much" + changedfiles: off + filesize: off + patches: off + upstream: off + + # https://bugzilla.redhat.com/show_bug.cgi?id=2010936 + annocheck: off From 409a7cdd41746c8ff3d957f52fcdaf3eef6f6b21 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 14 Dec 2021 13:51:22 -0500 Subject: [PATCH 02/32] Fix upstream URL; no code changes Signed-off-by: Robbie Harwood --- pesign.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index c1a004f..6383411 100644 --- a/pesign.spec +++ b/pesign.spec @@ -5,7 +5,7 @@ Summary: Signing utility for UEFI binaries Version: 113 Release: 17%{?dist} License: GPLv2 -URL: https://github.com/vathpela/pesign +URL: https://github.com/rhboot/pesign Obsoletes: pesign-rh-test-certs <= 0.111-7 BuildRequires: make From 98a054d3eb2938d5c338d676268031c38183191b Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 21 Jan 2022 07:08:24 +0000 Subject: [PATCH 03/32] - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pesign.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index 6383411..e688936 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 113 -Release: 17%{?dist} +Release: 18%{?dist} License: GPLv2 URL: https://github.com/rhboot/pesign @@ -168,6 +168,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Fri Jan 21 2022 Fedora Release Engineering - 113-18 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + * Fri Jul 23 2021 Fedora Release Engineering - 113-17 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild From c7c4e0f825f288b0355f8ed81f9744ebead8e8ad Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 1 Feb 2022 19:52:01 +0000 Subject: [PATCH 04/32] New upstream version (114) Signed-off-by: Robbie Harwood --- ...fikeygen-Fix-the-build-with-nss-3.44.patch | 45 --- 0002-pesigcheck-Fix-a-wrong-assignment.patch | 49 --- ...t-and-server-work-with-the-113-proto.patch | 317 --------------- 0004-Rename-var-run-to-run.patch | 46 --- ...c-got-updated-and-the-token-name-cha.patch | 30 -- ...-run-and-var-run-for-the-socket-path.patch | 86 ---- 0007-client-remove-an-extra-debug-print.patch | 25 -- ...ros.pesign-to-pesign-rpmbuild-helper.patch | 379 ------------------ 0009-pesign-authorize-shellcheck.patch | 60 --- ...ize-don-t-setfacl-etc-pki-pesign-foo.patch | 26 -- 0011-kernel-building-hack.patch | 41 -- 0012-Use-run-not-var-run.patch | 105 ----- 0013-Turn-off-free-nonheap-object.patch | 35 -- pesign.spec | 41 +- sources | 2 +- 15 files changed, 16 insertions(+), 1271 deletions(-) delete mode 100644 0001-efikeygen-Fix-the-build-with-nss-3.44.patch delete mode 100644 0002-pesigcheck-Fix-a-wrong-assignment.patch delete mode 100644 0003-Make-0.112-client-and-server-work-with-the-113-proto.patch delete mode 100644 0004-Rename-var-run-to-run.patch delete mode 100644 0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch delete mode 100644 0006-client-try-run-and-var-run-for-the-socket-path.patch delete mode 100644 0007-client-remove-an-extra-debug-print.patch delete mode 100644 0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch delete mode 100644 0009-pesign-authorize-shellcheck.patch delete mode 100644 0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch delete mode 100644 0011-kernel-building-hack.patch delete mode 100644 0012-Use-run-not-var-run.patch delete mode 100644 0013-Turn-off-free-nonheap-object.patch diff --git a/0001-efikeygen-Fix-the-build-with-nss-3.44.patch b/0001-efikeygen-Fix-the-build-with-nss-3.44.patch deleted file mode 100644 index e583369..0000000 --- a/0001-efikeygen-Fix-the-build-with-nss-3.44.patch +++ /dev/null @@ -1,45 +0,0 @@ -From b535d1ac5cbcdf18a97d97a92581e38080d9e521 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 14 May 2019 11:28:38 -0400 -Subject: [PATCH] efikeygen: Fix the build with nss 3.44 - -NSS 3.44 adds some certificate types, which changes a type and makes -some encoding stuff weird. As a result, we get: - -gcc8 -I/wrkdirs/usr/ports/sysutils/pesign/work/pesign-0.110/include -O2 -pipe -fstack-protector-strong -Wl,-rpath=/usr/local/lib/gcc8 -isystem /usr/local/include -fno-strict-aliasing -g -O0 -g -O0 -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants --std=gnu99 -D_GNU_SOURCE -Wno-unused-result -Wno-unused-function -I../include/ -I/usr/local/include/nss -I/usr/local/include/nss/nss -I/usr/local/include/nspr -Werror -fPIC -isystem /usr/local/include -DCONFIG_amd64 -DCONFIG_amd64 -c efikeygen.c -o efikeygen.o -In file included from /usr/local/include/nss/nss/cert.h:22, - from efikeygen.c:39: -efikeygen.c: In function 'add_cert_type': -/usr/local/include/nss/nss/certt.h:445:5: error: unsigned conversion from 'int' to 'unsigned char' changes value from '496' to '240' [-Werror=overflow] - (NS_CERT_TYPE_SSL_CLIENT | NS_CERT_TYPE_SSL_SERVER | NS_CERT_TYPE_EMAIL | \ - ^ -efikeygen.c:208:23: note: in expansion of macro 'NS_CERT_TYPE_APP' - unsigned char type = NS_CERT_TYPE_APP; - ^~~~~~~~~~~~~~~~ -cc1: all warnings being treated as errors - -This is fixed by just making it an int. - -Fixes github issue #48. - -Signed-off-by: Peter Jones ---- - src/efikeygen.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/efikeygen.c b/src/efikeygen.c -index ede76ef0b48..2cd953e9781 100644 ---- a/src/efikeygen.c -+++ b/src/efikeygen.c -@@ -208,7 +208,7 @@ static int - add_cert_type(cms_context *cms, void *extHandle, int is_ca) - { - SECItem bitStringValue; -- unsigned char type = NS_CERT_TYPE_APP; -+ int type = NS_CERT_TYPE_APP; - - if (is_ca) - type |= NS_CERT_TYPE_SSL_CA | --- -2.23.0 - diff --git a/0002-pesigcheck-Fix-a-wrong-assignment.patch b/0002-pesigcheck-Fix-a-wrong-assignment.patch deleted file mode 100644 index 7df5f0b..0000000 --- a/0002-pesigcheck-Fix-a-wrong-assignment.patch +++ /dev/null @@ -1,49 +0,0 @@ -From c555fd74c009242c3864576bd5f17a1f8f4fdffd Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 18 Feb 2020 16:28:56 -0500 -Subject: [PATCH] pesigcheck: Fix a wrong assignment - -gcc says: - - pesigcheck.c: In function 'check_signature': - pesigcheck.c:321:17: error: implicit conversion from 'enum ' to 'enum ' [-Werror=enum-conversion] - 321 | reason->type = siBuffer; - | ^ - pesigcheck.c:333:17: error: implicit conversion from 'enum ' to 'enum ' [-Werror=enum-conversion] - 333 | reason->type = siBuffer; - | ^ - cc1: all warnings being treated as errors - -And indeed, that line of code makes no sense at all - it was supposed to -be reason->sig.type. - -Signed-off-by: Peter Jones ---- - src/pesigcheck.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/pesigcheck.c b/src/pesigcheck.c -index 524cce307bf..8fa0f1ad03d 100644 ---- a/src/pesigcheck.c -+++ b/src/pesigcheck.c -@@ -318,7 +318,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons, - reason->type = SIGNATURE; - reason->sig.data = data; - reason->sig.len = datalen; -- reason->type = siBuffer; -+ reason->sig.type = siBuffer; - nreason += 1; - is_invalid = true; - } -@@ -330,7 +330,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons, - reason->type = SIGNATURE; - reason->sig.data = data; - reason->sig.len = datalen; -- reason->type = siBuffer; -+ reason->sig.type = siBuffer; - nreason += 1; - has_valid_cert = true; - } --- -2.24.1 - diff --git a/0003-Make-0.112-client-and-server-work-with-the-113-proto.patch b/0003-Make-0.112-client-and-server-work-with-the-113-proto.patch deleted file mode 100644 index e639675..0000000 --- a/0003-Make-0.112-client-and-server-work-with-the-113-proto.patch +++ /dev/null @@ -1,317 +0,0 @@ -From 84547e6b7173e4b10a1931fd25f329ea9a8f68b0 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Thu, 11 Jun 2020 16:23:14 -0400 -Subject: [PATCH] Make 0.112 client and server work with the 113 protocol and - vise versa - -This makes the version of the sign API that takes a file type optional, -and makes the client attempt to negotiate which version it's getting. -It also leaves the server able to still handle the version from before -the file type was added. - -Signed-off-by: Peter Jones ---- - src/client.c | 74 +++++++++++++++++++++++++++++++++++++--------------- - src/daemon.c | 63 +++++++++++++++++++++++++++++--------------- - src/daemon.h | 2 ++ - 3 files changed, 97 insertions(+), 42 deletions(-) - -diff --git a/src/client.c b/src/client.c -index aa373abd981..57bcc09cbe8 100644 ---- a/src/client.c -+++ b/src/client.c -@@ -11,6 +11,7 @@ - #include - #include - #include -+#include - #include - #include - #include -@@ -84,8 +85,8 @@ connect_to_server(void) - static int32_t - check_response(int sd, char **srvmsg); - --static void --check_cmd_version(int sd, uint32_t command, char *name, int32_t version) -+static int -+check_cmd_version(int sd, uint32_t command, char *name, int32_t version, bool do_exit) - { - struct msghdr msg; - struct iovec iov[1]; -@@ -104,7 +105,7 @@ check_cmd_version(int sd, uint32_t command, char *name, int32_t version) - ssize_t n; - n = sendmsg(sd, &msg, 0); - if (n < 0) { -- fprintf(stderr, "check-cmd-version: kill daemon failed: %m\n"); -+ fprintf(stderr, "check-cmd-version: sendmsg failed: %m\n"); - exit(1); - } - -@@ -120,11 +121,17 @@ check_cmd_version(int sd, uint32_t command, char *name, int32_t version) - - char *srvmsg = NULL; - int32_t rc = check_response(sd, &srvmsg); -- if (rc < 0) -+ -+ if (do_exit && rc < 0) - errx(1, "command \"%s\" not known by server", name); -- if (rc != version) -+ -+ if (do_exit && rc != version) - errx(1, "command \"%s\": client version %d, server version %d", - name, version, rc); -+ -+ if (rc < 0) -+ return rc; -+ return rc == version; - } - - static void -@@ -134,7 +141,7 @@ send_kill_daemon(int sd) - struct iovec iov; - pesignd_msghdr pm; - -- check_cmd_version(sd, CMD_KILL_DAEMON, "kill-daemon", 0); -+ check_cmd_version(sd, CMD_KILL_DAEMON, "kill-daemon", 0, true); - - pm.version = PESIGND_VERSION; - pm.command = CMD_KILL_DAEMON; -@@ -276,7 +283,7 @@ unlock_token(int sd, char *tokenname, char *pin) - - uint32_t size1 = pesignd_string_size(pin); - -- check_cmd_version(sd, CMD_UNLOCK_TOKEN, "unlock-token", 0); -+ check_cmd_version(sd, CMD_UNLOCK_TOKEN, "unlock-token", 0, true); - - pm.version = PESIGND_VERSION; - pm.command = CMD_UNLOCK_TOKEN; -@@ -353,7 +360,7 @@ is_token_unlocked(int sd, char *tokenname) - - uint32_t size0 = pesignd_string_size(tokenname); - -- check_cmd_version(sd, CMD_IS_TOKEN_UNLOCKED, "is-token-unlocked", 0); -+ check_cmd_version(sd, CMD_IS_TOKEN_UNLOCKED, "is-token-unlocked", 0, true); - - pm.version = PESIGND_VERSION; - pm.command = CMD_IS_TOKEN_UNLOCKED; -@@ -452,6 +459,9 @@ static void - sign(int sd, char *infile, char *outfile, char *tokenname, char *certname, - int attached, uint32_t format) - { -+ int rc; -+ bool add_file_type; -+ - int infd = open(infile, O_RDONLY); - if (infd < 0) { - fprintf(stderr, "pesign-client: could not open input file " -@@ -481,12 +491,28 @@ oom: - exit(1); - } - -- check_cmd_version(sd, attached ? CMD_SIGN_ATTACHED : CMD_SIGN_DETACHED, -- attached ? "sign-attached" : "sign-detached", 0); -+ rc = check_cmd_version(sd, -+ attached ? CMD_SIGN_ATTACHED_WITH_FILE_TYPE -+ : CMD_SIGN_DETACHED_WITH_FILE_TYPE, -+ attached ? "sign-attached" : "sign-detached", -+ 0, format == FORMAT_KERNEL_MODULE); -+ if (rc >= 0) { -+ add_file_type = true; -+ } else { -+ add_file_type = false; -+ check_cmd_version(sd, attached ? CMD_SIGN_ATTACHED -+ : CMD_SIGN_DETACHED, -+ attached ? "sign-attached" : "sign-detached", -+ 0, true); -+ } - -+ printf("add_file_type:%d\n", add_file_type); - pm->version = PESIGND_VERSION; -- pm->command = attached ? CMD_SIGN_ATTACHED : CMD_SIGN_DETACHED; -- pm->size = size0 + size1 + sizeof(format); -+ pm->command = attached ? (add_file_type ? CMD_SIGN_ATTACHED_WITH_FILE_TYPE -+ : CMD_SIGN_ATTACHED) -+ : (add_file_type ? CMD_SIGN_DETACHED_WITH_FILE_TYPE -+ : CMD_SIGN_DETACHED); -+ pm->size = size0 + size1 + (add_file_type ? sizeof(format) : 0); - iov[0].iov_base = pm; - iov[0].iov_len = sizeof (*pm); - -@@ -503,25 +529,31 @@ oom: - } - - char *buffer; -- buffer = malloc(size0 + size1); -+ buffer = malloc(pm->size); - if (!buffer) - goto oom; - -- iov[0].iov_base = &format; -- iov[0].iov_len = sizeof(format); -+ int pos = 0; -+ -+ if (add_file_type) { -+ iov[pos].iov_base = &format; -+ iov[pos].iov_len = sizeof(format); -+ pos++; -+ } - - pesignd_string *tn = (pesignd_string *)buffer; - pesignd_string_set(tn, tokenname); -- iov[1].iov_base = tn; -- iov[1].iov_len = size0; -+ iov[pos].iov_base = tn; -+ iov[pos].iov_len = size0; -+ pos++; - - pesignd_string *cn = pesignd_string_next(tn); - pesignd_string_set(cn, certname); -- iov[2].iov_base = cn; -- iov[2].iov_len = size1; -+ iov[pos].iov_base = cn; -+ iov[pos].iov_len = size1; - - msg.msg_iov = iov; -- msg.msg_iovlen = 3; -+ msg.msg_iovlen = add_file_type ? 3 : 2; - - n = sendmsg(sd, &msg, 0); - if (n < 0) { -@@ -535,7 +567,7 @@ oom: - send_fd(sd, outfd); - - char *srvmsg = NULL; -- int rc = check_response(sd, &srvmsg); -+ rc = check_response(sd, &srvmsg); - if (rc < 0) { - fprintf(stderr, "pesign-client: signing failed: \"%s\"\n", - srvmsg); -diff --git a/src/daemon.c b/src/daemon.c -index 9374d59be30..494beb9af72 100644 ---- a/src/daemon.c -+++ b/src/daemon.c -@@ -12,6 +12,7 @@ - #include - #include - #include -+#include - #include - #include - #include -@@ -561,7 +562,7 @@ out: - - static void - handle_signing(context *ctx, struct pollfd *pollfd, socklen_t size, -- int attached) -+ int attached, bool with_file_type) - { - struct msghdr msg; - struct iovec iov; -@@ -585,8 +586,12 @@ oom: - - n = recvmsg(pollfd->fd, &msg, MSG_WAITALL); - -- file_format = *((uint32_t *) buffer); -- n -= sizeof(uint32_t); -+ if (with_file_type) { -+ file_format = *((uint32_t *) buffer); -+ n -= sizeof(uint32_t); -+ } else { -+ file_format = FORMAT_PE_BINARY; -+ } - - pesignd_string *tn = (pesignd_string *)(buffer + sizeof(uint32_t)); - if (n < (long long)sizeof(tn->size)) { -@@ -666,34 +671,44 @@ finish: - teardown_digests(ctx->cms); - } - -+static inline void -+handle_sign_helper(context *ctx, struct pollfd *pollfd, socklen_t size, -+ int attached, bool with_file_type) -+{ -+ int rc = cms_context_alloc(&ctx->cms); -+ if (rc < 0) -+ return; -+ -+ steal_from_cms(ctx->backup_cms, ctx->cms); -+ -+ handle_signing(ctx, pollfd, size, attached, with_file_type); -+ -+ hide_stolen_goods_from_cms(ctx->cms, ctx->backup_cms); -+ cms_context_fini(ctx->cms); -+} -+ - static void - handle_sign_attached(context *ctx, struct pollfd *pollfd, socklen_t size) - { -- int rc = cms_context_alloc(&ctx->cms); -- if (rc < 0) -- return; -+ handle_sign_helper(ctx, pollfd, size, 1, false); -+} - -- steal_from_cms(ctx->backup_cms, ctx->cms); -- -- handle_signing(ctx, pollfd, size, 1); -- -- hide_stolen_goods_from_cms(ctx->cms, ctx->backup_cms); -- cms_context_fini(ctx->cms); -+static void -+handle_sign_attached_with_file_type(context *ctx, struct pollfd *pollfd, socklen_t size) -+{ -+ handle_sign_helper(ctx, pollfd, size, 1, true); - } - - static void - handle_sign_detached(context *ctx, struct pollfd *pollfd, socklen_t size) - { -- int rc = cms_context_alloc(&ctx->cms); -- if (rc < 0) -- return; -+ handle_sign_helper(ctx, pollfd, size, 0, false); -+} - -- steal_from_cms(ctx->backup_cms, ctx->cms); -- -- handle_signing(ctx, pollfd, size, 0); -- -- hide_stolen_goods_from_cms(ctx->cms, ctx->backup_cms); -- cms_context_fini(ctx->cms); -+static void -+handle_sign_detached_with_file_type(context *ctx, struct pollfd *pollfd, socklen_t size) -+{ -+ handle_sign_helper(ctx, pollfd, size, 0, true); - } - - static void -@@ -725,6 +740,12 @@ cmd_table_t cmd_table[] = { - { CMD_UNLOCK_TOKEN, handle_unlock_token, "unlock-token", 0 }, - { CMD_SIGN_ATTACHED, handle_sign_attached, "sign-attached", 0 }, - { CMD_SIGN_DETACHED, handle_sign_detached, "sign-detached", 0 }, -+ { CMD_SIGN_ATTACHED_WITH_FILE_TYPE, -+ handle_sign_attached_with_file_type, -+ "sign-attached-with-file-type", 0 }, -+ { CMD_SIGN_DETACHED_WITH_FILE_TYPE, -+ handle_sign_detached_with_file_type, -+ "sign-detached-with-file-type", 0 }, - { CMD_RESPONSE, NULL, "response", 0 }, - { CMD_IS_TOKEN_UNLOCKED, handle_is_token_unlocked, - "is-token-unlocked", 0 }, -diff --git a/src/daemon.h b/src/daemon.h -index dd430512f1a..834d62c72d0 100644 ---- a/src/daemon.h -+++ b/src/daemon.h -@@ -33,6 +33,8 @@ typedef enum { - CMD_RESPONSE, - CMD_IS_TOKEN_UNLOCKED, - CMD_GET_CMD_VERSION, -+ CMD_SIGN_ATTACHED_WITH_FILE_TYPE, -+ CMD_SIGN_DETACHED_WITH_FILE_TYPE, - CMD_LIST_END - } pesignd_cmd; - --- -2.26.2 - diff --git a/0004-Rename-var-run-to-run.patch b/0004-Rename-var-run-to-run.patch deleted file mode 100644 index 593761b..0000000 --- a/0004-Rename-var-run-to-run.patch +++ /dev/null @@ -1,46 +0,0 @@ -From f886b7088dfea224e28c03b097c85c9bc20f5441 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Fri, 12 Jun 2020 11:49:44 -0400 -Subject: [PATCH] Rename /var/run/ to /run/ - -Signed-off-by: Peter Jones ---- - src/macros.pesign | 12 ++++++------ - src/tmpfiles.conf | 2 +- - 2 files changed, 7 insertions(+), 7 deletions(-) - -diff --git a/src/macros.pesign b/src/macros.pesign -index 56f75cafbc4..5a6da1c6809 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -45,14 +45,14 @@ - rm -rf ${sattrs} ${sattrs}.sig ${nss} \ - elif [ "$(id -un)" == "kojibuilder" -a \\\ - grep -q ID=fedora /etc/os-release -a \\\ -- ! -S /var/run/pesign/socket ]; then \ -+ ! -S /run/pesign/socket ]; then \ - echo "No socket even though this is kojibuilder" 1>&2 \ -- ls -ld /var/run/pesign 1>&2 \ -- ls -l /var/run/pesign/socket 1>&2 \ -- getfacl /var/run/pesign 1>&2 \ -- getfacl /var/run/pesign/socket 1>&2 \ -+ ls -ld /run/pesign 1>&2 \ -+ ls -l /run/pesign/socket 1>&2 \ -+ getfacl /run/pesign 1>&2 \ -+ getfacl /run/pesign/socket 1>&2 \ - exit 1 \ -- elif [ -S /var/run/pesign/socket ]; then \ -+ elif [ -S /run/pesign/socket ]; then \ - %{_pesign_client} -t %{__pesign_client_token} \\\ - -c %{__pesign_client_cert} \\\ - %{-i} %{-o} %{-e} %{-s} %{-C} \ -diff --git a/src/tmpfiles.conf b/src/tmpfiles.conf -index c1cf35597d8..3375ad52a44 100644 ---- a/src/tmpfiles.conf -+++ b/src/tmpfiles.conf -@@ -1 +1 @@ --D /var/run/pesign 0770 pesign pesign - -+D /run/pesign 0770 pesign pesign - --- -2.26.2 - diff --git a/0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch b/0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch deleted file mode 100644 index 2b47880..0000000 --- a/0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch +++ /dev/null @@ -1,30 +0,0 @@ -From 56eaa15e986d808c670381ca375216eb3abd1588 Mon Sep 17 00:00:00 2001 -From: Jeremy Cline -Date: Tue, 18 Feb 2020 16:37:53 -0500 -Subject: [PATCH] Apparently opensc got updated and the token name changed - -All the kernel builds started failing yesterday because the signing -token could not be found. Update the token name in the macro shipped by -pesign. - -Signed-off-by: Peter Jones ---- - src/macros.pesign | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/macros.pesign b/src/macros.pesign -index 7c5cba170e9..56f75cafbc4 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -9,7 +9,7 @@ - %__pesign_token %{nil}%{?pe_signing_token:-t "%{pe_signing_token}"} - %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} - --%__pesign_client_token %{!?pe_signing_token:"Fedora Signer (OpenSC Card)"}%{?pe_signing_token:"%{pe_signing_token}"} -+%__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} - %__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} - - %_pesign /usr/bin/pesign --- -2.26.2 - diff --git a/0006-client-try-run-and-var-run-for-the-socket-path.patch b/0006-client-try-run-and-var-run-for-the-socket-path.patch deleted file mode 100644 index 337faab..0000000 --- a/0006-client-try-run-and-var-run-for-the-socket-path.patch +++ /dev/null @@ -1,86 +0,0 @@ -From c662ad097eaa0d8c3691a22254f5d0e9622b26b7 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 6 Jul 2020 16:13:09 -0400 -Subject: [PATCH 6/7] client: try /run and /var/run for the socket path. - -Signed-off-by: Peter Jones ---- - src/client.c | 40 +++++++++++++++++++++++++++++----------- - 1 file changed, 29 insertions(+), 11 deletions(-) - -diff --git a/src/client.c b/src/client.c -index 2119ef33bf8..a38383415d5 100644 ---- a/src/client.c -+++ b/src/client.c -@@ -49,24 +49,24 @@ print_flag_name(FILE *f, int flag) - } - - static int --connect_to_server(void) -+connect_to_server_helper(const char * const sockpath) - { -- int rc = access(SOCKPATH, R_OK); -+ int rc = access(sockpath, R_OK); - if (rc != 0) { -- fprintf(stderr, "pesign-client: could not connect to server: " -- "%m\n"); -- exit(1); -+ warn("could not access socket \"%s\"", sockpath); -+ return rc; - } - - struct sockaddr_un addr_un = { - .sun_family = AF_UNIX, -- .sun_path = SOCKPATH, - }; -+ strncpy(addr_un.sun_path, sockpath, sizeof(addr_un.sun_path)); -+ addr_un.sun_path[sizeof(addr_un.sun_path)-1] = '\0'; - - int sd = socket(AF_UNIX, SOCK_STREAM, 0); - if (sd < 0) { -- fprintf(stderr, "pesign-client: could not open socket: %m\n"); -- exit(1); -+ warn("could not open socket \"%s\"", sockpath); -+ return sd; - } - - socklen_t len = strlen(addr_un.sun_path) + -@@ -74,14 +74,32 @@ connect_to_server(void) - - rc = connect(sd, (struct sockaddr *)&addr_un, len); - if (rc < 0) { -- fprintf(stderr, "pesign-client: could not connect to daemon: " -- "%m\n"); -- exit(1); -+ warn("could not connect to daemon"); -+ return sd; - } - - return sd; - } - -+static int -+connect_to_server(void) -+{ -+ int rc, i; -+ const char * const sockets[] = { -+ "/run/pesign/socket", -+ "/var/run/pesign/socket", -+ NULL -+ }; -+ -+ for (i = 0; sockets[i] != NULL; i++) { -+ rc = connect_to_server_helper(sockets[i]); -+ if (rc >= 0) -+ return rc; -+ } -+ -+ exit(1); -+} -+ - static int32_t - check_response(int sd, char **srvmsg); - --- -2.26.2 - diff --git a/0007-client-remove-an-extra-debug-print.patch b/0007-client-remove-an-extra-debug-print.patch deleted file mode 100644 index b094ea5..0000000 --- a/0007-client-remove-an-extra-debug-print.patch +++ /dev/null @@ -1,25 +0,0 @@ -From ea81cec14d31cd0b0dbde5b42414bfae9daec9b8 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 14 Jul 2020 16:44:09 -0400 -Subject: [PATCH 07/11] client: remove an extra debug print - -Signed-off-by: Peter Jones ---- - src/client.c | 1 - - 1 file changed, 1 deletion(-) - -diff --git a/src/client.c b/src/client.c -index 0082be1f597..c9966295e5f 100644 ---- a/src/client.c -+++ b/src/client.c -@@ -536,7 +536,6 @@ oom: - 0, true); - } - -- printf("add_file_type:%d\n", add_file_type); - pm->version = PESIGND_VERSION; - pm->command = attached ? (add_file_type ? CMD_SIGN_ATTACHED_WITH_FILE_TYPE - : CMD_SIGN_ATTACHED) --- -2.26.2 - diff --git a/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch b/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch deleted file mode 100644 index 3a62cf6..0000000 --- a/0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch +++ /dev/null @@ -1,379 +0,0 @@ -From 6c16b978fd33f3611e9f7aaf4f9c44bce1679485 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 6 Jul 2020 13:54:35 -0400 -Subject: [PATCH] Move most of macros.pesign to pesign-rpmbuild-helper - -Signed-off-by: Peter Jones ---- - Make.defaults | 1 + - src/Makefile | 8 +- - src/macros.pesign | 74 ++++-------- - src/pesign-rpmbuild-helper.in | 222 ++++++++++++++++++++++++++++++++++ - 4 files changed, 252 insertions(+), 53 deletions(-) - create mode 100644 src/pesign-rpmbuild-helper.in - -diff --git a/Make.defaults b/Make.defaults -index 0bacafe0d01..d4cd626c11e 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -16,6 +16,7 @@ INSTALLROOT = $(DESTDIR) - - INSTALL ?= install - CROSS_COMPILE ?= -+EFI_ARCHES ?= aa64 ia32 x64 - - PKG_CONFIG = $(CROSS_COMPILE)pkg-config - CC := $(if $(filter default,$(origin CC)),$(CROSS_COMPILE)gcc,$(CC)) -diff --git a/src/Makefile b/src/Makefile -index 74327ba13f3..a7ca89159c6 100644 ---- a/src/Makefile -+++ b/src/Makefile -@@ -5,7 +5,7 @@ include $(TOPDIR)/Make.version - include $(TOPDIR)/Make.rules - include $(TOPDIR)/Make.defaults - --BINTARGETS=authvar client efikeygen efisiglist pesigcheck pesign -+BINTARGETS=authvar client efikeygen efisiglist pesigcheck pesign pesign-rpmbuild-helper - SVCTARGETS=pesign.sysvinit pesign.service - TARGETS=$(BINTARGETS) $(SVCTARGETS) - -@@ -49,6 +49,11 @@ pesign : $(call objects-of,$(PESIGN_SOURCES) $(COMMON_SOURCES) $(COMMON_PE_SOURC - pesign : LDLIBS+=$(TOPDIR)/libdpe/libdpe.a - pesign : PKGS=efivar nss nspr popt - -+pesign-rpmbuild-helper: pesign-rpmbuild-helper.in -+ sed \ -+ -e "s/@@EFI_ARCHES@@/$(EFI_ARCHES)/g" \ -+ $^ > $@ -+ - deps : PKGS=efivar nss nspr popt uuid - deps : $(ALL_SOURCES) - $(MAKE) -f $(TOPDIR)/Make.deps \ -@@ -94,6 +99,7 @@ install : - $(INSTALL) -m 644 macros.pesign $(INSTALLROOT)/etc/rpm/ - $(INSTALL) -d -m 755 $(INSTALLROOT)$(libexecdir)/pesign/ - $(INSTALL) -m 750 pesign-authorize $(INSTALLROOT)$(libexecdir)/pesign/ -+ $(INSTALL) -m 755 pesign-rpmbuild-helper $(INSTALLROOT)$(libexecdir)/pesign/ - $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pesign - $(INSTALL) -m 600 pesign-users $(INSTALLROOT)/etc/pesign/users - $(INSTALL) -m 600 pesign-groups $(INSTALLROOT)/etc/pesign/groups -diff --git a/src/macros.pesign b/src/macros.pesign -index 5a6da1c6809..2e984b4eeb3 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -6,7 +6,7 @@ - # %pesign -s -i shim.orig -o shim.efi - # And magically get the right thing. - --%__pesign_token %{nil}%{?pe_signing_token:-t "%{pe_signing_token}"} -+%__pesign_token %{nil}%{?pe_signing_token:--token "%{pe_signing_token}"} - %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} - - %__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} -@@ -24,54 +24,24 @@ - # -a # rhel only - # -s # perform signing - %pesign(i:o:C:e:c:n:a:s) \ -- _pesign_nssdir=/etc/pki/pesign \ -- if [ %{__pesign_cert} = "Red Hat Test Certificate" ]; then \ -- _pesign_nssdir=/etc/pki/pesign-rh-test \ -- fi \ -- if [ -x %{_pesign} ] && \\\ -- [ "%{_target_cpu}" == "x86_64" -o \\\ -- "%{_target_cpu}" == "aarch64" ]; then \ -- if [ "0%{?rhel}" -ge "7" -a -f /usr/bin/rpm-sign ]; then \ -- nss=$(mktemp -p $PWD -d) \ -- echo > ${nss}/pwfile \ -- certutil -N -d ${nss} -f ${nss}/pwfile \ -- certutil -A -n "ca" -t "CT,C," -i %{-a*} -d ${nss} \ -- certutil -A -n "signer" -t ",c," -i %{-c*} -d ${nss} \ -- sattrs=$(mktemp -p $PWD --suffix=.der) \ -- %{_pesign} %{-i} -E ${sattrs} --certdir ${nss} --force \ -- rpm-sign --key "%{-n*}" --rsadgstsign ${sattrs} \ -- %{_pesign} -R ${sattrs}.sig -I ${sattrs} %{-i} \\\ -- --certdir ${nss} -c signer %{-o} \ -- rm -rf ${sattrs} ${sattrs}.sig ${nss} \ -- elif [ "$(id -un)" == "kojibuilder" -a \\\ -- grep -q ID=fedora /etc/os-release -a \\\ -- ! -S /run/pesign/socket ]; then \ -- echo "No socket even though this is kojibuilder" 1>&2 \ -- ls -ld /run/pesign 1>&2 \ -- ls -l /run/pesign/socket 1>&2 \ -- getfacl /run/pesign 1>&2 \ -- getfacl /run/pesign/socket 1>&2 \ -- exit 1 \ -- elif [ -S /run/pesign/socket ]; then \ -- %{_pesign_client} -t %{__pesign_client_token} \\\ -- -c %{__pesign_client_cert} \\\ -- %{-i} %{-o} %{-e} %{-s} %{-C} \ -- else \ -- %{_pesign} %{__pesign_token} -c %{__pesign_cert} \\\ -- --certdir ${_pesign_nssdir} \\\ -- %{-i} %{-o} %{-e} %{-s} %{-C} \ -- fi \ -- else \ -- if [ -n "%{-i*}" -a -n "%{-o*}" ]; then \ -- mv %{-i*} %{-o*} \ -- elif [ -n "%{-i*}" -a -n "%{-e*}" ]; then \ -- touch %{-e*} \ -- fi \ -- fi \ -- if [ ! -s %{-o} ]; then \ -- if [ -e "%{-o*}" ]; then \ -- rm -f %{-o*} \ -- fi \ -- exit 1 \ -- fi ; -- -+ %{_libexecdir}/pesign/pesign-rpmbuild-helper \\\ -+ "%{_target_cpu}" \\\ -+ "%{_pesign}" \\\ -+ "%{_pesign_client}" \\\ -+ %{?__pesign_client_token:--client-token %{__pesign_client_token}} \\\ -+ %{?__pesign_client_cert:--client-cert %{__pesign_client_cert}} \\\ -+ %{?__pesign_token:%{__pesign_token}} \\\ -+ %{?__pesign_cert:--cert %{__pesign_cert}} \\\ -+ %{?_buildhost:--hostname "%{_buildhost}"} \\\ -+ %{?vendor:--vendor "%{vendor}"} \\\ -+ %{?_rhel:--rhelver "%{_rhel}"} \\\ -+ %{?-n:--rhelcert %{-n*}}%{?!-n:--rhelcert %{__pesign_cert}} \\\ -+ %{?-a:--rhelcafile "%{-a*}"} \\\ -+ %{?-c:--rhelcertfile "%{-c*}"} \\\ -+ %{?-C:--certout "%{-C*}"} \\\ -+ %{?-e:--sattrout "%{-e*}"} \\\ -+ %{?-i:--in "%{-i*}"} \\\ -+ %{?-o:--out "%{-o*}"} \\\ -+ %{?-s:--sign} \\\ -+ ; \ -+%{nil} -diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in -new file mode 100644 -index 00000000000..c5287c27e0c ---- /dev/null -+++ b/src/pesign-rpmbuild-helper.in -@@ -0,0 +1,222 @@ -+#!/bin/bash -+# shellcheck shell=bash -+ -+set -eu -+set -x -+ -+usage() { -+ local status="${1}" && shift -+ local out -+ if [[ "${status}" -eq 0 ]] ; then -+ out=/dev/stdout -+ else -+ out=/dev/stderr -+ fi -+ -+ if [[ $# -gt 0 ]] ; then -+ echo "${0}: error: $*" >>"${out}" -+ fi -+ echo "usage: ${0} TARGET_CPU PESIGN_BINARY PESIGN_CLIENT_BINARY [OPTIONS]" >>"${out}" -+ exit "${status}" -+} -+ -+is_efi_arch() { -+ local arch="${1}" -+ local arches=(@@EFI_ARCHES@@) -+ local x -+ for x in "${arches[@]}" ; do -+ if [[ "${arch}" = "${x}" ]] ; then -+ return 0 -+ fi -+ done -+ return 1 -+} -+ -+error_on_empty() { -+ local f="${1}" -+ if [[ ! -s "${f}" ]] ; then -+ if [[ -e "${f}" ]] ; then -+ rm -f "${f}" -+ fi -+ echo "${0}: error: empty result file \"${f}\"">>/dev/stderr -+ exit 1 -+ fi -+} -+ -+main() { -+ if [[ $# -lt 3 ]] ; then -+ usage 1 not enough arguments -+ fi -+ local target_cpu="${1}" && shift -+ local bin="${1}" && shift -+ local client="${1}" && shift -+ -+ local rhelcafile="" || : -+ local rhelcertfile="" || : -+ -+ local certout=() || : -+ local sattrout=() || : -+ local input=() || : -+ local output=() || : -+ local client_token=() || : -+ local client_cert=() || : -+ local token=() || : -+ local cert=() || : -+ local rhelcert=() || : -+ local rhelver=0 || : -+ local sign="" || : -+ local arch="" || : -+ local vendor="" || : -+ local HOSTNAME="" || : -+ -+ while [[ $# -ge 2 ]] ; do -+ case " ${1} " in -+ " --rhelcafile ") -+ rhelcafile="${2}" -+ ;; -+ " --rhelcertfile ") -+ rhelcertfile="${2}" -+ ;; -+ " --hostname ") -+ HOSTNAME="${2}" -+ ;; -+ " --certout ") -+ certout[0]=-C -+ certout[1]="${2}" -+ ;; -+ " --sattrout ") -+ sattrout[0]=-e -+ sattrout[1]="${2}" -+ ;; -+ " --client-token ") -+ client_token[0]=-t -+ client_token[1]="${2}" -+ ;; -+ " --client-cert ") -+ client_cert[0]=-c -+ client_cert[1]="${2}" -+ ;; -+ " --token ") -+ token[0]=-t -+ token[1]="${2}" -+ ;; -+ " --cert ") -+ cert[0]=-c -+ cert[1]="${2}" -+ ;; -+ " --rhelcert ") -+ rhelcert[0]=-c -+ rhelcert[1]="${2}" -+ ;; -+ " --in ") -+ input[0]=-i -+ input[1]="${2}" -+ ;; -+ " --out ") -+ output[0]=-o -+ output[1]="${2}" -+ ;; -+ " --rhelver ") -+ rhelver="${2}" -+ ;; -+ " --vendor ") -+ vendor="${2}" -+ ;; -+ *) -+ break -+ ;; -+ esac -+ shift -+ shift -+ done -+ if [[ $# -ge 1 ]] && [[ "${1}" = --sign ]] ; then -+ sign=-s -+ shift -+ fi -+ -+ if [[ -z "${target_cpu}" ]] ; then -+ target_cpu="$(uname -m)" -+ fi -+ -+ target_cpu="${target_cpu/i?86/ia32}" -+ target_cpu="${target_cpu/x86_64/x64}" -+ target_cpu="${target_cpu/aarch64/aa64}" -+ target_cpu="${target_cpu/arm*/arm/}" -+ -+ local nssdir=/etc/pki/pesign -+ if [[ "${#cert[@]}" -eq 2 ]] && -+ [[ "${cert[1]}" == "Red Hat Test Certificate" ]] ; then -+ nssdir=/etc/pki/pesign-rh-test -+ fi -+ -+ # is_efi_arch is ultimately returning "is pesign configured to sign these -+ # using the rpm macro", so if it isn't, we're just copying the input to -+ # the output -+ if [[ -x "${bin}" ]] && ! is_efi_arch "${target_cpu}" ; then -+ if [[ -n "${input[*]}" ]] && [[ -n "${output[*]}" ]] ; then -+ cp -v "${input[1]}" "${output[1]}" -+ elif [[ -n "${input[*]}" ]] && [[ -n "${sattrout[*]}" ]] ; then -+ touch "${sattrout[1]}" -+ fi -+ -+ # if there's a 0-sized output file, delete it and error out -+ error_on_empty "${output[1]}" -+ return 0 -+ fi -+ -+ USERNAME="${USERNAME:-$(id -un)}" -+ -+ local socket="" || : -+ if grep -q ID=fedora /etc/os-release \ -+ && [[ "${rhelver}" -lt 7 ]] \ -+ && [[ "${USERNAME}" = "mockbuild" ]] \ -+ && [[ "${vendor}" = "Fedora Project" ]] \ -+ && [[ "${HOSTNAME}" =~ bkernel.* ]] -+ then -+ if [[ -S /run/pesign/socket ]] ; then -+ socket=/run/pesign/socket -+ elif [[ -S /var/run/pesign/socket ]]; then -+ socket=/var/run/pesign/socket -+ else -+ echo "Warning: no pesign socket even though user is ${USERNAME}" 1>&2 -+ echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 -+ ls -ld /run/pesign /var/run/pesign 1>&2 ||: -+ ls -l /run/pesign/socket /var/run/pesign/socket 1>&2 ||: -+ getfacl /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: -+ getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: -+ fi -+ fi -+ -+ if [[ "${rhelver}" -ge 7 ]] ; then -+ nssdir="$(mktemp -p "${PWD}" -d)" -+ echo > "${nssdir}/pwfile" -+ certutil -N -d "${nssdir}" -f "${nssdir}/pwfile" -+ certutil -A -n "ca" -t "CTu,CTu,CTu" -i "${rhelcafile}" -d "${nssdir}" -+ certutil -A -n "signer" -t "CTu,CTu,CTu" -i "${rhelcertfile}" -d "${nssdir}" -+ sattrs="$(mktemp -p "${PWD}" --suffix=.der)" -+ "${bin}" -E "${sattrs}" --certdir "${nssdir}" \ -+ "${input[@]}" --force -+ rpm-sign --key "${rhelcert[1]}" --rsadgstsign "${sattrs}" -+ "${bin}" -R "${sattrs}.sig" -I "${sattrs}" \ -+ --certdir "${nssdir}" -c signer \ -+ "${input[@]}" "${output[@]}" -+ rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" -+ elif [[ -n "${socket}" ]] ; then -+ "${client}" "${client_token[@]}" "${client_cert[@]}" \ -+ "${sattrout[@]}" "${certout[@]}" \ -+ ${sign} "${input[@]}" "${output[@]}" -+ else -+ "${bin}" --certdir "${nssdir}" "${token[@]}" \ -+ "${cert[@]}" ${sign} "${sattrout[@]}" \ -+ "${certout[@]}" "${input[@]}" "${output[@]}" -+ fi -+ -+ # if there's a 0-sized output file, delete it and error out -+ if [[ "${#output[@]}" -eq 2 ]] ; then -+ error_on_empty "${output[1]}" -+ fi -+} -+ -+main "${@}" -+ -+# vim:filetype=sh:fenc=utf-8:tw=78:sts=4:sw=4 --- -2.26.2 - diff --git a/0009-pesign-authorize-shellcheck.patch b/0009-pesign-authorize-shellcheck.patch deleted file mode 100644 index 3597f5f..0000000 --- a/0009-pesign-authorize-shellcheck.patch +++ /dev/null @@ -1,60 +0,0 @@ -From 3107894285164a3d25ca215a76593ebb6d4bc84c Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 14 Jul 2020 15:07:32 -0400 -Subject: [PATCH 09/11] pesign-authorize: shellcheck - -Signed-off-by: Peter Jones ---- - src/pesign-authorize | 16 ++++++++-------- - 1 file changed, 8 insertions(+), 8 deletions(-) - -diff --git a/src/pesign-authorize b/src/pesign-authorize -index a496f601ab4..55cd5c4e55b 100755 ---- a/src/pesign-authorize -+++ b/src/pesign-authorize -@@ -12,21 +12,21 @@ set -u - # License: GPLv2 - declare -a fileusers=() - declare -a dirusers=() --for user in $(cat /etc/pesign/users); do -+while read -r user ; do - dirusers[${#dirusers[@]}]=-m - dirusers[${#dirusers[@]}]="u:$user:rwx" - fileusers[${#fileusers[@]}]=-m - fileusers[${#fileusers[@]}]="u:$user:rw" --done -+done -Date: Tue, 14 Jul 2020 15:08:15 -0400 -Subject: [PATCH 10/11] pesign-authorize: don't setfacl /etc/pki/pesign-foo/ - -Signed-off-by: Peter Jones ---- - src/pesign-authorize | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/pesign-authorize b/src/pesign-authorize -index 55cd5c4e55b..c5448329c2c 100755 ---- a/src/pesign-authorize -+++ b/src/pesign-authorize -@@ -47,7 +47,7 @@ update_subdir() { - done - } - --for x in /var/run/pesign/ /etc/pki/pesign*/ ; do -+for x in /var/run/pesign/ /etc/pki/pesign/ ; do - if [ -d "${x}" ]; then - update_subdir "${x}" - else --- -2.26.2 - diff --git a/0011-kernel-building-hack.patch b/0011-kernel-building-hack.patch deleted file mode 100644 index 69ffc56..0000000 --- a/0011-kernel-building-hack.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 0b9048cbcc1cfc2afd9cbf781732882736cbe965 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 14 Jul 2020 16:42:39 -0400 -Subject: [PATCH 11/11] kernel building hack - -Signed-off-by: Peter Jones ---- - src/pesign-rpmbuild-helper.in | 17 +++++++++++++++++ - 1 file changed, 17 insertions(+) - -diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in -index c5287c27e0c..27b8261bc17 100644 ---- a/src/pesign-rpmbuild-helper.in -+++ b/src/pesign-rpmbuild-helper.in -@@ -202,6 +202,23 @@ main() { - "${input[@]}" "${output[@]}" - rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" - elif [[ -n "${socket}" ]] ; then -+ ### welcome haaaaack city -+ if [[ "${client_token[1]}" = "OpenSC Card (Fedora Signer)" ]] ; then -+ if [[ "${input[1]}" =~ (/|^)vmlinuz($|[_.-]) ]] \ -+ || [[ "${input[1]}" =~ (/|^)bzImage($|[_.-]) ]] ; then -+ if [[ "${rhelcertfile}" =~ redhatsecureboot501.* ]] \ -+ || [[ "${rhelcertfile}" =~ redhatsecureboot401.* ]] \ -+ || [[ "${rhelcertfile}" =~ centossecureboot201.* ]] ; then -+ client_cert[1]=kernel-signer -+ elif [[ "${rhelcertfile}" =~ redhatsecureboot502.* ]] \ -+ || [[ "${rhelcertfile}" =~ centossecureboot202.* ]] ; then -+ client_cert[1]=grub2-signer -+ elif [[ "${rhelcertfile}" =~ redhatsecureboot503.* ]] \ -+ || [[ "${rhelcertfile}" =~ centossecureboot203.* ]] ; then -+ client_cert[1]=fwupd-signer -+ fi -+ fi -+ fi - "${client}" "${client_token[@]}" "${client_cert[@]}" \ - "${sattrout[@]}" "${certout[@]}" \ - ${sign} "${input[@]}" "${output[@]}" --- -2.26.2 - diff --git a/0012-Use-run-not-var-run.patch b/0012-Use-run-not-var-run.patch deleted file mode 100644 index 1b4e0c6..0000000 --- a/0012-Use-run-not-var-run.patch +++ /dev/null @@ -1,105 +0,0 @@ -From db4c6e8cc57271dce6d204a3144982e544e55025 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Thu, 16 Jul 2020 16:28:26 -0400 -Subject: [PATCH] Use /run not /var/run - -Signed-off-by: Peter Jones ---- - src/daemon.h | 4 ++-- - src/Makefile | 2 +- - src/pesign-authorize | 2 +- - src/pesign.service.in | 2 +- - src/pesign.sysvinit.in | 10 +++++----- - 5 files changed, 10 insertions(+), 10 deletions(-) - -diff --git a/src/daemon.h b/src/daemon.h -index 0368dc9256c..5fcd97ea717 100644 ---- a/src/daemon.h -+++ b/src/daemon.h -@@ -51,8 +51,8 @@ typedef enum { - } pesignd_cmd; - - #define PESIGND_VERSION 0x2a9edaf0 --#define SOCKPATH "/var/run/pesign/socket" --#define PIDFILE "/var/run/pesign.pid" -+#define SOCKPATH "/run/pesign/socket" -+#define PIDFILE "/run/pesign.pid" - - static inline uint32_t UNUSED - pesignd_string_size(char *buffer) -diff --git a/src/Makefile b/src/Makefile -index a7ca89159c6..f7fb5fc9ee5 100644 ---- a/src/Makefile -+++ b/src/Makefile -@@ -78,7 +78,7 @@ install_sysvinit: pesign.sysvinit - install : - $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign/ - $(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign-rh-test/ -- $(INSTALL) -d -m 770 $(INSTALLROOT)/var/run/pesign/ -+ $(INSTALL) -d -m 770 $(INSTALLROOT)/run/pesign/ - $(INSTALL) -d -m 755 $(INSTALLROOT)$(bindir) - $(INSTALL) -m 755 authvar $(INSTALLROOT)$(bindir) - $(INSTALL) -m 755 pesign $(INSTALLROOT)$(bindir) -diff --git a/src/pesign-authorize b/src/pesign-authorize -index c5448329c2c..2381302440c 100755 ---- a/src/pesign-authorize -+++ b/src/pesign-authorize -@@ -47,7 +47,7 @@ update_subdir() { - done - } - --for x in /var/run/pesign/ /etc/pki/pesign/ ; do -+for x in /run/pesign/ /var/run/pesign/ /etc/pki/pesign/ ; do - if [ -d "${x}" ]; then - update_subdir "${x}" - else -diff --git a/src/pesign.service.in b/src/pesign.service.in -index c75a000892a..4ac2199bce2 100644 ---- a/src/pesign.service.in -+++ b/src/pesign.service.in -@@ -4,6 +4,6 @@ Description=Pesign signing daemon - [Service] - PrivateTmp=true - Type=forking --PIDFile=/var/run/pesign.pid -+PIDFile=/run/pesign.pid - ExecStart=/usr/bin/pesign --daemonize - ExecStartPost=@@LIBEXECDIR@@/pesign/pesign-authorize -diff --git a/src/pesign.sysvinit.in b/src/pesign.sysvinit.in -index b0e0f84ff0b..bf8edec8ff3 100644 ---- a/src/pesign.sysvinit.in -+++ b/src/pesign.sysvinit.in -@@ -4,7 +4,7 @@ - # - # chkconfig: - 50 50 - # processname: /usr/bin/pesign --# pidfile: /var/run/pesign.pid -+# pidfile: /run/pesign.pid - ### BEGIN INIT INFO - # Provides: pesign - # Default-Start: -@@ -20,9 +20,9 @@ RETVAL=0 - - start(){ - echo -n "Starting pesign: " -- mkdir /var/run/pesign 2>/dev/null && -- chown pesign:pesign /var/run/pesign && -- chmod 0770 /var/run/pesign -+ mkdir /run/pesign 2>/dev/null && -+ chown pesign:pesign /run/pesign && -+ chmod 0770 /run/pesign - daemon /usr/bin/pesign --daemonize - RETVAL=$? - echo -@@ -32,7 +32,7 @@ start(){ - - stop(){ - echo -n "Stopping pesign: " -- killproc -p /var/run/pesign.pid pesignd -+ killproc -p /run/pesign.pid pesignd - RETVAL=$? - echo - rm -f /var/lock/subsys/pesign --- -2.26.2 - diff --git a/0013-Turn-off-free-nonheap-object.patch b/0013-Turn-off-free-nonheap-object.patch deleted file mode 100644 index 3e62bd8..0000000 --- a/0013-Turn-off-free-nonheap-object.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 59428daf4863f192419eee4afec15cd099e99c9b Mon Sep 17 00:00:00 2001 -From: Jeff Law -Date: Mon, 16 Nov 2020 12:07:59 -0700 -Subject: [PATCH] Turn off -Wfree-nonheap-object - -authvar.c has a call to free (tokenname) where tokenname is set to a string constant -and never changed. That triggers GCC to issue a diagnostic that the value should not -be passed to free. - -This is a false positive from GCC as the call is guarded by a suitable condition that -always happens to be false. But pesign is being built without optimization and thus -the condition and free call are not optimized away. - -This patch just disables the warning. A better solution would be to fix the sources -or build with the optimizer enabled. ---- - Make.defaults | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/Make.defaults b/Make.defaults -index d4cd626..705cc3a 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -40,7 +40,7 @@ gcc_cflags = -Wmaybe-uninitialized -grecord-gcc-switches -flto - cflags = $(CFLAGS) $(ARCH3264) \ - -Wall -Wextra -Wsign-compare -Wno-unused-result \ - -Wno-unused-function -Wno-missing-field-initializers \ -- -Werror -Wno-error=cpp \ -+ -Werror -Wno-error=cpp -Wno-free-nonheap-object \ - -std=gnu11 -fshort-wchar -fPIC -fno-strict-aliasing \ - -D_GNU_SOURCE -DCONFIG_$(ARCH) -I${TOPDIR}/include \ - $(if $(filter $(CC),clang),$(clang_cflags), ) \ --- -2.28.0 - diff --git a/pesign.spec b/pesign.spec index e688936..992b822 100644 --- a/pesign.spec +++ b/pesign.spec @@ -2,28 +2,29 @@ Name: pesign Summary: Signing utility for UEFI binaries -Version: 113 -Release: 18%{?dist} -License: GPLv2 +Version: 114 +Release: 1%{?dist} +License: GPL-2.0-only URL: https://github.com/rhboot/pesign Obsoletes: pesign-rh-test-certs <= 0.111-7 -BuildRequires: make +BuildRequires: efivar-devel >= 31-1 BuildRequires: gcc BuildRequires: git +BuildRequires: libuuid-devel +BuildRequires: make +BuildRequires: mandoc BuildRequires: nspr +BuildRequires: nspr-devel >= 4.9.2-1 BuildRequires: nss +BuildRequires: nss-devel >= 3.13.6-1 +BuildRequires: nss-tools BuildRequires: nss-util BuildRequires: popt-devel -BuildRequires: nss-tools -BuildRequires: nspr-devel >= 4.9.2-1 -BuildRequires: nss-devel >= 3.13.6-1 -BuildRequires: efivar-devel >= 31-1 -BuildRequires: libuuid-devel +BuildRequires: python3 +BuildRequires: python3-rpm-macros BuildRequires: tar BuildRequires: xz -BuildRequires: python3-rpm-macros -BuildRequires: python3 %if 0%{?rhel} >= 7 || 0%{?fedora} >= 17 BuildRequires: systemd-rpm-macros %endif @@ -43,20 +44,6 @@ Source0: https://github.com/rhboot/pesign/releases/download/%{version}/pesign-%{ Source1: certs.tar.xz Source2: pesign.py -Patch0001: 0001-efikeygen-Fix-the-build-with-nss-3.44.patch -Patch0002: 0002-pesigcheck-Fix-a-wrong-assignment.patch -Patch0003: 0003-Make-0.112-client-and-server-work-with-the-113-proto.patch -Patch0004: 0004-Rename-var-run-to-run.patch -Patch0005: 0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch -Patch0006: 0006-client-try-run-and-var-run-for-the-socket-path.patch -Patch0007: 0007-client-remove-an-extra-debug-print.patch -Patch0008: 0008-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch -Patch0009: 0009-pesign-authorize-shellcheck.patch -Patch0010: 0010-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch -Patch0011: 0011-kernel-building-hack.patch -Patch0012: 0012-Use-run-not-var-run.patch -Patch0013: 0013-Turn-off-free-nonheap-object.patch - %description This package contains the pesign utility for signing UEFI binaries as well as other associated tools. @@ -141,7 +128,6 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %doc README TODO %{_bindir}/authvar %{_bindir}/efikeygen -%{_bindir}/efisiglist %{_bindir}/pesigcheck %{_bindir}/pesign %{_bindir}/pesign-client @@ -168,6 +154,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Feb 01 2022 Robbie Harwood - 114-1 +- New upstream version (114) + * Fri Jan 21 2022 Fedora Release Engineering - 113-18 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild diff --git a/sources b/sources index d0199f7..3522848 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ SHA512 (certs.tar.xz) = ddac535c786d1a23074534323c4ce89f907d4f82b19c5d3a9c814b145fbac1599cd2386cf20c28d22aee7d5c4db441f052bab9ee655de756117a0a0bc99b525f -SHA512 (pesign-113.tar.bz2) = 89c5e33bf6ac8f8dc4b65192e5fd4bf1fea285106d1de2a6ea02a8c5090f2ec5976b1d80c60e57f74fa56dc25b174a4dd5682292db44ab9aeab69ea992dfef36 +SHA512 (pesign-114.tar.bz2) = 5465c002db6f59ab59799ec79504ed96662bc5da2310282d2e85fc1f03c938343d88927e764e595bf21c3501e599e529a4752281349097cdc74e616535179b3c From ed9353e1df400caadda12228ecbc534e4d6cb846 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 1 Feb 2022 22:38:47 +0000 Subject: [PATCH 05/32] Fix build for 32-bit arches Signed-off-by: Robbie Harwood --- ...Fix-format-strings-for-32-bit-arches.patch | 112 ++++++++++++++++++ pesign.spec | 2 + 2 files changed, 114 insertions(+) create mode 100644 0001-Fix-format-strings-for-32-bit-arches.patch diff --git a/0001-Fix-format-strings-for-32-bit-arches.patch b/0001-Fix-format-strings-for-32-bit-arches.patch new file mode 100644 index 0000000..2b71a0e --- /dev/null +++ b/0001-Fix-format-strings-for-32-bit-arches.patch @@ -0,0 +1,112 @@ +From 1f8d0985d59ed41e291398f937d32493898bd711 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 1 Feb 2022 17:37:14 -0500 +Subject: [PATCH] Fix format strings for 32-bit arches + +Sadly, in 2022, this remains a thing. + +Signed-off-by: Robbie Harwood +--- + src/cms_pe_common.c | 16 +++++++++------- + src/password.c | 7 ++++--- + 2 files changed, 13 insertions(+), 10 deletions(-) + +diff --git a/src/cms_pe_common.c b/src/cms_pe_common.c +index 964f0d9..3a3921b 100644 +--- a/src/cms_pe_common.c ++++ b/src/cms_pe_common.c +@@ -49,7 +49,7 @@ check_pointer_and_size(cms_context *cms, Pe *pe, void *ptr, size_t size) + + if (p + size > m + map_size) + cmsreterr(0, cms, +- "pointer %p is above mmap end at %p (%lu is %lu bytes past EOF at %lu)", ++ "pointer %p is above mmap end at %p (%lu is %lu bytes past EOF at %zu)", + (void *)((uintptr_t)p + size), + (void *)((uintptr_t)m + map_size), + p + size - m, +@@ -189,7 +189,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + if (!check_pointer_and_size(cms, pe, hash_base, hash_size)) + cmsgotoerr(error, cms, "PE header is invalid"); + dprintf("beginning of hash"); +- dprintf("digesting %lx + %lx", hash_base - map, hash_size); ++ dprintf("digesting %tx + %zx", hash_base - map, hash_size); + generate_digest_step(cms, hash_base, hash_size); + + /* 5. Skip over the image checksum +@@ -209,7 +209,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + cmsgotoerr(error, cms, "PE data directory is invalid"); + + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %lx + %lx", hash_base - map, hash_size); ++ dprintf("digesting %tx + %zx", hash_base - map, hash_size); + + /* 8. Skip over the crt dir + * 9. Hash everything up to the end of the image header. */ +@@ -222,7 +222,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + cmsgotoerr(error, cms, "PE relocations table is invalid"); + + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %lx + %lx", hash_base - map, hash_size); ++ dprintf("digesting %tx + %zx", hash_base - map, hash_size); + + /* 10. Set SUM_OF_BYTES_HASHED to the size of the header. */ + hashed_bytes = pe32opthdr ? pe32opthdr->header_size +@@ -265,7 +265,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + } + + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %lx + %lx", hash_base - map, hash_size); ++ dprintf("digesting %tx + %zx", hash_base - map, hash_size); + + hashed_bytes += hash_size; + } +@@ -285,10 +285,12 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + memset(tmp_array, '\0', tmp_size); + memcpy(tmp_array, hash_base, hash_size); + generate_digest_step(cms, tmp_array, tmp_size); +- dprintf("digesting %lx + %lx", (unsigned long)tmp_array, tmp_size); ++ dprintf("digesting %tx + %zx", (ptrdiff_t)tmp_array, ++ tmp_size); + } else { + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %lx + %lx", hash_base - map, hash_size); ++ dprintf("digesting %tx + %zx", hash_base - map, ++ hash_size); + } + } + dprintf("end of hash"); +diff --git a/src/password.c b/src/password.c +index 644f362..05add9a 100644 +--- a/src/password.c ++++ b/src/password.c +@@ -213,7 +213,7 @@ parse_pwfile_line(char *start, struct token_pass *tp) + dprintf("non-whitespace span is %zd", span); + + if (line[span] == '\0') { +- dprintf("returning %ld", (line + span) - start); ++ dprintf("returning %td", (line + span) - start); + return (line + span) - start; + } + line[span] = '\0'; +@@ -241,7 +241,7 @@ parse_pwfile_line(char *start, struct token_pass *tp) + dprintf("Setting token pass %p to { %p, %p }", tp, tp->token, tp->pass); + dprintf("token:\"%s\"", tp->token); + dprintf("pass:\"%s\"", tp->pass); +- dprintf("returning %ld", (line + span) - start); ++ dprintf("returning %td", (line + span) - start); + return (line + span) - start; + } + +@@ -330,7 +330,8 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) + if (c != '\0') + span++; + start += span; +- dprintf("start is file[%ld] == '\\x%02hhx'", start - file, start[0]); ++ dprintf("start is file[%td] == '\\x%02hhx'", start - file, ++ start[0]); + } + + qsort(phrases, nphrases, sizeof(struct token_pass), token_pass_cmp); +-- +2.34.1 + diff --git a/pesign.spec b/pesign.spec index 992b822..a42dddf 100644 --- a/pesign.spec +++ b/pesign.spec @@ -44,6 +44,8 @@ Source0: https://github.com/rhboot/pesign/releases/download/%{version}/pesign-%{ Source1: certs.tar.xz Source2: pesign.py +Patch0001: 0001-Fix-format-strings-for-32-bit-arches.patch + %description This package contains the pesign utility for signing UEFI binaries as well as other associated tools. From 534c97e8edb95c66a9c00f844c936ec3bed8df25 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 2 Feb 2022 21:11:44 +0000 Subject: [PATCH 06/32] Attempt to fix signing parsing by dropping pesign_args Signed-off-by: Robbie Harwood --- 0001-Revert-Move-license-to-GPLv3.patch | 969 ++++++++++++++++++ ...Fix-format-strings-for-32-bit-arches.patch | 4 +- 0003-macros-drop-_pesign_args.patch | 47 + pesign.spec | 9 +- 4 files changed, 1025 insertions(+), 4 deletions(-) create mode 100644 0001-Revert-Move-license-to-GPLv3.patch rename 0001-Fix-format-strings-for-32-bit-arches.patch => 0002-Fix-format-strings-for-32-bit-arches.patch (97%) create mode 100644 0003-macros-drop-_pesign_args.patch diff --git a/0001-Revert-Move-license-to-GPLv3.patch b/0001-Revert-Move-license-to-GPLv3.patch new file mode 100644 index 0000000..4b8931c --- /dev/null +++ b/0001-Revert-Move-license-to-GPLv3.patch @@ -0,0 +1,969 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Tue, 1 Feb 2022 15:04:30 -0500 +Subject: [PATCH 1/3] Revert "Move license to GPLv3+" + +This was done too soon. It's missing some pieces and we need buy-in on +a couple of source files. + +This reverts commit 735650258c7956525b7ecf4b67483d025f0500e8. +--- + COPYING | 881 +++++++++++++++++--------------------------------------- + 1 file changed, 272 insertions(+), 609 deletions(-) + +diff --git a/COPYING b/COPYING +index 4432540..d159169 100644 +--- a/COPYING ++++ b/COPYING +@@ -1,627 +1,285 @@ ++ GNU GENERAL PUBLIC LICENSE ++ Version 2, June 1991 + +- GNU GENERAL PUBLIC LICENSE +- Version 3, 29 June 2007 +- +- Copyright (C) 2007 Free Software Foundation, Inc. ++ Copyright (C) 1989, 1991 Free Software Foundation, Inc., ++ 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA + Everyone is permitted to copy and distribute verbatim copies + of this license document, but changing it is not allowed. + +- Preamble ++ Preamble + +- The GNU General Public License is a free, copyleft license for +-software and other kinds of works. +- +- The licenses for most software and other practical works are designed +-to take away your freedom to share and change the works. By contrast, +-the GNU General Public License is intended to guarantee your freedom to +-share and change all versions of a program--to make sure it remains free +-software for all its users. We, the Free Software Foundation, use the +-GNU General Public License for most of our software; it applies also to +-any other work released this way by its authors. You can apply it to ++ The licenses for most software are designed to take away your ++freedom to share and change it. By contrast, the GNU General Public ++License is intended to guarantee your freedom to share and change free ++software--to make sure the software is free for all its users. This ++General Public License applies to most of the Free Software ++Foundation's software and to any other program whose authors commit to ++using it. (Some other Free Software Foundation software is covered by ++the GNU Lesser General Public License instead.) You can apply it to + your programs, too. + + When we speak of free software, we are referring to freedom, not + price. Our General Public Licenses are designed to make sure that you + have the freedom to distribute copies of free software (and charge for +-them if you wish), that you receive source code or can get it if you +-want it, that you can change the software or use pieces of it in new +-free programs, and that you know you can do these things. ++this service if you wish), that you receive source code or can get it ++if you want it, that you can change the software or use pieces of it ++in new free programs; and that you know you can do these things. + +- To protect your rights, we need to prevent others from denying you +-these rights or asking you to surrender the rights. Therefore, you have +-certain responsibilities if you distribute copies of the software, or if +-you modify it: responsibilities to respect the freedom of others. ++ To protect your rights, we need to make restrictions that forbid ++anyone to deny you these rights or to ask you to surrender the rights. ++These restrictions translate to certain responsibilities for you if you ++distribute copies of the software, or if you modify it. + + For example, if you distribute copies of such a program, whether +-gratis or for a fee, you must pass on to the recipients the same +-freedoms that you received. You must make sure that they, too, receive +-or can get the source code. And you must show them these terms so they +-know their rights. ++gratis or for a fee, you must give the recipients all the rights that ++you have. You must make sure that they, too, receive or can get the ++source code. And you must show them these terms so they know their ++rights. + +- Developers that use the GNU GPL protect your rights with two steps: +-(1) assert copyright on the software, and (2) offer you this License +-giving you legal permission to copy, distribute and/or modify it. ++ We protect your rights with two steps: (1) copyright the software, and ++(2) offer you this license which gives you legal permission to copy, ++distribute and/or modify the software. + +- For the developers' and authors' protection, the GPL clearly explains +-that there is no warranty for this free software. For both users' and +-authors' sake, the GPL requires that modified versions be marked as +-changed, so that their problems will not be attributed erroneously to +-authors of previous versions. ++ Also, for each author's protection and ours, we want to make certain ++that everyone understands that there is no warranty for this free ++software. If the software is modified by someone else and passed on, we ++want its recipients to know that what they have is not the original, so ++that any problems introduced by others will not reflect on the original ++authors' reputations. + +- Some devices are designed to deny users access to install or run +-modified versions of the software inside them, although the manufacturer +-can do so. This is fundamentally incompatible with the aim of +-protecting users' freedom to change the software. The systematic +-pattern of such abuse occurs in the area of products for individuals to +-use, which is precisely where it is most unacceptable. Therefore, we +-have designed this version of the GPL to prohibit the practice for those +-products. If such problems arise substantially in other domains, we +-stand ready to extend this provision to those domains in future versions +-of the GPL, as needed to protect the freedom of users. +- +- Finally, every program is threatened constantly by software patents. +-States should not allow patents to restrict development and use of +-software on general-purpose computers, but in those that do, we wish to +-avoid the special danger that patents applied to a free program could +-make it effectively proprietary. To prevent this, the GPL assures that +-patents cannot be used to render the program non-free. ++ Finally, any free program is threatened constantly by software ++patents. We wish to avoid the danger that redistributors of a free ++program will individually obtain patent licenses, in effect making the ++program proprietary. To prevent this, we have made it clear that any ++patent must be licensed for everyone's free use or not licensed at all. + + The precise terms and conditions for copying, distribution and + modification follow. + +- TERMS AND CONDITIONS +- +- 0. Definitions. +- +- "This License" refers to version 3 of the GNU General Public License. +- +- "Copyright" also means copyright-like laws that apply to other kinds of +-works, such as semiconductor masks. +- +- "The Program" refers to any copyrightable work licensed under this +-License. Each licensee is addressed as "you". "Licensees" and +-"recipients" may be individuals or organizations. +- +- To "modify" a work means to copy from or adapt all or part of the work +-in a fashion requiring copyright permission, other than the making of an +-exact copy. The resulting work is called a "modified version" of the +-earlier work or a work "based on" the earlier work. +- +- A "covered work" means either the unmodified Program or a work based +-on the Program. +- +- To "propagate" a work means to do anything with it that, without +-permission, would make you directly or secondarily liable for +-infringement under applicable copyright law, except executing it on a +-computer or modifying a private copy. Propagation includes copying, +-distribution (with or without modification), making available to the +-public, and in some countries other activities as well. +- +- To "convey" a work means any kind of propagation that enables other +-parties to make or receive copies. Mere interaction with a user through +-a computer network, with no transfer of a copy, is not conveying. +- +- An interactive user interface displays "Appropriate Legal Notices" +-to the extent that it includes a convenient and prominently visible +-feature that (1) displays an appropriate copyright notice, and (2) +-tells the user that there is no warranty for the work (except to the +-extent that warranties are provided), that licensees may convey the +-work under this License, and how to view a copy of this License. If +-the interface presents a list of user commands or options, such as a +-menu, a prominent item in the list meets this criterion. +- +- 1. Source Code. +- +- The "source code" for a work means the preferred form of the work +-for making modifications to it. "Object code" means any non-source +-form of a work. +- +- A "Standard Interface" means an interface that either is an official +-standard defined by a recognized standards body, or, in the case of +-interfaces specified for a particular programming language, one that +-is widely used among developers working in that language. +- +- The "System Libraries" of an executable work include anything, other +-than the work as a whole, that (a) is included in the normal form of +-packaging a Major Component, but which is not part of that Major +-Component, and (b) serves only to enable use of the work with that +-Major Component, or to implement a Standard Interface for which an +-implementation is available to the public in source code form. A +-"Major Component", in this context, means a major essential component +-(kernel, window system, and so on) of the specific operating system +-(if any) on which the executable work runs, or a compiler used to +-produce the work, or an object code interpreter used to run it. +- +- The "Corresponding Source" for a work in object code form means all +-the source code needed to generate, install, and (for an executable +-work) run the object code and to modify the work, including scripts to +-control those activities. However, it does not include the work's +-System Libraries, or general-purpose tools or generally available free +-programs which are used unmodified in performing those activities but +-which are not part of the work. For example, Corresponding Source +-includes interface definition files associated with source files for +-the work, and the source code for shared libraries and dynamically +-linked subprograms that the work is specifically designed to require, +-such as by intimate data communication or control flow between those +-subprograms and other parts of the work. +- +- The Corresponding Source need not include anything that users +-can regenerate automatically from other parts of the Corresponding +-Source. +- +- The Corresponding Source for a work in source code form is that +-same work. +- +- 2. Basic Permissions. +- +- All rights granted under this License are granted for the term of +-copyright on the Program, and are irrevocable provided the stated +-conditions are met. This License explicitly affirms your unlimited +-permission to run the unmodified Program. The output from running a +-covered work is covered by this License only if the output, given its +-content, constitutes a covered work. This License acknowledges your +-rights of fair use or other equivalent, as provided by copyright law. +- +- You may make, run and propagate covered works that you do not +-convey, without conditions so long as your license otherwise remains +-in force. You may convey covered works to others for the sole purpose +-of having them make modifications exclusively for you, or provide you +-with facilities for running those works, provided that you comply with +-the terms of this License in conveying all material for which you do +-not control copyright. Those thus making or running the covered works +-for you must do so exclusively on your behalf, under your direction +-and control, on terms that prohibit them from making any copies of +-your copyrighted material outside their relationship with you. +- +- Conveying under any other circumstances is permitted solely under +-the conditions stated below. Sublicensing is not allowed; section 10 +-makes it unnecessary. +- +- 3. Protecting Users' Legal Rights From Anti-Circumvention Law. +- +- No covered work shall be deemed part of an effective technological +-measure under any applicable law fulfilling obligations under article +-11 of the WIPO copyright treaty adopted on 20 December 1996, or +-similar laws prohibiting or restricting circumvention of such +-measures. +- +- When you convey a covered work, you waive any legal power to forbid +-circumvention of technological measures to the extent such circumvention +-is effected by exercising rights under this License with respect to +-the covered work, and you disclaim any intention to limit operation or +-modification of the work as a means of enforcing, against the work's +-users, your or third parties' legal rights to forbid circumvention of +-technological measures. +- +- 4. Conveying Verbatim Copies. +- +- You may convey verbatim copies of the Program's source code as you +-receive it, in any medium, provided that you conspicuously and +-appropriately publish on each copy an appropriate copyright notice; +-keep intact all notices stating that this License and any +-non-permissive terms added in accord with section 7 apply to the code; +-keep intact all notices of the absence of any warranty; and give all +-recipients a copy of this License along with the Program. +- +- You may charge any price or no price for each copy that you convey, +-and you may offer support or warranty protection for a fee. +- +- 5. Conveying Modified Source Versions. +- +- You may convey a work based on the Program, or the modifications to +-produce it from the Program, in the form of source code under the +-terms of section 4, provided that you also meet all of these conditions: +- +- a) The work must carry prominent notices stating that you modified +- it, and giving a relevant date. +- +- b) The work must carry prominent notices stating that it is +- released under this License and any conditions added under section +- 7. This requirement modifies the requirement in section 4 to +- "keep intact all notices". +- +- c) You must license the entire work, as a whole, under this +- License to anyone who comes into possession of a copy. This +- License will therefore apply, along with any applicable section 7 +- additional terms, to the whole of the work, and all its parts, +- regardless of how they are packaged. This License gives no +- permission to license the work in any other way, but it does not +- invalidate such permission if you have separately received it. +- +- d) If the work has interactive user interfaces, each must display +- Appropriate Legal Notices; however, if the Program has interactive +- interfaces that do not display Appropriate Legal Notices, your +- work need not make them do so. +- +- A compilation of a covered work with other separate and independent +-works, which are not by their nature extensions of the covered work, +-and which are not combined with it such as to form a larger program, +-in or on a volume of a storage or distribution medium, is called an +-"aggregate" if the compilation and its resulting copyright are not +-used to limit the access or legal rights of the compilation's users +-beyond what the individual works permit. Inclusion of a covered work +-in an aggregate does not cause this License to apply to the other +-parts of the aggregate. +- +- 6. Conveying Non-Source Forms. +- +- You may convey a covered work in object code form under the terms +-of sections 4 and 5, provided that you also convey the +-machine-readable Corresponding Source under the terms of this License, +-in one of these ways: +- +- a) Convey the object code in, or embodied in, a physical product +- (including a physical distribution medium), accompanied by the +- Corresponding Source fixed on a durable physical medium +- customarily used for software interchange. +- +- b) Convey the object code in, or embodied in, a physical product +- (including a physical distribution medium), accompanied by a +- written offer, valid for at least three years and valid for as +- long as you offer spare parts or customer support for that product +- model, to give anyone who possesses the object code either (1) a +- copy of the Corresponding Source for all the software in the +- product that is covered by this License, on a durable physical +- medium customarily used for software interchange, for a price no +- more than your reasonable cost of physically performing this +- conveying of source, or (2) access to copy the +- Corresponding Source from a network server at no charge. +- +- c) Convey individual copies of the object code with a copy of the +- written offer to provide the Corresponding Source. This +- alternative is allowed only occasionally and noncommercially, and +- only if you received the object code with such an offer, in accord +- with subsection 6b. +- +- d) Convey the object code by offering access from a designated +- place (gratis or for a charge), and offer equivalent access to the +- Corresponding Source in the same way through the same place at no +- further charge. You need not require recipients to copy the +- Corresponding Source along with the object code. If the place to +- copy the object code is a network server, the Corresponding Source +- may be on a different server (operated by you or a third party) +- that supports equivalent copying facilities, provided you maintain +- clear directions next to the object code saying where to find the +- Corresponding Source. Regardless of what server hosts the +- Corresponding Source, you remain obligated to ensure that it is +- available for as long as needed to satisfy these requirements. +- +- e) Convey the object code using peer-to-peer transmission, provided +- you inform other peers where the object code and Corresponding +- Source of the work are being offered to the general public at no +- charge under subsection 6d. +- +- A separable portion of the object code, whose source code is excluded +-from the Corresponding Source as a System Library, need not be +-included in conveying the object code work. +- +- A "User Product" is either (1) a "consumer product", which means any +-tangible personal property which is normally used for personal, family, +-or household purposes, or (2) anything designed or sold for incorporation +-into a dwelling. In determining whether a product is a consumer product, +-doubtful cases shall be resolved in favor of coverage. For a particular +-product received by a particular user, "normally used" refers to a +-typical or common use of that class of product, regardless of the status +-of the particular user or of the way in which the particular user +-actually uses, or expects or is expected to use, the product. A product +-is a consumer product regardless of whether the product has substantial +-commercial, industrial or non-consumer uses, unless such uses represent +-the only significant mode of use of the product. +- +- "Installation Information" for a User Product means any methods, +-procedures, authorization keys, or other information required to install +-and execute modified versions of a covered work in that User Product from +-a modified version of its Corresponding Source. The information must +-suffice to ensure that the continued functioning of the modified object +-code is in no case prevented or interfered with solely because +-modification has been made. +- +- If you convey an object code work under this section in, or with, or +-specifically for use in, a User Product, and the conveying occurs as +-part of a transaction in which the right of possession and use of the +-User Product is transferred to the recipient in perpetuity or for a +-fixed term (regardless of how the transaction is characterized), the +-Corresponding Source conveyed under this section must be accompanied +-by the Installation Information. But this requirement does not apply +-if neither you nor any third party retains the ability to install +-modified object code on the User Product (for example, the work has +-been installed in ROM). +- +- The requirement to provide Installation Information does not include a +-requirement to continue to provide support service, warranty, or updates +-for a work that has been modified or installed by the recipient, or for +-the User Product in which it has been modified or installed. Access to a +-network may be denied when the modification itself materially and +-adversely affects the operation of the network or violates the rules and +-protocols for communication across the network. +- +- Corresponding Source conveyed, and Installation Information provided, +-in accord with this section must be in a format that is publicly +-documented (and with an implementation available to the public in +-source code form), and must require no special password or key for +-unpacking, reading or copying. +- +- 7. Additional Terms. +- +- "Additional permissions" are terms that supplement the terms of this +-License by making exceptions from one or more of its conditions. +-Additional permissions that are applicable to the entire Program shall +-be treated as though they were included in this License, to the extent +-that they are valid under applicable law. If additional permissions +-apply only to part of the Program, that part may be used separately +-under those permissions, but the entire Program remains governed by +-this License without regard to the additional permissions. +- +- When you convey a copy of a covered work, you may at your option +-remove any additional permissions from that copy, or from any part of +-it. (Additional permissions may be written to require their own +-removal in certain cases when you modify the work.) You may place +-additional permissions on material, added by you to a covered work, +-for which you have or can give appropriate copyright permission. +- +- Notwithstanding any other provision of this License, for material you +-add to a covered work, you may (if authorized by the copyright holders of +-that material) supplement the terms of this License with terms: +- +- a) Disclaiming warranty or limiting liability differently from the +- terms of sections 15 and 16 of this License; or +- +- b) Requiring preservation of specified reasonable legal notices or +- author attributions in that material or in the Appropriate Legal +- Notices displayed by works containing it; or +- +- c) Prohibiting misrepresentation of the origin of that material, or +- requiring that modified versions of such material be marked in +- reasonable ways as different from the original version; or +- +- d) Limiting the use for publicity purposes of names of licensors or +- authors of the material; or +- +- e) Declining to grant rights under trademark law for use of some +- trade names, trademarks, or service marks; or +- +- f) Requiring indemnification of licensors and authors of that +- material by anyone who conveys the material (or modified versions of +- it) with contractual assumptions of liability to the recipient, for +- any liability that these contractual assumptions directly impose on +- those licensors and authors. +- +- All other non-permissive additional terms are considered "further +-restrictions" within the meaning of section 10. If the Program as you +-received it, or any part of it, contains a notice stating that it is +-governed by this License along with a term that is a further +-restriction, you may remove that term. If a license document contains +-a further restriction but permits relicensing or conveying under this +-License, you may add to a covered work material governed by the terms +-of that license document, provided that the further restriction does +-not survive such relicensing or conveying. +- +- If you add terms to a covered work in accord with this section, you +-must place, in the relevant source files, a statement of the +-additional terms that apply to those files, or a notice indicating +-where to find the applicable terms. +- +- Additional terms, permissive or non-permissive, may be stated in the +-form of a separately written license, or stated as exceptions; +-the above requirements apply either way. +- +- 8. Termination. +- +- You may not propagate or modify a covered work except as expressly +-provided under this License. Any attempt otherwise to propagate or +-modify it is void, and will automatically terminate your rights under +-this License (including any patent licenses granted under the third +-paragraph of section 11). +- +- However, if you cease all violation of this License, then your +-license from a particular copyright holder is reinstated (a) +-provisionally, unless and until the copyright holder explicitly and +-finally terminates your license, and (b) permanently, if the copyright +-holder fails to notify you of the violation by some reasonable means +-prior to 60 days after the cessation. +- +- Moreover, your license from a particular copyright holder is +-reinstated permanently if the copyright holder notifies you of the +-violation by some reasonable means, this is the first time you have +-received notice of violation of this License (for any work) from that +-copyright holder, and you cure the violation prior to 30 days after +-your receipt of the notice. +- +- Termination of your rights under this section does not terminate the +-licenses of parties who have received copies or rights from you under +-this License. If your rights have been terminated and not permanently +-reinstated, you do not qualify to receive new licenses for the same +-material under section 10. +- +- 9. Acceptance Not Required for Having Copies. +- +- You are not required to accept this License in order to receive or +-run a copy of the Program. Ancillary propagation of a covered work +-occurring solely as a consequence of using peer-to-peer transmission +-to receive a copy likewise does not require acceptance. However, +-nothing other than this License grants you permission to propagate or +-modify any covered work. These actions infringe copyright if you do +-not accept this License. Therefore, by modifying or propagating a +-covered work, you indicate your acceptance of this License to do so. +- +- 10. Automatic Licensing of Downstream Recipients. +- +- Each time you convey a covered work, the recipient automatically +-receives a license from the original licensors, to run, modify and +-propagate that work, subject to this License. You are not responsible +-for enforcing compliance by third parties with this License. +- +- An "entity transaction" is a transaction transferring control of an +-organization, or substantially all assets of one, or subdividing an +-organization, or merging organizations. If propagation of a covered +-work results from an entity transaction, each party to that +-transaction who receives a copy of the work also receives whatever +-licenses to the work the party's predecessor in interest had or could +-give under the previous paragraph, plus a right to possession of the +-Corresponding Source of the work from the predecessor in interest, if +-the predecessor has it or can get it with reasonable efforts. +- +- You may not impose any further restrictions on the exercise of the +-rights granted or affirmed under this License. For example, you may +-not impose a license fee, royalty, or other charge for exercise of +-rights granted under this License, and you may not initiate litigation +-(including a cross-claim or counterclaim in a lawsuit) alleging that +-any patent claim is infringed by making, using, selling, offering for +-sale, or importing the Program or any portion of it. +- +- 11. Patents. +- +- A "contributor" is a copyright holder who authorizes use under this +-License of the Program or a work on which the Program is based. The +-work thus licensed is called the contributor's "contributor version". +- +- A contributor's "essential patent claims" are all patent claims +-owned or controlled by the contributor, whether already acquired or +-hereafter acquired, that would be infringed by some manner, permitted +-by this License, of making, using, or selling its contributor version, +-but do not include claims that would be infringed only as a +-consequence of further modification of the contributor version. For +-purposes of this definition, "control" includes the right to grant +-patent sublicenses in a manner consistent with the requirements of ++ GNU GENERAL PUBLIC LICENSE ++ TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION ++ ++ 0. This License applies to any program or other work which contains ++a notice placed by the copyright holder saying it may be distributed ++under the terms of this General Public License. The "Program", below, ++refers to any such program or work, and a "work based on the Program" ++means either the Program or any derivative work under copyright law: ++that is to say, a work containing the Program or a portion of it, ++either verbatim or with modifications and/or translated into another ++language. (Hereinafter, translation is included without limitation in ++the term "modification".) Each licensee is addressed as "you". ++ ++Activities other than copying, distribution and modification are not ++covered by this License; they are outside its scope. The act of ++running the Program is not restricted, and the output from the Program ++is covered only if its contents constitute a work based on the ++Program (independent of having been made by running the Program). ++Whether that is true depends on what the Program does. ++ ++ 1. You may copy and distribute verbatim copies of the Program's ++source code as you receive it, in any medium, provided that you ++conspicuously and appropriately publish on each copy an appropriate ++copyright notice and disclaimer of warranty; keep intact all the ++notices that refer to this License and to the absence of any warranty; ++and give any other recipients of the Program a copy of this License ++along with the Program. ++ ++You may charge a fee for the physical act of transferring a copy, and ++you may at your option offer warranty protection in exchange for a fee. ++ ++ 2. You may modify your copy or copies of the Program or any portion ++of it, thus forming a work based on the Program, and copy and ++distribute such modifications or work under the terms of Section 1 ++above, provided that you also meet all of these conditions: ++ ++ a) You must cause the modified files to carry prominent notices ++ stating that you changed the files and the date of any change. ++ ++ b) You must cause any work that you distribute or publish, that in ++ whole or in part contains or is derived from the Program or any ++ part thereof, to be licensed as a whole at no charge to all third ++ parties under the terms of this License. ++ ++ c) If the modified program normally reads commands interactively ++ when run, you must cause it, when started running for such ++ interactive use in the most ordinary way, to print or display an ++ announcement including an appropriate copyright notice and a ++ notice that there is no warranty (or else, saying that you provide ++ a warranty) and that users may redistribute the program under ++ these conditions, and telling the user how to view a copy of this ++ License. (Exception: if the Program itself is interactive but ++ does not normally print such an announcement, your work based on ++ the Program is not required to print an announcement.) ++ ++These requirements apply to the modified work as a whole. If ++identifiable sections of that work are not derived from the Program, ++and can be reasonably considered independent and separate works in ++themselves, then this License, and its terms, do not apply to those ++sections when you distribute them as separate works. But when you ++distribute the same sections as part of a whole which is a work based ++on the Program, the distribution of the whole must be on the terms of ++this License, whose permissions for other licensees extend to the ++entire whole, and thus to each and every part regardless of who wrote it. ++ ++Thus, it is not the intent of this section to claim rights or contest ++your rights to work written entirely by you; rather, the intent is to ++exercise the right to control the distribution of derivative or ++collective works based on the Program. ++ ++In addition, mere aggregation of another work not based on the Program ++with the Program (or with a work based on the Program) on a volume of ++a storage or distribution medium does not bring the other work under ++the scope of this License. ++ ++ 3. You may copy and distribute the Program (or a work based on it, ++under Section 2) in object code or executable form under the terms of ++Sections 1 and 2 above provided that you also do one of the following: ++ ++ a) Accompany it with the complete corresponding machine-readable ++ source code, which must be distributed under the terms of Sections ++ 1 and 2 above on a medium customarily used for software interchange; or, ++ ++ b) Accompany it with a written offer, valid for at least three ++ years, to give any third party, for a charge no more than your ++ cost of physically performing source distribution, a complete ++ machine-readable copy of the corresponding source code, to be ++ distributed under the terms of Sections 1 and 2 above on a medium ++ customarily used for software interchange; or, ++ ++ c) Accompany it with the information you received as to the offer ++ to distribute corresponding source code. (This alternative is ++ allowed only for noncommercial distribution and only if you ++ received the program in object code or executable form with such ++ an offer, in accord with Subsection b above.) ++ ++The source code for a work means the preferred form of the work for ++making modifications to it. For an executable work, complete source ++code means all the source code for all modules it contains, plus any ++associated interface definition files, plus the scripts used to ++control compilation and installation of the executable. However, as a ++special exception, the source code distributed need not include ++anything that is normally distributed (in either source or binary ++form) with the major components (compiler, kernel, and so on) of the ++operating system on which the executable runs, unless that component ++itself accompanies the executable. ++ ++If distribution of executable or object code is made by offering ++access to copy from a designated place, then offering equivalent ++access to copy the source code from the same place counts as ++distribution of the source code, even though third parties are not ++compelled to copy the source along with the object code. ++ ++ 4. You may not copy, modify, sublicense, or distribute the Program ++except as expressly provided under this License. Any attempt ++otherwise to copy, modify, sublicense or distribute the Program is ++void, and will automatically terminate your rights under this License. ++However, parties who have received copies, or rights, from you under ++this License will not have their licenses terminated so long as such ++parties remain in full compliance. ++ ++ 5. You are not required to accept this License, since you have not ++signed it. However, nothing else grants you permission to modify or ++distribute the Program or its derivative works. These actions are ++prohibited by law if you do not accept this License. Therefore, by ++modifying or distributing the Program (or any work based on the ++Program), you indicate your acceptance of this License to do so, and ++all its terms and conditions for copying, distributing or modifying ++the Program or works based on it. ++ ++ 6. Each time you redistribute the Program (or any work based on the ++Program), the recipient automatically receives a license from the ++original licensor to copy, distribute or modify the Program subject to ++these terms and conditions. You may not impose any further ++restrictions on the recipients' exercise of the rights granted herein. ++You are not responsible for enforcing compliance by third parties to + this License. + +- Each contributor grants you a non-exclusive, worldwide, royalty-free +-patent license under the contributor's essential patent claims, to +-make, use, sell, offer for sale, import and otherwise run, modify and +-propagate the contents of its contributor version. +- +- In the following three paragraphs, a "patent license" is any express +-agreement or commitment, however denominated, not to enforce a patent +-(such as an express permission to practice a patent or covenant not to +-sue for patent infringement). To "grant" such a patent license to a +-party means to make such an agreement or commitment not to enforce a +-patent against the party. +- +- If you convey a covered work, knowingly relying on a patent license, +-and the Corresponding Source of the work is not available for anyone +-to copy, free of charge and under the terms of this License, through a +-publicly available network server or other readily accessible means, +-then you must either (1) cause the Corresponding Source to be so +-available, or (2) arrange to deprive yourself of the benefit of the +-patent license for this particular work, or (3) arrange, in a manner +-consistent with the requirements of this License, to extend the patent +-license to downstream recipients. "Knowingly relying" means you have +-actual knowledge that, but for the patent license, your conveying the +-covered work in a country, or your recipient's use of the covered work +-in a country, would infringe one or more identifiable patents in that +-country that you have reason to believe are valid. +- +- If, pursuant to or in connection with a single transaction or +-arrangement, you convey, or propagate by procuring conveyance of, a +-covered work, and grant a patent license to some of the parties +-receiving the covered work authorizing them to use, propagate, modify +-or convey a specific copy of the covered work, then the patent license +-you grant is automatically extended to all recipients of the covered +-work and works based on it. +- +- A patent license is "discriminatory" if it does not include within +-the scope of its coverage, prohibits the exercise of, or is +-conditioned on the non-exercise of one or more of the rights that are +-specifically granted under this License. You may not convey a covered +-work if you are a party to an arrangement with a third party that is +-in the business of distributing software, under which you make payment +-to the third party based on the extent of your activity of conveying +-the work, and under which the third party grants, to any of the +-parties who would receive the covered work from you, a discriminatory +-patent license (a) in connection with copies of the covered work +-conveyed by you (or copies made from those copies), or (b) primarily +-for and in connection with specific products or compilations that +-contain the covered work, unless you entered into that arrangement, +-or that patent license was granted, prior to 28 March 2007. +- +- Nothing in this License shall be construed as excluding or limiting +-any implied license or other defenses to infringement that may +-otherwise be available to you under applicable patent law. +- +- 12. No Surrender of Others' Freedom. +- +- If conditions are imposed on you (whether by court order, agreement or ++ 7. If, as a consequence of a court judgment or allegation of patent ++infringement or for any other reason (not limited to patent issues), ++conditions are imposed on you (whether by court order, agreement or + otherwise) that contradict the conditions of this License, they do not +-excuse you from the conditions of this License. If you cannot convey a +-covered work so as to satisfy simultaneously your obligations under this +-License and any other pertinent obligations, then as a consequence you may +-not convey it at all. For example, if you agree to terms that obligate you +-to collect a royalty for further conveying from those to whom you convey +-the Program, the only way you could satisfy both those terms and this +-License would be to refrain entirely from conveying the Program. ++excuse you from the conditions of this License. If you cannot ++distribute so as to satisfy simultaneously your obligations under this ++License and any other pertinent obligations, then as a consequence you ++may not distribute the Program at all. For example, if a patent ++license would not permit royalty-free redistribution of the Program by ++all those who receive copies directly or indirectly through you, then ++the only way you could satisfy both it and this License would be to ++refrain entirely from distribution of the Program. + +- 13. Use with the GNU Affero General Public License. ++If any portion of this section is held invalid or unenforceable under ++any particular circumstance, the balance of the section is intended to ++apply and the section as a whole is intended to apply in other ++circumstances. + +- Notwithstanding any other provision of this License, you have +-permission to link or combine any covered work with a work licensed +-under version 3 of the GNU Affero General Public License into a single +-combined work, and to convey the resulting work. The terms of this +-License will continue to apply to the part which is the covered work, +-but the special requirements of the GNU Affero General Public License, +-section 13, concerning interaction through a network will apply to the +-combination as such. ++It is not the purpose of this section to induce you to infringe any ++patents or other property right claims or to contest validity of any ++such claims; this section has the sole purpose of protecting the ++integrity of the free software distribution system, which is ++implemented by public license practices. Many people have made ++generous contributions to the wide range of software distributed ++through that system in reliance on consistent application of that ++system; it is up to the author/donor to decide if he or she is willing ++to distribute software through any other system and a licensee cannot ++impose that choice. + +- 14. Revised Versions of this License. ++This section is intended to make thoroughly clear what is believed to ++be a consequence of the rest of this License. + +- The Free Software Foundation may publish revised and/or new versions of +-the GNU General Public License from time to time. Such new versions will ++ 8. If the distribution and/or use of the Program is restricted in ++certain countries either by patents or by copyrighted interfaces, the ++original copyright holder who places the Program under this License ++may add an explicit geographical distribution limitation excluding ++those countries, so that distribution is permitted only in or among ++countries not thus excluded. In such case, this License incorporates ++the limitation as if written in the body of this License. ++ ++ 9. The Free Software Foundation may publish revised and/or new versions ++of the General Public License from time to time. Such new versions will + be similar in spirit to the present version, but may differ in detail to + address new problems or concerns. + +- Each version is given a distinguishing version number. If the +-Program specifies that a certain numbered version of the GNU General +-Public License "or any later version" applies to it, you have the +-option of following the terms and conditions either of that numbered +-version or of any later version published by the Free Software +-Foundation. If the Program does not specify a version number of the +-GNU General Public License, you may choose any version ever published +-by the Free Software Foundation. ++Each version is given a distinguishing version number. If the Program ++specifies a version number of this License which applies to it and "any ++later version", you have the option of following the terms and conditions ++either of that version or of any later version published by the Free ++Software Foundation. If the Program does not specify a version number of ++this License, you may choose any version ever published by the Free Software ++Foundation. + +- If the Program specifies that a proxy can decide which future +-versions of the GNU General Public License can be used, that proxy's +-public statement of acceptance of a version permanently authorizes you +-to choose that version for the Program. ++ 10. If you wish to incorporate parts of the Program into other free ++programs whose distribution conditions are different, write to the author ++to ask for permission. For software which is copyrighted by the Free ++Software Foundation, write to the Free Software Foundation; we sometimes ++make exceptions for this. Our decision will be guided by the two goals ++of preserving the free status of all derivatives of our free software and ++of promoting the sharing and reuse of software generally. + +- Later license versions may give you additional or different +-permissions. However, no additional obligations are imposed on any +-author or copyright holder as a result of your choosing to follow a +-later version. ++ NO WARRANTY + +- 15. Disclaimer of Warranty. ++ 11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY ++FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN ++OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES ++PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED ++OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF ++MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS ++TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE ++PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, ++REPAIR OR CORRECTION. + +- THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY +-APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT +-HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY +-OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, +-THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR +-PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM +-IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF +-ALL NECESSARY SERVICING, REPAIR OR CORRECTION. ++ 12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING ++WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR ++REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, ++INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING ++OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED ++TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY ++YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER ++PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE ++POSSIBILITY OF SUCH DAMAGES. + +- 16. Limitation of Liability. ++ END OF TERMS AND CONDITIONS + +- IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING +-WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS +-THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY +-GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE +-USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF +-DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD +-PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), +-EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF +-SUCH DAMAGES. +- +- 17. Interpretation of Sections 15 and 16. +- +- If the disclaimer of warranty and limitation of liability provided +-above cannot be given local legal effect according to their terms, +-reviewing courts shall apply local law that most closely approximates +-an absolute waiver of all civil liability in connection with the +-Program, unless a warranty or assumption of liability accompanies a +-copy of the Program in return for a fee. +- +- END OF TERMS AND CONDITIONS +- +- How to Apply These Terms to Your New Programs ++ How to Apply These Terms to Your New Programs + + If you develop a new program, and you want it to be of the greatest + possible use to the public, the best way to achieve this is to make it +@@ -629,15 +287,15 @@ free software which everyone can redistribute and change under these terms. + + To do so, attach the following notices to the program. It is safest + to attach them to the start of each source file to most effectively +-state the exclusion of warranty; and each file should have at least ++convey the exclusion of warranty; and each file should have at least + the "copyright" line and a pointer to where the full notice is found. + + + Copyright (C) + +- This program is free software: you can redistribute it and/or modify ++ This program is free software; you can redistribute it and/or modify + it under the terms of the GNU General Public License as published by +- the Free Software Foundation, either version 3 of the License, or ++ the Free Software Foundation; either version 2 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, +@@ -645,32 +303,37 @@ the "copyright" line and a pointer to where the full notice is found. + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU General Public License for more details. + +- You should have received a copy of the GNU General Public License +- along with this program. If not, see . ++ You should have received a copy of the GNU General Public License along ++ with this program; if not, write to the Free Software Foundation, Inc., ++ 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. + + Also add information on how to contact you by electronic and paper mail. + +- If the program does terminal interaction, make it output a short +-notice like this when it starts in an interactive mode: ++If the program is interactive, make it output a short notice like this ++when it starts in an interactive mode: + +- Copyright (C) +- This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'. ++ Gnomovision version 69, Copyright (C) year name of author ++ Gnomovision comes with ABSOLUTELY NO WARRANTY; for details type `show w'. + This is free software, and you are welcome to redistribute it + under certain conditions; type `show c' for details. + + The hypothetical commands `show w' and `show c' should show the appropriate +-parts of the General Public License. Of course, your program's commands +-might be different; for a GUI interface, you would use an "about box". ++parts of the General Public License. Of course, the commands you use may ++be called something other than `show w' and `show c'; they could even be ++mouse-clicks or menu items--whatever suits your program. + +- You should also get your employer (if you work as a programmer) or school, +-if any, to sign a "copyright disclaimer" for the program, if necessary. +-For more information on this, and how to apply and follow the GNU GPL, see +-. ++You should also get your employer (if you work as a programmer) or your ++school, if any, to sign a "copyright disclaimer" for the program, if ++necessary. Here is a sample; alter the names: + +- The GNU General Public License does not permit incorporating your program +-into proprietary programs. If your program is a subroutine library, you +-may consider it more useful to permit linking proprietary applications with +-the library. If this is what you want to do, use the GNU Lesser General +-Public License instead of this License. But first, please read +-. ++ Yoyodyne, Inc., hereby disclaims all copyright interest in the program ++ `Gnomovision' (which makes passes at compilers) written by James Hacker. + ++ , 1 April 1989 ++ Ty Coon, President of Vice ++ ++This General Public License does not permit incorporating your program into ++proprietary programs. If your program is a subroutine library, you may ++consider it more useful to permit linking proprietary applications with the ++library. If this is what you want to do, use the GNU Lesser General ++Public License instead of this License. +-- +2.34.1 + diff --git a/0001-Fix-format-strings-for-32-bit-arches.patch b/0002-Fix-format-strings-for-32-bit-arches.patch similarity index 97% rename from 0001-Fix-format-strings-for-32-bit-arches.patch rename to 0002-Fix-format-strings-for-32-bit-arches.patch index 2b71a0e..3a5ece2 100644 --- a/0001-Fix-format-strings-for-32-bit-arches.patch +++ b/0002-Fix-format-strings-for-32-bit-arches.patch @@ -1,7 +1,7 @@ -From 1f8d0985d59ed41e291398f937d32493898bd711 Mon Sep 17 00:00:00 2001 +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 1 Feb 2022 17:37:14 -0500 -Subject: [PATCH] Fix format strings for 32-bit arches +Subject: [PATCH 2/3] Fix format strings for 32-bit arches Sadly, in 2022, this remains a thing. diff --git a/0003-macros-drop-_pesign_args.patch b/0003-macros-drop-_pesign_args.patch new file mode 100644 index 0000000..0511bfa --- /dev/null +++ b/0003-macros-drop-_pesign_args.patch @@ -0,0 +1,47 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 2 Feb 2022 16:07:46 -0500 +Subject: [PATCH 3/3] macros: drop %{_pesign_args} + +Effectively reverts 30b488682a92c524bb9c0d450c34e9abc0b56de9 + +Also, make our argument parser fail on extra arguments to make it easier +to debug when this kind of thing happens again. + +Signed-off-by: Robbie Harwood +--- + src/macros.pesign | 1 - + src/pesign-rpmbuild-helper.in | 5 +++++ + 2 files changed, 5 insertions(+), 1 deletion(-) + +diff --git a/src/macros.pesign b/src/macros.pesign +index 519a8a3..34af57c 100644 +--- a/src/macros.pesign ++++ b/src/macros.pesign +@@ -27,7 +27,6 @@ + %{_libexecdir}/pesign/pesign-rpmbuild-helper \\\ + "%{_target_cpu}" \\\ + "%{_pesign}" \\\ +- "%{_pesign_args}" \\\ + "%{_pesign_client}" \\\ + %{?__pesign_client_token:--client-token %{__pesign_client_token}} \\\ + %{?__pesign_client_cert:--client-cert %{__pesign_client_cert}} \\\ +diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in +index 27b8261..0a845d2 100644 +--- a/src/pesign-rpmbuild-helper.in ++++ b/src/pesign-rpmbuild-helper.in +@@ -133,6 +133,11 @@ main() { + sign=-s + shift + fi ++ if [[ $# -ge 1 ]] ; then ++ echo "$# extra unparsed arguments!">>/dev/stderr ++ echo "Cowardly refusing to run">>/dev/stderr ++ exit 1 ++ fi + + if [[ -z "${target_cpu}" ]] ; then + target_cpu="$(uname -m)" +-- +2.34.1 + diff --git a/pesign.spec b/pesign.spec index a42dddf..3282110 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 114 -Release: 1%{?dist} +Release: 2%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -44,7 +44,9 @@ Source0: https://github.com/rhboot/pesign/releases/download/%{version}/pesign-%{ Source1: certs.tar.xz Source2: pesign.py -Patch0001: 0001-Fix-format-strings-for-32-bit-arches.patch +Patch0001: 0001-Revert-Move-license-to-GPLv3.patch +Patch0002: 0002-Fix-format-strings-for-32-bit-arches.patch +Patch0003: 0003-macros-drop-_pesign_args.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -156,6 +158,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Wed Feb 02 2022 Robbie Harwood - 114-2 +- Attempt to fix signing parsing by dropping pesign_args + * Tue Feb 01 2022 Robbie Harwood - 114-1 - New upstream version (114) From eb423047cd0f8267a17756af3b1cfe7eed09974c Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 9 Feb 2022 14:35:36 -0500 Subject: [PATCH 07/32] Bump efivar minimum version for clarity Signed-off-by: Robbie Harwood --- pesign.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index 3282110..33f6f80 100644 --- a/pesign.spec +++ b/pesign.spec @@ -8,7 +8,7 @@ License: GPL-2.0-only URL: https://github.com/rhboot/pesign Obsoletes: pesign-rh-test-certs <= 0.111-7 -BuildRequires: efivar-devel >= 31-1 +BuildRequires: efivar-devel >= 38-1 BuildRequires: gcc BuildRequires: git BuildRequires: libuuid-devel From 840c1cffff634fea64c4497986a720903ff503fb Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Feb 2022 21:10:49 +0000 Subject: [PATCH 08/32] Fix explicit NULL deref when daemonizing Signed-off-by: Robbie Harwood --- 0001-Revert-Move-license-to-GPLv3.patch | 4 +- ...Fix-format-strings-for-32-bit-arches.patch | 4 +- 0003-macros-drop-_pesign_args.patch | 4 +- ...andle-NULL-pwdata-in-cms_set_pw_data.patch | 55 +++++++++++++++++++ 0005-fcf-protection-is-arch-specific.patch | 46 ++++++++++++++++ pesign.spec | 7 ++- 6 files changed, 113 insertions(+), 7 deletions(-) create mode 100644 0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch create mode 100644 0005-fcf-protection-is-arch-specific.patch diff --git a/0001-Revert-Move-license-to-GPLv3.patch b/0001-Revert-Move-license-to-GPLv3.patch index 4b8931c..4e4bec5 100644 --- a/0001-Revert-Move-license-to-GPLv3.patch +++ b/0001-Revert-Move-license-to-GPLv3.patch @@ -1,7 +1,7 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From fc20530a0ef666b49e6276c983d2d16517d3839b Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Tue, 1 Feb 2022 15:04:30 -0500 -Subject: [PATCH 1/3] Revert "Move license to GPLv3+" +Subject: [PATCH 1/5] Revert "Move license to GPLv3+" This was done too soon. It's missing some pieces and we need buy-in on a couple of source files. diff --git a/0002-Fix-format-strings-for-32-bit-arches.patch b/0002-Fix-format-strings-for-32-bit-arches.patch index 3a5ece2..1aaab2d 100644 --- a/0002-Fix-format-strings-for-32-bit-arches.patch +++ b/0002-Fix-format-strings-for-32-bit-arches.patch @@ -1,7 +1,7 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From df8783ed4ed87fef850268098690985049916ee9 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 1 Feb 2022 17:37:14 -0500 -Subject: [PATCH 2/3] Fix format strings for 32-bit arches +Subject: [PATCH 2/5] Fix format strings for 32-bit arches Sadly, in 2022, this remains a thing. diff --git a/0003-macros-drop-_pesign_args.patch b/0003-macros-drop-_pesign_args.patch index 0511bfa..40a7bf5 100644 --- a/0003-macros-drop-_pesign_args.patch +++ b/0003-macros-drop-_pesign_args.patch @@ -1,7 +1,7 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From 389decab7b9bcba307e52709b00741a19405f02b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 2 Feb 2022 16:07:46 -0500 -Subject: [PATCH 3/3] macros: drop %{_pesign_args} +Subject: [PATCH 3/5] macros: drop %{_pesign_args} Effectively reverts 30b488682a92c524bb9c0d450c34e9abc0b56de9 diff --git a/0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch b/0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch new file mode 100644 index 0000000..f36d1e0 --- /dev/null +++ b/0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch @@ -0,0 +1,55 @@ +From 4d1ead068248b56ecaeb437f0c0b59f9d89b9748 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 14 Feb 2022 15:46:25 -0500 +Subject: [PATCH 4/5] Handle NULL pwdata in cms_set_pw_data() + +When 12f16710ee44ef64ddb044a3523c3c4c4d90039a rewrote this function, it +didn't handle the NULL pwdata invocation from daemon.c. This leads to a +explicit NULL dereference and crash on all attempts to daemonize pesign. + +Signed-off-by: Robbie Harwood +(cherry picked from commit b879dda52f8122de697d145977c285fb0a022d76) +--- + src/cms_common.c | 18 ++++++++++++------ + 1 file changed, 12 insertions(+), 6 deletions(-) + +diff --git a/src/cms_common.c b/src/cms_common.c +index 332999e..ca37e6a 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -313,7 +313,7 @@ void cms_set_pw_data(cms_context *cms, secuPWData *pwdata) + + case PW_FROMFD: + if (cms->pwdata.intdata >= 0 && +- !(pwdata->source == PW_FROMFD && ++ !(pwdata && pwdata->source == PW_FROMFD && + cms->pwdata.intdata == pwdata->intdata)) + close(cms->pwdata.intdata); + break; +@@ -330,12 +330,18 @@ void cms_set_pw_data(cms_context *cms, secuPWData *pwdata) + xfree(cms->pwdata.data); + break; + } +- memmove(&cms->pwdata, pwdata, sizeof(*pwdata)); + +- dprintf("pwdata:%p", pwdata); +- dprintf("pwdata->source:%d", pwdata->source); +- dprintf("pwdata->data:%p (\"%s\")", pwdata->data, +- pwdata->data ? pwdata->data : "(null)"); ++ if (!pwdata) { ++ cms->pwdata.source = PW_SOURCE_INVALID; ++ dprintf("pwdata:NULL"); ++ } else { ++ memmove(&cms->pwdata, pwdata, sizeof(*pwdata)); ++ dprintf("pwdata:%p", pwdata); ++ dprintf("pwdata->source:%d", pwdata->source); ++ dprintf("pwdata->data:%p (\"%s\")", pwdata->data, ++ pwdata->data ? pwdata->data : "(null)"); ++ } ++ + egress(); + } + +-- +2.34.1 + diff --git a/0005-fcf-protection-is-arch-specific.patch b/0005-fcf-protection-is-arch-specific.patch new file mode 100644 index 0000000..84093bf --- /dev/null +++ b/0005-fcf-protection-is-arch-specific.patch @@ -0,0 +1,46 @@ +From f03c5fbe6b4327b9ecd781bfdf64147e1b68e6c1 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Wed, 9 Feb 2022 15:23:27 -0500 +Subject: [PATCH 5/5] -fcf-protection is arch-specific + +Signed-off-by: Robbie Harwood +(cherry picked from commit c48df510144de3b1187001bc3b5491509da1c58f) +--- + Make.defaults | 10 ++++++---- + 1 file changed, 6 insertions(+), 4 deletions(-) + +diff --git a/Make.defaults b/Make.defaults +index fdb961a..130c1ee 100644 +--- a/Make.defaults ++++ b/Make.defaults +@@ -22,11 +22,16 @@ EFI_ARCHES ?= aa64 ia32 x64 + + enabled = $(if $(filter undefined,$(origin $(1))),$(3),$(2)) + ++HOSTARCH = $(shell uname -m | sed s,i[3456789]86,ia32,) ++ARCH := $(shell uname -m | sed s,i[3456789]86,ia32,) ++ ++ + PKG_CONFIG ?= $(CROSS_COMPILE)pkg-config + CC := $(if $(filter default,$(origin CC)),$(CROSS_COMPILE)gcc,$(CC)) + CCLD := $(if $(filter undefined,$(origin CCLD)),$(CC),$(CCLD)) + CFLAGS ?= -O2 -g3 -pipe -fPIE -fstack-protector-all \ +- -fstack-clash-protection -fcf-protection=full ++ -fstack-clash-protection \ ++ $(if $(filter x86_64 ia32,$(ARCH)),-fcf-protection=full,) + DIAGFLAGS ?= -fmessage-length=0 \ + -fdiagnostics-color=always \ + -fdiagnostics-format=text \ +@@ -42,9 +47,6 @@ INSTALL ?= $(CROSS_COMPILE)install + + PKGS = efivar nspr nss nss-util uuid + +-HOSTARCH = $(shell uname -m | sed s,i[3456789]86,ia32,) +-ARCH := $(shell uname -m | sed s,i[3456789]86,ia32,) +- + SOFLAGS ?= -shared + clang_cflags = + gcc_cflags = -Wmaybe-uninitialized -grecord-gcc-switches \ +-- +2.34.1 + diff --git a/pesign.spec b/pesign.spec index 33f6f80..4905201 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 114 -Release: 2%{?dist} +Release: 3%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -47,6 +47,8 @@ Source2: pesign.py Patch0001: 0001-Revert-Move-license-to-GPLv3.patch Patch0002: 0002-Fix-format-strings-for-32-bit-arches.patch Patch0003: 0003-macros-drop-_pesign_args.patch +Patch0004: 0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch +Patch0005: 0005-fcf-protection-is-arch-specific.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -158,6 +160,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Mon Feb 14 2022 Robbie Harwood - 114-3 +- Fix explicit NULL deref when daemonizing + * Wed Feb 02 2022 Robbie Harwood - 114-2 - Attempt to fix signing parsing by dropping pesign_args From 2638a1181b39da5df436d33ac17799ab62f4368f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Feb 2022 22:29:12 +0000 Subject: [PATCH 09/32] Disable -fanalyzer since it's broken and pragmas don't work See-also: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=104370 Signed-off-by: Robbie Harwood --- 0006-Disable-analyzer-until-it-works.patch | 26 ++++++++++++++++++++++ pesign.spec | 6 ++++- 2 files changed, 31 insertions(+), 1 deletion(-) create mode 100644 0006-Disable-analyzer-until-it-works.patch diff --git a/0006-Disable-analyzer-until-it-works.patch b/0006-Disable-analyzer-until-it-works.patch new file mode 100644 index 0000000..4ed8cbf --- /dev/null +++ b/0006-Disable-analyzer-until-it-works.patch @@ -0,0 +1,26 @@ +From 288b05dcd5a3b48836c4904e38b14e38a0cdfa07 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 14 Feb 2022 17:26:19 -0500 +Subject: [PATCH] Disable analyzer until it works + +See-also: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=104370 +Signed-off-by: Robbie Harwood +--- + Make.defaults | 1 - + 1 file changed, 1 deletion(-) + +diff --git a/Make.defaults b/Make.defaults +index 130c1ee..5e56a76 100644 +--- a/Make.defaults ++++ b/Make.defaults +@@ -36,7 +36,6 @@ DIAGFLAGS ?= -fmessage-length=0 \ + -fdiagnostics-color=always \ + -fdiagnostics-format=text \ + -fdiagnostics-show-cwe \ +- -fanalyzer \ + $(call enabled,ENABLE_LEAK_CHECKER,-Wno-analyzer-malloc-leak,) + AS ?= $(CROSS_COMPILE)as + AR ?= $(CROSS_COMPILE)$(if $(filter $(CC),clang),llvm-ar,$(notdir $(CC))-ar) +-- +2.34.1 + diff --git a/pesign.spec b/pesign.spec index 4905201..583c18b 100644 --- a/pesign.spec +++ b/pesign.spec @@ -3,7 +3,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 114 -Release: 3%{?dist} +Release: 4%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -160,6 +160,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Mon Feb 14 2022 Robbie Harwood - 114-4 +- Disable -fanalyzer since it's broken and pragmas don't work +- See-also: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=104370 + * Mon Feb 14 2022 Robbie Harwood - 114-3 - Fix explicit NULL deref when daemonizing From 57b330e9051da6dfb54bc60c512cd7d98adc52f3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 14 Feb 2022 22:44:36 +0000 Subject: [PATCH 10/32] Disable distro build flags No. Signed-off-by: Robbie Harwood --- pesign.spec | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pesign.spec b/pesign.spec index 583c18b..d534229 100644 --- a/pesign.spec +++ b/pesign.spec @@ -1,5 +1,8 @@ %global macrosdir %(d=%{_rpmconfigdir}/macros.d; [ -d $d ] || d=%{_sysconfdir}/rpm; echo $d) +# No. I have enough trouble already. +%undefine _auto_set_build_flags + Name: pesign Summary: Signing utility for UEFI binaries Version: 114 From bdccb8412c5020d7e3ca4c3ad598d7dcfcce8bea Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 8 Mar 2022 17:54:45 +0000 Subject: [PATCH 11/32] New upstream version (115) Signed-off-by: Robbie Harwood --- 0001-Revert-Move-license-to-GPLv3.patch | 969 ------------------ ...daemon-remove-always-true-comparison.patch | 24 + ...Fix-format-strings-for-32-bit-arches.patch | 112 -- 0003-macros-drop-_pesign_args.patch | 47 - ...andle-NULL-pwdata-in-cms_set_pw_data.patch | 55 - 0005-fcf-protection-is-arch-specific.patch | 46 - 0006-Disable-analyzer-until-it-works.patch | 26 - pesign.spec | 13 +- sources | 2 +- 9 files changed, 31 insertions(+), 1263 deletions(-) delete mode 100644 0001-Revert-Move-license-to-GPLv3.patch create mode 100644 0001-daemon-remove-always-true-comparison.patch delete mode 100644 0002-Fix-format-strings-for-32-bit-arches.patch delete mode 100644 0003-macros-drop-_pesign_args.patch delete mode 100644 0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch delete mode 100644 0005-fcf-protection-is-arch-specific.patch delete mode 100644 0006-Disable-analyzer-until-it-works.patch diff --git a/0001-Revert-Move-license-to-GPLv3.patch b/0001-Revert-Move-license-to-GPLv3.patch deleted file mode 100644 index 4e4bec5..0000000 --- a/0001-Revert-Move-license-to-GPLv3.patch +++ /dev/null @@ -1,969 +0,0 @@ -From fc20530a0ef666b49e6276c983d2d16517d3839b Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 1 Feb 2022 15:04:30 -0500 -Subject: [PATCH 1/5] Revert "Move license to GPLv3+" - -This was done too soon. It's missing some pieces and we need buy-in on -a couple of source files. - -This reverts commit 735650258c7956525b7ecf4b67483d025f0500e8. ---- - COPYING | 881 +++++++++++++++++--------------------------------------- - 1 file changed, 272 insertions(+), 609 deletions(-) - -diff --git a/COPYING b/COPYING -index 4432540..d159169 100644 ---- a/COPYING -+++ b/COPYING -@@ -1,627 +1,285 @@ -+ GNU GENERAL PUBLIC LICENSE -+ Version 2, June 1991 - -- GNU GENERAL PUBLIC LICENSE -- Version 3, 29 June 2007 -- -- Copyright (C) 2007 Free Software Foundation, Inc. -+ Copyright (C) 1989, 1991 Free Software Foundation, Inc., -+ 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA - Everyone is permitted to copy and distribute verbatim copies - of this license document, but changing it is not allowed. - -- Preamble -+ Preamble - -- The GNU General Public License is a free, copyleft license for --software and other kinds of works. -- -- The licenses for most software and other practical works are designed --to take away your freedom to share and change the works. By contrast, --the GNU General Public License is intended to guarantee your freedom to --share and change all versions of a program--to make sure it remains free --software for all its users. We, the Free Software Foundation, use the --GNU General Public License for most of our software; it applies also to --any other work released this way by its authors. You can apply it to -+ The licenses for most software are designed to take away your -+freedom to share and change it. By contrast, the GNU General Public -+License is intended to guarantee your freedom to share and change free -+software--to make sure the software is free for all its users. This -+General Public License applies to most of the Free Software -+Foundation's software and to any other program whose authors commit to -+using it. (Some other Free Software Foundation software is covered by -+the GNU Lesser General Public License instead.) You can apply it to - your programs, too. - - When we speak of free software, we are referring to freedom, not - price. Our General Public Licenses are designed to make sure that you - have the freedom to distribute copies of free software (and charge for --them if you wish), that you receive source code or can get it if you --want it, that you can change the software or use pieces of it in new --free programs, and that you know you can do these things. -+this service if you wish), that you receive source code or can get it -+if you want it, that you can change the software or use pieces of it -+in new free programs; and that you know you can do these things. - -- To protect your rights, we need to prevent others from denying you --these rights or asking you to surrender the rights. Therefore, you have --certain responsibilities if you distribute copies of the software, or if --you modify it: responsibilities to respect the freedom of others. -+ To protect your rights, we need to make restrictions that forbid -+anyone to deny you these rights or to ask you to surrender the rights. -+These restrictions translate to certain responsibilities for you if you -+distribute copies of the software, or if you modify it. - - For example, if you distribute copies of such a program, whether --gratis or for a fee, you must pass on to the recipients the same --freedoms that you received. You must make sure that they, too, receive --or can get the source code. And you must show them these terms so they --know their rights. -+gratis or for a fee, you must give the recipients all the rights that -+you have. You must make sure that they, too, receive or can get the -+source code. And you must show them these terms so they know their -+rights. - -- Developers that use the GNU GPL protect your rights with two steps: --(1) assert copyright on the software, and (2) offer you this License --giving you legal permission to copy, distribute and/or modify it. -+ We protect your rights with two steps: (1) copyright the software, and -+(2) offer you this license which gives you legal permission to copy, -+distribute and/or modify the software. - -- For the developers' and authors' protection, the GPL clearly explains --that there is no warranty for this free software. For both users' and --authors' sake, the GPL requires that modified versions be marked as --changed, so that their problems will not be attributed erroneously to --authors of previous versions. -+ Also, for each author's protection and ours, we want to make certain -+that everyone understands that there is no warranty for this free -+software. If the software is modified by someone else and passed on, we -+want its recipients to know that what they have is not the original, so -+that any problems introduced by others will not reflect on the original -+authors' reputations. - -- Some devices are designed to deny users access to install or run --modified versions of the software inside them, although the manufacturer --can do so. This is fundamentally incompatible with the aim of --protecting users' freedom to change the software. The systematic --pattern of such abuse occurs in the area of products for individuals to --use, which is precisely where it is most unacceptable. Therefore, we --have designed this version of the GPL to prohibit the practice for those --products. If such problems arise substantially in other domains, we --stand ready to extend this provision to those domains in future versions --of the GPL, as needed to protect the freedom of users. -- -- Finally, every program is threatened constantly by software patents. --States should not allow patents to restrict development and use of --software on general-purpose computers, but in those that do, we wish to --avoid the special danger that patents applied to a free program could --make it effectively proprietary. To prevent this, the GPL assures that --patents cannot be used to render the program non-free. -+ Finally, any free program is threatened constantly by software -+patents. We wish to avoid the danger that redistributors of a free -+program will individually obtain patent licenses, in effect making the -+program proprietary. To prevent this, we have made it clear that any -+patent must be licensed for everyone's free use or not licensed at all. - - The precise terms and conditions for copying, distribution and - modification follow. - -- TERMS AND CONDITIONS -- -- 0. Definitions. -- -- "This License" refers to version 3 of the GNU General Public License. -- -- "Copyright" also means copyright-like laws that apply to other kinds of --works, such as semiconductor masks. -- -- "The Program" refers to any copyrightable work licensed under this --License. Each licensee is addressed as "you". "Licensees" and --"recipients" may be individuals or organizations. -- -- To "modify" a work means to copy from or adapt all or part of the work --in a fashion requiring copyright permission, other than the making of an --exact copy. The resulting work is called a "modified version" of the --earlier work or a work "based on" the earlier work. -- -- A "covered work" means either the unmodified Program or a work based --on the Program. -- -- To "propagate" a work means to do anything with it that, without --permission, would make you directly or secondarily liable for --infringement under applicable copyright law, except executing it on a --computer or modifying a private copy. Propagation includes copying, --distribution (with or without modification), making available to the --public, and in some countries other activities as well. -- -- To "convey" a work means any kind of propagation that enables other --parties to make or receive copies. Mere interaction with a user through --a computer network, with no transfer of a copy, is not conveying. -- -- An interactive user interface displays "Appropriate Legal Notices" --to the extent that it includes a convenient and prominently visible --feature that (1) displays an appropriate copyright notice, and (2) --tells the user that there is no warranty for the work (except to the --extent that warranties are provided), that licensees may convey the --work under this License, and how to view a copy of this License. If --the interface presents a list of user commands or options, such as a --menu, a prominent item in the list meets this criterion. -- -- 1. Source Code. -- -- The "source code" for a work means the preferred form of the work --for making modifications to it. "Object code" means any non-source --form of a work. -- -- A "Standard Interface" means an interface that either is an official --standard defined by a recognized standards body, or, in the case of --interfaces specified for a particular programming language, one that --is widely used among developers working in that language. -- -- The "System Libraries" of an executable work include anything, other --than the work as a whole, that (a) is included in the normal form of --packaging a Major Component, but which is not part of that Major --Component, and (b) serves only to enable use of the work with that --Major Component, or to implement a Standard Interface for which an --implementation is available to the public in source code form. A --"Major Component", in this context, means a major essential component --(kernel, window system, and so on) of the specific operating system --(if any) on which the executable work runs, or a compiler used to --produce the work, or an object code interpreter used to run it. -- -- The "Corresponding Source" for a work in object code form means all --the source code needed to generate, install, and (for an executable --work) run the object code and to modify the work, including scripts to --control those activities. However, it does not include the work's --System Libraries, or general-purpose tools or generally available free --programs which are used unmodified in performing those activities but --which are not part of the work. For example, Corresponding Source --includes interface definition files associated with source files for --the work, and the source code for shared libraries and dynamically --linked subprograms that the work is specifically designed to require, --such as by intimate data communication or control flow between those --subprograms and other parts of the work. -- -- The Corresponding Source need not include anything that users --can regenerate automatically from other parts of the Corresponding --Source. -- -- The Corresponding Source for a work in source code form is that --same work. -- -- 2. Basic Permissions. -- -- All rights granted under this License are granted for the term of --copyright on the Program, and are irrevocable provided the stated --conditions are met. This License explicitly affirms your unlimited --permission to run the unmodified Program. The output from running a --covered work is covered by this License only if the output, given its --content, constitutes a covered work. This License acknowledges your --rights of fair use or other equivalent, as provided by copyright law. -- -- You may make, run and propagate covered works that you do not --convey, without conditions so long as your license otherwise remains --in force. You may convey covered works to others for the sole purpose --of having them make modifications exclusively for you, or provide you --with facilities for running those works, provided that you comply with --the terms of this License in conveying all material for which you do --not control copyright. Those thus making or running the covered works --for you must do so exclusively on your behalf, under your direction --and control, on terms that prohibit them from making any copies of --your copyrighted material outside their relationship with you. -- -- Conveying under any other circumstances is permitted solely under --the conditions stated below. Sublicensing is not allowed; section 10 --makes it unnecessary. -- -- 3. Protecting Users' Legal Rights From Anti-Circumvention Law. -- -- No covered work shall be deemed part of an effective technological --measure under any applicable law fulfilling obligations under article --11 of the WIPO copyright treaty adopted on 20 December 1996, or --similar laws prohibiting or restricting circumvention of such --measures. -- -- When you convey a covered work, you waive any legal power to forbid --circumvention of technological measures to the extent such circumvention --is effected by exercising rights under this License with respect to --the covered work, and you disclaim any intention to limit operation or --modification of the work as a means of enforcing, against the work's --users, your or third parties' legal rights to forbid circumvention of --technological measures. -- -- 4. Conveying Verbatim Copies. -- -- You may convey verbatim copies of the Program's source code as you --receive it, in any medium, provided that you conspicuously and --appropriately publish on each copy an appropriate copyright notice; --keep intact all notices stating that this License and any --non-permissive terms added in accord with section 7 apply to the code; --keep intact all notices of the absence of any warranty; and give all --recipients a copy of this License along with the Program. -- -- You may charge any price or no price for each copy that you convey, --and you may offer support or warranty protection for a fee. -- -- 5. Conveying Modified Source Versions. -- -- You may convey a work based on the Program, or the modifications to --produce it from the Program, in the form of source code under the --terms of section 4, provided that you also meet all of these conditions: -- -- a) The work must carry prominent notices stating that you modified -- it, and giving a relevant date. -- -- b) The work must carry prominent notices stating that it is -- released under this License and any conditions added under section -- 7. This requirement modifies the requirement in section 4 to -- "keep intact all notices". -- -- c) You must license the entire work, as a whole, under this -- License to anyone who comes into possession of a copy. This -- License will therefore apply, along with any applicable section 7 -- additional terms, to the whole of the work, and all its parts, -- regardless of how they are packaged. This License gives no -- permission to license the work in any other way, but it does not -- invalidate such permission if you have separately received it. -- -- d) If the work has interactive user interfaces, each must display -- Appropriate Legal Notices; however, if the Program has interactive -- interfaces that do not display Appropriate Legal Notices, your -- work need not make them do so. -- -- A compilation of a covered work with other separate and independent --works, which are not by their nature extensions of the covered work, --and which are not combined with it such as to form a larger program, --in or on a volume of a storage or distribution medium, is called an --"aggregate" if the compilation and its resulting copyright are not --used to limit the access or legal rights of the compilation's users --beyond what the individual works permit. Inclusion of a covered work --in an aggregate does not cause this License to apply to the other --parts of the aggregate. -- -- 6. Conveying Non-Source Forms. -- -- You may convey a covered work in object code form under the terms --of sections 4 and 5, provided that you also convey the --machine-readable Corresponding Source under the terms of this License, --in one of these ways: -- -- a) Convey the object code in, or embodied in, a physical product -- (including a physical distribution medium), accompanied by the -- Corresponding Source fixed on a durable physical medium -- customarily used for software interchange. -- -- b) Convey the object code in, or embodied in, a physical product -- (including a physical distribution medium), accompanied by a -- written offer, valid for at least three years and valid for as -- long as you offer spare parts or customer support for that product -- model, to give anyone who possesses the object code either (1) a -- copy of the Corresponding Source for all the software in the -- product that is covered by this License, on a durable physical -- medium customarily used for software interchange, for a price no -- more than your reasonable cost of physically performing this -- conveying of source, or (2) access to copy the -- Corresponding Source from a network server at no charge. -- -- c) Convey individual copies of the object code with a copy of the -- written offer to provide the Corresponding Source. This -- alternative is allowed only occasionally and noncommercially, and -- only if you received the object code with such an offer, in accord -- with subsection 6b. -- -- d) Convey the object code by offering access from a designated -- place (gratis or for a charge), and offer equivalent access to the -- Corresponding Source in the same way through the same place at no -- further charge. You need not require recipients to copy the -- Corresponding Source along with the object code. If the place to -- copy the object code is a network server, the Corresponding Source -- may be on a different server (operated by you or a third party) -- that supports equivalent copying facilities, provided you maintain -- clear directions next to the object code saying where to find the -- Corresponding Source. Regardless of what server hosts the -- Corresponding Source, you remain obligated to ensure that it is -- available for as long as needed to satisfy these requirements. -- -- e) Convey the object code using peer-to-peer transmission, provided -- you inform other peers where the object code and Corresponding -- Source of the work are being offered to the general public at no -- charge under subsection 6d. -- -- A separable portion of the object code, whose source code is excluded --from the Corresponding Source as a System Library, need not be --included in conveying the object code work. -- -- A "User Product" is either (1) a "consumer product", which means any --tangible personal property which is normally used for personal, family, --or household purposes, or (2) anything designed or sold for incorporation --into a dwelling. In determining whether a product is a consumer product, --doubtful cases shall be resolved in favor of coverage. For a particular --product received by a particular user, "normally used" refers to a --typical or common use of that class of product, regardless of the status --of the particular user or of the way in which the particular user --actually uses, or expects or is expected to use, the product. A product --is a consumer product regardless of whether the product has substantial --commercial, industrial or non-consumer uses, unless such uses represent --the only significant mode of use of the product. -- -- "Installation Information" for a User Product means any methods, --procedures, authorization keys, or other information required to install --and execute modified versions of a covered work in that User Product from --a modified version of its Corresponding Source. The information must --suffice to ensure that the continued functioning of the modified object --code is in no case prevented or interfered with solely because --modification has been made. -- -- If you convey an object code work under this section in, or with, or --specifically for use in, a User Product, and the conveying occurs as --part of a transaction in which the right of possession and use of the --User Product is transferred to the recipient in perpetuity or for a --fixed term (regardless of how the transaction is characterized), the --Corresponding Source conveyed under this section must be accompanied --by the Installation Information. But this requirement does not apply --if neither you nor any third party retains the ability to install --modified object code on the User Product (for example, the work has --been installed in ROM). -- -- The requirement to provide Installation Information does not include a --requirement to continue to provide support service, warranty, or updates --for a work that has been modified or installed by the recipient, or for --the User Product in which it has been modified or installed. Access to a --network may be denied when the modification itself materially and --adversely affects the operation of the network or violates the rules and --protocols for communication across the network. -- -- Corresponding Source conveyed, and Installation Information provided, --in accord with this section must be in a format that is publicly --documented (and with an implementation available to the public in --source code form), and must require no special password or key for --unpacking, reading or copying. -- -- 7. Additional Terms. -- -- "Additional permissions" are terms that supplement the terms of this --License by making exceptions from one or more of its conditions. --Additional permissions that are applicable to the entire Program shall --be treated as though they were included in this License, to the extent --that they are valid under applicable law. If additional permissions --apply only to part of the Program, that part may be used separately --under those permissions, but the entire Program remains governed by --this License without regard to the additional permissions. -- -- When you convey a copy of a covered work, you may at your option --remove any additional permissions from that copy, or from any part of --it. (Additional permissions may be written to require their own --removal in certain cases when you modify the work.) You may place --additional permissions on material, added by you to a covered work, --for which you have or can give appropriate copyright permission. -- -- Notwithstanding any other provision of this License, for material you --add to a covered work, you may (if authorized by the copyright holders of --that material) supplement the terms of this License with terms: -- -- a) Disclaiming warranty or limiting liability differently from the -- terms of sections 15 and 16 of this License; or -- -- b) Requiring preservation of specified reasonable legal notices or -- author attributions in that material or in the Appropriate Legal -- Notices displayed by works containing it; or -- -- c) Prohibiting misrepresentation of the origin of that material, or -- requiring that modified versions of such material be marked in -- reasonable ways as different from the original version; or -- -- d) Limiting the use for publicity purposes of names of licensors or -- authors of the material; or -- -- e) Declining to grant rights under trademark law for use of some -- trade names, trademarks, or service marks; or -- -- f) Requiring indemnification of licensors and authors of that -- material by anyone who conveys the material (or modified versions of -- it) with contractual assumptions of liability to the recipient, for -- any liability that these contractual assumptions directly impose on -- those licensors and authors. -- -- All other non-permissive additional terms are considered "further --restrictions" within the meaning of section 10. If the Program as you --received it, or any part of it, contains a notice stating that it is --governed by this License along with a term that is a further --restriction, you may remove that term. If a license document contains --a further restriction but permits relicensing or conveying under this --License, you may add to a covered work material governed by the terms --of that license document, provided that the further restriction does --not survive such relicensing or conveying. -- -- If you add terms to a covered work in accord with this section, you --must place, in the relevant source files, a statement of the --additional terms that apply to those files, or a notice indicating --where to find the applicable terms. -- -- Additional terms, permissive or non-permissive, may be stated in the --form of a separately written license, or stated as exceptions; --the above requirements apply either way. -- -- 8. Termination. -- -- You may not propagate or modify a covered work except as expressly --provided under this License. Any attempt otherwise to propagate or --modify it is void, and will automatically terminate your rights under --this License (including any patent licenses granted under the third --paragraph of section 11). -- -- However, if you cease all violation of this License, then your --license from a particular copyright holder is reinstated (a) --provisionally, unless and until the copyright holder explicitly and --finally terminates your license, and (b) permanently, if the copyright --holder fails to notify you of the violation by some reasonable means --prior to 60 days after the cessation. -- -- Moreover, your license from a particular copyright holder is --reinstated permanently if the copyright holder notifies you of the --violation by some reasonable means, this is the first time you have --received notice of violation of this License (for any work) from that --copyright holder, and you cure the violation prior to 30 days after --your receipt of the notice. -- -- Termination of your rights under this section does not terminate the --licenses of parties who have received copies or rights from you under --this License. If your rights have been terminated and not permanently --reinstated, you do not qualify to receive new licenses for the same --material under section 10. -- -- 9. Acceptance Not Required for Having Copies. -- -- You are not required to accept this License in order to receive or --run a copy of the Program. Ancillary propagation of a covered work --occurring solely as a consequence of using peer-to-peer transmission --to receive a copy likewise does not require acceptance. However, --nothing other than this License grants you permission to propagate or --modify any covered work. These actions infringe copyright if you do --not accept this License. Therefore, by modifying or propagating a --covered work, you indicate your acceptance of this License to do so. -- -- 10. Automatic Licensing of Downstream Recipients. -- -- Each time you convey a covered work, the recipient automatically --receives a license from the original licensors, to run, modify and --propagate that work, subject to this License. You are not responsible --for enforcing compliance by third parties with this License. -- -- An "entity transaction" is a transaction transferring control of an --organization, or substantially all assets of one, or subdividing an --organization, or merging organizations. If propagation of a covered --work results from an entity transaction, each party to that --transaction who receives a copy of the work also receives whatever --licenses to the work the party's predecessor in interest had or could --give under the previous paragraph, plus a right to possession of the --Corresponding Source of the work from the predecessor in interest, if --the predecessor has it or can get it with reasonable efforts. -- -- You may not impose any further restrictions on the exercise of the --rights granted or affirmed under this License. For example, you may --not impose a license fee, royalty, or other charge for exercise of --rights granted under this License, and you may not initiate litigation --(including a cross-claim or counterclaim in a lawsuit) alleging that --any patent claim is infringed by making, using, selling, offering for --sale, or importing the Program or any portion of it. -- -- 11. Patents. -- -- A "contributor" is a copyright holder who authorizes use under this --License of the Program or a work on which the Program is based. The --work thus licensed is called the contributor's "contributor version". -- -- A contributor's "essential patent claims" are all patent claims --owned or controlled by the contributor, whether already acquired or --hereafter acquired, that would be infringed by some manner, permitted --by this License, of making, using, or selling its contributor version, --but do not include claims that would be infringed only as a --consequence of further modification of the contributor version. For --purposes of this definition, "control" includes the right to grant --patent sublicenses in a manner consistent with the requirements of -+ GNU GENERAL PUBLIC LICENSE -+ TERMS AND CONDITIONS FOR COPYING, DISTRIBUTION AND MODIFICATION -+ -+ 0. This License applies to any program or other work which contains -+a notice placed by the copyright holder saying it may be distributed -+under the terms of this General Public License. The "Program", below, -+refers to any such program or work, and a "work based on the Program" -+means either the Program or any derivative work under copyright law: -+that is to say, a work containing the Program or a portion of it, -+either verbatim or with modifications and/or translated into another -+language. (Hereinafter, translation is included without limitation in -+the term "modification".) Each licensee is addressed as "you". -+ -+Activities other than copying, distribution and modification are not -+covered by this License; they are outside its scope. The act of -+running the Program is not restricted, and the output from the Program -+is covered only if its contents constitute a work based on the -+Program (independent of having been made by running the Program). -+Whether that is true depends on what the Program does. -+ -+ 1. You may copy and distribute verbatim copies of the Program's -+source code as you receive it, in any medium, provided that you -+conspicuously and appropriately publish on each copy an appropriate -+copyright notice and disclaimer of warranty; keep intact all the -+notices that refer to this License and to the absence of any warranty; -+and give any other recipients of the Program a copy of this License -+along with the Program. -+ -+You may charge a fee for the physical act of transferring a copy, and -+you may at your option offer warranty protection in exchange for a fee. -+ -+ 2. You may modify your copy or copies of the Program or any portion -+of it, thus forming a work based on the Program, and copy and -+distribute such modifications or work under the terms of Section 1 -+above, provided that you also meet all of these conditions: -+ -+ a) You must cause the modified files to carry prominent notices -+ stating that you changed the files and the date of any change. -+ -+ b) You must cause any work that you distribute or publish, that in -+ whole or in part contains or is derived from the Program or any -+ part thereof, to be licensed as a whole at no charge to all third -+ parties under the terms of this License. -+ -+ c) If the modified program normally reads commands interactively -+ when run, you must cause it, when started running for such -+ interactive use in the most ordinary way, to print or display an -+ announcement including an appropriate copyright notice and a -+ notice that there is no warranty (or else, saying that you provide -+ a warranty) and that users may redistribute the program under -+ these conditions, and telling the user how to view a copy of this -+ License. (Exception: if the Program itself is interactive but -+ does not normally print such an announcement, your work based on -+ the Program is not required to print an announcement.) -+ -+These requirements apply to the modified work as a whole. If -+identifiable sections of that work are not derived from the Program, -+and can be reasonably considered independent and separate works in -+themselves, then this License, and its terms, do not apply to those -+sections when you distribute them as separate works. But when you -+distribute the same sections as part of a whole which is a work based -+on the Program, the distribution of the whole must be on the terms of -+this License, whose permissions for other licensees extend to the -+entire whole, and thus to each and every part regardless of who wrote it. -+ -+Thus, it is not the intent of this section to claim rights or contest -+your rights to work written entirely by you; rather, the intent is to -+exercise the right to control the distribution of derivative or -+collective works based on the Program. -+ -+In addition, mere aggregation of another work not based on the Program -+with the Program (or with a work based on the Program) on a volume of -+a storage or distribution medium does not bring the other work under -+the scope of this License. -+ -+ 3. You may copy and distribute the Program (or a work based on it, -+under Section 2) in object code or executable form under the terms of -+Sections 1 and 2 above provided that you also do one of the following: -+ -+ a) Accompany it with the complete corresponding machine-readable -+ source code, which must be distributed under the terms of Sections -+ 1 and 2 above on a medium customarily used for software interchange; or, -+ -+ b) Accompany it with a written offer, valid for at least three -+ years, to give any third party, for a charge no more than your -+ cost of physically performing source distribution, a complete -+ machine-readable copy of the corresponding source code, to be -+ distributed under the terms of Sections 1 and 2 above on a medium -+ customarily used for software interchange; or, -+ -+ c) Accompany it with the information you received as to the offer -+ to distribute corresponding source code. (This alternative is -+ allowed only for noncommercial distribution and only if you -+ received the program in object code or executable form with such -+ an offer, in accord with Subsection b above.) -+ -+The source code for a work means the preferred form of the work for -+making modifications to it. For an executable work, complete source -+code means all the source code for all modules it contains, plus any -+associated interface definition files, plus the scripts used to -+control compilation and installation of the executable. However, as a -+special exception, the source code distributed need not include -+anything that is normally distributed (in either source or binary -+form) with the major components (compiler, kernel, and so on) of the -+operating system on which the executable runs, unless that component -+itself accompanies the executable. -+ -+If distribution of executable or object code is made by offering -+access to copy from a designated place, then offering equivalent -+access to copy the source code from the same place counts as -+distribution of the source code, even though third parties are not -+compelled to copy the source along with the object code. -+ -+ 4. You may not copy, modify, sublicense, or distribute the Program -+except as expressly provided under this License. Any attempt -+otherwise to copy, modify, sublicense or distribute the Program is -+void, and will automatically terminate your rights under this License. -+However, parties who have received copies, or rights, from you under -+this License will not have their licenses terminated so long as such -+parties remain in full compliance. -+ -+ 5. You are not required to accept this License, since you have not -+signed it. However, nothing else grants you permission to modify or -+distribute the Program or its derivative works. These actions are -+prohibited by law if you do not accept this License. Therefore, by -+modifying or distributing the Program (or any work based on the -+Program), you indicate your acceptance of this License to do so, and -+all its terms and conditions for copying, distributing or modifying -+the Program or works based on it. -+ -+ 6. Each time you redistribute the Program (or any work based on the -+Program), the recipient automatically receives a license from the -+original licensor to copy, distribute or modify the Program subject to -+these terms and conditions. You may not impose any further -+restrictions on the recipients' exercise of the rights granted herein. -+You are not responsible for enforcing compliance by third parties to - this License. - -- Each contributor grants you a non-exclusive, worldwide, royalty-free --patent license under the contributor's essential patent claims, to --make, use, sell, offer for sale, import and otherwise run, modify and --propagate the contents of its contributor version. -- -- In the following three paragraphs, a "patent license" is any express --agreement or commitment, however denominated, not to enforce a patent --(such as an express permission to practice a patent or covenant not to --sue for patent infringement). To "grant" such a patent license to a --party means to make such an agreement or commitment not to enforce a --patent against the party. -- -- If you convey a covered work, knowingly relying on a patent license, --and the Corresponding Source of the work is not available for anyone --to copy, free of charge and under the terms of this License, through a --publicly available network server or other readily accessible means, --then you must either (1) cause the Corresponding Source to be so --available, or (2) arrange to deprive yourself of the benefit of the --patent license for this particular work, or (3) arrange, in a manner --consistent with the requirements of this License, to extend the patent --license to downstream recipients. "Knowingly relying" means you have --actual knowledge that, but for the patent license, your conveying the --covered work in a country, or your recipient's use of the covered work --in a country, would infringe one or more identifiable patents in that --country that you have reason to believe are valid. -- -- If, pursuant to or in connection with a single transaction or --arrangement, you convey, or propagate by procuring conveyance of, a --covered work, and grant a patent license to some of the parties --receiving the covered work authorizing them to use, propagate, modify --or convey a specific copy of the covered work, then the patent license --you grant is automatically extended to all recipients of the covered --work and works based on it. -- -- A patent license is "discriminatory" if it does not include within --the scope of its coverage, prohibits the exercise of, or is --conditioned on the non-exercise of one or more of the rights that are --specifically granted under this License. You may not convey a covered --work if you are a party to an arrangement with a third party that is --in the business of distributing software, under which you make payment --to the third party based on the extent of your activity of conveying --the work, and under which the third party grants, to any of the --parties who would receive the covered work from you, a discriminatory --patent license (a) in connection with copies of the covered work --conveyed by you (or copies made from those copies), or (b) primarily --for and in connection with specific products or compilations that --contain the covered work, unless you entered into that arrangement, --or that patent license was granted, prior to 28 March 2007. -- -- Nothing in this License shall be construed as excluding or limiting --any implied license or other defenses to infringement that may --otherwise be available to you under applicable patent law. -- -- 12. No Surrender of Others' Freedom. -- -- If conditions are imposed on you (whether by court order, agreement or -+ 7. If, as a consequence of a court judgment or allegation of patent -+infringement or for any other reason (not limited to patent issues), -+conditions are imposed on you (whether by court order, agreement or - otherwise) that contradict the conditions of this License, they do not --excuse you from the conditions of this License. If you cannot convey a --covered work so as to satisfy simultaneously your obligations under this --License and any other pertinent obligations, then as a consequence you may --not convey it at all. For example, if you agree to terms that obligate you --to collect a royalty for further conveying from those to whom you convey --the Program, the only way you could satisfy both those terms and this --License would be to refrain entirely from conveying the Program. -+excuse you from the conditions of this License. If you cannot -+distribute so as to satisfy simultaneously your obligations under this -+License and any other pertinent obligations, then as a consequence you -+may not distribute the Program at all. For example, if a patent -+license would not permit royalty-free redistribution of the Program by -+all those who receive copies directly or indirectly through you, then -+the only way you could satisfy both it and this License would be to -+refrain entirely from distribution of the Program. - -- 13. Use with the GNU Affero General Public License. -+If any portion of this section is held invalid or unenforceable under -+any particular circumstance, the balance of the section is intended to -+apply and the section as a whole is intended to apply in other -+circumstances. - -- Notwithstanding any other provision of this License, you have --permission to link or combine any covered work with a work licensed --under version 3 of the GNU Affero General Public License into a single --combined work, and to convey the resulting work. The terms of this --License will continue to apply to the part which is the covered work, --but the special requirements of the GNU Affero General Public License, --section 13, concerning interaction through a network will apply to the --combination as such. -+It is not the purpose of this section to induce you to infringe any -+patents or other property right claims or to contest validity of any -+such claims; this section has the sole purpose of protecting the -+integrity of the free software distribution system, which is -+implemented by public license practices. Many people have made -+generous contributions to the wide range of software distributed -+through that system in reliance on consistent application of that -+system; it is up to the author/donor to decide if he or she is willing -+to distribute software through any other system and a licensee cannot -+impose that choice. - -- 14. Revised Versions of this License. -+This section is intended to make thoroughly clear what is believed to -+be a consequence of the rest of this License. - -- The Free Software Foundation may publish revised and/or new versions of --the GNU General Public License from time to time. Such new versions will -+ 8. If the distribution and/or use of the Program is restricted in -+certain countries either by patents or by copyrighted interfaces, the -+original copyright holder who places the Program under this License -+may add an explicit geographical distribution limitation excluding -+those countries, so that distribution is permitted only in or among -+countries not thus excluded. In such case, this License incorporates -+the limitation as if written in the body of this License. -+ -+ 9. The Free Software Foundation may publish revised and/or new versions -+of the General Public License from time to time. Such new versions will - be similar in spirit to the present version, but may differ in detail to - address new problems or concerns. - -- Each version is given a distinguishing version number. If the --Program specifies that a certain numbered version of the GNU General --Public License "or any later version" applies to it, you have the --option of following the terms and conditions either of that numbered --version or of any later version published by the Free Software --Foundation. If the Program does not specify a version number of the --GNU General Public License, you may choose any version ever published --by the Free Software Foundation. -+Each version is given a distinguishing version number. If the Program -+specifies a version number of this License which applies to it and "any -+later version", you have the option of following the terms and conditions -+either of that version or of any later version published by the Free -+Software Foundation. If the Program does not specify a version number of -+this License, you may choose any version ever published by the Free Software -+Foundation. - -- If the Program specifies that a proxy can decide which future --versions of the GNU General Public License can be used, that proxy's --public statement of acceptance of a version permanently authorizes you --to choose that version for the Program. -+ 10. If you wish to incorporate parts of the Program into other free -+programs whose distribution conditions are different, write to the author -+to ask for permission. For software which is copyrighted by the Free -+Software Foundation, write to the Free Software Foundation; we sometimes -+make exceptions for this. Our decision will be guided by the two goals -+of preserving the free status of all derivatives of our free software and -+of promoting the sharing and reuse of software generally. - -- Later license versions may give you additional or different --permissions. However, no additional obligations are imposed on any --author or copyright holder as a result of your choosing to follow a --later version. -+ NO WARRANTY - -- 15. Disclaimer of Warranty. -+ 11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY -+FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN -+OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES -+PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED -+OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF -+MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS -+TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE -+PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, -+REPAIR OR CORRECTION. - -- THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY --APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT --HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY --OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, --THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR --PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM --IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF --ALL NECESSARY SERVICING, REPAIR OR CORRECTION. -+ 12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING -+WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR -+REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, -+INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING -+OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED -+TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY -+YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER -+PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE -+POSSIBILITY OF SUCH DAMAGES. - -- 16. Limitation of Liability. -+ END OF TERMS AND CONDITIONS - -- IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING --WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS --THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY --GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE --USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF --DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD --PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), --EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF --SUCH DAMAGES. -- -- 17. Interpretation of Sections 15 and 16. -- -- If the disclaimer of warranty and limitation of liability provided --above cannot be given local legal effect according to their terms, --reviewing courts shall apply local law that most closely approximates --an absolute waiver of all civil liability in connection with the --Program, unless a warranty or assumption of liability accompanies a --copy of the Program in return for a fee. -- -- END OF TERMS AND CONDITIONS -- -- How to Apply These Terms to Your New Programs -+ How to Apply These Terms to Your New Programs - - If you develop a new program, and you want it to be of the greatest - possible use to the public, the best way to achieve this is to make it -@@ -629,15 +287,15 @@ free software which everyone can redistribute and change under these terms. - - To do so, attach the following notices to the program. It is safest - to attach them to the start of each source file to most effectively --state the exclusion of warranty; and each file should have at least -+convey the exclusion of warranty; and each file should have at least - the "copyright" line and a pointer to where the full notice is found. - - - Copyright (C) - -- This program is free software: you can redistribute it and/or modify -+ This program is free software; you can redistribute it and/or modify - it under the terms of the GNU General Public License as published by -- the Free Software Foundation, either version 3 of the License, or -+ the Free Software Foundation; either version 2 of the License, or - (at your option) any later version. - - This program is distributed in the hope that it will be useful, -@@ -645,32 +303,37 @@ the "copyright" line and a pointer to where the full notice is found. - MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the - GNU General Public License for more details. - -- You should have received a copy of the GNU General Public License -- along with this program. If not, see . -+ You should have received a copy of the GNU General Public License along -+ with this program; if not, write to the Free Software Foundation, Inc., -+ 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA. - - Also add information on how to contact you by electronic and paper mail. - -- If the program does terminal interaction, make it output a short --notice like this when it starts in an interactive mode: -+If the program is interactive, make it output a short notice like this -+when it starts in an interactive mode: - -- Copyright (C) -- This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'. -+ Gnomovision version 69, Copyright (C) year name of author -+ Gnomovision comes with ABSOLUTELY NO WARRANTY; for details type `show w'. - This is free software, and you are welcome to redistribute it - under certain conditions; type `show c' for details. - - The hypothetical commands `show w' and `show c' should show the appropriate --parts of the General Public License. Of course, your program's commands --might be different; for a GUI interface, you would use an "about box". -+parts of the General Public License. Of course, the commands you use may -+be called something other than `show w' and `show c'; they could even be -+mouse-clicks or menu items--whatever suits your program. - -- You should also get your employer (if you work as a programmer) or school, --if any, to sign a "copyright disclaimer" for the program, if necessary. --For more information on this, and how to apply and follow the GNU GPL, see --. -+You should also get your employer (if you work as a programmer) or your -+school, if any, to sign a "copyright disclaimer" for the program, if -+necessary. Here is a sample; alter the names: - -- The GNU General Public License does not permit incorporating your program --into proprietary programs. If your program is a subroutine library, you --may consider it more useful to permit linking proprietary applications with --the library. If this is what you want to do, use the GNU Lesser General --Public License instead of this License. But first, please read --. -+ Yoyodyne, Inc., hereby disclaims all copyright interest in the program -+ `Gnomovision' (which makes passes at compilers) written by James Hacker. - -+ , 1 April 1989 -+ Ty Coon, President of Vice -+ -+This General Public License does not permit incorporating your program into -+proprietary programs. If your program is a subroutine library, you may -+consider it more useful to permit linking proprietary applications with the -+library. If this is what you want to do, use the GNU Lesser General -+Public License instead of this License. --- -2.34.1 - diff --git a/0001-daemon-remove-always-true-comparison.patch b/0001-daemon-remove-always-true-comparison.patch new file mode 100644 index 0000000..cbb5d32 --- /dev/null +++ b/0001-daemon-remove-always-true-comparison.patch @@ -0,0 +1,24 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Tue, 8 Mar 2022 12:59:34 -0500 +Subject: [PATCH] daemon: remove always-true comparison + +Signed-off-by: Robbie Harwood +--- + src/daemon.c | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +diff --git a/src/daemon.c b/src/daemon.c +index 0a66deb..ff88210 100644 +--- a/src/daemon.c ++++ b/src/daemon.c +@@ -221,8 +221,7 @@ malformed: + if (!ctx->cms->tokenname) + goto oom; + +- if (!tp->value) +- pin = strndup((char *)tp->value, tp->size); ++ pin = strndup((char *)tp->value, tp->size); + if (!pin) + goto oom; + diff --git a/0002-Fix-format-strings-for-32-bit-arches.patch b/0002-Fix-format-strings-for-32-bit-arches.patch deleted file mode 100644 index 1aaab2d..0000000 --- a/0002-Fix-format-strings-for-32-bit-arches.patch +++ /dev/null @@ -1,112 +0,0 @@ -From df8783ed4ed87fef850268098690985049916ee9 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 1 Feb 2022 17:37:14 -0500 -Subject: [PATCH 2/5] Fix format strings for 32-bit arches - -Sadly, in 2022, this remains a thing. - -Signed-off-by: Robbie Harwood ---- - src/cms_pe_common.c | 16 +++++++++------- - src/password.c | 7 ++++--- - 2 files changed, 13 insertions(+), 10 deletions(-) - -diff --git a/src/cms_pe_common.c b/src/cms_pe_common.c -index 964f0d9..3a3921b 100644 ---- a/src/cms_pe_common.c -+++ b/src/cms_pe_common.c -@@ -49,7 +49,7 @@ check_pointer_and_size(cms_context *cms, Pe *pe, void *ptr, size_t size) - - if (p + size > m + map_size) - cmsreterr(0, cms, -- "pointer %p is above mmap end at %p (%lu is %lu bytes past EOF at %lu)", -+ "pointer %p is above mmap end at %p (%lu is %lu bytes past EOF at %zu)", - (void *)((uintptr_t)p + size), - (void *)((uintptr_t)m + map_size), - p + size - m, -@@ -189,7 +189,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - if (!check_pointer_and_size(cms, pe, hash_base, hash_size)) - cmsgotoerr(error, cms, "PE header is invalid"); - dprintf("beginning of hash"); -- dprintf("digesting %lx + %lx", hash_base - map, hash_size); -+ dprintf("digesting %tx + %zx", hash_base - map, hash_size); - generate_digest_step(cms, hash_base, hash_size); - - /* 5. Skip over the image checksum -@@ -209,7 +209,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - cmsgotoerr(error, cms, "PE data directory is invalid"); - - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %lx + %lx", hash_base - map, hash_size); -+ dprintf("digesting %tx + %zx", hash_base - map, hash_size); - - /* 8. Skip over the crt dir - * 9. Hash everything up to the end of the image header. */ -@@ -222,7 +222,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - cmsgotoerr(error, cms, "PE relocations table is invalid"); - - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %lx + %lx", hash_base - map, hash_size); -+ dprintf("digesting %tx + %zx", hash_base - map, hash_size); - - /* 10. Set SUM_OF_BYTES_HASHED to the size of the header. */ - hashed_bytes = pe32opthdr ? pe32opthdr->header_size -@@ -265,7 +265,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - } - - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %lx + %lx", hash_base - map, hash_size); -+ dprintf("digesting %tx + %zx", hash_base - map, hash_size); - - hashed_bytes += hash_size; - } -@@ -285,10 +285,12 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - memset(tmp_array, '\0', tmp_size); - memcpy(tmp_array, hash_base, hash_size); - generate_digest_step(cms, tmp_array, tmp_size); -- dprintf("digesting %lx + %lx", (unsigned long)tmp_array, tmp_size); -+ dprintf("digesting %tx + %zx", (ptrdiff_t)tmp_array, -+ tmp_size); - } else { - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %lx + %lx", hash_base - map, hash_size); -+ dprintf("digesting %tx + %zx", hash_base - map, -+ hash_size); - } - } - dprintf("end of hash"); -diff --git a/src/password.c b/src/password.c -index 644f362..05add9a 100644 ---- a/src/password.c -+++ b/src/password.c -@@ -213,7 +213,7 @@ parse_pwfile_line(char *start, struct token_pass *tp) - dprintf("non-whitespace span is %zd", span); - - if (line[span] == '\0') { -- dprintf("returning %ld", (line + span) - start); -+ dprintf("returning %td", (line + span) - start); - return (line + span) - start; - } - line[span] = '\0'; -@@ -241,7 +241,7 @@ parse_pwfile_line(char *start, struct token_pass *tp) - dprintf("Setting token pass %p to { %p, %p }", tp, tp->token, tp->pass); - dprintf("token:\"%s\"", tp->token); - dprintf("pass:\"%s\"", tp->pass); -- dprintf("returning %ld", (line + span) - start); -+ dprintf("returning %td", (line + span) - start); - return (line + span) - start; - } - -@@ -330,7 +330,8 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) - if (c != '\0') - span++; - start += span; -- dprintf("start is file[%ld] == '\\x%02hhx'", start - file, start[0]); -+ dprintf("start is file[%td] == '\\x%02hhx'", start - file, -+ start[0]); - } - - qsort(phrases, nphrases, sizeof(struct token_pass), token_pass_cmp); --- -2.34.1 - diff --git a/0003-macros-drop-_pesign_args.patch b/0003-macros-drop-_pesign_args.patch deleted file mode 100644 index 40a7bf5..0000000 --- a/0003-macros-drop-_pesign_args.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 389decab7b9bcba307e52709b00741a19405f02b Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 2 Feb 2022 16:07:46 -0500 -Subject: [PATCH 3/5] macros: drop %{_pesign_args} - -Effectively reverts 30b488682a92c524bb9c0d450c34e9abc0b56de9 - -Also, make our argument parser fail on extra arguments to make it easier -to debug when this kind of thing happens again. - -Signed-off-by: Robbie Harwood ---- - src/macros.pesign | 1 - - src/pesign-rpmbuild-helper.in | 5 +++++ - 2 files changed, 5 insertions(+), 1 deletion(-) - -diff --git a/src/macros.pesign b/src/macros.pesign -index 519a8a3..34af57c 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -27,7 +27,6 @@ - %{_libexecdir}/pesign/pesign-rpmbuild-helper \\\ - "%{_target_cpu}" \\\ - "%{_pesign}" \\\ -- "%{_pesign_args}" \\\ - "%{_pesign_client}" \\\ - %{?__pesign_client_token:--client-token %{__pesign_client_token}} \\\ - %{?__pesign_client_cert:--client-cert %{__pesign_client_cert}} \\\ -diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in -index 27b8261..0a845d2 100644 ---- a/src/pesign-rpmbuild-helper.in -+++ b/src/pesign-rpmbuild-helper.in -@@ -133,6 +133,11 @@ main() { - sign=-s - shift - fi -+ if [[ $# -ge 1 ]] ; then -+ echo "$# extra unparsed arguments!">>/dev/stderr -+ echo "Cowardly refusing to run">>/dev/stderr -+ exit 1 -+ fi - - if [[ -z "${target_cpu}" ]] ; then - target_cpu="$(uname -m)" --- -2.34.1 - diff --git a/0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch b/0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch deleted file mode 100644 index f36d1e0..0000000 --- a/0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch +++ /dev/null @@ -1,55 +0,0 @@ -From 4d1ead068248b56ecaeb437f0c0b59f9d89b9748 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 14 Feb 2022 15:46:25 -0500 -Subject: [PATCH 4/5] Handle NULL pwdata in cms_set_pw_data() - -When 12f16710ee44ef64ddb044a3523c3c4c4d90039a rewrote this function, it -didn't handle the NULL pwdata invocation from daemon.c. This leads to a -explicit NULL dereference and crash on all attempts to daemonize pesign. - -Signed-off-by: Robbie Harwood -(cherry picked from commit b879dda52f8122de697d145977c285fb0a022d76) ---- - src/cms_common.c | 18 ++++++++++++------ - 1 file changed, 12 insertions(+), 6 deletions(-) - -diff --git a/src/cms_common.c b/src/cms_common.c -index 332999e..ca37e6a 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -313,7 +313,7 @@ void cms_set_pw_data(cms_context *cms, secuPWData *pwdata) - - case PW_FROMFD: - if (cms->pwdata.intdata >= 0 && -- !(pwdata->source == PW_FROMFD && -+ !(pwdata && pwdata->source == PW_FROMFD && - cms->pwdata.intdata == pwdata->intdata)) - close(cms->pwdata.intdata); - break; -@@ -330,12 +330,18 @@ void cms_set_pw_data(cms_context *cms, secuPWData *pwdata) - xfree(cms->pwdata.data); - break; - } -- memmove(&cms->pwdata, pwdata, sizeof(*pwdata)); - -- dprintf("pwdata:%p", pwdata); -- dprintf("pwdata->source:%d", pwdata->source); -- dprintf("pwdata->data:%p (\"%s\")", pwdata->data, -- pwdata->data ? pwdata->data : "(null)"); -+ if (!pwdata) { -+ cms->pwdata.source = PW_SOURCE_INVALID; -+ dprintf("pwdata:NULL"); -+ } else { -+ memmove(&cms->pwdata, pwdata, sizeof(*pwdata)); -+ dprintf("pwdata:%p", pwdata); -+ dprintf("pwdata->source:%d", pwdata->source); -+ dprintf("pwdata->data:%p (\"%s\")", pwdata->data, -+ pwdata->data ? pwdata->data : "(null)"); -+ } -+ - egress(); - } - --- -2.34.1 - diff --git a/0005-fcf-protection-is-arch-specific.patch b/0005-fcf-protection-is-arch-specific.patch deleted file mode 100644 index 84093bf..0000000 --- a/0005-fcf-protection-is-arch-specific.patch +++ /dev/null @@ -1,46 +0,0 @@ -From f03c5fbe6b4327b9ecd781bfdf64147e1b68e6c1 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Wed, 9 Feb 2022 15:23:27 -0500 -Subject: [PATCH 5/5] -fcf-protection is arch-specific - -Signed-off-by: Robbie Harwood -(cherry picked from commit c48df510144de3b1187001bc3b5491509da1c58f) ---- - Make.defaults | 10 ++++++---- - 1 file changed, 6 insertions(+), 4 deletions(-) - -diff --git a/Make.defaults b/Make.defaults -index fdb961a..130c1ee 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -22,11 +22,16 @@ EFI_ARCHES ?= aa64 ia32 x64 - - enabled = $(if $(filter undefined,$(origin $(1))),$(3),$(2)) - -+HOSTARCH = $(shell uname -m | sed s,i[3456789]86,ia32,) -+ARCH := $(shell uname -m | sed s,i[3456789]86,ia32,) -+ -+ - PKG_CONFIG ?= $(CROSS_COMPILE)pkg-config - CC := $(if $(filter default,$(origin CC)),$(CROSS_COMPILE)gcc,$(CC)) - CCLD := $(if $(filter undefined,$(origin CCLD)),$(CC),$(CCLD)) - CFLAGS ?= -O2 -g3 -pipe -fPIE -fstack-protector-all \ -- -fstack-clash-protection -fcf-protection=full -+ -fstack-clash-protection \ -+ $(if $(filter x86_64 ia32,$(ARCH)),-fcf-protection=full,) - DIAGFLAGS ?= -fmessage-length=0 \ - -fdiagnostics-color=always \ - -fdiagnostics-format=text \ -@@ -42,9 +47,6 @@ INSTALL ?= $(CROSS_COMPILE)install - - PKGS = efivar nspr nss nss-util uuid - --HOSTARCH = $(shell uname -m | sed s,i[3456789]86,ia32,) --ARCH := $(shell uname -m | sed s,i[3456789]86,ia32,) -- - SOFLAGS ?= -shared - clang_cflags = - gcc_cflags = -Wmaybe-uninitialized -grecord-gcc-switches \ --- -2.34.1 - diff --git a/0006-Disable-analyzer-until-it-works.patch b/0006-Disable-analyzer-until-it-works.patch deleted file mode 100644 index 4ed8cbf..0000000 --- a/0006-Disable-analyzer-until-it-works.patch +++ /dev/null @@ -1,26 +0,0 @@ -From 288b05dcd5a3b48836c4904e38b14e38a0cdfa07 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 14 Feb 2022 17:26:19 -0500 -Subject: [PATCH] Disable analyzer until it works - -See-also: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=104370 -Signed-off-by: Robbie Harwood ---- - Make.defaults | 1 - - 1 file changed, 1 deletion(-) - -diff --git a/Make.defaults b/Make.defaults -index 130c1ee..5e56a76 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -36,7 +36,6 @@ DIAGFLAGS ?= -fmessage-length=0 \ - -fdiagnostics-color=always \ - -fdiagnostics-format=text \ - -fdiagnostics-show-cwe \ -- -fanalyzer \ - $(call enabled,ENABLE_LEAK_CHECKER,-Wno-analyzer-malloc-leak,) - AS ?= $(CROSS_COMPILE)as - AR ?= $(CROSS_COMPILE)$(if $(filter $(CC),clang),llvm-ar,$(notdir $(CC))-ar) --- -2.34.1 - diff --git a/pesign.spec b/pesign.spec index d534229..764f6a6 100644 --- a/pesign.spec +++ b/pesign.spec @@ -5,8 +5,8 @@ Name: pesign Summary: Signing utility for UEFI binaries -Version: 114 -Release: 4%{?dist} +Version: 115 +Release: 1%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -47,11 +47,7 @@ Source0: https://github.com/rhboot/pesign/releases/download/%{version}/pesign-%{ Source1: certs.tar.xz Source2: pesign.py -Patch0001: 0001-Revert-Move-license-to-GPLv3.patch -Patch0002: 0002-Fix-format-strings-for-32-bit-arches.patch -Patch0003: 0003-macros-drop-_pesign_args.patch -Patch0004: 0004-Handle-NULL-pwdata-in-cms_set_pw_data.patch -Patch0005: 0005-fcf-protection-is-arch-specific.patch +Patch0001: 0001-daemon-remove-always-true-comparison.patch %description This package contains the pesign utility for signing UEFI binaries as @@ -163,6 +159,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Mar 08 2022 Robbie Harwood - 115-1 +- New upstream version (115) + * Mon Feb 14 2022 Robbie Harwood - 114-4 - Disable -fanalyzer since it's broken and pragmas don't work - See-also: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=104370 diff --git a/sources b/sources index 3522848..b6ddc75 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ SHA512 (certs.tar.xz) = ddac535c786d1a23074534323c4ce89f907d4f82b19c5d3a9c814b145fbac1599cd2386cf20c28d22aee7d5c4db441f052bab9ee655de756117a0a0bc99b525f -SHA512 (pesign-114.tar.bz2) = 5465c002db6f59ab59799ec79504ed96662bc5da2310282d2e85fc1f03c938343d88927e764e595bf21c3501e599e529a4752281349097cdc74e616535179b3c +SHA512 (pesign-115.tar.bz2) = 0091d70e286326b1ed74418ca8c5a2a63d42e6aa3eccdfc4f09a34241b2addfe878af17d1d74648b7da79d6cd7158fcca0f3a52f4a82a57cacae4617b42b1faa From b201f43f63402fcf484416060ab0a4dbbf79e261 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 24 Mar 2022 21:24:15 +0000 Subject: [PATCH 12/32] Add support for non-koji signing in macros Resolves: #1880858 Signed-off-by: Robbie Harwood --- ...ned-kernels-on-setups-other-than-koj.patch | 55 +++++++++++++++++++ pesign.patches | 2 + pesign.spec | 10 +++- 3 files changed, 65 insertions(+), 2 deletions(-) create mode 100644 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch create mode 100644 pesign.patches diff --git a/0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch b/0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch new file mode 100644 index 0000000..920eb6a --- /dev/null +++ b/0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch @@ -0,0 +1,55 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Julian Sikorski +Date: Wed, 23 Mar 2022 20:54:03 +0100 +Subject: [PATCH] Fix building signed kernels on setups other than koji + +Thanks to Will Springer for the idea. Details at +https://bugzilla.redhat.com/show_bug.cgi?id=1880858 + +Signed-off-by: Julian Sikorski +Suggested-by: Will Springer +(cherry picked from commit 9969b1757a1941c9f57081b308026d687f6c0943) +--- + src/pesign-rpmbuild-helper.in | 24 +++++++++++------------- + 1 file changed, 11 insertions(+), 13 deletions(-) + +diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in +index 0a845d2..c9d5570 100644 +--- a/src/pesign-rpmbuild-helper.in ++++ b/src/pesign-rpmbuild-helper.in +@@ -172,24 +172,22 @@ main() { + USERNAME="${USERNAME:-$(id -un)}" + + local socket="" || : +- if grep -q ID=fedora /etc/os-release \ ++ if [[ -S /run/pesign/socket ]] ; then ++ socket=/run/pesign/socket ++ elif [[ -S /var/run/pesign/socket ]]; then ++ socket=/var/run/pesign/socket ++ elif grep -q ID=fedora /etc/os-release \ + && [[ "${rhelver}" -lt 7 ]] \ + && [[ "${USERNAME}" = "mockbuild" ]] \ + && [[ "${vendor}" = "Fedora Project" ]] \ + && [[ "${HOSTNAME}" =~ bkernel.* ]] + then +- if [[ -S /run/pesign/socket ]] ; then +- socket=/run/pesign/socket +- elif [[ -S /var/run/pesign/socket ]]; then +- socket=/var/run/pesign/socket +- else +- echo "Warning: no pesign socket even though user is ${USERNAME}" 1>&2 +- echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 +- ls -ld /run/pesign /var/run/pesign 1>&2 ||: +- ls -l /run/pesign/socket /var/run/pesign/socket 1>&2 ||: +- getfacl /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: +- getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: +- fi ++ echo "Warning: no pesign socket even though user is ${USERNAME}" 1>&2 ++ echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 ++ ls -ld /run/pesign /var/run/pesign 1>&2 ||: ++ ls -l /run/pesign/socket /var/run/pesign/socket 1>&2 ||: ++ getfacl /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: ++ getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: + fi + + if [[ "${rhelver}" -ge 7 ]] ; then diff --git a/pesign.patches b/pesign.patches new file mode 100644 index 0000000..3126bdf --- /dev/null +++ b/pesign.patches @@ -0,0 +1,2 @@ +Patch0001: 0001-daemon-remove-always-true-comparison.patch +Patch0002: 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch diff --git a/pesign.spec b/pesign.spec index 764f6a6..8ca1139 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 1%{?dist} +Release: 2%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -46,8 +46,10 @@ BuildRequires: rh-signing-tools >= 1.20-2 Source0: https://github.com/rhboot/pesign/releases/download/%{version}/pesign-%{version}.tar.bz2 Source1: certs.tar.xz Source2: pesign.py +Source3: pesign.patches -Patch0001: 0001-daemon-remove-always-true-comparison.patch +# generate with tool +%include %{SOURCE3} %description This package contains the pesign utility for signing UEFI binaries as @@ -159,6 +161,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Thu Mar 24 2022 Robbie Harwood - 115-2 +- Add support for non-koji signing in macros +- Resolves: #1880858 + * Tue Mar 08 2022 Robbie Harwood - 115-1 - New upstream version (115) From c324cc0c6c5c0cd77a22f79def3472c268d6a6cd Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 25 Mar 2022 19:02:31 +0000 Subject: [PATCH 13/32] Add -D_GLIBCXX_ASSERTIONS to CPPFLAGS Signed-off-by: Robbie Harwood --- ...Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch | 23 +++++++++++++++++++ pesign.patches | 1 + pesign.spec | 5 +++- 3 files changed, 28 insertions(+), 1 deletion(-) create mode 100644 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch diff --git a/0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch b/0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch new file mode 100644 index 0000000..0dca694 --- /dev/null +++ b/0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch @@ -0,0 +1,23 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 25 Mar 2022 15:01:54 -0400 +Subject: [PATCH] Add -D_GLIBCXX_ASSERTIONS to CPPFLAGS + +Signed-off-by: Robbie Harwood +--- + Make.defaults | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/Make.defaults b/Make.defaults +index 130c1ee..4b0e77c 100644 +--- a/Make.defaults ++++ b/Make.defaults +@@ -79,7 +79,7 @@ ccldflags = $(cflags) $(CCLDFLAGS) $(LDFLAGS) \ + $(call pkg-config-ccldflags) + efi_cflags = $(cflags) + ASFLAGS ?= $(ARCH3264) +-CPPFLAGS ?= -D_FORTIFY_SOURCE=2 ++CPPFLAGS ?= -D_FORTIFY_SOURCE=2 -D_GLIBCXX_ASSERTIONS + RANLIBFLAGS ?= $(if $(filter $(CC),gcc),-D) + ARFLAGS ?= $(if $(filter $(CC),gcc),-Dcvqs)$(if $(filter $(CC),clang),-cqvs) + diff --git a/pesign.patches b/pesign.patches index 3126bdf..98cdf7c 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1,2 +1,3 @@ Patch0001: 0001-daemon-remove-always-true-comparison.patch Patch0002: 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch +Patch0003: 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch diff --git a/pesign.spec b/pesign.spec index 8ca1139..8e803f9 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 2%{?dist} +Release: 3%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,6 +161,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Fri Mar 25 2022 Robbie Harwood - 115-3 +- Add -D_GLIBCXX_ASSERTIONS to CPPFLAGS + * Thu Mar 24 2022 Robbie Harwood - 115-2 - Add support for non-koji signing in macros - Resolves: #1880858 From 1d2597d20dab3c18d0b62cc7ce74173758747353 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Fri, 1 Apr 2022 19:28:29 +0000 Subject: [PATCH 14/32] Correctly handle rhel and centos macros Signed-off-by: Robbie Harwood --- ...handle-centos-like-rhel-with-rhelver.patch | 25 +++++++++++++++++++ pesign.patches | 1 + pesign.spec | 5 +++- 3 files changed, 30 insertions(+), 1 deletion(-) create mode 100644 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch diff --git a/0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch b/0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch new file mode 100644 index 0000000..62d1936 --- /dev/null +++ b/0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch @@ -0,0 +1,25 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Tue, 10 Aug 2021 12:39:08 -0400 +Subject: [PATCH] macros.pesign: handle centos like rhel with --rhelver + +Signed-off-by: Peter Jones +(cherry picked from commit a1bc65c8b0fc20dbe9c9714ee3a31937184ba7f6) +--- + src/macros.pesign | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/src/macros.pesign b/src/macros.pesign +index 34af57c..b7d6af1 100644 +--- a/src/macros.pesign ++++ b/src/macros.pesign +@@ -34,7 +34,8 @@ + %{?__pesign_cert:--cert %{__pesign_cert}} \\\ + %{?_buildhost:--hostname "%{_buildhost}"} \\\ + %{?vendor:--vendor "%{vendor}"} \\\ +- %{?_rhel:--rhelver "%{_rhel}"} \\\ ++ %{?rhel:--rhelver "%{rhel}"} \\\ ++ %{?centos:--rhelver "%{centos}"} \\\ + %{?-n:--rhelcert %{-n*}}%{?!-n:--rhelcert %{__pesign_cert}} \\\ + %{?-a:--rhelcafile "%{-a*}"} \\\ + %{?-c:--rhelcertfile "%{-c*}"} \\\ diff --git a/pesign.patches b/pesign.patches index 98cdf7c..62ae005 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1,3 +1,4 @@ Patch0001: 0001-daemon-remove-always-true-comparison.patch Patch0002: 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch Patch0003: 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch +Patch0004: 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch diff --git a/pesign.spec b/pesign.spec index 8e803f9..dd5df45 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 3%{?dist} +Release: 4%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,6 +161,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Fri Apr 01 2022 Robbie Harwood - 115-4 +- Correctly handle rhel and centos macros + * Fri Mar 25 2022 Robbie Harwood - 115-3 - Add -D_GLIBCXX_ASSERTIONS to CPPFLAGS From 3bf806fd9f75943a3693e9afaaedb41e86e4447f Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Mon, 4 Apr 2022 18:52:40 +0000 Subject: [PATCH 15/32] Detect presence of rpm-sign when checking for rhel-ness Signed-off-by: Robbie Harwood --- ...nce-of-rpm-sign-when-checking-for-rh.patch | 26 +++++++++++++++++++ pesign.patches | 1 + pesign.spec | 5 +++- 3 files changed, 31 insertions(+), 1 deletion(-) create mode 100644 0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch diff --git a/0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch b/0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch new file mode 100644 index 0000000..0baddd6 --- /dev/null +++ b/0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch @@ -0,0 +1,26 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 4 Apr 2022 14:45:29 -0400 +Subject: [PATCH] Detect the presence of rpm-sign when checking for "rhel"-ness + +Signed-off-by: Peter Jones +[rharwood: manually reapply to main] +Signed-off-by: Robbie Harwood +(cherry picked from commit 17e5878cb087e0a766722d3c487f87c41b318f9a) +--- + src/pesign-rpmbuild-helper.in | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in +index c9d5570..9dee56e 100644 +--- a/src/pesign-rpmbuild-helper.in ++++ b/src/pesign-rpmbuild-helper.in +@@ -190,7 +190,7 @@ main() { + getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: + fi + +- if [[ "${rhelver}" -ge 7 ]] ; then ++ if [[ "${rhelver}" -ge 7 ]] && which rpm-sign >&/dev/null ; then + nssdir="$(mktemp -p "${PWD}" -d)" + echo > "${nssdir}/pwfile" + certutil -N -d "${nssdir}" -f "${nssdir}/pwfile" diff --git a/pesign.patches b/pesign.patches index 62ae005..848483a 100644 --- a/pesign.patches +++ b/pesign.patches @@ -2,3 +2,4 @@ Patch0001: 0001-daemon-remove-always-true-comparison.patch Patch0002: 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch Patch0003: 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch Patch0004: 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch +Patch0005: 0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch diff --git a/pesign.spec b/pesign.spec index dd5df45..483a42d 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 4%{?dist} +Release: 5%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,6 +161,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Mon Apr 04 2022 Robbie Harwood - 115-5 +- Detect presence of rpm-sign when checking for rhel-ness + * Fri Apr 01 2022 Robbie Harwood - 115-4 - Correctly handle rhel and centos macros From fbf8f35ae7fa4ad1edf325877df1f07bce3078e4 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Thu, 7 Jul 2022 21:06:42 +0000 Subject: [PATCH 16/32] Fix formatting of man pages Resolves: #2104778 --- ...oc-invocation-to-not-produce-garbage.patch | 32 +++++++++++++++++++ pesign.patches | 1 + pesign.spec | 6 +++- 3 files changed, 38 insertions(+), 1 deletion(-) create mode 100644 0006-Fix-mandoc-invocation-to-not-produce-garbage.patch diff --git a/0006-Fix-mandoc-invocation-to-not-produce-garbage.patch b/0006-Fix-mandoc-invocation-to-not-produce-garbage.patch new file mode 100644 index 0000000..fb105df --- /dev/null +++ b/0006-Fix-mandoc-invocation-to-not-produce-garbage.patch @@ -0,0 +1,32 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Thu, 7 Jul 2022 16:56:41 -0400 +Subject: [PATCH] Fix mandoc invocation to not produce garbage + +Bizarrely, mandoc doesn't default to outputting man - the default is +"locale", which is either ASCII or UTF-8 (by locale). This output is +supposed to be some kind of plain-text, but it's formatted so strangely +I'm not sure what the purpose is. Regardless, it doesn't go well to +feed this into man(1). + +Tell mandoc explicitly to produce man pages. + +Signed-off-by: Robbie Harwood +(cherry picked from commit 102c3d1d81c090750abb3815481d5cfd3e596677) +--- + Make.rules | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/Make.rules b/Make.rules +index 12e322b..f6bf5fa 100644 +--- a/Make.rules ++++ b/Make.rules +@@ -54,7 +54,7 @@ define substitute-version = + endef + + %.1 : %.1.mdoc +- @mandoc -man -Ios=Linux $^ > $@ ++ @mandoc -man -T man -Ios=Linux $^ > $@ + + % : %.in + @$(call substitute-version,$<,$@) diff --git a/pesign.patches b/pesign.patches index 848483a..9b257c3 100644 --- a/pesign.patches +++ b/pesign.patches @@ -3,3 +3,4 @@ Patch0002: 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch Patch0003: 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch Patch0004: 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch Patch0005: 0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch +Patch0006: 0006-Fix-mandoc-invocation-to-not-produce-garbage.patch diff --git a/pesign.spec b/pesign.spec index 483a42d..b850722 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 5%{?dist} +Release: 6%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,6 +161,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Thu Jul 07 2022 Robbie Harwood - 115-6 +- Fix formatting of man pages +- Resolves: #2104778 + * Mon Apr 04 2022 Robbie Harwood - 115-5 - Detect presence of rpm-sign when checking for rhel-ness From f1d5690e2e72c9755529f40822322bd0a4124270 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 22 Jul 2022 13:02:33 +0000 Subject: [PATCH 17/32] Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pesign.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index b850722..3787b15 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 6%{?dist} +Release: 7%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,6 +161,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Fri Jul 22 2022 Fedora Release Engineering +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + * Thu Jul 07 2022 Robbie Harwood - 115-6 - Fix formatting of man pages - Resolves: #2104778 From c2da1bf6da1aa7e3b031e5425aad9b74521a0169 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Aug 2022 10:32:50 -0400 Subject: [PATCH 18/32] Revert "Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild" This reverts commit f1d5690e2e72c9755529f40822322bd0a4124270. Signed-off-by: Robbie Harwood --- pesign.spec | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/pesign.spec b/pesign.spec index 3787b15..b850722 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 7%{?dist} +Release: 6%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,9 +161,6 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog -* Fri Jul 22 2022 Fedora Release Engineering -- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild - * Thu Jul 07 2022 Robbie Harwood - 115-6 - Fix formatting of man pages - Resolves: #2104778 From 4b458cfe9f2fab0c0618736998da4e34a7b541e3 Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 2 Aug 2022 14:34:06 +0000 Subject: [PATCH 19/32] Rebuild for python bytecode change See-also: #2107826 Signed-off-by: Robbie Harwood --- noautobuild | 0 pesign.spec | 6 +++++- 2 files changed, 5 insertions(+), 1 deletion(-) create mode 100644 noautobuild diff --git a/noautobuild b/noautobuild new file mode 100644 index 0000000..e69de29 diff --git a/pesign.spec b/pesign.spec index b850722..118b151 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 6%{?dist} +Release: 8%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -161,6 +161,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Aug 02 2022 Robbie Harwood - 115-8 +- Rebuild for python bytecode change +- See-also: #2107826 + * Thu Jul 07 2022 Robbie Harwood - 115-6 - Fix formatting of man pages - Resolves: #2104778 From bb3aaa1ba23053c22907afc0153eefb2de91127d Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Wed, 31 Aug 2022 21:06:34 +0000 Subject: [PATCH 20/32] Roll up to pjones's smartcard/cms fixes Signed-off-by: Robbie Harwood --- ...ndle-some-gcc-Wanalyzer-flags-better.patch | 40 ++ 0003-Rename-dprintf-to-dbgprintf.patch | 664 ++++++++++++++++++ ...add-compile_commands.json-and-.cache.patch | 30 + ...ests-before-filenames-like-sha256sum.patch | 31 + ...sum-an-authenticode-digest-generator.patch | 318 +++++++++ ...ned-kernels-on-setups-other-than-koj.patch | 1 - ...Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch | 2 +- ...handle-centos-like-rhel-with-rhelver.patch | 1 - ...nce-of-rpm-sign-when-checking-for-rh.patch | 1 - 0011-Rename-README-README.md.patch | 17 + 0012-README.md-show-off-a-bit-more.patch | 56 ++ 0013-Fix-missing-line-in-README.md.patch | 23 + 0014-Fix-typo-in-efikeygen-command.patch | 23 + ...pesigcheck-Fix-crash-on-digest-match.patch | 53 ++ ...e-digest-as-pointer-instead-of-index.patch | 272 +++++++ ...oc-invocation-to-not-produce-garbage.patch | 1 - ...being-obnoxiously-incompatible-with-.patch | 41 ++ ...sthrough-handle-the-callback-context.patch | 51 ++ ...ly-prune-CR-NL-from-the-end-of-the-f.patch | 47 ++ ...e-digest-as-pointer-instead-of-index.patch | 276 ++++++++ 0022-CMS-add-some-minor-cleanups.patch | 149 ++++ ...e-cms-selected_digest-an-index-again.patch | 291 ++++++++ pesign.patches | 27 +- pesign.spec | 8 +- 24 files changed, 2411 insertions(+), 12 deletions(-) create mode 100644 0002-make-handle-some-gcc-Wanalyzer-flags-better.patch create mode 100644 0003-Rename-dprintf-to-dbgprintf.patch create mode 100644 0004-.gitignore-add-compile_commands.json-and-.cache.patch create mode 100644 0005-pesign-print-digests-before-filenames-like-sha256sum.patch create mode 100644 0006-Add-pesum-an-authenticode-digest-generator.patch rename 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch => 0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch (97%) rename 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch => 0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch (96%) rename 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch => 0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch (93%) rename 0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch => 0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch (93%) create mode 100644 0011-Rename-README-README.md.patch create mode 100644 0012-README.md-show-off-a-bit-more.patch create mode 100644 0013-Fix-missing-line-in-README.md.patch create mode 100644 0014-Fix-typo-in-efikeygen-command.patch create mode 100644 0015-pesigcheck-Fix-crash-on-digest-match.patch create mode 100644 0016-cms-store-digest-as-pointer-instead-of-index.patch rename 0006-Fix-mandoc-invocation-to-not-produce-garbage.patch => 0017-Fix-mandoc-invocation-to-not-produce-garbage.patch (93%) create mode 100644 0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch create mode 100644 0019-get_password_passthrough-handle-the-callback-context.patch create mode 100644 0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch create mode 100644 0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch create mode 100644 0022-CMS-add-some-minor-cleanups.patch create mode 100644 0023-CMS-make-cms-selected_digest-an-index-again.patch diff --git a/0002-make-handle-some-gcc-Wanalyzer-flags-better.patch b/0002-make-handle-some-gcc-Wanalyzer-flags-better.patch new file mode 100644 index 0000000..5bee588 --- /dev/null +++ b/0002-make-handle-some-gcc-Wanalyzer-flags-better.patch @@ -0,0 +1,40 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Fri, 11 Mar 2022 12:45:28 -0500 +Subject: [PATCH] make: handle some gcc -Wanalyzer flags better + +This makes it so we won't use the -Wanalyzer / -fanalyzer flags by +default, because they're still pretty overzealous. + +Signed-off-by: Peter Jones +--- + Make.defaults | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/Make.defaults b/Make.defaults +index 130c1ee..1c18904 100644 +--- a/Make.defaults ++++ b/Make.defaults +@@ -32,11 +32,11 @@ CCLD := $(if $(filter undefined,$(origin CCLD)),$(CC),$(CCLD)) + CFLAGS ?= -O2 -g3 -pipe -fPIE -fstack-protector-all \ + -fstack-clash-protection \ + $(if $(filter x86_64 ia32,$(ARCH)),-fcf-protection=full,) +-DIAGFLAGS ?= -fmessage-length=0 \ ++DIAGFLAGS ?= $(call enabled,ENABLE_GCC_ANALYZER,-fmessage-length=0 \ + -fdiagnostics-color=always \ + -fdiagnostics-format=text \ + -fdiagnostics-show-cwe \ +- -fanalyzer \ ++ -fanalyzer) \ + $(call enabled,ENABLE_LEAK_CHECKER,-Wno-analyzer-malloc-leak,) + AS ?= $(CROSS_COMPILE)as + AR ?= $(CROSS_COMPILE)$(if $(filter $(CC),clang),llvm-ar,$(notdir $(CC))-ar) +@@ -59,7 +59,7 @@ endif + cflags = $(CFLAGS) $(ARCH3264) \ + -Wall -Wextra -Wsign-compare -Wno-unused-result \ + -Wno-unused-function -Wno-missing-field-initializers \ +- -Wno-analyzer-malloc-leak \ ++ $(call enabled,ENABLE_LEAK_CHECKER,-Wno-analyzer-malloc-leak,) \ + -Werror -Wno-error=cpp -Wno-free-nonheap-object \ + -std=gnu11 -fshort-wchar -fPIC -fno-strict-aliasing \ + -D_GNU_SOURCE -DCONFIG_$(ARCH) -I${TOPDIR}/include \ diff --git a/0003-Rename-dprintf-to-dbgprintf.patch b/0003-Rename-dprintf-to-dbgprintf.patch new file mode 100644 index 0000000..dac8401 --- /dev/null +++ b/0003-Rename-dprintf-to-dbgprintf.patch @@ -0,0 +1,664 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Fri, 11 Mar 2022 12:46:16 -0500 +Subject: [PATCH] Rename "dprintf' to "dbgprintf" + +stdio defines a dprintf() macro now, so using dprintf() for our debug +printer gets obnoxious warnings. This renames it to dbgprintf(). + +Signed-off-by: Peter Jones +--- + src/cms_common.c | 73 +++++++++++++++++++++++++++++------------------------ + src/cms_pe_common.c | 20 +++++++-------- + src/efikeygen.c | 16 ++++++------ + src/file_pe.c | 6 +++-- + src/password.c | 68 ++++++++++++++++++++++++------------------------- + src/pesign.c | 10 ++++---- + src/util.h | 26 +++++++++---------- + 7 files changed, 114 insertions(+), 105 deletions(-) + +diff --git a/src/cms_common.c b/src/cms_common.c +index ca37e6a..86341ca 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -333,13 +333,13 @@ void cms_set_pw_data(cms_context *cms, secuPWData *pwdata) + + if (!pwdata) { + cms->pwdata.source = PW_SOURCE_INVALID; +- dprintf("pwdata:NULL"); ++ dbgprintf("pwdata:NULL"); + } else { + memmove(&cms->pwdata, pwdata, sizeof(*pwdata)); +- dprintf("pwdata:%p", pwdata); +- dprintf("pwdata->source:%d", pwdata->source); +- dprintf("pwdata->data:%p (\"%s\")", pwdata->data, +- pwdata->data ? pwdata->data : "(null)"); ++ dbgprintf("pwdata:%p", pwdata); ++ dbgprintf("pwdata->source:%d", pwdata->source); ++ dbgprintf("pwdata->data:%p (\"%s\")", pwdata->data, ++ pwdata->data ? pwdata->data : "(null)"); + } + + egress(); +@@ -382,7 +382,7 @@ is_valid_cert(CERTCertificate *cert, void *data) + + errnum = PORT_GetError(); + if (errnum == SEC_ERROR_EXTENSION_NOT_FOUND) { +- dprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); ++ dbgprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); + PORT_SetError(0); + errnum = 0; + } +@@ -415,7 +415,7 @@ is_valid_cert_without_private_key(CERTCertificate *cert, void *data) + + errnum = PORT_GetError(); + if (errnum == SEC_ERROR_EXTENSION_NOT_FOUND) { +- dprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); ++ dbgprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); + PORT_SetError(0); + errnum = 0; + } +@@ -467,23 +467,23 @@ unescape_html_in_place(char *s) + size_t pos = 0; + char *s1; + +- dprintf("unescaping pos:%zd sz:%zd \"%s\"", pos, sz, s); ++ dbgprintf("unescaping pos:%zd sz:%zd \"%s\"", pos, sz, s); + do { + s1 = strchrnul(&s[pos], '%'); + if (s1[0] == '\0') + break; +- dprintf("s1 is \"%s\"", s1); ++ dbgprintf("s1 is \"%s\"", s1); + if ((size_t)(s1 - s) < (size_t)(sz - 3)) { + int c; + + c = (hexchar_to_bin(s1[1]) << 4) + | (hexchar_to_bin(s1[2]) & 0xf); +- dprintf("replacing %%%c%c with 0x%02hhx", s1[1], s1[2], (char)c); ++ dbgprintf("replacing %%%c%c with 0x%02hhx", s1[1], s1[2], (char)c); + s1[0] = c; + memmove(&s1[1], &s1[3], sz - (&s1[3] - s)); + sz -= 2; + pos = &s1[1] - s; +- dprintf("new pos:%zd sz:%zd s:\"%s\"", pos, sz, s); ++ dbgprintf("new pos:%zd sz:%zd s:\"%s\"", pos, sz, s); + } + } while (pos < sz); + } +@@ -499,7 +499,7 @@ resolve_pkcs11_token_in_place(char *tokenname) + char c = *cp; + *cp = '\0'; + +- dprintf("ntn:\"%s\"", ntn); ++ dbgprintf("ntn:\"%s\"", ntn); + if (!strncmp(&ntn[pos], "token=", 6)) { + ntn += 6; + memmove(tokenname, ntn, cp - ntn + 1); +@@ -510,13 +510,13 @@ resolve_pkcs11_token_in_place(char *tokenname) + ntn = cp + (c ? 1 : 0); + } + unescape_html_in_place(tokenname); +- dprintf("token name is \"%s\"", tokenname); ++ dbgprintf("token name is \"%s\"", tokenname); + } + + #define resolve_token_name(tn) ({ \ + char *s_ = tn; \ + if (!strncmp(tn, "pkcs11:", 7)) { \ +- dprintf("provided token name is pkcs11 uri; parsing"); \ ++ dbgprintf("provided token name is pkcs11 uri; parsing");\ + s_ = strdupa(tn+7); \ + resolve_pkcs11_token_in_place(s_); \ + } \ +@@ -528,7 +528,8 @@ unlock_nss_token(cms_context *cms) + { + char *tokenname = resolve_token_name(cms->tokenname); + +- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); ++ dbgprintf("setting password function to %s", ++ cms->func ? "cms->func" : "SECU_GetModulePassword"); + PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); + + PK11SlotList *slots = NULL; +@@ -592,7 +593,8 @@ find_certificate(cms_context *cms, int needs_private_key) + return -1; + } + +- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); ++ dbgprintf("setting password function to %s", ++ cms->func ? "cms->func" : "SECU_GetModulePassword"); + PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); + + PK11SlotList *slots = NULL; +@@ -610,10 +612,10 @@ find_certificate(cms_context *cms, int needs_private_key) + } + + while (psle) { +- dprintf("looking for token \"%s\", got \"%s\"", +- tokenname, PK11_GetTokenName(psle->slot)); ++ dbgprintf("looking for token \"%s\", got \"%s\"", ++ tokenname, PK11_GetTokenName(psle->slot)); + if (!strcmp(tokenname, PK11_GetTokenName(psle->slot))) { +- dprintf("found token \"%s\"", tokenname); ++ dbgprintf("found token \"%s\"", tokenname); + break; + } + +@@ -673,8 +675,9 @@ find_certificate(cms_context *cms, int needs_private_key) + psle->slot, is_valid_cert, &cbd); + errnum = PORT_GetError(); + if (errnum) +- dprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", +- PORT_ErrorToName(errnum), PORT_ErrorToString(errnum)); ++ dbgprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", ++ PORT_ErrorToName(errnum), ++ PORT_ErrorToString(errnum)); + } else { + status = PK11_TraverseCertsForNicknameInSlot(&nickname, + psle->slot, +@@ -682,28 +685,30 @@ find_certificate(cms_context *cms, int needs_private_key) + &cbd); + errnum = PORT_GetError(); + if (errnum) +- dprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", +- PORT_ErrorToName(errnum), PORT_ErrorToString(errnum)); ++ dbgprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", ++ PORT_ErrorToName(errnum), ++ PORT_ErrorToString(errnum)); + } +- dprintf("status:%d cbd.cert:%p", status, cbd.cert); ++ dbgprintf("status:%d cbd.cert:%p", status, cbd.cert); + if (status == SECSuccess && cbd.cert != NULL) { + if (cms->cert) + CERT_DestroyCertificate(cms->cert); + cms->cert = CERT_DupCertificate(cbd.cert); + } else { + errnum = PORT_GetError(); +- dprintf("token traversal %s; cert %sfound:%s:%s", +- status == SECSuccess ? "succeeded" : "failed", +- cbd.cert == NULL ? "not" : "", +- PORT_ErrorToName(errnum), PORT_ErrorToString(errnum)); ++ dbgprintf("token traversal %s; cert %sfound:%s:%s", ++ status == SECSuccess ? "succeeded" : "failed", ++ cbd.cert == NULL ? "not" : "", ++ PORT_ErrorToName(errnum), ++ PORT_ErrorToString(errnum)); + } + + save_port_err() { +- dprintf("Destroying cert list"); ++ dbgprintf("Destroying cert list"); + CERT_DestroyCertList(certlist); +- dprintf("Destroying slot list element"); ++ dbgprintf("Destroying slot list element"); + PK11_DestroySlotListElement(slots, &psle); +- dprintf("Destroying slot list"); ++ dbgprintf("Destroying slot list"); + PK11_FreeSlotList(slots); + cms->psle = NULL; + } +@@ -723,7 +728,8 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot) + + char *tokenname = resolve_token_name(cms->tokenname); + +- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); ++ dbgprintf("setting password function to %s", ++ cms->func ? "cms->func" : "SECU_GetModulePassword"); + PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); + + PK11SlotList *slots = NULL; +@@ -792,7 +798,8 @@ find_certificate_by_callback(cms_context *cms, + return -1; + } + +- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); ++ dbgprintf("setting password function to %s", ++ cms->func ? "cms->func" : "SECU_GetModulePassword"); + PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); + + PK11SlotList *slots = NULL; +diff --git a/src/cms_pe_common.c b/src/cms_pe_common.c +index 3a3921b..fb90ecb 100644 +--- a/src/cms_pe_common.c ++++ b/src/cms_pe_common.c +@@ -188,8 +188,8 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + } + if (!check_pointer_and_size(cms, pe, hash_base, hash_size)) + cmsgotoerr(error, cms, "PE header is invalid"); +- dprintf("beginning of hash"); +- dprintf("digesting %tx + %zx", hash_base - map, hash_size); ++ dbgprintf("beginning of hash"); ++ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); + generate_digest_step(cms, hash_base, hash_size); + + /* 5. Skip over the image checksum +@@ -209,7 +209,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + cmsgotoerr(error, cms, "PE data directory is invalid"); + + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %tx + %zx", hash_base - map, hash_size); ++ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); + + /* 8. Skip over the crt dir + * 9. Hash everything up to the end of the image header. */ +@@ -222,7 +222,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + cmsgotoerr(error, cms, "PE relocations table is invalid"); + + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %tx + %zx", hash_base - map, hash_size); ++ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); + + /* 10. Set SUM_OF_BYTES_HASHED to the size of the header. */ + hashed_bytes = pe32opthdr ? pe32opthdr->header_size +@@ -256,16 +256,16 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + char *name = shdrs[i].name; + if (name && name[0] == '/') + name = get_str(cms, pe, name + 1); +- dprintf("section:\"%s\"", name ? name : "(null)"); ++ dbgprintf("section:\"%s\"", name ? name : "(null)"); + if (name && !strcmp(name, ".vendor_cert")) { +- dprintf("skipping .vendor_cert section"); ++ dbgprintf("skipping .vendor_cert section"); + hashed_bytes += hash_size; + continue; + } + } + + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %tx + %zx", hash_base - map, hash_size); ++ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); + + hashed_bytes += hash_size; + } +@@ -285,15 +285,15 @@ generate_digest(cms_context *cms, Pe *pe, int padded) + memset(tmp_array, '\0', tmp_size); + memcpy(tmp_array, hash_base, hash_size); + generate_digest_step(cms, tmp_array, tmp_size); +- dprintf("digesting %tx + %zx", (ptrdiff_t)tmp_array, ++ dbgprintf("digesting %tx + %zx", (ptrdiff_t)tmp_array, + tmp_size); + } else { + generate_digest_step(cms, hash_base, hash_size); +- dprintf("digesting %tx + %zx", hash_base - map, ++ dbgprintf("digesting %tx + %zx", hash_base - map, + hash_size); + } + } +- dprintf("end of hash"); ++ dbgprintf("end of hash"); + + rc = generate_digest_finish(cms); + if (rc < 0) +diff --git a/src/efikeygen.c b/src/efikeygen.c +index 940fdf5..dd40502 100644 +--- a/src/efikeygen.c ++++ b/src/efikeygen.c +@@ -1067,9 +1067,9 @@ int main(int argc, char *argv[]) + + errno = 0; + timeul = strtoul(not_valid_before, &endptr, 0); +- dprintf("not_valid_before:%lu", timeul); ++ dbgprintf("not_valid_before:%lu", timeul); + if (errno == 0 && endptr && *endptr == 0) { +- dprintf("not_valid_before:%lu", timeul); ++ dbgprintf("not_valid_before:%lu", timeul); + not_before = (PRTime)timeul * PR_USEC_PER_SEC; + } else { + prstatus = PR_ParseTimeString(not_valid_before, +@@ -1078,7 +1078,7 @@ int main(int argc, char *argv[]) + "could not parse date \"%s\"", + not_valid_before); + } +- dprintf("not_before:%"PRId64, not_before); ++ dbgprintf("not_before:%"PRId64, not_before); + } + + if (not_valid_after) { +@@ -1086,11 +1086,11 @@ int main(int argc, char *argv[]) + char *endptr; + + errno = 0; +- dprintf("not_valid_after:%s", not_valid_after); ++ dbgprintf("not_valid_after:%s", not_valid_after); + timeul = strtoul(not_valid_after, &endptr, 0); +- dprintf("not_valid_after:%lu", timeul); ++ dbgprintf("not_valid_after:%lu", timeul); + if (errno == 0 && endptr && *endptr == 0) { +- dprintf("not_valid_after:%lu", timeul); ++ dbgprintf("not_valid_after:%lu", timeul); + not_after = (PRTime)timeul * PR_USEC_PER_SEC; + } else { + prstatus = PR_ParseTimeString(not_valid_after, PR_TRUE, +@@ -1102,10 +1102,10 @@ int main(int argc, char *argv[]) + } else { + // Mon Jan 19 03:14:07 GMT 2037, aka 0x7fffffff minus 1 year. + time_t time = 0x7ffffffful - 60ul * 60 * 24 * 365; +- dprintf("not_valid_after:%lu", time); ++ dbgprintf("not_valid_after:%lu", time); + not_after = (PRTime)time * PR_USEC_PER_SEC; + } +- dprintf("not_after:%"PRId64, not_after); ++ dbgprintf("not_after:%"PRId64, not_after); + + CERTValidity *validity = NULL; + validity = CERT_CreateValidity(not_before, not_after); +diff --git a/src/file_pe.c b/src/file_pe.c +index fa97b89..fed6edb 100644 +--- a/src/file_pe.c ++++ b/src/file_pe.c +@@ -264,7 +264,8 @@ pe_handle_action(pesign_context *ctxp, int action, int padding) + /* generate a signature and save it in a separate file */ + case EXPORT_SIGNATURE|GENERATE_SIGNATURE: + perr = PORT_GetError(); +- dprintf("PORT_GetError():%s:%s", PORT_ErrorToName(perr), PORT_ErrorToString(perr)); ++ dbgprintf("PORT_GetError():%s:%s", ++ PORT_ErrorToName(perr), PORT_ErrorToString(perr)); + PORT_SetError(0); + rc = find_certificate(ctxp->cms_ctx, 1); + conderrx(rc < 0, 1, "Could not find certificate %s", +@@ -281,7 +282,8 @@ pe_handle_action(pesign_context *ctxp, int action, int padding) + case IMPORT_SIGNATURE|GENERATE_SIGNATURE: + check_inputs(ctxp); + perr = PORT_GetError(); +- dprintf("PORT_GetError():%s:%s", PORT_ErrorToName(perr), PORT_ErrorToString(perr)); ++ dbgprintf("PORT_GetError():%s:%s", ++ PORT_ErrorToName(perr), PORT_ErrorToString(perr)); + rc = find_certificate(ctxp->cms_ctx, 1); + conderrx(rc < 0, 1, "Could not find certificate %s", + ctxp->cms_ctx->certname); +diff --git a/src/password.c b/src/password.c +index 05add9a..18c32ed 100644 +--- a/src/password.c ++++ b/src/password.c +@@ -167,7 +167,7 @@ SECU_GetPasswordString(void *arg UNUSED, char *prompt) + char *ret; + ingress(); + ret = get_password(stdin, stdout, prompt, NULL); +- dprintf("password:\"%s\"", ret ? ret : "(null)"); ++ dbgprintf("password:\"%s\"", ret ? ret : "(null)"); + egress(); + return ret; + } +@@ -194,7 +194,7 @@ parse_pwfile_line(char *start, struct token_pass *tp) + size_t offset = 0; + + span = strspn(line, whitespace_and_eol_chars); +- dprintf("whitespace span is %zd", span); ++ dbgprintf("whitespace span is %zd", span); + if (span == 0 && line[span] == '\0') + return -1; + line += span; +@@ -210,17 +210,17 @@ parse_pwfile_line(char *start, struct token_pass *tp) + offset += escspan + 2; + } while(escspan < span); + span += offset; +- dprintf("non-whitespace span is %zd", span); ++ dbgprintf("non-whitespace span is %zd", span); + + if (line[span] == '\0') { +- dprintf("returning %td", (line + span) - start); ++ dbgprintf("returning %td", (line + span) - start); + return (line + span) - start; + } + line[span] = '\0'; + + line += span + 1; + span = strspn(line, whitespace_and_eol_chars); +- dprintf("whitespace span is %zd", span); ++ dbgprintf("whitespace span is %zd", span); + line += span; + tp->token = tp->pass; + tp->pass = line; +@@ -233,15 +233,15 @@ parse_pwfile_line(char *start, struct token_pass *tp) + offset += escspan + 2; + } while(escspan < span); + span += offset; +- dprintf("non-whitespace span is %zd", span); ++ dbgprintf("non-whitespace span is %zd", span); + if (line[span] != '\0') + line[span++] = '\0'; + + resolve_escapes(tp->token); +- dprintf("Setting token pass %p to { %p, %p }", tp, tp->token, tp->pass); +- dprintf("token:\"%s\"", tp->token); +- dprintf("pass:\"%s\"", tp->pass); +- dprintf("returning %td", (line + span) - start); ++ dbgprintf("Setting token pass %p to { %p, %p }", tp, tp->token, tp->pass); ++ dbgprintf("token:\"%s\"", tp->token); ++ dbgprintf("pass:\"%s\"", tp->pass); ++ dbgprintf("returning %td", (line + span) - start); + return (line + span) - start; + } + +@@ -260,7 +260,7 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) + char *path; + + ingress(); +- dprintf("token_name: %s", token_name); ++ dbgprintf("token_name: %s", token_name); + if (cms->pwdata.source != PW_FROMFILEDB) { + cms->log(cms, LOG_ERR, + "Got to %s() but no file is specified.\n", +@@ -289,8 +289,8 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) + if (rc < 0 || file_len < 1) + goto err_file; + file[file_len-1] = '\0'; +- dprintf("file_len:%zd", file_len); +- dprintf("file:\"%s\"", file); ++ dbgprintf("file_len:%zd", file_len); ++ dbgprintf("file:\"%s\"", file); + + unbreak_line_continuations(file, file_len); + } +@@ -314,23 +314,23 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) + #pragma GCC diagnostic pop + + span = strspn(start, whitespace_and_eol_chars); +- dprintf("whitespace span is %zd", span); ++ dbgprintf("whitespace span is %zd", span); + start += span; + span = strcspn(start, eol_chars); +- dprintf("non-whitespace span is %zd", span); ++ dbgprintf("non-whitespace span is %zd", span); + + c = start[span]; + start[span] = '\0'; +- dprintf("file:\"%s\"", file); ++ dbgprintf("file:\"%s\"", file); + rc = parse_pwfile_line(start, &phrases[nphrases++]); +- dprintf("parse_pwfile_line returned %d", rc); ++ dbgprintf("parse_pwfile_line returned %d", rc); + if (rc < 0) + goto err_phrases; + + if (c != '\0') + span++; + start += span; +- dprintf("start is file[%td] == '\\x%02hhx'", start - file, ++ dbgprintf("start is file[%td] == '\\x%02hhx'", start - file, + start[0]); + } + +@@ -359,7 +359,7 @@ err_file: + err_phrases: + xfree(phrases); + err: +- dprintf("ret:\"%s\"", ret ? ret : "(null)"); ++ dbgprintf("ret:\"%s\"", ret ? ret : "(null)"); + egress(); + return ret; + } +@@ -412,10 +412,10 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) + ingress(); + + if (PK11_ProtectedAuthenticationPath(slot)) { +- dprintf("prompting for PW_DEVICE data"); ++ dbgprintf("prompting for PW_DEVICE data"); + pwdata = &pwxtrn; + } else { +- dprintf("using pwdata from cms"); ++ dbgprintf("using pwdata from cms"); + pwdata = &cms->pwdata; + } + +@@ -423,17 +423,17 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) + pwdata->source >= PW_SOURCE_MAX || + pwdata->orig_source <= PW_SOURCE_INVALID || + pwdata->orig_source >= PW_SOURCE_MAX) { +- dprintf("pwdata is invalid"); ++ dbgprintf("pwdata is invalid"); + return NULL; + } + +- dprintf("pwdata:%p retry:%d", pwdata, retry); +- dprintf("pwdata->source:%s (%d) orig:%s (%d)", +- pw_source_names[pwdata->source], pwdata->source, +- pw_source_names[pwdata->orig_source], pwdata->orig_source); +- dprintf("pwdata->data:%p (\"%s\")", pwdata->data, +- pwdata->data ? pwdata->data : "(null)"); +- dprintf("pwdata->intdata:%ld", pwdata->intdata); ++ dbgprintf("pwdata:%p retry:%d", pwdata, retry); ++ dbgprintf("pwdata->source:%s (%d) orig:%s (%d)", ++ pw_source_names[pwdata->source], pwdata->source, ++ pw_source_names[pwdata->orig_source], pwdata->orig_source); ++ dbgprintf("pwdata->data:%p (\"%s\")", pwdata->data, ++ pwdata->data ? pwdata->data : "(null)"); ++ dbgprintf("pwdata->intdata:%ld", pwdata->intdata); + + if (retry) { + warnx("Incorrect password/PIN entered."); +@@ -470,7 +470,7 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) + + case PW_FROMFILEDB: + case PW_DATABASE: +- dprintf("pwdata->source:%s", pw_source_names[pwdata->source]); ++ dbgprintf("pwdata->source:%s", pw_source_names[pwdata->source]); + /* Instead of opening and closing the file every time, get the pw + * once, then keep it in memory (duh). + */ +@@ -480,17 +480,17 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) + return pw; + + case PW_FROMENV: +- dprintf("pwdata->source:PW_FROMENV"); ++ dbgprintf("pwdata->source:PW_FROMENV"); + if (!pwdata || !pwdata->data) + break; + pw = get_env(pwdata->data); +- dprintf("env:%s pw:%s", pwdata->data, pw ? pw : "(null)"); ++ dbgprintf("env:%s pw:%s", pwdata->data, pw ? pw : "(null)"); + pwdata->data = pw; + pwdata->source = PW_PLAINTEXT; + goto PW_PLAINTEXT; + + case PW_FROMFILE: +- dprintf("pwdata->source:PW_FROMFILE"); ++ dbgprintf("pwdata->source:PW_FROMFILE"); + in = fopen(pwdata->data, "r"); + if (!in) + return NULL; +@@ -501,7 +501,7 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) + goto PW_PLAINTEXT; + + case PW_FROMFD: +- dprintf("pwdata->source:PW_FROMFD"); ++ dbgprintf("pwdata->source:PW_FROMFD"); + rc = pwdata->intdata; + in = fdopen(pwdata->intdata, "r"); + if (!in) +diff --git a/src/pesign.c b/src/pesign.c +index c2ff35f..f548d81 100644 +--- a/src/pesign.c ++++ b/src/pesign.c +@@ -333,7 +333,7 @@ main(int argc, char *argv[]) + while ((rc = poptGetNextOpt(optCon)) > 0) { + switch (rc) { + case POPT_RET_PWDB: +- dprintf("POPT_RET_PWDB:\"%s\"", pwdata.data ? pwdata.data : "(null)"); ++ dbgprintf("POPT_RET_PWDB:\"%s\"", pwdata.data ? pwdata.data : "(null)"); + if (pwdata.source != PW_SOURCE_INVALID) + errx(1, "only one password/pin method can be used at a time"); + if (pwdata.data == NULL) +@@ -346,7 +346,7 @@ main(int argc, char *argv[]) + continue; + + case POPT_RET_ENV: +- dprintf("POPT_RET_ENV:\"%s\"", pwdata.data ? pwdata.data : "(null)"); ++ dbgprintf("POPT_RET_ENV:\"%s\"", pwdata.data ? pwdata.data : "(null)"); + if (pwdata.source != PW_SOURCE_INVALID) + errx(1, "only one password/pin method can be used at a time"); + if (pwdata.data == NULL) +@@ -359,7 +359,7 @@ main(int argc, char *argv[]) + continue; + + case POPT_RET_PINFD: +- dprintf("POPT_RET_PINFD:\"%s\"", pwdata.data ? pwdata.data : "(null)"); ++ dbgprintf("POPT_RET_PINFD:\"%s\"", pwdata.data ? pwdata.data : "(null)"); + if (pwdata.source != PW_SOURCE_INVALID) + errx(1, "only one password/pin method can be used at a time"); + if (pwdata.data == NULL) +@@ -373,7 +373,7 @@ main(int argc, char *argv[]) + continue; + + case POPT_RET_PINFILE: +- dprintf("POPT_RET_PINFILE:\"%s\"", pwdata.data ? pwdata.data : "(null)"); ++ dbgprintf("POPT_RET_PINFILE:\"%s\"", pwdata.data ? pwdata.data : "(null)"); + if (pwdata.source != PW_SOURCE_INVALID) + errx(1, "only one password/pin method can be used at a time"); + if (pwdata.data == NULL) +@@ -387,7 +387,7 @@ main(int argc, char *argv[]) + } + } + +- dprintf("pwdata.source:%d %schecking for PESIGN_TOKEN_PIN", ++ dbgprintf("pwdata.source:%d %schecking for PESIGN_TOKEN_PIN", + pwdata.source, + pwdata.source == PW_SOURCE_INVALID ? "" : "not "); + if (pwdata.source == PW_SOURCE_INVALID && secure_getenv("PESIGN_TOKEN_PIN")) { +diff --git a/src/util.h b/src/util.h +index ba8c621..6616011 100644 +--- a/src/util.h ++++ b/src/util.h +@@ -269,28 +269,28 @@ proxy_fd_mode(int fd, char *infile, mode_t *outmode, size_t *inlength) + + extern long verbosity(void); + +-#define dprintf_(tv, file, func, line, fmt, args...) ({ \ +- struct timeval tv; \ +- gettimeofday(&tv, NULL); \ +- warnx("%ld.%lu %s:%s():%d: " fmt, \ +- tv.tv_sec, tv.tv_usec, \ +- file, func, line, ##args); \ ++#define dbgprintf_(tv, file, func, line, fmt, args...) ({ \ ++ struct timeval tv; \ ++ gettimeofday(&tv, NULL); \ ++ warnx("%ld.%lu %s:%s():%d: " fmt, \ ++ tv.tv_sec, tv.tv_usec, \ ++ file, func, line, ##args); \ + }) + #if defined(PESIGN_DEBUG) +-#define dprintf(fmt, args...) \ +- dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ +- __FILE__, __func__, __LINE__ - 2, fmt, ##args) ++#define dbgprintf(fmt, args...) \ ++ dbgprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ ++ __FILE__, __func__, __LINE__ - 2, fmt, ##args) + #else +-#define dprintf(fmt, args...) ({ \ ++#define dbgprintf(fmt, args...) ({ \ + if (verbosity() > 1) \ +- dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ ++ dbgprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ + __FILE__, __func__, __LINE__ - 3, \ + fmt, ##args); \ + 0; \ + }) + #endif +-#define ingress() dprintf("ingress"); +-#define egress() dprintf("egress"); ++#define ingress() dbgprintf("ingress"); ++#define egress() dbgprintf("egress"); + + #endif /* PESIGN_UTIL_H */ + // vim:fenc=utf-8:tw=75:noet diff --git a/0004-.gitignore-add-compile_commands.json-and-.cache.patch b/0004-.gitignore-add-compile_commands.json-and-.cache.patch new file mode 100644 index 0000000..fb7e7a4 --- /dev/null +++ b/0004-.gitignore-add-compile_commands.json-and-.cache.patch @@ -0,0 +1,30 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Fri, 11 Mar 2022 12:47:20 -0500 +Subject: [PATCH] .gitignore: add compile_commands.json and .cache/ + +These are used by bear/cnc/clangd/etc, but there's no reason to trip +over them all the time. + +Signed-off-by: Peter Jones +--- + .gitignore | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/.gitignore b/.gitignore +index bf0617b..7425432 100644 +--- a/.gitignore ++++ b/.gitignore +@@ -1,3 +1,4 @@ ++.cache/ + .*.d + .*.P + .*.sw? +@@ -26,6 +27,7 @@ + /*.rpm + *-8be4df61-93ca-11d2-aa0d-00e098032b8c + *-d719b2cb-3d3a-4596-a3bc-dad00e67656f ++compile_commands.json + core.* + cov-int/ + pwfile diff --git a/0005-pesign-print-digests-before-filenames-like-sha256sum.patch b/0005-pesign-print-digests-before-filenames-like-sha256sum.patch new file mode 100644 index 0000000..dbce340 --- /dev/null +++ b/0005-pesign-print-digests-before-filenames-like-sha256sum.patch @@ -0,0 +1,31 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Fri, 11 Mar 2022 12:44:46 -0500 +Subject: [PATCH] pesign: print digests before filenames like sha256sum does + +Most digest tools print the digest before the filename, there's no +reason pesign needs to be different. + +Signed-off-by: Peter Jones +--- + src/file_pe.c | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +diff --git a/src/file_pe.c b/src/file_pe.c +index fed6edb..805e614 100644 +--- a/src/file_pe.c ++++ b/src/file_pe.c +@@ -121,12 +121,11 @@ print_digest(pesign_context *pctx) + if (!ctx) + return; + +- printf("%s ", pctx->infile); + int j = ctx->selected_digest; + for (unsigned int i = 0; i < ctx->digests[j].pe_digest->len; i++) + printf("%02x", + (unsigned char)ctx->digests[j].pe_digest->data[i]); +- printf("\n"); ++ printf(" %s\n", pctx->infile); + } + + void diff --git a/0006-Add-pesum-an-authenticode-digest-generator.patch b/0006-Add-pesum-an-authenticode-digest-generator.patch new file mode 100644 index 0000000..10d6fb4 --- /dev/null +++ b/0006-Add-pesum-an-authenticode-digest-generator.patch @@ -0,0 +1,318 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Fri, 11 Mar 2022 12:54:39 -0500 +Subject: [PATCH] Add 'pesum', an authenticode digest generator. + +Signed-off-by: Peter Jones +--- + src/pesum.c | 195 +++++++++++++++++++++++++++++++++++++++++++++++++++++++ + src/.gitignore | 1 + + src/Makefile | 12 +++- + src/pesum.1.mdoc | 38 +++++++++++ + 4 files changed, 244 insertions(+), 2 deletions(-) + create mode 100644 src/pesum.c + create mode 100644 src/pesum.1.mdoc + +diff --git a/src/pesum.c b/src/pesum.c +new file mode 100644 +index 0000000..e4ddaf8 +--- /dev/null ++++ b/src/pesum.c +@@ -0,0 +1,195 @@ ++// SPDX-License-Identifier: GPLv2 ++/* ++ * pesum.c - pesum command line tool ++ * Copyright Peter Jones ++ */ ++ ++#include "fix_coverity.h" ++ ++#include ++#include ++ ++#include ++#include ++ ++#include "pesign.h" ++#include "pesign_standalone.h" ++ ++static struct { ++ int flag; ++ const char *name; ++} flag_names[] = { ++ {DAEMONIZE, "daemonize"}, ++ {GENERATE_DIGEST, "hash"}, ++ {GENERATE_SIGNATURE, "sign"}, ++ {IMPORT_RAW_SIGNATURE, "import-raw-sig"}, ++ {IMPORT_SIGNATURE, "import-sig"}, ++ {IMPORT_SATTRS, "import-sattrs" }, ++ {EXPORT_SATTRS, "export-sattrs" }, ++ {EXPORT_SIGNATURE, "export-sig"}, ++ {EXPORT_PUBKEY, "export-pubkey"}, ++ {EXPORT_CERT, "export-cert"}, ++ {REMOVE_SIGNATURE, "remove"}, ++ {LIST_SIGNATURES, "list"}, ++ {FLAG_LIST_END, NULL}, ++}; ++ ++void ++print_flag_name(FILE *f, int flag) ++{ ++ for (int i = 0; flag_names[i].flag != FLAG_LIST_END; i++) { ++ if (flag_names[i].flag == flag) ++ fprintf(f, "%s ", flag_names[i].name); ++ } ++} ++ ++static long *verbose; ++ ++long ++verbosity(void) ++{ ++ if (!verbose) ++ return 0; ++ return *verbose; ++} ++ ++int ++main(int argc, char *argv[]) ++{ ++ int rc; ++ SECStatus status; ++ ++ char *digest_name = "sha256"; ++ char *orig_digest_name = digest_name; ++ int padding = 1; ++ long verbose_cmd_line = 0; ++ const char *infile; ++ ++ int action = GENERATE_DIGEST|PRINT_DIGEST; ++ file_format fmt = FORMAT_PE_BINARY; ++ ++ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); ++ ++ verbose = &verbose_cmd_line; ++ ++ poptContext optCon; ++ struct poptOption options[] = { ++ {.argInfo = POPT_ARG_INTL_DOMAIN, ++ .arg = "pesum" }, ++ {.longName = "verbose", ++ .shortName = 'v', ++ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL, ++ .arg = &verbose_cmd_line, ++ .val = 1, ++ .descrip = "be more verbose" }, ++ {.longName = "debug", ++ .shortName = '\0', ++ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL, ++ .arg = &verbose_cmd_line, ++ .val = 2, ++ .descrip = "be very verbose" }, ++ {.longName = "digest-type", ++ .shortName = 'd', ++ .argInfo = POPT_ARG_STRING|POPT_ARGFLAG_SHOW_DEFAULT, ++ .arg = &digest_name, ++ .descrip = "digest type to use for pe hash" }, ++ {.longName = "digest_type", ++ .shortName = '\0', ++ .argInfo = POPT_ARG_STRING|POPT_ARGFLAG_DOC_HIDDEN, ++ .arg = &digest_name, ++ .descrip = "digest type to use for pe hash" }, ++ {.longName = "padding", ++ .shortName = 'P', ++ .argInfo = POPT_ARG_VAL, ++ .arg = &padding, ++ .val = 1, ++ .descrip = "pad data section (default)" }, ++ {.longName = "nopadding", ++ .shortName = 'p', ++ .argInfo = POPT_ARG_VAL, ++ .arg = &padding, ++ .val = 0, ++ .descrip = "do not pad the data section" }, ++ POPT_AUTOALIAS ++ POPT_AUTOHELP ++ POPT_TABLEEND ++ }; ++ ++ optCon = poptGetContext("pesum", argc, (const char **)argv, options,0); ++ ++ rc = poptReadDefaultConfig(optCon, 0); ++ if (rc < 0 && !(rc == POPT_ERROR_ERRNO && errno == ENOENT)) ++ errx(1, "poptReadDefaultConfig failed: %s", poptStrerror(rc)); ++ ++ while ((rc = poptGetNextOpt(optCon)) > 0) { ++ ; ++ } ++ ++ if (rc < -1) ++ errx(1, "Invalid argument: %s: %s", ++ poptBadOption(optCon, 0), poptStrerror(rc)); ++ ++ if (!poptPeekArg(optCon)) ++ errx(1, "nothing to do"); ++ ++ status = NSS_NoDB_Init(NULL); ++ if (status != SECSuccess) ++ errx(1, "Could not initialize nss.\n" ++ "NSS says \"%s\" errno says \"%m\"\n", ++ PORT_ErrorToString(PORT_GetError())); ++ ++ while ((infile = poptGetArg(optCon)) != NULL) { ++ pesign_context *ctxp = NULL; ++ ++ char *ext = strrchr(infile, '.'); ++ if (ext && strcmp(ext, ".ko") == 0) ++ fmt = FORMAT_KERNEL_MODULE; ++ ++ rc = pesign_context_new(&ctxp); ++ if (rc < 0) ++ err(1, "Could not initialize context"); ++ ++ ctxp->verbose = verbose_cmd_line; ++ ++ ctxp->hash = 1; ++ ctxp->infile = strdup(infile); ++ if (!ctxp->infile) ++ err(1, "Could not allocate memory"); ++ ++ rc = set_digest_parameters(ctxp->cms_ctx, digest_name); ++ int is_help = strcmp(digest_name, "help") ? 0 : 1; ++ if (rc < 0) { ++ if (!is_help) { ++ fprintf(stderr, "Digest \"%s\" not found.\n", ++ digest_name); ++ } ++ exit(!is_help); ++ } ++ ++ errno = 0; ++ switch (fmt) { ++ case FORMAT_PE_BINARY: ++ pe_handle_action(ctxp, action, padding); ++ break; ++ case FORMAT_KERNEL_MODULE: ++ kmod_handle_action(ctxp, action); ++ break; ++ } ++ ++ pesign_context_free(ctxp); ++ } ++ ++ poptFreeContext(optCon); ++ ++ if (digest_name && digest_name != orig_digest_name) ++ free(digest_name); ++ ++ status = NSS_Shutdown(); ++ if (status != SECSuccess) ++ errx(1, "could not shut down NSS: %s", ++ PORT_ErrorToString(PORT_GetError())); ++ ++ return 0; ++} ++ ++// vim:fenc=utf-8:tw=75:noet +diff --git a/src/.gitignore b/src/.gitignore +index 64ce217..f8f6d66 100644 +--- a/src/.gitignore ++++ b/src/.gitignore +@@ -5,6 +5,7 @@ client + efikeygen + efidbtool + pesigcheck ++pesum + peverify + pesign.service + pesign.sysvinit +diff --git a/src/Makefile b/src/Makefile +index 7010514..79cf09e 100644 +--- a/src/Makefile ++++ b/src/Makefile +@@ -6,7 +6,7 @@ include $(TOPDIR)/Make.rules + include $(TOPDIR)/Make.defaults + + BINTARGETS=authvar client efikeygen pesigcheck pesign \ +- pesign-rpmbuild-helper pesign-authorize ++ pesign-rpmbuild-helper pesign-authorize pesum + CFGTARGETS=tmpfiles.conf + SVCTARGETS=pesign.sysvinit pesign.service + MAN1TARGETS=authvar.1 efikeygen.1 pesigcheck.1 pesign-client.1 pesign.1 +@@ -29,9 +29,12 @@ EFIKEYGEN_SOURCES = efikeygen.c + PESIGCHECK_SOURCES = pesigcheck.c pesigcheck_context.c certdb.c + PESIGN_SOURCES = pesign.c pesign_context.c actions.c daemon.c \ + file_pe.c file_kmod.c pesign_kmod.c ++PESUM_SOURCES = pesum.c pesign_context.c actions.c \ ++ file_pe.c file_kmod.c pesign_kmod.c + + ALL_SOURCES=$(COMMON_SOURCES) $(AUTHVAR_SORUCES) $(CLIENT_SOURCES) \ +- $(EFIKEYGEN_SOURCES) $(PESIGCHECK_SOURCES) $(PESIGN_SOURCES) ++ $(EFIKEYGEN_SOURCES) $(PESIGCHECK_SOURCES) $(PESIGN_SOURCES) \ ++ $(PESUM_SOURCES) + -include $(call deps-of,$(ALL_SOURCES)) + + authvar : $(call objects-of,$(AUTHVAR_SOURCES) $(COMMON_SOURCES)) +@@ -53,6 +56,10 @@ pesign : $(call objects-of,$(PESIGN_SOURCES) $(COMMON_SOURCES) $(COMMON_PE_SOURC + pesign : LDLIBS+=$(TOPDIR)/libdpe/libdpe.a + pesign : PKGS=efivar nss nspr popt + ++pesum : $(call objects-of,$(PESUM_SOURCES) $(COMMON_SOURCES) $(COMMON_PE_SOURCES)) ++pesum : LDLIBS+=$(TOPDIR)/libdpe/libdpe.a ++pesum : PKGS=efivar nss nspr popt ++ + deps : PKGS=efivar nss nspr popt uuid + deps : $(ALL_SOURCES) + $(MAKE) -f $(TOPDIR)/Make.deps \ +@@ -81,6 +88,7 @@ install : + $(INSTALL) -d -m 755 $(INSTALLROOT)$(bindir) + $(INSTALL) -m 755 authvar $(INSTALLROOT)$(bindir) + $(INSTALL) -m 755 pesign $(INSTALLROOT)$(bindir) ++ $(INSTALL) -m 755 pesum $(INSTALLROOT)$(bindir) + $(INSTALL) -m 755 client $(INSTALLROOT)$(bindir)pesign-client + $(INSTALL) -m 755 efikeygen $(INSTALLROOT)$(bindir) + $(INSTALL) -m 755 pesigcheck $(INSTALLROOT)$(bindir) +diff --git a/src/pesum.1.mdoc b/src/pesum.1.mdoc +new file mode 100644 +index 0000000..edd08ce +--- /dev/null ++++ b/src/pesum.1.mdoc +@@ -0,0 +1,38 @@ ++.Dd $Mdocdate: Mar 11 2022$ ++.Dt PESUM 1 ++.Os Linux ++.Sh NAME ++.Nm pesum ++.Nd tool for generating Authenticode digests ++.Sh SYNOPSIS ++.Nm ++.Bk -words ++.Ar file0.efi ++.Op Ar file1.efi ... ++.Sh DESCRIPTION ++.Nm ++is a command line tool to generate Authenticode digests of PE binaries. ++.Sh EXAMPLES ++.Ss Getting the Authenticode digest of some files ++host:$ \fBpesum shimx64.efi grubx64.efi\fR ++8c5806e66bb5b052ebf860e1722474269cff3dde588610df21dbe8cf12c08390\ shimx64.efi ++546a71319c22da1d81879383c4c74be06d1c374bdecfafc9fcc80bd541802bfc\ grubx64.efi ++.Sh STANDARDS ++.Rs ++.%B Portable Executable ++.%I Microsoft ++.%D August 26, 2019 ++.%U https://docs.microsoft.com/en-us/windows/win32/debug/pe-format\ \& ++.Re ++ ++.Rs ++.%B Windows Authenticode Portable Executable Signature Format ++.%I Microsoft ++.%D March 21, 2008 ++.%U https://web.archive.org/web/20130518222430/http://download.microsoft.com/download/9/c/5/9c5b2167-8017-4bae-9fde-d599bac8184a/Authenticode_PE.docx\ \& ++.Re ++.Sh SEE ALSO ++.Xr pesign 1 ++.LP ++.Sh AUTHORS ++.An Peter Jones diff --git a/0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch b/0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch similarity index 97% rename from 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch rename to 0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch index 920eb6a..b342876 100644 --- a/0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch +++ b/0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch @@ -8,7 +8,6 @@ https://bugzilla.redhat.com/show_bug.cgi?id=1880858 Signed-off-by: Julian Sikorski Suggested-by: Will Springer -(cherry picked from commit 9969b1757a1941c9f57081b308026d687f6c0943) --- src/pesign-rpmbuild-helper.in | 24 +++++++++++------------- 1 file changed, 11 insertions(+), 13 deletions(-) diff --git a/0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch b/0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch similarity index 96% rename from 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch rename to 0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch index 0dca694..187a623 100644 --- a/0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch +++ b/0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch @@ -9,7 +9,7 @@ Signed-off-by: Robbie Harwood 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Make.defaults b/Make.defaults -index 130c1ee..4b0e77c 100644 +index 1c18904..05aadd0 100644 --- a/Make.defaults +++ b/Make.defaults @@ -79,7 +79,7 @@ ccldflags = $(cflags) $(CCLDFLAGS) $(LDFLAGS) \ diff --git a/0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch b/0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch similarity index 93% rename from 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch rename to 0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch index 62d1936..68cbe5f 100644 --- a/0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch +++ b/0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch @@ -4,7 +4,6 @@ Date: Tue, 10 Aug 2021 12:39:08 -0400 Subject: [PATCH] macros.pesign: handle centos like rhel with --rhelver Signed-off-by: Peter Jones -(cherry picked from commit a1bc65c8b0fc20dbe9c9714ee3a31937184ba7f6) --- src/macros.pesign | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch b/0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch similarity index 93% rename from 0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch rename to 0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch index 0baddd6..bb4bef2 100644 --- a/0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch +++ b/0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch @@ -6,7 +6,6 @@ Subject: [PATCH] Detect the presence of rpm-sign when checking for "rhel"-ness Signed-off-by: Peter Jones [rharwood: manually reapply to main] Signed-off-by: Robbie Harwood -(cherry picked from commit 17e5878cb087e0a766722d3c487f87c41b318f9a) --- src/pesign-rpmbuild-helper.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/0011-Rename-README-README.md.patch b/0011-Rename-README-README.md.patch new file mode 100644 index 0000000..ff10b8d --- /dev/null +++ b/0011-Rename-README-README.md.patch @@ -0,0 +1,17 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 13 May 2022 15:53:05 -0400 +Subject: [PATCH] Rename README -> README.md + +Rich text will let me compact links. + +Signed-off-by: Robbie Harwood +--- + README => README.md | 0 + 1 file changed, 0 insertions(+), 0 deletions(-) + rename README => README.md (100%) + +diff --git a/README b/README.md +similarity index 100% +rename from README +rename to README.md diff --git a/0012-README.md-show-off-a-bit-more.patch b/0012-README.md-show-off-a-bit-more.patch new file mode 100644 index 0000000..9d624f2 --- /dev/null +++ b/0012-README.md-show-off-a-bit-more.patch @@ -0,0 +1,56 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 13 May 2022 16:09:12 -0400 +Subject: [PATCH] README.md: show off a bit more + +Prominently mention efikeygen and add examples of usage for it and +pesign proper. + +Signed-off-by: Robbie Harwood +--- + README.md | 36 ++++++++++++++++++++++++++++++++---- + 1 file changed, 32 insertions(+), 4 deletions(-) + +diff --git a/README.md b/README.md +index d70bc53..e9f0cb7 100644 +--- a/README.md ++++ b/README.md +@@ -1,6 +1,34 @@ +-Signing tool for PE-COFF binaries, hopefully at least vaguely compliant with +-the PE and Authenticode specifications. ++# pesign + efikeygen + +-This is vaguely analogous to the tool described by +-http://msdn.microsoft.com/en-us/library/8s9b9yaz%28v=vs.80%29.aspx ++Signing tools for PE-COFF binaries. Compliant with the PE and Authenticode ++specifications. + ++(These serve a similar purpose to Microsoft's ++[SignTool.exe](http://msdn.microsoft.com/en-us/library/8s9b9yaz%28v=vs.80%29.aspx), ++except for Linux.) ++ ++## Examples ++ ++Generate a key for use with pesign, stored on disk: ++ ++``` ++efikeyen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' ++``` ++ ++For more complex and secure use cases (e.g., hardware tokens), see ++efikeygen man page (`man efikeygen`). ++ ++Sign a UEFI application using that key: ++ ++``` ++pesign -i grubx64.efi -o grubx64.efi.signed -c 'Custom Secureboot' -s ++``` ++ ++Show signatures on a UEFI application: ++ ++``` ++pesign -i grubx64.efi.signed -S ++``` ++ ++For more signing/verification operations, see the pesign man page (`man ++pesign`). diff --git a/0013-Fix-missing-line-in-README.md.patch b/0013-Fix-missing-line-in-README.md.patch new file mode 100644 index 0000000..185bcc3 --- /dev/null +++ b/0013-Fix-missing-line-in-README.md.patch @@ -0,0 +1,23 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Mon, 16 May 2022 15:31:25 -0400 +Subject: [PATCH] Fix missing line in README.md + +Signed-off-by: Robbie Harwood +--- + README.md | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/README.md b/README.md +index e9f0cb7..7bbd6dd 100644 +--- a/README.md ++++ b/README.md +@@ -15,6 +15,8 @@ Generate a key for use with pesign, stored on disk: + efikeyen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' + ``` + ++(where TYPE is m if you're only signing kernel modules, and k otherwise). ++ + For more complex and secure use cases (e.g., hardware tokens), see + efikeygen man page (`man efikeygen`). + diff --git a/0014-Fix-typo-in-efikeygen-command.patch b/0014-Fix-typo-in-efikeygen-command.patch new file mode 100644 index 0000000..82d228d --- /dev/null +++ b/0014-Fix-typo-in-efikeygen-command.patch @@ -0,0 +1,23 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Matt Bernhard +Date: Fri, 27 May 2022 14:40:49 -0400 +Subject: [PATCH] Fix typo in efikeygen command + +Signed-off-by: Matt Bernhard +--- + README.md | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/README.md b/README.md +index 7bbd6dd..b6949a2 100644 +--- a/README.md ++++ b/README.md +@@ -12,7 +12,7 @@ except for Linux.) + Generate a key for use with pesign, stored on disk: + + ``` +-efikeyen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' ++efikeygen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' + ``` + + (where TYPE is m if you're only signing kernel modules, and k otherwise). diff --git a/0015-pesigcheck-Fix-crash-on-digest-match.patch b/0015-pesigcheck-Fix-crash-on-digest-match.patch new file mode 100644 index 0000000..c948558 --- /dev/null +++ b/0015-pesigcheck-Fix-crash-on-digest-match.patch @@ -0,0 +1,53 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Visa Hankala +Date: Fri, 10 Jun 2022 13:25:13 +0000 +Subject: [PATCH] pesigcheck: Fix crash on digest match + +Set selected_digest when the digest is found in db or dbx. +This fixes the following crash of pesigcheck: + + Program received signal SIGSEGV, Segmentation fault. + 0x00005555555597fa in memcpy (__len=24, __src=0x31, + __dest=0x55555558d908) + at /usr/include/x86_64-linux-gnu/bits/string_fortified.h:34 + 34 return __builtin___memcpy_chk (__dest, __src, __len, __bos0 (__dest)); + (gdb) bt + #0 0x00005555555597fa in memcpy (__len=24, __src=0x31, + __dest=0x55555558d908) + at /usr/include/x86_64-linux-gnu/bits/string_fortified.h:34 + #1 get_digest (digest=digest@entry=0x55555558d908, + ctx=, ctx=) at pesigcheck.c:226 + #2 0x00005555555592fd in check_signature ( + reasons=, nreasons=, + ctx=0x7fffffffded0) at pesigcheck.c:262 + #3 main (argc=, argv=) + at pesigcheck.c:512 + +Signed-off-by: Visa Hankala +--- + src/certdb.c | 8 ++++++-- + 1 file changed, 6 insertions(+), 2 deletions(-) + +diff --git a/src/certdb.c b/src/certdb.c +index e013b9d..69d5daf 100644 +--- a/src/certdb.c ++++ b/src/certdb.c +@@ -267,12 +267,16 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, + + if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { + digest = ctx->cms_ctx->digests[0].pe_digest->data; +- if (memcmp (digest, sig->data, 32) == 0) ++ if (memcmp (digest, sig->data, 32) == 0) { ++ ctx->cms_ctx->selected_digest = 0; + return FOUND; ++ } + } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { + digest = ctx->cms_ctx->digests[1].pe_digest->data; +- if (memcmp (digest, sig->data, 20) == 0) ++ if (memcmp (digest, sig->data, 20) == 0) { ++ ctx->cms_ctx->selected_digest = 1; + return FOUND; ++ } + } + + return NOT_FOUND; diff --git a/0016-cms-store-digest-as-pointer-instead-of-index.patch b/0016-cms-store-digest-as-pointer-instead-of-index.patch new file mode 100644 index 0000000..a7fc4dd --- /dev/null +++ b/0016-cms-store-digest-as-pointer-instead-of-index.patch @@ -0,0 +1,272 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Robbie Harwood +Date: Fri, 10 Jun 2022 14:40:33 -0400 +Subject: [PATCH] cms: store digest as pointer instead of index + +Storage as an index is problematic because the sentinel value -1 was +used, but accesses were unchecked, leading to crashes like that in +3b1031a6b779cb80c11b34eec84c5a0cc215efed ("pesigcheck: Fix crash on +digest match"). By storing a pointer, we get an explicit NULL +dereference: still a crash, but preferred since it's clearer. + +Since the index was previously also used for retrieving digest +parameters, include a pointer to the relevant struct digest_param in the +struct digest. + +Signed-off-by: Robbie Harwood +--- + src/certdb.c | 15 ++++++++------- + src/cms_common.c | 34 ++++++++++------------------------ + src/content_info.c | 4 ++-- + src/file_kmod.c | 2 +- + src/file_pe.c | 9 +++++---- + src/pesigcheck.c | 4 +--- + src/cms_common.h | 13 ++++++++++++- + 7 files changed, 39 insertions(+), 42 deletions(-) + +diff --git a/src/certdb.c b/src/certdb.c +index 69d5daf..f512824 100644 +--- a/src/certdb.c ++++ b/src/certdb.c +@@ -263,18 +263,19 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, + { + efi_guid_t efi_sha256 = efi_guid_sha256; + efi_guid_t efi_sha1 = efi_guid_sha1; +- void *digest; ++ void *digest_data; ++ struct digest *digests = ctx->cms_ctx->digests; + + if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { +- digest = ctx->cms_ctx->digests[0].pe_digest->data; +- if (memcmp (digest, sig->data, 32) == 0) { +- ctx->cms_ctx->selected_digest = 0; ++ digest_data = digests[0].pe_digest->data; ++ if (memcmp (digest_data, sig->data, 32) == 0) { ++ ctx->cms_ctx->selected_digest = &digests[0]; + return FOUND; + } + } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { +- digest = ctx->cms_ctx->digests[1].pe_digest->data; +- if (memcmp (digest, sig->data, 20) == 0) { +- ctx->cms_ctx->selected_digest = 1; ++ digest_data = digests[1].pe_digest->data; ++ if (memcmp (digest_data, sig->data, 20) == 0) { ++ ctx->cms_ctx->selected_digest = &digests[1]; + return FOUND; + } + } +diff --git a/src/cms_common.c b/src/cms_common.c +index 86341ca..2275f67 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -33,15 +33,6 @@ + + #include "hex.h" + +-struct digest_param { +- char *name; +- SECOidTag digest_tag; +- SECOidTag signature_tag; +- SECOidTag digest_encryption_tag; +- const efi_guid_t *efi_guid; +- int size; +-}; +- + static struct digest_param digest_params[] = { + {.name = "sha256", + .digest_tag = SEC_OID_SHA256, +@@ -65,29 +56,25 @@ static int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); + SECOidTag + digest_get_digest_oid(cms_context *cms) + { +- int i = cms->selected_digest; +- return digest_params[i].digest_tag; ++ return cms->selected_digest->digest_params->digest_tag; + } + + SECOidTag + digest_get_encryption_oid(cms_context *cms) + { +- int i = cms->selected_digest; +- return digest_params[i].digest_encryption_tag; ++ return cms->selected_digest->digest_params->digest_encryption_tag; + } + + SECOidTag + digest_get_signature_oid(cms_context *cms) + { +- int i = cms->selected_digest; +- return digest_params[i].signature_tag; ++ return cms->selected_digest->digest_params->signature_tag; + } + + int + digest_get_digest_size(cms_context *cms) + { +- int i = cms->selected_digest; +- return digest_params[i].size; ++ return cms->selected_digest->digest_params->size; + } + + void +@@ -142,8 +129,6 @@ cms_context_init(cms_context *cms) + if (!cms->arena) + cnreterr(-1, cms, "could not create cryptographic arena"); + +- cms->selected_digest = -1; +- + INIT_LIST_HEAD(&cms->pk12_ins); + cms->pk12_out.fd = -1; + cms->db_out = cms->dbx_out = cms->dbt_out = -1; +@@ -226,7 +211,7 @@ cms_context_fini(cms_context *cms) + memset(&cms->newsig, '\0', sizeof (cms->newsig)); + } + +- cms->selected_digest = -1; ++ cms->selected_digest = NULL; + + if (cms->ci_digest) { + free_poison(cms->ci_digest->data, cms->ci_digest->len); +@@ -351,7 +336,7 @@ set_digest_parameters(cms_context *cms, char *name) + if (strcmp(name, "help")) { + for (int i = 0; i < n_digest_params; i++) { + if (!strcmp(name, digest_params[i].name)) { +- cms->selected_digest = i; ++ cms->selected_digest = &cms->digests[i]; + return 0; + } + } +@@ -1279,6 +1264,7 @@ generate_digest_begin(cms_context *cms) + cngotoerr(err, cms, "could not create digest context"); + + PK11_DigestBegin(digests[i].pk11ctx); ++ digests[i].digest_params = &digest_params[i]; + } + + cms->digests = digests; +@@ -1351,11 +1337,11 @@ generate_signature(cms_context *cms) + { + int rc = 0; + +- if (cms->digests[cms->selected_digest].pe_digest == NULL) ++ if (cms->selected_digest->pe_digest == NULL) + cnreterr(-1, cms, "PE digest has not been allocated"); + +- if (content_is_empty(cms->digests[cms->selected_digest].pe_digest->data, +- cms->digests[cms->selected_digest].pe_digest->len)) ++ if (content_is_empty(cms->selected_digest->pe_digest->data, ++ cms->selected_digest->pe_digest->len)) + cnreterr(-1, cms, "PE binary has not been digested"); + + SECItem sd_der; +diff --git a/src/content_info.c b/src/content_info.c +index 9684850..777aa28 100644 +--- a/src/content_info.c ++++ b/src/content_info.c +@@ -181,8 +181,8 @@ generate_spc_digest_info(cms_context *cms, SECItem *dip) + if (generate_algorithm_id(cms, &di.digestAlgorithm, + digest_get_digest_oid(cms)) < 0) + return -1; +- int i = cms->selected_digest; +- memcpy(&di.digest, cms->digests[i].pe_digest, sizeof (di.digest)); ++ memcpy(&di.digest, cms->selected_digest->pe_digest, ++ sizeof(di.digest)); + + if (content_is_empty(di.digest.data, di.digest.len)) { + cms->log(cms, LOG_ERR, "got empty digest"); +diff --git a/src/file_kmod.c b/src/file_kmod.c +index 6880cda..c8875fc 100644 +--- a/src/file_kmod.c ++++ b/src/file_kmod.c +@@ -60,7 +60,7 @@ ssize_t + kmod_write_signature(cms_context *cms, int outfd) + { + SEC_PKCS7ContentInfo *cinfo; +- SECItem *digest = cms->digests[cms->selected_digest].pe_digest; ++ SECItem *digest = cms->selected_digest->pe_digest; + SECStatus rv; + struct write_sig_info info = { + .outfd = outfd, +diff --git a/src/file_pe.c b/src/file_pe.c +index 805e614..c22b2af 100644 +--- a/src/file_pe.c ++++ b/src/file_pe.c +@@ -114,6 +114,8 @@ check_inputs(pesign_context *ctx) + static void + print_digest(pesign_context *pctx) + { ++ unsigned int i; ++ + if (!pctx) + return; + +@@ -121,10 +123,9 @@ print_digest(pesign_context *pctx) + if (!ctx) + return; + +- int j = ctx->selected_digest; +- for (unsigned int i = 0; i < ctx->digests[j].pe_digest->len; i++) +- printf("%02x", +- (unsigned char)ctx->digests[j].pe_digest->data[i]); ++ unsigned char *ddata = ctx->selected_digest->pe_digest->data; ++ for (i = 0; i < ctx->selected_digest->pe_digest->len; i++) ++ printf("%02x", ddata[i]); + printf(" %s\n", pctx->infile); + } + +diff --git a/src/pesigcheck.c b/src/pesigcheck.c +index 6dc67f7..ebb404d 100644 +--- a/src/pesigcheck.c ++++ b/src/pesigcheck.c +@@ -221,9 +221,7 @@ static void + get_digest(pesigcheck_context *ctx, SECItem *digest) + { + struct cms_context *cms = ctx->cms_ctx; +- struct digest *cms_digest = &cms->digests[cms->selected_digest]; +- +- memcpy(digest, cms_digest->pe_digest, sizeof (*digest)); ++ memcpy(digest, cms->selected_digest->pe_digest, sizeof(*digest)); + } + + static int +diff --git a/src/cms_common.h b/src/cms_common.h +index c7acbcf..c7d4f69 100644 +--- a/src/cms_common.h ++++ b/src/cms_common.h +@@ -12,6 +12,7 @@ + #include + + #include ++#include + #include + #include + #include +@@ -57,9 +58,19 @@ + goto errlabel; \ + }) + ++struct digest_param { ++ char *name; ++ SECOidTag digest_tag; ++ SECOidTag signature_tag; ++ SECOidTag digest_encryption_tag; ++ const efi_guid_t *efi_guid; ++ int size; ++}; ++ + struct digest { + PK11Context *pk11ctx; + SECItem *pe_digest; ++ struct digest_param *digest_params; + }; + + typedef struct pk12_file { +@@ -133,7 +144,7 @@ typedef struct cms_context { + int db_out, dbx_out, dbt_out; + + struct digest *digests; +- int selected_digest; ++ struct digest *selected_digest; + int omit_vendor_cert; + + SECItem newsig; diff --git a/0006-Fix-mandoc-invocation-to-not-produce-garbage.patch b/0017-Fix-mandoc-invocation-to-not-produce-garbage.patch similarity index 93% rename from 0006-Fix-mandoc-invocation-to-not-produce-garbage.patch rename to 0017-Fix-mandoc-invocation-to-not-produce-garbage.patch index fb105df..648055e 100644 --- a/0006-Fix-mandoc-invocation-to-not-produce-garbage.patch +++ b/0017-Fix-mandoc-invocation-to-not-produce-garbage.patch @@ -12,7 +12,6 @@ feed this into man(1). Tell mandoc explicitly to produce man pages. Signed-off-by: Robbie Harwood -(cherry picked from commit 102c3d1d81c090750abb3815481d5cfd3e596677) --- Make.rules | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch b/0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch new file mode 100644 index 0000000..3d0fd63 --- /dev/null +++ b/0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch @@ -0,0 +1,41 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 29 Aug 2022 15:31:52 -0400 +Subject: [PATCH] Work around GCC being obnoxiously incompatible with GCC + +GCC added and then later removed the diagnostic flag +"-Wanalyzer-use-of-uninitialized-value", and so this doesn't work with +newer versions of GCC. + +This patch removes the previous workaround for when it didn't work well. +I really wish any of our compilers had any sense of rigor with this +stuff at all. + +Signed-off-by: Peter Jones +--- + src/daemon.c | 5 ----- + 1 file changed, 5 deletions(-) + +diff --git a/src/daemon.c b/src/daemon.c +index ff88210..d66dd50 100644 +--- a/src/daemon.c ++++ b/src/daemon.c +@@ -917,10 +917,6 @@ do_shutdown(context *ctx, int nsockets, struct pollfd *pollfds) + free(pollfds); + } + +-/* GCC -fanalyzer has trouble with realloc +- * https://bugzilla.redhat.com/show_bug.cgi?id=2047926 */ +-#pragma GCC diagnostic push +-#pragma GCC diagnostic ignored "-Wanalyzer-use-of-uninitialized-value" + static int + handle_events(context *ctx) + { +@@ -999,7 +995,6 @@ shutdown: + } + return 0; + } +-#pragma GCC diagnostic pop + + static int + get_uid_and_gid(context *ctx, char **homedir) diff --git a/0019-get_password_passthrough-handle-the-callback-context.patch b/0019-get_password_passthrough-handle-the-callback-context.patch new file mode 100644 index 0000000..3240a32 --- /dev/null +++ b/0019-get_password_passthrough-handle-the-callback-context.patch @@ -0,0 +1,51 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 29 Aug 2022 14:21:44 -0400 +Subject: [PATCH] get_password_passthrough(): handle the callback context right + +Right now, we have a few callback functions for PK11_Authenticate(), and +they take different arguments. This is incorrect; none of the callers +ever pass anything through except our CMS context. + +This fixes get_password_passthrough() to correctly accept the CMS +context and get the passthrough data from cms->pwdata instead of trying +to treat the CMS context as the pwdata. + +Related: rhbz#2122777 + +Signed-off-by: Peter Jones +--- + src/password.c | 16 +++++++++++++--- + 1 file changed, 13 insertions(+), 3 deletions(-) + +diff --git a/src/password.c b/src/password.c +index 18c32ed..8eb1c33 100644 +--- a/src/password.c ++++ b/src/password.c +@@ -365,13 +365,23 @@ err: + } + + char * +-get_password_passthrough(PK11SlotInfo *slot UNUSED, +- PRBool retry, void *arg) ++get_password_passthrough(PK11SlotInfo *slot UNUSED, PRBool retry, void *arg) + { ++ cms_context *cms; ++ secuPWData *pwdata; ++ ++ dbgprintf("ctx:%p", arg); ++ + if (retry || !arg) + return NULL; + +- char *ret = strdup(arg); ++ cms = (cms_context *)arg; ++ pwdata = &cms->pwdata; ++ ++ if (pwdata->source != PW_PLAINTEXT) ++ return NULL; ++ ++ char *ret = strdup(pwdata->data); + if (!ret) + err(1, "Could not allocate memory"); + diff --git a/0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch b/0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch new file mode 100644 index 0000000..b69d5ff --- /dev/null +++ b/0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch @@ -0,0 +1,47 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 29 Aug 2022 15:22:10 -0400 +Subject: [PATCH] read_password(): only prune CR/NL from the end of the file + +Right now, when we read the password/PIN from a file, we're pruning the +end of the string from the file we read indiscriminately. If you don't +have a newline, that means we're cutting off the final digits of the +text. + +This changes it to prune only common special characters from the +pinfile, but also to prune /all/ of them. + +Related: rhbz#2122777 +Signed-off-by: Peter Jones +--- + src/password.c | 10 +++++++++- + 1 file changed, 9 insertions(+), 1 deletion(-) + +diff --git a/src/password.c b/src/password.c +index 8eb1c33..ac1866e 100644 +--- a/src/password.c ++++ b/src/password.c +@@ -79,6 +79,7 @@ read_password(FILE *in, FILE *out, char *buf, size_t bufsz) + int infd = fileno(in); + struct termios tio; + char *ret; ++ int len; + + ingress(); + ret = fgets(buf, bufsz, in); +@@ -96,7 +97,14 @@ read_password(FILE *in, FILE *out, char *buf, size_t bufsz) + if (ret == NULL) + return -1; + +- buf[strlen(buf)-1] = '\0'; ++ len = strlen(buf); ++ while (len > 0 && (buf[len-1] == '\r' || buf[len-1] == '\n')) { ++ buf[len-1] = '\0'; ++ len--; ++ } ++ if (len == 0) ++ return -1; ++ + egress(); + return 0; + } diff --git a/0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch b/0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch new file mode 100644 index 0000000..ac9bdfd --- /dev/null +++ b/0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch @@ -0,0 +1,276 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 29 Aug 2022 16:22:18 -0400 +Subject: [PATCH] Revert "cms: store digest as pointer instead of index" + +In 926782c216532a83f9ff864dee39d2349d61fd23, we switched +cms->selected_digest to be a pointer to the member of the digests array +rather than an index. Unfortunately this is just as bad, because the +bugs that come up wind up setting pointers to NULL+(selected*offset), +i.e. 0x10, and that doesn't get us any closer to actually finding any +problem. + +For now, the new approach is going to be to make it an index again, but +to default it to 0 (sha256) rather than -1, so if it isn't set at the +correct part of the lifecycle it'll just default to the (nearly always) +correct choice. + +This reverts commit 926782c216532a83f9ff864dee39d2349d61fd23. + +Signed-off-by: Peter Jones +--- + src/certdb.c | 15 +++++++-------- + src/cms_common.c | 34 ++++++++++++++++++++++++---------- + src/content_info.c | 4 ++-- + src/file_kmod.c | 2 +- + src/file_pe.c | 9 ++++----- + src/pesigcheck.c | 4 +++- + src/cms_common.h | 13 +------------ + 7 files changed, 42 insertions(+), 39 deletions(-) + +diff --git a/src/certdb.c b/src/certdb.c +index f512824..69d5daf 100644 +--- a/src/certdb.c ++++ b/src/certdb.c +@@ -263,19 +263,18 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, + { + efi_guid_t efi_sha256 = efi_guid_sha256; + efi_guid_t efi_sha1 = efi_guid_sha1; +- void *digest_data; +- struct digest *digests = ctx->cms_ctx->digests; ++ void *digest; + + if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { +- digest_data = digests[0].pe_digest->data; +- if (memcmp (digest_data, sig->data, 32) == 0) { +- ctx->cms_ctx->selected_digest = &digests[0]; ++ digest = ctx->cms_ctx->digests[0].pe_digest->data; ++ if (memcmp (digest, sig->data, 32) == 0) { ++ ctx->cms_ctx->selected_digest = 0; + return FOUND; + } + } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { +- digest_data = digests[1].pe_digest->data; +- if (memcmp (digest_data, sig->data, 20) == 0) { +- ctx->cms_ctx->selected_digest = &digests[1]; ++ digest = ctx->cms_ctx->digests[1].pe_digest->data; ++ if (memcmp (digest, sig->data, 20) == 0) { ++ ctx->cms_ctx->selected_digest = 1; + return FOUND; + } + } +diff --git a/src/cms_common.c b/src/cms_common.c +index 2275f67..86341ca 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -33,6 +33,15 @@ + + #include "hex.h" + ++struct digest_param { ++ char *name; ++ SECOidTag digest_tag; ++ SECOidTag signature_tag; ++ SECOidTag digest_encryption_tag; ++ const efi_guid_t *efi_guid; ++ int size; ++}; ++ + static struct digest_param digest_params[] = { + {.name = "sha256", + .digest_tag = SEC_OID_SHA256, +@@ -56,25 +65,29 @@ static int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); + SECOidTag + digest_get_digest_oid(cms_context *cms) + { +- return cms->selected_digest->digest_params->digest_tag; ++ int i = cms->selected_digest; ++ return digest_params[i].digest_tag; + } + + SECOidTag + digest_get_encryption_oid(cms_context *cms) + { +- return cms->selected_digest->digest_params->digest_encryption_tag; ++ int i = cms->selected_digest; ++ return digest_params[i].digest_encryption_tag; + } + + SECOidTag + digest_get_signature_oid(cms_context *cms) + { +- return cms->selected_digest->digest_params->signature_tag; ++ int i = cms->selected_digest; ++ return digest_params[i].signature_tag; + } + + int + digest_get_digest_size(cms_context *cms) + { +- return cms->selected_digest->digest_params->size; ++ int i = cms->selected_digest; ++ return digest_params[i].size; + } + + void +@@ -129,6 +142,8 @@ cms_context_init(cms_context *cms) + if (!cms->arena) + cnreterr(-1, cms, "could not create cryptographic arena"); + ++ cms->selected_digest = -1; ++ + INIT_LIST_HEAD(&cms->pk12_ins); + cms->pk12_out.fd = -1; + cms->db_out = cms->dbx_out = cms->dbt_out = -1; +@@ -211,7 +226,7 @@ cms_context_fini(cms_context *cms) + memset(&cms->newsig, '\0', sizeof (cms->newsig)); + } + +- cms->selected_digest = NULL; ++ cms->selected_digest = -1; + + if (cms->ci_digest) { + free_poison(cms->ci_digest->data, cms->ci_digest->len); +@@ -336,7 +351,7 @@ set_digest_parameters(cms_context *cms, char *name) + if (strcmp(name, "help")) { + for (int i = 0; i < n_digest_params; i++) { + if (!strcmp(name, digest_params[i].name)) { +- cms->selected_digest = &cms->digests[i]; ++ cms->selected_digest = i; + return 0; + } + } +@@ -1264,7 +1279,6 @@ generate_digest_begin(cms_context *cms) + cngotoerr(err, cms, "could not create digest context"); + + PK11_DigestBegin(digests[i].pk11ctx); +- digests[i].digest_params = &digest_params[i]; + } + + cms->digests = digests; +@@ -1337,11 +1351,11 @@ generate_signature(cms_context *cms) + { + int rc = 0; + +- if (cms->selected_digest->pe_digest == NULL) ++ if (cms->digests[cms->selected_digest].pe_digest == NULL) + cnreterr(-1, cms, "PE digest has not been allocated"); + +- if (content_is_empty(cms->selected_digest->pe_digest->data, +- cms->selected_digest->pe_digest->len)) ++ if (content_is_empty(cms->digests[cms->selected_digest].pe_digest->data, ++ cms->digests[cms->selected_digest].pe_digest->len)) + cnreterr(-1, cms, "PE binary has not been digested"); + + SECItem sd_der; +diff --git a/src/content_info.c b/src/content_info.c +index 777aa28..9684850 100644 +--- a/src/content_info.c ++++ b/src/content_info.c +@@ -181,8 +181,8 @@ generate_spc_digest_info(cms_context *cms, SECItem *dip) + if (generate_algorithm_id(cms, &di.digestAlgorithm, + digest_get_digest_oid(cms)) < 0) + return -1; +- memcpy(&di.digest, cms->selected_digest->pe_digest, +- sizeof(di.digest)); ++ int i = cms->selected_digest; ++ memcpy(&di.digest, cms->digests[i].pe_digest, sizeof (di.digest)); + + if (content_is_empty(di.digest.data, di.digest.len)) { + cms->log(cms, LOG_ERR, "got empty digest"); +diff --git a/src/file_kmod.c b/src/file_kmod.c +index c8875fc..6880cda 100644 +--- a/src/file_kmod.c ++++ b/src/file_kmod.c +@@ -60,7 +60,7 @@ ssize_t + kmod_write_signature(cms_context *cms, int outfd) + { + SEC_PKCS7ContentInfo *cinfo; +- SECItem *digest = cms->selected_digest->pe_digest; ++ SECItem *digest = cms->digests[cms->selected_digest].pe_digest; + SECStatus rv; + struct write_sig_info info = { + .outfd = outfd, +diff --git a/src/file_pe.c b/src/file_pe.c +index c22b2af..805e614 100644 +--- a/src/file_pe.c ++++ b/src/file_pe.c +@@ -114,8 +114,6 @@ check_inputs(pesign_context *ctx) + static void + print_digest(pesign_context *pctx) + { +- unsigned int i; +- + if (!pctx) + return; + +@@ -123,9 +121,10 @@ print_digest(pesign_context *pctx) + if (!ctx) + return; + +- unsigned char *ddata = ctx->selected_digest->pe_digest->data; +- for (i = 0; i < ctx->selected_digest->pe_digest->len; i++) +- printf("%02x", ddata[i]); ++ int j = ctx->selected_digest; ++ for (unsigned int i = 0; i < ctx->digests[j].pe_digest->len; i++) ++ printf("%02x", ++ (unsigned char)ctx->digests[j].pe_digest->data[i]); + printf(" %s\n", pctx->infile); + } + +diff --git a/src/pesigcheck.c b/src/pesigcheck.c +index ebb404d..6dc67f7 100644 +--- a/src/pesigcheck.c ++++ b/src/pesigcheck.c +@@ -221,7 +221,9 @@ static void + get_digest(pesigcheck_context *ctx, SECItem *digest) + { + struct cms_context *cms = ctx->cms_ctx; +- memcpy(digest, cms->selected_digest->pe_digest, sizeof(*digest)); ++ struct digest *cms_digest = &cms->digests[cms->selected_digest]; ++ ++ memcpy(digest, cms_digest->pe_digest, sizeof (*digest)); + } + + static int +diff --git a/src/cms_common.h b/src/cms_common.h +index c7d4f69..c7acbcf 100644 +--- a/src/cms_common.h ++++ b/src/cms_common.h +@@ -12,7 +12,6 @@ + #include + + #include +-#include + #include + #include + #include +@@ -58,19 +57,9 @@ + goto errlabel; \ + }) + +-struct digest_param { +- char *name; +- SECOidTag digest_tag; +- SECOidTag signature_tag; +- SECOidTag digest_encryption_tag; +- const efi_guid_t *efi_guid; +- int size; +-}; +- + struct digest { + PK11Context *pk11ctx; + SECItem *pe_digest; +- struct digest_param *digest_params; + }; + + typedef struct pk12_file { +@@ -144,7 +133,7 @@ typedef struct cms_context { + int db_out, dbx_out, dbt_out; + + struct digest *digests; +- struct digest *selected_digest; ++ int selected_digest; + int omit_vendor_cert; + + SECItem newsig; diff --git a/0022-CMS-add-some-minor-cleanups.patch b/0022-CMS-add-some-minor-cleanups.patch new file mode 100644 index 0000000..dfff3f5 --- /dev/null +++ b/0022-CMS-add-some-minor-cleanups.patch @@ -0,0 +1,149 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Mon, 29 Aug 2022 17:02:46 -0400 +Subject: [PATCH] CMS: add some minor cleanups + +We reverted 926782c216532a83f9ff864dee39d2349d61fd23 so that a future +patch can try a different approach, but that commit also had a few +cleanups that are worthwhile on their own. + +This patch re-introduces the cleanup to move "struct digest_param" to a +more reasonable place and the cleanup to check_hash(), and takes it just +a bit farther. + +Signed-off-by: Peter Jones +--- + src/certdb.c | 26 +++++++++++++++----------- + src/cms_common.c | 39 ++++++++++++++++----------------------- + src/cms_common.h | 16 ++++++++++++++++ + 3 files changed, 47 insertions(+), 34 deletions(-) + +diff --git a/src/certdb.c b/src/certdb.c +index 69d5daf..eb5221f 100644 +--- a/src/certdb.c ++++ b/src/certdb.c +@@ -263,20 +263,24 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, + { + efi_guid_t efi_sha256 = efi_guid_sha256; + efi_guid_t efi_sha1 = efi_guid_sha1; +- void *digest; ++ void *digest_data; ++ struct digest *digests = ctx->cms_ctx->digests; ++ int selected_digest = -1; ++ size_t size; + + if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { +- digest = ctx->cms_ctx->digests[0].pe_digest->data; +- if (memcmp (digest, sig->data, 32) == 0) { +- ctx->cms_ctx->selected_digest = 0; +- return FOUND; +- } ++ selected_digest = DIGEST_PARAM_SHA256; + } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { +- digest = ctx->cms_ctx->digests[1].pe_digest->data; +- if (memcmp (digest, sig->data, 20) == 0) { +- ctx->cms_ctx->selected_digest = 1; +- return FOUND; +- } ++ selected_digest = DIGEST_PARAM_SHA1; ++ } else { ++ return NOT_FOUND; ++ } ++ ++ digest_data = digests[selected_digest].pe_digest->data; ++ size = digest_params[selected_digest].size; ++ if (memcmp (digest_data, sig->data, size) == 0) { ++ ctx->cms_ctx->selected_digest = selected_digest; ++ return FOUND; + } + + return NOT_FOUND; +diff --git a/src/cms_common.c b/src/cms_common.c +index 86341ca..7bddedf 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -33,34 +33,27 @@ + + #include "hex.h" + +-struct digest_param { +- char *name; +- SECOidTag digest_tag; +- SECOidTag signature_tag; +- SECOidTag digest_encryption_tag; +- const efi_guid_t *efi_guid; +- int size; +-}; +- +-static struct digest_param digest_params[] = { +- {.name = "sha256", +- .digest_tag = SEC_OID_SHA256, +- .signature_tag = SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION, +- .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, +- .efi_guid = &efi_guid_sha256, +- .size = 32 ++const struct digest_param digest_params[] = { ++ [DIGEST_PARAM_SHA256] = { ++ .name = "sha256", ++ .digest_tag = SEC_OID_SHA256, ++ .signature_tag = SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION, ++ .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, ++ .efi_guid = &efi_guid_sha256, ++ .size = 32 + }, + #if 1 +- {.name = "sha1", +- .digest_tag = SEC_OID_SHA1, +- .signature_tag = SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION, +- .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, +- .efi_guid = &efi_guid_sha1, +- .size = 20 ++ [DIGEST_PARAM_SHA1] = { ++ .name = "sha1", ++ .digest_tag = SEC_OID_SHA1, ++ .signature_tag = SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION, ++ .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, ++ .efi_guid = &efi_guid_sha1, ++ .size = 20 + }, + #endif + }; +-static int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); ++const int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); + + SECOidTag + digest_get_digest_oid(cms_context *cms) +diff --git a/src/cms_common.h b/src/cms_common.h +index c7acbcf..e45402c 100644 +--- a/src/cms_common.h ++++ b/src/cms_common.h +@@ -12,6 +12,7 @@ + #include + + #include ++#include + #include + #include + #include +@@ -62,6 +63,21 @@ struct digest { + SECItem *pe_digest; + }; + ++#define DIGEST_PARAM_SHA256 0 ++#define DIGEST_PARAM_SHA1 1 ++ ++struct digest_param { ++ char *name; ++ SECOidTag digest_tag; ++ SECOidTag signature_tag; ++ SECOidTag digest_encryption_tag; ++ const efi_guid_t *efi_guid; ++ int size; ++}; ++ ++extern const struct digest_param digest_params[2]; ++extern const int n_digest_params; ++ + typedef struct pk12_file { + char *path; + int fd; diff --git a/0023-CMS-make-cms-selected_digest-an-index-again.patch b/0023-CMS-make-cms-selected_digest-an-index-again.patch new file mode 100644 index 0000000..6e19cd1 --- /dev/null +++ b/0023-CMS-make-cms-selected_digest-an-index-again.patch @@ -0,0 +1,291 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Tue, 30 Aug 2022 15:42:15 -0400 +Subject: [PATCH] CMS: make cms->selected_digest an index (again) + +In 926782c216532a83f9ff864dee39d2349d61fd23, we switched +cms->selected_digest to be a pointer to the entry in cms->digests. + +Because cms->digests is lazily allocated, setting the selected_digest +pointer has to be done at the right part of the CMS context life cycle, +and in some cases it clearly is not: + +==334217== Command: ./src/pesign -n tmp -s --pinfile tmp/pinfile -t OpenSC\ Card\ (testcard) -c kernel-signer -i tmp/unsigned.efi -o tmp/signed.efi --force +==334217== +==334217== Invalid read of size 8 +==334217== at 0x115E7D: digest_get_digest_oid (cms_common.c:59) +==334217== by 0x11CF41: generate_algorithm_id_list (signed_data.c:33) +==334217== by 0x11D348: generate_spc_signed_data (signed_data.c:279) +==334217== by 0x11EDFD: calculate_signature_space (wincert.c:297) +==334217== by 0x11467D: pe_handle_action (file_pe.c:298) +==334217== by 0x10F962: main (pesign.c:585) +==334217== Address 0x10 is not stack'd, malloc'd or (recently) free'd +==334217== +==334217== +==334217== Process terminating with default action of signal 11 (SIGSEGV): dumping core +==334217== Access not within mapped region at address 0x10 +==334217== at 0x115E7D: digest_get_digest_oid (cms_common.c:59) +==334217== by 0x11CF41: generate_algorithm_id_list (signed_data.c:33) +==334217== by 0x11D348: generate_spc_signed_data (signed_data.c:279) +==334217== by 0x11EDFD: calculate_signature_space (wincert.c:297) +==334217== by 0x11467D: pe_handle_action (file_pe.c:298) +==334217== by 0x10F962: main (pesign.c:585) +==334217== If you believe this happened as a result of a stack +==334217== overflow in your program's main thread (unlikely but +==334217== possible), you can try to increase the size of the +==334217== main thread stack using the --main-stacksize= flag. +==334217== The main thread stack size used in this run was 8388608. +==334217== +==334217== HEAP SUMMARY: +==334217== in use at exit: 588,544 bytes in 4,388 blocks +==334217== total heap usage: 8,568 allocs, 4,180 frees, 2,077,115 bytes allocated +==334217== +==334217== LEAK SUMMARY: +==334217== definitely lost: 25 bytes in 1 blocks +==334217== indirectly lost: 0 bytes in 0 blocks +==334217== possibly lost: 51,378 bytes in 166 blocks +==334217== still reachable: 537,141 bytes in 4,221 blocks +==334217== of which reachable via heuristic: +==334217== length64 : 321,312 bytes in 590 blocks +==334217== suppressed: 0 bytes in 0 blocks +==334217== Rerun with --leak-check=full to see details of leaked memory +==334217== +==334217== For lists of detected and suppressed errors, rerun with: -s +==334217== ERROR SUMMARY: 1 errors from 1 contexts (suppressed: 0 from 0) +Segmentation fault (core dumped) + +There is also a similar issue in the daemon code, and how to fix it +there is not immediately clear to me. + +Currently, we realistically only support using sha256 digests, so for +now I've chosen to paper over the issue by switching back to +cms->selected_digest be an index into both ctx->digests and +digest_params, but switching the default value from -1 to 0, aka +DIGEST_PARAM_SHA256. We can revisit this issue later whenever we add +sha384 support (or whichever other digest). + +Signed-off-by: Peter Jones +--- + src/certdb.c | 2 +- + src/cms_common.c | 41 +++++++++++++++++++++++------------------ + src/content_info.c | 2 +- + src/cms_common.h | 5 +++-- + 4 files changed, 28 insertions(+), 22 deletions(-) + +diff --git a/src/certdb.c b/src/certdb.c +index eb5221f..467a01d 100644 +--- a/src/certdb.c ++++ b/src/certdb.c +@@ -265,7 +265,7 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, + efi_guid_t efi_sha1 = efi_guid_sha1; + void *digest_data; + struct digest *digests = ctx->cms_ctx->digests; +- int selected_digest = -1; ++ unsigned int selected_digest; + size_t size; + + if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { +diff --git a/src/cms_common.c b/src/cms_common.c +index 7bddedf..1c54c90 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -33,6 +33,10 @@ + + #include "hex.h" + ++/* ++ * Note that cms->selected_digest defaults to 0, which means the first ++ * entry of this array is the default digest. ++ */ + const struct digest_param digest_params[] = { + [DIGEST_PARAM_SHA256] = { + .name = "sha256", +@@ -53,33 +57,33 @@ const struct digest_param digest_params[] = { + }, + #endif + }; +-const int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); ++const unsigned int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); + + SECOidTag + digest_get_digest_oid(cms_context *cms) + { +- int i = cms->selected_digest; ++ unsigned int i = cms->selected_digest; + return digest_params[i].digest_tag; + } + + SECOidTag + digest_get_encryption_oid(cms_context *cms) + { +- int i = cms->selected_digest; ++ unsigned int i = cms->selected_digest; + return digest_params[i].digest_encryption_tag; + } + + SECOidTag + digest_get_signature_oid(cms_context *cms) + { +- int i = cms->selected_digest; ++ unsigned int i = cms->selected_digest; + return digest_params[i].signature_tag; + } + + int + digest_get_digest_size(cms_context *cms) + { +- int i = cms->selected_digest; ++ unsigned int i = cms->selected_digest; + return digest_params[i].size; + } + +@@ -91,7 +95,7 @@ teardown_digests(cms_context *ctx) + if (!digests) + return; + +- for (int i = 0; i < n_digest_params; i++) { ++ for (unsigned int i = 0; i < n_digest_params; i++) { + if (digests[i].pk11ctx) { + PK11_Finalize(digests[i].pk11ctx); + PK11_DestroyContext(digests[i].pk11ctx, PR_TRUE); +@@ -135,7 +139,7 @@ cms_context_init(cms_context *cms) + if (!cms->arena) + cnreterr(-1, cms, "could not create cryptographic arena"); + +- cms->selected_digest = -1; ++ cms->selected_digest = DEFAULT_DIGEST_PARAM; + + INIT_LIST_HEAD(&cms->pk12_ins); + cms->pk12_out.fd = -1; +@@ -219,7 +223,7 @@ cms_context_fini(cms_context *cms) + memset(&cms->newsig, '\0', sizeof (cms->newsig)); + } + +- cms->selected_digest = -1; ++ cms->selected_digest = DEFAULT_DIGEST_PARAM; + + if (cms->ci_digest) { + free_poison(cms->ci_digest->data, cms->ci_digest->len); +@@ -342,7 +346,7 @@ int + set_digest_parameters(cms_context *cms, char *name) + { + if (strcmp(name, "help")) { +- for (int i = 0; i < n_digest_params; i++) { ++ for (unsigned int i = 0; i < n_digest_params; i++) { + if (!strcmp(name, digest_params[i].name)) { + cms->selected_digest = i; + return 0; +@@ -350,7 +354,7 @@ set_digest_parameters(cms_context *cms, char *name) + } + } else { + printf("Supported digests: "); +- for (int i = 0; digest_params[i].name != NULL; i++) { ++ for (unsigned int i = 0; digest_params[i].name != NULL; i++) { + printf("%s ", digest_params[i].name); + } + printf("\n"); +@@ -1265,7 +1269,7 @@ generate_digest_begin(cms_context *cms) + cnreterr(-1, cms, "could not allocate digest context"); + } + +- for (int i = 0; i < n_digest_params; i++) { ++ for (unsigned int i = 0; i < n_digest_params; i++) { + digests[i].pk11ctx = PK11_CreateDigestContext( + digest_params[i].digest_tag); + if (!digests[i].pk11ctx) +@@ -1278,7 +1282,7 @@ generate_digest_begin(cms_context *cms) + return 0; + + err: +- for (int i = 0; i < n_digest_params; i++) { ++ for (unsigned int i = 0; i < n_digest_params; i++) { + if (digests[i].pk11ctx) + PK11_DestroyContext(digests[i].pk11ctx, PR_TRUE); + } +@@ -1290,7 +1294,7 @@ err: + void + generate_digest_step(cms_context *cms, void *data, size_t len) + { +- for (int i = 0; i < n_digest_params; i++) ++ for (unsigned int i = 0; i < n_digest_params; i++) + PK11_DigestOp(cms->digests[i].pk11ctx, data, len); + } + +@@ -1299,7 +1303,7 @@ generate_digest_finish(cms_context *cms) + { + void *mark = PORT_ArenaMark(cms->arena); + +- for (int i = 0; i < n_digest_params; i++) { ++ for (unsigned int i = 0; i < n_digest_params; i++) { + SECItem *digest = PORT_ArenaZAlloc(cms->arena,sizeof (SECItem)); + if (digest == NULL) + cngotoerr(err, cms, "could not allocate memory"); +@@ -1326,7 +1330,7 @@ generate_digest_finish(cms_context *cms) + PORT_ArenaUnmark(cms->arena, mark); + return 0; + err: +- for (int i = 0; i < n_digest_params; i++) { ++ for (unsigned int i = 0; i < n_digest_params; i++) { + if (cms->digests[i].pk11ctx) + PK11_DestroyContext(cms->digests[i].pk11ctx, PR_TRUE); + } +@@ -1343,12 +1347,13 @@ int + generate_signature(cms_context *cms) + { + int rc = 0; ++ int i = cms->selected_digest; + +- if (cms->digests[cms->selected_digest].pe_digest == NULL) ++ if (cms->digests[i].pe_digest == NULL) + cnreterr(-1, cms, "PE digest has not been allocated"); + +- if (content_is_empty(cms->digests[cms->selected_digest].pe_digest->data, +- cms->digests[cms->selected_digest].pe_digest->len)) ++ if (content_is_empty(cms->digests[i].pe_digest->data, ++ cms->digests[i].pe_digest->len)) + cnreterr(-1, cms, "PE binary has not been digested"); + + SECItem sd_der; +diff --git a/src/content_info.c b/src/content_info.c +index 9684850..900974c 100644 +--- a/src/content_info.c ++++ b/src/content_info.c +@@ -181,7 +181,7 @@ generate_spc_digest_info(cms_context *cms, SECItem *dip) + if (generate_algorithm_id(cms, &di.digestAlgorithm, + digest_get_digest_oid(cms)) < 0) + return -1; +- int i = cms->selected_digest; ++ unsigned int i = cms->selected_digest; + memcpy(&di.digest, cms->digests[i].pe_digest, sizeof (di.digest)); + + if (content_is_empty(di.digest.data, di.digest.len)) { +diff --git a/src/cms_common.h b/src/cms_common.h +index e45402c..35a128a 100644 +--- a/src/cms_common.h ++++ b/src/cms_common.h +@@ -65,6 +65,7 @@ struct digest { + + #define DIGEST_PARAM_SHA256 0 + #define DIGEST_PARAM_SHA1 1 ++#define DEFAULT_DIGEST_PARAM DIGEST_PARAM_SHA256 + + struct digest_param { + char *name; +@@ -76,7 +77,7 @@ struct digest_param { + }; + + extern const struct digest_param digest_params[2]; +-extern const int n_digest_params; ++extern const unsigned int n_digest_params; + + typedef struct pk12_file { + char *path; +@@ -149,7 +150,7 @@ typedef struct cms_context { + int db_out, dbx_out, dbt_out; + + struct digest *digests; +- int selected_digest; ++ unsigned int selected_digest; + int omit_vendor_cert; + + SECItem newsig; diff --git a/pesign.patches b/pesign.patches index 9b257c3..0b756e9 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1,6 +1,23 @@ Patch0001: 0001-daemon-remove-always-true-comparison.patch -Patch0002: 0002-Fix-building-signed-kernels-on-setups-other-than-koj.patch -Patch0003: 0003-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch -Patch0004: 0004-macros.pesign-handle-centos-like-rhel-with-rhelver.patch -Patch0005: 0005-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch -Patch0006: 0006-Fix-mandoc-invocation-to-not-produce-garbage.patch +Patch0002: 0002-make-handle-some-gcc-Wanalyzer-flags-better.patch +Patch0003: 0003-Rename-dprintf-to-dbgprintf.patch +Patch0004: 0004-.gitignore-add-compile_commands.json-and-.cache.patch +Patch0005: 0005-pesign-print-digests-before-filenames-like-sha256sum.patch +Patch0006: 0006-Add-pesum-an-authenticode-digest-generator.patch +Patch0007: 0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch +Patch0008: 0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch +Patch0009: 0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch +Patch0010: 0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch +Patch0011: 0011-Rename-README-README.md.patch +Patch0012: 0012-README.md-show-off-a-bit-more.patch +Patch0013: 0013-Fix-missing-line-in-README.md.patch +Patch0014: 0014-Fix-typo-in-efikeygen-command.patch +Patch0015: 0015-pesigcheck-Fix-crash-on-digest-match.patch +Patch0016: 0016-cms-store-digest-as-pointer-instead-of-index.patch +Patch0017: 0017-Fix-mandoc-invocation-to-not-produce-garbage.patch +Patch0018: 0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch +Patch0019: 0019-get_password_passthrough-handle-the-callback-context.patch +Patch0020: 0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch +Patch0021: 0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch +Patch0022: 0022-CMS-add-some-minor-cleanups.patch +Patch0023: 0023-CMS-make-cms-selected_digest-an-index-again.patch diff --git a/pesign.spec b/pesign.spec index 118b151..4c835d0 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 115 -Release: 8%{?dist} +Release: 9%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -132,12 +132,13 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %files %{!?_licensedir:%global license %%doc} %license COPYING -%doc README TODO +%doc README.md TODO %{_bindir}/authvar %{_bindir}/efikeygen %{_bindir}/pesigcheck %{_bindir}/pesign %{_bindir}/pesign-client +%{_bindir}/pesum %dir %{_libexecdir}/pesign/ %dir %attr(0770,pesign,pesign) %{_sysconfdir}/pki/pesign/ %config(noreplace) %attr(0660,pesign,pesign) %{_sysconfdir}/pki/pesign/* @@ -161,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Wed Aug 31 2022 Robbie Harwood - 115-9 +- Roll up to pjones's smartcard/cms fixes + * Tue Aug 02 2022 Robbie Harwood - 115-8 - Rebuild for python bytecode change - See-also: #2107826 From 0b14fad476cc2b12dedda1d477285de909a2c94b Mon Sep 17 00:00:00 2001 From: Robbie Harwood Date: Tue, 31 Jan 2023 15:03:53 +0000 Subject: [PATCH 21/32] New upstream release (116) Resolves: CVE-2022-3560 Signed-off-by: Robbie Harwood --- ...daemon-remove-always-true-comparison.patch | 24 - ...ndle-some-gcc-Wanalyzer-flags-better.patch | 40 -- 0003-Rename-dprintf-to-dbgprintf.patch | 664 ------------------ ...add-compile_commands.json-and-.cache.patch | 30 - ...ests-before-filenames-like-sha256sum.patch | 31 - ...sum-an-authenticode-digest-generator.patch | 318 --------- ...ned-kernels-on-setups-other-than-koj.patch | 54 -- ...Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch | 23 - ...handle-centos-like-rhel-with-rhelver.patch | 24 - ...nce-of-rpm-sign-when-checking-for-rh.patch | 25 - 0011-Rename-README-README.md.patch | 17 - 0012-README.md-show-off-a-bit-more.patch | 56 -- 0013-Fix-missing-line-in-README.md.patch | 23 - 0014-Fix-typo-in-efikeygen-command.patch | 23 - ...pesigcheck-Fix-crash-on-digest-match.patch | 53 -- ...e-digest-as-pointer-instead-of-index.patch | 272 ------- ...oc-invocation-to-not-produce-garbage.patch | 31 - ...being-obnoxiously-incompatible-with-.patch | 41 -- ...sthrough-handle-the-callback-context.patch | 51 -- ...ly-prune-CR-NL-from-the-end-of-the-f.patch | 47 -- ...e-digest-as-pointer-instead-of-index.patch | 276 -------- 0022-CMS-add-some-minor-cleanups.patch | 149 ---- ...e-cms-selected_digest-an-index-again.patch | 291 -------- pesign.patches | 23 - pesign.spec | 8 +- sources | 2 +- 26 files changed, 7 insertions(+), 2589 deletions(-) delete mode 100644 0001-daemon-remove-always-true-comparison.patch delete mode 100644 0002-make-handle-some-gcc-Wanalyzer-flags-better.patch delete mode 100644 0003-Rename-dprintf-to-dbgprintf.patch delete mode 100644 0004-.gitignore-add-compile_commands.json-and-.cache.patch delete mode 100644 0005-pesign-print-digests-before-filenames-like-sha256sum.patch delete mode 100644 0006-Add-pesum-an-authenticode-digest-generator.patch delete mode 100644 0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch delete mode 100644 0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch delete mode 100644 0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch delete mode 100644 0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch delete mode 100644 0011-Rename-README-README.md.patch delete mode 100644 0012-README.md-show-off-a-bit-more.patch delete mode 100644 0013-Fix-missing-line-in-README.md.patch delete mode 100644 0014-Fix-typo-in-efikeygen-command.patch delete mode 100644 0015-pesigcheck-Fix-crash-on-digest-match.patch delete mode 100644 0016-cms-store-digest-as-pointer-instead-of-index.patch delete mode 100644 0017-Fix-mandoc-invocation-to-not-produce-garbage.patch delete mode 100644 0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch delete mode 100644 0019-get_password_passthrough-handle-the-callback-context.patch delete mode 100644 0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch delete mode 100644 0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch delete mode 100644 0022-CMS-add-some-minor-cleanups.patch delete mode 100644 0023-CMS-make-cms-selected_digest-an-index-again.patch diff --git a/0001-daemon-remove-always-true-comparison.patch b/0001-daemon-remove-always-true-comparison.patch deleted file mode 100644 index cbb5d32..0000000 --- a/0001-daemon-remove-always-true-comparison.patch +++ /dev/null @@ -1,24 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Tue, 8 Mar 2022 12:59:34 -0500 -Subject: [PATCH] daemon: remove always-true comparison - -Signed-off-by: Robbie Harwood ---- - src/daemon.c | 3 +-- - 1 file changed, 1 insertion(+), 2 deletions(-) - -diff --git a/src/daemon.c b/src/daemon.c -index 0a66deb..ff88210 100644 ---- a/src/daemon.c -+++ b/src/daemon.c -@@ -221,8 +221,7 @@ malformed: - if (!ctx->cms->tokenname) - goto oom; - -- if (!tp->value) -- pin = strndup((char *)tp->value, tp->size); -+ pin = strndup((char *)tp->value, tp->size); - if (!pin) - goto oom; - diff --git a/0002-make-handle-some-gcc-Wanalyzer-flags-better.patch b/0002-make-handle-some-gcc-Wanalyzer-flags-better.patch deleted file mode 100644 index 5bee588..0000000 --- a/0002-make-handle-some-gcc-Wanalyzer-flags-better.patch +++ /dev/null @@ -1,40 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Fri, 11 Mar 2022 12:45:28 -0500 -Subject: [PATCH] make: handle some gcc -Wanalyzer flags better - -This makes it so we won't use the -Wanalyzer / -fanalyzer flags by -default, because they're still pretty overzealous. - -Signed-off-by: Peter Jones ---- - Make.defaults | 6 +++--- - 1 file changed, 3 insertions(+), 3 deletions(-) - -diff --git a/Make.defaults b/Make.defaults -index 130c1ee..1c18904 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -32,11 +32,11 @@ CCLD := $(if $(filter undefined,$(origin CCLD)),$(CC),$(CCLD)) - CFLAGS ?= -O2 -g3 -pipe -fPIE -fstack-protector-all \ - -fstack-clash-protection \ - $(if $(filter x86_64 ia32,$(ARCH)),-fcf-protection=full,) --DIAGFLAGS ?= -fmessage-length=0 \ -+DIAGFLAGS ?= $(call enabled,ENABLE_GCC_ANALYZER,-fmessage-length=0 \ - -fdiagnostics-color=always \ - -fdiagnostics-format=text \ - -fdiagnostics-show-cwe \ -- -fanalyzer \ -+ -fanalyzer) \ - $(call enabled,ENABLE_LEAK_CHECKER,-Wno-analyzer-malloc-leak,) - AS ?= $(CROSS_COMPILE)as - AR ?= $(CROSS_COMPILE)$(if $(filter $(CC),clang),llvm-ar,$(notdir $(CC))-ar) -@@ -59,7 +59,7 @@ endif - cflags = $(CFLAGS) $(ARCH3264) \ - -Wall -Wextra -Wsign-compare -Wno-unused-result \ - -Wno-unused-function -Wno-missing-field-initializers \ -- -Wno-analyzer-malloc-leak \ -+ $(call enabled,ENABLE_LEAK_CHECKER,-Wno-analyzer-malloc-leak,) \ - -Werror -Wno-error=cpp -Wno-free-nonheap-object \ - -std=gnu11 -fshort-wchar -fPIC -fno-strict-aliasing \ - -D_GNU_SOURCE -DCONFIG_$(ARCH) -I${TOPDIR}/include \ diff --git a/0003-Rename-dprintf-to-dbgprintf.patch b/0003-Rename-dprintf-to-dbgprintf.patch deleted file mode 100644 index dac8401..0000000 --- a/0003-Rename-dprintf-to-dbgprintf.patch +++ /dev/null @@ -1,664 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Fri, 11 Mar 2022 12:46:16 -0500 -Subject: [PATCH] Rename "dprintf' to "dbgprintf" - -stdio defines a dprintf() macro now, so using dprintf() for our debug -printer gets obnoxious warnings. This renames it to dbgprintf(). - -Signed-off-by: Peter Jones ---- - src/cms_common.c | 73 +++++++++++++++++++++++++++++------------------------ - src/cms_pe_common.c | 20 +++++++-------- - src/efikeygen.c | 16 ++++++------ - src/file_pe.c | 6 +++-- - src/password.c | 68 ++++++++++++++++++++++++------------------------- - src/pesign.c | 10 ++++---- - src/util.h | 26 +++++++++---------- - 7 files changed, 114 insertions(+), 105 deletions(-) - -diff --git a/src/cms_common.c b/src/cms_common.c -index ca37e6a..86341ca 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -333,13 +333,13 @@ void cms_set_pw_data(cms_context *cms, secuPWData *pwdata) - - if (!pwdata) { - cms->pwdata.source = PW_SOURCE_INVALID; -- dprintf("pwdata:NULL"); -+ dbgprintf("pwdata:NULL"); - } else { - memmove(&cms->pwdata, pwdata, sizeof(*pwdata)); -- dprintf("pwdata:%p", pwdata); -- dprintf("pwdata->source:%d", pwdata->source); -- dprintf("pwdata->data:%p (\"%s\")", pwdata->data, -- pwdata->data ? pwdata->data : "(null)"); -+ dbgprintf("pwdata:%p", pwdata); -+ dbgprintf("pwdata->source:%d", pwdata->source); -+ dbgprintf("pwdata->data:%p (\"%s\")", pwdata->data, -+ pwdata->data ? pwdata->data : "(null)"); - } - - egress(); -@@ -382,7 +382,7 @@ is_valid_cert(CERTCertificate *cert, void *data) - - errnum = PORT_GetError(); - if (errnum == SEC_ERROR_EXTENSION_NOT_FOUND) { -- dprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); -+ dbgprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); - PORT_SetError(0); - errnum = 0; - } -@@ -415,7 +415,7 @@ is_valid_cert_without_private_key(CERTCertificate *cert, void *data) - - errnum = PORT_GetError(); - if (errnum == SEC_ERROR_EXTENSION_NOT_FOUND) { -- dprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); -+ dbgprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing"); - PORT_SetError(0); - errnum = 0; - } -@@ -467,23 +467,23 @@ unescape_html_in_place(char *s) - size_t pos = 0; - char *s1; - -- dprintf("unescaping pos:%zd sz:%zd \"%s\"", pos, sz, s); -+ dbgprintf("unescaping pos:%zd sz:%zd \"%s\"", pos, sz, s); - do { - s1 = strchrnul(&s[pos], '%'); - if (s1[0] == '\0') - break; -- dprintf("s1 is \"%s\"", s1); -+ dbgprintf("s1 is \"%s\"", s1); - if ((size_t)(s1 - s) < (size_t)(sz - 3)) { - int c; - - c = (hexchar_to_bin(s1[1]) << 4) - | (hexchar_to_bin(s1[2]) & 0xf); -- dprintf("replacing %%%c%c with 0x%02hhx", s1[1], s1[2], (char)c); -+ dbgprintf("replacing %%%c%c with 0x%02hhx", s1[1], s1[2], (char)c); - s1[0] = c; - memmove(&s1[1], &s1[3], sz - (&s1[3] - s)); - sz -= 2; - pos = &s1[1] - s; -- dprintf("new pos:%zd sz:%zd s:\"%s\"", pos, sz, s); -+ dbgprintf("new pos:%zd sz:%zd s:\"%s\"", pos, sz, s); - } - } while (pos < sz); - } -@@ -499,7 +499,7 @@ resolve_pkcs11_token_in_place(char *tokenname) - char c = *cp; - *cp = '\0'; - -- dprintf("ntn:\"%s\"", ntn); -+ dbgprintf("ntn:\"%s\"", ntn); - if (!strncmp(&ntn[pos], "token=", 6)) { - ntn += 6; - memmove(tokenname, ntn, cp - ntn + 1); -@@ -510,13 +510,13 @@ resolve_pkcs11_token_in_place(char *tokenname) - ntn = cp + (c ? 1 : 0); - } - unescape_html_in_place(tokenname); -- dprintf("token name is \"%s\"", tokenname); -+ dbgprintf("token name is \"%s\"", tokenname); - } - - #define resolve_token_name(tn) ({ \ - char *s_ = tn; \ - if (!strncmp(tn, "pkcs11:", 7)) { \ -- dprintf("provided token name is pkcs11 uri; parsing"); \ -+ dbgprintf("provided token name is pkcs11 uri; parsing");\ - s_ = strdupa(tn+7); \ - resolve_pkcs11_token_in_place(s_); \ - } \ -@@ -528,7 +528,8 @@ unlock_nss_token(cms_context *cms) - { - char *tokenname = resolve_token_name(cms->tokenname); - -- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); -+ dbgprintf("setting password function to %s", -+ cms->func ? "cms->func" : "SECU_GetModulePassword"); - PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); - - PK11SlotList *slots = NULL; -@@ -592,7 +593,8 @@ find_certificate(cms_context *cms, int needs_private_key) - return -1; - } - -- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); -+ dbgprintf("setting password function to %s", -+ cms->func ? "cms->func" : "SECU_GetModulePassword"); - PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); - - PK11SlotList *slots = NULL; -@@ -610,10 +612,10 @@ find_certificate(cms_context *cms, int needs_private_key) - } - - while (psle) { -- dprintf("looking for token \"%s\", got \"%s\"", -- tokenname, PK11_GetTokenName(psle->slot)); -+ dbgprintf("looking for token \"%s\", got \"%s\"", -+ tokenname, PK11_GetTokenName(psle->slot)); - if (!strcmp(tokenname, PK11_GetTokenName(psle->slot))) { -- dprintf("found token \"%s\"", tokenname); -+ dbgprintf("found token \"%s\"", tokenname); - break; - } - -@@ -673,8 +675,9 @@ find_certificate(cms_context *cms, int needs_private_key) - psle->slot, is_valid_cert, &cbd); - errnum = PORT_GetError(); - if (errnum) -- dprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", -- PORT_ErrorToName(errnum), PORT_ErrorToString(errnum)); -+ dbgprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", -+ PORT_ErrorToName(errnum), -+ PORT_ErrorToString(errnum)); - } else { - status = PK11_TraverseCertsForNicknameInSlot(&nickname, - psle->slot, -@@ -682,28 +685,30 @@ find_certificate(cms_context *cms, int needs_private_key) - &cbd); - errnum = PORT_GetError(); - if (errnum) -- dprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", -- PORT_ErrorToName(errnum), PORT_ErrorToString(errnum)); -+ dbgprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s", -+ PORT_ErrorToName(errnum), -+ PORT_ErrorToString(errnum)); - } -- dprintf("status:%d cbd.cert:%p", status, cbd.cert); -+ dbgprintf("status:%d cbd.cert:%p", status, cbd.cert); - if (status == SECSuccess && cbd.cert != NULL) { - if (cms->cert) - CERT_DestroyCertificate(cms->cert); - cms->cert = CERT_DupCertificate(cbd.cert); - } else { - errnum = PORT_GetError(); -- dprintf("token traversal %s; cert %sfound:%s:%s", -- status == SECSuccess ? "succeeded" : "failed", -- cbd.cert == NULL ? "not" : "", -- PORT_ErrorToName(errnum), PORT_ErrorToString(errnum)); -+ dbgprintf("token traversal %s; cert %sfound:%s:%s", -+ status == SECSuccess ? "succeeded" : "failed", -+ cbd.cert == NULL ? "not" : "", -+ PORT_ErrorToName(errnum), -+ PORT_ErrorToString(errnum)); - } - - save_port_err() { -- dprintf("Destroying cert list"); -+ dbgprintf("Destroying cert list"); - CERT_DestroyCertList(certlist); -- dprintf("Destroying slot list element"); -+ dbgprintf("Destroying slot list element"); - PK11_DestroySlotListElement(slots, &psle); -- dprintf("Destroying slot list"); -+ dbgprintf("Destroying slot list"); - PK11_FreeSlotList(slots); - cms->psle = NULL; - } -@@ -723,7 +728,8 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot) - - char *tokenname = resolve_token_name(cms->tokenname); - -- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); -+ dbgprintf("setting password function to %s", -+ cms->func ? "cms->func" : "SECU_GetModulePassword"); - PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); - - PK11SlotList *slots = NULL; -@@ -792,7 +798,8 @@ find_certificate_by_callback(cms_context *cms, - return -1; - } - -- dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword"); -+ dbgprintf("setting password function to %s", -+ cms->func ? "cms->func" : "SECU_GetModulePassword"); - PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword); - - PK11SlotList *slots = NULL; -diff --git a/src/cms_pe_common.c b/src/cms_pe_common.c -index 3a3921b..fb90ecb 100644 ---- a/src/cms_pe_common.c -+++ b/src/cms_pe_common.c -@@ -188,8 +188,8 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - } - if (!check_pointer_and_size(cms, pe, hash_base, hash_size)) - cmsgotoerr(error, cms, "PE header is invalid"); -- dprintf("beginning of hash"); -- dprintf("digesting %tx + %zx", hash_base - map, hash_size); -+ dbgprintf("beginning of hash"); -+ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); - generate_digest_step(cms, hash_base, hash_size); - - /* 5. Skip over the image checksum -@@ -209,7 +209,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - cmsgotoerr(error, cms, "PE data directory is invalid"); - - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %tx + %zx", hash_base - map, hash_size); -+ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); - - /* 8. Skip over the crt dir - * 9. Hash everything up to the end of the image header. */ -@@ -222,7 +222,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - cmsgotoerr(error, cms, "PE relocations table is invalid"); - - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %tx + %zx", hash_base - map, hash_size); -+ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); - - /* 10. Set SUM_OF_BYTES_HASHED to the size of the header. */ - hashed_bytes = pe32opthdr ? pe32opthdr->header_size -@@ -256,16 +256,16 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - char *name = shdrs[i].name; - if (name && name[0] == '/') - name = get_str(cms, pe, name + 1); -- dprintf("section:\"%s\"", name ? name : "(null)"); -+ dbgprintf("section:\"%s\"", name ? name : "(null)"); - if (name && !strcmp(name, ".vendor_cert")) { -- dprintf("skipping .vendor_cert section"); -+ dbgprintf("skipping .vendor_cert section"); - hashed_bytes += hash_size; - continue; - } - } - - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %tx + %zx", hash_base - map, hash_size); -+ dbgprintf("digesting %tx + %zx", hash_base - map, hash_size); - - hashed_bytes += hash_size; - } -@@ -285,15 +285,15 @@ generate_digest(cms_context *cms, Pe *pe, int padded) - memset(tmp_array, '\0', tmp_size); - memcpy(tmp_array, hash_base, hash_size); - generate_digest_step(cms, tmp_array, tmp_size); -- dprintf("digesting %tx + %zx", (ptrdiff_t)tmp_array, -+ dbgprintf("digesting %tx + %zx", (ptrdiff_t)tmp_array, - tmp_size); - } else { - generate_digest_step(cms, hash_base, hash_size); -- dprintf("digesting %tx + %zx", hash_base - map, -+ dbgprintf("digesting %tx + %zx", hash_base - map, - hash_size); - } - } -- dprintf("end of hash"); -+ dbgprintf("end of hash"); - - rc = generate_digest_finish(cms); - if (rc < 0) -diff --git a/src/efikeygen.c b/src/efikeygen.c -index 940fdf5..dd40502 100644 ---- a/src/efikeygen.c -+++ b/src/efikeygen.c -@@ -1067,9 +1067,9 @@ int main(int argc, char *argv[]) - - errno = 0; - timeul = strtoul(not_valid_before, &endptr, 0); -- dprintf("not_valid_before:%lu", timeul); -+ dbgprintf("not_valid_before:%lu", timeul); - if (errno == 0 && endptr && *endptr == 0) { -- dprintf("not_valid_before:%lu", timeul); -+ dbgprintf("not_valid_before:%lu", timeul); - not_before = (PRTime)timeul * PR_USEC_PER_SEC; - } else { - prstatus = PR_ParseTimeString(not_valid_before, -@@ -1078,7 +1078,7 @@ int main(int argc, char *argv[]) - "could not parse date \"%s\"", - not_valid_before); - } -- dprintf("not_before:%"PRId64, not_before); -+ dbgprintf("not_before:%"PRId64, not_before); - } - - if (not_valid_after) { -@@ -1086,11 +1086,11 @@ int main(int argc, char *argv[]) - char *endptr; - - errno = 0; -- dprintf("not_valid_after:%s", not_valid_after); -+ dbgprintf("not_valid_after:%s", not_valid_after); - timeul = strtoul(not_valid_after, &endptr, 0); -- dprintf("not_valid_after:%lu", timeul); -+ dbgprintf("not_valid_after:%lu", timeul); - if (errno == 0 && endptr && *endptr == 0) { -- dprintf("not_valid_after:%lu", timeul); -+ dbgprintf("not_valid_after:%lu", timeul); - not_after = (PRTime)timeul * PR_USEC_PER_SEC; - } else { - prstatus = PR_ParseTimeString(not_valid_after, PR_TRUE, -@@ -1102,10 +1102,10 @@ int main(int argc, char *argv[]) - } else { - // Mon Jan 19 03:14:07 GMT 2037, aka 0x7fffffff minus 1 year. - time_t time = 0x7ffffffful - 60ul * 60 * 24 * 365; -- dprintf("not_valid_after:%lu", time); -+ dbgprintf("not_valid_after:%lu", time); - not_after = (PRTime)time * PR_USEC_PER_SEC; - } -- dprintf("not_after:%"PRId64, not_after); -+ dbgprintf("not_after:%"PRId64, not_after); - - CERTValidity *validity = NULL; - validity = CERT_CreateValidity(not_before, not_after); -diff --git a/src/file_pe.c b/src/file_pe.c -index fa97b89..fed6edb 100644 ---- a/src/file_pe.c -+++ b/src/file_pe.c -@@ -264,7 +264,8 @@ pe_handle_action(pesign_context *ctxp, int action, int padding) - /* generate a signature and save it in a separate file */ - case EXPORT_SIGNATURE|GENERATE_SIGNATURE: - perr = PORT_GetError(); -- dprintf("PORT_GetError():%s:%s", PORT_ErrorToName(perr), PORT_ErrorToString(perr)); -+ dbgprintf("PORT_GetError():%s:%s", -+ PORT_ErrorToName(perr), PORT_ErrorToString(perr)); - PORT_SetError(0); - rc = find_certificate(ctxp->cms_ctx, 1); - conderrx(rc < 0, 1, "Could not find certificate %s", -@@ -281,7 +282,8 @@ pe_handle_action(pesign_context *ctxp, int action, int padding) - case IMPORT_SIGNATURE|GENERATE_SIGNATURE: - check_inputs(ctxp); - perr = PORT_GetError(); -- dprintf("PORT_GetError():%s:%s", PORT_ErrorToName(perr), PORT_ErrorToString(perr)); -+ dbgprintf("PORT_GetError():%s:%s", -+ PORT_ErrorToName(perr), PORT_ErrorToString(perr)); - rc = find_certificate(ctxp->cms_ctx, 1); - conderrx(rc < 0, 1, "Could not find certificate %s", - ctxp->cms_ctx->certname); -diff --git a/src/password.c b/src/password.c -index 05add9a..18c32ed 100644 ---- a/src/password.c -+++ b/src/password.c -@@ -167,7 +167,7 @@ SECU_GetPasswordString(void *arg UNUSED, char *prompt) - char *ret; - ingress(); - ret = get_password(stdin, stdout, prompt, NULL); -- dprintf("password:\"%s\"", ret ? ret : "(null)"); -+ dbgprintf("password:\"%s\"", ret ? ret : "(null)"); - egress(); - return ret; - } -@@ -194,7 +194,7 @@ parse_pwfile_line(char *start, struct token_pass *tp) - size_t offset = 0; - - span = strspn(line, whitespace_and_eol_chars); -- dprintf("whitespace span is %zd", span); -+ dbgprintf("whitespace span is %zd", span); - if (span == 0 && line[span] == '\0') - return -1; - line += span; -@@ -210,17 +210,17 @@ parse_pwfile_line(char *start, struct token_pass *tp) - offset += escspan + 2; - } while(escspan < span); - span += offset; -- dprintf("non-whitespace span is %zd", span); -+ dbgprintf("non-whitespace span is %zd", span); - - if (line[span] == '\0') { -- dprintf("returning %td", (line + span) - start); -+ dbgprintf("returning %td", (line + span) - start); - return (line + span) - start; - } - line[span] = '\0'; - - line += span + 1; - span = strspn(line, whitespace_and_eol_chars); -- dprintf("whitespace span is %zd", span); -+ dbgprintf("whitespace span is %zd", span); - line += span; - tp->token = tp->pass; - tp->pass = line; -@@ -233,15 +233,15 @@ parse_pwfile_line(char *start, struct token_pass *tp) - offset += escspan + 2; - } while(escspan < span); - span += offset; -- dprintf("non-whitespace span is %zd", span); -+ dbgprintf("non-whitespace span is %zd", span); - if (line[span] != '\0') - line[span++] = '\0'; - - resolve_escapes(tp->token); -- dprintf("Setting token pass %p to { %p, %p }", tp, tp->token, tp->pass); -- dprintf("token:\"%s\"", tp->token); -- dprintf("pass:\"%s\"", tp->pass); -- dprintf("returning %td", (line + span) - start); -+ dbgprintf("Setting token pass %p to { %p, %p }", tp, tp->token, tp->pass); -+ dbgprintf("token:\"%s\"", tp->token); -+ dbgprintf("pass:\"%s\"", tp->pass); -+ dbgprintf("returning %td", (line + span) - start); - return (line + span) - start; - } - -@@ -260,7 +260,7 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) - char *path; - - ingress(); -- dprintf("token_name: %s", token_name); -+ dbgprintf("token_name: %s", token_name); - if (cms->pwdata.source != PW_FROMFILEDB) { - cms->log(cms, LOG_ERR, - "Got to %s() but no file is specified.\n", -@@ -289,8 +289,8 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) - if (rc < 0 || file_len < 1) - goto err_file; - file[file_len-1] = '\0'; -- dprintf("file_len:%zd", file_len); -- dprintf("file:\"%s\"", file); -+ dbgprintf("file_len:%zd", file_len); -+ dbgprintf("file:\"%s\"", file); - - unbreak_line_continuations(file, file_len); - } -@@ -314,23 +314,23 @@ SECU_FilePasswd(PK11SlotInfo *slot, PRBool retry, void *arg) - #pragma GCC diagnostic pop - - span = strspn(start, whitespace_and_eol_chars); -- dprintf("whitespace span is %zd", span); -+ dbgprintf("whitespace span is %zd", span); - start += span; - span = strcspn(start, eol_chars); -- dprintf("non-whitespace span is %zd", span); -+ dbgprintf("non-whitespace span is %zd", span); - - c = start[span]; - start[span] = '\0'; -- dprintf("file:\"%s\"", file); -+ dbgprintf("file:\"%s\"", file); - rc = parse_pwfile_line(start, &phrases[nphrases++]); -- dprintf("parse_pwfile_line returned %d", rc); -+ dbgprintf("parse_pwfile_line returned %d", rc); - if (rc < 0) - goto err_phrases; - - if (c != '\0') - span++; - start += span; -- dprintf("start is file[%td] == '\\x%02hhx'", start - file, -+ dbgprintf("start is file[%td] == '\\x%02hhx'", start - file, - start[0]); - } - -@@ -359,7 +359,7 @@ err_file: - err_phrases: - xfree(phrases); - err: -- dprintf("ret:\"%s\"", ret ? ret : "(null)"); -+ dbgprintf("ret:\"%s\"", ret ? ret : "(null)"); - egress(); - return ret; - } -@@ -412,10 +412,10 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) - ingress(); - - if (PK11_ProtectedAuthenticationPath(slot)) { -- dprintf("prompting for PW_DEVICE data"); -+ dbgprintf("prompting for PW_DEVICE data"); - pwdata = &pwxtrn; - } else { -- dprintf("using pwdata from cms"); -+ dbgprintf("using pwdata from cms"); - pwdata = &cms->pwdata; - } - -@@ -423,17 +423,17 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) - pwdata->source >= PW_SOURCE_MAX || - pwdata->orig_source <= PW_SOURCE_INVALID || - pwdata->orig_source >= PW_SOURCE_MAX) { -- dprintf("pwdata is invalid"); -+ dbgprintf("pwdata is invalid"); - return NULL; - } - -- dprintf("pwdata:%p retry:%d", pwdata, retry); -- dprintf("pwdata->source:%s (%d) orig:%s (%d)", -- pw_source_names[pwdata->source], pwdata->source, -- pw_source_names[pwdata->orig_source], pwdata->orig_source); -- dprintf("pwdata->data:%p (\"%s\")", pwdata->data, -- pwdata->data ? pwdata->data : "(null)"); -- dprintf("pwdata->intdata:%ld", pwdata->intdata); -+ dbgprintf("pwdata:%p retry:%d", pwdata, retry); -+ dbgprintf("pwdata->source:%s (%d) orig:%s (%d)", -+ pw_source_names[pwdata->source], pwdata->source, -+ pw_source_names[pwdata->orig_source], pwdata->orig_source); -+ dbgprintf("pwdata->data:%p (\"%s\")", pwdata->data, -+ pwdata->data ? pwdata->data : "(null)"); -+ dbgprintf("pwdata->intdata:%ld", pwdata->intdata); - - if (retry) { - warnx("Incorrect password/PIN entered."); -@@ -470,7 +470,7 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) - - case PW_FROMFILEDB: - case PW_DATABASE: -- dprintf("pwdata->source:%s", pw_source_names[pwdata->source]); -+ dbgprintf("pwdata->source:%s", pw_source_names[pwdata->source]); - /* Instead of opening and closing the file every time, get the pw - * once, then keep it in memory (duh). - */ -@@ -480,17 +480,17 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) - return pw; - - case PW_FROMENV: -- dprintf("pwdata->source:PW_FROMENV"); -+ dbgprintf("pwdata->source:PW_FROMENV"); - if (!pwdata || !pwdata->data) - break; - pw = get_env(pwdata->data); -- dprintf("env:%s pw:%s", pwdata->data, pw ? pw : "(null)"); -+ dbgprintf("env:%s pw:%s", pwdata->data, pw ? pw : "(null)"); - pwdata->data = pw; - pwdata->source = PW_PLAINTEXT; - goto PW_PLAINTEXT; - - case PW_FROMFILE: -- dprintf("pwdata->source:PW_FROMFILE"); -+ dbgprintf("pwdata->source:PW_FROMFILE"); - in = fopen(pwdata->data, "r"); - if (!in) - return NULL; -@@ -501,7 +501,7 @@ SECU_GetModulePassword(PK11SlotInfo *slot, PRBool retry, void *arg) - goto PW_PLAINTEXT; - - case PW_FROMFD: -- dprintf("pwdata->source:PW_FROMFD"); -+ dbgprintf("pwdata->source:PW_FROMFD"); - rc = pwdata->intdata; - in = fdopen(pwdata->intdata, "r"); - if (!in) -diff --git a/src/pesign.c b/src/pesign.c -index c2ff35f..f548d81 100644 ---- a/src/pesign.c -+++ b/src/pesign.c -@@ -333,7 +333,7 @@ main(int argc, char *argv[]) - while ((rc = poptGetNextOpt(optCon)) > 0) { - switch (rc) { - case POPT_RET_PWDB: -- dprintf("POPT_RET_PWDB:\"%s\"", pwdata.data ? pwdata.data : "(null)"); -+ dbgprintf("POPT_RET_PWDB:\"%s\"", pwdata.data ? pwdata.data : "(null)"); - if (pwdata.source != PW_SOURCE_INVALID) - errx(1, "only one password/pin method can be used at a time"); - if (pwdata.data == NULL) -@@ -346,7 +346,7 @@ main(int argc, char *argv[]) - continue; - - case POPT_RET_ENV: -- dprintf("POPT_RET_ENV:\"%s\"", pwdata.data ? pwdata.data : "(null)"); -+ dbgprintf("POPT_RET_ENV:\"%s\"", pwdata.data ? pwdata.data : "(null)"); - if (pwdata.source != PW_SOURCE_INVALID) - errx(1, "only one password/pin method can be used at a time"); - if (pwdata.data == NULL) -@@ -359,7 +359,7 @@ main(int argc, char *argv[]) - continue; - - case POPT_RET_PINFD: -- dprintf("POPT_RET_PINFD:\"%s\"", pwdata.data ? pwdata.data : "(null)"); -+ dbgprintf("POPT_RET_PINFD:\"%s\"", pwdata.data ? pwdata.data : "(null)"); - if (pwdata.source != PW_SOURCE_INVALID) - errx(1, "only one password/pin method can be used at a time"); - if (pwdata.data == NULL) -@@ -373,7 +373,7 @@ main(int argc, char *argv[]) - continue; - - case POPT_RET_PINFILE: -- dprintf("POPT_RET_PINFILE:\"%s\"", pwdata.data ? pwdata.data : "(null)"); -+ dbgprintf("POPT_RET_PINFILE:\"%s\"", pwdata.data ? pwdata.data : "(null)"); - if (pwdata.source != PW_SOURCE_INVALID) - errx(1, "only one password/pin method can be used at a time"); - if (pwdata.data == NULL) -@@ -387,7 +387,7 @@ main(int argc, char *argv[]) - } - } - -- dprintf("pwdata.source:%d %schecking for PESIGN_TOKEN_PIN", -+ dbgprintf("pwdata.source:%d %schecking for PESIGN_TOKEN_PIN", - pwdata.source, - pwdata.source == PW_SOURCE_INVALID ? "" : "not "); - if (pwdata.source == PW_SOURCE_INVALID && secure_getenv("PESIGN_TOKEN_PIN")) { -diff --git a/src/util.h b/src/util.h -index ba8c621..6616011 100644 ---- a/src/util.h -+++ b/src/util.h -@@ -269,28 +269,28 @@ proxy_fd_mode(int fd, char *infile, mode_t *outmode, size_t *inlength) - - extern long verbosity(void); - --#define dprintf_(tv, file, func, line, fmt, args...) ({ \ -- struct timeval tv; \ -- gettimeofday(&tv, NULL); \ -- warnx("%ld.%lu %s:%s():%d: " fmt, \ -- tv.tv_sec, tv.tv_usec, \ -- file, func, line, ##args); \ -+#define dbgprintf_(tv, file, func, line, fmt, args...) ({ \ -+ struct timeval tv; \ -+ gettimeofday(&tv, NULL); \ -+ warnx("%ld.%lu %s:%s():%d: " fmt, \ -+ tv.tv_sec, tv.tv_usec, \ -+ file, func, line, ##args); \ - }) - #if defined(PESIGN_DEBUG) --#define dprintf(fmt, args...) \ -- dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ -- __FILE__, __func__, __LINE__ - 2, fmt, ##args) -+#define dbgprintf(fmt, args...) \ -+ dbgprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ -+ __FILE__, __func__, __LINE__ - 2, fmt, ##args) - #else --#define dprintf(fmt, args...) ({ \ -+#define dbgprintf(fmt, args...) ({ \ - if (verbosity() > 1) \ -- dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ -+ dbgprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \ - __FILE__, __func__, __LINE__ - 3, \ - fmt, ##args); \ - 0; \ - }) - #endif --#define ingress() dprintf("ingress"); --#define egress() dprintf("egress"); -+#define ingress() dbgprintf("ingress"); -+#define egress() dbgprintf("egress"); - - #endif /* PESIGN_UTIL_H */ - // vim:fenc=utf-8:tw=75:noet diff --git a/0004-.gitignore-add-compile_commands.json-and-.cache.patch b/0004-.gitignore-add-compile_commands.json-and-.cache.patch deleted file mode 100644 index fb7e7a4..0000000 --- a/0004-.gitignore-add-compile_commands.json-and-.cache.patch +++ /dev/null @@ -1,30 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Fri, 11 Mar 2022 12:47:20 -0500 -Subject: [PATCH] .gitignore: add compile_commands.json and .cache/ - -These are used by bear/cnc/clangd/etc, but there's no reason to trip -over them all the time. - -Signed-off-by: Peter Jones ---- - .gitignore | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/.gitignore b/.gitignore -index bf0617b..7425432 100644 ---- a/.gitignore -+++ b/.gitignore -@@ -1,3 +1,4 @@ -+.cache/ - .*.d - .*.P - .*.sw? -@@ -26,6 +27,7 @@ - /*.rpm - *-8be4df61-93ca-11d2-aa0d-00e098032b8c - *-d719b2cb-3d3a-4596-a3bc-dad00e67656f -+compile_commands.json - core.* - cov-int/ - pwfile diff --git a/0005-pesign-print-digests-before-filenames-like-sha256sum.patch b/0005-pesign-print-digests-before-filenames-like-sha256sum.patch deleted file mode 100644 index dbce340..0000000 --- a/0005-pesign-print-digests-before-filenames-like-sha256sum.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Fri, 11 Mar 2022 12:44:46 -0500 -Subject: [PATCH] pesign: print digests before filenames like sha256sum does - -Most digest tools print the digest before the filename, there's no -reason pesign needs to be different. - -Signed-off-by: Peter Jones ---- - src/file_pe.c | 3 +-- - 1 file changed, 1 insertion(+), 2 deletions(-) - -diff --git a/src/file_pe.c b/src/file_pe.c -index fed6edb..805e614 100644 ---- a/src/file_pe.c -+++ b/src/file_pe.c -@@ -121,12 +121,11 @@ print_digest(pesign_context *pctx) - if (!ctx) - return; - -- printf("%s ", pctx->infile); - int j = ctx->selected_digest; - for (unsigned int i = 0; i < ctx->digests[j].pe_digest->len; i++) - printf("%02x", - (unsigned char)ctx->digests[j].pe_digest->data[i]); -- printf("\n"); -+ printf(" %s\n", pctx->infile); - } - - void diff --git a/0006-Add-pesum-an-authenticode-digest-generator.patch b/0006-Add-pesum-an-authenticode-digest-generator.patch deleted file mode 100644 index 10d6fb4..0000000 --- a/0006-Add-pesum-an-authenticode-digest-generator.patch +++ /dev/null @@ -1,318 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Fri, 11 Mar 2022 12:54:39 -0500 -Subject: [PATCH] Add 'pesum', an authenticode digest generator. - -Signed-off-by: Peter Jones ---- - src/pesum.c | 195 +++++++++++++++++++++++++++++++++++++++++++++++++++++++ - src/.gitignore | 1 + - src/Makefile | 12 +++- - src/pesum.1.mdoc | 38 +++++++++++ - 4 files changed, 244 insertions(+), 2 deletions(-) - create mode 100644 src/pesum.c - create mode 100644 src/pesum.1.mdoc - -diff --git a/src/pesum.c b/src/pesum.c -new file mode 100644 -index 0000000..e4ddaf8 ---- /dev/null -+++ b/src/pesum.c -@@ -0,0 +1,195 @@ -+// SPDX-License-Identifier: GPLv2 -+/* -+ * pesum.c - pesum command line tool -+ * Copyright Peter Jones -+ */ -+ -+#include "fix_coverity.h" -+ -+#include -+#include -+ -+#include -+#include -+ -+#include "pesign.h" -+#include "pesign_standalone.h" -+ -+static struct { -+ int flag; -+ const char *name; -+} flag_names[] = { -+ {DAEMONIZE, "daemonize"}, -+ {GENERATE_DIGEST, "hash"}, -+ {GENERATE_SIGNATURE, "sign"}, -+ {IMPORT_RAW_SIGNATURE, "import-raw-sig"}, -+ {IMPORT_SIGNATURE, "import-sig"}, -+ {IMPORT_SATTRS, "import-sattrs" }, -+ {EXPORT_SATTRS, "export-sattrs" }, -+ {EXPORT_SIGNATURE, "export-sig"}, -+ {EXPORT_PUBKEY, "export-pubkey"}, -+ {EXPORT_CERT, "export-cert"}, -+ {REMOVE_SIGNATURE, "remove"}, -+ {LIST_SIGNATURES, "list"}, -+ {FLAG_LIST_END, NULL}, -+}; -+ -+void -+print_flag_name(FILE *f, int flag) -+{ -+ for (int i = 0; flag_names[i].flag != FLAG_LIST_END; i++) { -+ if (flag_names[i].flag == flag) -+ fprintf(f, "%s ", flag_names[i].name); -+ } -+} -+ -+static long *verbose; -+ -+long -+verbosity(void) -+{ -+ if (!verbose) -+ return 0; -+ return *verbose; -+} -+ -+int -+main(int argc, char *argv[]) -+{ -+ int rc; -+ SECStatus status; -+ -+ char *digest_name = "sha256"; -+ char *orig_digest_name = digest_name; -+ int padding = 1; -+ long verbose_cmd_line = 0; -+ const char *infile; -+ -+ int action = GENERATE_DIGEST|PRINT_DIGEST; -+ file_format fmt = FORMAT_PE_BINARY; -+ -+ setenv("NSS_DEFAULT_DB_TYPE", "sql", 0); -+ -+ verbose = &verbose_cmd_line; -+ -+ poptContext optCon; -+ struct poptOption options[] = { -+ {.argInfo = POPT_ARG_INTL_DOMAIN, -+ .arg = "pesum" }, -+ {.longName = "verbose", -+ .shortName = 'v', -+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL, -+ .arg = &verbose_cmd_line, -+ .val = 1, -+ .descrip = "be more verbose" }, -+ {.longName = "debug", -+ .shortName = '\0', -+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL, -+ .arg = &verbose_cmd_line, -+ .val = 2, -+ .descrip = "be very verbose" }, -+ {.longName = "digest-type", -+ .shortName = 'd', -+ .argInfo = POPT_ARG_STRING|POPT_ARGFLAG_SHOW_DEFAULT, -+ .arg = &digest_name, -+ .descrip = "digest type to use for pe hash" }, -+ {.longName = "digest_type", -+ .shortName = '\0', -+ .argInfo = POPT_ARG_STRING|POPT_ARGFLAG_DOC_HIDDEN, -+ .arg = &digest_name, -+ .descrip = "digest type to use for pe hash" }, -+ {.longName = "padding", -+ .shortName = 'P', -+ .argInfo = POPT_ARG_VAL, -+ .arg = &padding, -+ .val = 1, -+ .descrip = "pad data section (default)" }, -+ {.longName = "nopadding", -+ .shortName = 'p', -+ .argInfo = POPT_ARG_VAL, -+ .arg = &padding, -+ .val = 0, -+ .descrip = "do not pad the data section" }, -+ POPT_AUTOALIAS -+ POPT_AUTOHELP -+ POPT_TABLEEND -+ }; -+ -+ optCon = poptGetContext("pesum", argc, (const char **)argv, options,0); -+ -+ rc = poptReadDefaultConfig(optCon, 0); -+ if (rc < 0 && !(rc == POPT_ERROR_ERRNO && errno == ENOENT)) -+ errx(1, "poptReadDefaultConfig failed: %s", poptStrerror(rc)); -+ -+ while ((rc = poptGetNextOpt(optCon)) > 0) { -+ ; -+ } -+ -+ if (rc < -1) -+ errx(1, "Invalid argument: %s: %s", -+ poptBadOption(optCon, 0), poptStrerror(rc)); -+ -+ if (!poptPeekArg(optCon)) -+ errx(1, "nothing to do"); -+ -+ status = NSS_NoDB_Init(NULL); -+ if (status != SECSuccess) -+ errx(1, "Could not initialize nss.\n" -+ "NSS says \"%s\" errno says \"%m\"\n", -+ PORT_ErrorToString(PORT_GetError())); -+ -+ while ((infile = poptGetArg(optCon)) != NULL) { -+ pesign_context *ctxp = NULL; -+ -+ char *ext = strrchr(infile, '.'); -+ if (ext && strcmp(ext, ".ko") == 0) -+ fmt = FORMAT_KERNEL_MODULE; -+ -+ rc = pesign_context_new(&ctxp); -+ if (rc < 0) -+ err(1, "Could not initialize context"); -+ -+ ctxp->verbose = verbose_cmd_line; -+ -+ ctxp->hash = 1; -+ ctxp->infile = strdup(infile); -+ if (!ctxp->infile) -+ err(1, "Could not allocate memory"); -+ -+ rc = set_digest_parameters(ctxp->cms_ctx, digest_name); -+ int is_help = strcmp(digest_name, "help") ? 0 : 1; -+ if (rc < 0) { -+ if (!is_help) { -+ fprintf(stderr, "Digest \"%s\" not found.\n", -+ digest_name); -+ } -+ exit(!is_help); -+ } -+ -+ errno = 0; -+ switch (fmt) { -+ case FORMAT_PE_BINARY: -+ pe_handle_action(ctxp, action, padding); -+ break; -+ case FORMAT_KERNEL_MODULE: -+ kmod_handle_action(ctxp, action); -+ break; -+ } -+ -+ pesign_context_free(ctxp); -+ } -+ -+ poptFreeContext(optCon); -+ -+ if (digest_name && digest_name != orig_digest_name) -+ free(digest_name); -+ -+ status = NSS_Shutdown(); -+ if (status != SECSuccess) -+ errx(1, "could not shut down NSS: %s", -+ PORT_ErrorToString(PORT_GetError())); -+ -+ return 0; -+} -+ -+// vim:fenc=utf-8:tw=75:noet -diff --git a/src/.gitignore b/src/.gitignore -index 64ce217..f8f6d66 100644 ---- a/src/.gitignore -+++ b/src/.gitignore -@@ -5,6 +5,7 @@ client - efikeygen - efidbtool - pesigcheck -+pesum - peverify - pesign.service - pesign.sysvinit -diff --git a/src/Makefile b/src/Makefile -index 7010514..79cf09e 100644 ---- a/src/Makefile -+++ b/src/Makefile -@@ -6,7 +6,7 @@ include $(TOPDIR)/Make.rules - include $(TOPDIR)/Make.defaults - - BINTARGETS=authvar client efikeygen pesigcheck pesign \ -- pesign-rpmbuild-helper pesign-authorize -+ pesign-rpmbuild-helper pesign-authorize pesum - CFGTARGETS=tmpfiles.conf - SVCTARGETS=pesign.sysvinit pesign.service - MAN1TARGETS=authvar.1 efikeygen.1 pesigcheck.1 pesign-client.1 pesign.1 -@@ -29,9 +29,12 @@ EFIKEYGEN_SOURCES = efikeygen.c - PESIGCHECK_SOURCES = pesigcheck.c pesigcheck_context.c certdb.c - PESIGN_SOURCES = pesign.c pesign_context.c actions.c daemon.c \ - file_pe.c file_kmod.c pesign_kmod.c -+PESUM_SOURCES = pesum.c pesign_context.c actions.c \ -+ file_pe.c file_kmod.c pesign_kmod.c - - ALL_SOURCES=$(COMMON_SOURCES) $(AUTHVAR_SORUCES) $(CLIENT_SOURCES) \ -- $(EFIKEYGEN_SOURCES) $(PESIGCHECK_SOURCES) $(PESIGN_SOURCES) -+ $(EFIKEYGEN_SOURCES) $(PESIGCHECK_SOURCES) $(PESIGN_SOURCES) \ -+ $(PESUM_SOURCES) - -include $(call deps-of,$(ALL_SOURCES)) - - authvar : $(call objects-of,$(AUTHVAR_SOURCES) $(COMMON_SOURCES)) -@@ -53,6 +56,10 @@ pesign : $(call objects-of,$(PESIGN_SOURCES) $(COMMON_SOURCES) $(COMMON_PE_SOURC - pesign : LDLIBS+=$(TOPDIR)/libdpe/libdpe.a - pesign : PKGS=efivar nss nspr popt - -+pesum : $(call objects-of,$(PESUM_SOURCES) $(COMMON_SOURCES) $(COMMON_PE_SOURCES)) -+pesum : LDLIBS+=$(TOPDIR)/libdpe/libdpe.a -+pesum : PKGS=efivar nss nspr popt -+ - deps : PKGS=efivar nss nspr popt uuid - deps : $(ALL_SOURCES) - $(MAKE) -f $(TOPDIR)/Make.deps \ -@@ -81,6 +88,7 @@ install : - $(INSTALL) -d -m 755 $(INSTALLROOT)$(bindir) - $(INSTALL) -m 755 authvar $(INSTALLROOT)$(bindir) - $(INSTALL) -m 755 pesign $(INSTALLROOT)$(bindir) -+ $(INSTALL) -m 755 pesum $(INSTALLROOT)$(bindir) - $(INSTALL) -m 755 client $(INSTALLROOT)$(bindir)pesign-client - $(INSTALL) -m 755 efikeygen $(INSTALLROOT)$(bindir) - $(INSTALL) -m 755 pesigcheck $(INSTALLROOT)$(bindir) -diff --git a/src/pesum.1.mdoc b/src/pesum.1.mdoc -new file mode 100644 -index 0000000..edd08ce ---- /dev/null -+++ b/src/pesum.1.mdoc -@@ -0,0 +1,38 @@ -+.Dd $Mdocdate: Mar 11 2022$ -+.Dt PESUM 1 -+.Os Linux -+.Sh NAME -+.Nm pesum -+.Nd tool for generating Authenticode digests -+.Sh SYNOPSIS -+.Nm -+.Bk -words -+.Ar file0.efi -+.Op Ar file1.efi ... -+.Sh DESCRIPTION -+.Nm -+is a command line tool to generate Authenticode digests of PE binaries. -+.Sh EXAMPLES -+.Ss Getting the Authenticode digest of some files -+host:$ \fBpesum shimx64.efi grubx64.efi\fR -+8c5806e66bb5b052ebf860e1722474269cff3dde588610df21dbe8cf12c08390\ shimx64.efi -+546a71319c22da1d81879383c4c74be06d1c374bdecfafc9fcc80bd541802bfc\ grubx64.efi -+.Sh STANDARDS -+.Rs -+.%B Portable Executable -+.%I Microsoft -+.%D August 26, 2019 -+.%U https://docs.microsoft.com/en-us/windows/win32/debug/pe-format\ \& -+.Re -+ -+.Rs -+.%B Windows Authenticode Portable Executable Signature Format -+.%I Microsoft -+.%D March 21, 2008 -+.%U https://web.archive.org/web/20130518222430/http://download.microsoft.com/download/9/c/5/9c5b2167-8017-4bae-9fde-d599bac8184a/Authenticode_PE.docx\ \& -+.Re -+.Sh SEE ALSO -+.Xr pesign 1 -+.LP -+.Sh AUTHORS -+.An Peter Jones diff --git a/0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch b/0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch deleted file mode 100644 index b342876..0000000 --- a/0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch +++ /dev/null @@ -1,54 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Julian Sikorski -Date: Wed, 23 Mar 2022 20:54:03 +0100 -Subject: [PATCH] Fix building signed kernels on setups other than koji - -Thanks to Will Springer for the idea. Details at -https://bugzilla.redhat.com/show_bug.cgi?id=1880858 - -Signed-off-by: Julian Sikorski -Suggested-by: Will Springer ---- - src/pesign-rpmbuild-helper.in | 24 +++++++++++------------- - 1 file changed, 11 insertions(+), 13 deletions(-) - -diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in -index 0a845d2..c9d5570 100644 ---- a/src/pesign-rpmbuild-helper.in -+++ b/src/pesign-rpmbuild-helper.in -@@ -172,24 +172,22 @@ main() { - USERNAME="${USERNAME:-$(id -un)}" - - local socket="" || : -- if grep -q ID=fedora /etc/os-release \ -+ if [[ -S /run/pesign/socket ]] ; then -+ socket=/run/pesign/socket -+ elif [[ -S /var/run/pesign/socket ]]; then -+ socket=/var/run/pesign/socket -+ elif grep -q ID=fedora /etc/os-release \ - && [[ "${rhelver}" -lt 7 ]] \ - && [[ "${USERNAME}" = "mockbuild" ]] \ - && [[ "${vendor}" = "Fedora Project" ]] \ - && [[ "${HOSTNAME}" =~ bkernel.* ]] - then -- if [[ -S /run/pesign/socket ]] ; then -- socket=/run/pesign/socket -- elif [[ -S /var/run/pesign/socket ]]; then -- socket=/var/run/pesign/socket -- else -- echo "Warning: no pesign socket even though user is ${USERNAME}" 1>&2 -- echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 -- ls -ld /run/pesign /var/run/pesign 1>&2 ||: -- ls -l /run/pesign/socket /var/run/pesign/socket 1>&2 ||: -- getfacl /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: -- getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: -- fi -+ echo "Warning: no pesign socket even though user is ${USERNAME}" 1>&2 -+ echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2 -+ ls -ld /run/pesign /var/run/pesign 1>&2 ||: -+ ls -l /run/pesign/socket /var/run/pesign/socket 1>&2 ||: -+ getfacl /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: -+ getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: - fi - - if [[ "${rhelver}" -ge 7 ]] ; then diff --git a/0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch b/0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch deleted file mode 100644 index 187a623..0000000 --- a/0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch +++ /dev/null @@ -1,23 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 25 Mar 2022 15:01:54 -0400 -Subject: [PATCH] Add -D_GLIBCXX_ASSERTIONS to CPPFLAGS - -Signed-off-by: Robbie Harwood ---- - Make.defaults | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/Make.defaults b/Make.defaults -index 1c18904..05aadd0 100644 ---- a/Make.defaults -+++ b/Make.defaults -@@ -79,7 +79,7 @@ ccldflags = $(cflags) $(CCLDFLAGS) $(LDFLAGS) \ - $(call pkg-config-ccldflags) - efi_cflags = $(cflags) - ASFLAGS ?= $(ARCH3264) --CPPFLAGS ?= -D_FORTIFY_SOURCE=2 -+CPPFLAGS ?= -D_FORTIFY_SOURCE=2 -D_GLIBCXX_ASSERTIONS - RANLIBFLAGS ?= $(if $(filter $(CC),gcc),-D) - ARFLAGS ?= $(if $(filter $(CC),gcc),-Dcvqs)$(if $(filter $(CC),clang),-cqvs) - diff --git a/0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch b/0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch deleted file mode 100644 index 68cbe5f..0000000 --- a/0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch +++ /dev/null @@ -1,24 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 10 Aug 2021 12:39:08 -0400 -Subject: [PATCH] macros.pesign: handle centos like rhel with --rhelver - -Signed-off-by: Peter Jones ---- - src/macros.pesign | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/src/macros.pesign b/src/macros.pesign -index 34af57c..b7d6af1 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -34,7 +34,8 @@ - %{?__pesign_cert:--cert %{__pesign_cert}} \\\ - %{?_buildhost:--hostname "%{_buildhost}"} \\\ - %{?vendor:--vendor "%{vendor}"} \\\ -- %{?_rhel:--rhelver "%{_rhel}"} \\\ -+ %{?rhel:--rhelver "%{rhel}"} \\\ -+ %{?centos:--rhelver "%{centos}"} \\\ - %{?-n:--rhelcert %{-n*}}%{?!-n:--rhelcert %{__pesign_cert}} \\\ - %{?-a:--rhelcafile "%{-a*}"} \\\ - %{?-c:--rhelcertfile "%{-c*}"} \\\ diff --git a/0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch b/0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch deleted file mode 100644 index bb4bef2..0000000 --- a/0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch +++ /dev/null @@ -1,25 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 4 Apr 2022 14:45:29 -0400 -Subject: [PATCH] Detect the presence of rpm-sign when checking for "rhel"-ness - -Signed-off-by: Peter Jones -[rharwood: manually reapply to main] -Signed-off-by: Robbie Harwood ---- - src/pesign-rpmbuild-helper.in | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in -index c9d5570..9dee56e 100644 ---- a/src/pesign-rpmbuild-helper.in -+++ b/src/pesign-rpmbuild-helper.in -@@ -190,7 +190,7 @@ main() { - getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||: - fi - -- if [[ "${rhelver}" -ge 7 ]] ; then -+ if [[ "${rhelver}" -ge 7 ]] && which rpm-sign >&/dev/null ; then - nssdir="$(mktemp -p "${PWD}" -d)" - echo > "${nssdir}/pwfile" - certutil -N -d "${nssdir}" -f "${nssdir}/pwfile" diff --git a/0011-Rename-README-README.md.patch b/0011-Rename-README-README.md.patch deleted file mode 100644 index ff10b8d..0000000 --- a/0011-Rename-README-README.md.patch +++ /dev/null @@ -1,17 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 13 May 2022 15:53:05 -0400 -Subject: [PATCH] Rename README -> README.md - -Rich text will let me compact links. - -Signed-off-by: Robbie Harwood ---- - README => README.md | 0 - 1 file changed, 0 insertions(+), 0 deletions(-) - rename README => README.md (100%) - -diff --git a/README b/README.md -similarity index 100% -rename from README -rename to README.md diff --git a/0012-README.md-show-off-a-bit-more.patch b/0012-README.md-show-off-a-bit-more.patch deleted file mode 100644 index 9d624f2..0000000 --- a/0012-README.md-show-off-a-bit-more.patch +++ /dev/null @@ -1,56 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 13 May 2022 16:09:12 -0400 -Subject: [PATCH] README.md: show off a bit more - -Prominently mention efikeygen and add examples of usage for it and -pesign proper. - -Signed-off-by: Robbie Harwood ---- - README.md | 36 ++++++++++++++++++++++++++++++++---- - 1 file changed, 32 insertions(+), 4 deletions(-) - -diff --git a/README.md b/README.md -index d70bc53..e9f0cb7 100644 ---- a/README.md -+++ b/README.md -@@ -1,6 +1,34 @@ --Signing tool for PE-COFF binaries, hopefully at least vaguely compliant with --the PE and Authenticode specifications. -+# pesign + efikeygen - --This is vaguely analogous to the tool described by --http://msdn.microsoft.com/en-us/library/8s9b9yaz%28v=vs.80%29.aspx -+Signing tools for PE-COFF binaries. Compliant with the PE and Authenticode -+specifications. - -+(These serve a similar purpose to Microsoft's -+[SignTool.exe](http://msdn.microsoft.com/en-us/library/8s9b9yaz%28v=vs.80%29.aspx), -+except for Linux.) -+ -+## Examples -+ -+Generate a key for use with pesign, stored on disk: -+ -+``` -+efikeyen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' -+``` -+ -+For more complex and secure use cases (e.g., hardware tokens), see -+efikeygen man page (`man efikeygen`). -+ -+Sign a UEFI application using that key: -+ -+``` -+pesign -i grubx64.efi -o grubx64.efi.signed -c 'Custom Secureboot' -s -+``` -+ -+Show signatures on a UEFI application: -+ -+``` -+pesign -i grubx64.efi.signed -S -+``` -+ -+For more signing/verification operations, see the pesign man page (`man -+pesign`). diff --git a/0013-Fix-missing-line-in-README.md.patch b/0013-Fix-missing-line-in-README.md.patch deleted file mode 100644 index 185bcc3..0000000 --- a/0013-Fix-missing-line-in-README.md.patch +++ /dev/null @@ -1,23 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Mon, 16 May 2022 15:31:25 -0400 -Subject: [PATCH] Fix missing line in README.md - -Signed-off-by: Robbie Harwood ---- - README.md | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/README.md b/README.md -index e9f0cb7..7bbd6dd 100644 ---- a/README.md -+++ b/README.md -@@ -15,6 +15,8 @@ Generate a key for use with pesign, stored on disk: - efikeyen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' - ``` - -+(where TYPE is m if you're only signing kernel modules, and k otherwise). -+ - For more complex and secure use cases (e.g., hardware tokens), see - efikeygen man page (`man efikeygen`). - diff --git a/0014-Fix-typo-in-efikeygen-command.patch b/0014-Fix-typo-in-efikeygen-command.patch deleted file mode 100644 index 82d228d..0000000 --- a/0014-Fix-typo-in-efikeygen-command.patch +++ /dev/null @@ -1,23 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Matt Bernhard -Date: Fri, 27 May 2022 14:40:49 -0400 -Subject: [PATCH] Fix typo in efikeygen command - -Signed-off-by: Matt Bernhard ---- - README.md | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/README.md b/README.md -index 7bbd6dd..b6949a2 100644 ---- a/README.md -+++ b/README.md -@@ -12,7 +12,7 @@ except for Linux.) - Generate a key for use with pesign, stored on disk: - - ``` --efikeyen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' -+efikeygen -d /etc/pki/pesign -S -TYPE -c 'CN=Your Name Key' -n 'Custom Secureboot' - ``` - - (where TYPE is m if you're only signing kernel modules, and k otherwise). diff --git a/0015-pesigcheck-Fix-crash-on-digest-match.patch b/0015-pesigcheck-Fix-crash-on-digest-match.patch deleted file mode 100644 index c948558..0000000 --- a/0015-pesigcheck-Fix-crash-on-digest-match.patch +++ /dev/null @@ -1,53 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Visa Hankala -Date: Fri, 10 Jun 2022 13:25:13 +0000 -Subject: [PATCH] pesigcheck: Fix crash on digest match - -Set selected_digest when the digest is found in db or dbx. -This fixes the following crash of pesigcheck: - - Program received signal SIGSEGV, Segmentation fault. - 0x00005555555597fa in memcpy (__len=24, __src=0x31, - __dest=0x55555558d908) - at /usr/include/x86_64-linux-gnu/bits/string_fortified.h:34 - 34 return __builtin___memcpy_chk (__dest, __src, __len, __bos0 (__dest)); - (gdb) bt - #0 0x00005555555597fa in memcpy (__len=24, __src=0x31, - __dest=0x55555558d908) - at /usr/include/x86_64-linux-gnu/bits/string_fortified.h:34 - #1 get_digest (digest=digest@entry=0x55555558d908, - ctx=, ctx=) at pesigcheck.c:226 - #2 0x00005555555592fd in check_signature ( - reasons=, nreasons=, - ctx=0x7fffffffded0) at pesigcheck.c:262 - #3 main (argc=, argv=) - at pesigcheck.c:512 - -Signed-off-by: Visa Hankala ---- - src/certdb.c | 8 ++++++-- - 1 file changed, 6 insertions(+), 2 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index e013b9d..69d5daf 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -267,12 +267,16 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - - if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { - digest = ctx->cms_ctx->digests[0].pe_digest->data; -- if (memcmp (digest, sig->data, 32) == 0) -+ if (memcmp (digest, sig->data, 32) == 0) { -+ ctx->cms_ctx->selected_digest = 0; - return FOUND; -+ } - } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { - digest = ctx->cms_ctx->digests[1].pe_digest->data; -- if (memcmp (digest, sig->data, 20) == 0) -+ if (memcmp (digest, sig->data, 20) == 0) { -+ ctx->cms_ctx->selected_digest = 1; - return FOUND; -+ } - } - - return NOT_FOUND; diff --git a/0016-cms-store-digest-as-pointer-instead-of-index.patch b/0016-cms-store-digest-as-pointer-instead-of-index.patch deleted file mode 100644 index a7fc4dd..0000000 --- a/0016-cms-store-digest-as-pointer-instead-of-index.patch +++ /dev/null @@ -1,272 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Fri, 10 Jun 2022 14:40:33 -0400 -Subject: [PATCH] cms: store digest as pointer instead of index - -Storage as an index is problematic because the sentinel value -1 was -used, but accesses were unchecked, leading to crashes like that in -3b1031a6b779cb80c11b34eec84c5a0cc215efed ("pesigcheck: Fix crash on -digest match"). By storing a pointer, we get an explicit NULL -dereference: still a crash, but preferred since it's clearer. - -Since the index was previously also used for retrieving digest -parameters, include a pointer to the relevant struct digest_param in the -struct digest. - -Signed-off-by: Robbie Harwood ---- - src/certdb.c | 15 ++++++++------- - src/cms_common.c | 34 ++++++++++------------------------ - src/content_info.c | 4 ++-- - src/file_kmod.c | 2 +- - src/file_pe.c | 9 +++++---- - src/pesigcheck.c | 4 +--- - src/cms_common.h | 13 ++++++++++++- - 7 files changed, 39 insertions(+), 42 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index 69d5daf..f512824 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -263,18 +263,19 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - { - efi_guid_t efi_sha256 = efi_guid_sha256; - efi_guid_t efi_sha1 = efi_guid_sha1; -- void *digest; -+ void *digest_data; -+ struct digest *digests = ctx->cms_ctx->digests; - - if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { -- digest = ctx->cms_ctx->digests[0].pe_digest->data; -- if (memcmp (digest, sig->data, 32) == 0) { -- ctx->cms_ctx->selected_digest = 0; -+ digest_data = digests[0].pe_digest->data; -+ if (memcmp (digest_data, sig->data, 32) == 0) { -+ ctx->cms_ctx->selected_digest = &digests[0]; - return FOUND; - } - } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { -- digest = ctx->cms_ctx->digests[1].pe_digest->data; -- if (memcmp (digest, sig->data, 20) == 0) { -- ctx->cms_ctx->selected_digest = 1; -+ digest_data = digests[1].pe_digest->data; -+ if (memcmp (digest_data, sig->data, 20) == 0) { -+ ctx->cms_ctx->selected_digest = &digests[1]; - return FOUND; - } - } -diff --git a/src/cms_common.c b/src/cms_common.c -index 86341ca..2275f67 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -33,15 +33,6 @@ - - #include "hex.h" - --struct digest_param { -- char *name; -- SECOidTag digest_tag; -- SECOidTag signature_tag; -- SECOidTag digest_encryption_tag; -- const efi_guid_t *efi_guid; -- int size; --}; -- - static struct digest_param digest_params[] = { - {.name = "sha256", - .digest_tag = SEC_OID_SHA256, -@@ -65,29 +56,25 @@ static int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); - SECOidTag - digest_get_digest_oid(cms_context *cms) - { -- int i = cms->selected_digest; -- return digest_params[i].digest_tag; -+ return cms->selected_digest->digest_params->digest_tag; - } - - SECOidTag - digest_get_encryption_oid(cms_context *cms) - { -- int i = cms->selected_digest; -- return digest_params[i].digest_encryption_tag; -+ return cms->selected_digest->digest_params->digest_encryption_tag; - } - - SECOidTag - digest_get_signature_oid(cms_context *cms) - { -- int i = cms->selected_digest; -- return digest_params[i].signature_tag; -+ return cms->selected_digest->digest_params->signature_tag; - } - - int - digest_get_digest_size(cms_context *cms) - { -- int i = cms->selected_digest; -- return digest_params[i].size; -+ return cms->selected_digest->digest_params->size; - } - - void -@@ -142,8 +129,6 @@ cms_context_init(cms_context *cms) - if (!cms->arena) - cnreterr(-1, cms, "could not create cryptographic arena"); - -- cms->selected_digest = -1; -- - INIT_LIST_HEAD(&cms->pk12_ins); - cms->pk12_out.fd = -1; - cms->db_out = cms->dbx_out = cms->dbt_out = -1; -@@ -226,7 +211,7 @@ cms_context_fini(cms_context *cms) - memset(&cms->newsig, '\0', sizeof (cms->newsig)); - } - -- cms->selected_digest = -1; -+ cms->selected_digest = NULL; - - if (cms->ci_digest) { - free_poison(cms->ci_digest->data, cms->ci_digest->len); -@@ -351,7 +336,7 @@ set_digest_parameters(cms_context *cms, char *name) - if (strcmp(name, "help")) { - for (int i = 0; i < n_digest_params; i++) { - if (!strcmp(name, digest_params[i].name)) { -- cms->selected_digest = i; -+ cms->selected_digest = &cms->digests[i]; - return 0; - } - } -@@ -1279,6 +1264,7 @@ generate_digest_begin(cms_context *cms) - cngotoerr(err, cms, "could not create digest context"); - - PK11_DigestBegin(digests[i].pk11ctx); -+ digests[i].digest_params = &digest_params[i]; - } - - cms->digests = digests; -@@ -1351,11 +1337,11 @@ generate_signature(cms_context *cms) - { - int rc = 0; - -- if (cms->digests[cms->selected_digest].pe_digest == NULL) -+ if (cms->selected_digest->pe_digest == NULL) - cnreterr(-1, cms, "PE digest has not been allocated"); - -- if (content_is_empty(cms->digests[cms->selected_digest].pe_digest->data, -- cms->digests[cms->selected_digest].pe_digest->len)) -+ if (content_is_empty(cms->selected_digest->pe_digest->data, -+ cms->selected_digest->pe_digest->len)) - cnreterr(-1, cms, "PE binary has not been digested"); - - SECItem sd_der; -diff --git a/src/content_info.c b/src/content_info.c -index 9684850..777aa28 100644 ---- a/src/content_info.c -+++ b/src/content_info.c -@@ -181,8 +181,8 @@ generate_spc_digest_info(cms_context *cms, SECItem *dip) - if (generate_algorithm_id(cms, &di.digestAlgorithm, - digest_get_digest_oid(cms)) < 0) - return -1; -- int i = cms->selected_digest; -- memcpy(&di.digest, cms->digests[i].pe_digest, sizeof (di.digest)); -+ memcpy(&di.digest, cms->selected_digest->pe_digest, -+ sizeof(di.digest)); - - if (content_is_empty(di.digest.data, di.digest.len)) { - cms->log(cms, LOG_ERR, "got empty digest"); -diff --git a/src/file_kmod.c b/src/file_kmod.c -index 6880cda..c8875fc 100644 ---- a/src/file_kmod.c -+++ b/src/file_kmod.c -@@ -60,7 +60,7 @@ ssize_t - kmod_write_signature(cms_context *cms, int outfd) - { - SEC_PKCS7ContentInfo *cinfo; -- SECItem *digest = cms->digests[cms->selected_digest].pe_digest; -+ SECItem *digest = cms->selected_digest->pe_digest; - SECStatus rv; - struct write_sig_info info = { - .outfd = outfd, -diff --git a/src/file_pe.c b/src/file_pe.c -index 805e614..c22b2af 100644 ---- a/src/file_pe.c -+++ b/src/file_pe.c -@@ -114,6 +114,8 @@ check_inputs(pesign_context *ctx) - static void - print_digest(pesign_context *pctx) - { -+ unsigned int i; -+ - if (!pctx) - return; - -@@ -121,10 +123,9 @@ print_digest(pesign_context *pctx) - if (!ctx) - return; - -- int j = ctx->selected_digest; -- for (unsigned int i = 0; i < ctx->digests[j].pe_digest->len; i++) -- printf("%02x", -- (unsigned char)ctx->digests[j].pe_digest->data[i]); -+ unsigned char *ddata = ctx->selected_digest->pe_digest->data; -+ for (i = 0; i < ctx->selected_digest->pe_digest->len; i++) -+ printf("%02x", ddata[i]); - printf(" %s\n", pctx->infile); - } - -diff --git a/src/pesigcheck.c b/src/pesigcheck.c -index 6dc67f7..ebb404d 100644 ---- a/src/pesigcheck.c -+++ b/src/pesigcheck.c -@@ -221,9 +221,7 @@ static void - get_digest(pesigcheck_context *ctx, SECItem *digest) - { - struct cms_context *cms = ctx->cms_ctx; -- struct digest *cms_digest = &cms->digests[cms->selected_digest]; -- -- memcpy(digest, cms_digest->pe_digest, sizeof (*digest)); -+ memcpy(digest, cms->selected_digest->pe_digest, sizeof(*digest)); - } - - static int -diff --git a/src/cms_common.h b/src/cms_common.h -index c7acbcf..c7d4f69 100644 ---- a/src/cms_common.h -+++ b/src/cms_common.h -@@ -12,6 +12,7 @@ - #include - - #include -+#include - #include - #include - #include -@@ -57,9 +58,19 @@ - goto errlabel; \ - }) - -+struct digest_param { -+ char *name; -+ SECOidTag digest_tag; -+ SECOidTag signature_tag; -+ SECOidTag digest_encryption_tag; -+ const efi_guid_t *efi_guid; -+ int size; -+}; -+ - struct digest { - PK11Context *pk11ctx; - SECItem *pe_digest; -+ struct digest_param *digest_params; - }; - - typedef struct pk12_file { -@@ -133,7 +144,7 @@ typedef struct cms_context { - int db_out, dbx_out, dbt_out; - - struct digest *digests; -- int selected_digest; -+ struct digest *selected_digest; - int omit_vendor_cert; - - SECItem newsig; diff --git a/0017-Fix-mandoc-invocation-to-not-produce-garbage.patch b/0017-Fix-mandoc-invocation-to-not-produce-garbage.patch deleted file mode 100644 index 648055e..0000000 --- a/0017-Fix-mandoc-invocation-to-not-produce-garbage.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Robbie Harwood -Date: Thu, 7 Jul 2022 16:56:41 -0400 -Subject: [PATCH] Fix mandoc invocation to not produce garbage - -Bizarrely, mandoc doesn't default to outputting man - the default is -"locale", which is either ASCII or UTF-8 (by locale). This output is -supposed to be some kind of plain-text, but it's formatted so strangely -I'm not sure what the purpose is. Regardless, it doesn't go well to -feed this into man(1). - -Tell mandoc explicitly to produce man pages. - -Signed-off-by: Robbie Harwood ---- - Make.rules | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/Make.rules b/Make.rules -index 12e322b..f6bf5fa 100644 ---- a/Make.rules -+++ b/Make.rules -@@ -54,7 +54,7 @@ define substitute-version = - endef - - %.1 : %.1.mdoc -- @mandoc -man -Ios=Linux $^ > $@ -+ @mandoc -man -T man -Ios=Linux $^ > $@ - - % : %.in - @$(call substitute-version,$<,$@) diff --git a/0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch b/0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch deleted file mode 100644 index 3d0fd63..0000000 --- a/0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 29 Aug 2022 15:31:52 -0400 -Subject: [PATCH] Work around GCC being obnoxiously incompatible with GCC - -GCC added and then later removed the diagnostic flag -"-Wanalyzer-use-of-uninitialized-value", and so this doesn't work with -newer versions of GCC. - -This patch removes the previous workaround for when it didn't work well. -I really wish any of our compilers had any sense of rigor with this -stuff at all. - -Signed-off-by: Peter Jones ---- - src/daemon.c | 5 ----- - 1 file changed, 5 deletions(-) - -diff --git a/src/daemon.c b/src/daemon.c -index ff88210..d66dd50 100644 ---- a/src/daemon.c -+++ b/src/daemon.c -@@ -917,10 +917,6 @@ do_shutdown(context *ctx, int nsockets, struct pollfd *pollfds) - free(pollfds); - } - --/* GCC -fanalyzer has trouble with realloc -- * https://bugzilla.redhat.com/show_bug.cgi?id=2047926 */ --#pragma GCC diagnostic push --#pragma GCC diagnostic ignored "-Wanalyzer-use-of-uninitialized-value" - static int - handle_events(context *ctx) - { -@@ -999,7 +995,6 @@ shutdown: - } - return 0; - } --#pragma GCC diagnostic pop - - static int - get_uid_and_gid(context *ctx, char **homedir) diff --git a/0019-get_password_passthrough-handle-the-callback-context.patch b/0019-get_password_passthrough-handle-the-callback-context.patch deleted file mode 100644 index 3240a32..0000000 --- a/0019-get_password_passthrough-handle-the-callback-context.patch +++ /dev/null @@ -1,51 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 29 Aug 2022 14:21:44 -0400 -Subject: [PATCH] get_password_passthrough(): handle the callback context right - -Right now, we have a few callback functions for PK11_Authenticate(), and -they take different arguments. This is incorrect; none of the callers -ever pass anything through except our CMS context. - -This fixes get_password_passthrough() to correctly accept the CMS -context and get the passthrough data from cms->pwdata instead of trying -to treat the CMS context as the pwdata. - -Related: rhbz#2122777 - -Signed-off-by: Peter Jones ---- - src/password.c | 16 +++++++++++++--- - 1 file changed, 13 insertions(+), 3 deletions(-) - -diff --git a/src/password.c b/src/password.c -index 18c32ed..8eb1c33 100644 ---- a/src/password.c -+++ b/src/password.c -@@ -365,13 +365,23 @@ err: - } - - char * --get_password_passthrough(PK11SlotInfo *slot UNUSED, -- PRBool retry, void *arg) -+get_password_passthrough(PK11SlotInfo *slot UNUSED, PRBool retry, void *arg) - { -+ cms_context *cms; -+ secuPWData *pwdata; -+ -+ dbgprintf("ctx:%p", arg); -+ - if (retry || !arg) - return NULL; - -- char *ret = strdup(arg); -+ cms = (cms_context *)arg; -+ pwdata = &cms->pwdata; -+ -+ if (pwdata->source != PW_PLAINTEXT) -+ return NULL; -+ -+ char *ret = strdup(pwdata->data); - if (!ret) - err(1, "Could not allocate memory"); - diff --git a/0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch b/0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch deleted file mode 100644 index b69d5ff..0000000 --- a/0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 29 Aug 2022 15:22:10 -0400 -Subject: [PATCH] read_password(): only prune CR/NL from the end of the file - -Right now, when we read the password/PIN from a file, we're pruning the -end of the string from the file we read indiscriminately. If you don't -have a newline, that means we're cutting off the final digits of the -text. - -This changes it to prune only common special characters from the -pinfile, but also to prune /all/ of them. - -Related: rhbz#2122777 -Signed-off-by: Peter Jones ---- - src/password.c | 10 +++++++++- - 1 file changed, 9 insertions(+), 1 deletion(-) - -diff --git a/src/password.c b/src/password.c -index 8eb1c33..ac1866e 100644 ---- a/src/password.c -+++ b/src/password.c -@@ -79,6 +79,7 @@ read_password(FILE *in, FILE *out, char *buf, size_t bufsz) - int infd = fileno(in); - struct termios tio; - char *ret; -+ int len; - - ingress(); - ret = fgets(buf, bufsz, in); -@@ -96,7 +97,14 @@ read_password(FILE *in, FILE *out, char *buf, size_t bufsz) - if (ret == NULL) - return -1; - -- buf[strlen(buf)-1] = '\0'; -+ len = strlen(buf); -+ while (len > 0 && (buf[len-1] == '\r' || buf[len-1] == '\n')) { -+ buf[len-1] = '\0'; -+ len--; -+ } -+ if (len == 0) -+ return -1; -+ - egress(); - return 0; - } diff --git a/0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch b/0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch deleted file mode 100644 index ac9bdfd..0000000 --- a/0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch +++ /dev/null @@ -1,276 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 29 Aug 2022 16:22:18 -0400 -Subject: [PATCH] Revert "cms: store digest as pointer instead of index" - -In 926782c216532a83f9ff864dee39d2349d61fd23, we switched -cms->selected_digest to be a pointer to the member of the digests array -rather than an index. Unfortunately this is just as bad, because the -bugs that come up wind up setting pointers to NULL+(selected*offset), -i.e. 0x10, and that doesn't get us any closer to actually finding any -problem. - -For now, the new approach is going to be to make it an index again, but -to default it to 0 (sha256) rather than -1, so if it isn't set at the -correct part of the lifecycle it'll just default to the (nearly always) -correct choice. - -This reverts commit 926782c216532a83f9ff864dee39d2349d61fd23. - -Signed-off-by: Peter Jones ---- - src/certdb.c | 15 +++++++-------- - src/cms_common.c | 34 ++++++++++++++++++++++++---------- - src/content_info.c | 4 ++-- - src/file_kmod.c | 2 +- - src/file_pe.c | 9 ++++----- - src/pesigcheck.c | 4 +++- - src/cms_common.h | 13 +------------ - 7 files changed, 42 insertions(+), 39 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index f512824..69d5daf 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -263,19 +263,18 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - { - efi_guid_t efi_sha256 = efi_guid_sha256; - efi_guid_t efi_sha1 = efi_guid_sha1; -- void *digest_data; -- struct digest *digests = ctx->cms_ctx->digests; -+ void *digest; - - if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { -- digest_data = digests[0].pe_digest->data; -- if (memcmp (digest_data, sig->data, 32) == 0) { -- ctx->cms_ctx->selected_digest = &digests[0]; -+ digest = ctx->cms_ctx->digests[0].pe_digest->data; -+ if (memcmp (digest, sig->data, 32) == 0) { -+ ctx->cms_ctx->selected_digest = 0; - return FOUND; - } - } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { -- digest_data = digests[1].pe_digest->data; -- if (memcmp (digest_data, sig->data, 20) == 0) { -- ctx->cms_ctx->selected_digest = &digests[1]; -+ digest = ctx->cms_ctx->digests[1].pe_digest->data; -+ if (memcmp (digest, sig->data, 20) == 0) { -+ ctx->cms_ctx->selected_digest = 1; - return FOUND; - } - } -diff --git a/src/cms_common.c b/src/cms_common.c -index 2275f67..86341ca 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -33,6 +33,15 @@ - - #include "hex.h" - -+struct digest_param { -+ char *name; -+ SECOidTag digest_tag; -+ SECOidTag signature_tag; -+ SECOidTag digest_encryption_tag; -+ const efi_guid_t *efi_guid; -+ int size; -+}; -+ - static struct digest_param digest_params[] = { - {.name = "sha256", - .digest_tag = SEC_OID_SHA256, -@@ -56,25 +65,29 @@ static int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); - SECOidTag - digest_get_digest_oid(cms_context *cms) - { -- return cms->selected_digest->digest_params->digest_tag; -+ int i = cms->selected_digest; -+ return digest_params[i].digest_tag; - } - - SECOidTag - digest_get_encryption_oid(cms_context *cms) - { -- return cms->selected_digest->digest_params->digest_encryption_tag; -+ int i = cms->selected_digest; -+ return digest_params[i].digest_encryption_tag; - } - - SECOidTag - digest_get_signature_oid(cms_context *cms) - { -- return cms->selected_digest->digest_params->signature_tag; -+ int i = cms->selected_digest; -+ return digest_params[i].signature_tag; - } - - int - digest_get_digest_size(cms_context *cms) - { -- return cms->selected_digest->digest_params->size; -+ int i = cms->selected_digest; -+ return digest_params[i].size; - } - - void -@@ -129,6 +142,8 @@ cms_context_init(cms_context *cms) - if (!cms->arena) - cnreterr(-1, cms, "could not create cryptographic arena"); - -+ cms->selected_digest = -1; -+ - INIT_LIST_HEAD(&cms->pk12_ins); - cms->pk12_out.fd = -1; - cms->db_out = cms->dbx_out = cms->dbt_out = -1; -@@ -211,7 +226,7 @@ cms_context_fini(cms_context *cms) - memset(&cms->newsig, '\0', sizeof (cms->newsig)); - } - -- cms->selected_digest = NULL; -+ cms->selected_digest = -1; - - if (cms->ci_digest) { - free_poison(cms->ci_digest->data, cms->ci_digest->len); -@@ -336,7 +351,7 @@ set_digest_parameters(cms_context *cms, char *name) - if (strcmp(name, "help")) { - for (int i = 0; i < n_digest_params; i++) { - if (!strcmp(name, digest_params[i].name)) { -- cms->selected_digest = &cms->digests[i]; -+ cms->selected_digest = i; - return 0; - } - } -@@ -1264,7 +1279,6 @@ generate_digest_begin(cms_context *cms) - cngotoerr(err, cms, "could not create digest context"); - - PK11_DigestBegin(digests[i].pk11ctx); -- digests[i].digest_params = &digest_params[i]; - } - - cms->digests = digests; -@@ -1337,11 +1351,11 @@ generate_signature(cms_context *cms) - { - int rc = 0; - -- if (cms->selected_digest->pe_digest == NULL) -+ if (cms->digests[cms->selected_digest].pe_digest == NULL) - cnreterr(-1, cms, "PE digest has not been allocated"); - -- if (content_is_empty(cms->selected_digest->pe_digest->data, -- cms->selected_digest->pe_digest->len)) -+ if (content_is_empty(cms->digests[cms->selected_digest].pe_digest->data, -+ cms->digests[cms->selected_digest].pe_digest->len)) - cnreterr(-1, cms, "PE binary has not been digested"); - - SECItem sd_der; -diff --git a/src/content_info.c b/src/content_info.c -index 777aa28..9684850 100644 ---- a/src/content_info.c -+++ b/src/content_info.c -@@ -181,8 +181,8 @@ generate_spc_digest_info(cms_context *cms, SECItem *dip) - if (generate_algorithm_id(cms, &di.digestAlgorithm, - digest_get_digest_oid(cms)) < 0) - return -1; -- memcpy(&di.digest, cms->selected_digest->pe_digest, -- sizeof(di.digest)); -+ int i = cms->selected_digest; -+ memcpy(&di.digest, cms->digests[i].pe_digest, sizeof (di.digest)); - - if (content_is_empty(di.digest.data, di.digest.len)) { - cms->log(cms, LOG_ERR, "got empty digest"); -diff --git a/src/file_kmod.c b/src/file_kmod.c -index c8875fc..6880cda 100644 ---- a/src/file_kmod.c -+++ b/src/file_kmod.c -@@ -60,7 +60,7 @@ ssize_t - kmod_write_signature(cms_context *cms, int outfd) - { - SEC_PKCS7ContentInfo *cinfo; -- SECItem *digest = cms->selected_digest->pe_digest; -+ SECItem *digest = cms->digests[cms->selected_digest].pe_digest; - SECStatus rv; - struct write_sig_info info = { - .outfd = outfd, -diff --git a/src/file_pe.c b/src/file_pe.c -index c22b2af..805e614 100644 ---- a/src/file_pe.c -+++ b/src/file_pe.c -@@ -114,8 +114,6 @@ check_inputs(pesign_context *ctx) - static void - print_digest(pesign_context *pctx) - { -- unsigned int i; -- - if (!pctx) - return; - -@@ -123,9 +121,10 @@ print_digest(pesign_context *pctx) - if (!ctx) - return; - -- unsigned char *ddata = ctx->selected_digest->pe_digest->data; -- for (i = 0; i < ctx->selected_digest->pe_digest->len; i++) -- printf("%02x", ddata[i]); -+ int j = ctx->selected_digest; -+ for (unsigned int i = 0; i < ctx->digests[j].pe_digest->len; i++) -+ printf("%02x", -+ (unsigned char)ctx->digests[j].pe_digest->data[i]); - printf(" %s\n", pctx->infile); - } - -diff --git a/src/pesigcheck.c b/src/pesigcheck.c -index ebb404d..6dc67f7 100644 ---- a/src/pesigcheck.c -+++ b/src/pesigcheck.c -@@ -221,7 +221,9 @@ static void - get_digest(pesigcheck_context *ctx, SECItem *digest) - { - struct cms_context *cms = ctx->cms_ctx; -- memcpy(digest, cms->selected_digest->pe_digest, sizeof(*digest)); -+ struct digest *cms_digest = &cms->digests[cms->selected_digest]; -+ -+ memcpy(digest, cms_digest->pe_digest, sizeof (*digest)); - } - - static int -diff --git a/src/cms_common.h b/src/cms_common.h -index c7d4f69..c7acbcf 100644 ---- a/src/cms_common.h -+++ b/src/cms_common.h -@@ -12,7 +12,6 @@ - #include - - #include --#include - #include - #include - #include -@@ -58,19 +57,9 @@ - goto errlabel; \ - }) - --struct digest_param { -- char *name; -- SECOidTag digest_tag; -- SECOidTag signature_tag; -- SECOidTag digest_encryption_tag; -- const efi_guid_t *efi_guid; -- int size; --}; -- - struct digest { - PK11Context *pk11ctx; - SECItem *pe_digest; -- struct digest_param *digest_params; - }; - - typedef struct pk12_file { -@@ -144,7 +133,7 @@ typedef struct cms_context { - int db_out, dbx_out, dbt_out; - - struct digest *digests; -- struct digest *selected_digest; -+ int selected_digest; - int omit_vendor_cert; - - SECItem newsig; diff --git a/0022-CMS-add-some-minor-cleanups.patch b/0022-CMS-add-some-minor-cleanups.patch deleted file mode 100644 index dfff3f5..0000000 --- a/0022-CMS-add-some-minor-cleanups.patch +++ /dev/null @@ -1,149 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Mon, 29 Aug 2022 17:02:46 -0400 -Subject: [PATCH] CMS: add some minor cleanups - -We reverted 926782c216532a83f9ff864dee39d2349d61fd23 so that a future -patch can try a different approach, but that commit also had a few -cleanups that are worthwhile on their own. - -This patch re-introduces the cleanup to move "struct digest_param" to a -more reasonable place and the cleanup to check_hash(), and takes it just -a bit farther. - -Signed-off-by: Peter Jones ---- - src/certdb.c | 26 +++++++++++++++----------- - src/cms_common.c | 39 ++++++++++++++++----------------------- - src/cms_common.h | 16 ++++++++++++++++ - 3 files changed, 47 insertions(+), 34 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index 69d5daf..eb5221f 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -263,20 +263,24 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - { - efi_guid_t efi_sha256 = efi_guid_sha256; - efi_guid_t efi_sha1 = efi_guid_sha1; -- void *digest; -+ void *digest_data; -+ struct digest *digests = ctx->cms_ctx->digests; -+ int selected_digest = -1; -+ size_t size; - - if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { -- digest = ctx->cms_ctx->digests[0].pe_digest->data; -- if (memcmp (digest, sig->data, 32) == 0) { -- ctx->cms_ctx->selected_digest = 0; -- return FOUND; -- } -+ selected_digest = DIGEST_PARAM_SHA256; - } else if (memcmp(sigtype, &efi_sha1, sizeof(efi_guid_t)) == 0) { -- digest = ctx->cms_ctx->digests[1].pe_digest->data; -- if (memcmp (digest, sig->data, 20) == 0) { -- ctx->cms_ctx->selected_digest = 1; -- return FOUND; -- } -+ selected_digest = DIGEST_PARAM_SHA1; -+ } else { -+ return NOT_FOUND; -+ } -+ -+ digest_data = digests[selected_digest].pe_digest->data; -+ size = digest_params[selected_digest].size; -+ if (memcmp (digest_data, sig->data, size) == 0) { -+ ctx->cms_ctx->selected_digest = selected_digest; -+ return FOUND; - } - - return NOT_FOUND; -diff --git a/src/cms_common.c b/src/cms_common.c -index 86341ca..7bddedf 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -33,34 +33,27 @@ - - #include "hex.h" - --struct digest_param { -- char *name; -- SECOidTag digest_tag; -- SECOidTag signature_tag; -- SECOidTag digest_encryption_tag; -- const efi_guid_t *efi_guid; -- int size; --}; -- --static struct digest_param digest_params[] = { -- {.name = "sha256", -- .digest_tag = SEC_OID_SHA256, -- .signature_tag = SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION, -- .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, -- .efi_guid = &efi_guid_sha256, -- .size = 32 -+const struct digest_param digest_params[] = { -+ [DIGEST_PARAM_SHA256] = { -+ .name = "sha256", -+ .digest_tag = SEC_OID_SHA256, -+ .signature_tag = SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION, -+ .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, -+ .efi_guid = &efi_guid_sha256, -+ .size = 32 - }, - #if 1 -- {.name = "sha1", -- .digest_tag = SEC_OID_SHA1, -- .signature_tag = SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION, -- .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, -- .efi_guid = &efi_guid_sha1, -- .size = 20 -+ [DIGEST_PARAM_SHA1] = { -+ .name = "sha1", -+ .digest_tag = SEC_OID_SHA1, -+ .signature_tag = SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION, -+ .digest_encryption_tag = SEC_OID_PKCS1_RSA_ENCRYPTION, -+ .efi_guid = &efi_guid_sha1, -+ .size = 20 - }, - #endif - }; --static int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); -+const int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); - - SECOidTag - digest_get_digest_oid(cms_context *cms) -diff --git a/src/cms_common.h b/src/cms_common.h -index c7acbcf..e45402c 100644 ---- a/src/cms_common.h -+++ b/src/cms_common.h -@@ -12,6 +12,7 @@ - #include - - #include -+#include - #include - #include - #include -@@ -62,6 +63,21 @@ struct digest { - SECItem *pe_digest; - }; - -+#define DIGEST_PARAM_SHA256 0 -+#define DIGEST_PARAM_SHA1 1 -+ -+struct digest_param { -+ char *name; -+ SECOidTag digest_tag; -+ SECOidTag signature_tag; -+ SECOidTag digest_encryption_tag; -+ const efi_guid_t *efi_guid; -+ int size; -+}; -+ -+extern const struct digest_param digest_params[2]; -+extern const int n_digest_params; -+ - typedef struct pk12_file { - char *path; - int fd; diff --git a/0023-CMS-make-cms-selected_digest-an-index-again.patch b/0023-CMS-make-cms-selected_digest-an-index-again.patch deleted file mode 100644 index 6e19cd1..0000000 --- a/0023-CMS-make-cms-selected_digest-an-index-again.patch +++ /dev/null @@ -1,291 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Tue, 30 Aug 2022 15:42:15 -0400 -Subject: [PATCH] CMS: make cms->selected_digest an index (again) - -In 926782c216532a83f9ff864dee39d2349d61fd23, we switched -cms->selected_digest to be a pointer to the entry in cms->digests. - -Because cms->digests is lazily allocated, setting the selected_digest -pointer has to be done at the right part of the CMS context life cycle, -and in some cases it clearly is not: - -==334217== Command: ./src/pesign -n tmp -s --pinfile tmp/pinfile -t OpenSC\ Card\ (testcard) -c kernel-signer -i tmp/unsigned.efi -o tmp/signed.efi --force -==334217== -==334217== Invalid read of size 8 -==334217== at 0x115E7D: digest_get_digest_oid (cms_common.c:59) -==334217== by 0x11CF41: generate_algorithm_id_list (signed_data.c:33) -==334217== by 0x11D348: generate_spc_signed_data (signed_data.c:279) -==334217== by 0x11EDFD: calculate_signature_space (wincert.c:297) -==334217== by 0x11467D: pe_handle_action (file_pe.c:298) -==334217== by 0x10F962: main (pesign.c:585) -==334217== Address 0x10 is not stack'd, malloc'd or (recently) free'd -==334217== -==334217== -==334217== Process terminating with default action of signal 11 (SIGSEGV): dumping core -==334217== Access not within mapped region at address 0x10 -==334217== at 0x115E7D: digest_get_digest_oid (cms_common.c:59) -==334217== by 0x11CF41: generate_algorithm_id_list (signed_data.c:33) -==334217== by 0x11D348: generate_spc_signed_data (signed_data.c:279) -==334217== by 0x11EDFD: calculate_signature_space (wincert.c:297) -==334217== by 0x11467D: pe_handle_action (file_pe.c:298) -==334217== by 0x10F962: main (pesign.c:585) -==334217== If you believe this happened as a result of a stack -==334217== overflow in your program's main thread (unlikely but -==334217== possible), you can try to increase the size of the -==334217== main thread stack using the --main-stacksize= flag. -==334217== The main thread stack size used in this run was 8388608. -==334217== -==334217== HEAP SUMMARY: -==334217== in use at exit: 588,544 bytes in 4,388 blocks -==334217== total heap usage: 8,568 allocs, 4,180 frees, 2,077,115 bytes allocated -==334217== -==334217== LEAK SUMMARY: -==334217== definitely lost: 25 bytes in 1 blocks -==334217== indirectly lost: 0 bytes in 0 blocks -==334217== possibly lost: 51,378 bytes in 166 blocks -==334217== still reachable: 537,141 bytes in 4,221 blocks -==334217== of which reachable via heuristic: -==334217== length64 : 321,312 bytes in 590 blocks -==334217== suppressed: 0 bytes in 0 blocks -==334217== Rerun with --leak-check=full to see details of leaked memory -==334217== -==334217== For lists of detected and suppressed errors, rerun with: -s -==334217== ERROR SUMMARY: 1 errors from 1 contexts (suppressed: 0 from 0) -Segmentation fault (core dumped) - -There is also a similar issue in the daemon code, and how to fix it -there is not immediately clear to me. - -Currently, we realistically only support using sha256 digests, so for -now I've chosen to paper over the issue by switching back to -cms->selected_digest be an index into both ctx->digests and -digest_params, but switching the default value from -1 to 0, aka -DIGEST_PARAM_SHA256. We can revisit this issue later whenever we add -sha384 support (or whichever other digest). - -Signed-off-by: Peter Jones ---- - src/certdb.c | 2 +- - src/cms_common.c | 41 +++++++++++++++++++++++------------------ - src/content_info.c | 2 +- - src/cms_common.h | 5 +++-- - 4 files changed, 28 insertions(+), 22 deletions(-) - -diff --git a/src/certdb.c b/src/certdb.c -index eb5221f..467a01d 100644 ---- a/src/certdb.c -+++ b/src/certdb.c -@@ -265,7 +265,7 @@ check_hash(pesigcheck_context *ctx, SECItem *sig, efi_guid_t *sigtype, - efi_guid_t efi_sha1 = efi_guid_sha1; - void *digest_data; - struct digest *digests = ctx->cms_ctx->digests; -- int selected_digest = -1; -+ unsigned int selected_digest; - size_t size; - - if (memcmp(sigtype, &efi_sha256, sizeof(efi_guid_t)) == 0) { -diff --git a/src/cms_common.c b/src/cms_common.c -index 7bddedf..1c54c90 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -33,6 +33,10 @@ - - #include "hex.h" - -+/* -+ * Note that cms->selected_digest defaults to 0, which means the first -+ * entry of this array is the default digest. -+ */ - const struct digest_param digest_params[] = { - [DIGEST_PARAM_SHA256] = { - .name = "sha256", -@@ -53,33 +57,33 @@ const struct digest_param digest_params[] = { - }, - #endif - }; --const int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); -+const unsigned int n_digest_params = sizeof (digest_params) / sizeof (digest_params[0]); - - SECOidTag - digest_get_digest_oid(cms_context *cms) - { -- int i = cms->selected_digest; -+ unsigned int i = cms->selected_digest; - return digest_params[i].digest_tag; - } - - SECOidTag - digest_get_encryption_oid(cms_context *cms) - { -- int i = cms->selected_digest; -+ unsigned int i = cms->selected_digest; - return digest_params[i].digest_encryption_tag; - } - - SECOidTag - digest_get_signature_oid(cms_context *cms) - { -- int i = cms->selected_digest; -+ unsigned int i = cms->selected_digest; - return digest_params[i].signature_tag; - } - - int - digest_get_digest_size(cms_context *cms) - { -- int i = cms->selected_digest; -+ unsigned int i = cms->selected_digest; - return digest_params[i].size; - } - -@@ -91,7 +95,7 @@ teardown_digests(cms_context *ctx) - if (!digests) - return; - -- for (int i = 0; i < n_digest_params; i++) { -+ for (unsigned int i = 0; i < n_digest_params; i++) { - if (digests[i].pk11ctx) { - PK11_Finalize(digests[i].pk11ctx); - PK11_DestroyContext(digests[i].pk11ctx, PR_TRUE); -@@ -135,7 +139,7 @@ cms_context_init(cms_context *cms) - if (!cms->arena) - cnreterr(-1, cms, "could not create cryptographic arena"); - -- cms->selected_digest = -1; -+ cms->selected_digest = DEFAULT_DIGEST_PARAM; - - INIT_LIST_HEAD(&cms->pk12_ins); - cms->pk12_out.fd = -1; -@@ -219,7 +223,7 @@ cms_context_fini(cms_context *cms) - memset(&cms->newsig, '\0', sizeof (cms->newsig)); - } - -- cms->selected_digest = -1; -+ cms->selected_digest = DEFAULT_DIGEST_PARAM; - - if (cms->ci_digest) { - free_poison(cms->ci_digest->data, cms->ci_digest->len); -@@ -342,7 +346,7 @@ int - set_digest_parameters(cms_context *cms, char *name) - { - if (strcmp(name, "help")) { -- for (int i = 0; i < n_digest_params; i++) { -+ for (unsigned int i = 0; i < n_digest_params; i++) { - if (!strcmp(name, digest_params[i].name)) { - cms->selected_digest = i; - return 0; -@@ -350,7 +354,7 @@ set_digest_parameters(cms_context *cms, char *name) - } - } else { - printf("Supported digests: "); -- for (int i = 0; digest_params[i].name != NULL; i++) { -+ for (unsigned int i = 0; digest_params[i].name != NULL; i++) { - printf("%s ", digest_params[i].name); - } - printf("\n"); -@@ -1265,7 +1269,7 @@ generate_digest_begin(cms_context *cms) - cnreterr(-1, cms, "could not allocate digest context"); - } - -- for (int i = 0; i < n_digest_params; i++) { -+ for (unsigned int i = 0; i < n_digest_params; i++) { - digests[i].pk11ctx = PK11_CreateDigestContext( - digest_params[i].digest_tag); - if (!digests[i].pk11ctx) -@@ -1278,7 +1282,7 @@ generate_digest_begin(cms_context *cms) - return 0; - - err: -- for (int i = 0; i < n_digest_params; i++) { -+ for (unsigned int i = 0; i < n_digest_params; i++) { - if (digests[i].pk11ctx) - PK11_DestroyContext(digests[i].pk11ctx, PR_TRUE); - } -@@ -1290,7 +1294,7 @@ err: - void - generate_digest_step(cms_context *cms, void *data, size_t len) - { -- for (int i = 0; i < n_digest_params; i++) -+ for (unsigned int i = 0; i < n_digest_params; i++) - PK11_DigestOp(cms->digests[i].pk11ctx, data, len); - } - -@@ -1299,7 +1303,7 @@ generate_digest_finish(cms_context *cms) - { - void *mark = PORT_ArenaMark(cms->arena); - -- for (int i = 0; i < n_digest_params; i++) { -+ for (unsigned int i = 0; i < n_digest_params; i++) { - SECItem *digest = PORT_ArenaZAlloc(cms->arena,sizeof (SECItem)); - if (digest == NULL) - cngotoerr(err, cms, "could not allocate memory"); -@@ -1326,7 +1330,7 @@ generate_digest_finish(cms_context *cms) - PORT_ArenaUnmark(cms->arena, mark); - return 0; - err: -- for (int i = 0; i < n_digest_params; i++) { -+ for (unsigned int i = 0; i < n_digest_params; i++) { - if (cms->digests[i].pk11ctx) - PK11_DestroyContext(cms->digests[i].pk11ctx, PR_TRUE); - } -@@ -1343,12 +1347,13 @@ int - generate_signature(cms_context *cms) - { - int rc = 0; -+ int i = cms->selected_digest; - -- if (cms->digests[cms->selected_digest].pe_digest == NULL) -+ if (cms->digests[i].pe_digest == NULL) - cnreterr(-1, cms, "PE digest has not been allocated"); - -- if (content_is_empty(cms->digests[cms->selected_digest].pe_digest->data, -- cms->digests[cms->selected_digest].pe_digest->len)) -+ if (content_is_empty(cms->digests[i].pe_digest->data, -+ cms->digests[i].pe_digest->len)) - cnreterr(-1, cms, "PE binary has not been digested"); - - SECItem sd_der; -diff --git a/src/content_info.c b/src/content_info.c -index 9684850..900974c 100644 ---- a/src/content_info.c -+++ b/src/content_info.c -@@ -181,7 +181,7 @@ generate_spc_digest_info(cms_context *cms, SECItem *dip) - if (generate_algorithm_id(cms, &di.digestAlgorithm, - digest_get_digest_oid(cms)) < 0) - return -1; -- int i = cms->selected_digest; -+ unsigned int i = cms->selected_digest; - memcpy(&di.digest, cms->digests[i].pe_digest, sizeof (di.digest)); - - if (content_is_empty(di.digest.data, di.digest.len)) { -diff --git a/src/cms_common.h b/src/cms_common.h -index e45402c..35a128a 100644 ---- a/src/cms_common.h -+++ b/src/cms_common.h -@@ -65,6 +65,7 @@ struct digest { - - #define DIGEST_PARAM_SHA256 0 - #define DIGEST_PARAM_SHA1 1 -+#define DEFAULT_DIGEST_PARAM DIGEST_PARAM_SHA256 - - struct digest_param { - char *name; -@@ -76,7 +77,7 @@ struct digest_param { - }; - - extern const struct digest_param digest_params[2]; --extern const int n_digest_params; -+extern const unsigned int n_digest_params; - - typedef struct pk12_file { - char *path; -@@ -149,7 +150,7 @@ typedef struct cms_context { - int db_out, dbx_out, dbt_out; - - struct digest *digests; -- int selected_digest; -+ unsigned int selected_digest; - int omit_vendor_cert; - - SECItem newsig; diff --git a/pesign.patches b/pesign.patches index 0b756e9..e69de29 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1,23 +0,0 @@ -Patch0001: 0001-daemon-remove-always-true-comparison.patch -Patch0002: 0002-make-handle-some-gcc-Wanalyzer-flags-better.patch -Patch0003: 0003-Rename-dprintf-to-dbgprintf.patch -Patch0004: 0004-.gitignore-add-compile_commands.json-and-.cache.patch -Patch0005: 0005-pesign-print-digests-before-filenames-like-sha256sum.patch -Patch0006: 0006-Add-pesum-an-authenticode-digest-generator.patch -Patch0007: 0007-Fix-building-signed-kernels-on-setups-other-than-koj.patch -Patch0008: 0008-Add-D_GLIBCXX_ASSERTIONS-to-CPPFLAGS.patch -Patch0009: 0009-macros.pesign-handle-centos-like-rhel-with-rhelver.patch -Patch0010: 0010-Detect-the-presence-of-rpm-sign-when-checking-for-rh.patch -Patch0011: 0011-Rename-README-README.md.patch -Patch0012: 0012-README.md-show-off-a-bit-more.patch -Patch0013: 0013-Fix-missing-line-in-README.md.patch -Patch0014: 0014-Fix-typo-in-efikeygen-command.patch -Patch0015: 0015-pesigcheck-Fix-crash-on-digest-match.patch -Patch0016: 0016-cms-store-digest-as-pointer-instead-of-index.patch -Patch0017: 0017-Fix-mandoc-invocation-to-not-produce-garbage.patch -Patch0018: 0018-Work-around-GCC-being-obnoxiously-incompatible-with-.patch -Patch0019: 0019-get_password_passthrough-handle-the-callback-context.patch -Patch0020: 0020-read_password-only-prune-CR-NL-from-the-end-of-the-f.patch -Patch0021: 0021-Revert-cms-store-digest-as-pointer-instead-of-index.patch -Patch0022: 0022-CMS-add-some-minor-cleanups.patch -Patch0023: 0023-CMS-make-cms-selected_digest-an-index-again.patch diff --git a/pesign.spec b/pesign.spec index 4c835d0..3a44093 100644 --- a/pesign.spec +++ b/pesign.spec @@ -5,8 +5,8 @@ Name: pesign Summary: Signing utility for UEFI binaries -Version: 115 -Release: 9%{?dist} +Version: 116 +Release: 1%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -162,6 +162,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Jan 31 2023 Robbie Harwood - 116-1 +- New upstream release (116) +- Resolves: CVE-2022-3560 + * Wed Aug 31 2022 Robbie Harwood - 115-9 - Roll up to pjones's smartcard/cms fixes diff --git a/sources b/sources index b6ddc75..f7edcc4 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ SHA512 (certs.tar.xz) = ddac535c786d1a23074534323c4ce89f907d4f82b19c5d3a9c814b145fbac1599cd2386cf20c28d22aee7d5c4db441f052bab9ee655de756117a0a0bc99b525f -SHA512 (pesign-115.tar.bz2) = 0091d70e286326b1ed74418ca8c5a2a63d42e6aa3eccdfc4f09a34241b2addfe878af17d1d74648b7da79d6cd7158fcca0f3a52f4a82a57cacae4617b42b1faa +SHA512 (pesign-116.tar.bz2) = be3e1083f5e9f889cb8f7c50a8ebe723542fb2f6d1de8de9b04a9f21526ebaa8ab1efc7d4be11bcb0bc9862fa4bc6f78ee35e4d3496dd3b8927170b97795d25c From 04f02e8cd7210749cf49f1a6ab12f9daf60b8f13 Mon Sep 17 00:00:00 2001 From: Nicolas Frayer Date: Mon, 20 Feb 2023 18:20:00 +0100 Subject: [PATCH 22/32] cms_common: Fixed Segmentation fault Signed-off-by: Nicolas Frayer --- ...-cms_common-Fixed-Segmentation-fault.patch | 27 +++++++++++++++++++ pesign.patches | 1 + pesign.spec | 5 +++- 3 files changed, 32 insertions(+), 1 deletion(-) create mode 100644 0001-cms_common-Fixed-Segmentation-fault.patch diff --git a/0001-cms_common-Fixed-Segmentation-fault.patch b/0001-cms_common-Fixed-Segmentation-fault.patch new file mode 100644 index 0000000..4464ed0 --- /dev/null +++ b/0001-cms_common-Fixed-Segmentation-fault.patch @@ -0,0 +1,27 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Nicolas Frayer +Date: Mon, 20 Feb 2023 15:26:20 +0100 +Subject: [PATCH] cms_common: Fixed Segmentation fault + +When running efikeygen, the binary crashes with a segfault due +to dereferencing a **ptr instead of a *ptr. + +Signed-off-by: Nicolas Frayer +(cherry picked from commit 227435af461f38fc4abeafe02884675ad4b1feb4) +--- + src/cms_common.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/cms_common.c b/src/cms_common.c +index 24576f2..89d946a 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -956,7 +956,7 @@ find_certificate_by_issuer_and_sn(cms_context *cms, + if (!ias) + cnreterr(-1, cms, "invalid issuer and serial number"); + +- return find_certificate_by_callback(cms, match_issuer_and_serial, &ias, cert); ++ return find_certificate_by_callback(cms, match_issuer_and_serial, ias, cert); + } + + int diff --git a/pesign.patches b/pesign.patches index e69de29..2ca4433 100644 --- a/pesign.patches +++ b/pesign.patches @@ -0,0 +1 @@ +Patch0001: 0001-cms_common-Fixed-Segmentation-fault.patch diff --git a/pesign.spec b/pesign.spec index 3a44093..6d73398 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 1%{?dist} +Release: 2%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -162,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Mon Feb 20 2023 Nicolas Frayer - 116-2 +- cms_common: Fixed Segmentation fault + * Tue Jan 31 2023 Robbie Harwood - 116-1 - New upstream release (116) - Resolves: CVE-2022-3560 From 634e8088934852b8fbf2f421f1c077807f71bcad Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Fri, 2 Feb 2024 13:28:25 -0500 Subject: [PATCH 23/32] Fix incorrect calloc() invocations caught by -Wcalloc-transposed-args Signed-off-by: Peter Jones --- 0002-Fix-reversed-calloc-arguments.patch | 41 ++++++++++++++++++++++++ pesign.patches | 1 + pesign.spec | 5 ++- 3 files changed, 46 insertions(+), 1 deletion(-) create mode 100644 0002-Fix-reversed-calloc-arguments.patch diff --git a/0002-Fix-reversed-calloc-arguments.patch b/0002-Fix-reversed-calloc-arguments.patch new file mode 100644 index 0000000..861993c --- /dev/null +++ b/0002-Fix-reversed-calloc-arguments.patch @@ -0,0 +1,41 @@ +From 1f9e2fa0b4d872fdd01ca3ba81b04dfb1211a187 Mon Sep 17 00:00:00 2001 +From: Stephen Gallagher +Date: Fri, 2 Feb 2024 09:32:48 -0500 +Subject: [PATCH] Fix reversed calloc() arguments + +The prototype is "void *calloc(size_t nelem, size_t elsize);" + +These two instances had them reversed, almost certainly leading to +buffer overflow issues. This was detected by +-Werror=calloc-transposed-args on gcc. + +Signed-off-by: Stephen Gallagher +--- + src/pesigcheck.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/src/pesigcheck.c b/src/pesigcheck.c +index 6dc67f76a81..8119cf10a7b 100644 +--- a/src/pesigcheck.c ++++ b/src/pesigcheck.c +@@ -240,7 +240,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons, + + cert_iter iter; + +- reasonps = calloc(sizeof(struct reason), 512); ++ reasonps = calloc(512, sizeof(struct reason)); + if (!reasonps) + err(1, "check_signature"); + +@@ -281,7 +281,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons, + + num_reasons += 16; + +- new_reasons = calloc(sizeof(struct reason), num_reasons); ++ new_reasons = calloc(num_reasons, sizeof(struct reason)); + if (!new_reasons) + err(1, "check_signature"); + reasonps = new_reasons; +-- +2.41.0 + diff --git a/pesign.patches b/pesign.patches index 2ca4433..fa7478f 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1 +1,2 @@ Patch0001: 0001-cms_common-Fixed-Segmentation-fault.patch +Patch0002: 0002-Fix-reversed-calloc-arguments.patch diff --git a/pesign.spec b/pesign.spec index 6d73398..de9c1ce 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 2%{?dist} +Release: 3%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -162,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Fri Feb 02 2024 Peter Jones - 116-3 +- Fix incorrect calloc() invocations caught by -Wcalloc-transposed-args + * Mon Feb 20 2023 Nicolas Frayer - 116-2 - cms_common: Fixed Segmentation fault From 74685e918a559dcd0c40d28ba96d7a2ecba89f85 Mon Sep 17 00:00:00 2001 From: JasenChao Date: Tue, 5 Mar 2024 20:44:59 +0800 Subject: [PATCH 24/32] Add riscv64 support. --- pesign.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/pesign.spec b/pesign.spec index de9c1ce..0bccb2f 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 3%{?dist} +Release: 4%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -38,7 +38,7 @@ Requires: nss-util Requires: popt Requires: rpm Requires(pre): shadow-utils -ExclusiveArch: %{ix86} x86_64 ia64 aarch64 %{arm} +ExclusiveArch: %{ix86} x86_64 ia64 aarch64 %{arm} riscv64 %if 0%{?rhel} == 7 BuildRequires: rh-signing-tools >= 1.20-2 %endif @@ -162,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Mar 05 2024 Liu Yang - 116-4 +- Add riscv64. + * Fri Feb 02 2024 Peter Jones - 116-3 - Fix incorrect calloc() invocations caught by -Wcalloc-transposed-args From 58d5697b85b8a09a7560c916b36eed6ee8eafa42 Mon Sep 17 00:00:00 2001 From: Stephen Gallagher Date: Wed, 10 Jul 2024 10:07:44 -0400 Subject: [PATCH 25/32] Add package.cfg for ELN Starting with fedpkg 1.45, we can now have `fedpkg build` automatically trigger both the Rawhide and ELN build of this package, since it cannot be rebuilt by the normal ELN auto-rebuild service due to the restricted nature of this package. By adding this file, the maintainer does not need to remember to build it for both releases manually. Signed-off-by: Stephen Gallagher --- package.cfg | 3 +++ 1 file changed, 3 insertions(+) create mode 100644 package.cfg diff --git a/package.cfg b/package.cfg new file mode 100644 index 0000000..0cf8855 --- /dev/null +++ b/package.cfg @@ -0,0 +1,3 @@ +[koji] +targets = rawhide eln + From df4c12aec8bbcd45f1e82eb67ca0d968820578c2 Mon Sep 17 00:00:00 2001 From: Kevin Fenzi Date: Tue, 12 Nov 2024 14:05:21 -0800 Subject: [PATCH 26/32] Rebuild to pick up riscv64 change --- pesign.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pesign.spec b/pesign.spec index 0bccb2f..6c5e788 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 4%{?dist} +Release: 5%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -162,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Tue Nov 12 2024 Kevin Fenzi - 116-5 +- Rebuild to pick up riscv64 change + * Tue Mar 05 2024 Liu Yang - 116-4 - Add riscv64. From c938656c1214c9eb5edfecbc33febe543c96754a Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Thu, 21 Nov 2024 14:02:44 -0500 Subject: [PATCH 27/32] Work around OpenSC token name changes Signed-off-by: Peter Jones --- pesign.patches | 1 + pesign.spec | 5 ++++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/pesign.patches b/pesign.patches index fa7478f..50d9486 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1,2 +1,3 @@ Patch0001: 0001-cms_common-Fixed-Segmentation-fault.patch Patch0002: 0002-Fix-reversed-calloc-arguments.patch +Patch0003: 0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch diff --git a/pesign.spec b/pesign.spec index 6c5e788..723bab8 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 5%{?dist} +Release: 6%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -162,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Thu Nov 21 2024 Peter Jones - 116-6 +- Work around OpenSC token name changes + * Tue Nov 12 2024 Kevin Fenzi - 116-5 - Rebuild to pick up riscv64 change From 8b1bcf2332ace11c2c4afc264fe44a2ec7b2044d Mon Sep 17 00:00:00 2001 From: Peter Jones Date: Thu, 21 Nov 2024 14:02:44 -0500 Subject: [PATCH 28/32] Work around OpenSC token name changes Signed-off-by: Peter Jones --- ...SC-changing-token-names-on-fedora-bu.patch | 61 +++++++++++++++++++ 1 file changed, 61 insertions(+) create mode 100644 0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch diff --git a/0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch b/0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch new file mode 100644 index 0000000..663f4c4 --- /dev/null +++ b/0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch @@ -0,0 +1,61 @@ +From dc17b1d248c705073a5160e7c871a52aa9ce6e99 Mon Sep 17 00:00:00 2001 +From: Peter Jones +Date: Thu, 21 Nov 2024 13:58:05 -0500 +Subject: [PATCH] Work around OpenSC changing token names on fedora builders + *again*. + +Once again OpenSC has changed how token names work in an incompatible +way, and we need to work around it even harder on the Fedora kernel +builders. + +Reviewed-by: Kevin Fenzi +Reviewed-by: Justin Forbes +Signed-off-by: Peter Jones +--- + src/macros.pesign | 3 ++- + src/pesign-rpmbuild-helper.in | 15 ++++++++++++++- + 2 files changed, 16 insertions(+), 2 deletions(-) + +diff --git a/src/macros.pesign b/src/macros.pesign +index b7d6af1f6f5..47e3f19f8ed 100644 +--- a/src/macros.pesign ++++ b/src/macros.pesign +@@ -9,7 +9,8 @@ + %__pesign_token %{nil}%{?pe_signing_token:--token "%{pe_signing_token}"} + %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} + +-%__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} ++# See the comment in pesign-rpmbuild-helper.in about the token name here. ++%__pesign_client_token %{!?pe_signing_token:"OpenSC Card"}%{?pe_signing_token:"%{pe_signing_token}"} + %__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} + + %_pesign /usr/bin/pesign +diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in +index 30d5441207b..42de1a1e002 100644 +--- a/src/pesign-rpmbuild-helper.in ++++ b/src/pesign-rpmbuild-helper.in +@@ -214,7 +214,20 @@ main() { + rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" + elif [[ -n "${socket}" ]] ; then + ### welcome haaaaack city +- if [[ "${client_token[1]}" = "OpenSC Card (Fedora Signer)" ]] ; then ++ ### different versions of the opensc library name the token different ++ ### things, and as of this commit: ++ ### https://github.com/OpenSC/OpenSC/commit/259decf656a77a6d1bd3e944d6f198ed70832ff5 ++ ### that includes just not including the token label unless there's ++ ### more than one token. Unfortunately this is both for the displayed ++ ### info and for the token name you specify to /use/ the token, so we ++ ### have to handle all of those options here, and change the name to ++ ### match whatever the current version of opensc is using in the rpm ++ ### macro where we're setting it. Thankfully this is just a "is this ++ ### Fedora" check for us, and if it's RHEL we're not using OpenSC at ++ ### all. ++ if [[ "${client_token[1]}" = "OpenSC Card (Fedora Signer)" ]] \ ++ || [[ "${client_token[1]}" = "Fedora Signer" ]] \ ++ || [[ "${client_token[1]}" = "OpenSC Card" ]] ; then + if [[ "${input[1]}" =~ (/|^)vmlinuz($|[_.-]) ]] \ + || [[ "${input[1]}" =~ (/|^)bzImage($|[_.-]) ]] ; then + if [[ "${rhelcertfile}" =~ redhatsecureboot501.* ]] \ +-- +2.47.0 + From 93c64f2a0d041912609f8660c9eb09ec2e5b5d5b Mon Sep 17 00:00:00 2001 From: Luca Boccassi Date: Fri, 10 Jan 2025 20:40:35 +0000 Subject: [PATCH 29/32] Backport patch to skip auth on friendly slot Allow attaching a signature to a binary, needed for signing RPM packages in the SUSE Open Build Service. Upstream PR: https://github.com/rhboot/pesign/pull/101 Signed-off-by: Luca Boccassi --- ...-authentication-on-the-Friendly-slot.patch | 41 +++++++++++++++++++ pesign.patches | 1 + pesign.spec | 5 ++- 3 files changed, 46 insertions(+), 1 deletion(-) create mode 100644 0004-cms_common-skip-authentication-on-the-Friendly-slot.patch diff --git a/0004-cms_common-skip-authentication-on-the-Friendly-slot.patch b/0004-cms_common-skip-authentication-on-the-Friendly-slot.patch new file mode 100644 index 0000000..d13e454 --- /dev/null +++ b/0004-cms_common-skip-authentication-on-the-Friendly-slot.patch @@ -0,0 +1,41 @@ +From 616ec5f25adbde1a4bd78cdcacd6dcd7ecfa5a5c Mon Sep 17 00:00:00 2001 +From: Gary Lin +Date: Thu, 22 Dec 2022 13:49:34 +0800 +Subject: [PATCH] cms_common: skip authentication on the 'Friendly' slot + +When finding a certificate in a 'Friendly' slot without the need of the +private key, it is not necessary to authenticate the slot. + +For example, when the signed attributes and the raw signature are +created in a server and the user has the certificate, signkey.x509, and +tries to import them into myapp.efi: + + $ certutil -N -d nssdb -f passwd + $ certutil -A -d nssdb -f passwd -n signkey -t CT,CT,CT \ + -i signkey.x509 + $ pesign -n nssdb -c signkey -i myapp.efi -o myapp.efi.signed \ + -d sha256 -I myapp.sattr -R myapp.sig + +Since the "signkey" is 'Friendly', i.e. publicly readable, and the +private key is not needed, we can just skip the authentication and find +"signkey" in the slot. + +Signed-off-by: Gary Lin +--- + src/cms_common.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +diff --git a/src/cms_common.c b/src/cms_common.c +index cf572ca..44e5cca 100644 +--- a/src/cms_common.c ++++ b/src/cms_common.c +@@ -628,7 +628,8 @@ find_certificate(cms_context *cms, int needs_private_key) + + int errnum; + SECStatus status; +- if (PK11_NeedLogin(psle->slot) && !PK11_IsLoggedIn(psle->slot, cms)) { ++ if ((needs_private_key || !PK11_IsFriendly(psle->slot)) && ++ (PK11_NeedLogin(psle->slot) && !PK11_IsLoggedIn(psle->slot, cms))) { + status = PK11_Authenticate(psle->slot, PR_TRUE, cms); + if (status != SECSuccess) { + save_port_err() { diff --git a/pesign.patches b/pesign.patches index 50d9486..d5f5f82 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1,3 +1,4 @@ Patch0001: 0001-cms_common-Fixed-Segmentation-fault.patch Patch0002: 0002-Fix-reversed-calloc-arguments.patch Patch0003: 0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch +Patch0004: 0004-cms_common-skip-authentication-on-the-Friendly-slot.patch diff --git a/pesign.spec b/pesign.spec index 723bab8..eaef8eb 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 6%{?dist} +Release: 7%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -162,6 +162,9 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{python3_sitelib}/mockbuild/plugins/pesign.* %changelog +* Wed Jan 29 2025 Nicolas Frayer - 116-7 +- Backport patch to skip auth on friendly slot + * Thu Nov 21 2024 Peter Jones - 116-6 - Work around OpenSC token name changes From d06a6e72e4d5bcd168f77540735124e0d79518c0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Tue, 11 Feb 2025 15:53:30 +0100 Subject: [PATCH 30/32] Add sysusers.d config file to allow rpm to create users/groups automatically See https://fedoraproject.org/wiki/Changes/RPMSuportForSystemdSysusers. --- pesign.spec | 20 ++++++++++++-------- 1 file changed, 12 insertions(+), 8 deletions(-) diff --git a/pesign.spec b/pesign.spec index eaef8eb..9daa276 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 7%{?dist} +Release: 8%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -37,7 +37,6 @@ Requires: nss-tools >= 3.53 Requires: nss-util Requires: popt Requires: rpm -Requires(pre): shadow-utils ExclusiveArch: %{ix86} x86_64 ia64 aarch64 %{arm} riscv64 %if 0%{?rhel} == 7 BuildRequires: rh-signing-tools >= 1.20-2 @@ -67,6 +66,11 @@ git am %{patches} pesign.sysusers.conf </dev/null || groupadd -r pesign -getent passwd pesign >/dev/null || \ - useradd -r -g pesign -d /run/pesign -s /sbin/nologin \ - -c "Group for the pesign signing daemon" pesign -exit 0 +install -m0644 -D pesign.sysusers.conf %{buildroot}%{_sysusersdir}/pesign.conf + %if 0%{?rhel} >= 7 || 0%{?fedora} >= 17 %post @@ -160,8 +160,12 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %endif %{python3_sitelib}/mockbuild/plugins/*/pesign.* %{python3_sitelib}/mockbuild/plugins/pesign.* +%{_sysusersdir}/pesign.conf %changelog +* Tue Feb 11 2025 Zbigniew Jędrzejewski-Szmek +- Add sysusers.d config file to allow rpm to create users/groups automatically + * Wed Jan 29 2025 Nicolas Frayer - 116-7 - Backport patch to skip auth on friendly slot From 0fec26534d262708d3132b88f37d9e1e9b62f5c7 Mon Sep 17 00:00:00 2001 From: Yaakov Selkowitz Date: Fri, 20 Jun 2025 16:13:03 -0400 Subject: [PATCH 31/32] Remove package.cfg This did not consistently work as intended, and the ELN automation can now build this properly. --- package.cfg | 3 --- 1 file changed, 3 deletions(-) delete mode 100644 package.cfg diff --git a/package.cfg b/package.cfg deleted file mode 100644 index 0cf8855..0000000 --- a/package.cfg +++ /dev/null @@ -1,3 +0,0 @@ -[koji] -targets = rawhide eln - From cd8477a2ebae2f3fdc82adffdd217d0da0aade6e Mon Sep 17 00:00:00 2001 From: Nicolas Frayer Date: Mon, 22 Jun 2026 21:04:52 +0200 Subject: [PATCH 32/32] Fix a FTBFS issue caused by a missing const qualifier Resolves: #2491392 Signed-off-by: Nicolas Frayer --- 0005-Add-const-qualifier-to-variable.patch | 25 ++++++++++++++++++++++ pesign.patches | 1 + pesign.spec | 6 +++++- 3 files changed, 31 insertions(+), 1 deletion(-) create mode 100644 0005-Add-const-qualifier-to-variable.patch diff --git a/0005-Add-const-qualifier-to-variable.patch b/0005-Add-const-qualifier-to-variable.patch new file mode 100644 index 0000000..20669f0 --- /dev/null +++ b/0005-Add-const-qualifier-to-variable.patch @@ -0,0 +1,25 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Nicolas Frayer +Date: Mon, 22 Jun 2026 20:58:03 +0200 +Subject: [PATCH] Add const qualifier to variable + +Add const to a variable initialized with using strrchr. + +Signed-off-by: Nicolas Frayer +--- + src/pesum.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/pesum.c b/src/pesum.c +index e4ddaf86d7fa..5d7dcb929eec 100644 +--- a/src/pesum.c ++++ b/src/pesum.c +@@ -141,7 +141,7 @@ main(int argc, char *argv[]) + while ((infile = poptGetArg(optCon)) != NULL) { + pesign_context *ctxp = NULL; + +- char *ext = strrchr(infile, '.'); ++ const char *ext = strrchr(infile, '.'); + if (ext && strcmp(ext, ".ko") == 0) + fmt = FORMAT_KERNEL_MODULE; + diff --git a/pesign.patches b/pesign.patches index d5f5f82..9981c26 100644 --- a/pesign.patches +++ b/pesign.patches @@ -2,3 +2,4 @@ Patch0001: 0001-cms_common-Fixed-Segmentation-fault.patch Patch0002: 0002-Fix-reversed-calloc-arguments.patch Patch0003: 0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch Patch0004: 0004-cms_common-skip-authentication-on-the-Friendly-slot.patch +Patch0005: 0005-Add-const-qualifier-to-variable.patch diff --git a/pesign.spec b/pesign.spec index 9daa276..9785b6b 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 8%{?dist} +Release: 9%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -163,6 +163,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %{_sysusersdir}/pesign.conf %changelog +* Mon Jun 22 2026 Nicolas Frayer - 116-9 +- Fix a FTBFS issue caused by a missing const qualifier +- Resolves: #2491392 + * Tue Feb 11 2025 Zbigniew Jędrzejewski-Szmek - Add sysusers.d config file to allow rpm to create users/groups automatically