diff --git a/0002-Fix-reversed-calloc-arguments.patch b/0002-Fix-reversed-calloc-arguments.patch deleted file mode 100644 index 861993c..0000000 --- a/0002-Fix-reversed-calloc-arguments.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 1f9e2fa0b4d872fdd01ca3ba81b04dfb1211a187 Mon Sep 17 00:00:00 2001 -From: Stephen Gallagher -Date: Fri, 2 Feb 2024 09:32:48 -0500 -Subject: [PATCH] Fix reversed calloc() arguments - -The prototype is "void *calloc(size_t nelem, size_t elsize);" - -These two instances had them reversed, almost certainly leading to -buffer overflow issues. This was detected by --Werror=calloc-transposed-args on gcc. - -Signed-off-by: Stephen Gallagher ---- - src/pesigcheck.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/pesigcheck.c b/src/pesigcheck.c -index 6dc67f76a81..8119cf10a7b 100644 ---- a/src/pesigcheck.c -+++ b/src/pesigcheck.c -@@ -240,7 +240,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons, - - cert_iter iter; - -- reasonps = calloc(sizeof(struct reason), 512); -+ reasonps = calloc(512, sizeof(struct reason)); - if (!reasonps) - err(1, "check_signature"); - -@@ -281,7 +281,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons, - - num_reasons += 16; - -- new_reasons = calloc(sizeof(struct reason), num_reasons); -+ new_reasons = calloc(num_reasons, sizeof(struct reason)); - if (!new_reasons) - err(1, "check_signature"); - reasonps = new_reasons; --- -2.41.0 - diff --git a/0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch b/0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch deleted file mode 100644 index 663f4c4..0000000 --- a/0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch +++ /dev/null @@ -1,61 +0,0 @@ -From dc17b1d248c705073a5160e7c871a52aa9ce6e99 Mon Sep 17 00:00:00 2001 -From: Peter Jones -Date: Thu, 21 Nov 2024 13:58:05 -0500 -Subject: [PATCH] Work around OpenSC changing token names on fedora builders - *again*. - -Once again OpenSC has changed how token names work in an incompatible -way, and we need to work around it even harder on the Fedora kernel -builders. - -Reviewed-by: Kevin Fenzi -Reviewed-by: Justin Forbes -Signed-off-by: Peter Jones ---- - src/macros.pesign | 3 ++- - src/pesign-rpmbuild-helper.in | 15 ++++++++++++++- - 2 files changed, 16 insertions(+), 2 deletions(-) - -diff --git a/src/macros.pesign b/src/macros.pesign -index b7d6af1f6f5..47e3f19f8ed 100644 ---- a/src/macros.pesign -+++ b/src/macros.pesign -@@ -9,7 +9,8 @@ - %__pesign_token %{nil}%{?pe_signing_token:--token "%{pe_signing_token}"} - %__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"} - --%__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"} -+# See the comment in pesign-rpmbuild-helper.in about the token name here. -+%__pesign_client_token %{!?pe_signing_token:"OpenSC Card"}%{?pe_signing_token:"%{pe_signing_token}"} - %__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"} - - %_pesign /usr/bin/pesign -diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in -index 30d5441207b..42de1a1e002 100644 ---- a/src/pesign-rpmbuild-helper.in -+++ b/src/pesign-rpmbuild-helper.in -@@ -214,7 +214,20 @@ main() { - rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}" - elif [[ -n "${socket}" ]] ; then - ### welcome haaaaack city -- if [[ "${client_token[1]}" = "OpenSC Card (Fedora Signer)" ]] ; then -+ ### different versions of the opensc library name the token different -+ ### things, and as of this commit: -+ ### https://github.com/OpenSC/OpenSC/commit/259decf656a77a6d1bd3e944d6f198ed70832ff5 -+ ### that includes just not including the token label unless there's -+ ### more than one token. Unfortunately this is both for the displayed -+ ### info and for the token name you specify to /use/ the token, so we -+ ### have to handle all of those options here, and change the name to -+ ### match whatever the current version of opensc is using in the rpm -+ ### macro where we're setting it. Thankfully this is just a "is this -+ ### Fedora" check for us, and if it's RHEL we're not using OpenSC at -+ ### all. -+ if [[ "${client_token[1]}" = "OpenSC Card (Fedora Signer)" ]] \ -+ || [[ "${client_token[1]}" = "Fedora Signer" ]] \ -+ || [[ "${client_token[1]}" = "OpenSC Card" ]] ; then - if [[ "${input[1]}" =~ (/|^)vmlinuz($|[_.-]) ]] \ - || [[ "${input[1]}" =~ (/|^)bzImage($|[_.-]) ]] ; then - if [[ "${rhelcertfile}" =~ redhatsecureboot501.* ]] \ --- -2.47.0 - diff --git a/0004-cms_common-skip-authentication-on-the-Friendly-slot.patch b/0004-cms_common-skip-authentication-on-the-Friendly-slot.patch deleted file mode 100644 index d13e454..0000000 --- a/0004-cms_common-skip-authentication-on-the-Friendly-slot.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 616ec5f25adbde1a4bd78cdcacd6dcd7ecfa5a5c Mon Sep 17 00:00:00 2001 -From: Gary Lin -Date: Thu, 22 Dec 2022 13:49:34 +0800 -Subject: [PATCH] cms_common: skip authentication on the 'Friendly' slot - -When finding a certificate in a 'Friendly' slot without the need of the -private key, it is not necessary to authenticate the slot. - -For example, when the signed attributes and the raw signature are -created in a server and the user has the certificate, signkey.x509, and -tries to import them into myapp.efi: - - $ certutil -N -d nssdb -f passwd - $ certutil -A -d nssdb -f passwd -n signkey -t CT,CT,CT \ - -i signkey.x509 - $ pesign -n nssdb -c signkey -i myapp.efi -o myapp.efi.signed \ - -d sha256 -I myapp.sattr -R myapp.sig - -Since the "signkey" is 'Friendly', i.e. publicly readable, and the -private key is not needed, we can just skip the authentication and find -"signkey" in the slot. - -Signed-off-by: Gary Lin ---- - src/cms_common.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/src/cms_common.c b/src/cms_common.c -index cf572ca..44e5cca 100644 ---- a/src/cms_common.c -+++ b/src/cms_common.c -@@ -628,7 +628,8 @@ find_certificate(cms_context *cms, int needs_private_key) - - int errnum; - SECStatus status; -- if (PK11_NeedLogin(psle->slot) && !PK11_IsLoggedIn(psle->slot, cms)) { -+ if ((needs_private_key || !PK11_IsFriendly(psle->slot)) && -+ (PK11_NeedLogin(psle->slot) && !PK11_IsLoggedIn(psle->slot, cms))) { - status = PK11_Authenticate(psle->slot, PR_TRUE, cms); - if (status != SECSuccess) { - save_port_err() { diff --git a/0005-Add-const-qualifier-to-variable.patch b/0005-Add-const-qualifier-to-variable.patch deleted file mode 100644 index 20669f0..0000000 --- a/0005-Add-const-qualifier-to-variable.patch +++ /dev/null @@ -1,25 +0,0 @@ -From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 -From: Nicolas Frayer -Date: Mon, 22 Jun 2026 20:58:03 +0200 -Subject: [PATCH] Add const qualifier to variable - -Add const to a variable initialized with using strrchr. - -Signed-off-by: Nicolas Frayer ---- - src/pesum.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/pesum.c b/src/pesum.c -index e4ddaf86d7fa..5d7dcb929eec 100644 ---- a/src/pesum.c -+++ b/src/pesum.c -@@ -141,7 +141,7 @@ main(int argc, char *argv[]) - while ((infile = poptGetArg(optCon)) != NULL) { - pesign_context *ctxp = NULL; - -- char *ext = strrchr(infile, '.'); -+ const char *ext = strrchr(infile, '.'); - if (ext && strcmp(ext, ".ko") == 0) - fmt = FORMAT_KERNEL_MODULE; - diff --git a/pesign.patches b/pesign.patches index 9981c26..2ca4433 100644 --- a/pesign.patches +++ b/pesign.patches @@ -1,5 +1 @@ Patch0001: 0001-cms_common-Fixed-Segmentation-fault.patch -Patch0002: 0002-Fix-reversed-calloc-arguments.patch -Patch0003: 0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch -Patch0004: 0004-cms_common-skip-authentication-on-the-Friendly-slot.patch -Patch0005: 0005-Add-const-qualifier-to-variable.patch diff --git a/pesign.spec b/pesign.spec index 9785b6b..6d73398 100644 --- a/pesign.spec +++ b/pesign.spec @@ -6,7 +6,7 @@ Name: pesign Summary: Signing utility for UEFI binaries Version: 116 -Release: 9%{?dist} +Release: 2%{?dist} License: GPL-2.0-only URL: https://github.com/rhboot/pesign @@ -37,7 +37,8 @@ Requires: nss-tools >= 3.53 Requires: nss-util Requires: popt Requires: rpm -ExclusiveArch: %{ix86} x86_64 ia64 aarch64 %{arm} riscv64 +Requires(pre): shadow-utils +ExclusiveArch: %{ix86} x86_64 ia64 aarch64 %{arm} %if 0%{?rhel} == 7 BuildRequires: rh-signing-tools >= 1.20-2 %endif @@ -66,11 +67,6 @@ git am %{patches} pesign.sysusers.conf </dev/null || groupadd -r pesign +getent passwd pesign >/dev/null || \ + useradd -r -g pesign -d /run/pesign -s /sbin/nologin \ + -c "Group for the pesign signing daemon" pesign +exit 0 %if 0%{?rhel} >= 7 || 0%{?fedora} >= 17 %post @@ -160,31 +160,8 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null %endif %{python3_sitelib}/mockbuild/plugins/*/pesign.* %{python3_sitelib}/mockbuild/plugins/pesign.* -%{_sysusersdir}/pesign.conf %changelog -* Mon Jun 22 2026 Nicolas Frayer - 116-9 -- Fix a FTBFS issue caused by a missing const qualifier -- Resolves: #2491392 - -* Tue Feb 11 2025 Zbigniew Jędrzejewski-Szmek -- Add sysusers.d config file to allow rpm to create users/groups automatically - -* Wed Jan 29 2025 Nicolas Frayer - 116-7 -- Backport patch to skip auth on friendly slot - -* Thu Nov 21 2024 Peter Jones - 116-6 -- Work around OpenSC token name changes - -* Tue Nov 12 2024 Kevin Fenzi - 116-5 -- Rebuild to pick up riscv64 change - -* Tue Mar 05 2024 Liu Yang - 116-4 -- Add riscv64. - -* Fri Feb 02 2024 Peter Jones - 116-3 -- Fix incorrect calloc() invocations caught by -Wcalloc-transposed-args - * Mon Feb 20 2023 Nicolas Frayer - 116-2 - cms_common: Fixed Segmentation fault