Compare commits

..

9 commits

Author SHA1 Message Date
Peter Jones
ba9a699b4b Backport a bunch of stuff the upstream development tree.
Signed-off-by: Peter Jones <pjones@redhat.com>
2021-02-18 10:20:53 -05:00
Peter Jones
ff0566d2df Use %autosetup
Signed-off-by: Peter Jones <pjones@redhat.com>
2021-02-16 13:43:24 -05:00
Peter Jones
899acac822 Synchronize once again with master
Signed-off-by: Peter Jones <pjones@redhat.com>
2020-08-03 16:27:53 -04:00
Peter Jones
a3abd60677 fix rundir in files
Signed-off-by: Peter Jones <pjones@redhat.com>
2020-07-16 19:26:09 -04:00
Peter Jones
bbe011b416 Synchronize with master
Signed-off-by: Peter Jones <pjones@redhat.com>
2020-07-16 16:29:13 -04:00
Peter Jones
5d1affcd00 Make sure the patch for -29 is actually in the build in f32, and
synchronize with master.

Signed-off-by: Peter Jones <pjones@redhat.com>
2020-02-24 12:48:21 -05:00
Jeremy Cline
f5005c0628 pesign: Apparently opensc got updated and the token name changed
All the kernel builds started failing yesterday because the signing
token could not be found. Update the token name in the macro shipped by
pesign.
2020-02-24 12:47:24 -05:00
Peter Jones
d804a043d7 Backport a minor fix.
Signed-off-by: Peter Jones <pjones@redhat.com>
2020-02-18 17:34:50 -05:00
Peter Jones
6c258856c5 Rebuild to match OpenSC's token name mangling change.
Signed-off-by: Peter Jones <pjones@redhat.com>
2020-02-18 17:34:50 -05:00
53 changed files with 9269 additions and 377 deletions

1
.gitignore vendored
View file

@ -5,3 +5,4 @@ clog
/certs.tar.xz
.build*.log
/pesign-*/
/results_pesign/

View file

@ -1,27 +0,0 @@
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
From: Nicolas Frayer <nfrayer@redhat.com>
Date: Mon, 20 Feb 2023 15:26:20 +0100
Subject: [PATCH] cms_common: Fixed Segmentation fault
When running efikeygen, the binary crashes with a segfault due
to dereferencing a **ptr instead of a *ptr.
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
(cherry picked from commit 227435af461f38fc4abeafe02884675ad4b1feb4)
---
src/cms_common.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/cms_common.c b/src/cms_common.c
index 24576f2..89d946a 100644
--- a/src/cms_common.c
+++ b/src/cms_common.c
@@ -956,7 +956,7 @@ find_certificate_by_issuer_and_sn(cms_context *cms,
if (!ias)
cnreterr(-1, cms, "invalid issuer and serial number");
- return find_certificate_by_callback(cms, match_issuer_and_serial, &ias, cert);
+ return find_certificate_by_callback(cms, match_issuer_and_serial, ias, cert);
}
int

View file

@ -0,0 +1,45 @@
From 2eb9f3fa837d5fac5fd4e543df25477cc3dbcb1a Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 14 May 2019 11:28:38 -0400
Subject: [PATCH 01/42] efikeygen: Fix the build with nss 3.44
NSS 3.44 adds some certificate types, which changes a type and makes
some encoding stuff weird. As a result, we get:
gcc8 -I/wrkdirs/usr/ports/sysutils/pesign/work/pesign-0.110/include -O2 -pipe -fstack-protector-strong -Wl,-rpath=/usr/local/lib/gcc8 -isystem /usr/local/include -fno-strict-aliasing -g -O0 -g -O0 -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants --std=gnu99 -D_GNU_SOURCE -Wno-unused-result -Wno-unused-function -I../include/ -I/usr/local/include/nss -I/usr/local/include/nss/nss -I/usr/local/include/nspr -Werror -fPIC -isystem /usr/local/include -DCONFIG_amd64 -DCONFIG_amd64 -c efikeygen.c -o efikeygen.o
In file included from /usr/local/include/nss/nss/cert.h:22,
from efikeygen.c:39:
efikeygen.c: In function 'add_cert_type':
/usr/local/include/nss/nss/certt.h:445:5: error: unsigned conversion from 'int' to 'unsigned char' changes value from '496' to '240' [-Werror=overflow]
(NS_CERT_TYPE_SSL_CLIENT | NS_CERT_TYPE_SSL_SERVER | NS_CERT_TYPE_EMAIL | \
^
efikeygen.c:208:23: note: in expansion of macro 'NS_CERT_TYPE_APP'
unsigned char type = NS_CERT_TYPE_APP;
^~~~~~~~~~~~~~~~
cc1: all warnings being treated as errors
This is fixed by just making it an int.
Fixes github issue #48.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/efikeygen.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/efikeygen.c b/src/efikeygen.c
index 121a238685b..848480a9b01 100644
--- a/src/efikeygen.c
+++ b/src/efikeygen.c
@@ -208,7 +208,7 @@ static int
add_cert_type(cms_context *cms, void *extHandle, int is_ca)
{
SECItem bitStringValue;
- unsigned char type = NS_CERT_TYPE_APP;
+ int type = NS_CERT_TYPE_APP;
if (is_ca)
type |= NS_CERT_TYPE_SSL_CA |
--
2.29.2

View file

@ -1,41 +0,0 @@
From 1f9e2fa0b4d872fdd01ca3ba81b04dfb1211a187 Mon Sep 17 00:00:00 2001
From: Stephen Gallagher <sgallagh@redhat.com>
Date: Fri, 2 Feb 2024 09:32:48 -0500
Subject: [PATCH] Fix reversed calloc() arguments
The prototype is "void *calloc(size_t nelem, size_t elsize);"
These two instances had them reversed, almost certainly leading to
buffer overflow issues. This was detected by
-Werror=calloc-transposed-args on gcc.
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>
---
src/pesigcheck.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/src/pesigcheck.c b/src/pesigcheck.c
index 6dc67f76a81..8119cf10a7b 100644
--- a/src/pesigcheck.c
+++ b/src/pesigcheck.c
@@ -240,7 +240,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons,
cert_iter iter;
- reasonps = calloc(sizeof(struct reason), 512);
+ reasonps = calloc(512, sizeof(struct reason));
if (!reasonps)
err(1, "check_signature");
@@ -281,7 +281,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons,
num_reasons += 16;
- new_reasons = calloc(sizeof(struct reason), num_reasons);
+ new_reasons = calloc(num_reasons, sizeof(struct reason));
if (!new_reasons)
err(1, "check_signature");
reasonps = new_reasons;
--
2.41.0

View file

@ -0,0 +1,49 @@
From 8b985ccb2bf86aed612cac9813eadbe03905b91a Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 18 Feb 2020 16:28:56 -0500
Subject: [PATCH 02/42] pesigcheck: Fix a wrong assignment
gcc says:
pesigcheck.c: In function 'check_signature':
pesigcheck.c:321:17: error: implicit conversion from 'enum <anonymous>' to 'enum <anonymous>' [-Werror=enum-conversion]
321 | reason->type = siBuffer;
| ^
pesigcheck.c:333:17: error: implicit conversion from 'enum <anonymous>' to 'enum <anonymous>' [-Werror=enum-conversion]
333 | reason->type = siBuffer;
| ^
cc1: all warnings being treated as errors
And indeed, that line of code makes no sense at all - it was supposed to
be reason->sig.type.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/pesigcheck.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/src/pesigcheck.c b/src/pesigcheck.c
index 524cce307bf..8fa0f1ad03d 100644
--- a/src/pesigcheck.c
+++ b/src/pesigcheck.c
@@ -318,7 +318,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons,
reason->type = SIGNATURE;
reason->sig.data = data;
reason->sig.len = datalen;
- reason->type = siBuffer;
+ reason->sig.type = siBuffer;
nreason += 1;
is_invalid = true;
}
@@ -330,7 +330,7 @@ check_signature(pesigcheck_context *ctx, int *nreasons,
reason->type = SIGNATURE;
reason->sig.data = data;
reason->sig.len = datalen;
- reason->type = siBuffer;
+ reason->sig.type = siBuffer;
nreason += 1;
has_valid_cert = true;
}
--
2.29.2

View file

@ -0,0 +1,317 @@
From 3c525aa069dd52d85e3504e6179886a74aa14cd2 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Thu, 11 Jun 2020 16:23:14 -0400
Subject: [PATCH 03/42] Make 0.112 client and server work with the 113 protocol
and vise versa
This makes the version of the sign API that takes a file type optional,
and makes the client attempt to negotiate which version it's getting.
It also leaves the server able to still handle the version from before
the file type was added.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/client.c | 74 +++++++++++++++++++++++++++++++++++++---------------
src/daemon.c | 63 +++++++++++++++++++++++++++++---------------
src/daemon.h | 2 ++
3 files changed, 97 insertions(+), 42 deletions(-)
diff --git a/src/client.c b/src/client.c
index 4a9a44e915c..a4f1d1dbbe7 100644
--- a/src/client.c
+++ b/src/client.c
@@ -23,6 +23,7 @@
#include <fcntl.h>
#include <popt.h>
#include <pwd.h>
+#include <stdbool.h>
#include <stddef.h>
#include <stdlib.h>
#include <sys/socket.h>
@@ -96,8 +97,8 @@ connect_to_server(void)
static int32_t
check_response(int sd, char **srvmsg);
-static void
-check_cmd_version(int sd, uint32_t command, char *name, int32_t version)
+static int
+check_cmd_version(int sd, uint32_t command, char *name, int32_t version, bool do_exit)
{
struct msghdr msg;
struct iovec iov[1];
@@ -116,7 +117,7 @@ check_cmd_version(int sd, uint32_t command, char *name, int32_t version)
ssize_t n;
n = sendmsg(sd, &msg, 0);
if (n < 0) {
- fprintf(stderr, "check-cmd-version: kill daemon failed: %m\n");
+ fprintf(stderr, "check-cmd-version: sendmsg failed: %m\n");
exit(1);
}
@@ -132,11 +133,17 @@ check_cmd_version(int sd, uint32_t command, char *name, int32_t version)
char *srvmsg = NULL;
int32_t rc = check_response(sd, &srvmsg);
- if (rc < 0)
+
+ if (do_exit && rc < 0)
errx(1, "command \"%s\" not known by server", name);
- if (rc != version)
+
+ if (do_exit && rc != version)
errx(1, "command \"%s\": client version %d, server version %d",
name, version, rc);
+
+ if (rc < 0)
+ return rc;
+ return rc == version;
}
static void
@@ -146,7 +153,7 @@ send_kill_daemon(int sd)
struct iovec iov;
pesignd_msghdr pm;
- check_cmd_version(sd, CMD_KILL_DAEMON, "kill-daemon", 0);
+ check_cmd_version(sd, CMD_KILL_DAEMON, "kill-daemon", 0, true);
pm.version = PESIGND_VERSION;
pm.command = CMD_KILL_DAEMON;
@@ -288,7 +295,7 @@ unlock_token(int sd, char *tokenname, char *pin)
uint32_t size1 = pesignd_string_size(pin);
- check_cmd_version(sd, CMD_UNLOCK_TOKEN, "unlock-token", 0);
+ check_cmd_version(sd, CMD_UNLOCK_TOKEN, "unlock-token", 0, true);
pm.version = PESIGND_VERSION;
pm.command = CMD_UNLOCK_TOKEN;
@@ -365,7 +372,7 @@ is_token_unlocked(int sd, char *tokenname)
uint32_t size0 = pesignd_string_size(tokenname);
- check_cmd_version(sd, CMD_IS_TOKEN_UNLOCKED, "is-token-unlocked", 0);
+ check_cmd_version(sd, CMD_IS_TOKEN_UNLOCKED, "is-token-unlocked", 0, true);
pm.version = PESIGND_VERSION;
pm.command = CMD_IS_TOKEN_UNLOCKED;
@@ -464,6 +471,9 @@ static void
sign(int sd, char *infile, char *outfile, char *tokenname, char *certname,
int attached, uint32_t format)
{
+ int rc;
+ bool add_file_type;
+
int infd = open(infile, O_RDONLY);
if (infd < 0) {
fprintf(stderr, "pesign-client: could not open input file "
@@ -493,12 +503,28 @@ oom:
exit(1);
}
- check_cmd_version(sd, attached ? CMD_SIGN_ATTACHED : CMD_SIGN_DETACHED,
- attached ? "sign-attached" : "sign-detached", 0);
+ rc = check_cmd_version(sd,
+ attached ? CMD_SIGN_ATTACHED_WITH_FILE_TYPE
+ : CMD_SIGN_DETACHED_WITH_FILE_TYPE,
+ attached ? "sign-attached" : "sign-detached",
+ 0, format == FORMAT_KERNEL_MODULE);
+ if (rc >= 0) {
+ add_file_type = true;
+ } else {
+ add_file_type = false;
+ check_cmd_version(sd, attached ? CMD_SIGN_ATTACHED
+ : CMD_SIGN_DETACHED,
+ attached ? "sign-attached" : "sign-detached",
+ 0, true);
+ }
+ printf("add_file_type:%d\n", add_file_type);
pm->version = PESIGND_VERSION;
- pm->command = attached ? CMD_SIGN_ATTACHED : CMD_SIGN_DETACHED;
- pm->size = size0 + size1 + sizeof(format);
+ pm->command = attached ? (add_file_type ? CMD_SIGN_ATTACHED_WITH_FILE_TYPE
+ : CMD_SIGN_ATTACHED)
+ : (add_file_type ? CMD_SIGN_DETACHED_WITH_FILE_TYPE
+ : CMD_SIGN_DETACHED);
+ pm->size = size0 + size1 + (add_file_type ? sizeof(format) : 0);
iov[0].iov_base = pm;
iov[0].iov_len = sizeof (*pm);
@@ -515,25 +541,31 @@ oom:
}
char *buffer;
- buffer = malloc(size0 + size1);
+ buffer = malloc(pm->size);
if (!buffer)
goto oom;
- iov[0].iov_base = &format;
- iov[0].iov_len = sizeof(format);
+ int pos = 0;
+
+ if (add_file_type) {
+ iov[pos].iov_base = &format;
+ iov[pos].iov_len = sizeof(format);
+ pos++;
+ }
pesignd_string *tn = (pesignd_string *)buffer;
pesignd_string_set(tn, tokenname);
- iov[1].iov_base = tn;
- iov[1].iov_len = size0;
+ iov[pos].iov_base = tn;
+ iov[pos].iov_len = size0;
+ pos++;
pesignd_string *cn = pesignd_string_next(tn);
pesignd_string_set(cn, certname);
- iov[2].iov_base = cn;
- iov[2].iov_len = size1;
+ iov[pos].iov_base = cn;
+ iov[pos].iov_len = size1;
msg.msg_iov = iov;
- msg.msg_iovlen = 3;
+ msg.msg_iovlen = add_file_type ? 3 : 2;
n = sendmsg(sd, &msg, 0);
if (n < 0) {
@@ -547,7 +579,7 @@ oom:
send_fd(sd, outfd);
char *srvmsg = NULL;
- int rc = check_response(sd, &srvmsg);
+ rc = check_response(sd, &srvmsg);
if (rc < 0) {
fprintf(stderr, "pesign-client: signing failed: \"%s\"\n",
srvmsg);
diff --git a/src/daemon.c b/src/daemon.c
index 84b9ebcb13f..8522250c2b4 100644
--- a/src/daemon.c
+++ b/src/daemon.c
@@ -25,6 +25,7 @@
#include <poll.h>
#include <pwd.h>
#include <signal.h>
+#include <stdbool.h>
#include <stdlib.h>
#include <stdio.h>
#include <string.h>
@@ -569,7 +570,7 @@ out:
static void
handle_signing(context *ctx, struct pollfd *pollfd, socklen_t size,
- int attached)
+ int attached, bool with_file_type)
{
struct msghdr msg;
struct iovec iov;
@@ -593,8 +594,12 @@ oom:
n = recvmsg(pollfd->fd, &msg, MSG_WAITALL);
- file_format = *((uint32_t *) buffer);
- n -= sizeof(uint32_t);
+ if (with_file_type) {
+ file_format = *((uint32_t *) buffer);
+ n -= sizeof(uint32_t);
+ } else {
+ file_format = FORMAT_PE_BINARY;
+ }
pesignd_string *tn = (pesignd_string *)(buffer + sizeof(uint32_t));
if (n < (long long)sizeof(tn->size)) {
@@ -674,34 +679,44 @@ finish:
teardown_digests(ctx->cms);
}
+static inline void
+handle_sign_helper(context *ctx, struct pollfd *pollfd, socklen_t size,
+ int attached, bool with_file_type)
+{
+ int rc = cms_context_alloc(&ctx->cms);
+ if (rc < 0)
+ return;
+
+ steal_from_cms(ctx->backup_cms, ctx->cms);
+
+ handle_signing(ctx, pollfd, size, attached, with_file_type);
+
+ hide_stolen_goods_from_cms(ctx->cms, ctx->backup_cms);
+ cms_context_fini(ctx->cms);
+}
+
static void
handle_sign_attached(context *ctx, struct pollfd *pollfd, socklen_t size)
{
- int rc = cms_context_alloc(&ctx->cms);
- if (rc < 0)
- return;
+ handle_sign_helper(ctx, pollfd, size, 1, false);
+}
- steal_from_cms(ctx->backup_cms, ctx->cms);
-
- handle_signing(ctx, pollfd, size, 1);
-
- hide_stolen_goods_from_cms(ctx->cms, ctx->backup_cms);
- cms_context_fini(ctx->cms);
+static void
+handle_sign_attached_with_file_type(context *ctx, struct pollfd *pollfd, socklen_t size)
+{
+ handle_sign_helper(ctx, pollfd, size, 1, true);
}
static void
handle_sign_detached(context *ctx, struct pollfd *pollfd, socklen_t size)
{
- int rc = cms_context_alloc(&ctx->cms);
- if (rc < 0)
- return;
+ handle_sign_helper(ctx, pollfd, size, 0, false);
+}
- steal_from_cms(ctx->backup_cms, ctx->cms);
-
- handle_signing(ctx, pollfd, size, 0);
-
- hide_stolen_goods_from_cms(ctx->cms, ctx->backup_cms);
- cms_context_fini(ctx->cms);
+static void
+handle_sign_detached_with_file_type(context *ctx, struct pollfd *pollfd, socklen_t size)
+{
+ handle_sign_helper(ctx, pollfd, size, 0, true);
}
static void
@@ -733,6 +748,12 @@ cmd_table_t cmd_table[] = {
{ CMD_UNLOCK_TOKEN, handle_unlock_token, "unlock-token", 0 },
{ CMD_SIGN_ATTACHED, handle_sign_attached, "sign-attached", 0 },
{ CMD_SIGN_DETACHED, handle_sign_detached, "sign-detached", 0 },
+ { CMD_SIGN_ATTACHED_WITH_FILE_TYPE,
+ handle_sign_attached_with_file_type,
+ "sign-attached-with-file-type", 0 },
+ { CMD_SIGN_DETACHED_WITH_FILE_TYPE,
+ handle_sign_detached_with_file_type,
+ "sign-detached-with-file-type", 0 },
{ CMD_RESPONSE, NULL, "response", 0 },
{ CMD_IS_TOKEN_UNLOCKED, handle_is_token_unlocked,
"is-token-unlocked", 0 },
diff --git a/src/daemon.h b/src/daemon.h
index 69384ce775c..0368dc9256c 100644
--- a/src/daemon.h
+++ b/src/daemon.h
@@ -45,6 +45,8 @@ typedef enum {
CMD_RESPONSE,
CMD_IS_TOKEN_UNLOCKED,
CMD_GET_CMD_VERSION,
+ CMD_SIGN_ATTACHED_WITH_FILE_TYPE,
+ CMD_SIGN_DETACHED_WITH_FILE_TYPE,
CMD_LIST_END
} pesignd_cmd;
--
2.29.2

View file

@ -1,61 +0,0 @@
From dc17b1d248c705073a5160e7c871a52aa9ce6e99 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Thu, 21 Nov 2024 13:58:05 -0500
Subject: [PATCH] Work around OpenSC changing token names on fedora builders
*again*.
Once again OpenSC has changed how token names work in an incompatible
way, and we need to work around it even harder on the Fedora kernel
builders.
Reviewed-by: Kevin Fenzi <kevin@fedoraproject.org>
Reviewed-by: Justin Forbes <jforbes@fedoraproject.org>
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/macros.pesign | 3 ++-
src/pesign-rpmbuild-helper.in | 15 ++++++++++++++-
2 files changed, 16 insertions(+), 2 deletions(-)
diff --git a/src/macros.pesign b/src/macros.pesign
index b7d6af1f6f5..47e3f19f8ed 100644
--- a/src/macros.pesign
+++ b/src/macros.pesign
@@ -9,7 +9,8 @@
%__pesign_token %{nil}%{?pe_signing_token:--token "%{pe_signing_token}"}
%__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"}
-%__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"}
+# See the comment in pesign-rpmbuild-helper.in about the token name here.
+%__pesign_client_token %{!?pe_signing_token:"OpenSC Card"}%{?pe_signing_token:"%{pe_signing_token}"}
%__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"}
%_pesign /usr/bin/pesign
diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in
index 30d5441207b..42de1a1e002 100644
--- a/src/pesign-rpmbuild-helper.in
+++ b/src/pesign-rpmbuild-helper.in
@@ -214,7 +214,20 @@ main() {
rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}"
elif [[ -n "${socket}" ]] ; then
### welcome haaaaack city
- if [[ "${client_token[1]}" = "OpenSC Card (Fedora Signer)" ]] ; then
+ ### different versions of the opensc library name the token different
+ ### things, and as of this commit:
+ ### https://github.com/OpenSC/OpenSC/commit/259decf656a77a6d1bd3e944d6f198ed70832ff5
+ ### that includes just not including the token label unless there's
+ ### more than one token. Unfortunately this is both for the displayed
+ ### info and for the token name you specify to /use/ the token, so we
+ ### have to handle all of those options here, and change the name to
+ ### match whatever the current version of opensc is using in the rpm
+ ### macro where we're setting it. Thankfully this is just a "is this
+ ### Fedora" check for us, and if it's RHEL we're not using OpenSC at
+ ### all.
+ if [[ "${client_token[1]}" = "OpenSC Card (Fedora Signer)" ]] \
+ || [[ "${client_token[1]}" = "Fedora Signer" ]] \
+ || [[ "${client_token[1]}" = "OpenSC Card" ]] ; then
if [[ "${input[1]}" =~ (/|^)vmlinuz($|[_.-]) ]] \
|| [[ "${input[1]}" =~ (/|^)bzImage($|[_.-]) ]] ; then
if [[ "${rhelcertfile}" =~ redhatsecureboot501.* ]] \
--
2.47.0

View file

@ -0,0 +1,46 @@
From b9dd6b7826fdc540365776b860fe5190c51ab088 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Fri, 12 Jun 2020 11:49:44 -0400
Subject: [PATCH 04/42] Rename /var/run/ to /run/
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/macros.pesign | 12 ++++++------
src/tmpfiles.conf | 2 +-
2 files changed, 7 insertions(+), 7 deletions(-)
diff --git a/src/macros.pesign b/src/macros.pesign
index 7c5cba170e9..21bf3917795 100644
--- a/src/macros.pesign
+++ b/src/macros.pesign
@@ -45,14 +45,14 @@
rm -rf ${sattrs} ${sattrs}.sig ${nss} \
elif [ "$(id -un)" == "kojibuilder" -a \\\
grep -q ID=fedora /etc/os-release -a \\\
- ! -S /var/run/pesign/socket ]; then \
+ ! -S /run/pesign/socket ]; then \
echo "No socket even though this is kojibuilder" 1>&2 \
- ls -ld /var/run/pesign 1>&2 \
- ls -l /var/run/pesign/socket 1>&2 \
- getfacl /var/run/pesign 1>&2 \
- getfacl /var/run/pesign/socket 1>&2 \
+ ls -ld /run/pesign 1>&2 \
+ ls -l /run/pesign/socket 1>&2 \
+ getfacl /run/pesign 1>&2 \
+ getfacl /run/pesign/socket 1>&2 \
exit 1 \
- elif [ -S /var/run/pesign/socket ]; then \
+ elif [ -S /run/pesign/socket ]; then \
%{_pesign_client} -t %{__pesign_client_token} \\\
-c %{__pesign_client_cert} \\\
%{-i} %{-o} %{-e} %{-s} %{-C} \
diff --git a/src/tmpfiles.conf b/src/tmpfiles.conf
index c1cf35597d8..3375ad52a44 100644
--- a/src/tmpfiles.conf
+++ b/src/tmpfiles.conf
@@ -1 +1 @@
-D /var/run/pesign 0770 pesign pesign -
+D /run/pesign 0770 pesign pesign -
--
2.29.2

View file

@ -1,41 +0,0 @@
From 616ec5f25adbde1a4bd78cdcacd6dcd7ecfa5a5c Mon Sep 17 00:00:00 2001
From: Gary Lin <glin@suse.com>
Date: Thu, 22 Dec 2022 13:49:34 +0800
Subject: [PATCH] cms_common: skip authentication on the 'Friendly' slot
When finding a certificate in a 'Friendly' slot without the need of the
private key, it is not necessary to authenticate the slot.
For example, when the signed attributes and the raw signature are
created in a server and the user has the certificate, signkey.x509, and
tries to import them into myapp.efi:
$ certutil -N -d nssdb -f passwd
$ certutil -A -d nssdb -f passwd -n signkey -t CT,CT,CT \
-i signkey.x509
$ pesign -n nssdb -c signkey -i myapp.efi -o myapp.efi.signed \
-d sha256 -I myapp.sattr -R myapp.sig
Since the "signkey" is 'Friendly', i.e. publicly readable, and the
private key is not needed, we can just skip the authentication and find
"signkey" in the slot.
Signed-off-by: Gary Lin <glin@suse.com>
---
src/cms_common.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/src/cms_common.c b/src/cms_common.c
index cf572ca..44e5cca 100644
--- a/src/cms_common.c
+++ b/src/cms_common.c
@@ -628,7 +628,8 @@ find_certificate(cms_context *cms, int needs_private_key)
int errnum;
SECStatus status;
- if (PK11_NeedLogin(psle->slot) && !PK11_IsLoggedIn(psle->slot, cms)) {
+ if ((needs_private_key || !PK11_IsFriendly(psle->slot)) &&
+ (PK11_NeedLogin(psle->slot) && !PK11_IsLoggedIn(psle->slot, cms))) {
status = PK11_Authenticate(psle->slot, PR_TRUE, cms);
if (status != SECSuccess) {
save_port_err() {

View file

@ -1,25 +0,0 @@
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
From: Nicolas Frayer <nfrayer@redhat.com>
Date: Mon, 22 Jun 2026 20:58:03 +0200
Subject: [PATCH] Add const qualifier to variable
Add const to a variable initialized with using strrchr.
Signed-off-by: Nicolas Frayer <nfrayer@redhat.com>
---
src/pesum.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/pesum.c b/src/pesum.c
index e4ddaf86d7fa..5d7dcb929eec 100644
--- a/src/pesum.c
+++ b/src/pesum.c
@@ -141,7 +141,7 @@ main(int argc, char *argv[])
while ((infile = poptGetArg(optCon)) != NULL) {
pesign_context *ctxp = NULL;
- char *ext = strrchr(infile, '.');
+ const char *ext = strrchr(infile, '.');
if (ext && strcmp(ext, ".ko") == 0)
fmt = FORMAT_KERNEL_MODULE;

View file

@ -0,0 +1,31 @@
From 002371099d65b790e4850bc734dccddac790bb10 Mon Sep 17 00:00:00 2001
From: Jeremy Cline <jcline@redhat.com>
Date: Tue, 18 Feb 2020 16:37:53 -0500
Subject: [PATCH 05/42] Apparently opensc got updated and the token name
changed
All the kernel builds started failing yesterday because the signing
token could not be found. Update the token name in the macro shipped by
pesign.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/macros.pesign | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/macros.pesign b/src/macros.pesign
index 21bf3917795..5a6da1c6809 100644
--- a/src/macros.pesign
+++ b/src/macros.pesign
@@ -9,7 +9,7 @@
%__pesign_token %{nil}%{?pe_signing_token:-t "%{pe_signing_token}"}
%__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"}
-%__pesign_client_token %{!?pe_signing_token:"Fedora Signer (OpenSC Card)"}%{?pe_signing_token:"%{pe_signing_token}"}
+%__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"}
%__pesign_client_cert %{!?pe_signing_cert:"/CN=Fedora Secure Boot Signer"}%{?pe_signing_cert:"%{pe_signing_cert}"}
%_pesign /usr/bin/pesign
--
2.29.2

File diff suppressed because it is too large Load diff

View file

@ -0,0 +1,65 @@
From 2fd010b0edc814e46955c85a7ec2cfa8c12a7862 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Mon, 3 Feb 2020 15:42:52 -0500
Subject: [PATCH 07/42] Add hex utilities.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/hex.h | 45 +++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 45 insertions(+)
create mode 100644 src/hex.h
diff --git a/src/hex.h b/src/hex.h
new file mode 100644
index 00000000000..24014eb3056
--- /dev/null
+++ b/src/hex.h
@@ -0,0 +1,45 @@
+// SPDX-License-Identifier: GPLv2
+/*
+ * hex.h - hexidecimal conversion helpers
+ * Copyright Peter Jones <pjones@redhat.com>
+ */
+#ifndef HEX_H_
+#define HEX_H_
+
+static inline uint8_t hexchar_to_bin(char hex)
+{
+ if (hex >= '0' && hex <= '9')
+ return hex - '0';
+ if (hex >= 'A' && hex <= 'F')
+ return hex - 'A' + 10;
+ if (hex >= 'a' && hex <= 'f')
+ return hex - 'a' + 10;
+ return -1;
+}
+
+static inline int
+hex_to_bin(const char *hex, uint8_t *out, size_t size)
+{
+ for (size_t i = 0, j = 0; j < size; i+= 2, j++) {
+ uint8_t val;
+
+ val = hexchar_to_bin(hex[i]);
+ if (val > 15)
+ goto out_of_range;
+ out[j] = (val & 0xf) << 4;
+
+ val = hexchar_to_bin(hex[i+1]);
+ if (val > 15)
+ goto out_of_range;
+ out[j] |= val & 0xf;
+ }
+
+ errno = 0;
+ return 0;
+out_of_range:
+ errno = ERANGE;
+ return -1;
+}
+
+#endif /* !HEX_H_ */
+// vim:fenc=utf-8:tw=75:noet
--
2.29.2

View file

@ -0,0 +1,367 @@
From 2cd818c0ef885276cc66ff39bcbe01a90d385db8 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Mon, 22 Jun 2020 10:35:22 -0400
Subject: [PATCH 08/42] Add some text parsing helpers
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/text.c | 259 +++++++++++++++++++++++++++++++++++++++++++++++++++
src/pesign.h | 1 +
src/text.h | 53 +++++++++++
src/Makefile | 2 +-
4 files changed, 314 insertions(+), 1 deletion(-)
create mode 100644 src/text.c
create mode 100644 src/text.h
diff --git a/src/text.c b/src/text.c
new file mode 100644
index 00000000000..e463e8d05eb
--- /dev/null
+++ b/src/text.c
@@ -0,0 +1,259 @@
+// SPDX-License-Identifier: GPLv2
+/*
+ * text.c - helpers for text strings
+ * Copyright Peter Jones <pjones@redhat.com>
+ */
+#include "compiler.h"
+#include "text.h"
+
+#include <stdbool.h>
+#include <stdlib.h>
+#include <stdint.h>
+#include <string.h>
+
+const char * const eol_chars = "\f\r\v\n";
+// static const char * const whitespace_chars = "\t ";
+const char * const whitespace_and_eol_chars = "\t \f\r\v\n";
+
+// static const char * const binary_digits = "01";
+static const char * const octal_digits = "01234567";
+// static const char * const decimal_digits = "0123456789";
+static const char * const hex_digits = "0123456789abcdefABCDEF";
+
+static const char * const cnt_nl = "\\\n";
+static const char * const cnt_lfnl = "\\\r\n";
+static const char * const cnt_lf = "\\\r";
+static const char * const cnt_ff = "\\\f";
+static const char * const cnt_vt = "\\\v";
+
+static const char * const line_continuation_strs[] = {
+ cnt_nl,
+ cnt_lfnl,
+ cnt_lf,
+ cnt_ff,
+ cnt_vt,
+ NULL
+};
+
+/*
+ * unbreak_line_coninutations: remove all line continuations
+ * @buf: the buffer to operate on
+ * @bufsz: the size of the buffer
+ */
+void
+unbreak_line_continuations(char *buf, size_t bufsz)
+{
+ char *to = buf;
+ bool found = true;
+
+ while (found) {
+ found = false;
+
+ for (unsigned int i = 0; line_continuation_strs[i]; i++) {
+ size_t cntsz = strlen(line_continuation_strs[i]);
+ char *needle = strstr(to, line_continuation_strs[i]);
+ char *from;
+ size_t sz;
+
+ if (!needle)
+ continue;
+
+ found = true;
+ from = needle + cntsz;
+ sz = bufsz - (from - buf);
+
+ to = needle;
+ memmove(to, from, sz);
+ }
+ }
+}
+
+/*
+ * stresccspn: calculate the number of bytes which do not contain escape
+ * sequences.
+ * @buf: the buffer to search
+ *
+ * Returns the size of the initial segment of buf which does not contain
+ * any escape sequences. If no escape sequence is found, buf[return] will
+ * point to the NUL terminator.
+ */
+size_t stresccspn(const char * const buf)
+{
+ size_t span = strcspn(buf, "\\");
+
+ return span;
+}
+
+/*
+ * escape_func: parse the value for one single escape character
+ * @delimiter: the delimiter as to which kind of escape sequence this is
+ * (i.e. 'x' for \x1abc)
+ * @buf: the buffer being parsed
+ * @val: the parsed value is placed in val
+ * @valsz: how many bytes of val are meaningful
+ *
+ * Returns the number of bytes of buf to advance to skip the escape
+ * sequence, including the delimiter character but not the initial escape
+ * character. If the initial segment of buf is not an escape sequence,
+ * *valsz and the return value will both be 0.
+ */
+typedef size_t (*escape_func)(uint32_t delimiter, const char * const buf,
+ char val[9], size_t *valsz);
+
+static size_t
+simple_escape_sequence(uint32_t delimiter, const char * const buf UNUSED,
+ char val[9], size_t *valsz)
+{
+ val[0] = delimiter & 0xffu;
+ *valsz = 1;
+
+ return 1;
+}
+
+static size_t
+digits_escape_sequence(uint32_t delimiter, const char * const buf,
+ char val[2], size_t *valsz)
+{
+ size_t span;
+ unsigned long long ul;
+ char tmpbuf[4] = { 0, };
+ int base;
+
+ if (delimiter == 'x') {
+ span = strspn(buf, hex_digits);
+ base = 16;
+ if (span > 2)
+ span = 2;
+ strncpy(tmpbuf, buf, span);
+ } else {
+ span = strspn(buf, octal_digits);
+ base = 8;
+ if (span > 2)
+ span = 2;
+ tmpbuf[0] = delimiter & 0xffu;
+ strncpy(&tmpbuf[1], buf, span);
+ span += 1;
+ }
+ if (span == 0) {
+ val[0] = delimiter & 0xffu;
+ *valsz = 1;
+ return 1;
+ }
+
+ tmpbuf[span+1] = '\0';
+ ul = strtoul(tmpbuf, NULL, base);
+
+ val[0] = ul & 0xffu;
+ *valsz = 1;
+
+ return span;
+}
+
+struct escape_handler {
+ const char * const escapes;
+ escape_func func;
+};
+static struct escape_handler escape_handlers[] = {
+ {.escapes = " \"\'\?\a\b\f\n\r\t\v\\",
+ .func = simple_escape_sequence },
+ {.escapes = "x01234567",
+ .func = digits_escape_sequence },
+ {.escapes = 0,
+ .func = NULL }
+};
+
+/*
+ * parse_escape: parses one escape string
+ * @buf: the buffer being parsed
+ * @val: the parsed value is placed in val
+ * @valsz: how many bytes of val are meaningful
+ *
+ * Returns the number of bytes of buf to advance to skip the escape
+ * sequence. If the initial segment of buf is not an escape sequence,
+ * *valsz and the return value will both be 0.
+ */
+static size_t
+parse_escape(const char * const buf, char val[9], size_t *valsz)
+{
+ struct escape_handler *eh = NULL;
+
+ if (buf[0] != '\\')
+ return 0;
+
+ for(size_t i = 0; escape_handlers[i].escapes != 0; i++) {
+ char *match;
+ eh = &escape_handlers[i];
+
+ match = strchrnul(eh->escapes, buf[1]);
+ if (match[0] != buf[1])
+ continue;
+ }
+ if (eh && eh->func)
+ return eh->func(buf[1], &buf[2], val, valsz);
+ return 0;
+}
+
+/*
+ * strescspn: calculate the size of an escape sequence.
+ * @buf: a NUL-terminated utf-8 buffer.
+ *
+ * returns the number of bytes which are part of a single escape sequence.
+ * If no escape sequnce can be parsed, returns 0.
+ */
+size_t strescspn(const char * const buf)
+{
+ size_t advance = 0, valsz = 0;
+ char val[9] = { 0, };
+
+ if (!buf[0] || buf[0] != '\\')
+ return 0;
+
+ advance = parse_escape(&buf[1], val, &valsz);
+ if (advance == 0) {
+ /*
+ * If we come to illegal escape values like "\\xzz" then
+ * we just use the delimiter character (in this case 'x'),
+ * so the span here is 2.
+ */
+ return 2;
+ }
+ return valsz + 1;
+}
+
+/*
+ * resolve_escapes: parse all instances of escape sequences in buf
+ * @buf: the buffer to operate on
+ *
+ * Returns the size of buf once escape sequnces have been replaced.
+ */
+size_t
+resolve_escapes(char *buf)
+{
+ size_t to = 0;
+ for (size_t from = 0; buf[from]; from++) {
+ size_t advance, valsz = 0;
+ char val[9];
+ if (buf[from] != '\\') {
+ buf[to++] = buf[from];
+ continue;
+ }
+
+ advance = parse_escape(&buf[from], val, &valsz);
+ if (advance == 0) {
+ /*
+ * If we come to illegal escape values like "\\xzz"
+ * then just move the '\\' out of the way...
+ */
+ buf[to++] = buf[++from];
+ continue;
+ }
+
+ for (size_t j = 0; j < valsz; j++)
+ buf[to+j] = val[j];
+ to += advance + 1;
+ }
+ buf[to++] = '\0';
+ return to;
+}
+
+// vim:fenc=utf-8:tw=75:noet
diff --git a/src/pesign.h b/src/pesign.h
index 9f80a9ad108..1b404223d31 100644
--- a/src/pesign.h
+++ b/src/pesign.h
@@ -25,6 +25,7 @@
#include <libdpe/pe.h>
#include "util.h"
+#include "text.h"
#include "cms_common.h"
#include "pesign_context.h"
diff --git a/src/text.h b/src/text.h
new file mode 100644
index 00000000000..e5722c7aee1
--- /dev/null
+++ b/src/text.h
@@ -0,0 +1,53 @@
+// SPDX-License-Identifier: GPLv2
+/*
+ * text.c - helpers for text strings
+ * Copyright Peter Jones <pjones@redhat.com>
+ */
+#ifndef TEXT_H_
+#define TEXT_H_
+
+#include <unistd.h>
+
+/*
+ * Characters that can be considered whitespace or end-of-line markers.
+ */
+extern const char * const eol_chars;
+extern const char * const whitespace_and_eol_chars;
+
+/*
+ * unbreak_line_coninutations: remove all line continuations
+ * @buf: the buffer to operate on
+ * @bufsz: the size of the buffer
+ */
+extern void unbreak_line_continuations(char *buf, size_t bufsz);
+
+/*
+ * strescspn: calculate the size of an escape sequence.
+ * @buf: a NUL-terminated utf-8 buffer.
+ *
+ * returns the number of bytes which are part of a single escape sequence.
+ * If no escape sequnce can be parsed, returns 0.
+ */
+extern size_t strescspn(const char * const buf);
+
+/*
+ * stresccspn: calculate the number of bytes which do not contain escape
+ * sequences.
+ * @buf: the buffer to search
+ *
+ * Returns the size of the initial segment of buf which does not contain
+ * any escape sequences. If no escape sequence is found, buf[return] will
+ * point to the NUL terminator.
+ */
+extern size_t stresccspn(const char * const buf);
+
+/*
+ * resolve_escapes: parse all instances of escape sequences in buf
+ * @buf: the buffer to operate on
+ *
+ * Returns the size of buf once escape sequnces have been replaced.
+ */
+extern size_t resolve_escapes(char *buf);
+
+#endif /* !TEXT_H_ */
+// vim:fenc=utf-8:tw=75:noet
diff --git a/src/Makefile b/src/Makefile
index 74327ba13f3..dfdc7c5e4c5 100644
--- a/src/Makefile
+++ b/src/Makefile
@@ -12,7 +12,7 @@ TARGETS=$(BINTARGETS) $(SVCTARGETS)
all : deps $(TARGETS)
COMMON_SOURCES = cms_common.c content_info.c oid.c password.c \
- signed_data.c signer_info.c ucs2.c
+ signed_data.c signer_info.c text.c ucs2.c
COMMON_PE_SOURCES = wincert.c cms_pe_common.c
AUTHVAR_SOURCES = authvar.c authvar_context.c
CLIENT_SOURCES = pesign_context.c actions.c client.c
--
2.29.2

View file

@ -0,0 +1,113 @@
From d6787fbed0a1f993af6418c758c781361d553219 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Wed, 29 Apr 2020 18:23:30 -0400
Subject: [PATCH 09/42] libdpe: fix some minor analyzer discoveries.
I don't think we can meaningfully hit any of these in any use that
actually matters, but may as well fix them.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
libdpe/pe_begin.c | 3 +++
libdpe/pe_getdatadir.c | 2 +-
libdpe/pe_opthdr.c | 12 ++++++------
include/libdpe/libdpe.h | 4 ++--
4 files changed, 12 insertions(+), 9 deletions(-)
diff --git a/libdpe/pe_begin.c b/libdpe/pe_begin.c
index 51189f8069c..3bcc2c70c61 100644
--- a/libdpe/pe_begin.c
+++ b/libdpe/pe_begin.c
@@ -156,6 +156,9 @@ __libpe_read_mmapped_file(int fildes, void *map_address, size_t maxsize,
case PE_K_PE_EXE:
return file_read_pe_exe(fildes, map_address, p_ident,
maxsize, cmd, parent);
+ case PE_K_MZ:
+ errno = ENOSYS;
+ return NULL;
default:
break;
}
diff --git a/libdpe/pe_getdatadir.c b/libdpe/pe_getdatadir.c
index 08f46787304..f080f3a9998 100644
--- a/libdpe/pe_getdatadir.c
+++ b/libdpe/pe_getdatadir.c
@@ -24,7 +24,7 @@ pe_getdatadir(Pe *pe, data_directory **dd)
{
int rc = -1;
- if (!dd) {
+ if (!pe || !dd) {
__libpe_seterrno(PE_E_INVALID_INDEX);
return rc;
}
diff --git a/libdpe/pe_opthdr.c b/libdpe/pe_opthdr.c
index 02075e5cd49..ae74a897500 100644
--- a/libdpe/pe_opthdr.c
+++ b/libdpe/pe_opthdr.c
@@ -32,7 +32,7 @@ pe_getopthdr(Pe *pe)
}
}
-uint32_t
+int32_t
pe_get_file_alignment(Pe *pe)
{
struct pe32_opt_hdr *pe32opthdr = NULL;
@@ -42,12 +42,12 @@ pe_get_file_alignment(Pe *pe)
case PE_K_PE_EXE: {
void *opthdr = pe_getopthdr(pe);
pe32opthdr = opthdr;
- return pe32opthdr->file_align;
+ return pe32opthdr ? (int32_t)pe32opthdr->file_align : -1;
}
case PE_K_PE64_EXE: {
void *opthdr = pe_getopthdr(pe);
pe64opthdr = opthdr;
- return pe64opthdr->file_align;
+ return pe64opthdr ? (int32_t)pe64opthdr->file_align : -1;
break;
}
default:
@@ -56,7 +56,7 @@ pe_get_file_alignment(Pe *pe)
return -1;
}
-uint32_t
+int32_t
pe_get_scn_alignment(Pe *pe)
{
struct pe32_opt_hdr *pe32opthdr = NULL;
@@ -66,12 +66,12 @@ pe_get_scn_alignment(Pe *pe)
case PE_K_PE_EXE: {
void *opthdr = pe_getopthdr(pe);
pe32opthdr = opthdr;
- return pe32opthdr->section_align;
+ return pe32opthdr ? (int32_t)pe32opthdr->section_align : -1;
}
case PE_K_PE64_EXE: {
void *opthdr = pe_getopthdr(pe);
pe64opthdr = opthdr;
- return pe64opthdr->section_align;
+ return pe64opthdr ? (int32_t)pe64opthdr->section_align : -1;
break;
}
default:
diff --git a/include/libdpe/libdpe.h b/include/libdpe/libdpe.h
index 09f56a2a05e..895a208fe7d 100644
--- a/include/libdpe/libdpe.h
+++ b/include/libdpe/libdpe.h
@@ -87,8 +87,8 @@ extern struct pe_hdr *pe_getpehdr(Pe *pe, struct pe_hdr *pehdr);
extern char *pe_rawfile(Pe *pe, size_t *ptr);
extern int pe_getdatadir(Pe *pe, data_directory **dd);
extern void *pe_getopthdr(Pe *pe);
-extern uint32_t pe_get_file_alignment(Pe *pe);
-extern uint32_t pe_get_scn_alignment(Pe *pe);
+extern int32_t pe_get_file_alignment(Pe *pe);
+extern int32_t pe_get_scn_alignment(Pe *pe);
extern int pe_set_image_size(Pe *pe);
extern int pe_extend_file(Pe *pe, size_t size, uint32_t *new_space, int align);
--
2.29.2

View file

@ -0,0 +1,132 @@
From 8677eea21fc9b634b6b97e132a8c4295f2a9aa15 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Thu, 21 May 2020 14:27:01 -0400
Subject: [PATCH 10/42] libdpe: check for NULL pe at more places.
This isn't so much to fix a bug as to make "gcc -Wanalyze-..." output
smaller where these things are called.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
libdpe/pe_addcert.c | 17 +++++++++++++++++
libdpe/pe_allocspace.c | 19 +++++++++++++++++++
libdpe/libdpe_priv.h | 2 ++
3 files changed, 38 insertions(+)
diff --git a/libdpe/pe_addcert.c b/libdpe/pe_addcert.c
index 803ed61f7f0..b1251992ade 100644
--- a/libdpe/pe_addcert.c
+++ b/libdpe/pe_addcert.c
@@ -17,6 +17,7 @@
* Author(s): Peter Jones <pjones@redhat.com>
*/
#include <unistd.h>
+
#include "libdpe_priv.h"
int
@@ -25,6 +26,11 @@ pe_clearcert(Pe *pe)
int rc;
data_directory *dd = NULL;
+ if (!pe) {
+ errno = EINVAL;
+ return -1;
+ }
+
rc = pe_getdatadir(pe, &dd);
if (rc < 0)
return rc;
@@ -43,6 +49,11 @@ pe_alloccert(Pe *pe, size_t size)
int rc;
data_directory *dd = NULL;
+ if (!pe) {
+ errno = EINVAL;
+ return -1;
+ }
+
pe_clearcert(pe);
uint32_t new_space = 0;
@@ -69,6 +80,12 @@ pe_populatecert(Pe *pe, void *cert, size_t size)
{
int rc;
data_directory *dd = NULL;
+
+ if (!pe) {
+ errno = EINVAL;
+ return -1;
+ }
+
rc = pe_getdatadir(pe, &dd);
if (rc < 0)
return rc;
diff --git a/libdpe/pe_allocspace.c b/libdpe/pe_allocspace.c
index a2898f6d446..be704c52cf8 100644
--- a/libdpe/pe_allocspace.c
+++ b/libdpe/pe_allocspace.c
@@ -56,6 +56,11 @@ pe_fix_addresses(Pe *pe, int64_t offset)
int
pe_set_image_size(Pe *pe)
{
+ if (!pe) {
+ errno = EINVAL;
+ return -1;
+ }
+
uint32_t image_size = 0;
struct pe_hdr *pehdr = pe->state.pe.pehdr;
struct pe32plus_opt_hdr *opthdr = pe->state.pe32plus_exe.opthdr;
@@ -86,6 +91,11 @@ pe_set_image_size(Pe *pe)
int
pe_extend_file(Pe *pe, size_t size, uint32_t *new_space, int align)
{
+ if (!pe) {
+ errno = EINVAL;
+ return -1;
+ }
+
void *new = NULL;
if (align)
@@ -120,6 +130,10 @@ pe_shorten_file(Pe *pe, size_t size)
{
void *new = NULL;
+ if (!pe) {
+ errno = EINVAL;
+ return -1;
+ }
new = mremap(pe->map_address, pe->maximum_size,
pe->maximum_size - size, 0);
if (new == MAP_FAILED) {
@@ -138,6 +152,11 @@ pe_shorten_file(Pe *pe, size_t size)
int
pe_freespace(Pe *pe, uint32_t offset, size_t size)
{
+ if (!pe) {
+ errno = EINVAL;
+ return -1;
+ }
+
void *addr = compute_mem_addr(pe, offset);
memset(addr, '\0', size);
diff --git a/libdpe/libdpe_priv.h b/libdpe/libdpe_priv.h
index 26e50498c1d..e207772097a 100644
--- a/libdpe/libdpe_priv.h
+++ b/libdpe/libdpe_priv.h
@@ -19,7 +19,9 @@
#ifndef LIBDPE_PRIV_H
#define LIBDPE_PRIV_H 1
+#include <errno.h>
#include <libdpe/libdpe.h>
+
#include "compiler.h"
#include "endian.h"
--
2.29.2

View file

@ -0,0 +1,36 @@
From b4de3e4891be5f4de2c9a19740fc48c3bc28c68f Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Thu, 21 May 2020 15:23:11 -0400
Subject: [PATCH 11/42] wincert: try to convince the gcc analyzer of the
painfully obvious.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/wincert.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/src/wincert.c b/src/wincert.c
index 4ccf528efad..7c802d22025 100644
--- a/src/wincert.c
+++ b/src/wincert.c
@@ -364,9 +364,16 @@ err:
if (signatures) {
for (i = 0; i < nsigs; i++) {
if (signatures[i]) {
- if (signatures[i]->data)
+ if (signatures[i]->data) /* <-- see below */
free(signatures[i]->data);
free(signatures[i]);
+ /*
+ * in gcc-10.1.1-1.fc32 , -fanalyzer believes the test
+ * above is a use-after free. I really don't see how,
+ * but this somehow convinces it there's nothing wrong
+ * there.
+ */
+ signatures[i] = NULL;
}
}
free(signatures);
--
2.29.2

View file

@ -0,0 +1,26 @@
From 998e825efd44d3f5098022537f7967c24d208841 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Fri, 5 Jun 2020 10:20:30 -0400
Subject: [PATCH 12/42] Fix a missing malloc() return value check.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/pesigcheck.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/src/pesigcheck.c b/src/pesigcheck.c
index 8fa0f1ad03d..961a32a6ad7 100644
--- a/src/pesigcheck.c
+++ b/src/pesigcheck.c
@@ -116,6 +116,8 @@ cert_matches_digest(pesigcheck_context *ctx, void *data, ssize_t datalen,
digest = content->data + content->len - pe_digest->len;
if (digest_out) {
digest_out->data = malloc(pe_digest->len);
+ if (!digest_out->data)
+ goto out;
digest_out->len = pe_digest->len;
digest_out->type = pe_digest->type;
memcpy(digest_out->data, digest, pe_digest->len);
--
2.29.2

View file

@ -0,0 +1,67 @@
From 1f81f3ec196365d6bdf490d05776ba7a4e0257b0 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Thu, 21 May 2020 15:23:54 -0400
Subject: [PATCH 13/42] Fix some missed OOM error path -fanalyzer found.
Amazingly, it seems to find more *real* problems (surprisingly) *and*
present them more readably (not surprisingly at all) without -flto.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/actions.c | 19 +++++++++----------
1 file changed, 9 insertions(+), 10 deletions(-)
diff --git a/src/actions.c b/src/actions.c
index 69f9e3e1c1a..d0f538e81d4 100644
--- a/src/actions.c
+++ b/src/actions.c
@@ -68,8 +68,8 @@ insert_signature(cms_context *cms, int signum)
sizeof (SECItem *) * (cms->num_signatures + 1));
if (!signatures) {
err:
- cms->log(cms, LOG_ERR, "insert signature: could not allocate "
- "memory: %m");
+ cms->log(cms, LOG_ERR,
+ "insert signature: could not allocate memory: %m");
exit(1);
}
cms->signatures = signatures;
@@ -80,6 +80,9 @@ err:
}
SECItem *newsig = malloc(sizeof (*newsig));
+ if (!newsig)
+ goto err;
+
memcpy(newsig, sig, sizeof (*newsig));
newsig->data = malloc(sig->len);
if (!newsig->data)
@@ -293,10 +296,8 @@ parse_signature(pesign_context *ctx)
size_t siglen;
rc = read_file(ctx->insigfd, &sig, &siglen);
- if (rc < 0) {
- fprintf(stderr, "pesign: could not read signature.\n");
- exit(1);
- }
+ if (rc < 0)
+ liberr(1, "pesign: could not read signature");
unsigned char *der;
unsigned int derlen;
@@ -306,10 +307,8 @@ parse_signature(pesign_context *ctx)
if (base64) {
base64 += strlen(sig_begin_marker);
char *end = strstr(base64, sig_end_marker);
- if (!end) {
- fprintf(stderr, "pesign: Invalid signature.\n");
- exit(1);
- }
+ if (!end)
+ liberr(1, "pesign: Invalid signature");
derlen = end - base64;
base64[derlen] = '\0';
--
2.29.2

View file

@ -0,0 +1,189 @@
From d14dce18a8fa31e2097d99a717d87b23539b9098 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Wed, 15 May 2019 15:55:17 -0400
Subject: [PATCH 14/42] Don't allow (or require) --module or --kernel with
--ca.
If you're doing a CA/signer split setup, the CA shouldn't be allowed to
sign things other than other certificates.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/efikeygen.c | 55 ++++++++++++++++++++++++++++++++-----------------
src/efikeygen.1 | 6 ++++--
2 files changed, 40 insertions(+), 21 deletions(-)
diff --git a/src/efikeygen.c b/src/efikeygen.c
index 848480a9b01..b8b0c961739 100644
--- a/src/efikeygen.c
+++ b/src/efikeygen.c
@@ -54,6 +54,13 @@
#include "cms_common.h"
#include "oid.h"
+enum {
+ MODSIGN_EKU_NONE,
+ MODSIGN_EKU_KERNEL,
+ MODSIGN_EKU_MODULE,
+ MODSIGN_EKU_CA
+};
+
typedef struct {
SECItem data;
SECAlgorithmID keytype;
@@ -183,8 +190,7 @@ add_key_usage(cms_context *cms, void *extHandle, int is_ca)
if (is_ca) {
usage = KU_KEY_CERT_SIGN |
- KU_CRL_SIGN |
- KU_DIGITAL_SIGNATURE;
+ KU_CRL_SIGN;
} else {
usage = KU_KEY_ENCIPHERMENT |
KU_DATA_ENCIPHERMENT |
@@ -252,7 +258,7 @@ add_basic_constraints(cms_context *cms, void *extHandle)
}
static int
-add_extended_key_usage(cms_context *cms, int modsign_only, void *extHandle)
+add_extended_key_usage(cms_context *cms, int modsign_eku, void *extHandle)
{
SECItem values[2];
SECItem wrapped = { 0 };
@@ -260,7 +266,11 @@ add_extended_key_usage(cms_context *cms, int modsign_only, void *extHandle)
SECOidTag tag;
int rc;
- if (modsign_only < 1 || modsign_only > 2)
+ if (modsign_eku == MODSIGN_EKU_CA)
+ return 0;
+
+ if (modsign_eku != MODSIGN_EKU_KERNEL
+ && modsign_eku != MODSIGN_EKU_MODULE)
cmsreterr(-1, cms, "could not encode extended key usage");
rc = make_eku_oid(cms, &values[0], SEC_OID_EXT_KEY_USAGE_CODE_SIGN);
@@ -273,11 +283,10 @@ add_extended_key_usage(cms_context *cms, int modsign_only, void *extHandle)
if (rc < 0)
cmsreterr(-1, cms, "could not encode extended key usage");
- rc = wrap_in_seq(cms, &wrapped, values, modsign_only);
+ rc = wrap_in_seq(cms, &wrapped, values, modsign_eku);
if (rc < 0)
cmsreterr(-1, cms, "could not encode extended key usage");
-
status = CERT_AddExtension(extHandle, SEC_OID_X509_EXT_KEY_USAGE,
&wrapped, PR_FALSE, PR_TRUE);
if (status != SECSuccess)
@@ -311,7 +320,7 @@ static int
add_extensions_to_crq(cms_context *cms, CERTCertificateRequest *crq,
int is_ca, int is_self_signed, SECKEYPublicKey *pubkey,
SECKEYPublicKey *spubkey,
- char *url, int modsign_only)
+ char *url, int modsign_eku)
{
void *mark = PORT_ArenaMark(cms->arena);
@@ -336,7 +345,7 @@ add_extensions_to_crq(cms_context *cms, CERTCertificateRequest *crq,
if (rc < 0)
cmsreterr(-1, cms, "could not generate certificate extensions");
- rc = add_extended_key_usage(cms, modsign_only, extHandle);
+ rc = add_extended_key_usage(cms, modsign_eku, extHandle);
if (rc < 0)
cmsreterr(-1, cms, "could not generate certificate extensions");
@@ -486,7 +495,7 @@ int main(int argc, char *argv[])
{
int is_ca = 0;
int is_self_signed = -1;
- int modsign_only = 0;
+ int modsign_eku = MODSIGN_EKU_NONE;
char *tokenname = "NSS Certificate DB";
char *signer = NULL;
char *nickname = NULL;
@@ -543,14 +552,14 @@ int main(int argc, char *argv[])
{.longName = "kernel",
.shortName = 'k',
.argInfo = POPT_ARG_VAL|POPT_ARGFLAG_OR,
- .arg = &modsign_only,
- .val = 1,
+ .arg = &modsign_eku,
+ .val = MODSIGN_EKU_KERNEL,
.descrip = "Generate a kernel-signing certificate" },
{.longName = "module",
.shortName = 'm',
.argInfo = POPT_ARG_VAL|POPT_ARGFLAG_OR,
- .arg = &modsign_only,
- .val = 2,
+ .arg = &modsign_eku,
+ .val = MODSIGN_EKU_MODULE,
.descrip = "Generate a module-signing certificate" },
{.longName = "nickname",
.shortName = 'n',
@@ -622,10 +631,12 @@ int main(int argc, char *argv[])
/*
* Scenarios that are okay (x == valid combination)
*
- * is_ca is_self_signed pubkey
- * i_c x x x
- * i_s_s x x o
- * pubkey x o o
+ * is_ca is_self_signed pubkey modules kernel
+ * i_c x x x o o
+ * i_s_s x x o o o
+ * pubkey x o x x x
+ * modules o x x x x
+ * kernel o x x x x
*/
if (is_self_signed == -1)
@@ -660,8 +671,14 @@ int main(int argc, char *argv[])
liberr(1, "could not allocate cms context");
}
- if (modsign_only < 1 || modsign_only > 2)
+ if (is_ca) {
+ if (modsign_eku != MODSIGN_EKU_NONE)
+ errx(1, "CA certificates cannot have kernel or module signing credentials.");
+ modsign_eku = MODSIGN_EKU_CA;
+ } else if (modsign_eku != MODSIGN_EKU_KERNEL
+ && modsign_eku != MODSIGN_EKU_MODULE) {
errx(1, "either --kernel or --module must be used");
+ }
SECStatus status = NSS_InitReadWrite(dbdir);
if (status != SECSuccess)
@@ -752,7 +769,7 @@ int main(int argc, char *argv[])
crq = CERT_CreateCertificateRequest(name, spki, &attributes);
rc = add_extensions_to_crq(cms, crq, is_ca, is_self_signed, pubkey,
- spubkey, url, modsign_only);
+ spubkey, url, modsign_eku);
if (rc < 0)
exit(1);
diff --git a/src/efikeygen.1 b/src/efikeygen.1
index 255fadc3979..88ee7c2f7c0 100644
--- a/src/efikeygen.1
+++ b/src/efikeygen.1
@@ -33,11 +33,13 @@ Nickname of certificate to be used to sign the generated certificate.
.TP
\fB-\-kernel\fR
-The generated certificate is to be used to sign kernels.
+The generated certificate is to be used to sign kernels. Not to be used for CA
+certificates.
.TP
\fB-\-module\fR
-The generated certificate is to be used to sign kernel modules.
+The generated certificate is to be used to sign kernel modules. Not to be used
+for CA certificates.
.TP
\fB-\-token\fR=\fItoken\fR
--
2.29.2

View file

@ -0,0 +1,331 @@
From af3e0b8857825d68dde9661b74c382279e90c512 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Fri, 17 May 2019 13:47:14 -0400
Subject: [PATCH 15/42] Add super convenient errno-guard implementation.
This confuses the gcc analyzer either less or far more than
save_errno()'s fire-once loop.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/certdb.c | 32 ++++++++++++++---------
src/cms_common.c | 4 ++-
src/efikeygen.c | 1 +
src/errno-guard.c | 66 +++++++++++++++++++++++++++++++++++++++++++++++
src/errno-guard.h | 26 +++++++++++++++++++
src/pesigcheck.h | 1 +
src/pesign.h | 2 ++
src/util.h | 19 ++++----------
src/Makefile | 9 +++++--
9 files changed, 131 insertions(+), 29 deletions(-)
create mode 100644 src/errno-guard.c
create mode 100644 src/errno-guard.h
diff --git a/src/certdb.c b/src/certdb.c
index 9a4aae45f1d..f1eee3bf490 100644
--- a/src/certdb.c
+++ b/src/certdb.c
@@ -40,21 +40,23 @@ add_db_file(pesigcheck_context *ctx, db_specifier which, const char *dbfile,
db_f_type type)
{
dblist *db = calloc(1, sizeof (dblist));
+ int errno_guard;
if (!db)
return -1;
db->type = type;
db->fd = open(dbfile, O_RDONLY);
+ set_errno_guard_with_override(&errno_guard);
if (db->fd < 0) {
- save_errno(free(db));
+ free(db);
return -1;
}
char *path = strdup(dbfile);
if (!path) {
- save_errno(close(db->fd);
- free(db));
+ override_errno_guard(&errno_guard, errno);
+ free(db);
return -1;
}
@@ -62,17 +64,19 @@ add_db_file(pesigcheck_context *ctx, db_specifier which, const char *dbfile,
db->path = strdup(db->path);
free(path);
if (!db->path) {
- save_errno(close(db->fd);
- free(db));
+ override_errno_guard(&errno_guard, errno);
+ close(db->fd);
+ free(db);
return -1;
}
struct stat sb;
int rc = fstat(db->fd, &sb);
if (rc < 0) {
- save_errno(close(db->fd);
- free(db->path);
- free(db));
+ override_errno_guard(&errno_guard, errno);
+ close(db->fd);
+ free(db->path);
+ free(db);
return -1;
}
db->size = sb.st_size;
@@ -83,9 +87,10 @@ add_db_file(pesigcheck_context *ctx, db_specifier which, const char *dbfile,
size_t sz = 0;
rc = read_file(db->fd, (char **)&db->map, &sz);
if (rc < 0) {
- save_errno(close(db->fd);
- free(db->path);
- free(db));
+ override_errno_guard(&errno_guard, errno);
+ close(db->fd);
+ free(db->path);
+ free(db);
return -1;
}
}
@@ -108,8 +113,10 @@ add_db_file(pesigcheck_context *ctx, db_specifier which, const char *dbfile,
db->datalen = db->size + sizeof(EFI_SIGNATURE_LIST) +
sizeof(efi_guid_t);
db->data = calloc(1, db->datalen);
- if (!db->data)
+ if (!db->data) {
+ override_errno_guard(&errno_guard, errno);
return -1;
+ }
certlist = (EFI_SIGNATURE_LIST *)db->data;
memcpy((void *)&certlist->SignatureType, &efi_x509, sizeof(efi_guid_t));
@@ -129,6 +136,7 @@ add_db_file(pesigcheck_context *ctx, db_specifier which, const char *dbfile,
db->next = *tmp;
*tmp = db;
+ override_errno_guard(&errno_guard, 0);
return 0;
}
diff --git a/src/cms_common.c b/src/cms_common.c
index d13b2cb0f33..17f7bf252c7 100644
--- a/src/cms_common.c
+++ b/src/cms_common.c
@@ -241,7 +241,9 @@ cms_context_alloc(cms_context **cmsp)
int rc = cms_context_init(cms);
if (rc < 0) {
- save_errno(free(cms));
+ set_errno_guard();
+ xfree(cms);
+ cms = NULL;
return -1;
}
*cmsp = cms;
diff --git a/src/efikeygen.c b/src/efikeygen.c
index b8b0c961739..ac2ce45a420 100644
--- a/src/efikeygen.c
+++ b/src/efikeygen.c
@@ -52,6 +52,7 @@
#include "util.h"
#include "cms_common.h"
+#include "errno-guard.h"
#include "oid.h"
enum {
diff --git a/src/errno-guard.c b/src/errno-guard.c
new file mode 100644
index 00000000000..331692d8d70
--- /dev/null
+++ b/src/errno-guard.c
@@ -0,0 +1,66 @@
+/*
+ * errno-guard.c
+ * Copyright 2019 Peter Jones <pjones@redhat.com>
+ *
+ */
+#ifndef _GNU_SOURCE
+#define _GNU_SOURCE
+#endif
+
+#include <errno.h>
+#include <stdio.h>
+
+#include "compiler.h"
+#include "errno-guard.h"
+
+__thread int errno_guards_[ERRNO_GUARD_ENTRIES_];
+__thread int errno_guard_no_ = -1;
+
+void
+clean_up_errno_guard_(int *handle)
+{
+ if (*handle < 0
+ || *handle >= ERRNO_GUARD_ENTRIES_
+ || *handle > errno_guard_no_)
+ return;
+
+ if (errno_guards_[*handle] >= 0) {
+ errno = errno_guards_[*handle];
+ errno_guard_no_ = *handle - 1;
+ }
+ *handle = -1;
+}
+
+int
+set_up_errno_guard_(int *handle)
+{
+ int guard_var = ++errno_guard_no_;
+
+ if (guard_var < ERRNO_GUARD_ENTRIES_)
+ errno_guards_[guard_var] = errno;
+
+ if (handle)
+ *handle = guard_var;
+ return guard_var;
+}
+
+int
+override_errno_guard(int *handle, int error)
+{
+ if (handle == NULL
+ || *handle < 0
+ || *handle >= ERRNO_GUARD_ENTRIES_)
+ return -1;
+
+ if (*handle > errno_guard_no_) {
+ *handle = -1;
+ return -1;
+ }
+
+ errno = error;
+ errno_guard_no_ = *handle;
+
+ return *handle;
+}
+
+// vim:fenc=utf-8:tw=75:noet
diff --git a/src/errno-guard.h b/src/errno-guard.h
new file mode 100644
index 00000000000..e413cec95a4
--- /dev/null
+++ b/src/errno-guard.h
@@ -0,0 +1,26 @@
+/*
+ * errno-guard.h
+ * Copyright 2019 Peter Jones <pjones@redhat.com>
+ */
+
+#ifndef ERRNO_GUARD_H_
+#define ERRNO_GUARD_H_
+
+#define ERRNO_GUARD_ENTRIES_ ((int)(4096 / sizeof(int)))
+
+extern __thread int errno_guards_[ERRNO_GUARD_ENTRIES_];
+extern __thread int errno_guard_no_;
+
+extern void clean_up_errno_guard_(int *handle);
+extern int set_up_errno_guard_(int *handle);
+
+#define guard_errno_(handle, guard_var) \
+ CLEANUP_FUNC(clean_up_errno_guard_) UNUSED int guard_var = set_up_errno_guard_(handle)
+#define errno_guard_var_ CAT(CAT(CAT(CAT(errno_guard_,__LINE__),_),__COUNTER__),_)
+
+extern int override_errno_guard(int *handle, int error);
+#define set_errno_guard() guard_errno_(NULL, errno_guard_var_)
+#define set_errno_guard_with_override(handle) guard_errno_(handle, errno_guard_var_)
+
+#endif /* !ERRNO_GUARD_H_ */
+// vim:fenc=utf-8:tw=75:noet
diff --git a/src/pesigcheck.h b/src/pesigcheck.h
index 20e8040cc06..e4dbe54c59a 100644
--- a/src/pesigcheck.h
+++ b/src/pesigcheck.h
@@ -29,6 +29,7 @@
#include "certdb.h"
#include "endian.h"
+#include "errno-guard.h"
#include "oid.h"
#include "wincert.h"
#include "content_info.h"
diff --git a/src/pesign.h b/src/pesign.h
index 1b404223d31..91d30b57c02 100644
--- a/src/pesign.h
+++ b/src/pesign.h
@@ -32,7 +32,9 @@
#include "daemon.h"
#include "efitypes.h"
#include "actions.h"
+#include "errno-guard.h"
#include "endian.h"
+#include "errno-guard.h"
#include "oid.h"
#include "wincert.h"
#include "content_info.h"
diff --git a/src/util.h b/src/util.h
index 362c3559293..1b115a993f6 100644
--- a/src/util.h
+++ b/src/util.h
@@ -23,9 +23,8 @@
#include <errno.h>
#include <string.h>
#include <stdio.h>
-#include <unistd.h>
#include <stdlib.h>
-#include <errno.h>
+#include <unistd.h>
#include <libdpe/pe.h>
@@ -40,18 +39,10 @@
#define xstrdup(s) ({ void *p_ = strdup(s); if (!p_) liberr(1, "Could not allocate memory"); p_; })
#define xpfstat(path, fd, sb) ({ int rc_ = fstat(fd, sb); if (rc_ < 0) liberr(1, "Could not stat \"%s\"", path); })
-#define save_errno(x) \
- ({ \
- typeof (errno) __saved_errno = errno; \
- x; \
- errno = __saved_errno; \
- })
-#define save_pe_errno(x) \
- ({ \
- typeof (errno) __saved_errno = pe_errno(); \
- x; \
- __libpe_seterrno(__saved_errno); \
- })
+#define saved_errno_0_ CONCATENATE(CONCATENATE(error_,__LINE__),_0_)
+#define saved_errno_1_ CONCATENATE(CONCATENATE(error_,__LINE__),_1_)
+#define save_pe_errno() \
+ for (int saved_errno_0_ = 0, saved_errno_1_ = pe_errno(); saved_errno_0_ < 1; saved_errno_0_++, __libdpe_seterrno(saved_errno_1_))
#define conderr(cond, val, fmt, args...) ({ \
if (cond) \
diff --git a/src/Makefile b/src/Makefile
index dfdc7c5e4c5..bc3e5931456 100644
--- a/src/Makefile
+++ b/src/Makefile
@@ -11,8 +11,13 @@ TARGETS=$(BINTARGETS) $(SVCTARGETS)
all : deps $(TARGETS)
-COMMON_SOURCES = cms_common.c content_info.c oid.c password.c \
- signed_data.c signer_info.c text.c ucs2.c
+COMMON_SOURCES = cms_common.c content_info.c \
+ errno-guard.c \
+ oid.c \
+ password.c \
+ signed_data.c signer_info.c \
+ text.c \
+ ucs2.c
COMMON_PE_SOURCES = wincert.c cms_pe_common.c
AUTHVAR_SOURCES = authvar.c authvar_context.c
CLIENT_SOURCES = pesign_context.c actions.c client.c
--
2.29.2

View file

@ -0,0 +1,343 @@
From d2b39d942ab696d8aaf11280f4b037142ebc3643 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Fri, 17 May 2019 14:04:48 -0400
Subject: [PATCH 16/42] Make save_port_err() { } saner to read.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/cms_common.c | 65 ++++++++++++++++++++++++++++++++++-------------
src/signed_data.c | 39 ++++++++++++++++++++--------
src/cms_common.h | 14 +++++-----
3 files changed, 83 insertions(+), 35 deletions(-)
diff --git a/src/cms_common.c b/src/cms_common.c
index 17f7bf252c7..9218f69ef9e 100644
--- a/src/cms_common.c
+++ b/src/cms_common.c
@@ -350,7 +350,9 @@ unlock_nss_token(cms_context *cms)
PK11SlotListElement *psle = NULL;
psle = PK11_GetFirstSafe(slots);
if (!psle) {
- save_port_err(PK11_FreeSlotList(slots));
+ save_port_err() {
+ PK11_FreeSlotList(slots);
+ }
cmsreterr(-1, cms, "could not get pk11 safe");
}
@@ -362,7 +364,9 @@ unlock_nss_token(cms_context *cms)
}
if (!psle) {
- save_port_err(PK11_FreeSlotList(slots));
+ save_port_err() {
+ PK11_FreeSlotList(slots);
+ }
cms->log(cms, LOG_ERR, "could not find token \"%s\"",
cms->tokenname);
return -1;
@@ -406,7 +410,9 @@ find_certificate(cms_context *cms, int needs_private_key)
PK11SlotListElement *psle = NULL;
psle = PK11_GetFirstSafe(slots);
if (!psle) {
- save_port_err(PK11_FreeSlotList(slots));
+ save_port_err() {
+ PK11_FreeSlotList(slots);
+ }
cmsreterr(-1, cms, "could not get pk11 safe");
}
@@ -418,7 +424,9 @@ find_certificate(cms_context *cms, int needs_private_key)
}
if (!psle) {
- save_port_err(PK11_FreeSlotList(slots));
+ save_port_err() {
+ PK11_FreeSlotList(slots);
+ }
cms->log(cms, LOG_ERR, "could not find token \"%s\"",
cms->tokenname);
return -1;
@@ -439,9 +447,10 @@ find_certificate(cms_context *cms, int needs_private_key)
CERTCertList *certlist = NULL;
certlist = PK11_ListCertsInSlot(psle->slot);
if (!certlist) {
- save_port_err(
+ save_port_err() {
PK11_DestroySlotListElement(slots, &psle);
- PK11_FreeSlotList(slots));
+ PK11_FreeSlotList(slots);
+ }
cmsreterr(-1, cms, "could not get certificate list");
}
@@ -466,10 +475,11 @@ find_certificate(cms_context *cms, int needs_private_key)
&cbdata);
}
if (status != SECSuccess || cbdata.cert == NULL) {
- save_port_err(
+ save_port_err() {
CERT_DestroyCertList(certlist);
PK11_DestroySlotListElement(slots, &psle);
- PK11_FreeSlotList(slots));
+ PK11_FreeSlotList(slots);
+ }
cmsreterr(-1, cms, "could not find certificate in list");
}
@@ -502,7 +512,9 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot)
PK11SlotListElement *psle = NULL;
psle = PK11_GetFirstSafe(slots);
if (!psle) {
- save_port_err(PK11_FreeSlotList(slots));
+ save_port_err() {
+ PK11_FreeSlotList(slots);
+ }
cmsreterr(-1, cms, "could not get pk11 safe");
}
@@ -514,7 +526,9 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot)
}
if (!psle) {
- save_port_err(PK11_FreeSlotList(slots));
+ save_port_err() {
+ PK11_FreeSlotList(slots);
+ }
cms->log(cms, LOG_ERR, "could not find token \"%s\"",
cms->tokenname);
return -1;
@@ -555,7 +569,9 @@ find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
PK11SlotListElement *psle = NULL;
psle = PK11_GetFirstSafe(slots);
if (!psle) {
- save_port_err(PK11_FreeSlotList(slots));
+ save_port_err() {
+ PK11_FreeSlotList(slots);
+ }
cmsreterr(-1, cms, "could not get pk11 safe");
}
@@ -567,7 +583,9 @@ find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
}
if (!psle) {
- save_port_err(PK11_FreeSlotList(slots));
+ save_port_err() {
+ PK11_FreeSlotList(slots);
+ }
cms->log(cms, LOG_ERR, "could not find token \"%s\"",
cms->tokenname);
return -1;
@@ -588,9 +606,10 @@ find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
CERTCertList *certlist = NULL;
certlist = PK11_ListCertsInSlot(psle->slot);
if (!certlist) {
- save_port_err(
+ save_port_err() {
PK11_DestroySlotListElement(slots, &psle);
- PK11_FreeSlotList(slots));
+ PK11_FreeSlotList(slots);
+ }
cmsreterr(-1, cms, "could not get certificate list");
}
@@ -1158,7 +1177,9 @@ wrap_in_seq(cms_context *cms, SECItem *der, SECItem *items, int num_items)
int rc = 0;
ret = SEC_ASN1EncodeItem(cms->arena, der, items, tmpl);
if (ret == NULL) {
- save_port_err(PORT_ArenaRelease(cms->arena, mark));
+ save_port_err() {
+ PORT_ArenaRelease(cms->arena, mark);
+ }
cmsreterr(-1, cms, "could not encode set");
}
PORT_ArenaUnmark(cms->arena, mark);
@@ -1261,7 +1282,9 @@ generate_ava(cms_context *cms, SECItem *der, CERTAVA *certava)
oid = SECOID_FindOID(&certava->type);
if (!oid) {
- save_port_err(PORT_FreeArena(arena, PR_TRUE));
+ save_port_err() {
+ PORT_FreeArena(arena, PR_TRUE);
+ }
cms->arena = real_arena;
cmsreterr(-1, cms, "could not find OID");
}
@@ -1279,7 +1302,9 @@ generate_ava(cms_context *cms, SECItem *der, CERTAVA *certava)
SECItem tmp;
ret = SEC_ASN1EncodeItem(arena, &tmp, &ava, AVATemplate);
if (ret == NULL) {
- save_port_err(PORT_FreeArena(arena, PR_TRUE));
+ save_port_err() {
+ PORT_FreeArena(arena, PR_TRUE);
+ }
cms->arena = real_arena;
cmsreterr(-1, cms, "could not encode AVA");
}
@@ -1288,7 +1313,9 @@ generate_ava(cms_context *cms, SECItem *der, CERTAVA *certava)
der->len = tmp.len;
der->data = PORT_ArenaAlloc(real_arena, tmp.len);
if (!der->data) {
- save_port_err(PORT_FreeArena(arena, PR_TRUE));
+ save_port_err() {
+ PORT_FreeArena(arena, PR_TRUE);
+ }
cms->arena = real_arena;
cmsreterr(-1, cms, "could not allocate AVA");
}
@@ -1479,3 +1506,5 @@ generate_keys(cms_context *cms, PK11SlotInfo *slot,
cmsreterr(-1, cms, "could not generate RSA keypair");
return 0;
}
+
+// vim:fenc=utf-8:tw=75:noet
diff --git a/src/signed_data.c b/src/signed_data.c
index af3a84ff4ab..c6dff5481bb 100644
--- a/src/signed_data.c
+++ b/src/signed_data.c
@@ -81,14 +81,18 @@ generate_certificate_list(cms_context *cms, SECItem ***certificate_list_p)
certificates = PORT_ArenaZAlloc(cms->arena, sizeof (SECItem *) * 3);
if (!certificates) {
- save_port_err(PORT_ArenaRelease(cms->arena, mark));
+ save_port_err() {
+ PORT_ArenaRelease(cms->arena, mark);
+ }
cmsreterr(-1, cms, "could not allocate certificate list");
}
int i = 0;
certificates[i] = PORT_ArenaZAlloc(cms->arena, sizeof (SECItem));
if (!certificates[i]) {
- save_port_err(PORT_ArenaRelease(cms->arena, mark));
+ save_port_err() {
+ PORT_ArenaRelease(cms->arena, mark);
+ }
cmsreterr(-1, cms, "could not allocate certificate entry");
}
SECITEM_CopyItem(cms->arena, certificates[i++], &cms->cert->derCert);
@@ -106,8 +110,9 @@ generate_certificate_list(cms_context *cms, SECItem ***certificate_list_p)
certificates[i] = PORT_ArenaZAlloc(cms->arena,
sizeof (SECItem));
if (!certificates[i]) {
- save_port_err(
- PORT_ArenaRelease(cms->arena, mark));
+ save_port_err() {
+ PORT_ArenaRelease(cms->arena, mark);
+ }
cmsreterr(-1, cms,"could not allocate "
"certificate entry");
}
@@ -275,7 +280,9 @@ generate_spc_signed_data(cms_context *cms, SECItem *sdp)
void *mark = PORT_ArenaMark(cms->arena);
if (SEC_ASN1EncodeInteger(cms->arena, &sd.version, 1) == NULL) {
- save_port_err(PORT_ArenaRelease(cms->arena, mark));
+ save_port_err() {
+ PORT_ArenaRelease(cms->arena, mark);
+ }
cms->ci_digest = NULL;
cmsreterr(-1, cms, "could not encode integer");
}
@@ -309,7 +316,9 @@ generate_spc_signed_data(cms_context *cms, SECItem *sdp)
SECItem encoded = { 0, };
if (SEC_ASN1EncodeItem(cms->arena, &encoded, &sd, SignedDataTemplate)
== NULL) {
- save_port_err(PORT_ArenaRelease(cms->arena, mark));
+ save_port_err() {
+ PORT_ArenaRelease(cms->arena, mark);
+ }
cms->ci_digest = NULL;
cmsreterr(-1, cms, "could not encode SignedData");
}
@@ -325,7 +334,9 @@ generate_spc_signed_data(cms_context *cms, SECItem *sdp)
SECItem wrapper = { 0, };
if (SEC_ASN1EncodeItem(cms->arena, &wrapper, &sdw,
ContentInfoTemplate) == NULL) {
- save_port_err(PORT_ArenaRelease(cms->arena, mark));
+ save_port_err() {
+ PORT_ArenaRelease(cms->arena, mark);
+ }
cms->ci_digest = NULL;
cmsreterr(-1, cms, "could not encode SignedData");
}
@@ -347,7 +358,9 @@ generate_authvar_signed_data(cms_context *cms, SECItem *sdp)
void *mark = PORT_ArenaMark(cms->arena);
if (SEC_ASN1EncodeInteger(cms->arena, &sd.version, 1) == NULL) {
- save_port_err(PORT_ArenaRelease(cms->arena, mark));
+ save_port_err() {
+ PORT_ArenaRelease(cms->arena, mark);
+ }
cmsreterr(-1, cms, "could not encode integer");
}
@@ -376,7 +389,9 @@ generate_authvar_signed_data(cms_context *cms, SECItem *sdp)
SECItem encoded = { 0, };
if (SEC_ASN1EncodeItem(cms->arena, &encoded, &sd, SignedDataTemplate)
== NULL) {
- save_port_err(PORT_ArenaRelease(cms->arena, mark));
+ save_port_err() {
+ PORT_ArenaRelease(cms->arena, mark);
+ }
cmsreterr(-1, cms, "could not encode SignedData");
}
@@ -391,7 +406,9 @@ generate_authvar_signed_data(cms_context *cms, SECItem *sdp)
SECItem wrapper = { 0, };
if (SEC_ASN1EncodeItem(cms->arena, &wrapper, &sdw,
ContentInfoTemplate) == NULL) {
- save_port_err(PORT_ArenaRelease(cms->arena, mark));
+ save_port_err() {
+ PORT_ArenaRelease(cms->arena, mark);
+ }
cmsreterr(-1, cms, "could not encode SignedData");
}
@@ -399,3 +416,5 @@ generate_authvar_signed_data(cms_context *cms, SECItem *sdp)
PORT_ArenaUnmark(cms->arena, mark);
return 0;
}
+
+// vim:fenc=utf-8:tw=75:noet
diff --git a/src/cms_common.h b/src/cms_common.h
index c2b5981ba66..266fa224be0 100644
--- a/src/cms_common.h
+++ b/src/cms_common.h
@@ -19,21 +19,20 @@
#ifndef CMS_COMMON_H
#define CMS_COMMON_H 1
-#include <errno.h>
#include <cert.h>
#include <secpkcs7.h>
+
+#include <errno.h>
#include <signal.h>
#include <stdarg.h>
#include <syslog.h>
#include <time.h>
#include <unistd.h>
-#define save_port_err(x) \
- ({ \
- int __saved_errno = PORT_GetError(); \
- x; \
- PORT_SetError(__saved_errno); \
- })
+#include "util.h"
+
+#define save_port_err() \
+ for (error_t saved_errno_0_ = 0, saved_errno_1_ = PORT_GetError(); saved_errno_0_ < 1; saved_errno_0_++, PORT_SetError(saved_errno_1_))
#define cmserr(rv, cms, fmt, args...) ({ \
(cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt ": %s", \
@@ -173,3 +172,4 @@ typedef struct {
} secuPWData;
#endif /* CMS_COMMON_H */
+// vim:fenc=utf-8:tw=75:noet
--
2.29.2

View file

@ -0,0 +1,71 @@
From 03e2f49111fb846254f73ba9a2cce29ea13d3a99 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Fri, 17 May 2019 14:06:04 -0400
Subject: [PATCH 17/42] Make for_each_cert(cl, iter) for certificate list
traversal.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/cms_common.c | 18 ++++++++----------
src/cms_common.h | 3 +++
2 files changed, 11 insertions(+), 10 deletions(-)
diff --git a/src/cms_common.c b/src/cms_common.c
index 9218f69ef9e..75a95f053a2 100644
--- a/src/cms_common.c
+++ b/src/cms_common.c
@@ -614,20 +614,20 @@ find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
}
CERTCertListNode *node = NULL;
- for (node = CERT_LIST_HEAD(certlist); !CERT_LIST_END(node,certlist);
- node = CERT_LIST_NEXT(node)) {
- if (!strcmp(node->cert->subjectName, name))
+ for_each_cert(certlist, tmpnode) {
+ if (!strcmp(tmpnode->cert->subjectName, name)) {
+ node = tmpnode;
break;
+ }
}
/* If we're looking up the issuer of some cert, and the issuer isn't
* in the database, we'll get back what is essentially a template
* that's in NSS's cache waiting to be filled out. We can't use that,
* it'll just cause CERT_DupCertificate() to segfault. */
- if (CERT_LIST_END(node, certlist)
- || !node->cert || !node->cert->derCert.data
- || !node->cert->derCert.len
- || !node->cert->derIssuer.data
- || !node->cert->derIssuer.len) {
+ if (!node || !node->cert || !node->cert->derCert.data
+ || !node->cert->derCert.len
+ || !node->cert->derIssuer.data
+ || !node->cert->derIssuer.len) {
PK11_DestroySlotListElement(slots, &psle);
PK11_FreeSlotList(slots);
CERT_DestroyCertList(certlist);
@@ -635,8 +635,6 @@ find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
return -1;
}
-
-
*cert = CERT_DupCertificate(node->cert);
PK11_DestroySlotListElement(slots, &psle);
diff --git a/src/cms_common.h b/src/cms_common.h
index 266fa224be0..b0dc12fc3ab 100644
--- a/src/cms_common.h
+++ b/src/cms_common.h
@@ -34,6 +34,9 @@
#define save_port_err() \
for (error_t saved_errno_0_ = 0, saved_errno_1_ = PORT_GetError(); saved_errno_0_ < 1; saved_errno_0_++, PORT_SetError(saved_errno_1_))
+#define for_each_cert(cl, node) \
+ for (CERTCertListNode *node = CERT_LIST_HEAD(cl); !CERT_LIST_END(node, cl); node = CERT_LIST_NEXT(node))
+
#define cmserr(rv, cms, fmt, args...) ({ \
(cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt ": %s", \
__FILE__, __func__, __LINE__, ## args, \
--
2.29.2

View file

@ -0,0 +1,266 @@
From fc554b55d45a552982ba9949645e407231f06748 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 21 May 2019 13:54:37 -0400
Subject: [PATCH 18/42] file_pe: make most of our input and output checkers be
generated
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/file_pe.c | 237 ++++++++++++--------------------------------------
1 file changed, 57 insertions(+), 180 deletions(-)
diff --git a/src/file_pe.c b/src/file_pe.c
index 0555c28ebff..fcac6292d94 100644
--- a/src/file_pe.c
+++ b/src/file_pe.c
@@ -118,190 +118,67 @@ open_output(pesign_context *ctx)
Pe_Cmd cmd = ctx->outfd == STDOUT_FILENO ? PE_C_RDWR : PE_C_RDWR_MMAP;
ctx->outpe = pe_begin(ctx->outfd, cmd, NULL);
- if (!ctx->outpe) {
- fprintf(stderr, "pesign: could not load output file: %s\n",
- pe_errmsg(pe_errno()));
- exit(1);
- }
+ conderrx(!ctx->outpe, 1, "could not load output file \"%s\": %s",
+ ctx->outfile, pe_errmsg(pe_errno()));
pe_clearcert(ctx->outpe);
}
-static void
-open_rawsig_input(pesign_context *ctx)
-{
- if (!ctx->rawsig) {
- fprintf(stderr, "pesign: No input file specified.\n");
- exit(1);
- }
-
- ctx->rawsigfd = open(ctx->rawsig, O_RDONLY|O_CLOEXEC);
- if (ctx->rawsigfd < 0) {
- fprintf(stderr, "pesign: Error opening raw signature for input:"
- " %m\n");
- exit(1);
- }
-}
-
-static void
-close_rawsig_input(pesign_context *ctx)
-{
- close(ctx->rawsigfd);
- ctx->rawsigfd = -1;
-}
-
-static void
-open_sattr_input(pesign_context *ctx)
-{
- if (!ctx->insattrs) {
- fprintf(stderr, "pesign: No input file specified.\n");
- exit(1);
- }
-
- ctx->insattrsfd = open(ctx->insattrs, O_RDONLY|O_CLOEXEC);
- if (ctx->insattrsfd < 0) {
- fprintf(stderr, "pesign: Error opening signed attributes "
- "for input: %m\n");
- exit(1);
- }
-}
-
-static void
-close_sattr_input(pesign_context *ctx)
-{
- close(ctx->insattrsfd);
- ctx->insattrsfd = -1;
-}
-
-static void
-open_sattr_output(pesign_context *ctx)
-{
- if (!ctx->outsattrs) {
- fprintf(stderr, "pesign: No output file specified.\n");
- exit(1);
- }
-
- if (access(ctx->outsattrs, F_OK) == 0 && ctx->force == 0) {
- fprintf(stderr, "pesign: \"%s\" exists and --force "
- "was not given.\n", ctx->outsattrs);
- exit(1);
- }
-
- ctx->outsattrsfd = open(ctx->outsattrs,
- O_RDWR|O_CREAT|O_TRUNC|O_CLOEXEC,
- ctx->outmode);
- if (ctx->outsattrsfd < 0) {
- fprintf(stderr, "pesign: Error opening signed attributes "
- "for output: %m\n");
- exit(1);
- }
-}
-
-static void
-close_sattr_output(pesign_context *ctx)
-{
- close(ctx->outsattrsfd);
- ctx->outsattrsfd = -1;
-}
-
-static void
-open_sig_input(pesign_context *ctx)
-{
- if (!ctx->insig) {
- fprintf(stderr, "pesign: No input file specified.\n");
- exit(1);
- }
-
- ctx->insigfd = open(ctx->insig, O_RDONLY|O_CLOEXEC);
- if (ctx->insigfd < 0) {
- fprintf(stderr, "pesign: Error opening signature for input: "
- "%m\n");
- exit(1);
- }
-}
-
-static void
-close_sig_input(pesign_context *ctx)
-{
- close(ctx->insigfd);
- ctx->insigfd = -1;
-}
-
-static void
-open_sig_output(pesign_context *ctx)
-{
- if (!ctx->outsig) {
- fprintf(stderr, "pesign: No output file specified.\n");
- exit(1);
- }
-
- if (access(ctx->outsig, F_OK) == 0 && ctx->force == 0) {
- fprintf(stderr, "pesign: \"%s\" exists and --force "
- "was not given.\n", ctx->outsig);
- exit(1);
- }
-
- ctx->outsigfd = open(ctx->outsig, O_RDWR|O_CREAT|O_TRUNC|O_CLOEXEC,
- ctx->outmode);
- if (ctx->outsigfd < 0) {
- fprintf(stderr, "pesign: Error opening signature for output: "
- "%m\n");
- exit(1);
- }
-}
-
-static void
-close_sig_output(pesign_context *ctx)
-{
- close(ctx->outsigfd);
- ctx->outsigfd = -1;
-}
-
-static void
-open_pubkey_output(pesign_context *ctx)
-{
- if (!ctx->outkey) {
- fprintf(stderr, "pesign: No output file specified.\n");
- exit(1);
- }
-
- if (access(ctx->outkey, F_OK) == 0 && ctx->force == 0) {
- fprintf(stderr, "pesign: \"%s\" exists and --force "
- "was not given.\n", ctx->outkey);
- exit(1);
- }
-
- ctx->outkeyfd = open(ctx->outkey, O_RDWR|O_CREAT|O_TRUNC|O_CLOEXEC,
- ctx->outmode);
- if (ctx->outkeyfd < 0) {
- fprintf(stderr, "pesign: Error opening pubkey for output: "
- "%m\n");
- exit(1);
- }
-}
-
-static void
-open_cert_output(pesign_context *ctx)
-{
- if (!ctx->outcert) {
- fprintf(stderr, "pesign: No output file specified.\n");
- exit(1);
- }
-
- if (access(ctx->outcert, F_OK) == 0 && ctx->force == 0) {
- fprintf(stderr, "pesign: \"%s\" exists and --force "
- "was not given.\n", ctx->outcert);
- exit(1);
- }
-
- ctx->outcertfd = open(ctx->outcert, O_RDWR|O_CREAT|O_TRUNC|O_CLOEXEC,
- ctx->outmode);
- if (ctx->outcertfd < 0) {
- fprintf(stderr, "pesign: Error opening certificate for output: "
- "%m\n");
- exit(1);
- }
-}
+#define define_input_file(fname, name, descr) \
+ static void \
+ CAT3(open_, fname, _input)(pesign_context *ctx) \
+ { \
+ conderrx(!ctx->name, 1, \
+ "No input file specified for %s", \
+ descr); \
+ ctx->CAT(name, fd) = \
+ open(ctx->name, O_RDONLY|O_CLOEXEC); \
+ conderr(ctx->CAT(name, fd) < 0, 1, \
+ "Error opening %s file \"%s\" for input", \
+ descr, ctx->name); \
+ } \
+ static void \
+ CAT3(close_, fname, _input)(pesign_context *ctx) \
+ { \
+ close(ctx->CAT(name, fd)); \
+ ctx->CAT(name, fd) = -1; \
+ }
+
+#define define_output_file(fname, name, descr) \
+ static void \
+ CAT3(open_, fname, _output)(pesign_context *ctx) \
+ { \
+ conderrx(!ctx->name, 1, \
+ "No output file specified for %s.", \
+ descr); \
+ \
+ if (access(ctx->name, F_OK) == 0 && ctx->force == 0) \
+ errx(1, \
+ "\"%s\" exists and --force was not given.",\
+ ctx->name); \
+ \
+ ctx->CAT(name, fd) = \
+ open(ctx->name, \
+ O_RDWR|O_CREAT|O_TRUNC|O_CLOEXEC, \
+ ctx->outmode); \
+ conderr(ctx->CAT(name, fd) < 0, 1, \
+ "Error opening %s file \"%s\" for output", \
+ descr, ctx->name); \
+ } \
+ static void \
+ CAT3(close_, fname, _output)(pesign_context *ctx) \
+ { \
+ close(ctx->CAT(name,fd)); \
+ ctx->CAT(name,fd) = -1; \
+ }
+
+define_input_file(rawsig, rawsig, "raw signature");
+define_input_file(sattr, insattrs, "signed attributes");
+define_output_file(sattr, outsattrs, "signed attributes");
+define_input_file(sig, insig, "signature");
+define_output_file(sig, outsig, "signature");
+define_output_file(pubkey, outkey, "pubkey");
+define_output_file(cert, outcert, "certificate");
static void
check_inputs(pesign_context *ctx)
--
2.29.2

View file

@ -0,0 +1,275 @@
From 61bdc2689de3ab4f3960bee9a1ac7c63386cf727 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 21 May 2019 14:04:30 -0400
Subject: [PATCH 19/42] file_pe: user err() errx() etc.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/file_pe.c | 146 +++++++++++++++-----------------------------------
1 file changed, 44 insertions(+), 102 deletions(-)
diff --git a/src/file_pe.c b/src/file_pe.c
index fcac6292d94..ad076eba961 100644
--- a/src/file_pe.c
+++ b/src/file_pe.c
@@ -29,36 +29,23 @@
static void
open_input(pesign_context *ctx)
{
- if (!ctx->infile) {
- fprintf(stderr, "pesign: No input file specified.\n");
- exit(1);
- }
+ conderrx(!ctx->infile, 1, "No input file specified.");
struct stat statbuf;
ctx->infd = open(ctx->infile, O_RDONLY|O_CLOEXEC);
stat(ctx->infile, &statbuf);
ctx->outmode = statbuf.st_mode;
- if (ctx->infd < 0) {
- fprintf(stderr, "pesign: Error opening input: %m\n");
- exit(1);
- }
+ conderr(ctx->infd < 0, 1, "Error opening input");
Pe_Cmd cmd = ctx->infd == STDIN_FILENO ? PE_C_READ : PE_C_READ_MMAP;
ctx->inpe = pe_begin(ctx->infd, cmd, NULL);
- if (!ctx->inpe) {
- fprintf(stderr, "pesign: could not load input file: %s\n",
- pe_errmsg(pe_errno()));
- exit(1);
- }
+ conderrx(!ctx->inpe, 1, "could not load input file \"%s\": %s",
+ ctx->infile, pe_errmsg(pe_errno()));
int rc = parse_signatures(&ctx->cms_ctx->signatures,
&ctx->cms_ctx->num_signatures, ctx->inpe);
- if (rc < 0) {
- fprintf(stderr, "pesign: could not parse signature list in "
- "EFI binary\n");
- exit(1);
- }
+ conderrx(rc < 0, 1, "could not parse signature list in EFI binary");
}
static void
@@ -89,23 +76,16 @@ close_output(pesign_context *ctx)
static void
open_output(pesign_context *ctx)
{
- if (!ctx->outfile) {
- fprintf(stderr, "pesign: No output file specified.\n");
- exit(1);
- }
+ conderrx(!ctx->outfile, 1, "No output file specified.");
- if (access(ctx->outfile, F_OK) == 0 && ctx->force == 0) {
- fprintf(stderr, "pesign: \"%s\" exists and --force was "
- "not given.\n", ctx->outfile);
- exit(1);
- }
+ if (access(ctx->outfile, F_OK) == 0 && ctx->force == 0)
+ errx(1, "\"%s\" exists and --force was not given.",
+ ctx->outfile);
ctx->outfd = open(ctx->outfile, O_RDWR|O_CREAT|O_TRUNC|O_CLOEXEC,
ctx->outmode);
- if (ctx->outfd < 0) {
- fprintf(stderr, "pesign: Error opening output: %m\n");
- exit(1);
- }
+ conderr(ctx->outfd < 0, 1, "Error opening \"%s\" for output",
+ ctx->outfile);
size_t size;
char *addr;
@@ -119,7 +99,7 @@ open_output(pesign_context *ctx)
Pe_Cmd cmd = ctx->outfd == STDOUT_FILENO ? PE_C_RDWR : PE_C_RDWR_MMAP;
ctx->outpe = pe_begin(ctx->outfd, cmd, NULL);
conderrx(!ctx->outpe, 1, "could not load output file \"%s\": %s",
- ctx->outfile, pe_errmsg(pe_errno()));
+ ctx->outfile, pe_errmsg(pe_errno()));
pe_clearcert(ctx->outpe);
}
@@ -183,21 +163,11 @@ define_output_file(cert, outcert, "certificate");
static void
check_inputs(pesign_context *ctx)
{
- if (!ctx->infile) {
- fprintf(stderr, "pesign: No input file specified.\n");
- exit(1);
- }
+ conderrx(!ctx->infile, 1, "No input file specified.");
+ conderrx(!ctx->outfile, 1, "No output file specified.");
- if (!ctx->outfile) {
- fprintf(stderr, "pesign: No output file specified.\n");
- exit(1);
- }
-
- if (!strcmp(ctx->infile, ctx->outfile)) {
- fprintf(stderr, "pesign: in-place file editing "
- "is not yet supported\n");
- exit(1);
- }
+ conderrx(!strcmp(ctx->infile, ctx->outfile), 1,
+ "in-place file editing is not yet supported.");
}
static void
@@ -232,12 +202,8 @@ pe_handle_action(pesign_context *ctxp, int action, int padding)
case IMPORT_RAW_SIGNATURE|IMPORT_SATTRS:
check_inputs(ctxp);
rc = find_certificate(ctxp->cms_ctx, 0);
- if (rc < 0) {
- fprintf(stderr, "pesign: Could not find "
- "certificate %s\n",
- ctxp->cms_ctx->certname);
- exit(1);
- }
+ conderrx(rc < 0, 1, "Could not find certificate %s\n",
+ ctxp->cms_ctx->certname);
open_rawsig_input(ctxp);
open_sattr_input(ctxp);
import_raw_signature(ctxp);
@@ -266,10 +232,8 @@ pe_handle_action(pesign_context *ctxp, int action, int padding)
/* add a signature from a file */
case IMPORT_SIGNATURE:
check_inputs(ctxp);
- if (ctxp->signum > ctxp->cms_ctx->num_signatures + 1) {
- fprintf(stderr, "Invalid signature number.\n");
- exit(1);
- }
+ conderrx(ctxp->signum > ctxp->cms_ctx->num_signatures + 1,
+ 1, "Invalid signature number.");
open_input(ctxp);
open_output(ctxp);
close_input(ctxp);
@@ -285,23 +249,15 @@ pe_handle_action(pesign_context *ctxp, int action, int padding)
break;
case EXPORT_PUBKEY:
rc = find_certificate(ctxp->cms_ctx, 1);
- if (rc < 0) {
- fprintf(stderr, "pesign: Could not find "
- "certificate %s\n",
- ctxp->cms_ctx->certname);
- exit(1);
- }
+ conderrx(rc < 0, 1, "Could not find certificate %s",
+ ctxp->cms_ctx->certname);
open_pubkey_output(ctxp);
export_pubkey(ctxp);
break;
case EXPORT_CERT:
rc = find_certificate(ctxp->cms_ctx, 0);
- if (rc < 0) {
- fprintf(stderr, "pesign: Could not find "
- "certificate %s\n",
- ctxp->cms_ctx->certname);
- exit(1);
- }
+ conderrx(rc < 0, 1, "Could not find certificate %s",
+ ctxp->cms_ctx->certname);
open_cert_output(ctxp);
export_cert(ctxp);
break;
@@ -309,17 +265,12 @@ pe_handle_action(pesign_context *ctxp, int action, int padding)
case EXPORT_SIGNATURE:
open_input(ctxp);
open_sig_output(ctxp);
- if (ctxp->signum > ctxp->cms_ctx->num_signatures) {
- fprintf(stderr, "Invalid signature number.\n");
- exit(1);
- }
+ conderrx(ctxp->signum > ctxp->cms_ctx->num_signatures,
+ 1, "Invalid signature number.");
if (ctxp->signum < 0)
ctxp->signum = 0;
- if (ctxp->signum >= ctxp->cms_ctx->num_signatures) {
- fprintf(stderr, "No valid signature #%d.\n",
- ctxp->signum);
- exit(1);
- }
+ conderrx(ctxp->signum >= ctxp->cms_ctx->num_signatures,
+ 1, "No valid signature #%d.", ctxp->signum);
memcpy(&ctxp->cms_ctx->newsig,
ctxp->cms_ctx->signatures[ctxp->signum],
sizeof (ctxp->cms_ctx->newsig));
@@ -335,14 +286,12 @@ pe_handle_action(pesign_context *ctxp, int action, int padding)
open_input(ctxp);
open_output(ctxp);
close_input(ctxp);
- if (ctxp->signum < 0 ||
- ctxp->signum >=
- ctxp->cms_ctx->num_signatures) {
- fprintf(stderr, "Invalid signature number %d. "
- "Must be between 0 and %d.\n",
- ctxp->signum,
- ctxp->cms_ctx->num_signatures - 1);
- exit(1);
+ if(ctxp->signum < 0 ||
+ ctxp->signum >= ctxp->cms_ctx->num_signatures) {
+ warnx("Invalid signature number %d.",
+ ctxp->signum);
+ errx(1, "Must be between 0 and %d.",
+ ctxp->cms_ctx->num_signatures - 1);
}
remove_signature(ctxp);
close_output(ctxp);
@@ -365,12 +314,8 @@ pe_handle_action(pesign_context *ctxp, int action, int padding)
/* generate a signature and save it in a separate file */
case EXPORT_SIGNATURE|GENERATE_SIGNATURE:
rc = find_certificate(ctxp->cms_ctx, 1);
- if (rc < 0) {
- fprintf(stderr, "pesign: Could not find "
- "certificate %s\n",
- ctxp->cms_ctx->certname);
- exit(1);
- }
+ conderrx(rc < 0, 1, "Could not find certificate %s",
+ ctxp->cms_ctx->certname);
open_input(ctxp);
open_sig_output(ctxp);
generate_digest(ctxp->cms_ctx, ctxp->inpe, 1);
@@ -381,16 +326,10 @@ pe_handle_action(pesign_context *ctxp, int action, int padding)
case IMPORT_SIGNATURE|GENERATE_SIGNATURE:
check_inputs(ctxp);
rc = find_certificate(ctxp->cms_ctx, 1);
- if (rc < 0) {
- fprintf(stderr, "pesign: Could not find "
- "certificate %s\n",
- ctxp->cms_ctx->certname);
- exit(1);
- }
- if (ctxp->signum > ctxp->cms_ctx->num_signatures + 1) {
- fprintf(stderr, "Invalid signature number.\n");
- exit(1);
- }
+ conderrx(rc < 0, 1, "Could not find certificate %s",
+ ctxp->cms_ctx->certname);
+ conderrx(ctxp->signum > ctxp->cms_ctx->num_signatures + 1,
+ 1, "Invalid signature number.");
open_input(ctxp);
open_output(ctxp);
close_input(ctxp);
@@ -404,7 +343,8 @@ pe_handle_action(pesign_context *ctxp, int action, int padding)
close_output(ctxp);
break;
default:
- fprintf(stderr, "Incompatible flags (0x%08x): ", action);
+ fprintf(stderr, "%s: Incompatible flags (0x%08x): ",
+ program_invocation_short_name, action);
for (int i = 1; i < FLAG_LIST_END; i <<= 1) {
if (action & i)
print_flag_name(stderr, i);
@@ -413,3 +353,5 @@ pe_handle_action(pesign_context *ctxp, int action, int padding)
exit(1);
}
}
+
+// vim:fenc=utf-8:tw=75:noet
--
2.29.2

View file

@ -0,0 +1,165 @@
From 43d7021bc1a4d78cfaa8ad8a31c73058005e26ef Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 21 May 2019 14:45:24 -0400
Subject: [PATCH 20/42] pesign_kmod: user err() errx() etc.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/pesign_kmod.c | 80 +++++++++++++++--------------------------------
1 file changed, 26 insertions(+), 54 deletions(-)
diff --git a/src/pesign_kmod.c b/src/pesign_kmod.c
index 5d78131a69b..916ae52ebe2 100644
--- a/src/pesign_kmod.c
+++ b/src/pesign_kmod.c
@@ -122,6 +122,7 @@ import_sig_input(pesign_context *ctx)
{
unsigned char *map;
struct stat statbuf;
+ int rc;
if (!ctx->insig) {
fprintf(stderr, "pesign: No input file specified.\n");
@@ -135,23 +136,17 @@ import_sig_input(pesign_context *ctx)
exit(1);
}
- if (fstat(ctx->insigfd, &statbuf)) {
- fprintf(stderr, "pesign: Error on stat signature: %m\n");
- exit(1);
- }
+ rc = fstat(ctx->insigfd, &statbuf);
+ conderr(rc < 0, 1, "Could not fstat signature file \"%s\"",
+ ctx->insig);
/* Copy original module data */
map = mmap(NULL, ctx->inlength, PROT_READ, MAP_PRIVATE, ctx->infd, 0);
- if (map == MAP_FAILED) {
- fprintf(stderr, "pesign: Error mapping input: %m\n");
- exit(1);
- }
+ conderr(map == MAP_FAILED, 1, "Could not map kmod input");
- if (write_file(ctx->outfd, map, ctx->inlength) < 0) {
- fprintf(stderr, "pesign: failed to write module data: %m\n");
- exit(1);
- }
+ rc = write_file(ctx->outfd, map, ctx->inlength);
+ conderr(rc < 0, 1, "Failed to write module data");
munmap(map, ctx->inlength);
@@ -159,15 +154,11 @@ import_sig_input(pesign_context *ctx)
map = mmap(NULL, statbuf.st_size, PROT_READ, MAP_PRIVATE, ctx->insigfd,
0);
- if (map == MAP_FAILED) {
- fprintf(stderr, "pesign: failed to map signature: %m\n");
- exit(1);
- }
+ conderr(map == MAP_FAILED, 1, "Could not map signature input \"%s\"",
+ ctx->insig);
- if (write_file(ctx->outfd, map, statbuf.st_size) < 0) {
- fprintf(stderr, "pesign: Error writing output: %m\n");
- exit(1);
- }
+ rc = write_file(ctx->outfd, map, statbuf.st_size);
+ conderr(rc < 0, 1, "Error writing output");
munmap(map, statbuf.st_size);
}
@@ -180,20 +171,15 @@ handle_signing(pesign_context *ctx, int outfd, int attached)
ssize_t sig_len;
inmap = mmap(NULL, ctx->inlength, PROT_READ, MAP_PRIVATE, ctx->infd, 0);
- if (inmap == MAP_FAILED) {
- fprintf(stderr, "pesign: Error mapping input: %m\n");
- exit(1);
- }
+ conderrx(inmap == MAP_FAILED, 1, "Error mapping input kmod");
rc = kmod_generate_digest(ctx->cms_ctx, inmap, ctx->inlength);
if (rc < 0)
exit(1);
if (attached) {
- if (write_file(outfd, inmap, ctx->inlength) < 0) {
- fprintf(stderr, "pesign: failed to write module data: %m\n");
- exit(1);
- }
+ rc = write_file(outfd, inmap, ctx->inlength);
+ conderr(rc < 0, 1, "Failed to write module data");
}
munmap(inmap, ctx->inlength);
@@ -214,16 +200,10 @@ kmod_handle_action(pesign_context *ctxp, int action)
/* generate a signature and embed it in the module */
case IMPORT_SIGNATURE|GENERATE_SIGNATURE:
rc = find_certificate(ctxp->cms_ctx, 1);
- if (rc < 0) {
- fprintf(stderr, "pesign: Could not find "
- "certificate %s\n",
- ctxp->cms_ctx->certname);
- exit(1);
- }
- if (ctxp->signum > ctxp->cms_ctx->num_signatures + 1) {
- fprintf(stderr, "Invalid signature number.\n");
- exit(1);
- }
+ conderrx(rc < 0, 1, "Could not find certificate \"%s\"",
+ ctxp->cms_ctx->certname);
+ conderrx(ctxp->signum > ctxp->cms_ctx->num_signatures + 1,
+ 1, "Invalid signature number.");
open_input(ctxp);
open_output(ctxp);
@@ -235,16 +215,10 @@ kmod_handle_action(pesign_context *ctxp, int action)
/* generate a signature and save it in a separate file */
case EXPORT_SIGNATURE|GENERATE_SIGNATURE:
rc = find_certificate(ctxp->cms_ctx, 1);
- if (rc < 0) {
- fprintf(stderr, "pesign: Could not find "
- "certificate %s\n",
- ctxp->cms_ctx->certname);
- exit(1);
- }
- if (ctxp->signum > ctxp->cms_ctx->num_signatures + 1) {
- fprintf(stderr, "Invalid signature number.\n");
- exit(1);
- }
+ conderrx(rc < 0, 1, "Could not find certificate \"%s\"",
+ ctxp->cms_ctx->certname);
+ conderrx(ctxp->signum > ctxp->cms_ctx->num_signatures + 1,
+ 1, "Invalid signature number.");
open_input(ctxp);
open_sig_output(ctxp);
@@ -255,10 +229,8 @@ kmod_handle_action(pesign_context *ctxp, int action)
/* add a signature from a file */
case IMPORT_SIGNATURE:
- if (ctxp->signum > ctxp->cms_ctx->num_signatures + 1) {
- fprintf(stderr, "Invalid signature number.\n");
- exit(1);
- }
+ conderrx(ctxp->signum > ctxp->cms_ctx->num_signatures + 1,
+ 1, "Invalid signature number.");
open_input(ctxp);
open_output(ctxp);
import_sig_input(ctxp);
@@ -267,8 +239,8 @@ kmod_handle_action(pesign_context *ctxp, int action)
break;
default:
- fprintf(stderr, "Incompatible flags (0x%08x): ",
- action);
+ fprintf(stderr, "%s: Incompatible flags (0x%08x): ",
+ program_invocation_short_name, action);
for (int i = 1; i < FLAG_LIST_END; i <<= 1) {
if (action & i)
print_flag_name(stderr, i);
--
2.29.2

View file

@ -0,0 +1,411 @@
From 9209c1e45ca7fa0c821f0da57dd6e1ff746de267 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 21 May 2019 14:29:24 -0400
Subject: [PATCH 21/42] share input/output checker macros between pesign_kmod
and file_pe
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/file_pe.c | 48 ---------------
src/pesign.c | 2 +
src/pesign_kmod.c | 142 ++++++++-----------------------------------
src/pesign_context.h | 20 ++++--
src/util.h | 65 ++++++++++++++++++++
5 files changed, 110 insertions(+), 167 deletions(-)
diff --git a/src/file_pe.c b/src/file_pe.c
index ad076eba961..31672c68f79 100644
--- a/src/file_pe.c
+++ b/src/file_pe.c
@@ -104,54 +104,6 @@ open_output(pesign_context *ctx)
pe_clearcert(ctx->outpe);
}
-#define define_input_file(fname, name, descr) \
- static void \
- CAT3(open_, fname, _input)(pesign_context *ctx) \
- { \
- conderrx(!ctx->name, 1, \
- "No input file specified for %s", \
- descr); \
- ctx->CAT(name, fd) = \
- open(ctx->name, O_RDONLY|O_CLOEXEC); \
- conderr(ctx->CAT(name, fd) < 0, 1, \
- "Error opening %s file \"%s\" for input", \
- descr, ctx->name); \
- } \
- static void \
- CAT3(close_, fname, _input)(pesign_context *ctx) \
- { \
- close(ctx->CAT(name, fd)); \
- ctx->CAT(name, fd) = -1; \
- }
-
-#define define_output_file(fname, name, descr) \
- static void \
- CAT3(open_, fname, _output)(pesign_context *ctx) \
- { \
- conderrx(!ctx->name, 1, \
- "No output file specified for %s.", \
- descr); \
- \
- if (access(ctx->name, F_OK) == 0 && ctx->force == 0) \
- errx(1, \
- "\"%s\" exists and --force was not given.",\
- ctx->name); \
- \
- ctx->CAT(name, fd) = \
- open(ctx->name, \
- O_RDWR|O_CREAT|O_TRUNC|O_CLOEXEC, \
- ctx->outmode); \
- conderr(ctx->CAT(name, fd) < 0, 1, \
- "Error opening %s file \"%s\" for output", \
- descr, ctx->name); \
- } \
- static void \
- CAT3(close_, fname, _output)(pesign_context *ctx) \
- { \
- close(ctx->CAT(name,fd)); \
- ctx->CAT(name,fd) = -1; \
- }
-
define_input_file(rawsig, rawsig, "raw signature");
define_input_file(sattr, insattrs, "signed attributes");
define_output_file(sattr, outsattrs, "signed attributes");
diff --git a/src/pesign.c b/src/pesign.c
index 95a832df9e4..d2f3f221df0 100644
--- a/src/pesign.c
+++ b/src/pesign.c
@@ -462,3 +462,5 @@ main(int argc, char *argv[])
return (rc < 0);
}
+
+// vim:fenc=utf-8:tw=75:noet
diff --git a/src/pesign_kmod.c b/src/pesign_kmod.c
index 916ae52ebe2..a9799b83fa8 100644
--- a/src/pesign_kmod.c
+++ b/src/pesign_kmod.c
@@ -26,96 +26,10 @@
#include "pesign_standalone.h"
#include "file_kmod.h"
-static void
-open_input(pesign_context *ctx)
-{
- struct stat statbuf;
-
- if (!ctx->infile) {
- fprintf(stderr, "pesign: No input file specified.\n");
- exit(1);
- }
-
- ctx->infd = open(ctx->infile, O_RDONLY|O_CLOEXEC);
- if (ctx->infd < 0) {
- fprintf(stderr, "pesign: Error opening input: %m\n");
- exit(1);
- }
-
- if (fstat(ctx->infd, &statbuf)) {
- fprintf(stderr, "pesign: Error on stat input: %m\n");
- exit(1);
- }
-
- ctx->outmode = statbuf.st_mode;
- ctx->inlength = statbuf.st_size;
-}
-
-static void
-close_input(pesign_context *ctx)
-{
- close(ctx->infd);
- ctx->infd = -1;
-}
-
-static void
-open_output(pesign_context *ctx)
-{
- if (!ctx->outfile) {
- fprintf(stderr, "pesign: No output file specified.\n");
- exit(1);
- }
-
- if (access(ctx->outfile, F_OK) == 0 && ctx->force == 0) {
- fprintf(stderr, "pesign: \"%s\" exists and --force was "
- "not given.\n", ctx->outfile);
- exit(1);
- }
-
- ctx->outfd = open(ctx->outfile, O_RDWR|O_CREAT|O_TRUNC|O_CLOEXEC,
- ctx->outmode);
- if (ctx->outfd < 0) {
- fprintf(stderr, "pesign: Error opening output: %m\n");
- exit(1);
- }
-}
-
-static void
-close_output(pesign_context *ctx)
-{
- close(ctx->outfd);
- ctx->outfd = -1;
-}
-
-static void
-open_sig_output(pesign_context *ctx)
-{
- if (!ctx->outsig) {
- fprintf(stderr, "pesign: No output file specified.\n");
- exit(1);
- }
-
- if (access(ctx->outsig, F_OK) == 0 && ctx->force == 0) {
- fprintf(stderr, "pesign: \"%s\" exists and --force "
- "was not given.\n", ctx->outsig);
- exit(1);
- }
-
- ctx->outsigfd = open(ctx->outsig, O_RDWR|O_CREAT|O_TRUNC|O_CLOEXEC,
- ctx->outmode);
- if (ctx->outsigfd < 0) {
- fprintf(stderr, "pesign: Error opening signature for output: "
- "%m\n");
- exit(1);
- }
-}
-
-static void
-close_sig_output(pesign_context *ctx)
-{
- close(ctx->outsigfd);
- ctx->outsigfd = -1;
-}
+define_input_file(kmod, inkmod, "kmod");
+define_output_file(kmod, outkmod, "kmod");
+define_output_file(sig, outsig, "signature");
+define_input_file(sig, insig, "signature");
static void
import_sig_input(pesign_context *ctx)
@@ -124,17 +38,7 @@ import_sig_input(pesign_context *ctx)
struct stat statbuf;
int rc;
- if (!ctx->insig) {
- fprintf(stderr, "pesign: No input file specified.\n");
- exit(1);
- }
-
- ctx->insigfd = open(ctx->insig, O_RDONLY|O_CLOEXEC);
- if (ctx->insigfd < 0) {
- fprintf(stderr, "pesign: Error opening signature for input: "
- "%m\n");
- exit(1);
- }
+ open_sig_input(ctx);
rc = fstat(ctx->insigfd, &statbuf);
conderr(rc < 0, 1, "Could not fstat signature file \"%s\"",
@@ -143,10 +47,10 @@ import_sig_input(pesign_context *ctx)
/* Copy original module data */
map = mmap(NULL, ctx->inlength, PROT_READ, MAP_PRIVATE, ctx->infd, 0);
- conderr(map == MAP_FAILED, 1, "Could not map kmod input");
+ conderr(map == MAP_FAILED, 1, "Could not map kmod input file \"%s\"", ctx->inkmod);
rc = write_file(ctx->outfd, map, ctx->inlength);
- conderr(rc < 0, 1, "Failed to write module data");
+ conderr(rc < 0, 1, "Failed to write module data to \"%s\"", ctx->outkmod);
munmap(map, ctx->inlength);
@@ -171,7 +75,7 @@ handle_signing(pesign_context *ctx, int outfd, int attached)
ssize_t sig_len;
inmap = mmap(NULL, ctx->inlength, PROT_READ, MAP_PRIVATE, ctx->infd, 0);
- conderrx(inmap == MAP_FAILED, 1, "Error mapping input kmod");
+ conderr(inmap == MAP_FAILED, 1, "Could not map input kmod file \"%s\"", ctx->inkmod);
rc = kmod_generate_digest(ctx->cms_ctx, inmap, ctx->inlength);
if (rc < 0)
@@ -179,7 +83,7 @@ handle_signing(pesign_context *ctx, int outfd, int attached)
if (attached) {
rc = write_file(outfd, inmap, ctx->inlength);
- conderr(rc < 0, 1, "Failed to write module data");
+ conderr(rc < 0, 1, "Failed to write module data to \"%s\"", ctx->outkmod);
}
munmap(inmap, ctx->inlength);
@@ -205,11 +109,13 @@ kmod_handle_action(pesign_context *ctxp, int action)
conderrx(ctxp->signum > ctxp->cms_ctx->num_signatures + 1,
1, "Invalid signature number.");
- open_input(ctxp);
- open_output(ctxp);
+ open_kmod_input(ctxp);
+ proxy_fd_mode(ctxp->inkmodfd, ctxp->inkmod,
+ &ctxp->outmode, &ctxp->inlength);
+ open_kmod_output(ctxp);
handle_signing(ctxp, ctxp->outfd, 1);
- close_output(ctxp);
- close_input(ctxp);
+ close_kmod_output(ctxp);
+ close_kmod_input(ctxp);
break;
/* generate a signature and save it in a separate file */
@@ -220,22 +126,26 @@ kmod_handle_action(pesign_context *ctxp, int action)
conderrx(ctxp->signum > ctxp->cms_ctx->num_signatures + 1,
1, "Invalid signature number.");
- open_input(ctxp);
+ open_kmod_input(ctxp);
+ proxy_fd_mode(ctxp->inkmodfd, ctxp->inkmod,
+ &ctxp->outmode, &ctxp->inlength);
open_sig_output(ctxp);
handle_signing(ctxp, ctxp->outsigfd, 0);
close_sig_output(ctxp);
- close_input(ctxp);
+ close_kmod_input(ctxp);
break;
/* add a signature from a file */
case IMPORT_SIGNATURE:
conderrx(ctxp->signum > ctxp->cms_ctx->num_signatures + 1,
1, "Invalid signature number.");
- open_input(ctxp);
- open_output(ctxp);
+ open_kmod_input(ctxp);
+ proxy_fd_mode(ctxp->inkmodfd, ctxp->inkmod,
+ &ctxp->outmode, &ctxp->inlength);
+ open_kmod_output(ctxp);
import_sig_input(ctxp);
- close_input(ctxp);
- close_output(ctxp);
+ close_kmod_input(ctxp);
+ close_kmod_output(ctxp);
break;
default:
@@ -249,3 +159,5 @@ kmod_handle_action(pesign_context *ctxp, int action)
exit(1);
}
}
+
+// vim:fenc=utf-8:tw=75:noet
diff --git a/src/pesign_context.h b/src/pesign_context.h
index 8d8dfbd294e..45d6831aa7f 100644
--- a/src/pesign_context.h
+++ b/src/pesign_context.h
@@ -32,10 +32,22 @@ typedef enum {
} file_format;
typedef struct {
- int infd;
- int outfd;
- char *infile;
- char *outfile;
+ union {
+ int infd;
+ int inkmodfd;
+ };
+ union {
+ int outfd;
+ int outkmodfd;
+ };
+ union {
+ char *infile;
+ char *inkmod;
+ };
+ union {
+ char *outfile;
+ char *outkmod;
+ };
size_t inlength;
mode_t outmode;
diff --git a/src/util.h b/src/util.h
index 1b115a993f6..9b34f7b8886 100644
--- a/src/util.h
+++ b/src/util.h
@@ -24,6 +24,8 @@
#include <string.h>
#include <stdio.h>
#include <stdlib.h>
+#include <sys/types.h>
+#include <sys/stat.h>
#include <unistd.h>
#include <libdpe/pe.h>
@@ -207,4 +209,67 @@ content_is_empty(uint8_t *data, ssize_t len)
return 1;
}
+#define define_input_file(fname, name, descr) \
+ static void \
+ CAT3(open_, fname, _input)(pesign_context *ctx) \
+ { \
+ conderrx(!ctx->name, 1, \
+ "No input file specified for %s", \
+ descr); \
+ ctx->CAT(name, fd) = \
+ open(ctx->name, O_RDONLY|O_CLOEXEC); \
+ conderr(ctx->CAT(name, fd) < 0, 1, \
+ "Error opening %s file \"%s\" for input", \
+ descr, ctx->name); \
+ } \
+ static void \
+ CAT3(close_, fname, _input)(pesign_context *ctx) \
+ { \
+ close(ctx->CAT(name, fd)); \
+ ctx->CAT(name, fd) = -1; \
+ }
+
+#define define_output_file(fname, name, descr) \
+ static void \
+ CAT3(open_, fname, _output)(pesign_context *ctx) \
+ { \
+ conderrx(!ctx->name, 1, \
+ "No output file specified for %s.", \
+ descr); \
+ \
+ if (access(ctx->name, F_OK) == 0 && ctx->force == 0) \
+ errx(1, \
+ "\"%s\" exists and --force was not given.",\
+ ctx->name); \
+ \
+ ctx->CAT(name, fd) = \
+ open(ctx->name, \
+ O_RDWR|O_CREAT|O_TRUNC|O_CLOEXEC, \
+ ctx->outmode); \
+ conderr(ctx->CAT(name, fd) < 0, 1, \
+ "Error opening %s file \"%s\" for output", \
+ descr, ctx->name); \
+ } \
+ static void \
+ CAT3(close_, fname, _output)(pesign_context *ctx) \
+ { \
+ close(ctx->CAT(name,fd)); \
+ ctx->CAT(name,fd) = -1; \
+ }
+
+static inline void
+proxy_fd_mode(int fd, char *infile, mode_t *outmode, size_t *inlength)
+{
+ struct stat statbuf;
+ int rc;
+
+ rc = fstat(fd, &statbuf);
+ conderr(rc < 0, 1, "Could not fstat \"%s\"", infile);
+ if (outmode)
+ *outmode = statbuf.st_mode;
+ if (inlength)
+ *inlength = statbuf.st_size;
+}
+
#endif /* PESIGN_UTIL_H */
+// vim:fenc=utf-8:tw=75:noet
--
2.29.2

View file

@ -0,0 +1,66 @@
From 1ec1a523216aa9b63120fa36c3732de3c4cbf546 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 16 Feb 2021 13:24:54 -0500
Subject: [PATCH 22/42] Make verbose work in efisiglist
Signed-off-by: Peter Jones <rpm-build>
---
src/efisiglist.c | 25 +++++++++++++++++++++++++
1 file changed, 25 insertions(+)
diff --git a/src/efisiglist.c b/src/efisiglist.c
index b91e15bfb7b..48ff89c5661 100644
--- a/src/efisiglist.c
+++ b/src/efisiglist.c
@@ -114,6 +114,15 @@ out_of_range:
return ret;
}
+static long *verbose;
+
+long verbosity(void)
+{
+ if (!verbose)
+ return 0;
+ return *verbose;
+}
+
int
main(int argc, char *argv[])
{
@@ -128,9 +137,12 @@ main(int argc, char *argv[])
int certfd = -1;
void *cert_data = NULL;
size_t cert_size = 0;
+ long esl_verbose = 0;
int add = 1;
+ verbose = &esl_verbose;
+
struct poptOption options[] = {
{.argInfo = POPT_ARG_INTL_DOMAIN,
.arg = "pesign" },
@@ -175,6 +187,19 @@ main(int argc, char *argv[])
.arg = &certfile,
.descrip = "certificate to add",
.argDescrip = "<certfile>" },
+ {.longName = "verbose",
+ .shortName = 'v',
+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL,
+ .arg = &esl_verbose,
+ .val = 1,
+ .descrip = "be more verbose" },
+ {.longName = "debug",
+ .shortName = '\0',
+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL,
+ .arg = &esl_verbose,
+ .val = 2,
+ .descrip = "be very verbose" },
+
POPT_AUTOALIAS
POPT_AUTOHELP
POPT_TABLEEND
--
2.29.2

View file

@ -0,0 +1,321 @@
From 8fc539b9712c0e736abfdd3b493d97f7107e91ec Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 28 Apr 2020 10:08:03 -0400
Subject: [PATCH 23/42] Make --verbose and --debug more similar across tools
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/authvar.c | 21 +++++++++++++++++++++
src/client.c | 18 ++++++++++++++++++
src/cms_pe_common.c | 6 ------
src/efikeygen.c | 21 +++++++++++++++++++++
src/pesigcheck.c | 18 +++++++++++++++++-
src/pesign.c | 19 ++++++++++++++++++-
src/authvar_context.h | 2 ++
src/pesigcheck_context.h | 2 +-
src/pesign_context.h | 2 +-
src/util.h | 14 +++++++++++++-
10 files changed, 112 insertions(+), 11 deletions(-)
diff --git a/src/authvar.c b/src/authvar.c
index f9a7dcef9f7..a6c3970e4dc 100644
--- a/src/authvar.c
+++ b/src/authvar.c
@@ -260,6 +260,15 @@ show_signature_support(void)
return 0;
}
+static long *verbose;
+
+long verbosity(void)
+{
+ if (!verbose)
+ return 0;
+ return *verbose;
+}
+
int
main(int argc, char *argv[])
{
@@ -370,6 +379,18 @@ main(int argc, char *argv[])
.arg = &ctx.cms_ctx->certname,
.descrip = "sign variable with certificate <nickname>",
.argDescrip = "<nickname>" },
+ {.longName = "verbose",
+ .shortName = 'v',
+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL,
+ .arg = &ctxp->verbose,
+ .val = 1,
+ .descrip = "be more verbose" },
+ {.longName = "debug",
+ .shortName = '\0',
+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL,
+ .arg = &ctxp->verbose,
+ .val = 2,
+ .descrip = "be very verbose" },
POPT_AUTOALIAS
POPT_AUTOHELP
POPT_TABLEEND
diff --git a/src/client.c b/src/client.c
index a4f1d1dbbe7..a00b20f5dde 100644
--- a/src/client.c
+++ b/src/client.c
@@ -600,6 +600,12 @@ oom:
return;
}
+static long verbose;
+long verbosity(void)
+{
+ return verbose;
+}
+
int
main(int argc, char *argv[])
{
@@ -687,6 +693,18 @@ main(int argc, char *argv[])
.arg = &pinfile,
.descrip = "read named file for pin information",
.argDescrip = "<pin file name>" },
+ {.longName = "verbose",
+ .shortName = 'v',
+ .argInfo = POPT_ARG_VAL,
+ .arg = &verbose,
+ .val = 1,
+ .descrip = "be more verbose" },
+ {.longName = "debug",
+ .shortName = '\0',
+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL,
+ .arg = &verbose,
+ .val = 2,
+ .descrip = "be very verbose" },
POPT_AUTOALIAS
POPT_AUTOHELP
POPT_TABLEEND
diff --git a/src/cms_pe_common.c b/src/cms_pe_common.c
index 05f72e4431a..00061804a78 100644
--- a/src/cms_pe_common.c
+++ b/src/cms_pe_common.c
@@ -42,12 +42,6 @@
#include <secerr.h>
#include <certt.h>
-#if 1
-#define dprintf(fmt, ...)
-#else
-#define dprintf(fmt, args...) printf(fmt, ## args)
-#endif
-
static int
check_pointer_and_size(Pe *pe, void *ptr, size_t size)
{
diff --git a/src/efikeygen.c b/src/efikeygen.c
index ac2ce45a420..b1cac4705e8 100644
--- a/src/efikeygen.c
+++ b/src/efikeygen.c
@@ -492,6 +492,13 @@ SEC_ASN1EncodeLongLong(PRArenaPool *poolp, SECItem *dest,
return dest;
}
+static long verbose = 0;
+
+long verbosity(void)
+{
+ return verbose;
+}
+
int main(int argc, char *argv[])
{
int is_ca = 0;
@@ -586,6 +593,18 @@ int main(int argc, char *argv[])
.arg = &serial_str,
.descrip = "Serial number (default: random)",
.argDescrip = "<serial>" },
+ {.longName = "verbose",
+ .shortName = 'v',
+ .argInfo = POPT_ARG_VAL,
+ .arg = &verbose,
+ .val = 1,
+ .descrip = "Be more verbose" },
+ {.longName = "debug",
+ .shortName = '\0',
+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL,
+ .arg = &verbose,
+ .val = 2,
+ .descrip = "Be very verbose" },
/* hidden things */
{.longName = "pubkey",
@@ -870,3 +889,5 @@ int main(int argc, char *argv[])
NSS_Shutdown();
return 0;
}
+
+// vim:fenc=utf-8:tw=75:noet
diff --git a/src/pesigcheck.c b/src/pesigcheck.c
index 961a32a6ad7..87d4960a9a9 100644
--- a/src/pesigcheck.c
+++ b/src/pesigcheck.c
@@ -386,6 +386,15 @@ callback(poptContext con UNUSED,
}
}
+static long *verbose;
+
+long verbosity(void)
+{
+ if (!verbose)
+ return 0;
+ return *verbose;
+}
+
int
main(int argc, char *argv[])
{
@@ -436,10 +445,16 @@ main(int argc, char *argv[])
.descrip = "return only; no text output." },
{.longName = "verbose",
.shortName = 'v',
- .argInfo = POPT_BIT_SET,
+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL,
.arg = &ctx.verbose,
.val = 1,
.descrip = "print reasons for success and failure." },
+ {.longName = "debug",
+ .shortName = '\0',
+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL,
+ .arg = &ctxp->verbose,
+ .val = 2,
+ .descrip = "be very verbose" },
{.longName = "no-system-db",
.shortName = 'n',
.argInfo = POPT_ARG_INT,
@@ -475,6 +490,7 @@ main(int argc, char *argv[])
fprintf(stderr, "pesigcheck: Could not initialize context: %m\n");
exit(1);
}
+ verbose = &ctxp->verbose;
optCon = poptGetContext("pesigcheck", argc, (const char **)argv,
options,0);
diff --git a/src/pesign.c b/src/pesign.c
index d2f3f221df0..854120c15c5 100644
--- a/src/pesign.c
+++ b/src/pesign.c
@@ -64,6 +64,15 @@ print_flag_name(FILE *f, int flag)
}
}
+static long *verbose;
+
+long verbosity(void)
+{
+ if (!verbose)
+ return 0;
+ return *verbose;
+}
+
int
main(int argc, char *argv[])
{
@@ -94,6 +103,7 @@ main(int argc, char *argv[])
fprintf(stderr, "Could not initialize context: %m\n");
exit(1);
}
+ verbose = &ctxp->verbose;
poptContext optCon;
struct poptOption options[] = {
@@ -234,10 +244,17 @@ main(int argc, char *argv[])
.descrip = "don't fork when daemonizing" },
{.longName = "verbose",
.shortName = 'v',
- .argInfo = POPT_ARG_VAL,
+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL,
.arg = &ctxp->verbose,
.val = 1,
+ .descrip = "be more verbose" },
+ {.longName = "debug",
+ .shortName = '\0',
+ .argInfo = POPT_ARG_VAL|POPT_ARG_LONG|POPT_ARGFLAG_OPTIONAL,
+ .arg = &ctxp->verbose,
+ .val = 2,
.descrip = "be very verbose" },
+
{.longName = "padding",
.shortName = 'P',
.argInfo = POPT_ARG_VAL,
diff --git a/src/authvar_context.h b/src/authvar_context.h
index e9250dd250f..13c18a988f4 100644
--- a/src/authvar_context.h
+++ b/src/authvar_context.h
@@ -20,6 +20,8 @@
#define AUTHVAR_CONTEXT_H 1
typedef struct {
+ long verbose;
+
char *namespace;
efi_guid_t guid;
char *name;
diff --git a/src/pesigcheck_context.h b/src/pesigcheck_context.h
index aec415e0cbe..fa72439c875 100644
--- a/src/pesigcheck_context.h
+++ b/src/pesigcheck_context.h
@@ -61,7 +61,7 @@ typedef struct pesigcheck_context {
Pe *inpe;
int quiet;
- int verbose;
+ long verbose;
hashlist *hashes;
diff --git a/src/pesign_context.h b/src/pesign_context.h
index 45d6831aa7f..0af044d92b4 100644
--- a/src/pesign_context.h
+++ b/src/pesign_context.h
@@ -52,7 +52,7 @@ typedef struct {
mode_t outmode;
int force;
- int verbose;
+ long verbose;
char *rawsig;
int rawsigfd;
diff --git a/src/util.h b/src/util.h
index 9b34f7b8886..21a846c10ee 100644
--- a/src/util.h
+++ b/src/util.h
@@ -24,8 +24,9 @@
#include <string.h>
#include <stdio.h>
#include <stdlib.h>
-#include <sys/types.h>
#include <sys/stat.h>
+#include <sys/time.h>
+#include <sys/types.h>
#include <unistd.h>
#include <libdpe/pe.h>
@@ -271,5 +272,16 @@ proxy_fd_mode(int fd, char *infile, mode_t *outmode, size_t *inlength)
*inlength = statbuf.st_size;
}
+extern long verbosity(void);
+
+#define dprintf_(tv, file, func, line, fmt, args...) ({struct timeval tv; gettimeofday(&tv, NULL); warnx("%ld.%lu %s:%s():%d: " fmt, tv.tv_sec, tv.tv_usec, file, func, line, ##args); })
+#if defined(PESIGN_DEBUG)
+#define dprintf(fmt, args...) dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), __FILE__, __func__, __LINE__, fmt, ##args)
+#else
+#define dprintf(fmt, args...) ({ if (verbosity() > 1) dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), __FILE__, __func__, __LINE__, fmt, ##args); 0; })
+#endif
+#define ingress() dprintf("ingress");
+#define egress() dprintf("egress");
+
#endif /* PESIGN_UTIL_H */
// vim:fenc=utf-8:tw=75:noet
--
2.29.2

View file

@ -0,0 +1,46 @@
From fe2c0facc37f01bdcca8362cc4db7dbd701b6959 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 28 Apr 2020 10:18:08 -0400
Subject: [PATCH 24/42] Work around some NSS SECOID_AddEntry() bugs
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/oid.c | 14 +++++++++++---
1 file changed, 11 insertions(+), 3 deletions(-)
diff --git a/src/oid.c b/src/oid.c
index 4d95ede4046..a2e63093c00 100644
--- a/src/oid.c
+++ b/src/oid.c
@@ -72,17 +72,25 @@ static struct {
SECStatus
register_oids(cms_context *cms)
{
+ int err = PORT_GetError();
+ PORT_SetError(0);
for (int i = 0; oids[i].oid != END_OID_LIST; i++) {
SECOidTag rc;
rc = SECOID_AddEntry(&oids[i].sod);
oids[i].sod.offset = rc;
if (rc == SEC_OID_UNKNOWN) {
- cms->log(cms, LOG_ERR, "SECOid_AddEntry() failed: %s",
- PORT_ErrorToString(PORT_GetError()));
- return SECFailure;
+ cmsreterr(SECFailure, cms,
+ "SECOid_AddEntry() failed: %s",
+ PORT_ErrorToString(PORT_GetError()));
+ } else {
}
}
+ /*
+ * SECOID_AddEntry() leaves the error status that it
+ * used to look it up set. This is very annoying.
+ */
+ PORT_SetError(err);
return SECSuccess;
}
--
2.29.2

File diff suppressed because it is too large Load diff

View file

@ -0,0 +1,56 @@
From e89e23ff5970e9a2194bcb393fa579c123e37bd1 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 28 Apr 2020 10:34:31 -0400
Subject: [PATCH 26/42] Minor whitespace housekeeping
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/cms_pe_common.c | 2 +-
src/pesigcheck.c | 2 ++
src/cms_common.h | 3 +--
3 files changed, 4 insertions(+), 3 deletions(-)
diff --git a/src/cms_pe_common.c b/src/cms_pe_common.c
index bd96fe91d69..b5ef2b73058 100644
--- a/src/cms_pe_common.c
+++ b/src/cms_pe_common.c
@@ -331,4 +331,4 @@ error:
return -1;
}
-/* vim:fenc=utf-8:sw=8:sts=8:noet */
+// vim:fenc=utf-8:tw=75:noet
diff --git a/src/pesigcheck.c b/src/pesigcheck.c
index 87d4960a9a9..ada042e2f7e 100644
--- a/src/pesigcheck.c
+++ b/src/pesigcheck.c
@@ -544,3 +544,5 @@ main(int argc, char *argv[])
return (rc < 0);
}
+
+// vim:fenc=utf-8:tw=75:noet
diff --git a/src/cms_common.h b/src/cms_common.h
index 34ab6551ddd..a8c66cd3f9f 100644
--- a/src/cms_common.h
+++ b/src/cms_common.h
@@ -41,7 +41,7 @@
#define for_each_cert(cl, node) \
for (CERTCertListNode *node = CERT_LIST_HEAD(cl); !CERT_LIST_END(node, cl); node = CERT_LIST_NEXT(node))
-#define cmserr(rv, cms, fmt, args...) ({ \
+#define cmserr(rv, cms, fmt, args...) ({ \
(cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt ": %s", \
__FILE__, __func__, __LINE__, ## args, \
PORT_ErrorToString(PORT_GetError())); \
@@ -54,7 +54,6 @@
return rv; \
})
-
struct digest {
PK11Context *pk11ctx;
SECItem *pe_digest;
--
2.29.2

View file

@ -0,0 +1,34 @@
From 5c6ef128d03bad6fc3e4335935c8f5b20a4b4d51 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Fri, 5 Jun 2020 14:00:10 -0400
Subject: [PATCH 27/42] libdpe: make the initial read buffer always big enough
for the opt header
Signed-off-by: Peter Jones <pjones@redhat.com>
---
libdpe/pe_begin.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/libdpe/pe_begin.c b/libdpe/pe_begin.c
index 3bcc2c70c61..c6a22ab8c43 100644
--- a/libdpe/pe_begin.c
+++ b/libdpe/pe_begin.c
@@ -174,8 +174,14 @@ read_unmmapped_file(int fildes, size_t maxsize, Pe_Cmd cmd, Pe *parent)
struct {
struct mz_hdr mz;
struct pe_hdr pe;
+ union {
+ struct pe32_opt_hdr opt_hdr_32;
+ struct pe32plus_opt_hdr opt_hdr_64;
+ };
};
- unsigned char raw[1];
+ unsigned char raw[sizeof(struct mz_hdr)
+ + sizeof(struct pe_hdr)
+ + sizeof(struct pe32plus_opt_hdr)];
} mem;
ssize_t nread = pread_retry (fildes, &mem.mz, sizeof(mem.mz), 0);
--
2.29.2

View file

@ -0,0 +1,88 @@
From df954024f6e89d4b5947f1016f2e4e95505b45b1 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 16 Jun 2020 10:34:19 -0400
Subject: [PATCH 28/42] Fix some memory leaks
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/cms_common.c | 10 ++++++++++
src/pesign.c | 7 +++++++
2 files changed, 17 insertions(+)
diff --git a/src/cms_common.c b/src/cms_common.c
index c2f34e515a2..7cd98bc994f 100644
--- a/src/cms_common.c
+++ b/src/cms_common.c
@@ -345,7 +345,10 @@ is_valid_cert(CERTCertificate *cert, void *data)
privkey = PK11_FindPrivateKeyFromCert(slot, cert, cbd->cms);
if (privkey != NULL) {
+ if (cbd->cert)
+ CERT_DestroyCertificate(cbd->cert);
cbd->cert = CERT_DupCertificate(cert);
+ CERT_DestroyCertificate(cert);
SECKEY_DestroyPrivateKey(privkey);
return SECSuccess;
}
@@ -363,8 +366,15 @@ is_valid_cert_without_private_key(CERTCertificate *cert, void *data)
return SECFailure;
privkey = PK11_FindPrivateKeyFromCert(slot, cert, cbd->cms);
if (privkey == NULL) {
+ if (cbd->cert)
+ CERT_DestroyCertificate(cbd->cert);
+ PORT_SetError(0);
cbd->cert = CERT_DupCertificate(cert);
+ CERT_DestroyCertificate(cert);
return SECSuccess;
+ } else {
+ SECKEY_DestroyPrivateKey(privkey);
+ CERT_DestroyCertificate(cert);
}
return SECFailure;
}
diff --git a/src/pesign.c b/src/pesign.c
index e68a141b935..0e7ce3d0a4e 100644
--- a/src/pesign.c
+++ b/src/pesign.c
@@ -94,10 +94,12 @@ main(int argc, char *argv[])
int check_vendor_cert = 1;
char *digest_name = "sha256";
+ char *orig_digest_name = digest_name;
char *tokenname = "NSS Certificate DB";
char *origtoken = tokenname;
char *certname = NULL;
char *certdir = "/etc/pki/pesign";
+ char *orig_certdir = certdir;
char *signum = NULL;
secuPWData pwdata;
@@ -349,6 +351,7 @@ main(int argc, char *argv[])
fprintf(stderr, "invalid signature number: %m\n");
exit(1);
}
+ free(signum);
}
int action = 0;
@@ -473,6 +476,8 @@ main(int argc, char *argv[])
}
if (certname)
free(certname);
+ if (digest_name && digest_name != orig_digest_name)
+ free(digest_name);
if (ctxp->sign) {
@@ -507,6 +512,8 @@ main(int argc, char *argv[])
break;
}
}
+ if (certdir && certdir != orig_certdir)
+ free(certdir);
pesign_context_free(ctxp);
if (!daemon) {
--
2.29.2

View file

@ -0,0 +1,494 @@
From 5347765052981b323622c9a5684577778fc7cbab Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 16 Jun 2020 10:43:32 -0400
Subject: [PATCH 29/42] Improve debug output
---
src/cms_common.c | 78 ++++++++++++++++++++++++++++++++++++++-------
src/cms_pe_common.c | 20 ++++++------
src/file_kmod.c | 5 +--
src/file_pe.c | 7 ++++
src/password.c | 36 +++++++++++++++------
src/pesign.c | 10 ++++++
src/cms_common.h | 3 +-
7 files changed, 125 insertions(+), 34 deletions(-)
diff --git a/src/cms_common.c b/src/cms_common.c
index 7cd98bc994f..e2ca5c097d4 100644
--- a/src/cms_common.c
+++ b/src/cms_common.c
@@ -339,9 +339,19 @@ is_valid_cert(CERTCertificate *cert, void *data)
struct validity_cbdata *cbd = (struct validity_cbdata *)data;
PK11SlotInfo *slot = cbd->slot;
SECKEYPrivateKey *privkey = NULL;
+ int errnum;
- if (cert == NULL)
+ errnum = PORT_GetError();
+ if (errnum == SEC_ERROR_EXTENSION_NOT_FOUND) {
+ dprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing");
+ PORT_SetError(0);
+ errnum = 0;
+ }
+ if (cert == NULL) {
+ if (!errnum)
+ PORT_SetError(SEC_ERROR_UNKNOWN_CERT);
return SECFailure;
+ }
privkey = PK11_FindPrivateKeyFromCert(slot, cert, cbd->cms);
if (privkey != NULL) {
@@ -350,6 +360,7 @@ is_valid_cert(CERTCertificate *cert, void *data)
cbd->cert = CERT_DupCertificate(cert);
CERT_DestroyCertificate(cert);
SECKEY_DestroyPrivateKey(privkey);
+ PORT_SetError(0);
return SECSuccess;
}
return SECFailure;
@@ -361,9 +372,20 @@ is_valid_cert_without_private_key(CERTCertificate *cert, void *data)
struct validity_cbdata *cbd = (struct validity_cbdata *)data;
PK11SlotInfo *slot = cbd->slot;
SECKEYPrivateKey *privkey = NULL;
+ int errnum;
- if (cert == NULL)
+ errnum = PORT_GetError();
+ if (errnum == SEC_ERROR_EXTENSION_NOT_FOUND) {
+ dprintf("Got SEC_ERROR_EXTENSION_NOT_FOUND; clearing");
+ PORT_SetError(0);
+ errnum = 0;
+ }
+ if (cert == NULL) {
+ if (!errnum)
+ PORT_SetError(SEC_ERROR_UNKNOWN_CERT);
return SECFailure;
+ }
+
privkey = PK11_FindPrivateKeyFromCert(slot, cert, cbd->cms);
if (privkey == NULL) {
if (cbd->cert)
@@ -402,6 +424,7 @@ PK11_DestroySlotListElement(PK11SlotList *slots, PK11SlotListElement **psle)
int
unlock_nss_token(cms_context *cms)
{
+ dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword");
PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword);
PK11SlotList *slots = NULL;
@@ -438,11 +461,12 @@ unlock_nss_token(cms_context *cms)
status = PK11_Authenticate(psle->slot, PR_TRUE, cms);
if (status != SECSuccess) {
save_port_err() {
+ int err = PORT_GetError();
PK11_DestroySlotListElement(slots, &psle);
PK11_FreeSlotList(slots);
cms->log(cms, LOG_ERR,
- "authentication failed for token \"%s\"",
- cms->tokenname);
+ "authentication failed for token \"%s\": %s",
+ cms->tokenname, PORT_ErrorToString(err));
}
return -1;
}
@@ -462,6 +486,7 @@ find_certificate(cms_context *cms, int needs_private_key)
return -1;
}
+ dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword");
PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword);
PK11SlotList *slots = NULL;
@@ -479,8 +504,12 @@ find_certificate(cms_context *cms, int needs_private_key)
}
while (psle) {
- if (!strcmp(cms->tokenname, PK11_GetTokenName(psle->slot)))
+ dprintf("looking for token \"%s\", got \"%s\"",
+ cms->tokenname, PK11_GetTokenName(psle->slot));
+ if (!strcmp(cms->tokenname, PK11_GetTokenName(psle->slot))) {
+ dprintf("found token \"%s\"", cms->tokenname);
break;
+ }
psle = PK11_GetNextSafe(slots, psle, PR_FALSE);
}
@@ -492,16 +521,18 @@ find_certificate(cms_context *cms, int needs_private_key)
nssreterr(-1, "Could not find token \"%s\"", cms->tokenname);
}
+ int errnum;
SECStatus status;
if (PK11_NeedLogin(psle->slot) && !PK11_IsLoggedIn(psle->slot, cms)) {
status = PK11_Authenticate(psle->slot, PR_TRUE, cms);
if (status != SECSuccess) {
save_port_err() {
+ errnum = PORT_GetError();
PK11_DestroySlotListElement(slots, &psle);
PK11_FreeSlotList(slots);
cms->log(cms, LOG_ERR,
- "authentication failed for token \"%s\"",
- cms->tokenname);
+ "authentication failed for token \"%s\": %s",
+ cms->tokenname, PORT_ErrorToString(errnum));
}
return -1;
}
@@ -530,29 +561,48 @@ find_certificate(cms_context *cms, int needs_private_key)
cbd.slot = psle->slot;
cbd.cert = NULL;
+ PORT_SetError(SEC_ERROR_UNKNOWN_CERT);
if (needs_private_key) {
status = PK11_TraverseCertsForNicknameInSlot(&nickname,
psle->slot, is_valid_cert, &cbd);
+ errnum = PORT_GetError();
+ if (errnum)
+ dprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s",
+ PORT_ErrorToName(errnum), PORT_ErrorToString(errnum));
} else {
status = PK11_TraverseCertsForNicknameInSlot(&nickname,
psle->slot,
is_valid_cert_without_private_key,
&cbd);
+ errnum = PORT_GetError();
+ if (errnum)
+ dprintf("PK11_TraverseCertsForNicknameInSlot():%s:%s",
+ PORT_ErrorToName(errnum), PORT_ErrorToString(errnum));
}
+ dprintf("status:%d cbd.cert:%p", status, cbd.cert);
if (status == SECSuccess && cbd.cert != NULL) {
if (cms->cert)
CERT_DestroyCertificate(cms->cert);
cms->cert = CERT_DupCertificate(cbd.cert);
+ } else {
+ errnum = PORT_GetError();
+ dprintf("token traversal %s; cert %sfound:%s:%s",
+ status == SECSuccess ? "succeeded" : "failed",
+ cbd.cert == NULL ? "not" : "",
+ PORT_ErrorToName(errnum), PORT_ErrorToString(errnum));
}
save_port_err() {
+ dprintf("Destroying cert list");
CERT_DestroyCertList(certlist);
+ dprintf("Destroying slot list element");
PK11_DestroySlotListElement(slots, &psle);
+ dprintf("Destroying slot list");
PK11_FreeSlotList(slots);
cms->psle = NULL;
}
if (status != SECSuccess || cms->cert == NULL)
- cmsreterr(-1, cms, "could not find certificate in list");
+ cmsreterr(-1, cms, "could not find certificate");
return 0;
}
@@ -565,6 +615,7 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot)
return -1;
}
+ dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword");
PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword);
PK11SlotList *slots = NULL;
@@ -600,11 +651,12 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot)
status = PK11_Authenticate(psle->slot, PR_TRUE, cms);
if (status != SECSuccess) {
save_port_err() {
+ int err = PORT_GetError();
PK11_DestroySlotListElement(slots, &psle);
PK11_FreeSlotList(slots);
cms->log(cms, LOG_ERR,
- "authentication failed for token \"%s\"",
- cms->tokenname);
+ "authentication failed for token \"%s\": %s",
+ cms->tokenname, PORT_ErrorToString(err));
}
return -1;
}
@@ -621,6 +673,7 @@ find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
return -1;
}
+ dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword");
PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword);
PK11SlotList *slots = NULL;
@@ -658,11 +711,12 @@ find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
status = PK11_Authenticate(psle->slot, PR_TRUE, cms);
if (status != SECSuccess) {
save_port_err() {
+ int err = PORT_GetError();
PK11_DestroySlotListElement(slots, &psle);
PK11_FreeSlotList(slots);
cms->log(cms, LOG_ERR,
- "authentication failed for token \"%s\"",
- cms->tokenname);
+ "authentication failed for token \"%s\": %s",
+ cms->tokenname, PORT_ErrorToString(err));
}
return -1;
}
diff --git a/src/cms_pe_common.c b/src/cms_pe_common.c
index b5ef2b73058..e5a33eb6fe1 100644
--- a/src/cms_pe_common.c
+++ b/src/cms_pe_common.c
@@ -198,8 +198,8 @@ generate_digest(cms_context *cms, Pe *pe, int padded)
__FILE__, __func__, __LINE__);
goto error;
}
- dprintf("beginning of hash\n");
- dprintf("digesting %lx + %lx\n", hash_base - map, hash_size);
+ dprintf("beginning of hash");
+ dprintf("digesting %lx + %lx", hash_base - map, hash_size);
generate_digest_step(cms, hash_base, hash_size);
/* 5. Skip over the image checksum
@@ -224,7 +224,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded)
goto error;
}
generate_digest_step(cms, hash_base, hash_size);
- dprintf("digesting %lx + %lx\n", hash_base - map, hash_size);
+ dprintf("digesting %lx + %lx", hash_base - map, hash_size);
/* 8. Skip over the crt dir
* 9. Hash everything up to the end of the image header. */
@@ -239,7 +239,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded)
goto error;
}
generate_digest_step(cms, hash_base, hash_size);
- dprintf("digesting %lx + %lx\n", hash_base - map, hash_size);
+ dprintf("digesting %lx + %lx", hash_base - map, hash_size);
/* 10. Set SUM_OF_BYTES_HASHED to the size of the header. */
hashed_bytes = pe32opthdr ? pe32opthdr->header_size
@@ -275,16 +275,16 @@ generate_digest(cms_context *cms, Pe *pe, int padded)
char *name = shdrs[i].name;
if (name && name[0] == '/')
name = get_str(pe, name + 1);
- dprintf("section:\"%s\"\n", name ? name : "(null)");
+ dprintf("section:\"%s\"", name ? name : "(null)");
if (name && !strcmp(name, ".vendor_cert")) {
- dprintf("skipping .vendor_cert section\n");
+ dprintf("skipping .vendor_cert section");
hashed_bytes += hash_size;
continue;
}
}
generate_digest_step(cms, hash_base, hash_size);
- dprintf("digesting %lx + %lx\n", hash_base - map, hash_size);
+ dprintf("digesting %lx + %lx", hash_base - map, hash_size);
hashed_bytes += hash_size;
}
@@ -305,13 +305,13 @@ generate_digest(cms_context *cms, Pe *pe, int padded)
memset(tmp_array, '\0', tmp_size);
memcpy(tmp_array, hash_base, hash_size);
generate_digest_step(cms, tmp_array, tmp_size);
- dprintf("digesting %lx + %lx\n", (unsigned long)tmp_array, tmp_size);
+ dprintf("digesting %lx + %lx", (unsigned long)tmp_array, tmp_size);
} else {
generate_digest_step(cms, hash_base, hash_size);
- dprintf("digesting %lx + %lx\n", hash_base - map, hash_size);
+ dprintf("digesting %lx + %lx", hash_base - map, hash_size);
}
}
- dprintf("end of hash\n");
+ dprintf("end of hash");
rc = generate_digest_finish(cms);
if (rc < 0)
diff --git a/src/file_kmod.c b/src/file_kmod.c
index 077f0579e77..994e5639e71 100644
--- a/src/file_kmod.c
+++ b/src/file_kmod.c
@@ -84,8 +84,9 @@ kmod_write_signature(cms_context *cms, int outfd)
digest_get_digest_oid(cms),
digest, NULL, NULL);
if (!cinfo) {
- cms->log(cms, LOG_ERR, "failed to create signed data: %s",
- PORT_ErrorToString(PORT_GetError()));
+ cms->log(cms, LOG_ERR, "failed to create signed data: %s (%s)",
+ PORT_ErrorToString(PORT_GetError()),
+ PORT_ErrorToName(PORT_GetError()));
return -1;
}
diff --git a/src/file_pe.c b/src/file_pe.c
index 31672c68f79..5b6ac21763a 100644
--- a/src/file_pe.c
+++ b/src/file_pe.c
@@ -22,6 +22,7 @@
#include <fcntl.h>
#include <sys/stat.h>
#include <sys/types.h>
+#include <prerror.h>
#include "pesign.h"
#include "pesign_standalone.h"
@@ -144,6 +145,7 @@ void
pe_handle_action(pesign_context *ctxp, int action, int padding)
{
ssize_t sigspace = 0;
+ int err;
int rc;
switch (action) {
@@ -265,6 +267,9 @@ pe_handle_action(pesign_context *ctxp, int action, int padding)
break;
/* generate a signature and save it in a separate file */
case EXPORT_SIGNATURE|GENERATE_SIGNATURE:
+ err = PORT_GetError();
+ dprintf("PORT_GetError():%s:%s", PORT_ErrorToName(err), PORT_ErrorToString(err));
+ PORT_SetError(0);
rc = find_certificate(ctxp->cms_ctx, 1);
conderrx(rc < 0, 1, "Could not find certificate %s",
ctxp->cms_ctx->certname);
@@ -277,6 +282,8 @@ pe_handle_action(pesign_context *ctxp, int action, int padding)
/* generate a signature and embed it in the binary */
case IMPORT_SIGNATURE|GENERATE_SIGNATURE:
check_inputs(ctxp);
+ err = PORT_GetError();
+ dprintf("PORT_GetError():%s:%s", PORT_ErrorToName(err), PORT_ErrorToString(err));
rc = find_certificate(ctxp->cms_ctx, 1);
conderrx(rc < 0, 1, "Could not find certificate %s",
ctxp->cms_ctx->certname);
diff --git a/src/password.c b/src/password.c
index 0a4ef411ff7..13bd9b12320 100644
--- a/src/password.c
+++ b/src/password.c
@@ -58,15 +58,19 @@ print_prompt(FILE *in, FILE *out, char *prompt)
int infd = fileno(in);
struct termios tio;
+ ingress();
if (!isatty(infd))
return;
- fprintf(out, "%s", prompt);
- fflush(out);
+ if (out) {
+ fprintf(out, "%s", prompt);
+ fflush(out);
+ }
tcgetattr(infd, &tio);
tio.c_lflag &= ~ECHO;
tcsetattr(infd, TCSAFLUSH, &tio);
+ egress();
}
static inline char *
@@ -87,11 +91,14 @@ read_password(FILE *in, FILE *out, char *buf, size_t bufsz)
struct termios tio;
char *ret;
+ ingress();
ret = fgets(buf, bufsz, in);
if (isatty(infd)) {
- fprintf(out, "\n");
- fflush(out);
+ if (out) {
+ fprintf(out, "\n");
+ fflush(out);
+ }
tcgetattr(infd, &tio);
tio.c_lflag |= ECHO;
@@ -101,6 +108,7 @@ read_password(FILE *in, FILE *out, char *buf, size_t bufsz)
return -1;
buf[strlen(buf)-1] = '\0';
+ egress();
return 0;
}
@@ -109,15 +117,23 @@ check_password(char *cp)
{
unsigned int i;
- if (cp == NULL)
+ ingress();
+ if (cp == NULL) {
+ egress();
return PR_FALSE;
+ }
for (i = 0; cp[i] != 0; i++) {
- if (!isprint(cp[i]))
+ if (!isprint(cp[i])) {
+ egress();
return PR_FALSE;
+ }
}
- if (i == 0)
+ if (i == 0) {
+ egress();
return PR_FALSE;
+ }
+ egress();
return PR_TRUE;
}
@@ -134,7 +150,8 @@ get_password(FILE *input, FILE *output, char *prompt, PRBool (*ok)(char *))
while(true) {
int rc;
- print_prompt(input, output, prompt);
+ if (prompt)
+ print_prompt(input, output, prompt);
rc = read_password(input, output, phrase, size);
if (rc < 0)
return NULL;
@@ -160,7 +177,8 @@ SECU_GetPasswordString(void *arg UNUSED, char *prompt)
{
char *ret;
ingress();
- ret = get_password(stdin, stdout, prompt, check_password);
+ ret = get_password(stdin, stdout, prompt, NULL);
+ dprintf("password:\"%s\"", ret ? ret : "(null)");
egress();
return ret;
}
diff --git a/src/pesign.c b/src/pesign.c
index 0e7ce3d0a4e..b5c9823e1d4 100644
--- a/src/pesign.c
+++ b/src/pesign.c
@@ -434,6 +434,16 @@ main(int argc, char *argv[])
"NSS says \"%s\" errno says \"%m\"\n",
PORT_ErrorToString(PORT_GetError()));
}
+ /*
+ * At this point there is *often* an error set, but we
+ * should not get here if it was really an error; one
+ * example is PR_LOAD_LIBRARY_ERROR is often set by PKCS11
+ * modules that aren't present or whose physical token
+ * devices aren't available.
+ *
+ * Clear it.
+ */
+ PORT_SetError(0);
status = register_oids(ctxp->cms_ctx);
if (status != SECSuccess) {
diff --git a/src/cms_common.h b/src/cms_common.h
index a8c66cd3f9f..ee06f812a77 100644
--- a/src/cms_common.h
+++ b/src/cms_common.h
@@ -48,8 +48,9 @@
exit(rv); \
})
#define cmsreterr(rv, cms, fmt, args...) ({ \
- (cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt ": %s", \
+ (cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt ":%s:%s", \
__FILE__, __func__, __LINE__, ## args, \
+ PORT_ErrorToName(PORT_GetError()), \
PORT_ErrorToString(PORT_GetError())); \
return rv; \
})
--
2.29.2

View file

@ -0,0 +1,256 @@
From 1465c77dc36a9d5464f42e2477758e250b797fac Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Sat, 20 Jun 2020 17:13:17 -0400
Subject: [PATCH 30/42] support uri token names
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/cms_common.c | 103 ++++++++++++++++++++++++++++++++++++++++-------
1 file changed, 89 insertions(+), 14 deletions(-)
diff --git a/src/cms_common.c b/src/cms_common.c
index e2ca5c097d4..e9c2d08f94c 100644
--- a/src/cms_common.c
+++ b/src/cms_common.c
@@ -25,6 +25,7 @@
#include <time.h>
#include <unistd.h>
#include <stdarg.h>
+#include <string.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <syslog.h>
@@ -42,6 +43,8 @@
#include <secerr.h>
#include <certt.h>
+#include "hex.h"
+
struct digest_param {
char *name;
SECOidTag digest_tag;
@@ -421,9 +424,74 @@ PK11_DestroySlotListElement(PK11SlotList *slots, PK11SlotListElement **psle)
*psle = PK11_GetNextSafe(slots, *psle, PR_FALSE);
}
+static inline void
+unescape_html_in_place(char *s)
+{
+ size_t sz = strlen(s) + 1;
+ size_t pos = 0;
+ char *s1;
+
+ dprintf("unescaping pos:%zd sz:%zd \"%s\"", pos, sz, s);
+ do {
+ s1 = strchrnul(&s[pos], '%');
+ if (s1[0] == '\0')
+ break;
+ dprintf("s1 is \"%s\"", s1);
+ if ((size_t)(s1 - s) < (size_t)(sz - 3)) {
+ int c;
+
+ c = (hexchar_to_bin(s1[1]) << 4)
+ | (hexchar_to_bin(s1[2]) & 0xf);
+ dprintf("replacing %%%c%c with 0x%02hhx", s1[1], s1[2], (char)c);
+ s1[0] = c;
+ memmove(&s1[1], &s1[3], sz - (&s1[3] - s));
+ sz -= 2;
+ pos = &s1[1] - s;
+ dprintf("new pos:%zd sz:%zd s:\"%s\"", pos, sz, s);
+ }
+ } while (pos < sz);
+}
+
+static inline void
+resolve_pkcs11_token_in_place(char *tokenname)
+{
+ char *ntn = tokenname;
+ size_t pos = 0;
+
+ while (*ntn) {
+ char *cp = strchrnul(ntn, ';');
+ char c = *cp;
+ *cp = '\0';
+
+ dprintf("ntn:\"%s\"", ntn);
+ if (!strncmp(&ntn[pos], "token=", 6)) {
+ ntn += 6;
+ memmove(tokenname, ntn, cp - ntn + 1);
+ break;
+ }
+
+ *cp = c;
+ ntn = cp + (c ? 1 : 0);
+ }
+ unescape_html_in_place(tokenname);
+ dprintf("token name is \"%s\"", tokenname);
+}
+
+#define resolve_token_name(tn) ({ \
+ char *s_ = tn; \
+ if (!strncmp(tn, "pkcs11:", 7)) { \
+ dprintf("provided token name is pkcs11 uri; parsing"); \
+ s_ = strdupa(tn+7); \
+ resolve_pkcs11_token_in_place(s_); \
+ } \
+ s_; \
+})
+
int
unlock_nss_token(cms_context *cms)
{
+ char *tokenname = resolve_token_name(cms->tokenname);
+
dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword");
PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword);
@@ -432,6 +500,7 @@ unlock_nss_token(cms_context *cms)
if (!slots)
cmsreterr(-1, cms, "could not get pk11 token list");
+
PK11SlotListElement *psle = NULL;
psle = PK11_GetFirstSafe(slots);
if (!psle) {
@@ -442,7 +511,7 @@ unlock_nss_token(cms_context *cms)
}
while (psle) {
- if (!strcmp(cms->tokenname, PK11_GetTokenName(psle->slot)))
+ if (!strcmp(tokenname, PK11_GetTokenName(psle->slot)))
break;
psle = PK11_GetNextSafe(slots, psle, PR_FALSE);
@@ -452,7 +521,7 @@ unlock_nss_token(cms_context *cms)
save_port_err() {
PK11_FreeSlotList(slots);
}
- nssreterr(-1, "Could not find token \"%s\"", cms->tokenname);
+ nssreterr(-1, "Could not find token \"%s\"", tokenname);
}
SECStatus status;
@@ -466,7 +535,7 @@ unlock_nss_token(cms_context *cms)
PK11_FreeSlotList(slots);
cms->log(cms, LOG_ERR,
"authentication failed for token \"%s\": %s",
- cms->tokenname, PORT_ErrorToString(err));
+ tokenname, PORT_ErrorToString(err));
}
return -1;
}
@@ -480,6 +549,8 @@ unlock_nss_token(cms_context *cms)
int
find_certificate(cms_context *cms, int needs_private_key)
{
+ char *tokenname = resolve_token_name(cms->tokenname);
+
struct validity_cbdata cbd;
if (!cms->certname || !*cms->certname) {
cms->log(cms, LOG_ERR, "no certificate name specified");
@@ -505,9 +576,9 @@ find_certificate(cms_context *cms, int needs_private_key)
while (psle) {
dprintf("looking for token \"%s\", got \"%s\"",
- cms->tokenname, PK11_GetTokenName(psle->slot));
- if (!strcmp(cms->tokenname, PK11_GetTokenName(psle->slot))) {
- dprintf("found token \"%s\"", cms->tokenname);
+ tokenname, PK11_GetTokenName(psle->slot));
+ if (!strcmp(tokenname, PK11_GetTokenName(psle->slot))) {
+ dprintf("found token \"%s\"", tokenname);
break;
}
@@ -518,7 +589,7 @@ find_certificate(cms_context *cms, int needs_private_key)
save_port_err() {
PK11_FreeSlotList(slots);
}
- nssreterr(-1, "Could not find token \"%s\"", cms->tokenname);
+ nssreterr(-1, "Could not find token \"%s\"", tokenname);
}
int errnum;
@@ -532,7 +603,7 @@ find_certificate(cms_context *cms, int needs_private_key)
PK11_FreeSlotList(slots);
cms->log(cms, LOG_ERR,
"authentication failed for token \"%s\": %s",
- cms->tokenname, PORT_ErrorToString(errnum));
+ tokenname, PORT_ErrorToString(errnum));
}
return -1;
}
@@ -615,6 +686,8 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot)
return -1;
}
+ char *tokenname = resolve_token_name(cms->tokenname);
+
dprintf("setting password function to %s", cms->func ? "cms->func" : "SECU_GetModulePassword");
PK11_SetPasswordFunc(cms->func ? cms->func : SECU_GetModulePassword);
@@ -633,7 +706,7 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot)
}
while (psle) {
- if (!strcmp(cms->tokenname, PK11_GetTokenName(psle->slot)))
+ if (!strcmp(tokenname, PK11_GetTokenName(psle->slot)))
break;
psle = PK11_GetNextSafe(slots, psle, PR_FALSE);
@@ -643,7 +716,7 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot)
save_port_err() {
PK11_FreeSlotList(slots);
}
- nssreterr(-1, "Could not find token \"%s\"", cms->tokenname);
+ nssreterr(-1, "Could not find token \"%s\"", tokenname);
}
SECStatus status;
@@ -656,7 +729,7 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot)
PK11_FreeSlotList(slots);
cms->log(cms, LOG_ERR,
"authentication failed for token \"%s\": %s",
- cms->tokenname, PORT_ErrorToString(err));
+ tokenname, PORT_ErrorToString(err));
}
return -1;
}
@@ -668,6 +741,8 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot)
int
find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
{
+ char *tokenname = resolve_token_name(cms->tokenname);
+
if (!name) {
cms->log(cms, LOG_ERR, "no certificate name specified");
return -1;
@@ -691,7 +766,7 @@ find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
}
while (psle) {
- if (!strcmp(cms->tokenname, PK11_GetTokenName(psle->slot)))
+ if (!strcmp(tokenname, PK11_GetTokenName(psle->slot)))
break;
psle = PK11_GetNextSafe(slots, psle, PR_FALSE);
@@ -701,7 +776,7 @@ find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
save_port_err() {
PK11_FreeSlotList(slots);
cms->log(cms, LOG_ERR, "could not find token \"%s\"",
- cms->tokenname);
+ tokenname);
}
return -1;
}
@@ -716,7 +791,7 @@ find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
PK11_FreeSlotList(slots);
cms->log(cms, LOG_ERR,
"authentication failed for token \"%s\": %s",
- cms->tokenname, PORT_ErrorToString(err));
+ tokenname, PORT_ErrorToString(err));
}
return -1;
}
--
2.29.2

View file

@ -0,0 +1,178 @@
From 1b3f668daa34372308d94cf322b1f809e83fe4aa Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Mon, 22 Jun 2020 13:54:10 -0400
Subject: [PATCH 31/42] cms_common: add some more ways to find a cert
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/cms_common.c | 109 +++++++++++++++++++++++++++++++++++++++--------
src/cms_common.h | 9 ++++
2 files changed, 101 insertions(+), 17 deletions(-)
diff --git a/src/cms_common.c b/src/cms_common.c
index e9c2d08f94c..e274a8a50da 100644
--- a/src/cms_common.c
+++ b/src/cms_common.c
@@ -739,12 +739,18 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot)
}
int
-find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
+find_certificate_by_callback(cms_context *cms,
+ find_cert_match_t *match, void *cbdata,
+ CERTCertificate **cert)
{
char *tokenname = resolve_token_name(cms->tokenname);
- if (!name) {
- cms->log(cms, LOG_ERR, "no certificate name specified");
+ if (!match) {
+ cms->log(cms, LOG_ERR, "no certificate match callback not specified");
+ return -1;
+ }
+ if (!cbdata) {
+ cms->log(cms, LOG_ERR, "no certificate callback data not specified");
return -1;
}
@@ -809,25 +815,29 @@ find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
CERTCertListNode *node = NULL;
for_each_cert(certlist, tmpnode) {
- if (!strcmp(tmpnode->cert->subjectName, name)) {
+ /* If we're looking up the issuer of some cert, and the
+ * issuer isn't in the database, we'll get back what is
+ * essentially a template that's in NSS's cache waiting to
+ * be filled out. We can't use that, it'll just cause
+ * CERT_DupCertificate() to segfault. */
+ if (!tmpnode || !tmpnode->cert
+ || !tmpnode->cert->derCert.data
+ || !tmpnode->cert->derCert.len
+ || !tmpnode->cert->derIssuer.data
+ || !tmpnode->cert->derIssuer.len
+ || !tmpnode->cert->serialNumber.data
+ || !tmpnode->cert->serialNumber.len)
+ continue;
+
+ int rc = match(tmpnode->cert, cbdata);
+ if (rc == 0) {
node = tmpnode;
break;
}
}
- /* If we're looking up the issuer of some cert, and the issuer isn't
- * in the database, we'll get back what is essentially a template
- * that's in NSS's cache waiting to be filled out. We can't use that,
- * it'll just cause CERT_DupCertificate() to segfault. */
- if (!node || !node->cert || !node->cert->derCert.data
- || !node->cert->derCert.len
- || !node->cert->derIssuer.data
- || !node->cert->derIssuer.len) {
- PK11_DestroySlotListElement(slots, &psle);
- PK11_FreeSlotList(slots);
- CERT_DestroyCertList(certlist);
- return -1;
- }
+ if (!node)
+ cmsreterr(-1, cms, "Could not find certificate");
*cert = CERT_DupCertificate(node->cert);
@@ -836,6 +846,71 @@ find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
CERT_DestroyCertList(certlist);
return 0;
+
+}
+
+static int
+match_subject(CERTCertificate *cert, void *cbdatap)
+{
+ if (!cert->subjectName)
+ return 0;
+
+ if (!strcmp(cert->subjectName, (char *)cbdatap))
+ return 1;
+
+ return 0;
+}
+
+int
+find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
+{
+ if (!name)
+ cmsreterr(-1, cms, "no subject name specified");
+
+ return find_certificate_by_callback(cms, match_subject, name, cert);
+}
+
+static int
+match_issuer_and_serial(CERTCertificate *cert, void *cbdatap)
+{
+ CERTIssuerAndSN *ias = cbdatap;
+ bool found = false;
+
+ if (ias->derIssuer.len == cert->derIssuer.len &&
+ ias->derIssuer.len != 0) {
+ if (memcmp(ias->derIssuer.data, cert->derIssuer.data,
+ ias->derIssuer.len))
+ return 0;
+ found = true;
+ }
+
+ if (!found) {
+ SECComparison seccomp;
+
+ seccomp = CERT_CompareName(&ias->issuer, &cert->issuer);
+ if (seccomp != SECEqual)
+ return 0;
+ }
+
+ if (ias->serialNumber.len != cert->serialNumber.len)
+ return 0;
+
+ if (memcmp(ias->serialNumber.data, cert->serialNumber.data,
+ ias->serialNumber.len))
+ return 0;
+
+ return 1;
+}
+
+int
+find_certificate_by_issuer_and_sn(cms_context *cms,
+ CERTIssuerAndSN *ias,
+ CERTCertificate **cert)
+{
+ if (!ias)
+ cmsreterr(-1, cms, "invalid issuer and serial number");
+
+ return find_certificate_by_callback(cms, match_issuer_and_serial, &ias, cert);
}
int
diff --git a/src/cms_common.h b/src/cms_common.h
index ee06f812a77..04974035f0c 100644
--- a/src/cms_common.h
+++ b/src/cms_common.h
@@ -190,8 +190,17 @@ extern int generate_keys(cms_context *cms, PK11SlotInfo *slot,
SECKEYPrivateKey **privkey, SECKEYPublicKey **pubkey);
extern int is_issuer_of(CERTCertificate *c0, CERTCertificate *c1);
+typedef int (find_cert_match_t)(CERTCertificate *cert, void *cbdata);
+extern int find_certificate_by_callback(cms_context *cms,
+ find_cert_match_t *match, void *cbdata,
+ CERTCertificate **cert);
+
extern int find_named_certificate(cms_context *cms, char *name,
CERTCertificate **cert);
+extern int find_certificate_by_issuer_and_sn(cms_context *cms,
+ CERTIssuerAndSN *ias,
+ CERTCertificate **cert);
+
extern int find_slot_for_token(cms_context *cms, PK11SlotInfo **slot);
extern SECOidTag digest_get_digest_oid(cms_context *cms);
--
2.29.2

View file

@ -0,0 +1,86 @@
From 2dd5d6653ff965e2afc14a2abfba308f26934a65 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Mon, 6 Jul 2020 16:13:09 -0400
Subject: [PATCH 32/42] client: try /run and /var/run for the socket path.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/client.c | 40 +++++++++++++++++++++++++++++-----------
1 file changed, 29 insertions(+), 11 deletions(-)
diff --git a/src/client.c b/src/client.c
index a00b20f5dde..914f2c8bd55 100644
--- a/src/client.c
+++ b/src/client.c
@@ -61,24 +61,24 @@ print_flag_name(FILE *f, int flag)
}
static int
-connect_to_server(void)
+connect_to_server_helper(const char * const sockpath)
{
- int rc = access(SOCKPATH, R_OK);
+ int rc = access(sockpath, R_OK);
if (rc != 0) {
- fprintf(stderr, "pesign-client: could not connect to server: "
- "%m\n");
- exit(1);
+ warn("could not access socket \"%s\"", sockpath);
+ return rc;
}
struct sockaddr_un addr_un = {
.sun_family = AF_UNIX,
- .sun_path = SOCKPATH,
};
+ strncpy(addr_un.sun_path, sockpath, sizeof(addr_un.sun_path));
+ addr_un.sun_path[sizeof(addr_un.sun_path)-1] = '\0';
int sd = socket(AF_UNIX, SOCK_STREAM, 0);
if (sd < 0) {
- fprintf(stderr, "pesign-client: could not open socket: %m\n");
- exit(1);
+ warn("could not open socket \"%s\"", sockpath);
+ return sd;
}
socklen_t len = strlen(addr_un.sun_path) +
@@ -86,14 +86,32 @@ connect_to_server(void)
rc = connect(sd, (struct sockaddr *)&addr_un, len);
if (rc < 0) {
- fprintf(stderr, "pesign-client: could not connect to daemon: "
- "%m\n");
- exit(1);
+ warn("could not connect to daemon");
+ return sd;
}
return sd;
}
+static int
+connect_to_server(void)
+{
+ int rc, i;
+ const char * const sockets[] = {
+ "/run/pesign/socket",
+ "/var/run/pesign/socket",
+ NULL
+ };
+
+ for (i = 0; sockets[i] != NULL; i++) {
+ rc = connect_to_server_helper(sockets[i]);
+ if (rc >= 0)
+ return rc;
+ }
+
+ exit(1);
+}
+
static int32_t
check_response(int sd, char **srvmsg);
--
2.29.2

View file

@ -0,0 +1,25 @@
From 8ce83e63dd221beb775378981090deacd17e2166 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 14 Jul 2020 16:44:09 -0400
Subject: [PATCH 33/42] client: remove an extra debug print
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/client.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/src/client.c b/src/client.c
index 914f2c8bd55..48fdeaba6a4 100644
--- a/src/client.c
+++ b/src/client.c
@@ -536,7 +536,6 @@ oom:
0, true);
}
- printf("add_file_type:%d\n", add_file_type);
pm->version = PESIGND_VERSION;
pm->command = attached ? (add_file_type ? CMD_SIGN_ATTACHED_WITH_FILE_TYPE
: CMD_SIGN_ATTACHED)
--
2.29.2

View file

@ -0,0 +1,379 @@
From 8fd6066496fc148945570371863597769b8ffe1d Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Mon, 6 Jul 2020 13:54:35 -0400
Subject: [PATCH 34/42] Move most of macros.pesign to pesign-rpmbuild-helper
Signed-off-by: Peter Jones <pjones@redhat.com>
---
Make.defaults | 1 +
src/Makefile | 8 +-
src/macros.pesign | 74 ++++--------
src/pesign-rpmbuild-helper.in | 222 ++++++++++++++++++++++++++++++++++
4 files changed, 252 insertions(+), 53 deletions(-)
create mode 100644 src/pesign-rpmbuild-helper.in
diff --git a/Make.defaults b/Make.defaults
index 0bacafe0d01..d4cd626c11e 100644
--- a/Make.defaults
+++ b/Make.defaults
@@ -16,6 +16,7 @@ INSTALLROOT = $(DESTDIR)
INSTALL ?= install
CROSS_COMPILE ?=
+EFI_ARCHES ?= aa64 ia32 x64
PKG_CONFIG = $(CROSS_COMPILE)pkg-config
CC := $(if $(filter default,$(origin CC)),$(CROSS_COMPILE)gcc,$(CC))
diff --git a/src/Makefile b/src/Makefile
index bc3e5931456..82c2dfdec3f 100644
--- a/src/Makefile
+++ b/src/Makefile
@@ -5,7 +5,7 @@ include $(TOPDIR)/Make.version
include $(TOPDIR)/Make.rules
include $(TOPDIR)/Make.defaults
-BINTARGETS=authvar client efikeygen efisiglist pesigcheck pesign
+BINTARGETS=authvar client efikeygen efisiglist pesigcheck pesign pesign-rpmbuild-helper
SVCTARGETS=pesign.sysvinit pesign.service
TARGETS=$(BINTARGETS) $(SVCTARGETS)
@@ -54,6 +54,11 @@ pesign : $(call objects-of,$(PESIGN_SOURCES) $(COMMON_SOURCES) $(COMMON_PE_SOURC
pesign : LDLIBS+=$(TOPDIR)/libdpe/libdpe.a
pesign : PKGS=efivar nss nspr popt
+pesign-rpmbuild-helper: pesign-rpmbuild-helper.in
+ sed \
+ -e "s/@@EFI_ARCHES@@/$(EFI_ARCHES)/g" \
+ $^ > $@
+
deps : PKGS=efivar nss nspr popt uuid
deps : $(ALL_SOURCES)
$(MAKE) -f $(TOPDIR)/Make.deps \
@@ -99,6 +104,7 @@ install :
$(INSTALL) -m 644 macros.pesign $(INSTALLROOT)/etc/rpm/
$(INSTALL) -d -m 755 $(INSTALLROOT)$(libexecdir)/pesign/
$(INSTALL) -m 750 pesign-authorize $(INSTALLROOT)$(libexecdir)/pesign/
+ $(INSTALL) -m 755 pesign-rpmbuild-helper $(INSTALLROOT)$(libexecdir)/pesign/
$(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pesign
$(INSTALL) -m 600 pesign-users $(INSTALLROOT)/etc/pesign/users
$(INSTALL) -m 600 pesign-groups $(INSTALLROOT)/etc/pesign/groups
diff --git a/src/macros.pesign b/src/macros.pesign
index 5a6da1c6809..34af57c5b3b 100644
--- a/src/macros.pesign
+++ b/src/macros.pesign
@@ -6,7 +6,7 @@
# %pesign -s -i shim.orig -o shim.efi
# And magically get the right thing.
-%__pesign_token %{nil}%{?pe_signing_token:-t "%{pe_signing_token}"}
+%__pesign_token %{nil}%{?pe_signing_token:--token "%{pe_signing_token}"}
%__pesign_cert %{!?pe_signing_cert:"Red Hat Test Certificate"}%{?pe_signing_cert:"%{pe_signing_cert}"}
%__pesign_client_token %{!?pe_signing_token:"OpenSC Card (Fedora Signer)"}%{?pe_signing_token:"%{pe_signing_token}"}
@@ -24,54 +24,24 @@
# -a <input ca cert filename> # rhel only
# -s # perform signing
%pesign(i:o:C:e:c:n:a:s) \
- _pesign_nssdir=/etc/pki/pesign \
- if [ %{__pesign_cert} = "Red Hat Test Certificate" ]; then \
- _pesign_nssdir=/etc/pki/pesign-rh-test \
- fi \
- if [ -x %{_pesign} ] && \\\
- [ "%{_target_cpu}" == "x86_64" -o \\\
- "%{_target_cpu}" == "aarch64" ]; then \
- if [ "0%{?rhel}" -ge "7" -a -f /usr/bin/rpm-sign ]; then \
- nss=$(mktemp -p $PWD -d) \
- echo > ${nss}/pwfile \
- certutil -N -d ${nss} -f ${nss}/pwfile \
- certutil -A -n "ca" -t "CT,C," -i %{-a*} -d ${nss} \
- certutil -A -n "signer" -t ",c," -i %{-c*} -d ${nss} \
- sattrs=$(mktemp -p $PWD --suffix=.der) \
- %{_pesign} %{-i} -E ${sattrs} --certdir ${nss} --force \
- rpm-sign --key "%{-n*}" --rsadgstsign ${sattrs} \
- %{_pesign} -R ${sattrs}.sig -I ${sattrs} %{-i} \\\
- --certdir ${nss} -c signer %{-o} \
- rm -rf ${sattrs} ${sattrs}.sig ${nss} \
- elif [ "$(id -un)" == "kojibuilder" -a \\\
- grep -q ID=fedora /etc/os-release -a \\\
- ! -S /run/pesign/socket ]; then \
- echo "No socket even though this is kojibuilder" 1>&2 \
- ls -ld /run/pesign 1>&2 \
- ls -l /run/pesign/socket 1>&2 \
- getfacl /run/pesign 1>&2 \
- getfacl /run/pesign/socket 1>&2 \
- exit 1 \
- elif [ -S /run/pesign/socket ]; then \
- %{_pesign_client} -t %{__pesign_client_token} \\\
- -c %{__pesign_client_cert} \\\
- %{-i} %{-o} %{-e} %{-s} %{-C} \
- else \
- %{_pesign} %{__pesign_token} -c %{__pesign_cert} \\\
- --certdir ${_pesign_nssdir} \\\
- %{-i} %{-o} %{-e} %{-s} %{-C} \
- fi \
- else \
- if [ -n "%{-i*}" -a -n "%{-o*}" ]; then \
- mv %{-i*} %{-o*} \
- elif [ -n "%{-i*}" -a -n "%{-e*}" ]; then \
- touch %{-e*} \
- fi \
- fi \
- if [ ! -s %{-o} ]; then \
- if [ -e "%{-o*}" ]; then \
- rm -f %{-o*} \
- fi \
- exit 1 \
- fi ;
-
+ %{_libexecdir}/pesign/pesign-rpmbuild-helper \\\
+ "%{_target_cpu}" \\\
+ "%{_pesign}" \\\
+ "%{_pesign_client}" \\\
+ %{?__pesign_client_token:--client-token %{__pesign_client_token}} \\\
+ %{?__pesign_client_cert:--client-cert %{__pesign_client_cert}} \\\
+ %{?__pesign_token:%{__pesign_token}} \\\
+ %{?__pesign_cert:--cert %{__pesign_cert}} \\\
+ %{?_buildhost:--hostname "%{_buildhost}"} \\\
+ %{?vendor:--vendor "%{vendor}"} \\\
+ %{?_rhel:--rhelver "%{_rhel}"} \\\
+ %{?-n:--rhelcert %{-n*}}%{?!-n:--rhelcert %{__pesign_cert}} \\\
+ %{?-a:--rhelcafile "%{-a*}"} \\\
+ %{?-c:--rhelcertfile "%{-c*}"} \\\
+ %{?-C:--certout "%{-C*}"} \\\
+ %{?-e:--sattrout "%{-e*}"} \\\
+ %{?-i:--in "%{-i*}"} \\\
+ %{?-o:--out "%{-o*}"} \\\
+ %{?-s:--sign} \\\
+ ; \
+%{nil}
diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in
new file mode 100644
index 00000000000..c5287c27e0c
--- /dev/null
+++ b/src/pesign-rpmbuild-helper.in
@@ -0,0 +1,222 @@
+#!/bin/bash
+# shellcheck shell=bash
+
+set -eu
+set -x
+
+usage() {
+ local status="${1}" && shift
+ local out
+ if [[ "${status}" -eq 0 ]] ; then
+ out=/dev/stdout
+ else
+ out=/dev/stderr
+ fi
+
+ if [[ $# -gt 0 ]] ; then
+ echo "${0}: error: $*" >>"${out}"
+ fi
+ echo "usage: ${0} TARGET_CPU PESIGN_BINARY PESIGN_CLIENT_BINARY [OPTIONS]" >>"${out}"
+ exit "${status}"
+}
+
+is_efi_arch() {
+ local arch="${1}"
+ local arches=(@@EFI_ARCHES@@)
+ local x
+ for x in "${arches[@]}" ; do
+ if [[ "${arch}" = "${x}" ]] ; then
+ return 0
+ fi
+ done
+ return 1
+}
+
+error_on_empty() {
+ local f="${1}"
+ if [[ ! -s "${f}" ]] ; then
+ if [[ -e "${f}" ]] ; then
+ rm -f "${f}"
+ fi
+ echo "${0}: error: empty result file \"${f}\"">>/dev/stderr
+ exit 1
+ fi
+}
+
+main() {
+ if [[ $# -lt 3 ]] ; then
+ usage 1 not enough arguments
+ fi
+ local target_cpu="${1}" && shift
+ local bin="${1}" && shift
+ local client="${1}" && shift
+
+ local rhelcafile="" || :
+ local rhelcertfile="" || :
+
+ local certout=() || :
+ local sattrout=() || :
+ local input=() || :
+ local output=() || :
+ local client_token=() || :
+ local client_cert=() || :
+ local token=() || :
+ local cert=() || :
+ local rhelcert=() || :
+ local rhelver=0 || :
+ local sign="" || :
+ local arch="" || :
+ local vendor="" || :
+ local HOSTNAME="" || :
+
+ while [[ $# -ge 2 ]] ; do
+ case " ${1} " in
+ " --rhelcafile ")
+ rhelcafile="${2}"
+ ;;
+ " --rhelcertfile ")
+ rhelcertfile="${2}"
+ ;;
+ " --hostname ")
+ HOSTNAME="${2}"
+ ;;
+ " --certout ")
+ certout[0]=-C
+ certout[1]="${2}"
+ ;;
+ " --sattrout ")
+ sattrout[0]=-e
+ sattrout[1]="${2}"
+ ;;
+ " --client-token ")
+ client_token[0]=-t
+ client_token[1]="${2}"
+ ;;
+ " --client-cert ")
+ client_cert[0]=-c
+ client_cert[1]="${2}"
+ ;;
+ " --token ")
+ token[0]=-t
+ token[1]="${2}"
+ ;;
+ " --cert ")
+ cert[0]=-c
+ cert[1]="${2}"
+ ;;
+ " --rhelcert ")
+ rhelcert[0]=-c
+ rhelcert[1]="${2}"
+ ;;
+ " --in ")
+ input[0]=-i
+ input[1]="${2}"
+ ;;
+ " --out ")
+ output[0]=-o
+ output[1]="${2}"
+ ;;
+ " --rhelver ")
+ rhelver="${2}"
+ ;;
+ " --vendor ")
+ vendor="${2}"
+ ;;
+ *)
+ break
+ ;;
+ esac
+ shift
+ shift
+ done
+ if [[ $# -ge 1 ]] && [[ "${1}" = --sign ]] ; then
+ sign=-s
+ shift
+ fi
+
+ if [[ -z "${target_cpu}" ]] ; then
+ target_cpu="$(uname -m)"
+ fi
+
+ target_cpu="${target_cpu/i?86/ia32}"
+ target_cpu="${target_cpu/x86_64/x64}"
+ target_cpu="${target_cpu/aarch64/aa64}"
+ target_cpu="${target_cpu/arm*/arm/}"
+
+ local nssdir=/etc/pki/pesign
+ if [[ "${#cert[@]}" -eq 2 ]] &&
+ [[ "${cert[1]}" == "Red Hat Test Certificate" ]] ; then
+ nssdir=/etc/pki/pesign-rh-test
+ fi
+
+ # is_efi_arch is ultimately returning "is pesign configured to sign these
+ # using the rpm macro", so if it isn't, we're just copying the input to
+ # the output
+ if [[ -x "${bin}" ]] && ! is_efi_arch "${target_cpu}" ; then
+ if [[ -n "${input[*]}" ]] && [[ -n "${output[*]}" ]] ; then
+ cp -v "${input[1]}" "${output[1]}"
+ elif [[ -n "${input[*]}" ]] && [[ -n "${sattrout[*]}" ]] ; then
+ touch "${sattrout[1]}"
+ fi
+
+ # if there's a 0-sized output file, delete it and error out
+ error_on_empty "${output[1]}"
+ return 0
+ fi
+
+ USERNAME="${USERNAME:-$(id -un)}"
+
+ local socket="" || :
+ if grep -q ID=fedora /etc/os-release \
+ && [[ "${rhelver}" -lt 7 ]] \
+ && [[ "${USERNAME}" = "mockbuild" ]] \
+ && [[ "${vendor}" = "Fedora Project" ]] \
+ && [[ "${HOSTNAME}" =~ bkernel.* ]]
+ then
+ if [[ -S /run/pesign/socket ]] ; then
+ socket=/run/pesign/socket
+ elif [[ -S /var/run/pesign/socket ]]; then
+ socket=/var/run/pesign/socket
+ else
+ echo "Warning: no pesign socket even though user is ${USERNAME}" 1>&2
+ echo "Warning: if this is a non-scratch koji build, this is wrong" 1>&2
+ ls -ld /run/pesign /var/run/pesign 1>&2 ||:
+ ls -l /run/pesign/socket /var/run/pesign/socket 1>&2 ||:
+ getfacl /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||:
+ getfacl -n /run/pesign /run/pesign/socket /var/run/pesign /var/run/pesign/socket 1>&2 ||:
+ fi
+ fi
+
+ if [[ "${rhelver}" -ge 7 ]] ; then
+ nssdir="$(mktemp -p "${PWD}" -d)"
+ echo > "${nssdir}/pwfile"
+ certutil -N -d "${nssdir}" -f "${nssdir}/pwfile"
+ certutil -A -n "ca" -t "CTu,CTu,CTu" -i "${rhelcafile}" -d "${nssdir}"
+ certutil -A -n "signer" -t "CTu,CTu,CTu" -i "${rhelcertfile}" -d "${nssdir}"
+ sattrs="$(mktemp -p "${PWD}" --suffix=.der)"
+ "${bin}" -E "${sattrs}" --certdir "${nssdir}" \
+ "${input[@]}" --force
+ rpm-sign --key "${rhelcert[1]}" --rsadgstsign "${sattrs}"
+ "${bin}" -R "${sattrs}.sig" -I "${sattrs}" \
+ --certdir "${nssdir}" -c signer \
+ "${input[@]}" "${output[@]}"
+ rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}"
+ elif [[ -n "${socket}" ]] ; then
+ "${client}" "${client_token[@]}" "${client_cert[@]}" \
+ "${sattrout[@]}" "${certout[@]}" \
+ ${sign} "${input[@]}" "${output[@]}"
+ else
+ "${bin}" --certdir "${nssdir}" "${token[@]}" \
+ "${cert[@]}" ${sign} "${sattrout[@]}" \
+ "${certout[@]}" "${input[@]}" "${output[@]}"
+ fi
+
+ # if there's a 0-sized output file, delete it and error out
+ if [[ "${#output[@]}" -eq 2 ]] ; then
+ error_on_empty "${output[1]}"
+ fi
+}
+
+main "${@}"
+
+# vim:filetype=sh:fenc=utf-8:tw=78:sts=4:sw=4
--
2.29.2

View file

@ -0,0 +1,60 @@
From 556e51ec7cdd4225de5e1764fc7fac114bd926d1 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 14 Jul 2020 15:07:32 -0400
Subject: [PATCH 35/42] pesign-authorize: shellcheck
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/pesign-authorize | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/src/pesign-authorize b/src/pesign-authorize
index a496f601ab4..55cd5c4e55b 100755
--- a/src/pesign-authorize
+++ b/src/pesign-authorize
@@ -12,21 +12,21 @@ set -u
# License: GPLv2
declare -a fileusers=()
declare -a dirusers=()
-for user in $(cat /etc/pesign/users); do
+while read -r user ; do
dirusers[${#dirusers[@]}]=-m
dirusers[${#dirusers[@]}]="u:$user:rwx"
fileusers[${#fileusers[@]}]=-m
fileusers[${#fileusers[@]}]="u:$user:rw"
-done
+done </etc/pesign/users
declare -a filegroups=()
declare -a dirgroups=()
-for group in $(cat /etc/pesign/groups); do
+while read -r group ; do
dirgroups[${#dirgroups[@]}]=-m
dirgroups[${#dirgroups[@]}]="g:$group:rwx"
filegroups[${#filegroups[@]}]=-m
filegroups[${#filegroups[@]}]="g:$group:rw"
-done
+done </etc/pesign/groups
update_subdir() {
subdir=$1 && shift
@@ -35,12 +35,12 @@ update_subdir() {
setfacl "${dirusers[@]}" "${dirgroups[@]}" "${subdir}"
for x in "${subdir}"* ; do
if [ -d "${x}" ]; then
- setfacl -bk ${x}
- setfacl "${dirusers[@]}" "${dirgroups[@]}" ${x}
+ setfacl -bk "${x}"
+ setfacl "${dirusers[@]}" "${dirgroups[@]}" "${x}"
update_subdir "${x}/"
elif [ -e "${x}" ]; then
- setfacl -bk ${x}
- setfacl "${fileusers[@]}" "${filegroups[@]}" ${x}
+ setfacl -bk "${x}"
+ setfacl "${fileusers[@]}" "${filegroups[@]}" "${x}"
else
:;
fi
--
2.29.2

View file

@ -0,0 +1,26 @@
From 16b80efae3c932d2b966b0ee0095de367aa31c3a Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 14 Jul 2020 15:08:15 -0400
Subject: [PATCH 36/42] pesign-authorize: don't setfacl /etc/pki/pesign-foo/
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/pesign-authorize | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/pesign-authorize b/src/pesign-authorize
index 55cd5c4e55b..c5448329c2c 100755
--- a/src/pesign-authorize
+++ b/src/pesign-authorize
@@ -47,7 +47,7 @@ update_subdir() {
done
}
-for x in /var/run/pesign/ /etc/pki/pesign*/ ; do
+for x in /var/run/pesign/ /etc/pki/pesign/ ; do
if [ -d "${x}" ]; then
update_subdir "${x}"
else
--
2.29.2

View file

@ -0,0 +1,41 @@
From 59e539c55f22e838b7781efb3357da0d8f4de7db Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 14 Jul 2020 16:42:39 -0400
Subject: [PATCH 37/42] kernel building hack
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/pesign-rpmbuild-helper.in | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/src/pesign-rpmbuild-helper.in b/src/pesign-rpmbuild-helper.in
index c5287c27e0c..27b8261bc17 100644
--- a/src/pesign-rpmbuild-helper.in
+++ b/src/pesign-rpmbuild-helper.in
@@ -202,6 +202,23 @@ main() {
"${input[@]}" "${output[@]}"
rm -rf "${sattrs}" "${sattrs}.sig" "${nssdir}"
elif [[ -n "${socket}" ]] ; then
+ ### welcome haaaaack city
+ if [[ "${client_token[1]}" = "OpenSC Card (Fedora Signer)" ]] ; then
+ if [[ "${input[1]}" =~ (/|^)vmlinuz($|[_.-]) ]] \
+ || [[ "${input[1]}" =~ (/|^)bzImage($|[_.-]) ]] ; then
+ if [[ "${rhelcertfile}" =~ redhatsecureboot501.* ]] \
+ || [[ "${rhelcertfile}" =~ redhatsecureboot401.* ]] \
+ || [[ "${rhelcertfile}" =~ centossecureboot201.* ]] ; then
+ client_cert[1]=kernel-signer
+ elif [[ "${rhelcertfile}" =~ redhatsecureboot502.* ]] \
+ || [[ "${rhelcertfile}" =~ centossecureboot202.* ]] ; then
+ client_cert[1]=grub2-signer
+ elif [[ "${rhelcertfile}" =~ redhatsecureboot503.* ]] \
+ || [[ "${rhelcertfile}" =~ centossecureboot203.* ]] ; then
+ client_cert[1]=fwupd-signer
+ fi
+ fi
+ fi
"${client}" "${client_token[@]}" "${client_cert[@]}" \
"${sattrout[@]}" "${certout[@]}" \
${sign} "${input[@]}" "${output[@]}"
--
2.29.2

View file

@ -0,0 +1,105 @@
From 36a87a0471f79346dc245ba62bdaaddf1e9c908e Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Thu, 16 Jul 2020 16:28:26 -0400
Subject: [PATCH 38/42] Use /run not /var/run
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/daemon.h | 4 ++--
src/Makefile | 2 +-
src/pesign-authorize | 2 +-
src/pesign.service.in | 2 +-
src/pesign.sysvinit.in | 10 +++++-----
5 files changed, 10 insertions(+), 10 deletions(-)
diff --git a/src/daemon.h b/src/daemon.h
index 0368dc9256c..5fcd97ea717 100644
--- a/src/daemon.h
+++ b/src/daemon.h
@@ -51,8 +51,8 @@ typedef enum {
} pesignd_cmd;
#define PESIGND_VERSION 0x2a9edaf0
-#define SOCKPATH "/var/run/pesign/socket"
-#define PIDFILE "/var/run/pesign.pid"
+#define SOCKPATH "/run/pesign/socket"
+#define PIDFILE "/run/pesign.pid"
static inline uint32_t UNUSED
pesignd_string_size(char *buffer)
diff --git a/src/Makefile b/src/Makefile
index 82c2dfdec3f..e24bd600af0 100644
--- a/src/Makefile
+++ b/src/Makefile
@@ -83,7 +83,7 @@ install_sysvinit: pesign.sysvinit
install :
$(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign/
$(INSTALL) -d -m 700 $(INSTALLROOT)/etc/pki/pesign-rh-test/
- $(INSTALL) -d -m 770 $(INSTALLROOT)/var/run/pesign/
+ $(INSTALL) -d -m 770 $(INSTALLROOT)/run/pesign/
$(INSTALL) -d -m 755 $(INSTALLROOT)$(bindir)
$(INSTALL) -m 755 authvar $(INSTALLROOT)$(bindir)
$(INSTALL) -m 755 pesign $(INSTALLROOT)$(bindir)
diff --git a/src/pesign-authorize b/src/pesign-authorize
index c5448329c2c..2381302440c 100755
--- a/src/pesign-authorize
+++ b/src/pesign-authorize
@@ -47,7 +47,7 @@ update_subdir() {
done
}
-for x in /var/run/pesign/ /etc/pki/pesign/ ; do
+for x in /run/pesign/ /var/run/pesign/ /etc/pki/pesign/ ; do
if [ -d "${x}" ]; then
update_subdir "${x}"
else
diff --git a/src/pesign.service.in b/src/pesign.service.in
index c75a000892a..4ac2199bce2 100644
--- a/src/pesign.service.in
+++ b/src/pesign.service.in
@@ -4,6 +4,6 @@ Description=Pesign signing daemon
[Service]
PrivateTmp=true
Type=forking
-PIDFile=/var/run/pesign.pid
+PIDFile=/run/pesign.pid
ExecStart=/usr/bin/pesign --daemonize
ExecStartPost=@@LIBEXECDIR@@/pesign/pesign-authorize
diff --git a/src/pesign.sysvinit.in b/src/pesign.sysvinit.in
index b0e0f84ff0b..bf8edec8ff3 100644
--- a/src/pesign.sysvinit.in
+++ b/src/pesign.sysvinit.in
@@ -4,7 +4,7 @@
#
# chkconfig: - 50 50
# processname: /usr/bin/pesign
-# pidfile: /var/run/pesign.pid
+# pidfile: /run/pesign.pid
### BEGIN INIT INFO
# Provides: pesign
# Default-Start:
@@ -20,9 +20,9 @@ RETVAL=0
start(){
echo -n "Starting pesign: "
- mkdir /var/run/pesign 2>/dev/null &&
- chown pesign:pesign /var/run/pesign &&
- chmod 0770 /var/run/pesign
+ mkdir /run/pesign 2>/dev/null &&
+ chown pesign:pesign /run/pesign &&
+ chmod 0770 /run/pesign
daemon /usr/bin/pesign --daemonize
RETVAL=$?
echo
@@ -32,7 +32,7 @@ start(){
stop(){
echo -n "Stopping pesign: "
- killproc -p /var/run/pesign.pid pesignd
+ killproc -p /run/pesign.pid pesignd
RETVAL=$?
echo
rm -f /var/lock/subsys/pesign
--
2.29.2

View file

@ -0,0 +1,43 @@
From 854b9ea4fe5b743f643f8622e5a1ec26dd1eb2dc Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 16 Feb 2021 11:38:27 -0500
Subject: [PATCH 39/42] efikeygen: return error on AKID encoding failures
Clearly some of these exiting with nonsense error codes and some of them
returning error values is not how it's supposed to be.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/efikeygen.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/src/efikeygen.c b/src/efikeygen.c
index b1cac4705e8..8bf67c2ec20 100644
--- a/src/efikeygen.c
+++ b/src/efikeygen.c
@@ -156,11 +156,11 @@ add_auth_key_id(cms_context *cms, void *extHandle, SECKEYPublicKey *pubkey)
{
SECItem *pubkey_der = PK11_DEREncodePublicKey(pubkey);
if (!pubkey_der)
- cmserr(-1, cms, "could not encode CA Key ID extension");
+ cmsreterr(-1, cms, "could not encode CA Key ID extension");
SECItem *encoded = PK11_MakeIDFromPubKey(pubkey_der);
if (!encoded)
- cmserr(-1, cms, "could not encode CA Key ID extension");
+ cmsreterr(-1, cms, "could not encode CA Key ID extension");
SECItem cspecific = { 0 };
int rc = make_context_specific(cms, 0, &cspecific, encoded);
@@ -178,7 +178,7 @@ add_auth_key_id(cms_context *cms, void *extHandle, SECKEYPublicKey *pubkey)
status = CERT_AddExtension(extHandle, SEC_OID_X509_AUTH_KEY_ID,
&wrapped, PR_FALSE, PR_TRUE);
if (status != SECSuccess)
- cmserr(-1, cms, "could not encode CA Key ID extension");
+ cmsreterr(-1, cms, "could not encode CA Key ID extension");
return 0;
}
--
2.29.2

View file

@ -0,0 +1,567 @@
From eaf8471d14e54aa17802ce4d131db2d2440a69f9 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 16 Feb 2021 12:00:50 -0500
Subject: [PATCH 40/42] Rename some cms error functions
Some of these were really not clear, and efikeygen was misusing them.
This adds a couple more and disambiguates some of their names a bit.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/cms_common.c | 141 +++++++++++++++++++-------------------------
src/cms_pe_common.c | 8 +--
src/cms_common.h | 23 ++++++--
3 files changed, 80 insertions(+), 92 deletions(-)
diff --git a/src/cms_common.c b/src/cms_common.c
index e274a8a50da..4bbd5f5cfa9 100644
--- a/src/cms_common.c
+++ b/src/cms_common.c
@@ -152,7 +152,7 @@ cms_context_init(cms_context *cms)
cms->arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
if (!cms->arena)
- cmsreterr(-1, cms, "could not create cryptographic arena");
+ cnreterr(-1, cms, "could not create cryptographic arena");
cms->selected_digest = -1;
@@ -498,7 +498,7 @@ unlock_nss_token(cms_context *cms)
PK11SlotList *slots = NULL;
slots = PK11_GetAllTokens(CKM_RSA_PKCS, PR_FALSE, PR_TRUE, cms);
if (!slots)
- cmsreterr(-1, cms, "could not get pk11 token list");
+ cnreterr(-1, cms, "could not get pk11 token list");
PK11SlotListElement *psle = NULL;
@@ -507,7 +507,7 @@ unlock_nss_token(cms_context *cms)
save_port_err() {
PK11_FreeSlotList(slots);
}
- cmsreterr(-1, cms, "could not get pk11 safe");
+ cnreterr(-1, cms, "could not get pk11 safe");
}
while (psle) {
@@ -563,7 +563,7 @@ find_certificate(cms_context *cms, int needs_private_key)
PK11SlotList *slots = NULL;
slots = PK11_GetAllTokens(CKM_RSA_PKCS, PR_FALSE, PR_TRUE, cms);
if (!slots)
- cmsreterr(-1, cms, "could not get pk11 token list");
+ cnreterr(-1, cms, "could not get pk11 token list");
PK11SlotListElement *psle = NULL;
psle = PK11_GetFirstSafe(slots);
@@ -571,7 +571,7 @@ find_certificate(cms_context *cms, int needs_private_key)
save_port_err() {
PK11_FreeSlotList(slots);
}
- cmsreterr(-1, cms, "could not get pk11 safe");
+ cnreterr(-1, cms, "could not get pk11 safe");
}
while (psle) {
@@ -616,7 +616,7 @@ find_certificate(cms_context *cms, int needs_private_key)
PK11_DestroySlotListElement(slots, &psle);
PK11_FreeSlotList(slots);
}
- cmsreterr(-1, cms, "could not get certificate list");
+ cnreterr(-1, cms, "could not get certificate list");
}
SECItem nickname = {
@@ -673,7 +673,7 @@ find_certificate(cms_context *cms, int needs_private_key)
cms->psle = NULL;
}
if (status != SECSuccess || cms->cert == NULL)
- cmsreterr(-1, cms, "could not find certificate");
+ cnreterr(-1, cms, "could not find certificate");
return 0;
}
@@ -694,7 +694,7 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot)
PK11SlotList *slots = NULL;
slots = PK11_GetAllTokens(CKM_RSA_PKCS, PR_FALSE, PR_TRUE, cms);
if (!slots)
- cmsreterr(-1, cms, "could not get pk11 token list");
+ cnreterr(-1, cms, "could not get pk11 token list");
PK11SlotListElement *psle = NULL;
psle = PK11_GetFirstSafe(slots);
@@ -702,7 +702,7 @@ find_slot_for_token(cms_context *cms, PK11SlotInfo **slot)
save_port_err() {
PK11_FreeSlotList(slots);
}
- cmsreterr(-1, cms, "could not get pk11 safe");
+ cnreterr(-1, cms, "could not get pk11 safe");
}
while (psle) {
@@ -760,7 +760,7 @@ find_certificate_by_callback(cms_context *cms,
PK11SlotList *slots = NULL;
slots = PK11_GetAllTokens(CKM_RSA_PKCS, PR_FALSE, PR_TRUE, cms);
if (!slots)
- cmsreterr(-1, cms, "could not get pk11 token list");
+ cnreterr(-1, cms, "could not get pk11 token list");
PK11SlotListElement *psle = NULL;
psle = PK11_GetFirstSafe(slots);
@@ -768,7 +768,7 @@ find_certificate_by_callback(cms_context *cms,
save_port_err() {
PK11_FreeSlotList(slots);
}
- cmsreterr(-1, cms, "could not get pk11 safe");
+ cnreterr(-1, cms, "could not get pk11 safe");
}
while (psle) {
@@ -810,7 +810,7 @@ find_certificate_by_callback(cms_context *cms,
PK11_DestroySlotListElement(slots, &psle);
PK11_FreeSlotList(slots);
}
- cmsreterr(-1, cms, "could not get certificate list");
+ cnreterr(-1, cms, "could not get certificate list");
}
CERTCertListNode *node = NULL;
@@ -837,7 +837,7 @@ find_certificate_by_callback(cms_context *cms,
}
if (!node)
- cmsreterr(-1, cms, "Could not find certificate");
+ cnreterr(-1, cms, "Could not find certificate");
*cert = CERT_DupCertificate(node->cert);
@@ -865,7 +865,7 @@ int
find_named_certificate(cms_context *cms, char *name, CERTCertificate **cert)
{
if (!name)
- cmsreterr(-1, cms, "no subject name specified");
+ cnreterr(-1, cms, "no subject name specified");
return find_certificate_by_callback(cms, match_subject, name, cert);
}
@@ -908,7 +908,7 @@ find_certificate_by_issuer_and_sn(cms_context *cms,
CERTCertificate **cert)
{
if (!ias)
- cmsreterr(-1, cms, "invalid issuer and serial number");
+ cnreterr(-1, cms, "invalid issuer and serial number");
return find_certificate_by_callback(cms, match_issuer_and_serial, &ias, cert);
}
@@ -926,7 +926,7 @@ generate_string(cms_context *cms, SECItem *der, char *str)
ret = SEC_ASN1EncodeItem(cms->arena, der, &input,
SEC_PrintableStringTemplate);
if (ret == NULL)
- cmsreterr(-1, cms, "could not encode string");
+ cnreterr(-1, cms, "could not encode string");
return 0;
}
@@ -946,11 +946,11 @@ generate_time(cms_context *cms, SECItem *encoded, time_t when)
tm->tm_year % 100, tm->tm_mon + 1, tm->tm_mday,
tm->tm_hour, tm->tm_min, tm->tm_sec);
if (whenitem.len == 32)
- cmsreterr(-1, cms, "could not encode timestamp");
+ cnreterr(-1, cms, "could not encode timestamp");
if (SEC_ASN1EncodeItem(cms->arena, encoded, &whenitem,
SEC_UTCTimeTemplate) == NULL)
- cmsreterr(-1, cms, "could not encode timestamp");
+ cnreterr(-1, cms, "could not encode timestamp");
return 0;
}
@@ -975,7 +975,7 @@ generate_empty_sequence(cms_context *cms, SECItem *encoded)
ret = SEC_ASN1EncodeItem(cms->arena, encoded, &empty,
EmptySequenceTemplate);
if (ret == NULL)
- cmsreterr(-1, cms, "could not encode empty sequence");
+ cnreterr(-1, cms, "could not encode empty sequence");
return 0;
}
@@ -1000,7 +1000,7 @@ make_context_specific(cms_context *cms, int ctxt, SECItem *encoded,
rv = SEC_ASN1EncodeItem(cms->arena, encoded, original,
ContextSpecificSequence);
if (rv == NULL)
- cmsreterr(-1, cms, "could not encode context specific data");
+ cnreterr(-1, cms, "could not encode context specific data");
return 0;
}
@@ -1022,12 +1022,12 @@ make_eku_oid(cms_context *cms, SECItem *encoded, SECOidTag oid_tag)
oid_data = SECOID_FindOIDByTag(oid_tag);
if (!oid_data)
- cmsreterr(-1, cms, "could not encode eku oid data");
+ cnreterr(-1, cms, "could not encode eku oid data");
rv = SEC_ASN1EncodeItem(cms->arena, encoded, &oid_data->oid,
EKUOidSequence);
if (rv == NULL)
- cmsreterr(-1, cms, "could not encode eku oid data");
+ cnreterr(-1, cms, "could not encode eku oid data");
encoded->type = siBuffer;
return 0;
@@ -1042,7 +1042,7 @@ generate_octet_string(cms_context *cms, SECItem *encoded, SECItem *original)
}
if (SEC_ASN1EncodeItem(cms->arena, encoded, original,
SEC_OctetStringTemplate) == NULL)
- cmsreterr(-1, cms, "could not encode octet string");
+ cnreterr(-1, cms, "could not encode octet string");
return 0;
}
@@ -1054,13 +1054,13 @@ generate_object_id(cms_context *cms, SECItem *der, SECOidTag tag)
oid = SECOID_FindOIDByTag(tag);
if (!oid)
- cmsreterr(-1, cms, "could not find OID");
+ cnreterr(-1, cms, "could not find OID");
void *ret;
ret = SEC_ASN1EncodeItem(cms->arena, der, &oid->oid,
SEC_ObjectIDTemplate);
if (ret == NULL)
- cmsreterr(-1, cms, "could not encode ODI");
+ cnreterr(-1, cms, "could not encode ODI");
return 0;
}
@@ -1109,7 +1109,7 @@ encode_algorithm_id(cms_context *cms, SECItem *der, SECOidTag tag)
ret = SEC_ASN1EncodeItem(cms->arena, der, &id,
SECOID_AlgorithmIDTemplate);
if (ret == NULL)
- cmsreterr(-1, cms, "could not encode Algorithm ID");
+ cnreterr(-1, cms, "could not encode Algorithm ID");
return 0;
}
@@ -1144,14 +1144,14 @@ generate_spc_string(cms_context *cms, SECItem *ssp, char *str, int len)
SECITEM_AllocItem(cms->arena, &ss.unicode, len);
if (len != 0) {
if (!ss.unicode.data)
- cmsreterr(-1, cms, "could not allocate memory");
+ cnreterr(-1, cms, "could not allocate memory");
memcpy(ss.unicode.data, str, len);
}
ss.unicode.type = siBMPString;
if (SEC_ASN1EncodeItem(cms->arena, ssp, &ss, SpcStringTemplate) == NULL)
- cmsreterr(-1, cms, "could not encode SpcString");
+ cnreterr(-1, cms, "could not encode SpcString");
return 0;
}
@@ -1224,19 +1224,14 @@ generate_digest_begin(cms_context *cms)
} else {
digests = PORT_ZAlloc(n_digest_params * sizeof (*digests));
if (digests == NULL)
- cmsreterr(-1, cms, "could not allocate digest context");
+ cnreterr(-1, cms, "could not allocate digest context");
}
for (int i = 0; i < n_digest_params; i++) {
digests[i].pk11ctx = PK11_CreateDigestContext(
digest_params[i].digest_tag);
- if (!digests[i].pk11ctx) {
- cms->log(cms, LOG_ERR, "%s:%s:%d could not create "
- "digest context: %s",
- __FILE__, __func__, __LINE__,
- PORT_ErrorToString(PORT_GetError()));
- goto err;
- }
+ if (!digests[i].pk11ctx)
+ cngotoerr(err, cms, "could not create digest context");
PK11_DigestBegin(digests[i].pk11ctx);
}
@@ -1268,22 +1263,14 @@ generate_digest_finish(cms_context *cms)
for (int i = 0; i < n_digest_params; i++) {
SECItem *digest = PORT_ArenaZAlloc(cms->arena,sizeof (SECItem));
- if (digest == NULL) {
- cms->log(cms, LOG_ERR, "%s:%s:%d could not allocate "
- "memory: %s", __FILE__, __func__, __LINE__,
- PORT_ErrorToString(PORT_GetError()));
- goto err;
- }
+ if (digest == NULL)
+ cngotoerr(err, cms, "could not allocate memory");
digest->type = siBuffer;
digest->len = digest_params[i].size;
digest->data = PORT_ArenaZAlloc(cms->arena, digest_params[i].size);
- if (digest->data == NULL) {
- cms->log(cms, LOG_ERR, "%s:%s:%d could not allocate "
- "memory: %s", __FILE__, __func__, __LINE__,
- PORT_ErrorToString(PORT_GetError()));
- goto err;
- }
+ if (digest->data == NULL)
+ cngotoerr(err, cms, "could not allocate memory");
PK11_DigestFinal(cms->digests[i].pk11ctx,
digest->data, &digest->len, digest_params[i].size);
@@ -1319,29 +1306,23 @@ generate_signature(cms_context *cms)
{
int rc = 0;
- if (cms->digests[cms->selected_digest].pe_digest == NULL) {
- cms->log(cms, LOG_ERR, "%s:%s:%d PE digest has not been "
- "allocated", __FILE__, __func__, __LINE__);
- return -1;
- }
+ if (cms->digests[cms->selected_digest].pe_digest == NULL)
+ cnreterr(-1, cms, "PE digest has not been allocated");
if (content_is_empty(cms->digests[cms->selected_digest].pe_digest->data,
- cms->digests[cms->selected_digest].pe_digest->len)) {
- cms->log(cms, LOG_ERR, "%s:%s:%d PE binary has not been "
- "digested", __FILE__, __func__, __LINE__);
- return -1;
- }
+ cms->digests[cms->selected_digest].pe_digest->len))
+ cnreterr(-1, cms, "PE binary has not been digested");
SECItem sd_der;
memset(&sd_der, '\0', sizeof(sd_der));
rc = generate_spc_signed_data(cms, &sd_der);
if (rc < 0)
- cmsreterr(-1, cms, "could not create signed data");
+ cnreterr(-1, cms, "could not create signed data");
memcpy(&cms->newsig, &sd_der, sizeof (cms->newsig));
cms->newsig.data = malloc(sd_der.len);
if (!cms->newsig.data)
- cmsreterr(-1, cms, "could not allocate signed data");
+ cnreterr(-1, cms, "could not allocate signed data");
memcpy(cms->newsig.data, sd_der.data, sd_der.len);
return 0;
}
@@ -1387,7 +1368,7 @@ generate_validity(cms_context *cms, SECItem *der, time_t start, time_t end)
void *ret;
ret = SEC_ASN1EncodeItem(cms->arena, der, &validity, ValidityTemplate);
if (ret == NULL)
- cmsreterr(-1, cms, "could not encode validity");
+ cnreterr(-1, cms, "could not encode validity");
return 0;
}
@@ -1405,7 +1386,7 @@ wrap_in_set(cms_context *cms, SECItem *der, SECItem **items)
ret = SEC_ASN1EncodeItem(cms->arena, der, &items, &SetTemplate);
if (ret == NULL)
- cmsreterr(-1, cms, "could not encode set");
+ cnreterr(-1, cms, "could not encode set");
return 0;
}
@@ -1447,7 +1428,7 @@ wrap_in_seq(cms_context *cms, SECItem *der, SECItem *items, int num_items)
save_port_err() {
PORT_ArenaRelease(cms->arena, mark);
}
- cmsreterr(-1, cms, "could not encode set");
+ cnreterr(-1, cms, "could not encode set");
}
PORT_ArenaUnmark(cms->arena, mark);
return rc;
@@ -1494,7 +1475,7 @@ generate_common_name(cms_context *cms, SECItem *der, char *cn_str)
void *ret;
ret = SEC_ASN1EncodeItem(cms->arena, &cn_item, &cn, CommonNameTemplate);
if (ret == NULL)
- cmsreterr(-1, cms, "could not encode common name");
+ cnreterr(-1, cms, "could not encode common name");
SECItem cn_set;
SECItem *items[2] = {&cn_item, NULL};
@@ -1542,7 +1523,7 @@ generate_ava(cms_context *cms, SECItem *der, CERTAVA *certava)
void *arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
if (arena == NULL)
- cmsreterr(-1, cms, "could not create arena");
+ cnreterr(-1, cms, "could not create arena");
void *real_arena = cms->arena;
cms->arena = arena;
@@ -1553,7 +1534,7 @@ generate_ava(cms_context *cms, SECItem *der, CERTAVA *certava)
PORT_FreeArena(arena, PR_TRUE);
}
cms->arena = real_arena;
- cmsreterr(-1, cms, "could not find OID");
+ cnreterr(-1, cms, "could not find OID");
}
int rc = generate_object_id(cms, &ava.type, oid->offset);
@@ -1573,7 +1554,7 @@ generate_ava(cms_context *cms, SECItem *der, CERTAVA *certava)
PORT_FreeArena(arena, PR_TRUE);
}
cms->arena = real_arena;
- cmsreterr(-1, cms, "could not encode AVA");
+ cnreterr(-1, cms, "could not encode AVA");
}
der->type = tmp.type;
@@ -1584,7 +1565,7 @@ generate_ava(cms_context *cms, SECItem *der, CERTAVA *certava)
PORT_FreeArena(arena, PR_TRUE);
}
cms->arena = real_arena;
- cmsreterr(-1, cms, "could not allocate AVA");
+ cnreterr(-1, cms, "could not allocate AVA");
}
memcpy(der->data, tmp.data, tmp.len);
PORT_FreeArena(arena, PR_TRUE);
@@ -1612,7 +1593,7 @@ generate_name(cms_context *cms, SECItem *der, CERTName *certname)
if (num_items == 0) {
PORT_ArenaRelease(cms->arena, marka);
- cmsreterr(-1, cms, "No name items to encode");
+ cnreterr(-1, cms, "No name items to encode");
}
SECItem items[num_items];
@@ -1698,7 +1679,7 @@ generate_auth_info(cms_context *cms, SECItem *der, char *url)
SECOidData *oid = SECOID_FindOIDByTag(SEC_OID_PKIX_CA_ISSUERS);
if (!oid)
- cmsreterr(-1, cms, "could not get CA issuers OID");
+ cnreterr(-1, cms, "could not get CA issuers OID");
memcpy(&ai.oid, &oid->oid, sizeof (ai.oid));
@@ -1715,7 +1696,7 @@ generate_auth_info(cms_context *cms, SECItem *der, char *url)
SECItem unwrapped;
ret = SEC_ASN1EncodeItem(cms->arena, &unwrapped, &ai, AuthInfoTemplate);
if (ret == NULL)
- cmsreterr(-1, cms, "could not encode CA Issuers");
+ cnreterr(-1, cms, "could not encode CA Issuers");
rc = wrap_in_seq(cms, der, &unwrapped, 1);
if (rc < 0)
@@ -1725,19 +1706,17 @@ generate_auth_info(cms_context *cms, SECItem *der, char *url)
/* I've no idea how to get SEC_ASN1EncodeItem to spit out the thing
* we actually want here. So once again, just force the data to
* look correct :( */
- if (unwrapped.len < 12) {
- cms->log(cms, LOG_ERR, "%s:%s:%d generated CA Issuers Info "
- "cannot possibly be valid",
- __FILE__, __func__, __LINE__);
- return -1;
- }
+ if (unwrapped.len < 12)
+ cnreterr(-1, cms,
+ "generated CA Issuers Info cannot possibly be valid");
+
unwrapped.data[12] = 0x86;
unwrapped.type = siBuffer;
AuthInfo wrapper;
oid = SECOID_FindOIDByTag(SEC_OID_X509_AUTH_INFO_ACCESS);
if (!oid)
- cmsreterr(-1, cms, "could not find Auth Info Access OID");
+ cnreterr(-1, cms, "could not find Auth Info Access OID");
memcpy(&wrapper.oid, &oid->oid, sizeof (ai.oid));
@@ -1746,7 +1725,7 @@ generate_auth_info(cms_context *cms, SECItem *der, char *url)
ret = SEC_ASN1EncodeItem(cms->arena, der, &wrapper,
AuthInfoWrapperTemplate);
if (ret == NULL)
- cmsreterr(-1, cms, "could not encode CA Issuers OID");
+ cnreterr(-1, cms, "could not encode CA Issuers OID");
return 0;
}
@@ -1763,14 +1742,14 @@ generate_keys(cms_context *cms, PK11SlotInfo *slot,
SECStatus rv;
rv = PK11_Authenticate(slot, PR_TRUE, cms);
if (rv != SECSuccess)
- cmsreterr(-1, cms, "could not authenticate with pk11 service");
+ cnreterr(-1, cms, "could not authenticate with pk11 service");
void *params = &rsaparams;
*privkey = PK11_GenerateKeyPair(slot, CKM_RSA_PKCS_KEY_PAIR_GEN,
params, pubkey, PR_TRUE, PR_TRUE,
cms);
if (!*privkey)
- cmsreterr(-1, cms, "could not generate RSA keypair");
+ cnreterr(-1, cms, "could not generate RSA keypair");
return 0;
}
diff --git a/src/cms_pe_common.c b/src/cms_pe_common.c
index e5a33eb6fe1..f6c5cffc6a9 100644
--- a/src/cms_pe_common.c
+++ b/src/cms_pe_common.c
@@ -165,7 +165,7 @@ generate_digest(cms_context *cms, Pe *pe, int padded)
* 2. Initialize SHA hash context. */
map = pe_rawfile(pe, &map_size);
if (!map)
- pereterr(-1, "could not get raw output file address");
+ cmsreterr(-1, cms, "could not get raw output file address");
/* 3. Calculate the distance from the base of the image header to the
* image checksum.
@@ -174,10 +174,8 @@ generate_digest(cms_context *cms, Pe *pe, int padded)
hash_base = map;
opthdr = pe_getopthdr(pe);
- if (opthdr == NULL) {
- cms->log(cms, LOG_ERR, "%s:%s:%d PE header is invalid", __FILE__, __func__, __LINE__);
- goto error;
- }
+ if (opthdr == NULL)
+ cmsgotoerr(error, cms, "PE header is invalid");
switch (pe_kind(pe)) {
case PE_K_PE_EXE: {
diff --git a/src/cms_common.h b/src/cms_common.h
index 04974035f0c..1bffdcd034b 100644
--- a/src/cms_common.h
+++ b/src/cms_common.h
@@ -41,19 +41,30 @@
#define for_each_cert(cl, node) \
for (CERTCertListNode *node = CERT_LIST_HEAD(cl); !CERT_LIST_END(node, cl); node = CERT_LIST_NEXT(node))
-#define cmserr(rv, cms, fmt, args...) ({ \
- (cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt ": %s", \
- __FILE__, __func__, __LINE__, ## args, \
- PORT_ErrorToString(PORT_GetError())); \
- exit(rv); \
+#define cmsreterr(rv, cms, fmt, args...) ({ \
+ (cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt, \
+ __FILE__, __func__, __LINE__, ## args); \
+ return rv; \
})
-#define cmsreterr(rv, cms, fmt, args...) ({ \
+#define cmsgotoerr(errlabel, cms, fmt, args...) ({ \
+ (cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt, \
+ __FILE__, __func__, __LINE__, ## args); \
+ goto errlabel; \
+ })
+#define cnreterr(rv, cms, fmt, args...) ({ \
(cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt ":%s:%s", \
__FILE__, __func__, __LINE__, ## args, \
PORT_ErrorToName(PORT_GetError()), \
PORT_ErrorToString(PORT_GetError())); \
return rv; \
})
+#define cngotoerr(errlabel, cms, fmt, args...) ({ \
+ (cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt ":%s:%s", \
+ __FILE__, __func__, __LINE__, ## args, \
+ PORT_ErrorToName(PORT_GetError()), \
+ PORT_ErrorToString(PORT_GetError())); \
+ goto errlabel; \
+ })
struct digest {
PK11Context *pk11ctx;
--
2.29.2

View file

@ -0,0 +1,181 @@
From 2802ad709872f8291786ce31400a3496bbe23b14 Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 16 Feb 2021 11:19:30 -0500
Subject: [PATCH 41/42] Make cms_pe_common bounds check errors more verbose
One of these is failing for hughsie, and that's weird, so I want to know
why.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/cms_pe_common.c | 76 +++++++++++++++++++--------------------------
1 file changed, 32 insertions(+), 44 deletions(-)
diff --git a/src/cms_pe_common.c b/src/cms_pe_common.c
index f6c5cffc6a9..bdcfaff99f8 100644
--- a/src/cms_pe_common.c
+++ b/src/cms_pe_common.c
@@ -43,29 +43,30 @@
#include <certt.h>
static int
-check_pointer_and_size(Pe *pe, void *ptr, size_t size)
+check_pointer_and_size(cms_context *cms, Pe *pe, void *ptr, size_t size)
{
void *map = NULL;
size_t map_size = 0;
map = pe_rawfile(pe, &map_size);
if (!map || map_size < 1)
- return 0;
+ cmsreterr(0, cms, "mmap is %p mmap size is %zd end is %p",
+ map, map_size, (void *)((uintptr_t)map + map_size));
if ((uintptr_t)ptr < (uintptr_t)map)
- return 0;
+ cmsreterr(0, cms, "pointer %p is below mmap at %p", ptr, map);
if ((uintptr_t)ptr + size > (uintptr_t)map + map_size)
- return 0;
-
- if (ptr <= map && size >= map_size)
- return 0;
+ cmsreterr(0, cms,
+ "pointer region end %p is above mmap end at %p",
+ (void *)((uintptr_t)ptr + size),
+ (void *)((uintptr_t)map + map_size));
return 1;
}
static void *
-get_strtab(Pe *pe)
+get_strtab(cms_context *cms, Pe *pe)
{
static void *ret = NULL;
uint32_t *ptr;
@@ -91,17 +92,17 @@ get_strtab(Pe *pe)
intret += pehdr.symbols * sizeof(struct pe_symtab_entry);
ptr = (uint32_t *)((intptr_t)map + intret);
- if (!check_pointer_and_size(pe, ptr, 4))
+ if (!check_pointer_and_size(cms, pe, ptr, 4))
pereterr(NULL, "invalid string table start");
- if (!check_pointer_and_size(pe, ptr, *ptr))
+ if (!check_pointer_and_size(cms, pe, ptr, *ptr))
pereterr(NULL, "invalid string table size");
ret = ptr;
return ret;
}
static char *
-get_str(Pe *pe, char *strnum)
+get_str(cms_context *cms, Pe *pe, char *strnum)
{
size_t sz;
unsigned long num;
@@ -120,7 +121,7 @@ get_str(Pe *pe, char *strnum)
if (errno != 0)
return NULL;
- strtab = get_strtab(pe);
+ strtab = get_strtab(cms, pe);
if (!strtab)
return NULL;
@@ -191,11 +192,8 @@ generate_digest(cms_context *cms, Pe *pe, int padded)
default:
goto error;
}
- if (!check_pointer_and_size(pe, hash_base, hash_size)) {
- cms->log(cms, LOG_ERR, "%s:%s:%d PE header is invalid",
- __FILE__, __func__, __LINE__);
- goto error;
- }
+ if (!check_pointer_and_size(cms, pe, hash_base, hash_size))
+ cmsgotoerr(error, cms, "PE header is invalid");
dprintf("beginning of hash");
dprintf("digesting %lx + %lx", hash_base - map, hash_size);
generate_digest_step(cms, hash_base, hash_size);
@@ -209,18 +207,13 @@ generate_digest(cms_context *cms, Pe *pe, int padded)
data_directory *dd;
rc = pe_getdatadir(pe, &dd);
- if (rc < 0 || !dd || !check_pointer_and_size(pe, dd, sizeof(*dd))) {
- cms->log(cms, LOG_ERR, "%s:%s:%d PE data directory is invalid",
- __FILE__, __func__, __LINE__);
- goto error;
- }
+ if (rc < 0 || !dd || !check_pointer_and_size(cms, pe, dd, sizeof(*dd)))
+ cmsgotoerr(error, cms, "PE data directory is invalid");
hash_size = (uintptr_t)&dd->certs - (uintptr_t)hash_base;
- if (!check_pointer_and_size(pe, hash_base, hash_size)) {
- cms->log(cms, LOG_ERR, "%s:%s:%d PE data directory is invalid",
- __FILE__, __func__, __LINE__);
- goto error;
- }
+ if (!check_pointer_and_size(cms, pe, hash_base, hash_size))
+ cmsgotoerr(error, cms, "PE data directory is invalid");
+
generate_digest_step(cms, hash_base, hash_size);
dprintf("digesting %lx + %lx", hash_base - map, hash_size);
@@ -231,11 +224,9 @@ generate_digest(cms_context *cms, Pe *pe, int padded)
: pe64opthdr->header_size) -
((uintptr_t)&dd->base_relocations - (uintptr_t)map);
- if (!check_pointer_and_size(pe, hash_base, hash_size)) {
- cms->log(cms, LOG_ERR, "%s:%s:%d PE relocations table is "
- "invalid", __FILE__, __func__, __LINE__);
- goto error;
- }
+ if (!check_pointer_and_size(cms, pe, hash_base, hash_size))
+ cmsgotoerr(error, cms, "PE relocations table is invalid");
+
generate_digest_step(cms, hash_base, hash_size);
dprintf("digesting %lx + %lx", hash_base - map, hash_size);
@@ -262,17 +253,15 @@ generate_digest(cms_context *cms, Pe *pe, int padded)
hash_base = (void *)((uintptr_t)map + shdrs[i].data_addr);
hash_size = shdrs[i].raw_data_size;
- if (!check_pointer_and_size(pe, hash_base, hash_size)) {
- cms->log(cms, LOG_ERR, "%s:%s:%d PE section \"%s\" "
- "has invalid address",
- __FILE__, __func__, __LINE__, shdrs[i].name);
- goto error_shdrs;
- }
+ if (!check_pointer_and_size(cms, pe, hash_base, hash_size))
+ cmsgotoerr(error_shdrs, cms,
+ "PE section \"%s\" has invalid address",
+ shdrs[i].name);
if (cms->omit_vendor_cert) {
char *name = shdrs[i].name;
if (name && name[0] == '/')
- name = get_str(pe, name + 1);
+ name = get_str(cms, pe, name + 1);
dprintf("section:\"%s\"", name ? name : "(null)");
if (name && !strcmp(name, ".vendor_cert")) {
dprintf("skipping .vendor_cert section");
@@ -291,11 +280,10 @@ generate_digest(cms_context *cms, Pe *pe, int padded)
hash_base = (void *)((uintptr_t)map + hashed_bytes);
hash_size = map_size - dd->certs.size - hashed_bytes;
- if (!check_pointer_and_size(pe, hash_base, hash_size)) {
- cms->log(cms, LOG_ERR, "%s:%s:%d PE has invalid "
- "trailing data", __FILE__, __func__, __LINE__);
- goto error_shdrs;
- }
+ if (!check_pointer_and_size(cms, pe, hash_base, hash_size))
+ cmsgotoerr(error_shdrs, cms,
+ "PE has invalid trailing data");
+
if (hash_size % 8 != 0 && padded) {
size_t tmp_size = hash_size +
ALIGNMENT_PADDING(hash_size, 8);
--
2.29.2

View file

@ -0,0 +1,152 @@
From 25bc2f4ce9215cd39fb448ada642824a5d20205f Mon Sep 17 00:00:00 2001
From: Peter Jones <pjones@redhat.com>
Date: Tue, 16 Feb 2021 11:47:00 -0500
Subject: [PATCH 42/42] Fix our error message line numbers, hopefully.
Most of these seem to be off by a line or two; it's pretty obvious why.
Signed-off-by: Peter Jones <pjones@redhat.com>
---
src/cms_common.h | 10 ++++++----
src/compiler.h | 5 ++++-
src/util.h | 32 +++++++++++++++++++++++---------
3 files changed, 33 insertions(+), 14 deletions(-)
diff --git a/src/cms_common.h b/src/cms_common.h
index 1bffdcd034b..6cc31d5c6f0 100644
--- a/src/cms_common.h
+++ b/src/cms_common.h
@@ -43,24 +43,26 @@
#define cmsreterr(rv, cms, fmt, args...) ({ \
(cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt, \
- __FILE__, __func__, __LINE__, ## args); \
+ __FILE__, __func__, __LINE__ - 2, \
+ ## args); \
return rv; \
})
#define cmsgotoerr(errlabel, cms, fmt, args...) ({ \
(cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt, \
- __FILE__, __func__, __LINE__, ## args); \
+ __FILE__, __func__, __LINE__ - 2, \
+ ## args); \
goto errlabel; \
})
#define cnreterr(rv, cms, fmt, args...) ({ \
(cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt ":%s:%s", \
- __FILE__, __func__, __LINE__, ## args, \
+ __FILE__, __func__, __LINE__ - 2, ## args, \
PORT_ErrorToName(PORT_GetError()), \
PORT_ErrorToString(PORT_GetError())); \
return rv; \
})
#define cngotoerr(errlabel, cms, fmt, args...) ({ \
(cms)->log((cms), LOG_ERR, "%s:%s:%d: " fmt ":%s:%s", \
- __FILE__, __func__, __LINE__, ## args, \
+ __FILE__, __func__, __LINE__ - 2, ## args, \
PORT_ErrorToName(PORT_GetError()), \
PORT_ErrorToString(PORT_GetError())); \
goto errlabel; \
diff --git a/src/compiler.h b/src/compiler.h
index 31379ef9b33..5d979c9d977 100644
--- a/src/compiler.h
+++ b/src/compiler.h
@@ -23,6 +23,9 @@
#define ALIGNED(n) __attribute__((__aligned__(n)))
#define CLEANUP_FUNC(x) __attribute__((__cleanup__(x)))
+#ifndef __CONCAT
+#define __CONCAT(a, b) a ## b
+#endif
#define __CONCAT3(a, b, c) a ## b ## c
#define CONCATENATE(a, b) __CONCAT(a, b)
#define CAT(a, b) __CONCAT(a, b)
@@ -71,7 +74,7 @@
* compiler has support to do so.
*/
#define compiletime_assert(condition, msg) \
- _compiletime_assert(condition, msg, __compiletime_assert_, __LINE__)
+ _compiletime_assert(condition, msg, __compiletime_assert_, __LINE__ - 1)
/**
* BUILD_BUG_ON_MSG - break compile if a condition is true & emit supplied
diff --git a/src/util.h b/src/util.h
index 21a846c10ee..e2893b71c39 100644
--- a/src/util.h
+++ b/src/util.h
@@ -67,7 +67,7 @@
#define nsserr(rv, fmt, args...) ({ \
errx((rv), "%s:%s:%d: " fmt ": %s", \
- __FILE__, __func__, __LINE__, ##args, \
+ __FILE__, __func__, __LINE__ - 2, ##args, \
PORT_ErrorToString(PORT_GetError())); \
})
#define condnsserr(cond, rv, fmt, args...) ({ \
@@ -76,7 +76,7 @@
})
#define nssreterr(rv, fmt, args...) ({ \
fprintf(stderr, "%s:%s:%d: " fmt ": %s\n", \
- __FILE__, __func__, __LINE__, ##args, \
+ __FILE__, __func__, __LINE__ - 2, ##args, \
PORT_ErrorToString(PORT_GetError())); \
return rv; \
})
@@ -86,21 +86,21 @@
})
#define liberr(rv, fmt, args...) ({ \
err((rv), "%s:%s:%d: " fmt, \
- __FILE__, __func__, __LINE__, ##args); \
+ __FILE__, __func__, __LINE__ - 2, ##args); \
})
#define libreterr(rv, fmt, args...) ({ \
fprintf(stderr, "%s:%s:%d: " fmt ": %m\n", \
- __FILE__, __func__, __LINE__, ##args); \
+ __FILE__, __func__, __LINE__ - 2, ##args); \
return rv; \
})
#define peerr(rv, fmt, args...) ({ \
errx((rv), "%s:%s:%d: " fmt ": %s", \
- __FILE__, __func__, __LINE__, ##args, \
+ __FILE__, __func__, __LINE__ - 2, ##args, \
pe_errmsg(pe_errno())); \
})
#define pereterr(rv, fmt, args...) ({ \
fprintf(stderr, "%s:%s:%d: " fmt ": %s\n", \
- __FILE__, __func__, __LINE__, ##args, \
+ __FILE__, __func__, __LINE__ - 2, ##args, \
pe_errmsg(pe_errno())); \
return rv; \
})
@@ -274,11 +274,25 @@ proxy_fd_mode(int fd, char *infile, mode_t *outmode, size_t *inlength)
extern long verbosity(void);
-#define dprintf_(tv, file, func, line, fmt, args...) ({struct timeval tv; gettimeofday(&tv, NULL); warnx("%ld.%lu %s:%s():%d: " fmt, tv.tv_sec, tv.tv_usec, file, func, line, ##args); })
+#define dprintf_(tv, file, func, line, fmt, args...) ({ \
+ struct timeval tv; \
+ gettimeofday(&tv, NULL); \
+ warnx("%ld.%lu %s:%s():%d: " fmt, \
+ tv.tv_sec, tv.tv_usec, \
+ file, func, line, ##args); \
+ })
#if defined(PESIGN_DEBUG)
-#define dprintf(fmt, args...) dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), __FILE__, __func__, __LINE__, fmt, ##args)
+#define dprintf(fmt, args...) \
+ dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \
+ __FILE__, __func__, __LINE__ - 2, fmt, ##args)
#else
-#define dprintf(fmt, args...) ({ if (verbosity() > 1) dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), __FILE__, __func__, __LINE__, fmt, ##args); 0; })
+#define dprintf(fmt, args...) ({ \
+ if (verbosity() > 1) \
+ dprintf_(CAT(CAT(CAT(tv_,__COUNTER__),__LINE__),_), \
+ __FILE__, __func__, __LINE__ - 3, \
+ fmt, ##args); \
+ 0; \
+ })
#endif
#define ingress() dprintf("ingress");
#define egress() dprintf("egress");
--
2.29.2

View file

View file

@ -1,5 +0,0 @@
Patch0001: 0001-cms_common-Fixed-Segmentation-fault.patch
Patch0002: 0002-Fix-reversed-calloc-arguments.patch
Patch0003: 0003-Work-around-OpenSC-changing-token-names-on-fedora-bu.patch
Patch0004: 0004-cms_common-skip-authentication-on-the-Friendly-slot.patch
Patch0005: 0005-Add-const-qualifier-to-variable.patch

View file

@ -1,33 +1,28 @@
%global macrosdir %(d=%{_rpmconfigdir}/macros.d; [ -d $d ] || d=%{_sysconfdir}/rpm; echo $d)
# No. I have enough trouble already.
%undefine _auto_set_build_flags
Name: pesign
Summary: Signing utility for UEFI binaries
Version: 116
Release: 9%{?dist}
License: GPL-2.0-only
URL: https://github.com/rhboot/pesign
Version: 113
Release: 13%{?dist}
License: GPLv2
URL: https://github.com/vathpela/pesign
Obsoletes: pesign-rh-test-certs <= 0.111-7
BuildRequires: efivar-devel >= 38-1
BuildRequires: gcc
BuildRequires: git
BuildRequires: libuuid-devel
BuildRequires: make
BuildRequires: mandoc
BuildRequires: nspr
BuildRequires: nspr-devel >= 4.9.2-1
BuildRequires: nss
BuildRequires: nss-devel >= 3.13.6-1
BuildRequires: nss-tools
BuildRequires: nss-util
BuildRequires: popt-devel
BuildRequires: python3
BuildRequires: python3-rpm-macros
BuildRequires: nss-tools
BuildRequires: nspr-devel >= 4.9.2-1
BuildRequires: nss-devel >= 3.13.6-1
BuildRequires: efivar-devel >= 31-1
BuildRequires: libuuid-devel
BuildRequires: tar
BuildRequires: xz
BuildRequires: python3-rpm-macros
BuildRequires: python3
%if 0%{?rhel} >= 7 || 0%{?fedora} >= 17
BuildRequires: systemd-rpm-macros
%endif
@ -37,7 +32,8 @@ Requires: nss-tools >= 3.53
Requires: nss-util
Requires: popt
Requires: rpm
ExclusiveArch: %{ix86} x86_64 ia64 aarch64 %{arm} riscv64
Requires(pre): shadow-utils
ExclusiveArch: %{ix86} x86_64 ia64 aarch64 %{arm}
%if 0%{?rhel} == 7
BuildRequires: rh-signing-tools >= 1.20-2
%endif
@ -45,31 +41,57 @@ BuildRequires: rh-signing-tools >= 1.20-2
Source0: https://github.com/rhboot/pesign/releases/download/%{version}/pesign-%{version}.tar.bz2
Source1: certs.tar.xz
Source2: pesign.py
Source3: pesign.patches
# generate with tool
%include %{SOURCE3}
Patch0001: 0001-efikeygen-Fix-the-build-with-nss-3.44.patch
Patch0002: 0002-pesigcheck-Fix-a-wrong-assignment.patch
Patch0003: 0003-Make-0.112-client-and-server-work-with-the-113-proto.patch
Patch0004: 0004-Rename-var-run-to-run.patch
Patch0005: 0005-Apparently-opensc-got-updated-and-the-token-name-cha.patch
Patch0006: 0006-Add-some-more-utility-functions-and-fix-a-typo-in-AL.patch
Patch0007: 0007-Add-hex-utilities.patch
Patch0008: 0008-Add-some-text-parsing-helpers.patch
Patch0009: 0009-libdpe-fix-some-minor-analyzer-discoveries.patch
Patch0010: 0010-libdpe-check-for-NULL-pe-at-more-places.patch
Patch0011: 0011-wincert-try-to-convince-the-gcc-analyzer-of-the-pain.patch
Patch0012: 0012-Fix-a-missing-malloc-return-value-check.patch
Patch0013: 0013-Fix-some-missed-OOM-error-path-fanalyzer-found.patch
Patch0014: 0014-Don-t-allow-or-require-module-or-kernel-with-ca.patch
Patch0015: 0015-Add-super-convenient-errno-guard-implementation.patch
Patch0016: 0016-Make-save_port_err-saner-to-read.patch
Patch0017: 0017-Make-for_each_cert-cl-iter-for-certificate-list-trav.patch
Patch0018: 0018-file_pe-make-most-of-our-input-and-output-checkers-b.patch
Patch0019: 0019-file_pe-user-err-errx-etc.patch
Patch0020: 0020-pesign_kmod-user-err-errx-etc.patch
Patch0021: 0021-share-input-output-checker-macros-between-pesign_kmo.patch
Patch0022: 0022-Make-verbose-work-in-efisiglist.patch
Patch0023: 0023-Make-verbose-and-debug-more-similar-across-tools.patch
Patch0024: 0024-Work-around-some-NSS-SECOID_AddEntry-bugs.patch
Patch0025: 0025-Rework-the-wildly-undocumented-NSS-password-file-goo.patch
Patch0026: 0026-Minor-whitespace-housekeeping.patch
Patch0027: 0027-libdpe-make-the-initial-read-buffer-always-big-enoug.patch
Patch0028: 0028-Fix-some-memory-leaks.patch
Patch0029: 0029-Improve-debug-output.patch
Patch0030: 0030-support-uri-token-names.patch
Patch0031: 0031-cms_common-add-some-more-ways-to-find-a-cert.patch
Patch0032: 0032-client-try-run-and-var-run-for-the-socket-path.patch
Patch0033: 0033-client-remove-an-extra-debug-print.patch
Patch0034: 0034-Move-most-of-macros.pesign-to-pesign-rpmbuild-helper.patch
Patch0035: 0035-pesign-authorize-shellcheck.patch
Patch0036: 0036-pesign-authorize-don-t-setfacl-etc-pki-pesign-foo.patch
Patch0037: 0037-kernel-building-hack.patch
Patch0038: 0038-Use-run-not-var-run.patch
Patch0039: 0039-efikeygen-return-error-on-AKID-encoding-failures.patch
Patch0040: 0040-Rename-some-cms-error-functions.patch
Patch0041: 0041-Make-cms_pe_common-bounds-check-errors-more-verbose.patch
Patch0042: 0042-Fix-our-error-message-line-numbers-hopefully.patch
%description
This package contains the pesign utility for signing UEFI binaries as
well as other associated tools.
%prep
%setup -q -T -b 0
%autosetup -S git_am -n pesign-%{version}
%setup -q -T -D -c -n pesign-%{version}/ -a 1
git init
git config user.email "pesign-owner@fedoraproject.org"
git config user.name "Fedora Ninjas"
git add .
git commit -a -q -m "%{version} baseline."
git am %{patches} </dev/null
git config --unset user.email
git config --unset user.name
# Create a sysusers.d config file
cat >pesign.sysusers.conf <<EOF
u pesign - 'Group for the pesign signing daemon' /run/pesign -
EOF
%build
make PREFIX=%{_prefix} LIBDIR=%{_libdir}
@ -105,8 +127,12 @@ cp -av libdpe/*.[ch] src/
install -d -m 0755 %{buildroot}%{python3_sitelib}/mockbuild/plugins/
install -m 0755 %{SOURCE2} %{buildroot}%{python3_sitelib}/mockbuild/plugins/
install -m0644 -D pesign.sysusers.conf %{buildroot}%{_sysusersdir}/pesign.conf
%pre
getent group pesign >/dev/null || groupadd -r pesign
getent passwd pesign >/dev/null || \
useradd -r -g pesign -d /run/pesign -s /sbin/nologin \
-c "Group for the pesign signing daemon" pesign
exit 0
%if 0%{?rhel} >= 7 || 0%{?fedora} >= 17
%post
@ -132,13 +158,13 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null
%files
%{!?_licensedir:%global license %%doc}
%license COPYING
%doc README.md TODO
%doc README TODO
%{_bindir}/authvar
%{_bindir}/efikeygen
%{_bindir}/efisiglist
%{_bindir}/pesigcheck
%{_bindir}/pesign
%{_bindir}/pesign-client
%{_bindir}/pesum
%dir %{_libexecdir}/pesign/
%dir %attr(0770,pesign,pesign) %{_sysconfdir}/pki/pesign/
%config(noreplace) %attr(0660,pesign,pesign) %{_sysconfdir}/pki/pesign/*
@ -160,96 +186,10 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null
%endif
%{python3_sitelib}/mockbuild/plugins/*/pesign.*
%{python3_sitelib}/mockbuild/plugins/pesign.*
%{_sysusersdir}/pesign.conf
%changelog
* Mon Jun 22 2026 Nicolas Frayer <nfrayer@redhat.com> - 116-9
- Fix a FTBFS issue caused by a missing const qualifier
- Resolves: #2491392
* Tue Feb 11 2025 Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl>
- Add sysusers.d config file to allow rpm to create users/groups automatically
* Wed Jan 29 2025 Nicolas Frayer <nfrayer@redhat.com> - 116-7
- Backport patch to skip auth on friendly slot
* Thu Nov 21 2024 Peter Jones <pjones@redhat.com> - 116-6
- Work around OpenSC token name changes
* Tue Nov 12 2024 Kevin Fenzi <kevin@scrye.com> - 116-5
- Rebuild to pick up riscv64 change
* Tue Mar 05 2024 Liu Yang <Yang.Liu.sn@gmail.com> - 116-4
- Add riscv64.
* Fri Feb 02 2024 Peter Jones <pjones@redhat.com> - 116-3
- Fix incorrect calloc() invocations caught by -Wcalloc-transposed-args
* Mon Feb 20 2023 Nicolas Frayer <nfrayer@redhat.com> - 116-2
- cms_common: Fixed Segmentation fault
* Tue Jan 31 2023 Robbie Harwood <rharwood@redhat.com> - 116-1
- New upstream release (116)
- Resolves: CVE-2022-3560
* Wed Aug 31 2022 Robbie Harwood <rharwood@redhat.com> - 115-9
- Roll up to pjones's smartcard/cms fixes
* Tue Aug 02 2022 Robbie Harwood <rharwood@redhat.com> - 115-8
- Rebuild for python bytecode change
- See-also: #2107826
* Thu Jul 07 2022 Robbie Harwood <rharwood@redhat.com> - 115-6
- Fix formatting of man pages
- Resolves: #2104778
* Mon Apr 04 2022 Robbie Harwood <rharwood@redhat.com> - 115-5
- Detect presence of rpm-sign when checking for rhel-ness
* Fri Apr 01 2022 Robbie Harwood <rharwood@redhat.com> - 115-4
- Correctly handle rhel and centos macros
* Fri Mar 25 2022 Robbie Harwood <rharwood@redhat.com> - 115-3
- Add -D_GLIBCXX_ASSERTIONS to CPPFLAGS
* Thu Mar 24 2022 Robbie Harwood <rharwood@redhat.com> - 115-2
- Add support for non-koji signing in macros
- Resolves: #1880858
* Tue Mar 08 2022 Robbie Harwood <rharwood@redhat.com> - 115-1
- New upstream version (115)
* Mon Feb 14 2022 Robbie Harwood <rharwood@redhat.com> - 114-4
- Disable -fanalyzer since it's broken and pragmas don't work
- See-also: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=104370
* Mon Feb 14 2022 Robbie Harwood <rharwood@redhat.com> - 114-3
- Fix explicit NULL deref when daemonizing
* Wed Feb 02 2022 Robbie Harwood <rharwood@redhat.com> - 114-2
- Attempt to fix signing parsing by dropping pesign_args
* Tue Feb 01 2022 Robbie Harwood <rharwood@redhat.com> - 114-1
- New upstream version (114)
* Fri Jan 21 2022 Fedora Release Engineering <releng@fedoraproject.org> - 113-18
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Fri Jul 23 2021 Fedora Release Engineering <releng@fedoraproject.org> - 113-17
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> - 113-16
- Rebuilt for updated systemd-rpm-macros
See https://pagure.io/fesco/issue/2583.
* Wed Jan 27 2021 Fedora Release Engineering <releng@fedoraproject.org> - 113-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Mon Nov 16 2020 Jeff Law <law@redhat.com> - 113-14
- Turn off -Wfree-nonheap-object
* Mon Aug 03 2020 Peter Jones <pjones@redhat.com> - 113-13
- Add the rundir related stuff that was staged on my f32 checkout.
* Thu Feb 18 2021 Peter Jones <pjones@redhat.com> - 113-13
- Backport a bunch of stuff the upstream development tree.
* Mon Aug 03 2020 Peter Jones <pjones@redhat.com> - 113-12
- Try to make kernel and fwupd both work at the same time.
@ -258,43 +198,7 @@ certutil -d %{_sysconfdir}/pki/pesign/ -X -L > /dev/null
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Thu Jul 16 2020 Peter Jones <pjones@redhat.com> - 113-10
- I really cannot figure out why bkernel01 thinks the certificate nickname
starts with /CN=, but it does, so I'm gonna stop fighting with the sand.
* Thu Jul 16 2020 Peter Jones <pjones@redhat.com> - 113-9
- Even more kernel build debugging...
* Tue Jul 07 2020 Peter Jones <pjones@redhat.com> - 113-8
- More kernel build debugging...
* Tue Jul 07 2020 Peter Jones <pjones@redhat.com> - 113-6
- Disable the pesign-authorize call in posttrans, until we can figure out a
better way to deal with that in the fedora kernel builder chroot setup
* Tue Jul 07 2020 Peter Jones <pjones@redhat.com> - 113-5
- Make pesign require nss-tools for the posttrans scriptlet
- Move most of macros.pesign to /usr/libexec/pesign/pesign-rpmbuild-helper
* Mon Jul 06 2020 Peter Jones <pjones@redhat.com> - 113-4
- Attempt to fix kernel signing failures caused by -3...
* Fri Jun 12 2020 Peter Jones <pjones@redhat.com> - 113-3
- Fix the signer name for fedora and some other minor nits
Related: rhbz#1708773
Related: rhbz#1678146
* Thu Jun 11 2020 Peter Jones <pjones@redhat.com> - 113-2
- Fix a signing protocol bug we introduced in 113 that makes the fedora
kernel builders fail.
Related: rhbz#1708773
* Thu Jun 11 2020 Javier Martinez Canillas <javierm@redhat.com> - 113-1
- Update to 113 release
Resolves: rhbz#1708773
* Mon Jun 08 2020 Javier Martinez Canillas <javierm@redhat.com> - 0.112-31
- Switch default NSS database to SQLite format (pjones)
Resolves: rhbz#1827902
- Synchronize with master
* Mon Feb 24 2020 Peter Jones <pjones@redhat.com> - 0.112-30
- Make sure the patch for -29 is actually in the build in f32, and

View file

@ -1,13 +0,0 @@
---
inspections:
# Not a Java package
javabytecode: off
# These just flag when things change "too much"
changedfiles: off
filesize: off
patches: off
upstream: off
# https://bugzilla.redhat.com/show_bug.cgi?id=2010936
annocheck: off

View file

@ -1,2 +1,2 @@
SHA512 (certs.tar.xz) = ddac535c786d1a23074534323c4ce89f907d4f82b19c5d3a9c814b145fbac1599cd2386cf20c28d22aee7d5c4db441f052bab9ee655de756117a0a0bc99b525f
SHA512 (pesign-116.tar.bz2) = be3e1083f5e9f889cb8f7c50a8ebe723542fb2f6d1de8de9b04a9f21526ebaa8ab1efc7d4be11bcb0bc9862fa4bc6f78ee35e4d3496dd3b8927170b97795d25c
SHA512 (pesign-113.tar.bz2) = 89c5e33bf6ac8f8dc4b65192e5fd4bf1fea285106d1de2a6ea02a8c5090f2ec5976b1d80c60e57f74fa56dc25b174a4dd5682292db44ab9aeab69ea992dfef36