Compare commits
25 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a03c0c7017 |
||
|
|
9a650699eb |
||
|
|
91a6bb94a6 |
||
|
|
9017cd8b5a |
||
|
|
900e10c558 |
||
|
|
9111b85386 | ||
|
|
0954d1a211 | ||
|
|
670d5e43af | ||
|
|
c5af5ba810 | ||
|
|
2f6d98b494 | ||
|
|
3e4e7c4ad9 | ||
|
|
af6d350b20 | ||
|
|
31cf588afd | ||
|
|
00ae409662 | ||
|
|
0cddb04217 | ||
|
|
2da8e38627 | ||
|
|
f20c1143a3 | ||
|
|
6eccdf5e80 | ||
|
|
f673a25e51 |
||
|
|
fbcc49819f | ||
|
|
bc295d3869 |
||
|
|
5da24d354e |
||
|
|
f85686e675 | ||
|
|
730ac1cfc1 | ||
|
|
c2ad6f1c17 |
16 changed files with 191 additions and 181 deletions
1
.fmf/version
Normal file
1
.fmf/version
Normal file
|
|
@ -0,0 +1 @@
|
|||
1
|
||||
9
.gitignore
vendored
9
.gitignore
vendored
|
|
@ -25,3 +25,12 @@
|
|||
/sscg-3.0.0.tar.xz
|
||||
/sscg-3.0.1.tar.gz
|
||||
/sscg-3.0.2.tar.gz
|
||||
/sscg-3.0.3.tar.gz
|
||||
/sscg-3.0.5.tar.gz
|
||||
/sscg-3.0.6.tar.gz
|
||||
/sscg-3.0.7.tar.gz
|
||||
/sscg-3.0.8.tar.gz
|
||||
/sscg-4.0.0.tar.gz
|
||||
/sscg-4.0.1.tar.gz
|
||||
/sscg-4.0.2.tar.gz
|
||||
/sscg-4.0.3.tar.gz
|
||||
|
|
|
|||
51
.packit.yaml
Normal file
51
.packit.yaml
Normal file
|
|
@ -0,0 +1,51 @@
|
|||
# See the documentation for more information:
|
||||
# https://packit.dev/docs/configuration/
|
||||
|
||||
specfile_path: .distro/sscg.spec
|
||||
|
||||
files_to_sync:
|
||||
- src: .distro/sscg.spec
|
||||
dest: sscg.spec
|
||||
- src: .packit.yaml
|
||||
dest: .packit.yaml
|
||||
- src: get_current_version.sh
|
||||
dest: get_current_version.sh
|
||||
|
||||
sync_changelog: true
|
||||
|
||||
upstream_package_name: sscg
|
||||
downstream_package_name: sscg
|
||||
|
||||
upstream_tag_template: sscg-{version}
|
||||
|
||||
archive_root_dir_template: "{upstream_pkg_name}-{upstream_pkg_name}-{version}"
|
||||
|
||||
notifications:
|
||||
pull_request:
|
||||
successful_build: true
|
||||
|
||||
srpm_build_deps:
|
||||
- meson
|
||||
- jq
|
||||
|
||||
actions:
|
||||
get-current-version:
|
||||
- ./get_current_version.sh
|
||||
|
||||
jobs:
|
||||
- job: copr_build
|
||||
trigger: pull_request
|
||||
targets:
|
||||
- fedora-all
|
||||
- centos-stream-8
|
||||
- centos-stream-9
|
||||
- job: tests
|
||||
trigger: pull_request
|
||||
targets:
|
||||
- fedora-all
|
||||
- centos-stream-8
|
||||
- centos-stream-9
|
||||
- job: propose_downstream
|
||||
trigger: release
|
||||
dist_git_branches:
|
||||
- fedora-all
|
||||
38
0001-Avoid-segfault-on-receiving-bad-CLI-arguments.patch
Normal file
38
0001-Avoid-segfault-on-receiving-bad-CLI-arguments.patch
Normal file
|
|
@ -0,0 +1,38 @@
|
|||
From 0c37e7ace585cfb550a0ffd9d5c331d059fd687f Mon Sep 17 00:00:00 2001
|
||||
From: Stephen Gallagher <sgallagh@redhat.com>
|
||||
Date: Tue, 2 Dec 2025 12:12:26 -0500
|
||||
Subject: [PATCH] Avoid segfault on receiving bad CLI arguments
|
||||
|
||||
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>
|
||||
---
|
||||
src/sscg.c | 7 +++++--
|
||||
1 file changed, 5 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/src/sscg.c b/src/sscg.c
|
||||
index b9b191f109300f6447262858f57a3a8321a14966..00e2862c2d6be5c44a4a362fc926e1a07d31d7bf 100644
|
||||
--- a/src/sscg.c
|
||||
+++ b/src/sscg.c
|
||||
@@ -59,7 +59,7 @@ int
|
||||
main (int argc, const char **argv)
|
||||
{
|
||||
int ret, sret;
|
||||
- struct sscg_options *options;
|
||||
+ struct sscg_options *options = NULL;
|
||||
bool build_client_cert = false;
|
||||
char *dhparams_file = NULL;
|
||||
|
||||
@@ -342,7 +342,10 @@ main (int argc, const char **argv)
|
||||
done:
|
||||
if (ret != EOK)
|
||||
{
|
||||
- sscg_io_utils_delete_output_files (options->streams);
|
||||
+ if (options)
|
||||
+ {
|
||||
+ sscg_io_utils_delete_output_files (options->streams);
|
||||
+ }
|
||||
}
|
||||
talloc_zfree (main_ctx);
|
||||
if (getenv ("SSCG_TALLOC_REPORT"))
|
||||
--
|
||||
2.52.0
|
||||
|
||||
|
|
@ -1,40 +0,0 @@
|
|||
From e1e473650b45aff0b6a1fc50f4bdd7752dc45c85 Mon Sep 17 00:00:00 2001
|
||||
From: Stephen Gallagher <sgallagh@redhat.com>
|
||||
Date: Tue, 1 Mar 2022 16:37:22 -0500
|
||||
Subject: [PATCH 1/4] Protect against negative bitshift
|
||||
|
||||
Coverity scan identified that SSCG_FILE_TYPE_UNKNOWN could cause the
|
||||
bitshifts further down to attempt to shift a negative number, which
|
||||
results in undefined behavior. Though it should never occur that this
|
||||
function is called with an invalid type, it's best to be overly
|
||||
cautious and check for it.
|
||||
|
||||
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>
|
||||
---
|
||||
src/io_utils.c | 6 ++++++
|
||||
1 file changed, 6 insertions(+)
|
||||
|
||||
diff --git a/src/io_utils.c b/src/io_utils.c
|
||||
index 1b8bc41..0e05ed9 100644
|
||||
--- a/src/io_utils.c
|
||||
+++ b/src/io_utils.c
|
||||
@@ -99,10 +99,16 @@ struct sscg_stream *
|
||||
sscg_io_utils_get_stream_by_type (struct sscg_stream **streams,
|
||||
enum sscg_file_type filetype)
|
||||
{
|
||||
struct sscg_stream *stream = NULL;
|
||||
|
||||
+ if (filetype < 0 || filetype > SSCG_NUM_FILE_TYPES)
|
||||
+ {
|
||||
+ SSCG_LOG (SSCG_DEFAULT, "Unknown filetype for stream");
|
||||
+ return NULL;
|
||||
+ }
|
||||
+
|
||||
/* First see if this path already exists in the list */
|
||||
for (int i = 0; (stream = streams[i]) && i < SSCG_NUM_FILE_TYPES; i++)
|
||||
{
|
||||
SSCG_LOG (SSCG_DEBUG,
|
||||
"Checking for 0x%.4x in 0x%.4x\n",
|
||||
--
|
||||
2.35.1
|
||||
|
||||
|
|
@ -1,34 +0,0 @@
|
|||
From b9f757736f73db8c58bb9e422e018ab84eabd51f Mon Sep 17 00:00:00 2001
|
||||
From: Stephen Gallagher <sgallagh@redhat.com>
|
||||
Date: Tue, 1 Mar 2022 16:46:24 -0500
|
||||
Subject: [PATCH 2/4] Fix another negative bitshift issue
|
||||
|
||||
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>
|
||||
---
|
||||
src/io_utils.c | 6 ++++++
|
||||
1 file changed, 6 insertions(+)
|
||||
|
||||
diff --git a/src/io_utils.c b/src/io_utils.c
|
||||
index 0e05ed9..158db07 100644
|
||||
--- a/src/io_utils.c
|
||||
+++ b/src/io_utils.c
|
||||
@@ -264,10 +264,16 @@ sscg_io_utils_add_output_key (struct sscg_stream **streams,
|
||||
int ret, i;
|
||||
TALLOC_CTX *tmp_ctx = NULL;
|
||||
struct sscg_stream *stream = NULL;
|
||||
char *normalized_path = NULL;
|
||||
|
||||
+ if (filetype < 0 || filetype > SSCG_NUM_FILE_TYPES)
|
||||
+ {
|
||||
+ SSCG_ERROR ("Unknown filetype for stream");
|
||||
+ return EINVAL;
|
||||
+ }
|
||||
+
|
||||
/* If we haven't been passed a path, just return; it's probably an optional
|
||||
* output file
|
||||
*/
|
||||
if (path == NULL)
|
||||
{
|
||||
--
|
||||
2.35.1
|
||||
|
||||
|
|
@ -1,36 +0,0 @@
|
|||
From 3483a978eb1c667760992b012ea7350313b5a15a Mon Sep 17 00:00:00 2001
|
||||
From: Stephen Gallagher <sgallagh@redhat.com>
|
||||
Date: Tue, 8 Mar 2022 16:33:35 -0500
|
||||
Subject: [PATCH 3/4] Fix incorrect error-check
|
||||
|
||||
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>
|
||||
---
|
||||
src/x509.c | 8 +++++++-
|
||||
1 file changed, 7 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/x509.c b/src/x509.c
|
||||
index 7c7e4df..23bb337 100644
|
||||
--- a/src/x509.c
|
||||
+++ b/src/x509.c
|
||||
@@ -287,11 +287,17 @@ sscg_x509v3_csr_new (TALLOC_CTX *mem_ctx,
|
||||
alt_name = tmp;
|
||||
}
|
||||
}
|
||||
|
||||
ex = X509V3_EXT_conf_nid (NULL, NULL, NID_subject_alt_name, alt_name);
|
||||
- CHECK_MEM (ex);
|
||||
+ if (!ex)
|
||||
+ {
|
||||
+ ret = EINVAL;
|
||||
+ fprintf (stderr, "Invalid subjectAlternativeName: %s\n", alt_name);
|
||||
+ goto done;
|
||||
+ }
|
||||
+
|
||||
sk_X509_EXTENSION_push (certinfo->extensions, ex);
|
||||
|
||||
/* Set the public key for the certificate */
|
||||
sslret = X509_REQ_set_pubkey (csr->x509_req, spkey->evp_pkey);
|
||||
CHECK_SSL (sslret, X509_REQ_set_pubkey (OU));
|
||||
--
|
||||
2.35.1
|
||||
|
||||
|
|
@ -1,49 +0,0 @@
|
|||
From 2e9889320c76368d31e6c9d579f239fe88002cf9 Mon Sep 17 00:00:00 2001
|
||||
From: Stephen Gallagher <sgallagh@redhat.com>
|
||||
Date: Tue, 8 Mar 2022 16:34:09 -0500
|
||||
Subject: [PATCH 4/4] Truncate IP address in SAN
|
||||
|
||||
In OpenSSL 1.1, this was done automatically when addind a SAN extension,
|
||||
but in OpenSSL 3.0 it is rejected as an invalid input.
|
||||
|
||||
Signed-off-by: Stephen Gallagher <sgallagh@redhat.com>
|
||||
---
|
||||
src/x509.c | 7 +++++++
|
||||
1 file changed, 7 insertions(+)
|
||||
|
||||
diff --git a/src/x509.c b/src/x509.c
|
||||
index 23bb337..e828ec7 100644
|
||||
--- a/src/x509.c
|
||||
+++ b/src/x509.c
|
||||
@@ -131,10 +131,11 @@ sscg_x509v3_csr_new (TALLOC_CTX *mem_ctx,
|
||||
size_t i;
|
||||
X509_NAME *subject;
|
||||
char *alt_name = NULL;
|
||||
char *tmp = NULL;
|
||||
char *san = NULL;
|
||||
+ char *slash = NULL;
|
||||
TALLOC_CTX *tmp_ctx;
|
||||
X509_EXTENSION *ex = NULL;
|
||||
struct sscg_x509_req *csr;
|
||||
|
||||
/* Make sure we have a key available */
|
||||
@@ -265,10 +266,16 @@ sscg_x509v3_csr_new (TALLOC_CTX *mem_ctx,
|
||||
tmp_ctx, "DNS:%s", certinfo->subject_alt_names[i]);
|
||||
}
|
||||
else
|
||||
{
|
||||
san = talloc_strdup (tmp_ctx, certinfo->subject_alt_names[i]);
|
||||
+ /* SAN IP addresses cannot include the subnet mask */
|
||||
+ if ((slash = strchr (san, '/')))
|
||||
+ {
|
||||
+ /* Truncate at the slash */
|
||||
+ *slash = '\0';
|
||||
+ }
|
||||
}
|
||||
CHECK_MEM (san);
|
||||
|
||||
if (strnlen (san, MAXHOSTNAMELEN + 5) > MAXHOSTNAMELEN + 4)
|
||||
{
|
||||
--
|
||||
2.35.1
|
||||
|
||||
3
README.packit
Normal file
3
README.packit
Normal file
|
|
@ -0,0 +1,3 @@
|
|||
This repository is maintained by packit.
|
||||
https://packit.dev/
|
||||
The file was generated using packit 0.76.0.
|
||||
1
ci.fmf
Normal file
1
ci.fmf
Normal file
|
|
@ -0,0 +1 @@
|
|||
resultsdb-testcase: separate
|
||||
18
gating.yaml
Normal file
18
gating.yaml
Normal file
|
|
@ -0,0 +1,18 @@
|
|||
--- !Policy
|
||||
product_versions:
|
||||
- fedora-*
|
||||
decision_contexts: [bodhi_update_push_testing]
|
||||
subject_type: koji_build
|
||||
rules:
|
||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/tier1-public.functional}
|
||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/tier2-public.functional}
|
||||
|
||||
#gating rawhide
|
||||
--- !Policy
|
||||
product_versions:
|
||||
- fedora-*
|
||||
decision_contexts: [bodhi_update_push_stable]
|
||||
subject_type: koji_build
|
||||
rules:
|
||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/tier1-public.functional}
|
||||
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build./plans/tier2-public.functional}
|
||||
46
get_current_version.sh
Executable file
46
get_current_version.sh
Executable file
|
|
@ -0,0 +1,46 @@
|
|||
#!/usr/bin/bash
|
||||
|
||||
# This file is part of sscg.
|
||||
#
|
||||
# sscg is free software: you can redistribute it and/or modify
|
||||
# it under the terms of the GNU General Public License as published by
|
||||
# the Free Software Foundation, either version 3 of the License, or
|
||||
# (at your option) any later version.
|
||||
#
|
||||
# sscg is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
# along with sscg. If not, see <http://www.gnu.org/licenses/>.
|
||||
#
|
||||
# In addition, as a special exception, the copyright holders give
|
||||
# permission to link the code of portions of this program with the
|
||||
# OpenSSL library under certain conditions as described in each
|
||||
# individual source file, and distribute linked combinations
|
||||
# including the two.
|
||||
# You must obey the GNU General Public License in all respects
|
||||
# for all of the code used other than OpenSSL. If you modify
|
||||
# file(s) with this exception, you may extend this exception to your
|
||||
# version of the file(s), but you are not obligated to do so. If you
|
||||
# do not wish to do so, delete this exception statement from your
|
||||
# version. If you delete this exception statement from all source
|
||||
# files in the program, then also delete it here.
|
||||
#
|
||||
# Copyright 2023 by Stephen Gallagher <sgallagh@redhat.com>
|
||||
|
||||
set -e
|
||||
|
||||
tmpdir=$(mktemp -d)
|
||||
|
||||
function common_finalize {
|
||||
exitcode=$?
|
||||
rm -Rf "$tmpdir"
|
||||
return $exitcode
|
||||
}
|
||||
|
||||
trap common_finalize EXIT
|
||||
|
||||
meson setup ${tmpdir}/getcurrentversion 2>&1 > /dev/null
|
||||
meson introspect ${tmpdir}/getcurrentversion --projectinfo | jq -r .version
|
||||
7
plans/tier1-public.fmf
Normal file
7
plans/tier1-public.fmf
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
summary: Public (Fedora) Tier1 beakerlib tests
|
||||
discover:
|
||||
how: fmf
|
||||
url: https://src.fedoraproject.org/tests/sscg.git
|
||||
filter: 'tier: 1'
|
||||
execute:
|
||||
how: tmt
|
||||
7
plans/tier2-public.fmf
Normal file
7
plans/tier2-public.fmf
Normal file
|
|
@ -0,0 +1,7 @@
|
|||
summary: Public (Fedora) Tier2 beakerlib tests
|
||||
discover:
|
||||
how: fmf
|
||||
url: https://src.fedoraproject.org/tests/sscg.git
|
||||
filter: 'tier: 2'
|
||||
execute:
|
||||
how: tmt
|
||||
2
sources
2
sources
|
|
@ -1 +1 @@
|
|||
SHA512 (sscg-3.0.2.tar.gz) = c722bc0640d46ed5e8aa1c0b1b238419189501ca36bf37b057874eb91246d024209c19dd522903edddda660b8d4ee772d86362077195c0f1a59aabc1d6866c34
|
||||
SHA512 (sscg-4.0.3.tar.gz) = f629cf7e32d4d4e7c1f58c4a53be925b96980e6fb3106e3a36a72f85c723bd79fba6aecdbf092b50f915a8833297bc7c6c1ccbe04fef488db38bbdc1e3a95b96
|
||||
|
|
|
|||
30
sscg.spec
30
sscg.spec
|
|
@ -9,37 +9,25 @@
|
|||
%{!?meson_test: %global meson_test %{__meson} test -C %{_vpath_builddir} --num-processes %{_smp_build_ncpus} --print-errorlogs}
|
||||
|
||||
Name: sscg
|
||||
Version: 3.0.2
|
||||
Version: 4.0.3
|
||||
Release: %autorelease
|
||||
Summary: Simple SSL certificate generator
|
||||
Summary: Simple Signed Certificate Generator
|
||||
|
||||
License: GPLv3+ with exceptions
|
||||
License: GPL-3.0-or-later WITH cryptsetup-OpenSSL-exception
|
||||
URL: https://%{provider_prefix}
|
||||
Source0: https://%{provider_prefix}/archive/refs/tags/%{repo}-%{version}.tar.gz
|
||||
Source0: %{URL}/archive/refs/tags/sscg-%{version}.tar.gz
|
||||
BuildRequires: gcc
|
||||
BuildRequires: libtalloc-devel
|
||||
BuildRequires: openssl
|
||||
BuildRequires: openssl-devel
|
||||
BuildRequires: popt-devel
|
||||
BuildRequires: libpath_utils-devel
|
||||
BuildRequires: meson
|
||||
BuildRequires: ninja-build
|
||||
BuildRequires: help2man
|
||||
|
||||
# Protect against negative bitshift
|
||||
# Author: Stephen Gallagher <sgallagh@redhat.com>
|
||||
Patch1: 0001-Protect-against-negative-bitshift.patch
|
||||
|
||||
# Fix another negative bitshift issue
|
||||
# Author: Stephen Gallagher <sgallagh@redhat.com>
|
||||
Patch2: 0002-Fix-another-negative-bitshift-issue.patch
|
||||
|
||||
# Fix incorrect error-check
|
||||
# Author: Stephen Gallagher <sgallagh@redhat.com>
|
||||
Patch3: 0003-Fix-incorrect-error-check.patch
|
||||
|
||||
# Truncate IP address in SAN
|
||||
# Author: Stephen Gallagher <sgallagh@redhat.com>
|
||||
Patch4: 0004-Truncate-IP-address-in-SAN.patch
|
||||
# Upstream patch to avoid segfaults when receiving bad CLI arguments
|
||||
# https://github.com/sgallagher/sscg/commit/0c37e7ace585cfb550a0ffd9d5c331d059fd687f
|
||||
Patch: 0001-Avoid-segfault-on-receiving-bad-CLI-arguments.patch
|
||||
|
||||
|
||||
%description
|
||||
|
|
@ -51,7 +39,7 @@ up a full PKI environment and without exposing the machine to a risk of
|
|||
false signatures from the service certificate.
|
||||
|
||||
%prep
|
||||
%autosetup -p1 -n %{name}-%{name}-%{version}
|
||||
%autosetup -p1 -n sscg-sscg-%{version}
|
||||
|
||||
|
||||
%build
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue