diff --git a/.fmf/version b/.fmf/version new file mode 100644 index 0000000..d00491f --- /dev/null +++ b/.fmf/version @@ -0,0 +1 @@ +1 diff --git a/.packit.yaml b/.packit.yaml new file mode 100644 index 0000000..b3ae56b --- /dev/null +++ b/.packit.yaml @@ -0,0 +1,16 @@ +# See the documentation for more information: +# https://packit.dev/docs/configuration/ + +jobs: + - job: pull_from_upstream + trigger: release + dist_git_branches: + - fedora-rawhide + - job: koji_build + trigger: commit + dist_git_branches: + - fedora-all + - job: bodhi_update + trigger: commit + dist_git_branches: + - fedora-branched diff --git a/downgrade-x509.patch b/downgrade-x509.patch new file mode 100644 index 0000000..76a94bf --- /dev/null +++ b/downgrade-x509.patch @@ -0,0 +1,60 @@ +diff --git a/Cargo.toml b/Cargo.toml +index 2a38a77d0a32..ed0d5a2f7314 100644 +--- a/Cargo.toml ++++ b/Cargo.toml +@@ -24,7 +24,7 @@ byteorder = { version = "1", default-features = false } + clap = { version = "4.5.4", features = [ "derive", "wrap_help" ] } + clap_mangen = { version = ">= 0.2.30, < 0.4" } + env_logger = { version = "0.11" } +-der = { version = "0.8" } ++der = { version = "0.7.10" } + fdt = { version = "0.1" } + igvm = { version = "0.4" } + igvm_defs = { version = "0.4" } +@@ -38,7 +38,7 @@ spin = { version = ">= 0.10, < 0.13" } + uefi = { version = "0.39" } + uefi-raw = { version = "0.15.1" } + uguid = { version = "2" } +-x509-cert = { version = "0.3", default-features = false } ++x509-cert = { version = "0.2.5", default-features = false } + zerocopy = { version = "0.8", features = [ "derive" ] } + + virtfw-libhw = { path = "libhw", version = "0.5.2" } +diff --git a/libefi/src/sb/certs/info.rs b/libefi/src/sb/certs/info.rs +index 5926898c0e9d..0cd31bc376cc 100644 +--- a/libefi/src/sb/certs/info.rs ++++ b/libefi/src/sb/certs/info.rs +@@ -20,8 +20,8 @@ pub struct CertInfo { + + impl CertInfo { + fn attr(name: &Name, oid: &ObjectIdentifier) -> Option { +- for attr in name.iter_rdn() { +- if attr.iter().any(|x| x.oid == *oid) { ++ for attr in name.0.iter() { ++ if attr.0.iter().any(|x| x.oid == *oid) { + return Some(attr.to_string()); + } + } +@@ -30,16 +30,15 @@ impl CertInfo { + + pub fn new_from_der(der: &[u8]) -> Option { + let cert = Certificate::from_der(der).ok()?; +- let tbs = cert.tbs_certificate(); +- let subject = tbs.subject(); +- let issuer = tbs.issuer(); +- let not_before = tbs.validity().not_before.to_date_time(); +- let not_after = tbs.validity().not_after.to_date_time(); ++ let subject = cert.tbs_certificate.subject; ++ let issuer = cert.tbs_certificate.issuer; ++ let not_before = cert.tbs_certificate.validity.not_before.to_date_time(); ++ let not_after = cert.tbs_certificate.validity.not_after.to_date_time(); + let info = Self { + subject: subject.to_string(), +- subject_cn: Self::attr(subject, &OID_CN), ++ subject_cn: Self::attr(&subject, &OID_CN), + issuer: issuer.to_string(), +- issuer_cn: Self::attr(issuer, &OID_CN), ++ issuer_cn: Self::attr(&issuer, &OID_CN), + not_before: EfiTime::from(¬_before), + not_after: EfiTime::from(¬_after), + }; diff --git a/gating.yaml b/gating.yaml new file mode 100644 index 0000000..b1ef231 --- /dev/null +++ b/gating.yaml @@ -0,0 +1,8 @@ +--- !Policy +product_versions: + - fedora-* +decision_contexts: [bodhi_update_push_stable] +subject_type: koji_build +rules: + - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.tier0.functional} + - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.installability.functional} diff --git a/plans.fmf b/plans.fmf new file mode 100644 index 0000000..7ed6d72 --- /dev/null +++ b/plans.fmf @@ -0,0 +1,46 @@ +summary: run tests from distgit tarball +execute: + how: tmt + +/tmt: + summary: run upstream tmt tests + provision: + how: virtual + hardware: + memory: '>= 4 GB' + cpu: + processors: ">= 2" + virtualization: + is-supported: true + prepare: + - name: install dependencies + how: install + package: + - virt-firmware-rs + - qemu-system-x86-core + discover: + how: fmf + dist-git-source: true + +/cargo: + summary: run upstream cargo tests + prepare: + - name: install dependencies + how: install + package: + - git + - make + - cargo + - rustc + - openssl-devel + - systemd-devel + discover: + how: shell + dist-git-source: true + tests: + - name: /run/make/test + test: | + set -ex + version=$(rpmspec -q --qf '%{version}\n' $TMT_SOURCE_DIR/*.spec | head -1) + prepdir="$TMT_SOURCE_DIR/virt-firmware-rs-v${version}" + make -C $prepdir test diff --git a/sources b/sources index 27caf2b..4de98a4 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (virt-firmware-rs-v25.8.tar.gz) = 6e5cba78a5117acb8488a559a52d34285e108974889ca332094b21119ec09c112308cea6ec3fec17031c43cf1dd3e8567a19ebb4776a5fa9c4976f783e3de6a2 +SHA512 (virt-firmware-rs-v26.8.tar.gz) = 4573b05f567f2b4e17b2f7a0f54dd154b16e55f5b773a52358d42ffc841086be0c7a9231fa66150d55b5da267187a62b19d382ed10bd0c4558a264cb7baad68d diff --git a/virt-firmware-rs.spec b/virt-firmware-rs.spec index 40bb27e..ba8db1f 100644 --- a/virt-firmware-rs.spec +++ b/virt-firmware-rs.spec @@ -18,26 +18,31 @@ BuildRequires: rust-std-static-x86_64-unknown-uefi %endif Name: virt-firmware-rs -Version: 25.8 +Version: 26.8 Release: %autorelease Summary: Tools for EFI and virtual machine firmware SourceLicense: MIT License: %{shrink: - Apache-2.0 - Apache-2.0 OR BSL-1.0 - Apache-2.0 OR MIT - Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT - BSD-2-Clause OR Apache-2.0 OR MIT - MIT - MIT OR Apache-2.0 - MPL-2.0 - Unlicense OR MIT +((MIT OR Apache-2.0) AND Unicode-DFS-2016) AND +(0BSD OR MIT OR Apache-2.0) AND +(Apache-2.0) AND +(Apache-2.0 OR MIT) AND +(Apache-2.0 WITH LLVM-exception OR Apache-2.0 OR MIT) AND +(BSD-2-Clause OR Apache-2.0 OR MIT) AND +(BSD-3-Clause) AND +(MIT) AND +(MIT OR Apache-2.0) AND +(MIT OR Zlib OR Apache-2.0) AND +(MPL-2.0) AND +(Unlicense OR MIT) } URL: https://gitlab.com/kraxel/virt-firmware-rs Source: https://gitlab.com/kraxel/%{name}/-/archive/v%{version}/%{name}-v%{version}.tar.gz +Patch1: downgrade-x509.patch +ExclusiveArch: x86_64 aarch64 riscv64 BuildRequires: cargo-rpm-macros >= 24 BuildRequires: pkgconfig(libudev) @@ -59,20 +64,22 @@ firmware. This package has EFI applications for %{efiarch}. %prep %autosetup -n %{name}-v%{version} -p1 -%cargo_prep # drop unused packages from workspace to reduce dependencies. -sed -i Cargo.toml -e '/varstore/d' +sed -i Cargo.toml -e '/experimental/d' +sed -i Cargo.toml -e '/mefisto/d' %if %{without efi_apps} sed -i Cargo.toml -e '/efi-apps/d' %endif %generate_buildrequires -%cargo_generate_buildrequires +%cargo_generate_buildrequires -f std,json,pem,udev,authenticode %build +%cargo_prep %cargo_build -- --package virtfw-efi-tools --features udev %cargo_build -- --package virtfw-efi-tools -%cargo_build -- --package virtfw-igvm-tools +%cargo_build -- --package virtfw-igvm-tools --features authenticode +%cargo_build -- --package virtfw-varstore --features std,json,pem %if %{with efi_apps} %cargo_build -- --package virtfw-efi-apps --target $(uname -m)-unknown-uefi %endif @@ -85,9 +92,11 @@ install -d %{buildroot}%{_bindir} install -v -m 755 target/rpm/generate-boot-csv %{buildroot}%{_bindir} install -v -m 755 target/rpm/list-sb-vars %{buildroot}%{_bindir} install -v -m 755 target/rpm/mini-bootcfg %{buildroot}%{_bindir} +install -v -m 755 target/rpm/virt-fw-vars-setup %{buildroot}%{_bindir} install -v -m 755 target/rpm/uefi-boot-menu %{buildroot}%{_bindir}/uefi-boot-menu-rs install -v -m 755 target/rpm/igvm-inspect %{buildroot}%{_bindir} install -v -m 755 target/rpm/igvm-wrap %{buildroot}%{_bindir} +install -v -m 755 target/rpm/igvm-update %{buildroot}%{_bindir} %if %{with efi_apps} # efi-apps install -d %{buildroot}%{_datadir}/%{name}/%{efiarch} @@ -97,14 +106,18 @@ install -v -m 644 target/*-unknown-uefi/rpm/*.efi %{buildroot}%{_datadir}/%{name for dir in efi-apps efi-tools igvm-tools; do cp -v ${dir}/README.md README.${dir}.md done +# man pages +mkdir -p %{buildroot}%{_mandir}/man1 +for app in virt-fw-vars-setup igvm-inspect igvm-wrap igvm-update; do + %{buildroot}%{_bindir}/${app} --manpage > %{buildroot}%{_mandir}/man1/${app}.1 +done +%if %{with check} %check -%ifarch s390x -echo "skip tests on bigendian" -%else %cargo_test -- --package virtfw-libefi %cargo_test -- --package virtfw-efi-tools --features udev %cargo_test -- --package virtfw-igvm-tools +%cargo_test -- --package virtfw-varstore %endif %files @@ -115,9 +128,12 @@ echo "skip tests on bigendian" %{_bindir}/generate-boot-csv %{_bindir}/list-sb-vars %{_bindir}/mini-bootcfg +%{_bindir}/virt-fw-vars-setup %{_bindir}/uefi-boot-menu-rs %{_bindir}/igvm-inspect %{_bindir}/igvm-wrap +%{_bindir}/igvm-update +%{_mandir}/man1/* %if %{with efi_apps} %files -n %{name}-%{efiarch}