From 61e85de52cdd597607aa8f278b976dfcde18ab37 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Mon, 30 Jan 2023 15:18:34 +0100 Subject: [PATCH 01/31] Make the spec file EPEL compatible --- yubihsm-shell.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 29543af..0641725 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -28,7 +28,7 @@ BuildRequires: libedit-devel BuildRequires: pcsc-lite-devel BuildRequires: clang BuildRequires: pkg-config -%if 0%{fedora} > 36 +%if 0%{?fedora} > 36 BuildRequires: libusb-compat-0.1-devel %else BuildRequires: libusb-devel From 02b3e60c31f8efa86a7b7e934f96ca773ec3c812 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 22 Jul 2023 19:34:06 +0000 Subject: [PATCH 02/31] Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- yubihsm-shell.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 0641725..e18f4d7 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -2,7 +2,7 @@ Name: yubihsm-shell Version: 2.4.0 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Tools to interact with YubiHSM 2 License: ASL 2.0 @@ -110,6 +110,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Sat Jul 22 2023 Fedora Release Engineering - 2.4.0-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + * Mon Jan 30 2023 Jakub Jelen - 2.4.0-1 - New upstream release (#2165239) From e3525f8970a3003edd79924b3b2cfc7f50c8ed24 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Thu, 17 Aug 2023 09:50:21 +0200 Subject: [PATCH 03/31] yubihsm-shell-2.4.1-1 --- .gitignore | 2 + sources | 4 +- yubihsm-shell-2.4.0-fix-id-type.patch | 218 -------------------------- yubihsm-shell.spec | 11 +- 4 files changed, 9 insertions(+), 226 deletions(-) delete mode 100644 yubihsm-shell-2.4.0-fix-id-type.patch diff --git a/.gitignore b/.gitignore index 4c4e79c..2a9ddb4 100644 --- a/.gitignore +++ b/.gitignore @@ -23,3 +23,5 @@ /yubihsm-shell-2.3.2.tar.gz.sig /yubihsm-shell-2.4.0.tar.gz /yubihsm-shell-2.4.0.tar.gz.sig +/yubihsm-shell-2.4.1.tar.gz +/yubihsm-shell-2.4.1.tar.gz.sig diff --git a/sources b/sources index c98c3e3..3d8a419 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (yubihsm-shell-2.4.0.tar.gz) = 2b08e6e8932ff3bc12d1233d88147264a9875ce145290e29fb6b8f25eeb8e502afff9e7d02714a50454b85b0f01b09c0321d830a483d6b4f7afb962adce882d5 -SHA512 (yubihsm-shell-2.4.0.tar.gz.sig) = 5c429426023108629144ad691309997f5a08f242eaacb57b941120425dd09372929a38138ec63779d6bd46f334a936d1ca5ddbf33e9603d5f56cfaf6d94e0cab +SHA512 (yubihsm-shell-2.4.1.tar.gz) = e302d645ebbfc7425794a16e9301fdd4ce96d8dd9e8aca72458a3832e27e9b0d303ce0cfbbfb84aab94f3c1042b6a053cb42526879f77592b64377345b67fd58 +SHA512 (yubihsm-shell-2.4.1.tar.gz.sig) = 3a5792bf303707cff23929aeee8eed4796bd4d3ad15fdc07234cd7ee8e67371f98e466263ac60c1a5edd43d56d0d25c5011c54770833b5650f37b34897aaa66e SHA512 (gpgkey-9588EA0F.gpg) = ff3fb773cf95c8d28fb9630c8525539c7ba497a046292a9eda816dd77c4a8b199b74467c7639bbbb0236e439b4db4d0a8b1694a40b33e074072d3ecac46acd87 diff --git a/yubihsm-shell-2.4.0-fix-id-type.patch b/yubihsm-shell-2.4.0-fix-id-type.patch deleted file mode 100644 index 6e049ce..0000000 --- a/yubihsm-shell-2.4.0-fix-id-type.patch +++ /dev/null @@ -1,218 +0,0 @@ -From 4935de246254df236caf8487d15028d05ad88d94 Mon Sep 17 00:00:00 2001 -From: Per Nilsson -Date: Fri, 27 Jan 2023 10:09:11 +0100 -Subject: [PATCH] Fix type of id (#312) - ---- - pkcs11/util_pkcs11.c | 17 ++++------------- - pkcs11/util_pkcs11.h | 4 ++-- - pkcs11/yubihsm_pkcs11.c | 24 ++++++++---------------- - 3 files changed, 14 insertions(+), 31 deletions(-) - -diff --git a/pkcs11/util_pkcs11.c b/pkcs11/util_pkcs11.c -index 5834a5bd..db5f83ca 100644 ---- a/pkcs11/util_pkcs11.c -+++ b/pkcs11/util_pkcs11.c -@@ -4294,7 +4294,7 @@ CK_RV parse_hmac_template(CK_ATTRIBUTE_PTR pTemplate, CK_ULONG ulCount, - } - - CK_RV parse_meta_id_template(pkcs11_meta_object *pkcs11meta, bool pubkey, -- int *id, uint8_t *value, size_t value_len) { -+ uint16_t *id, uint8_t *value, size_t value_len) { - if (value_len != 2) { - if (pubkey) { - pkcs11meta->cka_id_pubkey.len = value_len; -@@ -4307,10 +4307,6 @@ CK_RV parse_meta_id_template(pkcs11_meta_object *pkcs11meta, bool pubkey, - } else { - if (!pubkey) { - *id = parse_id_value(value, value_len); -- if (*id == -1) { -- DBG_ERR("CKA_ID invalid in template"); -- return CKR_ATTRIBUTE_VALUE_INVALID; -- } - } - } - -@@ -4343,7 +4339,6 @@ CK_RV parse_rsa_generate_template(CK_ATTRIBUTE_PTR pPublicKeyTemplate, - - uint8_t *e = NULL; - CK_RV rv; -- int id = 0; - - memset(template->label, 0, sizeof(template->label)); - for (CK_ULONG i = 0; i < ulPublicKeyAttributeCount; i++) { -@@ -4482,14 +4477,13 @@ CK_RV parse_rsa_generate_template(CK_ATTRIBUTE_PTR pPublicKeyTemplate, - break; - - case CKA_ID: { -- rv = parse_meta_id_template(pkcs11meta, false, &id, -+ rv = parse_meta_id_template(pkcs11meta, false, &template->id, - pPrivateKeyTemplate[i].pValue, - pPrivateKeyTemplate[i].ulValueLen); - if (rv != CKR_OK) { - DBG_ERR("Failed to parse CKA_ID in PrivateKeyTemplate"); - return rv; - } -- template->id = id; - } break; - - case CKA_DECRYPT: -@@ -4572,7 +4566,7 @@ CK_RV parse_rsa_generate_template(CK_ATTRIBUTE_PTR pPublicKeyTemplate, - return CKR_OK; - } - --int parse_id_value(void *value, CK_ULONG len) { -+uint16_t parse_id_value(void *value, CK_ULONG len) { - switch (len) { - case 0: - return 0; -@@ -4596,7 +4590,6 @@ CK_RV parse_ec_generate_template(CK_ATTRIBUTE_PTR pPublicKeyTemplate, - uint8_t *ecparams = NULL; - uint16_t ecparams_len = 0; - CK_RV rv; -- int id; - - memset(template->label, 0, sizeof(template->label)); - for (CK_ULONG i = 0; i < ulPublicKeyAttributeCount; i++) { -@@ -4701,15 +4694,13 @@ CK_RV parse_ec_generate_template(CK_ATTRIBUTE_PTR pPublicKeyTemplate, - break; - - case CKA_ID: { -- rv = parse_meta_id_template(pkcs11meta, false, &id, -+ rv = parse_meta_id_template(pkcs11meta, false, &template->id, - pPrivateKeyTemplate[i].pValue, - pPrivateKeyTemplate[i].ulValueLen); - if (rv != CKR_OK) { - DBG_ERR("Failed to parse CKA_ID in PrivateKeyTemplate"); - return rv; - } -- template->id = id; -- - } break; - - case CKA_SIGN: -diff --git a/pkcs11/util_pkcs11.h b/pkcs11/util_pkcs11.h -index d8026e57..5a91ee34 100644 ---- a/pkcs11/util_pkcs11.h -+++ b/pkcs11/util_pkcs11.h -@@ -151,7 +151,7 @@ CK_RV parse_ec_generate_template(CK_ATTRIBUTE_PTR pPublicKeyTemplate, - yubihsm_pkcs11_object_template *template, - pkcs11_meta_object *pkcs11meta); - --int parse_id_value(void *value, CK_ULONG len); -+uint16_t parse_id_value(void *value, CK_ULONG len); - - CK_RV populate_template(int type, void *object, CK_ATTRIBUTE_PTR pTemplate, - CK_ULONG ulCount, yubihsm_pkcs11_session *session); -@@ -176,7 +176,7 @@ bool match_meta_attributes(yubihsm_pkcs11_session *session, - - bool is_meta_object(yh_object_descriptor *object); - CK_RV parse_meta_id_template(pkcs11_meta_object *pkcs11meta, bool public, -- int *id, uint8_t *value, size_t value_len); -+ uint16_t *id, uint8_t *value, size_t value_len); - void parse_meta_label_template(yubihsm_pkcs11_object_template *template, - pkcs11_meta_object *pkcs11meta, bool public, - uint8_t *value, size_t value_len); -diff --git a/pkcs11/yubihsm_pkcs11.c b/pkcs11/yubihsm_pkcs11.c -index 48b3bf46..6f715e01 100644 ---- a/pkcs11/yubihsm_pkcs11.c -+++ b/pkcs11/yubihsm_pkcs11.c -@@ -1383,10 +1383,6 @@ CK_DEFINE_FUNCTION(CK_RV, C_CreateObject) - id.d = 0; - } else { - id.d = parse_id_value(pTemplate[i].pValue, pTemplate[i].ulValueLen); -- if (id.d == (CK_ULONG) -1) { -- rv = CKR_ATTRIBUTE_VALUE_INVALID; -- goto c_co_out; -- } - } - id.set = true; - } else { -@@ -2200,7 +2196,7 @@ CK_DEFINE_FUNCTION(CK_RV, C_SetAttributeValue) - } - } - } else { -- int new_id = -+ uint16_t new_id = - parse_id_value(pTemplate[i].pValue, pTemplate[i].ulValueLen); - if (pTemplate[i].ulValueLen != 2 || new_id != object->object.id) { - if (object->object.type == YH_PUBLIC_KEY) { -@@ -2360,7 +2356,6 @@ CK_DEFINE_FUNCTION(CK_RV, C_FindObjectsInit) - - yh_rc rc = YHR_SUCCESS; - -- int id = 0; - uint8_t type = 0; - uint16_t domains = 0; - yh_capabilities capabilities = {{0}}; -@@ -2527,7 +2522,7 @@ CK_DEFINE_FUNCTION(CK_RV, C_FindObjectsInit) - yh_object_descriptor - tmp_objects[YH_MAX_ITEMS_COUNT + MAX_ECDH_SESSION_KEYS] = {0}; - size_t tmp_n_objects = YH_MAX_ITEMS_COUNT + MAX_ECDH_SESSION_KEYS; -- rc = yh_util_list_objects(session->slot->device_session, id, 0, domains, -+ rc = yh_util_list_objects(session->slot->device_session, 0, 0, domains, - &capabilities, algorithm, label, tmp_objects, - &tmp_n_objects); - if (rc != YHR_SUCCESS) { -@@ -2563,7 +2558,7 @@ CK_DEFINE_FUNCTION(CK_RV, C_FindObjectsInit) - } else { - yh_object_descriptor tmp_objects[YH_MAX_ITEMS_COUNT] = {0}; - size_t tmp_n_objects = sizeof(tmp_objects); -- rc = yh_util_list_objects(session->slot->device_session, id, -+ rc = yh_util_list_objects(session->slot->device_session, 0, - YH_OPAQUE, domains, &capabilities, - YH_ALGO_OPAQUE_X509_CERTIFICATE, label, - tmp_objects, &tmp_n_objects); -@@ -2599,7 +2594,7 @@ CK_DEFINE_FUNCTION(CK_RV, C_FindObjectsInit) - yh_object_descriptor - tmp_objects[YH_MAX_ITEMS_COUNT + MAX_ECDH_SESSION_KEYS] = {0}; - size_t tmp_n_objects = YH_MAX_ITEMS_COUNT + MAX_ECDH_SESSION_KEYS; -- rc = yh_util_list_objects(session->slot->device_session, id, type, -+ rc = yh_util_list_objects(session->slot->device_session, 0, type, - domains, &capabilities, algorithm, label, - tmp_objects, &tmp_n_objects); - -@@ -2636,12 +2631,7 @@ CK_DEFINE_FUNCTION(CK_RV, C_FindObjectsInit) - } - } - -- id = parse_id_value(template_id, template_id_len); -- if (id == -1) { -- DBG_ERR("Failed to parse ID from template"); -- rv = CKR_ATTRIBUTE_VALUE_INVALID; -- goto c_foi_out; -- } -+ uint16_t id = parse_id_value(template_id, template_id_len); - DBG_INFO("id parsed as %x", id); - - if (ulCount == 0 || -@@ -4948,12 +4938,14 @@ CK_DEFINE_FUNCTION(CK_RV, C_GenerateKey) - - case CKA_ID: - if (id.set == false) { -- rv = parse_meta_id_template(&meta_object, FALSE, (int *) &id.d, -+ uint16_t d; -+ rv = parse_meta_id_template(&meta_object, FALSE, &d, - pTemplate[i].pValue, - pTemplate[i].ulValueLen); - if (rv != CKR_OK) { - goto c_gk_out; - } -+ id.d = d; - id.set = true; - } else { - rv = CKR_TEMPLATE_INCONSISTENT; - -diff --git a/pkcs11/util_pkcs11.c b/pkcs11/util_pkcs11.c -index db5f83c..caa467f 100644 ---- a/pkcs11/util_pkcs11.c -+++ b/pkcs11/util_pkcs11.c -@@ -2720,7 +2720,7 @@ static CK_RV perform_aes_update(yh_session *session, - return rv; - } - -- DBG_INFO("Returning %lu bytes (buffered %lu bytes)", size, next); -+ DBG_INFO("Returning %zu bytes (buffered %zu bytes)", size, next); - *out_len = size; - - return CKR_OK; diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index e18f4d7..fffc5f9 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -1,8 +1,8 @@ %undefine __cmake_in_source_build Name: yubihsm-shell -Version: 2.4.0 -Release: 2%{?dist} +Version: 2.4.1 +Release: 1%{?dist} Summary: Tools to interact with YubiHSM 2 License: ASL 2.0 @@ -10,9 +10,6 @@ URL: https://github.com/Yubico/%{name}/ Source0: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.gz Source1: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.gz.sig Source2: gpgkey-9588EA0F.gpg -# https://github.com/Yubico/yubihsm-shell/pull/312 -# https://github.com/Yubico/yubihsm-shell/pull/314 -Patch1: yubihsm-shell-2.4.0-fix-id-type.patch BuildRequires: cmake BuildRequires: cppcheck @@ -50,7 +47,6 @@ Development libraries for working with yubihsm 2. %prep gpgv2 --quiet --keyring %{SOURCE2} %{SOURCE1} %{SOURCE0} %setup -q -%patch1 -p1 %build @@ -110,6 +106,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Thu Aug 17 2023 Jakub Jelen - 2.4.1-1 +- New upstream release (#2232340) + * Sat Jul 22 2023 Fedora Release Engineering - 2.4.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild From a0e17dab328b58e8243ec5f03a78699e403aecad Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Wed, 8 Nov 2023 09:22:33 +0100 Subject: [PATCH 04/31] yubihsm-shell-2.4.2-1 --- .gitignore | 2 ++ sources | 4 ++-- yubihsm-shell.spec | 5 ++++- 3 files changed, 8 insertions(+), 3 deletions(-) diff --git a/.gitignore b/.gitignore index 2a9ddb4..09ffd5c 100644 --- a/.gitignore +++ b/.gitignore @@ -25,3 +25,5 @@ /yubihsm-shell-2.4.0.tar.gz.sig /yubihsm-shell-2.4.1.tar.gz /yubihsm-shell-2.4.1.tar.gz.sig +/yubihsm-shell-2.4.2.tar.gz +/yubihsm-shell-2.4.2.tar.gz.sig diff --git a/sources b/sources index 3d8a419..e3c5ab9 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (yubihsm-shell-2.4.1.tar.gz) = e302d645ebbfc7425794a16e9301fdd4ce96d8dd9e8aca72458a3832e27e9b0d303ce0cfbbfb84aab94f3c1042b6a053cb42526879f77592b64377345b67fd58 -SHA512 (yubihsm-shell-2.4.1.tar.gz.sig) = 3a5792bf303707cff23929aeee8eed4796bd4d3ad15fdc07234cd7ee8e67371f98e466263ac60c1a5edd43d56d0d25c5011c54770833b5650f37b34897aaa66e +SHA512 (yubihsm-shell-2.4.2.tar.gz) = 2323f527f71bf569e12b860c3d43d8f08f4bfe93e320d4139cb038ce29c838e9b2149092f75062d46619f5ef32f35c6e11c5b85b796e2853046279a6de049a2e +SHA512 (yubihsm-shell-2.4.2.tar.gz.sig) = b633242ad94a62b9d1ecd4637d1957d64611fffaf23574db08f56b7002c971bf42ebfb6b071ffe3c6abf3888fb542314991dda19f4ccd29fb47503198e539f19 SHA512 (gpgkey-9588EA0F.gpg) = ff3fb773cf95c8d28fb9630c8525539c7ba497a046292a9eda816dd77c4a8b199b74467c7639bbbb0236e439b4db4d0a8b1694a40b33e074072d3ecac46acd87 diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index fffc5f9..c79b421 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -1,7 +1,7 @@ %undefine __cmake_in_source_build Name: yubihsm-shell -Version: 2.4.1 +Version: 2.4.2 Release: 1%{?dist} Summary: Tools to interact with YubiHSM 2 @@ -106,6 +106,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Wed Nov 08 2023 Jakub Jelen - 2.4.2-1 +- New upstream release (#2248609) + * Thu Aug 17 2023 Jakub Jelen - 2.4.1-1 - New upstream release (#2232340) From 7d50b40073728df5047db0db6dab23d4a6903c88 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 27 Jan 2024 10:53:00 +0000 Subject: [PATCH 05/31] Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild --- yubihsm-shell.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index c79b421..dc65f40 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -2,7 +2,7 @@ Name: yubihsm-shell Version: 2.4.2 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Tools to interact with YubiHSM 2 License: ASL 2.0 @@ -106,6 +106,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Sat Jan 27 2024 Fedora Release Engineering - 2.4.2-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + * Wed Nov 08 2023 Jakub Jelen - 2.4.2-1 - New upstream release (#2248609) From 4fa919f6c164a93a0fc07dcd5c81d50a5b8eafc7 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Tue, 2 Apr 2024 10:04:21 +0200 Subject: [PATCH 06/31] 2.5.0-1 --- .gitignore | 2 ++ sources | 4 ++-- yubihsm-shell.spec | 7 +++++-- 3 files changed, 9 insertions(+), 4 deletions(-) diff --git a/.gitignore b/.gitignore index 09ffd5c..1944690 100644 --- a/.gitignore +++ b/.gitignore @@ -27,3 +27,5 @@ /yubihsm-shell-2.4.1.tar.gz.sig /yubihsm-shell-2.4.2.tar.gz /yubihsm-shell-2.4.2.tar.gz.sig +/yubihsm-shell-2.5.0.tar.gz +/yubihsm-shell-2.5.0.tar.gz.sig diff --git a/sources b/sources index e3c5ab9..c98f1a7 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (yubihsm-shell-2.4.2.tar.gz) = 2323f527f71bf569e12b860c3d43d8f08f4bfe93e320d4139cb038ce29c838e9b2149092f75062d46619f5ef32f35c6e11c5b85b796e2853046279a6de049a2e -SHA512 (yubihsm-shell-2.4.2.tar.gz.sig) = b633242ad94a62b9d1ecd4637d1957d64611fffaf23574db08f56b7002c971bf42ebfb6b071ffe3c6abf3888fb542314991dda19f4ccd29fb47503198e539f19 +SHA512 (yubihsm-shell-2.5.0.tar.gz) = 02cab6549aa976f3f67e32d03038acf3c7194143f8e40fbf242f3ad92e90a666d69ecf381981306a3fd00524d15d2104d879cbfe1b3b44822542c72926f5a8b9 +SHA512 (yubihsm-shell-2.5.0.tar.gz.sig) = 3dcc5207ef9c9b9bc3f33dba349ad2e2a298d3fd862d3c70f995c4c1f3e9e67c4eeb22a659bd909f202273ed653c2c61a5fff9cfb2f4b0c61f7761f81efe98d6 SHA512 (gpgkey-9588EA0F.gpg) = ff3fb773cf95c8d28fb9630c8525539c7ba497a046292a9eda816dd77c4a8b199b74467c7639bbbb0236e439b4db4d0a8b1694a40b33e074072d3ecac46acd87 diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index dc65f40..2d3c70c 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -1,8 +1,8 @@ %undefine __cmake_in_source_build Name: yubihsm-shell -Version: 2.4.2 -Release: 2%{?dist} +Version: 2.5.0 +Release: 1%{?dist} Summary: Tools to interact with YubiHSM 2 License: ASL 2.0 @@ -106,6 +106,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Tue Apr 02 2024 Jakub Jelen - 2.5.0-1 +- New upstream release (#2272123) + * Sat Jan 27 2024 Fedora Release Engineering - 2.4.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild From 71c338c3a6ad5c9f9a5e84d3c4ad80b54fb644a0 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Tue, 2 Apr 2024 10:54:34 +0200 Subject: [PATCH 07/31] Fix format string on i686 --- yubihsm-shell-2.5.0-format.patch | 26 ++++++++++++++++++++++++++ yubihsm-shell.spec | 3 +++ 2 files changed, 29 insertions(+) create mode 100644 yubihsm-shell-2.5.0-format.patch diff --git a/yubihsm-shell-2.5.0-format.patch b/yubihsm-shell-2.5.0-format.patch new file mode 100644 index 0000000..661e0e9 --- /dev/null +++ b/yubihsm-shell-2.5.0-format.patch @@ -0,0 +1,26 @@ +From d93c78f5d91b9bd6dc2e6eda6596ad0659665014 Mon Sep 17 00:00:00 2001 +From: Jakub Jelen +Date: Tue, 2 Apr 2024 10:36:28 +0200 +Subject: [PATCH] pkcs11: Fix format string + +Signed-off-by: Jakub Jelen +--- + pkcs11/yubihsm_pkcs11.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/pkcs11/yubihsm_pkcs11.c b/pkcs11/yubihsm_pkcs11.c +index f3129df..d195cfe 100644 +--- a/pkcs11/yubihsm_pkcs11.c ++++ b/pkcs11/yubihsm_pkcs11.c +@@ -5667,7 +5667,7 @@ CK_DEFINE_FUNCTION(CK_RV, C_DeriveKey) + ecdh_key.id = ECDH_KEY_TYPE << 16 | seq; + ecdh_key.len = sizeof(ecdh_key.ecdh_key); + +- DBG_INFO("ecdh_key.id = %zu", ecdh_key.id); ++ DBG_INFO("ecdh_key.id = %lu", ecdh_key.id); + + if (value_len > ecdh_key.len) { + DBG_ERR("Requested derived key is too long"); +-- +2.44.0 + diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 2d3c70c..8840148 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -10,6 +10,8 @@ URL: https://github.com/Yubico/%{name}/ Source0: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.gz Source1: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.gz.sig Source2: gpgkey-9588EA0F.gpg +# https://github.com/Yubico/yubihsm-shell/pull/400 +Patch1: yubihsm-shell-2.5.0-format.patch BuildRequires: cmake BuildRequires: cppcheck @@ -47,6 +49,7 @@ Development libraries for working with yubihsm 2. %prep gpgv2 --quiet --keyring %{SOURCE2} %{SOURCE1} %{SOURCE0} %setup -q +%patch 1 -p1 %build From 765666d1767ae1bf8c0ea7ac8194f8ced967e2d5 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 20 Jul 2024 10:45:17 +0000 Subject: [PATCH 08/31] Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild --- yubihsm-shell.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 8840148..eb1dd99 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -2,7 +2,7 @@ Name: yubihsm-shell Version: 2.5.0 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Tools to interact with YubiHSM 2 License: ASL 2.0 @@ -109,6 +109,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Sat Jul 20 2024 Fedora Release Engineering - 2.5.0-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + * Tue Apr 02 2024 Jakub Jelen - 2.5.0-1 - New upstream release (#2272123) From dd9f683ed3dae3ecab96b4051143906386129ea2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miroslav=20Such=C3=BD?= Date: Wed, 24 Jul 2024 18:12:00 +0200 Subject: [PATCH 09/31] convert ASL 2.0 license to SPDX This is part of https://fedoraproject.org/wiki/Changes/SPDX_Licenses_Phase_4 --- yubihsm-shell.spec | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index eb1dd99..a3bf71c 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -2,10 +2,11 @@ Name: yubihsm-shell Version: 2.5.0 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Tools to interact with YubiHSM 2 -License: ASL 2.0 +# Automatically converted from old format: ASL 2.0 - review is highly recommended. +License: Apache-2.0 URL: https://github.com/Yubico/%{name}/ Source0: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.gz Source1: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.gz.sig @@ -109,6 +110,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Wed Jul 24 2024 Miroslav Suchý - 2.5.0-3 +- convert license to SPDX + * Sat Jul 20 2024 Fedora Release Engineering - 2.5.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild From 86a391634b094abab904a69d765cbdce4eeb11a4 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Tue, 30 Jul 2024 10:38:13 +0200 Subject: [PATCH 10/31] Unbreak build against the current pcsc-lite --- yubihsm-shell-2.5.0-pcsc-lite.patch | 38 +++++++++++++++++++++++++++++ yubihsm-shell.spec | 3 +++ 2 files changed, 41 insertions(+) create mode 100644 yubihsm-shell-2.5.0-pcsc-lite.patch diff --git a/yubihsm-shell-2.5.0-pcsc-lite.patch b/yubihsm-shell-2.5.0-pcsc-lite.patch new file mode 100644 index 0000000..c79ffb9 --- /dev/null +++ b/yubihsm-shell-2.5.0-pcsc-lite.patch @@ -0,0 +1,38 @@ +From 440ba3ad140732ab51bc2df56ae0c82684d02922 Mon Sep 17 00:00:00 2001 +From: Jakub Jelen +Date: Tue, 30 Jul 2024 10:18:02 +0200 +Subject: [PATCH] cmake: Fix build against pcsc-lite >= 2.2 + +The pcsc-lite 2.2.0 switched from autotools to meson and reworked the +pkgconfig files. The new pkg config provides CFLAGS that work ok, but +the yubihsm-shell ignores them and hopes that all included files are in +the default include directory (with the PCSC prefix). + +Note, the value ${LIBPCSC_CFLAGS} is a semicolon separated list which +we need to split to separate items here. + +This solution works with both old and new versions. + +Fixes: #404 + +Signed-off-by: Jakub Jelen +--- + CMakeLists.txt | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/CMakeLists.txt b/CMakeLists.txt +index acbb392..ecf3df8 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -194,6 +194,8 @@ if(NOT BUILD_ONLY_LIB) + + if(${CMAKE_SYSTEM_NAME} MATCHES "Linux") + pkg_search_module (LIBPCSC REQUIRED libpcsclite) ++ string (REPLACE ";" " " MY_LIBPCSC_CFLAGS "${LIBPCSC_CFLAGS}") ++ string (APPEND CMAKE_C_FLAGS " ${MY_LIBPCSC_CFLAGS}") + elseif(${CMAKE_SYSTEM_NAME} MATCHES "Windows") + set (LIBPCSC_LDFLAGS "winscard.lib") + elseif(${CMAKE_SYSTEM_NAME} MATCHES "Darwin") +-- +2.45.2 + diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index a3bf71c..5b9dfed 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -13,6 +13,8 @@ Source1: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.g Source2: gpgkey-9588EA0F.gpg # https://github.com/Yubico/yubihsm-shell/pull/400 Patch1: yubihsm-shell-2.5.0-format.patch +# https://github.com/Yubico/yubihsm-shell/pull/411 +Patch2: yubihsm-shell-2.5.0-pcsc-lite.patch BuildRequires: cmake BuildRequires: cppcheck @@ -51,6 +53,7 @@ Development libraries for working with yubihsm 2. gpgv2 --quiet --keyring %{SOURCE2} %{SOURCE1} %{SOURCE0} %setup -q %patch 1 -p1 +%patch 2 -p1 %build From 7e1438d1a8ca9b252e43b3f0af148fa1dfc2f3c9 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Tue, 30 Jul 2024 10:41:11 +0200 Subject: [PATCH 11/31] 2.5.0-4 --- yubihsm-shell.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 5b9dfed..b4ac44a 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -2,7 +2,7 @@ Name: yubihsm-shell Version: 2.5.0 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Tools to interact with YubiHSM 2 # Automatically converted from old format: ASL 2.0 - review is highly recommended. @@ -113,6 +113,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Tue Jul 30 2024 Jakub Jelen - 2.5.0-4 +- Fix build against pcsc-lite >= 2.2 (#2301379) + * Wed Jul 24 2024 Miroslav Suchý - 2.5.0-3 - convert license to SPDX From d143eb64cc39e2571aa82672e7e350d6ed2978e3 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Wed, 11 Sep 2024 09:28:08 +0200 Subject: [PATCH 12/31] 2.6.0-1 --- .gitignore | 2 ++ sources | 4 ++-- yubihsm-shell-2.5.0-format.patch | 26 -------------------------- yubihsm-shell.spec | 12 +++++++----- 4 files changed, 11 insertions(+), 33 deletions(-) delete mode 100644 yubihsm-shell-2.5.0-format.patch diff --git a/.gitignore b/.gitignore index 1944690..02f5822 100644 --- a/.gitignore +++ b/.gitignore @@ -29,3 +29,5 @@ /yubihsm-shell-2.4.2.tar.gz.sig /yubihsm-shell-2.5.0.tar.gz /yubihsm-shell-2.5.0.tar.gz.sig +/yubihsm-shell-2.6.0.tar.gz +/yubihsm-shell-2.6.0.tar.gz.sig diff --git a/sources b/sources index c98f1a7..4336d34 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (yubihsm-shell-2.5.0.tar.gz) = 02cab6549aa976f3f67e32d03038acf3c7194143f8e40fbf242f3ad92e90a666d69ecf381981306a3fd00524d15d2104d879cbfe1b3b44822542c72926f5a8b9 -SHA512 (yubihsm-shell-2.5.0.tar.gz.sig) = 3dcc5207ef9c9b9bc3f33dba349ad2e2a298d3fd862d3c70f995c4c1f3e9e67c4eeb22a659bd909f202273ed653c2c61a5fff9cfb2f4b0c61f7761f81efe98d6 +SHA512 (yubihsm-shell-2.6.0.tar.gz) = 04335fffa110fe43df2f1e46231e0ca7fcfe4f6a7305f8630dd346f7ed5d6d57bab53f6c268010bf7358729a429b05c52ffd273fe021cf60cfe97a6941ab0f56 +SHA512 (yubihsm-shell-2.6.0.tar.gz.sig) = 70d4c0d111626ad4567bf0adb5a5800fe1d571ef27eed79991a8c7ba473a8fad928b202c3d4aa6a640a28d7446d5b40d5723691de241e0660471163bb8aa1646 SHA512 (gpgkey-9588EA0F.gpg) = ff3fb773cf95c8d28fb9630c8525539c7ba497a046292a9eda816dd77c4a8b199b74467c7639bbbb0236e439b4db4d0a8b1694a40b33e074072d3ecac46acd87 diff --git a/yubihsm-shell-2.5.0-format.patch b/yubihsm-shell-2.5.0-format.patch deleted file mode 100644 index 661e0e9..0000000 --- a/yubihsm-shell-2.5.0-format.patch +++ /dev/null @@ -1,26 +0,0 @@ -From d93c78f5d91b9bd6dc2e6eda6596ad0659665014 Mon Sep 17 00:00:00 2001 -From: Jakub Jelen -Date: Tue, 2 Apr 2024 10:36:28 +0200 -Subject: [PATCH] pkcs11: Fix format string - -Signed-off-by: Jakub Jelen ---- - pkcs11/yubihsm_pkcs11.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/pkcs11/yubihsm_pkcs11.c b/pkcs11/yubihsm_pkcs11.c -index f3129df..d195cfe 100644 ---- a/pkcs11/yubihsm_pkcs11.c -+++ b/pkcs11/yubihsm_pkcs11.c -@@ -5667,7 +5667,7 @@ CK_DEFINE_FUNCTION(CK_RV, C_DeriveKey) - ecdh_key.id = ECDH_KEY_TYPE << 16 | seq; - ecdh_key.len = sizeof(ecdh_key.ecdh_key); - -- DBG_INFO("ecdh_key.id = %zu", ecdh_key.id); -+ DBG_INFO("ecdh_key.id = %lu", ecdh_key.id); - - if (value_len > ecdh_key.len) { - DBG_ERR("Requested derived key is too long"); --- -2.44.0 - diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index b4ac44a..19ccb83 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -1,8 +1,8 @@ %undefine __cmake_in_source_build Name: yubihsm-shell -Version: 2.5.0 -Release: 4%{?dist} +Version: 2.6.0 +Release: 1%{?dist} Summary: Tools to interact with YubiHSM 2 # Automatically converted from old format: ASL 2.0 - review is highly recommended. @@ -11,8 +11,6 @@ URL: https://github.com/Yubico/%{name}/ Source0: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.gz Source1: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.gz.sig Source2: gpgkey-9588EA0F.gpg -# https://github.com/Yubico/yubihsm-shell/pull/400 -Patch1: yubihsm-shell-2.5.0-format.patch # https://github.com/Yubico/yubihsm-shell/pull/411 Patch2: yubihsm-shell-2.5.0-pcsc-lite.patch @@ -52,7 +50,6 @@ Development libraries for working with yubihsm 2. %prep gpgv2 --quiet --keyring %{SOURCE2} %{SOURCE1} %{SOURCE0} %setup -q -%patch 1 -p1 %patch 2 -p1 @@ -107,12 +104,17 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %dir %{_includedir}/pkcs11 %{_includedir}/pkcs11/pkcs11.h %{_includedir}/pkcs11/pkcs11y.h +%{_includedir}/pkcs11/pkcs11f.h +%{_includedir}/pkcs11/pkcs11t.h %{_datadir}/pkgconfig/yubihsm.pc %{_datadir}/pkgconfig/ykhsmauth.pc %changelog +* Wed Sep 11 2024 Jakub Jelen - 2.6.0-1 +- New upstream release (#2311424) + * Tue Jul 30 2024 Jakub Jelen - 2.5.0-4 - Fix build against pcsc-lite >= 2.2 (#2301379) From ff554a070e5fb66c66418e1a03639c15f99b7cba Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Wed, 11 Sep 2024 11:05:28 +0200 Subject: [PATCH 13/31] Fix build on i686 --- ...hsm-shell-2.6.0-incompatible-pointer.patch | 23 +++++++++++++++++++ yubihsm-shell.spec | 3 +++ 2 files changed, 26 insertions(+) create mode 100644 yubihsm-shell-2.6.0-incompatible-pointer.patch diff --git a/yubihsm-shell-2.6.0-incompatible-pointer.patch b/yubihsm-shell-2.6.0-incompatible-pointer.patch new file mode 100644 index 0000000..84ef462 --- /dev/null +++ b/yubihsm-shell-2.6.0-incompatible-pointer.patch @@ -0,0 +1,23 @@ +diff --git a/pkcs11/tests/asym_wrap_test.c b/pkcs11/tests/asym_wrap_test.c +index 5f37ae4..6dcdec3 100644 +--- a/pkcs11/tests/asym_wrap_test.c ++++ b/pkcs11/tests/asym_wrap_test.c +@@ -334,6 +334,7 @@ static void get_wrapped_data(CK_OBJECT_HANDLE wrapping_keyid, + CK_RSA_PKCS_OAEP_PARAMS oaep_params = {CKM_SHA256, CKG_MGF1_SHA256, 0, NULL, 0}; + CK_RSA_AES_KEY_WRAP_PARAMS params = {256, &oaep_params}; + CK_MECHANISM mech = {0, ¶ms, sizeof(params)}; ++ CK_ULONG wrapped_len = *wrapped_obj_len; + + if (only_key) { + mech.mechanism = CKM_RSA_AES_KEY_WRAP; +@@ -341,7 +342,8 @@ static void get_wrapped_data(CK_OBJECT_HANDLE wrapping_keyid, + mech.mechanism = CKM_YUBICO_RSA_WRAP; + } + assert(p11->C_WrapKey(session, &mech, wrapping_keyid, keyid, wrapped_obj, +- wrapped_obj_len) == CKR_OK); ++ &wrapped_len) == CKR_OK); ++ *wrapped_obj_len = wrapped_len; + } + + static CK_OBJECT_HANDLE import_wrapped_data(CK_OBJECT_HANDLE wrapping_keyid, + diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 19ccb83..1a1acee 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -11,6 +11,8 @@ URL: https://github.com/Yubico/%{name}/ Source0: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.gz Source1: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.gz.sig Source2: gpgkey-9588EA0F.gpg +# https://github.com/Yubico/yubihsm-shell/pull/430 +Patch1: yubihsm-shell-2.6.0-incompatible-pointer.patch # https://github.com/Yubico/yubihsm-shell/pull/411 Patch2: yubihsm-shell-2.5.0-pcsc-lite.patch @@ -50,6 +52,7 @@ Development libraries for working with yubihsm 2. %prep gpgv2 --quiet --keyring %{SOURCE2} %{SOURCE1} %{SOURCE0} %setup -q +%patch 1 -p1 %patch 2 -p1 From 7bf666554b5750840183e533a56d4be5009dec73 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sun, 19 Jan 2025 16:37:54 +0000 Subject: [PATCH 14/31] Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild --- yubihsm-shell.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 1a1acee..fd3a6f2 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -2,7 +2,7 @@ Name: yubihsm-shell Version: 2.6.0 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Tools to interact with YubiHSM 2 # Automatically converted from old format: ASL 2.0 - review is highly recommended. @@ -115,6 +115,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Sun Jan 19 2025 Fedora Release Engineering - 2.6.0-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + * Wed Sep 11 2024 Jakub Jelen - 2.6.0-1 - New upstream release (#2311424) From ba8b9bd3b5ca29604356cf07c000ce34b6ab5484 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Wed, 5 Feb 2025 14:41:20 +0100 Subject: [PATCH 15/31] Fixes for gcc15 changes --- yubihsm-shell-gcc15.patch | 203 ++++++++++++++++++++++++++++++++++++++ yubihsm-shell.spec | 3 + 2 files changed, 206 insertions(+) create mode 100644 yubihsm-shell-gcc15.patch diff --git a/yubihsm-shell-gcc15.patch b/yubihsm-shell-gcc15.patch new file mode 100644 index 0000000..303707f --- /dev/null +++ b/yubihsm-shell-gcc15.patch @@ -0,0 +1,203 @@ +From f345fa4decfa075ea9b31624d3d643921289978c Mon Sep 17 00:00:00 2001 +From: Jakub Jelen +Date: Wed, 5 Feb 2025 14:16:13 +0100 +Subject: [PATCH] tests: Fix untermined string initializaions +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +The new GCC 15 reports error when the string initializers overflow the +size of the underlying structure. This is common when the byte strings +are constructed in quotes such as "\xBB" as such this string has +trailing null byte and therefore the size two. + +This is not an issue in the tests as they do not expect the string to be +NULL terminated, but it might uncover issues in other cases. + +Example of the error: + +/builddir/build/BUILD/yubihsm-shell-2.6.0-build/yubihsm-shell-2.6.0/pkcs11/tests/aes_encrypt_test.c:38:3: error: initializer-string for array of ‘unsigned char’ is too long [-Werror=unterminated-string-initialization] + 38 | "\x6b\xc1\xbe\xe2\x2e\x40\x9f\x96\xe9\x3d\x7e\x11\x73\x93\x17\x2a" + | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + +Signed-off-by: Jakub Jelen +--- + examples/encrypt_aes.c | 2 +- + examples/yubico_otp.c | 42 +++++++++++++++++++-------------- + lib/tests/test_parsing.c | 10 ++++---- + pkcs11/tests/aes_encrypt_test.c | 20 +++++++++------- + pkcs11/util_pkcs11.c | 10 ++++---- + 5 files changed, 46 insertions(+), 38 deletions(-) + +diff --git a/examples/encrypt_aes.c b/examples/encrypt_aes.c +index cc4a2db..b51f855 100644 +--- a/examples/encrypt_aes.c ++++ b/examples/encrypt_aes.c +@@ -25,7 +25,7 @@ + + const char *key_label = "label"; + const uint8_t password[] = "password"; +-const uint8_t plaintext[16] = "single block msg"; ++const uint8_t plaintext[16] = "singleblock msg"; + + int main(void) { + yh_connector *connector = NULL; +diff --git a/examples/yubico_otp.c b/examples/yubico_otp.c +index 8860f9a..343a4b9 100644 +--- a/examples/yubico_otp.c ++++ b/examples/yubico_otp.c +@@ -44,24 +44,30 @@ static const struct { + uint16_t crc; + uint8_t otp[32]; + } test_vectors[] = +- {{"\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f", +- "\x01\x02\x03\x04\x05\x06", 0x0001, 0x0001, 0x01, 0x01, 0x0000, 0xfe36, +- "\x2f\x5d\x71\xa4\x91\x5d\xec\x30\x4a\xa1\x3c\xcf\x97\xbb\x0d\xbb"}, +- {"\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f", +- "\x01\x02\x03\x04\x05\x06", 0x0001, 0x0001, 0x01, 0x02, 0x0000, 0x1152, +- "\xcb\x71\x0b\x46\x2b\x7b\x1c\x23\x10\x0c\xb2\x46\x85\xb6\x4d\x33"}, +- {"\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f", +- "\x01\x02\x03\x04\x05\x06", 0x0fff, 0x0001, 0x01, 0x01, 0x0000, 0x9454, +- "\x77\x99\x78\x12\x9b\xcc\x26\x42\xc8\xad\xf5\xc1\x99\x81\xa0\x16"}, +- {"\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88", +- "\x88\x88\x88\x88\x88\x88", 0x8888, 0x8888, 0x88, 0x88, 0x8888, 0xd3b6, +- "\x20\x76\x5f\xc6\x83\xe0\xfc\x7b\x62\x42\x21\x86\x48\x4d\x82\x37"}, +- {"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00", +- "\x00\x00\x00\x00\x00\x00", 0x0000, 0x0000, 0x00, 0x00, 0x0000, 0xa96a, +- "\x99\x9b\x08\xbf\x0b\x3b\x98\xf8\x5b\x08\x76\xa8\x77\x15\x16\x16"}, +- {"\xc4\x42\x28\x90\x65\x30\x76\xcd\xe7\x3d\x44\x9b\x19\x1b\x41\x6a", +- "\x33\xc6\x9e\x7f\x24\x9e", 0x0001, 0x13a7, 0x24, 0x00, 0xc63c, 0x1c86, +- "\x7e\x0f\xc9\x87\x35\x16\x72\xc0\x70\xfa\x5c\x05\x95\xec\x68\xb8"}}; ++ {{{0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f}, ++ {0x01, 0x02, 0x03, 0x04, 0x05, 0x06}, ++ 0x0001, 0x0001, 0x01, 0x01, 0x0000, 0xfe36, ++ {0x2f, 0x5d, 0x71, 0xa4, 0x91, 0x5d, 0xec, 0x30, 0x4a, 0xa1, 0x3c, 0xcf, 0x97, 0xbb, 0x0d, 0xbb}}, ++ {{0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f}, ++ {0x01, 0x02, 0x03, 0x04, 0x05, 0x06}, ++ 0x0001, 0x0001, 0x01, 0x02, 0x0000, 0x1152, ++ {0xcb, 0x71, 0x0b, 0x46, 0x2b, 0x7b, 0x1c, 0x23, 0x10, 0x0c, 0xb2, 0x46, 0x85, 0xb6, 0x4d, 0x33}}, ++ {{0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f}, ++ {0x01, 0x02, 0x03, 0x04, 0x05, 0x06}, ++ 0x0fff, 0x0001, 0x01, 0x01, 0x0000, 0x9454, ++ {0x77, 0x99, 0x78, 0x12, 0x9b, 0xcc, 0x26, 0x42, 0xc8, 0xad, 0xf5, 0xc1, 0x99, 0x81, 0xa0, 0x16}}, ++ {{0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88}, ++ {0x88, 0x88, 0x88, 0x88, 0x88, 0x88}, ++ 0x8888, 0x8888, 0x88, 0x88, 0x8888, 0xd3b6, ++ {0x20, 0x76, 0x5f, 0xc6, 0x83, 0xe0, 0xfc, 0x7b, 0x62, 0x42, 0x21, 0x86, 0x48, 0x4d, 0x82, 0x37}}, ++ {{0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00}, ++ {0x00, 0x00, 0x00, 0x00, 0x00, 0x00}, ++ 0x0000, 0x0000, 0x00, 0x00, 0x0000, 0xa96a, ++ {0x99, 0x9b, 0x08, 0xbf, 0x0b, 0x3b, 0x98, 0xf8, 0x5b, 0x08, 0x76, 0xa8, 0x77, 0x15, 0x16, 0x16}}, ++ {{0xc4, 0x42, 0x28, 0x90, 0x65, 0x30, 0x76, 0xcd, 0xe7, 0x3d, 0x44, 0x9b, 0x19, 0x1b, 0x41, 0x6a}, ++ {0x33, 0xc6, 0x9e, 0x7f, 0x24, 0x9e}, ++ 0x0001, 0x13a7, 0x24, 0x00, 0xc63c, 0x1c86, ++ {0x7e, 0x0f, 0xc9, 0x87, 0x35, 0x16, 0x72, 0xc0, 0x70, 0xfa, 0x5c, 0x05, 0x95, 0xec, 0x68, 0xb8}}}; + + static uint16_t yubikey_crc16(const uint8_t *buf, size_t buf_size) { + uint16_t m_crc = 0xffff; +diff --git a/lib/tests/test_parsing.c b/lib/tests/test_parsing.c +index 82c516a..1bd08e8 100644 +--- a/lib/tests/test_parsing.c ++++ b/lib/tests/test_parsing.c +@@ -67,12 +67,12 @@ static void test_capabilities1(void) { + const char *string; + yh_capabilities capabilities; + } tests[] = { +- {"get-opaque", {"\x00\x00\x00\x00\x00\x00\x00\x01"}}, ++ {"get-opaque", {{0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01}}}, + {"sign-hmac:verify-hmac|exportable-under-wrap,", +- {"\x00\x00\x00\x00\x00\xc1\x00\x00"}}, +- {",,unwrap-data|:wrap-data,,,", {"\x00\x00\x00\x60\x00\x00\x00\x00"}}, +- {"0x7fffffffffffffff", {"\x7f\xff\xff\xff\xff\xff\xff\xff"}}, +- {"0xffffffffffffffff", {"\xff\xff\xff\xff\xff\xff\xff\xff"}}, ++ {{0x00, 0x00, 0x00, 0x00, 0x00, 0xc1, 0x00, 0x00}}}, ++ {",,unwrap-data|:wrap-data,,,", {{0x00, 0x00, 0x00, 0x60, 0x00, 0x00, 0x00, 0x00}}}, ++ {"0x7fffffffffffffff", {{0x7f, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff}}}, ++ {"0xffffffffffffffff", {{0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff}}}, + }; + + for (size_t i = 0; i < sizeof(tests) / sizeof(tests[0]); i++) { +diff --git a/pkcs11/tests/aes_encrypt_test.c b/pkcs11/tests/aes_encrypt_test.c +index a5140f5..56acd3a 100644 +--- a/pkcs11/tests/aes_encrypt_test.c ++++ b/pkcs11/tests/aes_encrypt_test.c +@@ -34,11 +34,12 @@ + // the plaintext blocks. Each row corresponds to a whole block. + // clang-format off + #define PLAINTEXT_LENGTH (4 * 16) +-static uint8_t plaintext[PLAINTEXT_LENGTH] = +- "\x6b\xc1\xbe\xe2\x2e\x40\x9f\x96\xe9\x3d\x7e\x11\x73\x93\x17\x2a" +- "\xae\x2d\x8a\x57\x1e\x03\xac\x9c\x9e\xb7\x6f\xac\x45\xaf\x8e\x51" +- "\x30\xc8\x1c\x46\xa3\x5c\xe4\x11\xe5\xfb\xc1\x19\x1a\x0a\x52\xef" +- "\xf6\x9f\x24\x45\xdf\x4f\x9b\x17\xad\x2b\x41\x7b\xe6\x6c\x37\x10"; ++static uint8_t plaintext[PLAINTEXT_LENGTH] = { ++ 0x6b, 0xc1, 0xbe, 0xe2, 0x2e, 0x40, 0x9f, 0x96, 0xe9, 0x3d, 0x7e, 0x11, 0x73, 0x93, 0x17, 0x2a, ++ 0xae, 0x2d, 0x8a, 0x57, 0x1e, 0x03, 0xac, 0x9c, 0x9e, 0xb7, 0x6f, 0xac, 0x45, 0xaf, 0x8e, 0x51, ++ 0x30, 0xc8, 0x1c, 0x46, 0xa3, 0x5c, 0xe4, 0x11, 0xe5, 0xfb, 0xc1, 0x19, 0x1a, 0x0a, 0x52, 0xef, ++ 0xf6, 0x9f, 0x24, 0x45, 0xdf, 0x4f, 0x9b, 0x17, 0xad, 0x2b, 0x41, 0x7b, 0xe6, 0x6c, 0x37, 0x10, ++}; + // clang-format on + + #define TEST_ECB(key, ptlen, ct) \ +@@ -50,15 +51,16 @@ static uint8_t plaintext[PLAINTEXT_LENGTH] = + + struct test { + CK_MECHANISM_TYPE mechanism; +- uint8_t key[32]; ++ uint8_t key[32 + 1]; + uint8_t keylen; + size_t plaintext_len; +- uint8_t ciphertext[sizeof(plaintext) + 16]; ++ uint8_t ciphertext[sizeof(plaintext) + 16 + 1]; + size_t ciphertext_len; + }; + +-static uint8_t iv[16] = +- "\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f"; ++static uint8_t iv[16] = { ++ 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, ++}; + + // CKM_AES_{ECB,CBC} test vectors from NIST. + // CKM_AES_CBC_PAD calculated out-of-band. +diff --git a/pkcs11/util_pkcs11.c b/pkcs11/util_pkcs11.c +index 8d38c58..3bbad6b 100644 +--- a/pkcs11/util_pkcs11.c ++++ b/pkcs11/util_pkcs11.c +@@ -709,7 +709,7 @@ CK_RV get_mechanism_info(yubihsm_pkcs11_slot *slot, CK_MECHANISM_TYPE type, + #define PKCS11_LABEL_TAG 2 + #define PKCS11_PUBKEY_ID_TAG 3 + #define PKCS11_PUBKEY_LABEL_TAG 4 +-const char META_OBJECT_VERSION[4] = "MDB1"; ++const char META_OBJECT_VERSION[5] = "MDB1"; + + static uint16_t write_meta_item(uint8_t *target_value, uint8_t tag, + cka_meta_item *meta_item) { +@@ -763,11 +763,11 @@ static CK_RV read_meta_object(yubihsm_pkcs11_slot *slot, uint16_t opaque_id, + } + + uint8_t *p = opaque_value; +- if (memcmp(p, META_OBJECT_VERSION, sizeof(META_OBJECT_VERSION)) != 0) { ++ if (memcmp(p, META_OBJECT_VERSION, strlen(META_OBJECT_VERSION)) != 0) { + DBG_ERR("Meta object value has unexpected version"); + return CKR_DATA_INVALID; + } +- p += sizeof(META_OBJECT_VERSION); ++ p += strlen(META_OBJECT_VERSION); + + meta_object->target_type = *p++; + +@@ -931,8 +931,8 @@ CK_RV write_meta_object(yubihsm_pkcs11_slot *slot, + uint8_t opaque_value[YH_MSG_BUF_SIZE] = {0}; + uint8_t *p = opaque_value; + +- memcpy(p, META_OBJECT_VERSION, sizeof(META_OBJECT_VERSION)); +- p += sizeof(META_OBJECT_VERSION); ++ memcpy(p, META_OBJECT_VERSION, strlen(META_OBJECT_VERSION)); ++ p += strlen(META_OBJECT_VERSION); + + *p++ = meta_object->target_type; + +-- +2.48.1 + diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index fd3a6f2..9f828ab 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -15,6 +15,8 @@ Source2: gpgkey-9588EA0F.gpg Patch1: yubihsm-shell-2.6.0-incompatible-pointer.patch # https://github.com/Yubico/yubihsm-shell/pull/411 Patch2: yubihsm-shell-2.5.0-pcsc-lite.patch +# https://github.com/Yubico/yubihsm-shell/pull/450 +Patch3: yubihsm-shell-gcc15.patch BuildRequires: cmake BuildRequires: cppcheck @@ -54,6 +56,7 @@ gpgv2 --quiet --keyring %{SOURCE2} %{SOURCE1} %{SOURCE0} %setup -q %patch 1 -p1 %patch 2 -p1 +%patch 3 -p1 %build From 1889d564e20ff2384e3a127c1138ae42770eab19 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Wed, 5 Feb 2025 14:42:01 +0100 Subject: [PATCH 16/31] 2.6.0-3 --- yubihsm-shell.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 9f828ab..b0dcd98 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -2,7 +2,7 @@ Name: yubihsm-shell Version: 2.6.0 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Tools to interact with YubiHSM 2 # Automatically converted from old format: ASL 2.0 - review is highly recommended. @@ -118,6 +118,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Wed Feb 05 2025 Jakub Jelen - 2.6.0-3 +- Fix gcc15 warnings (#2341598) + * Sun Jan 19 2025 Fedora Release Engineering - 2.6.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild From 3f8b5cd0d4a0c86266014f71c30f97102b9bf994 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Tue, 17 Jun 2025 10:28:07 +0200 Subject: [PATCH 17/31] yubihsm-shell-2.7.0-1 --- .gitignore | 2 + sources | 4 +- ...hsm-shell-2.6.0-incompatible-pointer.patch | 23 -- yubihsm-shell-gcc15.patch | 203 ------------------ yubihsm-shell.spec | 11 +- 5 files changed, 9 insertions(+), 234 deletions(-) delete mode 100644 yubihsm-shell-2.6.0-incompatible-pointer.patch delete mode 100644 yubihsm-shell-gcc15.patch diff --git a/.gitignore b/.gitignore index 02f5822..d3e8947 100644 --- a/.gitignore +++ b/.gitignore @@ -31,3 +31,5 @@ /yubihsm-shell-2.5.0.tar.gz.sig /yubihsm-shell-2.6.0.tar.gz /yubihsm-shell-2.6.0.tar.gz.sig +/yubihsm-shell-2.7.0.tar.gz +/yubihsm-shell-2.7.0.tar.gz.sig diff --git a/sources b/sources index 4336d34..412fc9e 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (yubihsm-shell-2.6.0.tar.gz) = 04335fffa110fe43df2f1e46231e0ca7fcfe4f6a7305f8630dd346f7ed5d6d57bab53f6c268010bf7358729a429b05c52ffd273fe021cf60cfe97a6941ab0f56 -SHA512 (yubihsm-shell-2.6.0.tar.gz.sig) = 70d4c0d111626ad4567bf0adb5a5800fe1d571ef27eed79991a8c7ba473a8fad928b202c3d4aa6a640a28d7446d5b40d5723691de241e0660471163bb8aa1646 +SHA512 (yubihsm-shell-2.7.0.tar.gz) = 63c5062ba3d588cf922a4135b9106b40b7a299edffc0ab1ad18cdbb7489d9542510e58acc400c1449e785511426c40f8266e374f3d6d92315cdf302ebcd58201 +SHA512 (yubihsm-shell-2.7.0.tar.gz.sig) = 13fc99dbfc016f458a0394dec126bfba28538cd5f29e86ca3991783fcbe717e39cbdfc03eb955e96bd1bf354fbd99ff07da06b00e118eff5de3f55dc99f0cc08 SHA512 (gpgkey-9588EA0F.gpg) = ff3fb773cf95c8d28fb9630c8525539c7ba497a046292a9eda816dd77c4a8b199b74467c7639bbbb0236e439b4db4d0a8b1694a40b33e074072d3ecac46acd87 diff --git a/yubihsm-shell-2.6.0-incompatible-pointer.patch b/yubihsm-shell-2.6.0-incompatible-pointer.patch deleted file mode 100644 index 84ef462..0000000 --- a/yubihsm-shell-2.6.0-incompatible-pointer.patch +++ /dev/null @@ -1,23 +0,0 @@ -diff --git a/pkcs11/tests/asym_wrap_test.c b/pkcs11/tests/asym_wrap_test.c -index 5f37ae4..6dcdec3 100644 ---- a/pkcs11/tests/asym_wrap_test.c -+++ b/pkcs11/tests/asym_wrap_test.c -@@ -334,6 +334,7 @@ static void get_wrapped_data(CK_OBJECT_HANDLE wrapping_keyid, - CK_RSA_PKCS_OAEP_PARAMS oaep_params = {CKM_SHA256, CKG_MGF1_SHA256, 0, NULL, 0}; - CK_RSA_AES_KEY_WRAP_PARAMS params = {256, &oaep_params}; - CK_MECHANISM mech = {0, ¶ms, sizeof(params)}; -+ CK_ULONG wrapped_len = *wrapped_obj_len; - - if (only_key) { - mech.mechanism = CKM_RSA_AES_KEY_WRAP; -@@ -341,7 +342,8 @@ static void get_wrapped_data(CK_OBJECT_HANDLE wrapping_keyid, - mech.mechanism = CKM_YUBICO_RSA_WRAP; - } - assert(p11->C_WrapKey(session, &mech, wrapping_keyid, keyid, wrapped_obj, -- wrapped_obj_len) == CKR_OK); -+ &wrapped_len) == CKR_OK); -+ *wrapped_obj_len = wrapped_len; - } - - static CK_OBJECT_HANDLE import_wrapped_data(CK_OBJECT_HANDLE wrapping_keyid, - diff --git a/yubihsm-shell-gcc15.patch b/yubihsm-shell-gcc15.patch deleted file mode 100644 index 303707f..0000000 --- a/yubihsm-shell-gcc15.patch +++ /dev/null @@ -1,203 +0,0 @@ -From f345fa4decfa075ea9b31624d3d643921289978c Mon Sep 17 00:00:00 2001 -From: Jakub Jelen -Date: Wed, 5 Feb 2025 14:16:13 +0100 -Subject: [PATCH] tests: Fix untermined string initializaions -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -The new GCC 15 reports error when the string initializers overflow the -size of the underlying structure. This is common when the byte strings -are constructed in quotes such as "\xBB" as such this string has -trailing null byte and therefore the size two. - -This is not an issue in the tests as they do not expect the string to be -NULL terminated, but it might uncover issues in other cases. - -Example of the error: - -/builddir/build/BUILD/yubihsm-shell-2.6.0-build/yubihsm-shell-2.6.0/pkcs11/tests/aes_encrypt_test.c:38:3: error: initializer-string for array of ‘unsigned char’ is too long [-Werror=unterminated-string-initialization] - 38 | "\x6b\xc1\xbe\xe2\x2e\x40\x9f\x96\xe9\x3d\x7e\x11\x73\x93\x17\x2a" - | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - -Signed-off-by: Jakub Jelen ---- - examples/encrypt_aes.c | 2 +- - examples/yubico_otp.c | 42 +++++++++++++++++++-------------- - lib/tests/test_parsing.c | 10 ++++---- - pkcs11/tests/aes_encrypt_test.c | 20 +++++++++------- - pkcs11/util_pkcs11.c | 10 ++++---- - 5 files changed, 46 insertions(+), 38 deletions(-) - -diff --git a/examples/encrypt_aes.c b/examples/encrypt_aes.c -index cc4a2db..b51f855 100644 ---- a/examples/encrypt_aes.c -+++ b/examples/encrypt_aes.c -@@ -25,7 +25,7 @@ - - const char *key_label = "label"; - const uint8_t password[] = "password"; --const uint8_t plaintext[16] = "single block msg"; -+const uint8_t plaintext[16] = "singleblock msg"; - - int main(void) { - yh_connector *connector = NULL; -diff --git a/examples/yubico_otp.c b/examples/yubico_otp.c -index 8860f9a..343a4b9 100644 ---- a/examples/yubico_otp.c -+++ b/examples/yubico_otp.c -@@ -44,24 +44,30 @@ static const struct { - uint16_t crc; - uint8_t otp[32]; - } test_vectors[] = -- {{"\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f", -- "\x01\x02\x03\x04\x05\x06", 0x0001, 0x0001, 0x01, 0x01, 0x0000, 0xfe36, -- "\x2f\x5d\x71\xa4\x91\x5d\xec\x30\x4a\xa1\x3c\xcf\x97\xbb\x0d\xbb"}, -- {"\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f", -- "\x01\x02\x03\x04\x05\x06", 0x0001, 0x0001, 0x01, 0x02, 0x0000, 0x1152, -- "\xcb\x71\x0b\x46\x2b\x7b\x1c\x23\x10\x0c\xb2\x46\x85\xb6\x4d\x33"}, -- {"\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f", -- "\x01\x02\x03\x04\x05\x06", 0x0fff, 0x0001, 0x01, 0x01, 0x0000, 0x9454, -- "\x77\x99\x78\x12\x9b\xcc\x26\x42\xc8\xad\xf5\xc1\x99\x81\xa0\x16"}, -- {"\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88\x88", -- "\x88\x88\x88\x88\x88\x88", 0x8888, 0x8888, 0x88, 0x88, 0x8888, 0xd3b6, -- "\x20\x76\x5f\xc6\x83\xe0\xfc\x7b\x62\x42\x21\x86\x48\x4d\x82\x37"}, -- {"\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00", -- "\x00\x00\x00\x00\x00\x00", 0x0000, 0x0000, 0x00, 0x00, 0x0000, 0xa96a, -- "\x99\x9b\x08\xbf\x0b\x3b\x98\xf8\x5b\x08\x76\xa8\x77\x15\x16\x16"}, -- {"\xc4\x42\x28\x90\x65\x30\x76\xcd\xe7\x3d\x44\x9b\x19\x1b\x41\x6a", -- "\x33\xc6\x9e\x7f\x24\x9e", 0x0001, 0x13a7, 0x24, 0x00, 0xc63c, 0x1c86, -- "\x7e\x0f\xc9\x87\x35\x16\x72\xc0\x70\xfa\x5c\x05\x95\xec\x68\xb8"}}; -+ {{{0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f}, -+ {0x01, 0x02, 0x03, 0x04, 0x05, 0x06}, -+ 0x0001, 0x0001, 0x01, 0x01, 0x0000, 0xfe36, -+ {0x2f, 0x5d, 0x71, 0xa4, 0x91, 0x5d, 0xec, 0x30, 0x4a, 0xa1, 0x3c, 0xcf, 0x97, 0xbb, 0x0d, 0xbb}}, -+ {{0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f}, -+ {0x01, 0x02, 0x03, 0x04, 0x05, 0x06}, -+ 0x0001, 0x0001, 0x01, 0x02, 0x0000, 0x1152, -+ {0xcb, 0x71, 0x0b, 0x46, 0x2b, 0x7b, 0x1c, 0x23, 0x10, 0x0c, 0xb2, 0x46, 0x85, 0xb6, 0x4d, 0x33}}, -+ {{0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f}, -+ {0x01, 0x02, 0x03, 0x04, 0x05, 0x06}, -+ 0x0fff, 0x0001, 0x01, 0x01, 0x0000, 0x9454, -+ {0x77, 0x99, 0x78, 0x12, 0x9b, 0xcc, 0x26, 0x42, 0xc8, 0xad, 0xf5, 0xc1, 0x99, 0x81, 0xa0, 0x16}}, -+ {{0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88, 0x88}, -+ {0x88, 0x88, 0x88, 0x88, 0x88, 0x88}, -+ 0x8888, 0x8888, 0x88, 0x88, 0x8888, 0xd3b6, -+ {0x20, 0x76, 0x5f, 0xc6, 0x83, 0xe0, 0xfc, 0x7b, 0x62, 0x42, 0x21, 0x86, 0x48, 0x4d, 0x82, 0x37}}, -+ {{0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00}, -+ {0x00, 0x00, 0x00, 0x00, 0x00, 0x00}, -+ 0x0000, 0x0000, 0x00, 0x00, 0x0000, 0xa96a, -+ {0x99, 0x9b, 0x08, 0xbf, 0x0b, 0x3b, 0x98, 0xf8, 0x5b, 0x08, 0x76, 0xa8, 0x77, 0x15, 0x16, 0x16}}, -+ {{0xc4, 0x42, 0x28, 0x90, 0x65, 0x30, 0x76, 0xcd, 0xe7, 0x3d, 0x44, 0x9b, 0x19, 0x1b, 0x41, 0x6a}, -+ {0x33, 0xc6, 0x9e, 0x7f, 0x24, 0x9e}, -+ 0x0001, 0x13a7, 0x24, 0x00, 0xc63c, 0x1c86, -+ {0x7e, 0x0f, 0xc9, 0x87, 0x35, 0x16, 0x72, 0xc0, 0x70, 0xfa, 0x5c, 0x05, 0x95, 0xec, 0x68, 0xb8}}}; - - static uint16_t yubikey_crc16(const uint8_t *buf, size_t buf_size) { - uint16_t m_crc = 0xffff; -diff --git a/lib/tests/test_parsing.c b/lib/tests/test_parsing.c -index 82c516a..1bd08e8 100644 ---- a/lib/tests/test_parsing.c -+++ b/lib/tests/test_parsing.c -@@ -67,12 +67,12 @@ static void test_capabilities1(void) { - const char *string; - yh_capabilities capabilities; - } tests[] = { -- {"get-opaque", {"\x00\x00\x00\x00\x00\x00\x00\x01"}}, -+ {"get-opaque", {{0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01}}}, - {"sign-hmac:verify-hmac|exportable-under-wrap,", -- {"\x00\x00\x00\x00\x00\xc1\x00\x00"}}, -- {",,unwrap-data|:wrap-data,,,", {"\x00\x00\x00\x60\x00\x00\x00\x00"}}, -- {"0x7fffffffffffffff", {"\x7f\xff\xff\xff\xff\xff\xff\xff"}}, -- {"0xffffffffffffffff", {"\xff\xff\xff\xff\xff\xff\xff\xff"}}, -+ {{0x00, 0x00, 0x00, 0x00, 0x00, 0xc1, 0x00, 0x00}}}, -+ {",,unwrap-data|:wrap-data,,,", {{0x00, 0x00, 0x00, 0x60, 0x00, 0x00, 0x00, 0x00}}}, -+ {"0x7fffffffffffffff", {{0x7f, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff}}}, -+ {"0xffffffffffffffff", {{0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff}}}, - }; - - for (size_t i = 0; i < sizeof(tests) / sizeof(tests[0]); i++) { -diff --git a/pkcs11/tests/aes_encrypt_test.c b/pkcs11/tests/aes_encrypt_test.c -index a5140f5..56acd3a 100644 ---- a/pkcs11/tests/aes_encrypt_test.c -+++ b/pkcs11/tests/aes_encrypt_test.c -@@ -34,11 +34,12 @@ - // the plaintext blocks. Each row corresponds to a whole block. - // clang-format off - #define PLAINTEXT_LENGTH (4 * 16) --static uint8_t plaintext[PLAINTEXT_LENGTH] = -- "\x6b\xc1\xbe\xe2\x2e\x40\x9f\x96\xe9\x3d\x7e\x11\x73\x93\x17\x2a" -- "\xae\x2d\x8a\x57\x1e\x03\xac\x9c\x9e\xb7\x6f\xac\x45\xaf\x8e\x51" -- "\x30\xc8\x1c\x46\xa3\x5c\xe4\x11\xe5\xfb\xc1\x19\x1a\x0a\x52\xef" -- "\xf6\x9f\x24\x45\xdf\x4f\x9b\x17\xad\x2b\x41\x7b\xe6\x6c\x37\x10"; -+static uint8_t plaintext[PLAINTEXT_LENGTH] = { -+ 0x6b, 0xc1, 0xbe, 0xe2, 0x2e, 0x40, 0x9f, 0x96, 0xe9, 0x3d, 0x7e, 0x11, 0x73, 0x93, 0x17, 0x2a, -+ 0xae, 0x2d, 0x8a, 0x57, 0x1e, 0x03, 0xac, 0x9c, 0x9e, 0xb7, 0x6f, 0xac, 0x45, 0xaf, 0x8e, 0x51, -+ 0x30, 0xc8, 0x1c, 0x46, 0xa3, 0x5c, 0xe4, 0x11, 0xe5, 0xfb, 0xc1, 0x19, 0x1a, 0x0a, 0x52, 0xef, -+ 0xf6, 0x9f, 0x24, 0x45, 0xdf, 0x4f, 0x9b, 0x17, 0xad, 0x2b, 0x41, 0x7b, 0xe6, 0x6c, 0x37, 0x10, -+}; - // clang-format on - - #define TEST_ECB(key, ptlen, ct) \ -@@ -50,15 +51,16 @@ static uint8_t plaintext[PLAINTEXT_LENGTH] = - - struct test { - CK_MECHANISM_TYPE mechanism; -- uint8_t key[32]; -+ uint8_t key[32 + 1]; - uint8_t keylen; - size_t plaintext_len; -- uint8_t ciphertext[sizeof(plaintext) + 16]; -+ uint8_t ciphertext[sizeof(plaintext) + 16 + 1]; - size_t ciphertext_len; - }; - --static uint8_t iv[16] = -- "\x00\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f"; -+static uint8_t iv[16] = { -+ 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, -+}; - - // CKM_AES_{ECB,CBC} test vectors from NIST. - // CKM_AES_CBC_PAD calculated out-of-band. -diff --git a/pkcs11/util_pkcs11.c b/pkcs11/util_pkcs11.c -index 8d38c58..3bbad6b 100644 ---- a/pkcs11/util_pkcs11.c -+++ b/pkcs11/util_pkcs11.c -@@ -709,7 +709,7 @@ CK_RV get_mechanism_info(yubihsm_pkcs11_slot *slot, CK_MECHANISM_TYPE type, - #define PKCS11_LABEL_TAG 2 - #define PKCS11_PUBKEY_ID_TAG 3 - #define PKCS11_PUBKEY_LABEL_TAG 4 --const char META_OBJECT_VERSION[4] = "MDB1"; -+const char META_OBJECT_VERSION[5] = "MDB1"; - - static uint16_t write_meta_item(uint8_t *target_value, uint8_t tag, - cka_meta_item *meta_item) { -@@ -763,11 +763,11 @@ static CK_RV read_meta_object(yubihsm_pkcs11_slot *slot, uint16_t opaque_id, - } - - uint8_t *p = opaque_value; -- if (memcmp(p, META_OBJECT_VERSION, sizeof(META_OBJECT_VERSION)) != 0) { -+ if (memcmp(p, META_OBJECT_VERSION, strlen(META_OBJECT_VERSION)) != 0) { - DBG_ERR("Meta object value has unexpected version"); - return CKR_DATA_INVALID; - } -- p += sizeof(META_OBJECT_VERSION); -+ p += strlen(META_OBJECT_VERSION); - - meta_object->target_type = *p++; - -@@ -931,8 +931,8 @@ CK_RV write_meta_object(yubihsm_pkcs11_slot *slot, - uint8_t opaque_value[YH_MSG_BUF_SIZE] = {0}; - uint8_t *p = opaque_value; - -- memcpy(p, META_OBJECT_VERSION, sizeof(META_OBJECT_VERSION)); -- p += sizeof(META_OBJECT_VERSION); -+ memcpy(p, META_OBJECT_VERSION, strlen(META_OBJECT_VERSION)); -+ p += strlen(META_OBJECT_VERSION); - - *p++ = meta_object->target_type; - --- -2.48.1 - diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index b0dcd98..c0ff07d 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -1,8 +1,8 @@ %undefine __cmake_in_source_build Name: yubihsm-shell -Version: 2.6.0 -Release: 3%{?dist} +Version: 2.7.0 +Release: 1%{?dist} Summary: Tools to interact with YubiHSM 2 # Automatically converted from old format: ASL 2.0 - review is highly recommended. @@ -11,12 +11,8 @@ URL: https://github.com/Yubico/%{name}/ Source0: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.gz Source1: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.gz.sig Source2: gpgkey-9588EA0F.gpg -# https://github.com/Yubico/yubihsm-shell/pull/430 -Patch1: yubihsm-shell-2.6.0-incompatible-pointer.patch # https://github.com/Yubico/yubihsm-shell/pull/411 Patch2: yubihsm-shell-2.5.0-pcsc-lite.patch -# https://github.com/Yubico/yubihsm-shell/pull/450 -Patch3: yubihsm-shell-gcc15.patch BuildRequires: cmake BuildRequires: cppcheck @@ -118,6 +114,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Tue Jun 17 2025 Jakub Jelen - 2.7.0-1 +- New upstream release (#2372452) + * Wed Feb 05 2025 Jakub Jelen - 2.6.0-3 - Fix gcc15 warnings (#2341598) From d18ff3e8104373f13d46c57cd2fe3bed18b3f3b1 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Mon, 21 Jul 2025 11:24:57 +0200 Subject: [PATCH 18/31] Remove unused patches --- yubihsm-shell.spec | 2 -- 1 file changed, 2 deletions(-) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index c0ff07d..8d62502 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -50,9 +50,7 @@ Development libraries for working with yubihsm 2. %prep gpgv2 --quiet --keyring %{SOURCE2} %{SOURCE1} %{SOURCE0} %setup -q -%patch 1 -p1 %patch 2 -p1 -%patch 3 -p1 %build From 6767a644735a4814af0506d06a2846bde937d9a7 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Mon, 21 Jul 2025 11:38:41 +0200 Subject: [PATCH 19/31] Workaround for dropping install vars from the rpm macros https://fedoraproject.org/wiki/Changes/CMake_drop_install_vars --- yubihsm-shell.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 8d62502..bb9d090 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -63,7 +63,10 @@ export CFLAGS="$CFLAGS -Wno-error=format-overflow" %endif # OpenSSL 3.0 deprecates a lot of functions still widely used here export CFLAGS="$CFLAGS -Wno-error=deprecated-declarations" -%cmake -DCMAKE_SKIP_INSTALL_RPATH=ON +%cmake -DCMAKE_SKIP_INSTALL_RPATH=ON \ + %if "%{?_lib}" == "lib64" + %{?_cmake_lib_suffix64} + %endif %cmake_build From d5c5d15373eaf379942042b645a0d4f6e6f05457 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Mon, 21 Jul 2025 22:23:56 +0200 Subject: [PATCH 20/31] fix cmake on non-64b architecture --- yubihsm-shell.spec | 1 + 1 file changed, 1 insertion(+) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index bb9d090..5be7015 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -67,6 +67,7 @@ export CFLAGS="$CFLAGS -Wno-error=deprecated-declarations" %if "%{?_lib}" == "lib64" %{?_cmake_lib_suffix64} %endif + %{nil} %cmake_build From 4944da931d95d5dd25dd35876a6f35c73235d206 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 25 Jul 2025 21:14:12 +0000 Subject: [PATCH 21/31] Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild --- yubihsm-shell.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 5be7015..f71975d 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -2,7 +2,7 @@ Name: yubihsm-shell Version: 2.7.0 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Tools to interact with YubiHSM 2 # Automatically converted from old format: ASL 2.0 - review is highly recommended. @@ -116,6 +116,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Fri Jul 25 2025 Fedora Release Engineering - 2.7.0-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + * Tue Jun 17 2025 Jakub Jelen - 2.7.0-1 - New upstream release (#2372452) From 14c68d0e67f708a6eea7238cb986068ce21ca37a Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Mon, 3 Nov 2025 09:49:53 +0100 Subject: [PATCH 22/31] Remove needless condition for old Fedora --- yubihsm-shell.spec | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index f71975d..9bf2362 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -28,11 +28,7 @@ BuildRequires: libedit-devel BuildRequires: pcsc-lite-devel BuildRequires: clang BuildRequires: pkg-config -%if 0%{?fedora} > 36 -BuildRequires: libusb-compat-0.1-devel -%else -BuildRequires: libusb-devel -%endif +BuildRequires: libusb-compat-0.1-devel BuildRequires: chrpath BuildRequires: gnupg2 From 8dda199d8f6a5976090f6db730cfbadcbe58c4a9 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 17 Jan 2026 21:04:04 +0000 Subject: [PATCH 23/31] Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild --- yubihsm-shell.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 9bf2362..bfed5f4 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -2,7 +2,7 @@ Name: yubihsm-shell Version: 2.7.0 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Tools to interact with YubiHSM 2 # Automatically converted from old format: ASL 2.0 - review is highly recommended. @@ -112,6 +112,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Sat Jan 17 2026 Fedora Release Engineering - 2.7.0-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild + * Fri Jul 25 2025 Fedora Release Engineering - 2.7.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild From 89b293d1645a9db04ff31cf951624dcddaef3cce Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Tue, 20 Jan 2026 19:31:08 +0100 Subject: [PATCH 24/31] 2.7.1-1 --- .gitignore | 2 ++ sources | 4 ++-- yubihsm-shell.spec | 7 +++++-- 3 files changed, 9 insertions(+), 4 deletions(-) diff --git a/.gitignore b/.gitignore index d3e8947..a76c23c 100644 --- a/.gitignore +++ b/.gitignore @@ -33,3 +33,5 @@ /yubihsm-shell-2.6.0.tar.gz.sig /yubihsm-shell-2.7.0.tar.gz /yubihsm-shell-2.7.0.tar.gz.sig +/yubihsm-shell-2.7.1.tar.gz +/yubihsm-shell-2.7.1.tar.gz.sig diff --git a/sources b/sources index 412fc9e..c05c0f4 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (yubihsm-shell-2.7.0.tar.gz) = 63c5062ba3d588cf922a4135b9106b40b7a299edffc0ab1ad18cdbb7489d9542510e58acc400c1449e785511426c40f8266e374f3d6d92315cdf302ebcd58201 -SHA512 (yubihsm-shell-2.7.0.tar.gz.sig) = 13fc99dbfc016f458a0394dec126bfba28538cd5f29e86ca3991783fcbe717e39cbdfc03eb955e96bd1bf354fbd99ff07da06b00e118eff5de3f55dc99f0cc08 +SHA512 (yubihsm-shell-2.7.1.tar.gz) = 5fac5aa2854b376c4f7c12c519c36e05b53bad01ba0e623c60bffe59cd52000363899ffcc9d194aaa1f7e93183fe3739a0ade8ae269ad93327a923cdf6d34459 +SHA512 (yubihsm-shell-2.7.1.tar.gz.sig) = f9551b80466ce8b1fdf3bd489cafefa1e8820d8d0a08d1257e45b6400887972d057c07630fce4cc52371427b97fd2e4cb98ce4ec700201b1732fac88a4060187 SHA512 (gpgkey-9588EA0F.gpg) = ff3fb773cf95c8d28fb9630c8525539c7ba497a046292a9eda816dd77c4a8b199b74467c7639bbbb0236e439b4db4d0a8b1694a40b33e074072d3ecac46acd87 diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index bfed5f4..4c9dc22 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -1,8 +1,8 @@ %undefine __cmake_in_source_build Name: yubihsm-shell -Version: 2.7.0 -Release: 3%{?dist} +Version: 2.7.1 +Release: 1%{?dist} Summary: Tools to interact with YubiHSM 2 # Automatically converted from old format: ASL 2.0 - review is highly recommended. @@ -112,6 +112,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Tue Jan 20 2026 Jakub Jelen - 2.7.1-1 +- New upstream release (#2431274) + * Sat Jan 17 2026 Fedora Release Engineering - 2.7.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild From a1dc894b3cb4dd34f4a7483870c8505b7ad72be8 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Fri, 13 Mar 2026 11:41:23 +0100 Subject: [PATCH 25/31] 2.7.2-1 --- .gitignore | 2 ++ sources | 4 ++-- yubihsm-shell-2.5.0-pcsc-lite.patch | 4 ++-- yubihsm-shell.spec | 5 ++++- 4 files changed, 10 insertions(+), 5 deletions(-) diff --git a/.gitignore b/.gitignore index a76c23c..f5a7fc4 100644 --- a/.gitignore +++ b/.gitignore @@ -35,3 +35,5 @@ /yubihsm-shell-2.7.0.tar.gz.sig /yubihsm-shell-2.7.1.tar.gz /yubihsm-shell-2.7.1.tar.gz.sig +/yubihsm-shell-2.7.2.tar.gz +/yubihsm-shell-2.7.2.tar.gz.sig diff --git a/sources b/sources index c05c0f4..06d4295 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (yubihsm-shell-2.7.1.tar.gz) = 5fac5aa2854b376c4f7c12c519c36e05b53bad01ba0e623c60bffe59cd52000363899ffcc9d194aaa1f7e93183fe3739a0ade8ae269ad93327a923cdf6d34459 -SHA512 (yubihsm-shell-2.7.1.tar.gz.sig) = f9551b80466ce8b1fdf3bd489cafefa1e8820d8d0a08d1257e45b6400887972d057c07630fce4cc52371427b97fd2e4cb98ce4ec700201b1732fac88a4060187 +SHA512 (yubihsm-shell-2.7.2.tar.gz) = 58e91246e4a46c9333d1cefa182f4d4aa742e14ba5a5de8b9fa00b09c24e7c970f65d738096e0265d9f92ef472a5c53d19199519458bc6fde9fa62d83a72eb6b +SHA512 (yubihsm-shell-2.7.2.tar.gz.sig) = a70f8fbb28ab6ff0c9263dff304905bc28b6b7edd1e51a7c5d55f2c6e92035f856b1872a68ea2e11acf8490bdc202ad4f481160d68510646e396fac13da46748 SHA512 (gpgkey-9588EA0F.gpg) = ff3fb773cf95c8d28fb9630c8525539c7ba497a046292a9eda816dd77c4a8b199b74467c7639bbbb0236e439b4db4d0a8b1694a40b33e074072d3ecac46acd87 diff --git a/yubihsm-shell-2.5.0-pcsc-lite.patch b/yubihsm-shell-2.5.0-pcsc-lite.patch index c79ffb9..60331c9 100644 --- a/yubihsm-shell-2.5.0-pcsc-lite.patch +++ b/yubihsm-shell-2.5.0-pcsc-lite.patch @@ -25,8 +25,8 @@ index acbb392..ecf3df8 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -194,6 +194,8 @@ if(NOT BUILD_ONLY_LIB) - - if(${CMAKE_SYSTEM_NAME} MATCHES "Linux") + set(LIBPCSC_REQ "Linux" "FreeBSD") + if(${CMAKE_SYSTEM_NAME} IN_LIST LIBPCSC_REQ) pkg_search_module (LIBPCSC REQUIRED libpcsclite) + string (REPLACE ";" " " MY_LIBPCSC_CFLAGS "${LIBPCSC_CFLAGS}") + string (APPEND CMAKE_C_FLAGS " ${MY_LIBPCSC_CFLAGS}") diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 4c9dc22..0d3bfba 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -1,7 +1,7 @@ %undefine __cmake_in_source_build Name: yubihsm-shell -Version: 2.7.1 +Version: 2.7.2 Release: 1%{?dist} Summary: Tools to interact with YubiHSM 2 @@ -112,6 +112,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Fri Mar 13 2026 Jakub Jelen - 2.7.2-1 +- New upstream release (#2447224) + * Tue Jan 20 2026 Jakub Jelen - 2.7.1-1 - New upstream release (#2431274) From f2947b8fb09a1390e8966c24c7d52c2c972eae53 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Thu, 16 Apr 2026 15:51:08 +0200 Subject: [PATCH 26/31] 2.7.3-1 --- .gitignore | 2 ++ sources | 4 ++-- yubihsm-shell.spec | 5 ++++- 3 files changed, 8 insertions(+), 3 deletions(-) diff --git a/.gitignore b/.gitignore index f5a7fc4..990ba5c 100644 --- a/.gitignore +++ b/.gitignore @@ -37,3 +37,5 @@ /yubihsm-shell-2.7.1.tar.gz.sig /yubihsm-shell-2.7.2.tar.gz /yubihsm-shell-2.7.2.tar.gz.sig +/yubihsm-shell-2.7.3.tar.gz +/yubihsm-shell-2.7.3.tar.gz.sig diff --git a/sources b/sources index 06d4295..99ee5d5 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (yubihsm-shell-2.7.2.tar.gz) = 58e91246e4a46c9333d1cefa182f4d4aa742e14ba5a5de8b9fa00b09c24e7c970f65d738096e0265d9f92ef472a5c53d19199519458bc6fde9fa62d83a72eb6b -SHA512 (yubihsm-shell-2.7.2.tar.gz.sig) = a70f8fbb28ab6ff0c9263dff304905bc28b6b7edd1e51a7c5d55f2c6e92035f856b1872a68ea2e11acf8490bdc202ad4f481160d68510646e396fac13da46748 +SHA512 (yubihsm-shell-2.7.3.tar.gz) = ac8715369ddc7c559fba398b974bd3c4cf1456d260959a818936f072d650abb7a72a14af11fbce1da5743420951616283699830604c46468587cdfdf5a2db4b9 +SHA512 (yubihsm-shell-2.7.3.tar.gz.sig) = 3ccfd1772e5335c22dbfdc4d2d1c8fab692a789aac02ee93426b78e26f1c34e01b3d996d8c2debd99925069cc47d725a05e4674ac2a208b70ebcc86634a4e2d6 SHA512 (gpgkey-9588EA0F.gpg) = ff3fb773cf95c8d28fb9630c8525539c7ba497a046292a9eda816dd77c4a8b199b74467c7639bbbb0236e439b4db4d0a8b1694a40b33e074072d3ecac46acd87 diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 0d3bfba..93f2962 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -1,7 +1,7 @@ %undefine __cmake_in_source_build Name: yubihsm-shell -Version: 2.7.2 +Version: 2.7.3 Release: 1%{?dist} Summary: Tools to interact with YubiHSM 2 @@ -112,6 +112,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Thu Apr 16 2026 Jakub Jelen - 2.7.3-1 +- New upstream release (#2458149) + * Fri Mar 13 2026 Jakub Jelen - 2.7.2-1 - New upstream release (#2447224) From d9a08700ec5ba9bfeb8118b0b6e1b5a0791f3388 Mon Sep 17 00:00:00 2001 From: Simo Sorce Date: Tue, 28 Apr 2026 16:42:18 -0400 Subject: [PATCH 27/31] OpenSSL 4.0 build fixes Signed-off-by: Simo Sorce --- ...d-const-qualifiers-in-attest-example.patch | 33 +++++++++++++++++++ yubihsm-shell.spec | 8 ++++- 2 files changed, 40 insertions(+), 1 deletion(-) create mode 100644 0001-Add-const-qualifiers-in-attest-example.patch diff --git a/0001-Add-const-qualifiers-in-attest-example.patch b/0001-Add-const-qualifiers-in-attest-example.patch new file mode 100644 index 0000000..4f0255b --- /dev/null +++ b/0001-Add-const-qualifiers-in-attest-example.patch @@ -0,0 +1,33 @@ +From 99f25b323f26938974e54329983dbd925f7b0064 Mon Sep 17 00:00:00 2001 +From: Simo Sorce +Date: Tue, 28 Apr 2026 16:40:08 -0400 +Subject: [PATCH] Add const qualifiers in attest example + +Update the a_object and a_value pointers in the attest example to be const. +This ensures compatibility with modern OpenSSL APIs where these getter +functions return const pointers, resolving potential compiler warnings about +discarded qualifiers. + +Signed-off-by: Simo Sorce +--- + examples/attest.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/examples/attest.c b/examples/attest.c +index 4481720..5f2bdbf 100644 +--- a/examples/attest.c ++++ b/examples/attest.c +@@ -53,8 +53,8 @@ static void print_extension(X509_EXTENSION *extension) { + const uint8_t label[] = {0x06, 0x0a, 0x2b, 0x06, 0x01, 0x04, + 0x01, 0x82, 0xc4, 0x0a, 0x04, 0x09}; + +- ASN1_OBJECT *a_object = X509_EXTENSION_get_object(extension); +- ASN1_OCTET_STRING *a_value = X509_EXTENSION_get_data(extension); ++ const ASN1_OBJECT *a_object = X509_EXTENSION_get_object(extension); ++ const ASN1_OCTET_STRING *a_value = X509_EXTENSION_get_data(extension); + uint8_t object[1024]; + uint8_t *ptr = object; + if (i2d_ASN1_OBJECT(a_object, NULL) > 1024) { +-- +2.53.0 + diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 93f2962..c324f1f 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -2,7 +2,7 @@ Name: yubihsm-shell Version: 2.7.3 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Tools to interact with YubiHSM 2 # Automatically converted from old format: ASL 2.0 - review is highly recommended. @@ -13,6 +13,8 @@ Source1: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.g Source2: gpgkey-9588EA0F.gpg # https://github.com/Yubico/yubihsm-shell/pull/411 Patch2: yubihsm-shell-2.5.0-pcsc-lite.patch +# OpenSSL 4.0 build fixes +Patch3: 0001-Add-const-qualifiers-in-attest-example.patch BuildRequires: cmake BuildRequires: cppcheck @@ -47,6 +49,7 @@ Development libraries for working with yubihsm 2. gpgv2 --quiet --keyring %{SOURCE2} %{SOURCE1} %{SOURCE0} %setup -q %patch 2 -p1 +%patch 3 -p1 %build @@ -112,6 +115,9 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %changelog +* Tue Apr 28 2026 Simo Sorce - 2.7.3-2 +- OpenSSL 4.0 build fixes + * Thu Apr 16 2026 Jakub Jelen - 2.7.3-1 - New upstream release (#2458149) From 65b317ac32c310b4415f548c5ee3e7eb1265b3e0 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Wed, 29 Apr 2026 20:38:45 +0200 Subject: [PATCH 28/31] use %auto* macros to simplify maintenance --- changelog | 93 +++++++++++++++++++++++++++ yubihsm-shell.spec | 153 +-------------------------------------------- 2 files changed, 96 insertions(+), 150 deletions(-) create mode 100644 changelog diff --git a/changelog b/changelog new file mode 100644 index 0000000..c73f13e --- /dev/null +++ b/changelog @@ -0,0 +1,93 @@ +* Tue Apr 28 2026 Simo Sorce - 2.7.3-2 +- OpenSSL 4.0 build fixes + +* Thu Apr 16 2026 Jakub Jelen - 2.7.3-1 +- New upstream release (#2458149) + +* Fri Mar 13 2026 Jakub Jelen - 2.7.2-1 +- New upstream release (#2447224) + +* Tue Jan 20 2026 Jakub Jelen - 2.7.1-1 +- New upstream release (#2431274) + +* Tue Jun 17 2025 Jakub Jelen - 2.7.0-1 +- New upstream release (#2372452) + +* Wed Feb 05 2025 Jakub Jelen - 2.6.0-3 +- Fix gcc15 warnings (#2341598) + +* Wed Sep 11 2024 Jakub Jelen - 2.6.0-1 +- New upstream release (#2311424) + +* Tue Jul 30 2024 Jakub Jelen - 2.5.0-4 +- Fix build against pcsc-lite >= 2.2 (#2301379) + +* Wed Jul 24 2024 Miroslav Suchý - 2.5.0-3 +- convert license to SPDX + +* Tue Apr 02 2024 Jakub Jelen - 2.5.0-1 +- New upstream release (#2272123) + +* Wed Nov 08 2023 Jakub Jelen - 2.4.2-1 +- New upstream release (#2248609) + +* Thu Aug 17 2023 Jakub Jelen - 2.4.1-1 +- New upstream release (#2232340) + +* Mon Jan 30 2023 Jakub Jelen - 2.4.0-1 +- New upstream release (#2165239) + +* Mon Jun 27 2022 Jakub Jelen - 2.3.2-1 +- New upstream release (#2100542) + +* Tue Feb 22 2022 Veronika Hanulikova - 2.3.1-1 +- New upstream release (#2050104) + +* Mon Jan 03 2022 Jakub Jelen - 2.3.0b-1 +- New upstream release (#2035159) + +* Mon Dec 13 2021 Jakub Jelen - 2.3.0-1 +- New upstream release (#2030694) + +* Thu Nov 18 2021 Jakub Jelen - 2.2.0-5 +- Rebuild with deprecated OpenSSL 3.0 functions (#2021878) + +* Tue Sep 14 2021 Sahana Prasad - 2.2.0-4 +- Rebuilt with OpenSSL 3.0.0 + +* Tue Aug 03 2021 Jakub Jelen - 2.2.0-3 +- Disable rpath to allow build in Fedora 35 (#1988058) + +* Fri Apr 16 2021 Jakub Jelen - 2.2.0-1 +- New upstream release (#1950207) + +* Thu Mar 18 2021 Jakub Jelen - 2.1.0-1 +- New upstream release (#1936041) + +* Wed Oct 21 2020 Jakub Jelen - 2.0.3-1 +- New upstream release (#1889941) + +* Thu Aug 06 2020 Jakub Jelen - 2.0.2-7 +- Workaround FTBFS on s390x (#1865658) + +* Thu Aug 06 2020 Jakub Jelen - 2.0.2-6 +- Rebuild after libz3 soname bump (#1865658) + +* Mon Mar 16 2020 Jakub Jelen - 2.0.2-3 +- Avoid warnings/errors with new gcc on s390x (#1800289) + +* Tue Jan 07 2020 Jakub Jelen - 2.0.2-1 +- New upstream release (#1772013) + +* Tue Apr 02 2019 Jakub Jelen - 2.0.1-1 +- New upstream release (#1692935) + +* Wed Feb 13 2019 Jakub Jelen - 2.0.0-4 +- Workaround unreasonagle error from GCC9 (#1676257) + +* Mon Dec 03 2018 Jakub Jelen - 2.0.0-2 +- Pull the latest signed tarballs +- Address review comments (#1654689) + +* Thu Nov 29 2018 Jakub Jelen - 2.0.0-1 +- Initial release diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index c324f1f..9f0f333 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -2,7 +2,7 @@ Name: yubihsm-shell Version: 2.7.3 -Release: 2%{?dist} +Release: %autorelease Summary: Tools to interact with YubiHSM 2 # Automatically converted from old format: ASL 2.0 - review is highly recommended. @@ -47,9 +47,7 @@ Development libraries for working with yubihsm 2. %prep gpgv2 --quiet --keyring %{SOURCE2} %{SOURCE1} %{SOURCE0} -%setup -q -%patch 2 -p1 -%patch 3 -p1 +%autosetup -p1 %build @@ -112,150 +110,5 @@ chrpath --delete $RPM_BUILD_ROOT%{_libdir}/pkcs11/yubihsm_pkcs11.so %{_datadir}/pkgconfig/yubihsm.pc %{_datadir}/pkgconfig/ykhsmauth.pc - - %changelog -* Tue Apr 28 2026 Simo Sorce - 2.7.3-2 -- OpenSSL 4.0 build fixes - -* Thu Apr 16 2026 Jakub Jelen - 2.7.3-1 -- New upstream release (#2458149) - -* Fri Mar 13 2026 Jakub Jelen - 2.7.2-1 -- New upstream release (#2447224) - -* Tue Jan 20 2026 Jakub Jelen - 2.7.1-1 -- New upstream release (#2431274) - -* Sat Jan 17 2026 Fedora Release Engineering - 2.7.0-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild - -* Fri Jul 25 2025 Fedora Release Engineering - 2.7.0-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild - -* Tue Jun 17 2025 Jakub Jelen - 2.7.0-1 -- New upstream release (#2372452) - -* Wed Feb 05 2025 Jakub Jelen - 2.6.0-3 -- Fix gcc15 warnings (#2341598) - -* Sun Jan 19 2025 Fedora Release Engineering - 2.6.0-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild - -* Wed Sep 11 2024 Jakub Jelen - 2.6.0-1 -- New upstream release (#2311424) - -* Tue Jul 30 2024 Jakub Jelen - 2.5.0-4 -- Fix build against pcsc-lite >= 2.2 (#2301379) - -* Wed Jul 24 2024 Miroslav Suchý - 2.5.0-3 -- convert license to SPDX - -* Sat Jul 20 2024 Fedora Release Engineering - 2.5.0-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild - -* Tue Apr 02 2024 Jakub Jelen - 2.5.0-1 -- New upstream release (#2272123) - -* Sat Jan 27 2024 Fedora Release Engineering - 2.4.2-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Wed Nov 08 2023 Jakub Jelen - 2.4.2-1 -- New upstream release (#2248609) - -* Thu Aug 17 2023 Jakub Jelen - 2.4.1-1 -- New upstream release (#2232340) - -* Sat Jul 22 2023 Fedora Release Engineering - 2.4.0-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild - -* Mon Jan 30 2023 Jakub Jelen - 2.4.0-1 -- New upstream release (#2165239) - -* Sat Jan 21 2023 Fedora Release Engineering - 2.3.2-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild - -* Sat Jul 23 2022 Fedora Release Engineering - 2.3.2-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild - -* Mon Jun 27 2022 Jakub Jelen - 2.3.2-1 -- New upstream release (#2100542) - -* Tue Feb 22 2022 Veronika Hanulikova - 2.3.1-1 -- New upstream release (#2050104) - -* Sat Jan 22 2022 Fedora Release Engineering - 2.3.0b-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild - -* Mon Jan 03 2022 Jakub Jelen - 2.3.0b-1 -- New upstream release (#2035159) - -* Mon Dec 13 2021 Jakub Jelen - 2.3.0-1 -- New upstream release (#2030694) - -* Thu Nov 18 2021 Jakub Jelen - 2.2.0-5 -- Rebuild with deprecated OpenSSL 3.0 functions (#2021878) - -* Tue Sep 14 2021 Sahana Prasad - 2.2.0-4 -- Rebuilt with OpenSSL 3.0.0 - -* Tue Aug 03 2021 Jakub Jelen - 2.2.0-3 -- Disable rpath to allow build in Fedora 35 (#1988058) - -* Fri Jul 23 2021 Fedora Release Engineering - 2.2.0-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild - -* Fri Apr 16 2021 Jakub Jelen - 2.2.0-1 -- New upstream release (#1950207) - -* Thu Mar 18 2021 Jakub Jelen - 2.1.0-1 -- New upstream release (#1936041) - -* Thu Jan 28 2021 Fedora Release Engineering - 2.0.3-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild - -* Wed Oct 21 2020 Jakub Jelen - 2.0.3-1 -- New upstream release (#1889941) - -* Thu Aug 06 2020 Jakub Jelen - 2.0.2-7 -- Workaround FTBFS on s390x (#1865658) - -* Thu Aug 06 2020 Jakub Jelen - 2.0.2-6 -- Rebuild after libz3 soname bump (#1865658) - -* Sat Aug 01 2020 Fedora Release Engineering - 2.0.2-5 -- Second attempt - Rebuilt for - https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild - -* Wed Jul 29 2020 Fedora Release Engineering - 2.0.2-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild - -* Mon Mar 16 2020 Jakub Jelen - 2.0.2-3 -- Avoid warnings/errors with new gcc on s390x (#1800289) - -* Fri Jan 31 2020 Fedora Release Engineering - 2.0.2-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild - -* Tue Jan 07 2020 Jakub Jelen - 2.0.2-1 -- New upstream release (#1772013) - -* Sat Jul 27 2019 Fedora Release Engineering - 2.0.1-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild - -* Tue Apr 02 2019 Jakub Jelen - 2.0.1-1 -- New upstream release (#1692935) - -* Wed Feb 13 2019 Jakub Jelen - 2.0.0-4 -- Workaround unreasonagle error from GCC9 (#1676257) - -* Sun Feb 03 2019 Fedora Release Engineering - 2.0.0-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild - -* Mon Dec 03 2018 Jakub Jelen - 2.0.0-2 -- Pull the latest signed tarballs -- Address review comments (#1654689) - -* Thu Nov 29 2018 Jakub Jelen - 2.0.0-1 -- Initial release - - +%autochangelog From 8bfdd748fd35c446316aecb167e1663ab3963534 Mon Sep 17 00:00:00 2001 From: Yaakov Selkowitz Date: Fri, 12 Jun 2026 16:41:56 -0400 Subject: [PATCH 29/31] Rebuilt for openssl 4.0 From 52b2d075c5be83b65757923630efa154ddc63234 Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Tue, 7 Jul 2026 11:52:38 +0200 Subject: [PATCH 30/31] New upstream release 2.8.0 --- .gitignore | 2 ++ ...d-const-qualifiers-in-attest-example.patch | 33 ------------------- sources | 4 +-- yubihsm-shell.spec | 4 +-- 4 files changed, 5 insertions(+), 38 deletions(-) delete mode 100644 0001-Add-const-qualifiers-in-attest-example.patch diff --git a/.gitignore b/.gitignore index 990ba5c..ca2d831 100644 --- a/.gitignore +++ b/.gitignore @@ -39,3 +39,5 @@ /yubihsm-shell-2.7.2.tar.gz.sig /yubihsm-shell-2.7.3.tar.gz /yubihsm-shell-2.7.3.tar.gz.sig +/yubihsm-shell-2.8.0.tar.gz +/yubihsm-shell-2.8.0.tar.gz.sig diff --git a/0001-Add-const-qualifiers-in-attest-example.patch b/0001-Add-const-qualifiers-in-attest-example.patch deleted file mode 100644 index 4f0255b..0000000 --- a/0001-Add-const-qualifiers-in-attest-example.patch +++ /dev/null @@ -1,33 +0,0 @@ -From 99f25b323f26938974e54329983dbd925f7b0064 Mon Sep 17 00:00:00 2001 -From: Simo Sorce -Date: Tue, 28 Apr 2026 16:40:08 -0400 -Subject: [PATCH] Add const qualifiers in attest example - -Update the a_object and a_value pointers in the attest example to be const. -This ensures compatibility with modern OpenSSL APIs where these getter -functions return const pointers, resolving potential compiler warnings about -discarded qualifiers. - -Signed-off-by: Simo Sorce ---- - examples/attest.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/examples/attest.c b/examples/attest.c -index 4481720..5f2bdbf 100644 ---- a/examples/attest.c -+++ b/examples/attest.c -@@ -53,8 +53,8 @@ static void print_extension(X509_EXTENSION *extension) { - const uint8_t label[] = {0x06, 0x0a, 0x2b, 0x06, 0x01, 0x04, - 0x01, 0x82, 0xc4, 0x0a, 0x04, 0x09}; - -- ASN1_OBJECT *a_object = X509_EXTENSION_get_object(extension); -- ASN1_OCTET_STRING *a_value = X509_EXTENSION_get_data(extension); -+ const ASN1_OBJECT *a_object = X509_EXTENSION_get_object(extension); -+ const ASN1_OCTET_STRING *a_value = X509_EXTENSION_get_data(extension); - uint8_t object[1024]; - uint8_t *ptr = object; - if (i2d_ASN1_OBJECT(a_object, NULL) > 1024) { --- -2.53.0 - diff --git a/sources b/sources index 99ee5d5..b91dc37 100644 --- a/sources +++ b/sources @@ -1,3 +1,3 @@ -SHA512 (yubihsm-shell-2.7.3.tar.gz) = ac8715369ddc7c559fba398b974bd3c4cf1456d260959a818936f072d650abb7a72a14af11fbce1da5743420951616283699830604c46468587cdfdf5a2db4b9 -SHA512 (yubihsm-shell-2.7.3.tar.gz.sig) = 3ccfd1772e5335c22dbfdc4d2d1c8fab692a789aac02ee93426b78e26f1c34e01b3d996d8c2debd99925069cc47d725a05e4674ac2a208b70ebcc86634a4e2d6 +SHA512 (yubihsm-shell-2.8.0.tar.gz) = 9d3153444b3ae71fee344ed81f7b7229d62c5d9b40ebd31e38026c69d36f5a6f92ef411d029861cf2cd33fc1a8689c1ec3576cc076f91e81312795b344da8a58 +SHA512 (yubihsm-shell-2.8.0.tar.gz.sig) = 77ee4399c7e05d1daed4fd1164f8bacde8e69d69e4bbb6f35fc58a15e212f9455207c529b4f144814ee972e6dd8eb7f3804e7ad15a9d4a853ea187876f5a2630 SHA512 (gpgkey-9588EA0F.gpg) = ff3fb773cf95c8d28fb9630c8525539c7ba497a046292a9eda816dd77c4a8b199b74467c7639bbbb0236e439b4db4d0a8b1694a40b33e074072d3ecac46acd87 diff --git a/yubihsm-shell.spec b/yubihsm-shell.spec index 9f0f333..703be4a 100644 --- a/yubihsm-shell.spec +++ b/yubihsm-shell.spec @@ -1,7 +1,7 @@ %undefine __cmake_in_source_build Name: yubihsm-shell -Version: 2.7.3 +Version: 2.8.0 Release: %autorelease Summary: Tools to interact with YubiHSM 2 @@ -13,8 +13,6 @@ Source1: https://developers.yubico.com/%{name}/Releases/%{name}-%{version}.tar.g Source2: gpgkey-9588EA0F.gpg # https://github.com/Yubico/yubihsm-shell/pull/411 Patch2: yubihsm-shell-2.5.0-pcsc-lite.patch -# OpenSSL 4.0 build fixes -Patch3: 0001-Add-const-qualifiers-in-attest-example.patch BuildRequires: cmake BuildRequires: cppcheck From 0ff2e08964350d77d44e05bd31b0d6ed86695fba Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 17 Jul 2026 09:36:36 +0000 Subject: [PATCH 31/31] Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild