Received: by 2002:a05:6a10:413:0:0:0:0 with SMTP id 19csp1953949pxp; Thu, 10 Mar 2022 15:58:22 -0800 (PST) X-Google-Smtp-Source: ABdhPJwUu2UPQGrbclJVWGnegwembfXOAq5qnfQI0lhYLqqVaXVLW8ZoSpSYLFyMVpLfVNEPPRfZ X-Received: by 2002:a17:902:7296:b0:14f:2a67:b400 with SMTP id d22-20020a170902729600b0014f2a67b400mr7533763pll.172.1646956702016; Thu, 10 Mar 2022 15:58:22 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1646956702; cv=none; d=google.com; s=arc-20160816; b=0g6jKzmspKoIVp+zYnxawHXOwmjSccZniymY25Wb7BA8NSupq5RTAdfsyAHxXh7tPX NanijCL773Ig/1bAbe4C6WeHAId7MooB56MZyI+9qc9PRPCwD3Jq1aErI/1xsIfv5oWD 1mRJR523CsA/FGL7m1zPNn9AR43sGsD4EzoBWY97e7S1mNG7d5V6l30/Qpvnjm+Lt+2f fxvIn9rbUQprwKHa44i9u8yRGWQ0LLrKk8pg/R0xplv9st+DXYIBF32a1SDgTUwCMu4S NJa36GsloVeJcm8IDJ34HariyL7Ia82hjzr8+JrOzZylsoYGkRoApvqebj/bBAp9ktzK 6/IQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:dkim-signature; bh=im9f7by7aGXOO+TZZQNnb2KIlOuQvzBKwx8HD64EYiA=; b=incAtg5b3KchLUYTU/UpBjnZVH6f1a3OnjqIEga/YTPVVjC0tg5R91PA43rhvElpiK 0be2Z44tx0DGiLmxSppYlKDViFqiGM0inwO/ePtL2JLMz9w/41xLHr9uEtCDPgNxOZC7 Wsr6ygQ+qFDVOx/+eRJTGBZZxBoaAD3/mJMwdn8WdPsOCuwDmkrbNEGFNt0lhQBTrGXe jyM9/zww7xX+B1ljCcmR7r79O/aPMQ4Z82mjTviEka56k3Gh99JC6pgjNu+INpqktgb4 R/eKXZMJPRELK1xEUfxwmO5ROU4+mjhss8ruB0YRmOpXbnxZWhGfRH4g8iWSkABSR98w no4A== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b="Eib/uCZy"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id y9-20020a17090322c900b001519ac2ef66si6544037plg.170.2022.03.10.15.58.05; Thu, 10 Mar 2022 15:58:22 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b="Eib/uCZy"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S244389AbiCJRRH (ORCPT + 99 others); Thu, 10 Mar 2022 12:17:07 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:45390 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S244244AbiCJRRF (ORCPT ); Thu, 10 Mar 2022 12:17:05 -0500 Received: from mail-io1-xd31.google.com (mail-io1-xd31.google.com [IPv6:2607:f8b0:4864:20::d31]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 565F3186213 for ; Thu, 10 Mar 2022 09:16:03 -0800 (PST) Received: by mail-io1-xd31.google.com with SMTP id w7so7247376ioj.5 for ; Thu, 10 Mar 2022 09:16:03 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=im9f7by7aGXOO+TZZQNnb2KIlOuQvzBKwx8HD64EYiA=; b=Eib/uCZyn0+INuEMXw5mnfIb0ym7lVaTFBob1AYHWH1yDsWLS+oO37W6XBwro4GEaM G+mgaQ/wxOrrJuamrtWFxVZKUr5iIXfalnEMOILIOmwW1zxkHp2VZARoRmVVxZUbJ/1f OXk3aG+sDTRLBtd5FXPmgr8EntaLdX1n++g9bLWjrYtuMggosleaJw8YZsFQOKR8ZDcz 5kXoDBTb/U7lPpNNP7CAZfO+Fr5NSFHwzd5kKVJ4y6MCjAsrdtJTzuEc2rF252DfPWJK 7oYlKN56iyw1mGBFXC8whWtcluDpanz2W3zq3SuUYcoq0+5UJxw8FSgrHSfvwgAEX52Z hYdg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=im9f7by7aGXOO+TZZQNnb2KIlOuQvzBKwx8HD64EYiA=; b=Uq4xpdUurzG6GatYpupLdQGl7l0GCwxL94nMBM30ci9rrGJMgkP3L5mWYylQVWS7jH j3GkUKQMznIhIkMDkuH3HN1bbNknVXfHbsRQj2m8YfXJEQgxbF9fbRTuhwvKLSWrDpX6 TrVJ5Y7WXql05h56lVqVh5upXEmQNcOKRDfNVdyCVnKmee4ZmpIY+TfYiccp6Eb5bKEb mlTgt6/c2QAfMm9UufzLL0Imrde4PI0FaRkhayX9iqD7jGE1XNFqjFvoNrsHSTIkSstP FacKCHbKVas9ei0xidYB8VKy5q67aw3d5/+dpamMArnSgvGLsnyUXBD++UwuECQb9KzQ KFxA== X-Gm-Message-State: AOAM53215oYuICb6Z/8A1z+hko3JbTI50NhoNpoETnay4/Umk5VkB5m+ TT/QF1qTQ/uWAwscGy6FqTdR24X9eqx0dIhWrTfGkQ== X-Received: by 2002:a05:6638:f95:b0:314:58f9:5896 with SMTP id h21-20020a0566380f9500b0031458f95896mr4926817jal.228.1646932562537; Thu, 10 Mar 2022 09:16:02 -0800 (PST) MIME-Version: 1.0 References: <20211005161833.1522737-1-lee.jones@linaro.org> <202203100851.C00D9AB73@keescook> In-Reply-To: <202203100851.C00D9AB73@keescook> From: Adam Langley Date: Thu, 10 Mar 2022 09:15:45 -0800 Message-ID: Subject: Re: [PATCH v2 1/1] sign-file: Do not attempt to use the ENGINE_* API if it's not available To: Kees Cook Cc: Lee Jones , David Howells , David Woodhouse , keyrings@vger.kernel.org, linux-kernel@vger.kernel.org, Eric Biggers Content-Type: text/plain; charset="UTF-8" X-Spam-Status: No, score=-17.6 required=5.0 tests=BAYES_00,DKIMWL_WL_MED, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF, ENV_AND_HDR_SPF_MATCH,RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS, T_SCC_BODY_TEXT_LINE,USER_IN_DEF_DKIM_WL,USER_IN_DEF_SPF_WL autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Thu, Mar 10, 2022 at 8:52 AM Kees Cook wrote: > > On Tue, Mar 08, 2022 at 10:31:11AM +0000, Lee Jones wrote: > > OpenSSL's ENGINE API is deprecated in OpenSSL v3.0. > > > > Use OPENSSL_NO_ENGINE to ensure the ENGINE API is only used if it is > > present. This will safeguard against compile errors when using SSL > > implementations which lack support for this deprecated API. > > On Fedora rawhide, I'm still seeing a bunch of warnings: > > scripts/sign-file.c: In function 'display_openssl_errors': > scripts/sign-file.c:89:9: warning: 'ERR_get_error_line' is deprecated: Since OpenSSL 3.0 [-Wdeprecat > ed-declarations] The `display_openssl_errors` function should probably just call ERR_print_errors_fp: https://www.openssl.org/docs/man1.0.2/man3/ERR_print_errors_fp.html The `drain_openssl_errors` function should probably just call ERR_clear_error: https://www.openssl.org/docs/man3.0/man3/ERR_clear_error.html Cheers AGL