Received: by 2002:a05:6a10:413:0:0:0:0 with SMTP id 19csp804587pxp; Fri, 11 Mar 2022 15:36:29 -0800 (PST) X-Google-Smtp-Source: ABdhPJyVC1THjrz/FCER5P6zVEpFhkQEA3fhcFVyJSoQ9T1kR9CYWxCcyU4RHwh8Q8te84n5A3Uz X-Received: by 2002:a63:8ac9:0:b0:380:8d8b:d01a with SMTP id y192-20020a638ac9000000b003808d8bd01amr9986539pgd.572.1647041789110; Fri, 11 Mar 2022 15:36:29 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1647041789; cv=none; d=google.com; s=arc-20160816; b=pO8bk1He1u1Rr7vcde5awerSx7DGjKWpMgITq1aZkrmaseuK/cZwvMD0zRc2kJHsUe nkzxyk3r60bI+38r3iUQRi7+VnclDnl4CLHJnveyyt99TTmNr1GJuq4KRkIPDc/5J08K 4sgVL7HMCQrKTWEHiXi3P/pPIOB4cC1gGD+fWaeX6GrE0dn3C1G//+MrC2Nv/nnxDGIn 8Pi8XaDG4fSKirwzruX7iVtZldo5AwQIj9w68u2X4BX43LNVm+F52lWMaXQZUVKP0Dfe xfTwxWpSTp1zixwRuGFAIMCHcbfdWUL7I991MULCWkcUaA+LQivM1z+vmYOHdpvbbMky boQQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=B3pdfYyWo0OhCVTNyH6THmXanl+fxg8Ys7u7zsO5kBI=; b=wuCtrLeXD7oVUuISnUUQihvLRhVrDNspzE+M6zXTuZUBNt3pu3QkD6/kWKkxUzP2Hj c9WErDgPz2BISrPBM33TAIel5hc8gXbOha0K3G9JjeqUMqGy2sgOlOazDZXKcli/gHVQ ecK6N9x9cvRmEb17lOR67VMBu0Bh0AwxzSrMHBWm5m2SxDMeAEUjlaW7QRfDOkAwlX1W 93Y0sGsmUqJx8fE/0jtwTOUTYl68URFrk32oL/FlNySaYkoyezuCEQFl4Q1+nSg7qkD7 LzxUUshxgj1SW+nRfnbtJQYDTssDAF4o/yNQ2X1MMFGiL0qSuTh7RzBFgcW+iWyMZl/D 6knQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@ibm.com header.s=pp1 header.b=ABM9IjlJ; spf=softfail (google.com: domain of transitioning linux-kernel-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ibm.com Return-Path: Received: from lindbergh.monkeyblade.net (lindbergh.monkeyblade.net. [23.128.96.19]) by mx.google.com with ESMTPS id o39-20020a17090a0a2a00b001bf1d5158fcsi9300719pjo.84.2022.03.11.15.36.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 11 Mar 2022 15:36:29 -0800 (PST) Received-SPF: softfail (google.com: domain of transitioning linux-kernel-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) client-ip=23.128.96.19; Authentication-Results: mx.google.com; dkim=pass header.i=@ibm.com header.s=pp1 header.b=ABM9IjlJ; spf=softfail (google.com: domain of transitioning linux-kernel-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ibm.com Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id A64D32AEFA4; Fri, 11 Mar 2022 14:47:17 -0800 (PST) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229596AbiCKWsQ (ORCPT + 99 others); Fri, 11 Mar 2022 17:48:16 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:49126 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229580AbiCKWsA (ORCPT ); Fri, 11 Mar 2022 17:48:00 -0500 Received: from mx0a-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 79535B8238; Fri, 11 Mar 2022 14:35:50 -0800 (PST) Received: from pps.filterd (m0098413.ppops.net [127.0.0.1]) by mx0b-001b2d01.pphosted.com (8.16.1.2/8.16.1.2) with SMTP id 22BKcMu3014752; Fri, 11 Mar 2022 21:04:10 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=from : to : cc : subject : date : message-id : in-reply-to : references : mime-version : content-transfer-encoding; s=pp1; bh=B3pdfYyWo0OhCVTNyH6THmXanl+fxg8Ys7u7zsO5kBI=; b=ABM9IjlJPRLAHgeKHmWkyEmOiWGcsYcaEwQKCm2VSvD8ie6Joow82pkkUdLXBYZBnHVA qyyg7LUEbM2uXfOjXax8T/ZmwJ525C/p7hd1JHBBE9gdrqUSd0I16L2nkc/XQrkMXzLc v4qIVnb9hhre6oaIzz7mzYHqbg7v5rBIk9+zpu2ny+yryZ2oXF1eIBUsQtQM/d2jPzRf ScYVzDURsHruLFGA+HTU8u0v+bEavW2aYV0Kx6/htFlE05Bm4lwysigNBAmEoMmT3FSh MNp49FZyQoAChnyltZCvTV90dtFvlI5XD7+++9aBRQNaqHTNAg1wwuiZVCEzunK8+P5j 2Q== Received: from pps.reinject (localhost [127.0.0.1]) by mx0b-001b2d01.pphosted.com with ESMTP id 3eqrre7gms-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 11 Mar 2022 21:04:10 +0000 Received: from m0098413.ppops.net (m0098413.ppops.net [127.0.0.1]) by pps.reinject (8.16.0.43/8.16.0.43) with SMTP id 22BKpVgJ005143; Fri, 11 Mar 2022 21:04:10 GMT Received: from ppma04fra.de.ibm.com (6a.4a.5195.ip4.static.sl-reverse.com [149.81.74.106]) by mx0b-001b2d01.pphosted.com with ESMTP id 3eqrre7gmc-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 11 Mar 2022 21:04:09 +0000 Received: from pps.filterd (ppma04fra.de.ibm.com [127.0.0.1]) by ppma04fra.de.ibm.com (8.16.1.2/8.16.1.2) with SMTP id 22BL3Vxd011402; Fri, 11 Mar 2022 21:04:08 GMT Received: from b06cxnps3074.portsmouth.uk.ibm.com (d06relay09.portsmouth.uk.ibm.com [9.149.109.194]) by ppma04fra.de.ibm.com with ESMTP id 3ep8c3y13g-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 11 Mar 2022 21:04:07 +0000 Received: from d06av22.portsmouth.uk.ibm.com (d06av22.portsmouth.uk.ibm.com [9.149.105.58]) by b06cxnps3074.portsmouth.uk.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 22BL44NA17105370 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 11 Mar 2022 21:04:04 GMT Received: from d06av22.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 794CE4C044; Fri, 11 Mar 2022 21:04:04 +0000 (GMT) Received: from d06av22.portsmouth.uk.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id EA4424C04A; Fri, 11 Mar 2022 21:04:00 +0000 (GMT) Received: from li-4b5937cc-25c4-11b2-a85c-cea3a66903e4.ibm.com.com (unknown [9.211.110.168]) by d06av22.portsmouth.uk.ibm.com (Postfix) with ESMTP; Fri, 11 Mar 2022 21:04:00 +0000 (GMT) From: Nayna Jain To: linux-integrity@vger.kernel.org, keyrings@vger.kernel.org Cc: dhowells@redhat.com, zohar@linux.ibm.com, jarkko@kernel.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, dimitri.ledkov@canonical.com, seth@forshee.me, rnsastry@linux.ibm.com, masahiroy@kernel.org, Nayna Jain Subject: [PATCH v12 3/4] Revert "certs: move scripts/extract-cert to certs/" Date: Fri, 11 Mar 2022 16:03:43 -0500 Message-Id: <20220311210344.102396-4-nayna@linux.ibm.com> X-Mailer: git-send-email 2.27.0 In-Reply-To: <20220311210344.102396-1-nayna@linux.ibm.com> References: <20220311210344.102396-1-nayna@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-TM-AS-GCONF: 00 X-Proofpoint-ORIG-GUID: _q_TZ-tT8swzcoq0TjhDlkqVAnv9rVcB X-Proofpoint-GUID: hgIUDV40yWuKk1lrLc0BTMgepHsIWZzI X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.205,Aquarius:18.0.816,Hydra:6.0.425,FMLib:17.11.64.514 definitions=2022-03-11_09,2022-03-11_02,2022-02-23_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 priorityscore=1501 bulkscore=0 malwarescore=0 suspectscore=0 spamscore=0 lowpriorityscore=0 mlxlogscore=999 adultscore=0 impostorscore=0 phishscore=0 mlxscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2202240000 definitions=main-2203110103 X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,RDNS_NONE, SPF_HELO_NONE,T_SCC_BODY_TEXT_LINE autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org This reverts commit 340a02535ee785c64c62a9c45706597a0139e972. extract-cert is used outside certs/ by INTEGRITY_PLATFORM_KEYRING. Signed-off-by: Nayna Jain --- MAINTAINERS | 1 + certs/.gitignore | 1 - certs/Makefile | 13 ++++--------- scripts/.gitignore | 1 + scripts/Makefile | 11 +++++++++-- {certs => scripts}/extract-cert.c | 2 +- scripts/remove-stale-files | 2 -- 7 files changed, 16 insertions(+), 15 deletions(-) rename {certs => scripts}/extract-cert.c (98%) diff --git a/MAINTAINERS b/MAINTAINERS index 05fd080b82f3..cf4cd22ca3a0 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -4471,6 +4471,7 @@ L: keyrings@vger.kernel.org S: Maintained F: Documentation/admin-guide/module-signing.rst F: certs/ +F: scripts/extract-cert.c F: scripts/sign-file.c CFAG12864B LCD DRIVER diff --git a/certs/.gitignore b/certs/.gitignore index 9e42fe3e02f5..8c3763f80be3 100644 --- a/certs/.gitignore +++ b/certs/.gitignore @@ -1,4 +1,3 @@ # SPDX-License-Identifier: GPL-2.0-only -/extract-cert /x509_certificate_list /x509_revocation_list diff --git a/certs/Makefile b/certs/Makefile index b92b6ff339d5..a4a6f6a78904 100644 --- a/certs/Makefile +++ b/certs/Makefile @@ -14,11 +14,11 @@ obj-$(CONFIG_SYSTEM_BLACKLIST_KEYRING) += blacklist_nohashes.o endif quiet_cmd_extract_certs = CERT $@ - cmd_extract_certs = $(obj)/extract-cert $(2) $@ + cmd_extract_certs = scripts/extract-cert $(2) $@ $(obj)/system_certificates.o: $(obj)/x509_certificate_list -$(obj)/x509_certificate_list: $(CONFIG_SYSTEM_TRUSTED_KEYS) $(obj)/extract-cert FORCE +$(obj)/x509_certificate_list: $(CONFIG_SYSTEM_TRUSTED_KEYS) scripts/extract-cert FORCE $(call if_changed,extract_certs,$(if $(CONFIG_SYSTEM_TRUSTED_KEYS),$<,"")) targets += x509_certificate_list @@ -75,7 +75,7 @@ endif $(obj)/system_certificates.o: $(obj)/signing_key.x509 -$(obj)/signing_key.x509: $(X509_DEP) $(obj)/extract-cert FORCE +$(obj)/signing_key.x509: $(X509_DEP) scripts/extract-cert FORCE $(call if_changed,extract_certs,$(if $(CONFIG_MODULE_SIG_KEY),$(if $(X509_DEP),$<,$(CONFIG_MODULE_SIG_KEY)),"")) endif # CONFIG_MODULE_SIG @@ -83,12 +83,7 @@ targets += signing_key.x509 $(obj)/revocation_certificates.o: $(obj)/x509_revocation_list -$(obj)/x509_revocation_list: $(CONFIG_SYSTEM_REVOCATION_KEYS) $(obj)/extract-cert FORCE +$(obj)/x509_revocation_list: $(CONFIG_SYSTEM_REVOCATION_KEYS) scripts/extract-cert FORCE $(call if_changed,extract_certs,$(if $(CONFIG_SYSTEM_REVOCATION_KEYS),$<,"")) targets += x509_revocation_list - -hostprogs := extract-cert - -HOSTCFLAGS_extract-cert.o = $(shell pkg-config --cflags libcrypto 2> /dev/null) -HOSTLDLIBS_extract-cert = $(shell pkg-config --libs libcrypto 2> /dev/null || echo -lcrypto) diff --git a/scripts/.gitignore b/scripts/.gitignore index eed308bef604..e83c620ef52c 100644 --- a/scripts/.gitignore +++ b/scripts/.gitignore @@ -1,6 +1,7 @@ # SPDX-License-Identifier: GPL-2.0-only /asn1_compiler /bin2c +/extract-cert /insert-sys-cert /kallsyms /module.lds diff --git a/scripts/Makefile b/scripts/Makefile index ce5aa9030b74..cedc1f0e21d8 100644 --- a/scripts/Makefile +++ b/scripts/Makefile @@ -3,19 +3,26 @@ # scripts contains sources for various helper programs used throughout # the kernel for the build process. +CRYPTO_LIBS = $(shell pkg-config --libs libcrypto 2> /dev/null || echo -lcrypto) +CRYPTO_CFLAGS = $(shell pkg-config --cflags libcrypto 2> /dev/null) + hostprogs-always-$(CONFIG_BUILD_BIN2C) += bin2c hostprogs-always-$(CONFIG_KALLSYMS) += kallsyms hostprogs-always-$(BUILD_C_RECORDMCOUNT) += recordmcount hostprogs-always-$(CONFIG_BUILDTIME_TABLE_SORT) += sorttable hostprogs-always-$(CONFIG_ASN1) += asn1_compiler hostprogs-always-$(CONFIG_MODULE_SIG_FORMAT) += sign-file +hostprogs-always-$(CONFIG_SYSTEM_TRUSTED_KEYRING) += extract-cert hostprogs-always-$(CONFIG_SYSTEM_EXTRA_CERTIFICATE) += insert-sys-cert +hostprogs-always-$(CONFIG_SYSTEM_REVOCATION_LIST) += extract-cert HOSTCFLAGS_sorttable.o = -I$(srctree)/tools/include HOSTLDLIBS_sorttable = -lpthread HOSTCFLAGS_asn1_compiler.o = -I$(srctree)/include -HOSTCFLAGS_sign-file.o = $(shell pkg-config --cflags libcrypto 2> /dev/null) -HOSTLDLIBS_sign-file = $(shell pkg-config --libs libcrypto 2> /dev/null || echo -lcrypto) +HOSTCFLAGS_sign-file.o = $(CRYPTO_CFLAGS) +HOSTLDLIBS_sign-file = $(CRYPTO_LIBS) +HOSTCFLAGS_extract-cert.o = $(CRYPTO_CFLAGS) +HOSTLDLIBS_extract-cert = $(CRYPTO_LIBS) ifdef CONFIG_UNWINDER_ORC ifeq ($(ARCH),x86_64) diff --git a/certs/extract-cert.c b/scripts/extract-cert.c similarity index 98% rename from certs/extract-cert.c rename to scripts/extract-cert.c index f7ef7862f207..3bc48c726c41 100644 --- a/certs/extract-cert.c +++ b/scripts/extract-cert.c @@ -29,7 +29,7 @@ static __attribute__((noreturn)) void format(void) { fprintf(stderr, - "Usage: extract-cert \n"); + "Usage: scripts/extract-cert \n"); exit(2); } diff --git a/scripts/remove-stale-files b/scripts/remove-stale-files index 7adab4618035..80430b8fb617 100755 --- a/scripts/remove-stale-files +++ b/scripts/remove-stale-files @@ -39,5 +39,3 @@ if [ -n "${building_out_of_srctree}" ]; then rm -f arch/parisc/boot/compressed/${f} done fi - -rm -f scripts/extract-cert -- 2.34.1