From 65d5e121c865ac5f8c0ef562143e7de3042a5297 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B6rn=20Esser?= Date: Thu, 20 Jan 2022 06:48:34 +0100 Subject: [PATCH] Build without compat bootstrap sub package MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Björn Esser --- ...mctl-fix-memory-leak-in-get_password.patch | 38 ------------ ...e-SHA-256-the-default-hash-algorithm.patch | 61 ------------------- ima-evm-utils.spec | 20 +++--- sources | 1 - 4 files changed, 10 insertions(+), 110 deletions(-) delete mode 100644 0001-evmctl-fix-memory-leak-in-get_password.patch delete mode 100644 0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch diff --git a/0001-evmctl-fix-memory-leak-in-get_password.patch b/0001-evmctl-fix-memory-leak-in-get_password.patch deleted file mode 100644 index e6657d1..0000000 --- a/0001-evmctl-fix-memory-leak-in-get_password.patch +++ /dev/null @@ -1,38 +0,0 @@ -From 2f1740eab432abc8e85172531d97eba33342474c Mon Sep 17 00:00:00 2001 -From: Bruno Meneguele -Date: Mon, 16 Aug 2021 12:11:15 -0300 -Subject: [PATCH] evmctl: fix memory leak in get_password - -The variable "password" is not freed nor returned in case get_password() -succeeds. Return it instead of the intermediary variable "pwd". Issue found -by Coverity scan tool. - -src/evmctl.c:2565: leaked_storage: Variable "password" going out of scope - leaks the storage it points to. - -Signed-off-by: Bruno Meneguele ---- - src/evmctl.c | 7 ++++++- - 1 file changed, 6 insertions(+), 1 deletion(-) - -diff --git a/src/evmctl.c b/src/evmctl.c -index a8065bbe124a..ab7173723095 100644 ---- a/src/evmctl.c -+++ b/src/evmctl.c -@@ -2625,7 +2625,12 @@ static char *get_password(void) - return NULL; - } - -- return pwd; -+ if (pwd == NULL) { -+ free(password); -+ return NULL; -+ } -+ -+ return password; - } - - int main(int argc, char *argv[]) --- -2.31.1 - diff --git a/0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch b/0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch deleted file mode 100644 index e6dc92d..0000000 --- a/0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch +++ /dev/null @@ -1,61 +0,0 @@ -From 916a0f97fd244a48fde429a63ddc04ed1ed94f8b Mon Sep 17 00:00:00 2001 -From: Bruno Meneguele -Date: Mon, 16 Aug 2021 17:58:35 -0300 -Subject: [PATCH] libimaevm: make SHA-256 the default hash algorithm - -The SHA-1 algorithm is considered a weak hash algorithm and there has been -some movement within certain distros to drop its support completely or at -least drop it from the default behavior. ima-evm-utils uses it as the -default algorithm in case the user doesn't explicitly ask for another -through the --hashalgo/-a option. With that, make SHA-256 the default hash -algorithm instead. - -Signed-off-by: Bruno Meneguele ---- - README | 2 +- - src/evmctl.c | 2 +- - src/libimaevm.c | 2 +- - 3 files changed, 3 insertions(+), 3 deletions(-) - -diff --git a/README b/README -index 87cd3b5cd7da..0dc02f551673 100644 ---- a/README -+++ b/README -@@ -41,7 +41,7 @@ COMMANDS - OPTIONS - ------- - -- -a, --hashalgo sha1 (default), sha224, sha256, sha384, sha512 -+ -a, --hashalgo sha1, sha224, sha256 (default), sha384, sha512 - -s, --imasig make IMA signature - -d, --imahash make IMA hash - -f, --sigfile store IMA signature in .sig file instead of xattr -diff --git a/src/evmctl.c b/src/evmctl.c -index a8065bbe124a..e0e55bc0b122 100644 ---- a/src/evmctl.c -+++ b/src/evmctl.c -@@ -2496,7 +2496,7 @@ static void usage(void) - - printf( - "\n" -- " -a, --hashalgo sha1 (default), sha224, sha256, sha384, sha512, streebog256, streebog512\n" -+ " -a, --hashalgo sha1, sha224, sha256 (default), sha384, sha512, streebog256, streebog512\n" - " -s, --imasig make IMA signature\n" - " -d, --imahash make IMA hash\n" - " -f, --sigfile store IMA signature in .sig file instead of xattr\n" -diff --git a/src/libimaevm.c b/src/libimaevm.c -index 8e9615796153..f6c72b878d88 100644 ---- a/src/libimaevm.c -+++ b/src/libimaevm.c -@@ -88,7 +88,7 @@ static const char *const pkey_hash_algo_kern[PKEY_HASH__LAST] = { - struct libimaevm_params imaevm_params = { - .verbose = LOG_INFO, - .x509 = 1, -- .hash_algo = "sha1", -+ .hash_algo = "sha256", - }; - - static void __attribute__ ((constructor)) libinit(void); --- -2.31.1 - diff --git a/ima-evm-utils.spec b/ima-evm-utils.spec index cd6b24e..d4370e1 100644 --- a/ima-evm-utils.spec +++ b/ima-evm-utils.spec @@ -4,25 +4,25 @@ # is required to workaround the chiken-egg situation with the rpm-sign update. # The compat pkg must not make the compose, it's only a buildrequirement for # rpm-sign in a soname bump. -%bcond_without compat +%bcond_with compat %if %{with compat} -%global compat_soversion 2 +%global compat_soversion 3 %endif Name: ima-evm-utils Version: 1.4 -Release: 3%{?dist} +Release: 4%{?dist} Summary: IMA/EVM support utilities License: GPLv2 Url: http://linux-ima.sourceforge.net/ -Source: http://sourceforge.net/projects/linux-ima/files/ima-evm-utils/%{name}-%{version}.tar.gz +Source0: http://sourceforge.net/projects/linux-ima/files/ima-evm-utils/%{name}-%{version}.tar.gz # compat source and patches -Source10: ima-evm-utils-1.3.2.tar.gz -Patch10: 0001-evmctl-fix-memory-leak-in-get_password.patch -Patch11: 0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch +%if %{with compat} +Source10: ima-evm-utils-1.4.tar.gz +%endif BuildRequires: asciidoc BuildRequires: autoconf @@ -64,9 +64,6 @@ This package provides the libimaevm.so.%{compat_soversion} relative to %{name}-1 %if %{with compat} mkdir compat/ tar -zxf %{SOURCE10} --strip-components=1 -C compat/ -cd compat/ -%patch10 -p1 -%patch11 -p1 %endif %build @@ -115,6 +112,9 @@ popd %endif %changelog +* Thu Jan 20 2022 Björn Esser - 1.4-4 +- Build without compat bootstrap sub package + * Thu Jan 20 2022 Björn Esser - 1.4-3 - Build with compat bootstrap sub package diff --git a/sources b/sources index 9c14713..a03a3da 100644 --- a/sources +++ b/sources @@ -1,2 +1 @@ -SHA512 (ima-evm-utils-1.3.2.tar.gz) = af96935f953fbec8cdd40ba1a24001fae916633df03f9dee1e96775baec0ffea21a7a13798b3e3c3f375fd493a65fe65b5357887890b46cac0c4dcca5a5b79db SHA512 (ima-evm-utils-1.4.tar.gz) = 2fdf41470d88608162a084c4877ba17d531941b744bcb44dd4913e48ab2c2d131e0af3e3ead74c18748a5d46aced51213ebd7c13a5ee19050c28d54a26c011a3