Add compat subpkg for helping building dependencies
Add old ima-evm-utils version with the patches to expose the old soname for satisfying rpm-sign runtime dependency on the old soname. Thus, the new rpm-sign can be built and then depend on the new soname. Related: rhbz#2026028 Signed-off-by: Bruno Meneguele <bmeneg@redhat.com>
This commit is contained in:
parent
3f61e75888
commit
fdef5624a7
3
.gitignore
vendored
3
.gitignore
vendored
@ -1,4 +1 @@
|
||||
/ima-evm-utils-*.tar.gz
|
||||
/0001-evmctl-fix-memory-leak-with-password-variable.patch
|
||||
/0001-evmctl-fix-memory-leak-in-get_password.patch
|
||||
/0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch
|
||||
|
||||
38
0001-evmctl-fix-memory-leak-in-get_password.patch
Normal file
38
0001-evmctl-fix-memory-leak-in-get_password.patch
Normal file
@ -0,0 +1,38 @@
|
||||
From 2f1740eab432abc8e85172531d97eba33342474c Mon Sep 17 00:00:00 2001
|
||||
From: Bruno Meneguele <bmeneg@redhat.com>
|
||||
Date: Mon, 16 Aug 2021 12:11:15 -0300
|
||||
Subject: [PATCH] evmctl: fix memory leak in get_password
|
||||
|
||||
The variable "password" is not freed nor returned in case get_password()
|
||||
succeeds. Return it instead of the intermediary variable "pwd". Issue found
|
||||
by Coverity scan tool.
|
||||
|
||||
src/evmctl.c:2565: leaked_storage: Variable "password" going out of scope
|
||||
leaks the storage it points to.
|
||||
|
||||
Signed-off-by: Bruno Meneguele <bmeneg@redhat.com>
|
||||
---
|
||||
src/evmctl.c | 7 ++++++-
|
||||
1 file changed, 6 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/evmctl.c b/src/evmctl.c
|
||||
index a8065bbe124a..ab7173723095 100644
|
||||
--- a/src/evmctl.c
|
||||
+++ b/src/evmctl.c
|
||||
@@ -2625,7 +2625,12 @@ static char *get_password(void)
|
||||
return NULL;
|
||||
}
|
||||
|
||||
- return pwd;
|
||||
+ if (pwd == NULL) {
|
||||
+ free(password);
|
||||
+ return NULL;
|
||||
+ }
|
||||
+
|
||||
+ return password;
|
||||
}
|
||||
|
||||
int main(int argc, char *argv[])
|
||||
--
|
||||
2.31.1
|
||||
|
||||
61
0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch
Normal file
61
0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch
Normal file
@ -0,0 +1,61 @@
|
||||
From 916a0f97fd244a48fde429a63ddc04ed1ed94f8b Mon Sep 17 00:00:00 2001
|
||||
From: Bruno Meneguele <bmeneg@redhat.com>
|
||||
Date: Mon, 16 Aug 2021 17:58:35 -0300
|
||||
Subject: [PATCH] libimaevm: make SHA-256 the default hash algorithm
|
||||
|
||||
The SHA-1 algorithm is considered a weak hash algorithm and there has been
|
||||
some movement within certain distros to drop its support completely or at
|
||||
least drop it from the default behavior. ima-evm-utils uses it as the
|
||||
default algorithm in case the user doesn't explicitly ask for another
|
||||
through the --hashalgo/-a option. With that, make SHA-256 the default hash
|
||||
algorithm instead.
|
||||
|
||||
Signed-off-by: Bruno Meneguele <bmeneg@redhat.com>
|
||||
---
|
||||
README | 2 +-
|
||||
src/evmctl.c | 2 +-
|
||||
src/libimaevm.c | 2 +-
|
||||
3 files changed, 3 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/README b/README
|
||||
index 87cd3b5cd7da..0dc02f551673 100644
|
||||
--- a/README
|
||||
+++ b/README
|
||||
@@ -41,7 +41,7 @@ COMMANDS
|
||||
OPTIONS
|
||||
-------
|
||||
|
||||
- -a, --hashalgo sha1 (default), sha224, sha256, sha384, sha512
|
||||
+ -a, --hashalgo sha1, sha224, sha256 (default), sha384, sha512
|
||||
-s, --imasig make IMA signature
|
||||
-d, --imahash make IMA hash
|
||||
-f, --sigfile store IMA signature in .sig file instead of xattr
|
||||
diff --git a/src/evmctl.c b/src/evmctl.c
|
||||
index a8065bbe124a..e0e55bc0b122 100644
|
||||
--- a/src/evmctl.c
|
||||
+++ b/src/evmctl.c
|
||||
@@ -2496,7 +2496,7 @@ static void usage(void)
|
||||
|
||||
printf(
|
||||
"\n"
|
||||
- " -a, --hashalgo sha1 (default), sha224, sha256, sha384, sha512, streebog256, streebog512\n"
|
||||
+ " -a, --hashalgo sha1, sha224, sha256 (default), sha384, sha512, streebog256, streebog512\n"
|
||||
" -s, --imasig make IMA signature\n"
|
||||
" -d, --imahash make IMA hash\n"
|
||||
" -f, --sigfile store IMA signature in .sig file instead of xattr\n"
|
||||
diff --git a/src/libimaevm.c b/src/libimaevm.c
|
||||
index 8e9615796153..f6c72b878d88 100644
|
||||
--- a/src/libimaevm.c
|
||||
+++ b/src/libimaevm.c
|
||||
@@ -88,7 +88,7 @@ static const char *const pkey_hash_algo_kern[PKEY_HASH__LAST] = {
|
||||
struct libimaevm_params imaevm_params = {
|
||||
.verbose = LOG_INFO,
|
||||
.x509 = 1,
|
||||
- .hash_algo = "sha1",
|
||||
+ .hash_algo = "sha256",
|
||||
};
|
||||
|
||||
static void __attribute__ ((constructor)) libinit(void);
|
||||
--
|
||||
2.31.1
|
||||
|
||||
@ -1,11 +1,32 @@
|
||||
%bcond_with compat
|
||||
|
||||
# For cases where the soname requires a bump we need to make with_compat=1,
|
||||
# update the package into the side-tag, update RPM (rpm-sign) into side-tag,
|
||||
# _then_ turn with_compat=0 and rebuild the package into the side-tag. This
|
||||
# is required to workaround the chiken-egg situation with the rpm-sign update.
|
||||
# The compat pkg must not make the compose, it's only a buildrequirement for
|
||||
# rpm-sign in a soname bump.
|
||||
%if !%{with compat}
|
||||
%define with_compat 1
|
||||
%endif
|
||||
|
||||
%if %{with compat}
|
||||
%global compat_soversion 2
|
||||
%endif
|
||||
|
||||
Name: ima-evm-utils
|
||||
Version: 1.4
|
||||
Release: 1%{?dist}
|
||||
Release: 2%{?dist}
|
||||
Summary: IMA/EVM support utilities
|
||||
License: GPLv2
|
||||
Url: http://linux-ima.sourceforge.net/
|
||||
Source: http://sourceforge.net/projects/linux-ima/files/ima-evm-utils/%{name}-%{version}.tar.gz
|
||||
|
||||
# compat source and patches
|
||||
Source10: ima-evm-utils-1.3.2.tar.gz
|
||||
Patch10: 0001-evmctl-fix-memory-leak-in-get_password.patch
|
||||
Patch11: 0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch
|
||||
|
||||
BuildRequires: asciidoc
|
||||
BuildRequires: autoconf
|
||||
BuildRequires: automake
|
||||
@ -17,7 +38,6 @@ BuildRequires: make
|
||||
BuildRequires: openssl-devel
|
||||
BuildRequires: tpm2-tss-devel
|
||||
|
||||
|
||||
%description
|
||||
The Trusted Computing Group(TCG) run-time Integrity Measurement Architecture
|
||||
(IMA) maintains a list of hash values of executables and other sensitive
|
||||
@ -33,18 +53,49 @@ Requires: %{name} = %{version}-%{release}
|
||||
%description devel
|
||||
This package provides the header files for %{name}
|
||||
|
||||
%if %{with compat}
|
||||
%package -n %{name}%{compat_soversion}
|
||||
Summary: Compatibility package of %{name}
|
||||
|
||||
%description -n %{name}%{compat_soversion}
|
||||
This package provides the libimaevm.so.%{compat_soversion} relative to %{name}-1.3
|
||||
%endif
|
||||
|
||||
%prep
|
||||
%autosetup -p1
|
||||
%setup -q
|
||||
|
||||
%if %{with compat}
|
||||
mkdir compat/
|
||||
tar -zxf %{SOURCE10} --strip-components=1 -C compat/
|
||||
cd compat/
|
||||
%patch10 -p1
|
||||
%patch11 -p1
|
||||
%endif
|
||||
|
||||
%build
|
||||
autoreconf -vif
|
||||
%configure --disable-static
|
||||
%make_build
|
||||
|
||||
%if %{with compat}
|
||||
pushd compat/
|
||||
autoreconf -vif
|
||||
%configure --disable-static
|
||||
%make_build
|
||||
popd
|
||||
%endif
|
||||
|
||||
%install
|
||||
%make_install
|
||||
find %{buildroot} -type f -name "*.la" -print -delete
|
||||
|
||||
%if %{with compat}
|
||||
pushd compat/src/.libs/
|
||||
install -p libimaevm.so.%{compat_soversion}.0.0 %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion}.0.0
|
||||
ln -s -f %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion}.0.0 %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion}
|
||||
popd
|
||||
%endif
|
||||
|
||||
%ldconfig_scriptlets
|
||||
|
||||
%files
|
||||
@ -60,8 +111,17 @@ find %{buildroot} -type f -name "*.la" -print -delete
|
||||
%{_includedir}/imaevm.h
|
||||
%{_libdir}/libimaevm.so
|
||||
|
||||
%if %{with compat}
|
||||
%files -n %{name}%{compat_soversion}
|
||||
%{_libdir}/libimaevm.so.%{compat_soversion}
|
||||
%{_libdir}/libimaevm.so.%{compat_soversion}.0.0
|
||||
%endif
|
||||
|
||||
%changelog
|
||||
* Thu Dec 02 2021 Bruno Meneguele <bmeneg@redhat.com> - 1.4.0-1
|
||||
* Tue Dec 07 2021 Bruno Meneguele <bmeneg@redhat.com> - 1.4-2
|
||||
- Add compat subpkg for helping building dependencies (rhbz#2026028)
|
||||
|
||||
* Thu Dec 02 2021 Bruno Meneguele <bmeneg@redhat.com> - 1.4-1
|
||||
- Modify some pieces to get closer to Fedora's specfile
|
||||
- Remove patch handling memory leak: solved in the rebase
|
||||
- Remove patch handling SHA-256 default hash: solved in the rebase
|
||||
|
||||
1
sources
1
sources
@ -1 +1,2 @@
|
||||
SHA512 (ima-evm-utils-1.3.2.tar.gz) = af96935f953fbec8cdd40ba1a24001fae916633df03f9dee1e96775baec0ffea21a7a13798b3e3c3f375fd493a65fe65b5357887890b46cac0c4dcca5a5b79db
|
||||
SHA512 (ima-evm-utils-1.4.tar.gz) = 2fdf41470d88608162a084c4877ba17d531941b744bcb44dd4913e48ab2c2d131e0af3e3ead74c18748a5d46aced51213ebd7c13a5ee19050c28d54a26c011a3
|
||||
|
||||
Loading…
Reference in New Issue
Block a user