From fdef5624a78b946d327c818da1c08c0d36391eb3 Mon Sep 17 00:00:00 2001 From: Bruno Meneguele Date: Tue, 7 Dec 2021 15:50:57 -0300 Subject: [PATCH] Add compat subpkg for helping building dependencies Add old ima-evm-utils version with the patches to expose the old soname for satisfying rpm-sign runtime dependency on the old soname. Thus, the new rpm-sign can be built and then depend on the new soname. Related: rhbz#2026028 Signed-off-by: Bruno Meneguele --- .gitignore | 3 - ...mctl-fix-memory-leak-in-get_password.patch | 38 +++++++++++ ...e-SHA-256-the-default-hash-algorithm.patch | 61 +++++++++++++++++ ima-evm-utils.spec | 68 +++++++++++++++++-- sources | 1 + 5 files changed, 164 insertions(+), 7 deletions(-) create mode 100644 0001-evmctl-fix-memory-leak-in-get_password.patch create mode 100644 0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch diff --git a/.gitignore b/.gitignore index 8899b2c..2646509 100644 --- a/.gitignore +++ b/.gitignore @@ -1,4 +1 @@ /ima-evm-utils-*.tar.gz -/0001-evmctl-fix-memory-leak-with-password-variable.patch -/0001-evmctl-fix-memory-leak-in-get_password.patch -/0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch diff --git a/0001-evmctl-fix-memory-leak-in-get_password.patch b/0001-evmctl-fix-memory-leak-in-get_password.patch new file mode 100644 index 0000000..e6657d1 --- /dev/null +++ b/0001-evmctl-fix-memory-leak-in-get_password.patch @@ -0,0 +1,38 @@ +From 2f1740eab432abc8e85172531d97eba33342474c Mon Sep 17 00:00:00 2001 +From: Bruno Meneguele +Date: Mon, 16 Aug 2021 12:11:15 -0300 +Subject: [PATCH] evmctl: fix memory leak in get_password + +The variable "password" is not freed nor returned in case get_password() +succeeds. Return it instead of the intermediary variable "pwd". Issue found +by Coverity scan tool. + +src/evmctl.c:2565: leaked_storage: Variable "password" going out of scope + leaks the storage it points to. + +Signed-off-by: Bruno Meneguele +--- + src/evmctl.c | 7 ++++++- + 1 file changed, 6 insertions(+), 1 deletion(-) + +diff --git a/src/evmctl.c b/src/evmctl.c +index a8065bbe124a..ab7173723095 100644 +--- a/src/evmctl.c ++++ b/src/evmctl.c +@@ -2625,7 +2625,12 @@ static char *get_password(void) + return NULL; + } + +- return pwd; ++ if (pwd == NULL) { ++ free(password); ++ return NULL; ++ } ++ ++ return password; + } + + int main(int argc, char *argv[]) +-- +2.31.1 + diff --git a/0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch b/0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch new file mode 100644 index 0000000..e6dc92d --- /dev/null +++ b/0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch @@ -0,0 +1,61 @@ +From 916a0f97fd244a48fde429a63ddc04ed1ed94f8b Mon Sep 17 00:00:00 2001 +From: Bruno Meneguele +Date: Mon, 16 Aug 2021 17:58:35 -0300 +Subject: [PATCH] libimaevm: make SHA-256 the default hash algorithm + +The SHA-1 algorithm is considered a weak hash algorithm and there has been +some movement within certain distros to drop its support completely or at +least drop it from the default behavior. ima-evm-utils uses it as the +default algorithm in case the user doesn't explicitly ask for another +through the --hashalgo/-a option. With that, make SHA-256 the default hash +algorithm instead. + +Signed-off-by: Bruno Meneguele +--- + README | 2 +- + src/evmctl.c | 2 +- + src/libimaevm.c | 2 +- + 3 files changed, 3 insertions(+), 3 deletions(-) + +diff --git a/README b/README +index 87cd3b5cd7da..0dc02f551673 100644 +--- a/README ++++ b/README +@@ -41,7 +41,7 @@ COMMANDS + OPTIONS + ------- + +- -a, --hashalgo sha1 (default), sha224, sha256, sha384, sha512 ++ -a, --hashalgo sha1, sha224, sha256 (default), sha384, sha512 + -s, --imasig make IMA signature + -d, --imahash make IMA hash + -f, --sigfile store IMA signature in .sig file instead of xattr +diff --git a/src/evmctl.c b/src/evmctl.c +index a8065bbe124a..e0e55bc0b122 100644 +--- a/src/evmctl.c ++++ b/src/evmctl.c +@@ -2496,7 +2496,7 @@ static void usage(void) + + printf( + "\n" +- " -a, --hashalgo sha1 (default), sha224, sha256, sha384, sha512, streebog256, streebog512\n" ++ " -a, --hashalgo sha1, sha224, sha256 (default), sha384, sha512, streebog256, streebog512\n" + " -s, --imasig make IMA signature\n" + " -d, --imahash make IMA hash\n" + " -f, --sigfile store IMA signature in .sig file instead of xattr\n" +diff --git a/src/libimaevm.c b/src/libimaevm.c +index 8e9615796153..f6c72b878d88 100644 +--- a/src/libimaevm.c ++++ b/src/libimaevm.c +@@ -88,7 +88,7 @@ static const char *const pkey_hash_algo_kern[PKEY_HASH__LAST] = { + struct libimaevm_params imaevm_params = { + .verbose = LOG_INFO, + .x509 = 1, +- .hash_algo = "sha1", ++ .hash_algo = "sha256", + }; + + static void __attribute__ ((constructor)) libinit(void); +-- +2.31.1 + diff --git a/ima-evm-utils.spec b/ima-evm-utils.spec index 5e8824f..1f9e1ee 100644 --- a/ima-evm-utils.spec +++ b/ima-evm-utils.spec @@ -1,11 +1,32 @@ +%bcond_with compat + +# For cases where the soname requires a bump we need to make with_compat=1, +# update the package into the side-tag, update RPM (rpm-sign) into side-tag, +# _then_ turn with_compat=0 and rebuild the package into the side-tag. This +# is required to workaround the chiken-egg situation with the rpm-sign update. +# The compat pkg must not make the compose, it's only a buildrequirement for +# rpm-sign in a soname bump. +%if !%{with compat} +%define with_compat 1 +%endif + +%if %{with compat} +%global compat_soversion 2 +%endif + Name: ima-evm-utils Version: 1.4 -Release: 1%{?dist} +Release: 2%{?dist} Summary: IMA/EVM support utilities License: GPLv2 Url: http://linux-ima.sourceforge.net/ Source: http://sourceforge.net/projects/linux-ima/files/ima-evm-utils/%{name}-%{version}.tar.gz +# compat source and patches +Source10: ima-evm-utils-1.3.2.tar.gz +Patch10: 0001-evmctl-fix-memory-leak-in-get_password.patch +Patch11: 0001-libimaevm-make-SHA-256-the-default-hash-algorithm.patch + BuildRequires: asciidoc BuildRequires: autoconf BuildRequires: automake @@ -17,7 +38,6 @@ BuildRequires: make BuildRequires: openssl-devel BuildRequires: tpm2-tss-devel - %description The Trusted Computing Group(TCG) run-time Integrity Measurement Architecture (IMA) maintains a list of hash values of executables and other sensitive @@ -33,18 +53,49 @@ Requires: %{name} = %{version}-%{release} %description devel This package provides the header files for %{name} +%if %{with compat} +%package -n %{name}%{compat_soversion} +Summary: Compatibility package of %{name} + +%description -n %{name}%{compat_soversion} +This package provides the libimaevm.so.%{compat_soversion} relative to %{name}-1.3 +%endif + %prep -%autosetup -p1 +%setup -q + +%if %{with compat} +mkdir compat/ +tar -zxf %{SOURCE10} --strip-components=1 -C compat/ +cd compat/ +%patch10 -p1 +%patch11 -p1 +%endif %build autoreconf -vif %configure --disable-static %make_build +%if %{with compat} +pushd compat/ +autoreconf -vif +%configure --disable-static +%make_build +popd +%endif + %install %make_install find %{buildroot} -type f -name "*.la" -print -delete +%if %{with compat} +pushd compat/src/.libs/ +install -p libimaevm.so.%{compat_soversion}.0.0 %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion}.0.0 +ln -s -f %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion}.0.0 %{buildroot}%{_libdir}/libimaevm.so.%{compat_soversion} +popd +%endif + %ldconfig_scriptlets %files @@ -60,8 +111,17 @@ find %{buildroot} -type f -name "*.la" -print -delete %{_includedir}/imaevm.h %{_libdir}/libimaevm.so +%if %{with compat} +%files -n %{name}%{compat_soversion} +%{_libdir}/libimaevm.so.%{compat_soversion} +%{_libdir}/libimaevm.so.%{compat_soversion}.0.0 +%endif + %changelog -* Thu Dec 02 2021 Bruno Meneguele - 1.4.0-1 +* Tue Dec 07 2021 Bruno Meneguele - 1.4-2 +- Add compat subpkg for helping building dependencies (rhbz#2026028) + +* Thu Dec 02 2021 Bruno Meneguele - 1.4-1 - Modify some pieces to get closer to Fedora's specfile - Remove patch handling memory leak: solved in the rebase - Remove patch handling SHA-256 default hash: solved in the rebase diff --git a/sources b/sources index a03a3da..9c14713 100644 --- a/sources +++ b/sources @@ -1 +1,2 @@ +SHA512 (ima-evm-utils-1.3.2.tar.gz) = af96935f953fbec8cdd40ba1a24001fae916633df03f9dee1e96775baec0ffea21a7a13798b3e3c3f375fd493a65fe65b5357887890b46cac0c4dcca5a5b79db SHA512 (ima-evm-utils-1.4.tar.gz) = 2fdf41470d88608162a084c4877ba17d531941b744bcb44dd4913e48ab2c2d131e0af3e3ead74c18748a5d46aced51213ebd7c13a5ee19050c28d54a26c011a3