diff --git a/.gitignore b/.gitignore index f2d4966..bc21f86 100644 --- a/.gitignore +++ b/.gitignore @@ -1,2 +1,2 @@ -SOURCES/rust-keylime-0.2.2-vendor.tar.xz -SOURCES/v0.2.2.tar.gz +rust-keylime-0.2.9-vendor.tar.zstd +v0.2.9.tar.gz diff --git a/.keylime-agent-rust.metadata b/.keylime-agent-rust.metadata deleted file mode 100644 index 56ae8f8..0000000 --- a/.keylime-agent-rust.metadata +++ /dev/null @@ -1,2 +0,0 @@ -88bd80638a9e933d823dff0b98e2cff849e7e000 SOURCES/rust-keylime-0.2.2-vendor.tar.xz -f83bc06ae2d04673fb2ed8356bf691ec664ef9f7 SOURCES/v0.2.2.tar.gz diff --git a/0001-rust-keylime-metadata.patch b/0001-rust-keylime-metadata.patch new file mode 100644 index 0000000..1322861 --- /dev/null +++ b/0001-rust-keylime-metadata.patch @@ -0,0 +1,57 @@ +--- a/keylime/Cargo.toml 2026-02-13 09:29:02.000000000 +0100 ++++ b/keylime/Cargo.toml 2026-02-13 09:48:22.122618066 +0100 +@@ -40,7 +40,6 @@ + tokio.workspace = true + uuid.workspace = true + zip.workspace = true +-zmq = {version = "0.9.2", optional = true} + + [dev-dependencies] + tempfile.workspace = true +@@ -48,6 +47,5 @@ + wiremock = {version = "0.6"} + + [features] ++default = [] + testing = [] +-# This feature is deprecated and will be removed on next major release +-with-zmq = ["zmq"] +--- a/keylime-agent/Cargo.toml 2026-02-13 09:29:02.000000000 +0100 ++++ b/keylime-agent/Cargo.toml 2026-02-13 09:48:27.988361994 +0100 +@@ -28,7 +28,6 @@ + thiserror.workspace = true + uuid.workspace = true + zip.workspace = true +-zmq = {version = "0.9.2", optional = true} + + [dev-dependencies] + actix-rt.workspace = true +@@ -37,18 +36,6 @@ + # The features enabled by default + default = [] + testing = [] +-# Whether the agent should be compiled with support to listen for notification +-# messages on ZeroMQ +-# +-# This feature is deprecated and will be removed on next major release +-with-zmq = ["zmq"] +-# Whether the agent should be compiled with support for python revocation +-# actions loaded as modules, which is the only kind supported by the python +-# agent (unless the enhancement-55 is implemented). See: +-# https://github.com/keylime/enhancements/blob/master/55_revocation_actions_without_python.md +-# +-# This feature is deprecated and will be removed on next major release +-legacy-python-actions = [] + + [package.metadata.deb] + section = "net" +--- a/keylime-push-model-agent/Cargo.toml 2026-02-13 09:29:02.000000000 +0100 ++++ b/keylime-push-model-agent/Cargo.toml 2026-02-13 09:48:36.030812674 +0100 +@@ -34,7 +34,6 @@ + # The features enabled by default + default = [] + testing = ["keylime/testing"] +-legacy-python-actions = [] + + [package.metadata.deb] + section = "net" diff --git a/0002-rust-keylime-do-not-require-usr-libexec.patch b/0002-rust-keylime-do-not-require-usr-libexec.patch new file mode 100644 index 0000000..d9510a7 --- /dev/null +++ b/0002-rust-keylime-do-not-require-usr-libexec.patch @@ -0,0 +1,73 @@ +diff --git a/keylime/src/config/base.rs b/keylime/src/config/base.rs +index c171c85..d2e889a 100644 +--- a/keylime/src/config/base.rs ++++ b/keylime/src/config/base.rs +@@ -625,27 +625,15 @@ pub(crate) fn config_translate_keywords( + }); + } + +- let actions_dir = match config.revocation_actions_dir.as_ref() { +- "" => { +- error!("The option 'enable_revocation_notifications' is set as 'true' but the revocation actions directory was set as empty in 'revocation_actions_dir'"); +- return Err(KeylimeConfigError::IncompatibleOptions { +- option_a: "enable_revocation_notifications".into(), +- value_a: "true".into(), +- option_b: "revocation_actions_dir".into(), +- value_b: "empty".into(), +- }); +- } +- dir => Path::new(dir), ++ if config.revocation_actions_dir.is_empty() { ++ error!("The option 'enable_revocation_notifications' is set as 'true' but the revocation actions directory was set as empty in 'revocation_actions_dir'"); ++ return Err(KeylimeConfigError::IncompatibleOptions { ++ option_a: "enable_revocation_notifications".into(), ++ value_a: "true".into(), ++ option_b: "revocation_actions_dir".into(), ++ value_b: "empty".into(), ++ }); + }; +- +- // Validate that the revocation actions directory exists +- let _revocation_actions_dir = +- &actions_dir.canonicalize().map_err(|e| { +- KeylimeConfigError::MissingActionsDir { +- path: keylime_dir.display().to_string(), +- source: e, +- } +- })?; + } + + let revocation_cert = config_get_file_path( +@@ -938,32 +926,6 @@ mod tests { + assert!(result.is_ok()); + } + +- #[test] +- fn test_invalid_revocation_actions_dir() { +- let tempdir = tempfile::tempdir() +- .expect("failed to create temporary directory"); +- +- let test_config = AgentConfig { +- keylime_dir: tempdir.path().display().to_string(), +- enable_revocation_notifications: true, +- revocation_actions_dir: "/invalid".to_string(), +- ..Default::default() +- }; +- let result = config_translate_keywords(&test_config); +- // Expect error due to the inexistent directory +- assert!(result.is_err()); +- let test_config = AgentConfig { +- keylime_dir: tempdir.path().display().to_string(), +- enable_revocation_notifications: false, +- revocation_actions_dir: "/invalid".to_string(), +- ..Default::default() +- }; +- +- // Now unset enable_revocation_notifications and check that is allowed +- let result = config_translate_keywords(&test_config); +- assert!(result.is_ok()); +- } +- + #[test] + fn test_keylime_dir_option() { + let dir = tempfile::tempdir() diff --git a/0003-rust-keylime-registrar-tls-port.patch b/0003-rust-keylime-registrar-tls-port.patch new file mode 100644 index 0000000..9f46b09 --- /dev/null +++ b/0003-rust-keylime-registrar-tls-port.patch @@ -0,0 +1,514 @@ +From 3cbb5cddc5e149619ea11c797d2963e68b50b280 Mon Sep 17 00:00:00 2001 +From: Anderson Toshiyuki Sasaki +Date: Tue, 10 Mar 2026 10:47:01 +0100 +Subject: [PATCH 1/2] push-attestation: Use registrar TLS port when TLS is + enabled + +The push-attestation agent was using the plaintext registrar port (8890) +even when TLS was enabled, but the registrar listens on a separate port +for TLS connections (8891). Add a registrar_tls_port config option and +use it when TLS is active. + +The decision on whether using TLS or not is consolidated in +create_registrar_tls_config(), which now sets the registrar_tls_port in +RegistrarTlsConfig. Downstream code (register_agent) simply uses the +port from the TLS config when present, or falls back to the plaintext +port. + +Port constants (DEFAULT_REGISTRAR_PORT, DEFAULT_REGISTRAR_TLS_PORT) are +used instead of hardcoded values. + +Co-Authored-By: Claude Opus 4.6 +Signed-off-by: Anderson Toshiyuki Sasaki +--- + keylime-agent.conf | 8 ++ + keylime-push-model-agent/src/main.rs | 11 +++ + keylime-push-model-agent/src/registration.rs | 85 +++++++++++++++----- + keylime/src/config/base.rs | 3 + + keylime/src/config/push_model.rs | 2 + + keylime/src/config/testing.rs | 6 +- + 6 files changed, 95 insertions(+), 20 deletions(-) + +diff --git a/keylime-agent.conf b/keylime-agent.conf +index 4ed60ccf5..a9d822070 100644 +--- a/keylime-agent.conf ++++ b/keylime-agent.conf +@@ -61,6 +61,14 @@ contact_port = 9002 + registrar_ip = "127.0.0.1" + registrar_port = 8890 + ++# The TLS port of the registrar server which agent communicates with when ++# registrar_tls_enabled is set to true. ++# This is the port the registrar listens on for TLS connections. ++# ++# To override registrar_tls_port, set KEYLIME_AGENT_REGISTRAR_TLS_PORT ++# environment variable. ++registrar_tls_port = 8891 ++ + # Enable TLS communication between agent and registrar. + # When enabled, the agent will use TLS (server verification only) when + # communicating with the registrar. The registrar_tls_ca_cert option must be +diff --git a/keylime-push-model-agent/src/main.rs b/keylime-push-model-agent/src/main.rs +index bd0656d97..a9753bf8a 100644 +--- a/keylime-push-model-agent/src/main.rs ++++ b/keylime-push-model-agent/src/main.rs +@@ -117,6 +117,7 @@ fn create_registrar_tls_config( + ca_cert: Some(ca_cert.to_string()), + disable_tls: None, + timeout: Some(timeout), ++ registrar_tls_port: config.registrar_tls_port(), + }); + } + +@@ -346,10 +347,12 @@ async fn main() -> Result<()> { + #[cfg(test)] + mod tests { + use super::*; ++ use keylime::config::DEFAULT_REGISTRAR_TLS_PORT; + + // Mock config for testing + struct MockConfig { + tls_enabled: bool, ++ tls_port: u32, + ca_cert: String, + backoff_max_delay: Option, + backoff_max_retries: Option, +@@ -421,6 +424,9 @@ mod tests { + fn registrar_port(&self) -> u32 { + 0 + } ++ fn registrar_tls_port(&self) -> u32 { ++ self.tls_port ++ } + fn tpm_encryption_alg(&self) -> &str { + "" + } +@@ -446,6 +452,7 @@ mod tests { + // Test when TLS is disabled + let config = MockConfig { + tls_enabled: false, ++ tls_port: DEFAULT_REGISTRAR_TLS_PORT, + ca_cert: "".to_string(), + backoff_max_delay: None, + backoff_max_retries: None, +@@ -461,6 +468,7 @@ mod tests { + // Test when TLS is enabled with CA certificate (push model doesn't use client certs) + let config = MockConfig { + tls_enabled: true, ++ tls_port: DEFAULT_REGISTRAR_TLS_PORT, + ca_cert: "/path/to/ca.crt".to_string(), + backoff_max_delay: None, + backoff_max_retries: None, +@@ -474,6 +482,7 @@ mod tests { + assert_eq!(tls_config.ca_cert, Some("/path/to/ca.crt".to_string())); + assert_eq!(tls_config.timeout, Some(5000)); + assert_eq!(tls_config.disable_tls, None); ++ assert_eq!(tls_config.registrar_tls_port, DEFAULT_REGISTRAR_TLS_PORT); + } + + #[test] +@@ -481,6 +490,7 @@ mod tests { + // Test when TLS is enabled but no CA certificate path is provided + let config = MockConfig { + tls_enabled: true, ++ tls_port: DEFAULT_REGISTRAR_TLS_PORT, + ca_cert: "".to_string(), + backoff_max_delay: None, + backoff_max_retries: None, +@@ -496,6 +506,7 @@ mod tests { + // Test that custom timeout is properly set + let config = MockConfig { + tls_enabled: true, ++ tls_port: DEFAULT_REGISTRAR_TLS_PORT, + ca_cert: "/path/to/ca.crt".to_string(), + backoff_max_delay: None, + backoff_max_retries: None, +diff --git a/keylime-push-model-agent/src/registration.rs b/keylime-push-model-agent/src/registration.rs +index bc5e3b283..0189cb15b 100644 +--- a/keylime-push-model-agent/src/registration.rs ++++ b/keylime-push-model-agent/src/registration.rs +@@ -9,10 +9,15 @@ use keylime::{ + + /// TLS configuration for registrar communication in push model. + /// Push model uses server-only TLS verification (no client certificates/mTLS). ++/// ++/// When this struct is `Some`, TLS is considered active: the registrar client ++/// will use HTTPS, and `registrar_tls_port` will be used instead of the ++/// plaintext port. + pub struct RegistrarTlsConfig { + pub ca_cert: Option, + pub disable_tls: Option, + pub timeout: Option, ++ pub registrar_tls_port: u32, + } + + pub async fn check_registration( +@@ -55,18 +60,26 @@ pub async fn register_agent( + // Resolve agent UUID using the centralized helper + let agent_uuid = context_info.resolve_agent_id(config.uuid()); + +- // Extract TLS config values; push model doesn't use client certs (no mTLS) +- let (ca_cert, disable_tls, timeout) = if let Some(tls) = tls_config { +- (tls.ca_cert, tls.disable_tls, tls.timeout) +- } else { +- (None, None, None) +- }; ++ // Extract TLS config values; push model doesn't use client certs (no mTLS). ++ // When tls_config is Some, TLS is active: use the TLS port and CA cert. ++ // When None, TLS is not active: use the plaintext port. ++ let (ca_cert, disable_tls, timeout, registrar_port) = ++ if let Some(tls) = tls_config { ++ ( ++ tls.ca_cert, ++ tls.disable_tls, ++ tls.timeout, ++ tls.registrar_tls_port, ++ ) ++ } else { ++ (None, None, None, config.registrar_port()) ++ }; + + let ac = AgentRegistrationConfig { + contact_ip: config.contact_ip().to_string(), + contact_port: config.contact_port(), + registrar_ip: config.registrar_ip().to_string(), +- registrar_port: config.registrar_port(), ++ registrar_port, + enable_iak_idevid: config.enable_iak_idevid(), + ek_handle: config + .ek_handle() +@@ -114,7 +127,10 @@ mod tests { + use super::*; + + use keylime::{ +- config::get_testing_config, ++ config::{ ++ get_testing_config, DEFAULT_REGISTRAR_PORT, ++ DEFAULT_REGISTRAR_TLS_PORT, ++ }, + context_info::{AlgorithmConfigurationString, ContextInfo}, + tpm::testing, + }; +@@ -164,6 +180,7 @@ mod tests { + ca_cert: Some("/path/to/ca.pem".to_string()), + disable_tls: Some(false), + timeout: Some(5000), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + + assert_eq!(tls_config.ca_cert, Some("/path/to/ca.pem".to_string())); +@@ -177,6 +194,7 @@ mod tests { + ca_cert: None, + disable_tls: None, + timeout: None, ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + + assert_eq!(tls_config.ca_cert, None); +@@ -190,6 +208,7 @@ mod tests { + ca_cert: Some("/path/to/ca.pem".to_string()), + disable_tls: Some(true), + timeout: Some(10000), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + + assert_eq!(tls_config.ca_cert, Some("/path/to/ca.pem".to_string())); +@@ -203,6 +222,7 @@ mod tests { + ca_cert: Some("".to_string()), + disable_tls: Some(false), + timeout: Some(0), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + + assert_eq!(tls_config.ca_cert, Some("".to_string())); +@@ -233,6 +253,7 @@ mod tests { + ca_cert: Some("/path/to/ca.pem".to_string()), + disable_tls: Some(false), + timeout: Some(5000), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + + // Test with None context_info but Some tls_config (should not register) +@@ -268,6 +289,7 @@ mod tests { + ca_cert: Some("/path/to/ca.pem".to_string()), + disable_tls: Some(false), + timeout: Some(5000), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + + let result = +@@ -305,6 +327,7 @@ mod tests { + ca_cert: Some("/path/to/ca.pem".to_string()), + disable_tls: None, + timeout: Some(5000), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + + let result = +@@ -342,6 +365,7 @@ mod tests { + ca_cert: Some("/path/to/ca.pem".to_string()), + disable_tls: Some(true), + timeout: Some(5000), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + + let result = +@@ -413,6 +437,7 @@ mod tests { + ca_cert: Some("/path/to/ca.pem".to_string()), + disable_tls: None, + timeout: Some(0), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + assert_eq!(tls_config_zero.timeout, Some(0)); + +@@ -421,6 +446,7 @@ mod tests { + ca_cert: Some("/path/to/ca.pem".to_string()), + disable_tls: None, + timeout: Some(300000), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + assert_eq!(tls_config_large.timeout, Some(300000)); + +@@ -429,6 +455,7 @@ mod tests { + ca_cert: Some("/path/to/ca.pem".to_string()), + disable_tls: None, + timeout: None, ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + assert_eq!(tls_config_none.timeout, None); + } +@@ -439,32 +466,47 @@ mod tests { + ca_cert: Some("/ca.pem".to_string()), + disable_tls: Some(false), + timeout: Some(5000), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }); + +- let (ca_cert, disable_tls, timeout) = if let Some(tls) = tls_config { +- (tls.ca_cert, tls.disable_tls, tls.timeout) +- } else { +- (None, None, None) +- }; ++ let (ca_cert, disable_tls, timeout, registrar_port) = ++ if let Some(tls) = tls_config { ++ ( ++ tls.ca_cert, ++ tls.disable_tls, ++ tls.timeout, ++ tls.registrar_tls_port, ++ ) ++ } else { ++ (None, None, None, DEFAULT_REGISTRAR_PORT) ++ }; + + assert_eq!(ca_cert, Some("/ca.pem".to_string())); + assert_eq!(disable_tls, Some(false)); + assert_eq!(timeout, Some(5000)); ++ assert_eq!(registrar_port, DEFAULT_REGISTRAR_TLS_PORT); + } + + #[actix_rt::test] + async fn test_tls_config_extraction_none() { + let tls_config: Option = None; + +- let (ca_cert, disable_tls, timeout) = if let Some(tls) = tls_config { +- (tls.ca_cert, tls.disable_tls, tls.timeout) +- } else { +- (None, None, None) +- }; ++ let (ca_cert, disable_tls, timeout, registrar_port) = ++ if let Some(tls) = tls_config { ++ ( ++ tls.ca_cert, ++ tls.disable_tls, ++ tls.timeout, ++ tls.registrar_tls_port, ++ ) ++ } else { ++ (None, None, None, DEFAULT_REGISTRAR_PORT) ++ }; + + assert_eq!(ca_cert, None); + assert_eq!(disable_tls, None); + assert_eq!(timeout, None); ++ assert_eq!(registrar_port, DEFAULT_REGISTRAR_PORT); + } + + #[tokio::test] +@@ -503,6 +545,7 @@ mod tests { + ca_cert: Some(ca_path.to_string_lossy().to_string()), + disable_tls: Some(false), + timeout: Some(5000), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + + // Should fail due to invalid port, but TLS config should be processed +@@ -529,7 +572,7 @@ mod tests { + config.exponential_backoff_max_retries = None; + config.exponential_backoff_max_delay = None; + config.registrar_ip = "127.0.0.1".to_string(); +- config.registrar_port = 8891; ++ config.registrar_port = DEFAULT_REGISTRAR_TLS_PORT; + + let _guard = keylime::config::TestConfigGuard::new(config); + +@@ -541,6 +584,7 @@ mod tests { + ca_cert: Some("/nonexistent/ca.pem".to_string()), + disable_tls: Some(false), + timeout: Some(5000), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + + // Should fail due to missing certificate files +@@ -562,6 +606,7 @@ mod tests { + ca_cert: Some(ca_path.to_string_lossy().to_string()), + disable_tls: Some(false), + timeout: Some(10000), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + + // Verify all fields are set correctly +@@ -571,6 +616,7 @@ mod tests { + ); + assert_eq!(tls_config.disable_tls, Some(false)); + assert_eq!(tls_config.timeout, Some(10000)); ++ assert_eq!(tls_config.registrar_tls_port, DEFAULT_REGISTRAR_TLS_PORT); + } + + #[tokio::test] +@@ -602,6 +648,7 @@ mod tests { + ca_cert: Some("".to_string()), + disable_tls: Some(false), + timeout: Some(5000), ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + }; + + let result = +diff --git a/keylime/src/config/base.rs b/keylime/src/config/base.rs +index c171c8592..31fdc44ef 100644 +--- a/keylime/src/config/base.rs ++++ b/keylime/src/config/base.rs +@@ -36,6 +36,7 @@ pub static DEFAULT_IP: &str = "127.0.0.1"; + pub static DEFAULT_PORT: u32 = 9002; + pub static DEFAULT_REGISTRAR_IP: &str = "127.0.0.1"; + pub static DEFAULT_REGISTRAR_PORT: u32 = 8890; ++pub static DEFAULT_REGISTRAR_TLS_PORT: u32 = 8891; + pub static DEFAULT_REGISTRAR_TLS_ENABLED: bool = false; + pub static DEFAULT_REGISTRAR_TLS_CA_CERT: &str = "cv_ca/cacert.crt"; + pub static DEFAULT_KEYLIME_DIR: &str = "/var/lib/keylime"; +@@ -140,6 +141,7 @@ pub struct AgentConfig { + pub port: u32, + pub registrar_ip: String, + pub registrar_port: u32, ++ pub registrar_tls_port: u32, + pub registrar_tls_enabled: bool, + pub registrar_tls_ca_cert: String, + pub run_as: String, +@@ -318,6 +320,7 @@ impl Default for AgentConfig { + port: DEFAULT_PORT, + registrar_ip: DEFAULT_REGISTRAR_IP.to_string(), + registrar_port: DEFAULT_REGISTRAR_PORT, ++ registrar_tls_port: DEFAULT_REGISTRAR_TLS_PORT, + registrar_tls_enabled: DEFAULT_REGISTRAR_TLS_ENABLED, + registrar_tls_ca_cert: "default".to_string(), + revocation_actions: DEFAULT_REVOCATION_ACTIONS.to_string(), +diff --git a/keylime/src/config/push_model.rs b/keylime/src/config/push_model.rs +index 644051196..0e461c381 100644 +--- a/keylime/src/config/push_model.rs ++++ b/keylime/src/config/push_model.rs +@@ -70,6 +70,7 @@ pub struct PushModelConfig { + registrar_api_versions: Vec<&str>, + registrar_ip: String, + registrar_port: u32, ++ registrar_tls_port: u32, + registrar_tls_enabled: bool, + registrar_tls_ca_cert: String, + tpm_encryption_alg: String, +@@ -113,6 +114,7 @@ mod tests { + assert_eq!(config.enable_iak_idevid(), DEFAULT_ENABLE_IAK_IDEVID); + assert_eq!(config.registrar_ip(), DEFAULT_REGISTRAR_IP); + assert_eq!(config.registrar_port(), DEFAULT_REGISTRAR_PORT); ++ assert_eq!(config.registrar_tls_port(), DEFAULT_REGISTRAR_TLS_PORT); + assert_eq!( + config.uefi_logs_evidence_version(), + DEFAULT_UEFI_LOGS_EVIDENCE_VERSION +diff --git a/keylime/src/config/testing.rs b/keylime/src/config/testing.rs +index 94b52f978..4f666fb33 100644 +--- a/keylime/src/config/testing.rs ++++ b/keylime/src/config/testing.rs +@@ -58,7 +58,7 @@ fn apply_config_overrides( + ) { + use crate::config::{ + DEFAULT_CONTACT_PORT, DEFAULT_PORT, DEFAULT_REGISTRAR_PORT, +- DEFAULT_REVOCATION_NOTIFICATION_PORT, ++ DEFAULT_REGISTRAR_TLS_PORT, DEFAULT_REVOCATION_NOTIFICATION_PORT, + }; + + for (key, value) in overrides { +@@ -100,6 +100,10 @@ fn apply_config_overrides( + config.registrar_port = + value.parse().unwrap_or(DEFAULT_REGISTRAR_PORT); + } ++ "registrar_tls_port" => { ++ config.registrar_tls_port = ++ value.parse().unwrap_or(DEFAULT_REGISTRAR_TLS_PORT); ++ } + "run_as" => config.run_as = value, + "tpm_encryption_alg" => config.tpm_encryption_alg = value, + "tpm_hash_alg" => config.tpm_hash_alg = value, + +From 734a87c458bd644828805eaffa994cb4b7e0bd98 Mon Sep 17 00:00:00 2001 +From: Anderson Toshiyuki Sasaki +Date: Tue, 10 Mar 2026 10:48:24 +0100 +Subject: [PATCH 2/2] Use port constants instead of hardcoded values in tests + +Replace hardcoded port numbers (8891) with DEFAULT_REGISTRAR_TLS_PORT in +registrar client tests for consistency. + +Co-Authored-By: Claude Opus 4.6 +Signed-off-by: Anderson Toshiyuki Sasaki +--- + keylime/src/registrar_client.rs | 11 +++++++---- + 1 file changed, 7 insertions(+), 4 deletions(-) + +diff --git a/keylime/src/registrar_client.rs b/keylime/src/registrar_client.rs +index 3fb2f9686..7750a381e 100644 +--- a/keylime/src/registrar_client.rs ++++ b/keylime/src/registrar_client.rs +@@ -700,7 +700,10 @@ impl RegistrarClient { + #[cfg(test)] + mod tests { + use super::*; +- use crate::{agent_identity::AgentIdentityBuilder, crypto}; ++ use crate::{ ++ agent_identity::AgentIdentityBuilder, ++ config::DEFAULT_REGISTRAR_TLS_PORT, crypto, ++ }; + use wiremock::matchers::{method, path}; + use wiremock::{Mock, MockServer, ResponseTemplate}; + +@@ -1407,7 +1410,7 @@ mod tests { + } + + if to_add.contains(&"registrar_port") { +- builder = builder.registrar_port(8891); ++ builder = builder.registrar_port(DEFAULT_REGISTRAR_TLS_PORT); + } + + let result = builder.build().await; +@@ -1475,13 +1478,13 @@ mod tests { + async fn test_builder_chaining_with_tls() { + let builder = RegistrarClientBuilder::new() + .registrar_address("127.0.0.1".to_string()) +- .registrar_port(8891) ++ .registrar_port(DEFAULT_REGISTRAR_TLS_PORT) + .ca_certificate("/path/to/ca.pem".to_string()) + .disable_tls(false) + .timeout(5000); + + assert_eq!(builder.registrar_address, Some("127.0.0.1".to_string())); +- assert_eq!(builder.registrar_port, Some(8891)); ++ assert_eq!(builder.registrar_port, Some(DEFAULT_REGISTRAR_TLS_PORT)); + assert_eq!( + builder.ca_certificate, + Some("/path/to/ca.pem".to_string()) diff --git a/SOURCES/0001-rust-keylime-adjust-features.patch b/SOURCES/0001-rust-keylime-adjust-features.patch deleted file mode 100644 index 7ca1b1e..0000000 --- a/SOURCES/0001-rust-keylime-adjust-features.patch +++ /dev/null @@ -1,29 +0,0 @@ ---- a/keylime-agent/Cargo.toml 2025-02-07 17:53:24.436876268 +0100 -+++ b/keylime-agent/Cargo.toml 2025-02-07 17:54:06.501697761 +0100 -@@ -34,11 +34,6 @@ - tss-esapi = {version = "7.2.0", features = ["generate-bindings"]} - thiserror = "1.0" - uuid = {version = "1.3", features = ["v4"]} --zmq = {version = "0.9.2", optional = true} --# wiremock was moved to be a regular dependency because optional --# dev-dependencies are not supported --# see: https://github.com/rust-lang/cargo/issues/1596 --wiremock = {version = "0.5", optional = true} - - [dev-dependencies] - actix-rt = "2" -@@ -47,12 +42,12 @@ - # The features enabled by default - default = [] - # this should change to dev-dependencies when we have integration testing --testing = ["wiremock"] -+testing = [] - # Whether the agent should be compiled with support to listen for notification - # messages on ZeroMQ - # - # This feature is deprecated and will be removed on next major release --with-zmq = ["zmq"] -+with-zmq = [] - # Whether the agent should be compiled with support for python revocation - # actions loaded as modules, which is the only kind supported by the python - # agent (unless the enhancement-55 is implemented). See: diff --git a/SOURCES/0002-rust-keylime-openssl-0.10.70.patch b/SOURCES/0002-rust-keylime-openssl-0.10.70.patch deleted file mode 100644 index 60abe0a..0000000 --- a/SOURCES/0002-rust-keylime-openssl-0.10.70.patch +++ /dev/null @@ -1,635 +0,0 @@ -diff --git a/Cargo.lock b/tmp/Cargo.lock -index b91be43..6642d88 100644 ---- a/Cargo.lock -+++ b/tmp/Cargo.lock -@@ -1,6 +1,6 @@ - # This file is automatically @generated by Cargo. - # It is not intended for manual editing. --version = 3 -+version = 4 - - [[package]] - name = "actix-codec" -@@ -8,7 +8,7 @@ version = "0.5.0" - source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "57a7559404a7f3573127aab53c08ce37a6c6a315c374a31070f3c91cd1b4a7fe" - dependencies = [ -- "bitflags", -+ "bitflags 1.3.2", - "bytes", - "futures-core", - "futures-sink", -@@ -32,7 +32,7 @@ dependencies = [ - "actix-utils", - "ahash 0.8.3", - "base64 0.21.0", -- "bitflags", -+ "bitflags 1.3.2", - "bytes", - "bytestring", - "derive_more", -@@ -48,7 +48,7 @@ dependencies = [ - "mime", - "percent-encoding", - "pin-project-lite", -- "rand 0.8.5", -+ "rand", - "sha1", - "smallvec", - "tokio", -@@ -206,7 +206,7 @@ version = "0.7.6" - source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "fcb51a0695d8f838b1ee009b3fbf66bda078cd64590202a864a8f3e8c4315c47" - dependencies = [ -- "getrandom 0.2.7", -+ "getrandom", - "once_cell", - "version_check", - ] -@@ -218,7 +218,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "2c99f64d1e06488f620f932677e24bc6e2897582980441ae90a671415bd7ec2f" - dependencies = [ - "cfg-if", -- "getrandom 0.2.7", -+ "getrandom", - "once_cell", - "version_check", - ] -@@ -281,33 +281,6 @@ dependencies = [ - "windows-sys 0.48.0", - ] - --[[package]] --name = "anyhow" --version = "1.0.65" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "98161a4e3e2184da77bb14f02184cdd111e83bbbcc9979dfee3c44b9a85f5602" -- --[[package]] --name = "assert-json-diff" --version = "2.0.2" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "47e4f2b81832e72834d7518d8487a0396a28cc408186a2e8854c0f98011faf12" --dependencies = [ -- "serde", -- "serde_json", --] -- --[[package]] --name = "async-channel" --version = "1.7.1" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "e14485364214912d3b19cc3435dde4df66065127f05fa0d75c712f36f12c2f28" --dependencies = [ -- "concurrent-queue", -- "event-listener", -- "futures-core", --] -- - [[package]] - name = "async-trait" - version = "0.1.57" -@@ -354,7 +327,7 @@ version = "0.63.0" - source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "36d860121800b2a9a94f9b5604b332d5cffb234ce17609ea479d723dbc9d3885" - dependencies = [ -- "bitflags", -+ "bitflags 1.3.2", - "cexpr", - "clang-sys", - "lazy_static", -@@ -382,6 +355,12 @@ version = "1.3.2" - source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "bef38d45163c2f1dde094a7dfd33ccf595c92905c8f8f4fdc18d06fb1037718a" - -+[[package]] -+name = "bitflags" -+version = "2.8.0" -+source = "registry+https://github.com/rust-lang/crates.io-index" -+checksum = "8f68f53c83ab957f72c32642f3868eec03eb974d1fb82e453128456482613d36" -+ - [[package]] - name = "block-buffer" - version = "0.10.3" -@@ -412,12 +391,6 @@ dependencies = [ - "bytes", - ] - --[[package]] --name = "cache-padded" --version = "1.2.0" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "c1db59621ec70f09c5e9b597b220c7a2b43611f4710dc03ceb8748637775692c" -- - [[package]] - name = "cc" - version = "1.0.73" -@@ -509,15 +482,6 @@ dependencies = [ - "vcpkg", - ] - --[[package]] --name = "concurrent-queue" --version = "1.2.4" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "af4780a44ab5696ea9e28294517f1fffb421a83a25af521333c838635509db9c" --dependencies = [ -- "cache-padded", --] -- - [[package]] - name = "config" - version = "0.13.3" -@@ -529,7 +493,7 @@ dependencies = [ - "nom", - "pathdiff", - "serde", -- "toml 0.5.9", -+ "toml", - ] - - [[package]] -@@ -557,25 +521,6 @@ dependencies = [ - "typenum", - ] - --[[package]] --name = "deadpool" --version = "0.9.5" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "421fe0f90f2ab22016f32a9881be5134fdd71c65298917084b0c7477cbc3856e" --dependencies = [ -- "async-trait", -- "deadpool-runtime", -- "num_cpus", -- "retain_mut", -- "tokio", --] -- --[[package]] --name = "deadpool-runtime" --version = "0.1.2" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "eaa37046cc0f6c3cc6090fbdbf73ef0b8ef4cfcc37f6befc0020f63e8cf121e1" -- - [[package]] - name = "derive_more" - version = "0.99.17" -@@ -668,18 +613,6 @@ dependencies = [ - "libc", - ] - --[[package]] --name = "error-chain" --version = "0.10.0" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "d9435d864e017c3c6afeac1654189b06cdb491cf2ff73dbf0d73b0f292f42ff8" -- --[[package]] --name = "event-listener" --version = "2.5.3" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "0206175f82b8d6bf6652ff7d71a1e27fd2e4efde587fd368662814d6ec1d9ce0" -- - [[package]] - name = "fastrand" - version = "1.8.0" -@@ -767,21 +700,6 @@ version = "0.3.27" - source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "89d422fa3cbe3b40dca574ab087abb5bc98258ea57eea3fd6f1fa7162c778b91" - --[[package]] --name = "futures-lite" --version = "1.12.0" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "7694489acd39452c77daa48516b894c153f192c3578d5a839b62c58099fcbf48" --dependencies = [ -- "fastrand", -- "futures-core", -- "futures-io", -- "memchr", -- "parking", -- "pin-project-lite", -- "waker-fn", --] -- - [[package]] - name = "futures-macro" - version = "0.3.27" -@@ -805,12 +723,6 @@ version = "0.3.27" - source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "fd65540d33b37b16542a0438c12e6aeead10d4ac5d05bd3f805b8f35ab592879" - --[[package]] --name = "futures-timer" --version = "3.0.2" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "e64b03909df88034c26dc1547e8970b91f98bdb65165d6a4e9110d94263dbb2c" -- - [[package]] - name = "futures-util" - version = "0.3.27" -@@ -839,17 +751,6 @@ dependencies = [ - "version_check", - ] - --[[package]] --name = "getrandom" --version = "0.1.16" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "8fc3cb4d91f53b50155bdcfd23f6a4c39ae1969c2ae85982b135750cccaf5fce" --dependencies = [ -- "cfg-if", -- "libc", -- "wasi 0.9.0+wasi-snapshot-preview1", --] -- - [[package]] - name = "getrandom" - version = "0.2.7" -@@ -858,7 +759,7 @@ checksum = "4eb1a864a501629691edf6c15a593b7a51eebaa1e8468e9ddc623de7c9b58ec6" - dependencies = [ - "cfg-if", - "libc", -- "wasi 0.11.0+wasi-snapshot-preview1", -+ "wasi", - ] - - [[package]] -@@ -947,27 +848,6 @@ dependencies = [ - "pin-project-lite", - ] - --[[package]] --name = "http-types" --version = "2.12.0" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "6e9b187a72d63adbfba487f48095306ac823049cb504ee195541e91c7775f5ad" --dependencies = [ -- "anyhow", -- "async-channel", -- "base64 0.13.1", -- "futures-lite", -- "http", -- "infer", -- "pin-project-lite", -- "rand 0.7.3", -- "serde", -- "serde_json", -- "serde_qs", -- "serde_urlencoded", -- "url", --] -- - [[package]] - name = "httparse" - version = "1.8.0" -@@ -1033,12 +913,6 @@ dependencies = [ - "hashbrown", - ] - --[[package]] --name = "infer" --version = "0.2.3" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "64e9829a50b42bb782c1df523f78d332fe371b10c661e78b7a3c34b0198e9fac" -- - [[package]] - name = "instant" - version = "0.1.12" -@@ -1141,8 +1015,6 @@ dependencies = [ - "tokio", - "tss-esapi", - "uuid", -- "wiremock", -- "zmq", - ] - - [[package]] -@@ -1253,17 +1125,6 @@ version = "2.5.0" - source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "2dffe52ecf27772e601905b7522cb4ef790d2cc203488bbd0e2fe85fcb74566d" - --[[package]] --name = "metadeps" --version = "1.1.2" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "73b122901b3a675fac8cecf68dcb2f0d3036193bc861d1ac0e1c337f7d5254c2" --dependencies = [ -- "error-chain", -- "pkg-config", -- "toml 0.2.1", --] -- - [[package]] - name = "mime" - version = "0.3.16" -@@ -1284,7 +1145,7 @@ checksum = "57ee1c23c7c63b0c9250c339ffdc69255f110b298b901b9f6c82547b7b87caaf" - dependencies = [ - "libc", - "log", -- "wasi 0.11.0+wasi-snapshot-preview1", -+ "wasi", - "windows-sys 0.36.1", - ] - -@@ -1354,11 +1215,11 @@ checksum = "e82dad04139b71a90c080c8463fe0dc7902db5192d939bd0950f074d014339e1" - - [[package]] - name = "openssl" --version = "0.10.55" -+version = "0.10.70" - source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "345df152bc43501c5eb9e4654ff05f794effb78d4efe3d53abc158baddc0703d" -+checksum = "61cfb4e166a8bb8c9b55c500bc2308550148ece889be90f609377e58140f42c6" - dependencies = [ -- "bitflags", -+ "bitflags 2.8.0", - "cfg-if", - "foreign-types", - "libc", -@@ -1369,20 +1230,20 @@ dependencies = [ - - [[package]] - name = "openssl-macros" --version = "0.1.0" -+version = "0.1.1" - source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "b501e44f11665960c7e7fcf062c7d96a14ade4aa98116c004b2e37b5be7d736c" -+checksum = "a948666b637a0f465e8564c73e89d4dde00d72d4d473cc972f390fc3dcee7d9c" - dependencies = [ - "proc-macro2", - "quote", -- "syn 1.0.100", -+ "syn 2.0.25", - ] - - [[package]] - name = "openssl-sys" --version = "0.9.90" -+version = "0.9.105" - source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "374533b0e45f3a7ced10fcaeccca020e66656bc03dac384f852e4e5a7a8104a6" -+checksum = "8b22d5b84be05a8d6947c7cb71f7c849aa0f112acd4bf51c2a7c1c988ac0a9dc" - dependencies = [ - "cc", - "libc", -@@ -1390,12 +1251,6 @@ dependencies = [ - "vcpkg", - ] - --[[package]] --name = "parking" --version = "2.0.0" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "427c3892f9e783d91cc128285287e70a59e206ca452770ece88a76f7a3eddd72" -- - [[package]] - name = "parking_lot" - version = "0.12.1" -@@ -1602,19 +1457,6 @@ dependencies = [ - "proc-macro2", - ] - --[[package]] --name = "rand" --version = "0.7.3" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "6a6b1679d49b24bbfe0c803429aa1874472f50d9b363131f0e89fc356b544d03" --dependencies = [ -- "getrandom 0.1.16", -- "libc", -- "rand_chacha 0.2.2", -- "rand_core 0.5.1", -- "rand_hc", --] -- - [[package]] - name = "rand" - version = "0.8.5" -@@ -1622,18 +1464,8 @@ source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "34af8d1a0e25924bc5b7c43c079c942339d8f0a8b57c39049bef581b46327404" - dependencies = [ - "libc", -- "rand_chacha 0.3.1", -- "rand_core 0.6.4", --] -- --[[package]] --name = "rand_chacha" --version = "0.2.2" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "f4c8ed856279c9737206bf725bf36935d8666ead7aa69b52be55af369d193402" --dependencies = [ -- "ppv-lite86", -- "rand_core 0.5.1", -+ "rand_chacha", -+ "rand_core", - ] - - [[package]] -@@ -1643,16 +1475,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "e6c10a63a0fa32252be49d21e7709d4d4baf8d231c2dbce1eaa8141b9b127d88" - dependencies = [ - "ppv-lite86", -- "rand_core 0.6.4", --] -- --[[package]] --name = "rand_core" --version = "0.5.1" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "90bde5296fc891b0cef12a6d03ddccc162ce7b2aff54160af9338f8d40df6d19" --dependencies = [ -- "getrandom 0.1.16", -+ "rand_core", - ] - - [[package]] -@@ -1661,16 +1484,7 @@ version = "0.6.4" - source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "ec0be4795e2f6a28069bec0b5ff3e2ac9bafc99e6a9a7dc3547996c5c816922c" - dependencies = [ -- "getrandom 0.2.7", --] -- --[[package]] --name = "rand_hc" --version = "0.2.0" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "ca3129af7b92a17112d59ad498c6f81eaf463253766b90396d39ea7a39d6613c" --dependencies = [ -- "rand_core 0.5.1", -+ "getrandom", - ] - - [[package]] -@@ -1679,7 +1493,7 @@ version = "0.2.16" - source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "fb5a58c1855b4b6819d59012155603f0b22ad30cad752600aadfcb695265519a" - dependencies = [ -- "bitflags", -+ "bitflags 1.3.2", - ] - - [[package]] -@@ -1688,7 +1502,7 @@ version = "0.3.5" - source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "567664f262709473930a4bf9e51bf2ebf3348f2e748ccc50dea20646858f8f29" - dependencies = [ -- "bitflags", -+ "bitflags 1.3.2", - ] - - [[package]] -@@ -1742,12 +1556,6 @@ dependencies = [ - "winreg", - ] - --[[package]] --name = "retain_mut" --version = "0.1.9" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "4389f1d5789befaf6029ebd9f7dac4af7f7e3d61b69d4f30e2ac02b57e7712b0" -- - [[package]] - name = "rustc-hash" - version = "1.1.0" -@@ -1778,7 +1586,7 @@ version = "0.37.11" - source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "85597d61f83914ddeba6a47b3b8ffe7365107221c2e557ed94426489fefb5f77" - dependencies = [ -- "bitflags", -+ "bitflags 1.3.2", - "errno", - "io-lifetimes", - "libc", -@@ -1862,17 +1670,6 @@ dependencies = [ - "serde", - ] - --[[package]] --name = "serde_qs" --version = "0.8.5" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "c7715380eec75f029a4ef7de39a9200e0a63823176b759d055b613f5a87df6a6" --dependencies = [ -- "percent-encoding", -- "serde", -- "thiserror", --] -- - [[package]] - name = "serde_urlencoded" - version = "0.7.1" -@@ -2139,12 +1936,6 @@ dependencies = [ - "tracing", - ] - --[[package]] --name = "toml" --version = "0.2.1" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "736b60249cb25337bc196faa43ee12c705e426f3d55c214d73a4e7be06f92cb4" -- - [[package]] - name = "toml" - version = "0.5.9" -@@ -2268,7 +2059,6 @@ dependencies = [ - "form_urlencoded", - "idna", - "percent-encoding", -- "serde", - ] - - [[package]] -@@ -2283,7 +2073,7 @@ version = "1.3.1" - source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "5b55a3fef2a1e3b3a00ce878640918820d3c51081576ac657d23af9fc7928fdb" - dependencies = [ -- "getrandom 0.2.7", -+ "getrandom", - ] - - [[package]] -@@ -2298,12 +2088,6 @@ version = "0.9.4" - source = "registry+https://github.com/rust-lang/crates.io-index" - checksum = "49874b5167b65d7193b8aba1567f5c7d93d001cafc34600cee003eda787e483f" - --[[package]] --name = "waker-fn" --version = "1.1.0" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "9d5b2c62b4012a3e1eca5a7e077d13b3bf498c4073e33ccd58626607748ceeca" -- - [[package]] - name = "want" - version = "0.3.0" -@@ -2314,12 +2098,6 @@ dependencies = [ - "try-lock", - ] - --[[package]] --name = "wasi" --version = "0.9.0+wasi-snapshot-preview1" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "cccddf32554fecc6acb585f82a32a72e28b48f8c4c1883ddfeeeaa96f7d8e519" -- - [[package]] - name = "wasi" - version = "0.11.0+wasi-snapshot-preview1" -@@ -2562,28 +2340,6 @@ dependencies = [ - "winapi", - ] - --[[package]] --name = "wiremock" --version = "0.5.18" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "bd7b0b5b253ebc0240d6aac6dd671c495c467420577bf634d3064ae7e6fa2b4c" --dependencies = [ -- "assert-json-diff", -- "async-trait", -- "base64 0.21.0", -- "deadpool", -- "futures", -- "futures-timer", -- "http-types", -- "hyper", -- "log", -- "once_cell", -- "regex", -- "serde", -- "serde_json", -- "tokio", --] -- - [[package]] - name = "zeroize" - version = "1.5.7" -@@ -2604,25 +2360,3 @@ dependencies = [ - "syn 1.0.100", - "synstructure", - ] -- --[[package]] --name = "zmq" --version = "0.9.2" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "aad98a7a617d608cd9e1127147f630d24af07c7cd95ba1533246d96cbdd76c66" --dependencies = [ -- "bitflags", -- "libc", -- "log", -- "zmq-sys", --] -- --[[package]] --name = "zmq-sys" --version = "0.11.0" --source = "registry+https://github.com/rust-lang/crates.io-index" --checksum = "d33a2c51dde24d5b451a2ed4b488266df221a5eaee2ee519933dc46b9a9b3648" --dependencies = [ -- "libc", -- "metadeps", --] diff --git a/SOURCES/0003-rust-keylime-fix-unnecessary-qualifications.patch b/SOURCES/0003-rust-keylime-fix-unnecessary-qualifications.patch deleted file mode 100644 index ddc8cc2..0000000 --- a/SOURCES/0003-rust-keylime-fix-unnecessary-qualifications.patch +++ /dev/null @@ -1,91 +0,0 @@ -diff --git a/keylime-agent/src/crypto.rs b/keylime-agent/src/crypto.rs -index 8ec3449..aeebe34 100644 ---- a/keylime-agent/src/crypto.rs -+++ b/keylime-agent/src/crypto.rs -@@ -111,7 +111,7 @@ pub(crate) fn write_key_pair( - _ = file.write(&key.private_key_to_pem_pkcs8()?)?; - } else { - _ = file.write(&key.private_key_to_pem_pkcs8_passphrase( -- openssl::symm::Cipher::aes_256_cbc(), -+ Cipher::aes_256_cbc(), - pw.as_bytes(), - )?)?; - } -diff --git a/keylime-agent/src/errors_handler.rs b/keylime-agent/src/errors_handler.rs -index b0fa4c2..d3722d0 100644 ---- a/keylime-agent/src/errors_handler.rs -+++ b/keylime-agent/src/errors_handler.rs -@@ -379,7 +379,7 @@ mod tests { - let mut app = test::init_service( - App::new() - .wrap( -- middleware::ErrorHandlers::new() -+ ErrorHandlers::new() - .handler(http::StatusCode::NOT_FOUND, wrap_404), - ) - .app_data( -diff --git a/keylime-agent/src/main.rs b/keylime-agent/src/main.rs -index a17e3cb..beef809 100644 ---- a/keylime-agent/src/main.rs -+++ b/keylime-agent/src/main.rs -@@ -10,7 +10,6 @@ - overflowing_literals, - path_statements, - patterns_in_fns_without_body, -- private_in_public, - unconditional_recursion, - unused, - while_true, -diff --git a/keylime-agent/src/payloads.rs b/keylime-agent/src/payloads.rs -index e190e3a..fc58c43 100644 ---- a/keylime-agent/src/payloads.rs -+++ b/keylime-agent/src/payloads.rs -@@ -221,7 +221,7 @@ async fn run_encrypted_payload( - let action_file = unzipped.join("action_list"); - - if action_file.exists() { -- let action_data = std::fs::read_to_string(&action_file) -+ let action_data = fs::read_to_string(&action_file) - .expect("unable to read action_list"); - - action_data -diff --git a/keylime-agent/src/revocation.rs b/keylime-agent/src/revocation.rs -index 025a929..51edcea 100644 ---- a/keylime-agent/src/revocation.rs -+++ b/keylime-agent/src/revocation.rs -@@ -203,7 +203,7 @@ fn run_revocation_actions( - let action_file = unzipped.join("action_list"); - - if action_file.exists() { -- action_data = std::fs::read_to_string(&action_file) -+ action_data = fs::read_to_string(&action_file) - .expect("unable to read action_list"); - - let file_actions = parse_list(&action_data)?; -@@ -529,7 +529,7 @@ mod tests { - env!("CARGO_MANIFEST_DIR"), - "/tests/unzipped/test_ok.json" - ); -- let json_str = std::fs::read_to_string(json_file).unwrap(); //#[allow_ci] -+ let json_str = fs::read_to_string(json_file).unwrap(); //#[allow_ci] - let json = serde_json::from_str(&json_str).unwrap(); //#[allow_ci] - let actions_dir = - &Path::new(env!("CARGO_MANIFEST_DIR")).join("tests/actions/"); -@@ -568,7 +568,7 @@ mod tests { - env!("CARGO_MANIFEST_DIR"), - "/tests/unzipped/test_err.json" - ); -- let json_str = std::fs::read_to_string(json_file).unwrap(); //#[allow_ci] -+ let json_str = fs::read_to_string(json_file).unwrap(); //#[allow_ci] - let json = serde_json::from_str(&json_str).unwrap(); //#[allow_ci] - let actions_dir = - &Path::new(env!("CARGO_MANIFEST_DIR")).join("tests/actions/"); -@@ -603,7 +603,7 @@ mod tests { - let revocation_actions = "local_action_stand_alone.py, local_action_rev_script1.py"; - } - } -- let json_str = std::fs::read_to_string(json_file).unwrap(); //#[allow_ci] -+ let json_str = fs::read_to_string(json_file).unwrap(); //#[allow_ci] - let json = serde_json::from_str(&json_str).unwrap(); //#[allow_ci] - let actions_dir = - &Path::new(env!("CARGO_MANIFEST_DIR")).join("tests/actions/"); diff --git a/SOURCES/0004-rust-keylime-bump-tss-esapi-from-7.2.0-to-7.6.0.patch b/SOURCES/0004-rust-keylime-bump-tss-esapi-from-7.2.0-to-7.6.0.patch deleted file mode 100644 index 643eda9..0000000 --- a/SOURCES/0004-rust-keylime-bump-tss-esapi-from-7.2.0-to-7.6.0.patch +++ /dev/null @@ -1,62 +0,0 @@ -From 203caa94c6d899dc71845a3cdccebd20b226d3af Mon Sep 17 00:00:00 2001 -From: Anderson Toshiyuki Sasaki -Date: Fri, 6 Feb 2026 17:58:24 +0100 -Subject: [PATCH 4/7] Bump tss-esapi from 7.2.0 to 7.6.0 - -The tss-esapi 7.6.0 provides the create_ek_object_2 and create_ak_2 -APIs (from rust-tss-esapi PR #546) that accept -AsymmetricAlgorithmSelection with key size/curve info, which is -required for ECC key support. - -Also bump picky-asn1-der from 0.3.1 to 0.4 and picky-asn1-x509 from -0.6.1 to 0.12 to match the versions required by tss-esapi 7.6.0. - -Backported from upstream commits: -- https://github.com/keylime/rust-keylime/commit/b5c863e -- https://github.com/keylime/rust-keylime/commit/17202c6 - ---- - keylime-agent/Cargo.toml | 6 +++--- - keylime/Cargo.toml | 2 +- - 2 files changed, 4 insertions(+), 4 deletions(-) - -diff --git a/keylime-agent/Cargo.toml b/keylime-agent/Cargo.toml -index db6cec7..522be45 100644 ---- a/keylime-agent/Cargo.toml -+++ b/keylime-agent/Cargo.toml -@@ -21,8 +21,8 @@ keylime = { path = "../keylime" } - libc = "0.2.43" - log = "0.4" - openssl = "0.10.15" --picky-asn1-der = "0.3.1" --picky-asn1-x509 = "0.6.1" -+picky-asn1-der = "0.4" -+picky-asn1-x509 = "0.12" - pretty_env_logger = "0.4" - reqwest = {version = "0.11", default-features = false, features = ["json"]} - serde = "1.0.80" -@@ -31,7 +31,7 @@ serde_json = { version = "1.0", features = ["raw_value"] } - static_assertions = "1" - tempfile = "3.4.0" - tokio = {version = "1.24", features = ["rt", "sync", "macros"]} --tss-esapi = {version = "7.2.0", features = ["generate-bindings"]} -+tss-esapi = {version = "7.6.0", features = ["generate-bindings"]} - thiserror = "1.0" - uuid = {version = "1.3", features = ["v4"]} - -diff --git a/keylime/Cargo.toml b/keylime/Cargo.toml -index 61ad8b7..ddba447 100644 ---- a/keylime/Cargo.toml -+++ b/keylime/Cargo.toml -@@ -16,7 +16,7 @@ serde = "1.0.80" - serde_derive = "1.0.80" - static_assertions = "1" - thiserror = "1.0" --tss-esapi = {version = "7.2.0", features = ["generate-bindings"]} -+tss-esapi = {version = "7.6.0", features = ["generate-bindings"]} - - [dev-dependencies] - tempfile = "3.0.4" --- -2.52.0 - diff --git a/SOURCES/0005-rust-keylime-enable-non-standard-key-sizes-and-curve.patch b/SOURCES/0005-rust-keylime-enable-non-standard-key-sizes-and-curve.patch deleted file mode 100644 index 4e80b9a..0000000 --- a/SOURCES/0005-rust-keylime-enable-non-standard-key-sizes-and-curve.patch +++ /dev/null @@ -1,179 +0,0 @@ -From 9ba0459fab8852e073351614133cffdd7343fe94 Mon Sep 17 00:00:00 2001 -From: Anderson Toshiyuki Sasaki -Date: Fri, 6 Feb 2026 17:58:35 +0100 -Subject: [PATCH 5/7] Enable non-standard key sizes and curves for - EncryptionAlgorithm - -Replace the simple Rsa/Ecc variants with specific key sizes and curves: -- RSA: Rsa1024, Rsa2048, Rsa3072, Rsa4096 -- ECC: Ecc192, Ecc224, Ecc256, Ecc384, Ecc521, EccSm2 - -Add From for AsymmetricAlgorithmSelection to -support the tss-esapi 7.6.0 create_ek_object_2 and create_ak_2 APIs. - -For backwards compatibility, "rsa" maps to Rsa2048 and "ecc" maps to -Ecc256 in both parsing and display. - -Backported from upstream commit: -- https://github.com/keylime/rust-keylime/commit/2c73a2a - ---- - keylime/src/algorithms.rs | 109 ++++++++++++++++++++++++++++++++++---- - 1 file changed, 99 insertions(+), 10 deletions(-) - -diff --git a/keylime/src/algorithms.rs b/keylime/src/algorithms.rs -index c077466..fc35006 100644 ---- a/keylime/src/algorithms.rs -+++ b/keylime/src/algorithms.rs -@@ -6,8 +6,13 @@ use std::convert::TryFrom; - use std::fmt; - use thiserror::Error; - use tss_esapi::{ -- interface_types::algorithm::{ -- AsymmetricAlgorithm, HashingAlgorithm, SignatureSchemeAlgorithm, -+ abstraction::AsymmetricAlgorithmSelection, -+ interface_types::{ -+ algorithm::{ -+ AsymmetricAlgorithm, HashingAlgorithm, SignatureSchemeAlgorithm, -+ }, -+ ecc::EccCurve, -+ key_bits::RsaKeyBits, - }, - structures::{HashScheme, SignatureScheme}, - }; -@@ -87,15 +92,68 @@ impl From for MessageDigest { - - #[derive(Copy, Clone, Debug, PartialEq, Eq, Hash, Serialize, Deserialize)] - pub enum EncryptionAlgorithm { -- Rsa, -- Ecc, -+ Rsa1024, -+ Rsa2048, -+ Rsa3072, -+ Rsa4096, -+ Ecc192, -+ Ecc224, -+ Ecc256, -+ Ecc384, -+ Ecc521, -+ EccSm2, - } - - impl From for AsymmetricAlgorithm { - fn from(enc_alg: EncryptionAlgorithm) -> Self { - match enc_alg { -- EncryptionAlgorithm::Rsa => AsymmetricAlgorithm::Rsa, -- EncryptionAlgorithm::Ecc => AsymmetricAlgorithm::Ecc, -+ EncryptionAlgorithm::Rsa1024 -+ | EncryptionAlgorithm::Rsa2048 -+ | EncryptionAlgorithm::Rsa3072 -+ | EncryptionAlgorithm::Rsa4096 => AsymmetricAlgorithm::Rsa, -+ EncryptionAlgorithm::Ecc192 -+ | EncryptionAlgorithm::Ecc224 -+ | EncryptionAlgorithm::Ecc256 -+ | EncryptionAlgorithm::Ecc384 -+ | EncryptionAlgorithm::Ecc521 -+ | EncryptionAlgorithm::EccSm2 => AsymmetricAlgorithm::Ecc, -+ } -+ } -+} -+ -+impl From for AsymmetricAlgorithmSelection { -+ fn from(enc_alg: EncryptionAlgorithm) -> Self { -+ match enc_alg { -+ EncryptionAlgorithm::Rsa1024 => { -+ AsymmetricAlgorithmSelection::Rsa(RsaKeyBits::Rsa1024) -+ } -+ EncryptionAlgorithm::Rsa2048 => { -+ AsymmetricAlgorithmSelection::Rsa(RsaKeyBits::Rsa2048) -+ } -+ EncryptionAlgorithm::Rsa3072 => { -+ AsymmetricAlgorithmSelection::Rsa(RsaKeyBits::Rsa3072) -+ } -+ EncryptionAlgorithm::Rsa4096 => { -+ AsymmetricAlgorithmSelection::Rsa(RsaKeyBits::Rsa4096) -+ } -+ EncryptionAlgorithm::Ecc192 => { -+ AsymmetricAlgorithmSelection::Ecc(EccCurve::NistP192) -+ } -+ EncryptionAlgorithm::Ecc224 => { -+ AsymmetricAlgorithmSelection::Ecc(EccCurve::NistP224) -+ } -+ EncryptionAlgorithm::Ecc256 => { -+ AsymmetricAlgorithmSelection::Ecc(EccCurve::NistP256) -+ } -+ EncryptionAlgorithm::Ecc384 => { -+ AsymmetricAlgorithmSelection::Ecc(EccCurve::NistP384) -+ } -+ EncryptionAlgorithm::Ecc521 => { -+ AsymmetricAlgorithmSelection::Ecc(EccCurve::NistP521) -+ } -+ EncryptionAlgorithm::EccSm2 => { -+ AsymmetricAlgorithmSelection::Ecc(EccCurve::Sm2P256) -+ } - } - } - } -@@ -105,8 +163,18 @@ impl TryFrom<&str> for EncryptionAlgorithm { - - fn try_from(value: &str) -> Result { - match value { -- "rsa" => Ok(EncryptionAlgorithm::Rsa), -- "ecc" => Ok(EncryptionAlgorithm::Ecc), -+ "rsa" | "rsa2048" => Ok(EncryptionAlgorithm::Rsa2048), -+ "rsa1024" => Ok(EncryptionAlgorithm::Rsa1024), -+ "rsa3072" => Ok(EncryptionAlgorithm::Rsa3072), -+ "rsa4096" => Ok(EncryptionAlgorithm::Rsa4096), -+ "ecc" | "ecc256" | "ecc_nist_p256" => { -+ Ok(EncryptionAlgorithm::Ecc256) -+ } -+ "ecc192" | "ecc_nist_p192" => Ok(EncryptionAlgorithm::Ecc192), -+ "ecc224" | "ecc_nist_p224" => Ok(EncryptionAlgorithm::Ecc224), -+ "ecc384" | "ecc_nist_p384" => Ok(EncryptionAlgorithm::Ecc384), -+ "ecc521" | "ecc_nist_p521" => Ok(EncryptionAlgorithm::Ecc521), -+ "ecc_sm2" | "ecc_sm2_p256" => Ok(EncryptionAlgorithm::EccSm2), - _ => Err(AlgorithmError::Encrypt(format!( - "Encryption algorithm {value} not supported by Keylime" - ))), -@@ -117,8 +185,16 @@ impl TryFrom<&str> for EncryptionAlgorithm { - impl fmt::Display for EncryptionAlgorithm { - fn fmt(&self, f: &mut fmt::Formatter) -> fmt::Result { - let value = match self { -- EncryptionAlgorithm::Rsa => "rsa", -- EncryptionAlgorithm::Ecc => "ecc", -+ EncryptionAlgorithm::Rsa2048 => "rsa", -+ EncryptionAlgorithm::Rsa1024 => "rsa1024", -+ EncryptionAlgorithm::Rsa3072 => "rsa3072", -+ EncryptionAlgorithm::Rsa4096 => "rsa4096", -+ EncryptionAlgorithm::Ecc256 => "ecc", -+ EncryptionAlgorithm::Ecc192 => "ecc192", -+ EncryptionAlgorithm::Ecc224 => "ecc224", -+ EncryptionAlgorithm::Ecc384 => "ecc384", -+ EncryptionAlgorithm::Ecc521 => "ecc521", -+ EncryptionAlgorithm::EccSm2 => "ecc_sm2", - }; - write!(f, "{value}") - } -@@ -205,6 +281,19 @@ mod tests { - fn test_encrypt_try_from() { - let result = EncryptionAlgorithm::try_from("rsa"); - assert!(result.is_ok()); -+ assert_eq!(result.unwrap(), EncryptionAlgorithm::Rsa2048); //#[allow_ci] -+ -+ let result = EncryptionAlgorithm::try_from("ecc"); -+ assert!(result.is_ok()); -+ assert_eq!(result.unwrap(), EncryptionAlgorithm::Ecc256); //#[allow_ci] -+ -+ let result = EncryptionAlgorithm::try_from("rsa4096"); -+ assert!(result.is_ok()); -+ assert_eq!(result.unwrap(), EncryptionAlgorithm::Rsa4096); //#[allow_ci] -+ -+ let result = EncryptionAlgorithm::try_from("ecc384"); -+ assert!(result.is_ok()); -+ assert_eq!(result.unwrap(), EncryptionAlgorithm::Ecc384); //#[allow_ci] - } - #[test] - fn test_sign_tryfrom() { --- -2.52.0 - diff --git a/SOURCES/0006-rust-keylime-update-TPM-functions-for-ECC-support.patch b/SOURCES/0006-rust-keylime-update-TPM-functions-for-ECC-support.patch deleted file mode 100644 index ae13bb7..0000000 --- a/SOURCES/0006-rust-keylime-update-TPM-functions-for-ECC-support.patch +++ /dev/null @@ -1,269 +0,0 @@ -From d051c8e617f50c7200722ffb4e8d32b5a638f240 Mon Sep 17 00:00:00 2001 -From: Anderson Toshiyuki Sasaki -Date: Fri, 6 Feb 2026 01:00:00 +0100 -Subject: [PATCH 6/7] tpm: add policy auth for EK to activate crendential - -Backported from upstream commit: -- https://github.com/keylime/rust-keylime/commit/af32aa2 - ---- - keylime/src/tpm.rs | 168 +++++++++++++++++++++++++++++++++++++-------- - 1 file changed, 140 insertions(+), 28 deletions(-) - -diff --git a/keylime/src/tpm.rs b/keylime/src/tpm.rs -index 4b83e1f..9244b03 100644 ---- a/keylime/src/tpm.rs -+++ b/keylime/src/tpm.rs -@@ -16,11 +16,9 @@ use openssl::{ - - use tss_esapi::{ - abstraction::{ -- ak, -- cipher::Cipher, -- ek, -+ ak, ek, - pcr::{read_all, PcrData}, -- DefaultKey, -+ AsymmetricAlgorithmSelection, DefaultKey, - }, - attributes::session::SessionAttributesBuilder, - constants::{ -@@ -30,12 +28,13 @@ use tss_esapi::{ - AuthHandle, KeyHandle, PcrHandle, PersistentTpmHandle, TpmHandle, - }, - interface_types::{ -- algorithm::HashingAlgorithm, session_handles::AuthSession, -+ algorithm::HashingAlgorithm, -+ session_handles::{AuthSession, PolicySession}, - }, - structures::{ -- Attest, AttestInfo, Digest, DigestValues, EncryptedSecret, IdObject, -- PcrSelectionList, PcrSelectionListBuilder, PcrSlot, Signature, -- SignatureScheme, -+ Attest, AttestInfo, Digest, DigestList, DigestValues, -+ EncryptedSecret, IdObject, PcrSelectionList, PcrSelectionListBuilder, -+ PcrSlot, Signature, SignatureScheme, SymmetricDefinition, - }, - tcti_ldr::TctiNameConf, - traits::Marshall, -@@ -49,6 +48,59 @@ const TPML_DIGEST_SIZE: usize = std::mem::size_of::(); - const TPML_PCR_SELECTION_SIZE: usize = - std::mem::size_of::(); - -+// Policy digest constants from TCG EK Credential Profile for TPM Family 2.0 -+// Level 0 Version 2.5 Revision 2, Section B.6 -+ -+// Policy A (PolicySecret(ENDORSEMENT)) for SHA-384 -+const POLICY_A_SHA384: [u8; 48] = [ -+ 0x8b, 0xbf, 0x22, 0x66, 0x53, 0x7c, 0x17, 0x1c, 0xb5, 0x6e, 0x40, 0x3c, -+ 0x4d, 0xc1, 0xd4, 0xb6, 0x4f, 0x43, 0x26, 0x11, 0xdc, 0x38, 0x6e, 0x6f, -+ 0x53, 0x20, 0x50, 0xc3, 0x27, 0x8c, 0x93, 0x0e, 0x14, 0x3e, 0x8b, 0xb1, -+ 0x13, 0x38, 0x24, 0xcc, 0xb4, 0x31, 0x05, 0x38, 0x71, 0xc6, 0xdb, 0x53, -+]; -+ -+// Policy A (PolicySecret(ENDORSEMENT)) for SHA-512 -+const POLICY_A_SHA512: [u8; 64] = [ -+ 0x1e, 0x3b, 0x76, 0x50, 0x2c, 0x8a, 0x14, 0x25, 0xaa, 0x0b, 0x7b, 0x3f, -+ 0xc6, 0x46, 0xa1, 0xb0, 0xfa, 0xe0, 0x63, 0xb0, 0x3b, 0x53, 0x68, 0xf9, -+ 0xc4, 0xcd, 0xde, 0xca, 0xff, 0x08, 0x91, 0xdd, 0x68, 0x2b, 0xac, 0x1a, -+ 0x85, 0xd4, 0xd8, 0x32, 0xb7, 0x81, 0xea, 0x45, 0x19, 0x15, 0xde, 0x5f, -+ 0xc5, 0xbf, 0x0d, 0xc4, 0xa1, 0x91, 0x7c, 0xd4, 0x2f, 0xa0, 0x41, 0xe3, -+ 0xf9, 0x98, 0xe0, 0xee, -+]; -+ -+// Policy A (PolicySecret(ENDORSEMENT)) for SM3-256 -+const POLICY_A_SM3_256: [u8; 32] = [ -+ 0xc6, 0x7f, 0x7d, 0x35, 0xf6, 0x6f, 0x3b, 0xec, 0x13, 0xc8, 0x9f, 0xe8, -+ 0x98, 0x92, 0x1c, 0x65, 0x1b, 0x0c, 0xb5, 0xa3, 0x8a, 0x92, 0x69, 0x0a, -+ 0x62, 0xa4, 0x3c, 0x00, 0x12, 0xe4, 0xfb, 0x8b, -+]; -+ -+// Policy C (PolicyOr(PolicyA, PolicyB)) for SHA-384 -+const POLICY_C_SHA384: [u8; 48] = [ -+ 0xd6, 0x03, 0x2c, 0xe6, 0x1f, 0x2f, 0xb3, 0xc2, 0x40, 0xeb, 0x3c, 0xf6, -+ 0xa3, 0x32, 0x37, 0xef, 0x2b, 0x6a, 0x16, 0xf4, 0x29, 0x3c, 0x22, 0xb4, -+ 0x55, 0xe2, 0x61, 0xcf, 0xfd, 0x21, 0x7a, 0xd5, 0xb4, 0x94, 0x7c, 0x2d, -+ 0x73, 0xe6, 0x30, 0x05, 0xee, 0xd2, 0xdc, 0x2b, 0x35, 0x93, 0xd1, 0x65, -+]; -+ -+// Policy C (PolicyOr(PolicyA, PolicyB)) for SHA-512 -+const POLICY_C_SHA512: [u8; 64] = [ -+ 0x58, 0x9e, 0xe1, 0xe1, 0x46, 0x54, 0x47, 0x16, 0xe8, 0xde, 0xaf, 0xe6, -+ 0xdb, 0x24, 0x7b, 0x01, 0xb8, 0x1e, 0x9f, 0x9c, 0x7d, 0xd1, 0x6b, 0x81, -+ 0x4a, 0xa1, 0x59, 0x13, 0x87, 0x49, 0x10, 0x5f, 0xba, 0x53, 0x88, 0xdd, -+ 0x1d, 0xea, 0x70, 0x2f, 0x35, 0x24, 0x0c, 0x18, 0x49, 0x33, 0x12, 0x1e, -+ 0x2c, 0x61, 0xb8, 0xf5, 0x0d, 0x3e, 0xf9, 0x13, 0x93, 0xa4, 0x9a, 0x38, -+ 0xc3, 0xf7, 0x3f, 0xc8, -+]; -+ -+// Policy C (PolicyOr(PolicyA, PolicyB)) for SM3-256 -+const POLICY_C_SM3_256: [u8; 32] = [ -+ 0x2d, 0x4e, 0x81, 0x57, 0x8c, 0x35, 0x31, 0xd9, 0xbd, 0x1c, 0xdd, 0x7d, -+ 0x02, 0xba, 0x29, 0x8d, 0x56, 0x99, 0xa3, 0xe3, 0x9f, 0xc3, 0x55, 0x1b, -+ 0xfe, 0xff, 0xcf, 0x13, 0x2b, 0x49, 0xe1, 0x1d, -+]; -+ - #[derive(Error, Debug)] - pub enum TpmError { - #[error("TSS2 Error: {err:?}, kind: {kind:?}, {message}")] -@@ -153,9 +205,9 @@ impl Context { - let key_handle = match handle { - Some(v) => { - if v.is_empty() { -- ek::create_ek_object( -+ ek::create_ek_object_2( - &mut self.inner, -- alg.into(), -+ Into::::into(alg), - DefaultKey, - )? - } else { -@@ -168,12 +220,16 @@ impl Context { - .into() - } - } -- None => { -- ek::create_ek_object(&mut self.inner, alg.into(), DefaultKey)? -- } -+ None => ek::create_ek_object_2( -+ &mut self.inner, -+ Into::::into(alg), -+ DefaultKey, -+ )?, - }; -- let cert = match ek::retrieve_ek_pubcert(&mut self.inner, alg.into()) -- { -+ let cert = match ek::retrieve_ek_pubcert( -+ &mut self.inner, -+ Into::::into(alg), -+ ) { - Ok(v) => Some(v), - Err(_) => { - warn!("No EK certificate found in TPM NVRAM"); -@@ -194,11 +250,13 @@ impl Context { - handle: KeyHandle, - hash_alg: HashAlgorithm, - sign_alg: SignAlgorithm, -+ key_alg: EncryptionAlgorithm, - ) -> Result { -- let ak = ak::create_ak( -+ let ak = ak::create_ak_2( - &mut self.inner, - handle, - hash_alg.into(), -+ Into::::into(key_alg), - sign_alg.into(), - None, - DefaultKey, -@@ -228,14 +286,16 @@ impl Context { - fn create_empty_session( - &mut self, - ses_type: SessionType, -+ symmetric: SymmetricDefinition, -+ hash_alg: HashingAlgorithm, - ) -> Result { - let session = self.inner.start_auth_session( - None, - None, - None, - ses_type, -- Cipher::aes_128_cfb().try_into()?, -- HashingAlgorithm::Sha256, -+ symmetric, -+ hash_alg, - )?; - let (ses_attrs, ses_attrs_mask) = SessionAttributesBuilder::new() - .with_encrypt(true) -@@ -258,12 +318,49 @@ impl Context { - ) -> Result { - let (credential, secret) = parse_cred_and_secret(keyblob)?; - -- let ek_auth = self.create_empty_session(SessionType::Policy)?; -+ // Read EK public info to determine hash and symmetric algorithms -+ let (ek_public, _, _) = self.inner.read_public(ek)?; -+ let ek_hash_alg = ek_public.name_hashing_algorithm(); -+ let ek_symmetric: SymmetricDefinition = ek_public -+ .symmetric_algorithm() -+ .map(Into::into) -+ .unwrap_or(SymmetricDefinition::AES_128_CFB); //#[allow_ci] -+ -+ // Build policy digests for PolicyOr (needed for ECC EKs and -+ // non-default hash algorithms) -+ let mut policy_digests = DigestList::new(); -+ match ek_hash_alg { -+ HashingAlgorithm::Sha384 => { -+ policy_digests -+ .add(Digest::try_from(POLICY_A_SHA384.as_slice())?)?; -+ policy_digests -+ .add(Digest::try_from(POLICY_C_SHA384.as_slice())?)?; -+ } -+ HashingAlgorithm::Sha512 => { -+ policy_digests -+ .add(Digest::try_from(POLICY_A_SHA512.as_slice())?)?; -+ policy_digests -+ .add(Digest::try_from(POLICY_C_SHA512.as_slice())?)?; -+ } -+ HashingAlgorithm::Sm3_256 => { -+ policy_digests -+ .add(Digest::try_from(POLICY_A_SM3_256.as_slice())?)?; -+ policy_digests -+ .add(Digest::try_from(POLICY_C_SM3_256.as_slice())?)?; -+ } -+ _ => {} -+ } -+ -+ let ek_auth = self.create_empty_session( -+ SessionType::Policy, -+ ek_symmetric, -+ ek_hash_alg, -+ )?; - - // We authorize ses2 with PolicySecret(ENDORSEMENT) as per PolicyA - let _ = self.inner.execute_with_nullauth_session(|context| { - context.policy_secret( -- ek_auth.try_into()?, -+ PolicySession::try_from(ek_auth)?, - AuthHandle::Endorsement, - Default::default(), - Default::default(), -@@ -272,14 +369,29 @@ impl Context { - ) - })?; - -- self.inner -- .execute_with_sessions( -- (Some(AuthSession::Password), Some(ek_auth), None), -- |context| { -- context.activate_credential(ak, ek, credential, secret) -- }, -- ) -- .map_err(TpmError::from) -+ // Apply PolicyOr if needed (for ECC EKs and non-default hash algs) -+ // PolicyOR does not require authorization; use -+ // execute_without_session to ensure no extra sessions with -+ // encrypt/decrypt attributes are passed to Esys_PolicyOR. -+ if !policy_digests.is_empty() { -+ self.inner.execute_without_session(|ctx| { -+ ctx.policy_or( -+ PolicySession::try_from(ek_auth)?, -+ policy_digests.clone(), -+ ) -+ })?; -+ } -+ -+ let result = self.inner.execute_with_sessions( -+ (Some(AuthSession::Password), Some(ek_auth), None), -+ |context| { -+ context.activate_credential(ak, ek, credential, secret) -+ }, -+ )?; -+ -+ self.inner.clear_sessions(); -+ -+ Ok(result) - } - - // This function extends Pcr16 with the digest, then creates a PcrList --- -2.52.0 - diff --git a/SOURCES/0007-rust-keylime-pass-encryption-algorithm-to-create_ak.patch b/SOURCES/0007-rust-keylime-pass-encryption-algorithm-to-create_ak.patch deleted file mode 100644 index 88d6f6a..0000000 --- a/SOURCES/0007-rust-keylime-pass-encryption-algorithm-to-create_ak.patch +++ /dev/null @@ -1,54 +0,0 @@ -From 05a0c158a3d9ec1179a0b4539c28f048d1be5724 Mon Sep 17 00:00:00 2001 -From: Anderson Toshiyuki Sasaki -Date: Fri, 6 Feb 2026 01:00:00 +0100 -Subject: [PATCH 7/7] Pass encryption_alg to create AK - ---- - keylime-agent/src/common.rs | 1 + - keylime-agent/src/main.rs | 4 +++- - 2 files changed, 4 insertions(+), 1 deletion(-) - -diff --git a/keylime-agent/src/common.rs b/keylime-agent/src/common.rs -index 226bed3..a5f9975 100644 ---- a/keylime-agent/src/common.rs -+++ b/keylime-agent/src/common.rs -@@ -333,6 +333,7 @@ mod tests { - ek_result.key_handle, - tpm_hash_alg, - tpm_signing_alg, -+ tpm_encryption_alg, - )?; - - let agent_data_test = AgentData::create( -diff --git a/keylime-agent/src/main.rs b/keylime-agent/src/main.rs -index beef809..35c0c52 100644 ---- a/keylime-agent/src/main.rs -+++ b/keylime-agent/src/main.rs -@@ -363,6 +363,7 @@ async fn main() -> Result<()> { - ek_result.key_handle, - tpm_hash_alg, - tpm_signing_alg, -+ tpm_encryption_alg, - )?; - let ak_handle = ctx.load_ak(ek_result.key_handle, &new_ak)?; - (ak_handle, new_ak) -@@ -848,6 +849,7 @@ mod testing { - ek_result.key_handle, - tpm_hash_alg, - tpm_signing_alg, -+ tpm_encryption_alg, - )?; - let ak_handle = ctx.load_ak(ek_result.key_handle, &ak_result)?; - let ak_tpm2b_pub = -@@ -914,7 +916,7 @@ mod testing { - payload_tx, - revocation_tx, - hash_alg: keylime::algorithms::HashAlgorithm::Sha256, -- enc_alg: keylime::algorithms::EncryptionAlgorithm::Rsa, -+ enc_alg: keylime::algorithms::EncryptionAlgorithm::Rsa2048, - sign_alg: keylime::algorithms::SignAlgorithm::RsaSsa, - agent_uuid: test_config.agent.uuid, - allow_payload_revocation_actions: test_config --- -2.52.0 - diff --git a/SOURCES/0008-rust-keylime-bump-pretty-env-logger.patch b/SOURCES/0008-rust-keylime-bump-pretty-env-logger.patch deleted file mode 100644 index 6cc875a..0000000 --- a/SOURCES/0008-rust-keylime-bump-pretty-env-logger.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/keylime-agent/Cargo.toml b/keylime-agent/Cargo.toml -index 522be45..f77cf6c 100644 ---- a/keylime-agent/Cargo.toml -+++ b/keylime-agent/Cargo.toml -@@ -23,7 +23,7 @@ log = "0.4" - openssl = "0.10.15" - picky-asn1-der = "0.4" - picky-asn1-x509 = "0.12" --pretty_env_logger = "0.4" -+pretty_env_logger = "0.5" - reqwest = {version = "0.11", default-features = false, features = ["json"]} - serde = "1.0.80" - serde_derive = "1.0.80" diff --git a/SPECS/keylime-agent-rust.spec b/SPECS/keylime-agent-rust.spec deleted file mode 100644 index b167bdb..0000000 --- a/SPECS/keylime-agent-rust.spec +++ /dev/null @@ -1,444 +0,0 @@ -# keylime-agent-rust.spec -# Generated by rust2rpm 20 - -%bcond_without check - -%global crate keylime_agent - -# RHEL: Use bundled deps as it doesn't ship Rust libraries -%global bundled_rust_deps 1 - -Name: keylime-agent-rust -Version: 0.2.2 -Release: 5%{?dist} -Summary: Rust agent for Keylime - -# Upstream license specification: Apache-2.0 -# -# The build dependencies have the following licenses: -# -# 0BSD or MIT or ASL 2.0 -# ASL 2.0 -# ASL 2.0 or Boost -# ASL 2.0 or MIT -# ASL 2.0 with exceptions -# BSD -# MIT -# MIT or ASL 2.0 -# MIT or ASL 2.0 or zlib -# MIT or zlib or ASL 2.0 -# Unlicense or MIT -# zlib or ASL 2.0 or MIT -# -License: ASL 2.0 and BSD and MIT -URL: https://github.com/keylime/rust-keylime/ -# The source tarball is downloaded using the following commands: -# spectool -g keylime-agent-rust.spec -Source0: %{url}/archive/refs/tags/v%{version}.tar.gz -# The vendor tarball is created using cargo-vendor-filterer to remove Windows -# related files (https://github.com/cgwalters/cargo-vendor-filterer) -# tar xf rust-keylime-%%{version}.tar.gz -# cd rust-keylime-%%{version} -# cargo vendor-filterer --platform x86_64-unknown-linux-gnu \ -# --platform powerpc64le-unknown-linux-gnu \ -# --platform aarch64-unknown-linux-gnu \ -# --platform i686-unknown-linux-gnu \ -# --platform s390x-unknown-linux-gnu \ -# --exclude-crate-path "libloading#tests" -# tar jcf rust-keylime-%%{version}-vendor.tar.xz vendor -Source1: rust-keylime-%{version}-vendor.tar.xz -# Drop dependencies and adjust the features -Patch0: 0001-rust-keylime-adjust-features.patch -# Update openssl to version 0.10.70 to fix CVE-2025-24898 -Patch1: 0002-rust-keylime-openssl-0.10.70.patch -# Fix unnecessary qualification warnings -Patch2: 0003-rust-keylime-fix-unnecessary-qualifications.patch -# Bump tss-esapi from 7.2.0 to 7.6.0 for ECC key support -# Backported from upstream commits -# https://github.com/keylime/rust-keylime/commit/b5c863e -# https://github.com/keylime/rust-keylime/commit/17202c6 -Patch3: 0004-rust-keylime-bump-tss-esapi-from-7.2.0-to-7.6.0.patch -# Enable non-standard key sizes and curves for EncryptionAlgorithm -# Backported from upstream commits -# https://github.com/keylime/rust-keylime/commit/2c73a2a -Patch4: 0005-rust-keylime-enable-non-standard-key-sizes-and-curve.patch -# Update TPM functions for ECC support (EK/AK creation, credential activation) -# Backported from upstream commits -# https://github.com/keylime/rust-keylime/commit/af32aa2 -Patch5: 0006-rust-keylime-update-TPM-functions-for-ECC-support.patch -# Pass encryption algorithm to create_ak -Patch6: 0007-rust-keylime-pass-encryption-algorithm-to-create_ak.patch -# Bump pretty-env-logger to version 0.5 -# Backported from upstream commit: -# https://github.com/keylime/rust-keylime/commit/fbe6a03 -Patch7: 0008-rust-keylime-bump-pretty-env-logger.patch - -ExclusiveArch: %{rust_arches} - -Requires: tpm2-tss - -# The keylime-base package provides the configuration file from the python -# implementation which ca be used for the rust implementation. It is available -# from Fedora 36 -Requires: keylime-base -Requires: util-linux-core - -BuildRequires: clang -BuildRequires: git-core -BuildRequires: libarchive-devel -BuildRequires: openssl-devel -BuildRequires: rust-toolset -BuildRequires: systemd -BuildRequires: tpm2-tss-devel - -# Virtual Provides to support swapping between Python and Rust implementation -Provides: keylime-agent -Conflicts: keylime-agent - -Provides: bundled(crate(actix-codec)) = 0.5.2 -Provides: bundled(crate(actix-http)) = 3.11.2 -Provides: bundled(crate(actix-macros)) = 0.2.4 -Provides: bundled(crate(actix-router)) = 0.5.3 -Provides: bundled(crate(actix-rt)) = 2.11.0 -Provides: bundled(crate(actix-server)) = 2.6.0 -Provides: bundled(crate(actix-service)) = 2.0.3 -Provides: bundled(crate(actix-tls)) = 3.5.0 -Provides: bundled(crate(actix-utils)) = 3.0.1 -Provides: bundled(crate(actix-web)) = 4.12.1 -Provides: bundled(crate(actix-web-codegen)) = 4.3.0 -Provides: bundled(crate(aho-corasick)) = 1.1.4 -Provides: bundled(crate(anstream)) = 0.6.21 -Provides: bundled(crate(anstyle)) = 1.0.13 -Provides: bundled(crate(anstyle-parse)) = 0.2.7 -Provides: bundled(crate(anstyle-query)) = 1.1.5 -Provides: bundled(crate(async-trait)) = 0.1.89 -Provides: bundled(crate(autocfg)) = 1.5.0 -Provides: bundled(crate(base64)) = 0.21.7 -Provides: bundled(crate(bindgen)) = 0.66.1 -Provides: bundled(crate(bitfield)) = 0.14.0 -Provides: bundled(crate(bitflags)) = 2.10.0 -Provides: bundled(crate(block-buffer)) = 0.10.4 -Provides: bundled(crate(bytes)) = 1.11.1 -Provides: bundled(crate(bytestring)) = 1.5.0 -Provides: bundled(crate(cc)) = 1.2.55 -Provides: bundled(crate(cexpr)) = 0.6.0 -Provides: bundled(crate(cfg-if)) = 1.0.4 -Provides: bundled(crate(clang-sys)) = 1.8.1 -Provides: bundled(crate(clap)) = 4.5.57 -Provides: bundled(crate(clap_builder)) = 4.5.57 -Provides: bundled(crate(clap_derive)) = 4.5.55 -Provides: bundled(crate(clap_lex)) = 0.7.7 -Provides: bundled(crate(colorchoice)) = 1.0.4 -Provides: bundled(crate(compress-tools)) = 0.12.4 -Provides: bundled(crate(config)) = 0.13.4 -Provides: bundled(crate(convert_case)) = 0.10.0 -Provides: bundled(crate(cpufeatures)) = 0.2.17 -Provides: bundled(crate(crypto-common)) = 0.1.7 -Provides: bundled(crate(deranged)) = 0.5.6 -Provides: bundled(crate(derive_more)) = 0.99.20 -Provides: bundled(crate(derive_more)) = 2.1.1 -Provides: bundled(crate(derive_more-impl)) = 2.1.1 -Provides: bundled(crate(digest)) = 0.10.7 -Provides: bundled(crate(displaydoc)) = 0.2.5 -Provides: bundled(crate(either)) = 1.15.0 -Provides: bundled(crate(encoding_rs)) = 0.8.35 -Provides: bundled(crate(enumflags2)) = 0.7.12 -Provides: bundled(crate(enumflags2_derive)) = 0.7.12 -Provides: bundled(crate(env_logger)) = 0.10.2 -Provides: bundled(crate(equivalent)) = 1.0.2 -Provides: bundled(crate(errno)) = 0.3.14 -Provides: bundled(crate(fastrand)) = 2.3.0 -Provides: bundled(crate(find-msvc-tools)) = 0.1.9 -Provides: bundled(crate(fnv)) = 1.0.7 -Provides: bundled(crate(foldhash)) = 0.1.5 -Provides: bundled(crate(foreign-types)) = 0.3.2 -Provides: bundled(crate(foreign-types-shared)) = 0.1.1 -Provides: bundled(crate(form_urlencoded)) = 1.2.2 -Provides: bundled(crate(futures)) = 0.3.31 -Provides: bundled(crate(futures-channel)) = 0.3.31 -Provides: bundled(crate(futures-core)) = 0.3.31 -Provides: bundled(crate(futures-executor)) = 0.3.31 -Provides: bundled(crate(futures-io)) = 0.3.31 -Provides: bundled(crate(futures-macro)) = 0.3.31 -Provides: bundled(crate(futures-sink)) = 0.3.31 -Provides: bundled(crate(futures-task)) = 0.3.31 -Provides: bundled(crate(futures-util)) = 0.3.31 -Provides: bundled(crate(generic-array)) = 0.14.7 -Provides: bundled(crate(getrandom)) = 0.2.17 -Provides: bundled(crate(getrandom)) = 0.3.4 -Provides: bundled(crate(getrandom)) = 0.4.1 -Provides: bundled(crate(glob)) = 0.3.3 -Provides: bundled(crate(h2)) = 0.3.27 -Provides: bundled(crate(hashbrown)) = 0.16.1 -Provides: bundled(crate(heck)) = 0.5.0 -Provides: bundled(crate(hex)) = 0.4.3 -Provides: bundled(crate(home)) = 0.5.12 -Provides: bundled(crate(hostname-validator)) = 1.1.1 -Provides: bundled(crate(http)) = 0.2.12 -Provides: bundled(crate(http-body)) = 0.4.6 -Provides: bundled(crate(httparse)) = 1.10.1 -Provides: bundled(crate(httpdate)) = 1.0.3 -Provides: bundled(crate(humantime)) = 2.3.0 -Provides: bundled(crate(hyper)) = 0.14.32 -Provides: bundled(crate(icu_collections)) = 2.1.1 -Provides: bundled(crate(icu_locale_core)) = 2.1.1 -Provides: bundled(crate(icu_normalizer)) = 2.1.1 -Provides: bundled(crate(icu_normalizer_data)) = 2.1.1 -Provides: bundled(crate(icu_properties)) = 2.1.2 -Provides: bundled(crate(icu_properties_data)) = 2.1.2 -Provides: bundled(crate(icu_provider)) = 2.1.1 -Provides: bundled(crate(idna)) = 1.1.0 -Provides: bundled(crate(idna_adapter)) = 1.2.1 -Provides: bundled(crate(impl-more)) = 0.1.9 -Provides: bundled(crate(indexmap)) = 2.13.0 -Provides: bundled(crate(ipnet)) = 2.11.0 -Provides: bundled(crate(is-terminal)) = 0.4.17 -Provides: bundled(crate(is_terminal_polyfill)) = 1.70.2 -Provides: bundled(crate(itoa)) = 1.0.17 -Provides: bundled(crate(language-tags)) = 0.3.2 -Provides: bundled(crate(lazy_static)) = 1.5.0 -Provides: bundled(crate(lazycell)) = 1.3.0 -Provides: bundled(crate(libc)) = 0.2.181 -Provides: bundled(crate(libloading)) = 0.8.9 -Provides: bundled(crate(linux-raw-sys)) = 0.4.15 -Provides: bundled(crate(linux-raw-sys)) = 0.11.0 -Provides: bundled(crate(litemap)) = 0.8.1 -Provides: bundled(crate(local-waker)) = 0.1.4 -Provides: bundled(crate(lock_api)) = 0.4.14 -Provides: bundled(crate(log)) = 0.4.29 -Provides: bundled(crate(mbox)) = 0.7.1 -Provides: bundled(crate(memchr)) = 2.8.0 -Provides: bundled(crate(mime)) = 0.3.17 -Provides: bundled(crate(minimal-lexical)) = 0.2.1 -Provides: bundled(crate(mio)) = 1.1.1 -Provides: bundled(crate(nom)) = 7.1.3 -Provides: bundled(crate(num-conv)) = 0.2.0 -Provides: bundled(crate(num-derive)) = 0.4.2 -Provides: bundled(crate(num-traits)) = 0.2.19 -Provides: bundled(crate(oid)) = 0.2.1 -Provides: bundled(crate(once_cell)) = 1.21.3 -Provides: bundled(crate(openssl)) = 0.10.75 -Provides: bundled(crate(openssl-macros)) = 0.1.1 -Provides: bundled(crate(openssl-sys)) = 0.9.111 -Provides: bundled(crate(parking_lot)) = 0.12.5 -Provides: bundled(crate(parking_lot_core)) = 0.9.12 -Provides: bundled(crate(pathdiff)) = 0.2.3 -Provides: bundled(crate(peeking_take_while)) = 0.1.2 -Provides: bundled(crate(percent-encoding)) = 2.3.2 -Provides: bundled(crate(pest)) = 2.8.6 -Provides: bundled(crate(pest_derive)) = 2.8.6 -Provides: bundled(crate(pest_generator)) = 2.8.6 -Provides: bundled(crate(pest_meta)) = 2.8.6 -Provides: bundled(crate(picky-asn1)) = 0.8.0 -Provides: bundled(crate(picky-asn1-der)) = 0.4.1 -Provides: bundled(crate(picky-asn1-x509)) = 0.12.0 -Provides: bundled(crate(pin-project-lite)) = 0.2.16 -Provides: bundled(crate(pin-utils)) = 0.1.0 -Provides: bundled(crate(pkg-config)) = 0.3.32 -Provides: bundled(crate(potential_utf)) = 0.1.4 -Provides: bundled(crate(powerfmt)) = 0.2.0 -Provides: bundled(crate(pretty_env_logger)) = 0.5.0 -Provides: bundled(crate(prettyplease)) = 0.2.37 -Provides: bundled(crate(proc-macro2)) = 1.0.106 -Provides: bundled(crate(quote)) = 1.0.44 -Provides: bundled(crate(regex)) = 1.12.3 -Provides: bundled(crate(regex-automata)) = 0.4.14 -Provides: bundled(crate(regex-lite)) = 0.1.9 -Provides: bundled(crate(regex-syntax)) = 0.8.9 -Provides: bundled(crate(reqwest)) = 0.11.27 -Provides: bundled(crate(rustc-hash)) = 1.1.0 -Provides: bundled(crate(rustc_version)) = 0.4.1 -Provides: bundled(crate(rustix)) = 0.38.44 -Provides: bundled(crate(rustix)) = 1.1.3 -Provides: bundled(crate(ryu)) = 1.0.23 -Provides: bundled(crate(scopeguard)) = 1.2.0 -Provides: bundled(crate(semver)) = 1.0.27 -Provides: bundled(crate(serde)) = 1.0.228 -Provides: bundled(crate(serde_bytes)) = 0.11.19 -Provides: bundled(crate(serde_core)) = 1.0.228 -Provides: bundled(crate(serde_derive)) = 1.0.228 -Provides: bundled(crate(serde_json)) = 1.0.149 -Provides: bundled(crate(serde_urlencoded)) = 0.7.1 -Provides: bundled(crate(sha2)) = 0.10.9 -Provides: bundled(crate(shlex)) = 1.3.0 -Provides: bundled(crate(signal-hook)) = 0.3.18 -Provides: bundled(crate(signal-hook-registry)) = 1.4.8 -Provides: bundled(crate(slab)) = 0.4.12 -Provides: bundled(crate(smallvec)) = 1.15.1 -Provides: bundled(crate(socket2)) = 0.5.10 -Provides: bundled(crate(socket2)) = 0.6.2 -Provides: bundled(crate(stable_deref_trait)) = 1.2.1 -Provides: bundled(crate(static_assertions)) = 1.1.0 -Provides: bundled(crate(strsim)) = 0.11.1 -Provides: bundled(crate(syn)) = 2.0.114 -Provides: bundled(crate(sync_wrapper)) = 0.1.2 -Provides: bundled(crate(synstructure)) = 0.13.2 -Provides: bundled(crate(target-lexicon)) = 0.12.16 -Provides: bundled(crate(tempfile)) = 3.25.0 -Provides: bundled(crate(termcolor)) = 1.4.1 -Provides: bundled(crate(thiserror)) = 1.0.69 -Provides: bundled(crate(thiserror-impl)) = 1.0.69 -Provides: bundled(crate(time)) = 0.3.47 -Provides: bundled(crate(time-core)) = 0.1.8 -Provides: bundled(crate(time-macros)) = 0.2.27 -Provides: bundled(crate(tinystr)) = 0.8.2 -Provides: bundled(crate(tokio)) = 1.49.0 -Provides: bundled(crate(tokio-macros)) = 2.6.0 -Provides: bundled(crate(tokio-openssl)) = 0.6.5 -Provides: bundled(crate(tokio-util)) = 0.7.18 -Provides: bundled(crate(toml)) = 0.5.11 -Provides: bundled(crate(tower-service)) = 0.3.3 -Provides: bundled(crate(tracing)) = 0.1.44 -Provides: bundled(crate(tracing-attributes)) = 0.1.31 -Provides: bundled(crate(tracing-core)) = 0.1.36 -Provides: bundled(crate(try-lock)) = 0.2.5 -Provides: bundled(crate(tss-esapi)) = 7.6.0 -Provides: bundled(crate(tss-esapi-sys)) = 0.5.0 -Provides: bundled(crate(typenum)) = 1.19.0 -Provides: bundled(crate(ucd-trie)) = 0.1.7 -Provides: bundled(crate(unicode-ident)) = 1.0.23 -Provides: bundled(crate(unicode-segmentation)) = 1.12.0 -Provides: bundled(crate(unicode-xid)) = 0.2.6 -Provides: bundled(crate(url)) = 2.5.8 -Provides: bundled(crate(utf8_iter)) = 1.0.4 -Provides: bundled(crate(utf8parse)) = 0.2.2 -Provides: bundled(crate(uuid)) = 1.20.0 -Provides: bundled(crate(vcpkg)) = 0.2.15 -Provides: bundled(crate(version_check)) = 0.9.5 -Provides: bundled(crate(want)) = 0.3.1 -Provides: bundled(crate(which)) = 4.4.2 -Provides: bundled(crate(writeable)) = 0.6.2 -Provides: bundled(crate(yoke)) = 0.8.1 -Provides: bundled(crate(yoke-derive)) = 0.8.1 -Provides: bundled(crate(zerofrom)) = 0.1.6 -Provides: bundled(crate(zerofrom-derive)) = 0.1.6 -Provides: bundled(crate(zeroize)) = 1.8.2 -Provides: bundled(crate(zeroize_derive)) = 1.4.3 -Provides: bundled(crate(zerotrie)) = 0.2.3 -Provides: bundled(crate(zerovec)) = 0.11.5 -Provides: bundled(crate(zerovec-derive)) = 0.11.2 -Provides: bundled(crate(zmij)) = 1.0.20 - -%description -Rust agent for Keylime - -%prep -%autosetup -S git -N -n rust-keylime-%{version} -a1 -%cargo_prep -V 1 -%autopatch -p1 - -# Sometimes Rust sources start with #![...] attributes, and "smart" editors think -# it's a shebang and make them executable. Then brp-mangle-shebangs gets upset... -find -name '*.rs' -type f -perm /111 -exec chmod -v -x '{}' '+' - -%build -%cargo_build -n - -%install -mkdir -p %{buildroot}/%{_sharedstatedir}/keylime -mkdir -p --mode=0700 %{buildroot}/%{_rundir}/keylime -mkdir -p --mode=0700 %{buildroot}/%{_sysconfdir}/keylime -mkdir -p --mode=0700 %{buildroot}/%{_sysconfdir}/keylime/agent.conf.d - -install -Dpm 400 keylime-agent.conf \ - %{buildroot}%{_sysconfdir}/keylime/agent.conf - -install -Dpm 644 ./dist/systemd/system/keylime_agent.service \ - %{buildroot}%{_unitdir}/keylime_agent.service - -install -Dpm 644 ./dist/systemd/system/var-lib-keylime-secure.mount \ - %{buildroot}%{_unitdir}/var-lib-keylime-secure.mount - -# Setting up the agent to use keylime:keylime user/group after dropping privileges. -cat > %{buildroot}/%{_sysconfdir}/keylime/agent.conf.d/001-run_as.conf << EOF -[agent] -run_as = "keylime:keylime" -EOF - -install -Dpm 0755 \ - -t %{buildroot}%{_bindir} \ - ./target/release/keylime_agent -install -Dpm 0755 \ - -t %{buildroot}%{_bindir} \ - ./target/release/keylime_ima_emulator - -%posttrans -chmod 500 %{_sysconfdir}/keylime/agent.conf.d -chmod 400 %{_sysconfdir}/keylime/agent.conf.d/*.conf -chmod 500 %{_sysconfdir}/keylime -chown -R keylime:keylime %{_sysconfdir}/keylime - -%preun -%systemd_preun keylime_agent.service -%systemd_preun var-lib-keylime-secure.mount - -%postun -%systemd_postun_with_restart keylime_agent.service -%systemd_postun_with_restart var-lib-keylime-secure.mount - -%files -%license LICENSE -%doc README.md -%attr(500,keylime,keylime) %dir %{_sysconfdir}/keylime -%attr(500,keylime,keylime) %dir %{_sysconfdir}/keylime/agent.conf.d -%config(noreplace) %attr(400,keylime,keylime) %{_sysconfdir}/keylime/agent.conf.d/001-run_as.conf -%config(noreplace) %attr(400,keylime,keylime) %{_sysconfdir}/keylime/agent.conf -%{_unitdir}/keylime_agent.service -%{_unitdir}/var-lib-keylime-secure.mount -%attr(700,keylime,keylime) %dir %{_rundir}/keylime -%attr(700,keylime,keylime) %{_sharedstatedir}/keylime -%{_bindir}/keylime_agent -%{_bindir}/keylime_ima_emulator - -%if %{with check} -%check -%cargo_test -%endif - -%changelog -* Wed Feb 11 2026 Anderson Toshiyuki Sasaki - 0.2.2-5 -- Enable attestation with TPM ECC keys - Resolves: RHEL-118148 - -* Tue Feb 03 2026 Sergio Correia - 0.2.2-4 -- Remove /usr/libexec/keylime/ - Resolves: RHEL-145712 - -* Mon Jan 12 2026 Anderson Toshiyuki Sasaki - 0.2.2-3 -- Fix cargo_build macro usage - -* Fri Feb 07 2025 Anderson Toshiyuki Sasaki - 0.2.2-2 -- Update openssl crate to version 0.10.70 to fix CVE-2025-24898 - -* Thu Jul 20 2023 Anderson Toshiyuki Sasaki - 0.2.2-1 -- Update to upstream release 0.2.2 - -* Thu May 25 2023 Anderson Toshiyuki Sasaki - 0.2.1-1 -- Update to upstream release 0.2.1 - -* Wed Sep 21 2022 Anderson Toshiyuki Sasaki - 0.1.0-1 -- Update to upstream release 0.1.0 - -* Thu Aug 25 2022 Anderson Toshiyuki Sasaki - 0.1.0~20220805git0185093-1 -- Update to upstream commit 0186093 - -* Mon Jul 18 2022 Anderson Toshiyuki Sasaki - 0.1.0~20220603gitaed51c7-4 -- Remove vendored source files for non-Linux or unsupported platforms - -* Fri Jul 08 2022 Anderson Toshiyuki Sasaki - 0.1.0~20220603gitaed51c7-3 -- Add support for hash algorithms other than SHA-1 to the IMA emulator - -* Mon Jul 04 2022 Anderson Toshiyuki Sasaki - 0.1.0~20220603gitaed51c7-2 -- Use classic release instead of autorelease macro -- Use classic changelog instead of autochangelog macro - -* Mon Jul 04 2022 Anderson Toshiyuki Sasaki - 0.1.0~20220603gitaed51c7-2 -- Backport patch to load configuration file only once - -* Fri Jul 01 2022 Anderson Toshiyuki Sasaki - 0.1.0~20220603gitaed51c7-2 -- Set supplementary groups when dropping privileges -- Show more descriptive error messages on missing files errors -- Create /usr/libexec/keylime directory - -* Tue Jun 21 2022 Sergio Correia - 0.1.0~20220603gitaed51c7-1 -- Add keylime-agent-rust to RHEL 9 diff --git a/keylime-agent-rust.spec b/keylime-agent-rust.spec new file mode 100644 index 0000000..efa0d32 --- /dev/null +++ b/keylime-agent-rust.spec @@ -0,0 +1,391 @@ +## START: Set by rpmautospec +## (rpmautospec version 0.8.1) +## RPMAUTOSPEC: autorelease, autochangelog +%define autorelease(e:s:pb:n) %{?-p:0.}%{lua: + release_number = 3; + base_release_number = tonumber(rpm.expand("%{?-b*}%{!?-b:1}")); + print(release_number + base_release_number - 1); +}%{?-e:.%{-e*}}%{?-s:.%{-s*}}%{!?-n:%{?dist}} +## END: Set by rpmautospec + +# keylime-agent-rust.spec +# Generated by rust2rpm 20 + +%bcond_without check + +%global crate keylime_agent + +%if 0%{?rhel} +# RHEL: Use bundled deps as it doesn't ship Rust libraries +%global bundled_rust_deps 1 +%global __brp_mangle_shebangs_exclude_from ^/usr/src/debug/.*$ +%else +# Fedora: Use only system Rust libraries +%global bundled_rust_deps 0 +%endif + +Name: keylime-agent-rust +Version: 0.2.9 +Release: %{?autorelease}%{!?autorelease:1%{?dist}} +Summary: The Keylime agent + +# Upstream license specification: Apache-2.0 +# +# The build dependencies have the following licenses: +# +# 0BSD or MIT or ASL 2.0 +# ASL 2.0 +# ASL 2.0 or Boost +# ASL 2.0 or MIT +# ASL 2.0 with exceptions +# BSD +# MIT +# MIT or ASL 2.0 +# MIT or ASL 2.0 or zlib +# MIT or zlib or ASL 2.0 +# Unlicense or MIT +# zlib or ASL 2.0 or MIT +# +License: (Apache-2.0 OR MIT) AND BSD-3-Clause AND (MIT OR Apache-2.0) AND Unicode-DFS-2016 AND (Apache-2.0 OR Apache-2.0 WITH LLVM-exception OR MIT) AND (Apache-2.0 OR BSL-1.0) AND (Apache-2.0 OR MIT) AND (Apache-2.0 OR MIT OR Zlib) AND Apache-2.0 WITH LLVM-exception AND ISC AND MIT AND (MIT OR Unlicense) +URL: https://github.com/keylime/rust-keylime/ +# The source tarball is downloaded using the following commands: +# spectool -g keylime-agent-rust.spec +Source0: %{url}/archive/refs/tags/v%{version}.tar.gz +# The vendor tarball is created using cargo-vendor-filterer to remove Windows +# related files (https://github.com/cgwalters/cargo-vendor-filterer) +# tar xf rust-keylime-%%{version}.tar.zstd +# cd rust-keylime-%%{version} +# cargo vendor-filterer --platform x86_64-unknown-linux-gnu \ +# --platform powerpc64le-unknown-linux-gnu \ +# --platform aarch64-unknown-linux-gnu \ +# --platform i686-unknown-linux-gnu \ +# --platform s390x-unknown-linux-gnu \ +# --exclude-crate-path "libloading#tests" \ +# --prefix=vendor --format=tar.zstd +# Rename the vendor.tar.zstd tarball to rust-keylime-%%{version}-vendor.tar.zstd +Source1: rust-keylime-%{version}-vendor.tar.zstd +## (0-99) General patches +# Drop completely the legacy-python-actions feature +Patch1: 0001-rust-keylime-metadata.patch +# Do not require /usr/libexec/keylime to be present +Patch2: 0002-rust-keylime-do-not-require-usr-libexec.patch +# Use the correct registrar port when TLS is enabled +# Backported from https://github.com/keylime/rust-keylime/pull/1204 +Patch3: 0003-rust-keylime-registrar-tls-port.patch + +## (100-199) Patches for building from system Rust libraries (Fedora) +## (200+) Patches for building from vendored Rust libraries (RHEL) + +ExclusiveArch: %{rust_arches} + +BuildRequires: clang +BuildRequires: git-core +BuildRequires: openssl-devel +BuildRequires: systemd +BuildRequires: tpm2-tss-devel +%if 0%{?bundled_rust_deps} +BuildRequires: rust-toolset +%else +BuildRequires: rust-packaging >= 21-2 +%endif + +Requires: tpm2-tss +Requires: util-linux-core + +# The keylime-base package provides the keylime user creation. It is available +# from Fedora 36 +%if 0%{?fedora} >= 36 || 0%{?rhel} >= 9 +Requires: keylime-base +%endif + +# Requires common files from exact same release +Requires: keylime-agent-rust-common = %{version}-%{release} +# Require the IMA emulator +Requires: keylime-agent-rust-ima-emulator%{?_isa} = %{version}-%{release} + +# Virtual Provides to support swapping between pull and push model agents +Provides: keylime-agent = %{version}-%{release} + +%description +The Keylime agent + +#=============================================================================== + +%package common +Summary: Common files for Keylime agent +License: (Apache-2.0 OR MIT) AND BSD-3-Clause AND (MIT OR Apache-2.0) AND Unicode-DFS-2016 AND (Apache-2.0 OR Apache-2.0 WITH LLVM-exception OR MIT) AND (Apache-2.0 OR BSL-1.0) AND (Apache-2.0 OR MIT) AND (Apache-2.0 OR MIT OR Zlib) AND Apache-2.0 WITH LLVM-exception AND ISC AND MIT AND (MIT OR Unlicense) +BuildArch: noarch + +# The old unsplit keylime-agent-rust shipped files now owned by -common +# (agent.conf, config dirs). This conflict ensures the split packages are +# removed on downgrade to avoid file conflicts. +Conflicts: keylime-agent-rust < 0.2.9 + +%description common +Common files for the Keylime agent in both push and pull models + +#=============================================================================== + +%package push +Summary: The Keylime agent for push model deployment +License: (Apache-2.0 OR MIT) AND BSD-3-Clause AND (MIT OR Apache-2.0) AND Unicode-DFS-2016 AND (Apache-2.0 OR Apache-2.0 WITH LLVM-exception OR MIT) AND (Apache-2.0 OR BSL-1.0) AND (Apache-2.0 OR MIT) AND (Apache-2.0 OR MIT OR Zlib) AND Apache-2.0 WITH LLVM-exception AND ISC AND MIT AND (MIT OR Unlicense) +Requires: tpm2-tss +Requires: util-linux-core + +# Requires common files from exact same release +Requires: keylime-agent-rust-common = %{version}-%{release} +# Require the IMA emulator +Requires: keylime-agent-rust-ima-emulator%{?_isa} = %{version}-%{release} + +# The keylime-base package provides the keylime user creation. It is available +# from Fedora 36 +%if 0%{?fedora} >= 36 || 0%{?rhel} >= 9 +Requires: keylime-base +%endif + +# Virtual Provides to support swapping between pull and push model agents +Provides: keylime-agent = %{version}-%{release} + +%description push +The Keylime agent for push model deployment + +#=============================================================================== + +%package ima-emulator +Summary: The Keylime IMA emulator +License: (Apache-2.0 OR MIT) AND BSD-3-Clause AND (MIT OR Apache-2.0) AND Unicode-DFS-2016 AND (Apache-2.0 OR Apache-2.0 WITH LLVM-exception OR MIT) AND (Apache-2.0 OR BSL-1.0) AND (Apache-2.0 OR MIT) AND (Apache-2.0 OR MIT OR Zlib) AND Apache-2.0 WITH LLVM-exception AND ISC AND MIT AND (MIT OR Unlicense) +Requires: tpm2-tss + +# Requires common files from exact same release +Requires: keylime-agent-rust-common = %{version}-%{release} + +# The keylime-base package provides the keylime user creation. It is available +# from Fedora 36 +%if 0%{?fedora} >= 36 || 0%{?rhel} >= 9 +Requires: keylime-base +%endif + +# The old unsplit keylime-agent-rust shipped keylime_ima_emulator binary. +# This conflict ensures the split packages are removed on downgrade to avoid +# file conflicts. +Conflicts: keylime-agent-rust < 0.2.9 + +Provides: keylime-ima-emulator = %{version}-%{release} + +%description ima-emulator +The Keylime IMA emulator for testing with emulated TPM + +#=============================================================================== + +%prep +%autosetup -S git -n rust-keylime-%{version} -N %{?bundled_rust_deps:-a1} +%autopatch -M 99 -p1 +%if 0%{?bundled_rust_deps} +# Source1 is vendored dependencies +%cargo_prep -v vendor +# Add back the line below if patches are added (do not forget the '%') +# autopatch -m 200 -p1 +%else +# Add back the line below if patches are added (do not forget the '%') +# autopatch -m 100 -M 199 -p1 +%cargo_prep +%generate_buildrequires +%cargo_generate_buildrequires +%endif + +%build +%cargo_build +%cargo_license_summary +%{cargo_license} > LICENSE.dependencies +%if 0%{?bundled_rust_deps} +%cargo_vendor_manifest +%endif + +%install + +mkdir -p %{buildroot}/%{_sharedstatedir}/keylime +mkdir -p --mode=0700 %{buildroot}/%{_rundir}/keylime +mkdir -p --mode=0700 %{buildroot}/%{_sysconfdir}/keylime +mkdir -p --mode=0700 %{buildroot}/%{_sysconfdir}/keylime/agent.conf.d + +install -Dpm 400 keylime-agent.conf \ + %{buildroot}%{_sysconfdir}/keylime/agent.conf + +install -Dpm 644 ./dist/systemd/system/keylime_agent.service \ + %{buildroot}%{_unitdir}/keylime_agent.service + +install -Dpm 644 ./dist/systemd/system/var-lib-keylime-secure.mount \ + %{buildroot}%{_unitdir}/var-lib-keylime-secure.mount + +install -Dpm 644 ./dist/systemd/system/keylime_push_model_agent.service \ + %{buildroot}%{_unitdir}/keylime_push_model_agent.service + +# Setting up the agent to use keylime:keylime user/group after dropping privileges. +cat > %{buildroot}/%{_sysconfdir}/keylime/agent.conf.d/001-run_as.conf << EOF +[agent] +run_as = "keylime:keylime" +EOF + +install -Dpm 0755 \ + -t %{buildroot}%{_bindir} \ + ./target/release/keylime_agent +install -Dpm 0755 \ + -t %{buildroot}%{_bindir} \ + ./target/release/keylime_ima_emulator +install -Dpm 0755 \ + -t %{buildroot}%{_bindir} \ + ./target/release/keylime_push_model_agent + +%posttrans +chmod 500 %{_sysconfdir}/keylime/agent.conf.d +chmod 400 %{_sysconfdir}/keylime/agent.conf.d/*.conf +chmod 500 %{_sysconfdir}/keylime +chown -R keylime:keylime %{_sysconfdir}/keylime + +%preun +%systemd_preun keylime_push_model_agent.service +%systemd_preun keylime_agent.service +%systemd_preun var-lib-keylime-secure.mount + +%postun +%systemd_postun_with_restart keylime_push_model_agent.service +%systemd_postun_with_restart keylime_agent.service +%systemd_postun_with_restart var-lib-keylime-secure.mount + +%files common +%license LICENSE +%doc README.md +%attr(500,keylime,keylime) %dir %{_sysconfdir}/keylime +%attr(500,keylime,keylime) %dir %{_sysconfdir}/keylime/agent.conf.d +%config(noreplace) %attr(400,keylime,keylime) %{_sysconfdir}/keylime/agent.conf.d/001-run_as.conf +%config(noreplace) %attr(400,keylime,keylime) %{_sysconfdir}/keylime/agent.conf +%attr(700,keylime,keylime) %dir %{_rundir}/keylime +%attr(700,keylime,keylime) %{_sharedstatedir}/keylime + +%files +%license LICENSE.dependencies +%if 0%{?bundled_rust_deps} +%license cargo-vendor.txt +%endif +%{_unitdir}/keylime_agent.service +%{_unitdir}/var-lib-keylime-secure.mount +%{_bindir}/keylime_agent + +%files push +%license LICENSE.dependencies +%if 0%{?bundled_rust_deps} +%license cargo-vendor.txt +%endif +%{_unitdir}/keylime_push_model_agent.service +%{_bindir}/keylime_push_model_agent + +%files ima-emulator +%license LICENSE.dependencies +%if 0%{?bundled_rust_deps} +%license cargo-vendor.txt +%endif +%{_bindir}/keylime_ima_emulator + +%if %{with check} +%check +%cargo_test +%endif + +%changelog +## START: Generated by rpmautospec +* Thu May 07 2026 Anderson Toshiyuki Sasaki - 0.2.9-3 +- Fix upgrade to not remove keylime-agent-rust + +* Wed Apr 01 2026 Anderson Toshiyuki Sasaki - 0.2.9-2 +- Use correct port when registrar TLS is enabled + +* Mon Feb 16 2026 Anderson Toshiyuki Sasaki - 0.2.9-1 +- Update to upstream version 0.2.9 + +* Mon Oct 06 2025 Sergio Correia - 0.2.7-4 +- Enable ECC attestation + +* Mon Sep 29 2025 Sergio Correia - 0.2.7-3 +- Enable different key sizes and curves for EK and AK + +* Fri Feb 07 2025 Anderson Toshiyuki Sasaki - 0.2.7-2 +- Update openssl crate to version 0.10.70 + +* Wed Jan 22 2025 Anderson Toshiyuki Sasaki - 0.2.7-1 +- Update to upstream version 0.2.7 + +* Tue Oct 29 2024 Troy Dawson - 0.2.5-4 +- Bump release for October 2024 mass rebuild: + +* Mon Jun 24 2024 Karel Srot - 0.2.5-3 +- Add RHEL-10 gating.yaml + +* Mon Jun 24 2024 Troy Dawson - 0.2.5-2 +- Bump release for June 2024 mass rebuild + +* Wed Jun 12 2024 Anderson Toshiyuki Sasaki - 0.2.5-1 +- Update to upstream version 0.2.5 + +* Tue May 14 2024 Karel Srot - 0.2.2-4 +- tests: Update CI test plan for C10S + +* Fri Jul 14 2023 Anderson Toshiyuki Sasaki - 0.2.2-2 +- Update test plan + +* Thu Jul 13 2023 Anderson Toshiyuki Sasaki - 0.2.2-1 +- Update to upstream version 0.2.2 + +* Thu Jul 13 2023 Anderson Toshiyuki Sasaki - 0.2.1-5 +- Migrate to SPDX License + +* Fri Jun 02 2023 Yaakov Selkowitz - 0.2.1-4 +- Require keylime-base on RHEL + +* Fri Jun 02 2023 Anderson Toshiyuki Sasaki - 0.2.1-3 +- Add BuildRequires on clang regardless of the target + +* Thu Apr 27 2023 Anderson Toshiyuki Sasaki - 0.2.1-2 +- Enable Fedora CI tests + +* Thu Apr 27 2023 Anderson Toshiyuki Sasaki - 0.2.1-1 +- Update to upstream version 0.2.1 + +* Wed Feb 15 2023 Yaakov Selkowitz - 0.1.0-4 +- Fix RHEL build with tpm2-tss v4 + +* Thu Jan 19 2023 Fedora Release Engineering - 0.1.0-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Tue Nov 22 2022 Yaakov Selkowitz - 0.1.0-2 +- Fix build with bundled dependencies + +* Wed Nov 02 2022 Anderson Toshiyuki Sasaki - 0.1.0-1 +- Update to upstream version 0.1.0 + +* Fri Aug 05 2022 Daiki Ueno - 0.1.0~20220603gitaed51c7-3 +- Fix version requirement for clap to avoid FTBFS in Fedora + +* Thu Jul 21 2022 Fedora Release Engineering - 0.1.0~20220603gitaed51c7-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Fri Jul 01 2022 Anderson Toshiyuki Sasaki - 0.1.0~20220603gitaed51c7-1 +- Update, add services, and drop dependencies +- Update to aed51c7 commit +- Require keylime-base on Fedora >= 36 +- Update clap dependency +- Drop rustc-serialize and flate2 dependencies +- Make wiremock an optional dependency and re-enable tests +- Fix serialization of structures in quotes to fix issue on big-endian +- Add systemd services for the agent and secure mount +- BuildRequire systemd for the services +- Use more descriptive error messages on missing files errors +- Set supplementary groups when dropping privileges +- Create /usr/libexec/keylime directory + +* Fri Jun 03 2022 Daiki Ueno - 0.1.0~20220602gitc98e381-1 +- Update to latest snapshot to bump dependencies + +* Mon Jan 24 2022 Daiki Ueno - 0.1.0~20211110gitd5a3191-1 +- Initial package + +## END: Generated by rpmautospec diff --git a/sources b/sources new file mode 100644 index 0000000..d471e81 --- /dev/null +++ b/sources @@ -0,0 +1,2 @@ +SHA512 (rust-keylime-0.2.9-vendor.tar.zstd) = 86899e58a2ba7a26c29ba15b6c7bca51dd4500ade8468a2f1697e6b23feb2e2be2e5323b8fc351e3c04aa970dfb07b909c07349f822358b33d439a40f4ab596b +SHA512 (v0.2.9.tar.gz) = f51ce187462278328a96a05dfb6315167bd3be154cb1c9ad933de33d246e696b25bb487071a824ed552456016bb64154e89f5f8a0dc76b94eb896be0f4787e9f