From 5efe3d3a4f8cf20b27c9e1307d51438f6bdce327 Mon Sep 17 00:00:00 2001 From: Troy Dawson Date: Thu, 15 Oct 2020 09:35:47 -0700 Subject: [PATCH] RHEL 9.0.0 Alpha bootstrap The content of this branch was automatically imported from Fedora ELN with the following as its source: https://src.fedoraproject.org/rpms/shim-unsigned-aarch64#00c45e20c28efbe238dd6b79037818606c6b6edd --- .gitignore | 4 + build | 8 ++ dbx.esl | Bin 0 -> 304 bytes fedora-ca.cer | Bin 0 -> 876 bytes noautobuild | 0 rhtest.cer | Bin 0 -> 1020 bytes shim-find-debuginfo.sh | 90 ++++++++++++++++++++ shim-unsigned-aarch64.spec | 168 +++++++++++++++++++++++++++++++++++++ sources | 1 + 9 files changed, 271 insertions(+) create mode 100755 build create mode 100644 dbx.esl create mode 100644 fedora-ca.cer create mode 100644 noautobuild create mode 100644 rhtest.cer create mode 100755 shim-find-debuginfo.sh create mode 100644 shim-unsigned-aarch64.spec create mode 100644 sources diff --git a/.gitignore b/.gitignore index e69de29..2f727bd 100644 --- a/.gitignore +++ b/.gitignore @@ -0,0 +1,4 @@ +*.tar.* +clog +*.rpm +shim-*/ diff --git a/build b/build new file mode 100755 index 0000000..210f549 --- /dev/null +++ b/build @@ -0,0 +1,8 @@ +#!/bin/bash +set -e +if [ $# -ne 1 ]; then + echo "usage: ./build " 1>&2 + exit 1 +fi +arm-koji build $1 `fedpkg giturl` + diff --git a/dbx.esl b/dbx.esl new file mode 100644 index 0000000000000000000000000000000000000000..2ea555ccebee3c3fd2a8c73a78a90af156dbcd37 GIT binary patch literal 304 zcmY!rJ95w`V3Na{m5x8nCOc~wFfxFF0g&u}@^bBtInQPouHW*EVV?fuG$rE>!SYZS z7o{{o1_qZjh)M*hhGrJjCNHNRB#f5=kCWD|- i2SbOFF$0i;3P>?)W+=nV@(!g?1|=84nKK13%mM&)^i^5_ literal 0 HcmV?d00001 diff --git a/fedora-ca.cer b/fedora-ca.cer new file mode 100644 index 0000000000000000000000000000000000000000..b81707b175f2205af35ba9903eae779db0e84069 GIT binary patch literal 876 zcmXqLV$LvVVhUKm%*4pV#L6(U?9&$mUN%mxHjlRNyo`+8tPBPUhH?fnY|No7%)+8> zsVVtIi3-7~$)!c93Qqa?B?``t26E!OhDL@)2IhulMy94FQR2KtAg(EtON0qcj7rGX zGO{u-H!<=v7&I|*F*PwVGOYXhJ*aVIjGgv(+0ZXh87;bdy33}u@~ZEUSbFwg^QIp4 zSY@t@LR_UY7Cnn)?D}$Z{-1(9hmVL?Gi?<<5;*C>0oIb8dbTPR3o47J95|%CscHF_ z)#+YJpHt2r{>h`pxL^9Jt>ylczkbIB?OfvVTX=uFCRfUP#p*qBV$~h~A04!BDv7%L zwR}^N@eLM>+NilZuD1Tbl}A@A*GCpJ-P!K3f1P&0!Cxiym0#Z}Utnh4SSjKE*I)lp zvZQbMu7f(=n{Tq}-Mq0aPG59{C%uC^UyWfjr$|mjbp17o}8U#?PMSfQlQGhW55NoiJ93z79_~W zBF2JU4{90$MkXVJdHDw`$3-&p3$3rsp1M`^zSp)d7Xx?kvfP@pN%_NPlgQp3S7w!# zq&A2rS{bXxfHT|dm}{$^H&q=<-*=Kv zkY7wsZsn)Ee=K`n&HJ))^UW)X;T-KpX53gbGv%IWNN;$hi2N^J-|Vw9OuzE5?fqx3XS&*z?&Hm;YVX`O+Q$9`soS literal 0 HcmV?d00001 diff --git a/noautobuild b/noautobuild new file mode 100644 index 0000000..e69de29 diff --git a/rhtest.cer b/rhtest.cer new file mode 100644 index 0000000000000000000000000000000000000000..7c21c7a3b6cd57a1411a65e3581cc3780ee122f2 GIT binary patch literal 1020 zcmXqLV*X*!#PnbRGZP~d6DPxWiPSSfOxrIT@Un4gwRyCC=VfGMWo0lZGvqelWMd9x zVH0Kw4K@@r5CL&Ggn4}vi;EMJGfIn7OG=6jg$x8h;_Skl&WX86MVTq-sW7!%!n{GL zDGDBmB{~Y8dC7W)$_9!cwamg&P;rHj)Z!8a=hUK-%(TkPymSR;M*}%=UPB`Ta|265 zOG6_Q<0v547>PSz?rLIGLJlHERtDxKMt%l^CPpr%CPqev^-3Z!e+?Q_j=bMpE)%b` zwrtMtM&C127csM~VVv@N-<7hKZxg?ED9>GzCBgB)aKBlP$VP2r%Y~=jAJfwnQA?Up zJJB*jBW;h?8J(|(lboIh72Ia>&}Y0RmAQ_4=kLbbA59Ww@4Nh1y?dsFwa1=@-K~j~;Km_E+iB7WMLNzpftI_;jgxWbx(Wlcvp? z`zDO1-R8o)$1{!gwcK5hogr;_Lm^|enCB+19{#MA9zP;KXrAs1$>)oi_-yXm(uxZl zqTv-xE2hgXf8q5;=vs7Ld)g5{_D>tWhb>4`mi(dd_T}1htD6^2IVQVf$0Eie!m;3e1jA{j-w`!JTbNbn)cSpll`)V9Nh`BR7>G4sSHKNY zz|X=0Orrk`_(2?DM#ldvtOm?L%0QKkGoj6cvF(QwBQJ}Dm>4J#K@tx%DP<-nmZTy_ z7BD>nBa4xtMMC80gS`9~k!{r?mValu+bPcDd(dLGNb2Wx!zB~bAGzO1weGR~e8ny+ zUj9qzSqlUER7*aO$+FAtDlfc!#?OD{kwbm{cW%XQUYDGDqi)gS(v?-`v?e_X{#4c9 zE*Gq3AByE*+b^_S-Mz!*WRpFuK@lpS(k!TX1}?2X!HCqXNKRuUuAE|%3)fdW*=zeEmUxS V(~>pkME0+~B>gS9oVRR#Jpk^#dV&A| literal 0 HcmV?d00001 diff --git a/shim-find-debuginfo.sh b/shim-find-debuginfo.sh new file mode 100755 index 0000000..7e882ff --- /dev/null +++ b/shim-find-debuginfo.sh @@ -0,0 +1,90 @@ +#!/bin/bash +# +# shim-find-debuginfo.sh +# Copyright (C) 2017 Peter Jones +# +# Distributed under terms of the GPLv3 license. +# +set -e +set -u + +mainarch=$1 && shift +if [ $# == 1 ]; then + altarch=$1 && shift +fi +if ! [ -v RPM_BUILD_ROOT ]; then + echo "RPM_BUILD_ROOT must be set" 1>&2 + exit 1 +fi + +findsource() +{ + ( + cd ${RPM_BUILD_ROOT} + find usr/src/debug/ -type d | sed "s,^,%dir /," + find usr/src/debug/ -type f | sed "s,^,/," + ) +} + +finddebug() +{ + arch=$1 && shift + declare -a dirs=() + declare -a files=() + declare -a excludes=() + + pushd ${RPM_BUILD_ROOT} >/dev/null 2>&1 + for x in $(find usr/lib/debug/ -type f -iname *.efi.debug); do + if ! [ -e "${x}" ]; then + break + fi + if [[ ${x} =~ ${arch}\.efi\.debug$ ]]; then + files[${#files[@]}]=${x} + else + excludes[${#excludes[@]}]=${x} + fi + done + for x in usr/lib/debug/.build-id/*/*.debug ; do + if ! [ -e "${x}" ]; then + break + fi + link=$(readlink "${x}") + if [[ ${link} =~ ${arch}\.efi\.debug$ ]]; then + files[${#files[@]}]=${x} + files[${#files[@]}]=${x%%.debug} + else + excludes[${#excludes[@]}]=${x} + excludes[${#excludes[@]}]=${x%%.debug} + fi + done + for x in ${files[@]} ; do + declare name=$(dirname /${x}) + while [ "${name}" != "/" ]; do + case "${name}" in + "/usr/lib/debug"|"/usr/lib"|"/usr") + ;; + *) + dirs[${#dirs[@]}]=${name} + ;; + esac + name=$(dirname ${name}) + done + done + + popd >/dev/null 2>&1 + for x in ${dirs[@]} ; do + echo "%dir ${x}" + done | sort | uniq + for x in ${files[@]} ; do + echo "/${x}" + done | sort | uniq + for x in ${excludes[@]} ; do + echo "%exclude /${x}" + done +} + +findsource > build-${mainarch}/debugsource.list +finddebug ${mainarch} > build-${mainarch}/debugfiles.list +if [ -v altarch ]; then + finddebug ${altarch} > build-${altarch}/debugfiles.list +fi diff --git a/shim-unsigned-aarch64.spec b/shim-unsigned-aarch64.spec new file mode 100644 index 0000000..c72ac24 --- /dev/null +++ b/shim-unsigned-aarch64.spec @@ -0,0 +1,168 @@ +%global pesign_vre 0.106-1 +%global gnuefi_vre 1:3.0.8-1 +%global openssl_vre 1.0.2j + +%global debug_package %{nil} +%global __debug_package 1 +%global _binaries_in_noarch_packages_terminate_build 0 +%global __debug_install_post %{SOURCE100} aa64 +%undefine _debuginfo_subpackages + +%global efidir %(eval echo $(grep ^ID= /etc/os-release | sed -e 's/^ID=//' -e 's/rhel/redhat/')) +%global shimrootdir %{_datadir}/shim/ +%global shimversiondir %{shimrootdir}/%{version}-%{release} +%global efiarch aa64 +%global shimdir %{shimversiondir}/%{efiarch} + +Name: shim-unsigned-aarch64 +Version: 15 +Release: 1%{?dist} +Summary: First-stage UEFI bootloader +ExclusiveArch: aarch64 +License: BSD +URL: https://github.com/rhboot/shim +Source0: https://github.com/rhboot/shim/releases/download/%{version}/shim-%{version}.tar.bz2 +Source1: fedora-ca.cer +# currently here's what's in our dbx: +# grub2-efi-2.00-11.fc18.x86_64: +# grubx64.efi 6ac839881e73504047c06a1aac0c4763408ecb3642783c8acf77a2d393ea5cd7 +# gcdx64.efi 065cd63bab696ad2f4732af9634d66f2c0d48f8a3134b8808750d378550be151 +# grub2-efi-2.00-11.fc19.x86_64: +# grubx64.efi 49ece9a10a9403b32c8e0c892fd9afe24a974323c96f2cc3dd63608754bf9b45 +# gcdx64.efi 99fcaa957786c155a92b40be9c981c4e4685b8c62b408cb0f6cb2df9c30b9978 +# woops. +Source2: dbx.esl + +Source100: shim-find-debuginfo.sh + +BuildRequires: gcc make +BuildRequires: elfutils-libelf-devel +BuildRequires: git openssl-devel openssl +BuildRequires: pesign >= %{pesign_vre} +BuildRequires: gnu-efi >= %{gnuefi_vre} +BuildRequires: gnu-efi-devel >= %{gnuefi_vre} + +# Shim uses OpenSSL, but cannot use the system copy as the UEFI ABI is not +# compatible with SysV (there's no red zone under UEFI) and there isn't a +# POSIX-style C library. +# BuildRequires: OpenSSL +Provides: bundled(openssl) = %{openssl_vre} + +%global desc \ +Initial UEFI bootloader that handles chaining to a trusted full \ +bootloader under secure boot environments. +%global debug_desc \ +This package provides debug information for package %{expand:%%{name}} \ +Debug information is useful when developing applications that \ +use this package or when debugging this package. + +%description +%desc + +%package debuginfo +Summary: Debug information for shim-unsigned-aarch64 +Requires: %{name}-debugsource = %{version}-%{release} +AutoReqProv: 0 +BuildArch: noarch + +%description debuginfo +%debug_desc + +%package debugsource +Summary: Debug Source for shim-unsigned +AutoReqProv: 0 +BuildArch: noarch + +%description debugsource +%debug_desc + +%prep +%autosetup -S git -n shim-%{version} +git config --unset user.email +git config --unset user.name +mkdir build-%{efiarch} + +%build +COMMITID=$(cat commit) +MAKEFLAGS="TOPDIR=.. -f ../Makefile COMMITID=${COMMITID} " +MAKEFLAGS+="EFIDIR=%{efidir} PKGNAME=shim RELEASE=%{release} " +MAKEFLAGS+="ENABLE_HTTPBOOT=true ENABLE_SHIM_HASH=true " +MAKEFLAGS+="%{_smp_mflags}" +if [ -f "%{SOURCE1}" ]; then + MAKEFLAGS="$MAKEFLAGS VENDOR_CERT_FILE=%{SOURCE1}" +fi +if [ -f "%{SOURCE2}" ]; then + MAKEFLAGS="$MAKEFLAGS VENDOR_DBX_FILE=%{SOURCE2}" +fi + +cd build-%{efiarch} +make ${MAKEFLAGS} DEFAULT_LOADER='\\\\grub%{efiarch}.efi' all +cd .. + +%install +COMMITID=$(cat commit) +MAKEFLAGS="TOPDIR=.. -f ../Makefile COMMITID=${COMMITID} " +MAKEFLAGS+="EFIDIR=%{efidir} PKGNAME=shim RELEASE=%{release} " +MAKEFLAGS+="ENABLE_HTTPBOOT=true ENABLE_SHIM_HASH=true " +if [ -f "%{SOURCE1}" ]; then + MAKEFLAGS="$MAKEFLAGS VENDOR_CERT_FILE=%{SOURCE1}" +fi +if [ -f "%{SOURCE2}" ]; then + MAKEFLAGS="$MAKEFLAGS VENDOR_DBX_FILE=%{SOURCE2}" +fi + +cd build-%{efiarch} +make ${MAKEFLAGS} \ + DEFAULT_LOADER='\\\\grub%{efiarch}.efi' \ + DESTDIR=${RPM_BUILD_ROOT} \ + install-as-data install-debuginfo install-debugsource +cd .. + +%files +%license COPYRIGHT +%dir %{shimrootdir} +%dir %{shimversiondir} +%dir %{shimdir} +%{shimdir}/*.efi +%{shimdir}/*.hash + +%files debuginfo -f build-%{efiarch}/debugfiles.list + +%files debugsource -f build-%{efiarch}/debugsource.list + +%changelog +* Thu Apr 05 2018 Peter Jones - 15-1 +- Update to shim 15 +- better checking for bad linker output +- flicker-free console if there's no error output +- improved http boot support +- better protocol re-installation +- dhcp proxy support +- tpm measurement even when verification is disabled +- REQUIRE_TPM build flag +- more reproducable builds +- measurement of everything verified through shim_verify() +- coverity and scan-build checker make targets +- misc cleanups + +* Tue Sep 19 2017 Peter Jones - 13-3 +- Actually update to the *real* 13 final. + Related: rhbz#1489604 + +* Thu Aug 31 2017 Peter Jones - 13-2 +- Actually update to 13 final. + +* Mon Aug 21 2017 Peter Jones - 13-0.1 +- Update to shim-13 test release. + +* Thu Aug 03 2017 Fedora Release Engineering - 0.9-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild + +* Thu Jul 27 2017 Fedora Release Engineering - 0.9-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + +* Sat Feb 11 2017 Fedora Release Engineering - 0.9-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + +* Thu May 12 2016 Peter Jones - - 0.9-1 +- Initial split up of -aarch64 diff --git a/sources b/sources new file mode 100644 index 0000000..697992c --- /dev/null +++ b/sources @@ -0,0 +1 @@ +SHA512 (shim-15.tar.bz2) = f7dfac774d644111431ca56da76b5575b891b0abad970b318edaede11a0d83c869728bc39cb6af3689bdb203c6826545caf8ddd3d14228831027e334963cf957