From: David Woodhouse <dwmw2@infradead.org>
To: James Morris <jmorris@namei.org>
Cc: David Howells <dhowells@redhat.com>,
mcgrof@gmail.com, zohar@linux.vnet.ibm.com,
linux-kernel@vger.kernel.org,
linux-security-module@vger.kernel.org
Subject: Re: [GIT PULL] MODSIGN: Use PKCS#7 for module signatures [ver #7a]
Date: Wed, 12 Aug 2015 10:50:41 +0100 [thread overview]
Message-ID: <1439373041.3100.64.camel@infradead.org> (raw)
In-Reply-To: <alpine.LRH.2.20.1508121921190.13410@namei.org>
[-- Attachment #1: Type: text/plain, Size: 2335 bytes --]
On Wed, 2015-08-12 at 19:27 +1000, James Morris wrote:
>
> Yep:
>
> # CONFIG_MODULE_SIG_SHA512 is not set
> CONFIG_MODULE_SIG_HASH="sha1"
> CONFIG_MODULE_SIG_KEY="signing_key.pem"
> # CONFIG_MODULE_COMPRESS is not set
Can I have the full config please? Not that I understand how anything
else would really make much difference.
> >
> > At the very end of kernel/Makefile, in the rule for
> signing_key.x509,
> > please could you add an 'echo $(X509_DEP)' before the call to
> > extract_certs? That ought to be correctly depending on the
> > signing_key.pem file.
>
> $ make
> CHK include/config/kernel.release
> CHK include/generated/uapi/linux/version.h
> CHK include/generated/utsrelease.h
> CHK include/generated/bounds.h
> CHK include/generated/timeconst.h
> CHK include/generated/asm-offsets.h
> CALL scripts/checksyscalls.sh
> CHK include/generated/compile.h
> echo
>
> EXTRACT_CERTS signing_key.pem
>
> i.e. nothing.
Odd.
What are $(MODULE_SIG_KEY_FILENAME) and $(MODULE_SIG_KEY_SRCPREFIX) ?
I'm going to have to make another pot of coffee if I'm going to debug
the config_filename thing today... :)
I'm scared to start thinking this way but... what version of 'make' are
you using? If your precise .config doesn't help, is there any chance I
can log into an affected box to poke at it?
I've also been testing David's tree (commit f81977b46 precisely), so
perhaps I should also try *precisely* the merged tree you're looking
at. Again, not that I can imagine anything that would make this
difference.
> >
> > There's magic here to work out the precise dependency, since it
> might
> > be a filename relative to either the build tree or the source tree.
> > I'll take another look and work out how it copes in the case where
> the
> > file doesn't exist yet... is this an out-of-tree build?
> >
>
> Nope, but try a make mrproper first (as I have) and see if you get
> the same result.
I've been testing that, both in-tree and out-of-tree. I can't make it
*fail* to set X509_DEP and thus depend correctly on the signing_key.pem
file.
--
David Woodhouse Open Source Technology Centre
David.Woodhouse@intel.com Intel Corporation
[-- Attachment #2: smime.p7s --]
[-- Type: application/x-pkcs7-signature, Size: 5691 bytes --]
next prev parent reply other threads:[~2015-08-12 9:50 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-08-11 20:03 David Howells
2015-08-12 4:20 ` James Morris
2015-08-12 7:07 ` David Woodhouse
2015-08-12 9:08 ` James Morris
2015-08-12 9:12 ` David Woodhouse
2015-08-12 9:27 ` James Morris
2015-08-12 9:50 ` David Woodhouse [this message]
2015-08-12 10:08 ` James Morris
2015-08-12 10:23 ` David Woodhouse
2015-08-12 10:30 ` James Morris
2015-08-12 10:40 ` James Morris
2015-08-12 10:59 ` David Woodhouse
2015-08-12 15:51 ` David Howells
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1439373041.3100.64.camel@infradead.org \
--to=dwmw2@infradead.org \
--cc=dhowells@redhat.com \
--cc=jmorris@namei.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=mcgrof@gmail.com \
--cc=zohar@linux.vnet.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®