mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: David Howells <dhowells@redhat.com>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: dhowells@redhat.com, Abelardo Ricart III <aricart@memnix.com>,
	Michal Marek <mmarek@suse.cz>,
	Linux Kernel Mailing List <linux-kernel@vger.kernel.org>,
	Sedat Dilek <sedat.dilek@gmail.com>,
	keyrings@linux-nfs.org, Rusty Russell <rusty@rustcorp.com.au>,
	LSM List <linux-security-module@vger.kernel.org>,
	James Morris <james.l.morris@oracle.com>,
	Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Subject: Re: [PATCH] MODSIGN: Change default key details [ver #2]
Date: Tue, 05 May 2015 16:30:42 +0100	[thread overview]
Message-ID: <17605.1430839842@warthog.procyon.org.uk> (raw)
In-Reply-To: <CA+55aFzYjTyE7bx65K163Dy8cj05Bs_trK-k1OODhAveTMCpGQ@mail.gmail.com>

Linus Torvalds <torvalds@linux-foundation.org> wrote:

> ... 
> So the end result is that we run that "filechk_x509_list" script,
> compare the output to the old target, and update the target iff it is
> different. That would seem to be exactly what we want.

Yep.

> That said, as mentioned, the whole "X509_CERTIFICATES" thing is
> unstable, and ends up being "./signing_key.x509" or "signing_key.x509"
> depending on whether that file existed or not. That needs fixing, so
> that we get stable output. So some filtering required.

Yeah, the stability thing is a bit of an irritation.  X509_CERTIFICATES might
also include "$(srcdir)/signing_key.x509".  This is one of the things that has
given me difficulties because the source and build trees are sometimes the
same and sometimes not (and then throw in a symlink somewhere in the path...).
I was trying to use $(realpath ...) to deal with this - but that doesn't work
if the path doesn't point to an extant file:-/

Does it make sense to produce an error if the source and build trees are not
coincident and we see an x509 cert of the same filename cropping up in both?

Also X509_CERTIFICATES might hold other certs - though these shouldn't really
be seen in the build dir.  I wonder if we should enforce that to make life
easier.

David

  parent reply	other threads:[~2015-05-05 16:10 UTC|newest]

Thread overview: 44+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-04-30 13:58 David Howells
2015-04-30 14:39 ` Sedat Dilek
2015-04-30 14:50 ` David Howells
2015-04-30 17:49   ` Sedat Dilek
2015-04-30 18:00     ` Linus Torvalds
2015-05-01 21:41       ` Abelardo Ricart III
2015-05-02  4:12         ` Linus Torvalds
2015-05-02  6:57           ` Sedat Dilek
2015-05-02  9:46           ` Abelardo Ricart III
2015-05-04  1:45             ` Linus Torvalds
2015-05-04  4:42               ` Abelardo Ricart III
     [not found]                 ` <CA+55aFzYUsXHC=_RiQFBhMmDxrFT4bqNP5F0LGWUu7Hc9sXBFQ@mail.gmail.com>
2015-05-04  7:18                   ` Abelardo Ricart III
2015-05-04 21:40                   ` Abelardo Ricart III
2015-05-05 14:34                   ` David Howells
2015-05-05 22:44                     ` Abelardo Ricart III
2015-05-04 18:45               ` Linus Torvalds
2015-05-05 15:22                 ` Michal Marek
2015-05-05 15:41                   ` Linus Torvalds
2015-05-06 12:20                     ` Michal Marek
2015-05-07 11:00                     ` David Howells
2015-05-07 12:15                       ` Michal Marek
2015-05-07 12:24                         ` Michal Marek
2015-05-08 13:05                         ` David Howells
2015-05-12  8:51                           ` Michal Marek
2015-05-15 15:21                           ` David Howells
2015-05-19 14:14                           ` David Howells
2015-05-19 15:19                             ` David Woodhouse
2015-05-18 16:07                         ` David Woodhouse
2015-05-16 15:39                 ` David Woodhouse
2015-05-18 10:47                 ` David Howells
2015-05-18 11:13                   ` David Woodhouse
2015-05-19  2:14                     ` Mimi Zohar
2015-05-18 10:56                 ` David Howells
2015-05-05 14:33               ` David Howells
2015-05-05 14:43                 ` Linus Torvalds
2015-05-05 15:30                 ` David Howells [this message]
2015-05-05 14:37               ` David Howells
2015-05-20 10:17         ` David Woodhouse
2015-05-20 11:26           ` [PATCH] modsign: Use single PEM file for autogenerated key David Woodhouse
2015-05-20 14:56           ` David Howells
2015-05-20 15:18             ` David Woodhouse
2015-05-21 11:31             ` David Woodhouse
2015-05-20 10:51         ` [PATCH] MODSIGN: Change default key details [ver #2] David Howells
2015-05-20 11:08           ` David Woodhouse

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=17605.1430839842@warthog.procyon.org.uk \
    --to=dhowells@redhat.com \
    --cc=aricart@memnix.com \
    --cc=gregkh@linuxfoundation.org \
    --cc=james.l.morris@oracle.com \
    --cc=keyrings@linux-nfs.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=mmarek@suse.cz \
    --cc=rusty@rustcorp.com.au \
    --cc=sedat.dilek@gmail.com \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®