Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

modsign: Use extract-cert to process CONFIG_SYSTEM_TRUSTED_KEYS

Fix up the dependencies somewhat too, while we're at it.

Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
Signed-off-by: David Howells <dhowells@redhat.com>

authored by

David Woodhouse and committed by
David Howells
770f2b98 84706caa

+17 -14
+12 -13
kernel/Makefile
··· 166 166 # 167 167 ############################################################################### 168 168 169 - 170 169 ifeq ($(CONFIG_SYSTEM_TRUSTED_KEYRING),y) 171 170 172 171 $(eval $(call config_filename,SYSTEM_TRUSTED_KEYS)) 173 172 174 - SIGNING_X509-$(CONFIG_MODULE_SIG) += signing_key.x509 173 + # GCC doesn't include .incbin files in -MD generated dependencies (PR#66871) 174 + $(obj)/system_certificates.o: $(obj)/x509_certificate_list 175 175 176 - kernel/system_certificates.o: $(obj)/x509_certificate_list 176 + # Cope with signing_key.x509 existing in $(srctree) not $(objtree) 177 + AFLAGS_system_certificates.o := -I$(srctree) 177 178 178 - quiet_cmd_x509certs = CERTS $(SIGNING_X509-y) $(patsubst "%",%,$(2)) 179 - cmd_x509certs = ( cat $(SIGNING_X509-y) /dev/null; \ 180 - awk '/-----BEGIN CERTIFICATE-----/{flag=1;next}/-----END CERTIFICATE-----/{flag=0}flag' $(2) /dev/null | base64 -d ) > $@ || ( rm $@; exit 1) 179 + quiet_cmd_extract_certs = EXTRACT_CERTS $(patsubst "%",%,$(2)) 180 + cmd_extract_certs = scripts/extract-cert $(2) $@ || ( rm $@; exit 1) 181 181 182 - targets += $(obj)/x509_certificate_list 183 - $(obj)/x509_certificate_list: $(SIGNING_X509-y) include/config/system/trusted/keys.h $(wildcard include/config/module/sig.h) $(SYSTEM_TRUSTED_KEYS_SRCPREFIX)$(SYSTEM_TRUSTED_KEYS_FILENAME) 184 - $(call if_changed,x509certs,$(SYSTEM_TRUSTED_KEYS_SRCPREFIX)$(CONFIG_SYSTEM_TRUSTED_KEYS)) 185 - 182 + targets += x509_certificate_list 183 + $(obj)/x509_certificate_list: scripts/extract-cert $(SYSTEM_TRUSTED_KEYS_SRCPREFIX)$(SYSTEM_TRUSTED_KEYS_FILENAME) FORCE 184 + $(call if_changed,extract_certs,$(SYSTEM_TRUSTED_KEYS_SRCPREFIX)$(CONFIG_SYSTEM_TRUSTED_KEYS)) 186 185 endif 187 186 188 187 clean-files := x509_certificate_list .x509.list ··· 247 248 X509_DEP := $(MODULE_SIG_KEY_SRCPREFIX)$(MODULE_SIG_KEY_FILENAME) 248 249 endif 249 250 250 - quiet_cmd_extract_der = SIGNING_CERT $(patsubst "%",%,$(2)) 251 - cmd_extract_der = scripts/extract-cert $(2) signing_key.x509 251 + # GCC PR#66871 again. 252 + $(obj)/system_certificates.o: signing_key.x509 252 253 253 254 signing_key.x509: scripts/extract-cert include/config/module/sig/key.h $(X509_DEP) 254 - $(call cmd,extract_der,$(MODULE_SIG_KEY_SRCPREFIX)$(CONFIG_MODULE_SIG_KEY)) 255 + $(call cmd,extract_certs,$(MODULE_SIG_KEY_SRCPREFIX)$(CONFIG_MODULE_SIG_KEY)) 255 256 endif
+3
kernel/system_certificates.S
··· 7 7 .globl VMLINUX_SYMBOL(system_certificate_list) 8 8 VMLINUX_SYMBOL(system_certificate_list): 9 9 __cert_list_start: 10 + #ifdef CONFIG_MODULE_SIG 11 + .incbin "signing_key.x509" 12 + #endif 10 13 .incbin "kernel/x509_certificate_list" 11 14 __cert_list_end: 12 15
+2 -1
scripts/Makefile
··· 16 16 hostprogs-$(BUILD_C_RECORDMCOUNT) += recordmcount 17 17 hostprogs-$(CONFIG_BUILDTIME_EXTABLE_SORT) += sortextable 18 18 hostprogs-$(CONFIG_ASN1) += asn1_compiler 19 - hostprogs-$(CONFIG_MODULE_SIG) += sign-file extract-cert 19 + hostprogs-$(CONFIG_MODULE_SIG) += sign-file 20 + hostprogs-$(CONFIG_SYSTEM_TRUSTED_KEYRING) += extract-cert 20 21 21 22 HOSTCFLAGS_sortextable.o = -I$(srctree)/tools/include 22 23 HOSTCFLAGS_asn1_compiler.o = -I$(srctree)/include