zipl: detect signed files and create bootmap components

Add support for parsing IPL file signatures as produced by the Linux
kernel's sign-file tool. When preparing a disk for IPL, the signatures
will be added as separate data components that can be used by the Secure
Boot firmware feature to validate the integrity of the IPL files.

Signed-off-by: Stefan Haberland <sth@linux.ibm.com>
Reviewed-by: Peter Oberparleiter <oberpar@linux.ibm.com>
Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
This commit is contained in:
Stefan Haberland
2019-03-28 14:41:07 +01:00
committed by Jan Höppner
parent 0c1a63ce5e
commit 7c7e10ed8f
4 changed files with 218 additions and 61 deletions

View File

@@ -16,6 +16,37 @@
#include "job.h"
#include "zipl.h"
#define SIGNATURE_MAGIC "~Module signature appended~\n"
#define PKCS7_FORMAT 0x01
struct signature_header {
uint8_t format;
uint8_t reserved[3];
uint32_t length;
} __attribute((packed));
typedef union {
uint64_t load_address;
uint64_t load_psw;
struct signature_header sig_head;
} component_data;
/*
* The file_signature structure and the PKEY_ID definition
* are based on linux/scripts/sign-file.c
*/
struct file_signature {
u8 algorithm;
u8 hash;
u8 id_type;
u8 signer_len;
u8 key_id_len;
u8 __pad[3];
u32 sig_len;
char magic[28];
};
#define PKEY_ID_PKCS7 0x02
int bootmap_create(struct job_data* job, disk_blockptr_t* program_table,
disk_blockptr_t *scsi_dump_sb_blockptr,