mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
Compare commits
254 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 9eea78b3ad | |||
| 0a3a556879 | |||
| aba8900074 | |||
| f5744b95db | |||
| 13d721afd3 | |||
| 90a2e6d70e | |||
| bc9f8a8100 | |||
| 2b5e7b0491 | |||
| d7c95265cd | |||
| 8751cfc409 | |||
| 01f96d30f6 | |||
| fffbd93f12 | |||
| ddcfbdc8d2 | |||
| 173fd7cdca | |||
| d14e7593cc | |||
| 1a3d0b74f7 | |||
| f6c6f0cc71 | |||
| 966e67a252 | |||
| 1c128c0d11 | |||
| a3199d58db | |||
| 659483031e | |||
| 7dc2513205 | |||
| 0748d365a6 | |||
| 94a404ed10 | |||
| ef1799f31f | |||
| 47b0960cc7 | |||
| 2288331a6f | |||
| 23e9156f43 | |||
| 8f99e7c4ea | |||
| f3bcd94524 | |||
| a2f8b19c2a | |||
| 588d720517 | |||
| cd822cb770 | |||
| b27b8e3cd3 | |||
| 7a2c5dc980 | |||
| d9e3763d1c | |||
| 6f15ed3264 | |||
| 0d2b5af007 | |||
| 9e7a8f48e8 | |||
| 98f7a0569c | |||
| 551f66282e | |||
| 3d2ba5aaed | |||
| 94942a48ab | |||
| ab8984a7a3 | |||
| 4990f643c1 | |||
| 34bef977e8 | |||
| f36c34038b | |||
| bfd0e12d22 | |||
| 1450f85ada | |||
| 2a0f1e6977 | |||
| 0f433b1142 | |||
| ab6bcad263 | |||
| e40a3e0621 | |||
| e56acf4f14 | |||
| 17977eda30 | |||
| 459a257568 | |||
| fb65b53b9b | |||
| c8d4062f73 | |||
| c8e0992814 | |||
| c0a12b29d0 | |||
| 02dded11a5 | |||
| b71279cda5 | |||
| c70477f8c6 | |||
| 9b51b8b882 | |||
| 48539596ef | |||
| cafa99774c | |||
| b5f7ac95d8 | |||
| e984b97db0 | |||
| 64d4e02b4f | |||
| 90ddef5a41 | |||
| 58ef99f76b | |||
| 43c34956fb | |||
| d7dee1b9d3 | |||
| 94a38ebc3a | |||
| 0764460eaf | |||
| 6fd02279da | |||
| 6274294bc5 | |||
| 27708026d4 | |||
| 849aa5b105 | |||
| 0be83bfbba | |||
| f8592be43d | |||
| 647ad51423 | |||
| 73f51e45a8 | |||
| bc4f455151 | |||
| b4b5e0b6aa | |||
| 9927023680 | |||
| 9b2fb1d4d2 | |||
| 689b894506 | |||
| 06a30ae529 | |||
| ed106d7f28 | |||
| 9d08fd8c7e | |||
| 7e8126704b | |||
| d96767ee45 | |||
| 63f31bf73e | |||
| 7ecfe2353f | |||
| 7bec672c7e | |||
| 5aac5deb75 | |||
| 54e016ae71 | |||
| 6b53378839 | |||
| 1266f86444 | |||
| 231c02cdeb | |||
| 454a8d9d7b | |||
| bbe92b9cd3 | |||
| 7bb41732fb | |||
| c217f6be6a | |||
| 21662d38e6 | |||
| 19f3842292 | |||
| ae0cbf00b1 | |||
| 9019c6864a | |||
| d1b61c37fa | |||
| 32b68a5fad | |||
| 55fdb17b18 | |||
| af730c79a6 | |||
| 041e6131d1 | |||
| 5a7d7e05b8 | |||
| 71b93d55ef | |||
| d2b5e1e2d6 | |||
| a3cb877c54 | |||
| 6895a71cc4 | |||
| d9034b01f1 | |||
| 488ac8c3f2 | |||
| ecf36d53c8 | |||
| 893ad920c5 | |||
| 0695c79f4e | |||
| 8837ea24cb | |||
| 65222d03b9 | |||
| 54937495e2 | |||
| 8a783b81a4 | |||
| 093da2a5a7 | |||
| b68ea5fc7d | |||
| 90c587408f | |||
| 90475fbaa5 | |||
| 07ff9e1da0 | |||
| 5637799c92 | |||
| 73c82441e7 | |||
| 6d06921276 | |||
| 2996b34ddf | |||
| e5821301f6 | |||
| f4d1874ac5 | |||
| f3428929a2 | |||
| 263d6950a1 | |||
| 8024f8e31a | |||
| 3849b29594 | |||
| 0e4d4da0e5 | |||
| ca3cd51f91 | |||
| fda1e0d33d | |||
| 1a850392bc | |||
| 14a79eb142 | |||
| 271b809495 | |||
| 2363269c1c | |||
| f1db473d11 | |||
| e35d05a5e3 | |||
| c61783546b | |||
| c08794bdfb | |||
| 4905975f81 | |||
| d53bfb9201 | |||
| 0dac47cb62 | |||
| 7b68552359 | |||
| 775495c7e7 | |||
| 1057f13cdc | |||
| ce59a299cb | |||
| 8235e025d4 | |||
| b301381f90 | |||
| c62f930634 | |||
| 85eb44ac95 | |||
| d5f8063900 | |||
| ee66929465 | |||
| 1b044b8a40 | |||
| f46f6d34d3 | |||
| 3a96e8826f | |||
| 84738668ca | |||
| dbea311aa8 | |||
| d9ce54dee3 | |||
| 7b056735ed | |||
| 33fde99138 | |||
| 4b486e87cc | |||
| a07d1bca74 | |||
| 5e1ef90962 | |||
| 8fe214d915 | |||
| bec9d1dfcd | |||
| 694d5d4638 | |||
| a6ac7cd876 | |||
| 28751a097a | |||
| 19c795be0d | |||
| dd82c26f87 | |||
| c6f621d0dc | |||
| e6add997eb | |||
| a2baeb2fe2 | |||
| a500946e50 | |||
| b7c9c2679e | |||
| bc8a14895a | |||
| 4ae68d0430 | |||
| aabf97f885 | |||
| a9b546cb0f | |||
| 5566c31458 | |||
| ff96d6158e | |||
| 2aa9071aed | |||
| adf2a030e6 | |||
| 0783aa99d7 | |||
| 5a848c98bb | |||
| e98f9b9c4a | |||
| faac2520c9 | |||
| 3d098416c6 | |||
| 7e53611e3a | |||
| d8496160cb | |||
| c7f10bc76d | |||
| f8910caa59 | |||
| b1d948daef | |||
| 4d4ddbd887 | |||
| d205b47c08 | |||
| 2b7df1fcac | |||
| 53eccc0a3d | |||
| 951cf9d7b0 | |||
| 87136bb0d0 | |||
| eb06ebe245 | |||
| b06ca88cd4 | |||
| 5af2e30d9a | |||
| ea3529e624 | |||
| 0209c11bc1 | |||
| 6a24660472 | |||
| a3bc87d87d | |||
| 85493a2581 | |||
| ad544565fe | |||
| 5e135a9daf | |||
| 7770b7a2c0 | |||
| 2ef6f64b1d | |||
| de013d2f04 | |||
| ed94cf9839 | |||
| 2fec7688b0 | |||
| 3c1834f0fc | |||
| f6e78d3ecd | |||
| dad7fce7a1 | |||
| 8058921f58 | |||
| bb8e0e1047 | |||
| 5dcac6d2e3 | |||
| 552772d2a9 | |||
| 42611a787d | |||
| 743788d02f | |||
| 6028300366 | |||
| 70cb25766b | |||
| 36eede8f31 | |||
| ec0dcdb685 | |||
| 2a1a821bb3 | |||
| 09c01e580a | |||
| 27902c9106 | |||
| a8d328bba2 | |||
| 917d611883 | |||
| 94e0b644a7 | |||
| 10f8565e32 | |||
| 22bce41dd7 | |||
| e35e73d2a3 | |||
| f821f31a51 | |||
| 493af760ed | |||
| 3287bb9613 |
@@ -0,0 +1,3 @@
|
|||||||
|
parm
|
||||||
|
parms
|
||||||
|
crate
|
||||||
+1
-2
@@ -1,5 +1,4 @@
|
|||||||
[codespell]
|
[codespell]
|
||||||
ignore-words-list = parm,parms
|
ignore-words = .codespell.ignore
|
||||||
skip = ''
|
|
||||||
count = ''
|
count = ''
|
||||||
quiet-level = 3
|
quiet-level = 3
|
||||||
|
|||||||
@@ -8,6 +8,12 @@ insert_final_newline = true
|
|||||||
charset = utf-8
|
charset = utf-8
|
||||||
indent_style = tab
|
indent_style = tab
|
||||||
tab_width = 8
|
tab_width = 8
|
||||||
|
trim_trailing_whitespace = true
|
||||||
|
|
||||||
|
[*.rs]
|
||||||
|
indent_style = space
|
||||||
|
indent_size = 4
|
||||||
|
tab_width = 4
|
||||||
|
|
||||||
[*.sh]
|
[*.sh]
|
||||||
shell_variant = bash # used by `shfmt`
|
shell_variant = bash # used by `shfmt`
|
||||||
@@ -19,3 +25,9 @@ indent_size = 2
|
|||||||
[*.py]
|
[*.py]
|
||||||
indent_style = space
|
indent_style = space
|
||||||
indent_size = 4
|
indent_size = 4
|
||||||
|
|
||||||
|
[{Makefile,*.mak}]
|
||||||
|
indent_style = tab
|
||||||
|
|
||||||
|
[{COMMIT_EDITMSG,EDIT_DESCRIPTION}]
|
||||||
|
max_line_length = 72
|
||||||
|
|||||||
+9
-3
@@ -9,6 +9,10 @@
|
|||||||
tags
|
tags
|
||||||
TAGS
|
TAGS
|
||||||
|
|
||||||
|
# compile_commands.json
|
||||||
|
# (https://clang.llvm.org/docs/JSONCompilationDatabase.html)
|
||||||
|
compile_commands.json
|
||||||
|
|
||||||
# clangd cache (https://clangd.llvm.org/design/indexing#backgroundindex)
|
# clangd cache (https://clangd.llvm.org/design/indexing#backgroundindex)
|
||||||
.cache/
|
.cache/
|
||||||
|
|
||||||
@@ -19,6 +23,8 @@ TAGS
|
|||||||
#
|
#
|
||||||
# Ignore generated executables and other generated files
|
# Ignore generated executables and other generated files
|
||||||
#
|
#
|
||||||
|
**/.detect-openssl.dep.c
|
||||||
|
*.debug
|
||||||
ap_tools/ap-check
|
ap_tools/ap-check
|
||||||
cmsfs-fuse/cmsfs-fuse
|
cmsfs-fuse/cmsfs-fuse
|
||||||
cpacfstats/cpacfstats
|
cpacfstats/cpacfstats
|
||||||
@@ -26,6 +32,7 @@ cpacfstats/cpacfstatsd
|
|||||||
cpumf/chcpumf
|
cpumf/chcpumf
|
||||||
cpumf/lscpumf
|
cpumf/lscpumf
|
||||||
cpumf/lshwc
|
cpumf/lshwc
|
||||||
|
cpumf/lspai
|
||||||
cpumf/pai
|
cpumf/pai
|
||||||
cpuplugd/cpuplugd
|
cpuplugd/cpuplugd
|
||||||
dasdfmt/dasdfmt
|
dasdfmt/dasdfmt
|
||||||
@@ -50,8 +57,8 @@ iucvterm/src/iucvconn
|
|||||||
iucvterm/src/iucvtty
|
iucvterm/src/iucvtty
|
||||||
iucvterm/src/ttyrun
|
iucvterm/src/ttyrun
|
||||||
iucvterm/test/test_afiucv
|
iucvterm/test/test_afiucv
|
||||||
libap/check-dep-lock
|
|
||||||
libap/check-dep-json
|
libap/check-dep-json
|
||||||
|
libap/check-dep-lock
|
||||||
libekmfweb/check-dep-libekmfweb
|
libekmfweb/check-dep-libekmfweb
|
||||||
libekmfweb/detect-openssl-version.dep
|
libekmfweb/detect-openssl-version.dep
|
||||||
libekmfweb/libekmfweb.so
|
libekmfweb/libekmfweb.so
|
||||||
@@ -96,6 +103,7 @@ zdev/src/chzdev
|
|||||||
zdev/src/chzdev_usage.c
|
zdev/src/chzdev_usage.c
|
||||||
zdev/src/lszdev
|
zdev/src/lszdev
|
||||||
zdev/src/lszdev_usage.c
|
zdev/src/lszdev_usage.c
|
||||||
|
zdev/src/zdev_id
|
||||||
zdsfs/zdsfs
|
zdsfs/zdsfs
|
||||||
zdump/.check_dep_fuse
|
zdump/.check_dep_fuse
|
||||||
zdump/.check_dep_zgetdump
|
zdump/.check_dep_zgetdump
|
||||||
@@ -115,7 +123,6 @@ zipl/boot/*.exec
|
|||||||
zipl/boot/.loaders
|
zipl/boot/.loaders
|
||||||
zipl/boot/data.h
|
zipl/boot/data.h
|
||||||
zipl/src/chreipl_helper.device-mapper
|
zipl/src/chreipl_helper.device-mapper
|
||||||
zdev/src/zdev_id
|
|
||||||
zipl/src/zipl
|
zipl/src/zipl
|
||||||
zipl/src/zipl-editenv
|
zipl/src/zipl-editenv
|
||||||
zipl/src/zipl_helper.device-mapper
|
zipl/src/zipl_helper.device-mapper
|
||||||
@@ -129,4 +136,3 @@ zkey/kmip/zkey-kmip.so
|
|||||||
zkey/zkey
|
zkey/zkey
|
||||||
zkey/zkey-cryptsetup
|
zkey/zkey-cryptsetup
|
||||||
zpcictl/zpcictl
|
zpcictl/zpcictl
|
||||||
**/.detect-openssl.dep.c
|
|
||||||
|
|||||||
@@ -0,0 +1,35 @@
|
|||||||
|
---
|
||||||
|
exclude: \.(crt|crl)$
|
||||||
|
repos:
|
||||||
|
- repo: https://github.com/pre-commit/pre-commit-hooks
|
||||||
|
rev: v4.1.0
|
||||||
|
hooks:
|
||||||
|
- id: check-merge-conflict
|
||||||
|
- id: end-of-file-fixer
|
||||||
|
- id: mixed-line-ending
|
||||||
|
- id: trailing-whitespace
|
||||||
|
- id: check-executables-have-shebangs
|
||||||
|
- id: check-shebang-scripts-are-executable
|
||||||
|
exclude_types: ['rust']
|
||||||
|
- repo: local
|
||||||
|
hooks:
|
||||||
|
- id: git-clang-format
|
||||||
|
name: git-clang-format
|
||||||
|
description: Run git-clang-format
|
||||||
|
entry: git
|
||||||
|
args: [clang-format, --staged, --]
|
||||||
|
pass_filenames: true
|
||||||
|
language: system
|
||||||
|
require_serial: true
|
||||||
|
minimum_pre_commit_version: "2.9.0"
|
||||||
|
types_or: [c++, c]
|
||||||
|
- repo: https://github.com/codespell-project/codespell
|
||||||
|
rev: v2.2.1
|
||||||
|
hooks:
|
||||||
|
- id: codespell
|
||||||
|
exclude_types: ['rust']
|
||||||
|
- repo: https://github.com/jumanjihouse/pre-commit-hooks
|
||||||
|
rev: 3.0.0
|
||||||
|
hooks:
|
||||||
|
- id: shellcheck
|
||||||
|
args: ["--external-sources"]
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
edition = "2021"
|
||||||
|
newline_style = "Unix"
|
||||||
|
|
||||||
|
# Unstable options that help catching some mistakes in formatting and that we may want to enable
|
||||||
|
# when they become stable.
|
||||||
|
#
|
||||||
|
# They are kept here since they are useful to run from time to time.
|
||||||
|
#format_code_in_doc_comments = true
|
||||||
|
#reorder_impl_items = true
|
||||||
|
#comment_width = 100
|
||||||
|
#wrap_comments = true
|
||||||
|
#normalize_comments = true
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
# Search in the current script's directory by default (since 0.7.0)
|
||||||
|
source-path=SCRIPTDIR
|
||||||
|
|
||||||
|
# Allow external-sources (since 0.8.0)
|
||||||
|
external-sources=true
|
||||||
@@ -27,6 +27,7 @@ List of all individuals having contributed content to s390-tools
|
|||||||
- Eberhard Pasch
|
- Eberhard Pasch
|
||||||
- Eduard Shishkin
|
- Eduard Shishkin
|
||||||
- Einar Lueck
|
- Einar Lueck
|
||||||
|
- Eric Farman
|
||||||
- Eric Sandeen
|
- Eric Sandeen
|
||||||
- Erwin Vicari
|
- Erwin Vicari
|
||||||
- Eugene Crosser
|
- Eugene Crosser
|
||||||
@@ -35,6 +36,7 @@ List of all individuals having contributed content to s390-tools
|
|||||||
- Farhan Ali
|
- Farhan Ali
|
||||||
- Fedor Loshakov
|
- Fedor Loshakov
|
||||||
- Felix Beck
|
- Felix Beck
|
||||||
|
- Finn Callies
|
||||||
- Frank Blaschka
|
- Frank Blaschka
|
||||||
- Frank Heimes
|
- Frank Heimes
|
||||||
- Frank Munzert
|
- Frank Munzert
|
||||||
@@ -56,6 +58,7 @@ List of all individuals having contributed content to s390-tools
|
|||||||
- Horst Hummel
|
- Horst Hummel
|
||||||
- Ingo Franzki
|
- Ingo Franzki
|
||||||
- Ingo Tuchscherer
|
- Ingo Tuchscherer
|
||||||
|
- Jakub Čajka
|
||||||
- Jan Glauber
|
- Jan Glauber
|
||||||
- Jan Höppner
|
- Jan Höppner
|
||||||
- Jan Willeke
|
- Jan Willeke
|
||||||
@@ -124,6 +127,8 @@ List of all individuals having contributed content to s390-tools
|
|||||||
- Thomas Richter
|
- Thomas Richter
|
||||||
- Thomas Spatzier
|
- Thomas Spatzier
|
||||||
- Thomas Weber
|
- Thomas Weber
|
||||||
|
- Thorsten Winkler
|
||||||
|
- Tobias Huschle
|
||||||
- Tuan Hoang
|
- Tuan Hoang
|
||||||
- Ursula Braun
|
- Ursula Braun
|
||||||
- Utz Bacher
|
- Utz Bacher
|
||||||
@@ -134,3 +139,4 @@ List of all individuals having contributed content to s390-tools
|
|||||||
- Volker Sameske
|
- Volker Sameske
|
||||||
- Wenjia Zhang
|
- Wenjia Zhang
|
||||||
- Wolfgang Taphorn
|
- Wolfgang Taphorn
|
||||||
|
- Yaakov Selkowitz
|
||||||
|
|||||||
+115
@@ -1,6 +1,121 @@
|
|||||||
Release history for s390-tools (MIT version)
|
Release history for s390-tools (MIT version)
|
||||||
--------------------------------------------
|
--------------------------------------------
|
||||||
|
|
||||||
|
* __v2.32.0 (2024-04-03)__
|
||||||
|
|
||||||
|
For Linux kernel version: 6.8
|
||||||
|
|
||||||
|
Changes of existing tools:
|
||||||
|
- cpumf/lscpumf: add support for machine type 3932
|
||||||
|
- genprotimg, pvattest, and pvsecret accept IBM signing key with Armonk as
|
||||||
|
subject locality
|
||||||
|
- zdump/zipl: Support for List-Directed dump from ECKD DASD
|
||||||
|
- zkey: Detect FIPS mode and generate PBKDF for luksFormat according to it
|
||||||
|
|
||||||
|
Bug Fixes:
|
||||||
|
- dbginfo.sh: dash compatible copy sequence
|
||||||
|
- rust/pv_core: Fix UvDeviceInfo::get() method
|
||||||
|
- zipl/src: Fix leak of files if run with a broken configuration
|
||||||
|
- zkey: Fix convert command to accept only keys of type CCA-AESDATA
|
||||||
|
|
||||||
|
* __v2.31.0 (2024-02-02)__
|
||||||
|
|
||||||
|
For Linux kernel version: 6.7
|
||||||
|
|
||||||
|
General:
|
||||||
|
- common.mak: Set default C/C++ standard to gnu11/gnu++11
|
||||||
|
|
||||||
|
Add new tools / libraries:
|
||||||
|
- pvapconfig: Tool to automatically configure APQNs in SE KVM guests
|
||||||
|
- s390-tools: Provide pre-commit configuration
|
||||||
|
|
||||||
|
Changes of existing tools:
|
||||||
|
- cpuplugd: Adjust to CPU 0 being no longer hotpluggable
|
||||||
|
- dbginfo.sh: Check for Dynamic Partition Mode
|
||||||
|
- dbginfo.sh: Update man page and copyright
|
||||||
|
- rust/pv: Add user-data signing and verifying
|
||||||
|
- rust/pvsecret: Add user defined signatures and verifications
|
||||||
|
- zdev/dracut: Consolidate device configuration
|
||||||
|
|
||||||
|
Bug Fixes:
|
||||||
|
- dbginfo.sh: Fix relative path on script copy
|
||||||
|
- libkmipclient: Fix build with libxml2-2.12.0
|
||||||
|
- pvsecret: Fix panic if empty file is used as host key document
|
||||||
|
- rust/pv: Fix 'elided_lifetimes_in_associated_constant' warning
|
||||||
|
|
||||||
|
* __v2.30.0 (2023-12-01)__
|
||||||
|
|
||||||
|
For Linux kernel version: 6.6
|
||||||
|
|
||||||
|
Add new tools / libraries:
|
||||||
|
- lspai: Tool to display PAI counter sets
|
||||||
|
- s390-tools: Provide a ShellCheck configuration
|
||||||
|
|
||||||
|
Changes of existing tools / libraries:
|
||||||
|
- cpumf/pai: Add command line option for realtime scheduling
|
||||||
|
- dbginfo.sh: enhance ethtool collection for ROCE
|
||||||
|
- libutil/util_lockfile: add routine to return owning pid of file lock
|
||||||
|
- lszcrypt: Improve lszcrypt output on SE guests
|
||||||
|
- rust: Use a single workspace for all rust tools
|
||||||
|
- zdev: limit the derivation of ZDEV_SITE_ID
|
||||||
|
- zdump/df_s390: Update 'zgetdump -i' output with zlib info
|
||||||
|
- zdump/dfi_s390: Support reading compressed s390_ext dumps
|
||||||
|
- zipl/boot: Integrate zlib compression to single volume DASD dumper
|
||||||
|
- zipl/boot: compile the bootloaders only if HOST_ARCH is s390x
|
||||||
|
- zipl: Add --no-compress option to zipl command
|
||||||
|
- zkey: Also check for deconfigured and check-stopped cards
|
||||||
|
- dbginfo.sh: fix relative path on script copy
|
||||||
|
|
||||||
|
Bug Fixes:
|
||||||
|
- ap_tools/ap-check: handle get-attributes between pre and post event
|
||||||
|
- libutil: fix util_file_read_*() using wrong format specifiers
|
||||||
|
- rust/pv: fix Invalid write of size 1
|
||||||
|
|
||||||
|
* __v2.29.0 (2023-08-04)__
|
||||||
|
|
||||||
|
For Linux kernel version: 6.5
|
||||||
|
|
||||||
|
General:
|
||||||
|
- s390-tools now supports tools written in Rust.
|
||||||
|
- Add `compdb` Makefile target to create 'compile_commands.json' to LSP
|
||||||
|
backends in IDEs and editors
|
||||||
|
|
||||||
|
Add new tools / libraries:
|
||||||
|
- rust/pv: Library for pv tools written in rust
|
||||||
|
- rust/pvsecret: Tool to manage UV-secrets
|
||||||
|
|
||||||
|
Changes of existing tools:
|
||||||
|
- dbginfo.sh: Global IFS variable
|
||||||
|
- genprotimg: Add support for add-secret requests
|
||||||
|
- genprotimg: Build debuginfo files for bootloader
|
||||||
|
- hyptop: Add real SMT utilization field
|
||||||
|
- hyptop: Allow users to set speedup factor
|
||||||
|
- pvattest: Add yaml-output for verify command
|
||||||
|
- zipl: Build debuginfo files for bootloader
|
||||||
|
|
||||||
|
Bug Fixes:
|
||||||
|
- dump2tar: Fix truncated paths
|
||||||
|
- zdev/dracut: fix kdump build to integrate with site support
|
||||||
|
|
||||||
|
* __v2.28.0 (2023-07-11)__
|
||||||
|
|
||||||
|
For Linux kernel version: 6.4
|
||||||
|
|
||||||
|
Changes of existing tools:
|
||||||
|
- chzcrypt: Support for SE AP pass-through support
|
||||||
|
- genprotimg: Add support for non-s390x architectures
|
||||||
|
- lszcrypt: Support for SE AP pass-through support
|
||||||
|
- zdev: Add support for autoquiesce related sysfs attributes
|
||||||
|
|
||||||
|
Bug Fixes:
|
||||||
|
- ap_tools/ap-check: Handle missing 'matrix' and 'control_domains' attrs
|
||||||
|
- ap_tools/ap-check: Hold ap config file lock over get attributes
|
||||||
|
- s390-tools: Fix build for ppc64le
|
||||||
|
- zdev: Add missing label in the udev-rules
|
||||||
|
- zdev: Add proper value input for the ZDEV_SITE_ID key
|
||||||
|
- zdev: Use rename-file to avoid any symlinks created
|
||||||
|
- zipl/dump: fix ngdump dracut helper script
|
||||||
|
|
||||||
* __v2.27.0 (2023-05-30)__
|
* __v2.27.0 (2023-05-30)__
|
||||||
|
|
||||||
For Linux kernel version: 6.3
|
For Linux kernel version: 6.3
|
||||||
|
|||||||
@@ -15,11 +15,12 @@ TOOL_DIRS = zipl zdump fdasd dasdfmt dasdview tunedasd \
|
|||||||
vmcp man mon_tools dasdinfo vmur cpuplugd ipl_tools \
|
vmcp man mon_tools dasdinfo vmur cpuplugd ipl_tools \
|
||||||
ziomon iucvterm hyptop cmsfs-fuse qethqoat zfcpdump zdsfs cpumf \
|
ziomon iucvterm hyptop cmsfs-fuse qethqoat zfcpdump zdsfs cpumf \
|
||||||
systemd hmcdrvfs cpacfstats zdev dump2tar zkey netboot etc zpcictl \
|
systemd hmcdrvfs cpacfstats zdev dump2tar zkey netboot etc zpcictl \
|
||||||
genprotimg lsstp hsci hsavmcore chreipl-fcp-mpath ap_tools pvattest
|
genprotimg lsstp hsci hsavmcore chreipl-fcp-mpath ap_tools pvattest \
|
||||||
|
rust
|
||||||
else
|
else
|
||||||
BASELIB_DIRS =
|
BASELIB_DIRS =
|
||||||
LIB_DIRS = libpv
|
LIB_DIRS = libpv
|
||||||
TOOL_DIRS = pvattest
|
TOOL_DIRS = genprotimg pvattest rust
|
||||||
endif
|
endif
|
||||||
|
|
||||||
SUB_DIRS = $(BASELIB_DIRS) $(LIB_DIRS) $(TOOL_DIRS)
|
SUB_DIRS = $(BASELIB_DIRS) $(LIB_DIRS) $(TOOL_DIRS)
|
||||||
|
|||||||
@@ -15,6 +15,11 @@ The package also contains the following files:
|
|||||||
Package contents
|
Package contents
|
||||||
----------------
|
----------------
|
||||||
|
|
||||||
|
* rust:
|
||||||
|
all s390-tools that are written in rust and require external crates.
|
||||||
|
Disable the compilation of all tools in `rust/` using HAVE_CARGO=0
|
||||||
|
See the `rust/README.md` for Details
|
||||||
|
|
||||||
* dasdfmt:
|
* dasdfmt:
|
||||||
Low-level format ECKD DASDs with the classical Linux disk layout or the new
|
Low-level format ECKD DASDs with the classical Linux disk layout or the new
|
||||||
z/OS compatible disk layout.
|
z/OS compatible disk layout.
|
||||||
@@ -305,13 +310,14 @@ build options:
|
|||||||
| net-snmp | `HAVE_SNMP` | osasnmpd |
|
| net-snmp | `HAVE_SNMP` | osasnmpd |
|
||||||
| glibc-static | `HAVE_LIBC_STATIC` | zfcpdump |
|
| glibc-static | `HAVE_LIBC_STATIC` | zfcpdump |
|
||||||
| openssl | `HAVE_OPENSSL` | genprotimg, zkey, libekmfweb, |
|
| openssl | `HAVE_OPENSSL` | genprotimg, zkey, libekmfweb, |
|
||||||
| | | libkmipclient, pvattest, zgetdump |
|
| | | libkmipclient, pvattest, zgetdump, |
|
||||||
|
| | | rust/pvsecret, |
|
||||||
| cryptsetup | `HAVE_CRYPTSETUP2` | zkey-cryptsetup |
|
| cryptsetup | `HAVE_CRYPTSETUP2` | zkey-cryptsetup |
|
||||||
| json-c | `HAVE_JSONC` | zkey-cryptsetup, libekmfweb, |
|
| json-c | `HAVE_JSONC` | zkey-cryptsetup, libekmfweb, |
|
||||||
| | | libkmipclient |
|
| | | libkmipclient |
|
||||||
| glib2 | `HAVE_GLIB2` | genprotimg, pvattest, zgetdump |
|
| glib2 | `HAVE_GLIB2` | genprotimg, pvattest, zgetdump |
|
||||||
| libcurl | `HAVE_LIBCURL` | genprotimg, libekmfweb, libkmipclient,|
|
| libcurl | `HAVE_LIBCURL` | genprotimg, libekmfweb, libkmipclient,|
|
||||||
| | | pvattest |
|
| | | pvattest, rust/pvsecret, |
|
||||||
| libxml2 | `HAVE_LIBXML2` | libkmipclient |
|
| libxml2 | `HAVE_LIBXML2` | libkmipclient |
|
||||||
| systemd | `HAVE_SYSTEMD` | hsavmcore |
|
| systemd | `HAVE_SYSTEMD` | hsavmcore |
|
||||||
| libudev | `HAVE_LIBUDEV` | cpacfstatsd |
|
| libudev | `HAVE_LIBUDEV` | cpacfstatsd |
|
||||||
@@ -324,6 +330,7 @@ This table lists additional build or install options:
|
|||||||
| | | zipl |
|
| | | zipl |
|
||||||
| initramfs-tools | `HAVE_INITRAMFS` | zdev, zipl |
|
| initramfs-tools | `HAVE_INITRAMFS` | zdev, zipl |
|
||||||
| | `ZDEV_ALWAYS_UPDATE_INITRD` | zdev |
|
| | `ZDEV_ALWAYS_UPDATE_INITRD` | zdev |
|
||||||
|
| rust | `HAVE_CARGO` | rust/* |
|
||||||
|
|
||||||
The s390-tools build process uses "pkg-config" and therefore it must be
|
The s390-tools build process uses "pkg-config" and therefore it must be
|
||||||
available.
|
available.
|
||||||
@@ -334,6 +341,14 @@ Build and runtime requirements for specific tools
|
|||||||
In the following more details on the build an runtime requirements of
|
In the following more details on the build an runtime requirements of
|
||||||
the different tools are provided:
|
the different tools are provided:
|
||||||
|
|
||||||
|
* rust/pvsecret:
|
||||||
|
For building pvsecret you need OpenSSL version 1.1.1 or newer
|
||||||
|
installed (openssl-devel.rpm). Also required is cargo and libcurl.
|
||||||
|
Tip: you may skip the pvsecret build by adding
|
||||||
|
`HAVE_OPENSSL=0`, `HAVE_LIBCURL=0`, or `HAVE_CARGO=0`.
|
||||||
|
|
||||||
|
The runtime requirements are: openssl-libs (>= 1.1.1).
|
||||||
|
|
||||||
* dbginfo.sh:
|
* dbginfo.sh:
|
||||||
The tar package is required to archive collected data.
|
The tar package is required to archive collected data.
|
||||||
|
|
||||||
@@ -371,6 +386,24 @@ the different tools are provided:
|
|||||||
- Packages: blktrace, multipath-tools, sg3-utils
|
- Packages: blktrace, multipath-tools, sg3-utils
|
||||||
- Tools: rsync, tar, lsscsi
|
- Tools: rsync, tar, lsscsi
|
||||||
|
|
||||||
|
* zipl
|
||||||
|
For CCW-type DASD dump, zlib compression can be used to compress the dump
|
||||||
|
data before writing it to the DASD partition. It can benefit from
|
||||||
|
s390 on-chip compression accelerator (DFLTCC) and provide a faster dumping
|
||||||
|
process, hence lower system downtime.
|
||||||
|
The zlib version integrated with zipl (zipl/boot/zlib) is based on the Linux
|
||||||
|
kernel zlib (kernel version 6.3) which represents zlib version 1.1.3 with a
|
||||||
|
limited number of functions and a number of updates on top including s390
|
||||||
|
hardware compression (DFLTCC) support. Also, all memory allocations are
|
||||||
|
performed in advance, which aligns with zipl requirements.
|
||||||
|
The CCW-type standalone dumper is built as a single binary and must be
|
||||||
|
loaded to stage2 during boot. Hence, all required zlib functions must be
|
||||||
|
integrated into it, and its size is restricted. To limit the size, only
|
||||||
|
deflate-related parts are integrated (no decompression is required during
|
||||||
|
dumping).
|
||||||
|
Removing the inflate modules and function prototypes are the only major
|
||||||
|
modifications made to the kernel version of zlib.
|
||||||
|
|
||||||
* zgetdump
|
* zgetdump
|
||||||
For building zgetdump you need OpenSSL version 1.1.0 or newer
|
For building zgetdump you need OpenSSL version 1.1.0 or newer
|
||||||
installed (openssl-devel.rpm). Also required is glib2
|
installed (openssl-devel.rpm). Also required is glib2
|
||||||
|
|||||||
+53
-4
@@ -434,14 +434,23 @@ static int check_other_mdev_sysfs_cb(const char *path, const char *filename,
|
|||||||
strcasecmp(filename, cbdata->uuid) == 0)
|
strcasecmp(filename, cbdata->uuid) == 0)
|
||||||
return 0;
|
return 0;
|
||||||
|
|
||||||
dev2 = vfio_ap_device_new();
|
/*
|
||||||
|
* Read the 'matrix' attribute to get the list of queues for the active
|
||||||
|
* device. If the sysfs attribute is unreadable, assume the device is
|
||||||
|
* being destroyed and skip it.
|
||||||
|
*/
|
||||||
matrix_path = path_get_vfio_ap_attr(filename, "matrix");
|
matrix_path = path_get_vfio_ap_attr(filename, "matrix");
|
||||||
f = fopen(matrix_path, "r");
|
f = fopen(matrix_path, "r");
|
||||||
|
free(matrix_path);
|
||||||
|
if (!f)
|
||||||
|
return 0;
|
||||||
|
|
||||||
|
dev2 = vfio_ap_device_new();
|
||||||
|
|
||||||
while (fgets(buf, sizeof(buf), f))
|
while (fgets(buf, sizeof(buf), f))
|
||||||
vfio_ap_parse_matrix(dev2, buf);
|
vfio_ap_parse_matrix(dev2, buf);
|
||||||
vfio_ap_sort_matrix_results(dev2);
|
vfio_ap_sort_matrix_results(dev2);
|
||||||
fclose(f);
|
fclose(f);
|
||||||
free(matrix_path);
|
|
||||||
|
|
||||||
/* Look for conflicts between target device and this device */
|
/* Look for conflicts between target device and this device */
|
||||||
rc = find_apqn_conflicts(filename, dev->adapters, dev->domains,
|
rc = find_apqn_conflicts(filename, dev->adapters, dev->domains,
|
||||||
@@ -787,21 +796,61 @@ static int ap_check_handle_get_attributes(struct ap_check_anchor *anc)
|
|||||||
char buf[80];
|
char buf[80];
|
||||||
char *path;
|
char *path;
|
||||||
FILE *f;
|
FILE *f;
|
||||||
|
int rc;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* For the get-attributes callout, we are typically called without the
|
||||||
|
* callout lock held. However, there is a particular scenario (define
|
||||||
|
* of an active mdev) where we may or may not be called with the lock
|
||||||
|
* already held on behalf of mdevctl, depending on the mdevctl version.
|
||||||
|
* Let's test for lock ownership first and, if already owned by the
|
||||||
|
* parent (mdevctl) proceed rather than waiting on the file lock.
|
||||||
|
*/
|
||||||
|
rc = ap_try_lock_callout();
|
||||||
|
switch (rc) {
|
||||||
|
case 0:
|
||||||
|
/* Lock acquired */
|
||||||
|
anc->cleanup_lock = true;
|
||||||
|
break;
|
||||||
|
case 1:
|
||||||
|
/* Lock held by parent -- trust the lock will remain held */
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
/* Lock not acquired or held by parent -- do a normal obtain */
|
||||||
|
rc = ap_get_lock_callout();
|
||||||
|
if (rc) {
|
||||||
|
fprintf(stderr,
|
||||||
|
"Failed to acquire configuration lock %d\n",
|
||||||
|
rc);
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
|
anc->cleanup_lock = true;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Read the 'matrix' and 'control_domains' attributes to get the
|
||||||
|
* current attributes of the active device. If either of these sysfs
|
||||||
|
* attributes is unreadable, assume the device is being destroyed
|
||||||
|
* and return nothing.
|
||||||
|
*/
|
||||||
path = path_get_vfio_ap_attr(anc->uuid, "matrix");
|
path = path_get_vfio_ap_attr(anc->uuid, "matrix");
|
||||||
f = fopen(path, "r");
|
f = fopen(path, "r");
|
||||||
|
free(path);
|
||||||
|
if (!f)
|
||||||
|
return 0;
|
||||||
while (fgets(buf, sizeof(buf), f))
|
while (fgets(buf, sizeof(buf), f))
|
||||||
vfio_ap_parse_matrix(dev, buf);
|
vfio_ap_parse_matrix(dev, buf);
|
||||||
vfio_ap_sort_matrix_results(dev);
|
vfio_ap_sort_matrix_results(dev);
|
||||||
fclose(f);
|
fclose(f);
|
||||||
free(path);
|
|
||||||
|
|
||||||
path = path_get_vfio_ap_attr(anc->uuid, "control_domains");
|
path = path_get_vfio_ap_attr(anc->uuid, "control_domains");
|
||||||
f = fopen(path, "r");
|
f = fopen(path, "r");
|
||||||
|
free(path);
|
||||||
|
if (!f)
|
||||||
|
return 0;
|
||||||
while (fgets(buf, sizeof(buf), f))
|
while (fgets(buf, sizeof(buf), f))
|
||||||
vfio_ap_parse_control(dev, buf);
|
vfio_ap_parse_control(dev, buf);
|
||||||
fclose(f);
|
fclose(f);
|
||||||
free(path);
|
|
||||||
|
|
||||||
printf("[{");
|
printf("[{");
|
||||||
|
|
||||||
|
|||||||
@@ -17,7 +17,6 @@
|
|||||||
# GNU awk:
|
# GNU awk:
|
||||||
# - gawk
|
# - gawk
|
||||||
|
|
||||||
override SHELL := /bin/bash
|
|
||||||
override .SHELLFLAGS := -O globstar -O nullglob -O extglob -c
|
override .SHELLFLAGS := -O globstar -O nullglob -O extglob -c
|
||||||
|
|
||||||
# Include common s390-tools definitions
|
# Include common s390-tools definitions
|
||||||
|
|||||||
+65
-28
@@ -8,10 +8,14 @@ ASAN ?= 0
|
|||||||
ENABLE_WERROR ?= 0
|
ENABLE_WERROR ?= 0
|
||||||
OPT_FLAGS ?=
|
OPT_FLAGS ?=
|
||||||
MAKECMDGOALS ?=
|
MAKECMDGOALS ?=
|
||||||
|
CARGO ?= cargo
|
||||||
|
CARGOFLAGS ?=
|
||||||
|
|
||||||
ifeq ($(COMMON_INCLUDED),false)
|
ifeq ($(COMMON_INCLUDED),false)
|
||||||
COMMON_INCLUDED := true
|
COMMON_INCLUDED := true
|
||||||
|
|
||||||
|
override SHELL := /bin/bash
|
||||||
|
|
||||||
# 'BUILD_ARCH' is the architecture of the machine where the build takes place
|
# 'BUILD_ARCH' is the architecture of the machine where the build takes place
|
||||||
BUILD_ARCH := $(shell uname -m | sed -e 's/i.86/i386/' -e 's/sun4u/sparc64/' -e 's/arm.*/arm/' -e 's/sa110/arm/')
|
BUILD_ARCH := $(shell uname -m | sed -e 's/i.86/i386/' -e 's/sun4u/sparc64/' -e 's/arm.*/arm/' -e 's/sa110/arm/')
|
||||||
# 'HOST_ARCH' is the architecture of the machine that will run the compiled output
|
# 'HOST_ARCH' is the architecture of the machine that will run the compiled output
|
||||||
@@ -28,7 +32,7 @@ endif
|
|||||||
# The variable "DISTRELEASE" should be overwritten in rpm spec files with:
|
# The variable "DISTRELEASE" should be overwritten in rpm spec files with:
|
||||||
# "make DISTRELEASE=%{release}" and "make install DISTRELEASE=%{release}"
|
# "make DISTRELEASE=%{release}" and "make install DISTRELEASE=%{release}"
|
||||||
VERSION = 2
|
VERSION = 2
|
||||||
RELEASE = 27
|
RELEASE = 32
|
||||||
PATCHLEVEL = 0
|
PATCHLEVEL = 0
|
||||||
DISTRELEASE = build-$(shell date +%Y%m%d)
|
DISTRELEASE = build-$(shell date +%Y%m%d)
|
||||||
S390_TOOLS_RELEASE = $(VERSION).$(RELEASE).$(PATCHLEVEL)-$(DISTRELEASE)
|
S390_TOOLS_RELEASE = $(VERSION).$(RELEASE).$(PATCHLEVEL)-$(DISTRELEASE)
|
||||||
@@ -89,19 +93,19 @@ define cmd_define_and_export
|
|||||||
endef
|
endef
|
||||||
|
|
||||||
define define_toolchain_variables
|
define define_toolchain_variables
|
||||||
$(eval $(call cmd_define_and_export, AS$(1)," AS$(1) ",$(2)as))
|
$(call cmd_define_and_export, AS$(1)," AS$(1) ",$(2)as)
|
||||||
$(eval $(call cmd_define_and_export, CC$(1)," CC$(1) ",$(2)gcc))
|
$(call cmd_define_and_export, CC$(1)," CC$(1) ",$(2)gcc)
|
||||||
$(eval $(call cmd_define_and_export, LINK$(1)," LINK$(1) ",$$(CC$(1))))
|
$(call cmd_define_and_export, LINK$(1)," LINK$(1) ",$$(CC$(1)))
|
||||||
$(eval $(call cmd_define_and_export, CXX$(1)," CXX$(1) ",$(2)g++))
|
$(call cmd_define_and_export, CXX$(1)," CXX$(1) ",$(2)g++)
|
||||||
$(eval $(call cmd_define_and_export, LINKXX$(1)," LINKXX$(1) ",$$(CXX$(1))))
|
$(call cmd_define_and_export, LINKXX$(1)," LINKXX$(1) ",$$(CXX$(1)))
|
||||||
$(eval $(call cmd_define_and_export, CPP$(1)," CPP$(1) ",$(2)gcc -E))
|
$(call cmd_define_and_export, CPP$(1)," CPP$(1) ",$(2)gcc -E)
|
||||||
$(eval $(call cmd_define_and_export, AR$(1)," AR$(1) ",$(2)ar))
|
$(call cmd_define_and_export, AR$(1)," AR$(1) ",$(2)ar)
|
||||||
$(eval $(call cmd_define_and_export, NM$(1)," NM$(1) ",$(2)nm))
|
$(call cmd_define_and_export, NM$(1)," NM$(1) ",$(2)nm)
|
||||||
$(eval $(call cmd_define_and_export, STRIP$(1)," STRIP$(1) ",$(2)strip))
|
$(call cmd_define_and_export, STRIP$(1)," STRIP$(1) ",$(2)strip)
|
||||||
$(eval $(call cmd_define_and_export,OBJCOPY$(1)," OBJCOPY$(1) ",$(2)objcopy))
|
$(call cmd_define_and_export,OBJCOPY$(1)," OBJCOPY$(1) ",$(2)objcopy)
|
||||||
$(eval $(call cmd_define_and_export,OBJDUMP$(1)," OBJDUMP$(1) ",$(2)objdump))
|
$(call cmd_define_and_export,OBJDUMP$(1)," OBJDUMP$(1) ",$(2)objdump)
|
||||||
$(eval PKG_CONFIG$(1) = pkg-config)
|
PKG_CONFIG$(1) = pkg-config
|
||||||
$(eval export PKG_CONFIG$(1))
|
export PKG_CONFIG$(1)
|
||||||
endef
|
endef
|
||||||
|
|
||||||
# If the host architecture is not the same as the build architecture
|
# If the host architecture is not the same as the build architecture
|
||||||
@@ -115,15 +119,19 @@ ifneq ($(HOST_ARCH),$(BUILD_ARCH))
|
|||||||
endif
|
endif
|
||||||
endif
|
endif
|
||||||
|
|
||||||
$(call define_toolchain_variables,_FOR_BUILD,)
|
$(eval $(call define_toolchain_variables,_FOR_BUILD,))
|
||||||
$(call define_toolchain_variables,,$(CROSS_COMPILE))
|
$(eval $(call define_toolchain_variables,,$(CROSS_COMPILE)))
|
||||||
|
|
||||||
$(eval $(call cmd_define,RUNTEST," RUNTEST ",$(S390_TEST_LIB_PATH)/s390_runtest))
|
|
||||||
$(eval $(call cmd_define, CAT," CAT ",cat))
|
$(eval $(call cmd_define, RUNTEST," RUNTEST ",$(S390_TEST_LIB_PATH)/s390_runtest))
|
||||||
$(eval $(call cmd_define, SED," SED ",sed))
|
$(eval $(call cmd_define, CAT," CAT ",cat))
|
||||||
$(eval $(call cmd_define, GZIP," GZIP ",gzip))
|
$(eval $(call cmd_define, SED," SED ",sed))
|
||||||
$(eval $(call cmd_define, MV," MV ",mv))
|
$(eval $(call cmd_define, GZIP," GZIP ",gzip))
|
||||||
$(eval $(call cmd_define, PERLC," PERLC ",perl -c))
|
$(eval $(call cmd_define, MV," MV ",mv))
|
||||||
|
$(eval $(call cmd_define, PERLC," PERLC ",perl -c))
|
||||||
|
$(eval $(call cmd_define,CARGO_BUILD," CARGO BUILD ",$(CARGO) build))
|
||||||
|
$(eval $(call cmd_define,CARGO_TEST, " CARGO TEST ",$(CARGO) test))
|
||||||
|
$(eval $(call cmd_define,CARGO_CLEAN," CARGO CLEAN ",$(CARGO) clean))
|
||||||
|
|
||||||
CHECK = sparse
|
CHECK = sparse
|
||||||
CHECK_SILENT := $(CHECK)
|
CHECK_SILENT := $(CHECK)
|
||||||
@@ -133,8 +141,10 @@ SKIP = echo " SKIP $(call reldir) due to"
|
|||||||
|
|
||||||
INSTALL = install
|
INSTALL = install
|
||||||
CP = cp
|
CP = cp
|
||||||
|
ALL_CARGOFLAGS := $(CARGOFLAGS)
|
||||||
ifneq ("${V}","1")
|
ifneq ("${V}","1")
|
||||||
MAKEFLAGS += --quiet
|
MAKEFLAGS += --quiet
|
||||||
|
ALL_CARGOFLAGS += --quiet
|
||||||
echocmd=echo $1$(call reldir)$2;
|
echocmd=echo $1$(call reldir)$2;
|
||||||
RUNTEST += > /dev/null 2>&1
|
RUNTEST += > /dev/null 2>&1
|
||||||
else
|
else
|
||||||
@@ -211,8 +221,8 @@ fi
|
|||||||
# Returns the linker option if available and nothing otherwise
|
# Returns the linker option if available and nothing otherwise
|
||||||
#
|
#
|
||||||
define test_linker_flag
|
define test_linker_flag
|
||||||
$(shell printf "int main(void) {return 0;}\n" | \
|
$(shell printf ".globl _start\n_start:\nnop\n" | \
|
||||||
( $(CC) "-Wl,$1" -o /dev/null -x c - ) >/dev/null 2>&1 && printf -- '-Wl,%s' "$1")
|
( $(LINK) "-Wl,$1" -o /dev/null -nostdlib -x assembler -) >/dev/null 2>&1 && printf -- '-Wl,%s' "$1")
|
||||||
endef
|
endef
|
||||||
|
|
||||||
NO_WARN_RWX_SEGMENTS_LDFLAGS := $(call test_linker_flag,"--no-warn-rwx-segments")
|
NO_WARN_RWX_SEGMENTS_LDFLAGS := $(call test_linker_flag,"--no-warn-rwx-segments")
|
||||||
@@ -294,7 +304,7 @@ ZFCPDUMP_FLAVOR = zfcpdump
|
|||||||
export ZFCPDUMP_DIR ZFCPDUMP_IMAGE ZFCPDUMP_INITRD ZFCPDUMP_FLAVOR
|
export ZFCPDUMP_DIR ZFCPDUMP_IMAGE ZFCPDUMP_INITRD ZFCPDUMP_FLAVOR
|
||||||
|
|
||||||
CFLAGS ?= $(DEFAULT_CFLAGS) $(OPT_FLAGS)
|
CFLAGS ?= $(DEFAULT_CFLAGS) $(OPT_FLAGS)
|
||||||
CFLAGS_FOR_BUILD ?= $(DEFAULT_CFLAGS) $(OPT_FLAGS)
|
CFLAGS_FOR_BUILD ?= -std=gnu11 $(DEFAULT_CFLAGS) $(OPT_FLAGS)
|
||||||
CPPFLAGS ?= $(DEFAULT_CPPFLAGS)
|
CPPFLAGS ?= $(DEFAULT_CPPFLAGS)
|
||||||
LDFLAGS ?= $(DEFAULT_LDFLAGS)
|
LDFLAGS ?= $(DEFAULT_LDFLAGS)
|
||||||
|
|
||||||
@@ -303,14 +313,14 @@ ALL_CFLAGS = -DS390_TOOLS_RELEASE=$(S390_TOOLS_RELEASE) \
|
|||||||
-DS390_TOOLS_DATADIR=$(TOOLS_DATADIR) \
|
-DS390_TOOLS_DATADIR=$(TOOLS_DATADIR) \
|
||||||
-DS390_TOOLS_SYSCONFDIR=$(SYSCONFDIR) \
|
-DS390_TOOLS_SYSCONFDIR=$(SYSCONFDIR) \
|
||||||
-DS390_TOOLS_BINDIR=$(BINDIR) \
|
-DS390_TOOLS_BINDIR=$(BINDIR) \
|
||||||
$(CFLAGS)
|
-std=gnu11 $(CFLAGS)
|
||||||
CXXFLAGS ?= $(DEFAULT_CFLAGS) $(OPT_FLAGS)
|
CXXFLAGS ?= $(DEFAULT_CFLAGS) $(OPT_FLAGS)
|
||||||
ALL_CXXFLAGS = -DS390_TOOLS_RELEASE=$(S390_TOOLS_RELEASE) \
|
ALL_CXXFLAGS = -DS390_TOOLS_RELEASE=$(S390_TOOLS_RELEASE) \
|
||||||
-DS390_TOOLS_LIBDIR=$(TOOLS_LIBDIR) \
|
-DS390_TOOLS_LIBDIR=$(TOOLS_LIBDIR) \
|
||||||
-DS390_TOOLS_DATADIR=$(TOOLS_DATADIR) \
|
-DS390_TOOLS_DATADIR=$(TOOLS_DATADIR) \
|
||||||
-DS390_TOOLS_SYSCONFDIR=$(SYSCONFDIR) \
|
-DS390_TOOLS_SYSCONFDIR=$(SYSCONFDIR) \
|
||||||
-DS390_TOOLS_BINDIR=$(BINDIR) \
|
-DS390_TOOLS_BINDIR=$(BINDIR) \
|
||||||
$(CXXFLAGS)
|
-std=gnu++11 $(CXXFLAGS)
|
||||||
ALL_CPPFLAGS = -I $(rootdir)include $(CPPFLAGS)
|
ALL_CPPFLAGS = -I $(rootdir)include $(CPPFLAGS)
|
||||||
ALL_LDFLAGS = $(LDFLAGS)
|
ALL_LDFLAGS = $(LDFLAGS)
|
||||||
|
|
||||||
@@ -360,6 +370,7 @@ help:
|
|||||||
@echo ' all Build all tools (default target)'
|
@echo ' all Build all tools (default target)'
|
||||||
@echo ' install Install tools'
|
@echo ' install Install tools'
|
||||||
@echo ' clean Delete all generated files'
|
@echo ' clean Delete all generated files'
|
||||||
|
@echo ' compdb Generate compile_commands.json for clangd'
|
||||||
@echo ''
|
@echo ''
|
||||||
@echo 'OPTIONS'
|
@echo 'OPTIONS'
|
||||||
@echo ' D=1 Build with debugging option "-Og"'
|
@echo ' D=1 Build with debugging option "-Og"'
|
||||||
@@ -375,6 +386,32 @@ help:
|
|||||||
@echo ' # make C=1 CHECK=smatch'
|
@echo ' # make C=1 CHECK=smatch'
|
||||||
.PHONY: help
|
.PHONY: help
|
||||||
|
|
||||||
|
|
||||||
|
# 'compile_commands.json' generation
|
||||||
|
#
|
||||||
|
# Create the compilation database 'compile_commands.json'. See
|
||||||
|
# https://clang.llvm.org/docs/JSONCompilationDatabase.html for details.
|
||||||
|
#
|
||||||
|
.PHONY: compdb
|
||||||
|
compdb:
|
||||||
|
$(MAKE) clean
|
||||||
|
ifneq ($(shell command -v compiledb),)
|
||||||
|
compiledb $(MAKE)
|
||||||
|
else ifneq ($(shell command -v bear),)
|
||||||
|
ifeq ($(shell bear --help|grep -- '-- ...'),)
|
||||||
|
bear $(MAKE)
|
||||||
|
else
|
||||||
|
bear -- $(MAKE)
|
||||||
|
endif
|
||||||
|
else
|
||||||
|
$(error Please install either 'compiledb' or 'bear')
|
||||||
|
endif
|
||||||
|
|
||||||
|
# Prints the s390-tools release string
|
||||||
|
version:
|
||||||
|
$(info $(S390_TOOLS_RELEASE))
|
||||||
|
.PHONY: version
|
||||||
|
|
||||||
# Automatic dependency generation
|
# Automatic dependency generation
|
||||||
#
|
#
|
||||||
# Create ".o.d" dependency files with the -MM compile option for all ".c" and
|
# Create ".o.d" dependency files with the -MM compile option for all ".c" and
|
||||||
@@ -485,7 +522,7 @@ install_echo:
|
|||||||
install: install_echo install_dirs
|
install: install_echo install_dirs
|
||||||
|
|
||||||
clean_echo:
|
clean_echo:
|
||||||
$(call echocmd," CLEAN ")
|
$(call echocmd," CLEAN ")
|
||||||
clean_gcov:
|
clean_gcov:
|
||||||
rm -f -- *.gcda *.gcno *.gcov
|
rm -f -- *.gcda *.gcno *.gcov
|
||||||
clean_dep:
|
clean_dep:
|
||||||
|
|||||||
@@ -355,13 +355,13 @@ PCKMO DES,
|
|||||||
.IP \(bu
|
.IP \(bu
|
||||||
PCKMO 2key TDES,
|
PCKMO 2key TDES,
|
||||||
.IP \(bu
|
.IP \(bu
|
||||||
PCMKO TDES,
|
PCKMO TDES,
|
||||||
.IP \(bu
|
.IP \(bu
|
||||||
PCKMO AES 128bit,
|
PCKMO AES 128bit,
|
||||||
.IP \(bu
|
.IP \(bu
|
||||||
PCKMO AES 192bit,
|
PCKMO AES 192bit,
|
||||||
.IP \(bu
|
.IP \(bu
|
||||||
PCMKO AES 256bit,
|
PCKMO AES 256bit,
|
||||||
.IP \(bu
|
.IP \(bu
|
||||||
PCKMO ECC P256,
|
PCKMO ECC P256,
|
||||||
.IP \(bu
|
.IP \(bu
|
||||||
|
|||||||
@@ -204,10 +204,10 @@ static const char *const pai_str[] = {
|
|||||||
[142] = "KDSA EdDSA Sign Ed448 protected key",
|
[142] = "KDSA EdDSA Sign Ed448 protected key",
|
||||||
[143] = "PCKMO DES",
|
[143] = "PCKMO DES",
|
||||||
[144] = "PCKMO 2key TDES",
|
[144] = "PCKMO 2key TDES",
|
||||||
[145] = "PCMKO TDES",
|
[145] = "PCKMO TDES",
|
||||||
[146] = "PCKMO AES 128bit",
|
[146] = "PCKMO AES 128bit",
|
||||||
[147] = "PCKMO AES 192bit",
|
[147] = "PCKMO AES 192bit",
|
||||||
[148] = "PCMKO AES 256bit",
|
[148] = "PCKMO AES 256bit",
|
||||||
[149] = "PCKMO ECC P256",
|
[149] = "PCKMO ECC P256",
|
||||||
[150] = "PCKMO ECC P384",
|
[150] = "PCKMO ECC P384",
|
||||||
[151] = "PCKMO ECC P521",
|
[151] = "PCKMO ECC P521",
|
||||||
@@ -323,7 +323,7 @@ static void json_print_virtual_counter_answer(int s, int ctr,
|
|||||||
pai_str[paictr], space, paictr + 1);
|
pai_str[paictr], space, paictr + 1);
|
||||||
if (paistate < 0) {
|
if (paistate < 0) {
|
||||||
printf("\"error\":%d}", paistate);
|
printf("\"error\":%d}", paistate);
|
||||||
/* Protocol does not send furter counters. */
|
/* Protocol does not send further counters. */
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
printf("\"value\":%"PRIu64"}", paivalue);
|
printf("\"value\":%"PRIu64"}", paivalue);
|
||||||
@@ -420,7 +420,7 @@ static void json_print_answer(int s, int ctr, int state, uint64_t value)
|
|||||||
printf("\"value\":%"PRIu64"}", value);
|
printf("\"value\":%"PRIu64"}", value);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
int eprint(const char *format, ...)
|
int eprint(const char *format, ...)
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -45,9 +45,8 @@ counter set authorization control" checkbox.
|
|||||||
- The daemon requires root privileges to interact with the performance
|
- The daemon requires root privileges to interact with the performance
|
||||||
ioctls of the kernel.
|
ioctls of the kernel.
|
||||||
|
|
||||||
CPU hotplug is not recognized by the daemon. When adding or removing a CPU,
|
CPU hotplug is recognized by the daemon. When adding or removing a CPU,
|
||||||
restart the daemon to ensure correct summing of the per-CPU performance
|
the daemon ensures correct summing of the per-CPU performance counters.
|
||||||
counters.
|
|
||||||
|
|
||||||
The starting daemon first checks for any stale pid file
|
The starting daemon first checks for any stale pid file
|
||||||
\%/run/cpacfstatsd.pid. If this file exists, and the process ID in the
|
\%/run/cpacfstatsd.pid. If this file exists, and the process ID in the
|
||||||
|
|||||||
+57
-18
@@ -97,7 +97,7 @@ static int do_send_pai(int s, int user)
|
|||||||
{
|
{
|
||||||
int ctr, state, i, maxctr, rc = 0;
|
int ctr, state, i, maxctr, rc = 0;
|
||||||
uint64_t value;
|
uint64_t value;
|
||||||
|
|
||||||
if (user) {
|
if (user) {
|
||||||
ctr = PAI_USER;
|
ctr = PAI_USER;
|
||||||
maxctr = NUM_PAI_USER;
|
maxctr = NUM_PAI_USER;
|
||||||
@@ -252,20 +252,26 @@ static int do_print(int s, enum ctr_e ctr)
|
|||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
static int become_daemon(void)
|
static int become_daemon(int *startup_pipe)
|
||||||
{
|
{
|
||||||
|
int child_initialized = 0, fd;
|
||||||
|
int pipefds[2];
|
||||||
FILE *f;
|
FILE *f;
|
||||||
int fd;
|
|
||||||
|
|
||||||
/* syslog */
|
/* syslog */
|
||||||
openlog("cpacfstatsd", 0, LOG_DAEMON);
|
openlog("cpacfstatsd", 0, LOG_DAEMON);
|
||||||
|
|
||||||
|
if (pipe(pipefds) != 0) {
|
||||||
|
eprint("pipe() failed, errno=%d [%s]\n", errno, strerror(errno));
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* fork and terminate parent
|
* fork and terminate parent
|
||||||
* Reasons:
|
* Reasons:
|
||||||
* - opens new command line prompt
|
* - opens new command line prompt
|
||||||
* - the child process is guaranteed not to be the process group leader
|
* - the child process is guaranteed not to be the process group leader
|
||||||
* nessecarry for setsid.
|
* necessary for setsid.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
switch (fork()) {
|
switch (fork()) {
|
||||||
@@ -276,9 +282,23 @@ static int become_daemon(void)
|
|||||||
case 0: /* child */
|
case 0: /* child */
|
||||||
break;
|
break;
|
||||||
default: /* parent */
|
default: /* parent */
|
||||||
|
(void)close(pipefds[1]);
|
||||||
|
if (read(pipefds[0], &child_initialized, sizeof(child_initialized)) !=
|
||||||
|
sizeof(child_initialized)) {
|
||||||
|
eprint("Couldn't read from PIPE, errno=%d [%s]\n", errno, strerror(errno));
|
||||||
|
(void)close(pipefds[0]);
|
||||||
|
_exit(EXIT_FAILURE);
|
||||||
|
}
|
||||||
|
(void)close(pipefds[0]);
|
||||||
|
if (!child_initialized)
|
||||||
|
_exit(EXIT_FAILURE);
|
||||||
_exit(0);
|
_exit(0);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* Executed within the child context only */
|
||||||
|
(void)close(pipefds[0]);
|
||||||
|
*startup_pipe = pipefds[1];
|
||||||
|
|
||||||
if (chdir("/") != 0) {
|
if (chdir("/") != 0) {
|
||||||
eprint("Chdir('/') failed, errno=%d [%s]\n",
|
eprint("Chdir('/') failed, errno=%d [%s]\n",
|
||||||
errno, strerror(errno));
|
errno, strerror(errno));
|
||||||
@@ -418,7 +438,7 @@ int eprint(const char *format, ...)
|
|||||||
|
|
||||||
int main(int argc, char *argv[])
|
int main(int argc, char *argv[])
|
||||||
{
|
{
|
||||||
int rc, sfd, foreground = 0;
|
int rc, sfd, foreground = 0, startup_pipe = -1, initialized = 0;
|
||||||
struct sigaction act;
|
struct sigaction act;
|
||||||
|
|
||||||
if (argc > 1) {
|
if (argc > 1) {
|
||||||
@@ -454,27 +474,27 @@ int main(int argc, char *argv[])
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (check_pidfile() != 0) {
|
if (check_pidfile() != 0) {
|
||||||
eprint("Stalled pid file or daemon allready running, terminating\n");
|
eprint("Stalled pid file or daemon already running, terminating\n");
|
||||||
return EXIT_FAILURE;
|
return EXIT_FAILURE;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!foreground) {
|
if (!foreground) {
|
||||||
if (become_daemon() != 0) {
|
if (become_daemon(&startup_pipe) != 0) {
|
||||||
eprint("Couldn't daemonize\n");
|
eprint("Couldn't daemonize\n");
|
||||||
return EXIT_FAILURE;
|
goto error;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (perf_init() != 0) {
|
if (perf_init() != 0) {
|
||||||
eprint("Couldn't initialize perf lib\n");
|
eprint("Couldn't initialize perf lib\n");
|
||||||
return EXIT_FAILURE;
|
goto error;
|
||||||
}
|
}
|
||||||
atexit(perf_close);
|
atexit(perf_close);
|
||||||
|
|
||||||
sfd = open_socket(SERVER);
|
sfd = open_socket(SERVER);
|
||||||
if (sfd < 0) {
|
if (sfd < 0) {
|
||||||
eprint("Couldn't initialize server socket\n");
|
eprint("Couldn't initialize server socket\n");
|
||||||
return EXIT_FAILURE;
|
goto error;
|
||||||
}
|
}
|
||||||
atexit(remove_sock);
|
atexit(remove_sock);
|
||||||
|
|
||||||
@@ -484,17 +504,27 @@ int main(int argc, char *argv[])
|
|||||||
if (sigaction(SIGINT, &act, 0) != 0) {
|
if (sigaction(SIGINT, &act, 0) != 0) {
|
||||||
eprint("Couldn't establish signal handler for SIGINT, errno=%d [%s]\n",
|
eprint("Couldn't establish signal handler for SIGINT, errno=%d [%s]\n",
|
||||||
errno, strerror(errno));
|
errno, strerror(errno));
|
||||||
return EXIT_FAILURE;
|
goto error;
|
||||||
}
|
}
|
||||||
if (sigaction(SIGTERM, &act, 0) != 0) {
|
if (sigaction(SIGTERM, &act, 0) != 0) {
|
||||||
eprint("Couldn't establish signal handler for SIGTERM, errno=%d [%s]\n",
|
eprint("Couldn't establish signal handler for SIGTERM, errno=%d [%s]\n",
|
||||||
errno, strerror(errno));
|
errno, strerror(errno));
|
||||||
return EXIT_FAILURE;
|
goto error;
|
||||||
}
|
}
|
||||||
/* Ignore SIGPIPE such that we see EPIPE as return from write. */
|
/* Ignore SIGPIPE such that we see EPIPE as return from write. */
|
||||||
signal(SIGPIPE, SIG_IGN);
|
signal(SIGPIPE, SIG_IGN);
|
||||||
|
|
||||||
eprint("Running\n");
|
eprint("Running\n");
|
||||||
|
initialized = 1;
|
||||||
|
/* `startup_pipe` has been initialized, so we know we are
|
||||||
|
* running in daemon mode. Let's write to the pipe so that the
|
||||||
|
* parent knows that the initialization is complete.
|
||||||
|
*/
|
||||||
|
if (startup_pipe != -1 &&
|
||||||
|
write(startup_pipe, &initialized, sizeof(initialized)) != sizeof(initialized))
|
||||||
|
goto error;
|
||||||
|
(void)close(startup_pipe);
|
||||||
|
startup_pipe = -1;
|
||||||
|
|
||||||
while (!stopsig) {
|
while (!stopsig) {
|
||||||
enum ctr_e ctr;
|
enum ctr_e ctr;
|
||||||
@@ -507,13 +537,14 @@ int main(int argc, char *argv[])
|
|||||||
continue;
|
continue;
|
||||||
eprint("Accept() failure, errno=%d [%s]\n",
|
eprint("Accept() failure, errno=%d [%s]\n",
|
||||||
errno, strerror(errno));
|
errno, strerror(errno));
|
||||||
return EXIT_FAILURE;
|
goto error;
|
||||||
}
|
}
|
||||||
|
|
||||||
rc = recv_query(s, &ctr, &cmd);
|
rc = recv_query(s, &ctr, &cmd);
|
||||||
if (rc != 0) {
|
if (rc != 0) {
|
||||||
eprint("Recv_query() failed, ignoring\n");
|
eprint("Recv_query() failed, ignoring\n");
|
||||||
goto cleanup;
|
close(s);
|
||||||
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (cmd == ENABLE)
|
if (cmd == ENABLE)
|
||||||
@@ -527,11 +558,9 @@ int main(int argc, char *argv[])
|
|||||||
else {
|
else {
|
||||||
eprint("Received unknown command %d, ignoring\n",
|
eprint("Received unknown command %d, ignoring\n",
|
||||||
(int) cmd);
|
(int) cmd);
|
||||||
goto cleanup;
|
close(s);
|
||||||
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
cleanup:
|
|
||||||
close(s);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (stopsig == SIGTERM)
|
if (stopsig == SIGTERM)
|
||||||
@@ -543,4 +572,14 @@ cleanup:
|
|||||||
remove_pidfile();
|
remove_pidfile();
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
|
|
||||||
|
error:
|
||||||
|
if (startup_pipe != -1) {
|
||||||
|
/* Notify the parent process that there was an error */
|
||||||
|
if (write(startup_pipe, &initialized, sizeof(initialized)) != sizeof(initialized))
|
||||||
|
eprint("Couldn't write to PIPE, errno=%d [%s]\n", errno, strerror(errno));
|
||||||
|
(void)close(startup_pipe);
|
||||||
|
}
|
||||||
|
|
||||||
|
return EXIT_FAILURE;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -371,7 +371,7 @@ static int addallcpus(void)
|
|||||||
errno, strerror(errno));
|
errno, strerror(errno));
|
||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
|
|
||||||
while (!feof(fp)) {
|
while (!feof(fp)) {
|
||||||
/* scan all intervals of online cpus */
|
/* scan all intervals of online cpus */
|
||||||
scanned = fscanf(fp, "%u-%u", &start, &end);
|
scanned = fscanf(fp, "%u-%u", &start, &end);
|
||||||
@@ -414,7 +414,7 @@ static void *hotplughandler(void *UNUSED(unused))
|
|||||||
struct udev *hotplug;
|
struct udev *hotplug;
|
||||||
struct udev_monitor *monitor;
|
struct udev_monitor *monitor;
|
||||||
struct pollfd item;
|
struct pollfd item;
|
||||||
|
|
||||||
hotplug = udev_new();
|
hotplug = udev_new();
|
||||||
if (!hotplug) {
|
if (!hotplug) {
|
||||||
eprint("Failed to create hotplug device\n");
|
eprint("Failed to create hotplug device\n");
|
||||||
@@ -496,10 +496,8 @@ int perf_init(void)
|
|||||||
num -= 2;
|
num -= 2;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (num == 0) {
|
if (num == 0)
|
||||||
eprint("No crypto counters supported!\n");
|
eprint("No crypto counters supported!\n");
|
||||||
return -1;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (perf_load_counter_data())
|
if (perf_load_counter_data())
|
||||||
return -1;
|
return -1;
|
||||||
|
|||||||
+3
-2
@@ -1,7 +1,7 @@
|
|||||||
include ../common.mak
|
include ../common.mak
|
||||||
|
|
||||||
BIN_FILES = lscpumf chcpumf lshwc pai
|
BIN_FILES = lscpumf chcpumf lshwc pai lspai
|
||||||
MAN_FILES = lscpumf.8 chcpumf.8 lshwc.8 pai.8
|
MAN_FILES = lscpumf.8 chcpumf.8 lshwc.8 pai.8 lspai.8
|
||||||
|
|
||||||
all: $(BIN_FILES)
|
all: $(BIN_FILES)
|
||||||
|
|
||||||
@@ -11,6 +11,7 @@ lscpumf: lscpumf.o $(libs)
|
|||||||
chcpumf: chcpumf.o $(libs)
|
chcpumf: chcpumf.o $(libs)
|
||||||
lshwc: lshwc.o $(libs)
|
lshwc: lshwc.o $(libs)
|
||||||
pai: pai.o $(libs)
|
pai: pai.o $(libs)
|
||||||
|
lspai: lspai.o $(libs)
|
||||||
|
|
||||||
install: all install-man
|
install: all install-man
|
||||||
$(INSTALL) -d -m 755 $(DESTDIR)$(BINDIR) $(DESTDIR)$(MANDIR)/man8
|
$(INSTALL) -d -m 755 $(DESTDIR)$(BINDIR) $(DESTDIR)$(MANDIR)/man8
|
||||||
|
|||||||
@@ -3473,6 +3473,7 @@ static struct counters *get_counter(int ctrset, size_t *len)
|
|||||||
read_ccerror(cp, *len);
|
read_ccerror(cp, *len);
|
||||||
break;
|
break;
|
||||||
case UTIL_ARCH_MACHINE_TYPE_Z16:
|
case UTIL_ARCH_MACHINE_TYPE_Z16:
|
||||||
|
case UTIL_ARCH_MACHINE_TYPE_Z16_A02:
|
||||||
cp = cpumcf_z16_counters;
|
cp = cpumcf_z16_counters;
|
||||||
*len = ARRAY_SIZE(cpumcf_z16_counters);
|
*len = ARRAY_SIZE(cpumcf_z16_counters);
|
||||||
}
|
}
|
||||||
|
|||||||
+3
-10
@@ -276,9 +276,7 @@ static bool check_setpossible(void)
|
|||||||
if (!get_cpus(CPUS_KERNELMAX, cpubuf, sizeof(cpubuf)))
|
if (!get_cpus(CPUS_KERNELMAX, cpubuf, sizeof(cpubuf)))
|
||||||
return false;
|
return false;
|
||||||
max_possible_cpus = getnumber(cpubuf, '\0') + 1;
|
max_possible_cpus = getnumber(cpubuf, '\0') + 1;
|
||||||
check = calloc(max_possible_cpus, sizeof(*check));
|
check = util_zalloc(max_possible_cpus * sizeof(*check));
|
||||||
if (!check)
|
|
||||||
err(EXIT_FAILURE, "Maximum CPUs %u", max_possible_cpus);
|
|
||||||
if (!get_cpus(CPUS_POSSIBLE, cpubuf, sizeof(cpubuf))) {
|
if (!get_cpus(CPUS_POSSIBLE, cpubuf, sizeof(cpubuf))) {
|
||||||
free(check);
|
free(check);
|
||||||
return false;
|
return false;
|
||||||
@@ -533,13 +531,8 @@ static int do_read(int ioctlfd)
|
|||||||
struct s390_hwctr_read *read;
|
struct s390_hwctr_read *read;
|
||||||
int rc;
|
int rc;
|
||||||
|
|
||||||
if (!ioctlbuffer) {
|
if (!ioctlbuffer)
|
||||||
ioctlbuffer = malloc(ioctlbuffer_len);
|
ioctlbuffer = util_malloc(ioctlbuffer_len);
|
||||||
if (!ioctlbuffer) {
|
|
||||||
warn("ioctl S390_HWCTR_START");
|
|
||||||
return -ENOMEM;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
read = (struct s390_hwctr_read *)ioctlbuffer;
|
read = (struct s390_hwctr_read *)ioctlbuffer;
|
||||||
rc = ioctl(ioctlfd, S390_HWCTR_READ, read);
|
rc = ioctl(ioctlfd, S390_HWCTR_READ, read);
|
||||||
if (!rc)
|
if (!rc)
|
||||||
|
|||||||
+352
@@ -0,0 +1,352 @@
|
|||||||
|
/* Copyright IBM Corp. 2023
|
||||||
|
*
|
||||||
|
* s390-tools is free software; you can redistribute it and/or modify
|
||||||
|
* it under the terms of the MIT license. See LICENSE for details.
|
||||||
|
*/
|
||||||
|
|
||||||
|
/* List available Processor Assist Instrumentation (PAI) counters. */
|
||||||
|
|
||||||
|
#include <ctype.h>
|
||||||
|
#include <dirent.h>
|
||||||
|
#include <err.h>
|
||||||
|
#include <errno.h>
|
||||||
|
#include <limits.h>
|
||||||
|
#include <stdarg.h>
|
||||||
|
#include <stdbool.h>
|
||||||
|
#include <stdint.h>
|
||||||
|
#include <stdio.h>
|
||||||
|
#include <stdlib.h>
|
||||||
|
#include <string.h>
|
||||||
|
#include <unistd.h>
|
||||||
|
|
||||||
|
#include "lib/util_opt.h"
|
||||||
|
#include "lib/util_prg.h"
|
||||||
|
#include "lib/util_base.h"
|
||||||
|
#include "lib/util_path.h"
|
||||||
|
#include "lib/util_scandir.h"
|
||||||
|
#include "lib/util_libc.h"
|
||||||
|
#include "lib/util_file.h"
|
||||||
|
#include "lib/util_list.h"
|
||||||
|
#include "lib/libcpumf.h"
|
||||||
|
|
||||||
|
static struct util_opt opt_vec[] = {
|
||||||
|
UTIL_OPT_SECTION("OPTIONS"),
|
||||||
|
{
|
||||||
|
.option = { "numeric", no_argument, NULL, 'n' },
|
||||||
|
.desc = "Sort PAI counters by counter number"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
.option = { "type", required_argument, NULL, 't' },
|
||||||
|
.argument = "TYPE",
|
||||||
|
.desc = "Type of PAI counters to show: crypto, nnpa"
|
||||||
|
},
|
||||||
|
UTIL_OPT_HELP,
|
||||||
|
UTIL_OPT_VERSION,
|
||||||
|
UTIL_OPT_END
|
||||||
|
};
|
||||||
|
|
||||||
|
static const struct util_prg prg = {
|
||||||
|
.desc = "List Processor Assist Information counter sets",
|
||||||
|
.copyright_vec = {
|
||||||
|
{
|
||||||
|
.owner = "IBM Corp.",
|
||||||
|
.pub_first = 2023,
|
||||||
|
.pub_last = 2023,
|
||||||
|
},
|
||||||
|
UTIL_PRG_COPYRIGHT_END
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
static bool numsort; /* If true sort counter numerically */
|
||||||
|
|
||||||
|
#define PAI_PATH "/bus/event_source/devices/%s"
|
||||||
|
|
||||||
|
enum pai_types { /* Bit mask for supported PAI counters */
|
||||||
|
pai_type_crypto = 0, /* PAI Crypto Counters */
|
||||||
|
pai_type_nnpa = 1, /* PAI NNPA Counters */
|
||||||
|
pai_type_max = 2, /* PAI maximum value, must be last */
|
||||||
|
};
|
||||||
|
|
||||||
|
static int pai_types_show;
|
||||||
|
|
||||||
|
struct pai_ctrname { /* List of defined counters */
|
||||||
|
char *name; /* Counter name */
|
||||||
|
unsigned long nr; /* Counter number */
|
||||||
|
};
|
||||||
|
|
||||||
|
struct pai_node { /* Head for PAI counter sets */
|
||||||
|
struct util_list_node node; /* Successor in PAI counter set list */
|
||||||
|
enum pai_types type; /* PAI type */
|
||||||
|
int pmu; /* Assigned PMU type number */
|
||||||
|
const char *name; /* Counter set name */
|
||||||
|
char *name_uc; /* Counter set name upper case */
|
||||||
|
const char *sysfs_name; /* Counter set name in /sysfs tree */
|
||||||
|
const char *filter_name; /* Counter set name for scandir filter */
|
||||||
|
struct pai_ctrname *ctrlist; /* List of counter names & numbers */
|
||||||
|
size_t ctrsize; /* Total size in bytes of ctrlist */
|
||||||
|
int ctridx; /* Index of last entry used in ctrlist */
|
||||||
|
unsigned long base; /* Base number for counter set */
|
||||||
|
};
|
||||||
|
|
||||||
|
static struct util_list pai_list;
|
||||||
|
|
||||||
|
/* Return base of counter set, this is the first counter of this set. */
|
||||||
|
static unsigned long pai_type_base(enum pai_types t)
|
||||||
|
{
|
||||||
|
switch (t) {
|
||||||
|
case pai_type_crypto:
|
||||||
|
return 0x1000;
|
||||||
|
case pai_type_nnpa:
|
||||||
|
return 0x1800;
|
||||||
|
case pai_type_max:
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Test PAI counter name from command line option. */
|
||||||
|
static const char *pai_type_name(enum pai_types t)
|
||||||
|
{
|
||||||
|
switch (t) {
|
||||||
|
case pai_type_crypto:
|
||||||
|
return "crypto";
|
||||||
|
case pai_type_nnpa:
|
||||||
|
return "nnpa";
|
||||||
|
case pai_type_max:
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
return "unknown";
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Convert PAI counter type to sysfs directory name. Only validated
|
||||||
|
* input at this time.
|
||||||
|
*/
|
||||||
|
static const char *pai_type_sysfs(enum pai_types t)
|
||||||
|
{
|
||||||
|
if (t == pai_type_crypto)
|
||||||
|
return "pai_crypto";
|
||||||
|
return "pai_ext";
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Convert PAI counter type to sysfs directory name filter for scandir(). */
|
||||||
|
static const char *pai_type_filter(enum pai_types t)
|
||||||
|
{
|
||||||
|
if (t == pai_type_nnpa)
|
||||||
|
return "^NNPA";
|
||||||
|
return "[^.]"; /* Matches anything but . and .. in sysfs */
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Sort PAI counter names by assigned counter number. */
|
||||||
|
static int pai_ctrcmp(const void *p1, const void *p2)
|
||||||
|
{
|
||||||
|
struct pai_ctrname *l = (struct pai_ctrname *)p1;
|
||||||
|
struct pai_ctrname *r = (struct pai_ctrname *)p2;
|
||||||
|
|
||||||
|
return l->nr > r->nr ? 1 : -1;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Convert string to upper case. */
|
||||||
|
static char *str2uc(const char *s)
|
||||||
|
{
|
||||||
|
char *uc = util_strdup(s), *old_uc = uc;
|
||||||
|
|
||||||
|
for (; *uc; ++uc)
|
||||||
|
*uc = toupper(*uc);
|
||||||
|
return old_uc;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Read counter names and assigned event number from sysfs file tree.
|
||||||
|
* Exit when sysfs directory can not be scanned.
|
||||||
|
*/
|
||||||
|
static void read_counternames(struct pai_node *node)
|
||||||
|
{
|
||||||
|
int i, more = 0, ctr = 0, count = 0;
|
||||||
|
struct dirent **namelist = NULL;
|
||||||
|
char *path, *ctrpath;
|
||||||
|
|
||||||
|
/* Read counter names and assigned event number. */
|
||||||
|
path = util_path_sysfs(PAI_PATH "/events", node->sysfs_name);
|
||||||
|
count = util_scandir(&namelist, alphasort, path, node->filter_name);
|
||||||
|
if (count <= 0)
|
||||||
|
errx(EXIT_FAILURE, "Cannot open %s", path);
|
||||||
|
|
||||||
|
node->ctrsize = count * sizeof(*node->ctrlist);
|
||||||
|
node->ctrlist = util_malloc(node->ctrsize);
|
||||||
|
for (i = 0; i < count && ctr >= 0; i++) {
|
||||||
|
util_asprintf(&ctrpath, "%s/%s", path, namelist[i]->d_name);
|
||||||
|
if (util_file_read_va(ctrpath, "event=%x", &ctr) == 1) {
|
||||||
|
node->ctrlist[node->ctridx].name = util_strdup(namelist[i]->d_name);
|
||||||
|
node->ctrlist[node->ctridx++].nr = ctr;
|
||||||
|
more++;
|
||||||
|
} else {
|
||||||
|
warnx("Cannot parse %s", ctrpath);
|
||||||
|
}
|
||||||
|
free(ctrpath);
|
||||||
|
}
|
||||||
|
util_scandir_free(namelist, count);
|
||||||
|
free(path);
|
||||||
|
|
||||||
|
if (numsort && more > 1)
|
||||||
|
qsort(node->ctrlist, more, sizeof(*node->ctrlist), pai_ctrcmp);
|
||||||
|
}
|
||||||
|
|
||||||
|
static void show_painode(void)
|
||||||
|
{
|
||||||
|
struct pai_node *node;
|
||||||
|
int indent = 0;
|
||||||
|
int offset = 0;
|
||||||
|
|
||||||
|
util_list_iterate(&pai_list, node) {
|
||||||
|
for (int i = 0; i < node->ctridx; ++i)
|
||||||
|
indent = MAX((size_t)indent, strlen(node->ctrlist[i].name));
|
||||||
|
}
|
||||||
|
|
||||||
|
printf("RAW %*s NAME %*s DESCRIPTION\n", 3, "", indent - 5, "");
|
||||||
|
util_list_iterate(&pai_list, node) {
|
||||||
|
for (int i = 0; i < node->ctridx; ++i) {
|
||||||
|
printf("%d:%ld %s", node->pmu,
|
||||||
|
node->ctrlist[i].nr, node->ctrlist[i].name);
|
||||||
|
|
||||||
|
offset = indent - strlen(node->ctrlist[i].name) + 1;
|
||||||
|
printf("%*s", offset, "");
|
||||||
|
|
||||||
|
printf("Counter %ld / PAI %s counter set\n",
|
||||||
|
node->ctrlist[i].nr - node->base, node->name_uc);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Release all memory allocated at make_painode(). */
|
||||||
|
static void free_painode(void)
|
||||||
|
{
|
||||||
|
struct pai_node *next, *node;
|
||||||
|
|
||||||
|
util_list_iterate_safe(&pai_list, node, next) {
|
||||||
|
free(node->name_uc);
|
||||||
|
for (int i = 0; i < node->ctridx; ++i)
|
||||||
|
free(node->ctrlist[i].name);
|
||||||
|
free(node->ctrlist);
|
||||||
|
free(node);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
static void make_painode(enum pai_types t)
|
||||||
|
{
|
||||||
|
struct pai_node *node = util_zalloc(sizeof(*node));
|
||||||
|
char *path;
|
||||||
|
|
||||||
|
node->type = t;
|
||||||
|
node->sysfs_name = pai_type_sysfs(t);
|
||||||
|
node->name = pai_type_name(t);
|
||||||
|
node->name_uc = str2uc(node->name);
|
||||||
|
node->filter_name = pai_type_filter(t);
|
||||||
|
node->base = pai_type_base(t);
|
||||||
|
|
||||||
|
/* Read PMU type number. */
|
||||||
|
path = util_path_sysfs(PAI_PATH, node->sysfs_name);
|
||||||
|
node->pmu = libcpumf_pmutype(path);
|
||||||
|
if (node->pmu < 0)
|
||||||
|
errx(EXIT_FAILURE, "Cannot open %s", path);
|
||||||
|
free(path);
|
||||||
|
|
||||||
|
read_counternames(node);
|
||||||
|
|
||||||
|
util_list_add_tail(&pai_list, node);
|
||||||
|
}
|
||||||
|
|
||||||
|
static int painode_cmp(void *a, void *b, void *UNUSED(data))
|
||||||
|
{
|
||||||
|
struct pai_node *n1 = (struct pai_node *)a;
|
||||||
|
struct pai_node *n2 = (struct pai_node *)b;
|
||||||
|
|
||||||
|
return n1->pmu < n2->pmu ? -1 : 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
static void sort_painode(void)
|
||||||
|
{
|
||||||
|
util_list_sort(&pai_list, painode_cmp, NULL);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Check for hardware support and return false if not available. */
|
||||||
|
static bool have_support(enum pai_types t)
|
||||||
|
{
|
||||||
|
const char *sysfn = pai_type_sysfs(t);
|
||||||
|
char *path = util_path_sysfs(PAI_PATH, sysfn);
|
||||||
|
bool rc = true;
|
||||||
|
|
||||||
|
if (!util_path_is_dir(path)) {
|
||||||
|
warnx("No support for PAI %s facility", pai_type_name(t));
|
||||||
|
rc = false;
|
||||||
|
}
|
||||||
|
free(path);
|
||||||
|
return rc;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Check the argument for option -t. It must be a valid PAI counter set.
|
||||||
|
* Exit when an invalid PAI counter set name has been specified.
|
||||||
|
*/
|
||||||
|
static void check_type_name(const char *type)
|
||||||
|
{
|
||||||
|
bool no_match = true;
|
||||||
|
enum pai_types i;
|
||||||
|
const char *fn;
|
||||||
|
|
||||||
|
for (i = pai_type_crypto; i < pai_type_max; ++i) {
|
||||||
|
fn = pai_type_name(i);
|
||||||
|
if (!strcasecmp(fn, type)) {
|
||||||
|
pai_types_show |= (1 << i);
|
||||||
|
no_match = false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (no_match)
|
||||||
|
errx(EXIT_FAILURE, "Invalid argument for -t %s", type);
|
||||||
|
}
|
||||||
|
|
||||||
|
int main(int argc, char **argv)
|
||||||
|
{
|
||||||
|
int ch;
|
||||||
|
|
||||||
|
util_list_init(&pai_list, struct pai_node, node);
|
||||||
|
util_prg_init(&prg);
|
||||||
|
util_opt_init(opt_vec, NULL);
|
||||||
|
|
||||||
|
while ((ch = util_opt_getopt_long(argc, argv)) != -1) {
|
||||||
|
switch (ch) {
|
||||||
|
default:
|
||||||
|
util_opt_print_parse_error(ch, argv);
|
||||||
|
return EXIT_FAILURE;
|
||||||
|
case 'h':
|
||||||
|
util_prg_print_help();
|
||||||
|
util_opt_print_help();
|
||||||
|
return EXIT_SUCCESS;
|
||||||
|
case 'v':
|
||||||
|
util_prg_print_version();
|
||||||
|
return EXIT_SUCCESS;
|
||||||
|
case 'n':
|
||||||
|
numsort = true;
|
||||||
|
break;
|
||||||
|
case 't':
|
||||||
|
check_type_name(optarg);
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Nothing specified, show all PAI counters */
|
||||||
|
if (!pai_types_show)
|
||||||
|
pai_types_show = (1 << pai_type_crypto) | (1 << pai_type_nnpa);
|
||||||
|
|
||||||
|
/* Check for hardware support */
|
||||||
|
for (enum pai_types i = pai_type_crypto; i < pai_type_max; ++i) {
|
||||||
|
if ((pai_types_show & (1 << i))) {
|
||||||
|
if (!have_support(i))
|
||||||
|
pai_types_show &= ~(1 << i);
|
||||||
|
else
|
||||||
|
make_painode(i);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
sort_painode();
|
||||||
|
show_painode();
|
||||||
|
free_painode();
|
||||||
|
return ch;
|
||||||
|
}
|
||||||
@@ -0,0 +1,80 @@
|
|||||||
|
.\" lspai.8
|
||||||
|
.\"
|
||||||
|
.\"
|
||||||
|
.\" Copyright IBM Corp. 2021
|
||||||
|
.\" s390-tools is free software; you can redistribute it and/or modify
|
||||||
|
.\" it under the terms of the MIT license. See LICENSE for details.
|
||||||
|
.\" ----------------------------------------------------------------------
|
||||||
|
.ds c \fBlspai\fP
|
||||||
|
.
|
||||||
|
.TH \*c "8" "August 2023" "s390-tools" "CPU-MF management programs"
|
||||||
|
.
|
||||||
|
.SH NAME
|
||||||
|
\*c \- list Processor Activity Instrumentation (PAI) counters
|
||||||
|
.
|
||||||
|
.SH SYNOPSIS
|
||||||
|
\*c
|
||||||
|
.RB [ \-n ]
|
||||||
|
.RB [ \-t
|
||||||
|
.IR "\ TYPE" ]
|
||||||
|
.br
|
||||||
|
\*c
|
||||||
|
.BR \-h | \-\-help
|
||||||
|
.br
|
||||||
|
\*c
|
||||||
|
.BR \-v | \-\-version
|
||||||
|
.
|
||||||
|
.
|
||||||
|
.SH DESCRIPTION
|
||||||
|
\*c displays the Processor Activity Instrumentation (PAI) counters
|
||||||
|
for Linux on IBM Z.
|
||||||
|
The output is a human-readable list of available PAI counter
|
||||||
|
names and numbers.
|
||||||
|
.SH OPTIONS
|
||||||
|
.TP
|
||||||
|
.BR \-h ", " \-\-help
|
||||||
|
Displays help information, then exits.
|
||||||
|
.
|
||||||
|
.TP
|
||||||
|
.BR \-v ", " \-\-version
|
||||||
|
Displays version information, then exits.
|
||||||
|
.
|
||||||
|
.TP
|
||||||
|
.BR \-t ", " \-\-type "\ TYPE"
|
||||||
|
Specifies the PAI counter set to list.
|
||||||
|
Valid counter set values are
|
||||||
|
.I crypto
|
||||||
|
and
|
||||||
|
.IR nnpa .
|
||||||
|
By default, the command lists all available PAI counter sets.
|
||||||
|
NNPA refers to the Neural Network Processing Assist facility counter set.
|
||||||
|
Crypto refers to the Cryptografic Processing Assist facility counter set.
|
||||||
|
.
|
||||||
|
.TP
|
||||||
|
.BR \-n ", " \-\-numeric
|
||||||
|
Shows the PAI counter sets sorted by counter number.
|
||||||
|
Default sort order is PAI counter name.
|
||||||
|
.
|
||||||
|
.SH "EXAMPLE"
|
||||||
|
The \*c invocation lists all PAI Neural Network Processing Assist Facility
|
||||||
|
(NNPA) counters in numeric order:
|
||||||
|
.nf
|
||||||
|
# lspai -t nnpa -n
|
||||||
|
RAW NAME DESCRIPTION
|
||||||
|
13:6144 NNPA_ALL Counter 0 / PAI NNPA counter set
|
||||||
|
13:6145 NNPA_ADD Counter 1 / PAI NNPA counter set
|
||||||
|
13:6146 NNPA_SUB Counter 2 / PAI NNPA counter set
|
||||||
|
13:6147 NNPA_MUL Counter 3 / PAI NNPA counter set
|
||||||
|
\&...
|
||||||
|
.fi
|
||||||
|
The first column shows the raw event number suitable for
|
||||||
|
.IR perf "(8)"
|
||||||
|
raw event specification.
|
||||||
|
The second column shows the PAI NNPA counter name,
|
||||||
|
suitable for
|
||||||
|
.IR perf "(8)"
|
||||||
|
event specification by name.
|
||||||
|
The third gives a short explanation, if available.
|
||||||
|
.SH "SEE ALSO"
|
||||||
|
.BR pai (8)
|
||||||
|
.BR lscpumf (8)
|
||||||
@@ -18,6 +18,8 @@
|
|||||||
.IR size ]
|
.IR size ]
|
||||||
.RB [ \-i | \-\-interval
|
.RB [ \-i | \-\-interval
|
||||||
.IR ms ]
|
.IR ms ]
|
||||||
|
.RB [ \-R | \-\-realtime
|
||||||
|
.IR prio ]
|
||||||
.BR \-c | \-\-crypto [ \fIcpulist ][: \fIdata\fR "] [" \fIloops\fP ]
|
.BR \-c | \-\-crypto [ \fIcpulist ][: \fIdata\fR "] [" \fIloops\fP ]
|
||||||
.br
|
.br
|
||||||
\*c
|
\*c
|
||||||
@@ -25,6 +27,8 @@
|
|||||||
.IR size ]
|
.IR size ]
|
||||||
.RB [ \-i | \-\-interval
|
.RB [ \-i | \-\-interval
|
||||||
.IR ms ]
|
.IR ms ]
|
||||||
|
.RB [ \-R | \-\-realtime
|
||||||
|
.IR prio ]
|
||||||
.BR \-n | \-\-nnpa [ \fIcpulist ][: \fIdata\fR "] [" \fIloops\fP ]
|
.BR \-n | \-\-nnpa [ \fIcpulist ][: \fIdata\fR "] [" \fIloops\fP ]
|
||||||
.br
|
.br
|
||||||
\*c
|
\*c
|
||||||
@@ -191,6 +195,14 @@ The ring buffer is created with the
|
|||||||
.IR mmap (2)
|
.IR mmap (2)
|
||||||
system call.
|
system call.
|
||||||
.
|
.
|
||||||
|
.TP
|
||||||
|
.BR \-R ", " \-\-realtime "\ prio"
|
||||||
|
Collect data using the RT SCHED_FIFO priority specified by
|
||||||
|
.BR prio .
|
||||||
|
Valid values are integers in the range 1 (low) to 99 (high).
|
||||||
|
Use this option when gathering data from multiple CPUs
|
||||||
|
to prevent data loss.
|
||||||
|
.
|
||||||
.SH ARGUMENT
|
.SH ARGUMENT
|
||||||
The command line options determine how command line
|
The command line options determine how command line
|
||||||
arguments are interpreted.
|
arguments are interpreted.
|
||||||
|
|||||||
+35
-4
@@ -320,7 +320,7 @@ static void readmap(int fd)
|
|||||||
* ring buffer per event, sleep some short time and always read all
|
* ring buffer per event, sleep some short time and always read all
|
||||||
* ring buffer for new contents.
|
* ring buffer for new contents.
|
||||||
*/
|
*/
|
||||||
static void collect(unsigned long cnt)
|
static int collect(unsigned long cnt)
|
||||||
{
|
{
|
||||||
fd_set r_fds, e_fds, a_fds;
|
fd_set r_fds, e_fds, a_fds;
|
||||||
struct pai_event *p;
|
struct pai_event *p;
|
||||||
@@ -328,6 +328,7 @@ static void collect(unsigned long cnt)
|
|||||||
int rc, max_fd;
|
int rc, max_fd;
|
||||||
|
|
||||||
do {
|
do {
|
||||||
|
rc = -1;
|
||||||
max_fd = -1;
|
max_fd = -1;
|
||||||
tv.tv_sec = read_interval / 1000;
|
tv.tv_sec = read_interval / 1000;
|
||||||
tv.tv_usec = (1000 * read_interval) % 1000000;
|
tv.tv_usec = (1000 * read_interval) % 1000000;
|
||||||
@@ -357,6 +358,7 @@ static void collect(unsigned long cnt)
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
} while (rc != -1 && --cnt > 0);
|
} while (rc != -1 && --cnt > 0);
|
||||||
|
return rc;
|
||||||
}
|
}
|
||||||
|
|
||||||
static void lookup_event(__u64 evtnum, __u16 ctr, __u64 value)
|
static void lookup_event(__u64 evtnum, __u16 ctr, __u64 value)
|
||||||
@@ -449,6 +451,11 @@ static void evt_show(__u64 evtnum, const char *evtsel, struct pai_event_out *ev)
|
|||||||
ev->u.s_comm.tid);
|
ev->u.s_comm.tid);
|
||||||
break;
|
break;
|
||||||
|
|
||||||
|
case PERF_RECORD_SWITCH:
|
||||||
|
printf("cs-%s",
|
||||||
|
(ev->misc & PERF_RECORD_MISC_SWITCH_OUT) ? "out" : "in");
|
||||||
|
break;
|
||||||
|
|
||||||
case PERF_RECORD_SWITCH_CPU_WIDE:
|
case PERF_RECORD_SWITCH_CPU_WIDE:
|
||||||
if (ev->misc & PERF_RECORD_MISC_SWITCH_OUT) {
|
if (ev->misc & PERF_RECORD_MISC_SWITCH_OUT) {
|
||||||
short p = PERF_RECORD_MISC_SWITCH_OUT_PREEMPT;
|
short p = PERF_RECORD_MISC_SWITCH_OUT_PREEMPT;
|
||||||
@@ -549,6 +556,9 @@ static int evt_scan(char *fn, unsigned char *buf, size_t len,
|
|||||||
offset -= sizeof(__u64);
|
offset -= sizeof(__u64);
|
||||||
break;
|
break;
|
||||||
|
|
||||||
|
case PERF_RECORD_SWITCH:
|
||||||
|
break;
|
||||||
|
|
||||||
case PERF_RECORD_SWITCH_CPU_WIDE:
|
case PERF_RECORD_SWITCH_CPU_WIDE:
|
||||||
memcpy(&ev.u, buf + offset, sizeof(ev.u.s_cs));
|
memcpy(&ev.u, buf + offset, sizeof(ev.u.s_cs));
|
||||||
offset += sizeof(ev.u.s_cs);
|
offset += sizeof(ev.u.s_cs);
|
||||||
@@ -583,7 +593,7 @@ static int evt_scan(char *fn, unsigned char *buf, size_t len,
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
default:
|
default:
|
||||||
printf("unknown header-type %d ", hdr->type);
|
printf("unknown header-type %d\n", hdr->type);
|
||||||
offset += hdr->size - sizeof(*hdr);
|
offset += hdr->size - sizeof(*hdr);
|
||||||
goto bypass;
|
goto bypass;
|
||||||
}
|
}
|
||||||
@@ -944,6 +954,11 @@ static struct util_opt opt_vec[] = {
|
|||||||
.option = { "report", no_argument, NULL, 'r' },
|
.option = { "report", no_argument, NULL, 'r' },
|
||||||
.desc = "Report file contents"
|
.desc = "Report file contents"
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
.option = { "realtime", required_argument, NULL, 'R' },
|
||||||
|
.argument = "PRIO",
|
||||||
|
.desc = "Collect data with this RT SCHED_FIFO priority"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
.option = { "interval", required_argument, NULL, 'i' },
|
.option = { "interval", required_argument, NULL, 'i' },
|
||||||
.argument = "NUMBER",
|
.argument = "NUMBER",
|
||||||
@@ -1007,6 +1022,19 @@ static unsigned long check_mapsize(unsigned long n)
|
|||||||
return cnt == 1 ? n : 0;
|
return cnt == 1 ? n : 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static void setprio(const char *prio)
|
||||||
|
{
|
||||||
|
struct sched_param param;
|
||||||
|
char *endstr;
|
||||||
|
|
||||||
|
memset(¶m, 0, sizeof(param));
|
||||||
|
param.sched_priority = strtoul(prio, &endstr, 0);
|
||||||
|
if (*endstr)
|
||||||
|
errno = EINVAL;
|
||||||
|
if (*endstr || sched_setscheduler(0, SCHED_FIFO, ¶m))
|
||||||
|
err(EXIT_FAILURE, "Could not set realtime priority");
|
||||||
|
}
|
||||||
|
|
||||||
int main(int argc, char **argv)
|
int main(int argc, char **argv)
|
||||||
{
|
{
|
||||||
bool crypto_record = false, report = false;
|
bool crypto_record = false, report = false;
|
||||||
@@ -1061,6 +1089,9 @@ int main(int argc, char **argv)
|
|||||||
record_cpus_nnpa(optarg);
|
record_cpus_nnpa(optarg);
|
||||||
nnpa_record = true;
|
nnpa_record = true;
|
||||||
break;
|
break;
|
||||||
|
case 'R':
|
||||||
|
setprio(optarg);
|
||||||
|
break;
|
||||||
case 'r':
|
case 'r':
|
||||||
report = true;
|
report = true;
|
||||||
break;
|
break;
|
||||||
@@ -1094,12 +1125,12 @@ int main(int argc, char **argv)
|
|||||||
ev_install(group);
|
ev_install(group);
|
||||||
ev_enable();
|
ev_enable();
|
||||||
|
|
||||||
collect(loop_count);
|
ch = collect(loop_count);
|
||||||
|
|
||||||
ev_disable();
|
ev_disable();
|
||||||
ev_deinstall();
|
ev_deinstall();
|
||||||
ev_dealloc();
|
ev_dealloc();
|
||||||
return EXIT_SUCCESS;
|
return ch < 0 ? EXIT_FAILURE : EXIT_SUCCESS;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* Must be reporting */
|
/* Must be reporting */
|
||||||
|
|||||||
+9
-8
@@ -25,7 +25,7 @@ int get_numcpus()
|
|||||||
|
|
||||||
for (i = 0; ; i++) {
|
for (i = 0; ; i++) {
|
||||||
/* check whether file exists and is readable */
|
/* check whether file exists and is readable */
|
||||||
sprintf(path, "/sys/devices/system/cpu/cpu%d/online", i);
|
sprintf(path, "/sys/devices/system/cpu/cpu%d", i);
|
||||||
if (access(path, R_OK) == 0)
|
if (access(path, R_OK) == 0)
|
||||||
number++;
|
number++;
|
||||||
else
|
else
|
||||||
@@ -45,11 +45,13 @@ int get_num_online_cpus()
|
|||||||
int status = 0;
|
int status = 0;
|
||||||
int value_of_onlinefile, rc;
|
int value_of_onlinefile, rc;
|
||||||
|
|
||||||
for (i = 0; i <= get_numcpus(); i++) {
|
for (i = 0; i < get_numcpus(); i++) {
|
||||||
/* check wether file exists and is readable */
|
/* check wether file exists and is readable */
|
||||||
sprintf(path, "/sys/devices/system/cpu/cpu%d/online", i);
|
sprintf(path, "/sys/devices/system/cpu/cpu%d/online", i);
|
||||||
if (access(path, R_OK) != 0)
|
if (access(path, R_OK) != 0) {
|
||||||
|
status++;
|
||||||
continue;
|
continue;
|
||||||
|
}
|
||||||
filp = fopen(path, "r");
|
filp = fopen(path, "r");
|
||||||
if (!filp)
|
if (!filp)
|
||||||
cpuplugd_exit("Cannot open cpu online file: "
|
cpuplugd_exit("Cannot open cpu online file: "
|
||||||
@@ -101,10 +103,8 @@ int hotplug(int cpuid)
|
|||||||
cpuid);
|
cpuid);
|
||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
} else {
|
|
||||||
cpuplugd_error("hotplugging cpu with id %d failed\n", cpuid);
|
|
||||||
return -1;
|
|
||||||
}
|
}
|
||||||
|
cpuplugd_debug("cpu with id %d cannot be hotplugged\n", cpuid);
|
||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -135,9 +135,8 @@ int hotunplug(int cpuid)
|
|||||||
fclose(filp);
|
fclose(filp);
|
||||||
if (state == 0)
|
if (state == 0)
|
||||||
return 1;
|
return 1;
|
||||||
} else {
|
|
||||||
cpuplugd_error("unplugging cpu with id %d failed\n", cpuid);
|
|
||||||
}
|
}
|
||||||
|
cpuplugd_debug("cpu with id %d cannot be hotunplugged\n", cpuid);
|
||||||
return retval;
|
return retval;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -163,6 +162,8 @@ int is_online(int cpuid)
|
|||||||
retval = 0;
|
retval = 0;
|
||||||
}
|
}
|
||||||
fclose(filp);
|
fclose(filp);
|
||||||
|
} else {
|
||||||
|
retval = 1;
|
||||||
}
|
}
|
||||||
return retval;
|
return retval;
|
||||||
}
|
}
|
||||||
|
|||||||
+23
-24
@@ -15,13 +15,13 @@ dasdfmt \- formatting of DASD (ECKD) disk drives.
|
|||||||
|
|
||||||
.SH DESCRIPTION
|
.SH DESCRIPTION
|
||||||
\fBdasdfmt\fR formats a DASD (ECKD) disk drive to prepare it
|
\fBdasdfmt\fR formats a DASD (ECKD) disk drive to prepare it
|
||||||
for usage with Linux for S/390.
|
for usage with Linux for S/390.
|
||||||
The \fIdevice\fR is the node of the device (e.g. '/dev/dasda').
|
The \fIdevice\fR is the node of the device (e.g. '/dev/dasda').
|
||||||
Any device node created by udev for kernel 2.6 can be used
|
Any device node created by udev for kernel 2.6 can be used
|
||||||
(e.g. '/dev/dasd/0.0.b100/disc').
|
(e.g. '/dev/dasd/0.0.b100/disc').
|
||||||
.br
|
.br
|
||||||
|
|
||||||
\fBWARNING\fR: Careless usage of \fBdasdfmt\fR can result in
|
\fBWARNING\fR: Careless usage of \fBdasdfmt\fR can result in
|
||||||
\fBLOSS OF DATA\fR.
|
\fBLOSS OF DATA\fR.
|
||||||
|
|
||||||
.SH OPTIONS
|
.SH OPTIONS
|
||||||
@@ -31,7 +31,7 @@ Print usage and exit.
|
|||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB-t\fR or \fB--test\fR
|
\fB-t\fR or \fB--test\fR
|
||||||
Disables any modification of the disk drive.
|
Disables any modification of the disk drive.
|
||||||
.br
|
.br
|
||||||
\fBdasdfmt\fR just prints
|
\fBdasdfmt\fR just prints
|
||||||
out, what it \fBwould\fR do.
|
out, what it \fBwould\fR do.
|
||||||
@@ -41,7 +41,7 @@ out, what it \fBwould\fR do.
|
|||||||
Increases verbosity.
|
Increases verbosity.
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB-y\fR
|
\fB-y\fR
|
||||||
Start formatting without further user-confirmation.
|
Start formatting without further user-confirmation.
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
@@ -59,7 +59,7 @@ Omit the writing of a disk label after formatting.
|
|||||||
.br
|
.br
|
||||||
This makes only sense for the 'ldl' disk layout.
|
This makes only sense for the 'ldl' disk layout.
|
||||||
.br
|
.br
|
||||||
The '-L' option has to be specified after the '-d ldl' option.
|
The '-L' option has to be specified after the '-d ldl' option.
|
||||||
.br
|
.br
|
||||||
|
|
||||||
e.g. dasdfmt -d ldl -L /dev/...
|
e.g. dasdfmt -d ldl -L /dev/...
|
||||||
@@ -84,13 +84,13 @@ Formats the device with compatible disk layout or linux disk layout.
|
|||||||
\fIlayout\fR is either \fIcdl\fR for the compatible disk layout
|
\fIlayout\fR is either \fIcdl\fR for the compatible disk layout
|
||||||
(default) or \fIldl\fR for the linux disk layout.
|
(default) or \fIldl\fR for the linux disk layout.
|
||||||
.br
|
.br
|
||||||
Compatible disk layout means a special handling of the
|
Compatible disk layout means a special handling of the
|
||||||
first two tracks of the volume. This enables other S/390 or zSeries
|
first two tracks of the volume. This enables other S/390 or zSeries
|
||||||
operating systems to access this device (e.g. for backup purposes).
|
operating systems to access this device (e.g. for backup purposes).
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB-p\fR or \fB--progressbar\fR
|
\fB-p\fR or \fB--progressbar\fR
|
||||||
Print a progress bar while formatting.
|
Print a progress bar while formatting.
|
||||||
Do not use this option if you are using a 3270 console,
|
Do not use this option if you are using a 3270 console,
|
||||||
running in background or redirecting the output to a file.
|
running in background or redirecting the output to a file.
|
||||||
|
|
||||||
@@ -164,30 +164,30 @@ and always be a power of two. The recommended blocksize is 4096 bytes.
|
|||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB-l\fR \fIvolser\fR or \fB--label\fR=\fIvolser\fR
|
\fB-l\fR \fIvolser\fR or \fB--label\fR=\fIvolser\fR
|
||||||
Specify the volume serial number or volume identifier to be written
|
Specify the volume serial number or volume identifier to be written
|
||||||
to disk after formatting. If no label is specified, a sensible default
|
to disk after formatting. If no label is specified, a sensible default
|
||||||
is used. \fIvolser\fR is interpreted as ASCII string and is automatically
|
is used. \fIvolser\fR is interpreted as ASCII string and is automatically
|
||||||
converted to uppercase and then to EBCDIC.
|
converted to uppercase and then to EBCDIC.
|
||||||
.br
|
.br
|
||||||
|
|
||||||
e.g. -l LNX001 or --label=DASD01
|
e.g. -l LNX001 or --label=DASD01
|
||||||
.br
|
.br
|
||||||
|
|
||||||
The \fIvolser\fR identifies by serial number the volume. A volume serial
|
The \fIvolser\fR identifies by serial number the volume. A volume serial
|
||||||
number is 1 through 6 alphanumeric or one of the following special
|
number is 1 through 6 alphanumeric or one of the following special
|
||||||
characters: $, #, @, %. Enclose a serial number that contains special
|
characters: $, #, @, %. Enclose a serial number that contains special
|
||||||
characters in apostrophes. If the number is shorter than six
|
characters in apostrophes. If the number is shorter than six
|
||||||
characters, it is padded with trailing blanks.
|
characters, it is padded with trailing blanks.
|
||||||
.br
|
.br
|
||||||
|
|
||||||
Do not code a volume serial number as SCRTCH, PRIVAT, or Lnnnnn (L with
|
Do not code a volume serial number as SCRTCH, PRIVAT, or Lnnnnn (L with
|
||||||
five numbers); these are used in OS/390 messages to ask the operator to
|
five numbers); these are used in OS/390 messages to ask the operator to
|
||||||
mount a volume. Do not code a volume serial number as MIGRAT, which is
|
mount a volume. Do not code a volume serial number as MIGRAT, which is
|
||||||
used by the OS/390 Hierarchical Storage Manager DFSMShsm for migrated
|
used by the OS/390 Hierarchical Storage Manager DFSMShsm for migrated
|
||||||
data sets.
|
data sets.
|
||||||
.br
|
.br
|
||||||
|
|
||||||
NOTE: Try to avoid using special characters in the volume serial. This may cause problems accessing a disk by volser.
|
NOTE: Try to avoid using special characters in the volume serial. This may cause problems accessing a disk by volser.
|
||||||
.br
|
.br
|
||||||
In case you really have to use special characters, make sure you are using quotes. In addition there is a special handling for the '$' sign. Please specify it using '\\$' if necessary.
|
In case you really have to use special characters, make sure you are using quotes. In addition there is a special handling for the '$' sign. Please specify it using '\\$' if necessary.
|
||||||
.br
|
.br
|
||||||
@@ -197,9 +197,8 @@ e.g. -l 'a@b\\$c#' to get A@B$C#
|
|||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB-k\fR or \fB--keep_volser\fR
|
\fB-k\fR or \fB--keep_volser\fR
|
||||||
Keeps the Volume Serial Number, when writing the Volume Label. This is
|
Keeps the Volume Serial Number when writing the Volume Label. This is useful if
|
||||||
useful, if the Serial Number has been written with a VM Tool and should not
|
the volume already has a Serial Number that should not be overwritten.
|
||||||
be overwritten.
|
|
||||||
.br
|
.br
|
||||||
|
|
||||||
.SH SEE ALSO
|
.SH SEE ALSO
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
# Common definitions
|
# Common definitions
|
||||||
include ../../common.mak
|
include ../../common.mak
|
||||||
|
|
||||||
ALL_CPPFLAGS += -I../include -std=gnu99 -Wno-unused-parameter
|
ALL_CPPFLAGS += -I../include -Wno-unused-parameter
|
||||||
LDLIBS += -lpthread -lrt
|
LDLIBS += -lpthread -lrt
|
||||||
ifneq ($(HAVE_ZLIB),0)
|
ifneq ($(HAVE_ZLIB),0)
|
||||||
ALL_CPPFLAGS += -DHAVE_ZLIB
|
ALL_CPPFLAGS += -DHAVE_ZLIB
|
||||||
|
|||||||
+10
-3
@@ -23,9 +23,16 @@
|
|||||||
|
|
||||||
#define BLOCKSIZE 512
|
#define BLOCKSIZE 512
|
||||||
|
|
||||||
|
#if __has_attribute(nonstring)
|
||||||
|
# define __nonstring __attribute__ ((nonstring))
|
||||||
|
#else
|
||||||
|
# define __nonstring
|
||||||
|
#endif
|
||||||
|
|
||||||
|
|
||||||
/* Basic TAR header */
|
/* Basic TAR header */
|
||||||
struct tar_header {
|
struct tar_header {
|
||||||
char name[100];
|
char name[100] __nonstring;
|
||||||
char mode[8];
|
char mode[8];
|
||||||
char uid[8];
|
char uid[8];
|
||||||
char gid[8];
|
char gid[8];
|
||||||
@@ -33,7 +40,7 @@ struct tar_header {
|
|||||||
char mtime[12];
|
char mtime[12];
|
||||||
char chksum[8];
|
char chksum[8];
|
||||||
char typeflag;
|
char typeflag;
|
||||||
char linkname[100];
|
char linkname[100] __nonstring;
|
||||||
char magic[6];
|
char magic[6];
|
||||||
char version[2];
|
char version[2];
|
||||||
char uname[32];
|
char uname[32];
|
||||||
@@ -78,7 +85,7 @@ static void set_time(char *dest, size_t len, time_t value)
|
|||||||
#define SET_TIME_FIELD(obj, name, value) \
|
#define SET_TIME_FIELD(obj, name, value) \
|
||||||
set_time((obj)->name, sizeof((obj)->name), (time_t) (value))
|
set_time((obj)->name, sizeof((obj)->name), (time_t) (value))
|
||||||
#define SET_STR_FIELD(obj, name, value) \
|
#define SET_STR_FIELD(obj, name, value) \
|
||||||
util_strlcpy((obj)->name, (value), sizeof((obj)->name))
|
strncpy((obj)->name, (value), sizeof((obj)->name))
|
||||||
|
|
||||||
/* Initialize the tar file @header with the provided data */
|
/* Initialize the tar file @header with the provided data */
|
||||||
static void init_header(struct tar_header *header, const char *filename,
|
static void init_header(struct tar_header *header, const char *filename,
|
||||||
|
|||||||
@@ -28,6 +28,15 @@
|
|||||||
# DEVICE=0.0.4e13
|
# DEVICE=0.0.4e13
|
||||||
# DELAY_MINUTES=5
|
# DELAY_MINUTES=5
|
||||||
|
|
||||||
|
#
|
||||||
|
# Dump on ECKD device (DASD)
|
||||||
|
#
|
||||||
|
#ON_PANIC=dump
|
||||||
|
#DUMP_TYPE=eckd
|
||||||
|
#DEVICE=0.0.1004
|
||||||
|
#BOOTPROG=0
|
||||||
|
#BR_CHR=auto
|
||||||
|
|
||||||
#
|
#
|
||||||
# Dump on fcp device (SCSI Disk)
|
# Dump on fcp device (SCSI Disk)
|
||||||
#
|
#
|
||||||
|
|||||||
+25
-25
@@ -19,10 +19,10 @@ help:
|
|||||||
.br
|
.br
|
||||||
\fBfdasd\fR {-h|-v}
|
\fBfdasd\fR {-h|-v}
|
||||||
.SH DESCRIPTION
|
.SH DESCRIPTION
|
||||||
\fBfdasd\fR writes a partition table to a cdl (compatible disk layout)
|
\fBfdasd\fR writes a partition table to a cdl (compatible disk layout)
|
||||||
formatted DASD, in the form of
|
formatted DASD, in the form of
|
||||||
a VTOC (volume table of contents) for usage with Linux for S/390
|
a VTOC (volume table of contents) for usage with Linux for S/390
|
||||||
or zSeries. If fdasd detects a valid \fBVOL1\fR volume label, it
|
or zSeries. If fdasd detects a valid \fBVOL1\fR volume label, it
|
||||||
will use it, otherwise it asks to write a new one.
|
will use it, otherwise it asks to write a new one.
|
||||||
.br
|
.br
|
||||||
|
|
||||||
@@ -34,51 +34,51 @@ will use it, otherwise it asks to write a new one.
|
|||||||
Print usage information, then exit.
|
Print usage information, then exit.
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB-v\fR or \fB--version\fR
|
\fB-v\fR or \fB--version\fR
|
||||||
Print version information, then exit.
|
Print version information, then exit.
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB-s\fR or \fB--silent\fR
|
\fB-s\fR or \fB--silent\fR
|
||||||
Suppress messages in non-interactive mode.
|
Suppress messages in non-interactive mode.
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB-r\fR or \fB--verbose\fR
|
\fB-r\fR or \fB--verbose\fR
|
||||||
Provide more verbose output.
|
Provide more verbose output.
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB-a\fR or \fB--auto\fR
|
\fB-a\fR or \fB--auto\fR
|
||||||
Automatically create a partition using the entire disk in non-interactive
|
Automatically create a partition using the entire disk in non-interactive
|
||||||
mode.
|
mode.
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB-k\fR or \fB--keep_volser\fR
|
\fB-k\fR or \fB--keep_volser\fR
|
||||||
Keeps the volume serial when writing the volume label.
|
Keeps the Volume Serial Number when writing the Volume Label.
|
||||||
.br
|
.br
|
||||||
This is useful, if the volume serial has been written before and should not
|
This is useful if the volume already has a Serial Number that should not be
|
||||||
be overwritten. This option is only applicable in non-interactive mode.
|
overwritten. This option is only applicable in non-interactive mode.
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB-l\fR \fIvolser\fR or \fB--label\fR \fIvolser\fR
|
\fB-l\fR \fIvolser\fR or \fB--label\fR \fIvolser\fR
|
||||||
Specify the volume serial.
|
Specify the volume serial.
|
||||||
.br
|
.br
|
||||||
\fIvolser\fR is interpreted as ASCII string and is automatically converted to
|
\fIvolser\fR is interpreted as ASCII string and is automatically converted to
|
||||||
uppercase, padded with blanks and finally converted to EBCDIC to be written
|
uppercase, padded with blanks and finally converted to EBCDIC to be written
|
||||||
to disk. This option is only applicable in non-interactive mode.
|
to disk. This option is only applicable in non-interactive mode.
|
||||||
.br
|
.br
|
||||||
|
|
||||||
Do not use the following reserved volume serial: SCRTCH, PRIVAT, MIGRAT,
|
Do not use the following reserved volume serial: SCRTCH, PRIVAT, MIGRAT,
|
||||||
or Lnnnnn (L with five digit number); These are used as keywords by
|
or Lnnnnn (L with five digit number); These are used as keywords by
|
||||||
other operating systems (OS/390).
|
other operating systems (OS/390).
|
||||||
.br
|
.br
|
||||||
|
|
||||||
A volume serial is 1 through 6 alphanumeric characters or one of the
|
A volume serial is 1 through 6 alphanumeric characters or one of the
|
||||||
following special characters: $, #, @, %. All other characters are simply
|
following special characters: $, #, @, %. All other characters are simply
|
||||||
ignored.
|
ignored.
|
||||||
.br
|
.br
|
||||||
Try to avoid using special characters in the volume serial.
|
Try to avoid using special characters in the volume serial.
|
||||||
This may cause problems accessing a disk by volser.
|
This may cause problems accessing a disk by volser.
|
||||||
In case you really have to use special characters, make sure you are using
|
In case you really have to use special characters, make sure you are using
|
||||||
quotes. In addition there is a special handling for the '$' sign.
|
quotes. In addition there is a special handling for the '$' sign.
|
||||||
Please specify it using '\\$' if necessary.
|
Please specify it using '\\$' if necessary.
|
||||||
.br
|
.br
|
||||||
|
|
||||||
@@ -124,14 +124,14 @@ partitions that use the entire disk:
|
|||||||
.br
|
.br
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB-i\fR or \fB--volser\fR
|
\fB-i\fR or \fB--volser\fR
|
||||||
Print the volume serial, then exit.
|
Print the volume serial, then exit.
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB-p\fR or \fB--table\fR
|
\fB-p\fR or \fB--table\fR
|
||||||
Print partition table, then exit.
|
Print partition table, then exit.
|
||||||
.br
|
.br
|
||||||
In combination with the -s option fdasd will display a short version of the
|
In combination with the -s option fdasd will display a short version of the
|
||||||
partition table.
|
partition table.
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
@@ -179,7 +179,7 @@ In case your are not using the device file system, please specify:
|
|||||||
.br
|
.br
|
||||||
|
|
||||||
where \fIx\fR is one or more lowercase letter(s) or any other device
|
where \fIx\fR is one or more lowercase letter(s) or any other device
|
||||||
node specification configured by udev for kernel 2.6 or higher.
|
node specification configured by udev for kernel 2.6 or higher.
|
||||||
|
|
||||||
.SH SEE ALSO
|
.SH SEE ALSO
|
||||||
.BR dasdfmt (8)
|
.BR dasdfmt (8)
|
||||||
|
|||||||
+4
-6
@@ -3,18 +3,16 @@ include ../common.mak
|
|||||||
|
|
||||||
.DEFAULT_GOAL := all
|
.DEFAULT_GOAL := all
|
||||||
|
|
||||||
PKGDATADIR := "$(DESTDIR)$(TOOLS_DATADIR)/genprotimg"
|
PKGDATADIR := "$(TOOLS_DATADIR)/genprotimg"
|
||||||
TESTS :=
|
TESTS :=
|
||||||
SUBDIRS := boot src man
|
SUBDIRS := boot src man
|
||||||
RECURSIVE_TARGETS := all-recursive install-recursive clean-recursive
|
RECURSIVE_TARGETS := all-recursive install-recursive clean-recursive
|
||||||
|
|
||||||
all: all-recursive
|
all: all-recursive
|
||||||
|
|
||||||
install: all install-recursive
|
install: install-recursive
|
||||||
$(INSTALL) -d -m 755 "$(PKGDATADIR)"
|
$(INSTALL) -d -m 755 "$(DESTDIR)$(PKGDATADIR)"
|
||||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 boot/stage3a.bin "$(PKGDATADIR)"
|
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 755 samples/check_hostkeydoc "$(DESTDIR)$(PKGDATADIR)"
|
||||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 boot/stage3b_reloc.bin "$(PKGDATADIR)"
|
|
||||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 755 samples/check_hostkeydoc "$(PKGDATADIR)"
|
|
||||||
|
|
||||||
clean: clean-recursive
|
clean: clean-recursive
|
||||||
|
|
||||||
|
|||||||
@@ -1,8 +1,13 @@
|
|||||||
# Common definitions
|
# Common definitions
|
||||||
include ../../common.mak
|
include ../../common.mak
|
||||||
|
|
||||||
|
FILES := stage3a.bin stage3b.bin stage3b_reloc.bin
|
||||||
|
DEBUG_FILES := $(addsuffix .debug,$(FILES))
|
||||||
|
|
||||||
|
ifeq ($(HOST_ARCH),s390x)
|
||||||
ZIPL_DIR := $(rootdir)/zipl
|
ZIPL_DIR := $(rootdir)/zipl
|
||||||
ZIPL_BOOT_DIR := $(ZIPL_DIR)/boot
|
ZIPL_BOOT_DIR := $(ZIPL_DIR)/boot
|
||||||
|
PKGDATADIR := $(TOOLS_DATADIR)/genprotimg
|
||||||
|
|
||||||
INCLUDE_PATHS := $(ZIPL_BOOT_DIR) $(ZIPL_DIR)/include $(rootdir)/include
|
INCLUDE_PATHS := $(ZIPL_BOOT_DIR) $(ZIPL_DIR)/include $(rootdir)/include
|
||||||
INCLUDE_PARMS := $(addprefix -I,$(INCLUDE_PATHS))
|
INCLUDE_PARMS := $(addprefix -I,$(INCLUDE_PATHS))
|
||||||
@@ -18,8 +23,6 @@ ALL_CFLAGS := $(NO_PIE_CFLAGS) -Os -g \
|
|||||||
-Wall -Wformat-security -Wextra \
|
-Wall -Wformat-security -Wextra \
|
||||||
-Wno-array-bounds
|
-Wno-array-bounds
|
||||||
|
|
||||||
FILES := stage3a.bin stage3b.bin stage3b_reloc.bin
|
|
||||||
|
|
||||||
ZIPL_SRCS_C := libc.c ebcdic.c ebcdic_conv.c sclp.c
|
ZIPL_SRCS_C := libc.c ebcdic.c ebcdic_conv.c sclp.c
|
||||||
ZIPL_SRCS_ASM := entry.S
|
ZIPL_SRCS_ASM := entry.S
|
||||||
|
|
||||||
@@ -27,9 +30,6 @@ ZIPL_OBJS_C := $(ZIPL_SRCS_C:%.c=%.o)
|
|||||||
ZIPL_OBJS_ASM := $(ZIPL_SRCS_ASM:%.S=%.o)
|
ZIPL_OBJS_ASM := $(ZIPL_SRCS_ASM:%.S=%.o)
|
||||||
ZIPL_OBJS := $(ZIPL_OBJS_C) $(ZIPL_OBJS_ASM)
|
ZIPL_OBJS := $(ZIPL_OBJS_C) $(ZIPL_OBJS_ASM)
|
||||||
|
|
||||||
|
|
||||||
all: $(FILES)
|
|
||||||
|
|
||||||
# Prevent make from using some default rules...
|
# Prevent make from using some default rules...
|
||||||
%: %.S
|
%: %.S
|
||||||
|
|
||||||
@@ -72,15 +72,40 @@ stage3b_reloc.o: stage3b.bin
|
|||||||
stage3a.elf: head.o stage3a_init.o $(ZIPL_OBJS)
|
stage3a.elf: head.o stage3a_init.o $(ZIPL_OBJS)
|
||||||
stage3b.elf: head.o $(ZIPL_OBJS)
|
stage3b.elf: head.o $(ZIPL_OBJS)
|
||||||
|
|
||||||
|
.SECONDARY: $(FILES:.bin=.lds)
|
||||||
%.elf: %.lds %.o
|
%.elf: %.lds %.o
|
||||||
$(LINK) $(NO_PIE_LDFLAGS) $(NO_WARN_RWX_SEGMENTS_LDFLAGS) -Wl,-T,$< -Wl,--build-id=none -m64 -static -nostdlib $(filter %.o, $^) -o $@
|
$(LINK) $(NO_PIE_LDFLAGS) $(NO_WARN_RWX_SEGMENTS_LDFLAGS) -Wl,-T,$< -Wl,--build-id=none -m64 -static -nostdlib $(filter %.o, $^) -o $@
|
||||||
@chmod a-x $@
|
@chmod a-x $@
|
||||||
|
|
||||||
|
%.bin.debug: %.elf
|
||||||
|
$(OBJCOPY) --only-keep-debug $< $@
|
||||||
|
@chmod a-x $@
|
||||||
|
|
||||||
%.bin: %.elf
|
%.bin: %.elf
|
||||||
$(OBJCOPY) -O binary $< $@
|
$(OBJCOPY) -O binary $< $@
|
||||||
@chmod a-x $@
|
@chmod a-x $@
|
||||||
|
|
||||||
|
install: stage3a.bin stage3b_reloc.bin
|
||||||
|
$(INSTALL) -d -m 755 "$(DESTDIR)$(PKGDATADIR)"
|
||||||
|
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 stage3a.bin "$(DESTDIR)$(PKGDATADIR)"
|
||||||
|
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 stage3b_reloc.bin "$(DESTDIR)$(PKGDATADIR)"
|
||||||
|
|
||||||
|
else
|
||||||
|
# Don't generate the dependency files (see `common.mak` for the
|
||||||
|
# `-include $(dependencies_c)` statement).
|
||||||
|
.PHONY: $(dependencies_c)
|
||||||
|
|
||||||
|
$(FILES) $(DEBUG_FILES):
|
||||||
|
echo " SKIP $@ due to HOST_ARCH != s390x"
|
||||||
|
|
||||||
|
install:
|
||||||
|
echo " SKIP Bootloader installation due to HOST_ARCH != s390x"
|
||||||
|
endif
|
||||||
|
|
||||||
|
.DEFAULT_GOAL := all
|
||||||
|
all: $(FILES) $(DEBUG_FILES)
|
||||||
|
|
||||||
clean:
|
clean:
|
||||||
rm -f *.o *.elf *.bin *.map .*.d *.lds
|
rm -f -- *.o *.elf *.bin *.map .*.d *.lds *.debug
|
||||||
|
|
||||||
.PHONY: all clean
|
.PHONY: all clean
|
||||||
|
|||||||
@@ -11,10 +11,10 @@
|
|||||||
#include "stage3a.h"
|
#include "stage3a.h"
|
||||||
|
|
||||||
#include "lib/zt_common.h"
|
#include "lib/zt_common.h"
|
||||||
|
#include "boot/error.h"
|
||||||
#include "boot/s390.h"
|
#include "boot/s390.h"
|
||||||
#include "boot/ipl.h"
|
#include "boot/ipl.h"
|
||||||
#include "sclp.h"
|
#include "sclp.h"
|
||||||
#include "error.h"
|
|
||||||
|
|
||||||
|
|
||||||
static volatile struct stage3a_args __section(".loader_parms") loader_parms;
|
static volatile struct stage3a_args __section(".loader_parms") loader_parms;
|
||||||
|
|||||||
@@ -11,11 +11,12 @@
|
|||||||
#include "stage3b.h"
|
#include "stage3b.h"
|
||||||
|
|
||||||
#include "lib/zt_common.h"
|
#include "lib/zt_common.h"
|
||||||
|
#include "boot/psw.h"
|
||||||
|
#include "boot/error.h"
|
||||||
#include "boot/s390.h"
|
#include "boot/s390.h"
|
||||||
#include "boot/linux_layout.h"
|
#include "boot/linux_layout.h"
|
||||||
#include "boot/loaders_layout.h"
|
#include "boot/loaders_layout.h"
|
||||||
#include "sclp.h"
|
#include "sclp.h"
|
||||||
#include "error.h"
|
|
||||||
|
|
||||||
|
|
||||||
static volatile struct stage3b_args __section(".loader_parms") loader_parms;
|
static volatile struct stage3b_args __section(".loader_parms") loader_parms;
|
||||||
@@ -60,13 +61,17 @@ void __noreturn start(void)
|
|||||||
if (cmdline->size > get_kernel_cmdline_size())
|
if (cmdline->size > get_kernel_cmdline_size())
|
||||||
panic(EINTERNAL, "Command line is too large\n");
|
panic(EINTERNAL, "Command line is too large\n");
|
||||||
|
|
||||||
/* move the kernel cmdline */
|
if (cmdline->size > 0) {
|
||||||
memmove((void *)COMMAND_LINE,
|
/* make sure the cmdline is a null-terminated string */
|
||||||
(void *)cmdline->src,
|
if (((char *)cmdline->src)[cmdline->size - 1] != '\0')
|
||||||
cmdline->size);
|
panic(EINTERNAL, "Command line needs to be null-terminated\n");
|
||||||
|
|
||||||
|
/* move the kernel cmdline */
|
||||||
|
memmove((void *)COMMAND_LINE, (void *)cmdline->src, cmdline->size);
|
||||||
|
}
|
||||||
/* the initrd does not need to be moved */
|
/* the initrd does not need to be moved */
|
||||||
|
|
||||||
if (initrd->size != 0) {
|
if (initrd->size > 0) {
|
||||||
/* copy initrd start address and size into new kernel space */
|
/* copy initrd start address and size into new kernel space */
|
||||||
*(unsigned long long *)INITRD_START = initrd->src;
|
*(unsigned long long *)INITRD_START = initrd->src;
|
||||||
*(unsigned long long *)INITRD_SIZE = initrd->size;
|
*(unsigned long long *)INITRD_SIZE = initrd->size;
|
||||||
|
|||||||
@@ -21,7 +21,7 @@
|
|||||||
|
|
||||||
#include <stdint.h>
|
#include <stdint.h>
|
||||||
|
|
||||||
#include "boot/s390.h"
|
#include "boot/psw.h"
|
||||||
|
|
||||||
/* Must not have any padding included */
|
/* Must not have any padding included */
|
||||||
struct memblob {
|
struct memblob {
|
||||||
|
|||||||
@@ -97,18 +97,29 @@ Do not use for a production image unless you verified
|
|||||||
the host-key document before. Optional.
|
the host-key document before. Optional.
|
||||||
.TP
|
.TP
|
||||||
\fB\-\-comm\-key\fR=\fI\,FILE\/\fR
|
\fB\-\-comm\-key\fR=\fI\,FILE\/\fR
|
||||||
Specifies the encryption key you want to use for the PV guest dump. Use a
|
Specifies the customer communication key (CCK). This key is used for the
|
||||||
secure, random, plaintext AES-256 GCM key. Optional.
|
PV guest dump encryption and to derive the CCK-derived extension secret
|
||||||
|
used for add-secret requests. Use a secure, random, plaintext AES-256
|
||||||
|
GCM key. Optional.
|
||||||
.TP
|
.TP
|
||||||
\fB\-\-enable\-dump\fR
|
\fB\-\-enable\-dump\fR
|
||||||
Enable PV guest dumps. Requires the \fB\-\-comm-key\fR option. Optional.
|
Enable PV guest dumps. Requires the \fB\-\-comm\-key\fR option. Optional.
|
||||||
.TP
|
.TP
|
||||||
\fB\-\-disable\-dump\fR
|
\fB\-\-disable\-dump\fR
|
||||||
Disable PV guest dumps. This is the default. Optional.
|
Disable PV guest dumps. This is the default.
|
||||||
|
.TP
|
||||||
|
\fB\-\-enable\-cck\-extension\-secret\fR
|
||||||
|
Add-secret requests must provide an extension secret that matches the
|
||||||
|
CCK-derived extension secret. Requires the \fB\-\-comm\-key\fR option.
|
||||||
|
Optional.
|
||||||
|
.TP
|
||||||
|
\fB\-\-disable\-cck\-extension\-secret\fR
|
||||||
|
Add-secret requests don't have to provide an extension secret. This is
|
||||||
|
the default.
|
||||||
.TP
|
.TP
|
||||||
\fB\-\-enable\-pckmo\fR
|
\fB\-\-enable\-pckmo\fR
|
||||||
Enable the support for the DEA, TDEA, AES, and ECC PCKMO key encryption
|
Enable the support for the DEA, TDEA, AES, and ECC PCKMO key encryption
|
||||||
functions. This is the default. Optional.
|
functions. This is the default.
|
||||||
.TP
|
.TP
|
||||||
\fB\-\-disable\-pckmo\fR
|
\fB\-\-disable\-pckmo\fR
|
||||||
Disable the support for the DEA, TDEA, AES, and ECC PCKMO key encryption
|
Disable the support for the DEA, TDEA, AES, and ECC PCKMO key encryption
|
||||||
|
|||||||
+103
-100
@@ -4,7 +4,7 @@
|
|||||||
#
|
#
|
||||||
# Sample script to verify that a host key document is genuine by
|
# Sample script to verify that a host key document is genuine by
|
||||||
# verifying the issuer, the validity date and the signature.
|
# verifying the issuer, the validity date and the signature.
|
||||||
# Optionally verify the full trust chain using a CA certficate.
|
# Optionally verify the full trust chain using a CA certificate.
|
||||||
#
|
#
|
||||||
# Sample invocation:
|
# Sample invocation:
|
||||||
#
|
#
|
||||||
@@ -15,31 +15,33 @@
|
|||||||
# s390-tools is free software; you can redistribute it and/or modify
|
# s390-tools is free software; you can redistribute it and/or modify
|
||||||
# it under the terms of the MIT license. See LICENSE for details.
|
# it under the terms of the MIT license. See LICENSE for details.
|
||||||
|
|
||||||
|
|
||||||
# Allocate temporary files
|
# Allocate temporary files
|
||||||
ISSUER_PUBKEY_FILE=$(mktemp)
|
ISSUER_PUBKEY_FILE=$(mktemp)
|
||||||
SIGNATURE_FILE=$(mktemp)
|
SIGNATURE_FILE=$(mktemp)
|
||||||
BODY_FILE=$(mktemp)
|
BODY_FILE=$(mktemp)
|
||||||
ISSUER_DN_FILE=$(mktemp)
|
ISSUER_DN_FILE=$(mktemp)
|
||||||
SUBJECT_DN_FILE=$(mktemp)
|
SUBJECT_DN_FILE=$(mktemp)
|
||||||
DEF_ISSUER_DN_FILE=$(mktemp)
|
DEF_ISSUER_ARMONK_DN_FILE=$(mktemp)
|
||||||
|
DEF_ISSUER_POUGHKEEPSIE_DN_FILE=$(mktemp)
|
||||||
CANONICAL_ISSUER_DN_FILE=$(mktemp)
|
CANONICAL_ISSUER_DN_FILE=$(mktemp)
|
||||||
CRL_SERIAL_FILE=$(mktemp)
|
CRL_SERIAL_FILE=$(mktemp)
|
||||||
|
|
||||||
# Cleanup on exit
|
# Cleanup on exit
|
||||||
cleanup()
|
cleanup()
|
||||||
{
|
{
|
||||||
rm -f $ISSUER_PUBKEY_FILE $SIGNATURE_FILE $BODY_FILE \
|
rm -f "$ISSUER_PUBKEY_FILE" "$SIGNATURE_FILE" "$BODY_FILE" \
|
||||||
$ISSUER_DN_FILE $SUBJECT_DN_FILE $DEF_ISSUER_DN_FILE \
|
"$ISSUER_DN_FILE" "$SUBJECT_DN_FILE" "$DEF_ISSUER_ARMONK_DN_FILE" "$DEF_ISSUER_POUGHKEEPSIE_DN_FILE" \
|
||||||
$CANONICAL_ISSUER_DN_FILE $CRL_SERIAL_FILE
|
"$CANONICAL_ISSUER_DN_FILE" "$CRL_SERIAL_FILE"
|
||||||
}
|
}
|
||||||
trap cleanup EXIT
|
trap cleanup EXIT
|
||||||
|
|
||||||
# Enhanced error checking for bash
|
# Enhanced error checking for bash
|
||||||
if [ -n "${BASH}" ]
|
if [ -n "${BASH}" ]; then
|
||||||
then
|
# shellcheck disable=SC3040
|
||||||
set -o posix
|
set -o posix
|
||||||
|
# shellcheck disable=SC3040
|
||||||
set -o pipefail
|
set -o pipefail
|
||||||
|
# shellcheck disable=SC3040
|
||||||
set -o nounset
|
set -o nounset
|
||||||
fi
|
fi
|
||||||
set -e
|
set -e
|
||||||
@@ -47,8 +49,8 @@ set -e
|
|||||||
# Usage
|
# Usage
|
||||||
usage()
|
usage()
|
||||||
{
|
{
|
||||||
cat <<-EOF
|
cat <<-EOF
|
||||||
Usage: `basename $1` [-d] [-c CA-cert] [-r CRL] host-key-doc signing-key-cert
|
Usage: $(basename "$1") [-d] [-c CA-cert] [-r CRL] host-key-doc signing-key-cert
|
||||||
|
|
||||||
Verify an IBM Secure Execution host key document against
|
Verify an IBM Secure Execution host key document against
|
||||||
a signing key.
|
a signing key.
|
||||||
@@ -71,8 +73,7 @@ check_verify_chain()
|
|||||||
{
|
{
|
||||||
# Verify certificate chain in case a CA certificate file/bundle
|
# Verify certificate chain in case a CA certificate file/bundle
|
||||||
# was specified on the command line.
|
# was specified on the command line.
|
||||||
if [ $# = 1 ]
|
if [ -z "$2" ]; then
|
||||||
then
|
|
||||||
cat >&2 <<-EOF
|
cat >&2 <<-EOF
|
||||||
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
||||||
No CA certificate specified! Skipping trust chain verification.
|
No CA certificate specified! Skipping trust chain verification.
|
||||||
@@ -80,37 +81,37 @@ Make sure that '$1' is a valid certificate.
|
|||||||
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
||||||
EOF
|
EOF
|
||||||
else
|
else
|
||||||
openssl verify -crl_download -crl_check $2 &&
|
openssl verify -crl_download -crl_check "$2" &&
|
||||||
openssl verify -crl_download -crl_check -untrusted $2 $1 ||
|
openssl verify -crl_download -crl_check -untrusted "$2" "$1" ||
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
extract_pubkey()
|
extract_pubkey()
|
||||||
{
|
{
|
||||||
openssl x509 -in $1 -pubkey -noout > $2
|
openssl x509 -in "$1" -pubkey -noout >"$2"
|
||||||
}
|
}
|
||||||
|
|
||||||
extract_signature()
|
extract_signature()
|
||||||
{
|
{
|
||||||
# Assuming that the last field is the signature
|
# Assuming that the last field is the signature
|
||||||
SIGOFFSET=$(openssl asn1parse -in $1 | tail -1 | cut -d : -f 1)
|
SIGOFFSET=$(openssl asn1parse -in "$1" | tail -1 | cut -d : -f 1)
|
||||||
|
|
||||||
openssl asn1parse -in $1 -out $2 -strparse $SIGOFFSET -noout
|
openssl asn1parse -in "$1" -out "$2" -strparse "$SIGOFFSET" -noout
|
||||||
}
|
}
|
||||||
|
|
||||||
extract_body()
|
extract_body()
|
||||||
{
|
{
|
||||||
# Assuming that the first field is the full cert body
|
# Assuming that the first field is the full cert body
|
||||||
SIGOFFSET=$(openssl asn1parse -in $1 | head -2 | tail -1 | cut -d : -f 1)
|
SIGOFFSET=$(openssl asn1parse -in "$1" | head -2 | tail -1 | cut -d : -f 1)
|
||||||
|
|
||||||
openssl asn1parse -in $1 -out $2 -strparse $SIGOFFSET -noout
|
openssl asn1parse -in "$1" -out "$2" -strparse "$SIGOFFSET" -noout
|
||||||
}
|
}
|
||||||
|
|
||||||
verify_signature()
|
verify_signature()
|
||||||
{
|
{
|
||||||
# Assuming that the signature algorithm is SHA512 with RSA
|
# Assuming that the signature algorithm is SHA512 with RSA
|
||||||
openssl sha512 -verify $1 -signature $2 $3
|
openssl sha512 -verify "$1" -signature "$2" "$3"
|
||||||
}
|
}
|
||||||
|
|
||||||
canonical_dn()
|
canonical_dn()
|
||||||
@@ -120,18 +121,30 @@ canonical_dn()
|
|||||||
DNTYPE=$3
|
DNTYPE=$3
|
||||||
OUTPUT=$4
|
OUTPUT=$4
|
||||||
|
|
||||||
openssl $OBJTYPE -in $OBJ -$DNTYPE -noout -nameopt multiline \
|
openssl "$OBJTYPE" -in "$OBJ" -"$DNTYPE" -noout -nameopt multiline |
|
||||||
| sort | grep -v $DNTYPE= > $OUTPUT
|
LC_ALL=C sort | grep -v "$DNTYPE"= >"$OUTPUT"
|
||||||
}
|
}
|
||||||
|
|
||||||
default_issuer()
|
default_issuer_armonk()
|
||||||
|
{
|
||||||
|
cat <<-EOF
|
||||||
|
commonName = International Business Machines Corporation
|
||||||
|
countryName = US
|
||||||
|
localityName = Armonk
|
||||||
|
organizationName = International Business Machines Corporation
|
||||||
|
organizationalUnitName = Key Signing Service
|
||||||
|
stateOrProvinceName = New York
|
||||||
|
EOF
|
||||||
|
}
|
||||||
|
|
||||||
|
default_issuer_pougkeepsie()
|
||||||
{
|
{
|
||||||
cat <<-EOF
|
cat <<-EOF
|
||||||
commonName = International Business Machines Corporation
|
commonName = International Business Machines Corporation
|
||||||
countryName = US
|
countryName = US
|
||||||
localityName = Poughkeepsie
|
localityName = Poughkeepsie
|
||||||
organizationalUnitName = Key Signing Service
|
|
||||||
organizationName = International Business Machines Corporation
|
organizationName = International Business Machines Corporation
|
||||||
|
organizationalUnitName = Key Signing Service
|
||||||
stateOrProvinceName = New York
|
stateOrProvinceName = New York
|
||||||
EOF
|
EOF
|
||||||
}
|
}
|
||||||
@@ -141,42 +154,37 @@ EOF
|
|||||||
# stripping off the prefix
|
# stripping off the prefix
|
||||||
verify_default_issuer()
|
verify_default_issuer()
|
||||||
{
|
{
|
||||||
default_issuer > $DEF_ISSUER_DN_FILE
|
default_issuer_pougkeepsie >"$DEF_ISSUER_POUGHKEEPSIE_DN_FILE"
|
||||||
|
default_issuer_armonk >"$DEF_ISSUER_ARMONK_DN_FILE"
|
||||||
|
|
||||||
sed "s/\(^[ ]*organizationalUnitName[ ]*=[ ]*\).*\(Key Signing Service$\)/\1\2/" \
|
sed "s/\(^[ ]*organizationalUnitName[ ]*=[ ]*\).*\(Key Signing Service$\)/\1\2/" \
|
||||||
$ISSUER_DN_FILE > $CANONICAL_ISSUER_DN_FILE
|
"$ISSUER_DN_FILE" >"$CANONICAL_ISSUER_DN_FILE"
|
||||||
|
|
||||||
if ! diff $CANONICAL_ISSUER_DN_FILE $DEF_ISSUER_DN_FILE
|
if ! {
|
||||||
then
|
diff "$CANONICAL_ISSUER_DN_FILE" "$DEF_ISSUER_POUGHKEEPSIE_DN_FILE" ||
|
||||||
|
diff "$CANONICAL_ISSUER_DN_FILE" "$DEF_ISSUER_ARMONK_DN_FILE"
|
||||||
|
} >/dev/null 2>&1; then
|
||||||
echo Incorrect default issuer >&2 && exit 1
|
echo Incorrect default issuer >&2 && exit 1
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
verify_issuer_files()
|
verify_issuer_files()
|
||||||
{
|
{
|
||||||
if [ $1 -eq 1 ]
|
if [ "$1" -eq 1 ]; then
|
||||||
then
|
verify_default_issuer
|
||||||
verify_default_issuer
|
|
||||||
fi
|
|
||||||
|
|
||||||
if diff $ISSUER_DN_FILE $SUBJECT_DN_FILE
|
|
||||||
then
|
|
||||||
echo Issuer verification OK
|
|
||||||
else
|
|
||||||
echo Issuer verification failed >&2 && exit 1
|
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
cert_time()
|
cert_time()
|
||||||
{
|
{
|
||||||
DATE=$(openssl x509 -in $1 -$2 -noout | sed "s/^.*=//")
|
DATE=$(openssl x509 -in "$1" -"$2" -noout | sed "s/^.*=//")
|
||||||
|
|
||||||
date -d "$DATE" +%s
|
date -d "$DATE" +%s
|
||||||
}
|
}
|
||||||
|
|
||||||
crl_time()
|
crl_time()
|
||||||
{
|
{
|
||||||
DATE=$(openssl crl -in $1 -$2 -noout | sed "s/^.*=//")
|
DATE=$(openssl crl -in "$1" -"$2" -noout | sed "s/^.*=//")
|
||||||
|
|
||||||
date -d "$DATE" +%s
|
date -d "$DATE" +%s
|
||||||
}
|
}
|
||||||
@@ -188,8 +196,7 @@ verify_dates()
|
|||||||
MSG="${3:-Certificate}"
|
MSG="${3:-Certificate}"
|
||||||
NOW=$(date +%s)
|
NOW=$(date +%s)
|
||||||
|
|
||||||
if [ $START -le $NOW -a $NOW -le $END ]
|
if [ "$START" -le "$NOW" ] && [ "$NOW" -le "$END" ]; then
|
||||||
then
|
|
||||||
echo "${MSG} dates are OK"
|
echo "${MSG} dates are OK"
|
||||||
else
|
else
|
||||||
echo "${MSG} date verification failed" >&2 && exit 1
|
echo "${MSG} date verification failed" >&2 && exit 1
|
||||||
@@ -198,22 +205,21 @@ verify_dates()
|
|||||||
|
|
||||||
crl_serials()
|
crl_serials()
|
||||||
{
|
{
|
||||||
openssl crl -in $1 -text -noout | \
|
openssl crl -in "$1" -text -noout |
|
||||||
grep "Serial Number" > $CRL_SERIAL_FILE
|
grep "Serial Number" >"$CRL_SERIAL_FILE"
|
||||||
}
|
}
|
||||||
|
|
||||||
check_serial()
|
check_serial()
|
||||||
{
|
{
|
||||||
CERT_SERIAL=$(openssl x509 -in $1 -noout -serial | cut -d = -f 2)
|
CERT_SERIAL=$(openssl x509 -in "$1" -noout -serial | cut -d = -f 2)
|
||||||
|
|
||||||
grep -q $CERT_SERIAL $CRL_SERIAL_FILE
|
grep -q "$CERT_SERIAL" "$CRL_SERIAL_FILE"
|
||||||
}
|
}
|
||||||
|
|
||||||
check_file()
|
check_file()
|
||||||
{
|
{
|
||||||
[ $# = 0 ] ||
|
|
||||||
[ -e "$1" ] ||
|
[ -e "$1" ] ||
|
||||||
(echo "File '$1' not found" >&2 && exit 1)
|
(echo "File '$1' not found" >&2 && exit 1)
|
||||||
}
|
}
|
||||||
|
|
||||||
# check args
|
# check args
|
||||||
@@ -221,28 +227,25 @@ CRL_FILE=
|
|||||||
CA_FILE=
|
CA_FILE=
|
||||||
CHECK_DEFAULT_ISSUER=1
|
CHECK_DEFAULT_ISSUER=1
|
||||||
|
|
||||||
args=$(getopt -qu "dr:c:h" $*)
|
while getopts 'dr:c:h' opt; do
|
||||||
if [ $? = 0 ]
|
case $opt in
|
||||||
then
|
d) CHECK_DEFAULT_ISSUER=0 ;;
|
||||||
set -- $args
|
r) CRL_FILE=$OPTARG ;;
|
||||||
while [ $1 != "" ]
|
c) CA_FILE=$OPTARG ;;
|
||||||
do
|
h)
|
||||||
case $1 in
|
usage "$0"
|
||||||
-d) CHECK_DEFAULT_ISSUER=0; shift;;
|
exit 0
|
||||||
-r) CRL_FILE=$2; shift 2;;
|
;;
|
||||||
-c) CA_FILE=$2; shift 2;;
|
?)
|
||||||
-h) usage $0; exit 0;;
|
usage "$0"
|
||||||
--) shift; break;;
|
exit 1
|
||||||
esac
|
;;
|
||||||
done
|
esac
|
||||||
else
|
done
|
||||||
usage $0 >&2
|
shift "$((OPTIND - 1))"
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ $# -ne 2 ]
|
if [ $# -ne 2 ]; then
|
||||||
then
|
usage "$0" >&2
|
||||||
usage $0 >&2
|
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -250,51 +253,51 @@ HKD_FILE=$1
|
|||||||
HKSK_FILE=$2
|
HKSK_FILE=$2
|
||||||
|
|
||||||
# Check whether all specified files exist
|
# Check whether all specified files exist
|
||||||
check_file $HKD_FILE
|
check_file "$HKD_FILE"
|
||||||
check_file $HKSK_FILE
|
check_file "$HKSK_FILE"
|
||||||
check_file $CA_FILE
|
# CA and CRL are optional arguments
|
||||||
check_file $CRL_FILE
|
[ -n "$CA_FILE" ] && check_file "$CA_FILE"
|
||||||
|
[ -n "$CRL_FILE" ] && check_file "$CRL_FILE"
|
||||||
|
|
||||||
# Check trust chain
|
# Check trust chain
|
||||||
check_verify_chain $HKSK_FILE $CA_FILE
|
check_verify_chain "$HKSK_FILE" "$CA_FILE"
|
||||||
|
|
||||||
# Verify host key document signature
|
# Verify host key document signature
|
||||||
echo -n "Checking host key document signature: "
|
printf "Checking host key document signature: "
|
||||||
extract_pubkey $HKSK_FILE $ISSUER_PUBKEY_FILE &&
|
extract_pubkey "$HKSK_FILE" "$ISSUER_PUBKEY_FILE" &&
|
||||||
extract_signature $HKD_FILE $SIGNATURE_FILE &&
|
extract_signature "$HKD_FILE" "$SIGNATURE_FILE" &&
|
||||||
extract_body $HKD_FILE $BODY_FILE &&
|
extract_body "$HKD_FILE" "$BODY_FILE" &&
|
||||||
verify_signature $ISSUER_PUBKEY_FILE $SIGNATURE_FILE $BODY_FILE ||
|
verify_signature "$ISSUER_PUBKEY_FILE" "$SIGNATURE_FILE" "$BODY_FILE" ||
|
||||||
exit 1
|
exit 1
|
||||||
|
|
||||||
# Verify the issuer
|
# Verify the issuer
|
||||||
canonical_dn x509 $HKD_FILE issuer $ISSUER_DN_FILE
|
canonical_dn x509 "$HKD_FILE" issuer "$ISSUER_DN_FILE"
|
||||||
canonical_dn x509 $HKSK_FILE subject $SUBJECT_DN_FILE
|
canonical_dn x509 "$HKSK_FILE" subject "$SUBJECT_DN_FILE"
|
||||||
verify_issuer_files $CHECK_DEFAULT_ISSUER
|
verify_issuer_files $CHECK_DEFAULT_ISSUER
|
||||||
|
|
||||||
# Verify dates
|
# Verify dates
|
||||||
verify_dates $(cert_time $HKD_FILE startdate) $(cert_time $HKD_FILE enddate)
|
verify_dates "$(cert_time "$HKD_FILE" startdate)" "$(cert_time "$HKD_FILE" enddate)"
|
||||||
|
|
||||||
# Check CRL if specified
|
# Check CRL if specified
|
||||||
if [ -n "$CRL_FILE" ]
|
if [ -n "$CRL_FILE" ]; then
|
||||||
then
|
printf "Checking CRL signature: "
|
||||||
echo -n "Checking CRL signature: "
|
extract_signature "$CRL_FILE" "$SIGNATURE_FILE" &&
|
||||||
extract_signature $CRL_FILE $SIGNATURE_FILE &&
|
extract_body "$CRL_FILE" "$BODY_FILE" &&
|
||||||
extract_body $CRL_FILE $BODY_FILE &&
|
verify_signature "$ISSUER_PUBKEY_FILE" "$SIGNATURE_FILE" "$BODY_FILE" ||
|
||||||
verify_signature $ISSUER_PUBKEY_FILE $SIGNATURE_FILE $BODY_FILE ||
|
exit 1
|
||||||
exit 1
|
|
||||||
|
|
||||||
echo -n "CRL "
|
printf "CRL "
|
||||||
canonical_dn crl $CRL_FILE issuer $ISSUER_DN_FILE
|
canonical_dn crl "$CRL_FILE" issuer "$ISSUER_DN_FILE"
|
||||||
canonical_dn x509 $HKSK_FILE subject $SUBJECT_DN_FILE
|
canonical_dn x509 "$HKSK_FILE" subject "$SUBJECT_DN_FILE"
|
||||||
verify_issuer_files $CHECK_DEFAULT_ISSUER
|
verify_issuer_files $CHECK_DEFAULT_ISSUER
|
||||||
|
|
||||||
verify_dates $(crl_time $CRL_FILE lastupdate) $(crl_time $CRL_FILE nextupdate) 'CRL'
|
verify_dates "$(crl_time "$CRL_FILE" lastupdate)" "$(crl_time "$CRL_FILE" nextupdate)" 'CRL'
|
||||||
|
|
||||||
crl_serials $CRL_FILE
|
crl_serials "$CRL_FILE"
|
||||||
check_serial $HKD_FILE &&
|
check_serial "$HKD_FILE" &&
|
||||||
echo "Certificate is revoked, do not use it anymore!" >&2 &&
|
echo "Certificate is revoked, do not use it anymore!" >&2 &&
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# We made it
|
# We made it
|
||||||
echo All checks reqested for \'$HKD_FILE\' were successful
|
echo All checks requested for \'"$HKD_FILE"\' were successful
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ include ../../common.mak
|
|||||||
|
|
||||||
bin_PROGRAM = genprotimg
|
bin_PROGRAM = genprotimg
|
||||||
|
|
||||||
PKGDATADIR ?= "$(DESTDIR)$(TOOLS_DATADIR)/genprotimg"
|
PKGDATADIR ?= "$(TOOLS_DATADIR)/genprotimg"
|
||||||
SRC_DIR := $(dir $(realpath $(firstword $(MAKEFILE_LIST))))
|
SRC_DIR := $(dir $(realpath $(firstword $(MAKEFILE_LIST))))
|
||||||
TOP_SRCDIR := $(SRC_DIR)/../
|
TOP_SRCDIR := $(SRC_DIR)/../
|
||||||
ROOT_DIR = $(TOP_SRC_DIR)/../../
|
ROOT_DIR = $(TOP_SRC_DIR)/../../
|
||||||
@@ -27,7 +27,7 @@ $(bin_PROGRAM)_SRCS := $(bin_PROGRAM).c pv/pv_stage3.c pv/pv_image.c \
|
|||||||
$(NULL)
|
$(NULL)
|
||||||
$(bin_PROGRAM)_OBJS := $($(bin_PROGRAM)_SRCS:.c=.o)
|
$(bin_PROGRAM)_OBJS := $($(bin_PROGRAM)_SRCS:.c=.o)
|
||||||
|
|
||||||
ALL_CFLAGS += -std=gnu11 -DPKGDATADIR=$(PKGDATADIR) \
|
ALL_CFLAGS += -DPKGDATADIR=$(PKGDATADIR) \
|
||||||
$(GLIB2_CFLAGS) $(LIBCRYPTO_CFLAGS) $(LIBCURL_CFLAGS) \
|
$(GLIB2_CFLAGS) $(LIBCRYPTO_CFLAGS) $(LIBCURL_CFLAGS) \
|
||||||
-DOPENSSL_API_COMPAT=0x10100000L \
|
-DOPENSSL_API_COMPAT=0x10100000L \
|
||||||
$(WARNINGS) \
|
$(WARNINGS) \
|
||||||
|
|||||||
@@ -13,7 +13,6 @@
|
|||||||
#include <glib/gi18n.h>
|
#include <glib/gi18n.h>
|
||||||
|
|
||||||
#include "boot/linux_layout.h"
|
#include "boot/linux_layout.h"
|
||||||
#include "boot/s390.h"
|
|
||||||
#include "lib/zt_common.h"
|
#include "lib/zt_common.h"
|
||||||
|
|
||||||
static const gchar tool_name[] = "genprotimg";
|
static const gchar tool_name[] = "genprotimg";
|
||||||
|
|||||||
@@ -17,7 +17,8 @@
|
|||||||
/* IBM signing key subject */
|
/* IBM signing key subject */
|
||||||
#define PV_IBM_Z_SUBJECT_COMMON_NAME "International Business Machines Corporation"
|
#define PV_IBM_Z_SUBJECT_COMMON_NAME "International Business Machines Corporation"
|
||||||
#define PV_IBM_Z_SUBJECT_COUNTRY_NAME "US"
|
#define PV_IBM_Z_SUBJECT_COUNTRY_NAME "US"
|
||||||
#define PV_IBM_Z_SUBJECT_LOCALITY_NAME "Poughkeepsie"
|
#define PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE "Poughkeepsie"
|
||||||
|
#define PV_IBM_Z_SUBJECT_LOCALITY_NAME_ARMONK "Armonk"
|
||||||
#define PV_IBM_Z_SUBJECT_ORGANIZATIONONAL_UNIT_NAME_SUFFIX "Key Signing Service"
|
#define PV_IBM_Z_SUBJECT_ORGANIZATIONONAL_UNIT_NAME_SUFFIX "Key Signing Service"
|
||||||
#define PV_IBM_Z_SUBJECT_ORGANIZATION_NAME "International Business Machines Corporation"
|
#define PV_IBM_Z_SUBJECT_ORGANIZATION_NAME "International Business Machines Corporation"
|
||||||
#define PV_IBM_Z_SUBJECT_STATE "New York"
|
#define PV_IBM_Z_SUBJECT_STATE "New York"
|
||||||
|
|||||||
@@ -12,7 +12,7 @@
|
|||||||
|
|
||||||
#include <openssl/sha.h>
|
#include <openssl/sha.h>
|
||||||
|
|
||||||
#include "boot/s390.h"
|
#include "boot/psw.h"
|
||||||
#include "lib/zt_common.h"
|
#include "lib/zt_common.h"
|
||||||
#include "utils/crypto.h"
|
#include "utils/crypto.h"
|
||||||
|
|
||||||
@@ -34,6 +34,10 @@
|
|||||||
#define PV_PCF_PCKMO_AES __PV_BIT(57) /* PCKMO encrypt-AES-key functions allowed */
|
#define PV_PCF_PCKMO_AES __PV_BIT(57) /* PCKMO encrypt-AES-key functions allowed */
|
||||||
#define PV_PCF_PCKM_ECC __PV_BIT(58) /* PCKMO encrypt-ECC-key functions allowed */
|
#define PV_PCF_PCKM_ECC __PV_BIT(58) /* PCKMO encrypt-ECC-key functions allowed */
|
||||||
|
|
||||||
|
/* Secret control flags */
|
||||||
|
#define PV_SCF_CCK_EXTENSION_SECRET_ENFORCMENT \
|
||||||
|
__PV_BIT(1) /* All add-secret requests must provide an extension secret */
|
||||||
|
|
||||||
/* maxima for the PV version 1 */
|
/* maxima for the PV version 1 */
|
||||||
#define PV_V1_IPIB_MAX_SIZE PAGE_SIZE
|
#define PV_V1_IPIB_MAX_SIZE PAGE_SIZE
|
||||||
#define PV_V1_PV_HDR_MAX_SIZE (2 * PAGE_SIZE)
|
#define PV_V1_PV_HDR_MAX_SIZE (2 * PAGE_SIZE)
|
||||||
|
|||||||
+81
-58
@@ -62,11 +62,12 @@ static gint pv_args_set_defaults(PvArgs *args, GError **err G_GNUC_UNUSED)
|
|||||||
|
|
||||||
static gint pv_args_validate_options(PvArgs *args, GError **err)
|
static gint pv_args_validate_options(PvArgs *args, GError **err)
|
||||||
{
|
{
|
||||||
|
const PvControlFlagsArgs *cf_args = &args->cf_args;
|
||||||
PvComponentType KERNEL = PV_COMP_TYPE_KERNEL;
|
PvComponentType KERNEL = PV_COMP_TYPE_KERNEL;
|
||||||
|
|
||||||
/* Check for mutually exclusive arguments */
|
/* Check for mutually exclusive arguments */
|
||||||
if (args->pcf && !(args->allow_pckmo == PV_NOT_SET &&
|
if (cf_args->pcf &&
|
||||||
args->allow_dump == PV_NOT_SET)) {
|
!(cf_args->enable_pckmo == PV_NOT_SET && cf_args->enable_dump == PV_NOT_SET)) {
|
||||||
g_set_error(
|
g_set_error(
|
||||||
err, PV_PARSE_ERROR, PV_PARSE_ERROR_SYNTAX,
|
err, PV_PARSE_ERROR, PV_PARSE_ERROR_SYNTAX,
|
||||||
_("The '--x-pcf' option cannot be used with the '--(enable|disable)-pckmo' or"
|
_("The '--x-pcf' option cannot be used with the '--(enable|disable)-pckmo' or"
|
||||||
@@ -74,6 +75,13 @@ static gint pv_args_validate_options(PvArgs *args, GError **err)
|
|||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (cf_args->scf && !(cf_args->enable_cck_extension_secret_enforcement == PV_NOT_SET)) {
|
||||||
|
g_set_error(
|
||||||
|
err, PV_PARSE_ERROR, PV_PARSE_ERROR_SYNTAX,
|
||||||
|
_("The '--x-scf' option cannot be used with the '--(enable|disable)-extension-secret-required' flags.\nUse 'genprotimg --help' for more information"));
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
|
|
||||||
/* Check for unused arguments */
|
/* Check for unused arguments */
|
||||||
if (args->unused_values->len > 0) {
|
if (args->unused_values->len > 0) {
|
||||||
g_autofree gchar *unused = NULL;
|
g_autofree gchar *unused = NULL;
|
||||||
@@ -93,12 +101,20 @@ static gint pv_args_validate_options(PvArgs *args, GError **err)
|
|||||||
}
|
}
|
||||||
|
|
||||||
/* Check for mandatory arguments */
|
/* Check for mandatory arguments */
|
||||||
if (args->allow_dump == PV_TRUE && !args->cust_comm_key_path) {
|
if (cf_args->enable_dump == PV_TRUE && !args->cust_comm_key_path) {
|
||||||
g_set_error(err, PV_PARSE_ERROR, PR_PARSE_ERROR_MISSING_ARGUMENT,
|
g_set_error(err, PV_PARSE_ERROR, PR_PARSE_ERROR_MISSING_ARGUMENT,
|
||||||
_("Option '--allow-dump' requires the '--comm-key' option.\nUse 'genprotimg "
|
_("Option '--enable-dump' requires the '--comm-key' option.\nUse 'genprotimg "
|
||||||
"--help' for more information"));
|
"--help' for more information"));
|
||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
|
if (cf_args->enable_cck_extension_secret_enforcement == PV_TRUE &&
|
||||||
|
!args->cust_comm_key_path) {
|
||||||
|
g_set_error(
|
||||||
|
err, PV_PARSE_ERROR, PR_PARSE_ERROR_MISSING_ARGUMENT,
|
||||||
|
_("Option '--enable-cck-extension-secret' requires the '--comm-key' option.\nUse 'genprotimg "
|
||||||
|
"--help' for more information"));
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
|
|
||||||
if (!args->output_path) {
|
if (!args->output_path) {
|
||||||
g_set_error(err, PV_PARSE_ERROR, PR_PARSE_ERROR_MISSING_ARGUMENT,
|
g_set_error(err, PV_PARSE_ERROR, PR_PARSE_ERROR_MISSING_ARGUMENT,
|
||||||
@@ -178,11 +194,11 @@ static gboolean cb_set_string_option(const gchar *option, const gchar *value,
|
|||||||
if (g_str_equal(option, "--x-header-key"))
|
if (g_str_equal(option, "--x-header-key"))
|
||||||
args_option = &args->cust_root_key_path;
|
args_option = &args->cust_root_key_path;
|
||||||
if (g_str_equal(option, "--x-pcf"))
|
if (g_str_equal(option, "--x-pcf"))
|
||||||
args_option = &args->pcf;
|
args_option = &args->cf_args.pcf;
|
||||||
if (g_str_equal(option, "--x-psw"))
|
if (g_str_equal(option, "--x-psw"))
|
||||||
args_option = &args->psw_addr;
|
args_option = &args->psw_addr;
|
||||||
if (g_str_equal(option, "--x-scf"))
|
if (g_str_equal(option, "--x-scf"))
|
||||||
args_option = &args->scf;
|
args_option = &args->cf_args.scf;
|
||||||
|
|
||||||
if (!args_option) {
|
if (!args_option) {
|
||||||
g_set_error(err, PV_PARSE_ERROR, PV_PARSE_ERROR_SYNTAX,
|
g_set_error(err, PV_PARSE_ERROR, PV_PARSE_ERROR_SYNTAX,
|
||||||
@@ -217,49 +233,48 @@ static gboolean cb_remaining_values(const gchar *option G_GNUC_UNUSED,
|
|||||||
}
|
}
|
||||||
|
|
||||||
#define MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, VALUE) (cb_##FLAG##_##VALUE)
|
#define MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, VALUE) (cb_##FLAG##_##VALUE)
|
||||||
#define DEFINE_MUT_EXCL_BOOL_FLAG_CB(FLAG, VALUE) \
|
#define DEFINE_MUT_EXCL_BOOL_FLAG_CB(FLAG, VALUE) \
|
||||||
static gboolean MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, VALUE)( \
|
static gboolean MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, VALUE)(const gchar *option G_GNUC_UNUSED, \
|
||||||
const gchar *option G_GNUC_UNUSED, const gchar *value G_GNUC_UNUSED, \
|
const gchar *value G_GNUC_UNUSED, \
|
||||||
PvArgs *args, GError **err) \
|
PvArgs *args, GError **err) \
|
||||||
{ \
|
{ \
|
||||||
if (!(args->allow_##FLAG == PV_NOT_SET || \
|
if (!(args->cf_args.enable_##FLAG == PV_NOT_SET || \
|
||||||
args->allow_##FLAG == VALUE)) { \
|
args->cf_args.enable_##FLAG == VALUE)) { \
|
||||||
g_set_error(err, G_OPTION_ERROR, G_OPTION_ERROR_FAILED, \
|
g_set_error(err, G_OPTION_ERROR, G_OPTION_ERROR_FAILED, \
|
||||||
"'--enable-" #FLAG "' and '--disable-" #FLAG \
|
"'--enable-" #FLAG "' and '--disable-" #FLAG \
|
||||||
"' are mutually exclusive"); \
|
"' are mutually exclusive"); \
|
||||||
return FALSE; \
|
return FALSE; \
|
||||||
} \
|
} \
|
||||||
args->allow_##FLAG = VALUE; \
|
args->cf_args.enable_##FLAG = VALUE; \
|
||||||
return TRUE; \
|
return TRUE; \
|
||||||
}
|
}
|
||||||
|
|
||||||
#define DEFINE_MUT_EXCL_BOOL_FLAG_CBS(FLAG) \
|
#define DEFINE_MUT_EXCL_BOOL_FLAG_CBS(FLAG) \
|
||||||
DEFINE_MUT_EXCL_BOOL_FLAG_CB(FLAG, PV_TRUE) \
|
DEFINE_MUT_EXCL_BOOL_FLAG_CB(FLAG, PV_TRUE) \
|
||||||
DEFINE_MUT_EXCL_BOOL_FLAG_CB(FLAG, PV_FALSE)
|
DEFINE_MUT_EXCL_BOOL_FLAG_CB(FLAG, PV_FALSE)
|
||||||
|
|
||||||
#define MUT_EXCL_BOOL_FLAG(FLAG, ENABLE_DESC, DISABLE_DESC) \
|
#define MUT_EXCL_BOOL_FLAG(NAME, FLAG, ENABLE_DESC, DISABLE_DESC) \
|
||||||
{ \
|
{ \
|
||||||
.long_name = "enable-" #FLAG, \
|
.long_name = "enable-" #NAME, \
|
||||||
.short_name = 0, \
|
.short_name = 0, \
|
||||||
.flags = G_OPTION_FLAG_NO_ARG, \
|
.flags = G_OPTION_FLAG_NO_ARG, \
|
||||||
.arg = G_OPTION_ARG_CALLBACK, \
|
.arg = G_OPTION_ARG_CALLBACK, \
|
||||||
.arg_data = MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, PV_TRUE), \
|
.arg_data = MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, PV_TRUE), \
|
||||||
.description = ENABLE_DESC, \
|
.description = ENABLE_DESC, \
|
||||||
}, \
|
}, \
|
||||||
{ \
|
{ \
|
||||||
.long_name = "disable-" #FLAG, \
|
.long_name = "disable-" #NAME, .short_name = 0, .flags = G_OPTION_FLAG_NO_ARG, \
|
||||||
.short_name = 0, \
|
.arg = G_OPTION_ARG_CALLBACK, \
|
||||||
.flags = G_OPTION_FLAG_NO_ARG, \
|
.arg_data = MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, PV_FALSE), \
|
||||||
.arg = G_OPTION_ARG_CALLBACK, \
|
.description = DISABLE_DESC, \
|
||||||
.arg_data = MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, PV_FALSE), \
|
|
||||||
.description = DISABLE_DESC, \
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#define INDENT " "
|
#define INDENT " "
|
||||||
|
|
||||||
/* Define the callbacks for mutually exclusive command line flags */
|
/* Define the callbacks for mutually exclusive command line flags */
|
||||||
DEFINE_MUT_EXCL_BOOL_FLAG_CBS(dump)
|
DEFINE_MUT_EXCL_BOOL_FLAG_CBS(dump);
|
||||||
DEFINE_MUT_EXCL_BOOL_FLAG_CBS(pckmo)
|
DEFINE_MUT_EXCL_BOOL_FLAG_CBS(pckmo);
|
||||||
|
DEFINE_MUT_EXCL_BOOL_FLAG_CBS(cck_extension_secret_enforcement);
|
||||||
|
|
||||||
gint pv_args_parse_options(PvArgs *args, gint *argc, gchar **argv[],
|
gint pv_args_parse_options(PvArgs *args, gint *argc, gchar **argv[],
|
||||||
GError **err)
|
GError **err)
|
||||||
@@ -280,7 +295,7 @@ gint pv_args_parse_options(PvArgs *args, gint *argc, gchar **argv[],
|
|||||||
.arg_data = &args->host_keys,
|
.arg_data = &args->host_keys,
|
||||||
.description =
|
.description =
|
||||||
_("FILE specifies a host-key document. At least\n" INDENT
|
_("FILE specifies a host-key document. At least\n" INDENT
|
||||||
"one is required Specify this option multiple times\n" INDENT
|
"one is required. Specify this option multiple times\n" INDENT
|
||||||
"to enable the image to run on more than one host."),
|
"to enable the image to run on more than one host."),
|
||||||
.arg_description = _("FILE") },
|
.arg_description = _("FILE") },
|
||||||
{ .long_name = "cert",
|
{ .long_name = "cert",
|
||||||
@@ -325,27 +340,31 @@ gint pv_args_parse_options(PvArgs *args, gint *argc, gchar **argv[],
|
|||||||
.description = _("Use the kernel parameters stored in PARMFILE\n" INDENT
|
.description = _("Use the kernel parameters stored in PARMFILE\n" INDENT
|
||||||
"(optional)."),
|
"(optional)."),
|
||||||
.arg_description = _("PARMFILE") },
|
.arg_description = _("PARMFILE") },
|
||||||
|
MUT_EXCL_BOOL_FLAG(dump, dump,
|
||||||
|
_("Enable PV guest dumps (optional). This option\n" INDENT
|
||||||
|
"requires the '--comm-key' option."),
|
||||||
|
_("Disable PV guest dumps (default).")),
|
||||||
MUT_EXCL_BOOL_FLAG(
|
MUT_EXCL_BOOL_FLAG(
|
||||||
dump,
|
cck-extension-secret, cck_extension_secret_enforcement,
|
||||||
_("Enable PV guest dumps (optional). This option\n" INDENT
|
_("Add-secret requests must provide an extension\n" INDENT
|
||||||
"requires the '--comm-key' option."),
|
"secret that matches the CCK-derived extension\n" INDENT
|
||||||
_("Disable PV guest dumps (default) (optional).")),
|
"secret (optional). This option requires the\n" INDENT
|
||||||
MUT_EXCL_BOOL_FLAG(
|
"'--comm-key' option."),
|
||||||
pckmo,
|
_("Add-secret requests don't have to provide\n" INDENT
|
||||||
_("Enable the support for the DEA, TDEA, AES, and\n" INDENT
|
"the CCK-derived extension secret (default).")),
|
||||||
"ECC PCKMO key encryption functions (default)\n" INDENT
|
MUT_EXCL_BOOL_FLAG(pckmo, pckmo,
|
||||||
"(optional)."),
|
_("Enable the support for the DEA, TDEA, AES, and\n" INDENT
|
||||||
_("Disable the support for the DEA, TDEA, AES, and\n" INDENT
|
"ECC PCKMO key encryption functions (default)."),
|
||||||
"ECC PCKMO key encryption functions (optional).")),
|
_("Disable the support for the DEA, TDEA, AES, and\n" INDENT
|
||||||
|
"ECC PCKMO key encryption functions (optional).")),
|
||||||
{ .long_name = "comm-key",
|
{ .long_name = "comm-key",
|
||||||
.short_name = 0,
|
.short_name = 0,
|
||||||
.flags = G_OPTION_FLAG_FILENAME,
|
.flags = G_OPTION_FLAG_FILENAME,
|
||||||
.arg = G_OPTION_ARG_CALLBACK,
|
.arg = G_OPTION_ARG_CALLBACK,
|
||||||
.arg_data = cb_set_string_option,
|
.arg_data = cb_set_string_option,
|
||||||
.description = _(
|
.description = _(
|
||||||
"FILE contains the key with which you encrypt\n" INDENT
|
"FILE contains the customer communication key\n" INDENT
|
||||||
"the PV guest dump (optional). Required by\n" INDENT
|
"(CCK) (optional)."),
|
||||||
"the '--enable-dump' option."),
|
|
||||||
.arg_description = _("FILE") },
|
.arg_description = _("FILE") },
|
||||||
{ .long_name = "crl",
|
{ .long_name = "crl",
|
||||||
.short_name = 0,
|
.short_name = 0,
|
||||||
@@ -450,6 +469,8 @@ gint pv_args_parse_options(PvArgs *args, gint *argc, gchar **argv[],
|
|||||||
.arg_data = cb_set_string_option,
|
.arg_data = cb_set_string_option,
|
||||||
.description = _("Specify the secret control flags\n" INDENT
|
.description = _("Specify the secret control flags\n" INDENT
|
||||||
"as a hexadecimal value.\n" INDENT
|
"as a hexadecimal value.\n" INDENT
|
||||||
|
"Optional; mutually exclusive with\n" INDENT
|
||||||
|
"'--(enable|disable)-cck-extension-secret';\n" INDENT
|
||||||
"Optional; default: '0x0'."),
|
"Optional; default: '0x0'."),
|
||||||
.arg_description = _("VALUE") },
|
.arg_description = _("VALUE") },
|
||||||
{ 0 },
|
{ 0 },
|
||||||
@@ -487,8 +508,10 @@ PvArgs *pv_args_new(void)
|
|||||||
g_autoptr(PvArgs) args = g_new0(PvArgs, 1);
|
g_autoptr(PvArgs) args = g_new0(PvArgs, 1);
|
||||||
|
|
||||||
args->unused_values = g_ptr_array_new_with_free_func(g_free);
|
args->unused_values = g_ptr_array_new_with_free_func(g_free);
|
||||||
args->allow_dump = PV_NOT_SET;
|
/* `args->cf_args` is implicitly initialized with zeros since
|
||||||
args->allow_pckmo = PV_NOT_SET;
|
* `g_new0` is used. So there is no reason to explicitly
|
||||||
|
* initialize the values as PV_NOT_SET == 0.
|
||||||
|
*/
|
||||||
return g_steal_pointer(&args);
|
return g_steal_pointer(&args);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -497,8 +520,8 @@ void pv_args_free(PvArgs *args)
|
|||||||
if (!args)
|
if (!args)
|
||||||
return;
|
return;
|
||||||
|
|
||||||
g_free(args->pcf);
|
g_free(args->cf_args.pcf);
|
||||||
g_free(args->scf);
|
g_free(args->cf_args.scf);
|
||||||
g_free(args->psw_addr);
|
g_free(args->psw_addr);
|
||||||
g_free(args->cust_root_key_path);
|
g_free(args->cust_root_key_path);
|
||||||
g_free(args->cust_comm_key_path);
|
g_free(args->cust_comm_key_path);
|
||||||
|
|||||||
@@ -23,19 +23,27 @@ PvArg *pv_arg_new(PvComponentType type, const gchar *path);
|
|||||||
void pv_arg_free(PvArg *arg);
|
void pv_arg_free(PvArg *arg);
|
||||||
|
|
||||||
typedef enum pv_tristate {
|
typedef enum pv_tristate {
|
||||||
PV_NOT_SET = 0,
|
PV_NOT_SET = 0,
|
||||||
PV_TRUE,
|
PV_TRUE,
|
||||||
PV_FALSE,
|
PV_FALSE,
|
||||||
} PvTristate;
|
} PvTristate;
|
||||||
|
/* The value of PV_NOT_SET is not allowed to be changed */
|
||||||
|
STATIC_ASSERT(PV_NOT_SET == 0)
|
||||||
|
|
||||||
|
typedef struct {
|
||||||
|
gchar *pcf;
|
||||||
|
gchar *scf;
|
||||||
|
/* Add-secret requests do require CCK-extension secrets */
|
||||||
|
PvTristate enable_cck_extension_secret_enforcement;
|
||||||
|
PvTristate enable_dump;
|
||||||
|
PvTristate enable_pckmo;
|
||||||
|
} PvControlFlagsArgs;
|
||||||
|
|
||||||
typedef struct {
|
typedef struct {
|
||||||
gint log_level;
|
gint log_level;
|
||||||
gint no_verify;
|
gint no_verify;
|
||||||
gboolean offline;
|
gboolean offline;
|
||||||
gchar *pcf;
|
PvControlFlagsArgs cf_args;
|
||||||
gchar *scf;
|
|
||||||
PvTristate allow_dump;
|
|
||||||
PvTristate allow_pckmo;
|
|
||||||
gchar *psw_addr; /* PSW address which will be used for the start of
|
gchar *psw_addr; /* PSW address which will be used for the start of
|
||||||
* the actual component (e.g. Linux kernel)
|
* the actual component (e.g. Linux kernel)
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -15,7 +15,6 @@
|
|||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
|
|
||||||
#include "boot/s390.h"
|
|
||||||
#include "common.h"
|
#include "common.h"
|
||||||
#include "utils/align.h"
|
#include "utils/align.h"
|
||||||
#include "utils/buffer.h"
|
#include "utils/buffer.h"
|
||||||
|
|||||||
@@ -12,7 +12,7 @@
|
|||||||
#include <openssl/evp.h>
|
#include <openssl/evp.h>
|
||||||
#include <stdint.h>
|
#include <stdint.h>
|
||||||
|
|
||||||
#include "boot/s390.h"
|
#include "boot/psw.h"
|
||||||
#include "boot/stage3b.h"
|
#include "boot/stage3b.h"
|
||||||
#include "common.h"
|
#include "common.h"
|
||||||
#include "utils/align.h"
|
#include "utils/align.h"
|
||||||
|
|||||||
@@ -14,7 +14,7 @@
|
|||||||
#include <openssl/evp.h>
|
#include <openssl/evp.h>
|
||||||
#include <stdint.h>
|
#include <stdint.h>
|
||||||
|
|
||||||
#include "boot/s390.h"
|
#include "boot/psw.h"
|
||||||
#include "boot/stage3b.h"
|
#include "boot/stage3b.h"
|
||||||
#include "utils/buffer.h"
|
#include "utils/buffer.h"
|
||||||
|
|
||||||
|
|||||||
@@ -14,7 +14,7 @@
|
|||||||
#include <stdint.h>
|
#include <stdint.h>
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
|
|
||||||
#include "boot/s390.h"
|
#include "boot/psw.h"
|
||||||
#include "include/pv_crypto_def.h"
|
#include "include/pv_crypto_def.h"
|
||||||
#include "utils/buffer.h"
|
#include "utils/buffer.h"
|
||||||
#include "utils/crypto.h"
|
#include "utils/crypto.h"
|
||||||
|
|||||||
@@ -13,7 +13,6 @@
|
|||||||
#include <glib.h>
|
#include <glib.h>
|
||||||
#include <stdint.h>
|
#include <stdint.h>
|
||||||
|
|
||||||
#include "boot/s390.h"
|
|
||||||
#include "include/pv_hdr_def.h"
|
#include "include/pv_hdr_def.h"
|
||||||
#include "utils/crypto.h"
|
#include "utils/crypto.h"
|
||||||
#include "utils/buffer.h"
|
#include "utils/buffer.h"
|
||||||
|
|||||||
@@ -15,7 +15,7 @@
|
|||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
|
|
||||||
#include "boot/s390.h"
|
#include "boot/psw.h"
|
||||||
#include "boot/stage3a.h"
|
#include "boot/stage3a.h"
|
||||||
#include "common.h"
|
#include "common.h"
|
||||||
#include "include/pv_crypto_def.h"
|
#include "include/pv_crypto_def.h"
|
||||||
@@ -228,37 +228,40 @@ static gint pv_img_set_psw_addr(PvImage *img, const gchar *psw_addr_s,
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
static gint pv_img_set_control_flags(PvImage *img, const gchar *pcf_s,
|
static void pv_img_set_control_flag(uint64_t *flags, const PvTristate option, const uint64_t flag)
|
||||||
const gchar *scf_s,
|
{
|
||||||
PvTristate allow_dump,
|
if (option == PV_TRUE)
|
||||||
PvTristate allow_pckmo, GError **err)
|
*flags |= flag;
|
||||||
|
else if (option == PV_FALSE)
|
||||||
|
*flags &= ~flag;
|
||||||
|
}
|
||||||
|
|
||||||
|
static gint pv_img_set_control_flags(PvImage *img, const PvControlFlagsArgs *cf_args, GError **err)
|
||||||
{
|
{
|
||||||
uint64_t flags;
|
uint64_t flags;
|
||||||
|
|
||||||
if (pcf_s) {
|
/* Set plain control flags */
|
||||||
if (hex_str_toull(pcf_s, &flags, err) < 0)
|
if (cf_args->pcf) {
|
||||||
|
if (hex_str_toull(cf_args->pcf, &flags, err) < 0)
|
||||||
return -1;
|
return -1;
|
||||||
|
|
||||||
img->pcf = flags;
|
img->pcf = flags;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (scf_s) {
|
pv_img_set_control_flag(&img->pcf, cf_args->enable_dump, PV_PCF_ALLOW_DUMPING);
|
||||||
if (hex_str_toull(scf_s, &flags, err) < 0)
|
pv_img_set_control_flag(&img->pcf, cf_args->enable_pckmo,
|
||||||
|
PV_PCF_PCKM_ECC | PV_PCF_PCKMO_AES | PV_PCF_PCKMO_DEA_TDEA);
|
||||||
|
|
||||||
|
/* Set secret control flags */
|
||||||
|
if (cf_args->scf) {
|
||||||
|
if (hex_str_toull(cf_args->scf, &flags, err) < 0)
|
||||||
return -1;
|
return -1;
|
||||||
|
|
||||||
img->scf = flags;
|
img->scf = flags;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (allow_dump == PV_TRUE)
|
pv_img_set_control_flag(&img->scf, cf_args->enable_cck_extension_secret_enforcement,
|
||||||
img->pcf |= PV_PCF_ALLOW_DUMPING;
|
PV_SCF_CCK_EXTENSION_SECRET_ENFORCMENT);
|
||||||
else if (allow_dump == PV_FALSE)
|
|
||||||
img->pcf &= ~PV_PCF_ALLOW_DUMPING;
|
|
||||||
|
|
||||||
if (allow_pckmo == PV_TRUE)
|
|
||||||
img->pcf |= PV_PCF_PCKM_ECC | PV_PCF_PCKMO_AES | PV_PCF_PCKMO_DEA_TDEA;
|
|
||||||
else if (allow_pckmo == PV_FALSE)
|
|
||||||
img->pcf &= ~(PV_PCF_PCKM_ECC | PV_PCF_PCKMO_AES | PV_PCF_PCKMO_DEA_TDEA);
|
|
||||||
|
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -610,9 +613,7 @@ PvImage *pv_img_new(PvArgs *args, const gchar *stage3a_path, GError **err)
|
|||||||
return NULL;
|
return NULL;
|
||||||
|
|
||||||
/* set the control flags: PCF and SCF */
|
/* set the control flags: PCF and SCF */
|
||||||
if (pv_img_set_control_flags(ret, args->pcf, args->scf,
|
if (pv_img_set_control_flags(ret, &args->cf_args, err) < 0)
|
||||||
args->allow_dump, args->allow_pckmo,
|
|
||||||
err) < 0)
|
|
||||||
return NULL;
|
return NULL;
|
||||||
|
|
||||||
/* read in the keys */
|
/* read in the keys */
|
||||||
@@ -683,7 +684,26 @@ gint pv_img_add_component(PvImage *img, const PvArg *arg, GError **err)
|
|||||||
{
|
{
|
||||||
g_autoptr(PvComponent) comp = NULL;
|
g_autoptr(PvComponent) comp = NULL;
|
||||||
|
|
||||||
comp = pv_component_new_file(arg->type, arg->path, err);
|
switch (arg->type) {
|
||||||
|
case PV_COMP_TYPE_INITRD:
|
||||||
|
case PV_COMP_TYPE_KERNEL:
|
||||||
|
case PV_COMP_TYPE_STAGE3B:
|
||||||
|
comp = pv_component_new_file(arg->type, arg->path, err);
|
||||||
|
break;
|
||||||
|
case PV_COMP_TYPE_CMDLINE: {
|
||||||
|
g_autoptr(PvBuffer) buf = NULL;
|
||||||
|
g_autofree char *data = NULL;
|
||||||
|
gsize length;
|
||||||
|
|
||||||
|
if (!g_file_get_contents(arg->path, &data, &length, err))
|
||||||
|
return -1;
|
||||||
|
|
||||||
|
/* Add one for the null terminator */
|
||||||
|
buf = pv_buffer_take(g_steal_pointer(&data), length + 1);
|
||||||
|
comp = pv_component_new_buf(arg->type, buf, err);
|
||||||
|
} break;
|
||||||
|
}
|
||||||
|
|
||||||
if (!comp)
|
if (!comp)
|
||||||
return -1;
|
return -1;
|
||||||
|
|
||||||
|
|||||||
@@ -15,7 +15,7 @@
|
|||||||
#include <openssl/evp.h>
|
#include <openssl/evp.h>
|
||||||
#include <stdint.h>
|
#include <stdint.h>
|
||||||
|
|
||||||
#include "boot/s390.h"
|
#include "boot/psw.h"
|
||||||
#include "utils/buffer.h"
|
#include "utils/buffer.h"
|
||||||
|
|
||||||
#include "pv_args.h"
|
#include "pv_args.h"
|
||||||
|
|||||||
@@ -13,7 +13,6 @@
|
|||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
|
|
||||||
#include "boot/ipl.h"
|
#include "boot/ipl.h"
|
||||||
#include "boot/s390.h"
|
|
||||||
#include "common.h"
|
#include "common.h"
|
||||||
#include "include/pv_hdr_def.h"
|
#include "include/pv_hdr_def.h"
|
||||||
#include "lib/zt_common.h"
|
#include "lib/zt_common.h"
|
||||||
@@ -60,7 +59,7 @@ static gint pv_ipib_init(IplParameterBlock *ipib, GSList *comps,
|
|||||||
ipib_size = MAX(ipl_pl_hdr_size + blk0_len, (uint32_t)PAGE_SIZE);
|
ipib_size = MAX(ipl_pl_hdr_size + blk0_len, (uint32_t)PAGE_SIZE);
|
||||||
g_assert(pv_ipib_get_size(comps_length) == ipib_size);
|
g_assert(pv_ipib_get_size(comps_length) == ipib_size);
|
||||||
|
|
||||||
pv->pbt = IPL_TYPE_PV;
|
pv->pbt = IPL_PBT_PV;
|
||||||
pv->len = GUINT32_TO_BE(blk0_len);
|
pv->len = GUINT32_TO_BE(blk0_len);
|
||||||
pv->num_comp = GUINT32_TO_BE(comps_length);
|
pv->num_comp = GUINT32_TO_BE(comps_length);
|
||||||
/* both values will be overwritten during the IPL process by
|
/* both values will be overwritten during the IPL process by
|
||||||
|
|||||||
@@ -15,7 +15,6 @@
|
|||||||
#include <stdint.h>
|
#include <stdint.h>
|
||||||
|
|
||||||
#include "boot/ipl.h"
|
#include "boot/ipl.h"
|
||||||
#include "boot/s390.h"
|
|
||||||
#include "boot/stage3b.h"
|
#include "boot/stage3b.h"
|
||||||
#include "utils/buffer.h"
|
#include "utils/buffer.h"
|
||||||
|
|
||||||
|
|||||||
@@ -10,8 +10,8 @@
|
|||||||
#ifndef PV_UTILS_ALIGN_H
|
#ifndef PV_UTILS_ALIGN_H
|
||||||
#define PV_UTILS_ALIGN_H
|
#define PV_UTILS_ALIGN_H
|
||||||
|
|
||||||
#include "boot/s390.h"
|
|
||||||
#include "lib/zt_common.h"
|
#include "lib/zt_common.h"
|
||||||
|
#include "boot/page.h"
|
||||||
|
|
||||||
#define IS_ALIGNED(addr, size) (!(addr & (size - 1)))
|
#define IS_ALIGNED(addr, size) (!(addr & (size - 1)))
|
||||||
|
|
||||||
|
|||||||
@@ -26,6 +26,15 @@ PvBuffer *pv_buffer_alloc(gsize size)
|
|||||||
return ret;
|
return ret;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
PvBuffer *pv_buffer_take(char *data, gsize size)
|
||||||
|
{
|
||||||
|
PvBuffer *ret = g_new0(PvBuffer, 1);
|
||||||
|
|
||||||
|
ret->data = data;
|
||||||
|
ret->size = size;
|
||||||
|
return ret;
|
||||||
|
}
|
||||||
|
|
||||||
PvBuffer *pv_buffer_dup(const PvBuffer *buf, gboolean page_aligned)
|
PvBuffer *pv_buffer_dup(const PvBuffer *buf, gboolean page_aligned)
|
||||||
{
|
{
|
||||||
PvBuffer *ret;
|
PvBuffer *ret;
|
||||||
|
|||||||
@@ -21,6 +21,10 @@ typedef struct PvBuffer {
|
|||||||
} PvBuffer;
|
} PvBuffer;
|
||||||
|
|
||||||
PvBuffer *pv_buffer_alloc(gsize size);
|
PvBuffer *pv_buffer_alloc(gsize size);
|
||||||
|
/* After this call @data belongs to the PvBuffer and must no longer be modified
|
||||||
|
* by the caller.
|
||||||
|
*/
|
||||||
|
PvBuffer *pv_buffer_take(char *data, gsize size);
|
||||||
void pv_buffer_free(PvBuffer *buf);
|
void pv_buffer_free(PvBuffer *buf);
|
||||||
void pv_buffer_clear(PvBuffer **buf);
|
void pv_buffer_clear(PvBuffer **buf);
|
||||||
gint pv_buffer_write(const PvBuffer *buf, FILE *file, GError **err);
|
gint pv_buffer_write(const PvBuffer *buf, FILE *file, GError **err);
|
||||||
|
|||||||
+103
-113
@@ -24,7 +24,7 @@
|
|||||||
#include <stdint.h>
|
#include <stdint.h>
|
||||||
#include <string.h>
|
#include <string.h>
|
||||||
|
|
||||||
#include "boot/s390.h"
|
#include "boot/page.h"
|
||||||
#include "common.h"
|
#include "common.h"
|
||||||
#include "include/pv_crypto_def.h"
|
#include "include/pv_crypto_def.h"
|
||||||
#include "pv/pv_error.h"
|
#include "pv/pv_error.h"
|
||||||
@@ -664,62 +664,9 @@ static gboolean x509_name_data_by_nid_equal(X509_NAME *name, gint nid,
|
|||||||
return memcmp(data, y, data_len) == 0;
|
return memcmp(data, y, data_len) == 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
static gboolean own_X509_NAME_ENTRY_equal(const X509_NAME_ENTRY *x,
|
|
||||||
const X509_NAME_ENTRY *y)
|
|
||||||
{
|
|
||||||
const ASN1_OBJECT *x_obj = X509_NAME_ENTRY_get_object(x);
|
|
||||||
const ASN1_STRING *x_data = X509_NAME_ENTRY_get_data(x);
|
|
||||||
const ASN1_OBJECT *y_obj = X509_NAME_ENTRY_get_object(y);
|
|
||||||
const ASN1_STRING *y_data = X509_NAME_ENTRY_get_data(y);
|
|
||||||
gint x_len = ASN1_STRING_length(x_data);
|
|
||||||
gint y_len = ASN1_STRING_length(y_data);
|
|
||||||
|
|
||||||
if (x_len < 0 || x_len != y_len)
|
|
||||||
return FALSE;
|
|
||||||
|
|
||||||
/* ASN1_STRING_cmp(x_data, y_data) == 0 doesn't work because it also
|
|
||||||
* compares the type, which is sometimes different.
|
|
||||||
*/
|
|
||||||
return OBJ_cmp(x_obj, y_obj) == 0 &&
|
|
||||||
memcmp(ASN1_STRING_get0_data(x_data),
|
|
||||||
ASN1_STRING_get0_data(y_data),
|
|
||||||
(unsigned long)x_len) == 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
static gboolean own_X509_NAME_equal(const X509_NAME *x, const X509_NAME *y)
|
|
||||||
{
|
|
||||||
gint x_count = X509_NAME_entry_count(x);
|
|
||||||
gint y_count = X509_NAME_entry_count(y);
|
|
||||||
|
|
||||||
if (x != y && (!x || !y))
|
|
||||||
return FALSE;
|
|
||||||
|
|
||||||
if (x_count != y_count)
|
|
||||||
return FALSE;
|
|
||||||
|
|
||||||
for (gint i = 0; i < x_count; i++) {
|
|
||||||
const X509_NAME_ENTRY *entry_i = X509_NAME_get_entry(x, i);
|
|
||||||
gboolean entry_found = FALSE;
|
|
||||||
|
|
||||||
for (gint j = 0; j < y_count; j++) {
|
|
||||||
const X509_NAME_ENTRY *entry_j =
|
|
||||||
X509_NAME_get_entry(y, j);
|
|
||||||
|
|
||||||
if (own_X509_NAME_ENTRY_equal(entry_i, entry_j)) {
|
|
||||||
entry_found = TRUE;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!entry_found)
|
|
||||||
return FALSE;
|
|
||||||
}
|
|
||||||
return TRUE;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Checks whether the subject of @cert is a IBM signing key subject. For this we
|
/* Checks whether the subject of @cert is a IBM signing key subject. For this we
|
||||||
* must check that the subject is equal to: 'C = US, ST = New York, L =
|
* must check that the subject is equal to: 'C = US, ST = New York, L =
|
||||||
* Poughkeepsie, O = International Business Machines Corporation, CN =
|
* Poughkeepsie or Armonk, O = International Business Machines Corporation, CN =
|
||||||
* International Business Machines Corporation' and the organization unit (OUT)
|
* International Business Machines Corporation' and the organization unit (OUT)
|
||||||
* must end with the suffix ' Key Signing Service'.
|
* must end with the suffix ' Key Signing Service'.
|
||||||
*/
|
*/
|
||||||
@@ -743,8 +690,10 @@ static gboolean has_ibm_signing_subject(X509 *cert)
|
|||||||
PV_IBM_Z_SUBJECT_STATE))
|
PV_IBM_Z_SUBJECT_STATE))
|
||||||
return FALSE;
|
return FALSE;
|
||||||
|
|
||||||
if (!x509_name_data_by_nid_equal(subject, NID_localityName,
|
if (!(x509_name_data_by_nid_equal(subject, NID_localityName,
|
||||||
PV_IBM_Z_SUBJECT_LOCALITY_NAME))
|
PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE) ||
|
||||||
|
x509_name_data_by_nid_equal(subject, NID_localityName,
|
||||||
|
PV_IBM_Z_SUBJECT_LOCALITY_NAME_ARMONK)))
|
||||||
return FALSE;
|
return FALSE;
|
||||||
|
|
||||||
if (!x509_name_data_by_nid_equal(subject, NID_organizationName,
|
if (!x509_name_data_by_nid_equal(subject, NID_organizationName,
|
||||||
@@ -806,6 +755,39 @@ static X509_NAME *x509_name_reorder_attributes(const X509_NAME *name, const gint
|
|||||||
return g_steal_pointer(&ret);
|
return g_steal_pointer(&ret);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/** Replace locality 'Armonk' with 'Pougkeepsie'. If Armonk was not set return
|
||||||
|
* `NULL`.
|
||||||
|
*/
|
||||||
|
static X509_NAME *x509_armonk_locality_fixup(const X509_NAME *name)
|
||||||
|
{
|
||||||
|
g_autoptr(X509_NAME) ret = NULL;
|
||||||
|
int pos;
|
||||||
|
|
||||||
|
/* Check if ``L=Armonk`` */
|
||||||
|
if (!x509_name_data_by_nid_equal((X509_NAME *)name, NID_localityName,
|
||||||
|
PV_IBM_Z_SUBJECT_LOCALITY_NAME_ARMONK))
|
||||||
|
return NULL;
|
||||||
|
|
||||||
|
ret = X509_NAME_dup((X509_NAME *)name);
|
||||||
|
if (!ret)
|
||||||
|
g_abort();
|
||||||
|
|
||||||
|
pos = X509_NAME_get_index_by_NID(ret, NID_localityName, -1);
|
||||||
|
if (pos == -1)
|
||||||
|
return NULL;
|
||||||
|
|
||||||
|
X509_NAME_ENTRY_free(X509_NAME_delete_entry(ret, pos));
|
||||||
|
|
||||||
|
/* Create a new name entry at the same position as before */
|
||||||
|
if (X509_NAME_add_entry_by_NID(
|
||||||
|
ret, NID_localityName, MBSTRING_UTF8,
|
||||||
|
(const unsigned char *)&PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE,
|
||||||
|
sizeof(PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE) - 1, pos, 0) != 1)
|
||||||
|
return NULL;
|
||||||
|
|
||||||
|
return g_steal_pointer(&ret);
|
||||||
|
}
|
||||||
|
|
||||||
/* In RFC 5280 the attributes of a (subject/issuer) name is not mandatory
|
/* In RFC 5280 the attributes of a (subject/issuer) name is not mandatory
|
||||||
* ordered. The problem is that our certificates are not consistent in the order
|
* ordered. The problem is that our certificates are not consistent in the order
|
||||||
* (see https://tools.ietf.org/html/rfc5280#section-4.1.2.4 for details).
|
* (see https://tools.ietf.org/html/rfc5280#section-4.1.2.4 for details).
|
||||||
@@ -828,24 +810,10 @@ X509_NAME *c2b_name(const X509_NAME *name)
|
|||||||
return X509_NAME_dup((X509_NAME *)name);
|
return X509_NAME_dup((X509_NAME *)name);
|
||||||
}
|
}
|
||||||
|
|
||||||
/* Verify that: subject(issuer) == issuer(crl) and SKID(issuer) == AKID(crl) */
|
/* Verify that SKID(issuer) == AKID(crl) if available */
|
||||||
static gint check_crl_issuer(X509_CRL *crl, X509 *issuer, GError **err)
|
static gint check_crl_issuer(X509_CRL *crl, X509 *issuer, GError **err)
|
||||||
{
|
{
|
||||||
const X509_NAME *crl_issuer = X509_CRL_get_issuer(crl);
|
g_autoptr(AUTHORITY_KEYID) akid = NULL;
|
||||||
const X509_NAME *issuer_subject = X509_get_subject_name(issuer);
|
|
||||||
AUTHORITY_KEYID *akid = NULL;
|
|
||||||
|
|
||||||
if (!own_X509_NAME_equal(issuer_subject, crl_issuer)) {
|
|
||||||
g_autofree char *issuer_subject_str = X509_NAME_oneline(issuer_subject,
|
|
||||||
NULL, 0);
|
|
||||||
g_autofree char *crl_issuer_str = X509_NAME_oneline(crl_issuer, NULL, 0);
|
|
||||||
|
|
||||||
g_set_error(err, PV_CRYPTO_ERROR,
|
|
||||||
PV_CRYPTO_ERROR_CRL_SUBJECT_ISSUER_MISMATCH,
|
|
||||||
_("issuer mismatch:\n%s\n%s"),
|
|
||||||
issuer_subject_str, crl_issuer_str);
|
|
||||||
return -1;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* If AKID(@crl) is specified it must match with SKID(@issuer) */
|
/* If AKID(@crl) is specified it must match with SKID(@issuer) */
|
||||||
akid = X509_CRL_get_ext_d2i(crl, NID_authority_key_identifier, NULL, NULL);
|
akid = X509_CRL_get_ext_d2i(crl, NID_authority_key_identifier, NULL, NULL);
|
||||||
@@ -881,7 +849,6 @@ gint check_crl_valid_for_cert(X509_CRL *crl, X509 *cert,
|
|||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* check that the @crl issuer matches with the subject name of @cert*/
|
|
||||||
if (check_crl_issuer(crl, cert, err) < 0)
|
if (check_crl_issuer(crl, cert, err) < 0)
|
||||||
return -1;
|
return -1;
|
||||||
|
|
||||||
@@ -910,6 +877,60 @@ gint check_crl_valid_for_cert(X509_CRL *crl, X509 *cert,
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* This function contains work-arounds for some known subject(CRT)<->issuer(CRL)
|
||||||
|
* issues.
|
||||||
|
*/
|
||||||
|
static STACK_OF_X509_CRL *quirk_X509_STORE_ctx_get1_crls(X509_STORE_CTX *ctx,
|
||||||
|
const X509_NAME *subject, GError **err)
|
||||||
|
{
|
||||||
|
g_autoptr(X509_NAME) fixed_subject = NULL;
|
||||||
|
g_autoptr(STACK_OF_X509_CRL) ret = NULL;
|
||||||
|
|
||||||
|
ret = Pv_X509_STORE_CTX_get1_crls(ctx, subject);
|
||||||
|
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||||
|
return g_steal_pointer(&ret);
|
||||||
|
|
||||||
|
/* Workaround to fix the mismatch between issuer name of the * IBM
|
||||||
|
* signing CRLs and the IBM signing key subject name. Locality name has
|
||||||
|
* changed from Poughkeepsie to Armonk.
|
||||||
|
*/
|
||||||
|
fixed_subject = x509_armonk_locality_fixup(subject);
|
||||||
|
/* Was the locality replaced? */
|
||||||
|
if (fixed_subject) {
|
||||||
|
X509_NAME *tmp;
|
||||||
|
|
||||||
|
sk_X509_CRL_free(ret);
|
||||||
|
ret = Pv_X509_STORE_CTX_get1_crls(ctx, fixed_subject);
|
||||||
|
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||||
|
return g_steal_pointer(&ret);
|
||||||
|
|
||||||
|
/* Workaround to fix the ordering mismatch between issuer name
|
||||||
|
* of the IBM signing CRLs and the IBM signing key subject name.
|
||||||
|
*/
|
||||||
|
tmp = fixed_subject;
|
||||||
|
fixed_subject = c2b_name(fixed_subject);
|
||||||
|
X509_NAME_free(tmp);
|
||||||
|
sk_X509_CRL_free(ret);
|
||||||
|
ret = Pv_X509_STORE_CTX_get1_crls(ctx, fixed_subject);
|
||||||
|
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||||
|
return g_steal_pointer(&ret);
|
||||||
|
X509_NAME_free(fixed_subject);
|
||||||
|
fixed_subject = NULL;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Workaround to fix the ordering mismatch between issuer name of the
|
||||||
|
* IBM signing CRLs and the IBM signing key subject name.
|
||||||
|
*/
|
||||||
|
fixed_subject = c2b_name(subject);
|
||||||
|
sk_X509_CRL_free(ret);
|
||||||
|
ret = Pv_X509_STORE_CTX_get1_crls(ctx, fixed_subject);
|
||||||
|
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||||
|
return g_steal_pointer(&ret);
|
||||||
|
|
||||||
|
g_set_error(err, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_NO_CRL, _("no CRL found"));
|
||||||
|
return NULL;
|
||||||
|
}
|
||||||
|
|
||||||
/* Given a certificate @cert try to find valid revocation lists in @ctx. If no
|
/* Given a certificate @cert try to find valid revocation lists in @ctx. If no
|
||||||
* valid CRL was found NULL is returned.
|
* valid CRL was found NULL is returned.
|
||||||
*/
|
*/
|
||||||
@@ -927,20 +948,9 @@ STACK_OF_X509_CRL *store_ctx_find_valid_crls(X509_STORE_CTX *ctx, X509 *cert,
|
|||||||
return NULL;
|
return NULL;
|
||||||
}
|
}
|
||||||
|
|
||||||
ret = X509_STORE_CTX_get1_crls(ctx, subject);
|
ret = quirk_X509_STORE_ctx_get1_crls(ctx, subject, err);
|
||||||
if (!ret) {
|
if (!ret)
|
||||||
/* Workaround to fix the mismatch between issuer name of the
|
return NULL;
|
||||||
* IBM Z signing CRLs and the IBM Z signing key subject name.
|
|
||||||
*/
|
|
||||||
g_autoptr(X509_NAME) broken_subject = c2b_name(subject);
|
|
||||||
|
|
||||||
ret = X509_STORE_CTX_get1_crls(ctx, broken_subject);
|
|
||||||
if (!ret) {
|
|
||||||
g_set_error(err, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_NO_CRL,
|
|
||||||
_("no CRL found"));
|
|
||||||
return NULL;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Filter out non-valid CRLs for @cert */
|
/* Filter out non-valid CRLs for @cert */
|
||||||
for (gint i = 0; i < sk_X509_CRL_num(ret); i++) {
|
for (gint i = 0; i < sk_X509_CRL_num(ret); i++) {
|
||||||
@@ -1328,32 +1338,14 @@ gint check_chain_parameters(const STACK_OF_X509 *chain,
|
|||||||
|
|
||||||
/* It's almost the same as X509_check_issed from OpenSSL does except that we
|
/* It's almost the same as X509_check_issed from OpenSSL does except that we
|
||||||
* don't check the key usage of the potential issuer. This means we check:
|
* don't check the key usage of the potential issuer. This means we check:
|
||||||
* 1. issuer_name(cert) == subject_name(issuer)
|
* 1. Check whether the akid(cert) (if available) matches the issuer skid
|
||||||
* 2. Check whether the akid(cert) (if available) matches the issuer skid
|
* 2. Check that the cert algrithm matches the subject algorithm
|
||||||
* 3. Check that the cert algrithm matches the subject algorithm
|
* 3. Verify the signature of certificate @cert is using the public key of
|
||||||
* 4. Verify the signature of certificate @cert is using the public key of
|
|
||||||
* @issuer.
|
* @issuer.
|
||||||
*/
|
*/
|
||||||
static gint check_host_key_issued(X509 *cert, X509 *issuer, GError **err)
|
static gint check_host_key_issued(X509 *cert, X509 *issuer, GError **err)
|
||||||
{
|
{
|
||||||
const X509_NAME *issuer_subject = X509_get_subject_name(issuer);
|
g_autoptr(AUTHORITY_KEYID) akid = NULL;
|
||||||
const X509_NAME *cert_issuer = X509_get_issuer_name(cert);
|
|
||||||
AUTHORITY_KEYID *akid = NULL;
|
|
||||||
|
|
||||||
/* We cannot use X509_NAME_cmp() because it considers the order of the
|
|
||||||
* X509_NAME_Entries.
|
|
||||||
*/
|
|
||||||
if (!own_X509_NAME_equal(issuer_subject, cert_issuer)) {
|
|
||||||
g_autofree char *issuer_subject_str =
|
|
||||||
X509_NAME_oneline(issuer_subject, NULL, 0);
|
|
||||||
g_autofree char *cert_issuer_str =
|
|
||||||
X509_NAME_oneline(cert_issuer, NULL, 0);
|
|
||||||
g_set_error(err, PV_CRYPTO_ERROR,
|
|
||||||
PV_CRYPTO_ERROR_CERT_SUBJECT_ISSUER_MISMATCH,
|
|
||||||
_("Subject issuer mismatch:\n'%s'\n'%s'"),
|
|
||||||
issuer_subject_str, cert_issuer_str);
|
|
||||||
return -1;
|
|
||||||
}
|
|
||||||
|
|
||||||
akid = X509_get_ext_d2i(cert, NID_authority_key_identifier, NULL, NULL);
|
akid = X509_get_ext_d2i(cert, NID_authority_key_identifier, NULL, NULL);
|
||||||
if (akid && X509_check_akid(issuer, akid) != X509_V_OK) {
|
if (akid && X509_check_akid(issuer, akid) != X509_V_OK) {
|
||||||
@@ -1834,14 +1826,12 @@ static gint __encrypt_decrypt_bio(const struct cipher_parms *parms, BIO *b_in,
|
|||||||
g_assert(out_len >= 0);
|
g_assert(out_len >= 0);
|
||||||
|
|
||||||
num_bytes_written = BIO_write(b_out, out_buf, out_len);
|
num_bytes_written = BIO_write(b_out, out_buf, out_len);
|
||||||
if (num_bytes_written < 0) {
|
if (num_bytes_written != out_len) {
|
||||||
g_set_error(err, PV_CRYPTO_ERROR,
|
g_set_error(err, PV_CRYPTO_ERROR,
|
||||||
PV_CRYPTO_ERROR_INTERNAL,
|
PV_CRYPTO_ERROR_INTERNAL,
|
||||||
_("Failed to write"));
|
_("Failed to write"));
|
||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
g_assert(num_bytes_written == out_len);
|
|
||||||
|
|
||||||
tmp_size_out += (guint)num_bytes_written;
|
tmp_size_out += (guint)num_bytes_written;
|
||||||
|
|
||||||
/* Set new tweak value. Please keep in mind that the
|
/* Set new tweak value. Please keep in mind that the
|
||||||
|
|||||||
@@ -75,6 +75,7 @@ void x509_pair_free(x509_pair *pair);
|
|||||||
/* Register auto cleanup functions */
|
/* Register auto cleanup functions */
|
||||||
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(ASN1_INTEGER, ASN1_INTEGER_free)
|
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(ASN1_INTEGER, ASN1_INTEGER_free)
|
||||||
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(ASN1_OCTET_STRING, ASN1_OCTET_STRING_free)
|
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(ASN1_OCTET_STRING, ASN1_OCTET_STRING_free)
|
||||||
|
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(AUTHORITY_KEYID, AUTHORITY_KEYID_free)
|
||||||
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(BIGNUM, BN_free)
|
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(BIGNUM, BN_free)
|
||||||
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(BIO, BIO_free_all)
|
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(BIO, BIO_free_all)
|
||||||
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(BN_CTX, BN_CTX_free)
|
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(BN_CTX, BN_CTX_free)
|
||||||
|
|||||||
@@ -116,6 +116,7 @@ static void l_sd_cpu_fill(struct sd_cpu *cpu, struct l_x_cpu_info *cpu_info,
|
|||||||
int threads)
|
int threads)
|
||||||
{
|
{
|
||||||
sd_cpu_cpu_time_us_set(cpu, cpu_info->lp_time);
|
sd_cpu_cpu_time_us_set(cpu, cpu_info->lp_time);
|
||||||
|
sd_cpu_threads_per_core_set(cpu, threads);
|
||||||
if (threads > 1)
|
if (threads > 1)
|
||||||
sd_cpu_thread_time_us_set(cpu,
|
sd_cpu_thread_time_us_set(cpu,
|
||||||
cpu_info->lp_time * threads - cpu_info->mt_idle_time);
|
cpu_info->lp_time * threads - cpu_info->mt_idle_time);
|
||||||
@@ -297,6 +298,7 @@ static struct sd_sys_item *l_sys_item_vec[] = {
|
|||||||
&sd_sys_item_thread_cnt,
|
&sd_sys_item_thread_cnt,
|
||||||
&sd_sys_item_core_diff,
|
&sd_sys_item_core_diff,
|
||||||
&sd_sys_item_thread_diff,
|
&sd_sys_item_thread_diff,
|
||||||
|
&sd_sys_item_smt_diff,
|
||||||
&sd_sys_item_mgm_diff,
|
&sd_sys_item_mgm_diff,
|
||||||
&sd_sys_item_core,
|
&sd_sys_item_core,
|
||||||
&sd_sys_item_thread,
|
&sd_sys_item_thread,
|
||||||
@@ -326,6 +328,7 @@ static struct sd_cpu_item *l_cpu_item_vec[] = {
|
|||||||
&sd_cpu_item_type,
|
&sd_cpu_item_type,
|
||||||
&sd_cpu_item_core_diff,
|
&sd_cpu_item_core_diff,
|
||||||
&sd_cpu_item_thread_diff,
|
&sd_cpu_item_thread_diff,
|
||||||
|
&sd_cpu_item_smt_diff,
|
||||||
&sd_cpu_item_mgm_diff,
|
&sd_cpu_item_mgm_diff,
|
||||||
&sd_cpu_item_core,
|
&sd_cpu_item_core,
|
||||||
&sd_cpu_item_thread,
|
&sd_cpu_item_thread,
|
||||||
|
|||||||
@@ -391,3 +391,24 @@ void hyptop_helper_init(void)
|
|||||||
if (l_iconv_ebcdic_ascii == (iconv_t) -1)
|
if (l_iconv_ebcdic_ascii == (iconv_t) -1)
|
||||||
ERR_EXIT("Could not initialize iconv\n");
|
ERR_EXIT("Could not initialize iconv\n");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Calculate real SMT utilization
|
||||||
|
* @core_us: core utilization in us
|
||||||
|
* @thr_us: thread utilization in us
|
||||||
|
* @mgm_us: management utilization in us
|
||||||
|
* @thread_per_core: SMT thread count per core
|
||||||
|
*/
|
||||||
|
s64 ht_calculate_smt_util(u64 core_us, u64 thr_us, u64 mgm_us, int thread_per_core)
|
||||||
|
{
|
||||||
|
s64 component1, component2, smt_us;
|
||||||
|
double smt_factor = g.o.smt_factor;
|
||||||
|
|
||||||
|
component1 = thread_per_core * core_us - thr_us;
|
||||||
|
if (thread_per_core > 1)
|
||||||
|
component1 /= smt_factor;
|
||||||
|
component2 = thr_us - core_us;
|
||||||
|
smt_us = G0(component1 + component2 + mgm_us);
|
||||||
|
|
||||||
|
return smt_us;
|
||||||
|
}
|
||||||
|
|||||||
@@ -34,6 +34,7 @@ extern void ht_ebcdic_to_ascii(char *in, char *out, size_t len);
|
|||||||
extern char *ht_mount_point_get(const char *fs_type);
|
extern char *ht_mount_point_get(const char *fs_type);
|
||||||
extern u64 ht_ext_tod_2_us(void *tod_ext);
|
extern u64 ht_ext_tod_2_us(void *tod_ext);
|
||||||
extern void ht_print_time(void);
|
extern void ht_print_time(void);
|
||||||
|
extern s64 ht_calculate_smt_util(u64 core_us, u64 thr_us, u64 mgm_us, int thread_per_core);
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Memory alloc functions
|
* Memory alloc functions
|
||||||
|
|||||||
@@ -74,6 +74,18 @@ In this mode no user input is accepted.
|
|||||||
.BR "\-d <SECONDS>" " or " "\-\-delay=<SECONDS>"
|
.BR "\-d <SECONDS>" " or " "\-\-delay=<SECONDS>"
|
||||||
Specifies the delay between screen updates.
|
Specifies the delay between screen updates.
|
||||||
.TP
|
.TP
|
||||||
|
.BR "\-m <FACTOR>" " or " "\-\-smt_factor=<FACTOR>"
|
||||||
|
Specifies a workload dependent SMT speedup factor.
|
||||||
|
For IBM z15 servers, the default value is 1.3. If the workload benefits
|
||||||
|
from SMT, you can specify a higher value. If the workload does not benefit
|
||||||
|
from SMT, specifying lower values results in more accurate reports of
|
||||||
|
real CPU SMT utilization field for LPARs. There is no hard boundary except
|
||||||
|
that it must be a positive value. Example ranges to select a sensible value
|
||||||
|
from:
|
||||||
|
|
||||||
|
For IBM z13: [0.8, 1.3]
|
||||||
|
For IBM z15: [1.1, 1.5]
|
||||||
|
.TP
|
||||||
.BR "\-n <ITERATIONS>" " or " "\-\-iterations=<ITERATIONS>"
|
.BR "\-n <ITERATIONS>" " or " "\-\-iterations=<ITERATIONS>"
|
||||||
Specifies the maximum number of iterations before ending.
|
Specifies the maximum number of iterations before ending.
|
||||||
|
|
||||||
@@ -119,6 +131,7 @@ The following fields are available under LPAR:
|
|||||||
In "sys_list" and "sys" window:
|
In "sys_list" and "sys" window:
|
||||||
'c' - Core dispatch time per second
|
'c' - Core dispatch time per second
|
||||||
'e' - Thread time per second
|
'e' - Thread time per second
|
||||||
|
'S' - Real CPU SMT utilization
|
||||||
'm' - Management time per second
|
'm' - Management time per second
|
||||||
'C' - Total core dispatch time
|
'C' - Total core dispatch time
|
||||||
'E' - Total thread time
|
'E' - Total thread time
|
||||||
|
|||||||
@@ -22,6 +22,7 @@
|
|||||||
#include "table.h"
|
#include "table.h"
|
||||||
|
|
||||||
#define HYPTOP_OPT_DEFAULT_DELAY 2
|
#define HYPTOP_OPT_DEFAULT_DELAY 2
|
||||||
|
#define HYPTOP_OPT_DEFAULT_SMT_SCALE 1.3
|
||||||
#define HYPTOP_MAX_WIN_DEPTH 4
|
#define HYPTOP_MAX_WIN_DEPTH 4
|
||||||
#define HYPTOP_MAX_LINE 512
|
#define HYPTOP_MAX_LINE 512
|
||||||
#define PROG_NAME "hyptop"
|
#define PROG_NAME "hyptop"
|
||||||
@@ -60,6 +61,8 @@ struct hyptop_opts {
|
|||||||
|
|
||||||
int delay_s;
|
int delay_s;
|
||||||
int delay_us;
|
int delay_us;
|
||||||
|
|
||||||
|
double smt_factor;
|
||||||
};
|
};
|
||||||
|
|
||||||
/*
|
/*
|
||||||
|
|||||||
+21
-1
@@ -39,6 +39,7 @@ static char HELP_TEXT[] =
|
|||||||
"-t, --cpu_types TYPE[,..] CPU types used for time calculations\n"
|
"-t, --cpu_types TYPE[,..] CPU types used for time calculations\n"
|
||||||
"-b, --batch_mode Use batch mode (no curses)\n"
|
"-b, --batch_mode Use batch mode (no curses)\n"
|
||||||
"-d, --delay SECONDS Delay time between screen updates\n"
|
"-d, --delay SECONDS Delay time between screen updates\n"
|
||||||
|
"-m, --smt_factor FACTOR Machine generation dependent SMT speedup factor.\n"
|
||||||
"-n, --iterations NUMBER Number of iterations before ending\n";
|
"-n, --iterations NUMBER Number of iterations before ending\n";
|
||||||
|
|
||||||
/*
|
/*
|
||||||
@@ -48,6 +49,7 @@ static void l_init_defaults(void)
|
|||||||
{
|
{
|
||||||
g.prog_name = PROG_NAME;
|
g.prog_name = PROG_NAME;
|
||||||
g.o.delay_s = HYPTOP_OPT_DEFAULT_DELAY;
|
g.o.delay_s = HYPTOP_OPT_DEFAULT_DELAY;
|
||||||
|
g.o.smt_factor = HYPTOP_OPT_DEFAULT_SMT_SCALE;
|
||||||
g.w.cur = &win_sys_list;
|
g.w.cur = &win_sys_list;
|
||||||
g.o.cur_win = &win_sys_list;
|
g.o.cur_win = &win_sys_list;
|
||||||
}
|
}
|
||||||
@@ -108,6 +110,20 @@ static void l_delay_set(char *delay_string)
|
|||||||
g.o.delay_us = 0;
|
g.o.delay_us = 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Set SMT factor option
|
||||||
|
*/
|
||||||
|
static void l_factor_set(char *value_string)
|
||||||
|
{
|
||||||
|
double factor;
|
||||||
|
|
||||||
|
if (sscanf(value_string, "%lf", &factor) != 1)
|
||||||
|
ERR_EXIT("The SMT factor \"%s\" is invalid\n", value_string);
|
||||||
|
if (factor <= 0)
|
||||||
|
ERR_EXIT("The SMT factor \"%s\" is <= 0\n", value_string);
|
||||||
|
g.o.smt_factor = factor;
|
||||||
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Get number of occurrences of character 'c' in "str"
|
* Get number of occurrences of character 'c' in "str"
|
||||||
*/
|
*/
|
||||||
@@ -299,6 +315,7 @@ void opts_parse(int argc, char *argv[])
|
|||||||
{ "help", no_argument, NULL, 'h'},
|
{ "help", no_argument, NULL, 'h'},
|
||||||
{ "batch_mode", no_argument, NULL, 'b'},
|
{ "batch_mode", no_argument, NULL, 'b'},
|
||||||
{ "delay", required_argument, NULL, 'd'},
|
{ "delay", required_argument, NULL, 'd'},
|
||||||
|
{ "smt_factor", required_argument, NULL, 'm'},
|
||||||
{ "window", required_argument, NULL, 'w'},
|
{ "window", required_argument, NULL, 'w'},
|
||||||
{ "sys", required_argument, NULL, 's'},
|
{ "sys", required_argument, NULL, 's'},
|
||||||
{ "iterations", required_argument, NULL, 'n'},
|
{ "iterations", required_argument, NULL, 'n'},
|
||||||
@@ -307,7 +324,7 @@ void opts_parse(int argc, char *argv[])
|
|||||||
{ "cpu_types", required_argument, NULL, 't'},
|
{ "cpu_types", required_argument, NULL, 't'},
|
||||||
{ NULL, 0, NULL, 0 }
|
{ NULL, 0, NULL, 0 }
|
||||||
};
|
};
|
||||||
static const char option_string[] = "vhbd:w:s:n:f:t:S:";
|
static const char option_string[] = "vhbd:m:w:s:n:f:t:S:";
|
||||||
|
|
||||||
l_init_defaults();
|
l_init_defaults();
|
||||||
while (1) {
|
while (1) {
|
||||||
@@ -328,6 +345,9 @@ void opts_parse(int argc, char *argv[])
|
|||||||
case 'd':
|
case 'd':
|
||||||
l_delay_set(optarg);
|
l_delay_set(optarg);
|
||||||
break;
|
break;
|
||||||
|
case 'm':
|
||||||
|
l_factor_set(optarg);
|
||||||
|
break;
|
||||||
case 'w':
|
case 'w':
|
||||||
l_window_set(optarg);
|
l_window_set(optarg);
|
||||||
break;
|
break;
|
||||||
|
|||||||
@@ -200,6 +200,7 @@ struct sd_cpu {
|
|||||||
struct sd_cpu_info *d_cur;
|
struct sd_cpu_info *d_cur;
|
||||||
struct sd_cpu_info *d_prev;
|
struct sd_cpu_info *d_prev;
|
||||||
u16 cnt;
|
u16 cnt;
|
||||||
|
int threads_per_core;
|
||||||
enum sd_cpu_state state;
|
enum sd_cpu_state state;
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -232,6 +233,11 @@ static inline void sd_cpu_cpu_time_us_set(struct sd_cpu *cpu, u64 value)
|
|||||||
cpu->d_cur->cpu_time_us = value;
|
cpu->d_cur->cpu_time_us = value;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static inline void sd_cpu_threads_per_core_set(struct sd_cpu *cpu, int value)
|
||||||
|
{
|
||||||
|
cpu->threads_per_core = value;
|
||||||
|
}
|
||||||
|
|
||||||
static inline void sd_cpu_thread_time_us_set(struct sd_cpu *cpu, u64 value)
|
static inline void sd_cpu_thread_time_us_set(struct sd_cpu *cpu, u64 value)
|
||||||
{
|
{
|
||||||
cpu->d_cur->thread_time_us = value;
|
cpu->d_cur->thread_time_us = value;
|
||||||
@@ -335,6 +341,7 @@ extern struct sd_cpu_item sd_cpu_item_state;
|
|||||||
extern struct sd_cpu_item sd_cpu_item_cpu_diff;
|
extern struct sd_cpu_item sd_cpu_item_cpu_diff;
|
||||||
extern struct sd_cpu_item sd_cpu_item_core_diff;
|
extern struct sd_cpu_item sd_cpu_item_core_diff;
|
||||||
extern struct sd_cpu_item sd_cpu_item_thread_diff;
|
extern struct sd_cpu_item sd_cpu_item_thread_diff;
|
||||||
|
extern struct sd_cpu_item sd_cpu_item_smt_diff;
|
||||||
extern struct sd_cpu_item sd_cpu_item_mgm_diff;
|
extern struct sd_cpu_item sd_cpu_item_mgm_diff;
|
||||||
extern struct sd_cpu_item sd_cpu_item_wait_diff;
|
extern struct sd_cpu_item sd_cpu_item_wait_diff;
|
||||||
extern struct sd_cpu_item sd_cpu_item_steal_diff;
|
extern struct sd_cpu_item sd_cpu_item_steal_diff;
|
||||||
@@ -398,6 +405,7 @@ static inline char *sd_sys_item_str(struct sd_sys *sys,
|
|||||||
extern struct sd_sys_item sd_sys_item_cpu_cnt;
|
extern struct sd_sys_item sd_sys_item_cpu_cnt;
|
||||||
extern struct sd_sys_item sd_sys_item_core_cnt;
|
extern struct sd_sys_item sd_sys_item_core_cnt;
|
||||||
extern struct sd_sys_item sd_sys_item_thread_cnt;
|
extern struct sd_sys_item sd_sys_item_thread_cnt;
|
||||||
|
extern struct sd_sys_item sd_sys_item_smt_diff;
|
||||||
extern struct sd_sys_item sd_sys_item_cpu_oper_cnt;
|
extern struct sd_sys_item sd_sys_item_cpu_oper_cnt;
|
||||||
extern struct sd_sys_item sd_sys_item_cpu_deconf_cnt;
|
extern struct sd_sys_item sd_sys_item_cpu_deconf_cnt;
|
||||||
extern struct sd_sys_item sd_sys_item_cpu_stop_cnt;
|
extern struct sd_sys_item sd_sys_item_cpu_stop_cnt;
|
||||||
|
|||||||
@@ -98,6 +98,18 @@ static u64 l_cpu_item_64(struct sd_cpu_item *item, struct sd_cpu *cpu)
|
|||||||
return l_cpu_info_u64(cpu->d_cur, item->offset) / cpu->cnt;
|
return l_cpu_info_u64(cpu->d_cur, item->offset) / cpu->cnt;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static u64 l_cpu_smt_util(struct sd_cpu_item *item, struct sd_cpu *cpu)
|
||||||
|
{
|
||||||
|
u64 core_us, thr_us, mgm_us;
|
||||||
|
(void)item;
|
||||||
|
|
||||||
|
core_us = sd_cpu_item_u64(&sd_cpu_item_core_diff, cpu);
|
||||||
|
thr_us = sd_cpu_item_u64(&sd_cpu_item_thread_diff, cpu);
|
||||||
|
mgm_us = sd_cpu_item_u64(&sd_cpu_item_mgm_diff, cpu);
|
||||||
|
|
||||||
|
return ht_calculate_smt_util(core_us, thr_us, mgm_us, cpu->threads_per_core);
|
||||||
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* CPU item definitions
|
* CPU item definitions
|
||||||
*/
|
*/
|
||||||
@@ -139,6 +151,13 @@ struct sd_cpu_item sd_cpu_item_thread_diff = {
|
|||||||
.fn_u64 = l_cpu_diff_u64,
|
.fn_u64 = l_cpu_diff_u64,
|
||||||
};
|
};
|
||||||
|
|
||||||
|
struct sd_cpu_item sd_cpu_item_smt_diff = {
|
||||||
|
.table_col = TABLE_COL_TIME_DIFF_SUM(table_col_unit_perc, 'S', "smt"),
|
||||||
|
.type = SD_TYPE_U64,
|
||||||
|
.desc = "Real CPU SMT utilization",
|
||||||
|
.fn_u64 = l_cpu_smt_util,
|
||||||
|
};
|
||||||
|
|
||||||
struct sd_cpu_item sd_cpu_item_mgm_diff = {
|
struct sd_cpu_item sd_cpu_item_mgm_diff = {
|
||||||
.table_col = TABLE_COL_TIME_DIFF_SUM(table_col_unit_perc, 'm', "mgm"),
|
.table_col = TABLE_COL_TIME_DIFF_SUM(table_col_unit_perc, 'm', "mgm"),
|
||||||
.type = SD_TYPE_U64,
|
.type = SD_TYPE_U64,
|
||||||
|
|||||||
@@ -208,6 +208,18 @@ static s64 l_sys_cpu_info_diff_s64(struct sd_sys_item *item, struct sd_sys *sys)
|
|||||||
return rc;
|
return rc;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static u64 l_sys_smt_util(struct sd_sys_item *item, struct sd_sys *sys)
|
||||||
|
{
|
||||||
|
u64 core_us, thr_us, mgm_us;
|
||||||
|
(void)item;
|
||||||
|
|
||||||
|
core_us = sd_sys_item_u64(sys, &sd_sys_item_core_diff);
|
||||||
|
thr_us = sd_sys_item_u64(sys, &sd_sys_item_thread_diff);
|
||||||
|
mgm_us = sd_sys_item_u64(sys, &sd_sys_item_mgm_diff);
|
||||||
|
|
||||||
|
return ht_calculate_smt_util(core_us, thr_us, mgm_us, sys->threads_per_core);
|
||||||
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* System item definitions
|
* System item definitions
|
||||||
*/
|
*/
|
||||||
@@ -277,6 +289,13 @@ struct sd_sys_item sd_sys_item_thread_diff = {
|
|||||||
.fn_u64 = l_sys_cpu_info_diff_u64,
|
.fn_u64 = l_sys_cpu_info_diff_u64,
|
||||||
};
|
};
|
||||||
|
|
||||||
|
struct sd_sys_item sd_sys_item_smt_diff = {
|
||||||
|
.table_col = TABLE_COL_TIME_DIFF_SUM(table_col_unit_perc, 'S', "smt"),
|
||||||
|
.type = SD_TYPE_U64,
|
||||||
|
.desc = "Real CPU SMT utilization",
|
||||||
|
.fn_u64 = l_sys_smt_util,
|
||||||
|
};
|
||||||
|
|
||||||
struct sd_sys_item sd_sys_item_mgm_diff = {
|
struct sd_sys_item sd_sys_item_mgm_diff = {
|
||||||
.table_col = TABLE_COL_TIME_DIFF_SUM(table_col_unit_perc, 'm', "mgm"),
|
.table_col = TABLE_COL_TIME_DIFF_SUM(table_col_unit_perc, 'm', "mgm"),
|
||||||
.offset = SD_CPU_INFO_OFFSET(mgm_time_us),
|
.offset = SD_CPU_INFO_OFFSET(mgm_time_us),
|
||||||
|
|||||||
@@ -195,15 +195,25 @@ struct boot_info_bp_dump {
|
|||||||
uint8_t unused[16];
|
uint8_t unused[16];
|
||||||
} __packed;
|
} __packed;
|
||||||
|
|
||||||
|
/* This represents on-disk pointer to a block on disk */
|
||||||
|
union disk_blockptr {
|
||||||
|
struct eckd_blockptr_legacy eckd_legacy;
|
||||||
|
struct eckd_blockptr eckd;
|
||||||
|
struct linear_blockptr linear;
|
||||||
|
};
|
||||||
|
|
||||||
struct boot_info_bp_ipl {
|
struct boot_info_bp_ipl {
|
||||||
union {
|
union disk_blockptr bm_ptr;
|
||||||
struct eckd_blockptr_legacy eckd_legacy;
|
|
||||||
struct eckd_blockptr eckd;
|
|
||||||
struct linear_blockptr lin;
|
|
||||||
} bm_ptr;
|
|
||||||
uint8_t unused[16];
|
uint8_t unused[16];
|
||||||
} __packed;
|
} __packed;
|
||||||
|
|
||||||
|
struct disk_program_table {
|
||||||
|
uint32_t magic;
|
||||||
|
uint32_t version;
|
||||||
|
uint64_t unused;
|
||||||
|
union disk_blockptr component_table[0];
|
||||||
|
} __packed;
|
||||||
|
|
||||||
struct boot_info {
|
struct boot_info {
|
||||||
char magic[4];
|
char magic[4];
|
||||||
uint8_t version;
|
uint8_t version;
|
||||||
|
|||||||
@@ -34,10 +34,10 @@
|
|||||||
/* Secure IPL error */
|
/* Secure IPL error */
|
||||||
#define ESECUREBOOT 0x00004512
|
#define ESECUREBOOT 0x00004512
|
||||||
|
|
||||||
/* kdump: No operating system information was found */
|
/* os_info error: No operating system information was found */
|
||||||
#define EOS_INFO_MISSING 0x00004520
|
#define EOS_INFO_MISSING 0x00004520
|
||||||
|
|
||||||
/* kdump: The checksum of the operating system information is incorrect */
|
/* os_info error: The checksum of the operating system information is incorrect */
|
||||||
#define EOS_INFO_CSUM_FAILED 0x00004521
|
#define EOS_INFO_CSUM_FAILED 0x00004521
|
||||||
|
|
||||||
/* kdump: The major version of the operating system information is too high */
|
/* kdump: The major version of the operating system information is too high */
|
||||||
+11
-5
@@ -11,7 +11,7 @@
|
|||||||
#define IPL_H
|
#define IPL_H
|
||||||
|
|
||||||
#include "lib/zt_common.h"
|
#include "lib/zt_common.h"
|
||||||
#include "s390.h"
|
#include "page.h"
|
||||||
|
|
||||||
#define IPL_FLAG_SECURE 0x40
|
#define IPL_FLAG_SECURE 0x40
|
||||||
|
|
||||||
@@ -21,10 +21,6 @@
|
|||||||
#define IPL_MAX_SUPPORTED_VERSION 0
|
#define IPL_MAX_SUPPORTED_VERSION 0
|
||||||
#define IPL_PARM_BLOCK_VERSION 0x1
|
#define IPL_PARM_BLOCK_VERSION 0x1
|
||||||
|
|
||||||
/* IPL Types */
|
|
||||||
#define IPL_TYPE_PV 0x5
|
|
||||||
|
|
||||||
|
|
||||||
#ifndef __ASSEMBLER__
|
#ifndef __ASSEMBLER__
|
||||||
|
|
||||||
#include <stdint.h>
|
#include <stdint.h>
|
||||||
@@ -43,6 +39,16 @@ struct ipl_pb_hdr {
|
|||||||
uint8_t pbt;
|
uint8_t pbt;
|
||||||
} __packed;
|
} __packed;
|
||||||
|
|
||||||
|
/* IPL Parameter Block types */
|
||||||
|
enum ipl_pbt {
|
||||||
|
IPL_PBT_FCP = 0,
|
||||||
|
IPL_PBT_SCP_DATA = 1,
|
||||||
|
IPL_PBT_CCW = 2,
|
||||||
|
IPL_PBT_ECKD = 3,
|
||||||
|
IPL_PBT_NVME = 4,
|
||||||
|
IPL_PBT_PV = 5,
|
||||||
|
};
|
||||||
|
|
||||||
/* IPL Parameter Block 0 with common fields */
|
/* IPL Parameter Block 0 with common fields */
|
||||||
struct ipl_pb0_common {
|
struct ipl_pb0_common {
|
||||||
uint32_t len;
|
uint32_t len;
|
||||||
|
|||||||
@@ -22,11 +22,19 @@
|
|||||||
#define STAGE2_DESC _AC(0x78, UL)
|
#define STAGE2_DESC _AC(0x78, UL)
|
||||||
#define STAGE2_ENTRY _AC(0x2018, UL)
|
#define STAGE2_ENTRY _AC(0x2018, UL)
|
||||||
#define STAGE2_HEAP_ADDRESS _AC(0x6000, UL)
|
#define STAGE2_HEAP_ADDRESS _AC(0x6000, UL)
|
||||||
|
#define ECKD2DUMP_SV_HEAP_ADDRESS _AC(0xb000, UL)
|
||||||
#define STAGE2_HEAP_SIZE _AC(0x3000, UL)
|
#define STAGE2_HEAP_SIZE _AC(0x3000, UL)
|
||||||
#define STAGE2_STACK_ADDRESS _AC(0xe400, UL)
|
#define STAGE2_STACK_ADDRESS _AC(0xe400, UL)
|
||||||
#define STAGE2_STACK_SIZE _AC(0x1c00, UL)
|
#define STAGE2_STACK_SIZE _AC(0x1c00, UL)
|
||||||
|
#define ECKD2DUMP_SV_STACK_ADDRESS _AC(0xe000, UL)
|
||||||
|
#define ECKD2DUMP_SV_STACK_SIZE _AC(0x2000, UL)
|
||||||
#define STAGE2_MAX_SIZE _AC(0x3000, UL)
|
#define STAGE2_MAX_SIZE _AC(0x3000, UL)
|
||||||
|
|
||||||
|
#define STAGE2_DUMPER_SIZE_V1 _AC(0x1000, UL)
|
||||||
|
#define STAGE2_DUMPER_SIZE_V2 _AC(0x2000, UL)
|
||||||
|
#define STAGE2_DUMPER_SIZE_V3 _AC(0x3000, UL)
|
||||||
|
#define STAGE2_DUMPER_SIZE_ZLIB _AC(0x8000, UL)
|
||||||
|
|
||||||
#define STAGE3_ENTRY _AC(0xa000, UL)
|
#define STAGE3_ENTRY _AC(0xa000, UL)
|
||||||
|
|
||||||
#define STAGE2_LOAD_ADDRESS _AC(0x2000, UL)
|
#define STAGE2_LOAD_ADDRESS _AC(0x2000, UL)
|
||||||
|
|||||||
@@ -0,0 +1,78 @@
|
|||||||
|
/*
|
||||||
|
* zipl - zSeries Initial Program Loader tool
|
||||||
|
*
|
||||||
|
* os-info definitions
|
||||||
|
*
|
||||||
|
* Copyright IBM Corp. 2013, 2023
|
||||||
|
*
|
||||||
|
* s390-tools is free software; you can redistribute it and/or modify
|
||||||
|
* it under the terms of the MIT license. See LICENSE for details.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#ifndef OS_INFO_H
|
||||||
|
#define OS_INFO_H
|
||||||
|
|
||||||
|
#include "lib/zt_common.h"
|
||||||
|
#include "boot/error.h"
|
||||||
|
#include "boot/s390.h"
|
||||||
|
#include <stdint.h>
|
||||||
|
|
||||||
|
#define OS_INFO_MAGIC 0x4f53494e464f535aULL /* OSINFOSZ */
|
||||||
|
#define OS_INFO_CSUM_SIZE (sizeof(struct os_info) - offsetof(struct os_info, version_major))
|
||||||
|
#define OS_INFO_FLAGS_ENTRY_SIZE (sizeof(unsigned long))
|
||||||
|
|
||||||
|
#define OS_INFO_VMCOREINFO 0
|
||||||
|
#define OS_INFO_REIPL_BLOCK 1
|
||||||
|
#define OS_INFO_FLAGS_ENTRY 2
|
||||||
|
|
||||||
|
#define OS_INFO_FLAG_REIPL_CLEAR (1UL << 0)
|
||||||
|
|
||||||
|
struct os_info_entry {
|
||||||
|
uint64_t addr;
|
||||||
|
uint64_t size;
|
||||||
|
uint32_t csum;
|
||||||
|
} __packed;
|
||||||
|
|
||||||
|
struct os_info {
|
||||||
|
uint64_t magic;
|
||||||
|
uint32_t csum;
|
||||||
|
uint16_t version_major;
|
||||||
|
uint16_t version_minor;
|
||||||
|
uint64_t crashkernel_addr;
|
||||||
|
uint64_t crashkernel_size;
|
||||||
|
struct os_info_entry entry[3];
|
||||||
|
uint8_t reserved[4004];
|
||||||
|
} __packed;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Return 0 in case of valid os_info
|
||||||
|
* Return -EOS_INFO_MISSING if os_info address is not page aligned or page is
|
||||||
|
* not accessible or os_info magic value is missing.
|
||||||
|
* Return -EOS_INFO_CSUM_FAILED if os_info checksum is invalid.
|
||||||
|
*/
|
||||||
|
static inline int os_info_check(const struct os_info *os_info)
|
||||||
|
{
|
||||||
|
if (!os_info ||
|
||||||
|
(unsigned long)os_info % PAGE_SIZE ||
|
||||||
|
!page_is_valid((unsigned long)os_info) ||
|
||||||
|
os_info->magic != OS_INFO_MAGIC)
|
||||||
|
return -EOS_INFO_MISSING;
|
||||||
|
if (os_info->csum != csum_partial(&os_info->version_major, OS_INFO_CSUM_SIZE, 0))
|
||||||
|
return -EOS_INFO_CSUM_FAILED;
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Return 1 in case of valid os_info_entry, otherwise 0
|
||||||
|
* Make sure that the entire os_info structure is checked first with os_info_check().
|
||||||
|
*/
|
||||||
|
static inline int os_info_entry_is_valid(const struct os_info_entry *entry)
|
||||||
|
{
|
||||||
|
return (entry &&
|
||||||
|
entry->addr &&
|
||||||
|
entry->size &&
|
||||||
|
page_is_valid(entry->addr) &&
|
||||||
|
entry->csum == csum_partial((void *)entry->addr, entry->size, 0));
|
||||||
|
}
|
||||||
|
|
||||||
|
#endif /* OS_INFO_H */
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
/*
|
||||||
|
* Page related definitions and functions.
|
||||||
|
*
|
||||||
|
* Copyright IBM Corp. 2023
|
||||||
|
*
|
||||||
|
* s390-tools is free software; you can redistribute it and/or modify
|
||||||
|
* it under the terms of the MIT license. See LICENSE for details.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#ifndef BOOT_PAGE_H
|
||||||
|
#define BOOT_PAGE_H
|
||||||
|
#include "lib/zt_common.h"
|
||||||
|
|
||||||
|
#define PAGE_SIZE _AC(4096, UL)
|
||||||
|
#endif
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
/*
|
||||||
|
* Program Status Word related definitions and functions.
|
||||||
|
*
|
||||||
|
* Copyright IBM Corp. 2023
|
||||||
|
*
|
||||||
|
* s390-tools is free software; you can redistribute it and/or modify
|
||||||
|
* it under the terms of the MIT license. See LICENSE for details.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#ifndef BOOT_PSW_H
|
||||||
|
#define BOOT_PSW_H
|
||||||
|
|
||||||
|
#include "lib/zt_common.h"
|
||||||
|
|
||||||
|
#define PSW32_ADDR_MASK _AC(0x000000007fffffff, UL)
|
||||||
|
#define PSW_MASK_BA _AC(0x0000000080000000, UL)
|
||||||
|
#define PSW_MASK_EA _AC(0x0000000100000000, UL)
|
||||||
|
#define PSW_MASK_BIT_12 _AC(0x0008000000000000, UL)
|
||||||
|
#define PSW_LOAD _AC(0x0008000080000000, UL)
|
||||||
|
#define PSW_DISABLED_WAIT _AC(0x000a000000000000, UL)
|
||||||
|
|
||||||
|
#ifndef __ASSEMBLER__
|
||||||
|
#include <stdint.h>
|
||||||
|
|
||||||
|
struct psw_t {
|
||||||
|
uint64_t mask;
|
||||||
|
uint64_t addr;
|
||||||
|
} __aligned(8);
|
||||||
|
|
||||||
|
#endif
|
||||||
|
#endif
|
||||||
+15
-29
@@ -1,7 +1,8 @@
|
|||||||
/*
|
/*
|
||||||
* s390 related definitions and functions.
|
* s390 related definitions and functions.
|
||||||
|
* Should only be used for code targeting s390 (bootloader code)
|
||||||
*
|
*
|
||||||
* Copyright IBM Corp. 2013, 2020
|
* Copyright IBM Corp. 2013, 2023
|
||||||
*
|
*
|
||||||
* s390-tools is free software; you can redistribute it and/or modify
|
* s390-tools is free software; you can redistribute it and/or modify
|
||||||
* it under the terms of the MIT license. See LICENSE for details.
|
* it under the terms of the MIT license. See LICENSE for details.
|
||||||
@@ -12,29 +13,23 @@
|
|||||||
|
|
||||||
#include "lib/zt_common.h"
|
#include "lib/zt_common.h"
|
||||||
#include "boot/sigp.h"
|
#include "boot/sigp.h"
|
||||||
|
#include "boot/psw.h"
|
||||||
|
#include "boot/page.h"
|
||||||
|
|
||||||
#define __LC_IPLDEV 0x0c6c
|
#define __LC_IPLDEV 0x0c6c
|
||||||
#define __LC_OS_INFO 0x0e18
|
#define __LC_OS_INFO 0x0e18
|
||||||
|
|
||||||
#define LOWCORE_SIZE _AC(0x2000, UL)
|
#define LOWCORE_SIZE _AC(0x2000, UL)
|
||||||
|
|
||||||
#define PAGE_SIZE _AC(4096, UL)
|
|
||||||
|
|
||||||
/* Minimum size of a stack frame in bytes */
|
/* Minimum size of a stack frame in bytes */
|
||||||
#define STACK_FRAME_OVERHEAD _AC(160, U)
|
#define STACK_FRAME_OVERHEAD _AC(160, U)
|
||||||
|
|
||||||
/* Facilities */
|
/* Facilities */
|
||||||
|
#define DFLTCC_FACILITY _AC(151, U)
|
||||||
#define UNPACK_FACILITY _AC(161, U)
|
#define UNPACK_FACILITY _AC(161, U)
|
||||||
|
|
||||||
#define PSW32_ADDR_MASK _AC(0x000000007fffffff, UL)
|
|
||||||
#define PSW_MASK_BA _AC(0x0000000080000000, UL)
|
|
||||||
#define PSW_MASK_EA _AC(0x0000000100000000, UL)
|
|
||||||
#define PSW_MASK_BIT_12 _AC(0x0008000000000000, UL)
|
|
||||||
#define PSW_LOAD _AC(0x0008000080000000, UL)
|
|
||||||
#define PSW_DISABLED_WAIT _AC(0x000a000000000000, UL)
|
|
||||||
|
|
||||||
|
|
||||||
#ifndef __ASSEMBLER__
|
#ifndef __ASSEMBLER__
|
||||||
|
#include <stdint.h>
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* Helper macro for exception table entries
|
* Helper macro for exception table entries
|
||||||
@@ -46,18 +41,6 @@
|
|||||||
".long (" #_target ")\n" \
|
".long (" #_target ")\n" \
|
||||||
".previous\n"
|
".previous\n"
|
||||||
|
|
||||||
struct psw_t {
|
|
||||||
uint64_t mask;
|
|
||||||
uint64_t addr;
|
|
||||||
} __aligned(8);
|
|
||||||
|
|
||||||
struct psw32_t {
|
|
||||||
uint32_t mask;
|
|
||||||
uint32_t addr;
|
|
||||||
} __aligned(8);
|
|
||||||
|
|
||||||
void load_wait_psw(uint64_t, struct psw_t *);
|
|
||||||
|
|
||||||
struct subchannel_id {
|
struct subchannel_id {
|
||||||
uint32_t cssid:8;
|
uint32_t cssid:8;
|
||||||
uint32_t:4;
|
uint32_t:4;
|
||||||
@@ -303,18 +286,21 @@ static __always_inline void __ctl_set_bit(unsigned int cr, unsigned int bit)
|
|||||||
* DIAG 308 support
|
* DIAG 308 support
|
||||||
*/
|
*/
|
||||||
enum diag308_subcode {
|
enum diag308_subcode {
|
||||||
DIAG308_REL_HSA = 2,
|
DIAG308_CLEAR_RESET = 0,
|
||||||
DIAG308_IPL = 3,
|
DIAG308_LOAD_NORMAL_RESET = 1,
|
||||||
DIAG308_DUMP = 4,
|
DIAG308_REL_HSA = 2,
|
||||||
DIAG308_SET = 5,
|
DIAG308_LOAD_CLEAR = 3,
|
||||||
DIAG308_STORE = 6,
|
DIAG308_LOAD_NORMAL_DUMP = 4,
|
||||||
|
DIAG308_SET = 5,
|
||||||
|
DIAG308_STORE = 6,
|
||||||
|
DIAG308_LOAD_NORMAL = 7,
|
||||||
DIAG308_SET_PV = 8,
|
DIAG308_SET_PV = 8,
|
||||||
DIAG308_UNPACK_PV = 10,
|
DIAG308_UNPACK_PV = 10,
|
||||||
};
|
};
|
||||||
|
|
||||||
enum diag308_rc {
|
enum diag308_rc {
|
||||||
DIAG308_RC_OK = 0x0001,
|
DIAG308_RC_OK = 0x0001,
|
||||||
DIAG308_RC_NO_CONF = 0x0102,
|
DIAG308_RC_NOCONFIG = 0x0102,
|
||||||
};
|
};
|
||||||
|
|
||||||
static __always_inline unsigned long diag308(unsigned long subcode, void *addr)
|
static __always_inline unsigned long diag308(unsigned long subcode, void *addr)
|
||||||
|
|||||||
@@ -0,0 +1,145 @@
|
|||||||
|
/*
|
||||||
|
* s390 related definitions and functions.
|
||||||
|
*
|
||||||
|
* Copyright IBM Corp. 2013, 2023
|
||||||
|
*
|
||||||
|
* s390-tools is free software; you can redistribute it and/or modify
|
||||||
|
* it under the terms of the MIT license. See LICENSE for details.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#ifndef S390_DUMP_H
|
||||||
|
#define S390_DUMP_H
|
||||||
|
|
||||||
|
#include <stdint.h>
|
||||||
|
|
||||||
|
#include "boot/page.h"
|
||||||
|
#include "lib/zt_common.h"
|
||||||
|
|
||||||
|
/*
|
||||||
|
* S390 dump format defines
|
||||||
|
*/
|
||||||
|
#define DF_S390_MAGIC 0xa8190173618f23fdULL
|
||||||
|
#define DF_S390_MAGIC_EXT 0xa8190173618f23feULL
|
||||||
|
#define DF_S390_HDR_SIZE 0x1000
|
||||||
|
#define DF_S390_EM_SIZE 16
|
||||||
|
#define DF_S390_EM_MAGIC 0x44554d505f454e44ULL
|
||||||
|
#define DF_S390_EM_STR "DUMP_END"
|
||||||
|
#define DF_S390_CPU_MAX 512
|
||||||
|
#define DF_S390_MAGIC_BLK_ECKD 3
|
||||||
|
#define DF_S390_DUMPER_MAGIC_SIZE 7
|
||||||
|
#define DF_S390_DUMPER_MAGIC32 "ZECKD31"
|
||||||
|
#define DF_S390_DUMPER_MAGIC64 "ZECKD64"
|
||||||
|
#define DF_S390_DUMPER_MAGIC_EXT "XECKD64"
|
||||||
|
#define DF_S390_DUMPER_MAGIC32_FBA "ZDFBA31"
|
||||||
|
#define DF_S390_DUMPER_MAGIC64_FBA "ZDFBA64"
|
||||||
|
#define DF_S390_DUMPER_MAGIC_FBA_EXT "XDFBA64"
|
||||||
|
#define DF_S390_DUMPER_MAGIC_MV "ZMULT64"
|
||||||
|
#define DF_S390_DUMPER_MAGIC_MV_EXT "XMULT64"
|
||||||
|
#define OLD_DUMPER_HEX_INSTR1 "\x0d\x10\x47\xf0" /* BASR + 1st halfword of BC */
|
||||||
|
#define OLD_DUMPER_HEX_INSTR2 "\x0d\xd0" /* BASR 13,0 */
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Architecture of dumped system
|
||||||
|
*/
|
||||||
|
enum df_s390_arch {
|
||||||
|
DF_S390_ARCH_32 = 1,
|
||||||
|
DF_S390_ARCH_64 = 2,
|
||||||
|
};
|
||||||
|
|
||||||
|
/*
|
||||||
|
* zipl parameters passed at tail of dump tools
|
||||||
|
*/
|
||||||
|
struct stage2dump_parm_tail {
|
||||||
|
char reserved[6];
|
||||||
|
uint8_t no_compress;
|
||||||
|
uint8_t mvdump_force;
|
||||||
|
uint64_t mem_upper_limit;
|
||||||
|
} __packed;
|
||||||
|
|
||||||
|
/*
|
||||||
|
* s390 dump header format
|
||||||
|
*/
|
||||||
|
struct df_s390_hdr {
|
||||||
|
uint64_t magic; /* 0x000 */
|
||||||
|
uint32_t version; /* 0x008 */
|
||||||
|
uint32_t hdr_size; /* 0x00c */
|
||||||
|
uint32_t dump_level; /* 0x010 */
|
||||||
|
uint32_t page_size; /* 0x014 */
|
||||||
|
uint64_t mem_size; /* 0x018 */
|
||||||
|
uint64_t mem_start; /* 0x020 */
|
||||||
|
uint64_t mem_end; /* 0x028 */
|
||||||
|
uint32_t num_pages; /* 0x030 */
|
||||||
|
uint32_t pad; /* 0x034 */
|
||||||
|
uint64_t tod; /* 0x038 */
|
||||||
|
uint64_t cpu_id; /* 0x040 */
|
||||||
|
uint32_t arch; /* 0x048 */
|
||||||
|
uint32_t volnr; /* 0x04c */
|
||||||
|
uint32_t build_arch; /* 0x050 */
|
||||||
|
uint64_t mem_size_real; /* 0x054 */
|
||||||
|
uint8_t mvdump; /* 0x05c */
|
||||||
|
uint16_t cpu_cnt; /* 0x05d */
|
||||||
|
uint16_t real_cpu_cnt; /* 0x05f */
|
||||||
|
uint8_t zlib_version_s390; /* 0x061 */
|
||||||
|
uint32_t zlib_entry_size; /* 0x062 */
|
||||||
|
uint8_t end_pad1[0x200 - 0x066]; /* 0x066 */
|
||||||
|
uint64_t mvdump_sign; /* 0x200 */
|
||||||
|
uint64_t mvdump_zipl_time; /* 0x208 */
|
||||||
|
uint8_t end_pad2[0x800 - 0x210]; /* 0x210 */
|
||||||
|
uint32_t lc_vec[DF_S390_CPU_MAX]; /* 0x800 */
|
||||||
|
} __packed __aligned(16);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* End marker: Should be at the end of every valid s390 crash dump
|
||||||
|
*/
|
||||||
|
struct df_s390_em {
|
||||||
|
union {
|
||||||
|
uint64_t magic;
|
||||||
|
char str[8];
|
||||||
|
};
|
||||||
|
uint64_t tod;
|
||||||
|
} __packed __aligned(16);
|
||||||
|
|
||||||
|
/*
|
||||||
|
* Dump segment header
|
||||||
|
*/
|
||||||
|
struct df_s390_dump_segm_hdr {
|
||||||
|
union {
|
||||||
|
struct {
|
||||||
|
uint64_t start; /* 0x000 */
|
||||||
|
uint64_t len; /* 0x008 */
|
||||||
|
uint64_t stop_marker; /* 0x010 */
|
||||||
|
/* Size in blocks of compressed dump segment written to disk */
|
||||||
|
uint32_t size_on_disk; /* 0x018 */
|
||||||
|
uint8_t reserved_pad[0x30 - 0x1c]; /* 0x01c */
|
||||||
|
/*
|
||||||
|
* Number of compressed entries in this dump segment (up to
|
||||||
|
* 1011 entries)
|
||||||
|
*/
|
||||||
|
uint32_t entry_count; /* 0x030 */
|
||||||
|
/*
|
||||||
|
* Offsets in blocks to compressed entries written to disk
|
||||||
|
* from the start of the dump segment.
|
||||||
|
* High-order bit is set if the entry has been written
|
||||||
|
* uncompressed.
|
||||||
|
*/
|
||||||
|
uint32_t entry_offset[]; /* 0x034 */
|
||||||
|
} __packed;
|
||||||
|
uint8_t padding[PAGE_SIZE];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
/* Data compression granularity (size of input data chunk for zlib deflate) */
|
||||||
|
#define DUMP_SEGM_ZLIB_ENTSIZE (1 * MIB)
|
||||||
|
/* Maximum number of compressed entries in one dump segment */
|
||||||
|
#define DUMP_SEGM_ZLIB_MAXENTS ((sizeof(struct df_s390_dump_segm_hdr) \
|
||||||
|
- offsetof(struct df_s390_dump_segm_hdr, entry_offset)) \
|
||||||
|
/ sizeof(uint32_t))
|
||||||
|
/*
|
||||||
|
* Maximum length of compressed dump segment considering the size of
|
||||||
|
* a single input chunk
|
||||||
|
*/
|
||||||
|
#define DUMP_SEGM_ZLIB_MAXLEN (DUMP_SEGM_ZLIB_MAXENTS * DUMP_SEGM_ZLIB_ENTSIZE)
|
||||||
|
/* Bitmask to mark uncompressed chunks */
|
||||||
|
#define DUMP_SEGM_ENTRY_UNCOMPRESSED 0x80000000
|
||||||
|
|
||||||
|
#endif /* S390_DUMP_H */
|
||||||
@@ -89,6 +89,7 @@ void ap_list_remove_all(struct util_list *list);
|
|||||||
/* Lock Functions */
|
/* Lock Functions */
|
||||||
int ap_get_lock(void);
|
int ap_get_lock(void);
|
||||||
int ap_get_lock_callout(void);
|
int ap_get_lock_callout(void);
|
||||||
|
int ap_try_lock_callout(void);
|
||||||
int ap_release_lock(void);
|
int ap_release_lock(void);
|
||||||
int ap_release_lock_callout(void);
|
int ap_release_lock_callout(void);
|
||||||
|
|
||||||
|
|||||||
@@ -27,6 +27,7 @@ enum util_arch_machine_type {
|
|||||||
UTIL_ARCH_MACHINE_TYPE_Z15 = 8561,
|
UTIL_ARCH_MACHINE_TYPE_Z15 = 8561,
|
||||||
UTIL_ARCH_MACHINE_TYPE_Z15_T02 = 8562,
|
UTIL_ARCH_MACHINE_TYPE_Z15_T02 = 8562,
|
||||||
UTIL_ARCH_MACHINE_TYPE_Z16 = 3931,
|
UTIL_ARCH_MACHINE_TYPE_Z16 = 3931,
|
||||||
|
UTIL_ARCH_MACHINE_TYPE_Z16_A02 = 3932,
|
||||||
};
|
};
|
||||||
|
|
||||||
int util_arch_machine_type(void);
|
int util_arch_machine_type(void);
|
||||||
|
|||||||
@@ -23,4 +23,6 @@ int util_lockfile_parent_lock(char *lockfile, int retries);
|
|||||||
int util_lockfile_release(char *lockfile);
|
int util_lockfile_release(char *lockfile);
|
||||||
int util_lockfile_parent_release(char *lockfile);
|
int util_lockfile_parent_release(char *lockfile);
|
||||||
|
|
||||||
|
int util_lockfile_peek_owner(char *lockfile, int *pid);
|
||||||
|
|
||||||
#endif /** LIB_UTIL_LOCKFILE_H @} */
|
#endif /** LIB_UTIL_LOCKFILE_H @} */
|
||||||
|
|||||||
@@ -40,6 +40,7 @@
|
|||||||
#define LV_COMPAT_CYL 0xFFFE
|
#define LV_COMPAT_CYL 0xFFFE
|
||||||
|
|
||||||
#define VTOC_ERROR "VTOC error:"
|
#define VTOC_ERROR "VTOC error:"
|
||||||
|
#define MAX_VTOC_ENTRIES 9 /* max number of VTOC labels for cdl formatted DASD */
|
||||||
|
|
||||||
typedef struct ttr
|
typedef struct ttr
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -16,7 +16,8 @@
|
|||||||
|
|
||||||
#define PV_IBM_Z_SUBJECT_COMMON_NAME "International Business Machines Corporation"
|
#define PV_IBM_Z_SUBJECT_COMMON_NAME "International Business Machines Corporation"
|
||||||
#define PV_IBM_Z_SUBJECT_COUNTRY_NAME "US"
|
#define PV_IBM_Z_SUBJECT_COUNTRY_NAME "US"
|
||||||
#define PV_IBM_Z_SUBJECT_LOCALITY_NAME "Poughkeepsie"
|
#define PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE "Poughkeepsie"
|
||||||
|
#define PV_IBM_Z_SUBJECT_LOCALITY_NAME_ARMONK "Armonk"
|
||||||
#define PV_IBM_Z_SUBJECT_ORGANIZATIONAL_UNIT_NAME_SUFFIX "Key Signing Service"
|
#define PV_IBM_Z_SUBJECT_ORGANIZATIONAL_UNIT_NAME_SUFFIX "Key Signing Service"
|
||||||
#define PV_IBM_Z_SUBJECT_ORGANIZATION_NAME "International Business Machines Corporation"
|
#define PV_IBM_Z_SUBJECT_ORGANIZATION_NAME "International Business Machines Corporation"
|
||||||
#define PV_IBM_Z_SUBJECT_STATE "New York"
|
#define PV_IBM_Z_SUBJECT_STATE "New York"
|
||||||
|
|||||||
@@ -13,7 +13,7 @@
|
|||||||
|
|
||||||
#include <openssl/sha.h>
|
#include <openssl/sha.h>
|
||||||
|
|
||||||
#include "boot/s390.h"
|
#include "boot/psw.h"
|
||||||
#include "libpv/crypto.h"
|
#include "libpv/crypto.h"
|
||||||
#include "libpv/macros.h"
|
#include "libpv/macros.h"
|
||||||
|
|
||||||
|
|||||||
+1
-2
@@ -13,8 +13,7 @@ RECURSIVE_TARGETS = all-recursive install-recursive clean-recursive \
|
|||||||
|
|
||||||
|
|
||||||
all: all-recursive
|
all: all-recursive
|
||||||
check: check-recursive
|
install: install-recursive
|
||||||
install: all install-recursive
|
|
||||||
clean: clean-recursive
|
clean: clean-recursive
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
+28
@@ -722,6 +722,34 @@ int ap_get_lock_callout(void)
|
|||||||
return util_lockfile_parent_lock(AP_LOCKFILE, AP_LOCK_RETRIES);
|
return util_lockfile_parent_lock(AP_LOCKFILE, AP_LOCK_RETRIES);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Attempt to acquire the ap config lock using the Parent Process ID without
|
||||||
|
* waiting/retries. Detect if the attempt was rejected because the lock is
|
||||||
|
* already held by the Parent Process ID.
|
||||||
|
*
|
||||||
|
* @retval 0 Lock acquired on behalf of parent process
|
||||||
|
* @retval 1 Lock not obtained, already held by parent
|
||||||
|
* @retval != 0 Lock was not obtained, other error
|
||||||
|
*/
|
||||||
|
int ap_try_lock_callout(void)
|
||||||
|
{
|
||||||
|
int pid, ppid, rc;
|
||||||
|
|
||||||
|
if (util_lockfile_parent_lock(AP_LOCKFILE, 0)) {
|
||||||
|
/* Lock is already held, let's peek at the owner */
|
||||||
|
ppid = getppid();
|
||||||
|
rc = util_lockfile_peek_owner(AP_LOCKFILE, &pid);
|
||||||
|
if (rc || pid != ppid) {
|
||||||
|
/* We didn't get the lock, unknown or other owner */
|
||||||
|
return 2;
|
||||||
|
}
|
||||||
|
/* Signify that the lock is already held by the caller */
|
||||||
|
return 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Release the ap config lock
|
* Release the ap config lock
|
||||||
*
|
*
|
||||||
|
|||||||
+5
-5
@@ -55,7 +55,7 @@ check-dep-libekmfweb: detect-openssl-version.dep
|
|||||||
"detect-openssl-version.dep", \
|
"detect-openssl-version.dep", \
|
||||||
"openssl-devel version >= 1.1.1", \
|
"openssl-devel version >= 1.1.1", \
|
||||||
"HAVE_OPENSSL=0", \
|
"HAVE_OPENSSL=0", \
|
||||||
-I. -lcrypto -DOPENSSL_SUPPRESS_DEPRECATED)
|
-I. `$(PKG_CONFIG) --cflags --libs libcrypto` -DOPENSSL_SUPPRESS_DEPRECATED)
|
||||||
$(call check_dep, \
|
$(call check_dep, \
|
||||||
"libekmfweb", \
|
"libekmfweb", \
|
||||||
"json-c/json.h", \
|
"json-c/json.h", \
|
||||||
@@ -66,7 +66,7 @@ check-dep-libekmfweb: detect-openssl-version.dep
|
|||||||
"curl/curl.h", \
|
"curl/curl.h", \
|
||||||
"libcurl-devel", \
|
"libcurl-devel", \
|
||||||
"HAVE_LIBCURL=0" \
|
"HAVE_LIBCURL=0" \
|
||||||
`$(CURL_CONFIG) --cflags` `$(CURL_CONFIG) --libs`)
|
`$(PKG_CONFIG) --cflags --libs libcurl`)
|
||||||
$(CURL_CONFIG) --ssl-backends | grep OpenSSL >/dev/null 2>&1 || { echo "Error: libcurl is not built with the OpenSSL backend"; exit 1; }
|
$(CURL_CONFIG) --ssl-backends | grep OpenSSL >/dev/null 2>&1 || { echo "Error: libcurl is not built with the OpenSSL backend"; exit 1; }
|
||||||
touch check-dep-libekmfweb
|
touch check-dep-libekmfweb
|
||||||
|
|
||||||
@@ -85,8 +85,8 @@ ekmfweb.o: check-dep-libekmfweb ekmfweb.c utilities.h cca.h $(rootdir)include/ek
|
|||||||
utilities.o: check-dep-libekmfweb utilities.c utilities.h $(rootdir)include/ekmfweb/ekmfweb.h
|
utilities.o: check-dep-libekmfweb utilities.c utilities.h $(rootdir)include/ekmfweb/ekmfweb.h
|
||||||
cca.o: check-dep-libekmfweb cca.c cca.h utilities.h $(rootdir)include/ekmfweb/ekmfweb.h
|
cca.o: check-dep-libekmfweb cca.c cca.h utilities.h $(rootdir)include/ekmfweb/ekmfweb.h
|
||||||
|
|
||||||
libekmfweb.so.$(VERSION): ALL_CFLAGS += -fPIC `$(CURL_CONFIG) --cflags`
|
libekmfweb.so.$(VERSION): ALL_CFLAGS += -fPIC `$(PKG_CONFIG) --cflags json-c libcurl libcrypto libssl`
|
||||||
libekmfweb.so.$(VERSION): LDLIBS = -ljson-c -lcrypto -lssl `$(CURL_CONFIG) --libs` -ldl
|
libekmfweb.so.$(VERSION): LDLIBS = `$(PKG_CONFIG) --libs json-c libcurl libcrypto libssl` -ldl
|
||||||
libekmfweb.so.$(VERSION): ALL_LDFLAGS += -shared -Wl,--version-script=libekmfweb.map \
|
libekmfweb.so.$(VERSION): ALL_LDFLAGS += -shared -Wl,--version-script=libekmfweb.map \
|
||||||
-Wl,-z,defs,-Bsymbolic -Wl,-soname,libekmfweb.so.$(VERM)
|
-Wl,-z,defs,-Bsymbolic -Wl,-soname,libekmfweb.so.$(VERM)
|
||||||
libekmfweb.so.$(VERSION): ekmfweb.o utilities.o cca.o $(libs)
|
libekmfweb.so.$(VERSION): ekmfweb.o utilities.o cca.o $(libs)
|
||||||
@@ -98,7 +98,7 @@ install-libekmfweb.so.$(VERSION): libekmfweb.so.$(VERSION)
|
|||||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 755 -T libekmfweb.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so.$(VERSION)
|
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 755 -T libekmfweb.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so.$(VERSION)
|
||||||
ln -srf $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so.$(VERM)
|
ln -srf $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so.$(VERM)
|
||||||
ln -srf $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so
|
ln -srf $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so
|
||||||
$(INSTALL) -d -m 770 $(DESTDIR)$(USRINCLUDEDIR)/ekmfweb
|
$(INSTALL) -d -m 755 $(DESTDIR)$(USRINCLUDEDIR)/ekmfweb
|
||||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 $(rootdir)include/ekmfweb/ekmfweb.h $(DESTDIR)$(USRINCLUDEDIR)/ekmfweb
|
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 $(rootdir)include/ekmfweb/ekmfweb.h $(DESTDIR)$(USRINCLUDEDIR)/ekmfweb
|
||||||
|
|
||||||
install: all $(INSTALL_TARGETS)
|
install: all $(INSTALL_TARGETS)
|
||||||
|
|||||||
@@ -51,7 +51,6 @@ detect-openssl-version.dep:
|
|||||||
mv $(TMPFILE) $@
|
mv $(TMPFILE) $@
|
||||||
|
|
||||||
CURL_CONFIG ?= curl-config
|
CURL_CONFIG ?= curl-config
|
||||||
XML2_CONFIG ?= xml2-config
|
|
||||||
|
|
||||||
check-dep-libkmipclient: detect-openssl-version.dep
|
check-dep-libkmipclient: detect-openssl-version.dep
|
||||||
$(call check_dep, \
|
$(call check_dep, \
|
||||||
@@ -59,7 +58,7 @@ check-dep-libkmipclient: detect-openssl-version.dep
|
|||||||
"detect-openssl-version.dep", \
|
"detect-openssl-version.dep", \
|
||||||
"openssl-devel version >= 1.1.1", \
|
"openssl-devel version >= 1.1.1", \
|
||||||
"HAVE_OPENSSL=0", \
|
"HAVE_OPENSSL=0", \
|
||||||
-I. -lcrypto -DOPENSSL_SUPPRESS_DEPRECATED)
|
-I. `$(PKG_CONFIG) --cflags --libs libcrypto` -DOPENSSL_SUPPRESS_DEPRECATED)
|
||||||
$(call check_dep, \
|
$(call check_dep, \
|
||||||
"libkmipclient", \
|
"libkmipclient", \
|
||||||
"json-c/json.h", \
|
"json-c/json.h", \
|
||||||
@@ -70,13 +69,13 @@ check-dep-libkmipclient: detect-openssl-version.dep
|
|||||||
"libxml/tree.h", \
|
"libxml/tree.h", \
|
||||||
"libxml2-devel", \
|
"libxml2-devel", \
|
||||||
"HAVE_LIBXML2=0", \
|
"HAVE_LIBXML2=0", \
|
||||||
`$(XML2_CONFIG) --cflags` `$(XML2_CONFIG) --libs`)
|
`$(PKG_CONFIG) --cflags --libs libxml-2.0`)
|
||||||
$(call check_dep, \
|
$(call check_dep, \
|
||||||
"libkmipclient", \
|
"libkmipclient", \
|
||||||
"curl/curl.h", \
|
"curl/curl.h", \
|
||||||
"libcurl-devel", \
|
"libcurl-devel", \
|
||||||
"HAVE_LIBCURL=0" \
|
"HAVE_LIBCURL=0" \
|
||||||
`$(CURL_CONFIG) --cflags` `$(CURL_CONFIG) --libs`)
|
`$(PKG_CONFIG) --cflags --libs libcurl`)
|
||||||
$(CURL_CONFIG) --ssl-backends | grep OpenSSL >/dev/null 2>&1 || { echo "Error: libcurl is not built with the OpenSSL backend"; exit 1; }
|
$(CURL_CONFIG) --ssl-backends | grep OpenSSL >/dev/null 2>&1 || { echo "Error: libcurl is not built with the OpenSSL backend"; exit 1; }
|
||||||
touch check-dep-libkmipclient
|
touch check-dep-libkmipclient
|
||||||
|
|
||||||
@@ -107,8 +106,8 @@ tls.o: check-dep-libkmipclient tls.c kmip.h utils.h $(rootdir)include/kmipclient
|
|||||||
names.o: check-dep-libkmipclient names.c names.h utils.h $(rootdir)include/kmipclient/kmipclient.h
|
names.o: check-dep-libkmipclient names.c names.h utils.h $(rootdir)include/kmipclient/kmipclient.h
|
||||||
utils.o: check-dep-libkmipclient utils.c names.h utils.h $(rootdir)include/kmipclient/kmipclient.h
|
utils.o: check-dep-libkmipclient utils.c names.h utils.h $(rootdir)include/kmipclient/kmipclient.h
|
||||||
|
|
||||||
libkmipclient.so.$(VERSION): ALL_CFLAGS += -fPIC `$(XML2_CONFIG) --cflags` `$(CURL_CONFIG) --cflags`
|
libkmipclient.so.$(VERSION): ALL_CFLAGS += -fPIC `$(PKG_CONFIG) --cflags json-c libcrypto libssl libxml-2.0 libcurl`
|
||||||
libkmipclient.so.$(VERSION): LDLIBS = -ljson-c -lcrypto -lssl `$(XML2_CONFIG) --libs` `$(CURL_CONFIG) --libs`
|
libkmipclient.so.$(VERSION): LDLIBS = `$(PKG_CONFIG) --libs json-c libcrypto libssl libxml-2.0 libcurl`
|
||||||
libkmipclient.so.$(VERSION): ALL_LDFLAGS += -shared -Wl,--version-script=libkmipclient.map \
|
libkmipclient.so.$(VERSION): ALL_LDFLAGS += -shared -Wl,--version-script=libkmipclient.map \
|
||||||
-Wl,-z,defs,-Bsymbolic -Wl,-soname,libkmipclient.so.$(VERM)
|
-Wl,-z,defs,-Bsymbolic -Wl,-soname,libkmipclient.so.$(VERM)
|
||||||
libkmipclient.so.$(VERSION): kmip.o request.o response.o attribute.o key.o ttlv.o json.o \
|
libkmipclient.so.$(VERSION): kmip.o request.o response.o attribute.o key.o ttlv.o json.o \
|
||||||
@@ -121,7 +120,7 @@ install-libkmipclient.so.$(VERSION): libkmipclient.so.$(VERSION)
|
|||||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 755 -T libkmipclient.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so.$(VERSION)
|
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 755 -T libkmipclient.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so.$(VERSION)
|
||||||
ln -srf $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so.$(VERM)
|
ln -srf $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so.$(VERM)
|
||||||
ln -srf $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so
|
ln -srf $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so
|
||||||
$(INSTALL) -d -m 770 $(DESTDIR)$(USRINCLUDEDIR)/kmipclient
|
$(INSTALL) -d -m 755 $(DESTDIR)$(USRINCLUDEDIR)/kmipclient
|
||||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 $(rootdir)include/kmipclient/kmipclient.h $(DESTDIR)$(USRINCLUDEDIR)/kmipclient
|
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 $(rootdir)include/kmipclient/kmipclient.h $(DESTDIR)$(USRINCLUDEDIR)/kmipclient
|
||||||
|
|
||||||
install: all $(INSTALL_TARGETS)
|
install: all $(INSTALL_TARGETS)
|
||||||
|
|||||||
@@ -16,6 +16,7 @@
|
|||||||
#include <openssl/ssl.h>
|
#include <openssl/ssl.h>
|
||||||
|
|
||||||
#include <json-c/json.h>
|
#include <json-c/json.h>
|
||||||
|
#include <libxml/parser.h>
|
||||||
#include <libxml/tree.h>
|
#include <libxml/tree.h>
|
||||||
#include <curl/curl.h>
|
#include <curl/curl.h>
|
||||||
|
|
||||||
|
|||||||
+1
-2
@@ -21,8 +21,7 @@ WARNINGS := -Wall -Wextra -Wshadow \
|
|||||||
-Wno-unused-function -Wno-unused-parameter -Wno-unused-variable \
|
-Wno-unused-function -Wno-unused-parameter -Wno-unused-variable \
|
||||||
$(NULL)
|
$(NULL)
|
||||||
|
|
||||||
ALL_CFLAGS += -std=gnu11 \
|
ALL_CFLAGS += -DOPENSSL_API_COMPAT=0x10101000L \
|
||||||
-DOPENSSL_API_COMPAT=0x10101000L \
|
|
||||||
$(GLIB2_CFLAGS) \
|
$(GLIB2_CFLAGS) \
|
||||||
$(LIBCRYPTO_CFLAGS) \
|
$(LIBCRYPTO_CFLAGS) \
|
||||||
$(LIBCURL_CFLAGS) \
|
$(LIBCURL_CFLAGS) \
|
||||||
|
|||||||
+100
-48
@@ -857,7 +857,7 @@ static gboolean x509_name_data_by_nid_equal(X509_NAME *name, int nid, const char
|
|||||||
|
|
||||||
/* Checks whether the subject of @cert is a IBM signing key subject. For this we
|
/* Checks whether the subject of @cert is a IBM signing key subject. For this we
|
||||||
* must check that the subject is equal to: 'C = US, ST = New York, L =
|
* must check that the subject is equal to: 'C = US, ST = New York, L =
|
||||||
* Poughkeepsie, O = International Business Machines Corporation, CN =
|
* Poughkeepsie or Armonk, O = International Business Machines Corporation, CN =
|
||||||
* International Business Machines Corporation' and the organization unit (OUT)
|
* International Business Machines Corporation' and the organization unit (OUT)
|
||||||
* must end with the suffix ' Key Signing Service'.
|
* must end with the suffix ' Key Signing Service'.
|
||||||
*/
|
*/
|
||||||
@@ -879,7 +879,10 @@ static gboolean has_ibm_signing_subject(X509 *cert)
|
|||||||
if (!x509_name_data_by_nid_equal(subject, NID_stateOrProvinceName, PV_IBM_Z_SUBJECT_STATE))
|
if (!x509_name_data_by_nid_equal(subject, NID_stateOrProvinceName, PV_IBM_Z_SUBJECT_STATE))
|
||||||
return FALSE;
|
return FALSE;
|
||||||
|
|
||||||
if (!x509_name_data_by_nid_equal(subject, NID_localityName, PV_IBM_Z_SUBJECT_LOCALITY_NAME))
|
if (!(x509_name_data_by_nid_equal(subject, NID_localityName,
|
||||||
|
PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE) ||
|
||||||
|
x509_name_data_by_nid_equal(subject, NID_localityName,
|
||||||
|
PV_IBM_Z_SUBJECT_LOCALITY_NAME_ARMONK)))
|
||||||
return FALSE;
|
return FALSE;
|
||||||
|
|
||||||
if (!x509_name_data_by_nid_equal(subject, NID_organizationName,
|
if (!x509_name_data_by_nid_equal(subject, NID_organizationName,
|
||||||
@@ -1085,10 +1088,9 @@ static int check_signature_algo_match(const EVP_PKEY *pkey, const X509 *subject,
|
|||||||
|
|
||||||
/* It's almost the same as X509_check_issed from OpenSSL does except that we
|
/* It's almost the same as X509_check_issed from OpenSSL does except that we
|
||||||
* don't check the key usage of the potential issuer. This means we check:
|
* don't check the key usage of the potential issuer. This means we check:
|
||||||
* 1. issuer_name(cert) == subject_name(issuer)
|
* 1. Check whether the akid(cert) (if available) matches the issuer skid
|
||||||
* 2. Check whether the akid(cert) (if available) matches the issuer skid
|
* 2. Check that the cert algrithm matches the subject algorithm
|
||||||
* 3. Check that the cert algrithm matches the subject algorithm
|
* 3. Verify the signature of certificate @cert is using the public key of
|
||||||
* 4. Verify the signature of certificate @cert is using the public key of
|
|
||||||
* @issuer.
|
* @issuer.
|
||||||
*/
|
*/
|
||||||
static int check_host_key_issued(X509 *cert, X509 *issuer, GError **error)
|
static int check_host_key_issued(X509 *cert, X509 *issuer, GError **error)
|
||||||
@@ -1097,19 +1099,6 @@ static int check_host_key_issued(X509 *cert, X509 *issuer, GError **error)
|
|||||||
const X509_NAME *cert_issuer = X509_get_issuer_name(cert);
|
const X509_NAME *cert_issuer = X509_get_issuer_name(cert);
|
||||||
g_autoptr(AUTHORITY_KEYID) akid = NULL;
|
g_autoptr(AUTHORITY_KEYID) akid = NULL;
|
||||||
|
|
||||||
/* We cannot use X509_NAME_cmp() because it considers the order of the
|
|
||||||
* X509_NAME_Entries.
|
|
||||||
*/
|
|
||||||
if (!own_X509_NAME_equal(issuer_subject, cert_issuer)) {
|
|
||||||
g_autofree char *issuer_subject_str = pv_X509_NAME_oneline(issuer_subject);
|
|
||||||
g_autofree char *cert_issuer_str = pv_X509_NAME_oneline(cert_issuer);
|
|
||||||
|
|
||||||
g_set_error(error, PV_CERT_ERROR, PV_CERT_ERROR_CERT_SUBJECT_ISSUER_MISMATCH,
|
|
||||||
_("Subject issuer mismatch:\n'%s'\n'%s'"), issuer_subject_str,
|
|
||||||
cert_issuer_str);
|
|
||||||
return -1;
|
|
||||||
}
|
|
||||||
|
|
||||||
akid = X509_get_ext_d2i(cert, NID_authority_key_identifier, NULL, NULL);
|
akid = X509_get_ext_d2i(cert, NID_authority_key_identifier, NULL, NULL);
|
||||||
if (akid && X509_check_akid(issuer, akid) != X509_V_OK) {
|
if (akid && X509_check_akid(issuer, akid) != X509_V_OK) {
|
||||||
g_set_error(error, PV_CERT_ERROR, PV_CERT_ERROR_SKID_AKID_MISMATCH,
|
g_set_error(error, PV_CERT_ERROR, PV_CERT_ERROR_SKID_AKID_MISMATCH,
|
||||||
@@ -1286,21 +1275,10 @@ int pv_verify_cert(X509_STORE_CTX *ctx, X509 *cert, GError **error)
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* Verify that: subject(issuer) == issuer(crl) and SKID(issuer) == AKID(crl) */
|
/* Verify that SKID(issuer) == AKID(crl) */
|
||||||
static int check_crl_issuer(X509_CRL *crl, X509 *issuer, GError **error)
|
static int check_crl_issuer(X509_CRL *crl, X509 *issuer, GError **error)
|
||||||
{
|
{
|
||||||
const X509_NAME *crl_issuer = X509_CRL_get_issuer(crl);
|
g_autoptr(AUTHORITY_KEYID) akid = NULL;
|
||||||
const X509_NAME *issuer_subject = X509_get_subject_name(issuer);
|
|
||||||
AUTHORITY_KEYID *akid = NULL;
|
|
||||||
|
|
||||||
if (!own_X509_NAME_equal(issuer_subject, crl_issuer)) {
|
|
||||||
g_autofree char *issuer_subject_str = pv_X509_NAME_oneline(issuer_subject);
|
|
||||||
g_autofree char *crl_issuer_str = pv_X509_NAME_oneline(crl_issuer);
|
|
||||||
|
|
||||||
g_set_error(error, PV_CERT_ERROR, PV_CERT_ERROR_CRL_SUBJECT_ISSUER_MISMATCH,
|
|
||||||
_("issuer mismatch:\n%s\n%s"), issuer_subject_str, crl_issuer_str);
|
|
||||||
return -1;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* If AKID(@crl) is specified it must match with SKID(@issuer) */
|
/* If AKID(@crl) is specified it must match with SKID(@issuer) */
|
||||||
akid = X509_CRL_get_ext_d2i(crl, NID_authority_key_identifier, NULL, NULL);
|
akid = X509_CRL_get_ext_d2i(crl, NID_authority_key_identifier, NULL, NULL);
|
||||||
@@ -1325,7 +1303,6 @@ int pv_verify_crl(X509_CRL *crl, X509 *cert, int verify_flags, GError **error)
|
|||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* check that the @crl issuer matches with the subject name of @cert*/
|
|
||||||
if (check_crl_issuer(crl, cert, error) < 0)
|
if (check_crl_issuer(crl, cert, error) < 0)
|
||||||
return -1;
|
return -1;
|
||||||
|
|
||||||
@@ -1393,6 +1370,93 @@ int pv_check_chain_parameters(const STACK_OF_X509 *chain, GError **error)
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/** Replace locality 'Armonk' with 'Pougkeepsie'. If Armonk was not set return
|
||||||
|
* `NULL`.
|
||||||
|
*/
|
||||||
|
static X509_NAME *x509_armonk_locality_fixup(const X509_NAME *name)
|
||||||
|
{
|
||||||
|
g_autoptr(X509_NAME) ret = NULL;
|
||||||
|
int pos;
|
||||||
|
|
||||||
|
/* Check if ``L=Armonk`` */
|
||||||
|
if (!x509_name_data_by_nid_equal((X509_NAME *)name, NID_localityName,
|
||||||
|
PV_IBM_Z_SUBJECT_LOCALITY_NAME_ARMONK))
|
||||||
|
return NULL;
|
||||||
|
|
||||||
|
ret = X509_NAME_dup((X509_NAME *)name);
|
||||||
|
if (!ret)
|
||||||
|
g_abort();
|
||||||
|
|
||||||
|
pos = X509_NAME_get_index_by_NID(ret, NID_localityName, -1);
|
||||||
|
if (pos == -1)
|
||||||
|
return NULL;
|
||||||
|
|
||||||
|
X509_NAME_ENTRY_free(X509_NAME_delete_entry(ret, pos));
|
||||||
|
|
||||||
|
/* Create a new name entry at the same position as before */
|
||||||
|
if (X509_NAME_add_entry_by_NID(
|
||||||
|
ret, NID_localityName, MBSTRING_UTF8,
|
||||||
|
(const unsigned char *)&PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE,
|
||||||
|
sizeof(PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE) - 1, pos, 0) != 1)
|
||||||
|
return NULL;
|
||||||
|
|
||||||
|
return g_steal_pointer(&ret);
|
||||||
|
}
|
||||||
|
|
||||||
|
/* This function contains work-arounds for some known subject(CRT)<->issuer(CRL)
|
||||||
|
* issues.
|
||||||
|
*/
|
||||||
|
static STACK_OF_X509_CRL *quirk_X509_STORE_ctx_get1_crls(X509_STORE_CTX *ctx,
|
||||||
|
const X509_NAME *subject, GError **err)
|
||||||
|
{
|
||||||
|
g_autoptr(X509_NAME) fixed_subject = NULL;
|
||||||
|
g_autoptr(STACK_OF_X509_CRL) ret = NULL;
|
||||||
|
|
||||||
|
ret = pv_X509_STORE_CTX_get1_crls(ctx, subject);
|
||||||
|
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||||
|
return g_steal_pointer(&ret);
|
||||||
|
|
||||||
|
/* Workaround to fix the mismatch between issuer name of the * IBM
|
||||||
|
* signing CRLs and the IBM signing key subject name. Locality name has
|
||||||
|
* changed from Poughkeepsie to Armonk.
|
||||||
|
*/
|
||||||
|
fixed_subject = x509_armonk_locality_fixup(subject);
|
||||||
|
/* Was the locality replaced? */
|
||||||
|
if (fixed_subject) {
|
||||||
|
X509_NAME *tmp;
|
||||||
|
|
||||||
|
sk_X509_CRL_free(ret);
|
||||||
|
ret = pv_X509_STORE_CTX_get1_crls(ctx, fixed_subject);
|
||||||
|
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||||
|
return g_steal_pointer(&ret);
|
||||||
|
|
||||||
|
/* Workaround to fix the ordering mismatch between issuer name
|
||||||
|
* of the IBM signing CRLs and the IBM signing key subject name.
|
||||||
|
*/
|
||||||
|
tmp = fixed_subject;
|
||||||
|
fixed_subject = pv_c2b_name(fixed_subject);
|
||||||
|
X509_NAME_free(tmp);
|
||||||
|
sk_X509_CRL_free(ret);
|
||||||
|
ret = pv_X509_STORE_CTX_get1_crls(ctx, fixed_subject);
|
||||||
|
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||||
|
return g_steal_pointer(&ret);
|
||||||
|
X509_NAME_free(fixed_subject);
|
||||||
|
fixed_subject = NULL;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Workaround to fix the ordering mismatch between issuer name of the
|
||||||
|
* IBM signing CRLs and the IBM signing key subject name.
|
||||||
|
*/
|
||||||
|
fixed_subject = pv_c2b_name(subject);
|
||||||
|
sk_X509_CRL_free(ret);
|
||||||
|
ret = pv_X509_STORE_CTX_get1_crls(ctx, fixed_subject);
|
||||||
|
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||||
|
return g_steal_pointer(&ret);
|
||||||
|
|
||||||
|
g_set_error(err, PV_CERT_ERROR, PV_CERT_ERROR_NO_CRL, _("no CRL found"));
|
||||||
|
return NULL;
|
||||||
|
}
|
||||||
|
|
||||||
/* Given a certificate @cert try to find valid revocation lists in @ctx. If no
|
/* Given a certificate @cert try to find valid revocation lists in @ctx. If no
|
||||||
* valid CRL was found NULL is returned.
|
* valid CRL was found NULL is returned.
|
||||||
*/
|
*/
|
||||||
@@ -1412,21 +1476,9 @@ STACK_OF_X509_CRL *pv_store_ctx_find_valid_crls(X509_STORE_CTX *ctx, X509 *cert,
|
|||||||
return NULL;
|
return NULL;
|
||||||
}
|
}
|
||||||
|
|
||||||
ret = pv_X509_STORE_CTX_get1_crls(ctx, subject);
|
ret = quirk_X509_STORE_ctx_get1_crls(ctx, subject, error);
|
||||||
if (!ret) {
|
if (!ret)
|
||||||
/* Workaround to fix the mismatch between issuer name of the
|
return NULL;
|
||||||
* IBM Z signing CRLs and the IBM Z signing key subject name.
|
|
||||||
*/
|
|
||||||
g_autoptr(X509_NAME) broken_subject = pv_c2b_name(subject);
|
|
||||||
|
|
||||||
ret = pv_X509_STORE_CTX_get1_crls(ctx, broken_subject);
|
|
||||||
if (!ret) {
|
|
||||||
g_set_error(error, PV_CERT_ERROR, PV_CERT_ERROR_NO_CRL, _("no CRL found"));
|
|
||||||
g_info("ERROR: %s", (*error)->message);
|
|
||||||
return NULL;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Filter out non-valid CRLs for @cert */
|
/* Filter out non-valid CRLs for @cert */
|
||||||
for (int i = 0; i < sk_X509_CRL_num(ret); i++) {
|
for (int i = 0; i < sk_X509_CRL_num(ret); i++) {
|
||||||
X509_CRL *crl = sk_X509_CRL_value(ret, i);
|
X509_CRL *crl = sk_X509_CRL_value(ret, i);
|
||||||
|
|||||||
+3
-2
@@ -90,10 +90,10 @@ const char *util_arch_machine_type_to_str(int type)
|
|||||||
case UTIL_ARCH_MACHINE_TYPE_Z14_ZR1:
|
case UTIL_ARCH_MACHINE_TYPE_Z14_ZR1:
|
||||||
return "IBM z14 ZR1";
|
return "IBM z14 ZR1";
|
||||||
case UTIL_ARCH_MACHINE_TYPE_Z15:
|
case UTIL_ARCH_MACHINE_TYPE_Z15:
|
||||||
return "IBM z15";
|
|
||||||
case UTIL_ARCH_MACHINE_TYPE_Z15_T02:
|
case UTIL_ARCH_MACHINE_TYPE_Z15_T02:
|
||||||
return "IBM z15 Model T02";
|
return "IBM z15";
|
||||||
case UTIL_ARCH_MACHINE_TYPE_Z16:
|
case UTIL_ARCH_MACHINE_TYPE_Z16:
|
||||||
|
case UTIL_ARCH_MACHINE_TYPE_Z16_A02:
|
||||||
return "IBM z16";
|
return "IBM z16";
|
||||||
default:
|
default:
|
||||||
return "Unknown machine type";
|
return "Unknown machine type";
|
||||||
@@ -111,6 +111,7 @@ unsigned long util_arch_hsa_maxsize(void)
|
|||||||
case UTIL_ARCH_MACHINE_TYPE_Z15:
|
case UTIL_ARCH_MACHINE_TYPE_Z15:
|
||||||
case UTIL_ARCH_MACHINE_TYPE_Z15_T02:
|
case UTIL_ARCH_MACHINE_TYPE_Z15_T02:
|
||||||
case UTIL_ARCH_MACHINE_TYPE_Z16:
|
case UTIL_ARCH_MACHINE_TYPE_Z16:
|
||||||
|
case UTIL_ARCH_MACHINE_TYPE_Z16_A02:
|
||||||
return HSA_SIZE_512M;
|
return HSA_SIZE_512M;
|
||||||
default:
|
default:
|
||||||
return HSA_SIZE_32M;
|
return HSA_SIZE_32M;
|
||||||
|
|||||||
+6
-6
@@ -311,13 +311,13 @@ int util_file_read_i(int *val, int base, const char *fmt, ...)
|
|||||||
return -1;
|
return -1;
|
||||||
switch (base) {
|
switch (base) {
|
||||||
case 8:
|
case 8:
|
||||||
count = sscanf(buf, "%do", val);
|
count = sscanf(buf, "%o", val);
|
||||||
break;
|
break;
|
||||||
case 10:
|
case 10:
|
||||||
count = sscanf(buf, "%dd", val);
|
count = sscanf(buf, "%d", val);
|
||||||
break;
|
break;
|
||||||
case 16:
|
case 16:
|
||||||
count = sscanf(buf, "%dx", val);
|
count = sscanf(buf, "%x", val);
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
util_panic("Invalid base: %d\n", base);
|
util_panic("Invalid base: %d\n", base);
|
||||||
@@ -425,13 +425,13 @@ int util_file_read_ui(unsigned int *val, int base, const char *fmt, ...)
|
|||||||
return -1;
|
return -1;
|
||||||
switch (base) {
|
switch (base) {
|
||||||
case 8:
|
case 8:
|
||||||
count = sscanf(buf, "%uo", val);
|
count = sscanf(buf, "%o", val);
|
||||||
break;
|
break;
|
||||||
case 10:
|
case 10:
|
||||||
count = sscanf(buf, "%uu", val);
|
count = sscanf(buf, "%u", val);
|
||||||
break;
|
break;
|
||||||
case 16:
|
case 16:
|
||||||
count = sscanf(buf, "%ux", val);
|
count = sscanf(buf, "%x", val);
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
util_panic("Invalid base: %d\n", base);
|
util_panic("Invalid base: %d\n", base);
|
||||||
|
|||||||
@@ -299,3 +299,35 @@ int util_lockfile_parent_release(char *lockfile)
|
|||||||
{
|
{
|
||||||
return do_lockfile_release(lockfile, getppid());
|
return do_lockfile_release(lockfile, getppid());
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Return the pid that owns the specified lockfile.
|
||||||
|
*
|
||||||
|
* @param[in] lockfile Path to the lock file
|
||||||
|
* @param[in,out] pid Buffer to place owning pid
|
||||||
|
*
|
||||||
|
* @retval 0 pid provided in buffer
|
||||||
|
* @retval !=0 Error, no pid provided
|
||||||
|
*/
|
||||||
|
int util_lockfile_peek_owner(char *lockfile, int *pid)
|
||||||
|
{
|
||||||
|
char buf[BUFSIZE];
|
||||||
|
int fd, len;
|
||||||
|
|
||||||
|
if (!lockfile || !pid)
|
||||||
|
return UTIL_LOCKFILE_ERR;
|
||||||
|
|
||||||
|
/* Open lockfile, read the owning pid if it exists */
|
||||||
|
fd = open(lockfile, O_RDONLY);
|
||||||
|
if (fd < 0)
|
||||||
|
return UTIL_LOCKFILE_ERR;
|
||||||
|
|
||||||
|
len = read(fd, buf, sizeof(buf));
|
||||||
|
close(fd);
|
||||||
|
if (len <= 0)
|
||||||
|
return UTIL_LOCKFILE_ERR;
|
||||||
|
buf[len] = 0;
|
||||||
|
*pid = atoi(buf);
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|||||||
+23
-1
@@ -45,7 +45,7 @@ vmcmd: Trigger CP command according to the 'VMCMD_X' configuration in
|
|||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB - DUMP_TYPE:\fR
|
\fB - DUMP_TYPE:\fR
|
||||||
Type of dump device. Possible values are 'ccw', 'fcp' and 'nvme'.
|
Type of dump device. Possible values are 'ccw', 'eckd', 'fcp' and 'nvme'.
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB - DEVICE:\fR
|
\fB - DEVICE:\fR
|
||||||
@@ -71,6 +71,11 @@ Namespace ID for NVMe dump device.
|
|||||||
\fB - BOOTPROG:\fR
|
\fB - BOOTPROG:\fR
|
||||||
Boot program selector.
|
Boot program selector.
|
||||||
|
|
||||||
|
.TP
|
||||||
|
\fB - BR_CHR:\fR
|
||||||
|
Boot record location in "C,H,R" format (comma separated values for
|
||||||
|
Cylinder, Head and Record) or "auto".
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
\fB - BR_LBA:\fR
|
\fB - BR_LBA:\fR
|
||||||
Boot record logical block address.
|
Boot record logical block address.
|
||||||
@@ -146,6 +151,23 @@ DEVICE=0.0.1234
|
|||||||
DELAY_MINUTES=5
|
DELAY_MINUTES=5
|
||||||
.br
|
.br
|
||||||
|
|
||||||
|
#
|
||||||
|
.br
|
||||||
|
# Example configuration for an ECKD dump device (DASD)
|
||||||
|
.br
|
||||||
|
#
|
||||||
|
.br
|
||||||
|
ON_PANIC=dump
|
||||||
|
.br
|
||||||
|
DUMP_TYPE=eckd
|
||||||
|
.br
|
||||||
|
DEVICE=0.0.1004
|
||||||
|
.br
|
||||||
|
BOOTPROG=0
|
||||||
|
.br
|
||||||
|
BR_CHR=auto
|
||||||
|
.br
|
||||||
|
|
||||||
#
|
#
|
||||||
.br
|
.br
|
||||||
# Example configuration for an FCP dump device (SCSI Disk)
|
# Example configuration for an FCP dump device (SCSI Disk)
|
||||||
|
|||||||
@@ -16,7 +16,7 @@
|
|||||||
|
|
||||||
/* we may use header_generic and header_simple_table from the util_funcs module */
|
/* we may use header_generic and header_simple_table from the util_funcs module */
|
||||||
|
|
||||||
config_require(util_funcs)
|
config_require(util_funcs);
|
||||||
|
|
||||||
|
|
||||||
/* function prototypes */
|
/* function prototypes */
|
||||||
|
|||||||
+1
-2
@@ -3,13 +3,12 @@ include ../common.mak
|
|||||||
|
|
||||||
.DEFAULT_GOAL := all
|
.DEFAULT_GOAL := all
|
||||||
|
|
||||||
PKGDATADIR := "$(DESTDIR)$(TOOLS_DATADIR)/pvattest"
|
|
||||||
SUBDIRS := src man tools
|
SUBDIRS := src man tools
|
||||||
RECURSIVE_TARGETS := all-recursive clean-recursive install-recursive
|
RECURSIVE_TARGETS := all-recursive clean-recursive install-recursive
|
||||||
|
|
||||||
all: all-recursive
|
all: all-recursive
|
||||||
|
|
||||||
install: all install-recursive
|
install: install-recursive
|
||||||
|
|
||||||
clean: clean-recursive
|
clean: clean-recursive
|
||||||
|
|
||||||
|
|||||||
@@ -24,12 +24,27 @@ Show help options
|
|||||||
\fBFILE\fP specifies the attestation result as input.
|
\fBFILE\fP specifies the attestation result as input.
|
||||||
.TP
|
.TP
|
||||||
.B
|
.B
|
||||||
|
\fB-o\fP, \fB--ouput\fP=\fBFILE\fP
|
||||||
|
\fBFILE\fP specifies the output for the verification result.
|
||||||
|
.TP
|
||||||
|
.B
|
||||||
\fB--hdr\fP=\fBFILE\fP
|
\fB--hdr\fP=\fBFILE\fP
|
||||||
Specify the header of the guest image. Exactly one is required.
|
Specify the header of the guest image. Exactly one is required.
|
||||||
.TP
|
.TP
|
||||||
.B
|
.B
|
||||||
\fB-a\fP, \fB--arpk\fP=\fBFILE\fP
|
\fB-a\fP, \fB--arpk\fP=\fBFILE\fP
|
||||||
Use \fBFILE\fP to specify the GCM-AES256 key to decrypt the attestation request. Delete this key after verification.
|
Use \fBFILE\fP to specify the GCM-AES256 key to decrypt the attestation request. Delete this key after verification.
|
||||||
|
.TP
|
||||||
|
.B
|
||||||
|
\fB--format\fP=\fByaml\fP
|
||||||
|
Define the output format.
|
||||||
|
Default value: 'yaml'
|
||||||
|
|
||||||
|
Possible values:
|
||||||
|
.RS 4
|
||||||
|
- \fByaml\fP: Use YAML format
|
||||||
|
.RE
|
||||||
|
|
||||||
.TP
|
.TP
|
||||||
.B
|
.B
|
||||||
\fB-V\fP, \fB--verbose\fP
|
\fB-V\fP, \fB--verbose\fP
|
||||||
|
|||||||
@@ -1,10 +1,7 @@
|
|||||||
include ../../common.mak
|
include ../../common.mak
|
||||||
|
|
||||||
BIN_PROGRAM = pvattest
|
BIN_PROGRAM = pvattest
|
||||||
PKGDATADIR ?= "$(DESTDIR)$(TOOLS_DATADIR)/$(BIN_PROGRAM)"
|
|
||||||
|
|
||||||
SRC_DIR := $(dir $(realpath $(firstword $(MAKEFILE_LIST))))
|
SRC_DIR := $(dir $(realpath $(firstword $(MAKEFILE_LIST))))
|
||||||
PVATTESTDIR := $(rootdir)/pvattest
|
|
||||||
INCLUDE_PATHS = "$(SRC_DIR)" "$(rootdir)/include"
|
INCLUDE_PATHS = "$(SRC_DIR)" "$(rootdir)/include"
|
||||||
INCLUDE_PARMS = $(addprefix -I,$(INCLUDE_PATHS))
|
INCLUDE_PARMS = $(addprefix -I,$(INCLUDE_PATHS))
|
||||||
|
|
||||||
@@ -35,9 +32,7 @@ LIBCRYPTO_LIBS := $(shell $(PKG_CONFIG) --silence-errors --libs libcrypto)
|
|||||||
LIBCURL_CFLAGS := $(shell $(PKG_CONFIG) --silence-errors --cflags libcurl)
|
LIBCURL_CFLAGS := $(shell $(PKG_CONFIG) --silence-errors --cflags libcurl)
|
||||||
LIBCURL_LIBS := $(shell $(PKG_CONFIG) --silence-errors --libs libcurl)
|
LIBCURL_LIBS := $(shell $(PKG_CONFIG) --silence-errors --libs libcurl)
|
||||||
|
|
||||||
ALL_CFLAGS += -std=gnu11 \
|
ALL_CFLAGS += -DOPENSSL_API_COMPAT=0x10101000L \
|
||||||
-DPKGDATADIR=$(PKGDATADIR) \
|
|
||||||
-DOPENSSL_API_COMPAT=0x10101000L \
|
|
||||||
$(GLIB2_CFLAGS) \
|
$(GLIB2_CFLAGS) \
|
||||||
$(LIBCRYPTO_CFLAGS) \
|
$(LIBCRYPTO_CFLAGS) \
|
||||||
$(LIBCURL_CFLAGS) \
|
$(LIBCURL_CFLAGS) \
|
||||||
|
|||||||
+37
-8
@@ -49,8 +49,10 @@ static pvattest_config_t pvattest_config = {
|
|||||||
},
|
},
|
||||||
.verify = {
|
.verify = {
|
||||||
.input_path = NULL,
|
.input_path = NULL,
|
||||||
|
.output_path = NULL,
|
||||||
.hdr_path = NULL,
|
.hdr_path = NULL,
|
||||||
.arp_key_in_path = NULL,
|
.arp_key_in_path = NULL,
|
||||||
|
.output_fmt = VERIFY_FMT_YAML,
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
typedef gboolean (*verify_options_fn_t)(GError **);
|
typedef gboolean (*verify_options_fn_t)(GError **);
|
||||||
@@ -190,13 +192,13 @@ static gboolean hex_str_toull(const char *nptr, uint64_t *dst, GError **error)
|
|||||||
}
|
}
|
||||||
|
|
||||||
/* NOTE REQUIRED */
|
/* NOTE REQUIRED */
|
||||||
#define _entry_root_ca(__arg_data, __indent) \
|
#define _entry_root_ca(__arg_data, __indent) \
|
||||||
{ \
|
{ \
|
||||||
.long_name = "root-ca", .short_name = 0, .flags = G_OPTION_FLAG_NONE, \
|
.long_name = "root-ca", .short_name = 0, .flags = G_OPTION_FLAG_NONE, \
|
||||||
.arg = G_OPTION_ARG_FILENAME_ARRAY, .arg_data = __arg_data, \
|
.arg = G_OPTION_ARG_FILENAME, .arg_data = __arg_data, \
|
||||||
.description = "Use FILE as the trusted root CA instead the\n" __indent \
|
.description = "Use FILE as the trusted root CA instead the\n" __indent \
|
||||||
"root CAs that are installed on the system (optional).\n", \
|
"root CAs that are installed on the system (optional).\n", \
|
||||||
.arg_description = "FILE", \
|
.arg_description = "FILE", \
|
||||||
}
|
}
|
||||||
|
|
||||||
/* NOTE REQUIRED */
|
/* NOTE REQUIRED */
|
||||||
@@ -329,6 +331,15 @@ static gboolean hex_str_toull(const char *nptr, uint64_t *dst, GError **error)
|
|||||||
.description = "Use FILE to specify the user data.\n", .arg_description = "FILE", \
|
.description = "Use FILE to specify the user data.\n", .arg_description = "FILE", \
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#define _entry__verify_format(__indent) \
|
||||||
|
{ \
|
||||||
|
.long_name = "format", .short_name = 0, .flags = G_OPTION_FLAG_NONE, \
|
||||||
|
.arg = G_OPTION_ARG_CALLBACK, .arg_data = &set_verify_output_format, \
|
||||||
|
.description = "Define the output format.\n" __indent \
|
||||||
|
"Defaults to 'yaml'. (possible values: 'yaml')\n", \
|
||||||
|
.arg_description = "FORMAT", \
|
||||||
|
}
|
||||||
|
|
||||||
static gboolean increase_log_lvl(G_GNUC_UNUSED const char *option_name,
|
static gboolean increase_log_lvl(G_GNUC_UNUSED const char *option_name,
|
||||||
G_GNUC_UNUSED const char *value, G_GNUC_UNUSED void *data,
|
G_GNUC_UNUSED const char *value, G_GNUC_UNUSED void *data,
|
||||||
G_GNUC_UNUSED GError **error)
|
G_GNUC_UNUSED GError **error)
|
||||||
@@ -337,6 +348,20 @@ static gboolean increase_log_lvl(G_GNUC_UNUSED const char *option_name,
|
|||||||
return TRUE;
|
return TRUE;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static gboolean set_verify_output_format(const char *option_name, const char *value,
|
||||||
|
G_GNUC_UNUSED void *data, GError **error)
|
||||||
|
{
|
||||||
|
if (!g_strcmp0(value, "yaml")) {
|
||||||
|
pvattest_config.verify.output_fmt = VERIFY_FMT_YAML;
|
||||||
|
} else {
|
||||||
|
g_set_error(error, G_OPTION_ERROR, G_OPTION_ERROR_FAILED,
|
||||||
|
_("Found value '%s' for option '%s', but only 'yaml' is allowed."),
|
||||||
|
value, option_name);
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
|
return TRUE;
|
||||||
|
}
|
||||||
|
|
||||||
static gboolean create_set_paf(G_GNUC_UNUSED const char *option_name, const char *value,
|
static gboolean create_set_paf(G_GNUC_UNUSED const char *option_name, const char *value,
|
||||||
G_GNUC_UNUSED void *data, GError **error)
|
G_GNUC_UNUSED void *data, GError **error)
|
||||||
{
|
{
|
||||||
@@ -445,13 +470,16 @@ static gboolean verify_perform(GError **error)
|
|||||||
}
|
}
|
||||||
|
|
||||||
/************************* VERIFY OPTIONS ************************************/
|
/************************* VERIFY OPTIONS ************************************/
|
||||||
#define verify_indent " "
|
#define verify_indent " "
|
||||||
|
|
||||||
static GOptionEntry verify_options[] = {
|
static GOptionEntry verify_options[] = {
|
||||||
_entry_input(&pvattest_config.verify.input_path, "attestation result", verify_indent),
|
_entry_input(&pvattest_config.verify.input_path, "attestation result", verify_indent),
|
||||||
|
_entry_output(&pvattest_config.verify.output_path,
|
||||||
|
"verification result.\n" verify_indent "(optional)", verify_indent),
|
||||||
_entry_guest_hdr(&pvattest_config.verify.hdr_path, verify_indent),
|
_entry_guest_hdr(&pvattest_config.verify.hdr_path, verify_indent),
|
||||||
_entry_att_prot_key_load(&pvattest_config.verify.arp_key_in_path, verify_indent),
|
_entry_att_prot_key_load(&pvattest_config.verify.arp_key_in_path, verify_indent),
|
||||||
_entry_verbose(verify_indent),
|
_entry_verbose(verify_indent),
|
||||||
|
_entry__verify_format(verify_indent),
|
||||||
{ NULL },
|
{ NULL },
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -631,6 +659,7 @@ static void pvattest_parse_clear_verify_config(pvattest_verify_config_t *config)
|
|||||||
if (!config)
|
if (!config)
|
||||||
return;
|
return;
|
||||||
g_free(config->input_path);
|
g_free(config->input_path);
|
||||||
|
g_free(config->output_path);
|
||||||
g_free(config->hdr_path);
|
g_free(config->hdr_path);
|
||||||
g_free(config->arp_key_in_path);
|
g_free(config->arp_key_in_path);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -58,8 +58,15 @@ typedef struct {
|
|||||||
char *user_data_path; /* default NULL */
|
char *user_data_path; /* default NULL */
|
||||||
} pvattest_perform_config_t;
|
} pvattest_perform_config_t;
|
||||||
|
|
||||||
|
enum verify_output_format {
|
||||||
|
VERIFY_FMT_HUMAN,
|
||||||
|
VERIFY_FMT_YAML,
|
||||||
|
};
|
||||||
|
|
||||||
typedef struct {
|
typedef struct {
|
||||||
char *input_path;
|
char *input_path;
|
||||||
|
char *output_path;
|
||||||
|
enum verify_output_format output_fmt;
|
||||||
char *hdr_path;
|
char *hdr_path;
|
||||||
char *arp_key_in_path;
|
char *arp_key_in_path;
|
||||||
} pvattest_verify_config_t;
|
} pvattest_verify_config_t;
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user