mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
Compare commits
224 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9eea78b3ad | ||
|
|
0a3a556879 | ||
|
|
aba8900074 | ||
|
|
f5744b95db | ||
|
|
13d721afd3 | ||
|
|
90a2e6d70e | ||
|
|
bc9f8a8100 | ||
|
|
2b5e7b0491 | ||
|
|
d7c95265cd | ||
|
|
8751cfc409 | ||
|
|
01f96d30f6 | ||
|
|
fffbd93f12 | ||
|
|
ddcfbdc8d2 | ||
|
|
173fd7cdca | ||
|
|
d14e7593cc | ||
|
|
1a3d0b74f7 | ||
|
|
f6c6f0cc71 | ||
|
|
966e67a252 | ||
|
|
1c128c0d11 | ||
|
|
a3199d58db | ||
|
|
659483031e | ||
|
|
7dc2513205 | ||
|
|
0748d365a6 | ||
|
|
94a404ed10 | ||
|
|
ef1799f31f | ||
|
|
47b0960cc7 | ||
|
|
2288331a6f | ||
|
|
23e9156f43 | ||
|
|
8f99e7c4ea | ||
|
|
f3bcd94524 | ||
|
|
a2f8b19c2a | ||
|
|
588d720517 | ||
|
|
cd822cb770 | ||
|
|
b27b8e3cd3 | ||
|
|
7a2c5dc980 | ||
|
|
d9e3763d1c | ||
|
|
6f15ed3264 | ||
|
|
0d2b5af007 | ||
|
|
9e7a8f48e8 | ||
|
|
98f7a0569c | ||
|
|
551f66282e | ||
|
|
3d2ba5aaed | ||
|
|
94942a48ab | ||
|
|
ab8984a7a3 | ||
|
|
4990f643c1 | ||
|
|
34bef977e8 | ||
|
|
f36c34038b | ||
|
|
bfd0e12d22 | ||
|
|
1450f85ada | ||
|
|
2a0f1e6977 | ||
|
|
0f433b1142 | ||
|
|
ab6bcad263 | ||
|
|
e40a3e0621 | ||
|
|
e56acf4f14 | ||
|
|
17977eda30 | ||
|
|
459a257568 | ||
|
|
fb65b53b9b | ||
|
|
c8d4062f73 | ||
|
|
c8e0992814 | ||
|
|
c0a12b29d0 | ||
|
|
02dded11a5 | ||
|
|
b71279cda5 | ||
|
|
c70477f8c6 | ||
|
|
9b51b8b882 | ||
|
|
48539596ef | ||
|
|
cafa99774c | ||
|
|
b5f7ac95d8 | ||
|
|
e984b97db0 | ||
|
|
64d4e02b4f | ||
|
|
90ddef5a41 | ||
|
|
58ef99f76b | ||
|
|
43c34956fb | ||
|
|
d7dee1b9d3 | ||
|
|
94a38ebc3a | ||
|
|
0764460eaf | ||
|
|
6fd02279da | ||
|
|
6274294bc5 | ||
|
|
27708026d4 | ||
|
|
849aa5b105 | ||
|
|
0be83bfbba | ||
|
|
f8592be43d | ||
|
|
647ad51423 | ||
|
|
73f51e45a8 | ||
|
|
bc4f455151 | ||
|
|
b4b5e0b6aa | ||
|
|
9927023680 | ||
|
|
9b2fb1d4d2 | ||
|
|
689b894506 | ||
|
|
06a30ae529 | ||
|
|
ed106d7f28 | ||
|
|
9d08fd8c7e | ||
|
|
7e8126704b | ||
|
|
d96767ee45 | ||
|
|
63f31bf73e | ||
|
|
7ecfe2353f | ||
|
|
7bec672c7e | ||
|
|
5aac5deb75 | ||
|
|
54e016ae71 | ||
|
|
6b53378839 | ||
|
|
1266f86444 | ||
|
|
231c02cdeb | ||
|
|
454a8d9d7b | ||
|
|
bbe92b9cd3 | ||
|
|
7bb41732fb | ||
|
|
c217f6be6a | ||
|
|
21662d38e6 | ||
|
|
19f3842292 | ||
|
|
ae0cbf00b1 | ||
|
|
9019c6864a | ||
|
|
d1b61c37fa | ||
|
|
32b68a5fad | ||
|
|
55fdb17b18 | ||
|
|
af730c79a6 | ||
|
|
041e6131d1 | ||
|
|
5a7d7e05b8 | ||
|
|
71b93d55ef | ||
|
|
d2b5e1e2d6 | ||
|
|
a3cb877c54 | ||
|
|
6895a71cc4 | ||
|
|
d9034b01f1 | ||
|
|
488ac8c3f2 | ||
|
|
ecf36d53c8 | ||
|
|
893ad920c5 | ||
|
|
0695c79f4e | ||
|
|
8837ea24cb | ||
|
|
65222d03b9 | ||
|
|
54937495e2 | ||
|
|
8a783b81a4 | ||
|
|
093da2a5a7 | ||
|
|
b68ea5fc7d | ||
|
|
90c587408f | ||
|
|
90475fbaa5 | ||
|
|
07ff9e1da0 | ||
|
|
5637799c92 | ||
|
|
73c82441e7 | ||
|
|
6d06921276 | ||
|
|
2996b34ddf | ||
|
|
e5821301f6 | ||
|
|
f4d1874ac5 | ||
|
|
f3428929a2 | ||
|
|
263d6950a1 | ||
|
|
8024f8e31a | ||
|
|
3849b29594 | ||
|
|
0e4d4da0e5 | ||
|
|
ca3cd51f91 | ||
|
|
fda1e0d33d | ||
|
|
1a850392bc | ||
|
|
14a79eb142 | ||
|
|
271b809495 | ||
|
|
2363269c1c | ||
|
|
f1db473d11 | ||
|
|
e35d05a5e3 | ||
|
|
c61783546b | ||
|
|
c08794bdfb | ||
|
|
4905975f81 | ||
|
|
d53bfb9201 | ||
|
|
0dac47cb62 | ||
|
|
7b68552359 | ||
|
|
775495c7e7 | ||
|
|
1057f13cdc | ||
|
|
ce59a299cb | ||
|
|
8235e025d4 | ||
|
|
b301381f90 | ||
|
|
c62f930634 | ||
|
|
85eb44ac95 | ||
|
|
d5f8063900 | ||
|
|
ee66929465 | ||
|
|
1b044b8a40 | ||
|
|
f46f6d34d3 | ||
|
|
3a96e8826f | ||
|
|
84738668ca | ||
|
|
dbea311aa8 | ||
|
|
d9ce54dee3 | ||
|
|
7b056735ed | ||
|
|
33fde99138 | ||
|
|
4b486e87cc | ||
|
|
a07d1bca74 | ||
|
|
5e1ef90962 | ||
|
|
8fe214d915 | ||
|
|
bec9d1dfcd | ||
|
|
694d5d4638 | ||
|
|
a6ac7cd876 | ||
|
|
28751a097a | ||
|
|
19c795be0d | ||
|
|
dd82c26f87 | ||
|
|
c6f621d0dc | ||
|
|
e6add997eb | ||
|
|
a2baeb2fe2 | ||
|
|
a500946e50 | ||
|
|
b7c9c2679e | ||
|
|
bc8a14895a | ||
|
|
4ae68d0430 | ||
|
|
aabf97f885 | ||
|
|
a9b546cb0f | ||
|
|
5566c31458 | ||
|
|
ff96d6158e | ||
|
|
2aa9071aed | ||
|
|
adf2a030e6 | ||
|
|
0783aa99d7 | ||
|
|
5a848c98bb | ||
|
|
e98f9b9c4a | ||
|
|
faac2520c9 | ||
|
|
3d098416c6 | ||
|
|
7e53611e3a | ||
|
|
d8496160cb | ||
|
|
c7f10bc76d | ||
|
|
f8910caa59 | ||
|
|
b1d948daef | ||
|
|
4d4ddbd887 | ||
|
|
d205b47c08 | ||
|
|
2b7df1fcac | ||
|
|
53eccc0a3d | ||
|
|
951cf9d7b0 | ||
|
|
87136bb0d0 | ||
|
|
eb06ebe245 | ||
|
|
b06ca88cd4 | ||
|
|
5af2e30d9a | ||
|
|
ea3529e624 | ||
|
|
0209c11bc1 | ||
|
|
6a24660472 | ||
|
|
a3bc87d87d | ||
|
|
85493a2581 | ||
|
|
ad544565fe | ||
|
|
5e135a9daf |
3
.codespell.ignore
Normal file
3
.codespell.ignore
Normal file
@@ -0,0 +1,3 @@
|
||||
parm
|
||||
parms
|
||||
crate
|
||||
@@ -1,5 +1,4 @@
|
||||
[codespell]
|
||||
ignore-words-list = parm,parms
|
||||
skip = ''
|
||||
ignore-words = .codespell.ignore
|
||||
count = ''
|
||||
quiet-level = 3
|
||||
|
||||
@@ -8,6 +8,12 @@ insert_final_newline = true
|
||||
charset = utf-8
|
||||
indent_style = tab
|
||||
tab_width = 8
|
||||
trim_trailing_whitespace = true
|
||||
|
||||
[*.rs]
|
||||
indent_style = space
|
||||
indent_size = 4
|
||||
tab_width = 4
|
||||
|
||||
[*.sh]
|
||||
shell_variant = bash # used by `shfmt`
|
||||
@@ -19,3 +25,9 @@ indent_size = 2
|
||||
[*.py]
|
||||
indent_style = space
|
||||
indent_size = 4
|
||||
|
||||
[{Makefile,*.mak}]
|
||||
indent_style = tab
|
||||
|
||||
[{COMMIT_EDITMSG,EDIT_DESCRIPTION}]
|
||||
max_line_length = 72
|
||||
|
||||
12
.gitignore
vendored
12
.gitignore
vendored
@@ -9,6 +9,10 @@
|
||||
tags
|
||||
TAGS
|
||||
|
||||
# compile_commands.json
|
||||
# (https://clang.llvm.org/docs/JSONCompilationDatabase.html)
|
||||
compile_commands.json
|
||||
|
||||
# clangd cache (https://clangd.llvm.org/design/indexing#backgroundindex)
|
||||
.cache/
|
||||
|
||||
@@ -19,6 +23,8 @@ TAGS
|
||||
#
|
||||
# Ignore generated executables and other generated files
|
||||
#
|
||||
**/.detect-openssl.dep.c
|
||||
*.debug
|
||||
ap_tools/ap-check
|
||||
cmsfs-fuse/cmsfs-fuse
|
||||
cpacfstats/cpacfstats
|
||||
@@ -26,6 +32,7 @@ cpacfstats/cpacfstatsd
|
||||
cpumf/chcpumf
|
||||
cpumf/lscpumf
|
||||
cpumf/lshwc
|
||||
cpumf/lspai
|
||||
cpumf/pai
|
||||
cpuplugd/cpuplugd
|
||||
dasdfmt/dasdfmt
|
||||
@@ -50,8 +57,8 @@ iucvterm/src/iucvconn
|
||||
iucvterm/src/iucvtty
|
||||
iucvterm/src/ttyrun
|
||||
iucvterm/test/test_afiucv
|
||||
libap/check-dep-lock
|
||||
libap/check-dep-json
|
||||
libap/check-dep-lock
|
||||
libekmfweb/check-dep-libekmfweb
|
||||
libekmfweb/detect-openssl-version.dep
|
||||
libekmfweb/libekmfweb.so
|
||||
@@ -96,6 +103,7 @@ zdev/src/chzdev
|
||||
zdev/src/chzdev_usage.c
|
||||
zdev/src/lszdev
|
||||
zdev/src/lszdev_usage.c
|
||||
zdev/src/zdev_id
|
||||
zdsfs/zdsfs
|
||||
zdump/.check_dep_fuse
|
||||
zdump/.check_dep_zgetdump
|
||||
@@ -115,7 +123,6 @@ zipl/boot/*.exec
|
||||
zipl/boot/.loaders
|
||||
zipl/boot/data.h
|
||||
zipl/src/chreipl_helper.device-mapper
|
||||
zdev/src/zdev_id
|
||||
zipl/src/zipl
|
||||
zipl/src/zipl-editenv
|
||||
zipl/src/zipl_helper.device-mapper
|
||||
@@ -129,4 +136,3 @@ zkey/kmip/zkey-kmip.so
|
||||
zkey/zkey
|
||||
zkey/zkey-cryptsetup
|
||||
zpcictl/zpcictl
|
||||
**/.detect-openssl.dep.c
|
||||
|
||||
35
.pre-commit-config.yaml
Normal file
35
.pre-commit-config.yaml
Normal file
@@ -0,0 +1,35 @@
|
||||
---
|
||||
exclude: \.(crt|crl)$
|
||||
repos:
|
||||
- repo: https://github.com/pre-commit/pre-commit-hooks
|
||||
rev: v4.1.0
|
||||
hooks:
|
||||
- id: check-merge-conflict
|
||||
- id: end-of-file-fixer
|
||||
- id: mixed-line-ending
|
||||
- id: trailing-whitespace
|
||||
- id: check-executables-have-shebangs
|
||||
- id: check-shebang-scripts-are-executable
|
||||
exclude_types: ['rust']
|
||||
- repo: local
|
||||
hooks:
|
||||
- id: git-clang-format
|
||||
name: git-clang-format
|
||||
description: Run git-clang-format
|
||||
entry: git
|
||||
args: [clang-format, --staged, --]
|
||||
pass_filenames: true
|
||||
language: system
|
||||
require_serial: true
|
||||
minimum_pre_commit_version: "2.9.0"
|
||||
types_or: [c++, c]
|
||||
- repo: https://github.com/codespell-project/codespell
|
||||
rev: v2.2.1
|
||||
hooks:
|
||||
- id: codespell
|
||||
exclude_types: ['rust']
|
||||
- repo: https://github.com/jumanjihouse/pre-commit-hooks
|
||||
rev: 3.0.0
|
||||
hooks:
|
||||
- id: shellcheck
|
||||
args: ["--external-sources"]
|
||||
12
.rustfmt.toml
Normal file
12
.rustfmt.toml
Normal file
@@ -0,0 +1,12 @@
|
||||
edition = "2021"
|
||||
newline_style = "Unix"
|
||||
|
||||
# Unstable options that help catching some mistakes in formatting and that we may want to enable
|
||||
# when they become stable.
|
||||
#
|
||||
# They are kept here since they are useful to run from time to time.
|
||||
#format_code_in_doc_comments = true
|
||||
#reorder_impl_items = true
|
||||
#comment_width = 100
|
||||
#wrap_comments = true
|
||||
#normalize_comments = true
|
||||
5
.shellcheckrc
Normal file
5
.shellcheckrc
Normal file
@@ -0,0 +1,5 @@
|
||||
# Search in the current script's directory by default (since 0.7.0)
|
||||
source-path=SCRIPTDIR
|
||||
|
||||
# Allow external-sources (since 0.8.0)
|
||||
external-sources=true
|
||||
@@ -27,6 +27,7 @@ List of all individuals having contributed content to s390-tools
|
||||
- Eberhard Pasch
|
||||
- Eduard Shishkin
|
||||
- Einar Lueck
|
||||
- Eric Farman
|
||||
- Eric Sandeen
|
||||
- Erwin Vicari
|
||||
- Eugene Crosser
|
||||
@@ -35,6 +36,7 @@ List of all individuals having contributed content to s390-tools
|
||||
- Farhan Ali
|
||||
- Fedor Loshakov
|
||||
- Felix Beck
|
||||
- Finn Callies
|
||||
- Frank Blaschka
|
||||
- Frank Heimes
|
||||
- Frank Munzert
|
||||
@@ -56,6 +58,7 @@ List of all individuals having contributed content to s390-tools
|
||||
- Horst Hummel
|
||||
- Ingo Franzki
|
||||
- Ingo Tuchscherer
|
||||
- Jakub Čajka
|
||||
- Jan Glauber
|
||||
- Jan Höppner
|
||||
- Jan Willeke
|
||||
@@ -124,6 +127,8 @@ List of all individuals having contributed content to s390-tools
|
||||
- Thomas Richter
|
||||
- Thomas Spatzier
|
||||
- Thomas Weber
|
||||
- Thorsten Winkler
|
||||
- Tobias Huschle
|
||||
- Tuan Hoang
|
||||
- Ursula Braun
|
||||
- Utz Bacher
|
||||
@@ -134,3 +139,4 @@ List of all individuals having contributed content to s390-tools
|
||||
- Volker Sameske
|
||||
- Wenjia Zhang
|
||||
- Wolfgang Taphorn
|
||||
- Yaakov Selkowitz
|
||||
|
||||
96
CHANGELOG.md
96
CHANGELOG.md
@@ -1,6 +1,102 @@
|
||||
Release history for s390-tools (MIT version)
|
||||
--------------------------------------------
|
||||
|
||||
* __v2.32.0 (2024-04-03)__
|
||||
|
||||
For Linux kernel version: 6.8
|
||||
|
||||
Changes of existing tools:
|
||||
- cpumf/lscpumf: add support for machine type 3932
|
||||
- genprotimg, pvattest, and pvsecret accept IBM signing key with Armonk as
|
||||
subject locality
|
||||
- zdump/zipl: Support for List-Directed dump from ECKD DASD
|
||||
- zkey: Detect FIPS mode and generate PBKDF for luksFormat according to it
|
||||
|
||||
Bug Fixes:
|
||||
- dbginfo.sh: dash compatible copy sequence
|
||||
- rust/pv_core: Fix UvDeviceInfo::get() method
|
||||
- zipl/src: Fix leak of files if run with a broken configuration
|
||||
- zkey: Fix convert command to accept only keys of type CCA-AESDATA
|
||||
|
||||
* __v2.31.0 (2024-02-02)__
|
||||
|
||||
For Linux kernel version: 6.7
|
||||
|
||||
General:
|
||||
- common.mak: Set default C/C++ standard to gnu11/gnu++11
|
||||
|
||||
Add new tools / libraries:
|
||||
- pvapconfig: Tool to automatically configure APQNs in SE KVM guests
|
||||
- s390-tools: Provide pre-commit configuration
|
||||
|
||||
Changes of existing tools:
|
||||
- cpuplugd: Adjust to CPU 0 being no longer hotpluggable
|
||||
- dbginfo.sh: Check for Dynamic Partition Mode
|
||||
- dbginfo.sh: Update man page and copyright
|
||||
- rust/pv: Add user-data signing and verifying
|
||||
- rust/pvsecret: Add user defined signatures and verifications
|
||||
- zdev/dracut: Consolidate device configuration
|
||||
|
||||
Bug Fixes:
|
||||
- dbginfo.sh: Fix relative path on script copy
|
||||
- libkmipclient: Fix build with libxml2-2.12.0
|
||||
- pvsecret: Fix panic if empty file is used as host key document
|
||||
- rust/pv: Fix 'elided_lifetimes_in_associated_constant' warning
|
||||
|
||||
* __v2.30.0 (2023-12-01)__
|
||||
|
||||
For Linux kernel version: 6.6
|
||||
|
||||
Add new tools / libraries:
|
||||
- lspai: Tool to display PAI counter sets
|
||||
- s390-tools: Provide a ShellCheck configuration
|
||||
|
||||
Changes of existing tools / libraries:
|
||||
- cpumf/pai: Add command line option for realtime scheduling
|
||||
- dbginfo.sh: enhance ethtool collection for ROCE
|
||||
- libutil/util_lockfile: add routine to return owning pid of file lock
|
||||
- lszcrypt: Improve lszcrypt output on SE guests
|
||||
- rust: Use a single workspace for all rust tools
|
||||
- zdev: limit the derivation of ZDEV_SITE_ID
|
||||
- zdump/df_s390: Update 'zgetdump -i' output with zlib info
|
||||
- zdump/dfi_s390: Support reading compressed s390_ext dumps
|
||||
- zipl/boot: Integrate zlib compression to single volume DASD dumper
|
||||
- zipl/boot: compile the bootloaders only if HOST_ARCH is s390x
|
||||
- zipl: Add --no-compress option to zipl command
|
||||
- zkey: Also check for deconfigured and check-stopped cards
|
||||
- dbginfo.sh: fix relative path on script copy
|
||||
|
||||
Bug Fixes:
|
||||
- ap_tools/ap-check: handle get-attributes between pre and post event
|
||||
- libutil: fix util_file_read_*() using wrong format specifiers
|
||||
- rust/pv: fix Invalid write of size 1
|
||||
|
||||
* __v2.29.0 (2023-08-04)__
|
||||
|
||||
For Linux kernel version: 6.5
|
||||
|
||||
General:
|
||||
- s390-tools now supports tools written in Rust.
|
||||
- Add `compdb` Makefile target to create 'compile_commands.json' to LSP
|
||||
backends in IDEs and editors
|
||||
|
||||
Add new tools / libraries:
|
||||
- rust/pv: Library for pv tools written in rust
|
||||
- rust/pvsecret: Tool to manage UV-secrets
|
||||
|
||||
Changes of existing tools:
|
||||
- dbginfo.sh: Global IFS variable
|
||||
- genprotimg: Add support for add-secret requests
|
||||
- genprotimg: Build debuginfo files for bootloader
|
||||
- hyptop: Add real SMT utilization field
|
||||
- hyptop: Allow users to set speedup factor
|
||||
- pvattest: Add yaml-output for verify command
|
||||
- zipl: Build debuginfo files for bootloader
|
||||
|
||||
Bug Fixes:
|
||||
- dump2tar: Fix truncated paths
|
||||
- zdev/dracut: fix kdump build to integrate with site support
|
||||
|
||||
* __v2.28.0 (2023-07-11)__
|
||||
|
||||
For Linux kernel version: 6.4
|
||||
|
||||
5
Makefile
5
Makefile
@@ -15,11 +15,12 @@ TOOL_DIRS = zipl zdump fdasd dasdfmt dasdview tunedasd \
|
||||
vmcp man mon_tools dasdinfo vmur cpuplugd ipl_tools \
|
||||
ziomon iucvterm hyptop cmsfs-fuse qethqoat zfcpdump zdsfs cpumf \
|
||||
systemd hmcdrvfs cpacfstats zdev dump2tar zkey netboot etc zpcictl \
|
||||
genprotimg lsstp hsci hsavmcore chreipl-fcp-mpath ap_tools pvattest
|
||||
genprotimg lsstp hsci hsavmcore chreipl-fcp-mpath ap_tools pvattest \
|
||||
rust
|
||||
else
|
||||
BASELIB_DIRS =
|
||||
LIB_DIRS = libpv
|
||||
TOOL_DIRS = genprotimg pvattest
|
||||
TOOL_DIRS = genprotimg pvattest rust
|
||||
endif
|
||||
|
||||
SUB_DIRS = $(BASELIB_DIRS) $(LIB_DIRS) $(TOOL_DIRS)
|
||||
|
||||
37
README.md
37
README.md
@@ -15,6 +15,11 @@ The package also contains the following files:
|
||||
Package contents
|
||||
----------------
|
||||
|
||||
* rust:
|
||||
all s390-tools that are written in rust and require external crates.
|
||||
Disable the compilation of all tools in `rust/` using HAVE_CARGO=0
|
||||
See the `rust/README.md` for Details
|
||||
|
||||
* dasdfmt:
|
||||
Low-level format ECKD DASDs with the classical Linux disk layout or the new
|
||||
z/OS compatible disk layout.
|
||||
@@ -305,13 +310,14 @@ build options:
|
||||
| net-snmp | `HAVE_SNMP` | osasnmpd |
|
||||
| glibc-static | `HAVE_LIBC_STATIC` | zfcpdump |
|
||||
| openssl | `HAVE_OPENSSL` | genprotimg, zkey, libekmfweb, |
|
||||
| | | libkmipclient, pvattest, zgetdump |
|
||||
| | | libkmipclient, pvattest, zgetdump, |
|
||||
| | | rust/pvsecret, |
|
||||
| cryptsetup | `HAVE_CRYPTSETUP2` | zkey-cryptsetup |
|
||||
| json-c | `HAVE_JSONC` | zkey-cryptsetup, libekmfweb, |
|
||||
| | | libkmipclient |
|
||||
| glib2 | `HAVE_GLIB2` | genprotimg, pvattest, zgetdump |
|
||||
| libcurl | `HAVE_LIBCURL` | genprotimg, libekmfweb, libkmipclient,|
|
||||
| | | pvattest |
|
||||
| | | pvattest, rust/pvsecret, |
|
||||
| libxml2 | `HAVE_LIBXML2` | libkmipclient |
|
||||
| systemd | `HAVE_SYSTEMD` | hsavmcore |
|
||||
| libudev | `HAVE_LIBUDEV` | cpacfstatsd |
|
||||
@@ -324,6 +330,7 @@ This table lists additional build or install options:
|
||||
| | | zipl |
|
||||
| initramfs-tools | `HAVE_INITRAMFS` | zdev, zipl |
|
||||
| | `ZDEV_ALWAYS_UPDATE_INITRD` | zdev |
|
||||
| rust | `HAVE_CARGO` | rust/* |
|
||||
|
||||
The s390-tools build process uses "pkg-config" and therefore it must be
|
||||
available.
|
||||
@@ -334,6 +341,14 @@ Build and runtime requirements for specific tools
|
||||
In the following more details on the build an runtime requirements of
|
||||
the different tools are provided:
|
||||
|
||||
* rust/pvsecret:
|
||||
For building pvsecret you need OpenSSL version 1.1.1 or newer
|
||||
installed (openssl-devel.rpm). Also required is cargo and libcurl.
|
||||
Tip: you may skip the pvsecret build by adding
|
||||
`HAVE_OPENSSL=0`, `HAVE_LIBCURL=0`, or `HAVE_CARGO=0`.
|
||||
|
||||
The runtime requirements are: openssl-libs (>= 1.1.1).
|
||||
|
||||
* dbginfo.sh:
|
||||
The tar package is required to archive collected data.
|
||||
|
||||
@@ -371,6 +386,24 @@ the different tools are provided:
|
||||
- Packages: blktrace, multipath-tools, sg3-utils
|
||||
- Tools: rsync, tar, lsscsi
|
||||
|
||||
* zipl
|
||||
For CCW-type DASD dump, zlib compression can be used to compress the dump
|
||||
data before writing it to the DASD partition. It can benefit from
|
||||
s390 on-chip compression accelerator (DFLTCC) and provide a faster dumping
|
||||
process, hence lower system downtime.
|
||||
The zlib version integrated with zipl (zipl/boot/zlib) is based on the Linux
|
||||
kernel zlib (kernel version 6.3) which represents zlib version 1.1.3 with a
|
||||
limited number of functions and a number of updates on top including s390
|
||||
hardware compression (DFLTCC) support. Also, all memory allocations are
|
||||
performed in advance, which aligns with zipl requirements.
|
||||
The CCW-type standalone dumper is built as a single binary and must be
|
||||
loaded to stage2 during boot. Hence, all required zlib functions must be
|
||||
integrated into it, and its size is restricted. To limit the size, only
|
||||
deflate-related parts are integrated (no decompression is required during
|
||||
dumping).
|
||||
Removing the inflate modules and function prototypes are the only major
|
||||
modifications made to the kernel version of zlib.
|
||||
|
||||
* zgetdump
|
||||
For building zgetdump you need OpenSSL version 1.1.0 or newer
|
||||
installed (openssl-devel.rpm). Also required is glib2
|
||||
|
||||
@@ -798,12 +798,34 @@ static int ap_check_handle_get_attributes(struct ap_check_anchor *anc)
|
||||
FILE *f;
|
||||
int rc;
|
||||
|
||||
rc = ap_get_lock_callout();
|
||||
if (rc) {
|
||||
fprintf(stderr, "Failed to acquire configuration lock %d\n", rc);
|
||||
return -1;
|
||||
/*
|
||||
* For the get-attributes callout, we are typically called without the
|
||||
* callout lock held. However, there is a particular scenario (define
|
||||
* of an active mdev) where we may or may not be called with the lock
|
||||
* already held on behalf of mdevctl, depending on the mdevctl version.
|
||||
* Let's test for lock ownership first and, if already owned by the
|
||||
* parent (mdevctl) proceed rather than waiting on the file lock.
|
||||
*/
|
||||
rc = ap_try_lock_callout();
|
||||
switch (rc) {
|
||||
case 0:
|
||||
/* Lock acquired */
|
||||
anc->cleanup_lock = true;
|
||||
break;
|
||||
case 1:
|
||||
/* Lock held by parent -- trust the lock will remain held */
|
||||
break;
|
||||
default:
|
||||
/* Lock not acquired or held by parent -- do a normal obtain */
|
||||
rc = ap_get_lock_callout();
|
||||
if (rc) {
|
||||
fprintf(stderr,
|
||||
"Failed to acquire configuration lock %d\n",
|
||||
rc);
|
||||
return -1;
|
||||
}
|
||||
anc->cleanup_lock = true;
|
||||
}
|
||||
anc->cleanup_lock = true;
|
||||
|
||||
/*
|
||||
* Read the 'matrix' and 'control_domains' attributes to get the
|
||||
|
||||
@@ -17,7 +17,6 @@
|
||||
# GNU awk:
|
||||
# - gawk
|
||||
|
||||
override SHELL := /bin/bash
|
||||
override .SHELLFLAGS := -O globstar -O nullglob -O extglob -c
|
||||
|
||||
# Include common s390-tools definitions
|
||||
|
||||
89
common.mak
89
common.mak
@@ -8,10 +8,14 @@ ASAN ?= 0
|
||||
ENABLE_WERROR ?= 0
|
||||
OPT_FLAGS ?=
|
||||
MAKECMDGOALS ?=
|
||||
CARGO ?= cargo
|
||||
CARGOFLAGS ?=
|
||||
|
||||
ifeq ($(COMMON_INCLUDED),false)
|
||||
COMMON_INCLUDED := true
|
||||
|
||||
override SHELL := /bin/bash
|
||||
|
||||
# 'BUILD_ARCH' is the architecture of the machine where the build takes place
|
||||
BUILD_ARCH := $(shell uname -m | sed -e 's/i.86/i386/' -e 's/sun4u/sparc64/' -e 's/arm.*/arm/' -e 's/sa110/arm/')
|
||||
# 'HOST_ARCH' is the architecture of the machine that will run the compiled output
|
||||
@@ -28,7 +32,7 @@ endif
|
||||
# The variable "DISTRELEASE" should be overwritten in rpm spec files with:
|
||||
# "make DISTRELEASE=%{release}" and "make install DISTRELEASE=%{release}"
|
||||
VERSION = 2
|
||||
RELEASE = 28
|
||||
RELEASE = 32
|
||||
PATCHLEVEL = 0
|
||||
DISTRELEASE = build-$(shell date +%Y%m%d)
|
||||
S390_TOOLS_RELEASE = $(VERSION).$(RELEASE).$(PATCHLEVEL)-$(DISTRELEASE)
|
||||
@@ -89,19 +93,19 @@ define cmd_define_and_export
|
||||
endef
|
||||
|
||||
define define_toolchain_variables
|
||||
$(eval $(call cmd_define_and_export, AS$(1)," AS$(1) ",$(2)as))
|
||||
$(eval $(call cmd_define_and_export, CC$(1)," CC$(1) ",$(2)gcc))
|
||||
$(eval $(call cmd_define_and_export, LINK$(1)," LINK$(1) ",$$(CC$(1))))
|
||||
$(eval $(call cmd_define_and_export, CXX$(1)," CXX$(1) ",$(2)g++))
|
||||
$(eval $(call cmd_define_and_export, LINKXX$(1)," LINKXX$(1) ",$$(CXX$(1))))
|
||||
$(eval $(call cmd_define_and_export, CPP$(1)," CPP$(1) ",$(2)gcc -E))
|
||||
$(eval $(call cmd_define_and_export, AR$(1)," AR$(1) ",$(2)ar))
|
||||
$(eval $(call cmd_define_and_export, NM$(1)," NM$(1) ",$(2)nm))
|
||||
$(eval $(call cmd_define_and_export, STRIP$(1)," STRIP$(1) ",$(2)strip))
|
||||
$(eval $(call cmd_define_and_export,OBJCOPY$(1)," OBJCOPY$(1) ",$(2)objcopy))
|
||||
$(eval $(call cmd_define_and_export,OBJDUMP$(1)," OBJDUMP$(1) ",$(2)objdump))
|
||||
$(eval PKG_CONFIG$(1) = pkg-config)
|
||||
$(eval export PKG_CONFIG$(1))
|
||||
$(call cmd_define_and_export, AS$(1)," AS$(1) ",$(2)as)
|
||||
$(call cmd_define_and_export, CC$(1)," CC$(1) ",$(2)gcc)
|
||||
$(call cmd_define_and_export, LINK$(1)," LINK$(1) ",$$(CC$(1)))
|
||||
$(call cmd_define_and_export, CXX$(1)," CXX$(1) ",$(2)g++)
|
||||
$(call cmd_define_and_export, LINKXX$(1)," LINKXX$(1) ",$$(CXX$(1)))
|
||||
$(call cmd_define_and_export, CPP$(1)," CPP$(1) ",$(2)gcc -E)
|
||||
$(call cmd_define_and_export, AR$(1)," AR$(1) ",$(2)ar)
|
||||
$(call cmd_define_and_export, NM$(1)," NM$(1) ",$(2)nm)
|
||||
$(call cmd_define_and_export, STRIP$(1)," STRIP$(1) ",$(2)strip)
|
||||
$(call cmd_define_and_export,OBJCOPY$(1)," OBJCOPY$(1) ",$(2)objcopy)
|
||||
$(call cmd_define_and_export,OBJDUMP$(1)," OBJDUMP$(1) ",$(2)objdump)
|
||||
PKG_CONFIG$(1) = pkg-config
|
||||
export PKG_CONFIG$(1)
|
||||
endef
|
||||
|
||||
# If the host architecture is not the same as the build architecture
|
||||
@@ -115,15 +119,19 @@ ifneq ($(HOST_ARCH),$(BUILD_ARCH))
|
||||
endif
|
||||
endif
|
||||
|
||||
$(call define_toolchain_variables,_FOR_BUILD,)
|
||||
$(call define_toolchain_variables,,$(CROSS_COMPILE))
|
||||
$(eval $(call define_toolchain_variables,_FOR_BUILD,))
|
||||
$(eval $(call define_toolchain_variables,,$(CROSS_COMPILE)))
|
||||
|
||||
$(eval $(call cmd_define,RUNTEST," RUNTEST ",$(S390_TEST_LIB_PATH)/s390_runtest))
|
||||
$(eval $(call cmd_define, CAT," CAT ",cat))
|
||||
$(eval $(call cmd_define, SED," SED ",sed))
|
||||
$(eval $(call cmd_define, GZIP," GZIP ",gzip))
|
||||
$(eval $(call cmd_define, MV," MV ",mv))
|
||||
$(eval $(call cmd_define, PERLC," PERLC ",perl -c))
|
||||
|
||||
$(eval $(call cmd_define, RUNTEST," RUNTEST ",$(S390_TEST_LIB_PATH)/s390_runtest))
|
||||
$(eval $(call cmd_define, CAT," CAT ",cat))
|
||||
$(eval $(call cmd_define, SED," SED ",sed))
|
||||
$(eval $(call cmd_define, GZIP," GZIP ",gzip))
|
||||
$(eval $(call cmd_define, MV," MV ",mv))
|
||||
$(eval $(call cmd_define, PERLC," PERLC ",perl -c))
|
||||
$(eval $(call cmd_define,CARGO_BUILD," CARGO BUILD ",$(CARGO) build))
|
||||
$(eval $(call cmd_define,CARGO_TEST, " CARGO TEST ",$(CARGO) test))
|
||||
$(eval $(call cmd_define,CARGO_CLEAN," CARGO CLEAN ",$(CARGO) clean))
|
||||
|
||||
CHECK = sparse
|
||||
CHECK_SILENT := $(CHECK)
|
||||
@@ -133,8 +141,10 @@ SKIP = echo " SKIP $(call reldir) due to"
|
||||
|
||||
INSTALL = install
|
||||
CP = cp
|
||||
ALL_CARGOFLAGS := $(CARGOFLAGS)
|
||||
ifneq ("${V}","1")
|
||||
MAKEFLAGS += --quiet
|
||||
ALL_CARGOFLAGS += --quiet
|
||||
echocmd=echo $1$(call reldir)$2;
|
||||
RUNTEST += > /dev/null 2>&1
|
||||
else
|
||||
@@ -294,7 +304,7 @@ ZFCPDUMP_FLAVOR = zfcpdump
|
||||
export ZFCPDUMP_DIR ZFCPDUMP_IMAGE ZFCPDUMP_INITRD ZFCPDUMP_FLAVOR
|
||||
|
||||
CFLAGS ?= $(DEFAULT_CFLAGS) $(OPT_FLAGS)
|
||||
CFLAGS_FOR_BUILD ?= $(DEFAULT_CFLAGS) $(OPT_FLAGS)
|
||||
CFLAGS_FOR_BUILD ?= -std=gnu11 $(DEFAULT_CFLAGS) $(OPT_FLAGS)
|
||||
CPPFLAGS ?= $(DEFAULT_CPPFLAGS)
|
||||
LDFLAGS ?= $(DEFAULT_LDFLAGS)
|
||||
|
||||
@@ -303,14 +313,14 @@ ALL_CFLAGS = -DS390_TOOLS_RELEASE=$(S390_TOOLS_RELEASE) \
|
||||
-DS390_TOOLS_DATADIR=$(TOOLS_DATADIR) \
|
||||
-DS390_TOOLS_SYSCONFDIR=$(SYSCONFDIR) \
|
||||
-DS390_TOOLS_BINDIR=$(BINDIR) \
|
||||
$(CFLAGS)
|
||||
-std=gnu11 $(CFLAGS)
|
||||
CXXFLAGS ?= $(DEFAULT_CFLAGS) $(OPT_FLAGS)
|
||||
ALL_CXXFLAGS = -DS390_TOOLS_RELEASE=$(S390_TOOLS_RELEASE) \
|
||||
-DS390_TOOLS_LIBDIR=$(TOOLS_LIBDIR) \
|
||||
-DS390_TOOLS_DATADIR=$(TOOLS_DATADIR) \
|
||||
-DS390_TOOLS_SYSCONFDIR=$(SYSCONFDIR) \
|
||||
-DS390_TOOLS_BINDIR=$(BINDIR) \
|
||||
$(CXXFLAGS)
|
||||
-std=gnu++11 $(CXXFLAGS)
|
||||
ALL_CPPFLAGS = -I $(rootdir)include $(CPPFLAGS)
|
||||
ALL_LDFLAGS = $(LDFLAGS)
|
||||
|
||||
@@ -360,6 +370,7 @@ help:
|
||||
@echo ' all Build all tools (default target)'
|
||||
@echo ' install Install tools'
|
||||
@echo ' clean Delete all generated files'
|
||||
@echo ' compdb Generate compile_commands.json for clangd'
|
||||
@echo ''
|
||||
@echo 'OPTIONS'
|
||||
@echo ' D=1 Build with debugging option "-Og"'
|
||||
@@ -375,6 +386,32 @@ help:
|
||||
@echo ' # make C=1 CHECK=smatch'
|
||||
.PHONY: help
|
||||
|
||||
|
||||
# 'compile_commands.json' generation
|
||||
#
|
||||
# Create the compilation database 'compile_commands.json'. See
|
||||
# https://clang.llvm.org/docs/JSONCompilationDatabase.html for details.
|
||||
#
|
||||
.PHONY: compdb
|
||||
compdb:
|
||||
$(MAKE) clean
|
||||
ifneq ($(shell command -v compiledb),)
|
||||
compiledb $(MAKE)
|
||||
else ifneq ($(shell command -v bear),)
|
||||
ifeq ($(shell bear --help|grep -- '-- ...'),)
|
||||
bear $(MAKE)
|
||||
else
|
||||
bear -- $(MAKE)
|
||||
endif
|
||||
else
|
||||
$(error Please install either 'compiledb' or 'bear')
|
||||
endif
|
||||
|
||||
# Prints the s390-tools release string
|
||||
version:
|
||||
$(info $(S390_TOOLS_RELEASE))
|
||||
.PHONY: version
|
||||
|
||||
# Automatic dependency generation
|
||||
#
|
||||
# Create ".o.d" dependency files with the -MM compile option for all ".c" and
|
||||
@@ -485,7 +522,7 @@ install_echo:
|
||||
install: install_echo install_dirs
|
||||
|
||||
clean_echo:
|
||||
$(call echocmd," CLEAN ")
|
||||
$(call echocmd," CLEAN ")
|
||||
clean_gcov:
|
||||
rm -f -- *.gcda *.gcno *.gcov
|
||||
clean_dep:
|
||||
|
||||
@@ -355,13 +355,13 @@ PCKMO DES,
|
||||
.IP \(bu
|
||||
PCKMO 2key TDES,
|
||||
.IP \(bu
|
||||
PCMKO TDES,
|
||||
PCKMO TDES,
|
||||
.IP \(bu
|
||||
PCKMO AES 128bit,
|
||||
.IP \(bu
|
||||
PCKMO AES 192bit,
|
||||
.IP \(bu
|
||||
PCMKO AES 256bit,
|
||||
PCKMO AES 256bit,
|
||||
.IP \(bu
|
||||
PCKMO ECC P256,
|
||||
.IP \(bu
|
||||
|
||||
@@ -204,10 +204,10 @@ static const char *const pai_str[] = {
|
||||
[142] = "KDSA EdDSA Sign Ed448 protected key",
|
||||
[143] = "PCKMO DES",
|
||||
[144] = "PCKMO 2key TDES",
|
||||
[145] = "PCMKO TDES",
|
||||
[145] = "PCKMO TDES",
|
||||
[146] = "PCKMO AES 128bit",
|
||||
[147] = "PCKMO AES 192bit",
|
||||
[148] = "PCMKO AES 256bit",
|
||||
[148] = "PCKMO AES 256bit",
|
||||
[149] = "PCKMO ECC P256",
|
||||
[150] = "PCKMO ECC P384",
|
||||
[151] = "PCKMO ECC P521",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
include ../common.mak
|
||||
|
||||
BIN_FILES = lscpumf chcpumf lshwc pai
|
||||
MAN_FILES = lscpumf.8 chcpumf.8 lshwc.8 pai.8
|
||||
BIN_FILES = lscpumf chcpumf lshwc pai lspai
|
||||
MAN_FILES = lscpumf.8 chcpumf.8 lshwc.8 pai.8 lspai.8
|
||||
|
||||
all: $(BIN_FILES)
|
||||
|
||||
@@ -11,6 +11,7 @@ lscpumf: lscpumf.o $(libs)
|
||||
chcpumf: chcpumf.o $(libs)
|
||||
lshwc: lshwc.o $(libs)
|
||||
pai: pai.o $(libs)
|
||||
lspai: lspai.o $(libs)
|
||||
|
||||
install: all install-man
|
||||
$(INSTALL) -d -m 755 $(DESTDIR)$(BINDIR) $(DESTDIR)$(MANDIR)/man8
|
||||
|
||||
@@ -3473,6 +3473,7 @@ static struct counters *get_counter(int ctrset, size_t *len)
|
||||
read_ccerror(cp, *len);
|
||||
break;
|
||||
case UTIL_ARCH_MACHINE_TYPE_Z16:
|
||||
case UTIL_ARCH_MACHINE_TYPE_Z16_A02:
|
||||
cp = cpumcf_z16_counters;
|
||||
*len = ARRAY_SIZE(cpumcf_z16_counters);
|
||||
}
|
||||
|
||||
352
cpumf/lspai.c
Normal file
352
cpumf/lspai.c
Normal file
@@ -0,0 +1,352 @@
|
||||
/* Copyright IBM Corp. 2023
|
||||
*
|
||||
* s390-tools is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the MIT license. See LICENSE for details.
|
||||
*/
|
||||
|
||||
/* List available Processor Assist Instrumentation (PAI) counters. */
|
||||
|
||||
#include <ctype.h>
|
||||
#include <dirent.h>
|
||||
#include <err.h>
|
||||
#include <errno.h>
|
||||
#include <limits.h>
|
||||
#include <stdarg.h>
|
||||
#include <stdbool.h>
|
||||
#include <stdint.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
#include <unistd.h>
|
||||
|
||||
#include "lib/util_opt.h"
|
||||
#include "lib/util_prg.h"
|
||||
#include "lib/util_base.h"
|
||||
#include "lib/util_path.h"
|
||||
#include "lib/util_scandir.h"
|
||||
#include "lib/util_libc.h"
|
||||
#include "lib/util_file.h"
|
||||
#include "lib/util_list.h"
|
||||
#include "lib/libcpumf.h"
|
||||
|
||||
static struct util_opt opt_vec[] = {
|
||||
UTIL_OPT_SECTION("OPTIONS"),
|
||||
{
|
||||
.option = { "numeric", no_argument, NULL, 'n' },
|
||||
.desc = "Sort PAI counters by counter number"
|
||||
},
|
||||
{
|
||||
.option = { "type", required_argument, NULL, 't' },
|
||||
.argument = "TYPE",
|
||||
.desc = "Type of PAI counters to show: crypto, nnpa"
|
||||
},
|
||||
UTIL_OPT_HELP,
|
||||
UTIL_OPT_VERSION,
|
||||
UTIL_OPT_END
|
||||
};
|
||||
|
||||
static const struct util_prg prg = {
|
||||
.desc = "List Processor Assist Information counter sets",
|
||||
.copyright_vec = {
|
||||
{
|
||||
.owner = "IBM Corp.",
|
||||
.pub_first = 2023,
|
||||
.pub_last = 2023,
|
||||
},
|
||||
UTIL_PRG_COPYRIGHT_END
|
||||
}
|
||||
};
|
||||
|
||||
static bool numsort; /* If true sort counter numerically */
|
||||
|
||||
#define PAI_PATH "/bus/event_source/devices/%s"
|
||||
|
||||
enum pai_types { /* Bit mask for supported PAI counters */
|
||||
pai_type_crypto = 0, /* PAI Crypto Counters */
|
||||
pai_type_nnpa = 1, /* PAI NNPA Counters */
|
||||
pai_type_max = 2, /* PAI maximum value, must be last */
|
||||
};
|
||||
|
||||
static int pai_types_show;
|
||||
|
||||
struct pai_ctrname { /* List of defined counters */
|
||||
char *name; /* Counter name */
|
||||
unsigned long nr; /* Counter number */
|
||||
};
|
||||
|
||||
struct pai_node { /* Head for PAI counter sets */
|
||||
struct util_list_node node; /* Successor in PAI counter set list */
|
||||
enum pai_types type; /* PAI type */
|
||||
int pmu; /* Assigned PMU type number */
|
||||
const char *name; /* Counter set name */
|
||||
char *name_uc; /* Counter set name upper case */
|
||||
const char *sysfs_name; /* Counter set name in /sysfs tree */
|
||||
const char *filter_name; /* Counter set name for scandir filter */
|
||||
struct pai_ctrname *ctrlist; /* List of counter names & numbers */
|
||||
size_t ctrsize; /* Total size in bytes of ctrlist */
|
||||
int ctridx; /* Index of last entry used in ctrlist */
|
||||
unsigned long base; /* Base number for counter set */
|
||||
};
|
||||
|
||||
static struct util_list pai_list;
|
||||
|
||||
/* Return base of counter set, this is the first counter of this set. */
|
||||
static unsigned long pai_type_base(enum pai_types t)
|
||||
{
|
||||
switch (t) {
|
||||
case pai_type_crypto:
|
||||
return 0x1000;
|
||||
case pai_type_nnpa:
|
||||
return 0x1800;
|
||||
case pai_type_max:
|
||||
break;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* Test PAI counter name from command line option. */
|
||||
static const char *pai_type_name(enum pai_types t)
|
||||
{
|
||||
switch (t) {
|
||||
case pai_type_crypto:
|
||||
return "crypto";
|
||||
case pai_type_nnpa:
|
||||
return "nnpa";
|
||||
case pai_type_max:
|
||||
break;
|
||||
}
|
||||
return "unknown";
|
||||
}
|
||||
|
||||
/* Convert PAI counter type to sysfs directory name. Only validated
|
||||
* input at this time.
|
||||
*/
|
||||
static const char *pai_type_sysfs(enum pai_types t)
|
||||
{
|
||||
if (t == pai_type_crypto)
|
||||
return "pai_crypto";
|
||||
return "pai_ext";
|
||||
}
|
||||
|
||||
/* Convert PAI counter type to sysfs directory name filter for scandir(). */
|
||||
static const char *pai_type_filter(enum pai_types t)
|
||||
{
|
||||
if (t == pai_type_nnpa)
|
||||
return "^NNPA";
|
||||
return "[^.]"; /* Matches anything but . and .. in sysfs */
|
||||
}
|
||||
|
||||
/* Sort PAI counter names by assigned counter number. */
|
||||
static int pai_ctrcmp(const void *p1, const void *p2)
|
||||
{
|
||||
struct pai_ctrname *l = (struct pai_ctrname *)p1;
|
||||
struct pai_ctrname *r = (struct pai_ctrname *)p2;
|
||||
|
||||
return l->nr > r->nr ? 1 : -1;
|
||||
}
|
||||
|
||||
/* Convert string to upper case. */
|
||||
static char *str2uc(const char *s)
|
||||
{
|
||||
char *uc = util_strdup(s), *old_uc = uc;
|
||||
|
||||
for (; *uc; ++uc)
|
||||
*uc = toupper(*uc);
|
||||
return old_uc;
|
||||
}
|
||||
|
||||
/* Read counter names and assigned event number from sysfs file tree.
|
||||
* Exit when sysfs directory can not be scanned.
|
||||
*/
|
||||
static void read_counternames(struct pai_node *node)
|
||||
{
|
||||
int i, more = 0, ctr = 0, count = 0;
|
||||
struct dirent **namelist = NULL;
|
||||
char *path, *ctrpath;
|
||||
|
||||
/* Read counter names and assigned event number. */
|
||||
path = util_path_sysfs(PAI_PATH "/events", node->sysfs_name);
|
||||
count = util_scandir(&namelist, alphasort, path, node->filter_name);
|
||||
if (count <= 0)
|
||||
errx(EXIT_FAILURE, "Cannot open %s", path);
|
||||
|
||||
node->ctrsize = count * sizeof(*node->ctrlist);
|
||||
node->ctrlist = util_malloc(node->ctrsize);
|
||||
for (i = 0; i < count && ctr >= 0; i++) {
|
||||
util_asprintf(&ctrpath, "%s/%s", path, namelist[i]->d_name);
|
||||
if (util_file_read_va(ctrpath, "event=%x", &ctr) == 1) {
|
||||
node->ctrlist[node->ctridx].name = util_strdup(namelist[i]->d_name);
|
||||
node->ctrlist[node->ctridx++].nr = ctr;
|
||||
more++;
|
||||
} else {
|
||||
warnx("Cannot parse %s", ctrpath);
|
||||
}
|
||||
free(ctrpath);
|
||||
}
|
||||
util_scandir_free(namelist, count);
|
||||
free(path);
|
||||
|
||||
if (numsort && more > 1)
|
||||
qsort(node->ctrlist, more, sizeof(*node->ctrlist), pai_ctrcmp);
|
||||
}
|
||||
|
||||
static void show_painode(void)
|
||||
{
|
||||
struct pai_node *node;
|
||||
int indent = 0;
|
||||
int offset = 0;
|
||||
|
||||
util_list_iterate(&pai_list, node) {
|
||||
for (int i = 0; i < node->ctridx; ++i)
|
||||
indent = MAX((size_t)indent, strlen(node->ctrlist[i].name));
|
||||
}
|
||||
|
||||
printf("RAW %*s NAME %*s DESCRIPTION\n", 3, "", indent - 5, "");
|
||||
util_list_iterate(&pai_list, node) {
|
||||
for (int i = 0; i < node->ctridx; ++i) {
|
||||
printf("%d:%ld %s", node->pmu,
|
||||
node->ctrlist[i].nr, node->ctrlist[i].name);
|
||||
|
||||
offset = indent - strlen(node->ctrlist[i].name) + 1;
|
||||
printf("%*s", offset, "");
|
||||
|
||||
printf("Counter %ld / PAI %s counter set\n",
|
||||
node->ctrlist[i].nr - node->base, node->name_uc);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/* Release all memory allocated at make_painode(). */
|
||||
static void free_painode(void)
|
||||
{
|
||||
struct pai_node *next, *node;
|
||||
|
||||
util_list_iterate_safe(&pai_list, node, next) {
|
||||
free(node->name_uc);
|
||||
for (int i = 0; i < node->ctridx; ++i)
|
||||
free(node->ctrlist[i].name);
|
||||
free(node->ctrlist);
|
||||
free(node);
|
||||
}
|
||||
}
|
||||
|
||||
static void make_painode(enum pai_types t)
|
||||
{
|
||||
struct pai_node *node = util_zalloc(sizeof(*node));
|
||||
char *path;
|
||||
|
||||
node->type = t;
|
||||
node->sysfs_name = pai_type_sysfs(t);
|
||||
node->name = pai_type_name(t);
|
||||
node->name_uc = str2uc(node->name);
|
||||
node->filter_name = pai_type_filter(t);
|
||||
node->base = pai_type_base(t);
|
||||
|
||||
/* Read PMU type number. */
|
||||
path = util_path_sysfs(PAI_PATH, node->sysfs_name);
|
||||
node->pmu = libcpumf_pmutype(path);
|
||||
if (node->pmu < 0)
|
||||
errx(EXIT_FAILURE, "Cannot open %s", path);
|
||||
free(path);
|
||||
|
||||
read_counternames(node);
|
||||
|
||||
util_list_add_tail(&pai_list, node);
|
||||
}
|
||||
|
||||
static int painode_cmp(void *a, void *b, void *UNUSED(data))
|
||||
{
|
||||
struct pai_node *n1 = (struct pai_node *)a;
|
||||
struct pai_node *n2 = (struct pai_node *)b;
|
||||
|
||||
return n1->pmu < n2->pmu ? -1 : 1;
|
||||
}
|
||||
|
||||
static void sort_painode(void)
|
||||
{
|
||||
util_list_sort(&pai_list, painode_cmp, NULL);
|
||||
}
|
||||
|
||||
/* Check for hardware support and return false if not available. */
|
||||
static bool have_support(enum pai_types t)
|
||||
{
|
||||
const char *sysfn = pai_type_sysfs(t);
|
||||
char *path = util_path_sysfs(PAI_PATH, sysfn);
|
||||
bool rc = true;
|
||||
|
||||
if (!util_path_is_dir(path)) {
|
||||
warnx("No support for PAI %s facility", pai_type_name(t));
|
||||
rc = false;
|
||||
}
|
||||
free(path);
|
||||
return rc;
|
||||
}
|
||||
|
||||
/*
|
||||
* Check the argument for option -t. It must be a valid PAI counter set.
|
||||
* Exit when an invalid PAI counter set name has been specified.
|
||||
*/
|
||||
static void check_type_name(const char *type)
|
||||
{
|
||||
bool no_match = true;
|
||||
enum pai_types i;
|
||||
const char *fn;
|
||||
|
||||
for (i = pai_type_crypto; i < pai_type_max; ++i) {
|
||||
fn = pai_type_name(i);
|
||||
if (!strcasecmp(fn, type)) {
|
||||
pai_types_show |= (1 << i);
|
||||
no_match = false;
|
||||
}
|
||||
}
|
||||
if (no_match)
|
||||
errx(EXIT_FAILURE, "Invalid argument for -t %s", type);
|
||||
}
|
||||
|
||||
int main(int argc, char **argv)
|
||||
{
|
||||
int ch;
|
||||
|
||||
util_list_init(&pai_list, struct pai_node, node);
|
||||
util_prg_init(&prg);
|
||||
util_opt_init(opt_vec, NULL);
|
||||
|
||||
while ((ch = util_opt_getopt_long(argc, argv)) != -1) {
|
||||
switch (ch) {
|
||||
default:
|
||||
util_opt_print_parse_error(ch, argv);
|
||||
return EXIT_FAILURE;
|
||||
case 'h':
|
||||
util_prg_print_help();
|
||||
util_opt_print_help();
|
||||
return EXIT_SUCCESS;
|
||||
case 'v':
|
||||
util_prg_print_version();
|
||||
return EXIT_SUCCESS;
|
||||
case 'n':
|
||||
numsort = true;
|
||||
break;
|
||||
case 't':
|
||||
check_type_name(optarg);
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
/* Nothing specified, show all PAI counters */
|
||||
if (!pai_types_show)
|
||||
pai_types_show = (1 << pai_type_crypto) | (1 << pai_type_nnpa);
|
||||
|
||||
/* Check for hardware support */
|
||||
for (enum pai_types i = pai_type_crypto; i < pai_type_max; ++i) {
|
||||
if ((pai_types_show & (1 << i))) {
|
||||
if (!have_support(i))
|
||||
pai_types_show &= ~(1 << i);
|
||||
else
|
||||
make_painode(i);
|
||||
}
|
||||
}
|
||||
sort_painode();
|
||||
show_painode();
|
||||
free_painode();
|
||||
return ch;
|
||||
}
|
||||
80
cpumf/man/lspai.8
Normal file
80
cpumf/man/lspai.8
Normal file
@@ -0,0 +1,80 @@
|
||||
.\" lspai.8
|
||||
.\"
|
||||
.\"
|
||||
.\" Copyright IBM Corp. 2021
|
||||
.\" s390-tools is free software; you can redistribute it and/or modify
|
||||
.\" it under the terms of the MIT license. See LICENSE for details.
|
||||
.\" ----------------------------------------------------------------------
|
||||
.ds c \fBlspai\fP
|
||||
.
|
||||
.TH \*c "8" "August 2023" "s390-tools" "CPU-MF management programs"
|
||||
.
|
||||
.SH NAME
|
||||
\*c \- list Processor Activity Instrumentation (PAI) counters
|
||||
.
|
||||
.SH SYNOPSIS
|
||||
\*c
|
||||
.RB [ \-n ]
|
||||
.RB [ \-t
|
||||
.IR "\ TYPE" ]
|
||||
.br
|
||||
\*c
|
||||
.BR \-h | \-\-help
|
||||
.br
|
||||
\*c
|
||||
.BR \-v | \-\-version
|
||||
.
|
||||
.
|
||||
.SH DESCRIPTION
|
||||
\*c displays the Processor Activity Instrumentation (PAI) counters
|
||||
for Linux on IBM Z.
|
||||
The output is a human-readable list of available PAI counter
|
||||
names and numbers.
|
||||
.SH OPTIONS
|
||||
.TP
|
||||
.BR \-h ", " \-\-help
|
||||
Displays help information, then exits.
|
||||
.
|
||||
.TP
|
||||
.BR \-v ", " \-\-version
|
||||
Displays version information, then exits.
|
||||
.
|
||||
.TP
|
||||
.BR \-t ", " \-\-type "\ TYPE"
|
||||
Specifies the PAI counter set to list.
|
||||
Valid counter set values are
|
||||
.I crypto
|
||||
and
|
||||
.IR nnpa .
|
||||
By default, the command lists all available PAI counter sets.
|
||||
NNPA refers to the Neural Network Processing Assist facility counter set.
|
||||
Crypto refers to the Cryptografic Processing Assist facility counter set.
|
||||
.
|
||||
.TP
|
||||
.BR \-n ", " \-\-numeric
|
||||
Shows the PAI counter sets sorted by counter number.
|
||||
Default sort order is PAI counter name.
|
||||
.
|
||||
.SH "EXAMPLE"
|
||||
The \*c invocation lists all PAI Neural Network Processing Assist Facility
|
||||
(NNPA) counters in numeric order:
|
||||
.nf
|
||||
# lspai -t nnpa -n
|
||||
RAW NAME DESCRIPTION
|
||||
13:6144 NNPA_ALL Counter 0 / PAI NNPA counter set
|
||||
13:6145 NNPA_ADD Counter 1 / PAI NNPA counter set
|
||||
13:6146 NNPA_SUB Counter 2 / PAI NNPA counter set
|
||||
13:6147 NNPA_MUL Counter 3 / PAI NNPA counter set
|
||||
\&...
|
||||
.fi
|
||||
The first column shows the raw event number suitable for
|
||||
.IR perf "(8)"
|
||||
raw event specification.
|
||||
The second column shows the PAI NNPA counter name,
|
||||
suitable for
|
||||
.IR perf "(8)"
|
||||
event specification by name.
|
||||
The third gives a short explanation, if available.
|
||||
.SH "SEE ALSO"
|
||||
.BR pai (8)
|
||||
.BR lscpumf (8)
|
||||
@@ -18,6 +18,8 @@
|
||||
.IR size ]
|
||||
.RB [ \-i | \-\-interval
|
||||
.IR ms ]
|
||||
.RB [ \-R | \-\-realtime
|
||||
.IR prio ]
|
||||
.BR \-c | \-\-crypto [ \fIcpulist ][: \fIdata\fR "] [" \fIloops\fP ]
|
||||
.br
|
||||
\*c
|
||||
@@ -25,6 +27,8 @@
|
||||
.IR size ]
|
||||
.RB [ \-i | \-\-interval
|
||||
.IR ms ]
|
||||
.RB [ \-R | \-\-realtime
|
||||
.IR prio ]
|
||||
.BR \-n | \-\-nnpa [ \fIcpulist ][: \fIdata\fR "] [" \fIloops\fP ]
|
||||
.br
|
||||
\*c
|
||||
@@ -191,6 +195,14 @@ The ring buffer is created with the
|
||||
.IR mmap (2)
|
||||
system call.
|
||||
.
|
||||
.TP
|
||||
.BR \-R ", " \-\-realtime "\ prio"
|
||||
Collect data using the RT SCHED_FIFO priority specified by
|
||||
.BR prio .
|
||||
Valid values are integers in the range 1 (low) to 99 (high).
|
||||
Use this option when gathering data from multiple CPUs
|
||||
to prevent data loss.
|
||||
.
|
||||
.SH ARGUMENT
|
||||
The command line options determine how command line
|
||||
arguments are interpreted.
|
||||
|
||||
39
cpumf/pai.c
39
cpumf/pai.c
@@ -320,7 +320,7 @@ static void readmap(int fd)
|
||||
* ring buffer per event, sleep some short time and always read all
|
||||
* ring buffer for new contents.
|
||||
*/
|
||||
static void collect(unsigned long cnt)
|
||||
static int collect(unsigned long cnt)
|
||||
{
|
||||
fd_set r_fds, e_fds, a_fds;
|
||||
struct pai_event *p;
|
||||
@@ -328,6 +328,7 @@ static void collect(unsigned long cnt)
|
||||
int rc, max_fd;
|
||||
|
||||
do {
|
||||
rc = -1;
|
||||
max_fd = -1;
|
||||
tv.tv_sec = read_interval / 1000;
|
||||
tv.tv_usec = (1000 * read_interval) % 1000000;
|
||||
@@ -357,6 +358,7 @@ static void collect(unsigned long cnt)
|
||||
}
|
||||
}
|
||||
} while (rc != -1 && --cnt > 0);
|
||||
return rc;
|
||||
}
|
||||
|
||||
static void lookup_event(__u64 evtnum, __u16 ctr, __u64 value)
|
||||
@@ -449,6 +451,11 @@ static void evt_show(__u64 evtnum, const char *evtsel, struct pai_event_out *ev)
|
||||
ev->u.s_comm.tid);
|
||||
break;
|
||||
|
||||
case PERF_RECORD_SWITCH:
|
||||
printf("cs-%s",
|
||||
(ev->misc & PERF_RECORD_MISC_SWITCH_OUT) ? "out" : "in");
|
||||
break;
|
||||
|
||||
case PERF_RECORD_SWITCH_CPU_WIDE:
|
||||
if (ev->misc & PERF_RECORD_MISC_SWITCH_OUT) {
|
||||
short p = PERF_RECORD_MISC_SWITCH_OUT_PREEMPT;
|
||||
@@ -549,6 +556,9 @@ static int evt_scan(char *fn, unsigned char *buf, size_t len,
|
||||
offset -= sizeof(__u64);
|
||||
break;
|
||||
|
||||
case PERF_RECORD_SWITCH:
|
||||
break;
|
||||
|
||||
case PERF_RECORD_SWITCH_CPU_WIDE:
|
||||
memcpy(&ev.u, buf + offset, sizeof(ev.u.s_cs));
|
||||
offset += sizeof(ev.u.s_cs);
|
||||
@@ -583,7 +593,7 @@ static int evt_scan(char *fn, unsigned char *buf, size_t len,
|
||||
break;
|
||||
|
||||
default:
|
||||
printf("unknown header-type %d ", hdr->type);
|
||||
printf("unknown header-type %d\n", hdr->type);
|
||||
offset += hdr->size - sizeof(*hdr);
|
||||
goto bypass;
|
||||
}
|
||||
@@ -944,6 +954,11 @@ static struct util_opt opt_vec[] = {
|
||||
.option = { "report", no_argument, NULL, 'r' },
|
||||
.desc = "Report file contents"
|
||||
},
|
||||
{
|
||||
.option = { "realtime", required_argument, NULL, 'R' },
|
||||
.argument = "PRIO",
|
||||
.desc = "Collect data with this RT SCHED_FIFO priority"
|
||||
},
|
||||
{
|
||||
.option = { "interval", required_argument, NULL, 'i' },
|
||||
.argument = "NUMBER",
|
||||
@@ -1007,6 +1022,19 @@ static unsigned long check_mapsize(unsigned long n)
|
||||
return cnt == 1 ? n : 0;
|
||||
}
|
||||
|
||||
static void setprio(const char *prio)
|
||||
{
|
||||
struct sched_param param;
|
||||
char *endstr;
|
||||
|
||||
memset(¶m, 0, sizeof(param));
|
||||
param.sched_priority = strtoul(prio, &endstr, 0);
|
||||
if (*endstr)
|
||||
errno = EINVAL;
|
||||
if (*endstr || sched_setscheduler(0, SCHED_FIFO, ¶m))
|
||||
err(EXIT_FAILURE, "Could not set realtime priority");
|
||||
}
|
||||
|
||||
int main(int argc, char **argv)
|
||||
{
|
||||
bool crypto_record = false, report = false;
|
||||
@@ -1061,6 +1089,9 @@ int main(int argc, char **argv)
|
||||
record_cpus_nnpa(optarg);
|
||||
nnpa_record = true;
|
||||
break;
|
||||
case 'R':
|
||||
setprio(optarg);
|
||||
break;
|
||||
case 'r':
|
||||
report = true;
|
||||
break;
|
||||
@@ -1094,12 +1125,12 @@ int main(int argc, char **argv)
|
||||
ev_install(group);
|
||||
ev_enable();
|
||||
|
||||
collect(loop_count);
|
||||
ch = collect(loop_count);
|
||||
|
||||
ev_disable();
|
||||
ev_deinstall();
|
||||
ev_dealloc();
|
||||
return EXIT_SUCCESS;
|
||||
return ch < 0 ? EXIT_FAILURE : EXIT_SUCCESS;
|
||||
}
|
||||
|
||||
/* Must be reporting */
|
||||
|
||||
@@ -25,7 +25,7 @@ int get_numcpus()
|
||||
|
||||
for (i = 0; ; i++) {
|
||||
/* check whether file exists and is readable */
|
||||
sprintf(path, "/sys/devices/system/cpu/cpu%d/online", i);
|
||||
sprintf(path, "/sys/devices/system/cpu/cpu%d", i);
|
||||
if (access(path, R_OK) == 0)
|
||||
number++;
|
||||
else
|
||||
@@ -45,11 +45,13 @@ int get_num_online_cpus()
|
||||
int status = 0;
|
||||
int value_of_onlinefile, rc;
|
||||
|
||||
for (i = 0; i <= get_numcpus(); i++) {
|
||||
for (i = 0; i < get_numcpus(); i++) {
|
||||
/* check wether file exists and is readable */
|
||||
sprintf(path, "/sys/devices/system/cpu/cpu%d/online", i);
|
||||
if (access(path, R_OK) != 0)
|
||||
if (access(path, R_OK) != 0) {
|
||||
status++;
|
||||
continue;
|
||||
}
|
||||
filp = fopen(path, "r");
|
||||
if (!filp)
|
||||
cpuplugd_exit("Cannot open cpu online file: "
|
||||
@@ -101,10 +103,8 @@ int hotplug(int cpuid)
|
||||
cpuid);
|
||||
return -1;
|
||||
}
|
||||
} else {
|
||||
cpuplugd_error("hotplugging cpu with id %d failed\n", cpuid);
|
||||
return -1;
|
||||
}
|
||||
cpuplugd_debug("cpu with id %d cannot be hotplugged\n", cpuid);
|
||||
return -1;
|
||||
}
|
||||
|
||||
@@ -135,9 +135,8 @@ int hotunplug(int cpuid)
|
||||
fclose(filp);
|
||||
if (state == 0)
|
||||
return 1;
|
||||
} else {
|
||||
cpuplugd_error("unplugging cpu with id %d failed\n", cpuid);
|
||||
}
|
||||
cpuplugd_debug("cpu with id %d cannot be hotunplugged\n", cpuid);
|
||||
return retval;
|
||||
}
|
||||
|
||||
@@ -163,6 +162,8 @@ int is_online(int cpuid)
|
||||
retval = 0;
|
||||
}
|
||||
fclose(filp);
|
||||
} else {
|
||||
retval = 1;
|
||||
}
|
||||
return retval;
|
||||
}
|
||||
|
||||
@@ -15,13 +15,13 @@ dasdfmt \- formatting of DASD (ECKD) disk drives.
|
||||
|
||||
.SH DESCRIPTION
|
||||
\fBdasdfmt\fR formats a DASD (ECKD) disk drive to prepare it
|
||||
for usage with Linux for S/390.
|
||||
for usage with Linux for S/390.
|
||||
The \fIdevice\fR is the node of the device (e.g. '/dev/dasda').
|
||||
Any device node created by udev for kernel 2.6 can be used
|
||||
Any device node created by udev for kernel 2.6 can be used
|
||||
(e.g. '/dev/dasd/0.0.b100/disc').
|
||||
.br
|
||||
|
||||
\fBWARNING\fR: Careless usage of \fBdasdfmt\fR can result in
|
||||
\fBWARNING\fR: Careless usage of \fBdasdfmt\fR can result in
|
||||
\fBLOSS OF DATA\fR.
|
||||
|
||||
.SH OPTIONS
|
||||
@@ -31,7 +31,7 @@ Print usage and exit.
|
||||
|
||||
.TP
|
||||
\fB-t\fR or \fB--test\fR
|
||||
Disables any modification of the disk drive.
|
||||
Disables any modification of the disk drive.
|
||||
.br
|
||||
\fBdasdfmt\fR just prints
|
||||
out, what it \fBwould\fR do.
|
||||
@@ -41,7 +41,7 @@ out, what it \fBwould\fR do.
|
||||
Increases verbosity.
|
||||
|
||||
.TP
|
||||
\fB-y\fR
|
||||
\fB-y\fR
|
||||
Start formatting without further user-confirmation.
|
||||
|
||||
.TP
|
||||
@@ -59,7 +59,7 @@ Omit the writing of a disk label after formatting.
|
||||
.br
|
||||
This makes only sense for the 'ldl' disk layout.
|
||||
.br
|
||||
The '-L' option has to be specified after the '-d ldl' option.
|
||||
The '-L' option has to be specified after the '-d ldl' option.
|
||||
.br
|
||||
|
||||
e.g. dasdfmt -d ldl -L /dev/...
|
||||
@@ -84,13 +84,13 @@ Formats the device with compatible disk layout or linux disk layout.
|
||||
\fIlayout\fR is either \fIcdl\fR for the compatible disk layout
|
||||
(default) or \fIldl\fR for the linux disk layout.
|
||||
.br
|
||||
Compatible disk layout means a special handling of the
|
||||
first two tracks of the volume. This enables other S/390 or zSeries
|
||||
Compatible disk layout means a special handling of the
|
||||
first two tracks of the volume. This enables other S/390 or zSeries
|
||||
operating systems to access this device (e.g. for backup purposes).
|
||||
|
||||
.TP
|
||||
\fB-p\fR or \fB--progressbar\fR
|
||||
Print a progress bar while formatting.
|
||||
Print a progress bar while formatting.
|
||||
Do not use this option if you are using a 3270 console,
|
||||
running in background or redirecting the output to a file.
|
||||
|
||||
@@ -164,30 +164,30 @@ and always be a power of two. The recommended blocksize is 4096 bytes.
|
||||
|
||||
.TP
|
||||
\fB-l\fR \fIvolser\fR or \fB--label\fR=\fIvolser\fR
|
||||
Specify the volume serial number or volume identifier to be written
|
||||
to disk after formatting. If no label is specified, a sensible default
|
||||
is used. \fIvolser\fR is interpreted as ASCII string and is automatically
|
||||
Specify the volume serial number or volume identifier to be written
|
||||
to disk after formatting. If no label is specified, a sensible default
|
||||
is used. \fIvolser\fR is interpreted as ASCII string and is automatically
|
||||
converted to uppercase and then to EBCDIC.
|
||||
.br
|
||||
|
||||
e.g. -l LNX001 or --label=DASD01
|
||||
.br
|
||||
|
||||
The \fIvolser\fR identifies by serial number the volume. A volume serial
|
||||
The \fIvolser\fR identifies by serial number the volume. A volume serial
|
||||
number is 1 through 6 alphanumeric or one of the following special
|
||||
characters: $, #, @, %. Enclose a serial number that contains special
|
||||
characters in apostrophes. If the number is shorter than six
|
||||
characters: $, #, @, %. Enclose a serial number that contains special
|
||||
characters in apostrophes. If the number is shorter than six
|
||||
characters, it is padded with trailing blanks.
|
||||
.br
|
||||
.br
|
||||
|
||||
Do not code a volume serial number as SCRTCH, PRIVAT, or Lnnnnn (L with
|
||||
five numbers); these are used in OS/390 messages to ask the operator to
|
||||
mount a volume. Do not code a volume serial number as MIGRAT, which is
|
||||
used by the OS/390 Hierarchical Storage Manager DFSMShsm for migrated
|
||||
Do not code a volume serial number as SCRTCH, PRIVAT, or Lnnnnn (L with
|
||||
five numbers); these are used in OS/390 messages to ask the operator to
|
||||
mount a volume. Do not code a volume serial number as MIGRAT, which is
|
||||
used by the OS/390 Hierarchical Storage Manager DFSMShsm for migrated
|
||||
data sets.
|
||||
.br
|
||||
|
||||
NOTE: Try to avoid using special characters in the volume serial. This may cause problems accessing a disk by volser.
|
||||
NOTE: Try to avoid using special characters in the volume serial. This may cause problems accessing a disk by volser.
|
||||
.br
|
||||
In case you really have to use special characters, make sure you are using quotes. In addition there is a special handling for the '$' sign. Please specify it using '\\$' if necessary.
|
||||
.br
|
||||
@@ -197,9 +197,8 @@ e.g. -l 'a@b\\$c#' to get A@B$C#
|
||||
|
||||
.TP
|
||||
\fB-k\fR or \fB--keep_volser\fR
|
||||
Keeps the Volume Serial Number, when writing the Volume Label. This is
|
||||
useful, if the Serial Number has been written with a VM Tool and should not
|
||||
be overwritten.
|
||||
Keeps the Volume Serial Number when writing the Volume Label. This is useful if
|
||||
the volume already has a Serial Number that should not be overwritten.
|
||||
.br
|
||||
|
||||
.SH SEE ALSO
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
# Common definitions
|
||||
include ../../common.mak
|
||||
|
||||
ALL_CPPFLAGS += -I../include -std=gnu99 -Wno-unused-parameter
|
||||
ALL_CPPFLAGS += -I../include -Wno-unused-parameter
|
||||
LDLIBS += -lpthread -lrt
|
||||
ifneq ($(HAVE_ZLIB),0)
|
||||
ALL_CPPFLAGS += -DHAVE_ZLIB
|
||||
|
||||
@@ -23,9 +23,16 @@
|
||||
|
||||
#define BLOCKSIZE 512
|
||||
|
||||
#if __has_attribute(nonstring)
|
||||
# define __nonstring __attribute__ ((nonstring))
|
||||
#else
|
||||
# define __nonstring
|
||||
#endif
|
||||
|
||||
|
||||
/* Basic TAR header */
|
||||
struct tar_header {
|
||||
char name[100];
|
||||
char name[100] __nonstring;
|
||||
char mode[8];
|
||||
char uid[8];
|
||||
char gid[8];
|
||||
@@ -33,7 +40,7 @@ struct tar_header {
|
||||
char mtime[12];
|
||||
char chksum[8];
|
||||
char typeflag;
|
||||
char linkname[100];
|
||||
char linkname[100] __nonstring;
|
||||
char magic[6];
|
||||
char version[2];
|
||||
char uname[32];
|
||||
@@ -78,7 +85,7 @@ static void set_time(char *dest, size_t len, time_t value)
|
||||
#define SET_TIME_FIELD(obj, name, value) \
|
||||
set_time((obj)->name, sizeof((obj)->name), (time_t) (value))
|
||||
#define SET_STR_FIELD(obj, name, value) \
|
||||
util_strlcpy((obj)->name, (value), sizeof((obj)->name))
|
||||
strncpy((obj)->name, (value), sizeof((obj)->name))
|
||||
|
||||
/* Initialize the tar file @header with the provided data */
|
||||
static void init_header(struct tar_header *header, const char *filename,
|
||||
|
||||
@@ -28,6 +28,15 @@
|
||||
# DEVICE=0.0.4e13
|
||||
# DELAY_MINUTES=5
|
||||
|
||||
#
|
||||
# Dump on ECKD device (DASD)
|
||||
#
|
||||
#ON_PANIC=dump
|
||||
#DUMP_TYPE=eckd
|
||||
#DEVICE=0.0.1004
|
||||
#BOOTPROG=0
|
||||
#BR_CHR=auto
|
||||
|
||||
#
|
||||
# Dump on fcp device (SCSI Disk)
|
||||
#
|
||||
|
||||
@@ -19,10 +19,10 @@ help:
|
||||
.br
|
||||
\fBfdasd\fR {-h|-v}
|
||||
.SH DESCRIPTION
|
||||
\fBfdasd\fR writes a partition table to a cdl (compatible disk layout)
|
||||
\fBfdasd\fR writes a partition table to a cdl (compatible disk layout)
|
||||
formatted DASD, in the form of
|
||||
a VTOC (volume table of contents) for usage with Linux for S/390
|
||||
or zSeries. If fdasd detects a valid \fBVOL1\fR volume label, it
|
||||
or zSeries. If fdasd detects a valid \fBVOL1\fR volume label, it
|
||||
will use it, otherwise it asks to write a new one.
|
||||
.br
|
||||
|
||||
@@ -34,51 +34,51 @@ will use it, otherwise it asks to write a new one.
|
||||
Print usage information, then exit.
|
||||
|
||||
.TP
|
||||
\fB-v\fR or \fB--version\fR
|
||||
\fB-v\fR or \fB--version\fR
|
||||
Print version information, then exit.
|
||||
|
||||
.TP
|
||||
\fB-s\fR or \fB--silent\fR
|
||||
\fB-s\fR or \fB--silent\fR
|
||||
Suppress messages in non-interactive mode.
|
||||
|
||||
.TP
|
||||
\fB-r\fR or \fB--verbose\fR
|
||||
\fB-r\fR or \fB--verbose\fR
|
||||
Provide more verbose output.
|
||||
|
||||
.TP
|
||||
\fB-a\fR or \fB--auto\fR
|
||||
Automatically create a partition using the entire disk in non-interactive
|
||||
\fB-a\fR or \fB--auto\fR
|
||||
Automatically create a partition using the entire disk in non-interactive
|
||||
mode.
|
||||
|
||||
.TP
|
||||
\fB-k\fR or \fB--keep_volser\fR
|
||||
Keeps the volume serial when writing the volume label.
|
||||
Keeps the Volume Serial Number when writing the Volume Label.
|
||||
.br
|
||||
This is useful, if the volume serial has been written before and should not
|
||||
be overwritten. This option is only applicable in non-interactive mode.
|
||||
This is useful if the volume already has a Serial Number that should not be
|
||||
overwritten. This option is only applicable in non-interactive mode.
|
||||
|
||||
.TP
|
||||
\fB-l\fR \fIvolser\fR or \fB--label\fR \fIvolser\fR
|
||||
Specify the volume serial.
|
||||
.br
|
||||
\fIvolser\fR is interpreted as ASCII string and is automatically converted to
|
||||
\fIvolser\fR is interpreted as ASCII string and is automatically converted to
|
||||
uppercase, padded with blanks and finally converted to EBCDIC to be written
|
||||
to disk. This option is only applicable in non-interactive mode.
|
||||
.br
|
||||
|
||||
Do not use the following reserved volume serial: SCRTCH, PRIVAT, MIGRAT,
|
||||
or Lnnnnn (L with five digit number); These are used as keywords by
|
||||
Do not use the following reserved volume serial: SCRTCH, PRIVAT, MIGRAT,
|
||||
or Lnnnnn (L with five digit number); These are used as keywords by
|
||||
other operating systems (OS/390).
|
||||
.br
|
||||
|
||||
A volume serial is 1 through 6 alphanumeric characters or one of the
|
||||
following special characters: $, #, @, %. All other characters are simply
|
||||
ignored.
|
||||
A volume serial is 1 through 6 alphanumeric characters or one of the
|
||||
following special characters: $, #, @, %. All other characters are simply
|
||||
ignored.
|
||||
.br
|
||||
Try to avoid using special characters in the volume serial.
|
||||
This may cause problems accessing a disk by volser.
|
||||
In case you really have to use special characters, make sure you are using
|
||||
quotes. In addition there is a special handling for the '$' sign.
|
||||
Try to avoid using special characters in the volume serial.
|
||||
This may cause problems accessing a disk by volser.
|
||||
In case you really have to use special characters, make sure you are using
|
||||
quotes. In addition there is a special handling for the '$' sign.
|
||||
Please specify it using '\\$' if necessary.
|
||||
.br
|
||||
|
||||
@@ -124,14 +124,14 @@ partitions that use the entire disk:
|
||||
.br
|
||||
|
||||
.TP
|
||||
\fB-i\fR or \fB--volser\fR
|
||||
\fB-i\fR or \fB--volser\fR
|
||||
Print the volume serial, then exit.
|
||||
|
||||
.TP
|
||||
\fB-p\fR or \fB--table\fR
|
||||
Print partition table, then exit.
|
||||
\fB-p\fR or \fB--table\fR
|
||||
Print partition table, then exit.
|
||||
.br
|
||||
In combination with the -s option fdasd will display a short version of the
|
||||
In combination with the -s option fdasd will display a short version of the
|
||||
partition table.
|
||||
|
||||
.TP
|
||||
@@ -179,7 +179,7 @@ In case your are not using the device file system, please specify:
|
||||
.br
|
||||
|
||||
where \fIx\fR is one or more lowercase letter(s) or any other device
|
||||
node specification configured by udev for kernel 2.6 or higher.
|
||||
node specification configured by udev for kernel 2.6 or higher.
|
||||
|
||||
.SH SEE ALSO
|
||||
.BR dasdfmt (8)
|
||||
|
||||
@@ -3,16 +3,16 @@ include ../common.mak
|
||||
|
||||
.DEFAULT_GOAL := all
|
||||
|
||||
PKGDATADIR := "$(DESTDIR)$(TOOLS_DATADIR)/genprotimg"
|
||||
PKGDATADIR := "$(TOOLS_DATADIR)/genprotimg"
|
||||
TESTS :=
|
||||
SUBDIRS := boot src man
|
||||
RECURSIVE_TARGETS := all-recursive install-recursive clean-recursive
|
||||
|
||||
all: all-recursive
|
||||
|
||||
install: all install-recursive
|
||||
$(INSTALL) -d -m 755 "$(PKGDATADIR)"
|
||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 755 samples/check_hostkeydoc "$(PKGDATADIR)"
|
||||
install: install-recursive
|
||||
$(INSTALL) -d -m 755 "$(DESTDIR)$(PKGDATADIR)"
|
||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 755 samples/check_hostkeydoc "$(DESTDIR)$(PKGDATADIR)"
|
||||
|
||||
clean: clean-recursive
|
||||
|
||||
|
||||
@@ -2,11 +2,12 @@
|
||||
include ../../common.mak
|
||||
|
||||
FILES := stage3a.bin stage3b.bin stage3b_reloc.bin
|
||||
DEBUG_FILES := $(addsuffix .debug,$(FILES))
|
||||
|
||||
ifeq ($(HOST_ARCH),s390x)
|
||||
ZIPL_DIR := $(rootdir)/zipl
|
||||
ZIPL_BOOT_DIR := $(ZIPL_DIR)/boot
|
||||
PKGDATADIR := $(DESTDIR)$(TOOLS_DATADIR)/genprotimg
|
||||
PKGDATADIR := $(TOOLS_DATADIR)/genprotimg
|
||||
|
||||
INCLUDE_PATHS := $(ZIPL_BOOT_DIR) $(ZIPL_DIR)/include $(rootdir)/include
|
||||
INCLUDE_PARMS := $(addprefix -I,$(INCLUDE_PATHS))
|
||||
@@ -71,25 +72,30 @@ stage3b_reloc.o: stage3b.bin
|
||||
stage3a.elf: head.o stage3a_init.o $(ZIPL_OBJS)
|
||||
stage3b.elf: head.o $(ZIPL_OBJS)
|
||||
|
||||
.SECONDARY: $(FILES:.bin=.lds)
|
||||
%.elf: %.lds %.o
|
||||
$(LINK) $(NO_PIE_LDFLAGS) $(NO_WARN_RWX_SEGMENTS_LDFLAGS) -Wl,-T,$< -Wl,--build-id=none -m64 -static -nostdlib $(filter %.o, $^) -o $@
|
||||
@chmod a-x $@
|
||||
|
||||
%.bin.debug: %.elf
|
||||
$(OBJCOPY) --only-keep-debug $< $@
|
||||
@chmod a-x $@
|
||||
|
||||
%.bin: %.elf
|
||||
$(OBJCOPY) -O binary $< $@
|
||||
@chmod a-x $@
|
||||
|
||||
install: stage3a.bin stage3b_reloc.bin
|
||||
$(INSTALL) -d -m 755 "$(PKGDATADIR)"
|
||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 stage3a.bin "$(PKGDATADIR)"
|
||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 stage3b_reloc.bin "$(PKGDATADIR)"
|
||||
$(INSTALL) -d -m 755 "$(DESTDIR)$(PKGDATADIR)"
|
||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 stage3a.bin "$(DESTDIR)$(PKGDATADIR)"
|
||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 stage3b_reloc.bin "$(DESTDIR)$(PKGDATADIR)"
|
||||
|
||||
else
|
||||
# Don't generate the dependency files (see `common.mak` for the
|
||||
# `-include $(dependencies_c)` statement).
|
||||
.PHONY: $(dependencies_c)
|
||||
|
||||
$(FILES):
|
||||
$(FILES) $(DEBUG_FILES):
|
||||
echo " SKIP $@ due to HOST_ARCH != s390x"
|
||||
|
||||
install:
|
||||
@@ -97,9 +103,9 @@ install:
|
||||
endif
|
||||
|
||||
.DEFAULT_GOAL := all
|
||||
all: $(FILES)
|
||||
all: $(FILES) $(DEBUG_FILES)
|
||||
|
||||
clean:
|
||||
rm -f *.o *.elf *.bin *.map .*.d *.lds
|
||||
rm -f -- *.o *.elf *.bin *.map .*.d *.lds *.debug
|
||||
|
||||
.PHONY: all clean
|
||||
|
||||
@@ -11,9 +11,10 @@
|
||||
#include "stage3a.h"
|
||||
|
||||
#include "lib/zt_common.h"
|
||||
#include "boot/error.h"
|
||||
#include "boot/s390.h"
|
||||
#include "boot/ipl.h"
|
||||
#include "sclp.h"
|
||||
#include "error.h"
|
||||
|
||||
|
||||
static volatile struct stage3a_args __section(".loader_parms") loader_parms;
|
||||
|
||||
@@ -12,10 +12,11 @@
|
||||
|
||||
#include "lib/zt_common.h"
|
||||
#include "boot/psw.h"
|
||||
#include "boot/error.h"
|
||||
#include "boot/s390.h"
|
||||
#include "boot/linux_layout.h"
|
||||
#include "boot/loaders_layout.h"
|
||||
#include "sclp.h"
|
||||
#include "error.h"
|
||||
|
||||
|
||||
static volatile struct stage3b_args __section(".loader_parms") loader_parms;
|
||||
@@ -60,13 +61,17 @@ void __noreturn start(void)
|
||||
if (cmdline->size > get_kernel_cmdline_size())
|
||||
panic(EINTERNAL, "Command line is too large\n");
|
||||
|
||||
/* move the kernel cmdline */
|
||||
memmove((void *)COMMAND_LINE,
|
||||
(void *)cmdline->src,
|
||||
cmdline->size);
|
||||
if (cmdline->size > 0) {
|
||||
/* make sure the cmdline is a null-terminated string */
|
||||
if (((char *)cmdline->src)[cmdline->size - 1] != '\0')
|
||||
panic(EINTERNAL, "Command line needs to be null-terminated\n");
|
||||
|
||||
/* move the kernel cmdline */
|
||||
memmove((void *)COMMAND_LINE, (void *)cmdline->src, cmdline->size);
|
||||
}
|
||||
/* the initrd does not need to be moved */
|
||||
|
||||
if (initrd->size != 0) {
|
||||
if (initrd->size > 0) {
|
||||
/* copy initrd start address and size into new kernel space */
|
||||
*(unsigned long long *)INITRD_START = initrd->src;
|
||||
*(unsigned long long *)INITRD_SIZE = initrd->size;
|
||||
|
||||
@@ -97,18 +97,29 @@ Do not use for a production image unless you verified
|
||||
the host-key document before. Optional.
|
||||
.TP
|
||||
\fB\-\-comm\-key\fR=\fI\,FILE\/\fR
|
||||
Specifies the encryption key you want to use for the PV guest dump. Use a
|
||||
secure, random, plaintext AES-256 GCM key. Optional.
|
||||
Specifies the customer communication key (CCK). This key is used for the
|
||||
PV guest dump encryption and to derive the CCK-derived extension secret
|
||||
used for add-secret requests. Use a secure, random, plaintext AES-256
|
||||
GCM key. Optional.
|
||||
.TP
|
||||
\fB\-\-enable\-dump\fR
|
||||
Enable PV guest dumps. Requires the \fB\-\-comm-key\fR option. Optional.
|
||||
Enable PV guest dumps. Requires the \fB\-\-comm\-key\fR option. Optional.
|
||||
.TP
|
||||
\fB\-\-disable\-dump\fR
|
||||
Disable PV guest dumps. This is the default. Optional.
|
||||
Disable PV guest dumps. This is the default.
|
||||
.TP
|
||||
\fB\-\-enable\-cck\-extension\-secret\fR
|
||||
Add-secret requests must provide an extension secret that matches the
|
||||
CCK-derived extension secret. Requires the \fB\-\-comm\-key\fR option.
|
||||
Optional.
|
||||
.TP
|
||||
\fB\-\-disable\-cck\-extension\-secret\fR
|
||||
Add-secret requests don't have to provide an extension secret. This is
|
||||
the default.
|
||||
.TP
|
||||
\fB\-\-enable\-pckmo\fR
|
||||
Enable the support for the DEA, TDEA, AES, and ECC PCKMO key encryption
|
||||
functions. This is the default. Optional.
|
||||
functions. This is the default.
|
||||
.TP
|
||||
\fB\-\-disable\-pckmo\fR
|
||||
Disable the support for the DEA, TDEA, AES, and ECC PCKMO key encryption
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
#
|
||||
# Sample script to verify that a host key document is genuine by
|
||||
# verifying the issuer, the validity date and the signature.
|
||||
# Optionally verify the full trust chain using a CA certficate.
|
||||
# Optionally verify the full trust chain using a CA certificate.
|
||||
#
|
||||
# Sample invocation:
|
||||
#
|
||||
@@ -15,31 +15,33 @@
|
||||
# s390-tools is free software; you can redistribute it and/or modify
|
||||
# it under the terms of the MIT license. See LICENSE for details.
|
||||
|
||||
|
||||
# Allocate temporary files
|
||||
ISSUER_PUBKEY_FILE=$(mktemp)
|
||||
SIGNATURE_FILE=$(mktemp)
|
||||
BODY_FILE=$(mktemp)
|
||||
ISSUER_DN_FILE=$(mktemp)
|
||||
SUBJECT_DN_FILE=$(mktemp)
|
||||
DEF_ISSUER_DN_FILE=$(mktemp)
|
||||
DEF_ISSUER_ARMONK_DN_FILE=$(mktemp)
|
||||
DEF_ISSUER_POUGHKEEPSIE_DN_FILE=$(mktemp)
|
||||
CANONICAL_ISSUER_DN_FILE=$(mktemp)
|
||||
CRL_SERIAL_FILE=$(mktemp)
|
||||
|
||||
# Cleanup on exit
|
||||
cleanup()
|
||||
{
|
||||
rm -f $ISSUER_PUBKEY_FILE $SIGNATURE_FILE $BODY_FILE \
|
||||
$ISSUER_DN_FILE $SUBJECT_DN_FILE $DEF_ISSUER_DN_FILE \
|
||||
$CANONICAL_ISSUER_DN_FILE $CRL_SERIAL_FILE
|
||||
rm -f "$ISSUER_PUBKEY_FILE" "$SIGNATURE_FILE" "$BODY_FILE" \
|
||||
"$ISSUER_DN_FILE" "$SUBJECT_DN_FILE" "$DEF_ISSUER_ARMONK_DN_FILE" "$DEF_ISSUER_POUGHKEEPSIE_DN_FILE" \
|
||||
"$CANONICAL_ISSUER_DN_FILE" "$CRL_SERIAL_FILE"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
# Enhanced error checking for bash
|
||||
if [ -n "${BASH}" ]
|
||||
then
|
||||
if [ -n "${BASH}" ]; then
|
||||
# shellcheck disable=SC3040
|
||||
set -o posix
|
||||
# shellcheck disable=SC3040
|
||||
set -o pipefail
|
||||
# shellcheck disable=SC3040
|
||||
set -o nounset
|
||||
fi
|
||||
set -e
|
||||
@@ -47,8 +49,8 @@ set -e
|
||||
# Usage
|
||||
usage()
|
||||
{
|
||||
cat <<-EOF
|
||||
Usage: `basename $1` [-d] [-c CA-cert] [-r CRL] host-key-doc signing-key-cert
|
||||
cat <<-EOF
|
||||
Usage: $(basename "$1") [-d] [-c CA-cert] [-r CRL] host-key-doc signing-key-cert
|
||||
|
||||
Verify an IBM Secure Execution host key document against
|
||||
a signing key.
|
||||
@@ -71,8 +73,7 @@ check_verify_chain()
|
||||
{
|
||||
# Verify certificate chain in case a CA certificate file/bundle
|
||||
# was specified on the command line.
|
||||
if [ $# = 1 ]
|
||||
then
|
||||
if [ -z "$2" ]; then
|
||||
cat >&2 <<-EOF
|
||||
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
||||
No CA certificate specified! Skipping trust chain verification.
|
||||
@@ -80,37 +81,37 @@ Make sure that '$1' is a valid certificate.
|
||||
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
||||
EOF
|
||||
else
|
||||
openssl verify -crl_download -crl_check $2 &&
|
||||
openssl verify -crl_download -crl_check -untrusted $2 $1 ||
|
||||
exit 1
|
||||
openssl verify -crl_download -crl_check "$2" &&
|
||||
openssl verify -crl_download -crl_check -untrusted "$2" "$1" ||
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
|
||||
extract_pubkey()
|
||||
{
|
||||
openssl x509 -in $1 -pubkey -noout > $2
|
||||
openssl x509 -in "$1" -pubkey -noout >"$2"
|
||||
}
|
||||
|
||||
extract_signature()
|
||||
{
|
||||
# Assuming that the last field is the signature
|
||||
SIGOFFSET=$(openssl asn1parse -in $1 | tail -1 | cut -d : -f 1)
|
||||
SIGOFFSET=$(openssl asn1parse -in "$1" | tail -1 | cut -d : -f 1)
|
||||
|
||||
openssl asn1parse -in $1 -out $2 -strparse $SIGOFFSET -noout
|
||||
openssl asn1parse -in "$1" -out "$2" -strparse "$SIGOFFSET" -noout
|
||||
}
|
||||
|
||||
extract_body()
|
||||
{
|
||||
# Assuming that the first field is the full cert body
|
||||
SIGOFFSET=$(openssl asn1parse -in $1 | head -2 | tail -1 | cut -d : -f 1)
|
||||
SIGOFFSET=$(openssl asn1parse -in "$1" | head -2 | tail -1 | cut -d : -f 1)
|
||||
|
||||
openssl asn1parse -in $1 -out $2 -strparse $SIGOFFSET -noout
|
||||
openssl asn1parse -in "$1" -out "$2" -strparse "$SIGOFFSET" -noout
|
||||
}
|
||||
|
||||
verify_signature()
|
||||
{
|
||||
# Assuming that the signature algorithm is SHA512 with RSA
|
||||
openssl sha512 -verify $1 -signature $2 $3
|
||||
openssl sha512 -verify "$1" -signature "$2" "$3"
|
||||
}
|
||||
|
||||
canonical_dn()
|
||||
@@ -120,18 +121,30 @@ canonical_dn()
|
||||
DNTYPE=$3
|
||||
OUTPUT=$4
|
||||
|
||||
openssl $OBJTYPE -in $OBJ -$DNTYPE -noout -nameopt multiline \
|
||||
| sort | grep -v $DNTYPE= > $OUTPUT
|
||||
openssl "$OBJTYPE" -in "$OBJ" -"$DNTYPE" -noout -nameopt multiline |
|
||||
LC_ALL=C sort | grep -v "$DNTYPE"= >"$OUTPUT"
|
||||
}
|
||||
|
||||
default_issuer()
|
||||
default_issuer_armonk()
|
||||
{
|
||||
cat <<-EOF
|
||||
commonName = International Business Machines Corporation
|
||||
countryName = US
|
||||
localityName = Armonk
|
||||
organizationName = International Business Machines Corporation
|
||||
organizationalUnitName = Key Signing Service
|
||||
stateOrProvinceName = New York
|
||||
EOF
|
||||
}
|
||||
|
||||
default_issuer_pougkeepsie()
|
||||
{
|
||||
cat <<-EOF
|
||||
commonName = International Business Machines Corporation
|
||||
countryName = US
|
||||
localityName = Poughkeepsie
|
||||
organizationalUnitName = Key Signing Service
|
||||
organizationName = International Business Machines Corporation
|
||||
organizationalUnitName = Key Signing Service
|
||||
stateOrProvinceName = New York
|
||||
EOF
|
||||
}
|
||||
@@ -141,42 +154,37 @@ EOF
|
||||
# stripping off the prefix
|
||||
verify_default_issuer()
|
||||
{
|
||||
default_issuer > $DEF_ISSUER_DN_FILE
|
||||
default_issuer_pougkeepsie >"$DEF_ISSUER_POUGHKEEPSIE_DN_FILE"
|
||||
default_issuer_armonk >"$DEF_ISSUER_ARMONK_DN_FILE"
|
||||
|
||||
sed "s/\(^[ ]*organizationalUnitName[ ]*=[ ]*\).*\(Key Signing Service$\)/\1\2/" \
|
||||
$ISSUER_DN_FILE > $CANONICAL_ISSUER_DN_FILE
|
||||
"$ISSUER_DN_FILE" >"$CANONICAL_ISSUER_DN_FILE"
|
||||
|
||||
if ! diff $CANONICAL_ISSUER_DN_FILE $DEF_ISSUER_DN_FILE
|
||||
then
|
||||
if ! {
|
||||
diff "$CANONICAL_ISSUER_DN_FILE" "$DEF_ISSUER_POUGHKEEPSIE_DN_FILE" ||
|
||||
diff "$CANONICAL_ISSUER_DN_FILE" "$DEF_ISSUER_ARMONK_DN_FILE"
|
||||
} >/dev/null 2>&1; then
|
||||
echo Incorrect default issuer >&2 && exit 1
|
||||
fi
|
||||
}
|
||||
|
||||
verify_issuer_files()
|
||||
{
|
||||
if [ $1 -eq 1 ]
|
||||
then
|
||||
verify_default_issuer
|
||||
fi
|
||||
|
||||
if diff $ISSUER_DN_FILE $SUBJECT_DN_FILE
|
||||
then
|
||||
echo Issuer verification OK
|
||||
else
|
||||
echo Issuer verification failed >&2 && exit 1
|
||||
if [ "$1" -eq 1 ]; then
|
||||
verify_default_issuer
|
||||
fi
|
||||
}
|
||||
|
||||
cert_time()
|
||||
{
|
||||
DATE=$(openssl x509 -in $1 -$2 -noout | sed "s/^.*=//")
|
||||
DATE=$(openssl x509 -in "$1" -"$2" -noout | sed "s/^.*=//")
|
||||
|
||||
date -d "$DATE" +%s
|
||||
}
|
||||
|
||||
crl_time()
|
||||
{
|
||||
DATE=$(openssl crl -in $1 -$2 -noout | sed "s/^.*=//")
|
||||
DATE=$(openssl crl -in "$1" -"$2" -noout | sed "s/^.*=//")
|
||||
|
||||
date -d "$DATE" +%s
|
||||
}
|
||||
@@ -188,8 +196,7 @@ verify_dates()
|
||||
MSG="${3:-Certificate}"
|
||||
NOW=$(date +%s)
|
||||
|
||||
if [ $START -le $NOW -a $NOW -le $END ]
|
||||
then
|
||||
if [ "$START" -le "$NOW" ] && [ "$NOW" -le "$END" ]; then
|
||||
echo "${MSG} dates are OK"
|
||||
else
|
||||
echo "${MSG} date verification failed" >&2 && exit 1
|
||||
@@ -198,22 +205,21 @@ verify_dates()
|
||||
|
||||
crl_serials()
|
||||
{
|
||||
openssl crl -in $1 -text -noout | \
|
||||
grep "Serial Number" > $CRL_SERIAL_FILE
|
||||
openssl crl -in "$1" -text -noout |
|
||||
grep "Serial Number" >"$CRL_SERIAL_FILE"
|
||||
}
|
||||
|
||||
check_serial()
|
||||
{
|
||||
CERT_SERIAL=$(openssl x509 -in $1 -noout -serial | cut -d = -f 2)
|
||||
CERT_SERIAL=$(openssl x509 -in "$1" -noout -serial | cut -d = -f 2)
|
||||
|
||||
grep -q $CERT_SERIAL $CRL_SERIAL_FILE
|
||||
grep -q "$CERT_SERIAL" "$CRL_SERIAL_FILE"
|
||||
}
|
||||
|
||||
check_file()
|
||||
{
|
||||
[ $# = 0 ] ||
|
||||
[ -e "$1" ] ||
|
||||
(echo "File '$1' not found" >&2 && exit 1)
|
||||
(echo "File '$1' not found" >&2 && exit 1)
|
||||
}
|
||||
|
||||
# check args
|
||||
@@ -221,28 +227,25 @@ CRL_FILE=
|
||||
CA_FILE=
|
||||
CHECK_DEFAULT_ISSUER=1
|
||||
|
||||
args=$(getopt -qu "dr:c:h" $*)
|
||||
if [ $? = 0 ]
|
||||
then
|
||||
set -- $args
|
||||
while [ $1 != "" ]
|
||||
do
|
||||
case $1 in
|
||||
-d) CHECK_DEFAULT_ISSUER=0; shift;;
|
||||
-r) CRL_FILE=$2; shift 2;;
|
||||
-c) CA_FILE=$2; shift 2;;
|
||||
-h) usage $0; exit 0;;
|
||||
--) shift; break;;
|
||||
esac
|
||||
done
|
||||
else
|
||||
usage $0 >&2
|
||||
exit 1
|
||||
fi
|
||||
while getopts 'dr:c:h' opt; do
|
||||
case $opt in
|
||||
d) CHECK_DEFAULT_ISSUER=0 ;;
|
||||
r) CRL_FILE=$OPTARG ;;
|
||||
c) CA_FILE=$OPTARG ;;
|
||||
h)
|
||||
usage "$0"
|
||||
exit 0
|
||||
;;
|
||||
?)
|
||||
usage "$0"
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
done
|
||||
shift "$((OPTIND - 1))"
|
||||
|
||||
if [ $# -ne 2 ]
|
||||
then
|
||||
usage $0 >&2
|
||||
if [ $# -ne 2 ]; then
|
||||
usage "$0" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
@@ -250,51 +253,51 @@ HKD_FILE=$1
|
||||
HKSK_FILE=$2
|
||||
|
||||
# Check whether all specified files exist
|
||||
check_file $HKD_FILE
|
||||
check_file $HKSK_FILE
|
||||
check_file $CA_FILE
|
||||
check_file $CRL_FILE
|
||||
check_file "$HKD_FILE"
|
||||
check_file "$HKSK_FILE"
|
||||
# CA and CRL are optional arguments
|
||||
[ -n "$CA_FILE" ] && check_file "$CA_FILE"
|
||||
[ -n "$CRL_FILE" ] && check_file "$CRL_FILE"
|
||||
|
||||
# Check trust chain
|
||||
check_verify_chain $HKSK_FILE $CA_FILE
|
||||
check_verify_chain "$HKSK_FILE" "$CA_FILE"
|
||||
|
||||
# Verify host key document signature
|
||||
echo -n "Checking host key document signature: "
|
||||
extract_pubkey $HKSK_FILE $ISSUER_PUBKEY_FILE &&
|
||||
extract_signature $HKD_FILE $SIGNATURE_FILE &&
|
||||
extract_body $HKD_FILE $BODY_FILE &&
|
||||
verify_signature $ISSUER_PUBKEY_FILE $SIGNATURE_FILE $BODY_FILE ||
|
||||
exit 1
|
||||
printf "Checking host key document signature: "
|
||||
extract_pubkey "$HKSK_FILE" "$ISSUER_PUBKEY_FILE" &&
|
||||
extract_signature "$HKD_FILE" "$SIGNATURE_FILE" &&
|
||||
extract_body "$HKD_FILE" "$BODY_FILE" &&
|
||||
verify_signature "$ISSUER_PUBKEY_FILE" "$SIGNATURE_FILE" "$BODY_FILE" ||
|
||||
exit 1
|
||||
|
||||
# Verify the issuer
|
||||
canonical_dn x509 $HKD_FILE issuer $ISSUER_DN_FILE
|
||||
canonical_dn x509 $HKSK_FILE subject $SUBJECT_DN_FILE
|
||||
canonical_dn x509 "$HKD_FILE" issuer "$ISSUER_DN_FILE"
|
||||
canonical_dn x509 "$HKSK_FILE" subject "$SUBJECT_DN_FILE"
|
||||
verify_issuer_files $CHECK_DEFAULT_ISSUER
|
||||
|
||||
# Verify dates
|
||||
verify_dates $(cert_time $HKD_FILE startdate) $(cert_time $HKD_FILE enddate)
|
||||
verify_dates "$(cert_time "$HKD_FILE" startdate)" "$(cert_time "$HKD_FILE" enddate)"
|
||||
|
||||
# Check CRL if specified
|
||||
if [ -n "$CRL_FILE" ]
|
||||
then
|
||||
echo -n "Checking CRL signature: "
|
||||
extract_signature $CRL_FILE $SIGNATURE_FILE &&
|
||||
extract_body $CRL_FILE $BODY_FILE &&
|
||||
verify_signature $ISSUER_PUBKEY_FILE $SIGNATURE_FILE $BODY_FILE ||
|
||||
exit 1
|
||||
if [ -n "$CRL_FILE" ]; then
|
||||
printf "Checking CRL signature: "
|
||||
extract_signature "$CRL_FILE" "$SIGNATURE_FILE" &&
|
||||
extract_body "$CRL_FILE" "$BODY_FILE" &&
|
||||
verify_signature "$ISSUER_PUBKEY_FILE" "$SIGNATURE_FILE" "$BODY_FILE" ||
|
||||
exit 1
|
||||
|
||||
echo -n "CRL "
|
||||
canonical_dn crl $CRL_FILE issuer $ISSUER_DN_FILE
|
||||
canonical_dn x509 $HKSK_FILE subject $SUBJECT_DN_FILE
|
||||
printf "CRL "
|
||||
canonical_dn crl "$CRL_FILE" issuer "$ISSUER_DN_FILE"
|
||||
canonical_dn x509 "$HKSK_FILE" subject "$SUBJECT_DN_FILE"
|
||||
verify_issuer_files $CHECK_DEFAULT_ISSUER
|
||||
|
||||
verify_dates $(crl_time $CRL_FILE lastupdate) $(crl_time $CRL_FILE nextupdate) 'CRL'
|
||||
verify_dates "$(crl_time "$CRL_FILE" lastupdate)" "$(crl_time "$CRL_FILE" nextupdate)" 'CRL'
|
||||
|
||||
crl_serials $CRL_FILE
|
||||
check_serial $HKD_FILE &&
|
||||
echo "Certificate is revoked, do not use it anymore!" >&2 &&
|
||||
exit 1
|
||||
crl_serials "$CRL_FILE"
|
||||
check_serial "$HKD_FILE" &&
|
||||
echo "Certificate is revoked, do not use it anymore!" >&2 &&
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# We made it
|
||||
echo All checks reqested for \'$HKD_FILE\' were successful
|
||||
echo All checks requested for \'"$HKD_FILE"\' were successful
|
||||
|
||||
@@ -3,7 +3,7 @@ include ../../common.mak
|
||||
|
||||
bin_PROGRAM = genprotimg
|
||||
|
||||
PKGDATADIR ?= "$(DESTDIR)$(TOOLS_DATADIR)/genprotimg"
|
||||
PKGDATADIR ?= "$(TOOLS_DATADIR)/genprotimg"
|
||||
SRC_DIR := $(dir $(realpath $(firstword $(MAKEFILE_LIST))))
|
||||
TOP_SRCDIR := $(SRC_DIR)/../
|
||||
ROOT_DIR = $(TOP_SRC_DIR)/../../
|
||||
@@ -27,7 +27,7 @@ $(bin_PROGRAM)_SRCS := $(bin_PROGRAM).c pv/pv_stage3.c pv/pv_image.c \
|
||||
$(NULL)
|
||||
$(bin_PROGRAM)_OBJS := $($(bin_PROGRAM)_SRCS:.c=.o)
|
||||
|
||||
ALL_CFLAGS += -std=gnu11 -DPKGDATADIR=$(PKGDATADIR) \
|
||||
ALL_CFLAGS += -DPKGDATADIR=$(PKGDATADIR) \
|
||||
$(GLIB2_CFLAGS) $(LIBCRYPTO_CFLAGS) $(LIBCURL_CFLAGS) \
|
||||
-DOPENSSL_API_COMPAT=0x10100000L \
|
||||
$(WARNINGS) \
|
||||
|
||||
@@ -17,7 +17,8 @@
|
||||
/* IBM signing key subject */
|
||||
#define PV_IBM_Z_SUBJECT_COMMON_NAME "International Business Machines Corporation"
|
||||
#define PV_IBM_Z_SUBJECT_COUNTRY_NAME "US"
|
||||
#define PV_IBM_Z_SUBJECT_LOCALITY_NAME "Poughkeepsie"
|
||||
#define PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE "Poughkeepsie"
|
||||
#define PV_IBM_Z_SUBJECT_LOCALITY_NAME_ARMONK "Armonk"
|
||||
#define PV_IBM_Z_SUBJECT_ORGANIZATIONONAL_UNIT_NAME_SUFFIX "Key Signing Service"
|
||||
#define PV_IBM_Z_SUBJECT_ORGANIZATION_NAME "International Business Machines Corporation"
|
||||
#define PV_IBM_Z_SUBJECT_STATE "New York"
|
||||
|
||||
@@ -34,6 +34,10 @@
|
||||
#define PV_PCF_PCKMO_AES __PV_BIT(57) /* PCKMO encrypt-AES-key functions allowed */
|
||||
#define PV_PCF_PCKM_ECC __PV_BIT(58) /* PCKMO encrypt-ECC-key functions allowed */
|
||||
|
||||
/* Secret control flags */
|
||||
#define PV_SCF_CCK_EXTENSION_SECRET_ENFORCMENT \
|
||||
__PV_BIT(1) /* All add-secret requests must provide an extension secret */
|
||||
|
||||
/* maxima for the PV version 1 */
|
||||
#define PV_V1_IPIB_MAX_SIZE PAGE_SIZE
|
||||
#define PV_V1_PV_HDR_MAX_SIZE (2 * PAGE_SIZE)
|
||||
|
||||
@@ -62,11 +62,12 @@ static gint pv_args_set_defaults(PvArgs *args, GError **err G_GNUC_UNUSED)
|
||||
|
||||
static gint pv_args_validate_options(PvArgs *args, GError **err)
|
||||
{
|
||||
const PvControlFlagsArgs *cf_args = &args->cf_args;
|
||||
PvComponentType KERNEL = PV_COMP_TYPE_KERNEL;
|
||||
|
||||
/* Check for mutually exclusive arguments */
|
||||
if (args->pcf && !(args->allow_pckmo == PV_NOT_SET &&
|
||||
args->allow_dump == PV_NOT_SET)) {
|
||||
if (cf_args->pcf &&
|
||||
!(cf_args->enable_pckmo == PV_NOT_SET && cf_args->enable_dump == PV_NOT_SET)) {
|
||||
g_set_error(
|
||||
err, PV_PARSE_ERROR, PV_PARSE_ERROR_SYNTAX,
|
||||
_("The '--x-pcf' option cannot be used with the '--(enable|disable)-pckmo' or"
|
||||
@@ -74,6 +75,13 @@ static gint pv_args_validate_options(PvArgs *args, GError **err)
|
||||
return -1;
|
||||
}
|
||||
|
||||
if (cf_args->scf && !(cf_args->enable_cck_extension_secret_enforcement == PV_NOT_SET)) {
|
||||
g_set_error(
|
||||
err, PV_PARSE_ERROR, PV_PARSE_ERROR_SYNTAX,
|
||||
_("The '--x-scf' option cannot be used with the '--(enable|disable)-extension-secret-required' flags.\nUse 'genprotimg --help' for more information"));
|
||||
return -1;
|
||||
}
|
||||
|
||||
/* Check for unused arguments */
|
||||
if (args->unused_values->len > 0) {
|
||||
g_autofree gchar *unused = NULL;
|
||||
@@ -93,12 +101,20 @@ static gint pv_args_validate_options(PvArgs *args, GError **err)
|
||||
}
|
||||
|
||||
/* Check for mandatory arguments */
|
||||
if (args->allow_dump == PV_TRUE && !args->cust_comm_key_path) {
|
||||
if (cf_args->enable_dump == PV_TRUE && !args->cust_comm_key_path) {
|
||||
g_set_error(err, PV_PARSE_ERROR, PR_PARSE_ERROR_MISSING_ARGUMENT,
|
||||
_("Option '--allow-dump' requires the '--comm-key' option.\nUse 'genprotimg "
|
||||
_("Option '--enable-dump' requires the '--comm-key' option.\nUse 'genprotimg "
|
||||
"--help' for more information"));
|
||||
return -1;
|
||||
}
|
||||
if (cf_args->enable_cck_extension_secret_enforcement == PV_TRUE &&
|
||||
!args->cust_comm_key_path) {
|
||||
g_set_error(
|
||||
err, PV_PARSE_ERROR, PR_PARSE_ERROR_MISSING_ARGUMENT,
|
||||
_("Option '--enable-cck-extension-secret' requires the '--comm-key' option.\nUse 'genprotimg "
|
||||
"--help' for more information"));
|
||||
return -1;
|
||||
}
|
||||
|
||||
if (!args->output_path) {
|
||||
g_set_error(err, PV_PARSE_ERROR, PR_PARSE_ERROR_MISSING_ARGUMENT,
|
||||
@@ -178,11 +194,11 @@ static gboolean cb_set_string_option(const gchar *option, const gchar *value,
|
||||
if (g_str_equal(option, "--x-header-key"))
|
||||
args_option = &args->cust_root_key_path;
|
||||
if (g_str_equal(option, "--x-pcf"))
|
||||
args_option = &args->pcf;
|
||||
args_option = &args->cf_args.pcf;
|
||||
if (g_str_equal(option, "--x-psw"))
|
||||
args_option = &args->psw_addr;
|
||||
if (g_str_equal(option, "--x-scf"))
|
||||
args_option = &args->scf;
|
||||
args_option = &args->cf_args.scf;
|
||||
|
||||
if (!args_option) {
|
||||
g_set_error(err, PV_PARSE_ERROR, PV_PARSE_ERROR_SYNTAX,
|
||||
@@ -217,49 +233,48 @@ static gboolean cb_remaining_values(const gchar *option G_GNUC_UNUSED,
|
||||
}
|
||||
|
||||
#define MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, VALUE) (cb_##FLAG##_##VALUE)
|
||||
#define DEFINE_MUT_EXCL_BOOL_FLAG_CB(FLAG, VALUE) \
|
||||
static gboolean MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, VALUE)( \
|
||||
const gchar *option G_GNUC_UNUSED, const gchar *value G_GNUC_UNUSED, \
|
||||
PvArgs *args, GError **err) \
|
||||
{ \
|
||||
if (!(args->allow_##FLAG == PV_NOT_SET || \
|
||||
args->allow_##FLAG == VALUE)) { \
|
||||
g_set_error(err, G_OPTION_ERROR, G_OPTION_ERROR_FAILED, \
|
||||
"'--enable-" #FLAG "' and '--disable-" #FLAG \
|
||||
"' are mutually exclusive"); \
|
||||
return FALSE; \
|
||||
} \
|
||||
args->allow_##FLAG = VALUE; \
|
||||
return TRUE; \
|
||||
#define DEFINE_MUT_EXCL_BOOL_FLAG_CB(FLAG, VALUE) \
|
||||
static gboolean MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, VALUE)(const gchar *option G_GNUC_UNUSED, \
|
||||
const gchar *value G_GNUC_UNUSED, \
|
||||
PvArgs *args, GError **err) \
|
||||
{ \
|
||||
if (!(args->cf_args.enable_##FLAG == PV_NOT_SET || \
|
||||
args->cf_args.enable_##FLAG == VALUE)) { \
|
||||
g_set_error(err, G_OPTION_ERROR, G_OPTION_ERROR_FAILED, \
|
||||
"'--enable-" #FLAG "' and '--disable-" #FLAG \
|
||||
"' are mutually exclusive"); \
|
||||
return FALSE; \
|
||||
} \
|
||||
args->cf_args.enable_##FLAG = VALUE; \
|
||||
return TRUE; \
|
||||
}
|
||||
|
||||
#define DEFINE_MUT_EXCL_BOOL_FLAG_CBS(FLAG) \
|
||||
DEFINE_MUT_EXCL_BOOL_FLAG_CB(FLAG, PV_TRUE) \
|
||||
DEFINE_MUT_EXCL_BOOL_FLAG_CB(FLAG, PV_FALSE)
|
||||
|
||||
#define MUT_EXCL_BOOL_FLAG(FLAG, ENABLE_DESC, DISABLE_DESC) \
|
||||
{ \
|
||||
.long_name = "enable-" #FLAG, \
|
||||
.short_name = 0, \
|
||||
.flags = G_OPTION_FLAG_NO_ARG, \
|
||||
.arg = G_OPTION_ARG_CALLBACK, \
|
||||
.arg_data = MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, PV_TRUE), \
|
||||
.description = ENABLE_DESC, \
|
||||
}, \
|
||||
{ \
|
||||
.long_name = "disable-" #FLAG, \
|
||||
.short_name = 0, \
|
||||
.flags = G_OPTION_FLAG_NO_ARG, \
|
||||
.arg = G_OPTION_ARG_CALLBACK, \
|
||||
.arg_data = MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, PV_FALSE), \
|
||||
.description = DISABLE_DESC, \
|
||||
#define MUT_EXCL_BOOL_FLAG(NAME, FLAG, ENABLE_DESC, DISABLE_DESC) \
|
||||
{ \
|
||||
.long_name = "enable-" #NAME, \
|
||||
.short_name = 0, \
|
||||
.flags = G_OPTION_FLAG_NO_ARG, \
|
||||
.arg = G_OPTION_ARG_CALLBACK, \
|
||||
.arg_data = MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, PV_TRUE), \
|
||||
.description = ENABLE_DESC, \
|
||||
}, \
|
||||
{ \
|
||||
.long_name = "disable-" #NAME, .short_name = 0, .flags = G_OPTION_FLAG_NO_ARG, \
|
||||
.arg = G_OPTION_ARG_CALLBACK, \
|
||||
.arg_data = MUT_EXCL_BOOL_FLAG_CB_NAME(FLAG, PV_FALSE), \
|
||||
.description = DISABLE_DESC, \
|
||||
}
|
||||
|
||||
#define INDENT " "
|
||||
#define INDENT " "
|
||||
|
||||
/* Define the callbacks for mutually exclusive command line flags */
|
||||
DEFINE_MUT_EXCL_BOOL_FLAG_CBS(dump)
|
||||
DEFINE_MUT_EXCL_BOOL_FLAG_CBS(pckmo)
|
||||
DEFINE_MUT_EXCL_BOOL_FLAG_CBS(dump);
|
||||
DEFINE_MUT_EXCL_BOOL_FLAG_CBS(pckmo);
|
||||
DEFINE_MUT_EXCL_BOOL_FLAG_CBS(cck_extension_secret_enforcement);
|
||||
|
||||
gint pv_args_parse_options(PvArgs *args, gint *argc, gchar **argv[],
|
||||
GError **err)
|
||||
@@ -280,7 +295,7 @@ gint pv_args_parse_options(PvArgs *args, gint *argc, gchar **argv[],
|
||||
.arg_data = &args->host_keys,
|
||||
.description =
|
||||
_("FILE specifies a host-key document. At least\n" INDENT
|
||||
"one is required Specify this option multiple times\n" INDENT
|
||||
"one is required. Specify this option multiple times\n" INDENT
|
||||
"to enable the image to run on more than one host."),
|
||||
.arg_description = _("FILE") },
|
||||
{ .long_name = "cert",
|
||||
@@ -325,27 +340,31 @@ gint pv_args_parse_options(PvArgs *args, gint *argc, gchar **argv[],
|
||||
.description = _("Use the kernel parameters stored in PARMFILE\n" INDENT
|
||||
"(optional)."),
|
||||
.arg_description = _("PARMFILE") },
|
||||
MUT_EXCL_BOOL_FLAG(dump, dump,
|
||||
_("Enable PV guest dumps (optional). This option\n" INDENT
|
||||
"requires the '--comm-key' option."),
|
||||
_("Disable PV guest dumps (default).")),
|
||||
MUT_EXCL_BOOL_FLAG(
|
||||
dump,
|
||||
_("Enable PV guest dumps (optional). This option\n" INDENT
|
||||
"requires the '--comm-key' option."),
|
||||
_("Disable PV guest dumps (default) (optional).")),
|
||||
MUT_EXCL_BOOL_FLAG(
|
||||
pckmo,
|
||||
_("Enable the support for the DEA, TDEA, AES, and\n" INDENT
|
||||
"ECC PCKMO key encryption functions (default)\n" INDENT
|
||||
"(optional)."),
|
||||
_("Disable the support for the DEA, TDEA, AES, and\n" INDENT
|
||||
"ECC PCKMO key encryption functions (optional).")),
|
||||
cck-extension-secret, cck_extension_secret_enforcement,
|
||||
_("Add-secret requests must provide an extension\n" INDENT
|
||||
"secret that matches the CCK-derived extension\n" INDENT
|
||||
"secret (optional). This option requires the\n" INDENT
|
||||
"'--comm-key' option."),
|
||||
_("Add-secret requests don't have to provide\n" INDENT
|
||||
"the CCK-derived extension secret (default).")),
|
||||
MUT_EXCL_BOOL_FLAG(pckmo, pckmo,
|
||||
_("Enable the support for the DEA, TDEA, AES, and\n" INDENT
|
||||
"ECC PCKMO key encryption functions (default)."),
|
||||
_("Disable the support for the DEA, TDEA, AES, and\n" INDENT
|
||||
"ECC PCKMO key encryption functions (optional).")),
|
||||
{ .long_name = "comm-key",
|
||||
.short_name = 0,
|
||||
.flags = G_OPTION_FLAG_FILENAME,
|
||||
.arg = G_OPTION_ARG_CALLBACK,
|
||||
.arg_data = cb_set_string_option,
|
||||
.description = _(
|
||||
"FILE contains the key with which you encrypt\n" INDENT
|
||||
"the PV guest dump (optional). Required by\n" INDENT
|
||||
"the '--enable-dump' option."),
|
||||
"FILE contains the customer communication key\n" INDENT
|
||||
"(CCK) (optional)."),
|
||||
.arg_description = _("FILE") },
|
||||
{ .long_name = "crl",
|
||||
.short_name = 0,
|
||||
@@ -450,6 +469,8 @@ gint pv_args_parse_options(PvArgs *args, gint *argc, gchar **argv[],
|
||||
.arg_data = cb_set_string_option,
|
||||
.description = _("Specify the secret control flags\n" INDENT
|
||||
"as a hexadecimal value.\n" INDENT
|
||||
"Optional; mutually exclusive with\n" INDENT
|
||||
"'--(enable|disable)-cck-extension-secret';\n" INDENT
|
||||
"Optional; default: '0x0'."),
|
||||
.arg_description = _("VALUE") },
|
||||
{ 0 },
|
||||
@@ -487,8 +508,10 @@ PvArgs *pv_args_new(void)
|
||||
g_autoptr(PvArgs) args = g_new0(PvArgs, 1);
|
||||
|
||||
args->unused_values = g_ptr_array_new_with_free_func(g_free);
|
||||
args->allow_dump = PV_NOT_SET;
|
||||
args->allow_pckmo = PV_NOT_SET;
|
||||
/* `args->cf_args` is implicitly initialized with zeros since
|
||||
* `g_new0` is used. So there is no reason to explicitly
|
||||
* initialize the values as PV_NOT_SET == 0.
|
||||
*/
|
||||
return g_steal_pointer(&args);
|
||||
}
|
||||
|
||||
@@ -497,8 +520,8 @@ void pv_args_free(PvArgs *args)
|
||||
if (!args)
|
||||
return;
|
||||
|
||||
g_free(args->pcf);
|
||||
g_free(args->scf);
|
||||
g_free(args->cf_args.pcf);
|
||||
g_free(args->cf_args.scf);
|
||||
g_free(args->psw_addr);
|
||||
g_free(args->cust_root_key_path);
|
||||
g_free(args->cust_comm_key_path);
|
||||
|
||||
@@ -23,19 +23,27 @@ PvArg *pv_arg_new(PvComponentType type, const gchar *path);
|
||||
void pv_arg_free(PvArg *arg);
|
||||
|
||||
typedef enum pv_tristate {
|
||||
PV_NOT_SET = 0,
|
||||
PV_TRUE,
|
||||
PV_FALSE,
|
||||
PV_NOT_SET = 0,
|
||||
PV_TRUE,
|
||||
PV_FALSE,
|
||||
} PvTristate;
|
||||
/* The value of PV_NOT_SET is not allowed to be changed */
|
||||
STATIC_ASSERT(PV_NOT_SET == 0)
|
||||
|
||||
typedef struct {
|
||||
gchar *pcf;
|
||||
gchar *scf;
|
||||
/* Add-secret requests do require CCK-extension secrets */
|
||||
PvTristate enable_cck_extension_secret_enforcement;
|
||||
PvTristate enable_dump;
|
||||
PvTristate enable_pckmo;
|
||||
} PvControlFlagsArgs;
|
||||
|
||||
typedef struct {
|
||||
gint log_level;
|
||||
gint no_verify;
|
||||
gboolean offline;
|
||||
gchar *pcf;
|
||||
gchar *scf;
|
||||
PvTristate allow_dump;
|
||||
PvTristate allow_pckmo;
|
||||
PvControlFlagsArgs cf_args;
|
||||
gchar *psw_addr; /* PSW address which will be used for the start of
|
||||
* the actual component (e.g. Linux kernel)
|
||||
*/
|
||||
|
||||
@@ -228,37 +228,40 @@ static gint pv_img_set_psw_addr(PvImage *img, const gchar *psw_addr_s,
|
||||
return 0;
|
||||
}
|
||||
|
||||
static gint pv_img_set_control_flags(PvImage *img, const gchar *pcf_s,
|
||||
const gchar *scf_s,
|
||||
PvTristate allow_dump,
|
||||
PvTristate allow_pckmo, GError **err)
|
||||
static void pv_img_set_control_flag(uint64_t *flags, const PvTristate option, const uint64_t flag)
|
||||
{
|
||||
if (option == PV_TRUE)
|
||||
*flags |= flag;
|
||||
else if (option == PV_FALSE)
|
||||
*flags &= ~flag;
|
||||
}
|
||||
|
||||
static gint pv_img_set_control_flags(PvImage *img, const PvControlFlagsArgs *cf_args, GError **err)
|
||||
{
|
||||
uint64_t flags;
|
||||
|
||||
if (pcf_s) {
|
||||
if (hex_str_toull(pcf_s, &flags, err) < 0)
|
||||
/* Set plain control flags */
|
||||
if (cf_args->pcf) {
|
||||
if (hex_str_toull(cf_args->pcf, &flags, err) < 0)
|
||||
return -1;
|
||||
|
||||
img->pcf = flags;
|
||||
}
|
||||
|
||||
if (scf_s) {
|
||||
if (hex_str_toull(scf_s, &flags, err) < 0)
|
||||
pv_img_set_control_flag(&img->pcf, cf_args->enable_dump, PV_PCF_ALLOW_DUMPING);
|
||||
pv_img_set_control_flag(&img->pcf, cf_args->enable_pckmo,
|
||||
PV_PCF_PCKM_ECC | PV_PCF_PCKMO_AES | PV_PCF_PCKMO_DEA_TDEA);
|
||||
|
||||
/* Set secret control flags */
|
||||
if (cf_args->scf) {
|
||||
if (hex_str_toull(cf_args->scf, &flags, err) < 0)
|
||||
return -1;
|
||||
|
||||
img->scf = flags;
|
||||
}
|
||||
|
||||
if (allow_dump == PV_TRUE)
|
||||
img->pcf |= PV_PCF_ALLOW_DUMPING;
|
||||
else if (allow_dump == PV_FALSE)
|
||||
img->pcf &= ~PV_PCF_ALLOW_DUMPING;
|
||||
|
||||
if (allow_pckmo == PV_TRUE)
|
||||
img->pcf |= PV_PCF_PCKM_ECC | PV_PCF_PCKMO_AES | PV_PCF_PCKMO_DEA_TDEA;
|
||||
else if (allow_pckmo == PV_FALSE)
|
||||
img->pcf &= ~(PV_PCF_PCKM_ECC | PV_PCF_PCKMO_AES | PV_PCF_PCKMO_DEA_TDEA);
|
||||
|
||||
pv_img_set_control_flag(&img->scf, cf_args->enable_cck_extension_secret_enforcement,
|
||||
PV_SCF_CCK_EXTENSION_SECRET_ENFORCMENT);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -610,9 +613,7 @@ PvImage *pv_img_new(PvArgs *args, const gchar *stage3a_path, GError **err)
|
||||
return NULL;
|
||||
|
||||
/* set the control flags: PCF and SCF */
|
||||
if (pv_img_set_control_flags(ret, args->pcf, args->scf,
|
||||
args->allow_dump, args->allow_pckmo,
|
||||
err) < 0)
|
||||
if (pv_img_set_control_flags(ret, &args->cf_args, err) < 0)
|
||||
return NULL;
|
||||
|
||||
/* read in the keys */
|
||||
@@ -683,7 +684,26 @@ gint pv_img_add_component(PvImage *img, const PvArg *arg, GError **err)
|
||||
{
|
||||
g_autoptr(PvComponent) comp = NULL;
|
||||
|
||||
comp = pv_component_new_file(arg->type, arg->path, err);
|
||||
switch (arg->type) {
|
||||
case PV_COMP_TYPE_INITRD:
|
||||
case PV_COMP_TYPE_KERNEL:
|
||||
case PV_COMP_TYPE_STAGE3B:
|
||||
comp = pv_component_new_file(arg->type, arg->path, err);
|
||||
break;
|
||||
case PV_COMP_TYPE_CMDLINE: {
|
||||
g_autoptr(PvBuffer) buf = NULL;
|
||||
g_autofree char *data = NULL;
|
||||
gsize length;
|
||||
|
||||
if (!g_file_get_contents(arg->path, &data, &length, err))
|
||||
return -1;
|
||||
|
||||
/* Add one for the null terminator */
|
||||
buf = pv_buffer_take(g_steal_pointer(&data), length + 1);
|
||||
comp = pv_component_new_buf(arg->type, buf, err);
|
||||
} break;
|
||||
}
|
||||
|
||||
if (!comp)
|
||||
return -1;
|
||||
|
||||
|
||||
@@ -59,7 +59,7 @@ static gint pv_ipib_init(IplParameterBlock *ipib, GSList *comps,
|
||||
ipib_size = MAX(ipl_pl_hdr_size + blk0_len, (uint32_t)PAGE_SIZE);
|
||||
g_assert(pv_ipib_get_size(comps_length) == ipib_size);
|
||||
|
||||
pv->pbt = IPL_TYPE_PV;
|
||||
pv->pbt = IPL_PBT_PV;
|
||||
pv->len = GUINT32_TO_BE(blk0_len);
|
||||
pv->num_comp = GUINT32_TO_BE(comps_length);
|
||||
/* both values will be overwritten during the IPL process by
|
||||
|
||||
@@ -26,6 +26,15 @@ PvBuffer *pv_buffer_alloc(gsize size)
|
||||
return ret;
|
||||
}
|
||||
|
||||
PvBuffer *pv_buffer_take(char *data, gsize size)
|
||||
{
|
||||
PvBuffer *ret = g_new0(PvBuffer, 1);
|
||||
|
||||
ret->data = data;
|
||||
ret->size = size;
|
||||
return ret;
|
||||
}
|
||||
|
||||
PvBuffer *pv_buffer_dup(const PvBuffer *buf, gboolean page_aligned)
|
||||
{
|
||||
PvBuffer *ret;
|
||||
|
||||
@@ -21,6 +21,10 @@ typedef struct PvBuffer {
|
||||
} PvBuffer;
|
||||
|
||||
PvBuffer *pv_buffer_alloc(gsize size);
|
||||
/* After this call @data belongs to the PvBuffer and must no longer be modified
|
||||
* by the caller.
|
||||
*/
|
||||
PvBuffer *pv_buffer_take(char *data, gsize size);
|
||||
void pv_buffer_free(PvBuffer *buf);
|
||||
void pv_buffer_clear(PvBuffer **buf);
|
||||
gint pv_buffer_write(const PvBuffer *buf, FILE *file, GError **err);
|
||||
|
||||
@@ -664,62 +664,9 @@ static gboolean x509_name_data_by_nid_equal(X509_NAME *name, gint nid,
|
||||
return memcmp(data, y, data_len) == 0;
|
||||
}
|
||||
|
||||
static gboolean own_X509_NAME_ENTRY_equal(const X509_NAME_ENTRY *x,
|
||||
const X509_NAME_ENTRY *y)
|
||||
{
|
||||
const ASN1_OBJECT *x_obj = X509_NAME_ENTRY_get_object(x);
|
||||
const ASN1_STRING *x_data = X509_NAME_ENTRY_get_data(x);
|
||||
const ASN1_OBJECT *y_obj = X509_NAME_ENTRY_get_object(y);
|
||||
const ASN1_STRING *y_data = X509_NAME_ENTRY_get_data(y);
|
||||
gint x_len = ASN1_STRING_length(x_data);
|
||||
gint y_len = ASN1_STRING_length(y_data);
|
||||
|
||||
if (x_len < 0 || x_len != y_len)
|
||||
return FALSE;
|
||||
|
||||
/* ASN1_STRING_cmp(x_data, y_data) == 0 doesn't work because it also
|
||||
* compares the type, which is sometimes different.
|
||||
*/
|
||||
return OBJ_cmp(x_obj, y_obj) == 0 &&
|
||||
memcmp(ASN1_STRING_get0_data(x_data),
|
||||
ASN1_STRING_get0_data(y_data),
|
||||
(unsigned long)x_len) == 0;
|
||||
}
|
||||
|
||||
static gboolean own_X509_NAME_equal(const X509_NAME *x, const X509_NAME *y)
|
||||
{
|
||||
gint x_count = X509_NAME_entry_count(x);
|
||||
gint y_count = X509_NAME_entry_count(y);
|
||||
|
||||
if (x != y && (!x || !y))
|
||||
return FALSE;
|
||||
|
||||
if (x_count != y_count)
|
||||
return FALSE;
|
||||
|
||||
for (gint i = 0; i < x_count; i++) {
|
||||
const X509_NAME_ENTRY *entry_i = X509_NAME_get_entry(x, i);
|
||||
gboolean entry_found = FALSE;
|
||||
|
||||
for (gint j = 0; j < y_count; j++) {
|
||||
const X509_NAME_ENTRY *entry_j =
|
||||
X509_NAME_get_entry(y, j);
|
||||
|
||||
if (own_X509_NAME_ENTRY_equal(entry_i, entry_j)) {
|
||||
entry_found = TRUE;
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
if (!entry_found)
|
||||
return FALSE;
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
/* Checks whether the subject of @cert is a IBM signing key subject. For this we
|
||||
* must check that the subject is equal to: 'C = US, ST = New York, L =
|
||||
* Poughkeepsie, O = International Business Machines Corporation, CN =
|
||||
* Poughkeepsie or Armonk, O = International Business Machines Corporation, CN =
|
||||
* International Business Machines Corporation' and the organization unit (OUT)
|
||||
* must end with the suffix ' Key Signing Service'.
|
||||
*/
|
||||
@@ -743,8 +690,10 @@ static gboolean has_ibm_signing_subject(X509 *cert)
|
||||
PV_IBM_Z_SUBJECT_STATE))
|
||||
return FALSE;
|
||||
|
||||
if (!x509_name_data_by_nid_equal(subject, NID_localityName,
|
||||
PV_IBM_Z_SUBJECT_LOCALITY_NAME))
|
||||
if (!(x509_name_data_by_nid_equal(subject, NID_localityName,
|
||||
PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE) ||
|
||||
x509_name_data_by_nid_equal(subject, NID_localityName,
|
||||
PV_IBM_Z_SUBJECT_LOCALITY_NAME_ARMONK)))
|
||||
return FALSE;
|
||||
|
||||
if (!x509_name_data_by_nid_equal(subject, NID_organizationName,
|
||||
@@ -806,6 +755,39 @@ static X509_NAME *x509_name_reorder_attributes(const X509_NAME *name, const gint
|
||||
return g_steal_pointer(&ret);
|
||||
}
|
||||
|
||||
/** Replace locality 'Armonk' with 'Pougkeepsie'. If Armonk was not set return
|
||||
* `NULL`.
|
||||
*/
|
||||
static X509_NAME *x509_armonk_locality_fixup(const X509_NAME *name)
|
||||
{
|
||||
g_autoptr(X509_NAME) ret = NULL;
|
||||
int pos;
|
||||
|
||||
/* Check if ``L=Armonk`` */
|
||||
if (!x509_name_data_by_nid_equal((X509_NAME *)name, NID_localityName,
|
||||
PV_IBM_Z_SUBJECT_LOCALITY_NAME_ARMONK))
|
||||
return NULL;
|
||||
|
||||
ret = X509_NAME_dup((X509_NAME *)name);
|
||||
if (!ret)
|
||||
g_abort();
|
||||
|
||||
pos = X509_NAME_get_index_by_NID(ret, NID_localityName, -1);
|
||||
if (pos == -1)
|
||||
return NULL;
|
||||
|
||||
X509_NAME_ENTRY_free(X509_NAME_delete_entry(ret, pos));
|
||||
|
||||
/* Create a new name entry at the same position as before */
|
||||
if (X509_NAME_add_entry_by_NID(
|
||||
ret, NID_localityName, MBSTRING_UTF8,
|
||||
(const unsigned char *)&PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE,
|
||||
sizeof(PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE) - 1, pos, 0) != 1)
|
||||
return NULL;
|
||||
|
||||
return g_steal_pointer(&ret);
|
||||
}
|
||||
|
||||
/* In RFC 5280 the attributes of a (subject/issuer) name is not mandatory
|
||||
* ordered. The problem is that our certificates are not consistent in the order
|
||||
* (see https://tools.ietf.org/html/rfc5280#section-4.1.2.4 for details).
|
||||
@@ -828,24 +810,10 @@ X509_NAME *c2b_name(const X509_NAME *name)
|
||||
return X509_NAME_dup((X509_NAME *)name);
|
||||
}
|
||||
|
||||
/* Verify that: subject(issuer) == issuer(crl) and SKID(issuer) == AKID(crl) */
|
||||
/* Verify that SKID(issuer) == AKID(crl) if available */
|
||||
static gint check_crl_issuer(X509_CRL *crl, X509 *issuer, GError **err)
|
||||
{
|
||||
const X509_NAME *crl_issuer = X509_CRL_get_issuer(crl);
|
||||
const X509_NAME *issuer_subject = X509_get_subject_name(issuer);
|
||||
AUTHORITY_KEYID *akid = NULL;
|
||||
|
||||
if (!own_X509_NAME_equal(issuer_subject, crl_issuer)) {
|
||||
g_autofree char *issuer_subject_str = X509_NAME_oneline(issuer_subject,
|
||||
NULL, 0);
|
||||
g_autofree char *crl_issuer_str = X509_NAME_oneline(crl_issuer, NULL, 0);
|
||||
|
||||
g_set_error(err, PV_CRYPTO_ERROR,
|
||||
PV_CRYPTO_ERROR_CRL_SUBJECT_ISSUER_MISMATCH,
|
||||
_("issuer mismatch:\n%s\n%s"),
|
||||
issuer_subject_str, crl_issuer_str);
|
||||
return -1;
|
||||
}
|
||||
g_autoptr(AUTHORITY_KEYID) akid = NULL;
|
||||
|
||||
/* If AKID(@crl) is specified it must match with SKID(@issuer) */
|
||||
akid = X509_CRL_get_ext_d2i(crl, NID_authority_key_identifier, NULL, NULL);
|
||||
@@ -881,7 +849,6 @@ gint check_crl_valid_for_cert(X509_CRL *crl, X509 *cert,
|
||||
return -1;
|
||||
}
|
||||
|
||||
/* check that the @crl issuer matches with the subject name of @cert*/
|
||||
if (check_crl_issuer(crl, cert, err) < 0)
|
||||
return -1;
|
||||
|
||||
@@ -910,6 +877,60 @@ gint check_crl_valid_for_cert(X509_CRL *crl, X509 *cert,
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* This function contains work-arounds for some known subject(CRT)<->issuer(CRL)
|
||||
* issues.
|
||||
*/
|
||||
static STACK_OF_X509_CRL *quirk_X509_STORE_ctx_get1_crls(X509_STORE_CTX *ctx,
|
||||
const X509_NAME *subject, GError **err)
|
||||
{
|
||||
g_autoptr(X509_NAME) fixed_subject = NULL;
|
||||
g_autoptr(STACK_OF_X509_CRL) ret = NULL;
|
||||
|
||||
ret = Pv_X509_STORE_CTX_get1_crls(ctx, subject);
|
||||
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||
return g_steal_pointer(&ret);
|
||||
|
||||
/* Workaround to fix the mismatch between issuer name of the * IBM
|
||||
* signing CRLs and the IBM signing key subject name. Locality name has
|
||||
* changed from Poughkeepsie to Armonk.
|
||||
*/
|
||||
fixed_subject = x509_armonk_locality_fixup(subject);
|
||||
/* Was the locality replaced? */
|
||||
if (fixed_subject) {
|
||||
X509_NAME *tmp;
|
||||
|
||||
sk_X509_CRL_free(ret);
|
||||
ret = Pv_X509_STORE_CTX_get1_crls(ctx, fixed_subject);
|
||||
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||
return g_steal_pointer(&ret);
|
||||
|
||||
/* Workaround to fix the ordering mismatch between issuer name
|
||||
* of the IBM signing CRLs and the IBM signing key subject name.
|
||||
*/
|
||||
tmp = fixed_subject;
|
||||
fixed_subject = c2b_name(fixed_subject);
|
||||
X509_NAME_free(tmp);
|
||||
sk_X509_CRL_free(ret);
|
||||
ret = Pv_X509_STORE_CTX_get1_crls(ctx, fixed_subject);
|
||||
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||
return g_steal_pointer(&ret);
|
||||
X509_NAME_free(fixed_subject);
|
||||
fixed_subject = NULL;
|
||||
}
|
||||
|
||||
/* Workaround to fix the ordering mismatch between issuer name of the
|
||||
* IBM signing CRLs and the IBM signing key subject name.
|
||||
*/
|
||||
fixed_subject = c2b_name(subject);
|
||||
sk_X509_CRL_free(ret);
|
||||
ret = Pv_X509_STORE_CTX_get1_crls(ctx, fixed_subject);
|
||||
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||
return g_steal_pointer(&ret);
|
||||
|
||||
g_set_error(err, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_NO_CRL, _("no CRL found"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/* Given a certificate @cert try to find valid revocation lists in @ctx. If no
|
||||
* valid CRL was found NULL is returned.
|
||||
*/
|
||||
@@ -927,20 +948,9 @@ STACK_OF_X509_CRL *store_ctx_find_valid_crls(X509_STORE_CTX *ctx, X509 *cert,
|
||||
return NULL;
|
||||
}
|
||||
|
||||
ret = X509_STORE_CTX_get1_crls(ctx, subject);
|
||||
if (!ret) {
|
||||
/* Workaround to fix the mismatch between issuer name of the
|
||||
* IBM Z signing CRLs and the IBM Z signing key subject name.
|
||||
*/
|
||||
g_autoptr(X509_NAME) broken_subject = c2b_name(subject);
|
||||
|
||||
ret = X509_STORE_CTX_get1_crls(ctx, broken_subject);
|
||||
if (!ret) {
|
||||
g_set_error(err, PV_CRYPTO_ERROR, PV_CRYPTO_ERROR_NO_CRL,
|
||||
_("no CRL found"));
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
ret = quirk_X509_STORE_ctx_get1_crls(ctx, subject, err);
|
||||
if (!ret)
|
||||
return NULL;
|
||||
|
||||
/* Filter out non-valid CRLs for @cert */
|
||||
for (gint i = 0; i < sk_X509_CRL_num(ret); i++) {
|
||||
@@ -1328,32 +1338,14 @@ gint check_chain_parameters(const STACK_OF_X509 *chain,
|
||||
|
||||
/* It's almost the same as X509_check_issed from OpenSSL does except that we
|
||||
* don't check the key usage of the potential issuer. This means we check:
|
||||
* 1. issuer_name(cert) == subject_name(issuer)
|
||||
* 2. Check whether the akid(cert) (if available) matches the issuer skid
|
||||
* 3. Check that the cert algrithm matches the subject algorithm
|
||||
* 4. Verify the signature of certificate @cert is using the public key of
|
||||
* 1. Check whether the akid(cert) (if available) matches the issuer skid
|
||||
* 2. Check that the cert algrithm matches the subject algorithm
|
||||
* 3. Verify the signature of certificate @cert is using the public key of
|
||||
* @issuer.
|
||||
*/
|
||||
static gint check_host_key_issued(X509 *cert, X509 *issuer, GError **err)
|
||||
{
|
||||
const X509_NAME *issuer_subject = X509_get_subject_name(issuer);
|
||||
const X509_NAME *cert_issuer = X509_get_issuer_name(cert);
|
||||
AUTHORITY_KEYID *akid = NULL;
|
||||
|
||||
/* We cannot use X509_NAME_cmp() because it considers the order of the
|
||||
* X509_NAME_Entries.
|
||||
*/
|
||||
if (!own_X509_NAME_equal(issuer_subject, cert_issuer)) {
|
||||
g_autofree char *issuer_subject_str =
|
||||
X509_NAME_oneline(issuer_subject, NULL, 0);
|
||||
g_autofree char *cert_issuer_str =
|
||||
X509_NAME_oneline(cert_issuer, NULL, 0);
|
||||
g_set_error(err, PV_CRYPTO_ERROR,
|
||||
PV_CRYPTO_ERROR_CERT_SUBJECT_ISSUER_MISMATCH,
|
||||
_("Subject issuer mismatch:\n'%s'\n'%s'"),
|
||||
issuer_subject_str, cert_issuer_str);
|
||||
return -1;
|
||||
}
|
||||
g_autoptr(AUTHORITY_KEYID) akid = NULL;
|
||||
|
||||
akid = X509_get_ext_d2i(cert, NID_authority_key_identifier, NULL, NULL);
|
||||
if (akid && X509_check_akid(issuer, akid) != X509_V_OK) {
|
||||
@@ -1834,14 +1826,12 @@ static gint __encrypt_decrypt_bio(const struct cipher_parms *parms, BIO *b_in,
|
||||
g_assert(out_len >= 0);
|
||||
|
||||
num_bytes_written = BIO_write(b_out, out_buf, out_len);
|
||||
if (num_bytes_written < 0) {
|
||||
if (num_bytes_written != out_len) {
|
||||
g_set_error(err, PV_CRYPTO_ERROR,
|
||||
PV_CRYPTO_ERROR_INTERNAL,
|
||||
_("Failed to write"));
|
||||
return -1;
|
||||
}
|
||||
g_assert(num_bytes_written == out_len);
|
||||
|
||||
tmp_size_out += (guint)num_bytes_written;
|
||||
|
||||
/* Set new tweak value. Please keep in mind that the
|
||||
|
||||
@@ -75,6 +75,7 @@ void x509_pair_free(x509_pair *pair);
|
||||
/* Register auto cleanup functions */
|
||||
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(ASN1_INTEGER, ASN1_INTEGER_free)
|
||||
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(ASN1_OCTET_STRING, ASN1_OCTET_STRING_free)
|
||||
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(AUTHORITY_KEYID, AUTHORITY_KEYID_free)
|
||||
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(BIGNUM, BN_free)
|
||||
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(BIO, BIO_free_all)
|
||||
WRAPPED_G_DEFINE_AUTOPTR_CLEANUP_FUNC(BN_CTX, BN_CTX_free)
|
||||
|
||||
@@ -116,6 +116,7 @@ static void l_sd_cpu_fill(struct sd_cpu *cpu, struct l_x_cpu_info *cpu_info,
|
||||
int threads)
|
||||
{
|
||||
sd_cpu_cpu_time_us_set(cpu, cpu_info->lp_time);
|
||||
sd_cpu_threads_per_core_set(cpu, threads);
|
||||
if (threads > 1)
|
||||
sd_cpu_thread_time_us_set(cpu,
|
||||
cpu_info->lp_time * threads - cpu_info->mt_idle_time);
|
||||
@@ -297,6 +298,7 @@ static struct sd_sys_item *l_sys_item_vec[] = {
|
||||
&sd_sys_item_thread_cnt,
|
||||
&sd_sys_item_core_diff,
|
||||
&sd_sys_item_thread_diff,
|
||||
&sd_sys_item_smt_diff,
|
||||
&sd_sys_item_mgm_diff,
|
||||
&sd_sys_item_core,
|
||||
&sd_sys_item_thread,
|
||||
@@ -326,6 +328,7 @@ static struct sd_cpu_item *l_cpu_item_vec[] = {
|
||||
&sd_cpu_item_type,
|
||||
&sd_cpu_item_core_diff,
|
||||
&sd_cpu_item_thread_diff,
|
||||
&sd_cpu_item_smt_diff,
|
||||
&sd_cpu_item_mgm_diff,
|
||||
&sd_cpu_item_core,
|
||||
&sd_cpu_item_thread,
|
||||
|
||||
@@ -391,3 +391,24 @@ void hyptop_helper_init(void)
|
||||
if (l_iconv_ebcdic_ascii == (iconv_t) -1)
|
||||
ERR_EXIT("Could not initialize iconv\n");
|
||||
}
|
||||
|
||||
/*
|
||||
* Calculate real SMT utilization
|
||||
* @core_us: core utilization in us
|
||||
* @thr_us: thread utilization in us
|
||||
* @mgm_us: management utilization in us
|
||||
* @thread_per_core: SMT thread count per core
|
||||
*/
|
||||
s64 ht_calculate_smt_util(u64 core_us, u64 thr_us, u64 mgm_us, int thread_per_core)
|
||||
{
|
||||
s64 component1, component2, smt_us;
|
||||
double smt_factor = g.o.smt_factor;
|
||||
|
||||
component1 = thread_per_core * core_us - thr_us;
|
||||
if (thread_per_core > 1)
|
||||
component1 /= smt_factor;
|
||||
component2 = thr_us - core_us;
|
||||
smt_us = G0(component1 + component2 + mgm_us);
|
||||
|
||||
return smt_us;
|
||||
}
|
||||
|
||||
@@ -34,6 +34,7 @@ extern void ht_ebcdic_to_ascii(char *in, char *out, size_t len);
|
||||
extern char *ht_mount_point_get(const char *fs_type);
|
||||
extern u64 ht_ext_tod_2_us(void *tod_ext);
|
||||
extern void ht_print_time(void);
|
||||
extern s64 ht_calculate_smt_util(u64 core_us, u64 thr_us, u64 mgm_us, int thread_per_core);
|
||||
|
||||
/*
|
||||
* Memory alloc functions
|
||||
|
||||
@@ -74,6 +74,18 @@ In this mode no user input is accepted.
|
||||
.BR "\-d <SECONDS>" " or " "\-\-delay=<SECONDS>"
|
||||
Specifies the delay between screen updates.
|
||||
.TP
|
||||
.BR "\-m <FACTOR>" " or " "\-\-smt_factor=<FACTOR>"
|
||||
Specifies a workload dependent SMT speedup factor.
|
||||
For IBM z15 servers, the default value is 1.3. If the workload benefits
|
||||
from SMT, you can specify a higher value. If the workload does not benefit
|
||||
from SMT, specifying lower values results in more accurate reports of
|
||||
real CPU SMT utilization field for LPARs. There is no hard boundary except
|
||||
that it must be a positive value. Example ranges to select a sensible value
|
||||
from:
|
||||
|
||||
For IBM z13: [0.8, 1.3]
|
||||
For IBM z15: [1.1, 1.5]
|
||||
.TP
|
||||
.BR "\-n <ITERATIONS>" " or " "\-\-iterations=<ITERATIONS>"
|
||||
Specifies the maximum number of iterations before ending.
|
||||
|
||||
@@ -119,6 +131,7 @@ The following fields are available under LPAR:
|
||||
In "sys_list" and "sys" window:
|
||||
'c' - Core dispatch time per second
|
||||
'e' - Thread time per second
|
||||
'S' - Real CPU SMT utilization
|
||||
'm' - Management time per second
|
||||
'C' - Total core dispatch time
|
||||
'E' - Total thread time
|
||||
|
||||
@@ -22,6 +22,7 @@
|
||||
#include "table.h"
|
||||
|
||||
#define HYPTOP_OPT_DEFAULT_DELAY 2
|
||||
#define HYPTOP_OPT_DEFAULT_SMT_SCALE 1.3
|
||||
#define HYPTOP_MAX_WIN_DEPTH 4
|
||||
#define HYPTOP_MAX_LINE 512
|
||||
#define PROG_NAME "hyptop"
|
||||
@@ -60,6 +61,8 @@ struct hyptop_opts {
|
||||
|
||||
int delay_s;
|
||||
int delay_us;
|
||||
|
||||
double smt_factor;
|
||||
};
|
||||
|
||||
/*
|
||||
|
||||
@@ -39,6 +39,7 @@ static char HELP_TEXT[] =
|
||||
"-t, --cpu_types TYPE[,..] CPU types used for time calculations\n"
|
||||
"-b, --batch_mode Use batch mode (no curses)\n"
|
||||
"-d, --delay SECONDS Delay time between screen updates\n"
|
||||
"-m, --smt_factor FACTOR Machine generation dependent SMT speedup factor.\n"
|
||||
"-n, --iterations NUMBER Number of iterations before ending\n";
|
||||
|
||||
/*
|
||||
@@ -48,6 +49,7 @@ static void l_init_defaults(void)
|
||||
{
|
||||
g.prog_name = PROG_NAME;
|
||||
g.o.delay_s = HYPTOP_OPT_DEFAULT_DELAY;
|
||||
g.o.smt_factor = HYPTOP_OPT_DEFAULT_SMT_SCALE;
|
||||
g.w.cur = &win_sys_list;
|
||||
g.o.cur_win = &win_sys_list;
|
||||
}
|
||||
@@ -108,6 +110,20 @@ static void l_delay_set(char *delay_string)
|
||||
g.o.delay_us = 0;
|
||||
}
|
||||
|
||||
/*
|
||||
* Set SMT factor option
|
||||
*/
|
||||
static void l_factor_set(char *value_string)
|
||||
{
|
||||
double factor;
|
||||
|
||||
if (sscanf(value_string, "%lf", &factor) != 1)
|
||||
ERR_EXIT("The SMT factor \"%s\" is invalid\n", value_string);
|
||||
if (factor <= 0)
|
||||
ERR_EXIT("The SMT factor \"%s\" is <= 0\n", value_string);
|
||||
g.o.smt_factor = factor;
|
||||
}
|
||||
|
||||
/*
|
||||
* Get number of occurrences of character 'c' in "str"
|
||||
*/
|
||||
@@ -299,6 +315,7 @@ void opts_parse(int argc, char *argv[])
|
||||
{ "help", no_argument, NULL, 'h'},
|
||||
{ "batch_mode", no_argument, NULL, 'b'},
|
||||
{ "delay", required_argument, NULL, 'd'},
|
||||
{ "smt_factor", required_argument, NULL, 'm'},
|
||||
{ "window", required_argument, NULL, 'w'},
|
||||
{ "sys", required_argument, NULL, 's'},
|
||||
{ "iterations", required_argument, NULL, 'n'},
|
||||
@@ -307,7 +324,7 @@ void opts_parse(int argc, char *argv[])
|
||||
{ "cpu_types", required_argument, NULL, 't'},
|
||||
{ NULL, 0, NULL, 0 }
|
||||
};
|
||||
static const char option_string[] = "vhbd:w:s:n:f:t:S:";
|
||||
static const char option_string[] = "vhbd:m:w:s:n:f:t:S:";
|
||||
|
||||
l_init_defaults();
|
||||
while (1) {
|
||||
@@ -328,6 +345,9 @@ void opts_parse(int argc, char *argv[])
|
||||
case 'd':
|
||||
l_delay_set(optarg);
|
||||
break;
|
||||
case 'm':
|
||||
l_factor_set(optarg);
|
||||
break;
|
||||
case 'w':
|
||||
l_window_set(optarg);
|
||||
break;
|
||||
|
||||
@@ -200,6 +200,7 @@ struct sd_cpu {
|
||||
struct sd_cpu_info *d_cur;
|
||||
struct sd_cpu_info *d_prev;
|
||||
u16 cnt;
|
||||
int threads_per_core;
|
||||
enum sd_cpu_state state;
|
||||
};
|
||||
|
||||
@@ -232,6 +233,11 @@ static inline void sd_cpu_cpu_time_us_set(struct sd_cpu *cpu, u64 value)
|
||||
cpu->d_cur->cpu_time_us = value;
|
||||
}
|
||||
|
||||
static inline void sd_cpu_threads_per_core_set(struct sd_cpu *cpu, int value)
|
||||
{
|
||||
cpu->threads_per_core = value;
|
||||
}
|
||||
|
||||
static inline void sd_cpu_thread_time_us_set(struct sd_cpu *cpu, u64 value)
|
||||
{
|
||||
cpu->d_cur->thread_time_us = value;
|
||||
@@ -335,6 +341,7 @@ extern struct sd_cpu_item sd_cpu_item_state;
|
||||
extern struct sd_cpu_item sd_cpu_item_cpu_diff;
|
||||
extern struct sd_cpu_item sd_cpu_item_core_diff;
|
||||
extern struct sd_cpu_item sd_cpu_item_thread_diff;
|
||||
extern struct sd_cpu_item sd_cpu_item_smt_diff;
|
||||
extern struct sd_cpu_item sd_cpu_item_mgm_diff;
|
||||
extern struct sd_cpu_item sd_cpu_item_wait_diff;
|
||||
extern struct sd_cpu_item sd_cpu_item_steal_diff;
|
||||
@@ -398,6 +405,7 @@ static inline char *sd_sys_item_str(struct sd_sys *sys,
|
||||
extern struct sd_sys_item sd_sys_item_cpu_cnt;
|
||||
extern struct sd_sys_item sd_sys_item_core_cnt;
|
||||
extern struct sd_sys_item sd_sys_item_thread_cnt;
|
||||
extern struct sd_sys_item sd_sys_item_smt_diff;
|
||||
extern struct sd_sys_item sd_sys_item_cpu_oper_cnt;
|
||||
extern struct sd_sys_item sd_sys_item_cpu_deconf_cnt;
|
||||
extern struct sd_sys_item sd_sys_item_cpu_stop_cnt;
|
||||
|
||||
@@ -98,6 +98,18 @@ static u64 l_cpu_item_64(struct sd_cpu_item *item, struct sd_cpu *cpu)
|
||||
return l_cpu_info_u64(cpu->d_cur, item->offset) / cpu->cnt;
|
||||
}
|
||||
|
||||
static u64 l_cpu_smt_util(struct sd_cpu_item *item, struct sd_cpu *cpu)
|
||||
{
|
||||
u64 core_us, thr_us, mgm_us;
|
||||
(void)item;
|
||||
|
||||
core_us = sd_cpu_item_u64(&sd_cpu_item_core_diff, cpu);
|
||||
thr_us = sd_cpu_item_u64(&sd_cpu_item_thread_diff, cpu);
|
||||
mgm_us = sd_cpu_item_u64(&sd_cpu_item_mgm_diff, cpu);
|
||||
|
||||
return ht_calculate_smt_util(core_us, thr_us, mgm_us, cpu->threads_per_core);
|
||||
}
|
||||
|
||||
/*
|
||||
* CPU item definitions
|
||||
*/
|
||||
@@ -139,6 +151,13 @@ struct sd_cpu_item sd_cpu_item_thread_diff = {
|
||||
.fn_u64 = l_cpu_diff_u64,
|
||||
};
|
||||
|
||||
struct sd_cpu_item sd_cpu_item_smt_diff = {
|
||||
.table_col = TABLE_COL_TIME_DIFF_SUM(table_col_unit_perc, 'S', "smt"),
|
||||
.type = SD_TYPE_U64,
|
||||
.desc = "Real CPU SMT utilization",
|
||||
.fn_u64 = l_cpu_smt_util,
|
||||
};
|
||||
|
||||
struct sd_cpu_item sd_cpu_item_mgm_diff = {
|
||||
.table_col = TABLE_COL_TIME_DIFF_SUM(table_col_unit_perc, 'm', "mgm"),
|
||||
.type = SD_TYPE_U64,
|
||||
|
||||
@@ -208,6 +208,18 @@ static s64 l_sys_cpu_info_diff_s64(struct sd_sys_item *item, struct sd_sys *sys)
|
||||
return rc;
|
||||
}
|
||||
|
||||
static u64 l_sys_smt_util(struct sd_sys_item *item, struct sd_sys *sys)
|
||||
{
|
||||
u64 core_us, thr_us, mgm_us;
|
||||
(void)item;
|
||||
|
||||
core_us = sd_sys_item_u64(sys, &sd_sys_item_core_diff);
|
||||
thr_us = sd_sys_item_u64(sys, &sd_sys_item_thread_diff);
|
||||
mgm_us = sd_sys_item_u64(sys, &sd_sys_item_mgm_diff);
|
||||
|
||||
return ht_calculate_smt_util(core_us, thr_us, mgm_us, sys->threads_per_core);
|
||||
}
|
||||
|
||||
/*
|
||||
* System item definitions
|
||||
*/
|
||||
@@ -277,6 +289,13 @@ struct sd_sys_item sd_sys_item_thread_diff = {
|
||||
.fn_u64 = l_sys_cpu_info_diff_u64,
|
||||
};
|
||||
|
||||
struct sd_sys_item sd_sys_item_smt_diff = {
|
||||
.table_col = TABLE_COL_TIME_DIFF_SUM(table_col_unit_perc, 'S', "smt"),
|
||||
.type = SD_TYPE_U64,
|
||||
.desc = "Real CPU SMT utilization",
|
||||
.fn_u64 = l_sys_smt_util,
|
||||
};
|
||||
|
||||
struct sd_sys_item sd_sys_item_mgm_diff = {
|
||||
.table_col = TABLE_COL_TIME_DIFF_SUM(table_col_unit_perc, 'm', "mgm"),
|
||||
.offset = SD_CPU_INFO_OFFSET(mgm_time_us),
|
||||
|
||||
@@ -34,10 +34,10 @@
|
||||
/* Secure IPL error */
|
||||
#define ESECUREBOOT 0x00004512
|
||||
|
||||
/* kdump: No operating system information was found */
|
||||
/* os_info error: No operating system information was found */
|
||||
#define EOS_INFO_MISSING 0x00004520
|
||||
|
||||
/* kdump: The checksum of the operating system information is incorrect */
|
||||
/* os_info error: The checksum of the operating system information is incorrect */
|
||||
#define EOS_INFO_CSUM_FAILED 0x00004521
|
||||
|
||||
/* kdump: The major version of the operating system information is too high */
|
||||
@@ -21,10 +21,6 @@
|
||||
#define IPL_MAX_SUPPORTED_VERSION 0
|
||||
#define IPL_PARM_BLOCK_VERSION 0x1
|
||||
|
||||
/* IPL Types */
|
||||
#define IPL_TYPE_PV 0x5
|
||||
|
||||
|
||||
#ifndef __ASSEMBLER__
|
||||
|
||||
#include <stdint.h>
|
||||
@@ -43,6 +39,16 @@ struct ipl_pb_hdr {
|
||||
uint8_t pbt;
|
||||
} __packed;
|
||||
|
||||
/* IPL Parameter Block types */
|
||||
enum ipl_pbt {
|
||||
IPL_PBT_FCP = 0,
|
||||
IPL_PBT_SCP_DATA = 1,
|
||||
IPL_PBT_CCW = 2,
|
||||
IPL_PBT_ECKD = 3,
|
||||
IPL_PBT_NVME = 4,
|
||||
IPL_PBT_PV = 5,
|
||||
};
|
||||
|
||||
/* IPL Parameter Block 0 with common fields */
|
||||
struct ipl_pb0_common {
|
||||
uint32_t len;
|
||||
|
||||
@@ -22,11 +22,19 @@
|
||||
#define STAGE2_DESC _AC(0x78, UL)
|
||||
#define STAGE2_ENTRY _AC(0x2018, UL)
|
||||
#define STAGE2_HEAP_ADDRESS _AC(0x6000, UL)
|
||||
#define ECKD2DUMP_SV_HEAP_ADDRESS _AC(0xb000, UL)
|
||||
#define STAGE2_HEAP_SIZE _AC(0x3000, UL)
|
||||
#define STAGE2_STACK_ADDRESS _AC(0xe400, UL)
|
||||
#define STAGE2_STACK_SIZE _AC(0x1c00, UL)
|
||||
#define ECKD2DUMP_SV_STACK_ADDRESS _AC(0xe000, UL)
|
||||
#define ECKD2DUMP_SV_STACK_SIZE _AC(0x2000, UL)
|
||||
#define STAGE2_MAX_SIZE _AC(0x3000, UL)
|
||||
|
||||
#define STAGE2_DUMPER_SIZE_V1 _AC(0x1000, UL)
|
||||
#define STAGE2_DUMPER_SIZE_V2 _AC(0x2000, UL)
|
||||
#define STAGE2_DUMPER_SIZE_V3 _AC(0x3000, UL)
|
||||
#define STAGE2_DUMPER_SIZE_ZLIB _AC(0x8000, UL)
|
||||
|
||||
#define STAGE3_ENTRY _AC(0xa000, UL)
|
||||
|
||||
#define STAGE2_LOAD_ADDRESS _AC(0x2000, UL)
|
||||
|
||||
78
include/boot/os_info.h
Normal file
78
include/boot/os_info.h
Normal file
@@ -0,0 +1,78 @@
|
||||
/*
|
||||
* zipl - zSeries Initial Program Loader tool
|
||||
*
|
||||
* os-info definitions
|
||||
*
|
||||
* Copyright IBM Corp. 2013, 2023
|
||||
*
|
||||
* s390-tools is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the MIT license. See LICENSE for details.
|
||||
*/
|
||||
|
||||
#ifndef OS_INFO_H
|
||||
#define OS_INFO_H
|
||||
|
||||
#include "lib/zt_common.h"
|
||||
#include "boot/error.h"
|
||||
#include "boot/s390.h"
|
||||
#include <stdint.h>
|
||||
|
||||
#define OS_INFO_MAGIC 0x4f53494e464f535aULL /* OSINFOSZ */
|
||||
#define OS_INFO_CSUM_SIZE (sizeof(struct os_info) - offsetof(struct os_info, version_major))
|
||||
#define OS_INFO_FLAGS_ENTRY_SIZE (sizeof(unsigned long))
|
||||
|
||||
#define OS_INFO_VMCOREINFO 0
|
||||
#define OS_INFO_REIPL_BLOCK 1
|
||||
#define OS_INFO_FLAGS_ENTRY 2
|
||||
|
||||
#define OS_INFO_FLAG_REIPL_CLEAR (1UL << 0)
|
||||
|
||||
struct os_info_entry {
|
||||
uint64_t addr;
|
||||
uint64_t size;
|
||||
uint32_t csum;
|
||||
} __packed;
|
||||
|
||||
struct os_info {
|
||||
uint64_t magic;
|
||||
uint32_t csum;
|
||||
uint16_t version_major;
|
||||
uint16_t version_minor;
|
||||
uint64_t crashkernel_addr;
|
||||
uint64_t crashkernel_size;
|
||||
struct os_info_entry entry[3];
|
||||
uint8_t reserved[4004];
|
||||
} __packed;
|
||||
|
||||
/*
|
||||
* Return 0 in case of valid os_info
|
||||
* Return -EOS_INFO_MISSING if os_info address is not page aligned or page is
|
||||
* not accessible or os_info magic value is missing.
|
||||
* Return -EOS_INFO_CSUM_FAILED if os_info checksum is invalid.
|
||||
*/
|
||||
static inline int os_info_check(const struct os_info *os_info)
|
||||
{
|
||||
if (!os_info ||
|
||||
(unsigned long)os_info % PAGE_SIZE ||
|
||||
!page_is_valid((unsigned long)os_info) ||
|
||||
os_info->magic != OS_INFO_MAGIC)
|
||||
return -EOS_INFO_MISSING;
|
||||
if (os_info->csum != csum_partial(&os_info->version_major, OS_INFO_CSUM_SIZE, 0))
|
||||
return -EOS_INFO_CSUM_FAILED;
|
||||
return 0;
|
||||
}
|
||||
|
||||
/*
|
||||
* Return 1 in case of valid os_info_entry, otherwise 0
|
||||
* Make sure that the entire os_info structure is checked first with os_info_check().
|
||||
*/
|
||||
static inline int os_info_entry_is_valid(const struct os_info_entry *entry)
|
||||
{
|
||||
return (entry &&
|
||||
entry->addr &&
|
||||
entry->size &&
|
||||
page_is_valid(entry->addr) &&
|
||||
entry->csum == csum_partial((void *)entry->addr, entry->size, 0));
|
||||
}
|
||||
|
||||
#endif /* OS_INFO_H */
|
||||
@@ -25,6 +25,7 @@
|
||||
#define STACK_FRAME_OVERHEAD _AC(160, U)
|
||||
|
||||
/* Facilities */
|
||||
#define DFLTCC_FACILITY _AC(151, U)
|
||||
#define UNPACK_FACILITY _AC(161, U)
|
||||
|
||||
#ifndef __ASSEMBLER__
|
||||
@@ -285,18 +286,21 @@ static __always_inline void __ctl_set_bit(unsigned int cr, unsigned int bit)
|
||||
* DIAG 308 support
|
||||
*/
|
||||
enum diag308_subcode {
|
||||
DIAG308_REL_HSA = 2,
|
||||
DIAG308_IPL = 3,
|
||||
DIAG308_DUMP = 4,
|
||||
DIAG308_SET = 5,
|
||||
DIAG308_STORE = 6,
|
||||
DIAG308_CLEAR_RESET = 0,
|
||||
DIAG308_LOAD_NORMAL_RESET = 1,
|
||||
DIAG308_REL_HSA = 2,
|
||||
DIAG308_LOAD_CLEAR = 3,
|
||||
DIAG308_LOAD_NORMAL_DUMP = 4,
|
||||
DIAG308_SET = 5,
|
||||
DIAG308_STORE = 6,
|
||||
DIAG308_LOAD_NORMAL = 7,
|
||||
DIAG308_SET_PV = 8,
|
||||
DIAG308_UNPACK_PV = 10,
|
||||
};
|
||||
|
||||
enum diag308_rc {
|
||||
DIAG308_RC_OK = 0x0001,
|
||||
DIAG308_RC_NO_CONF = 0x0102,
|
||||
DIAG308_RC_NOCONFIG = 0x0102,
|
||||
};
|
||||
|
||||
static __always_inline unsigned long diag308(unsigned long subcode, void *addr)
|
||||
|
||||
145
include/dump/s390_dump.h
Normal file
145
include/dump/s390_dump.h
Normal file
@@ -0,0 +1,145 @@
|
||||
/*
|
||||
* s390 related definitions and functions.
|
||||
*
|
||||
* Copyright IBM Corp. 2013, 2023
|
||||
*
|
||||
* s390-tools is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the MIT license. See LICENSE for details.
|
||||
*/
|
||||
|
||||
#ifndef S390_DUMP_H
|
||||
#define S390_DUMP_H
|
||||
|
||||
#include <stdint.h>
|
||||
|
||||
#include "boot/page.h"
|
||||
#include "lib/zt_common.h"
|
||||
|
||||
/*
|
||||
* S390 dump format defines
|
||||
*/
|
||||
#define DF_S390_MAGIC 0xa8190173618f23fdULL
|
||||
#define DF_S390_MAGIC_EXT 0xa8190173618f23feULL
|
||||
#define DF_S390_HDR_SIZE 0x1000
|
||||
#define DF_S390_EM_SIZE 16
|
||||
#define DF_S390_EM_MAGIC 0x44554d505f454e44ULL
|
||||
#define DF_S390_EM_STR "DUMP_END"
|
||||
#define DF_S390_CPU_MAX 512
|
||||
#define DF_S390_MAGIC_BLK_ECKD 3
|
||||
#define DF_S390_DUMPER_MAGIC_SIZE 7
|
||||
#define DF_S390_DUMPER_MAGIC32 "ZECKD31"
|
||||
#define DF_S390_DUMPER_MAGIC64 "ZECKD64"
|
||||
#define DF_S390_DUMPER_MAGIC_EXT "XECKD64"
|
||||
#define DF_S390_DUMPER_MAGIC32_FBA "ZDFBA31"
|
||||
#define DF_S390_DUMPER_MAGIC64_FBA "ZDFBA64"
|
||||
#define DF_S390_DUMPER_MAGIC_FBA_EXT "XDFBA64"
|
||||
#define DF_S390_DUMPER_MAGIC_MV "ZMULT64"
|
||||
#define DF_S390_DUMPER_MAGIC_MV_EXT "XMULT64"
|
||||
#define OLD_DUMPER_HEX_INSTR1 "\x0d\x10\x47\xf0" /* BASR + 1st halfword of BC */
|
||||
#define OLD_DUMPER_HEX_INSTR2 "\x0d\xd0" /* BASR 13,0 */
|
||||
|
||||
/*
|
||||
* Architecture of dumped system
|
||||
*/
|
||||
enum df_s390_arch {
|
||||
DF_S390_ARCH_32 = 1,
|
||||
DF_S390_ARCH_64 = 2,
|
||||
};
|
||||
|
||||
/*
|
||||
* zipl parameters passed at tail of dump tools
|
||||
*/
|
||||
struct stage2dump_parm_tail {
|
||||
char reserved[6];
|
||||
uint8_t no_compress;
|
||||
uint8_t mvdump_force;
|
||||
uint64_t mem_upper_limit;
|
||||
} __packed;
|
||||
|
||||
/*
|
||||
* s390 dump header format
|
||||
*/
|
||||
struct df_s390_hdr {
|
||||
uint64_t magic; /* 0x000 */
|
||||
uint32_t version; /* 0x008 */
|
||||
uint32_t hdr_size; /* 0x00c */
|
||||
uint32_t dump_level; /* 0x010 */
|
||||
uint32_t page_size; /* 0x014 */
|
||||
uint64_t mem_size; /* 0x018 */
|
||||
uint64_t mem_start; /* 0x020 */
|
||||
uint64_t mem_end; /* 0x028 */
|
||||
uint32_t num_pages; /* 0x030 */
|
||||
uint32_t pad; /* 0x034 */
|
||||
uint64_t tod; /* 0x038 */
|
||||
uint64_t cpu_id; /* 0x040 */
|
||||
uint32_t arch; /* 0x048 */
|
||||
uint32_t volnr; /* 0x04c */
|
||||
uint32_t build_arch; /* 0x050 */
|
||||
uint64_t mem_size_real; /* 0x054 */
|
||||
uint8_t mvdump; /* 0x05c */
|
||||
uint16_t cpu_cnt; /* 0x05d */
|
||||
uint16_t real_cpu_cnt; /* 0x05f */
|
||||
uint8_t zlib_version_s390; /* 0x061 */
|
||||
uint32_t zlib_entry_size; /* 0x062 */
|
||||
uint8_t end_pad1[0x200 - 0x066]; /* 0x066 */
|
||||
uint64_t mvdump_sign; /* 0x200 */
|
||||
uint64_t mvdump_zipl_time; /* 0x208 */
|
||||
uint8_t end_pad2[0x800 - 0x210]; /* 0x210 */
|
||||
uint32_t lc_vec[DF_S390_CPU_MAX]; /* 0x800 */
|
||||
} __packed __aligned(16);
|
||||
|
||||
/*
|
||||
* End marker: Should be at the end of every valid s390 crash dump
|
||||
*/
|
||||
struct df_s390_em {
|
||||
union {
|
||||
uint64_t magic;
|
||||
char str[8];
|
||||
};
|
||||
uint64_t tod;
|
||||
} __packed __aligned(16);
|
||||
|
||||
/*
|
||||
* Dump segment header
|
||||
*/
|
||||
struct df_s390_dump_segm_hdr {
|
||||
union {
|
||||
struct {
|
||||
uint64_t start; /* 0x000 */
|
||||
uint64_t len; /* 0x008 */
|
||||
uint64_t stop_marker; /* 0x010 */
|
||||
/* Size in blocks of compressed dump segment written to disk */
|
||||
uint32_t size_on_disk; /* 0x018 */
|
||||
uint8_t reserved_pad[0x30 - 0x1c]; /* 0x01c */
|
||||
/*
|
||||
* Number of compressed entries in this dump segment (up to
|
||||
* 1011 entries)
|
||||
*/
|
||||
uint32_t entry_count; /* 0x030 */
|
||||
/*
|
||||
* Offsets in blocks to compressed entries written to disk
|
||||
* from the start of the dump segment.
|
||||
* High-order bit is set if the entry has been written
|
||||
* uncompressed.
|
||||
*/
|
||||
uint32_t entry_offset[]; /* 0x034 */
|
||||
} __packed;
|
||||
uint8_t padding[PAGE_SIZE];
|
||||
};
|
||||
};
|
||||
|
||||
/* Data compression granularity (size of input data chunk for zlib deflate) */
|
||||
#define DUMP_SEGM_ZLIB_ENTSIZE (1 * MIB)
|
||||
/* Maximum number of compressed entries in one dump segment */
|
||||
#define DUMP_SEGM_ZLIB_MAXENTS ((sizeof(struct df_s390_dump_segm_hdr) \
|
||||
- offsetof(struct df_s390_dump_segm_hdr, entry_offset)) \
|
||||
/ sizeof(uint32_t))
|
||||
/*
|
||||
* Maximum length of compressed dump segment considering the size of
|
||||
* a single input chunk
|
||||
*/
|
||||
#define DUMP_SEGM_ZLIB_MAXLEN (DUMP_SEGM_ZLIB_MAXENTS * DUMP_SEGM_ZLIB_ENTSIZE)
|
||||
/* Bitmask to mark uncompressed chunks */
|
||||
#define DUMP_SEGM_ENTRY_UNCOMPRESSED 0x80000000
|
||||
|
||||
#endif /* S390_DUMP_H */
|
||||
@@ -89,6 +89,7 @@ void ap_list_remove_all(struct util_list *list);
|
||||
/* Lock Functions */
|
||||
int ap_get_lock(void);
|
||||
int ap_get_lock_callout(void);
|
||||
int ap_try_lock_callout(void);
|
||||
int ap_release_lock(void);
|
||||
int ap_release_lock_callout(void);
|
||||
|
||||
|
||||
@@ -27,6 +27,7 @@ enum util_arch_machine_type {
|
||||
UTIL_ARCH_MACHINE_TYPE_Z15 = 8561,
|
||||
UTIL_ARCH_MACHINE_TYPE_Z15_T02 = 8562,
|
||||
UTIL_ARCH_MACHINE_TYPE_Z16 = 3931,
|
||||
UTIL_ARCH_MACHINE_TYPE_Z16_A02 = 3932,
|
||||
};
|
||||
|
||||
int util_arch_machine_type(void);
|
||||
|
||||
@@ -23,4 +23,6 @@ int util_lockfile_parent_lock(char *lockfile, int retries);
|
||||
int util_lockfile_release(char *lockfile);
|
||||
int util_lockfile_parent_release(char *lockfile);
|
||||
|
||||
int util_lockfile_peek_owner(char *lockfile, int *pid);
|
||||
|
||||
#endif /** LIB_UTIL_LOCKFILE_H @} */
|
||||
|
||||
@@ -40,6 +40,7 @@
|
||||
#define LV_COMPAT_CYL 0xFFFE
|
||||
|
||||
#define VTOC_ERROR "VTOC error:"
|
||||
#define MAX_VTOC_ENTRIES 9 /* max number of VTOC labels for cdl formatted DASD */
|
||||
|
||||
typedef struct ttr
|
||||
{
|
||||
|
||||
@@ -16,7 +16,8 @@
|
||||
|
||||
#define PV_IBM_Z_SUBJECT_COMMON_NAME "International Business Machines Corporation"
|
||||
#define PV_IBM_Z_SUBJECT_COUNTRY_NAME "US"
|
||||
#define PV_IBM_Z_SUBJECT_LOCALITY_NAME "Poughkeepsie"
|
||||
#define PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE "Poughkeepsie"
|
||||
#define PV_IBM_Z_SUBJECT_LOCALITY_NAME_ARMONK "Armonk"
|
||||
#define PV_IBM_Z_SUBJECT_ORGANIZATIONAL_UNIT_NAME_SUFFIX "Key Signing Service"
|
||||
#define PV_IBM_Z_SUBJECT_ORGANIZATION_NAME "International Business Machines Corporation"
|
||||
#define PV_IBM_Z_SUBJECT_STATE "New York"
|
||||
|
||||
@@ -13,8 +13,7 @@ RECURSIVE_TARGETS = all-recursive install-recursive clean-recursive \
|
||||
|
||||
|
||||
all: all-recursive
|
||||
check: check-recursive
|
||||
install: all install-recursive
|
||||
install: install-recursive
|
||||
clean: clean-recursive
|
||||
|
||||
|
||||
|
||||
28
libap/ap.c
28
libap/ap.c
@@ -722,6 +722,34 @@ int ap_get_lock_callout(void)
|
||||
return util_lockfile_parent_lock(AP_LOCKFILE, AP_LOCK_RETRIES);
|
||||
}
|
||||
|
||||
/**
|
||||
* Attempt to acquire the ap config lock using the Parent Process ID without
|
||||
* waiting/retries. Detect if the attempt was rejected because the lock is
|
||||
* already held by the Parent Process ID.
|
||||
*
|
||||
* @retval 0 Lock acquired on behalf of parent process
|
||||
* @retval 1 Lock not obtained, already held by parent
|
||||
* @retval != 0 Lock was not obtained, other error
|
||||
*/
|
||||
int ap_try_lock_callout(void)
|
||||
{
|
||||
int pid, ppid, rc;
|
||||
|
||||
if (util_lockfile_parent_lock(AP_LOCKFILE, 0)) {
|
||||
/* Lock is already held, let's peek at the owner */
|
||||
ppid = getppid();
|
||||
rc = util_lockfile_peek_owner(AP_LOCKFILE, &pid);
|
||||
if (rc || pid != ppid) {
|
||||
/* We didn't get the lock, unknown or other owner */
|
||||
return 2;
|
||||
}
|
||||
/* Signify that the lock is already held by the caller */
|
||||
return 1;
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* Release the ap config lock
|
||||
*
|
||||
|
||||
@@ -55,7 +55,7 @@ check-dep-libekmfweb: detect-openssl-version.dep
|
||||
"detect-openssl-version.dep", \
|
||||
"openssl-devel version >= 1.1.1", \
|
||||
"HAVE_OPENSSL=0", \
|
||||
-I. -lcrypto -DOPENSSL_SUPPRESS_DEPRECATED)
|
||||
-I. `$(PKG_CONFIG) --cflags --libs libcrypto` -DOPENSSL_SUPPRESS_DEPRECATED)
|
||||
$(call check_dep, \
|
||||
"libekmfweb", \
|
||||
"json-c/json.h", \
|
||||
@@ -66,7 +66,7 @@ check-dep-libekmfweb: detect-openssl-version.dep
|
||||
"curl/curl.h", \
|
||||
"libcurl-devel", \
|
||||
"HAVE_LIBCURL=0" \
|
||||
`$(CURL_CONFIG) --cflags` `$(CURL_CONFIG) --libs`)
|
||||
`$(PKG_CONFIG) --cflags --libs libcurl`)
|
||||
$(CURL_CONFIG) --ssl-backends | grep OpenSSL >/dev/null 2>&1 || { echo "Error: libcurl is not built with the OpenSSL backend"; exit 1; }
|
||||
touch check-dep-libekmfweb
|
||||
|
||||
@@ -85,8 +85,8 @@ ekmfweb.o: check-dep-libekmfweb ekmfweb.c utilities.h cca.h $(rootdir)include/ek
|
||||
utilities.o: check-dep-libekmfweb utilities.c utilities.h $(rootdir)include/ekmfweb/ekmfweb.h
|
||||
cca.o: check-dep-libekmfweb cca.c cca.h utilities.h $(rootdir)include/ekmfweb/ekmfweb.h
|
||||
|
||||
libekmfweb.so.$(VERSION): ALL_CFLAGS += -fPIC `$(CURL_CONFIG) --cflags`
|
||||
libekmfweb.so.$(VERSION): LDLIBS = -ljson-c -lcrypto -lssl `$(CURL_CONFIG) --libs` -ldl
|
||||
libekmfweb.so.$(VERSION): ALL_CFLAGS += -fPIC `$(PKG_CONFIG) --cflags json-c libcurl libcrypto libssl`
|
||||
libekmfweb.so.$(VERSION): LDLIBS = `$(PKG_CONFIG) --libs json-c libcurl libcrypto libssl` -ldl
|
||||
libekmfweb.so.$(VERSION): ALL_LDFLAGS += -shared -Wl,--version-script=libekmfweb.map \
|
||||
-Wl,-z,defs,-Bsymbolic -Wl,-soname,libekmfweb.so.$(VERM)
|
||||
libekmfweb.so.$(VERSION): ekmfweb.o utilities.o cca.o $(libs)
|
||||
@@ -98,7 +98,7 @@ install-libekmfweb.so.$(VERSION): libekmfweb.so.$(VERSION)
|
||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 755 -T libekmfweb.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so.$(VERSION)
|
||||
ln -srf $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so.$(VERM)
|
||||
ln -srf $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libekmfweb.so
|
||||
$(INSTALL) -d -m 770 $(DESTDIR)$(USRINCLUDEDIR)/ekmfweb
|
||||
$(INSTALL) -d -m 755 $(DESTDIR)$(USRINCLUDEDIR)/ekmfweb
|
||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 $(rootdir)include/ekmfweb/ekmfweb.h $(DESTDIR)$(USRINCLUDEDIR)/ekmfweb
|
||||
|
||||
install: all $(INSTALL_TARGETS)
|
||||
|
||||
@@ -51,7 +51,6 @@ detect-openssl-version.dep:
|
||||
mv $(TMPFILE) $@
|
||||
|
||||
CURL_CONFIG ?= curl-config
|
||||
XML2_CONFIG ?= xml2-config
|
||||
|
||||
check-dep-libkmipclient: detect-openssl-version.dep
|
||||
$(call check_dep, \
|
||||
@@ -59,7 +58,7 @@ check-dep-libkmipclient: detect-openssl-version.dep
|
||||
"detect-openssl-version.dep", \
|
||||
"openssl-devel version >= 1.1.1", \
|
||||
"HAVE_OPENSSL=0", \
|
||||
-I. -lcrypto -DOPENSSL_SUPPRESS_DEPRECATED)
|
||||
-I. `$(PKG_CONFIG) --cflags --libs libcrypto` -DOPENSSL_SUPPRESS_DEPRECATED)
|
||||
$(call check_dep, \
|
||||
"libkmipclient", \
|
||||
"json-c/json.h", \
|
||||
@@ -70,13 +69,13 @@ check-dep-libkmipclient: detect-openssl-version.dep
|
||||
"libxml/tree.h", \
|
||||
"libxml2-devel", \
|
||||
"HAVE_LIBXML2=0", \
|
||||
`$(XML2_CONFIG) --cflags` `$(XML2_CONFIG) --libs`)
|
||||
`$(PKG_CONFIG) --cflags --libs libxml-2.0`)
|
||||
$(call check_dep, \
|
||||
"libkmipclient", \
|
||||
"curl/curl.h", \
|
||||
"libcurl-devel", \
|
||||
"HAVE_LIBCURL=0" \
|
||||
`$(CURL_CONFIG) --cflags` `$(CURL_CONFIG) --libs`)
|
||||
`$(PKG_CONFIG) --cflags --libs libcurl`)
|
||||
$(CURL_CONFIG) --ssl-backends | grep OpenSSL >/dev/null 2>&1 || { echo "Error: libcurl is not built with the OpenSSL backend"; exit 1; }
|
||||
touch check-dep-libkmipclient
|
||||
|
||||
@@ -107,8 +106,8 @@ tls.o: check-dep-libkmipclient tls.c kmip.h utils.h $(rootdir)include/kmipclient
|
||||
names.o: check-dep-libkmipclient names.c names.h utils.h $(rootdir)include/kmipclient/kmipclient.h
|
||||
utils.o: check-dep-libkmipclient utils.c names.h utils.h $(rootdir)include/kmipclient/kmipclient.h
|
||||
|
||||
libkmipclient.so.$(VERSION): ALL_CFLAGS += -fPIC `$(XML2_CONFIG) --cflags` `$(CURL_CONFIG) --cflags`
|
||||
libkmipclient.so.$(VERSION): LDLIBS = -ljson-c -lcrypto -lssl `$(XML2_CONFIG) --libs` `$(CURL_CONFIG) --libs`
|
||||
libkmipclient.so.$(VERSION): ALL_CFLAGS += -fPIC `$(PKG_CONFIG) --cflags json-c libcrypto libssl libxml-2.0 libcurl`
|
||||
libkmipclient.so.$(VERSION): LDLIBS = `$(PKG_CONFIG) --libs json-c libcrypto libssl libxml-2.0 libcurl`
|
||||
libkmipclient.so.$(VERSION): ALL_LDFLAGS += -shared -Wl,--version-script=libkmipclient.map \
|
||||
-Wl,-z,defs,-Bsymbolic -Wl,-soname,libkmipclient.so.$(VERM)
|
||||
libkmipclient.so.$(VERSION): kmip.o request.o response.o attribute.o key.o ttlv.o json.o \
|
||||
@@ -121,7 +120,7 @@ install-libkmipclient.so.$(VERSION): libkmipclient.so.$(VERSION)
|
||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 755 -T libkmipclient.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so.$(VERSION)
|
||||
ln -srf $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so.$(VERM)
|
||||
ln -srf $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so.$(VERSION) $(DESTDIR)$(SOINSTALLDIR)/libkmipclient.so
|
||||
$(INSTALL) -d -m 770 $(DESTDIR)$(USRINCLUDEDIR)/kmipclient
|
||||
$(INSTALL) -d -m 755 $(DESTDIR)$(USRINCLUDEDIR)/kmipclient
|
||||
$(INSTALL) -g $(GROUP) -o $(OWNER) -m 644 $(rootdir)include/kmipclient/kmipclient.h $(DESTDIR)$(USRINCLUDEDIR)/kmipclient
|
||||
|
||||
install: all $(INSTALL_TARGETS)
|
||||
|
||||
@@ -16,6 +16,7 @@
|
||||
#include <openssl/ssl.h>
|
||||
|
||||
#include <json-c/json.h>
|
||||
#include <libxml/parser.h>
|
||||
#include <libxml/tree.h>
|
||||
#include <curl/curl.h>
|
||||
|
||||
|
||||
@@ -21,8 +21,7 @@ WARNINGS := -Wall -Wextra -Wshadow \
|
||||
-Wno-unused-function -Wno-unused-parameter -Wno-unused-variable \
|
||||
$(NULL)
|
||||
|
||||
ALL_CFLAGS += -std=gnu11 \
|
||||
-DOPENSSL_API_COMPAT=0x10101000L \
|
||||
ALL_CFLAGS += -DOPENSSL_API_COMPAT=0x10101000L \
|
||||
$(GLIB2_CFLAGS) \
|
||||
$(LIBCRYPTO_CFLAGS) \
|
||||
$(LIBCURL_CFLAGS) \
|
||||
|
||||
148
libpv/cert.c
148
libpv/cert.c
@@ -857,7 +857,7 @@ static gboolean x509_name_data_by_nid_equal(X509_NAME *name, int nid, const char
|
||||
|
||||
/* Checks whether the subject of @cert is a IBM signing key subject. For this we
|
||||
* must check that the subject is equal to: 'C = US, ST = New York, L =
|
||||
* Poughkeepsie, O = International Business Machines Corporation, CN =
|
||||
* Poughkeepsie or Armonk, O = International Business Machines Corporation, CN =
|
||||
* International Business Machines Corporation' and the organization unit (OUT)
|
||||
* must end with the suffix ' Key Signing Service'.
|
||||
*/
|
||||
@@ -879,7 +879,10 @@ static gboolean has_ibm_signing_subject(X509 *cert)
|
||||
if (!x509_name_data_by_nid_equal(subject, NID_stateOrProvinceName, PV_IBM_Z_SUBJECT_STATE))
|
||||
return FALSE;
|
||||
|
||||
if (!x509_name_data_by_nid_equal(subject, NID_localityName, PV_IBM_Z_SUBJECT_LOCALITY_NAME))
|
||||
if (!(x509_name_data_by_nid_equal(subject, NID_localityName,
|
||||
PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE) ||
|
||||
x509_name_data_by_nid_equal(subject, NID_localityName,
|
||||
PV_IBM_Z_SUBJECT_LOCALITY_NAME_ARMONK)))
|
||||
return FALSE;
|
||||
|
||||
if (!x509_name_data_by_nid_equal(subject, NID_organizationName,
|
||||
@@ -1085,10 +1088,9 @@ static int check_signature_algo_match(const EVP_PKEY *pkey, const X509 *subject,
|
||||
|
||||
/* It's almost the same as X509_check_issed from OpenSSL does except that we
|
||||
* don't check the key usage of the potential issuer. This means we check:
|
||||
* 1. issuer_name(cert) == subject_name(issuer)
|
||||
* 2. Check whether the akid(cert) (if available) matches the issuer skid
|
||||
* 3. Check that the cert algrithm matches the subject algorithm
|
||||
* 4. Verify the signature of certificate @cert is using the public key of
|
||||
* 1. Check whether the akid(cert) (if available) matches the issuer skid
|
||||
* 2. Check that the cert algrithm matches the subject algorithm
|
||||
* 3. Verify the signature of certificate @cert is using the public key of
|
||||
* @issuer.
|
||||
*/
|
||||
static int check_host_key_issued(X509 *cert, X509 *issuer, GError **error)
|
||||
@@ -1097,19 +1099,6 @@ static int check_host_key_issued(X509 *cert, X509 *issuer, GError **error)
|
||||
const X509_NAME *cert_issuer = X509_get_issuer_name(cert);
|
||||
g_autoptr(AUTHORITY_KEYID) akid = NULL;
|
||||
|
||||
/* We cannot use X509_NAME_cmp() because it considers the order of the
|
||||
* X509_NAME_Entries.
|
||||
*/
|
||||
if (!own_X509_NAME_equal(issuer_subject, cert_issuer)) {
|
||||
g_autofree char *issuer_subject_str = pv_X509_NAME_oneline(issuer_subject);
|
||||
g_autofree char *cert_issuer_str = pv_X509_NAME_oneline(cert_issuer);
|
||||
|
||||
g_set_error(error, PV_CERT_ERROR, PV_CERT_ERROR_CERT_SUBJECT_ISSUER_MISMATCH,
|
||||
_("Subject issuer mismatch:\n'%s'\n'%s'"), issuer_subject_str,
|
||||
cert_issuer_str);
|
||||
return -1;
|
||||
}
|
||||
|
||||
akid = X509_get_ext_d2i(cert, NID_authority_key_identifier, NULL, NULL);
|
||||
if (akid && X509_check_akid(issuer, akid) != X509_V_OK) {
|
||||
g_set_error(error, PV_CERT_ERROR, PV_CERT_ERROR_SKID_AKID_MISMATCH,
|
||||
@@ -1286,21 +1275,10 @@ int pv_verify_cert(X509_STORE_CTX *ctx, X509 *cert, GError **error)
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* Verify that: subject(issuer) == issuer(crl) and SKID(issuer) == AKID(crl) */
|
||||
/* Verify that SKID(issuer) == AKID(crl) */
|
||||
static int check_crl_issuer(X509_CRL *crl, X509 *issuer, GError **error)
|
||||
{
|
||||
const X509_NAME *crl_issuer = X509_CRL_get_issuer(crl);
|
||||
const X509_NAME *issuer_subject = X509_get_subject_name(issuer);
|
||||
AUTHORITY_KEYID *akid = NULL;
|
||||
|
||||
if (!own_X509_NAME_equal(issuer_subject, crl_issuer)) {
|
||||
g_autofree char *issuer_subject_str = pv_X509_NAME_oneline(issuer_subject);
|
||||
g_autofree char *crl_issuer_str = pv_X509_NAME_oneline(crl_issuer);
|
||||
|
||||
g_set_error(error, PV_CERT_ERROR, PV_CERT_ERROR_CRL_SUBJECT_ISSUER_MISMATCH,
|
||||
_("issuer mismatch:\n%s\n%s"), issuer_subject_str, crl_issuer_str);
|
||||
return -1;
|
||||
}
|
||||
g_autoptr(AUTHORITY_KEYID) akid = NULL;
|
||||
|
||||
/* If AKID(@crl) is specified it must match with SKID(@issuer) */
|
||||
akid = X509_CRL_get_ext_d2i(crl, NID_authority_key_identifier, NULL, NULL);
|
||||
@@ -1325,7 +1303,6 @@ int pv_verify_crl(X509_CRL *crl, X509 *cert, int verify_flags, GError **error)
|
||||
return -1;
|
||||
}
|
||||
|
||||
/* check that the @crl issuer matches with the subject name of @cert*/
|
||||
if (check_crl_issuer(crl, cert, error) < 0)
|
||||
return -1;
|
||||
|
||||
@@ -1393,6 +1370,93 @@ int pv_check_chain_parameters(const STACK_OF_X509 *chain, GError **error)
|
||||
return 0;
|
||||
}
|
||||
|
||||
/** Replace locality 'Armonk' with 'Pougkeepsie'. If Armonk was not set return
|
||||
* `NULL`.
|
||||
*/
|
||||
static X509_NAME *x509_armonk_locality_fixup(const X509_NAME *name)
|
||||
{
|
||||
g_autoptr(X509_NAME) ret = NULL;
|
||||
int pos;
|
||||
|
||||
/* Check if ``L=Armonk`` */
|
||||
if (!x509_name_data_by_nid_equal((X509_NAME *)name, NID_localityName,
|
||||
PV_IBM_Z_SUBJECT_LOCALITY_NAME_ARMONK))
|
||||
return NULL;
|
||||
|
||||
ret = X509_NAME_dup((X509_NAME *)name);
|
||||
if (!ret)
|
||||
g_abort();
|
||||
|
||||
pos = X509_NAME_get_index_by_NID(ret, NID_localityName, -1);
|
||||
if (pos == -1)
|
||||
return NULL;
|
||||
|
||||
X509_NAME_ENTRY_free(X509_NAME_delete_entry(ret, pos));
|
||||
|
||||
/* Create a new name entry at the same position as before */
|
||||
if (X509_NAME_add_entry_by_NID(
|
||||
ret, NID_localityName, MBSTRING_UTF8,
|
||||
(const unsigned char *)&PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE,
|
||||
sizeof(PV_IBM_Z_SUBJECT_LOCALITY_NAME_POUGHKEEPSIE) - 1, pos, 0) != 1)
|
||||
return NULL;
|
||||
|
||||
return g_steal_pointer(&ret);
|
||||
}
|
||||
|
||||
/* This function contains work-arounds for some known subject(CRT)<->issuer(CRL)
|
||||
* issues.
|
||||
*/
|
||||
static STACK_OF_X509_CRL *quirk_X509_STORE_ctx_get1_crls(X509_STORE_CTX *ctx,
|
||||
const X509_NAME *subject, GError **err)
|
||||
{
|
||||
g_autoptr(X509_NAME) fixed_subject = NULL;
|
||||
g_autoptr(STACK_OF_X509_CRL) ret = NULL;
|
||||
|
||||
ret = pv_X509_STORE_CTX_get1_crls(ctx, subject);
|
||||
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||
return g_steal_pointer(&ret);
|
||||
|
||||
/* Workaround to fix the mismatch between issuer name of the * IBM
|
||||
* signing CRLs and the IBM signing key subject name. Locality name has
|
||||
* changed from Poughkeepsie to Armonk.
|
||||
*/
|
||||
fixed_subject = x509_armonk_locality_fixup(subject);
|
||||
/* Was the locality replaced? */
|
||||
if (fixed_subject) {
|
||||
X509_NAME *tmp;
|
||||
|
||||
sk_X509_CRL_free(ret);
|
||||
ret = pv_X509_STORE_CTX_get1_crls(ctx, fixed_subject);
|
||||
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||
return g_steal_pointer(&ret);
|
||||
|
||||
/* Workaround to fix the ordering mismatch between issuer name
|
||||
* of the IBM signing CRLs and the IBM signing key subject name.
|
||||
*/
|
||||
tmp = fixed_subject;
|
||||
fixed_subject = pv_c2b_name(fixed_subject);
|
||||
X509_NAME_free(tmp);
|
||||
sk_X509_CRL_free(ret);
|
||||
ret = pv_X509_STORE_CTX_get1_crls(ctx, fixed_subject);
|
||||
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||
return g_steal_pointer(&ret);
|
||||
X509_NAME_free(fixed_subject);
|
||||
fixed_subject = NULL;
|
||||
}
|
||||
|
||||
/* Workaround to fix the ordering mismatch between issuer name of the
|
||||
* IBM signing CRLs and the IBM signing key subject name.
|
||||
*/
|
||||
fixed_subject = pv_c2b_name(subject);
|
||||
sk_X509_CRL_free(ret);
|
||||
ret = pv_X509_STORE_CTX_get1_crls(ctx, fixed_subject);
|
||||
if (ret && sk_X509_CRL_num(ret) > 0)
|
||||
return g_steal_pointer(&ret);
|
||||
|
||||
g_set_error(err, PV_CERT_ERROR, PV_CERT_ERROR_NO_CRL, _("no CRL found"));
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/* Given a certificate @cert try to find valid revocation lists in @ctx. If no
|
||||
* valid CRL was found NULL is returned.
|
||||
*/
|
||||
@@ -1412,21 +1476,9 @@ STACK_OF_X509_CRL *pv_store_ctx_find_valid_crls(X509_STORE_CTX *ctx, X509 *cert,
|
||||
return NULL;
|
||||
}
|
||||
|
||||
ret = pv_X509_STORE_CTX_get1_crls(ctx, subject);
|
||||
if (!ret) {
|
||||
/* Workaround to fix the mismatch between issuer name of the
|
||||
* IBM Z signing CRLs and the IBM Z signing key subject name.
|
||||
*/
|
||||
g_autoptr(X509_NAME) broken_subject = pv_c2b_name(subject);
|
||||
|
||||
ret = pv_X509_STORE_CTX_get1_crls(ctx, broken_subject);
|
||||
if (!ret) {
|
||||
g_set_error(error, PV_CERT_ERROR, PV_CERT_ERROR_NO_CRL, _("no CRL found"));
|
||||
g_info("ERROR: %s", (*error)->message);
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
|
||||
ret = quirk_X509_STORE_ctx_get1_crls(ctx, subject, error);
|
||||
if (!ret)
|
||||
return NULL;
|
||||
/* Filter out non-valid CRLs for @cert */
|
||||
for (int i = 0; i < sk_X509_CRL_num(ret); i++) {
|
||||
X509_CRL *crl = sk_X509_CRL_value(ret, i);
|
||||
|
||||
@@ -90,10 +90,10 @@ const char *util_arch_machine_type_to_str(int type)
|
||||
case UTIL_ARCH_MACHINE_TYPE_Z14_ZR1:
|
||||
return "IBM z14 ZR1";
|
||||
case UTIL_ARCH_MACHINE_TYPE_Z15:
|
||||
return "IBM z15";
|
||||
case UTIL_ARCH_MACHINE_TYPE_Z15_T02:
|
||||
return "IBM z15 Model T02";
|
||||
return "IBM z15";
|
||||
case UTIL_ARCH_MACHINE_TYPE_Z16:
|
||||
case UTIL_ARCH_MACHINE_TYPE_Z16_A02:
|
||||
return "IBM z16";
|
||||
default:
|
||||
return "Unknown machine type";
|
||||
@@ -111,6 +111,7 @@ unsigned long util_arch_hsa_maxsize(void)
|
||||
case UTIL_ARCH_MACHINE_TYPE_Z15:
|
||||
case UTIL_ARCH_MACHINE_TYPE_Z15_T02:
|
||||
case UTIL_ARCH_MACHINE_TYPE_Z16:
|
||||
case UTIL_ARCH_MACHINE_TYPE_Z16_A02:
|
||||
return HSA_SIZE_512M;
|
||||
default:
|
||||
return HSA_SIZE_32M;
|
||||
|
||||
@@ -311,13 +311,13 @@ int util_file_read_i(int *val, int base, const char *fmt, ...)
|
||||
return -1;
|
||||
switch (base) {
|
||||
case 8:
|
||||
count = sscanf(buf, "%do", val);
|
||||
count = sscanf(buf, "%o", val);
|
||||
break;
|
||||
case 10:
|
||||
count = sscanf(buf, "%dd", val);
|
||||
count = sscanf(buf, "%d", val);
|
||||
break;
|
||||
case 16:
|
||||
count = sscanf(buf, "%dx", val);
|
||||
count = sscanf(buf, "%x", val);
|
||||
break;
|
||||
default:
|
||||
util_panic("Invalid base: %d\n", base);
|
||||
@@ -425,13 +425,13 @@ int util_file_read_ui(unsigned int *val, int base, const char *fmt, ...)
|
||||
return -1;
|
||||
switch (base) {
|
||||
case 8:
|
||||
count = sscanf(buf, "%uo", val);
|
||||
count = sscanf(buf, "%o", val);
|
||||
break;
|
||||
case 10:
|
||||
count = sscanf(buf, "%uu", val);
|
||||
count = sscanf(buf, "%u", val);
|
||||
break;
|
||||
case 16:
|
||||
count = sscanf(buf, "%ux", val);
|
||||
count = sscanf(buf, "%x", val);
|
||||
break;
|
||||
default:
|
||||
util_panic("Invalid base: %d\n", base);
|
||||
|
||||
@@ -299,3 +299,35 @@ int util_lockfile_parent_release(char *lockfile)
|
||||
{
|
||||
return do_lockfile_release(lockfile, getppid());
|
||||
}
|
||||
|
||||
/**
|
||||
* Return the pid that owns the specified lockfile.
|
||||
*
|
||||
* @param[in] lockfile Path to the lock file
|
||||
* @param[in,out] pid Buffer to place owning pid
|
||||
*
|
||||
* @retval 0 pid provided in buffer
|
||||
* @retval !=0 Error, no pid provided
|
||||
*/
|
||||
int util_lockfile_peek_owner(char *lockfile, int *pid)
|
||||
{
|
||||
char buf[BUFSIZE];
|
||||
int fd, len;
|
||||
|
||||
if (!lockfile || !pid)
|
||||
return UTIL_LOCKFILE_ERR;
|
||||
|
||||
/* Open lockfile, read the owning pid if it exists */
|
||||
fd = open(lockfile, O_RDONLY);
|
||||
if (fd < 0)
|
||||
return UTIL_LOCKFILE_ERR;
|
||||
|
||||
len = read(fd, buf, sizeof(buf));
|
||||
close(fd);
|
||||
if (len <= 0)
|
||||
return UTIL_LOCKFILE_ERR;
|
||||
buf[len] = 0;
|
||||
*pid = atoi(buf);
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -45,7 +45,7 @@ vmcmd: Trigger CP command according to the 'VMCMD_X' configuration in
|
||||
|
||||
.TP
|
||||
\fB - DUMP_TYPE:\fR
|
||||
Type of dump device. Possible values are 'ccw', 'fcp' and 'nvme'.
|
||||
Type of dump device. Possible values are 'ccw', 'eckd', 'fcp' and 'nvme'.
|
||||
|
||||
.TP
|
||||
\fB - DEVICE:\fR
|
||||
@@ -71,6 +71,11 @@ Namespace ID for NVMe dump device.
|
||||
\fB - BOOTPROG:\fR
|
||||
Boot program selector.
|
||||
|
||||
.TP
|
||||
\fB - BR_CHR:\fR
|
||||
Boot record location in "C,H,R" format (comma separated values for
|
||||
Cylinder, Head and Record) or "auto".
|
||||
|
||||
.TP
|
||||
\fB - BR_LBA:\fR
|
||||
Boot record logical block address.
|
||||
@@ -146,6 +151,23 @@ DEVICE=0.0.1234
|
||||
DELAY_MINUTES=5
|
||||
.br
|
||||
|
||||
#
|
||||
.br
|
||||
# Example configuration for an ECKD dump device (DASD)
|
||||
.br
|
||||
#
|
||||
.br
|
||||
ON_PANIC=dump
|
||||
.br
|
||||
DUMP_TYPE=eckd
|
||||
.br
|
||||
DEVICE=0.0.1004
|
||||
.br
|
||||
BOOTPROG=0
|
||||
.br
|
||||
BR_CHR=auto
|
||||
.br
|
||||
|
||||
#
|
||||
.br
|
||||
# Example configuration for an FCP dump device (SCSI Disk)
|
||||
|
||||
@@ -16,7 +16,7 @@
|
||||
|
||||
/* we may use header_generic and header_simple_table from the util_funcs module */
|
||||
|
||||
config_require(util_funcs)
|
||||
config_require(util_funcs);
|
||||
|
||||
|
||||
/* function prototypes */
|
||||
|
||||
@@ -3,13 +3,12 @@ include ../common.mak
|
||||
|
||||
.DEFAULT_GOAL := all
|
||||
|
||||
PKGDATADIR := "$(DESTDIR)$(TOOLS_DATADIR)/pvattest"
|
||||
SUBDIRS := src man tools
|
||||
RECURSIVE_TARGETS := all-recursive clean-recursive install-recursive
|
||||
|
||||
all: all-recursive
|
||||
|
||||
install: all install-recursive
|
||||
install: install-recursive
|
||||
|
||||
clean: clean-recursive
|
||||
|
||||
|
||||
@@ -24,12 +24,27 @@ Show help options
|
||||
\fBFILE\fP specifies the attestation result as input.
|
||||
.TP
|
||||
.B
|
||||
\fB-o\fP, \fB--ouput\fP=\fBFILE\fP
|
||||
\fBFILE\fP specifies the output for the verification result.
|
||||
.TP
|
||||
.B
|
||||
\fB--hdr\fP=\fBFILE\fP
|
||||
Specify the header of the guest image. Exactly one is required.
|
||||
.TP
|
||||
.B
|
||||
\fB-a\fP, \fB--arpk\fP=\fBFILE\fP
|
||||
Use \fBFILE\fP to specify the GCM-AES256 key to decrypt the attestation request. Delete this key after verification.
|
||||
.TP
|
||||
.B
|
||||
\fB--format\fP=\fByaml\fP
|
||||
Define the output format.
|
||||
Default value: 'yaml'
|
||||
|
||||
Possible values:
|
||||
.RS 4
|
||||
- \fByaml\fP: Use YAML format
|
||||
.RE
|
||||
|
||||
.TP
|
||||
.B
|
||||
\fB-V\fP, \fB--verbose\fP
|
||||
|
||||
@@ -1,10 +1,7 @@
|
||||
include ../../common.mak
|
||||
|
||||
BIN_PROGRAM = pvattest
|
||||
PKGDATADIR ?= "$(DESTDIR)$(TOOLS_DATADIR)/$(BIN_PROGRAM)"
|
||||
|
||||
SRC_DIR := $(dir $(realpath $(firstword $(MAKEFILE_LIST))))
|
||||
PVATTESTDIR := $(rootdir)/pvattest
|
||||
INCLUDE_PATHS = "$(SRC_DIR)" "$(rootdir)/include"
|
||||
INCLUDE_PARMS = $(addprefix -I,$(INCLUDE_PATHS))
|
||||
|
||||
@@ -35,9 +32,7 @@ LIBCRYPTO_LIBS := $(shell $(PKG_CONFIG) --silence-errors --libs libcrypto)
|
||||
LIBCURL_CFLAGS := $(shell $(PKG_CONFIG) --silence-errors --cflags libcurl)
|
||||
LIBCURL_LIBS := $(shell $(PKG_CONFIG) --silence-errors --libs libcurl)
|
||||
|
||||
ALL_CFLAGS += -std=gnu11 \
|
||||
-DPKGDATADIR=$(PKGDATADIR) \
|
||||
-DOPENSSL_API_COMPAT=0x10101000L \
|
||||
ALL_CFLAGS += -DOPENSSL_API_COMPAT=0x10101000L \
|
||||
$(GLIB2_CFLAGS) \
|
||||
$(LIBCRYPTO_CFLAGS) \
|
||||
$(LIBCURL_CFLAGS) \
|
||||
|
||||
@@ -49,8 +49,10 @@ static pvattest_config_t pvattest_config = {
|
||||
},
|
||||
.verify = {
|
||||
.input_path = NULL,
|
||||
.output_path = NULL,
|
||||
.hdr_path = NULL,
|
||||
.arp_key_in_path = NULL,
|
||||
.output_fmt = VERIFY_FMT_YAML,
|
||||
},
|
||||
};
|
||||
typedef gboolean (*verify_options_fn_t)(GError **);
|
||||
@@ -190,13 +192,13 @@ static gboolean hex_str_toull(const char *nptr, uint64_t *dst, GError **error)
|
||||
}
|
||||
|
||||
/* NOTE REQUIRED */
|
||||
#define _entry_root_ca(__arg_data, __indent) \
|
||||
{ \
|
||||
.long_name = "root-ca", .short_name = 0, .flags = G_OPTION_FLAG_NONE, \
|
||||
.arg = G_OPTION_ARG_FILENAME_ARRAY, .arg_data = __arg_data, \
|
||||
.description = "Use FILE as the trusted root CA instead the\n" __indent \
|
||||
"root CAs that are installed on the system (optional).\n", \
|
||||
.arg_description = "FILE", \
|
||||
#define _entry_root_ca(__arg_data, __indent) \
|
||||
{ \
|
||||
.long_name = "root-ca", .short_name = 0, .flags = G_OPTION_FLAG_NONE, \
|
||||
.arg = G_OPTION_ARG_FILENAME, .arg_data = __arg_data, \
|
||||
.description = "Use FILE as the trusted root CA instead the\n" __indent \
|
||||
"root CAs that are installed on the system (optional).\n", \
|
||||
.arg_description = "FILE", \
|
||||
}
|
||||
|
||||
/* NOTE REQUIRED */
|
||||
@@ -329,6 +331,15 @@ static gboolean hex_str_toull(const char *nptr, uint64_t *dst, GError **error)
|
||||
.description = "Use FILE to specify the user data.\n", .arg_description = "FILE", \
|
||||
}
|
||||
|
||||
#define _entry__verify_format(__indent) \
|
||||
{ \
|
||||
.long_name = "format", .short_name = 0, .flags = G_OPTION_FLAG_NONE, \
|
||||
.arg = G_OPTION_ARG_CALLBACK, .arg_data = &set_verify_output_format, \
|
||||
.description = "Define the output format.\n" __indent \
|
||||
"Defaults to 'yaml'. (possible values: 'yaml')\n", \
|
||||
.arg_description = "FORMAT", \
|
||||
}
|
||||
|
||||
static gboolean increase_log_lvl(G_GNUC_UNUSED const char *option_name,
|
||||
G_GNUC_UNUSED const char *value, G_GNUC_UNUSED void *data,
|
||||
G_GNUC_UNUSED GError **error)
|
||||
@@ -337,6 +348,20 @@ static gboolean increase_log_lvl(G_GNUC_UNUSED const char *option_name,
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
static gboolean set_verify_output_format(const char *option_name, const char *value,
|
||||
G_GNUC_UNUSED void *data, GError **error)
|
||||
{
|
||||
if (!g_strcmp0(value, "yaml")) {
|
||||
pvattest_config.verify.output_fmt = VERIFY_FMT_YAML;
|
||||
} else {
|
||||
g_set_error(error, G_OPTION_ERROR, G_OPTION_ERROR_FAILED,
|
||||
_("Found value '%s' for option '%s', but only 'yaml' is allowed."),
|
||||
value, option_name);
|
||||
return FALSE;
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
static gboolean create_set_paf(G_GNUC_UNUSED const char *option_name, const char *value,
|
||||
G_GNUC_UNUSED void *data, GError **error)
|
||||
{
|
||||
@@ -445,13 +470,16 @@ static gboolean verify_perform(GError **error)
|
||||
}
|
||||
|
||||
/************************* VERIFY OPTIONS ************************************/
|
||||
#define verify_indent " "
|
||||
#define verify_indent " "
|
||||
|
||||
static GOptionEntry verify_options[] = {
|
||||
_entry_input(&pvattest_config.verify.input_path, "attestation result", verify_indent),
|
||||
_entry_output(&pvattest_config.verify.output_path,
|
||||
"verification result.\n" verify_indent "(optional)", verify_indent),
|
||||
_entry_guest_hdr(&pvattest_config.verify.hdr_path, verify_indent),
|
||||
_entry_att_prot_key_load(&pvattest_config.verify.arp_key_in_path, verify_indent),
|
||||
_entry_verbose(verify_indent),
|
||||
_entry__verify_format(verify_indent),
|
||||
{ NULL },
|
||||
};
|
||||
|
||||
@@ -631,6 +659,7 @@ static void pvattest_parse_clear_verify_config(pvattest_verify_config_t *config)
|
||||
if (!config)
|
||||
return;
|
||||
g_free(config->input_path);
|
||||
g_free(config->output_path);
|
||||
g_free(config->hdr_path);
|
||||
g_free(config->arp_key_in_path);
|
||||
}
|
||||
|
||||
@@ -58,8 +58,15 @@ typedef struct {
|
||||
char *user_data_path; /* default NULL */
|
||||
} pvattest_perform_config_t;
|
||||
|
||||
enum verify_output_format {
|
||||
VERIFY_FMT_HUMAN,
|
||||
VERIFY_FMT_YAML,
|
||||
};
|
||||
|
||||
typedef struct {
|
||||
char *input_path;
|
||||
char *output_path;
|
||||
enum verify_output_format output_fmt;
|
||||
char *hdr_path;
|
||||
char *arp_key_in_path;
|
||||
} pvattest_verify_config_t;
|
||||
|
||||
@@ -455,8 +455,7 @@ static void print_entry(const char *name, GBytes *data, const gboolean print_dat
|
||||
fprintf(stream, _("%s (%#lx bytes)"), name, g_bytes_get_size(data));
|
||||
if (print_data) {
|
||||
fprintf(stream, ":\n");
|
||||
pvattest_hexdump(g_bytes_get_data(data, NULL), g_bytes_get_size(data), 16, " ",
|
||||
stream);
|
||||
pvattest_hexdump(stream, data, 16, " ", TRUE);
|
||||
}
|
||||
fprintf(stream, "\n");
|
||||
}
|
||||
|
||||
@@ -159,24 +159,47 @@ void pvattest_log_bytes(const void *data, size_t size, size_t width, const char
|
||||
g_log(PVATTEST_BYTES_LOG_DOMAIN, log_lvl, "\n");
|
||||
}
|
||||
|
||||
void pvattest_hexdump(const void *data, size_t size, size_t width, const char *prefix, FILE *stream)
|
||||
int pvattest_hexdump(FILE *stream, GBytes *bytes, const size_t width, const char *prefix,
|
||||
const gboolean beautify)
|
||||
{
|
||||
const uint8_t *data_b = data;
|
||||
const uint8_t *data;
|
||||
size_t size;
|
||||
|
||||
pv_wrapped_g_assert(data);
|
||||
pv_wrapped_g_assert(bytes);
|
||||
pv_wrapped_g_assert(stream);
|
||||
|
||||
fprintf(stream, "%s0x0000 ", prefix);
|
||||
data = g_bytes_get_data(bytes, &size);
|
||||
pv_wrapped_g_assert(data);
|
||||
|
||||
if (beautify) {
|
||||
if (fprintf(stream, "%s0x0000 ", prefix) < 0)
|
||||
return -1;
|
||||
} else {
|
||||
if (fprintf(stream, "%s", prefix) < 0)
|
||||
return -1;
|
||||
}
|
||||
for (size_t i = 0; i < size; i++) {
|
||||
fprintf(stream, "%02x", data_b[i]);
|
||||
if (i % 2 == 1)
|
||||
fprintf(stream, " ");
|
||||
if (fprintf(stream, "%02x", data[i]) < 0)
|
||||
return -1;
|
||||
if (i % 2 == 1 && beautify) {
|
||||
if (fprintf(stream, " ") < 0)
|
||||
return -1;
|
||||
}
|
||||
if (i == size - 1)
|
||||
break;
|
||||
if (i % width == width - 1)
|
||||
fprintf(stream, "\n%s0x%04lx ", prefix, i + 1);
|
||||
if (width == 0)
|
||||
continue;
|
||||
if (i % width == width - 1) {
|
||||
if (beautify) {
|
||||
if (fprintf(stream, "\n%s0x%04lx ", prefix, i + 1) < 0)
|
||||
return -1;
|
||||
} else {
|
||||
if (fprintf(stream, "\n%s", prefix) < 0)
|
||||
return -1;
|
||||
}
|
||||
}
|
||||
}
|
||||
fprintf(stream, "\n");
|
||||
return 0;
|
||||
}
|
||||
|
||||
void pvattest_log_GError(const char *info, GError *error)
|
||||
|
||||
@@ -60,8 +60,8 @@ void pvattest_log_plain_logger(const char *log_domain, GLogLevelFlags level, con
|
||||
}
|
||||
void pvattest_log_bytes(const void *data, size_t size, size_t width, const char *prefix,
|
||||
gboolean beautify, GLogLevelFlags log_lvl) PV_NONNULL(1);
|
||||
void pvattest_hexdump(const void *data, size_t size, size_t width, const char *prefix, FILE *stream)
|
||||
PV_NONNULL(1, 5);
|
||||
int pvattest_hexdump(FILE *stream, GBytes *bytes, const size_t width, const char *prefix,
|
||||
const gboolean beautify) PV_NONNULL(1, 2);
|
||||
void pvattest_log_GError(const char *info, GError *error) PV_NONNULL(1);
|
||||
|
||||
#endif /* PVATTEST_LOG_H */
|
||||
|
||||
@@ -257,14 +257,63 @@ err_exit:
|
||||
}
|
||||
#endif /* PVATTEST_COMPILE_PERFORM */
|
||||
|
||||
static int fprint_verify_result(FILE *stream, const enum verify_output_format fmt,
|
||||
GBytes *config_uid, GBytes *additional_data)
|
||||
{
|
||||
switch (fmt) {
|
||||
case VERIFY_FMT_HUMAN:
|
||||
if (fprintf(stream, _("Attestation measurement verified\n")) < 0)
|
||||
return -1;
|
||||
if (fprintf(stream, _("Config UID:\n")) < 0)
|
||||
return -1;
|
||||
if (pvattest_hexdump(stream, config_uid, 0x10L, "0x", FALSE) < 0)
|
||||
return -1;
|
||||
if (fprintf(stream, _("\n")) < 0)
|
||||
return -1;
|
||||
|
||||
if (additional_data) {
|
||||
if (fprintf(stream, _("Additional Data:\n")) < 0)
|
||||
return -1;
|
||||
if (pvattest_hexdump(stream, additional_data, 0x60L, "0x", FALSE) < 0)
|
||||
return -1;
|
||||
if (fprintf(stream, _("\n")) < 0)
|
||||
return -1;
|
||||
}
|
||||
break;
|
||||
case VERIFY_FMT_YAML:
|
||||
if (fprintf(stream, "cuid: ") < 0)
|
||||
return -1;
|
||||
if (pvattest_hexdump(stream, config_uid, 0L, "'0x", FALSE) < 0)
|
||||
return -1;
|
||||
if (fprintf(stream, _("'\n")) < 0)
|
||||
return -1;
|
||||
|
||||
if (additional_data) {
|
||||
if (fprintf(stream, "add: ") < 0)
|
||||
return -1;
|
||||
|
||||
if (pvattest_hexdump(stream, additional_data, 0x0L, "'0x", FALSE) < 0)
|
||||
return -1;
|
||||
if (fprintf(stream, _("'\n")) < 0)
|
||||
return -1;
|
||||
}
|
||||
break;
|
||||
default:
|
||||
g_assert_not_reached();
|
||||
break;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
#define __PVATTEST_VERIFY_ERROR_MSG _("Attestation measurement verification failed")
|
||||
static int do_verify(pvattest_verify_config_t *verify_config)
|
||||
static int do_verify(const pvattest_verify_config_t *verify_config, const int appl_log_lvl)
|
||||
{
|
||||
g_autoptr(GBytes) user_data = NULL, uv_measurement = NULL, additional_data = NULL,
|
||||
image_hdr = NULL, calc_measurement = NULL, config_uid = NULL,
|
||||
meas_key = NULL, arp_key = NULL, nonce = NULL, serialized_arcb = NULL;
|
||||
g_autofree att_meas_ctx_t *measurement_hdr = NULL;
|
||||
g_autoptr(exchange_format_ctx_t) input_ctx = NULL;
|
||||
const char *err_prefix = __PVATTEST_VERIFY_ERROR_MSG;
|
||||
g_autoptr(GError) error = NULL;
|
||||
gboolean rc;
|
||||
|
||||
@@ -322,21 +371,37 @@ static int do_verify(pvattest_verify_config_t *verify_config)
|
||||
return PVATTEST_EXIT_MEASURE_NOT_VERIFIED;
|
||||
}
|
||||
|
||||
pvattest_log_info(_("Attestation measurement verified"));
|
||||
pvattest_log_info(_("Config UID:"));
|
||||
pvattest_log_bytes(g_bytes_get_data(config_uid, NULL), g_bytes_get_size(config_uid), 16L,
|
||||
"", FALSE, PVATTEST_LOG_LVL_INFO);
|
||||
/* Write human-readable output to stdout */
|
||||
if (appl_log_lvl >= PVATTEST_LOG_LVL_INFO) {
|
||||
if (fprint_verify_result(stdout, VERIFY_FMT_HUMAN, config_uid, additional_data) <
|
||||
0) {
|
||||
g_set_error(&error, PV_GLIB_HELPER_ERROR, PV_GLIB_HELPER_FILE_ERROR,
|
||||
"stdout: %s", g_strerror(errno));
|
||||
err_prefix = "Failed to write output";
|
||||
goto err_exit;
|
||||
}
|
||||
}
|
||||
|
||||
if (additional_data) {
|
||||
pvattest_log_info(_("\nAdditional Data:"));
|
||||
pvattest_log_bytes(g_bytes_get_data(additional_data, NULL),
|
||||
g_bytes_get_size(additional_data), 16L, "", FALSE,
|
||||
PVATTEST_LOG_LVL_INFO);
|
||||
/* Write to file */
|
||||
if (verify_config->output_path) {
|
||||
g_autoptr(FILE) output = pv_file_open(verify_config->output_path, "wx", &error);
|
||||
|
||||
if (!output) {
|
||||
err_prefix = "Failed to write output";
|
||||
goto err_exit;
|
||||
}
|
||||
if (fprint_verify_result(output, verify_config->output_fmt, config_uid,
|
||||
additional_data) < 0) {
|
||||
g_set_error(&error, PV_GLIB_HELPER_ERROR, PV_GLIB_HELPER_FILE_ERROR,
|
||||
"'%s': %s", verify_config->output_path, g_strerror(errno));
|
||||
err_prefix = "Failed to write output";
|
||||
goto err_exit;
|
||||
}
|
||||
}
|
||||
return EXIT_SUCCESS;
|
||||
|
||||
err_exit:
|
||||
pvattest_log_GError(__PVATTEST_VERIFY_ERROR_MSG, error);
|
||||
pvattest_log_GError(err_prefix, error);
|
||||
return EXIT_FAILURE;
|
||||
}
|
||||
|
||||
@@ -389,7 +454,7 @@ int main(int argc, char *argv[])
|
||||
break;
|
||||
#endif /* PVATTEST_COMPILE_PERFORM */
|
||||
case PVATTEST_SUBC_VERIFY:
|
||||
rc = do_verify(&config->verify);
|
||||
rc = do_verify(&config->verify, appl_log_lvl);
|
||||
break;
|
||||
default:
|
||||
g_return_val_if_reached(EXIT_FAILURE);
|
||||
|
||||
11
rust/.gitignore
vendored
Normal file
11
rust/.gitignore
vendored
Normal file
@@ -0,0 +1,11 @@
|
||||
# Generated by Cargo
|
||||
# will have compiled files and executables
|
||||
debug/
|
||||
target/
|
||||
|
||||
# These are backup files generated by rustfmt
|
||||
*.rs.bk
|
||||
|
||||
# Generated during make build can be removed at any point
|
||||
.check-dep-pvtools
|
||||
.check-cargo
|
||||
932
rust/Cargo.lock
generated
Normal file
932
rust/Cargo.lock
generated
Normal file
@@ -0,0 +1,932 @@
|
||||
# This file is automatically @generated by Cargo.
|
||||
# It is not intended for manual editing.
|
||||
version = 3
|
||||
|
||||
[[package]]
|
||||
name = "aho-corasick"
|
||||
version = "1.1.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b2969dcb958b36655471fc61f7e416fa76033bdd4bfed0678d8fee1e2d07a1f0"
|
||||
dependencies = [
|
||||
"memchr",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "anstream"
|
||||
version = "0.3.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "0ca84f3628370c59db74ee214b3263d58f9aadd9b4fe7e711fd87dc452b7f163"
|
||||
dependencies = [
|
||||
"anstyle",
|
||||
"anstyle-parse",
|
||||
"anstyle-query",
|
||||
"anstyle-wincon",
|
||||
"colorchoice",
|
||||
"is-terminal",
|
||||
"utf8parse",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "anstyle"
|
||||
version = "1.0.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "41ed9a86bf92ae6580e0a31281f65a1b1d867c0cc68d5346e2ae128dddfa6a7d"
|
||||
|
||||
[[package]]
|
||||
name = "anstyle-parse"
|
||||
version = "0.2.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "e765fd216e48e067936442276d1d57399e37bce53c264d6fefbe298080cb57ee"
|
||||
dependencies = [
|
||||
"utf8parse",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "anstyle-query"
|
||||
version = "1.0.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "5ca11d4be1bab0c8bc8734a9aa7bf4ee8316d462a08c6ac5052f888fef5b494b"
|
||||
dependencies = [
|
||||
"windows-sys 0.48.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "anstyle-wincon"
|
||||
version = "1.0.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "180abfa45703aebe0093f79badacc01b8fd4ea2e35118747e5811127f926e188"
|
||||
dependencies = [
|
||||
"anstyle",
|
||||
"windows-sys 0.48.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "anyhow"
|
||||
version = "1.0.71"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "9c7d0618f0e0b7e8ff11427422b64564d5fb0be1940354bfe2e0529b18a9d9b8"
|
||||
|
||||
[[package]]
|
||||
name = "autocfg"
|
||||
version = "1.1.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "d468802bab17cbc0cc575e9b053f41e72aa36bfa6b7f55e3529ffa43161b97fa"
|
||||
|
||||
[[package]]
|
||||
name = "bitflags"
|
||||
version = "1.3.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "bef38d45163c2f1dde094a7dfd33ccf595c92905c8f8f4fdc18d06fb1037718a"
|
||||
|
||||
[[package]]
|
||||
name = "bitflags"
|
||||
version = "2.4.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "327762f6e5a765692301e5bb513e0d9fef63be86bbc14528052b1cd3e6f03e07"
|
||||
|
||||
[[package]]
|
||||
name = "byteorder"
|
||||
version = "1.4.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "14c189c53d098945499cdfa7ecc63567cf3886b3332b312a5b4585d8d3a6a610"
|
||||
|
||||
[[package]]
|
||||
name = "cc"
|
||||
version = "1.0.79"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "50d30906286121d95be3d479533b458f87493b30a4b5f79a607db8f5d11aa91f"
|
||||
|
||||
[[package]]
|
||||
name = "cfg-if"
|
||||
version = "1.0.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "baf1de4339761588bc0619e3cbc0120ee582ebb74b53b4efbf79117bd2da40fd"
|
||||
|
||||
[[package]]
|
||||
name = "clap"
|
||||
version = "4.3.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "80672091db20273a15cf9fdd4e47ed43b5091ec9841bf4c6145c9dfbbcae09ed"
|
||||
dependencies = [
|
||||
"clap_builder",
|
||||
"clap_derive",
|
||||
"once_cell",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "clap_builder"
|
||||
version = "4.3.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "c1458a1df40e1e2afebb7ab60ce55c1fa8f431146205aa5f4887e0b111c27636"
|
||||
dependencies = [
|
||||
"anstream",
|
||||
"anstyle",
|
||||
"bitflags 1.3.2",
|
||||
"clap_lex",
|
||||
"strsim",
|
||||
"terminal_size",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "clap_derive"
|
||||
version = "4.3.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b8cd2b2a819ad6eec39e8f1d6b53001af1e5469f8c177579cdaeb313115b825f"
|
||||
dependencies = [
|
||||
"heck",
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "clap_lex"
|
||||
version = "0.5.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "2da6da31387c7e4ef160ffab6d5e7f00c42626fe39aea70a7b0f1773f7dd6c1b"
|
||||
|
||||
[[package]]
|
||||
name = "colorchoice"
|
||||
version = "1.0.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "acbf1af155f9b9ef647e42cdc158db4b64a1b61f743629225fde6f3e0be2a7c7"
|
||||
|
||||
[[package]]
|
||||
name = "curl"
|
||||
version = "0.4.44"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "509bd11746c7ac09ebd19f0b17782eae80aadee26237658a6b4808afb5c11a22"
|
||||
dependencies = [
|
||||
"curl-sys",
|
||||
"libc",
|
||||
"openssl-probe",
|
||||
"openssl-sys",
|
||||
"schannel",
|
||||
"socket2",
|
||||
"winapi",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "curl-sys"
|
||||
version = "0.4.72+curl-8.6.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "29cbdc8314c447d11e8fd156dcdd031d9e02a7a976163e396b548c03153bc9ea"
|
||||
dependencies = [
|
||||
"cc",
|
||||
"libc",
|
||||
"libz-sys",
|
||||
"openssl-sys",
|
||||
"pkg-config",
|
||||
"vcpkg",
|
||||
"windows-sys 0.52.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "errno"
|
||||
version = "0.3.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "4bcfec3a70f97c962c307b2d2c56e358cf1d00b558d74262b5f929ee8cc7e73a"
|
||||
dependencies = [
|
||||
"errno-dragonfly",
|
||||
"libc",
|
||||
"windows-sys 0.48.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "errno-dragonfly"
|
||||
version = "0.1.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "aa68f1b12764fab894d2755d2518754e71b4fd80ecfb822714a1206c2aab39bf"
|
||||
dependencies = [
|
||||
"cc",
|
||||
"libc",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "foreign-types"
|
||||
version = "0.3.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f6f339eb8adc052cd2ca78910fda869aefa38d22d5cb648e6485e4d3fc06f3b1"
|
||||
dependencies = [
|
||||
"foreign-types-shared",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "foreign-types-shared"
|
||||
version = "0.1.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "00b0228411908ca8685dba7fc2cdd70ec9990a6e753e89b6ac91a84c40fbaf4b"
|
||||
|
||||
[[package]]
|
||||
name = "getrandom"
|
||||
version = "0.2.10"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "be4136b2a15dd319360be1c07d9933517ccf0be8f16bf62a3bee4f0d618df427"
|
||||
dependencies = [
|
||||
"cfg-if",
|
||||
"libc",
|
||||
"wasi",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "hashbrown"
|
||||
version = "0.12.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "8a9ee70c43aaf417c914396645a0fa852624801b24ebb7ae78fe8272889ac888"
|
||||
|
||||
[[package]]
|
||||
name = "heck"
|
||||
version = "0.4.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "95505c38b4572b2d910cecb0281560f54b440a19336cbbcb27bf6ce6adc6f5a8"
|
||||
|
||||
[[package]]
|
||||
name = "hermit-abi"
|
||||
version = "0.3.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "fed44880c466736ef9a5c5b5facefb5ed0785676d0c02d612db14e54f0d84286"
|
||||
|
||||
[[package]]
|
||||
name = "indexmap"
|
||||
version = "1.9.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "bd070e393353796e801d209ad339e89596eb4c8d430d18ede6a1cced8fafbd99"
|
||||
dependencies = [
|
||||
"autocfg",
|
||||
"hashbrown",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "io-lifetimes"
|
||||
version = "1.0.11"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "eae7b9aee968036d54dce06cebaefd919e4472e753296daccd6d344e3e2df0c2"
|
||||
dependencies = [
|
||||
"hermit-abi",
|
||||
"libc",
|
||||
"windows-sys 0.48.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "is-terminal"
|
||||
version = "0.4.7"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "adcf93614601c8129ddf72e2d5633df827ba6551541c6d8c59520a371475be1f"
|
||||
dependencies = [
|
||||
"hermit-abi",
|
||||
"io-lifetimes",
|
||||
"rustix",
|
||||
"windows-sys 0.48.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "itoa"
|
||||
version = "1.0.6"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "453ad9f582a441959e5f0d088b02ce04cfe8d51a8eaf077f12ac6d3e94164ca6"
|
||||
|
||||
[[package]]
|
||||
name = "lazy_static"
|
||||
version = "1.4.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "e2abad23fbc42b3700f2f279844dc832adb2b2eb069b2df918f455c4e18cc646"
|
||||
|
||||
[[package]]
|
||||
name = "libc"
|
||||
version = "0.2.146"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f92be4933c13fd498862a9e02a3055f8a8d9c039ce33db97306fd5a6caa7f29b"
|
||||
|
||||
[[package]]
|
||||
name = "libz-sys"
|
||||
version = "1.1.9"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "56ee889ecc9568871456d42f603d6a0ce59ff328d291063a45cbdf0036baf6db"
|
||||
dependencies = [
|
||||
"cc",
|
||||
"libc",
|
||||
"pkg-config",
|
||||
"vcpkg",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "linux-raw-sys"
|
||||
version = "0.3.8"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "ef53942eb7bf7ff43a617b3e2c1c4a5ecf5944a7c1bc12d7ee39bbb15e5c1519"
|
||||
|
||||
[[package]]
|
||||
name = "log"
|
||||
version = "0.4.19"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b06a4cde4c0f271a446782e3eff8de789548ce57dbc8eca9292c27f4a42004b4"
|
||||
|
||||
[[package]]
|
||||
name = "memchr"
|
||||
version = "2.6.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f665ee40bc4a3c5590afb1e9677db74a508659dfd71e126420da8274909a0167"
|
||||
|
||||
[[package]]
|
||||
name = "once_cell"
|
||||
version = "1.19.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "3fdb12b2476b595f9358c5161aa467c2438859caa136dec86c26fdd2efe17b92"
|
||||
|
||||
[[package]]
|
||||
name = "openssl"
|
||||
version = "0.10.60"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "79a4c6c3a2b158f7f8f2a2fc5a969fa3a068df6fc9dbb4a43845436e3af7c800"
|
||||
dependencies = [
|
||||
"bitflags 2.4.1",
|
||||
"cfg-if",
|
||||
"foreign-types",
|
||||
"libc",
|
||||
"once_cell",
|
||||
"openssl-macros",
|
||||
"openssl-sys",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openssl-macros"
|
||||
version = "0.1.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "a948666b637a0f465e8564c73e89d4dde00d72d4d473cc972f390fc3dcee7d9c"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openssl-probe"
|
||||
version = "0.1.5"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "ff011a302c396a5197692431fc1948019154afc178baf7d8e37367442a4601cf"
|
||||
|
||||
[[package]]
|
||||
name = "openssl-sys"
|
||||
version = "0.9.96"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "3812c071ba60da8b5677cc12bcb1d42989a65553772897a7e0355545a819838f"
|
||||
dependencies = [
|
||||
"cc",
|
||||
"libc",
|
||||
"pkg-config",
|
||||
"vcpkg",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openssl_extensions"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"foreign-types",
|
||||
"libc",
|
||||
"log",
|
||||
"openssl",
|
||||
"openssl-sys",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "pkg-config"
|
||||
version = "0.3.27"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "26072860ba924cbfa98ea39c8c19b4dd6a4a25423dbdf219c1eca91aa0cf6964"
|
||||
|
||||
[[package]]
|
||||
name = "ppv-lite86"
|
||||
version = "0.2.17"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "5b40af805b3121feab8a3c29f04d8ad262fa8e0561883e7653e024ae4479e6de"
|
||||
|
||||
[[package]]
|
||||
name = "proc-macro2"
|
||||
version = "1.0.75"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "907a61bd0f64c2f29cd1cf1dc34d05176426a3f504a78010f08416ddb7b13708"
|
||||
dependencies = [
|
||||
"unicode-ident",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "pv"
|
||||
version = "1.0.0"
|
||||
dependencies = [
|
||||
"byteorder",
|
||||
"clap",
|
||||
"curl",
|
||||
"log",
|
||||
"openssl",
|
||||
"openssl_extensions",
|
||||
"pv_core",
|
||||
"serde",
|
||||
"serde_test",
|
||||
"thiserror",
|
||||
"utils",
|
||||
"zerocopy",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "pv_core"
|
||||
version = "1.0.0"
|
||||
dependencies = [
|
||||
"byteorder",
|
||||
"libc",
|
||||
"log",
|
||||
"serde",
|
||||
"serde_test",
|
||||
"thiserror",
|
||||
"utils",
|
||||
"zerocopy",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "pvapconfig"
|
||||
version = "0.9.0"
|
||||
dependencies = [
|
||||
"clap",
|
||||
"lazy_static",
|
||||
"openssl",
|
||||
"openssl-sys",
|
||||
"pv_core",
|
||||
"rand",
|
||||
"regex",
|
||||
"serde",
|
||||
"serde_yaml",
|
||||
"utils",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "pvsecret"
|
||||
version = "0.9.0"
|
||||
dependencies = [
|
||||
"anyhow",
|
||||
"clap",
|
||||
"log",
|
||||
"pv",
|
||||
"serde_yaml",
|
||||
"utils",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "quote"
|
||||
version = "1.0.35"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "291ec9ab5efd934aaf503a6466c5d5251535d108ee747472c3977cc5acc868ef"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rand"
|
||||
version = "0.8.5"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "34af8d1a0e25924bc5b7c43c079c942339d8f0a8b57c39049bef581b46327404"
|
||||
dependencies = [
|
||||
"libc",
|
||||
"rand_chacha",
|
||||
"rand_core",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rand_chacha"
|
||||
version = "0.3.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "e6c10a63a0fa32252be49d21e7709d4d4baf8d231c2dbce1eaa8141b9b127d88"
|
||||
dependencies = [
|
||||
"ppv-lite86",
|
||||
"rand_core",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "rand_core"
|
||||
version = "0.6.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "ec0be4795e2f6a28069bec0b5ff3e2ac9bafc99e6a9a7dc3547996c5c816922c"
|
||||
dependencies = [
|
||||
"getrandom",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "regex"
|
||||
version = "1.10.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "380b951a9c5e80ddfd6136919eef32310721aa4aacd4889a8d39124b026ab343"
|
||||
dependencies = [
|
||||
"aho-corasick",
|
||||
"memchr",
|
||||
"regex-automata",
|
||||
"regex-syntax",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "regex-automata"
|
||||
version = "0.4.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "5f804c7828047e88b2d32e2d7fe5a105da8ee3264f01902f796c8e067dc2483f"
|
||||
dependencies = [
|
||||
"aho-corasick",
|
||||
"memchr",
|
||||
"regex-syntax",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "regex-syntax"
|
||||
version = "0.8.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "c08c74e62047bb2de4ff487b251e4a92e24f48745648451635cec7d591162d9f"
|
||||
|
||||
[[package]]
|
||||
name = "rustix"
|
||||
version = "0.37.27"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "fea8ca367a3a01fe35e6943c400addf443c0f57670e6ec51196f71a4b8762dd2"
|
||||
dependencies = [
|
||||
"bitflags 1.3.2",
|
||||
"errno",
|
||||
"io-lifetimes",
|
||||
"libc",
|
||||
"linux-raw-sys",
|
||||
"windows-sys 0.48.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "ryu"
|
||||
version = "1.0.13"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f91339c0467de62360649f8d3e185ca8de4224ff281f66000de5eb2a77a79041"
|
||||
|
||||
[[package]]
|
||||
name = "schannel"
|
||||
version = "0.1.21"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "713cfb06c7059f3588fb8044c0fad1d09e3c01d225e25b9220dbfdcf16dbb1b3"
|
||||
dependencies = [
|
||||
"windows-sys 0.42.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "serde"
|
||||
version = "1.0.164"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "9e8c8cf938e98f769bc164923b06dce91cea1751522f46f8466461af04c9027d"
|
||||
dependencies = [
|
||||
"serde_derive",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "serde_derive"
|
||||
version = "1.0.164"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "d9735b638ccc51c28bf6914d90a2e9725b377144fc612c49a611fddd1b631d68"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "serde_test"
|
||||
version = "1.0.176"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "5a2f49ace1498612d14f7e0b8245519584db8299541dfe31a06374a828d620ab"
|
||||
dependencies = [
|
||||
"serde",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "serde_yaml"
|
||||
version = "0.9.21"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "d9d684e3ec7de3bf5466b32bd75303ac16f0736426e5a4e0d6e489559ce1249c"
|
||||
dependencies = [
|
||||
"indexmap",
|
||||
"itoa",
|
||||
"ryu",
|
||||
"serde",
|
||||
"unsafe-libyaml",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "socket2"
|
||||
version = "0.4.9"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "64a4a911eed85daf18834cfaa86a79b7d266ff93ff5ba14005426219480ed662"
|
||||
dependencies = [
|
||||
"libc",
|
||||
"winapi",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "strsim"
|
||||
version = "0.10.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "73473c0e59e6d5812c5dfe2a064a6444949f089e20eec9a2e5506596494e4623"
|
||||
|
||||
[[package]]
|
||||
name = "syn"
|
||||
version = "2.0.47"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "1726efe18f42ae774cc644f330953a5e7b3c3003d3edcecf18850fe9d4dd9afb"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"unicode-ident",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "terminal_size"
|
||||
version = "0.2.6"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "8e6bf6f19e9f8ed8d4048dc22981458ebcf406d67e94cd422e5ecd73d63b3237"
|
||||
dependencies = [
|
||||
"rustix",
|
||||
"windows-sys 0.48.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "thiserror"
|
||||
version = "1.0.40"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "978c9a314bd8dc99be594bc3c175faaa9794be04a5a5e153caba6915336cebac"
|
||||
dependencies = [
|
||||
"thiserror-impl",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "thiserror-impl"
|
||||
version = "1.0.40"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f9456a42c5b0d803c8cd86e73dd7cc9edd429499f37a3550d286d5e86720569f"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "unicode-ident"
|
||||
version = "1.0.9"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b15811caf2415fb889178633e7724bad2509101cde276048e013b9def5e51fa0"
|
||||
|
||||
[[package]]
|
||||
name = "unsafe-libyaml"
|
||||
version = "0.2.8"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "1865806a559042e51ab5414598446a5871b561d21b6764f2eabb0dd481d880a6"
|
||||
|
||||
[[package]]
|
||||
name = "utf8parse"
|
||||
version = "0.2.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "711b9620af191e0cdc7468a8d14e709c3dcdb115b36f838e601583af800a370a"
|
||||
|
||||
[[package]]
|
||||
name = "utils"
|
||||
version = "0.1.0"
|
||||
|
||||
[[package]]
|
||||
name = "vcpkg"
|
||||
version = "0.2.15"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "accd4ea62f7bb7a82fe23066fb0957d48ef677f6eeb8215f372f52e48bb32426"
|
||||
|
||||
[[package]]
|
||||
name = "wasi"
|
||||
version = "0.11.0+wasi-snapshot-preview1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "9c8d87e72b64a3b4db28d11ce29237c246188f4f51057d65a7eab63b7987e423"
|
||||
|
||||
[[package]]
|
||||
name = "winapi"
|
||||
version = "0.3.9"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "5c839a674fcd7a98952e593242ea400abe93992746761e38641405d28b00f419"
|
||||
dependencies = [
|
||||
"winapi-i686-pc-windows-gnu",
|
||||
"winapi-x86_64-pc-windows-gnu",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "winapi-i686-pc-windows-gnu"
|
||||
version = "0.4.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "ac3b87c63620426dd9b991e5ce0329eff545bccbbb34f3be09ff6fb6ab51b7b6"
|
||||
|
||||
[[package]]
|
||||
name = "winapi-x86_64-pc-windows-gnu"
|
||||
version = "0.4.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "712e227841d057c1ee1cd2fb22fa7e5a5461ae8e48fa2ca79ec42cfc1931183f"
|
||||
|
||||
[[package]]
|
||||
name = "windows-sys"
|
||||
version = "0.42.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "5a3e1820f08b8513f676f7ab6c1f99ff312fb97b553d30ff4dd86f9f15728aa7"
|
||||
dependencies = [
|
||||
"windows_aarch64_gnullvm 0.42.2",
|
||||
"windows_aarch64_msvc 0.42.2",
|
||||
"windows_i686_gnu 0.42.2",
|
||||
"windows_i686_msvc 0.42.2",
|
||||
"windows_x86_64_gnu 0.42.2",
|
||||
"windows_x86_64_gnullvm 0.42.2",
|
||||
"windows_x86_64_msvc 0.42.2",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "windows-sys"
|
||||
version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "677d2418bec65e3338edb076e806bc1ec15693c5d0104683f2efe857f61056a9"
|
||||
dependencies = [
|
||||
"windows-targets 0.48.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "windows-sys"
|
||||
version = "0.52.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "282be5f36a8ce781fad8c8ae18fa3f9beff57ec1b52cb3de0789201425d9a33d"
|
||||
dependencies = [
|
||||
"windows-targets 0.52.4",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "windows-targets"
|
||||
version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "7b1eb6f0cd7c80c79759c929114ef071b87354ce476d9d94271031c0497adfd5"
|
||||
dependencies = [
|
||||
"windows_aarch64_gnullvm 0.48.0",
|
||||
"windows_aarch64_msvc 0.48.0",
|
||||
"windows_i686_gnu 0.48.0",
|
||||
"windows_i686_msvc 0.48.0",
|
||||
"windows_x86_64_gnu 0.48.0",
|
||||
"windows_x86_64_gnullvm 0.48.0",
|
||||
"windows_x86_64_msvc 0.48.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "windows-targets"
|
||||
version = "0.52.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "7dd37b7e5ab9018759f893a1952c9420d060016fc19a472b4bb20d1bdd694d1b"
|
||||
dependencies = [
|
||||
"windows_aarch64_gnullvm 0.52.4",
|
||||
"windows_aarch64_msvc 0.52.4",
|
||||
"windows_i686_gnu 0.52.4",
|
||||
"windows_i686_msvc 0.52.4",
|
||||
"windows_x86_64_gnu 0.52.4",
|
||||
"windows_x86_64_gnullvm 0.52.4",
|
||||
"windows_x86_64_msvc 0.52.4",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "windows_aarch64_gnullvm"
|
||||
version = "0.42.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "597a5118570b68bc08d8d59125332c54f1ba9d9adeedeef5b99b02ba2b0698f8"
|
||||
|
||||
[[package]]
|
||||
name = "windows_aarch64_gnullvm"
|
||||
version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "91ae572e1b79dba883e0d315474df7305d12f569b400fcf90581b06062f7e1bc"
|
||||
|
||||
[[package]]
|
||||
name = "windows_aarch64_gnullvm"
|
||||
version = "0.52.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "bcf46cf4c365c6f2d1cc93ce535f2c8b244591df96ceee75d8e83deb70a9cac9"
|
||||
|
||||
[[package]]
|
||||
name = "windows_aarch64_msvc"
|
||||
version = "0.42.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "e08e8864a60f06ef0d0ff4ba04124db8b0fb3be5776a5cd47641e942e58c4d43"
|
||||
|
||||
[[package]]
|
||||
name = "windows_aarch64_msvc"
|
||||
version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b2ef27e0d7bdfcfc7b868b317c1d32c641a6fe4629c171b8928c7b08d98d7cf3"
|
||||
|
||||
[[package]]
|
||||
name = "windows_aarch64_msvc"
|
||||
version = "0.52.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "da9f259dd3bcf6990b55bffd094c4f7235817ba4ceebde8e6d11cd0c5633b675"
|
||||
|
||||
[[package]]
|
||||
name = "windows_i686_gnu"
|
||||
version = "0.42.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "c61d927d8da41da96a81f029489353e68739737d3beca43145c8afec9a31a84f"
|
||||
|
||||
[[package]]
|
||||
name = "windows_i686_gnu"
|
||||
version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "622a1962a7db830d6fd0a69683c80a18fda201879f0f447f065a3b7467daa241"
|
||||
|
||||
[[package]]
|
||||
name = "windows_i686_gnu"
|
||||
version = "0.52.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b474d8268f99e0995f25b9f095bc7434632601028cf86590aea5c8a5cb7801d3"
|
||||
|
||||
[[package]]
|
||||
name = "windows_i686_msvc"
|
||||
version = "0.42.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "44d840b6ec649f480a41c8d80f9c65108b92d89345dd94027bfe06ac444d1060"
|
||||
|
||||
[[package]]
|
||||
name = "windows_i686_msvc"
|
||||
version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "4542c6e364ce21bf45d69fdd2a8e455fa38d316158cfd43b3ac1c5b1b19f8e00"
|
||||
|
||||
[[package]]
|
||||
name = "windows_i686_msvc"
|
||||
version = "0.52.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "1515e9a29e5bed743cb4415a9ecf5dfca648ce85ee42e15873c3cd8610ff8e02"
|
||||
|
||||
[[package]]
|
||||
name = "windows_x86_64_gnu"
|
||||
version = "0.42.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "8de912b8b8feb55c064867cf047dda097f92d51efad5b491dfb98f6bbb70cb36"
|
||||
|
||||
[[package]]
|
||||
name = "windows_x86_64_gnu"
|
||||
version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "ca2b8a661f7628cbd23440e50b05d705db3686f894fc9580820623656af974b1"
|
||||
|
||||
[[package]]
|
||||
name = "windows_x86_64_gnu"
|
||||
version = "0.52.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "5eee091590e89cc02ad514ffe3ead9eb6b660aedca2183455434b93546371a03"
|
||||
|
||||
[[package]]
|
||||
name = "windows_x86_64_gnullvm"
|
||||
version = "0.42.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "26d41b46a36d453748aedef1486d5c7a85db22e56aff34643984ea85514e94a3"
|
||||
|
||||
[[package]]
|
||||
name = "windows_x86_64_gnullvm"
|
||||
version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "7896dbc1f41e08872e9d5e8f8baa8fdd2677f29468c4e156210174edc7f7b953"
|
||||
|
||||
[[package]]
|
||||
name = "windows_x86_64_gnullvm"
|
||||
version = "0.52.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "77ca79f2451b49fa9e2af39f0747fe999fcda4f5e241b2898624dca97a1f2177"
|
||||
|
||||
[[package]]
|
||||
name = "windows_x86_64_msvc"
|
||||
version = "0.42.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "9aec5da331524158c6d1a4ac0ab1541149c0b9505fde06423b02f5ef0106b9f0"
|
||||
|
||||
[[package]]
|
||||
name = "windows_x86_64_msvc"
|
||||
version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "1a515f5799fe4961cb532f983ce2b23082366b898e52ffbce459c86f67c8378a"
|
||||
|
||||
[[package]]
|
||||
name = "windows_x86_64_msvc"
|
||||
version = "0.52.4"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "32b752e52a2da0ddfbdbcc6fceadfeede4c939ed16d13e648833a61dfb611ed8"
|
||||
|
||||
[[package]]
|
||||
name = "zerocopy"
|
||||
version = "0.7.32"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "74d4d3961e53fa4c9a25a8637fc2bfaf2595b3d3ae34875568a5cf64787716be"
|
||||
dependencies = [
|
||||
"byteorder",
|
||||
"zerocopy-derive",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "zerocopy-derive"
|
||||
version = "0.7.32"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "9ce1b18ccd8e73a9321186f97e46f9f04b778851177567b1975109d26a08d2a6"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn",
|
||||
]
|
||||
16
rust/Cargo.toml
Normal file
16
rust/Cargo.toml
Normal file
@@ -0,0 +1,16 @@
|
||||
[workspace]
|
||||
members = [
|
||||
"pv",
|
||||
"pv_core",
|
||||
"pvapconfig",
|
||||
"pvsecret",
|
||||
"utils",
|
||||
]
|
||||
resolver = "2"
|
||||
|
||||
[workspace.package]
|
||||
edition = "2021"
|
||||
license = "MIT"
|
||||
|
||||
[profile.release]
|
||||
lto = true
|
||||
124
rust/Makefile
Normal file
124
rust/Makefile
Normal file
@@ -0,0 +1,124 @@
|
||||
include ../common.mak
|
||||
HAVE_CARGO ?= 1
|
||||
HAVE_OPENSSL ?= 1
|
||||
HAVE_LIBCURL ?= 1
|
||||
|
||||
INSTALL_TARGETS := skip-build
|
||||
BUILD_TARGETS := skip-build
|
||||
PV_BUILD_TARGETS := skip-pv-build
|
||||
CARGO_TARGETS :=
|
||||
PV_TARGETS :=
|
||||
CARGO_TEST_TARGETS :=
|
||||
|
||||
ifneq (${HAVE_CARGO},0)
|
||||
CARGO_TARGETS :=
|
||||
|
||||
BUILD_TARGETS = $(CARGO_TARGETS)
|
||||
INSTALL_TARGETS := install-rust-tools install-man
|
||||
CARGO_TEST_TARGETS = $(addsuffix .test, $(CARGO_TARGETS))
|
||||
|
||||
ifneq (${HAVE_OPENSSL},0)
|
||||
ifneq (${HAVE_LIBCURL},0)
|
||||
PV_TARGETS := pvsecret pvapconfig
|
||||
|
||||
PV_BUILD_TARGETS := $(PV_TARGETS)
|
||||
CARGO_TEST_TARGETS += $(addsuffix .test,pv $(PV_TARGETS))
|
||||
endif #LIBCURL
|
||||
endif #OPENSSL
|
||||
TEST_TARGETS := $(addsuffix _build,$(CARGO_TEST_TARGETS))
|
||||
endif #CARGO
|
||||
|
||||
BUILD_TARGETS += $(PV_BUILD_TARGETS)
|
||||
|
||||
# build release targets by default
|
||||
ifeq ("${D}","0")
|
||||
ALL_CARGOFLAGS += --release
|
||||
endif
|
||||
|
||||
# the cc crate uses these variables to compile c code. It does not open a shell
|
||||
# to call the compiler, so no echo etc. allowed here, just a path to a program
|
||||
$(BUILD_TARGETS) $(TEST_TARGETS) rust-test: CC = $(CC_SILENT)
|
||||
$(BUILD_TARGETS) $(TEST_TARGETS) rust-test: AR = $(AR_SILENT)
|
||||
|
||||
$(PV_TARGETS): .check-dep-pvtools
|
||||
$(PV_TARGETS) $(CARGO_TARGETS): .check-cargo .no-cross-compile
|
||||
$(CARGO_BUILD) --bin $@ $(ALL_CARGOFLAGS)
|
||||
.PHONY: $(PV_TARGETS) $(CARGO_TARGETS)
|
||||
|
||||
$(TEST_TARGETS): ALL_CARGOFLAGS += --no-run
|
||||
$(CARGO_TEST_TARGETS) $(TEST_TARGETS): .check-cargo .no-cross-compile
|
||||
$(CARGO_TEST) --package $(basename $@) --all-features $(ALL_CARGOFLAGS)
|
||||
.PHONY: $(TEST_TARGETS) $(CARGO_TEST_TARGETS)
|
||||
|
||||
skip-build:
|
||||
echo " SKIP rust-tools due to unresolved dependencies"
|
||||
|
||||
skip-pv-build:
|
||||
echo " SKIP rust-pv-tools due to unresolved dependencies"
|
||||
|
||||
all: $(BUILD_TARGETS)
|
||||
install: $(INSTALL_TARGETS)
|
||||
|
||||
print-rust-targets:
|
||||
echo $(BUILD_TARGETS)
|
||||
|
||||
clean:
|
||||
$(CARGO_CLEAN) ${ALL_CARGOFLAGS}
|
||||
$(RM) -- .check-dep-pvtools .detect-openssl.dep.c .check-cargo
|
||||
|
||||
rust-test: $(CARGO_TEST_TARGETS)
|
||||
|
||||
install-rust-tools: $(BUILD_TARGETS)
|
||||
$(INSTALL) -d -m 755 $(DESTDIR)$(USRBINDIR)
|
||||
$(foreach target,$(CARGO_TARGETS),\
|
||||
$(INSTALL) target/release/$(target) $(DESTDIR)$(USRBINDIR);)
|
||||
$(foreach target,$(PV_TARGETS),\
|
||||
$(INSTALL) target/release/$(target) $(DESTDIR)$(USRBINDIR);)
|
||||
|
||||
install-man:
|
||||
$(foreach target,$(CARGO_TARGETS),\
|
||||
$(INSTALL) -m 644 $(target)/man/*.1 -t $(DESTDIR)$(MANDIR)/man1;)
|
||||
$(foreach target,$(PV_TARGETS),\
|
||||
$(INSTALL) -m 644 $(target)/man/*.1 -t $(DESTDIR)$(MANDIR)/man1;)
|
||||
|
||||
.PHONY: all install clean skip-build install-rust-tools print-rust-targets install-man rust-test
|
||||
|
||||
.check-cargo:
|
||||
ifeq ($(shell command -v $(CARGO)),)
|
||||
$(call check_dep, \
|
||||
"rust/cargo", \
|
||||
"invalid-incl", \
|
||||
"cargo", \
|
||||
"HAVE_CARGO=0")
|
||||
endif
|
||||
touch $@
|
||||
|
||||
.no-cross-compile:
|
||||
ifneq ($(HOST_ARCH), $(BUILD_ARCH))
|
||||
$(error Cross compiling is not supported for rust code. Specify HAVE_CARGO=0 to disable rust compilation)
|
||||
endif
|
||||
.PHONY: .no-cross-compile
|
||||
|
||||
.detect-openssl.dep.c:
|
||||
echo "#include <openssl/evp.h>" > $@
|
||||
echo "#if OPENSSL_VERSION_NUMBER < 0x10101000L" >> $@
|
||||
echo " #error openssl version 1.1.1 is required" >> $@
|
||||
echo "#endif" >> $@
|
||||
echo "static void __attribute__((unused)) test(void) {" >> $@
|
||||
echo " EVP_MD_CTX *ctx = EVP_MD_CTX_new();" >> $@
|
||||
echo " EVP_MD_CTX_free(ctx);" >> $@
|
||||
echo "}" >> $@
|
||||
|
||||
.check-dep-pvtools: .detect-openssl.dep.c
|
||||
$(call check_dep, \
|
||||
"Rust-pv", \
|
||||
$^, \
|
||||
"openssl-devel / libssl-dev version >= 1.1.1", \
|
||||
"HAVE_OPENSSL=0", \
|
||||
"-I.")
|
||||
$(call check_dep, \
|
||||
"Rust-pv", \
|
||||
"curl/curl.h", \
|
||||
"libcurl-devel", \
|
||||
"HAVE_LIBCURL=0")
|
||||
touch $@
|
||||
146
rust/README.md
Normal file
146
rust/README.md
Normal file
@@ -0,0 +1,146 @@
|
||||
# s390-tools tools written in rust
|
||||
|
||||
## Setting up rust development and build environment
|
||||
Please refer to the official documentation to set up a working rust environment:
|
||||
https://www.rust-lang.org/learn/get-started
|
||||
|
||||
## Building rust code
|
||||
### s390-tools build system
|
||||
If `cargo` is installed a simple `make` should do the job. Note that,
|
||||
compiling rust programs take significantly longer than C code. To closely
|
||||
monitor the progress use `make V=1` By default release builds are made.
|
||||
|
||||
With `make CARGOFLAGS=<flags>` one can pass additional flags to cargo.
|
||||
With `make HAVE_CARGO=0` one can turn of any compilation that requires cargo.
|
||||
With `make CARGO=<...>` one can set the cargo binary
|
||||
|
||||
### cargo
|
||||
If you need to run cargo directly, `cd` to each project you want to build and
|
||||
issue your cargo commands. Do **NOT** forget to specify `--release` if you are
|
||||
building tools for a release. The s390-tools expect the environment variable
|
||||
`S390_TOOLS_RELEASE` to be present at build time. This is the version string the
|
||||
rust tools provide.
|
||||
|
||||
Tip: You can use `make version` to get the version string.
|
||||
|
||||
## Internal Libraries
|
||||
* __utils__ _Library for rust tools that bundles common stuff for the 390-tools_
|
||||
* provides a macro to get the `S390_TOOLS_RELEASE` string
|
||||
* provides macros for compile time assertions
|
||||
|
||||
* __pv_core__ _Library for pv tools, providing uvdevice access and utilities to send, receive and interpret various UV-calls._
|
||||
|
||||
* __pv__ _Library for pv tools, providing uvdevice access, encryption utilities, and utilities for generating UV-request_
|
||||
* requires openssl and libcurl
|
||||
* reexports ann symbols from __pv_core__
|
||||
* if no encryption utilities required, use __pv_core__
|
||||
|
||||
## Tools
|
||||
* __pvsecret__ _Manage secrets for IBM Secure Execution guests_
|
||||
|
||||
## Writing new tools
|
||||
We encourage to use Rust for new tools. However, for some use cases it makes
|
||||
sense to use C and C is still allowed to be used for a new tool/library.
|
||||
Exiting tools may be rewritten in Rust.
|
||||
|
||||
### What (third-party) crates can be used for s390-tools?
|
||||
A huge list of libraries are made available through Rusts' ecosystem and is one
|
||||
of many upsides. However, just like with Coding Style Guidelines, it is
|
||||
important to limit the usage of those libraries so that within a project,
|
||||
everyone is on the same page and that code written in Rust uses similar
|
||||
approaches. It makes it easier for code review and maintainability in general.
|
||||
|
||||
The following list of crates should cover a wide variety of use cases. This list
|
||||
is a start, but can change over time.
|
||||
|
||||
* [anyhow](https://crates.io/crates/anyhow)
|
||||
* Flexible concrete Error type built on std::error::Error
|
||||
* [byteorder](https://crates.io/crates/byteorder)
|
||||
* Library for reading/writing numbers in big-endian and little-endian.
|
||||
* [cfg-if](https://crates.io/crates/cfg-if)
|
||||
* A macro to ergonomically define an item depending on a large number of
|
||||
#[cfg] parameters. Structured like an if-else chain, the first matching
|
||||
branch is the item that gets emitted.
|
||||
* [clap](https://crates.io/crates/clap)
|
||||
* A simple to use, efficient, and full-featured Command Line Argument Parser
|
||||
* [curl](https://crates.io/crates/curl)
|
||||
* Rust bindings to libcurl for making HTTP requests
|
||||
* [libc](https://crates.io/crates/libc)
|
||||
* Raw FFI bindings to platform libraries like libc.
|
||||
* [log](https://crates.io/crates/log)
|
||||
* A lightweight logging facade for Rust
|
||||
* [openssl](https://crates.io/crates/openssl)
|
||||
* OpenSSL bindings
|
||||
* [serde](https://crates.io/crates/serde)
|
||||
* A generic serialization/deserialization framework
|
||||
* [serde_yaml](https://crates.io/crates/serde_yaml)
|
||||
* YAML data format for Serde
|
||||
* [thiserror](https://crates.io/crates/thiserror)
|
||||
* derive(Error)
|
||||
* [zerocopy](https://crates.io/crates/zerocopy)
|
||||
* Utilities for zero-copy parsing and serialization
|
||||
|
||||
Dependencies used by the crates listed above can be used, too.
|
||||
|
||||
### Add new tool
|
||||
To add a new tool issue `cargo new $TOOLNAME` in the `rust` directory.
|
||||
|
||||
Add the tool to the _s390-tools_ build system:
|
||||
```Makefile
|
||||
CARGO_TARGETS := $TOOLNAME
|
||||
```
|
||||
Add the library to the _s390-tools_ test list:
|
||||
```Makefile
|
||||
CARGO_TEST_TARGETS := $LIBNAME
|
||||
```
|
||||
|
||||
Add the tool/library to the cargo workspace:
|
||||
```toml
|
||||
[workspace]
|
||||
members = [
|
||||
"pv",
|
||||
"pvsecret",
|
||||
"$TOOLNAME",
|
||||
"$LIBNAME"
|
||||
"utils",
|
||||
]
|
||||
```
|
||||
|
||||
### Versions
|
||||
Do not communicate the version defined in the `toml` file by default. Use
|
||||
`release_string` from the `rust/utils` crate instead:
|
||||
|
||||
```rust
|
||||
use utils::release_string;
|
||||
|
||||
fn print_version() {
|
||||
println!(
|
||||
"{} version {}\nCopyright IBM Corp. 2023",
|
||||
env!("CARGO_PKG_NAME"), // collapses into the crates name
|
||||
release_string!() // this (very likely) collapses into a compile time constant
|
||||
);
|
||||
}
|
||||
```
|
||||
|
||||
### Unsafe rust
|
||||
rust allows you to write unsafe rust. Try to avoid it, it can make rust
|
||||
_unsafe_. If you need to, e.g. interacting with other languages like C, keep
|
||||
the `unsafe` block as small as possible and add a reasoning using `// SAFETY:
|
||||
`why this code is safe. Example:
|
||||
|
||||
```rust
|
||||
// Get the raw pointer and do an ioctl.
|
||||
//
|
||||
// SAFETY: the passed pointer points to a valid memory region that
|
||||
// contains the expected C-struct. The struct outlives this function.
|
||||
unsafe {
|
||||
let ptr: *mut ffi::uvio_ioctl_cb = cb as *mut _;
|
||||
rc = ioctl(raw_fd, cmd, ptr);
|
||||
}
|
||||
```
|
||||
|
||||
### Coding style
|
||||
Make `cargo fmt` and `cargo clippy` happy!
|
||||
|
||||
### Testing
|
||||
Prefer writing tests using rustdoc. Use explicit rust tests for more edge case tests.
|
||||
22
rust/pv/Cargo.toml
Normal file
22
rust/pv/Cargo.toml
Normal file
@@ -0,0 +1,22 @@
|
||||
[package]
|
||||
name = "pv"
|
||||
version = "1.0.0"
|
||||
edition.workspace = true
|
||||
license.workspace = true
|
||||
|
||||
[dependencies]
|
||||
byteorder = "1.3"
|
||||
clap = { version ="4", features = ["derive", "wrap_help"] }
|
||||
curl = "0.4.7"
|
||||
log = { version = "0.4.6", features = ["std", "release_max_level_debug"] }
|
||||
openssl = "0.10.49"
|
||||
serde = { version = "1.0.139", features = ["derive"] }
|
||||
thiserror = "1.0.33"
|
||||
utils = {path = "../utils"}
|
||||
zerocopy = { version="0.7", features = ["derive"] }
|
||||
|
||||
openssl_extensions = { path = "openssl_extensions" }
|
||||
pv_core = { path = "../pv_core" }
|
||||
|
||||
[dev-dependencies]
|
||||
serde_test = "1"
|
||||
12
rust/pv/openssl_extensions/Cargo.toml
Normal file
12
rust/pv/openssl_extensions/Cargo.toml
Normal file
@@ -0,0 +1,12 @@
|
||||
[package]
|
||||
name = "openssl_extensions"
|
||||
version = "0.1.0"
|
||||
edition.workspace = true
|
||||
license.workspace = true
|
||||
|
||||
[dependencies]
|
||||
foreign-types = "0.3.1"
|
||||
libc = {version = "0.2.49", features = [ "extra_traits"] }
|
||||
log = { version = "0.4.6", features = ["std", "release_max_level_debug"] }
|
||||
openssl = "0.10.49"
|
||||
openssl-sys = "0.9.85"
|
||||
45
rust/pv/openssl_extensions/build.rs
Normal file
45
rust/pv/openssl_extensions/build.rs
Normal file
@@ -0,0 +1,45 @@
|
||||
// SPDX-License-Identifier: MIT
|
||||
//
|
||||
// Copyright IBM Corp. 2023
|
||||
|
||||
#![allow(
|
||||
clippy::inconsistent_digit_grouping,
|
||||
clippy::uninlined_format_args,
|
||||
clippy::unusual_byte_groupings
|
||||
)]
|
||||
|
||||
use std::env;
|
||||
|
||||
fn main() {
|
||||
if let Ok(vars) = env::var("DEP_OPENSSL_CONF") {
|
||||
for var in vars.split(',') {
|
||||
println!("cargo:rustc-cfg=osslconf=\"{}\"", var);
|
||||
}
|
||||
}
|
||||
|
||||
if let Ok(version) = env::var("DEP_OPENSSL_VERSION_NUMBER") {
|
||||
let version = u64::from_str_radix(&version, 16).unwrap();
|
||||
|
||||
if version >= 0x1_00_01_00_0 {
|
||||
println!("cargo:rustc-cfg=ossl101");
|
||||
}
|
||||
if version >= 0x1_00_02_00_0 {
|
||||
println!("cargo:rustc-cfg=ossl102");
|
||||
}
|
||||
if version >= 0x1_01_00_00_0 {
|
||||
println!("cargo:rustc-cfg=ossl110");
|
||||
}
|
||||
if version >= 0x1_01_00_07_0 {
|
||||
println!("cargo:rustc-cfg=ossl110g");
|
||||
}
|
||||
if version >= 0x1_01_00_08_0 {
|
||||
println!("cargo:rustc-cfg=ossl110h");
|
||||
}
|
||||
if version >= 0x1_01_01_00_0 {
|
||||
println!("cargo:rustc-cfg=ossl111");
|
||||
}
|
||||
if version >= 0x3_00_00_00_0 {
|
||||
println!("cargo:rustc-cfg=ossl300");
|
||||
}
|
||||
}
|
||||
}
|
||||
120
rust/pv/openssl_extensions/src/akid.rs
Normal file
120
rust/pv/openssl_extensions/src/akid.rs
Normal file
@@ -0,0 +1,120 @@
|
||||
// SPDX-License-Identifier: MIT
|
||||
//
|
||||
// Copyright IBM Corp. 2023
|
||||
|
||||
use std::fmt;
|
||||
|
||||
use foreign_types::{foreign_type, ForeignType, ForeignTypeRef};
|
||||
use openssl::x509::{X509CrlRef, X509Ref};
|
||||
use std::ffi::c_int;
|
||||
|
||||
mod ffi {
|
||||
extern "C" {
|
||||
pub fn X509_check_akid(
|
||||
issuer: *const openssl_sys::X509,
|
||||
akid: *const openssl_sys::AUTHORITY_KEYID,
|
||||
) -> super::c_int;
|
||||
}
|
||||
}
|
||||
|
||||
foreign_type! {
|
||||
type CType = openssl_sys::AUTHORITY_KEYID;
|
||||
fn drop = openssl_sys::AUTHORITY_KEYID_free;
|
||||
|
||||
/// An `Authority Key Identifier`.
|
||||
pub struct Akid;
|
||||
/// Reference to `Akid`
|
||||
pub struct AkidRef;
|
||||
}
|
||||
|
||||
#[derive(Copy, Clone, PartialEq, Eq)]
|
||||
pub struct AkidCheckResult(c_int);
|
||||
|
||||
impl fmt::Debug for AkidCheckResult {
|
||||
fn fmt(&self, fmt: &mut fmt::Formatter<'_>) -> fmt::Result {
|
||||
fmt.debug_struct("AkidCheckResult")
|
||||
.field("code", &self.0)
|
||||
.finish()
|
||||
}
|
||||
}
|
||||
|
||||
impl AkidCheckResult {
|
||||
/// Creates an `AkidCheckResult` from a raw error number.
|
||||
unsafe fn from_raw(err: c_int) -> AkidCheckResult {
|
||||
AkidCheckResult(err)
|
||||
}
|
||||
|
||||
pub const OK: AkidCheckResult = AkidCheckResult(openssl_sys::X509_V_OK);
|
||||
pub const ERR_AKID_ISSUER_SERIAL_MISMATCH: AkidCheckResult =
|
||||
AkidCheckResult(openssl_sys::X509_V_ERR_AKID_ISSUER_SERIAL_MISMATCH);
|
||||
pub const ERR_AKID_SKID_MISMATCH: AkidCheckResult =
|
||||
AkidCheckResult(openssl_sys::X509_V_ERR_AKID_SKID_MISMATCH);
|
||||
}
|
||||
|
||||
impl AkidRef {
|
||||
///Check if the `Akid` matches the issuer
|
||||
///
|
||||
pub fn check(&self, issuer: &X509Ref) -> AkidCheckResult {
|
||||
unsafe {
|
||||
let res = ffi::X509_check_akid(issuer.as_ptr(), self.as_ptr());
|
||||
AkidCheckResult::from_raw(res)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
pub trait AkidExtension {
|
||||
fn akid(&self) -> Option<Akid>;
|
||||
}
|
||||
|
||||
impl AkidExtension for X509Ref {
|
||||
fn akid(&self) -> Option<Akid> {
|
||||
unsafe {
|
||||
let ptr = openssl_sys::X509_get_ext_d2i(
|
||||
self.as_ptr(),
|
||||
openssl_sys::NID_authority_key_identifier,
|
||||
std::ptr::null_mut(),
|
||||
std::ptr::null_mut(),
|
||||
);
|
||||
if ptr.is_null() {
|
||||
None
|
||||
} else {
|
||||
Some(Akid::from_ptr(ptr as *mut _))
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl AkidExtension for X509CrlRef {
|
||||
fn akid(&self) -> Option<Akid> {
|
||||
unsafe {
|
||||
let ptr = openssl_sys::X509_CRL_get_ext_d2i(
|
||||
self.as_ptr(),
|
||||
openssl_sys::NID_authority_key_identifier,
|
||||
std::ptr::null_mut(),
|
||||
std::ptr::null_mut(),
|
||||
);
|
||||
if ptr.is_null() {
|
||||
None
|
||||
} else {
|
||||
Some(Akid::from_ptr(ptr as *mut _))
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod test {
|
||||
use crate::test_utils::load_gen_cert;
|
||||
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn akid() {
|
||||
let cert = load_gen_cert("ibm.crt");
|
||||
let ca = load_gen_cert("root_ca.crt");
|
||||
|
||||
let akid = cert.akid().unwrap();
|
||||
let res = akid.check(&ca);
|
||||
assert_eq!(res, AkidCheckResult::OK);
|
||||
}
|
||||
}
|
||||
128
rust/pv/openssl_extensions/src/crl.rs
Normal file
128
rust/pv/openssl_extensions/src/crl.rs
Normal file
@@ -0,0 +1,128 @@
|
||||
// SPDX-License-Identifier: MIT
|
||||
//
|
||||
// Copyright IBM Corp. 2023
|
||||
|
||||
pub use crate::stackable_crl::*;
|
||||
use foreign_types::{ForeignType, ForeignTypeRef};
|
||||
use openssl::{
|
||||
error::ErrorStack,
|
||||
stack::{Stack, StackRef},
|
||||
x509::{
|
||||
store::{X509StoreBuilderRef, X509StoreRef},
|
||||
X509CrlRef, X509NameRef, X509Ref, X509StoreContextRef, X509,
|
||||
},
|
||||
};
|
||||
|
||||
pub fn opt_to_ptr<T: ForeignTypeRef>(o: Option<&T>) -> *mut T::CType {
|
||||
match o {
|
||||
None => std::ptr::null_mut(),
|
||||
Some(p) => p.as_ptr(),
|
||||
}
|
||||
}
|
||||
|
||||
mod ffi {
|
||||
extern "C" {
|
||||
#[cfg(ossl110)]
|
||||
pub fn X509_STORE_CTX_get1_crls(
|
||||
ctx: *mut openssl_sys::X509_STORE_CTX,
|
||||
nm: *mut openssl_sys::X509_NAME,
|
||||
) -> *mut openssl_sys::stack_st_X509_CRL;
|
||||
pub fn X509_STORE_add_crl(
|
||||
xs: *mut openssl_sys::X509_STORE,
|
||||
x: *mut openssl_sys::X509_CRL,
|
||||
) -> std::ffi::c_int;
|
||||
}
|
||||
}
|
||||
|
||||
pub trait X509StoreExtension {
|
||||
fn add_crl(&mut self, crl: &X509CrlRef) -> Result<(), ErrorStack>;
|
||||
}
|
||||
|
||||
impl X509StoreExtension for X509StoreBuilderRef {
|
||||
fn add_crl(&mut self, crl: &X509CrlRef) -> Result<(), ErrorStack> {
|
||||
unsafe {
|
||||
{
|
||||
let r = ffi::X509_STORE_add_crl(self.as_ptr(), crl.as_ptr());
|
||||
if r <= 0 {
|
||||
Err(ErrorStack::get())
|
||||
} else {
|
||||
Ok(())
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
pub trait X509StoreContextExtension {
|
||||
fn init_opt<F, T>(
|
||||
&mut self,
|
||||
trust: &X509StoreRef,
|
||||
cert: Option<&X509Ref>,
|
||||
cert_chain: Option<&StackRef<X509>>,
|
||||
with_context: F,
|
||||
) -> Result<T, ErrorStack>
|
||||
where
|
||||
F: FnOnce(&mut X509StoreContextRef) -> std::result::Result<T, ErrorStack>;
|
||||
fn crls(
|
||||
&mut self,
|
||||
subj: &X509NameRef,
|
||||
) -> std::result::Result<Stack<StackableX509Crl>, ErrorStack>;
|
||||
}
|
||||
|
||||
impl X509StoreContextExtension for X509StoreContextRef {
|
||||
fn init_opt<F, T>(
|
||||
&mut self,
|
||||
trust: &X509StoreRef,
|
||||
cert: Option<&X509Ref>,
|
||||
cert_chain: Option<&StackRef<X509>>,
|
||||
with_context: F,
|
||||
) -> Result<T, ErrorStack>
|
||||
where
|
||||
F: FnOnce(&mut X509StoreContextRef) -> std::result::Result<T, ErrorStack>,
|
||||
{
|
||||
struct Cleanup<'a>(&'a mut X509StoreContextRef);
|
||||
|
||||
impl<'a> Drop for Cleanup<'a> {
|
||||
fn drop(&mut self) {
|
||||
unsafe {
|
||||
openssl_sys::X509_STORE_CTX_cleanup(self.0.as_ptr());
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
unsafe {
|
||||
{
|
||||
let r = openssl_sys::X509_STORE_CTX_init(
|
||||
self.as_ptr(),
|
||||
trust.as_ptr(),
|
||||
opt_to_ptr(cert),
|
||||
opt_to_ptr(cert_chain),
|
||||
);
|
||||
if r <= 0 {
|
||||
Err(ErrorStack::get())
|
||||
} else {
|
||||
Ok(r)
|
||||
}
|
||||
}?;
|
||||
}
|
||||
let cleanup = Cleanup(self);
|
||||
with_context(cleanup.0)
|
||||
}
|
||||
/// Get all Certificate Revocation Lists with the subject currently stored
|
||||
#[cfg(ossl110)]
|
||||
fn crls(
|
||||
&mut self,
|
||||
subj: &X509NameRef,
|
||||
) -> std::result::Result<Stack<StackableX509Crl>, ErrorStack> {
|
||||
unsafe {
|
||||
{
|
||||
let r = ffi::X509_STORE_CTX_get1_crls(self.as_ptr(), subj.as_ptr());
|
||||
if r.is_null() {
|
||||
Err(ErrorStack::get())
|
||||
} else {
|
||||
Ok(Stack::from_ptr(r))
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
26
rust/pv/openssl_extensions/src/lib.rs
Normal file
26
rust/pv/openssl_extensions/src/lib.rs
Normal file
@@ -0,0 +1,26 @@
|
||||
// SPDX-License-Identifier: MIT
|
||||
//
|
||||
// Copyright IBM Corp. 2023
|
||||
|
||||
#![doc(hidden)]
|
||||
|
||||
/// Extensions to the rust-openssl crate, that are not upstream yet
|
||||
/// Upstreaming mostly work in progress
|
||||
pub mod akid;
|
||||
pub mod crl;
|
||||
mod stackable_crl;
|
||||
|
||||
/// Test if two CRLs are equal.
|
||||
///
|
||||
/// relates to X509_CRL_match
|
||||
/// (Upstream is missing that functionality)
|
||||
pub fn x509_crl_eq(a: &openssl::x509::X509CrlRef, b: &openssl::x509::X509CrlRef) -> bool {
|
||||
use foreign_types::ForeignTypeRef;
|
||||
let cmp = unsafe { openssl_sys::X509_CRL_match(a.as_ptr(), b.as_ptr()) };
|
||||
cmp == 0
|
||||
}
|
||||
|
||||
#[allow(dead_code)]
|
||||
mod test_utils {
|
||||
include!("../../src/test_utils.rs");
|
||||
}
|
||||
142
rust/pv/openssl_extensions/src/stackable_crl.rs
Normal file
142
rust/pv/openssl_extensions/src/stackable_crl.rs
Normal file
@@ -0,0 +1,142 @@
|
||||
// SPDX-License-Identifier: MIT
|
||||
//
|
||||
// Copyright IBM Corp. 2023
|
||||
|
||||
use std::{marker::PhantomData, ptr};
|
||||
|
||||
use foreign_types::{ForeignType, ForeignTypeRef};
|
||||
use openssl::{
|
||||
error::ErrorStack,
|
||||
stack::Stackable,
|
||||
x509::{X509Crl, X509CrlRef},
|
||||
};
|
||||
use openssl_sys::BIO_new_mem_buf;
|
||||
use std::ffi::c_int;
|
||||
|
||||
pub struct StackableX509Crl(*mut openssl_sys::X509_CRL);
|
||||
|
||||
impl ForeignType for StackableX509Crl {
|
||||
type CType = openssl_sys::X509_CRL;
|
||||
type Ref = X509CrlRef;
|
||||
unsafe fn from_ptr(ptr: *mut openssl_sys::X509_CRL) -> StackableX509Crl {
|
||||
StackableX509Crl(ptr)
|
||||
}
|
||||
fn as_ptr(&self) -> *mut openssl_sys::X509_CRL {
|
||||
self.0
|
||||
}
|
||||
}
|
||||
impl Drop for StackableX509Crl {
|
||||
fn drop(&mut self) {
|
||||
unsafe { (openssl_sys::X509_CRL_free)(self.0) }
|
||||
}
|
||||
}
|
||||
impl ::std::ops::Deref for StackableX509Crl {
|
||||
type Target = X509CrlRef;
|
||||
fn deref(&self) -> &X509CrlRef {
|
||||
unsafe { ForeignTypeRef::from_ptr(self.0) }
|
||||
}
|
||||
}
|
||||
impl ::std::ops::DerefMut for StackableX509Crl {
|
||||
fn deref_mut(&mut self) -> &mut X509CrlRef {
|
||||
unsafe { ForeignTypeRef::from_ptr_mut(self.0) }
|
||||
}
|
||||
}
|
||||
#[allow(clippy::explicit_auto_deref)]
|
||||
impl ::std::borrow::Borrow<X509CrlRef> for StackableX509Crl {
|
||||
fn borrow(&self) -> &X509CrlRef {
|
||||
&**self
|
||||
}
|
||||
}
|
||||
#[allow(clippy::explicit_auto_deref)]
|
||||
impl ::std::convert::AsRef<X509CrlRef> for StackableX509Crl {
|
||||
fn as_ref(&self) -> &X509CrlRef {
|
||||
&**self
|
||||
}
|
||||
}
|
||||
|
||||
impl Stackable for StackableX509Crl {
|
||||
type StackType = openssl_sys::stack_st_X509_CRL;
|
||||
}
|
||||
|
||||
pub struct MemBioSlice<'a>(*mut openssl_sys::BIO, PhantomData<&'a [u8]>);
|
||||
impl<'a> Drop for MemBioSlice<'a> {
|
||||
fn drop(&mut self) {
|
||||
unsafe {
|
||||
openssl_sys::BIO_free_all(self.0);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl<'a> MemBioSlice<'a> {
|
||||
pub fn new(buf: &'a [u8]) -> Result<MemBioSlice<'a>, ErrorStack> {
|
||||
openssl_sys::init();
|
||||
|
||||
assert!(buf.len() <= c_int::max_value() as usize);
|
||||
let bio = unsafe {
|
||||
{
|
||||
let r = BIO_new_mem_buf(buf.as_ptr() as *const _, buf.len() as c_int);
|
||||
if r.is_null() {
|
||||
Err(ErrorStack::get())
|
||||
} else {
|
||||
Ok(r)
|
||||
}
|
||||
}?
|
||||
};
|
||||
|
||||
Ok(MemBioSlice(bio, PhantomData))
|
||||
}
|
||||
|
||||
pub fn as_ptr(&self) -> *mut openssl_sys::BIO {
|
||||
self.0
|
||||
}
|
||||
}
|
||||
|
||||
impl StackableX509Crl {
|
||||
pub fn stack_from_pem(pem: &[u8]) -> Result<Vec<X509Crl>, ErrorStack> {
|
||||
unsafe {
|
||||
openssl_sys::init();
|
||||
let bio = MemBioSlice::new(pem)?;
|
||||
|
||||
let mut crls = vec![];
|
||||
loop {
|
||||
let r = openssl_sys::PEM_read_bio_X509_CRL(
|
||||
bio.as_ptr(),
|
||||
ptr::null_mut(),
|
||||
None,
|
||||
ptr::null_mut(),
|
||||
);
|
||||
if r.is_null() {
|
||||
let err = openssl_sys::ERR_peek_last_error();
|
||||
if openssl_sys::ERR_GET_LIB(err) as c_int == openssl_sys::ERR_LIB_PEM
|
||||
&& openssl_sys::ERR_GET_REASON(err) == openssl_sys::PEM_R_NO_START_LINE
|
||||
{
|
||||
openssl_sys::ERR_clear_error();
|
||||
break;
|
||||
}
|
||||
|
||||
return Err(ErrorStack::get());
|
||||
} else {
|
||||
crls.push(X509Crl::from_ptr(r));
|
||||
}
|
||||
}
|
||||
|
||||
Ok(crls)
|
||||
}
|
||||
}
|
||||
}
|
||||
impl From<X509Crl> for StackableX509Crl {
|
||||
fn from(value: X509Crl) -> Self {
|
||||
unsafe {
|
||||
openssl_sys::X509_CRL_up_ref(value.as_ptr());
|
||||
StackableX509Crl::from_ptr(value.as_ptr())
|
||||
}
|
||||
}
|
||||
}
|
||||
impl From<StackableX509Crl> for X509Crl {
|
||||
fn from(value: StackableX509Crl) -> Self {
|
||||
unsafe {
|
||||
openssl_sys::X509_CRL_up_ref(value.as_ptr());
|
||||
X509Crl::from_ptr(value.as_ptr())
|
||||
}
|
||||
}
|
||||
}
|
||||
1
rust/pv/openssl_extensions/tests/assets
Symbolic link
1
rust/pv/openssl_extensions/tests/assets
Symbolic link
@@ -0,0 +1 @@
|
||||
../../tests/assets
|
||||
245
rust/pv/src/brcb.rs
Normal file
245
rust/pv/src/brcb.rs
Normal file
@@ -0,0 +1,245 @@
|
||||
// SPDX-License-Identifier: MIT
|
||||
//
|
||||
// Copyright IBM Corp. 2023
|
||||
|
||||
use std::{
|
||||
io::{Read, Seek, SeekFrom::Current},
|
||||
mem::size_of,
|
||||
};
|
||||
|
||||
// (SE) boot request control block aka SE header
|
||||
use crate::{assert_size, static_assert, Error, Result, PAGESIZE};
|
||||
use log::debug;
|
||||
use pv_core::request::MagicValue;
|
||||
use zerocopy::{AsBytes, BigEndian, FromBytes, FromZeroes, U32, U64};
|
||||
|
||||
/// Struct containing all SE-header tags.
|
||||
///
|
||||
/// Contains:
|
||||
/// Page List Digest (pld)
|
||||
/// Address List Digest (ald)
|
||||
/// Tweak List Digest (tld)
|
||||
/// SE Header Tag (seht)
|
||||
///
|
||||
#[repr(C)]
|
||||
#[derive(Debug, Clone, Copy, AsBytes, PartialEq, Eq)]
|
||||
pub struct BootHdrTags {
|
||||
pld: [u8; BootHdrHead::DIGEST_SIZE],
|
||||
ald: [u8; BootHdrHead::DIGEST_SIZE],
|
||||
tld: [u8; BootHdrHead::DIGEST_SIZE],
|
||||
seht: [u8; BootHdrHead::SEHT_SIZE],
|
||||
}
|
||||
|
||||
/// Magiv value for a SE-(boot)header
|
||||
pub struct BootHdrMagic;
|
||||
impl MagicValue<8> for BootHdrMagic {
|
||||
const MAGIC: [u8; 8] = [0x49, 0x42, 0x4d, 0x53, 0x65, 0x63, 0x45, 0x78];
|
||||
}
|
||||
|
||||
impl BootHdrTags {
|
||||
/// Returns a reference to the SE-hdr tag of this [`BootHdrTags`].
|
||||
pub fn seht(&self) -> &[u8; 16] {
|
||||
&self.seht
|
||||
}
|
||||
|
||||
/// Creates a new [`BootHdrTags`]. Useful for writing tests.
|
||||
#[doc(hidden)]
|
||||
pub const fn new(pld: [u8; 64], ald: [u8; 64], tld: [u8; 64], seht: [u8; 16]) -> Self {
|
||||
Self {
|
||||
ald,
|
||||
tld,
|
||||
pld,
|
||||
seht,
|
||||
}
|
||||
}
|
||||
|
||||
/// returns false if no hdr found, true otherwise
|
||||
/// in the very unlikel case an IO error can appear
|
||||
/// when seeking to the beginning of the header
|
||||
fn seek_se_hdr_start<R>(img: &mut R) -> Result<bool>
|
||||
where
|
||||
R: Read + Seek,
|
||||
{
|
||||
const MAX_ITER: usize = 0x15;
|
||||
const BUF_SIZE: i64 = 8;
|
||||
static_assert!(BootHdrMagic::MAGIC.len() == BUF_SIZE as usize);
|
||||
|
||||
let mut buf = [0; BUF_SIZE as usize];
|
||||
for _ in [0; MAX_ITER] {
|
||||
match img.read_exact(&mut buf) {
|
||||
Ok(it) => it,
|
||||
Err(_) => return Ok(false),
|
||||
};
|
||||
|
||||
if BootHdrMagic::starts_with_magic(&buf) {
|
||||
// go back to the beginning of the header
|
||||
img.seek(Current(-BUF_SIZE))?;
|
||||
|
||||
return Ok(true);
|
||||
}
|
||||
// goto next page start
|
||||
// or report invalid file format if file ends "early"
|
||||
match img.seek(Current(PAGESIZE as i64 - BUF_SIZE)) {
|
||||
Ok(it) => it,
|
||||
Err(_) => return Ok(false),
|
||||
};
|
||||
}
|
||||
Ok(false)
|
||||
}
|
||||
|
||||
/// Deserializes a (SE) boot header and extracts the tags.
|
||||
///
|
||||
/// Searches for the header; if found extracts the tags.
|
||||
///
|
||||
/// # Errors
|
||||
///
|
||||
/// This function will return an error if `hdr` is not at least as long as the header specifies
|
||||
/// in bytes 12-15 or the first 8 bytes do not contain the magic value.
|
||||
pub fn from_se_image<R>(img: &mut R) -> Result<Self>
|
||||
where
|
||||
R: Read + Seek,
|
||||
{
|
||||
if !Self::seek_se_hdr_start(img)? {
|
||||
debug!("No boot hdr found");
|
||||
return Err(Error::InvBootHdr);
|
||||
}
|
||||
// read in the header
|
||||
let mut hdr = vec![0u8; size_of::<BootHdrHead>()];
|
||||
img.read_exact(&mut hdr)?;
|
||||
|
||||
let hdr_head = match BootHdrHead::read_from_prefix(hdr.as_mut_slice()) {
|
||||
Some(hdr) => hdr,
|
||||
None => {
|
||||
debug!("Boot hdr is to small");
|
||||
return Err(Error::InvBootHdr);
|
||||
}
|
||||
};
|
||||
|
||||
//Some sanity checks
|
||||
if !BootHdrMagic::starts_with_magic(&hdr) || hdr_head.version.get() != 0x100 {
|
||||
debug!("Inv magic or size");
|
||||
return Err(Error::InvBootHdr);
|
||||
}
|
||||
|
||||
//go to the Bot header tag
|
||||
img.seek(Current(
|
||||
hdr_head.size.get() as i64
|
||||
- size_of::<BootHdrHead>() as i64
|
||||
- BootHdrHead::SEHT_SIZE as i64,
|
||||
))?;
|
||||
|
||||
// read in the tag
|
||||
let mut seht = [0u8; BootHdrHead::SEHT_SIZE];
|
||||
img.read_exact(seht.as_mut_slice())?;
|
||||
|
||||
Ok(BootHdrTags {
|
||||
pld: hdr_head.pld,
|
||||
ald: hdr_head.ald,
|
||||
tld: hdr_head.tld,
|
||||
seht,
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
#[repr(C)]
|
||||
#[derive(Debug, Clone, FromBytes, FromZeroes)]
|
||||
struct BootHdrHead {
|
||||
magic: U64<BigEndian>,
|
||||
version: U32<BigEndian>,
|
||||
size: U32<BigEndian>,
|
||||
iv: [u8; 12],
|
||||
res1: u32,
|
||||
nks: U64<BigEndian>,
|
||||
sea: U64<BigEndian>,
|
||||
nep: U64<BigEndian>,
|
||||
pcf: U64<BigEndian>,
|
||||
user_pubkey: [u8; 160],
|
||||
pld: [u8; Self::DIGEST_SIZE],
|
||||
ald: [u8; Self::DIGEST_SIZE],
|
||||
tld: [u8; Self::DIGEST_SIZE],
|
||||
}
|
||||
assert_size!(BootHdrHead, 0x1A0);
|
||||
impl BootHdrHead {
|
||||
const DIGEST_SIZE: usize = 0x40;
|
||||
const SEHT_SIZE: usize = 0x10;
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use std::io::Cursor;
|
||||
|
||||
use super::*;
|
||||
use crate::get_test_asset;
|
||||
use crate::Error;
|
||||
|
||||
const EXP_HDR: BootHdrTags = BootHdrTags {
|
||||
pld: [
|
||||
0xbe, 0x94, 0xb5, 0xea, 0xb3, 0xc1, 0xb1, 0x18, 0xc7, 0x57, 0xd7, 0xdb, 0x7e, 0xa0,
|
||||
0xf6, 0x5d, 0x9b, 0x64, 0x82, 0x3a, 0x8d, 0xc5, 0x5b, 0xf8, 0xa8, 0x72, 0x5b, 0x58,
|
||||
0x07, 0x2d, 0x9d, 0x42, 0x58, 0xc5, 0x3e, 0x8a, 0x5d, 0xa8, 0x2d, 0xfb, 0x21, 0x92,
|
||||
0xd9, 0x1d, 0x07, 0xbc, 0x1c, 0x39, 0xb9, 0x5d, 0x63, 0x21, 0xd3, 0xba, 0x16, 0xa7,
|
||||
0x51, 0xa6, 0xe3, 0xe3, 0x2f, 0x3e, 0x01, 0x61,
|
||||
],
|
||||
ald: [
|
||||
0x28, 0x58, 0xc3, 0x36, 0x8b, 0x2a, 0x0a, 0xf0, 0xc5, 0xea, 0x0f, 0xde, 0x79, 0x05,
|
||||
0xeb, 0x15, 0xaf, 0x9c, 0xd1, 0xdd, 0x73, 0x71, 0x65, 0x93, 0x3c, 0xda, 0xa2, 0xb8,
|
||||
0x50, 0xb6, 0xa8, 0xe2, 0xf0, 0xf4, 0x2c, 0x7b, 0x36, 0xdd, 0x53, 0x81, 0x09, 0x62,
|
||||
0x88, 0xdc, 0x09, 0x2d, 0xaa, 0x8a, 0x6f, 0xac, 0xec, 0x25, 0x34, 0x13, 0x7b, 0xc9,
|
||||
0x4c, 0xa8, 0x0b, 0xda, 0x4f, 0xcb, 0x93, 0x28,
|
||||
],
|
||||
tld: [
|
||||
0x48, 0x60, 0xeb, 0xcf, 0x7b, 0x9d, 0x24, 0xeb, 0x90, 0x9a, 0x79, 0x53, 0x56, 0xad,
|
||||
0x32, 0xc9, 0x36, 0xb6, 0x21, 0x65, 0x98, 0x8a, 0x9f, 0xfc, 0xd6, 0x61, 0x70, 0xdb,
|
||||
0xc5, 0x90, 0xc2, 0x30, 0x10, 0xd7, 0x95, 0x2f, 0xa8, 0x82, 0xd1, 0xbb, 0x79, 0x55,
|
||||
0x8f, 0x9b, 0xe0, 0xa5, 0x49, 0xd8, 0xd7, 0xa9, 0x4a, 0xe7, 0x20, 0xe5, 0xc0, 0x76,
|
||||
0x0a, 0x82, 0x5d, 0x47, 0x9f, 0xe6, 0x7a, 0xf5,
|
||||
],
|
||||
seht: [
|
||||
0x92, 0x30, 0x9d, 0x45, 0x89, 0xb9, 0xa8, 0x5b, 0x42, 0x7f, 0x87, 0x53, 0x17, 0x1d,
|
||||
0x15, 0x20,
|
||||
],
|
||||
};
|
||||
|
||||
#[test]
|
||||
fn from_se_image_hdr() {
|
||||
let bin_hdr = get_test_asset!("exp/secure_guest.hdr");
|
||||
let hdr_tags = BootHdrTags::from_se_image(&mut Cursor::new(*bin_hdr)).unwrap();
|
||||
assert_eq!(hdr_tags, EXP_HDR);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn from_se_image_fail() {
|
||||
let bin_hdr = get_test_asset!("exp/secure_guest.hdr");
|
||||
let short_hdr = &bin_hdr[1..];
|
||||
|
||||
assert!(matches!(
|
||||
BootHdrTags::from_se_image(&mut Cursor::new(short_hdr)),
|
||||
Err(Error::InvBootHdr)
|
||||
));
|
||||
|
||||
// mess up magic
|
||||
let mut bin_hdr_copy = *bin_hdr;
|
||||
bin_hdr_copy.swap(0, 1);
|
||||
assert!(matches!(
|
||||
BootHdrTags::from_se_image(&mut Cursor::new(bin_hdr_copy)),
|
||||
Err(Error::InvBootHdr)
|
||||
));
|
||||
|
||||
//header is at a non expected position
|
||||
let mut img = vec![0u8; PAGESIZE];
|
||||
img[0x008..0x288].copy_from_slice(bin_hdr);
|
||||
assert!(matches!(
|
||||
BootHdrTags::from_se_image(&mut Cursor::new(img)),
|
||||
Err(Error::InvBootHdr)
|
||||
));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn from_se_image_img() {
|
||||
let mut img = vec![0u8; 0x13000];
|
||||
let bin_hdr = get_test_asset!("exp/secure_guest.hdr");
|
||||
img[0x12000..0x12280].copy_from_slice(bin_hdr);
|
||||
let hdr_tags = BootHdrTags::from_se_image(&mut Cursor::new(img)).unwrap();
|
||||
assert_eq!(hdr_tags, EXP_HDR);
|
||||
}
|
||||
}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user