From patchwork Tue Jul 16 00:03:02 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Dimitri John Ledkov X-Patchwork-Id: 1132353 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=none (mailfrom) smtp.mailfrom=lists.ubuntu.com (client-ip=91.189.94.19; helo=huckleberry.canonical.com; envelope-from=kernel-team-bounces@lists.ubuntu.com; receiver=) Authentication-Results: ozlabs.org; dmarc=none (p=none dis=none) header.from=ubuntu.com Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (1024-bit key; secure) header.d=surgut.co.uk header.i=@surgut.co.uk header.b="CiM4oY7C"; dkim-atps=neutral Received: from huckleberry.canonical.com (huckleberry.canonical.com [91.189.94.19]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 45ngbN5Jjnz9sN4; Tue, 16 Jul 2019 10:03:28 +1000 (AEST) Received: from localhost ([127.0.0.1] helo=huckleberry.canonical.com) by huckleberry.canonical.com with esmtp (Exim 4.86_2) (envelope-from ) id 1hnAwH-0001kM-7t; Tue, 16 Jul 2019 00:03:25 +0000 Received: from mail-wr1-f66.google.com ([209.85.221.66]) by huckleberry.canonical.com with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.86_2) (envelope-from ) id 1hnAwF-0001kG-5K for kernel-team@lists.ubuntu.com; Tue, 16 Jul 2019 00:03:23 +0000 Received: by mail-wr1-f66.google.com with SMTP id r1so18876100wrl.7 for ; Mon, 15 Jul 2019 17:03:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=surgut.co.uk; s=google; h=sender:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=VdEZ+B5gh0vW2nmW/fr6fiwug5gmCEB0sOBpNSQm7Dc=; b=CiM4oY7CigUFFtBzGMu9Y2lMpMBt/T4vxFcMnlVSqWKYjZ7uq6WuHNwluoqBzJAVor wg6Vv8XBnH7ozpgIC3bawqZEO0Cpl7+NIz/cJDI+ZUZKSGU9ju49NLr4mD2hV4ezDOZW NTsRcaQqSJgKOSvogJZUKvwu4yoJ0qbUh7lgM= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :mime-version:content-transfer-encoding; bh=VdEZ+B5gh0vW2nmW/fr6fiwug5gmCEB0sOBpNSQm7Dc=; b=MxPmkl2oi9yUBx4v+k1TaUWni9FR5yHFyy6omoD80E37X/iYU3I8/+ZFsiUr9YWuvb nYRfVGAoVoy3ZuGS/bl/gKOn7dTsmAscnvphTrW7XDlSIXSinN4h/nnVTpaKzaoj8Vlk j8rjguQj1Z6rW/AeGmoFbUvNwtJuF06ZMlTXXwf/WbMHkJ+Bu0LmFnglqHJ8XhdJugNf zhx4JbFHUqjjHRK5Lo8zaTA6Lr/Z8vX7SODuIW2EtflJx0bpIX87wnMw4Ak0IcxXuS33 1tfcx1hSTEuGJjGOep8ueozQ7r+XCbRCfgtdKPadH4cPS8CaHPvfAXiExK7tKcAJavFd ePHA== X-Gm-Message-State: APjAAAXXAp+0TehDLxRNX7CbuKqNgiNXdY+Z0m21oe9J+zbzOVGoYPcH RpYjWb7UieewXEoh6fl77Q1OZVro X-Google-Smtp-Source: APXvYqyU4Oo2OtgmS9uKaj8HxEQd03Jx5k8HiLYfd+H567D14T9Peak3sr5cJNGifR6cSuOyHyMrqg== X-Received: by 2002:a5d:4e4d:: with SMTP id r13mr32726975wrt.295.1563235402364; Mon, 15 Jul 2019 17:03:22 -0700 (PDT) Received: from localhost (9.a.8.f.7.f.e.f.f.f.2.3.f.4.a.1.1.4.e.1.c.6.e.d.0.b.8.0.1.0.0.2.ip6.arpa. [2001:8b0:de6c:1e41:1a4f:32ff:fef7:f8a9]) by smtp.gmail.com with ESMTPSA id i13sm18475109wrr.73.2019.07.15.17.03.21 (version=TLS1_3 cipher=AEAD-AES256-GCM-SHA384 bits=256/256); Mon, 15 Jul 2019 17:03:21 -0700 (PDT) From: Dimitri John Ledkov To: kernel-team@lists.ubuntu.com Subject: [PATCH linux-signed][EOAN] UBUNTU: enable secureboot signing on s390x. Date: Tue, 16 Jul 2019 01:03:02 +0100 Message-Id: <20190716000301.15366-1-xnox@ubuntu.com> X-Mailer: git-send-email 2.20.1 MIME-Version: 1.0 X-BeenThere: kernel-team@lists.ubuntu.com X-Mailman-Version: 2.1.20 Precedence: list List-Id: Kernel team discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Dimitri John Ledkov Errors-To: kernel-team-bounces@lists.ubuntu.com Sender: "kernel-team" Bug-Link: https://bugs.launchpad.net/bugs/1829749 Signed-off-by: Dimitri John Ledkov --- debian/control.stub | 6 +++--- debian/rules | 8 +++++++- 2 files changed, 10 insertions(+), 4 deletions(-) diff --git a/debian/control.stub b/debian/control.stub index a4b98d6..b998763 100644 --- a/debian/control.stub +++ b/debian/control.stub @@ -13,7 +13,7 @@ Build-Depends-Arch: Standards-Version: 3.9.4 Package: linux-image-ABI-generic -Architecture: amd64 arm64 ppc64el +Architecture: amd64 arm64 ppc64el s390x Depends: ${unsigned:Depends} Recommends: ${unsigned:Recommends} Suggests: ${unsigned:Suggests} @@ -41,7 +41,7 @@ Package-Type: udeb Section: debian-installer Priority: extra Provides: kernel-signed-image -Architecture: amd64 arm64 ppc64el +Architecture: amd64 arm64 ppc64el s390x Built-Using: UNSIGNED_SRC_PACKAGE (= UNSIGNED_SRC_VERSION) Description: Signed kernel image generic for the Debian installer A kernel image for generic. This version of it is signed with @@ -50,7 +50,7 @@ Description: Signed kernel image generic for the Debian installer Package: linux-image-ABI-generic-dbgsym Section: devel -Architecture: amd64 arm64 ppc64el +Architecture: amd64 arm64 ppc64el s390x Depends: linux-image-unsigned-ABI-generic-dbgsym Description: Signed kernel image generic A link to the debugging symbols for the generic signed kernel. diff --git a/debian/rules b/debian/rules index 69f2678..da653f0 100755 --- a/debian/rules +++ b/debian/rules @@ -60,7 +60,13 @@ override_dh_auto_build: [ ! -f "$$s" ] && continue; \ chmod 600 "$$s"; \ base=$$(echo "$$s" | sed -e 's/.opal.sig//'); \ - cat "$$base.opal" "$$s" >"../SIGNED/$$base";\ + cat "$$base.opal" "$$s" >"../SIGNED/$$base"; \ + done \ + for s in *.sipl.sig; do \ + [ ! -f "$$s" ] && continue; \ + chmod 600 "$$s"; \ + base=$$(echo "$$s" | sed -e 's/.sipl.sig//'); \ + cat "$$base.sipl" "$$s" >"../SIGNED/$$base"; \ done \ )