From: Vitaly Chikunov <vt@altlinux.org>
To: Mimi Zohar <zohar@linux.vnet.ibm.com>,
Dmitry Kasatkin <dmitry.kasatkin@gmail.com>,
linux-integrity@vger.kernel.org
Subject: [PATCH v8 0/2] ima-evm-utils: Add some tests for evmctl
Date: Fri, 27 Mar 2020 07:25:13 +0300 [thread overview]
Message-ID: <20200327042515.22315-1-vt@altlinux.org> (raw)
This series adds simple evmctl tests for hash, sign, and verify operations.
Signed-off-by: Vitaly Chikunov <vt@altlinux.org>
---
Changelog since v7:
- Absence of key file cause test skip instead of fail.
- Mono patch is split into two by Mimi Zohar request.
Changelog since v6:
- ima_hash.test: Compare generated hashes with known values.
I found that on power8 qemu with default -cpu calculates hashes wrongly.
For exmaple: `openssl dgst -sha224 -hex /dev/null' results in
83b2514951547ee00c7062fa3eb42079ff19f280ec81eedbdb0e3997 instead of
d14a028c2a3a2bc9476102bb288234c415a2b01f828ea62ac5b3e42f.
- Make `_keyid' use temporary files to not rely on presence of `/des/stdout'.
- evm sign: add `--generation 0' option.
I found that on overlay fs (with ext4 over 9p) FS_IOC_GETVERSION does
not work.
- gen-keys.sh: allows `force' argument to regenerate all test keys.
Changelog since v5:
- Fix tests if gost-engine is not present. Thx to Mimi Zohar for testing on
Xenial.
Changelog since v4:
- Fix bugs found by Mimi Zohar:
- Fix typos in variable names
- Fix `-out -' in asn1parse for openssl 1.0.x
Changelog since v3:
- Apply changes based on some suggestions from Petr Vorel, such as
- Add .gitignore
- Do not color output if stdout is not tty.
- Fix blkid error with --uuid option.
- Remove or change some comments
- Replace ENGINE with EVMCTL_ENGINE and OPENSSL_ENGINE.
- All tests pass over next branch.
Changelog since v2:
- ima_sign.test and ima_verify.test merged into sign_verify.test
which is also able to test evm signatures.
- Apply Mimi Zohar suggestions regarding commenting, variable renaming,
code rearranging, etc. with intent to simplify the code and review.
Changelog since v1:
- Apply suggestions by Petr Vorel:
- Rename function names and variables to be more understandable.
- Rename tests/functions to tests/functions.sh.
- Define exit codes (77, 99, ...) as variables.
- Added more comments and remove single letter variables (for Mimi Zohar).
- Move getfattr check into function.
- Move evmctl run and check into single function.
- Add sign/verify tests for v1 signatures.
- Minor improvements.
- Since I still edit all 5 files I did not split the patch into multiple
commits to separate the files, otherwise editing will become too
complicated, as I ought to continuously rebase and edit different
commits. This was really non-productive suggestion.
Vitaly Chikunov (2):
ima-evm-utils: Add some tests for evmctl
ima-evm-utils: Add sign/verify tests for evmctl
.gitignore | 2 +-
Makefile.am | 2 +-
configure.ac | 1 +
tests/.gitignore | 16 +++
tests/Makefile.am | 12 ++
tests/functions.sh | 272 ++++++++++++++++++++++++++++++++++++
tests/gen-keys.sh | 97 +++++++++++++
tests/ima_hash.test | 80 +++++++++++
tests/sign_verify.test | 364 +++++++++++++++++++++++++++++++++++++++++++++++++
9 files changed, 844 insertions(+), 2 deletions(-)
create mode 100644 tests/.gitignore
create mode 100644 tests/Makefile.am
create mode 100755 tests/functions.sh
create mode 100755 tests/gen-keys.sh
create mode 100755 tests/ima_hash.test
create mode 100755 tests/sign_verify.test
--
2.11.0
next reply other threads:[~2020-03-27 4:25 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-03-27 4:25 Vitaly Chikunov [this message]
2020-03-27 4:25 ` [PATCH v8 1/2] ima-evm-utils: Add some tests for evmctl Vitaly Chikunov
[not found] ` <f9b36972-df5d-db9a-d840-52e9ff76d271@linux.microsoft.com>
2020-03-30 16:29 ` Lakshmi Ramasubramanian
2020-03-30 17:11 ` Vitaly Chikunov
2020-03-31 14:25 ` Mimi Zohar
2020-03-31 15:14 ` Vitaly Chikunov
2020-03-31 16:04 ` Mimi Zohar
2020-03-27 4:25 ` [PATCH v8 2/2] ima-evm-utils: Add sign/verify " Vitaly Chikunov
[not found] ` <98cfccc0-2191-6072-aebe-296e6e150e0c@linux.microsoft.com>
2020-03-30 16:29 ` Lakshmi Ramasubramanian
2020-03-30 17:16 ` Vitaly Chikunov
2020-04-01 18:00 ` Mimi Zohar
2020-04-02 7:19 ` Vitaly Chikunov
2020-04-02 11:14 ` Mimi Zohar
[not found] ` <d39b433e-4504-d0a4-116f-dd33ca238f7f@linux.microsoft.com>
2020-03-30 16:28 ` [PATCH v8 0/2] ima-evm-utils: Add some " Lakshmi Ramasubramanian
2020-03-30 17:47 ` James Bottomley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200327042515.22315-1-vt@altlinux.org \
--to=vt@altlinux.org \
--cc=dmitry.kasatkin@gmail.com \
--cc=linux-integrity@vger.kernel.org \
--cc=zohar@linux.vnet.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).