From: Luca Boccassi <luca.boccassi@gmail.com>
To: Eric Biggers <ebiggers@kernel.org>
Cc: linux-fscrypt@vger.kernel.org
Subject: Re: [fsverity-utils PATCH v2] Add digest sub command
Date: Mon, 26 Oct 2020 18:12:10 +0000 [thread overview]
Message-ID: <8a5b5f20576841f13ad67f777d56b4e5d0819558.camel@gmail.com> (raw)
In-Reply-To: <20201026174814.GF858@sol.localdomain>
On Mon, 2020-10-26 at 10:48 -0700, Eric Biggers wrote:
> On Mon, Oct 26, 2020 at 11:40:07AM +0000, luca.boccassi@gmail.com wrote:
> > +/* Compute a file's fs-verity measurement, then print it in hex format. */
> > +int fsverity_cmd_digest(const struct fsverity_command *cmd,
> > + int argc, char *argv[])
> > +{
> > + struct filedes file = { .fd = -1 };
> > + u8 *salt = NULL;
> > + struct libfsverity_merkle_tree_params tree_params = { .version = 1 };
> > + struct libfsverity_digest *digest = NULL;
> > + struct fsverity_signed_digest *d = NULL;
> > + char digest_hex[FS_VERITY_MAX_DIGEST_SIZE * 2 + sizeof(struct fsverity_signed_digest) * 2 + 1];
> > + bool compact = false, for_builtin_sig = false;
> > + int status;
> > + int c;
> > +
> > + while ((c = getopt_long(argc, argv, "", longopts, NULL)) != -1) {
> > + switch (c) {
> > + case OPT_HASH_ALG:
> > + if (!parse_hash_alg_option(optarg,
> > + &tree_params.hash_algorithm))
> > + goto out_usage;
> > + break;
> > + case OPT_BLOCK_SIZE:
> > + if (!parse_block_size_option(optarg,
> > + &tree_params.block_size))
> > + goto out_usage;
> > + break;
> > + case OPT_SALT:
> > + if (!parse_salt_option(optarg, &salt,
> > + &tree_params.salt_size))
> > + goto out_usage;
> > + tree_params.salt = salt;
> > + break;
> > + case OPT_COMPACT:
> > + compact = true;
> > + break;
> > + case OPT_FOR_BUILTIN_SIG:
> > + for_builtin_sig = true;
> > + break;
> > + default:
> > + goto out_usage;
> > + }
> > + }
> > +
> > + argv += optind;
> > + argc -= optind;
> > +
> > + if (argc != 1)
> > + goto out_usage;
>
> I think this should allow specifying multiple files, like 'fsverity measure'
> does. 'fsverity measure' is intended to behave like the sha256sum program.
Added in v3.
> > + /* The kernel expects more than the digest as the signed payload */
> > + if (for_builtin_sig) {
> > + d = xzalloc(sizeof(*d) + digest->digest_size);
> > + if (!d)
> > + goto out_err;
>
> No need to check the return value of xzalloc(), since it exits on error.
Removed in v3.
> > + if (compact)
> > + printf("%s", digest_hex);
> > + else
> > + printf("File '%s' (%s:%s)\n", argv[0],
> > + libfsverity_get_hash_name(tree_params.hash_algorithm),
> > + digest_hex);
>
> Please make the output in the !compact case match 'fsverity measure':
>
> printf("%s:%s %s\n",
> libfsverity_get_hash_name(tree_params.hash_algorithm),
> digest_hex, argv[i]);
>
> - Eric
Done with v3, sorry got confused with the 'sign' output.
--
Kind regards,
Luca Boccassi
next prev parent reply other threads:[~2020-10-26 18:12 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-10-22 17:21 [fsverity-utils PATCH] Add digest sub command luca.boccassi
2020-10-24 4:23 ` Eric Biggers
2020-10-26 11:49 ` Luca Boccassi
2020-10-26 11:40 ` [fsverity-utils PATCH v2] " luca.boccassi
2020-10-26 17:48 ` Eric Biggers
2020-10-26 18:12 ` Luca Boccassi [this message]
2020-10-26 18:11 ` [fsverity-utils PATCH v3] " luca.boccassi
2020-10-26 18:17 ` [fsverity-utils PATCH v4] " luca.boccassi
2020-10-26 18:58 ` Eric Biggers
2020-10-26 19:21 ` Luca Boccassi
2020-10-26 19:18 ` [fsverity-utils PATCH v5] " luca.boccassi
2020-10-26 20:36 ` Eric Biggers
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8a5b5f20576841f13ad67f777d56b4e5d0819558.camel@gmail.com \
--to=luca.boccassi@gmail.com \
--cc=ebiggers@kernel.org \
--cc=linux-fscrypt@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.