From 9a3dd47c2b9f5970c92711fe0eb63bb2baefd8eb3a1c07b19b8494526739a6c7 Mon Sep 17 00:00:00 2001 From: Marcus Meissner Date: Wed, 7 Sep 2016 06:53:01 +0000 Subject: [PATCH 1/2] Accepting request 424303 from home:markkp:branches:openSUSE:Factory Latest fix from IBM developers. OBS-URL: https://build.opensuse.org/request/show/424303 OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=42 --- ocki-3.5-fix-pkcscca-calls.patch | 35 ++++++++++++++++++++++++++++++++ openCryptoki.changes | 5 +++++ openCryptoki.spec | 2 ++ 3 files changed, 42 insertions(+) create mode 100644 ocki-3.5-fix-pkcscca-calls.patch diff --git a/ocki-3.5-fix-pkcscca-calls.patch b/ocki-3.5-fix-pkcscca-calls.patch new file mode 100644 index 0000000..907444e --- /dev/null +++ b/ocki-3.5-fix-pkcscca-calls.patch @@ -0,0 +1,35 @@ +From 814e5861701798b4f5872fcc20f7292f79987104 Mon Sep 17 00:00:00 2001 +From: Eduardo Barretto +Date: Tue, 30 Aug 2016 16:46:40 -0300 +Subject: [PATCH] PKCSCCA: Fix symbol name to get the correct address + +The csulincl.h file was changed to substitute the xxx_32 bit API +declarations with the latest CCA v5. In order to pkcscca work and avoid +"Illegal Instruction" we had to fix the symbol name that should be called +based on the csulincl.h change. + +Signed-off-by: Eduardo Barretto +--- + usr/sbin/pkcscca/pkcscca.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/usr/sbin/pkcscca/pkcscca.c b/usr/sbin/pkcscca/pkcscca.c +index 6d9f8dd..05caea3 100644 +--- a/usr/sbin/pkcscca/pkcscca.c ++++ b/usr/sbin/pkcscca/pkcscca.c +@@ -1387,9 +1387,9 @@ int main(int argc, char **argv) + return -1; + } + +- CSNDKTC = dlsym(lib_csulcca, "CSNDKTC_32"); +- CSNBKTC = dlsym(lib_csulcca, "CSNBKTC_32"); +- CSNBKTC2 = dlsym(lib_csulcca, "CSNBKTC2_32"); ++ CSNDKTC = dlsym(lib_csulcca, "CSNDKTC"); ++ CSNBKTC = dlsym(lib_csulcca, "CSNBKTC"); ++ CSNBKTC2 = dlsym(lib_csulcca, "CSNBKTC2"); + ret = migrate_wrapped_keys(slot_id, userpin, masterkey); + } + done: +-- +1.9.1 + diff --git a/openCryptoki.changes b/openCryptoki.changes index 048bcd0..cb7cc4f 100644 --- a/openCryptoki.changes +++ b/openCryptoki.changes @@ -1,3 +1,8 @@ +------------------------------------------------------------------- +Thu Sep 1 17:06:45 UTC 2016 - mpost@suse.com + +- Added ocki-3.5-fix-pkcscca-calls.patch (bsc#996887). + ------------------------------------------------------------------- Fri Jul 29 17:32:24 UTC 2016 - mpost@suse.com diff --git a/openCryptoki.spec b/openCryptoki.spec index 421f007..84f2168 100644 --- a/openCryptoki.spec +++ b/openCryptoki.spec @@ -71,6 +71,7 @@ Patch6: ocki-3.5-icsf-sessionhandle-missing-fix.patch Patch7: ocki-3.5-icsf-reasoncode-2028-added.patch Patch8: ocki-3.5-added-NULLreturn-check.patch Patch9: ocki-3.5-create-missing-tpm-token-lock-directory.patch +Patch10: ocki-3.5-fix-pkcscca-calls.patch Url: https://sourceforge.net/projects/opencryptoki/ BuildRoot: %{_tmppath}/%{name}-%{version}-build @@ -158,6 +159,7 @@ Cryptographic Accelerator (FC 4960 on pSeries). %patch7 -p1 %patch8 -p1 %patch9 -p1 +%patch10 -p1 cp %{SOURCE2} . From 99ab635d6c1bf99f9b6b39e8f306320018427cc6ac815319e107c3252ac36674 Mon Sep 17 00:00:00 2001 From: Mark Post Date: Wed, 7 Sep 2016 18:55:37 +0000 Subject: [PATCH 2/2] OBS-URL: https://build.opensuse.org/package/show/security/openCryptoki?expand=0&rev=43 --- openCryptoki.changes | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openCryptoki.changes b/openCryptoki.changes index cb7cc4f..5b9cd80 100644 --- a/openCryptoki.changes +++ b/openCryptoki.changes @@ -1,7 +1,7 @@ ------------------------------------------------------------------- Thu Sep 1 17:06:45 UTC 2016 - mpost@suse.com -- Added ocki-3.5-fix-pkcscca-calls.patch (bsc#996887). +- Added ocki-3.5-fix-pkcscca-calls.patch (bsc#996867). ------------------------------------------------------------------- Fri Jul 29 17:32:24 UTC 2016 - mpost@suse.com