Your message dated Mon, 24 Jan 2022 18:20:03 +0000
with message-id <e1nc3wh-00098h...@fasolo.debian.org>
and subject line Bug#999824: fixed in ima-evm-utils 1.4-1.2
has caused the Debian Bug report #999824,
regarding ima-evm-utils: FTBFS without extended attributes support
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
999824: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=999824
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: ima-evm-utils
Version: 1.1-1+b1
Severity: normal
Dear Maintainer,
EVM signatures can be created with the option '--portable | -o ' to get
rid of a hashing of i_version and fsuuid.
When files should be verified after a signing with '--portable' on the
host, the tooling returns with "Verification failed" unless
the signing itself is correct.
The cause for this issue is a missing implementation for the probing
and verification of portable signatures.
A patch for this issue is already available in the official git source
of the ima-evm-utils tooling:
https://git.code.sf.net/p/linux-ima/ima-evm-utils
f4b901d081ec ("Add support for verifying portable EVM signatures")
The wrong checking of the signature format results in a false-positive
error.
Note, that this bug also affects version 1.3.2-2.1 provided
by Debian/SID https://packages.debian.org/sid/ima-evm-utils.
The official release 1.4 of the ima-evm-utils contains this fixes.
Please update the package version near-term.
Note:
ima-evm-utils were installed on my host manually since Debian Buster
does not provide a mainline ima-evm-utils version.
Thanks,
Steffen
The mentioned version above
-- System Information:
Debian Release: 10.11
APT prefers oldstable-updates
APT policy: (500, 'oldstable-updates'), (500, 'oldstable')
Architecture: amd64 (x86_64)
Foreign Architectures: armhf, arm64
Kernel: Linux 4.19.0-18-amd64 (SMP w/8 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8),
LANGUAGE= (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages ima-evm-utils depends on:
ii attr 1:2.4.48-4
ii keyutils 1.6-6
ii libc6 2.28-10
ii libimaevm0 1.1-1+b1
ii libkeyutils1 1.6-6
ii libssl1.1 1.1.1d-0+deb10u7
ima-evm-utils recommends no packages.
ima-evm-utils suggests no packages.
-- no debconf information
--- End Message ---
--- Begin Message ---
Source: ima-evm-utils
Source-Version: 1.4-1.2
Done: Bastian Germann <b...@debian.org>
We believe that the bug you reported is fixed in the latest version of
ima-evm-utils, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 999...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Bastian Germann <b...@debian.org> (supplier of updated ima-evm-utils package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 24 Jan 2022 18:33:09 +0100
Source: ima-evm-utils
Architecture: source
Version: 1.4-1.2
Distribution: unstable
Urgency: high
Maintainer: Dmitry Baryshkov <dbarysh...@gmail.com>
Changed-By: Bastian Germann <b...@debian.org>
Closes: 953929 999824
Changes:
ima-evm-utils (1.4-1.2) unstable; urgency=high
.
* Non-maintainer upload.
* d/control: Drop unnecessary build dependency libattr1-dev (Closes: #953929)
* d/rules: Skip tests (many depend on extended attrs, Closes: #999824)
Checksums-Sha1:
dcb68900a9a4ca6478237f563887d17ef04d71f3 1947 ima-evm-utils_1.4-1.2.dsc
59bed47d5213ba5c2d14a68248b503a63720c902 5896
ima-evm-utils_1.4-1.2.debian.tar.xz
6f203f405e7d6e4677d3f722a2359c463a368d67 6353
ima-evm-utils_1.4-1.2_source.buildinfo
Checksums-Sha256:
553d68e7ee5287d95a032f2281d23f3129f83c8fad184180059972084a9d2f3b 1947
ima-evm-utils_1.4-1.2.dsc
74ae485cfa7074fd9fe22468dbf78dc63d324a15d7057b5c620c31bc23b0772e 5896
ima-evm-utils_1.4-1.2.debian.tar.xz
7d2fe429ede4bc3f7fe32a0e6a16cae8614a37d0c02ffa56b3fb017b87bb5247 6353
ima-evm-utils_1.4-1.2_source.buildinfo
Files:
e9941259ee53484b59c4a0ef099cdddc 1947 utils optional ima-evm-utils_1.4-1.2.dsc
32e6d4500cfcd8d8350afdf78d37b345 5896 utils optional
ima-evm-utils_1.4-1.2.debian.tar.xz
891aed51ef8d41d6daf4398fd2949f11 6353 utils optional
ima-evm-utils_1.4-1.2_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQHEBAEBCgAuFiEEQGIgyLhVKAI3jM5BH1x6i0VWQxQFAmHu53UQHGJhZ2VAZGVi
aWFuLm9yZwAKCRAfXHqLRVZDFMNxC/9037eTzTnQ9srKtlWTnhn7EAKTI4un6URk
574ZYW8+8sKdyomtu53y18hzH91EG98tzunccK8B2vnQ3oxb7BRmm0Sgh8jhwtuP
U7qvddSr8hFV5S2iOdmQwK+Ic2OWonK5480+BzgvFa2aMLmeqDBQS1OftNG0umtB
ZfzwxJLjjuO4THCz6EWvyom+HKi4pvPEZ/f2iw8txfllbWI/tBaJGtAG73YHhHXc
8ofuNG3Zn3y3Nki/C9Ei6GkugolEF5K930ze25o0N3TJtUhJmioHHvF5nMakc8QU
8a/NIBnD99Vtvpy7ys+5tNz0/n0OzJsIk67uwPdTiHYwhqHDhGDlTO47aGL9vi42
xLjYFtQA5bcbQECTZSC5+FuDgqJADxQhR6DBWRo0nGGvG5z73hxX53IfFwayhonQ
9vw3jYWGSKvHI8kQdZIgieB3rSAf65epQWW3BVkDItX1dlWHNpn3M7QtTVe8jAuF
kFhAZBLGw4wGECGn+FGBzM1JIfbLNQc=
=rb4/
-----END PGP SIGNATURE-----
--- End Message ---