|
Harald Hoyer |
2d3fda |
From 338b43cd6a97cf767af2953ce5c69240d4c32290 Mon Sep 17 00:00:00 2001
|
|
Harald Hoyer |
2d3fda |
From: Harald Hoyer <harald@redhat.com>
|
|
Harald Hoyer |
2d3fda |
Date: Thu, 5 Jul 2012 10:42:22 +0200
|
|
Harald Hoyer |
2d3fda |
Subject: [PATCH] fips: add instmods silent check mode "-c -s"
|
|
Harald Hoyer |
2d3fda |
|
|
Harald Hoyer |
2d3fda |
---
|
|
Harald Hoyer |
2d3fda |
dracut-functions.sh | 18 ++++++++++++------
|
|
Harald Hoyer |
2d3fda |
modules.d/01fips/module-setup.sh | 4 ++--
|
|
Harald Hoyer |
2d3fda |
2 files changed, 14 insertions(+), 8 deletions(-)
|
|
Harald Hoyer |
2d3fda |
|
|
Harald Hoyer |
2d3fda |
diff --git a/dracut-functions.sh b/dracut-functions.sh
|
|
Harald Hoyer |
2d3fda |
index 6de7c72..d91e2a4 100755
|
|
Harald Hoyer |
2d3fda |
--- a/dracut-functions.sh
|
|
Harald Hoyer |
2d3fda |
+++ b/dracut-functions.sh
|
|
Harald Hoyer |
2d3fda |
@@ -1290,8 +1290,8 @@ find_kernel_modules () {
|
|
Harald Hoyer |
2d3fda |
find_kernel_modules_by_path drivers
|
|
Harald Hoyer |
2d3fda |
}
|
|
Harald Hoyer |
2d3fda |
|
|
Harald Hoyer |
2d3fda |
-# instmods [-c] <kernel module> [<kernel module> ... ]
|
|
Harald Hoyer |
2d3fda |
-# instmods [-c] <kernel subsystem>
|
|
Harald Hoyer |
2d3fda |
+# instmods [-c [-s]] <kernel module> [<kernel module> ... ]
|
|
Harald Hoyer |
2d3fda |
+# instmods [-c [-s]] <kernel subsystem>
|
|
Harald Hoyer |
2d3fda |
# install kernel modules along with all their dependencies.
|
|
Harald Hoyer |
2d3fda |
# <kernel subsystem> can be e.g. "=block" or "=drivers/usb/storage"
|
|
Harald Hoyer |
2d3fda |
instmods() {
|
|
Harald Hoyer |
2d3fda |
@@ -1299,11 +1299,17 @@ instmods() {
|
|
Harald Hoyer |
2d3fda |
# called [sub]functions inherit _fderr
|
|
Harald Hoyer |
2d3fda |
local _fderr=9
|
|
Harald Hoyer |
2d3fda |
local _check=no
|
|
Harald Hoyer |
2d3fda |
+ local _silent=no
|
|
Harald Hoyer |
2d3fda |
if [[ $1 = '-c' ]]; then
|
|
Harald Hoyer |
2d3fda |
_check=yes
|
|
Harald Hoyer |
2d3fda |
shift
|
|
Harald Hoyer |
2d3fda |
fi
|
|
Harald Hoyer |
2d3fda |
|
|
Harald Hoyer |
2d3fda |
+ if [[ $1 = '-s' ]]; then
|
|
Harald Hoyer |
2d3fda |
+ _silent=yes
|
|
Harald Hoyer |
2d3fda |
+ shift
|
|
Harald Hoyer |
2d3fda |
+ fi
|
|
Harald Hoyer |
2d3fda |
+
|
|
Harald Hoyer |
2d3fda |
function inst1mod() {
|
|
Harald Hoyer |
2d3fda |
local _ret=0 _mod="$1"
|
|
Harald Hoyer |
2d3fda |
case $_mod in
|
|
Harald Hoyer |
2d3fda |
@@ -1362,8 +1368,8 @@ instmods() {
|
|
Harald Hoyer |
2d3fda |
if (($# == 0)); then # filenames from stdin
|
|
Harald Hoyer |
2d3fda |
while read _mod; do
|
|
Harald Hoyer |
2d3fda |
inst1mod "${_mod%.ko*}" || {
|
|
Harald Hoyer |
2d3fda |
- if [ "$_check" = "yes" ]; then
|
|
Harald Hoyer |
2d3fda |
- dfatal "Failed to install $_mod"
|
|
Harald Hoyer |
2d3fda |
+ if [[ "$_check" == "yes" ]]; then
|
|
Harald Hoyer |
2d3fda |
+ [[ "$_silent" == "no" ]] && dfatal "Failed to install $_mod"
|
|
Harald Hoyer |
2d3fda |
return 1
|
|
Harald Hoyer |
2d3fda |
fi
|
|
Harald Hoyer |
2d3fda |
}
|
|
Harald Hoyer |
2d3fda |
@@ -1371,8 +1377,8 @@ instmods() {
|
|
Harald Hoyer |
2d3fda |
fi
|
|
Harald Hoyer |
2d3fda |
while (($# > 0)); do # filenames as arguments
|
|
Harald Hoyer |
2d3fda |
inst1mod ${1%.ko*} || {
|
|
Harald Hoyer |
2d3fda |
- if [ "$_check" = "yes" ]; then
|
|
Harald Hoyer |
2d3fda |
- dfatal "Failed to install $1"
|
|
Harald Hoyer |
2d3fda |
+ if [[ "$_check" == "yes" ]]; then
|
|
Harald Hoyer |
2d3fda |
+ [[ "$_silent" == "no" ]] && dfatal "Failed to install $1"
|
|
Harald Hoyer |
2d3fda |
return 1
|
|
Harald Hoyer |
2d3fda |
fi
|
|
Harald Hoyer |
2d3fda |
}
|
|
Harald Hoyer |
2d3fda |
diff --git a/modules.d/01fips/module-setup.sh b/modules.d/01fips/module-setup.sh
|
|
Harald Hoyer |
2d3fda |
index dbf51e3..2d238fb 100755
|
|
Harald Hoyer |
2d3fda |
--- a/modules.d/01fips/module-setup.sh
|
|
Harald Hoyer |
2d3fda |
+++ b/modules.d/01fips/module-setup.sh
|
|
Harald Hoyer |
2d3fda |
@@ -13,13 +13,13 @@ depends() {
|
|
Harald Hoyer |
2d3fda |
installkernel() {
|
|
Harald Hoyer |
2d3fda |
local _fipsmodules _mod
|
|
Harald Hoyer |
2d3fda |
_fipsmodules="aead aes_generic xts aes-x86_64 ansi_cprng cbc ccm chainiv ctr"
|
|
Harald Hoyer |
2d3fda |
- _fipsmodules+=" des deflate ecb eseqiv hmac seqiv sha256_generic sha512"
|
|
Harald Hoyer |
2d3fda |
+ _fipsmodules+=" des deflate ecb eseqiv hmac seqiv sha256 sha256_generic sha512 sha512_generic"
|
|
Harald Hoyer |
2d3fda |
_fipsmodules+=" cryptomgr crypto_null tcrypt dm-mod dm-crypt"
|
|
Harald Hoyer |
2d3fda |
|
|
Harald Hoyer |
2d3fda |
mkdir -m 0755 -p "${initdir}/etc/modprobe.d"
|
|
Harald Hoyer |
2d3fda |
|
|
Harald Hoyer |
2d3fda |
for _mod in $_fipsmodules; do
|
|
Harald Hoyer |
2d3fda |
- if hostonly='' instmods $_mod; then
|
|
Harald Hoyer |
2d3fda |
+ if hostonly='' instmods -c -s $_mod; then
|
|
Harald Hoyer |
2d3fda |
echo $_mod >> "${initdir}/etc/fipsmodules"
|
|
Harald Hoyer |
2d3fda |
echo "blacklist $_mod" >> "${initdir}/etc/modprobe.d/fips.conf"
|
|
Harald Hoyer |
2d3fda |
fi
|