Diff of the two buildlogs: -- --- b1/build.log 2024-01-12 15:21:20.386524443 +0000 +++ b2/build.log 2024-01-12 15:30:50.915611936 +0000 @@ -1,6 +1,6 @@ I: pbuilder: network access will be disabled during build -I: Current time: Thu Feb 13 09:42:09 -12 2025 -I: pbuilder-time-stamp: 1739482929 +I: Current time: Sat Jan 13 05:21:27 +14 2024 +I: pbuilder-time-stamp: 1705072887 I: Building the build Environment I: extracting base tarball [/var/cache/pbuilder/bullseye-reproducible-base.tgz] I: copying local configuration @@ -17,7 +17,7 @@ I: copying [./efitools_1.9.2-2~deb11u1.debian.tar.xz] I: Extracting source gpgv: unknown type of key resource 'trustedkeys.kbx' -gpgv: keyblock resource '/tmp/dpkg-verify-sig.qDqMeYj3/trustedkeys.kbx': General error +gpgv: keyblock resource '/tmp/dpkg-verify-sig.2jIExR2o/trustedkeys.kbx': General error gpgv: Signature made Thu Dec 8 17:23:12 2022 gpgv: using RSA key 3AFA757FAC6EA11D2FF45DF088D24287A2D898B1 gpgv: Can't check signature: No public key @@ -30,49 +30,80 @@ dpkg-source: info: applying fix-deps.patch I: using fakeroot in build. I: Installing the build-deps -I: user script /srv/workspace/pbuilder/2191863/tmp/hooks/D02_print_environment starting +I: user script /srv/workspace/pbuilder/951627/tmp/hooks/D01_modify_environment starting +debug: Running on ionos1-amd64. +I: Changing host+domainname to test build reproducibility +I: Adding a custom variable just for the fun of it... +I: Changing /bin/sh to bash +'/bin/sh' -> '/bin/bash' +lrwxrwxrwx 1 root root 9 Jan 12 15:22 /bin/sh -> /bin/bash +I: Setting pbuilder2's login shell to /bin/bash +I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other +I: user script /srv/workspace/pbuilder/951627/tmp/hooks/D01_modify_environment finished +I: user script /srv/workspace/pbuilder/951627/tmp/hooks/D02_print_environment starting I: set - BUILDDIR='/build/reproducible-path' - BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other' - BUILDUSERNAME='pbuilder1' - BUILD_ARCH='amd64' - DEBIAN_FRONTEND='noninteractive' - DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all,-fixfilepath parallel=16 ' - DISTRIBUTION='bullseye' - HOME='/root' - HOST_ARCH='amd64' + BASH=/bin/sh + BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:hostcomplete:interactive_comments:progcomp:promptvars:sourcepath + BASH_ALIASES=() + BASH_ARGC=() + BASH_ARGV=() + BASH_CMDS=() + BASH_LINENO=([0]="12" [1]="0") + BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment") + BASH_VERSINFO=([0]="5" [1]="1" [2]="4" [3]="1" [4]="release" [5]="x86_64-pc-linux-gnu") + BASH_VERSION='5.1.4(1)-release' + BUILDDIR=/build/reproducible-path + BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other' + BUILDUSERNAME=pbuilder2 + BUILD_ARCH=amd64 + DEBIAN_FRONTEND=noninteractive + DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all,-fixfilepath parallel=15 ' + DIRSTACK=() + DISTRIBUTION=bullseye + EUID=0 + FUNCNAME=([0]="Echo" [1]="main") + GROUPS=() + HOME=/root + HOSTNAME=i-capture-the-hostname + HOSTTYPE=x86_64 + HOST_ARCH=amd64 IFS=' ' - INVOCATION_ID='3a277bd27d134ad0b38b063ee16353c7' - LANG='C' - LANGUAGE='en_US:en' - LC_ALL='C' - MAIL='/var/mail/root' - OPTIND='1' - PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games' - PBCURRENTCOMMANDLINEOPERATION='build' - PBUILDER_OPERATION='build' - PBUILDER_PKGDATADIR='/usr/share/pbuilder' - PBUILDER_PKGLIBDIR='/usr/lib/pbuilder' - PBUILDER_SYSCONFDIR='/etc' - PPID='2191863' - PS1='# ' - PS2='> ' + INVOCATION_ID=ba01585d4e2646dd8b5dd79b64d15019 + LANG=C + LANGUAGE=et_EE:et + LC_ALL=C + MACHTYPE=x86_64-pc-linux-gnu + MAIL=/var/mail/root + OPTERR=1 + OPTIND=1 + OSTYPE=linux-gnu + PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path + PBCURRENTCOMMANDLINEOPERATION=build + PBUILDER_OPERATION=build + PBUILDER_PKGDATADIR=/usr/share/pbuilder + PBUILDER_PKGLIBDIR=/usr/lib/pbuilder + PBUILDER_SYSCONFDIR=/etc + PIPESTATUS=([0]="0") + POSIXLY_CORRECT=y + PPID=951627 PS4='+ ' - PWD='/' - SHELL='/bin/bash' - SHLVL='2' - SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.635n5xwB/pbuilderrc_nrk1 --distribution bullseye --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/bullseye-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.635n5xwB/b1 --logfile b1/build.log efitools_1.9.2-2~deb11u1.dsc' - SUDO_GID='111' - SUDO_UID='106' - SUDO_USER='jenkins' - TERM='unknown' - TZ='/usr/share/zoneinfo/Etc/GMT+12' - USER='root' - _='/usr/bin/systemd-run' - http_proxy='http://85.184.249.68:3128' + PWD=/ + SHELL=/bin/bash + SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix + SHLVL=3 + SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.635n5xwB/pbuilderrc_16Se --distribution bullseye --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/bullseye-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.635n5xwB/b2 --logfile b2/build.log efitools_1.9.2-2~deb11u1.dsc' + SUDO_GID=110 + SUDO_UID=105 + SUDO_USER=jenkins + TERM=unknown + TZ=/usr/share/zoneinfo/Etc/GMT-14 + UID=0 + USER=root + _='I: set' + http_proxy=http://78.137.99.97:3128 I: uname -a - Linux ionos15-amd64 6.5.0-0.deb12.4-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.5.10-1~bpo12+1 (2023-11-23) x86_64 GNU/Linux + Linux i-capture-the-hostname 6.1.0-17-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.69-1 (2023-12-30) x86_64 GNU/Linux I: ls -l /bin total 5476 -rwxr-xr-x 1 root root 1234376 Mar 27 2022 bash @@ -132,7 +163,7 @@ -rwxr-xr-x 1 root root 52032 Sep 24 2020 rmdir -rwxr-xr-x 1 root root 27472 Sep 27 2020 run-parts -rwxr-xr-x 1 root root 122224 Dec 22 2018 sed - lrwxrwxrwx 1 root root 4 Feb 8 15:47 sh -> dash + lrwxrwxrwx 1 root root 9 Jan 12 15:22 sh -> /bin/bash -rwxr-xr-x 1 root root 43808 Sep 24 2020 sleep -rwxr-xr-x 1 root root 84928 Sep 24 2020 stty -rwsr-xr-x 1 root root 71912 Jan 20 2022 su @@ -158,7 +189,7 @@ -rwxr-xr-x 1 root root 2206 Apr 10 2022 zless -rwxr-xr-x 1 root root 1842 Apr 10 2022 zmore -rwxr-xr-x 1 root root 4577 Apr 10 2022 znew -I: user script /srv/workspace/pbuilder/2191863/tmp/hooks/D02_print_environment finished +I: user script /srv/workspace/pbuilder/951627/tmp/hooks/D02_print_environment finished -> Attempting to satisfy build-dependencies -> Creating pbuilder-satisfydepends-dummy package Package: pbuilder-satisfydepends-dummy @@ -244,7 +275,7 @@ Get: 36 http://deb.debian.org/debian bullseye/main amd64 libssl-dev amd64 1.1.1w-0+deb11u1 [1820 kB] Get: 37 http://deb.debian.org/debian bullseye/main amd64 openssl amd64 1.1.1w-0+deb11u1 [859 kB] Get: 38 http://deb.debian.org/debian bullseye/main amd64 sbsigntool amd64 0.9.2-2 [63.5 kB] -Fetched 21.4 MB in 1s (24.9 MB/s) +Fetched 21.4 MB in 3s (8252 kB/s) debconf: delaying package configuration, since apt-utils is not installed Selecting previously unselected package bsdextrautils. (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 17743 files and directories currently installed.) @@ -417,7 +448,11 @@ fakeroot is already the newest version (1.25.3-1.1). 0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. I: Building the package -I: Running cd /build/reproducible-path/efitools-1.9.2/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S > ../efitools_1.9.2-2~deb11u1_source.changes +I: user script /srv/workspace/pbuilder/951627/tmp/hooks/A99_set_merged_usr starting +Not re-configuring usrmerge for bullseye +I: user script /srv/workspace/pbuilder/951627/tmp/hooks/A99_set_merged_usr finished +hostname: Name or service not known +I: Running cd /build/reproducible-path/efitools-1.9.2/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S > ../efitools_1.9.2-2~deb11u1_source.changes dpkg-buildpackage: info: source package efitools dpkg-buildpackage: info: source version 1.9.2-2~deb11u1 dpkg-buildpackage: info: source distribution bullseye @@ -427,7 +462,7 @@ fakeroot debian/rules clean dh clean dh_auto_clean - make -j16 clean + make -j15 clean make[1]: Entering directory '/build/reproducible-path/efitools-1.9.2' rm -f PK.* KEK.* DB.* HelloWorld.efi LockDown.efi Loader.efi ReadVars.efi UpdateVars.efi KeyTool.efi HashTool.efi SetNull.efi ShimReplace.efi HelloWorld-signed.efi LockDown-signed.efi Loader-signed.efi ReadVars-signed.efi UpdateVars-signed.efi KeyTool-signed.efi HashTool-signed.efi SetNull-signed.efi ShimReplace-signed.efi cert-to-efi-sig-list sig-list-to-certs sign-efi-sig-list hash-to-efi-sig-list efi-readvar efi-updatevar cert-to-efi-hash-list flash-var *.o *.so rm -f noPK.* @@ -467,86 +502,88 @@ dh_autoreconf dh_auto_configure dh_auto_build - make -j16 "INSTALL=install --strip-program=true" + make -j15 "INSTALL=install --strip-program=true" make[1]: Entering directory '/build/reproducible-path/efitools-1.9.2' make -C lib lib-efi.a make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c HelloWorld.c -o HelloWorld.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c simple_file.c -o simple_file.efi.o openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB/" -keyout DB.key -out DB.crt -days 3650 -nodes -sha256 +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c simple_file.c -o simple_file.efi.o openssl req -new -x509 -newkey rsa:2048 -subj "/CN=PK/" -keyout PK.key -out PK.crt -days 3650 -nodes -sha256 Generating a RSA private key -...........cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pecoff.c -o pecoff.efi.o -.......................Generating a RSA private key -......+++.+.+ -....cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-sig-list.c -o cert-to-efi-sig-list.o -........++..++.+. +......cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pecoff.c -o pecoff.efi.o +..........+++++ +..Generating a RSA private key +......cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-sig-list.c -o cert-to-efi-sig-list.o ++.++.++ writing new private key to 'DB.key' ----- -.....cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c guid.c -o guid.efi.o -..................make -C lib lib.a +...+++cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c guid.c -o guid.efi.o +++ +...........make -C lib lib.a .....cert-to-efi-sig-list.c:9: warning: "__STDC_VERSION__" redefined 9 | #define __STDC_VERSION__ 199901L | -.: note: this is the location of the previous definition -..............cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c sha256.c -o sha256.efi.o -.make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' -openssl req -new -x509 -newkey rsa:2048 -subj "/CN=KEK/" -keyout KEK.key -out KEK.crt -days 3650 -nodes -sha256 -...........................Generating a RSA private key -.........+++.cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c simple_file.c -o simple_file.o -...++ -..cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c console.c -o console.efi.o -......cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sign-efi-sig-list.c -o sign-efi-sig-list.o -......................+.++.++ -...........................++..+.+..+ +: note: this is the location of the previous definition +........cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c sha256.c -o sha256.efi.o +.........openssl req -new -x509 -newkey rsa:2048 -subj "/CN=KEK/" -keyout KEK.key -out KEK.crt -days 3650 -nodes -sha256 +make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' +...............cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c console.c -o console.efi.o +.....cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c simple_file.c -o simple_file.o ++Generating a RSA private key +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sign-efi-sig-list.c -o sign-efi-sig-list.o ++.++.+ writing new private key to 'PK.key' -...----- -..........+++++ -writing new private key to 'KEK.key' ----- -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pecoff.c -o pecoff.o -sign-efi-sig-list.c:7: warning: "__STDC_VERSION__" redefined +..........cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c execute.c -o execute.efi.o +......cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pecoff.c -o pecoff.o +.sign-efi-sig-list.c:7: warning: "__STDC_VERSION__" redefined 7 | #define __STDC_VERSION__ 199901L | : note: this is the location of the previous definition -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c execute.c -o execute.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c Loader.c -o Loader.o -make -C lib/asn1 libasn1-efi.a -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c guid.c -o guid.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c configtable.c -o configtable.efi.o -make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' +.cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c Loader.c -o Loader.o +..........cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c configtable.c -o configtable.efi.o +...make -C lib/asn1 libasn1-efi.a +.......cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c guid.c -o guid.o +..+++++ +.......make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' +..cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shell.c -o shell.efi.o +....cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ReadVars.c -o ReadVars.o +........cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sha256.c -o sha256.o +.....cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1.c -o asn1.efi.o +...cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c security_policy.c -o security_policy.efi.o +.....cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c UpdateVars.c -o UpdateVars.o +..+++++ +writing new private key to 'KEK.key' +----- +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c console.c -o console.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c KeyTool.c -o KeyTool.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1_parser.c -o asn1_parser.efi.o sign-efi-sig-list.c: In function 'main': +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shim_protocol.c -o shim_protocol.efi.o sign-efi-sig-list.c:166:3: warning: implicit declaration of function 'strptime'; did you mean 'strftime'? [-Wimplicit-function-declaration] 166 | strptime(timestampstr, "%Y-%m-%d %H:%M:%S", &tms); | ^~~~~~~~ | strftime -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ReadVars.c -o ReadVars.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sha256.c -o sha256.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shell.c -o shell.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1.c -o asn1.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c UpdateVars.c -o UpdateVars.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c console.c -o console.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c security_policy.c -o security_policy.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1_parser.c -o asn1_parser.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c KeyTool.c -o KeyTool.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c execute.c -o execute.o UpdateVars.c: In function 'efi_main': UpdateVars.c:24:42: warning: variable 'owner_guid' set but not used [-Wunused-but-set-variable] 24 | CHAR16 **ARGV, *var, *name, *progname, *owner_guid; | ^~~~~~~~~~ -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shim_protocol.c -o shim_protocol.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c enumerator.c -o enumerator.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c configtable.c -o configtable.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c HashTool.c -o HashTool.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pkcs7verify.c -o pkcs7verify.efi.o asn1_parser.c: In function 'iterate': +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pkcs7verify.c -o pkcs7verify.efi.o asn1_parser.c:82:8: warning: variable 'level' set but not used [-Wunused-but-set-variable] 82 | u_int level; | ^~~~~ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c configtable.c -o configtable.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c enumerator.c -o enumerator.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c HashTool.c -o HashTool.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c shell.c -o shell.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c variables.c -o variables.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c chunk.c -o chunk.efi.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c SetNull.c -o SetNull.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c variables.c -o variables.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c security_policy.c -o security_policy.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c oid.c -o oid.efi.o HashTool.c: In function 'efi_main': HashTool.c:187:4: warning: variable 'setup_mode_arg' set but not used [-Wunused-but-set-variable] 187 | setup_mode_arg = 0, keytool = NOSEL; @@ -554,25 +591,7 @@ HashTool.c:185:14: warning: variable 'setup_mode' set but not used [-Wunused-but-set-variable] 185 | int c = 0, setup_mode = NOSEL, uefi_reboot = NOSEL, | ^~~~~~~~~~ -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c security_policy.c -o security_policy.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c oid.c -o oid.efi.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ShimReplace.c -o ShimReplace.o -ShimReplace.c: In function 'efi_main': -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sig-list-to-certs.c -o sig-list-to-certs.o -ShimReplace.c:51:30: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers] - 51 | efi_status = execute(image, loader); - | ^~~~~~ -In file included from ShimReplace.c:17: -/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'} - 5 | execute(EFI_HANDLE image, CHAR16 *name); - | ~~~~~~~~^~~~ -ShimReplace.c:57:30: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers] - 57 | efi_status = execute(image, fallback); - | ^~~~~~~~ -In file included from ShimReplace.c:17: -/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'} - 5 | execute(EFI_HANDLE image, CHAR16 *name); - | ~~~~~~~~^~~~ cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c shim_protocol.c -o shim_protocol.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c identification.c -o identification.efi.o oid.c:13:43: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] @@ -755,6 +774,7 @@ 57 | { 0x13, 45, 0, 2, "basicConstraints" }, /* 44 */ | ^~~~~~~~~~~~~~~~~~ oid.c:57:43: note: (near initialization for 'oid_names[44].name') +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sig-list-to-certs.c -o sig-list-to-certs.o oid.c:58:43: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] 58 | { 0x14, 46, 0, 2, "crlNumber" }, /* 45 */ | ^~~~~~~~~~~ @@ -1267,6 +1287,7 @@ 185 | { 0x04, 194, 1, 3, "private" }, /* 172 */ | ^~~~~~~~~ oid.c:185:43: note: (near initialization for 'oid_names[172].name') +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pkcs7verify.c -o pkcs7verify.o oid.c:186:43: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] 186 | { 0x01, 0, 1, 4, "enterprise" }, /* 173 */ | ^~~~~~~~~~~~ @@ -1703,6 +1724,7 @@ 294 | { 0x07, 282, 0, 8, "brainpoolP256r1" }, /* 281 */ | ^~~~~~~~~~~~~~~~~ oid.c:294:43: note: (near initialization for 'oid_names[281].name') +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c x509.c -o x509.efi.o oid.c:295:43: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] 295 | { 0x08, 283, 0, 8, "brainpoolP256t1" }, /* 282 */ | ^~~~~~~~~~~~~~~~~ @@ -2083,13 +2105,27 @@ 389 | { 0x0F, 0, 0, 4, "tcg-at-tpmIdLabel" } /* 376 */ | ^~~~~~~~~~~~~~~~~~~ oid.c:389:43: note: (near initialization for 'oid_names[376].name') +ShimReplace.c: In function 'efi_main': +ShimReplace.c:51:30: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers] + 51 | efi_status = execute(image, loader); + | ^~~~~~ +In file included from ShimReplace.c:17: +/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'} + 5 | execute(EFI_HANDLE image, CHAR16 *name); + | ~~~~~~~~^~~~ +ShimReplace.c:57:30: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers] + 57 | efi_status = execute(image, fallback); + | ^~~~~~~~ sig-list-to-certs.c:7: warning: "__STDC_VERSION__" redefined 7 | #define __STDC_VERSION__ 199901L | : note: this is the location of the previous definition -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c x509.c -o x509.efi.o +In file included from ShimReplace.c:17: +/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'} + 5 | execute(EFI_HANDLE image, CHAR16 *name); + | ~~~~~~~~^~~~ cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c hash-to-efi-sig-list.c -o hash-to-efi-sig-list.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pkcs7verify.c -o pkcs7verify.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c kernel_efivars.c -o kernel_efivars.o identification.c:34:3: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] 34 | {"ND", OID_NAME_DISTINGUISHER, ASN1_PRINTABLESTRING}, | ^~~~ @@ -2209,12 +2245,11 @@ identification.c:33:24: warning: 'x501rdns' defined but not used [-Wunused-const-variable=] 33 | static const x501rdn_t x501rdns[] = { | ^~~~~~~~ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-readvar.c -o efi-readvar.o hash-to-efi-sig-list.c:7: warning: "__STDC_VERSION__" redefined 7 | #define __STDC_VERSION__ 199901L | : note: this is the location of the previous definition -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-readvar.c -o efi-readvar.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c kernel_efivars.c -o kernel_efivars.o x509.c:9:7: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] 9 | { 0, "x509", ASN1_SEQUENCE, ASN1_OBJ }, /* 0 */ | ^~~~~~ @@ -2323,9 +2358,9 @@ 35 | { 0, "exit", ASN1_EOC, ASN1_EXIT } | ^~~~~~ x509.c:35:7: note: (near initialization for 'x509_certObjects[26].name') -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-updatevar.c -o efi-updatevar.o -ar rcv libasn1-efi.a asn1.efi.o asn1_parser.efi.o enumerator.efi.o chunk.efi.o oid.efi.o identification.efi.o x509.efi.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c openssl_sign.c -o openssl_sign.o +ar rcv libasn1-efi.a asn1.efi.o asn1_parser.efi.o enumerator.efi.o chunk.efi.o oid.efi.o identification.efi.o x509.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-updatevar.c -o efi-updatevar.o kernel_efivars.c:19: warning: "__STDC_VERSION__" redefined 19 | #define __STDC_VERSION__ 199901L | @@ -2339,72 +2374,28 @@ a - x509.efi.o make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-hash-list.c -o cert-to-efi-hash-list.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c flash-var.c -o flash-var.o +> noPK.esl efi-readvar.c:20: warning: "__STDC_VERSION__" redefined 20 | #define __STDC_VERSION__ 199901L | : note: this is the location of the previous definition -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c flash-var.c -o flash-var.o -efi-updatevar.c:23: warning: "__STDC_VERSION__" redefined - 23 | #define __STDC_VERSION__ 199901L - | -: note: this is the location of the previous definition -> noPK.esl flash-var.c:13: warning: "__STDC_VERSION__" redefined 13 | #define __STDC_VERSION__ 199901L | : note: this is the location of the previous definition openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB1/" -keyout DB1.key -out DB1.crt -days 3650 -nodes -sha256 +ar rcv lib.a simple_file.o pecoff.o guid.o sha256.o console.o execute.o configtable.o shell.o security_policy.o shim_protocol.o pkcs7verify.o kernel_efivars.o openssl_sign.o flash-var.c: In function 'main': flash-var.c:109:3: warning: implicit declaration of function 'strptime'; did you mean 'strftime'? [-Wimplicit-function-declaration] 109 | strptime(timestampstr, "%Y-%m-%d %H:%M:%S", &tms); | ^~~~~~~~ | strftime +efi-updatevar.c:23: warning: "__STDC_VERSION__" redefined + 23 | #define __STDC_VERSION__ 199901L + | +: note: this is the location of the previous definition openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB2/" -keyout DB2.key -out DB2.crt -days 3650 -nodes -sha256 -Generating a RSA private key -......................++Generating a RSA private key -.+.++ -..........................++.+.++ -....+++++. -writing new private key to 'DB2.key' ------ -......ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds SetNull.o -o SetNull.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a -.........+++++ -writing new private key to 'DB1.key' ------ -# check we have no undefined symbols -nm -D SetNull.so | grep ' U ' && exit 1 || exit 0 -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 SetNull.so SetNull.efi -ar rcv lib-efi.a simple_file.efi.o pecoff.efi.o guid.efi.o sha256.efi.o console.efi.o execute.efi.o configtable.efi.o shell.efi.o security_policy.efi.o shim_protocol.efi.o pkcs7verify.efi.o variables.o -sbsign --key DB.key --cert DB.crt --output SetNull-signed.efi SetNull.efi -a - simple_file.efi.o -a - pecoff.efi.o -a - guid.efi.o -a - sha256.efi.o -a - console.efi.o -a - execute.efi.o -a - configtable.efi.o -a - shell.efi.o -a - security_policy.efi.o -a - shim_protocol.efi.o -a - pkcs7verify.efi.o -a - variables.o -make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' -warning: data remaining[3584 vs 3825]: gaps between PE/COFF sections? -warning: data remaining[3584 vs 3832]: gaps between PE/COFF sections? -Signing Unsigned original image -ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds ShimReplace.o lib/lib-efi.a -o ShimReplace.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a -# check we have no undefined symbols -nm -D ShimReplace.so | grep ' U ' && exit 1 || exit 0 -ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds HelloWorld.o lib/lib-efi.a -o HelloWorld.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a -# check we have no undefined symbols -nm -D HelloWorld.so | grep ' U ' && exit 1 || exit 0 -ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds Loader.o lib/lib-efi.a -o Loader.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a -# check we have no undefined symbols -nm -D Loader.so | grep ' U ' && exit 1 || exit 0 -ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds ReadVars.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o ReadVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a -ar rcv lib.a simple_file.o pecoff.o guid.o sha256.o console.o execute.o configtable.o shell.o security_policy.o shim_protocol.o pkcs7verify.o kernel_efivars.o openssl_sign.o a - simple_file.o a - pecoff.o a - guid.o @@ -2418,90 +2409,63 @@ a - pkcs7verify.o a - kernel_efivars.o a - openssl_sign.o +Generating a RSA private key make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' -# check we have no undefined symbols -nm -D ReadVars.so | grep ' U ' && exit 1 || exit 0 -ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds UpdateVars.o lib/lib-efi.a -o UpdateVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a -# check we have no undefined symbols -nm -D UpdateVars.so | grep ' U ' && exit 1 || exit 0 -ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds KeyTool.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o KeyTool.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a -# check we have no undefined symbols -nm -D KeyTool.so | grep ' U ' && exit 1 || exit 0 -ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds HashTool.o lib/lib-efi.a -o HashTool.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a -# check we have no undefined symbols -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 ShimReplace.so ShimReplace.efi -nm -D HashTool.so | grep ' U ' && exit 1 || exit 0 -cc -o sig-list-to-certs sig-list-to-certs.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -lcrypto -cc -o hash-to-efi-sig-list hash-to-efi-sig-list.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -cc -o efi-readvar efi-readvar.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -lcrypto -cc -o efi-updatevar efi-updatevar.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -lcrypto -/usr/bin/ld: lib/lib.a(kernel_efivars.o): in function `kernel_variable_init': -/build/reproducible-path/efitools-1.9.2/lib/kernel_efivars.c:40: warning: the use of `mktemp' is dangerous, better use `mkstemp' or `mkdtemp' -cc -o cert-to-efi-hash-list cert-to-efi-hash-list.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -lcrypto -/usr/bin/ld: lib/lib.a(kernel_efivars.o): in function `kernel_variable_init': +..................Generating a RSA private key +.........................cc -o cert-to-efi-sig-list cert-to-efi-sig-list.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -lcrypto +........................cc -o sign-efi-sig-list sign-efi-sig-list.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -lcrypto +.................+.++.++ +............ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds SetNull.o -o SetNull.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a +................cc -o sig-list-to-certs sig-list-to-certs.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -lcrypto +....# check we have no undefined symbols +......nm -D SetNull.so | grep ' U ' && exit 1 || exit 0 +..............++cc -o hash-to-efi-sig-list hash-to-efi-sig-list.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a +.++.+ +writing new private key to 'DB1.key' +----- +.........cc -o efi-readvar efi-readvar.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -lcrypto +...........cc -o cert-to-efi-hash-list cert-to-efi-hash-list.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -lcrypto +......../usr/bin/ld: lib/lib.a(kernel_efivars.o): in function `kernel_variable_init': /build/reproducible-path/efitools-1.9.2/lib/kernel_efivars.c:40: warning: the use of `mktemp' is dangerous, better use `mkstemp' or `mkdtemp' -cc -o flash-var flash-var.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -help2man --no-info -i doc/efi-readvar.1.in -o doc/efi-readvar.1 ./efi-readvar -help2man --no-info -i doc/efi-updatevar.1.in -o doc/efi-updatevar.1 ./efi-updatevar -help2man --no-info -i doc/hash-to-efi-sig-list.1.in -o doc/hash-to-efi-sig-list.1 ./hash-to-efi-sig-list +...cc -o flash-var flash-var.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a +..........help2man --no-info -i doc/cert-to-efi-sig-list.1.in -o doc/cert-to-efi-sig-list.1 ./cert-to-efi-sig-list +......+++++ +..........help2man --no-info -i doc/efi-readvar.1.in -o doc/efi-readvar.1 ./efi-readvar +......................help2man --no-info -i doc/hash-to-efi-sig-list.1.in -o doc/hash-to-efi-sig-list.1 ./hash-to-efi-sig-list +......+++++ +writing new private key to 'DB2.key' +----- help2man --no-info -i doc/sig-list-to-certs.1.in -o doc/sig-list-to-certs.1 ./sig-list-to-certs -./cert-to-efi-hash-list PK.crt PK-hash-blacklist.esl -./cert-to-efi-hash-list KEK.crt KEK-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 -./cert-to-efi-hash-list DB.crt DB-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 -./cert-to-efi-hash-list DB1.crt DB1-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 -./cert-to-efi-hash-list DB2.crt DB2-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 -./cert-to-efi-hash-list ms-uefi.crt ms-uefi-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 -./cert-to-efi-hash-list ms-kek.crt ms-kek-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 -TimeOfRevocation is 0-0-0 00:00:00 -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 HelloWorld.so HelloWorld.efi -cc -o cert-to-efi-sig-list cert-to-efi-sig-list.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -lcrypto -cc -o sign-efi-sig-list sign-efi-sig-list.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -lcrypto -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 Loader.so Loader.efi -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 ReadVars.so ReadVars.efi -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 UpdateVars.so UpdateVars.efi -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 KeyTool.so KeyTool.efi -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 HashTool.so HashTool.efi -sbsign --key DB.key --cert DB.crt --output ShimReplace-signed.efi ShimReplace.efi -warning: data remaining[86016 vs 97944]: gaps between PE/COFF sections? -help2man --no-info -i doc/cert-to-efi-hash-list.1.in -o doc/cert-to-efi-hash-list.1 ./cert-to-efi-hash-list -Signing Unsigned original image -help2man --no-info -i doc/cert-to-efi-sig-list.1.in -o doc/cert-to-efi-sig-list.1 ./cert-to-efi-sig-list help2man --no-info -i doc/sign-efi-sig-list.1.in -o doc/sign-efi-sig-list.1 ./sign-efi-sig-list -./sign-efi-sig-list -t "2025-02-13 21:43:30" -c PK.crt -k PK.key PK noPK.esl noPK.auth +./sign-efi-sig-list -t "2024-01-12 15:25:52" -c PK.crt -k PK.key PK noPK.esl noPK.auth ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc DB1.crt DB1.esl -Timestamp is 2025-2-13 21:43:30 +Timestamp is 2024-1-12 15:25:52 Authentication Payload size 40 Signature of size 1148 Signature at: 40 ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc DB2.crt DB2.esl +ar rcv lib-efi.a simple_file.efi.o pecoff.efi.o guid.efi.o sha256.efi.o console.efi.o execute.efi.o configtable.efi.o shell.efi.o security_policy.efi.o shim_protocol.efi.o pkcs7verify.efi.o variables.o ./cert-to-efi-sig-list -g 77FA9ABD-0359-4D32-BD60-28F4E78F784B ms-uefi.crt ms-uefi.esl +a - simple_file.efi.o +a - pecoff.efi.o +a - guid.efi.o +a - sha256.efi.o +a - console.efi.o +a - execute.efi.o +a - configtable.efi.o +a - shell.efi.o +a - security_policy.efi.o +a - shim_protocol.efi.o +a - pkcs7verify.efi.o +a - variables.o +make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' ./cert-to-efi-sig-list -g 77FA9ABD-0359-4D32-BD60-28F4E78F784B ms-kek.crt ms-kek.esl ./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB1.esl DB1-update.auth +./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB2.esl DB2-update.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 853 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB2.esl DB2-update.auth ./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-uefi.esl ms-uefi-update.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 853 @@ -2512,26 +2476,26 @@ Signature of size 1151 Signature at: 40 ./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-kek.esl ms-kek-update.auth +./sign-efi-sig-list -a -c PK.crt -k PK.key db DB1.esl DB1-pkupdate.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 1600 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -a -c PK.crt -k PK.key db DB1.esl DB1-pkupdate.auth +./sign-efi-sig-list -a -c PK.crt -k PK.key db DB2.esl DB2-pkupdate.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 853 Signature of size 1148 Signature at: 40 -./sign-efi-sig-list -a -c PK.crt -k PK.key db DB2.esl DB2-pkupdate.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 853 Signature of size 1148 Signature at: 40 ./sign-efi-sig-list -a -c PK.crt -k PK.key db ms-uefi.esl ms-uefi-pkupdate.auth +./sign-efi-sig-list -a -c PK.crt -k PK.key db ms-kek.esl ms-kek-pkupdate.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 1640 Signature of size 1148 Signature at: 40 -./sign-efi-sig-list -a -c PK.crt -k PK.key db ms-kek.esl ms-kek-pkupdate.auth ./cert-to-efi-sig-list PK.crt PK-blacklist.esl Timestamp is 0-0-0 00:00:00 Authentication Payload size 1600 @@ -2543,83 +2507,68 @@ ./cert-to-efi-sig-list DB2.crt DB2-blacklist.esl ./cert-to-efi-sig-list ms-uefi.crt ms-uefi-blacklist.esl ./cert-to-efi-sig-list ms-kek.crt ms-kek-blacklist.esl -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx PK-hash-blacklist.esl PK-hash-blacklist.auth -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx KEK-hash-blacklist.esl KEK-hash-blacklist.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB-hash-blacklist.esl DB-hash-blacklist.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB1-hash-blacklist.esl DB1-hash-blacklist.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB2-hash-blacklist.esl DB2-hash-blacklist.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-uefi-hash-blacklist.esl ms-uefi-hash-blacklist.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-kek-hash-blacklist.esl ms-kek-hash-blacklist.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 -sbsign --key DB.key --cert DB.crt --output HelloWorld-signed.efi HelloWorld.efi -warning: data remaining[44032 vs 53174]: gaps between PE/COFF sections? +./cert-to-efi-hash-list PK.crt PK-hash-blacklist.esl +./cert-to-efi-hash-list KEK.crt KEK-hash-blacklist.esl +TimeOfRevocation is 0-0-0 00:00:00 +./cert-to-efi-hash-list DB.crt DB-hash-blacklist.esl +TimeOfRevocation is 0-0-0 00:00:00 +./cert-to-efi-hash-list DB1.crt DB1-hash-blacklist.esl +TimeOfRevocation is 0-0-0 00:00:00 +./cert-to-efi-hash-list DB2.crt DB2-hash-blacklist.esl +TimeOfRevocation is 0-0-0 00:00:00 +./cert-to-efi-hash-list ms-uefi.crt ms-uefi-hash-blacklist.esl +TimeOfRevocation is 0-0-0 00:00:00 +./cert-to-efi-hash-list ms-kek.crt ms-kek-hash-blacklist.esl +TimeOfRevocation is 0-0-0 00:00:00 +TimeOfRevocation is 0-0-0 00:00:00 +ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds HelloWorld.o lib/lib-efi.a -o HelloWorld.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc PK.crt PK.esl -warning: data remaining[44032 vs 53176]: gaps between PE/COFF sections? -Signing Unsigned original image +# check we have no undefined symbols +nm -D HelloWorld.so | grep ' U ' && exit 1 || exit 0 ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc KEK.crt KEK.esl ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc DB.crt DB.esl -sbsign --key DB.key --cert DB.crt --output Loader-signed.efi Loader.efi -warning: data remaining[84992 vs 96469]: gaps between PE/COFF sections? -warning: data remaining[84992 vs 96472]: gaps between PE/COFF sections? -sbsign --key DB.key --cert DB.crt --output ReadVars-signed.efi ReadVars.efi -Signing Unsigned original image -sbsign --key DB.key --cert DB.crt --output UpdateVars-signed.efi UpdateVars.efi -warning: data remaining[114176 vs 126584]: gaps between PE/COFF sections? -Signing Unsigned original image -sbsign --key DB.key --cert DB.crt --output KeyTool-signed.efi KeyTool.efi -warning: data remaining[83968 vs 95455]: gaps between PE/COFF sections? -warning: data remaining[83968 vs 95456]: gaps between PE/COFF sections? -Signing Unsigned original image -sbsign --key DB.key --cert DB.crt --output HashTool-signed.efi HashTool.efi -warning: data remaining[123392 vs 136192]: gaps between PE/COFF sections? -Signing Unsigned original image -warning: data remaining[84992 vs 96519]: gaps between PE/COFF sections? -warning: data remaining[84992 vs 96520]: gaps between PE/COFF sections? -Signing Unsigned original image +ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds Loader.o lib/lib-efi.a -o Loader.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a +# check we have no undefined symbols +nm -D Loader.so | grep ' U ' && exit 1 || exit 0 +ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds ReadVars.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o ReadVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a +# check we have no undefined symbols +nm -D ReadVars.so | grep ' U ' && exit 1 || exit 0 +ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds UpdateVars.o lib/lib-efi.a -o UpdateVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a +# check we have no undefined symbols +nm -D UpdateVars.so | grep ' U ' && exit 1 || exit 0 +ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds KeyTool.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o KeyTool.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a +# check we have no undefined symbols +nm -D KeyTool.so | grep ' U ' && exit 1 || exit 0 +ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds HashTool.o lib/lib-efi.a -o HashTool.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a +# check we have no undefined symbols +nm -D HashTool.so | grep ' U ' && exit 1 || exit 0 +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 SetNull.so SetNull.efi +ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds ShimReplace.o lib/lib-efi.a -o ShimReplace.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a +cc -o efi-updatevar efi-updatevar.o -g -O2 -fdebug-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -Wformat -Werror=format-security -Wl,-z,relro lib/lib.a -lcrypto +# check we have no undefined symbols +nm -D ShimReplace.so | grep ' U ' && exit 1 || exit 0 +help2man --no-info -i doc/cert-to-efi-hash-list.1.in -o doc/cert-to-efi-hash-list.1 ./cert-to-efi-hash-list +/usr/bin/ld: lib/lib.a(kernel_efivars.o): in function `kernel_variable_init': +/build/reproducible-path/efitools-1.9.2/lib/kernel_efivars.c:40: warning: the use of `mktemp' is dangerous, better use `mkstemp' or `mkdtemp' ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB1.esl DB1.auth -Timestamp is 2025-2-13 21:43:37 +Timestamp is 2024-1-12 15:26:27 Authentication Payload size 853 Signature of size 1151 Signature at: 40 ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB2.esl DB2.auth -Timestamp is 2025-2-13 21:43:38 +./sign-efi-sig-list -c KEK.crt -k KEK.key db ms-uefi.esl ms-uefi.auth +Timestamp is 2024-1-12 15:26:28 Authentication Payload size 853 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -c KEK.crt -k KEK.key db ms-uefi.esl ms-uefi.auth -Timestamp is 2025-2-13 21:43:38 +./sign-efi-sig-list -c KEK.crt -k KEK.key db ms-kek.esl ms-kek.auth +Timestamp is 2024-1-12 15:26:29 Authentication Payload size 1640 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -c KEK.crt -k KEK.key db ms-kek.esl ms-kek.auth -Timestamp is 2025-2-13 21:43:38 +Timestamp is 2024-1-12 15:26:30 Authentication Payload size 1600 Signature of size 1151 Signature at: 40 @@ -2634,16 +2583,16 @@ Authentication Payload size 855 Signature of size 1148 Signature at: 40 +./sign-efi-sig-list -a -c PK.crt -k PK.key PK PK.esl PK-pkupdate.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 851 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -a -c PK.crt -k PK.key PK PK.esl PK-pkupdate.auth +./sign-efi-sig-list -a -c PK.crt -k PK.key KEK KEK.esl KEK-pkupdate.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 851 Signature of size 1148 Signature at: 40 -./sign-efi-sig-list -a -c PK.crt -k PK.key KEK KEK.esl KEK-pkupdate.auth ./sign-efi-sig-list -a -c PK.crt -k PK.key db DB.esl DB-pkupdate.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 855 @@ -2684,28 +2633,114 @@ Authentication Payload size 1642 Signature of size 1151 Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx PK-hash-blacklist.esl PK-hash-blacklist.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 1602 Signature of size 1151 Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx KEK-hash-blacklist.esl KEK-hash-blacklist.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB-hash-blacklist.esl DB-hash-blacklist.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB1-hash-blacklist.esl DB1-hash-blacklist.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB2-hash-blacklist.esl DB2-hash-blacklist.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-uefi-hash-blacklist.esl ms-uefi-hash-blacklist.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-kek-hash-blacklist.esl ms-kek-hash-blacklist.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 HelloWorld.so HelloWorld.efi ./sign-efi-sig-list -c PK.crt -k PK.key PK PK.esl PK.auth -Timestamp is 2025-2-13 21:43:41 +./sign-efi-sig-list -c PK.crt -k PK.key KEK KEK.esl KEK.auth +Timestamp is 2024-1-12 15:26:47 Authentication Payload size 851 Signature of size 1148 Signature at: 40 -./sign-efi-sig-list -c PK.crt -k PK.key KEK KEK.esl KEK.auth -Timestamp is 2025-2-13 21:43:42 +./sign-efi-sig-list -c KEK.crt -k KEK.key db DB.esl DB.auth +Timestamp is 2024-1-12 15:26:48 Authentication Payload size 855 Signature of size 1148 Signature at: 40 -./sign-efi-sig-list -c KEK.crt -k KEK.key db DB.esl DB.auth -Timestamp is 2025-2-13 21:43:42 +Timestamp is 2024-1-12 15:26:49 Authentication Payload size 851 Signature of size 1151 Signature at: 40 +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 Loader.so Loader.efi +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 ReadVars.so ReadVars.efi +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 UpdateVars.so UpdateVars.efi +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 KeyTool.so KeyTool.efi +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 HashTool.so HashTool.efi +sbsign --key DB.key --cert DB.crt --output SetNull-signed.efi SetNull.efi +warning: data remaining[3584 vs 3825]: gaps between PE/COFF sections? +warning: data remaining[3584 vs 3832]: gaps between PE/COFF sections? +Signing Unsigned original image +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 ShimReplace.so ShimReplace.efi +help2man --no-info -i doc/efi-updatevar.1.in -o doc/efi-updatevar.1 ./efi-updatevar +sbsign --key DB.key --cert DB.crt --output HelloWorld-signed.efi HelloWorld.efi ./xxdi.pl PK.auth > PK.h +warning: data remaining[44032 vs 53174]: gaps between PE/COFF sections? +warning: data remaining[44032 vs 53176]: gaps between PE/COFF sections? +Signing Unsigned original image ./xxdi.pl KEK.auth > KEK.h ./xxdi.pl DB.auth > DB.h +sbsign --key DB.key --cert DB.crt --output Loader-signed.efi Loader.efi +sbsign --key DB.key --cert DB.crt --output ReadVars-signed.efi ReadVars.efi +warning: data remaining[84992 vs 96469]: gaps between PE/COFF sections? +warning: data remaining[84992 vs 96472]: gaps between PE/COFF sections? +Signing Unsigned original image +sbsign --key DB.key --cert DB.crt --output UpdateVars-signed.efi UpdateVars.efi +warning: data remaining[114176 vs 126584]: gaps between PE/COFF sections? +Signing Unsigned original image +sbsign --key DB.key --cert DB.crt --output KeyTool-signed.efi KeyTool.efi +warning: data remaining[83968 vs 95455]: gaps between PE/COFF sections? +warning: data remaining[83968 vs 95456]: gaps between PE/COFF sections? +Signing Unsigned original image +sbsign --key DB.key --cert DB.crt --output HashTool-signed.efi HashTool.efi +warning: data remaining[123392 vs 136192]: gaps between PE/COFF sections? +Signing Unsigned original image +sbsign --key DB.key --cert DB.crt --output ShimReplace-signed.efi ShimReplace.efi +warning: data remaining[84992 vs 96519]: gaps between PE/COFF sections? +warning: data remaining[84992 vs 96520]: gaps between PE/COFF sections? +Signing Unsigned original image +warning: data remaining[86016 vs 97944]: gaps between PE/COFF sections? +Signing Unsigned original image cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -fno-stack-protector -ffreestanding -fno-stack-check -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c LockDown.c -o LockDown.o ld -nostdlib -shared -Bsymbolic /usr/lib/crt0-efi-x86_64.o -L /usr/lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds LockDown.o lib/lib-efi.a -o LockDown.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/10/libgcc.a # check we have no undefined symbols @@ -2731,15 +2766,15 @@ make[1]: Entering directory '/build/reproducible-path/efitools-1.9.2' dh_auto_install -- EFIDIR="debian/efitools/usr/lib/efitools/x86_64-linux-gnu" install -d /build/reproducible-path/efitools-1.9.2/debian/efitools - make -j16 install DESTDIR=/build/reproducible-path/efitools-1.9.2/debian/efitools AM_UPDATE_INFO_DIR=no "INSTALL=install --strip-program=true" EFIDIR=debian/efitools/usr/lib/efitools/x86_64-linux-gnu + make -j15 install DESTDIR=/build/reproducible-path/efitools-1.9.2/debian/efitools AM_UPDATE_INFO_DIR=no "INSTALL=install --strip-program=true" EFIDIR=debian/efitools/usr/lib/efitools/x86_64-linux-gnu make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2' make -C lib lib-efi.a make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' make -C lib lib.a -make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' -make -C lib/asn1 libasn1-efi.a make[3]: 'lib-efi.a' is up to date. make[3]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' +make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' +make -C lib/asn1 libasn1-efi.a make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' make[3]: 'lib.a' is up to date. make[3]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' @@ -2776,27 +2811,27 @@ dh_installchangelogs install -p -m0644 debian/changelog debian/efitools/usr/share/doc/efitools/changelog.Debian dh_installman + man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 + man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1 man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/sign-efi-sig-list.1 - man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1 - man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/efi-updatevar.1 man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/efi-readvar.1 - man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1 - man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 - mv debian/efitools/usr/share/man/man1/sign-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/sign-efi-sig-list.1 - chmod 0644 -- debian/efitools/usr/share/man/man1/sign-efi-sig-list.1 - mv debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1 - chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1 + man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 + man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/efi-updatevar.1 mv debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 chmod 0644 -- debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 - mv debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 - chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 - mv debian/efitools/usr/share/man/man1/sig-list-to-certs.1.dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1 - chmod 0644 -- debian/efitools/usr/share/man/man1/sig-list-to-certs.1 + mv debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1 + chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1 mv debian/efitools/usr/share/man/man1/efi-readvar.1.dh-new debian/efitools/usr/share/man/man1/efi-readvar.1 chmod 0644 -- debian/efitools/usr/share/man/man1/efi-readvar.1 + mv debian/efitools/usr/share/man/man1/sign-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/sign-efi-sig-list.1 + chmod 0644 -- debian/efitools/usr/share/man/man1/sign-efi-sig-list.1 mv debian/efitools/usr/share/man/man1/efi-updatevar.1.dh-new debian/efitools/usr/share/man/man1/efi-updatevar.1 chmod 0644 -- debian/efitools/usr/share/man/man1/efi-updatevar.1 + mv debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 + chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 + mv debian/efitools/usr/share/man/man1/sig-list-to-certs.1.dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1 + chmod 0644 -- debian/efitools/usr/share/man/man1/sig-list-to-certs.1 dh_perl dh_link dh_strip_nondeterminism @@ -2898,10 +2933,10 @@ chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/DEBIAN/md5sums chown 0:0 -- debian/.debhelper/efitools/dbgsym-root/DEBIAN/md5sums dh_builddeb - dpkg-deb --build debian/efitools .. dpkg-deb --build debian/.debhelper/efitools/dbgsym-root .. -dpkg-deb: building package 'efitools' in '../efitools_1.9.2-2~deb11u1_amd64.deb'. + dpkg-deb --build debian/efitools .. dpkg-deb: building package 'efitools-dbgsym' in '../efitools-dbgsym_1.9.2-2~deb11u1_amd64.deb'. +dpkg-deb: building package 'efitools' in '../efitools_1.9.2-2~deb11u1_amd64.deb'. dpkg-genbuildinfo --build=binary dpkg-genchanges --build=binary >../efitools_1.9.2-2~deb11u1_amd64.changes dpkg-genchanges: info: binary-only upload (no source code included) @@ -2909,12 +2944,14 @@ dpkg-buildpackage: info: binary-only upload (no source included) dpkg-genchanges: info: not including original source code in upload I: copying local configuration +I: user script /srv/workspace/pbuilder/951627/tmp/hooks/B01_cleanup starting +I: user script /srv/workspace/pbuilder/951627/tmp/hooks/B01_cleanup finished I: unmounting dev/ptmx filesystem I: unmounting dev/pts filesystem I: unmounting dev/shm filesystem I: unmounting proc filesystem I: unmounting sys filesystem I: cleaning the build env -I: removing directory /srv/workspace/pbuilder/2191863 and its subdirectories -I: Current time: Thu Feb 13 09:44:24 -12 2025 -I: pbuilder-time-stamp: 1739483064 +I: removing directory /srv/workspace/pbuilder/951627 and its subdirectories +I: Current time: Sat Jan 13 05:30:49 +14 2024 +I: pbuilder-time-stamp: 1705073449