Diff of the two buildlogs: -- --- b1/build.log 2025-10-02 05:23:41.875045441 +0000 +++ b2/build.log 2025-10-02 05:26:05.307217366 +0000 @@ -1,6 +1,6 @@ I: pbuilder: network access will be disabled during build -I: Current time: Tue Nov 3 23:44:25 -12 2026 -I: pbuilder-time-stamp: 1793792665 +I: Current time: Thu Oct 2 19:23:42 +14 2025 +I: pbuilder-time-stamp: 1759382622 I: Building the build Environment I: extracting base tarball [/var/cache/pbuilder/forky-reproducible-base.tgz] I: copying local configuration @@ -32,53 +32,85 @@ dpkg-source: info: applying gcc15.patch I: using fakeroot in build. I: Installing the build-deps -I: user script /srv/workspace/pbuilder/3581161/tmp/hooks/D02_print_environment starting +I: user script /srv/workspace/pbuilder/729246/tmp/hooks/D01_modify_environment starting +debug: Running on ionos11-amd64. +I: Changing host+domainname to test build reproducibility +I: Adding a custom variable just for the fun of it... +I: Changing /bin/sh to bash +'/bin/sh' -> '/bin/bash' +lrwxrwxrwx 1 root root 9 Oct 2 05:24 /bin/sh -> /bin/bash +I: Setting pbuilder2's login shell to /bin/bash +I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other +I: user script /srv/workspace/pbuilder/729246/tmp/hooks/D01_modify_environment finished +I: user script /srv/workspace/pbuilder/729246/tmp/hooks/D02_print_environment starting I: set - BUILDDIR='/build/reproducible-path' - BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other' - BUILDUSERNAME='pbuilder1' - BUILD_ARCH='amd64' - DEBIAN_FRONTEND='noninteractive' - DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=42 ' - DISTRIBUTION='forky' - HOME='/root' - HOST_ARCH='amd64' + BASH=/bin/sh + BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath + BASH_ALIASES=() + BASH_ARGC=() + BASH_ARGV=() + BASH_CMDS=() + BASH_LINENO=([0]="12" [1]="0") + BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:. + BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment") + BASH_VERSINFO=([0]="5" [1]="3" [2]="3" [3]="1" [4]="release" [5]="x86_64-pc-linux-gnu") + BASH_VERSION='5.3.3(1)-release' + BUILDDIR=/build/reproducible-path + BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other' + BUILDUSERNAME=pbuilder2 + BUILD_ARCH=amd64 + DEBIAN_FRONTEND=noninteractive + DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=40 ' + DIRSTACK=() + DISTRIBUTION=forky + EUID=0 + FUNCNAME=([0]="Echo" [1]="main") + GROUPS=() + HOME=/root + HOSTNAME=i-capture-the-hostname + HOSTTYPE=x86_64 + HOST_ARCH=amd64 IFS=' ' - INVOCATION_ID='300475cdb4354399aee4637fbd43f8d7' - LANG='C' - LANGUAGE='en_US:en' - LC_ALL='C' - MAIL='/var/mail/root' - OPTIND='1' - PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games' - PBCURRENTCOMMANDLINEOPERATION='build' - PBUILDER_OPERATION='build' - PBUILDER_PKGDATADIR='/usr/share/pbuilder' - PBUILDER_PKGLIBDIR='/usr/lib/pbuilder' - PBUILDER_SYSCONFDIR='/etc' - PPID='3581161' - PS1='# ' - PS2='> ' + INVOCATION_ID=ccebab56718447f584e5ca8c3d3e0b94 + LANG=C + LANGUAGE=et_EE:et + LC_ALL=C + MACHTYPE=x86_64-pc-linux-gnu + MAIL=/var/mail/root + OPTERR=1 + OPTIND=1 + OSTYPE=linux-gnu + PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path + PBCURRENTCOMMANDLINEOPERATION=build + PBUILDER_OPERATION=build + PBUILDER_PKGDATADIR=/usr/share/pbuilder + PBUILDER_PKGLIBDIR=/usr/lib/pbuilder + PBUILDER_SYSCONFDIR=/etc + PIPESTATUS=([0]="0") + POSIXLY_CORRECT=y + PPID=729246 PS4='+ ' - PWD='/' - SHELL='/bin/bash' - SHLVL='2' - SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.Fi1HpLsB/pbuilderrc_oRvm --distribution forky --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/forky-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.Fi1HpLsB/b1 --logfile b1/build.log efitools_1.9.2-3.6.dsc' - SUDO_GID='111' - SUDO_HOME='/var/lib/jenkins' - SUDO_UID='106' - SUDO_USER='jenkins' - TERM='unknown' - TZ='/usr/share/zoneinfo/Etc/GMT+12' - USER='root' - _='/usr/bin/systemd-run' - http_proxy='http://213.165.73.152:3128' + PWD=/ + SHELL=/bin/bash + SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix + SHLVL=3 + SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.Fi1HpLsB/pbuilderrc_qzZu --distribution forky --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/forky-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.Fi1HpLsB/b2 --logfile b2/build.log efitools_1.9.2-3.6.dsc' + SUDO_GID=111 + SUDO_HOME=/var/lib/jenkins + SUDO_UID=106 + SUDO_USER=jenkins + TERM=unknown + TZ=/usr/share/zoneinfo/Etc/GMT-14 + UID=0 + USER=root + _='I: set' + http_proxy=http://46.16.76.132:3128 I: uname -a - Linux ionos15-amd64 6.12.48+deb13-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.48-1 (2025-09-20) x86_64 GNU/Linux + Linux i-capture-the-hostname 6.12.48+deb13-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.48-1 (2025-09-20) x86_64 GNU/Linux I: ls -l /bin - lrwxrwxrwx 1 root root 7 Aug 10 2025 /bin -> usr/bin -I: user script /srv/workspace/pbuilder/3581161/tmp/hooks/D02_print_environment finished + lrwxrwxrwx 1 root root 7 Aug 10 12:30 /bin -> usr/bin +I: user script /srv/workspace/pbuilder/729246/tmp/hooks/D02_print_environment finished -> Attempting to satisfy build-dependencies -> Creating pbuilder-satisfydepends-dummy package Package: pbuilder-satisfydepends-dummy @@ -91,7 +123,7 @@ Depends: debhelper-compat (= 12), libfile-slurp-perl, help2man, libssl-dev, openssl, gnu-efi, sbsigntool dpkg-deb: building package 'pbuilder-satisfydepends-dummy' in '/tmp/satisfydepends-aptitude/pbuilder-satisfydepends-dummy.deb'. Selecting previously unselected package pbuilder-satisfydepends-dummy. -(Reading database ... 19919 files and directories currently installed.) +(Reading database ... 19898 files and directories currently installed.) Preparing to unpack .../pbuilder-satisfydepends-dummy.deb ... Unpacking pbuilder-satisfydepends-dummy (0.invalid.0) ... dpkg: pbuilder-satisfydepends-dummy: dependency problems, but configuring anyway as you requested: @@ -162,10 +194,10 @@ Get: 34 http://deb.debian.org/debian forky/main amd64 libssl-dev amd64 3.5.3-1 [2979 kB] Get: 35 http://deb.debian.org/debian forky/main amd64 openssl amd64 3.5.3-1 [1495 kB] Get: 36 http://deb.debian.org/debian forky/main amd64 sbsigntool amd64 0.9.4-3.2 [67.5 kB] -Fetched 16.3 MB in 7s (2482 kB/s) +Fetched 16.3 MB in 9s (1915 kB/s) Preconfiguring packages ... Selecting previously unselected package liblocale-gettext-perl. -(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 19919 files and directories currently installed.) +(Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 19898 files and directories currently installed.) Preparing to unpack .../00-liblocale-gettext-perl_1.07-7+b1_amd64.deb ... Unpacking liblocale-gettext-perl (1.07-7+b1) ... Selecting previously unselected package sensible-utils. @@ -327,7 +359,11 @@ fakeroot is already the newest version (1.37.1.2-1). 0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. I: Building the package -I: Running cd /build/reproducible-path/efitools-1.9.2/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S > ../efitools_1.9.2-3.6_source.changes +I: user script /srv/workspace/pbuilder/729246/tmp/hooks/A99_set_merged_usr starting +Not re-configuring usrmerge for forky +I: user script /srv/workspace/pbuilder/729246/tmp/hooks/A99_set_merged_usr finished +hostname: Name or service not known +I: Running cd /build/reproducible-path/efitools-1.9.2/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S > ../efitools_1.9.2-3.6_source.changes dpkg-buildpackage: info: source package efitools dpkg-buildpackage: info: source version 1.9.2-3.6 dpkg-buildpackage: info: source distribution unstable @@ -337,7 +373,7 @@ debian/rules clean dh clean dh_auto_clean - make -j42 clean + make -j40 clean make[1]: Entering directory '/build/reproducible-path/efitools-1.9.2' rm -f PK.* KEK.* DB.* HelloWorld.efi LockDown.efi Loader.efi ReadVars.efi UpdateVars.efi KeyTool.efi HashTool.efi SetNull.efi ShimReplace.efi HelloWorld-signed.efi LockDown-signed.efi Loader-signed.efi ReadVars-signed.efi UpdateVars-signed.efi KeyTool-signed.efi HashTool-signed.efi SetNull-signed.efi ShimReplace-signed.efi cert-to-efi-sig-list sig-list-to-certs sign-efi-sig-list hash-to-efi-sig-list efi-readvar efi-updatevar cert-to-efi-hash-list flash-var *.o *.so rm -f noPK.* @@ -377,46 +413,43 @@ dh_autoreconf dh_auto_configure dh_auto_build - make -j42 INSTALL="install --strip-program=true" + make -j40 INSTALL="install --strip-program=true" make[1]: Entering directory '/build/reproducible-path/efitools-1.9.2' make -C lib lib-efi.a make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c HelloWorld.c -o HelloWorld.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c simple_file.c -o simple_file.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pecoff.c -o pecoff.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c HelloWorld.c -o HelloWorld.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c guid.c -o guid.efi.o openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB/" -keyout DB.key -out DB.crt -days 3650 -nodes -sha256 +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c sha256.c -o sha256.efi.o openssl req -new -x509 -newkey rsa:2048 -subj "/CN=PK/" -keyout PK.key -out PK.crt -days 3650 -nodes -sha256 -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pecoff.c -o pecoff.efi.o -.....+.....+....+......+.....+.+...+..+...+...............+....+......+..+++++++++++++++++++++++++++++++++++++++*..+..........+..+......+...+.+...+.....+.+..+...+....+...+..+.+++++++++++++++++++++++++++++++++++++++*.....+...+.....+.......+......+..+.+.....+.+......+........+.+........+..........+...+..+......+.+...+...+........+....+..+.+...+..+.............+......+......+.........+.....................+..+............+.......+.............+....................+....+..........+.+......++..+++++++++++++++++++++++++++++++++++++++*..+........+....+....+...+..++..................+...+..................++++++++++++++++++++++++++++++++.+..+...+++++*+........+.....+.+...................+.....+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-sig-list.c -o cert-to-efi-sig-list.o -..+.+...+..+........................+................+...............+.....+......+.+.......+.....+......+.........+......+.+......+...................+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c guid.c -o guid.efi.o -+...........++........++...................++.............++...........+..+.........+...+..............+.+...........++....++......++.+........+................++......+........+.......+...+...+............+...+....................++........++..........++............++........................++.......++.........++..........++.+....+....++....++.......++.......++....................+.+...............+..+......+..................+.....+............+......+make -C lib lib.a -...+.+......+........+.....+.+.+......+........+..+..........+.........+..........+...+..+..+......+..........+...............+.....................+....+..+..+.......+...+..........++.....++........++.........++....++............++.........+.......+....++.........++.............++.........++......++............++.........++.....++................++..............++cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c sha256.c -o sha256.efi.o -.....++..........+............+....+....................+....+....+++.....................++..++.++ -....+...+........+....+.....+............++...+.............+...........+....+.....+...++.....+.+.........+.........+.........+........++.......+...+..+++++..+.....+.....+++++++++++++...+++++++++++++.+++++++++*....+..........+....++............+.+openssl req -new -x509 -newkey rsa:2048 -subj "/CN=KEK/" -keyout KEK.key -out KEK.crt -days 3650 -nodes -sha256 -++++++++++++++++++++++++++++++++++..+..+++*+........make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' -.+........+..................+.............+........+........+.+.......+.+.......++.........++..+.............+.+..+................++.......++....+.....+...........+.....+......++..............+.......+..+.......+..........+................................+.+..+.....+........+......+..+......+...+.........+....+.....+...+........+.+..........+...+....................++...++................++.......++....++...........++.........++.....++.................+...+.............+.+.............+..+.+....+...........++......++.................++.....++.....++......++......++............++..................++......+....+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c console.c -o console.efi.o -..............++......++.........................++...+..+......++.....++..........++............+......++.........+..+.+........+.......+...............+..+++++...++++++++++++++++++++.+.+.+..+.+.+..+....+.+++++++++*.....+........+...+.......+........+...+.+.......+...+++++++++++++++++++++.+.+.+..++.+...+..+.+.+.+++++++++++*...+........++......+.+.+....+..............+.............+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sign-efi-sig-list.c -o sign-efi-sig-list.o -................+.........++.............++..+..+....++.....................+..++............+++........+.....+..........+..................+++..............+........++....................+...++....................+.........++......++.+...................+.++....+..........++...................+++...........+.+.++......+++....+.++................+++.+ -..+...........+...++...++.........+.....+.......+++++++++++++++++.+.+++++++++++++.+..+.+..+.+..+.+..++*...+......+.........+....+.......+.......+.....+..++++++++++++++++++++++++++..++++++++++++++.+*..............+.........+.....cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c simple_file.c -o simple_file.o -+......+......++........++....+...................+.....+.....+......+.....+.....+................++............+....++.......+...........+.++..+......+++....+++..................++...++ -....+..+.+.++++++++++++++++++++++++++..+...++++++++++++*..+.+.....+.......+...+.........+....+..+...+....+.+++++.+.+..++++++++++++++++++++..+..+..+++++++++*.......+.............++..+....+.......+..............+...+...+.+..............++.............+++......+.++.............+...++...............+++...........+++...+......+...+....++.....+............+.cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c execute.c -o execute.efi.o -+.+......+.....+.........+...............+.........++...+................+++......+++............+.......+++ -......+..+.........+...+..+.....+..+....+...+..+..................++.....+...................++...----- -......++.....+.+.........++...cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c Loader.c -o Loader.o -.........++..........+.....+..................++..............++......++................++.......++........+......+....+.................+........+......+..........+.........++.....................++........++.............++.+++...++..++......+.+ -...+...+...........+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pecoff.c -o pecoff.o -......+...+.+..+.............+.........+...+..+...++++++ ------ +..+...+.....+..........+...+........+.+.....+.............+.................+......+...+......+....+..+....+.........+......+.........+.....+.+...............+.....+...+......+.......+..............+++++++++++++++++++++++++++++++++++++++*......+.+...+.....+....+..+................+.....+.......+..+....+++++++++++++++++++++++++++++++++++++++*...+.....+...+............+.+...+............+.....+.........+...+...+.......+...+..............+...+.+............+.....+....+...+..+.............+...........+....+........++++++ +..+...+.....+..........+..+.+......+...........+...+.+......+........+.......+..+++++++++++++++++++++++++++++++++++++++*...+....+.....+...+.........+..........+...+........+...+......+.+...+++++++++++++++++++++++++++++++++++++++*....+.....+.+..+...............+.+.................+.........+....+..+...+........+.....++...+........................+++++++++++++++++++++++++++++cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c console.c -o console.efi.o +++++++..++++*.++...+....+...+...+...........+...+......+++++++++++.+..++++++++++++++++++++++++++..+...+*..............++.........+..+.........+.+................++.......+.......+.......++........++..........++..........+..+....+...............+.......++........++cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-sig-list.c -o cert-to-efi-sig-list.o +...+.....+..................++.........................+.+..........+.....+.........+.+................++.......++....+.......+......++.....++..............+.....+.....+.+....++...............+.+.+......+.........++....+..+............+......+...+..+......+...+...........++........++...++...........++...+...+....++............++......++....++.....+..+....++.........++...............++...........++..++..............++...++.............++................++..........+..+...+...+........++................++...........+........+..............+..........+.+...+...+...+...+..............+........+.+......+............+.+...+.....+..................++.......+.........+...................+.......+.................++..................+.+........++................++.....+.+.+...............+..............+..................make -C lib lib.a +++...++..........++..........+.+..........++.........++....+...+.........++.......++......+.....+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c execute.c -o execute.efi.o +.......................++...........++..........++................+.+........................+..........+..............+..+.........+...+....+.........++.......++.........++...................++.......++....++.....++.......++.....++......++ +...................+.........................+..+...+.....+...+...+............+++++++++..+.+++++++++++++..+.+++++++++++++++.+..+.*........++...+...............+...+.........+...+..++...++++++++++++++++.....+....+.++++++++++++++++..++....+...++*+..+...+...++.+.....+.........+....+..+..+..........+..........+.....+.+.......++.......++..................++.........++...............++............++....++....+.........................+.........+.+..+.....+..........+.........+...+..........+.........+.....+...........+...+.+....+..........+..openssl req -new -x509 -newkey rsa:2048 -subj "/CN=KEK/" -keyout KEK.key -out KEK.crt -days 3650 -nodes -sha256 +....+.......++...+.make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' +......+..+..................+......+.....+.+......+.....+......+...+........++.....+..+......+.................+.......+...+...................++...+.+...+............................+....+......+.....+..........+......+.+..............+.......+.....++.+.....+......+...+..............+.....+.....+.+...................+++...++.......++ +......+...........+.+..+.+...........+...+...+.........+.............+......+..+.cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c configtable.c -o configtable.efi.o +..----- ++....+...+..+.+..+....+.....+......+...+...............+.+......+...+.....+.+.....+.+...............+........+....+......+.....+......+.+.....+.........+......+.......+...+...+..+....+..........................+...+.+...............+...+.+...+.......+........+....+.....+....+.....+...+...+...............++++++++++++++...+...+.+++++++++++++++...+..+...+....+..+++++++*.+...........+.+...+..................+............++...+....+.....+......+...+......+......+..++++++++++++++++.+++++++++++++++.+....++++++++*.+......+....+...+.............................++cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sign-efi-sig-list.c -o sign-efi-sig-list.o +...+.......+......+.+..........++................+..........+......+...++...++...+++..............++ +.......+...+..+......+...+.+...+......+......+...+----- +..+....+......+......+..+..................+.......+...+.....+.......+......+......+...+..+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shell.c -o shell.efi.o +................+...+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c simple_file.c -o simple_file.o +.....+....+...+..+.+.....+.+.....+....+............+.....+.......+..+.........+....+..+.+..+.......+..............+............+....+...+..+.+..+......+......+.+.....+...+....+...+..............+.+........+......+...+............+...+.+......+...+........+...+..........+.....+.+...........+....+...+..+.+.........+......+.....+...+..........+..+...............+.............+.....+......+.+...+...........+.+.....+............+.......+.....+.+..............+...+...+...........................+.............+..+.+...........cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pecoff.c -o pecoff.o ++.+........+....+............+.....+......+............+.+......+.....+....+.....+..........+..+.......+...+...+......+.....+...+.......+......+.....+...+....+...+...............+..+.+......+........+.+.....+..........+..+....+...+..+...+......++++++ +....+.+........+.........+......+.+++++++++++++++++++++++++++++++++++++++*..+...+....+...+......+++++++++++++++++++++++++++++++++++++++*.+......+...+...........+.+......+....................+...+...................+..+.+.....+.........+.+...........................+.....+..........+..+.+..+.......+......+..+............+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c guid.c -o guid.o +...+.......+.....+....+............+............+........+...+.+...+...+...++++++ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c Loader.c -o Loader.o ----- -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c configtable.c -o configtable.efi.o -make -C lib/asn1 libasn1-efi.a -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c guid.c -o guid.o -make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shell.c -o shell.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ReadVars.c -o ReadVars.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sha256.c -o sha256.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c UpdateVars.c -o UpdateVars.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c security_policy.c -o security_policy.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1.c -o asn1.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sha256.c -o sha256.o +make -C lib/asn1 libasn1-efi.a +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shim_protocol.c -o shim_protocol.efi.o In file included from pecoff.c:69: pecoff.c: In function 'pecoff_relocate': /build/reproducible-path/efitools-1.9.2/include/buildefi.h:8:27: warning: too many arguments for format [-Wformat-extra-args] @@ -425,47 +458,23 @@ pecoff.c:197:17: note: in expansion of macro 'Print' 197 | Print(L"Reloc table overflows binary %d %d\n", | ^~~~~ -ReadVars.c: In function 'efi_main': -ReadVars.c:177:73: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=] - 177 | Print(L"Variable %s has no entries\n", variables[i]); - | ^ -ReadVars.c:112:41: note: unnamed temporary defined here - 112 | variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL}; - | ^ -ReadVars.c:179:67: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=] - 179 | Print(L"Failed to get %s: %d\n", variables[i], status); - | ^ -ReadVars.c:112:41: note: unnamed temporary defined here - 112 | variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL}; - | ^ -ReadVars.c:184:61: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=] - 184 | parse_db(data, len, image, variables[i], save_keys); - | ^ -ReadVars.c:112:41: note: unnamed temporary defined here - 112 | variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL}; - | ^ -ReadVars.c:182:61: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=] - 182 | parse_db(data, len, image, variables[i], save_keys); - | ^ -ReadVars.c:112:41: note: unnamed temporary defined here - 112 | variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL}; - | ^ -ReadVars.c:181:68: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=] - 181 | Print(L"Variable %s length %d\n", variables[i], len); - | ^ -ReadVars.c:112:41: note: unnamed temporary defined here - 112 | variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL}; - | ^ cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c console.c -o console.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shim_protocol.c -o shim_protocol.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1_parser.c -o asn1_parser.efi.o +make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ReadVars.c -o ReadVars.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c UpdateVars.c -o UpdateVars.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1.c -o asn1.efi.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c KeyTool.c -o KeyTool.o -In file included from asn1.c:18: -chunk.h: In function 'chunk_equals': +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1_parser.c -o asn1_parser.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pkcs7verify.c -o pkcs7verify.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c execute.c -o execute.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c HashTool.c -o HashTool.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c enumerator.c -o enumerator.efi.o UpdateVars.c: In function 'efi_main': UpdateVars.c:24:49: warning: variable 'owner_guid' set but not used [-Wunused-but-set-variable] 24 | CHAR16 **ARGV, *var, *name, *progname, *owner_guid; | ^~~~~~~~~~ +In file included from asn1_parser.c:18: +chunk.h: In function 'chunk_equals': chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); | ~^~~~ @@ -493,20 +502,7 @@ | ^~~~~ /usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} 414 | IN CONST CHAR8 *s2, -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c execute.c -o execute.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pkcs7verify.c -o pkcs7verify.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c HashTool.c -o HashTool.o -In file included from sha256.c:35: -sha256.c: In function 'sha256_get_pecoff_digest_mem': -/build/reproducible-path/efitools-1.9.2/include/buildefi.h:8:27: warning: too many arguments for format [-Wformat-extra-args] - 8 | #define Print(...) printf("%ls", __VA_ARGS__) - | ^~~~~ -sha256.c:360:17: note: in expansion of macro 'Print' - 360 | Print(L"Invalid Data Size %d bytes too small\n", DataSize + context.SecDir->Size - sum_of_bytes); - | ^~~~~ -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c enumerator.c -o enumerator.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c configtable.c -o configtable.o -In file included from asn1_parser.c:18: +In file included from asn1.c:18: chunk.h: In function 'chunk_equals': chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); @@ -539,20 +535,128 @@ asn1_parser.c:82:15: warning: variable 'level' set but not used [-Wunused-but-set-variable] 82 | u_int level; | ^~~~~ +In file included from sha256.c:35: +sha256.c: In function 'sha256_get_pecoff_digest_mem': +/build/reproducible-path/efitools-1.9.2/include/buildefi.h:8:27: warning: too many arguments for format [-Wformat-extra-args] + 8 | #define Print(...) printf("%ls", __VA_ARGS__) + | ^~~~~ +sha256.c:360:17: note: in expansion of macro 'Print' + 360 | Print(L"Invalid Data Size %d bytes too small\n", DataSize + context.SecDir->Size - sum_of_bytes); + | ^~~~~ +ReadVars.c: In function 'efi_main': +ReadVars.c:177:73: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=] + 177 | Print(L"Variable %s has no entries\n", variables[i]); + | ^ +ReadVars.c:112:41: note: unnamed temporary defined here + 112 | variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL}; + | ^ +ReadVars.c:179:67: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=] + 179 | Print(L"Failed to get %s: %d\n", variables[i], status); + | ^ +ReadVars.c:112:41: note: unnamed temporary defined here + 112 | variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL}; + | ^ +ReadVars.c:184:61: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=] + 184 | parse_db(data, len, image, variables[i], save_keys); + | ^ +ReadVars.c:112:41: note: unnamed temporary defined here + 112 | variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL}; + | ^ +ReadVars.c:182:61: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=] + 182 | parse_db(data, len, image, variables[i], save_keys); + | ^ +ReadVars.c:112:41: note: unnamed temporary defined here + 112 | variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL}; + | ^ +ReadVars.c:181:68: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=] + 181 | Print(L"Variable %s length %d\n", variables[i], len); + | ^ +ReadVars.c:112:41: note: unnamed temporary defined here + 112 | variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL}; + | ^ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c configtable.c -o configtable.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c variables.c -o variables.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c SetNull.c -o SetNull.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c chunk.c -o chunk.efi.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c shell.c -o shell.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ShimReplace.c -o ShimReplace.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c oid.c -o oid.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c security_policy.c -o security_policy.o +HashTool.c: In function 'efi_main': +HashTool.c:187:25: warning: variable 'setup_mode_arg' set but not used [-Wunused-but-set-variable] + 187 | setup_mode_arg = 0, keytool = NOSEL; + | ^~~~~~~~~~~~~~ +HashTool.c:185:28: warning: variable 'setup_mode' set but not used [-Wunused-but-set-variable] + 185 | int c = 0, setup_mode = NOSEL, uefi_reboot = NOSEL, + | ^~~~~~~~~~ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sig-list-to-certs.c -o sig-list-to-certs.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c identification.c -o identification.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c SetNull.c -o SetNull.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c shim_protocol.c -o shim_protocol.o +In file included from chunk.c:18: +chunk.h: In function 'chunk_equals': +chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:32: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +chunk.h:139:43: note: in expansion of macro 'memeq' + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ^~~~~ +In file included from typedefs.h:3: +/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 413 | IN CONST CHAR8 *s1, +chunk.h:139:57: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:34: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +chunk.h:139:43: note: in expansion of macro 'memeq' + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ^~~~~ +/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 414 | IN CONST CHAR8 *s2, +chunk.c: In function 'chunk_compare': +chunk.c:55:24: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] + 55 | return memcmp(a.ptr, b.ptr, len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:32: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 413 | IN CONST CHAR8 *s1, +chunk.c:55:31: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] + 55 | return memcmp(a.ptr, b.ptr, len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:34: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 414 | IN CONST CHAR8 *s2, cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c x509.c -o x509.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ShimReplace.c -o ShimReplace.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pkcs7verify.c -o pkcs7verify.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sig-list-to-certs.c -o sig-list-to-certs.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c kernel_efivars.c -o kernel_efivars.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c hash-to-efi-sig-list.c -o hash-to-efi-sig-list.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-readvar.c -o efi-readvar.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-updatevar.c -o efi-updatevar.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-hash-list.c -o cert-to-efi-hash-list.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c flash-var.c -o flash-var.o +> noPK.esl +openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB1/" -keyout DB1.key -out DB1.crt -days 3650 -nodes -sha256 +..+++++++++++++++++++++++++++++++++++++++*.+.+...+.................+...+.+.....+...+...+..........+++++++++++++++++++++++++++++++++++++++*.+.................+.........+....+.....+.........+.+.........+.....+.+............+........+.+........+......+.+......+.....+...+....+...+........+.+.....+....+.........+..+.............+......+.....+.......+..+.+..+..........+..............+.............+.....+......+.+.....+.........+....+........+.......+..+....+.....+.+...+...........+....++++++ +......+++++++++++++++++++++++++++++++++++++++*...+...+........+.........+++++++++++++++++++++++++++++++++++++++*...+......+.....+.........+...+...+......+...................+..+...+.+........+...+....+.....+...............+......+....+........+......+.......+...+..+....+.........+......+.........+..+...+......+.+............+...+..............+.+.........+.....+......+...+....+......+.....+.........+.+.....+.......+.....+...+.+....................+....+.........+..+.+...+..+.......+..+......+.......+.....+......+....+.....+.+...........+...+..........+...+........+.+.....+....+.....+.........+............................+..+......+.......+..............+....+.................+...+......+.........+....+...+.................................+..+...+.+...+..+.........+.......+.....+...+....+..+...+.............+.................+.+......+...........+...+.+...........+...+....+.....+............+.+........+................+....................+..........+...+.....+...+.......+........+..........+..+.+......+......+...+.........+..+.........+....+...+.....+.......+......+..............+......+.......+.....+....+.....+.+........+.........+.+.....+.+.....+......+....+..................+...+.....+.........+...+................+......+......+..............+...+............+...+...+....+...........+.............+..+.............+..+..........+...+..+.......+..+................+.....+.........+..........+...+...+.....+...+....+..+....+...........+.........+.+......+...+.....+......+................+..+...+...+.+...+.....+............+.+...+.........+...+............+.....+...+...+....+......+.....+.......+........+.+........+.+...........+.+..............+.+.....+...+......+.+.........+...+..+..........+...........+.........+.+........+.......+..+......+............+.......+...+...+..+.......+..+......+....+..................+...+..............+.....................+....+...+..+......+...+......+......+.......+..+..........+...+..+.........+.+......+...+..+............+......+.+......+..............+.............+..+.+...............+..+.+..+.............+..+....+...+...........+......+..........+......++++++ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c security_policy.c -o security_policy.o +openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB2/" -keyout DB2.key -out DB2.crt -days 3650 -nodes -sha256 +----- +cert-to-efi-hash-list.c:9:9: warning: '_XOPEN_SOURCE' redefined + 9 | #define _XOPEN_SOURCE + | ^~~~~~~~~~~~~ +: note: this is the location of the previous definition oid.c:13:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 13 | {0x02, 7, 1, 0, "ITU-T Administration" }, /* 0 */ | ^~~~~~~~~~~~~~~~~~~~~~ @@ -637,7 +741,6 @@ 33 | { 0x03, 21, 0, 2, "CN" }, /* 20 */ | ^~~~ oid.c:33:43: note: (near initialization for 'oid_names[20].name') -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c openssl_sign.c -o openssl_sign.o oid.c:34:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 34 | { 0x04, 22, 0, 2, "S" }, /* 21 */ | ^~~ @@ -706,8 +809,6 @@ 50 | { 0x1D, 0, 1, 1, "id-ce" }, /* 37 */ | ^~~~~~~ oid.c:50:43: note: (near initialization for 'oid_names[37].name') -In file included from identification.c:18: -chunk.h: In function 'chunk_equals': oid.c:51:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 51 | { 0x09, 39, 0, 2, "subjectDirectoryAttrs" }, /* 38 */ | ^~~~~~~~~~~~~~~~~~~~~~~ @@ -724,17 +825,6 @@ 54 | { 0x10, 42, 0, 2, "privateKeyUsagePeriod" }, /* 41 */ | ^~~~~~~~~~~~~~~~~~~~~~~ oid.c:54:43: note: (near initialization for 'oid_names[41].name') -chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:32: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ -chunk.h:139:43: note: in expansion of macro 'memeq' - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ^~~~~ oid.c:55:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 55 | { 0x11, 43, 0, 2, "subjectAltName" }, /* 42 */ | ^~~~~~~~~~~~~~~~ @@ -743,9 +833,6 @@ 56 | { 0x12, 44, 0, 2, "issuerAltName" }, /* 43 */ | ^~~~~~~~~~~~~~~ oid.c:56:43: note: (near initialization for 'oid_names[43].name') -In file included from typedefs.h:3: -/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 413 | IN CONST CHAR8 *s1, oid.c:57:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 57 | { 0x13, 45, 0, 2, "basicConstraints" }, /* 44 */ | ^~~~~~~~~~~~~~~~~~ @@ -753,20 +840,7 @@ oid.c:58:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 58 | { 0x14, 46, 0, 2, "crlNumber" }, /* 45 */ | ^~~~~~~~~~~ -chunk.h:139:57: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:34: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ -chunk.h:139:43: note: in expansion of macro 'memeq' - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ^~~~~ oid.c:58:43: note: (near initialization for 'oid_names[45].name') -/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 414 | IN CONST CHAR8 *s2, oid.c:59:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 59 | { 0x15, 47, 0, 2, "reasonCode" }, /* 46 */ | ^~~~~~~~~~~~ @@ -878,123 +952,6 @@ oid.c:86:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 86 | { 0x01, 0, 1, 8, "algorithm" }, /* 73 */ | ^~~~~~~~~~~ -identification.c: At top level: -identification.c:34:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 34 | {"ND", OID_NAME_DISTINGUISHER, ASN1_PRINTABLESTRING}, - | ^~~~ -identification.c:34:10: note: (near initialization for 'x501rdns[0].name') -identification.c:35:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 35 | {"UID", OID_PILOT_USERID, ASN1_PRINTABLESTRING}, - | ^~~~~ -identification.c:35:10: note: (near initialization for 'x501rdns[1].name') -identification.c:36:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 36 | {"DC", OID_PILOT_DOMAIN_COMPONENT, ASN1_PRINTABLESTRING}, - | ^~~~ -identification.c:36:10: note: (near initialization for 'x501rdns[2].name') -identification.c:37:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 37 | {"CN", OID_COMMON_NAME, ASN1_PRINTABLESTRING}, - | ^~~~ -identification.c:37:10: note: (near initialization for 'x501rdns[3].name') -identification.c:38:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 38 | {"S", OID_SURNAME, ASN1_PRINTABLESTRING}, - | ^~~ -identification.c:38:10: note: (near initialization for 'x501rdns[4].name') -identification.c:39:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 39 | {"SN", OID_SERIAL_NUMBER, ASN1_PRINTABLESTRING}, - | ^~~~ -identification.c:39:10: note: (near initialization for 'x501rdns[5].name') -identification.c:40:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 40 | {"serialNumber", OID_SERIAL_NUMBER, ASN1_PRINTABLESTRING}, - | ^~~~~~~~~~~~~~ -identification.c:40:10: note: (near initialization for 'x501rdns[6].name') -identification.c:41:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 41 | {"C", OID_COUNTRY, ASN1_PRINTABLESTRING}, - | ^~~ -identification.c:41:10: note: (near initialization for 'x501rdns[7].name') -identification.c:42:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 42 | {"L", OID_LOCALITY, ASN1_PRINTABLESTRING}, - | ^~~ -identification.c:42:10: note: (near initialization for 'x501rdns[8].name') -identification.c:43:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 43 | {"ST", OID_STATE_OR_PROVINCE, ASN1_PRINTABLESTRING}, - | ^~~~ -identification.c:43:10: note: (near initialization for 'x501rdns[9].name') -identification.c:44:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 44 | {"O", OID_ORGANIZATION, ASN1_PRINTABLESTRING}, - | ^~~ -identification.c:44:10: note: (near initialization for 'x501rdns[10].name') -identification.c:45:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 45 | {"OU", OID_ORGANIZATION_UNIT, ASN1_PRINTABLESTRING}, - | ^~~~ -identification.c:45:10: note: (near initialization for 'x501rdns[11].name') -identification.c:46:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 46 | {"T", OID_TITLE, ASN1_PRINTABLESTRING}, - | ^~~ -identification.c:46:10: note: (near initialization for 'x501rdns[12].name') -identification.c:47:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 47 | {"D", OID_DESCRIPTION, ASN1_PRINTABLESTRING}, - | ^~~ -identification.c:47:10: note: (near initialization for 'x501rdns[13].name') -identification.c:48:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 48 | {"N", OID_NAME, ASN1_PRINTABLESTRING}, - | ^~~ -identification.c:48:10: note: (near initialization for 'x501rdns[14].name') -identification.c:49:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 49 | {"G", OID_GIVEN_NAME, ASN1_PRINTABLESTRING}, - | ^~~ -identification.c:49:10: note: (near initialization for 'x501rdns[15].name') -identification.c:50:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 50 | {"I", OID_INITIALS, ASN1_PRINTABLESTRING}, - | ^~~ -identification.c:50:10: note: (near initialization for 'x501rdns[16].name') -identification.c:51:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 51 | {"dnQualifier", OID_DN_QUALIFIER, ASN1_PRINTABLESTRING}, - | ^~~~~~~~~~~~~ -identification.c:51:10: note: (near initialization for 'x501rdns[17].name') -identification.c:52:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 52 | {"ID", OID_UNIQUE_IDENTIFIER, ASN1_PRINTABLESTRING}, - | ^~~~ -identification.c:52:10: note: (near initialization for 'x501rdns[18].name') -identification.c:53:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 53 | {"EN", OID_EMPLOYEE_NUMBER, ASN1_PRINTABLESTRING}, - | ^~~~ -identification.c:53:10: note: (near initialization for 'x501rdns[19].name') -identification.c:54:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 54 | {"employeeNumber", OID_EMPLOYEE_NUMBER, ASN1_PRINTABLESTRING}, - | ^~~~~~~~~~~~~~~~ -identification.c:54:10: note: (near initialization for 'x501rdns[20].name') -identification.c:55:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 55 | {"E", OID_EMAIL_ADDRESS, ASN1_IA5STRING}, - | ^~~ -identification.c:55:10: note: (near initialization for 'x501rdns[21].name') -identification.c:56:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 56 | {"Email", OID_EMAIL_ADDRESS, ASN1_IA5STRING}, - | ^~~~~~~ -identification.c:56:10: note: (near initialization for 'x501rdns[22].name') -identification.c:57:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 57 | {"emailAddress", OID_EMAIL_ADDRESS, ASN1_IA5STRING}, - | ^~~~~~~~~~~~~~ -identification.c:57:10: note: (near initialization for 'x501rdns[23].name') -identification.c:58:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 58 | {"UN", OID_UNSTRUCTURED_NAME, ASN1_IA5STRING}, - | ^~~~ -identification.c:58:10: note: (near initialization for 'x501rdns[24].name') -identification.c:59:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 59 | {"unstructuredName", OID_UNSTRUCTURED_NAME, ASN1_IA5STRING}, - | ^~~~~~~~~~~~~~~~~~ -identification.c:59:10: note: (near initialization for 'x501rdns[25].name') -identification.c:60:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 60 | {"UA", OID_UNSTRUCTURED_ADDRESS, ASN1_PRINTABLESTRING}, - | ^~~~ -identification.c:60:10: note: (near initialization for 'x501rdns[26].name') -identification.c:61:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 61 | {"unstructuredAddress", OID_UNSTRUCTURED_ADDRESS, ASN1_PRINTABLESTRING}, - | ^~~~~~~~~~~~~~~~~~~~~ -identification.c:61:10: note: (near initialization for 'x501rdns[27].name') -identification.c:62:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 62 | {"TCGID", OID_TCGID, ASN1_PRINTABLESTRING} - | ^~~~~~~ -identification.c:62:10: note: (near initialization for 'x501rdns[28].name') oid.c:86:43: note: (near initialization for 'oid_names[73].name') oid.c:87:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 87 | { 0x01, 0, 1, 9, "symm-encryption-alg" }, /* 74 */ @@ -1020,9 +977,6 @@ 92 | { 0x48, 0, 1, 2, "us" }, /* 79 */ | ^~~~ oid.c:92:43: note: (near initialization for 'oid_names[79].name') -identification.c:33:24: warning: 'x501rdns' defined but not used [-Wunused-const-variable=] - 33 | static const x501rdn_t x501rdns[] = { - | ^~~~~~~~ oid.c:93:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 93 | { 0x86, 128, 1, 3, "" }, /* 80 */ | ^~ @@ -1058,11 +1012,7 @@ oid.c:101:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 101 | { 0x01, 123, 1, 6, "PKCS" }, /* 88 */ | ^~~~~~ -ShimReplace.c: In function 'efi_main': oid.c:101:43: note: (near initialization for 'oid_names[88].name') -ShimReplace.c:51:37: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers] - 51 | efi_status = execute(image, loader); - | ^~~~~~ oid.c:102:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 102 | { 0x01, 100, 1, 7, "PKCS-1" }, /* 89 */ | ^~~~~~~~ @@ -1070,21 +1020,11 @@ oid.c:103:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 103 | { 0x01, 91, 0, 8, "rsaEncryption" }, /* 90 */ | ^~~~~~~~~~~~~~~ -In file included from ShimReplace.c:17: -/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'} - 5 | execute(EFI_HANDLE image, CHAR16 *name); - | ~~~~~~~~^~~~ oid.c:103:43: note: (near initialization for 'oid_names[90].name') -ShimReplace.c:57:37: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers] - 57 | efi_status = execute(image, fallback); - | ^~~~~~~~ oid.c:104:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 104 | { 0x02, 92, 0, 8, "md2WithRSAEncryption" }, /* 91 */ | ^~~~~~~~~~~~~~~~~~~~~~ oid.c:104:43: note: (near initialization for 'oid_names[91].name') -/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'} - 5 | execute(EFI_HANDLE image, CHAR16 *name); - | ~~~~~~~~^~~~ oid.c:105:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 105 | { 0x04, 93, 0, 8, "md5WithRSAEncryption" }, /* 92 */ | ^~~~~~~~~~~~~~~~~~~~~~ @@ -1693,8 +1633,6 @@ 256 | { 0x24, 289, 1, 1, "TeleTrusT" }, /* 243 */ | ^~~~~~~~~~~ oid.c:256:43: note: (near initialization for 'oid_names[243].name') -In file included from x509.c:1: -chunk.h: In function 'chunk_equals': oid.c:257:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 257 | { 0x03, 0, 1, 2, "algorithm" }, /* 244 */ | ^~~~~~~~~~~ @@ -1714,17 +1652,6 @@ oid.c:261:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 261 | { 0x03, 249, 0, 5, "rsaSigWithripemd128" }, /* 248 */ | ^~~~~~~~~~~~~~~~~~~~~ -chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:32: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ -chunk.h:139:43: note: in expansion of macro 'memeq' - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ^~~~~ oid.c:261:43: note: (near initialization for 'oid_names[248].name') oid.c:262:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 262 | { 0x04, 0, 0, 5, "rsaSigWithripemd256" }, /* 249 */ @@ -1738,9 +1665,6 @@ 264 | { 0x01, 252, 0, 5, "ecSignWithsha1" }, /* 251 */ | ^~~~~~~~~~~~~~~~ oid.c:264:43: note: (near initialization for 'oid_names[251].name') -In file included from typedefs.h:3: -/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 413 | IN CONST CHAR8 *s1, oid.c:265:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 265 | { 0x02, 253, 0, 5, "ecSignWithripemd160" }, /* 252 */ | ^~~~~~~~~~~~~~~~~~~~~ @@ -1748,20 +1672,7 @@ oid.c:266:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 266 | { 0x03, 254, 0, 5, "ecSignWithmd2" }, /* 253 */ | ^~~~~~~~~~~~~~~ -chunk.h:139:57: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:34: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ -chunk.h:139:43: note: in expansion of macro 'memeq' - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ^~~~~ oid.c:266:43: note: (near initialization for 'oid_names[253].name') -/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 414 | IN CONST CHAR8 *s2, oid.c:267:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 267 | { 0x04, 255, 0, 5, "ecSignWithmd5" }, /* 254 */ | ^~~~~~~~~~~~~~~ @@ -1794,8 +1705,6 @@ 274 | { 0x01, 0, 0, 7, "ecgPublicKey" }, /* 261 */ | ^~~~~~~~~~~~~~ oid.c:274:43: note: (near initialization for 'oid_names[261].name') -In file included from chunk.c:18: -chunk.h: In function 'chunk_equals': oid.c:275:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 275 | { 0x03, 263, 0, 6, "curve" }, /* 262 */ | ^~~~~~~ @@ -1812,17 +1721,6 @@ 278 | { 0x02, 266, 0, 7, "ecgdsa-with-SHA1" }, /* 265 */ | ^~~~~~~~~~~~~~~~~~ oid.c:278:43: note: (near initialization for 'oid_names[265].name') -chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:32: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ -chunk.h:139:43: note: in expansion of macro 'memeq' - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ^~~~~ oid.c:279:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 279 | { 0x03, 267, 0, 7, "ecgdsa-with-SHA224" }, /* 266 */ | ^~~~~~~~~~~~~~~~~~~~ @@ -1839,30 +1737,14 @@ 282 | { 0x06, 0, 0, 7, "ecgdsa-with-SHA512" }, /* 269 */ | ^~~~~~~~~~~~~~~~~~~~ oid.c:282:43: note: (near initialization for 'oid_names[269].name') -In file included from typedefs.h:3: -/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 413 | IN CONST CHAR8 *s1, oid.c:283:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 283 | { 0x05, 0, 1, 6, "module" }, /* 270 */ | ^~~~~~~~ oid.c:283:43: note: (near initialization for 'oid_names[270].name') -chunk.h:139:57: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:34: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ -chunk.h:139:43: note: in expansion of macro 'memeq' - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ^~~~~ oid.c:284:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 284 | { 0x01, 0, 0, 7, "1" }, /* 271 */ | ^~~ oid.c:284:43: note: (near initialization for 'oid_names[271].name') -/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 414 | IN CONST CHAR8 *s2, oid.c:285:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 285 | { 0x08, 0, 1, 5, "ecStdCurvesAndGeneration" }, /* 272 */ | ^~~~~~~~~~~~~~~~~~~~~~~~~~ @@ -1871,252 +1753,122 @@ 286 | { 0x01, 0, 1, 6, "ellipticCurve" }, /* 273 */ | ^~~~~~~~~~~~~~~ oid.c:286:43: note: (near initialization for 'oid_names[273].name') -x509.c: At top level: oid.c:287:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 287 | { 0x01, 0, 1, 7, "versionOne" }, /* 274 */ | ^~~~~~~~~~~~ oid.c:287:43: note: (near initialization for 'oid_names[274].name') -x509.c:9:14: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 9 | { 0, "x509", ASN1_SEQUENCE, ASN1_OBJ }, /* 0 */ - | ^~~~~~ oid.c:288:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 288 | { 0x01, 276, 0, 8, "brainpoolP160r1" }, /* 275 */ | ^~~~~~~~~~~~~~~~~ oid.c:288:43: note: (near initialization for 'oid_names[275].name') -x509.c:9:14: note: (near initialization for 'x509_certObjects[0].name') oid.c:289:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 289 | { 0x02, 277, 0, 8, "brainpoolP160t1" }, /* 276 */ | ^~~~~~~~~~~~~~~~~ oid.c:289:43: note: (near initialization for 'oid_names[276].name') -x509.c:10:16: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 10 | { 1, "tbsCertificate", ASN1_SEQUENCE, ASN1_OBJ }, /* 1 */ - | ^~~~~~~~~~~~~~~~ -x509.c:10:16: note: (near initialization for 'x509_certObjects[1].name') oid.c:290:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 290 | { 0x03, 278, 0, 8, "brainpoolP192r1" }, /* 277 */ | ^~~~~~~~~~~~~~~~~ oid.c:290:43: note: (near initialization for 'oid_names[277].name') -x509.c:11:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 11 | { 2, "DEFAULT v1", ASN1_CONTEXT_C_0, ASN1_DEF }, /* 2 */ - | ^~~~~~~~~~~~ oid.c:291:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 291 | { 0x04, 279, 0, 8, "brainpoolP192t1" }, /* 278 */ | ^~~~~~~~~~~~~~~~~ oid.c:291:43: note: (near initialization for 'oid_names[278].name') -x509.c:11:18: note: (near initialization for 'x509_certObjects[2].name') oid.c:292:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 292 | { 0x05, 280, 0, 8, "brainpoolP224r1" }, /* 279 */ | ^~~~~~~~~~~~~~~~~ -x509.c:12:20: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 12 | { 3, "version", ASN1_INTEGER, ASN1_BODY }, /* 3 */ - | ^~~~~~~~~ oid.c:292:43: note: (near initialization for 'oid_names[279].name') -x509.c:12:20: note: (near initialization for 'x509_certObjects[3].name') -chunk.c: In function 'chunk_compare': oid.c:293:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 293 | { 0x06, 281, 0, 8, "brainpoolP224t1" }, /* 280 */ | ^~~~~~~~~~~~~~~~~ oid.c:293:43: note: (near initialization for 'oid_names[280].name') -x509.c:13:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 13 | { 2, "serialNumber", ASN1_INTEGER, ASN1_BODY }, /* 4 */ - | ^~~~~~~~~~~~~~ -x509.c:13:18: note: (near initialization for 'x509_certObjects[4].name') oid.c:294:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 294 | { 0x07, 282, 0, 8, "brainpoolP256r1" }, /* 281 */ | ^~~~~~~~~~~~~~~~~ -chunk.c:55:24: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] - 55 | return memcmp(a.ptr, b.ptr, len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:32: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ oid.c:294:43: note: (near initialization for 'oid_names[281].name') -x509.c:14:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 14 | { 2, "signature", ASN1_EOC, ASN1_RAW }, /* 5 */ - | ^~~~~~~~~~~ -x509.c:14:18: note: (near initialization for 'x509_certObjects[5].name') -/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 413 | IN CONST CHAR8 *s1, oid.c:295:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 295 | { 0x08, 283, 0, 8, "brainpoolP256t1" }, /* 282 */ | ^~~~~~~~~~~~~~~~~ oid.c:295:43: note: (near initialization for 'oid_names[282].name') -x509.c:15:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 15 | { 2, "issuer", ASN1_SEQUENCE, ASN1_OBJ }, /* 6 */ - | ^~~~~~~~ -x509.c:15:18: note: (near initialization for 'x509_certObjects[6].name') -chunk.c:55:31: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] - 55 | return memcmp(a.ptr, b.ptr, len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:34: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ -/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 414 | IN CONST CHAR8 *s2, oid.c:296:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 296 | { 0x09, 284, 0, 8, "brainpoolP320r1" }, /* 283 */ | ^~~~~~~~~~~~~~~~~ oid.c:296:43: note: (near initialization for 'oid_names[283].name') -x509.c:16:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 16 | { 2, "validity", ASN1_SEQUENCE, ASN1_NONE }, /* 7 */ - | ^~~~~~~~~~ -x509.c:16:18: note: (near initialization for 'x509_certObjects[7].name') oid.c:297:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 297 | { 0x0A, 285, 0, 8, "brainpoolP320t1" }, /* 284 */ | ^~~~~~~~~~~~~~~~~ oid.c:297:43: note: (near initialization for 'oid_names[284].name') -x509.c:17:20: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 17 | { 3, "notBefore", ASN1_EOC, ASN1_RAW }, /* 8 */ - | ^~~~~~~~~~~ -x509.c:17:20: note: (near initialization for 'x509_certObjects[8].name') oid.c:298:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 298 | { 0x0B, 286, 0, 8, "brainpoolP384r1" }, /* 285 */ | ^~~~~~~~~~~~~~~~~ oid.c:298:43: note: (near initialization for 'oid_names[285].name') -x509.c:18:20: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 18 | { 3, "notAfter", ASN1_EOC, ASN1_RAW }, /* 9 */ - | ^~~~~~~~~~ -x509.c:18:20: note: (near initialization for 'x509_certObjects[9].name') oid.c:299:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 299 | { 0x0C, 287, 0, 8, "brainpoolP384t1" }, /* 286 */ | ^~~~~~~~~~~~~~~~~ oid.c:299:43: note: (near initialization for 'oid_names[286].name') -x509.c:19:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 19 | { 2, "subject", ASN1_SEQUENCE, ASN1_OBJ }, /* 10 */ - | ^~~~~~~~~ -x509.c:19:18: note: (near initialization for 'x509_certObjects[10].name') oid.c:300:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 300 | { 0x0D, 288, 0, 8, "brainpoolP512r1" }, /* 287 */ | ^~~~~~~~~~~~~~~~~ oid.c:300:43: note: (near initialization for 'oid_names[287].name') -x509.c:20:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 20 | { 2, "subjectPublicKeyInfo",ASN1_SEQUENCE, ASN1_RAW }, /* 11 */ - | ^~~~~~~~~~~~~~~~~~~~~~ -x509.c:20:18: note: (near initialization for 'x509_certObjects[11].name') oid.c:301:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 301 | { 0x0E, 0, 0, 8, "brainpoolP512t1" }, /* 288 */ | ^~~~~~~~~~~~~~~~~ oid.c:301:43: note: (near initialization for 'oid_names[288].name') -x509.c:21:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 21 | { 2, "issuerUniqueID", ASN1_CONTEXT_C_1, ASN1_OPT }, /* 12 */ - | ^~~~~~~~~~~~~~~~ -x509.c:21:18: note: (near initialization for 'x509_certObjects[12].name') oid.c:302:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 302 | { 0x81, 0, 1, 1, "" }, /* 289 */ | ^~ oid.c:302:43: note: (near initialization for 'oid_names[289].name') -x509.c:22:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 22 | { 2, "end opt", ASN1_EOC, ASN1_END }, /* 13 */ - | ^~~~~~~~~ -x509.c:22:18: note: (near initialization for 'x509_certObjects[13].name') oid.c:303:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 303 | { 0x04, 0, 1, 2, "Certicom" }, /* 290 */ | ^~~~~~~~~~ oid.c:303:43: note: (near initialization for 'oid_names[290].name') -x509.c:23:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 23 | { 2, "subjectUniqueID", ASN1_CONTEXT_C_2, ASN1_OPT }, /* 14 */ - | ^~~~~~~~~~~~~~~~~ -x509.c:23:18: note: (near initialization for 'x509_certObjects[14].name') oid.c:304:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 304 | { 0x00, 0, 1, 3, "curve" }, /* 291 */ | ^~~~~~~ oid.c:304:43: note: (near initialization for 'oid_names[291].name') -x509.c:24:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 24 | { 2, "end opt", ASN1_EOC, ASN1_END }, /* 15 */ - | ^~~~~~~~~ -x509.c:24:18: note: (near initialization for 'x509_certObjects[15].name') oid.c:305:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 305 | { 0x01, 293, 0, 4, "sect163k1" }, /* 292 */ | ^~~~~~~~~~~ oid.c:305:43: note: (near initialization for 'oid_names[292].name') -x509.c:25:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 25 | { 2, "optional extensions", ASN1_CONTEXT_C_3, ASN1_OPT }, /* 16 */ - | ^~~~~~~~~~~~~~~~~~~~~ -x509.c:25:18: note: (near initialization for 'x509_certObjects[16].name') oid.c:306:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 306 | { 0x02, 294, 0, 4, "sect163r1" }, /* 293 */ | ^~~~~~~~~~~ oid.c:306:43: note: (near initialization for 'oid_names[293].name') -x509.c:26:20: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 26 | { 3, "extensions", ASN1_SEQUENCE, ASN1_LOOP }, /* 17 */ - | ^~~~~~~~~~~~ -x509.c:26:20: note: (near initialization for 'x509_certObjects[17].name') oid.c:307:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 307 | { 0x03, 295, 0, 4, "sect239k1" }, /* 294 */ | ^~~~~~~~~~~ oid.c:307:43: note: (near initialization for 'oid_names[294].name') -x509.c:27:22: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 27 | { 4, "extension", ASN1_SEQUENCE, ASN1_NONE }, /* 18 */ - | ^~~~~~~~~~~ -x509.c:27:22: note: (near initialization for 'x509_certObjects[18].name') oid.c:308:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 308 | { 0x04, 296, 0, 4, "sect113r1" }, /* 295 */ | ^~~~~~~~~~~ oid.c:308:43: note: (near initialization for 'oid_names[295].name') -x509.c:28:24: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 28 | { 5, "extnID", ASN1_OID, ASN1_BODY }, /* 19 */ - | ^~~~~~~~ -x509.c:28:24: note: (near initialization for 'x509_certObjects[19].name') oid.c:309:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 309 | { 0x05, 297, 0, 4, "sect113r2" }, /* 296 */ | ^~~~~~~~~~~ oid.c:309:43: note: (near initialization for 'oid_names[296].name') -x509.c:29:24: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 29 | { 5, "critical", ASN1_BOOLEAN, ASN1_DEF|ASN1_BODY }, /* 20 */ - | ^~~~~~~~~~ -x509.c:29:24: note: (near initialization for 'x509_certObjects[20].name') oid.c:310:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 310 | { 0x06, 298, 0, 4, "secp112r1" }, /* 297 */ | ^~~~~~~~~~~ oid.c:310:43: note: (near initialization for 'oid_names[297].name') -x509.c:30:24: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 30 | { 5, "extnValue", ASN1_OCTET_STRING, ASN1_BODY }, /* 21 */ - | ^~~~~~~~~~~ -x509.c:30:24: note: (near initialization for 'x509_certObjects[21].name') oid.c:311:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 311 | { 0x07, 299, 0, 4, "secp112r2" }, /* 298 */ | ^~~~~~~~~~~ oid.c:311:43: note: (near initialization for 'oid_names[298].name') -x509.c:31:20: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 31 | { 3, "end loop", ASN1_EOC, ASN1_END }, /* 22 */ - | ^~~~~~~~~~ -x509.c:31:20: note: (near initialization for 'x509_certObjects[22].name') oid.c:312:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 312 | { 0x08, 300, 0, 4, "secp160r1" }, /* 299 */ | ^~~~~~~~~~~ oid.c:312:43: note: (near initialization for 'oid_names[299].name') -x509.c:32:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 32 | { 2, "end opt", ASN1_EOC, ASN1_END }, /* 23 */ - | ^~~~~~~~~ -x509.c:32:18: note: (near initialization for 'x509_certObjects[23].name') oid.c:313:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 313 | { 0x09, 301, 0, 4, "secp160k1" }, /* 300 */ | ^~~~~~~~~~~ oid.c:313:43: note: (near initialization for 'oid_names[300].name') -x509.c:33:16: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 33 | { 1, "signatureAlgorithm", ASN1_EOC, ASN1_RAW }, /* 24 */ - | ^~~~~~~~~~~~~~~~~~~~ -x509.c:33:16: note: (near initialization for 'x509_certObjects[24].name') oid.c:314:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 314 | { 0x0A, 302, 0, 4, "secp256k1" }, /* 301 */ | ^~~~~~~~~~~ oid.c:314:43: note: (near initialization for 'oid_names[301].name') -x509.c:34:16: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 34 | { 1, "signatureValue", ASN1_BIT_STRING, ASN1_BODY }, /* 25 */ - | ^~~~~~~~~~~~~~~~ -x509.c:34:16: note: (near initialization for 'x509_certObjects[25].name') oid.c:315:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 315 | { 0x0F, 303, 0, 4, "sect163r2" }, /* 302 */ | ^~~~~~~~~~~ oid.c:315:43: note: (near initialization for 'oid_names[302].name') -x509.c:35:14: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] - 35 | { 0, "exit", ASN1_EOC, ASN1_EXIT } - | ^~~~~~ -x509.c:35:14: note: (near initialization for 'x509_certObjects[26].name') oid.c:316:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 316 | { 0x10, 304, 0, 4, "sect283k1" }, /* 303 */ | ^~~~~~~~~~~ @@ -2237,17 +1989,10 @@ 345 | { 0x06, 333, 0, 8, "id-aes128-GCM" }, /* 332 */ | ^~~~~~~~~~~~~~~ oid.c:345:43: note: (near initialization for 'oid_names[332].name') -HashTool.c: In function 'efi_main': oid.c:346:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 346 | { 0x07, 334, 0, 8, "id-aes128-CCM" }, /* 333 */ | ^~~~~~~~~~~~~~~ -HashTool.c:187:25: warning: variable 'setup_mode_arg' set but not used [-Wunused-but-set-variable] - 187 | setup_mode_arg = 0, keytool = NOSEL; - | ^~~~~~~~~~~~~~ oid.c:346:43: note: (near initialization for 'oid_names[333].name') -HashTool.c:185:28: warning: variable 'setup_mode' set but not used [-Wunused-but-set-variable] - 185 | int c = 0, setup_mode = NOSEL, uefi_reboot = NOSEL, - | ^~~~~~~~~~ oid.c:347:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 347 | { 0x16, 335, 0, 8, "id-aes192-CBC" }, /* 334 */ | ^~~~~~~~~~~~~~~ @@ -2392,38 +2137,200 @@ 382 | {0x67, 0, 1, 0, "" }, /* 369 */ | ^~ oid.c:382:43: note: (near initialization for 'oid_names[369].name') -oid.c:383:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] +.oid.c:383:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 383 | { 0x81, 0, 1, 1, "" }, /* 370 */ | ^~ -oid.c:383:43: note: (near initialization for 'oid_names[370].name') -oid.c:384:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] +...oid.c:383:43: note: (near initialization for 'oid_names[370].name') ++oid.c:384:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 384 | { 0x05, 0, 1, 2, "" }, /* 371 */ | ^~ -oid.c:384:43: note: (near initialization for 'oid_names[371].name') -oid.c:385:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] ++oid.c:384:43: note: (near initialization for 'oid_names[371].name') +++oid.c:385:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 385 | { 0x02, 0, 1, 3, "tcg-attribute" }, /* 372 */ | ^~~~~~~~~~~~~~~ -oid.c:385:43: note: (near initialization for 'oid_names[372].name') -oid.c:386:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] ++oid.c:385:43: note: (near initialization for 'oid_names[372].name') +++oid.c:386:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 386 | { 0x01, 374, 0, 4, "tcg-at-tpmManufacturer" }, /* 373 */ | ^~~~~~~~~~~~~~~~~~~~~~~~ -oid.c:386:43: note: (near initialization for 'oid_names[373].name') -oid.c:387:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] ++oid.c:386:43: note: (near initialization for 'oid_names[373].name') +++oid.c:387:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 387 | { 0x02, 375, 0, 4, "tcg-at-tpmModel" }, /* 374 */ | ^~~~~~~~~~~~~~~~~ -oid.c:387:43: note: (near initialization for 'oid_names[374].name') -oid.c:388:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] ++oid.c:387:43: note: (near initialization for 'oid_names[374].name') +++oid.c:388:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 388 | { 0x03, 376, 0, 4, "tcg-at-tpmVersion" }, /* 375 */ | ^~~~~~~~~~~~~~~~~~~ oid.c:388:43: note: (near initialization for 'oid_names[375].name') -oid.c:389:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] +++oid.c:389:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 389 | { 0x0F, 0, 0, 4, "tcg-at-tpmIdLabel" } /* 376 */ | ^~~~~~~~~~~~~~~~~~~ oid.c:389:43: note: (near initialization for 'oid_names[376].name') -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-readvar.c -o efi-readvar.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-updatevar.c -o efi-updatevar.o -hash-to-efi-sig-list.c: In function 'main': -hash-to-efi-sig-list.c:96:60: warning: format '%d' expects argument of type 'int', but argument 3 has type 'EFI_STATUS' {aka 'long unsigned int'} [-Wformat=] +++++++++++++++++++++++++*......+++++++++++++++++++++++++++++++++++++++*...+.........+......+...+.......+In file included from identification.c:18: +chunk.h: In function 'chunk_equals': +chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:32: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +chunk.h:139:43: note: in expansion of macro 'memeq' + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ^~~~~ +ShimReplace.c: In function 'efi_main': +.ShimReplace.c:51:37: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers] + 51 | efi_status = execute(image, loader); + | ^~~~~~ +..+In file included from ShimReplace.c:17: +/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'} + 5 | execute(EFI_HANDLE image, CHAR16 *name); + | ~~~~~~~~^~~~ +In file included from typedefs.h:3: +/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 413 | IN CONST CHAR8 *s1, +ShimReplace.c:57:37: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers] + 57 | efi_status = execute(image, fallback); + | ^~~~~~~~ +/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'} + 5 | execute(EFI_HANDLE image, CHAR16 *name); + | ~~~~~~~~^~~~ +chunk.h:139:57: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:34: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +chunk.h:139:43: note: in expansion of macro 'memeq' + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ^~~~~ +/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 414 | IN CONST CHAR8 *s2, +..+...+..................+..........+...+..+....+identification.c: At top level: +identification.c:34:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 34 | {"ND", OID_NAME_DISTINGUISHER, ASN1_PRINTABLESTRING}, + | ^~~~ +identification.c:34:10: note: (near initialization for 'x501rdns[0].name') +identification.c:35:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 35 | {"UID", OID_PILOT_USERID, ASN1_PRINTABLESTRING}, + | ^~~~~ +identification.c:35:10: note: (near initialization for 'x501rdns[1].name') +identification.c:36:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 36 | {"DC", OID_PILOT_DOMAIN_COMPONENT, ASN1_PRINTABLESTRING}, + | ^~~~ +identification.c:36:10: note: (near initialization for 'x501rdns[2].name') +...identification.c:37:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 37 | {"CN", OID_COMMON_NAME, ASN1_PRINTABLESTRING}, + | ^~~~ +..identification.c:37:10: note: (near initialization for 'x501rdns[3].name') +.....identification.c:38:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 38 | {"S", OID_SURNAME, ASN1_PRINTABLESTRING}, + | ^~~ +.identification.c:38:10: note: (near initialization for 'x501rdns[4].name') +...identification.c:39:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 39 | {"SN", OID_SERIAL_NUMBER, ASN1_PRINTABLESTRING}, + | ^~~~ +identification.c:39:10: note: (near initialization for 'x501rdns[5].name') ++identification.c:40:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 40 | {"serialNumber", OID_SERIAL_NUMBER, ASN1_PRINTABLESTRING}, + | ^~~~~~~~~~~~~~ +identification.c:40:10: note: (near initialization for 'x501rdns[6].name') +identification.c:41:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 41 | {"C", OID_COUNTRY, ASN1_PRINTABLESTRING}, + | ^~~ +identification.c:41:10: note: (near initialization for 'x501rdns[7].name') +identification.c:42:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 42 | {"L", OID_LOCALITY, ASN1_PRINTABLESTRING}, + | ^~~ +identification.c:42:10: note: (near initialization for 'x501rdns[8].name') +identification.c:43:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 43 | {"ST", OID_STATE_OR_PROVINCE, ASN1_PRINTABLESTRING}, + | ^~~~ +identification.c:43:10: note: (near initialization for 'x501rdns[9].name') +identification.c:44:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 44 | {"O", OID_ORGANIZATION, ASN1_PRINTABLESTRING}, + | ^~~ +identification.c:44:10: note: (near initialization for 'x501rdns[10].name') +identification.c:45:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 45 | {"OU", OID_ORGANIZATION_UNIT, ASN1_PRINTABLESTRING}, + | ^~~~ +identification.c:45:10: note: (near initialization for 'x501rdns[11].name') +...identification.c:46:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 46 | {"T", OID_TITLE, ASN1_PRINTABLESTRING}, + | ^~~ +..identification.c:46:10: note: (near initialization for 'x501rdns[12].name') +..identification.c:47:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 47 | {"D", OID_DESCRIPTION, ASN1_PRINTABLESTRING}, + | ^~~ +identification.c:47:10: note: (near initialization for 'x501rdns[13].name') ++identification.c:48:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 48 | {"N", OID_NAME, ASN1_PRINTABLESTRING}, + | ^~~ +identification.c:48:10: note: (near initialization for 'x501rdns[14].name') +identification.c:49:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 49 | {"G", OID_GIVEN_NAME, ASN1_PRINTABLESTRING}, + | ^~~ +identification.c:49:10: note: (near initialization for 'x501rdns[15].name') +identification.c:50:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 50 | {"I", OID_INITIALS, ASN1_PRINTABLESTRING}, + | ^~~ +identification.c:50:10: note: (near initialization for 'x501rdns[16].name') +identification.c:51:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 51 | {"dnQualifier", OID_DN_QUALIFIER, ASN1_PRINTABLESTRING}, + | ^~~~~~~~~~~~~ +identification.c:51:10: note: (near initialization for 'x501rdns[17].name') +identification.c:52:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 52 | {"ID", OID_UNIQUE_IDENTIFIER, ASN1_PRINTABLESTRING}, + | ^~~~ +identification.c:52:10: note: (near initialization for 'x501rdns[18].name') +identification.c:53:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 53 | {"EN", OID_EMPLOYEE_NUMBER, ASN1_PRINTABLESTRING}, + | ^~~~ +identification.c:53:10: note: (near initialization for 'x501rdns[19].name') +identification.c:54:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 54 | {"employeeNumber", OID_EMPLOYEE_NUMBER, ASN1_PRINTABLESTRING}, + | ^~~~~~~~~~~~~~~~ +..identification.c:54:10: note: (near initialization for 'x501rdns[20].name') +identification.c:55:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 55 | {"E", OID_EMAIL_ADDRESS, ASN1_IA5STRING}, + | ^~~ +identification.c:55:10: note: (near initialization for 'x501rdns[21].name') ++identification.c:56:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 56 | {"Email", OID_EMAIL_ADDRESS, ASN1_IA5STRING}, + | ^~~~~~~ +identification.c:56:10: note: (near initialization for 'x501rdns[22].name') +identification.c:57:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 57 | {"emailAddress", OID_EMAIL_ADDRESS, ASN1_IA5STRING}, + | ^~~~~~~~~~~~~~ +identification.c:57:10: note: (near initialization for 'x501rdns[23].name') +identification.c:58:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 58 | {"UN", OID_UNSTRUCTURED_NAME, ASN1_IA5STRING}, + | ^~~~ +identification.c:58:10: note: (near initialization for 'x501rdns[24].name') +identification.c:59:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 59 | {"unstructuredName", OID_UNSTRUCTURED_NAME, ASN1_IA5STRING}, + | ^~~~~~~~~~~~~~~~~~ +identification.c:59:10: note: (near initialization for 'x501rdns[25].name') +identification.c:60:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 60 | {"UA", OID_UNSTRUCTURED_ADDRESS, ASN1_PRINTABLESTRING}, + | ^~~~ +identification.c:60:10: note: (near initialization for 'x501rdns[26].name') +identification.c:61:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 61 | {"unstructuredAddress", OID_UNSTRUCTURED_ADDRESS, ASN1_PRINTABLESTRING}, + | ^~~~~~~~~~~~~~~~~~~~~ +identification.c:61:10: note: (near initialization for 'x501rdns[27].name') +.identification.c:62:10: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 62 | {"TCGID", OID_TCGID, ASN1_PRINTABLESTRING} + | ^~~~~~~ +identification.c:62:10: note: (near initialization for 'x501rdns[28].name') ++.....+..........+......+.....+....+identification.c:33:24: warning: 'x501rdns' defined but not used [-Wunused-const-variable=] + 33 | static const x501rdn_t x501rdns[] = { + | ^~~~~~~~ +......++++++ +...+........+.......+........+...+++++++++++++++++++++++++++++++++++++++*.....+.+......+.....+...+..........+++++++++++++++hash-to-efi-sig-list.c: In function 'main': +++++hash-to-efi-sig-list.c:96:60: warning: format '%d' expects argument of type 'int', but argument 3 has type 'EFI_STATUS' {aka 'long unsigned int'} [-Wformat=] 96 | printf("Failed to get hash of %s: %d\n", argv[i+1], | ~^ | | @@ -2433,7 +2340,187 @@ | ~~~~~~ | | | EFI_STATUS {aka long unsigned int} -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-hash-list.c -o cert-to-efi-hash-list.o +++++++++++++++++++++*......+.....+...+.......+.....+.+..+...+.......+........+..........+..+.+..+....+...+..+.........+.......+........+.+In file included from x509.c:1: +chunk.h: In function 'chunk_equals': +chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:32: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +chunk.h:139:43: note: in expansion of macro 'memeq' + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ^~~~~ +........+In file included from typedefs.h:3: +/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 413 | IN CONST CHAR8 *s1, +chunk.h:139:57: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:34: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +chunk.h:139:43: note: in expansion of macro 'memeq' + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ^~~~~ +/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 414 | IN CONST CHAR8 *s2, +.............+........+x509.c: At top level: +x509.c:9:14: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 9 | { 0, "x509", ASN1_SEQUENCE, ASN1_OBJ }, /* 0 */ + | ^~~~~~ +x509.c:9:14: note: (near initialization for 'x509_certObjects[0].name') +.x509.c:10:16: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 10 | { 1, "tbsCertificate", ASN1_SEQUENCE, ASN1_OBJ }, /* 1 */ + | ^~~~~~~~~~~~~~~~ +..x509.c:10:16: note: (near initialization for 'x509_certObjects[1].name') +....x509.c:11:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 11 | { 2, "DEFAULT v1", ASN1_CONTEXT_C_0, ASN1_DEF }, /* 2 */ + | ^~~~~~~~~~~~ +x509.c:11:18: note: (near initialization for 'x509_certObjects[2].name') +x509.c:12:20: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 12 | { 3, "version", ASN1_INTEGER, ASN1_BODY }, /* 3 */ + | ^~~~~~~~~ ++x509.c:12:20: note: (near initialization for 'x509_certObjects[3].name') +x509.c:13:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 13 | { 2, "serialNumber", ASN1_INTEGER, ASN1_BODY }, /* 4 */ + | ^~~~~~~~~~~~~~ +x509.c:13:18: note: (near initialization for 'x509_certObjects[4].name') +x509.c:14:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 14 | { 2, "signature", ASN1_EOC, ASN1_RAW }, /* 5 */ + | ^~~~~~~~~~~ +x509.c:14:18: note: (near initialization for 'x509_certObjects[5].name') +x509.c:15:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 15 | { 2, "issuer", ASN1_SEQUENCE, ASN1_OBJ }, /* 6 */ + | ^~~~~~~~ +x509.c:15:18: note: (near initialization for 'x509_certObjects[6].name') +x509.c:16:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 16 | { 2, "validity", ASN1_SEQUENCE, ASN1_NONE }, /* 7 */ + | ^~~~~~~~~~ +x509.c:16:18: note: (near initialization for 'x509_certObjects[7].name') +x509.c:17:20: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 17 | { 3, "notBefore", ASN1_EOC, ASN1_RAW }, /* 8 */ + | ^~~~~~~~~~~ +x509.c:17:20: note: (near initialization for 'x509_certObjects[8].name') +x509.c:18:20: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 18 | { 3, "notAfter", ASN1_EOC, ASN1_RAW }, /* 9 */ + | ^~~~~~~~~~ +x509.c:18:20: note: (near initialization for 'x509_certObjects[9].name') +x509.c:19:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 19 | { 2, "subject", ASN1_SEQUENCE, ASN1_OBJ }, /* 10 */ + | ^~~~~~~~~ +x509.c:19:18: note: (near initialization for 'x509_certObjects[10].name') +x509.c:20:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 20 | { 2, "subjectPublicKeyInfo",ASN1_SEQUENCE, ASN1_RAW }, /* 11 */ + | ^~~~~~~~~~~~~~~~~~~~~~ +x509.c:20:18: note: (near initialization for 'x509_certObjects[11].name') +x509.c:21:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 21 | { 2, "issuerUniqueID", ASN1_CONTEXT_C_1, ASN1_OPT }, /* 12 */ + | ^~~~~~~~~~~~~~~~ +x509.c:21:18: note: (near initialization for 'x509_certObjects[12].name') +x509.c:22:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 22 | { 2, "end opt", ASN1_EOC, ASN1_END }, /* 13 */ + | ^~~~~~~~~ +x509.c:22:18: note: (near initialization for 'x509_certObjects[13].name') +x509.c:23:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 23 | { 2, "subjectUniqueID", ASN1_CONTEXT_C_2, ASN1_OPT }, /* 14 */ + | ^~~~~~~~~~~~~~~~~ +x509.c:23:18: note: (near initialization for 'x509_certObjects[14].name') +x509.c:24:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 24 | { 2, "end opt", ASN1_EOC, ASN1_END }, /* 15 */ + | ^~~~~~~~~ +x509.c:24:18: note: (near initialization for 'x509_certObjects[15].name') +.x509.c:25:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 25 | { 2, "optional extensions", ASN1_CONTEXT_C_3, ASN1_OPT }, /* 16 */ + | ^~~~~~~~~~~~~~~~~~~~~ +.x509.c:25:18: note: (near initialization for 'x509_certObjects[16].name') +...x509.c:26:20: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 26 | { 3, "extensions", ASN1_SEQUENCE, ASN1_LOOP }, /* 17 */ + | ^~~~~~~~~~~~ +x509.c:26:20: note: (near initialization for 'x509_certObjects[17].name') +x509.c:27:22: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 27 | { 4, "extension", ASN1_SEQUENCE, ASN1_NONE }, /* 18 */ + | ^~~~~~~~~~~ ++x509.c:27:22: note: (near initialization for 'x509_certObjects[18].name') +x509.c:28:24: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 28 | { 5, "extnID", ASN1_OID, ASN1_BODY }, /* 19 */ + | ^~~~~~~~ +x509.c:28:24: note: (near initialization for 'x509_certObjects[19].name') +x509.c:29:24: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 29 | { 5, "critical", ASN1_BOOLEAN, ASN1_DEF|ASN1_BODY }, /* 20 */ + | ^~~~~~~~~~ +x509.c:29:24: note: (near initialization for 'x509_certObjects[20].name') +x509.c:30:24: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 30 | { 5, "extnValue", ASN1_OCTET_STRING, ASN1_BODY }, /* 21 */ + | ^~~~~~~~~~~ +x509.c:30:24: note: (near initialization for 'x509_certObjects[21].name') +x509.c:31:20: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 31 | { 3, "end loop", ASN1_EOC, ASN1_END }, /* 22 */ + | ^~~~~~~~~~ +x509.c:31:20: note: (near initialization for 'x509_certObjects[22].name') +x509.c:32:18: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 32 | { 2, "end opt", ASN1_EOC, ASN1_END }, /* 23 */ + | ^~~~~~~~~ +x509.c:32:18: note: (near initialization for 'x509_certObjects[23].name') +x509.c:33:16: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 33 | { 1, "signatureAlgorithm", ASN1_EOC, ASN1_RAW }, /* 24 */ + | ^~~~~~~~~~~~~~~~~~~~ +x509.c:33:16: note: (near initialization for 'x509_certObjects[24].name') +x509.c:34:16: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 34 | { 1, "signatureValue", ASN1_BIT_STRING, ASN1_BODY }, /* 25 */ + | ^~~~~~~~~~~~~~~~ +x509.c:34:16: note: (near initialization for 'x509_certObjects[25].name') +x509.c:35:14: warning: pointer targets in initialization of 'const u_char *' {aka 'const unsigned char *'} from 'char *' differ in signedness [-Wpointer-sign] + 35 | { 0, "exit", ASN1_EOC, ASN1_EXIT } + | ^~~~~~ +x509.c:35:14: note: (near initialization for 'x509_certObjects[26].name') +.......+...+............+..+.+..+.......+.........+............+...+.........+......+...........++++++ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c shim_protocol.c -o shim_protocol.o +----- +flash-var.c: In function 'main': +flash-var.c:185:9: warning: 'memset' offset [0, 56] is out of the bounds [0, 0] [-Warray-bounds=] + 185 | memset(vh, 0, sizeof(*vh)); + | ^~~~~~~~~~~~~~~~~~~~~~~~~~ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pkcs7verify.c -o pkcs7verify.o +ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds SetNull.o -o SetNull.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a +ar rcv libasn1-efi.a asn1.efi.o asn1_parser.efi.o enumerator.efi.o chunk.efi.o oid.efi.o identification.efi.o x509.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c kernel_efivars.c -o kernel_efivars.o +a - asn1.efi.o +a - asn1_parser.efi.o +a - enumerator.efi.o +a - chunk.efi.o +a - oid.efi.o +a - identification.efi.o +a - x509.efi.o +# check we have no undefined symbols +nm -D SetNull.so | grep ' U ' && exit 1 || exit 0 +make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c openssl_sign.c -o openssl_sign.o +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 SetNull.so SetNull.efi +ar rcv lib-efi.a simple_file.efi.o pecoff.efi.o guid.efi.o sha256.efi.o console.efi.o execute.efi.o configtable.efi.o shell.efi.o security_policy.efi.o shim_protocol.efi.o pkcs7verify.efi.o variables.o +sbsign --key DB.key --cert DB.crt --output SetNull-signed.efi SetNull.efi +a - simple_file.efi.o +a - pecoff.efi.o +a - guid.efi.o +a - sha256.efi.o +a - console.efi.o +a - execute.efi.o +a - configtable.efi.o +a - shell.efi.o +a - security_policy.efi.o +a - shim_protocol.efi.o +a - pkcs7verify.efi.o +a - variables.o +warning: data remaining[35840 vs 48121]: gaps between PE/COFF sections? +warning: data remaining[35840 vs 48128]: gaps between PE/COFF sections? +make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' +Signing Unsigned original image openssl_sign.c: In function 'read_engine_private_key': openssl_sign.c:118:9: warning: 'ENGINE_load_builtin_engines' is deprecated: Since OpenSSL 3.0 [-Wdeprecated-declarations] 118 | ENGINE_load_builtin_engines(); @@ -2472,49 +2559,11 @@ /usr/include/openssl/engine.h:493:27: note: declared here 493 | OSSL_DEPRECATEDIN_3_0 int ENGINE_free(ENGINE *e); | ^~~~~~~~~~~ -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c flash-var.c -o flash-var.o -> noPK.esl -ar rcv libasn1-efi.a asn1.efi.o asn1_parser.efi.o enumerator.efi.o chunk.efi.o oid.efi.o identification.efi.o x509.efi.o -cert-to-efi-hash-list.c:9:9: warning: '_XOPEN_SOURCE' redefined - 9 | #define _XOPEN_SOURCE - | ^~~~~~~~~~~~~ -: note: this is the location of the previous definition -a - asn1.efi.o -a - asn1_parser.efi.o -a - enumerator.efi.o -a - chunk.efi.o -a - oid.efi.o -a - identification.efi.o -a - x509.efi.o -flash-var.c: In function 'main': -flash-var.c:185:9: warning: 'memset' offset [0, 56] is out of the bounds [0, 0] [-Warray-bounds=] - 185 | memset(vh, 0, sizeof(*vh)); - | ^~~~~~~~~~~~~~~~~~~~~~~~~~ -openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB1/" -keyout DB1.key -out DB1.crt -days 3650 -nodes -sha256 -make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' -.+.+...+...........+....+......+...+..+....+.....+....+...........+++++++++++++++++++++++++++++++++++++++*........+............+...........+...+.+...+++++++++++++++++++++++++++++++++++++++*.+.....+....+...........+....+..+.......+...+..+......+......+.........+....+..+.+.........+..................+........+...+.+...+..+................+...+..+...+.........+.......+...+......+..+............+.+..+.............+..+.......+...+..............+.........+.+...........+....+.....+.+............+..+.+........+...................+........+...+....+........+....+........+.......+........+.+.....+............+.......+........+...+.......+..+............+....+..+...................+.........+...............+..+.......+...+..+......+.+...+..+.+...............+.....+............+.+.....+.+.........+.....+.........+.........................openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB2/" -keyout DB2.key -out DB2.crt -days 3650 -nodes -sha256 -+ar rcv lib-efi.a simple_file.efi.o pecoff.efi.o guid.efi.o sha256.efi.o console.efi.o execute.efi.o configtable.efi.o shell.efi.o security_policy.efi.o shim_protocol.efi.o pkcs7verify.efi.o variables.o -..+......+...+.+.....+.+.....+.......+...+...+.........+..+......+....+......+...+.....+....+..+...+..................+...+.+...+..+...+......+.+.....+.............+..++++++ -...+...+...+......+++++++++++++++++++++++++++++++++++++++*.+...+.......+...+...+++++++++++++++++++++++++++++++++++++++*..+a - simple_file.efi.o -a - pecoff.efi.o -a - guid.efi.o -a - sha256.efi.o -a - console.efi.o -a - execute.efi.o -a - configtable.efi.o -a - shell.efi.o -a - security_policy.efi.o -a - shim_protocol.efi.o -a - pkcs7verify.efi.o -a - variables.o -.+.....+.+...+.......+..+.+..+..................+.+.......+....+....++..++++++++++++++++.+++..+.++.+..+..+++++++++++++*....+............+.......+.....+.+.....+...+.+...+...+............+...+...+.....+....+..+.+....+.................+...+...+....++...+..+.+......+...+++++++++++++++++++++++++++++++++++++.+.+*..+...........+...+..+.+........................+.............+....+....+.+........+....++.....++.......+........+.....+.+......+......+......+..+...+..............................++.+...+............+....+...+....................++......+...+.+..............++..+....+.........+..+.+.+.....+.....................++.........++....+........+...+.......+........+......+...............+...+...++.+........+.....................++.....+...+..........++.........++............++...+........+.........+....+............+..+...........++................++.+......+.............+..+..+.........................++.+......+.....+..+...+...........++...........++.................+.............+........++..........++.............++...+...............+.....+...+.........+..+.+........................+..........+.+..++.....+.+..++....+.+ -..........+.+......+..+.+.....+......+.........+....+......+.....+.........+.......+.........+.....+.+........+............+.........+.+......+........+.+.....+.+.........+...+......+..+.........+...+............+...+.+.....+............+....+.....................+.........+...+..+..........+...+...+..............+.+.................+...+....+......+..+...+.........++++++ -...+...........+++++++++++++++++++++++++++++++++++++++*..+...+...+..+...+....+...+........+..........+..............+.........+....+...+.........+...+..+...+.+.....+.........+.......+.....+......+....+++++++++++++++++++++++++++++++++++++++*.........+...+.......+......+..+.......+.....+.+..+.....................+.+......+..+..........+...+..............+.+.................+.+.....+..........+..............+.......+......+.........+...........+...+..........+.....+....+...+.........+...+........+...+.+...+........+...+.+...+......+..............+............+...+.......+......+...+.....+.......+.........+.....+....+.....+.........+...+....+.....+.........+.......+............++++++ -ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds SetNull.o -o SetNull.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a ------ ------ +ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds HelloWorld.o lib/lib-efi.a -o HelloWorld.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a ar rcv lib.a simple_file.o pecoff.o guid.o sha256.o console.o execute.o configtable.o shell.o security_policy.o shim_protocol.o pkcs7verify.o kernel_efivars.o openssl_sign.o -make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' +# check we have no undefined symbols +nm -D HelloWorld.so | grep ' U ' && exit 1 || exit 0 +ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds Loader.o lib/lib-efi.a -o Loader.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a a - simple_file.o a - pecoff.o a - guid.o @@ -2529,89 +2578,84 @@ a - kernel_efivars.o a - openssl_sign.o # check we have no undefined symbols +nm -D Loader.so | grep ' U ' && exit 1 || exit 0 make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' -nm -D SetNull.so | grep ' U ' && exit 1 || exit 0 +ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds ReadVars.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o ReadVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a +ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds UpdateVars.o lib/lib-efi.a -o UpdateVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a +ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds KeyTool.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o KeyTool.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a +# check we have no undefined symbols +nm -D ReadVars.so | grep ' U ' && exit 1 || exit 0 +ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds HashTool.o lib/lib-efi.a -o HashTool.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a +# check we have no undefined symbols +nm -D HashTool.so | grep ' U ' && exit 1 || exit 0 ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds ShimReplace.o lib/lib-efi.a -o ShimReplace.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a cc -o sig-list-to-certs sig-list-to-certs.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto # check we have no undefined symbols nm -D ShimReplace.so | grep ' U ' && exit 1 || exit 0 +# check we have no undefined symbols +# check we have no undefined symbols +nm -D UpdateVars.so | grep ' U ' && exit 1 || exit 0 +nm -D KeyTool.so | grep ' U ' && exit 1 || exit 0 cc -o hash-to-efi-sig-list hash-to-efi-sig-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a cc -o efi-readvar efi-readvar.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto cc -o efi-updatevar efi-updatevar.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto cc -o cert-to-efi-hash-list cert-to-efi-hash-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto cc -o flash-var flash-var.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -help2man --no-info -i doc/efi-readvar.1.in -o doc/efi-readvar.1 ./efi-readvar help2man --no-info -i doc/hash-to-efi-sig-list.1.in -o doc/hash-to-efi-sig-list.1 ./hash-to-efi-sig-list help2man --no-info -i doc/sig-list-to-certs.1.in -o doc/sig-list-to-certs.1 ./sig-list-to-certs -./cert-to-efi-hash-list PK.crt PK-hash-blacklist.esl -./cert-to-efi-hash-list KEK.crt KEK-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 -./cert-to-efi-hash-list DB.crt DB-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 -./cert-to-efi-hash-list DB1.crt DB1-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 -./cert-to-efi-hash-list DB2.crt DB2-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 -./cert-to-efi-hash-list ms-uefi.crt ms-uefi-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 -./cert-to-efi-hash-list ms-kek.crt ms-kek-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 -TimeOfRevocation is 0-0-0 00:00:00 -ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds HelloWorld.o lib/lib-efi.a -o HelloWorld.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 HelloWorld.so HelloWorld.efi cc -o cert-to-efi-sig-list cert-to-efi-sig-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto -# check we have no undefined symbols -nm -D HelloWorld.so | grep ' U ' && exit 1 || exit 0 cc -o sign-efi-sig-list sign-efi-sig-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto -ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds Loader.o lib/lib-efi.a -o Loader.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a -ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds ReadVars.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o ReadVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a -# check we have no undefined symbols -nm -D Loader.so | grep ' U ' && exit 1 || exit 0 -ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds UpdateVars.o lib/lib-efi.a -o UpdateVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a -# check we have no undefined symbols -nm -D ReadVars.so | grep ' U ' && exit 1 || exit 0 -ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds KeyTool.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o KeyTool.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a -# check we have no undefined symbols -nm -D UpdateVars.so | grep ' U ' && exit 1 || exit 0 -# check we have no undefined symbols -nm -D KeyTool.so | grep ' U ' && exit 1 || exit 0 -ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds HashTool.o lib/lib-efi.a -o HashTool.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 SetNull.so SetNull.efi + -j .reloc --target=efi-app-x86_64 Loader.so Loader.efi +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 ReadVars.so ReadVars.efi +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 UpdateVars.so UpdateVars.efi +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 KeyTool.so KeyTool.efi +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 HashTool.so HashTool.efi objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ -j .reloc --target=efi-app-x86_64 ShimReplace.so ShimReplace.efi help2man --no-info -i doc/cert-to-efi-hash-list.1.in -o doc/cert-to-efi-hash-list.1 ./cert-to-efi-hash-list -# check we have no undefined symbols -nm -D HashTool.so | grep ' U ' && exit 1 || exit 0 help2man --no-info -i doc/cert-to-efi-sig-list.1.in -o doc/cert-to-efi-sig-list.1 ./cert-to-efi-sig-list +help2man --no-info -i doc/efi-readvar.1.in -o doc/efi-readvar.1 ./efi-readvar help2man --no-info -i doc/efi-updatevar.1.in -o doc/efi-updatevar.1 ./efi-updatevar help2man --no-info -i doc/sign-efi-sig-list.1.in -o doc/sign-efi-sig-list.1 ./sign-efi-sig-list -./sign-efi-sig-list -t "2026-11-04 11:46:33" -c PK.crt -k PK.key PK noPK.esl noPK.auth +./sign-efi-sig-list -t "2025-10-02 05:25:55" -c PK.crt -k PK.key PK noPK.esl noPK.auth ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc DB1.crt DB1.esl -Timestamp is 2026-11-4 11:46:33 +./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc DB2.crt DB2.esl +Timestamp is 2025-10-2 05:25:55 Authentication Payload size 40 Signature of size 1148 Signature at: 40 -./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc DB2.crt DB2.esl ./cert-to-efi-sig-list -g 77FA9ABD-0359-4D32-BD60-28F4E78F784B ms-uefi.crt ms-uefi.esl ./cert-to-efi-sig-list -g 77FA9ABD-0359-4D32-BD60-28F4E78F784B ms-kek.crt ms-kek.esl ./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB1.esl DB1-update.auth -./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB2.esl DB2-update.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 853 Signature of size 1151 Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB2.esl DB2-update.auth +./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-uefi.esl ms-uefi-update.auth Timestamp is 0-0-0 00:00:00 -Authentication Payload size 853 +Authentication Payload size 1640 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-uefi.esl ms-uefi-update.auth -./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-kek.esl ms-kek-update.auth Timestamp is 0-0-0 00:00:00 -Authentication Payload size 1640 +Authentication Payload size 853 Signature of size 1151 Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-kek.esl ms-kek-update.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 1600 Signature of size 1151 @@ -2622,108 +2666,89 @@ Signature of size 1148 Signature at: 40 ./sign-efi-sig-list -a -c PK.crt -k PK.key db DB2.esl DB2-pkupdate.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 853 -Signature of size 1148 -Signature at: 40 ./sign-efi-sig-list -a -c PK.crt -k PK.key db ms-uefi.esl ms-uefi-pkupdate.auth ./sign-efi-sig-list -a -c PK.crt -k PK.key db ms-kek.esl ms-kek-pkupdate.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 1640 Signature of size 1148 Signature at: 40 -./cert-to-efi-sig-list PK.crt PK-blacklist.esl Timestamp is 0-0-0 00:00:00 -Authentication Payload size 1600 +Authentication Payload size 853 Signature of size 1148 Signature at: 40 +./cert-to-efi-sig-list PK.crt PK-blacklist.esl ./cert-to-efi-sig-list KEK.crt KEK-blacklist.esl ./cert-to-efi-sig-list DB.crt DB-blacklist.esl +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 1600 +Signature of size 1148 +Signature at: 40 ./cert-to-efi-sig-list DB1.crt DB1-blacklist.esl ./cert-to-efi-sig-list DB2.crt DB2-blacklist.esl ./cert-to-efi-sig-list ms-uefi.crt ms-uefi-blacklist.esl ./cert-to-efi-sig-list ms-kek.crt ms-kek-blacklist.esl -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx PK-hash-blacklist.esl PK-hash-blacklist.auth -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx KEK-hash-blacklist.esl KEK-hash-blacklist.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB-hash-blacklist.esl DB-hash-blacklist.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB1-hash-blacklist.esl DB1-hash-blacklist.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB2-hash-blacklist.esl DB2-hash-blacklist.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-uefi-hash-blacklist.esl ms-uefi-hash-blacklist.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-kek-hash-blacklist.esl ms-kek-hash-blacklist.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 HelloWorld.so HelloWorld.efi -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 -Signature of size 1151 -Signature at: 40 +./cert-to-efi-hash-list PK.crt PK-hash-blacklist.esl +./cert-to-efi-hash-list KEK.crt KEK-hash-blacklist.esl +TimeOfRevocation is 0-0-0 00:00:00 +./cert-to-efi-hash-list DB.crt DB-hash-blacklist.esl +TimeOfRevocation is 0-0-0 00:00:00 +./cert-to-efi-hash-list DB1.crt DB1-hash-blacklist.esl +TimeOfRevocation is 0-0-0 00:00:00 +./cert-to-efi-hash-list DB2.crt DB2-hash-blacklist.esl +TimeOfRevocation is 0-0-0 00:00:00 +./cert-to-efi-hash-list ms-uefi.crt ms-uefi-hash-blacklist.esl +TimeOfRevocation is 0-0-0 00:00:00 +./cert-to-efi-hash-list ms-kek.crt ms-kek-hash-blacklist.esl +TimeOfRevocation is 0-0-0 00:00:00 +sbsign --key DB.key --cert DB.crt --output HelloWorld-signed.efi HelloWorld.efi +TimeOfRevocation is 0-0-0 00:00:00 ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc PK.crt PK.esl +warning: data remaining[40960 vs 53979]: gaps between PE/COFF sections? +warning: data remaining[40960 vs 53984]: gaps between PE/COFF sections? +Signing Unsigned original image ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc KEK.crt KEK.esl ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc DB.crt DB.esl -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 Loader.so Loader.efi -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 ReadVars.so ReadVars.efi -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 UpdateVars.so UpdateVars.efi -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 KeyTool.so KeyTool.efi -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 HashTool.so HashTool.efi -sbsign --key DB.key --cert DB.crt --output SetNull-signed.efi SetNull.efi +sbsign --key DB.key --cert DB.crt --output Loader-signed.efi Loader.efi +sbsign --key DB.key --cert DB.crt --output ReadVars-signed.efi ReadVars.efi +warning: data remaining[77312 vs 93370]: gaps between PE/COFF sections? +warning: data remaining[77312 vs 93376]: gaps between PE/COFF sections? +Signing Unsigned original image +sbsign --key DB.key --cert DB.crt --output UpdateVars-signed.efi UpdateVars.efi +warning: data remaining[101888 vs 119313]: gaps between PE/COFF sections? +warning: data remaining[101888 vs 119320]: gaps between PE/COFF sections? +Signing Unsigned original image +sbsign --key DB.key --cert DB.crt --output KeyTool-signed.efi KeyTool.efi +warning: data remaining[77824 vs 93892]: gaps between PE/COFF sections? +warning: data remaining[77824 vs 93896]: gaps between PE/COFF sections? +Signing Unsigned original image +sbsign --key DB.key --cert DB.crt --output HashTool-signed.efi HashTool.efi +warning: data remaining[108544 vs 126415]: gaps between PE/COFF sections? +warning: data remaining[108544 vs 126416]: gaps between PE/COFF sections? +Signing Unsigned original image sbsign --key DB.key --cert DB.crt --output ShimReplace-signed.efi ShimReplace.efi -warning: data remaining[35840 vs 48121]: gaps between PE/COFF sections? -warning: data remaining[35840 vs 48128]: gaps between PE/COFF sections? +warning: data remaining[77824 vs 93932]: gaps between PE/COFF sections? +warning: data remaining[77824 vs 93936]: gaps between PE/COFF sections? Signing Unsigned original image warning: data remaining[78848 vs 95501]: gaps between PE/COFF sections? warning: data remaining[78848 vs 95504]: gaps between PE/COFF sections? Signing Unsigned original image ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB1.esl DB1.auth -Timestamp is 2026-11-4 11:46:34 +Timestamp is 2025-10-2 05:25:56 Authentication Payload size 853 Signature of size 1151 Signature at: 40 ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB2.esl DB2.auth -Timestamp is 2026-11-4 11:46:34 +Timestamp is 2025-10-2 05:25:56 Authentication Payload size 853 Signature of size 1151 Signature at: 40 ./sign-efi-sig-list -c KEK.crt -k KEK.key db ms-uefi.esl ms-uefi.auth -Timestamp is 2026-11-4 11:46:34 +Timestamp is 2025-10-2 05:25:56 Authentication Payload size 1640 Signature of size 1151 Signature at: 40 ./sign-efi-sig-list -c KEK.crt -k KEK.key db ms-kek.esl ms-kek.auth -Timestamp is 2026-11-4 11:46:34 +Timestamp is 2025-10-2 05:25:56 Authentication Payload size 1600 Signature of size 1151 Signature at: 40 @@ -2733,11 +2758,11 @@ Signature of size 1148 Signature at: 40 ./sign-efi-sig-list -a -c PK.crt -k PK.key KEK KEK.esl KEK-update.auth -./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB.esl DB-update.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 855 Signature of size 1148 Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB.esl DB-update.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 851 Signature of size 1151 @@ -2779,59 +2804,70 @@ Signature of size 1151 Signature at: 40 ./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-uefi-blacklist.esl ms-uefi-blacklist.auth -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-kek-blacklist.esl ms-kek-blacklist.auth -sbsign --key DB.key --cert DB.crt --output HelloWorld-signed.efi HelloWorld.efi Timestamp is 0-0-0 00:00:00 Authentication Payload size 855 Signature of size 1151 Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-kek-blacklist.esl ms-kek-blacklist.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 1642 Signature of size 1151 Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx PK-hash-blacklist.esl PK-hash-blacklist.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 1602 Signature of size 1151 Signature at: 40 -warning: data remaining[40960 vs 53979]: gaps between PE/COFF sections? -warning: data remaining[40960 vs 53984]: gaps between PE/COFF sections? -Signing Unsigned original image +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx KEK-hash-blacklist.esl KEK-hash-blacklist.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB-hash-blacklist.esl DB-hash-blacklist.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB1-hash-blacklist.esl DB1-hash-blacklist.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB2-hash-blacklist.esl DB2-hash-blacklist.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-uefi-hash-blacklist.esl ms-uefi-hash-blacklist.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-kek-hash-blacklist.esl ms-kek-hash-blacklist.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 134 +Signature of size 1151 +Signature at: 40 ./sign-efi-sig-list -c PK.crt -k PK.key PK PK.esl PK.auth -Timestamp is 2026-11-4 11:46:34 +Timestamp is 2025-10-2 05:25:57 Authentication Payload size 851 Signature of size 1148 Signature at: 40 ./sign-efi-sig-list -c PK.crt -k PK.key KEK KEK.esl KEK.auth -Timestamp is 2026-11-4 11:46:34 +Timestamp is 2025-10-2 05:25:57 Authentication Payload size 855 Signature of size 1148 Signature at: 40 ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB.esl DB.auth -sbsign --key DB.key --cert DB.crt --output Loader-signed.efi Loader.efi -Timestamp is 2026-11-4 11:46:35 +./xxdi.pl PK.auth > PK.h +Timestamp is 2025-10-2 05:25:57 Authentication Payload size 851 Signature of size 1151 Signature at: 40 -sbsign --key DB.key --cert DB.crt --output ReadVars-signed.efi ReadVars.efi -warning: data remaining[77312 vs 93370]: gaps between PE/COFF sections? -warning: data remaining[77312 vs 93376]: gaps between PE/COFF sections? -Signing Unsigned original image -sbsign --key DB.key --cert DB.crt --output UpdateVars-signed.efi UpdateVars.efi -warning: data remaining[101888 vs 119313]: gaps between PE/COFF sections? -warning: data remaining[101888 vs 119320]: gaps between PE/COFF sections? -Signing Unsigned original image -sbsign --key DB.key --cert DB.crt --output KeyTool-signed.efi KeyTool.efi -warning: data remaining[77824 vs 93892]: gaps between PE/COFF sections? -warning: data remaining[77824 vs 93896]: gaps between PE/COFF sections? -Signing Unsigned original image -sbsign --key DB.key --cert DB.crt --output HashTool-signed.efi HashTool.efi -warning: data remaining[108544 vs 126415]: gaps between PE/COFF sections? -warning: data remaining[108544 vs 126416]: gaps between PE/COFF sections? -Signing Unsigned original image -./xxdi.pl PK.auth > PK.h -warning: data remaining[77824 vs 93932]: gaps between PE/COFF sections? -warning: data remaining[77824 vs 93936]: gaps between PE/COFF sections? -Signing Unsigned original image ./xxdi.pl KEK.auth > KEK.h ./xxdi.pl DB.auth > DB.h cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c LockDown.c -o LockDown.o @@ -2856,11 +2892,11 @@ make[1]: Entering directory '/build/reproducible-path/efitools-1.9.2' dh_auto_install -- EFIDIR="debian/efitools/usr/lib/efitools/x86_64-linux-gnu" install -m0755 -d /build/reproducible-path/efitools-1.9.2/debian/efitools - make -j42 install DESTDIR=/build/reproducible-path/efitools-1.9.2/debian/efitools AM_UPDATE_INFO_DIR=no INSTALL="install --strip-program=true" EFIDIR=debian/efitools/usr/lib/efitools/x86_64-linux-gnu + make -j40 install DESTDIR=/build/reproducible-path/efitools-1.9.2/debian/efitools AM_UPDATE_INFO_DIR=no INSTALL="install --strip-program=true" EFIDIR=debian/efitools/usr/lib/efitools/x86_64-linux-gnu make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2' make -C lib lib-efi.a -make -C lib lib.a make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' +make -C lib lib.a make -C lib/asn1 libasn1-efi.a make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' make[3]: 'lib-efi.a' is up to date. @@ -2908,20 +2944,20 @@ man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1 man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/sign-efi-sig-list.1 - mv debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 - chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 - mv debian/efitools/usr/share/man/man1/efi-readvar.1.dh-new debian/efitools/usr/share/man/man1/efi-readvar.1 - chmod 0644 -- debian/efitools/usr/share/man/man1/efi-readvar.1 + mv debian/efitools/usr/share/man/man1/sig-list-to-certs.1.dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1 + chmod 0644 -- debian/efitools/usr/share/man/man1/sig-list-to-certs.1 + mv debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 + chmod 0644 -- debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 + mv debian/efitools/usr/share/man/man1/sign-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/sign-efi-sig-list.1 + chmod 0644 -- debian/efitools/usr/share/man/man1/sign-efi-sig-list.1 mv debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1 chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1 mv debian/efitools/usr/share/man/man1/efi-updatevar.1.dh-new debian/efitools/usr/share/man/man1/efi-updatevar.1 chmod 0644 -- debian/efitools/usr/share/man/man1/efi-updatevar.1 - mv debian/efitools/usr/share/man/man1/sign-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/sign-efi-sig-list.1 - chmod 0644 -- debian/efitools/usr/share/man/man1/sign-efi-sig-list.1 - mv debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 - chmod 0644 -- debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 - mv debian/efitools/usr/share/man/man1/sig-list-to-certs.1.dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1 - chmod 0644 -- debian/efitools/usr/share/man/man1/sig-list-to-certs.1 + mv debian/efitools/usr/share/man/man1/efi-readvar.1.dh-new debian/efitools/usr/share/man/man1/efi-readvar.1 + chmod 0644 -- debian/efitools/usr/share/man/man1/efi-readvar.1 + mv debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 + chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 dh_perl dh_link dh_strip_nondeterminism @@ -2945,21 +2981,16 @@ objcopy --compress-debug-sections debian/efitools/usr/lib/debug/.dwz/x86_64-linux-gnu/efitools.debug chmod 0644 -- debian/efitools/usr/lib/debug/.dwz/x86_64-linux-gnu/efitools.debug dh_strip - install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/fe - objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/cert-to-efi-hash-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/fe/de3905699d02b983ed8ff554e6d21644b67e96.debug - chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/fe/de3905699d02b983ed8ff554e6d21644b67e96.debug - strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/cert-to-efi-hash-list - objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/fe/de3905699d02b983ed8ff554e6d21644b67e96.debug debian/efitools/usr/bin/cert-to-efi-hash-list - install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99 - objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/hash-to-efi-sig-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99/908c0ace033852ba4667471afe3c62e953ee58.debug - chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99/908c0ace033852ba4667471afe3c62e953ee58.debug - strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/hash-to-efi-sig-list - objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99/908c0ace033852ba4667471afe3c62e953ee58.debug debian/efitools/usr/bin/hash-to-efi-sig-list - install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f - objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-readvar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f/756a48e08689e0e1758eb3fbcef4b5e1142001.debug - chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f/756a48e08689e0e1758eb3fbcef4b5e1142001.debug - strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-readvar - objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f/756a48e08689e0e1758eb3fbcef4b5e1142001.debug debian/efitools/usr/bin/efi-readvar + install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36 + objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-updatevar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36/2f99c94e08af78d45c71ecab40fe3a54a2bff3.debug + chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36/2f99c94e08af78d45c71ecab40fe3a54a2bff3.debug + strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-updatevar + objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36/2f99c94e08af78d45c71ecab40fe3a54a2bff3.debug debian/efitools/usr/bin/efi-updatevar + install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3 + objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/cert-to-efi-sig-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3/ccc27b8ff1eab2dc3680b39217d95e69617abf.debug + chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3/ccc27b8ff1eab2dc3680b39217d95e69617abf.debug + strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/cert-to-efi-sig-list + objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3/ccc27b8ff1eab2dc3680b39217d95e69617abf.debug debian/efitools/usr/bin/cert-to-efi-sig-list install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/4d objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/sig-list-to-certs debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/4d/79bdf2ffb9eb52842df5536c2614419e3d11bd.debug chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/4d/79bdf2ffb9eb52842df5536c2614419e3d11bd.debug @@ -2970,21 +3001,26 @@ chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/22/d004f575054abedea247b379682036578dda28.debug strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/sign-efi-sig-list objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/22/d004f575054abedea247b379682036578dda28.debug debian/efitools/usr/bin/sign-efi-sig-list + install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99 + objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/hash-to-efi-sig-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99/908c0ace033852ba4667471afe3c62e953ee58.debug + chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99/908c0ace033852ba4667471afe3c62e953ee58.debug + strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/hash-to-efi-sig-list + objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99/908c0ace033852ba4667471afe3c62e953ee58.debug debian/efitools/usr/bin/hash-to-efi-sig-list + install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/fe + objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/cert-to-efi-hash-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/fe/de3905699d02b983ed8ff554e6d21644b67e96.debug + chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/fe/de3905699d02b983ed8ff554e6d21644b67e96.debug + strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/cert-to-efi-hash-list + objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/fe/de3905699d02b983ed8ff554e6d21644b67e96.debug debian/efitools/usr/bin/cert-to-efi-hash-list install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/e0 objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/flash-var debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/e0/81c5a754491d4c685e83f314d8a6322104e120.debug chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/e0/81c5a754491d4c685e83f314d8a6322104e120.debug strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/flash-var objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/e0/81c5a754491d4c685e83f314d8a6322104e120.debug debian/efitools/usr/bin/flash-var - install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3 - objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/cert-to-efi-sig-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3/ccc27b8ff1eab2dc3680b39217d95e69617abf.debug - chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3/ccc27b8ff1eab2dc3680b39217d95e69617abf.debug - strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/cert-to-efi-sig-list - objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3/ccc27b8ff1eab2dc3680b39217d95e69617abf.debug debian/efitools/usr/bin/cert-to-efi-sig-list - install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36 - objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-updatevar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36/2f99c94e08af78d45c71ecab40fe3a54a2bff3.debug - chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36/2f99c94e08af78d45c71ecab40fe3a54a2bff3.debug - strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-updatevar - objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36/2f99c94e08af78d45c71ecab40fe3a54a2bff3.debug debian/efitools/usr/bin/efi-updatevar + install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f + objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-readvar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f/756a48e08689e0e1758eb3fbcef4b5e1142001.debug + chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f/756a48e08689e0e1758eb3fbcef4b5e1142001.debug + strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-readvar + objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f/756a48e08689e0e1758eb3fbcef4b5e1142001.debug debian/efitools/usr/bin/efi-readvar install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.dwz cp --reflink=auto -a debian/efitools/usr/lib/debug/.dwz/x86_64-linux-gnu debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.dwz rm -fr debian/efitools/usr/lib/debug/.dwz @@ -2996,7 +3032,7 @@ rm -f debian/efitools/DEBIAN/shlibs dh_shlibdeps install -m0755 -d debian/efitools/DEBIAN - dpkg-shlibdeps -Tdebian/efitools.substvars debian/efitools/usr/bin/cert-to-efi-hash-list debian/efitools/usr/bin/hash-to-efi-sig-list debian/efitools/usr/bin/efi-readvar debian/efitools/usr/bin/sig-list-to-certs debian/efitools/usr/bin/sign-efi-sig-list debian/efitools/usr/bin/flash-var debian/efitools/usr/bin/cert-to-efi-sig-list debian/efitools/usr/bin/efi-updatevar + dpkg-shlibdeps -Tdebian/efitools.substvars debian/efitools/usr/bin/efi-updatevar debian/efitools/usr/bin/cert-to-efi-sig-list debian/efitools/usr/bin/sig-list-to-certs debian/efitools/usr/bin/sign-efi-sig-list debian/efitools/usr/bin/hash-to-efi-sig-list debian/efitools/usr/bin/cert-to-efi-hash-list debian/efitools/usr/bin/flash-var debian/efitools/usr/bin/efi-readvar dh_installdeb install -m0755 -d debian/efitools/DEBIAN dh_gencontrol @@ -3027,12 +3063,14 @@ dpkg-buildpackage: info: binary-only upload (no source included) dpkg-genchanges: info: not including original source code in upload I: copying local configuration +I: user script /srv/workspace/pbuilder/729246/tmp/hooks/B01_cleanup starting +I: user script /srv/workspace/pbuilder/729246/tmp/hooks/B01_cleanup finished I: unmounting dev/ptmx filesystem I: unmounting dev/pts filesystem I: unmounting dev/shm filesystem I: unmounting proc filesystem I: unmounting sys filesystem I: cleaning the build env -I: removing directory /srv/workspace/pbuilder/3581161 and its subdirectories -I: Current time: Tue Nov 3 23:46:41 -12 2026 -I: pbuilder-time-stamp: 1793792801 +I: removing directory /srv/workspace/pbuilder/729246 and its subdirectories +I: Current time: Thu Oct 2 19:26:04 +14 2025 +I: pbuilder-time-stamp: 1759382764