Makefile (2565ca7f5ec1a98d51eea8860c4ab923f1ca2c85) Makefile (d1f044103dad70c1cec0a8f3abdf00834fec8b98)
1# SPDX-License-Identifier: GPL-2.0
2#
3# Makefile for the linux kernel signature checking certificates.
4#
5
6obj-$(CONFIG_SYSTEM_TRUSTED_KEYRING) += system_keyring.o system_certificates.o common.o
1# SPDX-License-Identifier: GPL-2.0
2#
3# Makefile for the linux kernel signature checking certificates.
4#
5
6obj-$(CONFIG_SYSTEM_TRUSTED_KEYRING) += system_keyring.o system_certificates.o common.o
7obj-$(CONFIG_SYSTEM_BLACKLIST_KEYRING) += blacklist.o
7obj-$(CONFIG_SYSTEM_BLACKLIST_KEYRING) += blacklist.o common.o
8obj-$(CONFIG_SYSTEM_REVOCATION_LIST) += revocation_certificates.o
8ifneq ($(CONFIG_SYSTEM_BLACKLIST_HASH_LIST),"")
9obj-$(CONFIG_SYSTEM_BLACKLIST_KEYRING) += blacklist_hashes.o
10else
11obj-$(CONFIG_SYSTEM_BLACKLIST_KEYRING) += blacklist_nohashes.o
12endif
13
14ifeq ($(CONFIG_SYSTEM_TRUSTED_KEYRING),y)
15

--- 8 unchanged lines hidden (view full) ---

24quiet_cmd_extract_certs = EXTRACT_CERTS $(patsubst "%",%,$(2))
25 cmd_extract_certs = scripts/extract-cert $(2) $@
26
27targets += x509_certificate_list
28$(obj)/x509_certificate_list: scripts/extract-cert $(SYSTEM_TRUSTED_KEYS_SRCPREFIX)$(SYSTEM_TRUSTED_KEYS_FILENAME) FORCE
29 $(call if_changed,extract_certs,$(SYSTEM_TRUSTED_KEYS_SRCPREFIX)$(CONFIG_SYSTEM_TRUSTED_KEYS))
30endif # CONFIG_SYSTEM_TRUSTED_KEYRING
31
9ifneq ($(CONFIG_SYSTEM_BLACKLIST_HASH_LIST),"")
10obj-$(CONFIG_SYSTEM_BLACKLIST_KEYRING) += blacklist_hashes.o
11else
12obj-$(CONFIG_SYSTEM_BLACKLIST_KEYRING) += blacklist_nohashes.o
13endif
14
15ifeq ($(CONFIG_SYSTEM_TRUSTED_KEYRING),y)
16

--- 8 unchanged lines hidden (view full) ---

25quiet_cmd_extract_certs = EXTRACT_CERTS $(patsubst "%",%,$(2))
26 cmd_extract_certs = scripts/extract-cert $(2) $@
27
28targets += x509_certificate_list
29$(obj)/x509_certificate_list: scripts/extract-cert $(SYSTEM_TRUSTED_KEYS_SRCPREFIX)$(SYSTEM_TRUSTED_KEYS_FILENAME) FORCE
30 $(call if_changed,extract_certs,$(SYSTEM_TRUSTED_KEYS_SRCPREFIX)$(CONFIG_SYSTEM_TRUSTED_KEYS))
31endif # CONFIG_SYSTEM_TRUSTED_KEYRING
32
32clean-files := x509_certificate_list .x509.list
33clean-files := x509_certificate_list .x509.list x509_revocation_list
33
34ifeq ($(CONFIG_MODULE_SIG),y)
35###############################################################################
36#
37# If module signing is requested, say by allyesconfig, but a key has not been
38# supplied, then one will need to be generated to make sure the build does not
39# fail and that the kernel may be used afterwards.
40#

--- 58 unchanged lines hidden (view full) ---

99
100# GCC PR#66871 again.
101$(obj)/system_certificates.o: $(obj)/signing_key.x509
102
103targets += signing_key.x509
104$(obj)/signing_key.x509: scripts/extract-cert $(X509_DEP) FORCE
105 $(call if_changed,extract_certs,$(MODULE_SIG_KEY_SRCPREFIX)$(CONFIG_MODULE_SIG_KEY))
106endif # CONFIG_MODULE_SIG
34
35ifeq ($(CONFIG_MODULE_SIG),y)
36###############################################################################
37#
38# If module signing is requested, say by allyesconfig, but a key has not been
39# supplied, then one will need to be generated to make sure the build does not
40# fail and that the kernel may be used afterwards.
41#

--- 58 unchanged lines hidden (view full) ---

100
101# GCC PR#66871 again.
102$(obj)/system_certificates.o: $(obj)/signing_key.x509
103
104targets += signing_key.x509
105$(obj)/signing_key.x509: scripts/extract-cert $(X509_DEP) FORCE
106 $(call if_changed,extract_certs,$(MODULE_SIG_KEY_SRCPREFIX)$(CONFIG_MODULE_SIG_KEY))
107endif # CONFIG_MODULE_SIG
108
109ifeq ($(CONFIG_SYSTEM_REVOCATION_LIST),y)
110
111$(eval $(call config_filename,SYSTEM_REVOCATION_KEYS))
112
113$(obj)/revocation_certificates.o: $(obj)/x509_revocation_list
114
115quiet_cmd_extract_certs = EXTRACT_CERTS $(patsubst "%",%,$(2))
116 cmd_extract_certs = scripts/extract-cert $(2) $@
117
118targets += x509_revocation_list
119$(obj)/x509_revocation_list: scripts/extract-cert $(SYSTEM_REVOCATION_KEYS_SRCPREFIX)$(SYSTEM_REVOCATION_KEYS_FILENAME) FORCE
120 $(call if_changed,extract_certs,$(SYSTEM_REVOCATION_KEYS_SRCPREFIX)$(CONFIG_SYSTEM_REVOCATION_KEYS))
121endif