diff mbox series

[v11,3/4] certs: conditionally build extract-cert if platform keyring is enabled

Message ID 20220310214450.676505-4-nayna@linux.ibm.com (mailing list archive)
State New, archived
Headers show
Series integrity: support including firmware ".platform" keys at build time | expand

Commit Message

Nayna Jain March 10, 2022, 9:44 p.m. UTC
extract-cert is used outside certs/ by INTEGRITY_PLATFORM_KEYRING.
Also build extract-cert if INTEGRITY_PLATFORM_KEYRING is enabled.

Signed-off-by: Nayna Jain <nayna@linux.ibm.com>
---
 certs/Makefile | 4 ++++
 1 file changed, 4 insertions(+)

Comments

Masahiro Yamada March 11, 2022, 4:34 a.m. UTC | #1
On Fri, Mar 11, 2022 at 6:45 AM Nayna Jain <nayna@linux.ibm.com> wrote:
>
> extract-cert is used outside certs/ by INTEGRITY_PLATFORM_KEYRING.
> Also build extract-cert if INTEGRITY_PLATFORM_KEYRING is enabled.

If really so, extract-cert should go back to scripts/ again.
(i.e. revert 340a02535ee785c64c62a9c45706597a0139e972)



>
> Signed-off-by: Nayna Jain <nayna@linux.ibm.com>
> ---
>  certs/Makefile | 4 ++++
>  1 file changed, 4 insertions(+)
>
> diff --git a/certs/Makefile b/certs/Makefile
> index b92b6ff339d5..dfb48e043cfe 100644
> --- a/certs/Makefile
> +++ b/certs/Makefile
> @@ -88,7 +88,11 @@ $(obj)/x509_revocation_list: $(CONFIG_SYSTEM_REVOCATION_KEYS) $(obj)/extract-cer
>
>  targets += x509_revocation_list
>
> +ifeq ($(CONFIG_INTEGRITY_PLATFORM_KEYRING),y)
> +hostprogs-always-y := extract-cert
> +else
>  hostprogs := extract-cert
> +endif
>
>  HOSTCFLAGS_extract-cert.o = $(shell pkg-config --cflags libcrypto 2> /dev/null)
>  HOSTLDLIBS_extract-cert = $(shell pkg-config --libs libcrypto 2> /dev/null || echo -lcrypto)
> --
> 2.27.0
>


--
Best Regards
Masahiro Yamada
diff mbox series

Patch

diff --git a/certs/Makefile b/certs/Makefile
index b92b6ff339d5..dfb48e043cfe 100644
--- a/certs/Makefile
+++ b/certs/Makefile
@@ -88,7 +88,11 @@  $(obj)/x509_revocation_list: $(CONFIG_SYSTEM_REVOCATION_KEYS) $(obj)/extract-cer
 
 targets += x509_revocation_list
 
+ifeq ($(CONFIG_INTEGRITY_PLATFORM_KEYRING),y)
+hostprogs-always-y := extract-cert
+else
 hostprogs := extract-cert
+endif
 
 HOSTCFLAGS_extract-cert.o = $(shell pkg-config --cflags libcrypto 2> /dev/null)
 HOSTLDLIBS_extract-cert = $(shell pkg-config --libs libcrypto 2> /dev/null || echo -lcrypto)