diff options
author | Markus Lehtonen <markus.lehtonen@linux.intel.com> | 2015-08-21 17:21:57 +0300 |
---|---|---|
committer | Richard Purdie <richard.purdie@linuxfoundation.org> | 2015-09-03 12:43:19 +0100 |
commit | 752736ae9f9c8842018e45cff2f5b1d770557d86 (patch) | |
tree | 0a95ef3491ff7c85747405ad9b831100dc2a9443 /meta/lib | |
parent | 103f0e5828d352b44681abe7fe47b606e6ad134b (diff) | |
download | poky-752736ae9f9c8842018e45cff2f5b1d770557d86.tar.gz |
package_rpm: support signing of rpm packages
This patch adds a new bbclass for generating rpm packages that are
signed with a user defined key. The packages are signed as part of the
"package_write_rpm" task.
In order to enable the feature you need to
1. 'INHERIT += " sign_rpm"' in bitbake config (e.g. local or
distro)
2. Create a file that contains the passphrase to your gpg secret key
3. 'RPM_GPG_PASSPHRASE_FILE = "<path_to_file>" in bitbake config,
pointing to the passphrase file created in 2.
4. Define GPG key name to use by either defining
'RPM_GPG_NAME = "<key_id>" in bitbake config OR by defining
%_gpg_name <key_id> in your ~/.oerpmmacros file
5. 'RPM_GPG_PUBKEY = "<path_to_pubkey>" in bitbake config pointing to
the public key (in "armor" format)
The user may optionally define "GPG_BIN" variable in the bitbake
configuration in order to specify a specific gpg binary/wrapper to use.
The sign_rpm.bbclass implements a simple scenario of locally signing the
packages. It could be replaced by a more advanced class that would
utilize a separate signing server for signing the packages, for example.
[YOCTO #8134]
(From OE-Core rev: 75f5f11b19ba1bf8743caf9ee7c99a3c67f4b266)
Signed-off-by: Markus Lehtonen <markus.lehtonen@linux.intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
Diffstat (limited to 'meta/lib')
-rw-r--r-- | meta/lib/oe/package_manager.py | 17 |
1 files changed, 17 insertions, 0 deletions
diff --git a/meta/lib/oe/package_manager.py b/meta/lib/oe/package_manager.py index f5a22abca7..3632a7af94 100644 --- a/meta/lib/oe/package_manager.py +++ b/meta/lib/oe/package_manager.py | |||
@@ -108,6 +108,7 @@ class RpmIndexer(Indexer): | |||
108 | archs = archs.union(set(sdk_pkg_archs)) | 108 | archs = archs.union(set(sdk_pkg_archs)) |
109 | 109 | ||
110 | rpm_createrepo = bb.utils.which(os.getenv('PATH'), "createrepo") | 110 | rpm_createrepo = bb.utils.which(os.getenv('PATH'), "createrepo") |
111 | |||
111 | index_cmds = [] | 112 | index_cmds = [] |
112 | rpm_dirs_found = False | 113 | rpm_dirs_found = False |
113 | for arch in archs: | 114 | for arch in archs: |
@@ -127,9 +128,16 @@ class RpmIndexer(Indexer): | |||
127 | bb.note("There are no packages in %s" % self.deploy_dir) | 128 | bb.note("There are no packages in %s" % self.deploy_dir) |
128 | return | 129 | return |
129 | 130 | ||
131 | # Create repodata | ||
130 | result = oe.utils.multiprocess_exec(index_cmds, create_index) | 132 | result = oe.utils.multiprocess_exec(index_cmds, create_index) |
131 | if result: | 133 | if result: |
132 | bb.fatal('%s' % ('\n'.join(result))) | 134 | bb.fatal('%s' % ('\n'.join(result))) |
135 | # Copy pubkey to repo | ||
136 | distro_version = self.d.getVar('DISTRO_VERSION', True) or "oe.0" | ||
137 | if self.d.getVar('RPM_SIGN_PACKAGES', True) == '1': | ||
138 | shutil.copy2(self.d.getVar('RPM_GPG_PUBKEY', True), | ||
139 | os.path.join(self.deploy_dir, | ||
140 | 'RPM-GPG-KEY-%s' % distro_version)) | ||
133 | 141 | ||
134 | 142 | ||
135 | class OpkgIndexer(Indexer): | 143 | class OpkgIndexer(Indexer): |
@@ -352,6 +360,9 @@ class RpmPkgsList(PkgsList): | |||
352 | pkg = line.split()[0] | 360 | pkg = line.split()[0] |
353 | arch = line.split()[1] | 361 | arch = line.split()[1] |
354 | ver = line.split()[2] | 362 | ver = line.split()[2] |
363 | # Skip GPG keys | ||
364 | if pkg == 'gpg-pubkey': | ||
365 | continue | ||
355 | if self.rpm_version == 4: | 366 | if self.rpm_version == 4: |
356 | pkgorigin = "unknown" | 367 | pkgorigin = "unknown" |
357 | else: | 368 | else: |
@@ -864,6 +875,12 @@ class RpmPM(PackageManager): | |||
864 | except subprocess.CalledProcessError as e: | 875 | except subprocess.CalledProcessError as e: |
865 | bb.fatal("Create rpm database failed. Command '%s' " | 876 | bb.fatal("Create rpm database failed. Command '%s' " |
866 | "returned %d:\n%s" % (cmd, e.returncode, e.output)) | 877 | "returned %d:\n%s" % (cmd, e.returncode, e.output)) |
878 | # Import GPG key to RPM database of the target system | ||
879 | if self.d.getVar('RPM_SIGN_PACKAGES', True) == '1': | ||
880 | pubkey_path = self.d.getVar('RPM_GPG_PUBKEY', True) | ||
881 | cmd = "%s --root %s --dbpath /var/lib/rpm --import %s > /dev/null" % ( | ||
882 | self.rpm_cmd, self.target_rootfs, pubkey_path) | ||
883 | subprocess.check_output(cmd, stderr=subprocess.STDOUT, shell=True) | ||
867 | 884 | ||
868 | # Configure smart | 885 | # Configure smart |
869 | bb.note("configuring Smart settings") | 886 | bb.note("configuring Smart settings") |