]> gitweb.fluxo.info Git - slackbuilds.git/commitdiff
homecrypt: signing Manifest
authorrhatto <rhatto@370017ae-e619-0410-ac65-c121f96126d4>
Wed, 28 Jan 2009 02:29:45 +0000 (02:29 +0000)
committerrhatto <rhatto@370017ae-e619-0410-ac65-c121f96126d4>
Wed, 28 Jan 2009 02:29:45 +0000 (02:29 +0000)
git-svn-id: svn+slack://slack.fluxo.info/var/svn/slackbuilds@2100 370017ae-e619-0410-ac65-c121f96126d4

app/crypt/homecrypt/Manifest [new file with mode: 0644]
app/crypt/homecrypt/homecrypt.SlackBuild

diff --git a/app/crypt/homecrypt/Manifest b/app/crypt/homecrypt/Manifest
new file mode 100644 (file)
index 0000000..f0ef67f
--- /dev/null
@@ -0,0 +1,22 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA1
+
+MKBUILD homecrypt.mkbuild 2531 MD5 0281f087f9abad36d977cb066b34b448 RMD160 c4003998dfe4b001c99e7aeb5b1331a0f59c32e1 SHA1 92c8bb12ef1072b0061ea826fcc2b79c10f64fb8 SHA256 067175757daccb9b5d031a38b58eb0e0c54395ead54c964a570d6e09dea590d0 SHA512 0b6287fda71ca0366836ca9ad1b49c98b34d4a47319f0785adfd9089e4dfc82ef240e94aa580aac5169058fece81a94322da71446d9986eb2ce59a18f93191d3
+SLACKBUILD homecrypt.SlackBuild 5273 MD5 da197a0b35d0107da40a95a8dfb4ec32 RMD160 8ddf2c7d4a90ecf80a5897de16027d4cae1621b4 SHA1 4049109f9ce4dd7366606406e8e20e9beb27de27 SHA256 af2200f47ed688ee8207920b469e939fb66ed8b0e57b1b0cb1213774ee8d53bf SHA512 873225a28e3b53592e8a5ee3cc10a12211af3fbdc5fda0b9dbd0b9889ccd72d313d19b6542c3f8fa10d96284524e4994f2df817286e6860237222ed735e485df
+-----BEGIN PGP SIGNATURE-----
+Version: GnuPG v1.4.9 (GNU/Linux)
+
+iQIcBAEBAgAGBQJJf8RQAAoJEEHL93ESzgeiXPMP/1S8ghHOfuPK0gi8FjSHw0y2
+Yhk7KZ0BmoG8sno+a7aHKbEwdF7FgzSF0ZYWUkhonG5KCtlyCozOh44OWqu1hCRl
+SC/tgLqUBQzl/tx/Pm+qdyU/kL5mgX3nfk9d+aO3REcOEBDLH9e2VYdBE67ube2T
+12f6BgymgXHDYACUtrmrnsiZvB2E6n43vHcZuuroWY9R6cgHopNX4mbvbejv355p
+wpY0oc8E/6CkSp6DBVsaL3w1uyaGSBljDHgTO3LsD7gdSx0j/Py8x2aJ57d3ktTM
+KQ3fVJQ8qhSuOeTRGP7R39hl6X0i5IWwdTXu9RYrwT2WXPHtvwLbBlNccTNfcM2S
+bXGZ+9TvrDWZa6yj/Jva1jVYqVaKe/qFUCD9AnI/ejdB5OtHe+XFwAWwRp6hxI1m
+OuCvU9kocdBeTve1tDBko9JelhB3+sPKUHu92O0DW3ebWXDRxx5gN5Bf90lpuIUj
+PvapKoa3/ic6dNP0roj8GLHSq0z/LXo1KlY0f81j+u8BvRwRBqpyZOL8T8LlBddP
+4KkrdN+XXaRbpxDWEit5jfwjmq8uGRWxKphyd0TD8Avnef0QRhogzbvPAQ5BQZaz
+/RQUV///oekcf/MqJ9s1tuy4ucbm6+RAY//N4TA+34bWFwYdC8tBTQHrpnUV5sTT
+DSOQv89jpnRjoWCWVzXS
+=IKmP
+-----END PGP SIGNATURE-----
index f29465002c3854f0c770e7ead21e58696d6c3425..f98191daa34f432591684b338f268d4c214bf823 100755 (executable)
@@ -47,9 +47,9 @@ NUMJOBS=${NUMJOBS:=""}
 LIBDIR="$PREFIX/lib"
 
 if [ "$ARCH" = "i386" ]; then
-  SLKCFLAGS="-O2 -march=i386 -mcpu=i686"
+  SLKCFLAGS="-O2 -march=i386 -mtune=i686"
 elif [ "$ARCH" = "i486" ]; then
-  SLKCFLAGS="-O2 -march=i486 -mcpu=i686"
+  SLKCFLAGS="-O2 -march=i486 -mtune=i686"
 elif [ "$ARCH" = "i686" ]; then
   SLKCFLAGS="-O2 -march=i686"
 elif [ "$ARCH" = "s390" ]; then
@@ -65,6 +65,7 @@ ERROR_WGET=31;      ERROR_MAKE=32;      ERROR_INSTALL=33
 ERROR_MD5=34;       ERROR_CONF=35;      ERROR_HELP=36
 ERROR_TAR=37;       ERROR_MKPKG=38;     ERROR_GPG=39
 ERROR_PATCH=40;     ERROR_VCS=41;       ERROR_MKDIR=42
+ERROR_MANIFEST=43;
 
 # Clean up any leftovers of previous builds
 rm -rf "$PKG_WORK" 2> /dev/null
@@ -96,6 +97,72 @@ cp -a $SRC_DIR/* .
 PKG_SRC="$PWD/$SND_DIR"
 cd "$PKG_SRC"
 
+# Check Manifest file
+if [ -e "$CWD/Manifest" ]; then
+
+  # Manifest signature checking
+  if grep -q -- "-----BEGIN PGP SIGNED MESSAGE-----" $CWD/Manifest; then
+    echo "Checking Manifest signature..."
+    gpg --verify $CWD/Manifest
+    if [ "$?" != "0" ]; then
+      exit $ERROR_MANIFEST
+    fi
+  fi
+
+  MANIFEST_LINES="`grep -E -v "^(MKBUILD|SLACKBUILD)" $CWD/Manifest | wc -l`"
+
+  for ((MANIFEST_COUNT=1; MANIFEST_COUNT <= $MANIFEST_LINES; MANIFEST_COUNT++)); do
+
+    MANIFEST_LINE="`grep -E -v "^(MKBUILD|SLACKBUILD)" $CWD/Manifest | head -n $MANIFEST_COUNT | tail -n 1`"
+    MANIFEST_FILE="`echo $MANIFEST_LINE | awk '{ print $2 }'`"
+    MANIFEST_FILE_TYPE="`echo $MANIFEST_LINE | awk '{ print $1 }'`"
+
+    if [ -e "$SRC_DIR/$MANIFEST_FILE" ]; then
+      MANIFEST_FILE="$SRC_DIR/$MANIFEST_FILE"
+    else
+      MANIFEST_FILE="`find $CWD -name $MANIFEST_FILE`"
+    fi
+
+    if [ ! -e "$MANIFEST_FILE" ] || [ -d "$MANIFEST_FILE" ]; then
+      continue
+    fi
+
+    echo "Checking Manifest for $MANIFEST_FILE_TYPE $MANIFEST_FILE integrity..."
+
+    SIZE_SRC="`wc -c $MANIFEST_FILE | awk '{ print $1 }'`"
+    SIZE_MANIFEST="`echo $MANIFEST_LINE | awk '{ print $3 }'`"
+
+    # Check source code size
+    if [ "$SIZE_SRC" != "$SIZE_MANIFEST" ]; then
+      echo "SIZE Manifest: $SIZE_MANIFEST; SIZE $SRC: $SIZE_SRC"
+      exit $ERROR_MANIFEST
+    else
+      echo "Size match."
+    fi
+
+    # Check source code integrity
+    for ALGO in md5 rmd160 sha1 sha256 sha512; do
+      if [ $ALGO = "rmd160" ]; then
+        ALGO_SRC="`openssl rmd160 $MANIFEST_FILE | awk '{ print $2 }'`"
+      else
+        ALGO_SRC="`"$ALGO"sum $MANIFEST_FILE | awk '{ print $1 }'`"
+      fi
+      ALGO="`echo $ALGO | tr '[:lower:]' '[:upper:]'`"
+      ALGO_MANIFEST=$(echo $MANIFEST_LINE | sed "s/.* $ALGO //" | awk '{ print $1 }')
+      if [ "$ALGO_SRC" != "$ALGO_MANIFEST" ]; then
+        echo "$ALGO Manifest: $ALGO_MANIFEST; $ALGO $SRC: $ALGO_SRC"
+        exit $ERROR_MANIFEST
+      else
+        echo "$ALGO match."
+      fi
+    done
+
+  done
+
+else
+  exit $ERROR_MANIFEST
+fi
+
 # Install
 make install DESTDIR="$PKG" || exit $ERROR_INSTALL
 
@@ -104,6 +171,6 @@ cd "$PKG"
 makepkg -l y -c n "$REPOS/$PKG_NAME-$PKG_VERSION-$ARCH-$BUILD.tgz" || exit $ERROR_MKPKG
 
 # Delete source and build directories if requested
-if [ "$CLEANUP" == "yes" ]; then
+if [ "$CLEANUP" == "yes" ] || [ "$1" = "--cleanup" ]; then
   rm -rf "$PKG_WORK" "$PKG"
 fi