Diff of the two buildlogs: -- --- b1/build.log 2025-10-26 12:11:29.484176509 +0000 +++ b2/build.log 2025-10-26 12:13:15.948309961 +0000 @@ -1,6 +1,6 @@ I: pbuilder: network access will be disabled during build -I: Current time: Sun Oct 26 00:08:30 -12 2025 -I: pbuilder-time-stamp: 1761480510 +I: Current time: Sun Nov 29 08:34:30 +14 2026 +I: pbuilder-time-stamp: 1795890870 I: Building the build Environment I: extracting base tarball [/var/cache/pbuilder/forky-reproducible-base.tgz] I: copying local configuration @@ -32,53 +32,85 @@ dpkg-source: info: applying gcc15.patch I: using fakeroot in build. I: Installing the build-deps -I: user script /srv/workspace/pbuilder/3424667/tmp/hooks/D02_print_environment starting +I: user script /srv/workspace/pbuilder/2439467/tmp/hooks/D01_modify_environment starting +debug: Running on ionos5-amd64. +I: Changing host+domainname to test build reproducibility +I: Adding a custom variable just for the fun of it... +I: Changing /bin/sh to bash +'/bin/sh' -> '/bin/bash' +lrwxrwxrwx 1 root root 9 Nov 28 18:34 /bin/sh -> /bin/bash +I: Setting pbuilder2's login shell to /bin/bash +I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other +I: user script /srv/workspace/pbuilder/2439467/tmp/hooks/D01_modify_environment finished +I: user script /srv/workspace/pbuilder/2439467/tmp/hooks/D02_print_environment starting I: set - BUILDDIR='/build/reproducible-path' - BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other' - BUILDUSERNAME='pbuilder1' - BUILD_ARCH='amd64' - DEBIAN_FRONTEND='noninteractive' - DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=40 ' - DISTRIBUTION='forky' - HOME='/root' - HOST_ARCH='amd64' + BASH=/bin/sh + BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath + BASH_ALIASES=() + BASH_ARGC=() + BASH_ARGV=() + BASH_CMDS=() + BASH_LINENO=([0]="12" [1]="0") + BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:. + BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment") + BASH_VERSINFO=([0]="5" [1]="3" [2]="3" [3]="1" [4]="release" [5]="x86_64-pc-linux-gnu") + BASH_VERSION='5.3.3(1)-release' + BUILDDIR=/build/reproducible-path + BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other' + BUILDUSERNAME=pbuilder2 + BUILD_ARCH=amd64 + DEBIAN_FRONTEND=noninteractive + DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=42 ' + DIRSTACK=() + DISTRIBUTION=forky + EUID=0 + FUNCNAME=([0]="Echo" [1]="main") + GROUPS=() + HOME=/root + HOSTNAME=i-capture-the-hostname + HOSTTYPE=x86_64 + HOST_ARCH=amd64 IFS=' ' - INVOCATION_ID='2d31f2be51bd4a5684aaf25007164b41' - LANG='C' - LANGUAGE='en_US:en' - LC_ALL='C' - MAIL='/var/mail/root' - OPTIND='1' - PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games' - PBCURRENTCOMMANDLINEOPERATION='build' - PBUILDER_OPERATION='build' - PBUILDER_PKGDATADIR='/usr/share/pbuilder' - PBUILDER_PKGLIBDIR='/usr/lib/pbuilder' - PBUILDER_SYSCONFDIR='/etc' - PPID='3424667' - PS1='# ' - PS2='> ' + INVOCATION_ID=e79e278d45ce487b8eed99893fad75bd + LANG=C + LANGUAGE=et_EE:et + LC_ALL=C + MACHTYPE=x86_64-pc-linux-gnu + MAIL=/var/mail/root + OPTERR=1 + OPTIND=1 + OSTYPE=linux-gnu + PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path + PBCURRENTCOMMANDLINEOPERATION=build + PBUILDER_OPERATION=build + PBUILDER_PKGDATADIR=/usr/share/pbuilder + PBUILDER_PKGLIBDIR=/usr/lib/pbuilder + PBUILDER_SYSCONFDIR=/etc + PIPESTATUS=([0]="0") + POSIXLY_CORRECT=y + PPID=2439467 PS4='+ ' - PWD='/' - SHELL='/bin/bash' - SHLVL='2' - SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.tRGW1Snw/pbuilderrc_XHH7 --distribution forky --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/forky-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.tRGW1Snw/b1 --logfile b1/build.log efitools_1.9.2-3.6.dsc' - SUDO_GID='111' - SUDO_HOME='/var/lib/jenkins' - SUDO_UID='106' - SUDO_USER='jenkins' - TERM='unknown' - TZ='/usr/share/zoneinfo/Etc/GMT+12' - USER='root' - _='/usr/bin/systemd-run' - http_proxy='http://46.16.76.132:3128' + PWD=/ + SHELL=/bin/bash + SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix + SHLVL=3 + SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.tRGW1Snw/pbuilderrc_Z7L1 --distribution forky --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/forky-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.tRGW1Snw/b2 --logfile b2/build.log efitools_1.9.2-3.6.dsc' + SUDO_GID=110 + SUDO_HOME=/var/lib/jenkins + SUDO_UID=105 + SUDO_USER=jenkins + TERM=unknown + TZ=/usr/share/zoneinfo/Etc/GMT-14 + UID=0 + USER=root + _='I: set' + http_proxy=http://213.165.73.152:3128 I: uname -a - Linux ionos11-amd64 6.12.48+deb13-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.48-1 (2025-09-20) x86_64 GNU/Linux + Linux i-capture-the-hostname 6.12.48+deb13-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.48-1 (2025-09-20) x86_64 GNU/Linux I: ls -l /bin - lrwxrwxrwx 1 root root 7 Aug 10 12:30 /bin -> usr/bin -I: user script /srv/workspace/pbuilder/3424667/tmp/hooks/D02_print_environment finished + lrwxrwxrwx 1 root root 7 Aug 10 2025 /bin -> usr/bin +I: user script /srv/workspace/pbuilder/2439467/tmp/hooks/D02_print_environment finished -> Attempting to satisfy build-dependencies -> Creating pbuilder-satisfydepends-dummy package Package: pbuilder-satisfydepends-dummy @@ -162,7 +194,7 @@ Get: 34 http://deb.debian.org/debian forky/main amd64 libssl-dev amd64 3.5.4-1 [2980 kB] Get: 35 http://deb.debian.org/debian forky/main amd64 openssl amd64 3.5.4-1 [1496 kB] Get: 36 http://deb.debian.org/debian forky/main amd64 sbsigntool amd64 0.9.4-3.2 [67.5 kB] -Fetched 16.4 MB in 6s (2965 kB/s) +Fetched 16.4 MB in 4s (4446 kB/s) Preconfiguring packages ... Selecting previously unselected package liblocale-gettext-perl. (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 19900 files and directories currently installed.) @@ -327,7 +359,11 @@ fakeroot is already the newest version (1.37.1.2-1). 0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. I: Building the package -I: Running cd /build/reproducible-path/efitools-1.9.2/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S > ../efitools_1.9.2-3.6_source.changes +I: user script /srv/workspace/pbuilder/2439467/tmp/hooks/A99_set_merged_usr starting +Not re-configuring usrmerge for forky +I: user script /srv/workspace/pbuilder/2439467/tmp/hooks/A99_set_merged_usr finished +hostname: Name or service not known +I: Running cd /build/reproducible-path/efitools-1.9.2/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S > ../efitools_1.9.2-3.6_source.changes dpkg-buildpackage: info: source package efitools dpkg-buildpackage: info: source version 1.9.2-3.6 dpkg-buildpackage: info: source distribution unstable @@ -337,7 +373,7 @@ debian/rules clean dh clean dh_auto_clean - make -j40 clean + make -j42 clean make[1]: Entering directory '/build/reproducible-path/efitools-1.9.2' rm -f PK.* KEK.* DB.* HelloWorld.efi LockDown.efi Loader.efi ReadVars.efi UpdateVars.efi KeyTool.efi HashTool.efi SetNull.efi ShimReplace.efi HelloWorld-signed.efi LockDown-signed.efi Loader-signed.efi ReadVars-signed.efi UpdateVars-signed.efi KeyTool-signed.efi HashTool-signed.efi SetNull-signed.efi ShimReplace-signed.efi cert-to-efi-sig-list sig-list-to-certs sign-efi-sig-list hash-to-efi-sig-list efi-readvar efi-updatevar cert-to-efi-hash-list flash-var *.o *.so rm -f noPK.* @@ -377,48 +413,41 @@ dh_autoreconf dh_auto_configure dh_auto_build - make -j40 INSTALL="install --strip-program=true" + make -j42 INSTALL="install --strip-program=true" make[1]: Entering directory '/build/reproducible-path/efitools-1.9.2' make -C lib lib-efi.a make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c simple_file.c -o simple_file.efi.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c HelloWorld.c -o HelloWorld.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pecoff.c -o pecoff.efi.o openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB/" -keyout DB.key -out DB.crt -days 3650 -nodes -sha256 -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c guid.c -o guid.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c simple_file.c -o simple_file.efi.o openssl req -new -x509 -newkey rsa:2048 -subj "/CN=PK/" -keyout PK.key -out PK.crt -days 3650 -nodes -sha256 -...+...........+....+..+...+....+..+..........+......+++++++++++++++++++++++++++++++++++++++*.+..........+......+..+.........+....+......+.....+.........+....+...+........+....+..+.+...+.....+......+.+........+......+..........+++++++++++++++++++++++++++++++++++++++*...+...+..........+.....+.+..+....+......+........+................+...+........+....+.....+.+...+...........+......+.......+..+.........+.........+..........+......+............+..+.+......+...+...+..+......+.+.....+.........+....+.....+......+.....+...........++...+..+.......+...+..+..............+....+....+.....+....+...+.....+..+.+.+..cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c sha256.c -o sha256.efi.o -++++++++++++++.+..+....+.+.+.+.+.+.++++++++++++++++*.....+.....+++++++++++++...++++++++++++.+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-sig-list.c -o cert-to-efi-sig-list.o -++++++++++++++.++..*.....+.........+..+.............++..+.....+....................++.......+..+......+............+.+.....+...+....+........+...+.......+...+.................++.....++....+...+.+..+...+...+..........+..........+...+....+.+...........+......+......+......+............++...++......+....+.....+..+............+....+......+.........+.........+...+.+..+..............+...+...+....+....+........+...+.+........+......+....+...+........+...+.........+..+..............+......+...+......+..+..+............+...+make -C lib lib.a -.........+...............+.+..........+...+........++.........+.+........+..+.........+........+.....+..+.......+.........................+.....+....................+...+......+..+...........+...+........+.+...+..+................+......+....+...+..+....................+...+......cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c console.c -o console.efi.o -+...+....+...+..+....+................+...++...++.....++....+++ -..+........++++++++++++++++++++++++...+..+..+...+...+++++++++++++*...+.....+...+..........+..+.+...........+.....+++++++++++++++++++++++++.+..+...+.++++++++++++*........+......++...++.....++......++..+ -.......+.+.....+.+...............+............+......+..+...+..........+......+.....+...+...+........make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' -...........+.....+...+......+......+...+...+...+.........+.......+...+..+..................................+.....+.........+.......+.....+...+.+..............+.+......+......+........+..........+.....+..........+......+...+............+...+.....+.+...........+....+......+.........+.....+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c execute.c -o execute.efi.o -.+...+...+.....+...+....+...+............+...+........................+...+.....+...+.......+.................+...+......+.+...+..+..........+.........+..+.........+...+.++++++ -.......+++++++++++++++++++++++++++++++++++++++*.+..+......+.+........+...+++++++++++++++++++++++++++++++++++++++*.............+.....+...............+.++++++ -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c configtable.c -o configtable.efi.o +.............+......+.+..+++++++++++++++++++++++++++++++++++++++*.+......+.............+.....+.+..+++++++++++++++++++++++++++++++++++++++*..+..+.+............+..+.+..+.+...............+..+....+......+............+..+...+......+......+....+......+...+...........+.+.........+..+...+....+...............+..+....+..+...+.+........+.+..+.............+..............+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pecoff.c -o pecoff.efi.o +............+......+....+........................+..+......................+...+..+......+....+...+........+.+++++++++++++++++++++++++++++++++++++++*...+...+...++..+.+..+.+++++++++++++++++++++++++++++++++++*...++......++.....+.+...............++......+.....+....++............+...+....+.+.............++........++...............................++cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-sig-list.c -o cert-to-efi-sig-list.o +.............++...........+.......+...+...+..............++.......+....+.+++........++.......++.....++ +.+....+..+.+..+.+......+.....+.+++++++++++++++++++.+..++..+.+.++++++++++++++++*.....+....+..+.+..+.......+........+.++++++++++++++++.+..+++++++++++++++++++++++*..+.........+....+.........+.............................+............+.+.....++....+.........++..+++....+++ +.....+.+........+...+...+.......+..............+...+......+.......+..+----- +......+............+.............+..+....+...+.....+......+....+...+..++++++ +....+.........+++++++++++++++++++++++++++++++++++++++*....+...+++++++++++++++++++++++++++++++++++++++*...+....................+.+.................cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c guid.c -o guid.efi.o +............+..........+make -C lib lib.a +.........+......+......+.....+........................+.+..+.+.....+.......+........+....+........+.......+..+....+......+........+...+...+.........+.+..+.........+...+..................+...+.+.....+.+..+......+.+...+........+...+....+.....+..........+..+....+..+...+.+...+......+..............+.+............+...............+.....+....+.....+.+.....+..........+openssl req -new -x509 -newkey rsa:2048 -subj "/CN=KEK/" -keyout KEK.key -out KEK.crt -days 3650 -nodes -sha256 +..+.make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' ++......+........+.+............+...+..+.........+...+.......+......+........+....+...+.....+....+...+...........+....+..+.+...+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c sha256.c -o sha256.efi.o +..+.......+.....+.+.....+..........+..+...................+........+...+...+.+...+.....+.......+......+.....+...+.........+...+....+...+.....+.............+............+..+....+......+.....+.+.....+...+....+...........+....+...+..................+.........+..+...+......+....+............+...+.............+....++++++++..+++++++++++++++.+++++++++++++++..+.....+..+*.......++..+.......++++++++....+.+++++++++++++...++++++++++++++..+....+...+.....+.+*+..+......+......+.......+..+.............+..++......++.++..++.+ +............+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sign-efi-sig-list.c -o sign-efi-sig-list.o +..+.+...........+...+.............+.....+.......+...+...+...........+----- +......+...+.......+...+......+......+..+.............+...+..+.........+.+........+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c console.c -o console.efi.o +.+..................+...+..+.+.....................+......+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c simple_file.c -o simple_file.o +..+......+.........+.+...........+...+...+...+......+.........+.+.....+.............+..+...+...+....+........+.......+......+........+................+.....+....++++++ +...+++++++++++++++++++++++++++++++++++++++*......+...+....................+......+.+..+......+.+...+..+.........+++++++++++++++++++++++++++++++++++++++*...........+.........+....+.....+.+...........+.+...+......+.........+..+...+....+..+......+....+......cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c Loader.c -o Loader.o +...+..+...+....+...+.....+.......+........++++++ ----- -openssl req -new -x509 -newkey rsa:2048 -subj "/CN=KEK/" -keyout KEK.key -out KEK.crt -days 3650 -nodes -sha256 ------ -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c simple_file.c -o simple_file.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c execute.c -o execute.efi.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pecoff.c -o pecoff.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shell.c -o shell.efi.o -.+.....+++++++++++++++++++++++++++++++++++++++*.........+.+......+......+..+..........+...........+....+...+...+.........+.....+......+.......+...+..+...+..........+...........+...+++++++++++++++++++++++++++++++++++++++*........+......+.+............+..+.+..+................+.........+...+........+.+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c guid.c -o guid.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sign-efi-sig-list.c -o sign-efi-sig-list.o -...............+......+.....+...+...................+...............+...+.....+....+..............+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c security_policy.c -o security_policy.efi.o -.+...........+....+...+......+.....+.+.....+....+..+...+......+...+..........+...+........+.......+..+.......+...........+...+.........+.......+...+...+..+...............+...+.......+...+..+.............+........+....+......+..+.......+........+...+..........++++++ -..................+.........+++++++++++++++++++++++++++++++++++++++*.......+++++++++++++++++++++++++++++++++++++++*....+..........+.....+......+...+............+....+......+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c Loader.c -o Loader.o -...+......+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sha256.c -o sha256.o -............+..+.......+.....+....+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shim_protocol.c -o shim_protocol.efi.o -......++++++ -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c console.c -o console.o ------ -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pkcs7verify.c -o pkcs7verify.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c execute.c -o execute.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c variables.c -o variables.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c configtable.c -o configtable.o make -C lib/asn1 libasn1-efi.a +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c configtable.c -o configtable.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c guid.c -o guid.o +make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ReadVars.c -o ReadVars.o In file included from pecoff.c:69: pecoff.c: In function 'pecoff_relocate': /build/reproducible-path/efitools-1.9.2/include/buildefi.h:8:27: warning: too many arguments for format [-Wformat-extra-args] @@ -427,30 +456,10 @@ pecoff.c:197:17: note: in expansion of macro 'Print' 197 | Print(L"Reloc table overflows binary %d %d\n", | ^~~~~ -make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c shell.c -o shell.o -In file included from sha256.c:35: -sha256.c: In function 'sha256_get_pecoff_digest_mem': -/build/reproducible-path/efitools-1.9.2/include/buildefi.h:8:27: warning: too many arguments for format [-Wformat-extra-args] - 8 | #define Print(...) printf("%ls", __VA_ARGS__) - | ^~~~~ -sha256.c:360:17: note: in expansion of macro 'Print' - 360 | Print(L"Invalid Data Size %d bytes too small\n", DataSize + context.SecDir->Size - sum_of_bytes); - | ^~~~~ -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ReadVars.c -o ReadVars.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c security_policy.c -o security_policy.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1.c -o asn1.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shell.c -o shell.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sha256.c -o sha256.o cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c UpdateVars.c -o UpdateVars.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1_parser.c -o asn1_parser.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c enumerator.c -o enumerator.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c chunk.c -o chunk.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c shim_protocol.c -o shim_protocol.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c oid.c -o oid.efi.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c identification.c -o identification.efi.o -UpdateVars.c: In function 'efi_main': -UpdateVars.c:24:49: warning: variable 'owner_guid' set but not used [-Wunused-but-set-variable] - 24 | CHAR16 **ARGV, *var, *name, *progname, *owner_guid; - | ^~~~~~~~~~ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1.c -o asn1.efi.o ReadVars.c: In function 'efi_main': ReadVars.c:177:73: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=] 177 | Print(L"Variable %s has no entries\n", variables[i]); @@ -482,6 +491,55 @@ ReadVars.c:112:41: note: unnamed temporary defined here 112 | variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL}; | ^ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c security_policy.c -o security_policy.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c console.c -o console.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c KeyTool.c -o KeyTool.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1_parser.c -o asn1_parser.efi.o +In file included from asn1.c:18: +chunk.h: In function 'chunk_equals': +chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:32: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +chunk.h:139:43: note: in expansion of macro 'memeq' + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ^~~~~ +In file included from typedefs.h:3: +/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 413 | IN CONST CHAR8 *s1, +chunk.h:139:57: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:34: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +chunk.h:139:43: note: in expansion of macro 'memeq' + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ^~~~~ +/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 414 | IN CONST CHAR8 *s2, +UpdateVars.c: In function 'efi_main': +UpdateVars.c:24:49: warning: variable 'owner_guid' set but not used [-Wunused-but-set-variable] + 24 | CHAR16 **ARGV, *var, *name, *progname, *owner_guid; + | ^~~~~~~~~~ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shim_protocol.c -o shim_protocol.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c execute.c -o execute.o +In file included from sha256.c:35: +sha256.c: In function 'sha256_get_pecoff_digest_mem': +/build/reproducible-path/efitools-1.9.2/include/buildefi.h:8:27: warning: too many arguments for format [-Wformat-extra-args] + 8 | #define Print(...) printf("%ls", __VA_ARGS__) + | ^~~~~ +sha256.c:360:17: note: in expansion of macro 'Print' + 360 | Print(L"Invalid Data Size %d bytes too small\n", DataSize + context.SecDir->Size - sum_of_bytes); + | ^~~~~ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c HashTool.c -o HashTool.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c enumerator.c -o enumerator.efi.o In file included from asn1_parser.c:18: chunk.h: In function 'chunk_equals': chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] @@ -515,7 +573,74 @@ asn1_parser.c:82:15: warning: variable 'level' set but not used [-Wunused-but-set-variable] 82 | u_int level; | ^~~~~ -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c KeyTool.c -o KeyTool.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pkcs7verify.c -o pkcs7verify.efi.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c configtable.c -o configtable.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c SetNull.c -o SetNull.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c chunk.c -o chunk.efi.o +HashTool.c: In function 'efi_main': +HashTool.c:187:25: warning: variable 'setup_mode_arg' set but not used [-Wunused-but-set-variable] + 187 | setup_mode_arg = 0, keytool = NOSEL; + | ^~~~~~~~~~~~~~ +HashTool.c:185:28: warning: variable 'setup_mode' set but not used [-Wunused-but-set-variable] + 185 | int c = 0, setup_mode = NOSEL, uefi_reboot = NOSEL, + | ^~~~~~~~~~ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c variables.c -o variables.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c shell.c -o shell.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ShimReplace.c -o ShimReplace.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c oid.c -o oid.efi.o +In file included from chunk.c:18: +chunk.h: In function 'chunk_equals': +chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:32: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +chunk.h:139:43: note: in expansion of macro 'memeq' + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ^~~~~ +In file included from typedefs.h:3: +/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 413 | IN CONST CHAR8 *s1, +chunk.h:139:57: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:34: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +chunk.h:139:43: note: in expansion of macro 'memeq' + 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); + | ^~~~~ +/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 414 | IN CONST CHAR8 *s2, +chunk.c: In function 'chunk_compare': +chunk.c:55:24: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] + 55 | return memcmp(a.ptr, b.ptr, len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:32: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 413 | IN CONST CHAR8 *s1, +chunk.c:55:31: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] + 55 | return memcmp(a.ptr, b.ptr, len); + | ~^~~~ + | | + | u_char * {aka unsigned char *} +typedefs.h:9:34: note: in definition of macro 'memcmp' + 9 | #define memcmp(x,y,z) strncmpa(x,y,z) + | ^ +/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} + 414 | IN CONST CHAR8 *s2, +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c security_policy.c -o security_policy.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sig-list-to-certs.c -o sig-list-to-certs.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c identification.c -o identification.efi.o oid.c:13:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 13 | {0x02, 7, 1, 0, "ITU-T Administration" }, /* 0 */ | ^~~~~~~~~~~~~~~~~~~~~~ @@ -1052,7 +1177,6 @@ 146 | { 0x00, 154, 1, 6, "c-TwoCurve" }, /* 133 */ | ^~~~~~~~~~~~ oid.c:146:43: note: (near initialization for 'oid_names[133].name') -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pkcs7verify.c -o pkcs7verify.o oid.c:147:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 147 | { 0x01, 135, 0, 7, "c2pnb163v1" }, /* 134 */ | ^~~~~~~~~~~~ @@ -1321,6 +1445,10 @@ 213 | { 0x07, 0, 0, 7, "ipAddrBlocks" }, /* 200 */ | ^~~~~~~~~~~~~~ oid.c:213:43: note: (near initialization for 'oid_names[200].name') +ShimReplace.c: In function 'efi_main': +ShimReplace.c:51:37: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers] + 51 | efi_status = execute(image, loader); + | ^~~~~~ oid.c:214:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 214 | { 0x02, 204, 1, 6, "id-qt" }, /* 201 */ | ^~~~~~~ @@ -1329,13 +1457,23 @@ 215 | { 0x01, 203, 0, 7, "cps" }, /* 202 */ | ^~~~~ oid.c:215:43: note: (near initialization for 'oid_names[202].name') +In file included from ShimReplace.c:17: +/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'} + 5 | execute(EFI_HANDLE image, CHAR16 *name); + | ~~~~~~~~^~~~ oid.c:216:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 216 | { 0x02, 0, 0, 7, "unotice" }, /* 203 */ | ^~~~~~~~~ oid.c:216:43: note: (near initialization for 'oid_names[203].name') +ShimReplace.c:57:37: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers] + 57 | efi_status = execute(image, fallback); + | ^~~~~~~~ oid.c:217:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 217 | { 0x03, 214, 1, 6, "id-kp" }, /* 204 */ | ^~~~~~~ +/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'} + 5 | execute(EFI_HANDLE image, CHAR16 *name); + | ~~~~~~~~^~~~ oid.c:217:43: note: (near initialization for 'oid_names[204].name') oid.c:218:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 218 | { 0x01, 206, 0, 7, "serverAuth" }, /* 205 */ @@ -1520,7 +1658,6 @@ oid.c:263:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 263 | { 0x02, 0, 1, 4, "ecSign" }, /* 250 */ | ^~~~~~~~ -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c x509.c -o x509.efi.o oid.c:263:43: note: (near initialization for 'oid_names[250].name') oid.c:264:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 264 | { 0x01, 252, 0, 5, "ecSignWithsha1" }, /* 251 */ @@ -1942,6 +2079,7 @@ 368 | { 0x01, 0, 1, 8, "" }, /* 355 */ | ^~ oid.c:368:43: note: (near initialization for 'oid_names[355].name') +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c shim_protocol.c -o shim_protocol.o oid.c:369:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 369 | { 0x03, 0, 0, 9, "employeeNumber" }, /* 356 */ | ^~~~~~~~~~~~~~~~ @@ -1981,40 +2119,11 @@ oid.c:378:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 378 | { 0x05, 366, 0, 9, "senderNonce" }, /* 365 */ | ^~~~~~~~~~~~~ -In file included from chunk.c:18: -chunk.h: In function 'chunk_equals': oid.c:378:43: note: (near initialization for 'oid_names[365].name') oid.c:379:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 379 | { 0x06, 367, 0, 9, "recipientNonce" }, /* 366 */ | ^~~~~~~~~~~~~~~~ -chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:32: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ -chunk.h:139:43: note: in expansion of macro 'memeq' - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ^~~~~ oid.c:379:43: note: (near initialization for 'oid_names[366].name') -In file included from typedefs.h:3: -/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 413 | IN CONST CHAR8 *s1, -chunk.h:139:57: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:34: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ -chunk.h:139:43: note: in expansion of macro 'memeq' - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ^~~~~ -/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 414 | IN CONST CHAR8 *s2, oid.c:380:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 380 | { 0x07, 368, 0, 9, "transID" }, /* 367 */ | ^~~~~~~~~ @@ -2022,28 +2131,7 @@ oid.c:381:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 381 | { 0x08, 0, 0, 9, "extensionReq" }, /* 368 */ | ^~~~~~~~~~~~~~ -chunk.c: In function 'chunk_compare': oid.c:381:43: note: (near initialization for 'oid_names[368].name') -chunk.c:55:24: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] - 55 | return memcmp(a.ptr, b.ptr, len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:32: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ -/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 413 | IN CONST CHAR8 *s1, -chunk.c:55:31: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] - 55 | return memcmp(a.ptr, b.ptr, len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:34: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ -/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 414 | IN CONST CHAR8 *s2, oid.c:382:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign] 382 | {0x67, 0, 1, 0, "" }, /* 369 */ | ^~ @@ -2076,36 +2164,8 @@ 389 | { 0x0F, 0, 0, 4, "tcg-at-tpmIdLabel" } /* 376 */ | ^~~~~~~~~~~~~~~~~~~ oid.c:389:43: note: (near initialization for 'oid_names[376].name') -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c HashTool.c -o HashTool.o -In file included from asn1.c:18: -chunk.h: In function 'chunk_equals': -chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:32: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ -chunk.h:139:43: note: in expansion of macro 'memeq' - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ^~~~~ -In file included from typedefs.h:3: -/usr/include/efi/efilib.h:413:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 413 | IN CONST CHAR8 *s1, -chunk.h:139:57: warning: pointer targets in passing argument 2 of 'strncmpa' differ in signedness [-Wpointer-sign] - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ~^~~~ - | | - | u_char * {aka unsigned char *} -typedefs.h:9:34: note: in definition of macro 'memcmp' - 9 | #define memcmp(x,y,z) strncmpa(x,y,z) - | ^ -chunk.h:139:43: note: in expansion of macro 'memeq' - 139 | a.len == b.len && memeq(a.ptr, b.ptr, a.len); - | ^~~~~ -/usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'} - 414 | IN CONST CHAR8 *s2, +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c hash-to-efi-sig-list.c -o hash-to-efi-sig-list.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c x509.c -o x509.efi.o In file included from identification.c:18: chunk.h: In function 'chunk_equals': chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] @@ -2255,9 +2315,8 @@ identification.c:33:24: warning: 'x501rdns' defined but not used [-Wunused-const-variable=] 33 | static const x501rdn_t x501rdns[] = { | ^~~~~~~~ -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c kernel_efivars.c -o kernel_efivars.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c SetNull.c -o SetNull.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c openssl_sign.c -o openssl_sign.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pkcs7verify.c -o pkcs7verify.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-readvar.c -o efi-readvar.o In file included from x509.c:1: chunk.h: In function 'chunk_equals': chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign] @@ -2396,34 +2455,34 @@ 35 | { 0, "exit", ASN1_EOC, ASN1_EXIT } | ^~~~~~ x509.c:35:14: note: (near initialization for 'x509_certObjects[26].name') -HashTool.c: In function 'efi_main': -HashTool.c:187:25: warning: variable 'setup_mode_arg' set but not used [-Wunused-but-set-variable] - 187 | setup_mode_arg = 0, keytool = NOSEL; - | ^~~~~~~~~~~~~~ -HashTool.c:185:28: warning: variable 'setup_mode' set but not used [-Wunused-but-set-variable] - 185 | int c = 0, setup_mode = NOSEL, uefi_reboot = NOSEL, - | ^~~~~~~~~~ -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ShimReplace.c -o ShimReplace.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sig-list-to-certs.c -o sig-list-to-certs.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c hash-to-efi-sig-list.c -o hash-to-efi-sig-list.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-readvar.c -o efi-readvar.o +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c kernel_efivars.c -o kernel_efivars.o +hash-to-efi-sig-list.c: In function 'main': +hash-to-efi-sig-list.c:96:60: warning: format '%d' expects argument of type 'int', but argument 3 has type 'EFI_STATUS' {aka 'long unsigned int'} [-Wformat=] + 96 | printf("Failed to get hash of %s: %d\n", argv[i+1], + | ~^ + | | + | int + | %ld + 97 | status); + | ~~~~~~ + | | + | EFI_STATUS {aka long unsigned int} cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-updatevar.c -o efi-updatevar.o -cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-hash-list.c -o cert-to-efi-hash-list.o ar rcv libasn1-efi.a asn1.efi.o asn1_parser.efi.o enumerator.efi.o chunk.efi.o oid.efi.o identification.efi.o x509.efi.o -ShimReplace.c: In function 'efi_main': -ShimReplace.c:51:37: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers] - 51 | efi_status = execute(image, loader); - | ^~~~~~ -In file included from ShimReplace.c:17: -/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'} - 5 | execute(EFI_HANDLE image, CHAR16 *name); - | ~~~~~~~~^~~~ -ShimReplace.c:57:37: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers] - 57 | efi_status = execute(image, fallback); - | ^~~~~~~~ -/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'} - 5 | execute(EFI_HANDLE image, CHAR16 *name); - | ~~~~~~~~^~~~ +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c openssl_sign.c -o openssl_sign.o +a - asn1.efi.o +a - asn1_parser.efi.o +a - enumerator.efi.o +a - chunk.efi.o +a - oid.efi.o +a - identification.efi.o +a - x509.efi.o +make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' +cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-hash-list.c -o cert-to-efi-hash-list.o +cert-to-efi-hash-list.c:9:9: warning: '_XOPEN_SOURCE' redefined + 9 | #define _XOPEN_SOURCE + | ^~~~~~~~~~~~~ +: note: this is the location of the previous definition cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c flash-var.c -o flash-var.o openssl_sign.c: In function 'read_engine_private_key': openssl_sign.c:118:9: warning: 'ENGINE_load_builtin_engines' is deprecated: Since OpenSSL 3.0 [-Wdeprecated-declarations] @@ -2465,42 +2524,19 @@ | ^~~~~~~~~~~ > noPK.esl openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB1/" -keyout DB1.key -out DB1.crt -days 3650 -nodes -sha256 -.......+.+......+...+..+.........+......+.........+....+++++++++++++++++++++++++++++++++++++++*............+...+..+......+.......+...+..+...+.......+..+...+....+...+........+.......+..+...+...+....+...+.....+..........+...+.........+........+......+.+.....+......+...+.......+++++++++++++++++++++++++++++++++++++++*..+.........+....................+.+.........+.....+......+......+...+......+......+..........+...+...+............+...+..+...+.......+..+...+...+....+...+......+..+...+.......+........................+......+.........+.....+......+.......+............++++++ -.+........+.+.....+.+++++++++++++++++++++++++++++++++++++++*.....+...+...+............+..........+...+...+...........+....+..............+...+...+....+...........+.+........+...............+............+.+........+.+......+........+++++++++++++++++++++++++++++++++++++++*..........+.......+..+............+....+.........+...+.....+......................+..+.+............+............+..............+......+...+.+.................+....+...+.....+......+......+...................++++++ +....+.....+.+...+.....+.+.....+....+......+...+..+.+........+....+++++++++++++++++++++++++++++++++++++++*......+..+....+.....+.+.........+..+..........+..+......+....+......+..+...+..........+++++++++++++++++++++++++++++++++++++++*.....+.+............+.....+...+....+.....+.............+..+.+...+......+...+......+............+..+.+..+....+.....+.+........+..........+......+.....+..........+...+...+.....+...+......+.+..+.+..+.........+...+..........+.....................+......+........++++++ +.+.+..+++++++++++++++++++++++++++++++++++++++*..............+...+...+...+..+.......+.....+.+.....+......+...+............+...............+.+.....+.........+.+..+.......+++++++++++++++++++++++++++++++++++++++*...........+.........+........+...+.......+..+...............+............+.+..+...+....+....................+....+..............+.+..+....+...+.....+...+..........+..+......+......+....+.....+.+.....+..................+..........+..+.+........+.........+.+..+...................+......+..+..........+............+........+.+.....+.........+.......+...+........+............+...+....+...+...........+....+......+.....+....+..+....+............+..+............+.+..+...+.........+.........+.........+.+......+...+..+.........+....++++++ openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB2/" -keyout DB2.key -out DB2.crt -days 3650 -nodes -sha256 ----- -a - asn1.efi.o -a - asn1_parser.efi.o -a - enumerator.efi.o -a - chunk.efi.o -a - oid.efi.o -a - identification.efi.o -a - x509.efi.o -cert-to-efi-hash-list.c:9:9: warning: '_XOPEN_SOURCE' redefined - 9 | #define _XOPEN_SOURCE - | ^~~~~~~~~~~~~ -: note: this is the location of the previous definition -.........+.+..+....+......+.....+.......+...........+......+....+..+.......+...+..+...+++++++++++++++++++++++++++++++++++++++*.+.....+.+......+.....+.......+++++++++++++++++++++++++++++++++++++++*.....+.........+.+..+.......+...+..+.........+......++++++ -.+......+..+.......+++++++++++++++++++++++++++++++++++++++*.......+.........+..+....+.....+......+...+....+...+++++++++++++++++++++++++++++++++++++++*...+.......+..+............+......+.......+.....+..........+..+.+.................+......+....+...+.....+...+.+......+.....+hash-to-efi-sig-list.c: In function 'main': -hash-to-efi-sig-list.c:96:60: warning: format '%d' expects argument of type 'int', but argument 3 has type 'EFI_STATUS' {aka 'long unsigned int'} [-Wformat=] - 96 | printf("Failed to get hash of %s: %d\n", argv[i+1], - | ~^ - | | - | int - | %ld - 97 | status); - | ~~~~~~ - | | - | EFI_STATUS {aka long unsigned int} -.......+......+.........+..+...+...+.............+...............+.....+.+........+...+.......+.....+...+....+.....+.........+....+..+.+.....+.........+..........+......+........+.+.....+.+..+.+.....+..........+......+........+...+...+.......+.................+...+.........+....+......+......+...+..+....+.........+.....+......+.+...+......+...+...+..+......+make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' -....+...........+.......+..+.+......+...+...........+.+..................+.....+............+.+..+.+...........+...+...+..........+...+..+............+.+..+.............+..+...+.+........+...............+......+......+....+..+.......+..+.+........+....+...+........+......+.+..............+......+...+.+......+..................+..............+...+....+......+..++++++ +ar rcv lib-efi.a simple_file.efi.o pecoff.efi.o guid.efi.o sha256.efi.o console.efi.o execute.efi.o configtable.efi.o shell.efi.o security_policy.efi.o shim_protocol.efi.o pkcs7verify.efi.o variables.o flash-var.c: In function 'main': flash-var.c:185:9: warning: 'memset' offset [0, 56] is out of the bounds [0, 0] [-Warray-bounds=] 185 | memset(vh, 0, sizeof(*vh)); | ^~~~~~~~~~~~~~~~~~~~~~~~~~ -ar rcv lib-efi.a simple_file.efi.o pecoff.efi.o guid.efi.o sha256.efi.o console.efi.o execute.efi.o configtable.efi.o shell.efi.o security_policy.efi.o shim_protocol.efi.o pkcs7verify.efi.o variables.o +......+..+...+.........+.............+.........+...+++++++++++++++++++++++++++++++++++++++*..+...+.+...+..+.............+..+.............+++++++++++++++++++++++++++++++++++++++*...+.+........+..........+..+....+...........+..................+.......+..+.+..............+..........+...+..+......+...............+....+..+...+............+...+......+.+...+......+.....++++++ +.+...+...+..+.......+..+...+.+...........+...+.+......+.....+.............+...+...+...........+...+.+.........+..+...+...+++++++++++++++++++++++++++++++++++++++*.+......+......+.......+...+...+..+....+........+......+....+...+.........+...+......+......+.....+......+++++++++++++++++++++++++++++++++++++++*.....+......+..........+.................................+..+....+......+..+...+...+......+......+.......+...+..+.+.........+.....+.+............+...+..+....+.....+.+...+....................+.+...+..+.+.....+.........+.............+............+........+......+.........+...+..........+........+.+........+...+...+.+......+.........+...........+.......+..+....+..+.........+...+.......+......+...+.....+.+.....+...+.......+.....+..........+...+.....+......+......+......++++++ +ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds SetNull.o -o SetNull.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a ----- -ar rcv lib.a simple_file.o pecoff.o guid.o sha256.o console.o execute.o configtable.o shell.o security_policy.o shim_protocol.o pkcs7verify.o kernel_efivars.o openssl_sign.o a - simple_file.efi.o a - pecoff.efi.o a - guid.efi.o @@ -2513,6 +2549,13 @@ a - shim_protocol.efi.o a - pkcs7verify.efi.o a - variables.o +# check we have no undefined symbols +nm -D SetNull.so | grep ' U ' && exit 1 || exit 0 +objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ + -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ + -j .reloc --target=efi-app-x86_64 SetNull.so SetNull.efi +make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' +ar rcv lib.a simple_file.o pecoff.o guid.o sha256.o console.o execute.o configtable.o shell.o security_policy.o shim_protocol.o pkcs7verify.o kernel_efivars.o openssl_sign.o a - simple_file.o a - pecoff.o a - guid.o @@ -2526,111 +2569,64 @@ a - pkcs7verify.o a - kernel_efivars.o a - openssl_sign.o -ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds SetNull.o -o SetNull.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a -# check we have no undefined symbols -nm -D SetNull.so | grep ' U ' && exit 1 || exit 0 -objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ - -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ - -j .reloc --target=efi-app-x86_64 SetNull.so SetNull.efi -sbsign --key DB.key --cert DB.crt --output SetNull-signed.efi SetNull.efi -make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' -make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' -warning: data remaining[35840 vs 48121]: gaps between PE/COFF sections? -warning: data remaining[35840 vs 48128]: gaps between PE/COFF sections? -Signing Unsigned original image ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds ShimReplace.o lib/lib-efi.a -o ShimReplace.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a +make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' cc -o sig-list-to-certs sig-list-to-certs.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto +# check we have no undefined symbols +nm -D ShimReplace.so | grep ' U ' && exit 1 || exit 0 cc -o hash-to-efi-sig-list hash-to-efi-sig-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a cc -o efi-readvar efi-readvar.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto cc -o efi-updatevar efi-updatevar.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto -# check we have no undefined symbols -nm -D ShimReplace.so | grep ' U ' && exit 1 || exit 0 cc -o cert-to-efi-hash-list cert-to-efi-hash-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto cc -o flash-var flash-var.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -help2man --no-info -i doc/hash-to-efi-sig-list.1.in -o doc/hash-to-efi-sig-list.1 ./hash-to-efi-sig-list help2man --no-info -i doc/sig-list-to-certs.1.in -o doc/sig-list-to-certs.1 ./sig-list-to-certs ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds HelloWorld.o lib/lib-efi.a -o HelloWorld.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a cc -o cert-to-efi-sig-list cert-to-efi-sig-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto +# check we have no undefined symbols +nm -D HelloWorld.so | grep ' U ' && exit 1 || exit 0 cc -o sign-efi-sig-list sign-efi-sig-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds Loader.o lib/lib-efi.a -o Loader.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a # check we have no undefined symbols -# check we have no undefined symbols -nm -D HelloWorld.so | grep ' U ' && exit 1 || exit 0 nm -D Loader.so | grep ' U ' && exit 1 || exit 0 ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds ReadVars.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o ReadVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a # check we have no undefined symbols nm -D ReadVars.so | grep ' U ' && exit 1 || exit 0 ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds UpdateVars.o lib/lib-efi.a -o UpdateVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a -ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds KeyTool.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o KeyTool.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a # check we have no undefined symbols nm -D UpdateVars.so | grep ' U ' && exit 1 || exit 0 +ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds KeyTool.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o KeyTool.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a # check we have no undefined symbols nm -D KeyTool.so | grep ' U ' && exit 1 || exit 0 ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds HashTool.o lib/lib-efi.a -o HashTool.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/15/libgcc.a +sbsign --key DB.key --cert DB.crt --output SetNull-signed.efi SetNull.efi +# check we have no undefined symbols +nm -D HashTool.so | grep ' U ' && exit 1 || exit 0 +warning: data remaining[35840 vs 48121]: gaps between PE/COFF sections? +warning: data remaining[35840 vs 48128]: gaps between PE/COFF sections? objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ -j .reloc --target=efi-app-x86_64 ShimReplace.so ShimReplace.efi -# check we have no undefined symbols -nm -D HashTool.so | grep ' U ' && exit 1 || exit 0 +Signing Unsigned original image help2man --no-info -i doc/cert-to-efi-hash-list.1.in -o doc/cert-to-efi-hash-list.1 ./cert-to-efi-hash-list help2man --no-info -i doc/cert-to-efi-sig-list.1.in -o doc/cert-to-efi-sig-list.1 ./cert-to-efi-sig-list help2man --no-info -i doc/efi-readvar.1.in -o doc/efi-readvar.1 ./efi-readvar help2man --no-info -i doc/efi-updatevar.1.in -o doc/efi-updatevar.1 ./efi-updatevar +help2man --no-info -i doc/hash-to-efi-sig-list.1.in -o doc/hash-to-efi-sig-list.1 ./hash-to-efi-sig-list help2man --no-info -i doc/sign-efi-sig-list.1.in -o doc/sign-efi-sig-list.1 ./sign-efi-sig-list -./sign-efi-sig-list -t "2025-10-26 12:11:06" -c PK.crt -k PK.key PK noPK.esl noPK.auth +./sign-efi-sig-list -t "2026-11-28 18:36:03" -c PK.crt -k PK.key PK noPK.esl noPK.auth ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc DB1.crt DB1.esl -Timestamp is 2025-10-26 12:11:06 -Authentication Payload size 40 -Signature of size 1148 -Signature at: 40 ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc DB2.crt DB2.esl ./cert-to-efi-sig-list -g 77FA9ABD-0359-4D32-BD60-28F4E78F784B ms-uefi.crt ms-uefi.esl ./cert-to-efi-sig-list -g 77FA9ABD-0359-4D32-BD60-28F4E78F784B ms-kek.crt ms-kek.esl -./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB1.esl DB1-update.auth -./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB2.esl DB2-update.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 853 -Signature of size 1151 -Signature at: 40 -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 853 -Signature of size 1151 -Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-uefi.esl ms-uefi-update.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 1640 -Signature of size 1151 -Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-kek.esl ms-kek-update.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 1600 -Signature of size 1151 -Signature at: 40 -./sign-efi-sig-list -a -c PK.crt -k PK.key db DB1.esl DB1-pkupdate.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 853 -Signature of size 1148 -Signature at: 40 -./sign-efi-sig-list -a -c PK.crt -k PK.key db DB2.esl DB2-pkupdate.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 853 -Signature of size 1148 -Signature at: 40 -./sign-efi-sig-list -a -c PK.crt -k PK.key db ms-uefi.esl ms-uefi-pkupdate.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 1640 -Signature of size 1148 -Signature at: 40 -./sign-efi-sig-list -a -c PK.crt -k PK.key db ms-kek.esl ms-kek-pkupdate.auth ./cert-to-efi-sig-list PK.crt PK-blacklist.esl -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 1600 -Signature of size 1148 -Signature at: 40 ./cert-to-efi-sig-list KEK.crt KEK-blacklist.esl ./cert-to-efi-sig-list DB.crt DB-blacklist.esl ./cert-to-efi-sig-list DB1.crt DB1-blacklist.esl ./cert-to-efi-sig-list DB2.crt DB2-blacklist.esl +Timestamp is 2026-11-28 18:36:03 +Authentication Payload size 40 +Signature of size 1148 +Signature at: 40 ./cert-to-efi-sig-list ms-uefi.crt ms-uefi-blacklist.esl ./cert-to-efi-sig-list ms-kek.crt ms-kek-blacklist.esl ./cert-to-efi-hash-list PK.crt PK-hash-blacklist.esl @@ -2643,10 +2639,7 @@ ./cert-to-efi-hash-list DB2.crt DB2-hash-blacklist.esl TimeOfRevocation is 0-0-0 00:00:00 ./cert-to-efi-hash-list ms-uefi.crt ms-uefi-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 ./cert-to-efi-hash-list ms-kek.crt ms-kek-hash-blacklist.esl -TimeOfRevocation is 0-0-0 00:00:00 -TimeOfRevocation is 0-0-0 00:00:00 objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ -j .reloc --target=efi-app-x86_64 HelloWorld.so HelloWorld.efi @@ -2662,6 +2655,9 @@ objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ -j .reloc --target=efi-app-x86_64 UpdateVars.so UpdateVars.efi +TimeOfRevocation is 0-0-0 00:00:00 +TimeOfRevocation is 0-0-0 00:00:00 +TimeOfRevocation is 0-0-0 00:00:00 objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \ -j .reloc --target=efi-app-x86_64 KeyTool.so KeyTool.efi @@ -2673,26 +2669,26 @@ warning: data remaining[78848 vs 95504]: gaps between PE/COFF sections? Signing Unsigned original image ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB1.esl DB1.auth -Timestamp is 2025-10-26 12:11:08 +Timestamp is 2026-11-28 18:36:03 Authentication Payload size 853 Signature of size 1151 Signature at: 40 ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB2.esl DB2.auth -Timestamp is 2025-10-26 12:11:09 +Timestamp is 2026-11-28 18:36:04 Authentication Payload size 853 Signature of size 1151 Signature at: 40 ./sign-efi-sig-list -c KEK.crt -k KEK.key db ms-uefi.esl ms-uefi.auth -Timestamp is 2025-10-26 12:11:09 +./sign-efi-sig-list -c KEK.crt -k KEK.key db ms-kek.esl ms-kek.auth +Timestamp is 2026-11-28 18:36:04 Authentication Payload size 1640 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -c KEK.crt -k KEK.key db ms-kek.esl ms-kek.auth -./sign-efi-sig-list -a -c PK.crt -k PK.key PK PK.esl PK-update.auth -Timestamp is 2025-10-26 12:11:11 +Timestamp is 2026-11-28 18:36:04 Authentication Payload size 1600 Signature of size 1151 Signature at: 40 +./sign-efi-sig-list -a -c PK.crt -k PK.key PK PK.esl PK-update.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 851 Signature of size 1148 @@ -2700,14 +2696,34 @@ ./sign-efi-sig-list -a -c PK.crt -k PK.key KEK KEK.esl KEK-update.auth ./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB.esl DB-update.auth Timestamp is 0-0-0 00:00:00 +Authentication Payload size 851 +Signature of size 1151 +Signature at: 40 +Timestamp is 0-0-0 00:00:00 Authentication Payload size 855 Signature of size 1148 Signature at: 40 -./sign-efi-sig-list -a -c PK.crt -k PK.key PK PK.esl PK-pkupdate.auth +./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB1.esl DB1-update.auth Timestamp is 0-0-0 00:00:00 -Authentication Payload size 851 +Authentication Payload size 853 Signature of size 1151 Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB2.esl DB2-update.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 853 +Signature of size 1151 +Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-uefi.esl ms-uefi-update.auth +./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-kek.esl ms-kek-update.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 1640 +Signature of size 1151 +Signature at: 40 +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 1600 +Signature of size 1151 +Signature at: 40 +./sign-efi-sig-list -a -c PK.crt -k PK.key PK PK.esl PK-pkupdate.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 851 Signature of size 1148 @@ -2718,11 +2734,31 @@ Signature of size 1148 Signature at: 40 ./sign-efi-sig-list -a -c PK.crt -k PK.key db DB.esl DB-pkupdate.auth -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx PK-blacklist.esl PK-blacklist.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 851 Signature of size 1148 Signature at: 40 +./sign-efi-sig-list -a -c PK.crt -k PK.key db DB1.esl DB1-pkupdate.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 853 +Signature of size 1148 +Signature at: 40 +./sign-efi-sig-list -a -c PK.crt -k PK.key db DB2.esl DB2-pkupdate.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 853 +Signature of size 1148 +Signature at: 40 +./sign-efi-sig-list -a -c PK.crt -k PK.key db ms-uefi.esl ms-uefi-pkupdate.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 1640 +Signature of size 1148 +Signature at: 40 +./sign-efi-sig-list -a -c PK.crt -k PK.key db ms-kek.esl ms-kek-pkupdate.auth +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx PK-blacklist.esl PK-blacklist.auth +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 1600 +Signature of size 1148 +Signature at: 40 ./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx KEK-blacklist.esl KEK-blacklist.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 853 @@ -2734,61 +2770,61 @@ Signature of size 1151 Signature at: 40 ./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB1-blacklist.esl DB1-blacklist.auth -Timestamp is 0-0-0 00:00:00 -Authentication Payload size 853 -Signature of size 1151 -Signature at: 40 ./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB2-blacklist.esl DB2-blacklist.auth +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-uefi-blacklist.esl ms-uefi-blacklist.auth +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-kek-blacklist.esl ms-kek-blacklist.auth +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx PK-hash-blacklist.esl PK-hash-blacklist.auth +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx KEK-hash-blacklist.esl KEK-hash-blacklist.auth +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB-hash-blacklist.esl DB-hash-blacklist.auth +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB1-hash-blacklist.esl DB1-hash-blacklist.auth +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB2-hash-blacklist.esl DB2-hash-blacklist.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 855 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-uefi-blacklist.esl ms-uefi-blacklist.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 855 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-kek-blacklist.esl ms-kek-blacklist.auth Timestamp is 0-0-0 00:00:00 -Authentication Payload size 1642 +Authentication Payload size 853 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx PK-hash-blacklist.esl PK-hash-blacklist.auth Timestamp is 0-0-0 00:00:00 -Authentication Payload size 1602 +Authentication Payload size 134 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx KEK-hash-blacklist.esl KEK-hash-blacklist.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 134 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB-hash-blacklist.esl DB-hash-blacklist.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 134 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB1-hash-blacklist.esl DB1-hash-blacklist.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 134 Signature of size 1151 Signature at: 40 -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB2-hash-blacklist.esl DB2-hash-blacklist.auth Timestamp is 0-0-0 00:00:00 -Authentication Payload size 134 +Authentication Payload size 1602 +Signature of size 1151 +Signature at: 40 +Timestamp is 0-0-0 00:00:00 +Authentication Payload size 1642 Signature of size 1151 Signature at: 40 ./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-uefi-hash-blacklist.esl ms-uefi-hash-blacklist.auth -./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-kek-hash-blacklist.esl ms-kek-hash-blacklist.auth -sbsign --key DB.key --cert DB.crt --output HelloWorld-signed.efi HelloWorld.efi Timestamp is 0-0-0 00:00:00 Authentication Payload size 134 Signature of size 1151 Signature at: 40 +./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-kek-hash-blacklist.esl ms-kek-hash-blacklist.auth Timestamp is 0-0-0 00:00:00 Authentication Payload size 134 Signature of size 1151 Signature at: 40 +sbsign --key DB.key --cert DB.crt --output HelloWorld-signed.efi HelloWorld.efi Timestamp is 0-0-0 00:00:00 Authentication Payload size 134 Signature of size 1151 @@ -2797,18 +2833,18 @@ warning: data remaining[40960 vs 53984]: gaps between PE/COFF sections? Signing Unsigned original image ./sign-efi-sig-list -c PK.crt -k PK.key PK PK.esl PK.auth -Timestamp is 2025-10-26 12:11:13 +Timestamp is 2026-11-28 18:36:05 Authentication Payload size 851 Signature of size 1148 Signature at: 40 ./sign-efi-sig-list -c PK.crt -k PK.key KEK KEK.esl KEK.auth -Timestamp is 2025-10-26 12:11:13 +Timestamp is 2026-11-28 18:36:06 Authentication Payload size 855 Signature of size 1148 Signature at: 40 ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB.esl DB.auth sbsign --key DB.key --cert DB.crt --output Loader-signed.efi Loader.efi -Timestamp is 2025-10-26 12:11:13 +Timestamp is 2026-11-28 18:36:06 Authentication Payload size 851 Signature of size 1151 Signature at: 40 @@ -2821,17 +2857,17 @@ warning: data remaining[101888 vs 119320]: gaps between PE/COFF sections? Signing Unsigned original image sbsign --key DB.key --cert DB.crt --output KeyTool-signed.efi KeyTool.efi -warning: data remaining[77824 vs 93892]: gaps between PE/COFF sections? -warning: data remaining[77824 vs 93896]: gaps between PE/COFF sections? -Signing Unsigned original image sbsign --key DB.key --cert DB.crt --output HashTool-signed.efi HashTool.efi -warning: data remaining[108544 vs 126415]: gaps between PE/COFF sections? -warning: data remaining[108544 vs 126416]: gaps between PE/COFF sections? -Signing Unsigned original image ./xxdi.pl PK.auth > PK.h warning: data remaining[77824 vs 93932]: gaps between PE/COFF sections? warning: data remaining[77824 vs 93936]: gaps between PE/COFF sections? Signing Unsigned original image +warning: data remaining[108544 vs 126415]: gaps between PE/COFF sections? +warning: data remaining[77824 vs 93892]: gaps between PE/COFF sections? +warning: data remaining[77824 vs 93896]: gaps between PE/COFF sections? +warning: data remaining[108544 vs 126416]: gaps between PE/COFF sections? +Signing Unsigned original image +Signing Unsigned original image ./xxdi.pl KEK.auth > KEK.h ./xxdi.pl DB.auth > DB.h cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c LockDown.c -o LockDown.o @@ -2856,18 +2892,18 @@ make[1]: Entering directory '/build/reproducible-path/efitools-1.9.2' dh_auto_install -- EFIDIR="debian/efitools/usr/lib/efitools/x86_64-linux-gnu" install -m0755 -d /build/reproducible-path/efitools-1.9.2/debian/efitools - make -j40 install DESTDIR=/build/reproducible-path/efitools-1.9.2/debian/efitools AM_UPDATE_INFO_DIR=no INSTALL="install --strip-program=true" EFIDIR=debian/efitools/usr/lib/efitools/x86_64-linux-gnu + make -j42 install DESTDIR=/build/reproducible-path/efitools-1.9.2/debian/efitools AM_UPDATE_INFO_DIR=no INSTALL="install --strip-program=true" EFIDIR=debian/efitools/usr/lib/efitools/x86_64-linux-gnu make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2' make -C lib lib-efi.a -make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' make -C lib lib.a +make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' make -C lib/asn1 libasn1-efi.a make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib' make[3]: 'lib-efi.a' is up to date. make[3]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' -make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' make[3]: 'lib.a' is up to date. make[3]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib' +make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' make[3]: 'libasn1-efi.a' is up to date. make[3]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib/asn1' install --strip-program=true -m 755 -d /build/reproducible-path/efitools-1.9.2/debian/efitools/usr/share/man/man1 @@ -2908,20 +2944,20 @@ man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1 man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/sign-efi-sig-list.1 + mv debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 + chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 mv debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1 chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1 - mv debian/efitools/usr/share/man/man1/sig-list-to-certs.1.dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1 - chmod 0644 -- debian/efitools/usr/share/man/man1/sig-list-to-certs.1 - mv debian/efitools/usr/share/man/man1/efi-readvar.1.dh-new debian/efitools/usr/share/man/man1/efi-readvar.1 - chmod 0644 -- debian/efitools/usr/share/man/man1/efi-readvar.1 mv debian/efitools/usr/share/man/man1/sign-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/sign-efi-sig-list.1 chmod 0644 -- debian/efitools/usr/share/man/man1/sign-efi-sig-list.1 - mv debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 - chmod 0644 -- debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 - mv debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 - chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1 + mv debian/efitools/usr/share/man/man1/efi-readvar.1.dh-new debian/efitools/usr/share/man/man1/efi-readvar.1 + chmod 0644 -- debian/efitools/usr/share/man/man1/efi-readvar.1 + mv debian/efitools/usr/share/man/man1/sig-list-to-certs.1.dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1 + chmod 0644 -- debian/efitools/usr/share/man/man1/sig-list-to-certs.1 mv debian/efitools/usr/share/man/man1/efi-updatevar.1.dh-new debian/efitools/usr/share/man/man1/efi-updatevar.1 chmod 0644 -- debian/efitools/usr/share/man/man1/efi-updatevar.1 + mv debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 + chmod 0644 -- debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1 dh_perl dh_link dh_strip_nondeterminism @@ -2945,46 +2981,46 @@ objcopy --compress-debug-sections debian/efitools/usr/lib/debug/.dwz/x86_64-linux-gnu/efitools.debug chmod 0644 -- debian/efitools/usr/lib/debug/.dwz/x86_64-linux-gnu/efitools.debug dh_strip - install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36 - objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-updatevar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36/2f99c94e08af78d45c71ecab40fe3a54a2bff3.debug - chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36/2f99c94e08af78d45c71ecab40fe3a54a2bff3.debug - strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-updatevar - objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36/2f99c94e08af78d45c71ecab40fe3a54a2bff3.debug debian/efitools/usr/bin/efi-updatevar - install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3 - objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/cert-to-efi-sig-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3/ccc27b8ff1eab2dc3680b39217d95e69617abf.debug - chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3/ccc27b8ff1eab2dc3680b39217d95e69617abf.debug - strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/cert-to-efi-sig-list - objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3/ccc27b8ff1eab2dc3680b39217d95e69617abf.debug debian/efitools/usr/bin/cert-to-efi-sig-list + install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f + objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-readvar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f/756a48e08689e0e1758eb3fbcef4b5e1142001.debug + chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f/756a48e08689e0e1758eb3fbcef4b5e1142001.debug + strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-readvar + objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f/756a48e08689e0e1758eb3fbcef4b5e1142001.debug debian/efitools/usr/bin/efi-readvar install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/4d objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/sig-list-to-certs debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/4d/79bdf2ffb9eb52842df5536c2614419e3d11bd.debug chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/4d/79bdf2ffb9eb52842df5536c2614419e3d11bd.debug strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/sig-list-to-certs objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/4d/79bdf2ffb9eb52842df5536c2614419e3d11bd.debug debian/efitools/usr/bin/sig-list-to-certs - install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/22 - objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/sign-efi-sig-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/22/d004f575054abedea247b379682036578dda28.debug - chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/22/d004f575054abedea247b379682036578dda28.debug - strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/sign-efi-sig-list - objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/22/d004f575054abedea247b379682036578dda28.debug debian/efitools/usr/bin/sign-efi-sig-list - install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99 - objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/hash-to-efi-sig-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99/908c0ace033852ba4667471afe3c62e953ee58.debug - chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99/908c0ace033852ba4667471afe3c62e953ee58.debug - strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/hash-to-efi-sig-list - objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99/908c0ace033852ba4667471afe3c62e953ee58.debug debian/efitools/usr/bin/hash-to-efi-sig-list install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/fe objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/cert-to-efi-hash-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/fe/de3905699d02b983ed8ff554e6d21644b67e96.debug chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/fe/de3905699d02b983ed8ff554e6d21644b67e96.debug strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/cert-to-efi-hash-list objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/fe/de3905699d02b983ed8ff554e6d21644b67e96.debug debian/efitools/usr/bin/cert-to-efi-hash-list + install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36 + objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-updatevar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36/2f99c94e08af78d45c71ecab40fe3a54a2bff3.debug + chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36/2f99c94e08af78d45c71ecab40fe3a54a2bff3.debug + strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-updatevar + objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/36/2f99c94e08af78d45c71ecab40fe3a54a2bff3.debug debian/efitools/usr/bin/efi-updatevar + install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99 + objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/hash-to-efi-sig-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99/908c0ace033852ba4667471afe3c62e953ee58.debug + chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99/908c0ace033852ba4667471afe3c62e953ee58.debug + strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/hash-to-efi-sig-list + objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/99/908c0ace033852ba4667471afe3c62e953ee58.debug debian/efitools/usr/bin/hash-to-efi-sig-list install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/e0 objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/flash-var debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/e0/81c5a754491d4c685e83f314d8a6322104e120.debug chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/e0/81c5a754491d4c685e83f314d8a6322104e120.debug strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/flash-var objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/e0/81c5a754491d4c685e83f314d8a6322104e120.debug debian/efitools/usr/bin/flash-var - install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f - objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-readvar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f/756a48e08689e0e1758eb3fbcef4b5e1142001.debug - chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f/756a48e08689e0e1758eb3fbcef4b5e1142001.debug - strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-readvar - objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1f/756a48e08689e0e1758eb3fbcef4b5e1142001.debug debian/efitools/usr/bin/efi-readvar + install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/22 + objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/sign-efi-sig-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/22/d004f575054abedea247b379682036578dda28.debug + chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/22/d004f575054abedea247b379682036578dda28.debug + strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/sign-efi-sig-list + objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/22/d004f575054abedea247b379682036578dda28.debug debian/efitools/usr/bin/sign-efi-sig-list + install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3 + objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/cert-to-efi-sig-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3/ccc27b8ff1eab2dc3680b39217d95e69617abf.debug + chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3/ccc27b8ff1eab2dc3680b39217d95e69617abf.debug + strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/cert-to-efi-sig-list + objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a3/ccc27b8ff1eab2dc3680b39217d95e69617abf.debug debian/efitools/usr/bin/cert-to-efi-sig-list install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.dwz cp --reflink=auto -a debian/efitools/usr/lib/debug/.dwz/x86_64-linux-gnu debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.dwz rm -fr debian/efitools/usr/lib/debug/.dwz @@ -2996,7 +3032,7 @@ rm -f debian/efitools/DEBIAN/shlibs dh_shlibdeps install -m0755 -d debian/efitools/DEBIAN - dpkg-shlibdeps -Tdebian/efitools.substvars debian/efitools/usr/bin/efi-updatevar debian/efitools/usr/bin/cert-to-efi-sig-list debian/efitools/usr/bin/sig-list-to-certs debian/efitools/usr/bin/sign-efi-sig-list debian/efitools/usr/bin/hash-to-efi-sig-list debian/efitools/usr/bin/cert-to-efi-hash-list debian/efitools/usr/bin/flash-var debian/efitools/usr/bin/efi-readvar + dpkg-shlibdeps -Tdebian/efitools.substvars debian/efitools/usr/bin/efi-readvar debian/efitools/usr/bin/sig-list-to-certs debian/efitools/usr/bin/cert-to-efi-hash-list debian/efitools/usr/bin/efi-updatevar debian/efitools/usr/bin/hash-to-efi-sig-list debian/efitools/usr/bin/flash-var debian/efitools/usr/bin/sign-efi-sig-list debian/efitools/usr/bin/cert-to-efi-sig-list dh_installdeb install -m0755 -d debian/efitools/DEBIAN dh_gencontrol @@ -3027,12 +3063,14 @@ dpkg-buildpackage: info: binary-only upload (no source included) dpkg-genchanges: info: not including original source code in upload I: copying local configuration +I: user script /srv/workspace/pbuilder/2439467/tmp/hooks/B01_cleanup starting +I: user script /srv/workspace/pbuilder/2439467/tmp/hooks/B01_cleanup finished I: unmounting dev/ptmx filesystem I: unmounting dev/pts filesystem I: unmounting dev/shm filesystem I: unmounting proc filesystem I: unmounting sys filesystem I: cleaning the build env -I: removing directory /srv/workspace/pbuilder/3424667 and its subdirectories -I: Current time: Sun Oct 26 00:11:26 -12 2025 -I: pbuilder-time-stamp: 1761480686 +I: removing directory /srv/workspace/pbuilder/2439467 and its subdirectories +I: Current time: Sun Nov 29 08:36:15 +14 2026 +I: pbuilder-time-stamp: 1795890975