imx-cst: upgrade 3.4.1 -> 4.0.1

CST 4.0.1 replaces the custom Makefile build with CMake. Inherit the
cmake class, use the source src directory, and switch the parser
dependency from byacc to bison. Add json-c and point CMake at its staged
headers.

Disable installation of internal CST static libraries. Suppress line
directives from flex and bison generated sources to avoid embedding build
paths in the output.

Refresh source and license checksums and account for json-c's MIT
license. Drop the obsolete Makefile race fix.

Import Debian's check_return_values.patch from its packaging repository:

https://salsa.debian.org/collabora-team/imx-code-signing-tool

It handles fgets() failures required by the warning-as-error build.

Signed-off-by: Fabio Estevam <festevam@gmail.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
This commit is contained in:
Fabio Estevam
2026-07-26 00:13:33 -03:00
committed by Khem Raj
parent 0af35863bb
commit cf4a97c05e
4 changed files with 137 additions and 87 deletions
@@ -0,0 +1,101 @@
From 8a0717cc07e78d1133cc10e62220770734181bee Mon Sep 17 00:00:00 2001
From: Tobias Deiminger <tobias.deiminger@linutronix.de>
Date: Fri, 30 Jan 2026 01:55:36 +0100
Subject: [PATCH] Check return value of fgets
The cmake project has a reasonable default setting
CMAKE_COMPILE_WARNING_AS_ERROR=ON in cmake/compiler_options.cmake. With this
setting our build will fail on unchecked return values from fgets(). This
patch fixes the issue by adding return value checks.
This is not just to silence the errors. C99 defines for fgets: "If a read
error occurs during the operation, the array contents are indeterminate and a
null pointer is returned". We should actually check the return value to avoid
undefined behavior from processing indeterminate data.
Let get_passcode_to_key_file return -1 on error, since it is used as callback
to OpenSSLs PEM_read_bio_PrivateKey_ex where documentation states "The
callback must return the number of characters in the passphrase or -1 if an
error occurred".
Upstream-Status: Pending
---
src/lib/back_end/pkey.c | 6 +++++-
src/tools/pki_tree/hab4_pki_tree.c | 25 +++++++++++++++++++++----
2 files changed, 26 insertions(+), 5 deletions(-)
diff --git a/src/lib/back_end/pkey.c b/src/lib/back_end/pkey.c
index 31b5c3d..d6e9784 100644
--- a/src/lib/back_end/pkey.c
+++ b/src/lib/back_end/pkey.c
@@ -102,8 +102,12 @@ int get_passcode_to_key_file(char *buf, int size, int rwflag, void *userdata)
return 0;
}
- fgets(buf, size, password_fp);
+ buf = fgets(buf, size, password_fp);
fclose(password_fp);
+ if (buf == NULL)
+ {
+ return -1;
+ }
chomp(buf);
return strlen(buf);
diff --git a/src/tools/pki_tree/hab4_pki_tree.c b/src/tools/pki_tree/hab4_pki_tree.c
index 3c878e4..4ff15b2 100644
--- a/src/tools/pki_tree/hab4_pki_tree.c
+++ b/src/tools/pki_tree/hab4_pki_tree.c
@@ -118,6 +118,7 @@ int main(int argc, char **argv)
int num_srk = 0;
int val_period = 0;
char *pass = NULL;
+ char *user_input = NULL;
unsigned long serial = 0;
char duration_str[10] = {0};
char num_srk_str[10] = {0};
@@ -304,10 +305,18 @@ int main(int argc, char **argv)
if (strcmp(existing_ca, "y") == 0)
{
printf("Enter CA key name: ");
- fgets(ca_key, sizeof(ca_key), stdin);
+ user_input = fgets(ca_key, sizeof(ca_key), stdin);
+ if (user_input == NULL) {
+ fprintf(stderr, "Error while reading user input\n");
+ return 1;
+ }
ca_key[strcspn(ca_key, "\n")] = '\0';
printf("Enter CA certificate name: ");
- fgets(ca_cert, sizeof(ca_cert), stdin);
+ user_input = fgets(ca_cert, sizeof(ca_cert), stdin);
+ if (user_input == NULL) {
+ fprintf(stderr, "Error while reading user input\n");
+ return 1;
+ }
ca_cert[strcspn(ca_cert, "\n")] = '\0';
}
printf("\nKey type options (confirm targeted device supports desired "
@@ -330,10 +339,18 @@ int main(int argc, char **argv)
ARRAY_SIZE(rsa_kl_values));
}
printf("Enter PKI tree duration (years): ");
- fgets(duration_str, sizeof(duration_str), stdin);
+ user_input = fgets(duration_str, sizeof(duration_str), stdin);
+ if (user_input == NULL) {
+ fprintf(stderr, "Error while reading user input\n");
+ return 1;
+ }
duration = atoi(duration_str);
printf("How many Super Root Keys should be generated ? : ");
- fgets(num_srk_str, sizeof(num_srk_str), stdin);
+ user_input = fgets(num_srk_str, sizeof(num_srk_str), stdin);
+ if (user_input == NULL) {
+ fprintf(stderr, "Error while reading user input\n");
+ return 1;
+ }
num_srk = atoi(num_srk_str);
ask_until_valid(
"Do you want the SRK certificates to have the CA flag set? (y/n) :",
--
2.47.3
@@ -1,45 +0,0 @@
From 73509cb22ffab827dc3e3ccda2781683b8e8296d Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?K=C3=A9l=C3=A9fa=20San=C3=A9?= <kelefa.sane@smile.fr>
Date: Mon, 2 Jun 2025 11:07:08 +0200
Subject: [PATCH] fix missing makefile rule dependency
During, the package build with an high CPU load we can face
a build failed issue, caused by the header file cst_parser.h not present
when compiling cst_lexer.c, which depend on cst_parser.h:
| x86_64-poky-linux-gcc ... -c cst_lexer.c -o cst_lexer.d
| ../../code/front_end/src/cst_lexer.l:21:10: fatal error:
|cst_parser.h: No such file or directory
| 21 | #include "cst_parser.h"
| | ^~~~~~~~~~~~~~
| compilation terminated.
The file cst_parser.h is generated during compilation
by a makefile rule which also generate cst_parser.c
To fix the issue, makefile rule needed to be update
in order for compilation of cst_lexer.c to be done,
always after the generation of cst_parser.h and .c
Upstream-Status: Submitted [https://community.nxp.com/t5/Other-NXP-Products/Package-imx-code-signing-tool-3-4-0-dfsg-2-build-issue/m-p/2108575#M28853]
Signed-off-by: Kelefa Sane <kelefa.sane@smile.fr>
---
code/build/make/rules.mk | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/code/build/make/rules.mk b/code/build/make/rules.mk
index 7720e4b..239108b 100644
--- a/code/build/make/rules.mk
+++ b/code/build/make/rules.mk
@@ -35,6 +35,11 @@ LFLAGS := -t
@echo "Link $@"
$(LD) $^ $(LDFLAGS) -o $@
+# Compilation of cst_lexer.c require cst_parser.h
+# (cst_lexer.c include cst_parser.h) which is generated
+# by the same makefile genrating cst_parser.c
+cst_lexer.o: cst_parser.c
+
%.o: %.c
@echo "Compile $@"
# generate dependency file
@@ -1,42 +0,0 @@
SUMMARY = "i.MX code signing tool"
DESCRIPTION = "Code signing support that integrates the HABv4 and AHAB library for i.MX processors"
LICENSE = "Apache-2.0 AND BSD-3-Clause"
LIC_FILES_CHKSUM = "\
file://LICENSE.bsd3;md5=14aba05f9fa6c25527297c8aac95fcf6 \
file://LICENSE.hidapi;md5=e0ea014f523f64f0adb13409055ee59e \
file://LICENSE.openssl;md5=3441526b1df5cc01d812c7dfc218cea6 \
"
DEPENDS = "byacc-native flex-native openssl"
# debian: 3.4.0+dfsg-2
DEBIAN_PGK_NAME = "imx-code-signing-tool"
DEBIAN_PGK_VERSION = "${PV}+dfsg"
SRC_URI = "\
${DEBIAN_MIRROR}/main/i/${DEBIAN_PGK_NAME}/${DEBIAN_PGK_NAME}_${DEBIAN_PGK_VERSION}.orig.tar.xz \
file://0001-fix-missing-makefile-rule-dependency.patch \
"
SRC_URI[sha256sum] = "342c0c028658a4a859fe70578b58c3b07e17bee0c7e3a13d063d4791e82c2dee"
S = "${UNPACKDIR}/${DEBIAN_PGK_NAME}-${DEBIAN_PGK_VERSION}"
EXTRA_OEMAKE = 'CC="${CC}" LD="${CC}" AR="${AR}" OBJCOPY="${OBJCOPY}"'
inherit siteinfo
do_compile() {
oe_runmake -C code/obj.linux${SITEINFO_BITS} OSTYPE=linux${SITEINFO_BITS} ENCRYPTION=yes COPTIONS="${CFLAGS} ${CPPFLAGS}" LDOPTIONS="${LDFLAGS}"
oe_runmake -C add-ons/hab_csf_parser COPTS="${CFLAGS} ${CPPFLAGS} ${LDFLAGS}"
}
do_install () {
install -d ${D}${bindir}
install -m 755 ${S}/code/obj.linux${SITEINFO_BITS}/cst ${D}${bindir}/
install -m 755 ${S}/code/obj.linux${SITEINFO_BITS}/srktool ${D}${bindir}
install -m 755 ${S}/add-ons/hab_csf_parser/csf_parser ${D}${bindir}
}
BBCLASSEXTEND = "native nativesdk"
@@ -0,0 +1,36 @@
SUMMARY = "i.MX code signing tool"
DESCRIPTION = "Code signing support that integrates the HABv4 and AHAB library for i.MX processors"
LICENSE = "Apache-2.0 AND BSD-3-Clause AND MIT"
LIC_FILES_CHKSUM = "\
file://licenses/LICENSE.bsd3;md5=1ef4297097d818a9787ed775218c133f \
file://licenses/LICENSE.json-c;md5=de54b60fbbc35123ba193fea8ee216f2 \
file://licenses/LICENSE.openssl;md5=3441526b1df5cc01d812c7dfc218cea6 \
"
DEPENDS = "bison-native flex-native json-c openssl"
DEBIAN_PKG_NAME = "imx-code-signing-tool"
DEBIAN_PKG_VERSION = "${PV}+dfsg"
SRC_URI = "\
${DEBIAN_MIRROR}/main/i/${DEBIAN_PKG_NAME}/${DEBIAN_PKG_NAME}_${DEBIAN_PKG_VERSION}.orig.tar.xz \
file://0001-check-return-value-of-fgets.patch \
"
SRC_URI[sha256sum] = "fd92a1a9faa10fb81bbf752c7ee1e257f17e1ec4c2964f8a47adf8a3eaa7df41"
S = "${UNPACKDIR}/${DEBIAN_PKG_NAME}-${DEBIAN_PKG_VERSION}"
OECMAKE_SOURCEPATH = "${S}/src"
# CST_INSTALL only controls installation of internal static libraries, not tools.
EXTRA_OECMAKE = "\
-DCST_INSTALL=OFF \
-DFLEX_TARGET_ARG_COMPILE_FLAGS=--noline \
-DBISON_TARGET_ARG_COMPILE_FLAGS=--no-lines \
-DJSONC_INCLUDE_DIR=${STAGING_INCDIR} \
"
inherit cmake
BBCLASSEXTEND = "native nativesdk"