From 967de7635d795cb7f422caa4ffee8526272b02f7 Mon Sep 17 00:00:00 2001 From: Andreas Linde <42185+DerAndereAndi@users.noreply.github.com> Date: Sun, 2 Oct 2022 17:51:22 +0200 Subject: [PATCH] chore: apply asn1 patch to GOROOT (#4694) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * Modify asn1 patch This mirrors how it is working locally: - `sudo` needs to be called this way to modify a readonly file the current user only has read access to - `sudo` may not be used to call `make patch-asn1` as it would change the user context and patch the the file for the root user (it was go 1.17 for the root user) - the network stack uses the crypt package in `GOROOT` instead of any downlaoded package via modules or vendor * Makefile fixes - make sure sudo runs with the current users paths and not with the root paths * Remove crypto tests and crypto mod These tests require crypto to be added as a mod, but the network stack won’t use the crypto package in mods or vendors but the system crypto package. Hence the tests will not validate if the network stack use the patched version --- Makefile | 16 ++++++++-------- go.mod | 2 +- main.go | 9 --------- patch_test.go | 16 ---------------- 4 files changed, 9 insertions(+), 34 deletions(-) delete mode 100644 patch_test.go diff --git a/Makefile b/Makefile index 0a814df42..a1272747d 100644 --- a/Makefile +++ b/Makefile @@ -24,6 +24,10 @@ IMAGE_OPTIONS := -hostname evcc -http_port 8080 github.com/gokrazy/serial-busybo # deb PACKAGES = ./release +# asn1-patch +GOROOT := $(shell go env GOROOT) +CURRDIR := $(shell pwd) + default:: build all:: clean install install-ui ui assets lint test-ui lint-ui test build @@ -127,11 +131,7 @@ soc:: # patch asn1.go to allow Elli buggy certificates to be accepted with EEBUS patch-asn1:: - # echo $$(go env GOROOT) - # cat $$(go env GOROOT)/src/vendor/golang.org/x/crypto/cryptobyte/asn1.go | grep -C 1 "out = true" - # patch -N -t -d $$(go env GOROOT)/src/vendor/golang.org/x/crypto/cryptobyte -i $$(pwd)/patch/asn1.diff - # cat $$(go env GOROOT)/src/vendor/golang.org/x/crypto/cryptobyte/asn1.go | grep -C 1 "out = true" - go mod vendor - cat vendor/golang.org/x/crypto/cryptobyte/asn1.go | grep -C 1 "out = true" - patch -N -t -d vendor/golang.org/x/crypto/cryptobyte -i $$(pwd)/patch/asn1.diff - cat vendor/golang.org/x/crypto/cryptobyte/asn1.go | grep -C 1 "out = true" + # echo $(GOROOT) + cat $(GOROOT)/src/vendor/golang.org/x/crypto/cryptobyte/asn1.go | grep -C 1 "out = true" + sudo patch -N -t -d $(GOROOT)/src/vendor/golang.org/x/crypto/cryptobyte -i $(CURRDIR)/patch/asn1.diff + cat $(GOROOT)/src/vendor/golang.org/x/crypto/cryptobyte/asn1.go | grep -C 1 "out = true" diff --git a/go.mod b/go.mod index f1bd0814e..8d77048cb 100644 --- a/go.mod +++ b/go.mod @@ -80,7 +80,6 @@ require ( github.com/volkszaehler/mbmd v0.0.0-20220916215221-af29846c997e github.com/writeas/go-strip-markdown v2.0.1+incompatible gitlab.com/bboehmke/sunny v0.15.1-0.20211022160056-2fba1c86ade6 - golang.org/x/crypto v0.0.0-20220829220503-c86fa9a7ed90 golang.org/x/exp v0.0.0-20220827204233-334a2380cb91 golang.org/x/net v0.0.0-20220826154423-83b083e8dc8b golang.org/x/oauth2 v0.0.0-20220822191816-0ebed06d0094 @@ -158,6 +157,7 @@ require ( github.com/vmihailenco/msgpack/v5 v5.3.5 // indirect github.com/vmihailenco/tagparser/v2 v2.0.0 // indirect go.opencensus.io v0.23.0 // indirect + golang.org/x/crypto v0.0.0-20220829220503-c86fa9a7ed90 // indirect golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4 // indirect golang.org/x/sync v0.0.0-20220819030929-7fc1605a5dde // indirect golang.org/x/sys v0.0.0-20220829200755-d48e67d00261 // indirect diff --git a/main.go b/main.go index a78ffb93b..798586ab6 100644 --- a/main.go +++ b/main.go @@ -2,7 +2,6 @@ package main import ( "embed" - "fmt" "io" "io/fs" "log" @@ -10,7 +9,6 @@ import ( "github.com/evcc-io/evcc/cmd" "github.com/evcc-io/evcc/server" _ "github.com/evcc-io/evcc/util/goversion" // require minimum go version - "golang.org/x/crypto/cryptobyte" ) //go:embed dist @@ -32,12 +30,5 @@ func main() { // see https://github.com/golang/oauth2/issues/487 log.SetOutput(io.Discard) - // Test if go is patched for accepting the buggy Elli certificate - var res bool - b := cryptobyte.String([]byte{0x01, 0x01, 0x01}) - if ok := b.ReadASN1Boolean(&res); !ok || !res { - panic(fmt.Sprintf("Crypto patch missing. Run `make patch-asn1` before compiling. Debug: %v/%v (want: true/true).", ok, res)) - } - cmd.Execute() } diff --git a/patch_test.go b/patch_test.go deleted file mode 100644 index 19d097ad7..000000000 --- a/patch_test.go +++ /dev/null @@ -1,16 +0,0 @@ -package main - -import ( - "testing" - - "github.com/stretchr/testify/assert" - "golang.org/x/crypto/cryptobyte" -) - -func TestPatch(t *testing.T) { - var res bool - b := cryptobyte.String([]byte{0x01, 0x01, 0x01}) - ok := b.ReadASN1Boolean(&res) - assert.True(t, ok, "read failed") - assert.Equal(t, true, res, "patch failed") -}