Mock Version: 3.5 Mock Version: 3.5 Mock Version: 3.5 ENTER ['do_with_status'](['bash', '--login', '-c', '/usr/bin/rpmbuild -bs --noclean --target x86_64 --nodeps /builddir/build/SPECS/pesign-test-app.spec'], chrootPath='/var/lib/mock/inferit-9_1-build-6733-9624/root'env={'TERM': 'vt100', 'SHELL': '/bin/bash', 'HOME': '/builddir', 'HOSTNAME': 'mock', 'PATH': '/usr/bin:/bin:/usr/sbin:/sbin', 'PROMPT_COMMAND': 'printf "\\033]0;\\007"', 'PS1': ' \\s-\\v\\$ ', 'LANG': 'C.UTF-8'}shell=Falselogger=timeout=86400uid=991gid=135user='mockbuild'nspawn_args=['--capability=cap_ipc_lock', '--bind=/tmp/mock-resolv.vvk5ka_w:/etc/resolv.conf', '--bind=/dev/mapper/control', '--bind=/dev/loop-control', '--bind=/dev/loop0', '--bind=/dev/loop1', '--bind=/dev/loop2', '--bind=/dev/loop3', '--bind=/dev/loop4', '--bind=/dev/loop5', '--bind=/dev/loop6', '--bind=/dev/loop7', '--bind=/dev/loop8', '--bind=/dev/loop9', '--bind=/dev/loop10', '--bind=/dev/loop11']unshare_net=TrueprintOutput=False) Using nspawn with args ['--capability=cap_ipc_lock', '--bind=/tmp/mock-resolv.vvk5ka_w:/etc/resolv.conf', '--bind=/dev/mapper/control', '--bind=/dev/loop-control', '--bind=/dev/loop0', '--bind=/dev/loop1', '--bind=/dev/loop2', '--bind=/dev/loop3', '--bind=/dev/loop4', '--bind=/dev/loop5', '--bind=/dev/loop6', '--bind=/dev/loop7', '--bind=/dev/loop8', '--bind=/dev/loop9', '--bind=/dev/loop10', '--bind=/dev/loop11'] Executing command: ['/usr/bin/systemd-nspawn', '-q', '-M', 'a0e3520e5294454fb2dd3ad85d6c5837', '-D', '/var/lib/mock/inferit-9_1-build-6733-9624/root', '-a', '-u', 'mockbuild', '--capability=cap_ipc_lock', '--bind=/tmp/mock-resolv.vvk5ka_w:/etc/resolv.conf', '--bind=/dev/mapper/control', '--bind=/dev/loop-control', '--bind=/dev/loop0', '--bind=/dev/loop1', '--bind=/dev/loop2', '--bind=/dev/loop3', '--bind=/dev/loop4', '--bind=/dev/loop5', '--bind=/dev/loop6', '--bind=/dev/loop7', '--bind=/dev/loop8', '--bind=/dev/loop9', '--bind=/dev/loop10', '--bind=/dev/loop11', '--console=pipe', '--setenv=TERM=vt100', '--setenv=SHELL=/bin/bash', '--setenv=HOME=/builddir', '--setenv=HOSTNAME=mock', '--setenv=PATH=/usr/bin:/bin:/usr/sbin:/sbin', '--setenv=PROMPT_COMMAND=printf "\\033]0;\\007"', '--setenv=PS1= \\s-\\v\\$ ', '--setenv=LANG=C.UTF-8', '--resolv-conf=off', 'bash', '--login', '-c', '/usr/bin/rpmbuild -bs --noclean --target x86_64 --nodeps /builddir/build/SPECS/pesign-test-app.spec'] with env {'TERM': 'vt100', 'SHELL': '/bin/bash', 'HOME': '/builddir', 'HOSTNAME': 'mock', 'PATH': '/usr/bin:/bin:/usr/sbin:/sbin', 'PROMPT_COMMAND': 'printf "\\033]0;\\007"', 'PS1': ' \\s-\\v\\$ ', 'LANG': 'C.UTF-8', 'SYSTEMD_NSPAWN_TMPFS_TMP': '0', 'SYSTEMD_SECCOMP': '0'} and shell False Building target platforms: x86_64 Building for target x86_64 setting SOURCE_DATE_EPOCH=1679875200 Wrote: /builddir/build/SRPMS/pesign-test-app-5-28.el9.inferit.src.rpm Child return code was: 0 ENTER ['do_with_status'](['bash', '--login', '-c', '/usr/bin/rpmbuild -bb --noclean --target x86_64 --nodeps /builddir/build/SPECS/pesign-test-app.spec'], chrootPath='/var/lib/mock/inferit-9_1-build-6733-9624/root'env={'TERM': 'vt100', 'SHELL': '/bin/bash', 'HOME': '/builddir', 'HOSTNAME': 'mock', 'PATH': '/usr/bin:/bin:/usr/sbin:/sbin', 'PROMPT_COMMAND': 'printf "\\033]0;\\007"', 'PS1': ' \\s-\\v\\$ ', 'LANG': 'C.UTF-8'}shell=Falselogger=timeout=86400uid=991gid=135user='mockbuild'nspawn_args=['--capability=cap_ipc_lock', '--bind=/tmp/mock-resolv.vvk5ka_w:/etc/resolv.conf', '--bind=/dev/mapper/control', '--bind=/dev/loop-control', '--bind=/dev/loop0', '--bind=/dev/loop1', '--bind=/dev/loop2', '--bind=/dev/loop3', '--bind=/dev/loop4', '--bind=/dev/loop5', '--bind=/dev/loop6', '--bind=/dev/loop7', '--bind=/dev/loop8', '--bind=/dev/loop9', '--bind=/dev/loop10', '--bind=/dev/loop11']unshare_net=TrueprintOutput=False) Using nspawn with args ['--capability=cap_ipc_lock', '--bind=/tmp/mock-resolv.vvk5ka_w:/etc/resolv.conf', '--bind=/dev/mapper/control', '--bind=/dev/loop-control', '--bind=/dev/loop0', '--bind=/dev/loop1', '--bind=/dev/loop2', '--bind=/dev/loop3', '--bind=/dev/loop4', '--bind=/dev/loop5', '--bind=/dev/loop6', '--bind=/dev/loop7', '--bind=/dev/loop8', '--bind=/dev/loop9', '--bind=/dev/loop10', '--bind=/dev/loop11'] Executing command: ['/usr/bin/systemd-nspawn', '-q', '-M', 'fd1a3157effb4f37a491a2e63bf0b198', '-D', '/var/lib/mock/inferit-9_1-build-6733-9624/root', '-a', '-u', 'mockbuild', '--capability=cap_ipc_lock', '--bind=/tmp/mock-resolv.vvk5ka_w:/etc/resolv.conf', '--bind=/dev/mapper/control', '--bind=/dev/loop-control', '--bind=/dev/loop0', '--bind=/dev/loop1', '--bind=/dev/loop2', '--bind=/dev/loop3', '--bind=/dev/loop4', '--bind=/dev/loop5', '--bind=/dev/loop6', '--bind=/dev/loop7', '--bind=/dev/loop8', '--bind=/dev/loop9', '--bind=/dev/loop10', '--bind=/dev/loop11', '--console=pipe', '--setenv=TERM=vt100', '--setenv=SHELL=/bin/bash', '--setenv=HOME=/builddir', '--setenv=HOSTNAME=mock', '--setenv=PATH=/usr/bin:/bin:/usr/sbin:/sbin', '--setenv=PROMPT_COMMAND=printf "\\033]0;\\007"', '--setenv=PS1= \\s-\\v\\$ ', '--setenv=LANG=C.UTF-8', '--resolv-conf=off', 'bash', '--login', '-c', '/usr/bin/rpmbuild -bb --noclean --target x86_64 --nodeps /builddir/build/SPECS/pesign-test-app.spec'] with env {'TERM': 'vt100', 'SHELL': '/bin/bash', 'HOME': '/builddir', 'HOSTNAME': 'mock', 'PATH': '/usr/bin:/bin:/usr/sbin:/sbin', 'PROMPT_COMMAND': 'printf "\\033]0;\\007"', 'PS1': ' \\s-\\v\\$ ', 'LANG': 'C.UTF-8', 'SYSTEMD_NSPAWN_TMPFS_TMP': '0', 'SYSTEMD_SECCOMP': '0'} and shell False Building target platforms: x86_64 Building for target x86_64 setting SOURCE_DATE_EPOCH=1679875200 Executing(%prep): /bin/sh -e /var/tmp/rpm-tmp.DYQ84x + umask 022 + cd /builddir/build/BUILD + cd /builddir/build/BUILD + rm -rf pesign-test-app-5 + /usr/bin/bzip2 -dc /builddir/build/SOURCES/pesign-test-app-5.tar.bz2 + /usr/bin/tar -xof - + STATUS=0 + '[' 0 -ne 0 ']' + cd pesign-test-app-5 + /usr/bin/chmod -Rf a+rX,u+w,g-w,o-w . + /usr/bin/git init -q + /usr/bin/git config user.name rpm-build + /usr/bin/git config user.email '' + /usr/bin/git config gc.auto 0 + /usr/bin/git add --force . + /usr/bin/git commit -q --allow-empty -a --author 'rpm-build ' -m 'pesign-test-app-5 base' + /usr/bin/cat /builddir/build/SOURCES/0001-Fix-gnu-efi-include-path.patch + /usr/bin/git apply --index --reject - Checking patch Makefile... Applied patch Makefile cleanly. + /usr/bin/git commit -q -m 0001-Fix-gnu-efi-include-path.patch --author 'rpm-build ' + RPM_EC=0 ++ jobs -p + exit 0 Executing(%build): /bin/sh -e /var/tmp/rpm-tmp.ssZCnY + umask 022 + cd /builddir/build/BUILD + cd pesign-test-app-5 + make LIBDIR=/usr/lib64 DATADIR=/usr/share 'CFLAGS=-O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64-v2 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection' LDFLAGS= gcc -O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64-v2 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection -fpic -Werror -Wall -Wextra -fshort-wchar -fno-merge-constants -ffreestanding -fno-stack-protector -fno-stack-check --std=gnu11 -DCONFIG_x86_64 -I/usr/include/efi/ -I/usr/include/efi/x64/ -I/usr/include/efi/protocol -mno-mmx -mno-sse -mno-red-zone -nostdinc -maccumulate-outgoing-args -DEFI_FUNCTION_WRAPPER -DGNU_EFI_USE_MS_ABI -I/usr/lib/gcc/x86_64-redhat-linux/11/include -c -o pesign-test-app.o pesign-test-app.c gcc -nostdlib -Wl,--warn-common -Wl,--no-undefined -Wl,--fatal-warnings -Wl,-shared -Wl,-Bsymbolic -L/usr/lib64 -L/usr/lib64/gnuefi//x64 -Wl,--build-id=sha1 -Wl,--hash-style=sysv /usr/lib64/gnuefi//x64/crt0.o -o pesign-test-app.so pesign-test-app.o -lefi -lgnuefi \ /usr/lib/gcc/x86_64-redhat-linux/11/libgcc.a \ -T /usr/lib64/gnuefi//x64/efi.lds objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \ -j .rel* -j .rela* -j .reloc -j .eh_frame \ --target efi-app-x86_64 pesign-test-app.so pesign-test-app.efi rm pesign-test-app.so pesign-test-app.o + cp pesign-test-app.efi pesign-test-app-unsigned.efi + id uid=991(mockbuild) gid=135(mock) groups=135(mock) + ls -ld /etc/pki/pesign drwxrwx---+ 2 pesign 989 55 Mar 26 21:12 /etc/pki/pesign + getfacl /etc/pki/pesign getfacl: Removing leading '/' from absolute path names # file: etc/pki/pesign # owner: pesign # group: 989 user::rwx user:mockbuild:r-x group::rwx mask::rwx other::--- + ls -l /etc/pki/pesign total 68 -rw-rw----+ 1 pesign 989 28672 Mar 26 21:12 cert9.db -rw-rw----+ 1 pesign 989 36864 Mar 26 21:12 key4.db -rw-rw----+ 1 pesign 989 429 Jun 8 2020 pkcs11.txt + getfacl /etc/pki/pesign/cert9.db /etc/pki/pesign/key4.db /etc/pki/pesign/pkcs11.txt getfacl: Removing leading '/' from absolute path names # file: etc/pki/pesign/cert9.db # owner: pesign # group: 989 user::rw- user:mockbuild:r-- group::rw- mask::rw- other::--- # file: etc/pki/pesign/key4.db # owner: pesign # group: 989 user::rw- user:mockbuild:r-- group::rw- mask::rw- other::--- # file: etc/pki/pesign/pkcs11.txt # owner: pesign # group: 989 user::rw- user:mockbuild:r-- group::rw- mask::rw- other::--- + cp pesign-test-app-unsigned.efi pesign-test-app-unsigned.0.efi + /usr/libexec/pesign/pesign-rpmbuild-helper x86_64 /usr/bin/pesign /usr/bin/pesign-client --client-token 'NSS Certificate DB' --client-cert 'MSVSphere Secure Boot Signing' --token 'NSS Certificate DB' --cert 'MSVSphere Secure Boot Signing' --hostname builder-x86-02.inferitos.ru --vendor MSVSphere --rhelver 9 --rhelver 9 --rhelcert spheresecureboot001 --rhelcafile spheresecurebootca.cer --rhelcertfile spheresecureboot001.cer --in pesign-test-app-unsigned.0.efi --out pesign-test-app-signed.efi --sign + main x86_64 /usr/bin/pesign /usr/bin/pesign-client --client-token 'NSS Certificate DB' --client-cert 'MSVSphere Secure Boot Signing' --token 'NSS Certificate DB' --cert 'MSVSphere Secure Boot Signing' --hostname builder-x86-02.inferitos.ru --vendor MSVSphere --rhelver 9 --rhelver 9 --rhelcert spheresecureboot001 --rhelcafile spheresecurebootca.cer --rhelcertfile spheresecureboot001.cer --in pesign-test-app-unsigned.0.efi --out pesign-test-app-signed.efi --sign + [[ 30 -lt 3 ]] + local target_cpu=x86_64 + shift + local bin=/usr/bin/pesign + shift + local client=/usr/bin/pesign-client + shift + local rhelcafile= + local rhelcertfile= + certout=() + local certout + sattrout=() + local sattrout + input=() + local input + output=() + local output + client_token=() + local client_token + client_cert=() + local client_cert + token=() + local token + cert=() + local cert + rhelcert=() + local rhelcert + local rhelver=0 + local sign= + local arch= + local vendor= + local HOSTNAME= + [[ 27 -ge 2 ]] + case " ${1} " in + client_token[0]=-t + client_token[1]='NSS Certificate DB' + shift + shift + [[ 25 -ge 2 ]] + case " ${1} " in + client_cert[0]=-c + client_cert[1]='MSVSphere Secure Boot Signing' + shift + shift + [[ 23 -ge 2 ]] + case " ${1} " in + token[0]=-t + token[1]='NSS Certificate DB' + shift + shift + [[ 21 -ge 2 ]] + case " ${1} " in + cert[0]=-c + cert[1]='MSVSphere Secure Boot Signing' + shift + shift + [[ 19 -ge 2 ]] + case " ${1} " in + HOSTNAME=builder-x86-02.inferitos.ru + shift + shift + [[ 17 -ge 2 ]] + case " ${1} " in + vendor=MSVSphere + shift + shift + [[ 15 -ge 2 ]] + case " ${1} " in + rhelver=9 + shift + shift + [[ 13 -ge 2 ]] + case " ${1} " in + rhelver=9 + shift + shift + [[ 11 -ge 2 ]] + case " ${1} " in + rhelcert[0]=-c + rhelcert[1]=spheresecureboot001 + shift + shift + [[ 9 -ge 2 ]] + case " ${1} " in + rhelcafile=spheresecurebootca.cer + shift + shift + [[ 7 -ge 2 ]] + case " ${1} " in + rhelcertfile=spheresecureboot001.cer + shift + shift + [[ 5 -ge 2 ]] + case " ${1} " in + input[0]=-i + input[1]=pesign-test-app-unsigned.0.efi + shift + shift + [[ 3 -ge 2 ]] + case " ${1} " in + output[0]=-o + output[1]=pesign-test-app-signed.efi + shift + shift + [[ 1 -ge 2 ]] + [[ 1 -ge 1 ]] + [[ --sign = --sign ]] + sign=-s + shift + [[ 0 -ge 1 ]] + [[ -z x86_64 ]] + target_cpu=x86_64 + target_cpu=x64 + target_cpu=x64 + target_cpu=x64 + local nssdir=/etc/pki/pesign + [[ 2 -eq 2 ]] + [[ MSVSphere Secure Boot Signing == \R\e\d\ \H\a\t\ \T\e\s\t\ \C\e\r\t\i\f\i\c\a\t\e ]] + [[ -x /usr/bin/pesign ]] + is_efi_arch x64 + local arch=x64 + arches=('aa64' 'ia32' 'x64') + local arches + local x + for x in "${arches[@]}" + [[ x64 = \a\a\6\4 ]] + for x in "${arches[@]}" + [[ x64 = \i\a\3\2 ]] + for x in "${arches[@]}" + [[ x64 = \x\6\4 ]] + return 0 ++ id -un + USERNAME=mockbuild + local socket= + grep -q ID=fedora /etc/os-release + [[ 9 -ge 7 ]] + which rpm-sign + [[ -n '' ]] + /usr/bin/pesign --certdir /etc/pki/pesign -t 'NSS Certificate DB' -c 'MSVSphere Secure Boot Signing' -s -i pesign-test-app-unsigned.0.efi -o pesign-test-app-signed.efi + [[ 2 -eq 2 ]] + error_on_empty pesign-test-app-signed.efi + local f=pesign-test-app-signed.efi + [[ ! -s pesign-test-app-signed.efi ]] + RPM_EC=0 ++ jobs -p + exit 0 Executing(%install): /bin/sh -e /var/tmp/rpm-tmp.B5foTp + umask 022 + cd /builddir/build/BUILD + '[' /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64 '!=' / ']' + rm -rf /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64 ++ dirname /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64 + mkdir -p /builddir/build/BUILDROOT + mkdir /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64 + cd pesign-test-app-5 + rm -rf /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64 + mkdir -p /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64//usr/lib64 + make LIBDIR=/usr/lib64 INSTALLROOT=/builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64 DATADIR=/usr/share install install -D -d -m 0755 /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64//usr/share/pesign-test-app-5 install -m 0644 pesign-test-app.efi /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64//usr/share/pesign-test-app-5/pesign-test-app.efi + mv pesign-test-app-signed.efi /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64//usr/share/pesign-test-app-5/ + /usr/lib/rpm/check-buildroot + /usr/lib/rpm/redhat/brp-ldconfig + /usr/lib/rpm/brp-compress + /usr/lib/rpm/brp-strip /usr/bin/strip + /usr/lib/rpm/brp-strip-comment-note /usr/bin/strip /usr/bin/objdump + /usr/lib/rpm/redhat/brp-strip-lto /usr/bin/strip + /usr/lib/rpm/brp-strip-static-archive /usr/bin/strip + /usr/lib/rpm/redhat/brp-python-bytecompile '' 1 0 + /usr/lib/rpm/brp-python-hardlink + /usr/lib/rpm/redhat/brp-mangle-shebangs Executing(%check): /bin/sh -e /var/tmp/rpm-tmp.1WrA10 + umask 022 + cd /builddir/build/BUILD + cd pesign-test-app-5 + for x in /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64//usr/share/pesign-test-app-5/pesign-test-app-signed.* + pesign -l -i /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64//usr/share/pesign-test-app-5/pesign-test-app-signed.efi --------------------------------------------- certificate address is 0x7ffff76b46c8 Content was not encrypted. Content is detached; signature cannot be verified. The signer's common name is MSVSphere Secure Boot Signing The signer's email address is security@msvsphere.ru Signing time: Mon Mar 27, 2023 There were certs or crls included. --------------------------------------------- + pesign -l -i /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64//usr/share/pesign-test-app-5/pesign-test-app-signed.efi ++ date '+%a %b %d, %Y' + grep -c -q '^Signing time: Mon Mar 27, 2023$' + pesign -l -i /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64//usr/share/pesign-test-app-5/pesign-test-app-signed.efi + grep -c -q '^The signer.s common name is MSVSphere Secure Boot Signing$' + RPM_EC=0 ++ jobs -p + exit 0 Processing files: pesign-test-app-5-28.el9.inferit.x86_64 Executing(%doc): /bin/sh -e /var/tmp/rpm-tmp.dF2MxQ + umask 022 + cd /builddir/build/BUILD + cd pesign-test-app-5 + DOCDIR=/builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64/usr/share/doc/pesign-test-app + export LC_ALL=C + LC_ALL=C + export DOCDIR + /usr/bin/mkdir -p /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64/usr/share/doc/pesign-test-app + cp -pr README /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64/usr/share/doc/pesign-test-app + cp -pr COPYING /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64/usr/share/doc/pesign-test-app + RPM_EC=0 ++ jobs -p + exit 0 Provides: pesign-test-app = 5-28.el9.inferit pesign-test-app(x86-64) = 5-28.el9.inferit Requires(rpmlib): rpmlib(CompressedFileNames) <= 3.0.4-1 rpmlib(FileDigests) <= 4.6.0-1 rpmlib(PayloadFilesHavePrefix) <= 4.0-1 Checking for unpackaged file(s): /usr/lib/rpm/check-files /builddir/build/BUILDROOT/pesign-test-app-5-28.el9.inferit.x86_64 Wrote: /builddir/build/RPMS/pesign-test-app-5-28.el9.inferit.x86_64.rpm Child return code was: 0