On Wed, Jun 23, 2021 at 05:08:09AM +0000, Denis Osterland-Heim wrote:
> Am Dienstag, den 22.06.2021, 15:05 +0200 schrieb Marc Kleine-Budde:
> > On 6/22/21 6:36 AM, Denis Osterland-Heim wrote:
> > > Please have a look at 
> > > https://git.pengutronix.de/cgit/ptxdist/commit/?id=4b3be8225f389c7db0e2d665e8e600cb2cf52b91
> > >  .
> > > This should answer your question.
> >
> > Thanks.
> You're welcome.
> 
> >
> > However that doesn't work, as the proprietary I'm using refuses to work with
> > https_proxy="" and I don't want to add more binary patches to the lib.
> :-/
> 
> Maybe it would be an option to add a configuration switch to disable this 
> behavior.
> So your code-signing-provider may select this.
> 
> --- a/scripts/lib/ptxd_make_world_common.sh
> +++ b/scripts/lib/ptxd_make_world_common.sh
> @@ -397,7 +397,7 @@ ptxd_make_world_init() {
>      #
>      # try to prevent downloads outside the get stage
>      #
> -    if [ "${pkg_stage}" != "get" ]; then
> +    if [ "${pkg_stage}" != "get" ] && [ -z 
> "${PTXCONF_DISABLE_DOWNLOAD_CHECK}" ]; then
>         pkg_env="HTTPS_PROXY=- HTTP_PROXY=- https_proxy=- http_proxy=- 
> ${pkg_env}"
>      fi
> 
> Not sure if this is really works.

I'd like to avoid disabling this globally. Maybe something like this:

In the signing provider rules/pre makefile:

CODE_SIGNING_NETWORK_ACCESS := YES

In the packages that use it:

<PKG>_NETWORK_ACCESS := $(CODE_SIGNING_NETWORK_ACCESS)

Add it to ptx/env and then check for it in ptxd_make_world_init().

Michael

-- 
Pengutronix e.K.                           |                             |
Steuerwalder Str. 21                       | http://www.pengutronix.de/  |
31137 Hildesheim, Germany                  | Phone: +49-5121-206917-0    |
Amtsgericht Hildesheim, HRA 2686           | Fax:   +49-5121-206917-5555 |

_______________________________________________
ptxdist mailing list
[email protected]
To unsubscribe, send a mail with subject "unsubscribe" to 
[email protected]

Reply via email to