Bug#990158: marked as done (shim-signed-common: No UEFI boot with error "Could not create MokListXRT")

2021-06-23 Thread Debian Bug Tracking System
Your message dated Wed, 23 Jun 2021 19:17:07 +
with message-id 
and subject line Bug#990158: fixed in shim 15.4-6~deb10u1
has caused the Debian Bug report #990158,
regarding shim-signed-common: No UEFI boot with error "Could not create 
MokListXRT"
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
990158: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=990158
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: shim-signed-common
Version: 1.33+15+1533136590.3beb971-7
Severity: critical
Justification: breaks the whole system

Dear Maintainer,


## What led up to the situation?

Upgrade:

* shim-signed:amd64 (1.33+15+1533136590.3beb971-7,
1.36~1+deb10u1+15.4-5~deb10u1)
* shim-signed-common:amd64 (1.33+15+1533136590.3beb971-7,
1.36~1+deb10u1+15.4-5~deb10u1)

System: Dell T5600 with BIOS Revision A19


## What was the outcome of this action?

System is unbootable on booting via UEFI. System shows error message and then
powers off immediately:

"Could not create MokListXRT: Out of Resources
Something has gone seriously wrong: import_mok_state() failed: Out of
Resources"


## What outcome did you expect instead?

A normal booting system loading GRUB.


## Also reproducible with Debian Live-Installations-Image

On affected hardware like "Dell T5600" doing a UEFI boot from USB with …

* debian-live-10.10.0-amd64-standard.iso does *not* work.
* debian-live-10.9.0-amd64-standard.iso works.


## Related resources

Might be related to:

* https://bugzilla.suse.com/show_bug.cgi?id=1185261



-- System Information:
Debian Release: 10.10
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 5.10.0-0.bpo.7-amd64 (SMP w/32 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8), 
LANGUAGE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages shim-signed-common depends on:
ii  debconf [debconf-2.0]  1.5.71
ii  mokutil0.3.0+1538710437.fb6250f-1

shim-signed-common recommends no packages.

shim-signed-common suggests no packages.

-- debconf information:
  shim/title/secureboot:
  shim/error/secureboot_key_mismatch:
  shim/secureboot_explanation:
  shim/error/bad_secureboot_key:
  shim/disable_secureboot: true
  shim/enable_secureboot: false
--- End Message ---
--- Begin Message ---
Source: shim
Source-Version: 15.4-6~deb10u1
Done: Steve McIntyre <93...@debian.org>

We believe that the bug you reported is fixed in the latest version of
shim, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 990...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Steve McIntyre <93...@debian.org> (supplier of updated shim package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA256

Format: 1.8
Date: Wed, 23 Jun 2021 19:08:54 +0100
Source: shim
Architecture: source
Version: 15.4-6~deb10u1
Distribution: buster
Urgency: high
Maintainer: Debian EFI team 
Changed-By: Steve McIntyre <93...@debian.org>
Closes: 989962 990082 990158 990190
Changes:
 shim (15.4-6~deb10u1) buster; urgency=high
 .
   * Add arm64 patch to tweak section layout and stop crashing
 problems. Upstream issue #371. Closes: #990082, #990190
   * In insecure mode, don't abort if we can't create the MokListXRT
 variable. Upstream issue #372. Closes: #989962, #990158
Checksums-Sha1:
 155795ed71243e83b53341566d8ced9a6ff0ead0 2311 shim_15.4-6~deb10u1.dsc
 279f1c7b62a0eefa20e4f1119ab2e5c60f57576f 33940 
shim_15.4-6~deb10u1.debian.tar.xz
 efa14875336e625ee536eab6f0d7c126ca48efc1 6076 
shim_15.4-6~deb10u1_source.buildinfo
Checksums-Sha256:
 cafe7121920c06bb40c3430e64199e8239b8ca32abb051b8cb43dfbc4df8b58b 2311 
shim_15.4-6~deb10u1.dsc
 d7cdf5fb5081b67e90c193d13e979748e127d1441c3be27403482ae342b2f476 33940 
shim_15.4-6~deb10u1.debian.tar.xz
 68b72d7f7fbd299ddb422ed1e894483dc5a4229e124dea5887cac58c3774720c 6076 
shim_15.4-6~deb10u1_source.buildinfo
Files:
 74e7bc27ef0616638fa8401c96ea139f 2311 admin optional shim_15.4-6~deb10u1.dsc
 83ee03c3871fa207a898c615c19ea5b1 33940 admin optional 

Bug#990158: marked as done (shim-signed-common: No UEFI boot with error "Could not create MokListXRT")

2021-06-23 Thread Debian Bug Tracking System
Your message dated Wed, 23 Jun 2021 18:18:51 +
with message-id 
and subject line Bug#990158: fixed in shim 15.4-6
has caused the Debian Bug report #990158,
regarding shim-signed-common: No UEFI boot with error "Could not create 
MokListXRT"
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
990158: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=990158
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: shim-signed-common
Version: 1.33+15+1533136590.3beb971-7
Severity: critical
Justification: breaks the whole system

Dear Maintainer,


## What led up to the situation?

Upgrade:

* shim-signed:amd64 (1.33+15+1533136590.3beb971-7,
1.36~1+deb10u1+15.4-5~deb10u1)
* shim-signed-common:amd64 (1.33+15+1533136590.3beb971-7,
1.36~1+deb10u1+15.4-5~deb10u1)

System: Dell T5600 with BIOS Revision A19


## What was the outcome of this action?

System is unbootable on booting via UEFI. System shows error message and then
powers off immediately:

"Could not create MokListXRT: Out of Resources
Something has gone seriously wrong: import_mok_state() failed: Out of
Resources"


## What outcome did you expect instead?

A normal booting system loading GRUB.


## Also reproducible with Debian Live-Installations-Image

On affected hardware like "Dell T5600" doing a UEFI boot from USB with …

* debian-live-10.10.0-amd64-standard.iso does *not* work.
* debian-live-10.9.0-amd64-standard.iso works.


## Related resources

Might be related to:

* https://bugzilla.suse.com/show_bug.cgi?id=1185261



-- System Information:
Debian Release: 10.10
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 5.10.0-0.bpo.7-amd64 (SMP w/32 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8), 
LANGUAGE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages shim-signed-common depends on:
ii  debconf [debconf-2.0]  1.5.71
ii  mokutil0.3.0+1538710437.fb6250f-1

shim-signed-common recommends no packages.

shim-signed-common suggests no packages.

-- debconf information:
  shim/title/secureboot:
  shim/error/secureboot_key_mismatch:
  shim/secureboot_explanation:
  shim/error/bad_secureboot_key:
  shim/disable_secureboot: true
  shim/enable_secureboot: false
--- End Message ---
--- Begin Message ---
Source: shim
Source-Version: 15.4-6
Done: Steve McIntyre <93...@debian.org>

We believe that the bug you reported is fixed in the latest version of
shim, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 990...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Steve McIntyre <93...@debian.org> (supplier of updated shim package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA256

Format: 1.8
Date: Wed, 23 Jun 2021 19:03:54 +0100
Source: shim
Architecture: source
Version: 15.4-6
Distribution: unstable
Urgency: high
Maintainer: Debian EFI team 
Changed-By: Steve McIntyre <93...@debian.org>
Closes: 989962 990082 990158 990190
Changes:
 shim (15.4-6) unstable; urgency=high
 .
   * Add arm64 patch to tweak section layout and stop crashing
 problems. Upstream issue #371. Closes: #990082, #990190
   * In insecure mode, don't abort if we can't create the MokListXRT
 variable. Upstream issue #372. Closes: #989962, #990158
Checksums-Sha1:
 2112b70489b4660c77eeb63207f54628fd0c5c04 2300 shim_15.4-6.dsc
 a2242f538b3f7e826b8ee78ef8caa49a9e766643 33932 shim_15.4-6.debian.tar.xz
 0409d674a6becceb329de2e29f8561fdd0ea0fdd 6054 shim_15.4-6_source.buildinfo
Checksums-Sha256:
 0316b340550238a3fb4cbb2a2b2a736fc93ba46032732c1e683ee1db8831 2300 
shim_15.4-6.dsc
 624357f05fdbf212523d9adcc6c4f92c03b442b3fb76732576ab56c756d8834a 33932 
shim_15.4-6.debian.tar.xz
 dfb64efa1657ea734dc16cb07f9e497faa23cd11a58420e38bc62b21a38fefcf 6054 
shim_15.4-6_source.buildinfo
Files:
 55b09f08418b65e28a14bbb7a27bfbda 2300 admin optional shim_15.4-6.dsc
 99e10023060aea0b923d3f566b415554 33932 admin optional shim_15.4-6.debian.tar.xz
 e41eaf923d9217c0afc50ed5177ab2d3 6054 admin optional