[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
** Changed in: shim-signed (Ubuntu Cosmic) Status: Triaged => Won't Fix ** Changed in: shim-signed (Ubuntu Bionic) Status: Triaged => Fix Released ** Changed in: linux-signed (Ubuntu Cosmic) Status: Triaged => Won't Fix ** Changed in: linux-meta (Ubuntu Cosmic) Status: Triaged => Won't Fix ** Changed in: linux (Ubuntu Cosmic) Status: Triaged => Won't Fix ** Changed in: linux-signed (Ubuntu Bionic) Status: Triaged => Won't Fix ** Changed in: linux (Ubuntu Bionic) Status: Triaged => Won't Fix ** Changed in: linux-meta (Ubuntu Bionic) Status: Triaged => Won't Fix ** Changed in: linux-signed-hwe-edge (Ubuntu) Status: New => Fix Released ** Changed in: linux-meta (Ubuntu) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1804481 Title: SecureBoot support for arm64 Status in linux package in Ubuntu: Fix Released Status in linux-meta package in Ubuntu: Fix Released Status in linux-signed package in Ubuntu: Fix Released Status in linux-signed-hwe package in Ubuntu: Invalid Status in linux-signed-hwe-edge package in Ubuntu: Fix Released Status in shim package in Ubuntu: Fix Released Status in shim-signed package in Ubuntu: Fix Released Status in linux source package in Bionic: Won't Fix Status in linux-meta source package in Bionic: Won't Fix Status in linux-signed source package in Bionic: Won't Fix Status in linux-signed-hwe source package in Bionic: Fix Released Status in linux-signed-hwe-edge source package in Bionic: Fix Released Status in shim source package in Bionic: Fix Released Status in shim-signed source package in Bionic: Fix Released Status in linux source package in Cosmic: Won't Fix Status in linux-meta source package in Cosmic: Won't Fix Status in linux-signed source package in Cosmic: Won't Fix Status in linux-signed-hwe source package in Cosmic: Invalid Status in linux-signed-hwe-edge source package in Cosmic: Invalid Status in shim source package in Cosmic: Fix Released Status in shim-signed source package in Cosmic: Won't Fix Status in linux source package in Disco: Fix Released Status in linux-meta source package in Disco: Won't Fix Status in linux-signed source package in Disco: Fix Released Status in linux-signed-hwe source package in Disco: Invalid Status in linux-signed-hwe-edge source package in Disco: Invalid Status in shim source package in Disco: Fix Released Status in shim-signed source package in Disco: Fix Released Bug description: [Impact] Ubuntu does not currently support SecureBoot for UEFI systems on arm64 platforms. [Test Case] See: https://wiki.ubuntu.com/UEFI/SecureBoot/Testing [Fix] - Introduce shim-signed for arm64 - Introduce grub-signed for arm64 - Produce signed linux kernels [Regression Risk] We're enabling new signed packages - regressions would most likely fall into packaging issues. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1804481/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
** Changed in: linux-meta (Ubuntu Disco) Status: In Progress => Won't Fix -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1804481 Title: SecureBoot support for arm64 Status in linux package in Ubuntu: Fix Released Status in linux-meta package in Ubuntu: In Progress Status in linux-signed package in Ubuntu: Fix Released Status in linux-signed-hwe package in Ubuntu: Invalid Status in linux-signed-hwe-edge package in Ubuntu: New Status in shim package in Ubuntu: Fix Released Status in shim-signed package in Ubuntu: Fix Released Status in linux source package in Bionic: Triaged Status in linux-meta source package in Bionic: Triaged Status in linux-signed source package in Bionic: Triaged Status in linux-signed-hwe source package in Bionic: Fix Released Status in linux-signed-hwe-edge source package in Bionic: Fix Released Status in shim source package in Bionic: Fix Released Status in shim-signed source package in Bionic: Triaged Status in linux source package in Cosmic: Triaged Status in linux-meta source package in Cosmic: Triaged Status in linux-signed source package in Cosmic: Triaged Status in linux-signed-hwe source package in Cosmic: Invalid Status in linux-signed-hwe-edge source package in Cosmic: Invalid Status in shim source package in Cosmic: Fix Released Status in shim-signed source package in Cosmic: Triaged Status in linux source package in Disco: Fix Released Status in linux-meta source package in Disco: Won't Fix Status in linux-signed source package in Disco: Fix Released Status in linux-signed-hwe source package in Disco: Invalid Status in linux-signed-hwe-edge source package in Disco: Invalid Status in shim source package in Disco: Fix Released Status in shim-signed source package in Disco: Fix Released Bug description: [Impact] Ubuntu does not currently support SecureBoot for UEFI systems on arm64 platforms. [Test Case] See: https://wiki.ubuntu.com/UEFI/SecureBoot/Testing [Fix] - Introduce shim-signed for arm64 - Introduce grub-signed for arm64 - Produce signed linux kernels [Regression Risk] We're enabling new signed packages - regressions would most likely fall into packaging issues. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1804481/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
This bug was fixed in the package linux-signed-hwe - 4.18.0-21.22~18.04.1 --- linux-signed-hwe (4.18.0-21.22~18.04.1) bionic; urgency=medium * Master version: 4.18.0-21.22~18.04.1 * Built-Using incorrect (LP: #1824016) - Rename "VERSION" template string to more precise "UNSIGNED_SRC_VERSION" - Use the correct source package name in Built-Using field linux-signed-hwe (4.18.0-20.21~18.04.1+signed1) bionic; urgency=medium * SecureBoot support for arm64 (LP: #1804481) - support recompression of signed kernels -- Stefan Bader Thu, 16 May 2019 16:52:10 +0200 ** Changed in: linux-signed-hwe (Ubuntu Bionic) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1804481 Title: SecureBoot support for arm64 Status in linux package in Ubuntu: Fix Released Status in linux-meta package in Ubuntu: In Progress Status in linux-signed package in Ubuntu: Fix Released Status in linux-signed-hwe package in Ubuntu: Invalid Status in linux-signed-hwe-edge package in Ubuntu: New Status in shim package in Ubuntu: Fix Released Status in shim-signed package in Ubuntu: Fix Released Status in linux source package in Bionic: Triaged Status in linux-meta source package in Bionic: Triaged Status in linux-signed source package in Bionic: Triaged Status in linux-signed-hwe source package in Bionic: Fix Released Status in linux-signed-hwe-edge source package in Bionic: Fix Released Status in shim source package in Bionic: Fix Released Status in shim-signed source package in Bionic: Triaged Status in linux source package in Cosmic: Triaged Status in linux-meta source package in Cosmic: Triaged Status in linux-signed source package in Cosmic: Triaged Status in linux-signed-hwe source package in Cosmic: Invalid Status in linux-signed-hwe-edge source package in Cosmic: Invalid Status in shim source package in Cosmic: Fix Released Status in shim-signed source package in Cosmic: Triaged Status in linux source package in Disco: Fix Released Status in linux-meta source package in Disco: In Progress Status in linux-signed source package in Disco: Fix Released Status in linux-signed-hwe source package in Disco: Invalid Status in linux-signed-hwe-edge source package in Disco: Invalid Status in shim source package in Disco: Fix Released Status in shim-signed source package in Disco: Fix Released Bug description: [Impact] Ubuntu does not currently support SecureBoot for UEFI systems on arm64 platforms. [Test Case] See: https://wiki.ubuntu.com/UEFI/SecureBoot/Testing [Fix] - Introduce shim-signed for arm64 - Introduce grub-signed for arm64 - Produce signed linux kernels [Regression Risk] We're enabling new signed packages - regressions would most likely fall into packaging issues. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1804481/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
This bug was fixed in the package linux-signed-hwe-edge - 5.0.0-15.16~18.04.1+signed1 --- linux-signed-hwe-edge (5.0.0-15.16~18.04.1+signed1) bionic; urgency=medium * SecureBoot support for arm64 (LP: #1804481) - support recompression of signed kernels -- Stefan Bader Tue, 14 May 2019 13:49:08 +0200 ** Changed in: linux-signed-hwe-edge (Ubuntu Bionic) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1804481 Title: SecureBoot support for arm64 Status in linux package in Ubuntu: Fix Released Status in linux-meta package in Ubuntu: In Progress Status in linux-signed package in Ubuntu: Fix Released Status in linux-signed-hwe package in Ubuntu: Invalid Status in linux-signed-hwe-edge package in Ubuntu: New Status in shim package in Ubuntu: Fix Released Status in shim-signed package in Ubuntu: Fix Released Status in linux source package in Bionic: Triaged Status in linux-meta source package in Bionic: Triaged Status in linux-signed source package in Bionic: Triaged Status in linux-signed-hwe source package in Bionic: Fix Committed Status in linux-signed-hwe-edge source package in Bionic: Fix Released Status in shim source package in Bionic: Fix Released Status in shim-signed source package in Bionic: Triaged Status in linux source package in Cosmic: Triaged Status in linux-meta source package in Cosmic: Triaged Status in linux-signed source package in Cosmic: Triaged Status in linux-signed-hwe source package in Cosmic: Invalid Status in linux-signed-hwe-edge source package in Cosmic: Invalid Status in shim source package in Cosmic: Fix Released Status in shim-signed source package in Cosmic: Triaged Status in linux source package in Disco: Fix Released Status in linux-meta source package in Disco: In Progress Status in linux-signed source package in Disco: Fix Released Status in linux-signed-hwe source package in Disco: Invalid Status in linux-signed-hwe-edge source package in Disco: Invalid Status in shim source package in Disco: Fix Released Status in shim-signed source package in Disco: Fix Released Bug description: [Impact] Ubuntu does not currently support SecureBoot for UEFI systems on arm64 platforms. [Test Case] See: https://wiki.ubuntu.com/UEFI/SecureBoot/Testing [Fix] - Introduce shim-signed for arm64 - Introduce grub-signed for arm64 - Produce signed linux kernels [Regression Risk] We're enabling new signed packages - regressions would most likely fall into packaging issues. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1804481/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
** Changed in: linux-signed-hwe-edge (Ubuntu Bionic) Status: In Progress => Fix Committed ** Also affects: linux-signed-hwe (Ubuntu) Importance: Undecided Status: New ** Changed in: linux-signed-hwe (Ubuntu Cosmic) Status: New => Invalid ** Changed in: linux-signed-hwe (Ubuntu Disco) Status: New => Invalid ** Changed in: linux-signed-hwe (Ubuntu) Status: New => Invalid ** Changed in: linux-signed-hwe (Ubuntu Bionic) Importance: Undecided => Critical ** Changed in: linux-signed-hwe (Ubuntu Bionic) Status: New => Fix Committed -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1804481 Title: SecureBoot support for arm64 Status in linux package in Ubuntu: Fix Released Status in linux-meta package in Ubuntu: In Progress Status in linux-signed package in Ubuntu: Fix Released Status in linux-signed-hwe package in Ubuntu: Invalid Status in linux-signed-hwe-edge package in Ubuntu: New Status in shim package in Ubuntu: Fix Released Status in shim-signed package in Ubuntu: Fix Released Status in linux source package in Bionic: Triaged Status in linux-meta source package in Bionic: Triaged Status in linux-signed source package in Bionic: Triaged Status in linux-signed-hwe source package in Bionic: Fix Committed Status in linux-signed-hwe-edge source package in Bionic: Fix Committed Status in shim source package in Bionic: Fix Released Status in shim-signed source package in Bionic: Triaged Status in linux source package in Cosmic: Triaged Status in linux-meta source package in Cosmic: Triaged Status in linux-signed source package in Cosmic: Triaged Status in linux-signed-hwe source package in Cosmic: Invalid Status in linux-signed-hwe-edge source package in Cosmic: Invalid Status in shim source package in Cosmic: Fix Released Status in shim-signed source package in Cosmic: Triaged Status in linux source package in Disco: Fix Released Status in linux-meta source package in Disco: In Progress Status in linux-signed source package in Disco: Fix Released Status in linux-signed-hwe source package in Disco: Invalid Status in linux-signed-hwe-edge source package in Disco: Invalid Status in shim source package in Disco: Fix Released Status in shim-signed source package in Disco: Fix Released Bug description: [Impact] Ubuntu does not currently support SecureBoot for UEFI systems on arm64 platforms. [Test Case] See: https://wiki.ubuntu.com/UEFI/SecureBoot/Testing [Fix] - Introduce shim-signed for arm64 - Introduce grub-signed for arm64 - Produce signed linux kernels [Regression Risk] We're enabling new signed packages - regressions would most likely fall into packaging issues. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1804481/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
Marking critical, as this prevents X-Gene/uboot systems from booting ** Changed in: linux-signed-hwe-edge (Ubuntu Bionic) Assignee: (unassigned) => dann frazier (dannf) -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1804481 Title: SecureBoot support for arm64 Status in linux package in Ubuntu: Fix Released Status in linux-meta package in Ubuntu: In Progress Status in linux-signed package in Ubuntu: Fix Released Status in linux-signed-hwe-edge package in Ubuntu: New Status in shim package in Ubuntu: Fix Released Status in shim-signed package in Ubuntu: Fix Released Status in linux source package in Bionic: Triaged Status in linux-meta source package in Bionic: Triaged Status in linux-signed source package in Bionic: Triaged Status in linux-signed-hwe-edge source package in Bionic: In Progress Status in shim source package in Bionic: Fix Released Status in shim-signed source package in Bionic: Triaged Status in linux source package in Cosmic: Triaged Status in linux-meta source package in Cosmic: Triaged Status in linux-signed source package in Cosmic: Triaged Status in linux-signed-hwe-edge source package in Cosmic: Invalid Status in shim source package in Cosmic: Fix Released Status in shim-signed source package in Cosmic: Triaged Status in linux source package in Disco: Fix Released Status in linux-meta source package in Disco: In Progress Status in linux-signed source package in Disco: Fix Released Status in linux-signed-hwe-edge source package in Disco: Invalid Status in shim source package in Disco: Fix Released Status in shim-signed source package in Disco: Fix Released Bug description: [Impact] Ubuntu does not currently support SecureBoot for UEFI systems on arm64 platforms. [Test Case] See: https://wiki.ubuntu.com/UEFI/SecureBoot/Testing [Fix] - Introduce shim-signed for arm64 - Introduce grub-signed for arm64 - Produce signed linux kernels [Regression Risk] We're enabling new signed packages - regressions would most likely fall into packaging issues. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1804481/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
Marking critical, as this prevents X-Gene/uboot systems from booting ** Changed in: linux-signed-hwe-edge (Ubuntu Bionic) Importance: Undecided => Critical -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1804481 Title: SecureBoot support for arm64 Status in linux package in Ubuntu: Fix Released Status in linux-meta package in Ubuntu: In Progress Status in linux-signed package in Ubuntu: Fix Released Status in linux-signed-hwe-edge package in Ubuntu: New Status in shim package in Ubuntu: Fix Released Status in shim-signed package in Ubuntu: Fix Released Status in linux source package in Bionic: Triaged Status in linux-meta source package in Bionic: Triaged Status in linux-signed source package in Bionic: Triaged Status in linux-signed-hwe-edge source package in Bionic: In Progress Status in shim source package in Bionic: Fix Released Status in shim-signed source package in Bionic: Triaged Status in linux source package in Cosmic: Triaged Status in linux-meta source package in Cosmic: Triaged Status in linux-signed source package in Cosmic: Triaged Status in linux-signed-hwe-edge source package in Cosmic: Invalid Status in shim source package in Cosmic: Fix Released Status in shim-signed source package in Cosmic: Triaged Status in linux source package in Disco: Fix Released Status in linux-meta source package in Disco: In Progress Status in linux-signed source package in Disco: Fix Released Status in linux-signed-hwe-edge source package in Disco: Invalid Status in shim source package in Disco: Fix Released Status in shim-signed source package in Disco: Fix Released Bug description: [Impact] Ubuntu does not currently support SecureBoot for UEFI systems on arm64 platforms. [Test Case] See: https://wiki.ubuntu.com/UEFI/SecureBoot/Testing [Fix] - Introduce shim-signed for arm64 - Introduce grub-signed for arm64 - Produce signed linux kernels [Regression Risk] We're enabling new signed packages - regressions would most likely fall into packaging issues. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1804481/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
** Also affects: linux-signed-hwe-edge (Ubuntu) Importance: Undecided Status: New ** Changed in: linux-signed-hwe-edge (Ubuntu Cosmic) Status: New => Invalid ** Changed in: linux-signed-hwe-edge (Ubuntu Disco) Status: New => Invalid ** Changed in: linux-signed-hwe-edge (Ubuntu Bionic) Status: New => In Progress -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1804481 Title: SecureBoot support for arm64 Status in linux package in Ubuntu: Fix Released Status in linux-meta package in Ubuntu: In Progress Status in linux-signed package in Ubuntu: Fix Released Status in linux-signed-hwe-edge package in Ubuntu: New Status in shim package in Ubuntu: Fix Released Status in shim-signed package in Ubuntu: Fix Released Status in linux source package in Bionic: Triaged Status in linux-meta source package in Bionic: Triaged Status in linux-signed source package in Bionic: Triaged Status in linux-signed-hwe-edge source package in Bionic: In Progress Status in shim source package in Bionic: Fix Released Status in shim-signed source package in Bionic: Triaged Status in linux source package in Cosmic: Triaged Status in linux-meta source package in Cosmic: Triaged Status in linux-signed source package in Cosmic: Triaged Status in linux-signed-hwe-edge source package in Cosmic: Invalid Status in shim source package in Cosmic: Fix Released Status in shim-signed source package in Cosmic: Triaged Status in linux source package in Disco: Fix Released Status in linux-meta source package in Disco: In Progress Status in linux-signed source package in Disco: Fix Released Status in linux-signed-hwe-edge source package in Disco: Invalid Status in shim source package in Disco: Fix Released Status in shim-signed source package in Disco: Fix Released Bug description: [Impact] Ubuntu does not currently support SecureBoot for UEFI systems on arm64 platforms. [Test Case] See: https://wiki.ubuntu.com/UEFI/SecureBoot/Testing [Fix] - Introduce shim-signed for arm64 - Introduce grub-signed for arm64 - Produce signed linux kernels [Regression Risk] We're enabling new signed packages - regressions would most likely fall into packaging issues. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1804481/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
This bug was fixed in the package linux-signed - 4.19.0-13.14 --- linux-signed (4.19.0-13.14) disco; urgency=medium * Master version: 4.19.0-13.14 * SecureBoot support for arm64 (LP: #1804481) - support recompression of signed kernels - Add support for arm64 * Miscellaneous Ubuntu changes - [Packaging] download-signed -- fix downloader component and handle versions correctly - Add missing dbgsym package for snapdragon. -- Seth Forshee Thu, 07 Feb 2019 15:34:50 -0600 ** Changed in: linux-signed (Ubuntu Disco) Status: Fix Committed => Fix Released ** Changed in: linux (Ubuntu Disco) Status: Fix Committed => Fix Released ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-16880 -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-meta in Ubuntu. https://bugs.launchpad.net/bugs/1804481 Title: SecureBoot support for arm64 Status in linux package in Ubuntu: Fix Released Status in linux-meta package in Ubuntu: In Progress Status in linux-signed package in Ubuntu: Fix Released Status in shim package in Ubuntu: Fix Released Status in shim-signed package in Ubuntu: Fix Released Status in linux source package in Bionic: Triaged Status in linux-meta source package in Bionic: Triaged Status in linux-signed source package in Bionic: Triaged Status in shim source package in Bionic: Fix Released Status in shim-signed source package in Bionic: Triaged Status in linux source package in Cosmic: Triaged Status in linux-meta source package in Cosmic: Triaged Status in linux-signed source package in Cosmic: Triaged Status in shim source package in Cosmic: Fix Released Status in shim-signed source package in Cosmic: Triaged Status in linux source package in Disco: Fix Released Status in linux-meta source package in Disco: In Progress Status in linux-signed source package in Disco: Fix Released Status in shim source package in Disco: Fix Released Status in shim-signed source package in Disco: Fix Released Bug description: [Impact] Ubuntu does not currently support SecureBoot for UEFI systems on arm64 platforms. [Test Case] See: https://wiki.ubuntu.com/UEFI/SecureBoot/Testing [Fix] - Introduce shim-signed for arm64 - Introduce grub-signed for arm64 - Produce signed linux kernels [Regression Risk] We're enabling new signed packages - regressions would most likely fall into packaging issues. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1804481/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
This bug was fixed in the package linux - 4.19.0-13.14 --- linux (4.19.0-13.14) disco; urgency=medium * linux: 4.19.0-13.14 -proposed tracker (LP: #1815103) * linux-buildinfo: pull out ABI information into its own package (LP: #1806380) - [Packaging] autoreconstruct -- base tag is always primary mainline version * [Packaging] Allow overlay of config annotations (LP: #1752072) - [Packaging] config-check: Add an include directive * Disco update: 4.19.20 upstream stable release (LP: #1815090) - Fix "net: ipv4: do not handle duplicate fragments as overlapping" - drm/msm/gpu: fix building without debugfs - ipv6: Consider sk_bound_dev_if when binding a socket to an address - ipv6: sr: clear IP6CB(skb) on SRH ip4ip6 encapsulation - ipvlan, l3mdev: fix broken l3s mode wrt local routes - l2tp: copy 4 more bytes to linear part if necessary - l2tp: fix reading optional fields of L2TPv3 - net: ip_gre: always reports o_key to userspace - net: ip_gre: use erspan key field for tunnel lookup - net/mlx4_core: Add masking for a few queries on HCA caps - netrom: switch to sock timer API - net/rose: fix NULL ax25_cb kernel panic - net: set default network namespace in init_dummy_netdev() - ravb: expand rx descriptor data to accommodate hw checksum - sctp: improve the events for sctp stream reset - tun: move the call to tun_set_real_num_queues - ucc_geth: Reset BQL queue when stopping device - net: ip6_gre: always reports o_key to userspace - sctp: improve the events for sctp stream adding - net/mlx5e: Allow MAC invalidation while spoofchk is ON - ip6mr: Fix notifiers call on mroute_clean_tables() - Revert "net/mlx5e: E-Switch, Initialize eswitch only if eswitch manager" - sctp: set chunk transport correctly when it's a new asoc - sctp: set flow sport from saddr only when it's 0 - virtio_net: Don't enable NAPI when interface is down - virtio_net: Don't call free_old_xmit_skbs for xdp_frames - virtio_net: Fix not restoring real_num_rx_queues - virtio_net: Fix out of bounds access of sq - virtio_net: Don't process redirected XDP frames when XDP is disabled - virtio_net: Use xdp_return_frame to free xdp_frames on destroying vqs - virtio_net: Differentiate sk_buff and xdp_frame on freeing - CIFS: Do not count -ENODATA as failure for query directory - CIFS: Fix trace command logging for SMB2 reads and writes - CIFS: Do not consider -ENODATA as stat failure for reads - fs/dcache: Fix incorrect nr_dentry_unused accounting in shrink_dcache_sb() - iommu/vt-d: Fix memory leak in intel_iommu_put_resv_regions() - selftests/seccomp: Enhance per-arch ptrace syscall skip tests - NFS: Fix up return value on fatal errors in nfs_page_async_flush() - ARM: cns3xxx: Fix writing to wrong PCI config registers after alignment - arm64: kaslr: ensure randomized quantities are clean also when kaslr is off - arm64: Do not issue IPIs for user executable ptes - arm64: hyp-stub: Forbid kprobing of the hyp-stub - arm64: hibernate: Clean the __hyp_text to PoC after resume - gpio: altera-a10sr: Set proper output level for direction_output - gpiolib: fix line event timestamps for nested irqs - gpio: pcf857x: Fix interrupts on multiple instances - gpio: sprd: Fix the incorrect data register - gpio: sprd: Fix incorrect irq type setting for the async EIC - gfs2: Revert "Fix loop in gfs2_rbm_find" - mmc: bcm2835: Fix DMA channel leak on probe error - mmc: mediatek: fix incorrect register setting of hs400_cmd_int_delay - ALSA: usb-audio: Add Opus #3 to quirks for native DSD support - ALSA: hda/realtek - Fixed hp_pin no value - IB/hfi1: Remove overly conservative VM_EXEC flag check - platform/x86: asus-nb-wmi: Map 0x35 to KEY_SCREENLOCK - platform/x86: asus-nb-wmi: Drop mapping of 0x33 and 0x34 scan codes - mmc: sdhci-iproc: handle mmc_of_parse() errors during probe - Btrfs: fix deadlock when allocating tree block during leaf/node split - btrfs: On error always free subvol_name in btrfs_mount - kernel/exit.c: release ptraced tasks before zap_pid_ns_processes - mm/hugetlb.c: teach follow_hugetlb_page() to handle FOLL_NOWAIT - oom, oom_reaper: do not enqueue same task twice - mm,memory_hotplug: fix scan_movable_pages() for gigantic hugepages - mm, oom: fix use-after-free in oom_kill_process - mm: hwpoison: use do_send_sig_info() instead of force_sig() - mm: migrate: don't rely on __PageMovable() of newpage after unlocking it - of: Convert to using %pOFn instead of device_node.name - of: overlay: add tests to validate kfrees from overlay removal - of: overlay: add missing of_node_get() in __of_attach_node_sysfs - of: overlay: use prop add changeset entry for property in new nodes - of: overlay: do not duplicate properties from overlay for new nodes -
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
These changes were committed after 4.19.0-12.13 ** Changed in: linux-signed (Ubuntu Disco) Status: Fix Released => Fix Committed ** Changed in: linux (Ubuntu Disco) Status: Fix Released => Fix Committed -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-meta in Ubuntu. https://bugs.launchpad.net/bugs/1804481 Title: SecureBoot support for arm64 Status in linux package in Ubuntu: Fix Committed Status in linux-meta package in Ubuntu: In Progress Status in linux-signed package in Ubuntu: Fix Committed Status in shim package in Ubuntu: Fix Released Status in shim-signed package in Ubuntu: Fix Released Status in linux source package in Bionic: Triaged Status in linux-meta source package in Bionic: Triaged Status in linux-signed source package in Bionic: Triaged Status in shim source package in Bionic: Fix Released Status in shim-signed source package in Bionic: Triaged Status in linux source package in Cosmic: Triaged Status in linux-meta source package in Cosmic: Triaged Status in linux-signed source package in Cosmic: Triaged Status in shim source package in Cosmic: Fix Released Status in shim-signed source package in Cosmic: Triaged Status in linux source package in Disco: Fix Committed Status in linux-meta source package in Disco: In Progress Status in linux-signed source package in Disco: Fix Committed Status in shim source package in Disco: Fix Released Status in shim-signed source package in Disco: Fix Released Bug description: [Impact] Ubuntu does not currently support SecureBoot for UEFI systems on arm64 platforms. [Test Case] See: https://wiki.ubuntu.com/UEFI/SecureBoot/Testing [Fix] - Introduce shim-signed for arm64 - Introduce grub-signed for arm64 - Produce signed linux kernels [Regression Risk] We're enabling new signed packages - regressions would most likely fall into packaging issues. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1804481/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
This bug was fixed in the package linux-signed - 4.19.0-12.13 --- linux-signed (4.19.0-12.13) disco; urgency=medium * Master version: 4.19.0-12.13 -- Seth Forshee Mon, 28 Jan 2019 15:40:56 -0600 ** Changed in: linux-signed (Ubuntu Disco) Status: Fix Committed => Fix Released ** Changed in: linux (Ubuntu Disco) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-meta in Ubuntu. https://bugs.launchpad.net/bugs/1804481 Title: SecureBoot support for arm64 Status in linux package in Ubuntu: Fix Released Status in linux-meta package in Ubuntu: In Progress Status in linux-signed package in Ubuntu: Fix Released Status in shim package in Ubuntu: Fix Released Status in shim-signed package in Ubuntu: Fix Released Status in linux source package in Bionic: Triaged Status in linux-meta source package in Bionic: Triaged Status in linux-signed source package in Bionic: Triaged Status in shim source package in Bionic: Fix Released Status in shim-signed source package in Bionic: Triaged Status in linux source package in Cosmic: Triaged Status in linux-meta source package in Cosmic: Triaged Status in linux-signed source package in Cosmic: Triaged Status in shim source package in Cosmic: Fix Released Status in shim-signed source package in Cosmic: Triaged Status in linux source package in Disco: Fix Released Status in linux-meta source package in Disco: In Progress Status in linux-signed source package in Disco: Fix Released Status in shim source package in Disco: Fix Released Status in shim-signed source package in Disco: Fix Released Bug description: [Impact] Ubuntu does not currently support SecureBoot for UEFI systems on arm64 platforms. [Test Case] See: https://wiki.ubuntu.com/UEFI/SecureBoot/Testing [Fix] - Introduce shim-signed for arm64 - Introduce grub-signed for arm64 - Produce signed linux kernels [Regression Risk] We're enabling new signed packages - regressions would most likely fall into packaging issues. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1804481/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
This bug was fixed in the package linux - 4.19.0-12.13 --- linux (4.19.0-12.13) disco; urgency=medium * linux: 4.19.0-12.13 -proposed tracker (LP: #1813664) * kernel oops in bcache module (LP: #1793901) - SAUCE: bcache: never writeback a discard operation * Disco update: 4.19.18 upstream stable release (LP: #1813611) - ipv6: Consider sk_bound_dev_if when binding a socket to a v4 mapped address - mlxsw: spectrum: Disable lag port TX before removing it - mlxsw: spectrum_switchdev: Set PVID correctly during VLAN deletion - net: dsa: mv88x6xxx: mv88e6390 errata - net, skbuff: do not prefer skb allocation fails early - qmi_wwan: add MTU default to qmap network interface - ipv6: Take rcu_read_lock in __inet6_bind for mapped addresses - net: clear skb->tstamp in bridge forwarding path - netfilter: ipset: Allow matching on destination MAC address for mac and ipmac sets - gpio: pl061: Move irq_chip definition inside struct pl061 - drm/amd/display: Guard against null stream_state in set_crc_source - drm/amdkfd: fix interrupt spin lock - ixgbe: allow IPsec Tx offload in VEPA mode - platform/x86: asus-wmi: Tell the EC the OS will handle the display off hotkey - e1000e: allow non-monotonic SYSTIM readings - usb: typec: tcpm: Do not disconnect link for self powered devices - selftests/bpf: enable (uncomment) all tests in test_libbpf.sh - of: overlay: add missing of_node_put() after add new node to changeset - writeback: don't decrement wb->refcnt if !wb->bdi - serial: set suppress_bind_attrs flag only if builtin - bpf: Allow narrow loads with offset > 0 - ALSA: oxfw: add support for APOGEE duet FireWire - x86/mce: Fix -Wmissing-prototypes warnings - MIPS: SiByte: Enable swiotlb for SWARM, LittleSur and BigSur - crypto: ecc - regularize scalar for scalar multiplication - arm64: perf: set suppress_bind_attrs flag to true - drm/atomic-helper: Complete fake_commit->flip_done potentially earlier - clk: meson: meson8b: fix incorrect divider mapping in cpu_scale_table - samples: bpf: fix: error handling regarding kprobe_events - usb: gadget: udc: renesas_usb3: add a safety connection way for forced_b_device - fpga: altera-cvp: fix probing for multiple FPGAs on the bus - selinux: always allow mounting submounts - ASoC: pcm3168a: Don't disable pcm3168a when CONFIG_PM defined - scsi: qedi: Check for session online before getting iSCSI TLV data. - drm/amdgpu: Reorder uvd ring init before uvd resume - rxe: IB_WR_REG_MR does not capture MR's iova field - efi/libstub: Disable some warnings for x86{,_64} - jffs2: Fix use of uninitialized delayed_work, lockdep breakage - clk: imx: make mux parent strings const - pstore/ram: Do not treat empty buffers as valid - media: uvcvideo: Refactor teardown of uvc on USB disconnect - powerpc/xmon: Fix invocation inside lock region - powerpc/pseries/cpuidle: Fix preempt warning - media: firewire: Fix app_info parameter type in avc_ca{,_app}_info - ASoC: use dma_ops of parent device for acp_audio_dma - media: venus: core: Set dma maximum segment size - staging: erofs: fix use-after-free of on-stack `z_erofs_vle_unzip_io' - net: call sk_dst_reset when set SO_DONTROUTE - scsi: target: use consistent left-aligned ASCII INQUIRY data - scsi: target/core: Make sure that target_wait_for_sess_cmds() waits long enough - selftests: do not macro-expand failed assertion expressions - arm64: kasan: Increase stack size for KASAN_EXTRA - clk: imx6q: reset exclusive gates on init - arm64: Fix minor issues with the dcache_by_line_op macro - bpf: relax verifier restriction on BPF_MOV | BPF_ALU - kconfig: fix file name and line number of warn_ignored_character() - kconfig: fix memory leak when EOF is encountered in quotation - mmc: atmel-mci: do not assume idle after atmci_request_end - btrfs: volumes: Make sure there is no overlap of dev extents at mount time - btrfs: alloc_chunk: fix more DUP stripe size handling - btrfs: fix use-after-free due to race between replace start and cancel - btrfs: improve error handling of btrfs_add_link - tty/serial: do not free trasnmit buffer page under port lock - perf intel-pt: Fix error with config term "pt=0" - perf tests ARM: Disable breakpoint tests 32-bit - perf svghelper: Fix unchecked usage of strncpy() - perf parse-events: Fix unchecked usage of strncpy() - perf vendor events intel: Fix Load_Miss_Real_Latency on SKL/SKX - netfilter: ipt_CLUSTERIP: check MAC address when duplicate config is set - netfilter: ipt_CLUSTERIP: remove wrong WARN_ON_ONCE in netns exit routine - netfilter: ipt_CLUSTERIP: fix deadlock in netns exit routine - x86/topology: Use total_cpus for max logical packages calculation - dm crypt: use u64 instead of sector_t t
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
** Changed in: linux (Ubuntu Disco) Status: In Progress => Fix Committed ** Changed in: linux-signed (Ubuntu Disco) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-meta in Ubuntu. https://bugs.launchpad.net/bugs/1804481 Title: SecureBoot support for arm64 Status in linux package in Ubuntu: Fix Committed Status in linux-meta package in Ubuntu: In Progress Status in linux-signed package in Ubuntu: Fix Committed Status in shim package in Ubuntu: Fix Released Status in shim-signed package in Ubuntu: Fix Released Status in linux source package in Bionic: Triaged Status in linux-meta source package in Bionic: Triaged Status in linux-signed source package in Bionic: Triaged Status in shim source package in Bionic: Fix Released Status in shim-signed source package in Bionic: Triaged Status in linux source package in Cosmic: Triaged Status in linux-meta source package in Cosmic: Triaged Status in linux-signed source package in Cosmic: Triaged Status in shim source package in Cosmic: Fix Released Status in shim-signed source package in Cosmic: Triaged Status in linux source package in Disco: Fix Committed Status in linux-meta source package in Disco: In Progress Status in linux-signed source package in Disco: Fix Committed Status in shim source package in Disco: Fix Released Status in shim-signed source package in Disco: Fix Released Bug description: [Impact] Ubuntu does not currently support SecureBoot for UEFI systems on arm64 platforms. [Test Case] See: https://wiki.ubuntu.com/UEFI/SecureBoot/Testing [Fix] - Introduce shim-signed for arm64 - Introduce grub-signed for arm64 - Produce signed linux kernels [Regression Risk] We're enabling new signed packages - regressions would most likely fall into packaging issues. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1804481/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp
[Kernel-packages] [Bug 1804481] Re: SecureBoot support for arm64
** Also affects: linux-signed (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-meta (Ubuntu) Importance: Undecided Status: New ** Also affects: shim-signed (Ubuntu) Importance: Undecided Status: New ** Also affects: shim (Ubuntu) Importance: Undecided Status: New ** Also affects: linux-meta (Ubuntu Disco) Importance: Undecided Status: New ** Also affects: linux (Ubuntu Disco) Importance: Undecided Status: Incomplete ** Also affects: shim (Ubuntu Disco) Importance: Undecided Status: New ** Also affects: linux-signed (Ubuntu Disco) Importance: Undecided Status: New ** Also affects: shim-signed (Ubuntu Disco) Importance: Undecided Status: New ** Also affects: linux-meta (Ubuntu Cosmic) Importance: Undecided Status: New ** Also affects: linux (Ubuntu Cosmic) Importance: Undecided Status: New ** Also affects: shim (Ubuntu Cosmic) Importance: Undecided Status: New ** Also affects: linux-signed (Ubuntu Cosmic) Importance: Undecided Status: New ** Also affects: shim-signed (Ubuntu Cosmic) Importance: Undecided Status: New ** Also affects: linux-meta (Ubuntu Bionic) Importance: Undecided Status: New ** Also affects: linux (Ubuntu Bionic) Importance: Undecided Status: New ** Also affects: shim (Ubuntu Bionic) Importance: Undecided Status: New ** Also affects: linux-signed (Ubuntu Bionic) Importance: Undecided Status: New ** Also affects: shim-signed (Ubuntu Bionic) Importance: Undecided Status: New ** Changed in: shim (Ubuntu Disco) Status: New => Fix Released ** Changed in: shim-signed (Ubuntu Disco) Status: New => Fix Released ** Changed in: shim (Ubuntu Cosmic) Status: New => Fix Released ** Changed in: shim (Ubuntu Bionic) Status: New => Fix Released ** Changed in: linux (Ubuntu Disco) Status: Incomplete => In Progress ** Changed in: linux (Ubuntu Disco) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: linux (Ubuntu Bionic) Status: New => Triaged ** Changed in: linux (Ubuntu Bionic) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: linux (Ubuntu Cosmic) Status: New => Triaged ** Changed in: linux (Ubuntu Cosmic) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: linux-meta (Ubuntu Bionic) Status: New => Triaged ** Changed in: linux-meta (Ubuntu Bionic) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: linux-meta (Ubuntu Cosmic) Status: New => Triaged ** Changed in: linux-meta (Ubuntu Cosmic) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: linux-meta (Ubuntu Disco) Status: New => In Progress ** Changed in: linux-meta (Ubuntu Disco) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: linux-signed (Ubuntu Bionic) Status: New => Triaged ** Changed in: linux-signed (Ubuntu Bionic) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: linux-signed (Ubuntu Cosmic) Status: New => Triaged ** Changed in: linux-signed (Ubuntu Cosmic) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: linux-signed (Ubuntu Disco) Status: New => In Progress ** Changed in: linux-signed (Ubuntu Disco) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: shim-signed (Ubuntu Bionic) Status: New => Triaged ** Changed in: shim-signed (Ubuntu Bionic) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: shim-signed (Ubuntu Cosmic) Status: New => Triaged ** Changed in: shim-signed (Ubuntu Cosmic) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: shim-signed (Ubuntu Disco) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: shim (Ubuntu Bionic) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: shim (Ubuntu Cosmic) Assignee: (unassigned) => dann frazier (dannf) ** Changed in: shim (Ubuntu Disco) Assignee: (unassigned) => dann frazier (dannf) -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-signed in Ubuntu. https://bugs.launchpad.net/bugs/1804481 Title: SecureBoot support for arm64 Status in linux package in Ubuntu: In Progress Status in linux-meta package in Ubuntu: In Progress Status in linux-signed package in Ubuntu: In Progress Status in shim package in Ubuntu: Fix Released Status in shim-signed package in Ubuntu: Fix Released Status in linux source package in Bionic: Triaged Status in linux-meta source package in Bionic: Triaged Status in linux-signed source package in Bionic: Triaged Status in shim source package in Bionic: Fix Released Status in shim-signed source package in Bionic: Triaged Status in linux source package in Cosmic: Triaged Status in linux-meta source package in Cosmic: Tr