[Bug 1921134] Re: SBAT shim 15.4 release

2021-10-05 Thread Mathew Hodson
** Changed in: oem-priority Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1921134 Title: SBAT shim 15.4 release To manage notifications about this bug go

[Bug 1921134] Re: SBAT shim 15.4 release

2021-09-07 Thread Launchpad Bug Tracker
This bug was fixed in the package shim-signed - 1.37~18.04.10 --- shim-signed (1.37~18.04.10) bionic; urgency=medium * Remove unnecessary efitools dependency that prevented build on arm64 shim-signed (1.37~18.04.9) bionic; urgency=medium * New upstream release 15.4. LP:

[Bug 1921134] Re: SBAT shim 15.4 release

2021-09-06 Thread Julian Andres Klode
Actually, the previous comment was for bionic this time. 1.37~18.04.10 / 15.4-0ubuntu7. fwupd loading has been tested in the fwupd sbat test case ** Tags removed: verification-needed verification-needed-bionic ** Tags added: verification-done verification-done-bionic -- You received this bug

[Bug 1921134] Re: SBAT shim 15.4 release

2021-09-06 Thread Julian Andres Klode
Most tests from focal and newer are valid on xenial too, as the binaries are the same. I hence just verified the interaction with xenial's mokutil and kernel keyring: * Tested enrolling MOK and modprobing vboxdrv module * Tested timeout and reset, modprobe after reset failed to find the key, as

[Bug 1921134] Re: SBAT shim 15.4 release

2021-08-18 Thread Julian Andres Klode
** Tags removed: block-proposed-bionic ** Tags removed: block-proposed-groovy -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1921134 Title: SBAT shim 15.4 release To manage notifications about

[Bug 1921134] Re: SBAT shim 15.4 release

2021-08-16 Thread Launchpad Bug Tracker
This bug was fixed in the package shim-signed - 1.33.1~16.04.10 --- shim-signed (1.33.1~16.04.10) xenial; urgency=medium * Update to shim 15.4-0ubuntu7: - Fix load option parsing, and thus fwupd execution (LP: #1929471) (PR #379) - Fix occasional crashes in _relocate() on

[Bug 1921134] Re: SBAT shim 15.4 release

2021-08-03 Thread Yuan-Chen Cheng
** Changed in: oem-priority Assignee: Yuan-Chen Cheng (ycheng-twn) => (unassigned) ** Changed in: oem-priority Assignee: (unassigned) => Yuan-Chen Cheng (ycheng-twn) ** Changed in: oem-priority Importance: Critical => Medium ** Changed in: oem-priority Status: In Progress =>

[Bug 1921134] Re: SBAT shim 15.4 release

2021-08-02 Thread Launchpad Bug Tracker
This bug was fixed in the package shim-signed - 1.40.6 --- shim-signed (1.40.6) focal; urgency=medium * Update to shim 15.4-0ubuntu7: - Fix load option parsing, and thus fwupd execution (LP: #1929471) (PR #379) - Fix occasional crashes in _relocate() on arm64 (LP: #1928010)

[Bug 1921134] Re: SBAT shim 15.4 release

2021-07-26 Thread Julian Andres Klode
Most tests from focal and newer are valid on xenial too, as the binaries are the same. I hence just verified the interaction with xenial's mokutil and kernel keyring: * Tested enrolling MOK and modprobing vboxdrv module * Tested timeout and reset, modprobe after reset failed to find the key, as

[Bug 1921134] Re: SBAT shim 15.4 release

2021-07-26 Thread Julian Andres Klode
Verified the shim on focal. * xnox verified windows booting on hirsute, binaries are same * I verified maas style chained netbooting * Verified the interactions with mokutil + Verified loading dkms modules + Verified end2end IRL boot on ThinkPad X230 with ZFS - Did not verify actual Maas boot,

[Bug 1921134] Re: SBAT shim 15.4 release

2021-07-21 Thread Yuan-Chen Cheng
** Changed in: oem-priority Status: Confirmed => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1921134 Title: SBAT shim 15.4 release To manage notifications about this bug go

[Bug 1921134] Re: SBAT shim 15.4 release

2021-07-19 Thread Łukasz Zemczak
Hello Dimitri, or anyone else affected, Accepted shim-signed into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim- signed/1.33.1~16.04.10 in a few hours, and then in the -proposed repository. Please help us by testing this new package.

[Bug 1921134] Re: SBAT shim 15.4 release

2021-07-19 Thread Łukasz Zemczak
Hello Dimitri, or anyone else affected, Accepted shim-signed into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim- signed/1.37~18.04.9 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1921134] Re: SBAT shim 15.4 release

2021-07-07 Thread Julian Andres Klode
While that is true, we also discovered another regression yesterday which breaks booting on real hardware: In bug 1934780, we discovered that Mellanox BF1 SmartNic do not support querying variable storage info, and hence fail to boot. SUSE discovered similar issues. I don't think this is ready

[Bug 1921134] Re: SBAT shim 15.4 release

2021-07-06 Thread Steve Langasek
> It turns out that while there is no signed *fwupd* on xenial, there is a > signed *fwupdate*, so releasing this update would break firmware > updating after all :/ Not a blocker. fwupdate is obsolete, cannot be trivially migrated to fwupd (the SRU of fwupd-signed in bionic was quite painful),

[Bug 1921134] Re: SBAT shim 15.4 release

2021-07-05 Thread Julian Andres Klode
It turns out that while there is no signed *fwupd* on xenial, there is a signed *fwupdate*, so releasing this update would break firmware updating after all :/ ** Tags added: block-proposed-xenial -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed

[Bug 1921134] Re: SBAT shim 15.4 release

2021-07-03 Thread Harm van Bakel
I tried installing the new shim package on a second system that also had Oracle Virtualbox 6.1 installed and didn't encounter the same issue on this system. I then tried upgrading the first system again after first uninstalling Virtualbox. This time there were no issues after the upgrade. I then

[Bug 1921134] Re: SBAT shim 15.4 release

2021-06-29 Thread Julian Andres Klode
I don't see any relevant changes in the shim userspace bits in the focal update, and I can't speak to what Oracle does or does not do with their packages. Certainly trying to compile the modules and install them, setting up MOK, during boot like that is not going to work. -- You received this

[Bug 1921134] Re: SBAT shim 15.4 release

2021-06-28 Thread Harm van Bakel
After installing shim-15.4-0ubuntu5 and shim-signed-1.40.5+15.4-0ubuntu5 on focal and rebooting, I noticed my /var/log/syslog was being flooded with the following messages from vboxdrv.sh: Jun 28 21:33:52 ... vboxdrv.sh[7701]: Enter a password for Secure Boot. It will be asked again after a

[Bug 1921134] Re: SBAT shim 15.4 release

2021-06-28 Thread Julian Andres Klode
I had already checked the various chainbooting thingies for newer releases, and the binaries are the same, so for xenial, I have validated the mokutil integration and everything worked as expected with 1.33.1~16.04.9 ** Tags removed: verification-needed-xenial ** Tags added:

[Bug 1921134] Re: SBAT shim 15.4 release

2021-06-28 Thread Łukasz Zemczak
Hello Dimitri, or anyone else affected, Accepted shim-signed into focal-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim-signed/1.40.5 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1921134] Re: SBAT shim 15.4 release

2021-05-14 Thread Łukasz Zemczak
Hello Dimitri, or anyone else affected, Accepted shim-signed into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim- signed/1.33.1~16.04.7 in a few hours, and then in the -proposed repository. Please help us by testing this new package.

[Bug 1921134] Re: SBAT shim 15.4 release

2021-05-10 Thread Steve Langasek
This is a false-positive for the SRU due to the binary copy of shim 1.47 from impish to hirsute-proposed. It has already been fixed in hirsute release, there is no change here and no need for an SRU verification. ** Changed in: shim-signed (Ubuntu Hirsute) Status: Fix Committed => Fix

[Bug 1921134] Re: SBAT shim 15.4 release

2021-05-06 Thread Łukasz Zemczak
Hello Dimitri, or anyone else affected, Accepted shim-signed into hirsute-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim- signed/1.47 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1921134] Re: SBAT shim 15.4 release

2021-04-15 Thread Yuan-Chen Cheng
** Changed in: oem-priority Assignee: (unassigned) => Yuan-Chen Cheng (ycheng-twn) ** Changed in: oem-priority Status: New => Confirmed ** Changed in: oem-priority Importance: Undecided => Critical -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 1921134] Re: SBAT shim 15.4 release

2021-04-13 Thread Launchpad Bug Tracker
This bug was fixed in the package shim-signed - 1.46 --- shim-signed (1.46) hirsute; urgency=medium * New upstream release 15.4 LP: #1921134 * Ship fb & mm from shim-signed package. * Remove shim-canonical-unsigned dependency, now provided by shim itself. * Generalize

[Bug 1921134] Re: SBAT shim 15.4 release

2021-04-13 Thread Launchpad Bug Tracker
This bug was fixed in the package shim - 15.4-0ubuntu1 --- shim (15.4-0ubuntu1) hirsute; urgency=medium [ Dimitri John Ledkov ] * New upstream release 15.4 LP: #1921134 - Update the commit hash in debian/rules * debian/rules: add request to sign EFI binaries with archive

[Bug 1921134] Re: SBAT shim 15.4 release

2021-04-13 Thread Dimitri John Ledkov
** Tags removed: block-proposed-hirsute -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1921134 Title: SBAT shim 15.4 release To manage notifications about this bug go to:

[Bug 1921134] Re: SBAT shim 15.4 release

2021-04-13 Thread Dimitri John Ledkov
** Tags added: block-proposed-hirsute ** Tags added: block-proposed-bionic block-proposed-focal block- proposed-groovy block-proposed-xenial -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1921134

[Bug 1921134] Re: SBAT shim 15.4 release

2021-04-11 Thread Rex Tsai
** Tags added: oem-priority -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1921134 Title: SBAT shim 15.4 release To manage notifications about this bug go to:

[Bug 1921134] Re: SBAT shim 15.4 release

2021-04-02 Thread Steve Beattie
** Changed in: shim (Ubuntu) Status: New => Confirmed ** Changed in: shim-signed (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1921134 Title: SBAT

[Bug 1921134] Re: SBAT shim 15.4 release

2021-04-01 Thread Yuan-Chen Cheng
** Also affects: oem-priority Importance: Undecided Status: New ** Tags added: fwupd ** Tags added: sbat -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1921134 Title: SBAT shim 15.4

[Bug 1921134] Re: SBAT shim 15.4 release

2021-03-31 Thread Dimitri John Ledkov
** Summary changed: - SBAT shim 15.3 release + SBAT shim 15.4 release ** Description changed: [Impact] -  * New upstream shim release 15.3 +  * New upstream shim release 15.4  * It includes and enforces SBAT validation [Test Plan]  *