[Bug 1936759] Re: shim-signed 1.48+15.4-0ubuntu5 does not secure boot

2021-07-21 Thread Julian Andres Klode
We discussed this a bit upstream and we believe this to be random, and not a regression in those later 15.4 updates. Apparently there is a buffer overflow in shim that makes it override memory of other EFI components, and depending on where that triggers, it can cause all sorts of random boot

[Bug 1936759] Re: shim-signed 1.48+15.4-0ubuntu5 does not secure boot

2021-07-20 Thread Jacques Williamson
The suggested v1.47 package worked! I did: wget https://launchpad.net/ubuntu/+source/shim-signed/1.47/+build/21482148/+files/shim-signed_1.47+15.4-0ubuntu2_amd64.deb sudo dpkg -i ./sudo dpkg -i ./shim-signed_1.47+15.4-0ubuntu2_amd64.deb ... followed by a reboot, worked! (Booted OK with secure

[Bug 1936759] Re: shim-signed 1.48+15.4-0ubuntu5 does not secure boot

2021-07-20 Thread Julian Andres Klode
If you could try the 1.47+15.4-0ubuntu2 binaries as well, that'd be great, you can find them via launchpad: https://launchpad.net/ubuntu/+source/shim-signed/1.47/+build/21482148 If this fails, the issue is one of the three patches in there -- You received this bug notification because you are

[Bug 1936759] Re: shim-signed 1.48+15.4-0ubuntu5 does not secure boot

2021-07-20 Thread Julian Andres Klode
** Changed in: shim-signed (Ubuntu) Status: Incomplete => New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1936759 Title: shim-signed 1.48+15.4-0ubuntu5 does not secure boot To manage

[Bug 1936759] Re: shim-signed 1.48+15.4-0ubuntu5 does not secure boot

2021-07-19 Thread Jacques Williamson
With shim-signed 1.48+15.4-0ubuntu5 installed and secure boot enabled, I also ran: $ sudo mokutil --set-verbosity true ... rebooted, and captured output in a video as requested. See here (attaching to this ticket failed):

[Bug 1936759] Re: shim-signed 1.48+15.4-0ubuntu5 does not secure boot

2021-07-19 Thread Jacques Williamson
$ sudo apt install shim-signed=1.50+15.4-0ubuntu7 ... from proposed packages, followed by a reboot with secure boot enabled has the same result, stuck on UEFI vendor firmware logo. Trying to capture additional logging for you next. -- You received this bug notification because you are a member

[Bug 1936759] Re: shim-signed 1.48+15.4-0ubuntu5 does not secure boot

2021-07-19 Thread Jacques Williamson
~guiverc - Please see above for the apport-collect output. ~juliank - I will try the proposed shim-signed 1.50+ as update shortly. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1936759 Title:

[Bug 1936759] Re: shim-signed 1.48+15.4-0ubuntu5 does not secure boot

2021-07-19 Thread Jacques Williamson
apport information ** Tags added: apport-collected hirsute wayland-session ** Description changed: shim-signed package installs with no error with apt upgrade, but then the system cannot boot afterwards with secure boot enabled. System hangs indefinitely on UEFI manufacturer logo screen

[Bug 1936759] Re: shim-signed 1.48+15.4-0ubuntu5 does not secure boot

2021-07-19 Thread Julian Andres Klode
Please also test the shim-signed 1.50+... binaries in proposed. If they do not work, please run mokutil --set-verbosity true and reboot and capture the output with a camera such that we can see verbose logging. Thank you! ** Changed in: shim-signed (Ubuntu) Status: New => Incomplete --

[Bug 1936759] Re: shim-signed 1.48+15.4-0ubuntu5 does not secure boot

2021-07-18 Thread Chris Guiver
Thank you for taking the time to report this bug and helping to make Ubuntu better. Please execute the following command only once, as it will automatically gather debugging information, in a terminal: apport-collect 1936759 When reporting bugs in the future please use apport by using 'ubuntu-