[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-09-07 Thread Launchpad Bug Tracker
This bug was fixed in the package shim-signed - 1.37~18.04.10 --- shim-signed (1.37~18.04.10) bionic; urgency=medium * Remove unnecessary efitools dependency that prevented build on arm64 shim-signed (1.37~18.04.9) bionic; urgency=medium * New upstream release 15.4. LP:

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-08-16 Thread Launchpad Bug Tracker
This bug was fixed in the package shim-signed - 1.33.1~16.04.10 --- shim-signed (1.33.1~16.04.10) xenial; urgency=medium * Update to shim 15.4-0ubuntu7: - Fix load option parsing, and thus fwupd execution (LP: #1929471) (PR #379) - Fix occasional crashes in _relocate() on

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-08-16 Thread Launchpad Bug Tracker
This bug was fixed in the package shim - 15.4-0ubuntu7 --- shim (15.4-0ubuntu7) hirsute; urgency=medium * Fix load option parsing, and thus fwupd execution (LP: #1929471) (PR #379) * Fix occasional crashes in _relocate() on arm64 (LP: #1928010) (PR #383) * Fix accidental

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-08-02 Thread Launchpad Bug Tracker
This bug was fixed in the package shim-signed - 1.40.6 --- shim-signed (1.40.6) focal; urgency=medium * Update to shim 15.4-0ubuntu7: - Fix load option parsing, and thus fwupd execution (LP: #1929471) (PR #379) - Fix occasional crashes in _relocate() on arm64 (LP: #1928010)

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-08-02 Thread Launchpad Bug Tracker
This bug was fixed in the package shim - 15.4-0ubuntu7 --- shim (15.4-0ubuntu7) hirsute; urgency=medium * Fix load option parsing, and thus fwupd execution (LP: #1929471) (PR #379) * Fix occasional crashes in _relocate() on arm64 (LP: #1928010) (PR #383) * Fix accidental

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-07-26 Thread Julian Andres Klode
** Tags removed: block-proposed-focal -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928434 Title: shim-signed does not boot on EFI 2.40 by Apple To manage notifications about this bug go to:

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-07-23 Thread Julian Andres Klode
We verified them once, no need or ability to reverify those binaries across all releases on macs. ** Tags removed: verification-needed verification-needed-bionic verification-needed-focal verification-needed-xenial ** Tags added: verification-done verification-done-bionic

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-07-19 Thread Łukasz Zemczak
Hello Kris, or anyone else affected, Accepted shim-signed into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim- signed/1.33.1~16.04.10 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-07-19 Thread Łukasz Zemczak
Hello Kris, or anyone else affected, Accepted shim-signed into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim- signed/1.37~18.04.9 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-07-05 Thread Launchpad Bug Tracker
This bug was fixed in the package shim - 15.4-0ubuntu5 --- shim (15.4-0ubuntu5) hirsute; urgency=medium * Rebuild in hirsute to get a more stable target to keep shim reproducible for a longer time. shim (15.4-0ubuntu3) impish; urgency=medium [ Steve Langasek ] * Use -Zxz

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-07-05 Thread Launchpad Bug Tracker
This bug was fixed in the package shim-signed - 1.48 --- shim-signed (1.48) impish; urgency=medium [ Dimitri John Ledkov ] * Ship externally signed shims in the source package, instead of detached signatures. [ Steve Langasek ] * Restore build-time 'cmp' check to assert

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-28 Thread Julian Andres Klode
Remarking xenial as done, got overridden by late shim-signed acceptance. ** Tags removed: verification-needed-xenial ** Tags added: verification-done-xenial -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-28 Thread Łukasz Zemczak
Hello Kris, or anyone else affected, Accepted shim-signed into focal-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim-signed/1.40.5 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-25 Thread Łukasz Zemczak
Hello Kris, or anyone else affected, Accepted shim into focal-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim/15.4-0ubuntu5 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-24 Thread Brian Murray
Hello Kris, or anyone else affected, Accepted shim-signed into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim- signed/1.33.1~16.04.9 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-24 Thread Julian Andres Klode
The binaries are the same across all releases, and we got confirmation before pushing the SRU out that they fix the issue, so marking as verified. ** Tags removed: verification-needed-hirsute verification-needed-xenial ** Tags added: verification-doen-hirsute verification-done-xenial ** Tags

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-22 Thread Steve Langasek
Hello Kris, or anyone else affected, Accepted shim-signed into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim- signed/1.33.1~16.04.8 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-22 Thread Steve Langasek
Hello Kris, or anyone else affected, Accepted shim into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim/15.4-0ubuntu5 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-22 Thread Steve Langasek
Hello Kris, or anyone else affected, Accepted shim into hirsute-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim/15.4-0ubuntu5 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-22 Thread Launchpad Bug Tracker
This bug was fixed in the package shim-signed - 1.48 --- shim-signed (1.48) impish; urgency=medium [ Dimitri John Ledkov ] * Ship externally signed shims in the source package, instead of detached signatures. [ Steve Langasek ] * Restore build-time 'cmp' check to assert

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-22 Thread Julian Andres Klode
** Description changed: + [Impact] + Booting MacBook is broken + + [Test plan] + We don't have a test plan per se to verify this bug, but the shim fix has been tested. Hard to verify those bugs :( + + [Where problems could occur] + We disable mirroring of vendor dbx into MokListXRT EFI

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-22 Thread Julian Andres Klode
** Tags removed: block-proposed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928434 Title: shim-signed does not boot on EFI 2.40 by Apple To manage notifications about this bug go to:

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-22 Thread Julian Andres Klode
** Tags added: block-proposed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928434 Title: shim-signed does not boot on EFI 2.40 by Apple To manage notifications about this bug go to:

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-22 Thread Launchpad Bug Tracker
This bug was fixed in the package shim - 15.4-0ubuntu5 --- shim (15.4-0ubuntu5) hirsute; urgency=medium * Rebuild in hirsute to get a more stable target to keep shim reproducible for a longer time. shim (15.4-0ubuntu3) impish; urgency=medium [ Steve Langasek ] * Use -Zxz

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-08 Thread Julian Andres Klode
Please note that this bug is about the shim itself. Disabling upgrades is tracked in bug 1929449 which was obviously fixed, causing the regression of sorts and that regression is tracked in bug 1931112. The update for that regression is in the process of being released. -- You received this bug

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-08 Thread jorge santos
I have Ubuntu MATE 20.10 running on my Raspberry Pi 4 and I can't upgrade because of this bug as well. I went to the file "DistUpgradeQuirks.py" (as mentioned above) and I can't see any "apple" string there to change and force the upgrade. I'm just stuck. -- You received this bug notification

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-08 Thread Virsacer
> What went wrong is that the code check was also applied to non-UEFI systems. So, will the "Fix Committed" stop preventing upgrades on non-UEFI Raspberry Pi? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-08 Thread Julian Andres Klode
Doug, I'm not sure how you get confused, or why you spam the bug tracker with ASCII art like this. This = "vendor is apple OR can't read vendor" - the statement which caused the issue and which you blamed Python for for unknown reasons - was intentional, as I said. We explicitly discussed that

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-08 Thread Doug McDonald
> This is by design, we should not upgrade Apple systems just because their dmi is broken. Wait, what? Can you not see the differences between "This", "we should not upgrade Apple systems just because their dmi is broken" and "Seems we forgot to check that we are booting on UEFI in the first

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-07 Thread Julian Andres Klode
** Changed in: shim (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928434 Title: shim-signed does not boot on EFI 2.40 by Apple To manage

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-07 Thread Julian Andres Klode
Please don't blame Python. This is by design, we should not upgrade Apple systems just because their dmi is broken. Seems we forgot to check that we are booting on UEFI in the first place, though, but oh well, still a step up from nobody upgrading to most x86 'PC's upgrading. -- You received

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-07 Thread Doug McDonald
oh sweet jesus python strikes again let's make programming fun and accessible they said logic and reason is so yesterday they said -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928434 Title:

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-07 Thread Alyssa Rowan
That's because _test_and_fail_on_apple in DistUpgradeQuirks.py (see line 377) in the upgrader itself, is set to fail if vendor.startswith('Apple Inc.') OR if vendor is unknown i.e. /sys/class/dmi/id/sys_vendor is null (for example as it will be in WSL or just about any other system where DMI isn't

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-07 Thread Doug McDonald
> However, a change has been made to ubuntu-release-upgrader that lets us > block upgrades only for Apple hardware, and upgrades have been turned on for > 20.10 to 21.04. So I'm not sure why you say that it "currently prevents" > it. What I meant by "[this bug] currently prevents

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-05 Thread Michael Paul McCaffery
the change to ubuntu-release-upgrader seems to prevent me upgrading an old raspberry pi, so its not just apple An upgrade is not possible at this time Due to a bug in shim, LP: #1928434, upgrades are not currently safe for your hardware. Once that bug has been resolved you will be able to

Re: [Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-03 Thread Steve Langasek
On Fri, Jun 04, 2021 at 03:11:59AM -, Doug McDonald wrote: > Does this bug affect ppc64le? It currently prevents do-release-upgrade > to 21.04 from 20.10. This bug does not affect ppc64el, but there is no interface for turning on upgrades on a per-architecture basis. However, a change has

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-03 Thread Doug McDonald
Does this bug affect ppc64le? It currently prevents do-release-upgrade to 21.04 from 20.10. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928434 Title: shim-signed does not boot on EFI 2.40 by

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-02 Thread Steve Langasek
Thanks so much for the quick turnaround! We'll make sure this gets submitted to Microsoft for signing ASAP so we can get the fix into 21.04 for all users. ** Changed in: shim-signed (Ubuntu) Status: Incomplete => In Progress ** Changed in: shim (Ubuntu) Status: Triaged => In

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-02 Thread Kris Budde
Hi Steve, Hi Julian, I didn't realize how seriously this problem was taken and I was quite busy last week. Sorry for the delay. I just tested it and it worked. Only thing which might be worth to mention: I still have the logging enabled. And the blue screen with warning "secure boot not

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-06-02 Thread Steve Langasek
Kris, we would appreciate if you could run the above test as requested by Julian and let us know if it boots on your system. We take boot regressions seriously and have put upgrades to 21.04 on hold for all users while this bug remains unresolved, but it's important to be able to close this bug

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-24 Thread Julian Andres Klode
(for clarification, I forgot to say that this is for testing purposes, trying to figure out if this resolves the issue) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928434 Title: shim-signed does

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-24 Thread Julian Andres Klode
Hi there, could you replace BOOTX64.EFI and shimx64.efi in your ESP with the shimx64.efi in? http://ppa.launchpad.net/ubuntu-uefi- team/ppa/ubuntu/dists/impish/main/signed/shim- amd64/15.4-0ubuntu3~uefi2/signed.tar.gz This makes the shim only mirror the actual MokListX, and not add the giant

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-18 Thread Julian Andres Klode
This is trying to mirror our insanely large MokListX to MokListXRT, which is so large due to COVID related travel restrictions preventing the generation of a new signing key, and having to revoke all binaries this way instead. However, we do not actually need to mirror that list AFAIUI, because

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-18 Thread Julian Andres Klode
The log shows us that in mirror_mok_db() the call to get_max_var_sz() in mok.c:366 was successful, so it must hang before line 424 where dprint() is called. Given 19304 < 0x4FDC, I assume the path in 373 is being taken, and the call to SetVariable() inside there is hanging in the firmware

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-18 Thread Kris Budde
** Attachment added: "2.jpeg" https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1928434/+attachment/5498532/+files/2.jpeg -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928434 Title:

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-18 Thread Kris Budde
** Attachment added: "1.jpeg" https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1928434/+attachment/5498531/+files/1.jpeg -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928434 Title:

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-18 Thread Kris Budde
** Attachment added: "0.jpeg" https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1928434/+attachment/5498530/+files/0.jpeg -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928434 Title:

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-18 Thread Kris Budde
Hi, thank you for the ppa. It was much easier this way. After reinstalling shim and 'sudo mokutil --set-verbosity true' I got a blue screen (secure boot not enabled > ok) and afterwards three pages of logs. I created a professional slow motion screen recording and extracted the pages. Not sure

Re: [Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-17 Thread Steve Langasek
On Mon, May 17, 2021 at 03:23:45PM -, Dimitri John Ledkov wrote: > See > https://github.com/lcp/mokutil/commit/03bb7af4a84c39f2417fd14ef20b11b2e8d1ad51 > Is this something you can compile yourself, or do you need me to provide > you with an updated mokutil package? I have provided a mokutil

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-17 Thread Julian Andres Klode
> I reinstalled Ubuntu 21.04 from scratch and updated all packages during installation. If you were able to boot the install image, then this might not be a bug in shim, as the shim on the install image should not work either. Also we only download upgrades during install, but do not apply them,

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-17 Thread Dimitri John Ledkov
@kebkeb you can download that efivariable as a file into the efivars dir. Or you need to compile the new mokutil that supports setting that on non-secureboot systems too. See https://github.com/lcp/mokutil/commit/03bb7af4a84c39f2417fd14ef20b11b2e8d1ad51 Is this something you can compile

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-16 Thread Kris Budde
I tried "sudo mokutil --set-verbosity true" but >"This system doesn't support Secure Boot". ** Description changed: Hi, I have a MacBookPro14,3. After upgrade to Ubuntu 21.04 it failed to boot. At first I thought I'm affected by

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-14 Thread Matthieu Clemenceau
** Tags added: fr-1373 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928434 Title: shim-signed does not boot on EFI 2.40 by Apple To manage notifications about this bug go to:

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-14 Thread Steve Langasek
** Changed in: shim-signed (Ubuntu) Status: Triaged => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928434 Title: shim-signed does not boot on EFI 2.40 by Apple To manage

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-14 Thread Dimitri John Ledkov
For your current work around to persist, you should also do: $ sudo dpkg-divert /usr/lib/shim/shimx64.efi.signed $ sudo cp /usr/lib/grub/x86_64-efi-signed/grubx64.efi.signed /usr/lib/shim/shimx64.efi.signed This way whenever grub-install is called, _grub_ is used instead of shim. Unfortunately

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-14 Thread Steve Langasek
One thing you can try while booted up is to run 'mokutil --set-verbosity true' and then reboot, to see if you get any output on the screen from shim that would let us narrow down where things are failing. -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

2021-05-14 Thread Dimitri John Ledkov
** Changed in: shim-signed (Ubuntu) Status: New => Triaged ** Changed in: shim-signed (Ubuntu) Importance: Undecided => Critical ** Changed in: shim (Ubuntu) Importance: Undecided => Critical ** Changed in: shim (Ubuntu) Status: New => Triaged -- You received this bug