follow up #29, per the built un-signed fwupdx64.efi, it does have the sbat section.
$ objdump -h ./fwupdx64.efi ./fwupdx64.efi: file format pei-x86-64 Sections: Idx Name Size VMA LMA File off Algn 0 .text 00007a2b 0000000000004000 0000000000004000 00000400 2**4 CONTENTS, ALLOC, LOAD, READONLY, CODE 1 .reloc 0000000a 000000000000c000 000000000000c000 00008000 2**0 CONTENTS, ALLOC, LOAD, READONLY, DATA 2 .data 00002ea8 000000000000d000 000000000000d000 00008200 2**5 CONTENTS, ALLOC, LOAD, DATA 3 .sbat 000000ec 0000000000010000 0000000000010000 0000b200 2**0 CONTENTS, ALLOC, LOAD, READONLY, DATA 4 .dynamic 00000150 0000000000011000 0000000000011000 0000b400 2**3 CONTENTS, ALLOC, LOAD, DATA 5 .rela 00000e70 0000000000012000 0000000000012000 0000b600 2**3 CONTENTS, ALLOC, LOAD, READONLY, DATA 6 .rela.plt 00000018 0000000000012e70 0000000000012e70 0000c670 2**3 CONTENTS, ALLOC, LOAD, READONLY, DATA 7 .dynsym 00000288 0000000000013000 0000000000013000 0000ca00 2**3 CONTENTS, ALLOC, LOAD, READONLY, DATA -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1921539 Title: Add support for SBAT To manage notifications about this bug go to: https://bugs.launchpad.net/oem-priority/+bug/1921539/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs