-
Notifications
You must be signed in to change notification settings - Fork 131
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Alpaquita Linux shim-15.7 x64 #325
Comments
|
Updated the tag in the dockerfile hopefully this will make the build reproducible in the future. @dennis-tseng99 Thanks for checking!
Am I missing something or does it seem like there is no docker or podman installed? |
Switched from Alpaquita to Debian container to build the shim. Updated the currently used grub version. The new shim sha256 hash: |
Updated grub and kernel versions in use. grub now has NX support. |
Review for
|
@THS-on Thank you for the thorough review! Here are the answers to the questions:
Yes, we use build time generated key.
The patch was originally added back in 2016 to fix some sort of gcc build issue while having Considering the above, I will make the changes to the GRUB package and update the tag. |
@THS-on Added the changes to GRUB, which include the following:
Tag: https://github.com/akodanev/shim-review/tree/alpaquita-shim-x64-20231010 |
Tag alpaquita-shim-x64-20231010 now LGTM! I've sent out emails for contact verification. @dennis-tseng99 can you have another look at it? |
@akodanev just a small comment regarding SBAT for GRUB. You include mostly the patches from Fedora, but not all of them. It might still make sense to include their SBAT entry, to make revocation easier if there is an issue with one of their patches. |
milligrams soupiest truck's fashion divider's specialising preferring northward spinoffs torsos |
convertibility's ignitions undelivered loan's nutmeg's brush undone sliding poltergeist phonograph |
Phrases are correct, contact verification is complete! |
That's right. It does make sense to add the Fedora SBAT entry to our GRUB. Here is the new tag with the update: alpaquita-shim-x64-20231012 |
@THS-on Sorry for the late reply. I just reviewed the x64-20231012 tag, and got:
sbat, 1, SBAT Version, sbat, 1, https://github.com/rhboot/shim/blob/main/SBAT.md
|
I double checked the kernel config from https://packages.bell-sw.com/alpaquita/sources/stream/linux-aports-stream-latest.tar.gz:
Marking the submission with tag |
@THS-on @dennis-tseng99 Great! thank you so much! |
What is the status of this? Did you get a signed shim back or are creating a new submission for 15.8? |
It's not signed yet (submitted but not returned), basically the process was held up by the EV certificate we had to replace to get it uploaded, hence the delay. Yes, we are going to prepare the new submission for 15.8. |
@akodanev thanks for the update. I'll then close this and then please create a new submission for 15.8 |
This shim was signed by Microsoft (received March 13, 2024). |
Confirm the following are included in your repo, checking each box:
What is the link to your tag in a repo cloned from rhboot/shim-review?
https://github.com/akodanev/shim-review/tree/alpaquita-shim-x64-20231012
What is the SHA256 hash of your final SHIM binary?
e8995c52597b49639b12f6d954141280c2d2fc2ba1e1e7761c0af65e44e1a102
What is the link to your previous shim review request (if any, otherwise N/A)?
N/A
The text was updated successfully, but these errors were encountered: