-
Notifications
You must be signed in to change notification settings - Fork 131
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Shim 15.8 for OL7 (ol7-shim-x86_64-20240215) #382
Comments
Hi, I'm not an authorized reviewer. I just want to help. |
@realnickel kindly asking if you had a chance to review this request. |
@iokomin, sorry for keeping you waiting. The review is still WIP, I'll try to finish it ASAP. |
While I am not an official reviewer, looking at latest tag: https://github.com/oracle/shim-review/tree/ol7-shim-x86_64-20240215 and additionally guided by discussions in #377 and #378 (same vendor, different distro branch) I can confirm that:
Previous accepted submission for OL7 was issue #306 (ol7-shim-x86_64-20221129). git diff origin/ol7-shim-x86_64-20221129..origin/ol7-shim-x86_64-20240215 Source code provided in shim-15.8-2.0.3.el7.src.rpm package matches to upstream shim-15.8.tar.bz2 Vendor is probably going to drop shipping signed ia32 version of shim as neither binary nor its hash provided for review (while it is still built inside the provided container). No security contact verification since first submission in 2018 (issue #33) has been performed explicitly, but IMHO that's no issue here as vendor had got several accepted submissions before "new vendor" tag was even introduced. Moreover @iokomin (who first was involved in issue #69 discussion and continuously submits shim for review since then) mentions non-public keybase review for shim 15.6 accepted and signed as part of grub2 embargo cve-2021-3695 work in his comment [1][2]. That fact pretty well confirms security contacts status. It also might be useful to consider comments on SBAT_AUTOMATIC_DATE=2021030218 in shim.spec [3] and @@Version@@ in grub2 SBAT metadata [4] in advance as they seem to be relevant to this submission either. Main concerns at this point:I haven't dig deep into mentioned kernels' lockdown patches and Oracle customization patches [5] on top of RHEL GRUB2 yet. [1] #306 (comment) |
One more point worth mentioning on security contacts information: it seems John Haxby's key might need a renewal nowadays?
|
@realnickel appreciate for reviewing this submission. |
@aronowski please share if there are any blocking issues left with this request to have it accepted. |
@realnickel 's review looks good, let's get another set of eyes too. |
Review of Shim 15.8 for OL7: ol7-shim-x86_64-20240215OK
Minor nits
|
Accepted! |
@steve-mcintyre thanks for quick turnaround, appreciate your time.
Ack, will definitely do. |
submission id: 13904177012883421 |
Confirm the following are included in your repo, checking each box:
What is the link to your tag in a repo cloned from rhboot/shim-review?
https://github.com/oracle/shim-review/tree/ol7-shim-x86_64-20240215
What is the SHA256 hash of your final SHIM binary?
26ee414cdf7e900938f7f6120f9f9825b58d45314172a418d29c96d70ba81893 shimx64.efi
What is the link to your previous shim review request (if any, otherwise N/A)?
#306
The text was updated successfully, but these errors were encountered: