[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

Steve Langasek 1928434 at bugs.launchpad.net
Tue Jun 22 21:51:23 UTC 2021


Hello Kris, or anyone else affected,

Accepted shim-signed into xenial-proposed. The package will build now
and be available at https://launchpad.net/ubuntu/+source/shim-
signed/1.33.1~16.04.8 in a few hours, and then in the -proposed
repository.

Please help us by testing this new package.  See
https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how
to enable and use -proposed.  Your feedback will aid us getting this
update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug,
mentioning the version of the package you tested, what testing has been
performed on the package and change the tag from verification-needed-
xenial to verification-done-xenial. If it does not fix the bug for you,
please add a comment stating that, and change the tag to verification-
failed-xenial. In either case, without details of your testing we will
not be able to proceed.

Further information regarding the verification process can be found at
https://wiki.ubuntu.com/QATeam/PerformingSRUVerification .  Thank you in
advance for helping!

N.B. The updated package will be released to -updates after the bug(s)
fixed by this package have been verified and the package has been in
-proposed for a minimum of 7 days.

** Changed in: shim-signed (Ubuntu Xenial)
       Status: New => Fix Committed

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to shim in Ubuntu.
https://bugs.launchpad.net/bugs/1928434

Title:
  shim-signed does not boot on EFI 2.40 by Apple

Status in shim package in Ubuntu:
  Fix Released
Status in shim-signed package in Ubuntu:
  Fix Released
Status in shim source package in Xenial:
  Fix Committed
Status in shim-signed source package in Xenial:
  Fix Committed
Status in shim source package in Hirsute:
  Fix Committed
Status in shim-signed source package in Hirsute:
  Fix Committed

Bug description:
  [Impact]
  Booting MacBook is broken

  [Test plan]
  We don't have a test plan per se to verify this bug, but the shim fix has been tested. Hard to verify those bugs :(

  [Where problems could occur]
  We disable mirroring of vendor dbx into MokListXRT EFI variable, so mokutil is not able to read the vendor dbx anymore. Other things might not be able to do so either; we don't believe we've been using it so far, though.

  [Original bug report]
  Hi,

  I have a MacBookPro14,3. After upgrade to Ubuntu 21.04 it failed to boot.
  At first I thought I'm affected by https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1925010.

  But my MacBook has newer efi Version and the fixed version of shim-
  signed is not solving my issues.

  >sudo dmesg | grep EFI
  [    0.000000] efi: EFI v2.40 by Apple
  [    0.011978] ACPI: UEFI 0x000000007AF7D000 000042 (v01 INTEL  EDK2     00000002      01000013)
  [    0.012029] ACPI: Reserving UEFI table memory at [mem 0x7af7d000-0x7af7d041]
  [    0.411423] fb0: EFI VGA frame buffer device
  [    0.418914] EFI Variables Facility v0.08 2004-May-17
  [    2.696996] fb0: switching to amdgpudrmfb from EFI VGA

  I reinstalled Ubuntu 21.04 from scratch and updated all packages during installation.
  The reboot failed. I hear the apple start sound and then an endless repeating echo.
  I've chrooted inside my system and verified that shim-signed 1.47+15.4-0ubuntu2 is installed.

  The suggested workaround from the other bug works (I can normally boot afterwards):
  /boot/efi/EFI# cp -b ubuntu/grubx64.efi ubuntu/shimx64.efi
  /boot/efi/EFI# cp -b ubuntu/grubx64.efi BOOT/BOOTX64.EFI

  "sudo apt reinstall shim-signed" reliable breaks my macbook again.

  Is there anything I can do to help solving this issue? What do you
  need?

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1928434/+subscriptions



More information about the foundations-bugs mailing list