[ubuntu/hirsute-proposed] shim-signed 1.48 (Accepted)

Julian Andres Klode julian.klode at canonical.com
Tue Jun 22 21:29:05 UTC 2021

shim-signed (1.48) impish; urgency=medium

  [ Dimitri John Ledkov ]
  * Ship externally signed shims in the source package, instead of
    detached signatures.

  [ Steve Langasek ]
  * Restore build-time 'cmp' check to assert that the output of sbattach
    matches the binary received from Microsoft.
  * Include external-$arch.p7c in the clean target.

  [ Julian Andres Klode ]
  * download-signed: Work around non-HTTP apt sources
  * Update to shim 15.4-0ubuntu5:
    - Stop addending vendor dbx to MokListXRT during MokListX mirroring. This
      is causing systems to run out of EFI storage space, or just hang up
      when trying to write it (LP: #1924605) (LP: #1928434)
    - Further relax the check for variable mirroring on non-secureboot systems
      avoiding boot failures on out of space conditons (pull request #372)
    - Don't unhook ExitBootServices() when EBS protection is disabled
      (LP: #1931136) (pull request #378)

Date: 2021-06-22 10:25:09.170453+00:00
Changed-By: Julian Andres Klode <julian.klode at canonical.com>
Maintainer: Steve Langasek <steve.langasek at canonical.com>
-------------- next part --------------
Sorry, changesfile not available.

More information about the Hirsute-changes mailing list