[SRU][B][F][H][I][UNSTABLE][PATCH] UBUNTU: [Packaging] Add system trusted and revocation keys final check

Dimitri John Ledkov dimitri.ledkov at canonical.com
Wed Oct 13 16:20:36 UTC 2021


If certificates are packaged, the config keys to use them must be
enabled otherwise boot testing will fail. This check ensures early
detection of incorrect configuration when rebasing derivative kernels.

The patch is identical for all series, but applies with fuzz, hence
sending three patches which apply cleanly on bionic; focal & hirsute;
impish & unstable.

This has no end-user effect as the final-checks are performed during
build and by cranky close when preparing kernels. It is a safety net
to prevent incorrect kernel rebases due to lax derivative config
enforements. (missing parent config includes, missing enforce, missing
do enforce all, mismatch in config include versions)

Dimitri John Ledkov (1):
  UBUNTU: [Packaging] Add system trusted and revocation keys final check

 debian/scripts/misc/final-checks | 12 ++++++++++++
 1 file changed, 12 insertions(+)

-- 
2.30.2




More information about the kernel-team mailing list