[ubuntu/trusty-updates] shim 13-0ubuntu2 (Accepted)

Łukasz Zemczak lukasz.zemczak at canonical.com
Thu Sep 13 09:33:06 UTC 2018

shim (13-0ubuntu2) bionic; urgency=medium

  * debian/patches/abort_abort_abort.patch: signtool.exe isn't happy with some
    of the structure of our binary, partly because abort() is thought to be an
    external symbol, which causes some relocalisations to appear.

shim (13-0ubuntu1) artful; urgency=medium

  * New upstream release: 13
  * debian/control: add a Build-Depends on libelf-dev.
  * debian/control: add Breaks: for the previous shim-signed builds given
    that shim will now build and ship BOOT.CSV by itself.
  * debian/rules:
    - Update dh_auto_build/dh_auto_clean/dh_auto_install for new upstream
      options: set MAKELEVEL.
    - Define an EFI_ARCH variable, and use that for paths to shim. This
      makes it possible to build a shim for other architectures than amd64.
    - Set EFIDIR=ubuntu for dh_auto_install; that will let files be installed
      in the "right" final directories, and makes boot.csv for us.
    - Set ENABLE_SHIM_CERT, to keep using ephemeral self-signed certs built
      at compile-time for MokManager and fallback.
    - Set ENABLE_SBSIGN, to use sbsign instead of pesign for signing fallback
      and MokManager.
  * debian/patches/second-stage-path: dropped; the default loader path now
    includes an arch suffix.
  * debian/patches/sbsigntool-no-pesign: dropped; no longer needed..
  * debian/patches/0001-shim-fix-the-mirroring-MokSBState-fail.patch: dropped,
    included upstream.
  * debian/shim.install: update paths in light of using shim's upstream install
  * debian/rules, debian/shim.install: make sure the 'make install' step does
    what it's meant to do by upstream: we can easily make use of the end result
    to have the files we need.

Date: 2017-11-07 20:26:24.204177+00:00
Changed-By: Mathieu Trudel-Lapierre <mathieu.tl at gmail.com>
Signed-By: Łukasz Zemczak <lukasz.zemczak at canonical.com>
-------------- next part --------------
Sorry, changesfile not available.

More information about the Trusty-changes mailing list