[Bug 1926011] Re: groovy / focal fwupd sbat support

Mario Limonciello 1926011 at bugs.launchpad.net
Tue Apr 27 14:50:29 UTC 2021

I'm not sure how strong of a problem this is anymore.  It definitely was
problematic early in fwupd's development, but fwupd-efi hasn't had any
"ABI" impacting changes for a while now.

Interesting point.  There is a fwupd-efi.pc that will represent UEFI
executable version (https://github.com/fwupd/fwupd-
efi/blob/main/meson.build#L118).  This is only used at build time in
fwupd 1.6.0, and not consumed at runtime.  So it was going to be
installed into a build-deps only package fwupd-unsigned-dev

If there is a need to represent this from runtime, it would probably
mean we need to actually install at runtime too (place in fwupd-unsigned

You received this bug notification because you are a member of Ubuntu
Sponsors Team, which is subscribed to the bug report.

  groovy / focal fwupd sbat support

Status in OEM Priority Project:
Status in fwupd package in Ubuntu:
Status in fwupd-signed package in Ubuntu:
Status in fwupd source package in Groovy:
Status in fwupd-signed source package in Groovy:

Bug description:
  this is a follow-up bug for


  Future releases of shim will require that EFI binaries that are chainloaded include an SBAT region. fwupd in bionic does not currently contain this region.

  [Test Case]
  Verify that a shim that checks for sbat region can boot the fwupd with sbat region.

  [Regression Potential]
  This is moving to a new stable release in each of the series which is in bug fix only mode. The sbat region is the only "feature" that has been backported to this series in over a year.

To manage notifications about this bug go to:

More information about the Ubuntu-sponsors mailing list