[ubuntu/xenial-proposed] shim-signed 1.33.1~16.04.10 (Accepted)

Julian Andres Klode juliank at ubuntu.com
Mon Jul 19 12:35:39 UTC 2021


shim-signed (1.33.1~16.04.10) xenial; urgency=medium

  * Update to shim 15.4-0ubuntu7:
    - Fix load option parsing, and thus fwupd execution (LP: #1929471) (PR #379)
    - Fix occasional crashes in _relocate() on arm64 (LP: #1928010) (PR #383)
    - Fix accidental deletion of RT variables (LP: #1934506) (PR #387)
    - mok: relax the maximum variable size check (LP: #1934780) (PR #369)

shim-signed (1.33.1~16.04.9) xenial; urgency=medium

  * Do not build a dual-signed shim (fixing regression from ~16.04.7), and
    disable verifying fbx64.efi and mmx64.efi certificates as xenial's
    sbverify is unable to (impish works fine)
  * Clean up debhelper log file accidentally imported into git during 16.04.7
    import.

shim-signed (1.33.1~16.04.8) xenial; urgency=medium

  * debian/*.postinst: Unconditionally call grub-install with
    --force-extra-removable, so that the \EFI\BOOT removable path as used in
    cloud images receives the updates.  LP: #1930742.
  * Update to shim 15.4-0ubuntu5:
    - Stop addending vendor dbx to MokListXRT during MokListX mirroring. This
      is causing systems to run out of EFI storage space, or just hang up
      when trying to write it (LP: #1924605) (LP: #1928434)
    - Further relax the check for variable mirroring on non-secureboot systems
      avoiding boot failures on out of space conditons (pull request #372)
    - Don't unhook ExitBootServices() when EBS protection is disabled
      (LP: #1931136) (pull request #378)

shim-signed (1.33.1~16.04.7) xenial; urgency=medium

  * New upstream release 15.4.  LP: #1921134
  * Update packaging to pull fb and mm from shim-signed package as in
    later releases, dropping the runtime dependency on shim.
  * Add download-signed script from linux-signed package
  * Add a versioned dependency on the mokutil that introduces --timeout, and
    call mokutil --timeout -1 so that users don't end up with broken systems
    by missing MokManager on reboot after install.  LP: #1856422.
  * Add versioned dependencies on grub-efi-amd64-signed and grub2-common,
    to ensure we have SBAT-compatible grub.efi and grub 2.04-compatible
    grub-install present when we are installing new shim to the ESP.
  * Include reworked Makefile from devel to better assert the integrity of
    the executables.

Date: Fri, 16 Jul 2021 13:04:57 +0200
Changed-By: Julian Andres Klode <juliank at ubuntu.com>
Maintainer: Steve Langasek <steve.langasek at ubuntu.com>
https://launchpad.net/ubuntu/+source/shim-signed/1.33.1~16.04.10
-------------- next part --------------
Format: 1.8
Date: Fri, 16 Jul 2021 13:04:57 +0200
Source: shim-signed
Built-For-Profiles: noudeb
Architecture: source
Version: 1.33.1~16.04.10
Distribution: xenial
Urgency: medium
Maintainer: Steve Langasek <steve.langasek at ubuntu.com>
Changed-By: Julian Andres Klode <juliank at ubuntu.com>
Launchpad-Bugs-Fixed: 1856422 1921134 1924605 1928010 1928434 1929471 1930742 1931136 1934506 1934780
Changes:
 shim-signed (1.33.1~16.04.10) xenial; urgency=medium
 .
   * Update to shim 15.4-0ubuntu7:
     - Fix load option parsing, and thus fwupd execution (LP: #1929471) (PR #379)
     - Fix occasional crashes in _relocate() on arm64 (LP: #1928010) (PR #383)
     - Fix accidental deletion of RT variables (LP: #1934506) (PR #387)
     - mok: relax the maximum variable size check (LP: #1934780) (PR #369)
 .
 shim-signed (1.33.1~16.04.9) xenial; urgency=medium
 .
   * Do not build a dual-signed shim (fixing regression from ~16.04.7), and
     disable verifying fbx64.efi and mmx64.efi certificates as xenial's
     sbverify is unable to (impish works fine)
   * Clean up debhelper log file accidentally imported into git during 16.04.7
     import.
 .
 shim-signed (1.33.1~16.04.8) xenial; urgency=medium
 .
   * debian/*.postinst: Unconditionally call grub-install with
     --force-extra-removable, so that the \EFI\BOOT removable path as used in
     cloud images receives the updates.  LP: #1930742.
   * Update to shim 15.4-0ubuntu5:
     - Stop addending vendor dbx to MokListXRT during MokListX mirroring. This
       is causing systems to run out of EFI storage space, or just hang up
       when trying to write it (LP: #1924605) (LP: #1928434)
     - Further relax the check for variable mirroring on non-secureboot systems
       avoiding boot failures on out of space conditons (pull request #372)
     - Don't unhook ExitBootServices() when EBS protection is disabled
       (LP: #1931136) (pull request #378)
 .
 shim-signed (1.33.1~16.04.7) xenial; urgency=medium
 .
   * New upstream release 15.4.  LP: #1921134
   * Update packaging to pull fb and mm from shim-signed package as in
     later releases, dropping the runtime dependency on shim.
   * Add download-signed script from linux-signed package
   * Add a versioned dependency on the mokutil that introduces --timeout, and
     call mokutil --timeout -1 so that users don't end up with broken systems
     by missing MokManager on reboot after install.  LP: #1856422.
   * Add versioned dependencies on grub-efi-amd64-signed and grub2-common,
     to ensure we have SBAT-compatible grub.efi and grub 2.04-compatible
     grub-install present when we are installing new shim to the ESP.
   * Include reworked Makefile from devel to better assert the integrity of
     the executables.
Checksums-Sha1:
 66b31bc47a546ef29546f47f1ae4c9699403ff7a 1727 shim-signed_1.33.1~16.04.10.dsc
 7ec55362abe2feda1624b38c9e905d947becaa33 338156 shim-signed_1.33.1~16.04.10.tar.xz
 1e9f57085bbbb810f84abebda76da1713369b58c 8509 shim-signed_1.33.1~16.04.10_source.buildinfo
Checksums-Sha256:
 3a067801291293fa87cc9d51efd8b1230166ec629925eb9b083068d447540b92 1727 shim-signed_1.33.1~16.04.10.dsc
 8314d1f6c1988b00168b3c4ec063be2b7d35700fa16244f922fbe9012db9a2bf 338156 shim-signed_1.33.1~16.04.10.tar.xz
 2cf14444e120f13031a905a3be41e2de103902d37c237e1bb22ce6444185967c 8509 shim-signed_1.33.1~16.04.10_source.buildinfo
Files:
 76f720348dbafccb3584831125b5436f 1727 utils optional shim-signed_1.33.1~16.04.10.dsc
 d779bf6a094e025702e3dcc17362617d 338156 utils optional shim-signed_1.33.1~16.04.10.tar.xz
 f08719f8e99a3e6f292f76db8ac7488b 8509 utils optional shim-signed_1.33.1~16.04.10_source.buildinfo


More information about the Xenial-changes mailing list