[ubuntu/xenial-proposed] shim-signed 1.33.1~16.04.10 (Accepted)
Julian Andres Klode
juliank at ubuntu.com
Mon Jul 19 12:35:39 UTC 2021
shim-signed (1.33.1~16.04.10) xenial; urgency=medium
* Update to shim 15.4-0ubuntu7:
- Fix load option parsing, and thus fwupd execution (LP: #1929471) (PR #379)
- Fix occasional crashes in _relocate() on arm64 (LP: #1928010) (PR #383)
- Fix accidental deletion of RT variables (LP: #1934506) (PR #387)
- mok: relax the maximum variable size check (LP: #1934780) (PR #369)
shim-signed (1.33.1~16.04.9) xenial; urgency=medium
* Do not build a dual-signed shim (fixing regression from ~16.04.7), and
disable verifying fbx64.efi and mmx64.efi certificates as xenial's
sbverify is unable to (impish works fine)
* Clean up debhelper log file accidentally imported into git during 16.04.7
import.
shim-signed (1.33.1~16.04.8) xenial; urgency=medium
* debian/*.postinst: Unconditionally call grub-install with
--force-extra-removable, so that the \EFI\BOOT removable path as used in
cloud images receives the updates. LP: #1930742.
* Update to shim 15.4-0ubuntu5:
- Stop addending vendor dbx to MokListXRT during MokListX mirroring. This
is causing systems to run out of EFI storage space, or just hang up
when trying to write it (LP: #1924605) (LP: #1928434)
- Further relax the check for variable mirroring on non-secureboot systems
avoiding boot failures on out of space conditons (pull request #372)
- Don't unhook ExitBootServices() when EBS protection is disabled
(LP: #1931136) (pull request #378)
shim-signed (1.33.1~16.04.7) xenial; urgency=medium
* New upstream release 15.4. LP: #1921134
* Update packaging to pull fb and mm from shim-signed package as in
later releases, dropping the runtime dependency on shim.
* Add download-signed script from linux-signed package
* Add a versioned dependency on the mokutil that introduces --timeout, and
call mokutil --timeout -1 so that users don't end up with broken systems
by missing MokManager on reboot after install. LP: #1856422.
* Add versioned dependencies on grub-efi-amd64-signed and grub2-common,
to ensure we have SBAT-compatible grub.efi and grub 2.04-compatible
grub-install present when we are installing new shim to the ESP.
* Include reworked Makefile from devel to better assert the integrity of
the executables.
Date: Fri, 16 Jul 2021 13:04:57 +0200
Changed-By: Julian Andres Klode <juliank at ubuntu.com>
Maintainer: Steve Langasek <steve.langasek at ubuntu.com>
https://launchpad.net/ubuntu/+source/shim-signed/1.33.1~16.04.10
-------------- next part --------------
Format: 1.8
Date: Fri, 16 Jul 2021 13:04:57 +0200
Source: shim-signed
Built-For-Profiles: noudeb
Architecture: source
Version: 1.33.1~16.04.10
Distribution: xenial
Urgency: medium
Maintainer: Steve Langasek <steve.langasek at ubuntu.com>
Changed-By: Julian Andres Klode <juliank at ubuntu.com>
Launchpad-Bugs-Fixed: 1856422 1921134 1924605 1928010 1928434 1929471 1930742 1931136 1934506 1934780
Changes:
shim-signed (1.33.1~16.04.10) xenial; urgency=medium
.
* Update to shim 15.4-0ubuntu7:
- Fix load option parsing, and thus fwupd execution (LP: #1929471) (PR #379)
- Fix occasional crashes in _relocate() on arm64 (LP: #1928010) (PR #383)
- Fix accidental deletion of RT variables (LP: #1934506) (PR #387)
- mok: relax the maximum variable size check (LP: #1934780) (PR #369)
.
shim-signed (1.33.1~16.04.9) xenial; urgency=medium
.
* Do not build a dual-signed shim (fixing regression from ~16.04.7), and
disable verifying fbx64.efi and mmx64.efi certificates as xenial's
sbverify is unable to (impish works fine)
* Clean up debhelper log file accidentally imported into git during 16.04.7
import.
.
shim-signed (1.33.1~16.04.8) xenial; urgency=medium
.
* debian/*.postinst: Unconditionally call grub-install with
--force-extra-removable, so that the \EFI\BOOT removable path as used in
cloud images receives the updates. LP: #1930742.
* Update to shim 15.4-0ubuntu5:
- Stop addending vendor dbx to MokListXRT during MokListX mirroring. This
is causing systems to run out of EFI storage space, or just hang up
when trying to write it (LP: #1924605) (LP: #1928434)
- Further relax the check for variable mirroring on non-secureboot systems
avoiding boot failures on out of space conditons (pull request #372)
- Don't unhook ExitBootServices() when EBS protection is disabled
(LP: #1931136) (pull request #378)
.
shim-signed (1.33.1~16.04.7) xenial; urgency=medium
.
* New upstream release 15.4. LP: #1921134
* Update packaging to pull fb and mm from shim-signed package as in
later releases, dropping the runtime dependency on shim.
* Add download-signed script from linux-signed package
* Add a versioned dependency on the mokutil that introduces --timeout, and
call mokutil --timeout -1 so that users don't end up with broken systems
by missing MokManager on reboot after install. LP: #1856422.
* Add versioned dependencies on grub-efi-amd64-signed and grub2-common,
to ensure we have SBAT-compatible grub.efi and grub 2.04-compatible
grub-install present when we are installing new shim to the ESP.
* Include reworked Makefile from devel to better assert the integrity of
the executables.
Checksums-Sha1:
66b31bc47a546ef29546f47f1ae4c9699403ff7a 1727 shim-signed_1.33.1~16.04.10.dsc
7ec55362abe2feda1624b38c9e905d947becaa33 338156 shim-signed_1.33.1~16.04.10.tar.xz
1e9f57085bbbb810f84abebda76da1713369b58c 8509 shim-signed_1.33.1~16.04.10_source.buildinfo
Checksums-Sha256:
3a067801291293fa87cc9d51efd8b1230166ec629925eb9b083068d447540b92 1727 shim-signed_1.33.1~16.04.10.dsc
8314d1f6c1988b00168b3c4ec063be2b7d35700fa16244f922fbe9012db9a2bf 338156 shim-signed_1.33.1~16.04.10.tar.xz
2cf14444e120f13031a905a3be41e2de103902d37c237e1bb22ce6444185967c 8509 shim-signed_1.33.1~16.04.10_source.buildinfo
Files:
76f720348dbafccb3584831125b5436f 1727 utils optional shim-signed_1.33.1~16.04.10.dsc
d779bf6a094e025702e3dcc17362617d 338156 utils optional shim-signed_1.33.1~16.04.10.tar.xz
f08719f8e99a3e6f292f76db8ac7488b 8509 utils optional shim-signed_1.33.1~16.04.10_source.buildinfo
More information about the Xenial-changes
mailing list