Package: src:tiny-initramfs Version: 0.1-2 Severity: normal (Filing this as maintainer of tiny-initramfs after seeing the the other bugs related to secure boot filed on debian-devel.)
As well as the other initramfs implementations in Debian (dracut, #820041 and initramfs-tools, #820037), tiny-initramfs should also support detached signatures for the kernel modules to support secure boot. Since it doesn't use kmod to load modules but the syscall directly, support for appending the signatures needs to be added to tiny-initramfs - in addition to the code required in the Debian packaging that generates the initramfs and copies the modules there. I plan to work on this once I've familiarized myself with how the signature stuff works. @Ben: I'll leave it up to you if you want to block #820036 with this bug, as tiny-initramfs is a very niche thing with low popcon. Regards, Christian