[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
** Changed in: shim (Ubuntu Xenial) Status: Fix Committed => Fix Released ** Changed in: shim (Ubuntu Bionic) Status: Fix Committed => Fix Released ** Changed in: shim (Ubuntu Focal) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
This bug was fixed in the package shim-signed - 1.37~18.04.8 --- shim-signed (1.37~18.04.8) bionic; urgency=medium * Followup fix to actually include the updated shimx64.efi (LP: #1862171), as the previous upload accidentally only contained an updated shimaa64.efi shim-signed (1.37~18.04.7) bionic; urgency=medium * Build shim-signed:arm64 (LP: #1890813) * Update to the signed 15+1552672080.a4a1fbe-0ubuntu2 binary from Microsoft. (LP: #1862171) -- Julian Andres Klode Thu, 27 Aug 2020 13:32:46 +0200 ** Changed in: shim-signed (Ubuntu Bionic) Status: Fix Committed => Fix Released ** Changed in: shim-signed (Ubuntu Xenial) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
This bug was fixed in the package shim-signed - 1.33.1~16.04.6 --- shim-signed (1.33.1~16.04.6) xenial; urgency=medium * Update to the signed 15+1552672080.a4a1fbe-0ubuntu2 binary from Microsoft. (LP: #1862171) -- Julian Andres Klode Fri, 07 Aug 2020 14:10:55 +0200 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
This bug was fixed in the package shim-signed - 1.40.4 --- shim-signed (1.40.4) focal; urgency=medium * Update to the signed 15+1552672080.a4a1fbe-0ubuntu2 binary from Microsoft. (LP: #1862171) -- Julian Andres Klode Fri, 07 Aug 2020 13:42:41 +0200 ** Changed in: shim-signed (Ubuntu Focal) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
Sweet. Yeah that message was the plan. It should also do stuff like mount /proc and cat /proc/cmdline and tell you secure boot state and such from inside the kernel. Such that we check that too. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
-device e1000,netdev=n1,bootindex=1 adding ',bootindex=1' causes the netboot to actually be used by default. And for automating the test, it would be nice to boot to echo a message and shutdown, such that one can capture console log to verify if the boot was as expected. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
(xnox tested chainloading windows now too) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
here's a log even for xenial, so it's visible how the tests are coalesced: - Enroll MOK with timeout 66 - OK - disable validation - OK - reenable validation with timeout -1 (completes mokutil timeout test) - OK - reset MOK - OK This means xenial passed too, weeehh (1.33.1~16.04.6). ** Tags removed: verification-needed verification-needed-xenial ** Tags added: verification-done verification-done-xenial -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
shim-signed/bionic=1.37~18.04.8 is good. I coalesced some of the timeout tests with the other reset tests to reduce the number of reboots needed, and it was nicer :) ** Tags removed: verification-needed-bionic ** Tags added: verification-done-bionic -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
I've not verified Windows chainloading (which xnox did for 0ubuntu1, and we only had a tiny patch on top), or MAAS, as those are not really feasible for me. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
Presumably the binaries work OK enough for MAAS, as they've been in groovy for quite a while now. That said, MAAS also has a lot of failures on the grub side, so verifying is probably not even possible. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
So this means focal (shim-signed 1.40.4) as done. fwupd is tracked in bug 1864223. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
Verified the MokManager and mokutil tests on focal ** Tags removed: verification-needed-focal ** Tags added: verification-done-focal -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
netboot - testing the new shim binaries against stable release grubs using PXE boot xenial, bionic, and focal all pass the tests netboot - booted to kernel ✓ netboot-unsigned-grub - unsigned grub rejected - "security violation" ✓ netboot-unsigned-kernel - unsigned kernel rejected / not loaded ✓ See test script. Can be run on groovy or any of the systems with the shim installed, against specified grub debs. ** Attachment added: "shimctl" https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+attachment/5407414/+files/shimctl -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
** Tags added: id-5bdb8a5a8202ad5b735c45b9 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
shim booting, desktop inside secureboot VM: focal ✓ bionic ✓ xenial ✓ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
Hello Julian, or anyone else affected, Accepted shim-signed into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim- signed/1.37~18.04.8 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users. If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested, what testing has been performed on the package and change the tag from verification-needed- bionic to verification-done-bionic. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification- failed-bionic. In either case, without details of your testing we will not be able to proceed. Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance for helping! N.B. The updated package will be released to -updates after the bug(s) fixed by this package have been verified and the package has been in -proposed for a minimum of 7 days. ** Tags removed: verification-failed-bionic ** Tags added: verification-needed-bionic -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
The shim-signed SRU for bionic accidentally contained the old shimx64.efi (only shimaa64.efi was updated), hence verification failed (and it built successfully against the old shim rather than FTBFS until the new one was published). ** Tags removed: verification-needed-bionic ** Tags added: verification-failed-bionic -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
Along with the shim-signed SRUs, I have also accepted the related shim binary syncs (15+1552672080.a4a1fbe-0ubuntu2). Since those did not have any relevant bug links (as they're syncs from one build), they did not appear as part of this SRU - but they are. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
Hello Julian, or anyone else affected, Accepted shim-signed into xenial-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim- signed/1.33.1~16.04.6 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users. If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested, what testing has been performed on the package and change the tag from verification-needed- xenial to verification-done-xenial. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification- failed-xenial. In either case, without details of your testing we will not be able to proceed. Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance for helping! N.B. The updated package will be released to -updates after the bug(s) fixed by this package have been verified and the package has been in -proposed for a minimum of 7 days. ** Changed in: shim-signed (Ubuntu Xenial) Status: In Progress => Fix Committed ** Tags added: verification-needed-xenial ** Changed in: shim (Ubuntu Bionic) Status: In Progress => Fix Committed ** Changed in: shim (Ubuntu Xenial) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
Hello Julian, or anyone else affected, Accepted shim-signed into bionic-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim- signed/1.37~18.04.7 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users. If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested, what testing has been performed on the package and change the tag from verification-needed- bionic to verification-done-bionic. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification- failed-bionic. In either case, without details of your testing we will not be able to proceed. Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance for helping! N.B. The updated package will be released to -updates after the bug(s) fixed by this package have been verified and the package has been in -proposed for a minimum of 7 days. ** Changed in: shim-signed (Ubuntu Bionic) Status: In Progress => Fix Committed ** Tags added: verification-needed-bionic -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2
Hello Julian, or anyone else affected, Accepted shim-signed into focal-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/shim-signed/1.40.4 in a few hours, and then in the -proposed repository. Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users. If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested, what testing has been performed on the package and change the tag from verification-needed- focal to verification-done-focal. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification- failed-focal. In either case, without details of your testing we will not be able to proceed. Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance for helping! N.B. The updated package will be released to -updates after the bug(s) fixed by this package have been verified and the package has been in -proposed for a minimum of 7 days. ** Changed in: shim-signed (Ubuntu Focal) Status: In Progress => Fix Committed ** Tags added: verification-needed verification-needed-focal ** Changed in: shim (Ubuntu Focal) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1862171 Title: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs