[Bug 1862171] Re: [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2

Julian Andres Klode 1862171 at bugs.launchpad.net
Wed Aug 26 10:22:30 UTC 2020


The shim-signed SRU for bionic accidentally contained the old
shimx64.efi (only shimaa64.efi was updated), hence verification failed
(and it built successfully against the old shim rather than FTBFS until
the new one was published).


** Tags removed: verification-needed-bionic
** Tags added: verification-failed-bionic

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to shim in Ubuntu.
https://bugs.launchpad.net/bugs/1862171

Title:
  [SRU] shim 15+1552672080.a4a1fbe-0ubuntu2

Status in shim package in Ubuntu:
  Fix Released
Status in shim-signed package in Ubuntu:
  Fix Released
Status in shim source package in Xenial:
  Fix Committed
Status in shim-signed source package in Xenial:
  Fix Committed
Status in shim source package in Bionic:
  Fix Committed
Status in shim-signed source package in Bionic:
  Fix Committed
Status in shim source package in Focal:
  Fix Committed
Status in shim-signed source package in Focal:
  Fix Committed
Status in shim source package in Groovy:
  Fix Released
Status in shim-signed source package in Groovy:
  Fix Released

Bug description:
  [Impact]
  New shim, various upstream fixes, fixes support for ARM64, also see bionic arm64 SRU bug: LP: #1890813.

  [Test case]

  Roughly

  https://wiki.ubuntu.com/UEFI/SecureBoot/ShimUpdateProcess/TestPlan

  but I certainly don't have any clue about the maas one.

  [Regression potential]
  - System might not boot anymore
  - System might not boot some helpers like fwupd anymore (which was a regression in ubuntu1 we fixed)
  - New security bugs that make shim load unsigned stuff are of course possible too

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1862171/+subscriptions



More information about the foundations-bugs mailing list