[Bug 1931136] Re: Don't unhook ExitBootServices() when EBS protection is disabled

dann frazier 1931136 at bugs.launchpad.net
Mon Jun 28 16:01:43 UTC 2021


As with xenial (see Comment #11), my focal verification just shows that
booting under SB still works:

ubuntu at dannf-shim-f:~$ dpkg-query -W shim-signed
shim-signed	1.40.5+15.4-0ubuntu5
ubuntu at dannf-shim-f:~$ sudo mokutil --sb-state
SecureBoot enabled


** Tags removed: verification-needed-focal
** Tags added: verification-done-focal

** Tags removed: verification-needed
** Tags added: verification-done

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to shim in Ubuntu.
https://bugs.launchpad.net/bugs/1931136

Title:
  Don't unhook ExitBootServices() when EBS protection is disabled

Status in shim package in Ubuntu:
  Fix Released
Status in shim-signed package in Ubuntu:
  Fix Committed
Status in shim source package in Xenial:
  Fix Committed
Status in shim source package in Focal:
  Fix Committed
Status in shim-signed source package in Focal:
  Fix Committed
Status in shim source package in Hirsute:
  Fix Committed

Bug description:
  [Impact]
  This is a regression in shim 15.4 that causes a crash in shim when chainbooting.

  Also, the machine resets when you exit grub, rather than going back to
  the EFI shell when launched from it.

  [Test plan]

  Boot an Ubuntu hirsute image in Secure Boot mode. While this issue was
  originally seen while chainbooting in
  https://github.com/lxc/lxd/issues/8770 - it was shown to be also
  reproducible just by booting a hirsute instance.

  [Where problems could occur]
  In exiting shim, failure to boot, etc.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1931136/+subscriptions



More information about the foundations-bugs mailing list