[Bug 1941888] Re: FFe: sbsigntools 0.9.4

Launchpad Bug Tracker 1941888 at bugs.launchpad.net
Sat Sep 4 02:25:40 UTC 2021


This bug was fixed in the package sbsigntool - 0.9.4-2ubuntu1

---------------
sbsigntool (0.9.4-2ubuntu1) impish; urgency=medium

  * Merge from Debian unstable (LP: #1941888)
    Remaining changes:
    - d/p/ubuntu-kernel-module-signing.patch (rebased on 0.9.4) and
      d/p/ubuntu-kernel-module-signing-fixes.patch (rebased on 0.9.4):
      add the kernel module signing tool to the package.
    - d/p/ubuntu-clear-image-before-use.patch: avoid use of uninitialised
      data causing a startup crash.
    - dp/sbkeysync-Don-t-ignore-errors-from-insert_new_keys.patch: exit non-zero
      upon key insertion failure

sbsigntool (0.9.4-2) experimental; urgency=medium

  * Add patch for RISC-V support.
    Thanks to Heinrich Schuchardt for the patch (LP: #1938438)

sbsigntool (0.9.4-1) experimental; urgency=medium

  * Team upload
  * debian/rules: Add reproducible get-orig-source target
  * New upstream version 0.9.4
  * Drop fix_checksum_calc.patch, applied upstream
  * Use debhelper-compat (= 13) instead of debian/compat 9
  * Remove explicit dh-autoreconf dependency
  * Bump Standards-Version to 4.5.1
  * Add any-riscv64 to Architecture

 -- Heinrich Schuchardt <heinrich.schuchardt at canonical.com>  Wed, 18 Aug
2021 09:47:17 +0200

** Changed in: sbsigntool (Ubuntu)
       Status: Fix Committed => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to sbsigntool in Ubuntu.
https://bugs.launchpad.net/bugs/1941888

Title:
  FFe: sbsigntools 0.9.4

Status in sbsigntool package in Ubuntu:
  Fix Released

Bug description:
  FFe: sbsigntools 0.9.4

  The current sbsigntool-0.9.2-2ubuntu4 package lacks support for the riscv64
  architecture.

  For developing UEFI booting on RISC-V we need these tools.

  Since release 0.9.2 several bugs have been resolved. A major one leads
  to incorrect signatures for EFI binaries.

  0.9.4 brought one additional feature:

  The command sbsign received an additional optional parameter --addcert for
  specifying intermediate certificates.

  I have prepared an upload in my PPA, which builds on all EFI enabled
  architectures including riscv64 and I have tested the package locally
  on riscv64 and amd64 and it works for me. There are no autopackage tests
  available and device certification should test on all relevant
  architectures.

  Please consider a feature freeze exception for sbsigntools 0.9.4.

  sbsigntool 0.9.4-2ubuntu2 is availabe in ppa:xypron/gnu-efi

  Changelog:

  Version 0.9.4

  * sbsign: allow for adding intermediate certificates
  * sbverify: fix verification with intermediate certificates
  * Tests: Add intermediate certificate tests to the sign-verify cases
  * Fix some openssl 1.1.0 deprecated functions
  * sbvarsign: remove unused global variable
  * sbverify: refer to unused function
  * Fix errors on 32 bit
  * Enable -Werror for builds
  * docs: add man page for sbkeysync

  Version 0.9.3

  * README: update git location and add mailing list information
  * sbvarsign: fix "EFI_VARIABLE_AUTHENTICATION_2.TimeStamp.Year" assignment
  * Fix PE/COFF checksum calculation

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/sbsigntool/+bug/1941888/+subscriptions




More information about the foundations-bugs mailing list