[Bug 2011808] Re: [SRU] [HWE] fwupd-efi/1:1.4-0ubuntu0.1 tracker
Launchpad Bug Tracker
2011808 at bugs.launchpad.net
Tue Jun 20 07:41:56 UTC 2023
This bug was fixed in the package fwupd-signed - 1.51.1~18.04.1
---------------
fwupd-signed (1.51.1~18.04.1) bionic; urgency=medium
* Rebuild against fwupd-efi 1:1.4-0ubuntu0.1 (LP: #2011808)
* Install binaries to /usr/lib/fwupd on bionic for compatibility with
fwupd 1.2.
fwupd-signed (1.51) lunar; urgency=medium
* Remove i386 and armhf from the architecture list
* Check that we are signing the correct version of fwupd and it is not revoked
fwupd-signed (1.48) lunar; urgency=medium
[ Julian Andres Klode ]
* Rebuild for 2022v1 resigning (LP: #2003365)
[ Andy Whitcroft ]
* Fix signing artifact download when faced with an authenticated archive
pool. Switch to using common download-signed from grub2/kernel.
fwupd-signed (1.44) jammy; urgency=medium
* Built-Using must reference the source package, not binary packages.
* Manually include the epoch in the version number for Built-Using,
since for some reason this is not included in the version file published
for the EFI binaries.
fwupd-signed (1.43) jammy; urgency=medium
* remove fwupd-unsigned from Recommends of fwupd-signed deb. (LP:
#1960783)
fwupd-signed (1.42) jammy; urgency=medium
* Adjust dependency requirements. Since the package is decoupled from
fwupd now, the version it needs to depend on doesn't need to match
the package version.
fwupd-signed (1.41) jammy; urgency=medium
* Build depends on fwupd-unsigned 1:1.1-3 (LP: #1955386)
* Adjust download script to download candidate version instead of from
"current" symlink
-- Julian Andres Klode <juliank at ubuntu.com> Tue, 07 Mar 2023 13:32:57
+0100
--
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to fwupd-signed in Ubuntu.
https://bugs.launchpad.net/bugs/2011808
Title:
[SRU] [HWE] fwupd-efi/1:1.4-0ubuntu0.1 tracker
Status in fwupd-efi package in Ubuntu:
Fix Released
Status in fwupd-signed package in Ubuntu:
Fix Released
Status in fwupd-efi source package in Bionic:
Fix Released
Status in fwupd-signed source package in Bionic:
Fix Released
Status in fwupd-efi source package in Focal:
Fix Released
Status in fwupd-signed source package in Focal:
Fix Released
Status in fwupd-efi source package in Jammy:
Fix Released
Status in fwupd-signed source package in Jammy:
Fix Released
Status in fwupd-efi source package in Kinetic:
Fix Released
Status in fwupd-signed source package in Kinetic:
Fix Released
Status in fwupd-efi source package in Lunar:
Fix Released
Status in fwupd-signed source package in Lunar:
Fix Released
Bug description:
[Impact]
fwupd-efi 1.4 fixes issues with firmware updates on some hardware and is the first release with the NX bit set.
[[Release Notes]]
## 1.3
This release fixes the following bugs:
Fix a regression when applying updates on an HP M60
Fix the ARM system crt0 name
Show the version when starting fwupd-efi
## 1.4
This release fixes the following bugs:
Add additional checks for incompatible CRT0
Align sections to 512 bytes
Generate images that are NX compatible
Use manual symbols mode on ARM32
Use objcopy to build arm/aarch64 binaries for new binutils
[Workflow]
fwupd-efi is built in ppa:ubuntu-uefi-team/ubuntu/ppa against the security pocket in kinetic only and then binary copied following the in-progress signed boot asset workflow. fwupd-signed are built in the signing PPA in each release separately.
[Test plan]
- Boot it in the VM
- Boot it on real hardware (Julian can check built binary on ThinkPad T14 G3 AMD)
[Where problems could occur]
fwupd efi binary could regress on some platforms if there's bugs, preventing people on those platforms from upgrading their firmware.
[See also]
bug 2011804 for the related gnu-efi update.
[Other info]
We branched kinetic fwupd-signed packaging off a bit, and hence the versioning is now 1.51.1 (lunar is at 1.52), and it is that 1.51.1 that gets also backported to older releases (reuploaded with ~22.04.1 and similar).
Some changes were needed for the SRUs due to the fwupd-unsigned build-
dep being to strong in 1.52, and having to install binaries to
/usr/lib on bionic.
This brings it in line with grub2-signed., which also maintains one
devel series and one stable series.
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/fwupd-efi/+bug/2011808/+subscriptions
More information about the foundations-bugs
mailing list