[Bug 2129017] [NEW] [SRU] Fix incorrect PCR selection list used in nullboot tests

Mate Kukri 2129017 at bugs.launchpad.net
Mon Oct 20 10:22:15 UTC 2025


Public bug reported:

[ Impact ]

 * This is a follow up fix for
https://bugs.launchpad.net/ubuntu/+source/ubuntu-boot-test/+bug/2123887

 * The incorrect PCR selection list was used in the nullboot automated tests due to encrypt-cloud-image
   not being passed a "UEFI config".

[ Test Plan ]

 * Make sure the autopkgtests pass for ubuntu-boot-test in proposed, and
   review the logs to ensure the correct PCR selection list is used.

 * ubuntu-boot-test is not intended to be installed or used on end user
   machines, thus there isn't any value in traditional manual local tests.

[ Where problems could occur ]

 * The ubuntu-boot-test package was never seeded, nor is it intended to be
   used by end users.

 * The worst case scenario is regression of tests into producing false positives,
   but this is unlikely given that we are only changing the nullboot one, which
   does not currently test PCR sealing correctly. 

[ Other Info ]

 * Despite being a universe package, ubuntu-boot-test is maintained by the
   Canonical Foundations team.

 * Azure CVMs are not supported by Ubuntu on non-LTS releases, thus there is no
   value in uploading this change first to devel as no images exist that are
   required to enable this test.

 * The proper fix for this requires the backporting of the python-uefivars package to Jammy.
   This was accepted into the archive alongside the initial ubuntu-boot-test uploads in 2023
   here: https://bugs.launchpad.net/ubuntu/+source/python-uefivars/+bug/2044086

** Affects: python-uefivars (Ubuntu)
     Importance: Undecided
         Status: Invalid

** Affects: ubuntu-boot-test (Ubuntu)
     Importance: Undecided
         Status: New

** Affects: python-uefivars (Ubuntu Jammy)
     Importance: Undecided
         Status: New

** Affects: ubuntu-boot-test (Ubuntu Jammy)
     Importance: Undecided
         Status: New

** Affects: python-uefivars (Ubuntu Noble)
     Importance: Undecided
         Status: Invalid

** Affects: ubuntu-boot-test (Ubuntu Noble)
     Importance: Undecided
         Status: New

** Also affects: python-uefivars (Ubuntu)
   Importance: Undecided
       Status: New

** Also affects: ubuntu-boot-test (Ubuntu Jammy)
   Importance: Undecided
       Status: New

** Also affects: python-uefivars (Ubuntu Jammy)
   Importance: Undecided
       Status: New

** Also affects: ubuntu-boot-test (Ubuntu Noble)
   Importance: Undecided
       Status: New

** Also affects: python-uefivars (Ubuntu Noble)
   Importance: Undecided
       Status: New

** Changed in: python-uefivars (Ubuntu)
       Status: New => Invalid

** Changed in: python-uefivars (Ubuntu Noble)
       Status: New => Invalid

** Summary changed:

- [SRU] Fix incorrect PCR selection used in nullboot tests
+ [SRU] Fix incorrect PCR selection list used in nullboot tests

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to ubuntu-boot-test in Ubuntu.
https://bugs.launchpad.net/bugs/2129017

Title:
  [SRU] Fix incorrect PCR selection list used in nullboot tests

Status in python-uefivars package in Ubuntu:
  Invalid
Status in ubuntu-boot-test package in Ubuntu:
  New
Status in python-uefivars source package in Jammy:
  New
Status in ubuntu-boot-test source package in Jammy:
  New
Status in python-uefivars source package in Noble:
  Invalid
Status in ubuntu-boot-test source package in Noble:
  New

Bug description:
  [ Impact ]

   * This is a follow up fix for
  https://bugs.launchpad.net/ubuntu/+source/ubuntu-boot-
  test/+bug/2123887

   * The incorrect PCR selection list was used in the nullboot automated tests due to encrypt-cloud-image
     not being passed a "UEFI config".

  [ Test Plan ]

   * Make sure the autopkgtests pass for ubuntu-boot-test in proposed, and
     review the logs to ensure the correct PCR selection list is used.

   * ubuntu-boot-test is not intended to be installed or used on end user
     machines, thus there isn't any value in traditional manual local tests.

  [ Where problems could occur ]

   * The ubuntu-boot-test package was never seeded, nor is it intended to be
     used by end users.

   * The worst case scenario is regression of tests into producing false positives,
     but this is unlikely given that we are only changing the nullboot one, which
     does not currently test PCR sealing correctly. 

  [ Other Info ]

   * Despite being a universe package, ubuntu-boot-test is maintained by the
     Canonical Foundations team.

   * Azure CVMs are not supported by Ubuntu on non-LTS releases, thus there is no
     value in uploading this change first to devel as no images exist that are
     required to enable this test.

   * The proper fix for this requires the backporting of the python-uefivars package to Jammy.
     This was accepted into the archive alongside the initial ubuntu-boot-test uploads in 2023
     here: https://bugs.launchpad.net/ubuntu/+source/python-uefivars/+bug/2044086

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/python-uefivars/+bug/2129017/+subscriptions




More information about the foundations-bugs mailing list