[Bug 2129017] Re: [SRU] Fix incorrect PCR selection list used in nullboot tests
Julian Andres Klode
2129017 at bugs.launchpad.net
Tue Oct 21 13:36:21 UTC 2025
Hello Mate, or anyone else affected,
Accepted ubuntu-boot-test into jammy-proposed. The package will build
now and be available at https://launchpad.net/ubuntu/+source/ubuntu-
boot-test/2.2~22.04 in a few hours, and then in the -proposed
repository.
Please help us by testing this new package. See
https://wiki.ubuntu.com/Testing/EnableProposed for documentation on how
to enable and use -proposed. Your feedback will aid us getting this
update out to other Ubuntu users.
If this package fixes the bug for you, please add a comment to this bug,
mentioning the version of the package you tested, what testing has been
performed on the package and change the tag from verification-needed-
jammy to verification-done-jammy. If it does not fix the bug for you,
please add a comment stating that, and change the tag to verification-
failed-jammy. In either case, without details of your testing we will
not be able to proceed.
Further information regarding the verification process can be found at
https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in
advance for helping!
N.B. The updated package will be released to -updates after the bug(s)
fixed by this package have been verified and the package has been in
-proposed for a minimum of 7 days.
** Tags added: verification-needed-jammy
--
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to ubuntu-boot-test in Ubuntu.
https://bugs.launchpad.net/bugs/2129017
Title:
[SRU] Fix incorrect PCR selection list used in nullboot tests
Status in python-uefivars package in Ubuntu:
Invalid
Status in ubuntu-boot-test package in Ubuntu:
New
Status in python-uefivars source package in Jammy:
Fix Committed
Status in ubuntu-boot-test source package in Jammy:
Fix Committed
Status in python-uefivars source package in Noble:
Invalid
Status in ubuntu-boot-test source package in Noble:
Fix Committed
Bug description:
[ Impact ]
* This is a follow up fix for
https://bugs.launchpad.net/ubuntu/+source/ubuntu-boot-
test/+bug/2123887
* The incorrect PCR selection list was used in the nullboot automated tests due to encrypt-cloud-image
not being passed a "UEFI config".
[ Test Plan ]
* Make sure the autopkgtests pass for ubuntu-boot-test in proposed, and
review the logs to ensure the correct PCR selection list is used.
* ubuntu-boot-test is not intended to be installed or used on end user
machines, thus there isn't any value in traditional manual local tests.
[ Where problems could occur ]
* The ubuntu-boot-test package was never seeded, nor is it intended to be
used by end users.
* The worst case scenario is regression of tests into producing false positives,
but this is unlikely given that we are only changing the nullboot one, which
does not currently test PCR sealing correctly.
[ Other Info ]
* Despite being a universe package, ubuntu-boot-test is maintained by the
Canonical Foundations team.
* Azure CVMs are not supported by Ubuntu on non-LTS releases, thus there is no
value in uploading this change first to devel as no images exist that are
required to enable this test.
* The proper fix for this requires the backporting of the python-uefivars package to Jammy.
This was accepted into the archive alongside the initial ubuntu-boot-test uploads in 2023
here: https://bugs.launchpad.net/ubuntu/+source/python-uefivars/+bug/2044086
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/python-uefivars/+bug/2129017/+subscriptions
More information about the foundations-bugs
mailing list