290 Commits

Author SHA256 Message Date
Ana Guerrero
ad40245344 Accepting request 1232808 from devel:openSUSE:Factory
undefine %_enable_debug_packages to fix building with rpm-4.20

OBS-URL: https://build.opensuse.org/request/show/1232808
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=124
2025-01-31 15:01:53 +00:00
2550efcadf - undefine %_enable_debug_packages to fix building with rpm-4.20
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=217
2024-12-20 10:36:18 +00:00
9837b63228 Accepting request 1219481 from devel:openSUSE:Factory
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1219481
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=123
2024-10-31 15:09:15 +00:00
Gary Ching-Pang Lin
b85a3305e7 - Update shim-install to limit the scope of the 'removable'
SL-Micro to the image booting with TPM2 unsealing (bsc#1210382)
  * 769e41d Limit the removable option to encrypted SL-Micro

OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=216
2024-10-15 02:08:00 +00:00
Ana Guerrero
ab4a407325 Accepting request 1201684 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1201684
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=122
2024-09-18 13:26:07 +00:00
Joey Lee
ceaad5e057 - Update shim-install to apply the missing fix for openSUSE Leap
(bsc#1210382)
  * 86b73d1 Fix that bootx64.efi is not updated on Leap
- Update shim-install to use the 'removable' way for SL-Micro
  (bsc#1230316)
  * 433cc4e Always use the removable way for SL-Micro

OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=215
2024-09-18 04:26:12 +00:00
Ana Guerrero
ee4b9ae99c Accepting request 1184771 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1184771
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=121
2024-07-02 16:15:29 +00:00
Tseng
92d5f944ea bugowner: dtseng
Submitting for updating asc files after being signed back from Microsoft

OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=214
2024-07-02 05:35:57 +00:00
Tseng
b2dd022059 bugowner: dtseng
Submitting for updating asc files after being signed back from Microsoft

OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=213
2024-06-25 09:12:15 +00:00
Ana Guerrero
2d8ebccca8 Accepting request 1164003 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1164003
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=120
2024-04-02 14:38:25 +00:00
Joey Lee
4af5b3f4d4 Accepting request 1164001 from home:gary_lin:branches:devel:openSUSE:Factory
- Introduce %shim_use_fde_tpm_helper macro so that the project
  can include the fde-tpm-helper-macros for the build targets
  other than Tumbleweed

OBS-URL: https://build.opensuse.org/request/show/1164001
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=212
2024-04-02 04:26:58 +00:00
0a0bbf3847 Accepting request 1155012 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1155012
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=119
2024-03-06 22:03:16 +00:00
b7db283760 Accepting request 1151489 from home:dimstar:rpm4.20:s
Prepare for RPM 4.20

OBS-URL: https://build.opensuse.org/request/show/1151489
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=211
2024-03-05 09:01:55 +00:00
Ana Guerrero
ddfae9a5c9 Accepting request 1147311 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1147311
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=118
2024-02-18 19:22:58 +00:00
Joey Lee
8f7d539eb7 Accepting request 1147310 from home:joeyli:branches:devel:openSUSE:Factory
Add suffix string of project to filename of included certificates

OBS-URL: https://build.opensuse.org/request/show/1147310
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=210
2024-02-17 10:35:28 +00:00
Ana Guerrero
b2a602e75f Accepting request 1146847 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1146847
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=117
2024-02-15 19:59:36 +00:00
Joey Lee
e7152e6c04 Accepting request 1146844 from home:joeyli:branches:devel:openSUSE:Factory
Sync shim.spec and changelog between openSUSE:Factory/shim with SLE-15-SP3/shim

OBS-URL: https://build.opensuse.org/request/show/1146844
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=209
2024-02-15 13:09:03 +00:00
Joey Lee
05ae7fe0d8 Accepting request 1144843 from home:gary_lin:branches:devel:openSUSE:Factory
- Update shim-install to set the TPM2 SRK algorithm (bsc#1213945)
  92d0f4305df73 Set the SRK algorithm for the TPM2 protector

OBS-URL: https://build.opensuse.org/request/show/1144843
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=208
2024-02-15 08:29:23 +00:00
Joey Lee
e4f7469733 Accepting request 1141279 from home:lnussel:branches:devel:openSUSE:Factory
- Generate dbx during build so we don't include binary files in sources

OBS-URL: https://build.opensuse.org/request/show/1141279
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=207
2024-02-15 08:27:36 +00:00
Ana Guerrero
e6cf2d4dce Accepting request 1144136 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1144136
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=116
2024-02-06 15:32:42 +00:00
Tseng
ffda8d5b51 Accepting request 1143635 from home:gary_lin:branches:devel:openSUSE:Factory
- Limit the requirement of fde-tpm-helper-macros to the distro with
  suse_version 1600 and above (bsc#1219460)

OBS-URL: https://build.opensuse.org/request/show/1143635
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=206
2024-02-05 08:55:58 +00:00
Ana Guerrero
c03e6aa37a Accepting request 1143192 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1143192
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=115
2024-02-01 17:04:12 +00:00
Joey Lee
6e9e2655ab Accepting request 1142576 from home:dtseng:branches:devel:openSUSE:Factory
bugowner: dtseng
Submitting for upgrading shim to v15.8 (bsc#1215099, bsc#1215098,bsc#1215100,bsc#1215101,bsc#1215102,and bsc#1215103)

OBS-URL: https://build.opensuse.org/request/show/1142576
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=205
2024-02-01 07:25:56 +00:00
Ana Guerrero
3ec9adf395 Accepting request 1116629 from devel:openSUSE:Factory
- Don't require grub so shim can still be used with systemd-boot (forwarded request 1115842 from lnussel)

OBS-URL: https://build.opensuse.org/request/show/1116629
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=114
2023-10-10 18:52:13 +00:00
Ludwig Nussel
a86220a02f Accepting request 1115842 from home:lnussel:branches:devel:openSUSE:Factory
- Don't require grub so shim can still be used with systemd-boot

OBS-URL: https://build.opensuse.org/request/show/1115842
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=204
2023-10-10 09:27:16 +00:00
Joey Lee
c5f457c08d Accepting request 1112452 from home:gary_lin:branches:devel:openSUSE:Factory
- Update shim-install to fix boot failure of ext4 root file system
  on RAID10 (bsc#1205855)
   226c94ca5cfca  Use hint in looking for root if possible
- Adopt the macros from fde-tpm-helper-macros to update the
  signature in the sealed key after a bootloader upgrade

The macros package depends on the latest fde-tools:
https://build.opensuse.org/request/show/1112138

OBS-URL: https://build.opensuse.org/request/show/1112452
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=203
2023-09-22 08:46:59 +00:00
b42affaed6 Accepting request 1089032 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1089032
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=113
2023-05-26 18:15:09 +00:00
Gary Ching-Pang Lin
b90dab54cc Accepting request 1087321 from home:gary_lin:branches:devel:openSUSE:Factory
- Update shim-install to amend full disk encryption support
    b540061e041b  Adopt TPM 2.0 Key File for grub2 TPM 2.0 protector
    f2e8143ce831  Use the long name to specify the grub2 key protector
    72830120e5ea  cryptodisk: support TPM authorized policies
    49e7a0d307f3  Do not use tpm_record_pcrs unless the command is in command.lst

OBS-URL: https://build.opensuse.org/request/show/1087321
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=202
2023-05-25 12:41:58 +00:00
6d8249d4ab Accepting request 1078224 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1078224
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=112
2023-04-11 11:50:40 +00:00
Joey Lee
84a3ac6c45 Accepting request 1078223 from home:joeyli:branches:devel:openSUSE:Factory
Removed POST_PROCESS_PE_FLAGS=-N from the build command in shim.spec (bsc#1205588)

OBS-URL: https://build.opensuse.org/request/show/1078223
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=201
2023-04-10 06:10:02 +00:00
6708fb2b48 Accepting request 1057935 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1057935
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=111
2023-01-13 23:02:14 +00:00
Joey Lee
8dffdb384c Accepting request 1057932 from home:joeyli:branches:devel:openSUSE:Factory
Removed shim-bsc1198101-opensuse-cert-prompt.patch (bsc#1198101)

OBS-URL: https://build.opensuse.org/request/show/1057932
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=200
2023-01-12 09:08:02 +00:00
e19705596e Accepting request 1041832 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1041832
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=110
2022-12-10 20:17:34 +00:00
Joey Lee
171b8de0fc Accepting request 1041831 from home:joeyli:branches:devel:openSUSE:Factory
Modified shim-install, add patches to support full disk encryption: (jsc#PED-922)

OBS-URL: https://build.opensuse.org/request/show/1041831
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=199
2022-12-09 09:53:50 +00:00
1db8fca6e8 Accepting request 1037458 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1037458
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=109
2022-11-24 11:22:07 +00:00
Joey Lee
34a594d236 Accepting request 1037456 from home:joeyli:branches:devel:openSUSE:Factory
Add POST_PROCESS_PE_FLAGS=-N to the build command in shim.spec to disable the NX compatibility flag when using post-process-pe because grub2 is not ready. (bsc#1205588)

OBS-URL: https://build.opensuse.org/request/show/1037456
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=198
2022-11-23 07:50:36 +00:00
0003b2da45 Accepting request 1037006 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1037006
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=108
2022-11-22 15:09:23 +00:00
Joey Lee
ccd71ae517 Accepting request 1037005 from home:joeyli:branches:devel:openSUSE:Factory
Add shim-Enable-the-NX-compatibility-flag-by-default.patch to enable the NX compatibility flag by default. (jsc#PED-127)

OBS-URL: https://build.opensuse.org/request/show/1037005
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=197
2022-11-21 05:00:30 +00:00
37f9322c31 Accepting request 1036529 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1036529
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=107
2022-11-19 17:08:40 +00:00
Joey Lee
958db7043d Accepting request 1036528 from home:joeyli:branches:devel:openSUSE:Factory
Drop upstreamed patch shim-Enable-TDX-measurement-to-RTMR-register.patch (jsc#PED-1273)

OBS-URL: https://build.opensuse.org/request/show/1036528
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=196
2022-11-18 04:37:27 +00:00
Joey Lee
b7972463e9 Accepting request 1036423 from home:joeyli:branches:devel:openSUSE:Factory
Update to 15.7 (bsc#1198458)(jsc#PED-127)

OBS-URL: https://build.opensuse.org/request/show/1036423
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=195
2022-11-17 10:52:49 +00:00
d9c97f8d02 Accepting request 1035800 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1035800
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=106
2022-11-16 14:42:21 +00:00
Joey Lee
e8b8c97820 Accepting request 1035798 from home:joeyli:branches:devel:openSUSE:Factory
Add shim-jscPED-127-upgrade-shim-in-SLE15-SP5.patch for backporting the following patches between 15.6 with aa1b289a1a (jsc#PED-127)

OBS-URL: https://build.opensuse.org/request/show/1035798
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=194
2022-11-15 09:50:55 +00:00
7640073c6c Accepting request 1007166 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1007166
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=105
2022-10-03 11:44:20 +00:00
Joey Lee
63e4498fc9 Accepting request 1006812 from home:michael-chang:branches:devel:openSUSE:Factory
- shim-install: ensure grub.cfg created is not overwritten after
  installing grub related files

OBS-URL: https://build.opensuse.org/request/show/1006812
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=193
2022-09-30 06:58:17 +00:00
f62f42e58e Accepting request 1004027 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1004027
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=104
2022-09-17 18:10:05 +00:00
Joey Lee
2386bd59cb Accepting request 1002927 from home:KHanich:branches:devel:openSUSE:Factory
- Add logic to shim.spec to only set sbat policy when efivarfs is writeable.
  (bsc#1201066)

OBS-URL: https://build.opensuse.org/request/show/1002927
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=192
2022-09-16 06:35:39 +00:00
00c82fc0f9 Accepting request 993204 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/993204
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=103
2022-08-05 17:50:25 +00:00
Joey Lee
a379c7b18b Accepting request 993203 from home:joeyli:branches:devel:openSUSE:Factory
Add logic to shim.spec for detecting --set-sbat-policy option before using mokutil to set sbat policy. (bsc#1202120)

OBS-URL: https://build.opensuse.org/request/show/993203
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=191
2022-08-05 05:58:36 +00:00
221584db81 Accepting request 991619 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/991619
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=102
2022-07-31 21:00:49 +00:00