Commit Graph

281 Commits

Author SHA256 Message Date
Ana Guerrero
2d8ebccca8 Accepting request 1164003 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1164003
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=120
2024-04-02 14:38:25 +00:00
Joey Lee
4af5b3f4d4 Accepting request 1164001 from home:gary_lin:branches:devel:openSUSE:Factory
- Introduce %shim_use_fde_tpm_helper macro so that the project
  can include the fde-tpm-helper-macros for the build targets
  other than Tumbleweed

OBS-URL: https://build.opensuse.org/request/show/1164001
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=212
2024-04-02 04:26:58 +00:00
Dominique Leuenberger
0a0bbf3847 Accepting request 1155012 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1155012
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=119
2024-03-06 22:03:16 +00:00
b7db283760 Accepting request 1151489 from home:dimstar:rpm4.20:s
Prepare for RPM 4.20

OBS-URL: https://build.opensuse.org/request/show/1151489
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=211
2024-03-05 09:01:55 +00:00
Ana Guerrero
ddfae9a5c9 Accepting request 1147311 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1147311
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=118
2024-02-18 19:22:58 +00:00
Joey Lee
8f7d539eb7 Accepting request 1147310 from home:joeyli:branches:devel:openSUSE:Factory
Add suffix string of project to filename of included certificates

OBS-URL: https://build.opensuse.org/request/show/1147310
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=210
2024-02-17 10:35:28 +00:00
Ana Guerrero
b2a602e75f Accepting request 1146847 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1146847
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=117
2024-02-15 19:59:36 +00:00
Joey Lee
e7152e6c04 Accepting request 1146844 from home:joeyli:branches:devel:openSUSE:Factory
Sync shim.spec and changelog between openSUSE:Factory/shim with SLE-15-SP3/shim

OBS-URL: https://build.opensuse.org/request/show/1146844
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=209
2024-02-15 13:09:03 +00:00
Joey Lee
05ae7fe0d8 Accepting request 1144843 from home:gary_lin:branches:devel:openSUSE:Factory
- Update shim-install to set the TPM2 SRK algorithm (bsc#1213945)
  92d0f4305df73 Set the SRK algorithm for the TPM2 protector

OBS-URL: https://build.opensuse.org/request/show/1144843
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=208
2024-02-15 08:29:23 +00:00
Joey Lee
e4f7469733 Accepting request 1141279 from home:lnussel:branches:devel:openSUSE:Factory
- Generate dbx during build so we don't include binary files in sources

OBS-URL: https://build.opensuse.org/request/show/1141279
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=207
2024-02-15 08:27:36 +00:00
Ana Guerrero
e6cf2d4dce Accepting request 1144136 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1144136
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=116
2024-02-06 15:32:42 +00:00
Tseng
ffda8d5b51 Accepting request 1143635 from home:gary_lin:branches:devel:openSUSE:Factory
- Limit the requirement of fde-tpm-helper-macros to the distro with
  suse_version 1600 and above (bsc#1219460)

OBS-URL: https://build.opensuse.org/request/show/1143635
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=206
2024-02-05 08:55:58 +00:00
Ana Guerrero
c03e6aa37a Accepting request 1143192 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1143192
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=115
2024-02-01 17:04:12 +00:00
Joey Lee
6e9e2655ab Accepting request 1142576 from home:dtseng:branches:devel:openSUSE:Factory
bugowner: dtseng
Submitting for upgrading shim to v15.8 (bsc#1215099, bsc#1215098,bsc#1215100,bsc#1215101,bsc#1215102,and bsc#1215103)

OBS-URL: https://build.opensuse.org/request/show/1142576
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=205
2024-02-01 07:25:56 +00:00
Ana Guerrero
3ec9adf395 Accepting request 1116629 from devel:openSUSE:Factory
- Don't require grub so shim can still be used with systemd-boot (forwarded request 1115842 from lnussel)

OBS-URL: https://build.opensuse.org/request/show/1116629
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=114
2023-10-10 18:52:13 +00:00
Ludwig Nussel
a86220a02f Accepting request 1115842 from home:lnussel:branches:devel:openSUSE:Factory
- Don't require grub so shim can still be used with systemd-boot

OBS-URL: https://build.opensuse.org/request/show/1115842
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=204
2023-10-10 09:27:16 +00:00
Joey Lee
c5f457c08d Accepting request 1112452 from home:gary_lin:branches:devel:openSUSE:Factory
- Update shim-install to fix boot failure of ext4 root file system
  on RAID10 (bsc#1205855)
   226c94ca5cfca  Use hint in looking for root if possible
- Adopt the macros from fde-tpm-helper-macros to update the
  signature in the sealed key after a bootloader upgrade

The macros package depends on the latest fde-tools:
https://build.opensuse.org/request/show/1112138

OBS-URL: https://build.opensuse.org/request/show/1112452
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=203
2023-09-22 08:46:59 +00:00
Dominique Leuenberger
b42affaed6 Accepting request 1089032 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1089032
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=113
2023-05-26 18:15:09 +00:00
Gary Ching-Pang Lin
b90dab54cc Accepting request 1087321 from home:gary_lin:branches:devel:openSUSE:Factory
- Update shim-install to amend full disk encryption support
    b540061e041b  Adopt TPM 2.0 Key File for grub2 TPM 2.0 protector
    f2e8143ce831  Use the long name to specify the grub2 key protector
    72830120e5ea  cryptodisk: support TPM authorized policies
    49e7a0d307f3  Do not use tpm_record_pcrs unless the command is in command.lst

OBS-URL: https://build.opensuse.org/request/show/1087321
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=202
2023-05-25 12:41:58 +00:00
Dominique Leuenberger
6d8249d4ab Accepting request 1078224 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1078224
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=112
2023-04-11 11:50:40 +00:00
Joey Lee
84a3ac6c45 Accepting request 1078223 from home:joeyli:branches:devel:openSUSE:Factory
Removed POST_PROCESS_PE_FLAGS=-N from the build command in shim.spec (bsc#1205588)

OBS-URL: https://build.opensuse.org/request/show/1078223
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=201
2023-04-10 06:10:02 +00:00
Dominique Leuenberger
6708fb2b48 Accepting request 1057935 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1057935
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=111
2023-01-13 23:02:14 +00:00
Joey Lee
8dffdb384c Accepting request 1057932 from home:joeyli:branches:devel:openSUSE:Factory
Removed shim-bsc1198101-opensuse-cert-prompt.patch (bsc#1198101)

OBS-URL: https://build.opensuse.org/request/show/1057932
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=200
2023-01-12 09:08:02 +00:00
Dominique Leuenberger
e19705596e Accepting request 1041832 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1041832
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=110
2022-12-10 20:17:34 +00:00
Joey Lee
171b8de0fc Accepting request 1041831 from home:joeyli:branches:devel:openSUSE:Factory
Modified shim-install, add patches to support full disk encryption: (jsc#PED-922)

OBS-URL: https://build.opensuse.org/request/show/1041831
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=199
2022-12-09 09:53:50 +00:00
Dominique Leuenberger
1db8fca6e8 Accepting request 1037458 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1037458
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=109
2022-11-24 11:22:07 +00:00
Joey Lee
34a594d236 Accepting request 1037456 from home:joeyli:branches:devel:openSUSE:Factory
Add POST_PROCESS_PE_FLAGS=-N to the build command in shim.spec to disable the NX compatibility flag when using post-process-pe because grub2 is not ready. (bsc#1205588)

OBS-URL: https://build.opensuse.org/request/show/1037456
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=198
2022-11-23 07:50:36 +00:00
Dominique Leuenberger
0003b2da45 Accepting request 1037006 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1037006
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=108
2022-11-22 15:09:23 +00:00
Joey Lee
ccd71ae517 Accepting request 1037005 from home:joeyli:branches:devel:openSUSE:Factory
Add shim-Enable-the-NX-compatibility-flag-by-default.patch to enable the NX compatibility flag by default. (jsc#PED-127)

OBS-URL: https://build.opensuse.org/request/show/1037005
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=197
2022-11-21 05:00:30 +00:00
Dominique Leuenberger
37f9322c31 Accepting request 1036529 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1036529
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=107
2022-11-19 17:08:40 +00:00
Joey Lee
958db7043d Accepting request 1036528 from home:joeyli:branches:devel:openSUSE:Factory
Drop upstreamed patch shim-Enable-TDX-measurement-to-RTMR-register.patch (jsc#PED-1273)

OBS-URL: https://build.opensuse.org/request/show/1036528
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=196
2022-11-18 04:37:27 +00:00
Joey Lee
b7972463e9 Accepting request 1036423 from home:joeyli:branches:devel:openSUSE:Factory
Update to 15.7 (bsc#1198458)(jsc#PED-127)

OBS-URL: https://build.opensuse.org/request/show/1036423
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=195
2022-11-17 10:52:49 +00:00
Dominique Leuenberger
d9c97f8d02 Accepting request 1035800 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1035800
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=106
2022-11-16 14:42:21 +00:00
Joey Lee
e8b8c97820 Accepting request 1035798 from home:joeyli:branches:devel:openSUSE:Factory
Add shim-jscPED-127-upgrade-shim-in-SLE15-SP5.patch for backporting the following patches between 15.6 with aa1b289a1a (jsc#PED-127)

OBS-URL: https://build.opensuse.org/request/show/1035798
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=194
2022-11-15 09:50:55 +00:00
Dominique Leuenberger
7640073c6c Accepting request 1007166 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1007166
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=105
2022-10-03 11:44:20 +00:00
Joey Lee
63e4498fc9 Accepting request 1006812 from home:michael-chang:branches:devel:openSUSE:Factory
- shim-install: ensure grub.cfg created is not overwritten after
  installing grub related files

OBS-URL: https://build.opensuse.org/request/show/1006812
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=193
2022-09-30 06:58:17 +00:00
Dominique Leuenberger
f62f42e58e Accepting request 1004027 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1004027
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=104
2022-09-17 18:10:05 +00:00
Joey Lee
2386bd59cb Accepting request 1002927 from home:KHanich:branches:devel:openSUSE:Factory
- Add logic to shim.spec to only set sbat policy when efivarfs is writeable.
  (bsc#1201066)

OBS-URL: https://build.opensuse.org/request/show/1002927
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=192
2022-09-16 06:35:39 +00:00
Dominique Leuenberger
00c82fc0f9 Accepting request 993204 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/993204
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=103
2022-08-05 17:50:25 +00:00
Joey Lee
a379c7b18b Accepting request 993203 from home:joeyli:branches:devel:openSUSE:Factory
Add logic to shim.spec for detecting --set-sbat-policy option before using mokutil to set sbat policy. (bsc#1202120)

OBS-URL: https://build.opensuse.org/request/show/993203
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=191
2022-08-05 05:58:36 +00:00
Fabian Vogt
221584db81 Accepting request 991619 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/991619
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=102
2022-07-31 21:00:49 +00:00
Joey Lee
63fb624566 Accepting request 991618 from home:joeyli:branches:devel:openSUSE:Factory
Change the URL in SBAT section to mail:security@suse.de. (bsc#1193282)

OBS-URL: https://build.opensuse.org/request/show/991618
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=190
2022-07-29 02:47:14 +00:00
Joey Lee
3bb7cc18a5 Accepting request 991171 from home:joeyli:branches:devel:openSUSE:Factory
Revoked the change in shim.spec for use common SBAT values (boo#1193282) (bsc#1198458)

OBS-URL: https://build.opensuse.org/request/show/991171
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=189
2022-07-26 04:16:19 +00:00
Richard Brown
4181401fdb Accepting request 989068 from devel:openSUSE:Factory
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/989068
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=101
2022-07-18 16:32:49 +00:00
Joey Lee
20e705b979 Accepting request 971203 from home:lnussel:branches:Base:System
- use common SBAT values (boo#1193282)

OBS-URL: https://build.opensuse.org/request/show/971203
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=188
2022-07-14 02:23:22 +00:00
Dominique Leuenberger
8b17f8e390 Accepting request 985419 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/985419
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=100
2022-06-29 14:00:19 +00:00
Joey Lee
7410f7aef0 Accepting request 985418 from home:joeyli:branches:devel:openSUSE:Factory
Update to 15.6 (bsc#1198458)

OBS-URL: https://build.opensuse.org/request/show/985418
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=187
2022-06-28 05:59:27 +00:00
Dominique Leuenberger
1d98db8b74 Accepting request 903340 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/903340
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=99
2021-07-04 20:09:58 +00:00
Gary Ching-Pang Lin
182fd24b7c Accepting request 903339 from home:gary_lin:branches:devel:openSUSE:Factory
avoid deleting the mirrored RT variables (bsc#1187696)

OBS-URL: https://build.opensuse.org/request/show/903339
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=186
2021-07-01 06:13:57 +00:00
Dominique Leuenberger
309e8054a3 Accepting request 901237 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/901237
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=98
2021-06-25 13:00:33 +00:00