Commit Graph

260 Commits

Author SHA256 Message Date
Dominique Leuenberger
6708fb2b48 Accepting request 1057935 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1057935
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=111
2023-01-13 23:02:14 +00:00
Joey Lee
8dffdb384c Accepting request 1057932 from home:joeyli:branches:devel:openSUSE:Factory
Removed shim-bsc1198101-opensuse-cert-prompt.patch (bsc#1198101)

OBS-URL: https://build.opensuse.org/request/show/1057932
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=200
2023-01-12 09:08:02 +00:00
Dominique Leuenberger
e19705596e Accepting request 1041832 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1041832
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=110
2022-12-10 20:17:34 +00:00
Joey Lee
171b8de0fc Accepting request 1041831 from home:joeyli:branches:devel:openSUSE:Factory
Modified shim-install, add patches to support full disk encryption: (jsc#PED-922)

OBS-URL: https://build.opensuse.org/request/show/1041831
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=199
2022-12-09 09:53:50 +00:00
Dominique Leuenberger
1db8fca6e8 Accepting request 1037458 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1037458
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=109
2022-11-24 11:22:07 +00:00
Joey Lee
34a594d236 Accepting request 1037456 from home:joeyli:branches:devel:openSUSE:Factory
Add POST_PROCESS_PE_FLAGS=-N to the build command in shim.spec to disable the NX compatibility flag when using post-process-pe because grub2 is not ready. (bsc#1205588)

OBS-URL: https://build.opensuse.org/request/show/1037456
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=198
2022-11-23 07:50:36 +00:00
Dominique Leuenberger
0003b2da45 Accepting request 1037006 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1037006
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=108
2022-11-22 15:09:23 +00:00
Joey Lee
ccd71ae517 Accepting request 1037005 from home:joeyli:branches:devel:openSUSE:Factory
Add shim-Enable-the-NX-compatibility-flag-by-default.patch to enable the NX compatibility flag by default. (jsc#PED-127)

OBS-URL: https://build.opensuse.org/request/show/1037005
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=197
2022-11-21 05:00:30 +00:00
Dominique Leuenberger
37f9322c31 Accepting request 1036529 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1036529
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=107
2022-11-19 17:08:40 +00:00
Joey Lee
958db7043d Accepting request 1036528 from home:joeyli:branches:devel:openSUSE:Factory
Drop upstreamed patch shim-Enable-TDX-measurement-to-RTMR-register.patch (jsc#PED-1273)

OBS-URL: https://build.opensuse.org/request/show/1036528
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=196
2022-11-18 04:37:27 +00:00
Joey Lee
b7972463e9 Accepting request 1036423 from home:joeyli:branches:devel:openSUSE:Factory
Update to 15.7 (bsc#1198458)(jsc#PED-127)

OBS-URL: https://build.opensuse.org/request/show/1036423
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=195
2022-11-17 10:52:49 +00:00
Dominique Leuenberger
d9c97f8d02 Accepting request 1035800 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1035800
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=106
2022-11-16 14:42:21 +00:00
Joey Lee
e8b8c97820 Accepting request 1035798 from home:joeyli:branches:devel:openSUSE:Factory
Add shim-jscPED-127-upgrade-shim-in-SLE15-SP5.patch for backporting the following patches between 15.6 with aa1b289a1a (jsc#PED-127)

OBS-URL: https://build.opensuse.org/request/show/1035798
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=194
2022-11-15 09:50:55 +00:00
Dominique Leuenberger
7640073c6c Accepting request 1007166 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1007166
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=105
2022-10-03 11:44:20 +00:00
Joey Lee
63e4498fc9 Accepting request 1006812 from home:michael-chang:branches:devel:openSUSE:Factory
- shim-install: ensure grub.cfg created is not overwritten after
  installing grub related files

OBS-URL: https://build.opensuse.org/request/show/1006812
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=193
2022-09-30 06:58:17 +00:00
Dominique Leuenberger
f62f42e58e Accepting request 1004027 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/1004027
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=104
2022-09-17 18:10:05 +00:00
Joey Lee
2386bd59cb Accepting request 1002927 from home:KHanich:branches:devel:openSUSE:Factory
- Add logic to shim.spec to only set sbat policy when efivarfs is writeable.
  (bsc#1201066)

OBS-URL: https://build.opensuse.org/request/show/1002927
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=192
2022-09-16 06:35:39 +00:00
Dominique Leuenberger
00c82fc0f9 Accepting request 993204 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/993204
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=103
2022-08-05 17:50:25 +00:00
Joey Lee
a379c7b18b Accepting request 993203 from home:joeyli:branches:devel:openSUSE:Factory
Add logic to shim.spec for detecting --set-sbat-policy option before using mokutil to set sbat policy. (bsc#1202120)

OBS-URL: https://build.opensuse.org/request/show/993203
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=191
2022-08-05 05:58:36 +00:00
Fabian Vogt
221584db81 Accepting request 991619 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/991619
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=102
2022-07-31 21:00:49 +00:00
Joey Lee
63fb624566 Accepting request 991618 from home:joeyli:branches:devel:openSUSE:Factory
Change the URL in SBAT section to mail:security@suse.de. (bsc#1193282)

OBS-URL: https://build.opensuse.org/request/show/991618
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=190
2022-07-29 02:47:14 +00:00
Joey Lee
3bb7cc18a5 Accepting request 991171 from home:joeyli:branches:devel:openSUSE:Factory
Revoked the change in shim.spec for use common SBAT values (boo#1193282) (bsc#1198458)

OBS-URL: https://build.opensuse.org/request/show/991171
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=189
2022-07-26 04:16:19 +00:00
Richard Brown
4181401fdb Accepting request 989068 from devel:openSUSE:Factory
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/989068
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=101
2022-07-18 16:32:49 +00:00
Joey Lee
20e705b979 Accepting request 971203 from home:lnussel:branches:Base:System
- use common SBAT values (boo#1193282)

OBS-URL: https://build.opensuse.org/request/show/971203
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=188
2022-07-14 02:23:22 +00:00
Dominique Leuenberger
8b17f8e390 Accepting request 985419 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/985419
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=100
2022-06-29 14:00:19 +00:00
Joey Lee
7410f7aef0 Accepting request 985418 from home:joeyli:branches:devel:openSUSE:Factory
Update to 15.6 (bsc#1198458)

OBS-URL: https://build.opensuse.org/request/show/985418
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=187
2022-06-28 05:59:27 +00:00
Dominique Leuenberger
1d98db8b74 Accepting request 903340 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/903340
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=99
2021-07-04 20:09:58 +00:00
Gary Ching-Pang Lin
182fd24b7c Accepting request 903339 from home:gary_lin:branches:devel:openSUSE:Factory
avoid deleting the mirrored RT variables (bsc#1187696)

OBS-URL: https://build.opensuse.org/request/show/903339
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=186
2021-07-01 06:13:57 +00:00
Dominique Leuenberger
309e8054a3 Accepting request 901237 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/901237
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=98
2021-06-25 13:00:33 +00:00
Gary Ching-Pang Lin
4e7f70bc3a Accepting request 901235 from home:gary_lin:branches:devel:openSUSE:Factory
- Add shim-bsc1185232-fix-config-table-copying.patch to avoid
  buffer overflow when copying data to the MOK config table
  (bsc#1185232)

OBS-URL: https://build.opensuse.org/request/show/901235
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=185
2021-06-22 02:03:16 +00:00
Gary Ching-Pang Lin
32f6f1f55a Accepting request 901053 from home:gary_lin:branches:devel:openSUSE:Factory
- Add shim-disable-export-vendor-dbx.patch to disable exporting
  vendor-dbx to MokListXRT since writing a large RT variable
  could crash some machines (bsc#1185261)
- Add shim-bsc1187260-fix-efi-1.10-machines.patch to avoid the
  potential crash when calling QueryVariableInfo in EFI 1.10
  machines (bsc#1187260)

- Add shim-fix-aa64-relsz.patch to fix the size of rela sections
  for AArch64
  Fix: https://github.com/rhboot/shim/issues/371

OBS-URL: https://build.opensuse.org/request/show/901053
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=184
2021-06-21 02:58:46 +00:00
Dominique Leuenberger
174d77b398 Accepting request 900009 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/900009
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=97
2021-06-15 14:37:00 +00:00
Gary Ching-Pang Lin
b128f342b9 Accepting request 900008 from home:gary_lin:branches:devel:openSUSE:Factory
ignore the odd LoadOptions length (bsc#1185232)

OBS-URL: https://build.opensuse.org/request/show/900008
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=183
2021-06-15 03:59:23 +00:00
Gary Ching-Pang Lin
b088ad9ddf Accepting request 897356 from home:gary_lin:branches:devel:openSUSE:Factory
- shim-install: reset def_shim_efi to "shim.efi" if the given
  file doesn't exist

OBS-URL: https://build.opensuse.org/request/show/897356
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=182
2021-06-04 08:21:06 +00:00
Dominique Leuenberger
67b777306d Accepting request 895435 from devel:openSUSE:Factory
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/895435
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=96
2021-06-02 20:10:23 +00:00
Gary Ching-Pang Lin
7f83b4b531 Accepting request 894182 from home:gary_lin:branches:devel:openSUSE:Factory
- shim-install: instead of assuming "removable" for Azure, remove
  fallback.efi from \EFI\Boot and copy grub.efi/cfg to \EFI\Boot
  to make \EFI\Boot bootable and keep the boot option created by
  efibootmgr (bsc#1185464, bsc#1185961)

- Add shim-bsc1185261-relax-import_mok_state-check.patch to relax
  the check for import_mok_state() when Secure Boot is off.
  (bsc#1185261)

OBS-URL: https://build.opensuse.org/request/show/894182
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=181
2021-05-19 01:26:58 +00:00
Dominique Leuenberger
9d260d7357 Accepting request 891231 from devel:openSUSE:Factory
- shim-install: always assume "removable" for Azure to avoid the endless reset loop (bsc#1185464)
- relax the maximum variable size check for u-boot (bsc#1185621)
- handle ignore_db and user_insecure_mode correctly (bsc#1185441)

OBS-URL: https://build.opensuse.org/request/show/891231
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=95
2021-05-08 20:07:23 +00:00
Gary Ching-Pang Lin
d24e6a73df Accepting request 891229 from home:gary_lin:branches:devel:openSUSE:Factory
shim-install: always assume "removable" for Azure to avoid the endless reset loop (bsc#1185464)

OBS-URL: https://build.opensuse.org/request/show/891229
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=180
2021-05-07 08:38:12 +00:00
Gary Ching-Pang Lin
f94c2e5bcf Accepting request 890839 from home:gary_lin:branches:devel:openSUSE:Factory
- Add shim-bsc1185621-relax-max-var-sz-check.patch to relax the
  maximum variable size check for u-boot (bsc#1185621)

- Add shim-bsc1185441-fix-handling-of-ignore_db-and-user_insecure_mode.patch
  to handle ignore_db and user_insecure_mode correctly
  (bsc#1185441)

OBS-URL: https://build.opensuse.org/request/show/890839
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=179
2021-05-06 03:35:27 +00:00
Dominique Leuenberger
191992cbed Accepting request 888995 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/888995
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=94
2021-05-02 16:35:23 +00:00
Gary Ching-Pang Lin
14a92e6f61 Accepting request 888994 from home:gary_lin:branches:devel:openSUSE:Factory
- Split the keys in vendor-dbx.bin to vendor-dbx-sles and
  vendor-dbx-opensuse for shim-sles and shim-opensuse to reduce
  the size of MokListXRT (bsc#1185261) 
  + Also update generate-vendor-dbx.sh in dbx-cert.tar.xz

OBS-URL: https://build.opensuse.org/request/show/888994
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=178
2021-04-28 10:01:26 +00:00
Richard Brown
7973583f9b Accepting request 883801 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/883801
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=93
2021-04-10 13:26:12 +00:00
Gary Ching-Pang Lin
0f47283b84 Accepting request 883796 from home:gary_lin:branches:devel:openSUSE:Factory
- avoid the error message during linux system boot (bsc#1184454)
- prevent the build id being added to the binary. That can cause issues with the signature

OBS-URL: https://build.opensuse.org/request/show/883796
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=177
2021-04-08 09:16:46 +00:00
Gary Ching-Pang Lin
1354ba095a Accepting request 882314 from home:gary_lin:branches:devel:openSUSE:Factory
Update to 15.4 (bsc#1182057)

OBS-URL: https://build.opensuse.org/request/show/882314
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=176
2021-03-31 08:55:10 +00:00
Gary Ching-Pang Lin
bbfcbff67b Accepting request 881822 from home:gary_lin:branches:devel:openSUSE:Factory
change the SBAT variable name and enhance the handling of SBAT (bsc#1182057)

OBS-URL: https://build.opensuse.org/request/show/881822
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=175
2021-03-29 07:54:46 +00:00
Gary Ching-Pang Lin
300c690132 Accepting request 880836 from home:gary_lin:branches:devel:openSUSE:Factory
Update the changelog to address a dropped patch

OBS-URL: https://build.opensuse.org/request/show/880836
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=174
2021-03-24 03:33:21 +00:00
Gary Ching-Pang Lin
0fc0214e26 Accepting request 880833 from home:gary_lin:branches:devel:openSUSE:Factory
- Update to 15.3 for SBAT support (bsc#1182057)

OBS-URL: https://build.opensuse.org/request/show/880833
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=173
2021-03-24 03:16:20 +00:00
Dominique Leuenberger
171432bbde Accepting request 878251 from devel:openSUSE:Factory
OBS-URL: https://build.opensuse.org/request/show/878251
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=92
2021-03-15 09:53:37 +00:00
Gary Ching-Pang Lin
b9c4429460 Accepting request 878250 from home:gary_lin:branches:devel:openSUSE:Factory
- Refresh shim-bsc1182776-fix-crash-at-exit.patch to do the cleanup
  also when Secure Boot is disabled (bsc#1183213, bsc#1182776)
- Merged linker-version.pl into timestamp.pl and add the linker
  version to signature files accordingly

OBS-URL: https://build.opensuse.org/request/show/878250
OBS-URL: https://build.opensuse.org/package/show/devel:openSUSE:Factory/shim?expand=0&rev=172
2021-03-11 03:36:34 +00:00
Dominique Leuenberger
94234ea7c9 Accepting request 877920 from devel:openSUSE:Factory
Add shim-bsc1182776-fix-crash-at-exit.patch to fix the potential crash at Exit() (bsc#1182776)

OBS-URL: https://build.opensuse.org/request/show/877920
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/shim?expand=0&rev=91
2021-03-10 07:50:40 +00:00