-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 04 May 2024 21:28:21 +0100 Source: shim Binary: shim-helpers-amd64-signed-template shim-unsigned Architecture: amd64 Version: 15.8-1~deb12u1 Distribution: bookworm Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Steve McIntyre <93sam@debian.org> Description: shim-helpers-amd64-signed-template - boot loader to chain-load signed boot loaders (signing template) shim-unsigned - boot loader to chain-load signed boot loaders under Secure Boot Closes: 936009 1046268 1069054 Changes: shim (15.8-1~deb12u1) bookworm; urgency=medium . [ Steve McIntyre ] * Cope with changes in pesign packaging. * New upstream release fixing more bugs * Remove all our previous patches, no longer needed: + Make-sbat_var.S-parse-right-with-buggy-gcc-binutils.patch (now upstream) + Enable-NX.patch (we don't want NX just yet until the whole boot stack is NX-capable) + block-grub-sbat3-debian.patch (not needed now upstream grub SBAT is 4) * Cherry-pick 2 new patches from upstream for grub revocations: + 0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch + 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch * Log if the build is nx-compatible or not * Force shim to use the latest revocations by default to block some older grub / peimage issues. This is: "shim,4\ngrub,4\ngrub.peimage,2\n" * Install a copy of the Debian CA certificate into /usr/share/shim. Closes: #1069054 * Clean up better after build. Closes: #1046268 . [ Bastien Roucariès ] * Port autopkgtest from ubuntu * Import MR-12: "shim-unsigned:amd64 cannot be installed alongside shim-unsigned:i386", thanks to adrian15 adrian15 (Closes: #936009). * Fix debian/watch and check signature Checksums-Sha1: 6aaf164f8c6fd8fde4bf10f0d567436bdccad518 11528 shim-helpers-amd64-signed-template_15.8-1~deb12u1_amd64.deb 109cb3e6cd07c89034c7a12c63e8505fb85393c0 440260 shim-unsigned_15.8-1~deb12u1_amd64.deb 178b290043e7fbea5d028d5bf3644bac22340af4 6846 shim_15.8-1~deb12u1_amd64-buildd.buildinfo Checksums-Sha256: 4cd91b5bbd81e277d98d9da4bd8f72833100e225f774d33185fb9118fa4c8c2a 11528 shim-helpers-amd64-signed-template_15.8-1~deb12u1_amd64.deb 97e810e1f55cb7f9361a02e06c5adb5385a71c2586c9254184a545f04473fa9e 440260 shim-unsigned_15.8-1~deb12u1_amd64.deb eea9e55b0bd22e34e076e64745af4e1c1d11a97833224aae0c6ada8661610245 6846 shim_15.8-1~deb12u1_amd64-buildd.buildinfo Files: 52fcb4662f5f9175b385e50f1067890a 11528 admin optional shim-helpers-amd64-signed-template_15.8-1~deb12u1_amd64.deb b4189c307006e5159d2edac72d6a8b5a 440260 admin optional shim-unsigned_15.8-1~deb12u1_amd64.deb d08c4596fe590d451d15527e832e145b 6846 admin optional shim_15.8-1~deb12u1_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEgdRoRGwEM09wlaMzOni7ZmUpKEcFAmY7xrsACgkQOni7ZmUp KEci9A/7BNzMBoE89YTfHLbustLMCmq+jnpv9UcyRIfYST59Et/H3Swmj0sgFVUM lLeMXM6vuPA2SXffrE/b7CqfJlc/3LAm6xtDsmoJI/n5dmNhVCwY9tcUdjyAwVmv 4xNzknal4oWBJOAN3/bi+kn6gb6Zk42URLqFG8X9AsCTfUV1PZ/0WQCGoEeJC7vm gILTaZQ8gTGQl8tcGrM8rTgOnPcHAKIhFeXIp8eqc+58KOyYPTpaOjv2pMLyQDS3 xrI/NSpU2pwtOhvr42/SBQ4bYhUMdfnQEwVWE8IswTsriqraRc+FYnOw6xIl6LlO w0q9aRDqov7tXQix2H6r8h6zGhKNwp9T2JFAzc7MBhgfF9lv8dWi8SVaf22JlI2+ flu92tQJExCRs9YFLj8FuqNNczDxxGwHrEF+WPONig280r16qWQHw4msysS/6iAO hwpi5ONb1GHQoTvMzbJD12lR0U/klativ+8q/zNV+wOtVL8EnB+spFUZNJy6DhMB vpURvW+c8Iy85dNBV328fCO8OvJmur9vMftIjK5iuS4KWrq4oI4QuZsQ1rG3qSSu ev1PA+W9kceybyGFJtIWihzWp6+chqLNMO51lH5rTX1kg2m7MP0Rn61hEjO8J/rn CY9AGYYxu6smOsRh8ZKXE5uk72CnBka6/UZAwlO0DD0E7zNpX3I= =aBBg -----END PGP SIGNATURE-----