UEFI copies within same archive shouldn't require re-approval

Bug #1068558 reported by Colin Watson
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Launchpad itself
Triaged
Low
Colin Watson

Bug Description

In bug 1016594, it was required that uploads to the primary archive containing a UEFI image tarball should never be auto-approved, in order to allow us to preserve a reasonably Ubuntu-ish upload permissions model without making it trivial for anyone with even the narrowest per-package upload rights to get an arbitrary binary signed with the Canonical UEFI key.

However, this was slightly over the top in that it also affects copies within the same archive. For example, if we publish a security update to GRUB, that will be copied to quantal-updates and the copy must be independently approved, even though the same binary has already been signed with the Canonical key. Similarly, when we opened raring, several UEFI copies landed in the unapproved queue which had already been signed and could have been auto-approved. It'd be nice to eliminate this unnecessary manual work.

Related branches

Colin Watson (cjwatson)
Changed in launchpad:
importance: Undecided → Low
assignee: nobody → Colin Watson (cjwatson)
status: New → In Progress
Revision history for this message
Launchpad QA Bot (lpqabot) wrote :
tags: added: qa-needstesting
Changed in launchpad:
status: In Progress → Fix Committed
Revision history for this message
Colin Watson (cjwatson) wrote :

This doesn't seem to have worked on dogfood, and I'm not quite sure why. I'll investigate later. On the other hand, it hasn't made things any worse as far as I can tell, so qa-ok anyway.

Changed in launchpad:
status: Fix Committed → In Progress
tags: added: qa-ok
removed: qa-needstesting
Colin Watson (cjwatson)
tags: added: uefi
William Grant (wgrant)
tags: added: package-copies
William Grant (wgrant)
Changed in launchpad:
status: In Progress → Triaged
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.