Netboot initrd is not updated with signed modules

Bug #1799070 reported by Roland Kaufmann
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
debian-installer (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

At the time of writing (21-oct-2018) the distribution directory at

http://ftp.ubuntu.com/ubuntu/dists/bionic-updates/main/signed/linux-amd64/

contains kernels for versions 4.15.0-33.36, 4.15.0-34.37 and 4.15.0-36.39, whereas

http://ftp.ubuntu.com/ubuntu/dists/bionic-updates/main/installer-amd64/current/images/netboot/ubuntu-installer/amd64/initrd.gz

contains modules for kernel version 4.15.0-29.

Thus, a signed UEFI netboot image cannot be constructed for the latest point release of Ubuntu Bionic, as the modules don't match the kernel.

I would expect that *either* the modules in the netboot image were updated when a new kernel version was built, *or* that the old kernels that at one time matched the netboot image were still available for download.

Tags: netboot
description: updated
Revision history for this message
Adam Conrad (adconrad) wrote :

The old kernels that match the netboot image are always available, literally right next to the initrd you pointed to.

Changed in debian-installer (Ubuntu):
status: New → Invalid
Revision history for this message
Roland Kaufmann (rlndkfmn+launchpad) wrote :

It used to be that the kernel in main/installer-amd64 was unsigned, which is why my scripts had to go look in main/signed instead. Apparently this changed at some point, which announcement I missed, and as you say the kernel that is stored together with the netboot image is now signed. I am happy, as a fair bunch of bespoke logic to figure out the correct kernel can now be shown the door, and the script becomes significantly simpler. But, I should have checked this beforehand with sbverify. Mea culpa indeed. Sorry for the hassle.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.