[ Dimitri John Ledkov ]
* Ship externally signed shims in the source package, instead of
detached signatures.
[ Steve Langasek ]
* Restore build-time 'cmp' check to assert that the output of sbattach
matches the binary received from Microsoft.
* Include external-$arch.p7c in the clean target.
[ Julian Andres Klode ]
* download-signed: Work around non-HTTP apt sources
* Update to shim 15.4-0ubuntu5:
- Stop addending vendor dbx to MokListXRT during MokListX mirroring. This
is causing systems to run out of EFI storage space, or just hang up
when trying to write it (LP: #1924605) (LP: #1928434)
- Further relax the check for variable mirroring on non-secureboot systems
avoiding boot failures on out of space conditons (pull request #372)
- Don't unhook ExitBootServices() when EBS protection is disabled
(LP: #1931136) (pull request #378)
-- Julian Andres Klode <email address hidden> Tue, 22 Jun 2021 12:19:31 +0200
This bug was fixed in the package shim-signed - 1.48
---------------
shim-signed (1.48) impish; urgency=medium
[ Dimitri John Ledkov ]
* Ship externally signed shims in the source package, instead of
detached signatures.
[ Steve Langasek ]
* Restore build-time 'cmp' check to assert that the output of sbattach
matches the binary received from Microsoft.
* Include external-$arch.p7c in the clean target.
[ Julian Andres Klode ]
* download-signed: Work around non-HTTP apt sources
* Update to shim 15.4-0ubuntu5:
- Stop addending vendor dbx to MokListXRT during MokListX mirroring. This
is causing systems to run out of EFI storage space, or just hang up
when trying to write it (LP: #1924605) (LP: #1928434)
- Further relax the check for variable mirroring on non-secureboot systems
avoiding boot failures on out of space conditons (pull request #372)
- Don't unhook ExitBootServices() when EBS protection is disabled
(LP: #1931136) (pull request #378)
-- Julian Andres Klode <email address hidden> Tue, 22 Jun 2021 12:19:31 +0200