-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 04 May 2024 21:28:21 +0100 Source: shim Binary: shim-helpers-i386-signed-template shim-unsigned Architecture: i386 Version: 15.8-1~deb12u1 Distribution: bookworm Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Steve McIntyre <93sam@debian.org> Description: shim-helpers-i386-signed-template - boot loader to chain-load signed boot loaders (signing template) shim-unsigned - boot loader to chain-load signed boot loaders under Secure Boot Closes: 936009 1046268 1069054 Changes: shim (15.8-1~deb12u1) bookworm; urgency=medium . [ Steve McIntyre ] * Cope with changes in pesign packaging. * New upstream release fixing more bugs * Remove all our previous patches, no longer needed: + Make-sbat_var.S-parse-right-with-buggy-gcc-binutils.patch (now upstream) + Enable-NX.patch (we don't want NX just yet until the whole boot stack is NX-capable) + block-grub-sbat3-debian.patch (not needed now upstream grub SBAT is 4) * Cherry-pick 2 new patches from upstream for grub revocations: + 0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch + 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch * Log if the build is nx-compatible or not * Force shim to use the latest revocations by default to block some older grub / peimage issues. This is: "shim,4\ngrub,4\ngrub.peimage,2\n" * Install a copy of the Debian CA certificate into /usr/share/shim. Closes: #1069054 * Clean up better after build. Closes: #1046268 . [ Bastien Roucariès ] * Port autopkgtest from ubuntu * Import MR-12: "shim-unsigned:amd64 cannot be installed alongside shim-unsigned:i386", thanks to adrian15 adrian15 (Closes: #936009). * Fix debian/watch and check signature Checksums-Sha1: 5364ab7f31c71abadd14a7563ceb36a5b80c54db 11520 shim-helpers-i386-signed-template_15.8-1~deb12u1_i386.deb 044a615d16ec572926a20e999513dc45a50dcbed 398768 shim-unsigned_15.8-1~deb12u1_i386.deb d2aea82efa799aad92eb1241605890980e40dcaf 6798 shim_15.8-1~deb12u1_i386-buildd.buildinfo Checksums-Sha256: 70288b3a55c6ca9e482d754bb0d9e27d05b3b6d1d3935a4e744c160a36f04682 11520 shim-helpers-i386-signed-template_15.8-1~deb12u1_i386.deb 8ea3794b8607cb0e0379079441c15c05ae57e8a71718df08af9680620efe522d 398768 shim-unsigned_15.8-1~deb12u1_i386.deb 80f540a1bb75b13e3b1d291482029d3998717f714db076b6df54357eecb2d981 6798 shim_15.8-1~deb12u1_i386-buildd.buildinfo Files: 3ea8f8028970af2b85ae2704b3698f0e 11520 admin optional shim-helpers-i386-signed-template_15.8-1~deb12u1_i386.deb b6d68cf1725257cb09141203227a9325 398768 admin optional shim-unsigned_15.8-1~deb12u1_i386.deb c4d460f4f50c5abc0ebf59e89af2d3d1 6798 admin optional shim_15.8-1~deb12u1_i386-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEyTfXx8sBpQ0Lh3cUU9a0/LcaTpMFAmY7xrUACgkQU9a0/Lca TpOzww/+JnWGag6X+QRPpYfC9rupyLEfPWI8uIXwBSN77TW+oKErCROjm4rZcfBd j2gA9otEZAleyz0XJ5PCgNpGu6yLcbCdgSr8nFnauSg/FjRC0EV6kadHzDZwz6ZU AwPOoG1al6X4J10oieYNt1ypeq4JdY5RBpWkXk4qSiQo6OPpWIIETMy0+F1nxUVX +sqJyQaaV7m2qgKq9B4MUJZ89SxIBfDsRoyHmg3zOJQLBLhlx6Zguzx3WRYW1K0X c26cNzIFN7XtvzEouIH8+KY7MPVhF1HGNFuZc9H24f9i64GKV+V81p2BO1gvoapD GHvYMjscQVquuAGC5zjjSw/LcVVzFB0vL9zirNvVSx+WA6m4f3/tl/gPudZhbARa O+RVivEpfkgD03Ca+JyQyBplGGYMKi66XwS7iqc0iFqItPrZkItzAy//7SGRgHta 3mv0Oxn3FAvOX0Fd0m8MX0jxrXmD2nTEW69/VHSqLUbvksgmhjIPjslqU0zeHL1E 4YZetAJDds+GBIdNprw7bnDXOp6dhgNsW4KjHTrkaTRLYhi/tePSYxWbuiUX+ls1 gM5+87A/qXbCd35bo78pvNjcVCaCybOQfNw7pVs+UJcXjwvK/eXmbIM/gGg0k7y6 dStUtvyrx2exoMKk54WHSio9t+JdokGorIb6YT3yGNYvXBhbUJI= =Oj3c -----END PGP SIGNATURE-----