Age | Commit message (Collapse) | Author | |
---|---|---|---|
2019-03-11 | Correct maintainer address in signing template | Ansgar Burchardt | |
2019-03-09 | Prepare Debian release 15+1533136590.3beb971-4debian/15+1533136590.3beb971-4 | Steve McIntyre | |
Force a no-change rebuild on all arches with a source-only upload | |||
2019-03-09 | Prepare Debian release 15+1533136590.3beb971-3debian/15+1533136590.3beb971-3 | Steve McIntyre | |
2019-03-08 | Update the signing-template JSON metadata | Steve McIntyre | |
Move all the data under a new top-level "packages" key Add an empty "trusted_certs" key - the helper binaries do not do any further verification with an embedded key. | |||
2019-03-07 | Merge branch 'rename-helpers' into 'master' | Steve McIntyre | |
Rename all the packages containg the helper binaries See merge request efi-team/shim!2 | |||
2019-03-06 | Rename all the packages containg the helper binaries | Steve McIntyre | |
Remove potential confusion with shim-signed. We will now end up with shim-helpers-$arch-signed to make it clear that they just contain the helper binaries (fb.efi and mm.efi) | |||
2019-03-06 | Change maintenance address to be the EFI team | Steve McIntyre | |
Add me and vorlon to the Uploaders list | |||
2019-03-06 | Typo fix: s,singing,signing,g | Steve McIntyre | |
2019-02-15 | Add uname.patch to avoid architecture variability | Luca Boccassi | |
Signed-off-by: Luca Boccassi <bluca@debian.org> | |||
2019-02-15 | Include /usr/share/dpkg/architecture.mk instead of shelling out. | Luca Boccassi | |
2019-02-15 | Override lintian error about template rules file | Luca Boccassi | |
Lintian parses the shebang in the rules files of the templates packages and complains that there is no dependency on make. But they are special packages, so override it. | |||
2019-02-15 | Add shim-$arch-signed-template support | Philipp Hahn | |
for getting the MOK-manager and fall-back binary to be signed by Debians singing service instead of using an ephemeral key. Closes: #922228 | |||
2019-02-15 | Rename to shim-unsigned | Philipp Hahn | |
as all EFI binaries are now unsigned. They are useless to any normal user as - shim is useless without being signed by an external UEFI CA. - mm and fb won't be loaded by shim as they are now no longer linked to corresponding shim by the ephemeral key any longer. | |||
2019-02-15 | Disable ephemeral key on Debian | Philipp Hahn | |
shim creates an ephemeral key, which gets embedded into shim and is used to sign the corresponding mok-manager (mm*.efi) and fall-back-manager (fb*.efi). This makes the build unreproducible. For Debian we will get those two binaries signed by our Debian-UEFI-CA, which is the primary (and only) key embedded in shim. | |||
2019-02-15 | debian/rules: fixing permissions no longer required | Philipp Hahn | |
as Makefiles used "install -m 0644" by now. | |||
2019-02-11 | releasing package shim version 15+1533136590.3beb971-2debian/15+1533136590.3beb971-2 | Steve Langasek | |
2019-02-10 | Update debian/copyright (drop reference to file no longer in source) | Steve Langasek | |
2019-02-10 | Update Standards-Version. | Steve Langasek | |
2019-02-10 | Ensure DEB_HOST_ARCH is set even if not present in the environment. | Steve Langasek | |
2019-02-10 | Enable build for i386. | Steve Langasek | |
2019-02-10 | Fix debian/rules syntax for arm64 build. | Steve Langasek | |
2019-02-10 | Update VCS to point to salsa. | Steve Langasek | |
2019-02-10 | Update debian/watch. | Steve Langasek | |
2019-02-09 | * New upstream release.debian/15+1533136590.3beb971-1 | Steve Langasek | |
- debian/patches/second-stage-path: dropped; the default loader path now includes an arch suffix. - debian/patches/sbsigntool-no-pesign: dropped; no longer needed. * Drop remaining patches that were not being applied. * Sync packaging from Ubuntu: - debian/copyright: Update upstream source location. - debian/control: add a Build-Depends on libelf-dev. - Enable arm64 build. - debian/patches/fixup_git.patch: don't run git in clean; we're not really in a git tree. - debian/rules, debian/shim.install: use the upstream install target as intended, and move files to the target directory using dh_install. - define RELEASE and COMMIT_ID for the snapshot. - Set ENABLE_HTTPBOOT to enable the HTTP Boot feature. - Update dh_auto_build/dh_auto_clean/dh_auto_install for new upstream options: set MAKELEVEL. - Define an EFI_ARCH variable, and use that for paths to shim. This makes it possible to build a shim for other architectures than amd64. - Set EFIDIR=$distro for dh_auto_install; that will let files be installed in the "right" final directories, and makes boot.csv for us. - Set ENABLE_SHIM_CERT, to keep using ephemeral self-signed certs built at compile-time for MokManager and fallback. - Set ENABLE_SBSIGN, to use sbsign instead of pesign for signing fallback and MokManager. | |||
2019-02-09 | null merge of the Ubuntu git history | Steve Langasek | |
2018-08-22 | releasing package shim version 15+1533136590.3beb971-0ubuntu1debian/15+1533136590.3beb971-0ubuntu1 | Mathieu Trudel-Lapierre | |
2018-08-22 | Make sure we pass the right COMMIT_ID to build | Mathieu Trudel-Lapierre | |
2018-08-21 | Update to new snapshot | Mathieu Trudel-Lapierre | |
2018-08-21 | New upstream version 15+1533136590.3beb971upstream/15+1533136590.3beb971 | Mathieu Trudel-Lapierre | |
2018-08-21 | Update upstream source from tag 'upstream/15+1533136590.3beb971' | Mathieu Trudel-Lapierre | |
Update to upstream version '15+1533136590.3beb971' with Debian dir 26714b7953c3d4b1f6aa8b95e9e1e026d455a008 | |||
2018-08-14 | releasing package shim version 15+1531942534.dd3230d-0ubuntu1debian/15+1531942534.dd3230d-0ubuntu1 | Mathieu Trudel-Lapierre | |
2018-07-24 | debian/patches/fixup_git.patch: don't run git in clean; we're not really in ↵ | Mathieu Trudel-Lapierre | |
a git tree. | |||
2018-07-24 | * debian/rules: | Mathieu Trudel-Lapierre | |
- define RELEASE and COMMIT_ID for the snapshot. - Set ENABLE_HTTPBOOT to enable the HTTP Boot feature. | |||
2018-07-24 | debian/patches/abort_abort_abort.patch: dropped patch, included upstream. | Mathieu Trudel-Lapierre | |
2018-07-24 | New upstream snapshot. | Mathieu Trudel-Lapierre | |
2018-07-24 | New upstream version 15+1531942534.dd3230dupstream/15+1531942534.dd3230d | Mathieu Trudel-Lapierre | |
2018-07-24 | Update upstream source from tag 'upstream/15+1531942534.dd3230d' | Mathieu Trudel-Lapierre | |
Update to upstream version '15+1531942534.dd3230d' with Debian dir 8b167be00338c76b0ddc9164059ce6090c274641 | |||
2018-04-24 | Enable arm64 build. | dann frazier | |
2018-04-23 | Fix Vcs link. | Steve Langasek | |
2018-04-05 | Bump version to 15Version_1515 | Peter Jones | |
2018-04-05 | Audit get_variable() calls for correct FreePool() use. | Peter Jones | |
Signed-off-by: Peter Jones <pjones@redhat.com> | |||
2018-04-05 | Fix get_variable() usage in setup_verbosity() | Peter Jones | |
Signed-off-by: Peter Jones <pjones@redhat.com> | |||
2018-04-05 | Make setup_console(-1) do GetMode() and call it from setup_verbosity() | Peter Jones | |
Signed-off-by: Peter Jones <pjones@redhat.com> | |||
2018-04-05 | Make handle_image() use console_print() not console_notify() on success | Peter Jones | |
Signed-off-by: Peter Jones <pjones@redhat.com> | |||
2018-04-05 | Fix lib/ rebuild-on-change dependencies in the Makefile | Peter Jones | |
Signed-off-by: Peter Jones <pjones@redhat.com> | |||
2018-04-05 | Get rid of dprinta(), it's useless | Peter Jones | |
Signed-off-by: Peter Jones <pjones@redhat.com> | |||
2018-04-04 | tpm_log_event_raw(): be more careful about EFI_NOT_FOUND | Peter Jones | |
Don't return EFI_NOT_FOUND from tpm_log_event*() unless we're in REQUIRE_TPM mode. Signed-off-by: Peter Jones <pjones@redhat.com> | |||
2018-04-04 | Make the 'something has gone seriously wrong' message less ambiguous | Peter Jones | |
Signed-off-by: Peter Jones <pjones@redhat.com> | |||
2018-04-04 | read_header(): fix the case where signatures have been removed. | Peter Jones | |
Signed-off-by: Peter Jones <pjones@redhat.com> | |||
2018-04-04 | Add another TODO for shim-16 | Peter Jones | |
Signed-off-by: Peter Jones <pjones@redhat.com> |