Age | Commit message (Collapse) | Author | |
---|---|---|---|
2024-05-03 | New upstream version 15.8 | Steve McIntyre | |
2021-02-16 | Fix up a bunch of our license statements and add SPDX most places | Peter Jones | |
The license statements in our source files were getting to be a giant mess, and mostly they all just say the same thing. I've switched most of it to SPDX labels, but left copyright statements in place (where they were not obviously incorrect copy-paste jobs that I did...). If there's some change here you don't think is valid, let me know and we can fix it up together. Signed-off-by: Peter Jones <pjones@redhat.com> | |||
2020-07-23 | Add support for vendor_db built-in shim authorized list. | Peter Jones | |
Potential new signing strategies ( for example signing grub, fwupdate and vmlinuz with separate certificates ) require shim to support a vendor provided bundle of trusted certificates and hashes, which allows shim to trust EFI binaries matching either certificate by signature or hash in the vendor_db. Functionality is similar to vendor_dbx. This also improves the mirroring quite a bit. Upstream: pr#206 | |||
2020-07-23 | Make cert.S not impossible to read. | Peter Jones | |
Signed-off-by: Peter Jones <pjones@redhat.com> Upstream: pr#206 | |||
2014-08-12 | Add support for 32-bit ARM | Ard Biesheuvel | |
This adds support for building the shim for a 32-bit ARM UEFI environment. Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org> | |||
2013-10-01 | Make vendor_cert/vendor_dbx actually replaceable by an external tool. | Peter Jones | |
This moves them both to be computed at runtime from a pointer+offset rather than just a pointer, so that their real address can be entirely derived from the section they're in. This means you can replace the whole .vendor_cert section with a new one with certs that don't have the same size. | |||
2013-06-11 | Fix some pointer casting issues. | Peter Jones | |
This also fixes the size of an empty vendor_cert or dbx_cert. Signed-off-by: Peter Jones <shim-owner@fedoraproject.org> | |||
2013-06-10 | Make .vendor_cert get the right flags set. | Peter Jones | |
Signed-off-by: Peter Jones <pjones@redhat.com> | |||
2013-06-10 | Move embedded certificates to their own section. | Peter Jones | |
With this change, the embedded certificate and dbx lists (vendor_cert, vendor_cert_size, vendor_dbx, and vendor_dbx_size) wind up being in a section named .vendor_cert, and so will look something like: ------ fenchurch:~/devel/github.com/shim$ objdump -h shim.efi shim.efi: file format pei-x86-64 Sections: Idx Name Size VMA LMA File off Algn 0 .eh_frame 000174a8 0000000000005000 0000000000005000 00000400 2**3 CONTENTS, ALLOC, LOAD, READONLY, DATA 1 .text 000aa7e1 000000000001d000 000000000001d000 00017a00 2**4 CONTENTS, ALLOC, LOAD, READONLY, CODE 2 .reloc 0000000a 00000000000c8000 00000000000c8000 000c2200 2**0 CONTENTS, ALLOC, LOAD, READONLY, DATA 3 .data 00031228 00000000000c9000 00000000000c9000 000c2400 2**5 CONTENTS, ALLOC, LOAD, DATA 4 .vendor_cert 00000375 00000000000fb000 00000000000fb000 000f3800 2**0 CONTENTS, READONLY 5 .dynamic 000000f0 00000000000fc000 00000000000fc000 000f3c00 2**3 CONTENTS, ALLOC, LOAD, DATA 6 .rela 0002afa8 00000000000fd000 00000000000fd000 000f3e00 2**3 CONTENTS, ALLOC, LOAD, READONLY, DATA 7 .dynsym 0000f1f8 0000000000128000 0000000000128000 0011ee00 2**3 CONTENTS, ALLOC, LOAD, READONLY, DATA ------ This simplifies a security audit, because it means that different versions of shim with substantially the same code with different keys will be more easily comperable, and therefore logic differences may be more easily identified. This also means that if there's a trusted build you want to use, you can remove the certificates, implant new ones, and have it signed, and the code sections won't change. Signed-off-by: Peter Jones <pjones@redhat.com> | |||
2013-06-10 | vendor_cert_size's size in the binary should be 4, not -4. | Peter Jones | |
The thing about subtraction is that the minuend needs to be before the subtrahend in the text. Signed-off-by: Peter Jones <pjones@redhat.com> | |||
2012-09-06 | Fix data alignment on vendor_cert so we don't wind up with padding. | Peter Jones | |
2012-09-06 | Allow specification of vendor_cert through a build command line option. | Peter Jones | |
This allows you to specify the vendor_cert as a file on the command line during build. |