Age | Commit message (Collapse) | Author | |
---|---|---|---|
2024-05-04 | *Actually* release 15.8-1~deb12u1 for bookwormdebian/15.8-1_deb12u1bookworm/updates | Steve McIntyre | |
2024-05-04 | Clean up better after build. Closes: #1046268 | Steve McIntyre | |
2024-05-04 | Install a copy of the Debian CA certificate into /usr/share/shim. | Steve McIntyre | |
Closes: #1069054 | |||
2024-05-04 | Release 15.8-1~deb12u1 for bookworm | Steve McIntyre | |
2024-05-03 | Update version for bookworm | Steve McIntyre | |
2024-05-03 | Force usage of newest revocations at build time | Steve McIntyre | |
Force shim to use the latest revocations by default to block some older grub / peimage issues. This is: "shim,4\ngrub,4\ngrub.peimage,2\n" This should work with the current released grub builds in all of buster, bullseye, bookwork and trixie/unstable. Let's not leave known security holes in the wild. | |||
2024-05-03 | Cherry-pick latest grub revocation patches from upstream shim | Steve McIntyre | |
0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch | |||
2024-05-03 | Log if the build is nx-compatible or not | Steve McIntyre | |
Add a new simple script to do this: check_nx | |||
2024-05-03 | Switch to 15.8 upstream and drop patches | Steve McIntyre | |
2024-04-29 | Add changelog entry | Bastien Roucariès | |
2024-04-29 | Closes: #936009 | Bastien Roucariès | |
2024-04-15 | Update changelog | Bastien Roucariès | |
2023-11-02 | Tweak building with pesign changes | Steve McIntyre | |
We used to use efisiglist to generate the DBX list. Newer versions of the pesign package don't include it any more, and the recommended replacement tool is now efisecdb from efivar. Tweak the generate_dbx_list script to work with both old and new. Let's make backports easy... | |||
2023-01-31 | Release 15.7-1debian/15.7-1 | Steve McIntyre | |
2023-01-30 | Swith to using the upstream "enable NX" patch | Steve McIntyre | |
2023-01-29 | Block Debian grub binaries with sbat < 4 (see #1024617) | Steve McIntyre | |
2023-01-24 | Enable NX support at build time | Steve McIntyre | |
As required by policy for signing new shim binaries. | |||
2023-01-22 | Update to Standards-Version 4.6.2 (no changes needed) | Steve McIntyre | |
2023-01-22 | Switch to using gcc-12 | Steve McIntyre | |
Closes: #1022180 | |||
2023-01-22 | Switch to new upstream (15.7) | Steve McIntyre | |
Also import patch to deal with buggy binutils | |||
2022-07-21 | Release 15.6-1debian/15.6-1 | Steve McIntyre | |
2022-06-23 | Start packaging updates for the new 15.6 upstream release | Steve McIntyre | |
Remove all our patches, all upstream now | |||
2022-04-28 | Fix format strings for 32-bit builds | Steve McIntyre | |
2022-04-28 | Add new build-dep on libefivar-dev for tests | Steve McIntyre | |
2022-04-27 | Tweak setup for dh_auto_test so the tests work | Steve McIntyre | |
2022-04-27 | Start packaging updates for the new 15.51 upstream release | Steve McIntyre | |
Remove all our patches, all upstream now. | |||
2021-07-12 | Tweak how we call grub-install; don't abort on errordebian/15.4-7 | Steve McIntyre | |
Not ideal behaviour either, but don't break upgrades. Copy the behaviour from the grub packages here. Closes: #990966 | |||
2021-06-23 | Release 15.4-6debian/15.4-6 | Steve McIntyre | |
2021-06-22 | In insecure mode, don't abort if we can't create the MokListXRT var | Steve McIntyre | |
Upstream issue #372. Closes: #989962, #990158 | |||
2021-06-22 | Add arm64 patch to tweak section layout and stop crashing problems | Steve McIntyre | |
Upstream issue #371. Closes: #990082, #990190 | |||
2021-05-06 | Add defensive code around calls to db_getdebian/15.4-5 | Steve McIntyre | |
Don't fail if they return errors. | |||
2021-05-04 | Fix up the template maintainer scriptsdebian/15.4-4 | Steve McIntyre | |
if we're not running on an EFI system then exit cleanly | |||
2021-05-03 | Add maintainer scripts to the template packagesdebian/15.4-3 | Steve McIntyre | |
Manage installing and removing fbXXX.efi and mmXXX.efi when we install/remove the shim-helpers-$arch-signed packages. Closes: #966845 | |||
2021-04-21 | Add changelog for 15.4-2 with new patchesdebian/15.4-2 | Steve McIntyre | |
2021-04-14 | allocate MOK config table as BootServicesData | Steve McIntyre | |
Another patch from upstream, needed with newer kernels on x86 | |||
2021-03-31 | Add one more patch from upstream to fix i386 binary relocations | Steve McIntyre | |
2021-03-31 | Override dh_auto_build setting INSTALL, cut down on build noise | Steve McIntyre | |
2021-03-31 | Update to the 15.4 release | Steve McIntyre | |
2021-03-24 | Print sha256 checksums of the EFI binaries when the build is done | Steve McIntyre | |
2021-03-24 | Tweak the SBAT data to keep reproducibilitydebian/15.3-3 | Steve McIntyre | |
Only include the upstream version in the Debian SBAT metadata, so we don't break reproducibility on every minor packaging change. | |||
2021-03-24 | Add missing build-dep on xxd for build-time unit testsdebian/15.3-2 | Steve McIntyre | |
2021-03-23 | Switch to using the 15.3 release from upstream | Steve McIntyre | |
2021-03-23 | Update copyright file | Steve McIntyre | |
Update a couple of top-level changes, copy in gnu-efi information from the gnu-efi package | |||
2021-03-23 | Add an extra rule to generate the extra gnu-efi tarball | Steve McIntyre | |
Thanks to Dmitri John Ledkov for help | |||
2021-03-23 | Add Debian SBAT data to the shim build | Steve McIntyre | |
Add a Debian SBAT template, and rules to use it Adds a build-dep on dos2unix | |||
2021-03-23 | Add dbx entries for all our existing grub binaries | Steve McIntyre | |
They're insecure, let's break the chainloading hole | |||
2021-02-21 | Change changelog to shut lintian up | Steve McIntyre | |
2021-02-21 | Add new patch cast-CHAR8-string-handling.patch | Steve McIntyre | |
Cast CHAR8 strings to use (const char *) when using string functions Looks like gnu-efi definitions of CHAR8 are problematic | |||
2021-02-21 | Trivial change to remove bashisms in Make.coverity | Steve McIntyre | |
2021-02-21 | Remove all our old patches, no longer needed: | Steve McIntyre | |
- avoid_null_vsprint.patch - check_null_sn_ln.patch - fixup_git.patch - uname.patch - use_compare_mem_gcc9.patch |