Age | Commit message (Collapse) | Author | |
---|---|---|---|
2025-07-07 | T861: add VyOS UEFI CA alongside Debian UEFI CAHEADvyos/current | Christian Breunig | |
2024-05-04 | Release 15.8-1debian/15.8-1 | Steve McIntyre | |
2024-05-04 | Clean up better after build. Closes: #1046268 | Steve McIntyre | |
2024-05-04 | Install a copy of the Debian CA certificate into /usr/share/shim. | Steve McIntyre | |
Closes: #1069054 | |||
2024-05-04 | Tag bugfixes | Steve McIntyre | |
2024-05-03 | Force usage of newest revocations at build time | Steve McIntyre | |
Force shim to use the latest revocations by default to block some older grub / peimage issues. This is: "shim,4\ngrub,4\ngrub.peimage,2\n" This should work with the current released grub builds in all of buster, bullseye, bookwork and trixie/unstable. Let's not leave known security holes in the wild. | |||
2024-05-03 | Cherry-pick latest grub revocation patches from upstream shim | Steve McIntyre | |
0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch | |||
2024-05-03 | Log if the build is nx-compatible or not | Steve McIntyre | |
Add a new simple script to do this: check_nx | |||
2024-05-03 | Stop building shim for i386 | Steve McIntyre | |
Debian kernels are no longer signed for i386, it's time to stop supporting i386 SB. | |||
2024-05-03 | Switch to 15.8 upstream and drop patches | Steve McIntyre | |
2024-05-02 | Tweak the UUID handling to be clearer | Steve McIntyre | |
2024-05-02 | Add salsa-ci.yml | Bastien Roucariès | |
2024-04-29 | Add changelog entry | Bastien Roucariès | |
2024-04-29 | Add verification of upstream release | Bastien Roucariès | |
2024-04-29 | Fix d/watch | Bastien Roucariès | |
2024-04-29 | Closes: #936009 | Bastien Roucariès | |
2024-04-29 | Apply multi-arch hints. + shim-unsigned: Add Multi-Arch: same. | Debian Janitor | |
Changes-By: apply-multiarch-hints | |||
2024-04-16 | Add machine smm=on | Bastien Roucariès | |
2024-04-15 | Fix test failure | Bastien Roucariès | |
2024-04-15 | Fix depreciation warnings | Bastien Roucariès | |
2024-04-15 | Use popen for lsb_release | Bastien Roucariès | |
2024-04-15 | Fix depends | Bastien Roucariès | |
2024-04-15 | Update changelog | Bastien Roucariès | |
2024-04-15 | Port to debian | Bastien Roucariès | |
2024-04-15 | Add ubuntu test | Bastien Roucariès | |
2024-01-20 | generate_dbx_list: pick a fixed UUID | Steve McIntyre | |
otherwise our build won't be reproducible, doh! | |||
2023-11-02 | Tweak building with pesign changes | Steve McIntyre | |
We used to use efisiglist to generate the DBX list. Newer versions of the pesign package don't include it any more, and the recommended replacement tool is now efisecdb from efivar. Tweak the generate_dbx_list script to work with both old and new. Let's make backports easy... | |||
2023-01-31 | Release 15.7-1debian/15.7-1 | Steve McIntyre | |
2023-01-30 | Swith to using the upstream "enable NX" patch | Steve McIntyre | |
2023-01-29 | Block Debian grub binaries with sbat < 4 (see #1024617) | Steve McIntyre | |
2023-01-24 | Enable NX support at build time | Steve McIntyre | |
As required by policy for signing new shim binaries. | |||
2023-01-22 | Update upstream commit hash in build | Steve McIntyre | |
We're using 657b2483ca6e9fcf2ad8ac7ee577ff546d24c3aa, which is the 15.7 release plus the one patch we're applying. | |||
2023-01-22 | Update to Standards-Version 4.6.2 (no changes needed) | Steve McIntyre | |
2023-01-22 | Switch to using gcc-12 | Steve McIntyre | |
Closes: #1022180 | |||
2023-01-22 | Switch to new upstream (15.7) | Steve McIntyre | |
Also import patch to deal with buggy binutils | |||
2022-07-21 | Release 15.6-1debian/15.6-1 | Steve McIntyre | |
2022-06-23 | Start packaging updates for the new 15.6 upstream release | Steve McIntyre | |
Remove all our patches, all upstream now | |||
2022-05-01 | Update the 32-bit format patch after upstream review | Steve McIntyre | |
2022-04-28 | Add patch headers for our patches now I've pushed PRs | Steve McIntyre | |
2022-04-28 | Try again on the string format fix | Steve McIntyre | |
2022-04-28 | Fix format strings for 32-bit builds | Steve McIntyre | |
2022-04-28 | Add new build-dep on libefivar-dev for tests | Steve McIntyre | |
2022-04-28 | Try again with includes | Steve McIntyre | |
2022-04-27 | Tweak setup for dh_auto_test so the tests work | Steve McIntyre | |
2022-04-27 | Start packaging updates for the new 15.51 upstream release | Steve McIntyre | |
Remove all our patches, all upstream now. | |||
2021-07-12 | Tweak how we call grub-install; don't abort on errordebian/15.4-7 | Steve McIntyre | |
Not ideal behaviour either, but don't break upgrades. Copy the behaviour from the grub packages here. Closes: #990966 | |||
2021-06-23 | Release 15.4-6debian/15.4-6 | Steve McIntyre | |
2021-06-22 | In insecure mode, don't abort if we can't create the MokListXRT var | Steve McIntyre | |
Upstream issue #372. Closes: #989962, #990158 | |||
2021-06-22 | Add arm64 patch to tweak section layout and stop crashing problems | Steve McIntyre | |
Upstream issue #371. Closes: #990082, #990190 | |||
2021-05-06 | Add defensive code around calls to db_getdebian/15.4-5 | Steve McIntyre | |
Don't fail if they return errors. |