tag name | 14 (98a4042bc580b6d8aeeed2a3c31f000d61d25676) |
tag date | 2017-12-19 16:52:44 -0500 |
tagged by | Peter Jones <pjones@redhat.com> |
tagged object | commit 02e2fc61bd... |
download | efi-boot-shim-14.tar.gz efi-boot-shim-14.zip |
---|
shim 14 - Important bug fix release
The shim EFI binary cannot have sections whose offset is not a multiple of the
file header offset, or else signtool.exe will generate an incorrect signature
that cannot be verified. Currently we generate a PLT section that is
incorrectly aligned, due to an error in rebasing OpenSSL to fix a different
issue. This version rectifies that error, as well as adding --no-undefined to
the final link, so that any such missing symbol will cause a build error. This
doesn't necessarily solve the file offset problem in all cases, but it does
solve it in all the cases we've actually seen so far.
-----BEGIN PGP SIGNATURE-----
iQIcBAABCgAGBQJaOYozAAoJEO7SZrcPT+8Qt5EQAJpLDKftEHCEH5P59ivhGPSu
yZv4wNDendy+hUyZc2m4aFcdtC2WSo+CHgZmDoCehrcVeHSCKpNGrwnqSjobf9l5
uZJHOBEw0T2g5W7T9TWG4QLu9VFECiMa3RFdMVu1DzLARA+tSzFXX5pA9ZO/7KV5
YDK+jpJLnX3xDwBAz+BMd+yn6TDJdj4Aal8ZzORBTwGTy/k5KZaP9iHxGxK5np9h
+zYt6WbXOwiZOhx+PcHn2yNmDoa2cJGNpz0AaReMhYSqtVMykvOAV50DT0XlsMru
RKO1xp+lYMEPYr6JG+glWoeJ4A894mh5Md94mTk3uwohX7pEhgY6ReWn5YCi4qHp
1YXapyVWpng53tCvZz9MjhhWKbQ5FqpZi61g32obqtYPvApAQpWtRuS3ADbrXTb5
wBxvjEFoCnxnBcR3tAo+z0gVtxcP+rekkVEfjEdj4V7iP1lElUZCKXpkYFZCiaqR
DSKE/K0mc76zWMKIAkhTcHrzoJMoLl6tKV+WxbHZP0uL36bmycOWuihQ3wcmudR9
+6+VUnCTFaipOQUFBJxMskfm+/42PicC+G2Qdn/iimuxBc0fLjUTv5xWycoEm602
pysrd1VdMFc67w2L1zqlbuPTLfCUwGYOczPL5ukWWVZdqWP5zed1Osc12Rbx5a/w
CcaPYFAAreN2X4pmLvdd
=5UyX
-----END PGP SIGNATURE-----