Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Shim 15.6 for EuroLinux 8 #258

Closed
8 tasks done
jaromaz opened this issue Jul 2, 2022 · 15 comments
Closed
8 tasks done

Shim 15.6 for EuroLinux 8 #258

jaromaz opened this issue Jul 2, 2022 · 15 comments
Labels
bug Problem with the review that must be fixed before it will be accepted new vendor This is a new vendor

Comments

@jaromaz
Copy link

jaromaz commented Jul 2, 2022

Confirm the following are included in your repo, checking each box:

  • completed README.md file with the necessary information
  • shim.efi to be signed
  • public portion of your certificate(s) embedded in shim (the file passed to VENDOR_CERT_FILE)
  • binaries, for which hashes are added to vendor_db ( if you use vendor_db and have hashes allow-listed )
  • any extra patches to shim via your own git tree or as files
  • any extra patches to grub via your own git tree or as files
  • build logs
  • a Dockerfile to reproduce the build of the provided shim EFI binaries

What is the link to your tag in a repo cloned from rhboot/shim-review?


https://github.com/EuroLinux/shim-review/tree/eurolinux-shim-x86_64-20220702


What is the SHA256 hash of your final SHIM binary?


9103237187d50053b4dbe37f24851af36c7adfd00de2eab8c1dc83d2706fa43e

@frozencemetery frozencemetery added new vendor This is a new vendor contact verification needed Contact verification is needed for this review labels Aug 15, 2022
@frozencemetery
Copy link
Member

I'm sending you some words. Please post them here when you receive them.

@aronowski
Copy link
Collaborator

aronowski commented Aug 15, 2022

regnskapsregistrene
storselskapenes
næringsmeldinga
sjeledrama
klosterlatin
skagene
minskningene
denudasjonen
brestingen
tilhenget
hovedstadshotellet
tomgangstap
rønne

@AlexBaranowski
Copy link

@frozencemetery FYI @jaromaz is currently on vacation during which he wanted to be "offline" && "tech detox" as much as possible. We are trying to reach him, but it might take some time.

Sorry for keeping You waiting.

@jaromaz
Copy link
Author

jaromaz commented Aug 18, 2022

@frozencemetery @AlexBaranowski My keys are secured offline - I return from vacation on 25.08 and will send the list of words then, since I didn't even take my laptop on this trip.

@jaromaz
Copy link
Author

jaromaz commented Aug 24, 2022

@frozencemetery

privatsamlerens
fellesskapsverdier
vilttrygdavgiftene
klimaavdelingen
endringsfase
eitelens
stemningsskiftets
evidens
teglstein
dynnets
sjukdomsårsaker
fallskjermgodtgjøring
stillingsinnehaverne

@frozencemetery
Copy link
Member

Sorry for keeping You waiting.

Not a problem for me; the only ones who suffer here are you :)

In any case, both word sets match; contact verification complete.

@frozencemetery frozencemetery removed the contact verification needed Contact verification is needed for this review label Aug 25, 2022
@frozencemetery
Copy link
Member

Your README states that you're a "Linux operating system based on Red Hat Enterprise Linux source code". Yet your Dockerfile is building using Oracle Linux. Which is it?

Your grub2 sbat has grub.eurolinux,2,... - why is this? (There's no rule that they need to increase as you go down, so we'd expect 1 here unless there was a problem.)

@frozencemetery frozencemetery added the question Reviewer(s) waiting on response label Aug 25, 2022
@aronowski
Copy link
Collaborator

The reason for that number 2 in EuroLinux' GRUB2 generation number is that after upstream updated their generation number, we did the same for management simplification.

@jaromaz
Copy link
Author

jaromaz commented Aug 29, 2022

Yet your Dockerfile is building using Oracle Linux.

All these systems are binary compatible, produce exactly the same artifacts. Of course, there is no problem to use our container, but in the reviews several comments suggested such a procedure: using a container with a different, independent distro, was recommended.

@frozencemetery
Copy link
Member

The reason for that number 2 in EuroLinux' GRUB2 generation number is that after upstream updated their generation number, we did the same for management simplification.

This is not the correct use of SBAT.

@frozencemetery frozencemetery added bug Problem with the review that must be fixed before it will be accepted and removed question Reviewer(s) waiting on response labels Aug 30, 2022
@aronowski
Copy link
Collaborator

aronowski commented Sep 1, 2022

Everything is explained in SBAT.md, the document SBAT.example.md mislead me a bit.

Thank you for pointing out the mistake. We should have given 1 and this number shall not be higher in our case, because we are compatible with Red Hat Enterprise Linux and thus no custom changes will be made here.

We fixed the issue and our current review has been updated to the tag eurolinux-shim-x86_64-20220901.

@frozencemetery frozencemetery removed the bug Problem with the review that must be fixed before it will be accepted label Sep 1, 2022
@jaromaz
Copy link
Author

jaromaz commented Sep 13, 2022

@frozencemetery @julian-klode Is there anything else we can help with to speed up the process?

@AlexBaranowski
Copy link

Hi!

Is there any ETA for review?

@frozencemetery
Copy link
Member

Please note #307

@frozencemetery frozencemetery added the bug Problem with the review that must be fixed before it will be accepted label Feb 16, 2023
@jaromaz
Copy link
Author

jaromaz commented Apr 13, 2023

Closing due to shim 15.7 and NX support requirement.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Problem with the review that must be fixed before it will be accepted new vendor This is a new vendor
Projects
None yet
Development

No branches or pull requests

4 participants