-
Notifications
You must be signed in to change notification settings - Fork 131
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Ctrl IQ, Inc Shim 15.8 for x64 & ia32 #366
Comments
While I am not an official reviewer, here are my comments "looking at latest tag: https://bitbucket.org/ciqinc/ciq-shim-build/src/ctrliq-shim-x64-ia32-20240131/":
Regarding certwrapper(mule), it's great tool, however based on my understanding, it's still in early stages, while you can sign the .EFI with your certs and package it to your users, you must know it is still not fully tested and might causes some issues I think we need two more official reviewer to look at this submission, best of luck with the submission :) |
The build does reproduce, checksums match. No NX compatibility bit, as the whole chain is not NX-compatible. No binutils bug. OK.
👍 Yes, this is a thing I got aware of recently - the Enterprise Linux 8.9 kernel does have the CVE-2022-21499 fix implemented by the commit Furthermore, debugging appears to be enabled only in aarch64 debug config:
LGTM! Let's wait for another official review. |
(Not an official reviewer, but here we go) Basics
CA
Shim
GRUB
sd-boot
Kernel
|
Shim point I missed:
|
Signed binaries returned, closing |
Confirm the following are included in your repo, checking each box:
What is the link to your tag in a repo cloned from rhboot/shim-review?
https://bitbucket.org/ciqinc/ciq-shim-build/src/ctrliq-shim-x64-ia32-20240131/
Orginal repo migrated to
https://github.com/ctrliq/ciq-shim-build/tree/ctrliq-shim-x64-ia32-20240131
What is the SHA256 hash of your final SHIM binary?
SHA256 (shimx64.efi) = 654d8efe248cd113f7ecb5a1f4fc9c309cc0d65a66b4bb8d9b2991f57f2dbcf6
SHA256 (shimia32.efi) = b739423471c03d32f2918906286076ea73c1385ced3f175a60ceeb8fadf009de
What is the link to your previous shim review request (if any, otherwise N/A)?
Ctrl IQ, Inc Shim 15.7 for x64 & ia32 #339
The text was updated successfully, but these errors were encountered: