-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 05 May 2024 11:33:57 +0100 Source: shim Binary: shim-helpers-arm64-signed-template shim-unsigned Architecture: arm64 Version: 15.8-1~deb11u1 Distribution: bullseye Urgency: medium Maintainer: arm Build Daemon (arm-conova-04) Changed-By: Steve McIntyre <93sam@debian.org> Description: shim-helpers-arm64-signed-template - boot loader to chain-load signed boot loaders (signing template) shim-unsigned - boot loader to chain-load signed boot loaders under Secure Boot Closes: 1046268 1069054 Changes: shim (15.8-1~deb11u1) bullseye; urgency=medium . * New upstream release fixing more bugs * Remove all our previous patches, no longer needed: + Make-sbat_var.S-parse-right-with-buggy-gcc-binutils.patch (now upstream) + Enable-NX.patch (we don't want NX just yet until the whole boot stack is NX-capable) + block-grub-sbat3-debian.patch (not needed now upstream grub SBAT is 4) * Cherry-pick 2 new patches from upstream for grub revocations: + 0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch + 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch * Log if the build is nx-compatible or not * Force shim to use the latest revocations by default to block some older grub / peimage issues. This is: "shim,4\ngrub,4\ngrub.peimage,2\n" * Install a copy of the Debian CA certificate into /usr/share/shim. Closes: #1069054 * Clean up better after build. Closes: #1046268 Checksums-Sha1: b4b6f5de4cf9dcd06a6d0c38c1524b6ca91df4c6 15420 shim-helpers-arm64-signed-template_15.8-1~deb11u1_arm64.deb b70698c7086731110df3987ee1e397672dba582b 342952 shim-unsigned_15.8-1~deb11u1_arm64.deb fc33913e002dc66af950c32eec23516481c091d2 6790 shim_15.8-1~deb11u1_arm64-buildd.buildinfo Checksums-Sha256: 8cf24ee0fce62b7e8311ad45ef8cc2b59200e71c6321f5363d46cd8a791c1307 15420 shim-helpers-arm64-signed-template_15.8-1~deb11u1_arm64.deb e49b7f3132f832c45f06e14ac75bad01dfcc2abb95b54195ef1cb0bdcd2f71c3 342952 shim-unsigned_15.8-1~deb11u1_arm64.deb 7455ff7af1962bd19acc6185b93818c83431f8d55a372ff44002c2f55ea0a2db 6790 shim_15.8-1~deb11u1_arm64-buildd.buildinfo Files: e7d3b24666b1d61c2d2ccb2e5fd85e11 15420 admin optional shim-helpers-arm64-signed-template_15.8-1~deb11u1_arm64.deb 699bd7d64f7bb5c9d6e5b3531bb1ed82 342952 admin optional shim-unsigned_15.8-1~deb11u1_arm64.deb 515415b3b9c9a5233215032d8097d582 6790 admin optional shim_15.8-1~deb11u1_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEElif5H+pIB11ZS5Aay8vyjiVDuNYFAmY7xmEACgkQy8vyjiVD uNZB4hAAnjwTLvbGKVz6G+l5GlJaJCpLnKIxFUKM6k09+jlrjhVIx7CwM109IepP IAK5zulPTybED+VTJbo6KaxICiT23k0Xbb/ifcjkF7S/gnitrN+zqhrbk8JweVUz AOGASeHMWa8BcdqMf3tgwTdZc+cRCOfJ7owfpWKPTMp0o6aw4vVq/E4KS8wPLtCx fmVmhnhnxcRScHNcbuBlX8+3sj9z5tvf8iyYoSPuQ+cluJybJCRAbCkQOeG8THtn xOITGhLSFEirBJFJj87/xFFuN8ninUZK3iq9xMuk1SjaTuOOAQw/x7FA9sSWOnpB bR4AFKs2BEVLQqZURj3sxfa6+QzMlKkQabfIkDX48eulbSDyws76JvLUVemh9tbX dCybewQd0Ws8A1StT+JBNm6V9R4l+ue8Zk3Fj2G6xReupu+f/zWV0J53+Z3s2N0F 5s4jV2ljKUEBbSgROpHJpeEIiVZ6rEXTsf/j1Ty6WN5r0smNAyh/Oi0xBWWs0w2F jOojz2O+I+IXxGOZCQwVV9uc7yIoCvA/bCNaJbjLCQ6rExUvnvuR1Jn3mLBFWLtX Jx3mmDnpikVKWfPZZRwUQbFuxMDA7ASPcJolYNL/Z7NZ4eu8sh9qWoBYqH3+acBT lEtXZBl8xZda2SMayN6XyBVZTef4eTZRFaQGVBPtHuTRFs1EEx8= =iZ1C -----END PGP SIGNATURE-----