-
Notifications
You must be signed in to change notification settings - Fork 131
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
shim 15.8 for SUSE Enterprise Linux #393
Comments
Updated the tag to indicted the current SLES service pack (SP5 instead of SP4) |
seems like the architecture variable is not set (line 206 in the README.md). Please try |
Reviewing. The x86_64 shim binary does reproduce and has the checksum However, the binary attached in the repository has a different checksum (
I'm worried about this, as it may be a dealbreaker as of today. I'd be happy to try things out on my end and recompile the system kernel if needed, but asking first: Note for myself: leaving the v5.14 kernel module signing document here in case I need it later. Minor curiosity: the shim SBAT entry written in the application 's README.md has the * checked by dumping the In order to reproduce the aarch64 build on an x86_64 machine, I ran this command:
The binary looks alright! 👍 |
Thank you for the review. The shim binary is the one from our build service, not of the local (or container build). That was my error, sorry. The pesign hash has been fine, but the sha256sum not. I uploaded the proper shim binary in jsegitz@8519f8d and updated the tag |
Ephemeral keys: We work with vendors to make their kernel modules work on our operating system. Recompiling every module for every new kernel would be problematic for us. I'll raise this with our kernel team, but even if it's possible (and I'm not so sure about this) it would need quite some time. SBAT entries email: These addresses are reaching the same team, but I'll see that we unify this. Thanks for the note |
If there's anything we can do to help this move quickly please don't hesitate to tell us. Thanks |
I'm not spotting any remaining issues here. |
thank you very much for the review! |
Confirm the following are included in your repo, checking each box:
What is the link to your tag in a repo cloned from rhboot/shim-review?
https://github.com/jsegitz/shim-review/tree/SUSE-SLES-shim-x86_aarch64-20240229
What is the SHA256 hash of your final SHIM binary?
x86_64:
pesign: f327bfe0e31193974df9fa68b621a2c87d154ef2986059ce16fc6d0bd7537a96 shim-sles.efi
sha256sum: bf24a19e3bd5ca535b0815be9e49b36b835a9f36310ed5b3e5f87959a52b87e2 shim-sles.efi
aarch64:
pesign: 8bfe4fc6a7506d82a4efdd39ecac04ef0ab6f65d9ac3514d803462a7b4ae7fcf shim-sles.efi
sha256sum: 5f3c747130027da84c47256a6d089b6cb1c923a3517d31c8703e360c9f2832c6 shim-sles.efi
What is the link to your previous shim review request (if any, otherwise N/A)?
#301
The text was updated successfully, but these errors were encountered: