From a64f2873539335b362e0fba3439566363119a882 Mon Sep 17 00:00:00 2001 From: Sofia Boldyreva Date: Wed, 15 Jan 2025 22:23:12 +0100 Subject: [PATCH] Initial commit --- config.yaml | 62 ++++++++++++++++++++++++++++++++++++++ files/clsecureboot001.cer | Bin 0 -> 1561 bytes 2 files changed, 62 insertions(+) create mode 100644 config.yaml create mode 100644 files/clsecureboot001.cer diff --git a/config.yaml b/config.yaml new file mode 100644 index 0000000..8a45678 --- /dev/null +++ b/config.yaml @@ -0,0 +1,62 @@ +actions: + - replace: + - target: "spec" + find: "%global glib2_version 2.45.8" + replace: | + %global efi_vendor almalinux + %global efidir almalinux + %global efi_esp_dir /boot/efi/EFI/%{efidir} + + %global glib2_version 2.45.8 + count: 1 + - target: "spec" + find: | + -Dfwupd-efi:efi_sbat_distro_id="rhel" \ + -Dfwupd-efi:efi_sbat_distro_summary="Red Hat Enterprise Linux" \ + replace: | + -Dfwupd-efi:efi_sbat_distro_id="almalinux" \ + -Dfwupd-efi:efi_sbat_distro_summary="AlmaLinux" \ + count: 1 + - target: "spec" + find: "-Dfwupd-efi:efi_sbat_distro_url=\"mail:secalert@redhat.com\" \\" + replace: "-Dfwupd-efi:efi_sbat_distro_url=\"mail:security@almalinux.org\" \\" + count: 1 + - target: "spec" + find: | + %pesign -s -i %{fwup_efi_fn} -o %{fwup_efi_fn}.tmp -a %{SOURCE300} -c %{SOURCE301} -n redhatsecureboot301 + %pesign -s -i %{fwup_efi_fn}.tmp -o %{fwup_efi_fn}.signed -a %{SOURCE500} -c %{SOURCE503} -n redhatsecureboot503 + rm -fv %{fwup_efi_fn}.tmp + replace: "%pesign -s -i %{fwup_efi_fn} -o %{fwup_efi_fn}.signed -a %{SOURCE300} -c %{SOURCE301} -n clsecureboot001" + count: 1 + - target: "spec" + find: | + %{_datadir}/fwupd/uefi-capsule-ux.tar.xz + %endif + replace: | + %{_datadir}/fwupd/uefi-capsule-ux.tar.xz + %endif + %if 0%{?have_modem_manager} + %{_libdir}/fwupd-plugins-3/libfu_plugin_modem_manager.so + %endif + count: 1 + + - modify_release: + - suffix: ".alma.1" + enabled: true + + - changelog_entry: + - name: "Andrei Lukoshko" + email: "alukoshko@almalinux.org" + line: + - "AlmaLinux changes" + + - add_files: + - type: "source" + name: "clsecureboot001.cer" + number: 300 + + - delete_files: + - file_name: "redhatsecureboot301.cer" + - file_name: "redhatsecureboot503.cer" + - file_name: "redhatsecurebootca3.cer" + - file_name: "redhatsecurebootca5.cer" diff --git a/files/clsecureboot001.cer b/files/clsecureboot001.cer new file mode 100644 index 0000000000000000000000000000000000000000..ca9ce5d92a13320a2995ed90f173ea719a132d8f GIT binary patch literal 1561 zcmZ`(Yfuwc6wXbS1jzzo5X>OBh=_zHxtj+9!bnI+p+=zweAJF{O%_-i65K3=V6`P` zg!+Oiw$+NM3{cvRbwp7M9c2G4W9CPDY!P9nY%kz?r;WtSRH=h8 zU|e*l3WsV{DvoP4TGbnDs9{5GAcS5Z!6h(4C{7Uq1bAm>@_|6YFE-;+7(G78M}rNd zop2L0iATV2PECX)*l5Dk>U3O<$HA#wY63bL*TU2^EXQ6+VmX8d(^It7PU5jJhO385 zA`5A%ieN~rfG#CiV@9QqDqzb&l8`jD9Hy((P@^7aCo5+n4C4+6Mny(D>xqpR~zVhEx6umhZ5RVFal3r5M(h>Ej0sf_MTi2%d}hSB1Z;Kcx_Vo?>QeGcGz_P@TPE#k$jU}t{ z=C4WMHPazOp*1PT3fm+ruI6lS_~q`^8L{y-bu+Gf%@__g=3FU^|HN|Z8E=KQmHrw0 zI*CrQY%Us>cb>W=8$P+bYgw+q?~#eYnR*Y9;aJhXnxTwk!v=F7YKwQfz8bV zV01@f!?{5q0>0>7n9VhhK+@rCzjllgEbu48Bs8(uEH~tubc=NhbLDzdL9qcd0ymIeCpOTfNz>=FRp+_ZMjPwTEfKR;4GdG@D`O}rr^ zO(!d6#<-~YhKw(p3S9X|dM{X}bRc;161eWzPCUA!^tNx{O73;zPg)%xE6 literal 0 HcmV?d00001