diff --git a/.gitignore b/.gitignore index 3a4f2b3..f5749fd 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1,2 @@ -SOURCES/shim-15.8.tar.bz2r +SOURCES/redhatsecurebootca8.cer +SOURCES/shim-16.1.tar.bz2 diff --git a/.shim-unsigned-aarch64.metadata b/.shim-unsigned-aarch64.metadata index 89e9ccb..df091d6 100644 --- a/.shim-unsigned-aarch64.metadata +++ b/.shim-unsigned-aarch64.metadata @@ -1 +1,2 @@ -cdec924ca437a4509dcb178396996ddf92c11183 SOURCES/shim-15.8.tar.bz2 +a0ee61374fd590fbcc17aa84abf32d4c5e90887c SOURCES/redhatsecurebootca8.cer +53a4a52f2cddd7ae880e405b4e3336a5968c5683 SOURCES/shim-16.1.tar.bz2 diff --git a/SOURCES/sbat.almalinux.csv b/SOURCES/sbat.almalinux.csv index f2496f1..8002f06 100644 --- a/SOURCES/sbat.almalinux.csv +++ b/SOURCES/sbat.almalinux.csv @@ -1 +1 @@ -shim.almalinux,3,AlmaLinux,shim,15.8,security@almalinux.org +shim.almalinux,3,AlmaLinux,shim,16.1,security@almalinux.org diff --git a/SOURCES/shim-15.8.tar.bz2 b/SOURCES/shim-15.8.tar.bz2 deleted file mode 100644 index 4e1f3ad..0000000 Binary files a/SOURCES/shim-15.8.tar.bz2 and /dev/null differ diff --git a/SPECS/shim-unsigned-aarch64.spec b/SPECS/shim-unsigned-aarch64.spec index 41c2516..3f5851f 100644 --- a/SPECS/shim-unsigned-aarch64.spec +++ b/SPECS/shim-unsigned-aarch64.spec @@ -1,6 +1,7 @@ %global pesign_vre 0.106-1 %global gnuefi_vre 1:3.0.5-6 %global openssl_vre 1.0.2j +%global shim_commit_id afc49558b34548644c1cd0ad1b6526a9470182ed %global debug_package %{nil} %global __debug_package 1 @@ -15,7 +16,7 @@ %global shimdir %{shimversiondir}/%{efiarch} Name: shim-unsigned-aarch64 -Version: 15.8 +Version: 16.1 Release: 2.el9.alma.1 Summary: First-stage UEFI bootloader ExclusiveArch: aarch64 @@ -25,14 +26,15 @@ Source0: https://github.com/rhboot/shim/releases/download/%{version}/shim-%{vers # currently here's what's in our dbx: # nothing. Source2: dbx.esl -Source3: sbat.almalinux.csv Source4: shim.patches Source100: shim-find-debuginfo.sh -Source101: almalinux-sb-cert-1.der -Source102: almalinux-sb-cert-2.der -Source103: almalinux-sb-cert-3.der +# AlmaLinux Source +Source3: sbat.almalinux.csv +Source101: almalinux-sb-cert-1.der +Source102: almalinux-sb-cert-2.der +Source103: almalinux-sb-cert-3.der %include %{SOURCE4} @@ -104,40 +106,34 @@ cat 01.esl 02.esl 03.esl > vendor_db.esl %if 0%{?rhel} == 8 || 0%{?rhel} == 9 source scl_source enable gcc-toolset-12 || : %endif - -COMMIT_ID=5914984a1ffeab841f482c791426d7ca9935a5e6 -MAKEFLAGS="TOPDIR=.. -f ../Makefile COMMIT_ID=${COMMIT_ID} " +COMMIT_ID=%{shim_commit_id} +MAKEFLAGS="TOPDIR=.. -f ../Makefile COMMITID=${COMMIT_ID} " MAKEFLAGS+="EFIDIR=%{efidir} PKGNAME=shim RELEASE=%{release} " MAKEFLAGS+="ENABLE_SHIM_HASH=true " MAKEFLAGS+="SBAT_AUTOMATIC_DATE=2023012900 " MAKEFLAGS+="%{_smp_mflags}" -if [ -s vendor_db.esl ]; then - MAKEFLAGS="$MAKEFLAGS VENDOR_DB_FILE=../vendor_db.esl" +if [ -f "%{SOURCE1}" ]; then + MAKEFLAGS="$MAKEFLAGS VENDOR_CERT_FILE=%{SOURCE1} " fi -if [ -s "%{SOURCE2}" ]; then - MAKEFLAGS="$MAKEFLAGS VENDOR_DBX_FILE=%{SOURCE2}" +if [ -f "%{SOURCE2}" ]; then + MAKEFLAGS="$MAKEFLAGS VENDOR_DBX_FILE=%{SOURCE2} " fi cd build-%{efiarch} -make ${MAKEFLAGS} \ - DEFAULT_LOADER='\\\\grub%{efiarch}.efi' \ - all +make ${MAKEFLAGS} DEFAULT_LOADER='\\\\grub%{efiarch}.efi' all cd .. %install -%if 0%{?rhel} == 8 || 0%{?rhel} == 9 -source scl_source enable gcc-toolset-12 || : -%endif -COMMIT_ID=5914984a1ffeab841f482c791426d7ca9935a5e6 -MAKEFLAGS="TOPDIR=.. -f ../Makefile COMMIT_ID=${COMMIT_ID} " +COMMIT_ID=%{shim_commit_id} +MAKEFLAGS="TOPDIR=.. -f ../Makefile COMMITID=${COMMIT_ID} " MAKEFLAGS+="EFIDIR=%{efidir} PKGNAME=shim RELEASE=%{release} " -MAKEFLAGS+="ENABLE_HTTPBOOT=true ENABLE_SHIM_HASH=true " +MAKEFLAGS+="ENABLE_SHIM_HASH=true " MAKEFLAGS+="SBAT_AUTOMATIC_DATE=2023012900 " -if [ -s vendor_db.esl ]; then - MAKEFLAGS="$MAKEFLAGS VENDOR_DB_FILE=../vendor_db.esl" +if [ -f "%{SOURCE1}" ]; then + MAKEFLAGS="$MAKEFLAGS VENDOR_CERT_FILE=%{SOURCE1} " fi -if [ -s "%{SOURCE2}" ]; then - MAKEFLAGS="$MAKEFLAGS VENDOR_DBX_FILE=%{SOURCE2}" +if [ -f "%{SOURCE2}" ]; then + MAKEFLAGS="$MAKEFLAGS VENDOR_DBX_FILE=%{SOURCE2} " fi cd build-%{efiarch} @@ -152,84 +148,70 @@ cd .. %dir %{shimrootdir} %dir %{shimversiondir} %dir %{shimdir} -%{shimdir}/*.CSV %{shimdir}/*.efi %{shimdir}/*.hash - +%{shimdir}/*.CSV %files debuginfo -f build-%{efiarch}/debugfiles.list %files debugsource -f build-%{efiarch}/debugsource.list %changelog -* Fri May 10 2024 Eduard Abdullin - 15.8-2.el9.alma.1 +* Wed Oct 29 2025 Eduard Abdullin - 16.1-2.el9.alma.1 - Use AlmaLinux cert - Use gcc-toolset-12 +* Tue Aug 26 2025 Peter Jones - 16.1-2.el9 +- Fix the sbat data + Related: RHEL-18969 + +* Mon Aug 18 2025 Peter Jones - 16.1-1.el9 +- Update to shim-16.1 + Resolves: RHEL-18969 + * Wed Feb 07 2024 Peter Jones - 15.8-2.el9 - Rebuild to fix the commit ident and MAKEFLAGS - Resolves: RHEL-11259 + Resolves: RHEL-11262 * Tue Dec 05 2023 Peter Jones - 15.8-1.el9 - Update to shim-15.8 for CVE-2023-40547 - Resolves: RHEL-11259 + Resolves: RHEL-11262 -* Wed Jun 01 2022 Peter Jones - 15.6-1.el9 -- Update to shim-15.6 - Resolves: CVE-2022-28737 +* Tue May 26 2020 Javier Martinez Canillas - 15-6 +- Fix a shim crash when attempting to netboot + Resolves: rhbz#1840036 -* Thu Sep 17 2020 Peter Jones - 15-9.el9 -- Fix an incorrect allocation size. - Related: rhbz#1877253 +* Mon May 04 2020 Javier Martinez Canillas - 15-5 +- Fix firmware update bug in aarch64 caused by shim ignoring arguments + Resolves: rhbz#1817882 -* Thu Jul 30 2020 Peter Jones - 15-8 -- Fix a load-address-dependent forever loop. - Resolves: rhbz#1861977 - Related: CVE-2020-10713 - Related: CVE-2020-14308 - Related: CVE-2020-14309 - Related: CVE-2020-14310 - Related: CVE-2020-14311 - Related: CVE-2020-15705 - Related: CVE-2020-15706 - Related: CVE-2020-15707 - -* Sat Jul 25 2020 Peter Jones - 15-7 -- Implement Lenny's workaround - Related: CVE-2020-10713 - Related: CVE-2020-14308 - Related: CVE-2020-14309 - Related: CVE-2020-14310 - Related: CVE-2020-14311 - -* Fri Jul 24 2020 Peter Jones - 15-5 -- Once more with the MokListRT config table patch added. - Related: CVE-2020-10713 - Related: CVE-2020-14308 - Related: CVE-2020-14309 - Related: CVE-2020-14310 - Related: CVE-2020-14311 - -* Thu Jul 23 2020 Peter Jones - 15-4 -- Rebuild for bug fixes and new signing keys - Related: CVE-2020-10713 - Related: CVE-2020-14308 - Related: CVE-2020-14309 - Related: CVE-2020-14310 - Related: CVE-2020-14311 +* Fri Jun 07 2019 Javier Martinez Canillas - 15-4 +- Add a gating.yaml file so the package can be properly gated + Related: rhbz#1682749 * Wed Jun 05 2019 Javier Martinez Canillas - 15-3 - Make EFI variable copying fatal only on secureboot enabled systems - Resolves: rhbz#1715878 + Resolves: rhbz#1704854 - Fix booting shim from an EFI shell using a relative path - Resolves: rhbz#1717064 + Resolves: rhbz#1717063 * Tue Feb 12 2019 Peter Jones - 15-2 - Fix MoK mirroring issue which breaks kdump without intervention Related: rhbz#1668966 -* Fri Jul 20 2018 Peter Jones - 15-1 +* Thu Apr 05 2018 Peter Jones - 15-1 - Update to shim 15 +- better checking for bad linker output +- flicker-free console if there's no error output +- improved http boot support +- better protocol re-installation +- dhcp proxy support +- tpm measurement even when verification is disabled +- REQUIRE_TPM build flag +- more reproducable builds +- measurement of everything verified through shim_verify() +- coverity and scan-build checker make targets +- misc cleanups * Tue Sep 19 2017 Peter Jones - 13-3 - Actually update to the *real* 13 final. @@ -238,7 +220,17 @@ cd .. * Thu Aug 31 2017 Peter Jones - 13-2 - Actually update to 13 final. -* Fri Aug 18 2017 Peter Jones - 13-1 -- Make a new shim-unsigned-x64 package like the shim-unsigned-aarch64 one. -- This will (eventually) supersede what's in the "shim" package so we can - make "shim" hold the signed one, which will confuse fewer people. +* Mon Aug 21 2017 Peter Jones - 13-0.1 +- Update to shim-13 test release. + +* Thu Aug 03 2017 Fedora Release Engineering - 0.9-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild + +* Thu Jul 27 2017 Fedora Release Engineering - 0.9-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + +* Sat Feb 11 2017 Fedora Release Engineering - 0.9-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + +* Thu May 12 2016 Peter Jones - - 0.9-1 +- Initial split up of -aarch64