commit a978be6b55cda7c97e86d6e137d0b987964aefec Author: Andrew Lukoshko Date: Tue Feb 17 12:13:11 2026 +0000 sync with AlmaLinux shim-unsigned-x64-16.1-1.el9.alma.1 diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..10ecec9 --- /dev/null +++ b/.gitignore @@ -0,0 +1,4 @@ +almalinux-sb-cert-1.der +almalinux-sb-cert-2.der +almalinux-sb-cert-3.der +shim-16.1.tar.bz2 diff --git a/dbx.esl b/dbx.esl new file mode 100644 index 0000000..e69de29 diff --git a/sbat.almalinux.csv b/sbat.almalinux.csv new file mode 100644 index 0000000..8002f06 --- /dev/null +++ b/sbat.almalinux.csv @@ -0,0 +1 @@ +shim.almalinux,3,AlmaLinux,shim,16.1,security@almalinux.org diff --git a/shim-find-debuginfo.sh b/shim-find-debuginfo.sh new file mode 100755 index 0000000..868fe04 --- /dev/null +++ b/shim-find-debuginfo.sh @@ -0,0 +1,89 @@ +#!/bin/bash +# +# shim-find-debuginfo.sh +# Copyright (C) 2017 Peter Jones +# +# Distributed under terms of the GPLv3 license. +# +set -e +set -u + +mainarch=$1 && shift +if [ $# == 1 ]; then + altarch=$1 && shift +fi +if ! [ -v RPM_BUILD_ROOT ]; then + echo "RPM_BUILD_ROOT must be set" 1>&2 + exit 1 +fi + +findsource() +{ + ( + cd ${RPM_BUILD_ROOT} + find usr/src/debug/ -type d | sed "s,^,%dir /," + find usr/src/debug/ -type f | sed "s,^,/," + ) +} + +finddebug() +{ + arch=$1 && shift + declare -a dirs=() + declare -a files=() + declare -a excludes=() + pushd ${RPM_BUILD_ROOT} >/dev/null 2>&1 + for x in $(find usr/lib/debug/ -type f -iname *.efi.debug); do + if ! [ -e "${x}" ]; then + break + fi + if [[ ${x} =~ ${arch}\.efi\.debug$ ]]; then + files[${#files[@]}]=${x} + else + excludes[${#excludes[@]}]=${x} + fi + done + for x in usr/lib/debug/.build-id/*/*.debug ; do + if ! [ -e "${x}" ]; then + break + fi + link=$(readlink "${x}") + if [[ ${link} =~ ${arch}\.efi\.debug$ ]]; then + files[${#files[@]}]=${x} + files[${#files[@]}]=${x%%.debug} + else + excludes[${#excludes[@]}]=${x} + excludes[${#excludes[@]}]=${x%%.debug} + fi + done + for x in ${files[@]} ; do + declare name=$(dirname /${x}) + while [ "${name}" != "/" ]; do + case "${name}" in + "/usr/lib/debug"|"/usr/lib"|"/usr") + ;; + *) + dirs[${#dirs[@]}]=${name} + ;; + esac + name=$(dirname ${name}) + done + done + + popd >/dev/null 2>&1 + for x in ${dirs[@]} ; do + echo "%dir ${x}" + done | sort | uniq + for x in ${files[@]} ; do + echo "/${x}" + done | sort | uniq + for x in ${excludes[@]} ; do + echo "%exclude /${x}" + done +} + +findsource > build-${mainarch}/debugsource.list +finddebug ${mainarch} > build-${mainarch}/debugfiles.list +if [ -v altarch ]; then + finddebug ${altarch} > build-${altarch}/debugfiles.list +fi diff --git a/shim-unsigned-x64.spec b/shim-unsigned-x64.spec new file mode 100644 index 0000000..0c40370 --- /dev/null +++ b/shim-unsigned-x64.spec @@ -0,0 +1,282 @@ +%global pesign_vre 0.106-1 +%global openssl_vre 1.0.2j +%global shim_commit_id afc49558b34548644c1cd0ad1b6526a9470182ed + +%global efidir almalinux +%global shimrootdir %{_datadir}/shim/ +%global shimversiondir %{shimrootdir}/%{version}-%{release} +%global efiarch x64 +%global shimdir %{shimversiondir}/%{efiarch} +%global efialtarch ia32 +%global shimaltdir %{shimversiondir}/%{efialtarch} + +%global debug_package %{nil} +%global __debug_package 1 +%global _binaries_in_noarch_packages_terminate_build 0 +%global __debug_install_post %{SOURCE100} %{efiarch} %{efialtarch} +%undefine _debuginfo_subpackages + + +Name: shim-unsigned-%{efiarch} +Version: 16.1 +Release: 1.el9.alma.1 +Summary: First-stage UEFI bootloader +ExclusiveArch: x86_64 +License: BSD +URL: https://github.com/rhboot/shim +Source0: https://github.com/rhboot/shim/releases/download/%{version}/shim-%{version}.tar.bz2 +Source4: shim.patches + +Source100: shim-find-debuginfo.sh + +# AlmaLinux Source +Source2: dbx.esl +Source3: sbat.almalinux.csv +Source101: almalinux-sb-cert-1.der +Source102: almalinux-sb-cert-2.der +Source103: almalinux-sb-cert-3.der + +%include %{SOURCE4} + +BuildRequires: gcc make +BuildRequires: elfutils-libelf-devel +BuildRequires: git openssl-devel openssl +BuildRequires: pesign >= %{pesign_vre} +BuildRequires: dos2unix findutils +BuildRequires: efitools + +# Shim uses OpenSSL, but cannot use the system copy as the UEFI ABI is not +# compatible with SysV (there's no red zone under UEFI) and there isn't a +# POSIX-style C library. +# BuildRequires: OpenSSL +Provides: bundled(openssl) = %{openssl_vre} + +%global desc \ +Initial UEFI bootloader that handles chaining to a trusted full \ +bootloader under secure boot environments. +%global debug_desc \ +This package provides debug information for package %{expand:%%{name}} \ +Debug information is useful when developing applications that \ +use this package or when debugging this package. + +%description +%desc + +%package -n shim-unsigned-%{efialtarch} +Summary: First-stage UEFI bootloader (unsigned data) +Provides: bundled(openssl) = %{openssl_vre} + +%description -n shim-unsigned-%{efialtarch} +%desc + +%package debuginfo +Summary: Debug information for shim-unsigned-%{efiarch} +Group: Development/Debug +AutoReqProv: 0 +BuildArch: noarch + +%description debuginfo +%debug_desc + +%package -n shim-unsigned-%{efialtarch}-debuginfo +Summary: Debug information for shim-unsigned-%{efialtarch} +Group: Development/Debug +AutoReqProv: 0 +BuildArch: noarch + +%description -n shim-unsigned-%{efialtarch}-debuginfo +%debug_desc + +%package debugsource +Summary: Debug Source for shim-unsigned +Group: Development/Debug +AutoReqProv: 0 +BuildArch: noarch + +%description debugsource +%debug_desc + +%prep +%autosetup -S git_am -n shim-%{version} +git config --unset user.email +git config --unset user.name +mkdir build-%{efiarch} +mkdir build-%{efialtarch} +cp %{SOURCE3} data/ + +%build +# Prepare vendor_db.esl file +openssl x509 -inform DER -in %{SOURCE101} -out 01.pem +openssl x509 -inform DER -in %{SOURCE102} -out 02.pem +openssl x509 -inform DER -in %{SOURCE103} -out 03.pem +cert-to-efi-sig-list -g 9DD8A2AC-0977-4AEF-99A0-E794FD2A31FE 01.pem 01.esl +cert-to-efi-sig-list -g 33D81FE3-5EC0-44F8-AB02-C9DA554F63D8 02.pem 02.esl +cert-to-efi-sig-list -g 50413300-1AC7-49DA-B755-BB0D93E634B6 03.pem 03.esl +cat 01.esl 02.esl 03.esl > vendor_db.esl +COMMIT_ID=%{shim_commit_id} +MAKEFLAGS="TOPDIR=.. -f ../Makefile COMMIT_ID=${COMMIT_ID} " +MAKEFLAGS+="EFIDIR=%{efidir} PKGNAME=shim RELEASE=%{release} " +MAKEFLAGS+="ENABLE_SHIM_HASH=true " +MAKEFLAGS+="SBAT_AUTOMATIC_DATE=2023012900 " +MAKEFLAGS+="%{_smp_mflags}" +if [ -s vendor_db.esl ]; then + MAKEFLAGS="$MAKEFLAGS VENDOR_DB_FILE=../vendor_db.esl" +fi +if [ -s "%{SOURCE2}" ]; then + MAKEFLAGS="$MAKEFLAGS VENDOR_DBX_FILE=%{SOURCE2}" +fi + +cd build-%{efiarch} +make ${MAKEFLAGS} \ + DEFAULT_LOADER='\\\\grub%{efiarch}.efi' \ + all +cd .. + +%install +COMMIT_ID=%{shim_commit_id} +MAKEFLAGS="TOPDIR=.. -f ../Makefile COMMIT_ID=${COMMIT_ID} " +MAKEFLAGS+="EFIDIR=%{efidir} PKGNAME=shim RELEASE=%{release} " +MAKEFLAGS+="ENABLE_SHIM_HASH=true " +MAKEFLAGS+="SBAT_AUTOMATIC_DATE=2023012900 " +if [ -s vendor_db.esl ]; then + MAKEFLAGS="$MAKEFLAGS VENDOR_DB_FILE=../vendor_db.esl" +fi +if [ -s "%{SOURCE2}" ]; then + MAKEFLAGS="$MAKEFLAGS VENDOR_DBX_FILE=%{SOURCE2}" +fi + +cd build-%{efiarch} +make ${MAKEFLAGS} \ + DEFAULT_LOADER='\\\\grub%{efiarch}.efi' \ + DESTDIR=${RPM_BUILD_ROOT} \ + install-as-data install-debuginfo install-debugsource +cd .. + +%files +%license COPYRIGHT +%dir %{shimrootdir} +%dir %{shimversiondir} +%dir %{shimdir} +%{shimdir}/*.CSV +%{shimdir}/*.efi +%{shimdir}/*.hash + +%files debuginfo -f build-%{efiarch}/debugfiles.list + +%files debugsource -f build-%{efiarch}/debugsource.list + +%changelog +* Wed Oct 29 2025 Eduard Abdullin - 16.1-1.el9.alma.1 +- Use AlmaLinux OS cert and SBAT entry + +* Mon Aug 18 2025 Peter Jones - 16.1-1.el9 +- Update to shim-16.1 + Resolves: RHEL-67333 + +* Wed Feb 07 2024 Peter Jones - 15.8-2.el9 +- Rebuild to fix the commit ident and MAKEFLAGS + Resolves: RHEL-11262 + +* Tue Jan 23 2024 Peter Jones - 15.8-1.el9 +- Update to shim-15.8 for CVE-2023-40547 + Resolves: RHEL-11262 + +* Wed Jun 01 2022 Peter Jones - 15.6-1.el9 +- Update to shim-15.6 for CVE-2022-28737 + +* Tue May 24 2022 Peter Jones - 15.6~rc1-1.el9 +- Update to shim-15.6~rc1 for CVE-2022-28737 + +* Wed Mar 09 2022 Peter Jones - 15.5-1 +- Update to shim-15.5 + Related: rhbz#1932057 + +* Thu Apr 01 2021 Peter Jones - 15.4-4 +- Fix the sbat data to actually match /this/ product. + Resolves: CVE-2020-14372 + Resolves: CVE-2020-25632 + Resolves: CVE-2020-25647 + Resolves: CVE-2020-27749 + Resolves: CVE-2020-27779 + Resolves: CVE-2021-20225 + Resolves: CVE-2021-20233 + +* Wed Mar 31 2021 Peter Jones - 15.4-3 +- Build with the correct certificate trust list for this OS. + Resolves: CVE-2020-14372 + Resolves: CVE-2020-25632 + Resolves: CVE-2020-25647 + Resolves: CVE-2020-27749 + Resolves: CVE-2020-27779 + Resolves: CVE-2021-20225 + Resolves: CVE-2021-20233 + +* Wed Mar 31 2021 Peter Jones - 15.4-2 +- Fix the ia32 build. + Resolves: CVE-2020-14372 + Resolves: CVE-2020-25632 + Resolves: CVE-2020-25647 + Resolves: CVE-2020-27749 + Resolves: CVE-2020-27779 + Resolves: CVE-2021-20225 + Resolves: CVE-2021-20233 + +* Tue Mar 30 2021 Peter Jones - 15.4-1 +- Update to shim 15.4 + - Support for revocations via the ".sbat" section and SBAT EFI variable + - A new unit test framework and a bunch of unit tests + - No external gnu-efi dependency + - Better CI + Resolves: CVE-2020-14372 + Resolves: CVE-2020-25632 + Resolves: CVE-2020-25647 + Resolves: CVE-2020-27749 + Resolves: CVE-2020-27779 + Resolves: CVE-2021-20225 + Resolves: CVE-2021-20233 + +* Wed Mar 24 2021 Peter Jones - 15.3-0~1 +- Update to shim 15.3 + - Support for revocations via the ".sbat" section and SBAT EFI variable + - A new unit test framework and a bunch of unit tests + - No external gnu-efi dependency + - Better CI + Resolves: CVE-2020-14372 + Resolves: CVE-2020-25632 + Resolves: CVE-2020-25647 + Resolves: CVE-2020-27749 + Resolves: CVE-2020-27779 + Resolves: CVE-2021-20225 + Resolves: CVE-2021-20233 + +* Wed Jun 05 2019 Javier Martinez Canillas - 15-3 +- Make EFI variable copying fatal only on secureboot enabled systems + Resolves: rhbz#1715878 +- Fix booting shim from an EFI shell using a relative path + Resolves: rhbz#1717064 + +* Tue Feb 12 2019 Peter Jones - 15-2 +- Fix MoK mirroring issue which breaks kdump without intervention + Related: rhbz#1668966 + +* Thu Apr 05 2018 Peter Jones - 15-1 +- Update to shim 15 +- better checking for bad linker output +- flicker-free console if there's no error output +- improved http boot support +- better protocol re-installation +- dhcp proxy support +- tpm measurement even when verification is disabled +- REQUIRE_TPM build flag +- more reproducable builds +- measurement of everything verified through shim_verify() +- coverity and scan-build checker make targets +- misc cleanups + +* Fri Feb 09 2018 Fedora Release Engineering - 13-0.2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + +* Fri Aug 18 2017 Peter Jones - 13-0.1 +- Make a new shim-unsigned-x64 package like the shim-unsigned-aarch64 one. +- This will (eventually) supersede what's in the "shim" package so we can + make "shim" hold the signed one, which will confuse fewer people. diff --git a/shim.patches b/shim.patches new file mode 100644 index 0000000..e69de29 diff --git a/sources b/sources new file mode 100644 index 0000000..809a697 --- /dev/null +++ b/sources @@ -0,0 +1,4 @@ +SHA512 (almalinux-sb-cert-1.der) = 9190a7d5808d3f4181f0f868d07ba83368357a02970f40594e5ec880d33771d890c69f1dfd4ce6c2bc92e6e14217be1aebf7ecc045e6603032b50e33228763ae +SHA512 (almalinux-sb-cert-2.der) = 15a8e4b8a835f26ec552e9574ebec683cef13101734cd6b5ec52925a4e58f199325443a368be85093963998e633258c61c003b66151859694cc47bedd9fbd911 +SHA512 (almalinux-sb-cert-3.der) = 8cc47b54781dc140e8c96977ca10f30bf875f469d27b77a5423bf62d7f41689679069746cfe4fd373e880297e769b445398454ad5256873007b88b755fe894cf +SHA512 (shim-16.1.tar.bz2) = ca5f80e82f3b80b622028f03ef23105c98ee1b6a25f52a59c823080a3202dd4b9962266489296e99f955eb92e36ce13e0b1d57f688350006bba45f2718f159fb