-
Notifications
You must be signed in to change notification settings - Fork 131
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Blancco Shim 15.7 for x64 & ia32 #290
Comments
Tagged a new release, we needed to replace the embedded certificate. |
You appear to be using Red Hat's grub2 + shim (which is of course fine). But I don't see from your submission why you need to rebuild them - could you not just ship Red Hat's signed shim+grub2+kernel directly? |
I'd have to compare the Red Hat Kconfig with ours to find all of the differences but end of the day the biggest issue is that we have a variety of custom kernel patches (mainly to storage drivers) to work around a variety of quirks. These have not been upstreamed. |
Updated the shim request to version 15.7. Need any additional information from our end? |
Updated the shim submission with the NX compatibility flags set. |
@frozencemetery @vathpela Checking to see if there is something we need to do on our end. Our customers are having to turn off secure boot to use our products. |
Please note #307 |
@frozencemetery We're already setting the NX flag, as can be seen in the Dockerfile. I can switch to providing a patch, but it seems unnecessary given the changes. Is there some other issue holding this up?
|
@frozencemetery |
@frozencemetery |
@don-blancco, answering your question:
As far as I can see, the best people can do to speed up the reviewing process is to help review other issues - the point of this project is that issues should be peer-reviewed:
|
Working on this now, apologies for the delay. Identification mails sent - please follow the instructions there. |
Review of Blancco Shim 15.7 for x64 & ia32 blancco-shim15.7-x64-ia32-20230103OK
Issues / queries / outstanding
|
Thanks for reviewing, @steve-mcintyre ! About the kernel patches, we sometimes patch the kernel for hardware support issues, from patches that have not been accepted into mainline yet, or backporting to the version we are using at that moment. |
@steve-mcintyre decriminalize crest redoubtable nodular inkwells nonconductor canisters programmed rankness turmoil |
Could you also please update the copy of shimx64.efi in git as well? |
Hmmm, ok. |
Updated on today's tag. |
Still waiting on contact verification from @evilteq |
I'm me, I swear ;) |
Validating identity: midland wrests nasturtiums galleys optimizer investiture swigging Han booklets bologna |
Review of
|
Thanks for reviewing!
|
Can you make an update to GRUB2 and include it with the SBAT in the review just to document it? Otherwise this LGTM! If @steve-mcintyre confirms the contact verification and finishes the review, this should be ready to go. |
Yes, contact verification looks fine. I can't find any mention of the labels for that now which is odd :-( Happy to mark this approved if we can see a new GRUB2 build. |
NTFS patches are still not applied in their repository. Just for a quick test, I've applied them manually and everything seems fine. |
Yes indeed. Just apply them once they are in their repo or applied as patches in Fedora. @evilteq can you add the SBAT of a current GRUB2 build with upstream line appended to the review, for documentation |
We just updated the review repo with today's tag with the SBAT of a test build of fedora + ntfs cve patches. |
LGTM, marking as accepted. Just make sure that when you are building a GRUB2 with SBAT level 4 to include ntfs patches, because as mentioned the git branch currently does not include them. |
Thank you very much everyone, we've received the signed shims from Microsoft. |
Confirm the following are included in your repo, checking each box:
What is the link to your tag in a repo cloned from rhboot/shim-review?
https://github.com/dpedigo/shim-review/tree/blancco-shim15.7-x64-ia32-20231113
What is the SHA256 hash of your final SHIM binary?
What is the link to your previous shim review request (if any, otherwise N/A)?
#9
The text was updated successfully, but these errors were encountered: