Bug 4631 - [NEWPACKAGE+UPDATE REQUEST] coolkey, pesign, popt, shim-unsigned
: [NEWPACKAGE+UPDATE REQUEST] coolkey, pesign, popt, shim-unsigned
Status: VERIFIED FIXED
Product: Desktop Bugs
Classification: ROSA Desktop
Component: Main Packages
: Fresh
: All Linux
: Normal normal
: ---
Assigned To: ROSA Linux Bugs
: ROSA Linux Bugs
:
Depends on: 4630
Blocks:
  Show dependency treegraph
 
Reported: 2014-11-07 21:07 MSK by Konstantin Vlasov
Modified: 2014-11-24 15:27 MSK (History)
3 users (show)

See Also:
RPM Package:
ISO-related:
Bad POT generating:
Upstream:
vladimir.potapov: qa_verified+
kuzma.kazygashev: secteam_verified+
denis.silakov: published+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Konstantin Vlasov 2014-11-07 21:07:13 MSK
For implementing SecureBoot support, shim-unsigned package with its requirements should be added to the main repository.

Please, note that updated efivar>=0.12 is also required; see bug #4630.
Comment 1 Konstantin Vlasov 2014-11-07 21:09:43 MSK
popt (update):
https://abf.rosalinux.ru/build_lists/2325930
https://abf.rosalinux.ru/build_lists/2325931

Advisory: Fixed provided dependency.


coolkey (new package):
https://abf.rosalinux.ru/build_lists/2325452
https://abf.rosalinux.ru/build_lists/2325422

Advisory: Linux Driver support for the CoolKey and CAC products.
 

pesign (new package):
https://abf.rosalinux.ru/build_lists/2325936
https://abf.rosalinux.ru/build_lists/2325937

Advisory: Utility for signing UEFI binaries as well as other associated tools.


shim-unsigned (new package, x86_64 only):
https://abf.rosalinux.ru/build_lists/2329982

Advisory: Initial UEFI bootloader that handles chaining to a trusted full bootloader under secure boot environments.


P.S. Please, disregard the fact that ABF tests failed. The problem is caused by urpmi ("losing" some of the packages during installation).
Comment 2 Konstantin Vlasov 2014-11-07 21:17:57 MSK
Sorry, a typo in the link. Correct buildlists for coolkey:
https://abf.rosalinux.ru/build_lists/2325452
https://abf.rosalinux.ru/build_lists/2325421
Comment 3 Vladimir Potapov 2014-11-19 16:23:10 MSK
urpmi shim-unsigned


    http://abf-downloads.rosalinux.ru/rosa2014.1/container/2329982/x86_64/main/release/shim-unsigned-0.8-1-rosa2014.1.x86_64.rpm
устанавливается shim-unsigned-0.8-1-rosa2014.1.x86_64.rpm из /var/cache/urpmi/rpms                                                                                             
Подготовка...                    #############################################################################################################################################  
Установка не удалась:   файл /boot/efi/EFI/rosa/MokManager.efi из устанавливаемого пакета shim-unsigned-0.8-1.x86_64 конфликтует с файлом из пакета shim-0.2-1.x86_64           
        файл /boot/efi/EFI/rosa/shim.efi из устанавливаемого пакета shim-unsigned-0.8-1.x86_64 конфликтует с файлом из пакета shim-0.2-1.x86_64
Comment 4 Konstantin Vlasov 2014-11-19 17:28:32 MSK
Hm... Didn't think about it. OK, I'll add a Conflict rule, and the "shim" package will have to be removed for testing shim-unsigned. These two packages, indeed, cannot coexist on the same system since shim is just the Microsoft-signed version of shim-unsigned (we have to keep them separately to avoid losing signed binary required for future SecureBoot support).

BTW, please, delay this update request for a little: I've decided to rearrange projects structure a bit, so that shim and mokutil would be separate projects. I'll post new buildlists here when ready.
Comment 5 Vladimir Potapov 2014-11-19 17:58:52 MSK
ок. Please, reopen the request with new containers
**************************************************
QA Denied
Comment 6 Konstantin Vlasov 2014-11-20 03:35:05 MSK
popt (update):
https://abf.rosalinux.ru/build_lists/2325930
https://abf.rosalinux.ru/build_lists/2325931

Advisory: Fixed provided dependency.


coolkey (new package):
https://abf.rosalinux.ru/build_lists/2325452
https://abf.rosalinux.ru/build_lists/2325421

Advisory: Linux Driver support for the CoolKey and CAC products.
 

pesign (new package):
https://abf.rosalinux.ru/build_lists/2325936
https://abf.rosalinux.ru/build_lists/2325937

Advisory: Utility for signing UEFI binaries as well as other associated tools.


shim-unsigned (new package):
https://abf.rosalinux.ru/build_lists/2335232
https://abf.rosalinux.ru/build_lists/2335233

Advisory: Initial UEFI bootloader that handles chaining to a trusted full bootloader under secure boot environments.


mokutil (new package, x86_64 only):
https://abf.rosalinux.ru/build_lists/2335036

Advisory: Utility for managing SecureBoot/MOK database.
Comment 7 Vladimir Potapov 2014-11-24 13:31:22 MSK
popt-1.16-14
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2325930/i586/main/release/
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2325931/x86_64/main/release/

coolkey-1.1.0-25
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2325452/i586/main/release/
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2325421/x86_64/main/release/

pesign-0.108-3
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2325936/i586/main/release/
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2325937/x86_64/main/release/

shim-unsigned-0.8-1
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2335232/i586/main/release/
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2335233/x86_64/main/release/

mokutil-0.3.0-1
http://abf-downloads.rosalinux.ru/rosa2014.1/container/2335036/x86_64/main/release/

*********************** Advisory ************************
popt: Fixed provided dependency.
coolkey (new package): Linux Driver support for the CoolKey and CAC products.
pesign (new package): Utility for signing UEFI binaries as well as other associated tools.
shim-unsigned (new package): Initial UEFI bootloader that handles chaining to a trusted full bootloader under secure boot environments.
mokutil (new package): Utility for managing SecureBoot/MOK database.
**********************************************************
QA Verified