Go to file
Fabian Grünbichler 348ed14e27 bump version to 16.0-1+pmx1
Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
2025-03-28 10:27:31 +01:00
.github/workflows New upstream version 16.0 2025-03-24 10:18:24 +01:00
Cryptlib New upstream version 16.0 2025-03-24 10:18:24 +01:00
data New upstream version 15.8 2024-05-03 16:02:10 +01:00
debian bump version to 16.0-1+pmx1 2025-03-28 10:27:31 +01:00
gnu-efi New upstream version 16.0 2025-03-24 10:18:24 +01:00
include New upstream version 16.0 2025-03-24 10:18:24 +01:00
lib New upstream version 16.0 2025-03-24 10:18:24 +01:00
test-data New upstream version 15.8 2024-05-03 16:02:10 +01:00
.clang-format New upstream version 15.3 2021-03-23 23:49:46 +00:00
.gitignore New upstream version 16.0 2025-03-24 10:18:24 +01:00
.gitmodules New upstream version 16.0 2025-03-24 10:18:24 +01:00
buildid.c Fix up a bunch of our license statements and add SPDX most places 2021-02-16 09:12:48 +01:00
BUILDING New upstream version 16.0 2025-03-24 10:18:24 +01:00
cert.S New upstream version 15.8 2024-05-03 16:02:10 +01:00
CODE_OF_CONDUCT.md New upstream version 16.0 2025-03-24 10:18:24 +01:00
commit New upstream version 16.0 2025-03-24 10:18:24 +01:00
COPYRIGHT Import upstream version 0~20120728.3df9e294 2012-08-29 16:51:10 -07:00
crypt_blowfish.c New upstream version 15.3 2021-03-23 23:49:46 +00:00
csv.c New upstream version 15.5 2022-04-27 22:41:59 +01:00
Delivering_Sbat_Revocations.md New upstream version 16.0 2025-03-24 10:18:24 +01:00
dp.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
elf_aarch64_efi.lds New upstream version 15.7 2023-01-22 13:05:10 +00:00
elf_arm_efi.lds New upstream version 15.5 2022-04-27 22:41:59 +01:00
elf_ia32_efi.lds New upstream version 15.7 2023-01-22 13:05:10 +00:00
elf_ia64_efi.lds New upstream version 15.7 2023-01-22 13:05:10 +00:00
elf_x86_64_efi.lds New upstream version 15.7 2023-01-22 13:05:10 +00:00
errlog.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
fallback.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
fuzz-csv.c New upstream version 15.8 2024-05-03 16:02:10 +01:00
fuzz-pe-relocate.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
fuzz-sbat.c New upstream version 15.8 2024-05-03 16:02:10 +01:00
generate_sbat_var_defs.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
globals.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
httpboot.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
load-options.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
loader-proto.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
make-archive New upstream version 16.0 2025-03-24 10:18:24 +01:00
make-certs New upstream version 16.0 2025-03-24 10:18:24 +01:00
Make.defaults New upstream version 16.0 2025-03-24 10:18:24 +01:00
Make.rules New upstream version 15.8 2024-05-03 16:02:10 +01:00
Makefile New upstream version 16.0 2025-03-24 10:18:24 +01:00
memattrs.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
mock-variables.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
model.c New upstream version 15.8 2024-05-03 16:02:10 +01:00
mok.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
MokManager.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
MokVars.txt New upstream version 16.0 2025-03-24 10:18:24 +01:00
netboot.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
PasswordCrypt.c New upstream version 15.3 2021-03-23 23:49:46 +00:00
pe-relocate.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
pe.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
post-process-pe.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
README.fallback New upstream version 12+1501864225.b586175 2017-08-07 17:34:45 -04:00
README.md New upstream version 15.8 2024-05-03 16:02:10 +01:00
README.tpm New upstream version 16.0 2025-03-24 10:18:24 +01:00
sbat_var.S New upstream version 16.0 2025-03-24 10:18:24 +01:00
sbat.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
SBAT.example.md New upstream version 15.8 2024-05-03 16:02:10 +01:00
SBAT.md New upstream version 16.0 2025-03-24 10:18:24 +01:00
SbatLevel_Variable.txt New upstream version 16.0 2025-03-24 10:18:24 +01:00
shim.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
shim.h New upstream version 16.0 2025-03-24 10:18:24 +01:00
test-csv.c New upstream version 15.5 2022-04-27 22:41:59 +01:00
test-load-options.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
test-mock-variables.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
test-mok-mirror.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
test-pe-relocate.c New upstream version 15.8 2024-05-03 16:02:10 +01:00
test-pe-util.c New upstream version 15.8 2024-05-03 16:02:10 +01:00
test-sbat.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
test-str.c New upstream version 15.6 2022-06-23 00:16:56 +01:00
test.c New upstream version 15.6 2022-06-23 00:16:56 +01:00
testplan.txt New upstream version 15.3 2021-03-23 23:49:46 +00:00
TODO New upstream version 15.3 2021-03-23 23:49:46 +00:00
tpm.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
utils.c New upstream version 16.0 2025-03-24 10:18:24 +01:00
version.c.in New upstream version 15.3 2021-03-23 23:49:46 +00:00
version.h New upstream version 15.3 2021-03-23 23:49:46 +00:00

shim, a first-stage UEFI bootloader

shim is a trivial EFI application that, when run, attempts to open and execute another application. It will initially attempt to do this via the standard EFI LoadImage() and StartImage() calls. If these fail (because Secure Boot is enabled and the binary is not signed with an appropriate key, for instance) it will then validate the binary against a built-in certificate. If this succeeds and if the binary or signing key are not forbidden then shim will relocate and execute the binary.

shim will also install a protocol which permits the second-stage bootloader to perform similar binary validation. This protocol has a GUID as described in the shim.h header file and provides a single entry point. On 64-bit systems this entry point expects to be called with SysV ABI rather than MSABI, so calls to it should not be wrapped.

On systems with a TPM chip enabled and supported by the system firmware, shim will extend various PCRs with the digests of the targets it is loading. A full list is in the file README.tpm .

To use shim, simply place a DER-encoded public certificate in a file such as pub.cer and build with make VENDOR_CERT_FILE=pub.cer.

There are a couple of build options, and a couple of ways to customize the build, described in BUILDING.

See the test plan, and file a ticket if anything fails!

In the event that the developers need to be contacted related to a security incident or vulnerability, please mail secalert@redhat.com.