mirror of
https://git.proxmox.com/git/efi-boot-shim
synced 2025-08-11 14:56:52 +00:00
Block Debian grub binaries with sbat < 4 (see #1024617)
This commit is contained in:
parent
736533df5b
commit
ba98d1fec3
3
debian/changelog
vendored
3
debian/changelog
vendored
@ -7,8 +7,9 @@ shim (15.7-1) UNRELEASED; urgency=medium
|
|||||||
* Update to Standards-Version 4.6.2 (no changes needed)
|
* Update to Standards-Version 4.6.2 (no changes needed)
|
||||||
* Enable NX support at build time, as required by policy for signing
|
* Enable NX support at build time, as required by policy for signing
|
||||||
new shim binaries.
|
new shim binaries.
|
||||||
|
* Block Debian grub binaries with sbat < 4 (see #1024617)
|
||||||
|
|
||||||
-- Steve McIntyre <93sam@debian.org> Sun, 22 Jan 2023 13:12:14 +0000
|
-- Steve McIntyre <93sam@debian.org> Sun, 29 Jan 2023 23:34:40 +0000
|
||||||
|
|
||||||
shim (15.6-1) unstable; urgency=medium
|
shim (15.6-1) unstable; urgency=medium
|
||||||
|
|
||||||
|
19
debian/patches/block-grub-sbat3-debian.patch
vendored
Normal file
19
debian/patches/block-grub-sbat3-debian.patch
vendored
Normal file
@ -0,0 +1,19 @@
|
|||||||
|
diff --git a/include/sbat_var_defs.h b/include/sbat_var_defs.h
|
||||||
|
index 6b01573e..5b1a764f 100644
|
||||||
|
--- a/include/sbat_var_defs.h
|
||||||
|
+++ b/include/sbat_var_defs.h
|
||||||
|
@@ -35,8 +35,12 @@
|
||||||
|
SBAT_VAR_SIG SBAT_VAR_VERSION SBAT_VAR_PREVIOUS_DATE "\n" \
|
||||||
|
SBAT_VAR_PREVIOUS_REVOCATIONS
|
||||||
|
|
||||||
|
-#define SBAT_VAR_LATEST_DATE "2022111500"
|
||||||
|
-#define SBAT_VAR_LATEST_REVOCATIONS "shim,2\ngrub,3\n"
|
||||||
|
+/*
|
||||||
|
+ * Debian's grub.3 update was broken - some binaries included the SBAT
|
||||||
|
+ * data update but not the security patches :-(
|
||||||
|
+ */
|
||||||
|
+#define SBAT_VAR_LATEST_DATE "2023012900"
|
||||||
|
+#define SBAT_VAR_LATEST_REVOCATIONS "shim,2\ngrub,3\ngrub.debian,4\n"
|
||||||
|
#define SBAT_VAR_LATEST \
|
||||||
|
SBAT_VAR_SIG SBAT_VAR_VERSION SBAT_VAR_LATEST_DATE "\n" \
|
||||||
|
SBAT_VAR_LATEST_REVOCATIONS
|
1
debian/patches/series
vendored
1
debian/patches/series
vendored
@ -1,2 +1,3 @@
|
|||||||
Make-sbat_var.S-parse-right-with-buggy-gcc-binutils.patch
|
Make-sbat_var.S-parse-right-with-buggy-gcc-binutils.patch
|
||||||
Enable-NX.patch
|
Enable-NX.patch
|
||||||
|
block-grub-sbat3-debian.patch
|
||||||
|
Loading…
Reference in New Issue
Block a user