rhboot / shim-review

Reviews of shim
66 stars 131 forks source link

Alpaquita Linux shim-15.8 x64 and aarch64 #426

Closed akodanev closed 3 months ago

akodanev commented 5 months ago

Confirm the following are included in your repo, checking each box:


What is the link to your tag in a repo cloned from rhboot/shim-review?


https://github.com/akodanev/shim-review/tree/alpaquita-shim-x64-aarch64-20240624


What is the SHA256 hash of your final SHIM binary?


f83b753616fab1bffa57a1ea446577c1c20e36d0726885ae6f9da035cf12ef9b  shimaa64.efi
2b2f2dada7a8e0060dfbd8d6d4ef926b0d57a49edb8560623091eedcc9f205fd  shimx64.efi

What is the link to your previous shim review request (if any, otherwise N/A)?


https://github.com/rhboot/shim-review/issues/325


If no security contacts have changed since verification, what is the link to your request, where they've been verified (if any, otherwise N/A)?


https://github.com/rhboot/shim-review/issues/325#issuecomment-1755613348

steve-mcintyre commented 5 months ago

Contact verification has been done previously, marking as such

THS-on commented 5 months ago

Review for alpaquita-shim-x64-aarch64-20240528

Shim

Kernel

GRUB

Notes and questions

Besides those questions LGTM

akodanev commented 5 months ago

@THS-on thanks for your review!

Last review was accepted, but not signed by MS

It was returned signed by Microsoft some time after the issue was closed. I should have mentioned this in a comment there.

The latest submission template includes now question on how you contributed to the shim review process

Added. The new tag is https://github.com/akodanev/shim-review/tree/alpaquita-shim-x64-aarch64-20240624.

Are you planning on signing UKIs, systemd-boot or fwupd in the future?

There are no plans to sign UKI or systemd-boot. However, we will most likely make the fwupd component available for review in the next shim update.

THS-on commented 4 months ago

@akodanev thanks for the clarifications. LGTM from my side.

SherifNagy commented 4 months ago

Review of alpaquita-shim-x64-aarch64-20240624

Shim

GRUB2

Kernel

Notes

Other than those few notes, LGTM

akodanev commented 4 months ago

For your next submission, make sure to include the patch from here

OK. I am hoping that this will be the next release of the shim so that the patch will already be there.

Regarding grub2 sbat entry, if you are fetching from Alpine, I guess you need to maintain the upstream SBAT entry int your SBAT

There is none upstream. Maybe it's only helpful if there's more than one such shim/grub based on this Alpine version.

Other than those few notes, LGTM

Thank you @SherifNagy!

THS-on commented 4 months ago

Regarding grub2 sbat entry, if you are fetching from Alpine, I guess you need to maintain the upstream SBAT entry int your SBAT, @THS-on any thoughts on this?

@SherifNagy as mentioned Alpine does not have one. As the current package is mostly vanilla GRUB2 + peimage patches, I'm fine with not having an Alpine specific one.

THS-on commented 4 months ago

marking it as accepted

akodanev commented 3 months ago

The signed binaries received. Closing this as completed.