← Back to team overview

group.of.nepali.translators team mailing list archive

[Bug 1928434] Re: shim-signed does not boot on EFI 2.40 by Apple

 

This bug was fixed in the package shim-signed - 1.37~18.04.10

---------------
shim-signed (1.37~18.04.10) bionic; urgency=medium

  * Remove unnecessary efitools dependency that prevented build on arm64

shim-signed (1.37~18.04.9) bionic; urgency=medium

  * New upstream release 15.4.  LP: #1921134
  * Synchronize packaging with 1.50, summary
    - Update packaging to pull fb and mm from shim-signed package as in
      later releases, dropping the runtime dependency on shim.
    - Add download-signed script from linux-signed package
    - Include reworked Makefile from devel to better assert the integrity of
      the executables.
    - Dual-signed shim
    - Set XB-Important: yes on shim-signed package so that it cannot be
      removed by accident (LP: #1898729)
    - download-signed: Fetch signed artefacts from versioned URL instead
      of current/ symlink to work around caching (LP: #1936640)
  * Update to shim 15.4-0ubuntu5:
    - Stop addending vendor dbx to MokListXRT during MokListX mirroring. This
      is causing systems to run out of EFI storage space, or just hang up
      when trying to write it (LP: #1924605) (LP: #1928434)
    - Further relax the check for variable mirroring on non-secureboot systems
      avoiding boot failures on out of space conditons (pull request #372)
    - Don't unhook ExitBootServices() when EBS protection is disabled
      (LP: #1931136) (pull request #378)
  * Update to shim 15.4-0ubuntu7:
    - Fix load option parsing, and thus fwupd execution (LP: #1929471) (PR #379)
    - Fix occasional crashes in _relocate() on arm64 (LP: #1928010) (PR #383)
    - Fix accidental deletion of RT variables (LP: #1934506) (PR #387)
    - mok: relax the maximum variable size check (LP: #1934780) (PR #369)

 -- Julian Andres Klode <juliank@xxxxxxxxxx>  Mon, 19 Jul 2021 17:01:19
+0200

** Changed in: shim-signed (Ubuntu Bionic)
       Status: Fix Committed => Fix Released

-- 
You received this bug notification because you are a member of नेपाली
भाषा समायोजकहरुको समूह, which is subscribed to Xenial.
Matching subscriptions: Ubuntu 16.04 Bugs
https://bugs.launchpad.net/bugs/1928434

Title:
  shim-signed does not boot on EFI 2.40 by Apple

Status in shim package in Ubuntu:
  Fix Released
Status in shim-signed package in Ubuntu:
  Fix Released
Status in shim source package in Xenial:
  Fix Released
Status in shim-signed source package in Xenial:
  Fix Released
Status in shim-signed source package in Bionic:
  Fix Released
Status in shim source package in Focal:
  Fix Released
Status in shim-signed source package in Focal:
  Fix Released
Status in shim source package in Hirsute:
  Fix Released
Status in shim-signed source package in Hirsute:
  Fix Released

Bug description:
  [Impact]
  Booting MacBook is broken

  [Test plan]
  We don't have a test plan per se to verify this bug, but the shim fix has been tested. Hard to verify those bugs :(

  [Where problems could occur]
  We disable mirroring of vendor dbx into MokListXRT EFI variable, so mokutil is not able to read the vendor dbx anymore. Other things might not be able to do so either; we don't believe we've been using it so far, though.

  [Original bug report]
  Hi,

  I have a MacBookPro14,3. After upgrade to Ubuntu 21.04 it failed to boot.
  At first I thought I'm affected by https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1925010.

  But my MacBook has newer efi Version and the fixed version of shim-
  signed is not solving my issues.

  >sudo dmesg | grep EFI
  [    0.000000] efi: EFI v2.40 by Apple
  [    0.011978] ACPI: UEFI 0x000000007AF7D000 000042 (v01 INTEL  EDK2     00000002      01000013)
  [    0.012029] ACPI: Reserving UEFI table memory at [mem 0x7af7d000-0x7af7d041]
  [    0.411423] fb0: EFI VGA frame buffer device
  [    0.418914] EFI Variables Facility v0.08 2004-May-17
  [    2.696996] fb0: switching to amdgpudrmfb from EFI VGA

  I reinstalled Ubuntu 21.04 from scratch and updated all packages during installation.
  The reboot failed. I hear the apple start sound and then an endless repeating echo.
  I've chrooted inside my system and verified that shim-signed 1.47+15.4-0ubuntu2 is installed.

  The suggested workaround from the other bug works (I can normally boot afterwards):
  /boot/efi/EFI# cp -b ubuntu/grubx64.efi ubuntu/shimx64.efi
  /boot/efi/EFI# cp -b ubuntu/grubx64.efi BOOT/BOOTX64.EFI

  "sudo apt reinstall shim-signed" reliable breaks my macbook again.

  Is there anything I can do to help solving this issue? What do you
  need?

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/shim/+bug/1928434/+subscriptions