|
|
|
|
Changelog for shim-15.4-lp154.54.1.x86_64.rpm :
* Wed Jun 07 2023 Gary Ching-Pang Lin - Update shim-install to support FDE + Read GRUB_CRYPTODISK_PASSWORD and GRUB_TPM2_SEALED_KEY to create the proper cryptomount command for grub.cfg + Save the PCR snapshot if grub2 supports the command + Support \'no_grub_install\' to skip grub2-install + Detect the OS ID of openSUSE Leap * Thu May 25 2023 Gary Ching-Pang Lin - Remove the sym-links in /usr/lib64/efi for the newer distro versions since we don\'t use them anymore * Wed Jul 21 2021 jleeAATTsuse.com- Update to shim to 15.4-lp152.4.17.1 from openSUSE Leap 15.2 + Version: 15.4, \"Thu Jul 15 2021\" + Updated openSUSE x86 signature + Include the fixes for bsc#1187696, bsc#1185261, bsc#1185441, bsc#1187071, bsc#1185621, bsc#1185261, bsc#1185232, bsc#1185261, bsc#1187260, bsc#1185232.- Remove shim-install because the shim-install is updated in Leap 15.2 RPM. * Thu May 20 2021 Gary Ching-Pang Lin - shim-install: instead of assuming \"removable\" for Azure, remove fallback.efi from \\EFI\\Boot and copy grub.efi/cfg to \\EFI\\Boot to make \\EFI\\Boot bootable and keep the boot option created by efibootmgr (bsc#1185464, bsc#1185961) * Fri May 07 2021 Gary Ching-Pang Lin - shim-install: always assume \"removable\" for Azure to avoid the endless reset loop (bsc#1185464) * Tue Apr 27 2021 Gary Ching-Pang Lin - Update to shim to 15.4-lp152.4.8.1 from openSUSE Leap 15.2 for SBAT support (bsc#1182057) + Version: 15.4, \"Wed Apr 21 05:46:19 UTC 2021\" + Include the fixes for bsc#1177789, CVE-2019-14584, bsc#1177315, bsc#1175509, bsc#1173411, bsc#1177404, bsc#1174512, bsc#1184454- Add README to note why we need shim-leap for Tumbleweed * Thu Aug 27 2020 Gary Ching-Pang Lin - Update shim to 15+git47-lp152.4.5.1 from openSUSE Leap 15.2 + shim-install: install MokManager to \\EFI\\boot to process the pending MOK request (bsc#1175626, bsc#1175656) * Tue Aug 11 2020 Gary Ching-Pang Lin - Update shim to 15+git47-lp152.4.3.1 from openSUSE Leap 15.2 + Version: 15+git47 \"Fri Jul 31 07:41:26 UTC 2020\" + Use shim-install in the rpm package * Wed Jul 22 2020 Gary Ching-Pang Lin - Update the path to grub-tpm.efi in shim-install (bsc#1174320)- shim-install: add check for btrfs is used as root file system to enable relative path lookup for file. (bsc#1153953)- Update shim-install to handle the partitioned MD devices (bsc#1119762, bsc#1119763)- Update grub2 path in shim-install * Tue Mar 31 2020 Gary Ching-Pang Lin - Use the full path of efibootmgr to avoid errors when invoking shim-install from packagekitd (bsc#1168104) * Mon Mar 30 2020 Gary Ching-Pang Lin - Use \"suse_version\" instead of \"sle_version\" to avoid shim_lib64_share_compat being set in Tumbleweed forever. * Fri Mar 27 2020 Gary Ching-Pang Lin - Move \'efi\'-executables to \'/usr/share/efi\' (FATE#326960, bsc#1166523) * Thu Dec 06 2018 Gary Ching-Pang Lin - Update shim-install to set the grub2-install target explicitly for some special cases. (bsc#1118363) * Fri Jun 08 2018 glinAATTsuse.com- Update shim to 14-lp150.8.5.1 + Replace shim-bsc1092000-fallback-always-try-first-option.patch with shim-bsc1092000-fallback-menu.patch to show a countdown menu before reset (bsc#1092000) * Mon May 14 2018 glinAATTsuse.com- Update shim to 14-lp150.7.3 + Amend fallback.efi to avoid being trapped in the infinite reset loop (bsc#1092000) * Wed Apr 25 2018 mlinAATTsuse.com- Update shim to 14-lp150.4.1- New signature from Microsoft * Tue Apr 25 2017 glinAATTsuse.com- Update shim to 0.9-15.3.1 + shim-install: add option --suse-enable-tpm (fate#315831) (Fix from mchangAATTsuse.com) * Tue Dec 27 2016 glinAATTsuse.com- Update shim to 0.9-13.1 + Update shim-install to support \"--no-nvram\" and improve removable media and fallback mode handling (bsc#985568, bsc#999818) (Fix from mchangAATTsuse.com) * Fri Oct 07 2016 jsegitzAATTnovell.com- New signature from Microsoft * Fri Aug 19 2016 mchangAATTsuse.com- shim-install : fix regression of password prompt (bsc#993764) * Fri Aug 05 2016 glinAATTsuse.com- Add shim-bsc991885-fix-sig-length.patch to fix the signature length passed to Authenticode (bsc#991885) * Wed Aug 03 2016 glinAATTsuse.com- Update shim-bsc973496-mokmanager-no-append-write.patch to try append write first * Tue Aug 02 2016 glinAATTsuse.com- Add shim-update-openssl-1.0.2h.patch to update openssl to 1.0.2h- Bump the requirement of gnu-efi due to the HTTPBoot support * Mon Aug 01 2016 glinAATTsuse.com- Add shim-httpboot-support.patch to support HTTPBoot- Add shim-update-openssl-1.0.2g.patch to update openssl to 1.0.2g and Cryptlib to 5e2318dd37a51948aaf845c7d920b11f47cdcfe6- Drop patches since they are merged into shim-update-openssl-1.0.2g.patch + shim-update-openssl-1.0.2d.patch + shim-gcc5.patch + shim-bsc950569-fix-cryptlib-va-functions.patch + shim-fix-aarch64.patch- Refresh shim-change-debug-file-path.patch- Add shim-bsc973496-mokmanager-no-append-write.patch to work around the firmware that doesn\'t support APPEND_WRITE (bsc973496)- shim-install : remove \'\ \' from the help message (bsc#991188)- shim-install : print a message if there is no valid EFI partition (bsc#991187) * Mon May 09 2016 rwAATTsuse.com- shim-install : support simple MD RAID1 target devices (FATE#314829) * Wed May 04 2016 agrafAATTsuse.com- Add shim-fix-aarch64.patch to fix compilation on AArch64 (bsc#978438) * Wed Mar 09 2016 mchangAATTsuse.com- shim-install : fix typing ESC can escape to parent config which is in command mode and cannot return back (bsc#966701)- shim-install : fix no which command for JeOS (bsc#968264) * Thu Dec 03 2015 jsegitzAATTnovell.com- acquired updated signature from Microsoft * Mon Nov 09 2015 glinAATTsuse.com- Add shim-bsc950569-fix-cryptlib-va-functions.patch to fix the definition of va functions to avoid the potential crash (bsc#950569)- Update shim-opensuse-cert-prompt.patch to avoid setting NULL to MokListRT (bsc#950801)- Drop shim-fix-mokmanager-sections.patch as we are using the newer binutils now- Refresh shim-change-debug-file-path.patch * Thu Oct 08 2015 jsegitzAATTnovell.com- acquired updated signature from Microsoft * Tue Sep 15 2015 mchangAATTsuse.com- shim-install : set default GRUB_DISTRIBUTOR from /etc/os-release if it is empty or not set by user (bsc#942519) * Thu Jul 16 2015 glinAATTsuse.com- Add shim-update-openssl-1.0.2d.patch to update openssl to 1.0.2d- Refresh shim-gcc5.patch and add it back since we really need it- Add shim-change-debug-file-path.patch to change the debug file path in shim.efi + also add the debuginfo and debugsource subpackages- Drop shim-fix-gnu-efi-30w.patch which is not necessary anymore * Mon Jul 06 2015 glinAATTsuse.com- Update to 0.9- Refresh patches + shim-fix-gnu-efi-30w.patch + shim-fix-mokmanager-sections.patch + shim-opensuse-cert-prompt.patch- Drop upstreamed patches + shim-bsc920515-fix-fallback-buffer-length.patch + shim-mokx-support.patch + shim-update-cryptlib.patch- Drop shim-bsc919675-uninstall-shim-protocols.patch since upstream fixed the bug in another way.- Drop shim-gcc5.patch which was fixed in another way * Wed Apr 08 2015 glinAATTsuse.com- Fix tags in the spec file * Tue Apr 07 2015 glinAATTsuse.com- Add shim-update-cryptlib.patch to update Cryptlib to r16559 and openssl to 0.9.8zf- Add shim-bsc919675-uninstall-shim-protocols.patch to uninstall the shim protocols at Exit (bsc#919675)- Add shim-bsc920515-fix-fallback-buffer-length.patch to adjust the buffer size for the boot options (bsc#920515)- Refresh shim-opensuse-cert-prompt.patch * Thu Apr 02 2015 crrodriguezAATTopensuse.org- shim-gcc5.patch: shim needs -std=gnu89 to build with GCC5 * Tue Feb 17 2015 mchangAATTsuse.com- shim-install : fix cryptodisk installation (boo#917427) * Tue Nov 11 2014 glinAATTsuse.com- Add shim-fix-mokmanager-sections.patch to fix the objcopy parameters for the EFI files * Tue Oct 28 2014 glinAATTsuse.com- Update to 0.8- Add shim-fix-gnu-efi-30w.patch to adapt the change in gnu-efi-3.0w- Merge shim-signed-unsigned-compares.patch, shim-mokmanager-support-sha-family.patch and shim-bnc863205-mokmanager-fix-hash-delete.patch into shim-mokx-support.patch- Refresh shim-opensuse-cert-prompt.patch- Drop upstreamed patches: shim-update-openssl-0.9.8zb.patch, bug-889332_shim-overflow.patch, and bug-889332_shim-mok-oob.patch- Enable aarch64 * Mon Oct 13 2014 jsegitzAATTnovell.com- Fixed buffer overflow and OOB access in shim trusted code path (bnc#889332, CVE-2014-3675, CVE-2014-3676, CVE-2014-3677) * added bug-889332_shim-mok-oob.patch, bug-889332_shim-overflow.patch- Added new certificate by Microsoft
|
|
|