[SRU] [HWE] Backport gnu-efi 3.0.2 to 15.04

Bug #1512510 reported by Mathieu Trudel-Lapierre
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gnu-efi (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

[Impact]
Shipping fwupdate in 15.04 (hardware enablement tool; a firmware updater tool) requires the use of gnu-efi >= 3.0.2.

[Test Case]
1) Attempt to build fwupdate in 15.04.
   Without gnu-efi >= 3.0.2, the build will fail to complete.
2) build shim and sbsigntool in 15.04.
3) verify that shim and sbsigntool run correctly when rebuilt against gnu-efi 3.0.2.

[Regression Potential]
Limited to EFI installations. Issues in efivar may incur specific failures at handling EFI variables; or when trying to build EFI images (which may show as unexpected behavior in these images).

However, gnu-efi 3.0.2 is already shipping in 15.10 and has not been causing issues.

Revision history for this message
Steve Langasek (vorlon) wrote :

$ reverse-depends -b src:gnu-efi
Reverse-Build-Depends
=====================
* efitools (for gnu-efi)
* fwupdate (for gnu-efi)
* gummiboot (for gnu-efi)
* kexec-tools (for gnu-efi)
* sbsigntool (for gnu-efi)
* shim (for gnu-efi)
* systemd (for gnu-efi)
$

This impacts several packages other than fwupdate. The SRU test case needs to include confirming buildability of all of these reverse-dependencies, and confirming that shim and sbsigntool work correctly after rebuild.

Revision history for this message
Mathieu Trudel-Lapierre (cyphermox) wrote :

All of the reverse-dependencies build correctly except efitools, which was already failing to build for i386 (but the fix is apparent to me now, and I'll correct the issue in xenial ASAP).

Steve Langasek (vorlon)
description: updated
Revision history for this message
Steve Langasek (vorlon) wrote : Please test proposed package

Hello Mathieu, or anyone else affected,

Accepted gnu-efi into vivid-proposed. The package will build now and be available at https://launchpad.net/ubuntu/+source/gnu-efi/3.0.2-1ubuntu1~15.04.1 in a few hours, and then in the -proposed repository.

Please help us by testing this new package. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to enable and use -proposed. Your feedback will aid us getting this update out to other Ubuntu users.

If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested, and change the tag from verification-needed to verification-done. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-failed. In either case, details of your testing will help us make a better decision.

Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance!

tags: added: verification-needed
Revision history for this message
Mathieu Trudel-Lapierre (cyphermox) wrote :

sbsigntool and shim were also tested separately after rebuild; I used the code being built for vivid, installed on xenial, used sbsigntool to sign the shim image (and an EFI shell image), after adding my local key I was able to boot both images successfully with SecureBoot enabled. The shim image obviously also works if SecureBoot isn't enabled.

Revision history for this message
Mathieu Trudel-Lapierre (cyphermox) wrote :

shim and sbsigntool were tested after a rebuild in a PPA against the same version of gnu-efi shipped to vivid; marking verification-done.

tags: added: verification-done
removed: verification-needed
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package gnu-efi - 3.0.2-1ubuntu1~15.04.1

---------------
gnu-efi (3.0.2-1ubuntu1~15.04.1) vivid; urgency=medium

  * Backport gnu-efi to 15.04; to support fwupdate. (LP: #1512510)

 -- Mathieu Trudel-Lapierre <email address hidden> Mon, 02 Nov 2015 16:45:49 -0600

Changed in gnu-efi (Ubuntu):
status: New → Fix Released
Revision history for this message
Steve Langasek (vorlon) wrote : Update Released

The verification of the Stable Release Update for gnu-efi has completed successfully and the package has now been released to -updates. Subsequently, the Ubuntu Stable Release Updates Team is being unsubscribed and will not receive messages about this bug report. In the event that you encounter a regression using the package from -updates please report a new bug using ubuntu-bug and tag the bug report regression-update so we can easily find any regressions.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.