-
Notifications
You must be signed in to change notification settings - Fork 131
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
shim 15.8 for Navix 8 #370
Comments
Updated questionsThere are some minor fixes that are not mentioned on this list, but they are shim/grub version and typo fixes.
|
Disclaimer: I am not an official reviewer. Basics
CA
shim
GRUB2
Kernel
|
While I am not an official reviewer, here are my comments "looking at latest tag: https://github.com/NaverCloudPlatform/shim-review/tree/navix-shim-x86_64-20240205":
SBAT entry for shim is wrong, seems like a copy / paste error mostly, in the issue it is shim,3 while in the binary it is shim,4 as it should be since you are building 15.8
|
One more thing, but this is a personal preference, I like to submit my mock build and root logs while I am building the SRPM RPM itself instead of the logs from building the docker container, but this is just me :) I know they are very similar, but again, that's just my personal preference |
And there are couple of question into merged into your issue, such as the usage of systemd-boot , stub and UKI |
You're right. We fixed shim's SBAT entry.
We migrated review template to current version and answered all questions. |
We updated our review template to fix errors mentioned by SherifNagy. |
All seems good, typo got fixed. We need to wait for couple of trusted reviewers to look at this. Best of luck with the review process |
The build reproduces, checksums match, NX support properly disabled until the whole chain gets NX support. Accepting! Great job! Notes:
No systemd-boot entries as GRUB2 is used. The answer above got me worried for a moment. No UKIs as far as I'm aware as of today (RHEL 8 fork). |
Awesome! Thank you all people for reviewing our application! |
You need to enroll your company in Microsoft's 'Hardware Development' program and make a request on the platform for shim signing. |
We finally got signed shim binary from Microsoft, |
Confirm the following are included in your repo, checking each box:
What is the link to your tag in a repo cloned from rhboot/shim-review?
https://github.com/NaverCloudPlatform/shim-review/tree/navix-shim-x86_64-20240226
What is the SHA256 hash of your final SHIM binary?
What is the link to your previous shim review request (if any, otherwise N/A)?
#346
The text was updated successfully, but these errors were encountered: