Bug#836140: grub2: support for shim and Secure Boot on arm64

Linn Crosetto linn at hpe.com
Tue Aug 30 21:10:28 UTC 2016


Source: grub2
Version: 2.02~beta2-37
Severity: wishlist
Tags: patch

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

The attached patch sets add support for shim and Secure Boot on arm64. 
 
The first set adds support to GRUB and many of the patches have been pulled
from upstream, with the Origin tags listing the source of each. 12 of the
patches would be picked up with an update to a newer upstream. 
 
The second set is packaging changes to build the UEFI images on Debian.
 
I have tested these patches on top of debian/master (2.02~beta2-37) on QEMU.
The current version of qemu-efi in Stretch is enabled to test with Secure
Boot. Instructions for enabling persistent UEFI variables with QEMU: 
https://wiki.linaro.org/LEG/UEFIforQEMU 

Also included are patches for #820129 and #769172. Kernel support for Secure
Boot on arm64 was added in #831827.


-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJXxfZEAAoJEF/3aG7d/FTWjbwP/2pGc+W19XxtxH0yJk4BPoqU
l0tyeCV88oebIJo/T4wtEfVR4OAXgyNfyiONsGjbLs7yjJOzkw2tGGYGeIOltc3z
hevGLbBHhyengqUjGJqSzq7YCS7+Nk2tIBHHSjDMOpnazHQgFk7Tks+oZNbY5MYp
Rszh46w3sYGNLvi7SiAdLMmJ2JwaVkX4Q/rj+bkpgDW38tvxJ/DyKfkWt1s3ekCs
FmJeYXWieMJxYZmx0KaUhStSb9jOL8DAgL64pXZgaMjZB15DTduWkCbntmHV5JW0
FYlH5nZ1Th6yoeEVEOWMmjbkVPKSqmuMRQh5AsN9VeTLxtbH1V56nS+ApYIZqJGM
MOgCpnbhHFvKJEJKRMJrCX6CVbPmuy7a47D5T0TxwfSKv9NWJXClxfoNiI3sBfHL
Myb5OHLvnO8rSQTLe++919OwO0e7/C3KunUTJQzRHKXNzk+U4dDNPOLwrhc6pS63
8nCHEKEh8HJ3u6n/hOm1B2MGjnIuZzpm2yQwJKP3EdGVQN/FnK4Ap263ZLLneu+b
EJ+vTw56wM5cwOLefhil1xR7l2l22KHeRxf6agPdryb0YnMCBuoJXGvU13kkSV2x
R9rPzJIEx7VgMOxq1kEvRPPnZYzrdO4JSrm4abDkzstwR5gkLNZlTOEAbl2aKe3t
4FUz6ZZEYfsODie7A3m2
=PxjI
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: grub-shim-support-arm64.tar.xz
Type: application/x-xz
Size: 25940 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-grub-devel/attachments/20160830/1294fcbc/attachment-0002.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image-builds.tar.xz
Type: application/x-xz
Size: 1168 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/pkg-grub-devel/attachments/20160830/1294fcbc/attachment-0003.bin>


More information about the Pkg-grub-devel mailing list