Bug#1109984: systemd-boot does not declare an interest in the systemd-boot-signed trigger
Jarl Gullberg
jarl.gullberg at algiz.nu
Sun Jul 27 17:49:28 BST 2025
Package: systemd-boot
Version: 257.7-1
Severity: normal
X-Debbugs-Cc: jarl.gullberg at algiz.nu
Dear Maintainer,
While testing various signed configurations of systemd-boot I noticed that while
systemd-boot contains code for handling a named "systemd-boot-signed" trigger
(and, indeed, systemd-boot-efi-*-signed declare an activation of that trigger), the
package does not actually declare an interest in it.
As such, the trigger script will not be run when systemd-boot-efi-*-signed is installed
or the named trigger is explicitly triggered from another maintscript.
The code also handles a path trigger on /usr/lib/grub, but that appears to have been
intentionally removed in 9a5eea982313a208d03f29897e61298e974cc9f1.
If this is not the intended trigger to use when a new signed systemd-boot binary has been
installed and requires an update to the version installed to the ESP, please let me know
and I'll test with that instead.
-- System Information:
Debian Release: 13.0
APT prefers testing-security
APT policy: (500, 'testing-security'), (500, 'testing')
Architecture: amd64 (x86_64)
Kernel: Linux 6.12.33+deb13-amd64 (SMP w/6 CPU threads; PREEMPT)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE=en_GB:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled
Versions of packages systemd-boot depends on:
ii libc6 2.41-10
ii libsystemd-shared 257.7-1
ii systemd 257.7-1
pn systemd-boot-efi-signed | systemd-boot-efi <none>
pn systemd-boot-tools <none>
Versions of packages systemd-boot recommends:
pn efibootmgr <none>
ii shim-signed 1.46+15.8-1
Versions of packages systemd-boot suggests:
pn systemd-ukify <none>
More information about the Pkg-systemd-maintainers
mailing list