Bug#1109984: systemd-boot does not declare an interest in the systemd-boot-signed trigger

Jarl Gullberg jarl.gullberg at algiz.nu
Sun Jul 27 17:49:28 BST 2025


Package: systemd-boot
Version: 257.7-1
Severity: normal
X-Debbugs-Cc: jarl.gullberg at algiz.nu

Dear Maintainer,

While testing various signed configurations of systemd-boot I noticed that while
systemd-boot contains code for handling a named "systemd-boot-signed" trigger 
(and, indeed, systemd-boot-efi-*-signed declare an activation of that trigger), the
package does not actually declare an interest in it.

As such, the trigger script will not be run when systemd-boot-efi-*-signed is installed
or the named trigger is explicitly triggered from another maintscript.

The code also handles a path trigger on /usr/lib/grub, but that appears to have been
intentionally removed in 9a5eea982313a208d03f29897e61298e974cc9f1.

If this is not the intended trigger to use when a new signed systemd-boot binary has been
installed and requires an update to the version installed to the ESP, please let me know
and I'll test with that instead.

-- System Information:
Debian Release: 13.0
  APT prefers testing-security
  APT policy: (500, 'testing-security'), (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 6.12.33+deb13-amd64 (SMP w/6 CPU threads; PREEMPT)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE=en_GB:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages systemd-boot depends on:
ii  libc6                                       2.41-10
ii  libsystemd-shared                           257.7-1
ii  systemd                                     257.7-1
pn  systemd-boot-efi-signed | systemd-boot-efi  <none>
pn  systemd-boot-tools                          <none>

Versions of packages systemd-boot recommends:
pn  efibootmgr   <none>
ii  shim-signed  1.46+15.8-1

Versions of packages systemd-boot suggests:
pn  systemd-ukify  <none>



More information about the Pkg-systemd-maintainers mailing list