[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [PATCH] efi: Set shim_lock_enabled even if validation is disabled
From: |
Julian Andres Klode |
Subject: |
Re: [PATCH] efi: Set shim_lock_enabled even if validation is disabled |
Date: |
Tue, 10 Oct 2023 18:26:11 +0200 |
On Wed, Jul 19, 2023 at 03:16:00PM +0200, Julian Andres Klode wrote:
> If validation has been disabled via MokSbState, secure boot on the
> firmware is still enabled, and the kernel fails to boot.
>
> This is a bit hacky, because shim_lock is not *fully* enabled, but
> it triggers the right code paths.
>
> Ultimately, all this will be resolved by shim gaining it's own image
> loading and starting protocol, so this is more a temporary workaround.
>
> Fixes: 6425c12cd (efi: Fallback to legacy mode if shim is loaded on x86 archs)
Ping, this is kind of a blocker for 2.12
--
debian developer - deb.li/jak | jak-linux.org - free software dev
ubuntu core developer i speak de, en
- Re: [PATCH] efi: Set shim_lock_enabled even if validation is disabled,
Julian Andres Klode <=