[Bug 1137216] New: ovmf package misses binaries signed with keys for secureboot testing
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216 Bug ID: 1137216 Summary: ovmf package misses binaries signed with keys for secureboot testing Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.1 Hardware: aarch64 OS: Linux Status: NEW Severity: Normal Priority: P5 - None Component: Virtualization:Tools Assignee: virt-bugs@suse.de Reporter: guillaume.gardet@arm.com QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- ovmf package in Leap15.1/SLE15-SP1 misses binaries signed with keys for secureboot testing. The required update is https://build.opensuse.org/request/show/701042 While at it, we should add this update https://build.opensuse.org/request/show/686880 to fix aarch32 packaging. Could we add those updates for :Update, please? -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
Guillaume GARDET
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216#c1
Gary Ching-Pang Lin
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216#c2
Andreas Färber
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216#c3
Guillaume GARDET
Guillaume, what's the use case for this? I understood that this would only allow to boot into our installation medium but not into the installed system's GRUB?
The use case is openQA. Our aarch64 worker runs Leap 15.1 and we would need those firmware to follow/test the current status of SecureBoot. It is currently broken after installation, as signed Grub is not installed properly yet. But at least we can monitor progress/regressions. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
Santiago Zarate
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
Oliver Kurz
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216#c4
--- Comment #4 from Oliver Kurz
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216#c5
--- Comment #5 from Guillaume GARDET
so could you simply create a MR for Leap 15.1 (and potentially 15.0) with the changes corresponding to https://build.opensuse.org/request/show/701162 ?
ovmf is a package inherited from SLE, so updates must go through SLE. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216#c6
--- Comment #6 from Oliver Kurz
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
Andreas Färber
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
Oliver Kurz
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216#c9
--- Comment #9 from Gary Ching-Pang Lin
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216#c10
--- Comment #10 from Guillaume GARDET
If it's just for test, it would be fine to extract the "code" and "vars" files from ovmf in Factory and configure openQA to use the specific firmware files.
This is what okurz did yesterday on aarch64 openQA worker. But it would be better to provide it to SLE/Leap users directly, if possible. -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216
http://bugzilla.opensuse.org/show_bug.cgi?id=1137216#c11
Guillaume GARDET
participants (2)
-
bugzilla_noreply@novell.com
-
bugzilla_noreply@suse.com