[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#990158: marked as done (shim-signed-common: No UEFI boot with error "Could not create MokListXRT")



Your message dated Wed, 23 Jun 2021 18:18:51 +0000
with message-id <E1lw7Sd-0004My-M6@fasolo.debian.org>
and subject line Bug#990158: fixed in shim 15.4-6
has caused the Debian Bug report #990158,
regarding shim-signed-common: No UEFI boot with error "Could not create MokListXRT"
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
990158: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=990158
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: shim-signed-common
Version: 1.33+15+1533136590.3beb971-7
Severity: critical
Justification: breaks the whole system

Dear Maintainer,


## What led up to the situation?

Upgrade:

* shim-signed:amd64 (1.33+15+1533136590.3beb971-7,
1.36~1+deb10u1+15.4-5~deb10u1)
* shim-signed-common:amd64 (1.33+15+1533136590.3beb971-7,
1.36~1+deb10u1+15.4-5~deb10u1)

System: Dell T5600 with BIOS Revision A19


## What was the outcome of this action?

System is unbootable on booting via UEFI. System shows error message and then
powers off immediately:

"Could not create MokListXRT: Out of Resources
Something has gone seriously wrong: import_mok_state() failed: Out of
Resources"


## What outcome did you expect instead?

A normal booting system loading GRUB.


## Also reproducible with Debian Live-Installations-Image

On affected hardware like "Dell T5600" doing a UEFI boot from USB with …

* debian-live-10.10.0-amd64-standard.iso does *not* work.
* debian-live-10.9.0-amd64-standard.iso works.


## Related resources

Might be related to:

* https://bugzilla.suse.com/show_bug.cgi?id=1185261



-- System Information:
Debian Release: 10.10
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 5.10.0-0.bpo.7-amd64 (SMP w/32 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8), LANGUAGE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages shim-signed-common depends on:
ii  debconf [debconf-2.0]  1.5.71
ii  mokutil                0.3.0+1538710437.fb6250f-1

shim-signed-common recommends no packages.

shim-signed-common suggests no packages.

-- debconf information:
  shim/title/secureboot:
  shim/error/secureboot_key_mismatch:
  shim/secureboot_explanation:
  shim/error/bad_secureboot_key:
  shim/disable_secureboot: true
  shim/enable_secureboot: false

--- End Message ---
--- Begin Message ---
Source: shim
Source-Version: 15.4-6
Done: Steve McIntyre <93sam@debian.org>

We believe that the bug you reported is fixed in the latest version of
shim, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 990158@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Steve McIntyre <93sam@debian.org> (supplier of updated shim package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 23 Jun 2021 19:03:54 +0100
Source: shim
Architecture: source
Version: 15.4-6
Distribution: unstable
Urgency: high
Maintainer: Debian EFI team <debian-efi@lists.debian.org>
Changed-By: Steve McIntyre <93sam@debian.org>
Closes: 989962 990082 990158 990190
Changes:
 shim (15.4-6) unstable; urgency=high
 .
   * Add arm64 patch to tweak section layout and stop crashing
     problems. Upstream issue #371. Closes: #990082, #990190
   * In insecure mode, don't abort if we can't create the MokListXRT
     variable. Upstream issue #372. Closes: #989962, #990158
Checksums-Sha1:
 2112b70489b4660c77eeb63207f54628fd0c5c04 2300 shim_15.4-6.dsc
 a2242f538b3f7e826b8ee78ef8caa49a9e766643 33932 shim_15.4-6.debian.tar.xz
 0409d674a6becceb329de2e29f8561fdd0ea0fdd 6054 shim_15.4-6_source.buildinfo
Checksums-Sha256:
 0316b340550238a3fb4cbb2a2b2a736fc93ba460327000032c1e683ee1db8831 2300 shim_15.4-6.dsc
 624357f05fdbf212523d9adcc6c4f92c03b442b3fb76732576ab56c756d8834a 33932 shim_15.4-6.debian.tar.xz
 dfb64efa1657ea734dc16cb07f9e497faa23cd11a58420e38bc62b21a38fefcf 6054 shim_15.4-6_source.buildinfo
Files:
 55b09f08418b65e28a14bbb7a27bfbda 2300 admin optional shim_15.4-6.dsc
 99e10023060aea0b923d3f566b415554 33932 admin optional shim_15.4-6.debian.tar.xz
 e41eaf923d9217c0afc50ed5177ab2d3 6054 admin optional shim_15.4-6_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJFBAEBCAAvFiEEzrtSMB1hfpEDkP4WWHl5VzRCaE4FAmDTeNARHDkzc2FtQGRl
Ymlhbi5vcmcACgkQWHl5VzRCaE4z4g//X9j9XrMkhJ2E3nsNozPMbz8jxzM92QCA
ltWZEQ+f3x/3AzF6qSbA7zeScwTQXXx2kwpYz1kVc6eI1xakD7TFMeNEf/DM5NPL
LK36OSe13DgqxqMj38jbhKr9l17rxcqasuRbjYSd+4DtQY8+4gBd6R+jdsjhdi03
FNRhiZIKX2aQLBZ1vCBkSdf49bAfooR8U/ylGhztZkbV3Kx1RW2Rt5dJofaIt7Q3
icU1hm6T6HG4hpQLnpSk3RNEvfLa/RYTqaAW9dJLTurd2e9iKHBeRtstYOxPT3hb
E9cMVs2IVlYOek5Lt5Lh8ePlkWIYcZpR+a8u5Puri8jxFV62iHhKXjE7nBD9nERM
KiNoKTdzUEqe0KFv86/d7sg6J4JKCeoO62ZJZXfRPRCTi2S3xW+AMZjECTEsAQbu
vVEiYkPK6WTt/WpiO48QjeEsji0LglrQj3E5TfnebSqnIyJAlma2ebX4KlR0ZpEj
hgdVW8rgPsmg1UqdP8pT9NLDr0dBbFWXmw/Ra5SJpRGmriP6CdxVcOwjcOS5kT4X
zQ2/DbcJV7Uv4iks8Ar8HNfwXFiMOW4Zq74xIeO01jh2jjkSu3jramN4uyIY3tM2
TwdnEI2N/gVitOiFQcLDyorkEeZibXDBG4IRi53StrCkIkq/7DQ6GIDhxWyZ67d8
ej/7spFtnSs=
=b3wE
-----END PGP SIGNATURE-----

--- End Message ---

Reply to: