From patchwork Thu Dec 9 17:35:36 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Tim Gardner X-Patchwork-Id: 1566015 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: bilbo.ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=canonical.com header.i=@canonical.com header.a=rsa-sha256 header.s=20210705 header.b=hENcOgIS; dkim-atps=neutral Authentication-Results: ozlabs.org; spf=none (no SPF record) smtp.mailfrom=lists.ubuntu.com (client-ip=91.189.94.19; helo=huckleberry.canonical.com; envelope-from=kernel-team-bounces@lists.ubuntu.com; receiver=) Received: from huckleberry.canonical.com (huckleberry.canonical.com [91.189.94.19]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by bilbo.ozlabs.org (Postfix) with ESMTPS id 4J91R52tNBz9sR4 for ; Fri, 10 Dec 2021 04:36:00 +1100 (AEDT) Received: from localhost ([127.0.0.1] helo=huckleberry.canonical.com) by huckleberry.canonical.com with esmtp (Exim 4.86_2) (envelope-from ) id 1mvNKf-0005Bq-6G; Thu, 09 Dec 2021 17:35:49 +0000 Received: from smtp-relay-internal-1.internal ([10.131.114.114] helo=smtp-relay-internal-1.canonical.com) by huckleberry.canonical.com with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.86_2) (envelope-from ) id 1mvNKd-0005Af-2e for kernel-team@lists.ubuntu.com; Thu, 09 Dec 2021 17:35:47 +0000 Received: from mail-pl1-f197.google.com (mail-pl1-f197.google.com [209.85.214.197]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by smtp-relay-internal-1.canonical.com (Postfix) with ESMTPS id 943533F1B3 for ; Thu, 9 Dec 2021 17:35:44 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=canonical.com; s=20210705; t=1639071344; bh=ZDzvG9EioAiU0ct/u9jm/Xa505lLVNqVdYv3VWJJdf8=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=hENcOgISU+jur+hWY8ePT0Prbxn40PvYz86p7YbK9ZgbXVXL37PFWfdArJTvjGQQm vt5Wan/JOtgUcd2gTMfOjJh4FLSqiXpVtgvKbC/AMSmMXa2OkYYPQ2ll8a0fQMBxLs 2jb3TBFT+GV1AC/p06YrRV8LjvHCaVbcSX9QAuhwA2ICr4o+hpwSczejChWj3uAh9M wKHO2Dkz2dfH6w48OHbsLbh7rLogF/vT0YKGr0WhwFLEvBWamuVZI4BeFwxq1pLSHV rcaOi/nW4KIzD9qQIq3PNM0c0An3FmH2FLjWeM20KAGKx2YQpr9w7kyK1mdnGBLmPY 1uDLFNU6JnFFA== Received: by mail-pl1-f197.google.com with SMTP id m17-20020a170902db1100b001421cb34857so2705642plx.15 for ; Thu, 09 Dec 2021 09:35:44 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=ZDzvG9EioAiU0ct/u9jm/Xa505lLVNqVdYv3VWJJdf8=; b=nTyfphnfu597UWxorxwIT4odN75SUwzMQp8jw9EZ5xPakWrsy1TMaqRkMp2vXae9Xm JTxT1ioG5LfH86AhV4UnhMvOYMOWAgnBii/sY4GinghrumUhhJVt2sjE2KUfFLL9QuPF IrxwAfbCKtRZ4oHr8QPiVpJQqCtJx48ej4udJNMwT30A/MX8yGifUNTAJhvl7R6OVgE2 FnD3KhwhNB1Z0mgcPh3OoutTOOtinpPxDW0+9iy9wc0mskB3Ez5SUM+sgDwUlGRQGkHC 07jtMbu6QEyrP/Bqr7LN+HWVORJqMW6b+IU3pv+yUi5SIk+KJgjlB2HTaR/PRTYXZ+O3 IAXQ== X-Gm-Message-State: AOAM532BCFax4wV57TwgBKybDTqPYTRKMIflmEMImg3h1hRq2QqP9UwY uWzya2oc3rGfxKZjMlJatNfV0Uw2Qrh5rRL4OFILs3edcwQp88FmFr18eFvx4dnSjkOFUeek+w7 mSDyAkvmIDIdBM+zShpZUIj4mfsRWKVOAdFhGHkBjag== X-Received: by 2002:a17:90b:110a:: with SMTP id gi10mr17397174pjb.124.1639071342972; Thu, 09 Dec 2021 09:35:42 -0800 (PST) X-Google-Smtp-Source: ABdhPJzbDRkrnd9+PG2BC6e4ZokzlHgrlZET1M+0+FgTdc9mDTD5I0lxX8hY1vbAsl4rm5UslLQNSg== X-Received: by 2002:a17:90b:110a:: with SMTP id gi10mr17397128pjb.124.1639071342527; Thu, 09 Dec 2021 09:35:42 -0800 (PST) Received: from localhost.localdomain ([69.163.84.166]) by smtp.gmail.com with ESMTPSA id u32sm289366pfg.220.2021.12.09.09.35.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 09 Dec 2021 09:35:42 -0800 (PST) From: Tim Gardner To: kernel-team@lists.ubuntu.com Subject: [PATCH][bionic/linux-aws] UBUNTU: [Packaging] aws: Enable signed kernel Date: Thu, 9 Dec 2021 10:35:36 -0700 Message-Id: <20211209173537.22517-2-tim.gardner@canonical.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20211209173537.22517-1-tim.gardner@canonical.com> References: <20211209173537.22517-1-tim.gardner@canonical.com> MIME-Version: 1.0 X-BeenThere: kernel-team@lists.ubuntu.com X-Mailman-Version: 2.1.20 Precedence: list List-Id: Kernel team discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: kernel-team-bounces@lists.ubuntu.com Sender: "kernel-team" BugLink: https://bugs.launchpad.net/bugs/1951011 Signed-off-by: Tim Gardner --- debian.aws/control.d/flavour-control.stub | 7 ++++--- debian.aws/rules.d/amd64.mk | 2 +- debian.aws/rules.d/arm64.mk | 1 + 3 files changed, 6 insertions(+), 4 deletions(-) diff --git a/debian.aws/control.d/flavour-control.stub b/debian.aws/control.d/flavour-control.stub index 0bb756b4ec0a8..bd22e3549ef13 100644 --- a/debian.aws/control.d/flavour-control.stub +++ b/debian.aws/control.d/flavour-control.stub @@ -21,7 +21,7 @@ # # XXX: Leave the blank line before the first package!! -Package: linux-image-PKGVER-ABINUM-FLAVOUR +Package: linux-image=SIGN-ME-PKG=-PKGVER-ABINUM-FLAVOUR Build-Profiles: Architecture: ARCH Section: kernel @@ -30,6 +30,7 @@ Provides: linux-image, fuse-module, aufs-dkms, =PROVIDES=${linux:rprovides} Depends: ${misc:Depends}, ${shlibs:Depends}, kmod, linux-base (>= 4.5ubuntu1~16.04.1), linux-modules-PKGVER-ABINUM-FLAVOUR Recommends: BOOTLOADER, initramfs-tools | linux-initramfs-tool Breaks: flash-kernel (<< 3.0~rc.4ubuntu64) [arm64] +Conflicts: linux-image=SIGN-PEER-PKG=-PKGVER-ABINUM-FLAVOUR Suggests: fdutils, SRCPKGNAME-doc-PKGVER | SRCPKGNAME-source-PKGVER, SRCPKGNAME-tools, linux-headers-PKGVER-ABINUM-FLAVOUR Description: Linux kernel image for version PKGVER on DESC This package contains the Linux kernel image for version PKGVER on @@ -67,7 +68,7 @@ Build-Profiles: Architecture: ARCH Section: kernel Priority: optional -Depends: ${misc:Depends}, ${shlibs:Depends}, linux-image-PKGVER-ABINUM-FLAVOUR, crda | wireless-crda +Depends: ${misc:Depends}, ${shlibs:Depends}, linux-image=SIGN-ME-PKG=-PKGVER-ABINUM-FLAVOUR, crda | wireless-crda Description: Linux kernel extra modules for version PKGVER on DESC This package contains the Linux kernel extra modules for version PKGVER on DESC. @@ -94,7 +95,7 @@ Description: Linux kernel headers for version PKGVER on DESC This is for sites that want the latest kernel headers. Please read /usr/share/doc/linux-headers-PKGVER-ABINUM/debian.README.gz for details. -Package: linux-image-PKGVER-ABINUM-FLAVOUR-dbgsym +Package: linux-image=SIGN-ME-PKG=-PKGVER-ABINUM-FLAVOUR-dbgsym Build-Profiles: Architecture: ARCH Section: devel diff --git a/debian.aws/rules.d/amd64.mk b/debian.aws/rules.d/amd64.mk index 32ef2351bb3d7..69c2b53802ead 100644 --- a/debian.aws/rules.d/amd64.mk +++ b/debian.aws/rules.d/amd64.mk @@ -9,7 +9,7 @@ install_file = vmlinuz loader = grub vdso = vdso_install no_dumpfile = true -uefi_signed = false +uefi_signed = true do_tools_usbip = true do_tools_cpupower = true do_tools_perf = true diff --git a/debian.aws/rules.d/arm64.mk b/debian.aws/rules.d/arm64.mk index 4a986236a4800..2f2c29af0b67c 100644 --- a/debian.aws/rules.d/arm64.mk +++ b/debian.aws/rules.d/arm64.mk @@ -28,3 +28,4 @@ do_source_package = false do_dtbs = false do_common_headers_indep = false do_tools_perf_jvmti = true +uefi_signed = true