Your message dated Wed, 08 May 2024 17:36:02 +0000
with message-id <e1s4ld0-004d95...@fasolo.debian.org>
and subject line Bug#936009: fixed in shim 15.8-1~deb12u1
has caused the Debian Bug report #936009,
regarding shim-unsigned:amd64 cannot be installed alongside shim-unsigned:i386
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
936009: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=936009
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: shim-unsigned
Version: 15+1533136590.3beb971-7
Severity: normal
Dear Maintainer,
I want to be able to build a live cd that has both ia32 and x64 Secure
Boot UEFI support.
So I need both shim-signed:amd64 and shim-signed:i386 installed.
Those two packages depend on shim-unsigned:amd64 and shim-unsigned:i386
among other packages.
I cannot install those unsigned packages hence neither I can install the
signed ones.
After adding and apt i386 architecture to an amd64 system if I run:
apt-get install shim-unsigned:amd64 shim-unsigned:i386
I get this output:
Reading package lists... Done
Building dependency tree
Reading state information... Done
shim-unsigned is already the newest version (15+1533136590.3beb971-7).
shim-unsigned set to manually installed.
Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.
The following information may help to resolve the situation:
The following packages have unmet dependencies:
shim-unsigned : Conflicts: shim-unsigned:i386 but 15+1533136590.3beb971-7
is to be installed
shim-unsigned:i386 : Conflicts: shim-unsigned but 15+1533136590.3beb971-7
is to be installed
E: Unable to correct problems, you have held broken packages.
I would like to be able to install both packages at the same time
because generated binaries do not collide between them.
It would seem those packages are lacking some multi-arch declaration on
the package metadata.
This same problem was fixed for shim-signed on
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=928486 and fixed there.
Associated commit to that fix:
https://salsa.debian.org/efi-team/shim-signed/commit/f3393e69ed073007cda61d57c60e5c907c4faf51
.
I suspect that shim-helpers-amd64-signed and shim-helpers-i386-signed
packages will need a similar workaround but I'm not sure on this one.
Thank you very much!
-- System Information:
Debian Release: 10.0
APT prefers stable
APT policy: (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386
Kernel: Linux 4.19.0-5-amd64 (SMP w/2 CPU cores)
Kernel taint flags: TAINT_OOT_MODULE
Locale: LANG=C, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE=C (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: unable to detect
-- no debconf information
--- End Message ---
--- Begin Message ---
Source: shim
Source-Version: 15.8-1~deb12u1
Done: Steve McIntyre <93...@debian.org>
We believe that the bug you reported is fixed in the latest version of
shim, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 936...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Steve McIntyre <93...@debian.org> (supplier of updated shim package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Sat, 04 May 2024 21:28:21 +0100
Source: shim
Architecture: source
Version: 15.8-1~deb12u1
Distribution: bookworm
Urgency: medium
Maintainer: Debian EFI team <debian-...@lists.debian.org>
Changed-By: Steve McIntyre <93...@debian.org>
Closes: 936009 1046268 1069054
Changes:
shim (15.8-1~deb12u1) bookworm; urgency=medium
.
[ Steve McIntyre ]
* Cope with changes in pesign packaging.
* New upstream release fixing more bugs
* Remove all our previous patches, no longer needed:
+ Make-sbat_var.S-parse-right-with-buggy-gcc-binutils.patch (now
upstream)
+ Enable-NX.patch (we don't want NX just yet until the whole boot
stack is NX-capable)
+ block-grub-sbat3-debian.patch (not needed now upstream grub SBAT
is 4)
* Cherry-pick 2 new patches from upstream for grub revocations:
+ 0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch
+ 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch
* Log if the build is nx-compatible or not
* Force shim to use the latest revocations by default to block some
older grub / peimage issues. This is:
"shim,4\ngrub,4\ngrub.peimage,2\n"
* Install a copy of the Debian CA certificate into /usr/share/shim.
Closes: #1069054
* Clean up better after build. Closes: #1046268
.
[ Bastien Roucariès ]
* Port autopkgtest from ubuntu
* Import MR-12: "shim-unsigned:amd64 cannot be installed alongside
shim-unsigned:i386", thanks to adrian15 adrian15 (Closes: #936009).
* Fix debian/watch and check signature
Checksums-Sha1:
54777b393c1ee62bd69cc41a15572d95746f8b94 2631 shim_15.8-1~deb12u1.dsc
cdec924ca437a4509dcb178396996ddf92c11183 2315201 shim_15.8.orig.tar.bz2
e7559e3b15883b3b8dfcfd7cd6bebe55af846381 59116
shim_15.8-1~deb12u1.debian.tar.xz
2aa71bf7c38a495f46f48578f5d734fa88078975 6340
shim_15.8-1~deb12u1_source.buildinfo
Checksums-Sha256:
c202fbfb5de17bd6587b23bd171ea6f7f11dbce1c1b063f34a1469dbc517056e 2631
shim_15.8-1~deb12u1.dsc
a79f0a9b89f3681ab384865b1a46ab3f79d88b11b4ca59aa040ab03fffae80a9 2315201
shim_15.8.orig.tar.bz2
6c15c6111e7e40683f6aec2e8302a3ae830caa4144aba7e448553e574de30647 59116
shim_15.8-1~deb12u1.debian.tar.xz
e73e757e06c53ebf509bded8a8044262593da5565158e8b576d3756869bfc28c 6340
shim_15.8-1~deb12u1_source.buildinfo
Files:
58394cd894da6ce30b83b1da0abcc630 2631 admin optional shim_15.8-1~deb12u1.dsc
a9452c2e6fafe4e1b87ab2e1cac9ec00 2315201 admin optional shim_15.8.orig.tar.bz2
36e1403be664711c56eb17926930aac1 59116 admin optional
shim_15.8-1~deb12u1.debian.tar.xz
38ccb3a5f4781e77b163e3ad0da3cc79 6340 admin optional
shim_15.8-1~deb12u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJFBAEBCAAvFiEEzrtSMB1hfpEDkP4WWHl5VzRCaE4FAmY40WYRHDkzc2FtQGRl
Ymlhbi5vcmcACgkQWHl5VzRCaE4QsRAAwj05rxAIN5cSpWkkD77TjFKUaDsQJQY9
SC0xoYElMqELO45vCG7/KfSSJAqY8tuVUIcgM6i8DRmL7C441DDYEXKwUCiEUxbg
9HgpmTHRez34gKc1YJe6FdHkRvHXxodTx6S+hhf38EQbicopd9uML8Uo29IL/31W
SMt6P0qlFgc7Jw9EGkqMPApMzzRGgWT6CM0SazEYQXnAEhfB/r27uzWlPOUh2j/Y
j854QKFo6LUcbenLKSgz+yl0G0Vcd4gSyK3phGApM+sGpHk4R45l3Qkn2p9aYOSy
g+e0Z5KTqiIHMjwCMJo7jSun4Ar8wJiKdT6/hXtkhN+WjUNy5Zdm31IsRXiMeEFh
4AXUF1uoPkMGAsUU5KPmd6EMZs2kdiCc9ccPrjCcJ92Xf2lsGoMQk+jDB3Hi8XiM
o97zb63fQQOg19pHYy+KZADmxLU6B78ZE5Nf5gpdXghpJD7g7Cehp7guWJbsQKpl
G8y+XkAwkYMN50dZ9mHKUCYWTXhbp/4Gi1/UxJpnLD78u3/PLUIfYgiVMUko4F8C
003IDznsLBAWRQSPycAszpllXM6WQ+xAyZ81vmNPfKerKKx3ePyA91CzChzrxit8
EBL7789X7+pxsylDugOla1MNb5W0bgzbF3N/BGXyURXA33HiX6oTAJlgj9Qn5H+R
v2ouhuQLoUc=
=l0pU
-----END PGP SIGNATURE-----
pgppixg6MkaXM.pgp
Description: PGP signature
--- End Message ---