Hi,
I've just built a netboot-gtk mini.iso against unstable, including the
new kernel. A regular “almost all defaults” (except French to check
things like translations, keymap fun, etc.) install on UEFI gave an
overall successful installation according to d-i, but it doesn't boot:
Verifying shim SBAT data failed: Security Policy Violation
It's been a while since I last toyed with unstable, so I'm not sure
whether this is known already, where it's coming from, etc. Even when
built against unstable, d-i installs testing, so that shouldn't be
linked to the new Linux version running the installer, as what ends up
on disk is testing's version.
This is the exact same test setup as for (old)stable point release
preps, with qemu/bookworm running on a bookworm system.
kvm -m 1G -machine q35,smm=on -pflash /tmp/1/code.fd -pflash /tmp/1/vars.fd -hda /tmp/1/sda.img
with both pflash files initialized from those respectively:
- /usr/share/OVMF/OVMF_CODE_4M.ms.fd
- /usr/share/OVMF/OVMF_VARS_4M.ms.fd
Wild guess: Maybe ovmf would need to ship refreshed files?
Can't investigate more right now, live stream and travel are next.
Cheers,
--
Cyril Brulebois (
[email protected]) <
https://debamax.com/>
D-I release manager -- Release team member -- Freelance Consultant
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEtg6/KYRFPHDXTPR4/5FK8MKzVSAFAmZ+hzUACgkQ/5FK8MKz VSDaCRAAjc8+OuCaYbwM2yAr/zfkJiSF5AIpy6Y0j2jniNmW30rHuysErwRE0Eq+ arjGvOHI5B+rLG9OEJ+DM1U/v+2H2gZjdYJSXfvSRRURFhJCO2D8PO235wHM9YEI vWewT+/vqekyz44P+PXEKzLcvfyMjVVokXWgbxUP34GjlBsXaqO1yBPDanIbZaxh Rh2yVPmPn/8WCH1yyTPE51QLN6Cfrl+sE53ZB+u3UcF507W9Id6/AVRJcutmUrHu ZVPIpy3YXvG+huNXZf/gBaWYnMBFEGXlyJCZekfb0aLbXTLd97XG7D2NL4SndDjo ewJ2O7mUd80QB9vXPK0mXRKa8mySH7d/7knQr5GTvrM0FdsVfZTIep8crj1AixTv yeLUw5XagxekhstMTg5Wtr25stOPs+0p/nrxMAoLxBbf5g55HdjrNPsHWgbs7I6g KfpDfr44qXFrM20mN88qSdQg9Pk2IobASTrYYyJqjvFj0bQhcvmT3VyCAWYBN3au YBiYzyT8Xt9nJSm+3x53TcPqAM2zY+Q2z28uLpXkYX5gOBas748OAoWcorpgHhRZ I+1pYQnr8b199vJG+VQyQVxuCVvIgN0XC8BswZK8PIASypQij1tTAIGkOihPgx1a g5G8V5PiF+h60Mf9ukzNFCkz0qWKDMK2ERH8jzPm2QEp3Fpbvqw=
=4eaS
-----END PGP SIGNATURE-----
--- SoupGate-Win32 v1.05
*