/srv/irclogs.ubuntu.com/2021/12/16/#ubuntu-devel.txt

=== genii is now known as genii-core
=== pizzaiolo is now known as pizza
=== genii is now known as genii-core
cpaelzerrbasak: yeah - those suggestions (e.g. not fetching that refs) is why I asked what the exact pain point is. To avoid suggesting solutions not addressing the problem mwhudson has with it.06:21
cpaelzerand BTW there already is a bug asking for something like a shallow clone to be faster in the many cases you just want it to behave like pull-lp-source06:22
cpaelzerthat might (or not) resolve these current issues as well06:22
mwhudsoncpaelzer: it's not really that painful since 1TiB nvme drives got cheap i guess :)08:43
cpaelzerhehe08:54
cpaelzermwhudson: but so I assume it is both then, time to clone AND local disk space - or anything else on top of that?08:55
mwhudsoncpaelzer: it's also just that pristine-tar basically doesn't work at all with go upstream tarballs08:55
mwhudsoni mean, it works but it saves 0% space08:55
cpaelzermaybe we could make git-ubuntu export-orig learn how to fetch from alternative places. That way the "works the same every time" would not be broken09:01
cpaelzerI'm sure rbasak will have more detailed thoughts ...09:02
cpaelzerStill I'd think a bug would be better than chat messages, we only get to work on GU every once in a while09:02
cpaelzerand things occuring in between withotu tracking can  forgotten too easily09:02
schopino/ any core dev available to sponsor LP: #1955026 ? :)11:44
ubottuLaunchpad bug 1955026 in openssl (Ubuntu) "Upgrade openssl to 3.0.1 on Jammy" [High, New] https://launchpad.net/bugs/195502611:44
seb128schopin, hey, uploaded12:24
schopinseb128: thank you :)12:25
seb128np!12:25
=== cpaelzer_ is now known as cpaelzer
=== genii-core is now known as genii
hallynhey xnox - you very familiar with sbat?  i have a noob question.22:31
hallyn(or maybe juliank would have the answer) :  who is supposed to write the definitive version info that shim compares against?22:33
hallynhttps://github.com/rhboot/shim/blob/main/SBAT.md   talks about "UEFI CA will do an update".22:33
hallynI don't get how that works in practice.22:33
vorlonhallyn: the UEFI CA in question is Microsoft22:57
hallynyes but how is it inolved in setting sbat versions ?23:00
hallynif i'm going to be running my own kernelinitrd.efi, i can set an sbat variable on it but how do i specify on the host what the min accepted version of it is?23:00
hallynor if there's a grub update that claims the last version is revoked, how does the new revocation get registered?23:01
vorlonhallyn: the min accepted version is specified by a UEFI variable update, that has to be signed by a key in KEK23:02
hallynI havent' found a document that describes that.  can anyone woh's root on my system update the uefi db variable for it?23:02
vorlonthis is what's meant by "UEFI CA"23:02
hallynIs there an efivars command to load such a signed update?23:02
hallynok so if my own key is in the KEK then i can write my own sbat-versions i assume23:02
vorloner there are commands for it but I never remember without looking them up23:02
vorlonbasically it's the same commands used in the secureboot-db package23:03
hallynok but it can be done from userspace?  (don't have to be before exitbootservices in efi or anything)23:03
hallynok - thanks vorlon !23:03
vorloncorrect23:03
hallyni think that's all i need to find the rest :) \o23:03
vorlonmind you I'm not conversant with the details of the variable name / UUID / format23:03
vorlonso hopefully that's documented :)23:03
hallynthe GUID is documented at least23:04
jmblhi vorlon, hallyn, i had been looking at shim code... and if that uefi sbat var is not set, shim sets it with a default value and attributes, which make it persistent and only available before exitbootservices... is that just a default thingy and a vendor will not use those attributes if setting himself?23:21
vorlonthat's definitely a default thingy, the goal is to have it set by the CA so that we have information across all shim vendors23:22
jmblahhhhhhh that is good to know.23:22
hallynah so that's why it was working despite my never having set such a thing :)  gotcha.23:25

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!