/srv/irclogs.ubuntu.com/2025/01/30/#ubuntu-kernel.txt

=== ubuntu_4321 is now known as ubuntu4321
lissyxtomreyn, right, but I still dont get why those mainline cannot signed07:16
tjaaltonbecause every new version would have to be tested07:42
tjaaltonnot going to happen07:43
tjaaltonthey are provided as-is anyway07:43
lissyxI'm sorry but I dont get why signature would be tied to testing can't they be provided as-is but signed to be able to boot on secureboot?08:33
lissyxone has to manually install it anyway, so it's not like it's going to happen by accident08:34
tjaaltonthey need to be signed by the archive key to be useful08:36
tjaaltonor08:36
tjaaltonthere are ppa builds of in-flight kernels which are signed by ppa keys, then tested to see that secure boot works, then passed on to be signed with the archive key on a private ppa08:37
tjaaltonso, you could use a newer ppa kernel but it'd require importing the ppa key08:38
tjaaltonunless I'm mistaken08:38
lissyxand archive key signature can only happen after testing?08:39
lissyxTBH from an outsider point of view that looks like bureaucracy with no real value in this specific case except making it mostly useless to have those kernels available in my case08:40
tjaaltontough08:44
lissyxI dont want to hurt anyone08:46
lissyxthat's just what I can see from where I am, not knowing any of the backdoor processes08:46
lissyxtl;dr is that I'm willing to test mainline but that situation makes me unable to do it so far, so we cannot assert whether the bug is fixed or not08:47
tjaaltonyou have 6.13.0-2.2 for testing in ppa:canonical-kernel-team/ubuntu/bootstrap , then instructions on how to enable lockdown here https://canonical-kteam-docs.readthedocs-hosted.com/en/latest/reference/testing/secure_boot.html09:01
tjaaltonalso, mainline builds don't even carry the lockdown patches09:02
lissyxok someone mentionned PPA was broken as well so if it works that's nice09:05
lissyxtjaalton, that documentation link seems to be private09:06
lissyxasks for an account09:06
tjaaltonah09:07
tjaaltonlet me see09:07
tjaaltonshould be public09:07
tjaaltonI think09:07
tjaaltonmeh, isn't09:10
tjaaltonthe public docs are at https://canonical-kteam-docs.readthedocs-hosted.com/en/public/ and can't see that there09:10
lissyxthis comment mentiosn the PPA being dead: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2095100/comments/809:15
-ubottu:#ubuntu-kernel- Launchpad bug 2095100 in linux (Ubuntu) "kernel panic when setting application in fullscreen" [Undecided, New]09:15
lissyxmaybe it refers to a different one?09:15
esembeeapw, now09:17
tjaaltonDay changed to 19 Jan 202509:26
tjaalton20:45 < juergh> bambinone, this is all tied to the move of the builders. It's a very brittle infrastructure with lots of dependencies. Upgrading the builders also introduced a whole new set of problems that need to be looked at.09:26
tjaaltonlatest on mainline ppa. it's not officially supported, so no ETA for it being fully live09:27
lissyxtjaalton, ok, so I'm not sure, does it means I can use the PPA you mentionned or just be patient for the generic PPA mentionned in the bug to be fixed?12:31
tjaaltonif you need 6.13 final, built for plucky, use bootstrap ppa12:36
tjaaltonbut it still isn't signed12:36
tjaaltonhmm12:36
tjaaltonactually, plucky-proposed has a signed version12:36
tjaaltonno it doesn't.. not yet :)12:37
tjaaltonbecause lockdown needs to be tested, arm64/amd64 by me, s390x by others12:37
tjaaltonmaybe next week12:37
tjaaltonthe ppa version is signed with the ppa key12:38
tjaaltonextract the tarball from http://ppa.launchpad.net/canonical-kernel-team/bootstrap/ubuntu/dists/plucky/main/signed/linux-generate-unstable-amd64/6.13.0-2.213:08
tjaaltonit has ../control/uefi.crt13:08
tjaaltonmodify it to DER format; openssl x509 -in <version>/control/uefi.crt -inform PEM -outform DER -out MOK.der13:09
tjaaltonthen enroll it like on https://wiki.debian.org/SecureBoot13:09
lissyxi tried that, I already have an enrolled key for signing modules, but the kernel would still not boot13:38

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!