mirror of
https://github.com/xcat2/xcat-dep.git
synced 2026-09-30 23:05:17 +00:00
9d944ee3c7
The rpm and the deb install ipxe-shimx64.efi and ipxe-shimaa64.efi over x86_64-sb/shimx64.efi and arm64-sb/shimaa64.efi of the release tree, so firmware that trusts only the Microsoft UEFI CA 2023 loads the shim with Secure Boot on. The ipxe-shim.efi and snponly-shim.efi links keep their targets, and every other file of the tree is unchanged. payload.sha256 lists the digests of the new shims, which both builders check. The README says how to update them.
88 lines
3.8 KiB
Plaintext
88 lines
3.8 KiB
Plaintext
ipxe-xcat
|
|
=========
|
|
|
|
This package installs the ipxeboot.tar.gz tree of the iPXE v2.0.0 release
|
|
under /tftpboot/xcat/ipxe. Nothing is rebuilt, and only the two shims are
|
|
replaced: see The shim. The x86_64-sb
|
|
and arm64-sb builds carry their Secure Boot signatures inside the files, and
|
|
the shim finds snponly.efi and ipxe.efi by name in its own directory, so the
|
|
package keeps every name, symlink and byte of the release tree.
|
|
|
|
Files
|
|
-----
|
|
|
|
ipxeboot-2.0.0.tar.gz
|
|
The ipxeboot.tar.gz asset of
|
|
https://github.com/ipxe/ipxe/releases/tag/v2.0.0, renamed. Its SHA-256,
|
|
01a526d4cc791fc30362259c609d6c506cc64a7bdff51b9a5eb788354e17eee1, is the
|
|
digest that GitHub publishes for the asset.
|
|
|
|
ipxe-2.0.0-source.tar.gz
|
|
The source archive of tag v2.0.0, commit
|
|
12798ec29aa8a64d8675c4378b99f5fe28447afb, from
|
|
https://github.com/ipxe/ipxe/archive/refs/tags/v2.0.0.tar.gz. Its content
|
|
equals "git archive --prefix=ipxe-2.0.0/ v2.0.0". snpnet.c and undinet.c
|
|
are GPL2_OR_LATER without the UBDL, so snponly.efi and undionly.kpxe are
|
|
GPLv2+ as a whole. The package installs this archive with the binaries.
|
|
|
|
ipxe-shimx64.efi, ipxe-shimaa64.efi
|
|
The ipxe-shimx64.efi and ipxe-shimaa64.efi assets of
|
|
https://github.com/ipxe/shim/releases/tag/ipxe-16.1, as ipxe replaced
|
|
them on 2026-05-27. Their SHA-256 values are the digests that GitHub
|
|
publishes for the assets.
|
|
|
|
SHA256SUMS
|
|
The SHA-256 of both archives and both shims. Both builders check it
|
|
before the build.
|
|
|
|
payload.sha256
|
|
One line for each directory, file and symlink of the release tree, with
|
|
the SHA-256 of each file and the target of each symlink. After the build,
|
|
both builders unpack the RPM or deb and compare its /tftpboot/xcat/ipxe
|
|
with this list, entry for entry, with verify-payload.pl. A difference
|
|
fails the build.
|
|
|
|
licenses/
|
|
ipxe/COPYING, COPYING.GPLv2 and COPYING.UBDL are from iPXE tag v2.0.0.
|
|
shim/COPYRIGHT is from ipxe/shim tag ipxe-16.1.
|
|
shim/openssl/LICENSE is from openssl/openssl tag OpenSSL_1_0_2k, the
|
|
OpenSSL version that shim 16.1 carries in Cryptlib.
|
|
shim/gnu-efi/README.efilib is from rhboot/gnu-efi commit dc7fd96, the
|
|
gnu-efi commit that tag ipxe-16.1 pins.
|
|
|
|
The shim
|
|
--------
|
|
|
|
The release tree carries shim 16.1 as x86_64-sb/shimx64.efi and
|
|
arm64-sb/shimaa64.efi, signed by the Microsoft Corporation UEFI CA 2011
|
|
only. Firmware that trusts only the UEFI CA 2023 refuses them with Secure
|
|
Boot on. On 2026-05-27 ipxe replaced the ipxe/shim ipxe-16.1 release assets
|
|
with a build signed by both CAs. Both builders install ipxe-shimx64.efi and
|
|
ipxe-shimaa64.efi over the shims of the tree, under the same names, so the
|
|
ipxe-shim.efi and snponly-shim.efi links still point to them. payload.sha256
|
|
lists the digests of the replacements.
|
|
|
|
Update to a new release
|
|
-----------------------
|
|
|
|
1. Download ipxeboot.tar.gz from the release, and compare its SHA-256 with
|
|
the digest on the release page.
|
|
2. Download the source archive of the tag, and compare its content with
|
|
"git archive" of the tag.
|
|
3. Replace both archives. Download ipxe-shimx64.efi and ipxe-shimaa64.efi
|
|
from the latest ipxe/shim release, and compare their SHA-256 with the
|
|
digests on its page. Drop them and their install lines when the shims of
|
|
the new tree carry the UEFI CA 2023 signature.
|
|
4. Write SHA256SUMS with sha256sum.
|
|
5. Write payload.sha256 from the tree with the shims in place:
|
|
|
|
mkdir tree
|
|
tar -xzf ipxeboot-<version>.tar.gz --strip-components=1 -C tree
|
|
cp ipxe-shimx64.efi tree/x86_64-sb/shimx64.efi
|
|
cp ipxe-shimaa64.efi tree/arm64-sb/shimaa64.efi
|
|
./verify-payload.pl --generate tree > payload.sha256
|
|
|
|
6. Update licenses/ when the release changes its licence texts or its shim.
|
|
7. Set the version in ipxe-xcat.spec and debian/changelog, and the ipxe-xcat
|
|
pins in packages-manifest.conf and debs-manifest.conf.
|