Update to 15.4 results in shim being marked for autoremoval

Bug #1938774 reported by Owain Kenway
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
shim (Ubuntu)
Invalid
Undecided
Unassigned
shim-signed (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

(on 20.04)

The update to fix #1898729 can result in "shim" being marked to be autoremoved.

From /var/apt/history.log

Start-Date: 2021-08-03 09:32:20
Commandline: apt dist-upgrade
Requested-By: uccaoke (1000)
Upgrade: shim-signed:amd64 (1.40.4+15+1552672080.a4a1fbe-0ubuntu2, 1.40.6+15.4-0ubuntu7), shim:amd64 (15+1552672080.a4a1fbe-0ubuntu2, 15.4-0ubuntu7)
End-Date: 2021-08-03 09:32:23

Start-Date: 2021-08-03 09:32:37
Commandline: apt autoremove
Requested-By: uccaoke (1000)
Remove: shim:amd64 (15.4-0ubuntu7)
End-Date: 2021-08-03 09:32:37

I'm unclear on whether this will result in an non-bootable system so I re-installed shim to be doubly sure (I need this machine for work!)

Revision history for this message
Julian Andres Klode (juliank) wrote :

This is expected.

Changed in shim-signed (Ubuntu):
status: New → Incomplete
status: Incomplete → Invalid
Changed in shim (Ubuntu):
status: New → Invalid
Revision history for this message
Owain Kenway (o-kenway) wrote :

OK- thanks

Revision history for this message
Julian Andres Klode (juliank) wrote :

To add more detail, sorry for the brevity, the shim-signed package took over the remaining files in the shim package, and the shim package itself is hence no longer needed. The reason for that is that those files (mm*.efi and fb*.efi) were previously signed by an ephemeral key at build time, but are now signed by the signing service like a linux kernel, for example, and hence can't be in the shim package itself.

shim-signed is now marked to prevent it from being removed where installed, which should ensure people don't end up with an unbootable system :)

Revision history for this message
Owain Kenway (o-kenway) wrote (last edit ):

OK - thanks - that helps with my inevitable follow-up question I was otherwise going to ask over at askubuntu!

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.