mirror of
https://github.com/xcat2/xcat-dep.git
synced 2026-09-28 08:10:54 +00:00
9d944ee3c7
The rpm and the deb install ipxe-shimx64.efi and ipxe-shimaa64.efi over x86_64-sb/shimx64.efi and arm64-sb/shimaa64.efi of the release tree, so firmware that trusts only the Microsoft UEFI CA 2023 loads the shim with Secure Boot on. The ipxe-shim.efi and snponly-shim.efi links keep their targets, and every other file of the tree is unchanged. payload.sha256 lists the digests of the new shims, which both builders check. The README says how to update them.
ipxe-xcat
=========
This package installs the ipxeboot.tar.gz tree of the iPXE v2.0.0 release
under /tftpboot/xcat/ipxe. Nothing is rebuilt, and only the two shims are
replaced: see The shim. The x86_64-sb
and arm64-sb builds carry their Secure Boot signatures inside the files, and
the shim finds snponly.efi and ipxe.efi by name in its own directory, so the
package keeps every name, symlink and byte of the release tree.
Files
-----
ipxeboot-2.0.0.tar.gz
The ipxeboot.tar.gz asset of
https://github.com/ipxe/ipxe/releases/tag/v2.0.0, renamed. Its SHA-256,
01a526d4cc791fc30362259c609d6c506cc64a7bdff51b9a5eb788354e17eee1, is the
digest that GitHub publishes for the asset.
ipxe-2.0.0-source.tar.gz
The source archive of tag v2.0.0, commit
12798ec29aa8a64d8675c4378b99f5fe28447afb, from
https://github.com/ipxe/ipxe/archive/refs/tags/v2.0.0.tar.gz. Its content
equals "git archive --prefix=ipxe-2.0.0/ v2.0.0". snpnet.c and undinet.c
are GPL2_OR_LATER without the UBDL, so snponly.efi and undionly.kpxe are
GPLv2+ as a whole. The package installs this archive with the binaries.
ipxe-shimx64.efi, ipxe-shimaa64.efi
The ipxe-shimx64.efi and ipxe-shimaa64.efi assets of
https://github.com/ipxe/shim/releases/tag/ipxe-16.1, as ipxe replaced
them on 2026-05-27. Their SHA-256 values are the digests that GitHub
publishes for the assets.
SHA256SUMS
The SHA-256 of both archives and both shims. Both builders check it
before the build.
payload.sha256
One line for each directory, file and symlink of the release tree, with
the SHA-256 of each file and the target of each symlink. After the build,
both builders unpack the RPM or deb and compare its /tftpboot/xcat/ipxe
with this list, entry for entry, with verify-payload.pl. A difference
fails the build.
licenses/
ipxe/COPYING, COPYING.GPLv2 and COPYING.UBDL are from iPXE tag v2.0.0.
shim/COPYRIGHT is from ipxe/shim tag ipxe-16.1.
shim/openssl/LICENSE is from openssl/openssl tag OpenSSL_1_0_2k, the
OpenSSL version that shim 16.1 carries in Cryptlib.
shim/gnu-efi/README.efilib is from rhboot/gnu-efi commit dc7fd96, the
gnu-efi commit that tag ipxe-16.1 pins.
The shim
--------
The release tree carries shim 16.1 as x86_64-sb/shimx64.efi and
arm64-sb/shimaa64.efi, signed by the Microsoft Corporation UEFI CA 2011
only. Firmware that trusts only the UEFI CA 2023 refuses them with Secure
Boot on. On 2026-05-27 ipxe replaced the ipxe/shim ipxe-16.1 release assets
with a build signed by both CAs. Both builders install ipxe-shimx64.efi and
ipxe-shimaa64.efi over the shims of the tree, under the same names, so the
ipxe-shim.efi and snponly-shim.efi links still point to them. payload.sha256
lists the digests of the replacements.
Update to a new release
-----------------------
1. Download ipxeboot.tar.gz from the release, and compare its SHA-256 with
the digest on the release page.
2. Download the source archive of the tag, and compare its content with
"git archive" of the tag.
3. Replace both archives. Download ipxe-shimx64.efi and ipxe-shimaa64.efi
from the latest ipxe/shim release, and compare their SHA-256 with the
digests on its page. Drop them and their install lines when the shims of
the new tree carry the UEFI CA 2023 signature.
4. Write SHA256SUMS with sha256sum.
5. Write payload.sha256 from the tree with the shims in place:
mkdir tree
tar -xzf ipxeboot-<version>.tar.gz --strip-components=1 -C tree
cp ipxe-shimx64.efi tree/x86_64-sb/shimx64.efi
cp ipxe-shimaa64.efi tree/arm64-sb/shimaa64.efi
./verify-payload.pl --generate tree > payload.sha256
6. Update licenses/ when the release changes its licence texts or its shim.
7. Set the version in ipxe-xcat.spec and debian/changelog, and the ipxe-xcat
pins in packages-manifest.conf and debs-manifest.conf.