2
0
mirror of https://github.com/xcat2/xcat-dep.git synced 2026-09-28 08:10:54 +00:00
Files
Vinícius Ferrão 9d944ee3c7 build(ipxe-xcat): install the shims signed by both UEFI CAs
The rpm and the deb install ipxe-shimx64.efi and ipxe-shimaa64.efi over
x86_64-sb/shimx64.efi and arm64-sb/shimaa64.efi of the release tree, so
firmware that trusts only the Microsoft UEFI CA 2023 loads the shim
with Secure Boot on. The ipxe-shim.efi and snponly-shim.efi links keep
their targets, and every other file of the tree is unchanged.
payload.sha256 lists the digests of the new shims, which both builders
check. The README says how to update them.
2026-09-27 12:01:19 -03:00
..

ipxe-xcat
=========

This package installs the ipxeboot.tar.gz tree of the iPXE v2.0.0 release
under /tftpboot/xcat/ipxe. Nothing is rebuilt, and only the two shims are
replaced: see The shim. The x86_64-sb
and arm64-sb builds carry their Secure Boot signatures inside the files, and
the shim finds snponly.efi and ipxe.efi by name in its own directory, so the
package keeps every name, symlink and byte of the release tree.

Files
-----

ipxeboot-2.0.0.tar.gz
    The ipxeboot.tar.gz asset of
    https://github.com/ipxe/ipxe/releases/tag/v2.0.0, renamed. Its SHA-256,
    01a526d4cc791fc30362259c609d6c506cc64a7bdff51b9a5eb788354e17eee1, is the
    digest that GitHub publishes for the asset.

ipxe-2.0.0-source.tar.gz
    The source archive of tag v2.0.0, commit
    12798ec29aa8a64d8675c4378b99f5fe28447afb, from
    https://github.com/ipxe/ipxe/archive/refs/tags/v2.0.0.tar.gz. Its content
    equals "git archive --prefix=ipxe-2.0.0/ v2.0.0". snpnet.c and undinet.c
    are GPL2_OR_LATER without the UBDL, so snponly.efi and undionly.kpxe are
    GPLv2+ as a whole. The package installs this archive with the binaries.

ipxe-shimx64.efi, ipxe-shimaa64.efi
    The ipxe-shimx64.efi and ipxe-shimaa64.efi assets of
    https://github.com/ipxe/shim/releases/tag/ipxe-16.1, as ipxe replaced
    them on 2026-05-27. Their SHA-256 values are the digests that GitHub
    publishes for the assets.

SHA256SUMS
    The SHA-256 of both archives and both shims. Both builders check it
    before the build.

payload.sha256
    One line for each directory, file and symlink of the release tree, with
    the SHA-256 of each file and the target of each symlink. After the build,
    both builders unpack the RPM or deb and compare its /tftpboot/xcat/ipxe
    with this list, entry for entry, with verify-payload.pl. A difference
    fails the build.

licenses/
    ipxe/COPYING, COPYING.GPLv2 and COPYING.UBDL are from iPXE tag v2.0.0.
    shim/COPYRIGHT is from ipxe/shim tag ipxe-16.1.
    shim/openssl/LICENSE is from openssl/openssl tag OpenSSL_1_0_2k, the
    OpenSSL version that shim 16.1 carries in Cryptlib.
    shim/gnu-efi/README.efilib is from rhboot/gnu-efi commit dc7fd96, the
    gnu-efi commit that tag ipxe-16.1 pins.

The shim
--------

The release tree carries shim 16.1 as x86_64-sb/shimx64.efi and
arm64-sb/shimaa64.efi, signed by the Microsoft Corporation UEFI CA 2011
only. Firmware that trusts only the UEFI CA 2023 refuses them with Secure
Boot on. On 2026-05-27 ipxe replaced the ipxe/shim ipxe-16.1 release assets
with a build signed by both CAs. Both builders install ipxe-shimx64.efi and
ipxe-shimaa64.efi over the shims of the tree, under the same names, so the
ipxe-shim.efi and snponly-shim.efi links still point to them. payload.sha256
lists the digests of the replacements.

Update to a new release
-----------------------

1. Download ipxeboot.tar.gz from the release, and compare its SHA-256 with
   the digest on the release page.
2. Download the source archive of the tag, and compare its content with
   "git archive" of the tag.
3. Replace both archives. Download ipxe-shimx64.efi and ipxe-shimaa64.efi
   from the latest ipxe/shim release, and compare their SHA-256 with the
   digests on its page. Drop them and their install lines when the shims of
   the new tree carry the UEFI CA 2023 signature.
4. Write SHA256SUMS with sha256sum.
5. Write payload.sha256 from the tree with the shims in place:

       mkdir tree
       tar -xzf ipxeboot-<version>.tar.gz --strip-components=1 -C tree
       cp ipxe-shimx64.efi tree/x86_64-sb/shimx64.efi
       cp ipxe-shimaa64.efi tree/arm64-sb/shimaa64.efi
       ./verify-payload.pl --generate tree > payload.sha256

6. Update licenses/ when the release changes its licence texts or its shim.
7. Set the version in ipxe-xcat.spec and debian/changelog, and the ipxe-xcat
   pins in packages-manifest.conf and debs-manifest.conf.