For review. (buster-amd64-devel)kibi@armor:~/work/bsp/secure-boot/redo$ (debdiff shim_*.dsc; echo; echo =====; echo; debdiff shim_*.deb; echo; echo ====; echo; debdiff shim-signed_*.dsc; echo; echo ====; echo; debdiff shim-signed_*.deb) 2>/dev/null diff -Nru shim-0.9+1474479173.6c180c6/debian/changelog shim-16+1474479173.6c180c6/debian/changelog --- shim-0.9+1474479173.6c180c6/debian/changelog 2016-10-15 13:17:34.000000000 +0000 +++ shim-16+1474479173.6c180c6/debian/changelog 2019-03-03 20:54:44.000000000 +0000 @@ -1,3 +1,17 @@ +shim (16+1474479173.6c180c6-1) unstable; urgency=medium + + * Re-upload 0.9+1474479173.6c180c6-1 with a version number that's higher + than 15+1533136590.3beb971-1, superseding the version currently in + unstable that has no matching shim-signed packages with updated + signatures (See: #922179). + * The shim binary package isn't actually getting rebuilt with this upload, + as it cannot be built reproducibly; this would invalidate the signature + shipped in the shim-signed package. So this new source package is + accompanied by the old binary package (from 0.9+1474479173.6c180c6-1), + repacked as a newer version (16+1474479173.6c180c6-1). + + -- Cyril Brulebois Sun, 03 Mar 2019 20:54:44 +0000 + shim (0.9+1474479173.6c180c6-1) unstable; urgency=medium [ Steve Langasek ] ===== File lists identical (after any substitutions) Control files: lines which differ (wdiff format) ------------------------------------------------ Version: [-0.9+1474479173.6c180c6-1-] {+16+1474479173.6c180c6-1+} ==== diff -Nru shim-signed-1.28+nmu1/debian/changelog shim-signed-1.28+nmu2/debian/changelog --- shim-signed-1.28+nmu1/debian/changelog 2018-11-04 07:09:26.000000000 +0000 +++ shim-signed-1.28+nmu2/debian/changelog 2019-03-03 20:57:35.000000000 +0000 @@ -1,3 +1,14 @@ +shim-signed (1.28+nmu2) unstable; urgency=medium + + * Update dependency to the repacked, old version of shim, fixing + installability issues. Closes: #922179. + * This package isn't actually rebuilt against the repacked shim as tooling + changed a bit (regarding how packing is handled), so the old shim-signed + binary (1.28+nmu1+0.9+1474479173.6c180c6-1) is repacked as well, + updating the following fields: Depends, Source, Version. + + -- Cyril Brulebois Sun, 03 Mar 2019 20:57:35 +0000 + shim-signed (1.28+nmu1) unstable; urgency=medium * Non-maintainer upload. ==== File lists identical (after any substitutions) Control files: lines which differ (wdiff format) ------------------------------------------------ Depends: debconf (>= 0.5) | debconf-2.0, shim (= [-0.9+1474479173.6c180c6-1),-] {+16+1474479173.6c180c6-1),+} grub-efi-amd64-bin, grub2-common (>= 2.02~beta2-36ubuntu12), mokutil Source: shim-signed [-(1.28+nmu1)-] {+(1.28+nmu2)+} Version: [-1.28+nmu1+0.9+1474479173.6c180c6-1-] {+1.28+nmu2+16+1474479173.6c180c6-1+} No differences were encountered between the postinst files No differences were encountered between the postrm files No differences were encountered between the templates files No differences were encountered between the triggers files