3.6 planning: Secure Boot without Microsoft-trusted keys - #3
Draft
ShadowfetchLinux wants to merge 1 commit into
Draft
3.6 planning: Secure Boot without Microsoft-trusted keys#3ShadowfetchLinux wants to merge 1 commit into
ShadowfetchLinux wants to merge 1 commit into
Conversation
Record what 3.6 can honestly ship without Microsoft-trusted keys: MOK, optional Debian signed-chain reuse, and the firmware-disable path already published. Confirm Phoenix/Fireproof already covers the old snapshots bet. Do not rebuild the ISO or change live-build. Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueComment |
8 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Planning only. 3.5.0 Fire and Ice («Umbra») is already shipped; this PR does not rebuild the ISO, does not change live-build packages, and does not invent Microsoft/Secure Boot signing keys.
Why this note
The public known-issues page lists unsigned Secure Boot as issue #1 (no Microsoft-trusted shim). The ISO is already 3,980,310,528 bytes (~3.98 GB). The old
ROADMAP-NEXT-BUILD.mdstill treats Btrfs snapshots as the next headline bet; 3.5.0 already ships Phoenix + Fireproof +grub-btrfs, so that bet is done. Secure Boot is the actual next differentiator.What landed
next-release/3.6-secure-boot.md— engineering-honest 3.6 plan:grub-btrfs/ Phoenix snapshot-boot)--removable --no-nvram)next-release/README.md— short pointer; existing 2.2.0 staged-binary notes keptNo product claim on the website should change until a Secure-Boot-on test exists. Known-issues #1 stays #1.