Skip to content

3.6 planning: Secure Boot without Microsoft-trusted keys - #3

Draft
ShadowfetchLinux wants to merge 1 commit into
mainfrom
cursor/3.6-secure-boot-plan-e592
Draft

3.6 planning: Secure Boot without Microsoft-trusted keys#3
ShadowfetchLinux wants to merge 1 commit into
mainfrom
cursor/3.6-secure-boot-plan-e592

Conversation

@ShadowfetchLinux

Copy link
Copy Markdown
Owner

Planning only. 3.5.0 Fire and Ice («Umbra») is already shipped; this PR does not rebuild the ISO, does not change live-build packages, and does not invent Microsoft/Secure Boot signing keys.

Why this note

The public known-issues page lists unsigned Secure Boot as issue #1 (no Microsoft-trusted shim). The ISO is already 3,980,310,528 bytes (~3.98 GB). The old ROADMAP-NEXT-BUILD.md still treats Btrfs snapshots as the next headline bet; 3.5.0 already ships Phoenix + Fireproof + grub-btrfs, so that bet is done. Secure Boot is the actual next differentiator.

What landed

  • next-release/3.6-secure-boot.md — engineering-honest 3.6 plan:
    • what we can ship without Microsoft-trusted keys (keep the published firmware-disable path; MOK as a machine-local DKMS helper, not a substitute; optional Debian signed-chain reuse if and only if a signed-boot test passes)
    • UKI as research, not a default (ISO size + grub-btrfs / Phoenix snapshot-boot)
    • ISO-size math and squashfs-headroom warning
    • risks (claim drift, NVIDIA lockdown, BitLocker, live-USB chicken-and-egg, --removable --no-nvram)
    • explicit out-of-scope list for 3.6
  • next-release/README.md — short pointer; existing 2.2.0 staged-binary notes kept

No product claim on the website should change until a Secure-Boot-on test exists. Known-issues #1 stays #1.

Open in Web Open in Cursor 

Record what 3.6 can honestly ship without Microsoft-trusted keys:
MOK, optional Debian signed-chain reuse, and the firmware-disable
path already published. Confirm Phoenix/Fireproof already covers
the old snapshots bet. Do not rebuild the ISO or change live-build.

Co-authored-by: Bob Corbin <ShadowfetchLinux@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants