Tracking checklist for turning the 3.6 Secure Boot planning note into a real ship.
Source of truth: draft PR #3 (next-release/3.6-secure-boot.md). Planning only — no live-build edits and no ISO rebuild until the gates below say so.
Non-negotiables
Gates
Explicitly out for 3.6
Microsoft third-party CA / Shadowfetch-branded shim, UKI as default, systemd-boot A/B replacing GRUB, rebuilding 3.5.0 “just to try,” and any claim that shipping mokutil / shim-signed packages fixed known-issues #1.
Opened by Pam (VP ops) after first-plate review with Candice.
Tracking checklist for turning the 3.6 Secure Boot planning note into a real ship.
Source of truth: draft PR #3 (
next-release/3.6-secure-boot.md). Planning only — no live-build edits and no ISO rebuild until the gates below say so.Non-negotiables
docs/GITHUB-CLAIM-SOURCES.md).grub-btrfssnapshot-boot for a prettier EFI path.Gates
main) so the plan is the repo record.filesystem.squashfs+ ESP contents on the shipped 3.5.0 ISO (3,980,310,528bytes / sha2562af853b1…). Write numbers into the plan before adding boot payloads.shim-signed+grub-efi-amd64-signedas installed UEFI first-stage, replacing unsignedsf-install-grub, prefer--removableunless a test shows NVRAM is required.grub-btrfssnapshot-boot with Secure Boot + lockdown on.Explicitly out for 3.6
Microsoft third-party CA / Shadowfetch-branded shim, UKI as default, systemd-boot A/B replacing GRUB, rebuilding 3.5.0 “just to try,” and any claim that shipping
mokutil/shim-signedpackages fixed known-issues #1.Opened by Pam (VP ops) after first-plate review with Candice.