Skip to content

3.6 Secure Boot — implementation gates (from PR #3 plan) #4

Description

@ShadowfetchLinux

Tracking checklist for turning the 3.6 Secure Boot planning note into a real ship.

Source of truth: draft PR #3 (next-release/3.6-secure-boot.md). Planning only — no live-build edits and no ISO rebuild until the gates below say so.

Non-negotiables

Gates

  • Merge PR 3.6 planning: Secure Boot without Microsoft-trusted keys #3 (or land the planning docs on main) so the plan is the repo record.
  • Measure filesystem.squashfs + ESP contents on the shipped 3.5.0 ISO (3,980,310,528 bytes / sha256 2af853b1…). Write numbers into the plan before adding boot payloads.
  • Spike (lab only): install Debian shim-signed + grub-efi-amd64-signed as installed UEFI first-stage, replacing unsigned sf-install-grub, prefer --removable unless a test shows NVRAM is required.
  • Success metric for spike: Secure Boot-on OVMF guest boots the installed disk on Debian’s signatures. Failure is allowed — write it down.
  • If and only if the spike works: machine-local MOK helper for DKMS / NVIDIA under lockdown; Phoenix Point still wraps the driver transaction.
  • Re-test Phoenix / grub-btrfs snapshot-boot with Secure Boot + lockdown on.
  • Add a Secure-Boot-on acceptance gate (OVMF + at least one physical machine). Virtual Mesa alone is not enough.
  • Separate publication decision for site/known-issues copy — only after the gate exists.

Explicitly out for 3.6

Microsoft third-party CA / Shadowfetch-branded shim, UKI as default, systemd-boot A/B replacing GRUB, rebuilding 3.5.0 “just to try,” and any claim that shipping mokutil / shim-signed packages fixed known-issues #1.

Opened by Pam (VP ops) after first-plate review with Candice.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions