Skip to content

Conversation

@MingcongBai
Copy link
Contributor

Connect to our signing server during build time and sign the kernel image as it gets installed to the temporary Debian packaging directory.

Connect to our signing server during build time and sign the kernel image as
it gets installed to the temporary Debian packaging directory.

Co-authored-by: 李成刚 <lichenggang@uniontech.com>
Signed-off-by: Mingcong Bai <baimingcong@uniontech.com>
Signed-off-by: 李成刚 <lichenggang@uniontech.com>
Signed-off-by: Meng Tang <tangmeng@uniontech.com>
@Avenger-285714
Copy link
Member

/lgtm

@Avenger-285714 Avenger-285714 merged commit f18ca95 into deepin-community:linux-6.6.y Jun 20, 2024
@deepin-ci-robot
Copy link

deepin pr auto review

关键摘要:

  • builddeb脚本中添加了UEFI Secure Boot CA证书路径,但未提供证书的来源和有效性验证。
  • 添加了UEFI Secure Boot签名代码,但没有对签名工具sbsign的执行进行错误处理或日志记录。
  • 使用了硬编码的IP地址和端口,这可能导致在不同环境下需要手动修改配置。

是否建议立即修改:

建议的修改:

  • 确保提供有效的UEFI Secure Boot CA证书,并验证证书的有效性和安全性。
  • sbsign命令的执行进行错误处理和日志记录,以便在出现问题时能够追踪问题。
  • 使用环境变量或配置文件来存储IP地址和端口,以便在不同的环境之间进行配置。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants