#13050 shim-unsigned-foo tagging for shim-16.1 in f44
Opened by pjones. Modified

  • Describe the issue
    We need shim-unsigned-aarch64-16.1-1 and shim-unsigned-x64-16.1-1 tagged into f44 so we can build the "signed" package.

  • When do you need this? (YYYY/MM/DD)
    2025/10/30

  • When is this no longer needed or useful? (YYYY/MM/DD)
    Next year

  • If we cannot complete your request, what is the impact?
    Shim in f41 will be newer than in f44.

Please check https://www.fedorastatus.org/ for any known
outages before filing issues on an outage.


Discussed it on chat with nirik and we'd also like the following:

shim-unsigned-aarch64-16.1-1 tagged into f42-updates-testing
shim-unsigned-aarch64-16.1-1 tagged into f43-updates-testing
shim-unsigned-x64-16.1-1 tagged into f42-updates-testing
shim-unsigned-x64-16.1-1 tagged into f43-updates-testing
shim-16.1-2 tagged into f42-updates-testing
shim-16.1-2 tagged into f43-updates-testing

CC: @adamwill should we run any of these by openqa since we are bypassing bodhi here?

uh, sure, I can...

I tagged the f44 ones in.

I have not done the rest yet, let me know when it would be good to.

tests looking good, just silverblue to finish up. ignore the upgrade_desktop_graphical failures on aarch64, that's a WIP I have going atm.

ok. good to tag then? and what critera should we use to move them from updates-testing to updates? I guess let them soak until next week?

Metadata Update from @jnsamyak:
- Issue tagged with: low-gain, medium-gain, ops

Metadata Update from @jnsamyak:
- Issue assigned to kevin

Please also push https://src.fedoraproject.org/rpms/shim-unsigned-x64/c/d355c62164bd48c6f47774fe04b0d730d892e006?branch=f43 to the rawhide branch.

I was wondering why the tests I ran for this issue didn't show up the problems we saw when we landed new shim in rawhide, but I think I see why. In this ticket we're referring to shim-16.1-2 . That's https://koji.fedoraproject.org/koji/buildinfo?buildID=2851862 , which was built against an f41 buildroot. So it didn't get the auto-hardlink change. But for Rawhide we landed shim-16.1-4, which was built against a Rawhide buildroot, so it did get the auto-hardlink change.

So, I didn't actually tag these last week, I have been swamped with fires. ;(

Should it be ok to tag the f42/43 ones to testing? or just to updates?

ok, I have tagged the builds into f42-updates-testing and f43-updates-testing.

They should go out in the next updates push.

Early next week I will tag them over to updates if there's no issues reported.

Metadata