shim-unsigned-foo tagging for shim-16.1 in f44 #13050

Open
opened 2025-10-30 20:00:37 +00:00 by pjones · 17 comments
  • Describe the issue
    We need shim-unsigned-aarch64-16.1-1 and shim-unsigned-x64-16.1-1 tagged into f44 so we can build the "signed" package.

  • When do you need this? (YYYY/MM/DD)
    2025/10/30

  • When is this no longer needed or useful? (YYYY/MM/DD)
    Next year

  • If we cannot complete your request, what is the impact?
    Shim in f41 will be newer than in f44.

Please check https://www.fedorastatus.org/ for any known
outages before filing issues on an outage.

* Describe the issue We need shim-unsigned-aarch64-16.1-1 and shim-unsigned-x64-16.1-1 tagged into f44 so we can build the "signed" package. * When do you need this? (YYYY/MM/DD) 2025/10/30 * When is this no longer needed or useful? (YYYY/MM/DD) Next year * If we cannot complete your request, what is the impact? Shim in f41 will be newer than in f44. Please check https://www.fedorastatus.org/ for any known outages before filing issues on an outage.
Author

Discussed it on chat with nirik and we'd also like the following:

shim-unsigned-aarch64-16.1-1 tagged into f42-updates-testing
shim-unsigned-aarch64-16.1-1 tagged into f43-updates-testing
shim-unsigned-x64-16.1-1 tagged into f42-updates-testing
shim-unsigned-x64-16.1-1 tagged into f43-updates-testing
shim-16.1-2 tagged into f42-updates-testing
shim-16.1-2 tagged into f43-updates-testing

Discussed it on chat with nirik and we'd also like the following: shim-unsigned-aarch64-16.1-1 tagged into f42-updates-testing shim-unsigned-aarch64-16.1-1 tagged into f43-updates-testing shim-unsigned-x64-16.1-1 tagged into f42-updates-testing shim-unsigned-x64-16.1-1 tagged into f43-updates-testing shim-16.1-2 tagged into f42-updates-testing shim-16.1-2 tagged into f43-updates-testing
Owner

CC: @adamwill should we run any of these by openqa since we are bypassing bodhi here?

CC: @adamwill should we run any of these by openqa since we are bypassing bodhi here?
Member

uh, sure, I can...

uh, sure, I can...
Owner

I tagged the f44 ones in.

I have not done the rest yet, let me know when it would be good to.

I tagged the f44 ones in. I have not done the rest yet, let me know when it would be good to.
Member
tests running: * [F42 x86_64](https://openqa.stg.fedoraproject.org/tests/overview?distri=fedora&version=42&build=Kojitask-138544794_136733102-NOREPORT&groupid=2) * [F43 x86_64](https://openqa.stg.fedoraproject.org/tests/overview?distri=fedora&version=43&build=Kojitask-138544794_136733102-NOREPORT&groupid=2) * [F42 aarch64](https://openqa.stg.fedoraproject.org/tests/overview?distri=fedora&version=42&build=Kojitask-138544794_136733100-NOREPORT&groupid=7) * [F43 aarch64](https://openqa.stg.fedoraproject.org/tests/overview?distri=fedora&version=43&build=Kojitask-138544794_136733100-NOREPORT&groupid=7)
Member

tests looking good, just silverblue to finish up. ignore the upgrade_desktop_graphical failures on aarch64, that's a WIP I have going atm.

tests looking good, just silverblue to finish up. ignore the upgrade_desktop_graphical failures on aarch64, that's a WIP I have going atm.
Owner

ok. good to tag then? and what critera should we use to move them from updates-testing to updates? I guess let them soak until next week?

ok. good to tag then? and what critera should we use to move them from updates-testing to updates? I guess let them soak until next week?
Owner

Metadata Update from @jnsamyak:

  • Issue tagged with: low-gain, medium-gain, ops
**Metadata Update from @jnsamyak**: - Issue tagged with: low-gain, medium-gain, ops
Owner

Metadata Update from @jnsamyak:

  • Issue assigned to kevin
**Metadata Update from @jnsamyak**: - Issue assigned to kevin
Contributor
Please also push https://src.fedoraproject.org/rpms/shim-unsigned-x64/c/d355c62164bd48c6f47774fe04b0d730d892e006?branch=f43 to the rawhide branch.
Member

I was wondering why the tests I ran for this issue didn't show up the problems we saw when we landed new shim in rawhide, but I think I see why. In this ticket we're referring to shim-16.1-2 . That's https://koji.fedoraproject.org/koji/buildinfo?buildID=2851862 , which was built against an f41 buildroot. So it didn't get the auto-hardlink change. But for Rawhide we landed shim-16.1-4, which was built against a Rawhide buildroot, so it did get the auto-hardlink change.

I was wondering why the tests I ran for this issue didn't show up the problems we saw when we landed new shim in rawhide, but I think I see why. In this ticket we're referring to shim-16.1-2 . That's https://koji.fedoraproject.org/koji/buildinfo?buildID=2851862 , which was built against an f41 buildroot. So it didn't get the auto-hardlink change. But for Rawhide we landed [shim-16.1-4](https://koji.fedoraproject.org/koji/buildinfo?buildID=2852551), which was built against a Rawhide buildroot, so it *did* get the auto-hardlink change.
Owner

So, I didn't actually tag these last week, I have been swamped with fires. ;(

Should it be ok to tag the f42/43 ones to testing? or just to updates?

So, I didn't actually tag these last week, I have been swamped with fires. ;( Should it be ok to tag the f42/43 ones to testing? or just to updates?
Owner

ok, I have tagged the builds into f42-updates-testing and f43-updates-testing.

They should go out in the next updates push.

Early next week I will tag them over to updates if there's no issues reported.

ok, I have tagged the builds into f42-updates-testing and f43-updates-testing. They should go out in the next updates push. Early next week I will tag them over to updates if there's no issues reported.
Owner

Reading above, I think the work is done here. If not please feel free to reopen this, trying to clear out the backlogs.

Reading above, I think the work is done here. If not please feel free to reopen this, trying to clear out the backlogs.
Owner

This is not actually done. They were tagged into testing, but then there were problem reports, so I never tagged them into stable updates.

This is not actually done. They were tagged into testing, but then there were problem reports, so I never tagged them into stable updates.
kevin reopened this issue 2025-12-31 21:28:49 +00:00
Member

Right, and the thread just sort of died inconclusively. So I'm not sure what we should do. Still...the packages are still in u-t, right? So folks with u-t enabled should have them? In which case I'd kinda expect more noise by now if there was a wider problem..

Right, and [the thread](https://lists.fedoraproject.org/archives/list/test@lists.fedoraproject.org/thread/44G3DOHQOIJ4KSBF55ERQQDBSLRJWHTP/#KMR4DR5PHM7IUGZUZ4G557ZZNNYQF6EU) just sort of died inconclusively. So I'm not sure what we should do. Still...the packages are still in u-t, right? So folks with u-t enabled should have them? In which case I'd kinda expect more noise by now if there was a wider problem..
Owner

Yeah. Probibly next week after checking in with @pjones we can move them to stable updates...

Yeah. Probibly next week after checking in with @pjones we can move them to stable updates...
Sign in to join this conversation.
No milestone
No project
No assignees
5 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
releng/tickets#13050
No description provided.