End of the year and third blog post! Hope everyone has had a nice new years eve :)
The first news of the month is that Remi Gacogne was accepted as Trusted User. Congratulations to him and super exciting.
Other then that I have had a meeting with the devops team discussing how we should implement the debuginfod system on our infrastructure. I have written up the ansible role for debuginfod and it was more or less decided that we want to host it on a small VPS for the service itself, and sync debug packages to the host to serve them. This avoid the problem of hosting more services on our server which distributes packages with services it does not really need.
My hope is to have debuginfod implemented by February, but there is still quite a few things to figure out!
Secureboot.dev
I have started planning a bit how to organize the notes and stuff i learn while
programming on sbctl and go-uefi. My current plan is to document it on a
website since I got a pretty nice domain name: https://secureboot.dev/.
The idea is to try document the existing secure boot tools, what they cover and
where they fit. Along with any information that might be useful for users that
intend to use Secure Boot on Linux. I also want to try lay out some pointers of
the UEFI spec. It would mostly deal with how efivars works on Linux, and point
out the relevant parts from the specification. The intention is to aid people
that want to provide better userspace tooling for secure boot.
It is currently a work in progress, but there is a Github repo with the source if someone is interested contributing to the page.
My talk to the FOSDEM Open Source Firmware, BMC and Bootloader devroom has also
been accepted. I’ll introduce some of the work I have been doing with sbctl
and go-uefi the past year to make things easier for users, along with my
current gripes with the existing secure boot tooling. Super exciting!
I’m also going to rename the go library from goefi to go-uefi as it makes
more sense and resonates better with the go libraries in the same space. Like
go-tpm and go-attestation.
Package Updates to [community]
podmanupdated to2.2.0-1,2.2.1-1dockerupdated to1:19.03.14-1,1:19.03.14-2libslirpupdated to4.4.0-1python-google-api-python-clientupdated to1.12.8-1python-google-api-coreupdated to1.23.0-1,1.24.0-1,1.24.1-1python-pandasupdated to1.1.4-1,1.1.5-1python-pipenvupdated to2020.11.15-1python-pykkaupdated to2.0.3-1python-xlibupdated to0.29-1python-jsonrpclib-pelixupdated to0.4.2-1python-language-serverupdated to0.36.1-1,0.36.2-1python-docsupdated to3.9.0-1,3.9.1-1python-hidapiupdated to0.10.1-1python-dockerupdated to4.4.0-1,4.4.1-1python-pyserialupdated to3.5-1python-babelupdated to2.9.0-1slirp4netnsupdated to1.1.8-1qmkupdated to0.0.37-1github-cliupdated to1.3.1-1,1.4.0-1goupdated to2:1.15.6-1k9supdated to0.24.2-1gliderupdated to0.13.0-1qutebrowserupdated to1.14.1-1goplsupdated to0.5.5-1,0.6.0-1,0.6.1-1bluemanupdated to2.1.4-1fzfupdated to0.24.4-1archlinux-contribupdated to20201205-1screenkeyupdated to1.3-1python-m2cryptoupdated to0.37.1-1dns-over-httpsupdated to2.2.4-1delveupdated to1.5.1-1helmupdated to3.4.2-1cni-pluginsupdated to0.9.0-1,0.9.0-3plocateupdated to1.1.2-1,1.1.3-1lxdupdated to4.9-1git-lfsupdated to2.13.1-1python-autobahnupdated to20.12.1-1,20.12.2-1staticcheckupdated to2020.2-1python-sqlobjectupdated to3.9.0-1dockerupdated to1:20.10.1-1mopidyupdated to3.1.0-1,3.1.1-1conmonupdated to1:2.0.22-1darktableupdated to2:3.5.0-1libmdupdated to1.0.2-1python-reportlabupdated to3.5.57-1
Package additions to [community]
python-adblock: Allowsqutebrowserto implement ABP style adblocking
Potential new packages for [community]
- oomd
- vgrep
- git-publish
- b4
- psi-notify
- etcd
- micro
- tailscale
- Is going to be uploaded to
[community]through january.
- Is going to be uploaded to
Bugfixes
qmk: Removed the udev files in favour of the combined file file from upstream.docker: Fixed FS#68833- No more
-ceembedded in the binary.
- No more
cni-plugins: Ensure binaries are symlinked into/opt/cni/bin
Security Team
This month the security team has published 26 advisories and created around 88 Advisory Groups. A lot of this work has been done by Jonas Witschel!
Other things…
archlinux-contribarchlinux-repro
Cheers and a happy new year :)