jammy/linux-azure-fips: 5.15.0-1058.66+fips1 -proposed tracker

Bug #2052046 reported by Stefan Bader
12
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Kernel SRU Workflow
Fix Released
Medium
Unassigned
Abi-testing
Invalid
Medium
Unassigned
Automated-testing
Invalid
Medium
Unassigned
Boot-testing
Fix Released
Medium
Unassigned
Certification-testing
Invalid
Medium
Unassigned
New-review
Fix Released
Medium
Andy Whitcroft
Prepare-package
Fix Released
Medium
Magali Lemes do Sacramento
Prepare-package-generate
Fix Released
Medium
Magali Lemes do Sacramento
Prepare-package-lrg
Fix Released
Medium
Unassigned
Prepare-package-lrm
Fix Released
Medium
Andy Whitcroft
Prepare-package-lrs
Fix Released
Medium
Andy Whitcroft
Prepare-package-meta
Fix Released
Medium
Magali Lemes do Sacramento
Prepare-package-signed
Fix Released
Medium
Magali Lemes do Sacramento
Promote-signing-to-proposed
Invalid
Medium
Unassigned
Promote-to-proposed
Fix Released
Medium
Ubuntu Stable Release Updates Team
Promote-to-security
Invalid
Medium
Ubuntu Stable Release Updates Team
Promote-to-updates
Fix Released
Medium
Andy Whitcroft
Regression-testing
Fix Released
Medium
Canonical Kernel Team
Security-signoff
Invalid
Medium
Canonical Security Team
Signing-signoff
Fix Released
Medium
Magali Lemes do Sacramento
Sru-review
Fix Released
Medium
Andy Whitcroft
Stakeholder-signoff
Fix Released
Medium
linux-azure stakeholder signoff
Verification-testing
Fix Released
Medium
Canonical Kernel Team
canonical-signing-jobs
Task00
Fix Released
Medium
Andy Whitcroft
linux (Ubuntu)
Jammy
New
Medium
Unassigned

Bug Description

This bug will contain status and test results related to a kernel source (or snap) as stated in the title.

For an explanation of the tasks and the associated workflow see:
  https://wiki.ubuntu.com/Kernel/kernel-sru-workflow

-- swm properties --
built:
  from: f7d90a6cd40ddeba
  route-entry: 1
delta:
  promote-to-proposed: [lrm, lrs, lrg]
  promote-to-updates: [lrm, lrs, main, meta, signed]
flag:
  boot-testing-requested: true
  bugs-spammed: true
  proposed-announcement-sent: true
  proposed-testing-requested: true
  stream-from-cycle: true
issue: KSRU-11008
kernel-stable-master-bug: 2052049
packages:
  generate: linux-generate-azure-fips
  lrg: linux-restricted-generate-azure-fips
  lrm: linux-restricted-modules-azure-fips
  lrs: linux-restricted-signatures-azure-fips
  main: linux-azure-fips
  meta: linux-meta-azure-fips
  signed: linux-signed-azure-fips
phase: Complete
phase-changed: Thursday, 07. March 2024 20:56 UTC
reason: {}
synthetic:
  :promote-to-as-proposed: Invalid
variant: debs
versions:
  lrm: 5.15.0-1058.66+fips1+1
  main: 5.15.0-1058.66+fips1
  meta: 5.15.0.1058.47
  signed: 5.15.0-1058.66+fips1
versions-replace:
  lrm: [5.15.0-1058.66+fips1]
~~:
  announce:
    swm-transition-crankable: 2024-02-27 01:36:27.263548
  clamps:
    new-review: f7d90a6cd40ddeba
    promote-to-proposed: f7d90a6cd40ddeba
    self: 5.15.0-1058.66+fips1
    sru-review: f7d90a6cd40ddeba
  tracker:
    last-message: '2024-03-07 22:00:42.591550+00:00'

Stefan Bader (smb)
tags: added: kernel-release-tracking-bug-live
description: updated
tags: added: kernel-sru-cycle-2024.02.05-1
description: updated
tags: added: kernel-sru-derivative-of-2052049
Changed in kernel-sru-workflow:
status: New → Confirmed
importance: Undecided → Medium
Changed in linux (Ubuntu Jammy):
importance: Undecided → Medium
Changed in kernel-sru-workflow:
status: Confirmed → Triaged
description: updated
Changed in kernel-sru-workflow:
status: Triaged → In Progress
tags: added: kernel-jira-issue-ksru-11008
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
summary: - jammy/linux-azure-fips: <version to be filled> -proposed tracker
+ jammy/linux-azure-fips: 5.15.0-1058.66+fips1 -proposed tracker
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
Revision history for this message
Ubuntu Kernel Bot (ubuntu-kernel-bot) wrote : Kernel requires additional signoff

New kernel with signed kernels; signing-review required.

description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
Revision history for this message
Magali Lemes do Sacramento (magalilemes) wrote :

Tested secure boot and kernel lockdown on both arm64 and x86_64:

ubuntu@j-azure-fips:~$ uname -a
Linux j-azure-fips 5.15.0-1058-azure-fips #66+fips1-Ubuntu SMP Tue Feb 27 13:37:55 UTC 2024 aarch64 aarch64 aarch64 GNU/Linux
ubuntu@j-azure-fips:~$ sudo dmesg | grep -i "secure boot" | head -n2
[ 0.000000] secureboot: Secure boot enabled
[ 0.000000] Kernel is locked down from EFI Secure Boot mode; see man kernel_lockdown.7
ubuntu@j-azure-fips:~$ cat /sys/kernel/security/lockdown
none [integrity] confidentiality

ubuntu@j-azure-fips:~$ uname -a
Linux j-azure-fips 5.15.0-1058-azure-fips #66+fips1-Ubuntu SMP Tue Feb 27 13:29:42 UTC 2024 x86_64 x86_64 x86_64 GNU/Linux
ubuntu@j-azure-fips:~$ sudo dmesg | grep -i "secure boot" | head -n2
[ 0.000000] secureboot: Secure boot enabled
[ 0.000000] Kernel is locked down from EFI Secure Boot mode; see man kernel_lockdown.7
ubuntu@j-azure-fips:~$ cat /sys/kernel/security/lockdown
none [integrity] confidentiality

description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
Revision history for this message
Magali Lemes do Sacramento (magalilemes) wrote :

Nothing to be verified.

tags: added: verification-testing-passed
description: updated
description: updated
description: updated
Andy Whitcroft (apw)
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
description: updated
Revision history for this message
Ubuntu Kernel Bot (ubuntu-kernel-bot) wrote : Workflow done!

All tasks have been completed and the bug is being closed

Changed in kernel-sru-workflow:
status: In Progress → Fix Committed
Changed in kernel-sru-workflow:
status: Fix Committed → Fix Released
description: updated
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.