grub-efi - GRand Unified Bootloader, version 2 (dummy package)

Distribution: Ubuntu 17.04 (Zesty Zapus)
This is a dummy transitional package that depends on either grub-efi-ia32 or grub-efi-amd64, depending on the architecture.


    2017-06-14 - Mathieu Trudel-Lapierre <> grub2 (2.02~beta3-4ubuntu2.2) zesty; urgency=medium * debian/patches: Rework linuxefi/SecureBoot support and sync with upstream SB patch set: (LP: #1696599) - linuxefi_arm_sb_support.patch: add Secure Boot support for arm for its chainloader. - linuxefi_fix_validation_race.patch: Fix a race in validating images. - linuxefi_chainloader_path.patch: honor the starting path for grub, so images do not need to be started from $root. - linuxefi_chainloader_sb.patch: Fix some more issues in chainloader use when Secure Boot is enabled. - linuxefi_loaders_enforce_sb.patch: Enforce Secure Boot policy for all loaders: don't load the commands when Secure Boot is enabled. - linuxefi_re-enable_linux_cmd.patch: Since we rely on the linux and initrd commands to automatically hand-off to linuxefi/initrdefi; re- enable the linux loader. - linuxefi_chainloader_pe_fixes.patch: PE parsing fixes for chainloading "special" PE images, such as Windows'. - linuxefi_rework_non-sb_cases.patch: rework cases where Secure Boot is disabled or shim validation is disabled so loading works as EFI binaries when it is supposed to. - Removed linuxefi_require_shim.patch; superseded by the above. (LP: #1689687)

    2017-05-24 - Mathieu Trudel-Lapierre <> grub2 (2.02~beta3-4ubuntu2.1) zesty; urgency=medium * debian/patches/install_signed.patch: don't install fb$arch.efi; it breaks "removable" installs where files are all installed to /EFI/BOOT; and it also doesn't belong in the /EFI/ubuntu path for the default case. Fallback install simply needs more work and isn't ready for SRU. (LP: #1684341) * debian/ clean up fb$arch.efi.

    2017-03-30 - Mathieu Trudel-Lapierre <> grub2 (2.02~beta3-4ubuntu2) zesty; urgency=medium * debian/build-efi-images: provide a new grub EFI image which enforces that loaded kernels are signed for Secure Boot: build gsb$arch.efi; which is the same as grub$arch.efi minus the 'linux' module. Without fallback to 'linux' for unsigned loading, this makes it effectively enforce having a signed kernel. (LP: #1401532)

    2017-02-09 - dann frazier <> grub2 (2.02~beta3-4ubuntu1) zesty; urgency=medium * Merge with Debian; remaining changes: - debian/patches/support_initrd-less_boot.patch: Added knobs to allow non-initrd boot config. (LP: #1640878) - Disable os-prober for ppc64el on the PowerNV platform, to reduce the number of entries/clutter from other OSes in Petitboot (LP: #1447500)