FS#75002 - [grub] secure boot broken with grub 2.06.r261.g2f4430cc0-1

Attached to Project: Arch Linux
Opened by sunghwan jung (sunghwan) - Thursday, 09 June 2022, 05:35 GMT
Last edited by Toolybird (Toolybird) - Saturday, 01 July 2023, 01:47 GMT
Task Type Bug Report
Category Packages: Core
Status Closed
Assigned To Christian Hesse (eworm)
Architecture x86_64
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 4
Private No


after update to 2.06.r261.g2f4430cc0-1, secure boot is not work with "error: prohibited by secure boot policy
enter entering rescue mode
grub rescue>".
secure boot is work again after downgrade to 2.06-5.

Additional info:
* grub 2.06.r261.g2f4430cc0-1
* kernel 5.18.2-arch1-1
* secure boot by shim with shim-signed package (https://wiki.archlinux.org/title/Unified_Extensible_Firmware_Interface/Secure_Boot#shim)
* partiton - nvmen0n1p1:efi,vfat nvmen0n1p2: windows reserved partiton nvmen0n1p3:windows11,ntfs nvmen0n1p4:arch,ext4
This task depends upon

Closed by  Toolybird (Toolybird)
Saturday, 01 July 2023, 01:47 GMT
Reason for closing:  Not a bug
Additional comments about closing:  See comments re Wiki article
Comment by sunghwan jung (sunghwan) - Thursday, 09 June 2022, 06:32 GMT Comment by Morten Linderud (Foxboron) - Thursday, 09 June 2022, 07:08 GMT
You need the signed 15.6 shim, it's currently working as expected.
Comment by Lyubomir (mystiquewolf) - Friday, 08 July 2022, 01:57 GMT
  • Field changed: Percent Complete (100% → 0%)
FWIW this bug still happens after I updated both shim-signed to 15.6 and grub. With previous version of shim-signed 15.4,the issue still happened after update of grub. Reverting grub to 2.06-5 back then fixed it, so I have some reason to believe that the grub update is the cause of it.
Comment by Toolybird (Toolybird) - Sunday, 11 June 2023, 03:53 GMT
Still happening with latest pkgs? Have you strictly followed [1]?

[1] https://wiki.archlinux.org/title/Unified_Extensible_Firmware_Interface/Secure_Boot#shim_with_key_and_GRUB