Package: shim-helpers-amd64-signed
Version: 1+15+1533136590.3beb971+7+deb10u1
(I don't know if this is actually a bug)
This package does not have any maintainer scripts. Hence, an update
places new versions of fbx64+mmx64 in /usr/lib/shim, but leaves the old
ones in /boot/efi.
shim-signed does appear to have such scripts, but the history suggests
they're not generally updated together (and not having to do so is
possibly the whole point of them being separate packages).
I haven't checked whether the other architectures also have this issue.
$ dpkg -l shim*
Desired=Unknown/Install/Remove/Purge/Hold
|
Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name Version
Architecture Des
+++-=========================-=================================-============-===
un shim <none> <none>
(no
ii shim-helpers-amd64-signed 1+15+1533136590.3beb971+7+deb10u1 amd64
boo
ii shim-signed:amd64 1.33+15+1533136590.3beb971-7 amd64
Sec
ii shim-signed-common 1.33+15+1533136590.3beb971-7 all
Sec
ii shim-unsigned 15+1533136590.3beb971-7+deb10u1 amd64
boo
$ sha256sum /usr/lib/shim/*
726dfb8abb923624c188b2505dc744409c3d589bed82b627984b6390c230a384
/usr/lib/shim/BOOTX64.CSV
a6614eb49da5292ba3254908c5530224d55f598440abca69d9c5f1b5242e9300
/usr/lib/shim/fbx64.efi
409681bf79c7678c4a4fc9bcb1e6ebac8c855da221fb85736a9a4e5b6bb9afde
/usr/lib/shim/fbx64.efi.signed
8081d19a4cdd8f75a8ef4448afaeed708bea4a2ca02bfda98e63fc0b7d148985
/usr/lib/shim/mmx64.efi
ace876d5f0052e6742ee7903771659434668c82d38aaf0e3d264441d984c7a3b
/usr/lib/shim/mmx64.efi.signed
a1974739a314a9d40a28d5ad413207dfe7805eb67ccc463dec9a6a98cc6a2442
/usr/lib/shim/shimx64.efi
599a102b6445fa88392b8c85a31d80ece950624219d846affbfb7131d4bf550b
/usr/lib/shim/shimx64.efi.signed
$ sudo sh -c "sha256sum /boot/efi/EFI/debian/*"
726dfb8abb923624c188b2505dc744409c3d589bed82b627984b6390c230a384
/boot/efi/EFI/debian/BOOTX64.CSV
ecaddaf33618754fef7a9340e589f8e2dad2d4656442680c19799d3deea7535f
/boot/efi/EFI/debian/fbx64.efi
18b4692f9a82886e859cba001ee00051b83664f8d44770fee2141f4e1b951510
/boot/efi/EFI/debian/grub.cfg
40c3753b2a80b50d498ed4cf4037510d8232f9f0be42fb67c4cfa8b441aea979
/boot/efi/EFI/debian/grubx64.efi
9b05af2f2b5b5bf5b1f8daae5b014ef33a94873fd95ec198d8aeac223bcef399
/boot/efi/EFI/debian/mmx64.efi
599a102b6445fa88392b8c85a31d80ece950624219d846affbfb7131d4bf550b
/boot/efi/EFI/debian/shimx64.efi