Diff of the two buildlogs:

--
--- b1/build.log	2025-03-19 05:18:43.555963731 +0000
+++ b2/build.log	2025-03-19 05:20:09.212103649 +0000
@@ -1,6 +1,6 @@
 I: pbuilder: network access will be disabled during build
-I: Current time: Tue Mar 18 17:17:07 -12 2025
-I: pbuilder-time-stamp: 1742361427
+I: Current time: Wed Apr 22 01:41:45 +14 2026
+I: pbuilder-time-stamp: 1776771705
 I: Building the build Environment
 I: extracting base tarball [/var/cache/pbuilder/trixie-reproducible-base.tgz]
 I: copying local configuration
@@ -31,52 +31,84 @@
 dpkg-source: info: applying no-efi-on-aarch64.patch
 I: using fakeroot in build.
 I: Installing the build-deps
-I: user script /srv/workspace/pbuilder/3266645/tmp/hooks/D02_print_environment starting
+I: user script /srv/workspace/pbuilder/181475/tmp/hooks/D01_modify_environment starting
+debug: Running on ionos5-amd64.
+I: Changing host+domainname to test build reproducibility
+I: Adding a custom variable just for the fun of it...
+I: Changing /bin/sh to bash
+'/bin/sh' -> '/bin/bash'
+lrwxrwxrwx 1 root root 9 Apr 21 11:42 /bin/sh -> /bin/bash
+I: Setting pbuilder2's login shell to /bin/bash
+I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other
+I: user script /srv/workspace/pbuilder/181475/tmp/hooks/D01_modify_environment finished
+I: user script /srv/workspace/pbuilder/181475/tmp/hooks/D02_print_environment starting
 I: set
-  BUILDDIR='/build/reproducible-path'
-  BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other'
-  BUILDUSERNAME='pbuilder1'
-  BUILD_ARCH='amd64'
-  DEBIAN_FRONTEND='noninteractive'
-  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=20 '
-  DISTRIBUTION='trixie'
-  HOME='/root'
-  HOST_ARCH='amd64'
+  BASH=/bin/sh
+  BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath
+  BASH_ALIASES=()
+  BASH_ARGC=()
+  BASH_ARGV=()
+  BASH_CMDS=()
+  BASH_LINENO=([0]="12" [1]="0")
+  BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:.
+  BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment")
+  BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="x86_64-pc-linux-gnu")
+  BASH_VERSION='5.2.37(1)-release'
+  BUILDDIR=/build/reproducible-path
+  BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other'
+  BUILDUSERNAME=pbuilder2
+  BUILD_ARCH=amd64
+  DEBIAN_FRONTEND=noninteractive
+  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=42 '
+  DIRSTACK=()
+  DISTRIBUTION=trixie
+  EUID=0
+  FUNCNAME=([0]="Echo" [1]="main")
+  GROUPS=()
+  HOME=/root
+  HOSTNAME=i-capture-the-hostname
+  HOSTTYPE=x86_64
+  HOST_ARCH=amd64
   IFS=' 	
   '
-  INVOCATION_ID='2fc5eb5bd911426db628d3c4d8994726'
-  LANG='C'
-  LANGUAGE='en_US:en'
-  LC_ALL='C'
-  MAIL='/var/mail/root'
-  OPTIND='1'
-  PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games'
-  PBCURRENTCOMMANDLINEOPERATION='build'
-  PBUILDER_OPERATION='build'
-  PBUILDER_PKGDATADIR='/usr/share/pbuilder'
-  PBUILDER_PKGLIBDIR='/usr/lib/pbuilder'
-  PBUILDER_SYSCONFDIR='/etc'
-  PPID='3266645'
-  PS1='# '
-  PS2='> '
+  INVOCATION_ID=07b1f5f6d8754db7be3aaaed285a3b1f
+  LANG=C
+  LANGUAGE=et_EE:et
+  LC_ALL=C
+  MACHTYPE=x86_64-pc-linux-gnu
+  MAIL=/var/mail/root
+  OPTERR=1
+  OPTIND=1
+  OSTYPE=linux-gnu
+  PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path
+  PBCURRENTCOMMANDLINEOPERATION=build
+  PBUILDER_OPERATION=build
+  PBUILDER_PKGDATADIR=/usr/share/pbuilder
+  PBUILDER_PKGLIBDIR=/usr/lib/pbuilder
+  PBUILDER_SYSCONFDIR=/etc
+  PIPESTATUS=([0]="0")
+  POSIXLY_CORRECT=y
+  PPID=181475
   PS4='+ '
-  PWD='/'
-  SHELL='/bin/bash'
-  SHLVL='2'
-  SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.YFYCrvgs/pbuilderrc_PUeX --distribution trixie --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/trixie-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.YFYCrvgs/b1 --logfile b1/build.log efitools_1.9.2-3.5.dsc'
-  SUDO_GID='110'
-  SUDO_UID='105'
-  SUDO_USER='jenkins'
-  TERM='unknown'
-  TZ='/usr/share/zoneinfo/Etc/GMT+12'
-  USER='root'
-  _='/usr/bin/systemd-run'
-  http_proxy='http://46.16.76.132:3128'
+  PWD=/
+  SHELL=/bin/bash
+  SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix
+  SHLVL=3
+  SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.YFYCrvgs/pbuilderrc_lwhk --distribution trixie --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/trixie-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.YFYCrvgs/b2 --logfile b2/build.log efitools_1.9.2-3.5.dsc'
+  SUDO_GID=110
+  SUDO_UID=105
+  SUDO_USER=jenkins
+  TERM=unknown
+  TZ=/usr/share/zoneinfo/Etc/GMT-14
+  UID=0
+  USER=root
+  _='I: set'
+  http_proxy=http://213.165.73.152:3128
 I: uname -a
-  Linux ionos1-amd64 6.1.0-32-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.129-1 (2025-03-06) x86_64 GNU/Linux
+  Linux i-capture-the-hostname 6.12.12+bpo-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.12-1~bpo12+1 (2025-02-23) x86_64 GNU/Linux
 I: ls -l /bin
-  lrwxrwxrwx 1 root root 7 Mar  4 11:20 /bin -> usr/bin
-I: user script /srv/workspace/pbuilder/3266645/tmp/hooks/D02_print_environment finished
+  lrwxrwxrwx 1 root root 7 Mar  4  2025 /bin -> usr/bin
+I: user script /srv/workspace/pbuilder/181475/tmp/hooks/D02_print_environment finished
  -> Attempting to satisfy build-dependencies
  -> Creating pbuilder-satisfydepends-dummy package
 Package: pbuilder-satisfydepends-dummy
@@ -330,7 +362,11 @@
 fakeroot is already the newest version (1.37.1-1).
 0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
 I: Building the package
-I: Running cd /build/reproducible-path/efitools-1.9.2/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S  > ../efitools_1.9.2-3.5_source.changes
+I: user script /srv/workspace/pbuilder/181475/tmp/hooks/A99_set_merged_usr starting
+Not re-configuring usrmerge for trixie
+I: user script /srv/workspace/pbuilder/181475/tmp/hooks/A99_set_merged_usr finished
+hostname: Name or service not known
+I: Running cd /build/reproducible-path/efitools-1.9.2/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S  > ../efitools_1.9.2-3.5_source.changes
 dpkg-buildpackage: info: source package efitools
 dpkg-buildpackage: info: source version 1.9.2-3.5
 dpkg-buildpackage: info: source distribution unstable
@@ -340,7 +376,7 @@
  debian/rules clean
 dh clean
    dh_auto_clean
-	make -j20 clean
+	make -j42 clean
 make[1]: Entering directory '/build/reproducible-path/efitools-1.9.2'
 rm -f PK.* KEK.* DB.* HelloWorld.efi LockDown.efi Loader.efi ReadVars.efi UpdateVars.efi KeyTool.efi HashTool.efi SetNull.efi ShimReplace.efi HelloWorld-signed.efi LockDown-signed.efi Loader-signed.efi ReadVars-signed.efi UpdateVars-signed.efi KeyTool-signed.efi HashTool-signed.efi SetNull-signed.efi ShimReplace-signed.efi cert-to-efi-sig-list sig-list-to-certs sign-efi-sig-list hash-to-efi-sig-list efi-readvar efi-updatevar cert-to-efi-hash-list flash-var *.o *.so
 rm -f noPK.*
@@ -380,7 +416,7 @@
    dh_autoreconf
    dh_auto_configure
    dh_auto_build
-	make -j20 "INSTALL=install --strip-program=true"
+	make -j42 "INSTALL=install --strip-program=true"
 make[1]: Entering directory '/build/reproducible-path/efitools-1.9.2'
 make -C lib lib-efi.a
 make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib'
@@ -388,44 +424,48 @@
 openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB/" -keyout DB.key -out DB.crt -days 3650 -nodes -sha256
 cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c simple_file.c -o simple_file.efi.o
 openssl req -new -x509 -newkey rsa:2048 -subj "/CN=PK/" -keyout PK.key -out PK.crt -days 3650 -nodes -sha256
-.......+....+...+......+.....+++++++++++++++++++++++++++++++++++++++*......+.....+...............+...+....+.....+.+..+.+...............+++++++++++++++++++++++++++++++++++++++*.+.........................+...+......+...............+.........+..+.......+.....+.+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pecoff.c -o pecoff.efi.o
-.....+.+.....+...+............+.+..+..................+.......+............+...+..+......+...+.+........+......+.......+..+.+.............++..+.......+..+...+++++++++++++++++++++++++++++++.+.++++++++*.....+....+...+..+.+..+..........+..+.+............+...++++++++++++++++.+..+..+.++..+..+..+++++++++++++++++*..........+......+.....+...+.+.+..............+...+.......+...........++....++cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-sig-list.c -o cert-to-efi-sig-list.o
-+...++.........++
-........+.+..+.......+...++++++.+..++..+++++++++++++++++++++++++++++++*.....+...........+...+....+...+...+.........+.........++..+.............+..+.......+...+...+.....+...+......+++++++++++++++++++++++.+..++++++++++++++++*......+.......+...+...+..........+..+..+....+.+...............+.....+...........................+...+........++...+.....+.......................+.+..........+...+.............+.+.....+.........+.........+.........+......+.....++cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c guid.c -o guid.efi.o
-...................++.....+++......++
-......+.+.........+......+....................+..........+...+..+make -C lib lib.a
+........+..+....+.........+..+....+..+...+++++++++++++++++++++++++++++++++++++++*..+..+...+.+......+........+......+....+.....+.........+.+......+..............+.........+..........+.....+++++++++++++++++++++++++++++++++++++++*...+......+............+.+..+........................+...............+...+.+............+..............+....+..+...+.......+..+...+....+.....++++++
+........+....+...............+.....+.+.....+.+......+...+.................+.......+..+.........+....+.....+...+....+.........+..+....+...+...+..+...+...+......+.........+......+.+.........+...+++++++++++++++++++++++++++++++++++++++*........+...+....+..+.+....cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pecoff.c -o pecoff.efi.o
+.............+.......+...+........+...+..........+++++++++++++++++++++++++++++++++++++++*.....+.....................+.+.....+...+.+.........+...+..+...+...+....+...........................+.+.+..+...+...............+......++...+++++++++++.+..+++++++++++++++...+....+.....+.+++++++++++*....+..+......++.....+....+.....+......+.+++...+...+....+++++++++++++++..+++++++++++++++.+++++++*..+..+.............++...............+...+...........++cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-sig-list.c -o cert-to-efi-sig-list.o
+..++..............++.....+................+........+.........+....+......+.+.....++.....+...............+..........+.+......+.....++......++...........+.+..............+....+................+..+...++.........++.....+...+.............++.......+..+.......+...+.....+..+..........+..+.......+............+...+.........+............++..........++........+..+.........++.....+..+.......+...+..............++............++...+++...................++.....+++
+...+.+......+...........+...+......+...+......+.......+...+-----
+.........+.................+......+..........+..+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c guid.c -o guid.efi.o
+......+....+............+......+make -C lib lib.a
+...+.........+............+...+...........+.......+..+...+....+.....+..........+...+...+..............+....+.....+.+...........+...+......+..........+...+.................+....+..+.............+..+............+.......+......+..+.+............+..+.......+.....+................+........+..........+...........+....+......+......+..+.+......+...+..+...+.+...............+..+...+make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib'
+...............+....+........+.......+...+..+...+.......+..+....+..+....+..............+......+...............+....+.........+.................+....+..+.........+.+..+.......+.....+...+.+............+..+.+.........+...+........+.........++++++
+..+.....+.+...+......+......+..+.+.....+......+++++++++++++++++++++++++++++++++++++++*..+............+.+........+++++++++++++++++++++++++++++++++++++++*....+..+.........+...+...+.......+...+.....+..........+........+..........+..+...+....+..+.........+......+....+...........+.+..+..........+......+......+........+...+....+...+..+.+...+.....+.+...........+.........+......+..........+.....++++openssl req -new -x509 -newkey rsa:2048 -subj "/CN=KEK/" -keyout KEK.key -out KEK.crt -days 3650 -nodes -sha256
+++
 -----
-.............+......+......+..+...+.........+...+.....................+.+.....+..........+...+......+..+.......+..+...+...+............+.+............+.....+...+.......+.........+..............+.+...+.....+......+.+openssl req -new -x509 -newkey rsa:2048 -subj "/CN=KEK/" -keyout KEK.key -out KEK.crt -days 3650 -nodes -sha256
-...+make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib'
-........+...+.......+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c sha256.c -o sha256.efi.o
-.....+............+.+......+......+..+.+...........+.+...+.....+......+...+...+.......+...+............+....................+...+....+.....+....+.....+....+......+......+........+......++++++
-..+...+.+......+...+........+++++++++++++++++++++++++++++++++++++++*..+.....+......+.+...+.....+.........+......+.+.........+.....+......+......+.......+.....+...+++++++++++++++++++++++++++++++++++++++*......+..............+.......++++++++++.++++++++++++++++++++++++++++++*..+..........+........+.+......+..+........+...+....+...+........+.+......+........+......+.+..+............+...+.+..............+..........+......+.....++.++++++++++++++++++++++++++++++++++++++*.........++......++cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sign-efi-sig-list.c -o sign-efi-sig-list.o
-.+............+........+...+.+.........+.....+...+.+........+..+.+...........................+.....+..........++....+......+.....+..+.......+...+..+...............+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c console.c -o console.efi.o
-...+.......+....+............+...+.....+..+...+..........+.+...+......+...+...+.....+............+.............+.....+...........+........................+.+.......+.....+..+.......+.......+.................+......+....+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c simple_file.c -o simple_file.o
-...+.....+.........+......+...+....+...+.................+.........+..........+..+..+....+...+.....+...+.......+.........+..+......+............+......+...+.+......+..+............+.....................+...+.+......+.......++................++........+..+..+......+.+.......+.....+........+.........+........................+.+...+..+...............+......................+......+......+......cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c Loader.c -o Loader.o
-+.....+.+...++.++.....++...++.......++
-......+........+.+...+.....+...+...+....+-----
-..+......+.......+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c execute.c -o execute.efi.o
-..+...+..........+.....+.......+........+.+.....+..........+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pecoff.c -o pecoff.o
-.....++++++
-..+.......+...............+...+...+..+.......+...........+.+...+...........+.+.....+.+..+.......+.........+..............+++++++++++++++++++++++++++++++++++++++*.....+.....+....+..+...+...+++++++++++++++++++++++++++++++++++++++*.+...+...+...+......+.+.....+............................+.....+.........+...+make -C lib/asn1 libasn1-efi.a
-.......+...........+......+.+.................+..........+..+......+...........................+...+....+...........+.......+.....+.......+......+........+.......+..+...+....+...+..+.+.....+.........+..................+.+..+...+.........+.+..............+.+.....+......+.+make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib/asn1'
-.........+......+.....+.............+..+..........+...+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c guid.c -o guid.o
-......+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c configtable.c -o configtable.efi.o
-..............+.+...+...+..+.+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ReadVars.c -o ReadVars.o
-..+.........+...+................+..+....+...+..+......+...+....+..+.........................+...........+.......+...+..+..........+..+.........+......+..........+...+..+.............+......+.....................+...+..+....+..+....+...+...+..+...+............+.+...........+....+.....+.In file included from pecoff.c:69:
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c sha256.c -o sha256.efi.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c simple_file.c -o simple_file.o
+...+......+++++++++++++++++++++++++++++++++++++++*...+..+++++++++++++++++++++++++++++++++++++++*...........+.....+.+.....+++cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sign-efi-sig-list.c -o sign-efi-sig-list.o
++++
+....+......+.+.........+++++++++++++++++++++++++++++++++++++++*..+....+..+.+..+.......+++++++++++++++++++++++++++++++++++++++*.+..+....+........+.......+.....+..........+.....+.........+....+........+....+...+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c console.c -o console.efi.o
+......+..+.......+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pecoff.c -o pecoff.o
+..+.+..+.+..+.............+.........+...+..+..............................+......+.+......+..............+......+...+..........+......+.....+...+.+......+...........+...+.......+.........+...........+....+...+..+.+.....+...+....+........+...+.......+..............+.........+.+...............+......+.........+........+.+..+..................+.+.....................+..+...+.........+.........+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c Loader.c -o Loader.o
+.+...+........+.......+..+...............+...+..........+.....+............+.+...+...........+.+...+...........+...+......+....+......+..+.cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c execute.c -o execute.efi.o
+......+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c guid.c -o guid.o
+...+........+.+.........+..+....+...+..+.+..+...+.......+...+............+.....+.+...........++++++
+In file included from pecoff.c:69:
 pecoff.c: In function 'pecoff_relocate':
-+/build/reproducible-path/efitools-1.9.2/include/buildefi.h:8:27: warning: too many arguments for format [-Wformat-extra-args]
+/build/reproducible-path/efitools-1.9.2/include/buildefi.h:8:27: warning: too many arguments for format [-Wformat-extra-args]
     8 | #define Print(...) printf("%ls", __VA_ARGS__)
       |                           ^~~~~
 pecoff.c:197:17: note: in expansion of macro 'Print'
   197 |                 Print(L"Reloc table overflows binary %d %d\n",
       |                 ^~~~~
-........+...+.............+..............+............+....+.........+...+..+.......+...............+......+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sha256.c -o sha256.o
-...+..+...+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1.c -o asn1.efi.o
-.+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shell.c -o shell.efi.o
-..............+.......+.....+.......+............+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c UpdateVars.c -o UpdateVars.o
-.......................+.+.........+..+....+.....+.........+.+..+...+......+...+.......+...+..+.+.....+.......+.....+...+....+.....+....+......+......+.....+...+.......+..+......+..........+.....+...............+......+....+..............+.+ReadVars.c: In function 'efi_main':
+make -C lib/asn1 libasn1-efi.a
+-----
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c configtable.c -o configtable.efi.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sha256.c -o sha256.o
+make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib/asn1'
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ReadVars.c -o ReadVars.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c console.c -o console.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shell.c -o shell.efi.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1.c -o asn1.efi.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c UpdateVars.c -o UpdateVars.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c execute.c -o execute.o
+ReadVars.c: In function 'efi_main':
 ReadVars.c:177:73: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=]
   177 |                         Print(L"Variable %s has no entries\n", variables[i]);
       |                                                                         ^
@@ -438,13 +478,13 @@
 ReadVars.c:112:41: note: unnamed temporary defined here
   112 |                 variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL};
       |                                         ^
-...ReadVars.c:184:61: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=]
+ReadVars.c:184:61: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=]
   184 |                         parse_db(data, len, image, variables[i], save_keys);
       |                                                             ^
-......ReadVars.c:112:41: note: unnamed temporary defined here
+ReadVars.c:112:41: note: unnamed temporary defined here
   112 |                 variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL};
       |                                         ^
-+ReadVars.c:182:61: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=]
+ReadVars.c:182:61: warning: dangling pointer 'variables' to an unnamed temporary may be used [-Wdangling-pointer=]
   182 |                         parse_db(data, len, image, variables[i], save_keys);
       |                                                             ^
 ReadVars.c:112:41: note: unnamed temporary defined here
@@ -456,12 +496,18 @@
 ReadVars.c:112:41: note: unnamed temporary defined here
   112 |                 variables = (CHAR16 *[]){ L"PK", L"KEK", L"db", L"dbx", L"dbt", L"MokList" , NULL};
       |                                         ^
-..+.............+........+....+.....+.........+.+......+...+.....+....+.....+...+...............+.......+...+...+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c console.c -o console.o
-.........+..+...+......+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c KeyTool.c -o KeyTool.o
-.........+.+..............cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c security_policy.c -o security_policy.efi.o
-+.......+.....+.+.........+.....+...+...+....++++++
+In file included from sha256.c:35:
+sha256.c: In function 'sha256_get_pecoff_digest_mem':
+/build/reproducible-path/efitools-1.9.2/include/buildefi.h:8:27: warning: too many arguments for format [-Wformat-extra-args]
+    8 | #define Print(...) printf("%ls", __VA_ARGS__)
+      |                           ^~~~~
+sha256.c:360:17: note: in expansion of macro 'Print'
+  360 |                 Print(L"Invalid Data Size %d bytes too small\n", DataSize + context.SecDir->Size - sum_of_bytes);
+      |                 ^~~~~
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c security_policy.c -o security_policy.efi.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c KeyTool.c -o KeyTool.o
 cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c asn1_parser.c -o asn1_parser.efi.o
------
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c configtable.c -o configtable.o
 In file included from asn1.c:18:
 chunk.h: In function 'chunk_equals':
 chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign]
@@ -495,18 +541,10 @@
 UpdateVars.c:24:49: warning: variable 'owner_guid' set but not used [-Wunused-but-set-variable]
    24 |         CHAR16 **ARGV, *var, *name, *progname, *owner_guid;
       |                                                 ^~~~~~~~~~
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c execute.c -o execute.o
-In file included from sha256.c:35:
-sha256.c: In function 'sha256_get_pecoff_digest_mem':
-/build/reproducible-path/efitools-1.9.2/include/buildefi.h:8:27: warning: too many arguments for format [-Wformat-extra-args]
-    8 | #define Print(...) printf("%ls", __VA_ARGS__)
-      |                           ^~~~~
-sha256.c:360:17: note: in expansion of macro 'Print'
-  360 |                 Print(L"Invalid Data Size %d bytes too small\n", DataSize + context.SecDir->Size - sum_of_bytes);
-      |                 ^~~~~
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shim_protocol.c -o shim_protocol.efi.o
 cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c HashTool.c -o HashTool.o
 cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c enumerator.c -o enumerator.efi.o
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c shim_protocol.c -o shim_protocol.efi.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c shell.c -o shell.o
 In file included from asn1_parser.c:18:
 chunk.h: In function 'chunk_equals':
 chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign]
@@ -540,10 +578,10 @@
 asn1_parser.c:82:15: warning: variable 'level' set but not used [-Wunused-but-set-variable]
    82 |         u_int level;
       |               ^~~~~
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c SetNull.c -o SetNull.o
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c configtable.c -o configtable.o
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c chunk.c -o chunk.efi.o
 cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c pkcs7verify.c -o pkcs7verify.efi.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c chunk.c -o chunk.efi.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c SetNull.c -o SetNull.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c security_policy.c -o security_policy.o
 HashTool.c: In function 'efi_main':
 HashTool.c:187:25: warning: variable 'setup_mode_arg' set but not used [-Wunused-but-set-variable]
   187 |                         setup_mode_arg = 0, keytool = NOSEL;
@@ -551,10 +589,10 @@
 HashTool.c:185:28: warning: variable 'setup_mode' set but not used [-Wunused-but-set-variable]
   185 |                 int c = 0, setup_mode = NOSEL, uefi_reboot = NOSEL,
       |                            ^~~~~~~~~~
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ShimReplace.c -o ShimReplace.o
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c shell.c -o shell.o
 cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c oid.c -o oid.efi.o
 cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c variables.c -o variables.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c ShimReplace.c -o ShimReplace.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c shim_protocol.c -o shim_protocol.o
 In file included from chunk.c:18:
 chunk.h: In function 'chunk_equals':
 chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign]
@@ -605,8 +643,6 @@
       |                                  ^
 /usr/include/efi/efilib.h:414:24: note: expected 'const CHAR8 *' {aka 'const char *'} but argument is of type 'u_char *' {aka 'unsigned char *'}
   414 |     IN CONST CHAR8    *s2,
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sig-list-to-certs.c -o sig-list-to-certs.o
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c security_policy.c -o security_policy.o
 cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c identification.c -o identification.efi.o
 oid.c:13:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
    13 |  {0x02,                         7, 1,  0, "ITU-T Administration"      }, /*   0 */
@@ -851,6 +887,7 @@
 oid.c:73:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
    73 |  {      0x00,                   0, 0,  3, "anyExtendedKeyUsage"       }, /*  60 */
       |                                           ^~~~~~~~~~~~~~~~~~~~~
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c sig-list-to-certs.c -o sig-list-to-certs.o
 oid.c:73:43: note: (near initialization for 'oid_names[60].name')
 oid.c:74:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
    74 |  {    0x2E,                    62, 0,  2, "freshestCRL"               }, /*  61 */
@@ -996,24 +1033,10 @@
   109 |  {                0x0B,        97, 0,  8, "sha256WithRSAEncryption"   }, /*  96 */
       |                                           ^~~~~~~~~~~~~~~~~~~~~~~~~
 oid.c:109:43: note: (near initialization for 'oid_names[96].name')
-ShimReplace.c: In function 'efi_main':
-ShimReplace.c:51:37: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers]
-   51 |         efi_status = execute(image, loader);
-      |                                     ^~~~~~
-In file included from ShimReplace.c:17:
-/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'}
-    5 | execute(EFI_HANDLE image, CHAR16 *name);
-      |                           ~~~~~~~~^~~~
 oid.c:110:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
   110 |  {                0x0C,        98, 0,  8, "sha384WithRSAEncryption"   }, /*  97 */
       |                                           ^~~~~~~~~~~~~~~~~~~~~~~~~
 oid.c:110:43: note: (near initialization for 'oid_names[97].name')
-ShimReplace.c:57:37: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers]
-   57 |         efi_status = execute(image, fallback);
-      |                                     ^~~~~~~~
-/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'}
-    5 | execute(EFI_HANDLE image, CHAR16 *name);
-      |                           ~~~~~~~~^~~~
 oid.c:111:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
   111 |  {                0x0D,        99, 0,  8, "sha512WithRSAEncryption"   }, /*  98 */
       |                                           ^~~~~~~~~~~~~~~~~~~~~~~~~
@@ -1070,6 +1093,7 @@
   124 |  {                0x06,         0, 0,  8, "encryptedData"             }, /* 111 */
       |                                           ^~~~~~~~~~~~~~~
 oid.c:124:43: note: (near initialization for 'oid_names[111].name')
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pkcs7verify.c -o pkcs7verify.o
 oid.c:125:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
   125 |  {              0x09,           0, 1,  7, "PKCS-9"                    }, /* 112 */
       |                                           ^~~~~~~~
@@ -1206,7 +1230,6 @@
   158 |  {              0x0C,         146, 0,  7, "c2tnb239v2"                }, /* 145 */
       |                                           ^~~~~~~~~~~~
 oid.c:158:43: note: (near initialization for 'oid_names[145].name')
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c hash-to-efi-sig-list.c -o hash-to-efi-sig-list.o
 oid.c:159:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
   159 |  {              0x0D,         147, 0,  7, "c2tnb239v3"                }, /* 146 */
       |                                           ^~~~~~~~~~~~
@@ -1283,10 +1306,24 @@
   177 |  {            0x03,             0, 1,  6, "ecdsa-with-Specified"      }, /* 164 */
       |                                           ^~~~~~~~~~~~~~~~~~~~~~
 oid.c:177:43: note: (near initialization for 'oid_names[164].name')
+ShimReplace.c: In function 'efi_main':
+ShimReplace.c:51:37: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers]
+   51 |         efi_status = execute(image, loader);
+      |                                     ^~~~~~
+In file included from ShimReplace.c:17:
+/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'}
+    5 | execute(EFI_HANDLE image, CHAR16 *name);
+      |                           ~~~~~~~~^~~~
 oid.c:178:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
   178 |  {              0x01,         166, 0,  7, "ecdsa-with-SHA224"         }, /* 165 */
       |                                           ^~~~~~~~~~~~~~~~~~~
 oid.c:178:43: note: (near initialization for 'oid_names[165].name')
+ShimReplace.c:57:37: warning: passing argument 2 of 'execute' discards 'const' qualifier from pointer target type [-Wdiscarded-qualifiers]
+   57 |         efi_status = execute(image, fallback);
+      |                                     ^~~~~~~~
+/build/reproducible-path/efitools-1.9.2/include/execute.h:5:35: note: expected 'CHAR16 *' {aka 'short unsigned int *'} but argument is of type 'const CHAR16 *' {aka 'const short unsigned int *'}
+    5 | execute(EFI_HANDLE image, CHAR16 *name);
+      |                           ~~~~~~~~^~~~
 oid.c:179:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
   179 |  {              0x02,         167, 0,  7, "ecdsa-with-SHA256"         }, /* 166 */
       |                                           ^~~~~~~~~~~~~~~~~~~
@@ -1495,7 +1532,6 @@
   230 |  {              0x01,         218, 0,  7, "authenticationInfo"        }, /* 217 */
       |                                           ^~~~~~~~~~~~~~~~~~~~
 oid.c:230:43: note: (near initialization for 'oid_names[217].name')
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c shim_protocol.c -o shim_protocol.o
 oid.c:231:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
   231 |  {              0x02,         219, 0,  7, "accessIdentity"            }, /* 218 */
       |                                           ^~~~~~~~~~~~~~~~
@@ -1568,7 +1604,6 @@
   248 |  {            0x02,             0, 1,  6, "certificate"               }, /* 235 */
       |                                           ^~~~~~~~~~~~~
 oid.c:248:43: note: (near initialization for 'oid_names[235].name')
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c x509.c -o x509.efi.o
 oid.c:249:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
   249 |  {              0x02,           0, 0,  7, "iKEIntermediate"           }, /* 236 */
       |                                           ^~~~~~~~~~~~~~~~~
@@ -1633,6 +1668,7 @@
   264 |  {          0x01,             252, 0,  5, "ecSignWithsha1"            }, /* 251 */
       |                                           ^~~~~~~~~~~~~~~~
 oid.c:264:43: note: (near initialization for 'oid_names[251].name')
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c hash-to-efi-sig-list.c -o hash-to-efi-sig-list.o
 oid.c:265:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
   265 |  {          0x02,             253, 0,  5, "ecSignWithripemd160"       }, /* 252 */
       |                                           ^~~~~~~~~~~~~~~~~~~~~
@@ -1677,6 +1713,7 @@
   275 |  {            0x03,           263, 0,  6, "curve"                     }, /* 262 */
       |                                           ^~~~~~~
 oid.c:275:43: note: (near initialization for 'oid_names[262].name')
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c kernel_efivars.c -o kernel_efivars.o
 oid.c:276:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
   276 |  {            0x04,           270, 1,  6, "signatures"                }, /* 263 */
       |                                           ^~~~~~~~~~~~
@@ -2105,6 +2142,7 @@
   382 |  {0x67,                         0, 1,  0, ""                          }, /* 369 */
       |                                           ^~
 oid.c:382:43: note: (near initialization for 'oid_names[369].name')
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-readvar.c -o efi-readvar.o
 oid.c:383:43: warning: pointer targets in initialization of 'const unsigned char *' from 'char *' differ in signedness [-Wpointer-sign]
   383 |  {  0x81,                       0, 1,  1, ""                          }, /* 370 */
       |                                           ^~
@@ -2133,6 +2171,9 @@
   389 |  {        0x0F,                 0, 0,  4, "tcg-at-tpmIdLabel"         }  /* 376 */
       |                                           ^~~~~~~~~~~~~~~~~~~
 oid.c:389:43: note: (near initialization for 'oid_names[376].name')
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c openssl_sign.c -o openssl_sign.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -fno-toplevel-reorder -DBUILD_EFI -c x509.c -o x509.efi.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-updatevar.c -o efi-updatevar.o
 In file included from identification.c:18:
 chunk.h: In function 'chunk_equals':
 chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign]
@@ -2282,8 +2323,17 @@
 identification.c:33:24: warning: 'x501rdns' defined but not used [-Wunused-const-variable=]
    33 | static const x501rdn_t x501rdns[] = {
       |                        ^~~~~~~~
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-readvar.c -o efi-readvar.o
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c pkcs7verify.c -o pkcs7verify.o
+hash-to-efi-sig-list.c: In function 'main':
+hash-to-efi-sig-list.c:96:60: warning: format '%d' expects argument of type 'int', but argument 3 has type 'EFI_STATUS' {aka 'long unsigned int'} [-Wformat=]
+   96 |                         printf("Failed to get hash of %s: %d\n", argv[i+1],
+      |                                                           ~^
+      |                                                            |
+      |                                                            int
+      |                                                           %ld
+   97 |                                status);
+      |                                ~~~~~~                       
+      |                                |
+      |                                EFI_STATUS {aka long unsigned int}
 In file included from x509.c:1:
 chunk.h: In function 'chunk_equals':
 chunk.h:139:50: warning: pointer targets in passing argument 1 of 'strncmpa' differ in signedness [-Wpointer-sign]
@@ -2422,43 +2472,8 @@
    35 |         { 0, "exit",                                    ASN1_EOC,                       ASN1_EXIT                       }
       |              ^~~~~~
 x509.c:35:14: note: (near initialization for 'x509_certObjects[26].name')
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c efi-updatevar.c -o efi-updatevar.o
-hash-to-efi-sig-list.c: In function 'main':
-hash-to-efi-sig-list.c:96:60: warning: format '%d' expects argument of type 'int', but argument 3 has type 'EFI_STATUS' {aka 'long unsigned int'} [-Wformat=]
-   96 |                         printf("Failed to get hash of %s: %d\n", argv[i+1],
-      |                                                           ~^
-      |                                                            |
-      |                                                            int
-      |                                                           %ld
-   97 |                                status);
-      |                                ~~~~~~                       
-      |                                |
-      |                                EFI_STATUS {aka long unsigned int}
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c kernel_efivars.c -o kernel_efivars.o
-ar rcv libasn1-efi.a asn1.efi.o asn1_parser.efi.o enumerator.efi.o chunk.efi.o oid.efi.o identification.efi.o x509.efi.o
 cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c cert-to-efi-hash-list.c -o cert-to-efi-hash-list.o
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c openssl_sign.c -o openssl_sign.o
-a - asn1.efi.o
-a - asn1_parser.efi.o
-a - enumerator.efi.o
-a - chunk.efi.o
-a - oid.efi.o
-a - identification.efi.o
-a - x509.efi.o
-make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib/asn1'
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c flash-var.c -o flash-var.o
-cert-to-efi-hash-list.c:9:9: warning: "_XOPEN_SOURCE" redefined
-    9 | #define _XOPEN_SOURCE
-      |         ^~~~~~~~~~~~~
-<command-line>: note: this is the location of the previous definition
-> noPK.esl
-openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB1/" -keyout DB1.key -out DB1.crt -days 3650 -nodes -sha256
-openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB2/" -keyout DB2.key -out DB2.crt -days 3650 -nodes -sha256
-......+..+...+....+......+...+..+...+.......+...+.........+..+....++++++flash-var.c: In function 'main':
-+++flash-var.c:185:9: warning: 'memset' offset [0, 56] is out of the bounds [0, 0] [-Warray-bounds=]
-  185 |         memset(vh, 0, sizeof(*vh));
-      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~
-++++++++++++++++++++++++++++++*....+.+..+...+.......+++++++++++++++++++++++++++++++++++++++*....+........+.+.....+.+.....+.+..............+...+.......+......+...+.................+.......+......+.........+...+..+.+.....+.......+..+......+..........+openssl_sign.c: In function 'read_engine_private_key':
+openssl_sign.c: In function 'read_engine_private_key':
 openssl_sign.c:118:9: warning: 'ENGINE_load_builtin_engines' is deprecated: Since OpenSSL 3.0 [-Wdeprecated-declarations]
   118 |         ENGINE_load_builtin_engines();
       |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~
@@ -2478,7 +2493,7 @@
 /usr/include/openssl/engine.h:620:27: note: declared here
   620 | OSSL_DEPRECATEDIN_3_0 int ENGINE_init(ENGINE *e);
       |                           ^~~~~~~~~~~
-..+openssl_sign.c:141:9: warning: 'ENGINE_load_private_key' is deprecated: Since OpenSSL 3.0 [-Wdeprecated-declarations]
+openssl_sign.c:141:9: warning: 'ENGINE_load_private_key' is deprecated: Since OpenSSL 3.0 [-Wdeprecated-declarations]
   141 |         pkey = ENGINE_load_private_key(e, keyfile, ui, NULL);
       |         ^~~~
 /usr/include/openssl/engine.h:638:11: note: declared here
@@ -2496,24 +2511,32 @@
 /usr/include/openssl/engine.h:493:27: note: declared here
   493 | OSSL_DEPRECATEDIN_3_0 int ENGINE_free(ENGINE *e);
       |                           ^~~~~~~~~~~
-...+.+......+...............+........+....+.......................+....++++++++++++++++++++++++...++++++++++++++++*..+..+....+..+++++++++++++++++.+++++++++++++++++++++++*.......+........+..............+...+...................+...+..+..........+.+......+........+.....+.+......++...++....++........++...++
-..+...............+..+......+.......+......+..+...+.+...+.....+.......++......+....+.....+....+............+.....+......+.......+.....+...+....+.........+.........+.....+.+.........++++.+..+..++++++++++++++++++++++++++++++++++*..+...+.....................+...++.+......+..................+...+..+...+....+++++++++++++++++++++.+.++++++++++++++++++*...+.........+..+.+......+...+.+......+...+...+.....+...+....+...........+............+.+..+...+...+.........+.......+...+..+........+...................++.........+.+..+...........+...............+.........+.+.............+...+.....+......+............+...+....+.....+..+...+...............+...+...+.......+.+.....+.....+.......+....+.............+....+........................+....+.....+.....+.....+.....++..++......++...++
-.....+.........+.+........+....+..........+.+........+..+......+...+++++++++++++++++++++++...+...++++++++++++++++*..+...+......+...+.....+.............+..+..+.....++++++++++++++++++++++++++++++++..+.+++++++*...+..+....+......+.....+...+...............+ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds SetNull.o -o SetNull.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
-....+....+.................+...+.+..+........+...............++.++.........++...+++
-..+..................+.......+..+...+.+..+....+-----
-.........+..+...+.+........+......+....+...+..+...............+...+....+......+..+.......+...+......+..+.......+..+...+................+.....+....+......+...........+....+...........+..........+...........+# check we have no undefined symbols
-...+nm -D SetNull.so | grep ' U ' && exit 1 || exit 0
-.+...+..+.........+....+.....+...............................+..+....+...+..+objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \
-	   -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \
-	   -j .reloc --target=efi-app-x86_64 SetNull.so SetNull.efi
-.+........+.+.........+....................+.+...+..+....+..+...+.........+...+.......+......+.....+....+........+....+...+...........+......+...+..................+.......+......+.....+......+....+......+...........+..........+..++++++
------
-sbsign --key DB.key --cert DB.crt --output SetNull-signed.efi SetNull.efi
-warning: data remaining[35840 vs 45097]: gaps between PE/COFF sections?
-warning: data remaining[35840 vs 45104]: gaps between PE/COFF sections?
-Signing Unsigned original image
-ar rcv lib-efi.a simple_file.efi.o pecoff.efi.o guid.efi.o sha256.efi.o console.efi.o execute.efi.o configtable.efi.o shell.efi.o security_policy.efi.o shim_protocol.efi.o pkcs7verify.efi.o variables.o
-a - simple_file.efi.o
+cert-to-efi-hash-list.c:9:9: warning: "_XOPEN_SOURCE" redefined
+    9 | #define _XOPEN_SOURCE
+      |         ^~~~~~~~~~~~~
+<command-line>: note: this is the location of the previous definition
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/x86_64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DEFI_FUNCTION_WRAPPER -mno-red-zone -DCONFIG_x86_64 -c flash-var.c -o flash-var.o
+ar rcv libasn1-efi.a asn1.efi.o asn1_parser.efi.o enumerator.efi.o chunk.efi.o oid.efi.o identification.efi.o x509.efi.o
+> noPK.esl
+a - asn1.efi.o
+a - asn1_parser.efi.o
+a - enumerator.efi.o
+a - chunk.efi.o
+a - oid.efi.o
+a - identification.efi.o
+a - x509.efi.o
+make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib/asn1'
+openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB1/" -keyout DB1.key -out DB1.crt -days 3650 -nodes -sha256
+openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB2/" -keyout DB2.key -out DB2.crt -days 3650 -nodes -sha256
+........+........+...+....+..+....+......+...+..+...+...+.......+...+..+......+...............++++flash-var.c: In function 'main':
++flash-var.c:185:9: warning: 'memset' offset [0, 56] is out of the bounds [0, 0] [-Warray-bounds=]
+  185 |         memset(vh, 0, sizeof(*vh));
+      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~
+++++++++++++++++++++++++++++++++++*.+++++++++++++++++++++++++++++++++++++++*....+..+....+.................+....+......+..+......+....+...+..+......+.......+...............+.........+......+.....+.......+......+...........+..........+...........+....+...++++++
+......+.....+.+..+.+++++++++++++++++++++++++++++++++++++++*.....+.....+++++++++++++++++++++++++++++++++++++++*.....+.+..............+...+..........+..+......+...................+...+.....+.+............+..+...+.........+..+....+.....+.+..+...+++++++++++++++.+.+.+++++++++++++++++++++++*....+...+.........+...+...++++++++++..+.+.++++++++++++++++++++++++++++*.+........+....+....+.........+...........++...............+......+..............+.+......+..+....+.........+...+....+..+........+...+.+......+.+..........++..........++.+......+......+..+........+.........+......+ar rcv lib-efi.a simple_file.efi.o pecoff.efi.o guid.efi.o sha256.efi.o console.efi.o execute.efi.o configtable.efi.o shell.efi.o security_policy.efi.o shim_protocol.efi.o pkcs7verify.efi.o variables.o
+...........+....+....+.+............+..........+......+.............++......+..+.+.........+.....+..+......+.......+....+...+......................+.........+.........+...+...+.......+.........+....+..+.......+....+.....+......+.+..............+..+.+........++.++............++..++
+................+.....+....+...+...............+...............+..+...+.+.....+......+....+..............-----
++......+....+...+..............+.+..+......................+...+...+..+.+..+...........................+...+.......+..+......+....+...+....................+.+..+....+........................+..+.......+..+.........+.......+a - simple_file.efi.o
 a - pecoff.efi.o
 a - guid.efi.o
 a - sha256.efi.o
@@ -2525,17 +2548,21 @@
 a - shim_protocol.efi.o
 a - pkcs7verify.efi.o
 a - variables.o
-make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib'
-ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds HelloWorld.o lib/lib-efi.a -o HelloWorld.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
+...+...........+.+..+...+....+..............+......+......ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds SetNull.o -o SetNull.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
+....+...........+...+.+......+..+++make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib'
++++
+.+..............+....+...+++++++++++++++++++++++++++++++++++++++*..+++++++++++++++++++++++++++++++++++++++*.+.........+....+.....................+.........+...+.....+.........+....+............+............+..+...+......+.+......+.....+.......+...+..+...+.......+...+.....+..........+...+......+...+......+......+........+......+....+..+.........+.+.....+....+..+....+.....+...+.......+.....+....++++++
+-----
 # check we have no undefined symbols
-nm -D HelloWorld.so | grep ' U ' && exit 1 || exit 0
-ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds Loader.o lib/lib-efi.a -o Loader.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
+nm -D SetNull.so | grep ' U ' && exit 1 || exit 0
+ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds ShimReplace.o lib/lib-efi.a -o ShimReplace.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
 # check we have no undefined symbols
-nm -D Loader.so | grep ' U ' && exit 1 || exit 0
-ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds ReadVars.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o ReadVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
+nm -D ShimReplace.so | grep ' U ' && exit 1 || exit 0
+ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds HelloWorld.o lib/lib-efi.a -o HelloWorld.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
 # check we have no undefined symbols
+nm -D HelloWorld.so | grep ' U ' && exit 1 || exit 0
 ar rcv lib.a simple_file.o pecoff.o guid.o sha256.o console.o execute.o configtable.o shell.o security_policy.o shim_protocol.o pkcs7verify.o kernel_efivars.o openssl_sign.o
-nm -D ReadVars.so | grep ' U ' && exit 1 || exit 0
+ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds Loader.o lib/lib-efi.a -o Loader.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
 a - simple_file.o
 a - pecoff.o
 a - guid.o
@@ -2549,27 +2576,51 @@
 a - pkcs7verify.o
 a - kernel_efivars.o
 a - openssl_sign.o
-ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds UpdateVars.o lib/lib-efi.a -o UpdateVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
 make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib'
 # check we have no undefined symbols
+nm -D Loader.so | grep ' U ' && exit 1 || exit 0
+ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds ReadVars.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o ReadVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
+# check we have no undefined symbols
+nm -D ReadVars.so | grep ' U ' && exit 1 || exit 0
+ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds UpdateVars.o lib/lib-efi.a -o UpdateVars.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
+# check we have no undefined symbols
 nm -D UpdateVars.so | grep ' U ' && exit 1 || exit 0
 ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds KeyTool.o lib/lib-efi.a lib/asn1/libasn1-efi.a -o KeyTool.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
 # check we have no undefined symbols
 nm -D KeyTool.so | grep ' U ' && exit 1 || exit 0
 ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds HashTool.o lib/lib-efi.a -o HashTool.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
+objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \
+	   -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \
+	   -j .reloc --target=efi-app-x86_64 SetNull.so SetNull.efi
 # check we have no undefined symbols
 nm -D HashTool.so | grep ' U ' && exit 1 || exit 0
-ld -nostdlib -shared -Bsymbolic /lib/crt0-efi-x86_64.o -L /lib -L /usr/lib -L /usr/lib64 -T elf_x86_64_efi.lds ShimReplace.o lib/lib-efi.a -o ShimReplace.so -lefi -lgnuefi /usr/lib/gcc/x86_64-linux-gnu/14/libgcc.a
+objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \
+	   -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \
+	   -j .reloc --target=efi-app-x86_64 ShimReplace.so ShimReplace.efi
 cc  -o sig-list-to-certs sig-list-to-certs.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto
-# check we have no undefined symbols
-nm -D ShimReplace.so | grep ' U ' && exit 1 || exit 0
 cc  -o hash-to-efi-sig-list hash-to-efi-sig-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a
 cc  -o efi-readvar efi-readvar.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto
 cc  -o efi-updatevar efi-updatevar.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto
 cc  -o cert-to-efi-hash-list cert-to-efi-hash-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a -lcrypto
 cc  -o flash-var flash-var.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wl,-z,relro lib/lib.a
+help2man --no-info -i doc/efi-readvar.1.in -o doc/efi-readvar.1 ./efi-readvar
+help2man --no-info -i doc/efi-updatevar.1.in -o doc/efi-updatevar.1 ./efi-updatevar
 help2man --no-info -i doc/hash-to-efi-sig-list.1.in -o doc/hash-to-efi-sig-list.1 ./hash-to-efi-sig-list
 help2man --no-info -i doc/sig-list-to-certs.1.in -o doc/sig-list-to-certs.1 ./sig-list-to-certs
+./cert-to-efi-hash-list PK.crt PK-hash-blacklist.esl
+./cert-to-efi-hash-list KEK.crt KEK-hash-blacklist.esl
+TimeOfRevocation is 0-0-0 00:00:00
+./cert-to-efi-hash-list DB.crt DB-hash-blacklist.esl
+TimeOfRevocation is 0-0-0 00:00:00
+./cert-to-efi-hash-list DB1.crt DB1-hash-blacklist.esl
+TimeOfRevocation is 0-0-0 00:00:00
+./cert-to-efi-hash-list DB2.crt DB2-hash-blacklist.esl
+TimeOfRevocation is 0-0-0 00:00:00
+./cert-to-efi-hash-list ms-uefi.crt ms-uefi-hash-blacklist.esl
+TimeOfRevocation is 0-0-0 00:00:00
+./cert-to-efi-hash-list ms-kek.crt ms-kek-hash-blacklist.esl
+TimeOfRevocation is 0-0-0 00:00:00
+TimeOfRevocation is 0-0-0 00:00:00
 objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \
 	   -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \
 	   -j .reloc --target=efi-app-x86_64 HelloWorld.so HelloWorld.efi
@@ -2590,45 +2641,109 @@
 objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \
 	   -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \
 	   -j .reloc --target=efi-app-x86_64 HashTool.so HashTool.efi
-objcopy -j .text -j .sdata -j .data -j .dynamic -j .dynsym \
-	   -j .rel -j .rela -j .rel.* -j .rela.* -j .rel* -j .rela* \
-	   -j .reloc --target=efi-app-x86_64 ShimReplace.so ShimReplace.efi
+sbsign --key DB.key --cert DB.crt --output SetNull-signed.efi SetNull.efi
+sbsign --key DB.key --cert DB.crt --output ShimReplace-signed.efi ShimReplace.efi
+warning: data remaining[35840 vs 45097]: gaps between PE/COFF sections?
+warning: data remaining[35840 vs 45104]: gaps between PE/COFF sections?
+Signing Unsigned original image
 help2man --no-info -i doc/cert-to-efi-hash-list.1.in -o doc/cert-to-efi-hash-list.1 ./cert-to-efi-hash-list
+warning: data remaining[78848 vs 91343]: gaps between PE/COFF sections?
+warning: data remaining[78848 vs 91344]: gaps between PE/COFF sections?
+Signing Unsigned original image
 help2man --no-info -i doc/cert-to-efi-sig-list.1.in -o doc/cert-to-efi-sig-list.1 ./cert-to-efi-sig-list
-help2man --no-info -i doc/efi-readvar.1.in -o doc/efi-readvar.1 ./efi-readvar
-help2man --no-info -i doc/efi-updatevar.1.in -o doc/efi-updatevar.1 ./efi-updatevar
 help2man --no-info -i doc/sign-efi-sig-list.1.in -o doc/sign-efi-sig-list.1 ./sign-efi-sig-list
-./sign-efi-sig-list -t "2025-03-19 05:18:31" -c PK.crt -k PK.key PK noPK.esl noPK.auth
+./sign-efi-sig-list -t "2026-04-21 11:42:52" -c PK.crt -k PK.key PK noPK.esl noPK.auth
 ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc DB1.crt DB1.esl
-Timestamp is 2025-3-19 05:18:31
+Timestamp is 2026-4-21 11:42:52
 Authentication Payload size 40
 Signature of size 1148
 Signature at: 40
 ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc DB2.crt DB2.esl
 ./cert-to-efi-sig-list -g 77FA9ABD-0359-4D32-BD60-28F4E78F784B ms-uefi.crt ms-uefi.esl
 ./cert-to-efi-sig-list -g 77FA9ABD-0359-4D32-BD60-28F4E78F784B ms-kek.crt ms-kek.esl
+./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB1.esl DB1-update.auth
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 853
+Signature of size 1151
+Signature at: 40
+./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB2.esl DB2-update.auth
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 853
+Signature of size 1151
+Signature at: 40
+./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-uefi.esl ms-uefi-update.auth
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 1640
+Signature of size 1151
+Signature at: 40
+./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-kek.esl ms-kek-update.auth
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 1600
+Signature of size 1151
+Signature at: 40
+./sign-efi-sig-list -a -c PK.crt -k PK.key db DB1.esl DB1-pkupdate.auth
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 853
+Signature of size 1148
+Signature at: 40
+./sign-efi-sig-list -a -c PK.crt -k PK.key db DB2.esl DB2-pkupdate.auth
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 853
+Signature of size 1148
+Signature at: 40
+./sign-efi-sig-list -a -c PK.crt -k PK.key db ms-uefi.esl ms-uefi-pkupdate.auth
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 1640
+Signature of size 1148
+Signature at: 40
+./sign-efi-sig-list -a -c PK.crt -k PK.key db ms-kek.esl ms-kek-pkupdate.auth
 ./cert-to-efi-sig-list PK.crt PK-blacklist.esl
 ./cert-to-efi-sig-list KEK.crt KEK-blacklist.esl
 ./cert-to-efi-sig-list DB.crt DB-blacklist.esl
 ./cert-to-efi-sig-list DB1.crt DB1-blacklist.esl
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 1600
+Signature of size 1148
+Signature at: 40
 ./cert-to-efi-sig-list DB2.crt DB2-blacklist.esl
 ./cert-to-efi-sig-list ms-uefi.crt ms-uefi-blacklist.esl
 ./cert-to-efi-sig-list ms-kek.crt ms-kek-blacklist.esl
-./cert-to-efi-hash-list PK.crt PK-hash-blacklist.esl
-./cert-to-efi-hash-list KEK.crt KEK-hash-blacklist.esl
-TimeOfRevocation is 0-0-0 00:00:00
-./cert-to-efi-hash-list DB.crt DB-hash-blacklist.esl
-TimeOfRevocation is 0-0-0 00:00:00
-./cert-to-efi-hash-list DB1.crt DB1-hash-blacklist.esl
-TimeOfRevocation is 0-0-0 00:00:00
-./cert-to-efi-hash-list DB2.crt DB2-hash-blacklist.esl
-TimeOfRevocation is 0-0-0 00:00:00
-./cert-to-efi-hash-list ms-uefi.crt ms-uefi-hash-blacklist.esl
-TimeOfRevocation is 0-0-0 00:00:00
-./cert-to-efi-hash-list ms-kek.crt ms-kek-hash-blacklist.esl
-TimeOfRevocation is 0-0-0 00:00:00
+./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx PK-hash-blacklist.esl PK-hash-blacklist.auth
+./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx KEK-hash-blacklist.esl KEK-hash-blacklist.auth
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 134
+Signature of size 1151
+Signature at: 40
+./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB-hash-blacklist.esl DB-hash-blacklist.auth
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 134
+Signature of size 1151
+Signature at: 40
+./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB1-hash-blacklist.esl DB1-hash-blacklist.auth
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 134
+Signature of size 1151
+Signature at: 40
+./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB2-hash-blacklist.esl DB2-hash-blacklist.auth
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 134
+Signature of size 1151
+Signature at: 40
+./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-uefi-hash-blacklist.esl ms-uefi-hash-blacklist.auth
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 134
+Signature of size 1151
+Signature at: 40
+./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-kek-hash-blacklist.esl ms-kek-hash-blacklist.auth
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 134
+Signature of size 1151
+Signature at: 40
 sbsign --key DB.key --cert DB.crt --output HelloWorld-signed.efi HelloWorld.efi
-TimeOfRevocation is 0-0-0 00:00:00
+Timestamp is 0-0-0 00:00:00
+Authentication Payload size 134
+Signature of size 1151
+Signature at: 40
 ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc PK.crt PK.esl
 warning: data remaining[41472 vs 51215]: gaps between PE/COFF sections?
 warning: data remaining[41472 vs 51216]: gaps between PE/COFF sections?
@@ -2652,30 +2767,26 @@
 warning: data remaining[108544 vs 121951]: gaps between PE/COFF sections?
 warning: data remaining[108544 vs 121952]: gaps between PE/COFF sections?
 Signing Unsigned original image
-sbsign --key DB.key --cert DB.crt --output ShimReplace-signed.efi ShimReplace.efi
 warning: data remaining[78336 vs 90430]: gaps between PE/COFF sections?
 warning: data remaining[78336 vs 90432]: gaps between PE/COFF sections?
 Signing Unsigned original image
-warning: data remaining[78848 vs 91343]: gaps between PE/COFF sections?
-warning: data remaining[78848 vs 91344]: gaps between PE/COFF sections?
-Signing Unsigned original image
 ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB1.esl DB1.auth
-Timestamp is 2025-3-19 05:18:31
+Timestamp is 2026-4-21 11:42:53
 Authentication Payload size 853
 Signature of size 1151
 Signature at: 40
 ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB2.esl DB2.auth
-Timestamp is 2025-3-19 05:18:31
+Timestamp is 2026-4-21 11:42:53
 Authentication Payload size 853
 Signature of size 1151
 Signature at: 40
 ./sign-efi-sig-list -c KEK.crt -k KEK.key db ms-uefi.esl ms-uefi.auth
-Timestamp is 2025-3-19 05:18:31
+Timestamp is 2026-4-21 11:42:53
 Authentication Payload size 1640
 Signature of size 1151
 Signature at: 40
 ./sign-efi-sig-list -c KEK.crt -k KEK.key db ms-kek.esl ms-kek.auth
-Timestamp is 2025-3-19 05:18:31
+Timestamp is 2026-4-21 11:42:53
 Authentication Payload size 1600
 Signature of size 1151
 Signature at: 40
@@ -2694,26 +2805,6 @@
 Authentication Payload size 851
 Signature of size 1151
 Signature at: 40
-./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB1.esl DB1-update.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 853
-Signature of size 1151
-Signature at: 40
-./sign-efi-sig-list -a -c KEK.crt -k KEK.key db DB2.esl DB2-update.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 853
-Signature of size 1151
-Signature at: 40
-./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-uefi.esl ms-uefi-update.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 1640
-Signature of size 1151
-Signature at: 40
-./sign-efi-sig-list -a -c KEK.crt -k KEK.key db ms-kek.esl ms-kek-update.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 1600
-Signature of size 1151
-Signature at: 40
 ./sign-efi-sig-list -a -c PK.crt -k PK.key PK PK.esl PK-pkupdate.auth
 Timestamp is 0-0-0 00:00:00
 Authentication Payload size 851
@@ -2725,29 +2816,9 @@
 Signature of size 1148
 Signature at: 40
 ./sign-efi-sig-list -a -c PK.crt -k PK.key db DB.esl DB-pkupdate.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 851
-Signature of size 1148
-Signature at: 40
-./sign-efi-sig-list -a -c PK.crt -k PK.key db DB1.esl DB1-pkupdate.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 853
-Signature of size 1148
-Signature at: 40
-./sign-efi-sig-list -a -c PK.crt -k PK.key db DB2.esl DB2-pkupdate.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 853
-Signature of size 1148
-Signature at: 40
-./sign-efi-sig-list -a -c PK.crt -k PK.key db ms-uefi.esl ms-uefi-pkupdate.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 1640
-Signature of size 1148
-Signature at: 40
-./sign-efi-sig-list -a -c PK.crt -k PK.key db ms-kek.esl ms-kek-pkupdate.auth
 ./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx PK-blacklist.esl PK-blacklist.auth
 Timestamp is 0-0-0 00:00:00
-Authentication Payload size 1600
+Authentication Payload size 851
 Signature of size 1148
 Signature at: 40
 ./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx KEK-blacklist.esl KEK-blacklist.auth
@@ -2780,58 +2851,23 @@
 Authentication Payload size 1642
 Signature of size 1151
 Signature at: 40
-./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx PK-hash-blacklist.esl PK-hash-blacklist.auth
 Timestamp is 0-0-0 00:00:00
 Authentication Payload size 1602
 Signature of size 1151
 Signature at: 40
-./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx KEK-hash-blacklist.esl KEK-hash-blacklist.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 134
-Signature of size 1151
-Signature at: 40
-./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB-hash-blacklist.esl DB-hash-blacklist.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 134
-Signature of size 1151
-Signature at: 40
-./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB1-hash-blacklist.esl DB1-hash-blacklist.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 134
-Signature of size 1151
-Signature at: 40
-./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx DB2-hash-blacklist.esl DB2-hash-blacklist.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 134
-Signature of size 1151
-Signature at: 40
-./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-uefi-hash-blacklist.esl ms-uefi-hash-blacklist.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 134
-Signature of size 1151
-Signature at: 40
-./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx ms-kek-hash-blacklist.esl ms-kek-hash-blacklist.auth
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 134
-Signature of size 1151
-Signature at: 40
-Timestamp is 0-0-0 00:00:00
-Authentication Payload size 134
-Signature of size 1151
-Signature at: 40
 ./sign-efi-sig-list -c PK.crt -k PK.key PK PK.esl PK.auth
-Timestamp is 2025-3-19 05:18:33
+Timestamp is 2026-4-21 11:42:54
 Authentication Payload size 851
 Signature of size 1148
 Signature at: 40
 ./sign-efi-sig-list -c PK.crt -k PK.key KEK KEK.esl KEK.auth
-Timestamp is 2025-3-19 05:18:33
+Timestamp is 2026-4-21 11:42:54
 Authentication Payload size 855
 Signature of size 1148
 Signature at: 40
 ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB.esl DB.auth
 ./xxdi.pl PK.auth > PK.h
-Timestamp is 2025-3-19 05:18:33
+Timestamp is 2026-4-21 11:42:54
 Authentication Payload size 851
 Signature of size 1151
 Signature at: 40
@@ -2859,7 +2895,7 @@
 make[1]: Entering directory '/build/reproducible-path/efitools-1.9.2'
 dh_auto_install -- EFIDIR="debian/efitools/usr/lib/efitools/x86_64-linux-gnu"
 	install -m0755 -d /build/reproducible-path/efitools-1.9.2/debian/efitools
-	make -j20 install DESTDIR=/build/reproducible-path/efitools-1.9.2/debian/efitools AM_UPDATE_INFO_DIR=no "INSTALL=install --strip-program=true" EFIDIR=debian/efitools/usr/lib/efitools/x86_64-linux-gnu
+	make -j42 install DESTDIR=/build/reproducible-path/efitools-1.9.2/debian/efitools AM_UPDATE_INFO_DIR=no "INSTALL=install --strip-program=true" EFIDIR=debian/efitools/usr/lib/efitools/x86_64-linux-gnu
 make[2]: Entering directory '/build/reproducible-path/efitools-1.9.2'
 make -C lib lib-efi.a
 make -C lib lib.a
@@ -2868,9 +2904,9 @@
 make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib'
 make[3]: 'lib-efi.a' is up to date.
 make[3]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib'
-make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib/asn1'
 make[3]: 'lib.a' is up to date.
 make[3]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib'
+make[3]: Entering directory '/build/reproducible-path/efitools-1.9.2/lib/asn1'
 make[3]: 'libasn1-efi.a' is up to date.
 make[3]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib/asn1'
 install --strip-program=true -m 755 -d /build/reproducible-path/efitools-1.9.2/debian/efitools/usr/share/man/man1
@@ -2911,16 +2947,16 @@
 	man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1
 	man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1
 	man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/sign-efi-sig-list.1
-	mv debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1
-	chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1
 	mv debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1
 	chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1
 	mv debian/efitools/usr/share/man/man1/efi-readvar.1.dh-new debian/efitools/usr/share/man/man1/efi-readvar.1
 	chmod 0644 -- debian/efitools/usr/share/man/man1/efi-readvar.1
-	mv debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1
-	chmod 0644 -- debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1
 	mv debian/efitools/usr/share/man/man1/efi-updatevar.1.dh-new debian/efitools/usr/share/man/man1/efi-updatevar.1
 	chmod 0644 -- debian/efitools/usr/share/man/man1/efi-updatevar.1
+	mv debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1
+	chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1
+	mv debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1
+	chmod 0644 -- debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1
 	mv debian/efitools/usr/share/man/man1/sig-list-to-certs.1.dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1
 	chmod 0644 -- debian/efitools/usr/share/man/man1/sig-list-to-certs.1
 	mv debian/efitools/usr/share/man/man1/sign-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/sign-efi-sig-list.1
@@ -2948,31 +2984,36 @@
 	objcopy --compress-debug-sections debian/efitools/usr/lib/debug/.dwz/x86_64-linux-gnu/efitools.debug
 	chmod 0644 -- debian/efitools/usr/lib/debug/.dwz/x86_64-linux-gnu/efitools.debug
    dh_strip
-	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a2
-	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/flash-var debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a2/4bb2ca0f6df738a82afea26fd3fedd26573419.debug
-	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a2/4bb2ca0f6df738a82afea26fd3fedd26573419.debug
-	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/flash-var
-	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a2/4bb2ca0f6df738a82afea26fd3fedd26573419.debug debian/efitools/usr/bin/flash-var
-	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/82
-	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-updatevar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/82/4cd68e257b8d58b19f4f59106a25517fba5404.debug
-	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/82/4cd68e257b8d58b19f4f59106a25517fba5404.debug
-	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-updatevar
-	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/82/4cd68e257b8d58b19f4f59106a25517fba5404.debug debian/efitools/usr/bin/efi-updatevar
+	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/ef
+	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-readvar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/ef/9fbe6e555c8e9fbc6e9f26a109563f657a9602.debug
+	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/ef/9fbe6e555c8e9fbc6e9f26a109563f657a9602.debug
+	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-readvar
+	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/ef/9fbe6e555c8e9fbc6e9f26a109563f657a9602.debug debian/efitools/usr/bin/efi-readvar
+	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/b4
+	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/sig-list-to-certs debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/b4/9013166735dfc8927c945333188721524c8a32.debug
+	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/b4/9013166735dfc8927c945333188721524c8a32.debug
+	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/sig-list-to-certs
+	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/b4/9013166735dfc8927c945333188721524c8a32.debug debian/efitools/usr/bin/sig-list-to-certs
 	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/79
 	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/cert-to-efi-hash-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/79/f9163abb034e351dae7dfbeca5febdaf8a7748.debug
 	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/79/f9163abb034e351dae7dfbeca5febdaf8a7748.debug
 	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/cert-to-efi-hash-list
 	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/79/f9163abb034e351dae7dfbeca5febdaf8a7748.debug debian/efitools/usr/bin/cert-to-efi-hash-list
+	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/82
+	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-updatevar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/82/4cd68e257b8d58b19f4f59106a25517fba5404.debug
+	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/82/4cd68e257b8d58b19f4f59106a25517fba5404.debug
+	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-updatevar
+	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/82/4cd68e257b8d58b19f4f59106a25517fba5404.debug debian/efitools/usr/bin/efi-updatevar
 	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/56
 	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/hash-to-efi-sig-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/56/b8ff4a461d472908b0dbecbe1a4ae74ca4d885.debug
 	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/56/b8ff4a461d472908b0dbecbe1a4ae74ca4d885.debug
 	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/hash-to-efi-sig-list
 	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/56/b8ff4a461d472908b0dbecbe1a4ae74ca4d885.debug debian/efitools/usr/bin/hash-to-efi-sig-list
-	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/b4
-	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/sig-list-to-certs debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/b4/9013166735dfc8927c945333188721524c8a32.debug
-	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/b4/9013166735dfc8927c945333188721524c8a32.debug
-	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/sig-list-to-certs
-	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/b4/9013166735dfc8927c945333188721524c8a32.debug debian/efitools/usr/bin/sig-list-to-certs
+	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a2
+	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/flash-var debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a2/4bb2ca0f6df738a82afea26fd3fedd26573419.debug
+	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a2/4bb2ca0f6df738a82afea26fd3fedd26573419.debug
+	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/flash-var
+	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/a2/4bb2ca0f6df738a82afea26fd3fedd26573419.debug debian/efitools/usr/bin/flash-var
 	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/3c
 	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/sign-efi-sig-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/3c/ea03dacae171ebb853d1a15b29a81e3d391dda.debug
 	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/3c/ea03dacae171ebb853d1a15b29a81e3d391dda.debug
@@ -2983,11 +3024,6 @@
 	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1c/8fd583551379cbe865580a942622d78628db9c.debug
 	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/cert-to-efi-sig-list
 	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/1c/8fd583551379cbe865580a942622d78628db9c.debug debian/efitools/usr/bin/cert-to-efi-sig-list
-	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/ef
-	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-readvar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/ef/9fbe6e555c8e9fbc6e9f26a109563f657a9602.debug
-	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/ef/9fbe6e555c8e9fbc6e9f26a109563f657a9602.debug
-	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-readvar
-	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/ef/9fbe6e555c8e9fbc6e9f26a109563f657a9602.debug debian/efitools/usr/bin/efi-readvar
 	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.dwz
 	cp --reflink=auto -a debian/efitools/usr/lib/debug/.dwz/x86_64-linux-gnu debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.dwz
 	rm -fr debian/efitools/usr/lib/debug/.dwz
@@ -2999,7 +3035,7 @@
 	rm -f debian/efitools/DEBIAN/shlibs
    dh_shlibdeps
 	install -m0755 -d debian/efitools/DEBIAN
-	dpkg-shlibdeps -Tdebian/efitools.substvars debian/efitools/usr/bin/flash-var debian/efitools/usr/bin/efi-updatevar debian/efitools/usr/bin/cert-to-efi-hash-list debian/efitools/usr/bin/hash-to-efi-sig-list debian/efitools/usr/bin/sig-list-to-certs debian/efitools/usr/bin/sign-efi-sig-list debian/efitools/usr/bin/cert-to-efi-sig-list debian/efitools/usr/bin/efi-readvar
+	dpkg-shlibdeps -Tdebian/efitools.substvars debian/efitools/usr/bin/efi-readvar debian/efitools/usr/bin/sig-list-to-certs debian/efitools/usr/bin/cert-to-efi-hash-list debian/efitools/usr/bin/efi-updatevar debian/efitools/usr/bin/hash-to-efi-sig-list debian/efitools/usr/bin/flash-var debian/efitools/usr/bin/sign-efi-sig-list debian/efitools/usr/bin/cert-to-efi-sig-list
    dh_installdeb
 	install -m0755 -d debian/efitools/DEBIAN
    dh_gencontrol
@@ -3030,12 +3066,14 @@
 dpkg-buildpackage: info: binary-only upload (no source included)
 dpkg-genchanges: info: not including original source code in upload
 I: copying local configuration
+I: user script /srv/workspace/pbuilder/181475/tmp/hooks/B01_cleanup starting
+I: user script /srv/workspace/pbuilder/181475/tmp/hooks/B01_cleanup finished
 I: unmounting dev/ptmx filesystem
 I: unmounting dev/pts filesystem
 I: unmounting dev/shm filesystem
 I: unmounting proc filesystem
 I: unmounting sys filesystem
 I: cleaning the build env 
-I: removing directory /srv/workspace/pbuilder/3266645 and its subdirectories
-I: Current time: Tue Mar 18 17:18:42 -12 2025
-I: pbuilder-time-stamp: 1742361522
+I: removing directory /srv/workspace/pbuilder/181475 and its subdirectories
+I: Current time: Wed Apr 22 01:43:08 +14 2026
+I: pbuilder-time-stamp: 1776771788