openSUSE Bugs
Threads by month
- ----- 2025 -----
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
November 2024
- 1 participants
- 1859 discussions
[Bug 1229048] New: Always prompted for recovery key, but could not update predictions
by bugzilla_noreply@suse.com 03 Jan '25
by bugzilla_noreply@suse.com 03 Jan '25
03 Jan '25
https://bugzilla.suse.com/show_bug.cgi?id=1229048
Bug ID: 1229048
Summary: Always prompted for recovery key, but could not update
predictions
Classification: openSUSE
Product: openSUSE Aeon
Version: Current
Hardware: x86-64
OS: Other
Status: NEW
Severity: Major
Priority: P5 - None
Component: Base
Assignee: rbrown(a)suse.com
Reporter: vandeft(a)gmail.com
QA Contact: qa-bugs(a)suse.de
Target Milestone: ---
Found By: ---
Blocker: ---
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:129.0) Gecko/20100101
Firefox/129.0
Build Identifier:
The recovery key prompt started after disabling and enabling Secure Boot. I
tried running the following command as recommended on the troubleshooting page:
sudo sdbootutil --ask-pin update-predictions
The problem is that I get the error: "Provided PIN Incorrect or TPM2 locked
after too many retries" even after only entering the recovery key once. I know
it was entered correctly because I copied it from my password manager.
Reproducible: Always
Steps to Reproduce:
1. Disable Secure Boot and restart
2. Enable Secure Boot and restart
3. Boot openSUSE Aeon and enter recovery key
4. Open terminal and run "sudo sdbootutil --ask-pin update-predictions"
5. Enter recovery key
Actual Results:
sdbootutil tries to restore the link between my system and its encryption, but
fails.
Expected Results:
sdbootutil should succeed in restoring the link between my system and its
encryption.
○ → sudo sdbootutil -vv --ask-pin update-predictions
Found cgroup2 on /sys/fs/cgroup/, full unified hierarchy
Found container virtualization none.
Failed to check file system type of "/efi": No such file or directory
File system "/boot" is not a FAT EFI System Partition (ESP) file system.
Using EFI System Partition at /boot/efi.
Directory "/boot" is not the root of the file system.
Didn't find an XBOOTLDR partition, using the ESP as $BOOT.
Reading EFI variable
/sys/firmware/efi/efivars/LoaderEntries-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f.
Reading EFI variable
/sys/firmware/efi/efivars/LoaderEntryOneShot-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f.
open("/sys/firmware/efi/efivars/LoaderEntryOneShot-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f")
failed: No such file or directory
Reading EFI variable
/sys/firmware/efi/efivars/LoaderEntryDefault-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f.
Reading EFI variable
/sys/firmware/efi/efivars/LoaderEntrySelected-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f.
Found default: id "opensuse-aeon-6.10.3-1-default-22.conf" is matched by
LoaderEntryDefault
TPM PC Client Platform Firmware Profile: family 2.0, revision 0.0
Ignoring device path element type=0x04 subtype=0x07
Ignoring device path element type=0x04 subtype=0x06
Ignoring device path element type=0x02 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x03 subtype=0x17
Ignoring device path element type=0x04 subtype=0x01
Garbage after device path end, ignoring.
Loaded 'libtss2-esys.so.0' via dlopen()
Loaded 'libtss2-rc.so.0' via dlopen()
Loaded 'libtss2-mu.so.0' via dlopen()
Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'.
Loaded 'libtss2-tcti-device.so.0' via dlopen()
Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux
kernel interface.) [Version 2]
TPM successfully started up.
Getting TPM2 capability 0x0000 property 0x0001 count 127.
Getting TPM2 capability 0x0002 property 0x011f count 256.
Getting TPM2 capability 0x0008 property 0x0000 count 508.
Getting TPM2 capability 0x0005 property 0x0000 count 1.
Reading PCR selection:
[sha1(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha1(0+1+2+3+4+5+6+7)]
PCR value: 0:sha1=23745cb6a52f04f520bcb67a57a8ceeaa67cdcf7
PCR value: 1:sha1=b57cd41bd48870f77d0d89830a04ee328fe916b0
PCR value: 2:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236
PCR value: 3:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236
PCR value: 4:sha1=5822de53cb1b4fb68f7535304b12309e833c93c8
PCR value: 5:sha1=4fd367f64ae596ff430c5c81ccd39c8f3febf992
PCR value: 6:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236
PCR value: 7:sha1=e820d059eeab7d4b134ceae88672f569d4a7eb74
Reading PCR selection: [sha1(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha1(8+9+10+11+12+13+14+15)]
PCR value: 8:sha1=0000000000000000000000000000000000000000
PCR value: 9:sha1=28420f38f0c0493e60bc4349ff11f2bc1cadf744
PCR value: 10:sha1=0f7ed4a3679f7f30a7934952afd2de10d93ad37b
PCR value: 11:sha1=0000000000000000000000000000000000000000
PCR value: 12:sha1=b170a442bed9b3c14c3b6a72cc3866dc6d844382
PCR value: 13:sha1=0000000000000000000000000000000000000000
PCR value: 14:sha1=677f1f77d72332e8e8041f16b6c082bf077ece84
PCR value: 15:sha1=0000000000000000000000000000000000000000
Reading PCR selection: [sha1(16+17+18+19+20+21+22+23)]
Read PCR selection: [sha1(16+17+18+19+20+21+22+23)]
PCR value: 16:sha1=0000000000000000000000000000000000000000
PCR value: 17:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 18:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 19:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 20:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 21:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 22:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 23:sha1=0000000000000000000000000000000000000000
Reading PCR selection:
[sha256(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(0+1+2+3+4+5+6+7)]
PCR value:
0:sha256=c1f2e40d330b6a6b982f00c5aa76ac32800a36f7afdb294bf34569f1433335bb
PCR value:
1:sha256=da33d382da316e5c6be06d1164b785dbec2ed2c9aaf3938c43dbcf675d074846
PCR value:
2:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
3:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
4:sha256=2c8acbf406e4ea74fa014baf1180c8f28d7c60cb3a27265d274b027885cc2416
PCR value:
5:sha256=c0b661f390b58a95f7c0173ae70e0cccaa6917f6108de9542463c578cee1d203
PCR value:
6:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
7:sha256=22f5a51babd581abe57a405f84e41c8f3da14c41ab345f274ba406d998886962
Reading PCR selection: [sha256(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(8+9+10+11+12+13+14+15)]
PCR value:
8:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
9:sha256=d4d845f23d71324ec38766e1c19f2cfe2bd413ecf27ae3b0681a5aaab38d897f
PCR value:
10:sha256=e47fa4366c3527eabfabcdbb73db784214a87af792ffcdd0fc2ff44c76185f93
PCR value:
11:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
12:sha256=a443f6cf29ccc0245b39893ebf2d8bd221a021d9f68c3124849f0cb20e965832
PCR value:
13:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
14:sha256=1095b057262e3e9e1b0f3952228f2b2741be5d85dbfe5951c7e41279ceb2ebe8
PCR value:
15:sha256=0000000000000000000000000000000000000000000000000000000000000000
Reading PCR selection: [sha256(16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(16+17+18+19+20+21+22+23)]
PCR value:
16:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
17:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
18:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
19:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
20:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
21:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
22:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
23:sha256=0000000000000000000000000000000000000000000000000000000000000000
/var/lib/pcrlock.d/250-firmware-code-early.pcrlock.d/generated.pcrlock written.
/var/lib/pcrlock.d/550-firmware-code-late.pcrlock.d/generated.pcrlock written.
TPM PC Client Platform Firmware Profile: family 2.0, revision 0.0
Ignoring device path element type=0x04 subtype=0x07
Ignoring device path element type=0x04 subtype=0x06
Ignoring device path element type=0x02 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x03 subtype=0x17
Ignoring device path element type=0x04 subtype=0x01
Garbage after device path end, ignoring.
Loaded 'libtss2-esys.so.0' via dlopen()
Loaded 'libtss2-rc.so.0' via dlopen()
Loaded 'libtss2-mu.so.0' via dlopen()
Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'.
Loaded 'libtss2-tcti-device.so.0' via dlopen()
Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux
kernel interface.) [Version 2]
TPM successfully started up.
Getting TPM2 capability 0x0000 property 0x0001 count 127.
Getting TPM2 capability 0x0002 property 0x011f count 256.
Getting TPM2 capability 0x0008 property 0x0000 count 508.
Getting TPM2 capability 0x0005 property 0x0000 count 1.
Reading PCR selection:
[sha1(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha1(0+1+2+3+4+5+6+7)]
PCR value: 0:sha1=23745cb6a52f04f520bcb67a57a8ceeaa67cdcf7
PCR value: 1:sha1=b57cd41bd48870f77d0d89830a04ee328fe916b0
PCR value: 2:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236
PCR value: 3:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236
PCR value: 4:sha1=5822de53cb1b4fb68f7535304b12309e833c93c8
PCR value: 5:sha1=4fd367f64ae596ff430c5c81ccd39c8f3febf992
PCR value: 6:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236
PCR value: 7:sha1=e820d059eeab7d4b134ceae88672f569d4a7eb74
Reading PCR selection: [sha1(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha1(8+9+10+11+12+13+14+15)]
PCR value: 8:sha1=0000000000000000000000000000000000000000
PCR value: 9:sha1=28420f38f0c0493e60bc4349ff11f2bc1cadf744
PCR value: 10:sha1=0f7ed4a3679f7f30a7934952afd2de10d93ad37b
PCR value: 11:sha1=0000000000000000000000000000000000000000
PCR value: 12:sha1=b170a442bed9b3c14c3b6a72cc3866dc6d844382
PCR value: 13:sha1=0000000000000000000000000000000000000000
PCR value: 14:sha1=677f1f77d72332e8e8041f16b6c082bf077ece84
PCR value: 15:sha1=0000000000000000000000000000000000000000
Reading PCR selection: [sha1(16+17+18+19+20+21+22+23)]
Read PCR selection: [sha1(16+17+18+19+20+21+22+23)]
PCR value: 16:sha1=0000000000000000000000000000000000000000
PCR value: 17:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 18:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 19:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 20:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 21:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 22:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 23:sha1=0000000000000000000000000000000000000000
Reading PCR selection:
[sha256(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(0+1+2+3+4+5+6+7)]
PCR value:
0:sha256=c1f2e40d330b6a6b982f00c5aa76ac32800a36f7afdb294bf34569f1433335bb
PCR value:
1:sha256=da33d382da316e5c6be06d1164b785dbec2ed2c9aaf3938c43dbcf675d074846
PCR value:
2:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
3:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
4:sha256=2c8acbf406e4ea74fa014baf1180c8f28d7c60cb3a27265d274b027885cc2416
PCR value:
5:sha256=c0b661f390b58a95f7c0173ae70e0cccaa6917f6108de9542463c578cee1d203
PCR value:
6:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
7:sha256=22f5a51babd581abe57a405f84e41c8f3da14c41ab345f274ba406d998886962
Reading PCR selection: [sha256(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(8+9+10+11+12+13+14+15)]
PCR value:
8:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
9:sha256=d4d845f23d71324ec38766e1c19f2cfe2bd413ecf27ae3b0681a5aaab38d897f
PCR value:
10:sha256=e47fa4366c3527eabfabcdbb73db784214a87af792ffcdd0fc2ff44c76185f93
PCR value:
11:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
12:sha256=a443f6cf29ccc0245b39893ebf2d8bd221a021d9f68c3124849f0cb20e965832
PCR value:
13:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
14:sha256=1095b057262e3e9e1b0f3952228f2b2741be5d85dbfe5951c7e41279ceb2ebe8
PCR value:
15:sha256=0000000000000000000000000000000000000000000000000000000000000000
Reading PCR selection: [sha256(16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(16+17+18+19+20+21+22+23)]
PCR value:
16:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
17:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
18:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
19:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
20:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
21:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
22:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
23:sha256=0000000000000000000000000000000000000000000000000000000000000000
/var/lib/pcrlock.d/250-firmware-config-early.pcrlock.d/generated.pcrlock
written.
/var/lib/pcrlock.d/550-firmware-config-late.pcrlock.d/generated.pcrlock
written.
/var/lib/pcrlock.d/600-gpt.pcrlock.d/generated.pcrlock written.
Hashing 216 @ 0 → 216
Hashing 76 @ 220 → 296
Hashing 720 @ 304 → 1024
Hashing 117760 @ 1024 → 118784
Hashing 379392 @ 118784 → 498176
Hashing 512 @ 498176 → 498688
Hashing 512 @ 498688 → 499200
Hashing 179712 @ 499200 → 678912
Hashing 6656 @ 678912 → 685568
Hashing 512 @ 685568 → 686080
Hashing 111616 @ 686080 → 797696
Hashing 512 @ 797696 → 798208
Hashing 125368 @ 798208 → 923576
Hashing 216 @ 0 → 216
Hashing 76 @ 220 → 296
Hashing 720 @ 304 → 1024
Hashing 117760 @ 1024 → 118784
Hashing 379392 @ 118784 → 498176
Hashing 512 @ 498176 → 498688
Hashing 512 @ 498688 → 499200
Hashing 179712 @ 499200 → 678912
Hashing 6656 @ 678912 → 685568
Hashing 512 @ 685568 → 686080
Hashing 111616 @ 686080 → 797696
Hashing 512 @ 797696 → 798208
Hashing 125368 @ 798208 → 923576
Hashing 216 @ 0 → 216
Hashing 76 @ 220 → 296
Hashing 720 @ 304 → 1024
Hashing 117760 @ 1024 → 118784
Hashing 379392 @ 118784 → 498176
Hashing 512 @ 498176 → 498688
Hashing 512 @ 498688 → 499200
Hashing 179712 @ 499200 → 678912
Hashing 6656 @ 678912 → 685568
Hashing 512 @ 685568 → 686080
Hashing 111616 @ 686080 → 797696
Hashing 512 @ 797696 → 798208
Hashing 125368 @ 798208 → 923576
Hashing 216 @ 0 → 216
Hashing 76 @ 220 → 296
Hashing 720 @ 304 → 1024
Hashing 117760 @ 1024 → 118784
Hashing 379392 @ 118784 → 498176
Hashing 512 @ 498176 → 498688
Hashing 512 @ 498688 → 499200
Hashing 179712 @ 499200 → 678912
Hashing 6656 @ 678912 → 685568
Hashing 512 @ 685568 → 686080
Hashing 111616 @ 686080 → 797696
Hashing 512 @ 797696 → 798208
Hashing 125368 @ 798208 → 923576
/var/lib/pcrlock.d/630-shim-efi-application.pcrlock.d/generated.pcrlock
written.
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 784 @ 240 → 1024
Hashing 74752 @ 1024 → 75776
Hashing 20480 @ 75776 → 96256
Hashing 512 @ 96256 → 96768
Hashing 512 @ 96768 → 97280
Hashing 512 @ 97280 → 97792
Hashing 512 @ 97792 → 98304
Hashing 512 @ 98304 → 98816
Hashing 0 @ 98816 → 98816
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 784 @ 240 → 1024
Hashing 74752 @ 1024 → 75776
Hashing 20480 @ 75776 → 96256
Hashing 512 @ 96256 → 96768
Hashing 512 @ 96768 → 97280
Hashing 512 @ 97280 → 97792
Hashing 512 @ 97792 → 98304
Hashing 512 @ 98304 → 98816
Hashing 0 @ 98816 → 98816
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 784 @ 240 → 1024
Hashing 74752 @ 1024 → 75776
Hashing 20480 @ 75776 → 96256
Hashing 512 @ 96256 → 96768
Hashing 512 @ 96768 → 97280
Hashing 512 @ 97280 → 97792
Hashing 512 @ 97792 → 98304
Hashing 512 @ 98304 → 98816
Hashing 0 @ 98816 → 98816
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 784 @ 240 → 1024
Hashing 74752 @ 1024 → 75776
Hashing 20480 @ 75776 → 96256
Hashing 512 @ 96256 → 96768
Hashing 512 @ 96768 → 97280
Hashing 512 @ 97280 → 97792
Hashing 512 @ 97792 → 98304
Hashing 512 @ 98304 → 98816
Hashing 0 @ 98816 → 98816
/var/lib/pcrlock.d/640-boot-loader-efi-application.pcrlock.d/generated.pcrlock
written.
/var/lib/pcrlock.d/641-sdboot-loader-conf.pcrlock written.
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 3856 @ 240 → 4096
Hashing 12288 @ 4096 → 16384
Hashing 4096 @ 16384 → 20480
Hashing 14741504 @ 20480 → 14761984
Hashing 4608 @ 14761984 → 14766592
Hashing 0 @ 14766592 → 14766592
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 3856 @ 240 → 4096
Hashing 12288 @ 4096 → 16384
Hashing 4096 @ 16384 → 20480
Hashing 14741504 @ 20480 → 14761984
Hashing 4608 @ 14761984 → 14766592
Hashing 0 @ 14766592 → 14766592
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 3856 @ 240 → 4096
Hashing 12288 @ 4096 → 16384
Hashing 4096 @ 16384 → 20480
Hashing 14741504 @ 20480 → 14761984
Hashing 4608 @ 14761984 → 14766592
Hashing 0 @ 14766592 → 14766592
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 3856 @ 240 → 4096
Hashing 12288 @ 4096 → 16384
Hashing 4096 @ 16384 → 20480
Hashing 14741504 @ 20480 → 14761984
Hashing 4608 @ 14761984 → 14766592
Hashing 0 @ 14766592 → 14766592
/var/lib/pcrlock.d/650-kernel-efi-application.pcrlock.d/linux-1.pcrlock
written.
/tmp/sdbootutil.pzayUU/cmdline.pcrlock written.
/var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-1.pcrlock
written.
/tmp/sdbootutil.pzayUU/cmdline.pcrlock written.
/var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-2.pcrlock
written.
Recovery PIN: TPM PC Client Platform Firmware Profile: family 2.0, revision 0.0
Ignoring device path element type=0x04 subtype=0x07
Ignoring device path element type=0x04 subtype=0x06
Ignoring device path element type=0x02 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x03 subtype=0x17
Ignoring device path element type=0x04 subtype=0x01
Garbage after device path end, ignoring.
Loaded 'libtss2-esys.so.0' via dlopen()
Loaded 'libtss2-rc.so.0' via dlopen()
Loaded 'libtss2-mu.so.0' via dlopen()
Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'.
Loaded 'libtss2-tcti-device.so.0' via dlopen()
Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux
kernel interface.) [Version 2]
TPM successfully started up.
Getting TPM2 capability 0x0000 property 0x0001 count 127.
Getting TPM2 capability 0x0002 property 0x011f count 256.
Getting TPM2 capability 0x0008 property 0x0000 count 508.
Getting TPM2 capability 0x0005 property 0x0000 count 1.
Reading PCR selection:
[sha1(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha1(0+1+2+3+4+5+6+7)]
PCR value: 0:sha1=23745cb6a52f04f520bcb67a57a8ceeaa67cdcf7
PCR value: 1:sha1=b57cd41bd48870f77d0d89830a04ee328fe916b0
PCR value: 2:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236
PCR value: 3:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236
PCR value: 4:sha1=5822de53cb1b4fb68f7535304b12309e833c93c8
PCR value: 5:sha1=4fd367f64ae596ff430c5c81ccd39c8f3febf992
PCR value: 6:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236
PCR value: 7:sha1=e820d059eeab7d4b134ceae88672f569d4a7eb74
Reading PCR selection: [sha1(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha1(8+9+10+11+12+13+14+15)]
PCR value: 8:sha1=0000000000000000000000000000000000000000
PCR value: 9:sha1=28420f38f0c0493e60bc4349ff11f2bc1cadf744
PCR value: 10:sha1=0f7ed4a3679f7f30a7934952afd2de10d93ad37b
PCR value: 11:sha1=0000000000000000000000000000000000000000
PCR value: 12:sha1=b170a442bed9b3c14c3b6a72cc3866dc6d844382
PCR value: 13:sha1=0000000000000000000000000000000000000000
PCR value: 14:sha1=677f1f77d72332e8e8041f16b6c082bf077ece84
PCR value: 15:sha1=0000000000000000000000000000000000000000
Reading PCR selection: [sha1(16+17+18+19+20+21+22+23)]
Read PCR selection: [sha1(16+17+18+19+20+21+22+23)]
PCR value: 16:sha1=0000000000000000000000000000000000000000
PCR value: 17:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 18:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 19:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 20:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 21:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 22:sha1=ffffffffffffffffffffffffffffffffffffffff
PCR value: 23:sha1=0000000000000000000000000000000000000000
Reading PCR selection:
[sha256(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(0+1+2+3+4+5+6+7)]
PCR value:
0:sha256=c1f2e40d330b6a6b982f00c5aa76ac32800a36f7afdb294bf34569f1433335bb
PCR value:
1:sha256=da33d382da316e5c6be06d1164b785dbec2ed2c9aaf3938c43dbcf675d074846
PCR value:
2:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
3:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
4:sha256=2c8acbf406e4ea74fa014baf1180c8f28d7c60cb3a27265d274b027885cc2416
PCR value:
5:sha256=c0b661f390b58a95f7c0173ae70e0cccaa6917f6108de9542463c578cee1d203
PCR value:
6:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
7:sha256=22f5a51babd581abe57a405f84e41c8f3da14c41ab345f274ba406d998886962
Reading PCR selection: [sha256(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(8+9+10+11+12+13+14+15)]
PCR value:
8:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
9:sha256=d4d845f23d71324ec38766e1c19f2cfe2bd413ecf27ae3b0681a5aaab38d897f
PCR value:
10:sha256=e47fa4366c3527eabfabcdbb73db784214a87af792ffcdd0fc2ff44c76185f93
PCR value:
11:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
12:sha256=a443f6cf29ccc0245b39893ebf2d8bd221a021d9f68c3124849f0cb20e965832
PCR value:
13:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
14:sha256=1095b057262e3e9e1b0f3952228f2b2741be5d85dbfe5951c7e41279ceb2ebe8
PCR value:
15:sha256=0000000000000000000000000000000000000000000000000000000000000000
Reading PCR selection: [sha256(16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(16+17+18+19+20+21+22+23)]
PCR value:
16:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
17:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
18:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
19:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
20:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
21:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
22:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
23:sha256=0000000000000000000000000000000000000000000000000000000000000000
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
Found 2 possible variants of component '650-kernel-efi-application' in event
log (linux-1, linux-2). Proceeding.
Couldn't find component '750-enter-initrd' in event log.
Didn't find component '800-leave-initrd' in event log, assuming system hasn't
reached it yet.
Didn't find component '850-sysinit' in event log, assuming system hasn't
reached it yet.
Didn't find component '900-ready' in event log, assuming system hasn't reached
it yet.
Skipped 2 components after location '940-' (950-shutdown, 990-final).
Unable to recognize 1 components in event log.
Event log record 29 (PCR 14, "Raw: MokList\000") not matching any component.
PCR 0 (platform-code) matches event log and fully consists of recognized
measurements. Including in set of PCRs.
PCR 4 (boot-loader-code) matches event log and fully consists of recognized
measurements. Including in set of PCRs.
PCR 5 (boot-loader-config) matches event log and fully consists of recognized
measurements. Including in set of PCRs.
PCR 7 (secure-boot-policy) matches event log and fully consists of recognized
measurements. Including in set of PCRs.
PCR 9 (kernel-initrd) matches event log and fully consists of recognized
measurements. Including in set of PCRs.
No PCRs dropped from protection mask.
PCRs in protection mask: 0 (platform-code), 4 (boot-loader-code), 5
(boot-loader-config), 7 (secure-boot-policy), 9 (kernel-initrd)
Added prediction result 1 for PCR 0 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 2 for PCR 0 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@600-0xffffffff:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 1 for PCR 4 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 2 for PCR 4 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@600-0xffffffff:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 1 for PCR 5 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 2 for PCR 5 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@600-absent:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 3 for PCR 5 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@600-0xffffffff:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 4 for PCR 5 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@600-0xffffffff:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@600-absent:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 1 for PCR 7 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 2 for PCR 7 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@600-0xffffffff:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 1 for PCR 9 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 2 for PCR 9 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-2:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 3 for PCR 9 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-3:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Predicted future PCRs in 1.979ms.
[
{
"pcr" : 0,
"values" : [
"c1f2e40d330b6a6b982f00c5aa76ac32800a36f7afdb294bf34569f1433335bb",
"42898f424c28badd6fe7cbeb49c107f80ac910760b69ed9b6bd32920a2a65b33"
]
},
{
"pcr" : 4,
"values" : [
"2c8acbf406e4ea74fa014baf1180c8f28d7c60cb3a27265d274b027885cc2416",
"27cbe31f31e033805684ec185def5e32b6d4cb08432d64f43a377bec0243cefb"
]
},
{
"pcr" : 5,
"values" : [
"c0b661f390b58a95f7c0173ae70e0cccaa6917f6108de9542463c578cee1d203",
"935075d2a20e8ddc861722f2bdc0de78aad8f306843f092910c6ed32dbe888e4",
"072b91ff3de7696151dbb5584575e8ac348c670a34f271fb099f617c2afd4448",
"0ed87e2ffb634d91b6e20da816eec3dd2284b8fe0035fde8531c3e96370a8f18"
]
},
{
"pcr" : 7,
"values" : [
"22f5a51babd581abe57a405f84e41c8f3da14c41ab345f274ba406d998886962",
"1a2deb2d5316c9093ef8a6f4e20dbac5e0be296eb0efe0be0a3e23e621157a3c"
]
},
{
"pcr" : 9,
"values" : [
"d4d845f23d71324ec38766e1c19f2cfe2bd413ecf27ae3b0681a5aaab38d897f",
"0d1b30845de98a7dd32201a94aad68f18a0665cd25cde2d599cccb0b363ee2b9",
"433a0b89e7fcab6694c177acb686489bec81018e14fe4ce954d5438316603177"
]
}
]
Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'.
Loaded 'libtss2-tcti-device.so.0' via dlopen()
Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux
kernel interface.) [Version 2]
TPM successfully started up.
Getting TPM2 capability 0x0000 property 0x0001 count 127.
Getting TPM2 capability 0x0002 property 0x011f count 256.
Getting TPM2 capability 0x0008 property 0x0000 count 508.
Getting TPM2 capability 0x0005 property 0x0000 count 1.
Starting HMAC encryption session.
Converting PIN into TPM2 HMAC-SHA256 object.
Loading external key into TPM.
Starting policy session.
Submitting PolicySigned policy for HMAC-SHA256.
Acquiring policy digest.
Session policy digest:
c3261b61d61ae9cebc2fbe4e64ab2548b58ef9dd3643d1cf172bd28a74132fd5
Calculating new PCR policy to write...
PolicyPCR calculated digest:
6b4175491ce0b23cd5d93dbc3f3364768a64283951ae62610c56871f1843d8fd
Calculated PCR policy variant 1 for PCR 0
PolicyPCR calculated digest:
c2bb1c9990f5b7b6b8dfb343b21b2d532e20486b871387679b6f82ef6e5ea27e
Calculated PCR policy variant 2 for PCR 0
OR Branch #0: 6b4175491ce0b23cd5d93dbc3f3364768a64283951ae62610c56871f1843d8fd
OR Branch #1: c2bb1c9990f5b7b6b8dfb343b21b2d532e20486b871387679b6f82ef6e5ea27e
PolicyOR calculated digest:
cd5d6970e6b52fc15ab5d3b9ce978cd2848198ac7d1f902dd9b660f13d58ff8f
Combined 2 variants in OR policy.
PolicyPCR calculated digest:
32aced0716b3b3a9385be277f969bfb6dd7d683ed1a881212d736bd2ecc08701
Calculated PCR policy variant 1 for PCR 4
PolicyPCR calculated digest:
c07fdb3efd446bff0d2fa4c59e78da8bf66437052b487e22df015363827fd844
Calculated PCR policy variant 2 for PCR 4
OR Branch #0: 32aced0716b3b3a9385be277f969bfb6dd7d683ed1a881212d736bd2ecc08701
OR Branch #1: c07fdb3efd446bff0d2fa4c59e78da8bf66437052b487e22df015363827fd844
PolicyOR calculated digest:
e5806d8dfbfd4b188b458fa271d2e75490cc659684f238d02b56d1680597eb57
Combined 2 variants in OR policy.
PolicyPCR calculated digest:
8cc15772306c7d06c4d1638458d0561318f1b80f3f97b812d401ee45356f3883
Calculated PCR policy variant 1 for PCR 5
PolicyPCR calculated digest:
c6c8983c5b6bd48524cc0b84b1d3529ddbb7ddafc439f605e2d1adb296017485
Calculated PCR policy variant 2 for PCR 5
PolicyPCR calculated digest:
ad2f61d1f30b27bc2d2139f01a144108ab0b31c2837f18736581d04d1c68d33f
Calculated PCR policy variant 3 for PCR 5
PolicyPCR calculated digest:
30f63fb7db60131c9ca62bac1af4269f6947a506a940975b93110ddccdd9099c
Calculated PCR policy variant 4 for PCR 5
OR Branch #0: 8cc15772306c7d06c4d1638458d0561318f1b80f3f97b812d401ee45356f3883
OR Branch #1: c6c8983c5b6bd48524cc0b84b1d3529ddbb7ddafc439f605e2d1adb296017485
OR Branch #2: ad2f61d1f30b27bc2d2139f01a144108ab0b31c2837f18736581d04d1c68d33f
OR Branch #3: 30f63fb7db60131c9ca62bac1af4269f6947a506a940975b93110ddccdd9099c
PolicyOR calculated digest:
ed8533e59387bea4f6dfadbfac6e7bc6d43d696be8329ab21a1af31bc16266c5
Combined 4 variants in OR policy.
PolicyPCR calculated digest:
62f42e42a8b2bcf3e5b50071e7003f3e84923c77c27e0ba2fee00f80ac636279
Calculated PCR policy variant 1 for PCR 7
PolicyPCR calculated digest:
838e0466d318fae0f4a380d3c50131ad787a608d7a0d87ef1b2a325137121a0e
Calculated PCR policy variant 2 for PCR 7
OR Branch #0: 62f42e42a8b2bcf3e5b50071e7003f3e84923c77c27e0ba2fee00f80ac636279
OR Branch #1: 838e0466d318fae0f4a380d3c50131ad787a608d7a0d87ef1b2a325137121a0e
PolicyOR calculated digest:
80fc0a160542eac4c8364982675e3e1e6d1f89cf31f61c9e5907f99a753e4f87
Combined 2 variants in OR policy.
PolicyPCR calculated digest:
7911cd4e5ff5175d18b57643a3576932a237abd97f5240f2c7318b8586775c53
Calculated PCR policy variant 1 for PCR 9
PolicyPCR calculated digest:
9d69423bfe4901d61f0792e69e2da706b22c8a80d4289abd8d592774c11565d9
Calculated PCR policy variant 2 for PCR 9
PolicyPCR calculated digest:
ce0d60c2d319db72aecc881eb8d42d6dc17beca8394af8a832d6a0f297604db1
Calculated PCR policy variant 3 for PCR 9
OR Branch #0: 7911cd4e5ff5175d18b57643a3576932a237abd97f5240f2c7318b8586775c53
OR Branch #1: 9d69423bfe4901d61f0792e69e2da706b22c8a80d4289abd8d592774c11565d9
OR Branch #2: ce0d60c2d319db72aecc881eb8d42d6dc17beca8394af8a832d6a0f297604db1
PolicyOR calculated digest:
a95db79012016c57c33f257e0fd02d1da8862c6740bcfa599c5145819e374d24
Combined 3 variants in OR policy.
Calculated new PCR policy in 526us.
Writing new PCR policy to NV index...
WARNING:esys:src/tss2-esys/api/Esys_NV_Write.c:310:Esys_NV_Write_Finish()
Received TPM Error
ERROR:esys:src/tss2-esys/api/Esys_NV_Write.c:110:Esys_NV_Write() Esys Finish
ErrorCode (0x0000099d)
Failed to write NV index: tpm:session(1):a policy check failed
Failed to write to NV index: State not recoverable
Error creating the policy!
Provided PIN incorrect or TPM2 locked after too many retries
NVIndex policy created
--
You are receiving this mail because:
You are on the CC list for the bug.
1
2
[Bug 1232734] New: Recovery key re-enrollement seemed to work but eventually broke the bootloader
by bugzilla_noreply@suse.com 03 Jan '25
by bugzilla_noreply@suse.com 03 Jan '25
03 Jan '25
https://bugzilla.suse.com/show_bug.cgi?id=1232734
Bug ID: 1232734
Summary: Recovery key re-enrollement seemed to work but
eventually broke the bootloader
Classification: openSUSE
Product: openSUSE Aeon
Version: Current
Hardware: x86-64
OS: Other
Status: NEW
Severity: Normal
Priority: P5 - None
Component: Transactional Update
Assignee: rbrown(a)suse.com
Reporter: vincent.conus(a)pm.me
QA Contact: qa-bugs(a)suse.de
Target Milestone: ---
Found By: ---
Blocker: ---
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:132.0) Gecko/20100101
Firefox/132.0
Build Identifier:
Having a similar issue with the recovery key being requested after system
update, as described in issue 1228863, I tried and went through a full
re-enrollement, as described on the Advanced documentation.
https://bugzilla.opensuse.org/show_bug.cgi?id=1228863
This step was not working and I kept getting prompt that the recovery key was
unvalid, even though I just used it to manually unlock my system.
Following the advice in comment
https://bugzilla.opensuse.org/show_bug.cgi?id=1228863#c12,
I tried and ran `systemd-cryptenroll --tpm2-device=auto /dev/nvme0n1p2`.
This seemed to work, since I could successfully enter my recovery key, and
after running
`sudo systemd-cryptenroll`, a TPM entry was visible.
However, after rebooting the system, no partition was available to boot
anymore!
I'm guessing the re-enrollement broke the bootloader...
Reproducible: Didn't try
Steps to Reproduce:
1. At some point, a system update reboot would start asking me to enter the
recovery key. This happens randomly as some updates on the same machine worked
just fine.
2. `sudo sdbootutil --ask-pin update-predictions` fails, then trying a full
re-enrollement.
3.`sudo sdbootutil unenroll --method=tpm2` seems to work
4. `sudo systemd-cryptenroll`: no more TPM entry
5. `sudo sdbootutil enroll --method=tpm2` fails, saying the recovery key is
wrong.
6. `echo 5 | sudo tee /sys/class/tpm/tpm0/ppi/request`
7. reboot, recovery key
8. `systemd-cryptenroll --tpm2-device=auto /dev/nvme0n1p2` is successful
9. `sudo systemd-cryptenroll` is succseful: a TPM entry was visible
10. Reboot
11. No more bootable partition visible from the BIOS !!
Actual Results:
No more bootable partition visible on boot.
No really knowing what to do, I proceed with a full system re-install.
Because of that, I don't have any logs at hand. I'll update this ticket it the
bug re-appear!
Expected Results:
The system restart as usual, using TPM2.0 without asking for the recovery key.
Some error messages spitted by the full re-enrollement commands suggest that
the fact that I have another NVMe SSD in my laptop, also containing a LUKS
partition confused the TMP system, as some command seemed to try to work on the
other disk instead of the system one.
--
You are receiving this mail because:
You are on the CC list for the bug.
1
2
[Bug 1217920] New: QT_IM_MODULE is always set on plasma 5.27.9
by bugzilla_noreply@suse.com 03 Jan '25
by bugzilla_noreply@suse.com 03 Jan '25
03 Jan '25
https://bugzilla.suse.com/show_bug.cgi?id=1217920
Bug ID: 1217920
Summary: QT_IM_MODULE is always set on plasma 5.27.9
Classification: openSUSE
Product: openSUSE Tumbleweed
Version: Current
Hardware: Other
OS: Other
Status: NEW
Severity: Normal
Priority: P5 - None
Component: Other
Assignee: screening-team-bugs(a)suse.de
Reporter: i(a)xuzhao.net
QA Contact: qa-bugs(a)suse.de
Target Milestone: ---
Found By: ---
Blocker: ---
According to the fcitx5 on wayland wiki page:
https://fcitx-im.org/wiki/Using_Fcitx_5_on_Wayland
QT_IM_MODULE and GTK_IM_MODULE and SDL_IM_MODULE are not suggested to be set on
fcitx5+plasma_wayland>5.27.
However, after I install fcitx5 on opensuse 20231117, these environment
variables are still being set by default.
Is there a way that I can disable setting these environment variables on
startup?
--
You are receiving this mail because:
You are on the CC list for the bug.
1
8
[Bug 1230006] New: Mobile Broadband unavailable after installation
by bugzilla_noreply@suse.com 03 Jan '25
by bugzilla_noreply@suse.com 03 Jan '25
03 Jan '25
https://bugzilla.suse.com/show_bug.cgi?id=1230006
Bug ID: 1230006
Summary: Mobile Broadband unavailable after installation
Classification: openSUSE
Product: openSUSE Aeon
Version: Current
Hardware: x86-64
OS: Other
Status: NEW
Severity: Normal
Priority: P5 - None
Component: Base
Assignee: rbrown(a)suse.com
Reporter: hja37(a)aol.com
QA Contact: qa-bugs(a)suse.de
Target Milestone: ---
Found By: ---
Blocker: ---
On a fresh installation of openSUSE Aeon, it is not possible to configure a
Mobile Broadband connection due to a missing dependency of ModemManager,
libmbim. Without this library ModemManager is unable to configure the modem.
Observable behaviour is Mobile Network is absent from GNOME settings.
Solution: Install missing libmbim dependency and reboot the system. Mobile
Broadband is then configurable from GNOME settings, as expected.
# transactional-update pkg in libmbim
--
You are receiving this mail because:
You are on the CC list for the bug.
1
4
[Bug 1226405] New: Nautilus crash when opening multiple mp3 files
by bugzilla_noreply@suse.com 03 Jan '25
by bugzilla_noreply@suse.com 03 Jan '25
03 Jan '25
https://bugzilla.suse.com/show_bug.cgi?id=1226405
Bug ID: 1226405
Summary: Nautilus crash when opening multiple mp3 files
Classification: openSUSE
Product: openSUSE Aeon
Version: Current
Hardware: x86-64
OS: Other
Status: NEW
Severity: Minor
Priority: P5 - None
Component: Desktop Environment
Assignee: rbrown(a)suse.com
Reporter: thiagomagalhaes07(a)yahoo.com
QA Contact: qa-bugs(a)suse.de
Target Milestone: ---
Found By: ---
Blocker: ---
Created attachment 875506
--> https://bugzilla.suse.com/attachment.cgi?id=875506&action=edit
Crash example
Nautilus 46.2 crash when one tries to open multiple musics in some apps. The
crash happens when one tries to open 29 musics in "Clapper", "Celluloid",
"Music" and "Amberol", but works using "Rhythmbox" and "VLC". (all mentioned
apps in current flathub versions)
--
You are receiving this mail because:
You are on the CC list for the bug.
1
1
[Bug 1228416] New: Aeon RC3 (20240726) automatically unlocks partition even if kernel cmdline is modified
by bugzilla_noreply@suse.com 03 Jan '25
by bugzilla_noreply@suse.com 03 Jan '25
03 Jan '25
https://bugzilla.suse.com/show_bug.cgi?id=1228416
Bug ID: 1228416
Summary: Aeon RC3 (20240726) automatically unlocks partition
even if kernel cmdline is modified
Classification: openSUSE
Product: openSUSE Aeon
Version: Current
Hardware: x86-64
OS: Other
Status: NEW
Severity: Major
Priority: P5 - None
Component: Installation
Assignee: rbrown(a)suse.com
Reporter: philipp(a)nhus.de
QA Contact: qa-bugs(a)suse.de
Target Milestone: ---
Found By: ---
Blocker: ---
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101
Firefox/128.0
Build Identifier:
I've installed Aeon RC3 (Aeon-Installer.x86_64-0.1.0-Snapshot20240726.raw) on a
ThinkPad T14s AMD Gen1. The installation finished without any errors and Aeon
was installed in "Default" mode.
After booting the system, I wanted to see if it actually prevents booting if
the kernel cmdline is modified. So, I hit "e" in the systemd-boot menu, changed
the cmdline, and the system booted without asking for the recovery key, which I
did not expect.
I then checked the LUKS header with "cryptsetup luksDump <device>" which
reported the following:
tpm2-hash-pcrs: 7
tpm2-pcrlock: false
But pcrlock has to be enabled to prevent tampering of boot config on Aeon,
correct?
I then manually re-enrolled with
systemd-cryptenroll <device> --wipe-slot 2
systemd-cryptenroll <device> --tpm2-device auto
Afterwards, luksDump reports this:
tpm2-hash-pcrs: <empty>
tpm2-pcrlock: true
which is what I would expect. If I now try to modify the cmdline on boot, it
correctly asks for the recovery key.
I've reinstalled 3 times, always with the same behavior. I don't have a tik.log
on the stick after installation, is it not saved if the installation finished
successfully?
Reproducible: Always
Steps to Reproduce:
1. Install Aeon-Installer.x86_64-0.1.0-Snapshot20240726 from USB stick
2. Boot the system, set up initial user account & reboot
3. In systemd-boot, press "e" to edit the kernel cmdline, remove "quiet" from
the cmdline and boot
Actual Results:
System automatically unlocks partition without asking for recovery code.
Expected Results:
System refuses automatic unlocking of partition, because kernel cmdline has
changed. It asks for the recovery code to unlock.
--
You are receiving this mail because:
You are on the CC list for the bug.
1
5
[Bug 1230653] New: `transactional-update dup` snapshot boot failure, dracut-initqueue scripts 90-crypt.sh
by bugzilla_noreply@suse.com 03 Jan '25
by bugzilla_noreply@suse.com 03 Jan '25
03 Jan '25
https://bugzilla.suse.com/show_bug.cgi?id=1230653
Bug ID: 1230653
Summary: `transactional-update dup` snapshot boot failure,
dracut-initqueue scripts 90-crypt.sh
Classification: openSUSE
Product: openSUSE Aeon
Version: Current
Hardware: HP
OS: SUSE Other
Status: NEW
Severity: Major
Priority: P5 - None
Component: Transactional Update
Assignee: rbrown(a)suse.com
Reporter: toms.b.gm(a)gmail.com
QA Contact: qa-bugs(a)suse.de
Target Milestone: ---
Found By: ---
Blocker: ---
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:130.0) Gecko/20100101
Firefox/130.0
Build Identifier:
Can't boot latest snapshot after `transactional-update dup` when updating
slightly outdated packages (kernel 6.10.5-1) to latest packages (kernel
6.10.9-1) on default TPM FDE installation.
Reproducible: Didn't try
Steps to Reproduce:
1. Install and use OpenSUSE Aeon with slightly outdated packages (kernel
6.10.5-1), default TPM FDE installation
2. Update packages to latest version (kernel 6.10.9-1) via `sudo
transactional-update dup`
3. Reboot system via `sudo reboot`
Actual Results:
Black screen for 2 minutes before being spammed the following:
dracut-initqueue[546]: Warning: dracut-initqueue: starting timeout scripts
dracut-initqueue[546]: Warning: dracut-initqueue: timeout, still waiting for
following initqueue hooks:
dracut-initqueue[546]: Warning:
/lib/dracut/hooks/initqueue/finished/90-crypt.sh: "[ -e
/dev/disk/by-id/dm-uuid-CRYPT_LUKS?-*-1b0e3ea6054943698ceef6214d27717c*-* ] ||
exit 1"
dracut-initqueue[546]: Warning:
/lib/dracut/hooks/initqueue/finished/devexists-\x2fdev\x2fdisk\x2fby-uuid\x2ffba03bc2-e554-4abf-9864-208c541d469c.sh:
"[ -e "/dev/disk/by-uuid/fba03bc2-e554-4abf-9864-208c541d469c" ]"
After a minute of this, system seems to restart and repeat this.
Expected Results:
I expected it to fully boot to GDM login.
Output from `sudo sdbootutil -vv --ask-pin update-predictions`:
Found cgroup2 on /sys/fs/cgroup/, full unified hierarchy
Found container virtualization none.
Failed to check file system type of "/efi": No such file or directory
File system "/boot" is not a FAT EFI System Partition (ESP) file system.
Using EFI System Partition at /boot/efi.
Directory "/boot" is not the root of the file system.
Didn't find an XBOOTLDR partition, using the ESP as $BOOT.
Reading EFI variable
/sys/firmware/efi/efivars/LoaderEntries-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f.
Reading EFI variable
/sys/firmware/efi/efivars/LoaderEntryOneShot-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f.
open("/sys/firmware/efi/efivars/LoaderEntryOneShot-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f")
failed: No such file or directory
Reading EFI variable
/sys/firmware/efi/efivars/LoaderEntryDefault-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f.
Reading EFI variable
/sys/firmware/efi/efivars/LoaderEntrySelected-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f.
Found default: id "aeon-6.10.9-1-default-22.conf" is matched by
LoaderEntryDefault
TPM PC Client Platform Firmware Profile: family 2.0, revision 1.5
Found StartupLocality event: 3
Ignoring device path element type=0x02 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x03 subtype=0x17
Ignoring device path element type=0x04 subtype=0x01
Ignoring device path element type=0x02 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x03 subtype=0x17
Ignoring device path element type=0x04 subtype=0x01
Loaded 'libtss2-esys.so.0' via dlopen()
Loaded 'libtss2-rc.so.0' via dlopen()
Loaded 'libtss2-mu.so.0' via dlopen()
Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'.
Loaded 'libtss2-tcti-device.so.0' via dlopen()
Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux
kernel interface.) [Version 2]
TPM successfully started up.
Getting TPM2 capability 0x0000 property 0x0001 count 127.
Getting TPM2 capability 0x0002 property 0x011f count 256.
Getting TPM2 capability 0x0008 property 0x0000 count 508.
Getting TPM2 capability 0x0005 property 0x0000 count 1.
Reading PCR selection:
[sha256(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(0+1+2+3+4+5+6+7)]
PCR value:
0:sha256=7ffe0181383f43d8d3d105a1feab73f5fd93048e1116808c563387e6a227faaf
PCR value:
1:sha256=7bb778fcab821bf1f7abcffab3b5651909b68a9dbaffe1621bd8179634d34d78
PCR value:
2:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
3:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
4:sha256=aa4cb0dee0c0090784a3a14c8bd820effca45348739f3214acb9dc0cb00f681e
PCR value:
5:sha256=e5dd9b9e539ef55f889c79d0859ca1f6e05d2699929e25ec9d019e78eb3e5b30
PCR value:
6:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
7:sha256=fea1985302857b5a720ffa310e6d301b71d1097454dfce43a9635ee54b172353
Reading PCR selection: [sha256(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(8+9+10+11+12+13+14+15)]
PCR value:
8:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
9:sha256=93e4a5226b16f772db5c32c5f6a9db8dece27e6dce6b5353c1025171d5ffe638
PCR value:
10:sha256=2067d93034a8f0fcf26094fab932f5f9bd9410d3e9d012f264022a7ccb01f537
PCR value:
11:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
12:sha256=d50d6e4b5a2cf9dfe0a2a379609fc4c349db32ab3aaa2ebcc6382ea10d778f31
PCR value:
13:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
14:sha256=84344d7c9bd000dc7918460efc682a4040cfebdef7c6f1742b717e833df6b2bc
PCR value:
15:sha256=0000000000000000000000000000000000000000000000000000000000000000
Reading PCR selection: [sha256(16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(16+17+18+19+20+21+22+23)]
PCR value:
16:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
17:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
18:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
19:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
20:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
21:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
22:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
23:sha256=0000000000000000000000000000000000000000000000000000000000000000
/var/lib/pcrlock.d/250-firmware-code-early.pcrlock.d/generated.pcrlock written.
/var/lib/pcrlock.d/550-firmware-code-late.pcrlock.d/generated.pcrlock written.
TPM PC Client Platform Firmware Profile: family 2.0, revision 1.5
Found StartupLocality event: 3
Ignoring device path element type=0x02 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x03 subtype=0x17
Ignoring device path element type=0x04 subtype=0x01
Ignoring device path element type=0x02 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x03 subtype=0x17
Ignoring device path element type=0x04 subtype=0x01
Loaded 'libtss2-esys.so.0' via dlopen()
Loaded 'libtss2-rc.so.0' via dlopen()
Loaded 'libtss2-mu.so.0' via dlopen()
Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'.
Loaded 'libtss2-tcti-device.so.0' via dlopen()
Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux
kernel interface.) [Version 2]
TPM successfully started up.
Getting TPM2 capability 0x0000 property 0x0001 count 127.
Getting TPM2 capability 0x0002 property 0x011f count 256.
Getting TPM2 capability 0x0008 property 0x0000 count 508.
Getting TPM2 capability 0x0005 property 0x0000 count 1.
Reading PCR selection:
[sha256(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(0+1+2+3+4+5+6+7)]
PCR value:
0:sha256=7ffe0181383f43d8d3d105a1feab73f5fd93048e1116808c563387e6a227faaf
PCR value:
1:sha256=7bb778fcab821bf1f7abcffab3b5651909b68a9dbaffe1621bd8179634d34d78
PCR value:
2:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
3:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
4:sha256=aa4cb0dee0c0090784a3a14c8bd820effca45348739f3214acb9dc0cb00f681e
PCR value:
5:sha256=e5dd9b9e539ef55f889c79d0859ca1f6e05d2699929e25ec9d019e78eb3e5b30
PCR value:
6:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
7:sha256=fea1985302857b5a720ffa310e6d301b71d1097454dfce43a9635ee54b172353
Reading PCR selection: [sha256(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(8+9+10+11+12+13+14+15)]
PCR value:
8:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
9:sha256=93e4a5226b16f772db5c32c5f6a9db8dece27e6dce6b5353c1025171d5ffe638
PCR value:
10:sha256=2067d93034a8f0fcf26094fab932f5f9bd9410d3e9d012f264022a7ccb01f537
PCR value:
11:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
12:sha256=d50d6e4b5a2cf9dfe0a2a379609fc4c349db32ab3aaa2ebcc6382ea10d778f31
PCR value:
13:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
14:sha256=84344d7c9bd000dc7918460efc682a4040cfebdef7c6f1742b717e833df6b2bc
PCR value:
15:sha256=0000000000000000000000000000000000000000000000000000000000000000
Reading PCR selection: [sha256(16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(16+17+18+19+20+21+22+23)]
PCR value:
16:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
17:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
18:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
19:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
20:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
21:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
22:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
23:sha256=0000000000000000000000000000000000000000000000000000000000000000
/var/lib/pcrlock.d/250-firmware-config-early.pcrlock.d/generated.pcrlock
written.
/var/lib/pcrlock.d/550-firmware-config-late.pcrlock.d/generated.pcrlock
written.
/var/lib/pcrlock.d/600-gpt.pcrlock.d/generated.pcrlock written.
Hashing 216 @ 0 → 216
Hashing 76 @ 220 → 296
Hashing 720 @ 304 → 1024
Hashing 121856 @ 1024 → 122880
Hashing 394240 @ 122880 → 517120
Hashing 512 @ 517120 → 517632
Hashing 512 @ 517632 → 518144
Hashing 512 @ 518144 → 518656
Hashing 187392 @ 518656 → 706048
Hashing 7680 @ 706048 → 713728
Hashing 512 @ 713728 → 714240
Hashing 112128 @ 714240 → 826368
Hashing 512 @ 826368 → 826880
Hashing 127112 @ 826880 → 953992
Hashing 216 @ 0 → 216
Hashing 76 @ 220 → 296
Hashing 720 @ 304 → 1024
Hashing 121856 @ 1024 → 122880
Hashing 394240 @ 122880 → 517120
Hashing 512 @ 517120 → 517632
Hashing 512 @ 517632 → 518144
Hashing 512 @ 518144 → 518656
Hashing 187392 @ 518656 → 706048
Hashing 7680 @ 706048 → 713728
Hashing 512 @ 713728 → 714240
Hashing 112128 @ 714240 → 826368
Hashing 512 @ 826368 → 826880
Hashing 127112 @ 826880 → 953992
Hashing 216 @ 0 → 216
Hashing 76 @ 220 → 296
Hashing 720 @ 304 → 1024
Hashing 121856 @ 1024 → 122880
Hashing 394240 @ 122880 → 517120
Hashing 512 @ 517120 → 517632
Hashing 512 @ 517632 → 518144
Hashing 512 @ 518144 → 518656
Hashing 187392 @ 518656 → 706048
Hashing 7680 @ 706048 → 713728
Hashing 512 @ 713728 → 714240
Hashing 112128 @ 714240 → 826368
Hashing 512 @ 826368 → 826880
Hashing 127112 @ 826880 → 953992
Hashing 216 @ 0 → 216
Hashing 76 @ 220 → 296
Hashing 720 @ 304 → 1024
Hashing 121856 @ 1024 → 122880
Hashing 394240 @ 122880 → 517120
Hashing 512 @ 517120 → 517632
Hashing 512 @ 517632 → 518144
Hashing 512 @ 518144 → 518656
Hashing 187392 @ 518656 → 706048
Hashing 7680 @ 706048 → 713728
Hashing 512 @ 713728 → 714240
Hashing 112128 @ 714240 → 826368
Hashing 512 @ 826368 → 826880
Hashing 127112 @ 826880 → 953992
/var/lib/pcrlock.d/630-shim-efi-application.pcrlock.d/generated.pcrlock
written.
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 784 @ 240 → 1024
Hashing 75264 @ 1024 → 76288
Hashing 20480 @ 76288 → 96768
Hashing 512 @ 96768 → 97280
Hashing 512 @ 97280 → 97792
Hashing 512 @ 97792 → 98304
Hashing 512 @ 98304 → 98816
Hashing 512 @ 98816 → 99328
Hashing 0 @ 99328 → 99328
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 784 @ 240 → 1024
Hashing 75264 @ 1024 → 76288
Hashing 20480 @ 76288 → 96768
Hashing 512 @ 96768 → 97280
Hashing 512 @ 97280 → 97792
Hashing 512 @ 97792 → 98304
Hashing 512 @ 98304 → 98816
Hashing 512 @ 98816 → 99328
Hashing 0 @ 99328 → 99328
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 784 @ 240 → 1024
Hashing 75264 @ 1024 → 76288
Hashing 20480 @ 76288 → 96768
Hashing 512 @ 96768 → 97280
Hashing 512 @ 97280 → 97792
Hashing 512 @ 97792 → 98304
Hashing 512 @ 98304 → 98816
Hashing 512 @ 98816 → 99328
Hashing 0 @ 99328 → 99328
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 784 @ 240 → 1024
Hashing 75264 @ 1024 → 76288
Hashing 20480 @ 76288 → 96768
Hashing 512 @ 96768 → 97280
Hashing 512 @ 97280 → 97792
Hashing 512 @ 97792 → 98304
Hashing 512 @ 98304 → 98816
Hashing 512 @ 98816 → 99328
Hashing 0 @ 99328 → 99328
/var/lib/pcrlock.d/640-boot-loader-efi-application.pcrlock.d/generated.pcrlock
written.
/var/lib/pcrlock.d/641-sdboot-loader-conf.pcrlock written.
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 3856 @ 240 → 4096
Hashing 12288 @ 4096 → 16384
Hashing 4096 @ 16384 → 20480
Hashing 14745600 @ 20480 → 14766080
Hashing 4608 @ 14766080 → 14770688
Hashing 0 @ 14770688 → 14770688
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 3856 @ 240 → 4096
Hashing 12288 @ 4096 → 16384
Hashing 4096 @ 16384 → 20480
Hashing 14745600 @ 20480 → 14766080
Hashing 4608 @ 14766080 → 14770688
Hashing 0 @ 14770688 → 14770688
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 3856 @ 240 → 4096
Hashing 12288 @ 4096 → 16384
Hashing 4096 @ 16384 → 20480
Hashing 14745600 @ 20480 → 14766080
Hashing 4608 @ 14766080 → 14770688
Hashing 0 @ 14770688 → 14770688
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 3856 @ 240 → 4096
Hashing 12288 @ 4096 → 16384
Hashing 4096 @ 16384 → 20480
Hashing 14745600 @ 20480 → 14766080
Hashing 4608 @ 14766080 → 14770688
Hashing 0 @ 14770688 → 14770688
/var/lib/pcrlock.d/650-kernel-efi-application.pcrlock.d/linux-1.pcrlock
written.
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 3856 @ 240 → 4096
Hashing 12288 @ 4096 → 16384
Hashing 4096 @ 16384 → 20480
Hashing 14860288 @ 20480 → 14880768
Hashing 4608 @ 14880768 → 14885376
Hashing 0 @ 14885376 → 14885376
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 3856 @ 240 → 4096
Hashing 12288 @ 4096 → 16384
Hashing 4096 @ 16384 → 20480
Hashing 14860288 @ 20480 → 14880768
Hashing 4608 @ 14880768 → 14885376
Hashing 0 @ 14885376 → 14885376
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 3856 @ 240 → 4096
Hashing 12288 @ 4096 → 16384
Hashing 4096 @ 16384 → 20480
Hashing 14860288 @ 20480 → 14880768
Hashing 4608 @ 14880768 → 14885376
Hashing 0 @ 14885376 → 14885376
Hashing 152 @ 0 → 152
Hashing 76 @ 156 → 232
Hashing 3856 @ 240 → 4096
Hashing 12288 @ 4096 → 16384
Hashing 4096 @ 16384 → 20480
Hashing 14860288 @ 20480 → 14880768
Hashing 4608 @ 14880768 → 14885376
Hashing 0 @ 14885376 → 14885376
/var/lib/pcrlock.d/650-kernel-efi-application.pcrlock.d/linux-2.pcrlock
written.
/tmp/sdbootutil.9dnZ5i/cmdline.pcrlock written.
/var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-1.pcrlock
written.
/tmp/sdbootutil.9dnZ5i/cmdline.pcrlock written.
/var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-2.pcrlock
written.
/tmp/sdbootutil.9dnZ5i/cmdline.pcrlock written.
/var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-3.pcrlock
written.
Recovery PIN: TPM PC Client Platform Firmware Profile: family 2.0, revision 1.5
Found StartupLocality event: 3
Ignoring device path element type=0x02 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x03 subtype=0x17
Ignoring device path element type=0x04 subtype=0x01
Ignoring device path element type=0x02 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x01 subtype=0x01
Ignoring device path element type=0x03 subtype=0x17
Ignoring device path element type=0x04 subtype=0x01
Loaded 'libtss2-esys.so.0' via dlopen()
Loaded 'libtss2-rc.so.0' via dlopen()
Loaded 'libtss2-mu.so.0' via dlopen()
Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'.
Loaded 'libtss2-tcti-device.so.0' via dlopen()
Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux
kernel interface.) [Version 2]
TPM successfully started up.
Getting TPM2 capability 0x0000 property 0x0001 count 127.
Getting TPM2 capability 0x0002 property 0x011f count 256.
Getting TPM2 capability 0x0008 property 0x0000 count 508.
Getting TPM2 capability 0x0005 property 0x0000 count 1.
Reading PCR selection:
[sha256(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(0+1+2+3+4+5+6+7)]
PCR value:
0:sha256=7ffe0181383f43d8d3d105a1feab73f5fd93048e1116808c563387e6a227faaf
PCR value:
1:sha256=7bb778fcab821bf1f7abcffab3b5651909b68a9dbaffe1621bd8179634d34d78
PCR value:
2:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
3:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
4:sha256=aa4cb0dee0c0090784a3a14c8bd820effca45348739f3214acb9dc0cb00f681e
PCR value:
5:sha256=e5dd9b9e539ef55f889c79d0859ca1f6e05d2699929e25ec9d019e78eb3e5b30
PCR value:
6:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969
PCR value:
7:sha256=fea1985302857b5a720ffa310e6d301b71d1097454dfce43a9635ee54b172353
Reading PCR selection: [sha256(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(8+9+10+11+12+13+14+15)]
PCR value:
8:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
9:sha256=93e4a5226b16f772db5c32c5f6a9db8dece27e6dce6b5353c1025171d5ffe638
PCR value:
10:sha256=2067d93034a8f0fcf26094fab932f5f9bd9410d3e9d012f264022a7ccb01f537
PCR value:
11:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
12:sha256=d50d6e4b5a2cf9dfe0a2a379609fc4c349db32ab3aaa2ebcc6382ea10d778f31
PCR value:
13:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
14:sha256=84344d7c9bd000dc7918460efc682a4040cfebdef7c6f1742b717e833df6b2bc
PCR value:
15:sha256=0000000000000000000000000000000000000000000000000000000000000000
Reading PCR selection: [sha256(16+17+18+19+20+21+22+23)]
Read PCR selection: [sha256(16+17+18+19+20+21+22+23)]
PCR value:
16:sha256=0000000000000000000000000000000000000000000000000000000000000000
PCR value:
17:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
18:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
19:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
20:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
21:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
22:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff
PCR value:
23:sha256=0000000000000000000000000000000000000000000000000000000000000000
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
'content_type' missing from TPM measurement log file entry, ignoring.
Couldn't find component '710-kernel-cmdline-boot-loader' in event log.
Couldn't find component '750-enter-initrd' in event log.
Didn't find component '800-leave-initrd' in event log, assuming system hasn't
reached it yet.
Didn't find component '850-sysinit' in event log, assuming system hasn't
reached it yet.
Didn't find component '900-ready' in event log, assuming system hasn't reached
it yet.
Skipped 2 components after location '940-' (950-shutdown, 990-final).
Unable to recognize 2 components in event log.
Event log record 34 (PCR 5, "GPT: disk a8dbca6f-77a6-485c-8c67-b653758a8928")
not matching any component.
Event log record 30 (PCR 7, "Authority:
SbatLevel-605dab50-e046-4300-abb6-3dd810dd8b23") not matching any component.
Event log record 36 (PCR 12, "String:
initrd=\aeon\6.10.5-1-default\initrd-47ee25c3cff38e8c62d1fabbb864b2d002eaee0a
quiet loglevel=2 systemd.show_status=no console=ttyS0,115200 console=tty0
vt.global_cursor_default=0 ignition.platform.id=metal security=selinux
selinux=1 root=UUID=fba03bc2-e554-4abf-9864-208c541d469c
rootflags=subvol=(a)/.snapshots/19/snapshot
systemd.machine_id=cbe9f0d83488464891587d8f07c2c12b") not matching any
component.
Event log record 28 (PCR 14, "Raw: MokList\000") not matching any component.
PCR 0 (platform-code) matches event log and fully consists of recognized
measurements. Including in set of PCRs.
PCR 4 (boot-loader-code) matches event log and fully consists of recognized
measurements. Including in set of PCRs.
PCR 5 (boot-loader-config) event log contains unrecognized measurements.
Removing from set of PCRs.
PCR 7 (secure-boot-policy) event log contains unrecognized measurements.
Removing from set of PCRs.
PCR 9 (kernel-initrd) matches event log and fully consists of recognized
measurements. Including in set of PCRs.
PCRs dropped from protection mask: 5 (boot-loader-config), 7
(secure-boot-policy)
PCRs in protection mask: 0 (platform-code), 4 (boot-loader-code), 9
(kernel-initrd)
Added prediction result 1 for PCR 0 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 2 for PCR 0 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@600-0xffffffff:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 1 for PCR 4 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 2 for PCR 4 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-2:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 3 for PCR 4 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@600-0xffffffff:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 4 for PCR 4 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@600-0xffffffff:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-2:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 1 for PCR 9 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 2 for PCR 9 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-2:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Added prediction result 3 for PCR 9 (path:
240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-3:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready)
Predicted future PCRs in 1.502ms.
[
{
"pcr" : 0,
"values" : [
"7ffe0181383f43d8d3d105a1feab73f5fd93048e1116808c563387e6a227faaf",
"1b0debb8bcf768c08aa02b476fb113e98975989afedcf021bc400cc1f91d39ca"
]
},
{
"pcr" : 4,
"values" : [
"aa4cb0dee0c0090784a3a14c8bd820effca45348739f3214acb9dc0cb00f681e",
"1594d884537c303190e34ab6dbd6a51ad2ef51e0ab6da517e72d509db3765dda",
"df999a2508a52c3f455dda450d74bb6a09c441dc7af2f0d77d1bf3957d46f93c",
"dac23ce7ca141dab270aae4b12ddbf62500e3bafcc6901af5a43d2c516ddadf3"
]
},
{
"pcr" : 9,
"values" : [
"3d49d1580970ec40bcd1c76975c245a31547c1cd61008230f835d692b42029d5",
"93e4a5226b16f772db5c32c5f6a9db8dece27e6dce6b5353c1025171d5ffe638",
"37a8d8d1b6d4512401f87921577818e82fc7b2aa6981daceab1e612c9386bbed"
]
}
]
Prediction is identical to current policy, skipping update.
NVIndex policy created
--
You are receiving this mail because:
You are on the CC list for the bug.
1
2
[Bug 1229084] New: gdm does not recognize the keyboard layout
by bugzilla_noreply@suse.com 03 Jan '25
by bugzilla_noreply@suse.com 03 Jan '25
03 Jan '25
https://bugzilla.suse.com/show_bug.cgi?id=1229084
Bug ID: 1229084
Summary: gdm does not recognize the keyboard layout
Classification: openSUSE
Product: openSUSE Aeon
Version: Current
Hardware: x86-64
OS: Other
Status: NEW
Severity: Normal
Priority: P5 - None
Component: Desktop Environment
Assignee: rbrown(a)suse.com
Reporter: hotel-brot.0z(a)icloud.com
QA Contact: qa-bugs(a)suse.de
Target Milestone: ---
Found By: ---
Blocker: ---
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:129.0) Gecko/20100101
Firefox/129.0
Build Identifier:
Logs:
I do not know what kind of logs I could give you, but if you need some, you can
ask me and I will do my best.
Reproducible: Always
Steps to Reproduce:
1.Choose a non-US keyboard layout in gnome-control-center
2.Log out / reboot
3.Notice that the keyboard layout is not recognized.
Actual Results:
GDM is set to the US keyboard layout.
Expected Results:
GDM recognizes system settings
Workaround:
'localectl set-keymap $layout'
--
You are receiving this mail because:
You are on the CC list for the bug.
1
2
[Bug 1229060] New: Cannot access console root account is locked
by bugzilla_noreply@suse.com 03 Jan '25
by bugzilla_noreply@suse.com 03 Jan '25
03 Jan '25
https://bugzilla.suse.com/show_bug.cgi?id=1229060
Bug ID: 1229060
Summary: Cannot access console root account is locked
Classification: openSUSE
Product: openSUSE Aeon
Version: Current
Hardware: Other
OS: Other
Status: NEW
Severity: Normal
Priority: P5 - None
Component: Installation
Assignee: rbrown(a)suse.com
Reporter: ab.serv(a)mailbox.org
QA Contact: qa-bugs(a)suse.de
Target Milestone: ---
Found By: ---
Blocker: ---
When I attempted to install Aeon I had this prompt appear during the second
boot of the installer, after it had entered maintenance mode during the first
boot (issue #1229058). This error occurred when I installed Aeon on a cheap
32gb Sandisk Cruzer, but went away (or rather, went to #1229058) when I used a
nicer 64gb thumbdrive.
The Aeon installer image was downloaded yesterday (August 11 2024)
--
You are receiving this mail because:
You are on the CC list for the bug.
1
1
[Bug 1229058] New: Installation media & first boot enters maintenance mode
by bugzilla_noreply@suse.com 03 Jan '25
by bugzilla_noreply@suse.com 03 Jan '25
03 Jan '25
https://bugzilla.suse.com/show_bug.cgi?id=1229058
Bug ID: 1229058
Summary: Installation media & first boot enters maintenance
mode
Classification: openSUSE
Product: openSUSE Aeon
Version: Current
Hardware: x86-64
OS: Other
Status: NEW
Severity: Major
Priority: P5 - None
Component: Installation
Assignee: rbrown(a)suse.com
Reporter: ab.serv(a)mailbox.org
QA Contact: qa-bugs(a)suse.de
Target Milestone: ---
Found By: ---
Blocker: ---
Created attachment 876619
--> https://bugzilla.suse.com/attachment.cgi?id=876619&action=edit
journalctl --no-pager output during maintenance mode
When using the Aeon installation media, or booting Aeon for the first time, the
system enters maintenance mode.
I read rdsosreport.txt and I vaguely remember it said something about a block
device being mounted twice, so I'm hoping it'll be a simple fix.
--
You are receiving this mail because:
You are on the CC list for the bug.
1
3