[Bug 1234257] New: Recovery Key
https://bugzilla.suse.com/show_bug.cgi?id=1234257 Bug ID: 1234257 Summary: Recovery Key Classification: openSUSE Product: openSUSE Aeon Version: Current Hardware: Other OS: SUSE Other Status: NEW Severity: Major Priority: P5 - None Component: Base Assignee: rbrown@suse.com Reporter: christian.online.konto@posteo.de QA Contact: qa-bugs@suse.de Target Milestone: --- Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0 Build Identifier: Since ca. 1 Week my system allways asks for recovery key during start up. Moreover, i was not able to rollback by pressing "space" during startup. I executed the command in the documentation: troubleshooting, with following outcom: christian@linux:~> sudo sdbootutil -vv --ask-pin update-predictions Found cgroup2 on /sys/fs/cgroup/, full unified hierarchy Found container virtualization none. Failed to check file system type of "/efi": No such file or directory File system "/boot" is not a FAT EFI System Partition (ESP) file system. Using EFI System Partition at /boot/efi. Directory "/boot" is not the root of the file system. Didn't find an XBOOTLDR partition, using the ESP as $BOOT. Reading EFI variable /sys/firmware/efi/efivars/LoaderEntries-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f. Reading EFI variable /sys/firmware/efi/efivars/LoaderEntryOneShot-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f. open("/sys/firmware/efi/efivars/LoaderEntryOneShot-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f") failed: No such file or directory Reading EFI variable /sys/firmware/efi/efivars/LoaderEntryDefault-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f. Reading EFI variable /sys/firmware/efi/efivars/LoaderEntrySelected-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f. Found default: id "aeon-6.11.6-2-default-11.conf" is matched by LoaderEntryDefault TPM PC Client Platform Firmware Profile: family 2.0, revision 0.0 Ignoring device path element type=0x02 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x03 subtype=0x17 Ignoring device path element type=0x04 subtype=0x01 Ignoring device path element type=0x02 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x03 subtype=0x17 Ignoring device path element type=0x04 subtype=0x01 Garbage after device path end, ignoring. Loaded 'libtss2-esys.so.0' via dlopen() Loaded 'libtss2-rc.so.0' via dlopen() Loaded 'libtss2-mu.so.0' via dlopen() Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'. Loaded 'libtss2-tcti-device.so.0' via dlopen() Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux kernel interface.) [Version 2] TPM successfully started up. Getting TPM2 capability 0x0000 property 0x0001 count 127. Getting TPM2 capability 0x0002 property 0x011f count 256. Getting TPM2 capability 0x0008 property 0x0000 count 508. Getting TPM2 capability 0x0005 property 0x0000 count 1. Reading PCR selection: [sha1(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(0+1+2+3+4+5+6+7)] PCR value: 0:sha1=a5e6594ca83024ced25f1e1411d94c4c6f473e4d PCR value: 1:sha1=236f0adde857f76d3850fd2b7b5b476b45dcec1d PCR value: 2:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 3:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 4:sha1=6053244d4b6bc7689db30dfeb240ace4d9d8cc7c PCR value: 5:sha1=39ec830dded6f380442c66fc39402950e0515888 PCR value: 6:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 7:sha1=9d156b5060e1782e7a08a50edc099787bb5b8808 Reading PCR selection: [sha1(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(8+9+10+11+12+13+14+15)] PCR value: 8:sha1=0000000000000000000000000000000000000000 PCR value: 9:sha1=5d206dd55fab120f87f5e90be12247671f43dbb5 PCR value: 10:sha1=eeeb54af243451476c175567b6777f8bdf3f9267 PCR value: 11:sha1=0000000000000000000000000000000000000000 PCR value: 12:sha1=0be5b4015192d0870d540ebbccd826476a4adec6 PCR value: 13:sha1=0000000000000000000000000000000000000000 PCR value: 14:sha1=b17590499faebdbc6caa39fade7443dd9558ec4c PCR value: 15:sha1=0000000000000000000000000000000000000000 Reading PCR selection: [sha1(16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(16+17+18+19+20+21+22+23)] PCR value: 16:sha1=0000000000000000000000000000000000000000 PCR value: 17:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 18:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 19:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 20:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 21:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 22:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 23:sha1=0000000000000000000000000000000000000000 Reading PCR selection: [sha256(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(0+1+2+3+4+5+6+7)] PCR value: 0:sha256=45780482c5061afc3c5a69e6919df97cbceaa88770b3e38ce8799c0036ecb3d9 PCR value: 1:sha256=4796d8c56d2b67d23e38b446825ce3587a3352da64b624bc23ddc55aa94385ee PCR value: 2:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 3:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 4:sha256=5a81482ecfd85495d4872e92d371b543dad587f133c6da5d40ba280a7c703c10 PCR value: 5:sha256=7c4bcd38d84e40251e774f88e843df03686f1e50eb4815b6c0561efbd83c9875 PCR value: 6:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 7:sha256=89f8cf85f13654606ee65c392b3d7196f3b98fd5ac3e5ca8050b066ff112f1e2 Reading PCR selection: [sha256(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(8+9+10+11+12+13+14+15)] PCR value: 8:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 9:sha256=f5b1a3981235a042e4fd1699437c25feae1b860a137a457b331be86fa1d1e8ca PCR value: 10:sha256=b351e68af2d535d76899e72f6cb7eaad371ef70119521dc604a404b4c24d430d PCR value: 11:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 12:sha256=5a2f5fcbb372103f46bcb7e603a300416eace14ab0a8cf31d1f3124d92a8acfd PCR value: 13:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 14:sha256=da3b44ac2739fc95ec16ce931425812acb2fbb97fe9caf16520d388e03db02cf PCR value: 15:sha256=0000000000000000000000000000000000000000000000000000000000000000 Reading PCR selection: [sha256(16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(16+17+18+19+20+21+22+23)] PCR value: 16:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 17:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 18:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 19:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 20:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 21:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 22:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 23:sha256=0000000000000000000000000000000000000000000000000000000000000000 /var/lib/pcrlock.d/250-firmware-code-early.pcrlock.d/generated.pcrlock written. /var/lib/pcrlock.d/550-firmware-code-late.pcrlock.d/generated.pcrlock written. TPM PC Client Platform Firmware Profile: family 2.0, revision 0.0 Ignoring device path element type=0x02 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x03 subtype=0x17 Ignoring device path element type=0x04 subtype=0x01 Ignoring device path element type=0x02 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x03 subtype=0x17 Ignoring device path element type=0x04 subtype=0x01 Garbage after device path end, ignoring. Loaded 'libtss2-esys.so.0' via dlopen() Loaded 'libtss2-rc.so.0' via dlopen() Loaded 'libtss2-mu.so.0' via dlopen() Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'. Loaded 'libtss2-tcti-device.so.0' via dlopen() Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux kernel interface.) [Version 2] TPM successfully started up. Getting TPM2 capability 0x0000 property 0x0001 count 127. Getting TPM2 capability 0x0002 property 0x011f count 256. Getting TPM2 capability 0x0008 property 0x0000 count 508. Getting TPM2 capability 0x0005 property 0x0000 count 1. Reading PCR selection: [sha1(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(0+1+2+3+4+5+6+7)] PCR value: 0:sha1=a5e6594ca83024ced25f1e1411d94c4c6f473e4d PCR value: 1:sha1=236f0adde857f76d3850fd2b7b5b476b45dcec1d PCR value: 2:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 3:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 4:sha1=6053244d4b6bc7689db30dfeb240ace4d9d8cc7c PCR value: 5:sha1=39ec830dded6f380442c66fc39402950e0515888 PCR value: 6:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 7:sha1=9d156b5060e1782e7a08a50edc099787bb5b8808 Reading PCR selection: [sha1(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(8+9+10+11+12+13+14+15)] PCR value: 8:sha1=0000000000000000000000000000000000000000 PCR value: 9:sha1=5d206dd55fab120f87f5e90be12247671f43dbb5 PCR value: 10:sha1=eeeb54af243451476c175567b6777f8bdf3f9267 PCR value: 11:sha1=0000000000000000000000000000000000000000 PCR value: 12:sha1=0be5b4015192d0870d540ebbccd826476a4adec6 PCR value: 13:sha1=0000000000000000000000000000000000000000 PCR value: 14:sha1=b17590499faebdbc6caa39fade7443dd9558ec4c PCR value: 15:sha1=0000000000000000000000000000000000000000 Reading PCR selection: [sha1(16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(16+17+18+19+20+21+22+23)] PCR value: 16:sha1=0000000000000000000000000000000000000000 PCR value: 17:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 18:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 19:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 20:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 21:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 22:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 23:sha1=0000000000000000000000000000000000000000 Reading PCR selection: [sha256(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(0+1+2+3+4+5+6+7)] PCR value: 0:sha256=45780482c5061afc3c5a69e6919df97cbceaa88770b3e38ce8799c0036ecb3d9 PCR value: 1:sha256=4796d8c56d2b67d23e38b446825ce3587a3352da64b624bc23ddc55aa94385ee PCR value: 2:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 3:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 4:sha256=5a81482ecfd85495d4872e92d371b543dad587f133c6da5d40ba280a7c703c10 PCR value: 5:sha256=7c4bcd38d84e40251e774f88e843df03686f1e50eb4815b6c0561efbd83c9875 PCR value: 6:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 7:sha256=89f8cf85f13654606ee65c392b3d7196f3b98fd5ac3e5ca8050b066ff112f1e2 Reading PCR selection: [sha256(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(8+9+10+11+12+13+14+15)] PCR value: 8:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 9:sha256=f5b1a3981235a042e4fd1699437c25feae1b860a137a457b331be86fa1d1e8ca PCR value: 10:sha256=b351e68af2d535d76899e72f6cb7eaad371ef70119521dc604a404b4c24d430d PCR value: 11:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 12:sha256=5a2f5fcbb372103f46bcb7e603a300416eace14ab0a8cf31d1f3124d92a8acfd PCR value: 13:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 14:sha256=da3b44ac2739fc95ec16ce931425812acb2fbb97fe9caf16520d388e03db02cf PCR value: 15:sha256=0000000000000000000000000000000000000000000000000000000000000000 Reading PCR selection: [sha256(16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(16+17+18+19+20+21+22+23)] PCR value: 16:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 17:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 18:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 19:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 20:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 21:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 22:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 23:sha256=0000000000000000000000000000000000000000000000000000000000000000 /var/lib/pcrlock.d/250-firmware-config-early.pcrlock.d/generated.pcrlock written. /var/lib/pcrlock.d/550-firmware-config-late.pcrlock.d/generated.pcrlock written. /var/lib/pcrlock.d/600-gpt.pcrlock.d/generated.pcrlock written. Hashing 216 @ 0 → 216 Hashing 76 @ 220 → 296 Hashing 720 @ 304 → 1024 Hashing 121856 @ 1024 → 122880 Hashing 394240 @ 122880 → 517120 Hashing 512 @ 517120 → 517632 Hashing 512 @ 517632 → 518144 Hashing 512 @ 518144 → 518656 Hashing 187392 @ 518656 → 706048 Hashing 7680 @ 706048 → 713728 Hashing 512 @ 713728 → 714240 Hashing 112128 @ 714240 → 826368 Hashing 512 @ 826368 → 826880 Hashing 127112 @ 826880 → 953992 Hashing 216 @ 0 → 216 Hashing 76 @ 220 → 296 Hashing 720 @ 304 → 1024 Hashing 121856 @ 1024 → 122880 Hashing 394240 @ 122880 → 517120 Hashing 512 @ 517120 → 517632 Hashing 512 @ 517632 → 518144 Hashing 512 @ 518144 → 518656 Hashing 187392 @ 518656 → 706048 Hashing 7680 @ 706048 → 713728 Hashing 512 @ 713728 → 714240 Hashing 112128 @ 714240 → 826368 Hashing 512 @ 826368 → 826880 Hashing 127112 @ 826880 → 953992 Hashing 216 @ 0 → 216 Hashing 76 @ 220 → 296 Hashing 720 @ 304 → 1024 Hashing 121856 @ 1024 → 122880 Hashing 394240 @ 122880 → 517120 Hashing 512 @ 517120 → 517632 Hashing 512 @ 517632 → 518144 Hashing 512 @ 518144 → 518656 Hashing 187392 @ 518656 → 706048 Hashing 7680 @ 706048 → 713728 Hashing 512 @ 713728 → 714240 Hashing 112128 @ 714240 → 826368 Hashing 512 @ 826368 → 826880 Hashing 127112 @ 826880 → 953992 Hashing 216 @ 0 → 216 Hashing 76 @ 220 → 296 Hashing 720 @ 304 → 1024 Hashing 121856 @ 1024 → 122880 Hashing 394240 @ 122880 → 517120 Hashing 512 @ 517120 → 517632 Hashing 512 @ 517632 → 518144 Hashing 512 @ 518144 → 518656 Hashing 187392 @ 518656 → 706048 Hashing 7680 @ 706048 → 713728 Hashing 512 @ 713728 → 714240 Hashing 112128 @ 714240 → 826368 Hashing 512 @ 826368 → 826880 Hashing 127112 @ 826880 → 953992 /var/lib/pcrlock.d/630-shim-efi-application.pcrlock.d/generated.pcrlock written. Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 784 @ 240 → 1024 Hashing 80896 @ 1024 → 81920 Hashing 20480 @ 81920 → 102400 Hashing 512 @ 102400 → 102912 Hashing 512 @ 102912 → 103424 Hashing 512 @ 103424 → 103936 Hashing 512 @ 103936 → 104448 Hashing 512 @ 104448 → 104960 Hashing 0 @ 104960 → 104960 Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 784 @ 240 → 1024 Hashing 80896 @ 1024 → 81920 Hashing 20480 @ 81920 → 102400 Hashing 512 @ 102400 → 102912 Hashing 512 @ 102912 → 103424 Hashing 512 @ 103424 → 103936 Hashing 512 @ 103936 → 104448 Hashing 512 @ 104448 → 104960 Hashing 0 @ 104960 → 104960 Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 784 @ 240 → 1024 Hashing 80896 @ 1024 → 81920 Hashing 20480 @ 81920 → 102400 Hashing 512 @ 102400 → 102912 Hashing 512 @ 102912 → 103424 Hashing 512 @ 103424 → 103936 Hashing 512 @ 103936 → 104448 Hashing 512 @ 104448 → 104960 Hashing 0 @ 104960 → 104960 Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 784 @ 240 → 1024 Hashing 80896 @ 1024 → 81920 Hashing 20480 @ 81920 → 102400 Hashing 512 @ 102400 → 102912 Hashing 512 @ 102912 → 103424 Hashing 512 @ 103424 → 103936 Hashing 512 @ 103936 → 104448 Hashing 512 @ 104448 → 104960 Hashing 0 @ 104960 → 104960 /var/lib/pcrlock.d/640-boot-loader-efi-application.pcrlock.d/generated.pcrlock written. /var/lib/pcrlock.d/641-sdboot-loader-conf.pcrlock written. Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 3856 @ 240 → 4096 Hashing 12288 @ 4096 → 16384 Hashing 4096 @ 16384 → 20480 Hashing 14905344 @ 20480 → 14925824 Hashing 4608 @ 14925824 → 14930432 Hashing 0 @ 14930432 → 14930432 Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 3856 @ 240 → 4096 Hashing 12288 @ 4096 → 16384 Hashing 4096 @ 16384 → 20480 Hashing 14905344 @ 20480 → 14925824 Hashing 4608 @ 14925824 → 14930432 Hashing 0 @ 14930432 → 14930432 Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 3856 @ 240 → 4096 Hashing 12288 @ 4096 → 16384 Hashing 4096 @ 16384 → 20480 Hashing 14905344 @ 20480 → 14925824 Hashing 4608 @ 14925824 → 14930432 Hashing 0 @ 14930432 → 14930432 Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 3856 @ 240 → 4096 Hashing 12288 @ 4096 → 16384 Hashing 4096 @ 16384 → 20480 Hashing 14905344 @ 20480 → 14925824 Hashing 4608 @ 14925824 → 14930432 Hashing 0 @ 14930432 → 14930432 /var/lib/pcrlock.d/650-kernel-efi-application.pcrlock.d/linux-1.pcrlock written. /tmp/sdbootutil.cgIsmU/cmdline.pcrlock written. /var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-1.pcrlock written. /tmp/sdbootutil.cgIsmU/cmdline.pcrlock written. /var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-2.pcrlock written. /tmp/sdbootutil.cgIsmU/cmdline.pcrlock written. /var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-3.pcrlock written. Recovery PIN: TPM PC Client Platform Firmware Profile: family 2.0, revision 0.0 Ignoring device path element type=0x02 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x03 subtype=0x17 Ignoring device path element type=0x04 subtype=0x01 Ignoring device path element type=0x02 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x03 subtype=0x17 Ignoring device path element type=0x04 subtype=0x01 Garbage after device path end, ignoring. Loaded 'libtss2-esys.so.0' via dlopen() Loaded 'libtss2-rc.so.0' via dlopen() Loaded 'libtss2-mu.so.0' via dlopen() Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'. Loaded 'libtss2-tcti-device.so.0' via dlopen() Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux kernel interface.) [Version 2] TPM successfully started up. Getting TPM2 capability 0x0000 property 0x0001 count 127. Getting TPM2 capability 0x0002 property 0x011f count 256. Getting TPM2 capability 0x0008 property 0x0000 count 508. Getting TPM2 capability 0x0005 property 0x0000 count 1. Reading PCR selection: [sha1(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(0+1+2+3+4+5+6+7)] PCR value: 0:sha1=a5e6594ca83024ced25f1e1411d94c4c6f473e4d PCR value: 1:sha1=236f0adde857f76d3850fd2b7b5b476b45dcec1d PCR value: 2:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 3:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 4:sha1=6053244d4b6bc7689db30dfeb240ace4d9d8cc7c PCR value: 5:sha1=39ec830dded6f380442c66fc39402950e0515888 PCR value: 6:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 7:sha1=9d156b5060e1782e7a08a50edc099787bb5b8808 Reading PCR selection: [sha1(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(8+9+10+11+12+13+14+15)] PCR value: 8:sha1=0000000000000000000000000000000000000000 PCR value: 9:sha1=5d206dd55fab120f87f5e90be12247671f43dbb5 PCR value: 10:sha1=eeeb54af243451476c175567b6777f8bdf3f9267 PCR value: 11:sha1=0000000000000000000000000000000000000000 PCR value: 12:sha1=0be5b4015192d0870d540ebbccd826476a4adec6 PCR value: 13:sha1=0000000000000000000000000000000000000000 PCR value: 14:sha1=b17590499faebdbc6caa39fade7443dd9558ec4c PCR value: 15:sha1=0000000000000000000000000000000000000000 Reading PCR selection: [sha1(16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(16+17+18+19+20+21+22+23)] PCR value: 16:sha1=0000000000000000000000000000000000000000 PCR value: 17:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 18:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 19:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 20:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 21:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 22:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 23:sha1=0000000000000000000000000000000000000000 Reading PCR selection: [sha256(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(0+1+2+3+4+5+6+7)] PCR value: 0:sha256=45780482c5061afc3c5a69e6919df97cbceaa88770b3e38ce8799c0036ecb3d9 PCR value: 1:sha256=4796d8c56d2b67d23e38b446825ce3587a3352da64b624bc23ddc55aa94385ee PCR value: 2:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 3:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 4:sha256=5a81482ecfd85495d4872e92d371b543dad587f133c6da5d40ba280a7c703c10 PCR value: 5:sha256=7c4bcd38d84e40251e774f88e843df03686f1e50eb4815b6c0561efbd83c9875 PCR value: 6:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 7:sha256=89f8cf85f13654606ee65c392b3d7196f3b98fd5ac3e5ca8050b066ff112f1e2 Reading PCR selection: [sha256(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(8+9+10+11+12+13+14+15)] PCR value: 8:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 9:sha256=f5b1a3981235a042e4fd1699437c25feae1b860a137a457b331be86fa1d1e8ca PCR value: 10:sha256=b351e68af2d535d76899e72f6cb7eaad371ef70119521dc604a404b4c24d430d PCR value: 11:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 12:sha256=5a2f5fcbb372103f46bcb7e603a300416eace14ab0a8cf31d1f3124d92a8acfd PCR value: 13:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 14:sha256=da3b44ac2739fc95ec16ce931425812acb2fbb97fe9caf16520d388e03db02cf PCR value: 15:sha256=0000000000000000000000000000000000000000000000000000000000000000 Reading PCR selection: [sha256(16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(16+17+18+19+20+21+22+23)] PCR value: 16:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 17:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 18:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 19:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 20:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 21:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 22:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 23:sha256=0000000000000000000000000000000000000000000000000000000000000000 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. Couldn't find component '350-action-efi-application' in event log. Couldn't find component '710-kernel-cmdline-boot-loader' in event log. Couldn't find component '750-enter-initrd' in event log. Didn't find component '800-leave-initrd' in event log, assuming system hasn't reached it yet. Didn't find component '850-sysinit' in event log, assuming system hasn't reached it yet. Didn't find component '900-ready' in event log, assuming system hasn't reached it yet. Skipped 2 components after location '940-' (950-shutdown, 990-final). Unable to recognize 3 components in event log. Event log record 26 (PCR 4, "File: \EFI\BOOT\fallback.efi") not matching any component. Event log record 27 (PCR 5, "GPT: disk d7ad8d10-63e2-4e69-ae86-ffa82c400580") not matching any component. Event log record 37 (PCR 12, "String: initrd=\aeon\6.11.6-2-default\initrd-a31022ed03b53c96e752a8ebac4b5ef5822b6206 quiet loglevel=2 systemd.show_status=no console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root rootflags=subvol=@/.snapshots/10/snapshot systemd.machine_id=a23922751ab84104995531cbb65c8184") not matching any component. Event log record 21 (PCR 14, "Raw: MokList\000") not matching any component. PCR 0 (platform-code) matches event log and fully consists of recognized measurements. Including in set of PCRs. PCR 4 (boot-loader-code) event log contains unrecognized measurements. Removing from set of PCRs. PCR 5 (boot-loader-config) event log contains unrecognized measurements. Removing from set of PCRs. PCR 7 (secure-boot-policy) matches event log and fully consists of recognized measurements. Including in set of PCRs. PCR 9 (kernel-initrd) matches event log and fully consists of recognized measurements. Including in set of PCRs. PCRs dropped from protection mask: 4 (boot-loader-code), 5 (boot-loader-config) PCRs in protection mask: 0 (platform-code), 7 (secure-boot-policy), 9 (kernel-initrd) Added prediction result 1 for PCR 0 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 2 for PCR 0 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@600-0xffffffff:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 1 for PCR 7 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 2 for PCR 7 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@600-0xffffffff:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 1 for PCR 9 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 2 for PCR 9 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-2:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 3 for PCR 9 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-3:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Predicted future PCRs in 1.733ms. [{"pcr":0,"values":["45780482c5061afc3c5a69e6919df97cbceaa88770b3e38ce8799c0036ecb3d9","391db98152fefe64d6687212f796ba0129d87b443b50fcd3dad6c7acc145cb7f"]},{"pcr":7,"values":["89f8cf85f13654606ee65c392b3d7196f3b98fd5ac3e5ca8050b066ff112f1e2","34b268ab4129a7c3860d73e81817f8773355d69cda169f03457b20205f043335"]},{"pcr":9,"values":["23b47b3d6b07f4a5bf57adf715df67b810fc74761f804a6cd68403218715a2e0","f5b1a3981235a042e4fd1699437c25feae1b860a137a457b331be86fa1d1e8ca","d51686c14e01814d7f70c99ee7057f733820ab7db2e4843443de3813baca7278"]}] Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'. Loaded 'libtss2-tcti-device.so.0' via dlopen() Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux kernel interface.) [Version 2] TPM successfully started up. Getting TPM2 capability 0x0000 property 0x0001 count 127. Getting TPM2 capability 0x0002 property 0x011f count 256. Getting TPM2 capability 0x0008 property 0x0000 count 508. Getting TPM2 capability 0x0005 property 0x0000 count 1. Starting HMAC encryption session. Converting PIN into TPM2 HMAC-SHA256 object. Loading external key into TPM. Starting policy session. Submitting PolicySigned policy for HMAC-SHA256. Acquiring policy digest. Session policy digest: e70c3cd74d038f5b68569046c24688e76181591da188296f73d2a4343ba29281 Calculating new PCR policy to write... PolicyPCR calculated digest: ef172d5c57215186c0acf7ca31d7f8c5f4335b2c9d8a336387069368b2fccd8d Calculated PCR policy variant 1 for PCR 0 PolicyPCR calculated digest: 0166f33f1815b0d786a4f417e4c5b710a5330e1e816cf8549c28218c883e3b6f Calculated PCR policy variant 2 for PCR 0 OR Branch #0: ef172d5c57215186c0acf7ca31d7f8c5f4335b2c9d8a336387069368b2fccd8d OR Branch #1: 0166f33f1815b0d786a4f417e4c5b710a5330e1e816cf8549c28218c883e3b6f PolicyOR calculated digest: 0f27551403bf99c82a1d30b3af430441c01acca2c471e24f222f35522232ef59 Combined 2 variants in OR policy. PolicyPCR calculated digest: 00d1418a8a2c95be955e6a3bbd005d113c1d0b3927574cc8b3a74aa3e122cbed Calculated PCR policy variant 1 for PCR 7 PolicyPCR calculated digest: 4fc4286b26809dab057f3ef6bcfd7e510b4723ac432e9f3a7ab65c9b506bdb84 Calculated PCR policy variant 2 for PCR 7 OR Branch #0: 00d1418a8a2c95be955e6a3bbd005d113c1d0b3927574cc8b3a74aa3e122cbed OR Branch #1: 4fc4286b26809dab057f3ef6bcfd7e510b4723ac432e9f3a7ab65c9b506bdb84 PolicyOR calculated digest: 245d5e7d899391dc0f118a3f9065591556f0555e6eeea30810dcd49603a6d3e2 Combined 2 variants in OR policy. PolicyPCR calculated digest: f195b1c1c23e8e43a41e611153f3020e1dc1bb257e1909418827d51666bb9ac4 Calculated PCR policy variant 1 for PCR 9 PolicyPCR calculated digest: c5df80d5630effd688ac4c41889519ca2569ba7a9fbb8024b95baadb1407e83b Calculated PCR policy variant 2 for PCR 9 PolicyPCR calculated digest: c633361a0e4c7505b4751e52d7b1cb4799679b68e3b5fa19083e4407763e6799 Calculated PCR policy variant 3 for PCR 9 OR Branch #0: f195b1c1c23e8e43a41e611153f3020e1dc1bb257e1909418827d51666bb9ac4 OR Branch #1: c5df80d5630effd688ac4c41889519ca2569ba7a9fbb8024b95baadb1407e83b OR Branch #2: c633361a0e4c7505b4751e52d7b1cb4799679b68e3b5fa19083e4407763e6799 PolicyOR calculated digest: 02490c290dbf129b4446863e9c8ab4eb6062610134f032e357171174a9c024c2 Combined 3 variants in OR policy. Calculated new PCR policy in 300us. Writing new PCR policy to NV index... WARNING:esys:src/tss2-esys/api/Esys_NV_Write.c:310:Esys_NV_Write_Finish() Received TPM Error ERROR:esys:src/tss2-esys/api/Esys_NV_Write.c:110:Esys_NV_Write() Esys Finish ErrorCode (0x0000099d) Failed to write NV index: tpm:session(1):a policy check failed Failed to write to NV index: State not recoverable Reproducible: Always Steps to Reproduce: 1.Start system 2.Enter recovery key 3.Welcome screen -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com