first boot after "TPM" install of mantic-desktop-canary-amd64.iso fails

Bug #2031576 reported by Brian Murray
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ubuntu CD Images
Fix Released
Undecided
Alfonso Sanchez-Beato

Bug Description

My TPM install of a mantic-desktop-canary-amd64.iso using serial 20230816.2 is stuck in a boot loop.

It is failing to mount proc-sys-fs-binfmt_misc.mount.

For what is worth this command line I used to test the image:

 $ virt-install --os-variant ubuntu22.04 --name ubuntu-canary-install --memory 4096 --disk /srv/vms/mantic-install.img --cdrom /misc/isos/ubuntu/mantic-desktop-canary-amd64.iso --machine q35 --features smm.state=on --boot loader=/usr/share/OVMF/OVMF_CODE.secboot.fd,loader.readonly=yes,loader.type=pflash,nvram.template=/usr/share/OVMF/OVMF_VARS.ms.fd,loader_secure=yes --tpm backend.type=emulator,backend.version=2.0,model=tpm-tis

summary: - first boot after "TPM" install of
- https://cdimage.ubuntu.com/ubuntu/daily-canary/20230816.2/mantic-
- desktop-canary-amd64.iso fails
+ first boot after "TPM" install of mantic-desktop-canary-amd64.iso fails
tags: added: cuqa-manual-testing
Revision history for this message
Brian Murray (brian-murray) wrote :
Changed in ubuntu-cdimage:
status: New → Confirmed
tags: added: fde
Revision history for this message
Alfonso Sanchez-Beato (alfonsosanchezbeato) wrote :
Changed in ubuntu-cdimage:
assignee: nobody → Alfonso Sanchez-Beato (alfonsosanchezbeato)
status: Confirmed → Fix Committed
Changed in ubuntu-cdimage:
status: Fix Committed → In Progress
Revision history for this message
Dimitri John Ledkov (xnox) wrote :

There is in-progress build of v6.4 kernel which should include pc-kernel snap builds.

Revision history for this message
Dimitri John Ledkov (xnox) wrote :

In mantic, kernel team has added the ability to produce self-signed kernel snaps, out of kernel team's build ppas, prior to completing secureboot verification and thus prior to the production secureboot signing.

The respin of a v6.4 kernel abi is now ready for amd64 in the stream2 build ppa, and a kernel snap is available for testing.

It is signed with the self-signed kernel team unstable secureboot certificate from https://ppa.launchpadcontent.net/canonical-kernel-team/unstable/ubuntu/dists/mantic/main/signed/linux-generate-amd64/6.4.0-2.2/signed.tar.gz

Please enroll that into DB prior to attempting installation.

Please use revision 1386 of pc-kernel, version 6.4.0.2.2 to verify if this issue is resolved. It is accessible from the following global store channel 23.10/edge/stream2 but also via manual inclusion (snap refresh --revision 1386 available publically, snap download --revision 1386 pc-kernel, or fetchable from launchpad librarian at https://launchpad.net/~canonical-kernel-snaps/+snap/mantic--linux--pc-kernel--edge--2/+build/2204108 )

This kernel snap was built using ubuntu-core-initramfs amd64 66+284+202308102031~ubuntu23.10.1 & snapd snapd 2.60.2+23.10.

Revision history for this message
Dan Bungert (dbungert) wrote (last edit ):

Rev 1386 of pc-kernel, plus the cert in the DB, looks like enough to solve this issue.
Attached is the procedure for updating for ISO for the above pc-kernel (more or less, I ran it in parts and threw this together, so the script might need tweaks)

Revision history for this message
Jean-Baptiste Lallement (jibel) wrote :

I'm closing this issue. 20230822.1 boots both on VM and HW even if there are missing modules and firmware.

Changed in ubuntu-cdimage:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.