[Bug 2119357] Re: "Syntax error at line 248 in generated grub.cfg.new in Ubuntu 25.04 (Plucky)"

2025-08-05 Thread Mate Kukri
> /etc/default/grub is clean Please share its contents, and that of /etc/default/grub.d as well anyways > , and there are no significant manual edits in /etc/grub.d/ Please also share any "insignificant" manual edits.. ** Changed in: grub2 (Ubuntu) Status: New => Incomplete -- You rece

[Bug 2112179] Re: Cannot pass unescaped double quotes to the linux command line

2025-08-01 Thread Mate Kukri
** Changed in: grub2 (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2112179 Title: Cannot pass unescaped double quotes to the linux command line To manage

[Bug 2116328] Re: iptables-netflow-dkms FTBFS in Questing with 6.15 kernel

2025-07-31 Thread Mate Kukri
Uploaded this, it seems reasonable. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2116328 Title: iptables-netflow-dkms FTBFS in Questing with 6.15 kernel To manage notifications about this bug go t

[Bug 2116712] Re: Sync lenovolegionlinux_0.0.19+git2025-02-20.43f2ad0e+ds-0.2ubuntu1 (universe) from Debian unstable (main)

2025-07-31 Thread Mate Kukri
I have synced this. ** Changed in: lenovolegionlinux (Ubuntu) Status: New => Fix Released ** Changed in: lenovolegionlinux (Ubuntu) Status: Fix Released => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. h

[Bug 2060695] Re: 24.04 grub-pc cannot upgrade on mirrored software RAID root disk

2025-07-31 Thread Mate Kukri
It looks like this might not be fixed in call cases: https://bugs.launchpad.net/ubuntu/+source/grub2/+bug/2119155 ** Changed in: subiquity (Ubuntu) Status: Fix Released => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2119155] Re: grub-pc cannot install on software raid1

2025-07-31 Thread Mate Kukri
Hmm okay in that case this is duplicate of https://bugs.launchpad.net/ubuntu/+source/grub2/+bug/2060695 and that bug should be re-opened as still not fixed. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bug

[Bug 2079866] Re: grub-pc configure fails during upgrade from 22.04 to 24.04

2025-07-31 Thread Mate Kukri
etups might brake in the future in other ways. Mate -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2079866 Title: grub-pc configure fails during upgrade from 22.04 to 24.04 To manage notifications about

[Bug 2118787] Re: [SRU] [noble] Rebuild cd-boot-images-* for .3

2025-07-31 Thread Mate Kukri
Everything was built against correct u-boot and grub. ** Tags removed: verification-needed verification-needed-noble ** Tags added: verification-done verification-done-noble -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs

[Bug 2119155] Re: grub-pc cannot install on software raid1

2025-07-31 Thread Mate Kukri
Try > echo "set grub-pc/cloud_style_installation false" | sudo debconf-communicate Then do > sudo dpkg-reconfigure grub-pc And select /dev/sda and /dev/sdb when asked for disks. That should fix this issue, but the question is, did this installation come from a cloud image? Or what media was used

[Bug 2079866] Re: grub-pc configure fails during upgrade from 22.04 to 24.04

2025-07-30 Thread Mate Kukri
I am just curious, how did you end up with this OS installation? We've seen a few like these before, it looks like it came from a cloud image, but it is on RAID? cloud_style_installation: true should only be set in cloud images for what it is worth. -- You received this bug notification because

[Bug 2079866] Re: grub-pc configure fails during upgrade from 22.04 to 24.04

2025-07-29 Thread Mate Kukri
Hmm i wonder how did you end with a raid setup on an installation that looks like it came from a cloud image? you can fix it by setting > echo "set grub-pc/cloud_style_installation false" | sudo debconf-communicate then doing > dpkg-reconfigure grub-pc -- You received this bug notification beca

[Bug 2118787] Re: [SRU] [noble] Rebuild cd-boot-images-* for .3

2025-07-29 Thread Mate Kukri
I believe that is the case for riscv binaries already, only arm binaries were held back, no? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2118787 Title: [SRU] [noble] Rebuild cd-boot-images-* for .

[Bug 2118787] Re: [SRU] [noble] Rebuild cd-boot-images-* for .3

2025-07-29 Thread Mate Kukri
Done riscv64 just now. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2118787 Title: [SRU] [noble] Rebuild cd-boot-images-* for .3 To manage notifications about this bug go to: https://bugs.launchpa

[Bug 2118787] Re: [SRU] [noble] Rebuild cd-boot-images-* for .3

2025-07-29 Thread Mate Kukri
I think I can upload risc-v as well know, the u-boot we are depending on for risc-v is already in updates, only arm64 was a problem which is not relevant for cd-boot-images-arm64 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://

[Bug 2118823] Re: package grub-efi-amd64 2.12-1ubuntu7.3 failed to install/upgrade: installed grub-efi-amd64 package post-installation script subprocess returned error exit status 1

2025-07-27 Thread Mate Kukri
Try `dpkg-reconfigure grub-efi-amd64` and select the correct disk Ubuntu is installed on when asked. This is either a case of the installation having been moved to a different disk, or possibly a case of https://bugs.launchpad.net/ubuntu/+source/grub2/+bug/2083176 -- You received this bug notifi

[Bug 2118787] [NEW] [SRU] [noble] Rebuild cd-boot-images-* for .3

2025-07-25 Thread Mate Kukri
Public bug reported: This isn't really a regular SRU, the bootloader assets in question are already part of noble and tested, these packages are just technical debt in the process of being eliminated. ** Affects: cd-boot-images-amd64 (Ubuntu) Importance: Undecided Status: New ** Af

[Bug 2116736] Re: [25.10 FEAT] Upgrade cryptsetup to latest v2.8.0

2025-07-25 Thread Mate Kukri
** Tags added: foundations-todo -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2116736 Title: [25.10 FEAT] Upgrade cryptsetup to latest v2.8.0 To manage notifications about this bug go to: https://b

[Bug 2116736] Re: [25.10 FEAT] Upgrade cryptsetup to latest v2.8.0

2025-07-25 Thread Mate Kukri
** Changed in: cryptsetup (Ubuntu) Status: Triaged => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2116736 Title: [25.10 FEAT] Upgrade cryptsetup to latest v2.8.0 To manage noti

Re: [Bug 2116736] Re: [25.10 FEAT] Upgrade cryptsetup to latest v2.8.0

2025-07-24 Thread Mate Kukri
I can probably do the merge from experimental unless someone already picked this up? On Wed, Jul 23, 2025 at 8:15 PM Sebastien Bacher <2116...@bugs.launchpad.net> wrote: > > ** Changed in: cryptsetup (Ubuntu) >Importance: Medium => High > > -- > You received this bug notification because you a

[Bug 1965983] Re: ZFS snapshots without etc directory causes grub.cfg build failure

2025-07-23 Thread Mate Kukri
Incomplete ** Changed in: grub2 (Ubuntu Jammy) Status: Triaged => Incomplete ** Tags removed: foundations-todo ** Changed in: grub2 (Ubuntu) Assignee: Mate Kukri (mkukri) => (unassigned) ** Changed in: grub2 (Ubuntu Focal) Assignee: Mate Kukri (mkukri) => (unassigned)

[Bug 2104316] Re: 25.04 beta TPMFDE: first boot failure

2025-07-23 Thread Mate Kukri
** Changed in: grub2 (Ubuntu) Status: New => In Progress ** Changed in: grub2 (Ubuntu) Assignee: (unassigned) => Mate Kukri (mkukri) ** Changed in: grub2 (Ubuntu) Importance: Undecided => Medium ** Summary changed: - 25.04 beta TPMFDE: first boot failure + grub2+sys

[Bug 2088181] Re: route_table_size is parsed as number of entries but it should be bytes

2025-07-23 Thread Mate Kukri
** Information type changed from Private to Public ** Changed in: grub2 (Ubuntu) Assignee: (unassigned) => Mate Kukri (mkukri) ** Changed in: grub2 (Ubuntu) Status: New => In Progress ** Changed in: grub2 (Ubuntu) Importance: Undecided => Low -- You received

[Bug 2106208] Re: Relocation overflow in GRUB when booting with RISC-V EDK II and emulating NUMA.

2025-07-22 Thread Mate Kukri
** Changed in: grub2 (Ubuntu) Assignee: Adriano Cordova Fedeli (adrianoco) => Mate Kukri (mkukri) ** Changed in: grub2 (Ubuntu Plucky) Assignee: Adriano Cordova Fedeli (adrianoco) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs, wh

[Bug 1940723] Re: GRUB (re)installation failing due to stale grub-{pc, efi}/install_devices (implement UUID based grub-install)

2025-07-21 Thread Mate Kukri
** Summary changed: - GRUB (re)installation failing due to stale grub-{pc,efi}/install_devices + GRUB (re)installation failing due to stale grub-{pc,efi}/install_devices (implement UUID based grub-install) -- You received this bug notification because you are a member of Ubuntu Bugs, which is s

[Bug 2055835] Re: GRUB 2025 spring security update

2025-07-21 Thread Mate Kukri
Only ESM updates are left which are tracked separately and will only land in the ESM ppa so marking those releases as 'Invalid' for archive uploads. ** Changed in: grub2-signed (Ubuntu Xenial) Status: New => Invalid ** Changed in: grub2-signed (Ubuntu Bionic) Status: New => Invalid

[Bug 2073634] Re: [SRU] Enable suppression of /EndEntire message

2025-07-21 Thread Mate Kukri
** Changed in: grub2 (Ubuntu Focal) Status: Fix Committed => Invalid ** Changed in: grub2 (Ubuntu Jammy) Status: Fix Committed => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/20

Re: [Bug 2116736] Re: [25.10 FEAT] Upgrade cryptsetup to latest v2.8.0

2025-07-11 Thread Mate Kukri
wrote: > > On ven. 11 juil. 2025 15:15:08, Mate Kukri wrote: > > We shouldn't be handling cryptsetup downstream, it should be updated in > > Debian first (which I am sure the maintainers are working on), then > > merged. > > No. That's only true if you ei

[Bug 2116736] Re: [25.10 FEAT] Upgrade cryptsetup to latest v2.8.0

2025-07-11 Thread Mate Kukri
We shouldn't be handling cryptsetup downstream, it should be updated in Debian first (which I am sure the maintainers are working on), then merged. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2116736

[Bug 2112584] Re: Stop using cd-boot-images-* in noble

2025-07-09 Thread Mate Kukri
** Description changed: [ Impact ]  * The aim of this bug is to stop using the package cd-boot-images-* in noble.    This has been done for plucky in LP: #2086841. This is similar, but an SRU. +  * Cd-boot-images caused a duplication of binary bootloader assets, resulting +in increas

[Bug 2112584] Re: Stop using cd-boot-images-* in noble

2025-07-09 Thread Mate Kukri
** Summary changed: - Please remove cd-boot-images-* from noble + Stop using cd-boot-images-* in noble -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2112584 Title: Stop using cd-boot-images-* in no

[Bug 2112584] Re: Please remove cd-boot-images-* from noble

2025-07-09 Thread Mate Kukri
Title still wrong rest okay. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2112584 Title: Please remove cd-boot-images-* from noble To manage notifications about this bug go to: https://bugs.launch

[Bug 2098641] Re: FAT filesystem probing fails if a file's timestamp exceeds 2038

2025-06-27 Thread Mate Kukri
Does not seem to affect kernel. ** No longer affects: linux-bluefield (Ubuntu) ** No longer affects: linux-bluefield (Ubuntu Focal) ** No longer affects: linux-bluefield (Ubuntu Jammy) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2098641] Re: FAT filesystem probing fails if a file's timestamp exceeds 2038

2025-06-26 Thread Mate Kukri
** Changed in: grub2-unsigned (Ubuntu) Status: New => Fix Released ** Changed in: grub2 (Ubuntu) Status: New => Won't Fix ** Changed in: grub2 (Ubuntu Jammy) Status: In Progress => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, whic

[Bug 2114143] Re: grub_drop_alloc called with wrong page count

2025-06-25 Thread Mate Kukri
So this definitely will not get a CVE, please post the patch to grub- devel mailing list. ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2114

[Bug 2064319] Re: Power guest secure boot with key management: GRUB2 portion

2025-06-16 Thread Mate Kukri
/en/latest/reference/services/signing/ The script that does the concatenation mentioned above is part of the grub2-signed source package which is provided in the previously discussed PPA (you can use apt source for example to acquire it). Mate -- You received this bug notification because you are a

[Bug 2114715] Re: package grub-efi-amd64-signed 1.187.12+2.06-2ubuntu14.8 failed to install/upgrade: installed grub-efi-amd64-signed package post-installation script subprocess returned error exit sta

2025-06-16 Thread Mate Kukri
This is not a setup created by the Ubuntu installer is it? I believe ESP on RAID is not created by the Ubuntu installer and not supported by GRUB2, please use multi ESP support we have for the same purpose. ** Changed in: grub2-signed (Ubuntu) Status: New => Incomplete -- You received t

[Bug 2112458] Re: package grub-efi-amd64 2.12-1ubuntu7.3 failed to install/upgrade: installed grub-efi-amd64 package post-installation script subprocess returned error exit status 127

2025-06-15 Thread Mate Kukri
Seems like your /etc/default/grub is corrupt, please double check that. ** Changed in: grub2-unsigned (Ubuntu) Status: Confirmed => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2112

[Bug 2112584] Re: Please remove cd-boot-images-* from noble

2025-06-11 Thread Mate Kukri
This is good, but grub2 MP needs to be re-filed against correct repo at https://code.launchpad.net/~ubuntu-core-dev/grub/+git/ubuntu. Also I am not sure if there is much benefit to actually removing the cd- boot-images packages (removal SRUs are super rare) in case a user relies on them, but updat

[Bug 1995751] Re: update to 2.04-1ubuntu47.4 drops zz-update-grub

2025-06-11 Thread Mate Kukri
** Changed in: grub2-unsigned (Ubuntu Bionic) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1995751 Title: update to 2.04-1ubuntu47.4 drops zz-update-grub

[Bug 1995751] Re: update to 2.04-1ubuntu47.4 drops zz-update-grub

2025-06-11 Thread Mate Kukri
** Changed in: grub2-unsigned (Ubuntu) Status: Confirmed => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1995751 Title: update to 2.04-1ubuntu47.4 drops zz-update-grub To manage not

[Bug 2112229] Re: failure during update package grub-efi-amd64-signed with RAID1

2025-06-03 Thread Mate Kukri
ESP on RAID is not supported in Ubuntu GRUB because we don't create such configurations. Unlike other distros, there is also no reason to do this because we have multi ESP support in the GRUB package. You can just RAID your regular filesystems and have two (or N) ESPs, one on each disks and GRUB

[Bug 2112229] Re: failure during update package grub-efi-amd64-signed with RAID1

2025-06-02 Thread Mate Kukri
Was this RAID setup created by the Ubuntu Installer, or did you create it yourself? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2112229 Title: failure during update package grub-efi-amd64-signed w

[Bug 2112179] Re: Cannot pass unescaped double quotes to the linux command line

2025-05-30 Thread Mate Kukri
** Tags added: foundations-todo ** Changed in: grub2 (Ubuntu) Assignee: (unassigned) => Mate Kukri (mkukri) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2112179 Title: Cannot pass unesca

[Bug 2064319] Re: Power guest secure boot with key management: GRUB2 portion

2025-05-27 Thread Mate Kukri
Yes I can look into picking up the new patches. Re: signature size allocation, the binary build and signing happens at different stages on purpose, so allocating the exact size is impossible, and one binary might even be signed with different keys. (Also extra space is intended to leave room for m

[Bug 2104316] Re: 25.04 beta TPMFDE: first boot failure

2025-05-13 Thread Mate Kukri
Hi Dann, I hope the bug this is trigerring will be fixed in the questing cycle and then we can re-enable the memory attribute protocol by default. I am not against syncing this now, but re-enabling NX by default might still cause problems with older distros/releases that wont carry all the necess

[Bug 1981127] Re: package nullboot 0.4.0-0ubuntu0.20.04.1 failed to install/upgrade: installed nullboot package post-installation script subprocess returned error exit status 1

2025-05-09 Thread Mate Kukri
nullboot on focal was beta only and this bug is 3 years old, so closing. if you are experiencing it on newer ubuntu and nullboot, please report a new bug. ** Changed in: nullboot (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bu

[Bug 2110302] [NEW] nullboot 0.5.3 SRUs

2025-05-09 Thread Mate Kukri
Public bug reported: [Impact] new upstream release; usual vendored dependency updates per Go MIR policy (vendor/ directory is automatically generated by go mod vendor based on go.mod). Targeted releases: noble, jammy [Test plan] * Test suite passes * Deploy Azure CVM and TPM FDE * Upgrade to t

[Bug 2064319] Re: Power guest secure boot with key management: GRUB2 portion

2025-05-07 Thread Mate Kukri
Yes everything with appended signatures built in that PPA is signed using that certificate. It should hopefully verify correctly, and can be used for testing, but please note that it is not to be used in production. Kind regards, Mate Kukri -- You received this bug notification because you are

[Bug 2104572] Re: Booting the daily noble RISC-V installer image fails

2025-04-28 Thread Mate Kukri
Uploaded again. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2104572 Title: Booting the daily noble RISC-V installer image fails To manage notifications about this bug go to: https://bugs.launchpa

[Bug 2064319] Re: Power guest secure boot with key management: GRUB2 portion

2025-04-25 Thread Mate Kukri
The test grub has a slightly older version number, you can install the exact versions using: apt install \ grub-ieee1275-signed=1.209.1+powersb7+2.12-5ubuntu7+powersb9 \ grub-ieee1275=2.12-5ubuntu7+powersb9 \ grub-ieee1275-bin=2.12-5ubuntu7+powersb9 \ grub-common=2.12-5ubuntu7+powersb9 \ grub2-com

[Bug 2106208] Re: Relocation overflow in GRUB when booting with RISC-V EDK II and emulating NUMA.

2025-04-24 Thread Mate Kukri
I don't believe this is an edk2 problem. The GRUB side will be resolved by picking up Vladimir's patch from grub- devel. ** No longer affects: edk2 (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/b

[Bug 2106208] Re: Relocation overflow in GRUB when booting with RISC-V EDK II and emulating NUMA.

2025-04-24 Thread Mate Kukri
Pushed a test build of phcoder's mshared patches to the uefi team build ppa -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2106208 Title: Relocation overflow in GRUB when booting with RISC-V EDK II a

[Bug 2055835] Re: GRUB 2025 spring security update

2025-04-23 Thread Mate Kukri
Verification done, test matrix here https://docs.google.com/document/d/1a5tlAWPNriB2JvvItAb- ISSYnQlcmdVm2mesuM2jC3c/edit?tab=t.0 ** Tags removed: verification-needed verification-needed-focal verification-needed-jammy verification-needed-noble verification-needed-oracular ** Tags added: verifica

[Bug 2107457] Re: Can't boot after installation with TPM backed FDE on xps9320

2025-04-16 Thread Mate Kukri
Can you try booting the hard-disk via the same boot menu you booted the installer from? Some devices unfortunately have issues where the boot UI is included in the measurements and if you autoboot the HDD without going through the menu it fails. -- You received this bug notification because you

[Bug 2107408] Re: do-release-upgrade on zfs encrypted, "/boot/efi doesn't look like an EFI partition"

2025-04-15 Thread Mate Kukri
** Changed in: grub2 (Ubuntu) Assignee: (unassigned) => Mate Kukri (mkukri) ** Tags added: foundations-todo -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2107408 Title: do-release-upgrade

[Bug 2104316] Re: 25.04 beta TPMFDE: first boot failure

2025-04-15 Thread Mate Kukri
This still needs a grub2 upload and systemd stub change to properly fix so i wouldnt remove, edk2 is only a workaround. ** Also affects: grub2 (Ubuntu) Importance: Undecided Status: New ** Also affects: systemd (Ubuntu) Importance: Undecided Status: New -- You received this

[Bug 2064319] Re: Power guest secure boot with key management: GRUB2 portion

2025-04-15 Thread Mate Kukri
My dev PPA can be added with add-apt-repository ppa:mkukri/dev-ppc64el -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2064319 Title: Power guest secure boot with key management: GRUB2 portion To m

[Bug 2106728] Re: grub-efi-arm64 fails with out of memory error on some hardware

2025-04-11 Thread Mate Kukri
This is waiting to be signed at https://bugs.launchpad.net/canonical- signing-jobs/+bug/2106805 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2106728 Title: grub-efi-arm64 fails with out of memory e

[Bug 2106728] Re: grub-efi-arm64 fails with out of memory error on some hardware

2025-04-10 Thread Mate Kukri
** Also affects: grub2-unsigned (Ubuntu) Importance: Undecided Status: New ** Also affects: grub2-signed (Ubuntu) Importance: Undecided Status: New ** Changed in: grub2-signed (Ubuntu Plucky) Milestone: None => ubuntu-25.04 ** Changed in: grub2-unsigned (Ubuntu Plucky)

[Bug 2104572] Re: Booting the daily noble RISC-V installer image fails

2025-04-10 Thread Mate Kukri
Ah the changelog entry post facto fixup was my bad, cleaned up the git history after the mistake in the original upload, but we can rid of that change. > The rootfs should be the only filesystem in the image containing a file named > /.disk/info. If not, we risk loading an incorrect filesystem. I

[Bug 2104316] Re: 25.04 beta TPMFDE: first boot failure

2025-04-05 Thread Mate Kukri
So update is im 99% sure this a is bad interaction between the systemd UKI stub and the memory attribute protocol... -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2104316 Title: 25.04 beta TPMFDE: f

[Bug 2055835] Re: GRUB 2025 spring security update

2025-04-04 Thread Mate Kukri
I made the judgement that picking up those patches alongside the new ones marked as security fixes has a lower overall regression potential compared to me trying to untangle the security fixes from the old(er) XFS patches. Perhaps not a perfect solution, but in GRUB world there never is, we've don

[Bug 2104316] Re: 25.04 beta TPMFDE: first boot failure

2025-04-04 Thread Mate Kukri
> This makes sense because other systems boot after all. Is this "borked hooking" only in newer systemds? (because Noble TPM FDE installs apparently work with plucky ovmf) Hmm I am not sure, I'll look into this in more detail as part of fixing this bug properly after edk2 workaround is done. > Yo

[Bug 2055835] Re: GRUB 2025 spring security update

2025-04-04 Thread Mate Kukri
Sorry the test plan perhaps could have been clearer: - The automated tests do _not_ currently include XFS. - "create an XFS /boot; boot from it" was part of the manual tests planned Updated test plan now. ** Description changed: Just to be clear this is now the tracking bug for all GRUB2 CVE f

[Bug 2106208] Re: Relocation overflow in GRUB when booting with RISC-V EDK II and emulating NUMA.

2025-04-04 Thread Mate Kukri
NUMA nodes usually represents two or more pieces of silicon, each with memory connected to them directly, but where both are also interconnected into a proper SMP system using some bus like DMI. Which means memory all memory is logically accessible to all processors same ways as UMA SMP system, bu

[Bug 2106208] Re: Relocation overflow in GRUB when booting with RISC-V EDK II and emulating NUMA.

2025-04-04 Thread Mate Kukri
I think NUMA here is just causing the memory map to have big enough holes in it, and the allocator to behave in such a way that some relocations will have addends that overflow a 32-bit signed slot. We had the same issue exposed by a 4GB memory limit here: https://bugs.launchpad.net/ubuntu/+source

[Bug 2055835] Re: GRUB 2025 spring security update

2025-04-03 Thread Mate Kukri
** Changed in: grub2-unsigned (Ubuntu Focal) Status: Incomplete => Fix Committed ** Changed in: grub2-unsigned (Ubuntu Jammy) Status: Incomplete => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bu

[Bug 2104316] Re: 25.04 beta TPMFDE: first boot failure

2025-04-03 Thread Mate Kukri
GRUB issue is that peimage tries to write relocations addends to read- only sections after setting them read only But i suspect fixing that will make the GRUB problem be the same as the firmware direct boot problem, so we nicely caught two bugs here. ** Changed in: edk2 (Ubuntu) Status

[Bug 2104316] Re: 25.04 beta TPMFDE: first boot failure

2025-04-03 Thread Mate Kukri
these are fixed. ** Also affects: systemd (Ubuntu) Importance: Undecided Status: New ** Also affects: grub2 (Ubuntu) Importance: Undecided Status: New ** Changed in: grub2 (Ubuntu) Assignee: (unassigned) => Mate Kukri (mkukri) ** Changed in: systemd (Ubuntu) Ass

[Bug 2104572] Re: Booting the daily noble RISC-V installer image fails

2025-03-31 Thread Mate Kukri
Uploaded noble with the version number change mentioned in the MP, and committed to ~ubuntu-core-dev/cd-boot-images-riscv64. If the same debian-cd breakage is happening on jammy and/or oracular, please file MPs for those too. -- You received this bug notification because you are a member of Ubun

[Bug 2104316] Re: 25.04 beta TPMFDE: first boot failure

2025-03-28 Thread Mate Kukri
** Tags added: foundations-todo ** Changed in: edk2 (Ubuntu) Assignee: (unassigned) => Mate Kukri (mkukri) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2104316 Title: 25.04 beta TPM

[Bug 2104316] Re: 25.04 beta TPMFDE: first boot failure

2025-03-28 Thread Mate Kukri
Also keep in mind that the /EndEntire message was simply removed from GRUB a while back, so that not showing up means nothing by itself. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2104316 Title:

[Bug 2104316] Re: 25.04 beta TPMFDE: first boot failure

2025-03-28 Thread Mate Kukri
I wouldn't discount an edk2 regression here, ive seen another recently too. Will try to look into this today. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2104316 Title: 25.04 beta TPMFDE: first b

[Bug 2104316] Re: 25.04 beta TPMFDE: first boot failure

2025-03-28 Thread Mate Kukri
Maybe the presence of the mem attr protocol triggers edk2 to change memory attributes to NX on allocated buffer for even explicitly non-NX images... We have an optional NX compat chain available in the shim package (that's off by default) and all this was tested a while ago, but at that point the

[Bug 2064319] Re: Power guest secure boot with key management: GRUB2 portion

2025-03-27 Thread Mate Kukri
Hello, Code https://code.launchpad.net/~ubuntu-uefi-team/grub/+git/ubuntu/+ref/power-sb My PPC test PPA (the power-sb ppa is out of date): https://launchpad.net/~mkukri/+archive/ubuntu/dev-ppc64el Signing key for the PPA above: https://ppa.launchpadcontent.net/mkukri/dev-ppc64el/ubuntu/dists/plu

[Bug 2101797] Re: built-in shell still present in AAVMF secboot image

2025-03-26 Thread Mate Kukri
** Changed in: edk2 (Ubuntu) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2101797 Title: built-in shell still present in AAVMF secboot image To manage

[Bug 2101797] Re: built-in shell still present in AAVMF secboot image

2025-03-26 Thread Mate Kukri
Branches for the noble and oracular fixes are here: https://code.launchpad.net/~ubuntu-core-dev/ubuntu/+source/edk2/+git/edk2/+ref/ubuntu/noble https://code.launchpad.net/~ubuntu-core-dev/ubuntu/+source/edk2/+git/edk2/+ref/ubuntu/oracular Seems like the SRU team wants this released as a security

[Bug 2103864] Re: grub-efi-riscv64-bin 2.12-5ubuntu9 fails with "relocation overflow"

2025-03-22 Thread Mate Kukri
But also we should test arm64 AAVMF VMs too, the laptops might be fine, but maybe AAVMF loads the core high? It is also possible that the arm64 module loader is correct in the sense that it allows modules to be loaded anywhere without overflowing relocations. ** Changed in: grub2 (Ubuntu)

[Bug 2103864] Re: grub-efi-riscv64-bin 2.12-5ubuntu9 fails with "relocation overflow"

2025-03-22 Thread Mate Kukri
It seems like risc-v EFI loads the core high, and restricting dynamic allocations <=4GB causes modules to be loaded low. Then the module loader tries to patch up some relocations with the delta between some symbols in the core and the module, but it fails due to the large offset. Modules should b

[Bug 2103864] Re: grub-efi-riscv64-bin 2.12-5ubuntu9 fails with "relocation overflow"

2025-03-22 Thread Mate Kukri
Welp, we need to remove the 4gb address limit on risc-v i think. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2103864 Title: grub-efi-riscv64-bin 2.12-5ubuntu9 fails with "relocation overflow" To

[Bug 2101797] Re: built-in shell still present in AAVMF secboot image

2025-03-21 Thread Mate Kukri
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2101797 Title: built-in shell still present in AAVMF secboot image To manage notif

[Bug 2055835] Re: GRUB 2025 spring security update

2025-03-19 Thread Mate Kukri
** Changed in: grub2-signed (Ubuntu Plucky) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2055835 Title: GRUB 2025 spring security update To manage noti

[Bug 2055835] Re: insmod reference count overflow (GRUB 2025 spring security update)

2025-03-19 Thread Mate Kukri
This was fixed in debian sid already. ** Description changed: + [ Impact ] + + * A large batch of secure boot CVEs in GRUB2 were fixed earlier this + year and recently un-embargoed earlier. + + * This has an obvious impact on everyone relying on Secure Boot for any + purpose. + + [ Test Plan

[Bug 2043084] Re: GRUB menu loading failure via HTTP Boot on BlueField

2025-03-19 Thread Mate Kukri
Was verified a long time ago and not released, but 14.8 will cumulatively include this fix, so mentioning this if and when a reviewer of that will inevitably run into this. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.l

[Bug 2073634] Re: [SRU] Enable suppression of /EndEntire message

2025-03-19 Thread Mate Kukri
This is all verified now, and because 14.8 will cumulatively include this fix, it is worth mentioning this if and when a reviewer of that will inevitably run into this. ** Tags removed: verification-needed verification-needed-focal verification-needed-jammy ** Tags added: verification-done verifi

[Bug 2103463] Re: [SRU] Repository profiles only act on .list files and do not affect .source files Edit

2025-03-19 Thread Mate Kukri
No doubt it isn't really on the radar for Landscape, but I would be inclined to include Oracular as well if this gets uploaded before Oracular goes EOL. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/21

[Bug 2055835] Re: insmod reference count overflow

2025-03-13 Thread Mate Kukri
affects: grub2-unsigned (Ubuntu Noble) Importance: Undecided Status: New ** Also affects: grub2-unsigned (Ubuntu Jammy) Importance: Undecided Status: New ** Also affects: grub2-unsigned (Ubuntu Plucky) Importance: Undecided Assignee: Mate Kukri (mkukri) Status: New

[Bug 2100783] Re: systemd-boot does not support an externally provided initrd on UKI

2025-03-11 Thread Mate Kukri
The overall security model of the CA on which we would sign such UKIs already allows loading external initrds without a UKI being used. This would be for the simple convenience of being able to use the stub purely as a (temporary) mechanism for signing dtbs and the kernel together, not to provide

[Bug 2069439] Re: edk2 2024.05-1 netboot regression

2025-03-11 Thread Mate Kukri
Hi Dann, News entry is fine by me, i've already worked around this for my usecase, but others might run into this as well. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2069439 Title: edk2 2024.05-1

[Bug 2099811] Re: Os-prober segmentation fault one message for each partition on same PC

2025-03-04 Thread Mate Kukri
> The grub file system drivers have a huge number of security issues and we should run them isolated, they should be using user namespaces, mount namespaces to hide / or have it all readonly, and like empty network namespaces so they can't phone home. No doubt about that, but in a perfect world e

[Bug 2099811] Re: Os-prober segmentation fault one message for each partition on same PC

2025-03-03 Thread Mate Kukri
Im gonna set this public if this is just an apparmor rule issue. ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2099811 Title: Os-prober s

[Bug 2100718] Re: GRUB2 Configuration Issue: GRUB_TIMEOUT_STYLE ignored when GRUB_RECORDFAIL_TIMEOUT is not set

2025-03-02 Thread Mate Kukri
What filesystem and/or device mapper container your /boot is located on? If /boot is not writable from GRUB the 30 second timeout is expected behaviour due to recordfail not working. A 30 second timeout should not happen if grub can write to /boot. -- You received this bug notification because

[Bug 2098748] Re: GRUB issue. Kubuntu have not fully support F2FS file system

2025-02-18 Thread Mate Kukri
The short answer is that we do not support an F2FS /boot filesystem and support is not built into signed monolithic GRUB for that reason. If you need to have an F2FS root partition, you can use a separate /boot with a supported file system as you suggested. If you insist on having F2FS as /boot,

[Bug 2098118] [NEW] 24.04.02 arm64 ISO, no graphical console on UTM

2025-02-12 Thread Mate Kukri
Public bug reported: Platform: UTM virtual machine on arm64 macOS ISO: 24.04.2 465 milestone build, arm64 server ISO. Issue: Console output only shows up on the serial port without manually specifying console=tty0. ** Affects: livecd-rootfs (Ubuntu) Importance: Undecided Status: N

[Bug 2097510] [NEW] serial.mod not included in signed GRUB2 for Jammy and older

2025-02-06 Thread Mate Kukri
Public bug reported: serial.mod not included in signed GRUB2 for Jammy and older. ** Affects: grub2 (Ubuntu) Importance: Undecided Assignee: Mate Kukri (mkukri) Status: New ** Tags: foundations-todo ** Tags added: foundations-todo ** Changed in: grub2 (Ubuntu

[Bug 2097317] Re: bpftrace: error while loading shared libraries: libLLVM-18.so.18.1: cannot open shared object file: No such file or directory

2025-02-05 Thread Mate Kukri
The debug counter crash is likely the same as https://bugs.launchpad.net/ubuntu/+source/bpftrace/+bug/2086104. Afaik this version of bpftrace has a linking issue against LLVM where it sometimes pulls in a static and a shared copy into the same process and when the versions mismatch it fails. Ther

[Bug 2073634] Re: [SRU] Enable suppression of /EndEntire message

2025-02-05 Thread Mate Kukri
** Changed in: grub2-signed (Ubuntu) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2073634 Title: [SRU] Enable suppression of /EndEntire message To mana

[Bug 2073634] Re: [SRU] Enable suppression of /EndEntire message

2025-02-05 Thread Mate Kukri
** Changed in: grub2-unsigned (Ubuntu Oracular) Status: New => Fix Released ** Changed in: grub2-unsigned (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bu

[Bug 2076651] Re: [SRU] Crash on RISC-V in virtual machine using KVM

2025-02-05 Thread Mate Kukri
** Changed in: grub2 (Ubuntu Noble) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2076651 Title: [SRU] Crash on RISC-V in virtual machine using KVM To m

[Bug 2073634] Re: [SRU] Enable suppression of /EndEntire message

2025-02-05 Thread Mate Kukri
** Changed in: grub2 (Ubuntu Noble) Status: In Progress => Fix Released ** Also affects: grub2-unsigned (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad

  1   2   3   4   5   6   7   8   9   10   >