Public bug reported:
Fresh install of Ubuntu 26.04 with encrypted LVM (LUKS) does not unlock the root
volume at boot. The system drops into the dracut emergency shell, with the root
LV never activated.
=== Host / VM environment ===
Host OS: Windows 11
Hypervisor: VMware Workstation <version, e.g. 17.6.x / 25H2>
Guest VM:
guest type: Ubuntu 64-bit
hardware compatibility: Workstation 25H2 or later
firmware: UEFI, Secure Boot DISABLED, no TPM device attached
CPU: 8 vCPU, RAM: 8 GB
virtual disk: 256 GB NVMe (single disk, "VMware Virtual NVMe Disk")
network: NAT
display: auto-detect, 3D acceleration: <on/off>
VMware Tools: "sync guest time with host" enabled
Guest OS:
Ubuntu 26.04 (Resolute Raccoon), installer media: 26.04.1 <desktop/server>
kernel: 7.0.0-<xx>-generic
dracut: <ver>, dracut-core: <ver>, initramfs-tools: <ver>, cryptsetup: <ver>
Install method: guided option "erase disk and encrypt" (LUKS + LVM), LUKS2,
passphrase only (no keyfile, no TPM token, no clevis).
Storage layout (lsblk -f):
/dev/nvme0n1p1 -> EFI System Partition, vfat, unencrypted
/dev/nvme0n1p2 -> /boot, ext4, unencrypted
/dev/nvme0n1p3 -> LUKS2 container "dm_crypt-0"
-> LVM VG "ubuntu-vg" / LV "ubuntu-lv" (root)
/etc/crypttab: dm_crypt-0 UUID=<uuid> none luks
=== Steps to reproduce ===
1. Create a VM with the configuration above, boot the Ubuntu 26.04 installer.
2. Use the guided option "encrypt the disk" (LUKS + LVM) with a passphrase.
3. Reboot.
=== Actual result ===
[FAILED] Failed to start systemd-cryptsetup@dm_crypt-0.service - Cryptography
Setup for dm_crypt-0
[DEPEND] Dependency failed for cryptsetup.target.
[DEPEND] Dependency failed for cryptsetup.target - Local Encrypted Volumes.
[ ** ] dev-mapper-ubuntu\x2dvg\x2dubuntu\x2dlv.device running (1min xx / no
limit)
then:
Warning: "/dev/mapper/ubuntu--vg-ubuntu--lv" does not exist
Warning: "/dev/ubuntu-vg/ubuntu-lv" does not exist
Entering emergency mode.
The LUKS container is never opened automatically, so the LVM VG on top of it is
never activated and the root LV never appears.
=== Expected result ===
The LUKS passphrase should be requested (or the volume unlocked automatically)
and the system should boot normally.
=== The passphrase is NOT the problem ===
The same passphrase unlocks the volume successfully:
- from the dracut emergency shell:
cryptsetup luksOpen /dev/nvme0n1p3 dm_crypt-0 -> works
vgchange -ay -> works
- from an Ubuntu 26.04 Live USB (cryptsetup luksOpen -> works)
=== Workaround ===
At the dracut emergency shell:
cryptsetup luksOpen /dev/nvme0n1p3 dm_crypt-0
vgchange -ay
# Ctrl-D to continue
Boot then completes. Rebuilding the initramfs manually with
"dracut --regenerate-all --force" also produces a bootable system, which
suggests the initrd / boot configuration generated at install time is the
problem, not the disk or the passphrase.
=== Findings on the installed system ===
/etc/default/grub GRUB_CMDLINE_LINUX_DEFAULT: <paste>
-> no rd.luks.uuid= present
/etc/dracut.conf.d/: <empty / list>
lsinitramfs /boot/initrd.img-$(uname -r) | grep -i cryptsetup: <paste>
=== Reproducibility ===
Fresh install in this VM: 100% reproducible (<N>/<N> attempts).
Same ISO on other hardware or with a different virtual disk type:
<tested/untested>
=== Note ===
This does not look like an isolated case. Similar failures with encrypted LVM on
26.04 are also reported in LP #2162931, LP #2157753 and LP #2161181.
Attachments: rdsosreport.txt, photo of the boot console.
** Affects: dracut (Ubuntu)
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168733
Title:
Encrypted LVM root not unlocked at boot on fresh 26.04 install, drops
to dracut emergency shell
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/dracut/+bug/2168733/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs