module intel_sgx appears to be blacklisted by the kernel.

Bug #1862201 reported by Bruce Campbell on 2020-02-06
16
This bug affects 2 people
Affects Status Importance Assigned to Milestone
linux-azure (Ubuntu)
Status tracked in Focal
Xenial
Undecided
Unassigned
Bionic
Undecided
Marcelo Cerri
Eoan
Undecided
Unassigned
Focal
Undecided
Unassigned

Bug Description

In the linux-0azure kernel 5.0.0.1029 the intel_Sgx driver has become blacklisted. The directories /etc/modlprobe.d and /etc/module_load.d

 systemctl status systemd-modules-load.service

indicates the driver is blacklisted
azureuser@brcamp-oe-ubu2:~/Projects/Azure-Compute-OpenEnclave-SecureRepro$ systemctl status systemd-modules-load.service
● systemd-modules-load.service - Load Kernel Modules
   Loaded: loaded (/lib/systemd/system/systemd-modules-load.service; static; vendor preset: enabled)
   Active: active (exited) since Tue 2020-02-04 19:42:29 UTC; 1 day 20h ago
     Docs: man:systemd-modules-load.service(8)
           man:modules-load.d(5)
  Process: 490 ExecStart=/lib/systemd/systemd-modules-load (code=exited, status=0/SUCCESS)
 Main PID: 490 (code=exited, status=0/SUCCESS)

This is affecting azure customers.

Joshua R. Poulson (jrp) wrote :

Looks like it is blacklisted in /lib/modprobe.d/blacklist_linux-azure_5.0.0-1029-azure.conf

Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in linux-azure (Ubuntu):
status: New → Confirmed
Marcelo Cerri (mhcerri) on 2020-02-06
Changed in linux-azure (Ubuntu Bionic):
status: New → In Progress
assignee: nobody → Marcelo Cerri (mhcerri)
Changed in linux-azure (Ubuntu Eoan):
status: New → In Progress
Changed in linux-azure (Ubuntu Xenial):
status: New → In Progress
Changed in linux-azure (Ubuntu Bionic):
status: In Progress → Fix Committed
Marcelo Cerri (mhcerri) wrote :

The fix for bionic:linux-azure is already committed and an official build was already triggered on the Canonical Kernel Team PPA.

An unofficial test build is also available at https://kernel.ubuntu.com/~mhcerri/azure/lp1862201/ (with a tarball with the debian packages available at https://kernel.ubuntu.com/~mhcerri/azure/lp1862201/linux-azure_5.0.0-1031.33_debs.tar.gz).

The solution was to revert the blacklist entry from the current version and divert to another location the .conf files from older kernels that blacklisted sgx. That means means it's necessary to install the new version and manually load the sgx module or reboot the system.

The changes are available at: https://git.launchpad.net/~canonical-kernel/ubuntu/+source/linux-azure/+git/bionic/log/?h=master-next

Launchpad Janitor (janitor) wrote :

This bug was fixed in the package linux-azure - 5.0.0-1031.33

---------------
linux-azure (5.0.0-1031.33) bionic; urgency=medium

  * bionic/linux-azure: 5.0.0-1031.33 -proposed tracker (LP: #1862239)

  * module intel_sgx appears to be blacklisted by the kernel. (LP: #1862201)
    - Revert "UBUNTU: [Packaging] linux-azure: Prevent intel_sgx from being
      automatically loaded"
    - [Packaging] linux-azure: Divert conf files blacklisting intel_sgx

  * Packaging resync (LP: #1786013)
    - [Packaging] update update.conf

 -- Marcelo Henrique Cerri <email address hidden> Thu, 06 Feb 2020 18:41:04 -0300

Changed in linux-azure (Ubuntu Bionic):
status: Fix Committed → Fix Released
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package linux-azure - 5.3.0-1012.13

---------------
linux-azure (5.3.0-1012.13) eoan; urgency=medium

  * eoan/linux-azure: 5.3.0-1012.13 -proposed tracker (LP: #1862350)

  * module intel_sgx appears to be blacklisted by the kernel. (LP: #1862201)
    - Revert "UBUNTU: [Packaging] linux-azure: Prevent intel_sgx from being
      automatically loaded"
    - [Packaging] linux-azure: Divert conf files blacklisting intel_sgx

 -- Marcelo Henrique Cerri <email address hidden> Fri, 07 Feb 2020 11:46:51 -0300

Changed in linux-azure (Ubuntu Eoan):
status: In Progress → Fix Released
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package linux-azure - 4.15.0-1069.74

---------------
linux-azure (4.15.0-1069.74) xenial; urgency=medium

  * xenial/linux-azure: 4.15.0-1069.74 -proposed tracker (LP: #1862355)

  * module intel_sgx appears to be blacklisted by the kernel. (LP: #1862201)
    - Revert "UBUNTU: [Packaging] linux-azure: Prevent intel_sgx from being
      automatically loaded"
    - [Packaging] linux-azure: Divert conf files blacklisting intel_sgx

 -- Marcelo Henrique Cerri <email address hidden> Fri, 07 Feb 2020 13:09:00 -0300

Changed in linux-azure (Ubuntu Xenial):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers