grub_efi_secure_boot signal at the beginning of the boot process

Bug #1744979 reported by csola48
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
linux (Ubuntu)
Confirmed
High
Unassigned

Bug Description

The previous kernel (4.4.0-109) was running without any problems, without triggering an error.
After today's kernel update, the machine can not be started unless you select "run" the selected kernel from the advanced settings menu item.
The first message always: grub_efi_secure_boot

Ubuntu 4.4.0-112.135-generic 4.4.98
LSB Version: core-9.20160110ubuntu0.2-ia32:core-9.20160110ubuntu0.2-noarch:security-9.20160110ubuntu0.2-ia32:security-9.20160110ubuntu0.2-noarch
Distributor ID: Ubuntu
Description: Ubuntu 16.04.3 LTS
Release: 16.04
Codename: xenial

Intel® Core™ i5-3330 CPU @ 3.00GHz × 4
GeForce GT 630/PCIe/SSE2
system 32 bit

Please help...
I chose 16.04 LTS because I wanted to have a long, calm and safe use ...
---
ApportVersion: 2.20.1-0ubuntu2.15
Architecture: i386
AudioDevicesInUse:
 USER PID ACCESS COMMAND
 /dev/snd/controlC1: csola48 1454 F.... pulseaudio
 /dev/snd/controlC2: csola48 1454 F.... pulseaudio
 /dev/snd/controlC0: csola48 1454 F.... pulseaudio
CurrentDesktop: Unity
DistroRelease: Ubuntu 16.04
HibernationDevice: RESUME=UUID=6c8c77a4-d4d3-4e31-a038-13930e1abfd0
InstallationDate: Installed on 2016-11-08 (441 days ago)
InstallationMedia: Ubuntu 16.04 LTS "Xenial Xerus" - Release i386 (20160420.1)
IwConfig:
 lo no wireless extensions.

 enp4s0 no wireless extensions.
MachineType: Gigabyte Technology Co., Ltd. To be filled by O.E.M.
NonfreeKernelModules: nvidia_drm nvidia_modeset nvidia
Package: linux (not installed)
ProcFB: 0 VESA VGA
ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-4.4.0-112-generic root=UUID=4cbb9ed4-c9ab-4ee3-8eb5-2473af0d2ae7 ro quiet splash vt.handoff=7
ProcVersionSignature: Ubuntu 4.4.0-112.135-generic 4.4.98
RelatedPackageVersions:
 linux-restricted-modules-4.4.0-112-generic N/A
 linux-backports-modules-4.4.0-112-generic N/A
 linux-firmware 1.157.14
RfKill:

Tags: xenial
Uname: Linux 4.4.0-112-generic i686
UpgradeStatus: No upgrade log present (probably fresh install)
UserGroups: adm cdrom dip lpadmin lxd plugdev sambashare sudo
_MarkForUpload: True
dmi.bios.date: 08/21/2012
dmi.bios.vendor: American Megatrends Inc.
dmi.bios.version: F7
dmi.board.asset.tag: To be filled by O.E.M.
dmi.board.name: H77-DS3H
dmi.board.vendor: Gigabyte Technology Co., Ltd.
dmi.board.version: x.x
dmi.chassis.asset.tag: To Be Filled By O.E.M.
dmi.chassis.type: 3
dmi.chassis.vendor: Gigabyte Technology Co., Ltd.
dmi.chassis.version: To Be Filled By O.E.M.
dmi.modalias: dmi:bvnAmericanMegatrendsInc.:bvrF7:bd08/21/2012:svnGigabyteTechnologyCo.,Ltd.:pnTobefilledbyO.E.M.:pvrTobefilledbyO.E.M.:rvnGigabyteTechnologyCo.,Ltd.:rnH77-DS3H:rvrx.x:cvnGigabyteTechnologyCo.,Ltd.:ct3:cvrToBeFilledByO.E.M.:
dmi.product.name: To be filled by O.E.M.
dmi.product.version: To be filled by O.E.M.
dmi.sys.vendor: Gigabyte Technology Co., Ltd.

Revision history for this message
csola48 (mail-csordaslaszlo) wrote :
Revision history for this message
Ubuntu Kernel Bot (ubuntu-kernel-bot) wrote : Missing required logs.

This bug is missing log files that will aid in diagnosing the problem. While running an Ubuntu kernel (not a mainline or third-party kernel) please enter the following command in a terminal window:

apport-collect 1744979

and then change the status of the bug to 'Confirmed'.

If, due to the nature of the issue you have encountered, you are unable to run this command, please add a comment stating that fact and change the bug status to 'Confirmed'.

This change has been made by an automated script, maintained by the Ubuntu Kernel Team.

Changed in linux (Ubuntu):
status: New → Incomplete
tags: added: xenial
Revision history for this message
csola48 (mail-csordaslaszlo) wrote : AlsaInfo.txt

apport information

Changed in linux (Ubuntu):
status: Incomplete → Confirmed
tags: added: apport-collected
description: updated
Revision history for this message
csola48 (mail-csordaslaszlo) wrote : CRDA.txt

apport information

Revision history for this message
csola48 (mail-csordaslaszlo) wrote : CurrentDmesg.txt

apport information

Revision history for this message
csola48 (mail-csordaslaszlo) wrote : JournalErrors.txt

apport information

Revision history for this message
csola48 (mail-csordaslaszlo) wrote : Lspci.txt

apport information

Revision history for this message
csola48 (mail-csordaslaszlo) wrote : Lsusb.txt

apport information

Revision history for this message
csola48 (mail-csordaslaszlo) wrote : ProcCpuinfo.txt

apport information

Revision history for this message
csola48 (mail-csordaslaszlo) wrote : ProcCpuinfoMinimal.txt

apport information

Revision history for this message
csola48 (mail-csordaslaszlo) wrote : ProcEnviron.txt

apport information

Revision history for this message
csola48 (mail-csordaslaszlo) wrote : ProcInterrupts.txt

apport information

Revision history for this message
csola48 (mail-csordaslaszlo) wrote : ProcModules.txt

apport information

Revision history for this message
csola48 (mail-csordaslaszlo) wrote : PulseList.txt

apport information

Revision history for this message
csola48 (mail-csordaslaszlo) wrote : UdevDb.txt

apport information

Revision history for this message
csola48 (mail-csordaslaszlo) wrote : WifiSyslog.txt

apport information

Revision history for this message
Joseph Salisbury (jsalisbury) wrote :

Would it be possible for you to test the latest upstream stable kernel? Refer to https://wiki.ubuntu.com/KernelMainlineBuilds . Please test the latest v4.4 stable kernel[0].

If this bug is fixed in the mainline kernel, please add the following tag 'kernel-fixed-upstream'.

If the mainline kernel does not fix this bug, please add the tag: 'kernel-bug-exists-upstream'.

If you are unable to test the mainline kernel, for example it will not boot, please add the tag: 'kernel-unable-to-test-upstream'.
Once testing of the upstream kernel is complete, please mark this bug as "Confirmed".

Thanks in advance.

[0] http://kernel.ubuntu.com/~kernel-ppa/mainline/v4.4.113

Changed in linux (Ubuntu):
importance: Undecided → High
status: Confirmed → Incomplete
tags: added: needs-bisect
Changed in linux (Ubuntu):
status: Incomplete → Confirmed
Revision history for this message
csola48 (mail-csordaslaszlo) wrote :
Download full text (18.8 KiB)

/boot/grub/grub.cfg
#
# DO NOT EDIT THIS FILE
#
# It is automatically generated by grub-mkconfig using templates
# from /etc/grub.d and settings from /etc/default/grub
#

### BEGIN /etc/grub.d/00_header ###
if [ -s $prefix/grubenv ]; then
  set have_grubenv=true
  load_env
fi
if [ "${next_entry}" ] ; then
   set default="${next_entry}"
   set next_entry=
   save_env next_entry
   set boot_once=true
else
   set default="2"
fi

if [ x"${feature_menuentry_id}" = xy ]; then
  menuentry_id_option="--id"
else
  menuentry_id_option=""
fi

export menuentry_id_option

if [ "${prev_saved_entry}" ]; then
  set saved_entry="${prev_saved_entry}"
  save_env saved_entry
  set prev_saved_entry=
  save_env prev_saved_entry
  set boot_once=true
fi

function savedefault {
  if [ -z "${boot_once}" ]; then
    saved_entry="${chosen}"
    save_env saved_entry
  fi
}
function recordfail {
  set recordfail=1
  if [ -n "${have_grubenv}" ]; then if [ -z "${boot_once}" ]; then save_env recordfail; fi; fi
}
function load_video {
  if [ x$feature_all_video_module = xy ]; then
    insmod all_video
  else
    insmod efi_gop
    insmod efi_uga
    insmod ieee1275_fb
    insmod vbe
    insmod vga
    insmod video_bochs
    insmod video_cirrus
  fi
}

if [ x$feature_default_font_path = xy ] ; then
   font=unicode
else
insmod part_msdos
insmod ext2
set root='hd1,msdos1'
if [ x$feature_platform_search_hint = xy ]; then
  search --no-floppy --fs-uuid --set=root --hint-bios=hd1,msdos1 --hint-efi=hd1,msdos1 --hint-baremetal=ahci1,msdos1 4cbb9ed4-c9ab-4ee3-8eb5-2473af0d2ae7
else
  search --no-floppy --fs-uuid --set=root 4cbb9ed4-c9ab-4ee3-8eb5-2473af0d2ae7
fi
    font="/usr/share/grub/unicode.pf2"
fi

if loadfont $font ; then
  set gfxmode=auto
  load_video
  insmod gfxterm
  set locale_dir=$prefix/locale
  set lang=hu_HU
  insmod gettext
fi
terminal_output gfxterm
if [ "${recordfail}" = 1 ] ; then
  set timeout=30
else
  if [ x$feature_timeout_style = xy ] ; then
    set timeout_style=hidden
    set timeout=0
  # Fallback hidden-timeout code in case the timeout_style feature is
  # unavailable.
  elif sleep --interruptible 0 ; then
    set timeout=0
  fi
fi
### END /etc/grub.d/00_header ###

### BEGIN /etc/grub.d/05_debian_theme ###
set menu_color_normal=white/black
set menu_color_highlight=black/light-gray
if background_color 44,0,30,0; then
  clear
fi
### END /etc/grub.d/05_debian_theme ###

### BEGIN /etc/grub.d/10_linux ###
function gfxmode {
 set gfxpayload="${1}"
 if [ "${1}" = "keep" ]; then
  set vt_handoff=vt.handoff=7
 else
  set vt_handoff=
 fi
}
if [ "${recordfail}" != 1 ]; then
  if [ -e ${prefix}/gfxblacklist.txt ]; then
    if hwmatch ${prefix}/gfxblacklist.txt 3; then
      if [ ${match} = 0 ]; then
        set linux_gfx_mode=keep
      else
        set linux_gfx_mode=text
      fi
    else
      set linux_gfx_mode=text
    fi
  else
    set linux_gfx_mode=keep
  fi
else
  set linux_gfx_mode=text
fi
export linux_gfx_mode
menuentry 'Ubuntu' --class ubuntu --class gnu-linux --class gnu --class os $menuentry_id_option 'gnulinux-simple-4cbb9ed4-c9ab-4ee3-8eb5-2473af0d2ae7' {
 recordfail
 load_video
 gfxmode $linux_gfx_mode
 insmod gzio
 if [ x$grub_platform = xxen ]; ...

Revision history for this message
csola48 (mail-csordaslaszlo) wrote :

After installing the proposed kernel:
sudo update-grub
[sudo] csola48 jelszava:
GRUB beállítófájl előállítása…
Figyelem: A GRUB_TIMEOUT beállítása egy nem nulla értékre, ha a beállított GRUB_HIDDEN_TIMEOUT többé nem támogatott.
Megtalált linux lemezkép: /boot/vmlinuz-4.10.0-42-generic
Megtalált initrd lemezkép: /boot/initrd.img-4.10.0-42-generic
Megtalált linux lemezkép: /boot/vmlinuz-4.10.0-40-generic
Megtalált initrd lemezkép: /boot/initrd.img-4.10.0-40-generic
Megtalált linux lemezkép: /boot/vmlinuz-4.4.113-0404113-lowlatency
Megtalált initrd lemezkép: /boot/initrd.img-4.4.113-0404113-lowlatency
Megtalált linux lemezkép: /boot/vmlinuz-4.4.113-0404113-generic
Megtalált initrd lemezkép: /boot/initrd.img-4.4.113-0404113-generic
Megtalált linux lemezkép: /boot/vmlinuz-4.4.0-112-generic
Megtalált initrd lemezkép: /boot/initrd.img-4.4.0-112-generic
Megtalált linux lemezkép: /boot/vmlinuz-4.4.0-109-generic
Megtalált initrd lemezkép: /boot/initrd.img-4.4.0-109-generic
Found memtest86+ image: /boot/memtest86+.elf
Found memtest86+ image: /boot/memtest86+.bin
kész

With this option, the kernel 3 will not start, but the displayed text will appear:
GRUB_DEFAULT=2
GRUB_HIDDEN_TIMEOUT=0
GRUB_HIDDEN_TIMEOUT_QUIET=true
GRUB_TIMEOUT=10
GRUB_DISTRIBUTOR=`lsb_release -i -s 2> /dev/null || echo Debian`
GRUB_CMDLINE_LINUX_DEFAULT="quiet splash"
GRUB_CMDLINE_LINUX=""

If grub is left automatically running, then kernel 4.10.0-42 starts ...
What's the mistake?....

From the second part of grub (special settings!) Any selected kernel can be "normally" started...

Revision history for this message
csola48 (mail-csordaslaszlo) wrote :

Sorry this missed ...

With this option, the kernel 3 will not start, but the displayed text will appear: grub_efi_secure_boot

Revision history for this message
csola48 (mail-csordaslaszlo) wrote :

How much should GRUB_DEFAULT be set to for example start 4.4.0-112 kernel automatically when booting?
Different descriptions do not give a clear answer to which "menuentry" counts and which one does not ...
https://pastebin.com/G23aHrMn and
https://pastebin.com/g4hr6Ltf

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.