2017-03-17 15:26:04 |
Jeremy Bícha |
bug |
|
|
added bug |
2017-03-17 15:26:54 |
Jeremy Bícha |
attachment added |
|
unattended-upgrades-dpkg.log https://bugs.launchpad.net/ubuntu/+source/shim-signed/+bug/1673817/+attachment/4839527/+files/unattended-upgrades-dpkg.log |
|
2017-03-17 15:27:42 |
Jeremy Bícha |
attachment removed |
JournalErrors.txt https://bugs.launchpad.net/ubuntu/+source/shim-signed/+bug/1673817/+attachment/4839525/+files/JournalErrors.txt |
|
|
2017-03-17 15:28:07 |
Jeremy Bícha |
attachment removed |
BootEFIContents.txt https://bugs.launchpad.net/ubuntu/+source/shim-signed/+bug/1673817/+attachment/4839522/+files/BootEFIContents.txt |
|
|
2017-03-17 15:28:10 |
Jeremy Bícha |
attachment removed |
EFIBootMgr.txt https://bugs.launchpad.net/ubuntu/+source/shim-signed/+bug/1673817/+attachment/4839524/+files/EFIBootMgr.txt |
|
|
2017-03-17 15:28:32 |
Jeremy Bícha |
bug task added |
|
unattended-upgrades (Ubuntu) |
|
2017-03-17 15:32:26 |
Adam Conrad |
unattended-upgrades (Ubuntu): status |
New |
Invalid |
|
2017-03-17 15:32:37 |
Adam Conrad |
shim-signed (Ubuntu): assignee |
|
Mathieu Trudel-Lapierre (cyphermox) |
|
2017-03-17 15:32:49 |
Adam Conrad |
shim-signed (Ubuntu): importance |
Undecided |
High |
|
2017-03-17 15:52:36 |
Mathieu Trudel-Lapierre |
shim-signed (Ubuntu): status |
New |
Incomplete |
|
2017-03-21 15:41:50 |
Brian Murray |
tags |
amd64 apport-bug wayland-session zesty |
amd64 apport-bug rls-z-incoming wayland-session zesty |
|
2017-03-22 01:50:10 |
Mathieu Trudel-Lapierre |
shim-signed (Ubuntu): milestone |
|
ubuntu-17.03 |
|
2017-03-22 01:50:17 |
Mathieu Trudel-Lapierre |
shim-signed (Ubuntu): status |
Incomplete |
In Progress |
|
2017-03-22 06:43:13 |
Launchpad Janitor |
shim-signed (Ubuntu): status |
In Progress |
Fix Released |
|
2017-03-23 20:59:58 |
Mathieu Trudel-Lapierre |
nominated for series |
|
Ubuntu Yakkety |
|
2017-03-23 20:59:58 |
Mathieu Trudel-Lapierre |
bug task added |
|
unattended-upgrades (Ubuntu Yakkety) |
|
2017-03-23 20:59:58 |
Mathieu Trudel-Lapierre |
bug task added |
|
shim-signed (Ubuntu Yakkety) |
|
2017-03-23 20:59:58 |
Mathieu Trudel-Lapierre |
nominated for series |
|
Ubuntu Trusty |
|
2017-03-23 20:59:58 |
Mathieu Trudel-Lapierre |
bug task added |
|
unattended-upgrades (Ubuntu Trusty) |
|
2017-03-23 20:59:58 |
Mathieu Trudel-Lapierre |
bug task added |
|
shim-signed (Ubuntu Trusty) |
|
2017-03-23 20:59:58 |
Mathieu Trudel-Lapierre |
nominated for series |
|
Ubuntu Xenial |
|
2017-03-23 20:59:58 |
Mathieu Trudel-Lapierre |
bug task added |
|
unattended-upgrades (Ubuntu Xenial) |
|
2017-03-23 20:59:58 |
Mathieu Trudel-Lapierre |
bug task added |
|
shim-signed (Ubuntu Xenial) |
|
2017-03-23 21:05:02 |
Mathieu Trudel-Lapierre |
description |
Currently, unattended-upgrades will automatically install all updates for those running development releases of Ubuntu (LP: #1649709)
Today, my computer was acting very sluggish. Looking at my process list, I saw/ usr/sbin/update-secureboot-policy was using a log of CPU.
I killed the process. I have a /var/crash/shim-signed.0.crash but since it's 750 MB, I didn't bother submitting it or looking at it more. Maybe it crashed because I killed the process. Also, I see that unattended-upgrades-dpkg.log is 722 MB.
Today's update included both VirtualBox and the linux kernel.
I am attaching an excerpt of /var/log/unattended-upgrades/unattended-upgrades-dpkg.log
This message was repeated a very large number of times (but I only included it once in the attachment:
"Invalid password
The Secure Boot key you've entered is not valid. The password used must be
between 8 and 16 characters."
ProblemType: Bug
DistroRelease: Ubuntu 17.04
Package: shim-signed 1.23+0.9+1474479173.6c180c6-0ubuntu1
ProcVersionSignature: Ubuntu 4.10.0-11.13-generic 4.10.1
Uname: Linux 4.10.0-11-generic x86_64
NonfreeKernelModules: zfs zunicode zavl zcommon znvpair
ApportVersion: 2.20.4-0ubuntu2
Architecture: amd64
CurrentDesktop: GNOME
Date: Fri Mar 17 11:15:04 2017
EcryptfsInUse: Yes
InstallationDate: Installed on 2017-02-23 (21 days ago)
InstallationMedia: Ubuntu-GNOME 17.04 "Zesty Zapus" - Alpha amd64 (20170219)
SourcePackage: shim-signed
UpgradeStatus: No upgrade log present (probably fresh install) |
[Impact]
Any user with unattended upgrades enabled and DKMS packages in a Secure Boot environment might be prompted to change Secure Boot policy, which will fail and crash in unattended-upgrades.
[Test case]
1) Install new package
2) Create /var/lib/dkms/TEST-DKMS
3) Reboot triggering unattended-upgrades:
<process TBD>
Upgrade should run smoothly and complete without issue (see original description).
[Regression Potential]
Any failure to prompt for or change Secure Boot policy in mokutil (crashes of update-secureboot-policy, higher CPU usage, etc.) would constitute a regression of this SRU.
Any other issues related to booting in Secure Boot mode should instead be directed to bug 1637290 (shim update).
---
Currently, unattended-upgrades will automatically install all updates for those running development releases of Ubuntu (LP: #1649709)
Today, my computer was acting very sluggish. Looking at my process list, I saw/ usr/sbin/update-secureboot-policy was using a log of CPU.
I killed the process. I have a /var/crash/shim-signed.0.crash but since it's 750 MB, I didn't bother submitting it or looking at it more. Maybe it crashed because I killed the process. Also, I see that unattended-upgrades-dpkg.log is 722 MB.
Today's update included both VirtualBox and the linux kernel.
I am attaching an excerpt of /var/log/unattended-upgrades/unattended-upgrades-dpkg.log
This message was repeated a very large number of times (but I only included it once in the attachment:
"Invalid password
The Secure Boot key you've entered is not valid. The password used must be
between 8 and 16 characters."
ProblemType: Bug
DistroRelease: Ubuntu 17.04
Package: shim-signed 1.23+0.9+1474479173.6c180c6-0ubuntu1
ProcVersionSignature: Ubuntu 4.10.0-11.13-generic 4.10.1
Uname: Linux 4.10.0-11-generic x86_64
NonfreeKernelModules: zfs zunicode zavl zcommon znvpair
ApportVersion: 2.20.4-0ubuntu2
Architecture: amd64
CurrentDesktop: GNOME
Date: Fri Mar 17 11:15:04 2017
EcryptfsInUse: Yes
InstallationDate: Installed on 2017-02-23 (21 days ago)
InstallationMedia: Ubuntu-GNOME 17.04 "Zesty Zapus" - Alpha amd64 (20170219)
SourcePackage: shim-signed
UpgradeStatus: No upgrade log present (probably fresh install) |
|
2017-03-24 06:41:24 |
Steve Langasek |
shim-signed (Ubuntu Xenial): status |
New |
Fix Committed |
|
2017-03-24 06:41:26 |
Steve Langasek |
bug |
|
|
added subscriber Ubuntu Stable Release Updates Team |
2017-03-24 06:41:33 |
Steve Langasek |
bug |
|
|
added subscriber SRU Verification |
2017-03-24 06:41:37 |
Steve Langasek |
tags |
amd64 apport-bug rls-z-incoming wayland-session zesty |
amd64 apport-bug rls-z-incoming verification-needed wayland-session zesty |
|
2017-03-24 06:56:56 |
Steve Langasek |
shim-signed (Ubuntu Yakkety): status |
New |
Fix Committed |
|
2017-03-31 16:16:28 |
Mathieu Trudel-Lapierre |
description |
[Impact]
Any user with unattended upgrades enabled and DKMS packages in a Secure Boot environment might be prompted to change Secure Boot policy, which will fail and crash in unattended-upgrades.
[Test case]
1) Install new package
2) Create /var/lib/dkms/TEST-DKMS
3) Reboot triggering unattended-upgrades:
<process TBD>
Upgrade should run smoothly and complete without issue (see original description).
[Regression Potential]
Any failure to prompt for or change Secure Boot policy in mokutil (crashes of update-secureboot-policy, higher CPU usage, etc.) would constitute a regression of this SRU.
Any other issues related to booting in Secure Boot mode should instead be directed to bug 1637290 (shim update).
---
Currently, unattended-upgrades will automatically install all updates for those running development releases of Ubuntu (LP: #1649709)
Today, my computer was acting very sluggish. Looking at my process list, I saw/ usr/sbin/update-secureboot-policy was using a log of CPU.
I killed the process. I have a /var/crash/shim-signed.0.crash but since it's 750 MB, I didn't bother submitting it or looking at it more. Maybe it crashed because I killed the process. Also, I see that unattended-upgrades-dpkg.log is 722 MB.
Today's update included both VirtualBox and the linux kernel.
I am attaching an excerpt of /var/log/unattended-upgrades/unattended-upgrades-dpkg.log
This message was repeated a very large number of times (but I only included it once in the attachment:
"Invalid password
The Secure Boot key you've entered is not valid. The password used must be
between 8 and 16 characters."
ProblemType: Bug
DistroRelease: Ubuntu 17.04
Package: shim-signed 1.23+0.9+1474479173.6c180c6-0ubuntu1
ProcVersionSignature: Ubuntu 4.10.0-11.13-generic 4.10.1
Uname: Linux 4.10.0-11-generic x86_64
NonfreeKernelModules: zfs zunicode zavl zcommon znvpair
ApportVersion: 2.20.4-0ubuntu2
Architecture: amd64
CurrentDesktop: GNOME
Date: Fri Mar 17 11:15:04 2017
EcryptfsInUse: Yes
InstallationDate: Installed on 2017-02-23 (21 days ago)
InstallationMedia: Ubuntu-GNOME 17.04 "Zesty Zapus" - Alpha amd64 (20170219)
SourcePackage: shim-signed
UpgradeStatus: No upgrade log present (probably fresh install) |
[Impact]
Any user with unattended upgrades enabled and DKMS packages in a Secure Boot environment might be prompted to change Secure Boot policy, which will fail and crash in unattended-upgrades.
[Test case]
= unattended upgrade =
1) Create /var/lib/dkms/TEST-DKMS
2) Install new package
3) Trigger unattended-upgrades: unattended-upgrades -d
Upgrade should run smoothly for all the processing but fail to complete; shim-signed should end the unattended upgrade with a error as unattended change of the Secure Boot policy can not be done. Upgrade should not hang in high CPU usage.
= standard upgrade =
1) Create /var/lib/dkms/TEST-DKMS
2) install new package.
3) Verify that the upgrade completes normally.
[Regression Potential]
Any failure to prompt for or change Secure Boot policy in mokutil while in an *attended* upgrade scenario would constitute a regression of this SRU.
Any other issues related to booting in Secure Boot mode should instead be directed to bug 1637290 (shim update).
---
Currently, unattended-upgrades will automatically install all updates for those running development releases of Ubuntu (LP: #1649709)
Today, my computer was acting very sluggish. Looking at my process list, I saw/ usr/sbin/update-secureboot-policy was using a log of CPU.
I killed the process. I have a /var/crash/shim-signed.0.crash but since it's 750 MB, I didn't bother submitting it or looking at it more. Maybe it crashed because I killed the process. Also, I see that unattended-upgrades-dpkg.log is 722 MB.
Today's update included both VirtualBox and the linux kernel.
I am attaching an excerpt of /var/log/unattended-upgrades/unattended-upgrades-dpkg.log
This message was repeated a very large number of times (but I only included it once in the attachment:
"Invalid password
The Secure Boot key you've entered is not valid. The password used must be
between 8 and 16 characters."
ProblemType: Bug
DistroRelease: Ubuntu 17.04
Package: shim-signed 1.23+0.9+1474479173.6c180c6-0ubuntu1
ProcVersionSignature: Ubuntu 4.10.0-11.13-generic 4.10.1
Uname: Linux 4.10.0-11-generic x86_64
NonfreeKernelModules: zfs zunicode zavl zcommon znvpair
ApportVersion: 2.20.4-0ubuntu2
Architecture: amd64
CurrentDesktop: GNOME
Date: Fri Mar 17 11:15:04 2017
EcryptfsInUse: Yes
InstallationDate: Installed on 2017-02-23 (21 days ago)
InstallationMedia: Ubuntu-GNOME 17.04 "Zesty Zapus" - Alpha amd64 (20170219)
SourcePackage: shim-signed
UpgradeStatus: No upgrade log present (probably fresh install) |
|
2017-03-31 16:19:30 |
Mathieu Trudel-Lapierre |
tags |
amd64 apport-bug rls-z-incoming verification-needed wayland-session zesty |
amd64 apport-bug rls-z-incoming verification-done-yakkety verification-needed wayland-session zesty |
|
2017-03-31 18:24:44 |
Mathieu Trudel-Lapierre |
tags |
amd64 apport-bug rls-z-incoming verification-done-yakkety verification-needed wayland-session zesty |
amd64 apport-bug rls-z-incoming verification-done-xenial verification-done-yakkety wayland-session zesty |
|
2017-04-03 19:37:01 |
Launchpad Janitor |
shim-signed (Ubuntu Yakkety): status |
Fix Committed |
Fix Released |
|
2017-04-03 19:37:19 |
Steve Langasek |
removed subscriber Ubuntu Stable Release Updates Team |
|
|
|
2017-04-03 19:46:50 |
Launchpad Janitor |
shim-signed (Ubuntu Xenial): status |
Fix Committed |
Fix Released |
|
2017-07-13 21:09:57 |
Steve Langasek |
unattended-upgrades (Ubuntu Trusty): status |
New |
Invalid |
|
2017-07-13 21:09:59 |
Steve Langasek |
unattended-upgrades (Ubuntu Xenial): status |
New |
Invalid |
|
2017-07-13 21:10:03 |
Steve Langasek |
unattended-upgrades (Ubuntu Yakkety): status |
New |
Invalid |
|
2017-07-17 14:51:23 |
Steve Langasek |
shim-signed (Ubuntu Trusty): status |
New |
Fix Committed |
|
2017-07-17 14:51:25 |
Steve Langasek |
bug |
|
|
added subscriber Ubuntu Stable Release Updates Team |
2017-07-17 14:51:30 |
Steve Langasek |
tags |
amd64 apport-bug rls-z-incoming verification-done-xenial verification-done-yakkety wayland-session zesty |
amd64 apport-bug rls-z-incoming verification-done-xenial verification-done-yakkety verification-needed verification-needed-trusty wayland-session zesty |
|
2017-07-19 20:08:22 |
Mathieu Trudel-Lapierre |
tags |
amd64 apport-bug rls-z-incoming verification-done-xenial verification-done-yakkety verification-needed verification-needed-trusty wayland-session zesty |
amd64 apport-bug rls-z-incoming verification-done-trusty verification-done-xenial verification-done-yakkety wayland-session zesty |
|
2017-08-28 15:29:46 |
Launchpad Janitor |
shim-signed (Ubuntu Trusty): status |
Fix Committed |
Fix Released |
|
2019-05-18 01:56:07 |
Mathew Hodson |
bug task deleted |
unattended-upgrades (Ubuntu) |
|
|
2019-05-18 01:56:16 |
Mathew Hodson |
bug task deleted |
unattended-upgrades (Ubuntu Trusty) |
|
|
2019-05-18 01:56:22 |
Mathew Hodson |
bug task deleted |
unattended-upgrades (Ubuntu Xenial) |
|
|
2019-05-18 01:56:28 |
Mathew Hodson |
bug task deleted |
unattended-upgrades (Ubuntu Yakkety) |
|
|