canonical / canonical/core-initrd

Debugging failure to unlock is hard

Open
#272 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
18
Forks
33
PR merge metrics
No merged PRs in 30d

Description

During release sprint debugging failure to unlock hybrid desktop was hard.

One had to boot to live session, change boot partition cmdline to go into dangerous mode to extract journal and TPM measurements.

It would have failed upon failure to unlock to store a copy of tpm measurements and journal on the boot or seed partition.

It would also help if reporting install failure from a live session would stop and upload copies of the above stored failed to unlock. Such that if first boot fails one can go back to installer to report failure.

Separately it was concerning that measurements to get to installer boot were not verified to be plausible for first boot unlock.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.