#1021052 manpages: kernel_lockdown(7): Rule about "unencrypted hibernation" is unclear

Package:
manpages
Source:
manpages
Submitter:
Jonathan Neuschäfer
Date:
2023-12-23 12:27:03 UTC
Severity:
normal
Tags:
#1021052#5
Date:
2022-10-01 08:21:37 UTC
From:
To:
The kernel_lockdown(7) manpage states:

 • Unencrypted hibernation/suspend to swap are disallowed as the kernel
   image is saved to a medium that can then be accessed.

I have a swap partition in LVM on an encrypted volume, so it could
arguably count as encrypted. However "systemctl hibernate" fails
and places the following line into the system log:

[  727.705737] Lockdown: systemd-logind: hibernation is restricted; see man kernel_lockdown.7

It is unclear to me whether I'm seeing false documentation or a bug in
the implementation or my local configuration.

Please clarify the kernel_lockdown(7) manpage with regards to this
relatively common situation of swap on LVM on LUKS.


Best regards.

#1021052#12
Date:
2023-12-23 12:12:58 UTC
From:
To:
tags 1021052 + upstream
thanks

Hello Tobias,
Am Sat, Oct 01, 2022 at 10:21:37AM +0200 schrieb Jonathan Neuschäfer:

Should this be forwarded to upstream? (Or maybe you did so already?)
Upstream is quite responsive.

Greetings

            Helge