#1052299 gnome-boxes: Cannot install "GNOME OS Nightly" - secure-boot set by ovmf while gnome os efi seems not signed #1052299
- Package:
- gnome-boxes
- Source:
- gnome-boxes
- Description:
- Simple GNOME app to access virtual systems
- Submitter:
- Alban Browaeys
- Date:
- 2024-02-19 12:39:06 UTC
- Severity:
- normal
Dear Maintainer,
If I attempt to create a GNOME OS guest I end up on the edkII console.
If inhte console I try to boot the EFI (in FS0: be it bootx64.efi in
\EFI\BOOT or systemd-bootx64.efi in EFI\systemd) I get a "Command Error
Status: Access Denied" error.
I got he clue it might be secure boot related by https://forum.proxmox.com/threads/vm-always-going-into-uefi-interactive-shell.119215/
I also learned that the install was fine with the flatpak, so I compared
the VM configurations for GNOME OS:
Debian gome-boxes 45:
<os firmware="efi">
<type arch="x86_64" machine="pc-q35-8.0">hvm</type>
<firmware>
<feature enabled="yes" name="enrolled-keys"/>
<feature enabled="yes" name="secure-boot"/>
</firmware>
<loader readonly="yes" secure="yes" type="pflash">/usr/share/OVMF/OVMF_CODE_4M.ms.fd</loader>
<nvram template="/usr/share/OVMF/OVMF_VARS_4M.ms.fd">/home/prahal/.config/libvirt/qemu/nvram/gnomenightly_VARS.fd</nvram>
<boot dev="cdrom"/>
<boot dev="hd"/>
<bootmenu enable="yes"/>
</os>
<features>
<acpi/>
<apic/>
<smm state="on"/>
</features> >
Flatpak gnome-boxes 44:
<os firmware="efi">
<type arch="x86_64" machine="pc-q35-7.2">hvm</type>
<boot dev="cdrom"/>
<boot dev="hd"/>
<bootmenu enable="yes"/>
</os>
<features>
<acpi/>
<apic/>
</features>
Grepping where this secure-boot feature comes from, I ended up on:
/usr/share/qemu/firmware/40-edk2-x86_64-secure-enrolled.json
Scrambling the target (for example, replacing in "machines", "pc-q35-*"
by "pc-q35xxx-*") in this file to avoid its settings being added to
(all?) the guest VM I now can install "GNOME OS Nightly x86_64" (ie
edk2 boots into the installer and the installer proceeds).
This might well be an ovmf bug.
Still, as I don' know if gnome-boxes or qemu have flags to avoid ovmf
bringing in this secure-boot for all guest setups, I start up the stack.
Cheers,
Alban
Control: forwarded -1 https://gitlab.gnome.org/GNOME/gnome-build-meta/-/issues/732 Thank you for your thorough bug report. As a workaround, I am disabling Secure Boot in GNOME Boxes now (cherry-picking a future GNOME Boxes 46 change). I cloned this bug for that change. I believe ultimately a major problem here is that the GNOME OS images are not adequately signed for Secure Boot yet. I found an issue upstream that seems to talk about fixing that issue. Thank you, Jeremy Bícha
Hello, Bug #1052299 in gnome-boxes reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/gnome-team/gnome-boxes/-/commit/0b1012e0c9bf1624d3d4af46eb3bfd9df6fa471c ------------------------------------------------------------------------ Cherry-pick proposed patch to enable GNOME OS by disabling Secure Boot inside GNOME Boxes Gbp-Dch: Full Closes: #1052299 ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1052299
We believe that the bug you reported is fixed in the latest version of
gnome-boxes, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1052299@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Jeremy Bícha <jbicha@ubuntu.com> (supplier of updated gnome-boxes package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 19 Feb 2024 07:19:21 -0500
Source: gnome-boxes
Built-For-Profiles: noudeb
Architecture: source
Version: 45.0-3
Distribution: unstable
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>
Changed-By: Jeremy Bícha <jbicha@ubuntu.com>
Closes: 1052299
Changes:
gnome-boxes (45.0-3) unstable; urgency=medium
.
* Cherry-pick patch to enable GNOME OS by disabling Secure Boot
inside GNOME Boxes (Closes: #1052299)
* Bump minimum libvirt-glib to 5.0.0
Checksums-Sha1:
4899d586049b7735fe138a1a7db01da9bd2f02ea 2719 gnome-boxes_45.0-3.dsc
cb49fe4eca0ff8160ae23ba3227bd927604b5ef5 21052 gnome-boxes_45.0-3.debian.tar.xz
2a01afbc87341867b8ef91ebbf6169aa847e0d49 18536 gnome-boxes_45.0-3_source.buildinfo
Checksums-Sha256:
a74d98b54729109d62cb9291a2623efb58e7095cf5ab91d5fc2bacfa16af65ad 2719 gnome-boxes_45.0-3.dsc
17706ee28281962b4b4d74d06bd14bed6bc217a6adf297496bc4a63180a926ad 21052 gnome-boxes_45.0-3.debian.tar.xz
780ea155003e3baa4242af4153e0dd6bcb7876d406dec09ec7f9e453e8444932 18536 gnome-boxes_45.0-3_source.buildinfo
Files:
c98c830ddfa57bbfe6f0fa36948c1120 2719 gnome optional gnome-boxes_45.0-3.dsc
0c25ba1d8c3a9930e9d1cf617dcb53b8 21052 gnome optional gnome-boxes_45.0-3.debian.tar.xz
fcded99f554c12639b456914e8efa980 18536 gnome optional gnome-boxes_45.0-3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmXTR7AACgkQ5mx3Wuv+
bH2ceQ/8DW2U6fAlygYnqaOS47qbD6WG6XoQlHqlI2yd0UC6ONzFfXTK32Cf80B3
cVn/mTmMnUeE9WzYip5CWNN/eGlQ+LkpQ6itF6MNjWBunopAYLaHmGfp+Nlp/nd8
+8wjXfwEwuFlKHyyQIQPiLRFY/Qt50j1Omw13W4yxdSonf3WCbeuzG0ZeJBEH7JF
m0Wsh7D6FzoroCGabV9nfrkpvDRxLrNw0NjuiHHSzrKOa5nQUm3BHgsheCA26CXy
jrA07lLbtIVg7jDGWW2bLh1c1kOVzY+VYldVRMG9t2nRFHttZbcG4Z70JKG4eTJy
7N2jieVNNUM/tHW06Iru8qS4li7dhOwFsfyVLIGgvc5tx1shfLKNmDYVaXztLNDj
enwzuHsDgyZfvSDijJPfgMGrm5+cQY096BIxoQeh/jvMbG5HiviFE70IguSIyKCu
BS31gQbZG+w+UEJn1qsZXJR2U6NoZeyPRIu/B9ceuSEwIvUNUNwhPqoaqGXgEQfw
lf5dQxYJSWF6itkaIDExxdkqLaG9HeTFyTnV1ZrE39X7Yp3+p9KwL3ryPoTiDDSZ
0n3IWrvECldHlkl0gPOejrAczBV36vVjHEGxibhx8aMQeq5RTJ7sR332Jty+ryHR
GPR/dzcINoaFN1tqiKJJgIgklYrlAqLXJdCzKNkCDurCqPu7QEU=
=xsHk
-----END PGP SIGNATURE-----