Bug 33303 - Kernel not compiled with SECURITY_LOCKDOWN_LSM thus fwupd does not work
Summary: Kernel not compiled with SECURITY_LOCKDOWN_LSM thus fwupd does not work
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Kernel and Drivers maintainers
QA Contact:
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-06-13 11:48 CEST by Vincent D
Modified: 2024-06-13 21:14 CEST (History)
0 users

See Also:
Source RPM: kernel-6.6.28-1.mga9.src.rpm
CVE:
Status comment:


Attachments

Description Vincent D 2024-06-13 11:48:00 CEST
The command `fwupdtool security` returns the following error message: failed to get public key using /fpf/OemCred: generic failure [0xb].

Also all related tools (fwupd*) are not able to update any firmware. It seems the cause is that the kernel is not built with the option SECURITY_LOCKDOWN_LSM as it can be seen in the file (for instance) /boot/config-6.6.18-desktop-1.mga9:
# CONFIG_SECURITY_LOCKDOWN_LSM is not set

A related thread:
https://github.com/fwupd/fwupd/issues/5745
Comment 1 Lewis Smith 2024-06-13 21:14:28 CEST
Thank you for the report.
The thread you indicate is complicated, and seems extremely hardware specific.

Assigning to kernel.

Assignee: bugsquad => kernel


Note You need to log in before you can comment on or make changes to this bug.