Hello Marek,

Please look at my comments below:

Wim 

-----Original Message-----
From: qubes-users@googlegroups.com [mailto:qubes-users@googlegroups.com] On 
Behalf Of Marek Marczykowski-Górecki
Sent: Wednesday, April 19, 2017 9:39 PM
To: Wim Vervoorn <wvervo...@eltan.com>
Cc: qubes-users <qubes-users@googlegroups.com>
Subject: Re: [qubes-users] UEFI installation issue

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Wed, Apr 19, 2017 at 09:06:48AM +0000, Wim Vervoorn wrote:
> Hello Marek,
> 
> Thanks for getting back to me.
> 
> I obtained the logs and had a look at them. 
> 
> I couldn't find anything obvious. Can you have a look at them.

Hmm, I found this in anaconda.log:
23:19:35,474 INFO anaconda: skipping boot loader install per user request

Do you remember some question about it, or changing such option?

* WIM: No I have not seen anything like this

> 
> Please be aware this isn't a standard UEFI BIOS but coreboot with a TianoCore 
> payload on top of it. This implementation is UEFI only and doesn't support a 
> CSM in any way.

This may be important details. We have some code targeting specifically 
coreboot, but then assuming grub payload there...
But it shouldn't disable installing UEFI entries, only allow to have encrypted 
/boot (since grub in coreboot can handle it).

Some relevant log entries:

anaconda.log:
01:50:16,997 INFO anaconda: bootloader XenEFI on EFI platform
01:50:17,067 INFO anaconda: dmidecode -s bios-vendor returns coreboot

syslog:
01:49:52,515 WARNING kernel:[  223.240750] efivars: get_next_variable: 
status=8000000000000003

Hmm, this actually may be a problem. I'm not sure what
status=8000000000000003 is, but if accessing efivars does not work, efibootmgr 
would not work, so can't add Qubes entry. Does `efibootmgr
- -v` show anything?

Other than that, I also can't see anything interesting.

** WIM : the efivars filesystem is populated and the efibootmgr -v is reporting 
the options I am expecting so that seems to be fine. The 0x8000000000000003 is 
EFI_UNSUPPORTED

This could be because the request has been made with attributes that aren't 
supported by the system, without know the call parameters I can't tell if this 
is the case.

  if ((Attributes & EFI_VARIABLE_ATTRIBUTES_MASK) == 0) {
    //
    // Make sure the Attributes combination is supported by the platform.
    //
    return EFI_UNSUPPORTED;

#define EFI_VARIABLE_ATTRIBUTES_MASK (EFI_VARIABLE_NON_VOLATILE | \
                                      EFI_VARIABLE_BOOTSERVICE_ACCESS | \
                                      EFI_VARIABLE_RUNTIME_ACCESS | \
                                      EFI_VARIABLE_HARDWARE_ERROR_RECORD | \
                                      EFI_VARIABLE_AUTHENTICATED_WRITE_ACCESS | 
\
                                      
EFI_VARIABLE_TIME_BASED_AUTHENTICATED_WRITE_ACCESS | \
                                      EFI_VARIABLE_APPEND_WRITE)


- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJY97zYAAoJENuP0xzK19cszh4H/2uGpcbGXvUsflXZvyo5A08Y
/kXqiO8mHfcCTWsu1knqVT2WJ8KmjJm8ERNDg3pVxor1paZBZ+BKkCzrp20zBJ/d
prhv9j3M9wHNJF+4BSJKUse7gy1RBJrKFnz85gvLBT55PH/k9BGGVk/+eXylmTuM
0yJXkYBqAik84XFRGXWrdm/Rn40h4Gjj1MlXicewKctu8oymqdzOxsIlTxeNYXZa
ZiVen8cFlc4Nsh1LvDfKi61JHrhj/0I623Pacyf/xvsSgynBK5ymRHUY3NlAGHSs
otU9IzsfCUTE6SSaQwKibWRt7P2+MSR4gW6OOgviHr5Ei0bXSQRCf0uCvVyXyQw=
=tbyJ
-----END PGP SIGNATURE-----

--
You received this message because you are subscribed to a topic in the Google 
Groups "qubes-users" group.
To unsubscribe from this topic, visit 
https://groups.google.com/d/topic/qubes-users/WLAf7nOh9Qg/unsubscribe.
To unsubscribe from this group and all its topics, send an email to 
qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20170419193904.GE1486%40mail-itl.
For more options, visit https://groups.google.com/d/optout.


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/2e6b8dd062294a3fadfaf69a3e7c68a7%40Eltsrv03.Eltan.local.
For more options, visit https://groups.google.com/d/optout.

Reply via email to