Skip to content

Debugging failure to unlock is hard #272

@xnox

Description

@xnox

During release sprint debugging failure to unlock hybrid desktop was hard.

One had to boot to live session, change boot partition cmdline to go into dangerous mode to extract journal and TPM measurements.

It would have failed upon failure to unlock to store a copy of tpm measurements and journal on the boot or seed partition.

It would also help if reporting install failure from a live session would stop and upload copies of the above stored failed to unlock. Such that if first boot fails one can go back to installer to report failure.

Separately it was concerning that measurements to get to installer boot were not verified to be plausible for first boot unlock.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions