Open marmarek opened 7 months ago
@marmarek you need to reset TPM instead of resealing totp from TPM menu
Normally, flow after installing OS is to run oem factory reset / re-ownership.
Doing OEM re-ownership resets TPM as well.
Has it changed at some point? I think the current flow coded in that openQA test worked before (but not sure when, definitely not recently)...
Has it changed at some point? I think the current flow coded in that openQA test worked before (but not sure when, definitely not recently)...
I can check deeper in the next week but that code hasn't changed for 6 years. But string concatenation might be flaky here, while counter clearly doesn't exist here in shared output.
Please identify some basic details to help process the report
A. Provide Hardware Details
1. What board are you using (see list of boards here)?
2. Does your computer have a dGPU or is it iGPU-only?
3. Who installed Heads on this computer?
4. What PGP key is being used?
5. Are you using the PGP key to provide HOTP verification?
B. Identify how the board was flashed
1. Is this problem related to updating heads or flashing it for the first time?
2. If the problem is related to an update, how did you attempt to apply the update?
3. How was Heads initially flashed
4. Was the board flashed with a maximized or non-maximized/legacy rom?
5. If Heads was externally flashed, was IFD unlocked?
C. Identify the rom related to this bug report
1. Did you download or build the rom at issue in this bug report?
2. If you downloaded your rom, where did you get it from?
Please provide the release number or otherwise identify the rom downloaded
https://circleci.com/gh/linuxboot/heads/14178 ( x230-hotp-maximized_usb-kb of https://github.com/linuxboot/heads/commit/4a57c615e972149eefd52d95ba919ff54d53bb0a)
Please describe the problem
Describe the bug
Creating rollback file fails after OS reinstall (including wiping /boot).
To Reproduce Steps to reproduce the behavior:
Expected behavior
Rollback file successfully created.
Screenshots
https://openqa.qubes-os.org/tests/88760/video?filename=video.ogv&t=92.9
The link above includes full flow leading to the failure, I recommend watching with 25% speed otherwise it's hard to follow.
Additional context
The problem didn't happened when I preserved heads-related files in /boot across reinstall (then it only required re-signing boot configs, which works fine).