------- Comment From <email address hidden> 2020-02-04 04:02 EDT-------
(In reply to comment #17)
> Did you also do a test based on a cleanly installed system, rather than
> after an upgrade?
> If not, would you mind giving it a try?
Retried the test with a new Ubuntu20.04 installation.
This install already had s390-tools 2.12 in place.
When trying to IPL the system with "Enable Secure Boot for Linux"
option selected on the HMC, the IPL failed just as before:
Preparing system.
Starting system.
System version 8.
Watchdog enabled.
Running 'ZBootLoader' version '1.0.0' level 'D41C.D41C_0013'.
ZBootLoader 2.0.0.
MLOLOA6269050E Secure IPL: Execute entry does not point to the beginning of a signed component on device HBA=0.0.1900, WWPN=500507630B01C320, LUN=4050404700000000.
IPL fail
------- Comment From <email address hidden> 2020-02-04 04:02 EDT-------
(In reply to comment #17)
> Did you also do a test based on a cleanly installed system, rather than
> after an upgrade?
> If not, would you mind giving it a try?
Retried the test with a new Ubuntu20.04 installation.
This install already had s390-tools 2.12 in place.
root@t35lp36:~# cat /etc/os-release /www.ubuntu. com/" /help.ubuntu. com/" /bugs.launchpad .net/ubuntu/" POLICY_ URL="https:/ /www.ubuntu. com/legal/ terms-and- policies/ privacy- policy" CODENAME= focal CODENAME= focal
NAME="Ubuntu"
VERSION="20.04 LTS (Focal Fossa)"
ID=ubuntu
ID_LIKE=debian
PRETTY_NAME="Ubuntu Focal Fossa (development branch)"
VERSION_ID="20.04"
HOME_URL="https:/
SUPPORT_URL="https:/
BUG_REPORT_URL="https:/
PRIVACY_
VERSION_
UBUNTU_
root@t35lp36:~#
root@t35lp36:~# uname -a
Linux t35lp36 5.4.0-12-generic #15-Ubuntu SMP Tue Jan 21 17:56:00 UTC 2020 s390x s390x s390x GNU/Linux
root@t35lp36:~# apt list s390-tools focal,now 2.12.0-0ubuntu1 s390x [installed]
Listing... Done
s390-tools/
root@t35lp36:~# cat /etc/zipl.conf
[defaultboot]
defaultmenu = menu
secure=1
:menu
target = /boot
1 = ubuntu
2 = old
default = 1
prompt = 1
timeout = 10
[ubuntu] a631ceb7- 59fc-4450- 8ff7-208b91bd22 c1 crashkernel=196M
target = /boot
image = /boot/vmlinuz
ramdisk = /boot/initrd.img
parameters = root=UUID=
[old] img.old a631ceb7- 59fc-4450- 8ff7-208b91bd22 c1 crashkernel=196M
target = /boot
image = /boot/vmlinuz.old
ramdisk = /boot/initrd.
parameters = root=UUID=
optional = 1
root@t35lp36:~# zipl -V tools/zipl_ helper. device- mapper /boot ....... ....... ....... ....: fd:00 *) ....... ....... ....... .: fd:01 ....... ....... ....: dm-0 ....... ....... ....... ....: disk partition ....... ....... ......: SCSI disk layout *) ....... ....... : 2048 *) a631ceb7- 59fc-4450- 8ff7-208b91bd22 c1 crashkernel=196M' 0x00005fff 0x0000ffff 0x0000dfff 0x000091ff 0x007d8fff 0x007da1ff 0x01a8f5ff img.old a631ceb7- 59fc-4450- 8ff7-208b91bd22 c1 crashkernel=196M' 0x00005fff 0x0000ffff 0x0000dfff 0x000091ff 0x007d8fff 0x007da1ff 0x01a8f5ff
Using config file '/etc/zipl.conf'
Run /lib/s390-
Target device information
Device.
Partition.
Device name...
Device driver name..............: device-mapper
Type...
Disk layout.
Geometry - start..
File system block size..........: 4096
Physical block size.............: 512 *)
Device size in physical blocks..: 37746688
*) Data provided by script.
Building bootmap in '/boot'
Building menu 'menu'
Adding #1: IPL section 'ubuntu' (default)
initial ramdisk...: /boot/initrd.img
kernel image......: /boot/vmlinuz
kernel parmline...: 'root=UUID=
component address:
heap area.......: 0x00002000-
stack area......: 0x0000f000-
internal loader.: 0x0000a000-
parameters......: 0x00009000-
kernel image....: 0x00010000-
parmline........: 0x007da000-
initial ramdisk.: 0x007e0000-
Adding #2: IPL section 'old'
initial ramdisk...: /boot/initrd.
kernel image......: /boot/vmlinuz.old
kernel parmline...: 'root=UUID=
component address:
heap area.......: 0x00002000-
stack area......: 0x0000f000-
internal loader.: 0x0000a000-
parameters......: 0x00009000-
kernel image....: 0x00010000-
parmline........: 0x007da000-
initial ramdisk.: 0x007e0000-
Preparing boot device: dm-0.
Detected SCSI PCBIOS disk layout.
Writing SCSI master boot record.
Syncing disks...
Done.
root@t35lp36:~#
When trying to IPL the system with "Enable Secure Boot for Linux"
option selected on the HMC, the IPL failed just as before:
Preparing system. 01C320, LUN=40504047000 00000.
Starting system.
System version 8.
Watchdog enabled.
Running 'ZBootLoader' version '1.0.0' level 'D41C.D41C_0013'.
ZBootLoader 2.0.0.
MLOLOA6269050E Secure IPL: Execute entry does not point to the beginning of a signed component on device HBA=0.0.1900, WWPN=500507630B
IPL fail