Skip to content

Always prompted for recovery key at boot - Acer Swift SFA16-41 #36

@ML0B

Description

@ML0B

Describe the bug
Always prompted for recovery key at boot - Acer Swift SFA16-41

To Reproduce
Install Aeon, reboot after successful installation, get prompted for recovery key on first boot

Follow documentation on how to remeasure boot integrity:
Enter sudo sdbootutil update-predictions or sudo sdbootutil --ask-pin update-predictions

NVIndex policy created

Expected behavior
Reboot computer and expect FDE/TPM2 to auto unlock disk

/etc/os-release

NAME="Aeon"
# VERSION="20260108"
ID="aeon"
ID_LIKE="suse opensuse opensuse-tumbleweed opensuse-microos opensuse-aeon microos"
VERSION_ID="20260108"
PRETTY_NAME="Aeon"
ANSI_COLOR="0;32"
CPE_NAME="cpe:/o:opensuse:aeon:20260108"
BUG_REPORT_URL="https://aeondesktop.org/reportbug"
SUPPORT_URL="https://aeondesktop.org/bugs"
HOME_URL="https://aeondesktop.org/"
DOCUMENTATION_URL="https://aeondesktop.org/docs"
LOGO="distributor-logo-Aeon"

Additional context
sudo sdbootutil -vv update-predictions

DEBUG: root_snapshot: 7
DEBUG: boot_root: /boot/efi
DEBUG: boot_dst: /EFI/systemd
Updating predictions
Loading config file /etc/sysconfig/fde-tools
DEBUG: /etc/sysconfig/fde-tools
FDE_SEAL_PCR_LIST=4,5,7,9
Generating TPM2 predictions with systemd-pcrlock
DEBUG: /tmp/sdbootutil.Rf7TMa/snapper.json
{
  "root": [
    {
      "subvolume": "/",
      "number": 0,
      "default": false,
      "active": false,
      "type": "single",
      "pre-number": null,
      "date": "",
      "user": "root",
      "cleanup": "",
      "description": "current",
      "userdata": null
    },
    {
      "subvolume": "/",
      "number": 1,
      "default": false,
      "active": false,
      "type": "single",
      "pre-number": null,
      "date": "2026-01-08 18:38:41",
      "user": "root",
      "cleanup": "number",
      "description": "first root filesystem",
      "userdata": {
        "important": "yes"
      }
    },
    {
      "subvolume": "/",
      "number": 2,
      "default": false,
      "active": false,
      "type": "single",
      "pre-number": null,
      "date": "2026-01-12 00:40:32",
      "user": "root",
      "cleanup": "number",
      "description": "Snapshot Update of #1",
      "userdata": null
    },
    {
      "subvolume": "/",
      "number": 3,
      "default": false,
      "active": false,
      "type": "single",
      "pre-number": null,
      "date": "2026-01-13 17:09:02",
      "user": "root",
      "cleanup": "number",
      "description": "Snapshot Update of #2",
      "userdata": null
    },
    {
      "subvolume": "/",
      "number": 4,
      "default": false,
      "active": false,
      "type": "single",
      "pre-number": null,
      "date": "2026-01-13 17:10:48",
      "user": "root",
      "cleanup": "number",
      "description": "Snapshot Update of #3",
      "userdata": null
    },
    {
      "subvolume": "/",
      "number": 5,
      "default": false,
      "active": false,
      "type": "single",
      "pre-number": null,
      "date": "2026-01-13 17:37:01",
      "user": "root",
      "cleanup": "number",
      "description": "Snapshot Update of #2",
      "userdata": null
    },
    {
      "subvolume": "/",
      "number": 6,
      "default": false,
      "active": false,
      "type": "single",
      "pre-number": null,
      "date": "2026-01-13 17:47:03",
      "user": "root",
      "cleanup": "number",
      "description": "Snapshot Update of #5",
      "userdata": null
    },
    {
      "subvolume": "/",
      "number": 7,
      "default": true,
      "active": true,
      "type": "single",
      "pre-number": null,
      "date": "2026-01-13 17:49:39",
      "user": "root",
      "cleanup": "number",
      "description": "Snapshot Update of #5",
      "userdata": null
    }
  ]
}
DEBUG: Entry filter: jq [.[]|select(has("options"))|select(.options|test("root=(?:UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581|/dev/mapper/aeon_root) .*rootflags=subvol=@/.snapshots/(:?7|5|2)/snapshot"))]
DEBUG: /tmp/sdbootutil.Rf7TMa/entries.json
[
  {
    "type": "type1",
    "source": "esp",
    "id": "aeon-6.18.3-1-default-7.conf",
    "path": "/boot/efi/loader/entries/aeon-6.18.3-1-default-7.conf",
    "root": "/boot/efi",
    "title": "Aeon 20260108",
    "showTitle": "Aeon 20260108 (7@6.18.3-1-default)",
    "sortKey": "aeon",
    "version": "7@6.18.3-1-default",
    "options": "quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/7/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490",
    "linux": "/aeon/6.18.3-1-default/linux-486a1027722e38ef3daa159cb5c40996322db294",
    "initrd": [
      "/aeon/6.18.3-1-default/initrd-d4b2433450e97748e8f17ebe0bfd7dc0409c4aee"
    ],
    "isReported": true,
    "isDefault": true,
    "isSelected": true,
    "addons": null,
    "cmdline": "quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/7/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490"
  },
  {
    "type": "type1",
    "source": "esp",
    "id": "aeon-6.18.3-1-default-5.conf",
    "path": "/boot/efi/loader/entries/aeon-6.18.3-1-default-5.conf",
    "root": "/boot/efi",
    "title": "Aeon 20260108",
    "showTitle": "Aeon 20260108 (5@6.18.3-1-default)",
    "sortKey": "aeon",
    "version": "5@6.18.3-1-default",
    "options": "quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/5/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490",
    "linux": "/aeon/6.18.3-1-default/linux-486a1027722e38ef3daa159cb5c40996322db294",
    "initrd": [
      "/aeon/6.18.3-1-default/initrd-d4b2433450e97748e8f17ebe0bfd7dc0409c4aee"
    ],
    "isReported": true,
    "isDefault": false,
    "isSelected": false,
    "addons": null,
    "cmdline": "quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/5/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490"
  },
  {
    "type": "type1",
    "source": "esp",
    "id": "aeon-6.18.3-1-default-2.conf",
    "path": "/boot/efi/loader/entries/aeon-6.18.3-1-default-2.conf",
    "root": "/boot/efi",
    "title": "Aeon 20260108",
    "showTitle": "Aeon 20260108 (2@6.18.3-1-default)",
    "sortKey": "aeon",
    "version": "2@6.18.3-1-default",
    "options": "quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/2/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490",
    "linux": "/aeon/6.18.3-1-default/linux-486a1027722e38ef3daa159cb5c40996322db294",
    "initrd": [
      "/aeon/6.18.3-1-default/initrd-d4b2433450e97748e8f17ebe0bfd7dc0409c4aee"
    ],
    "isReported": true,
    "isDefault": false,
    "isSelected": false,
    "addons": null,
    "cmdline": "quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/2/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490"
  }
]
DEBUG: Added priority and kernel version to entry file (for prediction)
DEBUG: /tmp/sdbootutil.Rf7TMa/entries.json
[
  {
    "type": "type1",
    "source": "esp",
    "id": "aeon-6.18.3-1-default-7.conf",
    "path": "/boot/efi/loader/entries/aeon-6.18.3-1-default-7.conf",
    "root": "/boot/efi",
    "title": "Aeon 20260108",
    "showTitle": "Aeon 20260108 (7@6.18.3-1-default)",
    "sortKey": "aeon",
    "version": "7@6.18.3-1-default",
    "options": "quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/7/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490",
    "linux": "/aeon/6.18.3-1-default/linux-486a1027722e38ef3daa159cb5c40996322db294",
    "initrd": [
      "/aeon/6.18.3-1-default/initrd-d4b2433450e97748e8f17ebe0bfd7dc0409c4aee"
    ],
    "isReported": true,
    "isDefault": true,
    "isSelected": true,
    "addons": null,
    "cmdline": "quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/7/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490",
    "priority": 0,
    "kernel": [
      6,
      18,
      3,
      1
    ]
  },
  {
    "type": "type1",
    "source": "esp",
    "id": "aeon-6.18.3-1-default-5.conf",
    "path": "/boot/efi/loader/entries/aeon-6.18.3-1-default-5.conf",
    "root": "/boot/efi",
    "title": "Aeon 20260108",
    "showTitle": "Aeon 20260108 (5@6.18.3-1-default)",
    "sortKey": "aeon",
    "version": "5@6.18.3-1-default",
    "options": "quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/5/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490",
    "linux": "/aeon/6.18.3-1-default/linux-486a1027722e38ef3daa159cb5c40996322db294",
    "initrd": [
      "/aeon/6.18.3-1-default/initrd-d4b2433450e97748e8f17ebe0bfd7dc0409c4aee"
    ],
    "isReported": true,
    "isDefault": false,
    "isSelected": false,
    "addons": null,
    "cmdline": "quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/5/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490",
    "priority": 1,
    "kernel": [
      6,
      18,
      3,
      1
    ]
  },
  {
    "type": "type1",
    "source": "esp",
    "id": "aeon-6.18.3-1-default-2.conf",
    "path": "/boot/efi/loader/entries/aeon-6.18.3-1-default-2.conf",
    "root": "/boot/efi",
    "title": "Aeon 20260108",
    "showTitle": "Aeon 20260108 (2@6.18.3-1-default)",
    "sortKey": "aeon",
    "version": "2@6.18.3-1-default",
    "options": "quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/2/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490",
    "linux": "/aeon/6.18.3-1-default/linux-486a1027722e38ef3daa159cb5c40996322db294",
    "initrd": [
      "/aeon/6.18.3-1-default/initrd-d4b2433450e97748e8f17ebe0bfd7dc0409c4aee"
    ],
    "isReported": true,
    "isDefault": false,
    "isSelected": false,
    "addons": null,
    "cmdline": "quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/2/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490",
    "priority": 2,
    "kernel": [
      6,
      18,
      3,
      1
    ]
  }
]
DEBUG: Cleaning shifted measurements older than 29 minutes
DEBUG: systemd-pcrlock log --json=short
Couldn't find component '710-kernel-cmdline-boot-loader' in event log.
Couldn't find component '750-enter-initrd' in event log.
Didn't find component '800-leave-initrd' in event log, assuming system hasn't reached it yet.
Didn't find component '850-sysinit' in event log, assuming system hasn't reached it yet.
Didn't find component '900-ready' in event log, assuming system hasn't reached it yet.
Skipped 2 components after location '940-' (950-shutdown, 990-final).
Unable to recognize 2 components in event log.
Event log record 63 (PCR 12, "String: initrd=\aeon\6.18.3-1-default\initrd-d4b2433450e97748e8f17ebe0bfd7dc0409c4aee quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/7/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490") not matching any component.
Event log record 55 (PCR 14, "Raw: MokList\000") not matching any component.
Event log record 68 (PCR 15, "cryptsetup:aeon_root:069d6395-2810-437c-bc3a-5373036cc7a3") not matching any component.
DEBUG: Shifting component 250-firmware-code-early
DEBUG: /var/lib/pcrlock.d/250-firmware-code-early.pcrlock.d/generated.pcrlock found in the eventlog
DEBUG: Shifting component 550-firmware-code-late
DEBUG: /var/lib/pcrlock.d/550-firmware-code-late.pcrlock.d/generated.pcrlock found in the eventlog
DEBUG: systemd-pcrlock lock-firmware-code
/var/lib/pcrlock.d/250-firmware-code-early.pcrlock.d/generated.pcrlock written.
/var/lib/pcrlock.d/550-firmware-code-late.pcrlock.d/generated.pcrlock written.
DEBUG: Shifting component 250-firmware-config-early
DEBUG: /var/lib/pcrlock.d/250-firmware-config-early.pcrlock.d/generated.pcrlock found in the eventlog
DEBUG: Shifting component 550-firmware-config-late
DEBUG: /var/lib/pcrlock.d/550-firmware-config-late.pcrlock.d/generated.pcrlock found in the eventlog
DEBUG: systemd-pcrlock lock-firmware-config
/var/lib/pcrlock.d/250-firmware-config-early.pcrlock.d/generated.pcrlock written.
/var/lib/pcrlock.d/550-firmware-config-late.pcrlock.d/generated.pcrlock written.
DEBUG: Shifting component 240-secureboot-policy
DEBUG: /var/lib/pcrlock.d/240-secureboot-policy.pcrlock.d/generated.pcrlock found in the eventlog
DEBUG: Shifting component 620-secureboot-authority
DEBUG: /var/lib/pcrlock.d/620-secureboot-authority.pcrlock.d/generated.pcrlock found in the eventlog
DEBUG: Shifting component 600-gpt
DEBUG: /var/lib/pcrlock.d/600-gpt.pcrlock.d/generated.pcrlock found in the eventlog
DEBUG: systemd-pcrlock lock-gpt /boot/efi
/var/lib/pcrlock.d/600-gpt.pcrlock.d/generated.pcrlock written.
DEBUG: Shifting component 630-shim-efi-application
DEBUG: /var/lib/pcrlock.d/630-shim-efi-application.pcrlock.d/generated.pcrlock found in the eventlog
DEBUG: systemd-pcrlock lock-pe --pcrlock=/var/lib/pcrlock.d/630-shim-efi-application.pcrlock.d/generated.pcrlock /boot/efi/EFI/systemd/shim.efi
/var/lib/pcrlock.d/630-shim-efi-application.pcrlock.d/generated.pcrlock written.
DEBUG: Shifting component 640-boot-loader-efi-application
DEBUG: /var/lib/pcrlock.d/640-boot-loader-efi-application.pcrlock.d/generated.pcrlock found in the eventlog
DEBUG: systemd-pcrlock lock-pe --pcrlock=/var/lib/pcrlock.d/640-boot-loader-efi-application.pcrlock.d/generated.pcrlock /boot/efi/EFI/systemd/grub.efi
/var/lib/pcrlock.d/640-boot-loader-efi-application.pcrlock.d/generated.pcrlock written.
Generating TPM2 predictions with systemd-pcrlock (systemd-boot)
DEBUG: Shifting component 641-sdboot-loader-conf
DEBUG: /var/lib/pcrlock.d/641-sdboot-loader-conf.pcrlock.d/generated.pcrlock found in the eventlog
DEBUG: systemd-pcrlock lock-raw /boot/efi/loader/loader.conf --pcr=5 --pcrlock=/var/lib/pcrlock.d/641-sdboot-loader-conf.pcrlock.d/generated.pcrlock
/var/lib/pcrlock.d/641-sdboot-loader-conf.pcrlock.d/generated.pcrlock written.
DEBUG: Shifting component 650-kernel-efi-application
DEBUG: /var/lib/pcrlock.d/650-kernel-efi-application.pcrlock.d/linux-1.pcrlock found in the eventlog
DEBUG: systemd-pcrlock lock-pe --pcrlock=/var/lib/pcrlock.d/650-kernel-efi-application.pcrlock.d/linux-1.pcrlock /boot/efi//aeon/6.18.3-1-default/linux-486a1027722e38ef3daa159cb5c40996322db294
/var/lib/pcrlock.d/650-kernel-efi-application.pcrlock.d/linux-1.pcrlock written.
DEBUG: Shifting component 710-kernel-cmdline-initrd-entry
DEBUG: /var/lib/pcrlock.d/710-kernel-cmdline-initrd-entry.pcrlock.d/cmdline-initrd-1.pcrlock found in the eventlog
DEBUG: Shifting component 710-kernel-cmdline-boot-loader
DEBUG: No matching variation found for 710-kernel-cmdline-boot-loader
DEBUG: systemd-pcrlock lock-kernel-cmdline --pcrlock=/tmp/sdbootutil.Rf7TMa/cmdline.pcrlock /tmp/sdbootutil.Rf7TMa/cmdline
/tmp/sdbootutil.Rf7TMa/cmdline.pcrlock written.
DEBUG: systemd-pcrlock lock-raw --pcr=12 --pcrlock=/var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-1.pcrlock /tmp/sdbootutil.Rf7TMa/cmdline.utf16
/var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-1.pcrlock written.
DEBUG: systemd-pcrlock lock-kernel-cmdline --pcrlock=/tmp/sdbootutil.Rf7TMa/cmdline.pcrlock /tmp/sdbootutil.Rf7TMa/cmdline
/tmp/sdbootutil.Rf7TMa/cmdline.pcrlock written.
DEBUG: systemd-pcrlock lock-raw --pcr=12 --pcrlock=/var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-2.pcrlock /tmp/sdbootutil.Rf7TMa/cmdline.utf16
/var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-2.pcrlock written.
DEBUG: systemd-pcrlock lock-kernel-cmdline --pcrlock=/tmp/sdbootutil.Rf7TMa/cmdline.pcrlock /tmp/sdbootutil.Rf7TMa/cmdline
/tmp/sdbootutil.Rf7TMa/cmdline.pcrlock written.
DEBUG: systemd-pcrlock lock-raw --pcr=12 --pcrlock=/var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-3.pcrlock /tmp/sdbootutil.Rf7TMa/cmdline.utf16
/var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-3.pcrlock written.
DEBUG: systemd-pcrlock --pcr=4,5,7,9 --recovery-pin=show make-policy
Couldn't find component '710-kernel-cmdline-boot-loader' in event log.
Couldn't find component '750-enter-initrd' in event log.
Didn't find component '800-leave-initrd' in event log, assuming system hasn't reached it yet.
Didn't find component '850-sysinit' in event log, assuming system hasn't reached it yet.
Didn't find component '900-ready' in event log, assuming system hasn't reached it yet.
Skipped 2 components after location '940-' (950-shutdown, 990-final).
Unable to recognize 2 components in event log.
Event log record 63 (PCR 12, "String: initrd=\aeon\6.18.3-1-default\initrd-d4b2433450e97748e8f17ebe0bfd7dc0409c4aee quiet loglevel=2 systemd.show_status=0 console=ttyS0,115200 console=tty0 vt.global_cursor_default=0 ignition.platform.id=metal security=selinux selinux=1 root=/dev/mapper/aeon_root root=UUID=88c26e95-d8f8-43c6-a2bb-c9cb02f81581 rootflags=subvol=@/.snapshots/7/snapshot systemd.machine_id=cad56c24333b4468a8d9a46143d0d490") not matching any component.
Event log record 55 (PCR 14, "Raw: MokList\000") not matching any component.
Event log record 68 (PCR 15, "cryptsetup:aeon_root:069d6395-2810-437c-bc3a-5373036cc7a3") not matching any component.
PCR 4 (boot-loader-code) matches event log and fully consists of recognized measurements. Including in set of PCRs.
PCR 5 (boot-loader-config) matches event log and fully consists of recognized measurements. Including in set of PCRs.
PCR 7 (secure-boot-policy) matches event log and fully consists of recognized measurements. Including in set of PCRs.
PCR 9 (kernel-initrd) matches event log and fully consists of recognized measurements. Including in set of PCRs.
PCRs in protection mask: 4 (boot-loader-code), 5 (boot-loader-config), 7 (secure-boot-policy), 9 (kernel-initrd)
Predicted future PCRs in 1.477288s.
Prediction is identical to current policy, skipping update.
NVIndex policy created
DEBUG: Cleaning temporary directory /tmp/sdbootutil.Rf7TMa

grep . /sys/class/tpm/tpm0/device/* 2>/dev/null

/sys/class/tpm/tpm0/device/description:TPM 2.0 Device
/sys/class/tpm/tpm0/device/hid:MSFT0101
/sys/class/tpm/tpm0/device/modalias:acpi:MSFT0101:MSFT0101:
/sys/class/tpm/tpm0/device/path:\_SB_.TPM2
/sys/class/tpm/tpm0/device/status:15
/sys/class/tpm/tpm0/device/uevent:DRIVER=tpm_crb
/sys/class/tpm/tpm0/device/uevent:MODALIAS=acpi:MSFT0101:MSFT0101:

cat /sys/class/dmi/id/bios_vendor
Insyde Corp.
cat /sys/class/dmi/id/bios_version
V1.10
cat /sys/class/dmi/id/bios_date
01/15/2024

=== OS ===
NAME="Aeon"

VERSION="20260108"

ID="aeon"
ID_LIKE="suse opensuse opensuse-tumbleweed opensuse-microos opensuse-aeon microos"
VERSION_ID="20260108"
PRETTY_NAME="Aeon"
ANSI_COLOR="0;32"
CPE_NAME="cpe:/o:opensuse:aeon:20260108"
BUG_REPORT_URL="https://aeondesktop.org/reportbug"
SUPPORT_URL="https://aeondesktop.org/bugs"
HOME_URL="https://aeondesktop.org/"
DOCUMENTATION_URL="https://aeondesktop.org/docs"
LOGO="distributor-logo-Aeon"

=== Kernel ===
Linux blackbook 6.18.3-1-default #1 SMP PREEMPT_DYNAMIC Fri Jan 2 18:23:02 UTC 2026 (c68e342) x86_64 x86_64 x86_64 GNU/Linux

=== CPU ===
Architecture: x86_64
CPU op-mode(s): 32-bit, 64-bit
Address sizes: 48 bits physical, 48 bits virtual
Byte Order: Little Endian
CPU(s): 12
On-line CPU(s) list: 0-11
Vendor ID: AuthenticAMD
Model name: AMD Ryzen 5 6600U with Radeon Graphics
CPU family: 25
Model: 68
Thread(s) per core: 2
Core(s) per socket: 6
Socket(s): 1
Stepping: 1
Frequency boost: enabled
CPU(s) scaling MHz: 32%
CPU max MHz: 4586,3428
CPU min MHz: 414,4290
BogoMIPS: 5789,42
Flags: fpu vme de pse tsc msr pae mce cx8 apic sep mtrr pge mca cmov pat pse36 c
lflush mmx fxsr sse sse2 ht syscall nx mmxext fxsr_opt pdpe1gb rdtscp lm
constant_tsc rep_good nopl xtopology nonstop_tsc cpuid extd_apicid aperfm
perf rapl pni pclmulqdq monitor ssse3 fma cx16 sse4_1 sse4_2 x2apic movbe
popcnt aes xsave avx f16c rdrand lahf_lm cmp_legacy svm extapic cr8_lega
cy abm sse4a misalignsse 3dnowprefetch osvw ibs skinit wdt tce topoext pe
rfctr_core perfctr_nb bpext perfctr_llc mwaitx cpb cat_l3 cdp_l3 hw_pstat
e ssbd mba ibrs ibpb stibp vmmcall fsgsbase bmi1 avx2 smep bmi2 erms invp
cid cqm rdt_a rdseed adx smap clflushopt clwb sha_ni xsaveopt xsavec xget
bv1 xsaves cqm_llc cqm_occup_llc cqm_mbm_total cqm_mbm_local user_shstk c
lzero irperf xsaveerptr rdpru wbnoinvd cppc arat npt lbrv svm_lock nrip_s
ave tsc_scale vmcb_clean flushbyasid decodeassists pausefilter pfthreshol
d avic v_vmsave_vmload vgif v_spec_ctrl umip pku ospke vaes vpclmulqdq rd
pid overflow_recov succor smca fsrm debug_swap
Virtualization features:
Virtualization: AMD-V
Caches (sum of all):
L1d: 192 KiB (6 instances)
L1i: 192 KiB (6 instances)
L2: 3 MiB (6 instances)
L3: 16 MiB (1 instance)
NUMA:
NUMA node(s): 1
NUMA node0 CPU(s): 0-11
Vulnerabilities:
Gather data sampling: Not affected
Ghostwrite: Not affected
Indirect target selection: Not affected
Itlb multihit: Not affected
L1tf: Not affected
Mds: Not affected
Meltdown: Not affected
Mmio stale data: Not affected
Old microcode: Not affected
Reg file data sampling: Not affected
Retbleed: Not affected
Spec rstack overflow: Mitigation; Safe RET
Spec store bypass: Mitigation; Speculative Store Bypass disabled via prctl
Spectre v1: Mitigation; usercopy/swapgs barriers and __user pointer sanitization
Spectre v2: Mitigation; Retpolines; IBPB conditional; IBRS_FW; STIBP always-on; RSB f
illing; PBRSB-eIBRS Not affected; BHI Not affected
Srbds: Not affected
Tsa: Mitigation; Clear CPU buffers
Tsx async abort: Not affected
Vmscape: Mitigation; IBPB before exit to userspace

=== Memory ===
total used free shared buff/cache available
Mem: 14Gi 12Gi 264Mi 469Mi 2,7Gi 2,2Gi
Swap: 14Gi 124Mi 14Gi

=== Storage ===
Filesystem Size Used Avail Use% Mounted on
/dev/mapper/aeon_root 473G 84G 387G 18% /
/dev/mapper/aeon_root 473G 84G 387G 18% /etc
/dev/mapper/aeon_root 473G 84G 387G 18% /root
/dev/mapper/aeon_root 473G 84G 387G 18% /var
devtmpfs 7,4G 0 7,4G 0% /dev
tmpfs 7,5G 18M 7,4G 1% /dev/shm
efivarfs 148K 127K 17K 89% /sys/firmware/efi/efivars
tmpfs 3,0G 2,1M 3,0G 1% /run
tmpfs 1,0M 0 1,0M 0% /run/credentials/systemd-cryptsetup@aeon_root.service
tmpfs 7,5G 764K 7,5G 1% /tmp
tmpfs 1,0M 0 1,0M 0% /run/credentials/systemd-journald.service
/dev/mapper/aeon_root 473G 84G 387G 18% /.snapshots
/dev/mapper/aeon_root 473G 84G 387G 18% /opt
/dev/mapper/aeon_root 473G 84G 387G 18% /boot/writable
/dev/mapper/aeon_root 473G 84G 387G 18% /usr/local
/dev/mapper/aeon_root 473G 84G 387G 18% /boot/grub2/x86_64-efi
/dev/mapper/aeon_root 473G 84G 387G 18% /boot/grub2/i386-pc
/dev/mapper/aeon_root 473G 84G 387G 18% /srv
/dev/nvme0n1p1 4,0G 173M 3,9G 5% /boot/efi
/dev/mapper/aeon_root 473G 84G 387G 18% /home
tmpfs 1,5G 246M 1,3G 17% /run/user/1000
tmpfs 1,0M 0 1,0M 0% /run/credentials/serial-getty@ttyS0.service

=== Motherboard ===
/sys/class/dmi/id/board_asset_tag:Type2 - Board Asset Tag
/sys/class/dmi/id/board_name:Globefish_RBU
/sys/class/dmi/id/board_vendor:RB
/sys/class/dmi/id/board_version:V1.10

=== BIOS ===
/sys/class/dmi/id/bios_date:01/15/2024
/sys/class/dmi/id/bios_release:1.10
/sys/class/dmi/id/bios_vendor:Insyde Corp.
/sys/class/dmi/id/bios_version:V1.10

=== TPM ===
/dev/tpm0 /dev/tpmrm0
dmesg: read kernel buffer failed: Operation not permitted

Metadata

Metadata

Assignees

No one assigned

    Labels

    WIPWork In ProgressbugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions