Bug 1219991 - [Build 20240215] sdboot/encrypted fails to auto-decrypt with TPM
Summary: [Build 20240215] sdboot/encrypted fails to auto-decrypt with TPM
Status: RESOLVED FIXED
Alias: None
Product: openSUSE Tumbleweed
Classification: openSUSE
Component: Other (show other bugs)
Version: Current
Hardware: Other Other
: P5 - None : Normal (vote)
Target Milestone: ---
Assignee: Ludwig Nussel
QA Contact: E-mail List
URL: https://openqa.opensuse.org/tests/394...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-02-16 08:30 UTC by Dominique Leuenberger
Modified: 2024-02-19 13:14 UTC (History)
2 users (show)

See Also:
Found By: openQA
Services Priority:
Business Priority:
Blocker: Yes
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Dominique Leuenberger 2024-02-16 08:30:01 UTC
## Observation

Latest change most likely influencing this:
 https://build.opensuse.org/request/show/1146526

From discussion on IRC: it seems systemd-pcrlock is missing in the image

openQA test in scenario microos-Tumbleweed-MicroOS-Image-sdboot-x86_64-microos-wizard-tpm@uefi fails in
[ansible](https://openqa.opensuse.org/tests/3942950/modules/ansible/steps/30)

## Test suite description
Like MicroOS, but use neither combustion nor ignition for the intial configuration, so jeos-firstboot runs.


## Reproducible

Fails since (at least) Build [20240215](https://openqa.opensuse.org/tests/3942950) (current job)


## Expected result

Last good: [20240214](https://openqa.opensuse.org/tests/3940264) (or more recent)


## Further details

Always latest result in this scenario: [latest](https://openqa.opensuse.org/tests/latest?arch=x86_64&distri=microos&flavor=MicroOS-Image-sdboot&machine=uefi&test=microos-wizard-tpm&version=Tumbleweed)
Comment 1 Alberto Planas Dominguez 2024-02-19 13:06:43 UTC
I think that the problem is that the image should be tested with the disk-encryption-tool update
Comment 2 Dominique Leuenberger 2024-02-19 13:14:13 UTC
(In reply to Alberto Planas Dominguez from comment #1)
> I think that the problem is that the image should be tested with the
> disk-encryption-tool update

I think we can confirm this as fixed:
  https://openqa.opensuse.org/tests/3945743

Snapshot 0216 got the disk-encryption-tool update included and the test passed again (Snapshot 0215 was discarded, 0216 was published)