Skip to content

cbmem -L output with TPM1.2 under coreboot 24.12 segfaults #1956

Closed
@marmarek

Description

@marmarek

Issue was renamed from symptom "Regenerating HOTP fails with "Unable to unseal HOTP secret" to "cbmem -L output with TPM1.2 under coreboot 24.12 segfaults" cause.

Please identify some basic details to help process the report

A. Provide Hardware Details

  1. What board are you using? (Choose from the list of boards here)

x230

  1. Does your computer have a dGPU or is it iGPU-only?

    • dGPU (Distinct GPU other then internal GPU)
    • iGPU-only (Internal GPU, normally Intel GPU)
  2. Who installed Heads on this computer?

  3. What PGP key is being used?

    • Librem Key (Nitrokey Pro 2 rebranded)
    • Nitrokey Pro
    • Nitrokey Pro 2
    • Nitrokey 3 NFC
    • Nitrokey 3 NFC Mini
    • Nitrokey Storage
    • Nitrokey Storage 2
    • Yubikey
    • Other
  4. Are you using the PGP key to provide HOTP verification?

    • Yes
    • No
    • I don't know

B. Identify how the board was flashed

  1. Is this problem related to updating heads or flashing it for the first time?

    • First-time flash
    • Updating heads
  2. If the problem is related to an update, how did you attempt to apply the update?

    • Using the Heads menus
    • Flashrom via the Recovery Shell
    • External flashing
  3. How was Heads initially flashed?

    • External flashing
    • Internal-only / 1vyprep+1vyrain / skulls
    • Don't know
  4. Was the board flashed with a maximized or non-maximized/legacy rom?

    • Maximized
    • Non-maximized / legacy
    • I don't know
  5. If Heads was externally flashed, was IFD unlocked?

    • Yes
    • No
    • Don't know

C. Identify the rom related to this bug report

  1. Did you download or build the rom at issue in this bug report?

    • I downloaded it
    • I built it
  2. If you downloaded your rom, where did you get it from?

    • Heads CircleCi
    • Purism
    • Nitrokey
    • Dasharo DTS (Novacustom)
    • Somewhere else (please identify)

    Please provide the release number or otherwise identify the rom downloaded

  3. If you built your rom, which repository:branch did you use?

    • Heads:Master
    • Other (please identify)
  4. What version of coreboot did you use in building?
    { You can find this information from github commit ID or once flashed, by giving the complete version from Sytem Information under Options --> menu}

  5. In building the rom, where did you get the blobs?

    • No blobs required
    • Provided by the company that installed Heads on the device
    • Extracted from a backup rom taken from this device
    • Extracted from another backup rom taken from another device (please identify the board model)
    • Extracted from the online bios using the automated tools provided in Heads
    • I don't know

Please describe the problem

Describe the bug

After Heads update (via the menu) regenerating HOTP secret fails with message that it fails to unseal the HOTP secret. But I'm regenerating it exactly because it (as expected) couldn't be unsealed after the update!

To Reproduce
Steps to reproduce the behavior:

  1. Fetch heads-x230-hotp-maximized_usb-kb-v0.2.0-2731-gf572998.zip from CI.
  2. Update Heads via the menu.
  3. Reboot the system after update, see "TOTP Generation Failed" message
  4. Choose "Generate new HOTP/TOTP secret"
  5. Confirm ("Yes")
  6. See QR code, confirm to "configure your HOTP USB Security dongle"
  7. See the message "Error PCR mismatch from TPM_Unseal"

Expected behavior

New secret written to the USB dongle (after the admin pin prompt).

Screenshots

Image

Additional context
Add any other context about the problem here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions