Bug 1842980 - RHCOS not starting with TPM encryption enabled on OCP 4.4
Summary: RHCOS not starting with TPM encryption enabled on OCP 4.4
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: RHCOS
Version: 4.4
Hardware: Unspecified
OS: Unspecified
low
high
Target Milestone: ---
: 4.4.z
Assignee: Jonathan Lebon
QA Contact: Michael Nguyen
URL:
Whiteboard:
Depends On: 1833335
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-06-02 13:50 UTC by David Sanz
Modified: 2020-08-06 19:08 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: No Doc Update
Doc Text:
Clone Of: 1833335
Environment:
Last Closed: 2020-08-06 19:07:59 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2020:3237 0 None None None 2020-08-06 19:08:27 UTC

Comment 2 Jonathan Lebon 2020-06-02 14:21:07 UTC
Chatted with David about this. CI on Packet for 4.4+TPM is red due to this. That said, no customer is currently hitting it (that we know of), and it would require a bootimage bump.

Comment 3 Jonathan Lebon 2020-06-02 20:34:59 UTC
One concern is that although no customer may be hitting it, the fact that CI is failing on this means that we're potentially blind to any other regressions that may show up in 4.4 on TPM which customers *could* hit.

Comment 7 Jonathan Lebon 2020-07-08 19:57:35 UTC
Reducing priority to low for this based on conversations.

Comment 8 David Sanz 2020-07-27 09:52:42 UTC
Verified it is working on 4.4.0-0.nightly-2020-07-25-091418 with 44.81.202004250133-0 as boot image and 44.82.202007211530-0 as working image

[root@master-00 ~]# lsblk
NAME                                          MAJ:MIN RM   SIZE RO TYPE  MOUNTPOINT
sda                                             8:0    0 447.1G  0 disk  
|-sda1                                          8:1    0   384M  0 part  /boot
|-sda2                                          8:2    0   127M  0 part  /boot/efi
|-sda3                                          8:3    0     1M  0 part  
`-sda4                                          8:4    0 446.6G  0 part  
  `-luks-00000000-0000-4000-a000-000000000002 253:0    0 446.6G  0 crypt /sysroot
sdb                                             8:16   0 447.1G  0 disk  
sdc                                             8:32   0 223.6G  0 disk  
sdd                                             8:48   0 223.6G  0 disk  


Michael Nguyen, you can mark this bug as verified

Comment 9 Micah Abbott 2020-07-31 13:08:59 UTC
Moving to MODIFIED, so the errata bot can pick this up.

Comment 12 Timothée Ravier 2020-08-03 14:12:19 UTC
Verified via comment #8.

Comment 13 Jonathan Lebon 2020-08-04 14:26:37 UTC
I'm actually not sure why this now works. We haven't backported `random.trust_cpu=on` to 4.4. I suspect there's something in 8.2 which made this better (but not `CONFIG_RANDOM_TRUST_CPU` since that's still unset there). Anyway, if this works, then great!

Comment 15 errata-xmlrpc 2020-08-06 19:07:59 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (OpenShift Container Platform 4.4.16 bug fix update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2020:3237


Note You need to log in before you can comment on or make changes to this bug.