[uc20] snapd needs a way to incorporate firmware update with fwupd
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
snapd |
Incomplete
|
Wishlist
|
Unassigned |
Bug Description
For now, the actual EFI vfat partition is covered by ubuntu-seed which is mounted at /run/mnt/
order:
/boot/efi
/boot/EFI
/efi
The initial idea is that snapd can do bind mount for /boot/efi -> /run/mnt/
However, the critical issue after that is that updating firmware also impacts TPM measurement, so that snapd/initramfs may fail to unseal the encryption, unless the system enters recovery mode to reseal the encrypted disk. We need to have more discussions about how snapd deals with the case of PCRs changing.
Changed in snapd: | |
status: | New → Triaged |
A PR for this is proposed in https:/ /github. com/snapcore/ core-initrd/ pull/8