failed to run fde-reveal-key if prefer-unencrypted defined in model assertion

Bug #2043557 reported by Aristo Chen
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
OEM Priority Project
New
Undecided
Unassigned
snapd
New
Undecided
Unassigned

Bug Description

Hi,

I have definied `storage-safety: prefer-unencrypted` in the model assertion, and tested with the following different scenario

1. fde-reveal-key and optee-os are removed, and device boots fine
2. fde-reveal-key and optee-os are not removed, and device boots fine
3. fde-reveal-key not removed and optee-os removed, the device does not boot

and here is the log(https://pastebin.ubuntu.com/p/8zx4Hb7Z6Z/) for the error in install mode

Does it make sense for snapd to check the model assertion before running reveal-key?

Tags: oem-priority
Aristo Chen (aristochen)
tags: added: oem-priority
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.