thfedo
(Thomas V)
October 20, 2023, 7:24pm
1
Hi, I have some failed kernel checks in the security section in Fedora 38 Gnome, apparently the most recent check failed, does anyone know what could have caused this, also I would like to know if I don’t have faulty hardware drivers or corrupted files, does anyone know how I can look at that?
finally I wanted to ask why I get the message that the security checks are not available, as you can see on the top left of the image.
attached image:
phatle
(Marko Jokinen)
October 21, 2023, 3:14am
2
does this work click on left side box and copy technical report paste it to text editor to see what is failing etc there might be something on bios or something else on report you can see more details what is failed etc
thfedo
(Thomas V)
October 21, 2023, 4:44am
3
Detalles del informe
Fecha generada: 2023-10-20 17:38:49
Versión de fwupd 1.9.6
System details
Modelo de hardware: ASUSTeK COMPUTER INC. ASUSLaptop X509DA
Procesador AMD Ryzen 7 4500 with Radeon Vega Mobile Gfx
SO: Fedora Linux 38 (Workstation Edition)
Nivel de seguridad: HSI:INVALID:missing-data
HSI-1 Pruebas
Variables del servicio de arranque de UEFI: Correcto (Bloqueada)
Llave de Plataforma UEFI: Correcto (Válido)
TPM v2.0: Correcto (Encontrada)
BIOS Firmware updates: Correcto (Activada)
Arranque Seguro UEFI: Correcto (Activada)
Configuración de Plataforma TPM: Correcto (Válido)
HSI-2 Pruebas
Reconstrucción TPM: Correcto (Válido)
Protección de dispositivo IOMMU: Correcto (Activada)
HSI-3 Pruebas
Protección DMA de pre-arranque: Falló (No activada)
Suspender a RAM: Falló (Activada)
Suspendido a Descanso: Falló (No activada)
HSI-4 Pruebas
RAM cifrada: Falló (No soportada)
Pruebas de tiempo de ejecución
Verificación para Actualizador del Firmware: Correcto (No envenenado)
Intercambio (swap) de Linux: Correcto (Cifrado)
Verificación de Kernel Linux: Falló (Envenenado)
Kernel Linux bloqueado: Correcto (Activada)
Eventos de seguridad del equipo
2023-10-14 23:12:15 Verificación de Kernel LinuFalló (No envenenado → Envenenado)
2023-10-10 15:04:34 Verificación de Kernel Linux Correcto (Envenenado → No envenenado)
2023-10-10 13:31:18 Verificación de Kernel LinuFalló (No envenenado → Envenenado)
2023-10-10 09:41:04 Verificación de Kernel Linux Correcto (Envenenado → No envenenado)
2023-10-09 21:36:40 Intercambio (swap) de Linux Correcto (No cifrado → Cifrado)
2023-10-09 13:30:02 Verificación de Kernel LinuFalló (No envenenado → Envenenado)
phatle
(Marko Jokinen)
October 21, 2023, 4:55am
4
this one caught on my eyes
Nivel de seguridad: HSI:INVALID:missing-data
my output says on that
Security level: HSI:3! (v1.9.6)
thfedo
(Thomas V)
October 21, 2023, 5:10am
5
$ journalctl -k | grep taint
oct 20 07:21:11 hrqm495z kernel: vboxdrv: loading out-of-tree module taints kernel.
$ dmesg | grep -i taint
[ 57.085479] vboxdrv: loading out-of-tree module taints kernel.
[15455.169117] CPU: 6 PID: 110 Comm: scsi_eh_0 Tainted: G O 6.5.7-200.fc38.x86_64 #1
thfedo
(Thomas V)
October 21, 2023, 5:16am
6
$ fwupdmgr security --force
Without sufficient data that was provided by the platform to make an HSI calculation.
$ sudo fwupdmgr refresh --force
Actualizando lvfs
Descargando… [ - ]
failed to download file: Could not resolve host: cdn.fwupd.org
$ sudo fwupdmgr get-updates
Dispositivos sin actualizaciones del firmware disponible:
• ELAN1200:00 04F3:309F
• INTEL SSDPEKNW512G8
• System Firmware
Dispositivos con la última versión disponible del firmware:
• UEFI dbx
────────────────────────────────────────────────
Dispositivos que han sido actualizados correctamente:
• UEFI dbx (371 → 371)
$ fwupdmgr refresh --verbose
(fwupdmgr:50556): GLib-DEBUG: 00:32:30.688: setenv()/putenv() are not thread-safe and should not be used after threads are created
(pkttyagent:50558): GLib-GIO-DEBUG: 00:32:30.699: Using cross-namespace EXTERNAL authentication (this will deadlock if server is GDBus < 2.73.3)
(fwupdmgr:50556): GLib-GIO-DEBUG: 00:32:30.713: _g_io_module_get_default: Found default implementation dconf (DConfSettingsBackend) for ‘gsettings-backend’
(fwupdmgr:50556): dconf-DEBUG: 00:32:30.713: watch_fast: "/system/proxy/" (establishing: 0, active: 0)
(fwupdmgr:50556): dconf-DEBUG: 00:32:30.714: watch_fast: "/system/proxy/http/" (establishing: 0, active: 0)
(fwupdmgr:50556): dconf-DEBUG: 00:32:30.714: watch_fast: "/system/proxy/https/" (establishing: 0, active: 0)
(fwupdmgr:50556): dconf-DEBUG: 00:32:30.714: watch_fast: "/system/proxy/ftp/" (establishing: 0, active: 0)
(fwupdmgr:50556): dconf-DEBUG: 00:32:30.714: watch_fast: "/system/proxy/socks/" (establishing: 0, active: 0)
(fwupdmgr:50556): GLib-GIO-DEBUG: 00:32:30.714: _g_io_module_get_default: Found default implementation gnome (GProxyResolverGnome) for ‘gio-proxy-resolver’
(fwupdmgr:50556): GLib-GIO-DEBUG: 00:32:30.716: Using cross-namespace EXTERNAL authentication (this will deadlock if server is GDBus < 2.73.3)
(fwupdmgr:50556): GLib-GIO-DEBUG: 00:32:30.716: Using cross-namespace EXTERNAL authentication (this will deadlock if server is GDBus < 2.73.3)
(fwupdmgr:50556): dconf-DEBUG: 00:32:30.718: watch_established: "/system/proxy/" (establishing: 1)
(fwupdmgr:50556): dconf-DEBUG: 00:32:30.718: watch_established: "/system/proxy/http/" (establishing: 1)
(fwupdmgr:50556): dconf-DEBUG: 00:32:30.719: watch_established: "/system/proxy/https/" (establishing: 1)
(fwupdmgr:50556): dconf-DEBUG: 00:32:30.719: watch_established: "/system/proxy/ftp/" (establishing: 1)
(fwupdmgr:50556): dconf-DEBUG: 00:32:30.719: watch_established: "/system/proxy/socks/" (establishing: 1)
(fwupdmgr:50556): Fwupd-DEBUG: 00:32:30.720: Emitting ::status-changed() [idle]
Actualizando lvfs
Fwupd-INFO: 00:32:30.737: downloading https://cdn.fwupd.org/downloads/firmware.xml.xz.jcat
(fwupdmgr:50556): Fwupd-DEBUG: 00:32:30.737: Emitting ::status-changed() [downloading]
Descargando… [ | ]Fwupd-INFO: 00:32:31.051: download progress: 100%
(fwupdmgr:50556): Fwupd-DEBUG: 00:32:31.051: Emitting ::status-changed() [idle]
Fwupd-INFO: 00:32:31.051: status-code was 200
Fwupd-INFO: 00:32:31.052: changing metadata URI from https://cdn.fwupd.org/downloads/firmware.xml.xz to https://cdn.fwupd.org/downloads/firmware-06816-stable.xml.xz
Fwupd-INFO: 00:32:31.052: downloading https://localhost:27500/firmware-06816-stable.xml.xz?sha256=2e78bd6baa579cb208bcf95a99b603ab81d5b2a6f3d73c9a3d4dd6c61a073b88
(fwupdmgr:50556): Fwupd-DEBUG: 00:32:31.052: Emitting ::status-changed() [downloading]
(fwupdmgr:50556): Fwupd-DEBUG: 00:32:31.052: Emitting ::status-changed() [idle]
Fwupd-INFO: 00:32:31.052: failed to download https://localhost:27500/firmware-06816-stable.xml.xz?sha256=2e78bd6baa579cb208bcf95a99b603ab81d5b2a6f3d73c9a3d4dd6c61a073b88: failed to download file: Failed to connect to localhost port 27500 after 0 ms: Couldn't connect to server, trying next URI…
Fwupd-INFO: 00:32:31.052: downloading https://cdn.fwupd.org/downloads/firmware-06816-stable.xml.xz
(fwupdmgr:50556): Fwupd-DEBUG: 00:32:31.052: Emitting ::status-changed() [downloading]
Descargando… [ - ]Fwupd-INFO: 00:32:31.125: download progress: 1%
Descargando… [ ]Fwupd-INFO: 00:32:31.131: download progress: 3%
Descargando… [* ]Fwupd-INFO: 00:32:31.135: download progress: 4%
Descargando… [* ]Fwupd-INFO: 00:32:31.138: download progress: 6%
Descargando… [** ]Fwupd-INFO: 00:32:31.147: download progress: 8%
Descargando… [*** ]Fwupd-INFO: 00:32:31.150: download progress: 9%
Descargando… [*** ]Fwupd-INFO: 00:32:31.153: download progress: 11%
Descargando… [**** ]Fwupd-INFO: 00:32:31.157: download progress: 12%
Descargando… [**** ]Fwupd-INFO: 00:32:31.161: download progress: 14%
Descargando… [***** ]Fwupd-INFO: 00:32:31.166: download progress: 16%
Descargando… [****** ]Fwupd-INFO: 00:32:31.169: download progress: 17%
Descargando… [****** ]Fwupd-INFO: 00:32:31.173: download progress: 19%
Descargando… [******* ]Fwupd-INFO: 00:32:31.176: download progress: 20%
Descargando… [******* ]Fwupd-INFO: 00:32:31.179: download progress: 22%
Descargando… [******** ]Fwupd-INFO: 00:32:31.182: download progress: 24%
Descargando… [********* ]Fwupd-INFO: 00:32:31.185: download progress: 25%
Descargando… [********* ]Fwupd-INFO: 00:32:31.188: download progress: 27%
Descargando… [********** ]Fwupd-INFO: 00:32:31.191: download progress: 28%
Descargando… [********** ]Fwupd-INFO: 00:32:31.194: download progress: 30%
Descargando… [*********** ]Fwupd-INFO: 00:32:31.197: download progress: 32%
Descargando… [************ ]Fwupd-INFO: 00:32:31.201: download progress: 33%
Descargando… [************ ]Fwupd-INFO: 00:32:31.203: download progress: 35%
Descargando… [************* ]Fwupd-INFO: 00:32:31.206: download progress: 36%
Descargando… [************** ]Fwupd-INFO: 00:32:31.210: download progress: 38%
Descargando… [************** ]Fwupd-INFO: 00:32:31.211: download progress: 39%
Descargando… [*************** ]Fwupd-INFO: 00:32:31.214: download progress: 41%
Descargando… [*************** ]Fwupd-INFO: 00:32:31.217: download progress: 42%
Descargando… [**************** ]Fwupd-INFO: 00:32:31.220: download progress: 44%
Descargando… [***************** ]Fwupd-INFO: 00:32:31.225: download progress: 45%
Descargando… [***************** ]Fwupd-INFO: 00:32:31.229: download progress: 47%
Descargando… [****************** ]Fwupd-INFO: 00:32:31.232: download progress: 49%
Descargando… [******************* ]Fwupd-INFO: 00:32:31.235: download progress: 50%
Descargando… [******************* ]Fwupd-INFO: 00:32:31.237: download progress: 52%
Descargando… [******************** ]Fwupd-INFO: 00:32:31.243: download progress: 53%
Descargando… [******************** ]Fwupd-INFO: 00:32:31.246: download progress: 55%
Descargando… [********************* ]Fwupd-INFO: 00:32:31.248: download progress: 57%
Descargando… [********************** ]Fwupd-INFO: 00:32:31.252: download progress: 58%
Descargando… [********************** ]Fwupd-INFO: 00:32:31.254: download progress: 60%
Descargando… [*********************** ]Fwupd-INFO: 00:32:31.257: download progress: 61%
Descargando… [*********************** ]Fwupd-INFO: 00:32:31.259: download progress: 63%
Descargando… [************************ ]Fwupd-INFO: 00:32:31.262: download progress: 65%
Descargando… [************************* ]Fwupd-INFO: 00:32:31.268: download progress: 66%
Descargando… [************************* ]Fwupd-INFO: 00:32:31.269: download progress: 68%
Descargando… [************************** ]Fwupd-INFO: 00:32:31.272: download progress: 70%
Descargando… [*************************** ]Fwupd-INFO: 00:32:31.275: download progress: 71%
Descargando… [*************************** ]Fwupd-INFO: 00:32:31.277: download progress: 73%
Descargando… [**************************** ]Fwupd-INFO: 00:32:31.280: download progress: 74%
Descargando… [**************************** ]Fwupd-INFO: 00:32:31.283: download progress: 76%
Descargando… [***************************** ]Fwupd-INFO: 00:32:31.285: download progress: 78%
Descargando… [****************************** ]Fwupd-INFO: 00:32:31.288: download progress: 79%
Descargando… [****************************** ]Fwupd-INFO: 00:32:31.290: download progress: 81%
Descargando… [******************************* ]Fwupd-INFO: 00:32:31.294: download progress: 82%
Descargando… [******************************* ]Fwupd-INFO: 00:32:31.297: download progress: 84%
Descargando… [******************************** ]Fwupd-INFO: 00:32:31.300: download progress: 86%
Descargando… [********************************* ]Fwupd-INFO: 00:32:31.303: download progress: 87%
Descargando… [********************************* ]Fwupd-INFO: 00:32:31.305: download progress: 89%
Descargando… [********************************** ]Fwupd-INFO: 00:32:31.308: download progress: 90%
Descargando… [*********************************** ]Fwupd-INFO: 00:32:31.310: download progress: 92%
Descargando… [*********************************** ]Fwupd-INFO: 00:32:31.314: download progress: 94%
Descargando… [************************************ ]Fwupd-INFO: 00:32:31.316: download progress: 95%
Descargando… [************************************* ]Fwupd-INFO: 00:32:31.318: download progress: 96%
Descargando… [************************************* ]Fwupd-INFO: 00:32:31.323: download progress: 98%
Descargando… [************************************** ]Fwupd-INFO: 00:32:31.325: download progress: 100%
Descargando… [***************************************](fwupdmgr:50556): Fwupd-DEBUG: 00:32:31.325: Emitting ::status-changed() [idle]
Fwupd-INFO: 00:32:31.325: status-code was 200
(fwupdmgr:50556): Fwupd-DEBUG: 00:32:32.146: Emitting ::changed()
(fwupdmgr:50556): Fwupd-DEBUG: 00:32:32.162: Emitting ::changed()
Descarga correctamente metadatos nuevos: 1 dispositivo local mantenido