-
Notifications
You must be signed in to change notification settings - Fork 24
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bug 2181920: Disable Secure Boot for UEFI Boot mode #1236
Bug 2181920: Disable Secure Boot for UEFI Boot mode #1236
Conversation
Disable secure boot when choosing "UEFI" option in the VM Details page for "Boot mode" field. Fix the yaml when choosing this option. Fixes https://bugzilla.redhat.com/show_bug.cgi?id=2181920
@hstastna: This pull request references Bugzilla bug 2181920, which is valid. The bug has been moved to the POST state. The bug has been updated to refer to the pull request using the external bug tracker. 3 validation(s) were run on this bug
Requesting review from QA contact: In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
@avivtur @metalice @pcbailey @upalatucci @vojtechszocs please review |
@hstastna: This pull request references Bugzilla bug 2181920, which is valid. 3 validation(s) were run on this bug
Requesting review from QA contact: In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
/lgtm |
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: hstastna, pcbailey The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
@hstastna: All pull requests linked via external trackers have merged: Bugzilla bug 2181920 has been moved to the MODIFIED state. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
This is a followup of kubevirt-ui#1236 introducing the change that "efi: { secureBoot: false }" was written to VM's yaml when changing Boot mode field value to "UEFI", because that was correct representation of "UEFI" boot mode (secure boot disabled). In this commit, the following remaining issues are fixed: - for existing VM: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section - in Create VM wizard: -- it shows "UEFI" for Boot mode field in Review and create VirtualMachine screen for "efi: {}" in the yaml's bootloader section - for existing template: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section -- after changing Boot mode field to "UEFI", "efi: {}" occurs in the yaml (this doesn't happen for existing VMs or when creating a VM) Fixes https://bugzilla.redhat.com/show_bug.cgi?id=2181920
This is a followup of kubevirt-ui#1236 introducing the change that "efi: { secureBoot: false }" was written to VM's yaml when changing Boot mode field value to "UEFI", because that was correct representation of "UEFI" boot mode (secure boot disabled). In this commit, the following remaining issues are fixed: - for existing VM: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section - in Create VM wizard: -- it shows "UEFI" for Boot mode field in Review and create VirtualMachine screen for "efi: {}" in the yaml's bootloader section - for existing template: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section -- after changing Boot mode field to "UEFI", "efi: {}" occurs in the yaml (this doesn't happen for existing VMs or when creating a VM) Fixes https://bugzilla.redhat.com/show_bug.cgi?id=2181920
This is a followup of kubevirt-ui#1236 introducing the change that "efi: { secureBoot: false }" was written to VM's yaml when changing Boot mode field value to "UEFI", because that was correct representation of "UEFI" boot mode (secure boot disabled). In this commit, the following remaining issues are fixed: - for existing VM: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section - in Create VM wizard: -- it shows "UEFI" for Boot mode field in Review and create VirtualMachine screen for "efi: {}" in the yaml's bootloader section - for existing template: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section -- after changing Boot mode field to "UEFI", "efi: {}" occurs in the yaml (this doesn't happen for existing VMs or when creating a VM) Fixes https://bugzilla.redhat.com/show_bug.cgi?id=2181920
This is a followup of kubevirt-ui#1236 introducing the change that "efi: { secureBoot: false }" was written to VM's yaml when changing Boot mode field value to "UEFI", because that was correct representation of "UEFI" boot mode (secure boot disabled). In this commit, the following remaining issues are fixed: - for existing VM: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section - in Create VM wizard: -- it shows "UEFI" for Boot mode field in Review and create VirtualMachine screen for "efi: {}" in the yaml's bootloader section - for existing template: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section -- after changing Boot mode field to "UEFI", "efi: {}" occurs in the yaml (this doesn't happen for existing VMs or when creating a VM) Fixes https://bugzilla.redhat.com/show_bug.cgi?id=2181920
This is a followup of kubevirt-ui#1236 introducing the change that "efi: { secureBoot: false }" was written to VM's yaml when changing Boot mode field value to "UEFI", because that was correct representation of "UEFI" boot mode (secure boot disabled). In this commit, the following remaining issues are fixed: - for existing VM: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section - in Create VM wizard: -- it shows "UEFI" for Boot mode field in Review and create VirtualMachine screen for "efi: {}" in the yaml's bootloader section - for existing template: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section -- after changing Boot mode field to "UEFI", "efi: {}" occurs in the yaml (this doesn't happen for existing VMs or when creating a VM) Fixes https://bugzilla.redhat.com/show_bug.cgi?id=2181920
This is a followup of kubevirt-ui#1236 introducing the change that "efi: { secureBoot: false }" was written to VM's yaml when changing Boot mode field value to "UEFI", because that was correct representation of "UEFI" boot mode (secure boot disabled). In this commit, the following remaining issues are fixed: - for existing VM: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section - in Create VM wizard: -- it shows "UEFI" for Boot mode field in Review and create VirtualMachine screen for "efi: {}" in the yaml's bootloader section - for existing template: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section -- after changing Boot mode field to "UEFI", "efi: {}" occurs in the yaml (this doesn't happen for existing VMs or when creating a VM) Fixes https://bugzilla.redhat.com/show_bug.cgi?id=2181920
This is a followup of kubevirt-ui#1236 introducing the change that "efi: { secureBoot: false }" was written to VM's yaml when changing Boot mode field value to "UEFI", because that was correct representation of "UEFI" boot mode (secure boot disabled). In this commit, the following remaining issues are fixed: - for existing VM: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section - in Create VM wizard: -- it shows "UEFI" for Boot mode field in Review and create VirtualMachine screen for "efi: {}" in the yaml's bootloader section - for existing template: -- it shows "UEFI" for Boot mode field in Details for "efi: {}" in the yaml's bootloader section -- after changing Boot mode field to "UEFI", "efi: {}" occurs in the yaml (this doesn't happen for existing VMs or when creating a VM) Fixes https://bugzilla.redhat.com/show_bug.cgi?id=2181920
📝 Description
Fixes:
https://bugzilla.redhat.com/show_bug.cgi?id=2181920
Disable secure boot when choosing "UEFI" option in the VM Details page for "Boot mode" field. Fix the yaml when choosing this option in the UI.
How to reproduce the bug:
click on Open web console in VM Overview tab or also you can go to VM Console tab
(or you also can look to the VM's Scripts tab - Cloud-init section, where you also can change the password if you are allowed to do so)
sudo bootctl status | grep "Secure Boot"
=> it was enabled even if it shouldn't be!
🎥 Screenshots
Choosing "UEFI" option in the VM Details page for "Boot mode" field:
Before:
Secure boot enabled, when checking the status after logging to the VM:
VM's yaml:
After:
Secure boot disabled as expected, when checking the status after logging to the VM:
VM's yaml: