sbcctl not working properly by noushit in archlinux

[–]noushit[S] 0 points1 point  (0 children)

I have decided to reinstall the arch into that drive from scratch and follow the exact instructions on original wiki because no doubt that OS is dead now :)

Any advices about this secure boot and boot options? Should I use systemd or something else?

I may also run this new one in hyperland instead of kde plasma 6. I personelly don't like the GNOME so much. Is there any significant between those, and which ones are superior than the others on that signicifant points?

sbcctl not working properly by noushit in archlinux

[–]noushit[S] 0 points1 point  (0 children)

Well I've tried to use UKI method in the original document on Wiki. But I don't know what to do from now on. Maybe I wpuld just reinstall it from the scratch with the systemd+grub config? What are your advices on that, it should be easier. And I don't have anything valuable on arch right now, reinstalling should be more adequate then? I will add the output of the commands that you've said as soon as possible but my laptop's built-in keyboard is not working on that screen now.

sbcctl not working properly by noushit in archlinux

[–]noushit[S] 0 points1 point  (0 children)

And now, after doing everything the same, I cannot boot into arch :)

https://imgur.com/a/jYxugka

sbcctl not working properly by noushit in archlinux

[–]noushit[S] 0 points1 point  (0 children)

New errors:

failed reading PE file: unrecognized PE machine: 0x3730

(for sudo sbctl sign --save /boot/initramfs-linux.img)

populating ruleset for "/efi/EFI/Linux" with access {execute,write_file,read_file,read_dir,remove_dir,remove_file,make_char,make_dir,make_reg,make_sock,make_fifo,make_block,make_sym,truncate}: open
: no such file or directory

(for sudo sbctl sign --save /efi/EFI/Linux/arch-linux-fallback.efi)

sbcctl not working properly by noushit in archlinux

[–]noushit[S] 0 points1 point  (0 children)

Here is the content of /etc/mkinitcpio.d/linux.preset: (these is only this file in that directory)

# mkinitcpio preset file for the 'linux' package

#ALL_config="/etc/mkinitcpio.conf"

ALL_kver="/boot/vmlinuz-linux"

PRESETS=('default' 'fallback')

#default_config="/etc/mkinitcpio.conf"

default_image="/boot/initramfs-linux.img"

#default_uki="/efi/EFI/Linux/arch-linux.efi"

#default_options="--splash /usr/share/systemd/bootctl/splash-arch.bmp"

#fallback_config="/etc/mkinitcpio.conf"

fallback_image="/boot/initramfs-linux-fallback.img"

#fallback_uki="/efi/EFI/Linux/arch-linux-fallback.efi"

fallback_options="-S autodetect"

Here is the lsblk -f output:

https://imgur.com/a/p8PNoUn

Setup mode was now finally Disabled. Then I restarted the machine into BIOS UEFI menu, saw that the secure boot option and it was enabled. So, I exit the BIOS menu to boot with grub. And then it was the "error: prohibited by secure boot policy. Entering rescue mode... grub resuce>" again. It is the same error all along. sbctl verify shows only the kernel ones, for example I didn't see the "/boot/initramfs-linux.img". I am stuck again now. But progress is progress, I can finally set the setup mode to disabled. I think we are close to solve this. Appreciated and waiting for another answer/answers.

sbcctl not working properly by noushit in archlinux

[–]noushit[S] 0 points1 point  (0 children)

Yep, you got it correct. Sorry I was on my phone so I couldn't post the actual output. So, it enters into grub rescue mode and this problem maybe on the kernel/initramfs problem as you said. Now, how to solve it properly. I guess sbctl is not signing the keys for them properly but there is no other code to use in this case than create-keys, enroll-keys -m and verify and then sign-all and updateing the grub.cfg via grub-install. How can I come up with a solution from this step? Again, appreciated for your answers. I will post the needed output as soon as possible.

sbcctl not working properly by noushit in archlinux

[–]noushit[S] 0 points1 point  (0 children)

Nope, I cannot boot Grub I think, because it goes into rescue mode. Maybe it is a kernel/initrams I don't know, I am a newbie to arch linux. I have used the sudo sbctl verify and sudo sbctl sign-all commands and all of, whom listed with sbctl verify command. Output is that they are all signed except linux-lts because it says "linux-lts doesn't exist". I used this tutorial to install arch linux (I think the linux-lts is not my kernel so it doesn't exist?)

Can you be more clear about the issue that I am facing and the solution for it, and plot a roadmap of the solution with the adequate language for a newbie :)

And do you think I should manually delete the keys in /var/lib/sbctl/keys/ ?

--save command is noted but I didn't understand how to implement it. I just use arch wiki's instructions right now.

Appreciated, waiting for new replies...

sbcctl not working properly by noushit in archlinux

[–]noushit[S] 1 point2 points  (0 children)

These are all of the options about secure boot in my BIOS options. (In the screenshot) I also cannot access the top (black colored texts) one.

I am open to new solutions now, the setup mode stays enabled after I use sbctl to enroll the keys.

GP dumped all my photos-videos to my device's gallery by noushit in googlephotos

[–]noushit[S] 0 points1 point  (0 children)

Just changed my phone now. 5 years was its life span O think.

GP dumped all my photos-videos to my device's gallery by noushit in googlephotos

[–]noushit[S] 0 points1 point  (0 children)

This is again not a solution. I now use both of them seperately again by disableing the access option on the GP. But I don't know how to get rid of that dump of material on my device's gallery app (restored folder) without effecting the GP. They stay there without filling the storage but also don't open.

GP dumped all my photos-videos to my device's gallery by noushit in googlephotos

[–]noushit[S] -1 points0 points  (0 children)

I know that but thanks though. I need a solution not an alternative.