#No boot after setting hardened kags
1 messages Β· Page 1 of 1 (latest)
Messed around in BIOS, changed settings one by one, set it to default (it's up to date btw) to no avail π€
Also tried with Kinoite, same problem
That's odd. One of them must be unstable on your hardware for some reason. Probably has to do with the i3-7100U being 9 years old. You may have performance problems on secureblue as a number of our security changes decrease performance to improve security, and a dual core 2.4 GHz processor is fairly anemic by modern standards. Regardless I would go through the kargs that the script sets and manually set them and see which one(s) cause problems.
Ait! Will do, I managed to install Secureblue on a 14 year old Lenovo laptop tho (i7 3rd gen) and with half the RAM of the NUC (got 16gb on the NUC, 8 on the Lenovo) hmm
Thanks!
That's awesome to hear, just wanted to set expectations if the desktop experience isn't smooth. Let us know if you have other problems.
@sour crater in addition to what @hardy pasture said, you can try binary searching
set half of them, then half of half, etc
until you find the problem karg
Alrighty! Now I tried with only denying 32-bit in that part and it does the same! Might be something with that then hmm
Stuck again...
wdym stuck
you can always reboot into the prior deployment
Sorry, I'm doing 10 things simultaneously here, I let it restart to the snapshot it chose itself and it seemed stuck. But if I chose the other snapshot it carried on. Only just now did the audit and all is good except I'm still a wheel user apparently, tho I've tried twice in the admin account to fix that, soooo looking good apart from having to chose another snapshot (1 instead of 0 which it defaults)
wait im confused
so was it the 32 bit karg?
After I did the karg hardening part it would always do something it didn't on the laptop with the snapshots, not sure if it was the 32 bit karg or not, I'm confused myself π΅βπ«
Working fine if I just choose the other snapshot tho
Yea...
π€ do you mind posting rpm-ostree status and rpm-ostree kargs
would give a better idea of what state your system is in
interesting yeah
if that staged boot is broken for some reason
you can remove it
rpm-ostree cleanup --pending
Ah thanks, was gonna look up the possibility, I'll have a go at that!
one of the many benefits of atomic π
you basically never need to reinstall even if you bork your shit
Praise the lord, it worked! Snapped right in there. Thanks! And thanks for what seems an amazing project, if that's the right word even
for sure π
Did you see anything with the status and karg reports that should need any doing?
nope
Sweet
it's very very very weird that you would have boot issues with the 32bit karg applied tho
like
it makes zero sense π
wait...
ia32_emulation=0
it's not that
must have been something else 

Yea, I'm far from good with any of this tho so you need to pop around far fuck off in the forest of Sweden to find out I suppose π
I what?
i think i know what you're saying but you're inadvertently using north american slang i think π
I've no idea what kinda English I'm using either π
i was mostly chuckling because "pop" is slang for "shoot" π
Didn't know, so you're in the USB?
A
idk ive never heard that phrase π
I thought pop was slang for carbonate beverages
as a noun yeah
never heard that
but also pop as a soft drink is a regional thing
at this point im convinced you're making stuff up π
Useful!
but then as a verb, "to pop" means "to shoot" π
nah
No damn clue...
Aha
FΓ€kk
I knew that come to think of it
almost like the cartoon sound for a punch
that too
Alrighty, too late already, half twelve, gotta sleep, thanks!
cya
idk i wouldnt say that
idk what half twelve is π
do you mean maybe "half past twelve"
would mean 12:30
am
uk english and american english are pretty different yeah