#How can I install a custom kernel module on Secureblue?

1 messages · Page 1 of 1 (latest)

atomic holly
#

Hi there, I'm trying to setup Looking Glass on Secureblue. The docs recommend that you install a kernel module with dkms, which sadly isn't available on Fedora Atomic.

How can I install the module without dkms? Happy for any advice.

jagged cliff
#

ublue already has a kvmfr kmod

#

so you can use theirs via bluebuild using their kmods module

atomic holly
#

Damn!

#

Nice, thank you for the hint. I'll give it a try and report!

jagged cliff
#

you may have secure boot issues given that their kmods are signed with a different key

#

but if you enroll their key which you should already have enrolled, it might just work

#

¯_(ツ)_/¯

jagged cliff
#

because we used to use their nvidia kmod

#

until today

atomic holly
#

Well, I have to admit, I've managed to brick my desktop PC today, so I have to re-install Secureblue. Will that secureboot-key-issue pose a problem then?

jagged cliff
#

easy fix though

#

just enroll it 🙂

atomic holly
#

Sorry I'm not very knowledgeable about this. Before Secureblue I've never used secureboot. I assume enrolling multiple keys is possible then? Doesn't that pose a security risk?

jagged cliff
#

and you're already trusting them to install a module running in ring 0 in the kernel

#

so no it's not really any risk on top of that

#

you're just telling the bios that you trust them

#

which if you're running their module in your kernel

#

you already are

atomic holly
#

... true.

#

Hey, on the topic of bricking my system, is there a way of keeping more ... snapshots? Images? Choices to boot from in GRUP, I mean. In case I do a thing again.

atomic holly
#

That's nice to know as well, but if I'd like to have more choices, e.g. not choosing between the current or the last deployment, but choosing the one before the last. Is it possible to extend the list of deployments to, say, five entries?

jagged cliff
#

not to my knowledge

atomic holly
#

Ahh, what a pity. Then I'll just need to remind myself to pin a deployment before doing something stupid very smart the next time.

lunar rune
jagged cliff
atomic holly
jagged cliff
#

you will need a custom image

lunar rune
#

i'm also trying to install this custom module for my laptop before installing atomic fedora and rebase to secureblue
https://github.com/ferstar/ideapad-laptop-tb

what i tried so far:

  • create my own bluebuild autobuild with github action with help from bluebuild workshop
  • set base to
base-image: ghcr.io/secureblue/silverblue-main-hardened
image-version: latest
  • and uh... my brain got so hot from reading and processing docs around lol

i'm seeking for advice (like am I going right or most effective way), any other help is greatly appreciated

thanks

GitHub

The IdeaPad ACPI Extras kernel modules for ThinkBook 2024 NoteBooks - ferstar/ideapad-laptop-tb

#

going out for dinner, will be back soon

cinder geyser
jagged cliff
#

also this guy is banned now 🙂

cinder geyser
atomic holly
jagged cliff
#

@atomic holly @cinder geyser casual homophobia followed by trying to argue about the ban in another server...

atomic holly
jagged cliff
#

also then he logged in on an alt

#

just kept giving me more reasons to ban him

#

😆

atomic holly
#

Also: why. I mean politics are strictly banned on this server, right? What is there about Secureblue that could spark such comments?