Bug#990447: fwupdmgr: Unable to install new updates
Hi,
On Tue, Jun 29, 2021 at 02:04:47PM +0200, Salvatore Bonaccorso wrote:
> Package: fwupd
> Version: 1.5.7-4
> Severity: normal
> X-Debbugs-Cc: carnil@debian.org
>
> Hi
>
> I'm not entirely sure how to trackle this problem, since some time I'm
> unable anymore to install updates available trough fwupdmgr. Secure
> boot is enable, and in BIOS the 'boot order lock' *is* disabled.
>
> Though on every update, the firmware get's downloaded, the capsules
> put in /boot/efi/EFI/debian/fw and reboot requested (and even choosing
> the Linux Firmare Update manually) the firmware(s) are nut updated.
>
> The get-history command reflects that:
>
> ----cut---------cut---------cut---------cut---------cut---------cut-----
> 20KGS05200
> │
> ├─LENSE30512GMSP34MEAT3TA:
> │ │ Device ID: 04e17fcf7d3de91da49a163ffe4907855c3648be
> │ │ Previous version: 1.4.0412
> │ │ Update State: Success
> │ │ Last modified: 2020-10-01 23:11
> │ │ GUID: 124c38ac-0100-5a50-aac8-89602d99769f
> │ │ Device Flags: • Internal device
> │ │ • Updatable
> │ │ • System requires external power source
> │ │ • Supported on remote server
> │ │ • Needs a reboot after installation
> │ │ • Reported to remote server
> │ │ • Device is usable for the duration of the update
> │ │
> │ └─LENSE30512GMSP34MEAT3TA Device Update:
> │ New version: 2.5.0412
> │ Remote ID: lvfs
> │ Summary: Unionmemory LENSE30512GMSP34MEAT3TA NVMe SSD Firmware for Lenovo PC
> │ License: Proprietary
> │ Size: 588.8 kB
> │ Created: 2016-07-08
> │ Urgency: High
> │ Vendor: Unionmemory
> │ Description:
> │ Do NOT turn off your computer or remove the AC adapter while update is in progress.
> │
> │ The computer shall be restarted after updating firmware completely. The device may not properly function until you shut down or reboot PC
> │
> │ Supported devices and firmware version : Unionmemory LENSE30512GMSP34MEAT3TA-512G-2.5.0412
> │
> │ Supported Product Scope : Lenovo ThinkPad, ThinkCentre, ThinkStation, IdeaCentre
> │
> ├─Embedded Controller:
> │ │ Device ID: 9698faabddf0d7b18925cfbbda95f8b0d0dacc53
> │ │ Previous version: 0.1.8
> │ │ Update State: Success
> │ │ Last modified: 2020-11-17 16:05
> │ │ GUID: 3babca5f-b2bf-4f4b-a72e-2bdc84eb4019
> │ │ Device Flags: • Internal device
> │ │ • Updatable
> │ │ • System requires external power source
> │ │ • Supported on remote server
> │ │ • Needs a reboot after installation
> │ │ • Reported to remote server
> │ │ • Device is usable for the duration of the update
> │ │
> │ └─ThinkPad X1 Carbon 6th Embedded Controller Update:
> │ New version: 0.1.22
> │ Remote ID: lvfs
> │ Summary: Lenovo ThinkPad X1 Carbon 6th Embedded Controller Firmware
> │ License: Proprietary
> │ Size: 767.1 kB
> │ Created: 2016-07-08
> │ Urgency: High
> │ Vendor: Lenovo Ltd.
> │ Description:
> │ Lenovo ThinkPad X1 Carbon 6th Embedded Controller Firmware
> │
> │ Fixed an issue where ThinkVision T24m-10 monitor might not connected properly.
> │
> ├─UEFI Device Firmware:
> │ │ Device ID: 9e329270a7a68d289c82fe77d32d02208ddf0890
> │ │ Previous version: 0.73.4
> │ │ Update State: Success
> │ │ Last modified: 2021-04-27 20:27
> │ │ GUID: cea87551-1701-43fb-afbc-6e8ce9728345
> │ │ Device Flags: • Internal device
> │ │ • Updatable
> │ │ • System requires external power source
> │ │ • Supported on remote server
> │ │ • Needs a reboot after installation
> │ │ • Reported to remote server
> │ │ • Device is usable for the duration of the update
> │ │
> │ └─ThinkPad X1 Carbon 6th System Update:
> │ New version: 0.73.20
> │ Remote ID: lvfs
> │ Summary: Lenovo ThinkPad X1 Carbon 6th STM TPM Firmware
> │ License: Proprietary
> │ Size: 439.6 kB
> │ Created: 2020-03-03
> │ Urgency: High
> │ Vendor: Lenovo Ltd.
> │ Description:
> │ Lenovo ThinkPad X1 Carbon 6th STM TPM Firmware Version 73.20
> │
> │ • Do NOT turn off your computer or remove the AC adaptor while update is in progress
> │
> ├─Intel Management Engine:
> │ │ Device ID: e563ad307df81c99f0de8c26292afd71cf409673
> │ │ Previous version: 184.83.3874
> │ │ Update State: Failed
> │ │ Update Error: failed to run update on reboot
> │ │ Last modified: 2021-06-29 11:45
> │ │ GUID: 42a0a96e-c9f3-438f-9687-7826be33e4ce
> │ │ Device Flags: • Internal device
> │ │ • Updatable
> │ │ • System requires external power source
> │ │ • Supported on remote server
> │ │ • Needs a reboot after installation
> │ │ • Device is usable for the duration of the update
> │ │
> │ └─ThinkPad X1 Carbon 6th Corporate ME Update:
> │ New version: 184.86.3909
> │ Remote ID: lvfs
> │ Summary: Lenovo ThinkPad X1 Carbon 6th Corporate ME Firmware
> │ License: Proprietary
> │ Size: 7.5 MB
> │ Created: 2016-07-08
> │ Urgency: High
> │ Details: https://pcsupport.lenovo.com/de/en/search?query=N23RM17W
> │ Vendor: Lenovo Ltd.
> │ Flags: is-upgrade
> │ Description:
> │ Lenovo ThinkPad X1 Carbon 6th ME Firmware Version 11.8.86.3909(LVFS: 184.86.3909)
> │
> │ The computer will be restarted automatically after updating completely. Do NOT turn off your computer or remove the AC adaptor while update is in progress.
> │
> │ This stable release fixes the following issues:
> │
> │ • Intel CSME IPU 2021.1:
> │
> │ Addressed several critical security vulnerabilities.
> │
> └─System Firmware:
> │ Device ID: 1c53551e7da69d896138fac1ae131c83ad46d923
> │ Previous version: 0.1.50
> │ Update State: Failed
> │ Update Error: failed to run update on reboot
> │ Last modified: 2021-06-29 11:47
> │ GUID: a4b51dca-8f97-4310-8821-3330f83c9135
> │ Device Flags: • Internal device
> │ • Updatable
> │ • System requires external power source
> │ • Supported on remote server
> │ • Needs a reboot after installation
> │ • Cryptographic hash verification is available
> │ • Device is usable for the duration of the update
> │
> └─ThinkPad X1 Carbon 6th System Update:
> New version: 0.1.51
> Remote ID: lvfs
> Summary: Lenovo ThinkPad X1 Carbon 6th System Firmware
> License: Proprietary
> Size: 9.5 MB
> Created: 2016-07-08
> Urgency: High
> Vendor: Lenovo Ltd.
> Flags: is-upgrade
> Description:
> Lenovo ThinkPad X1 Carbon 6th System Firmware
>
> • Fixed an security issue.
> • Update Version 04.17.000 code of FIT's InROM diagnostics.
> ----cut---------cut---------cut---------cut---------cut---------cut-----
>
> Any idea how to untagle this? Which information would be helpfull if
> you direct me directly to fwupd upstream (happy to put it there but
> I'm currently a bit lost on how to tackle this update loops, as the
> most common suggestion is the disable boot order lock, which *is*
> disabled).
Interesting datapoint: I experimented further, and disabled secure
boot. After that I was able to install those updates.
Does that possibly ring some bell?
Regards,
Salvatore
Reply to: