GNU bug report logs - #74711
GRUB error when booting: symbol `grub_is_shim_lock_enabled` not found

Please note: This is a static page, with minimal formatting, updated once a day.
Click here to see this page with the latest information and nicer formatting.

Package: guix; Reported by: ngraves@HIDDEN; Done: Nicolas Graves <ngraves@HIDDEN>; Maintainer for guix is bug-guix@HIDDEN.
bug closed, send any further explanations to 74711 <at> debbugs.gnu.org and ngraves@HIDDEN Request was from Nicolas Graves <ngraves@HIDDEN> to control <at> debbugs.gnu.org. Full text available.

Message received at 74711 <at> debbugs.gnu.org:


Received: (at 74711) by debbugs.gnu.org; 10 Dec 2024 23:38:50 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Tue Dec 10 18:38:50 2024
Received: from localhost ([127.0.0.1]:60115 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1tL9oX-0005rj-P7
	for submit <at> debbugs.gnu.org; Tue, 10 Dec 2024 18:38:50 -0500
Received: from eggs.gnu.org ([209.51.188.92]:59670)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <ludo@HIDDEN>) id 1tL9oW-0005r0-F0
 for 74711 <at> debbugs.gnu.org; Tue, 10 Dec 2024 18:38:48 -0500
Received: from fencepost.gnu.org ([2001:470:142:3::e])
 by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <ludo@HIDDEN>)
 id 1tL9oQ-0002n1-2W; Tue, 10 Dec 2024 18:38:42 -0500
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org;
 s=fencepost-gnu-org; h=MIME-Version:Date:References:In-Reply-To:Subject:To:
 From; bh=suX6zruhvL9yEakLnJL7sMnxlm4J6XHBtY1gfYQBeOA=; b=W5oxjgS81wlTBKo0PsND
 AIQ7mndztOgvG6LKPopHV2D8SdNhkY9WOAI82eUXSVruL30YMFNppRC5WCbmiDzIGSsX/g/JI/kvu
 RbV+UWYQrDO2uAW9MPjcIOTkyvjmMOHfaJRO802iO/6J29Adv+YCTLvQiCUPmNDfhuaKiRpGLNOj5
 OxAgqGhW6OcEMmNN35JjQRaOneE0kmY+wnlrpCk9ad8e60+FL9P/LnyNmBaDI/AewU6Ug+Do43Nuy
 jEpLXRIXdBAbff/c9LVZNmbjY39XAB9FB6leuGg7hhC89U8DCTfziktm3LaGcFuiWYABD77i4DcpR
 nnLLNAkn4J4NuA==;
From: =?utf-8?Q?Ludovic_Court=C3=A8s?= <ludo@HIDDEN>
To: ngraves@HIDDEN
Subject: Re: bug#74711: Is grub broken and breaking Guix ?
In-Reply-To: <877c87i3ds.fsf_-_@HIDDEN> ("Ludovic =?utf-8?Q?Court=C3=A8s?=
 =?utf-8?Q?=22's?= message of "Tue, 10 Dec 2024 23:23:27 +0100")
References: <a34560f8716ffb8ffd6522c3f8af07c8@HIDDEN>
 <4fe84e12db12aa32d75a427d3000db02@HIDDEN>
 <877c87i3ds.fsf_-_@HIDDEN>
Date: Wed, 11 Dec 2024 00:38:40 +0100
Message-ID: <87ldwnglbz.fsf_-_@HIDDEN>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
X-Spam-Score: -2.3 (--)
X-Debbugs-Envelope-To: 74711
Cc: 74711 <at> debbugs.gnu.org
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -3.3 (---)

Ludovic Court=C3=A8s <ludo@HIDDEN> skribis:

> That said, what we could/should do is add a =E2=80=98--no-check-certifica=
te=E2=80=99
> option to =E2=80=98pull=E2=80=99 and =E2=80=98time-machine=E2=80=99; it w=
ould be handy in emergency
> situations like you described.

See <https://issues.guix.gnu.org/74776>.




Information forwarded to bug-guix@HIDDEN:
bug#74711; Package guix. Full text available.

Message received at 74711 <at> debbugs.gnu.org:


Received: (at 74711) by debbugs.gnu.org; 10 Dec 2024 23:17:50 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Tue Dec 10 18:17:50 2024
Received: from localhost ([127.0.0.1]:60000 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1tL9UE-00043A-5K
	for submit <at> debbugs.gnu.org; Tue, 10 Dec 2024 18:17:50 -0500
Received: from eggs.gnu.org ([209.51.188.92]:43366)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <ludo@HIDDEN>) id 1tL9UB-00042P-Ff
 for 74711 <at> debbugs.gnu.org; Tue, 10 Dec 2024 18:17:48 -0500
Received: from fencepost.gnu.org ([2001:470:142:3::e])
 by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <ludo@HIDDEN>)
 id 1tL9U4-0000sg-CU; Tue, 10 Dec 2024 18:17:40 -0500
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org;
 s=fencepost-gnu-org; h=MIME-Version:Date:References:In-Reply-To:Subject:To:
 From; bh=gFpNw1jfoDSYL0vFtxdYlL+X40gbO9Smb3hpuxja8Ng=; b=cdZiOchxb8/spiVciQkG
 ZYWZKxS7fkm80gr2YSTlTPqG6kg5V5CMCyjQg0pZWJ7R4VZ5ExZxHjthw07SkkmA1ZQuk9K8J9tmx
 dd6MFxAhrSWemI8wEifyrG1UDrWdxyTI+NtWnl3BIqefkZHgzkByvWoZ5oLy+Y41tCVEwpf5f6rF4
 PZIj6pJLkydrKjD2RHS3jC48hC5gWHjiKEp6tKNn6OIcLPx9w9ubpCGkJMYIHu6etTtmqBI9gurAQ
 pL6yGE3p5fFgSOZVjLMR7VeDXlz9Nh9sXHay2MIoJ+hHAKle/cIYYYmtNAcqkH8+1OhNq6YtKUS0/
 LAZc5+6/fVNY3Q==;
From: =?utf-8?Q?Ludovic_Court=C3=A8s?= <ludo@HIDDEN>
To: ngraves@HIDDEN
Subject: Re: bug#74711: Is grub broken and breaking Guix ?
In-Reply-To: <a34560f8716ffb8ffd6522c3f8af07c8@HIDDEN>
 (ngraves@HIDDEN's message of "Fri, 06 Dec 2024 14:47:57 +0100")
References: <a34560f8716ffb8ffd6522c3f8af07c8@HIDDEN>
Date: Wed, 11 Dec 2024 00:17:31 +0100
Message-ID: <87ttbbgmb8.fsf@HIDDEN>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
X-Spam-Score: -2.3 (--)
X-Debbugs-Envelope-To: 74711
Cc: 74711 <at> debbugs.gnu.org
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -3.3 (---)

Hi,

ngraves@HIDDEN skribis:

> On my backup computer, I tried updating Guix before generating an
> installable image, and that broke my backup computer. I'm unable to
> install Guix that I broke due to the following error :
> https://savannah.gnu.org/bugs/?64406

The error at boot time is:

  error: symbol `grub_is_shim_lock_enabled` not found when trying to boot i=
mage

Is that right?

I don=E2=80=99t think this has been reported before.  Is there a chance it =
has
to do specifically with the Btrfs/LUKS setup you describe?

Had this machine been upgraded and reconfigured recently?

Ludo=E2=80=99.




Information forwarded to bug-guix@HIDDEN:
bug#74711; Package guix. Full text available.
Changed bug title to 'GRUB error when booting: symbol `grub_is_shim_lock_enabled` not found' from 'Is grub broken and breaking Guix ?' Request was from Ludovic Courtès <ludo@HIDDEN> to control <at> debbugs.gnu.org. Full text available.

Message received at 74711 <at> debbugs.gnu.org:


Received: (at 74711) by debbugs.gnu.org; 10 Dec 2024 22:27:35 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Tue Dec 10 17:27:35 2024
Received: from localhost ([127.0.0.1]:59928 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1tL8hb-0008MX-EJ
	for submit <at> debbugs.gnu.org; Tue, 10 Dec 2024 17:27:35 -0500
Received: from eggs.gnu.org ([209.51.188.92]:47038)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <ludo@HIDDEN>) id 1tL8hZ-0008M4-Cv
 for 74711 <at> debbugs.gnu.org; Tue, 10 Dec 2024 17:27:33 -0500
Received: from fencepost.gnu.org ([2001:470:142:3::e])
 by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <ludo@HIDDEN>)
 id 1tL8hT-00046E-30; Tue, 10 Dec 2024 17:27:27 -0500
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org;
 s=fencepost-gnu-org; h=MIME-Version:Date:References:In-Reply-To:Subject:To:
 From; bh=cDjciwzSwiZe96cUmz7Sw9qWrvufcxMFzMVWPx907y0=; b=dlgg7MNlYBDkmBdh8OoB
 coNB82qxFJbG+/D9chPD367xTC4tad5c4Yja4b4fZSbMnjRK9bidgdtHfU38GerkMebkQt075oyOv
 2EcGQSI2DDPbg7sUIVQSaa3ubEkDqLJ5tQp8spDfuLgnZMFc5hDYr4/XX9390XRQ3V5WYcL4orPNi
 fVcIm085CAwbnuPmL8uURvGLeV5emRzf/0NOgI93JJNU3jW/Tavs9wTzQTXw5ZdJ0GEfDu4o5Zkfr
 +5wPutFr8ytrlQltFaKcYbnrnJjW+xdnNmYtvF73uReo+2BmtH/wcGVODA2hAF3O6aOQpe6t1T81J
 rGeFDqgRAbYGqA==;
From: =?utf-8?Q?Ludovic_Court=C3=A8s?= <ludo@HIDDEN>
To: ngraves@HIDDEN
Subject: Re: bug#74711: Is grub broken and breaking Guix ?
In-Reply-To: <305651c5d363f13f253b8290e09ba497@HIDDEN>
 (ngraves@HIDDEN's message of "Sat, 07 Dec 2024 10:53:40 +0100")
References: <4fe84e12db12aa32d75a427d3000db02@HIDDEN>
 <305651c5d363f13f253b8290e09ba497@HIDDEN>
Date: Tue, 10 Dec 2024 23:27:24 +0100
Message-ID: <871pyfi377.fsf_-_@HIDDEN>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
X-Spam-Score: -2.3 (--)
X-Debbugs-Envelope-To: 74711
Cc: 74711 <at> debbugs.gnu.org
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -3.3 (---)

ngraves@HIDDEN skribis:

> By the way, guix install did work perfectly fine despite SSL
> certificates failing, does that mean that it doesn't do any SSL
> certificate verification ? Is that considered safe? How about
> man-in-the-middle and data-tampering attacks? Are they impossible due
> to sha checksums in Guix, or is that a vulnerability ?

The error with =E2=80=98guix pull=E2=80=99 comes from libgit2 when talking =
to
https://git.sv.gnu.org.

=E2=80=98guix install=E2=80=99 does not do that.  When it downloads substit=
utes, it
authenticates them (narinfos are signed) and checks their integrity once
the download is complete.

X.509 certificates do not matter at all here and are explicitly ignored;
see #:verify-certificate? in (guix scripts substitutes).

Ludo=E2=80=99.




Information forwarded to bug-guix@HIDDEN:
bug#74711; Package guix. Full text available.

Message received at 74711 <at> debbugs.gnu.org:


Received: (at 74711) by debbugs.gnu.org; 10 Dec 2024 22:23:43 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Tue Dec 10 17:23:43 2024
Received: from localhost ([127.0.0.1]:59919 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1tL8do-00081W-Qs
	for submit <at> debbugs.gnu.org; Tue, 10 Dec 2024 17:23:43 -0500
Received: from eggs.gnu.org ([209.51.188.92]:60240)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <ludo@HIDDEN>) id 1tL8dl-0007zo-B2
 for 74711 <at> debbugs.gnu.org; Tue, 10 Dec 2024 17:23:38 -0500
Received: from fencepost.gnu.org ([2001:470:142:3::e])
 by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <ludo@HIDDEN>)
 id 1tL8de-0003lV-CM; Tue, 10 Dec 2024 17:23:30 -0500
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnu.org;
 s=fencepost-gnu-org; h=MIME-Version:Date:References:In-Reply-To:Subject:To:
 From; bh=DGTh71KfVcl5RnP3mCdXKRNYb1YBGfmOsVtPv8P54sE=; b=CIZNI7lolS9IqEDQI9TD
 I1VEWbX8/Etuqx+y/XTHzjLiAsrUhewPSIXTGGjbyKxgmuaJQD2chvyrwM218mdRadYA4QO6hrD2a
 76/iG0uHXllqwAeD9+xWQEcrrz7gBRPQIKmU/RI0H1YGsMpdMZhmAuHy+1FL6WbnB5oC4/th3rcsd
 i6AZWO7bmCis2Z1T6brzX+GIylXgEpzo8FwHAiKdE9iZ3+KwgBBEz6ctRdgIn+DdeMcph4//t1Elo
 l8Qknbd2KXmVexrAf5/EtFSDPBHDqufy9qmJVutGIXs3yB/PsLRttP35SCQ/nTAmyX17NLEbeysA3
 eUP9TR97Ieuptw==;
From: =?utf-8?Q?Ludovic_Court=C3=A8s?= <ludo@HIDDEN>
To: ngraves@HIDDEN
Subject: Certificate issues with =?utf-8?B?4oCYZ3VpeCBwdWxs4oCZ?= when
 system clock is in the past
In-Reply-To: <4fe84e12db12aa32d75a427d3000db02@HIDDEN>
 (ngraves@HIDDEN's message of "Sat, 07 Dec 2024 10:45:02 +0100")
References: <a34560f8716ffb8ffd6522c3f8af07c8@HIDDEN>
 <4fe84e12db12aa32d75a427d3000db02@HIDDEN>
Date: Tue, 10 Dec 2024 23:23:27 +0100
Message-ID: <877c87i3ds.fsf_-_@HIDDEN>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
X-Spam-Score: -2.3 (--)
X-Debbugs-Envelope-To: 74711
Cc: 74711 <at> debbugs.gnu.org
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -3.3 (---)

Hi,

ngraves@HIDDEN skribis:

> I've found the reason behind the extremely annoying SSL certification
> refusals.
>
> When I use an installation image, the date is not necessarily set at
> the real date.  In my case, `date` was set in 2019, and triggered the
> SSL verification refusal (not yet valid).

Could it be that the clock battery of that computer is dead?  Otherwise
it=E2=80=99s not supposed to happen.

> I don't know why it sometimes doesn't happen.  If we can't
> fix/automate it at the time we boot in the installation medium, we
> should probably add a warning in the manual / a hint in guix pull / a
> proper error in guile-git (that could provide more information than
> just Git failing) ?

The error I see is:

--8<---------------cut here---------------start------------->8---
$ guix shell libfaketime -- faketime 2019-01-01 guix pull -p /tmp/p
Updating channel 'shepherd' from Git repository at 'https://git.savannah.gn=
u.org/git/shepherd.git'...
guix pull: error: Git error: the SSL certificate is invalid
--8<---------------cut here---------------end--------------->8---

I agree it could give more details, but that=E2=80=99s all we get from libg=
it2 I
believe.  Worth investigating how this can be improved.

That said, what we could/should do is add a =E2=80=98--no-check-certificate=
=E2=80=99
option to =E2=80=98pull=E2=80=99 and =E2=80=98time-machine=E2=80=99; it wou=
ld be handy in emergency
situations like you described.

It should be possible to implement that with the =E2=80=98certificate_check=
=E2=80=99
callback in =E2=80=98git_remote_callbacks=E2=80=99.  I=E2=80=99ll see what =
can be done in this
area.

Thanks,
Ludo=E2=80=99.




Information forwarded to bug-guix@HIDDEN:
bug#74711; Package guix. Full text available.

Message received at 74711 <at> debbugs.gnu.org:


Received: (at 74711) by debbugs.gnu.org; 7 Dec 2024 09:53:45 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Sat Dec 07 04:53:45 2024
Received: from localhost ([127.0.0.1]:45430 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1tJrVR-0002bw-6S
	for submit <at> debbugs.gnu.org; Sat, 07 Dec 2024 04:53:45 -0500
Received: from 2.mo576.mail-out.ovh.net ([178.33.251.80]:33635)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <ngraves@HIDDEN>) id 1tJrVO-0002bk-6E
 for 74711 <at> debbugs.gnu.org; Sat, 07 Dec 2024 04:53:43 -0500
Received: from director5.ghost.mail-out.ovh.net (unknown [10.109.148.126])
 by mo576.mail-out.ovh.net (Postfix) with ESMTP id 4Y53Nh6SG3z1j8X
 for <74711 <at> debbugs.gnu.org>; Sat,  7 Dec 2024 09:53:40 +0000 (UTC)
Received: from ghost-submission-5b5ff79f4f-5l579 (unknown [10.110.101.176])
 by director5.ghost.mail-out.ovh.net (Postfix) with ESMTPS id A51FC1FE42
 for <74711 <at> debbugs.gnu.org>; Sat,  7 Dec 2024 09:53:40 +0000 (UTC)
Received: from ngraves.fr ([37.59.142.103])
 by ghost-submission-5b5ff79f4f-5l579 with ESMTPSA
 id cLDNHSQbVGcjDhgAWsXwQw (envelope-from <ngraves@HIDDEN>)
 for <74711 <at> debbugs.gnu.org>; Sat, 07 Dec 2024 09:53:40 +0000
Authentication-Results: garm.ovh; auth=pass
 (GARM-103G00577715fd2-9d45-4934-8ed4-88841af7a8b4,
 7603EEAE480C95FC7608FEAED483BD06369A0934) smtp.auth=ngraves@HIDDEN
X-OVh-ClientIp: 176.31.238.120
MIME-Version: 1.0
Date: Sat, 07 Dec 2024 10:53:40 +0100
From: ngraves@HIDDEN
To: 74711 <at> debbugs.gnu.org
Subject: Re: Sharing some progress
In-Reply-To: <4fe84e12db12aa32d75a427d3000db02@HIDDEN>
References: <4fe84e12db12aa32d75a427d3000db02@HIDDEN>
Message-ID: <305651c5d363f13f253b8290e09ba497@HIDDEN>
X-Sender: ngraves@HIDDEN
X-Originating-IP: 90.92.117.144
X-Webmail-UserID: ngraves@HIDDEN
Content-Type: text/plain; charset=UTF-8;
 format=flowed
Content-Transfer-Encoding: 8bit
X-Ovh-Tracer-Id: 1955688140266463828
X-VR-SPAMSTATE: OK
X-VR-SPAMSCORE: 0
X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeefuddrjedugddtkecutefuodetggdotefrodftvfcurfhrohhfihhlvgemucfqggfjpdevjffgvefmvefgnecuuegrihhlohhuthemucehtddtnecunecujfgurhepggffhffvufgjfhfkgihitgfgsehtkehjtddttdejnecuhfhrohhmpehnghhrrghvvghssehnghhrrghvvghsrdhfrhenucggtffrrghtthgvrhhnpeekveegvedttdfflefhvdevueeutedvjefgffeffeeghedujedvgfejvdfhtdeghfenucfkphepuddvjedrtddrtddruddpledtrdelvddruddujedrudeggedpudejiedrfedurddvfeekrdduvddtpdefjedrheelrddugedvrddutdefnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepuddvjedrtddrtddruddpmhgrihhlfhhrohhmpehnghhrrghvvghssehnghhrrghvvghsrdhfrhdpnhgspghrtghpthhtohepuddprhgtphhtthhopeejgeejudduseguvggssghughhsrdhgnhhurdhorhhgpdfovfetjfhoshhtpehmohehjeeimgdpmhhouggvpehsmhhtphhouhht
DKIM-Signature: a=rsa-sha256; bh=EZPz6Pm6n5h5walP6m5FN0FPfxBUmj4Eu6H1Kw7Z9EI=; 
 c=relaxed/relaxed; d=ngraves.fr; h=From;
 s=ovhmo4487190-selector1; t=1733565221; v=1;
 b=HS9WNLk1KI0JMTZ//Qzo+3bBwBf+4vKd+ydHB6qACBCgoYab/1aCrsLu7UdW6vzyBClbViA6
 icpMmwg6mDEmciVbcsAzlZWCV4rfDzGt85nQkUcFgK9YWwBKG829vmLnUE/CCMdqWo48tF+Dcr2
 MuR16gic9N7ZkUq563iKf6ak+bZoVSmApRNAYZ32cuIOpTdTxGAvX2uQntgQSmhm+cXhGAFOQNy
 sF+noXvwTyY7tkKvE10rCYDHSD3oknmrmVBTmBgG5xBmt7KBYEluN+qJihvjMOH1Vb/wY1SBz9O
 +HUipuA14uABlBaqKbf1VGmMCW0s6Qozu7w9dsKmopb9Q==
X-Spam-Score: 0.0 (/)
X-Debbugs-Envelope-To: 74711
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -1.0 (-)

Le 07.12.2024 10:45, ngraves@HIDDEN a écrit :
> 
> WDYT ?

By the way, guix install did work perfectly fine despite SSL 
certificates failing, does that mean that it doesn't do any SSL 
certificate verification ? Is that considered safe? How about 
man-in-the-middle and data-tampering attacks? Are they impossible due to 
sha checksums in Guix, or is that a vulnerability ?

Nicolas




Information forwarded to bug-guix@HIDDEN:
bug#74711; Package guix. Full text available.

Message received at 74711 <at> debbugs.gnu.org:


Received: (at 74711) by debbugs.gnu.org; 7 Dec 2024 09:45:17 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Sat Dec 07 04:45:16 2024
Received: from localhost ([127.0.0.1]:45414 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1tJrNE-0002FD-Jn
	for submit <at> debbugs.gnu.org; Sat, 07 Dec 2024 04:45:16 -0500
Received: from 5.mo550.mail-out.ovh.net ([178.33.45.107]:35379)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <ngraves@HIDDEN>) id 1tJrNA-0002At-1o
 for 74711 <at> debbugs.gnu.org; Sat, 07 Dec 2024 04:45:15 -0500
Received: from director10.ghost.mail-out.ovh.net (unknown [10.108.25.157])
 by mo550.mail-out.ovh.net (Postfix) with ESMTP id 4Y53Bt31gkz1BhM
 for <74711 <at> debbugs.gnu.org>; Sat,  7 Dec 2024 09:45:10 +0000 (UTC)
Received: from ghost-submission-5b5ff79f4f-jnm98 (unknown [10.110.178.91])
 by director10.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 36F531FD97
 for <74711 <at> debbugs.gnu.org>; Sat,  7 Dec 2024 09:45:09 +0000 (UTC)
Received: from ngraves.fr ([37.59.142.105])
 by ghost-submission-5b5ff79f4f-jnm98 with ESMTPSA
 id P/sRLiUZVGeCHAAA84mebQ (envelope-from <ngraves@HIDDEN>)
 for <74711 <at> debbugs.gnu.org>; Sat, 07 Dec 2024 09:45:09 +0000
Authentication-Results: garm.ovh; auth=pass
 (GARM-105G0066da73d5a-e8cd-4ebf-8d4c-7cd01ad50d9c,
 7603EEAE480C95FC7608FEAED483BD06369A0934) smtp.auth=ngraves@HIDDEN
X-OVh-ClientIp: 176.31.238.120
MIME-Version: 1.0
Date: Sat, 07 Dec 2024 10:45:02 +0100
From: ngraves@HIDDEN
To: 74711 <at> debbugs.gnu.org
Subject: Sharing some progress
Message-ID: <4fe84e12db12aa32d75a427d3000db02@HIDDEN>
X-Sender: ngraves@HIDDEN
X-Originating-IP: 90.92.117.144
X-Webmail-UserID: ngraves@HIDDEN
Content-Type: text/plain; charset=US-ASCII;
 format=flowed
Content-Transfer-Encoding: 7bit
X-Ovh-Tracer-Id: 1812135900411388500
X-VR-SPAMSTATE: OK
X-VR-SPAMSCORE: 0
X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeefuddrjedugddtiecutefuodetggdotefrodftvfcurfhrohhfihhlvgemucfqggfjpdevjffgvefmvefgnecuuegrihhlohhuthemucehtddtnecunecujfgurhepggffhffvuffkgihitgfgsehtjehjtddttddvnecuhfhrohhmpehnghhrrghvvghssehnghhrrghvvghsrdhfrhenucggtffrrghtthgvrhhnpeeuvdehudeuudejgfehgfetleekleegteekuedthedvudeltddvgeefveehteeijeenucfkphepuddvjedrtddrtddruddpledtrdelvddruddujedrudeggedpudejiedrfedurddvfeekrdduvddtpdefjedrheelrddugedvrddutdehnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepuddvjedrtddrtddruddpmhgrihhlfhhrohhmpehnghhrrghvvghssehnghhrrghvvghsrdhfrhdpnhgspghrtghpthhtohepuddprhgtphhtthhopeejgeejudduseguvggssghughhsrdhgnhhurdhorhhgpdfovfetjfhoshhtpehmohehhedtmgdpmhhouggvpehsmhhtphhouhht
DKIM-Signature: a=rsa-sha256; bh=6SxACyYfd+z6KMM60sXvF9FVn9OGH90nZA89dS6JmMY=; 
 c=relaxed/relaxed; d=ngraves.fr; h=From;
 s=ovhmo4487190-selector1; t=1733564710; v=1;
 b=zis8KqteTLP1YYYVjZXHW+oSi1T+LT7N5iFKK04NGgE7no8qU63JbP5VT5/5xsTnEuwbVHta
 EfkVizXlS3Yco4mc+GoRDY8580OE/APLZFY3gNwuTpjKsY+6dySU37gRVCrkZaOaaORYqQSV1az
 NGsjyWBvG+FbUS08ELFYrXz8zcih3MpfmwtyN6Du3icmu+U77cgnGelSDjSXi/PlvoowAQM7D+a
 rqMt06uXWTbpozLdNw/tvqEINS36YHV+TAyZqksOq9SOg1XMaqOEfhG3c/z9rkWHAMRRYWWQiRw
 c6Y+ZB2MNlrGElySc22YbRgimex2Tls2xDK4B+dNwjLsw==
X-Spam-Score: 0.0 (/)
X-Debbugs-Envelope-To: 74711
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -1.0 (-)

I've found the reason behind the extremely annoying SSL certification 
refusals.

When I use an installation image, the date is not necessarily set at the 
real date.  In my case, `date` was set in 2019, and triggered the SSL 
verification refusal (not yet valid).

I don't know why it sometimes doesn't happen.  If we can't fix/automate 
it at the time we boot in the installation medium, we should probably 
add a warning in the manual / a hint in guix pull / a proper error in 
guile-git (that could provide more information than just Git failing) ?

WDYT ?

Best regards,
Nicolas




Information forwarded to bug-guix@HIDDEN:
bug#74711; Package guix. Full text available.

Message received at submit <at> debbugs.gnu.org:


Received: (at submit) by debbugs.gnu.org; 6 Dec 2024 13:48:28 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Fri Dec 06 08:48:28 2024
Received: from localhost ([127.0.0.1]:42399 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1tJYh2-0001kY-7M
	for submit <at> debbugs.gnu.org; Fri, 06 Dec 2024 08:48:28 -0500
Received: from lists.gnu.org ([209.51.188.17]:55726)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <ngraves@HIDDEN>) id 1tJYgz-0001kO-Mq
 for submit <at> debbugs.gnu.org; Fri, 06 Dec 2024 08:48:26 -0500
Received: from eggs.gnu.org ([2001:470:142:3::10])
 by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <ngraves@HIDDEN>)
 id 1tJYgy-0004s6-D5
 for bug-guix@HIDDEN; Fri, 06 Dec 2024 08:48:25 -0500
Received: from 5.mo550.mail-out.ovh.net ([178.33.45.107])
 by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <ngraves@HIDDEN>)
 id 1tJYgv-0007K5-7U
 for bug-guix@HIDDEN; Fri, 06 Dec 2024 08:48:24 -0500
Received: from director8.ghost.mail-out.ovh.net (unknown [10.109.148.180])
 by mo550.mail-out.ovh.net (Postfix) with ESMTP id 4Y4XdX29pyz1RTn
 for <bug-guix@HIDDEN>; Fri,  6 Dec 2024 13:48:00 +0000 (UTC)
Received: from ghost-submission-5b5ff79f4f-7957q (unknown [10.110.118.228])
 by director8.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 0D1261FEB8
 for <bug-guix@HIDDEN>; Fri,  6 Dec 2024 13:48:00 +0000 (UTC)
Received: from ngraves.fr ([37.59.142.105])
 by ghost-submission-5b5ff79f4f-7957q with ESMTPSA
 id cCFPN48AU2eOlwUAvkAw/A (envelope-from <ngraves@HIDDEN>)
 for <bug-guix@HIDDEN>; Fri, 06 Dec 2024 13:48:00 +0000
Authentication-Results: garm.ovh; auth=pass
 (GARM-105G006cfe20ef5-7643-43c5-bf7c-ec61c759265e,
 9ECB5035520FF3C1D79B43E6ED276846211902CC) smtp.auth=ngraves@HIDDEN
X-OVh-ClientIp: 151.80.29.20
MIME-Version: 1.0
Date: Fri, 06 Dec 2024 14:47:57 +0100
From: ngraves@HIDDEN
To: bug-guix@HIDDEN
Subject: Is grub broken and breaking Guix ?
Message-ID: <a34560f8716ffb8ffd6522c3f8af07c8@HIDDEN>
X-Sender: ngraves@HIDDEN
X-Originating-IP: 90.92.117.144
X-Webmail-UserID: ngraves@HIDDEN
Content-Type: text/plain; charset=US-ASCII;
 format=flowed
Content-Transfer-Encoding: 7bit
X-Ovh-Tracer-Id: 40532398384800432
X-VR-SPAMSTATE: OK
X-VR-SPAMSCORE: 0
X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeefuddrieelgdehhecutefuodetggdotefrodftvfcurfhrohhfihhlvgemucfqggfjpdevjffgvefmvefgnecuuegrihhlohhuthemucehtddtnecunecujfgurhepggffhffvuffkgihitgfgsehtjehjtddttddvnecuhfhrohhmpehnghhrrghvvghssehnghhrrghvvghsrdhfrhenucggtffrrghtthgvrhhnpeeiiefgvedtffeuudetieelgefgheevtddtudegleffffejhfelheeijeejteefveenucffohhmrghinhepghhnuhdrohhrghenucfkphepuddvjedrtddrtddruddpledtrdelvddruddujedrudeggedpudehuddrkedtrddvledrvddtpdefjedrheelrddugedvrddutdehnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepuddvjedrtddrtddruddpmhgrihhlfhhrohhmpehnghhrrghvvghssehnghhrrghvvghsrdhfrhdpnhgspghrtghpthhtohepuddprhgtphhtthhopegsuhhgqdhguhhigiesghhnuhdrohhrghdpoffvtefjohhsthepmhhoheehtdgmpdhmohguvgepshhmthhpohhuth
DKIM-Signature: a=rsa-sha256; bh=UJVd7wxswvw5te8taVLK8jLv3bEF49+gOReV/gQOR4o=; 
 c=relaxed/relaxed; d=ngraves.fr; h=From;
 s=ovhmo4487190-selector1; t=1733492880; v=1;
 b=WNGkzgTf/SUS9B+LBTvbYtqq0ZpGUejUv9P9vTLxnepCn7cpFwyVZGxUGw/fHdUs+S/uv0Dg
 PhfHaVJlsMjv9w16IWktqtWokWZd1w11Cqmukz8KdKIOh372xBlWK0NGuRC29jiwQzJNdQkWsiW
 gag4N2jouU2o2gTEig8syX1LbdyvRf1euh0YgOUzrJDUwzmbe9KzLnia4PW+Urc5whQjqzbpUqJ
 nUP3m64GyYsQ5GDnJkprD+aPHq9owTs5AQACpgfgLuci5ecGRdrqENgePoXytKm64l+gEBLC8Om
 pkvg4WZwBPQFf/AJnuMgWEa9tD9zvo5vysJRJmWkGwlNg==
Received-SPF: pass client-ip=178.33.45.107; envelope-from=ngraves@HIDDEN;
 helo=5.mo550.mail-out.ovh.net
X-Spam_score_int: -20
X-Spam_score: -2.1
X-Spam_bar: --
X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,
 RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001,
 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001,
 SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no
X-Spam_action: no action
X-Spam-Score: -1.3 (-)
X-Debbugs-Envelope-To: submit
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -2.3 (--)

Hi Guix,

I've had a low-level btrfs failing issue once again on my main computer, 
but this time I'm almost unable to recover from it.

On my backup computer, I tried updating Guix before generating an 
installable image, and that broke my backup computer. I'm unable to 
install Guix that I broke due to the following error :
https://savannah.gnu.org/bugs/?64406

This error also breaks the possibility to roll-back, I have the exact 
same error with earlier Guix system profiles, thus I am stuck trying to 
reinstall a working system profile on my backup computer.

I'm able to build everything, but it fails when running grub-install.

I use a single LUKS device, with btrfs on top, and a carefully selected 
btrfs layout.

I'm able to fix the grub-install invocation using the prefixed 
GRUB_ENABLE_CRYPTODISK=y and running the command by hand, but utimately, 
it doesn't fix the underlying error. I'm not able to run it with this 
prefix using grub 2.06.

I've also been experiencing extremely annoying git and guile-git SSL 
certificates issues, despites the SSL_CERT_DIR and SSL_CERT_FILE being 
set properly. For some reason, I was not able to `guix pull` even on the 
official installation device on tuesday but without changing anything, 
but was able to do that on wednesday.

Here I am, 4 days later, still trying to get a proper up-to-date Guix 
working, even with 3-4 years of Guix experience. There's still some 
progress ahead ;)

I'm quite stuck now, I'll happily take any advice.

Nicolas




Acknowledgement sent to ngraves@HIDDEN:
New bug report received and forwarded. Copy sent to bug-guix@HIDDEN. Full text available.
Report forwarded to bug-guix@HIDDEN:
bug#74711; Package guix. Full text available.
Please note: This is a static page, with minimal formatting, updated once a day.
Click here to see this page with the latest information and nicer formatting.
Last modified: Sun, 12 Jan 2025 05:45:02 UTC

GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997 nCipher Corporation Ltd, 1994-97 Ian Jackson.