Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #89007

Bug#1112207: Secure Boot unconditionally disables hibernation

From Anton Khirnov <anton@khirnov.net>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#1112207: Secure Boot unconditionally disables hibernation
Date 2025-08-27 15:10 +0200
Message-ID <Loo4x-aKZ9-3@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


Source: linux
Severity: normal

Dear maintainer(s),
it seems that when Debian kernel images are booted under UEFI Secure
Boot, they unconditionally enable kernel lockdown, which (among other
things) unconditionally disables the ability to hibernate (suspend to
disk).

While I understand the reasoning behind this is that the suspended image
could be maliciously modified, this is not a concern for every user -
e.g. in my case the system suspends to a LUKS-encrypted swap partition.

Therefore I believe there should be a way for people to make use of
Secure Boot's boot image integrity guarantees while preserving the
ability to hibernate.

Cheers,
-- 
Anton Khirnov

-- System Information:
Debian Release: 13.0
  APT prefers unstable-debug
  APT policy: (500, 'unstable-debug'), (500, 'stable-debug'), (500, 'stable'), (400, 'unstable'), (300, 'experimental'), (1, 'experimental-debug')
Architecture: amd64 (x86_64)

Kernel: Linux 6.16.3+deb14-amd64 (SMP w/12 CPU threads; PREEMPT)
Kernel taint flags: TAINT_CPU_OUT_OF_SPEC
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: sysvinit (via /sbin/init)

Back to linux.debian.kernel | Previous | Next | Find similar | Unroll thread


Thread

Bug#1112207: Secure Boot unconditionally disables hibernation Anton Khirnov <anton@khirnov.net> - 2025-08-27 15:10 +0200

csiph-web