Received: by 2002:a05:6358:1087:b0:cb:c9d3:cd90 with SMTP id j7csp1519370rwi; Fri, 14 Oct 2022 21:17:06 -0700 (PDT) X-Google-Smtp-Source: AMsMyM4bA1ypbckZbYXQMtecmBlOuGrZcRMa1r5mpk3YaqpRO7XnK6Z/gnRFbM0OMjQ5csvmY2uF X-Received: by 2002:a05:6402:274c:b0:45c:bb27:3d39 with SMTP id z12-20020a056402274c00b0045cbb273d39mr834969edd.163.1665807426398; Fri, 14 Oct 2022 21:17:06 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1665807426; cv=none; d=google.com; s=arc-20160816; b=gJrrP5cr6zAcGlb3L0Jqs/lTRrh9u025s3L5Rg05rV7nVog0WcOiIkQIlJTqlKmVY2 13RGs+opifYi8ff0ddu7nHcxvLcY8TdmiV9BAGLGcHTFMTG5Kj1Nt9AXN3uVqbUKLr57 T4tDFVz90VhwJFHpSWIZIqvfci9/HnKZY2RAGo0/DCyE8O/B9cLZZUG/jcr/a94MQFh7 /GWIBZu+EGrM6i2Au+vfWGflW3DQlFbnu7cGXFOucsQBOR2HqA0txNBt9VWsbshVVCar nhldMIgwEJ2ouw0Qg+EtpdEc742IWRgWGHwbGRK0ir6LXvaWyDSu+TjlasKN0ajMfn63 Omiw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:jabber-id:content-disposition:mime-version :message-id:subject:cc:to:from:dkim-signature:date; bh=U8xvXcEsK7tvXOqJfIaOyDf2VD0+6rvjfEmv0MNaC+Q=; b=y+4KbJeAvtcD9YY7cgPI0Pl8koiXBbs8W8kP4n0kkRrAEFVA1wB7cGQD6x1u29ITRE U7Aef5XH8gy9BvF0PoM6f8zOkbKmqb0N5FCOzO+SO7D6G0OOfuO5IpPM7ih4J4VVbBrv i0Uky6d/QtmSXgbuwRRJQmBW1qyxNAH5GdoA3FtQvkAqMcRAGVGvYYrtDVM+m6MQweSY f372qHGnLyrChgir1S75+mh9BpV1LKucQio1SoBwB5uqGNocCvZkFta11Cq3zm6erbsF rPfa4yCR1UEuyjnNM7o/eYDId/XaPFFCgyBL9RlmJxPcSbMvRH6tlgcwOGq1xi/v6lj7 Va3Q== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@t-8ch.de header.s=mail header.b=axNeRpnt; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id sc41-20020a1709078a2900b0078ddde15fdcsi4298817ejc.279.2022.10.14.21.16.40; Fri, 14 Oct 2022 21:17:06 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=fail header.i=@t-8ch.de header.s=mail header.b=axNeRpnt; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229681AbiJODRI (ORCPT + 99 others); Fri, 14 Oct 2022 23:17:08 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:43516 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229540AbiJODRG (ORCPT ); Fri, 14 Oct 2022 23:17:06 -0400 Received: from todd.t-8ch.de (todd.t-8ch.de [159.69.126.157]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id B1DB7923D8 for ; Fri, 14 Oct 2022 20:17:04 -0700 (PDT) Date: Sat, 15 Oct 2022 05:16:49 +0200 DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=t-8ch.de; s=mail; t=1665803819; bh=U8xvXcEsK7tvXOqJfIaOyDf2VD0+6rvjfEmv0MNaC+Q=; h=Date:From:To:Cc:Subject:From; b=axNeRpntvhmaeNQl+2N0orJkCMTpoi0tRmDwmw+MtkebVJQMFBPafdMYfk2u9t4qT /ZictVzSMznKwbeLSER/xJ1V52PSYYphxfNVylX0ylG5Bdx+tdDkvqFm10WzfsJ92X 0AKiWvf9HKDgMD1iXuo4g7PuSoLNW370lxyYV1I0= From: Thomas =?utf-8?Q?Wei=C3=9Fschuh?= To: =?utf-8?Q?Micka=C3=ABl_Sala=C3=BCn?= , Jarkko Sakkinen , David Howells , David Woodhouse , keyrings@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Mark Pearson Subject: [BUG] blacklist: Problem blacklisting hash (-13) during boot Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Jabber-ID: thomas@t-8ch.de X-Accept: text/plain, text/html;q=0.2, text/*;q=0.1 X-Accept-Language: en-us, en;q=0.8, de-de;q=0.7, de;q=0.6 X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi, Since 5.19 during boot I see lots of the following entries in dmesg: blacklist: Problem blacklisting hash (-13) This happens because the firmware contains duplicate blacklist entries. As commit 6364d106e041 [0] modified the "blacklist" keyring to reject updates this now leads to the spurious error messages. The machine is a Thinkpad X1 Cargon Gen9 with BIOS revision 1.56 and firmware revision 1.33. [0] 6364d106e041 ("certs: Allow root user to append signed hashes to the blacklist keyring")