Hi, On Tue, Jun 29, 2021 at 02:04:47PM +0200, Salvatore Bonaccorso wrote: > Package: fwupd > Version: 1.5.7-4 > Severity: normal > X-Debbugs-Cc: car...@debian.org > > Hi > > I'm not entirely sure how to trackle this problem, since some time I'm > unable anymore to install updates available trough fwupdmgr. Secure > boot is enable, and in BIOS the 'boot order lock' *is* disabled. > > Though on every update, the firmware get's downloaded, the capsules > put in /boot/efi/EFI/debian/fw and reboot requested (and even choosing > the Linux Firmare Update manually) the firmware(s) are nut updated. > > The get-history command reflects that: > > ----cut---------cut---------cut---------cut---------cut---------cut----- > 20KGS05200 > │ > ├─LENSE30512GMSP34MEAT3TA: > │ │ Device ID: 04e17fcf7d3de91da49a163ffe4907855c3648be > │ │ Previous version: 1.4.0412 > │ │ Update State: Success > │ │ Last modified: 2020-10-01 23:11 > │ │ GUID: 124c38ac-0100-5a50-aac8-89602d99769f > │ │ Device Flags: • Internal device > │ │ • Updatable > │ │ • System requires external power source > │ │ • Supported on remote server > │ │ • Needs a reboot after installation > │ │ • Reported to remote server > │ │ • Device is usable for the duration of the update > │ │ > │ └─LENSE30512GMSP34MEAT3TA Device Update: > │ New version: 2.5.0412 > │ Remote ID: lvfs > │ Summary: Unionmemory LENSE30512GMSP34MEAT3TA NVMe SSD > Firmware for Lenovo PC > │ License: Proprietary > │ Size: 588.8 kB > │ Created: 2016-07-08 > │ Urgency: High > │ Vendor: Unionmemory > │ Description: > │ Do NOT turn off your computer or remove the AC adapter while update > is in progress. > │ > │ The computer shall be restarted after updating firmware completely. > The device may not properly function until you shut down or reboot PC > │ > │ Supported devices and firmware version : Unionmemory > LENSE30512GMSP34MEAT3TA-512G-2.5.0412 > │ > │ Supported Product Scope : Lenovo ThinkPad, ThinkCentre, ThinkStation, > IdeaCentre > │ > ├─Embedded Controller: > │ │ Device ID: 9698faabddf0d7b18925cfbbda95f8b0d0dacc53 > │ │ Previous version: 0.1.8 > │ │ Update State: Success > │ │ Last modified: 2020-11-17 16:05 > │ │ GUID: 3babca5f-b2bf-4f4b-a72e-2bdc84eb4019 > │ │ Device Flags: • Internal device > │ │ • Updatable > │ │ • System requires external power source > │ │ • Supported on remote server > │ │ • Needs a reboot after installation > │ │ • Reported to remote server > │ │ • Device is usable for the duration of the update > │ │ > │ └─ThinkPad X1 Carbon 6th Embedded Controller Update: > │ New version: 0.1.22 > │ Remote ID: lvfs > │ Summary: Lenovo ThinkPad X1 Carbon 6th Embedded Controller > Firmware > │ License: Proprietary > │ Size: 767.1 kB > │ Created: 2016-07-08 > │ Urgency: High > │ Vendor: Lenovo Ltd. > │ Description: > │ Lenovo ThinkPad X1 Carbon 6th Embedded Controller Firmware > │ > │ Fixed an issue where ThinkVision T24m-10 monitor might not connected > properly. > │ > ├─UEFI Device Firmware: > │ │ Device ID: 9e329270a7a68d289c82fe77d32d02208ddf0890 > │ │ Previous version: 0.73.4 > │ │ Update State: Success > │ │ Last modified: 2021-04-27 20:27 > │ │ GUID: cea87551-1701-43fb-afbc-6e8ce9728345 > │ │ Device Flags: • Internal device > │ │ • Updatable > │ │ • System requires external power source > │ │ • Supported on remote server > │ │ • Needs a reboot after installation > │ │ • Reported to remote server > │ │ • Device is usable for the duration of the update > │ │ > │ └─ThinkPad X1 Carbon 6th System Update: > │ New version: 0.73.20 > │ Remote ID: lvfs > │ Summary: Lenovo ThinkPad X1 Carbon 6th STM TPM Firmware > │ License: Proprietary > │ Size: 439.6 kB > │ Created: 2020-03-03 > │ Urgency: High > │ Vendor: Lenovo Ltd. > │ Description: > │ Lenovo ThinkPad X1 Carbon 6th STM TPM Firmware Version 73.20 > │ > │ • Do NOT turn off your computer or remove the AC adaptor while update > is in progress > │ > ├─Intel Management Engine: > │ │ Device ID: e563ad307df81c99f0de8c26292afd71cf409673 > │ │ Previous version: 184.83.3874 > │ │ Update State: Failed > │ │ Update Error: failed to run update on reboot > │ │ Last modified: 2021-06-29 11:45 > │ │ GUID: 42a0a96e-c9f3-438f-9687-7826be33e4ce > │ │ Device Flags: • Internal device > │ │ • Updatable > │ │ • System requires external power source > │ │ • Supported on remote server > │ │ • Needs a reboot after installation > │ │ • Device is usable for the duration of the update > │ │ > │ └─ThinkPad X1 Carbon 6th Corporate ME Update: > │ New version: 184.86.3909 > │ Remote ID: lvfs > │ Summary: Lenovo ThinkPad X1 Carbon 6th Corporate ME Firmware > │ License: Proprietary > │ Size: 7.5 MB > │ Created: 2016-07-08 > │ Urgency: High > │ Details: > https://pcsupport.lenovo.com/de/en/search?query=N23RM17W > │ Vendor: Lenovo Ltd. > │ Flags: is-upgrade > │ Description: > │ Lenovo ThinkPad X1 Carbon 6th ME Firmware Version 11.8.86.3909(LVFS: > 184.86.3909) > │ > │ The computer will be restarted automatically after updating > completely. Do NOT turn off your computer or remove the AC adaptor while > update is in progress. > │ > │ This stable release fixes the following issues: > │ > │ • Intel CSME IPU 2021.1: > │ > │ Addressed several critical security vulnerabilities. > │ > └─System Firmware: > │ Device ID: 1c53551e7da69d896138fac1ae131c83ad46d923 > │ Previous version: 0.1.50 > │ Update State: Failed > │ Update Error: failed to run update on reboot > │ Last modified: 2021-06-29 11:47 > │ GUID: a4b51dca-8f97-4310-8821-3330f83c9135 > │ Device Flags: • Internal device > │ • Updatable > │ • System requires external power source > │ • Supported on remote server > │ • Needs a reboot after installation > │ • Cryptographic hash verification is available > │ • Device is usable for the duration of the update > │ > └─ThinkPad X1 Carbon 6th System Update: > New version: 0.1.51 > Remote ID: lvfs > Summary: Lenovo ThinkPad X1 Carbon 6th System Firmware > License: Proprietary > Size: 9.5 MB > Created: 2016-07-08 > Urgency: High > Vendor: Lenovo Ltd. > Flags: is-upgrade > Description: > Lenovo ThinkPad X1 Carbon 6th System Firmware > > • Fixed an security issue. > • Update Version 04.17.000 code of FIT's InROM diagnostics. > ----cut---------cut---------cut---------cut---------cut---------cut----- > > Any idea how to untagle this? Which information would be helpfull if > you direct me directly to fwupd upstream (happy to put it there but > I'm currently a bit lost on how to tackle this update loops, as the > most common suggestion is the disable boot order lock, which *is* > disabled).
Interesting datapoint: I experimented further, and disabled secure boot. After that I was able to install those updates. Does that possibly ring some bell? Regards, Salvatore