You are not logged in.

#1 2019-11-24 12:41:26

s1ncla
Member
Registered: 2019-11-24
Posts: 5

Something wrong with RNG protocol

Hello to all.

Here is trouble.

After clean install i see this message everytime during boot:

SHA256 validated
Failed to acquire RNG protocol: Not found

after: sudo bootctl random-seed
this message is gone, but:

systemctl status systemd-boot-system-token.service

says:

● systemd-boot-system-token.service - Store a System Token in an EFI Variable
   Loaded: loaded (/usr/lib/systemd/system/systemd-boot-system-token.service; static; vendor preset: disabled)
   Active: inactive (dead)
Condition: start condition failed at Sat 2019-11-23 19:36:42 MSK; 2h 56min left
           ├─ ConditionPathExists=|!/sys/firmware/efi/efivars/LoaderSystemToken-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f was not met
           └─ ConditionPathExists=|!/sys/firmware/efi/efivars/LoaderRandomSeed-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f was not met
     Docs: man:systemd-boot-system-token.service(8)

interesting thing, i do: sudo rm /boot/loader/random-seed

reboot

systemctl status systemd-boot-system-token.service

● systemd-boot-system-token.service - Store a System Token in an EFI Variable
   Loaded: loaded (/usr/lib/systemd/system/systemd-boot-system-token.service; static; vendor preset: disabled)
   Active: active (exited) since Sun 2019-11-24 14:08:23 MSK; 57s ago
     Docs: man:systemd-boot-system-token.service(8)
  Process: 539 ExecStart=/usr/bin/bootctl random-seed (code=exited, status=0/SUCCESS)
 Main PID: 539 (code=exited, status=0/SUCCESS)

ноя 24 14:08:23 evgarch systemd[1]: Starting Store a System Token in an EFI Variable...
ноя 24 14:08:23 evgarch bootctl[539]: Random seed file /boot/loader/random-seed successfully written (512 bytes).
ноя 24 14:08:23 evgarch systemd[1]: Started Store a System Token in an EFI Variable.

looks like everything ok?

reboot again and...

● systemd-boot-system-token.service - Store a System Token in an EFI Variable
   Loaded: loaded (/usr/lib/systemd/system/systemd-boot-system-token.service; static; vendor preset: disabled)
   Active: inactive (dead)
Condition: start condition failed at Sat 2019-11-23 19:36:42 MSK; 2h 56min left
           ├─ ConditionPathExists=|!/sys/firmware/efi/efivars/LoaderSystemToken-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f was not met
           └─ ConditionPathExists=|!/sys/firmware/efi/efivars/LoaderRandomSeed-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f was not met
     Docs: man:systemd-boot-system-token.service(8)

anybody knows whats wrong with this???

Last edited by s1ncla (2019-11-24 12:43:01)

Offline

#2 2019-11-24 13:24:19

loqs
Member
Registered: 2014-03-06
Posts: 19,097

Re: Something wrong with RNG protocol

Offline

#3 2019-11-24 13:31:35

s1ncla
Member
Registered: 2019-11-24
Posts: 5

Re: Something wrong with RNG protocol

Ok, but why when i delete random-seed file and reboot everything looks normal ???

● systemd-boot-system-token.service - Store a System Token in an EFI Variable
   Loaded: loaded (/usr/lib/systemd/system/systemd-boot-system-token.service; static; vendor preset: disabled)
   Active: active (exited) since Sun 2019-11-24 14:08:23 MSK; 57s ago
 

Offline

#4 2019-11-24 13:59:26

loqs
Member
Registered: 2014-03-06
Posts: 19,097

Re: Something wrong with RNG protocol

systemd-boot-system-token.service does not use the random seed.
Is sd-boot not printing a message "Failed to open random seed file"?
https://github.com/systemd/systemd/blob … eed.c#L262

Offline

#5 2019-11-24 14:13:33

2ManyDogs
Forum Fellow
Registered: 2012-01-15
Posts: 4,648

Re: Something wrong with RNG protocol

Moving to Newbie Corner.

Offline

#6 2019-11-25 12:51:23

s1ncla
Member
Registered: 2019-11-24
Posts: 5

Re: Something wrong with RNG protocol

loqs, why do you post this links to source code???? I'm not programmer !

Offline

#7 2019-11-25 21:50:36

loqs
Member
Registered: 2014-03-06
Posts: 19,097

Re: Something wrong with RNG protocol

I provided the link to the source as that was my basis for asking about the message "Failed to open random seed file"?
I try to provide reasoning / references for my requests wen they may not be obvious.
While https://systemd.io/RANDOM_SEEDS covers the use of random seeds in systemd detail it does not cover implementation details such as error messages.

Offline

#8 2019-11-25 23:00:23

s1ncla
Member
Registered: 2019-11-24
Posts: 5

Re: Something wrong with RNG protocol

I would like to know what it means at all and can I (should ?) fix it?

Is it possible to check what the case is? Because some point to an outdated UEFI, but the version of UEFI I have 2.60

Last edited by s1ncla (2019-11-25 23:05:57)

Offline

#9 2019-11-25 23:17:03

loqs
Member
Registered: 2014-03-06
Posts: 19,097

Re: Something wrong with RNG protocol

Is the system updated to use systemd 243.162-2?
The messages should no longer be printed with that version.

SHA256 validated

Was only meant to be printed on debug builds and should be fixed by [1]

Failed to acquire RNG protocol: Not found

See my links in posts #2 and #7 will no longer be printed after commit [2]

[1] https://github.com/systemd/systemd-stab … 836e03845a
[2] https://github.com/systemd/systemd-stab … ec4686fa7b

Offline

#10 2019-11-25 23:26:44

s1ncla
Member
Registered: 2019-11-24
Posts: 5

Re: Something wrong with RNG protocol

Message is not show anymore, I just asking another thing:

● systemd-boot-system-token.service - Store a System Token in an EFI Variable
   Loaded: loaded (/usr/lib/systemd/system/systemd-boot-system-token.service; static; vendor preset: disabled)
   Active: inactive (dead)
Condition: start condition failed at Sat 2019-11-23 19:36:42 MSK; 2h 56min left
           ├─ ConditionPathExists=|!/sys/firmware/efi/efivars/LoaderSystemToken-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f was not met
           └─ ConditionPathExists=|!/sys/firmware/efi/efivars/LoaderRandomSeed-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f was not met
     Docs: man:systemd-boot-system-token.service(8)

what does means: Active: inactive (dead) ??

and this: ConditionPathExists=|!/sys/firmware/efi/efivars/LoaderSystemToken-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f was not met
             ConditionPathExists=|!/sys/firmware/efi/efivars/LoaderRandomSeed-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f was not met

Offline

#11 2019-11-26 00:17:13

loqs
Member
Registered: 2014-03-06
Posts: 19,097

Re: Something wrong with RNG protocol

Inactive means literally that,  not running.  The condition lines detail which conditions were not met.
The entries are prefixed | meaing one of the conditions must be met instead of all of them.
The entries are prefixed ! so the the path must not exist.
Combining the above the service will be started if one of the following paths:

/sys/firmware/efi/efivars/LoaderSystemToken-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f
/sys/firmware/efi/efivars/LoaderRandomSeed-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f

does not exist.
So if both those paths exist on your system the unit will be quietly skipped.
In this case the unit checks if the random seed should be stored in an EFI variable and if those variables has already been created.
The variable is not rewritten to reduce writes to EFI variables which may be stored in low quality NVRAM.

More details on systemd unit conditions in `man 5 systemd.unit`
BOOT_LOADER_INTERFACE.md covers the difference between LoaderRandomSeed and LoaderSystemToken.

Last edited by loqs (2019-11-26 00:36:55)

Offline

Board footer

Powered by FluxBB