3 ms·
If UEFI Secure Boot is enabled, Fedora kernels detect this and lockdown. And hibernation is then disabled. The reason is lack of an autheticated hibernation ima
by cmurf 1y ago
If UEFI Secure Boot is enabled, Fedora kernels detect this and lockdown. And hibernation is then disabled. The reason is lack of an autheticated hibernation image. This work has had several proposals but still isn't implemented.
I'm not sure of the status on other distro kernels but allowing it would be a significant bypass of Secure Boot's purpose.
- fluoridation 1y agoCan secure boot be disabled on Macs?
- GeekyBear 1y agoMacs allow the device owner to install an OS that isn't signed at all, without having it degrade the security of the system when you do boot into MacOS.
- fluoridation 1y agoFine, but can it be disabled? If secure boot is interfering with another function of the computer, the owner might decide they prefer hibernation over secure boot.
- wtallis 1y agoI think what you're missing is that "secure boot" isn't a system-wide on/off thing on a Mac, it's a per-OS thing. And UEFI Secure Boot specifically is something that only exists on a Mac to the extent that Asahi shoehorns it into a system that doesn't natively do anything UEFI-related. It would be very surprising if Asahi Linux didn't still provide a way to skip their UEFI Secure Boot code paths and just plain boot.
- bigyabai 1y agoYes, but that's not a perfect excuse since OpenCore (and Clover) exists. macOS very well can boot without iBoot's opaque "man behind the curtain" blobs, Apple simply never entertained it as an option on their chips. Apparently important stuff is happening in that boot process and they can't have you emulating it for fun or profit. That is worth discussing though, as it's a marked departure from old Macbooks that did support the UEFI method.
- bri3d 1y agoThis exact thing is irrelevant to Asahi; the reason they don't support suspend-to-disk is that their drivers don't support full reconfiguration. This is a difficult task, as is "true suspend," because Macs have tons and tons of peripheral SoCs running firmware with their own SRAM, so resuming from suspend or hibernate creates a delta between the firmware state and the system state. (and, before the usual Apple trolls show up, this is true on x86 lately too, but on x86 the driver and platform interface is more standardized to support these kind of state changes without as much OS support). Needing a way to securely verify the hibernate image is ALSO a problem, and one of the reasons Asahi haven't focused on suspend-to-disk, but it's not the first-order issue.
- zozbot234 1y agoYou can always set the system up to boot in insecure mode via shim, even if UEFI Secure Boot is active. It requires an explicit configuration step with physical presence, but it's doable.
- izacus 1y agoYeah, the security freaks basically broke hibernation across Linux ecosystem.