Thanks! This definitely seems to be related to secure boot, but not lockdown (which gets enabled automatically when booted under secure boot). I'll try following that lead and see what I can find.
The other thing which might still help is testing the kernel from comment #17 with secure boot enabled, to see if we can get the oops message captured in persistent storage. This means generating your own MOK with the correct extendedKeyUsage, enrolling it with shim, and signing the kernel with that key. If you're up for it, instructions are here: https://ubuntu.com/blog/how-to-sign-things-for-secure-boot Just be sure to read the section under "Enrolling the key" before actually generating your keys, which notes that you need to remove an OID from extendedKeyUsage if you want to use the key for signing kernels. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1844784 Title: X1 carbon gen 6 cannot boot 5.3.0-12 Status in linux package in Ubuntu: Confirmed Bug description: My X1 carbon gen6 will not boot the 5.3.0-12 (or 5.3.0-10) kernel. It gets as far as saying: EFI stub: Secure boot enabled Nothing else is printed. --- ProblemType: Bug ApportVersion: 2.20.11-0ubuntu7 Architecture: amd64 AudioDevicesInUse: USER PID ACCESS COMMAND /dev/snd/controlC0: powersj 1385 F.... pulseaudio CurrentDesktop: ubuntu:GNOME DistroRelease: Ubuntu 19.10 HibernationDevice: RESUME=UUID=1eb43198-8ef5-4035-8b81-74c3e2936ad7 InstallationDate: Installed on 2018-12-06 (288 days ago) InstallationMedia: Ubuntu 18.04.1 LTS "Bionic Beaver" - Release amd64 (20180725) Lsusb: Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub Bus 001 Device 002: ID 5986:2115 Acer, Inc Integrated Camera Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub MachineType: LENOVO 20KHCTO1WW Package: linux (not installed) ProcFB: 0 i915drmfb ProcKernelCmdLine: BOOT_IMAGE=/vmlinuz-5.2.0-15-generic root=/dev/mapper/ubuntu--vg-root ro ProcVersionSignature: Ubuntu 5.2.0-15.16-generic 5.2.9 RelatedPackageVersions: linux-restricted-modules-5.2.0-15-generic N/A linux-backports-modules-5.2.0-15-generic N/A linux-firmware 1.182 RfKill: 0: phy0: Wireless LAN Soft blocked: no Hard blocked: no Tags: eoan Uname: Linux 5.2.0-15-generic x86_64 UpgradeStatus: Upgraded to eoan on 2019-08-27 (24 days ago) UserGroups: adm cdrom dip docker kvm libvirt lpadmin lxd plugdev sambashare sudo _MarkForUpload: True dmi.bios.date: 07/02/2019 dmi.bios.vendor: LENOVO dmi.bios.version: N23ET65W (1.40 ) dmi.board.asset.tag: Not Available dmi.board.name: 20KHCTO1WW dmi.board.vendor: LENOVO dmi.board.version: SDK0J40709 WIN dmi.chassis.asset.tag: No Asset Information dmi.chassis.type: 10 dmi.chassis.vendor: LENOVO dmi.chassis.version: None dmi.modalias: dmi:bvnLENOVO:bvrN23ET65W(1.40):bd07/02/2019:svnLENOVO:pn20KHCTO1WW:pvrThinkPadX1Carbon6th:rvnLENOVO:rn20KHCTO1WW:rvrSDK0J40709WIN:cvnLENOVO:ct10:cvrNone: dmi.product.family: ThinkPad X1 Carbon 6th dmi.product.name: 20KHCTO1WW dmi.product.sku: LENOVO_MT_20KH_BU_Think_FM_ThinkPad X1 Carbon 6th dmi.product.version: ThinkPad X1 Carbon 6th dmi.sys.vendor: LENOVO To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1844784/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp