forked from heavy-duty/box
The console log finally showed the real error behind the GRUB-menu hang: error: prohibited by secure boot policy. error: bad shim signature. Failed to boot both default and fallback entries. Incus defaults VMs to security.secureboot=true. A Debian cloud image whose shim is signed with a key this host's OVMF does not trust then fails signature verification, the kernel never loads, and the VM sits at the GRUB menu forever — which is exactly the 5-min agent timeout on every box. It worked in runs 11–15 on the old cached image and broke the moment --purge-storage re-downloaded a build with a different shim. security.secureboot=false on VM launch (cmd_new, and the drill's legacy box). Secure Boot inside a throwaway box is not part of its threat model — the VM boundary is — and off, it boots reliably across image rebuilds. Container mode has no firmware and is unaffected. Bare repro that isolated it: 'incus launch images:debian/13/cloud x --vm' alone reproduced the hang, proving it was never the 0.5.0 code. |
||
|---|---|---|
| .. | ||
| box | ||