diff --git a/crates/cardwire-daemon/src/daemon.rs b/crates/cardwire-daemon/src/daemon.rs index 8b6e672b..c4bdf0dc 100644 --- a/crates/cardwire-daemon/src/daemon.rs +++ b/crates/cardwire-daemon/src/daemon.rs @@ -22,7 +22,8 @@ pub const STATE_PATH: &str = "/var/lib/cardwire"; #[tokio::main] async fn main() -> Result<()> { // log - env_logger::Builder::from_env(Env::default().default_filter_or("info")) + // zbus logs every incoming D-Bus call at info level, with the whole message + env_logger::Builder::from_env(Env::default().default_filter_or("info,zbus=warn")) .format_target(false) .format_timestamp(None) .init(); diff --git a/crates/cardwire-ebpf-userspace/src/lib.rs b/crates/cardwire-ebpf-userspace/src/lib.rs index 0c8591be..1f4c4907 100644 --- a/crates/cardwire-ebpf-userspace/src/lib.rs +++ b/crates/cardwire-ebpf-userspace/src/lib.rs @@ -8,7 +8,7 @@ use aya::{ Btf, Ebpf, maps::{Array, HashMap, MapError, RingBuf}, programs::{Lsm, TracePoint} }; use aya_log::EbpfLogger; -use log::{Log, error, info, warn}; +use log::{Log, debug, error, info, warn}; use tokio::{ io::{Interest, unix::AsyncFd}, sync::RwLock }; @@ -150,12 +150,15 @@ impl EbpfBlocker { } Err(err) => { // If we cannot load the program, it usually mean the kernel lockdown is enabled - let lockdown = is_lockdown_enabled(); - warn!( - "Failed to load sys_exit_getdents64. Lockdown status: {}", - lockdown - ); - warn!("{}", err); + if is_lockdown_enabled() { + // Expected under lockdown, the verifier log is only noise then + warn!( + "Kernel lockdown is enabled (e.g. by Secure Boot), sys_exit_getdents64 cannot be loaded: blocked GPUs will still show up in directory listings" + ); + debug!("{}", err); + } else { + warn!("Failed to load sys_exit_getdents64: {}", err); + } warn!("falling back to a weakened cardwired..."); } }; diff --git a/docs/diagnostics/troubleshooting.md b/docs/diagnostics/troubleshooting.md index 036144f8..71cc2710 100644 --- a/docs/diagnostics/troubleshooting.md +++ b/docs/diagnostics/troubleshooting.md @@ -63,3 +63,20 @@ sudo systemctl restart nvidia-powerd.service > [!NOTE] > This was fixed in cardwire 0.12.1, cardwired now stop and start nvidia-powerd on mode switch instead of a naive restart + +## Secure Boot and kernel lockdown + +With Secure Boot, most distributions enable kernel lockdown. Check it with: + +```bash +cat /sys/kernel/security/lockdown +``` + +If `[integrity]` or `[confidentiality]` is selected, the kernel refuses the eBPF program that hides blocked GPUs from directory listings, and cardwired logs: + +``` +Kernel lockdown is enabled (e.g. by Secure Boot), sys_exit_getdents64 cannot be loaded: blocked GPUs will still show up in directory listings +falling back to a weakened cardwired... +``` + +Blocking still works: apps cannot open a blocked GPU, and it can still power down. The GPU's sysfs entries stay visible but cannot be read, so for example `lspci` shows a blocked GPU as `Unassigned class [ffff]: Illegal Vendor ID Device ffff`. This is expected and harmless.