Files
s390-tools/rust/pvebc/95sel-ebc/sel-ebc-pvebc.service
T
Finn Callies 851f63eb03 pvebc: Fix dependency for non EBC guests
For guests that do not make use of the EBC feature the boot should not
be impacted by this module. This requires removing the boot.mount unit
because it will unconditionally create a dependency on a unit that
conflicts with that idea. The downside is that mounting of the boot
partition has to be done manually.

Fixes: https://github.com/ibm-s390-linux/s390-tools/issues/202
Reviewed-by: Holger Dengler <dengler@linux.ibm.com>
Signed-off-by: Finn Callies <fcallies@linux.ibm.com>
Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
2026-05-21 13:20:06 +02:00

37 lines
1.1 KiB
Desktop File

[Unit]
Description=Run pvebc during early boot to process SICS
# boot partition contains SICS
# Loading of kernel modules is required which are needed for protected keys
Requires=systemd-modules-load.service
Requires=sel-ebc-boot-mount.service
# Ensure this runs before the handoff to the real root, if that's required:
Before=initrd-root-device.target
Before=cryptsetup-pre.target
Before=cryptsetup.target
After=systemd-modules-load.service
After=sel-ebc-boot-mount.service
# Initramfs requirement
DefaultDependencies=no
# Make absolutely sure this only runs in initramfs
ConditionPathExists=/etc/initrd-release
AssertPathIsDirectory=/boot/sics
ConditionKernelCommandLine=rd.sel-ebc
[Service]
Type=oneshot
# execute pvebc
ExecStart=/bin/bash /etc/sel-ebc/pvebc-wrapper.sh
RemainAfterExit=yes
# If pvebc fails immediately abort boot
FailureAction=poweroff-immediate
# boot partition is unencrypted and contains SICS so we can get logs out this way
# logs do not leek any sensitive information
StandardOutput=console
StandardError=console
[Install]
RequiredBy=sel-ebc.target