mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
851f63eb03
For guests that do not make use of the EBC feature the boot should not be impacted by this module. This requires removing the boot.mount unit because it will unconditionally create a dependency on a unit that conflicts with that idea. The downside is that mounting of the boot partition has to be done manually. Fixes: https://github.com/ibm-s390-linux/s390-tools/issues/202 Reviewed-by: Holger Dengler <dengler@linux.ibm.com> Signed-off-by: Finn Callies <fcallies@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
37 lines
1.1 KiB
Desktop File
37 lines
1.1 KiB
Desktop File
[Unit]
|
|
Description=Run pvebc during early boot to process SICS
|
|
|
|
# boot partition contains SICS
|
|
# Loading of kernel modules is required which are needed for protected keys
|
|
Requires=systemd-modules-load.service
|
|
Requires=sel-ebc-boot-mount.service
|
|
|
|
# Ensure this runs before the handoff to the real root, if that's required:
|
|
Before=initrd-root-device.target
|
|
Before=cryptsetup-pre.target
|
|
Before=cryptsetup.target
|
|
After=systemd-modules-load.service
|
|
After=sel-ebc-boot-mount.service
|
|
|
|
# Initramfs requirement
|
|
DefaultDependencies=no
|
|
# Make absolutely sure this only runs in initramfs
|
|
ConditionPathExists=/etc/initrd-release
|
|
AssertPathIsDirectory=/boot/sics
|
|
ConditionKernelCommandLine=rd.sel-ebc
|
|
|
|
[Service]
|
|
Type=oneshot
|
|
# execute pvebc
|
|
ExecStart=/bin/bash /etc/sel-ebc/pvebc-wrapper.sh
|
|
RemainAfterExit=yes
|
|
# If pvebc fails immediately abort boot
|
|
FailureAction=poweroff-immediate
|
|
# boot partition is unencrypted and contains SICS so we can get logs out this way
|
|
# logs do not leek any sensitive information
|
|
StandardOutput=console
|
|
StandardError=console
|
|
|
|
[Install]
|
|
RequiredBy=sel-ebc.target
|