mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
For guests that do not make use of the EBC feature the boot should not be impacted by this module. This requires removing the boot.mount unit because it will unconditionally create a dependency on a unit that conflicts with that idea. The downside is that mounting of the boot partition has to be done manually. Fixes: https://github.com/ibm-s390-linux/s390-tools/issues/202 Reviewed-by: Holger Dengler <dengler@linux.ibm.com> Signed-off-by: Finn Callies <fcallies@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
85 lines
2.6 KiB
Bash
85 lines
2.6 KiB
Bash
#!/bin/bash
|
|
# SPDX-License-Identifier: MIT
|
|
#
|
|
# Copyright IBM Corp.
|
|
|
|
|
|
# Called by dracut
|
|
check() {
|
|
# always include
|
|
return 0
|
|
}
|
|
|
|
# Called by dracut
|
|
depends() {
|
|
# We need systemd in the initramfs
|
|
echo systemd
|
|
echo systemd-udevd
|
|
echo crypt
|
|
echo dm
|
|
return 0
|
|
}
|
|
|
|
# Called by dracut
|
|
installkernel() {
|
|
# kernel modules needed for opening an encrypted rfs
|
|
hostonly='' instmods -c uvdevice
|
|
hostonly='' instmods -c paes_s390
|
|
hostonly='' instmods -c pkey_uv
|
|
hostonly='' instmods -c pkey_pckmo
|
|
hostonly='' instmods -c pkey
|
|
}
|
|
|
|
# Called by dracut
|
|
install() {
|
|
# shellcheck disable=SC2154
|
|
# moddir, systemdsystemunitdir, and initdir are provided by dracut
|
|
# Copy the units into the initramfs' systemd unit dir
|
|
inst_simple "$moddir/sel-ebc.target" \
|
|
"$systemdsystemunitdir/sel-ebc.target"
|
|
inst_simple "$moddir/sel-ebc-pvebc.service" \
|
|
"$systemdsystemunitdir/sel-ebc-pvebc.service"
|
|
inst_simple "$moddir/sel-ebc-paes-enforce.service" \
|
|
"$systemdsystemunitdir/sel-ebc-paes-enforce.service"
|
|
inst_simple "$moddir/sel-ebc-override-crypttab.service" \
|
|
"$systemdsystemunitdir/sel-ebc-override-crypttab.service"
|
|
inst_simple "$moddir/sel-ebc-boot-mount.service" \
|
|
"$systemdsystemunitdir/sel-ebc-boot-mount.service"
|
|
|
|
# already exisitng unit we depend on for kernel modules
|
|
inst_simple /usr/lib/systemd/system/systemd-modules-load.service \
|
|
"$systemdsystemunitdir/systemd-modules-load.service"
|
|
|
|
# wrapper for sel-ebc.service
|
|
inst_simple "$moddir/pvebc-wrapper.sh" \
|
|
"/etc/sel-ebc/pvebc-wrapper.sh"
|
|
|
|
# override crypttab
|
|
inst_simple "$moddir/override-crypttab.sh" \
|
|
"/etc/sel-ebc/override-crypttab.sh"
|
|
|
|
# mount boot partition to /boot
|
|
inst_simple "$moddir/boot-mount.sh" \
|
|
"/etc/sel-ebc/boot-mount.sh"
|
|
|
|
# install kernel module dependencies
|
|
inst_simple "$moddir/sel-ebc-modules.conf" \
|
|
"/usr/lib/modules-load.d/sel-ebc-modules.conf"
|
|
|
|
# copy main application
|
|
inst_binary "/usr/bin/pvebc"
|
|
inst_binary "/usr/bin/pvsecret"
|
|
|
|
inst_simple "$moddir/sel-ebc.crypttab" "/etc/sel-ebc/crypttab"
|
|
|
|
# Create the enablement symlinks in the image using host systemctl:
|
|
# shellcheck disable=SC2154
|
|
inst_dir "$initdir/etc/systemd/system"
|
|
systemctl --root "$initdir" --no-reload --quiet enable sel-ebc.target
|
|
systemctl --root "$initdir" --no-reload --quiet enable sel-ebc-pvebc.service
|
|
systemctl --root "$initdir" --no-reload --quiet enable sel-ebc-override-crypttab.service
|
|
systemctl --root "$initdir" --no-reload --quiet enable sel-ebc-paes-enforce.service
|
|
systemctl --root "$initdir" --no-reload --quiet enable systemd-modules-load.service
|
|
systemctl --root "$initdir" --no-reload --quiet enable sel-ebc-boot-mount.service
|
|
}
|