Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-16952

systemd-stub: support signed extensions (UKI addons)

    • Icon: Story Story
    • Resolution: Done-Errata
    • Icon: Major Major
    • rhel-9.4
    • rhel-9.4
    • systemd
    • systemd-252-31.el9_4
    • None
    • rhel-sst-cs-plumbers
    • ssg_core_services
    • 28
    • 5
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • Approved Exception
    • None

      What were you trying to do that didn't work?

      Downstream systemd-stub is v252. Starting from v253, "addons" were introduced to be able to extend UKI command line securely.

      The main patch is 05c9f9c251 stub: allow loading and verifying cmdline addons. But also all the other following are required.

      Steps to reproduce

      2 ways to check if systemd-stub is updated:

      1) just install the rpm

      1. sudo dnf install -y systemd-boot
      2. check that /usr/lib/systemd/boot/efi/addonx64.efi.stub exists

      2) create an addon (requires ukify https://issues.redhat.com/browse/RHEL-13199)

       

              msekleta@redhat.com Michal Sekletar
              eesposit@redhat.com Emanuele Giuseppe Esposito
              systemd maint mailing list systemd maint mailing list
              Frantisek Sumsal Frantisek Sumsal
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated:
                Resolved: