Open yockgen opened 1 week ago
Hi @yockgen, would UKI addons be something you are looking for?
https://uapi-group.org/specifications/specs/unified_kernel_image/#pe-addons
Thanks @trungams , Yes, PE addon is one of possible solutions, however, there is a rigid security requirement for my project that if the PE addon EFI could be copied and pasted to other UKIs in the device to overwrite the cmdline, according to my understanding, this is possible. What is your suggestion on this?
My Mariner OS is built with following features:
1, Unified Kernel Image (kernel+initrd+cmdline)
Systemd-boot config files looks like below
With Secure Boot enabled, the /proc/cmdline is no longer overwritten by the systemd-boot configuration. The cmdline is shown those params during UKI built time.
Runtime logs as below:
I couldn't hardcode the 'yockgen' parameter during the build process, as its value depends on the runtime environment. This value needs to be assessed by a custom Dracut module during the initrd stage to mount specific devices.
What could be the possible solution for this?
Thanks a lot of any guidance!