mirror of
https://github.com/morgan9e/systemd
synced 2026-04-15 00:47:10 +09:00
update TODO
This commit is contained in:
12
TODO
12
TODO
@@ -143,10 +143,17 @@ Features:
|
||||
waits and then reboots. Then use OnFailure=bsod.target from various jobs that
|
||||
should result in system reboots, such as TPM tamper detection cases.
|
||||
|
||||
* honour validatefs xattrs in dissect-image.c too
|
||||
|
||||
* pcrextend: maybe add option to disable measurements entirely via kernel cmdline
|
||||
|
||||
* tpm2-setup: reboot if we detect SRK changed
|
||||
|
||||
* validatefs: validate more things: check if image id + os id of initrd match
|
||||
target mount, so that we refuse early any attempts to boot into different
|
||||
images with the wrong kernels. check min/max kernel version too. all encoded
|
||||
via xattrs in the target fs.
|
||||
|
||||
* pcrextend: when we fail to measure, reboot the system (at least optionally).
|
||||
important because certain measurements are supposed to "destroy" tpm object
|
||||
access.
|
||||
@@ -157,11 +164,6 @@ Features:
|
||||
|
||||
* cryptsetup: add boolean for disabling use of any password/recovery key slots.
|
||||
|
||||
* dissect: when mounting a file system, look into certain xattrs on / in them, and
|
||||
if that exists, check if gpt partition flags + type uuid + uuid match the
|
||||
data encoded therein, so that attackers cannot make us misuse our file
|
||||
systems
|
||||
|
||||
* complete varlink introspection comments:
|
||||
- io.systemd.BootControl
|
||||
- io.systemd.Hostname
|
||||
|
||||
Reference in New Issue
Block a user