SYSTEMD-STUB(7) systemd-stub SYSTEMD-STUB(7) systemd-stub, sd-stub, linuxx64.efi.stub, linuxia32.efi.stub, linuxaa64.efi.stub - UEFI /usr/lib/systemd/boot/efi/linuxx64.efi.stub /usr/lib/systemd/boot/efi/linuxia32.efi.stub /usr/lib/systemd/boot/efi/linuxaa64.efi.stub ESP/.../foo.efi.extra.d/*.addon.efi ESP/.../foo.efi.extra.d/*.cred ESP/.../foo.efi.extra.d/*.raw ESP/.../foo.efi.extra.d/*.sysext.raw ESP/.../foo.efi.extra.d/*.confext.raw ESP/loader/addons/*.addon.efi ESP/loader/credentials/*.cred ESP/loader/extensions/*.raw ESP/loader/extensions/*.sysext.raw ESP/loader/extensions/*.confext.raw systemd-stub ( linuxx64.efi.stub, linuxia32.efi.stub, linuxaa64.efi.stub ) UEFI . UEFI UEFI . UEFI UEFI . UEFI PE UEFI . PE (" " "UKI" ) UEFI SecureBoot . PE : o ".linux" ELF. . o ".osrel" os-release(5) . o ".cmdline" . o ".initrd" initrd. o ".ucode" initrd initrd . initrd . o ".splash" ( Windows .BMP) . o ".dtb" DeviceTree . o ".dtbauto". systemd-stub . "" DeviceTree "" ".dtbauto". DeviceTree ".hwids" . ".hwids" ( ) "" . ".dtbauto" ".dtb" . o ".efifw" . ".dtbauto". systemd-stub . ".hwids" SMBIOS ( ). "fwid" ".efifw". . o ".hwids" DeviceTrees. systemd-stub SMBIOS ( [1]) ".hwids". . o ".uname" uname -r ".linux". o ".sbat" SBAT[2]. o ".pcrsig" TPM2 PCR JSON. TPM2 . o ".pcrpkey" PEM ".pcrsig". UKI ".dtbauto" ".hwids". UKI " " . PE ".profile" . ".profile" ".osrel". UKIs . UEFI SecureBoot ".cmdline" EFI. UEFI SecureBoot PE . EFI EFI TPM PCR 12 ( TPM ). DeviceTree ".dtb" DeviceTree EFI . systemd-stub "EFI_DT_FIXUP_PROTOCOL" DeviceTree. 11 12 TPM PCR 11. . ".pcrsig" PCR . UKI PE ( ). PCR 12. ".pcrsig" / ".pcrpkey" initrd /.extra/tpm2-pcr-signature.json /.extra/tpm2-pcr-public-key.pem. tmpfiles.d(5) /run/systemd/tpm2-pcr-signature.json /run/systemd/tpm2-pcr-public-key.pem initrd . systemd-cryptsetup@.service(8) systemd-cryptenroll(1) systemd-creds(1) ( ) . UKI UAPI.5 UKI[3]. systemd-stub UEFI boot stub EFI cpio initrd . : o foo.efi .cred foo.efi.extra.d/ . [4] . foo+3-0.efi foo.efi.extra.d/. cpio /.extra/credentials/ initrd. initrd . LoadCredentialEncrypted UEFI. systemd.exec(5) systemd-creds(1) . cpio TPM PCR 12 ( TPM ). o foo.efi.extra.d/*.sysext.raw cpio /.extra/sysext/ initrd. UKI initrd. systemd-sysext(8) . cpio TPM PCR 13 ( TPM ). o /loader/extensions/*.sysext.raw cpio /.extra/global_sysext/ initrd. initrd. systemd-sysext(8) . cpio TPM PCR 13 ( TPM ). o foo.efi.extra.d/*.confext.raw cpio /.extra/confext/ initrd. UKI initrd. systemd-confext(8) . cpio TPM PCR 12 ( TPM ). o /loader/extensions/*.confext.raw cpio /.extra/global_confext/ initrd. initrd. systemd-confext(8) . cpio TPM PCR 12 ( TPM ). o foo.efi.extra.d/*.addon.efi PE . ( ".cmdline") DeviceTree ( ".dtb") initrds ( ".initrd") ( ".ucode"). . UEFI DB DB Shim MOK Shim . UKI ".uname" . ".sbat" SBAT DBX/MOKX. ukify(1) SBAT . SBAT Shim[2]. TPM PCR 12 ( TPM ) . UKI /loader/addons/*.addon.efi UKI. Device tree . ( UKI UKI). . PCR12. PE ESP . PCR12 . o /loader/credentials/*.cred cpio /.extra/global_credentials/ initrd. initrd . cpio TPM PCR 12 ( TPM ). o /loader/addons/*.addon.efi PE ".cmdline" ".dtb" ".initrd" ".ucode" . DeviceTree initrds . initrd ( ) : PCR TPM. : / TPM systemd-creds encrypt -T ( systemd-creds(1) ) Verity . UKIS UKI ( " ") . UKI : " " ( systemd-storagetm.service(8)). ".linux" ".initrd" ".cmdline" . "systemd.unit=factory-reset.target" "rd.systemd.unit=storagetm.target". UKI PE ".profile". PE . PE ".profile" UKI PE ".profile" ".profile" ".profile". ".profile" "" UKI. ".profile" . PE ".profile" . : . UKI ".profile" ".profile" "@0". UKI : Table 1. Multi-Profile UKI Example +-----------+--------------------------+ |Section | Profile | +-----------+--------------------------+ |".linux" | Base profile | +-----------+ | |".osrel" | | +-----------+ | |".cmdline" | | +-----------+ | |".initrd" | | +-----------+--------------------------+ |".profile" | | | | | | | @0 | +-----------+--------------------------+ |".profile" | | | | | | | @1 | +-----------+ | |".cmdline" | | +-----------+--------------------------+ |".profile" | | | | | | | @2 | +-----------+ | |".cmdline" | | +-----------+--------------------------+ . . ".profile" @0. ( ) ".profile" @1. . @2 . ( ".cmdline" ".profile" . 0 .) UKI : "@" . UKI 0. ".profile" . ".osrel" ( ). : "ID=" ( "ID=factory-reset"). "TITLE=" ( "TITLE='Factory Reset this Device'"). TPM PCR systemd-stub TPM PCR 4 initrd ( ) UKI . systemd-stub PE (VirtualSize) (SizeOfRawData). systemd-stub . systemd-stub . ukify UKIs . initrds TPM PCR 9. initrd ( UKI ) : initrds PCR 4 PCR 9 PCR 11 initrd ( ) PCR 9 PCR 12 initrd PCR 4 PCR 9. PCRs : 2. PCR +-------------------------------+------------------------+ | | PCR | | | | +-------------------------------+------------------------+ | systemd-stub | 4 | |( | | | | | | PE | | |) | | +-------------------------------+------------------------+ | | 4 + 11 | | | | |( | | | PE | | |) | | +-------------------------------+------------------------+ | | 4 + 11 | | | | | | | |( | | | PE | | |) | | +-------------------------------+------------------------+ |initrd | 4 + 9 + 11 | |( | | | PE | | |) | | +-------------------------------+------------------------+ |initrd | 4 + 9 + 11 | | | | | | | |( | | | PE | | |) | | +-------------------------------+------------------------+ | | 4 + 11 | | | | | | | |( | | | PE | | |) | | +-------------------------------+------------------------+ | | 12 | | | | | | | +-------------------------------+------------------------+ | | 4 + 11 | | | | |( | | | PE | | |) | | +-------------------------------+------------------------+ | TPM2 PCR | 4 + 9 | | JSON | | |( | | | PE | | | | | | | | |initrd) | | +-------------------------------+------------------------+ | TPM2 PCR | 4 + 9 + 11 | | | | | PEM | | |( | | | PE | | | | | | | | |initrd) | | +-------------------------------+------------------------+ | | 9 + 12 | | | | |(initrd | | | | | |) | | +-------------------------------+------------------------+ | | 9 + 13 | | (initrd | | | | | | | | |) | | +-------------------------------+------------------------+ | | 9 + 12 | | (initrd | | | | | | | | |) | | +-------------------------------+------------------------+ | | 12 | | | | | | | | | | | | | +-------------------------------+------------------------+ EFI EFI systemd-stub UUID "4a67b082-0a4c-41cf-b6c7-440b29bb8c4f" : LoaderDevicePartUUID UUID ( EFI). systemd-stub. UUID . systemd-gpt-auto-generator(8) . 224. LoaderFirmwareInfo LoaderFirmwareType . bootctl(1) . 250. LoaderTpm2ActivePcrBanks TCG EFI TPM 2.0 EFI_TCG2_BOOT_HASH_ALG_*. TPM2 0. . systemd-analyze(1) . 258. LoaderImageIdentifier EFI ( LoaderDevicePartUUID ). EFI . bootctl(1) . 237. StubDevicePartUUID StubImageIdentifier LoaderDevicePartUUID LoaderImageIdentifier EFI . 257. StubDeviceURL URL . . 258. StubInfo . bootctl(1) . 250. StubPcrKernelImage PCR initrd ASCII ( "11"). . 252. StubPcrKernelParameters PCR ASCII ( "12"). . 252. StubPcrInitRDSysExts PCR initrd . ASCII ( "13"). . 252. StubPcrInitRDConfExts PCR initrd . ASCII ( "12"). . 255. StubProfile "@" . UKIs . ( "0" .) 257. . . Boot Loader Interface[5]. INITRD cpio initrd initrd: / initrd PE ".initrd" . 252. /.extra/credentials/*.cred ( ".cred") ( ) /.extra/credentials/ initrd. 252. /.extra/global_credentials/*.cred /loader/credentials/ /.extra/global_credentials/ initrd. 252. /.extra/sysext/*.sysext.raw ( ".sysext.raw") ( ) /.extra/sysext/ initrd. 252. /.extra/global_sysext/*.sysext.raw ( ".sysext.raw") /loader/extensions/ /.extra/global_sysext/ initrd. 258. /.extra/confext/*.confext.raw ( ".confext.raw") ( ) /.extra/confext/ initrd. 255. /.extra/global_confext/*.confext.raw ( ".confext.raw") /loader/extensions/ /.extra/global_confext/ initrd. 258. /.extra/tpm2-pcr-signature.json JSON TPM2 PCR PE ".pcrsig" /.extra/tpm2-pcr-signature.json initrd. 252. /.extra/tpm2-pcr-public-key.pem PEM PE ".pcrpkey" /.extra/tpm2-pcr-public-key.pem initrd. 252. /\&.extra/profile /\&.extra/os-release ".profile" ".osrel" . 257. "tmpfs" initrd initrd . tmpfiles.d(5) . TPM2 PCR . SMBIOS 11 systemd-stub SMBIOS 11. "=" . systemd-stub systemd-stub . : io.systemd.stub.kernel-cmdline-extra PCR12 . 254. io.systemd.boot.loglevel . ( ) "emerg" "alert" "crit" "err" "warning" "notice" "info" "debug". 261. ukify(1). systemd-boot(7) systemd.exec(5) systemd-creds(1) systemd-sysext(8) UAPI.1 Boot Loader Specification[6] Boot Loader Interface[5] ukify(1) systemd-measure(1) TPM2 PCR Measurements Made by systemd[7] 1. https://learn.microsoft.com/en-us/windows-hardware/drivers/install/specifying-hardware-ids-for-a-computer 2. SBAT https://github.com/rhboot/shim/blob/main/SBAT.md 3. UAPI.5 UKI https://uapi-group.org/specifications/specs/unified_kernel_image/ 4. https://systemd.io/AUTOMATIC_BOOT_ASSESSMENT 5. https://systemd.io/BOOT_LOADER_INTERFACE 6. UAPI.1 https://uapi-group.org/specifications/specs/boot_loader_specification 7. TPM2 PCR systemd https://systemd.io/TPM2_PCR_MEASUREMENTS 3 . . : . systemd 260.2 SYSTEMD-STUB(7)