[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <20230914112739.112729-3-alessandro.carminati@gmail.com>
Date: Thu, 14 Sep 2023 11:27:39 +0000
From: "Alessandro Carminati (Red Hat)" <alessandro.carminati@...il.com>
To: linux-modules@...r.kernel.org
Cc: linux-kernel@...r.kernel.org, Luis Chamberlain <mcgrof@...nel.org>,
Jonathan Corbet <corbet@....net>, linux-doc@...r.kernel.org,
Alessandro Carminati <alessandro.carminati@...il.com>
Subject: [RFC PATCH 2/2] docs: Update kernel-parameters.txt for signature verification enhancement
Update kernel-parameters.txt to reflect new deferred signature
verification.
Enhances boot speed by allowing unsigned modules in initrd after
bootloader check.
Signed-off-by: Alessandro Carminati (Red Hat) <alessandro.carminati@...il.com>
---
Documentation/admin-guide/kernel-parameters.txt | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/Documentation/admin-guide/kernel-parameters.txt b/Documentation/admin-guide/kernel-parameters.txt
index 0c38a8af95ce..beec86f0dd05 100644
--- a/Documentation/admin-guide/kernel-parameters.txt
+++ b/Documentation/admin-guide/kernel-parameters.txt
@@ -3410,6 +3410,15 @@
Note that if CONFIG_MODULE_SIG_FORCE is set, that
is always true, so this option does nothing.
+ module_sig_check_wait=
+ This parameter enables delayed activation of module
+ signature checks, deferring the process until userspace
+ triggers it. Once activated, this setting becomes
+ permanent and cannot be reversed. This feature proves
+ valuable for incorporating unsigned modules within
+ initrd, especially after bootloader verification.
+ By employing this option, boot times can be quicker.
+
module_blacklist= [KNL] Do not load a comma-separated list of
modules. Useful for debugging problem modules.
--
2.34.1
Powered by blists - more mailing lists