3 <!DOCTYPE refentry PUBLIC
"-//OASIS//DTD DocBook XML V4.5//EN"
4 "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd">
5 <!-- SPDX-License-Identifier: LGPL-2.1-or-later -->
6 <refentry id=
"systemd-veritysetup_.service" conditional='HAVE_LIBCRYPTSETUP'
7 xmlns:
xi=
"http://www.w3.org/2001/XInclude">
10 <title>systemd-veritysetup@.service
</title>
11 <productname>systemd
</productname>
15 <refentrytitle>systemd-veritysetup@.service
</refentrytitle>
16 <manvolnum>8</manvolnum>
20 <refname>systemd-veritysetup@.service
</refname>
21 <refname>systemd-veritysetup
</refname>
22 <refpurpose>Disk verity protection logic
</refpurpose>
26 <para><filename>systemd-veritysetup@.service
</filename></para>
27 <para><filename>/usr/lib/systemd/systemd-veritysetup
</filename></para>
31 <title>Description
</title>
33 <para><filename>systemd-veritysetup@.service
</filename> is a service responsible for setting up verity
34 protection block devices. It should be instantiated for each device that requires verity
37 <para>At early boot and when the system manager configuration is reloaded kernel command line configuration for
38 verity protected block devices is translated into
<filename>systemd-veritysetup@.service
</filename> units by
39 <citerefentry><refentrytitle>systemd-veritysetup-generator
</refentrytitle><manvolnum>8</manvolnum></citerefentry>.
</para>
41 <para><filename>systemd-veritysetup@.service
</filename> calls
<command>systemd-veritysetup
</command>.
</para>
45 <title>Commands
</title>
47 <para>The following commands are understood by
<command>systemd-veritysetup
</command>:
</para>
52 <option>attach
</option>
53 <replaceable>volume
</replaceable>
54 <replaceable>datadevice
</replaceable>
55 <replaceable>hashdevice
</replaceable>
56 <replaceable>roothash
</replaceable>
57 [
<replaceable>option
</replaceable>...]
60 <listitem><para>Create a block device
<replaceable>volume
</replaceable> using
61 <replaceable>datadevice
</replaceable> and
<replaceable>hashdevice
</replaceable> as the backing
62 devices.
<replaceable>roothash
</replaceable> forms the root of the tree of hashes stored on
63 <replaceable>hashdevice
</replaceable>. See
64 <ulink url=
"https://docs.kernel.org/admin-guide/device-mapper/verity.html">
65 Kernel dm-verity
</ulink> documentation for details.
68 <xi:include href=
"version-info.xml" xpointer=
"v250"/></listitem>
73 <option>detach
</option>
74 <replaceable>volume
</replaceable>
77 <listitem><para>Detach (destroy) the block device
78 <replaceable>volume
</replaceable>.
</para>
80 <xi:include href=
"version-info.xml" xpointer=
"v250"/></listitem>
88 <listitem><para>Print short information about command syntax.
</para>
90 <xi:include href=
"version-info.xml" xpointer=
"v250"/></listitem>
96 <title>See Also
</title>
97 <para><simplelist type=
"inline">
98 <member><citerefentry><refentrytitle>systemd
</refentrytitle><manvolnum>1</manvolnum></citerefentry></member>
99 <member><citerefentry><refentrytitle>systemd-veritysetup-generator
</refentrytitle><manvolnum>8</manvolnum></citerefentry></member>
100 <member><citerefentry project='die-net'
><refentrytitle>veritysetup
</refentrytitle><manvolnum>8</manvolnum></citerefentry></member>