From 3bac245049d0fbe39d8536e16a0dc5655a62f04d Mon Sep 17 00:00:00 2001 From: Luca Boccassi Date: Thu, 16 Oct 2025 14:59:04 +0100 Subject: [PATCH] mkosi: provide detached verity signatures too for minimal images Useful for manual testing in the VM (cherry picked from commit 39175477bd6e094542671599e0e258daa6351115) --- mkosi/mkosi.postinst.chroot | 1 + 1 file changed, 1 insertion(+) diff --git a/mkosi/mkosi.postinst.chroot b/mkosi/mkosi.postinst.chroot index 32d2ad00f6f..2251f008508 100755 --- a/mkosi/mkosi.postinst.chroot +++ b/mkosi/mkosi.postinst.chroot @@ -28,6 +28,7 @@ rm -f /etc/resolv.conf for f in "$BUILDROOT"/usr/share/*.verity.sig; do jq --join-output '.rootHash' "$f" >"${f%.verity.sig}.roothash" + jq --join-output '.signature' "$f" | base64 --decode >"${f%.verity.sig}.roothash.p7s" done # We want /var/log/journal to be created on first boot so it can be created with the right chattr settings by -- 2.47.3