heads/initrd/bin
Kyle Rankin c99d5a8437
Add red background to boot console for insecure "force" boot
In the event a user does pick the insecure "force" boot option that
bypasses checksum and signing checks in Heads, it would be nice to
provide a clear visual warning during the boot process that they are in
this state. This change will add a kernel argument that changes the boot
console background to be red and removes any boot splash that might
obscure it, in the event the user picks the insecure boot mode.

Since a user should only boot into this mode during emergencies, having
it be apparent that it's an unsafe mode helps ensure the user doesn't
pick this boot option needlessly.
2018-04-11 16:09:46 -07:00
..
flashrom-kgpe-d16-openbmc.sh Board, linux and coreboot configs 2018-03-01 00:40:46 -05:00
flashrom-kgpe-d16.sh Board, linux and coreboot configs 2018-03-01 00:40:46 -05:00
flashrom-x230.sh copy file and compute sha256 before flashing 2017-04-12 06:50:18 -04:00
generic-init Ensure recovery for failed default boot 2017-09-02 14:13:29 -04:00
gpgv Enable gpg with card support (issue #32) 2017-04-05 17:59:49 -04:00
gui-init Add GUI package update handler w/ checksum update function 2018-04-03 15:20:34 -07:00
kexec-boot Moved network init to a separate bootscript 2018-03-10 15:40:07 -08:00
kexec-insert-key Allow boot without unseal of TPM LUKS key 2017-09-02 14:13:29 -04:00
kexec-iso-init Strip invalid leading/trailing '/' from script params 2017-09-02 14:13:29 -04:00
kexec-parse-boot Strip invalid leading/trailing '/' from script params 2017-09-02 14:13:29 -04:00
kexec-save-default Cleanup of init to support server and desktop 2018-02-25 11:51:19 -08:00
kexec-save-key Allow TPM LUKS key to be set during default selection 2017-09-02 14:13:29 -04:00
kexec-seal-key remove trailing / on the /boot device parameter 2017-07-17 12:43:14 -04:00
kexec-select-boot Add red background to boot console for insecure "force" boot 2018-04-11 16:09:46 -07:00
kexec-sign-config Add OHCI and UHCI drivers to initrd. 2018-02-15 22:59:22 +08:00
kexec-unseal-key Allow boot without unseal of TPM LUKS key 2017-09-02 14:13:29 -04:00
mount-usb Cleanup of init to support server and desktop 2018-02-25 11:51:19 -08:00
network-init-recovery Moved network init to a separate bootscript 2018-03-10 15:40:07 -08:00
poweroff Ensure recovery for failed default boot 2017-09-02 14:13:29 -04:00
qubes-measure-luks qubes init script and improved TPM disk encryption with LUKS headers (issue #123 and #6) 2017-04-01 23:02:00 -04:00
reboot Ensure recovery for failed default boot 2017-09-02 14:13:29 -04:00
seal-totp import the seal/unseal totp scripts since they are very specialized to the heads install, skip owner password if not required (issue #151) 2017-04-12 06:49:39 -04:00
tpm-reset helper to do a forcible TPM reset (issue #27) 2017-04-12 06:45:15 -04:00
unseal-totp print and update the timestamp on the TOTP while waiting for disk unlock code 2017-04-12 08:28:31 -04:00
usb-init Cleanup of init to support server and desktop 2018-02-25 11:51:19 -08:00
usb-scan Allow TPM LUKS key to be set during default selection 2017-09-02 14:13:29 -04:00
wget-measure.sh wget and measure files into the PCR 2017-03-27 18:03:29 -04:00
x230-flash.init load usb-storage module in x230-flash.init 2017-04-16 17:37:14 -04:00