Fedora 40 is set to implement the second stage of universal kernel image deployment.

In the Fedora Linux 40 release, the second stage of transitioning to a modernized boot process proposed by Lennart Poettering is planned. The differences from the classic boot process involve using a unified kernel image (UKI), generated in the distribution's infrastructure and signed with the distribution's digital signature, instead of the initrd image created on the local system when installing the kernel package. This proposal has not yet been reviewed by the FESCo (Fedora Engineering Steering Committee), which is responsible for the technical aspects of Fedora distribution development.

The UKI image combines a handler for booting the kernel from UEFI (UEFI boot stub), the Linux kernel image, and the initrd system environment loaded into memory, all in one file. When the UKI image is called from UEFI, it allows integrity and authenticity checks via digital signatures, not only for the kernel but also for the initrd content, which is crucial as key extraction for decrypting the root filesystem occurs in this environment.

The first stage of UKI implementation was completed in Fedora Linux 38, resulting in the addition of UKI support in the bootloader, the establishment of tools for installing and updating UKI, and the creation of an experimental UKI image for booting. of virtual machines with a limited set of components and drivers.

In the second stage, it is planned to add the ability to boot UKI directly from the UEFI module shim.efi without involving a separate bootloader (grub, sd-boot), implement UKI usage on Aarch64 architecture systems, and prepare a variant of the UKI image for cloud environments and secure virtual machines.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster