initramfs: Enforce --panic-on-corruption for veritysetup

Let's enforce an error on veritysetup in case there's any tampering with
the rootfs.

Signed-off-by: Fabiano Fidêncio <fidencio@northflank.com>
This commit is contained in:
Fabiano Fidêncio
2025-08-22 20:42:07 +02:00
committed by Fabiano Fidêncio
parent bdd98ec623
commit 8f948e28dd

View File

@@ -48,7 +48,7 @@ then
exit 1
fi
veritysetup open "${root_device}" root "${hash_device}" "${rootfs_hash}"
veritysetup open --panic-on-corruption "${root_device}" root "${hash_device}" "${rootfs_hash}"
mount /dev/mapper/root /mnt
else
echo "No LUKS device found"