initramfs: Enforce --panic-on-corruption for veritysetup

Let's enforce an error on veritysetup in case there's any tampering with
the rootfs.

Signed-off-by: Fabiano Fidêncio <fidencio@northflank.com>
This commit is contained in:
Fabiano Fidêncio
2025-08-22 20:42:07 +02:00
committed by Fabiano Fidêncio
parent bc75f6a158
commit d056fb20fe

View File

@@ -48,7 +48,7 @@ then
exit 1 exit 1
fi fi
veritysetup open "${root_device}" root "${hash_device}" "${rootfs_hash}" veritysetup open --panic-on-corruption "${root_device}" root "${hash_device}" "${rootfs_hash}"
mount /dev/mapper/root /mnt mount /dev/mapper/root /mnt
else else
echo "No LUKS device found" echo "No LUKS device found"