|
|
Subscribe / Log in / New account

vs. dm-verity

vs. dm-verity

Posted Jan 10, 2019 4:47 UTC (Thu) by thestinger (guest, #91827)
In reply to: vs. dm-verity by corbet
Parent article: A setback for fs-verity

fs-verity is used to implement ro.apk_verity.mode for the rw userdata partition. The OS itself is fully verified via dm-verity (system/vendor), hashes (boot/dtbo) and a signature (vbmeta). Those are all read-only at runtime, and updated by writing to the alternate partition set.


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds