3 ms·
Possibly a dumb question -- how can one perform kernel/firmware updates if root is "locked out"?
by lwb 6y ago
Possibly a dumb question -- how can one perform kernel/firmware updates if root is "locked out"?
- Ao7bei3s 6y agoThe integrity mode applies to the running kernel in RAM. You generally don't actually upgrade that, instead you replace the kernel image on disk (vmlinuz), which is still possible. On next boot, the new image will be loaded. But if you have trusted boot enabled, the new image will only be booted if it is appropriately signed. Live patching still works if the updates are signed. The kernel can still do whatever - with integrity enabled it just refuses to do certain things, such as loading kernel modules or updates that aren't signed.
- lwb 6y agoGreat explanation, thanks!