3 ms·
The integrity mode applies to the running kernel in RAM. You generally don't actually upgrade that, instead you replace the kernel image on disk (vmlinuz), whic
by Ao7bei3s 6y ago
The integrity mode applies to the running kernel in RAM. You generally don't actually upgrade that, instead you replace the kernel image on disk (vmlinuz), which is still possible. On next boot, the new image will be loaded. But if you have trusted boot enabled, the new image will only be booted if it is appropriately signed.
Live patching still works if the updates are signed. The kernel can still do whatever - with integrity enabled it just refuses to do certain things, such as loading kernel modules or updates that aren't signed.
- lwb 6y agoGreat explanation, thanks!