units: Order pcrlock services after systemd-remounts-fs.service

These write to /var and as such need to wait until after the rootfs
has been remounted read-write.
This commit is contained in:
Daan De Meyer 2024-01-26 11:29:35 +01:00 committed by Luca Boccassi
parent 678bd12cfc
commit 09e6921758
7 changed files with 7 additions and 2 deletions

View file

@ -13,6 +13,7 @@ Documentation=man:systemd-pcrlock(8)
DefaultDependencies=no
Conflicts=shutdown.target
Before=sysinit.target shutdown.target systemd-pcrlock-make-policy.service
After=systemd-remount-fs.service var.mount
ConditionPathExists=!/etc/initrd-release
ConditionSecurity=measured-uki

View file

@ -12,7 +12,7 @@ Description=Lock Firmware Code to TPM2 PCR Policy
Documentation=man:systemd-pcrlock(8)
DefaultDependencies=no
Conflicts=shutdown.target
After=systemd-tpm2-setup.service
After=systemd-tpm2-setup.service systemd-remount-fs.service var.mount
Before=sysinit.target shutdown.target systemd-pcrlock-make-policy.service
ConditionPathExists=!/etc/initrd-release
ConditionSecurity=measured-uki

View file

@ -12,7 +12,7 @@ Description=Lock Firmware Configuration to TPM2 PCR Policy
Documentation=man:systemd-pcrlock(8)
DefaultDependencies=no
Conflicts=shutdown.target
After=systemd-tpm2-setup.service
After=systemd-tpm2-setup.service systemd-remount-fs.service var.mount
Before=sysinit.target shutdown.target systemd-pcrlock-make-policy.service
ConditionPathExists=!/etc/initrd-release
ConditionSecurity=measured-uki

View file

@ -13,6 +13,7 @@ Documentation=man:systemd-pcrlock(8)
DefaultDependencies=no
Conflicts=shutdown.target
Before=sysinit.target shutdown.target systemd-pcrlock-make-policy.service
After=systemd-remount-fs.service var.mount
ConditionPathExists=!/etc/initrd-release
ConditionSecurity=measured-uki

View file

@ -14,6 +14,7 @@ DefaultDependencies=no
Conflicts=shutdown.target
After=systemd-tpm2-setup.service
Before=sysinit.target shutdown.target
After=systemd-remount-fs.service var.mount
ConditionPathExists=!/etc/initrd-release
ConditionSecurity=measured-uki

View file

@ -14,6 +14,7 @@ DefaultDependencies=no
Conflicts=shutdown.target
After=systemd-tpm2-setup.service
Before=sysinit.target shutdown.target systemd-pcrlock-make-policy.service
After=systemd-remount-fs.service var.mount
ConditionPathExists=!/etc/initrd-release
ConditionSecurity=measured-uki

View file

@ -14,6 +14,7 @@ DefaultDependencies=no
Conflicts=shutdown.target
After=systemd-tpm2-setup.service
Before=sysinit.target shutdown.target systemd-pcrlock-make-policy.service
After=systemd-remount-fs.service var.mount
ConditionPathExists=!/etc/initrd-release
ConditionSecurity=measured-uki