* Sat Oct 25 2025 CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com> [5.14.0-630.el9]
- crypto: xts - Handle EBUSY correctly (CKI Backport Bot) [RHEL-119237] {CVE-2023-53494}
- xfrm: use kfree_sensitive() for SA secret zeroization (Sabrina Dubroca) [RHEL-115629]
- espintcp: remove encap socket caching to avoid reference leak (Sabrina Dubroca) [RHEL-115629]
- espintcp: fix skb leaks (Sabrina Dubroca) [RHEL-115629]
- ext4: goto right label 'out_mmap_sem' in ext4_setattr() (Brian Foster) [RHEL-109217]
- mm: zero range of eof folio exposed by inode size extension (Brian Foster) [RHEL-109217]
- mm: convert pagecache_isize_extended to use a folio (Brian Foster) [RHEL-109217]
- ext4: partial zero eof block on unaligned inode size extension (Brian Foster) [RHEL-109217]
- ext4: do not mark inode dirty every time when appending using delalloc (Brian Foster) [RHEL-109217]
- uki-virt: add systemd-repart module (Emanuele Giuseppe Esposito) [RHEL-107273]
Resolves: RHEL-107273, RHEL-109217, RHEL-115629, RHEL-119237
Signed-off-by: CKI KWF Bot <cki-ci-bot+kwf-gitlab-com@redhat.com>
49 lines
1.3 KiB
Plaintext
49 lines
1.3 KiB
Plaintext
# generic + compressed please
|
|
hostonly="no"
|
|
compress="xz"
|
|
|
|
# VMs can't update microcode anyway
|
|
early_microcode="no"
|
|
|
|
# modules: basics
|
|
dracutmodules+=" base systemd systemd-initrd dracut-systemd dbus dbus-broker usrmount shutdown "
|
|
|
|
# modules: storage support
|
|
dracutmodules+=" dm lvm rootfs-block fs-lib "
|
|
|
|
# modules: tpm and crypto
|
|
dracutmodules+=" crypt crypt-loop tpm2-tss systemd-pcrphase "
|
|
|
|
# modules: root disk integrity protection
|
|
dracutmodules+=" systemd-veritysetup "
|
|
|
|
# modules: root creation and encryption
|
|
dracutmodules+=" systemd-repart "
|
|
# FIXME: remove this once RHEL-103385 is merged
|
|
install_items+=" /usr/sbin/mkfs.vfat /usr/sbin/mkfs.ext4 /usr/sbin/mkfs.xfs "
|
|
|
|
# modules: FIPS
|
|
dracutmodules+=" fips "
|
|
# FIPS mode requires early crypto drivers test
|
|
drivers+=" =crypto "
|
|
|
|
# drivers: virtual buses, pci
|
|
drivers+=" virtio-pci virtio-mmio " # qemu-kvm
|
|
drivers+=" hv-vmbus pci-hyperv " # hyperv
|
|
drivers+=" xen-pcifront " # xen
|
|
|
|
# drivers: storage
|
|
drivers+=" ahci nvme sd_mod sr_mod " # generic
|
|
drivers+=" virtio-blk virtio-scsi " # qemu-kvm
|
|
drivers+=" hv-storvsc " # hyperv
|
|
drivers+=" xen-blkfront " # xen
|
|
|
|
# root encryption
|
|
drivers+=" dm_crypt "
|
|
|
|
# root disk integrity protection
|
|
drivers+=" dm_verity overlay "
|
|
|
|
# filesystems
|
|
filesystems+=" vfat ext4 xfs overlay "
|