This repository was archived by the owner on Sep 5, 2024. It is now read-only.

Latest commit

History

10 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

signmodules (archived)

Warning This repository is archived in GitHub and will no longer be maintained here. This repository lives here now.

A shell script for signing kernel modules with a Machine Owner Key, for Fedora.

Background

In machines with Secure Boot installed, the bootloader, kernel, and all modules loaded by the kernel must be signed by either of the following:

  • A hardware manufacturer
  • A trusted Operating System vendor or provider

On Linux, a few distributions work with Secure Boot installed, as for example Fedora, Debian and Ubuntu. This means that they are trusted Operating System vendors, and hence the modules they ship as part of the distribution are signed by them and will work.

However, if you install any software from a third party, that requires to load a kernel module, you will have to sign it yourself.

This script works for Fedora and will:

  1. Sign all the modules passed as parameter, and all their dependencies, i.e., any other modules present in the same directory of the tree.
  2. Restart any systemd unit that is failed, bringing back the system to a running state if all failed units are so due to kernel modules that have not been loaded.

The script should be run after a reboot performed as a result of a kernel update, or own / third party modules updates.

Prerrequisites

Install

Clone this repository or download the script signmodules, and place it in the $PATH variable.

Invocation and Behaviour

The usage of the script is the following:

signmodules /path/to/MOK.priv /path/to/MOK.der MODULE_1 MODULE_2 ... MODULE_N
  • /path/to/MOK.priv: private part of the MOK (Machine Owner Key --the signing key)
  • /path/to/MOK.der: public part of the MOK.
  • MODULE_1 MODULE_2 ... MODULE_N: a list of modules' names that we want to sign, e.g.: vboxdrv v4l2loopback

The script will ask for the user password, as both signing modules and restarting systemd services are operations that must be run under sudo.

Invoked like the above, the script won't write any logs (unless in trouble). Add -v (verbose) before the list of modules to enable logs

Result Codes

The result codes are 0 if all operations were successful, or:

  • 1 if there were failures while signing modules,
  • 2 if there were failires while trying to restart systemd services,
  • 3 if both.

Example

An example invocation is the following, useful for signing all modules for Virtual Box and Video4Linux Loopback, and restarting the relevant systemd services, all in one go:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: [signmodules] Processing all modules for 'vboxdrv':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'
[signmodules] Processing all modules for 'v4l2loopback':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'
[signmodules] Restarting any failed services after processing modules:
[signmodules] Requested 'vboxdrv' restart with result 0
[signmodules] Requested 'systemd-modules-load' restart with result 0
[signmodules] Done. Exiting with code 0 --success.
$ echo $?
0

Without logs:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: $ echo $?
0

Automation of the script

To run the script in an automation and without user interaction, set up the environment variable KBUILD_SIGN_PIN with the passphrase of the private part of the Machine Owner Key, MOK.priv, and run the script as an privileged service / under a system user with elevated privileges.

Credits

This script is inspired by this Gist by Reilly Tucker Siemens, and taken further to sign any set of modules, plus fix any broken systemd service caused by unsigned modules.

About

A shell script for signing kernel modules with a Machine Owner Key, for Fedora

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
This repository was archived by the owner on Sep 5, 2024. It is now read-only.

Latest commit

History

10 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

signmodules (archived)

Warning This repository is archived in GitHub and will no longer be maintained here. This repository lives here now.

A shell script for signing kernel modules with a Machine Owner Key, for Fedora.

Background

In machines with Secure Boot installed, the bootloader, kernel, and all modules loaded by the kernel must be signed by either of the following:

  • A hardware manufacturer
  • A trusted Operating System vendor or provider

On Linux, a few distributions work with Secure Boot installed, as for example Fedora, Debian and Ubuntu. This means that they are trusted Operating System vendors, and hence the modules they ship as part of the distribution are signed by them and will work.

However, if you install any software from a third party, that requires to load a kernel module, you will have to sign it yourself.

This script works for Fedora and will:

  1. Sign all the modules passed as parameter, and all their dependencies, i.e., any other modules present in the same directory of the tree.
  2. Restart any systemd unit that is failed, bringing back the system to a running state if all failed units are so due to kernel modules that have not been loaded.

The script should be run after a reboot performed as a result of a kernel update, or own / third party modules updates.

Prerrequisites

Install

Clone this repository or download the script signmodules, and place it in the $PATH variable.

Invocation and Behaviour

The usage of the script is the following:

signmodules /path/to/MOK.priv /path/to/MOK.der MODULE_1 MODULE_2 ... MODULE_N
  • /path/to/MOK.priv: private part of the MOK (Machine Owner Key --the signing key)
  • /path/to/MOK.der: public part of the MOK.
  • MODULE_1 MODULE_2 ... MODULE_N: a list of modules' names that we want to sign, e.g.: vboxdrv v4l2loopback

The script will ask for the user password, as both signing modules and restarting systemd services are operations that must be run under sudo.

Invoked like the above, the script won't write any logs (unless in trouble). Add -v (verbose) before the list of modules to enable logs

Result Codes

The result codes are 0 if all operations were successful, or:

  • 1 if there were failures while signing modules,
  • 2 if there were failires while trying to restart systemd services,
  • 3 if both.

Example

An example invocation is the following, useful for signing all modules for Virtual Box and Video4Linux Loopback, and restarting the relevant systemd services, all in one go:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: [signmodules] Processing all modules for 'vboxdrv':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'
[signmodules] Processing all modules for 'v4l2loopback':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'
[signmodules] Restarting any failed services after processing modules:
[signmodules] Requested 'vboxdrv' restart with result 0
[signmodules] Requested 'systemd-modules-load' restart with result 0
[signmodules] Done. Exiting with code 0 --success.
$ echo $?
0

Without logs:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: $ echo $?
0

Automation of the script

To run the script in an automation and without user interaction, set up the environment variable KBUILD_SIGN_PIN with the passphrase of the private part of the Machine Owner Key, MOK.priv, and run the script as an privileged service / under a system user with elevated privileges.

Credits

This script is inspired by this Gist by Reilly Tucker Siemens, and taken further to sign any set of modules, plus fix any broken systemd service caused by unsigned modules.

About

A shell script for signing kernel modules with a Machine Owner Key, for Fedora

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Sep 5, 2024. It is now read-only.

Latest commit

History

10 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

signmodules (archived)

Warning This repository is archived in GitHub and will no longer be maintained here. This repository lives here now.

A shell script for signing kernel modules with a Machine Owner Key, for Fedora.

Background

In machines with Secure Boot installed, the bootloader, kernel, and all modules loaded by the kernel must be signed by either of the following:

  • A hardware manufacturer
  • A trusted Operating System vendor or provider

On Linux, a few distributions work with Secure Boot installed, as for example Fedora, Debian and Ubuntu. This means that they are trusted Operating System vendors, and hence the modules they ship as part of the distribution are signed by them and will work.

However, if you install any software from a third party, that requires to load a kernel module, you will have to sign it yourself.

This script works for Fedora and will:

  1. Sign all the modules passed as parameter, and all their dependencies, i.e., any other modules present in the same directory of the tree.
  2. Restart any systemd unit that is failed, bringing back the system to a running state if all failed units are so due to kernel modules that have not been loaded.

The script should be run after a reboot performed as a result of a kernel update, or own / third party modules updates.

Prerrequisites

Install

Clone this repository or download the script signmodules, and place it in the $PATH variable.

Invocation and Behaviour

The usage of the script is the following:

signmodules /path/to/MOK.priv /path/to/MOK.der MODULE_1 MODULE_2 ... MODULE_N
  • /path/to/MOK.priv: private part of the MOK (Machine Owner Key --the signing key)
  • /path/to/MOK.der: public part of the MOK.
  • MODULE_1 MODULE_2 ... MODULE_N: a list of modules' names that we want to sign, e.g.: vboxdrv v4l2loopback

The script will ask for the user password, as both signing modules and restarting systemd services are operations that must be run under sudo.

Invoked like the above, the script won't write any logs (unless in trouble). Add -v (verbose) before the list of modules to enable logs

Result Codes

The result codes are 0 if all operations were successful, or:

  • 1 if there were failures while signing modules,
  • 2 if there were failires while trying to restart systemd services,
  • 3 if both.

Example

An example invocation is the following, useful for signing all modules for Virtual Box and Video4Linux Loopback, and restarting the relevant systemd services, all in one go:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: [signmodules] Processing all modules for 'vboxdrv':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'
[signmodules] Processing all modules for 'v4l2loopback':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'
[signmodules] Restarting any failed services after processing modules:
[signmodules] Requested 'vboxdrv' restart with result 0
[signmodules] Requested 'systemd-modules-load' restart with result 0
[signmodules] Done. Exiting with code 0 --success.
$ echo $?
0

Without logs:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: $ echo $?
0

Automation of the script

To run the script in an automation and without user interaction, set up the environment variable KBUILD_SIGN_PIN with the passphrase of the private part of the Machine Owner Key, MOK.priv, and run the script as an privileged service / under a system user with elevated privileges.

Credits

This script is inspired by this Gist by Reilly Tucker Siemens, and taken further to sign any set of modules, plus fix any broken systemd service caused by unsigned modules.

About

A shell script for signing kernel modules with a Machine Owner Key, for Fedora

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Sep 5, 2024. It is now read-only.

Latest commit

History

10 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

signmodules (archived)

Warning This repository is archived in GitHub and will no longer be maintained here. This repository lives here now.

A shell script for signing kernel modules with a Machine Owner Key, for Fedora.

Background

In machines with Secure Boot installed, the bootloader, kernel, and all modules loaded by the kernel must be signed by either of the following:

  • A hardware manufacturer
  • A trusted Operating System vendor or provider

On Linux, a few distributions work with Secure Boot installed, as for example Fedora, Debian and Ubuntu. This means that they are trusted Operating System vendors, and hence the modules they ship as part of the distribution are signed by them and will work.

However, if you install any software from a third party, that requires to load a kernel module, you will have to sign it yourself.

This script works for Fedora and will:

  1. Sign all the modules passed as parameter, and all their dependencies, i.e., any other modules present in the same directory of the tree.
  2. Restart any systemd unit that is failed, bringing back the system to a running state if all failed units are so due to kernel modules that have not been loaded.

The script should be run after a reboot performed as a result of a kernel update, or own / third party modules updates.

Prerrequisites

Install

Clone this repository or download the script signmodules, and place it in the $PATH variable.

Invocation and Behaviour

The usage of the script is the following:

signmodules /path/to/MOK.priv /path/to/MOK.der MODULE_1 MODULE_2 ... MODULE_N
  • /path/to/MOK.priv: private part of the MOK (Machine Owner Key --the signing key)
  • /path/to/MOK.der: public part of the MOK.
  • MODULE_1 MODULE_2 ... MODULE_N: a list of modules' names that we want to sign, e.g.: vboxdrv v4l2loopback

The script will ask for the user password, as both signing modules and restarting systemd services are operations that must be run under sudo.

Invoked like the above, the script won't write any logs (unless in trouble). Add -v (verbose) before the list of modules to enable logs

Result Codes

The result codes are 0 if all operations were successful, or:

  • 1 if there were failures while signing modules,
  • 2 if there were failires while trying to restart systemd services,
  • 3 if both.

Example

An example invocation is the following, useful for signing all modules for Virtual Box and Video4Linux Loopback, and restarting the relevant systemd services, all in one go:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: [signmodules] Processing all modules for 'vboxdrv':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'
[signmodules] Processing all modules for 'v4l2loopback':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'
[signmodules] Restarting any failed services after processing modules:
[signmodules] Requested 'vboxdrv' restart with result 0
[signmodules] Requested 'systemd-modules-load' restart with result 0
[signmodules] Done. Exiting with code 0 --success.
$ echo $?
0

Without logs:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: $ echo $?
0

Automation of the script

To run the script in an automation and without user interaction, set up the environment variable KBUILD_SIGN_PIN with the passphrase of the private part of the Machine Owner Key, MOK.priv, and run the script as an privileged service / under a system user with elevated privileges.

Credits

This script is inspired by this Gist by Reilly Tucker Siemens, and taken further to sign any set of modules, plus fix any broken systemd service caused by unsigned modules.

About

A shell script for signing kernel modules with a Machine Owner Key, for Fedora

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
This repository was archived by the owner on Sep 5, 2024. It is now read-only.

Latest commit

History

10 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

signmodules (archived)

Warning This repository is archived in GitHub and will no longer be maintained here. This repository lives here now.

A shell script for signing kernel modules with a Machine Owner Key, for Fedora.

Background

In machines with Secure Boot installed, the bootloader, kernel, and all modules loaded by the kernel must be signed by either of the following:

  • A hardware manufacturer
  • A trusted Operating System vendor or provider

On Linux, a few distributions work with Secure Boot installed, as for example Fedora, Debian and Ubuntu. This means that they are trusted Operating System vendors, and hence the modules they ship as part of the distribution are signed by them and will work.

However, if you install any software from a third party, that requires to load a kernel module, you will have to sign it yourself.

This script works for Fedora and will:

  1. Sign all the modules passed as parameter, and all their dependencies, i.e., any other modules present in the same directory of the tree.
  2. Restart any systemd unit that is failed, bringing back the system to a running state if all failed units are so due to kernel modules that have not been loaded.

The script should be run after a reboot performed as a result of a kernel update, or own / third party modules updates.

Prerrequisites

Install

Clone this repository or download the script signmodules, and place it in the $PATH variable.

Invocation and Behaviour

The usage of the script is the following:

signmodules /path/to/MOK.priv /path/to/MOK.der MODULE_1 MODULE_2 ... MODULE_N
  • /path/to/MOK.priv: private part of the MOK (Machine Owner Key --the signing key)
  • /path/to/MOK.der: public part of the MOK.
  • MODULE_1 MODULE_2 ... MODULE_N: a list of modules' names that we want to sign, e.g.: vboxdrv v4l2loopback

The script will ask for the user password, as both signing modules and restarting systemd services are operations that must be run under sudo.

Invoked like the above, the script won't write any logs (unless in trouble). Add -v (verbose) before the list of modules to enable logs

Result Codes

The result codes are 0 if all operations were successful, or:

  • 1 if there were failures while signing modules,
  • 2 if there were failires while trying to restart systemd services,
  • 3 if both.

Example

An example invocation is the following, useful for signing all modules for Virtual Box and Video4Linux Loopback, and restarting the relevant systemd services, all in one go:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: [signmodules] Processing all modules for 'vboxdrv':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'
[signmodules] Processing all modules for 'v4l2loopback':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'
[signmodules] Restarting any failed services after processing modules:
[signmodules] Requested 'vboxdrv' restart with result 0
[signmodules] Requested 'systemd-modules-load' restart with result 0
[signmodules] Done. Exiting with code 0 --success.
$ echo $?
0

Without logs:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: $ echo $?
0

Automation of the script

To run the script in an automation and without user interaction, set up the environment variable KBUILD_SIGN_PIN with the passphrase of the private part of the Machine Owner Key, MOK.priv, and run the script as an privileged service / under a system user with elevated privileges.

Credits

This script is inspired by this Gist by Reilly Tucker Siemens, and taken further to sign any set of modules, plus fix any broken systemd service caused by unsigned modules.

About

A shell script for signing kernel modules with a Machine Owner Key, for Fedora

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Sep 5, 2024. It is now read-only.

Latest commit

History

10 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

signmodules (archived)

Warning This repository is archived in GitHub and will no longer be maintained here. This repository lives here now.

A shell script for signing kernel modules with a Machine Owner Key, for Fedora.

Background

In machines with Secure Boot installed, the bootloader, kernel, and all modules loaded by the kernel must be signed by either of the following:

  • A hardware manufacturer
  • A trusted Operating System vendor or provider

On Linux, a few distributions work with Secure Boot installed, as for example Fedora, Debian and Ubuntu. This means that they are trusted Operating System vendors, and hence the modules they ship as part of the distribution are signed by them and will work.

However, if you install any software from a third party, that requires to load a kernel module, you will have to sign it yourself.

This script works for Fedora and will:

  1. Sign all the modules passed as parameter, and all their dependencies, i.e., any other modules present in the same directory of the tree.
  2. Restart any systemd unit that is failed, bringing back the system to a running state if all failed units are so due to kernel modules that have not been loaded.

The script should be run after a reboot performed as a result of a kernel update, or own / third party modules updates.

Prerrequisites

Install

Clone this repository or download the script signmodules, and place it in the $PATH variable.

Invocation and Behaviour

The usage of the script is the following:

signmodules /path/to/MOK.priv /path/to/MOK.der MODULE_1 MODULE_2 ... MODULE_N
  • /path/to/MOK.priv: private part of the MOK (Machine Owner Key --the signing key)
  • /path/to/MOK.der: public part of the MOK.
  • MODULE_1 MODULE_2 ... MODULE_N: a list of modules' names that we want to sign, e.g.: vboxdrv v4l2loopback

The script will ask for the user password, as both signing modules and restarting systemd services are operations that must be run under sudo.

Invoked like the above, the script won't write any logs (unless in trouble). Add -v (verbose) before the list of modules to enable logs

Result Codes

The result codes are 0 if all operations were successful, or:

  • 1 if there were failures while signing modules,
  • 2 if there were failires while trying to restart systemd services,
  • 3 if both.

Example

An example invocation is the following, useful for signing all modules for Virtual Box and Video4Linux Loopback, and restarting the relevant systemd services, all in one go:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: [signmodules] Processing all modules for 'vboxdrv':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'
[signmodules] Processing all modules for 'v4l2loopback':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'
[signmodules] Restarting any failed services after processing modules:
[signmodules] Requested 'vboxdrv' restart with result 0
[signmodules] Requested 'systemd-modules-load' restart with result 0
[signmodules] Done. Exiting with code 0 --success.
$ echo $?
0

Without logs:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: $ echo $?
0

Automation of the script

To run the script in an automation and without user interaction, set up the environment variable KBUILD_SIGN_PIN with the passphrase of the private part of the Machine Owner Key, MOK.priv, and run the script as an privileged service / under a system user with elevated privileges.

Credits

This script is inspired by this Gist by Reilly Tucker Siemens, and taken further to sign any set of modules, plus fix any broken systemd service caused by unsigned modules.

About

A shell script for signing kernel modules with a Machine Owner Key, for Fedora

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Sep 5, 2024. It is now read-only.

Latest commit

History

10 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

signmodules (archived)

Warning This repository is archived in GitHub and will no longer be maintained here. This repository lives here now.

A shell script for signing kernel modules with a Machine Owner Key, for Fedora.

Background

In machines with Secure Boot installed, the bootloader, kernel, and all modules loaded by the kernel must be signed by either of the following:

  • A hardware manufacturer
  • A trusted Operating System vendor or provider

On Linux, a few distributions work with Secure Boot installed, as for example Fedora, Debian and Ubuntu. This means that they are trusted Operating System vendors, and hence the modules they ship as part of the distribution are signed by them and will work.

However, if you install any software from a third party, that requires to load a kernel module, you will have to sign it yourself.

This script works for Fedora and will:

  1. Sign all the modules passed as parameter, and all their dependencies, i.e., any other modules present in the same directory of the tree.
  2. Restart any systemd unit that is failed, bringing back the system to a running state if all failed units are so due to kernel modules that have not been loaded.

The script should be run after a reboot performed as a result of a kernel update, or own / third party modules updates.

Prerrequisites

Install

Clone this repository or download the script signmodules, and place it in the $PATH variable.

Invocation and Behaviour

The usage of the script is the following:

signmodules /path/to/MOK.priv /path/to/MOK.der MODULE_1 MODULE_2 ... MODULE_N
  • /path/to/MOK.priv: private part of the MOK (Machine Owner Key --the signing key)
  • /path/to/MOK.der: public part of the MOK.
  • MODULE_1 MODULE_2 ... MODULE_N: a list of modules' names that we want to sign, e.g.: vboxdrv v4l2loopback

The script will ask for the user password, as both signing modules and restarting systemd services are operations that must be run under sudo.

Invoked like the above, the script won't write any logs (unless in trouble). Add -v (verbose) before the list of modules to enable logs

Result Codes

The result codes are 0 if all operations were successful, or:

  • 1 if there were failures while signing modules,
  • 2 if there were failires while trying to restart systemd services,
  • 3 if both.

Example

An example invocation is the following, useful for signing all modules for Virtual Box and Video4Linux Loopback, and restarting the relevant systemd services, all in one go:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: [signmodules] Processing all modules for 'vboxdrv':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'
[signmodules] Processing all modules for 'v4l2loopback':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'
[signmodules] Restarting any failed services after processing modules:
[signmodules] Requested 'vboxdrv' restart with result 0
[signmodules] Requested 'systemd-modules-load' restart with result 0
[signmodules] Done. Exiting with code 0 --success.
$ echo $?
0

Without logs:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: $ echo $?
0

Automation of the script

To run the script in an automation and without user interaction, set up the environment variable KBUILD_SIGN_PIN with the passphrase of the private part of the Machine Owner Key, MOK.priv, and run the script as an privileged service / under a system user with elevated privileges.

Credits

This script is inspired by this Gist by Reilly Tucker Siemens, and taken further to sign any set of modules, plus fix any broken systemd service caused by unsigned modules.

About

A shell script for signing kernel modules with a Machine Owner Key, for Fedora

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
This repository was archived by the owner on Sep 5, 2024. It is now read-only.

Latest commit

History

10 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

signmodules (archived)

Warning This repository is archived in GitHub and will no longer be maintained here. This repository lives here now.

A shell script for signing kernel modules with a Machine Owner Key, for Fedora.

Background

In machines with Secure Boot installed, the bootloader, kernel, and all modules loaded by the kernel must be signed by either of the following:

  • A hardware manufacturer
  • A trusted Operating System vendor or provider

On Linux, a few distributions work with Secure Boot installed, as for example Fedora, Debian and Ubuntu. This means that they are trusted Operating System vendors, and hence the modules they ship as part of the distribution are signed by them and will work.

However, if you install any software from a third party, that requires to load a kernel module, you will have to sign it yourself.

This script works for Fedora and will:

  1. Sign all the modules passed as parameter, and all their dependencies, i.e., any other modules present in the same directory of the tree.
  2. Restart any systemd unit that is failed, bringing back the system to a running state if all failed units are so due to kernel modules that have not been loaded.

The script should be run after a reboot performed as a result of a kernel update, or own / third party modules updates.

Prerrequisites

Install

Clone this repository or download the script signmodules, and place it in the $PATH variable.

Invocation and Behaviour

The usage of the script is the following:

signmodules /path/to/MOK.priv /path/to/MOK.der MODULE_1 MODULE_2 ... MODULE_N
  • /path/to/MOK.priv: private part of the MOK (Machine Owner Key --the signing key)
  • /path/to/MOK.der: public part of the MOK.
  • MODULE_1 MODULE_2 ... MODULE_N: a list of modules' names that we want to sign, e.g.: vboxdrv v4l2loopback

The script will ask for the user password, as both signing modules and restarting systemd services are operations that must be run under sudo.

Invoked like the above, the script won't write any logs (unless in trouble). Add -v (verbose) before the list of modules to enable logs

Result Codes

The result codes are 0 if all operations were successful, or:

  • 1 if there were failures while signing modules,
  • 2 if there were failires while trying to restart systemd services,
  • 3 if both.

Example

An example invocation is the following, useful for signing all modules for Virtual Box and Video4Linux Loopback, and restarting the relevant systemd services, all in one go:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: [signmodules] Processing all modules for 'vboxdrv':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxdrv.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetadp.ko'
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/VirtualBox/vboxnetflt.ko'
[signmodules] Processing all modules for 'v4l2loopback':
[signmodules] Unpacking '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko.xz'...
[signmodules] Signing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'...
[signmodules] Recompressing '/lib/modules/5.19.6-200.fc36.x86_64/extra/v4l2loopback/v4l2loopback.ko'
[signmodules] Restarting any failed services after processing modules:
[signmodules] Requested 'vboxdrv' restart with result 0
[signmodules] Requested 'systemd-modules-load' restart with result 0
[signmodules] Done. Exiting with code 0 --success.
$ echo $?
0

Without logs:

$ signmodules ~/Downloads/MOK.priv ~/Downloads/MOK.der -v vboxdrv v4l2loopback
[sudo] password for gvisoc: Passphrase for /home/gvisoc/Downloads/MOK.priv: $ echo $?
0

Automation of the script

To run the script in an automation and without user interaction, set up the environment variable KBUILD_SIGN_PIN with the passphrase of the private part of the Machine Owner Key, MOK.priv, and run the script as an privileged service / under a system user with elevated privileges.

Credits

This script is inspired by this Gist by Reilly Tucker Siemens, and taken further to sign any set of modules, plus fix any broken systemd service caused by unsigned modules.

About

A shell script for signing kernel modules with a Machine Owner Key, for Fedora

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Contributors