| # Copyright 2018 The Chromium OS Authors. All rights reserved. |
| # Use of this source code is governed by a BSD-style license that can be |
| # found in the LICENSE file. |
| # |
| # This service maintains /mnt/stateful_partition/.secure_boot. We want this file |
| # to exist if the system has *ever* been booted in secure boot mode, so it is |
| # intentional that we do not remove /mnt/stateful_partition/.secure_boot when |
| # the system boots in non-secure boot mode. |
| |
| [Unit] |
| Description=Check if secure boot is enabled |
| |
| [Service] |
| Type=oneshot |
| RemainAfterExit=yes |
| ExecStart=/bin/bash -c "if /usr/share/cloud/is-secure-boot; then \ |
| touch /mnt/stateful_partition/.secure_boot; fi" |
| |
| [Install] |
| WantedBy=multi-user.target |