blob: babfae6554165d82c541397dcb3a5219b9224d7b [file] [log] [blame]
# Copyright 2018 The Chromium OS Authors. All rights reserved.
# Use of this source code is governed by a BSD-style license that can be
# found in the LICENSE file.
#
# This service maintains /mnt/stateful_partition/.secure_boot. We want this file
# to exist if the system has *ever* been booted in secure boot mode, so it is
# intentional that we do not remove /mnt/stateful_partition/.secure_boot when
# the system boots in non-secure boot mode.
[Unit]
Description=Check if secure boot is enabled
[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=/bin/bash -c "if /usr/share/cloud/is-secure-boot; then \
touch /mnt/stateful_partition/.secure_boot; fi"
[Install]
WantedBy=multi-user.target