-
Notifications
You must be signed in to change notification settings - Fork 235
install: Use systemd-repart for partitioning #2314
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
38827a7
18b0b54
a0b54db
e129372
05e21f5
d638d41
41e48ca
5dba22e
912e505
cdb3f83
18b7346
8d6d76e
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -1770,13 +1770,12 @@ async fn prepare_install( | |
| println!("Digest: {digest}"); | ||
| } | ||
|
|
||
| let root_filesystem = target_fs | ||
| .or(install_config | ||
| .as_ref() | ||
| .and_then(|c| c.filesystem_root()) | ||
| .and_then(|r| r.fstype)) | ||
| .ok_or_else(|| anyhow::anyhow!("No root filesystem specified"))?; | ||
| let composefs_fsverity_supported = root_filesystem.supports_fsverity(); | ||
| // Don't error out if a filesystem is not passed in via cli as we could have | ||
| // repart.d definitions available | ||
| let root_filesystem = target_fs.or(install_config | ||
| .as_ref() | ||
| .and_then(|c| c.filesystem_root()) | ||
| .and_then(|r| r.fstype)); | ||
|
|
||
| let mut is_uki = false; | ||
|
|
||
|
|
@@ -1787,39 +1786,46 @@ async fn prepare_install( | |
| // we hard require it in that particular case | ||
| // | ||
| // NOTE: This isn't really 100% accurate 100% of the time as the cmdline can be in an addon | ||
| match kernel { | ||
| Some(k) => match k.k_type { | ||
| crate::kernel::KernelType::Uki { cmdline, .. } => { | ||
| let allow_missing_fsverity = if let Some(cmdline) = cmdline { | ||
| ComposefsCmdline::find_in_cmdline(&cmdline)? | ||
| .is_some_and(|cfs_cmdline| cfs_cmdline.allow_missing_fsverity) | ||
| } else { | ||
| false | ||
| }; | ||
|
|
||
| if !allow_missing_fsverity { | ||
| anyhow::ensure!( | ||
| root_filesystem.supports_fsverity(), | ||
| "Specified filesystem {root_filesystem} does not support fs-verity" | ||
| ); | ||
| } | ||
| if let Some(root_filesystem) = root_filesystem { | ||
| match kernel { | ||
| Some(k) => match k.k_type { | ||
| crate::kernel::KernelType::Uki { cmdline, .. } => { | ||
| let allow_missing_fsverity = if let Some(cmdline) = cmdline { | ||
| ComposefsCmdline::find_in_cmdline(&cmdline)? | ||
| .is_some_and(|cfs_cmdline| cfs_cmdline.allow_missing_fsverity) | ||
| } else { | ||
| false | ||
| }; | ||
| // >>>>>>> 626befdf (install: Handle root filesystem) | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This is weird
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Sorry, must've missed this during all the rebases
Member
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Fixed here #2522 |
||
|
|
||
| if !allow_missing_fsverity { | ||
| anyhow::ensure!( | ||
| root_filesystem.supports_fsverity(), | ||
| "Specified filesystem {root_filesystem} does not support fs-verity" | ||
| ); | ||
| } | ||
|
|
||
| composefs_options.allow_missing_verity = allow_missing_fsverity; | ||
| is_uki = true; | ||
| } | ||
| composefs_options.allow_missing_verity = allow_missing_fsverity; | ||
| is_uki = true; | ||
| } | ||
|
|
||
| crate::kernel::KernelType::Vmlinuz { .. } => {} | ||
| }, | ||
| crate::kernel::KernelType::Vmlinuz { .. } => {} | ||
| }, | ||
|
|
||
| None => {} | ||
| } | ||
| None => {} | ||
| } | ||
|
|
||
| // If `--allow-missing-verity` is already passed via CLI, don't modify | ||
| if composefs_options.composefs_backend && !composefs_options.allow_missing_verity && !is_uki { | ||
| composefs_options.allow_missing_verity = !root_filesystem.supports_fsverity(); | ||
| // If `--allow-missing-verity` is already passed via CLI, don't modify | ||
| if composefs_options.composefs_backend && !composefs_options.allow_missing_verity && !is_uki | ||
| { | ||
| composefs_options.allow_missing_verity = !root_filesystem.supports_fsverity(); | ||
| } | ||
| } | ||
|
|
||
| tracing::info!( | ||
| root_filesystem = root_filesystem | ||
| .map(|f| f.to_string()) | ||
| .unwrap_or("None".into()), | ||
| allow_missing_fsverity = composefs_options.allow_missing_verity, | ||
| uki = is_uki, | ||
| "ComposeFS install prep", | ||
|
|
@@ -1870,7 +1876,10 @@ async fn prepare_install( | |
| host_is_container, | ||
| composefs_required, | ||
| composefs_options, | ||
| composefs_fsverity_supported, | ||
| // assume fs-verity is supported as that's the safer option | ||
| composefs_fsverity_supported: root_filesystem | ||
| .map(|fs| fs.supports_fsverity()) | ||
| .unwrap_or(true), | ||
| allow_missing_verity_explicit, | ||
| }); | ||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think this matching could be condensed
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Done in #2522