Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions crates/lib/src/bootc_composefs/state.rs
Original file line number Diff line number Diff line change
Expand Up @@ -329,7 +329,7 @@ pub(crate) async fn write_composefs_state(
}

pub(crate) fn composefs_usr_overlay(access_mode: FilesystemOverlayAccessMode) -> Result<()> {
let status = get_composefs_usr_overlay_status()?;
let status = get_usr_overlay_status()?;
if status.is_some() {
println!("An overlayfs is already mounted on /usr");
return Ok(());
Expand All @@ -351,7 +351,7 @@ pub(crate) fn composefs_usr_overlay(access_mode: FilesystemOverlayAccessMode) ->
Ok(())
}

pub(crate) fn get_composefs_usr_overlay_status() -> Result<Option<FilesystemOverlay>> {
pub(crate) fn get_usr_overlay_status() -> Result<Option<FilesystemOverlay>> {
let usr = Dir::open_ambient_dir("/usr", ambient_authority()).context("Opening /usr")?;
let is_usr_mounted = usr
.is_mountpoint(".")
Expand Down
4 changes: 2 additions & 2 deletions crates/lib/src/bootc_composefs/status.rs
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ use crate::{
bootc_composefs::{
boot::BootType,
selinux::are_selinux_policies_compatible,
state::{get_composefs_usr_overlay_status, read_origin},
state::{get_usr_overlay_status, read_origin},
utils::{compute_store_boot_digest_for_uki, get_uki_cmdline},
},
composefs_consts::{
Expand Down Expand Up @@ -1142,7 +1142,7 @@ async fn composefs_deployment_status_from(
host.spec.boot_order = BootOrder::Rollback
};

host.status.usr_overlay = get_composefs_usr_overlay_status().ok().flatten();
host.status.usr_overlay = get_usr_overlay_status().ok().flatten();

set_soft_reboot_capability(storage, &mut host, sorted_bls_config, cmdline)?;

Expand Down
14 changes: 9 additions & 5 deletions crates/lib/src/bootloader.rs
Original file line number Diff line number Diff line change
Expand Up @@ -290,7 +290,7 @@ pub(crate) fn install_systemd_boot(
if configopts.generic_image {
bootctl_args.push("--no-variables");
// `--random-seed` was only added to `bootctl install` in systemd 257.
let systemd_version = bootctl_systemd_version()?;
let systemd_version = systemd_version()?;
if systemd_version >= BOOTCTL_RANDOM_SEED_MIN_VERSION {
bootctl_args.extend(["--random-seed", "no"]);
} else {
Expand Down Expand Up @@ -361,15 +361,19 @@ pub(crate) fn install_systemd_boot(
Ok(())
}

#[context("Querying bootctl version")]
pub(crate) fn bootctl_systemd_version() -> Result<u32> {
/// Query the major version of systemd via `systemctl --version`, caching the
/// result so it can be shared across callers (bootctl, systemd-repart, etc.).
#[context("Querying systemd version")]
pub(crate) fn systemd_version() -> Result<u32> {
static VERSION: OnceLock<u32> = OnceLock::new();

if let Some(v) = VERSION.get() {
return Ok(*v);
};

let out = Command::new("bootctl").arg("--version").run_get_string()?;
let out = Command::new("systemctl")
.arg("--version")
.run_get_string()?;
let v = parse_systemd_version(&out).context("Failed to parse version to integer")?;

let version = VERSION.get_or_init(|| v);
Expand All @@ -379,7 +383,7 @@ pub(crate) fn bootctl_systemd_version() -> Result<u32> {

/// Parse the systemd major version from `bootctl --version` output, whose first
/// line looks like `systemd 259 (259.5-0ubuntu3)`.
fn parse_systemd_version(output: &str) -> Result<u32> {
pub(crate) fn parse_systemd_version(output: &str) -> Result<u32> {
output
.split_whitespace()
.nth(1)
Expand Down
7 changes: 7 additions & 0 deletions crates/lib/src/cli.rs
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@ use serde::{Deserialize, Serialize};
use crate::bootc_composefs::delete::delete_composefs_deployment;
use crate::bootc_composefs::gc::{GCOpts, composefs_gc};
use crate::bootc_composefs::soft_reboot::{prepare_soft_reboot_composefs, reset_soft_reboot};
use crate::bootc_composefs::state::get_usr_overlay_status;
use crate::bootc_composefs::{
digest::{compute_composefs_digest, new_temp_composefs_repo},
finalize::{composefs_backend_finalize, get_etc_diff},
Expand Down Expand Up @@ -1844,6 +1845,12 @@ async fn edit(opts: EditOpts) -> Result<()> {

/// Implementation of `bootc usroverlay`
async fn usroverlay(access_mode: FilesystemOverlayAccessMode) -> Result<()> {
let status = get_usr_overlay_status()?;
if status.is_some() {
println!("An overlayfs is already mounted on /usr");
return Ok(());
}

// This is just a pass-through today. At some point we may make this a libostree API
// or even oxidize it.
let args = match access_mode {
Expand Down
3 changes: 3 additions & 0 deletions crates/lib/src/discoverable_partition_specification.rs
Original file line number Diff line number Diff line change
Expand Up @@ -499,6 +499,9 @@ pub const TMP: &str = "7ec6f557-3bc5-4aca-b293-16ef5df639d1";
/// Generic Linux filesystem data partition
pub const LINUX_DATA: &str = "0fc63daf-8483-4772-8e79-3d69d8477de4";

/// BIOS boot partition
pub const BIOS_BOOT: &str = "21686148-6449-6e6f-744e-656564454649";

// ============================================================================
// ARCHITECTURE-SPECIFIC HELPERS
// ============================================================================
Expand Down
77 changes: 43 additions & 34 deletions crates/lib/src/install.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1770,13 +1770,12 @@ async fn prepare_install(
println!("Digest: {digest}");
}

let root_filesystem = target_fs
.or(install_config
.as_ref()
.and_then(|c| c.filesystem_root())
.and_then(|r| r.fstype))
.ok_or_else(|| anyhow::anyhow!("No root filesystem specified"))?;
let composefs_fsverity_supported = root_filesystem.supports_fsverity();
// Don't error out if a filesystem is not passed in via cli as we could have
// repart.d definitions available
let root_filesystem = target_fs.or(install_config
.as_ref()
.and_then(|c| c.filesystem_root())
.and_then(|r| r.fstype));

let mut is_uki = false;

Expand All @@ -1787,39 +1786,46 @@ async fn prepare_install(
// we hard require it in that particular case
//
// NOTE: This isn't really 100% accurate 100% of the time as the cmdline can be in an addon
match kernel {
Some(k) => match k.k_type {
crate::kernel::KernelType::Uki { cmdline, .. } => {
let allow_missing_fsverity = if let Some(cmdline) = cmdline {
ComposefsCmdline::find_in_cmdline(&cmdline)?
.is_some_and(|cfs_cmdline| cfs_cmdline.allow_missing_fsverity)
} else {
false
};

if !allow_missing_fsverity {
anyhow::ensure!(
root_filesystem.supports_fsverity(),
"Specified filesystem {root_filesystem} does not support fs-verity"
);
}
if let Some(root_filesystem) = root_filesystem {
match kernel {
Some(k) => match k.k_type {
crate::kernel::KernelType::Uki { cmdline, .. } => {
Comment on lines +1789 to +1792

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this matching could be condensed

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done in #2522

let allow_missing_fsverity = if let Some(cmdline) = cmdline {
ComposefsCmdline::find_in_cmdline(&cmdline)?
.is_some_and(|cfs_cmdline| cfs_cmdline.allow_missing_fsverity)
} else {
false
};
// >>>>>>> 626befdf (install: Handle root filesystem)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is weird

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, must've missed this during all the rebases

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed here #2522


if !allow_missing_fsverity {
anyhow::ensure!(
root_filesystem.supports_fsverity(),
"Specified filesystem {root_filesystem} does not support fs-verity"
);
}

composefs_options.allow_missing_verity = allow_missing_fsverity;
is_uki = true;
}
composefs_options.allow_missing_verity = allow_missing_fsverity;
is_uki = true;
}

crate::kernel::KernelType::Vmlinuz { .. } => {}
},
crate::kernel::KernelType::Vmlinuz { .. } => {}
},

None => {}
}
None => {}
}

// If `--allow-missing-verity` is already passed via CLI, don't modify
if composefs_options.composefs_backend && !composefs_options.allow_missing_verity && !is_uki {
composefs_options.allow_missing_verity = !root_filesystem.supports_fsverity();
// If `--allow-missing-verity` is already passed via CLI, don't modify
if composefs_options.composefs_backend && !composefs_options.allow_missing_verity && !is_uki
{
composefs_options.allow_missing_verity = !root_filesystem.supports_fsverity();
}
}

tracing::info!(
root_filesystem = root_filesystem
.map(|f| f.to_string())
.unwrap_or("None".into()),
allow_missing_fsverity = composefs_options.allow_missing_verity,
uki = is_uki,
"ComposeFS install prep",
Expand Down Expand Up @@ -1870,7 +1876,10 @@ async fn prepare_install(
host_is_container,
composefs_required,
composefs_options,
composefs_fsverity_supported,
// assume fs-verity is supported as that's the safer option
composefs_fsverity_supported: root_filesystem
.map(|fs| fs.supports_fsverity())
.unwrap_or(true),
allow_missing_verity_explicit,
});

Expand Down
Loading
Loading