fix(os/mkosi): mask systemd's TPM SRK setup units - #1411
Merged
Merged
Conversation
On a measured-UKI boot (GCP), systemd-tpm2-setup.service tries to write the SRK public key to /var/lib/systemd/tpm2-srk-public-key.pem. It runs before sysinit.target, but the writable /var overlays come from dstack-volatile-binds.service, which the unit does not order after, so it hits the read-only root, fails, and leaves the system degraded. Nothing in dstack uses systemd's SRK: the TPM key provider creates its own primary key at 0x81000100 through tpm2-tss, and no image component uses systemd-creds or systemd-cryptenroll with a TPM. The Yocto image builds systemd without TPM support, so these units never existed there. Mask both SRK units instead of giving them a writable path, which would only keep an unused object persisted in the vTPM. Signed-off-by: Kevin Wang <wy721@qq.com>
This was referenced Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
On GCP (measured-UKI boot),
systemd-tpm2-setup.servicefails withFailed to open SRK public key file '/var/lib/systemd/tpm2-srk-public-key.pem' for writing: Read-only file system, which leaves the systemdegraded. The unit runs beforesysinit.target, but the writable/varoverlays come fromdstack-volatile-binds.service, and the unit is not ordered after that service.Fix
Mask
systemd-tpm2-setup.serviceandsystemd-tpm2-setup-early.servicein the image skeleton, the same way the sleep targets and debug shell are already masked. The static acceptance test now checks both masks.Masking is better than giving the unit a writable path:
0x81000100through tpm2-tss, and no image component usessystemd-credsorsystemd-cryptenrollwith a TPM.tpm2PACKAGECONFIG, so these units never existed there.Verification
os/mkosi/build.sh lintpasses, including the new acceptance check.a3-highgpu-1gTDX, SPOT, key providertpm. Dev mkosi image built rootless from this change plus fix(os/mkosi): apply rootfs tmpfiles inside the image as root #1409 and fix(guest): measure gpu-attestation after TPM key provisioning #1410. Checked on two boots, before and aftergcloud compute instances reset:maskedsystemctl is-system-runningreturnsrunningwith no failed units/run/systemd/tpm2-srk-public-key.*is absent