diff --git a/os/mkosi/mkosi.skeleton/etc/systemd/system/systemd-tpm2-setup-early.service b/os/mkosi/mkosi.skeleton/etc/systemd/system/systemd-tpm2-setup-early.service new file mode 120000 index 000000000..dc1dc0cde --- /dev/null +++ b/os/mkosi/mkosi.skeleton/etc/systemd/system/systemd-tpm2-setup-early.service @@ -0,0 +1 @@ +/dev/null \ No newline at end of file diff --git a/os/mkosi/mkosi.skeleton/etc/systemd/system/systemd-tpm2-setup.service b/os/mkosi/mkosi.skeleton/etc/systemd/system/systemd-tpm2-setup.service new file mode 120000 index 000000000..dc1dc0cde --- /dev/null +++ b/os/mkosi/mkosi.skeleton/etc/systemd/system/systemd-tpm2-setup.service @@ -0,0 +1 @@ +/dev/null \ No newline at end of file diff --git a/os/mkosi/tests/acceptance.sh b/os/mkosi/tests/acceptance.sh index 44fb408ef..046115165 100755 --- a/os/mkosi/tests/acceptance.sh +++ b/os/mkosi/tests/acceptance.sh @@ -120,6 +120,15 @@ grep -q '^WatchdogSec=' "$gw_unit" || { echo 'dstack-gateway-checker.service must set WatchdogSec'; exit 1; } test ! -e "$D/../common/rootfs/wg-checker.sh" test ! -e "$D/../common/rootfs/wg-checker.service" +# systemd-tpm2-setup writes the SRK public key to /var/lib/systemd before the +# /var overlays exist, so on a measured-UKI boot it fails on the read-only root +# and leaves the system degraded. Nothing in dstack uses systemd's SRK (the TPM +# key provider has its own primary key), and the Yocto systemd has no TPM +# support, so both SRK units are masked instead of given a writable path. +for unit in systemd-tpm2-setup.service systemd-tpm2-setup-early.service; do + [[ $(readlink "$D/mkosi.skeleton/etc/systemd/system/$unit") == /dev/null ]] || { + echo "$unit must be masked in the image skeleton"; exit 1; } +done # systemd enables any unit that matches no preset rule, so the enable list is # only meaningful with a terminal disable. Without it, every package pulled in # by Packages= would start at boot with no diff to 80-dstack.preset.