Skip to content

fix(os/mkosi): keep the TPM keystore root-owned 0755 at runtime - #1413

Closed
kvinwang wants to merge 1 commit into
nextfrom
fix/mkosi-keystore-boot-mode
Closed

kvinwang wants to merge 1 commit into
nextfrom
fix/mkosi-keystore-boot-mode

Conversation

@kvinwang

Copy link
Copy Markdown
Collaborator

#1331 applies rootfs.tmpfiles at build time only, assuming the root stays read-only at runtime. /var/lib is a writable overlay, though (dstack-volatile-binds.sh), so systemd-tmpfiles-setup re-applies tpm2-tss-fapi.conf on every boot and /var/lib/tpm2-tss/system/keystore comes back as 2775 tss:tss instead of the image's 0755 root:root, the package default rootfs.tmpfiles exists to override.

Ship a boot-time entry for that one path that sorts before the package's file (the earliest file wins for a path). No other rootfs.tmpfiles entry is on a writable overlay or conflicts with a package tmpfiles file.

Found by the PR 841 acceptance suite (tc-gos-platform-005).

Verification

Rootless mkosi dev image on a TDX host, booted under dstack-vmm: stat -c %a /var/lib/tpm2-tss/system/keystore is 2775 on next and 755 with this change; the squashfs content is 0755 0/0 in both.

#1331 applies rootfs.tmpfiles at build time only, on the premise that the
root is read-only at runtime. /var/lib is a writable overlay, though, so
systemd-tmpfiles-setup re-applies tpm2-tss-fapi.conf at every boot and the
keystore comes back as 2775 tss:tss. Ship a boot-time entry that sorts before
the package's and restores the image's mode.

Signed-off-by: Kevin Wang <wy721@qq.com>
@kvinwang

Copy link
Copy Markdown
Collaborator Author

Superseded by #1415, which reverts #1331 instead of patching its symptoms separately.

@kvinwang kvinwang closed this Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant