Skip to content

revert(os/mkosi): apply rootfs tmpfiles at boot again - #1415

Merged
kvinwang merged 1 commit into
nextfrom
revert/1331-rootfs-tmpfiles
Sep 26, 2026
Merged

kvinwang merged 1 commit into
nextfrom
revert/1331-rootfs-tmpfiles

Conversation

@kvinwang

Copy link
Copy Markdown
Collaborator

Reverts #1331.

Applying rootfs.tmpfiles only at build time broke two things:

  • mkosi.finalize runs as the invoking user in a rootless build, so systemd-tmpfiles cannot chown the root-owned entries and every rootless make os-image fails (fchownat() of /buildroot/dstack failed, exit 73). CI runs mkosi as root and did not notice.
  • /var/lib is a writable overlay at runtime, so the boot-time pass was not a no-op there: it kept /var/lib/tpm2-tss/system/keystore at 0755 root:root. Without it, tpm2-tss-fapi.conf resets the keystore to 2775 tss:tss on every boot.

The boot-time entries that land on the read-only root were harmless no-ops. This replaces #1409 and #1413, which patched each symptom separately.

Verification

  • The revert applies cleanly on next; os/mkosi/build.sh lint passes.
  • Rootless build and physical TDX boot results will follow in a comment.

This reverts #1331 (merge 81cb016).

Applying rootfs.tmpfiles only at build time broke two things:

- mkosi.finalize runs as the invoking user in a rootless build, so
  systemd-tmpfiles cannot chown the root-owned entries and every
  rootless `make os-image` fails with exit code 73.
- /var/lib is a writable overlay at runtime, so the boot-time pass was
  not a no-op: it kept /var/lib/tpm2-tss/system/keystore at 0755
  root:root. Without it, tpm2-tss-fapi.conf resets the keystore to
  2775 tss:tss on every boot.

The boot-time entries that land on the read-only root were harmless
no-ops, so restoring them costs nothing.

Signed-off-by: Kevin Wang <wy721@qq.com>
kvinwang added a commit that referenced this pull request Sep 26, 2026
#1415 reverts #1331, so the image again ships dstack-image.conf in
tmpfiles.d and the first-boot unit. tc-gos-platform-005 keeps the
outcome that matters, a root-owned 0755 TPM keystore at runtime, and the
source catalogs follow the file back to its old path.

Signed-off-by: Kevin Wang <wy721@qq.com>
@kvinwang

Copy link
Copy Markdown
Collaborator Author

Physical TDX (tdxlab) validation of next at 635e7a2200 plus this PR, #1414 and the #841 suite (tree ef0f7b94c), without #1409 or #1413:

  • Rootless build (mkosi 26, unprivileged user namespaces): the prod, dev and identity-variant images all build. On next alone the finalize step failed with fchownat() … Invalid argument.
  • tc-gos-platform-005 passes: at runtime /var/lib/tpm2-tss/system/keystore is 755 and /tapp links to dstack.
  • Full sweep, 4 workers, 372 scripted cases: 361 PASS, 7 BLOCKED (NVIDIA CC GPU or Yocto image required), 2 FAIL and 2 ERROR. All four failures were KMS upgrade-matrix cases (tc-kms-upgrade-001/005, tc-int-end-to-end-003, tc-int-failure-se-002) that timed out waiting for the KMS CVM under 4-worker load. All four pass when rerun one at a time on the same tree and images.

@kvinwang
kvinwang merged commit 2d215be into next Sep 26, 2026
8 checks passed
@kvinwang
kvinwang deleted the revert/1331-rootfs-tmpfiles branch September 26, 2026 04:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant