Repository navigation
hash-signature (1): add optional verity root hash signature - #834
Draft
bfjelds (bfjelds) wants to merge 8 commits into
Draft
bfjelds (bfjelds) wants to merge 8 commits into
bfjelds (bfjelds) wants to merge 8 commits into
Conversation
Adds VerityDevice.signature_device_id (Option<BlockDeviceId>) to the HostConfiguration API, linking a verity device to an optional partition holding a detached PKCS#7 signature of its root hash. Wires the new link through the storage dependency graph as a new SpecialReferenceKind::VerityRootHashSignatureDevice: enforces homogeneous partition types, and restricts allowed partition types to LinuxGeneric (no DPS GUID exists for this partition role). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Adds signature_device_id: None to the remaining VerityDevice struct literals across the codebase (test fixtures, sample configs, engine and subsystem call sites) so the workspace builds cleanly with the new optional field. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Azure Pipelines: Successfully started running 1 pipeline(s). There may be pipelines that require an authorized user to comment /azp run to run. |
This was referenced Oct 8, 2026
Renames for clarity ahead of further stack PRs: - SpecialReferenceKind::VerityRootHashSignatureDevice -> VerityHashSignatureDevice - VerityDevice.signature_device_id -> hash_signature_device_id Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Move the construction of the VerityHashSignatureDevice special reference out of node.rs, since the graph-wiring logic is only meaningful once the engine can act on it. This will land in the engine PR instead. Mark the enum variant #[allow(dead_code)] in the meantime, consistent with the existing KnownMetadataVersion precedent.
Cover the Some(...) case, not just the None default: verify the field serializes/deserializes correctly under its camelCase name and round-trips through VerityDevice. Graph-level validation of the signature device is exercised separately once the reference is wired up in the engine PR.
Regenerate API schema/docs after simplifying the field description.
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
The signature reference is never added to the storage graph, leaving its existence and partition rules unenforced.
1 open finding
What changed in this PR
Adds the HostConfiguration API surface for an optional dm-verity root-hash signature partition.
Changes:
- Adds the optional
hashSignatureDeviceIdfield, schema, documentation, and serde tests. - Defines storage-graph rules for signature partitions.
- Updates existing
VerityDeviceconstruction sites.
| File | Description |
|---|---|
docs/Reference/Host-Configuration/API-Reference/VerityDevice.md |
Documents the optional field. |
crates/trident/src/subsystems/storage/osimage.rs |
Updates test fixtures. |
crates/trident/src/subsystems/storage/fstab.rs |
Updates test fixtures. |
crates/trident/src/subsystems/selinux.rs |
Updates test fixtures. |
crates/trident/src/osimage/cosi/derived_hc.rs |
Initializes the field for derived configurations. |
crates/trident/src/init/offline/mod.rs |
Initializes offline status data. |
crates/trident/src/init/acl/mod.rs |
Initializes ACL status data. |
crates/trident/src/engine/storage/verity.rs |
Updates functional-test fixtures. |
crates/trident/src/engine/rollback.rs |
Updates rollback fixtures. |
crates/trident/src/engine/context/mod.rs |
Updates context fixtures. |
crates/trident_api/src/samples/sample_hc.rs |
Updates sample configurations. |
crates/trident_api/src/config/host/storage/verity.rs |
Adds the API field and serde tests. |
crates/trident_api/src/config/host/storage/storage_graph/validation_tests.rs |
Updates validation fixtures. |
crates/trident_api/src/config/host/storage/storage_graph/rules/mod.rs |
Defines signature-partition rules. |
crates/trident_api/src/config/host/storage/storage_graph/references.rs |
Adds the signature reference kind. |
crates/trident_api/src/config/host/storage/storage_graph/graph.rs |
Updates graph fixtures. |
crates/trident_api/src/config/host/storage/storage_graph/display.rs |
Formats the new reference kind. |
crates/trident_api/src/config/host/storage/storage_graph/builder/partition.rs |
Prevents signature attribute passthrough. |
crates/trident_api/src/config/host/storage/mod.rs |
Updates storage fixtures. |
crates/trident_api/src/config/host/mod.rs |
Updates host fixtures. |
crates/trident_api/schemas/host-config-schema.json |
Adds the field to JSON Schema. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d61c42e7-3c43-4fe5-8c89-89d38ff9528b
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
First PR in a 3-part stack implementing an optional dm-verity root hash signature partition.
This PR adds the HostConfiguration API surface only: a new optional field linking a verity device to a partition holding a detached signature of its root hash. No COSI or engine behavior changes yet (those are PR2 and PR3).
Changes
VerityDevice.signature_device_id: Option<BlockDeviceId>— the ID of the partition holding the dm-verity root hash signature, if any.SpecialReferenceKind::VerityRootHashSignatureDevicein the storage dependency graph:LinuxGenericonly (no Discoverable Partition Spec GUID exists for this role).VerityDevicestruct-literal construction sites across the workspace to account for the new field.Stack
Testing