Skip to content

hash-signature (1): add optional verity root hash signature - #834

Draft
bfjelds (bfjelds) wants to merge 8 commits into
mainfrom
user/bfjelds/verity-roothash-sig-1-api
Draft

bfjelds (bfjelds) wants to merge 8 commits into
mainfrom
user/bfjelds/verity-roothash-sig-1-api

Conversation

@bfjelds

@bfjelds bfjelds (bfjelds) commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Summary

First PR in a 3-part stack implementing an optional dm-verity root hash signature partition.

This PR adds the HostConfiguration API surface only: a new optional field linking a verity device to a partition holding a detached signature of its root hash. No COSI or engine behavior changes yet (those are PR2 and PR3).

Changes

  • VerityDevice.signature_device_id: Option<BlockDeviceId> — the ID of the partition holding the dm-verity root hash signature, if any.
  • New SpecialReferenceKind::VerityRootHashSignatureDevice in the storage dependency graph:
    • Enforces homogeneous partition types (same as data/hash devices).
    • Restricts allowed partition types to LinuxGeneric only (no Discoverable Partition Spec GUID exists for this role).
    • Does not pass through partition attributes (consumed entirely by the verity device, like the hash device).
  • Updated all VerityDevice struct-literal construction sites across the workspace to account for the new field.

Stack

  1. (this PR) hash-signature (1): add optional verity root hash signature #834
  2. hash-signature (2): v1.3 spec with optional verity signature partition #835
  3. hash-signature (3): deploy and open verity root hash signature partitions #836

Testing

bfjelds (bfjelds) and others added 2 commits October 8, 2026 15:51
Adds VerityDevice.signature_device_id (Option<BlockDeviceId>) to the
HostConfiguration API, linking a verity device to an optional
partition holding a detached PKCS#7 signature of its root hash.

Wires the new link through the storage dependency graph as a new
SpecialReferenceKind::VerityRootHashSignatureDevice: enforces
homogeneous partition types, and restricts allowed partition types to
LinuxGeneric (no DPS GUID exists for this partition role).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Adds signature_device_id: None to the remaining VerityDevice struct
literals across the codebase (test fixtures, sample configs, engine
and subsystem call sites) so the workspace builds cleanly with the
new optional field.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
There may be pipelines that require an authorized user to comment /azp run to run.

@bfjelds bfjelds (bfjelds) changed the title hostconfig: add optional verity root hash signature device hash-signature: add optional verity root hash signature Oct 8, 2026
@bfjelds bfjelds (bfjelds) changed the title hash-signature: add optional verity root hash signature hash-signature (1): add optional verity root hash signature Oct 8, 2026
bfjelds (bfjelds) and others added 5 commits October 8, 2026 16:18
Renames for clarity ahead of further stack PRs:
- SpecialReferenceKind::VerityRootHashSignatureDevice -> VerityHashSignatureDevice
- VerityDevice.signature_device_id -> hash_signature_device_id

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Move the construction of the VerityHashSignatureDevice special reference out of node.rs, since the graph-wiring logic is only meaningful once the engine can act on it. This will land in the engine PR instead. Mark the enum variant #[allow(dead_code)] in the meantime, consistent with the existing KnownMetadataVersion precedent.
Cover the Some(...) case, not just the None default: verify the field serializes/deserializes correctly under its camelCase name and round-trips through VerityDevice. Graph-level validation of the signature device is exercised separately once the reference is wired up in the engine PR.
Regenerate API schema/docs after simplifying the field description.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The signature reference is never added to the storage graph, leaving its existence and partition rules unenforced.

1 open finding
What changed in this PR

Adds the HostConfiguration API surface for an optional dm-verity root-hash signature partition.

Changes:

  • Adds the optional hashSignatureDeviceId field, schema, documentation, and serde tests.
  • Defines storage-graph rules for signature partitions.
  • Updates existing VerityDevice construction sites.
File Description
docs/​Reference/​Host-Configuration/​API-Reference/​VerityDevice.md Documents the optional field.
crates/​trident/​src/​subsystems/​storage/​osimage.rs Updates test fixtures.
crates/​trident/​src/​subsystems/​storage/​fstab.rs Updates test fixtures.
crates/​trident/​src/​subsystems/​selinux.rs Updates test fixtures.
crates/​trident/​src/​osimage/​cosi/​derived_hc.rs Initializes the field for derived configurations.
crates/​trident/​src/​init/​offline/​mod.rs Initializes offline status data.
crates/​trident/​src/​init/​acl/​mod.rs Initializes ACL status data.
crates/​trident/​src/​engine/​storage/​verity.rs Updates functional-test fixtures.
crates/​trident/​src/​engine/​rollback.rs Updates rollback fixtures.
crates/​trident/​src/​engine/​context/​mod.rs Updates context fixtures.
crates/​trident_api/​src/​samples/​sample_hc.rs Updates sample configurations.
crates/​trident_api/​src/​config/​host/​storage/​verity.rs Adds the API field and serde tests.
crates/​trident_api/​src/​config/​host/​storage/​storage_graph/​validation_tests.rs Updates validation fixtures.
crates/​trident_api/​src/​config/​host/​storage/​storage_graph/​rules/​mod.rs Defines signature-partition rules.
crates/​trident_api/​src/​config/​host/​storage/​storage_graph/​references.rs Adds the signature reference kind.
crates/​trident_api/​src/​config/​host/​storage/​storage_graph/​graph.rs Updates graph fixtures.
crates/​trident_api/​src/​config/​host/​storage/​storage_graph/​display.rs Formats the new reference kind.
crates/​trident_api/​src/​config/​host/​storage/​storage_graph/​builder/​partition.rs Prevents signature attribute passthrough.
crates/​trident_api/​src/​config/​host/​storage/​mod.rs Updates storage fixtures.
crates/​trident_api/​src/​config/​host/​mod.rs Updates host fixtures.
crates/​trident_api/​schemas/​host-config-schema.json Adds the field to JSON Schema.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The scoped API and schema changes are consistent, with runtime graph wiring explicitly deferred to the follow-on stack.

0 open findings

1 resolved since last review

🧠 Review effort: Balanced

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The new validation rule rejects standard DPS verity-signature partition types already represented by the codebase.

1 open finding

🧠 Review effort: Balanced

Comment thread crates/trident_api/src/config/host/storage/storage_graph/rules/mod.rs Outdated
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d61c42e7-3c43-4fe5-8c89-89d38ff9528b

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants