Skip to content
2 changes: 2 additions & 0 deletions crates/trident/src/engine/context/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -757,6 +757,7 @@ mod tests {
name: "root".to_string(),
data_device_id: "root-data".to_string(),
hash_device_id: "root-hash".to_string(),
hash_signature_device_id: None,
..Default::default()
}];

Expand All @@ -767,6 +768,7 @@ mod tests {
name: "root".to_string(),
data_device_id: "root-data".to_string(),
hash_device_id: "root-hash".to_string(),
hash_signature_device_id: None,
..Default::default()
}
);
Expand Down
3 changes: 3 additions & 0 deletions crates/trident/src/engine/rollback.rs
Original file line number Diff line number Diff line change
Expand Up @@ -984,6 +984,7 @@ mod tests {
name: "root".into(),
data_device_id: "root-data".into(),
hash_device_id: "root-hash".into(),
hash_signature_device_id: None,
..Default::default()
}];

Expand Down Expand Up @@ -1358,6 +1359,7 @@ mod functional_test {
name: "root".to_string(),
data_device_id: "root-data".to_string(),
hash_device_id: "root-hash".to_string(),
hash_signature_device_id: None,
..Default::default()
}];

Expand Down Expand Up @@ -1414,6 +1416,7 @@ mod functional_test {
name: "root".to_string(),
data_device_id: "root-data".to_string(),
hash_device_id: "root-hash".to_string(),
hash_signature_device_id: None,
..Default::default()
}];

Expand Down
2 changes: 2 additions & 0 deletions crates/trident/src/engine/storage/verity.rs
Original file line number Diff line number Diff line change
Expand Up @@ -640,6 +640,7 @@ mod functional_test {
name: "root".into(),
data_device_id: "root-data".into(),
hash_device_id: "root-hash".into(),
hash_signature_device_id: None,
..Default::default()
}],
filesystems: vec![
Expand Down Expand Up @@ -771,6 +772,7 @@ mod functional_test {
name: "root".into(),
data_device_id: "root".into(),
hash_device_id: "root-hash".into(),
hash_signature_device_id: None,
..Default::default()
}],
..Default::default()
Expand Down
1 change: 1 addition & 0 deletions crates/trident/src/init/acl/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -278,6 +278,7 @@ fn inner_initial_host_status(
name: "usr".to_string(),
data_device_id: "usr-data".to_string(),
hash_device_id: "usr-hash".to_string(),
hash_signature_device_id: None,
..Default::default()
}],
ab_update: Some(AbUpdate {
Expand Down
1 change: 1 addition & 0 deletions crates/trident/src/init/offline/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -226,6 +226,7 @@ fn generate_host_status(
name: prism_verity.name.clone(),
data_device_id,
hash_device_id,
hash_signature_device_id: None,
corruption_option: match prism_verity.corruption_option.as_deref() {
None => VerityCorruptionOption::default(),
Some("io-error") => VerityCorruptionOption::IoError,
Expand Down
1 change: 1 addition & 0 deletions crates/trident/src/osimage/cosi/derived_hc.rs
Original file line number Diff line number Diff line change
Expand Up @@ -115,6 +115,7 @@ pub(super) fn derive_host_configuration_inner(
name: verity_name,
data_device_id: partition_id.clone(),
hash_device_id: hash_partition_id.clone(),
hash_signature_device_id: None,
corruption_option: Default::default(),
});

Expand Down
1 change: 1 addition & 0 deletions crates/trident/src/subsystems/selinux.rs
Original file line number Diff line number Diff line change
Expand Up @@ -507,6 +507,7 @@ mod tests {
name: "root".into(),
data_device_id: "root-data".into(),
hash_device_id: "root-hash".into(),
hash_signature_device_id: None,
corruption_option: VerityCorruptionOption::Ignore,
}],
..Default::default()
Expand Down
2 changes: 2 additions & 0 deletions crates/trident/src/subsystems/storage/fstab.rs
Original file line number Diff line number Diff line change
Expand Up @@ -505,6 +505,7 @@ mod tests {
name: "root".to_owned(),
data_device_id: "root-data".to_owned(),
hash_device_id: "root-hash".to_owned(),
hash_signature_device_id: None,
..Default::default()
}],
filesystems: vec![
Expand Down Expand Up @@ -663,6 +664,7 @@ mod tests {
name: "usr".to_owned(),
data_device_id: "usr-data".to_owned(),
hash_device_id: "usr-hash".to_owned(),
hash_signature_device_id: None,
..Default::default()
}],
filesystems: vec![
Expand Down
3 changes: 3 additions & 0 deletions crates/trident/src/subsystems/storage/osimage.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1105,6 +1105,7 @@ mod tests {
name: "verity".into(),
data_device_id: "data".into(),
hash_device_id: "hash".into(),
hash_signature_device_id: None,
..Default::default()
}],
filesystems: vec![FileSystem {
Expand Down Expand Up @@ -1157,6 +1158,7 @@ mod tests {
name: "verity".into(),
data_device_id: "data".into(),
hash_device_id: "hash".into(),
hash_signature_device_id: None,
..Default::default()
}],
filesystems: vec![FileSystem {
Expand Down Expand Up @@ -1401,6 +1403,7 @@ mod tests {
name: "verity".into(),
data_device_id: "data".into(),
hash_device_id: "hash".into(),
hash_signature_device_id: None,
..Default::default()
}],
filesystems: vec![FileSystem {
Expand Down
13 changes: 13 additions & 0 deletions crates/trident_api/schemas/host-config-schema.json
Original file line number Diff line number Diff line change
Expand Up @@ -895,6 +895,14 @@
"root-verity"
]
},
{
"title": "Root verity hash signature partition",
"description": "x64: `41092b05-9fc8-4523-994f-2def0408b176`",
"type": "string",
"enum": [
"root-verity-sig"
]
},
{
"title": "Home partition",
"description": "`933ac7e1-2eb4-4f13-b844-0e14e2aef915`",
Expand Down Expand Up @@ -1817,6 +1825,11 @@
"type": "string",
"format": "Block Device ID"
},
"hashSignatureDeviceId": {
"description": "The ID of the partition to use as the verity hash signature partition.",
"type": "string",
"format": "Block Device ID"
},
"id": {
"description": "Block device id of the verity device.",
"type": "string"
Expand Down
3 changes: 3 additions & 0 deletions crates/trident_api/src/config/host/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -798,6 +798,7 @@ mod tests {
id: "root".into(),
data_device_id: "root-data".into(),
hash_device_id: "root-hash".into(),
hash_signature_device_id: None,
name: "root".into(),
..Default::default()
}],
Expand Down Expand Up @@ -931,13 +932,15 @@ mod tests {
name: "usr".to_string(),
data_device_id: "usr-data".into(),
hash_device_id: "usr-hash".into(),
hash_signature_device_id: None,
..Default::default()
},
VerityDevice {
id: "root".into(),
name: "root".to_string(),
data_device_id: "root-data".into(),
hash_device_id: "root-hash".into(),
hash_signature_device_id: None,
..Default::default()
},
],
Expand Down
3 changes: 3 additions & 0 deletions crates/trident_api/src/config/host/storage/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -761,6 +761,7 @@ mod tests {
name: "root".into(),
data_device_id: "root-a".into(),
hash_device_id: "root-a-verity".into(),
hash_signature_device_id: None,
..Default::default()
}];
storage.filesystems.push(FileSystem {
Expand Down Expand Up @@ -2760,6 +2761,7 @@ mod tests {
name: "usr".into(),
data_device_id: "some-data-device".into(),
hash_device_id: "some-hash-device".into(),
hash_signature_device_id: None,
..Default::default()
})
.expect("Failed to validate usr verity device");
Expand All @@ -2772,6 +2774,7 @@ mod tests {
name: "usr-foo".into(),
data_device_id: "some-data-device".into(),
hash_device_id: "some-hash-device".into(),
hash_signature_device_id: None,
..Default::default()
})
.unwrap_err(),
Expand Down
34 changes: 25 additions & 9 deletions crates/trident_api/src/config/host/storage/partitions.rs
Original file line number Diff line number Diff line change
Expand Up @@ -123,6 +123,11 @@ pub enum PartitionType {
/// x64: `2c7357ed-ebd2-46d9-aec1-23d437ec2bf5`
RootVerity,

/// # Root verity hash signature partition
///
/// x64: `41092b05-9fc8-4523-994f-2def0408b176`
RootVeritySig,

/// # Home partition
///
/// `933ac7e1-2eb4-4f13-b844-0e14e2aef915`
Expand Down Expand Up @@ -201,6 +206,7 @@ impl PartitionType {
PartitionType::Root => "root",
PartitionType::Swap => "swap",
PartitionType::RootVerity => "root-verity",
PartitionType::RootVeritySig => "root-verity-sig",
PartitionType::Home => "home",
PartitionType::Var => "var",
PartitionType::Usr => "usr",
Expand Down Expand Up @@ -232,6 +238,7 @@ impl PartitionType {
Self::LinuxGeneric => Some(Self::LinuxGeneric),

Self::RootVerity
| Self::RootVeritySig
| Self::UsrVerity
| Self::UsrVeritySig
| Self::Esp
Expand Down Expand Up @@ -259,6 +266,7 @@ impl From<PartitionType> for DiscoverablePartitionType {
PartitionType::Root => Self::Root,
PartitionType::Swap => Self::Swap,
PartitionType::RootVerity => Self::RootVerity,
PartitionType::RootVeritySig => Self::RootVeritySig,
PartitionType::Home => Self::Home,
PartitionType::Var => Self::Var,
PartitionType::Usr => Self::Usr,
Expand Down Expand Up @@ -328,11 +336,10 @@ impl From<DiscoverablePartitionType> for PartitionType {
| DiscoverablePartitionType::UsrAmd64VeritySig
| DiscoverablePartitionType::UsrArm64VeritySig => Self::UsrVeritySig,

// Root verity signature partitions do not have a corresponding
// PartitionType variant yet, so we treat them as unknown.
// We coalesce all root verity signature variants into one.
DiscoverablePartitionType::RootVeritySig
| DiscoverablePartitionType::RootAmd64VeritySig
| DiscoverablePartitionType::RootArm64VeritySig => Self::Unknown(dpt.to_uuid()),
| DiscoverablePartitionType::RootArm64VeritySig => Self::RootVeritySig,

// Fallback for unknown types
DiscoverablePartitionType::Unknown(uuid) => Self::Unknown(uuid),
Expand Down Expand Up @@ -419,17 +426,26 @@ mod tests {
assert_eq!(PartitionType::from(dpt), PartitionType::UsrVeritySig);
}

// Root-verity-sig variants have no corresponding PartitionType
// variant yet, so they still fall back to Unknown.
assert_eq!(
DiscoverablePartitionType::from(PartitionType::RootVeritySig),
DiscoverablePartitionType::RootVeritySig
);
assert_eq!(
PartitionType::RootVeritySig.to_sdrepart_part_type(),
"root-verity-sig"
);
let root_sig: PartitionType = serde_yaml::from_str("root-verity-sig").unwrap();
assert_eq!(root_sig, PartitionType::RootVeritySig);
assert_eq!(
serde_yaml::to_string(&root_sig).unwrap().trim(),
"root-verity-sig"
);
for dpt in [
DiscoverablePartitionType::RootVeritySig,
DiscoverablePartitionType::RootAmd64VeritySig,
DiscoverablePartitionType::RootArm64VeritySig,
] {
assert!(matches!(
PartitionType::from(dpt),
PartitionType::Unknown(_)
));
assert_eq!(PartitionType::from(dpt), PartitionType::RootVeritySig);
}
}

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,11 @@ impl SpecialReferenceKind {
// attributes as the hash device is entirely consumed by the verity
// device.
SpecialReferenceKind::VerityHashDevice => false,

// The verity root hash signature device should NOT pass through
// partition attributes either, as it is entirely consumed by the
// verity device.
SpecialReferenceKind::VerityHashSignatureDevice => false,
}
}
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,7 @@ impl Display for SpecialReferenceKind {
match self {
Self::VerityDataDevice => write!(f, "verity-data-device"),
Self::VerityHashDevice => write!(f, "verity-hash-device"),
Self::VerityHashSignatureDevice => write!(f, "verity-hash-signature-device"),
}
}
}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -390,6 +390,7 @@ mod tests {
name: "myVerityDevice".into(),
data_device_id: "data".into(),
hash_device_id: "hash".into(),
hash_signature_device_id: None,
..Default::default()
};
let backing_node_idx = graph.inner.add_node((&verity_dev).into());
Expand Down Expand Up @@ -420,6 +421,7 @@ mod tests {
name: "myVerityDevice2".into(),
data_device_id: "data2".into(),
hash_device_id: "hash2".into(),
hash_signature_device_id: None,
..Default::default()
};
let backing_node_idx2 = graph.inner.add_node((&verity_dev2).into());
Expand Down Expand Up @@ -510,6 +512,7 @@ mod tests {
name: "myVerityDevice".into(),
data_device_id: "data".into(),
hash_device_id: "hash".into(),
hash_signature_device_id: None,
..Default::default()
}),
}));
Expand Down Expand Up @@ -607,6 +610,7 @@ mod tests {
name: "myVerityDevice".into(),
data_device_id: "data".into(),
hash_device_id: "hash".into(),
hash_signature_device_id: None,
..Default::default()
}),
}));
Expand Down Expand Up @@ -759,6 +763,7 @@ mod tests {
name: "verity".into(),
data_device_id: "data".into(),
hash_device_id: "hash".into(),
hash_signature_device_id: None,
..Default::default()
}],
encryption: Some(Encryption {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,10 @@ pub enum SpecialReferenceKind {

/// A reference to a Verity device's underlying hash device.
VerityHashDevice,

/// A reference to a Verity device's root hash signature device.
#[allow(dead_code)]
VerityHashSignatureDevice,
Comment thread
bfjelds marked this conversation as resolved.
}

/// A reference to a block device in the configuration.
Expand Down
Loading
Loading