Skip to content

refactor(os): apply rootfs tmpfiles at build time only - #1331

Merged
kvinwang merged 1 commit into
nextfrom
docs/os-tmpfiles-readonly-root
Sep 24, 2026
Merged

kvinwang merged 1 commit into
nextfrom
docs/os-tmpfiles-readonly-root

Conversation

@kvinwang

@kvinwang kvinwang commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

dstack-image.conf sat in /usr/lib/tmpfiles.d, so it was re-run on every boot against the read-only verity root, where it can only be a no-op or fail. Move it out of the image (os/mkosi/rootfs.tmpfiles) and apply it from mkosi.finalize, after mkosi's own tmpfiles pass so it still overrides package defaults (e.g. tpm2-tss's 2775 keystore).

That makes the .dstack-keep skeleton markers, their RemoveFiles= cleanup and the matching exclusion in normalize-skeleton-modes.sh redundant, so they go too. dstack-firstboot.service, which mkdir -p'd the same directories on the read-only root at every boot, is dropped as well.

Tested: prod image built with make os-image; its rootfs listing (mode, owner, size, path) is identical to the image built with the .dstack-keep markers still in place. Booted it under TDX with dstack-vmm run: systemd-tmpfiles-setup succeeds, no failed units, the app container runs.

@kvinwang
kvinwang force-pushed the docs/os-tmpfiles-readonly-root branch from 3c90c94 to f16fb73 Compare September 24, 2026 03:32
@kvinwang kvinwang changed the title docs(os): say why the image tmpfiles lines run on a read-only root refactor(os): apply rootfs tmpfiles at build time only Sep 24, 2026
dstack-image.conf lived in /usr/lib/tmpfiles.d, so besides shaping the
build root it was re-run on every boot against the read-only verity
root, where it can only succeed as a no-op or fail. Move it out of the
skeleton and apply it from mkosi.finalize, after mkosi's own tmpfiles
pass, so the image no longer carries a boot-time step that needs
explaining.

Running last, it also overrides the package defaults for the /var
directories itself (e.g. tpm2-tss's 2775 keystore), which makes the
.dstack-keep skeleton markers and their RemoveFiles= cleanup redundant.

dstack-firstboot.service did the same with mkdir -p on directories the
build already creates; drop it and its preset entry.
@kvinwang
kvinwang force-pushed the docs/os-tmpfiles-readonly-root branch from f16fb73 to fc65011 Compare September 24, 2026 04:33
@kvinwang
kvinwang merged commit 81cb016 into next Sep 24, 2026
8 checks passed
@kvinwang
kvinwang deleted the docs/os-tmpfiles-readonly-root branch September 24, 2026 04:44
kvinwang added a commit that referenced this pull request Sep 26, 2026
#1415 reverts #1331, so the image again ships dstack-image.conf in
tmpfiles.d and the first-boot unit. tc-gos-platform-005 keeps the
outcome that matters, a root-owned 0755 TPM keystore at runtime, and the
source catalogs follow the file back to its old path.

Signed-off-by: Kevin Wang <wy721@qq.com>
source-c pushed a commit to silicon-foundation/dstack that referenced this pull request Oct 4, 2026
This reverts Dstack-TEE#1331 (merge 81cb016).

Applying rootfs.tmpfiles only at build time broke two things:

- mkosi.finalize runs as the invoking user in a rootless build, so
  systemd-tmpfiles cannot chown the root-owned entries and every
  rootless `make os-image` fails with exit code 73.
- /var/lib is a writable overlay at runtime, so the boot-time pass was
  not a no-op: it kept /var/lib/tpm2-tss/system/keystore at 0755
  root:root. Without it, tpm2-tss-fapi.conf resets the keystore to
  2775 tss:tss on every boot.

The boot-time entries that land on the read-only root were harmless
no-ops, so restoring them costs nothing.

Signed-off-by: Kevin Wang <wy721@qq.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant