bootc-dev / bootc-dev/bootc

Support locking an existing staged deployment with --download-only

Offen
#2,425 5 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
triaged
Vorherrschende Sprache
Rust
Sterne
2.3k
Forks
230
Ø Merge
3 T. 12 Std.
Gemergte PRs (30 T.)
38

Beschreibung

## Problem
Running bootc switch --download-only for the same image that is already
staged does not convert the staged deployment from unlocked to download-only.
Instead, bootc exits successfully without changing the staged deployment:
```
Image specification is unchanged.
```

The staged deployment continues to report:
```
{
"downloadOnly": false
}
```
This means management software cannot safely enable a policy requiring an
explicit apply operation after the image has already been staged.

The result was reproduced on both:
- OSTree backend using XFS
- composefs backend using ext4, GRUB and BLS

Both returned `Image specification is unchanged`. with exit status 0, and both
left `status.staged.downloadOnly` set to `false`.

The OSTree-specific `ostree admin lock-finalization` command may provide a
low-level workaround, but it is not a backend-independent bootc interface.

## Background Why this matters https://github.com/bootc-dev/bootc-operator/pull/151
While implementing `RequireSoftReboot` support in bootc-operator, we need to
guarantee that a staged deployment cannot be applied by an ordinary reboot
before the operator explicitly applies it.

For `RequireSoftReboot`, the operator must ensure that an ordinary reboot
cannot accidentally apply the staged image.

If `RequireSoftReboot` is enabled after an update was staged normally,
bootc-operator currently cannot safely lock that existing stage. It must reject
the policy transition and report SoftRebootStageUnlocked.

## Expected Behavior:

If changing the state is unsupported, the command should return a clear error
instead of successfully reporting that the image specification is unchanged.

The operation should ideally be idempotent:
- An unlocked staged deployment becomes locked.
- An already locked deployment remains locked.
- The selected image and digest do not change.

A backend-independent bootc operation would let the operator safely adopt the
existing stage instead.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start by reproducing `bootc switch --download-only` against an already staged image on the OSTree and composefs backends, then trace the handling of the staged deployment state. The work is done when an unlocked stage becomes locked without changing its image or digest, an already locked stage remains unchanged, and unsupported changes return a clear error.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
rust
Bereich
operating-systems
Issue-Typ
Feature
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Aktiv
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
52/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.