bootc-dev / bootc-dev/bootc

check shim version before installing with LUKS root

Offen
#561 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
area/install enhancement
Vorherrschende Sprache
Rust
Sterne
2.3k
Forks
230
Ø Merge
3 T. 12 Std.
Gemergte PRs (30 T.)
38

Beschreibung

As shown in #421 if the shim version is not the same between the installation OS (could be anything really) booted when/where `bootc install to-disk --block-setup tpm2-luks` is run, the resulting system will fail to boot as PCR #7 hash changes when booted with the different EFI shim.

If a LUKS root is chosen for the installation to disk, bootc should check the shim version in the container image to be installed against the version available on the host system. If they do not agree, bootc should not proceed with the installation and produce an informative error message.

It also might be necessary to advise of restrictions with the to-disk installation workflow when using a LUKS root to ensure an installation OS is used that shares the same EFI shim as the system to be installed. This could be a documentation update or some more informative help messages produced by bootc. Or both.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start at the `bootc install to-disk --block-setup tpm2-luks` entry point and trace how the container image and host EFI shim are inspected during installation. Done means a mismatched shim version prevents installation with an informative error, with any needed restrictions or guidance reflected in help or documentation.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
rust
Bereich
operating-systems, security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.