mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-27 16:51:12 -07:00
Mount the rootfs read-only on both images
The rootfs mounted read-write, so a slot ran with its own files open to change, and the factory-slot mounts rode along on the release image. Both images now carry the read-only-rootfs feature: the ro root line and the rcS default, the volatile links made at rootfs time, a writable copy of /var/lib at boot, a build failure for a post-install that needs the machine, and the removal of shadow, base-passwd, update-rc.d and update-alternatives. What must last or change at run time is handled file by file: - forgefirm-users renders the four account files from the record into /run/forgefirm/accounts and bind-mounts each copy over its /etc file (useradd and the rest are gone with shadow); a render writes through the mount, and the image's own files apply until the first render. - forgefirm-banner bind-mounts a copy of /etc/issue and writes the address block through it. - sshd keeps its host keys under /data/forgefirm/ssh, so the fingerprint survives updates; both sshd configs carry the same HostKey lines. - forgefirm-logging passes logrotate a state file under /var/run (logrotate refuses to run without one). - forgefirm-persist points the boot timestamp and the random seed at /data/forgefirm. The dev image appends the /factory slot mounts, without nofail (busybox mount hands it to the kernel, which rejects it). The rootfs command entries lose their semicolons: on scarthgap the value is the task's vardeps, split on whitespace, so "name;" left the function body out of the signature and a changed body did not remake the rootfs; with the bodies tracked, the dev image's DATETIME string needs a vardepsexclude. release.sh gains the read-only gate (root ro, no /factory line, ROOTFS_READ_ONLY=yes, host keys on /data). image.health checks the mounts, the account binds, the banner bind, the host keys and the dev-only /factory mounts. Proven on the bench reference (dev image 20260909140901): / ro, /data rw, /var/lib a tmpfs copy, the four account files and /etc/issue bound from tmpfs, the host keys in /data/forgefirm/ssh, no "Read-only file system" line in any log; forgectrl.auth and commission.account-login (a temporary account rendered, logged in over HTTPS and removed again), kernel.latch-locked-idle and motion.liveness-probe PASS; logrotate runs with the volatile state. forgetest unit tests 335 OK; both images build clean, and debugfs on the built rootfs shows every setting above.
This commit is contained in:
@@ -1,8 +1,9 @@
|
||||
SUMMARY = "ForgeFIRM operator accounts: record replay and the root shell warning"
|
||||
DESCRIPTION = "Replays the account record (/data/forgefirm/users, written \
|
||||
by forgectrl) into the system account files at boot and on reload, \
|
||||
removes the local accounts the record does not name, and installs the \
|
||||
warning an interactive root shell prints."
|
||||
SUMMARY = "ForgeFIRM operator accounts: record render and the root shell warning"
|
||||
DESCRIPTION = "Renders the account record (/data/forgefirm/users, written \
|
||||
by forgectrl) into the system account files at boot and on reload. The \
|
||||
rootfs is read-only: the four files show tmpfs copies, bind-mounted, and \
|
||||
a render writes through them; the accounts the record does not name are \
|
||||
left out. Also installs the warning an interactive root shell prints."
|
||||
LICENSE = "MIT"
|
||||
LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda2f7b4f302"
|
||||
|
||||
@@ -16,12 +17,12 @@ S = "${WORKDIR}"
|
||||
inherit update-rc.d
|
||||
|
||||
INITSCRIPT_NAME = "forgefirm-users"
|
||||
# 05: rcS has run (mountall mounted /data at S03) and sshd starts at
|
||||
# S09, so the accounts exist before the first login can arrive.
|
||||
# 05: rcS has run (mountall mounted /data and /run at S03) and sshd starts
|
||||
# at S09, so the accounts exist before the first login can arrive.
|
||||
INITSCRIPT_PARAMS = "start 05 2 3 4 5 ."
|
||||
|
||||
# useradd, groupadd, usermod, userdel, groupdel
|
||||
RDEPENDS:${PN} += "shadow"
|
||||
# No shadow tools: the read-only-rootfs image feature drops the shadow
|
||||
# package from the image, and the script writes the account lines itself.
|
||||
|
||||
do_install() {
|
||||
install -Dm 0755 ${WORKDIR}/forgefirm-users.init ${D}${sysconfdir}/init.d/forgefirm-users
|
||||
|
||||
Reference in New Issue
Block a user