Pin root= before the packages that can drop it (#6951)
* Pin root= before the packages that can drop it limine-entry-tool falls back to /proc/cmdline for root= only while nothing appends to KERNEL_CMDLINE. Installing omarchy-settings lands a drop-in that appends with +=, switching that fallback off, and a kernel bump in the same transaction then bakes a UKI with no root= at all. preserve_kernel_cmdline_root repaired that afterwards, so a completed upgrade booted — but the machine was unbootable for the seconds in between, and an upgrade interrupted there left it in an emergency shell. Pinning cannot wait until after the packages land, and the old guard could not be moved earlier as it was: it asked the tool for its effective cmdline, which still resolves root= through the fallback right up until the drop-in arrives, so it reported healthy on exactly the machines about to break. Ask the config layers whether root= is stated explicitly instead, for the default profile alone, and pin before the package transaction. Verification stays after it, since that is what rebuilds the UKIs. The pin no longer gates on limine-mkinitcpio being present, since it now runs before the transaction that can install it, and a machine still missing it is exactly one that needs pinning first. Verified in a VM upgrading a 3.8.0 install, sampling the UKI every 2s across the upgrade: a legacy install without the pin lost root= for ~10s, and booting that state landed in "Failed to mount '' on real root". With this change the same upgrade never loses it, and an install that already pins root= is untouched. Closes #6894 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * Merge the limine config layers when checking for a root= pin, and re-pin after the transaction The pin check returned on any line that mentioned root= under KERNEL_CMDLINE[default]. limine-entry-tool merges its layers in order, /usr/share drop-ins, /etc/limine-entry-tool.conf, /etc drop-ins, then /etc/default/limine, where = replaces and += appends, so a later layer's = could remove a pin the check still counted, and a quote before root= let systemd.setenv="root=..." read as one. Both skip the pin, which is the direction that bricks the next boot. The check now merges the layers the same way, strips only the outer double quotes the tool strips, drops quoted values the kernel does not split, and looks for root= as a parameter of its own. It was checked against limine-entry-tool --get-cmdline on a worker for every fixture in the test. Installing limine-mkinitcpio-hook runs limine-install, so a machine with no /boot/limine.conf when the pin runs ahead of the transaction can have one after it, and verification only warned about the UKI it found without root=. Verification now runs the pin for any machine the first call skipped. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Co-Authored-By: Codex Medium <noreply@openai.com> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> Co-authored-by: omarchybot <omarchybot@users.noreply.github.com> Co-authored-by: Codex Medium <noreply@openai.com>
This commit is contained in:
2 files changed
+149
-20
No files matched your search
@@ -250,8 +250,14 @@ pass "Omarchy 4 upgrade removes stale nofile drop-ins"
|
||||
|
||||
cmdline_line=$(grep -n '^preserve_kernel_cmdline_root$' "$upgrade_to_quattro" | cut -d: -f1)
|
||||
packages_line=$(grep -n '^install_omarchy_quattro_packages$' "$upgrade_to_quattro" | cut -d: -f1)
|
||||
[[ -n $cmdline_line && -n $packages_line ]] || fail "kernel cmdline preservation and package install calls exist"
|
||||
(( packages_line < cmdline_line )) || fail "kernel cmdline preservation runs once limine-mkinitcpio is installed"
|
||||
verify_line=$(grep -n '^verify_kernel_cmdline_root$' "$upgrade_to_quattro" | cut -d: -f1)
|
||||
[[ -n $cmdline_line && -n $packages_line && -n $verify_line ]] ||
|
||||
fail "kernel cmdline preservation, verification and package install calls exist"
|
||||
# The package transaction installs the += drop-in that drops root=, so the pin
|
||||
# has to be on disk before it runs or the UKI it bakes is unbootable.
|
||||
(( cmdline_line < packages_line )) || fail "kernel cmdline is pinned before the packages that can drop root="
|
||||
# The UKIs are rebuilt by the transaction, so they can only be checked after it.
|
||||
(( verify_line > packages_line )) || fail "kernel cmdline is verified after the packages are installed"
|
||||
grep -F '/etc/default/limine' "$upgrade_to_quattro" >/dev/null
|
||||
grep -F 'KERNEL_CMDLINE[default]+=" ${boot_params[*]}"' "$upgrade_to_quattro" >/dev/null
|
||||
grep -F 'cat /proc/cmdline' "$upgrade_to_quattro" >/dev/null
|
||||
@@ -260,13 +266,84 @@ grep -F 'rootflags=subvol=' "$upgrade_to_quattro" >/dev/null
|
||||
grep -F 'cryptdevice' "$upgrade_to_quattro" >/dev/null
|
||||
pass "Omarchy 4 upgrade preserves the kernel cmdline root parameters"
|
||||
|
||||
# The += drop-ins make limine-entry-tool ignore /etc/kernel/cmdline and
|
||||
# /proc/cmdline, so only the tool's own merge can say whether root= survives.
|
||||
# Queried for the default key, so a kernel-specific pin cannot cover for the
|
||||
# entries this repairs.
|
||||
grep -F 'limine-entry-tool --get-cmdline default' "$upgrade_to_quattro" >/dev/null
|
||||
grep -F "grep -qE '(^|[[:space:]])root='" "$upgrade_to_quattro" >/dev/null
|
||||
pass "Omarchy 4 upgrade asks limine-entry-tool whether root= survives"
|
||||
# The tool's effective cmdline still resolves root= from /proc/cmdline until the
|
||||
# first += drop-in lands, so it reads healthy on exactly the machines about to
|
||||
# break. Ask the config layers whether root= is stated instead, for the default
|
||||
# key alone so a fallback or kernel-specific pin cannot cover for it.
|
||||
grep -F 'kernel_cmdline_root_pinned' "$upgrade_to_quattro" >/dev/null
|
||||
grep -F 'KERNEL_CMDLINE\[default\]' "$upgrade_to_quattro" >/dev/null
|
||||
! grep -F 'limine-entry-tool --get-cmdline' "$upgrade_to_quattro" >/dev/null ||
|
||||
fail "the pin check does not depend on the fallback it is about to lose"
|
||||
pass "Omarchy 4 upgrade checks whether root= is pinned in the limine config"
|
||||
|
||||
# Run the pin check against fixture config layers. A false positive skips the
|
||||
# pin and the next boot has no root=; a false negative appends a second pin.
|
||||
eval "$(sed -n '/^kernel_cmdline_root_pinned() {$/,/^}$/p' "$upgrade_to_quattro")"
|
||||
pin_root=$(mktemp -d)
|
||||
trap 'rm -rf "$pin_root"' EXIT
|
||||
as_root() {
|
||||
local script=${3//\/etc\//$pin_root/etc/}
|
||||
bash -c "${script//\/usr\/share\//$pin_root/usr/share/}"
|
||||
}
|
||||
# Takes pairs of a config layer and a line to append to it.
|
||||
root_pinned() {
|
||||
rm -rf "${pin_root:?}"/{etc,usr}
|
||||
mkdir -p "$pin_root/etc/default" "$pin_root/etc/limine-entry-tool.d" "$pin_root/usr/share/limine-entry-tool.d"
|
||||
while (($#)); do
|
||||
printf '%s\n' "$2" >>"$pin_root/$1"
|
||||
shift 2
|
||||
done
|
||||
kernel_cmdline_root_pinned
|
||||
}
|
||||
root_pinned etc/default/limine 'KERNEL_CMDLINE[default]+=" root=UUID=abc rw"' || fail "a quoted root= pin is recognised"
|
||||
root_pinned etc/default/limine 'KERNEL_CMDLINE[default]=root=UUID=abc' || fail "an unquoted root= pin is recognised"
|
||||
root_pinned etc/default/limine 'KERNEL_CMDLINE[default]+=" dm-mod.create="foo" root=UUID=abc rw"' ||
|
||||
fail "a pin with a quoted parameter before root= is recognised"
|
||||
root_pinned usr/share/limine-entry-tool.d/root.conf 'KERNEL_CMDLINE[default]+="root=UUID=abc"' \
|
||||
etc/default/limine 'KERNEL_CMDLINE[default]+=" rw"' || fail "an appending layer keeps an earlier pin"
|
||||
root_pinned etc/default/limine 'KERNEL_CMDLINE[default] += " root=UUID=abc rw"' || fail "a pin spaced around += is recognised"
|
||||
! root_pinned etc/default/limine "KERNEL_CMDLINE[default]+='root=UUID=abc rw'" ||
|
||||
fail "single quotes are kept, as limine-entry-tool keeps them"
|
||||
! root_pinned etc/default/limine 'OLD_KERNEL_CMDLINE[default]+=" root=UUID=abc rw"' || fail "a renamed key is not a pin"
|
||||
! root_pinned etc/default/limine '# KERNEL_CMDLINE[default]+=" root=UUID=abc rw"' || fail "a commented-out pin is not a pin"
|
||||
! root_pinned etc/default/limine 'KERNEL_CMDLINE[fallback]+=" root=UUID=abc rw"' || fail "a fallback-only pin does not cover default"
|
||||
! root_pinned etc/default/limine 'KERNEL_CMDLINE[default]+=" rootflags=subvol=@ rw"' || fail "rootflags= is not root="
|
||||
! root_pinned etc/default/limine 'KERNEL_CMDLINE[default]+=" systemd.setenv="root=UUID=abc" rw"' ||
|
||||
fail "root= inside another parameter's value is not a pin"
|
||||
! root_pinned etc/default/limine 'KERNEL_CMDLINE[default]+=" systemd.setenv="NOTE=x root=UUID=abc" rw"' ||
|
||||
fail "root= after a space inside a quoted value is not a pin"
|
||||
! root_pinned etc/default/limine 'KERNEL_CMDLINE[default]=systemd.setenv="NOTE=x root=UUID=abc rw' ||
|
||||
fail "root= after an unmatched quote is not a pin"
|
||||
! root_pinned etc/default/limine 'KERNEL_CMDLINE[default]=ro"x"ot=UUID=abc rw' ||
|
||||
fail "a quoted segment inside a parameter name does not make it root="
|
||||
! root_pinned etc/limine-entry-tool.conf 'KERNEL_CMDLINE[default]=root=UUID=abc rw' \
|
||||
etc/default/limine 'KERNEL_CMDLINE[default]=quiet' || fail "a pin replaced by a later layer is not a pin"
|
||||
! root_pinned etc/default/limine 'KERNEL_CMDLINE[default]+=" root=UUID=abc rw"' \
|
||||
etc/default/limine 'KERNEL_CMDLINE[default]="quiet"' || fail "a pin replaced later in the same layer is not a pin"
|
||||
unset -f as_root
|
||||
pass "Omarchy 4 upgrade recognises exactly the root= pins that hold"
|
||||
|
||||
# Installing the limine packages can deploy limine on a machine that had no
|
||||
# limine.conf when the pin ran, so verification pins whatever the first call skipped.
|
||||
(
|
||||
eval "$(sed -n '/^kernel_cmdline_root_checked=/p;/^preserve_kernel_cmdline_root() {$/,/^}$/p;/^verify_kernel_cmdline_root() {$/,/^}$/p' "$upgrade_to_quattro")"
|
||||
limine_conf=0 pin_checks=0
|
||||
as_root() {
|
||||
if [[ $1 == "test" ]]; then
|
||||
((limine_conf))
|
||||
fi
|
||||
}
|
||||
kernel_cmdline_root_pinned() { ((++pin_checks)); }
|
||||
limine-mkinitcpio() { :; }
|
||||
preserve_kernel_cmdline_root
|
||||
((pin_checks == 0)) || fail "the pin waits for a limine.conf"
|
||||
limine_conf=1
|
||||
verify_kernel_cmdline_root
|
||||
((pin_checks == 1)) || fail "kernel cmdline verification pins a machine the transaction put on limine"
|
||||
verify_kernel_cmdline_root
|
||||
((pin_checks == 1)) || fail "kernel cmdline verification pins a machine only once"
|
||||
)
|
||||
pass "Omarchy 4 upgrade pins root= on machines the transaction moves to limine"
|
||||
|
||||
# The crypt layer hides in the parents on LVM-on-LUKS, and a partial cmdline
|
||||
# for an encrypted root must not be written at all.
|
||||
|
||||
Reference in new issue
Block a user