Skip to content

fix: images ship root locked, or the build fails; stamp the build date - #31

Merged
marcos-mendez merged 1 commit into
19.xfrom
fix/image-ships-root-locked
Oct 2, 2026
Merged

marcos-mendez merged 1 commit into
19.xfrom
fix/image-ships-root-locked

Conversation

@marcos-mendez

Copy link
Copy Markdown
Collaborator

Layer (a) of the review finding on Keel-Linux/inithooks#35: Keep must never be offered for a password the image itself shipped.

  • mk/turnkey/seal-root, run last in root.patched/post of mk/turnkey.mk: fails the build unless root's shadow field is exactly *, ! or !* (what passwd --lock makes of *). The field is compared, never printed. Then it writes the build date, UTC, to /etc/keel/build-date, the stamp inithooks compares the password's last change against.
  • conf/turnkey.d/rootpass and conf/samba-rootpass ignore a build time ROOT_PASS (a line says so, without the value): it gave every copy the same password. The first boot preseed ROOT_PASS (inithooks) is untouched. turnkey-desktop.mk is left as it is.
  • Five older WordPress images shipped U6aMy0wojraho (the crypt of the empty string). seal-root refuses it, and so does inithooks#35.

Tests (written first)

tests/seal-root.bats (new, 100 percent of seal-root's lines under kcov): accepts *, !, !* and stamps the date; refuses a hash (not printed), the empty-password hash, an empty field, a locked hash, a missing root entry, a missing shadow file; checks that turnkey.mk calls it last. The ROOT_PASS tests in rootpass.bats, samba-rootpass.bats and before-firstboot.bats now expect it ignored.

Test plan

  • CI green
  • Next image build: /etc/keel/build-date present, root * in the tar.zst

mk/turnkey/seal-root, last in root.patched/post, fails the build unless
root's shadow field is '*', '!' or '!*' (never printed) and writes
/etc/keel/build-date. ROOT_PASS is ignored at build time by rootpass and
samba-rootpass, with a line that does not carry its value.

inithooks' first boot offers Keep for a root password set at container
creation only when it changed on or after this date; an image that
shipped a password (ROOT_PASS, or U6aMy0wojraho in older WordPress
images) must never have it offered as recommended.
@marcos-mendez
marcos-mendez merged commit 8e1f2ee into 19.x Oct 2, 2026
7 checks passed
marcos-mendez pushed a commit that referenced this pull request Oct 2, 2026
Rebased onto 19.x after common#30 and #31. The root.patched/post recipe
of mk/turnkey.mk now ends in mk/turnkey/seal-root (#31), which the fab
stubs of tests/mk-identity.bats did not reach, so three of its tests
failed. The harness links the real seal-root under its FAB_PATH and gives
the scratch root a locked root, and asserts what both changes promise:
both identity files, the build date stamped last, a shipped root
password refused, and no per-appliance apt User-Agent written (#6), which
this branch's makefiles used to write before the rebase.

The feature gets its bullet in the unreleased changelog entry.
marcos-mendez pushed a commit that referenced this pull request Oct 2, 2026
Rebased onto 19.x after common#30 and #31. The root.patched/post recipe
of mk/turnkey.mk now ends in mk/turnkey/seal-root (#31), which the fab
stubs of tests/mk-identity.bats did not reach, so three of its tests
failed. The harness links the real seal-root under its FAB_PATH and gives
the scratch root a locked root, and asserts what both changes promise:
both identity files, the build date stamped last, a shipped root
password refused, and no per-appliance apt User-Agent written (#6), which
this branch's makefiles used to write before the rebase.

The feature gets its bullet in the unreleased changelog entry.
marcos-mendez pushed a commit that referenced this pull request Oct 2, 2026
Rebased onto 19.x after common#30 and #31. The root.patched/post recipe
of mk/turnkey.mk now ends in mk/turnkey/seal-root (#31), which the fab
stubs of tests/mk-identity.bats did not reach, so three of its tests
failed. The harness links the real seal-root under its FAB_PATH and gives
the scratch root a locked root, and asserts what both changes promise:
both identity files, the build date stamped last, a shipped root
password refused, and no per-appliance apt User-Agent written (#6), which
this branch's makefiles used to write before the rebase.

The feature gets its bullet in the unreleased changelog entry.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant