Repository navigation
fix: images ship root locked, or the build fails; stamp the build date - #31
Merged
Merged
Conversation
mk/turnkey/seal-root, last in root.patched/post, fails the build unless root's shadow field is '*', '!' or '!*' (never printed) and writes /etc/keel/build-date. ROOT_PASS is ignored at build time by rootpass and samba-rootpass, with a line that does not carry its value. inithooks' first boot offers Keep for a root password set at container creation only when it changed on or after this date; an image that shipped a password (ROOT_PASS, or U6aMy0wojraho in older WordPress images) must never have it offered as recommended.
3 tasks
3 of 5 tasks
marcos-mendez
pushed a commit
that referenced
this pull request
Oct 2, 2026
Rebased onto 19.x after common#30 and #31. The root.patched/post recipe of mk/turnkey.mk now ends in mk/turnkey/seal-root (#31), which the fab stubs of tests/mk-identity.bats did not reach, so three of its tests failed. The harness links the real seal-root under its FAB_PATH and gives the scratch root a locked root, and asserts what both changes promise: both identity files, the build date stamped last, a shipped root password refused, and no per-appliance apt User-Agent written (#6), which this branch's makefiles used to write before the rebase. The feature gets its bullet in the unreleased changelog entry.
3 of 4 tasks
marcos-mendez
pushed a commit
that referenced
this pull request
Oct 2, 2026
Rebased onto 19.x after common#30 and #31. The root.patched/post recipe of mk/turnkey.mk now ends in mk/turnkey/seal-root (#31), which the fab stubs of tests/mk-identity.bats did not reach, so three of its tests failed. The harness links the real seal-root under its FAB_PATH and gives the scratch root a locked root, and asserts what both changes promise: both identity files, the build date stamped last, a shipped root password refused, and no per-appliance apt User-Agent written (#6), which this branch's makefiles used to write before the rebase. The feature gets its bullet in the unreleased changelog entry.
marcos-mendez
pushed a commit
that referenced
this pull request
Oct 2, 2026
Rebased onto 19.x after common#30 and #31. The root.patched/post recipe of mk/turnkey.mk now ends in mk/turnkey/seal-root (#31), which the fab stubs of tests/mk-identity.bats did not reach, so three of its tests failed. The harness links the real seal-root under its FAB_PATH and gives the scratch root a locked root, and asserts what both changes promise: both identity files, the build date stamped last, a shipped root password refused, and no per-appliance apt User-Agent written (#6), which this branch's makefiles used to write before the rebase. The feature gets its bullet in the unreleased changelog entry.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Layer (a) of the review finding on Keel-Linux/inithooks#35: Keep must never be offered for a password the image itself shipped.
mk/turnkey/seal-root, run last inroot.patched/postofmk/turnkey.mk: fails the build unless root's shadow field is exactly*,!or!*(whatpasswd --lockmakes of*). The field is compared, never printed. Then it writes the build date, UTC, to/etc/keel/build-date, the stamp inithooks compares the password's last change against.conf/turnkey.d/rootpassandconf/samba-rootpassignore a build timeROOT_PASS(a line says so, without the value): it gave every copy the same password. The first boot preseedROOT_PASS(inithooks) is untouched.turnkey-desktop.mkis left as it is.U6aMy0wojraho(the crypt of the empty string). seal-root refuses it, and so does inithooks#35.Tests (written first)
tests/seal-root.bats(new, 100 percent of seal-root's lines under kcov): accepts*,!,!*and stamps the date; refuses a hash (not printed), the empty-password hash, an empty field, a locked hash, a missing root entry, a missing shadow file; checks that turnkey.mk calls it last. The ROOT_PASS tests inrootpass.bats,samba-rootpass.batsandbefore-firstboot.batsnow expect it ignored.Test plan
/etc/keel/build-datepresent, root*in the tar.zst