Skip to content

install: Reject logically bound images with the composefs backend - #2549

Open
andrewdunndev wants to merge 2 commits into
bootc-dev:mainfrom
andrewdunndev:fix/composefs-reject-bound-images
Open

andrewdunndev wants to merge 2 commits into
bootc-dev:mainfrom
andrewdunndev:fix/composefs-reject-bound-images

Conversation

@andrewdunndev

Copy link
Copy Markdown
Contributor

With the composefs backend, bootc install now fails when the image has logically bound images. Before this, it exited 0 and installed without them (#2540):

error: Installing to disk: Logically bound images are not supported with the composefs backend (found docker.io/library/busybox:latest); use --bound-images skip to install without them

The check runs in prepare_install beside InstallComposefsOpts::validate, so it fails before to-disk partitions or to-filesystem wipes anything, and covers to-existing-root and images that select composefs themselves. --bound-images skip still goes ahead without them, as with ostree. A malformed bound-images.d now fails composefs installs with the same error as ostree.

Where the check runs

flowchart TD
    D["install to-disk"] --> P["prepare_install"]
    F["install to-filesystem"] --> P
    E["install to-existing-root"] --> F
    P --> C{"composefs backend,<br/>an image in bound-images.d,<br/>and no --bound-images skip?"}
    C -- yes --> X["error, before the disk is touched"]
    C -- no --> W["to-disk partitions,<br/>to-filesystem wipes"]
    W --> I["install_to_filesystem_impl"]
    I -- ostree --> O["ostree_install copies<br/>the bound images"]
    I -- composefs --> N["composefs branch,<br/>no bound images step"]
Loading

Test images

The first commit removes the bindings from the composefs test images, including the published -uki dev images, because they select composefs themselves and CI installs them with bcvk. Built from fedora-bootc:44 with this change, the BLS and sealed UKI test images have an empty bound-images.d. The BLS image installs through bcvk and boots, and the sealed UKI image passes its CI plans, readonly and image-upgrade-reboot. The bound image plans already skip composefs.

bcvk

bcvk has no option for --bound-images, so a composefs image with bound images can't be installed through it: with a binding added back, the BLS test image fails through bcvk with the error above. The error names skip, which --help doesn't list. Should it?

Testing

make validate and the bootc-lib unit tests pass. test_composefs_opts_validate_bound_images fails with any condition mutated or the method returning early, and removing the call from prepare_install fails to compile, since the workspace denies dead code.

On a test VM, bootc install to-disk --via-loopback --filesystem ext4 --generic-image --wipe --composefs-backend of fedora-bootc:44 with this bootc and one bound image exited 1 with the error above, leaving no partition table. With --bound-images skip it completed and booted on composefs. Main's bootc completed the same install with no bound image storage on the disk. On ostree the image installs with its bound image. There's no new tmt test.

Related: #2540

The composefs backend doesn't install logically bound images, so the
three that the test images bind have been missing from each composefs
test system, and the bound image plans already skip composefs. The next
change makes such an install fail. These images select composefs
themselves and bcvk can't pass --bound-images, so remove the bindings
from the composefs variants, including the published -uki dev images,
until the backend supports them.

Related: bootc-dev#2540

Assisted-by: AI
Signed-off-by: Andrew Dunn <andrew@dunn.dev>
The composefs install path never reads /usr/lib/bootc/bound-images.d,
so an image with logically bound images installs without them and
exits 0. Until the backend can install them, fail instead. The check
runs in prepare_install beside the other composefs option checks, so
it fails before to-disk partitions or to-filesystem wipes anything,
and it covers to-existing-root and images that select composefs
themselves. --bound-images skip still goes ahead without them, as on
ostree, and a malformed bound-images.d now fails a composefs install
with the same error as an ostree one.

Related: bootc-dev#2540

Assisted-by: AI
Signed-off-by: Andrew Dunn <andrew@dunn.dev>
@github-actions github-actions Bot added the area/install Issues related to `bootc install` label Oct 5, 2026
@bootc-bot
bootc-bot Bot requested a review from jeckersb October 5, 2026 21:36
Comment thread crates/lib/src/install.rs
composefs_options.composefs_backend |= composefs_required || composefs_default;
composefs_options.validate(config_opts.bootloader.as_ref())?;

composefs_options.validate_bound_images(config_opts.bound_images, &rootfs)?;

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this should be called from inside of composefs_options.validate, but okay for now

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/install Issues related to `bootc install`

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants