install: Reject logically bound images with the composefs backend - #2549
Open
andrewdunndev wants to merge 2 commits into
Open
andrewdunndev wants to merge 2 commits into
andrewdunndev wants to merge 2 commits into
Conversation
The composefs backend doesn't install logically bound images, so the three that the test images bind have been missing from each composefs test system, and the bound image plans already skip composefs. The next change makes such an install fail. These images select composefs themselves and bcvk can't pass --bound-images, so remove the bindings from the composefs variants, including the published -uki dev images, until the backend supports them. Related: bootc-dev#2540 Assisted-by: AI Signed-off-by: Andrew Dunn <andrew@dunn.dev>
The composefs install path never reads /usr/lib/bootc/bound-images.d, so an image with logically bound images installs without them and exits 0. Until the backend can install them, fail instead. The check runs in prepare_install beside the other composefs option checks, so it fails before to-disk partitions or to-filesystem wipes anything, and it covers to-existing-root and images that select composefs themselves. --bound-images skip still goes ahead without them, as on ostree, and a malformed bound-images.d now fails a composefs install with the same error as an ostree one. Related: bootc-dev#2540 Assisted-by: AI Signed-off-by: Andrew Dunn <andrew@dunn.dev>
Johan-Liebert1
approved these changes
Oct 6, 2026
| composefs_options.composefs_backend |= composefs_required || composefs_default; | ||
| composefs_options.validate(config_opts.bootloader.as_ref())?; | ||
|
|
||
| composefs_options.validate_bound_images(config_opts.bound_images, &rootfs)?; |
Member
There was a problem hiding this comment.
I think this should be called from inside of composefs_options.validate, but okay for now
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
With the composefs backend,
bootc installnow fails when the image has logically bound images. Before this, it exited 0 and installed without them (#2540):The check runs in
prepare_installbesideInstallComposefsOpts::validate, so it fails before to-disk partitions or to-filesystem wipes anything, and covers to-existing-root and images that select composefs themselves.--bound-images skipstill goes ahead without them, as with ostree. A malformedbound-images.dnow fails composefs installs with the same error as ostree.Where the check runs
flowchart TD D["install to-disk"] --> P["prepare_install"] F["install to-filesystem"] --> P E["install to-existing-root"] --> F P --> C{"composefs backend,<br/>an image in bound-images.d,<br/>and no --bound-images skip?"} C -- yes --> X["error, before the disk is touched"] C -- no --> W["to-disk partitions,<br/>to-filesystem wipes"] W --> I["install_to_filesystem_impl"] I -- ostree --> O["ostree_install copies<br/>the bound images"] I -- composefs --> N["composefs branch,<br/>no bound images step"]Test images
The first commit removes the bindings from the composefs test images, including the published
-ukidev images, because they select composefs themselves and CI installs them with bcvk. Built fromfedora-bootc:44with this change, the BLS and sealed UKI test images have an emptybound-images.d. The BLS image installs through bcvk and boots, and the sealed UKI image passes its CI plans,readonlyandimage-upgrade-reboot. The bound image plans already skip composefs.bcvk
bcvk has no option for
--bound-images, so a composefs image with bound images can't be installed through it: with a binding added back, the BLS test image fails through bcvk with the error above. The error namesskip, which--helpdoesn't list. Should it?Testing
make validateand the bootc-lib unit tests pass.test_composefs_opts_validate_bound_imagesfails with any condition mutated or the method returning early, and removing the call fromprepare_installfails to compile, since the workspace denies dead code.On a test VM,
bootc install to-disk --via-loopback --filesystem ext4 --generic-image --wipe --composefs-backendoffedora-bootc:44with this bootc and one bound image exited 1 with the error above, leaving no partition table. With--bound-images skipit completed and booted on composefs. Main's bootc completed the same install with no bound image storage on the disk. On ostree the image installs with its bound image. There's no new tmt test.Related: #2540