Repository navigation
Enable ACL confidential VM boot and harden Azure time synchronization - #61
Conversation
|
Is this all we were missing to unlock encrypted rootfs on boot? |
These were the remaining blockers in our validation, the TPM2 libraries needed for auto-unlock and the decrypt-root ordering fix. The LUKS/dracut support was already added in #33. With these changes, encrypted ROOT now unlocks and boots successfully in our CVM test. |
|
While this is still in draft — could you fill in the description before marking it ready? Right now it's the unmodified template: no change-type ticked, empty "Test details:", and no linked issue. Given this touches initramfs root decryption and time sync on every Azure image, the things I'd most want recorded are:
Also worth revisiting the title — "Add ACL CVM support" undersells it a bit, since four of the seven files change chrony behaviour on every Azure image rather than just CVMs. |
0dd6275 to
1675739
Compare
There was a problem hiding this comment.
🟡 Changes recommended
The initramfs TPM2 library inclusion is currently /usr/lib64-only, which can omit required libs on non-lib64 layouts and break LUKS root auto-unlock.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR enables Azure Confidential VM boot support (TPM-backed LUKS root auto-unlock) and hardens Azure time synchronization by making Hyper-V PTP optional/non-blocking while retaining a public NTP fallback.
Changes:
- Add a chrony helper (
chrony-azure-ptp) and systemd drop-in to generate PTP chrony config at service start when/dev/ptp_hypervexists. - Add TPM2 (tss2) shared libraries to the initramfs explicit install list to support runtime
dlopen()bysystemd-cryptsetup. - Patch bootengine’s
decrypt-root.serviceordering to run beforeinitrd-root-device.target.
File summaries
| File | Description |
|---|---|
| sdk_container/src/third_party/coreos-overlay/coreos-base/oem-azure/files/manglefs_rpm.sh | Adjusts chronyd unit customization, removes unsupported ExecStopPost helper, and installs the Azure PTP helper + drop-in. |
| sdk_container/src/third_party/coreos-overlay/coreos-base/oem-azure/files/chrony.conf | Switches to include Azure runtime-generated chrony config and reintroduces time.windows.com fallback. |
| sdk_container/src/third_party/coreos-overlay/coreos-base/oem-azure/files/chrony-hyperv.conf | Updates chronyd drop-in to avoid waiting for Hyper-V PTP while still ordering after it when present, and runs PTP config generator. |
| sdk_container/src/third_party/coreos-overlay/coreos-base/oem-azure/files/chrony-azure-ptp | New helper script that writes/removes the PTP refclock config under /run/chrony-azure/conf.d. |
| build_library/rpm/additional_files/99-acl.conf | Adds explicit TPM2 shared library inclusion for initramfs root auto-unlock support. |
| acl/SPECS/bootengine/bootengine.spec | Bumps release and applies new decrypt-root ordering patch. |
| acl/SPECS/bootengine/0003-decrypt-root-fix-firstboot-ordering.patch | Ensures decrypt-root runs before initrd-root-device.target to preserve firstboot ordering. |
Review details
- Files reviewed: 7/7 changed files
- Comments generated: 3
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
1675739 to
c9f47cb
Compare
There was a problem hiding this comment.
🔵 Needs a closer look
It changes early-boot/initramfs composition and systemd ordering for encrypted-root bring-up, which is high impact and best gated by final human review.
Review details
- Files reviewed: 8/8 changed files
- Comments generated: 0 new
- Review effort level: Lite
Use the signed ACL production Azure Compute Gallery images for amd64, arm64, and CVM VHD builds. Pin amd64 to 20260923.1209152.0 and arm64 to 20260923.1209110.0. Route ACL CVM through the amd64 ACG source instead of Marketplace coordinates. Preserve empty Marketplace SKU arguments in the content tests so ACL retains its cron-permission exemption. Prefix the optional IMG_SKU and FEATURE_FLAGS values at the Run Command boundary, then remove those prefixes in the VM script. This prevents empty arguments from shifting the commit SHA and repository URL while preserving exact-commit checkout and legacy unprefixed callers. Add transport round-trip regressions for empty values, ACL/FIPS/CVM and non-ACL flags, literal prefixes, custom repository URLs, and the legacy repository default. Temporarily skip testChrony only for ACL images with the exact cvm feature flag, before any service checks or clock mutation. Log the waiver explicitly and retain the package endpoint test and all other image validation. Remove this exception once the pinned ACL base image includes microsoft/azure-container-linux#61. Add 19 Chrony regression cases covering the real call site, combined flags, non-CVM ACL, other OSes, and preserved service/time-correction failures. The four waiver cases fail before the change; all 56 focused examples pass afterward. Bash lint and syntax checks pass with no new POSIX diagnostics. Signed-off-by: Aadhar Agarwal <aadagarwal@microsoft.com>
Use the signed ACL production Azure Compute Gallery images for amd64, arm64, and CVM VHD builds. Pin amd64 to 20260923.1209152.2 and arm64 to 20260923.1209110.1. Route ACL CVM through the amd64 ACG source instead of Marketplace coordinates. Preserve empty Marketplace SKU arguments in the content tests so ACL retains its cron-permission exemption. Prefix the optional IMG_SKU and FEATURE_FLAGS values at the Run Command boundary, then remove those prefixes in the VM script. This prevents empty arguments from shifting the commit SHA and repository URL while preserving exact-commit checkout and legacy unprefixed callers. Add transport round-trip regressions for empty values, ACL/FIPS/CVM and non-ACL flags, literal prefixes, custom repository URLs, and the legacy repository default. Temporarily skip testChrony only for ACL images with the exact cvm feature flag, before any service checks or clock mutation. Log the waiver explicitly and retain the package endpoint test and all other image validation. Remove this exception once the pinned ACL base image includes microsoft/azure-container-linux#61. Add 19 Chrony regression cases covering the real call site, combined flags, non-CVM ACL, other OSes, and preserved service/time-correction failures. The four waiver cases fail before the change; all 56 focused examples pass afterward. Bash lint and syntax checks pass with no new POSIX diagnostics. Use ACL publish run 1214376, which reused the exact bundle tags and digests from run 1209759 and published to all destinations with West Europe included in gallery replication. Signed-off-by: Aadhar Agarwal <aadagarwal@microsoft.com>
Use signed production ACG images replicated to West Europe: amd64 20260923.1209152.2, arm64 20260923.1209110.1. Preserve empty test arguments and temporarily skip ACL CVM Chrony until microsoft/azure-container-linux#61 is included. Signed-off-by: Aadhar Agarwal <aadagarwal@microsoft.com>
…t merge) Experiment only, do not merge. Builds the ACL CVM VHD (buildaclcvmgen2) on the microsoft/azure-container-linux#61 PR validation image 035db282-f1c8-4ce7-b78f-2a7265d5398c-ACLDEVEL/acldevel-gh-amd64/0.20261007.1219462 to check whether the chrony fix clears the known testChrony failures. The PR image's UKI is dev-signed, so the CVM test and scan VMs boot with Secure Boot off. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Thanks, have updated now to extracts the list and checks it's non-empty before touching the archive, failing through the existing cleanup path. |
|
The new |
|
The new initramfs check searches |
c4bcad4 to
3d64086
Compare
There was a problem hiding this comment.
🟡 Changes recommended
The encrypted-root dependency ordering has a critical unresolved issue, and the changed OEM package needs a revision bump.
1 open finding
🧠 Review effort: Lite
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
3d64086 to
8fe0429
Compare
|
Could we coordinate the downstream image customization update before it consumes this change? Both Please re-audit the downstream Chrony overrides against the new PTP source generation, then update the stock-file pins in coordination with this PR rather than refreshing the hashes alone. |
Now we are retaining the TPM2 dracut module, so I've dropped both the explicit install_items and the assertion entirely. Nothing left to check. |
Measured it on a VM, time.windows.com reports root delay 61us / dispersion 10.2ms, so ~10ms root distance against chrony's 3s default. Setting maxdistance 16.0 explicitly changed nothing, so I've left it off rather than widen acceptance for every source. |
Now we are retaining the TPM2 dracut module, so I've dropped both the explicit install_items and the assertion entirely. Nothing left to check. |
Rather than just refreshing the hashes, acl-t's refclock now gets trust: without it a disagreement between the host clock and the network source marks both falsetickers and chronyd stops syncing entirely (reproduced on a VM). Pins updated to match. Needs to merge alongside the current PR since they track those exact files. pipeline -> |


Summary
Enable ACL confidential VM boot and harden Azure time synchronization
doc - https://microsoftapc-my.sharepoint.com/:w:/r/personal/mayansingh_microsoft_com/_layouts/15/Doc.aspx?sourcedoc=%7Bebae3a07-f597-4c65-96f0-143459146fb9%7D&action=default
Summary
Adds Azure Confidential VM support and hardens Azure time synchronization.
Change Log
Type of Change
Does this affect the image build?
Associated Issues
https://dev.azure.com/mariner-org/ACL/_workitems/edit/23679
Test Methodology
Test details:
Merge Checklist
All applicable boxes should be checked before merging