Skip to content

Make explicit hash signature partitions - #88

Open
bfjelds (bfjelds) wants to merge 4 commits into
aclmainfrom
user/bfjelds/usr-hash-signature-split
Open

bfjelds (bfjelds) wants to merge 4 commits into
aclmainfrom
user/bfjelds/usr-hash-signature-split

Conversation

@bfjelds

@bfjelds bfjelds (bfjelds) commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Summary

Split bigger HASH partitions into more appropriately sized HASH and HASH-SIGN partitions to enable hash signatures.

Change Log

  • Split HASH into new HASH and HASH-SIGN A/B partitions

Type of Change

  • Image build change (base image, sysexts, OEM images)
  • Package/SPEC update
  • CI/automation change
  • SDK/toolchain update
  • Configuration change
  • Documentation update
  • Bug fix

Does this affect the image build?

  • Yes
  • No

Associated Issues

Test Methodology

Merge Checklist

All applicable boxes should be checked before merging

  • Image builds successfully with this change (or image build is not affected)
  • Any updated packages/SPECs build successfully
  • Relevant kola tests pass
  • All package sources are available
  • Source files have up-to-date hashes/manifests
  • Documentation has been updated to match any changes
  • Ready to merge

@bfjelds
bfjelds (bfjelds) requested a balanced review from Copilot October 2, 2026 21:32

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Copilot review overview

Review effort: Lite
Findings: 3 Medium severity · 1 Low severity

Open (4)
What changed in this PR

Splits the existing /usr dm-verity HASH partitions into separate HASH and reserved HASH-SIG partitions to enable future verity root-hash signatures, and updates partition type resolution/documentation accordingly.

Changes:

  • Added a new DPS partition type placeholder (dps-usr-verity-sig) with architecture-specific GUIDs.
  • Updated UKI disk layout to split HASH into HASH + HASH-SIG partitions and renumber subsequent partitions/references.
  • Documented the new reserved HASH-SIG partition in ACL architecture docs.
File Description
build_library/​disk_util Adds GUID mapping and placeholder resolution for the new signature partition type.
build_library/​disk_layout_uki.json Splits HASH-A/B into HASH + HASH-SIG, adjusts sizing/alignment, and renumbers partitions/references.
acl/​docs/​architecture.md Documents the new reserved HASH-SIG partition following HASH-A.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread build_library/disk_layout_uki.json Outdated
Comment thread build_library/disk_layout_uki.json Outdated
Comment thread build_library/disk_layout_uki.json Outdated
Comment thread acl/docs/architecture.md Outdated
@bfjelds
bfjelds (bfjelds) requested a balanced review from Copilot October 2, 2026 22:09

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread acl/docs/architecture.md Outdated
Comment thread build_library/disk_layout_uki.json Outdated
Comment thread build_library/disk_layout_uki.json Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The shipped disk-layout change needs actual image-build and boot/kola validation before human approval.

Review effort: Balanced
Findings: None

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The shipped disk-layout change still needs successful image-build and boot validation.

Review effort: Balanced
Findings: 1 Low severity

Open (1)

Comment thread build_library/disk_layout_uki.json
Copilot AI balanced review requested due to automatic review settings October 5, 2026 18:55

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Boot-critical partition renumbering requires human confirmation of image boot and update compatibility with the coordinated Trident changes.

Review effort: Balanced
Findings: None

Resolved since last review (1)

bfjelds (bfjelds) and others added 4 commits October 7, 2026 21:46
…tion

Replace the single 10 MiB HASH-A/HASH-B partitions with two partitions
each: HASH-A/HASH-B (exact 9 MiB, verity hash tree, dps-usr-verity)
and HASH-SIG-A/HASH-SIG-B (exact 1 MiB, reserved for a future verity
root-hash signature, dps-usr-verity-sig). Add DPS_USR_VERITY_SIG_GUIDS
to disk_util alongside the existing DPS_USR_VERITY_GUIDS constants,
using the official UAPI Discoverable Partitions Specification GUIDs
for the usr-verity-sig partition type (x86_64 and aarch64), so the new
partitions are resolved the same way as the existing verity/root types
instead of using the generic data GUID.

Total space per slot is unchanged; subsequent partitions (OEM, ROOT)
and all verity_hash/layout references are renumbered accordingly.
disk_util aligns every partition start up to part_alignment (4096
blocks/2MiB) before placing it. Because HASH-A/HASH-B (18432 blocks =
9 MiB) and HASH-SIG-A/HASH-SIG-B (2048 blocks = 1 MiB) are not
themselves multiples of 4096, the default alignment silently inserted
four 1 MiB padding gaps (before each HASH-SIG and before USR-B/OEM)
that belong to no partition and cannot be used - 4 MiB of dead space
per disk image, contradicting the intent that splitting HASH into
HASH+HASH-SIG not change total footprint.

Override part_alignment to 2048 (1 MiB) on HASH-SIG-A/B specifically:
they do not need 2 MiB alignment (small, non-performance-sensitive
signature partitions), and since HASH-A + HASH-SIG-A (9 MiB + 1 MiB =
10 MiB) is itself a 2 MiB multiple, this removes the gap with no
other side effects - every downstream partition offset (USR-B, HASH-B,
HASH-SIG-B, OEM, ROOT) and the final disk image size now exactly match
the original pre-split layout.

Verified via disk_util.LoadPartitionConfig: zero gaps, and every
partition offset after HASH-A matches the pre-split baseline exactly.
- disk_layout_uki.json: expand HASH-A/_B _comment with verity hash
  tree sizing rationale (sha256 + 4096-byte blocks assumption, ~8.08
  MiB computed size vs 9 MiB allocated). Clarify blocks/part_alignment
  units are 512-byte sectors on the new HASH-SIG-A/B entries.
- architecture.md: split the HASH-A/HASH-SIG-A bullet into two for
  readability.
The usr-hash-sig-a/b partitions shift ROOT from the 7th to the 9th
partition on the new layout. Hard-coding `nbd0p7` and `max_part=8`
broke the documented verification steps.

Select ROOT by GPT partition label instead of a hard-coded index, so
the commands work for both the old and new layouts.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 7, 2026 21:46
@bfjelds
bfjelds (bfjelds) force-pushed the user/bfjelds/usr-hash-signature-split branch from 629c9e3 to 4af23f0 Compare October 7, 2026 21:46

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Trident support has merged, but compatible package publication to PMC and inclusion in image builds remain unverified.

0 open findings

🧠 Review effort: Balanced

@bfjelds

Copy link
Copy Markdown
Member Author

🔵 Needs a closer look

Trident support has merged, but compatible package publication to PMC and inclusion in image builds remain unverified.

0 open findings

🧠 Review effort: Balanced

trident is now pulled from azure-container-linux/acl/SPECS/trident, which has support for hash-signature existance.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

All UKI layouts validate successfully for both supported architectures, with no unresolved correctness issues found.

0 open findings

🧠 Review effort: Balanced

This branch was successfully deployed

1 active deployment
development — 4af23f02 Deployed Oct 7, 2026 by bfjelds via Check if we need to update the SDK #96
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants