Repository navigation
Make explicit hash signature partitions - #88
bfjelds (bfjelds) wants to merge 4 commits into
Conversation
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Copilot review overview
Review effort: Lite
Findings: 3
Open (4)
The PR description marks this as an 'Image build change' but also answers 'Does this affect the… · New This change reduces the verity hash partition size from 20480 blocks (10 MiB) to 18432 blocks (9… · New The meaning/units ofpart_alignmentandblocksaren’t explicit in the file itself. Since the… · New This bullet is quite long and combines multiple concepts. Consider splitting it into two bullets… · New
What changed in this PR
Splits the existing /usr dm-verity HASH partitions into separate HASH and reserved HASH-SIG partitions to enable future verity root-hash signatures, and updates partition type resolution/documentation accordingly.
Changes:
- Added a new DPS partition type placeholder (
dps-usr-verity-sig) with architecture-specific GUIDs. - Updated UKI disk layout to split HASH into HASH + HASH-SIG partitions and renumber subsequent partitions/references.
- Documented the new reserved HASH-SIG partition in ACL architecture docs.
| File | Description |
|---|---|
| build_library/disk_util | Adds GUID mapping and placeholder resolution for the new signature partition type. |
| build_library/disk_layout_uki.json | Splits HASH-A/B into HASH + HASH-SIG, adjusts sizing/alignment, and renumbers partitions/references. |
| acl/docs/architecture.md | Documents the new reserved HASH-SIG partition following HASH-A. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Copilot review overview
Review effort: Lite
Findings: 5
Open (7)
These lines start with|-, which typically won’t render as a proper Markdown list item. Consider… · New PR metadata says this is an “Image build change” but also says it does not affect the image build… · New The meaning/units ofpart_alignmentandblocksaren’t explicit in the file itself. Since the… This change reduces the verity hash partition size from 20480 blocks (10 MiB) to 18432 blocks (9… The PR description marks this as an 'Image build change' but also answers 'Does this affect the… The_commentis very long and also relies on implicit units (e.g., why2048equals 1 MiB). To… · New This bullet is quite long and combines multiple concepts. Consider splitting it into two bullets…
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The shipped partition-layout changes still require an actual image build and boot/kola validation before human approval.
Review effort: Balanced
Findings: None
Resolved since last review (7)
PR metadata says this is an “Image build change” but also says it does not affect the image build… These lines start with|-, which typically won’t render as a proper Markdown list item. Consider… The meaning/units ofpart_alignmentandblocksaren’t explicit in the file itself. Since the… This change reduces the verity hash partition size from 20480 blocks (10 MiB) to 18432 blocks (9… The PR description marks this as an 'Image build change' but also answers 'Does this affect the… The_commentis very long and also relies on implicit units (e.g., why2048equals 1 MiB). To… This bullet is quite long and combines multiple concepts. Consider splitting it into two bullets…
…tion Replace the single 10 MiB HASH-A/HASH-B partitions with two partitions each: HASH-A/HASH-B (exact 9 MiB, verity hash tree, dps-usr-verity) and HASH-SIG-A/HASH-SIG-B (exact 1 MiB, reserved for a future verity root-hash signature, dps-usr-verity-sig). Add DPS_USR_VERITY_SIG_GUIDS to disk_util alongside the existing DPS_USR_VERITY_GUIDS constants, using the official UAPI Discoverable Partitions Specification GUIDs for the usr-verity-sig partition type (x86_64 and aarch64), so the new partitions are resolved the same way as the existing verity/root types instead of using the generic data GUID. Total space per slot is unchanged; subsequent partitions (OEM, ROOT) and all verity_hash/layout references are renumbered accordingly.
disk_util aligns every partition start up to part_alignment (4096 blocks/2MiB) before placing it. Because HASH-A/HASH-B (18432 blocks = 9 MiB) and HASH-SIG-A/HASH-SIG-B (2048 blocks = 1 MiB) are not themselves multiples of 4096, the default alignment silently inserted four 1 MiB padding gaps (before each HASH-SIG and before USR-B/OEM) that belong to no partition and cannot be used - 4 MiB of dead space per disk image, contradicting the intent that splitting HASH into HASH+HASH-SIG not change total footprint. Override part_alignment to 2048 (1 MiB) on HASH-SIG-A/B specifically: they do not need 2 MiB alignment (small, non-performance-sensitive signature partitions), and since HASH-A + HASH-SIG-A (9 MiB + 1 MiB = 10 MiB) is itself a 2 MiB multiple, this removes the gap with no other side effects - every downstream partition offset (USR-B, HASH-B, HASH-SIG-B, OEM, ROOT) and the final disk image size now exactly match the original pre-split layout. Verified via disk_util.LoadPartitionConfig: zero gaps, and every partition offset after HASH-A matches the pre-split baseline exactly.
- disk_layout_uki.json: expand HASH-A/_B _comment with verity hash tree sizing rationale (sha256 + 4096-byte blocks assumption, ~8.08 MiB computed size vs 9 MiB allocated). Clarify blocks/part_alignment units are 512-byte sectors on the new HASH-SIG-A/B entries. - architecture.md: split the HASH-A/HASH-SIG-A bullet into two for readability.
The usr-hash-sig-a/b partitions shift ROOT from the 7th to the 9th partition on the new layout. Hard-coding `nbd0p7` and `max_part=8` broke the documented verification steps. Select ROOT by GPT partition label instead of a hard-coded index, so the commands work for both the old and new layouts. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
629c9e3 to
4af23f0
Compare
trident is now pulled from azure-container-linux/acl/SPECS/trident, which has support for hash-signature existance. |


Summary
Split bigger HASH partitions into more appropriately sized HASH and HASH-SIGN partitions to enable hash signatures.
Change Log
Type of Change
Does this affect the image build?
Associated Issues
Test Methodology
Merge Checklist
All applicable boxes should be checked before merging