From 2284549c7be70d98d12ba65718629e7b85a5422c Mon Sep 17 00:00:00 2001 From: Kevin Wang Date: Thu, 24 Sep 2026 21:10:19 -0700 Subject: [PATCH] fix(os/mkosi): keep the TPM keystore root-owned 0755 at runtime #1331 applies rootfs.tmpfiles at build time only, on the premise that the root is read-only at runtime. /var/lib is a writable overlay, though, so systemd-tmpfiles-setup re-applies tpm2-tss-fapi.conf at every boot and the keystore comes back as 2775 tss:tss. Ship a boot-time entry that sorts before the package's and restores the image's mode. Signed-off-by: Kevin Wang --- .../mkosi.skeleton/usr/lib/tmpfiles.d/dstack-keystore.conf | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 os/mkosi/mkosi.skeleton/usr/lib/tmpfiles.d/dstack-keystore.conf diff --git a/os/mkosi/mkosi.skeleton/usr/lib/tmpfiles.d/dstack-keystore.conf b/os/mkosi/mkosi.skeleton/usr/lib/tmpfiles.d/dstack-keystore.conf new file mode 100644 index 000000000..8511bf681 --- /dev/null +++ b/os/mkosi/mkosi.skeleton/usr/lib/tmpfiles.d/dstack-keystore.conf @@ -0,0 +1,5 @@ +# SPDX-License-Identifier: Apache-2.0 +# /var/lib is a writable overlay, so tpm2-tss-fapi.conf re-applies its 2775 +# tss:tss keystore on every boot. This file sorts first and keeps the image's +# 0755 root:root (rootfs.tmpfiles) at runtime too. +d /var/lib/tpm2-tss/system/keystore 0755 root root -