Bug 12216

Summary: dm-verity boot support
Product: [Build System, Metadata & Runtime] OE-Core Reporter: jonathan.yong
Component: coreAssignee: Ross Burton <ross.burton>
Status: RESOLVED NOTABUG QA Contact:
Severity: enhancement    
Priority: Undecided CC: meta.mr.watcher, meta.watcher
Version: 2.5   
Target Milestone: ---   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Yes (doc changes required)

Description jonathan.yong 2017-10-11 00:52:46 UTC
dm-verity is a platform independent way of verifying the root filesystem at the block level, but consequently, the filesystem is read-only.

So far, one of the notable issues found is pulseaudio failing because /home is read-only.
Comment 1 Ross Burton 2017-10-11 09:07:03 UTC
I'd always expected /home would be a separate mount point under dm-verity so that the system is actually useful.
Comment 2 Ross Burton 2017-10-11 09:46:18 UTC
Pulseaudio wants to write state to $HOME.  So will others.  You either need to have a tmpfs for state/sockets/etc (in /run or similar) which you can configure pulseaudio to use, or put $HOME in a separate read/write partition.

I've also a hunch that you may be using sysv and switching to systemd will make pulse use /run, but then again there may be a hard-coded $HOME in Pulseaudio somewhere.

I'm going to close this as it's too vague, as you said dm-verity works and RefKit also use it to validate the installer media.  Please open specific bugs for specific issues that are not just integration issues in your system.
Comment 3 jonathan.yong 2017-10-11 23:44:33 UTC
We're using systemd, and yes, we're already aware of the need for writeable /home.

I am not aware of the refkit, is that a layer to enable dm-verity support?
Comment 4 Ross Burton 2017-10-12 09:20:34 UTC
refkit is a distro that targets IoT (hosted on git.yoctoproject.org).

Reclosing, please file concrete bugs for concrete problems.