Skip to content

initramfs: scope root device lookup strictly to xvda sysfs (Fixes #11149) - #146

Open
akshat-lakhera wants to merge 1 commit into
QubesOS:mainfrom
akshat-lakhera:fix-root-dev-xvda-11149
Open

akshat-lakhera wants to merge 1 commit into
QubesOS:mainfrom
akshat-lakhera:fix-root-dev-xvda-11149

Conversation

@akshat-lakhera

@akshat-lakhera akshat-lakhera commented Sep 28, 2026 •

Copy link
Copy Markdown

Fixes QubesOS/qubes-issues#11149: Attaching block dev to new disposable qube can result in qube using dev as root device

Summary
Scope root partition discovery during early boot strictly to xvda sysfs entries rather than the global by-partlabel symlink.

Key Changes

  • In dracut/simple/init.sh and dracut/full-dmroot/qubes_cow_setup.sh, look up PARTNAME=Root filesystem directly under /sys/block/xvda/xvda*/uevent, ignoring secondary block devices (such as xvdi).
  • Use tail -n 1 to safely select a single partition node if multiple partitions on xvda share the root label.
  • Fall back cleanly to xvda3 if no matching partition label is found on xvda.
  • In udev/udev-qubes-dmroot.rules, add KERNEL==xvda* condition so attached block devices never receive the mapper/dmroot symlink.

@codecov-commenter

codecov-commenter commented Sep 28, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 71.27%. Comparing base (2506306) to head (91c9025).

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #146      +/-   ##
==========================================
+ Coverage   71.24%   71.27%   +0.02%     
==========================================
  Files           6        6              
  Lines         991      992       +1     
==========================================
+ Hits          706      707       +1     
  Misses        285      285              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@crass crass left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is roughly what I had in mind.

Comment thread dracut/full-dmroot/qubes_cow_setup.sh Outdated
udevadm settle --exit-if-exists=/dev/xvda1
if [ -e "/dev/disk/by-partlabel/Root\\x20filesystem" ]; then
ROOT_DEV=$(readlink "/dev/disk/by-partlabel/Root\\x20filesystem")
ROOT_DEV=$(grep -l "PARTNAME=Root filesystem" /sys/block/xvda/xvda*/uevent 2>/dev/null | tail -n 1)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What ordering will the glob produce? Lexographic? If so, then for partitions labeled "Root filesystem" at xdva3 and xvda9, xvda9 will be used as the root. But for partitions at xvda3 and xvda10, xvda3 will be root. Might be confusing. But then again, I estimate an almost 0 probability that someone would hit that. Regardless, I suggest we force an ordering just to be sure that the ordering is actually consistent.

Comment thread udev/udev-qubes-dmroot.rules Outdated
# On TemplateBasedVM, it is really a device mapper device.

SUBSYSTEM=="block", ENV{ID_PART_ENTRY_NAME}=="Root\x20filesystem", ATTR{ro}=="0", SYMLINK+="mapper/dmroot"
SUBSYSTEM=="block", KERNEL=="xvda*", ENV{ID_PART_ENTRY_NAME}=="Root\x20filesystem", ATTR{ro}=="0", SYMLINK+="mapper/dmroot"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For this, there's an assumption that the last seen block device with partition name "Root filesystem" should be dmroot. Is this a valid assumption? Or should be get rid of this udev rule completely and manually add the symlink in the changes above, where we are certain which root device is being used?

Do not look up the root partition via the global /dev/disk/by-partlabel
symlink, because when secondary block devices are attached (such as
attaching a disk image to a new disposable qube), duplicated partition
labels like "Root filesystem" cause udev to point the symlink at the
attached device instead of xvda.

Look up the partition label strictly under /sys/block/xvda/xvda*/uevent
with sort -V to ensure natural numeric ordering. For TemplateVMs,
create /dev/mapper/dmroot directly and register the runtime udev rule
under /run/udev/rules.d/ so that the mapping persists across switch_root
without relying on static partition name matching.

Fixes QubesOS/qubes-issues#11149
@akshat-lakhera
akshat-lakhera force-pushed the fix-root-dev-xvda-11149 branch from fa9f793 to 91c9025 Compare October 1, 2026 23:59

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Attaching block dev to new disposable qube can result in qube using dev as root device

3 participants