Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

initrdscripts: migrate: panic on installation failure #3560

Merged
merged 2 commits into from
Nov 22, 2024

Conversation

alexgg
Copy link
Contributor

@alexgg alexgg commented Nov 20, 2024

Right now if the flashing script errors out the initramfs just keeps running modules. This is a security risk specially for secure boot systems as at that point we have an authorized trusted OS running in an unvetted path.

This commit exits init if the flasher returns, and also attemps to crash the kernel followed by an infinite sleep for paranoic reasons.

Change-type: patch


Contributor checklist

Reviewer Guidelines

  • When submitting a review, please pick:
    • 'Approve' if this change would be acceptable in the codebase (even if there are minor or cosmetic tweaks that could be improved).
    • 'Request Changes' if this change would not be acceptable in our codebase (e.g. bugs, changes that will make development harder in future, security/performance issues, etc).
    • 'Comment' if you don't feel you have enough information to decide either way (e.g. if you have major questions, or you don't understand the context of the change sufficiently to fully review yourself, but want to make a comment)

@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg requested a review from a team November 20, 2024 14:51
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg had a problem deploying to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Failure
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 20, 2024 14:51 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:20 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:20 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:20 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:20 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:20 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:20 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:20 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:20 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:20 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:20 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:20 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:20 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:20 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-staging.com November 21, 2024 13:21 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-cloud.com November 21, 2024 14:18 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-cloud.com November 21, 2024 14:18 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-cloud.com November 21, 2024 14:28 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-cloud.com November 21, 2024 14:28 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-cloud.com November 21, 2024 14:28 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-cloud.com November 21, 2024 15:15 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-cloud.com November 21, 2024 15:15 — with GitHub Actions Inactive
@alexgg alexgg temporarily deployed to balena-cloud.com November 21, 2024 15:15 — with GitHub Actions Inactive
@mtoman
Copy link
Contributor

mtoman commented Nov 22, 2024

lgtm

@alexgg alexgg temporarily deployed to balena-cloud.com November 22, 2024 13:52 — with GitHub Actions Inactive
@flowzone-app flowzone-app bot merged commit 972d123 into master Nov 22, 2024
159 of 161 checks passed
@flowzone-app flowzone-app bot deleted the alexgg/migrate branch November 22, 2024 14:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants