feat: kernel-dependent BTRFS UUID collision resolution (temp_fsid on >=6.7) - #674
Open
bfjelds wants to merge 10 commits into
Open
feat: kernel-dependent BTRFS UUID collision resolution (temp_fsid on >=6.7)#674bfjelds wants to merge 10 commits into
bfjelds wants to merge 10 commits into
Conversation
bfjelds
force-pushed
the
user/bfjelds/mjolnir/acl-cosi-temp-fsuid
branch
from
June 5, 2026 19:36
eed9f51 to
e4eaf3f
Compare
Member
Author
|
/azp run [GITHUB]-trident-pr |
|
Azure Pipelines could not run because the pipeline triggers exclude this branch/path. |
bfjelds
marked this pull request as ready for review
June 8, 2026 18:16
bfjelds
force-pushed
the
user/bfjelds/mjolnir/acl-cosi-combined
branch
from
June 11, 2026 19:06
b5f1ff1 to
1522587
Compare
On kernel >=6.7, use mount -o temp_fsuid to mount the staging device directly, bypassing the BTRFS global UUID registry. This is the preferred solution as it mounts real staging content without needing verity hash verification. On kernel <6.7 (e.g. 6.6.x), fall back to the existing bind-mount strategy which requires verity hash matching to prove the active and staging content are identical. Changes: - Add KernelVersion parser to osutils/uname.rs with unit tests - Split detect_acl_btrfs_uuid_collision into collision detection and resolution strategy (AclBtrfsCollisionResolution enum) - Add verify_acl_bind_mount_safety for the bind-mount path - Mount handler selects strategy based on kernel version Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The temp_fsuid mount path (kernel >=6.7) is aspirational and untested in production. Gate it behind the enableAzl4 internal parameter so it only activates when explicitly opted in. When the flag is absent, the bind-mount fallback is used. No special warning or fallback from temp_fsuid failure — mount errors propagate as-is to surface issues. The enableAzl4 flag is intentionally broad: it will gate additional Azure Linux 4 behaviors as they are added. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
DR-002: Move BTRFS temp_fsuid domain knowledge out of osutils. Remove supports_btrfs_temp_fsuid() from KernelVersion (generic layer) and define BTRFS_TEMP_FSUID_MIN_KERNEL constant in the consumer (newroot.rs). KernelVersion now relies on derived Ord for version comparisons. DR-003: Distinguish uname execution failure from parse failure. The match on KernelVersion::running() now logs different warnings for Err (uname command failed) vs Ok(None) (output not parseable). DR-004: Add doc comment explaining why verity hash verification is intentionally skipped for the temp_fsuid path (it mounts real staging content, not a bind-mount of active, so no identity assumption to verify). DR-005: Eliminate double pattern match on AclBtrfsCollisionResolution in the mount loop. Add collision_uuid() accessor method so the UUID is extracted once, then dispatch on the resolution variant in a single match. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
bfjelds
force-pushed
the
user/bfjelds/mjolnir/acl-cosi-temp-fsuid
branch
from
July 14, 2026 16:22
e4eaf3f to
66af464
Compare
bfjelds
changed the base branch from
user/bfjelds/mjolnir/acl-cosi-combined
to
main
July 14, 2026 16:23
Contributor
There was a problem hiding this comment.
Pull request overview
This PR adds a kernel-version-dependent strategy for handling ACL BTRFS filesystem UUID collisions during A/B updates, preferring temp_fsuid mounts on kernels that support it (>= 6.7) and otherwise falling back to the existing verity-validated bind-mount approach.
Changes:
- Introduces
KernelVersionparsing/comparison utilities inosutils::unameto gate behavior on the running kernel’s major/minor. - Refactors ACL BTRFS UUID collision handling in
newrootto select betweentemp_fsuidmounting vs bind-mounting active/usr. - Adds a new internal param constant (
enableAzl4) to explicitly gate AZL4/kernel-capability-dependent behavior.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
| crates/trident/src/engine/newroot.rs | Adds strategy selection for ACL BTRFS UUID collision resolution (temp_fsuid vs bind-mount) and refactors detection/verification helpers. |
| crates/trident_api/src/constants.rs | Adds internal_params::ENABLE_AZL4 to gate AZL4-specific behaviors. |
| crates/osutils/src/uname.rs | Adds KernelVersion parsing + ordering and unit tests for common uname formats. |
- verify_acl_bind_mount_safety: refuse bind-mount when no staging verity hash is available instead of allowing it, matching the BindMountActiveUsr verity-proof contract. - detect_acl_btrfs_uuid_collision: warn when lsblk errors instead of silently swallowing the error. - resolve_acl_btrfs_uuid_collision: correct a misleading comment about enableAzl4-absent behavior. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…ogging The Linux 6.7 BTRFS option is temp_fsid, not temp_fsuid; the old string would fail at mount time with an unknown-option error. Rename the runtime mount string, enum variant, constant, local var, and all comments/docstrings. Restructure the kernel-version gating so uname execution failure and parse failure emit distinct warnings instead of both logging 'could not parse'. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- KernelVersion::parse: trim uname output so a trailing newline on a bare major.minor release (e.g. '5.15\n') no longer fails to parse. - detect_acl_btrfs_uuid_collision: warn explicitly when lsblk returns Ok(None) instead of swallowing it, matching the Err treatment. - resolve_acl_btrfs_uuid_collision: return Result and fail with a structured AclBtrfsUuidCollisionUnresolved error (carrying the verity reason) when a collision exists but cannot be safely resolved, instead of returning None and deferring to an opaque mount failure. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…eanup - Extract pure select_acl_collision_strategy() and add unit tests for strategy selection (enableAzl4+6.7 => TempFsid; +6.6 / undetermined kernel / flag-off => BindMount) plus verify_acl_bind_mount_safety missing/empty-hash cases. - temp_fsid mount arm: use with_context to avoid eagerly allocating the error string on the success path. - bind-mount arm: use USR_MOUNT_POINT_PATH instead of a hard-coded /usr literal. - Reword the collision warnings to describe temp_fsid availability rather than asserting a specific kernel version, since BindMount is also chosen when the flag is unset or the kernel version is undetermined. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Member
Author
|
/azp run [GITHUB]-trident-pr-e2e |
|
Azure Pipelines: Successfully started running 1 pipeline(s). |
Member
Author
|
/azp run [GITHUB]-trident-pr-e2e |
|
Azure Pipelines will not run the associated pipelines, because the pull request was updated after the run command was issued. Review the pull request again and issue a new run command. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds kernel-version-dependent mount strategy for ACL BTRFS UUID collisions during A/B updates:
-o temp_fsid, which assigns a temporary in-memory UUID and bypasses the BTRFS global UUID registry. This is the preferred solution as it mounts real staging content without needing verity hash verification./usr, which requires verity hash matching to prove content is identical.Changes
crates/osutils/src/uname.rsKernelVersionstruct withparse()andrunning(); kernel capability is checked inline viakv >= BTRFS_TEMP_FSID_MIN_KERNELat the single call site.crates/trident/src/engine/newroot.rsdetect_acl_btrfs_uuid_collisioninto three focused functions:detect_acl_btrfs_uuid_collision- pure UUID collision detectionverify_acl_bind_mount_safety- verity hash check (bind-mount path only)resolve_acl_btrfs_uuid_collision- orchestrator that picks strategy based on kernel versionAclBtrfsCollisionResolutionenum:TempFsidvsBindMountActiveUsrTesting
KernelVersionunit tests passcargo buildandcargo fmt --checkclean on Linux