snap-bootstrap should validate which ubuntu-data is mounted

Bug #1863886 reported by Dimitri John Ledkov
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
snapd
Fix Released
High
Ian Johnson

Bug Description

snap-bootstrap should validate which ubuntu-data is mounted

after snap-bootstrap unseals key, and attaches encrypted data, it must ensure that ubuntu-data from the encrypted dm device gets mounted as data.

because there might be unencrypted partitions with label ubuntu-data out there with udev symlinks.

Tags: core20
tags: added: core20
Changed in snapd:
status: New → Triaged
importance: Undecided → High
assignee: nobody → Claudio Matsuoka (cmatsuoka)
Changed in snapd:
assignee: Claudio Matsuoka (cmatsuoka) → Ian Johnson (anonymouse67)
Revision history for this message
Ian Johnson (anonymouse67) wrote :

Part of the fix is proposed here: https://github.com/snapcore/snapd/pull/8683

There will likely be one more PR after that is merged, potentially more than one.

Changed in snapd:
status: Triaged → In Progress
Revision history for this message
Ian Johnson (anonymouse67) wrote :

Well I was wrong there are a few more PR's, but the one that should close this bug is here: https://github.com/snapcore/snapd/pull/9081, but it will be a while before that is mergable.

Revision history for this message
Ian Johnson (anonymouse67) wrote :

This is now committed to snapd, needs to go into ubuntu-core-initramfs and then get picked up in the kernel snap from there before it is fix released.

Changed in snapd:
status: In Progress → Won't Fix
status: Won't Fix → Fix Committed
Changed in snapd:
status: Fix Committed → Fix Released
milestone: none → 2.46
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.