Skip to content

fix(roles/aide): stop reporting /boot/efi and fwupd.conf on unchanged hosts - #418

Merged
NavidSassan merged 2 commits into
mainfrom
fix/aide-boot-efi
Oct 2, 2026
Merged

NavidSassan merged 2 commits into
mainfrom
fix/aide-boot-efi

Conversation

@markuslf

@markuslf markuslf commented Oct 2, 2026

Copy link
Copy Markdown
Member

On a Rocky 9 host, aidecheck.service failed with findings on files that had not changed. Two of them are false positives of the role's default rules.

Changes

  • role:aide, /boot/efi: checked with DATAONLY instead of NORMAL. The EFI system partition is vfat, which stores no inode numbers: fat_build_inode() assigns a new one with iunique() whenever a file is read in again (fs/fat/inode.c), so once the inodes were evicted from the cache, every file below /boot/efi was reported as changed. Content, permissions and ownership are still checked, as for /etc/ld.so.cache.
  • role:aide, /etc/fwupd/fwupd.conf: checked with ftype+u+g+selinux+xattrs, i.e. the catch-all PERMS without the mode and its ACL. fwupd 1.9.1 and later sets the file to 0640 whenever its daemon starts (fu_config_ensure_permissions() in libfwupdplugin/fu-config.c), while the package ships it with 0644, so the first daemon start after aide --init or after an update of fwupd failed the check.
  • molecule aide: prepare.yml deploys a probe file to /boot/efi. verify.yml drops the page cache and asserts that the probe got a new inode number, resets fwupd.conf to 0644, restarts fwupd and asserts it set 0640, and then requires the check to run clean. A content change below /boot/efi is still reported.

Tests

  • molecule test --scenario-name aide, full sequence (verify, idempotence, verify), green on Debian 13, Rocky 8, Rocky 9, Ubuntu 24.04 and Ubuntu 26.04 (Ubuntu 24.04 and 26.04 in the run with the fwupd rule; Ubuntu 24.04 failed on fwupd.conf before it).
  • echo 2 > /proc/sys/vm/drop_caches leaves the inode number as it is on Debian 13, Rocky 9 and Ubuntu 24.04, since the kernel keeps an inode that still has cached pages; the probe uses echo 3.

VM creation in Molecule failed at first in the ARP-based address discovery, as in #416: virsh domifaddr --source arp reads only the first netlink datagram of the neighbour dump (virNetlinkCommand() in libvirt), so VMs whose entry lands in a later datagram are not found once the host's neighbour cache is large. Flushing the stale entries (ip neigh flush dev <bridge>) made it work.

vfat stores no inode numbers. fat_build_inode() assigns one with
iunique() whenever a file is read in again, so once the inodes below
/boot/efi had been evicted from the cache, every check reported all
files there as changed (seen on a Rocky 9 host). /boot/efi now uses
DATAONLY, like /etc/ld.so.cache, which still reports changes of content,
permissions and ownership.

The aide scenario drops the page cache before the clean check, asserts
that the probe file below /boot/efi got a new inode number, and that a
content change there is still reported. Verified on Debian 13, Rocky 8,
Rocky 9 and Ubuntu 24.04.
fwupd 1.9.1 and later sets its config to 0640 whenever the daemon
starts (fu_config_ensure_permissions() in libfwupdplugin/fu-config.c),
while the package ships it with 0644. The catch-all `/etc PERMS` checks
the mode and its ACL, so the first daemon start after `aide --init` or
after an update of fwupd failed the check. The file is now checked
with PERMS minus the mode and the ACL.

The aide scenario resets the file to 0644, restarts fwupd, asserts that
the daemon set it to 0640, and requires the check to stay clean.
Verified on Rocky 9, Ubuntu 24.04 and Ubuntu 26.04.
@NavidSassan
NavidSassan merged commit cbb990e into main Oct 2, 2026
13 checks passed
@NavidSassan
NavidSassan deleted the fix/aide-boot-efi branch October 2, 2026 13:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants