Skip to content

test(images): validate kernel FIPS boot options - #19023

Merged
Tobias Brick (tobiasb-ms) merged 2 commits into
microsoft:4.0from
tobiasb-ms:tobiasb-ms/fips-marketplace-image-tests
Oct 8, 2026
Merged

Tobias Brick (tobiasb-ms) merged 2 commits into
microsoft:4.0from
tobiasb-ms:tobiasb-ms/fips-marketplace-image-tests

Conversation

@tobiasb-ms

@tobiasb-ms Tobias Brick (tobiasb-ms) commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • parse kernel options from every BLS boot entry through a reusable image-test fixture
  • require fips=1 exactly once for -fips machine-bootable images
  • reject all kernel FIPS options from non-FIPS machine-bootable images

Testing

  • ran pre-commit run --all-files: Ruff, Pyright, editorconfig-checker, and lychee passed
  • locally built azurelinux-repos-4.0-23.azl4 from the current 4.0 source
  • built all 13 x86_64 image definitions with the branch-consistent repository package
  • ran static-image-checks against all 12 configured image artifacts: 315 passed, 177 capability-based skips
  • built the x86_64 installer ISO; its registered iso-validation suite is LISA metadata-only and cannot run locally without a pinned LISA source

Copilot AI balanced review requested due to automatic review settings October 2, 2026 20:58

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Copilot review overview

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds a static image test to validate kernel FIPS boot options by parsing kernel arguments from each BLS boot entry and enforcing fips=1 only for -fips machine-bootable images.

Changes:

  • Introduces a session-scoped fixture that parses kernel options from BLS boot entry .conf files.
  • Adds a static test asserting fips=1 appears exactly once on -fips images and never on non-FIPS images.
  • Documents the new fixture in the image tests README.
File Description
base/​images/​tests/​conftest.py Adds boot_entry_kernel_options fixture to parse kernel cmdline options from BLS entries.
base/​images/​tests/​cases/​static/​test_fips.py New static test enforcing FIPS kernel option expectations by image variant.
base/​images/​tests/​README.md Documents the new fixture in the fixture table.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread base/images/tests/conftest.py Outdated
Copilot AI balanced review requested due to automatic review settings October 2, 2026 21:27
@tobiasb-ms
Tobias Brick (tobiasb-ms) force-pushed the tobiasb-ms/fips-marketplace-image-tests branch from a30aa9f to 8ce0860 Compare October 2, 2026 21:27
@tobiasb-ms

Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
2 pipeline(s) were filtered out due to trigger conditions.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Copilot review overview

Review effort: Lite
Findings: 1 High severity · 1 Medium severity

Open (2)
Resolved since last review (1)

Comment thread base/images/tests/conftest.py Outdated
Comment thread base/images/tests/conftest.py Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

BLS files must be read through the confined resolver to prevent image symlinks from accessing host files.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (2)

Comment thread base/images/tests/conftest.py Outdated
Copilot AI balanced review requested due to automatic review settings October 5, 2026 14:32
@tobiasb-ms
Tobias Brick (tobiasb-ms) force-pushed the tobiasb-ms/fips-marketplace-image-tests branch from 66333c1 to 1971803 Compare October 5, 2026 14:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation matches the stated requirements and is supported by comprehensive image-test results.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@tobiasb-ms

Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
2 pipeline(s) were filtered out due to trigger conditions.

@tobiasb-ms
Tobias Brick (tobiasb-ms) marked this pull request as ready for review October 5, 2026 14:42
@tobiasb-ms
Tobias Brick (tobiasb-ms) requested a review from a team as a code owner October 5, 2026 14:42
@tobiasb-ms
Tobias Brick (tobiasb-ms) marked this pull request as draft October 5, 2026 15:53
@tobiasb-ms
Tobias Brick (tobiasb-ms) force-pushed the tobiasb-ms/fips-marketplace-image-tests branch from 1971803 to f1253fe Compare October 5, 2026 16:09
Copilot AI balanced review requested due to automatic review settings October 5, 2026 16:09
@tobiasb-ms

Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
2 pipeline(s) were filtered out due to trigger conditions.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Copilot review overview

Review effort: Lite
Findings: 2 Medium severity

Open (2)

Comment thread base/images/tests/conftest.py Outdated
Comment thread base/images/tests/conftest.py Outdated
Copilot AI balanced review requested due to automatic review settings October 6, 2026 22:59
@tobiasb-ms
Tobias Brick (tobiasb-ms) force-pushed the tobiasb-ms/fips-marketplace-image-tests branch from f1253fe to 4618bfa Compare October 6, 2026 22:59

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation matches the stated requirements and was validated across all configured x86_64 image artifacts.

Review effort: Balanced
Findings: None

Resolved since last review (2)

@tobiasb-ms

Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
2 pipeline(s) were filtered out due to trigger conditions.

@tobiasb-ms
Tobias Brick (tobiasb-ms) force-pushed the tobiasb-ms/fips-marketplace-image-tests branch from 4618bfa to 5241307 Compare October 8, 2026 17:47
Copilot AI balanced review requested due to automatic review settings October 8, 2026 17:47

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The implementation matches the stated requirements and was comprehensively validated across the configured images.

0 open findings

🧠 Review effort: Balanced

@tobiasb-ms
Tobias Brick (tobiasb-ms) marked this pull request as ready for review October 8, 2026 17:52
@tobiasb-ms

Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
2 pipeline(s) were filtered out due to trigger conditions.

Comment thread base/images/tests/conftest.py Outdated


@pytest.fixture(scope="session")
def boot_entry_kernel_options(rootfs: Path) -> dict[Path, list[str]]:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

issue(blocking): Since this method is a test fixture it should not do any validation other than required to make sure data population or fixture setup works as expected or fails gracefully. That means it ideally only parses the conf file and returns the values as is. Interpretation or validation is done by the consumers of the fixture returned values.

A direct impact is a fixture failure instead of a test failure when something is wrong with the configuration.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good callout. I've refactored so the fixture just returns raw line and then there's a parsing helper that tests can use.

@pytest.fixture(scope="session")
def boot_entry_kernel_options(rootfs: Path) -> dict[Path, list[str]]:
"""Kernel command-line options keyed by BLS boot entry path."""
entries_dirs = (

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

suggestion(non-blocking): I am not very comfortable with the implicit selection of whichever boot configs are found in the image. Much like image capability driving what to expect in the image can't we drive this fixture the same way?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It feels like we should check everything and then caller can decide what to do. In our case, it feels very unlikely that any images will ever actually have multiple entrieson a freshly-baked image so we should be safe. But either way, in principle, I'd prefer to cover them all.

Thoughts?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your argument is valid and that anticipation is why the comment is non-blocking. To illustrate what I am trying to convey if we look at the rootfs fixture, it checks the image type and does the mounting in different ways. Similarly, since we know what kind of image we are inspecting, we can look at the deterministic loader configuration path for that image. This definitely does not break the test and it is your choice whether to make a change.

Parse BLS kernel options once through a shared session fixture and reuse
the parsed arguments for swap validation. Cover both standard and EFI BLS
entry locations while retaining separate handling for grub.cfg.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Require every machine-bootable image to carry kernel FIPS options
matching its declared image capabilities.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 8, 2026 19:02
@tobiasb-ms
Tobias Brick (tobiasb-ms) force-pushed the tobiasb-ms/fips-marketplace-image-tests branch from 5241307 to 524e2da Compare October 8, 2026 19:02

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The implementation matches the stated requirements and is supported by comprehensive image-test results.

0 open findings

🧠 Review effort: Balanced

@tobiasb-ms

Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
2 pipeline(s) were filtered out due to trigger conditions.

@tobiasb-ms
Tobias Brick (tobiasb-ms) merged commit 4bff11d into microsoft:4.0 Oct 8, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants