Repository navigation
Conversation
oliverkurth
reviewed
Sep 1, 2026
| # UI modules, which need not be a module-level dependency of the ISO | ||
| # builder. These go to the ISO's RPMS/ only, not into self.initrd_pkgs, | ||
| # so the initrd does not grow. | ||
| from stigenable import KS_STIG_PACKAGES |
Collaborator
There was a problem hiding this comment.
Can you please move this to the top of the file, with import stigenable, and refer to it as stigenable.KS_STIG_PACKAGES?
Contributor
Author
There was a problem hiding this comment.
git apply --check (strict, no fuzz) returns 0 on v2.8, v2.9 and origin/master; after applying, isoBuilder.py compiles, import stigenable works headless, isoBuilder.stigenable.KS_STIG_PACKAGES is stigenable.KS_STIG_PACKAGES holds, and on all three the hunk lands in downloadPkgs() with the import at module level.
Tested on minimal-iso x86_64. Ongoing full-iso build should be the same. aarch64 not tested.
Two gaps in how the download list is built. 1. The STIG menu offers "Apply STIG hardening", which makes the installer request KS_STIG_PACKAGES at install time. Those names were never added to the ISO's own RPMS/, so on a minimal ISO - where downloadPkgs() resolves a closure rather than copying every rpm - the packages simply were not there and the install failed with "Error(1011) : No matching packages". Refer to stigenable.KS_STIG_PACKAGES rather than restating the names in a package list file; restating them is exactly how the media and the installer drifted apart. 2. Packages named via --initrd-pkgs never reached this list either. Only the list *file* was parsed, so a package requested on the command line could not be installed into the initrd from the ISO's own RPMS/. Both extend self.pkg_list only, so they land in the ISO's RPMS/ and the initrd does not grow. Verified end to end: a minimal ISO built with this carries 290 rpms instead of 254, including selinux-policy, libselinux-utils, rsyslog, aide, openssl-fips-provider and ntpsec; the UI wizard's STIG option completes; and the installed system comes up SELinux Enforcing with 0 failed ansible tasks. Signed-off-by: Daniel Casota <dcasota@gmail.com> Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota
force-pushed
the
upstream/isobuilder-installer-pkgs-on-media
branch
from
September 1, 2026 18:16
5a6fff7 to
aefaa84
Compare
dcasota
added a commit
to dcasota/photon
that referenced
this pull request
Sep 1, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which carries the form requested in review on vmware/photon-os-installer#49: a module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`, rather than a local `from stigenable import KS_STIG_PACKAGES` inside downloadPkgs(). Package selection is unchanged; only where the import happens moves. Change-Id: Idbc6e7565c915770305eeb22a7198ba649735ca0 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota
added a commit
to dcasota/photon
that referenced
this pull request
Sep 1, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which carries the form requested in review on vmware/photon-os-installer#49: a module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`, rather than a local `from stigenable import KS_STIG_PACKAGES` inside downloadPkgs(). Package selection is unchanged; only where the import happens moves. Change-Id: I3be44f73d323be4bb243c85be2e88d10a6d8f8a8 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota
added a commit
to dcasota/photon
that referenced
this pull request
Sep 1, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which carries the form requested in review on vmware/photon-os-installer#49: a module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`, rather than a local `from stigenable import KS_STIG_PACKAGES` inside downloadPkgs(). Package selection is unchanged; only where the import happens moves. Change-Id: Iff902337549b191c714ff4ef8a42564017feb402 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota
added a commit
to dcasota/photon
that referenced
this pull request
Sep 16, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which carries the form requested in review on vmware/photon-os-installer#49: a module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`, rather than a local `from stigenable import KS_STIG_PACKAGES` inside downloadPkgs(). Package selection is unchanged; only where the import happens moves. Change-Id: Iff902337549b191c714ff4ef8a42564017feb402 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota
added a commit
to dcasota/photon
that referenced
this pull request
Sep 16, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which carries the form requested in review on vmware/photon-os-installer#49: a module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`, rather than a local `from stigenable import KS_STIG_PACKAGES` inside downloadPkgs(). Package selection is unchanged; only where the import happens moves. Change-Id: Iff902337549b191c714ff4ef8a42564017feb402 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota
added a commit
to dcasota/photon
that referenced
this pull request
Sep 16, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which carries the form requested in review on vmware/photon-os-installer#49: a module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`, rather than a local `from stigenable import KS_STIG_PACKAGES` inside downloadPkgs(). Package selection is unchanged; only where the import happens moves. Change-Id: Iff902337549b191c714ff4ef8a42564017feb402 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota
added a commit
to dcasota/photon
that referenced
this pull request
Sep 16, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which carries the form requested in review on vmware/photon-os-installer#49: a module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`, rather than a local `from stigenable import KS_STIG_PACKAGES` inside downloadPkgs(). Package selection is unchanged; only where the import happens moves. Change-Id: I3be44f73d323be4bb243c85be2e88d10a6d8f8a8 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota
added a commit
to dcasota/photon
that referenced
this pull request
Sep 17, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which carries the form requested in review on vmware/photon-os-installer#49: a module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`, rather than a local `from stigenable import KS_STIG_PACKAGES` inside downloadPkgs(). Package selection is unchanged; only where the import happens moves. Change-Id: Iff902337549b191c714ff4ef8a42564017feb402 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota
added a commit
to dcasota/photon
that referenced
this pull request
Sep 17, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which carries the form requested in review on vmware/photon-os-installer#49: a module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`, rather than a local `from stigenable import KS_STIG_PACKAGES` inside downloadPkgs(). Package selection is unchanged; only where the import happens moves. Change-Id: I3be44f73d323be4bb243c85be2e88d10a6d8f8a8 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes a minimal ISO offering a STIG option it cannot honour.
Symptom
Installing from a minimal ISO and selecting Apply STIG hardening in the wizard fails with:
Root cause
create_full_iso()passes--rpms-list-file, socopyRPMs()copies all ~1900 rpms and the STIG packages happen to be present.create_custom_iso()omits it, sodownloadPkgs()resolves a dependency closure fromself.pkg_listinstead — andself.pkg_listis built only frompackages_installer_initrd.jsonplus the kickstart package list.KS_STIG_PACKAGESis never consulted. The installer can request those packages at install time, but a minimal ISO has no copy of them. The media and the installer had drifted apart.A second, related gap: packages named via
--initrd-pkgsalso never reached this list — only the list file was parsed — so a package requested on the command line could not be installed into the initrd from the ISO's ownRPMS/.The change
Extend
self.pkg_listwith both, indownloadPkgs():stigenable.KS_STIG_PACKAGES— referring to the installer's own declaration rather than restating those names in a package list file. Restating them is precisely the drift that caused this. Per review,import stigenablesits at the top of the file with the other imports.self.pkg_list.extend(self.initrd_pkgs)Both touch
self.pkg_listonly, so the packages land in the ISO'sRPMS/and the initrd does not grow.Verified end to end
Ten unattended permutation-matrix rows, each a full ISO build plus a kickstart install in a VM, on both installer variants —
photon-os-installer-2.8-7and2.9-3:rsyslog,openssl-fips-provider,selinux-policy,libselinux-utils,aideandntpsec— the last two of those transitively, which is the point: the closure is resolved from the installer's own list rather than a restatement of itError(1011)count is 0 on every row, and the STIG ansible run finishes with 0 failed tasksdmesgBUG/oopsOne correction to an earlier revision of this description, which claimed the installed systems boot SELinux Enforcing: they boot Permissive, and that is correct.
selinux-policyshipsSELINUX=permissiveat subrelease ≥ 92 by design; only builds at subrelease ≤ 90 boot Enforcing. Nothing in this PR affects the mode.What these rows do not cover
self.pkg_list.extend(self.initrd_pkgs)is exercised only in the sense that it runs — the Photon build never passes--initrd-pkgs, soself.initrd_pkgsis empty on every row and that line is a no-op there. TheKS_STIG_PACKAGEShalf is what the rows actually prove.create_full_iso()is untouched by this change — it takes thecopyRPMs()branch, notdownloadPkgs()— but no full-ISO row ran, so that is reasoning rather than a measurement.extendcalls targetingself.pkg_listrather thanself.initrd_pkgs; it was not measured byte-for-byte.SUPPORTED_RELEASES) and aarch64 were not built.Compatibility
Verified to apply cleanly to photon-os-installer 2.8, 2.9 and master.