Skip to content

isoBuilder: put installer-requestable packages on the media - #49

Open
dcasota wants to merge 1 commit into
vmware:masterfrom
dcasota:upstream/isobuilder-installer-pkgs-on-media
Open

dcasota wants to merge 1 commit into
vmware:masterfrom
dcasota:upstream/isobuilder-installer-pkgs-on-media

Conversation

@dcasota

@dcasota dcasota commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Fixes a minimal ISO offering a STIG option it cannot honour.

Symptom

Installing from a minimal ISO and selecting Apply STIG hardening in the wizard fails with:

Error(1011) : No matching packages

Root cause

create_full_iso() passes --rpms-list-file, so copyRPMs() copies all ~1900 rpms and the STIG packages happen to be present. create_custom_iso() omits it, so downloadPkgs() resolves a dependency closure from self.pkg_list instead — and self.pkg_list is built only from packages_installer_initrd.json plus the kickstart package list.

KS_STIG_PACKAGES is never consulted. The installer can request those packages at install time, but a minimal ISO has no copy of them. The media and the installer had drifted apart.

A second, related gap: packages named via --initrd-pkgs also never reached this list — only the list file was parsed — so a package requested on the command line could not be installed into the initrd from the ISO's own RPMS/.

The change

Extend self.pkg_list with both, in downloadPkgs():

  • stigenable.KS_STIG_PACKAGES — referring to the installer's own declaration rather than restating those names in a package list file. Restating them is precisely the drift that caused this. Per review, import stigenable sits at the top of the file with the other imports.
  • self.pkg_list.extend(self.initrd_pkgs)

Both touch self.pkg_list only, so the packages land in the ISO's RPMS/ and the initrd does not grow.

Verified end to end

Ten unattended permutation-matrix rows, each a full ISO build plus a kickstart install in a VM, on both installer variants — photon-os-installer-2.8-7 and 2.9-3:

  • media carries 290 rpms, and every package the STIG option can request resolves on it: rsyslog, openssl-fips-provider, selinux-policy, libselinux-utils, aide and ntpsec — the last two of those transitively, which is the point: the closure is resolved from the installer's own list rather than a restatement of it
  • a negative control (a name that must never resolve) finds 0, so the presence checks above are not vacuously passing on a broken extraction
  • Error(1011) count is 0 on every row, and the STIG ansible run finishes with 0 failed tasks
  • installed systems boot clean: 0 failed units, 0 dmesg BUG/oops

One correction to an earlier revision of this description, which claimed the installed systems boot SELinux Enforcing: they boot Permissive, and that is correct. selinux-policy ships SELINUX=permissive at subrelease ≥ 92 by design; only builds at subrelease ≤ 90 boot Enforcing. Nothing in this PR affects the mode.

What these rows do not cover

  • self.pkg_list.extend(self.initrd_pkgs) is exercised only in the sense that it runs — the Photon build never passes --initrd-pkgs, so self.initrd_pkgs is empty on every row and that line is a no-op there. The KS_STIG_PACKAGES half is what the rows actually prove.
  • create_full_iso() is untouched by this change — it takes the copyRPMs() branch, not downloadPkgs() — but no full-ISO row ran, so that is reasoning rather than a measurement.
  • "the initrd does not grow" follows from both extend calls targeting self.pkg_list rather than self.initrd_pkgs; it was not measured byte-for-byte.
  • Release 4.0 (also in SUPPORTED_RELEASES) and aarch64 were not built.

Compatibility

Verified to apply cleanly to photon-os-installer 2.8, 2.9 and master.

Comment thread photon_installer/isoBuilder.py Outdated
# UI modules, which need not be a module-level dependency of the ISO
# builder. These go to the ISO's RPMS/ only, not into self.initrd_pkgs,
# so the initrd does not grow.
from stigenable import KS_STIG_PACKAGES

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you please move this to the top of the file, with import stigenable, and refer to it as stigenable.KS_STIG_PACKAGES?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

git apply --check (strict, no fuzz) returns 0 on v2.8, v2.9 and origin/master; after applying, isoBuilder.py compiles, import stigenable works headless, isoBuilder.stigenable.KS_STIG_PACKAGES is stigenable.KS_STIG_PACKAGES holds, and on all three the hunk lands in downloadPkgs() with the import at module level.
Tested on minimal-iso x86_64. Ongoing full-iso build should be the same. aarch64 not tested.

Two gaps in how the download list is built.

1. The STIG menu offers "Apply STIG hardening", which makes the installer
   request KS_STIG_PACKAGES at install time. Those names were never added to
   the ISO's own RPMS/, so on a minimal ISO - where downloadPkgs() resolves a
   closure rather than copying every rpm - the packages simply were not there
   and the install failed with "Error(1011) : No matching packages".
   Refer to stigenable.KS_STIG_PACKAGES rather than restating the names in a
   package list file; restating them is exactly how the media and the
   installer drifted apart.

2. Packages named via --initrd-pkgs never reached this list either. Only the
   list *file* was parsed, so a package requested on the command line could
   not be installed into the initrd from the ISO's own RPMS/.

Both extend self.pkg_list only, so they land in the ISO's RPMS/ and the
initrd does not grow.

Verified end to end: a minimal ISO built with this carries 290 rpms instead
of 254, including selinux-policy, libselinux-utils, rsyslog, aide,
openssl-fips-provider and ntpsec; the UI wizard's STIG option completes; and
the installed system comes up SELinux Enforcing with 0 failed ansible tasks.

Signed-off-by: Daniel Casota <dcasota@gmail.com>

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
@dcasota
dcasota force-pushed the upstream/isobuilder-installer-pkgs-on-media branch from 5a6fff7 to aefaa84 Compare September 1, 2026 18:16
dcasota added a commit to dcasota/photon that referenced this pull request Sep 1, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which
carries the form requested in review on vmware/photon-os-installer#49: a
module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`,
rather than a local `from stigenable import KS_STIG_PACKAGES` inside
downloadPkgs().

Package selection is unchanged; only where the import happens moves.

Change-Id: Idbc6e7565c915770305eeb22a7198ba649735ca0
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota added a commit to dcasota/photon that referenced this pull request Sep 1, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which
carries the form requested in review on vmware/photon-os-installer#49: a
module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`,
rather than a local `from stigenable import KS_STIG_PACKAGES` inside
downloadPkgs().

Package selection is unchanged; only where the import happens moves.

Change-Id: I3be44f73d323be4bb243c85be2e88d10a6d8f8a8
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota added a commit to dcasota/photon that referenced this pull request Sep 1, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which
carries the form requested in review on vmware/photon-os-installer#49: a
module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`,
rather than a local `from stigenable import KS_STIG_PACKAGES` inside
downloadPkgs().

Package selection is unchanged; only where the import happens moves.

Change-Id: Iff902337549b191c714ff4ef8a42564017feb402
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota added a commit to dcasota/photon that referenced this pull request Sep 16, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which
carries the form requested in review on vmware/photon-os-installer#49: a
module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`,
rather than a local `from stigenable import KS_STIG_PACKAGES` inside
downloadPkgs().

Package selection is unchanged; only where the import happens moves.

Change-Id: Iff902337549b191c714ff4ef8a42564017feb402
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota added a commit to dcasota/photon that referenced this pull request Sep 16, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which
carries the form requested in review on vmware/photon-os-installer#49: a
module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`,
rather than a local `from stigenable import KS_STIG_PACKAGES` inside
downloadPkgs().

Package selection is unchanged; only where the import happens moves.

Change-Id: Iff902337549b191c714ff4ef8a42564017feb402
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota added a commit to dcasota/photon that referenced this pull request Sep 16, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which
carries the form requested in review on vmware/photon-os-installer#49: a
module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`,
rather than a local `from stigenable import KS_STIG_PACKAGES` inside
downloadPkgs().

Package selection is unchanged; only where the import happens moves.

Change-Id: Iff902337549b191c714ff4ef8a42564017feb402
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota added a commit to dcasota/photon that referenced this pull request Sep 16, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which
carries the form requested in review on vmware/photon-os-installer#49: a
module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`,
rather than a local `from stigenable import KS_STIG_PACKAGES` inside
downloadPkgs().

Package selection is unchanged; only where the import happens moves.

Change-Id: I3be44f73d323be4bb243c85be2e88d10a6d8f8a8
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota added a commit to dcasota/photon that referenced this pull request Sep 17, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which
carries the form requested in review on vmware/photon-os-installer#49: a
module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`,
rather than a local `from stigenable import KS_STIG_PACKAGES` inside
downloadPkgs().

Package selection is unchanged; only where the import happens moves.

Change-Id: Iff902337549b191c714ff4ef8a42564017feb402
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
dcasota added a commit to dcasota/photon that referenced this pull request Sep 17, 2026
Regenerated 0008 from github.com/dcasota/photon-os-installer @ 56ae83c, which
carries the form requested in review on vmware/photon-os-installer#49: a
module-level `import stigenable` referenced as `stigenable.KS_STIG_PACKAGES`,
rather than a local `from stigenable import KS_STIG_PACKAGES` inside
downloadPkgs().

Package selection is unchanged; only where the import happens moves.

Change-Id: I3be44f73d323be4bb243c85be2e88d10a6d8f8a8
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants