install: Mount /boot
readonly by default
#341
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
As we want to support enabling
root.transient
in some images, this means that things likeapt|dnf install foo
literally just works out of the box.However...we have a looming danger around things like kernels. Typically the package installation scripts for those aren't going to handle this correctly.
Let's mount
/boot
readonly by default, as we have been doing in Fedora CoreOS and derivatives for a while.Now I'm not totally happy with this because ultimately I think this should be configurable by the OS, not hardcoded in bootc. We have some thought to put in to exactly how that's exposed.
But for now let's set the precedent here.