Skip to content

test: drop vTPM from virt-install VMs - #193

Open
miabbott wants to merge 1 commit into
fedora-iot:mainfrom
miabbott:fix-vtpm-ci
Open

test: drop vTPM from virt-install VMs#193
miabbott wants to merge 1 commit into
fedora-iot:mainfrom
miabbott:fix-vtpm-ci

Conversation

@miabbott

@miabbott miabbott commented Aug 6, 2026

Copy link
Copy Markdown
Member

greenboot tests don't exercise TPM or measured-boot functionality, but virt-install's os-variant device policy auto-adds a vTPM device for UEFI boots on modern os-variants. A Fedora 44 SELinux userspace regression (3.10->3.11) currently breaks swtpm-selinux's CIL policy compilation (RHBZ#2511086), leaving /usr/bin/swtpm mislabeled and unable to exec under libvirt, which fails every UEFI VM boot in CI. Since the vTPM was never needed, explicitly disable it instead of waiting for the swtpm fix to reach stable Fedora 44 repos.

Suggested-by: Klára Nečasová knecasov@redhat.com
🤖 Assisted-by: OpenCode (Claude Sonnet 5)

greenboot tests don't exercise TPM or measured-boot functionality,
but virt-install's os-variant device policy auto-adds a vTPM device
for UEFI boots on modern os-variants. A Fedora 44 SELinux userspace
regression (3.10->3.11) currently breaks swtpm-selinux's CIL policy
compilation (RHBZ#2511086), leaving /usr/bin/swtpm mislabeled and
unable to exec under libvirt, which fails every UEFI VM boot in CI.
Since the vTPM was never needed, explicitly disable it instead of
waiting for the swtpm fix to reach stable Fedora 44 repos.

Suggested-by: Klára Nečasová <knecasov@redhat.com>
🤖 Assisted-by: OpenCode (Claude Sonnet 5)

Signed-off-by: Micah Abbott <miabbott@redhat.com>
@miabbott

miabbott commented Aug 6, 2026

Copy link
Copy Markdown
Member Author

It looks like the TPM fix got pulled in with 565377c as part of #190; this just rounds it out with one last fix to the fedora-iot-raw script

@miabbott

miabbott commented Aug 7, 2026

Copy link
Copy Markdown
Member Author

/test

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant