diff --git a/docs/infra/keel-provision.pending b/docs/infra/keel-provision.pending index c9efc5c..99b9781 100755 --- a/docs/infra/keel-provision.pending +++ b/docs/infra/keel-provision.pending @@ -104,6 +104,51 @@ lxc.idmap = u 0 $SUB_UID 65536 lxc.idmap = g 0 $SUB_GID 65536 LXCDEF chown runner:runner /home/runner/.config/lxc/default.conf +# The nesting profile the containers run under, as the lxc package ships it +# (1:6.0.4-4+deb13u4) plus two mount rules systemd 257 needs: at boot, +# systemd-journald (and every unit with credentials) runs sd-mkdcreds, +# which mounts a ramfs on /run/credentials/ and remounts it +# read-only with (ro,remount,bind,nosuid,nodev,noexec,nosymfollow). The +# stock profile allows neither, so in a CI container journald died with +# status=243/CREDENTIALS, /dev/log was gone, and the first boot hooks that +# log under bash -e died with it (Keel-Linux/inithooks#38, the published +# core 19.0-6 booted headless on 2026-10-03). The file is the package's +# conffile, written here as /etc/nftables.conf is: an lxc upgrade that +# changes it asks, and this script is the answer. The profile keeps its +# name, so bin/unprivileged-lxc of keel-linux/.github and the default.conf +# above need no change. +cat > /etc/apparmor.d/lxc/lxc-default-with-nesting << 'PROFILE' +# Do not load this file. Rather, load /etc/apparmor.d/lxc-containers, which +# will source all profiles under /etc/apparmor.d/lxc +# +# Written by keel-provision: the lxc package's profile, plus the two mount +# rules marked below (systemd 257 credentials, Keel-Linux/inithooks#38). + +profile lxc-container-default-with-nesting flags=(attach_disconnected,mediate_deleted) { + #include + #include + + deny /dev/.lxc/proc/** rw, + deny /dev/.lxc/sys/** rw, + mount fstype=proc -> /var/cache/lxc/**, + mount fstype=sysfs -> /var/cache/lxc/**, + mount options=(rw,bind), + mount options=(rw,rbind) -> /run/systemd/mount-rootfs/, + mount options=(rw,rbind) -> /run/systemd/mount-rootfs/**, + mount options=(rw,rbind) -> /run/systemd/unit-root/, + mount options=(rw,rbind) -> /run/systemd/unit-root/**, + mount options=(rw,rshared) -> /, + mount options=(rw,nosuid,nodev,noexec) proc -> /run/systemd/unit-root/proc/, + mount fstype=cgroup -> /sys/fs/cgroup/**, + mount fstype=cgroup2 -> /sys/fs/cgroup/**, + # keel-provision: systemd 257 sd-mkdcreds, the credentials of a unit + mount fstype=ramfs, + mount options=(ro,remount,bind,nosuid,nodev,noexec,nosymfollow), +} +PROFILE +chmod 0644 /etc/apparmor.d/lxc/lxc-default-with-nesting +apparmor_parser -r /etc/apparmor.d/lxc-containers +aa-status 2>/dev/null | grep -q 'lxc-container-default-with-nesting' && log "nesting profile loaded with the credentials mounts" loginctl enable-linger runner install -d -m 0755 -o runner -g runner /var/tmp/keel-ci rm -f /usr/local/sbin/keel-ci-boot-test /usr/local/sbin/keel-ci-cleanup