Skip to content

Give the boot test container the apparmor profile systemd units need - #8

Merged
marcos-mendez merged 1 commit into
mainfrom
fix/boot-test-apparmor
Sep 27, 2026
Merged

marcos-mendez merged 1 commit into
mainfrom
fix/boot-test-apparmor

Conversation

@marcos-mendez

Copy link
Copy Markdown
Contributor

With the rebuilt layer the appliance gate gets all the way to a booted
container for the first time. The first boot then fails in
firstboot.d/40nodebb:

Job for redis-server.service failed because the control process exited
with error code.
Main PID: 1167 (code=exited, status=226/NAMESPACE)

redis-server.service asks systemd for a mount namespace, and the stock LXC
container apparmor profile refuses it. Redis never comes up, the hook exits 1,
and the forum is never set up, so the boot test's HTTP check cannot pass.

Measured on the build host, on a container assembled from
/mnt/builds/layers: adding

lxc.apparmor.profile = generated
lxc.apparmor.allow_nesting = 1

to the container config and restarting it makes redis-server.service
active. The long lived appliance containers on that host have both settings;
only the config bt_lxc_config writes was missing them, which went unnoticed
while the published layer could not finish its first boot at all.

Nothing in the layer changes, so there is no changelog entry.

Test plan:

  • bats tests/boot-test.bats, 36 tests, one added for the two settings
  • shellcheck -S warning tests/lib/boot-test-lib.sh
  • appliance / build-and-boot against the republished chain

… need

With the rebuilt layer the gate finally boots the appliance, and the first
boot then fails in firstboot.d/40nodebb:

    Job for redis-server.service failed
    Main PID: 1167 (code=exited, status=226/NAMESPACE)

redis-server.service asks systemd for a mount namespace, which the stock LXC
container apparmor profile refuses, so Redis never comes up, the hook exits 1
and the forum is never set up. Adding the two lines to the container config
and restarting it makes the unit active, measured on the build host against
a container assembled from /mnt/builds/layers.

The appliance containers on that host have carried both settings all along;
only the config bt_lxc_config writes was missing them. The boot test needs
them for the same reason: it boots a real systemd.

Nothing in the layer changes, so no changelog entry.
@marcos-mendez
marcos-mendez merged commit 6693fbd into main Sep 27, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant