Repository navigation
Give the boot test container the apparmor profile systemd units need - #8
Merged
Merged
Conversation
… need
With the rebuilt layer the gate finally boots the appliance, and the first
boot then fails in firstboot.d/40nodebb:
Job for redis-server.service failed
Main PID: 1167 (code=exited, status=226/NAMESPACE)
redis-server.service asks systemd for a mount namespace, which the stock LXC
container apparmor profile refuses, so Redis never comes up, the hook exits 1
and the forum is never set up. Adding the two lines to the container config
and restarting it makes the unit active, measured on the build host against
a container assembled from /mnt/builds/layers.
The appliance containers on that host have carried both settings all along;
only the config bt_lxc_config writes was missing them. The boot test needs
them for the same reason: it boots a real systemd.
Nothing in the layer changes, so no changelog entry.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
With the rebuilt layer the appliance gate gets all the way to a booted
container for the first time. The first boot then fails in
firstboot.d/40nodebb:redis-server.serviceasks systemd for a mount namespace, and the stock LXCcontainer apparmor profile refuses it. Redis never comes up, the hook exits 1,
and the forum is never set up, so the boot test's HTTP check cannot pass.
Measured on the build host, on a container assembled from
/mnt/builds/layers: addingto the container config and restarting it makes
redis-server.serviceactive. The long lived appliance containers on that host have both settings;
only the config
bt_lxc_configwrites was missing them, which went unnoticedwhile the published layer could not finish its first boot at all.
Nothing in the layer changes, so there is no changelog entry.
Test plan:
bats tests/boot-test.bats, 36 tests, one added for the two settingsshellcheck -S warning tests/lib/boot-test-lib.shappliance / build-and-bootagainst the republished chain