From 2d1a90f122e37ed381d25bbfd16278ff2d4b0f00 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marcos=20M=C3=A9ndez?= Date: Sun, 27 Sep 2026 01:54:50 +0000 Subject: [PATCH] test: give the boot test container the apparmor profile systemd units need With the rebuilt layer the gate finally boots the appliance, and the first boot then fails in firstboot.d/40nodebb: Job for redis-server.service failed Main PID: 1167 (code=exited, status=226/NAMESPACE) redis-server.service asks systemd for a mount namespace, which the stock LXC container apparmor profile refuses, so Redis never comes up, the hook exits 1 and the forum is never set up. Adding the two lines to the container config and restarting it makes the unit active, measured on the build host against a container assembled from /mnt/builds/layers. The appliance containers on that host have carried both settings all along; only the config bt_lxc_config writes was missing them. The boot test needs them for the same reason: it boots a real systemd. Nothing in the layer changes, so no changelog entry. --- tests/boot-test.bats | 6 ++++++ tests/lib/boot-test-lib.sh | 10 ++++++++++ 2 files changed, 16 insertions(+) diff --git a/tests/boot-test.bats b/tests/boot-test.bats index 7e74344..dd337e4 100644 --- a/tests/boot-test.bats +++ b/tests/boot-test.bats @@ -241,6 +241,12 @@ never() { return 1; } [[ $output == *"lxc.net.0.type = veth"* ]] } +@test "lxc_config: asks for the apparmor profile a unit with a namespace needs" { + output=$(bt_lxc_config keel-nodebb-boot-test /var/lib/lxc/keel-nodebb-boot-test/rootfs br0) + [[ $output == *"lxc.apparmor.profile = generated"* ]] + [[ $output == *"lxc.apparmor.allow_nesting = 1"* ]] +} + @test "spec_targets: both paths the first boot reads, under the rootfs" { output=$(bt_spec_targets /r) [ "$output" = $'/r/etc/keel/instance.yaml\n/r/etc/inithooks.yaml' ] diff --git a/tests/lib/boot-test-lib.sh b/tests/lib/boot-test-lib.sh index d5920fe..05fed5f 100644 --- a/tests/lib/boot-test-lib.sh +++ b/tests/lib/boot-test-lib.sh @@ -216,11 +216,21 @@ bt_lxc_config() { # bt_lxc_config NAME ROOTFS BRIDGE: an LXC config for a plain rootfs # directory on a bridge; the address comes from the bridge (SLAAC or # DHCPv6), the spec declares managed_by: host. + # + # The apparmor pair is not decoration. Under the stock container profile + # a unit that asks systemd for a mount namespace is refused, and + # redis-server.service asks: it fails with status=226/NAMESPACE, so + # firstboot.d/40nodebb never reaches Redis and the forum never starts. A + # generated profile with nesting allowed is what a container running + # systemd needs, and it is what the appliance containers on the build + # host have carried all along. cat <