Repository navigation
Switch root once in init and run the headers worker from the image - #479
Closed
sjmiller609 wants to merge 1 commit into
Closed
sjmiller609 wants to merge 1 commit into
sjmiller609 wants to merge 1 commit into
Conversation
Move the root switch out of the two mode functions into main.go, after the shared phases and before mode dispatch, so everything after one point sees only the image rootfs. Make / private before MS_MOVE instead of relying on the initrd tree being private. Stage the kernel headers tarball into the image before the switch in both modes and run the worker from image paths afterwards, which drops the initrd path variant and the mount-namespace unshare. systemd unit injection now runs after the switch against /. Tests: share the manager fixture across the integration tests, assert the guest root is the image overlay and that kernel headers install in both exec and systemd mode, and fix the dockerd readiness failure message, which formatted its output before polling.
Collaborator
Author
|
closing: too much change for what it buys. the useful subset (make / private before MS_MOVE, stale comments, guest-root assertion and readiness message fix in the tests) is folded into #478. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #478. Follow-up cleanup from review; #478 stands on its own.
summary
switchRootmoves fromrunExecMode/runSystemdModeintomain.go, after the shared phases and before mode dispatch. Everything after that line, in either mode, sees only the image rootfs.switchRootmakes/MS_PRIVATE|MS_RECbeforeMS_MOVEinstead of relying on the initrd tree happening to be private./kernel-headers.tar.gzinto the image at/opt/hypeman/kernel-headers.tar.gzbefore the switch (systemd mode also copies the init binary, as before) and run the worker from image paths after it. This dropsinitrdKernelHeadersPaths, the--headers-workerinitrd variant, and theCLONE_NEWNSunshare. Exec mode re-execs/proc/self/exe, which still resolves after the switch. Exec-mode guests now see the tarball bind mount at/opt/hypeman/kernel-headers.tar.gz, as systemd-mode guests already did./; the helpers take a root argument and usefilepath.Join.newIntegrationManagersfixture shared by the systemd, vGPU, and nested-docker tests. New assertions in bothTestSystemdModeandTestNestedDockerExecRoot: the guest/is the image overlay in/proc/self/mountinfo, and/run/hypeman/kernel-headers.statusreachesreadywith headers and thebuildsymlink installed. The dockerd readiness check usesEventuallyWithTso a failure reports the lastdocker infooutput instead of an empty string.testing
on a KVM dev box:
TestNestedDockerExecRootandTestSystemdModepass with the new root and headers assertions in both modesTestBuilderPersistentCacheReuse,TestExecInstanceNonTTY,TestExecWithDebianMinimal,TestCpToAndFromInstance,TestCpDirectoryToInstance,TestVolumeMultiAttachReadOnlypassgo vetandgo test ./lib/system/init/pass