From 84397b50989670c2cfff01de23a5a73e67cd4088 Mon Sep 17 00:00:00 2001 From: Robert C Jennings Date: Sat, 18 Jul 2020 16:52:18 -0500 Subject: [PATCH] Avoid rbind /sys for chroot snap pre-seeding (cgroups fail to unmount) Builds in LP with the Xenial kernel were happy with the recursive mount of /sys inside the chroot while performing snap-preseeding but autopkgtests with the groovy kernel failed. With the groovy kernel the build was unable to unmount sys/kernel/slab/*/cgroup/* (Operation not permitted). This patch mounts /sys and /sys/kernel/security in the chroot in the same way we've added for binary hooks. This provides the paths under /sys needed for snap-preseed while avoiding issues unmounting other paths. --- debian/changelog | 6 ++++++ live-build/auto/build | 3 ++- 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/debian/changelog b/debian/changelog index 6bf1b718..0ebdecf4 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,9 @@ +livecd-rootfs (2.677) groovy; urgency=medium + + * Avoid rbind /sys for chroot snap pre-seeding (cgroups fail to unmount) + + -- Robert C Jennings Sat, 18 Jul 2020 16:51:05 -0500 + livecd-rootfs (2.676) groovy; urgency=medium * apparmor: Add generic v5.4 kernel apparmor features diff --git a/live-build/auto/build b/live-build/auto/build index 2d3e2431..4cd879bd 100755 --- a/live-build/auto/build +++ b/live-build/auto/build @@ -119,7 +119,8 @@ preinstall_snaps() { fi mount --rbind /dev chroot/dev - mount --rbind /sys chroot/sys + mount --bind /sys chroot/sys + mount --bind /sys/kernel/security chroot/sys/kernel/security mount --bind /proc chroot/proc # Provide more up to date apparmor features, matching target kernel mount -o bind /usr/share/livecd-rootfs/live-build/apparmor/generic chroot/sys/kernel/security/apparmor/features