Skip to content

fix(os/mkosi): apply rootfs tmpfiles inside the image as root - #1409

Closed
kvinwang wants to merge 1 commit into
nextfrom
fix/mkosi-rootless-tmpfiles
Closed

kvinwang wants to merge 1 commit into
nextfrom
fix/mkosi-rootless-tmpfiles

Conversation

@kvinwang

@kvinwang kvinwang commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

#1331 moved rootfs.tmpfiles into mkosi.finalize, which runs on the host as the invoking user in a rootless build. systemd-tmpfiles then cannot chown the d ... root root entries and every rootless make os-image fails:

fchownat() of /buildroot/dstack failed: Invalid argument
‣ "/work/finalize" returned non-zero exit code 73.

CI is unaffected because it runs mkosi as root. Apply the file through mkosi-chroot (root in the image) instead; mkosi-chroot bind-mounts /etc/resolv.conf, so that link is created from outside.

Verification

  • Rootless build (mkosi 26, user with subuid range) on a TDX host: prod, dev and identity-variant images now build; before this change the finalize step failed as above.
  • The images boot, and the squashfs rootfs carries the tmpfiles-owned paths as 0755 0/0 / 0700 0/0 with the /etc/resolv.conf, /tapp and /usr/sbin/init links; the PR 841 physical-TDX sweep passes with this change (together with fix(os/mkosi): keep the TPM keystore root-owned 0755 at runtime #1413 for the runtime keystore mode).

mkosi runs a host-side finalize script as the invoking user in a rootless
build, so systemd-tmpfiles could not chown the rootfs directories to root
and failed with EINVAL, aborting every rootless image build. Run it through
mkosi-chroot, which becomes root in the image. mkosi-chroot bind-mounts
/etc/resolv.conf, so that one link is made from outside.

Signed-off-by: Kevin Wang <wy721@qq.com>
@kvinwang

Copy link
Copy Markdown
Collaborator Author

Superseded by #1415, which reverts #1331 instead of patching its symptoms separately.

@kvinwang kvinwang closed this Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant