From 4e69ae4fa249430af61526ad4f7a02910c90ceb3 Mon Sep 17 00:00:00 2001 From: Kevin Wang Date: Thu, 24 Sep 2026 19:32:48 -0700 Subject: [PATCH] fix(os/mkosi): apply rootfs tmpfiles inside the image as root mkosi runs a host-side finalize script as the invoking user in a rootless build, so systemd-tmpfiles could not chown the rootfs directories to root and failed with EINVAL, aborting every rootless image build. Run it through mkosi-chroot, which becomes root in the image. mkosi-chroot bind-mounts /etc/resolv.conf, so that one link is made from outside. Signed-off-by: Kevin Wang --- os/mkosi/mkosi.finalize | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/os/mkosi/mkosi.finalize b/os/mkosi/mkosi.finalize index 1707aa8d8..4365060d1 100755 --- a/os/mkosi/mkosi.finalize +++ b/os/mkosi/mkosi.finalize @@ -13,8 +13,13 @@ ARTIFACTS="$WORK/artifacts" source "$SELF/versions.env" "$SELF/scripts/normalize-skeleton-modes.sh" "$TREE" "$FLAVOR" -# After mkosi's own tmpfiles pass, so these override package defaults. -systemd-tmpfiles --root="$TREE" --create "$SELF/rootfs.tmpfiles" +# After mkosi's own tmpfiles pass, so these override package defaults. Run it +# in the image as root: a rootless build runs this script as the caller, which +# cannot chown to root. mkosi-chroot bind-mounts /etc/resolv.conf, so that link +# is made from outside. +mkosi-chroot systemd-tmpfiles --create --exclude-prefix=/etc/resolv.conf \ + "$CHROOT_SRCDIR/dstack/os/mkosi/rootfs.tmpfiles" +ln -sfn /run/systemd/resolve/stub-resolv.conf "$TREE/etc/resolv.conf" "$SELF/scripts/write-os-release.sh" \ "$TREE" "$DSTACK_VERSION" "$DSTACK_CODENAME" mkdir -p "$KSTAGE/usr/lib" "$OUTPUTDIR/.image-tools"