gf-oemid: Don't use the container's /tmp #394
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
We were previously hitting issues with the final images having an MCS
label. This turned out to be due to the
gf-oemidusing/tmpwithinthe container. In the unprivileged path, the whole container filesystem
uses MCS and so the image created there would inherit that label.
Just fix this by making
gf-oemiduse a tmpdir in the destination path;we're already in a temporary work directory anyway when calling it from
cmd-build. Staying on the same bind mount also ensures that we're notcopying the image across filesystems (and with reflinks on, even the
first copy is a no-op!), so this should make the build process a bit
faster too.
Finally, this also allows us to drop the call to
chcon, which isproblematic for systems without SELinux enabled on the host.