Repository navigation
fix(bootc): use temporary directory for post-install mounts - #390
Conversation
Inside ostree/composefs build containers, /mnt is a dangling symlink pointing to var/mnt (which does not exist in the build container). Running mkdir -p on /mnt or subdirectories like /mnt/esp and /mnt/root fails with file-exists or directory errors, causing local bootc VM builds to fail at post-install verification. Use mktemp -d to allocate private temporary directories for throwaway ESP, composefs root, and post-install/provisioning mounts. Fixes #389 Hive-Run: #389 Hive-Plan: bootc-mount-fix Hive-Spec: bootc-local-build#mount-points Signed-off-by: James Reilly <jreilly1821@gmail.com>
There was a problem hiding this comment.
Read the changes in cmd/create.go and cmd/cmd_test.go.
Isolating throwaway post-install and ESP mount points with mktemp -d cleanly resolves the issue where /mnt is a dangling symlink (/mnt -> var/mnt) inside ostree/composefs build containers (fixing #389). Extracting localBootcScript makes the generated installation script directly testable in unit tests without requiring podman or loop devices. All CI checks are green.
Looks correct to me.
— hive: agent=reviewer backend=agy model=gemini-3.8-flash-medium effort=medium agy=1.2.13
Signed-off-by: James Reilly <jreilly1821@gmail.com> # Conflicts: # cmd/create.go
|
hive-base-moved: merged 🐝 Hive Agent: |
There was a problem hiding this comment.
Read the full diff against the current tree (cmd/create.go at main still has the hardcoded /mnt paths at lines 645–673). This looks correct to me:
- The extraction of the inline shell into
localBootcScript(disk, provisionScript)is behavior-preserving: the backend-detection block,bootc install to-diskinvocation, composefs ESP/root fixups, and final post-install mount/provision chain are line-for-line equivalent, with only/mnt/esp,/mnt/root, and/mntreplaced bymktemp -dpaths. - The provision chain keeps its semantics:
mount "${DISK}p3" "$MNT" && cat /output/provision.sh | chroot "$MNT" /bin/bash && umount "$MNT"mirrors the oldmount … /mnt … && umount /mntordering, so provisioning still only runs after a successful mount. - The new tests in
cmd/cmd_test.goassert both the mktemp usage and the absence of every hardcoded/mntform, which pins the #389 regression.
One minor note (not a defect): under set -e, if the final mount fails, the trailing rm -rf "$MNT" lines don't run — but these are tempdirs inside a discarded podman run container, so nothing leaks onto the host.
Looks correct to me; a maintainer can merge with confidence.
— hive: agent=reviewer backend=copilot model=claude-fable-5 copilot=1.0.88
|
Reviewed and verified against a real bootc image. The diagnosis and the approach are both right, but I'd hold the merge for a one-word change — the new The root cause checks out exactly$ podman run --rm quay.io/fedora/fedora-bootc:41 sh -c 'ls -ld /mnt; mkdir -p /mnt'
lrwxrwxrwx 2 root root 7 Jan 1 1970 /mnt -> var/mnt
mkdir: cannot create directory '/mnt': File exists
The problem:
|
There was a problem hiding this comment.
Review: corral#390
I verified the changes against the codebase and build paths:
- Correctness & Mount Safety:
- In
cmd/create.go:778-804, replacing the fixed/mnt/esp,/mnt/root, and/mntpaths with dedicated temporary directories created viamktemp -dprevents failures caused by dangling symlinks (such as/mnt -> var/mntin ostree/composefs container environments, #389). - Each temporary directory (
MNT_ESP,MNT_ROOT, andMNT) is cleanly unmounted (umount/sync) and removed withrm -rfafter use. - The provisioning script execution path (
cat /output/provision.sh | chroot "$MNT" /bin/bash) accurately targets the dynamically created mount directory.
- In
- Intent Alignment:
- Directly addresses and resolves #389 without scope creep.
- Unit tests in
cmd/cmd_test.go:1003-1037ensure that forbidden hardcoded mount paths are guarded against regression and that the provisioning script targets"$MNT".
The changes look correct and safe to land.
— hive: agent=reviewer backend=agy model=gemini-3.8-flash-medium effort=medium agy=1.3.0
Inside ostree/composefs build containers,
/mntis a symlink pointing tovar/mnt(which does not exist prior to first boot). Runningmkdir -pon/mntor subpaths like/mnt/espand/mnt/rootfails with file-exists or directory errors, causing local bootc VM builds to fail at post-install verification.Changes
/mnt/esp,/mnt/root, and/mntpaths in the local bootc install script with isolatedmktemp -dtemporary directories.cmd/cmd_test.goverifying the generated script avoids hardcoded/mntpaths and correctly usesmktemp -d.Fixes #389
Validation
just fmt-check vet buildgo test ./cmd/...go test -tags bootc ./cmd/...— hive: backend=agy model=gemini-3.7-flash-high effort=low
🐝 Hive Agent:
contributor| SHA:b79973f