Repository navigation
fix(packaging): report rootfs extraction failures in the arch smoke test - #2137
nullPointerEnjoyer wants to merge 2 commits into
Conversation
Brings in the chroot-based foreign-architecture smoke test shipped in v1.4.1 (via the release realignment merge), so the reporting fixes on top apply to the code that actually runs in CI.
|
🔍 OpenCodeReview found 5 issue(s) in this PR.
📄
|
| if ! probe_out="$(pacman --disable-sandbox -Sh 2>&1)"; then | ||
| echo "ERROR: chroot pacman probe failed; if it rejected --disable-sandbox, pacman >= 6.1 is required. Probe output: $probe_out" >&2 | ||
| exit 1 | ||
| fi |
There was a problem hiding this comment.
The probe treats any non-zero exit as 'pacman rejected --disable-sandbox' but the same failure signature occurs for unrelated causes: no network for the -Sh sync-database path in an offline chroot, a corrupted rootfs pacman.conf, or a missing downloader binary. In those cases the operator is sent chasing a pacman-version problem that does not exist. Since the rootfs is sha256-pinned this is a narrow window, but including the probe output in the message (or a distinct hint) would save a debugging cycle.
Suggestion:
| if ! probe_out="$(pacman --disable-sandbox -Sh 2>&1)"; then | |
| echo "ERROR: chroot pacman probe failed; if it rejected --disable-sandbox, pacman >= 6.1 is required. Probe output: $probe_out" >&2 | |
| exit 1 | |
| fi | |
| if ! probe_out="$(pacman --disable-sandbox -Sh 2>&1)"; then | |
| echo "ERROR: chroot pacman probe failed (pacman >= 6.1 required for --disable-sandbox; network/config problems produce the same signature). Probe output: $probe_out" >&2 | |
| exit 1 | |
| fi |
| rm -f "$CHROOT_DIR/etc/mtab" | ||
| cp /proc/self/mounts "$CHROOT_DIR/etc/mtab" |
There was a problem hiding this comment.
This static copy of /proc/self/mounts is the host container's mount table (overlay root, /work bind mount, docker virtual filesystems), none of which exist inside the chroot. Modern pacman computes its free-space check with statvfs() on the target directory, so a wrong mtab is mostly harmless today, but if pacman (or any hook/script run during -U, e.g. ldconfig under emulation) ever consults it, the bogus entries could mislead diagnostics or trigger a spurious disk-space failure that is very hard to debug in CI. Consider documenting this explicitly here (or minimizing the table), since the comment currently implies the copy is a faithful stand-in.
Suggestion:
| rm -f "$CHROOT_DIR/etc/mtab" | |
| cp /proc/self/mounts "$CHROOT_DIR/etc/mtab" | |
| rm -f "$CHROOT_DIR/etc/mtab" | |
| # Host mount table; modern pacman uses statvfs() on the target dir, so this | |
| # is a best-effort stand-in only — entries reference host paths absent from | |
| # the chroot. | |
| cp /proc/self/mounts "$CHROOT_DIR/etc/mtab" |
Summary
Fixes the findings from the review of #2134, which are pre-existing in
packaging/checks/smoke-arch.shas shipped in v1.4.1 (that PR only realignsmaster with the release branch and intentionally carries no fixes).
Merge after #2134 — commit 1 (326a28a) syncs the script with the
release-v1.4.1 version so this PR's diff shows only the fixes once #2134
lands; until then the diff includes the sync.
Fixes (all on
smoke-arch.sh):2>/dev/null || truesilently passed the smoke test on a corrupt/truncated rootfs. Any non-zero
tar exit now fails the run with the exit code logged.
on every path; INT/TERM mapped to clean exits. The chroot's exit code is
propagated.
pacman -Ql | grep -qman-page checksrace with
set -o pipefail; the file list is captured first and greppedfrom a variable.
an invalid
kind(node/gui), before any state is touched.ArchLinuxARM-aarch64-latest.tar.gzand executes it as root in the chroot,with no verification. It now pins a sha256 (bump deliberately, same policy
as
packaging/images.env), verifies each mirror's download before use, andfalls through to the next mirror on failure or mismatch (the computed hash
is logged).
ALARM_ROOTFS_URL/ALARM_ROOTFS_SHA256overrides for localtesting are visible as job-log warnings.
window (
--retry-max-time), connect/transfer timeouts.qemu-aarch64registeredwith F (fix-binary) flags; the script checks and fails fast with a precise
message instead of dying mid-
pacman(skipped with a warning whenbinfmt_misc is not mounted, e.g. plain
docker run).own design decision (
--exclude='./dev/*'); the essential nodes(
null,zero,random,urandom) are recreated withmknodso thechroot's redirects and hooks work.
(
pacman --disable-sandbox -Sh, needs pacman >= 6.1) replaces help-textmatching, with probe output included in the failure message.
Notes / deliberate non-changes
rolling artifact — that is the point of the pin; the failure message says
so.
packaging/images.envif more consumers appear; wire shellcheck + a shelltest harness into CI; per-run unique paths or a lockfile if the node/gui
smoke tests are ever run concurrently in one container.
Test plan
bash -n; behavioral checks: usage/exit-64 paths (no args, wrong counts,bad kind), binfmt pre-flight (exact
qemu-aarch64entry,enabledstate,F flag), download-loop fallthrough (download-failed vs hash-mismatch
warnings), override warnings (each var independently)
(829 MB, hash matches the mirror's published md5 cross-check)
./do_checks.shgreen