mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 11:08:25 +00:00
The name directory is created with `mktemp -d` and bind-mounted into the build container. A bind-mount source is resolved by the Docker daemon in the host's mount namespace, so where this script runs with a private /tmp the path exists only in this process's namespace: the daemon finds nothing at it, creates its own directory at the same path in the host's /tmp, and the container writes the name there while the script reads an empty directory and reports that the build named nothing. That is what the internal builder does. Its worker unit sets PrivateTmp=true, so every run on every branch failed the dns-resolver and deb-install suites and published no package or image, while local CI and GitHub Actions passed because neither has a private /tmp. Create the directory inside the output directory instead. That is already bind-mounted as /out, so it already resolves the same way in both namespaces, which makes it the one place the name can travel through unconditionally. The container-side path and the /name mount are unchanged. Two things come with it. The failure message now names the namespace as the usual cause, because the message it replaces sent the last diagnosis looking in the wrong place. And stale name directories more than two hours old are cleared before a new one is made: the cleanup trap does not run on a SIGKILL, the builder group-kills a run that overruns its ceiling or is superseded, and nothing else sweeps the output directory. testing/native-api carries a shared_tmpdir() helper and a comment saying not to use `mktemp -d` for anything that becomes a bind-mount source. That convention predates this script and was not visible from packaging/.