Files
fips/packaging/debian
Johnathan Corgan bf668384fa Let the package name travel through the output directory, not /tmp
The name directory is created with `mktemp -d` and bind-mounted into the
build container. A bind-mount source is resolved by the Docker daemon in
the host's mount namespace, so where this script runs with a private /tmp
the path exists only in this process's namespace: the daemon finds nothing
at it, creates its own directory at the same path in the host's /tmp, and
the container writes the name there while the script reads an empty
directory and reports that the build named nothing.

That is what the internal builder does. Its worker unit sets
PrivateTmp=true, so every run on every branch failed the dns-resolver and
deb-install suites and published no package or image, while local CI and
GitHub Actions passed because neither has a private /tmp.

Create the directory inside the output directory instead. That is already
bind-mounted as /out, so it already resolves the same way in both
namespaces, which makes it the one place the name can travel through
unconditionally. The container-side path and the /name mount are unchanged.

Two things come with it. The failure message now names the namespace as
the usual cause, because the message it replaces sent the last diagnosis
looking in the wrong place. And stale name directories more than two hours
old are cleared before a new one is made: the cleanup trap does not run on
a SIGKILL, the builder group-kills a run that overruns its ceiling or is
superseded, and nothing else sweeps the output directory.

testing/native-api carries a shared_tmpdir() helper and a comment saying
not to use `mktemp -d` for anything that becomes a bind-mount source. That
convention predates this script and was not visible from packaging/.
2026-09-20 14:39:56 +00:00
..