Source: dnsmasq Version: 2.93-1 Severity: important Justification: fails autopkgtest on Debian CI infrastructure Tags: forky sid User: [email protected] Usertags: lxc
Hi, Debian CI is switching away from lxc containers in favor of incus Containers. This is motivated by security concerns from us; incus is based on lxc, but orchestrates containers substantially different: containers are not privileged (so root in the container is not uid 0 outside of it, and incus imposes a stricter isolation from the host system. dnsmasq passes its tests under lxc, but fails under incus. The relevant part of the failure is (hopefully): > Setting up bind9 (1:9.20.26-1) ... > wrote key file "/etc/bind/rndc.key" > named-resolvconf.service is a disabled or a static unit, not starting it. > Created symlink '/etc/systemd/system/bind9.service' → > '/usr/lib/systemd/system/named.service'. > Created symlink '/etc/systemd/system/multi-user.target.wants/named.service' → > '/usr/lib/systemd/system/named.service'. > Setting up bind9-host (1:9.20.26-1) ... > Setting up bind9-dnsutils (1:9.20.26-1) ... > Processing triggers for dbus (1.16.2-5+b1) ... > Processing triggers for libc-bin (2.42-17) ... > autopkgtest [21:13:30]: test get-address+query-dns+check-utils: > [----------------------- > Purging systemd-resolved... > Reading package lists... > Building dependency tree... > Reading state information... > Solving dependencies... > The following packages will be REMOVED: > systemd-resolved* > 0 upgraded, 0 newly installed, 1 to remove and 0 not upgraded. > After this operation, 877 kB disk space will be freed. > (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 10843 files and directories currently installed.) > Removing systemd-resolved (261.2-1) ... > Removing /etc/resolv.conf symlink to /run/systemd/resolve/stub-resolv.conf... > Copying /run/systemd/resolve/resolv.conf to /etc/resolv.conf... > Processing triggers for dbus (1.16.2-5+b1) ... > (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 10806 files and directories currently installed.) > Purging configuration files for systemd-resolved (261.2-1) ... > ~~~ Get an address on veth1 and check the result... > mount of /sys failed: Operation not permitted > autopkgtest [21:13:33]: test get-address+query-dns+check-utils: > -----------------------] > autopkgtest [21:13:33]: test get-address+query-dns+check-utils: - - - - - - > - - - - results - - - - - - - - - - > get-address+query-dns+check-utils FAIL non-zero exit status 253 The full autokpgtest logs are available at: https://ci.debian.net/experiments/8/regressions/ (please beware of pagination) Common types of failure and suggested fixes are being documented at: https://wiki.debian.org/ContinuousIntegration/LxcToIncus Note that for the time being, dnsmasq is still being tested under lxc to avoid disturbing its testing migration test results. If you decide to add the `isolation-machine` restriction to get this package tested under qemu, please mention that explicitly when closing this bug (it's fine to do that only in the package changelog entry that closes the bug) so that we can configure your package for qemu on ci.debian.net.
signature.asc
Description: PGP signature

