From 48daea43243e6c8c5bb7eb8067fbb2d91d0fb70f Mon Sep 17 00:00:00 2001 From: JP Hastings-Spital Date: Sat, 8 Aug 2026 19:34:01 +0100 Subject: [PATCH] fix: declare the buildah storage driver so ignore_chown_errors attaches MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit With the driver auto-picked, storage.conf's per-driver option sections never apply — the golang layer unpack died on lchown /etc/gshadow with a size-1 uid mapping despite the option being present. Declare overlay with fuse-overlayfs by absolute path (vfs fallback), option attached to the matching section. Third finding from the v0.1.0 runs (ATFS-bq8m). --- .beans/ATFS-bq8m--cut-v010.md | 4 +++- .tangled/workflows/publish-image.yml | 13 +++++++++++-- 2 files changed, 14 insertions(+), 3 deletions(-) diff --git a/.beans/ATFS-bq8m--cut-v010.md b/.beans/ATFS-bq8m--cut-v010.md index dfaa755..5782dd2 100644 --- a/.beans/ATFS-bq8m--cut-v010.md +++ b/.beans/ATFS-bq8m--cut-v010.md @@ -5,7 +5,7 @@ status: in-progress type: task priority: high created_at: 2026-08-07T14:02:41Z -updated_at: 2026-08-08T18:25:02Z +updated_at: 2026-08-08T18:34:01Z --- The release ritual, now that the milestone is done and the instance is proven: push the repo to its Tangled remote; set ATCR_HANDLE + ATCR_APP_PASSWORD secrets (publishing identity decision included); git tag v0.1.0 && git push origin v0.1.0; watch the first publish-image run (rootless buildah on Tangled microvm is the one unproven assumption) and the image workflow; confirm atcr.io//atfs:0.1.0 pulls and runs. @@ -18,3 +18,5 @@ The release ritual, now that the milestone is done and the instance is proven: p - atcr.io appears to require an authenticated Bluesky identity for pulls as well as pushes — if confirmed, the README quickstart needs a docker login prelude. Second failure: no policy.json anywhere on the runner — fixed with a prep step writing per-user policy.json (insecureAcceptAnything, Docker's effective default) + storage.conf (ignore_chown_errors for the no-subuid single-uid mapping) + BUILDAH_ISOLATION=chroot for RUN steps without a userns. + +Third failure: ignore_chown_errors never attached because the storage driver was auto-picked — per-driver option sections in storage.conf only apply when [storage] driver is declared explicitly. Now: driver=overlay with mount_program=fuse-overlayfs (resolved by absolute path at prep time), vfs fallback, ignore_chown_errors in the matching section. diff --git a/.tangled/workflows/publish-image.yml b/.tangled/workflows/publish-image.yml index 23e2366..0a5d71b 100644 --- a/.tangled/workflows/publish-image.yml +++ b/.tangled/workflows/publish-image.yml @@ -126,8 +126,17 @@ steps: CONF="${XDG_CONFIG_HOME:-$HOME/.config}/containers" mkdir -p "$CONF" printf '%s' '{"default":[{"type":"insecureAcceptAnything"}]}' > "$CONF/policy.json" - printf '[storage.options.overlay]\nignore_chown_errors = "true"\n[storage.options.vfs]\nignore_chown_errors = "true"\n' > "$CONF/storage.conf" - echo "containers config written to $CONF" + # The driver must be declared explicitly: with an auto-picked driver, + # storage.conf's per-driver option sections never attach, and + # ignore_chown_errors silently doesn't happen (found the hard way — + # lchown /etc/gshadow EINVAL while unpacking golang's layers). + FUSE="$(command -v fuse-overlayfs || true)" + if [ -n "$FUSE" ]; then + printf '[storage]\ndriver = "overlay"\n\n[storage.options.overlay]\nmount_program = "%s"\nignore_chown_errors = "true"\n' "$FUSE" > "$CONF/storage.conf" + else + printf '[storage]\ndriver = "vfs"\n\n[storage.options.vfs]\nignore_chown_errors = "true"\n' > "$CONF/storage.conf" + fi + echo "containers config written to $CONF:" && cat "$CONF/storage.conf" - name: "build amd64+arm64 and assemble the manifest list" command: | -- 2.51.2