From 867b1938e47146dc295e1233f6081ade226209b9 Mon Sep 17 00:00:00 2001 From: ScottW514 Date: Wed, 9 Sep 2026 13:22:12 -0400 Subject: [PATCH] Cold build: allow unprivileged user namespaces on the noble runner BitBake isolates the network of its tasks with a user namespace, and the ubuntu-24.04 hosted runner's AppArmor profile refuses that to an unprivileged process, so the cold build stopped before its first task (run 34381825302). The workflow lifts the restriction for the run; nothing in the layers or the image changes. --- .github/workflows/yocto-cold-build.yml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/.github/workflows/yocto-cold-build.yml b/.github/workflows/yocto-cold-build.yml index 4aa9ad7..60d1e29 100644 --- a/.github/workflows/yocto-cold-build.yml +++ b/.github/workflows/yocto-cold-build.yml @@ -52,6 +52,12 @@ jobs: sudo locale-gen en_US.UTF-8 pip3 install kas + # BitBake isolates the network of its tasks with a user namespace; + # the ubuntu-24.04 runner's AppArmor profile refuses that to an + # unprivileged process, so the build would stop before its first task. + - name: Allow unprivileged user namespaces (BitBake network isolation) + run: sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 + - name: Build (rm_work, release image only) working-directory: forgefirm run: kas build kas/forgefirm-glowforge.yml:kas/ci.yml