diff options
| author | Roman Scherer <roman@burningswell.com> | 2026-03-07 13:10:43 +0100 |
|---|---|---|
| committer | Ludovic Courtès <ludo@gnu.org> | 2026-03-19 15:32:46 +0100 |
| commit | 82f84f5e7fb34cc719ed6ea538a3d1ca7516f23d (patch) | |
| tree | 7497fc15b032af634846f74638461a3c78879cba /gnu | |
| parent | aa5de6c847f4676f3a6e7def844a04f1254d1a18 (diff) | |
daemon: Resolve symlinks in /etc/resolv.conf for slirp4netns chroot.
* nix/libstore/build.cc (prepareSlirpChrootAction): Use
canonPath(i, true) to resolve symlinks when adding /etc/resolv.conf
and /etc/hosts to the slirp4netns chroot, so that bindMount receives
a regular file path instead of a symlink.
On systems using systemd-resolved, /etc/resolv.conf is typically a
symlink:
/etc/resolv.conf -> /run/systemd/resolve/stub-resolv.conf
The slirp4netns chroot creates an empty /run/ directory, so when
bindMount copies the symlink verbatim (spawn.cc line 537-542), the
target does not exist and slirp4netns cannot determine the upstream
DNS server. This causes all DNS resolution to fail for fixed-output
derivations that use the Guile-based git-fetch builder (e.g.
git-fetch/lfs), since they rely on slirp4netns for network access
in the build chroot.
Derivations using builtin:git-download are unaffected because they
run in the daemon process itself, which has full network access.
Change-Id: Ib73e69a8760e74eb8141dd0408c27aa8b3001e37
Signed-off-by: Ludovic Courtès <ludo@gnu.org>
Merges: #6959
Diffstat (limited to 'gnu')
0 files changed, 0 insertions, 0 deletions
