diff --git a/patches/builds-images-ubuntu-genimg.patch b/patches/builds-images-ubuntu-genimg.patch index b650510bb4241ed01bcc0b792d5c7aedb95bf6df..a4b05fbf05634e097b228a66ea845bbd38add42d 100644 --- a/patches/builds-images-ubuntu-genimg.patch +++ b/patches/builds-images-ubuntu-genimg.patch @@ -32,11 +32,22 @@ `/etc/resolv.conf` makes the VM resolve internal hostnames (e.g. `git.srht.bigb.es`) to their *public* address. On a self-hosted forge whose public IP routes back through the user's own ISP, the worker container can't NAT-hairpin to itself and every `git clone` from a build dies with - "Couldn't connect to server". Use QEMU SLIRP's built-in DNS proxy - (`10.0.2.3`) instead: SLIRP forwards each query through the host process's - `/etc/resolv.conf`, which inside the worker container is Docker's embedded - resolver, which knows the LAN DNS — so internal hostnames resolve to the - LAN IP and the path stays entirely on-LAN. + "Couldn't connect to server". The fix is to use QEMU SLIRP's built-in DNS + proxy (`10.0.2.3`) in the *guest*: SLIRP forwards each query through the + host process's `/etc/resolv.conf`, which inside the worker container is + Docker's embedded resolver, which knows the LAN DNS — so internal hostnames + resolve to the LAN IP and the path stays entirely on-LAN. + + Subtle constraint: the script's `/mnt/etc/resolv.conf` is dual-purpose — + `chroot`'d `apt-get` reads it during debootstrap, *and* the same file is + what the booted guest uses. SLIRP's `10.0.2.3` only exists *inside* a + QEMU SLIRP guest; on the image-builder host it's unroutable, so swapping + the file early breaks `apt-get install linux-image-generic` with + "Temporary failure resolving 'archive.ubuntu.com'". Leave the public DNS + in place for the build, then overwrite `/mnt/etc/resolv.conf` with + `nameserver 10.0.2.3` at the end of the script — after all apt operations, + immediately before `sync`. This way the build still works and the booted + guest gets the SLIRP DNS proxy. Apply when refreshing the apk recipe tree on the image-builder host: @@ -53,12 +64,11 @@ +for i in 1 2 3 4 5; do sleep 0.$i; partprobe /dev/nbd0 && break; done trap cleanup EXIT if [ "$arch" = "amd64" ] -@@ -85,9 +86,8 @@ +@@ -85,9 +86,9 @@ rm -f /mnt/etc/resolv.conf --echo 'nameserver 8.8.8.8' >/mnt/etc/resolv.conf --echo 'nameserver 8.8.4.4' >>/mnt/etc/resolv.conf + echo 'nameserver 8.8.8.8' >/mnt/etc/resolv.conf + echo 'nameserver 8.8.4.4' >>/mnt/etc/resolv.conf -cat >/mnt/etc/systemd/network/25-ens3.network </mnt/etc/resolv.conf +cat >/mnt/etc/systemd/network/25-ethernet.network </mnt/etc/resolv.conf + sync