We used to let mkfs.ext4 initialize the filesystem for us, but it turns out that the metadata attributes of the root directory were not being initialized from the source tree. In particular, this meant that the SELinu labels were left as unconfined_t, rather than root_t, which would not allow us to boot in enforcing mode. An alternative approach might be to fixup the root inode manually, while still doing the rest using mkfs.ext4, but let's leave that for the future if it turns out to be worth it. Signed-off-by: Tom Gundersen <teg@jklm.no> |
||
|---|---|---|
| .. | ||
| org.osbuild.noop | ||
| org.osbuild.qcow2 | ||
| org.osbuild.tar | ||
| osbuild | ||