Explorar o código

.github/workflows: Disable apparmor

Add --security-opt apparmor=unconfined to docker cmdline.

Suggested-by: Khem Raj <raj.khem@gmail.com>
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Leon Anavi hai 4 semanas
pai
achega
2aa34651a7

+ 2 - 1
.github/workflows/compliance.yml

@@ -23,7 +23,8 @@ jobs:
           id: ${{ github.event.number }}
       - name: Do DCO check
         run: |
-          docker run --rm -v "$GITHUB_WORKSPACE:/work:ro" \
+          docker run --rm --security-opt apparmor=unconfined \
+            -v "$GITHUB_WORKSPACE:/work:ro" \
             --env "BASE_REF=$GITHUB_BASE_REF" \
             "dco-check-${{ github.event.number }}"
       - name: Cleanup temporary docker image

+ 1 - 1
.github/workflows/yocto-builds.yml

@@ -66,7 +66,7 @@ jobs:
         if: steps.changed-files-specific.outputs.any_changed == 'true'
       - name: Build the image
         run: |
-          docker run --rm \
+          docker run --rm --security-opt apparmor=unconfined \
             -v "$GITHUB_WORKSPACE:/work:ro" \
             -v "$DL_DIR:$DL_DIR:rw" \
             -v "$SSTATE_DIR:$SSTATE_DIR:rw" \

+ 2 - 1
.github/workflows/yocto-layer.yml

@@ -42,7 +42,8 @@ jobs:
         if: steps.changed-files-specific.outputs.any_changed == 'true'
       - name: Run yocto-check-layer
         run: |
-          docker run --rm -v "$GITHUB_WORKSPACE:/work:ro" \
+          docker run --rm --security-opt apparmor=unconfined \
+            -v "$GITHUB_WORKSPACE:/work:ro" \
             --env "BASE_REF=$GITHUB_BASE_REF" \
             "yocto-builder-${{ github.event.number }}" \
             /entrypoint-yocto-check-layer.sh