瀏覽代碼

.github/workflows: Disable apparmor

Add --security-opt apparmor=unconfined to docker cmdline.

Suggested-by: Khem Raj <raj.khem@gmail.com>
Signed-off-by: Leon Anavi <leon.anavi@konsulko.com>
Leon Anavi 1 月之前
父節點
當前提交
2aa34651a7
共有 3 個文件被更改,包括 5 次插入3 次删除
  1. 2 1
      .github/workflows/compliance.yml
  2. 1 1
      .github/workflows/yocto-builds.yml
  3. 2 1
      .github/workflows/yocto-layer.yml

+ 2 - 1
.github/workflows/compliance.yml

@@ -23,7 +23,8 @@ jobs:
           id: ${{ github.event.number }}
       - name: Do DCO check
         run: |
-          docker run --rm -v "$GITHUB_WORKSPACE:/work:ro" \
+          docker run --rm --security-opt apparmor=unconfined \
+            -v "$GITHUB_WORKSPACE:/work:ro" \
             --env "BASE_REF=$GITHUB_BASE_REF" \
             "dco-check-${{ github.event.number }}"
       - name: Cleanup temporary docker image

+ 1 - 1
.github/workflows/yocto-builds.yml

@@ -66,7 +66,7 @@ jobs:
         if: steps.changed-files-specific.outputs.any_changed == 'true'
       - name: Build the image
         run: |
-          docker run --rm \
+          docker run --rm --security-opt apparmor=unconfined \
             -v "$GITHUB_WORKSPACE:/work:ro" \
             -v "$DL_DIR:$DL_DIR:rw" \
             -v "$SSTATE_DIR:$SSTATE_DIR:rw" \

+ 2 - 1
.github/workflows/yocto-layer.yml

@@ -42,7 +42,8 @@ jobs:
         if: steps.changed-files-specific.outputs.any_changed == 'true'
       - name: Run yocto-check-layer
         run: |
-          docker run --rm -v "$GITHUB_WORKSPACE:/work:ro" \
+          docker run --rm --security-opt apparmor=unconfined \
+            -v "$GITHUB_WORKSPACE:/work:ro" \
             --env "BASE_REF=$GITHUB_BASE_REF" \
             "yocto-builder-${{ github.event.number }}" \
             /entrypoint-yocto-check-layer.sh