From 703319e732f11ac6314b265ffe59098039ac2bd7 Mon Sep 17 00:00:00 2001 From: faizanahmad055 Date: Wed, 7 Jan 2026 09:27:29 +0100 Subject: [PATCH] Improve file filtering in UBI docker image Signed-off-by: faizanahmad055 --- Dockerfile.ubi | 30 ++++++++++++++++++++---------- 1 file changed, 20 insertions(+), 10 deletions(-) diff --git a/Dockerfile.ubi b/Dockerfile.ubi index 20e2b16f..9d8c88d8 100644 --- a/Dockerfile.ubi +++ b/Dockerfile.ubi @@ -23,19 +23,29 @@ COPY ubi-build-files-${TARGETARCH}.txt /tmp # Filter existing files and exclude temporary entitlement files that may be removed during build RUN set -e && \ # Filter files that actually exist (files, directories, or symlinks) + # This ensures we only copy files that are present, avoiding "Cannot stat" errors while IFS= read -r file; do \ [ -n "$file" ] && ([ -e "$file" ] || [ -L "$file" ]) && echo "$file"; \ done < /tmp/ubi-build-files-${TARGETARCH}.txt > /tmp/existing-files.txt && \ - # Create tarball if we have files to archive - if [ -s /tmp/existing-files.txt ]; then \ - tar -chf /tmp/files.tar \ - --exclude='etc/pki/entitlement-host*' \ - -T /tmp/existing-files.txt 2>&1 | grep -vE "(File removed before we read it|Cannot stat)" || true; \ - # Extract only if tarball was created successfully - if [ -f /tmp/files.tar ]; then \ - tar -xf /tmp/files.tar -C /image/ && \ - rm -f /tmp/files.tar; \ - fi; \ + # Verify we have files to copy (fail if list is empty to catch configuration issues) + if [ ! -s /tmp/existing-files.txt ]; then \ + echo "ERROR: No files found to copy from ubi-build-files-${TARGETARCH}.txt" >&2; \ + echo "This indicates the base image may be missing required files or the file list is incorrect." >&2; \ + echo "Expected files from ubi-build-files-${TARGETARCH}.txt:" >&2; \ + cat /tmp/ubi-build-files-${TARGETARCH}.txt >&2; \ + exit 1; \ + fi && \ + # Create tarball, excluding only temporary entitlement files (safe to exclude) + # Note: --exclude only affects files within directories being archived, not the directories themselves + tar -chf /tmp/files.tar \ + --exclude='etc/pki/entitlement-host*' \ + -T /tmp/existing-files.txt 2>&1 | grep -vE "(File removed before we read it|Cannot stat)" || true; \ + # Extract tarball (critical files like libc.so.6, ld-linux, etc/ssl/certs are included) + if [ -f /tmp/files.tar ]; then \ + tar -xf /tmp/files.tar -C /image/ && \ + rm -f /tmp/files.tar; \ + else \ + echo "WARNING: Tarball was not created, but continuing..." >&2; \ fi && \ # Clean up temporary file list rm -f /tmp/existing-files.txt