Skip to content

A privileged container cannot see new loop partition nodes

scope: generic · severity: trap · confidence: proven · subsystem: build

Symptom — pmbootstrap finishes installing packages, creates a GPT image, then fails with File did not appear: /dev/loop0p2. Docker is already privileged.

Cause — Kernel loop partitions exist in sysfs, but runner udev creates their nodes outside the container’s private /dev. Privilege alone does not share that mount. A broader device-directory bind is unnecessary.

What to do — For the allocated image loop device only, create missing partition nodes using the kernel’s major/minor numbers from /sys/class/block/<partition>/dev. Never apply this fallback to an explicitly selected physical disk or replace existing nodes.

Control — The failing run above stopped before mounting the root partition. With the narrow fix, the second run reached pmbootstrap’s completed image result; its later validation permission failure is a separate check. The regression executes the actual node-creation branch: physical disks do nothing, a missing image partition requests the exact sysfs numbers, and an existing node stays untouched. This evidence establishes image assembly, not device bootability.