refactor: upstream-based multi-image pipeline, add fedora-cosmic
Build fedora-cosmic from the upstream Fedora manifests in fedora/ostree/ci-test (44 and rawhide) with custom overlays: - remove firefox from the base system - add token2-fido-bridge + PC/SC smartcard stack and uhid - install per-user Flatpaks on first login via a systemd user unit Replace the legacy builder/changelog scripts with: - build.sh: rpm-ostree compose image (upstream overlay or standalone) - release.sh: package changelog published as Gitea releases CI moves to the job-v2 runner with a build matrix, cosign signing and release publishing. Drop the legacy asahi-cosmic/shared/base images, builder.sh, changelog.sh, Containerfile and changelogs/.
This commit is contained in:
@@ -1,16 +0,0 @@
|
||||
#Asahi specific packages
|
||||
packages:
|
||||
# base
|
||||
- alsa-ucm-asahi
|
||||
- asahi-platform-metapackage
|
||||
- asahi-repos
|
||||
# - fedora-asahi-remix-scripts # Depends on dnf right now
|
||||
- tiny-dfr
|
||||
# boot
|
||||
- grub2-efi-aa64-modules
|
||||
- uboot-images-armv8
|
||||
- asahi-fwupdate
|
||||
- dracut-asahi
|
||||
- update-m1n1
|
||||
# desktop-environments
|
||||
- aajohan-comfortaa-fonts
|
||||
@@ -1,67 +0,0 @@
|
||||
metadata:
|
||||
summary: Asahi remix atomic with the cosmic desktop
|
||||
|
||||
edition: "2024" #todo: figure out what this is used for
|
||||
|
||||
# Be minimal
|
||||
recommends: false
|
||||
|
||||
# Default to `bash` in our container, the same as other containers we ship.
|
||||
container-cmd:
|
||||
- /sbin/init
|
||||
|
||||
#Settings
|
||||
#Set the default systemd target
|
||||
default_target: graphical.target
|
||||
#Set selinux to true
|
||||
selinux: true
|
||||
|
||||
include:
|
||||
- ../shared/base.yaml
|
||||
- ./asahi.yaml
|
||||
- ./packages.yaml
|
||||
|
||||
repos:
|
||||
- fedora-base
|
||||
- fedora-updates
|
||||
- fedora-asahi-remix-hotfixes
|
||||
- copr:copr.fedorainfracloud.org:group_asahi:fedora-remix-branding
|
||||
- copr:copr.fedorainfracloud.org:group_asahi:fedora-remix-scripts
|
||||
- copr:copr.fedorainfracloud.org:group_asahi:kernel
|
||||
- copr:copr.fedorainfracloud.org:group_asahi:mesa
|
||||
- copr:copr.fedorainfracloud.org:group_asahi:u-boot
|
||||
|
||||
postprocess:
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
|
||||
# Work around https://bugzilla.redhat.com/show_bug.cgi?id=1265295
|
||||
# From https://github.com/coreos/fedora-coreos-config/blob/testing-devel/overlay.d/05core/usr/lib/systemd/journald.conf.d/10-coreos-persistent.conf
|
||||
install -dm0755 /usr/lib/systemd/journald.conf.d/
|
||||
echo -e "[Journal]\nStorage=persistent" > /usr/lib/systemd/journald.conf.d/10-persistent.conf
|
||||
|
||||
# See: https://src.fedoraproject.org/rpms/glibc/pull-request/4
|
||||
# Basically that program handles deleting old shared library directories
|
||||
# mid-transaction, which never applies to rpm-ostree. This is structured as a
|
||||
# loop/glob to avoid hardcoding (or trying to match) the architecture.
|
||||
for x in /usr/sbin/glibc_post_upgrade.*; do
|
||||
if test -f ${x}; then
|
||||
ln -srf /usr/bin/true ${x}
|
||||
fi
|
||||
done
|
||||
|
||||
# Remove loader directory causing issues in Anaconda in unified core mode
|
||||
# Will be obsolete once we start using bootupd
|
||||
rm -rf /usr/lib/ostree-boot/loader
|
||||
|
||||
# Undo RPM scripts enabling units; we want the presets to be canonical
|
||||
# https://github.com/projectatomic/rpm-ostree/issues/1803
|
||||
rm -rf /etc/systemd/system/*
|
||||
systemctl preset-all
|
||||
rm -rf /etc/systemd/user/*
|
||||
systemctl --user --global preset-all
|
||||
|
||||
# Fix triggerin for samba-client in cups package (not supported by rpm-ostree yet)
|
||||
# https://github.com/fedora-silverblue/issue-tracker/issues/532
|
||||
ln -snf /usr/libexec/samba/cups_backend_smb /usr/lib/cups/backend/smb
|
||||
@@ -1,273 +0,0 @@
|
||||
|
||||
# System packages (boot)
|
||||
packages-aarch64:
|
||||
- grub2-efi
|
||||
- efibootmgr
|
||||
- shim
|
||||
|
||||
#System packages (common)
|
||||
|
||||
# Core packages (common.yaml upstream)
|
||||
packages:
|
||||
- cosmic-edit
|
||||
- cosmic-files
|
||||
- cosmic-initial-setup
|
||||
- cosmic-player
|
||||
- cosmic-session
|
||||
- cosmic-store
|
||||
- cosmic-term
|
||||
- flatpak
|
||||
- gnome-disk-utility
|
||||
- gnome-keyring-pam
|
||||
- gnome-system-monitor
|
||||
- mesa-dri-drivers
|
||||
- mesa-vulkan-drivers
|
||||
- plymouth-system-theme
|
||||
- system-config-printer
|
||||
- xdg-desktop-portal-gtk
|
||||
- gvfs-mtp
|
||||
# Ensure that we have a kernel. Kernel packages are not in any comps group
|
||||
# - kernel
|
||||
# - kernel-modules
|
||||
# - kernel-modules-extra
|
||||
# Do not include "full" Git as it brings in Perl
|
||||
- git-core
|
||||
# Explicitely add Git docs
|
||||
- git-core-doc
|
||||
# Required until we've completed the move to systemd-sysusers
|
||||
# See: https://github.com/fedora-silverblue/issue-tracker/issues/362
|
||||
- nss-altfiles
|
||||
# Container management
|
||||
- buildah
|
||||
- podman
|
||||
- skopeo
|
||||
# Keep fuse-overlayfs for compatibilty and rootless containers use cases
|
||||
# See: https://github.com/coreos/fedora-coreos-tracker/issues/1749
|
||||
- fuse-overlayfs
|
||||
# See: https://github.com/fedora-silverblue/issue-tracker/issues/503
|
||||
- systemd-container
|
||||
# Provides terminal tools like clear, reset, tput, and tset
|
||||
- ncurses
|
||||
# Flatpak support
|
||||
- flatpak
|
||||
- xdg-desktop-portal
|
||||
# the archive repo for more reliable package layering
|
||||
# https://github.com/coreos/fedora-coreos-tracker/issues/400
|
||||
- fedora-repos-archive
|
||||
# Always include at least full English language support by default
|
||||
# https://gitlab.com/fedora/ostree/sig/-/issues/14
|
||||
- langpacks-en
|
||||
# Selected packages from the anaconda-tools group. See: https://gitlab.com/fedora/ostree/sig/-/issues/5
|
||||
- dosfstools
|
||||
- lvm2
|
||||
- nvme-cli
|
||||
- xfsprogs
|
||||
# HFS filesystem tools for Apple hardware
|
||||
# See https://github.com/projectatomic/rpm-ostree/issues/1380
|
||||
- hfsplus-tools
|
||||
|
||||
# See: https://github.com/fedora-silverblue/issue-tracker/issues/390
|
||||
- wireguard-tools
|
||||
# See: https://gitlab.com/fedora/ostree/sig/-/issues/101
|
||||
- gnupg2-scdaemon
|
||||
- NetworkManager
|
||||
- NetworkManager-bluetooth
|
||||
- NetworkManager-config-connectivity-fedora
|
||||
- NetworkManager-wifi
|
||||
- NetworkManager-wwan
|
||||
- acl
|
||||
- alsa-ucm
|
||||
- alsa-utils
|
||||
- at-spi2-atk
|
||||
- at-spi2-core
|
||||
- attr
|
||||
- audit
|
||||
- b43-fwcutter
|
||||
- b43-openfwwf
|
||||
- bash
|
||||
- bash-color-prompt
|
||||
- bash-completion
|
||||
- bc
|
||||
- bind-utils
|
||||
- bluez-cups
|
||||
- brcmfmac-firmware
|
||||
- brltty
|
||||
- btrfs-progs
|
||||
- bzip2
|
||||
- chrony
|
||||
- cifs-utils
|
||||
- colord
|
||||
- compsize
|
||||
- coreutils
|
||||
- cpio
|
||||
- cryptsetup
|
||||
- cups
|
||||
- cups-browsed
|
||||
- cups-filters
|
||||
- curl
|
||||
- cyrus-sasl-plain
|
||||
- default-editor
|
||||
- default-fonts-cjk-mono
|
||||
- default-fonts-cjk-sans
|
||||
- default-fonts-cjk-serif
|
||||
- default-fonts-core-emoji
|
||||
- default-fonts-core-math
|
||||
- default-fonts-core-mono
|
||||
- default-fonts-core-sans
|
||||
- default-fonts-core-serif
|
||||
- default-fonts-other-mono
|
||||
- default-fonts-other-sans
|
||||
- default-fonts-other-serif
|
||||
- dnsmasq
|
||||
- e2fsprogs
|
||||
- ethtool
|
||||
- exfatprogs
|
||||
- file
|
||||
- filesystem
|
||||
- firewalld
|
||||
- fpaste
|
||||
- fwupd
|
||||
- gamemode
|
||||
- glibc
|
||||
- glibc-all-langpacks
|
||||
- gnupg2
|
||||
- gstreamer1-plugin-dav1d
|
||||
- gstreamer1-plugin-libav
|
||||
- gstreamer1-plugins-bad-free
|
||||
- gstreamer1-plugins-good
|
||||
- gstreamer1-plugins-ugly-free
|
||||
- gutenprint
|
||||
- gutenprint-cups
|
||||
- hostname
|
||||
- hplip
|
||||
- hunspell
|
||||
- ibus-anthy
|
||||
- ibus-chewing
|
||||
- ibus-gtk3
|
||||
- ibus-gtk4
|
||||
- ibus-hangul
|
||||
- ibus-libpinyin
|
||||
- ibus-m17n
|
||||
- ibus-typing-booster
|
||||
- iproute
|
||||
- iptables-nft
|
||||
- iptstate
|
||||
- iputils
|
||||
- kbd
|
||||
- kmscon
|
||||
- less
|
||||
- libglvnd-gles
|
||||
- linux-firmware
|
||||
- logrotate
|
||||
- lrzsz
|
||||
- lsof
|
||||
- man-db
|
||||
- man-pages
|
||||
- mdadm
|
||||
- mesa-dri-drivers
|
||||
- mesa-vulkan-drivers
|
||||
- mpage
|
||||
- mtr
|
||||
- nfs-utils
|
||||
- nss-altfiles
|
||||
- nss-mdns
|
||||
- ntfs-3g
|
||||
- ntfsprogs
|
||||
- opensc
|
||||
- openssh-clients
|
||||
- openssh-server
|
||||
- pam_afs_session
|
||||
- paps
|
||||
- passwdqc
|
||||
- pciutils
|
||||
- pinfo
|
||||
- pipewire-alsa
|
||||
- pipewire-config-raop
|
||||
- pipewire-gstreamer
|
||||
- pipewire-pulseaudio
|
||||
- pipewire-utils
|
||||
- plymouth
|
||||
- plymouth-system-theme
|
||||
- policycoreutils
|
||||
- policycoreutils-python-utils
|
||||
- prefixdevname
|
||||
- procps-ng
|
||||
- psmisc
|
||||
- quota
|
||||
- realtek-firmware
|
||||
- rootfiles
|
||||
- rpm
|
||||
- rpm-ostree
|
||||
- rsync
|
||||
- samba-client
|
||||
- selinux-policy-targeted
|
||||
- setup
|
||||
- shadow-utils
|
||||
- sos
|
||||
- speech-dispatcher
|
||||
- spice-vdagent
|
||||
- spice-webdavd
|
||||
- sssd-common
|
||||
- sssd-kcm
|
||||
- sudo
|
||||
- system-config-printer-udev
|
||||
- systemd
|
||||
- systemd-oomd-defaults
|
||||
- systemd-resolved
|
||||
- systemd-udev
|
||||
- tar
|
||||
- time
|
||||
- tree
|
||||
- unzip
|
||||
- uresourced
|
||||
- usb_modeswitch
|
||||
- usbutils
|
||||
- util-linux
|
||||
- vim-minimal
|
||||
- wget2-wget
|
||||
- which
|
||||
- whois
|
||||
- wireplumber
|
||||
- words
|
||||
- wpa_supplicant
|
||||
- zip
|
||||
- zram-generator-defaults
|
||||
- qrtr
|
||||
- rmtfs
|
||||
- upower
|
||||
|
||||
|
||||
# Make sure the following are not pulled in when Recommended by other packages
|
||||
exclude-packages:
|
||||
- PackageKit
|
||||
# We can not include openh264. See https://fedoraproject.org/wiki/OpenH264
|
||||
- gstreamer1-plugin-openh264
|
||||
- mozilla-openh264
|
||||
- openh264
|
||||
# https://github.com/fedora-silverblue/issue-tracker/issues/517
|
||||
- sdubby
|
||||
# Exclude Tk. We can not exclude Tcl as it is neeeded for usb_modeswitch
|
||||
- tk
|
||||
# Exclude QEMU. See: https://gitlab.com/fedora/ostree/sig/-/issues/58
|
||||
- qemu-kvm
|
||||
- qemu-kvm-core
|
||||
- qemu-device-display-virtio-gpu
|
||||
- qemu-device-display-virtio-vga
|
||||
# See: https://github.com/fedora-silverblue/issue-tracker/issues/646
|
||||
- hplip-gui
|
||||
# Ensure that we do not include any Perl package
|
||||
- perl-interpreter
|
||||
- perl-libs
|
||||
# Exclude GNOME Software's langpack plugin to avoid layering langpacks on
|
||||
# systems where GNOME Software is included
|
||||
- gnome-software-fedora-langpacks
|
||||
# We include wget instead
|
||||
- wcurl
|
||||
# See: https://fedoraproject.org/wiki/Changes/AtomicDesktopDropPklaCompat
|
||||
- polkit-pkla-compat
|
||||
# See: https://fedoraproject.org/wiki/Changes/AtomicDesktopDropFuse2
|
||||
# See: https://gitlab.com/fedora/ostree/sig/-/issues/50
|
||||
- fuse
|
||||
- fuselibs
|
||||
# Can only be excluded on variants that do not include GNOME Software
|
||||
- PackageKit-glib
|
||||
@@ -1,11 +0,0 @@
|
||||
[fedora-asahi-remix-hotfixes]
|
||||
name=Fedora Asahi Remix Hotfixes
|
||||
baseurl=https://fedora-asahi-remix.org/repos/hotfixes/$releasever/
|
||||
type=rpm-md
|
||||
skip_if_unavailable=True
|
||||
gpgcheck=1
|
||||
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
|
||||
repo_gpgcheck=0
|
||||
enabled=1
|
||||
enabled_metadata=1
|
||||
priority=1
|
||||
@@ -1,11 +0,0 @@
|
||||
[copr:copr.fedorainfracloud.org:group_asahi:fedora-remix-branding]
|
||||
name=Copr repo for fedora-remix-branding owned by @asahi
|
||||
baseurl=https://download.copr.fedorainfracloud.org/results/@asahi/fedora-remix-branding/fedora-$releasever-$basearch/
|
||||
type=rpm-md
|
||||
skip_if_unavailable=False
|
||||
gpgcheck=1
|
||||
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-group_asahi-fedora-remix-branding
|
||||
repo_gpgcheck=0
|
||||
enabled=1
|
||||
enabled_metadata=1
|
||||
priority=1
|
||||
@@ -1,11 +0,0 @@
|
||||
[copr:copr.fedorainfracloud.org:group_asahi:fedora-remix-scripts]
|
||||
name=Copr repo for fedora-remix-scripts owned by @asahi
|
||||
baseurl=https://download.copr.fedorainfracloud.org/results/@asahi/fedora-remix-scripts/fedora-$releasever-$basearch/
|
||||
type=rpm-md
|
||||
skip_if_unavailable=False
|
||||
gpgcheck=1
|
||||
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-group_asahi-fedora-remix-scripts
|
||||
repo_gpgcheck=0
|
||||
enabled=1
|
||||
enabled_metadata=1
|
||||
priority=5
|
||||
@@ -1,11 +0,0 @@
|
||||
[copr:copr.fedorainfracloud.org:group_asahi:kernel]
|
||||
name=Copr repo for kernel owned by @asahi
|
||||
baseurl=https://download.copr.fedorainfracloud.org/results/@asahi/kernel/fedora-$releasever-$basearch/
|
||||
type=rpm-md
|
||||
skip_if_unavailable=False
|
||||
gpgcheck=1
|
||||
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-group_asahi-kernel
|
||||
repo_gpgcheck=0
|
||||
enabled=1
|
||||
enabled_metadata=1
|
||||
priority=5
|
||||
@@ -1,11 +0,0 @@
|
||||
[copr:copr.fedorainfracloud.org:group_asahi:mesa]
|
||||
name=Copr repo for mesa owned by @asahi
|
||||
baseurl=https://download.copr.fedorainfracloud.org/results/@asahi/mesa/fedora-$releasever-$basearch/
|
||||
type=rpm-md
|
||||
skip_if_unavailable=False
|
||||
gpgcheck=1
|
||||
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-group_asahi-mesa
|
||||
repo_gpgcheck=0
|
||||
enabled=1
|
||||
enabled_metadata=1
|
||||
priority=5
|
||||
@@ -1,11 +0,0 @@
|
||||
[copr:copr.fedorainfracloud.org:group_asahi:u-boot]
|
||||
name=Copr repo for u-boot owned by @asahi
|
||||
baseurl=https://download.copr.fedorainfracloud.org/results/@asahi/u-boot/fedora-$releasever-$basearch/
|
||||
type=rpm-md
|
||||
skip_if_unavailable=False
|
||||
gpgcheck=1
|
||||
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-group_asahi-u-boot
|
||||
repo_gpgcheck=0
|
||||
enabled=1
|
||||
enabled_metadata=1
|
||||
priority=5
|
||||
@@ -1,6 +0,0 @@
|
||||
#!/bin/bash
|
||||
set -euxo pipefail
|
||||
|
||||
#Get the asahi GPG keys
|
||||
dnf copr enable -y @asahi/fedora-remix-branding
|
||||
dnf install -y asahi-repos
|
||||
@@ -1,53 +0,0 @@
|
||||
metadata:
|
||||
summary: Effectively just bootc, systemd, kernel, and dnf as a starting point.
|
||||
|
||||
edition: "2024" #todo: figure out what this is used for
|
||||
|
||||
variables:
|
||||
passwd_mode: full
|
||||
|
||||
recommends: true
|
||||
|
||||
# Default to `bash` in our container, the same as other containers we ship.
|
||||
container-cmd:
|
||||
- /sbin/init
|
||||
|
||||
remove-from-packages:
|
||||
# Generally we expect other tools to do this (e.g. Ignition or cloud-init)
|
||||
- [systemd, /usr/lib/systemd/system/sysinit.target.wants/systemd-firstboot.service]
|
||||
|
||||
include:
|
||||
- ../shared/base.yaml
|
||||
|
||||
packages:
|
||||
- kernel
|
||||
# this is implied by dependencies but let's make it explicit
|
||||
- coreutils
|
||||
- dnf
|
||||
# Even in minimal, we have this. If you don't want SELinux today, you'll need
|
||||
# to build a custom image.
|
||||
- selinux-policy-targeted
|
||||
# And we want container-selinux because trying to layer it on later currently causes issues.
|
||||
- container-selinux
|
||||
# Needed for tpm2 bound luks
|
||||
- tpm2-tools
|
||||
|
||||
packages-x86_64:
|
||||
- grub2 grub2-efi-x64 efibootmgr shim
|
||||
- microcode_ctl
|
||||
|
||||
exclude-packages:
|
||||
- kernel-debug-core
|
||||
|
||||
remove-from-packages:
|
||||
# The grub bits are mainly designed for desktops, and IMO haven't seen
|
||||
# enough testing in concert with ostree. At some point we'll flesh out
|
||||
# the full plan in https://github.com/coreos/fedora-coreos-tracker/issues/47
|
||||
- [grub2-tools, /etc/grub.d/08_fallback_counting,
|
||||
/etc/grub.d/10_reset_boot_success,
|
||||
/etc/grub.d/12_menu_auto_hide,
|
||||
/usr/lib/systemd/.*]
|
||||
|
||||
repos:
|
||||
- fedora-base
|
||||
- fedora-updates
|
||||
@@ -0,0 +1,17 @@
|
||||
# Build configuration for images/fedora-cosmic. Sourced by build.sh.
|
||||
|
||||
BUILD_MODE=upstream
|
||||
|
||||
# Upstream Fedora atomic desktop manifests (fork of workstation-ostree-config).
|
||||
UPSTREAM_REPO="https://gitlab.com/fedora/ostree/ci-test.git"
|
||||
|
||||
# Map the distro we build to an upstream branch.
|
||||
# main -> rawhide (currently releasever 46)
|
||||
# f44 -> Fedora 44 stable
|
||||
declare -A UPSTREAM_REFS=(
|
||||
[44]=f44
|
||||
[rawhide]=main
|
||||
)
|
||||
|
||||
# Fetch token2-fido-bridge from its GitHub releases into a local repo.
|
||||
TOKEN2=1
|
||||
@@ -0,0 +1,55 @@
|
||||
# Customizations layered on top of the upstream Fedora COSMIC Atomic manifests.
|
||||
|
||||
packages:
|
||||
# Fedora integration packages normally provided by the upstream fedora.yaml,
|
||||
# re-added here without Firefox (which is shipped as a Flatpak instead).
|
||||
- fedora-bookmarks
|
||||
- fedora-chromium-config
|
||||
- fedora-flathub-remote
|
||||
- fedora-workstation-backgrounds
|
||||
- fedora-workstation-repositories
|
||||
- fedora-release-cosmic-atomic
|
||||
- toolbox
|
||||
|
||||
# Smartcard / FIDO2 support for token2-fido-bridge.
|
||||
# token2-fido-bridge itself is installed from a local repo that build.sh
|
||||
# generates from the upstream GitHub release (it is not packaged in Fedora).
|
||||
- pcsc-lite
|
||||
- pcsc-lite-ccid
|
||||
- pcsc-tools
|
||||
- opensc
|
||||
- libfido2
|
||||
- fido2-tools
|
||||
- p11-kit
|
||||
- pam-u2f
|
||||
- token2-fido-bridge
|
||||
|
||||
# Firefox is intentionally not part of the base system. It is preinstalled as a
|
||||
# per-user Flatpak on first login instead (see flatpaks.list).
|
||||
exclude-packages:
|
||||
- firefox
|
||||
|
||||
add-files:
|
||||
- ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"]
|
||||
- ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"]
|
||||
- ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"]
|
||||
- ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"]
|
||||
- ["50-token2-fido-bridge.preset", "/usr/lib/systemd/system-preset/50-token2-fido-bridge.preset"]
|
||||
- ["uhid.conf", "/usr/lib/modules-load.d/uhid.conf"]
|
||||
|
||||
postprocess:
|
||||
# The upstream fedora.yaml removes the Google Chrome repo from the Fedora
|
||||
# Third Party repo list. We opt out of that manifest, so replicate it here.
|
||||
# Workaround for https://github.com/coreos/rpm-ostree/issues/5494
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
sed -i -e '/google-chrome/,+2d' /usr/lib/fedora-third-party/conf.d/fedora-workstation.conf || true
|
||||
|
||||
# Ensure the first-login script is executable and make sure the
|
||||
# globally-enabled per-user Flatpak unit is picked up.
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
chmod 0755 /usr/libexec/flatpak-user-firstboot
|
||||
systemctl --user --global preset-all
|
||||
@@ -0,0 +1,4 @@
|
||||
# Enable the PC/SC smartcard daemon and the token2-fido-bridge daemon so that
|
||||
# FIDO2 smartcards are exposed to browsers as a virtual USB-HID security key.
|
||||
enable pcscd.socket
|
||||
enable token2-fido-bridge.service
|
||||
@@ -0,0 +1 @@
|
||||
enable flatpak-user-firstboot.service
|
||||
+24
@@ -0,0 +1,24 @@
|
||||
#!/usr/bin/env bash
|
||||
# Install the per-user Flatpaks listed in /usr/share/flatpak/flatpaks.list on
|
||||
# the first login of each user. Run as a systemd --user oneshot unit.
|
||||
set -euo pipefail
|
||||
|
||||
LIST="/usr/share/flatpak/flatpaks.list"
|
||||
MARKER="${HOME}/.config/flatpak-user-firstboot.done"
|
||||
|
||||
[[ -f "${LIST}" ]] || exit 0
|
||||
|
||||
# Make Flathub available for the current user.
|
||||
flatpak remote-add --user --if-not-exists flathub \
|
||||
https://flathub.org/repo/flathub.flatpakrepo
|
||||
|
||||
mapfile -t apps < <(
|
||||
sed -e 's/#.*//' -e 's/[[:space:]]//g' "${LIST}" | grep -v '^$' || true
|
||||
)
|
||||
|
||||
if [[ ${#apps[@]} -gt 0 ]]; then
|
||||
flatpak install --user --noninteractive --assumeyes "${apps[@]}"
|
||||
fi
|
||||
|
||||
install -dm0755 "$(dirname "${MARKER}")"
|
||||
touch "${MARKER}"
|
||||
@@ -0,0 +1,14 @@
|
||||
[Unit]
|
||||
Description=Install per-user Flatpak applications on first login
|
||||
Documentation=https://docs.flatpak.org/en/latest/flatpak-command-reference.html
|
||||
ConditionPathExists=!%h/.config/flatpak-user-firstboot.done
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
RemainAfterExit=yes
|
||||
ExecStart=/usr/libexec/flatpak-user-firstboot
|
||||
|
||||
[Install]
|
||||
WantedBy=default.target
|
||||
@@ -0,0 +1,5 @@
|
||||
# Flatpaks installed into each user's per-user installation on first login.
|
||||
# One application/runtime ID per line. Lines starting with # are ignored.
|
||||
#
|
||||
# Firefox is not part of the base system and is installed here instead.
|
||||
org.mozilla.firefox
|
||||
@@ -0,0 +1,2 @@
|
||||
# token2-fido-bridge needs the uhid module to create the virtual FIDO2 device.
|
||||
uhid
|
||||
@@ -0,0 +1,23 @@
|
||||
# Custom Fedora COSMIC Atomic image.
|
||||
#
|
||||
# This is a thin downstream layer on top of the upstream Fedora manifests from
|
||||
# https://gitlab.com/fedora/ostree/ci-test, which are cloned into this directory
|
||||
# at build time by build.sh (see build.conf for the ref mapping).
|
||||
#
|
||||
# The upstream leaf manifest is `cosmic-atomic.yaml`, which pulls in
|
||||
# `cosmic-atomic-common.yaml` -> `common.yaml` + `packages/cosmic-atomic.yaml`.
|
||||
|
||||
metadata:
|
||||
summary: Fedora COSMIC Atomic (custom)
|
||||
|
||||
variables:
|
||||
# Opt out of the upstream `fedora.yaml` include so that we can ship our own
|
||||
# Fedora integration package set without Firefox. This is the documented
|
||||
# downstream hook (see the comment at the top of upstream's fedora.yaml).
|
||||
distro: "fedora-cosmic"
|
||||
|
||||
ref: fedora-cosmic/${releasever_ref}/${basearch}/cosmic
|
||||
|
||||
include:
|
||||
- cosmic-atomic.yaml
|
||||
- custom.yaml
|
||||
@@ -1,184 +0,0 @@
|
||||
#This file merges all the required yaml files from (https://gitlab.com/fedora/bootc/base-images/-/tree/main/minimal) into one
|
||||
|
||||
#==========================================================postprocess-conf.yaml========================================
|
||||
# We want content lifecycled with the image
|
||||
opt-usrlocal: "root"
|
||||
|
||||
# https://github.com/CentOS/centos-bootc/issues/167
|
||||
machineid-compat: true
|
||||
|
||||
rpmdb: target
|
||||
# We never want rpmdb.sqlite-shm as it's unreproducible
|
||||
rpmdb-normalize: true
|
||||
|
||||
ignore-removed-users:
|
||||
- root
|
||||
ignore-removed-groups:
|
||||
- root
|
||||
# By default users and groups are injected to nss-altfiles
|
||||
# which is immutable. This list moves a selected set
|
||||
# to /etc/group instead, which is mutable per system
|
||||
# and allows local users to become part of these groups.
|
||||
etc-group-members:
|
||||
- wheel
|
||||
- systemd-journal
|
||||
- tss # https://issues.redhat.com/browse/BIFROST-618
|
||||
- kvm # https://issues.redhat.com/browse/RHEL-115278
|
||||
- adm
|
||||
|
||||
#Only use the newer imports, not the one with backwards compatibility
|
||||
#The files are retrieved when building to stay in sync with upstream
|
||||
check-passwd:
|
||||
type: "file"
|
||||
filename: "passwd"
|
||||
check-groups:
|
||||
type: "file"
|
||||
filename: "group"
|
||||
|
||||
#==========================================================postprocess-conf.yaml========================================
|
||||
|
||||
#tmpfiles.yaml
|
||||
postprocess:
|
||||
- |
|
||||
#!/bin/bash
|
||||
set -xeuo pipefail
|
||||
cat >/usr/lib/tmpfiles.d/bootc-base-rpmstate.conf <<'EOF'
|
||||
# Workaround for https://bugzilla.redhat.com/show_bug.cgi?id=771713
|
||||
d /var/lib/rpm-state 0755 - - -
|
||||
EOF
|
||||
# Workaround for https://issues.redhat.com/browse/RHEL-106203
|
||||
rm -f /usr/lib/tmpfiles.d/home.conf
|
||||
|
||||
- |
|
||||
#!/bin/bash
|
||||
set -xeuo pipefail
|
||||
# Transforms /usr/lib/ostree-boot into a bootupd-compatible update payload
|
||||
/usr/bin/bootupctl backend generate-update-metadata
|
||||
|
||||
# Workaround for https://issues.redhat.com/browse/RHEL-78104
|
||||
- |
|
||||
#!/bin/bash
|
||||
set -xeuo pipefail
|
||||
rm -vrf /usr/lib/ostree-boot/loader
|
||||
|
||||
# Set up default root config
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
mkdir -p /usr/lib/ostree
|
||||
cat > /usr/lib/ostree/prepare-root.conf << EOF
|
||||
[composefs]
|
||||
enabled = yes
|
||||
[sysroot]
|
||||
readonly = true
|
||||
EOF
|
||||
|
||||
#initrams config
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
mkdir -p /usr/lib/dracut/dracut.conf.d
|
||||
cat > /usr/lib/dracut/dracut.conf.d/20-bootc-base.conf << 'EOF'
|
||||
# We want a generic image; hostonly makes no sense as part of a server side build
|
||||
hostonly=no
|
||||
# Dracut will always fail to set security.selinux xattrs at build time
|
||||
# https://github.com/dracut-ng/dracut-ng/issues/1561
|
||||
export DRACUT_NO_XATTR=1
|
||||
add_dracutmodules+=" kernel-modules dracut-systemd systemd-initrd base ostree "
|
||||
EOF
|
||||
cat > /usr/lib/dracut/dracut.conf.d/22-bootc-generic.conf << 'EOF'
|
||||
# Extra modules that we want by default that are known to exist in the kernel
|
||||
add_dracutmodules+=" virtiofs "
|
||||
EOF
|
||||
cat > /usr/lib/dracut/dracut.conf.d/59-altfiles.conf << 'EOF'
|
||||
# https://issues.redhat.com/browse/RHEL-49590
|
||||
# On image mode systems we use nss-altfiles for passwd and group,
|
||||
# this makes sure dracut uses them which also fixes kdump writing to NFS.
|
||||
install_items+=" /usr/lib/passwd /usr/lib/group "
|
||||
EOF
|
||||
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
mkdir -p /usr/lib/systemd/system/local-fs.target.wants
|
||||
if test '!' -f /usr/lib/systemd/system/local-fs.target.wants/tmp.mount; then
|
||||
ln -sf ../tmp.mount /usr/lib/systemd/system/local-fs.target.wants
|
||||
fi
|
||||
sed -i -e 's, /root, /var/roothome,' /usr/lib/tmpfiles.d/provision.conf > /dev/null
|
||||
sed -i -e '/^d- \/var\/roothome /d' /usr/lib/tmpfiles.d/provision.conf > /dev/null
|
||||
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
source /usr/lib/os-release
|
||||
mkdir -p /usr/lib/kernel/install.conf.d
|
||||
echo -e "# kernel-install will not try to run dracut and allow rpm-ostree to\n\
|
||||
# take over. Rpm-ostree will use this to know that it is responsible\n\
|
||||
# to run dracut and ensure that there is only one kernel in the image\n\
|
||||
layout=ostree" | tee /usr/lib/kernel/install.conf /usr/lib/kernel/install.conf.d/00-bootc-kernel-layout.conf > /dev/null
|
||||
# By default dnf keeps multiple versions of the kernel, with this
|
||||
# configuration we tell dnf to treat the kernel as everything else.
|
||||
# https://dnf.readthedocs.io/en/latest/conf_ref.html#main-options
|
||||
# Let's add the config to a distribution configuration file if dnf5
|
||||
# is used, we append to /etc/dnf/dnf.conf if not.
|
||||
# Also set protect_running_kernel=False, dnf/yum pre-dates Containers and
|
||||
# uses uname to protect the running kernel even on Container builds.
|
||||
if [ -d "/usr/share/dnf5/libdnf.conf.d/" ]; then
|
||||
echo -e "[main]\ninstallonlypkgs=''" >> /usr/share/dnf5/libdnf.conf.d/20-ostree-installonlypkgs.conf
|
||||
echo -e "[main]\nprotect_running_kernel=False" >> /usr/share/dnf5/libdnf.conf.d/20-ostree-protect_running_kernel.conf
|
||||
else
|
||||
echo "installonlypkgs=''" >> /etc/dnf/dnf.conf
|
||||
echo "protect_running_kernel=False" >> /etc/dnf/dnf.conf
|
||||
fi
|
||||
|
||||
- |
|
||||
#!/bin/bash
|
||||
set -xeuo pipefail
|
||||
# Override some of the default presets.
|
||||
cat <<EOF > usr/lib/systemd/system-preset/85-bootc.preset
|
||||
# Disable dnf-makecache.timer on bootc/image mode systems
|
||||
# https://github.com/coreos/fedora-coreos-tracker/issues/1896#issuecomment-2848251507
|
||||
disable dnf-makecache.timer
|
||||
EOF
|
||||
# Enable bootloader-update.service on F43+.
|
||||
# https://github.com/coreos/fedora-coreos-tracker/issues/1468#issuecomment-2996654547
|
||||
# https://fedoraproject.org/wiki/Changes/AutomaticBootloaderUpdatesBootc
|
||||
- |
|
||||
#!/bin/bash
|
||||
set -xeuo pipefail
|
||||
echo "enable bootloader-update.service" >> /usr/lib/systemd/system-preset/85-bootc.preset
|
||||
# Undo RPM scripts enabling units; we want the presets to be canonical
|
||||
# https://github.com/projectatomic/rpm-ostree/issues/1803
|
||||
- |
|
||||
#!/bin/bash
|
||||
set -xeuo pipefail
|
||||
rm -rf /etc/systemd/system/*
|
||||
systemctl preset-all
|
||||
rm -rf /etc/systemd/user/*
|
||||
systemctl --user --global preset-all
|
||||
|
||||
#Selected ownership fixes for files in /etc & /var owned by a dynamic UID/GID
|
||||
# See: https://gitlab.com/fedora/ostree/sig/-/issues/90
|
||||
- |
|
||||
#!/bin/bash
|
||||
set -xeuo pipefail
|
||||
|
||||
cat > /usr/lib/tmpfiles.d/90-atomic-desktops-ownership-fixes.conf << 'EOF'
|
||||
Z /var/lib/passim - passim passim
|
||||
Z /var/log/passim - passim passim
|
||||
Z /etc/colord/ - colord colord
|
||||
EOF
|
||||
|
||||
packages:
|
||||
|
||||
# systemd. Also name systemd-pam because it was dropped to a recommends
|
||||
# but we still want it for handling user logins/sessions.
|
||||
- systemd systemd-pam
|
||||
# bootc itself.
|
||||
- bootc
|
||||
# Required by bootc install, sgdisk has been replaced by Rust crate
|
||||
# in bootc https://github.com/containers/bootc/pull/775
|
||||
- xfsprogs e2fsprogs dosfstools
|
||||
- bootupd
|
||||
|
||||
|
||||
@@ -1,6 +0,0 @@
|
||||
[fedora-base]
|
||||
name=Fedora $releasever $basearch Base
|
||||
mirrorlist=https://mirrors.fedoraproject.org/metalink?repo=fedora-$releasever&arch=$basearch
|
||||
enabled=1
|
||||
gpgcheck=1
|
||||
metadata_expire=1d
|
||||
@@ -1,6 +0,0 @@
|
||||
[fedora-updates]
|
||||
name=Fedora $releasever $basearch Updates
|
||||
mirrorlist=https://mirrors.fedoraproject.org/metalink?repo=updates-released-f$releasever&arch=$basearch
|
||||
enabled=1
|
||||
gpgcheck=1
|
||||
metadata_expire=1d
|
||||
@@ -1,45 +0,0 @@
|
||||
root:x:0:
|
||||
bin:x:1:
|
||||
daemon:x:2:
|
||||
sys:x:3:
|
||||
adm:x:4:
|
||||
tty:x:5:
|
||||
disk:x:6:
|
||||
lp:x:7:
|
||||
mem:x:8:
|
||||
kmem:x:9:
|
||||
wheel:x:10:
|
||||
cdrom:x:11:
|
||||
mail:x:12:
|
||||
man:x:15:
|
||||
dialout:x:18:
|
||||
floppy:x:19:
|
||||
games:x:20:
|
||||
rpcuser:x:29:
|
||||
tape:x:33:
|
||||
video:x:39:
|
||||
dip:x:40:
|
||||
ftp:x:50:
|
||||
lock:x:54:
|
||||
audio:x:63:
|
||||
tcpdump:x:72:
|
||||
nobody:x:99:
|
||||
users:x:100:
|
||||
input:x:104:
|
||||
ceph:x:167:
|
||||
avahi-autoipd:x:170:
|
||||
systemd-journal:x:190:
|
||||
dockerroot:x:986:
|
||||
cockpit-ws:x:987:
|
||||
systemd-bus-proxy:x:988:
|
||||
systemd-resolve:x:989:
|
||||
systemd-network:x:990:
|
||||
systemd-timesync:x:991:
|
||||
chrony:x:992:
|
||||
sssd:x:993:
|
||||
kube:x:994:
|
||||
cgred:x:996:
|
||||
etcd:x:997:
|
||||
polkitd:x:998:
|
||||
ssh_keys:x:999:
|
||||
nfsnobody:x:65534:
|
||||
@@ -1,33 +0,0 @@
|
||||
|
||||
root:x:0:0:Super User:/root:/bin/bash
|
||||
bin:x:1:1:bin:/bin:/usr/sbin/nologin
|
||||
daemon:x:2:2:daemon:/sbin:/usr/sbin/nologin
|
||||
adm:x:3:4:adm:/var/adm:/usr/sbin/nologin
|
||||
lp:x:4:7:lp:/var/spool/lpd:/usr/sbin/nologin
|
||||
sync:x:5:0:sync:/sbin:/bin/sync
|
||||
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
|
||||
halt:x:7:0:halt:/sbin:/sbin/halt
|
||||
mail:x:8:12:mail:/var/spool/mail:/usr/sbin/nologin
|
||||
operator:x:11:0:operator:/root:/usr/sbin/nologin
|
||||
games:x:12:100:games:/usr/games:/usr/sbin/nologin
|
||||
ftp:x:14:50:FTP User:/var/ftp:/usr/sbin/nologin
|
||||
rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/usr/sbin/nologin
|
||||
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/usr/sbin/nologin
|
||||
tcpdump:x:72:72::/:/usr/sbin/nologin
|
||||
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/usr/sbin/nologin
|
||||
dbus:x:81:81:System Message Bus:/:/usr/sbin/nologin
|
||||
nobody:x:99:99:Kernel Overflow User:/:/usr/sbin/nologin
|
||||
ceph:x:167:167:Ceph daemons:/var/lib/ceph:/usr/sbin/nologin
|
||||
avahi-autoipd:x:170:170:Avahi IPv4LL Stack:/var/lib/avahi-autoipd:/usr/sbin/nologin
|
||||
cockpit-ws:x:988:987:User for cockpit-ws:/:/usr/sbin/nologin
|
||||
systemd-bus-proxy:x:989:988:systemd Bus Proxy:/:/usr/sbin/nologin
|
||||
systemd-resolve:x:990:989:systemd Resolver:/:/usr/sbin/nologin
|
||||
systemd-network:x:991:990:systemd Network Management:/:/usr/sbin/nologin
|
||||
systemd-timesync:x:993:991:systemd Time Synchronization:/:/usr/sbin/nologin
|
||||
chrony:x:994:992::/var/lib/chrony:/usr/sbin/nologin
|
||||
sssd:x:995:993:User for sssd:/run/sssd:/usr/sbin/nologin
|
||||
kube:x:996:994:Kubernetes user:/:/usr/sbin/nologin
|
||||
dockerroot:x:997:986:Docker User:/var/lib/docker:/usr/sbin/nologin
|
||||
etcd:x:998:997:etcd user:/var/lib/etcd:/usr/sbin/nologin
|
||||
polkitd:x:999:998:User for polkitd:/:/usr/sbin/nologin
|
||||
nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/usr/sbin/nologin
|
||||
Reference in New Issue
Block a user