refactor: upstream-based multi-image pipeline, add fedora-cosmic
Build fedora-cosmic from the upstream Fedora manifests in fedora/ostree/ci-test (44 and rawhide) with custom overlays: - remove firefox from the base system - add token2-fido-bridge + PC/SC smartcard stack and uhid - install per-user Flatpaks on first login via a systemd user unit Replace the legacy builder/changelog scripts with: - build.sh: rpm-ostree compose image (upstream overlay or standalone) - release.sh: package changelog published as Gitea releases CI moves to the job-v2 runner with a build matrix, cosign signing and release publishing. Drop the legacy asahi-cosmic/shared/base images, builder.sh, changelog.sh, Containerfile and changelogs/.
This commit is contained in:
@@ -0,0 +1,17 @@
|
||||
# Build configuration for images/fedora-cosmic. Sourced by build.sh.
|
||||
|
||||
BUILD_MODE=upstream
|
||||
|
||||
# Upstream Fedora atomic desktop manifests (fork of workstation-ostree-config).
|
||||
UPSTREAM_REPO="https://gitlab.com/fedora/ostree/ci-test.git"
|
||||
|
||||
# Map the distro we build to an upstream branch.
|
||||
# main -> rawhide (currently releasever 46)
|
||||
# f44 -> Fedora 44 stable
|
||||
declare -A UPSTREAM_REFS=(
|
||||
[44]=f44
|
||||
[rawhide]=main
|
||||
)
|
||||
|
||||
# Fetch token2-fido-bridge from its GitHub releases into a local repo.
|
||||
TOKEN2=1
|
||||
@@ -0,0 +1,55 @@
|
||||
# Customizations layered on top of the upstream Fedora COSMIC Atomic manifests.
|
||||
|
||||
packages:
|
||||
# Fedora integration packages normally provided by the upstream fedora.yaml,
|
||||
# re-added here without Firefox (which is shipped as a Flatpak instead).
|
||||
- fedora-bookmarks
|
||||
- fedora-chromium-config
|
||||
- fedora-flathub-remote
|
||||
- fedora-workstation-backgrounds
|
||||
- fedora-workstation-repositories
|
||||
- fedora-release-cosmic-atomic
|
||||
- toolbox
|
||||
|
||||
# Smartcard / FIDO2 support for token2-fido-bridge.
|
||||
# token2-fido-bridge itself is installed from a local repo that build.sh
|
||||
# generates from the upstream GitHub release (it is not packaged in Fedora).
|
||||
- pcsc-lite
|
||||
- pcsc-lite-ccid
|
||||
- pcsc-tools
|
||||
- opensc
|
||||
- libfido2
|
||||
- fido2-tools
|
||||
- p11-kit
|
||||
- pam-u2f
|
||||
- token2-fido-bridge
|
||||
|
||||
# Firefox is intentionally not part of the base system. It is preinstalled as a
|
||||
# per-user Flatpak on first login instead (see flatpaks.list).
|
||||
exclude-packages:
|
||||
- firefox
|
||||
|
||||
add-files:
|
||||
- ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"]
|
||||
- ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"]
|
||||
- ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"]
|
||||
- ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"]
|
||||
- ["50-token2-fido-bridge.preset", "/usr/lib/systemd/system-preset/50-token2-fido-bridge.preset"]
|
||||
- ["uhid.conf", "/usr/lib/modules-load.d/uhid.conf"]
|
||||
|
||||
postprocess:
|
||||
# The upstream fedora.yaml removes the Google Chrome repo from the Fedora
|
||||
# Third Party repo list. We opt out of that manifest, so replicate it here.
|
||||
# Workaround for https://github.com/coreos/rpm-ostree/issues/5494
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
sed -i -e '/google-chrome/,+2d' /usr/lib/fedora-third-party/conf.d/fedora-workstation.conf || true
|
||||
|
||||
# Ensure the first-login script is executable and make sure the
|
||||
# globally-enabled per-user Flatpak unit is picked up.
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
chmod 0755 /usr/libexec/flatpak-user-firstboot
|
||||
systemctl --user --global preset-all
|
||||
@@ -0,0 +1,4 @@
|
||||
# Enable the PC/SC smartcard daemon and the token2-fido-bridge daemon so that
|
||||
# FIDO2 smartcards are exposed to browsers as a virtual USB-HID security key.
|
||||
enable pcscd.socket
|
||||
enable token2-fido-bridge.service
|
||||
@@ -0,0 +1 @@
|
||||
enable flatpak-user-firstboot.service
|
||||
+24
@@ -0,0 +1,24 @@
|
||||
#!/usr/bin/env bash
|
||||
# Install the per-user Flatpaks listed in /usr/share/flatpak/flatpaks.list on
|
||||
# the first login of each user. Run as a systemd --user oneshot unit.
|
||||
set -euo pipefail
|
||||
|
||||
LIST="/usr/share/flatpak/flatpaks.list"
|
||||
MARKER="${HOME}/.config/flatpak-user-firstboot.done"
|
||||
|
||||
[[ -f "${LIST}" ]] || exit 0
|
||||
|
||||
# Make Flathub available for the current user.
|
||||
flatpak remote-add --user --if-not-exists flathub \
|
||||
https://flathub.org/repo/flathub.flatpakrepo
|
||||
|
||||
mapfile -t apps < <(
|
||||
sed -e 's/#.*//' -e 's/[[:space:]]//g' "${LIST}" | grep -v '^$' || true
|
||||
)
|
||||
|
||||
if [[ ${#apps[@]} -gt 0 ]]; then
|
||||
flatpak install --user --noninteractive --assumeyes "${apps[@]}"
|
||||
fi
|
||||
|
||||
install -dm0755 "$(dirname "${MARKER}")"
|
||||
touch "${MARKER}"
|
||||
@@ -0,0 +1,14 @@
|
||||
[Unit]
|
||||
Description=Install per-user Flatpak applications on first login
|
||||
Documentation=https://docs.flatpak.org/en/latest/flatpak-command-reference.html
|
||||
ConditionPathExists=!%h/.config/flatpak-user-firstboot.done
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
RemainAfterExit=yes
|
||||
ExecStart=/usr/libexec/flatpak-user-firstboot
|
||||
|
||||
[Install]
|
||||
WantedBy=default.target
|
||||
@@ -0,0 +1,5 @@
|
||||
# Flatpaks installed into each user's per-user installation on first login.
|
||||
# One application/runtime ID per line. Lines starting with # are ignored.
|
||||
#
|
||||
# Firefox is not part of the base system and is installed here instead.
|
||||
org.mozilla.firefox
|
||||
@@ -0,0 +1,2 @@
|
||||
# token2-fido-bridge needs the uhid module to create the virtual FIDO2 device.
|
||||
uhid
|
||||
@@ -0,0 +1,23 @@
|
||||
# Custom Fedora COSMIC Atomic image.
|
||||
#
|
||||
# This is a thin downstream layer on top of the upstream Fedora manifests from
|
||||
# https://gitlab.com/fedora/ostree/ci-test, which are cloned into this directory
|
||||
# at build time by build.sh (see build.conf for the ref mapping).
|
||||
#
|
||||
# The upstream leaf manifest is `cosmic-atomic.yaml`, which pulls in
|
||||
# `cosmic-atomic-common.yaml` -> `common.yaml` + `packages/cosmic-atomic.yaml`.
|
||||
|
||||
metadata:
|
||||
summary: Fedora COSMIC Atomic (custom)
|
||||
|
||||
variables:
|
||||
# Opt out of the upstream `fedora.yaml` include so that we can ship our own
|
||||
# Fedora integration package set without Firefox. This is the documented
|
||||
# downstream hook (see the comment at the top of upstream's fedora.yaml).
|
||||
distro: "fedora-cosmic"
|
||||
|
||||
ref: fedora-cosmic/${releasever_ref}/${basearch}/cosmic
|
||||
|
||||
include:
|
||||
- cosmic-atomic.yaml
|
||||
- custom.yaml
|
||||
Reference in New Issue
Block a user