refactor: upstream-based multi-image pipeline, add fedora-cosmic
Build fedora-cosmic from the upstream Fedora manifests in fedora/ostree/ci-test (44 and rawhide) with custom overlays: - remove firefox from the base system - add token2-fido-bridge + PC/SC smartcard stack and uhid - install per-user Flatpaks on first login via a systemd user unit Replace the legacy builder/changelog scripts with: - build.sh: rpm-ostree compose image (upstream overlay or standalone) - release.sh: package changelog published as Gitea releases CI moves to the job-v2 runner with a build matrix, cosign signing and release publishing. Drop the legacy asahi-cosmic/shared/base images, builder.sh, changelog.sh, Containerfile and changelogs/.
This commit is contained in:
+81
-73
@@ -6,31 +6,64 @@ on:
|
|||||||
branches: ["main"]
|
branches: ["main"]
|
||||||
push:
|
push:
|
||||||
branches: ["main"]
|
branches: ["main"]
|
||||||
|
schedule:
|
||||||
|
- cron: "0 4 * * *"
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build_push:
|
build:
|
||||||
name: Build and push image
|
name: ${{ matrix.image }} (${{ matrix.distro }})
|
||||||
runs-on: wesley-arm
|
runs-on: ${{ matrix.runner }}
|
||||||
|
|
||||||
env:
|
strategy:
|
||||||
IMAGE: asahi-cosmic
|
fail-fast: false
|
||||||
VERSION: 43
|
# To build another image, add images/<name>/{manifest.yaml,build.conf}
|
||||||
|
# and a matching matrix entry here.
|
||||||
|
matrix:
|
||||||
|
include:
|
||||||
|
- image: fedora-cosmic
|
||||||
|
distro: "44"
|
||||||
|
arch: x86_64
|
||||||
|
runner: job-v2
|
||||||
|
- image: fedora-cosmic
|
||||||
|
distro: rawhide
|
||||||
|
arch: x86_64
|
||||||
|
runner: job-v2
|
||||||
|
|
||||||
container:
|
container:
|
||||||
image: "quay.io/fedora-ostree-desktops/buildroot:${{ env.VERSION }}"
|
image: "quay.io/fedora-ostree-desktops/buildroot:${{ matrix.distro }}"
|
||||||
options: "--security-opt=label=disable --privileged --user 0:0 --device=/dev/fuse --volume /:/run/host:rw"
|
options: "--security-opt=label=disable --privileged --user 0:0 --device=/dev/fuse --volume /:/run/host:rw"
|
||||||
|
|
||||||
|
env:
|
||||||
|
IMAGE: ${{ matrix.image }}
|
||||||
|
DISTRO: ${{ matrix.distro }}
|
||||||
|
ARCH: ${{ matrix.arch }}
|
||||||
|
REGISTRY: git.plabble.org/misthios
|
||||||
|
GITEA_URL: https://git.plabble.org
|
||||||
|
GITEA_REPO: Misthios/bootc-images
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
|
- name: Install build tools
|
||||||
- name: Install rpm-ostree + tools
|
|
||||||
run: |
|
run: |
|
||||||
dnf upgrade -y --enablerepo=updates-testing --refresh rpm-ostree
|
set -xeuo pipefail
|
||||||
dnf install -y nodejs skopeo jq buildah rsync git
|
dnf install -y jq curl git createrepo_c
|
||||||
mkdir -p ~/.docker
|
dnf install -y skopeo buildah
|
||||||
|
dnf install -y cosign || true
|
||||||
|
if ! command -v cosign >/dev/null; then
|
||||||
|
case "$(uname -m)" in
|
||||||
|
x86_64) cosign_arch=amd64 ;;
|
||||||
|
aarch64) cosign_arch=arm64 ;;
|
||||||
|
*) echo "Unsupported arch for cosign"; exit 1 ;;
|
||||||
|
esac
|
||||||
|
curl -fsSL -o /usr/local/bin/cosign \
|
||||||
|
"https://github.com/sigstore/cosign/releases/latest/download/cosign-linux-${cosign_arch}"
|
||||||
|
chmod +x /usr/local/bin/cosign
|
||||||
|
fi
|
||||||
|
|
||||||
- name: Fix containers/storage.conf
|
- name: Configure containers storage
|
||||||
run: |
|
run: |
|
||||||
|
if [ -f /usr/share/containers/storage.conf ]; then
|
||||||
sed -i 's/driver = "overlay"/driver = "vfs"/' /usr/share/containers/storage.conf
|
sed -i 's/driver = "overlay"/driver = "vfs"/' /usr/share/containers/storage.conf
|
||||||
|
fi
|
||||||
|
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
@@ -38,72 +71,47 @@ jobs:
|
|||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
|
|
||||||
- name: Log in to registry
|
- name: Log in to registry
|
||||||
uses: redhat-actions/podman-login@v1
|
env:
|
||||||
with:
|
REGISTRY_USERNAME: ${{ secrets.REGISTRY_USERNAME }}
|
||||||
registry: git.plabble.org
|
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
||||||
username: ${{ secrets.REGISTRY_USERNAME }}
|
|
||||||
password: ${{ secrets.REGISTRY_TOKEN }}
|
|
||||||
auth_file_path: /tmp/auth.json
|
|
||||||
|
|
||||||
- name: Build rootfs with rpm-ostree
|
|
||||||
run: |
|
|
||||||
sudo -E ./builder.sh "${IMAGE}" "${VERSION}"
|
|
||||||
|
|
||||||
- name: Build and push OCI image from rootfs
|
|
||||||
run: |
|
run: |
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
|
mkdir -p ~/.docker
|
||||||
|
registry_host="${REGISTRY%%/*}"
|
||||||
|
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
|
||||||
|
--password-stdin --authfile /tmp/auth.json "${registry_host}"
|
||||||
|
echo "${REGISTRY_TOKEN}" | skopeo login -u "${REGISTRY_USERNAME}" \
|
||||||
|
--password-stdin --authfile ~/.docker/config.json "${registry_host}"
|
||||||
|
|
||||||
REGISTRY="git.plabble.org/misthios"
|
- name: Build image
|
||||||
ROOTFS="images/${IMAGE}/rootfs"
|
run: ./build.sh "${IMAGE}" "${DISTRO}" "${ARCH}"
|
||||||
|
|
||||||
if [[ ! -d "${ROOTFS}" ]]; then
|
|
||||||
echo "ERROR: rootfs not found at ${ROOTFS}"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Build ID (YYYYMMDD.0)
|
|
||||||
if [[ -f ".buildid" ]]; then
|
|
||||||
buildid="$(< .buildid)"
|
|
||||||
else
|
|
||||||
buildid="$(date '+%Y%m%d.0')"
|
|
||||||
echo "${buildid}" > .buildid
|
|
||||||
fi
|
|
||||||
|
|
||||||
full_tag="${VERSION}.${buildid}"
|
|
||||||
|
|
||||||
|
- name: Push and sign image
|
||||||
|
if: github.event_name != 'pull_request'
|
||||||
|
env:
|
||||||
|
COSIGN_PRIVATE_KEY: ${{ secrets.COSIGN_PRIVATE_KEY }}
|
||||||
|
run: |
|
||||||
|
set -xeuo pipefail
|
||||||
export STORAGE_DRIVER=vfs
|
export STORAGE_DRIVER=vfs
|
||||||
|
buildid="$(cat .buildid)"
|
||||||
|
oci="build/${IMAGE}-${DISTRO}-${ARCH}/${IMAGE}-${DISTRO}-${ARCH}.ociarchive"
|
||||||
|
tag="${DISTRO}.${buildid}"
|
||||||
|
|
||||||
ctr="$(buildah from scratch)"
|
skopeo copy --authfile /tmp/auth.json \
|
||||||
mnt="$(buildah mount "${ctr}")"
|
"oci-archive:${oci}" "docker://${REGISTRY}/${IMAGE}:${tag}"
|
||||||
|
skopeo copy --authfile /tmp/auth.json \
|
||||||
|
"oci-archive:${oci}" "docker://${REGISTRY}/${IMAGE}:${DISTRO}"
|
||||||
|
|
||||||
rsync -aHAX "${ROOTFS}/" "${mnt}/"
|
printf '%s' "${COSIGN_PRIVATE_KEY}" | base64 -d > private.key
|
||||||
|
cosign sign -y --key private.key "${REGISTRY}/${IMAGE}:${tag}"
|
||||||
|
cosign sign -y --key private.key "${REGISTRY}/${IMAGE}:${DISTRO}"
|
||||||
|
rm -f private.key
|
||||||
|
|
||||||
buildah config --label containers.bootc=1 "${ctr}"
|
- name: Generate changelog and publish release
|
||||||
buildah config --env container=oci "${ctr}"
|
if: github.event_name != 'pull_request'
|
||||||
buildah config --cmd "/sbin/init" "${ctr}"
|
env:
|
||||||
|
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
|
||||||
buildah commit "${ctr}" "localhost/${IMAGE}:${full_tag}"
|
|
||||||
buildah unmount "${ctr}"
|
|
||||||
|
|
||||||
skopeo copy \
|
|
||||||
--authfile /tmp/auth.json \
|
|
||||||
containers-storage:localhost/${IMAGE}:${full_tag} \
|
|
||||||
docker://${REGISTRY}/${IMAGE}:${full_tag}
|
|
||||||
|
|
||||||
skopeo copy \
|
|
||||||
--authfile /tmp/auth.json \
|
|
||||||
containers-storage:localhost/${IMAGE}:${full_tag} \
|
|
||||||
docker://${REGISTRY}/${IMAGE}:${VERSION}
|
|
||||||
|
|
||||||
- name: Generate changelog
|
|
||||||
run: |
|
run: |
|
||||||
./changelog.sh "${IMAGE}" "${VERSION}"
|
buildid="$(cat .buildid)"
|
||||||
|
oci="build/${IMAGE}-${DISTRO}-${ARCH}/${IMAGE}-${DISTRO}-${ARCH}.ociarchive"
|
||||||
- name: Commit and push changelog
|
./release.sh "${IMAGE}" "${DISTRO}" "${buildid}" "${oci}"
|
||||||
if: github.ref == 'refs/heads/main'
|
|
||||||
run: |
|
|
||||||
git config user.name "Automation"
|
|
||||||
git config user.email "actions@invalid.tld"
|
|
||||||
git add changelogs/
|
|
||||||
git commit -m "Update changelog for ${IMAGE} ${VERSION} build $(cat .buildid)" || echo "No changes"
|
|
||||||
git push
|
|
||||||
|
|||||||
+1
-7
@@ -1,10 +1,4 @@
|
|||||||
/*.ociarchive
|
/*.ociarchive
|
||||||
/.buildid
|
/.buildid
|
||||||
|
/build/
|
||||||
/cache/
|
/cache/
|
||||||
/debugdata/
|
|
||||||
/fedora-comps/
|
|
||||||
/fedora-lorax-templates/
|
|
||||||
/iso/
|
|
||||||
/logs/
|
|
||||||
/repo/
|
|
||||||
/tmp/
|
|
||||||
|
|||||||
@@ -1,10 +0,0 @@
|
|||||||
|
|
||||||
FROM scratch
|
|
||||||
ARG IMAGE
|
|
||||||
COPY images/$IMAGE/manifest.ociarchive /
|
|
||||||
|
|
||||||
LABEL containers.bootc 1
|
|
||||||
ENV container=oci
|
|
||||||
|
|
||||||
STOPSIGNAL SIGRTMIN+3
|
|
||||||
CMD ["/sbin/init"]
|
|
||||||
@@ -0,0 +1,156 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# Build a bootc OCI image from an image definition under images/<image>.
|
||||||
|
#
|
||||||
|
# Usage: build.sh <image> <distro> [arch]
|
||||||
|
#
|
||||||
|
# The per-image build.conf selects the build mode:
|
||||||
|
#
|
||||||
|
# upstream Clone the upstream Fedora manifest repo at a ref mapped from
|
||||||
|
# <distro>, overlay this image's manifests and support files, then
|
||||||
|
# compose the OCI image with `rpm-ostree compose image`.
|
||||||
|
#
|
||||||
|
# standalone Compose from this image's own manifest.yaml, wrapping it with the
|
||||||
|
# releasever/ref from build.conf.
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
if [[ $# -lt 2 ]]; then
|
||||||
|
echo "Usage: $0 <image> <distro> [arch]" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
IMAGE="$1"
|
||||||
|
DISTRO="$2"
|
||||||
|
ARCH="${3:-$(uname -m)}"
|
||||||
|
|
||||||
|
REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
|
IMAGE_DIR="${REPO_ROOT}/images/${IMAGE}"
|
||||||
|
CONF="${IMAGE_DIR}/build.conf"
|
||||||
|
|
||||||
|
[[ -d "${IMAGE_DIR}" ]] || { echo "Unknown image: ${IMAGE}" >&2; exit 1; }
|
||||||
|
[[ -f "${CONF}" ]] || { echo "Missing build config: ${CONF}" >&2; exit 1; }
|
||||||
|
|
||||||
|
# Defaults, overridden by build.conf.
|
||||||
|
BUILD_MODE=""
|
||||||
|
UPSTREAM_REPO=""
|
||||||
|
TOKEN2=0
|
||||||
|
RUN_TEST_SH=0
|
||||||
|
RELEASEVER=""
|
||||||
|
REF=""
|
||||||
|
declare -A UPSTREAM_REFS=()
|
||||||
|
|
||||||
|
# shellcheck disable=SC1090
|
||||||
|
source "${CONF}"
|
||||||
|
|
||||||
|
BUILD_DIR="${REPO_ROOT}/build/${IMAGE}-${DISTRO}-${ARCH}"
|
||||||
|
OCI_ARCHIVE="${BUILD_DIR}/${IMAGE}-${DISTRO}-${ARCH}.ociarchive"
|
||||||
|
CACHE_DIR="${REPO_ROOT}/cache"
|
||||||
|
|
||||||
|
[[ -n "${BUILD_MODE}" ]] || { echo "BUILD_MODE not set in ${CONF}" >&2; exit 1; }
|
||||||
|
|
||||||
|
buildid="$(date '+%Y%m%d.0')"
|
||||||
|
echo "${buildid}" > "${REPO_ROOT}/.buildid"
|
||||||
|
|
||||||
|
rm -rf "${BUILD_DIR}"
|
||||||
|
mkdir -p "${BUILD_DIR}" "${CACHE_DIR}"
|
||||||
|
|
||||||
|
if [[ "${RUN_TEST_SH}" == "1" && -x "${IMAGE_DIR}/test.sh" ]]; then
|
||||||
|
echo "Running ${IMAGE_DIR}/test.sh"
|
||||||
|
( cd "${IMAGE_DIR}" && ./test.sh )
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Download the latest token2-fido-bridge RPM from GitHub and turn it into a
|
||||||
|
# local yum repo so the manifest can install it.
|
||||||
|
setup_token2_repo() {
|
||||||
|
local dest="$1"
|
||||||
|
local api url
|
||||||
|
api="https://api.github.com/repos/token2/token2-fido-bridge/releases/latest"
|
||||||
|
url="$(curl -fsSL "${api}" \
|
||||||
|
| jq -r '.assets[] | select(.name | endswith(".rpm")) | .browser_download_url' \
|
||||||
|
| head -n1)"
|
||||||
|
if [[ -z "${url}" || "${url}" == "null" ]]; then
|
||||||
|
echo "ERROR: no token2-fido-bridge .rpm found in the latest GitHub release" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
mkdir -p "${dest}/token2-repo"
|
||||||
|
curl -fsSL "${url}" -o "${dest}/token2-repo/$(basename "${url}")"
|
||||||
|
createrepo_c "${dest}/token2-repo"
|
||||||
|
cat > "${dest}/token2-fido-bridge.repo" <<EOF
|
||||||
|
[token2-fido-bridge]
|
||||||
|
name=token2-fido-bridge
|
||||||
|
baseurl=file://${dest}/token2-repo
|
||||||
|
enabled=1
|
||||||
|
gpgcheck=0
|
||||||
|
EOF
|
||||||
|
}
|
||||||
|
|
||||||
|
case "${BUILD_MODE}" in
|
||||||
|
upstream)
|
||||||
|
[[ -n "${UPSTREAM_REPO}" ]] || { echo "UPSTREAM_REPO not set in ${CONF}" >&2; exit 1; }
|
||||||
|
upstream_ref="${UPSTREAM_REFS[${DISTRO}]:-}"
|
||||||
|
[[ -n "${upstream_ref}" ]] || { echo "No upstream ref configured for distro '${DISTRO}'" >&2; exit 1; }
|
||||||
|
|
||||||
|
git clone --depth 1 --branch "${upstream_ref}" "${UPSTREAM_REPO}" "${BUILD_DIR}/upstream"
|
||||||
|
|
||||||
|
# Overlay our manifests/support files into the upstream tree so that
|
||||||
|
# relative includes and *.repo discovery keep working.
|
||||||
|
cp "${IMAGE_DIR}/manifest.yaml" "${BUILD_DIR}/upstream/"
|
||||||
|
cp "${IMAGE_DIR}/custom.yaml" "${BUILD_DIR}/upstream/"
|
||||||
|
if compgen -G "${IMAGE_DIR}/repos/*.repo" >/dev/null; then
|
||||||
|
cp "${IMAGE_DIR}"/repos/*.repo "${BUILD_DIR}/upstream/"
|
||||||
|
fi
|
||||||
|
if [[ -d "${IMAGE_DIR}/files" ]]; then
|
||||||
|
cp -a "${IMAGE_DIR}/files/." "${BUILD_DIR}/upstream/"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "${TOKEN2}" == "1" ]]; then
|
||||||
|
setup_token2_repo "${BUILD_DIR}/upstream"
|
||||||
|
fi
|
||||||
|
|
||||||
|
MANIFEST="${BUILD_DIR}/upstream/manifest.yaml"
|
||||||
|
;;
|
||||||
|
standalone)
|
||||||
|
[[ -n "${RELEASEVER}" ]] || { echo "RELEASEVER not set in ${CONF}" >&2; exit 1; }
|
||||||
|
[[ -n "${REF}" ]] || { echo "REF not set in ${CONF}" >&2; exit 1; }
|
||||||
|
|
||||||
|
# Build from a copy so we never mutate the checked-in image definition.
|
||||||
|
mkdir -p "${BUILD_DIR}/images"
|
||||||
|
cp -a "${IMAGE_DIR}" "${BUILD_DIR}/images/${IMAGE}"
|
||||||
|
|
||||||
|
local_dir="${BUILD_DIR}/images/${IMAGE}"
|
||||||
|
if compgen -G "${local_dir}/repos/*.repo" >/dev/null; then
|
||||||
|
cp "${local_dir}"/repos/*.repo "${local_dir}/"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "${TOKEN2}" == "1" ]]; then
|
||||||
|
setup_token2_repo "${local_dir}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
cat > "${local_dir}/.build-manifest.yaml" <<EOF
|
||||||
|
releasever: ${RELEASEVER}
|
||||||
|
ref: ${REF}
|
||||||
|
include:
|
||||||
|
- manifest.yaml
|
||||||
|
EOF
|
||||||
|
MANIFEST="${local_dir}/.build-manifest.yaml"
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
echo "Unknown BUILD_MODE: ${BUILD_MODE}" >&2
|
||||||
|
exit 1
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
echo "Composing ${IMAGE} ${DISTRO} (${ARCH}) build ${buildid} ..."
|
||||||
|
|
||||||
|
RPM_OSTREE=(rpm-ostree)
|
||||||
|
if [[ "${EUID}" -ne 0 ]]; then
|
||||||
|
RPM_OSTREE=(sudo -E rpm-ostree)
|
||||||
|
fi
|
||||||
|
|
||||||
|
"${RPM_OSTREE[@]}" compose image \
|
||||||
|
--cachedir="${CACHE_DIR}" \
|
||||||
|
--initialize \
|
||||||
|
--max-layers=256 \
|
||||||
|
"${MANIFEST}" \
|
||||||
|
"${OCI_ARCHIVE}"
|
||||||
|
|
||||||
|
echo "Built: ${OCI_ARCHIVE}"
|
||||||
-75
@@ -1,75 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
set -euxo pipefail
|
|
||||||
|
|
||||||
if [[ $# -lt 2 ]]; then
|
|
||||||
echo "Usage: $0 <image-name> <version>"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
IMAGE="$1"
|
|
||||||
VERSION="$2"
|
|
||||||
|
|
||||||
IMAGE_DIR="images/${IMAGE}"
|
|
||||||
MANIFEST="${IMAGE_DIR}/manifest.yaml"
|
|
||||||
ROOTFS="${IMAGE_DIR}/rootfs"
|
|
||||||
REF="images/${IMAGE}/${VERSION}"
|
|
||||||
|
|
||||||
# --- CHECKS ---
|
|
||||||
if [[ ! -d "$IMAGE_DIR" ]]; then
|
|
||||||
echo "Image directory not found: $IMAGE_DIR"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [[ ! -f "$MANIFEST" ]]; then
|
|
||||||
echo "Manifest not found: $MANIFEST"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# --- PREPARE OSTREE REPO ---
|
|
||||||
mkdir -p repo cache
|
|
||||||
if [[ ! -f "repo/config" ]]; then
|
|
||||||
pushd repo >/dev/null
|
|
||||||
ostree init --repo=. --mode=bare-user
|
|
||||||
popd >/dev/null
|
|
||||||
fi
|
|
||||||
|
|
||||||
ostree --repo=repo config set core.fsync false
|
|
||||||
|
|
||||||
# --- VERSIONING ---
|
|
||||||
buildid="$(date '+%Y%m%d.0')"
|
|
||||||
timestamp="$(date --iso-8601=sec)"
|
|
||||||
echo "${buildid}" > .buildid
|
|
||||||
|
|
||||||
echo "Composing ${VERSION}.${buildid} ..."
|
|
||||||
|
|
||||||
# --- REPOS IMPORT ---
|
|
||||||
cp images/shared/*.repo "${IMAGE_DIR}/"
|
|
||||||
cp "${IMAGE_DIR}"/repos/*.repo "${IMAGE_DIR}/"
|
|
||||||
|
|
||||||
# --- MANIFEST FIXUPS ---
|
|
||||||
sed -i '/^ref:/d' "$MANIFEST"
|
|
||||||
sed -i '/^releasever:/d' "$MANIFEST"
|
|
||||||
|
|
||||||
sed -i "1i releasever: ${VERSION}" "$MANIFEST"
|
|
||||||
sed -i "1i ref: ${REF}" "$MANIFEST"
|
|
||||||
|
|
||||||
# --- OPTIONAL POSTPROCESS ---
|
|
||||||
POSTPROCESS="$IMAGE_DIR/test.sh"
|
|
||||||
if [[ -x "$POSTPROCESS" ]]; then
|
|
||||||
echo "Running postprocess script: $POSTPROCESS"
|
|
||||||
"$POSTPROCESS"
|
|
||||||
else
|
|
||||||
echo "No postprocess.sh found in ${IMAGE_DIR}, skipping."
|
|
||||||
fi
|
|
||||||
|
|
||||||
# --- COMPOSE ROOTFS ---
|
|
||||||
ARGS=(
|
|
||||||
"--cachedir=cache"
|
|
||||||
)
|
|
||||||
|
|
||||||
rm -rf "${ROOTFS:?}"
|
|
||||||
|
|
||||||
rpm-ostree compose rootfs \
|
|
||||||
"${ARGS[@]}" \
|
|
||||||
"$MANIFEST" \
|
|
||||||
"$ROOTFS"
|
|
||||||
-117
@@ -1,117 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
set -euox pipefail
|
|
||||||
|
|
||||||
IMAGE="$1"
|
|
||||||
VERSION="$2"
|
|
||||||
|
|
||||||
ROOTFS="${GITHUB_WORKSPACE}/images/${IMAGE}/rootfs"
|
|
||||||
CHANGELOG_DIR="changelogs/${IMAGE}"
|
|
||||||
|
|
||||||
mkdir -p "${CHANGELOG_DIR}"
|
|
||||||
|
|
||||||
PKG_CUR="${CHANGELOG_DIR}/packages-current.txt"
|
|
||||||
PKG_PREV="${CHANGELOG_DIR}/packages-latest.txt"
|
|
||||||
BUILD_ID="$(cat .buildid)"
|
|
||||||
CHANGELOG_FILE="${CHANGELOG_DIR}/${VERSION}.${BUILD_ID}.json"
|
|
||||||
|
|
||||||
# Ensure rpmdb exists (Berkeley DB or SQLite)
|
|
||||||
RPMDB="${ROOTFS}/usr/lib/sysimage/rpm"
|
|
||||||
if [[ ! -f "${RPMDB}/Packages" && ! -f "${RPMDB}/Packages.db" && ! -f "${RPMDB}/rpmdb.sqlite" ]]; then
|
|
||||||
echo "WARNING: rpmdb missing in rootfs (${ROOTFS})"
|
|
||||||
echo "Skipping changelog generation."
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Extract package list
|
|
||||||
rpm -qa --root "${ROOTFS}" --qf '%{NAME} %{EVR}\n' | sort > "${PKG_CUR}"
|
|
||||||
|
|
||||||
# Prepare safe temp files
|
|
||||||
CUR_NAMES_FILE="$(mktemp)"
|
|
||||||
PREV_NAMES_FILE="$(mktemp)"
|
|
||||||
|
|
||||||
cut -d' ' -f1 "${PKG_CUR}" | sort > "${CUR_NAMES_FILE}"
|
|
||||||
|
|
||||||
if [[ -f "${PKG_PREV}" ]]; then
|
|
||||||
cut -d' ' -f1 "${PKG_PREV}" | sort > "${PREV_NAMES_FILE}"
|
|
||||||
else
|
|
||||||
cp "${CUR_NAMES_FILE}" "${PREV_NAMES_FILE}"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Safe comm operations
|
|
||||||
ADDED_NAMES="$(comm -13 "${PREV_NAMES_FILE}" "${CUR_NAMES_FILE}" || true)"
|
|
||||||
REMOVED_NAMES="$(comm -23 "${PREV_NAMES_FILE}" "${CUR_NAMES_FILE}" || true)"
|
|
||||||
COMMON_NAMES="$(comm -12 "${PREV_NAMES_FILE}" "${CUR_NAMES_FILE}" || true)"
|
|
||||||
|
|
||||||
# Helper: get version from file using awk (exact match)
|
|
||||||
get_ver() {
|
|
||||||
local pkg="$1"
|
|
||||||
local file="$2"
|
|
||||||
awk -v p="$pkg" '$1 == p {print $2}' "$file"
|
|
||||||
}
|
|
||||||
|
|
||||||
# Build lists
|
|
||||||
ADDED_LIST=()
|
|
||||||
while read -r name; do
|
|
||||||
[[ -z "$name" ]] && continue
|
|
||||||
ver="$(get_ver "$name" "$PKG_CUR")"
|
|
||||||
ADDED_LIST+=("${name} ${ver}")
|
|
||||||
done <<< "${ADDED_NAMES}"
|
|
||||||
|
|
||||||
REMOVED_LIST=()
|
|
||||||
while read -r name; do
|
|
||||||
[[ -z "$name" ]] && continue
|
|
||||||
ver="$(get_ver "$name" "$PKG_PREV")"
|
|
||||||
REMOVED_LIST+=("${name} ${ver}")
|
|
||||||
done <<< "${REMOVED_NAMES}"
|
|
||||||
|
|
||||||
UPDATED_LIST=()
|
|
||||||
while read -r name; do
|
|
||||||
[[ -z "$name" ]] && continue
|
|
||||||
old_ver="$(get_ver "$name" "$PKG_PREV")"
|
|
||||||
new_ver="$(get_ver "$name" "$PKG_CUR")"
|
|
||||||
|
|
||||||
# Skip if either version is missing
|
|
||||||
[[ -z "$old_ver" || -z "$new_ver" ]] && continue
|
|
||||||
|
|
||||||
if [[ "$old_ver" != "$new_ver" ]]; then
|
|
||||||
UPDATED_LIST+=("${name} ${old_ver} -> ${new_ver}")
|
|
||||||
fi
|
|
||||||
done <<< "${COMMON_NAMES}"
|
|
||||||
|
|
||||||
ADDED_COUNT="${#ADDED_LIST[@]}"
|
|
||||||
REMOVED_COUNT="${#REMOVED_LIST[@]}"
|
|
||||||
UPDATED_COUNT="${#UPDATED_LIST[@]}"
|
|
||||||
|
|
||||||
# Write JSON
|
|
||||||
{
|
|
||||||
echo "{"
|
|
||||||
echo " \"image\": \"${IMAGE}\","
|
|
||||||
echo " \"version\": \"${VERSION}\","
|
|
||||||
echo " \"build_id\": \"${BUILD_ID}\","
|
|
||||||
echo " \"added_count\": ${ADDED_COUNT},"
|
|
||||||
echo " \"removed_count\": ${REMOVED_COUNT},"
|
|
||||||
echo " \"updated_count\": ${UPDATED_COUNT},"
|
|
||||||
echo " \"added\": ["
|
|
||||||
for i in "${!ADDED_LIST[@]}"; do
|
|
||||||
sep=$([[ $i -lt $((ADDED_COUNT-1)) ]] && echo "," || echo "")
|
|
||||||
printf ' "%s"%s\n' "${ADDED_LIST[$i]}" "${sep}"
|
|
||||||
done
|
|
||||||
echo " ],"
|
|
||||||
echo " \"removed\": ["
|
|
||||||
for i in "${!REMOVED_LIST[@]}"; do
|
|
||||||
sep=$([[ $i -lt $((REMOVED_COUNT-1)) ]] && echo "," || echo "")
|
|
||||||
printf ' "%s"%s\n' "${REMOVED_LIST[$i]}" "${sep}"
|
|
||||||
done
|
|
||||||
echo " ],"
|
|
||||||
echo " \"updated\": ["
|
|
||||||
for i in "${!UPDATED_LIST[@]}"; do
|
|
||||||
sep=$([[ $i -lt $((UPDATED_COUNT-1)) ]] && echo "," || echo "")
|
|
||||||
printf ' "%s"%s\n' "${UPDATED_LIST[$i]}" "${sep}"
|
|
||||||
done
|
|
||||||
echo " ]"
|
|
||||||
echo "}"
|
|
||||||
} > "${CHANGELOG_FILE}"
|
|
||||||
|
|
||||||
mv "${PKG_CUR}" "${PKG_PREV}"
|
|
||||||
|
|
||||||
echo "Changelog written to ${CHANGELOG_FILE}"
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,30 +0,0 @@
|
|||||||
{
|
|
||||||
"image": "asahi-cosmic",
|
|
||||||
"version": "43",
|
|
||||||
"build_id": "20260305.0",
|
|
||||||
"added_count": 2,
|
|
||||||
"removed_count": 0,
|
|
||||||
"updated_count": 14,
|
|
||||||
"added": [
|
|
||||||
"gvfs-mtp 1.58.1-1.fc43",
|
|
||||||
"libmtp 1.1.22-2.fc43"
|
|
||||||
],
|
|
||||||
"removed": [
|
|
||||||
],
|
|
||||||
"updated": [
|
|
||||||
"brcmfmac-firmware 20260110-1.fc43 -> 20260221-1.fc43",
|
|
||||||
"hwdata 0.404-1.fc43 -> 0.405-1.fc43",
|
|
||||||
"libnfsidmap 1:2.8.5-0.fc43 -> 1:2.8.5-0.rc3.fc43",
|
|
||||||
"lilv-libs 0.24.26-7.fc43 -> 0.26.4-1.fc43",
|
|
||||||
"linux-firmware 20260110-1.fc43 -> 20260221-1.fc43",
|
|
||||||
"linux-firmware-whence 20260110-1.fc43 -> 20260221-1.fc43",
|
|
||||||
"nfs-utils 1:2.8.5-0.fc43 -> 1:2.8.5-0.rc3.fc43",
|
|
||||||
"realtek-firmware 20260110-1.fc43 -> 20260221-1.fc43",
|
|
||||||
"rpm-ostree 2025.12-1.fc43 -> 2026.1-1.fc43",
|
|
||||||
"rpm-ostree-libs 2025.12-1.fc43 -> 2026.1-1.fc43",
|
|
||||||
"serd 0.32.4-2.fc43 -> 0.32.8-1.fc43",
|
|
||||||
"sord 0.16.18-2.fc43 -> 0.16.22-1.fc43",
|
|
||||||
"sratom 0.6.18-2.fc43 -> 0.6.22-1.fc43",
|
|
||||||
"zix 0.6.2-2.fc43 -> 0.8.0-2.fc43"
|
|
||||||
]
|
|
||||||
}
|
|
||||||
@@ -1,38 +0,0 @@
|
|||||||
{
|
|
||||||
"image": "asahi-cosmic",
|
|
||||||
"version": "43",
|
|
||||||
"build_id": "20260308.0",
|
|
||||||
"added_count": 0,
|
|
||||||
"removed_count": 0,
|
|
||||||
"updated_count": 24,
|
|
||||||
"added": [
|
|
||||||
],
|
|
||||||
"removed": [
|
|
||||||
],
|
|
||||||
"updated": [
|
|
||||||
"bootc 1.12.1-1.fc43 -> 1.13.0-2.fc43",
|
|
||||||
"buildah 2:1.42.2-1.fc43 -> 2:1.43.0-1.fc43",
|
|
||||||
"ca-certificates 2025.2.80_v9.0.304-1.1.fc43 -> 2025.2.80_v9.0.304-1.2.fc43",
|
|
||||||
"containers-common 5:0.64.2-1.fc43 -> 5:0.67.0-1.fc43",
|
|
||||||
"containers-common-extra 5:0.64.2-1.fc43 -> 5:0.67.0-1.fc43",
|
|
||||||
"kernel-16k 6.18.10-402.asahi.fc43 -> 6.18.15-400.asahi.fc43",
|
|
||||||
"kernel-16k-core 6.18.10-402.asahi.fc43 -> 6.18.15-400.asahi.fc43",
|
|
||||||
"kernel-16k-modules 6.18.10-402.asahi.fc43 -> 6.18.15-400.asahi.fc43",
|
|
||||||
"kernel-16k-modules-core 6.18.10-402.asahi.fc43 -> 6.18.15-400.asahi.fc43",
|
|
||||||
"kernel-16k-modules-extra 6.18.10-402.asahi.fc43 -> 6.18.15-400.asahi.fc43",
|
|
||||||
"podman 5:5.7.1-1.fc43 -> 5:5.8.0-1.fc43",
|
|
||||||
"skopeo 1:1.21.0-1.fc43 -> 1:1.22.0-2.fc43",
|
|
||||||
"systemd 258.5-1.fc43 -> 258.5-2.fc43",
|
|
||||||
"systemd-container 258.5-1.fc43 -> 258.5-2.fc43",
|
|
||||||
"systemd-libs 258.5-1.fc43 -> 258.5-2.fc43",
|
|
||||||
"systemd-oomd-defaults 258.5-1.fc43 -> 258.5-2.fc43",
|
|
||||||
"systemd-pam 258.5-1.fc43 -> 258.5-2.fc43",
|
|
||||||
"systemd-resolved 258.5-1.fc43 -> 258.5-2.fc43",
|
|
||||||
"systemd-shared 258.5-1.fc43 -> 258.5-2.fc43",
|
|
||||||
"systemd-sysusers 258.5-1.fc43 -> 258.5-2.fc43",
|
|
||||||
"systemd-udev 258.5-1.fc43 -> 258.5-2.fc43",
|
|
||||||
"tiny-dfr 0.3.5-3.fc43 -> 0.3.7-2.fc43",
|
|
||||||
"vim-data 2:9.2.045-1.fc43 -> 2:9.2.112-2.fc43",
|
|
||||||
"vim-minimal 2:9.2.045-1.fc43 -> 2:9.2.112-2.fc43"
|
|
||||||
]
|
|
||||||
}
|
|
||||||
@@ -1,139 +0,0 @@
|
|||||||
{
|
|
||||||
"image": "asahi-cosmic",
|
|
||||||
"version": "43",
|
|
||||||
"build_id": "20260403.0",
|
|
||||||
"added_count": 1,
|
|
||||||
"removed_count": 2,
|
|
||||||
"updated_count": 122,
|
|
||||||
"added": [
|
|
||||||
"gtk4-layer-shell 1.3.0-1.fc43"
|
|
||||||
],
|
|
||||||
"removed": [
|
|
||||||
"granite 6.2.0-11.fc43",
|
|
||||||
"gtk-layer-shell 0.10.0-1.fc43"
|
|
||||||
],
|
|
||||||
"updated": [
|
|
||||||
"SwayNotificationCenter 0.10.1-2.fc42 -> 0.12.5-1.fc43",
|
|
||||||
"at-spi2-atk 2.58.3-1.fc43 -> 2.58.4-1.fc43",
|
|
||||||
"at-spi2-core 2.58.3-1.fc43 -> 2.58.4-1.fc43",
|
|
||||||
"atk 2.58.3-1.fc43 -> 2.58.4-1.fc43",
|
|
||||||
"audit 4.1.3-1.fc43 -> 4.1.4-1.fc43",
|
|
||||||
"audit-libs 4.1.3-1.fc43 -> 4.1.4-1.fc43",
|
|
||||||
"audit-rules 4.1.3-1.fc43 -> 4.1.4-1.fc43",
|
|
||||||
"bind-libs 32:9.18.44-1.fc43 -> 32:9.18.47-1.fc43",
|
|
||||||
"bind-utils 32:9.18.44-1.fc43 -> 32:9.18.47-1.fc43",
|
|
||||||
"bootc 1.13.0-2.fc43 -> 1.14.1-1.fc43",
|
|
||||||
"brcmfmac-firmware 20260221-1.fc43 -> 20260309-1.fc43",
|
|
||||||
"btrfs-progs 6.17.1-1.fc43 -> 6.19.1-1.fc43",
|
|
||||||
"cifs-utils 7.2-2.fc43 -> 7.5-1.fc43",
|
|
||||||
"conmon 2:2.1.13-2.fc43 -> 2:2.2.1-2.fc43",
|
|
||||||
"container-selinux 4:2.245.0-1.fc43 -> 4:2.247.0-1.fc43",
|
|
||||||
"coreutils 9.7-7.fc43 -> 9.7-8.fc43",
|
|
||||||
"coreutils-common 9.7-7.fc43 -> 9.7-8.fc43",
|
|
||||||
"crun 1.25.1-1.fc43 -> 1.27-1.fc43",
|
|
||||||
"cups 1:2.4.16-4.fc43 -> 1:2.4.16-7.fc43",
|
|
||||||
"cups-client 1:2.4.16-4.fc43 -> 1:2.4.16-7.fc43",
|
|
||||||
"cups-filesystem 1:2.4.16-4.fc43 -> 1:2.4.16-7.fc43",
|
|
||||||
"cups-libs 1:2.4.16-4.fc43 -> 1:2.4.16-7.fc43",
|
|
||||||
"ethtool 2:6.15-3.fc43 -> 2:6.19-1.fc43",
|
|
||||||
"exfatprogs 1.3.1-1.fc43 -> 1.3.2-1.fc43",
|
|
||||||
"fd-find 10.3.0-1.fc43 -> 10.4.2-1.fc43",
|
|
||||||
"fedora-asahi-remix-release 43-13 -> 43-14",
|
|
||||||
"fedora-asahi-remix-release-common 43-13 -> 43-14",
|
|
||||||
"fedora-asahi-remix-release-identity-basic 43-13 -> 43-14",
|
|
||||||
"giflib 5.2.2-8.fc43 -> 5.2.2-9.fc43",
|
|
||||||
"glib2 2.86.4-1.fc43 -> 2.86.4-2.fc43",
|
|
||||||
"grub2-common 1:2.12-40.fc43 -> 1:2.12-42.fc43",
|
|
||||||
"grub2-efi-aa64 1:2.12-40.fc43 -> 1:2.12-42.fc43",
|
|
||||||
"grub2-efi-aa64-modules 1:2.12-40.fc43 -> 1:2.12-42.fc43",
|
|
||||||
"grub2-tools 1:2.12-40.fc43 -> 1:2.12-42.fc43",
|
|
||||||
"grub2-tools-minimal 1:2.12-40.fc43 -> 1:2.12-42.fc43",
|
|
||||||
"gstreamer1 1.26.10-1.fc43 -> 1.26.11-1.fc43",
|
|
||||||
"gstreamer1-plugin-libav 1.26.10-1.fc43 -> 1.26.11-1.fc43",
|
|
||||||
"gstreamer1-plugins-bad-free 1.26.10-1.fc43 -> 1.26.11-1.fc43",
|
|
||||||
"gstreamer1-plugins-bad-free-libs 1.26.10-1.fc43 -> 1.26.11-1.fc43",
|
|
||||||
"gstreamer1-plugins-base 1.26.10-1.fc43 -> 1.26.11-1.fc43",
|
|
||||||
"gstreamer1-plugins-good 1.26.10-1.fc43 -> 1.26.11-1.fc43",
|
|
||||||
"gstreamer1-plugins-ugly-free 1.26.10-1.fc43 -> 1.26.11-1.fc43",
|
|
||||||
"gtk-update-icon-cache 3.24.51-2.fc43 -> 3.24.52-1.fc43",
|
|
||||||
"gtk3 3.24.51-2.fc43 -> 3.24.52-1.fc43",
|
|
||||||
"gtk4 4.20.3-1.fc43 -> 4.20.4-1.fc43",
|
|
||||||
"gvfs 1.58.1-1.fc43 -> 1.58.4-1.fc43",
|
|
||||||
"gvfs-client 1.58.1-1.fc43 -> 1.58.4-1.fc43",
|
|
||||||
"gvfs-fuse 1.58.1-1.fc43 -> 1.58.4-1.fc43",
|
|
||||||
"gvfs-mtp 1.58.1-1.fc43 -> 1.58.4-1.fc43",
|
|
||||||
"krb5-libs 1.22.2-2.fc43 -> 1.22.2-3.fc43",
|
|
||||||
"libX11 1.8.12-1.fc43 -> 1.8.13-1.fc43",
|
|
||||||
"libX11-common 1.8.12-1.fc43 -> 1.8.13-1.fc43",
|
|
||||||
"libX11-xcb 1.8.12-1.fc43 -> 1.8.13-1.fc43",
|
|
||||||
"libadwaita 1.8.4-1.fc43 -> 1.8.5.1-1.fc43",
|
|
||||||
"libcap-ng 0.9.1-1.fc43 -> 0.9.2-1.fc43",
|
|
||||||
"libjpeg-turbo 3.1.2-1.fc43 -> 3.1.3-1.fc43",
|
|
||||||
"libmaxminddb 1.13.1-1.fc43 -> 1.13.3-1.fc43",
|
|
||||||
"libnfsidmap 1:2.8.5-0.rc3.fc43 -> 1:2.8.7-1.fc43",
|
|
||||||
"libopenmpt 0.8.4-1.fc43 -> 0.8.6-1.fc43",
|
|
||||||
"libseat 0.9.2-1.fc43 -> 0.9.3-1.fc43",
|
|
||||||
"libsolv 0.7.35-3.fc43 -> 0.7.36-2.fc43",
|
|
||||||
"libsoup3 3.6.6-1.fc43 -> 3.6.6-2.fc43",
|
|
||||||
"libtasn1 4.20.0-2.fc43 -> 4.21.0-1.fc43",
|
|
||||||
"linux-firmware 20260221-1.fc43 -> 20260309-1.fc43",
|
|
||||||
"linux-firmware-whence 20260221-1.fc43 -> 20260309-1.fc43",
|
|
||||||
"lsp-plugins-lv2 1.2.26-1.fc43 -> 1.2.27-1.fc43",
|
|
||||||
"nfs-utils 1:2.8.5-0.rc3.fc43 -> 1:2.8.7-1.fc43",
|
|
||||||
"ngtcp2 1.19.0-1.fc43 -> 1.21.0-1.fc43",
|
|
||||||
"ngtcp2-crypto-gnutls 1.19.0-1.fc43 -> 1.21.0-1.fc43",
|
|
||||||
"ngtcp2-crypto-ossl 1.19.0-1.fc43 -> 1.21.0-1.fc43",
|
|
||||||
"nspr 4.38.2-3.fc43 -> 4.38.2-4.fc43",
|
|
||||||
"nss 3.120.1-1.fc43 -> 3.121.0-1.fc43",
|
|
||||||
"nss-softokn 3.120.1-1.fc43 -> 3.121.0-1.fc43",
|
|
||||||
"nss-softokn-freebl 3.120.1-1.fc43 -> 3.121.0-1.fc43",
|
|
||||||
"nss-sysinit 3.120.1-1.fc43 -> 3.121.0-1.fc43",
|
|
||||||
"nss-util 3.120.1-1.fc43 -> 3.121.0-1.fc43",
|
|
||||||
"openldap 2.6.10-4.fc43 -> 2.6.13-1.fc43",
|
|
||||||
"openssh 10.0p1-6.fc43 -> 10.0p1-8.fc43",
|
|
||||||
"openssh-clients 10.0p1-6.fc43 -> 10.0p1-8.fc43",
|
|
||||||
"openssh-server 10.0p1-6.fc43 -> 10.0p1-8.fc43",
|
|
||||||
"pango 1.57.0-1.fc43 -> 1.57.1-1.fc43",
|
|
||||||
"pipewire 1.4.10-1.fc43 -> 1.4.11-1.fc43",
|
|
||||||
"pipewire-alsa 1.4.10-1.fc43 -> 1.4.11-1.fc43",
|
|
||||||
"pipewire-config-raop 1.4.10-1.fc43 -> 1.4.11-1.fc43",
|
|
||||||
"pipewire-gstreamer 1.4.10-1.fc43 -> 1.4.11-1.fc43",
|
|
||||||
"pipewire-libs 1.4.10-1.fc43 -> 1.4.11-1.fc43",
|
|
||||||
"pipewire-module-filter-chain-lv2 1.4.10-1.fc43 -> 1.4.11-1.fc43",
|
|
||||||
"pipewire-pulseaudio 1.4.10-1.fc43 -> 1.4.11-1.fc43",
|
|
||||||
"pipewire-utils 1.4.10-1.fc43 -> 1.4.11-1.fc43",
|
|
||||||
"podman 5:5.8.0-1.fc43 -> 5:5.8.1-1.fc43",
|
|
||||||
"polkit 126-6.fc43 -> 126-6.fc43.2",
|
|
||||||
"polkit-libs 126-6.fc43 -> 126-6.fc43.2",
|
|
||||||
"python3 3.14.3-1.fc43 -> 3.14.3-2.fc43",
|
|
||||||
"python3-asahi_firmware 0.7.9-4.fc43 -> 0.8.0-1.fc43",
|
|
||||||
"python3-audit 4.1.3-1.fc43 -> 4.1.4-1.fc43",
|
|
||||||
"python3-libs 3.14.3-1.fc43 -> 3.14.3-2.fc43",
|
|
||||||
"python3-pexpect 4.9.0-14.fc43 -> 4.9.0-15.fc43",
|
|
||||||
"realtek-firmware 20260221-1.fc43 -> 20260309-1.fc43",
|
|
||||||
"rmtfs 1.1-4.fc43 -> 1.1.1-2.fc43",
|
|
||||||
"rpm-ostree 2026.1-1.fc43 -> 2026.1-2.fc43",
|
|
||||||
"rpm-ostree-libs 2026.1-1.fc43 -> 2026.1-2.fc43",
|
|
||||||
"selinux-policy 42.24-1.fc43 -> 43.4-2.fc43",
|
|
||||||
"selinux-policy-targeted 42.24-1.fc43 -> 43.4-2.fc43",
|
|
||||||
"speakersafetyd 1.0.2-6.fc43 -> 1.0.2-7.fc43",
|
|
||||||
"systemd 258.5-2.fc43 -> 258.7-1.fc43",
|
|
||||||
"systemd-container 258.5-2.fc43 -> 258.7-1.fc43",
|
|
||||||
"systemd-libs 258.5-2.fc43 -> 258.7-1.fc43",
|
|
||||||
"systemd-oomd-defaults 258.5-2.fc43 -> 258.7-1.fc43",
|
|
||||||
"systemd-pam 258.5-2.fc43 -> 258.7-1.fc43",
|
|
||||||
"systemd-resolved 258.5-2.fc43 -> 258.7-1.fc43",
|
|
||||||
"systemd-shared 258.5-2.fc43 -> 258.7-1.fc43",
|
|
||||||
"systemd-sysusers 258.5-2.fc43 -> 258.7-1.fc43",
|
|
||||||
"systemd-udev 258.5-2.fc43 -> 258.7-1.fc43",
|
|
||||||
"tiny-dfr 0.3.7-2.fc43 -> 0.3.7-3.fc43",
|
|
||||||
"tzdata 2025c-1.fc43 -> 2026a-1.fc43",
|
|
||||||
"vim-data 2:9.2.112-2.fc43 -> 2:9.2.240-1.fc43",
|
|
||||||
"vim-minimal 2:9.2.112-2.fc43 -> 2:9.2.240-1.fc43",
|
|
||||||
"whois 5.6.5-1.fc43 -> 5.6.6-1.fc43",
|
|
||||||
"whois-nls 5.6.5-1.fc43 -> 5.6.6-1.fc43",
|
|
||||||
"wireplumber 0.5.13-1.fc43 -> 0.5.14-1.fc43",
|
|
||||||
"wireplumber-libs 0.5.13-1.fc43 -> 0.5.14-1.fc43",
|
|
||||||
"zlib-ng-compat 2.3.3-1.fc43 -> 2.3.3-2.fc43"
|
|
||||||
]
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,16 +0,0 @@
|
|||||||
#Asahi specific packages
|
|
||||||
packages:
|
|
||||||
# base
|
|
||||||
- alsa-ucm-asahi
|
|
||||||
- asahi-platform-metapackage
|
|
||||||
- asahi-repos
|
|
||||||
# - fedora-asahi-remix-scripts # Depends on dnf right now
|
|
||||||
- tiny-dfr
|
|
||||||
# boot
|
|
||||||
- grub2-efi-aa64-modules
|
|
||||||
- uboot-images-armv8
|
|
||||||
- asahi-fwupdate
|
|
||||||
- dracut-asahi
|
|
||||||
- update-m1n1
|
|
||||||
# desktop-environments
|
|
||||||
- aajohan-comfortaa-fonts
|
|
||||||
@@ -1,67 +0,0 @@
|
|||||||
metadata:
|
|
||||||
summary: Asahi remix atomic with the cosmic desktop
|
|
||||||
|
|
||||||
edition: "2024" #todo: figure out what this is used for
|
|
||||||
|
|
||||||
# Be minimal
|
|
||||||
recommends: false
|
|
||||||
|
|
||||||
# Default to `bash` in our container, the same as other containers we ship.
|
|
||||||
container-cmd:
|
|
||||||
- /sbin/init
|
|
||||||
|
|
||||||
#Settings
|
|
||||||
#Set the default systemd target
|
|
||||||
default_target: graphical.target
|
|
||||||
#Set selinux to true
|
|
||||||
selinux: true
|
|
||||||
|
|
||||||
include:
|
|
||||||
- ../shared/base.yaml
|
|
||||||
- ./asahi.yaml
|
|
||||||
- ./packages.yaml
|
|
||||||
|
|
||||||
repos:
|
|
||||||
- fedora-base
|
|
||||||
- fedora-updates
|
|
||||||
- fedora-asahi-remix-hotfixes
|
|
||||||
- copr:copr.fedorainfracloud.org:group_asahi:fedora-remix-branding
|
|
||||||
- copr:copr.fedorainfracloud.org:group_asahi:fedora-remix-scripts
|
|
||||||
- copr:copr.fedorainfracloud.org:group_asahi:kernel
|
|
||||||
- copr:copr.fedorainfracloud.org:group_asahi:mesa
|
|
||||||
- copr:copr.fedorainfracloud.org:group_asahi:u-boot
|
|
||||||
|
|
||||||
postprocess:
|
|
||||||
- |
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -xeuo pipefail
|
|
||||||
|
|
||||||
# Work around https://bugzilla.redhat.com/show_bug.cgi?id=1265295
|
|
||||||
# From https://github.com/coreos/fedora-coreos-config/blob/testing-devel/overlay.d/05core/usr/lib/systemd/journald.conf.d/10-coreos-persistent.conf
|
|
||||||
install -dm0755 /usr/lib/systemd/journald.conf.d/
|
|
||||||
echo -e "[Journal]\nStorage=persistent" > /usr/lib/systemd/journald.conf.d/10-persistent.conf
|
|
||||||
|
|
||||||
# See: https://src.fedoraproject.org/rpms/glibc/pull-request/4
|
|
||||||
# Basically that program handles deleting old shared library directories
|
|
||||||
# mid-transaction, which never applies to rpm-ostree. This is structured as a
|
|
||||||
# loop/glob to avoid hardcoding (or trying to match) the architecture.
|
|
||||||
for x in /usr/sbin/glibc_post_upgrade.*; do
|
|
||||||
if test -f ${x}; then
|
|
||||||
ln -srf /usr/bin/true ${x}
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
|
|
||||||
# Remove loader directory causing issues in Anaconda in unified core mode
|
|
||||||
# Will be obsolete once we start using bootupd
|
|
||||||
rm -rf /usr/lib/ostree-boot/loader
|
|
||||||
|
|
||||||
# Undo RPM scripts enabling units; we want the presets to be canonical
|
|
||||||
# https://github.com/projectatomic/rpm-ostree/issues/1803
|
|
||||||
rm -rf /etc/systemd/system/*
|
|
||||||
systemctl preset-all
|
|
||||||
rm -rf /etc/systemd/user/*
|
|
||||||
systemctl --user --global preset-all
|
|
||||||
|
|
||||||
# Fix triggerin for samba-client in cups package (not supported by rpm-ostree yet)
|
|
||||||
# https://github.com/fedora-silverblue/issue-tracker/issues/532
|
|
||||||
ln -snf /usr/libexec/samba/cups_backend_smb /usr/lib/cups/backend/smb
|
|
||||||
@@ -1,273 +0,0 @@
|
|||||||
|
|
||||||
# System packages (boot)
|
|
||||||
packages-aarch64:
|
|
||||||
- grub2-efi
|
|
||||||
- efibootmgr
|
|
||||||
- shim
|
|
||||||
|
|
||||||
#System packages (common)
|
|
||||||
|
|
||||||
# Core packages (common.yaml upstream)
|
|
||||||
packages:
|
|
||||||
- cosmic-edit
|
|
||||||
- cosmic-files
|
|
||||||
- cosmic-initial-setup
|
|
||||||
- cosmic-player
|
|
||||||
- cosmic-session
|
|
||||||
- cosmic-store
|
|
||||||
- cosmic-term
|
|
||||||
- flatpak
|
|
||||||
- gnome-disk-utility
|
|
||||||
- gnome-keyring-pam
|
|
||||||
- gnome-system-monitor
|
|
||||||
- mesa-dri-drivers
|
|
||||||
- mesa-vulkan-drivers
|
|
||||||
- plymouth-system-theme
|
|
||||||
- system-config-printer
|
|
||||||
- xdg-desktop-portal-gtk
|
|
||||||
- gvfs-mtp
|
|
||||||
# Ensure that we have a kernel. Kernel packages are not in any comps group
|
|
||||||
# - kernel
|
|
||||||
# - kernel-modules
|
|
||||||
# - kernel-modules-extra
|
|
||||||
# Do not include "full" Git as it brings in Perl
|
|
||||||
- git-core
|
|
||||||
# Explicitely add Git docs
|
|
||||||
- git-core-doc
|
|
||||||
# Required until we've completed the move to systemd-sysusers
|
|
||||||
# See: https://github.com/fedora-silverblue/issue-tracker/issues/362
|
|
||||||
- nss-altfiles
|
|
||||||
# Container management
|
|
||||||
- buildah
|
|
||||||
- podman
|
|
||||||
- skopeo
|
|
||||||
# Keep fuse-overlayfs for compatibilty and rootless containers use cases
|
|
||||||
# See: https://github.com/coreos/fedora-coreos-tracker/issues/1749
|
|
||||||
- fuse-overlayfs
|
|
||||||
# See: https://github.com/fedora-silverblue/issue-tracker/issues/503
|
|
||||||
- systemd-container
|
|
||||||
# Provides terminal tools like clear, reset, tput, and tset
|
|
||||||
- ncurses
|
|
||||||
# Flatpak support
|
|
||||||
- flatpak
|
|
||||||
- xdg-desktop-portal
|
|
||||||
# the archive repo for more reliable package layering
|
|
||||||
# https://github.com/coreos/fedora-coreos-tracker/issues/400
|
|
||||||
- fedora-repos-archive
|
|
||||||
# Always include at least full English language support by default
|
|
||||||
# https://gitlab.com/fedora/ostree/sig/-/issues/14
|
|
||||||
- langpacks-en
|
|
||||||
# Selected packages from the anaconda-tools group. See: https://gitlab.com/fedora/ostree/sig/-/issues/5
|
|
||||||
- dosfstools
|
|
||||||
- lvm2
|
|
||||||
- nvme-cli
|
|
||||||
- xfsprogs
|
|
||||||
# HFS filesystem tools for Apple hardware
|
|
||||||
# See https://github.com/projectatomic/rpm-ostree/issues/1380
|
|
||||||
- hfsplus-tools
|
|
||||||
|
|
||||||
# See: https://github.com/fedora-silverblue/issue-tracker/issues/390
|
|
||||||
- wireguard-tools
|
|
||||||
# See: https://gitlab.com/fedora/ostree/sig/-/issues/101
|
|
||||||
- gnupg2-scdaemon
|
|
||||||
- NetworkManager
|
|
||||||
- NetworkManager-bluetooth
|
|
||||||
- NetworkManager-config-connectivity-fedora
|
|
||||||
- NetworkManager-wifi
|
|
||||||
- NetworkManager-wwan
|
|
||||||
- acl
|
|
||||||
- alsa-ucm
|
|
||||||
- alsa-utils
|
|
||||||
- at-spi2-atk
|
|
||||||
- at-spi2-core
|
|
||||||
- attr
|
|
||||||
- audit
|
|
||||||
- b43-fwcutter
|
|
||||||
- b43-openfwwf
|
|
||||||
- bash
|
|
||||||
- bash-color-prompt
|
|
||||||
- bash-completion
|
|
||||||
- bc
|
|
||||||
- bind-utils
|
|
||||||
- bluez-cups
|
|
||||||
- brcmfmac-firmware
|
|
||||||
- brltty
|
|
||||||
- btrfs-progs
|
|
||||||
- bzip2
|
|
||||||
- chrony
|
|
||||||
- cifs-utils
|
|
||||||
- colord
|
|
||||||
- compsize
|
|
||||||
- coreutils
|
|
||||||
- cpio
|
|
||||||
- cryptsetup
|
|
||||||
- cups
|
|
||||||
- cups-browsed
|
|
||||||
- cups-filters
|
|
||||||
- curl
|
|
||||||
- cyrus-sasl-plain
|
|
||||||
- default-editor
|
|
||||||
- default-fonts-cjk-mono
|
|
||||||
- default-fonts-cjk-sans
|
|
||||||
- default-fonts-cjk-serif
|
|
||||||
- default-fonts-core-emoji
|
|
||||||
- default-fonts-core-math
|
|
||||||
- default-fonts-core-mono
|
|
||||||
- default-fonts-core-sans
|
|
||||||
- default-fonts-core-serif
|
|
||||||
- default-fonts-other-mono
|
|
||||||
- default-fonts-other-sans
|
|
||||||
- default-fonts-other-serif
|
|
||||||
- dnsmasq
|
|
||||||
- e2fsprogs
|
|
||||||
- ethtool
|
|
||||||
- exfatprogs
|
|
||||||
- file
|
|
||||||
- filesystem
|
|
||||||
- firewalld
|
|
||||||
- fpaste
|
|
||||||
- fwupd
|
|
||||||
- gamemode
|
|
||||||
- glibc
|
|
||||||
- glibc-all-langpacks
|
|
||||||
- gnupg2
|
|
||||||
- gstreamer1-plugin-dav1d
|
|
||||||
- gstreamer1-plugin-libav
|
|
||||||
- gstreamer1-plugins-bad-free
|
|
||||||
- gstreamer1-plugins-good
|
|
||||||
- gstreamer1-plugins-ugly-free
|
|
||||||
- gutenprint
|
|
||||||
- gutenprint-cups
|
|
||||||
- hostname
|
|
||||||
- hplip
|
|
||||||
- hunspell
|
|
||||||
- ibus-anthy
|
|
||||||
- ibus-chewing
|
|
||||||
- ibus-gtk3
|
|
||||||
- ibus-gtk4
|
|
||||||
- ibus-hangul
|
|
||||||
- ibus-libpinyin
|
|
||||||
- ibus-m17n
|
|
||||||
- ibus-typing-booster
|
|
||||||
- iproute
|
|
||||||
- iptables-nft
|
|
||||||
- iptstate
|
|
||||||
- iputils
|
|
||||||
- kbd
|
|
||||||
- kmscon
|
|
||||||
- less
|
|
||||||
- libglvnd-gles
|
|
||||||
- linux-firmware
|
|
||||||
- logrotate
|
|
||||||
- lrzsz
|
|
||||||
- lsof
|
|
||||||
- man-db
|
|
||||||
- man-pages
|
|
||||||
- mdadm
|
|
||||||
- mesa-dri-drivers
|
|
||||||
- mesa-vulkan-drivers
|
|
||||||
- mpage
|
|
||||||
- mtr
|
|
||||||
- nfs-utils
|
|
||||||
- nss-altfiles
|
|
||||||
- nss-mdns
|
|
||||||
- ntfs-3g
|
|
||||||
- ntfsprogs
|
|
||||||
- opensc
|
|
||||||
- openssh-clients
|
|
||||||
- openssh-server
|
|
||||||
- pam_afs_session
|
|
||||||
- paps
|
|
||||||
- passwdqc
|
|
||||||
- pciutils
|
|
||||||
- pinfo
|
|
||||||
- pipewire-alsa
|
|
||||||
- pipewire-config-raop
|
|
||||||
- pipewire-gstreamer
|
|
||||||
- pipewire-pulseaudio
|
|
||||||
- pipewire-utils
|
|
||||||
- plymouth
|
|
||||||
- plymouth-system-theme
|
|
||||||
- policycoreutils
|
|
||||||
- policycoreutils-python-utils
|
|
||||||
- prefixdevname
|
|
||||||
- procps-ng
|
|
||||||
- psmisc
|
|
||||||
- quota
|
|
||||||
- realtek-firmware
|
|
||||||
- rootfiles
|
|
||||||
- rpm
|
|
||||||
- rpm-ostree
|
|
||||||
- rsync
|
|
||||||
- samba-client
|
|
||||||
- selinux-policy-targeted
|
|
||||||
- setup
|
|
||||||
- shadow-utils
|
|
||||||
- sos
|
|
||||||
- speech-dispatcher
|
|
||||||
- spice-vdagent
|
|
||||||
- spice-webdavd
|
|
||||||
- sssd-common
|
|
||||||
- sssd-kcm
|
|
||||||
- sudo
|
|
||||||
- system-config-printer-udev
|
|
||||||
- systemd
|
|
||||||
- systemd-oomd-defaults
|
|
||||||
- systemd-resolved
|
|
||||||
- systemd-udev
|
|
||||||
- tar
|
|
||||||
- time
|
|
||||||
- tree
|
|
||||||
- unzip
|
|
||||||
- uresourced
|
|
||||||
- usb_modeswitch
|
|
||||||
- usbutils
|
|
||||||
- util-linux
|
|
||||||
- vim-minimal
|
|
||||||
- wget2-wget
|
|
||||||
- which
|
|
||||||
- whois
|
|
||||||
- wireplumber
|
|
||||||
- words
|
|
||||||
- wpa_supplicant
|
|
||||||
- zip
|
|
||||||
- zram-generator-defaults
|
|
||||||
- qrtr
|
|
||||||
- rmtfs
|
|
||||||
- upower
|
|
||||||
|
|
||||||
|
|
||||||
# Make sure the following are not pulled in when Recommended by other packages
|
|
||||||
exclude-packages:
|
|
||||||
- PackageKit
|
|
||||||
# We can not include openh264. See https://fedoraproject.org/wiki/OpenH264
|
|
||||||
- gstreamer1-plugin-openh264
|
|
||||||
- mozilla-openh264
|
|
||||||
- openh264
|
|
||||||
# https://github.com/fedora-silverblue/issue-tracker/issues/517
|
|
||||||
- sdubby
|
|
||||||
# Exclude Tk. We can not exclude Tcl as it is neeeded for usb_modeswitch
|
|
||||||
- tk
|
|
||||||
# Exclude QEMU. See: https://gitlab.com/fedora/ostree/sig/-/issues/58
|
|
||||||
- qemu-kvm
|
|
||||||
- qemu-kvm-core
|
|
||||||
- qemu-device-display-virtio-gpu
|
|
||||||
- qemu-device-display-virtio-vga
|
|
||||||
# See: https://github.com/fedora-silverblue/issue-tracker/issues/646
|
|
||||||
- hplip-gui
|
|
||||||
# Ensure that we do not include any Perl package
|
|
||||||
- perl-interpreter
|
|
||||||
- perl-libs
|
|
||||||
# Exclude GNOME Software's langpack plugin to avoid layering langpacks on
|
|
||||||
# systems where GNOME Software is included
|
|
||||||
- gnome-software-fedora-langpacks
|
|
||||||
# We include wget instead
|
|
||||||
- wcurl
|
|
||||||
# See: https://fedoraproject.org/wiki/Changes/AtomicDesktopDropPklaCompat
|
|
||||||
- polkit-pkla-compat
|
|
||||||
# See: https://fedoraproject.org/wiki/Changes/AtomicDesktopDropFuse2
|
|
||||||
# See: https://gitlab.com/fedora/ostree/sig/-/issues/50
|
|
||||||
- fuse
|
|
||||||
- fuselibs
|
|
||||||
# Can only be excluded on variants that do not include GNOME Software
|
|
||||||
- PackageKit-glib
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
[fedora-asahi-remix-hotfixes]
|
|
||||||
name=Fedora Asahi Remix Hotfixes
|
|
||||||
baseurl=https://fedora-asahi-remix.org/repos/hotfixes/$releasever/
|
|
||||||
type=rpm-md
|
|
||||||
skip_if_unavailable=True
|
|
||||||
gpgcheck=1
|
|
||||||
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch
|
|
||||||
repo_gpgcheck=0
|
|
||||||
enabled=1
|
|
||||||
enabled_metadata=1
|
|
||||||
priority=1
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
[copr:copr.fedorainfracloud.org:group_asahi:fedora-remix-branding]
|
|
||||||
name=Copr repo for fedora-remix-branding owned by @asahi
|
|
||||||
baseurl=https://download.copr.fedorainfracloud.org/results/@asahi/fedora-remix-branding/fedora-$releasever-$basearch/
|
|
||||||
type=rpm-md
|
|
||||||
skip_if_unavailable=False
|
|
||||||
gpgcheck=1
|
|
||||||
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-group_asahi-fedora-remix-branding
|
|
||||||
repo_gpgcheck=0
|
|
||||||
enabled=1
|
|
||||||
enabled_metadata=1
|
|
||||||
priority=1
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
[copr:copr.fedorainfracloud.org:group_asahi:fedora-remix-scripts]
|
|
||||||
name=Copr repo for fedora-remix-scripts owned by @asahi
|
|
||||||
baseurl=https://download.copr.fedorainfracloud.org/results/@asahi/fedora-remix-scripts/fedora-$releasever-$basearch/
|
|
||||||
type=rpm-md
|
|
||||||
skip_if_unavailable=False
|
|
||||||
gpgcheck=1
|
|
||||||
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-group_asahi-fedora-remix-scripts
|
|
||||||
repo_gpgcheck=0
|
|
||||||
enabled=1
|
|
||||||
enabled_metadata=1
|
|
||||||
priority=5
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
[copr:copr.fedorainfracloud.org:group_asahi:kernel]
|
|
||||||
name=Copr repo for kernel owned by @asahi
|
|
||||||
baseurl=https://download.copr.fedorainfracloud.org/results/@asahi/kernel/fedora-$releasever-$basearch/
|
|
||||||
type=rpm-md
|
|
||||||
skip_if_unavailable=False
|
|
||||||
gpgcheck=1
|
|
||||||
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-group_asahi-kernel
|
|
||||||
repo_gpgcheck=0
|
|
||||||
enabled=1
|
|
||||||
enabled_metadata=1
|
|
||||||
priority=5
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
[copr:copr.fedorainfracloud.org:group_asahi:mesa]
|
|
||||||
name=Copr repo for mesa owned by @asahi
|
|
||||||
baseurl=https://download.copr.fedorainfracloud.org/results/@asahi/mesa/fedora-$releasever-$basearch/
|
|
||||||
type=rpm-md
|
|
||||||
skip_if_unavailable=False
|
|
||||||
gpgcheck=1
|
|
||||||
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-group_asahi-mesa
|
|
||||||
repo_gpgcheck=0
|
|
||||||
enabled=1
|
|
||||||
enabled_metadata=1
|
|
||||||
priority=5
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
[copr:copr.fedorainfracloud.org:group_asahi:u-boot]
|
|
||||||
name=Copr repo for u-boot owned by @asahi
|
|
||||||
baseurl=https://download.copr.fedorainfracloud.org/results/@asahi/u-boot/fedora-$releasever-$basearch/
|
|
||||||
type=rpm-md
|
|
||||||
skip_if_unavailable=False
|
|
||||||
gpgcheck=1
|
|
||||||
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-group_asahi-u-boot
|
|
||||||
repo_gpgcheck=0
|
|
||||||
enabled=1
|
|
||||||
enabled_metadata=1
|
|
||||||
priority=5
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
set -euxo pipefail
|
|
||||||
|
|
||||||
#Get the asahi GPG keys
|
|
||||||
dnf copr enable -y @asahi/fedora-remix-branding
|
|
||||||
dnf install -y asahi-repos
|
|
||||||
@@ -1,53 +0,0 @@
|
|||||||
metadata:
|
|
||||||
summary: Effectively just bootc, systemd, kernel, and dnf as a starting point.
|
|
||||||
|
|
||||||
edition: "2024" #todo: figure out what this is used for
|
|
||||||
|
|
||||||
variables:
|
|
||||||
passwd_mode: full
|
|
||||||
|
|
||||||
recommends: true
|
|
||||||
|
|
||||||
# Default to `bash` in our container, the same as other containers we ship.
|
|
||||||
container-cmd:
|
|
||||||
- /sbin/init
|
|
||||||
|
|
||||||
remove-from-packages:
|
|
||||||
# Generally we expect other tools to do this (e.g. Ignition or cloud-init)
|
|
||||||
- [systemd, /usr/lib/systemd/system/sysinit.target.wants/systemd-firstboot.service]
|
|
||||||
|
|
||||||
include:
|
|
||||||
- ../shared/base.yaml
|
|
||||||
|
|
||||||
packages:
|
|
||||||
- kernel
|
|
||||||
# this is implied by dependencies but let's make it explicit
|
|
||||||
- coreutils
|
|
||||||
- dnf
|
|
||||||
# Even in minimal, we have this. If you don't want SELinux today, you'll need
|
|
||||||
# to build a custom image.
|
|
||||||
- selinux-policy-targeted
|
|
||||||
# And we want container-selinux because trying to layer it on later currently causes issues.
|
|
||||||
- container-selinux
|
|
||||||
# Needed for tpm2 bound luks
|
|
||||||
- tpm2-tools
|
|
||||||
|
|
||||||
packages-x86_64:
|
|
||||||
- grub2 grub2-efi-x64 efibootmgr shim
|
|
||||||
- microcode_ctl
|
|
||||||
|
|
||||||
exclude-packages:
|
|
||||||
- kernel-debug-core
|
|
||||||
|
|
||||||
remove-from-packages:
|
|
||||||
# The grub bits are mainly designed for desktops, and IMO haven't seen
|
|
||||||
# enough testing in concert with ostree. At some point we'll flesh out
|
|
||||||
# the full plan in https://github.com/coreos/fedora-coreos-tracker/issues/47
|
|
||||||
- [grub2-tools, /etc/grub.d/08_fallback_counting,
|
|
||||||
/etc/grub.d/10_reset_boot_success,
|
|
||||||
/etc/grub.d/12_menu_auto_hide,
|
|
||||||
/usr/lib/systemd/.*]
|
|
||||||
|
|
||||||
repos:
|
|
||||||
- fedora-base
|
|
||||||
- fedora-updates
|
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
# Build configuration for images/fedora-cosmic. Sourced by build.sh.
|
||||||
|
|
||||||
|
BUILD_MODE=upstream
|
||||||
|
|
||||||
|
# Upstream Fedora atomic desktop manifests (fork of workstation-ostree-config).
|
||||||
|
UPSTREAM_REPO="https://gitlab.com/fedora/ostree/ci-test.git"
|
||||||
|
|
||||||
|
# Map the distro we build to an upstream branch.
|
||||||
|
# main -> rawhide (currently releasever 46)
|
||||||
|
# f44 -> Fedora 44 stable
|
||||||
|
declare -A UPSTREAM_REFS=(
|
||||||
|
[44]=f44
|
||||||
|
[rawhide]=main
|
||||||
|
)
|
||||||
|
|
||||||
|
# Fetch token2-fido-bridge from its GitHub releases into a local repo.
|
||||||
|
TOKEN2=1
|
||||||
@@ -0,0 +1,55 @@
|
|||||||
|
# Customizations layered on top of the upstream Fedora COSMIC Atomic manifests.
|
||||||
|
|
||||||
|
packages:
|
||||||
|
# Fedora integration packages normally provided by the upstream fedora.yaml,
|
||||||
|
# re-added here without Firefox (which is shipped as a Flatpak instead).
|
||||||
|
- fedora-bookmarks
|
||||||
|
- fedora-chromium-config
|
||||||
|
- fedora-flathub-remote
|
||||||
|
- fedora-workstation-backgrounds
|
||||||
|
- fedora-workstation-repositories
|
||||||
|
- fedora-release-cosmic-atomic
|
||||||
|
- toolbox
|
||||||
|
|
||||||
|
# Smartcard / FIDO2 support for token2-fido-bridge.
|
||||||
|
# token2-fido-bridge itself is installed from a local repo that build.sh
|
||||||
|
# generates from the upstream GitHub release (it is not packaged in Fedora).
|
||||||
|
- pcsc-lite
|
||||||
|
- pcsc-lite-ccid
|
||||||
|
- pcsc-tools
|
||||||
|
- opensc
|
||||||
|
- libfido2
|
||||||
|
- fido2-tools
|
||||||
|
- p11-kit
|
||||||
|
- pam-u2f
|
||||||
|
- token2-fido-bridge
|
||||||
|
|
||||||
|
# Firefox is intentionally not part of the base system. It is preinstalled as a
|
||||||
|
# per-user Flatpak on first login instead (see flatpaks.list).
|
||||||
|
exclude-packages:
|
||||||
|
- firefox
|
||||||
|
|
||||||
|
add-files:
|
||||||
|
- ["flatpak-user-firstboot", "/usr/libexec/flatpak-user-firstboot"]
|
||||||
|
- ["flatpak-user-firstboot.service", "/usr/lib/systemd/user/flatpak-user-firstboot.service"]
|
||||||
|
- ["60-flatpak-user-firstboot.preset", "/usr/lib/systemd/user-preset/60-flatpak-user-firstboot.preset"]
|
||||||
|
- ["flatpaks.list", "/usr/share/flatpak/flatpaks.list"]
|
||||||
|
- ["50-token2-fido-bridge.preset", "/usr/lib/systemd/system-preset/50-token2-fido-bridge.preset"]
|
||||||
|
- ["uhid.conf", "/usr/lib/modules-load.d/uhid.conf"]
|
||||||
|
|
||||||
|
postprocess:
|
||||||
|
# The upstream fedora.yaml removes the Google Chrome repo from the Fedora
|
||||||
|
# Third Party repo list. We opt out of that manifest, so replicate it here.
|
||||||
|
# Workaround for https://github.com/coreos/rpm-ostree/issues/5494
|
||||||
|
- |
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -xeuo pipefail
|
||||||
|
sed -i -e '/google-chrome/,+2d' /usr/lib/fedora-third-party/conf.d/fedora-workstation.conf || true
|
||||||
|
|
||||||
|
# Ensure the first-login script is executable and make sure the
|
||||||
|
# globally-enabled per-user Flatpak unit is picked up.
|
||||||
|
- |
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
set -xeuo pipefail
|
||||||
|
chmod 0755 /usr/libexec/flatpak-user-firstboot
|
||||||
|
systemctl --user --global preset-all
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
# Enable the PC/SC smartcard daemon and the token2-fido-bridge daemon so that
|
||||||
|
# FIDO2 smartcards are exposed to browsers as a virtual USB-HID security key.
|
||||||
|
enable pcscd.socket
|
||||||
|
enable token2-fido-bridge.service
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
enable flatpak-user-firstboot.service
|
||||||
+24
@@ -0,0 +1,24 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# Install the per-user Flatpaks listed in /usr/share/flatpak/flatpaks.list on
|
||||||
|
# the first login of each user. Run as a systemd --user oneshot unit.
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
LIST="/usr/share/flatpak/flatpaks.list"
|
||||||
|
MARKER="${HOME}/.config/flatpak-user-firstboot.done"
|
||||||
|
|
||||||
|
[[ -f "${LIST}" ]] || exit 0
|
||||||
|
|
||||||
|
# Make Flathub available for the current user.
|
||||||
|
flatpak remote-add --user --if-not-exists flathub \
|
||||||
|
https://flathub.org/repo/flathub.flatpakrepo
|
||||||
|
|
||||||
|
mapfile -t apps < <(
|
||||||
|
sed -e 's/#.*//' -e 's/[[:space:]]//g' "${LIST}" | grep -v '^$' || true
|
||||||
|
)
|
||||||
|
|
||||||
|
if [[ ${#apps[@]} -gt 0 ]]; then
|
||||||
|
flatpak install --user --noninteractive --assumeyes "${apps[@]}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
install -dm0755 "$(dirname "${MARKER}")"
|
||||||
|
touch "${MARKER}"
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Install per-user Flatpak applications on first login
|
||||||
|
Documentation=https://docs.flatpak.org/en/latest/flatpak-command-reference.html
|
||||||
|
ConditionPathExists=!%h/.config/flatpak-user-firstboot.done
|
||||||
|
After=network-online.target
|
||||||
|
Wants=network-online.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
RemainAfterExit=yes
|
||||||
|
ExecStart=/usr/libexec/flatpak-user-firstboot
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=default.target
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
# Flatpaks installed into each user's per-user installation on first login.
|
||||||
|
# One application/runtime ID per line. Lines starting with # are ignored.
|
||||||
|
#
|
||||||
|
# Firefox is not part of the base system and is installed here instead.
|
||||||
|
org.mozilla.firefox
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
# token2-fido-bridge needs the uhid module to create the virtual FIDO2 device.
|
||||||
|
uhid
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
# Custom Fedora COSMIC Atomic image.
|
||||||
|
#
|
||||||
|
# This is a thin downstream layer on top of the upstream Fedora manifests from
|
||||||
|
# https://gitlab.com/fedora/ostree/ci-test, which are cloned into this directory
|
||||||
|
# at build time by build.sh (see build.conf for the ref mapping).
|
||||||
|
#
|
||||||
|
# The upstream leaf manifest is `cosmic-atomic.yaml`, which pulls in
|
||||||
|
# `cosmic-atomic-common.yaml` -> `common.yaml` + `packages/cosmic-atomic.yaml`.
|
||||||
|
|
||||||
|
metadata:
|
||||||
|
summary: Fedora COSMIC Atomic (custom)
|
||||||
|
|
||||||
|
variables:
|
||||||
|
# Opt out of the upstream `fedora.yaml` include so that we can ship our own
|
||||||
|
# Fedora integration package set without Firefox. This is the documented
|
||||||
|
# downstream hook (see the comment at the top of upstream's fedora.yaml).
|
||||||
|
distro: "fedora-cosmic"
|
||||||
|
|
||||||
|
ref: fedora-cosmic/${releasever_ref}/${basearch}/cosmic
|
||||||
|
|
||||||
|
include:
|
||||||
|
- cosmic-atomic.yaml
|
||||||
|
- custom.yaml
|
||||||
@@ -1,184 +0,0 @@
|
|||||||
#This file merges all the required yaml files from (https://gitlab.com/fedora/bootc/base-images/-/tree/main/minimal) into one
|
|
||||||
|
|
||||||
#==========================================================postprocess-conf.yaml========================================
|
|
||||||
# We want content lifecycled with the image
|
|
||||||
opt-usrlocal: "root"
|
|
||||||
|
|
||||||
# https://github.com/CentOS/centos-bootc/issues/167
|
|
||||||
machineid-compat: true
|
|
||||||
|
|
||||||
rpmdb: target
|
|
||||||
# We never want rpmdb.sqlite-shm as it's unreproducible
|
|
||||||
rpmdb-normalize: true
|
|
||||||
|
|
||||||
ignore-removed-users:
|
|
||||||
- root
|
|
||||||
ignore-removed-groups:
|
|
||||||
- root
|
|
||||||
# By default users and groups are injected to nss-altfiles
|
|
||||||
# which is immutable. This list moves a selected set
|
|
||||||
# to /etc/group instead, which is mutable per system
|
|
||||||
# and allows local users to become part of these groups.
|
|
||||||
etc-group-members:
|
|
||||||
- wheel
|
|
||||||
- systemd-journal
|
|
||||||
- tss # https://issues.redhat.com/browse/BIFROST-618
|
|
||||||
- kvm # https://issues.redhat.com/browse/RHEL-115278
|
|
||||||
- adm
|
|
||||||
|
|
||||||
#Only use the newer imports, not the one with backwards compatibility
|
|
||||||
#The files are retrieved when building to stay in sync with upstream
|
|
||||||
check-passwd:
|
|
||||||
type: "file"
|
|
||||||
filename: "passwd"
|
|
||||||
check-groups:
|
|
||||||
type: "file"
|
|
||||||
filename: "group"
|
|
||||||
|
|
||||||
#==========================================================postprocess-conf.yaml========================================
|
|
||||||
|
|
||||||
#tmpfiles.yaml
|
|
||||||
postprocess:
|
|
||||||
- |
|
|
||||||
#!/bin/bash
|
|
||||||
set -xeuo pipefail
|
|
||||||
cat >/usr/lib/tmpfiles.d/bootc-base-rpmstate.conf <<'EOF'
|
|
||||||
# Workaround for https://bugzilla.redhat.com/show_bug.cgi?id=771713
|
|
||||||
d /var/lib/rpm-state 0755 - - -
|
|
||||||
EOF
|
|
||||||
# Workaround for https://issues.redhat.com/browse/RHEL-106203
|
|
||||||
rm -f /usr/lib/tmpfiles.d/home.conf
|
|
||||||
|
|
||||||
- |
|
|
||||||
#!/bin/bash
|
|
||||||
set -xeuo pipefail
|
|
||||||
# Transforms /usr/lib/ostree-boot into a bootupd-compatible update payload
|
|
||||||
/usr/bin/bootupctl backend generate-update-metadata
|
|
||||||
|
|
||||||
# Workaround for https://issues.redhat.com/browse/RHEL-78104
|
|
||||||
- |
|
|
||||||
#!/bin/bash
|
|
||||||
set -xeuo pipefail
|
|
||||||
rm -vrf /usr/lib/ostree-boot/loader
|
|
||||||
|
|
||||||
# Set up default root config
|
|
||||||
- |
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -xeuo pipefail
|
|
||||||
mkdir -p /usr/lib/ostree
|
|
||||||
cat > /usr/lib/ostree/prepare-root.conf << EOF
|
|
||||||
[composefs]
|
|
||||||
enabled = yes
|
|
||||||
[sysroot]
|
|
||||||
readonly = true
|
|
||||||
EOF
|
|
||||||
|
|
||||||
#initrams config
|
|
||||||
- |
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -xeuo pipefail
|
|
||||||
mkdir -p /usr/lib/dracut/dracut.conf.d
|
|
||||||
cat > /usr/lib/dracut/dracut.conf.d/20-bootc-base.conf << 'EOF'
|
|
||||||
# We want a generic image; hostonly makes no sense as part of a server side build
|
|
||||||
hostonly=no
|
|
||||||
# Dracut will always fail to set security.selinux xattrs at build time
|
|
||||||
# https://github.com/dracut-ng/dracut-ng/issues/1561
|
|
||||||
export DRACUT_NO_XATTR=1
|
|
||||||
add_dracutmodules+=" kernel-modules dracut-systemd systemd-initrd base ostree "
|
|
||||||
EOF
|
|
||||||
cat > /usr/lib/dracut/dracut.conf.d/22-bootc-generic.conf << 'EOF'
|
|
||||||
# Extra modules that we want by default that are known to exist in the kernel
|
|
||||||
add_dracutmodules+=" virtiofs "
|
|
||||||
EOF
|
|
||||||
cat > /usr/lib/dracut/dracut.conf.d/59-altfiles.conf << 'EOF'
|
|
||||||
# https://issues.redhat.com/browse/RHEL-49590
|
|
||||||
# On image mode systems we use nss-altfiles for passwd and group,
|
|
||||||
# this makes sure dracut uses them which also fixes kdump writing to NFS.
|
|
||||||
install_items+=" /usr/lib/passwd /usr/lib/group "
|
|
||||||
EOF
|
|
||||||
|
|
||||||
- |
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -xeuo pipefail
|
|
||||||
mkdir -p /usr/lib/systemd/system/local-fs.target.wants
|
|
||||||
if test '!' -f /usr/lib/systemd/system/local-fs.target.wants/tmp.mount; then
|
|
||||||
ln -sf ../tmp.mount /usr/lib/systemd/system/local-fs.target.wants
|
|
||||||
fi
|
|
||||||
sed -i -e 's, /root, /var/roothome,' /usr/lib/tmpfiles.d/provision.conf > /dev/null
|
|
||||||
sed -i -e '/^d- \/var\/roothome /d' /usr/lib/tmpfiles.d/provision.conf > /dev/null
|
|
||||||
|
|
||||||
- |
|
|
||||||
#!/usr/bin/env bash
|
|
||||||
set -xeuo pipefail
|
|
||||||
source /usr/lib/os-release
|
|
||||||
mkdir -p /usr/lib/kernel/install.conf.d
|
|
||||||
echo -e "# kernel-install will not try to run dracut and allow rpm-ostree to\n\
|
|
||||||
# take over. Rpm-ostree will use this to know that it is responsible\n\
|
|
||||||
# to run dracut and ensure that there is only one kernel in the image\n\
|
|
||||||
layout=ostree" | tee /usr/lib/kernel/install.conf /usr/lib/kernel/install.conf.d/00-bootc-kernel-layout.conf > /dev/null
|
|
||||||
# By default dnf keeps multiple versions of the kernel, with this
|
|
||||||
# configuration we tell dnf to treat the kernel as everything else.
|
|
||||||
# https://dnf.readthedocs.io/en/latest/conf_ref.html#main-options
|
|
||||||
# Let's add the config to a distribution configuration file if dnf5
|
|
||||||
# is used, we append to /etc/dnf/dnf.conf if not.
|
|
||||||
# Also set protect_running_kernel=False, dnf/yum pre-dates Containers and
|
|
||||||
# uses uname to protect the running kernel even on Container builds.
|
|
||||||
if [ -d "/usr/share/dnf5/libdnf.conf.d/" ]; then
|
|
||||||
echo -e "[main]\ninstallonlypkgs=''" >> /usr/share/dnf5/libdnf.conf.d/20-ostree-installonlypkgs.conf
|
|
||||||
echo -e "[main]\nprotect_running_kernel=False" >> /usr/share/dnf5/libdnf.conf.d/20-ostree-protect_running_kernel.conf
|
|
||||||
else
|
|
||||||
echo "installonlypkgs=''" >> /etc/dnf/dnf.conf
|
|
||||||
echo "protect_running_kernel=False" >> /etc/dnf/dnf.conf
|
|
||||||
fi
|
|
||||||
|
|
||||||
- |
|
|
||||||
#!/bin/bash
|
|
||||||
set -xeuo pipefail
|
|
||||||
# Override some of the default presets.
|
|
||||||
cat <<EOF > usr/lib/systemd/system-preset/85-bootc.preset
|
|
||||||
# Disable dnf-makecache.timer on bootc/image mode systems
|
|
||||||
# https://github.com/coreos/fedora-coreos-tracker/issues/1896#issuecomment-2848251507
|
|
||||||
disable dnf-makecache.timer
|
|
||||||
EOF
|
|
||||||
# Enable bootloader-update.service on F43+.
|
|
||||||
# https://github.com/coreos/fedora-coreos-tracker/issues/1468#issuecomment-2996654547
|
|
||||||
# https://fedoraproject.org/wiki/Changes/AutomaticBootloaderUpdatesBootc
|
|
||||||
- |
|
|
||||||
#!/bin/bash
|
|
||||||
set -xeuo pipefail
|
|
||||||
echo "enable bootloader-update.service" >> /usr/lib/systemd/system-preset/85-bootc.preset
|
|
||||||
# Undo RPM scripts enabling units; we want the presets to be canonical
|
|
||||||
# https://github.com/projectatomic/rpm-ostree/issues/1803
|
|
||||||
- |
|
|
||||||
#!/bin/bash
|
|
||||||
set -xeuo pipefail
|
|
||||||
rm -rf /etc/systemd/system/*
|
|
||||||
systemctl preset-all
|
|
||||||
rm -rf /etc/systemd/user/*
|
|
||||||
systemctl --user --global preset-all
|
|
||||||
|
|
||||||
#Selected ownership fixes for files in /etc & /var owned by a dynamic UID/GID
|
|
||||||
# See: https://gitlab.com/fedora/ostree/sig/-/issues/90
|
|
||||||
- |
|
|
||||||
#!/bin/bash
|
|
||||||
set -xeuo pipefail
|
|
||||||
|
|
||||||
cat > /usr/lib/tmpfiles.d/90-atomic-desktops-ownership-fixes.conf << 'EOF'
|
|
||||||
Z /var/lib/passim - passim passim
|
|
||||||
Z /var/log/passim - passim passim
|
|
||||||
Z /etc/colord/ - colord colord
|
|
||||||
EOF
|
|
||||||
|
|
||||||
packages:
|
|
||||||
|
|
||||||
# systemd. Also name systemd-pam because it was dropped to a recommends
|
|
||||||
# but we still want it for handling user logins/sessions.
|
|
||||||
- systemd systemd-pam
|
|
||||||
# bootc itself.
|
|
||||||
- bootc
|
|
||||||
# Required by bootc install, sgdisk has been replaced by Rust crate
|
|
||||||
# in bootc https://github.com/containers/bootc/pull/775
|
|
||||||
- xfsprogs e2fsprogs dosfstools
|
|
||||||
- bootupd
|
|
||||||
|
|
||||||
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
[fedora-base]
|
|
||||||
name=Fedora $releasever $basearch Base
|
|
||||||
mirrorlist=https://mirrors.fedoraproject.org/metalink?repo=fedora-$releasever&arch=$basearch
|
|
||||||
enabled=1
|
|
||||||
gpgcheck=1
|
|
||||||
metadata_expire=1d
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
[fedora-updates]
|
|
||||||
name=Fedora $releasever $basearch Updates
|
|
||||||
mirrorlist=https://mirrors.fedoraproject.org/metalink?repo=updates-released-f$releasever&arch=$basearch
|
|
||||||
enabled=1
|
|
||||||
gpgcheck=1
|
|
||||||
metadata_expire=1d
|
|
||||||
@@ -1,45 +0,0 @@
|
|||||||
root:x:0:
|
|
||||||
bin:x:1:
|
|
||||||
daemon:x:2:
|
|
||||||
sys:x:3:
|
|
||||||
adm:x:4:
|
|
||||||
tty:x:5:
|
|
||||||
disk:x:6:
|
|
||||||
lp:x:7:
|
|
||||||
mem:x:8:
|
|
||||||
kmem:x:9:
|
|
||||||
wheel:x:10:
|
|
||||||
cdrom:x:11:
|
|
||||||
mail:x:12:
|
|
||||||
man:x:15:
|
|
||||||
dialout:x:18:
|
|
||||||
floppy:x:19:
|
|
||||||
games:x:20:
|
|
||||||
rpcuser:x:29:
|
|
||||||
tape:x:33:
|
|
||||||
video:x:39:
|
|
||||||
dip:x:40:
|
|
||||||
ftp:x:50:
|
|
||||||
lock:x:54:
|
|
||||||
audio:x:63:
|
|
||||||
tcpdump:x:72:
|
|
||||||
nobody:x:99:
|
|
||||||
users:x:100:
|
|
||||||
input:x:104:
|
|
||||||
ceph:x:167:
|
|
||||||
avahi-autoipd:x:170:
|
|
||||||
systemd-journal:x:190:
|
|
||||||
dockerroot:x:986:
|
|
||||||
cockpit-ws:x:987:
|
|
||||||
systemd-bus-proxy:x:988:
|
|
||||||
systemd-resolve:x:989:
|
|
||||||
systemd-network:x:990:
|
|
||||||
systemd-timesync:x:991:
|
|
||||||
chrony:x:992:
|
|
||||||
sssd:x:993:
|
|
||||||
kube:x:994:
|
|
||||||
cgred:x:996:
|
|
||||||
etcd:x:997:
|
|
||||||
polkitd:x:998:
|
|
||||||
ssh_keys:x:999:
|
|
||||||
nfsnobody:x:65534:
|
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
|
|
||||||
root:x:0:0:Super User:/root:/bin/bash
|
|
||||||
bin:x:1:1:bin:/bin:/usr/sbin/nologin
|
|
||||||
daemon:x:2:2:daemon:/sbin:/usr/sbin/nologin
|
|
||||||
adm:x:3:4:adm:/var/adm:/usr/sbin/nologin
|
|
||||||
lp:x:4:7:lp:/var/spool/lpd:/usr/sbin/nologin
|
|
||||||
sync:x:5:0:sync:/sbin:/bin/sync
|
|
||||||
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
|
|
||||||
halt:x:7:0:halt:/sbin:/sbin/halt
|
|
||||||
mail:x:8:12:mail:/var/spool/mail:/usr/sbin/nologin
|
|
||||||
operator:x:11:0:operator:/root:/usr/sbin/nologin
|
|
||||||
games:x:12:100:games:/usr/games:/usr/sbin/nologin
|
|
||||||
ftp:x:14:50:FTP User:/var/ftp:/usr/sbin/nologin
|
|
||||||
rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/usr/sbin/nologin
|
|
||||||
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/usr/sbin/nologin
|
|
||||||
tcpdump:x:72:72::/:/usr/sbin/nologin
|
|
||||||
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/usr/sbin/nologin
|
|
||||||
dbus:x:81:81:System Message Bus:/:/usr/sbin/nologin
|
|
||||||
nobody:x:99:99:Kernel Overflow User:/:/usr/sbin/nologin
|
|
||||||
ceph:x:167:167:Ceph daemons:/var/lib/ceph:/usr/sbin/nologin
|
|
||||||
avahi-autoipd:x:170:170:Avahi IPv4LL Stack:/var/lib/avahi-autoipd:/usr/sbin/nologin
|
|
||||||
cockpit-ws:x:988:987:User for cockpit-ws:/:/usr/sbin/nologin
|
|
||||||
systemd-bus-proxy:x:989:988:systemd Bus Proxy:/:/usr/sbin/nologin
|
|
||||||
systemd-resolve:x:990:989:systemd Resolver:/:/usr/sbin/nologin
|
|
||||||
systemd-network:x:991:990:systemd Network Management:/:/usr/sbin/nologin
|
|
||||||
systemd-timesync:x:993:991:systemd Time Synchronization:/:/usr/sbin/nologin
|
|
||||||
chrony:x:994:992::/var/lib/chrony:/usr/sbin/nologin
|
|
||||||
sssd:x:995:993:User for sssd:/run/sssd:/usr/sbin/nologin
|
|
||||||
kube:x:996:994:Kubernetes user:/:/usr/sbin/nologin
|
|
||||||
dockerroot:x:997:986:Docker User:/var/lib/docker:/usr/sbin/nologin
|
|
||||||
etcd:x:998:997:etcd user:/var/lib/etcd:/usr/sbin/nologin
|
|
||||||
polkitd:x:999:998:User for polkitd:/:/usr/sbin/nologin
|
|
||||||
nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/usr/sbin/nologin
|
|
||||||
Executable
+163
@@ -0,0 +1,163 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# Generate a package changelog for a freshly built image and publish it as a
|
||||||
|
# Gitea release (instead of committing JSON files under changelogs/).
|
||||||
|
#
|
||||||
|
# Usage: release.sh <image> <distro> <buildid> <ociarchive>
|
||||||
|
#
|
||||||
|
# The full package list is attached to each release as
|
||||||
|
# packages-<image>-<distro>.txt
|
||||||
|
# and the previous release's asset is used as the diff baseline.
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
if [[ $# -lt 4 ]]; then
|
||||||
|
echo "Usage: $0 <image> <distro> <buildid> <ociarchive>" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
IMAGE="$1"
|
||||||
|
DISTRO="$2"
|
||||||
|
BUILDID="$3"
|
||||||
|
OCI_ARCHIVE="$4"
|
||||||
|
|
||||||
|
GITEA_URL="${GITEA_URL:-https://git.plabble.org}"
|
||||||
|
GITEA_REPO="${GITEA_REPO:-Misthios/bootc-images}"
|
||||||
|
TOKEN="${RELEASE_TOKEN:-${GITHUB_TOKEN:-}}"
|
||||||
|
|
||||||
|
[[ -n "${TOKEN}" ]] || { echo "RELEASE_TOKEN (or GITHUB_TOKEN) is required" >&2; exit 1; }
|
||||||
|
[[ -f "${OCI_ARCHIVE}" ]] || { echo "Missing OCI archive: ${OCI_ARCHIVE}" >&2; exit 1; }
|
||||||
|
|
||||||
|
API="${GITEA_URL%/}/api/v1/repos/${GITEA_REPO}"
|
||||||
|
RELEASE_TAG="${IMAGE}-${DISTRO}.${BUILDID}"
|
||||||
|
ASSET_NAME="packages-${IMAGE}-${DISTRO}.txt"
|
||||||
|
RELEASE_TITLE="${IMAGE} ${DISTRO} ${BUILDID}"
|
||||||
|
|
||||||
|
WORK="$(mktemp -d)"
|
||||||
|
trap 'rm -rf "${WORK}"' EXIT
|
||||||
|
|
||||||
|
# Idempotency: never create the same release twice (e.g. a re-run).
|
||||||
|
if curl -fsSL -H "Authorization: token ${TOKEN}" \
|
||||||
|
"${API}/releases/tags/${RELEASE_TAG}" >/dev/null 2>&1; then
|
||||||
|
echo "Release ${RELEASE_TAG} already exists; nothing to do."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# --- package list from the built image -------------------------------------
|
||||||
|
echo "Extracting package list from ${OCI_ARCHIVE} ..."
|
||||||
|
export STORAGE_DRIVER=vfs
|
||||||
|
ctr="$(buildah from "oci-archive:${OCI_ARCHIVE}")"
|
||||||
|
mnt="$(buildah mount "${ctr}")"
|
||||||
|
rpm -qa --root "${mnt}" --qf '%{NAME} %{EVR}\n' | sort > "${WORK}/packages-current.txt"
|
||||||
|
buildah unmount "${ctr}"
|
||||||
|
buildah rm "${ctr}" >/dev/null
|
||||||
|
|
||||||
|
# --- previous package list from the last release ---------------------------
|
||||||
|
# Walk the release list (newest first) until we find the newest release for
|
||||||
|
# this image/distro.
|
||||||
|
prev_release_id=""
|
||||||
|
page=1
|
||||||
|
while :; do
|
||||||
|
page_json="$(curl -fsSL -H "Authorization: token ${TOKEN}" \
|
||||||
|
"${API}/releases?limit=50&page=${page}")"
|
||||||
|
[[ "$(jq 'length' <<< "${page_json}")" -eq 0 ]] && break
|
||||||
|
prev_release_id="$(jq -r --arg prefix "${IMAGE}-${DISTRO}." \
|
||||||
|
'.[] | select(.tag_name | startswith($prefix)) | .id' <<< "${page_json}" \
|
||||||
|
| head -n1)"
|
||||||
|
[[ -n "${prev_release_id}" ]] && break
|
||||||
|
page=$((page + 1))
|
||||||
|
[[ "${page}" -gt 20 ]] && break
|
||||||
|
done
|
||||||
|
|
||||||
|
if [[ -n "${prev_release_id}" ]]; then
|
||||||
|
asset_url="$(curl -fsSL -H "Authorization: token ${TOKEN}" \
|
||||||
|
"${API}/releases/${prev_release_id}" \
|
||||||
|
| jq -r --arg name "${ASSET_NAME}" \
|
||||||
|
'.assets[] | select(.name == $name) | .browser_download_url' \
|
||||||
|
| head -n1)"
|
||||||
|
if [[ -n "${asset_url}" && "${asset_url}" != "null" ]]; then
|
||||||
|
curl -fsSL -H "Authorization: token ${TOKEN}" "${asset_url}" \
|
||||||
|
-o "${WORK}/packages-previous.txt" || true
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
# First ever build: baseline against itself so nothing shows up as removed.
|
||||||
|
[[ -f "${WORK}/packages-previous.txt" ]] \
|
||||||
|
|| cp "${WORK}/packages-current.txt" "${WORK}/packages-previous.txt"
|
||||||
|
|
||||||
|
# --- diff -------------------------------------------------------------------
|
||||||
|
CUR_NAMES="$(mktemp)"
|
||||||
|
PREV_NAMES="$(mktemp)"
|
||||||
|
cut -d' ' -f1 "${WORK}/packages-current.txt" | sort > "${CUR_NAMES}"
|
||||||
|
cut -d' ' -f1 "${WORK}/packages-previous.txt" | sort > "${PREV_NAMES}"
|
||||||
|
|
||||||
|
added_names="$(comm -13 "${PREV_NAMES}" "${CUR_NAMES}" || true)"
|
||||||
|
removed_names="$(comm -23 "${PREV_NAMES}" "${CUR_NAMES}" || true)"
|
||||||
|
common_names="$(comm -12 "${PREV_NAMES}" "${CUR_NAMES}" || true)"
|
||||||
|
|
||||||
|
ver_of() { awk -v p="$1" '$1 == p {print $2}' "$2"; }
|
||||||
|
|
||||||
|
added=()
|
||||||
|
while read -r n; do
|
||||||
|
[[ -z "${n}" ]] && continue
|
||||||
|
added+=("${n} $(ver_of "${n}" "${WORK}/packages-current.txt")")
|
||||||
|
done <<< "${added_names}"
|
||||||
|
|
||||||
|
removed=()
|
||||||
|
while read -r n; do
|
||||||
|
[[ -z "${n}" ]] && continue
|
||||||
|
removed+=("${n} $(ver_of "${n}" "${WORK}/packages-previous.txt")")
|
||||||
|
done <<< "${removed_names}"
|
||||||
|
|
||||||
|
updated=()
|
||||||
|
while read -r n; do
|
||||||
|
[[ -z "${n}" ]] && continue
|
||||||
|
old="$(ver_of "${n}" "${WORK}/packages-previous.txt")"
|
||||||
|
new="$(ver_of "${n}" "${WORK}/packages-current.txt")"
|
||||||
|
[[ -z "${old}" || -z "${new}" ]] && continue
|
||||||
|
[[ "${old}" != "${new}" ]] && updated+=("${n} ${old} -> ${new}")
|
||||||
|
done <<< "${common_names}"
|
||||||
|
|
||||||
|
{
|
||||||
|
echo "Automated build of \`${IMAGE}\` \`${DISTRO}\` (\`${BUILDID}\`)."
|
||||||
|
echo
|
||||||
|
echo "- Added: ${#added[@]}"
|
||||||
|
echo "- Removed: ${#removed[@]}"
|
||||||
|
echo "- Updated: ${#updated[@]}"
|
||||||
|
echo
|
||||||
|
if (( ${#added[@]} )); then
|
||||||
|
echo "### Added"
|
||||||
|
printf -- '- %s\n' "${added[@]}"
|
||||||
|
echo
|
||||||
|
fi
|
||||||
|
if (( ${#removed[@]} )); then
|
||||||
|
echo "### Removed"
|
||||||
|
printf -- '- %s\n' "${removed[@]}"
|
||||||
|
echo
|
||||||
|
fi
|
||||||
|
if (( ${#updated[@]} )); then
|
||||||
|
echo "### Updated"
|
||||||
|
printf -- '- %s\n' "${updated[@]}"
|
||||||
|
echo
|
||||||
|
fi
|
||||||
|
} > "${WORK}/changelog.md"
|
||||||
|
|
||||||
|
# --- create the release -----------------------------------------------------
|
||||||
|
echo "Creating release ${RELEASE_TAG} ..."
|
||||||
|
payload="$(jq -n \
|
||||||
|
--arg tag "${RELEASE_TAG}" \
|
||||||
|
--arg name "${RELEASE_TITLE}" \
|
||||||
|
--arg body "$(cat "${WORK}/changelog.md")" \
|
||||||
|
'{tag_name: $tag, name: $name, body: $body, draft: false, prerelease: false}')"
|
||||||
|
|
||||||
|
response="$(curl -fsSL -X POST \
|
||||||
|
-H "Authorization: token ${TOKEN}" \
|
||||||
|
-H "Content-Type: application/json" \
|
||||||
|
-d "${payload}" \
|
||||||
|
"${API}/releases")"
|
||||||
|
release_id="$(jq -r '.id' <<< "${response}")"
|
||||||
|
|
||||||
|
echo "Uploading ${ASSET_NAME} ..."
|
||||||
|
curl -fsSL -X POST \
|
||||||
|
-H "Authorization: token ${TOKEN}" \
|
||||||
|
-F "attachment=@${WORK}/packages-current.txt" \
|
||||||
|
"${API}/releases/${release_id}/assets?name=${ASSET_NAME}"
|
||||||
|
|
||||||
|
echo "Published release ${RELEASE_TAG}."
|
||||||
Reference in New Issue
Block a user