ci: generate package list during compose via finalize.d
Avoid mounting the built image with buildah (ran out of disk); the finalize.d hook records the rpm list next to the treefile and release.sh consumes it directly.
This commit is contained in:
@@ -46,7 +46,7 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
dnf install -y nodejs jq curl git createrepo_c
|
dnf install -y nodejs jq curl git createrepo_c
|
||||||
dnf install -y skopeo buildah
|
dnf install -y skopeo
|
||||||
dnf install -y cosign || true
|
dnf install -y cosign || true
|
||||||
if ! command -v cosign >/dev/null; then
|
if ! command -v cosign >/dev/null; then
|
||||||
case "$(uname -m)" in
|
case "$(uname -m)" in
|
||||||
@@ -114,5 +114,5 @@ jobs:
|
|||||||
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
|
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
|
||||||
run: |
|
run: |
|
||||||
buildid="$(cat .buildid)"
|
buildid="$(cat .buildid)"
|
||||||
oci="build/${IMAGE}-${DISTRO}-${ARCH}/${IMAGE}-${DISTRO}-${ARCH}.ociarchive"
|
pkgs="build/${IMAGE}-${DISTRO}-${ARCH}/packages-current.txt"
|
||||||
./release.sh "${IMAGE}" "${DISTRO}" "${buildid}" "${oci}"
|
./release.sh "${IMAGE}" "${DISTRO}" "${buildid}" "${pkgs}"
|
||||||
|
|||||||
@@ -198,4 +198,11 @@ fi
|
|||||||
"${MANIFEST}" \
|
"${MANIFEST}" \
|
||||||
"${OCI_ARCHIVE}"
|
"${OCI_ARCHIVE}"
|
||||||
|
|
||||||
|
# The finalize.d hook records the installed package list next to the treefile.
|
||||||
|
manifest_dir="$(dirname "${MANIFEST}")"
|
||||||
|
if [[ -f "${manifest_dir}/packages-current.txt" ]]; then
|
||||||
|
cp "${manifest_dir}/packages-current.txt" "${BUILD_DIR}/packages-current.txt"
|
||||||
|
echo "Package list: ${BUILD_DIR}/packages-current.txt"
|
||||||
|
fi
|
||||||
|
|
||||||
echo "Built: ${OCI_ARCHIVE}"
|
echo "Built: ${OCI_ARCHIVE}"
|
||||||
|
|||||||
+12
@@ -0,0 +1,12 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
# Runs in the target root during `rpm-ostree compose image` (edition 2024
|
||||||
|
# finalize.d hook). Records the installed package list next to the treefile so
|
||||||
|
# build.sh can hand it to release.sh without having to mount the built image.
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
if [[ -z "${RPMOSTREE_WORKDIR:-}" ]]; then
|
||||||
|
echo "RPMOSTREE_WORKDIR not set, skipping package list" >&2
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
rpm -qa --root "${PWD}" --qf '%{NAME} %{EVR}\n' | sort > "${RPMOSTREE_WORKDIR}/packages-current.txt"
|
||||||
+7
-12
@@ -2,7 +2,7 @@
|
|||||||
# Generate a package changelog for a freshly built image and publish it as a
|
# Generate a package changelog for a freshly built image and publish it as a
|
||||||
# Gitea release (instead of committing JSON files under changelogs/).
|
# Gitea release (instead of committing JSON files under changelogs/).
|
||||||
#
|
#
|
||||||
# Usage: release.sh <image> <distro> <buildid> <ociarchive>
|
# Usage: release.sh <image> <distro> <buildid> <packages-file>
|
||||||
#
|
#
|
||||||
# The full package list is attached to each release as
|
# The full package list is attached to each release as
|
||||||
# packages-<image>-<distro>.txt
|
# packages-<image>-<distro>.txt
|
||||||
@@ -10,21 +10,21 @@
|
|||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
if [[ $# -lt 4 ]]; then
|
if [[ $# -lt 4 ]]; then
|
||||||
echo "Usage: $0 <image> <distro> <buildid> <ociarchive>" >&2
|
echo "Usage: $0 <image> <distro> <buildid> <packages-file>" >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
IMAGE="$1"
|
IMAGE="$1"
|
||||||
DISTRO="$2"
|
DISTRO="$2"
|
||||||
BUILDID="$3"
|
BUILDID="$3"
|
||||||
OCI_ARCHIVE="$4"
|
PACKAGES_FILE="$4"
|
||||||
|
|
||||||
GITEA_URL="${GITEA_URL:-https://git.plabble.org}"
|
GITEA_URL="${GITEA_URL:-https://git.plabble.org}"
|
||||||
GITEA_REPO="${GITEA_REPO:-Misthios/bootc-images}"
|
GITEA_REPO="${GITEA_REPO:-Misthios/bootc-images}"
|
||||||
TOKEN="${RELEASE_TOKEN:-${GITHUB_TOKEN:-}}"
|
TOKEN="${RELEASE_TOKEN:-${GITHUB_TOKEN:-}}"
|
||||||
|
|
||||||
[[ -n "${TOKEN}" ]] || { echo "RELEASE_TOKEN (or GITHUB_TOKEN) is required" >&2; exit 1; }
|
[[ -n "${TOKEN}" ]] || { echo "RELEASE_TOKEN (or GITHUB_TOKEN) is required" >&2; exit 1; }
|
||||||
[[ -f "${OCI_ARCHIVE}" ]] || { echo "Missing OCI archive: ${OCI_ARCHIVE}" >&2; exit 1; }
|
[[ -f "${PACKAGES_FILE}" ]] || { echo "Missing package list: ${PACKAGES_FILE}" >&2; exit 1; }
|
||||||
|
|
||||||
API="${GITEA_URL%/}/api/v1/repos/${GITEA_REPO}"
|
API="${GITEA_URL%/}/api/v1/repos/${GITEA_REPO}"
|
||||||
RELEASE_TAG="${IMAGE}-${DISTRO}.${BUILDID}"
|
RELEASE_TAG="${IMAGE}-${DISTRO}.${BUILDID}"
|
||||||
@@ -41,14 +41,9 @@ if curl -fsSL -H "Authorization: token ${TOKEN}" \
|
|||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# --- package list from the built image -------------------------------------
|
# --- package list from the build -------------------------------------------
|
||||||
echo "Extracting package list from ${OCI_ARCHIVE} ..."
|
echo "Using package list ${PACKAGES_FILE} ..."
|
||||||
export STORAGE_DRIVER=vfs
|
cp "${PACKAGES_FILE}" "${WORK}/packages-current.txt"
|
||||||
ctr="$(buildah from "oci-archive:${OCI_ARCHIVE}")"
|
|
||||||
mnt="$(buildah mount "${ctr}")"
|
|
||||||
rpm -qa --root "${mnt}" --qf '%{NAME} %{EVR}\n' | sort > "${WORK}/packages-current.txt"
|
|
||||||
buildah unmount "${ctr}"
|
|
||||||
buildah rm "${ctr}" >/dev/null
|
|
||||||
|
|
||||||
# --- previous package list from the last release ---------------------------
|
# --- previous package list from the last release ---------------------------
|
||||||
# Walk the release list (newest first) until we find the newest release for
|
# Walk the release list (newest first) until we find the newest release for
|
||||||
|
|||||||
Reference in New Issue
Block a user