From 384327a6cf4c2ea2b798dc839070108305f75c03 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Mon, 2 Sep 2019 16:25:56 +0800 Subject: [PATCH 01/60] Bump version to 32 for master --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 00a3caa..cc5b79e 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ -FROM registry.fedoraproject.org/fedora:31 +FROM registry.fedoraproject.org/fedora:32 -ENV NAME=fedora-toolbox VERSION=31 +ENV NAME=fedora-toolbox VERSION=32 LABEL com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ name="$FGC/$NAME" \ From a2171d8742b18b65e22119bf789871b97f000455 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Mon, 2 Sep 2019 17:50:22 +0800 Subject: [PATCH 02/60] base image no longer uses coreutils-single https://github.com/fedora-cloud/docker-brew-fedora/issues/58 --- Dockerfile | 1 - 1 file changed, 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index cc5b79e..ccbee63 100644 --- a/Dockerfile +++ b/Dockerfile @@ -12,7 +12,6 @@ LABEL com.github.debarshiray.toolbox="true" \ COPY README.md / RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf -RUN dnf -y swap coreutils-single coreutils-full COPY missing-docs / RUN dnf -y reinstall $( Date: Tue, 24 Sep 2019 20:10:54 +0200 Subject: [PATCH 03/60] Avoid losing useradd(8) by accident The shadow-utils package was added to the base toolbox images to ensure the presence of the useradd(8) command. Currently the package is already pulled in by various dependencies. Therefore, it doesn't increase the size of the base image, but serves as a safeguard against any inadvertent changes. --- extra-packages | 1 + 1 file changed, 1 insertion(+) diff --git a/extra-packages b/extra-packages index d48965e..c998b3f 100644 --- a/extra-packages +++ b/extra-packages @@ -24,6 +24,7 @@ passwd pigz procps-ng rsync +shadow-utils sudo tcpdump time From 7a9383999ef6e648adc517bcb630bd005cce2afb Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Tue, 24 Sep 2019 21:05:43 +0200 Subject: [PATCH 04/60] Install only flatpak-spawn, not the rest of flatpak-xdg-utils https://github.com/debarshiray/toolbox/issues/147 --- extra-packages | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extra-packages b/extra-packages index c998b3f..b37c946 100644 --- a/extra-packages +++ b/extra-packages @@ -3,7 +3,7 @@ bzip2 diffutils dnf-plugins-core findutils -flatpak-xdg-utils +flatpak-spawn fpaste git gnupg From fccc0ad0cfa9f41a932d088ccbd53f4778ebe464 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 10 Oct 2019 16:02:22 +0200 Subject: [PATCH 05/60] Update the label for tagging to reflect the project's new home https://github.com/containers/toolbox/pull/293 --- Dockerfile | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index ccbee63..6252478 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,8 @@ FROM registry.fedoraproject.org/fedora:32 ENV NAME=fedora-toolbox VERSION=32 -LABEL com.github.debarshiray.toolbox="true" \ +LABEL com.github.containers.toolbox="true" \ + com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ name="$FGC/$NAME" \ version="$VERSION" \ From 7b8140e7255d54e38242fb442105367b4ac3a436 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Fri, 21 Feb 2020 22:49:31 +0800 Subject: [PATCH 06/60] bump version to 33 for master --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 6252478..2a296f2 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ -FROM registry.fedoraproject.org/fedora:32 +FROM registry.fedoraproject.org/fedora:33 -ENV NAME=fedora-toolbox VERSION=32 +ENV NAME=fedora-toolbox VERSION=33 LABEL com.github.containers.toolbox="true" \ com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ From c4524abdf274465f3aa89cd69c858dba4fc2eae8 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Fri, 28 Feb 2020 10:17:46 +0800 Subject: [PATCH 07/60] try removing uninstalled packages from missing-docs (error 143) atomic_reactor.util - Package chkconfig available, but not installed. atomic_reactor.util - No match for argument: chkconfig atomic_reactor.util - Package dbus-daemon available, but not installed. atomic_reactor.util - No match for argument: dbus-daemon atomic_reactor.util - Package rpm-plugin-systemd-inhibit available, but not installed. atomic_reactor.util - No match for argument: rpm-plugin-systemd-inhibit : : atomic_reactor.util - DEBUG - Running scriptlet: gawk-5.0.1-7.fc32.x86_64 38/38 atomic_reactor.util - DEBUG - Removing intermediate container a533251cf472 atomic_reactor.util - ERROR - {'errorDetail': {'code': 143, 'message': "The command '/bin/sh -c dnf -y reinstall $( Date: Sat, 11 Apr 2020 10:59:09 +0800 Subject: [PATCH 08/60] drop mlocate: https://github.com/containers/toolbox/issues/391 --- extra-packages | 1 - 1 file changed, 1 deletion(-) diff --git a/extra-packages b/extra-packages index b37c946..05763f6 100644 --- a/extra-packages +++ b/extra-packages @@ -17,7 +17,6 @@ less lsof man-db man-pages -mlocate mtr openssh-clients passwd From f552b51ec2ff429f1cb3da1a0eb8c61c6e57af95 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 26 May 2020 11:49:20 +0800 Subject: [PATCH 09/60] no need to explicitly list krb5-libs --- extra-packages | 1 - 1 file changed, 1 deletion(-) diff --git a/extra-packages b/extra-packages index 05763f6..462d177 100644 --- a/extra-packages +++ b/extra-packages @@ -12,7 +12,6 @@ hostname iputils jwhois keyutils -krb5-libs less lsof man-db From f064121de56bbceb26f83c63fac616884147437e Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Mon, 15 Jun 2020 19:15:20 +0200 Subject: [PATCH 10/60] Revert "no need to explicitly list krb5-libs" Currently, krb5-libs is pulled in by various other packages that are already part of the fedora-toolbox OCI image. Unless someone is keeping a close eye on the contents of the image, a change in the package dependencies or the contents of the base fedora OCI image can cause krb5-libs to go missing from the fedora-toolbox image. This would be undesirable because toolbox(1) relies on the presence of the /etc/krb5.conf file and the /etc/krb5.conf.d directory to set up Kerberos inside a toolbox container, and those are provided by the krb5-libs package. Therefore, explicitly listing krb5-libs prevents us from accidentally losing Kerberos integration in toolbox containers, and doesn't cost us anything because it's already part of the image anyway. This reverts commit f552b51ec2ff429f1cb3da1a0eb8c61c6e57af95. --- extra-packages | 1 + 1 file changed, 1 insertion(+) diff --git a/extra-packages b/extra-packages index 462d177..05763f6 100644 --- a/extra-packages +++ b/extra-packages @@ -12,6 +12,7 @@ hostname iputils jwhois keyutils +krb5-libs less lsof man-db From d8b3e6baac54c3419abd4ef008672e9fc0c97b8f Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Mon, 15 Jun 2020 19:42:09 +0200 Subject: [PATCH 11/60] extra-packages: Add gvfs-client The gvfs-client package is necessary for GIO-based processes inside toolbox containers to use the GVfs backend and volume monitor daemons, and it comes preinstalled on Fedora Silverblue and Workstation. https://github.com/containers/toolbox/pull/466 --- extra-packages | 1 + 1 file changed, 1 insertion(+) diff --git a/extra-packages b/extra-packages index 05763f6..a4c839e 100644 --- a/extra-packages +++ b/extra-packages @@ -8,6 +8,7 @@ fpaste git gnupg gnupg2-smime +gvfs-client hostname iputils jwhois From e7d30ac5c1a052fe3f279338f79cde41d175faab Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Fri, 21 Aug 2020 16:26:51 +0200 Subject: [PATCH 12/60] Bump version to 34 for master --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 2a296f2..deabbea 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ -FROM registry.fedoraproject.org/fedora:33 +FROM registry.fedoraproject.org/fedora:34 -ENV NAME=fedora-toolbox VERSION=33 +ENV NAME=fedora-toolbox VERSION=34 LABEL com.github.containers.toolbox="true" \ com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ From efa6be73c3b3a653bc5645fa2593269042d2b44e Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Fri, 30 Oct 2020 19:45:38 +0100 Subject: [PATCH 13/60] extra-packages: Allow X11 clients to run as root If an X11 client is started inside a 'su -' session, then xauth(1) needs to be present so that pam_xauth.so can add a new XAUTHORITY environment variable to the 'su -' session. https://github.com/containers/toolbox/pull/572 --- extra-packages | 1 + 1 file changed, 1 insertion(+) diff --git a/extra-packages b/extra-packages index a4c839e..95ecebb 100644 --- a/extra-packages +++ b/extra-packages @@ -35,5 +35,6 @@ vte-profile wget which words +xorg-x11-xauth xz zip From 0304688fd88c2cd2f70dd30f1816f368a1676942 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Sun, 15 Nov 2020 23:25:28 +0100 Subject: [PATCH 14/60] Make locate(1) work inside toolbox containers This reverts commit bd035973c9f49a96256951f3e2ec454a0973abfd. https://github.com/containers/toolbox/issues/391 --- extra-packages | 1 + 1 file changed, 1 insertion(+) diff --git a/extra-packages b/extra-packages index 95ecebb..0597b1b 100644 --- a/extra-packages +++ b/extra-packages @@ -18,6 +18,7 @@ less lsof man-db man-pages +mlocate mtr openssh-clients passwd From f6e830047e22c7341da9e0a3f517edd0803ac037 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Sun, 15 Nov 2020 23:11:40 +0100 Subject: [PATCH 15/60] Give access to Avahi to resolve the .local mDNS domain The nss-mdns plugin for the GNU Name Service Switch (or NSS) functionality of the GNU C Library is necessary to resolve the .local mDNS domain. The plugin talks to the Avahi daemon running on the host to resolve the names. https://github.com/containers/toolbox/issues/209 --- extra-packages | 1 + 1 file changed, 1 insertion(+) diff --git a/extra-packages b/extra-packages index 0597b1b..942271c 100644 --- a/extra-packages +++ b/extra-packages @@ -20,6 +20,7 @@ man-db man-pages mlocate mtr +nss-mdns openssh-clients passwd pigz From d863edf9d7822b81f226318de2bf41698e191ba0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20M=C3=ADchal?= Date: Sun, 27 Sep 2020 23:58:37 +0200 Subject: [PATCH 16/60] Simplify image name Currently the images are named as "f/fedora-toolbox". This is troublesome for new users of toolbox (even those with some background to containers) because everywhere the image is advertised or talked about as "fedora-toolbox". This is taken care of by Toolbox CLI but has no effect on Podman itself (or any other tool capable of working with OCI images). Another pain point is in the Fedora registry[0] all "fedora-toolbox" images get a different entry for every version of Fedora. There is no single place for all "fedora-toolbox" images. With this change I propose to only use "fedora-toolbox" as the name of the container and make use of VERSION to distinguish between versions of Fedora. Currently when you go to the Fedora registry and find an entry for "fedora-toolbox" you'll see all previous images. I believe that with this change that "feature" will be lost. But I personally find that "feature" to be rather confusing because what usually a user wants the latest version of a container (I partially base this statement on the fact that most images are versioned this way; e.g. Ubuntu on Docker Hub[1]). [0] https://registry.fedoraproject.org/ [1] https://hub.docker.com/_/ubuntu --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index deabbea..3d0ef8a 100644 --- a/Dockerfile +++ b/Dockerfile @@ -4,7 +4,7 @@ ENV NAME=fedora-toolbox VERSION=34 LABEL com.github.containers.toolbox="true" \ com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ - name="$FGC/$NAME" \ + name="$NAME" \ version="$VERSION" \ usage="This image is meant to be used with the toolbox command" \ summary="Base image for creating Fedora toolbox containers" \ From 8d796028ba2e89e90eccb691a167b234cabd16d4 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Fri, 19 Feb 2021 12:07:10 +0800 Subject: [PATCH 17/60] rawhide is now Fedora 35 --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 3d0ef8a..73fc3f6 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ -FROM registry.fedoraproject.org/fedora:34 +FROM registry.fedoraproject.org/fedora:35 -ENV NAME=fedora-toolbox VERSION=34 +ENV NAME=fedora-toolbox VERSION=35 LABEL com.github.containers.toolbox="true" \ com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ From 8ad99234bdc0d0972273057a610b2e10c96508f7 Mon Sep 17 00:00:00 2001 From: Otto Urpelainen Date: Wed, 17 Feb 2021 09:34:27 +0200 Subject: [PATCH 18/60] Include the nano default editor Since Fedora 33, `nano` is the default editor[0]. It needs to be included in the fedora-toolbox image to have the standard Fedora experience inside the container. https://fedoraproject.org/wiki/Changes/UseNanoByDefault). --- extra-packages | 1 + 1 file changed, 1 insertion(+) diff --git a/extra-packages b/extra-packages index 942271c..12fe02f 100644 --- a/extra-packages +++ b/extra-packages @@ -20,6 +20,7 @@ man-db man-pages mlocate mtr +nano-default-editor nss-mdns openssh-clients passwd From 085c05199ba38d39f713ad691d6e545db0f61519 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Tue, 29 Jun 2021 16:18:47 +0200 Subject: [PATCH 19/60] Add bc and update README.md --- README.md | 165 ++++++++++++++++++++++++++++++++++++++++++------- extra-packages | 1 + 2 files changed, 142 insertions(+), 24 deletions(-) diff --git a/README.md b/README.md index a602a07..117528e 100644 --- a/README.md +++ b/README.md @@ -1,41 +1,158 @@ -# Toolbox — Unprivileged development environment - -[Toolbox](https://github.com/debarshiray/toolbox) is a tool that offers a -familiar RPM based environment for developing and debugging software that runs -fully unprivileged using [Podman](https://podman.io/). - -The toolbox container is a fully *mutable* container; when you see -`yum install ansible` for example, that's something you can do inside your -toolbox container, without affecting the base operating system. +[Toolbox](https://github.com/containers/toolbox) is a tool for Linux operating +systems, which allows the use of containerized command line environments. It is +built on top of [Podman](https://podman.io/) and other standard container +technologies from [OCI](https://opencontainers.org/). This is particularly useful on -[OSTree](https://ostree.readthedocs.io/en/latest/) based Fedora systems like -[Silverblue](https://silverblue.fedoraproject.org/). The intention of these +[OSTree](https://ostree.readthedocs.io/en/latest/) based operating systems like +[Fedora CoreOS](https://coreos.fedoraproject.org/) and +[Silverblue](https://silverblue.fedoraproject.org/). The intention of these systems is to discourage installation of software on the host, and instead -install software as (or in) containers. +install software as (or in) containers — they mostly don't even have package +managers like DNF or YUM. This makes it difficult to set up a development +environment or install tools for debugging in the usual way. -However, this tool doesn't *require* using an OSTree based system — it -works equally well if you're running e.g. existing Fedora Workstation or -Server, and that's a useful way to incrementally adopt containerization. +Toolbox solves this problem by providing a fully mutable container within +which one can install their favourite development and debugging tools, editors +and SDKs. For example, it's possible to do `yum install ansible` without +affecting the base operating system. + +However, this tool doesn't *require* using an OSTree based system. It works +equally well on Fedora Workstation and Server, and that's a useful way to +incrementally adopt containerization. The toolbox environment is based on an [OCI](https://www.opencontainers.org/) -image. On Fedora this is the `fedora-toolbox` image. This image is then -customized for the current user to create a toolbox container that seamlessly -integrates with the rest of the operating system. +image. On Fedora this is the `fedora-toolbox` image. This image is used to +create a toolbox container that seamlessly integrates with the rest of the +operating system by providing access to the user's home directory, the Wayland +and X11 sockets, networking (including Avahi), removable devices (like USB +sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the udev +database, etc.. + + +## Installation + +Toolbox is installed by default on Fedora Silverblue. On other operating +systems it's just a matter of installing the `toolbox` package. ## Usage ### Create your toolbox container: -``` +```console [user@hostname ~]$ toolbox create +Created container: fedora-toolbox-33 +Enter with: toolbox enter [user@hostname ~]$ ``` -This will create a container, and an image, called -`fedora-toolbox-:` that's specifically customised -for your host user. +This will create a container called `fedora-toolbox-`. ### Enter the toolbox: -``` +```console [user@hostname ~]$ toolbox enter -🔹[user@toolbox ~]$ +⬢[user@toolbox ~]$ +``` + +### Remove a toolbox container: +```console +[user@hostname ~]$ toolbox rm fedora-toolbox-33 +[user@hostname ~]$ +``` + +## Dependencies and Building + +Toolbox requires at least Podman 1.4.0 to work, and uses the Meson build +system. + +The following dependencies are required to build it: +- meson +- go-md2man +- systemd +- go +- ninja + +The following dependencies enable various optional features: +- bash-completion + +It can be built and installed as any other typical Meson-based project: +```console +[user@hostname toolbox]$ meson -Dprofile_dir=/etc/profile.d builddir +[user@hostname toolbox]$ ninja -C builddir +[user@hostname toolbox]$ sudo ninja -C builddir install +``` + +Toolbox is written in Go. Consult the +[src/go.mod](https://github.com/containers/toolbox/blob/main/src/go.mod) file +for a full list of all the Go dependencies. + +By default, Toolbox uses Go modules and all the required Go packages are +automatically downloaded as part of the build. There's no need to worry about +the Go dependencies, unless the build environment doesn't have network access +or any such peculiarities. + +## Distro support + +By default, Toolbox creates the container using an +[OCI](https://www.opencontainers.org/) image called +`-toolbox:`, where `` and `` are taken from the +host's `/usr/lib/os-release`. For example, the default image on a Fedora 33 +host would be `fedora-toolbox:33`. + +This default can be overridden by the `--image` option in `toolbox create`, +but operating system distributors should provide an adequately configured +default image to ensure a smooth user experience. + +## Image requirements + +Toolbox customizes newly created containers in a certain way. This requires +certain tools and paths to be present and have certain characteristics inside +the OCI image. + +Tools: +* `getent(1)` +* `id(1)` +* `ln(1)` +* `mkdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` +* `passwd(1)` +* `readlink(1)` +* `rm(1)` +* `rmdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` +* `sleep(1)` +* `test(1)` +* `touch(1)` +* `unlink(1)` +* `useradd(8)` +* `usermod(8)` + +Paths: +* `/etc/host.conf`: optional, if present not a bind mount +* `/etc/hosts`: optional, if present not a bind mount +* `/etc/krb5.conf.d`: directory, not a bind mount +* `/etc/localtime`: optional, if present not a bind mount +* `/etc/machine-id`: optional, not a bind mount +* `/etc/resolv.conf`: optional, if present not a bind mount +* `/etc/timezone`: optional, if present not a bind mount + +Toolbox enables `sudo(8)` access inside containers. The following is necessary +for that to work: + +* The image should have `sudo(8)` enabled for users belonging to either the + `sudo` or `wheel` groups, and the group itself should exist. File an + [issue](https://github.com/containers/toolbox/issues/new) if you really need + support for a different group. However, it's preferable to keep this list as + short as possible. + +* The image should allow empty passwords for `sudo(8)`. This can be achieved + by either adding the `nullok` option to the `PAM(8)` configuration, or by + add the `NOPASSWD` tag to the `sudoers(5)` configuration. + +Since Toolbox only works with OCI images that fulfill certain requirements, +it will refuse images that aren't tagged with +`com.github.containers.toolbox="true"` and +`com.github.debarshiray.toolbox="true"` labels. These labels are meant to be +used by the maintainer of the image to indicate that they have read this +document and tested that the image works with Toolbox. You can use the +following snippet in a Dockerfile for this: +```Dockerfile +LABEL com.github.containers.toolbox="true" \ + com.github.debarshiray.toolbox="true" ``` diff --git a/extra-packages b/extra-packages index 12fe02f..a639e09 100644 --- a/extra-packages +++ b/extra-packages @@ -1,4 +1,5 @@ bash-completion +bc bzip2 diffutils dnf-plugins-core From 7105bdf49ebea2227d983d5fc582537ef3e9afd2 Mon Sep 17 00:00:00 2001 From: Oliver Gutierrez Date: Tue, 29 Jun 2021 16:00:33 +0100 Subject: [PATCH 20/60] Renamed Dockerfile to Containerfile and updated README.md --- Dockerfile => Containerfile | 0 README.md | 8 ++++++++ 2 files changed, 8 insertions(+) rename Dockerfile => Containerfile (100%) diff --git a/Dockerfile b/Containerfile similarity index 100% rename from Dockerfile rename to Containerfile diff --git a/README.md b/README.md index 117528e..3d5586c 100644 --- a/README.md +++ b/README.md @@ -1,3 +1,11 @@ +Toolbox logo landscape + +[![Zuul](https://zuul-ci.org/gated.svg)](https://softwarefactory-project.io/zuul/t/local/builds?project=containers/toolbox) +[![Daily Pipeline](https://softwarefactory-project.io/zuul/api/tenant/local/badge?project=containers/toolbox&pipeline=periodic)](https://softwarefactory-project.io/zuul/t/local/builds?project=containers%2Ftoolbox&pipeline=periodic) + +[![Arch Linux package](https://img.shields.io/archlinux/v/community/x86_64/toolbox)](https://www.archlinux.org/packages/community/x86_64/toolbox/) +[![Fedora package](https://img.shields.io/fedora/v/toolbox/rawhide)](https://src.fedoraproject.org/rpms/toolbox/) + [Toolbox](https://github.com/containers/toolbox) is a tool for Linux operating systems, which allows the use of containerized command line environments. It is built on top of [Podman](https://podman.io/) and other standard container From 692c49780c6b26184c292b46ec84dc704f864693 Mon Sep 17 00:00:00 2001 From: Oliver Gutierrez Date: Tue, 29 Jun 2021 16:03:09 +0100 Subject: [PATCH 21/60] Reverted renaming of Dockerfile --- Containerfile => Dockerfile | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename Containerfile => Dockerfile (100%) diff --git a/Containerfile b/Dockerfile similarity index 100% rename from Containerfile rename to Dockerfile From 030ad6d05287143fe3a9eb4a8a709f78b4d51a9b Mon Sep 17 00:00:00 2001 From: Oliver Gutierrez Date: Tue, 29 Jun 2021 16:46:38 +0100 Subject: [PATCH 22/60] Reverted changes in README.md --- README.md | 8 -------- 1 file changed, 8 deletions(-) diff --git a/README.md b/README.md index 3d5586c..117528e 100644 --- a/README.md +++ b/README.md @@ -1,11 +1,3 @@ -Toolbox logo landscape - -[![Zuul](https://zuul-ci.org/gated.svg)](https://softwarefactory-project.io/zuul/t/local/builds?project=containers/toolbox) -[![Daily Pipeline](https://softwarefactory-project.io/zuul/api/tenant/local/badge?project=containers/toolbox&pipeline=periodic)](https://softwarefactory-project.io/zuul/t/local/builds?project=containers%2Ftoolbox&pipeline=periodic) - -[![Arch Linux package](https://img.shields.io/archlinux/v/community/x86_64/toolbox)](https://www.archlinux.org/packages/community/x86_64/toolbox/) -[![Fedora package](https://img.shields.io/fedora/v/toolbox/rawhide)](https://src.fedoraproject.org/rpms/toolbox/) - [Toolbox](https://github.com/containers/toolbox) is a tool for Linux operating systems, which allows the use of containerized command line environments. It is built on top of [Podman](https://podman.io/) and other standard container From f131a12ec5a7cbe8af101cbe14956b18ace017da Mon Sep 17 00:00:00 2001 From: Oliver Gutierrez Date: Fri, 9 Jul 2021 10:06:48 +0100 Subject: [PATCH 23/60] Added iproute package --- extra-packages | 1 + 1 file changed, 1 insertion(+) diff --git a/extra-packages b/extra-packages index a639e09..34ee156 100644 --- a/extra-packages +++ b/extra-packages @@ -11,6 +11,7 @@ gnupg gnupg2-smime gvfs-client hostname +iproute iputils jwhois keyutils From ae16371775b71c687626187aabc3ae06c67c23e7 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Thu, 12 Aug 2021 11:42:51 +0800 Subject: [PATCH 24/60] Rawhide version is now 36 --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 73fc3f6..a332d11 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ -FROM registry.fedoraproject.org/fedora:35 +FROM registry.fedoraproject.org/fedora:36 -ENV NAME=fedora-toolbox VERSION=35 +ENV NAME=fedora-toolbox VERSION=36 LABEL com.github.containers.toolbox="true" \ com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ From 98d9106a1f2f7a303cba510d00d58a8570b7438f Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Sat, 4 Sep 2021 00:35:54 +0800 Subject: [PATCH 25/60] add coreutils-common to missing docs --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index b634f27..c185ad3 100644 --- a/missing-docs +++ b/missing-docs @@ -1,5 +1,6 @@ acl bash +coreutils-common curl gawk grep From 40a5f298f9ff884a7c6b764793887b12ea08d6ff Mon Sep 17 00:00:00 2001 From: Oliver Gutierrez Date: Thu, 9 Sep 2021 11:51:43 +0100 Subject: [PATCH 26/60] Activated automatic rebuilds --- .osbs-repo-config | 3 +++ container.yaml | 3 +++ 2 files changed, 6 insertions(+) create mode 100644 .osbs-repo-config create mode 100644 container.yaml diff --git a/.osbs-repo-config b/.osbs-repo-config new file mode 100644 index 0000000..d2914e4 --- /dev/null +++ b/.osbs-repo-config @@ -0,0 +1,3 @@ +[autorebuild] +enabled = true + diff --git a/container.yaml b/container.yaml new file mode 100644 index 0000000..c19a51f --- /dev/null +++ b/container.yaml @@ -0,0 +1,3 @@ +autorebuild: + from_latest: true + ignore_isolated_builds: false From ae4a7842b4912a75eb56610695987783f1233b44 Mon Sep 17 00:00:00 2001 From: Oliver Gutierrez Date: Thu, 9 Sep 2021 12:03:31 +0100 Subject: [PATCH 27/60] Fixed autorebuild configuration --- container.yaml | 1 - 1 file changed, 1 deletion(-) diff --git a/container.yaml b/container.yaml index c19a51f..6281e92 100644 --- a/container.yaml +++ b/container.yaml @@ -1,3 +1,2 @@ autorebuild: from_latest: true - ignore_isolated_builds: false From 9057055b440c856b0c9581a39bcae90be60f0e5a Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 25 Nov 2021 19:46:14 +0100 Subject: [PATCH 28/60] Ensure that coreutils-single is replaced by coreutils-full It's true that the fedora base images no longer come with coreutils-single, but they used to, and the ubi base images still do. Therefore, it's worth being extra defensive about this. It's better to make the build system execute one extra redundant command than expose users to a bug because of a change that snuck in unnoticed. This reverts commit a2171d8742b18b65e22119bf789871b97f000455. https://github.com/containers/toolbox/pull/931 --- Dockerfile | 1 + 1 file changed, 1 insertion(+) diff --git a/Dockerfile b/Dockerfile index a332d11..4bdbe63 100644 --- a/Dockerfile +++ b/Dockerfile @@ -13,6 +13,7 @@ LABEL com.github.containers.toolbox="true" \ COPY README.md / RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf +RUN dnf -y swap coreutils-single coreutils-full COPY missing-docs / RUN dnf -y reinstall $( Date: Thu, 25 Nov 2021 19:48:38 +0100 Subject: [PATCH 29/60] extra-packages: Avoid losing mount(8) by accident The util-linux package was added to ensure the presence of the mount(8) command. Currently the package is already pulled in by various dependencies. Therefore, it doesn't increase the size of the image, but serves as a safeguard against any inadvertent changes. Note that starting from Fedora 35 onwards, the fedora base images no longer have mount(8), which increases the importance of this change. https://github.com/containers/toolbox/issues/929 --- extra-packages | 1 + 1 file changed, 1 insertion(+) diff --git a/extra-packages b/extra-packages index 34ee156..105f5b0 100644 --- a/extra-packages +++ b/extra-packages @@ -36,6 +36,7 @@ time traceroute tree unzip +util-linux vte-profile wget which From 74393208c39d2699324c12787bbc940a93c0433f Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Dec 2021 15:16:13 +0100 Subject: [PATCH 30/60] Remove misleading and redundant CMD There's no need to specify a CMD in a Toolbox image because it's specified by 'toolbox create', through 'podman create', when creating a container. A CMD was specified [1] because the Fedora Container Guidelines requires it [2]. The idea behind the guidelines is that the right thing should happen when one runs: $ podman run However, that only makes sense for images targeting single service containers. Toolbox containers and images are different - they are not meant to be used like that to run a single one-off service. Conceptually, 'running' a Toolbox container is expected to provide the user with a reasonable interactive command line experience. Arguably, that means offering something like /bin/bash, not /bin/sh. Also, note that when the CMD was introduced [1], Toolbox containers were actually created, through 'podman create', with /bin/sh as their entry points. So, it did make some sense. However, things have changed since then [3]. The entry point is now 'toolbox init-container'. It's not possible to mention it in the Toolbox image because the /usr/bin/toolbox binary isn't present in the image, and it's not meant to be present. Therefore, today, /bin/sh is simply not the right fit for a Toolbox image's CMD. A better option would be /bin/bash. Note that the fedora base images have their CMD set to /bin/bash, which is inherited by the fedora-toolbox images. So, there are two options. Either repeat the same CMD in the fedora-toolbox images and satisfy the guidelines, or take some liberties and let the CMD be inherited from the fedora base images. This commit takes the latter option. People tend to use the fedora-toolbox images as the starting point for other custom Toolbox images, sometimes for other operating system distributions. It's better to keep them minimal to avoid implying extra requirements. In this case, the CMD is an abstract concept, and the actual entry point is 'toolbox init-container' as specified by 'toolbox create'. Specifying /bin/bash might discourage people from creating custom images that are only meant to have /bin/zsh. Also, note that the current CMD was actually '/bin/sh -c /bin/sh', not /bin/sh. Unless a CMD is specified as an array of command line arguments, it's passed as a single argument to '/bin/sh -c' [4]. So, this: CMD foo bar ... is the same as: CMD [ "/bin/sh", "-c", "foo bar" ] [1] Toolbox commit 5cc2678a3677af44 https://github.com/containers/toolbox/commit/5cc2678a3677af44 [2] https://docs.fedoraproject.org/en-US/containers/guidelines/creation/ [3] Toolbox commit 8b84b5e4604921fa https://github.com/containers/toolbox/pull/160 [4] https://docs.docker.com/engine/reference/builder/#cmd https://github.com/containers/toolbox/issues/885 --- Dockerfile | 2 -- 1 file changed, 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 4bdbe63..f4b8a71 100644 --- a/Dockerfile +++ b/Dockerfile @@ -24,5 +24,3 @@ RUN dnf -y install $( Date: Wed, 1 Dec 2021 16:55:15 +0100 Subject: [PATCH 31/60] Make locate(1) opt-in by default Currently, the entry point of a Toolbox container runs updatedb(8) on start-up, which can be very I/O intensive. This might be a hindrance when troubleshooting performance problems on a host, or when re-creating containers somewhat more frequently. Users can install the mlocate RPM and restart their containers to enable locate(1). https://github.com/containers/toolbox/pull/938 --- extra-packages | 1 - 1 file changed, 1 deletion(-) diff --git a/extra-packages b/extra-packages index 105f5b0..52bf3f3 100644 --- a/extra-packages +++ b/extra-packages @@ -20,7 +20,6 @@ less lsof man-db man-pages -mlocate mtr nano-default-editor nss-mdns From 94f0cc793b5fd7b127bc0ee21bf7312e3b797482 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Fri, 11 Feb 2022 11:07:52 +0800 Subject: [PATCH 32/60] bump fedora version to 37 --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index f4b8a71..7209890 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ -FROM registry.fedoraproject.org/fedora:36 +FROM registry.fedoraproject.org/fedora:37 -ENV NAME=fedora-toolbox VERSION=36 +ENV NAME=fedora-toolbox VERSION=37 LABEL com.github.containers.toolbox="true" \ com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ From 77bce0df24c214bb74ca4280b1ee559ae9435abd Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 8 Mar 2022 15:25:53 +0800 Subject: [PATCH 33/60] try removing autorebuild config to unbreak OBS build see https://pagure.io/releng/issue/10658 --- .osbs-repo-config | 3 --- container.yaml | 2 -- 2 files changed, 5 deletions(-) delete mode 100644 .osbs-repo-config delete mode 100644 container.yaml diff --git a/.osbs-repo-config b/.osbs-repo-config deleted file mode 100644 index d2914e4..0000000 --- a/.osbs-repo-config +++ /dev/null @@ -1,3 +0,0 @@ -[autorebuild] -enabled = true - diff --git a/container.yaml b/container.yaml deleted file mode 100644 index 6281e92..0000000 --- a/container.yaml +++ /dev/null @@ -1,2 +0,0 @@ -autorebuild: - from_latest: true From 64b6d607e9eb39e41503096fec593975c6a99dae Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 9 Aug 2022 14:24:49 +0800 Subject: [PATCH 34/60] findutils missing docs --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index c185ad3..cb44892 100644 --- a/missing-docs +++ b/missing-docs @@ -2,6 +2,7 @@ acl bash coreutils-common curl +findutils gawk grep gzip From 32bf967e6d08cc406c56758ee037ed4fb3b978a5 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Fri, 12 Aug 2022 15:27:43 +0800 Subject: [PATCH 35/60] bump version to 38 --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 7209890..6ae65fb 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ -FROM registry.fedoraproject.org/fedora:37 +FROM registry.fedoraproject.org/fedora:38 -ENV NAME=fedora-toolbox VERSION=37 +ENV NAME=fedora-toolbox VERSION=38 LABEL com.github.containers.toolbox="true" \ com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ From 805dc32c280b10f328f318a708814a107d71a874 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 13 Dec 2022 18:19:13 +0800 Subject: [PATCH 36/60] missing-docs: add util-linux-core --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index cb44892..e19a580 100644 --- a/missing-docs +++ b/missing-docs @@ -15,3 +15,4 @@ rpm sed systemd tar +util-linux-core From ae36f4f6794233cd2e4ccabb6f6d0bb4dcf850a8 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 00:23:16 +0100 Subject: [PATCH 37/60] Removed deprecated com.github.debarshiray.toolbox tag https://github.com/containers/toolbox/pull/820 --- Dockerfile | 1 - 1 file changed, 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 6ae65fb..76d7b6b 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,7 +2,6 @@ FROM registry.fedoraproject.org/fedora:38 ENV NAME=fedora-toolbox VERSION=38 LABEL com.github.containers.toolbox="true" \ - com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ version="$VERSION" \ From b8912160a77faf8feead9cf33dea632aa2f65e84 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 00:30:35 +0100 Subject: [PATCH 38/60] Ensure that all the glibc language packs are available ... and not just C, POSIX and C.UTF-8. https://github.com/containers/toolbox/issues/60 --- Dockerfile | 1 + 1 file changed, 1 insertion(+) diff --git a/Dockerfile b/Dockerfile index 76d7b6b..34264a6 100644 --- a/Dockerfile +++ b/Dockerfile @@ -13,6 +13,7 @@ COPY README.md / RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf RUN dnf -y swap coreutils-single coreutils-full +RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks COPY missing-docs / RUN dnf -y reinstall $( Date: Wed, 1 Feb 2023 00:32:45 +0100 Subject: [PATCH 39/60] Remove RPM configuration to strip out translations Note that this doesn't restore the translations that were stripped out from the base fedora image. It only ensures that subsequent RPM transactions retain the translations. https://github.com/containers/toolbox/issues/60 --- Dockerfile | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Dockerfile b/Dockerfile index 34264a6..3b0be36 100644 --- a/Dockerfile +++ b/Dockerfile @@ -11,7 +11,9 @@ LABEL com.github.containers.toolbox="true" \ COPY README.md / +RUN rm /etc/rpm/macros.image-language-conf RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf + RUN dnf -y swap coreutils-single coreutils-full RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks From 0168da1191f32a16fafffe7f8d6e8537df08ce57 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 01:34:01 +0100 Subject: [PATCH 40/60] Enable OpenGL and Vulkan for hardware with free drivers https://github.com/containers/toolbox/issues/1110 --- extra-packages | 3 +++ 1 file changed, 3 insertions(+) diff --git a/extra-packages b/extra-packages index 52bf3f3..cdd2aa1 100644 --- a/extra-packages +++ b/extra-packages @@ -20,6 +20,8 @@ less lsof man-db man-pages +mesa-dri-drivers +mesa-vulkan-drivers mtr nano-default-editor nss-mdns @@ -37,6 +39,7 @@ tree unzip util-linux vte-profile +vulkan-loader wget which words From e931fd05a5be0e61813a80e31f0320f2c4889801 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 01:39:01 +0100 Subject: [PATCH 41/60] Ensure that the sudo(8), sudoers(5), etc. manuals are available https://github.com/containers/toolbox/pull/1068 https://github.com/containers/toolbox/pull/1133 --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index e19a580..2350648 100644 --- a/missing-docs +++ b/missing-docs @@ -13,6 +13,7 @@ pam python3 rpm sed +sudo systemd tar util-linux-core From 6d4ecac69f5080be37febfc853bc21c373e4323a Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 19:53:56 +0100 Subject: [PATCH 42/60] Avoid unexpected DNF behaviour when reinstalling or swapping The RPM packages in the base 'fedora' image can be older than the those currently available in the DNF 'updates' repository [1], but at the same time newer than those available in the DNF 'fedora' repository [1]. The first part happens because the base image isn't updated as often as the individual packages, so the 'updates' repository can have newer RPMs. The second part happens because the base image does get updated after a stable Fedora has been released, and hence can have newer RPMs than the 'fedora' repository. This is complicated by the fact that packages can get pulled directly from Fedora's Koji build system into the base 'fedora' image before they make it to one of the well-known repositories like 'fedora' or 'updates' [1]. These packages are marked as having come from the koji-override-0 repository. All that combined can lead to unexpected behaviour when DNF is invoked to reinstall or swap the RPM packages in the base image. Some examples below. The base fedora:36 image contains glibc-minimal-langpack-2.35-20.fc36 that came from koji-override-0, while 'fedora' and 'updates' have glibc-all-langpacks-2.35-4.fc36 and glibc-all-langpacks-2.35-22.fc36 respectively. This leads to: STEP 8/15: RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks Last metadata expiration check: 0:00:03 ago on Wed Feb 1 12:37:04... Dependencies resolved. ====================================================================== Package Arch Version Repository ====================================================================== Installing: glibc-all-langpacks x86_64 2.35-4.fc36 fedora Removing: glibc-minimal-langpack x86_64 2.35-20.fc36 @koji-override-0 Downgrading: glibc x86_64 2.35-4.fc36 fedora glibc-common x86_64 2.35-4.fc36 fedora That's unexpected. Instead of upgrading all the glibc sub-packages to the latest version from 'updates', it's downgrading them to the older version from 'fedora'. Similarly, the base fedora:36 image has bash-5.2.9-2.fc36.x86_64 from koji-override-0, and there is bash-5.2.15-1.fc36.x86_64 in 'updates'. This leads to: STEP 10/15: RUN dnf -y reinstall $( Date: Wed, 1 Feb 2023 19:57:32 +0100 Subject: [PATCH 43/60] images: Ensure that the desired manuals are indeed present Building an OCI image leads to so much spew that it's hard to notice if something unexpected happened, and as seen in the previous commit [1], unexpected things do happen. Therefore, this adds a built-in test to ensure that the desired files are actually present in the final image. Right now it only checks the presence of some representative manuals to ensure that the packages listed in the 'missing-docs' file really do get reinstalled, and the documentation that was stripped out in the base image really does get restored. [1] Commit 6d4ecac69f5080be https://github.com/containers/toolbox/pull/1226 https://github.com/containers/toolbox/pull/1226 --- ensure-files | 7 +++++++ 1 file changed, 7 insertions(+) create mode 100644 ensure-files diff --git a/ensure-files b/ensure-files new file mode 100644 index 0000000..4d11969 --- /dev/null +++ b/ensure-files @@ -0,0 +1,7 @@ +/usr/share/man/man1/bash.1* +/usr/share/man/man1/cd.1* +/usr/share/man/man1/export.1* + +/usr/share/man/fr/man8/rpm.8* +/usr/share/man/ja/man8/rpm.8* +/usr/share/man/man8/rpm.8* From e8f3f03d0a61f08209ad6ca7cfadbfb5be6d9c72 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 20:02:23 +0100 Subject: [PATCH 44/60] Fix up the previous commit Fallout from d6f0488665e3c7a56add516b3689516f54c04e39 --- Dockerfile | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/Dockerfile b/Dockerfile index 5fc08ec..f0c6372 100644 --- a/Dockerfile +++ b/Dockerfile @@ -26,4 +26,18 @@ COPY extra-packages / RUN dnf -y install $(/dev/null; then \ + echo "$file: No such file or directory" >&2; \ + ret_val=1; \ + break; \ + fi; \ + done Date: Wed, 1 Feb 2023 20:18:28 +0100 Subject: [PATCH 45/60] Ensure that the cat(1), cp(1), ls(1), etc. manuals are available https://github.com/containers/toolbox/pull/1226 --- ensure-files | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/ensure-files b/ensure-files index 4d11969..8ce26a7 100644 --- a/ensure-files +++ b/ensure-files @@ -2,6 +2,10 @@ /usr/share/man/man1/cd.1* /usr/share/man/man1/export.1* +/usr/share/man/man1/cat.1* +/usr/share/man/man1/cp.1* +/usr/share/man/man1/ls.1* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* From 39f8656075aef40f40ecb3b2104468c163af6975 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 21:59:30 +0100 Subject: [PATCH 46/60] Ensure that the kill(1), mount(8), etc. manuals are available https://github.com/containers/toolbox/pull/1227 --- ensure-files | 3 +++ 1 file changed, 3 insertions(+) diff --git a/ensure-files b/ensure-files index 8ce26a7..24b89a0 100644 --- a/ensure-files +++ b/ensure-files @@ -9,3 +9,6 @@ /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* + +/usr/share/man/man1/kill.1* +/usr/share/man/man8/mount.8* From 379a48413f3f8a48984b559d407576aac8995985 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 2 Feb 2023 18:33:23 +0100 Subject: [PATCH 47/60] Use the package name instead of a virtual Provides for gnupg2 The package for GnuPG 2.0 has always been called gnupg2 [1], so this must have been a mistake. [1] https://pagure.io/fedora-comps/blob/main/f/comps-f21.xml.in https://github.com/containers/toolbox/pull/1228 --- extra-packages | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extra-packages b/extra-packages index cdd2aa1..14c9028 100644 --- a/extra-packages +++ b/extra-packages @@ -7,7 +7,7 @@ findutils flatpak-spawn fpaste git -gnupg +gnupg2 gnupg2-smime gvfs-client hostname From f661837d4d4eae121526b8606fd5b221ed8929e7 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 2 Feb 2023 18:52:02 +0100 Subject: [PATCH 48/60] Ensure that the gpg2(1), gnupg2(7), etc. manuals are available It turns out that at least since Fedora 30 [1], the gnupg2 package has been part of the fedora base image, because it's required by the dnf package: dnf -> python3-dnf -> python3-libdnf -> libdnf -> gpgme -> gnupg2 Hence, the need to restore the gnupg2 documentation that was stripped out in the base image. [1] It's difficult to find out if the gnupg2 package wasn't part of the fedora base image before Fedora 30, because those images are no longer available from registry.fedoraproject.org. https://github.com/containers/toolbox/pull/1228 --- ensure-files | 3 +++ missing-docs | 1 + 2 files changed, 4 insertions(+) diff --git a/ensure-files b/ensure-files index 24b89a0..9693d36 100644 --- a/ensure-files +++ b/ensure-files @@ -6,6 +6,9 @@ /usr/share/man/man1/cp.1* /usr/share/man/man1/ls.1* +/usr/share/man/man1/gpg2.1* +/usr/share/man/man7/gnupg2.7* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* diff --git a/missing-docs b/missing-docs index 2350648..b06fdc3 100644 --- a/missing-docs +++ b/missing-docs @@ -4,6 +4,7 @@ coreutils-common curl findutils gawk +gnupg2 grep gzip libcap From a6eb5426080ecbd528e49eb52dbf77d160de37ae Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 2 Feb 2023 20:54:30 +0100 Subject: [PATCH 49/60] Replace jwhois with whois Since Fedora 37, the whois package has replaced jwhois as the default whois(1) implementation [1] on Fedora Silverblue and Workstation. [1] fedora-comps commit e4bf2706306c219a https://pagure.io/fedora-comps/c/e4bf2706306c219a https://pagure.io/fedora-comps/pull-request/729 https://fedoraproject.org/wiki/Changes/Replace_jwhois_with_whois_in_Fedora_Workstation https://github.com/containers/toolbox/pull/1228 --- extra-packages | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extra-packages b/extra-packages index 14c9028..f6cf387 100644 --- a/extra-packages +++ b/extra-packages @@ -13,7 +13,7 @@ gvfs-client hostname iproute iputils -jwhois +whois keyutils krb5-libs less From 1d328a24ef7c828fac5b37d85e5da8d74469a5ed Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Tue, 14 Feb 2023 23:11:23 +0100 Subject: [PATCH 50/60] Synchronize with upstream --- README.md | 162 ++++++++---------------------------------------------- 1 file changed, 24 insertions(+), 138 deletions(-) diff --git a/README.md b/README.md index 117528e..6f9943b 100644 --- a/README.md +++ b/README.md @@ -1,7 +1,13 @@ -[Toolbox](https://github.com/containers/toolbox) is a tool for Linux operating -systems, which allows the use of containerized command line environments. It is -built on top of [Podman](https://podman.io/) and other standard container -technologies from [OCI](https://opencontainers.org/). +[Toolbox](https://containertoolbx.org/) is a tool for Linux, which allows the +use of interactive command line environments for development and +troubleshooting the host operating system, without having to install software +on the host. It is built on top of [Podman](https://podman.io/) and other +standard container technologies from [OCI](https://opencontainers.org/). + +Toolbox environments have seamless access to the user's home directory, +the Wayland and X11 sockets, networking (including Avahi), removable devices +(like USB sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the +udev database, etc.. This is particularly useful on [OSTree](https://ostree.readthedocs.io/en/latest/) based operating systems like @@ -10,12 +16,12 @@ This is particularly useful on systems is to discourage installation of software on the host, and instead install software as (or in) containers — they mostly don't even have package managers like DNF or YUM. This makes it difficult to set up a development -environment or install tools for debugging in the usual way. +environment or troubleshoot the operating system in the usual way. Toolbox solves this problem by providing a fully mutable container within -which one can install their favourite development and debugging tools, editors -and SDKs. For example, it's possible to do `yum install ansible` without -affecting the base operating system. +which one can install their favourite development and troubleshooting tools, +editors and SDKs. For example, it's possible to do `yum install ansible` +without affecting the base operating system. However, this tool doesn't *require* using an OSTree based system. It works equally well on Fedora Workstation and Server, and that's a useful way to @@ -23,136 +29,16 @@ incrementally adopt containerization. The toolbox environment is based on an [OCI](https://www.opencontainers.org/) image. On Fedora this is the `fedora-toolbox` image. This image is used to -create a toolbox container that seamlessly integrates with the rest of the -operating system by providing access to the user's home directory, the Wayland -and X11 sockets, networking (including Avahi), removable devices (like USB -sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the udev -database, etc.. +create a toolbox container that offers the interactive command line +environment. + +Note that Toolbox makes no promise about security beyond what's already +available in the usual command line environment on the host that everybody is +familiar with. -## Installation +## Installation & Use -Toolbox is installed by default on Fedora Silverblue. On other operating -systems it's just a matter of installing the `toolbox` package. - -## Usage - -### Create your toolbox container: -```console -[user@hostname ~]$ toolbox create -Created container: fedora-toolbox-33 -Enter with: toolbox enter -[user@hostname ~]$ -``` -This will create a container called `fedora-toolbox-`. - -### Enter the toolbox: -```console -[user@hostname ~]$ toolbox enter -⬢[user@toolbox ~]$ -``` - -### Remove a toolbox container: -```console -[user@hostname ~]$ toolbox rm fedora-toolbox-33 -[user@hostname ~]$ -``` - -## Dependencies and Building - -Toolbox requires at least Podman 1.4.0 to work, and uses the Meson build -system. - -The following dependencies are required to build it: -- meson -- go-md2man -- systemd -- go -- ninja - -The following dependencies enable various optional features: -- bash-completion - -It can be built and installed as any other typical Meson-based project: -```console -[user@hostname toolbox]$ meson -Dprofile_dir=/etc/profile.d builddir -[user@hostname toolbox]$ ninja -C builddir -[user@hostname toolbox]$ sudo ninja -C builddir install -``` - -Toolbox is written in Go. Consult the -[src/go.mod](https://github.com/containers/toolbox/blob/main/src/go.mod) file -for a full list of all the Go dependencies. - -By default, Toolbox uses Go modules and all the required Go packages are -automatically downloaded as part of the build. There's no need to worry about -the Go dependencies, unless the build environment doesn't have network access -or any such peculiarities. - -## Distro support - -By default, Toolbox creates the container using an -[OCI](https://www.opencontainers.org/) image called -`-toolbox:`, where `` and `` are taken from the -host's `/usr/lib/os-release`. For example, the default image on a Fedora 33 -host would be `fedora-toolbox:33`. - -This default can be overridden by the `--image` option in `toolbox create`, -but operating system distributors should provide an adequately configured -default image to ensure a smooth user experience. - -## Image requirements - -Toolbox customizes newly created containers in a certain way. This requires -certain tools and paths to be present and have certain characteristics inside -the OCI image. - -Tools: -* `getent(1)` -* `id(1)` -* `ln(1)` -* `mkdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` -* `passwd(1)` -* `readlink(1)` -* `rm(1)` -* `rmdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` -* `sleep(1)` -* `test(1)` -* `touch(1)` -* `unlink(1)` -* `useradd(8)` -* `usermod(8)` - -Paths: -* `/etc/host.conf`: optional, if present not a bind mount -* `/etc/hosts`: optional, if present not a bind mount -* `/etc/krb5.conf.d`: directory, not a bind mount -* `/etc/localtime`: optional, if present not a bind mount -* `/etc/machine-id`: optional, not a bind mount -* `/etc/resolv.conf`: optional, if present not a bind mount -* `/etc/timezone`: optional, if present not a bind mount - -Toolbox enables `sudo(8)` access inside containers. The following is necessary -for that to work: - -* The image should have `sudo(8)` enabled for users belonging to either the - `sudo` or `wheel` groups, and the group itself should exist. File an - [issue](https://github.com/containers/toolbox/issues/new) if you really need - support for a different group. However, it's preferable to keep this list as - short as possible. - -* The image should allow empty passwords for `sudo(8)`. This can be achieved - by either adding the `nullok` option to the `PAM(8)` configuration, or by - add the `NOPASSWD` tag to the `sudoers(5)` configuration. - -Since Toolbox only works with OCI images that fulfill certain requirements, -it will refuse images that aren't tagged with -`com.github.containers.toolbox="true"` and -`com.github.debarshiray.toolbox="true"` labels. These labels are meant to be -used by the maintainer of the image to indicate that they have read this -document and tested that the image works with Toolbox. You can use the -following snippet in a Dockerfile for this: -```Dockerfile -LABEL com.github.containers.toolbox="true" \ - com.github.debarshiray.toolbox="true" -``` +See our guides on +[installing & getting started](https://containertoolbx.org/install/) with +Toolbox and [Linux distro support](https://containertoolbx.org/distros/). From e0813a6d6f7627cbe1ebb15c239d5495e27c5fcd Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Tue, 14 Feb 2023 23:15:51 +0100 Subject: [PATCH 51/60] Bump version to 39 for rawhide --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index f0c6372..0646c48 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ -FROM registry.fedoraproject.org/fedora:38 +FROM registry.fedoraproject.org/fedora:39 -ENV NAME=fedora-toolbox VERSION=38 +ENV NAME=fedora-toolbox VERSION=39 LABEL com.github.containers.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ From 77bb135f27016cc370effb13271666415435f16a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Timoth=C3=A9e=20Ravier?= Date: Thu, 16 Feb 2023 17:35:15 +0100 Subject: [PATCH 52/60] Use ARG instead of ENV to avoid leaking variables We only need those temporary variables for the container build and for the LABELS. We do not want to set those specific environment variables for the container environment itself. Using ARG instead of ENV lets us do that. See: https://github.com/containers/toolbox/issues/188 See: https://github.com/containers/docs/pull/15 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 0646c48..c598741 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ FROM registry.fedoraproject.org/fedora:39 -ENV NAME=fedora-toolbox VERSION=39 +ARG NAME=fedora-toolbox VERSION=39 LABEL com.github.containers.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ From dfa4cee9046b6f6f08a56f81d097b9ca1a066833 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Mar 2023 12:42:54 +0100 Subject: [PATCH 53/60] Attempt to fix the use of ARG ... because the image failed to build with: Error in plugin orchestrate_build: {"x86_64": {"docker_api": "ARG requires exactly one argument"}, "aarch64": {"docker_api": "Dockerfile parse error line 4: ARG requires exactly one argument"}}. Fallout from 77bb135f27016cc370effb13271666415435f16a --- Dockerfile | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index c598741..b4d45b3 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,7 @@ FROM registry.fedoraproject.org/fedora:39 -ARG NAME=fedora-toolbox VERSION=39 +ARG NAME=fedora-toolbox +ARG VERSION=39 LABEL com.github.containers.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ From 3c5e37aee9257ddde05bf483922c95ac9afdfd5f Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Mon, 9 Oct 2023 15:32:05 +0200 Subject: [PATCH 54/60] Reorder alphabetically Note that the fedora-toolbox OCI image for Fedora 39 onwards is no longer built using OpenShift Build Service from the Dockerfile here. It's now being built using Image Factory from fedora-kickstarts and pungi-fedora [1], as part of the ToolbxReleaseBlocker Change [2] for Fedora 39. Hence this is only for the sake of completeness. Fallout from a6eb5426080ecbd528e49eb52dbf77d160de37ae [1] https://pagure.io/fedora-kickstarts/ https://pagure.io/pungi-fedora/ [2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker https://github.com/containers/toolbox/pull/1384 --- extra-packages | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extra-packages b/extra-packages index f6cf387..a85268f 100644 --- a/extra-packages +++ b/extra-packages @@ -13,7 +13,6 @@ gvfs-client hostname iproute iputils -whois keyutils krb5-libs less @@ -42,6 +41,7 @@ vte-profile vulkan-loader wget which +whois words xorg-x11-xauth xz From 00dfa04654591f26e3d48f857eec48ed35ec9bfb Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Mon, 9 Oct 2023 15:27:01 +0200 Subject: [PATCH 55/60] Ensure that the manuals from extra-packages are available Until now, only the packages that are present in the fedora base image, and had their documentation stripped out, were being tested for the availability of documentation. There were no tests for the extra packages that get added to the base image to form the fedora-toolbox image. The util-linux and xz packages were picked as examples for these new tests. The xz package is a particularly good example because it has translations for its manuals. It can help test that the fedora-toolbox image is localized just like Fedora Silverblue and Workstation. Note that the fedora-toolbox OCI image for Fedora 39 onwards is no longer built using OpenShift Build Service from the Dockerfile here. It's now being built using Image Factory from fedora-kickstarts and pungi-fedora [1], as part of the ToolbxReleaseBlocker Change [2] for Fedora 39. Hence this is only for the sake of completeness. [1] https://pagure.io/fedora-kickstarts/ https://pagure.io/pungi-fedora/ [2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker https://github.com/containers/toolbox/pull/1384 --- ensure-files | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/ensure-files b/ensure-files index 9693d36..851baaa 100644 --- a/ensure-files +++ b/ensure-files @@ -13,5 +13,13 @@ /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* +/usr/share/man/man1/cal.1.* +/usr/share/man/man1/getopt.1* +/usr/share/man/man1/hexdump.1* + /usr/share/man/man1/kill.1* /usr/share/man/man8/mount.8* + +/usr/share/man/fr/man1/xz.1* +/usr/share/man/ko/man1/xz.1* +/usr/share/man/man1/xz.1* From 396de4320908225e8664b36576e8f475e61cd27d Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Fri, 20 Oct 2023 12:08:59 +0200 Subject: [PATCH 56/60] Add psmisc It's currently being pulled in as a dependency of iproute. However, since it's explicitly mentioned in the list of default packages on Fedora Silverblue and Workstation [1], it should be mentioned here too. The psmisc package marks the translations for its manuals with %lang(). Therefore, it's a very good example for testing that the fedora-toolbox image is localized just like Fedora Silverblue and Workstation. This is unlike the xz package, whose translations for manuals were added to the tests recently [2]. The xz package doesn't mark its translated manuals with %lang() [3], which means that they are going to get installed regardless of whether RPM has been configured to not install localization files or not. eg., through the %_install_langs macro. So, they aren't a good candidate for the tests until this is fixed. Note that the fedora-toolbox OCI image for Fedora 39 onwards is no longer built using OpenShift Build Service from the Dockerfile here. It's now being built using Image Factory from fedora-kickstarts and pungi-fedora [4], as part of the ToolbxReleaseBlocker Change [5] for Fedora 39. Hence this is only for the sake of completeness. [1] fedora-comps commit e4ed54dfcc497fd0 https://pagure.io/fedora-comps/c/e4ed54dfcc497fd0 https://pagure.io/fedora-comps/pull-request/379 [2] Toolbx commit 20188a097a1a7a16 https://github.com/containers/toolbox/commit/20188a097a1a7a16 https://github.com/containers/toolbox/pull/1384 [3] https://src.fedoraproject.org/rpms/xz/pull-request/10 [4] https://pagure.io/fedora-kickstarts/ https://pagure.io/pungi-fedora/ [5] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker https://github.com/containers/toolbox/pull/1390 --- ensure-files | 4 ++++ extra-packages | 1 + 2 files changed, 5 insertions(+) diff --git a/ensure-files b/ensure-files index 851baaa..1450f58 100644 --- a/ensure-files +++ b/ensure-files @@ -9,6 +9,10 @@ /usr/share/man/man1/gpg2.1* /usr/share/man/man7/gnupg2.7* +/usr/share/man/fr/man1/pstree.1* +/usr/share/man/ko/man1/pstree.1* +/usr/share/man/man1/pstree.1* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* diff --git a/extra-packages b/extra-packages index a85268f..f07bf58 100644 --- a/extra-packages +++ b/extra-packages @@ -28,6 +28,7 @@ openssh-clients passwd pigz procps-ng +psmisc rsync shadow-utils sudo From 04b26152ae1ab3eaaef6db085b4de220bac83afe Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Fri, 27 Oct 2023 20:13:27 +0200 Subject: [PATCH 57/60] Update the tests The translations for the RPM manuals were removed upstream during the RPM 4.19 development cycle [1]. So, replace them with rpm2cpio(8), which is another popular command shipped by the rpm package. Note that the fedora-toolbox OCI image for Fedora 39 onwards is no longer built using OpenShift Build Service from the Dockerfile here. It's now being built using Image Factory from fedora-kickstarts and pungi-fedora [2], as part of the ToolbxReleaseBlocker Change [3] for Fedora 39. [1] RPM commit 4df74a9644b18136 https://github.com/rpm-software-management/rpm/commit/4df74a9644b18136 https://github.com/rpm-software-management/rpm/pull/2245 [2] https://pagure.io/fedora-kickstarts/ https://pagure.io/pungi-fedora/ [3] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker https://github.com/containers/toolbox/pull/1391 --- ensure-files | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/ensure-files b/ensure-files index 1450f58..f5266f5 100644 --- a/ensure-files +++ b/ensure-files @@ -13,9 +13,8 @@ /usr/share/man/ko/man1/pstree.1* /usr/share/man/man1/pstree.1* -/usr/share/man/fr/man8/rpm.8* -/usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* +/usr/share/man/man8/rpm2cpio.8* /usr/share/man/man1/cal.1.* /usr/share/man/man1/getopt.1* From 5ff7fd359738f4b163adbbb3afb2825dad222cce Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Fri, 27 Oct 2023 20:24:24 +0200 Subject: [PATCH 58/60] Ensure that the useradd(8), etc. manuals are available The shadow-utils package has always been part of the fedora base image. It's explicitly listed in extra-packages as a safeguard against losing useradd(8) and usermod(8) by mistake because they are needed by the entry point of a Toolbx container [1]. Hence, the need to restore the shadow-utils documentation that was stripped out in the base image. Note that the fedora-toolbox OCI image for Fedora 39 onwards is no longer built using OpenShift Build Service from the Dockerfile here. It's now being built using Image Factory from fedora-kickstarts and pungi-fedora [2], as part of the ToolbxReleaseBlocker Change [3] for Fedora 39. Hence this is only for the sake of completeness. [1] Toolbx commit c6772f0f112e8004 https://github.com/containers/toolbox/commit/c6772f0f112e8004 [2] https://pagure.io/fedora-kickstarts/ https://pagure.io/pungi-fedora/ [3] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker https://github.com/containers/toolbox/pull/1394 --- ensure-files | 4 ++++ missing-docs | 1 + 2 files changed, 5 insertions(+) diff --git a/ensure-files b/ensure-files index f5266f5..69457a5 100644 --- a/ensure-files +++ b/ensure-files @@ -16,6 +16,10 @@ /usr/share/man/man8/rpm.8* /usr/share/man/man8/rpm2cpio.8* +/usr/share/man/fr/man8/useradd.8* +/usr/share/man/ja/man8/useradd.8* +/usr/share/man/man8/useradd.8* + /usr/share/man/man1/cal.1.* /usr/share/man/man1/getopt.1* /usr/share/man/man1/hexdump.1* diff --git a/missing-docs b/missing-docs index b06fdc3..887d9ba 100644 --- a/missing-docs +++ b/missing-docs @@ -14,6 +14,7 @@ pam python3 rpm sed +shadow-utils sudo systemd tar From 6c46178bbba38bec985bca4d45664a8b469052bb Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Nov 2023 15:23:43 +0100 Subject: [PATCH 59/60] Ensure that documentation and translations are present This should finally ensure that the fedora-toolbox image doesn't have any package that had its content, such as documentation or translations, stripped out by the fedora base image. Until now, missing-docs had a hand-maintained list of packages that had their content stripped out by the fedora base image. These packages are reinstalled when building the fedora-toolbox image to restore the lost content. Unfortunately, this list was incomplete because it was only updated when someone noticed that something is missing. Now, the list is generated with: $ rpm --all --query --state --queryformat "PACKAGE: %{NAME}\n" ... to ensure that it's always complete. The existing built-in test to ensure that the desired files are actually present in the final image was extended to cover some of those that were absent. A new built-in test, based on the above rpm(1) command, was added as a fallback to ensure that the final image doesn't have any package with missing content. As suggested by Brian Campbell. Note that the fedora-toolbox OCI image for Fedora 39 onwards is no longer built using OpenShift Build Service from the Dockerfile here. It's now being built using Image Factory from fedora-kickstarts and pungi-fedora [1], as part of the ToolbxReleaseBlocker Change [2] for Fedora 39. Hence this is only for the sake of completeness. [1] https://pagure.io/fedora-kickstarts/ https://pagure.io/pungi-fedora/ [2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker https://github.com/containers/toolbox/issues/603 --- Dockerfile | 10 ++++++++ ensure-files | 13 ++++++++++ missing-docs | 69 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 3 files changed, 92 insertions(+) diff --git a/Dockerfile b/Dockerfile index b4d45b3..771edc2 100644 --- a/Dockerfile +++ b/Dockerfile @@ -41,4 +41,14 @@ RUN ret_val=0; \ fi RUN rm /ensure-files +RUN broken_packages="$(rpm --all --query --state --queryformat "PACKAGE: %{NAME}\n" \ + | sed --quiet --regexp-extended '/PACKAGE: /{s/PACKAGE: // ; h ; b }; /^not installed/ { g; p }' \ + | uniq \ + | sort)"; \ + if [ "$broken_packages" != "" ]; then \ + echo "Packages with missing files:" >&2; \ + echo "$broken_packages" >&2; \ + false; \ + fi + RUN dnf clean all diff --git a/ensure-files b/ensure-files index 69457a5..1e39f69 100644 --- a/ensure-files +++ b/ensure-files @@ -6,13 +6,26 @@ /usr/share/man/man1/cp.1* /usr/share/man/man1/ls.1* +/usr/share/man/man8/dnf.8* +/usr/share/man/man5/dnf.conf.5* + +/usr/share/locale/de/LC_MESSAGES/elfutils.mo +/usr/share/locale/ja/LC_MESSAGES/elfutils.mo + /usr/share/man/man1/gpg2.1* /usr/share/man/man7/gnupg2.7* +/usr/share/info/nettle.info* + +/usr/share/locale/fr/LC_MESSAGES/popt.mo +/usr/share/locale/ja/LC_MESSAGES/popt.mo + /usr/share/man/fr/man1/pstree.1* /usr/share/man/ko/man1/pstree.1* /usr/share/man/man1/pstree.1* +/usr/share/info/history.info* + /usr/share/man/man8/rpm.8* /usr/share/man/man8/rpm2cpio.8* diff --git a/missing-docs b/missing-docs index 887d9ba..98f1395 100644 --- a/missing-docs +++ b/missing-docs @@ -1,21 +1,90 @@ acl +alternatives +audit-libs +authselect +authselect-libs bash +ca-certificates coreutils-common +cracklib +crypto-policies curl +cyrus-sasl-lib +dnf +dnf-data +elfutils-libelf +expat +file-libs +filesystem findutils gawk +glib2 +gmp gnupg2 +gnutls grep gzip +ima-evm-utils +keyutils-libs +krb5-libs +libarchive +libassuan +libblkid libcap +libcap-ng +libcomps +libdb +libdnf +libeconf +libevent +libffi +libgcrypt +libgomp +libgpg-error +libidn2 +libksba +libmodulemd +libpwquality +librepo +libsemanage +libsigsegv +libsolv +libssh +libtasn1 +libtirpc +libunistring +libverto +libxcrypt +libxml2 +libyaml +lz4-libs +mpfr +ncurses-base +nettle +openldap openssl p11-kit pam +pcre2-syntax +popt python3 +python3-libs +python3-rpm +readline rpm +rpm-sequoia sed +setup shadow-utils +sqlite-libs sudo systemd +systemd-libs tar +tpm2-tss +tzdata util-linux-core +vim-minimal +yum +zchunk-libs +zlib From 8930a119688067cc6037334817456acfae7651ca Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Fri, 8 Dec 2023 00:13:24 +0100 Subject: [PATCH 60/60] Retire --- Dockerfile | 54 ------------------------------ README.md | 44 ------------------------ dead.container | 9 +++++ ensure-files | 45 ------------------------- extra-packages | 49 --------------------------- missing-docs | 90 -------------------------------------------------- 6 files changed, 9 insertions(+), 282 deletions(-) delete mode 100644 Dockerfile delete mode 100644 README.md create mode 100644 dead.container delete mode 100644 ensure-files delete mode 100644 extra-packages delete mode 100644 missing-docs diff --git a/Dockerfile b/Dockerfile deleted file mode 100644 index 771edc2..0000000 --- a/Dockerfile +++ /dev/null @@ -1,54 +0,0 @@ -FROM registry.fedoraproject.org/fedora:39 - -ARG NAME=fedora-toolbox -ARG VERSION=39 -LABEL com.github.containers.toolbox="true" \ - com.redhat.component="$NAME" \ - name="$NAME" \ - version="$VERSION" \ - usage="This image is meant to be used with the toolbox command" \ - summary="Base image for creating Fedora toolbox containers" \ - maintainer="Debarshi Ray " - -COPY README.md / - -RUN rm /etc/rpm/macros.image-language-conf -RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf - -RUN dnf -y upgrade -RUN dnf -y swap coreutils-single coreutils-full -RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks - -COPY missing-docs / -RUN dnf -y reinstall $(/dev/null; then \ - echo "$file: No such file or directory" >&2; \ - ret_val=1; \ - break; \ - fi; \ - done &2; \ - echo "$broken_packages" >&2; \ - false; \ - fi - -RUN dnf clean all diff --git a/README.md b/README.md deleted file mode 100644 index 6f9943b..0000000 --- a/README.md +++ /dev/null @@ -1,44 +0,0 @@ -[Toolbox](https://containertoolbx.org/) is a tool for Linux, which allows the -use of interactive command line environments for development and -troubleshooting the host operating system, without having to install software -on the host. It is built on top of [Podman](https://podman.io/) and other -standard container technologies from [OCI](https://opencontainers.org/). - -Toolbox environments have seamless access to the user's home directory, -the Wayland and X11 sockets, networking (including Avahi), removable devices -(like USB sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the -udev database, etc.. - -This is particularly useful on -[OSTree](https://ostree.readthedocs.io/en/latest/) based operating systems like -[Fedora CoreOS](https://coreos.fedoraproject.org/) and -[Silverblue](https://silverblue.fedoraproject.org/). The intention of these -systems is to discourage installation of software on the host, and instead -install software as (or in) containers — they mostly don't even have package -managers like DNF or YUM. This makes it difficult to set up a development -environment or troubleshoot the operating system in the usual way. - -Toolbox solves this problem by providing a fully mutable container within -which one can install their favourite development and troubleshooting tools, -editors and SDKs. For example, it's possible to do `yum install ansible` -without affecting the base operating system. - -However, this tool doesn't *require* using an OSTree based system. It works -equally well on Fedora Workstation and Server, and that's a useful way to -incrementally adopt containerization. - -The toolbox environment is based on an [OCI](https://www.opencontainers.org/) -image. On Fedora this is the `fedora-toolbox` image. This image is used to -create a toolbox container that offers the interactive command line -environment. - -Note that Toolbox makes no promise about security beyond what's already -available in the usual command line environment on the host that everybody is -familiar with. - - -## Installation & Use - -See our guides on -[installing & getting started](https://containertoolbx.org/install/) with -Toolbox and [Linux distro support](https://containertoolbx.org/distros/). diff --git a/dead.container b/dead.container new file mode 100644 index 0000000..ac43a2a --- /dev/null +++ b/dead.container @@ -0,0 +1,9 @@ +The fedora-toolbox OCI image for Fedora 39 onwards is no longer built using +OpenShift Build Service from the Dockerfile here. It's now being built using +Image Factory from fedora-kickstarts and pungi-fedora [1], as part of the +ToolbxReleaseBlocker Change [2] for Fedora 39. + +[1] https://pagure.io/fedora-kickstarts/ + https://pagure.io/pungi-fedora/ + +[2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker diff --git a/ensure-files b/ensure-files deleted file mode 100644 index 1e39f69..0000000 --- a/ensure-files +++ /dev/null @@ -1,45 +0,0 @@ -/usr/share/man/man1/bash.1* -/usr/share/man/man1/cd.1* -/usr/share/man/man1/export.1* - -/usr/share/man/man1/cat.1* -/usr/share/man/man1/cp.1* -/usr/share/man/man1/ls.1* - -/usr/share/man/man8/dnf.8* -/usr/share/man/man5/dnf.conf.5* - -/usr/share/locale/de/LC_MESSAGES/elfutils.mo -/usr/share/locale/ja/LC_MESSAGES/elfutils.mo - -/usr/share/man/man1/gpg2.1* -/usr/share/man/man7/gnupg2.7* - -/usr/share/info/nettle.info* - -/usr/share/locale/fr/LC_MESSAGES/popt.mo -/usr/share/locale/ja/LC_MESSAGES/popt.mo - -/usr/share/man/fr/man1/pstree.1* -/usr/share/man/ko/man1/pstree.1* -/usr/share/man/man1/pstree.1* - -/usr/share/info/history.info* - -/usr/share/man/man8/rpm.8* -/usr/share/man/man8/rpm2cpio.8* - -/usr/share/man/fr/man8/useradd.8* -/usr/share/man/ja/man8/useradd.8* -/usr/share/man/man8/useradd.8* - -/usr/share/man/man1/cal.1.* -/usr/share/man/man1/getopt.1* -/usr/share/man/man1/hexdump.1* - -/usr/share/man/man1/kill.1* -/usr/share/man/man8/mount.8* - -/usr/share/man/fr/man1/xz.1* -/usr/share/man/ko/man1/xz.1* -/usr/share/man/man1/xz.1* diff --git a/extra-packages b/extra-packages deleted file mode 100644 index f07bf58..0000000 --- a/extra-packages +++ /dev/null @@ -1,49 +0,0 @@ -bash-completion -bc -bzip2 -diffutils -dnf-plugins-core -findutils -flatpak-spawn -fpaste -git -gnupg2 -gnupg2-smime -gvfs-client -hostname -iproute -iputils -keyutils -krb5-libs -less -lsof -man-db -man-pages -mesa-dri-drivers -mesa-vulkan-drivers -mtr -nano-default-editor -nss-mdns -openssh-clients -passwd -pigz -procps-ng -psmisc -rsync -shadow-utils -sudo -tcpdump -time -traceroute -tree -unzip -util-linux -vte-profile -vulkan-loader -wget -which -whois -words -xorg-x11-xauth -xz -zip diff --git a/missing-docs b/missing-docs deleted file mode 100644 index 98f1395..0000000 --- a/missing-docs +++ /dev/null @@ -1,90 +0,0 @@ -acl -alternatives -audit-libs -authselect -authselect-libs -bash -ca-certificates -coreutils-common -cracklib -crypto-policies -curl -cyrus-sasl-lib -dnf -dnf-data -elfutils-libelf -expat -file-libs -filesystem -findutils -gawk -glib2 -gmp -gnupg2 -gnutls -grep -gzip -ima-evm-utils -keyutils-libs -krb5-libs -libarchive -libassuan -libblkid -libcap -libcap-ng -libcomps -libdb -libdnf -libeconf -libevent -libffi -libgcrypt -libgomp -libgpg-error -libidn2 -libksba -libmodulemd -libpwquality -librepo -libsemanage -libsigsegv -libsolv -libssh -libtasn1 -libtirpc -libunistring -libverto -libxcrypt -libxml2 -libyaml -lz4-libs -mpfr -ncurses-base -nettle -openldap -openssl -p11-kit -pam -pcre2-syntax -popt -python3 -python3-libs -python3-rpm -readline -rpm -rpm-sequoia -sed -setup -shadow-utils -sqlite-libs -sudo -systemd -systemd-libs -tar -tpm2-tss -tzdata -util-linux-core -vim-minimal -yum -zchunk-libs -zlib