From 970f159073c7e6e36d2fe22aa79d7554910dafcf Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 13 Dec 2022 18:19:13 +0800 Subject: [PATCH 01/23] missing-docs: add util-linux-core --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index cb44892..e19a580 100644 --- a/missing-docs +++ b/missing-docs @@ -15,3 +15,4 @@ rpm sed systemd tar +util-linux-core From 942ce219b6c21ba6bdadba5e9f234d2aea44e0c9 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 00:23:16 +0100 Subject: [PATCH 02/23] Removed deprecated com.github.debarshiray.toolbox tag https://github.com/containers/toolbox/pull/820 --- Dockerfile | 1 - 1 file changed, 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 7209890..536af5c 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,7 +2,6 @@ FROM registry.fedoraproject.org/fedora:37 ENV NAME=fedora-toolbox VERSION=37 LABEL com.github.containers.toolbox="true" \ - com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ version="$VERSION" \ From 3975aa7012138d75a4f18c393467a4a2000fa140 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 00:30:35 +0100 Subject: [PATCH 03/23] Ensure that all the glibc language packs are available ... and not just C, POSIX and C.UTF-8. https://github.com/containers/toolbox/issues/60 --- Dockerfile | 1 + 1 file changed, 1 insertion(+) diff --git a/Dockerfile b/Dockerfile index 536af5c..a1c0f93 100644 --- a/Dockerfile +++ b/Dockerfile @@ -13,6 +13,7 @@ COPY README.md / RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf RUN dnf -y swap coreutils-single coreutils-full +RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks COPY missing-docs / RUN dnf -y reinstall $( Date: Wed, 1 Feb 2023 00:32:45 +0100 Subject: [PATCH 04/23] Remove RPM configuration to strip out translations Note that this doesn't restore the translations that were stripped out from the base fedora image. It only ensures that subsequent RPM transactions retain the translations. https://github.com/containers/toolbox/issues/60 --- Dockerfile | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Dockerfile b/Dockerfile index a1c0f93..ef99f70 100644 --- a/Dockerfile +++ b/Dockerfile @@ -11,7 +11,9 @@ LABEL com.github.containers.toolbox="true" \ COPY README.md / +RUN rm /etc/rpm/macros.image-language-conf RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf + RUN dnf -y swap coreutils-single coreutils-full RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks From b9f71a8ca2b30a9466f6c544bb1d2cdc25879cb1 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 01:34:01 +0100 Subject: [PATCH 05/23] Enable OpenGL and Vulkan for hardware with free drivers https://github.com/containers/toolbox/issues/1110 --- extra-packages | 3 +++ 1 file changed, 3 insertions(+) diff --git a/extra-packages b/extra-packages index 52bf3f3..cdd2aa1 100644 --- a/extra-packages +++ b/extra-packages @@ -20,6 +20,8 @@ less lsof man-db man-pages +mesa-dri-drivers +mesa-vulkan-drivers mtr nano-default-editor nss-mdns @@ -37,6 +39,7 @@ tree unzip util-linux vte-profile +vulkan-loader wget which words From 25637f0398eaf6a4ec854253fabdfd3a7a362887 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 01:39:01 +0100 Subject: [PATCH 06/23] Ensure that the sudo(8), sudoers(5), etc. manuals are available https://github.com/containers/toolbox/pull/1068 https://github.com/containers/toolbox/pull/1133 --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index e19a580..2350648 100644 --- a/missing-docs +++ b/missing-docs @@ -13,6 +13,7 @@ pam python3 rpm sed +sudo systemd tar util-linux-core From e8aa82c64300db5391b7fda7c246a8eee3101724 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 19:53:56 +0100 Subject: [PATCH 07/23] Avoid unexpected DNF behaviour when reinstalling or swapping The RPM packages in the base 'fedora' image can be older than the those currently available in the DNF 'updates' repository [1], but at the same time newer than those available in the DNF 'fedora' repository [1]. The first part happens because the base image isn't updated as often as the individual packages, so the 'updates' repository can have newer RPMs. The second part happens because the base image does get updated after a stable Fedora has been released, and hence can have newer RPMs than the 'fedora' repository. This is complicated by the fact that packages can get pulled directly from Fedora's Koji build system into the base 'fedora' image before they make it to one of the well-known repositories like 'fedora' or 'updates' [1]. These packages are marked as having come from the koji-override-0 repository. All that combined can lead to unexpected behaviour when DNF is invoked to reinstall or swap the RPM packages in the base image. Some examples below. The base fedora:36 image contains glibc-minimal-langpack-2.35-20.fc36 that came from koji-override-0, while 'fedora' and 'updates' have glibc-all-langpacks-2.35-4.fc36 and glibc-all-langpacks-2.35-22.fc36 respectively. This leads to: STEP 8/15: RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks Last metadata expiration check: 0:00:03 ago on Wed Feb 1 12:37:04... Dependencies resolved. ====================================================================== Package Arch Version Repository ====================================================================== Installing: glibc-all-langpacks x86_64 2.35-4.fc36 fedora Removing: glibc-minimal-langpack x86_64 2.35-20.fc36 @koji-override-0 Downgrading: glibc x86_64 2.35-4.fc36 fedora glibc-common x86_64 2.35-4.fc36 fedora That's unexpected. Instead of upgrading all the glibc sub-packages to the latest version from 'updates', it's downgrading them to the older version from 'fedora'. Similarly, the base fedora:36 image has bash-5.2.9-2.fc36.x86_64 from koji-override-0, and there is bash-5.2.15-1.fc36.x86_64 in 'updates'. This leads to: STEP 10/15: RUN dnf -y reinstall $( Date: Wed, 1 Feb 2023 19:57:32 +0100 Subject: [PATCH 08/23] images: Ensure that the desired manuals are indeed present Building an OCI image leads to so much spew that it's hard to notice if something unexpected happened, and as seen in the previous commit [1], unexpected things do happen. Therefore, this adds a built-in test to ensure that the desired files are actually present in the final image. Right now it only checks the presence of some representative manuals to ensure that the packages listed in the 'missing-docs' file really do get reinstalled, and the documentation that was stripped out in the base image really does get restored. [1] Commit 6d4ecac69f5080be https://github.com/containers/toolbox/pull/1226 https://github.com/containers/toolbox/pull/1226 --- ensure-files | 7 +++++++ 1 file changed, 7 insertions(+) create mode 100644 ensure-files diff --git a/ensure-files b/ensure-files new file mode 100644 index 0000000..4d11969 --- /dev/null +++ b/ensure-files @@ -0,0 +1,7 @@ +/usr/share/man/man1/bash.1* +/usr/share/man/man1/cd.1* +/usr/share/man/man1/export.1* + +/usr/share/man/fr/man8/rpm.8* +/usr/share/man/ja/man8/rpm.8* +/usr/share/man/man8/rpm.8* From 7b443307420f3a48374c01a22556ba20d0b31a38 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 20:02:23 +0100 Subject: [PATCH 09/23] Fix up the previous commit Fallout from d6f0488665e3c7a56add516b3689516f54c04e39 --- Dockerfile | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/Dockerfile b/Dockerfile index 7b58c19..367fab2 100644 --- a/Dockerfile +++ b/Dockerfile @@ -26,4 +26,18 @@ COPY extra-packages / RUN dnf -y install $(/dev/null; then \ + echo "$file: No such file or directory" >&2; \ + ret_val=1; \ + break; \ + fi; \ + done Date: Wed, 1 Feb 2023 20:18:28 +0100 Subject: [PATCH 10/23] Ensure that the cat(1), cp(1), ls(1), etc. manuals are available https://github.com/containers/toolbox/pull/1226 --- ensure-files | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/ensure-files b/ensure-files index 4d11969..8ce26a7 100644 --- a/ensure-files +++ b/ensure-files @@ -2,6 +2,10 @@ /usr/share/man/man1/cd.1* /usr/share/man/man1/export.1* +/usr/share/man/man1/cat.1* +/usr/share/man/man1/cp.1* +/usr/share/man/man1/ls.1* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* From 45c8ab3b42c28d802c033e66e531cb8c8829e2de Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 21:59:30 +0100 Subject: [PATCH 11/23] Ensure that the kill(1), mount(8), etc. manuals are available https://github.com/containers/toolbox/pull/1227 --- ensure-files | 3 +++ 1 file changed, 3 insertions(+) diff --git a/ensure-files b/ensure-files index 8ce26a7..24b89a0 100644 --- a/ensure-files +++ b/ensure-files @@ -9,3 +9,6 @@ /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* + +/usr/share/man/man1/kill.1* +/usr/share/man/man8/mount.8* From 9d0a3c9213e91314832785bdc2c958130fd4722f Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 2 Feb 2023 18:33:23 +0100 Subject: [PATCH 12/23] Use the package name instead of a virtual Provides for gnupg2 The package for GnuPG 2.0 has always been called gnupg2 [1], so this must have been a mistake. [1] https://pagure.io/fedora-comps/blob/main/f/comps-f21.xml.in https://github.com/containers/toolbox/pull/1228 --- extra-packages | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extra-packages b/extra-packages index cdd2aa1..14c9028 100644 --- a/extra-packages +++ b/extra-packages @@ -7,7 +7,7 @@ findutils flatpak-spawn fpaste git -gnupg +gnupg2 gnupg2-smime gvfs-client hostname From 61a2b0e5c1d74b181f00cc17b8acb6a11ed8dfdd Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 2 Feb 2023 18:52:02 +0100 Subject: [PATCH 13/23] Ensure that the gpg2(1), gnupg2(7), etc. manuals are available It turns out that at least since Fedora 30 [1], the gnupg2 package has been part of the fedora base image, because it's required by the dnf package: dnf -> python3-dnf -> python3-libdnf -> libdnf -> gpgme -> gnupg2 Hence, the need to restore the gnupg2 documentation that was stripped out in the base image. [1] It's difficult to find out if the gnupg2 package wasn't part of the fedora base image before Fedora 30, because those images are no longer available from registry.fedoraproject.org. https://github.com/containers/toolbox/pull/1228 --- ensure-files | 3 +++ missing-docs | 1 + 2 files changed, 4 insertions(+) diff --git a/ensure-files b/ensure-files index 24b89a0..9693d36 100644 --- a/ensure-files +++ b/ensure-files @@ -6,6 +6,9 @@ /usr/share/man/man1/cp.1* /usr/share/man/man1/ls.1* +/usr/share/man/man1/gpg2.1* +/usr/share/man/man7/gnupg2.7* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* diff --git a/missing-docs b/missing-docs index 2350648..b06fdc3 100644 --- a/missing-docs +++ b/missing-docs @@ -4,6 +4,7 @@ coreutils-common curl findutils gawk +gnupg2 grep gzip libcap From 9bb785561e14d2bcb7c9d6b297b1b06e77f3356b Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 2 Feb 2023 20:54:30 +0100 Subject: [PATCH 14/23] Replace jwhois with whois Since Fedora 37, the whois package has replaced jwhois as the default whois(1) implementation [1] on Fedora Silverblue and Workstation. [1] fedora-comps commit e4bf2706306c219a https://pagure.io/fedora-comps/c/e4bf2706306c219a https://pagure.io/fedora-comps/pull-request/729 https://fedoraproject.org/wiki/Changes/Replace_jwhois_with_whois_in_Fedora_Workstation https://github.com/containers/toolbox/pull/1228 --- extra-packages | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extra-packages b/extra-packages index 14c9028..f6cf387 100644 --- a/extra-packages +++ b/extra-packages @@ -13,7 +13,7 @@ gvfs-client hostname iproute iputils -jwhois +whois keyutils krb5-libs less From 52d2c5031d716f8b2cc1239822255d43d67a12aa Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Mar 2023 13:14:23 +0100 Subject: [PATCH 15/23] Synchronize with upstream --- README.md | 162 ++++++++---------------------------------------------- 1 file changed, 24 insertions(+), 138 deletions(-) diff --git a/README.md b/README.md index 117528e..6f9943b 100644 --- a/README.md +++ b/README.md @@ -1,7 +1,13 @@ -[Toolbox](https://github.com/containers/toolbox) is a tool for Linux operating -systems, which allows the use of containerized command line environments. It is -built on top of [Podman](https://podman.io/) and other standard container -technologies from [OCI](https://opencontainers.org/). +[Toolbox](https://containertoolbx.org/) is a tool for Linux, which allows the +use of interactive command line environments for development and +troubleshooting the host operating system, without having to install software +on the host. It is built on top of [Podman](https://podman.io/) and other +standard container technologies from [OCI](https://opencontainers.org/). + +Toolbox environments have seamless access to the user's home directory, +the Wayland and X11 sockets, networking (including Avahi), removable devices +(like USB sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the +udev database, etc.. This is particularly useful on [OSTree](https://ostree.readthedocs.io/en/latest/) based operating systems like @@ -10,12 +16,12 @@ This is particularly useful on systems is to discourage installation of software on the host, and instead install software as (or in) containers — they mostly don't even have package managers like DNF or YUM. This makes it difficult to set up a development -environment or install tools for debugging in the usual way. +environment or troubleshoot the operating system in the usual way. Toolbox solves this problem by providing a fully mutable container within -which one can install their favourite development and debugging tools, editors -and SDKs. For example, it's possible to do `yum install ansible` without -affecting the base operating system. +which one can install their favourite development and troubleshooting tools, +editors and SDKs. For example, it's possible to do `yum install ansible` +without affecting the base operating system. However, this tool doesn't *require* using an OSTree based system. It works equally well on Fedora Workstation and Server, and that's a useful way to @@ -23,136 +29,16 @@ incrementally adopt containerization. The toolbox environment is based on an [OCI](https://www.opencontainers.org/) image. On Fedora this is the `fedora-toolbox` image. This image is used to -create a toolbox container that seamlessly integrates with the rest of the -operating system by providing access to the user's home directory, the Wayland -and X11 sockets, networking (including Avahi), removable devices (like USB -sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the udev -database, etc.. +create a toolbox container that offers the interactive command line +environment. + +Note that Toolbox makes no promise about security beyond what's already +available in the usual command line environment on the host that everybody is +familiar with. -## Installation +## Installation & Use -Toolbox is installed by default on Fedora Silverblue. On other operating -systems it's just a matter of installing the `toolbox` package. - -## Usage - -### Create your toolbox container: -```console -[user@hostname ~]$ toolbox create -Created container: fedora-toolbox-33 -Enter with: toolbox enter -[user@hostname ~]$ -``` -This will create a container called `fedora-toolbox-`. - -### Enter the toolbox: -```console -[user@hostname ~]$ toolbox enter -⬢[user@toolbox ~]$ -``` - -### Remove a toolbox container: -```console -[user@hostname ~]$ toolbox rm fedora-toolbox-33 -[user@hostname ~]$ -``` - -## Dependencies and Building - -Toolbox requires at least Podman 1.4.0 to work, and uses the Meson build -system. - -The following dependencies are required to build it: -- meson -- go-md2man -- systemd -- go -- ninja - -The following dependencies enable various optional features: -- bash-completion - -It can be built and installed as any other typical Meson-based project: -```console -[user@hostname toolbox]$ meson -Dprofile_dir=/etc/profile.d builddir -[user@hostname toolbox]$ ninja -C builddir -[user@hostname toolbox]$ sudo ninja -C builddir install -``` - -Toolbox is written in Go. Consult the -[src/go.mod](https://github.com/containers/toolbox/blob/main/src/go.mod) file -for a full list of all the Go dependencies. - -By default, Toolbox uses Go modules and all the required Go packages are -automatically downloaded as part of the build. There's no need to worry about -the Go dependencies, unless the build environment doesn't have network access -or any such peculiarities. - -## Distro support - -By default, Toolbox creates the container using an -[OCI](https://www.opencontainers.org/) image called -`-toolbox:`, where `` and `` are taken from the -host's `/usr/lib/os-release`. For example, the default image on a Fedora 33 -host would be `fedora-toolbox:33`. - -This default can be overridden by the `--image` option in `toolbox create`, -but operating system distributors should provide an adequately configured -default image to ensure a smooth user experience. - -## Image requirements - -Toolbox customizes newly created containers in a certain way. This requires -certain tools and paths to be present and have certain characteristics inside -the OCI image. - -Tools: -* `getent(1)` -* `id(1)` -* `ln(1)` -* `mkdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` -* `passwd(1)` -* `readlink(1)` -* `rm(1)` -* `rmdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` -* `sleep(1)` -* `test(1)` -* `touch(1)` -* `unlink(1)` -* `useradd(8)` -* `usermod(8)` - -Paths: -* `/etc/host.conf`: optional, if present not a bind mount -* `/etc/hosts`: optional, if present not a bind mount -* `/etc/krb5.conf.d`: directory, not a bind mount -* `/etc/localtime`: optional, if present not a bind mount -* `/etc/machine-id`: optional, not a bind mount -* `/etc/resolv.conf`: optional, if present not a bind mount -* `/etc/timezone`: optional, if present not a bind mount - -Toolbox enables `sudo(8)` access inside containers. The following is necessary -for that to work: - -* The image should have `sudo(8)` enabled for users belonging to either the - `sudo` or `wheel` groups, and the group itself should exist. File an - [issue](https://github.com/containers/toolbox/issues/new) if you really need - support for a different group. However, it's preferable to keep this list as - short as possible. - -* The image should allow empty passwords for `sudo(8)`. This can be achieved - by either adding the `nullok` option to the `PAM(8)` configuration, or by - add the `NOPASSWD` tag to the `sudoers(5)` configuration. - -Since Toolbox only works with OCI images that fulfill certain requirements, -it will refuse images that aren't tagged with -`com.github.containers.toolbox="true"` and -`com.github.debarshiray.toolbox="true"` labels. These labels are meant to be -used by the maintainer of the image to indicate that they have read this -document and tested that the image works with Toolbox. You can use the -following snippet in a Dockerfile for this: -```Dockerfile -LABEL com.github.containers.toolbox="true" \ - com.github.debarshiray.toolbox="true" -``` +See our guides on +[installing & getting started](https://containertoolbx.org/install/) with +Toolbox and [Linux distro support](https://containertoolbx.org/distros/). From b69c902becd44dfa0d8c41edf198165bc9a81d70 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Timoth=C3=A9e=20Ravier?= Date: Thu, 16 Feb 2023 17:35:15 +0100 Subject: [PATCH 16/23] Use ARG instead of ENV to avoid leaking variables We only need those temporary variables for the container build and for the LABELS. We do not want to set those specific environment variables for the container environment itself. Using ARG instead of ENV lets us do that. See: https://github.com/containers/toolbox/issues/188 See: https://github.com/containers/docs/pull/15 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 367fab2..be41926 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ FROM registry.fedoraproject.org/fedora:37 -ENV NAME=fedora-toolbox VERSION=37 +ARG NAME=fedora-toolbox VERSION=37 LABEL com.github.containers.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ From e2528d6088afad4529fead0bcad4a009b9a105c7 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Mar 2023 12:42:54 +0100 Subject: [PATCH 17/23] Attempt to fix the use of ARG ... because the image failed to build with: Error in plugin orchestrate_build: {"x86_64": {"docker_api": "ARG requires exactly one argument"}, "aarch64": {"docker_api": "Dockerfile parse error line 4: ARG requires exactly one argument"}}. Fallout from b69c902becd44dfa0d8c41edf198165bc9a81d70 --- Dockerfile | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index be41926..a58be5b 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,7 @@ FROM registry.fedoraproject.org/fedora:37 -ARG NAME=fedora-toolbox VERSION=37 +ARG NAME=fedora-toolbox +ARG VERSION=37 LABEL com.github.containers.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ From 1d9b907b34824fce69f78e8d47789444f1330276 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Mon, 9 Oct 2023 15:25:19 +0200 Subject: [PATCH 18/23] Reorder alphabetically Fallout from 9bb785561e14d2bcb7c9d6b297b1b06e77f3356b https://github.com/containers/toolbox/pull/1384 --- extra-packages | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extra-packages b/extra-packages index f6cf387..a85268f 100644 --- a/extra-packages +++ b/extra-packages @@ -13,7 +13,6 @@ gvfs-client hostname iproute iputils -whois keyutils krb5-libs less @@ -42,6 +41,7 @@ vte-profile vulkan-loader wget which +whois words xorg-x11-xauth xz From 71730c30c9e0a91bcc2d5143f447a6092b68f91c Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Mon, 9 Oct 2023 15:27:01 +0200 Subject: [PATCH 19/23] Ensure that the manuals from extra-packages are available Until now, only the packages that are present in the fedora base image, and had their documentation stripped out, were being tested for the availability of documentation. There were no tests for the extra packages that get added to the base image to form the fedora-toolbox image. The util-linux and xz packages were picked as examples for these new tests. The xz package is a particularly good example because it has translations for its manuals. It can help test that the fedora-toolbox image is localized just like Fedora Silverblue and Workstation. https://github.com/containers/toolbox/pull/1384 --- ensure-files | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/ensure-files b/ensure-files index 9693d36..851baaa 100644 --- a/ensure-files +++ b/ensure-files @@ -13,5 +13,13 @@ /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* +/usr/share/man/man1/cal.1.* +/usr/share/man/man1/getopt.1* +/usr/share/man/man1/hexdump.1* + /usr/share/man/man1/kill.1* /usr/share/man/man8/mount.8* + +/usr/share/man/fr/man1/xz.1* +/usr/share/man/ko/man1/xz.1* +/usr/share/man/man1/xz.1* From dcf9a87d2b66f09eacdbc772745ab6936fbc1d6b Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Fri, 20 Oct 2023 12:08:59 +0200 Subject: [PATCH 20/23] Add psmisc It's currently being pulled in as a dependency of iproute. However, since it's explicitly mentioned in the list of default packages on Fedora Silverblue and Workstation [1], it should be mentioned here too. The psmisc package marks the translations for its manuals with %lang(). Therefore, it's a very good example for testing that the fedora-toolbox image is localized just like Fedora Silverblue and Workstation. This is unlike the xz package, whose translations for manuals were added to the tests recently [2]. The xz package doesn't mark its translated manuals with %lang() [3], which means that they are going to get installed regardless of whether RPM has been configured to not install localization files or not. eg., through the %_install_langs macro. So, they aren't a good candidate for the tests until this is fixed. No need to issue a build just for this. [1] fedora-comps commit e4ed54dfcc497fd0 https://pagure.io/fedora-comps/c/e4ed54dfcc497fd0 https://pagure.io/fedora-comps/pull-request/379 [2] Toolbx commit 20188a097a1a7a16 https://github.com/containers/toolbox/commit/20188a097a1a7a16 https://github.com/containers/toolbox/pull/1384 [3] https://src.fedoraproject.org/rpms/xz/pull-request/10 https://github.com/containers/toolbox/pull/1390 --- ensure-files | 4 ++++ extra-packages | 1 + 2 files changed, 5 insertions(+) diff --git a/ensure-files b/ensure-files index 851baaa..1450f58 100644 --- a/ensure-files +++ b/ensure-files @@ -9,6 +9,10 @@ /usr/share/man/man1/gpg2.1* /usr/share/man/man7/gnupg2.7* +/usr/share/man/fr/man1/pstree.1* +/usr/share/man/ko/man1/pstree.1* +/usr/share/man/man1/pstree.1* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* diff --git a/extra-packages b/extra-packages index a85268f..f07bf58 100644 --- a/extra-packages +++ b/extra-packages @@ -28,6 +28,7 @@ openssh-clients passwd pigz procps-ng +psmisc rsync shadow-utils sudo From 2d768d5d1502000d84099470ef58d304bb140d66 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Fri, 27 Oct 2023 20:03:27 +0200 Subject: [PATCH 21/23] Unbreak the tests The Korean translations for the psmisc manuals were only added in psmisc 23.6 [1], while Fedora 37 has psmisc 23.4. This led to: STEP 16/20: RUN rm /extra-packages STEP 17/20: COPY ensure-files / STEP 18/20: RUN ret_val=0; while read file; do if ! compgen ... /usr/share/man/ko/man1/pstree.1*: No such file or directory Error: building at STEP "RUN ret_val=0; while read file; do...": while running runtime: exit status 1 Fallout from dcf9a87d2b66f09eacdbc772745ab6936fbc1d6b [1] psmisc commit 3098e641dc1ddb21 https://gitlab.com/psmisc/psmisc/-/commit/3098e641dc1ddb21 [2] https://src.fedoraproject.org/rpms/psmisc/tree/f37 --- ensure-files | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ensure-files b/ensure-files index 1450f58..2b3c957 100644 --- a/ensure-files +++ b/ensure-files @@ -10,7 +10,7 @@ /usr/share/man/man7/gnupg2.7* /usr/share/man/fr/man1/pstree.1* -/usr/share/man/ko/man1/pstree.1* +/usr/share/man/ru/man1/pstree.1* /usr/share/man/man1/pstree.1* /usr/share/man/fr/man8/rpm.8* From 11899d50419f26141a046e8c83e72dd4b11ccf4a Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Fri, 27 Oct 2023 20:24:24 +0200 Subject: [PATCH 22/23] Ensure that the useradd(8), etc. manuals are available The shadow-utils package has always been part of the fedora base image. It's explicitly listed in extra-packages as a safeguard against losing useradd(8) and usermod(8) by mistake because they are needed by the entry point of a Toolbx container [1]. Hence, the need to restore the shadow-utils documentation that was stripped out in the base image. [1] Toolbx commit c6772f0f112e8004 https://github.com/containers/toolbox/commit/c6772f0f112e8004 https://github.com/containers/toolbox/pull/1394 --- ensure-files | 4 ++++ missing-docs | 1 + 2 files changed, 5 insertions(+) diff --git a/ensure-files b/ensure-files index 2b3c957..a9a5425 100644 --- a/ensure-files +++ b/ensure-files @@ -17,6 +17,10 @@ /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* +/usr/share/man/fr/man8/useradd.8* +/usr/share/man/ja/man8/useradd.8* +/usr/share/man/man8/useradd.8* + /usr/share/man/man1/cal.1.* /usr/share/man/man1/getopt.1* /usr/share/man/man1/hexdump.1* diff --git a/missing-docs b/missing-docs index b06fdc3..887d9ba 100644 --- a/missing-docs +++ b/missing-docs @@ -14,6 +14,7 @@ pam python3 rpm sed +shadow-utils sudo systemd tar From 00d6b6920377d66bc338888db469a8e73b30819d Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Nov 2023 15:23:43 +0100 Subject: [PATCH 23/23] Ensure that documentation and translations are present This should finally ensure that the fedora-toolbox image doesn't have any package that had its content, such as documentation or translations, stripped out by the fedora base image. Until now, missing-docs had a hand-maintained list of packages that had their content stripped out by the fedora base image. These packages are reinstalled when building the fedora-toolbox image to restore the lost content. Unfortunately, this list was incomplete because it was only updated when someone noticed that something is missing. Now, the list is generated with: $ rpm --all --query --state --queryformat "PACKAGE: %{NAME}\n" ... to ensure that it's always complete. The existing built-in test to ensure that the desired files are actually present in the final image was extended to cover some of those that were absent. A new built-in test, based on the above rpm(1) command, was added as a fallback to ensure that the final image doesn't have any package with missing content. As suggested by Brian Campbell. https://github.com/containers/toolbox/issues/603 --- Dockerfile | 10 ++++++++ ensure-files | 13 ++++++++++ missing-docs | 70 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 3 files changed, 93 insertions(+) diff --git a/Dockerfile b/Dockerfile index a58be5b..f7c57bd 100644 --- a/Dockerfile +++ b/Dockerfile @@ -41,4 +41,14 @@ RUN ret_val=0; \ fi RUN rm /ensure-files +RUN broken_packages="$(rpm --all --query --state --queryformat "PACKAGE: %{NAME}\n" \ + | sed --quiet --regexp-extended '/PACKAGE: /{s/PACKAGE: // ; h ; b }; /^not installed/ { g; p }' \ + | uniq \ + | sort)"; \ + if [ "$broken_packages" != "" ]; then \ + echo "Packages with missing files:" >&2; \ + echo "$broken_packages" >&2; \ + false; \ + fi + RUN dnf clean all diff --git a/ensure-files b/ensure-files index a9a5425..b9227a9 100644 --- a/ensure-files +++ b/ensure-files @@ -6,13 +6,26 @@ /usr/share/man/man1/cp.1* /usr/share/man/man1/ls.1* +/usr/share/man/man8/dnf.8* +/usr/share/man/man5/dnf.conf.5* + +/usr/share/locale/de/LC_MESSAGES/elfutils.mo +/usr/share/locale/ja/LC_MESSAGES/elfutils.mo + /usr/share/man/man1/gpg2.1* /usr/share/man/man7/gnupg2.7* +/usr/share/info/nettle.info* + +/usr/share/locale/fr/LC_MESSAGES/popt.mo +/usr/share/locale/ja/LC_MESSAGES/popt.mo + /usr/share/man/fr/man1/pstree.1* /usr/share/man/ru/man1/pstree.1* /usr/share/man/man1/pstree.1* +/usr/share/info/history.info* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* diff --git a/missing-docs b/missing-docs index 887d9ba..f7b041b 100644 --- a/missing-docs +++ b/missing-docs @@ -1,21 +1,91 @@ acl +alternatives +audit-libs +authselect +authselect-libs bash +ca-certificates coreutils-common +cracklib +crypto-policies curl +cyrus-sasl-lib +dnf +dnf-data +elfutils-libelf +expat +file-libs +filesystem findutils gawk +glib2 +gmp gnupg2 +gnutls +gpgme grep gzip +ima-evm-utils +keyutils-libs +krb5-libs +libarchive +libassuan +libblkid libcap +libcap-ng +libdb +libdnf +libeconf +libevent +libffi +libgcrypt +libgomp +libgpg-error +libidn2 +libksba +libmodulemd +libpwquality +librepo +libsemanage +libsigsegv +libsolv +libssh +libtasn1 +libtirpc +libunistring +libverto +libxcrypt +libxml2 +libyaml +lz4-libs +mpfr +ncurses-base +nettle +openldap openssl p11-kit pam +pcre +pcre2-syntax +popt python3 +python3-gpg +python3-libs +python3-rpm +readline rpm sed +setup shadow-utils +sqlite-libs sudo systemd +systemd-libs tar +tpm2-tss +tzdata util-linux-core +vim-minimal +yum +zchunk-libs +zlib