From 94f0cc793b5fd7b127bc0ee21bf7312e3b797482 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Fri, 11 Feb 2022 11:07:52 +0800 Subject: [PATCH 01/47] bump fedora version to 37 --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index f4b8a71..7209890 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ -FROM registry.fedoraproject.org/fedora:36 +FROM registry.fedoraproject.org/fedora:37 -ENV NAME=fedora-toolbox VERSION=36 +ENV NAME=fedora-toolbox VERSION=37 LABEL com.github.containers.toolbox="true" \ com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ From 77bce0df24c214bb74ca4280b1ee559ae9435abd Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 8 Mar 2022 15:25:53 +0800 Subject: [PATCH 02/47] try removing autorebuild config to unbreak OBS build see https://pagure.io/releng/issue/10658 --- .osbs-repo-config | 3 --- container.yaml | 2 -- 2 files changed, 5 deletions(-) delete mode 100644 .osbs-repo-config delete mode 100644 container.yaml diff --git a/.osbs-repo-config b/.osbs-repo-config deleted file mode 100644 index d2914e4..0000000 --- a/.osbs-repo-config +++ /dev/null @@ -1,3 +0,0 @@ -[autorebuild] -enabled = true - diff --git a/container.yaml b/container.yaml deleted file mode 100644 index 6281e92..0000000 --- a/container.yaml +++ /dev/null @@ -1,2 +0,0 @@ -autorebuild: - from_latest: true From 8859dc0fc7e7d605dc5555b17f28e0656f4cd846 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 8 Mar 2022 15:33:41 +0800 Subject: [PATCH 03/47] remove autorebuild config to unbreak koji OBS build see https://pagure.io/releng/issue/10658 --- .osbs-repo-config | 3 --- container.yaml | 2 -- 2 files changed, 5 deletions(-) delete mode 100644 .osbs-repo-config delete mode 100644 container.yaml diff --git a/.osbs-repo-config b/.osbs-repo-config deleted file mode 100644 index d2914e4..0000000 --- a/.osbs-repo-config +++ /dev/null @@ -1,3 +0,0 @@ -[autorebuild] -enabled = true - diff --git a/container.yaml b/container.yaml deleted file mode 100644 index 6281e92..0000000 --- a/container.yaml +++ /dev/null @@ -1,2 +0,0 @@ -autorebuild: - from_latest: true From 64b6d607e9eb39e41503096fec593975c6a99dae Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 9 Aug 2022 14:24:49 +0800 Subject: [PATCH 04/47] findutils missing docs --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index c185ad3..cb44892 100644 --- a/missing-docs +++ b/missing-docs @@ -2,6 +2,7 @@ acl bash coreutils-common curl +findutils gawk grep gzip From af1edb81ec6267c21f98368c5b290687bc9f238f Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 9 Aug 2022 14:26:33 +0800 Subject: [PATCH 05/47] findutils missing docs --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index c185ad3..cb44892 100644 --- a/missing-docs +++ b/missing-docs @@ -2,6 +2,7 @@ acl bash coreutils-common curl +findutils gawk grep gzip From 32bf967e6d08cc406c56758ee037ed4fb3b978a5 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Fri, 12 Aug 2022 15:27:43 +0800 Subject: [PATCH 06/47] bump version to 38 --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 7209890..6ae65fb 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ -FROM registry.fedoraproject.org/fedora:37 +FROM registry.fedoraproject.org/fedora:38 -ENV NAME=fedora-toolbox VERSION=37 +ENV NAME=fedora-toolbox VERSION=38 LABEL com.github.containers.toolbox="true" \ com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ From 805dc32c280b10f328f318a708814a107d71a874 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 13 Dec 2022 18:19:13 +0800 Subject: [PATCH 07/47] missing-docs: add util-linux-core --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index cb44892..e19a580 100644 --- a/missing-docs +++ b/missing-docs @@ -15,3 +15,4 @@ rpm sed systemd tar +util-linux-core From 85ef0e9bbe9dd01add5df994db711785715dad89 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 13 Dec 2022 18:19:13 +0800 Subject: [PATCH 08/47] missing-docs: add util-linux-core --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index cb44892..e19a580 100644 --- a/missing-docs +++ b/missing-docs @@ -15,3 +15,4 @@ rpm sed systemd tar +util-linux-core From ae36f4f6794233cd2e4ccabb6f6d0bb4dcf850a8 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 00:23:16 +0100 Subject: [PATCH 09/47] Removed deprecated com.github.debarshiray.toolbox tag https://github.com/containers/toolbox/pull/820 --- Dockerfile | 1 - 1 file changed, 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 6ae65fb..76d7b6b 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,7 +2,6 @@ FROM registry.fedoraproject.org/fedora:38 ENV NAME=fedora-toolbox VERSION=38 LABEL com.github.containers.toolbox="true" \ - com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ version="$VERSION" \ From b8912160a77faf8feead9cf33dea632aa2f65e84 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 00:30:35 +0100 Subject: [PATCH 10/47] Ensure that all the glibc language packs are available ... and not just C, POSIX and C.UTF-8. https://github.com/containers/toolbox/issues/60 --- Dockerfile | 1 + 1 file changed, 1 insertion(+) diff --git a/Dockerfile b/Dockerfile index 76d7b6b..34264a6 100644 --- a/Dockerfile +++ b/Dockerfile @@ -13,6 +13,7 @@ COPY README.md / RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf RUN dnf -y swap coreutils-single coreutils-full +RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks COPY missing-docs / RUN dnf -y reinstall $( Date: Wed, 1 Feb 2023 00:32:45 +0100 Subject: [PATCH 11/47] Remove RPM configuration to strip out translations Note that this doesn't restore the translations that were stripped out from the base fedora image. It only ensures that subsequent RPM transactions retain the translations. https://github.com/containers/toolbox/issues/60 --- Dockerfile | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Dockerfile b/Dockerfile index 34264a6..3b0be36 100644 --- a/Dockerfile +++ b/Dockerfile @@ -11,7 +11,9 @@ LABEL com.github.containers.toolbox="true" \ COPY README.md / +RUN rm /etc/rpm/macros.image-language-conf RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf + RUN dnf -y swap coreutils-single coreutils-full RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks From 0168da1191f32a16fafffe7f8d6e8537df08ce57 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 01:34:01 +0100 Subject: [PATCH 12/47] Enable OpenGL and Vulkan for hardware with free drivers https://github.com/containers/toolbox/issues/1110 --- extra-packages | 3 +++ 1 file changed, 3 insertions(+) diff --git a/extra-packages b/extra-packages index 52bf3f3..cdd2aa1 100644 --- a/extra-packages +++ b/extra-packages @@ -20,6 +20,8 @@ less lsof man-db man-pages +mesa-dri-drivers +mesa-vulkan-drivers mtr nano-default-editor nss-mdns @@ -37,6 +39,7 @@ tree unzip util-linux vte-profile +vulkan-loader wget which words From e931fd05a5be0e61813a80e31f0320f2c4889801 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 01:39:01 +0100 Subject: [PATCH 13/47] Ensure that the sudo(8), sudoers(5), etc. manuals are available https://github.com/containers/toolbox/pull/1068 https://github.com/containers/toolbox/pull/1133 --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index e19a580..2350648 100644 --- a/missing-docs +++ b/missing-docs @@ -13,6 +13,7 @@ pam python3 rpm sed +sudo systemd tar util-linux-core From 6d4ecac69f5080be37febfc853bc21c373e4323a Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 19:53:56 +0100 Subject: [PATCH 14/47] Avoid unexpected DNF behaviour when reinstalling or swapping The RPM packages in the base 'fedora' image can be older than the those currently available in the DNF 'updates' repository [1], but at the same time newer than those available in the DNF 'fedora' repository [1]. The first part happens because the base image isn't updated as often as the individual packages, so the 'updates' repository can have newer RPMs. The second part happens because the base image does get updated after a stable Fedora has been released, and hence can have newer RPMs than the 'fedora' repository. This is complicated by the fact that packages can get pulled directly from Fedora's Koji build system into the base 'fedora' image before they make it to one of the well-known repositories like 'fedora' or 'updates' [1]. These packages are marked as having come from the koji-override-0 repository. All that combined can lead to unexpected behaviour when DNF is invoked to reinstall or swap the RPM packages in the base image. Some examples below. The base fedora:36 image contains glibc-minimal-langpack-2.35-20.fc36 that came from koji-override-0, while 'fedora' and 'updates' have glibc-all-langpacks-2.35-4.fc36 and glibc-all-langpacks-2.35-22.fc36 respectively. This leads to: STEP 8/15: RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks Last metadata expiration check: 0:00:03 ago on Wed Feb 1 12:37:04... Dependencies resolved. ====================================================================== Package Arch Version Repository ====================================================================== Installing: glibc-all-langpacks x86_64 2.35-4.fc36 fedora Removing: glibc-minimal-langpack x86_64 2.35-20.fc36 @koji-override-0 Downgrading: glibc x86_64 2.35-4.fc36 fedora glibc-common x86_64 2.35-4.fc36 fedora That's unexpected. Instead of upgrading all the glibc sub-packages to the latest version from 'updates', it's downgrading them to the older version from 'fedora'. Similarly, the base fedora:36 image has bash-5.2.9-2.fc36.x86_64 from koji-override-0, and there is bash-5.2.15-1.fc36.x86_64 in 'updates'. This leads to: STEP 10/15: RUN dnf -y reinstall $( Date: Wed, 1 Feb 2023 19:57:32 +0100 Subject: [PATCH 15/47] images: Ensure that the desired manuals are indeed present Building an OCI image leads to so much spew that it's hard to notice if something unexpected happened, and as seen in the previous commit [1], unexpected things do happen. Therefore, this adds a built-in test to ensure that the desired files are actually present in the final image. Right now it only checks the presence of some representative manuals to ensure that the packages listed in the 'missing-docs' file really do get reinstalled, and the documentation that was stripped out in the base image really does get restored. [1] Commit 6d4ecac69f5080be https://github.com/containers/toolbox/pull/1226 https://github.com/containers/toolbox/pull/1226 --- ensure-files | 7 +++++++ 1 file changed, 7 insertions(+) create mode 100644 ensure-files diff --git a/ensure-files b/ensure-files new file mode 100644 index 0000000..4d11969 --- /dev/null +++ b/ensure-files @@ -0,0 +1,7 @@ +/usr/share/man/man1/bash.1* +/usr/share/man/man1/cd.1* +/usr/share/man/man1/export.1* + +/usr/share/man/fr/man8/rpm.8* +/usr/share/man/ja/man8/rpm.8* +/usr/share/man/man8/rpm.8* From e8f3f03d0a61f08209ad6ca7cfadbfb5be6d9c72 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 20:02:23 +0100 Subject: [PATCH 16/47] Fix up the previous commit Fallout from d6f0488665e3c7a56add516b3689516f54c04e39 --- Dockerfile | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/Dockerfile b/Dockerfile index 5fc08ec..f0c6372 100644 --- a/Dockerfile +++ b/Dockerfile @@ -26,4 +26,18 @@ COPY extra-packages / RUN dnf -y install $(/dev/null; then \ + echo "$file: No such file or directory" >&2; \ + ret_val=1; \ + break; \ + fi; \ + done Date: Wed, 1 Feb 2023 20:18:28 +0100 Subject: [PATCH 17/47] Ensure that the cat(1), cp(1), ls(1), etc. manuals are available https://github.com/containers/toolbox/pull/1226 --- ensure-files | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/ensure-files b/ensure-files index 4d11969..8ce26a7 100644 --- a/ensure-files +++ b/ensure-files @@ -2,6 +2,10 @@ /usr/share/man/man1/cd.1* /usr/share/man/man1/export.1* +/usr/share/man/man1/cat.1* +/usr/share/man/man1/cp.1* +/usr/share/man/man1/ls.1* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* From 39f8656075aef40f40ecb3b2104468c163af6975 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 21:59:30 +0100 Subject: [PATCH 18/47] Ensure that the kill(1), mount(8), etc. manuals are available https://github.com/containers/toolbox/pull/1227 --- ensure-files | 3 +++ 1 file changed, 3 insertions(+) diff --git a/ensure-files b/ensure-files index 8ce26a7..24b89a0 100644 --- a/ensure-files +++ b/ensure-files @@ -9,3 +9,6 @@ /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* + +/usr/share/man/man1/kill.1* +/usr/share/man/man8/mount.8* From 379a48413f3f8a48984b559d407576aac8995985 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 2 Feb 2023 18:33:23 +0100 Subject: [PATCH 19/47] Use the package name instead of a virtual Provides for gnupg2 The package for GnuPG 2.0 has always been called gnupg2 [1], so this must have been a mistake. [1] https://pagure.io/fedora-comps/blob/main/f/comps-f21.xml.in https://github.com/containers/toolbox/pull/1228 --- extra-packages | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extra-packages b/extra-packages index cdd2aa1..14c9028 100644 --- a/extra-packages +++ b/extra-packages @@ -7,7 +7,7 @@ findutils flatpak-spawn fpaste git -gnupg +gnupg2 gnupg2-smime gvfs-client hostname From f661837d4d4eae121526b8606fd5b221ed8929e7 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 2 Feb 2023 18:52:02 +0100 Subject: [PATCH 20/47] Ensure that the gpg2(1), gnupg2(7), etc. manuals are available It turns out that at least since Fedora 30 [1], the gnupg2 package has been part of the fedora base image, because it's required by the dnf package: dnf -> python3-dnf -> python3-libdnf -> libdnf -> gpgme -> gnupg2 Hence, the need to restore the gnupg2 documentation that was stripped out in the base image. [1] It's difficult to find out if the gnupg2 package wasn't part of the fedora base image before Fedora 30, because those images are no longer available from registry.fedoraproject.org. https://github.com/containers/toolbox/pull/1228 --- ensure-files | 3 +++ missing-docs | 1 + 2 files changed, 4 insertions(+) diff --git a/ensure-files b/ensure-files index 24b89a0..9693d36 100644 --- a/ensure-files +++ b/ensure-files @@ -6,6 +6,9 @@ /usr/share/man/man1/cp.1* /usr/share/man/man1/ls.1* +/usr/share/man/man1/gpg2.1* +/usr/share/man/man7/gnupg2.7* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* diff --git a/missing-docs b/missing-docs index 2350648..b06fdc3 100644 --- a/missing-docs +++ b/missing-docs @@ -4,6 +4,7 @@ coreutils-common curl findutils gawk +gnupg2 grep gzip libcap From 92830d16350d922e5919c245867a8f7f497780a1 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 00:23:16 +0100 Subject: [PATCH 21/47] Removed deprecated com.github.debarshiray.toolbox tag https://github.com/containers/toolbox/pull/820 --- Dockerfile | 1 - 1 file changed, 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index f4b8a71..693f8f8 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,7 +2,6 @@ FROM registry.fedoraproject.org/fedora:36 ENV NAME=fedora-toolbox VERSION=36 LABEL com.github.containers.toolbox="true" \ - com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ version="$VERSION" \ From bfcccc0943da9f5c3a107c3852c3d7b56ee161c8 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 00:30:35 +0100 Subject: [PATCH 22/47] Ensure that all the glibc language packs are available ... and not just C, POSIX and C.UTF-8. https://github.com/containers/toolbox/issues/60 --- Dockerfile | 1 + 1 file changed, 1 insertion(+) diff --git a/Dockerfile b/Dockerfile index 693f8f8..de28e43 100644 --- a/Dockerfile +++ b/Dockerfile @@ -13,6 +13,7 @@ COPY README.md / RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf RUN dnf -y swap coreutils-single coreutils-full +RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks COPY missing-docs / RUN dnf -y reinstall $( Date: Wed, 1 Feb 2023 00:32:45 +0100 Subject: [PATCH 23/47] Remove RPM configuration to strip out translations Note that this doesn't restore the translations that were stripped out from the base fedora image. It only ensures that subsequent RPM transactions retain the translations. https://github.com/containers/toolbox/issues/60 --- Dockerfile | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Dockerfile b/Dockerfile index de28e43..ba1118d 100644 --- a/Dockerfile +++ b/Dockerfile @@ -11,7 +11,9 @@ LABEL com.github.containers.toolbox="true" \ COPY README.md / +RUN rm /etc/rpm/macros.image-language-conf RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf + RUN dnf -y swap coreutils-single coreutils-full RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks From a4947a9269f6509eb49701871c958deb8cdb069f Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 01:34:01 +0100 Subject: [PATCH 24/47] Enable OpenGL and Vulkan for hardware with free drivers https://github.com/containers/toolbox/issues/1110 --- extra-packages | 3 +++ 1 file changed, 3 insertions(+) diff --git a/extra-packages b/extra-packages index 52bf3f3..cdd2aa1 100644 --- a/extra-packages +++ b/extra-packages @@ -20,6 +20,8 @@ less lsof man-db man-pages +mesa-dri-drivers +mesa-vulkan-drivers mtr nano-default-editor nss-mdns @@ -37,6 +39,7 @@ tree unzip util-linux vte-profile +vulkan-loader wget which words From 08f4699d4a2b34f5a638df85d0b296e6ee59df04 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 01:39:01 +0100 Subject: [PATCH 25/47] Ensure that the sudo(8), sudoers(5), etc. manuals are available https://github.com/containers/toolbox/pull/1068 https://github.com/containers/toolbox/pull/1133 --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index e19a580..2350648 100644 --- a/missing-docs +++ b/missing-docs @@ -13,6 +13,7 @@ pam python3 rpm sed +sudo systemd tar util-linux-core From a1d5815684a8833f773106d7407b7003e9a78b17 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 19:53:56 +0100 Subject: [PATCH 26/47] Avoid unexpected DNF behaviour when reinstalling or swapping The RPM packages in the base 'fedora' image can be older than the those currently available in the DNF 'updates' repository [1], but at the same time newer than those available in the DNF 'fedora' repository [1]. The first part happens because the base image isn't updated as often as the individual packages, so the 'updates' repository can have newer RPMs. The second part happens because the base image does get updated after a stable Fedora has been released, and hence can have newer RPMs than the 'fedora' repository. This is complicated by the fact that packages can get pulled directly from Fedora's Koji build system into the base 'fedora' image before they make it to one of the well-known repositories like 'fedora' or 'updates' [1]. These packages are marked as having come from the koji-override-0 repository. All that combined can lead to unexpected behaviour when DNF is invoked to reinstall or swap the RPM packages in the base image. Some examples below. The base fedora:36 image contains glibc-minimal-langpack-2.35-20.fc36 that came from koji-override-0, while 'fedora' and 'updates' have glibc-all-langpacks-2.35-4.fc36 and glibc-all-langpacks-2.35-22.fc36 respectively. This leads to: STEP 8/15: RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks Last metadata expiration check: 0:00:03 ago on Wed Feb 1 12:37:04... Dependencies resolved. ====================================================================== Package Arch Version Repository ====================================================================== Installing: glibc-all-langpacks x86_64 2.35-4.fc36 fedora Removing: glibc-minimal-langpack x86_64 2.35-20.fc36 @koji-override-0 Downgrading: glibc x86_64 2.35-4.fc36 fedora glibc-common x86_64 2.35-4.fc36 fedora That's unexpected. Instead of upgrading all the glibc sub-packages to the latest version from 'updates', it's downgrading them to the older version from 'fedora'. Similarly, the base fedora:36 image has bash-5.2.9-2.fc36.x86_64 from koji-override-0, and there is bash-5.2.15-1.fc36.x86_64 in 'updates'. This leads to: STEP 10/15: RUN dnf -y reinstall $( Date: Wed, 1 Feb 2023 19:57:32 +0100 Subject: [PATCH 27/47] images: Ensure that the desired manuals are indeed present Building an OCI image leads to so much spew that it's hard to notice if something unexpected happened, and as seen in the previous commit [1], unexpected things do happen. Therefore, this adds a built-in test to ensure that the desired files are actually present in the final image. Right now it only checks the presence of some representative manuals to ensure that the packages listed in the 'missing-docs' file really do get reinstalled, and the documentation that was stripped out in the base image really does get restored. [1] Commit 6d4ecac69f5080be https://github.com/containers/toolbox/pull/1226 https://github.com/containers/toolbox/pull/1226 --- ensure-files | 7 +++++++ 1 file changed, 7 insertions(+) create mode 100644 ensure-files diff --git a/ensure-files b/ensure-files new file mode 100644 index 0000000..4d11969 --- /dev/null +++ b/ensure-files @@ -0,0 +1,7 @@ +/usr/share/man/man1/bash.1* +/usr/share/man/man1/cd.1* +/usr/share/man/man1/export.1* + +/usr/share/man/fr/man8/rpm.8* +/usr/share/man/ja/man8/rpm.8* +/usr/share/man/man8/rpm.8* From 38d38e140e27140eca8e2cc412b29b88b7277f0d Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 20:02:23 +0100 Subject: [PATCH 28/47] Fix up the previous commit Fallout from d6f0488665e3c7a56add516b3689516f54c04e39 --- Dockerfile | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/Dockerfile b/Dockerfile index eaf2512..0136d83 100644 --- a/Dockerfile +++ b/Dockerfile @@ -26,4 +26,18 @@ COPY extra-packages / RUN dnf -y install $(/dev/null; then \ + echo "$file: No such file or directory" >&2; \ + ret_val=1; \ + break; \ + fi; \ + done Date: Wed, 1 Feb 2023 20:18:28 +0100 Subject: [PATCH 29/47] Ensure that the cat(1), cp(1), ls(1), etc. manuals are available https://github.com/containers/toolbox/pull/1226 --- ensure-files | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/ensure-files b/ensure-files index 4d11969..8ce26a7 100644 --- a/ensure-files +++ b/ensure-files @@ -2,6 +2,10 @@ /usr/share/man/man1/cd.1* /usr/share/man/man1/export.1* +/usr/share/man/man1/cat.1* +/usr/share/man/man1/cp.1* +/usr/share/man/man1/ls.1* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* From 63ef4ae48f98d170c16366e9b9fa34a96f203f0c Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 21:59:30 +0100 Subject: [PATCH 30/47] Ensure that the kill(1), mount(8), etc. manuals are available https://github.com/containers/toolbox/pull/1227 --- ensure-files | 3 +++ 1 file changed, 3 insertions(+) diff --git a/ensure-files b/ensure-files index 8ce26a7..24b89a0 100644 --- a/ensure-files +++ b/ensure-files @@ -9,3 +9,6 @@ /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* + +/usr/share/man/man1/kill.1* +/usr/share/man/man8/mount.8* From 1c389e3eb4fcbd21beda2950e5e066c5290b6f61 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 2 Feb 2023 18:33:23 +0100 Subject: [PATCH 31/47] Use the package name instead of a virtual Provides for gnupg2 The package for GnuPG 2.0 has always been called gnupg2 [1], so this must have been a mistake. [1] https://pagure.io/fedora-comps/blob/main/f/comps-f21.xml.in https://github.com/containers/toolbox/pull/1228 --- extra-packages | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extra-packages b/extra-packages index cdd2aa1..14c9028 100644 --- a/extra-packages +++ b/extra-packages @@ -7,7 +7,7 @@ findutils flatpak-spawn fpaste git -gnupg +gnupg2 gnupg2-smime gvfs-client hostname From 4d60442315a78ca9f856e278d8279b4106d371a9 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 2 Feb 2023 18:52:02 +0100 Subject: [PATCH 32/47] Ensure that the gpg2(1), gnupg2(7), etc. manuals are available It turns out that at least since Fedora 30 [1], the gnupg2 package has been part of the fedora base image, because it's required by the dnf package: dnf -> python3-dnf -> python3-libdnf -> libdnf -> gpgme -> gnupg2 Hence, the need to restore the gnupg2 documentation that was stripped out in the base image. [1] It's difficult to find out if the gnupg2 package wasn't part of the fedora base image before Fedora 30, because those images are no longer available from registry.fedoraproject.org. https://github.com/containers/toolbox/pull/1228 --- ensure-files | 3 +++ missing-docs | 1 + 2 files changed, 4 insertions(+) diff --git a/ensure-files b/ensure-files index 24b89a0..9693d36 100644 --- a/ensure-files +++ b/ensure-files @@ -6,6 +6,9 @@ /usr/share/man/man1/cp.1* /usr/share/man/man1/ls.1* +/usr/share/man/man1/gpg2.1* +/usr/share/man/man7/gnupg2.7* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* diff --git a/missing-docs b/missing-docs index 2350648..b06fdc3 100644 --- a/missing-docs +++ b/missing-docs @@ -4,6 +4,7 @@ coreutils-common curl findutils gawk +gnupg2 grep gzip libcap From a6eb5426080ecbd528e49eb52dbf77d160de37ae Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 2 Feb 2023 20:54:30 +0100 Subject: [PATCH 33/47] Replace jwhois with whois Since Fedora 37, the whois package has replaced jwhois as the default whois(1) implementation [1] on Fedora Silverblue and Workstation. [1] fedora-comps commit e4bf2706306c219a https://pagure.io/fedora-comps/c/e4bf2706306c219a https://pagure.io/fedora-comps/pull-request/729 https://fedoraproject.org/wiki/Changes/Replace_jwhois_with_whois_in_Fedora_Workstation https://github.com/containers/toolbox/pull/1228 --- extra-packages | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extra-packages b/extra-packages index 14c9028..f6cf387 100644 --- a/extra-packages +++ b/extra-packages @@ -13,7 +13,7 @@ gvfs-client hostname iproute iputils -jwhois +whois keyutils krb5-libs less From 1d328a24ef7c828fac5b37d85e5da8d74469a5ed Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Tue, 14 Feb 2023 23:11:23 +0100 Subject: [PATCH 34/47] Synchronize with upstream --- README.md | 162 ++++++++---------------------------------------------- 1 file changed, 24 insertions(+), 138 deletions(-) diff --git a/README.md b/README.md index 117528e..6f9943b 100644 --- a/README.md +++ b/README.md @@ -1,7 +1,13 @@ -[Toolbox](https://github.com/containers/toolbox) is a tool for Linux operating -systems, which allows the use of containerized command line environments. It is -built on top of [Podman](https://podman.io/) and other standard container -technologies from [OCI](https://opencontainers.org/). +[Toolbox](https://containertoolbx.org/) is a tool for Linux, which allows the +use of interactive command line environments for development and +troubleshooting the host operating system, without having to install software +on the host. It is built on top of [Podman](https://podman.io/) and other +standard container technologies from [OCI](https://opencontainers.org/). + +Toolbox environments have seamless access to the user's home directory, +the Wayland and X11 sockets, networking (including Avahi), removable devices +(like USB sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the +udev database, etc.. This is particularly useful on [OSTree](https://ostree.readthedocs.io/en/latest/) based operating systems like @@ -10,12 +16,12 @@ This is particularly useful on systems is to discourage installation of software on the host, and instead install software as (or in) containers — they mostly don't even have package managers like DNF or YUM. This makes it difficult to set up a development -environment or install tools for debugging in the usual way. +environment or troubleshoot the operating system in the usual way. Toolbox solves this problem by providing a fully mutable container within -which one can install their favourite development and debugging tools, editors -and SDKs. For example, it's possible to do `yum install ansible` without -affecting the base operating system. +which one can install their favourite development and troubleshooting tools, +editors and SDKs. For example, it's possible to do `yum install ansible` +without affecting the base operating system. However, this tool doesn't *require* using an OSTree based system. It works equally well on Fedora Workstation and Server, and that's a useful way to @@ -23,136 +29,16 @@ incrementally adopt containerization. The toolbox environment is based on an [OCI](https://www.opencontainers.org/) image. On Fedora this is the `fedora-toolbox` image. This image is used to -create a toolbox container that seamlessly integrates with the rest of the -operating system by providing access to the user's home directory, the Wayland -and X11 sockets, networking (including Avahi), removable devices (like USB -sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the udev -database, etc.. +create a toolbox container that offers the interactive command line +environment. + +Note that Toolbox makes no promise about security beyond what's already +available in the usual command line environment on the host that everybody is +familiar with. -## Installation +## Installation & Use -Toolbox is installed by default on Fedora Silverblue. On other operating -systems it's just a matter of installing the `toolbox` package. - -## Usage - -### Create your toolbox container: -```console -[user@hostname ~]$ toolbox create -Created container: fedora-toolbox-33 -Enter with: toolbox enter -[user@hostname ~]$ -``` -This will create a container called `fedora-toolbox-`. - -### Enter the toolbox: -```console -[user@hostname ~]$ toolbox enter -⬢[user@toolbox ~]$ -``` - -### Remove a toolbox container: -```console -[user@hostname ~]$ toolbox rm fedora-toolbox-33 -[user@hostname ~]$ -``` - -## Dependencies and Building - -Toolbox requires at least Podman 1.4.0 to work, and uses the Meson build -system. - -The following dependencies are required to build it: -- meson -- go-md2man -- systemd -- go -- ninja - -The following dependencies enable various optional features: -- bash-completion - -It can be built and installed as any other typical Meson-based project: -```console -[user@hostname toolbox]$ meson -Dprofile_dir=/etc/profile.d builddir -[user@hostname toolbox]$ ninja -C builddir -[user@hostname toolbox]$ sudo ninja -C builddir install -``` - -Toolbox is written in Go. Consult the -[src/go.mod](https://github.com/containers/toolbox/blob/main/src/go.mod) file -for a full list of all the Go dependencies. - -By default, Toolbox uses Go modules and all the required Go packages are -automatically downloaded as part of the build. There's no need to worry about -the Go dependencies, unless the build environment doesn't have network access -or any such peculiarities. - -## Distro support - -By default, Toolbox creates the container using an -[OCI](https://www.opencontainers.org/) image called -`-toolbox:`, where `` and `` are taken from the -host's `/usr/lib/os-release`. For example, the default image on a Fedora 33 -host would be `fedora-toolbox:33`. - -This default can be overridden by the `--image` option in `toolbox create`, -but operating system distributors should provide an adequately configured -default image to ensure a smooth user experience. - -## Image requirements - -Toolbox customizes newly created containers in a certain way. This requires -certain tools and paths to be present and have certain characteristics inside -the OCI image. - -Tools: -* `getent(1)` -* `id(1)` -* `ln(1)` -* `mkdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` -* `passwd(1)` -* `readlink(1)` -* `rm(1)` -* `rmdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` -* `sleep(1)` -* `test(1)` -* `touch(1)` -* `unlink(1)` -* `useradd(8)` -* `usermod(8)` - -Paths: -* `/etc/host.conf`: optional, if present not a bind mount -* `/etc/hosts`: optional, if present not a bind mount -* `/etc/krb5.conf.d`: directory, not a bind mount -* `/etc/localtime`: optional, if present not a bind mount -* `/etc/machine-id`: optional, not a bind mount -* `/etc/resolv.conf`: optional, if present not a bind mount -* `/etc/timezone`: optional, if present not a bind mount - -Toolbox enables `sudo(8)` access inside containers. The following is necessary -for that to work: - -* The image should have `sudo(8)` enabled for users belonging to either the - `sudo` or `wheel` groups, and the group itself should exist. File an - [issue](https://github.com/containers/toolbox/issues/new) if you really need - support for a different group. However, it's preferable to keep this list as - short as possible. - -* The image should allow empty passwords for `sudo(8)`. This can be achieved - by either adding the `nullok` option to the `PAM(8)` configuration, or by - add the `NOPASSWD` tag to the `sudoers(5)` configuration. - -Since Toolbox only works with OCI images that fulfill certain requirements, -it will refuse images that aren't tagged with -`com.github.containers.toolbox="true"` and -`com.github.debarshiray.toolbox="true"` labels. These labels are meant to be -used by the maintainer of the image to indicate that they have read this -document and tested that the image works with Toolbox. You can use the -following snippet in a Dockerfile for this: -```Dockerfile -LABEL com.github.containers.toolbox="true" \ - com.github.debarshiray.toolbox="true" -``` +See our guides on +[installing & getting started](https://containertoolbx.org/install/) with +Toolbox and [Linux distro support](https://containertoolbx.org/distros/). From e0813a6d6f7627cbe1ebb15c239d5495e27c5fcd Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Tue, 14 Feb 2023 23:15:51 +0100 Subject: [PATCH 35/47] Bump version to 39 for rawhide --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index f0c6372..0646c48 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ -FROM registry.fedoraproject.org/fedora:38 +FROM registry.fedoraproject.org/fedora:39 -ENV NAME=fedora-toolbox VERSION=38 +ENV NAME=fedora-toolbox VERSION=39 LABEL com.github.containers.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ From 77bb135f27016cc370effb13271666415435f16a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Timoth=C3=A9e=20Ravier?= Date: Thu, 16 Feb 2023 17:35:15 +0100 Subject: [PATCH 36/47] Use ARG instead of ENV to avoid leaking variables We only need those temporary variables for the container build and for the LABELS. We do not want to set those specific environment variables for the container environment itself. Using ARG instead of ENV lets us do that. See: https://github.com/containers/toolbox/issues/188 See: https://github.com/containers/docs/pull/15 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 0646c48..c598741 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ FROM registry.fedoraproject.org/fedora:39 -ENV NAME=fedora-toolbox VERSION=39 +ARG NAME=fedora-toolbox VERSION=39 LABEL com.github.containers.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ From dfa4cee9046b6f6f08a56f81d097b9ca1a066833 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Mar 2023 12:42:54 +0100 Subject: [PATCH 37/47] Attempt to fix the use of ARG ... because the image failed to build with: Error in plugin orchestrate_build: {"x86_64": {"docker_api": "ARG requires exactly one argument"}, "aarch64": {"docker_api": "Dockerfile parse error line 4: ARG requires exactly one argument"}}. Fallout from 77bb135f27016cc370effb13271666415435f16a --- Dockerfile | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index c598741..b4d45b3 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,7 @@ FROM registry.fedoraproject.org/fedora:39 -ARG NAME=fedora-toolbox VERSION=39 +ARG NAME=fedora-toolbox +ARG VERSION=39 LABEL com.github.containers.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ From 951b464d509feb29ac9cf96097a175e85cc1db63 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Mar 2023 13:21:19 +0100 Subject: [PATCH 38/47] Synchronize with upstream --- README.md | 162 ++++++++---------------------------------------------- 1 file changed, 24 insertions(+), 138 deletions(-) diff --git a/README.md b/README.md index 117528e..6f9943b 100644 --- a/README.md +++ b/README.md @@ -1,7 +1,13 @@ -[Toolbox](https://github.com/containers/toolbox) is a tool for Linux operating -systems, which allows the use of containerized command line environments. It is -built on top of [Podman](https://podman.io/) and other standard container -technologies from [OCI](https://opencontainers.org/). +[Toolbox](https://containertoolbx.org/) is a tool for Linux, which allows the +use of interactive command line environments for development and +troubleshooting the host operating system, without having to install software +on the host. It is built on top of [Podman](https://podman.io/) and other +standard container technologies from [OCI](https://opencontainers.org/). + +Toolbox environments have seamless access to the user's home directory, +the Wayland and X11 sockets, networking (including Avahi), removable devices +(like USB sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the +udev database, etc.. This is particularly useful on [OSTree](https://ostree.readthedocs.io/en/latest/) based operating systems like @@ -10,12 +16,12 @@ This is particularly useful on systems is to discourage installation of software on the host, and instead install software as (or in) containers — they mostly don't even have package managers like DNF or YUM. This makes it difficult to set up a development -environment or install tools for debugging in the usual way. +environment or troubleshoot the operating system in the usual way. Toolbox solves this problem by providing a fully mutable container within -which one can install their favourite development and debugging tools, editors -and SDKs. For example, it's possible to do `yum install ansible` without -affecting the base operating system. +which one can install their favourite development and troubleshooting tools, +editors and SDKs. For example, it's possible to do `yum install ansible` +without affecting the base operating system. However, this tool doesn't *require* using an OSTree based system. It works equally well on Fedora Workstation and Server, and that's a useful way to @@ -23,136 +29,16 @@ incrementally adopt containerization. The toolbox environment is based on an [OCI](https://www.opencontainers.org/) image. On Fedora this is the `fedora-toolbox` image. This image is used to -create a toolbox container that seamlessly integrates with the rest of the -operating system by providing access to the user's home directory, the Wayland -and X11 sockets, networking (including Avahi), removable devices (like USB -sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the udev -database, etc.. +create a toolbox container that offers the interactive command line +environment. + +Note that Toolbox makes no promise about security beyond what's already +available in the usual command line environment on the host that everybody is +familiar with. -## Installation +## Installation & Use -Toolbox is installed by default on Fedora Silverblue. On other operating -systems it's just a matter of installing the `toolbox` package. - -## Usage - -### Create your toolbox container: -```console -[user@hostname ~]$ toolbox create -Created container: fedora-toolbox-33 -Enter with: toolbox enter -[user@hostname ~]$ -``` -This will create a container called `fedora-toolbox-`. - -### Enter the toolbox: -```console -[user@hostname ~]$ toolbox enter -⬢[user@toolbox ~]$ -``` - -### Remove a toolbox container: -```console -[user@hostname ~]$ toolbox rm fedora-toolbox-33 -[user@hostname ~]$ -``` - -## Dependencies and Building - -Toolbox requires at least Podman 1.4.0 to work, and uses the Meson build -system. - -The following dependencies are required to build it: -- meson -- go-md2man -- systemd -- go -- ninja - -The following dependencies enable various optional features: -- bash-completion - -It can be built and installed as any other typical Meson-based project: -```console -[user@hostname toolbox]$ meson -Dprofile_dir=/etc/profile.d builddir -[user@hostname toolbox]$ ninja -C builddir -[user@hostname toolbox]$ sudo ninja -C builddir install -``` - -Toolbox is written in Go. Consult the -[src/go.mod](https://github.com/containers/toolbox/blob/main/src/go.mod) file -for a full list of all the Go dependencies. - -By default, Toolbox uses Go modules and all the required Go packages are -automatically downloaded as part of the build. There's no need to worry about -the Go dependencies, unless the build environment doesn't have network access -or any such peculiarities. - -## Distro support - -By default, Toolbox creates the container using an -[OCI](https://www.opencontainers.org/) image called -`-toolbox:`, where `` and `` are taken from the -host's `/usr/lib/os-release`. For example, the default image on a Fedora 33 -host would be `fedora-toolbox:33`. - -This default can be overridden by the `--image` option in `toolbox create`, -but operating system distributors should provide an adequately configured -default image to ensure a smooth user experience. - -## Image requirements - -Toolbox customizes newly created containers in a certain way. This requires -certain tools and paths to be present and have certain characteristics inside -the OCI image. - -Tools: -* `getent(1)` -* `id(1)` -* `ln(1)` -* `mkdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` -* `passwd(1)` -* `readlink(1)` -* `rm(1)` -* `rmdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` -* `sleep(1)` -* `test(1)` -* `touch(1)` -* `unlink(1)` -* `useradd(8)` -* `usermod(8)` - -Paths: -* `/etc/host.conf`: optional, if present not a bind mount -* `/etc/hosts`: optional, if present not a bind mount -* `/etc/krb5.conf.d`: directory, not a bind mount -* `/etc/localtime`: optional, if present not a bind mount -* `/etc/machine-id`: optional, not a bind mount -* `/etc/resolv.conf`: optional, if present not a bind mount -* `/etc/timezone`: optional, if present not a bind mount - -Toolbox enables `sudo(8)` access inside containers. The following is necessary -for that to work: - -* The image should have `sudo(8)` enabled for users belonging to either the - `sudo` or `wheel` groups, and the group itself should exist. File an - [issue](https://github.com/containers/toolbox/issues/new) if you really need - support for a different group. However, it's preferable to keep this list as - short as possible. - -* The image should allow empty passwords for `sudo(8)`. This can be achieved - by either adding the `nullok` option to the `PAM(8)` configuration, or by - add the `NOPASSWD` tag to the `sudoers(5)` configuration. - -Since Toolbox only works with OCI images that fulfill certain requirements, -it will refuse images that aren't tagged with -`com.github.containers.toolbox="true"` and -`com.github.debarshiray.toolbox="true"` labels. These labels are meant to be -used by the maintainer of the image to indicate that they have read this -document and tested that the image works with Toolbox. You can use the -following snippet in a Dockerfile for this: -```Dockerfile -LABEL com.github.containers.toolbox="true" \ - com.github.debarshiray.toolbox="true" -``` +See our guides on +[installing & getting started](https://containertoolbx.org/install/) with +Toolbox and [Linux distro support](https://containertoolbx.org/distros/). From 0914617155c7e96de178c7c62d01692c0a939cea Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Timoth=C3=A9e=20Ravier?= Date: Thu, 16 Feb 2023 17:35:15 +0100 Subject: [PATCH 39/47] Use ARG instead of ENV to avoid leaking variables We only need those temporary variables for the container build and for the LABELS. We do not want to set those specific environment variables for the container environment itself. Using ARG instead of ENV lets us do that. See: https://github.com/containers/toolbox/issues/188 See: https://github.com/containers/docs/pull/15 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 0136d83..64692ad 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ FROM registry.fedoraproject.org/fedora:36 -ENV NAME=fedora-toolbox VERSION=36 +ARG NAME=fedora-toolbox VERSION=36 LABEL com.github.containers.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ From 9ff633d04b94bb37fb3f48374778838c9cc5d060 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Mar 2023 12:42:54 +0100 Subject: [PATCH 40/47] Attempt to fix the use of ARG ... because the image failed to build with: Error in plugin orchestrate_build: {"x86_64": {"docker_api": "ARG requires exactly one argument"}, "aarch64": {"docker_api": "Dockerfile parse error line 4: ARG requires exactly one argument"}}. Fallout from 0914617155c7e96de178c7c62d01692c0a939cea --- Dockerfile | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 64692ad..3189122 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,7 @@ FROM registry.fedoraproject.org/fedora:36 -ARG NAME=fedora-toolbox VERSION=36 +ARG NAME=fedora-toolbox +ARG VERSION=36 LABEL com.github.containers.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ From 3c5e37aee9257ddde05bf483922c95ac9afdfd5f Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Mon, 9 Oct 2023 15:32:05 +0200 Subject: [PATCH 41/47] Reorder alphabetically Note that the fedora-toolbox OCI image for Fedora 39 onwards is no longer built using OpenShift Build Service from the Dockerfile here. It's now being built using Image Factory from fedora-kickstarts and pungi-fedora [1], as part of the ToolbxReleaseBlocker Change [2] for Fedora 39. Hence this is only for the sake of completeness. Fallout from a6eb5426080ecbd528e49eb52dbf77d160de37ae [1] https://pagure.io/fedora-kickstarts/ https://pagure.io/pungi-fedora/ [2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker https://github.com/containers/toolbox/pull/1384 --- extra-packages | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extra-packages b/extra-packages index f6cf387..a85268f 100644 --- a/extra-packages +++ b/extra-packages @@ -13,7 +13,6 @@ gvfs-client hostname iproute iputils -whois keyutils krb5-libs less @@ -42,6 +41,7 @@ vte-profile vulkan-loader wget which +whois words xorg-x11-xauth xz From 00dfa04654591f26e3d48f857eec48ed35ec9bfb Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Mon, 9 Oct 2023 15:27:01 +0200 Subject: [PATCH 42/47] Ensure that the manuals from extra-packages are available Until now, only the packages that are present in the fedora base image, and had their documentation stripped out, were being tested for the availability of documentation. There were no tests for the extra packages that get added to the base image to form the fedora-toolbox image. The util-linux and xz packages were picked as examples for these new tests. The xz package is a particularly good example because it has translations for its manuals. It can help test that the fedora-toolbox image is localized just like Fedora Silverblue and Workstation. Note that the fedora-toolbox OCI image for Fedora 39 onwards is no longer built using OpenShift Build Service from the Dockerfile here. It's now being built using Image Factory from fedora-kickstarts and pungi-fedora [1], as part of the ToolbxReleaseBlocker Change [2] for Fedora 39. Hence this is only for the sake of completeness. [1] https://pagure.io/fedora-kickstarts/ https://pagure.io/pungi-fedora/ [2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker https://github.com/containers/toolbox/pull/1384 --- ensure-files | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/ensure-files b/ensure-files index 9693d36..851baaa 100644 --- a/ensure-files +++ b/ensure-files @@ -13,5 +13,13 @@ /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* +/usr/share/man/man1/cal.1.* +/usr/share/man/man1/getopt.1* +/usr/share/man/man1/hexdump.1* + /usr/share/man/man1/kill.1* /usr/share/man/man8/mount.8* + +/usr/share/man/fr/man1/xz.1* +/usr/share/man/ko/man1/xz.1* +/usr/share/man/man1/xz.1* From 396de4320908225e8664b36576e8f475e61cd27d Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Fri, 20 Oct 2023 12:08:59 +0200 Subject: [PATCH 43/47] Add psmisc It's currently being pulled in as a dependency of iproute. However, since it's explicitly mentioned in the list of default packages on Fedora Silverblue and Workstation [1], it should be mentioned here too. The psmisc package marks the translations for its manuals with %lang(). Therefore, it's a very good example for testing that the fedora-toolbox image is localized just like Fedora Silverblue and Workstation. This is unlike the xz package, whose translations for manuals were added to the tests recently [2]. The xz package doesn't mark its translated manuals with %lang() [3], which means that they are going to get installed regardless of whether RPM has been configured to not install localization files or not. eg., through the %_install_langs macro. So, they aren't a good candidate for the tests until this is fixed. Note that the fedora-toolbox OCI image for Fedora 39 onwards is no longer built using OpenShift Build Service from the Dockerfile here. It's now being built using Image Factory from fedora-kickstarts and pungi-fedora [4], as part of the ToolbxReleaseBlocker Change [5] for Fedora 39. Hence this is only for the sake of completeness. [1] fedora-comps commit e4ed54dfcc497fd0 https://pagure.io/fedora-comps/c/e4ed54dfcc497fd0 https://pagure.io/fedora-comps/pull-request/379 [2] Toolbx commit 20188a097a1a7a16 https://github.com/containers/toolbox/commit/20188a097a1a7a16 https://github.com/containers/toolbox/pull/1384 [3] https://src.fedoraproject.org/rpms/xz/pull-request/10 [4] https://pagure.io/fedora-kickstarts/ https://pagure.io/pungi-fedora/ [5] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker https://github.com/containers/toolbox/pull/1390 --- ensure-files | 4 ++++ extra-packages | 1 + 2 files changed, 5 insertions(+) diff --git a/ensure-files b/ensure-files index 851baaa..1450f58 100644 --- a/ensure-files +++ b/ensure-files @@ -9,6 +9,10 @@ /usr/share/man/man1/gpg2.1* /usr/share/man/man7/gnupg2.7* +/usr/share/man/fr/man1/pstree.1* +/usr/share/man/ko/man1/pstree.1* +/usr/share/man/man1/pstree.1* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* diff --git a/extra-packages b/extra-packages index a85268f..f07bf58 100644 --- a/extra-packages +++ b/extra-packages @@ -28,6 +28,7 @@ openssh-clients passwd pigz procps-ng +psmisc rsync shadow-utils sudo From 04b26152ae1ab3eaaef6db085b4de220bac83afe Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Fri, 27 Oct 2023 20:13:27 +0200 Subject: [PATCH 44/47] Update the tests The translations for the RPM manuals were removed upstream during the RPM 4.19 development cycle [1]. So, replace them with rpm2cpio(8), which is another popular command shipped by the rpm package. Note that the fedora-toolbox OCI image for Fedora 39 onwards is no longer built using OpenShift Build Service from the Dockerfile here. It's now being built using Image Factory from fedora-kickstarts and pungi-fedora [2], as part of the ToolbxReleaseBlocker Change [3] for Fedora 39. [1] RPM commit 4df74a9644b18136 https://github.com/rpm-software-management/rpm/commit/4df74a9644b18136 https://github.com/rpm-software-management/rpm/pull/2245 [2] https://pagure.io/fedora-kickstarts/ https://pagure.io/pungi-fedora/ [3] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker https://github.com/containers/toolbox/pull/1391 --- ensure-files | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/ensure-files b/ensure-files index 1450f58..f5266f5 100644 --- a/ensure-files +++ b/ensure-files @@ -13,9 +13,8 @@ /usr/share/man/ko/man1/pstree.1* /usr/share/man/man1/pstree.1* -/usr/share/man/fr/man8/rpm.8* -/usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* +/usr/share/man/man8/rpm2cpio.8* /usr/share/man/man1/cal.1.* /usr/share/man/man1/getopt.1* From 5ff7fd359738f4b163adbbb3afb2825dad222cce Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Fri, 27 Oct 2023 20:24:24 +0200 Subject: [PATCH 45/47] Ensure that the useradd(8), etc. manuals are available The shadow-utils package has always been part of the fedora base image. It's explicitly listed in extra-packages as a safeguard against losing useradd(8) and usermod(8) by mistake because they are needed by the entry point of a Toolbx container [1]. Hence, the need to restore the shadow-utils documentation that was stripped out in the base image. Note that the fedora-toolbox OCI image for Fedora 39 onwards is no longer built using OpenShift Build Service from the Dockerfile here. It's now being built using Image Factory from fedora-kickstarts and pungi-fedora [2], as part of the ToolbxReleaseBlocker Change [3] for Fedora 39. Hence this is only for the sake of completeness. [1] Toolbx commit c6772f0f112e8004 https://github.com/containers/toolbox/commit/c6772f0f112e8004 [2] https://pagure.io/fedora-kickstarts/ https://pagure.io/pungi-fedora/ [3] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker https://github.com/containers/toolbox/pull/1394 --- ensure-files | 4 ++++ missing-docs | 1 + 2 files changed, 5 insertions(+) diff --git a/ensure-files b/ensure-files index f5266f5..69457a5 100644 --- a/ensure-files +++ b/ensure-files @@ -16,6 +16,10 @@ /usr/share/man/man8/rpm.8* /usr/share/man/man8/rpm2cpio.8* +/usr/share/man/fr/man8/useradd.8* +/usr/share/man/ja/man8/useradd.8* +/usr/share/man/man8/useradd.8* + /usr/share/man/man1/cal.1.* /usr/share/man/man1/getopt.1* /usr/share/man/man1/hexdump.1* diff --git a/missing-docs b/missing-docs index b06fdc3..887d9ba 100644 --- a/missing-docs +++ b/missing-docs @@ -14,6 +14,7 @@ pam python3 rpm sed +shadow-utils sudo systemd tar From 6c46178bbba38bec985bca4d45664a8b469052bb Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Nov 2023 15:23:43 +0100 Subject: [PATCH 46/47] Ensure that documentation and translations are present This should finally ensure that the fedora-toolbox image doesn't have any package that had its content, such as documentation or translations, stripped out by the fedora base image. Until now, missing-docs had a hand-maintained list of packages that had their content stripped out by the fedora base image. These packages are reinstalled when building the fedora-toolbox image to restore the lost content. Unfortunately, this list was incomplete because it was only updated when someone noticed that something is missing. Now, the list is generated with: $ rpm --all --query --state --queryformat "PACKAGE: %{NAME}\n" ... to ensure that it's always complete. The existing built-in test to ensure that the desired files are actually present in the final image was extended to cover some of those that were absent. A new built-in test, based on the above rpm(1) command, was added as a fallback to ensure that the final image doesn't have any package with missing content. As suggested by Brian Campbell. Note that the fedora-toolbox OCI image for Fedora 39 onwards is no longer built using OpenShift Build Service from the Dockerfile here. It's now being built using Image Factory from fedora-kickstarts and pungi-fedora [1], as part of the ToolbxReleaseBlocker Change [2] for Fedora 39. Hence this is only for the sake of completeness. [1] https://pagure.io/fedora-kickstarts/ https://pagure.io/pungi-fedora/ [2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker https://github.com/containers/toolbox/issues/603 --- Dockerfile | 10 ++++++++ ensure-files | 13 ++++++++++ missing-docs | 69 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 3 files changed, 92 insertions(+) diff --git a/Dockerfile b/Dockerfile index b4d45b3..771edc2 100644 --- a/Dockerfile +++ b/Dockerfile @@ -41,4 +41,14 @@ RUN ret_val=0; \ fi RUN rm /ensure-files +RUN broken_packages="$(rpm --all --query --state --queryformat "PACKAGE: %{NAME}\n" \ + | sed --quiet --regexp-extended '/PACKAGE: /{s/PACKAGE: // ; h ; b }; /^not installed/ { g; p }' \ + | uniq \ + | sort)"; \ + if [ "$broken_packages" != "" ]; then \ + echo "Packages with missing files:" >&2; \ + echo "$broken_packages" >&2; \ + false; \ + fi + RUN dnf clean all diff --git a/ensure-files b/ensure-files index 69457a5..1e39f69 100644 --- a/ensure-files +++ b/ensure-files @@ -6,13 +6,26 @@ /usr/share/man/man1/cp.1* /usr/share/man/man1/ls.1* +/usr/share/man/man8/dnf.8* +/usr/share/man/man5/dnf.conf.5* + +/usr/share/locale/de/LC_MESSAGES/elfutils.mo +/usr/share/locale/ja/LC_MESSAGES/elfutils.mo + /usr/share/man/man1/gpg2.1* /usr/share/man/man7/gnupg2.7* +/usr/share/info/nettle.info* + +/usr/share/locale/fr/LC_MESSAGES/popt.mo +/usr/share/locale/ja/LC_MESSAGES/popt.mo + /usr/share/man/fr/man1/pstree.1* /usr/share/man/ko/man1/pstree.1* /usr/share/man/man1/pstree.1* +/usr/share/info/history.info* + /usr/share/man/man8/rpm.8* /usr/share/man/man8/rpm2cpio.8* diff --git a/missing-docs b/missing-docs index 887d9ba..98f1395 100644 --- a/missing-docs +++ b/missing-docs @@ -1,21 +1,90 @@ acl +alternatives +audit-libs +authselect +authselect-libs bash +ca-certificates coreutils-common +cracklib +crypto-policies curl +cyrus-sasl-lib +dnf +dnf-data +elfutils-libelf +expat +file-libs +filesystem findutils gawk +glib2 +gmp gnupg2 +gnutls grep gzip +ima-evm-utils +keyutils-libs +krb5-libs +libarchive +libassuan +libblkid libcap +libcap-ng +libcomps +libdb +libdnf +libeconf +libevent +libffi +libgcrypt +libgomp +libgpg-error +libidn2 +libksba +libmodulemd +libpwquality +librepo +libsemanage +libsigsegv +libsolv +libssh +libtasn1 +libtirpc +libunistring +libverto +libxcrypt +libxml2 +libyaml +lz4-libs +mpfr +ncurses-base +nettle +openldap openssl p11-kit pam +pcre2-syntax +popt python3 +python3-libs +python3-rpm +readline rpm +rpm-sequoia sed +setup shadow-utils +sqlite-libs sudo systemd +systemd-libs tar +tpm2-tss +tzdata util-linux-core +vim-minimal +yum +zchunk-libs +zlib From 8930a119688067cc6037334817456acfae7651ca Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Fri, 8 Dec 2023 00:13:24 +0100 Subject: [PATCH 47/47] Retire --- Dockerfile | 54 ------------------------------ README.md | 44 ------------------------ dead.container | 9 +++++ ensure-files | 45 ------------------------- extra-packages | 49 --------------------------- missing-docs | 90 -------------------------------------------------- 6 files changed, 9 insertions(+), 282 deletions(-) delete mode 100644 Dockerfile delete mode 100644 README.md create mode 100644 dead.container delete mode 100644 ensure-files delete mode 100644 extra-packages delete mode 100644 missing-docs diff --git a/Dockerfile b/Dockerfile deleted file mode 100644 index 771edc2..0000000 --- a/Dockerfile +++ /dev/null @@ -1,54 +0,0 @@ -FROM registry.fedoraproject.org/fedora:39 - -ARG NAME=fedora-toolbox -ARG VERSION=39 -LABEL com.github.containers.toolbox="true" \ - com.redhat.component="$NAME" \ - name="$NAME" \ - version="$VERSION" \ - usage="This image is meant to be used with the toolbox command" \ - summary="Base image for creating Fedora toolbox containers" \ - maintainer="Debarshi Ray " - -COPY README.md / - -RUN rm /etc/rpm/macros.image-language-conf -RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf - -RUN dnf -y upgrade -RUN dnf -y swap coreutils-single coreutils-full -RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks - -COPY missing-docs / -RUN dnf -y reinstall $(/dev/null; then \ - echo "$file: No such file or directory" >&2; \ - ret_val=1; \ - break; \ - fi; \ - done &2; \ - echo "$broken_packages" >&2; \ - false; \ - fi - -RUN dnf clean all diff --git a/README.md b/README.md deleted file mode 100644 index 6f9943b..0000000 --- a/README.md +++ /dev/null @@ -1,44 +0,0 @@ -[Toolbox](https://containertoolbx.org/) is a tool for Linux, which allows the -use of interactive command line environments for development and -troubleshooting the host operating system, without having to install software -on the host. It is built on top of [Podman](https://podman.io/) and other -standard container technologies from [OCI](https://opencontainers.org/). - -Toolbox environments have seamless access to the user's home directory, -the Wayland and X11 sockets, networking (including Avahi), removable devices -(like USB sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the -udev database, etc.. - -This is particularly useful on -[OSTree](https://ostree.readthedocs.io/en/latest/) based operating systems like -[Fedora CoreOS](https://coreos.fedoraproject.org/) and -[Silverblue](https://silverblue.fedoraproject.org/). The intention of these -systems is to discourage installation of software on the host, and instead -install software as (or in) containers — they mostly don't even have package -managers like DNF or YUM. This makes it difficult to set up a development -environment or troubleshoot the operating system in the usual way. - -Toolbox solves this problem by providing a fully mutable container within -which one can install their favourite development and troubleshooting tools, -editors and SDKs. For example, it's possible to do `yum install ansible` -without affecting the base operating system. - -However, this tool doesn't *require* using an OSTree based system. It works -equally well on Fedora Workstation and Server, and that's a useful way to -incrementally adopt containerization. - -The toolbox environment is based on an [OCI](https://www.opencontainers.org/) -image. On Fedora this is the `fedora-toolbox` image. This image is used to -create a toolbox container that offers the interactive command line -environment. - -Note that Toolbox makes no promise about security beyond what's already -available in the usual command line environment on the host that everybody is -familiar with. - - -## Installation & Use - -See our guides on -[installing & getting started](https://containertoolbx.org/install/) with -Toolbox and [Linux distro support](https://containertoolbx.org/distros/). diff --git a/dead.container b/dead.container new file mode 100644 index 0000000..ac43a2a --- /dev/null +++ b/dead.container @@ -0,0 +1,9 @@ +The fedora-toolbox OCI image for Fedora 39 onwards is no longer built using +OpenShift Build Service from the Dockerfile here. It's now being built using +Image Factory from fedora-kickstarts and pungi-fedora [1], as part of the +ToolbxReleaseBlocker Change [2] for Fedora 39. + +[1] https://pagure.io/fedora-kickstarts/ + https://pagure.io/pungi-fedora/ + +[2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker diff --git a/ensure-files b/ensure-files deleted file mode 100644 index 1e39f69..0000000 --- a/ensure-files +++ /dev/null @@ -1,45 +0,0 @@ -/usr/share/man/man1/bash.1* -/usr/share/man/man1/cd.1* -/usr/share/man/man1/export.1* - -/usr/share/man/man1/cat.1* -/usr/share/man/man1/cp.1* -/usr/share/man/man1/ls.1* - -/usr/share/man/man8/dnf.8* -/usr/share/man/man5/dnf.conf.5* - -/usr/share/locale/de/LC_MESSAGES/elfutils.mo -/usr/share/locale/ja/LC_MESSAGES/elfutils.mo - -/usr/share/man/man1/gpg2.1* -/usr/share/man/man7/gnupg2.7* - -/usr/share/info/nettle.info* - -/usr/share/locale/fr/LC_MESSAGES/popt.mo -/usr/share/locale/ja/LC_MESSAGES/popt.mo - -/usr/share/man/fr/man1/pstree.1* -/usr/share/man/ko/man1/pstree.1* -/usr/share/man/man1/pstree.1* - -/usr/share/info/history.info* - -/usr/share/man/man8/rpm.8* -/usr/share/man/man8/rpm2cpio.8* - -/usr/share/man/fr/man8/useradd.8* -/usr/share/man/ja/man8/useradd.8* -/usr/share/man/man8/useradd.8* - -/usr/share/man/man1/cal.1.* -/usr/share/man/man1/getopt.1* -/usr/share/man/man1/hexdump.1* - -/usr/share/man/man1/kill.1* -/usr/share/man/man8/mount.8* - -/usr/share/man/fr/man1/xz.1* -/usr/share/man/ko/man1/xz.1* -/usr/share/man/man1/xz.1* diff --git a/extra-packages b/extra-packages deleted file mode 100644 index f07bf58..0000000 --- a/extra-packages +++ /dev/null @@ -1,49 +0,0 @@ -bash-completion -bc -bzip2 -diffutils -dnf-plugins-core -findutils -flatpak-spawn -fpaste -git -gnupg2 -gnupg2-smime -gvfs-client -hostname -iproute -iputils -keyutils -krb5-libs -less -lsof -man-db -man-pages -mesa-dri-drivers -mesa-vulkan-drivers -mtr -nano-default-editor -nss-mdns -openssh-clients -passwd -pigz -procps-ng -psmisc -rsync -shadow-utils -sudo -tcpdump -time -traceroute -tree -unzip -util-linux -vte-profile -vulkan-loader -wget -which -whois -words -xorg-x11-xauth -xz -zip diff --git a/missing-docs b/missing-docs deleted file mode 100644 index 98f1395..0000000 --- a/missing-docs +++ /dev/null @@ -1,90 +0,0 @@ -acl -alternatives -audit-libs -authselect -authselect-libs -bash -ca-certificates -coreutils-common -cracklib -crypto-policies -curl -cyrus-sasl-lib -dnf -dnf-data -elfutils-libelf -expat -file-libs -filesystem -findutils -gawk -glib2 -gmp -gnupg2 -gnutls -grep -gzip -ima-evm-utils -keyutils-libs -krb5-libs -libarchive -libassuan -libblkid -libcap -libcap-ng -libcomps -libdb -libdnf -libeconf -libevent -libffi -libgcrypt -libgomp -libgpg-error -libidn2 -libksba -libmodulemd -libpwquality -librepo -libsemanage -libsigsegv -libsolv -libssh -libtasn1 -libtirpc -libunistring -libverto -libxcrypt -libxml2 -libyaml -lz4-libs -mpfr -ncurses-base -nettle -openldap -openssl -p11-kit -pam -pcre2-syntax -popt -python3 -python3-libs -python3-rpm -readline -rpm -rpm-sequoia -sed -setup -shadow-utils -sqlite-libs -sudo -systemd -systemd-libs -tar -tpm2-tss -tzdata -util-linux-core -vim-minimal -yum -zchunk-libs -zlib