From 8859dc0fc7e7d605dc5555b17f28e0656f4cd846 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 8 Mar 2022 15:33:41 +0800 Subject: [PATCH 01/18] remove autorebuild config to unbreak koji OBS build see https://pagure.io/releng/issue/10658 --- .osbs-repo-config | 3 --- container.yaml | 2 -- 2 files changed, 5 deletions(-) delete mode 100644 .osbs-repo-config delete mode 100644 container.yaml diff --git a/.osbs-repo-config b/.osbs-repo-config deleted file mode 100644 index d2914e4..0000000 --- a/.osbs-repo-config +++ /dev/null @@ -1,3 +0,0 @@ -[autorebuild] -enabled = true - diff --git a/container.yaml b/container.yaml deleted file mode 100644 index 6281e92..0000000 --- a/container.yaml +++ /dev/null @@ -1,2 +0,0 @@ -autorebuild: - from_latest: true From af1edb81ec6267c21f98368c5b290687bc9f238f Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 9 Aug 2022 14:26:33 +0800 Subject: [PATCH 02/18] findutils missing docs --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index c185ad3..cb44892 100644 --- a/missing-docs +++ b/missing-docs @@ -2,6 +2,7 @@ acl bash coreutils-common curl +findutils gawk grep gzip From 85ef0e9bbe9dd01add5df994db711785715dad89 Mon Sep 17 00:00:00 2001 From: Jens Petersen Date: Tue, 13 Dec 2022 18:19:13 +0800 Subject: [PATCH 03/18] missing-docs: add util-linux-core --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index cb44892..e19a580 100644 --- a/missing-docs +++ b/missing-docs @@ -15,3 +15,4 @@ rpm sed systemd tar +util-linux-core From 92830d16350d922e5919c245867a8f7f497780a1 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 00:23:16 +0100 Subject: [PATCH 04/18] Removed deprecated com.github.debarshiray.toolbox tag https://github.com/containers/toolbox/pull/820 --- Dockerfile | 1 - 1 file changed, 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index f4b8a71..693f8f8 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,7 +2,6 @@ FROM registry.fedoraproject.org/fedora:36 ENV NAME=fedora-toolbox VERSION=36 LABEL com.github.containers.toolbox="true" \ - com.github.debarshiray.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ version="$VERSION" \ From bfcccc0943da9f5c3a107c3852c3d7b56ee161c8 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 00:30:35 +0100 Subject: [PATCH 05/18] Ensure that all the glibc language packs are available ... and not just C, POSIX and C.UTF-8. https://github.com/containers/toolbox/issues/60 --- Dockerfile | 1 + 1 file changed, 1 insertion(+) diff --git a/Dockerfile b/Dockerfile index 693f8f8..de28e43 100644 --- a/Dockerfile +++ b/Dockerfile @@ -13,6 +13,7 @@ COPY README.md / RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf RUN dnf -y swap coreutils-single coreutils-full +RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks COPY missing-docs / RUN dnf -y reinstall $( Date: Wed, 1 Feb 2023 00:32:45 +0100 Subject: [PATCH 06/18] Remove RPM configuration to strip out translations Note that this doesn't restore the translations that were stripped out from the base fedora image. It only ensures that subsequent RPM transactions retain the translations. https://github.com/containers/toolbox/issues/60 --- Dockerfile | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Dockerfile b/Dockerfile index de28e43..ba1118d 100644 --- a/Dockerfile +++ b/Dockerfile @@ -11,7 +11,9 @@ LABEL com.github.containers.toolbox="true" \ COPY README.md / +RUN rm /etc/rpm/macros.image-language-conf RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf + RUN dnf -y swap coreutils-single coreutils-full RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks From a4947a9269f6509eb49701871c958deb8cdb069f Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 01:34:01 +0100 Subject: [PATCH 07/18] Enable OpenGL and Vulkan for hardware with free drivers https://github.com/containers/toolbox/issues/1110 --- extra-packages | 3 +++ 1 file changed, 3 insertions(+) diff --git a/extra-packages b/extra-packages index 52bf3f3..cdd2aa1 100644 --- a/extra-packages +++ b/extra-packages @@ -20,6 +20,8 @@ less lsof man-db man-pages +mesa-dri-drivers +mesa-vulkan-drivers mtr nano-default-editor nss-mdns @@ -37,6 +39,7 @@ tree unzip util-linux vte-profile +vulkan-loader wget which words From 08f4699d4a2b34f5a638df85d0b296e6ee59df04 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 01:39:01 +0100 Subject: [PATCH 08/18] Ensure that the sudo(8), sudoers(5), etc. manuals are available https://github.com/containers/toolbox/pull/1068 https://github.com/containers/toolbox/pull/1133 --- missing-docs | 1 + 1 file changed, 1 insertion(+) diff --git a/missing-docs b/missing-docs index e19a580..2350648 100644 --- a/missing-docs +++ b/missing-docs @@ -13,6 +13,7 @@ pam python3 rpm sed +sudo systemd tar util-linux-core From a1d5815684a8833f773106d7407b7003e9a78b17 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 19:53:56 +0100 Subject: [PATCH 09/18] Avoid unexpected DNF behaviour when reinstalling or swapping The RPM packages in the base 'fedora' image can be older than the those currently available in the DNF 'updates' repository [1], but at the same time newer than those available in the DNF 'fedora' repository [1]. The first part happens because the base image isn't updated as often as the individual packages, so the 'updates' repository can have newer RPMs. The second part happens because the base image does get updated after a stable Fedora has been released, and hence can have newer RPMs than the 'fedora' repository. This is complicated by the fact that packages can get pulled directly from Fedora's Koji build system into the base 'fedora' image before they make it to one of the well-known repositories like 'fedora' or 'updates' [1]. These packages are marked as having come from the koji-override-0 repository. All that combined can lead to unexpected behaviour when DNF is invoked to reinstall or swap the RPM packages in the base image. Some examples below. The base fedora:36 image contains glibc-minimal-langpack-2.35-20.fc36 that came from koji-override-0, while 'fedora' and 'updates' have glibc-all-langpacks-2.35-4.fc36 and glibc-all-langpacks-2.35-22.fc36 respectively. This leads to: STEP 8/15: RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks Last metadata expiration check: 0:00:03 ago on Wed Feb 1 12:37:04... Dependencies resolved. ====================================================================== Package Arch Version Repository ====================================================================== Installing: glibc-all-langpacks x86_64 2.35-4.fc36 fedora Removing: glibc-minimal-langpack x86_64 2.35-20.fc36 @koji-override-0 Downgrading: glibc x86_64 2.35-4.fc36 fedora glibc-common x86_64 2.35-4.fc36 fedora That's unexpected. Instead of upgrading all the glibc sub-packages to the latest version from 'updates', it's downgrading them to the older version from 'fedora'. Similarly, the base fedora:36 image has bash-5.2.9-2.fc36.x86_64 from koji-override-0, and there is bash-5.2.15-1.fc36.x86_64 in 'updates'. This leads to: STEP 10/15: RUN dnf -y reinstall $( Date: Wed, 1 Feb 2023 19:57:32 +0100 Subject: [PATCH 10/18] images: Ensure that the desired manuals are indeed present Building an OCI image leads to so much spew that it's hard to notice if something unexpected happened, and as seen in the previous commit [1], unexpected things do happen. Therefore, this adds a built-in test to ensure that the desired files are actually present in the final image. Right now it only checks the presence of some representative manuals to ensure that the packages listed in the 'missing-docs' file really do get reinstalled, and the documentation that was stripped out in the base image really does get restored. [1] Commit 6d4ecac69f5080be https://github.com/containers/toolbox/pull/1226 https://github.com/containers/toolbox/pull/1226 --- ensure-files | 7 +++++++ 1 file changed, 7 insertions(+) create mode 100644 ensure-files diff --git a/ensure-files b/ensure-files new file mode 100644 index 0000000..4d11969 --- /dev/null +++ b/ensure-files @@ -0,0 +1,7 @@ +/usr/share/man/man1/bash.1* +/usr/share/man/man1/cd.1* +/usr/share/man/man1/export.1* + +/usr/share/man/fr/man8/rpm.8* +/usr/share/man/ja/man8/rpm.8* +/usr/share/man/man8/rpm.8* From 38d38e140e27140eca8e2cc412b29b88b7277f0d Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 20:02:23 +0100 Subject: [PATCH 11/18] Fix up the previous commit Fallout from d6f0488665e3c7a56add516b3689516f54c04e39 --- Dockerfile | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/Dockerfile b/Dockerfile index eaf2512..0136d83 100644 --- a/Dockerfile +++ b/Dockerfile @@ -26,4 +26,18 @@ COPY extra-packages / RUN dnf -y install $(/dev/null; then \ + echo "$file: No such file or directory" >&2; \ + ret_val=1; \ + break; \ + fi; \ + done Date: Wed, 1 Feb 2023 20:18:28 +0100 Subject: [PATCH 12/18] Ensure that the cat(1), cp(1), ls(1), etc. manuals are available https://github.com/containers/toolbox/pull/1226 --- ensure-files | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/ensure-files b/ensure-files index 4d11969..8ce26a7 100644 --- a/ensure-files +++ b/ensure-files @@ -2,6 +2,10 @@ /usr/share/man/man1/cd.1* /usr/share/man/man1/export.1* +/usr/share/man/man1/cat.1* +/usr/share/man/man1/cp.1* +/usr/share/man/man1/ls.1* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* From 63ef4ae48f98d170c16366e9b9fa34a96f203f0c Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Feb 2023 21:59:30 +0100 Subject: [PATCH 13/18] Ensure that the kill(1), mount(8), etc. manuals are available https://github.com/containers/toolbox/pull/1227 --- ensure-files | 3 +++ 1 file changed, 3 insertions(+) diff --git a/ensure-files b/ensure-files index 8ce26a7..24b89a0 100644 --- a/ensure-files +++ b/ensure-files @@ -9,3 +9,6 @@ /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* + +/usr/share/man/man1/kill.1* +/usr/share/man/man8/mount.8* From 1c389e3eb4fcbd21beda2950e5e066c5290b6f61 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 2 Feb 2023 18:33:23 +0100 Subject: [PATCH 14/18] Use the package name instead of a virtual Provides for gnupg2 The package for GnuPG 2.0 has always been called gnupg2 [1], so this must have been a mistake. [1] https://pagure.io/fedora-comps/blob/main/f/comps-f21.xml.in https://github.com/containers/toolbox/pull/1228 --- extra-packages | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/extra-packages b/extra-packages index cdd2aa1..14c9028 100644 --- a/extra-packages +++ b/extra-packages @@ -7,7 +7,7 @@ findutils flatpak-spawn fpaste git -gnupg +gnupg2 gnupg2-smime gvfs-client hostname From 4d60442315a78ca9f856e278d8279b4106d371a9 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Thu, 2 Feb 2023 18:52:02 +0100 Subject: [PATCH 15/18] Ensure that the gpg2(1), gnupg2(7), etc. manuals are available It turns out that at least since Fedora 30 [1], the gnupg2 package has been part of the fedora base image, because it's required by the dnf package: dnf -> python3-dnf -> python3-libdnf -> libdnf -> gpgme -> gnupg2 Hence, the need to restore the gnupg2 documentation that was stripped out in the base image. [1] It's difficult to find out if the gnupg2 package wasn't part of the fedora base image before Fedora 30, because those images are no longer available from registry.fedoraproject.org. https://github.com/containers/toolbox/pull/1228 --- ensure-files | 3 +++ missing-docs | 1 + 2 files changed, 4 insertions(+) diff --git a/ensure-files b/ensure-files index 24b89a0..9693d36 100644 --- a/ensure-files +++ b/ensure-files @@ -6,6 +6,9 @@ /usr/share/man/man1/cp.1* /usr/share/man/man1/ls.1* +/usr/share/man/man1/gpg2.1* +/usr/share/man/man7/gnupg2.7* + /usr/share/man/fr/man8/rpm.8* /usr/share/man/ja/man8/rpm.8* /usr/share/man/man8/rpm.8* diff --git a/missing-docs b/missing-docs index 2350648..b06fdc3 100644 --- a/missing-docs +++ b/missing-docs @@ -4,6 +4,7 @@ coreutils-common curl findutils gawk +gnupg2 grep gzip libcap From 951b464d509feb29ac9cf96097a175e85cc1db63 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Mar 2023 13:21:19 +0100 Subject: [PATCH 16/18] Synchronize with upstream --- README.md | 162 ++++++++---------------------------------------------- 1 file changed, 24 insertions(+), 138 deletions(-) diff --git a/README.md b/README.md index 117528e..6f9943b 100644 --- a/README.md +++ b/README.md @@ -1,7 +1,13 @@ -[Toolbox](https://github.com/containers/toolbox) is a tool for Linux operating -systems, which allows the use of containerized command line environments. It is -built on top of [Podman](https://podman.io/) and other standard container -technologies from [OCI](https://opencontainers.org/). +[Toolbox](https://containertoolbx.org/) is a tool for Linux, which allows the +use of interactive command line environments for development and +troubleshooting the host operating system, without having to install software +on the host. It is built on top of [Podman](https://podman.io/) and other +standard container technologies from [OCI](https://opencontainers.org/). + +Toolbox environments have seamless access to the user's home directory, +the Wayland and X11 sockets, networking (including Avahi), removable devices +(like USB sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the +udev database, etc.. This is particularly useful on [OSTree](https://ostree.readthedocs.io/en/latest/) based operating systems like @@ -10,12 +16,12 @@ This is particularly useful on systems is to discourage installation of software on the host, and instead install software as (or in) containers — they mostly don't even have package managers like DNF or YUM. This makes it difficult to set up a development -environment or install tools for debugging in the usual way. +environment or troubleshoot the operating system in the usual way. Toolbox solves this problem by providing a fully mutable container within -which one can install their favourite development and debugging tools, editors -and SDKs. For example, it's possible to do `yum install ansible` without -affecting the base operating system. +which one can install their favourite development and troubleshooting tools, +editors and SDKs. For example, it's possible to do `yum install ansible` +without affecting the base operating system. However, this tool doesn't *require* using an OSTree based system. It works equally well on Fedora Workstation and Server, and that's a useful way to @@ -23,136 +29,16 @@ incrementally adopt containerization. The toolbox environment is based on an [OCI](https://www.opencontainers.org/) image. On Fedora this is the `fedora-toolbox` image. This image is used to -create a toolbox container that seamlessly integrates with the rest of the -operating system by providing access to the user's home directory, the Wayland -and X11 sockets, networking (including Avahi), removable devices (like USB -sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the udev -database, etc.. +create a toolbox container that offers the interactive command line +environment. + +Note that Toolbox makes no promise about security beyond what's already +available in the usual command line environment on the host that everybody is +familiar with. -## Installation +## Installation & Use -Toolbox is installed by default on Fedora Silverblue. On other operating -systems it's just a matter of installing the `toolbox` package. - -## Usage - -### Create your toolbox container: -```console -[user@hostname ~]$ toolbox create -Created container: fedora-toolbox-33 -Enter with: toolbox enter -[user@hostname ~]$ -``` -This will create a container called `fedora-toolbox-`. - -### Enter the toolbox: -```console -[user@hostname ~]$ toolbox enter -⬢[user@toolbox ~]$ -``` - -### Remove a toolbox container: -```console -[user@hostname ~]$ toolbox rm fedora-toolbox-33 -[user@hostname ~]$ -``` - -## Dependencies and Building - -Toolbox requires at least Podman 1.4.0 to work, and uses the Meson build -system. - -The following dependencies are required to build it: -- meson -- go-md2man -- systemd -- go -- ninja - -The following dependencies enable various optional features: -- bash-completion - -It can be built and installed as any other typical Meson-based project: -```console -[user@hostname toolbox]$ meson -Dprofile_dir=/etc/profile.d builddir -[user@hostname toolbox]$ ninja -C builddir -[user@hostname toolbox]$ sudo ninja -C builddir install -``` - -Toolbox is written in Go. Consult the -[src/go.mod](https://github.com/containers/toolbox/blob/main/src/go.mod) file -for a full list of all the Go dependencies. - -By default, Toolbox uses Go modules and all the required Go packages are -automatically downloaded as part of the build. There's no need to worry about -the Go dependencies, unless the build environment doesn't have network access -or any such peculiarities. - -## Distro support - -By default, Toolbox creates the container using an -[OCI](https://www.opencontainers.org/) image called -`-toolbox:`, where `` and `` are taken from the -host's `/usr/lib/os-release`. For example, the default image on a Fedora 33 -host would be `fedora-toolbox:33`. - -This default can be overridden by the `--image` option in `toolbox create`, -but operating system distributors should provide an adequately configured -default image to ensure a smooth user experience. - -## Image requirements - -Toolbox customizes newly created containers in a certain way. This requires -certain tools and paths to be present and have certain characteristics inside -the OCI image. - -Tools: -* `getent(1)` -* `id(1)` -* `ln(1)` -* `mkdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` -* `passwd(1)` -* `readlink(1)` -* `rm(1)` -* `rmdir(1)`: for hosts where `/home` is a symbolic link to `/var/home` -* `sleep(1)` -* `test(1)` -* `touch(1)` -* `unlink(1)` -* `useradd(8)` -* `usermod(8)` - -Paths: -* `/etc/host.conf`: optional, if present not a bind mount -* `/etc/hosts`: optional, if present not a bind mount -* `/etc/krb5.conf.d`: directory, not a bind mount -* `/etc/localtime`: optional, if present not a bind mount -* `/etc/machine-id`: optional, not a bind mount -* `/etc/resolv.conf`: optional, if present not a bind mount -* `/etc/timezone`: optional, if present not a bind mount - -Toolbox enables `sudo(8)` access inside containers. The following is necessary -for that to work: - -* The image should have `sudo(8)` enabled for users belonging to either the - `sudo` or `wheel` groups, and the group itself should exist. File an - [issue](https://github.com/containers/toolbox/issues/new) if you really need - support for a different group. However, it's preferable to keep this list as - short as possible. - -* The image should allow empty passwords for `sudo(8)`. This can be achieved - by either adding the `nullok` option to the `PAM(8)` configuration, or by - add the `NOPASSWD` tag to the `sudoers(5)` configuration. - -Since Toolbox only works with OCI images that fulfill certain requirements, -it will refuse images that aren't tagged with -`com.github.containers.toolbox="true"` and -`com.github.debarshiray.toolbox="true"` labels. These labels are meant to be -used by the maintainer of the image to indicate that they have read this -document and tested that the image works with Toolbox. You can use the -following snippet in a Dockerfile for this: -```Dockerfile -LABEL com.github.containers.toolbox="true" \ - com.github.debarshiray.toolbox="true" -``` +See our guides on +[installing & getting started](https://containertoolbx.org/install/) with +Toolbox and [Linux distro support](https://containertoolbx.org/distros/). From 0914617155c7e96de178c7c62d01692c0a939cea Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Timoth=C3=A9e=20Ravier?= Date: Thu, 16 Feb 2023 17:35:15 +0100 Subject: [PATCH 17/18] Use ARG instead of ENV to avoid leaking variables We only need those temporary variables for the container build and for the LABELS. We do not want to set those specific environment variables for the container environment itself. Using ARG instead of ENV lets us do that. See: https://github.com/containers/toolbox/issues/188 See: https://github.com/containers/docs/pull/15 --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 0136d83..64692ad 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ FROM registry.fedoraproject.org/fedora:36 -ENV NAME=fedora-toolbox VERSION=36 +ARG NAME=fedora-toolbox VERSION=36 LABEL com.github.containers.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \ From 9ff633d04b94bb37fb3f48374778838c9cc5d060 Mon Sep 17 00:00:00 2001 From: Debarshi Ray Date: Wed, 1 Mar 2023 12:42:54 +0100 Subject: [PATCH 18/18] Attempt to fix the use of ARG ... because the image failed to build with: Error in plugin orchestrate_build: {"x86_64": {"docker_api": "ARG requires exactly one argument"}, "aarch64": {"docker_api": "Dockerfile parse error line 4: ARG requires exactly one argument"}}. Fallout from 0914617155c7e96de178c7c62d01692c0a939cea --- Dockerfile | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 64692ad..3189122 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,7 @@ FROM registry.fedoraproject.org/fedora:36 -ARG NAME=fedora-toolbox VERSION=36 +ARG NAME=fedora-toolbox +ARG VERSION=36 LABEL com.github.containers.toolbox="true" \ com.redhat.component="$NAME" \ name="$NAME" \