Compare commits

..

44 commits

Author SHA1 Message Date
8930a11968 Retire 2023-12-08 00:13:24 +01:00
6c46178bbb Ensure that documentation and translations are present
This should finally ensure that the fedora-toolbox image doesn't have
any package that had its content, such as documentation or translations,
stripped out by the fedora base image.

Until now, missing-docs had a hand-maintained list of packages that had
their content stripped out by the fedora base image.  These packages are
reinstalled when building the fedora-toolbox image to restore the lost
content.  Unfortunately, this list was incomplete because it was only
updated when someone noticed that something is missing.

Now, the list is generated with:
  $ rpm --all --query --state --queryformat "PACKAGE: %{NAME}\n"

... to ensure that it's always complete.

The existing built-in test to ensure that the desired files are actually
present in the final image was extended to cover some of those that were
absent.  A new built-in test, based on the above rpm(1) command, was
added as a fallback to ensure that the final image doesn't have any
package with missing content.

As suggested by Brian Campbell.

Note that the fedora-toolbox OCI image for Fedora 39 onwards is no
longer built using OpenShift Build Service from the Dockerfile here.
It's now being built using Image Factory from fedora-kickstarts and
pungi-fedora [1], as part of the ToolbxReleaseBlocker Change [2] for
Fedora 39.

Hence this is only for the sake of completeness.

[1] https://pagure.io/fedora-kickstarts/
    https://pagure.io/pungi-fedora/

[2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker

https://github.com/containers/toolbox/issues/603
2023-11-01 15:36:23 +01:00
5ff7fd3597 Ensure that the useradd(8), etc. manuals are available
The shadow-utils package has always been part of the fedora base image.
It's explicitly listed in extra-packages as a safeguard against losing
useradd(8) and usermod(8) by mistake because they are needed by the
entry point of a Toolbx container [1].  Hence, the need to restore the
shadow-utils documentation that was stripped out in the base image.

Note that the fedora-toolbox OCI image for Fedora 39 onwards is no
longer built using OpenShift Build Service from the Dockerfile here.
It's now being built using Image Factory from fedora-kickstarts and
pungi-fedora [2], as part of the ToolbxReleaseBlocker Change [3] for
Fedora 39.

Hence this is only for the sake of completeness.

[1] Toolbx commit c6772f0f112e8004
    c6772f0f11

[2] https://pagure.io/fedora-kickstarts/
    https://pagure.io/pungi-fedora/

[3] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker

https://github.com/containers/toolbox/pull/1394
2023-10-27 20:30:14 +02:00
04b26152ae Update the tests
The translations for the RPM manuals were removed upstream during the
RPM 4.19 development cycle [1].  So, replace them with rpm2cpio(8),
which is another popular command shipped by the rpm package.

Note that the fedora-toolbox OCI image for Fedora 39 onwards is no
longer built using OpenShift Build Service from the Dockerfile here.
It's now being built using Image Factory from fedora-kickstarts and
pungi-fedora [2], as part of the ToolbxReleaseBlocker Change [3] for
Fedora 39.

[1] RPM commit 4df74a9644b18136
    4df74a9644
    https://github.com/rpm-software-management/rpm/pull/2245

[2] https://pagure.io/fedora-kickstarts/
    https://pagure.io/pungi-fedora/

[3] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker

https://github.com/containers/toolbox/pull/1391
2023-10-27 20:16:51 +02:00
396de43209 Add psmisc
It's currently being pulled in as a dependency of iproute.  However,
since it's explicitly mentioned in the list of default packages on
Fedora Silverblue and Workstation [1], it should be mentioned here too.

The psmisc package marks the translations for its manuals with %lang().
Therefore, it's a very good example for testing that the fedora-toolbox
image is localized just like Fedora Silverblue and Workstation.

This is unlike the xz package, whose translations for manuals were added
to the tests recently [2].  The xz package doesn't mark its translated
manuals with %lang() [3], which means that they are going to get
installed regardless of whether RPM has been configured to not install
localization files or not.  eg., through the %_install_langs macro.  So,
they aren't a good candidate for the tests until this is fixed.

Note that the fedora-toolbox OCI image for Fedora 39 onwards is no
longer built using OpenShift Build Service from the Dockerfile here.
It's now being built using Image Factory from fedora-kickstarts and
pungi-fedora [4], as part of the ToolbxReleaseBlocker Change [5] for
Fedora 39.

Hence this is only for the sake of completeness.

[1] fedora-comps commit e4ed54dfcc497fd0
    https://pagure.io/fedora-comps/c/e4ed54dfcc497fd0
    https://pagure.io/fedora-comps/pull-request/379

[2] Toolbx commit 20188a097a1a7a16
    20188a097a
    https://github.com/containers/toolbox/pull/1384

[3] https://src.fedoraproject.org/rpms/xz/pull-request/10

[4] https://pagure.io/fedora-kickstarts/
    https://pagure.io/pungi-fedora/

[5] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker

https://github.com/containers/toolbox/pull/1390
2023-10-20 12:08:59 +02:00
00dfa04654 Ensure that the manuals from extra-packages are available
Until now, only the packages that are present in the fedora base image,
and had their documentation stripped out, were being tested for the
availability of documentation.  There were no tests for the extra
packages that get added to the base image to form the fedora-toolbox
image.

The util-linux and xz packages were picked as examples for these new
tests.  The xz package is a particularly good example because it has
translations for its manuals.  It can help test that the fedora-toolbox
image is localized just like Fedora Silverblue and Workstation.

Note that the fedora-toolbox OCI image for Fedora 39 onwards is no
longer built using OpenShift Build Service from the Dockerfile here.
It's now being built using Image Factory from fedora-kickstarts and
pungi-fedora [1], as part of the ToolbxReleaseBlocker Change [2] for
Fedora 39.

Hence this is only for the sake of completeness.

[1] https://pagure.io/fedora-kickstarts/
    https://pagure.io/pungi-fedora/

[2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker

https://github.com/containers/toolbox/pull/1384
2023-10-09 15:49:48 +02:00
3c5e37aee9 Reorder alphabetically
Note that the fedora-toolbox OCI image for Fedora 39 onwards is no
longer built using OpenShift Build Service from the Dockerfile here.
It's now being built using Image Factory from fedora-kickstarts and
pungi-fedora [1], as part of the ToolbxReleaseBlocker Change [2] for
Fedora 39.

Hence this is only for the sake of completeness.

Fallout from a6eb542608

[1] https://pagure.io/fedora-kickstarts/
    https://pagure.io/pungi-fedora/

[2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker

https://github.com/containers/toolbox/pull/1384
2023-10-09 15:48:38 +02:00
dfa4cee904 Attempt to fix the use of ARG
... because the image failed to build with:
  Error in plugin orchestrate_build:
    {"x86_64": {"docker_api": "ARG requires exactly one argument"},
     "aarch64": {"docker_api": "Dockerfile parse error line 4: ARG
                  requires exactly one argument"}}.

Fallout from 77bb135f27
2023-03-01 12:42:54 +01:00
Timothée Ravier
77bb135f27 Use ARG instead of ENV to avoid leaking variables
We only need those temporary variables for the container build and for
the LABELS. We do not want to set those specific environment variables
for the container environment itself.

Using ARG instead of ENV lets us do that.

See: https://github.com/containers/toolbox/issues/188
See: https://github.com/containers/docs/pull/15
2023-02-16 17:35:59 +01:00
e0813a6d6f Bump version to 39 for rawhide 2023-02-14 23:15:51 +01:00
1d328a24ef Synchronize with upstream 2023-02-14 23:11:23 +01:00
a6eb542608 Replace jwhois with whois
Since Fedora 37, the whois package has replaced jwhois as the default
whois(1) implementation [1] on Fedora Silverblue and Workstation.

[1] fedora-comps commit e4bf2706306c219a
    https://pagure.io/fedora-comps/c/e4bf2706306c219a
    https://pagure.io/fedora-comps/pull-request/729
    https://fedoraproject.org/wiki/Changes/Replace_jwhois_with_whois_in_Fedora_Workstation

https://github.com/containers/toolbox/pull/1228
2023-02-02 20:54:30 +01:00
f661837d4d Ensure that the gpg2(1), gnupg2(7), etc. manuals are available
It turns out that at least since Fedora 30 [1], the gnupg2 package has
been part of the fedora base image, because it's required by the dnf
package:
  dnf -> python3-dnf -> python3-libdnf -> libdnf -> gpgme -> gnupg2

Hence, the need to restore the gnupg2 documentation that was stripped
out in the base image.

[1] It's difficult to find out if the gnupg2 package wasn't part of the
    fedora base image before Fedora 30, because those images are no
    longer available from registry.fedoraproject.org.

https://github.com/containers/toolbox/pull/1228
2023-02-02 18:52:02 +01:00
379a48413f Use the package name instead of a virtual Provides for gnupg2
The package for GnuPG 2.0 has always been called gnupg2 [1], so this
must have been a mistake.

[1] https://pagure.io/fedora-comps/blob/main/f/comps-f21.xml.in

https://github.com/containers/toolbox/pull/1228
2023-02-02 18:33:23 +01:00
39f8656075 Ensure that the kill(1), mount(8), etc. manuals are available
https://github.com/containers/toolbox/pull/1227
2023-02-01 21:59:30 +01:00
fbca80d652 Ensure that the cat(1), cp(1), ls(1), etc. manuals are available
https://github.com/containers/toolbox/pull/1226
2023-02-01 20:18:28 +01:00
e8f3f03d0a Fix up the previous commit
Fallout from d6f0488665
2023-02-01 20:02:23 +01:00
d6f0488665 images: Ensure that the desired manuals are indeed present
Building an OCI image leads to so much spew that it's hard to notice if
something unexpected happened, and as seen in the previous commit [1],
unexpected things do happen.

Therefore, this adds a built-in test to ensure that the desired files
are actually present in the final image.  Right now it only checks the
presence of some representative manuals to ensure that the packages
listed in the 'missing-docs' file really do get reinstalled, and the
documentation that was stripped out in the base image really does get
restored.

[1] Commit 6d4ecac69f
    https://github.com/containers/toolbox/pull/1226

https://github.com/containers/toolbox/pull/1226
2023-02-01 19:57:32 +01:00
6d4ecac69f Avoid unexpected DNF behaviour when reinstalling or swapping
The RPM packages in the base 'fedora' image can be older than the those
currently available in the DNF 'updates' repository [1], but at the same
time newer than those available in the DNF 'fedora' repository [1].  The
first part happens because the base image isn't updated as often as the
individual packages, so the 'updates' repository can have newer RPMs.
The second part happens because the base image does get updated after a
stable Fedora has been released, and hence can have newer RPMs than the
'fedora' repository.

This is complicated by the fact that packages can get pulled directly
from Fedora's Koji build system into the base 'fedora' image before
they make it to one of the well-known repositories like 'fedora' or
'updates' [1].  These packages are marked as having come from the
koji-override-0 repository.

All that combined can lead to unexpected behaviour when DNF is invoked
to reinstall or swap the RPM packages in the base image.  Some examples
below.

The base fedora:36 image contains glibc-minimal-langpack-2.35-20.fc36
that came from koji-override-0, while 'fedora' and 'updates' have
glibc-all-langpacks-2.35-4.fc36 and glibc-all-langpacks-2.35-22.fc36
respectively.  This leads to:
  STEP 8/15: RUN dnf -y swap glibc-minimal-langpack glibc-all-langpacks
  Last metadata expiration check: 0:00:03 ago on Wed Feb  1 12:37:04...
  Dependencies resolved.
  ======================================================================
   Package                   Arch      Version          Repository
  ======================================================================
  Installing:
   glibc-all-langpacks       x86_64    2.35-4.fc36      fedora
  Removing:
   glibc-minimal-langpack    x86_64    2.35-20.fc36     @koji-override-0
  Downgrading:
   glibc                     x86_64    2.35-4.fc36      fedora
   glibc-common              x86_64    2.35-4.fc36      fedora

That's unexpected.  Instead of upgrading all the glibc sub-packages to
the latest version from 'updates', it's downgrading them to the older
version from 'fedora'.

Similarly, the base fedora:36 image has bash-5.2.9-2.fc36.x86_64 from
koji-override-0, and there is bash-5.2.15-1.fc36.x86_64 in 'updates'.
This leads to:
  STEP 10/15: RUN dnf -y reinstall $(<missing-docs)
  Last metadata expiration check: 0:00:06 ago on Wed Feb  1 12:37:04...
  Package acl available, but not installed.
  No match for argument: acl
  Installed package bash-5.2.9-2.fc36.x86_64 (from koji-override-0) not
    available.

That's unexpected.  Instead of upgrading bash to the latest version from
'updates', it's simply skipping the 'reinstall', which means that the
documentation that was stripped out in the base image doesn't get
restored.

Updating all the RPM packages in the base 'fedora' image to match the
contents of the 'updates' repository before making any changes to the
image's package set will avoid such unexpected behaviour.

[1] https://docs.fedoraproject.org/en-US/quick-docs/repositories/

https://github.com/containers/toolbox/pull/1226
2023-02-01 19:53:56 +01:00
e931fd05a5 Ensure that the sudo(8), sudoers(5), etc. manuals are available
https://github.com/containers/toolbox/pull/1068
https://github.com/containers/toolbox/pull/1133
2023-02-01 01:41:11 +01:00
0168da1191 Enable OpenGL and Vulkan for hardware with free drivers
https://github.com/containers/toolbox/issues/1110
2023-02-01 01:34:01 +01:00
c1c17b28a6 Remove RPM configuration to strip out translations
Note that this doesn't restore the translations that were stripped out
from the base fedora image.  It only ensures that subsequent RPM
transactions retain the translations.

https://github.com/containers/toolbox/issues/60
2023-02-01 01:33:17 +01:00
b8912160a7 Ensure that all the glibc language packs are available
... and not just C, POSIX and C.UTF-8.

https://github.com/containers/toolbox/issues/60
2023-02-01 00:30:35 +01:00
ae36f4f679 Removed deprecated com.github.debarshiray.toolbox tag
https://github.com/containers/toolbox/pull/820
2023-02-01 00:23:16 +01:00
Jens Petersen
805dc32c28 missing-docs: add util-linux-core 2022-12-13 18:19:13 +08:00
Jens Petersen
32bf967e6d bump version to 38 2022-08-12 15:27:43 +08:00
Jens Petersen
64b6d607e9 findutils missing docs 2022-08-09 14:24:49 +08:00
Jens Petersen
77bce0df24 try removing autorebuild config to unbreak OBS build
see https://pagure.io/releng/issue/10658
2022-03-08 15:25:53 +08:00
Jens Petersen
94f0cc793b bump fedora version to 37 2022-02-11 11:07:52 +08:00
b2d0ebbad6 Make locate(1) opt-in by default
Currently, the entry point of a Toolbox container runs updatedb(8) on
start-up, which can be very I/O intensive. This might be a hindrance
when troubleshooting performance problems on a host, or when
re-creating containers somewhat more frequently.

Users can install the mlocate RPM and restart their containers to
enable locate(1).

https://github.com/containers/toolbox/pull/938
2021-12-01 16:55:15 +01:00
74393208c3 Remove misleading and redundant CMD
There's no need to specify a CMD in a Toolbox image because it's
specified by 'toolbox create', through 'podman create', when creating a
container.

A CMD was specified [1] because the Fedora Container Guidelines
requires it [2]. The idea behind the guidelines is that the right
thing should happen when one runs:
  $ podman run <image>

However, that only makes sense for images targeting single service
containers. Toolbox containers and images are different - they are not
meant to be used like that to run a single one-off service.

Conceptually, 'running' a Toolbox container is expected to provide the
user with a reasonable interactive command line experience. Arguably,
that means offering something like /bin/bash, not /bin/sh.

Also, note that when the CMD was introduced [1], Toolbox containers
were actually created, through 'podman create', with /bin/sh as their
entry points. So, it did make some sense. However, things have changed
since then [3]. The entry point is now 'toolbox init-container'. It's
not possible to mention it in the Toolbox image because the
/usr/bin/toolbox binary isn't present in the image, and it's not meant
to be present.

Therefore, today, /bin/sh is simply not the right fit for a Toolbox
image's CMD. A better option would be /bin/bash.

Note that the fedora base images have their CMD set to /bin/bash, which
is inherited by the fedora-toolbox images.

So, there are two options. Either repeat the same CMD in the
fedora-toolbox images and satisfy the guidelines, or take some
liberties and let the CMD be inherited from the fedora base images.

This commit takes the latter option. People tend to use the
fedora-toolbox images as the starting point for other custom Toolbox
images, sometimes for other operating system distributions. It's
better to keep them minimal to avoid implying extra requirements. In
this case, the CMD is an abstract concept, and the actual entry point
is 'toolbox init-container' as specified by 'toolbox create'.
Specifying /bin/bash might discourage people from creating custom
images that are only meant to have /bin/zsh.

Also, note that the current CMD was actually '/bin/sh -c /bin/sh', not
/bin/sh. Unless a CMD is specified as an array of command line
arguments, it's passed as a single argument to '/bin/sh -c' [4]. So,
this:
  CMD foo bar

... is the same as:
  CMD [ "/bin/sh", "-c", "foo bar" ]

[1] Toolbox commit 5cc2678a3677af44
    5cc2678a36

[2] https://docs.fedoraproject.org/en-US/containers/guidelines/creation/

[3] Toolbox commit 8b84b5e4604921fa
    https://github.com/containers/toolbox/pull/160

[4] https://docs.docker.com/engine/reference/builder/#cmd

https://github.com/containers/toolbox/issues/885
2021-12-01 15:20:49 +01:00
c5af06ead0 extra-packages: Avoid losing mount(8) by accident
The util-linux package was added to ensure the presence of the mount(8)
command. Currently the package is already pulled in by various
dependencies. Therefore, it doesn't increase the size of the image, but
serves as a safeguard against any inadvertent changes.

Note that starting from Fedora 35 onwards, the fedora base images no
longer have mount(8), which increases the importance of this change.

https://github.com/containers/toolbox/issues/929
2021-11-25 19:48:38 +01:00
9057055b44 Ensure that coreutils-single is replaced by coreutils-full
It's true that the fedora base images no longer come with
coreutils-single, but they used to, and the ubi base images still do.
Therefore, it's worth being extra defensive about this.

It's better to make the build system execute one extra redundant
command than expose users to a bug because of a change that snuck in
unnoticed.

This reverts commit a2171d8742.

https://github.com/containers/toolbox/pull/931
2021-11-25 19:46:14 +01:00
Oliver Gutierrez
ae4a7842b4
Fixed autorebuild configuration 2021-09-09 12:03:31 +01:00
Oliver Gutierrez
40a5f298f9
Activated automatic rebuilds 2021-09-09 11:51:43 +01:00
Jens Petersen
98d9106a1f add coreutils-common to missing docs 2021-09-04 00:35:54 +08:00
Jens Petersen
ae16371775 Rawhide version is now 36 2021-08-12 11:42:51 +08:00
Oliver Gutierrez
f131a12ec5
Added iproute package 2021-07-09 10:06:48 +01:00
Oliver Gutierrez
030ad6d052
Reverted changes in README.md 2021-06-29 16:46:38 +01:00
Oliver Gutierrez
692c49780c
Reverted renaming of Dockerfile 2021-06-29 16:03:09 +01:00
Oliver Gutierrez
7105bdf49e
Renamed Dockerfile to Containerfile and updated README.md 2021-06-29 16:00:33 +01:00
085c05199b Add bc and update README.md 2021-06-29 16:19:55 +02:00
Otto Urpelainen
8ad99234bd Include the nano default editor
Since Fedora 33, `nano` is the default editor[0]. It needs to be
included in the fedora-toolbox image to have the standard Fedora
experience inside the container.

https://fedoraproject.org/wiki/Changes/UseNanoByDefault).
2021-03-10 11:31:22 +01:00
Jens Petersen
8d796028ba rawhide is now Fedora 35 2021-02-19 12:07:10 +08:00
5 changed files with 9 additions and 244 deletions

View file

@ -1,26 +0,0 @@
FROM registry.fedoraproject.org/fedora:34
ENV NAME=fedora-toolbox VERSION=34
LABEL com.github.containers.toolbox="true" \
com.github.debarshiray.toolbox="true" \
com.redhat.component="$NAME" \
name="$NAME" \
version="$VERSION" \
usage="This image is meant to be used with the toolbox command" \
summary="Base image for creating Fedora toolbox containers" \
maintainer="Debarshi Ray <rishi@fedoraproject.org>"
COPY README.md /
RUN sed -i '/tsflags=nodocs/d' /etc/dnf/dnf.conf
RUN dnf -y swap coreutils-single coreutils-full
COPY missing-docs /
RUN dnf -y reinstall $(<missing-docs)
RUN rm /missing-docs
COPY extra-packages /
RUN dnf -y install $(<extra-packages)
RUN rm /extra-packages
RUN dnf clean all

158
README.md
View file

@ -1,158 +0,0 @@
[Toolbox](https://github.com/containers/toolbox) is a tool for Linux operating
systems, which allows the use of containerized command line environments. It is
built on top of [Podman](https://podman.io/) and other standard container
technologies from [OCI](https://opencontainers.org/).
This is particularly useful on
[OSTree](https://ostree.readthedocs.io/en/latest/) based operating systems like
[Fedora CoreOS](https://coreos.fedoraproject.org/) and
[Silverblue](https://silverblue.fedoraproject.org/). The intention of these
systems is to discourage installation of software on the host, and instead
install software as (or in) containers — they mostly don't even have package
managers like DNF or YUM. This makes it difficult to set up a development
environment or install tools for debugging in the usual way.
Toolbox solves this problem by providing a fully mutable container within
which one can install their favourite development and debugging tools, editors
and SDKs. For example, it's possible to do `yum install ansible` without
affecting the base operating system.
However, this tool doesn't *require* using an OSTree based system. It works
equally well on Fedora Workstation and Server, and that's a useful way to
incrementally adopt containerization.
The toolbox environment is based on an [OCI](https://www.opencontainers.org/)
image. On Fedora this is the `fedora-toolbox` image. This image is used to
create a toolbox container that seamlessly integrates with the rest of the
operating system by providing access to the user's home directory, the Wayland
and X11 sockets, networking (including Avahi), removable devices (like USB
sticks), systemd journal, SSH agent, D-Bus, ulimits, /dev and the udev
database, etc..
## Installation
Toolbox is installed by default on Fedora Silverblue. On other operating
systems it's just a matter of installing the `toolbox` package.
## Usage
### Create your toolbox container:
```console
[user@hostname ~]$ toolbox create
Created container: fedora-toolbox-33
Enter with: toolbox enter
[user@hostname ~]$
```
This will create a container called `fedora-toolbox-<version-id>`.
### Enter the toolbox:
```console
[user@hostname ~]$ toolbox enter
⬢[user@toolbox ~]$
```
### Remove a toolbox container:
```console
[user@hostname ~]$ toolbox rm fedora-toolbox-33
[user@hostname ~]$
```
## Dependencies and Building
Toolbox requires at least Podman 1.4.0 to work, and uses the Meson build
system.
The following dependencies are required to build it:
- meson
- go-md2man
- systemd
- go
- ninja
The following dependencies enable various optional features:
- bash-completion
It can be built and installed as any other typical Meson-based project:
```console
[user@hostname toolbox]$ meson -Dprofile_dir=/etc/profile.d builddir
[user@hostname toolbox]$ ninja -C builddir
[user@hostname toolbox]$ sudo ninja -C builddir install
```
Toolbox is written in Go. Consult the
[src/go.mod](https://github.com/containers/toolbox/blob/main/src/go.mod) file
for a full list of all the Go dependencies.
By default, Toolbox uses Go modules and all the required Go packages are
automatically downloaded as part of the build. There's no need to worry about
the Go dependencies, unless the build environment doesn't have network access
or any such peculiarities.
## Distro support
By default, Toolbox creates the container using an
[OCI](https://www.opencontainers.org/) image called
`<ID>-toolbox:<VERSION-ID>`, where `<ID>` and `<VERSION-ID>` are taken from the
host's `/usr/lib/os-release`. For example, the default image on a Fedora 33
host would be `fedora-toolbox:33`.
This default can be overridden by the `--image` option in `toolbox create`,
but operating system distributors should provide an adequately configured
default image to ensure a smooth user experience.
## Image requirements
Toolbox customizes newly created containers in a certain way. This requires
certain tools and paths to be present and have certain characteristics inside
the OCI image.
Tools:
* `getent(1)`
* `id(1)`
* `ln(1)`
* `mkdir(1)`: for hosts where `/home` is a symbolic link to `/var/home`
* `passwd(1)`
* `readlink(1)`
* `rm(1)`
* `rmdir(1)`: for hosts where `/home` is a symbolic link to `/var/home`
* `sleep(1)`
* `test(1)`
* `touch(1)`
* `unlink(1)`
* `useradd(8)`
* `usermod(8)`
Paths:
* `/etc/host.conf`: optional, if present not a bind mount
* `/etc/hosts`: optional, if present not a bind mount
* `/etc/krb5.conf.d`: directory, not a bind mount
* `/etc/localtime`: optional, if present not a bind mount
* `/etc/machine-id`: optional, not a bind mount
* `/etc/resolv.conf`: optional, if present not a bind mount
* `/etc/timezone`: optional, if present not a bind mount
Toolbox enables `sudo(8)` access inside containers. The following is necessary
for that to work:
* The image should have `sudo(8)` enabled for users belonging to either the
`sudo` or `wheel` groups, and the group itself should exist. File an
[issue](https://github.com/containers/toolbox/issues/new) if you really need
support for a different group. However, it's preferable to keep this list as
short as possible.
* The image should allow empty passwords for `sudo(8)`. This can be achieved
by either adding the `nullok` option to the `PAM(8)` configuration, or by
add the `NOPASSWD` tag to the `sudoers(5)` configuration.
Since Toolbox only works with OCI images that fulfill certain requirements,
it will refuse images that aren't tagged with
`com.github.containers.toolbox="true"` and
`com.github.debarshiray.toolbox="true"` labels. These labels are meant to be
used by the maintainer of the image to indicate that they have read this
document and tested that the image works with Toolbox. You can use the
following snippet in a Dockerfile for this:
```Dockerfile
LABEL com.github.containers.toolbox="true" \
com.github.debarshiray.toolbox="true"
```

9
dead.container Normal file
View file

@ -0,0 +1,9 @@
The fedora-toolbox OCI image for Fedora 39 onwards is no longer built using
OpenShift Build Service from the Dockerfile here. It's now being built using
Image Factory from fedora-kickstarts and pungi-fedora [1], as part of the
ToolbxReleaseBlocker Change [2] for Fedora 39.
[1] https://pagure.io/fedora-kickstarts/
https://pagure.io/pungi-fedora/
[2] https://fedoraproject.org/wiki/Changes/ToolbxReleaseBlocker

View file

@ -1,45 +0,0 @@
bash-completion
bc
bzip2
diffutils
dnf-plugins-core
findutils
flatpak-spawn
fpaste
git
gnupg
gnupg2-smime
gvfs-client
hostname
iproute
iputils
jwhois
keyutils
krb5-libs
less
lsof
man-db
man-pages
mtr
nano-default-editor
nss-mdns
openssh-clients
passwd
pigz
procps-ng
rsync
shadow-utils
sudo
tcpdump
time
traceroute
tree
unzip
util-linux
vte-profile
wget
which
words
xorg-x11-xauth
xz
zip

View file

@ -1,15 +0,0 @@
acl
bash
curl
gawk
grep
gzip
libcap
openssl
p11-kit
pam
python3
rpm
sed
systemd
tar