diff --git a/.fmf/version b/.fmf/version deleted file mode 100644 index d00491f..0000000 --- a/.fmf/version +++ /dev/null @@ -1 +0,0 @@ -1 diff --git a/.gitignore b/.gitignore index 523a91e..a935d69 100644 --- a/.gitignore +++ b/.gitignore @@ -219,27 +219,3 @@ /v2.221.1.tar.gz /v2.222.0.tar.gz /v2.224.0.tar.gz -/v2.226.0.tar.gz -/v2.227.0.tar.gz -/v2.228.0.tar.gz -/v2.228.1.tar.gz -/v2.229.0.tar.gz -/v2.229.1.tar.gz -/v2.230.0.tar.gz -/v2.231.0.tar.gz -/packit-tmt-bodhi-reuse.zip -/v2.232.1.tar.gz -/v2.233.0.tar.gz -/v2.234.1.tar.gz -/v2.234.2.tar.gz -/v2.235.0.tar.gz -/v2.236.0.tar.gz -/v2.237.0.tar.gz -/v2.238.0.tar.gz -/v2.239.0.tar.gz -/v2.240.0.tar.gz -/v2.241.0.tar.gz -/v2.242.0.tar.gz -/v2.243.0.tar.gz -/v2.244.0.tar.gz -/v2.245.0.tar.gz diff --git a/.packit.yaml b/.packit.yaml index d25d664..6f84a58 100644 --- a/.packit.yaml +++ b/.packit.yaml @@ -2,78 +2,30 @@ # See the documentation for more information: # https://packit.dev/docs/configuration/ -downstream_package_name: container-selinux +specfile_path: rpm/container-selinux.spec upstream_tag_template: v{version} -# Ref: https://packit.dev/docs/configuration#files_to_sync -files_to_sync: - - src: rpm/gating.yaml - dest: gating.yaml - delete: true - - src: plans/ - dest: plans/ - delete: true - mkpath: true - - src: test/ - dest: test/ - delete: true - mkpath: true - - src: .fmf/ - dest: .fmf/ - delete: true - - .packit.yaml - -packages: - container-selinux-fedora: - pkg_tool: fedpkg - specfile_path: rpm/container-selinux.spec - container-selinux-centos: - pkg_tool: centpkg - specfile_path: rpm/container-selinux.spec - container-selinux-eln: - specfile_path: rpm/container-selinux.spec - srpm_build_deps: - make jobs: - job: copr_build trigger: pull_request - packages: [container-selinux-fedora] - notifications: &copr_build_failure_notification + notifications: failure_comment: message: "Ephemeral COPR build failed. @containers/packit-build please check." enable_net: true # container-selinux is noarch so we only need to test on one arch - targets: &fedora_copr_targets - - fedora-all-x86_64 - - fedora-all-aarch64 - - - job: copr_build - trigger: pull_request - packages: [container-selinux-eln] - notifications: *copr_build_failure_notification - enable_net: true - targets: &eln_copr_targets - - fedora-eln-x86_64 - - fedora-eln-aarch64 - - - job: copr_build - trigger: pull_request - packages: [container-selinux-centos] - notifications: *copr_build_failure_notification - enable_net: true - targets: ¢os_copr_targets - - centos-stream-9-x86_64 - - centos-stream-9-aarch64 - - centos-stream-10-x86_64 - - centos-stream-10-aarch64 + targets: + - fedora-all + - fedora-eln + - epel-9 + - epel-8 # Run on commit to main branch # Build targets managed in copr settings - job: copr_build trigger: commit - packages: [container-selinux-fedora] notifications: failure_comment: message: "podman-next COPR build failed. @containers/packit-build please check." @@ -83,63 +35,67 @@ jobs: enable_net: true # All tests specified in the `/plans/` subdir - # Tests for Fedora + # Podman e2e tests for Fedora and CentOS Stream - job: tests trigger: pull_request - packages: [container-selinux-fedora] - notifications: &test_failure_notification + notifications: failure_comment: - message: "Tests failed. @containers/packit-build please check." - targets: *fedora_copr_targets - tf_extra_params: - environments: - - artifacts: - - type: repository-file - id: https://copr.fedorainfracloud.org/coprs/rhcontainerbot/podman-next/repo/fedora-$releasever/rhcontainerbot-podman-next-fedora-$releasever.repo - - # Tests for Fedora - - job: tests - trigger: pull_request - packages: [container-selinux-eln] - notifications: *test_failure_notification - targets: *eln_copr_targets - tf_extra_params: - environments: - - artifacts: - - type: repository-file - id: https://copr.fedorainfracloud.org/coprs/rhcontainerbot/podman-next/repo/fedora-eln/rhcontainerbot-podman-next-fedora-eln.repo - - # Tests for CentOS Stream - - job: tests - trigger: pull_request - packages: [container-selinux-centos] - notifications: *test_failure_notification - targets: *centos_copr_targets - tf_extra_params: - environments: - - artifacts: - - type: repository-file - id: https://copr.fedorainfracloud.org/coprs/rhcontainerbot/podman-next/repo/centos-stream-$releasever/rhcontainerbot-podman-next-centos-stream-$releasever.repo - - - job: propose_downstream - trigger: release - packages: [container-selinux-fedora] - dist_git_branches: &fedora_targets + message: "podman e2e tests failed. @containers/packit-build please check." + targets: &pr_test_targets - fedora-all + - epel-9 + - epel-8 + identifier: podman_e2e_test + tmt_plan: "/plans/podman_e2e_test" + + # Podman system tests for Fedora and CentOS Stream + - job: tests + trigger: pull_request + notifications: + failure_comment: + message: "podman system tests failed. @containers/packit-build please check." + targets: *pr_test_targets + identifier: podman_system_test + tmt_plan: "/plans/podman_system_test" + + # Podman e2e tests for RHEL + - job: tests + trigger: pull_request + use_internal_tf: true + notifications: + failure_comment: + message: "podman e2e tests failed on RHEL. @containers/packit-build please check." + targets: &pr_test_targets_rhel + epel-9-x86_64: + distros: [RHEL-9.2.0-Nightly] + epel-8-x86_64: + distros: [RHEL-8.10.0-Nightly] + identifier: podman_e2e_test_internal + tmt_plan: "/plans/podman_e2e_test" + + # Podman system tests for RHEL + - job: tests + trigger: pull_request + use_internal_tf: true + notifications: + failure_comment: + message: "podman system tests failed on RHEL. @containers/packit-build please check." + targets: *pr_test_targets_rhel + identifier: podman_system_test_internal + tmt_plan: "/plans/podman_system_test" - job: propose_downstream trigger: release - packages: [container-selinux-centos] + update_release: false dist_git_branches: - - c10s + - fedora-all - job: koji_build trigger: commit - packages: [container-selinux-fedora] - dist_git_branches: *fedora_targets + dist_git_branches: + - fedora-all - job: bodhi_update trigger: commit - packages: [container-selinux-fedora] dist_git_branches: - fedora-branched # rawhide updates are created automatically diff --git a/README.packit b/README.packit index db537f9..327dfec 100644 --- a/README.packit +++ b/README.packit @@ -1,3 +1,3 @@ This repository is maintained by packit. https://packit.dev/ -The file was generated using packit 1.13.0. +The file was generated using packit 0.83.0.post1.dev4+g46d87465. diff --git a/container-selinux.spec b/container-selinux.spec index 6348202..3c995a5 100644 --- a/container-selinux.spec +++ b/container-selinux.spec @@ -2,6 +2,7 @@ # container-selinux stuff (prefix with ds_ for version/release etc.) # Some bits borrowed from the openstack-selinux package +%global selinuxtype targeted %global moduletype services %global modulenames container @@ -10,32 +11,29 @@ # Format must contain '$x' somewhere to do anything useful %global _format() export %1=""; for x in %{modulenames}; do %1+=%2; %1+=" "; done; -# RHEL < 10 and Fedora < 40 use file context entries in /var/run -%if %{defined rhel} && 0%{?rhel} < 10 || %{defined fedora} && 0%{?fedora} < 40 -%define legacy_var_run 1 +# RHEL 8 doesn't allow watch and systemd_chat_resolved +%if %{defined rhel} && 0%{?rhel} == 8 +%define no_watch 1 +%define no_systemd_chat_resolved 1 +%global _selinux_policy_version 3.14.3-80.el8 %endif # https://github.com/containers/container-selinux/issues/203 -%if %{!defined fedora} && %{!defined rhel} || %{defined rhel} && 0%{?rhel} <= 9 +%if %{!defined fedora} && %{!defined rhel} || %{defined fedora} && 0%{?fedora} <= 37 || %{defined rhel} && 0%{?rhel} <= 9 %define no_user_namespace 1 %endif -# set copr_build is more intuitive than copr_username -%if %{defined copr_username} && "%{copr_username}" == "rhcontainerbot" && "%{copr_projectname}" == "podman-next" -%define next_build 1 -%endif - Name: container-selinux -# Set different Epoch for rhcontainerbot/podman-next copr build -%if %{defined next_build} +# Set different Epochs for copr and koji +%if %{defined copr_username} Epoch: 102 %else -Epoch: 4 +Epoch: 2 %endif # Keep Version in upstream specfile at 0. It will be automatically set # to the correct value by Packit for copr and koji builds. # IGNORE this comment if you're looking at it in dist-git. -Version: 2.245.0 +Version: 2.224.0 Release: %autorelease License: GPL-2.0-only URL: https://github.com/containers/%{name} @@ -50,8 +48,7 @@ BuildRequires: selinux-policy-devel >= %_selinux_policy_version # RE: rhbz#1195804 - ensure min NVR for selinux-policy Requires: selinux-policy >= %_selinux_policy_version Requires(post): selinux-policy-base >= %_selinux_policy_version -Requires(post): selinux-policy-any >= %_selinux_policy_version -Recommends: selinux-policy-targeted >= %_selinux_policy_version +Requires(post): selinux-policy-targeted >= %_selinux_policy_version Requires(post): policycoreutils Requires(post): libselinux-utils Requires(post): sed @@ -70,12 +67,18 @@ SELinux policy modules for use with container runtimes. sed -i 's/^man: install-policy/man:/' Makefile sed -i 's/^install: man/install:/' Makefile -%if %{defined no_user_namespace} -sed -i '/user_namespace/d' container.te +%if %{defined no_watch} +sed -i 's/watch watch_reads//' container.if +sed -i 's/watch watch_reads//' container.te +sed -i '/sysfs_t:dir watch/d' container.te %endif -%if %{defined legacy_var_run} -sed -i 's|^/run/|/var/run/|' container.fc +%if %{defined no_systemd_chat_resolved} +sed -i '/^systemd_chat_resolved/d' container.te +%endif + +%if %{defined no_user_namespace} +sed -i '/user_namespace/d' container.te %endif %build @@ -86,8 +89,11 @@ make %_format MODULES $x.pp.bz2 %{__make} DATADIR=%{buildroot}%{_datadir} SYSCONFDIR=%{buildroot}%{_sysconfdir} install install.udica-templates install.selinux-user +# Ref: https://bugzilla.redhat.com/show_bug.cgi?id=2209120 +rm %{buildroot}%{_mandir}/man8/container_selinux.8 + %pre -%selinux_relabel_pre +%selinux_relabel_pre -s %{selinuxtype} %post # Install all modules in a single transaction @@ -95,24 +101,21 @@ if [ $1 -eq 1 ]; then %{_sbindir}/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi %_format MODULES %{_datadir}/selinux/packages/$x.pp.bz2 +%{_sbindir}/semodule -n -s %{selinuxtype} -r container 2> /dev/null +%{_sbindir}/semodule -n -s %{selinuxtype} -d docker 2> /dev/null +%{_sbindir}/semodule -n -s %{selinuxtype} -d gear 2> /dev/null +%selinux_modules_install -s %{selinuxtype} $MODULES . %{_sysconfdir}/selinux/config -%{_sbindir}/semodule -n -s ${SELINUXTYPE} -r container 2> /dev/null -%{_sbindir}/semodule -n -s ${SELINUXTYPE} -d docker 2> /dev/null -%{_sbindir}/semodule -n -s ${SELINUXTYPE} -d gear 2> /dev/null -%selinux_modules_install -s ${SELINUXTYPE} $MODULES sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV %{_sharedstatedir}/containers || restorecon -R %{_sharedstatedir}/containers &> /dev/null || : %postun if [ $1 -eq 0 ]; then - %selinux_modules_uninstall %{modulenames} docker + %selinux_modules_uninstall -s %{selinuxtype} %{modulenames} docker fi %posttrans -%selinux_relabel_post - -# Empty placeholder check to silence rpmlint -%check +%selinux_relabel_post -s %{selinuxtype} #define license tag if not already defined %{!?_licensedir:%global license %doc} @@ -122,14 +125,12 @@ fi %{_datadir}/selinux/* %dir %{_datadir}/containers/selinux %{_datadir}/containers/selinux/contexts -%dir %{_datadir}/udica %dir %{_datadir}/udica/templates/ %{_datadir}/udica/templates/* # Ref: https://bugzilla.redhat.com/show_bug.cgi?id=2209120 -%{_mandir}/man8/container_selinux.8.gz -%{_sysconfdir}/selinux/targeted/contexts/users/container_u -%ghost %verify(not mode) %{_selinux_store_path}/targeted/active/modules/200/%{modulenames} -%ghost %verify(not mode) %{_selinux_store_path}/mls/active/modules/200/%{modulenames} +#%%{_mandir}/man8/container_selinux.8.gz +%{_sysconfdir}/selinux/targeted/contexts/users/* +%ghost %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{modulenames} %triggerpostun -- container-selinux < 2:2.162.1-3 if %{_sbindir}/selinuxenabled ; then diff --git a/gating.yaml b/gating.yaml index c692db7..c2182c7 100644 --- a/gating.yaml +++ b/gating.yaml @@ -1,14 +1,6 @@ --- !Policy product_versions: - fedora-* -decision_contexts: - - bodhi_update_push_stable - - bodhi_update_push_testing +decision_context: bodhi_update_push_stable rules: - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.tier0.functional} - ---- !Policy -product_versions: - - rhel-* -decision_context: osci_compose_gate -rules: [] diff --git a/plans/main.fmf b/plans/main.fmf deleted file mode 100644 index c758669..0000000 --- a/plans/main.fmf +++ /dev/null @@ -1,30 +0,0 @@ -discover: - how: fmf -execute: - how: tmt -prepare: - - how: feature - epel: enabled - # TODO: Revisit this once https://github.com/teemtee/tmt/issues/3990 is in place. - # FIXME: For whatever reason, CentOS Stream envs end up upgrading container-selinux - # from podman-next instead of using the one installed by Packit. This apparently should - # be easier to handle once tmt#3990 is done. Things work as expected on Fedora already. - - when: initiator == packit - how: shell - script: | - COPR_REPO_FILE="/etc/yum.repos.d/*podman-next*.repo" - if compgen -G $COPR_REPO_FILE > /dev/null; then - sed -i -n '/^priority=/!p;$apriority=1' $COPR_REPO_FILE - fi - -/basic_check: - discover+: - test: /test/basic_check - -/podman_rootful_system: - discover+: - test: /test/podman_rootful_system - -/podman_rootless_system: - discover+: - test: /test/podman_rootless_system diff --git a/plans/tmt.fmf b/plans/tmt.fmf deleted file mode 100644 index 1941978..0000000 --- a/plans/tmt.fmf +++ /dev/null @@ -1,9 +0,0 @@ -/: - inherit: false - -summary: Run tmt's integration tests -plan: - import: - url: https://github.com/teemtee/tmt - path: /plans/friends - name: /podman diff --git a/sources b/sources index ce107a4..2eec748 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (v2.245.0.tar.gz) = 0bc85980780631ceccb38f2fde64ff7f3792be18d4501806532f097deedde70f446e2389c543dd78e9087b45cd1a6916c0e096e6ea42dd77ac377ad4111b7db2 +SHA512 (v2.224.0.tar.gz) = ab838c379aae99347c5d49ef84513c5fa1cd03faf1ab6b1dd4b6c571875c7c9df389abfb41ce0e2c2a57e14d11c47cbac85e2a6ad8004c2db6087849d91282aa diff --git a/test/main.fmf b/test/main.fmf deleted file mode 100644 index 741aef1..0000000 --- a/test/main.fmf +++ /dev/null @@ -1,34 +0,0 @@ -require: - - attr - - container-selinux - - podman-tests - - policycoreutils -recommend: - - bats - -/basic_check: - summary: Run basic checks - test: | - semodule --list=full | grep container - semodule -B - rpm -Vqf /var/lib/selinux/*/active/modules/200/container - -/podman_rootful_system: - summary: Run SELinux specific Podman system tests - test: bash ./podman-rootful-tests.sh - -/podman_rootless_system: - summary: Run rootless Podman system tests - test: bash ./podman-rootless-tests.sh - require+: - - passt - - passt-selinux - environment: - ROOTLESS_USER: "fedora" - adjust: - - when: distro == centos-stream - environment+: - ROOTLESS_USER: "ec2-user" - - when: distro == rhel - environment+: - ROOTLESS_USER: "cloud-user" diff --git a/test/podman-rootful-tests.sh b/test/podman-rootful-tests.sh deleted file mode 100644 index faa504b..0000000 --- a/test/podman-rootful-tests.sh +++ /dev/null @@ -1,16 +0,0 @@ -#!/usr/bin/env bash - -set -exo pipefail - -cat /etc/redhat-release - -if [[ "$(id -u)" -ne 0 ]];then - echo "Please run as superuser" - exit 1 -fi - -# Print versions of distro and installed packages -rpm -q bats container-selinux podman podman-tests policycoreutils selinux-policy - -# Run podman system tests -bats /usr/share/podman/test/system/410-selinux.bats diff --git a/test/podman-rootless-tests.sh b/test/podman-rootless-tests.sh deleted file mode 100644 index e5583e0..0000000 --- a/test/podman-rootless-tests.sh +++ /dev/null @@ -1,15 +0,0 @@ -#!/usr/bin/env bash - -set -exo pipefail - -cat /etc/redhat-release - -# Print versions of distro and installed packages -rpm -q bats container-selinux passt passt-selinux podman podman-tests policycoreutils selinux-policy - -loginctl enable-linger "$ROOTLESS_USER" - -# Run podman system tests -su - "$ROOTLESS_USER" -c "bats /usr/share/podman/test/system/410-selinux.bats" -su - "$ROOTLESS_USER" -c "bats /usr/share/podman/test/system/500-networking.bats" -su - "$ROOTLESS_USER" -c "bats /usr/share/podman/test/system/505-networking-pasta.bats" diff --git a/tests/tests.yml b/tests/tests.yml new file mode 100644 index 0000000..552bdbb --- /dev/null +++ b/tests/tests.yml @@ -0,0 +1,16 @@ +- hosts: localhost + tags: + - classic + roles: + - role: standard-test-basic + required_packages: + - policycoreutils + - container-selinux + - podman + tests: + - is-module-installed: + run: semodule --list=full | grep container + - can-rebuild-policy: + run: semodule -B + - can-run-podman: + run: podman run --rm quay.io/libpod/testimage:20210610 cat -v /proc/self/attr/current