diff --git a/.fmf/version b/.fmf/version deleted file mode 100644 index d00491f..0000000 --- a/.fmf/version +++ /dev/null @@ -1 +0,0 @@ -1 diff --git a/.gitignore b/.gitignore index 5bb2950..af6a8de 100644 --- a/.gitignore +++ b/.gitignore @@ -1821,76 +1821,3 @@ /gvisor-tap-vsock-aab0ac9367fc5142f5857c36ac2352bcb3c60ab7.tar.gz /v4.4.0.tar.gz /v4.4.1.tar.gz -/v4.4.2.tar.gz -/v4.4.3.tar.gz -/v4.4.4.tar.gz -/v4.5.0-rc1.tar.gz -/v4.5.0-rc2.tar.gz -/v4.5.0.tar.gz -/gvisor-tap-vsock-407efb5dcdb0f4445935f7360535800b60447544.tar.gz -/v4.5.1.tar.gz -/v4.6.0-rc1.tar.gz -/v4.6.0-rc2.tar.gz -/v4.6.0.tar.gz -/v4.6.1.tar.gz -/v4.6.2.tar.gz -/v4.7.0-rc1.tar.gz -/v4.7.0.tar.gz -/v4.7.1.tar.gz -/v4.7.2.tar.gz -/v4.8.0-rc1.tar.gz -/v4.8.0.tar.gz -/v4.8.1.tar.gz -/v4.8.2.tar.gz -/v4.8.3.tar.gz -/v4.9.0.tar.gz -/v4.9.1.tar.gz -/v4.9.2.tar.gz -/v5.0.0-rc1.tar.gz -/v5.0.0-rc2.tar.gz -/v5.0.0-rc3.tar.gz -/v5.0.0-rc4.tar.gz -/v5.0.0-rc5.tar.gz -/v5.0.0-rc6.tar.gz -/v5.0.0-rc7.tar.gz -/v5.0.0.tar.gz -/v5.0.1.tar.gz -/v5.0.2.tar.gz -/v5.0.3.tar.gz -/v5.1.0-rc1.tar.gz -/v5.1.0.tar.gz -/v5.1.1.tar.gz -/v5.1.2.tar.gz -/v5.2.0-rc1.tar.gz -/v5.2.0-rc2.tar.gz -/v5.2.0.tar.gz -/v5.2.1.tar.gz -/v5.2.2.tar.gz -/v5.2.3.tar.gz -/v5.2.4.tar.gz -/v5.2.5.tar.gz -/v5.3.0-rc1.tar.gz -/v5.3.0-rc2.tar.gz -/v5.3.0-rc3.tar.gz -/v5.3.0.tar.gz -/v5.3.1.tar.gz -/v5.3.2.tar.gz -/v5.4.0-rc2.tar.gz -/v5.4.0-rc3.tar.gz -/v5.4.0.tar.gz -/v5.4.1.tar.gz -/v5.4.2.tar.gz -/v5.5.0-rc1.tar.gz -/v5.5.0-rc2.tar.gz -/v5.5.0.tar.gz -/v5.5.1.tar.gz -/v5.5.2.tar.gz -/v5.6.0-rc1.tar.gz -/v5.6.0-rc2.tar.gz -/v5.6.0.tar.gz -/v5.6.1.tar.gz -/v5.6.2.tar.gz -/v5.7.0-rc1.tar.gz -/v5.7.0-rc2.tar.gz -/v5.7.0.tar.gz -/v5.7.1.tar.gz diff --git a/.packit.yaml b/.packit.yaml deleted file mode 100644 index 117c7b5..0000000 --- a/.packit.yaml +++ /dev/null @@ -1,166 +0,0 @@ ---- -# See the documentation for more information: -# https://packit.dev/docs/configuration/ - -downstream_package_name: podman -upstream_tag_template: v{version} - -# These files get synced from upstream to downstream (Fedora / CentOS Stream) on every -# propose-downstream job. This is done so tests maintained upstream can be run -# downstream in Zuul CI and Bodhi. -# Ref: https://packit.dev/docs/configuration#files_to_sync -files_to_sync: - - src: rpm/gating.yaml - dest: gating.yaml - delete: true - - src: plans/ - dest: plans/ - delete: true - mkpath: true - - src: test/tmt/ - dest: test/tmt/ - delete: true - mkpath: true - - src: .fmf/ - dest: .fmf/ - delete: true - - .packit.yaml - -packages: - podman-fedora: - pkg_tool: fedpkg - specfile_path: rpm/podman.spec - podman-centos: - pkg_tool: centpkg - specfile_path: rpm/podman.spec - podman-eln: - specfile_path: rpm/podman.spec - -# Disable automatic merging for Copr builds (and subsequent Testing Farm) -merge_pr_in_ci: false - -srpm_build_deps: - - git-archive-all - - make - -actions: - fix-spec-file: "bash .packit-copr-rpm.sh" - pre-sync: "bash .packit-rpm-git-commit.sh" - -jobs: - - job: copr_build - trigger: pull_request - packages: [podman-fedora] - notifications: &packit_generic_failure_notification - failure_comment: - message: "[NON-BLOCKING] Packit jobs failed. @containers/packit-build please check. Everyone else, feel free to ignore." - enable_net: true - targets: - - fedora-all-x86_64 - - fedora-all-aarch64 - # Re-enable these scans if OpenScanHub starts scanning go packages - # https://packit.dev/posts/openscanhub-prototype - osh_diff_scan_after_copr_build: false - - # Ignore until golang is updated in distro buildroot to go 1.23.3+ - - job: copr_build - trigger: ignore - packages: [podman-eln] - notifications: *packit_generic_failure_notification - enable_net: true - targets: - fedora-eln-x86_64: - additional_repos: - - "https://kojipkgs.fedoraproject.org/repos/eln-build/latest/x86_64/" - fedora-eln-aarch64: - additional_repos: - - "https://kojipkgs.fedoraproject.org/repos/eln-build/latest/aarch64/" - - # Ignore until golang is updated in distro buildroot to go 1.23.3+ - - job: copr_build - trigger: ignore - packages: [podman-centos] - notifications: *packit_generic_failure_notification - enable_net: true - targets: - - centos-stream-9-x86_64 - - centos-stream-9-aarch64 - - centos-stream-10-x86_64 - - centos-stream-10-aarch64 - - # Run on commit to main branch - - job: copr_build - trigger: commit - packages: [podman-fedora] - branch: main - owner: rhcontainerbot - project: podman-next - enable_net: true - - # Tests on Fedora - - job: tests - trigger: pull_request - packages: [podman-fedora] - notifications: *packit_generic_failure_notification - targets: - - fedora-all - tmt_plan: "/plans/system/*" - - - job: tests - identifier: cockpit-revdeps - trigger: pull_request - packages: [podman-fedora] - notifications: - failure_comment: - message: "Cockpit tests failed for commit {commit_sha}. @martinpitt, @jelly, @mvollmer please check." - targets: - - fedora-latest-stable - - fedora-development - tf_extra_params: - environments: - - artifacts: - - type: repository-file - id: https://copr.fedorainfracloud.org/coprs/g/cockpit/main-builds/repo/fedora-$releasever/group_cockpit-main-builds-fedora-$releasever.repo - tmt: - context: - revdeps: "yes" - - - job: tests - identifier: tmt-revdeps - trigger: pull_request - packages: [podman-fedora] - notifications: - failure_comment: - message: "tmt tests failed for commit {commit_sha}. @lsm5, @psss, @thrix please check." - targets: - - fedora-latest - fmf_url: https://github.com/teemtee/tmt - fmf_path: /plans/friends - fmf_ref: main - tmt_plan: "/podman" - - - job: propose_downstream - trigger: release - update_release: false - packages: [podman-fedora] - dist_git_branches: &fedora_targets - - fedora-all - - - job: koji_build - trigger: commit - packages: [podman-fedora] - sidetag_group: podman-releases - dist_git_branches: *fedora_targets - - - job: bodhi_update - trigger: koji_build - packages: [podman-fedora] - sidetag_group: podman-releases - # Dependencies are not rpm dependencies, but packages that should go in the - # same bodhi update - # Ref: https://packit.dev/docs/fedora-releases-guide/releasing-multiple-packages - dependencies: - - buildah - - containers-common - - skopeo - dist_git_branches: *fedora_targets diff --git a/CVE-2023-0778.patch b/CVE-2023-0778.patch new file mode 100644 index 0000000..3fadf81 --- /dev/null +++ b/CVE-2023-0778.patch @@ -0,0 +1,102 @@ +From 805e94b034ceb59e10a57413c1493b7e8b7e33a0 Mon Sep 17 00:00:00 2001 +From: Aditya R +Date: Fri, 10 Feb 2023 15:16:27 +0530 +Subject: [PATCH] volume,container: chroot to source before exporting content + +* Utils must support higher level API to create Tar with chrooted into + directory +* Volume export: use TarwithChroot instead of Tar so we can make sure no + symlink can be exported by tar if it exists outside of the source +directory. +* container export: use chroot and Tar instead of Tar so we can make sure no + symlink can be exported by tar if it exists outside of the mointPoint. + +[NO NEW TESTS NEEDED] +[NO TESTS NEEDED] +Race needs combination of external/in-container mechanism which is hard to repro in CI. + +Closes: BZ:#2168256 +CVE: https://access.redhat.com/security/cve/CVE-2023-0778 + +Signed-off-by: Aditya R + + + +Signed-off-by: Matt Heon +--- + libpod/container_internal.go | 4 ++-- + utils/utils.go | 25 ++++++++++++++++++++++++- + 2 files changed, 26 insertions(+), 3 deletions(-) + +diff --git a/libpod/container_internal.go b/libpod/container_internal.go +index c37d6be2b1b..ee6a7b6cc2c 100644 +--- a/libpod/container_internal.go ++++ b/libpod/container_internal.go +@@ -34,7 +34,7 @@ import ( + "github.com/containers/podman/v4/pkg/systemd/notifyproxy" + "github.com/containers/podman/v4/pkg/util" + "github.com/containers/storage" +- "github.com/containers/storage/pkg/archive" ++ "github.com/containers/storage/pkg/chrootarchive" + "github.com/containers/storage/pkg/idtools" + "github.com/containers/storage/pkg/lockfile" + "github.com/containers/storage/pkg/mount" +@@ -763,7 +763,7 @@ func (c *Container) export(out io.Writer) error { + }() + } + +- input, err := archive.Tar(mountPoint, archive.Uncompressed) ++ input, err := chrootarchive.Tar(mountPoint, nil, mountPoint) + if err != nil { + return fmt.Errorf("reading container directory %q: %w", c.ID(), err) + } +diff --git a/utils/utils.go b/utils/utils.go +index f9f96f2835e..81b77e544a3 100644 +--- a/utils/utils.go ++++ b/utils/utils.go +@@ -13,6 +13,7 @@ import ( + + "github.com/containers/common/pkg/cgroups" + "github.com/containers/storage/pkg/archive" ++ "github.com/containers/storage/pkg/chrootarchive" + "github.com/godbus/dbus/v5" + "github.com/sirupsen/logrus" + ) +@@ -63,7 +64,7 @@ func CreateTarFromSrc(source string, dest string) error { + return fmt.Errorf("could not create tarball file '%s': %w", dest, err) + } + defer file.Close() +- return TarToFilesystem(source, file) ++ return TarChrootToFilesystem(source, file) + } + + // TarToFilesystem creates a tarball from source and writes to an os.file +@@ -87,6 +88,28 @@ func Tar(source string) (io.ReadCloser, error) { + return archive.Tar(source, archive.Uncompressed) + } + ++// TarChrootToFilesystem creates a tarball from source and writes to an os.file ++// provided while chrooted to the source. ++func TarChrootToFilesystem(source string, tarball *os.File) error { ++ tb, err := TarWithChroot(source) ++ if err != nil { ++ return err ++ } ++ _, err = io.Copy(tarball, tb) ++ if err != nil { ++ return err ++ } ++ logrus.Debugf("wrote tarball file %s", tarball.Name()) ++ return nil ++} ++ ++// TarWithChroot creates a tarball from source and returns a readcloser of it ++// while chrooted to the source. ++func TarWithChroot(source string) (io.ReadCloser, error) { ++ logrus.Debugf("creating tarball of %s", source) ++ return chrootarchive.Tar(source, nil, source) ++} ++ + // RemoveScientificNotationFromFloat returns a float without any + // scientific notation if the number has any. + // golang does not handle conversion of float64s that have scientific diff --git a/README.packit b/README.packit deleted file mode 100644 index 1d2f35b..0000000 --- a/README.packit +++ /dev/null @@ -1,3 +0,0 @@ -This repository is maintained by packit. -https://packit.dev/ -The file was generated using packit 1.12.0.post1.dev22+gfe66fd850. diff --git a/gating.yaml b/gating.yaml index 92c7dc4..5ab3627 100644 --- a/gating.yaml +++ b/gating.yaml @@ -7,11 +7,3 @@ decision_contexts: subject_type: koji_build rules: - !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.tier0.functional} - -# recipients: jnovy, lsm5, santiago ---- !Policy -product_versions: - - rhel-* -decision_context: osci_compose_gate -rules: - - !PassingTestCaseRule {test_case_name: osci.brew-build.tier0.functional} diff --git a/plans/cockpit-podman.fmf b/plans/cockpit-podman.fmf deleted file mode 100644 index 9485470..0000000 --- a/plans/cockpit-podman.fmf +++ /dev/null @@ -1,37 +0,0 @@ -# reverse dependency test for https://github.com/cockpit-project/cockpit-podman/ -# packit should automatically notify the cockpit maintainers on failures. -# For questions, please contact @martinpitt, @jelly, @mvollmer -enabled: false - -adjust+: - when: revdeps == yes - enabled: true - -discover: - how: fmf - url: https://github.com/cockpit-project/cockpit-podman - ref: "main" - -execute: - how: tmt - -# not relevant for testing podman -environment: - TEST_AUDIT_NO_SELINUX: 1 - TEST_ALLOW_JOURNAL_MESSAGES: ".*" - -# This has to duplicate cockpit-podman's plan structure; see https://github.com/teemtee/tmt/issues/1770 -/podman-system: - summary: Run cockpit-podman system tests - discover+: - test: /test/browser/system - -/podman-user: - summary: Run cockpit-podman user tests - discover+: - test: /test/browser/user - -/podman-misc: - summary: Run other cockpit-podman tests - discover+: - test: /test/browser/other diff --git a/plans/system.fmf b/plans/system.fmf deleted file mode 100644 index b04c062..0000000 --- a/plans/system.fmf +++ /dev/null @@ -1,50 +0,0 @@ -discover: - how: fmf - -execute: - how: tmt - -prepare: - - how: shell - script: modprobe null_blk nr_devices=1 - order: 5 - - when: distro == centos-stream or distro == rhel - how: shell - script: | - dnf -y install https://dl.fedoraproject.org/pub/epel/epel-release-latest-$(rpm --eval '%{?rhel}').noarch.rpm - dnf -y config-manager --set-enabled epel - order: 10 - -adjust+: - - enabled: false - when: revdeps == yes - -provision: - how: artemis - hardware: - memory: ">= 16 GB" - cpu: - cores: ">= 4" - threads: ">=8" - disk: - - size: ">= 512 GB" - -/local-root: - summary: Local rootful tests - discover+: - filter: 'tag:local & tag:root' - -/local-rootless: - summary: Local rootless tests - discover+: - filter: 'tag:local & tag:rootless' - -/remote-root: - summary: Remote rootful tests - discover+: - filter: 'tag:remote & tag:root' - -/remote-rootless: - summary: Remote rootless tests - discover+: - filter: 'tag:remote & tag:rootless' diff --git a/plans/tmt.fmf b/plans/tmt.fmf deleted file mode 100644 index 1589b5c..0000000 --- a/plans/tmt.fmf +++ /dev/null @@ -1,21 +0,0 @@ -summary: Run tmt container provision test (downstream only) - -enabled: false -adjust+: - - enabled: true - when: initiator != packit and distro != rhel - -discover: - how: fmf - filter: 'tag:tmt & tag:downstream' - -execute: - how: tmt - -prepare: - - when: distro == centos-stream or distro == rhel - how: shell - script: | - dnf -y install https://dl.fedoraproject.org/pub/epel/epel-release-latest-$(rpm --eval '%{?rhel}').noarch.rpm - dnf -y config-manager --set-enabled epel - order: 10 diff --git a/plans/toolbox.fmf b/plans/toolbox.fmf deleted file mode 100644 index 0aceed0..0000000 --- a/plans/toolbox.fmf +++ /dev/null @@ -1,29 +0,0 @@ -summary: Run toolbox tests (downstream only) - -enabled: false -adjust+: - - enabled: true - when: initiator != packit and distro == fedora - -provision: - how: artemis - hardware: - memory: ">= 16 GB" - cpu: - cores: ">= 4" - threads: ">=8" - disk: - - size: ">= 512 GB" - -prepare: - - name: packages - how: install - package: [toolbox-tests] - -discover: - how: fmf - url: https://src.fedoraproject.org/rpms/toolbox - ref: "rawhide" - -execute: - how: tmt diff --git a/podman.spec b/podman.spec index 1475aed..48fe6a6 100644 --- a/podman.spec +++ b/podman.spec @@ -7,89 +7,55 @@ %global debug_package %{nil} %endif -%global gomodulesmode GO111MODULE=on +%global provider github +%global provider_tld com +%global project containers +%global repo %{name} +# https://github.com/containers/%%{name} +%global import_path %{provider}.%{provider_tld}/%{project}/%{repo} +%global git0 https://%{import_path} -%if %{defined fedora} -%define build_with_btrfs 1 -# qemu-system* isn't packageed for CentOS Stream / RHEL -%define qemu 1 -# bats is included in the default repos (No epel/copr etc.) -%define distro_bats 1 -%if %{?fedora} >= 43 -%define sequoia 1 -%endif -%endif +# dnsname +%global repo_plugins dnsname +# https://github.com/containers/dnsname +%global import_path_plugins %{provider}.%{provider_tld}/%{project}/%{repo_plugins} +%global git_plugins https://%{import_path_plugins} +%global commit_plugins 18822f9a4fb35d1349eb256f4cd2bfd372474d84 -%if %{defined copr_username} -%define copr_build 1 -%if "%{copr_username}" == "rhcontainerbot" && "%{copr_projectname}" == "podman-next" -%define next_build 1 -%endif -%endif +# gvproxy +%global repo_gvproxy gvisor-tap-vsock +# https://github.com/containers/gvisor-tap-vsock +%global import_path_gvproxy %%{provider}.%{provider_tld}/%{project}/%{repo_gvproxy} +%global git_gvproxy https://%{import_path_gvproxy} +%global commit_gvproxy aab0ac9367fc5142f5857c36ac2352bcb3c60ab7 -# Only RHEL and CentOS Stream rpms are built with fips-enabled go compiler -%if %{defined rhel} -%define fips_enabled 1 -%endif - -%global container_base_path github.com/containers -%global container_base_url https://%{container_base_path} - -# For LDFLAGS -%global ld_project %{container_base_path}/%{name}/v5 -%global ld_libpod %{ld_project}/libpod - -# %%{name} -%global git0 %{container_base_url}/%{name} - -# podman-machine subpackage will be present only on these architectures -%global machine_arches x86_64 aarch64 - -%if %{defined copr_build} -%define build_origin Copr: %{?copr_username}/%{?copr_projectname} -%else -%define build_origin %{?packager} -%endif +%global built_tag v4.4.1 +%global built_tag_strip %(b=%{built_tag}; echo ${b:1}) +%global gen_version %(b=%{built_tag_strip}; echo ${b/-/"~"}) Name: podman -%if %{defined next_build} -Epoch: 102 -%else Epoch: 5 -%endif -# DO NOT TOUCH the Version string! -# The TRUE source of this specfile is: -# https://github.com/containers/podman/blob/main/rpm/podman.spec -# If that's what you're reading, Version must be 0, and will be updated by Packit for -# copr and koji builds. -# If you're reading this on dist-git, the version is automatically filled in by Packit. -Version: 5.7.1 -# The `AND` needs to be uppercase in the License for SPDX compatibility -License: Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND ISC AND MIT AND MPL-2.0 +Version: %{gen_version} +License: ASL 2.0 and BSD and ISC and MIT and MPLv2.0 Release: %autorelease -%if %{defined golang_arches_future} ExclusiveArch: %{golang_arches_future} -%else -ExclusiveArch: aarch64 ppc64le s390x x86_64 riscv64 -%endif Summary: Manage Pods, Containers and Container Images URL: https://%{name}.io/ # All SourceN files fetched from upstream -Source0: %{git0}/archive/v%{version_no_tilde}.tar.gz +Source0: %{git0}/archive/%{built_tag}.tar.gz +Source1: %{git_plugins}/archive/%{commit_plugins}/%{repo_plugins}-%{commit_plugins}.tar.gz +Source2: %{git_gvproxy}/archive/%{commit_gvproxy}/%{repo_gvproxy}-%{commit_gvproxy}.tar.gz +Patch0: CVE-2023-0778.patch Provides: %{name}-manpages = %{epoch}:%{version}-%{release} -BuildRequires: %{_bindir}/envsubst -%if %{defined build_with_btrfs} +BuildRequires: go-md2man BuildRequires: btrfs-progs-devel -%endif BuildRequires: gcc BuildRequires: glib2-devel BuildRequires: glibc-devel BuildRequires: glibc-static BuildRequires: golang BuildRequires: git-core -%if %{undefined rhel} || 0%{?rhel} >= 10 BuildRequires: go-rpm-macros -%endif BuildRequires: gpgme-devel BuildRequires: libassuan-devel BuildRequires: libgpg-error-devel @@ -98,26 +64,172 @@ BuildRequires: libselinux-devel BuildRequires: shadow-utils-subid-devel BuildRequires: pkgconfig BuildRequires: make -BuildRequires: man-db -BuildRequires: sqlite-devel +BuildRequires: ostree-devel BuildRequires: systemd BuildRequires: systemd-devel Requires: catatonit -Requires: conmon >= 2:2.1.7-2 -%if %{defined fedora} && 0%{?fedora} >= 40 -# TODO: Remove the f40 conditional after a few releases to keep conditionals to -# a minimum -# Ref: https://bugzilla.redhat.com/show_bug.cgi?id=2269148 -Requires: containers-common-extra >= 5:0.58.0-1 +Requires: conmon >= 2:2.0.30-2 +%if 0%{?fedora} > 37 +Requires: containers-common-extra >= 4:1-84 %else -Requires: containers-common-extra +%if 0%{?fedora} == 37 +Requires: containers-common-extra >= 4:1-78 +%else +Requires: containers-common-extra >= 4:1-66 %endif -%if %{defined sequoia} -Requires: podman-sequoia %endif - +Recommends: %{name}-gvproxy = %{epoch}:%{version}-%{release} +Provides: %{name}-quadlet Obsoletes: %{name}-quadlet <= 5:4.4.0-1 Provides: %{name}-quadlet = %{epoch}:%{version}-%{release} +# vendored libraries +# awk '{print "Provides: bundled(golang("$1")) = "$2}' go.mod | sort | uniq | sed -e 's/-/_/g' -e '/bundled(golang())/d' -e '/bundled(golang(go\|module\|replace\|require))/d' +Provides: bundled(golang(github.com/Azure/go_ansiterm)) = v0.0.0_20210617225240_d185dfc1b5a1 +Provides: bundled(golang(github.com/BurntSushi/toml)) = v1.2.1 +Provides: bundled(golang(github.com/Microsoft/go_winio)) = v0.6.0 +Provides: bundled(golang(github.com/Microsoft/hcsshim)) = v0.9.6 +Provides: bundled(golang(github.com/VividCortex/ewma)) = v1.2.0 +Provides: bundled(golang(github.com/acarl005/stripansi)) = v0.0.0_20180116102854_5a71ef0e047d +Provides: bundled(golang(github.com/asaskevich/govalidator)) = v0.0.0_20210307081110_f21760c49a8d +Provides: bundled(golang(github.com/blang/semver/v4)) = v4.0.0 +Provides: bundled(golang(github.com/buger/goterm)) = v1.0.4 +Provides: bundled(golang(github.com/checkpoint_restore/checkpointctl)) = v0.0.0_20220321135231_33f4a66335f0 +Provides: bundled(golang(github.com/checkpoint_restore/go_criu/v6)) = v6.3.0 +Provides: bundled(golang(github.com/chzyer/readline)) = v1.5.1 +Provides: bundled(golang(github.com/container_orchestrated_devices/container_device_interface)) = v0.5.3 +Provides: bundled(golang(github.com/containerd/cgroups)) = v1.0.4 +Provides: bundled(golang(github.com/containerd/containerd)) = v1.6.15 +Provides: bundled(golang(github.com/containerd/stargz_snapshotter/estargz)) = v0.13.0 +Provides: bundled(golang(github.com/containernetworking/cni)) = v1.1.2 +Provides: bundled(golang(github.com/containernetworking/plugins)) = v1.2.0 +Provides: bundled(golang(github.com/containers/buildah)) = v1.29.0 +Provides: bundled(golang(github.com/containers/common)) = v0.51.0 +Provides: bundled(golang(github.com/containers/conmon)) = v2.0.20+incompatible +Provides: bundled(golang(github.com/containers/image/v5)) = v5.24.0 +Provides: bundled(golang(github.com/containers/libtrust)) = v0.0.0_20230121012942_c1716e8a8d01 +Provides: bundled(golang(github.com/containers/ocicrypt)) = v1.1.7 +Provides: bundled(golang(github.com/containers/psgo)) = v1.8.0 +Provides: bundled(golang(github.com/containers/storage)) = v1.45.3 +Provides: bundled(golang(github.com/coreos/go_oidc/v3)) = v3.5.0 +Provides: bundled(golang(github.com/coreos/go_systemd)) = v0.0.0_20190719114852_fd7a80b32e1f +Provides: bundled(golang(github.com/coreos/go_systemd/v22)) = v22.5.0 +Provides: bundled(golang(github.com/coreos/stream_metadata_go)) = v0.0.0_20210225230131_70edb9eb47b3 +Provides: bundled(golang(github.com/cyberphone/json_canonicalization)) = v0.0.0_20220623050100_57a0ce2678a7 +Provides: bundled(golang(github.com/cyphar/filepath_securejoin)) = v0.2.3 +Provides: bundled(golang(github.com/davecgh/go_spew)) = v1.1.1 +Provides: bundled(golang(github.com/digitalocean/go_libvirt)) = v0.0.0_20201209184759_e2a69bcd5bd1 +Provides: bundled(golang(github.com/digitalocean/go_qemu)) = v0.0.0_20210326154740_ac9e0b687001 +Provides: bundled(golang(github.com/disiqueira/gotree/v3)) = v3.0.2 +Provides: bundled(golang(github.com/docker/distribution)) = v2.8.1+incompatible +Provides: bundled(golang(github.com/docker/docker)) = v20.10.23+incompatible +Provides: bundled(golang(github.com/docker/docker_credential_helpers)) = v0.7.0 +Provides: bundled(golang(github.com/docker/go_connections)) = v0.4.1_0.20210727194412_58542c764a11 +Provides: bundled(golang(github.com/docker/go_plugins_helpers)) = v0.0.0_20211224144127_6eecb7beb651 +Provides: bundled(golang(github.com/docker/go_units)) = v0.5.0 +Provides: bundled(golang(github.com/felixge/httpsnoop)) = v1.0.3 +Provides: bundled(golang(github.com/fsnotify/fsnotify)) = v1.6.0 +Provides: bundled(golang(github.com/fsouza/go_dockerclient)) = v1.9.3 +Provides: bundled(golang(github.com/ghodss/yaml)) = v1.0.0 +Provides: bundled(golang(github.com/go_jose/go_jose/v3)) = v3.0.0 +Provides: bundled(golang(github.com/go_openapi/analysis)) = v0.21.4 +Provides: bundled(golang(github.com/go_openapi/errors)) = v0.20.3 +Provides: bundled(golang(github.com/go_openapi/jsonpointer)) = v0.19.5 +Provides: bundled(golang(github.com/go_openapi/jsonreference)) = v0.20.0 +Provides: bundled(golang(github.com/go_openapi/loads)) = v0.21.2 +Provides: bundled(golang(github.com/go_openapi/runtime)) = v0.24.1 +Provides: bundled(golang(github.com/go_openapi/spec)) = v0.20.7 +Provides: bundled(golang(github.com/go_openapi/strfmt)) = v0.21.3 +Provides: bundled(golang(github.com/go_openapi/swag)) = v0.22.3 +Provides: bundled(golang(github.com/go_openapi/validate)) = v0.22.0 +Provides: bundled(golang(github.com/go_playground/locales)) = v0.14.0 +Provides: bundled(golang(github.com/go_playground/universal_translator)) = v0.18.0 +Provides: bundled(golang(github.com/go_playground/validator/v10)) = v10.11.1 +Provides: bundled(golang(github.com/godbus/dbus/v5)) = v5.1.1_0.20221029134443_4b691ce883d5 +Provides: bundled(golang(github.com/gogo/protobuf)) = v1.3.2 +Provides: bundled(golang(github.com/golang/groupcache)) = v0.0.0_20210331224755_41bb18bfe9da +Provides: bundled(golang(github.com/golang/protobuf)) = v1.5.2 +Provides: bundled(golang(github.com/google/go_cmp)) = v0.5.9 +Provides: bundled(golang(github.com/google/go_containerregistry)) = v0.12.1 +Provides: bundled(golang(github.com/google/go_intervals)) = v0.0.2 +Provides: bundled(golang(github.com/google/gofuzz)) = v1.2.0 +Provides: bundled(golang(github.com/google/shlex)) = v0.0.0_20191202100458_e7afc7fbc510 +Provides: bundled(golang(github.com/google/trillian)) = v1.5.0 +Provides: bundled(golang(github.com/google/uuid)) = v1.3.0 +Provides: bundled(golang(github.com/gorilla/handlers)) = v1.5.1 +Provides: bundled(golang(github.com/gorilla/mux)) = v1.8.0 +Provides: bundled(golang(github.com/gorilla/schema)) = v1.2.0 +Provides: bundled(golang(github.com/hashicorp/errwrap)) = v1.1.0 +Provides: bundled(golang(github.com/hashicorp/go_cleanhttp)) = v0.5.2 +Provides: bundled(golang(github.com/hashicorp/go_multierror)) = v1.1.1 +Provides: bundled(golang(github.com/hashicorp/go_retryablehttp)) = v0.7.2 +Provides: bundled(golang(github.com/imdario/mergo)) = v0.3.13 +Provides: bundled(golang(github.com/inconshreveable/mousetrap)) = v1.0.1 +Provides: bundled(golang(github.com/jinzhu/copier)) = v0.3.5 +Provides: bundled(golang(github.com/josharian/intern)) = v1.0.0 +Provides: bundled(golang(github.com/json_iterator/go)) = v1.1.12 +Provides: bundled(golang(github.com/klauspost/compress)) = v1.15.15 +Provides: bundled(golang(github.com/klauspost/pgzip)) = v1.2.6_0.20220930104621_17e8dac29df8 +Provides: bundled(golang(github.com/kr/fs)) = v0.1.0 +Provides: bundled(golang(github.com/leodido/go_urn)) = v1.2.1 +Provides: bundled(golang(github.com/letsencrypt/boulder)) = v0.0.0_20221109233200_85aa52084eaf +Provides: bundled(golang(github.com/mailru/easyjson)) = v0.7.7 +Provides: bundled(golang(github.com/manifoldco/promptui)) = v0.9.0 +Provides: bundled(golang(github.com/mattn/go_runewidth)) = v0.0.14 +Provides: bundled(golang(github.com/mattn/go_shellwords)) = v1.0.12 +Provides: bundled(golang(github.com/miekg/pkcs11)) = v1.1.1 +Provides: bundled(golang(github.com/mistifyio/go_zfs/v3)) = v3.0.0 +Provides: bundled(golang(github.com/mitchellh/mapstructure)) = v1.5.0 +Provides: bundled(golang(github.com/moby/sys/mount)) = v0.3.3 +Provides: bundled(golang(github.com/moby/sys/mountinfo)) = v0.6.2 +Provides: bundled(golang(github.com/moby/term)) = v0.0.0_20210619224110_3f7ff695adc6 +Provides: bundled(golang(github.com/modern_go/concurrent)) = v0.0.0_20180306012644_bacd9c7ef1dd +Provides: bundled(golang(github.com/modern_go/reflect2)) = v1.0.2 +Provides: bundled(golang(github.com/morikuni/aec)) = v1.0.0 +Provides: bundled(golang(github.com/nxadm/tail)) = v1.4.8 +Provides: bundled(golang(github.com/oklog/ulid)) = v1.3.1 +Provides: bundled(golang(github.com/onsi/ginkgo)) = v1.16.5 +Provides: bundled(golang(github.com/onsi/gomega)) = v1.26.0 +Provides: bundled(golang(github.com/opencontainers/go_digest)) = v1.0.0 +Provides: bundled(golang(github.com/opencontainers/image_spec)) = v1.1.0_rc2 +Provides: bundled(golang(github.com/opencontainers/runc)) = v1.1.4 +Provides: bundled(golang(github.com/opencontainers/runtime_spec)) = v1.0.3_0.20220825212826_86290f6a00fb +Provides: bundled(golang(github.com/opencontainers/runtime_tools)) = v0.9.1_0.20221014010322_58c91d646d86 +Provides: bundled(golang(github.com/opencontainers/selinux)) = v1.10.2 +Provides: bundled(golang(github.com/openshift/imagebuilder)) = v1.2.4_0.20220711175835_4151e43600df +Provides: bundled(golang(github.com/opentracing/opentracing_go)) = v1.2.0 +Provides: bundled(golang(github.com/ostreedev/ostree_go)) = v0.0.0_20210805093236_719684c64e4f +Provides: bundled(golang(github.com/pkg/errors)) = v0.9.1 +Provides: bundled(golang(github.com/pkg/sftp)) = v1.13.5 +Provides: bundled(golang(github.com/pmezard/go_difflib)) = v1.0.0 +Provides: bundled(golang(github.com/proglottis/gpgme)) = v0.1.3 +Provides: bundled(golang(github.com/rivo/uniseg)) = v0.4.3 +Provides: bundled(golang(github.com/rootless_containers/rootlesskit)) = v1.1.0 +Provides: bundled(golang(github.com/seccomp/libseccomp_golang)) = v0.10.0 +Provides: bundled(golang(github.com/segmentio/ksuid)) = v1.0.4 +Provides: bundled(golang(github.com/sigstore/fulcio)) = v1.0.0 +Provides: bundled(golang(github.com/sigstore/rekor)) = v1.0.1 +Provides: bundled(golang(github.com/sigstore/sigstore)) = v1.5.1 +Provides: bundled(golang(github.com/sirupsen/logrus)) = v1.9.0 +Provides: bundled(golang(github.com/skratchdot/open_golang)) = v0.0.0_20200116055534_eef842397966 +Provides: bundled(golang(github.com/spf13/cobra)) = v1.6.1 +Provides: bundled(golang(github.com/spf13/pflag)) = v1.0.5 +Provides: bundled(golang(github.com/stefanberger/go_pkcs11uri)) = v0.0.0_20201008174630_78d3cae3a980 +Provides: bundled(golang(github.com/stretchr/testify)) = v1.8.1 +Provides: bundled(golang(github.com/sylabs/sif/v2)) = v2.9.0 +Provides: bundled(golang(github.com/syndtr/gocapability)) = v0.0.0_20200815063812_42c35b437635 +Provides: bundled(golang(github.com/tchap/go_patricia)) = v2.3.0+incompatible +Provides: bundled(golang(github.com/theupdateframework/go_tuf)) = v0.5.2_0.20221207161717_9cb61d6e65f5 +Provides: bundled(golang(github.com/titanous/rocacheck)) = v0.0.0_20171023193734_afe73141d399 +Provides: bundled(golang(github.com/uber/jaeger_client_go)) = v2.30.0+incompatible +Provides: bundled(golang(github.com/ulikunitz/xz)) = v0.5.11 +Provides: bundled(golang(github.com/vbatts/tar_split)) = v0.11.2 +Provides: bundled(golang(github.com/vbauerster/mpb/v7)) = v7.5.3 +Provides: bundled(golang(github.com/vishvananda/netlink)) = v1.2.1_beta.2 +Provides: bundled(golang(github.com/vishvananda/netns)) = v0.0.0_20210104183010_2eb08e3e575f +Provides: bundled(golang(github.com/xeipuuv/gojsonpointer)) = v0.0.0_20190905194746_02993c407bfb +Provides: bundled(golang(github.com/xeipuuv/gojsonreference)) = v0.0.0_20180127040603_bd5ef7bd5415 +Provides: bundled(golang(github.com/xeipuuv/gojsonschema)) = v1.2.0 +Provides: bundled(golang(sigs.k8s.io/yaml)) = v1.3.0 %description %{name} (Pod Manager) is a fully featured container engine that is a simple @@ -131,6 +243,8 @@ additional privileges. Both tools share image (not container) storage, hence each can use or manipulate images (but not containers) created by the other. +%{summary} +%{repo} Simple management tool for pods, containers and images %package docker Summary: Emulate Docker CLI using %{name} @@ -151,26 +265,20 @@ pages and %{name}. Summary: Tests for %{name} Requires: %{name} = %{epoch}:%{version}-%{release} -%if %{defined distro_bats} Requires: bats -%endif -Requires: attr Requires: jq Requires: skopeo Requires: nmap-ncat Requires: httpd-tools Requires: openssl Requires: socat -Requires: slirp4netns Requires: buildah Requires: gnupg -Requires: xfsprogs %description tests %{summary} -This package contains system tests for %{name}. Only intended to be used for -gating tests. Not supported for end users / customers. +This package contains system tests for %{name} %package remote Summary: (Experimental) Remote client for managing %{name} containers @@ -185,56 +293,41 @@ run %{name}-remote in production. manage pods, containers and container images. %{name}-remote supports ssh connections as well. -%package -n %{name}sh -Summary: Confined login and user shell using %{name} -Requires: %{name} = %{epoch}:%{version}-%{release} -Provides: %{name}-shell = %{epoch}:%{version}-%{release} -Provides: %{name}-%{name}sh = %{epoch}:%{version}-%{release} +%package plugins +Summary: Plugins for %{name} +Requires: dnsmasq +Recommends: %{name}-gvproxy = %{epoch}:%{version}-%{release} -%description -n %{name}sh -%{name}sh provides a confined login and user shell with access to volumes and -capabilities specified in user quadlets. +%description plugins +This plugin sets up the use of dnsmasq on a given CNI network so +that Pods can resolve each other by name. When configured, +the pod and its IP address are added to a network specific hosts file +that dnsmasq will read in. Similarly, when a pod +is removed from the network, it will remove the entry from the hosts +file. Each CNI network will have its own dnsmasq instance. -It is a symlink to %{_bindir}/%{name} and execs into the `%{name}sh` container -when `%{_bindir}/%{name}sh` is set as a login shell or set as os.Args[0]. +%package gvproxy +Summary: Go replacement for libslirp and VPNKit -%ifarch %{machine_arches} -%package machine -Summary: Metapackage for setting up %{name} machine -Requires: %{name} = %{epoch}:%{version}-%{release} -Requires: gvisor-tap-vsock -%if %{defined qemu} -%ifarch aarch64 -Requires: qemu-system-aarch64-core -%endif -%ifarch x86_64 -Requires: qemu-system-x86-core -%endif -%else -Requires: qemu-kvm -%endif -Requires: qemu-img -Requires: virtiofsd -ExclusiveArch: x86_64 aarch64 - -%description machine -This subpackage installs the dependencies for %{name} machine, for more see: -https://docs.podman.io/en/latest/markdown/podman-machine.1.html -%endif +%description gvproxy +A replacement for libslirp and VPNKit, written in pure Go. +It is based on the network stack of gVisor. Compared to libslirp, +gvisor-tap-vsock brings a configurable DNS server and +dynamic port forwarding. %prep -%autosetup -Sgit -n %{name}-%{version_no_tilde} +%autosetup -Sgit -n %{name}-%{built_tag_strip} sed -i 's;@@PODMAN@@\;$(BINDIR);@@PODMAN@@\;%{_bindir};' Makefile -# cgroups-v1 is supported on rhel9 -%if 0%{?rhel} == 9 -sed -i '/DELETE ON RHEL9/,/DELETE ON RHEL9/d' libpod/runtime.go -%endif +# untar dnsname +tar zxf %{SOURCE1} + +# untar %%{name}-gvproxy +tar zxf %{SOURCE2} %build %set_build_flags export CGO_CFLAGS=$CFLAGS - # These extra flags present in $CFLAGS have been skipped for now as they break the build CGO_CFLAGS=$(echo $CGO_CFLAGS | sed 's/-flto=auto//g') CGO_CFLAGS=$(echo $CGO_CFLAGS | sed 's/-Wp,D_GLIBCXX_ASSERTIONS//g') @@ -244,61 +337,64 @@ CGO_CFLAGS=$(echo $CGO_CFLAGS | sed 's/-specs=\/usr\/lib\/rpm\/redhat\/redhat-an export CGO_CFLAGS+=" -m64 -mtune=generic -fcf-protection=full" %endif -export GOPROXY=direct +export GO111MODULE=off +export GOPATH=$(pwd)/_build:$(pwd) -LDFLAGS="-X %{ld_libpod}/define.buildInfo=${SOURCE_DATE_EPOCH:-$(date +%s)} \ - -X \"%{ld_libpod}/define.buildOrigin=%{build_origin}\" \ - -X %{ld_libpod}/config._installPrefix=%{_prefix} \ - -X %{ld_libpod}/config._etcDir=%{_sysconfdir} \ - -X %{ld_project}/pkg/systemd/quadlet._binDir=%{_bindir}" +mkdir _build +cd _build +mkdir -p src/%{provider}.%{provider_tld}/%{project} +ln -s ../../../../ src/%{import_path} +cd .. +ln -s vendor src -# This variable will be set by Packit actions. See .packit.yaml in the root dir -# of the repo (upstream as well as Fedora dist-git). -GIT_COMMIT="f845d14e941889ba4c071f35233d09b29d363c75" -LDFLAGS="$LDFLAGS -X %{ld_libpod}/define.gitCommit=$GIT_COMMIT" +# build date. FIXME: Makefile uses '/v2/libpod', that doesn't work here? +LDFLAGS="-X %{import_path}/libpod/define.buildInfo=$(date +%s)" # build rootlessport first -%gobuild -o bin/rootlessport ./cmd/rootlessport +%gobuild -o bin/rootlessport %{import_path}/cmd/rootlessport -export BASEBUILDTAGS="seccomp $(hack/systemd_tag.sh) $(hack/libsubid_tag.sh) libsqlite3 grpcnotrace" - -# libtrust_openssl buildtag switches to using the FIPS-compatible func -# `ecdsa.HashSign`. -# Ref 1: https://github.com/golang-fips/go/blob/main/patches/015-add-hash-sign-verify.patch#L22 -# Ref 2: https://github.com/containers/libtrust/blob/main/ec_key_openssl.go#L23 -%if %{defined fips_enabled} -export BASEBUILDTAGS="$BASEBUILDTAGS libtrust_openssl" -%endif +export BASEBUILDTAGS="seccomp exclude_graphdriver_devicemapper $(hack/selinux_tag.sh) $(hack/systemd_tag.sh) $(hack/libsubid_tag.sh)" # build %%{name} -export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh)" +export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh) $(hack/btrfs_tag.sh) $(hack/libdm_tag.sh)" -%if %{defined sequoia} -export BUILDTAGS="$BUILDTAGS containers_image_sequoia" -%endif - -%gobuild -o bin/%{name} ./cmd/%{name} +%gobuild -o bin/%{name} %{import_path}/cmd/%{name} # build %%{name}-remote -export BUILDTAGS="$BASEBUILDTAGS exclude_graphdriver_btrfs remote" -%gobuild -o bin/%{name}-remote ./cmd/%{name} +export BUILDTAGS="$BASEBUILDTAGS exclude_graphdriver_btrfs btrfs_noversion remote" +%gobuild -o bin/%{name}-remote %{import_path}/cmd/%{name} # build quadlet -export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh)" -%gobuild -o bin/quadlet ./cmd/quadlet +export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh) $(hack/btrfs_tag.sh)" +%gobuild -o bin/quadlet %{import_path}/cmd/quadlet -# build %%{name}-testing -export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh)" -%gobuild -o bin/podman-testing ./cmd/podman-testing +cd %{repo_plugins}-%{commit_plugins} +mkdir _build +cd _build +mkdir -p src/%{provider}.%{provider_tld}/%{project} +ln -s ../../../../ src/%{import_path_plugins} +cd .. +ln -s vendor src +export GOPATH=$(pwd)/_build:$(pwd) +%gobuild -o bin/dnsname %{import_path_plugins}/plugins/meta/dnsname +cd .. -# reset LDFLAGS for plugins binaries -LDFLAGS='' +cd %{repo_gvproxy}-%{commit_gvproxy} +mkdir _build +cd _build +mkdir -p src/%{provider}.%{provider_tld}/%{project} +ln -s ../../../../ src/%{import_path_gvproxy} +cd .. +ln -s vendor src +export GOPATH=$(pwd)/_build:$(pwd) +%gobuild -o bin/gvproxy %{import_path_gvproxy}/cmd/gvproxy +cd .. %{__make} docs docker-docs %install install -dp %{buildroot}%{_unitdir} -PODMAN_VERSION=%{version} %{__make} DESTDIR=%{buildroot} PREFIX=%{_prefix} ETCDIR=%{_sysconfdir} \ +PODMAN_VERSION=%{version} %{__make} PREFIX=%{buildroot}%{_prefix} ETCDIR=%{buildroot}%{_sysconfdir} \ install.bin \ install.man \ install.systemd \ @@ -306,33 +402,36 @@ PODMAN_VERSION=%{version} %{__make} DESTDIR=%{buildroot} PREFIX=%{_prefix} ETCDI install.docker \ install.docker-docs \ install.remote \ - install.testing +%if 0%{?fedora} >= 36 + install.modules-load +%endif -sed -i 's;%{buildroot};;g' %{buildroot}%{_bindir}/docker +# install dnsname plugin +cd %{repo_plugins}-%{commit_plugins} +%{__make} PREFIX=%{_prefix} DESTDIR=%{buildroot} install +cd .. + +# install gvproxy +cd %{repo_gvproxy}-%{commit_gvproxy} +install -dp %{buildroot}%{_libexecdir}/%{name} +install -p -m0755 bin/gvproxy %{buildroot}%{_libexecdir}/%{name} +cd .. # do not include docker and podman-remote man pages in main package -for file in `find %{buildroot}%{_mandir}/man[157] -type f | sed "s,%{buildroot},," | grep -v -e %{name}sh.1 -e remote -e docker`; do - echo "$file*" >> %{name}.file-list +for file in `find %{buildroot}%{_mandir}/man[15] -type f | sed "s,%{buildroot},," | grep -v -e remote -e docker`; do + echo "$file*" >> podman.file-list done rm -f %{buildroot}%{_mandir}/man5/docker*.5 -install -d -p %{buildroot}%{_datadir}/%{name}/test/system -cp -pav test/system %{buildroot}%{_datadir}/%{name}/test/ - -%ifarch %{machine_arches} -# symlink virtiofsd in %%{name} libexecdir for machine subpackage -ln -s ../virtiofsd %{buildroot}%{_libexecdir}/%{name} -%endif +install -d -p %{buildroot}/%{_datadir}/%{name}/test/system +cp -pav test/system %{buildroot}/%{_datadir}/%{name}/test/ #define license tag if not already defined %{!?_licensedir:%global license %doc} -# Include empty check to silence rpmlint warning -%check - %files -f %{name}.file-list -%license LICENSE vendor/modules.txt +%license LICENSE %doc README.md CONTRIBUTING.md install.md transfer.md %{_bindir}/%{name} %dir %{_libexecdir}/%{name} @@ -349,17 +448,11 @@ ln -s ../virtiofsd %{buildroot}%{_libexecdir}/%{name} %{_tmpfilesdir}/%{name}.conf %{_systemdgeneratordir}/%{name}-system-generator %{_systemdusergeneratordir}/%{name}-user-generator -# iptables modules are only needed with iptables-legacy, -# as of f41 netavark will default to nftables so do not load unessary modules -# https://fedoraproject.org/wiki/Changes/NetavarkNftablesDefault -%if %{defined fedora} && 0%{?fedora} < 41 %{_modulesloaddir}/%{name}-iptables.conf -%endif %files docker %{_bindir}/docker %{_mandir}/man1/docker*.1* -%{_sysconfdir}/profile.d/%{name}-docker.* %{_tmpfilesdir}/%{name}-docker.conf %{_user_tmpfilesdir}/%{name}-docker.conf @@ -374,18 +467,20 @@ ln -s ../virtiofsd %{buildroot}%{_libexecdir}/%{name} %{_datadir}/zsh/site-functions/_%{name}-remote %files tests -%{_bindir}/%{name}-testing +%license LICENSE %{_datadir}/%{name}/test -%files -n %{name}sh -%{_bindir}/%{name}sh -%{_mandir}/man1/%{name}sh.1* +%files plugins +%license %{repo_plugins}-%{commit_plugins}/LICENSE +%doc %{repo_plugins}-%{commit_plugins}/{README.md,README_PODMAN.md} +%dir %{_libexecdir}/cni +%{_libexecdir}/cni/dnsname -%ifarch %{machine_arches} -%files machine +%files gvproxy +%license %{repo_gvproxy}-%{commit_gvproxy}/LICENSE +%doc %{repo_gvproxy}-%{commit_gvproxy}/README.md %dir %{_libexecdir}/%{name} -%{_libexecdir}/%{name}/virtiofsd -%endif +%{_libexecdir}/%{name}/gvproxy %changelog %autochangelog diff --git a/sources b/sources index 1ab124d..a860097 100644 --- a/sources +++ b/sources @@ -1 +1,3 @@ -SHA512 (v5.7.1.tar.gz) = 81fd4c27ff1d16dcb85229d4e4fd2cb06943ddfe966b5324fa8a8a957b2d2ec2aed7c5da05d6c009148f53b76545b27b0cba506622c8861f70bf7cad6c214a08 +SHA512 (dnsname-18822f9a4fb35d1349eb256f4cd2bfd372474d84.tar.gz) = de371722fbf18cd23b31485ee7ba36bb41d0d9a932d15e50872989c3ca1ff7246da63143c3725d81089fadda3821a54c18b22150d9d16005b07df6824f5f71f8 +SHA512 (gvisor-tap-vsock-aab0ac9367fc5142f5857c36ac2352bcb3c60ab7.tar.gz) = e138125f0fad46f84afebad5769d4428cb29f24ce34e209b21689dc4409487bf2e946c9eb6551297baf36286c9be9a5310a77df4884563cfe247113980f18291 +SHA512 (v4.4.1.tar.gz) = 33a22b7941f4f6715baa1cd2d5b29a4e2e95264c5239877122448f71e1408d8c393bcd2cdaef9516a580eede911c84f1cfea9d7b4c9d287a2737986fdc604e2c diff --git a/test/tmt/system.fmf b/test/tmt/system.fmf deleted file mode 100644 index 65f4dd0..0000000 --- a/test/tmt/system.fmf +++ /dev/null @@ -1,51 +0,0 @@ -require: - - podman-tests - - psmisc - -environment: - # PODMAN_TESTING envvar is set in system.sh - PODMAN: /usr/bin/podman - QUADLET: /usr/libexec/podman/quadlet - ROOTLESS_USER: "fedora" -adjust+: - - when: distro == centos-stream - environment+: - ROOTLESS_USER: "ec2-user" - - when: distro == rhel - environment+: - ROOTLESS_USER: "cloud-user" - - when: initiator != "packit" - environment+: - RELEASE_TESTING: true - -/local-root: - tag: [ local, root ] - summary: local rootful test - test: bash ./system.sh - duration: 30m - -/local-rootless: - tag: [ local, rootless ] - summary: rootless test - test: bash ./system.sh rootless - duration: 30m - -/remote-root: - tag: [ remote, root ] - summary: remote rootful test - test: bash ./system.sh - duration: 30m - environment+: - PODMAN: /usr/bin/podman-remote - require+: - - podman-remote - -/remote-rootless: - tag: [ remote, rootless ] - summary: remote rootless test - test: bash ./system.sh rootless - duration: 30m - environment+: - PODMAN: /usr/bin/podman-remote - require+: - - podman-remote diff --git a/test/tmt/system.sh b/test/tmt/system.sh deleted file mode 100644 index 3cd29da..0000000 --- a/test/tmt/system.sh +++ /dev/null @@ -1,44 +0,0 @@ -#!/usr/bin/env bash - -set -exo pipefail - -uname -r - -loginctl enable-linger "$ROOTLESS_USER" - -rpm -q \ - aardvark-dns \ - buildah \ - conmon \ - container-selinux \ - containers-common \ - criu \ - crun \ - netavark \ - passt \ - podman \ - podman-tests \ - skopeo \ - slirp4netns \ - systemd - -export system_service_cmd="/usr/bin/podman system service --timeout=0 &" -export test_cmd="whoami && cd /usr/share/podman/test/system && PODMAN_TESTING=/usr/bin/podman-testing bats ." - -if [[ -z $1 ]]; then - if [[ $PODMAN == "/usr/bin/podman-remote" ]]; then - eval "$system_service_cmd" - fi - eval "$test_cmd" -elif [[ $1 == "rootless" ]]; then - if [[ $PODMAN == "/usr/bin/podman-remote" ]]; then - su - "$ROOTLESS_USER" -c "eval $system_service_cmd" - fi - su - "$ROOTLESS_USER" -c "eval $test_cmd" -fi - -# Kill all podman processes for remote tests -if [[ $PODMAN == "/usr/bin/podman-remote" ]]; then - killall -q podman -fi -exit 0 diff --git a/test/tmt/tmt.fmf b/test/tmt/tmt.fmf deleted file mode 100644 index f016947..0000000 --- a/test/tmt/tmt.fmf +++ /dev/null @@ -1,13 +0,0 @@ -enabled: false -adjust: - enabled: true - when: initiator != packit && distro != rhel -summary: Make sure that TMT container provision works -tag: [downstream] -require: - - tmt+provision-container -test: - tmt run --verbose --remove - provision --how container --image fedora - login --command 'cat /etc/os-release' - finish diff --git a/tests/README b/tests/README new file mode 100644 index 0000000..672acdb --- /dev/null +++ b/tests/README @@ -0,0 +1,25 @@ +I'm sorry. The playbooks here are a much-too-complicated way of saying: + + - test podman (root and rootless) under cgroups v2 + - reboot into cgroups v1 + - repeat the same podman tests + +We can't use standard-test-basic any more because, tl;dr, that has to +be the last stanza in the playbook and it doesn't offer any mechanism +for running a reboot in the middle of tests. (I actually found a way +but it was even uglier than this approach). + +The starting point is tests.yml . From there: + + tests.yml + \- test_podman.yml + |- roles/rootless_user_ready/ + \- test_podman_cgroups_vn.yml (runs twice: cgroups v2, v1) + |- roles/set_cgroups/ + \- roles/run_bats_tests/ (runs tests: root, rootless) + +Principal result is the file 'artifacts/test.log'. It will contain +one line for each test run, format will be '(PASS|FAIL|ERROR) ' + +For each completed test there will also be a 'test..bats.log' +containing some setup blurbs (RPMs, environment) and the full BATS log. diff --git a/tests/check_results.yml b/tests/check_results.yml new file mode 100644 index 0000000..e1de3bd --- /dev/null +++ b/tests/check_results.yml @@ -0,0 +1,36 @@ +--- +# Copied from standard-test-basic +# ...and, 2020-05-13, updated, looks like they changed the whole thing around +- name: Check the results + local_action: + module: shell + cmd: | + log="{{ artifacts }}/test.log" + if [ ! -f "$log" ]; then + echo ERROR + echo "Test results not found." 1>&2 + elif grep ^ERROR "$log" 1>&2; then + echo ERROR + elif grep ^FAIL "$log" 1>&2; then + echo FAIL + elif grep -q ^PASS "$log"; then + echo PASS + else + echo ERROR + echo "No test results found." 1>&2 + fi + register: test_results + +- name: Set role result + set_fact: + role_result: "{{ test_results.stdout }}" + role_message: "{{ test_results.stderr|d('test execution error.') }}" + +- name: display results + vars: + msg: | + role_result: {{ role_result|d('Undefined') }} + {{ role_message|d('[No error messages found]') }} + debug: + msg: "{{ msg.split('\n') }}" + failed_when: role_message|d("") != "" diff --git a/tests/roles/rootless_user_ready/tasks/main.yml b/tests/roles/rootless_user_ready/tasks/main.yml new file mode 100644 index 0000000..88ad032 --- /dev/null +++ b/tests/roles/rootless_user_ready/tasks/main.yml @@ -0,0 +1,14 @@ +--- +- name: make sure rootless account exists + user: name={{ rootless_user }} + +- name: rootless account | enable linger + shell: loginctl enable-linger {{ rootless_user }} + +- name: rootless account | get uid + getent: + database: passwd + key: "{{ rootless_user }}" + +- name: rootless account | preserve uid + set_fact: rootless_uid="{{ getent_passwd[rootless_user][1] }}" diff --git a/tests/roles/run_bats_tests/files/run_bats_tests.sh b/tests/roles/run_bats_tests/files/run_bats_tests.sh new file mode 100755 index 0000000..249c3ec --- /dev/null +++ b/tests/roles/run_bats_tests/files/run_bats_tests.sh @@ -0,0 +1,73 @@ +#!/bin/bash +# +# Run bats tests for a given $TEST_PACKAGE, e.g. buildah, podman +# +# This is invoked by the 'run_bats_tests' role; we assume that +# the package foo has a foo-tests subpackage which provides the +# directory /usr/share/foo/test/system, containing one or more .bats +# test files. +# +# We create two files: +# +# /tmp/test.summary.log - one-liner with FAIL, PASS, ERROR and a blurb +# /tmp/test.bats.log - full log of this script, plus the BATS run +# +export PATH=/usr/local/bin:/usr/sbin:/usr/bin + +FULL_LOG=/tmp/test.bats.log +rm -f $FULL_LOG +touch $FULL_LOG + +# Preserve output to a log file, but also emit on stdout. This covers +# RHEL (which preserves logfiles but runs ansible without --verbose) +# and Fedora (which hides logfiles but runs ansible --verbose). +exec &> >(tee -a $FULL_LOG) + +# Log program versions +echo "Packages:" +echo " Kernel: $(uname -r)" +rpm -qa |\ + egrep 'podman|conmon|containers-common|crun|runc|iptable|slirp|aardvark|netavark|containernetworking-plugins|systemd|container-selinux' |\ + sort |\ + sed -e 's/^/ /' + +divider='------------------------------------------------------------------' +echo $divider +printenv | sort +echo $divider +echo "ip addr:" +ip addr +echo $divider + +testdir=/usr/share/${TEST_PACKAGE}/test/system + +if ! cd $testdir; then + echo "FAIL ${TEST_NAME} : cd $testdir" > /tmp/test.summary.log + exit 0 +fi + +if [[ $PODMAN =~ remote ]]; then + ${PODMAN%%-remote} system service -t0 &>/dev/null & + PODMAN_SERVER_PID=$! +fi + +echo "\$ bats ." +bats . +rc=$? + +if [[ -n "$PODMAN_SERVER_PID" ]]; then + kill $PODMAN_SERVER_PID +fi + +echo $divider +echo "bats completed with status $rc" + +status=PASS +if [ $rc -ne 0 ]; then + status=FAIL +fi + +echo "${status} ${TEST_NAME}" > /tmp/test.summary.log + +# FIXME: for CI purposes, always exit 0. This allows subsequent tests. +exit 0 diff --git a/tests/roles/run_bats_tests/tasks/main.yml b/tests/roles/run_bats_tests/tasks/main.yml new file mode 100644 index 0000000..a207c05 --- /dev/null +++ b/tests/roles/run_bats_tests/tasks/main.yml @@ -0,0 +1,10 @@ +--- +# Create empty results file, world-writable +- name: initialize test.log file + copy: dest=/tmp/test.log content='' force=yes mode=0666 + +- name: execute tests + include: run_one_test.yml + with_items: "{{ tests }}" + loop_control: + loop_var: test diff --git a/tests/roles/run_bats_tests/tasks/run_one_test.yml b/tests/roles/run_bats_tests/tasks/run_one_test.yml new file mode 100644 index 0000000..9ef8cb7 --- /dev/null +++ b/tests/roles/run_bats_tests/tasks/run_one_test.yml @@ -0,0 +1,87 @@ +--- +- name: "{{ test.name }} | install test packages" + dnf: name="{{ test.package }}-tests" state=installed + +- name: "{{ test.name }} | define helper variables" + set_fact: + test_name_oneword: "{{ test.name | replace(' ','-') }}" + +# UGH. This is necessary because our caller sets some environment variables +# and we need to set a few more based on other caller variables; then we +# need to combine the two dicts when running the test. This seems to be +# the only way to do it in ansible. +- name: "{{ test.name }} | define local environment" + set_fact: + local_environment: + TEST_NAME: "{{ test.name }}" + TEST_PACKAGE: "{{ test.package }}" + TEST_ENV: "{{ test.environment }}" + +- name: "{{ test.name }} | setup/teardown helper | see if exists" + local_action: stat path={{ role_path }}/files/helper.{{ test_name_oneword }}.sh + register: helper + +- name: "{{ test.name }} | setup/teardown helper | install" + copy: src=helper.{{ test_name_oneword }}.sh dest=/tmp/helper.sh + when: helper.stat.exists + +# This is what runs the BATS tests. +- name: "{{ test.name }} | run test" + script: ./run_bats_tests.sh + args: + chdir: /usr/share/{{ test.package }}/test/system + become: "{{ true if test.become is defined else false }}" + become_user: "{{ rootless_user }}" + environment: "{{ local_environment | combine(test.environment) }}" + +# BATS tests will always exit zero and should leave behind two files: +# a full log (test.bats.log) and a one-line PASS/FAIL file (.summary.log) +- name: "{{ test.name }} | pull logs" + fetch: + src: "/tmp/test.{{ item }}.log" + dest: "{{ artifacts }}/test.{{ test_name_oneword }}.{{ item }}.log" + flat: yes + with_items: + - bats + - summary + +# Collect all the one-line PASS/FAIL results in one file, test.log +# Write the same thing, in a different format, to results.yml +# https://docs.fedoraproject.org/en-US/ci/standard-test-interface/ +- name: "{{ test.name }} | keep running tally of test results" + local_action: + module: shell + cmd: | + cd {{ artifacts }} + cat "test.{{ test_name_oneword }}.summary.log" >>test.log + + status=$(awk '{print $1}' >results.yml + echo " result: $status" >>results.yml + echo " logs: test.{{ test_name_oneword }}.bats.log" >>results.yml + + # delete the oneliner file, to keep artifacts dir clean + rm -f test.{{ test_name_oneword }}.summary.log + +- name: "{{ test.name }} | remove remote logs and helpers" + file: + dest=/tmp/{{ item }} + state=absent + with_items: + - test.bats.log + - test.summary.log + - helper.sh + +# AAAAARGH! +# +# Fedora gating tests are failing, because str-common-final/tasks/main.yml +# tries to pull test.log and other logs from $remote_host:/tmp/artifacts . +# Those don't exist, because I track status and artifacts locally, because +# with the reboot I can't rely on /tmp being preserved. +# I see no way to tell str-common-final to skip this step; so let's just +# push logs over upon completion of each subtest. +- name: keep remote artifacts synced + synchronize: + src: "{{ artifacts }}/" + dest: "{{ remote_artifacts|d('/tmp/artifacts') }}/" + mode: push diff --git a/tests/roles/set_cgroups/tasks/main.yml b/tests/roles/set_cgroups/tasks/main.yml new file mode 100644 index 0000000..133d7fe --- /dev/null +++ b/tests/roles/set_cgroups/tasks/main.yml @@ -0,0 +1,75 @@ +--- +# Check the CURRENT cgroup level; we get this from /proc/cmdline +- name: check current kernel options + shell: fgrep systemd.unified_cgroup_hierarchy=0 /proc/cmdline + register: result + ignore_errors: true + +- name: determine current cgroups | assume v2 + set_fact: current_cgroups=2 + +- name: determine current cgroups | looks like v1 + set_fact: current_cgroups=1 + when: result is succeeded + +- debug: + msg: "want: v{{ want_cgroups }} actual: v{{ current_cgroups }}" + +- name: grubenv, pre-edit, cat + shell: cat /boot/grub2/grubenv + register: grubenv + +- name: grubenv, pre-edit, show + debug: + msg: "{{ grubenv.stdout_lines }}" + +# Update grubenv file to reflect the desired cgroup level +- name: remove cgroup option from kernel flags + shell: + cmd: sed -i -e "s/^\(kernelopts=.*\)systemd\.unified_cgroup_hierarchy=.\(.*\)/\1 \2/" /boot/grub2/grubenv + warn: false + +- name: add it with the desired value + shell: + cmd: sed -i -e "s/^\(kernelopts=.*\)/\1 systemd.unified_cgroup_hierarchy=0/" /boot/grub2/grubenv + warn: false + when: want_cgroups == 1 + +- name: grubenv, post-edit, cat + shell: cat /boot/grub2/grubenv + register: grubenv + +- name: grubenv, post-edit, show + debug: + msg: "post: {{ grubenv.stdout_lines }}" + +# If want != have, reboot +- name: reboot and wait + block: + - name: reboot + reboot: + reboot_timeout: 900 + ignore_errors: yes + - name: wait and reconnect + wait_for_connection: + timeout: 900 + when: want_cgroups|int != current_cgroups|int + +- set_fact: + expected_fstype: + - none + - tmpfs + - cgroup2fs + +- name: confirm cgroups setting + shell: stat -f -c "%T" /sys/fs/cgroup + register: fstype + +- debug: + msg: "stat(/sys/fs/cgroup) = {{ fstype.stdout }}" + +- name: system cgroups is the expected type + assert: + that: + - fstype.stdout == expected_fstype[want_cgroups|int] + fail_msg: "stat(/sys/fs/cgroup) = {{ fstype.stdout }} (expected {{ expected_fstype[want_cgroups|int] }})" diff --git a/tests/test_podman.yml b/tests/test_podman.yml new file mode 100644 index 0000000..9674dea --- /dev/null +++ b/tests/test_podman.yml @@ -0,0 +1,50 @@ +--- +- hosts: localhost + tags: + - classic + - container + vars: + - artifacts: ./artifacts + rootless_user: testuser + roles: + - role: rootless_user_ready + + tasks: + # At the start of a run, clean up state. Useful for test reruns. + - name: local artifacts directory exists + local_action: file path="{{ artifacts }}" state=directory + + - name: remove stale log files + local_action: shell rm -f {{ artifacts }}/test*.log + + - name: clear test results (test.log) + local_action: command truncate --size=0 {{ artifacts }}/test.log + + - name: clear test results (results.yml) + local_action: copy content="results:\n" dest={{ artifacts }}/results.yml + + # These are the actual tests: set cgroups vN, then run root/rootless tests. + # + # FIXME FIXME FIXME: 2020-05-21: 'loop' should be '2, 1' but there's some + # nightmarish bug in CI wherein reboots hang forever. There's a bug open[1] + # but it seems dead. Without a working reboot, there's no way to test v1. + # [1] https://redhat.service-now.com/surl.do?n=PNT0808530 + # I'm leaving this as a 'loop' in (foolish? vain?) hope that the bug will + # be fixed. Let's revisit this after, say, 2020-08. If the bug persists + # then let's just revert the entire cgroups v1 change, and go back to + # using standard-test-basic. + - name: set cgroups and run podman tests + include_tasks: test_podman_cgroups_vn.yml + loop: [ 2 ] + loop_control: + loop_var: want_cgroups + + - name: test podman-remote + include_tasks: test_podman_remote.yml + + - name: test toolbox + include_tasks: test_toolbox.yml + + # Postprocessing: check for FAIL or ERROR in any test, exit 1 if so + - name: check results + include_tasks: check_results.yml diff --git a/tests/test_podman_cgroups_vn.yml b/tests/test_podman_cgroups_vn.yml new file mode 100644 index 0000000..5d48663 --- /dev/null +++ b/tests/test_podman_cgroups_vn.yml @@ -0,0 +1,21 @@ +--- +# Requires: 'want_cgroups' variable set to 1 or 2 +- include_role: + name: set_cgroups +- include_role: + name: run_bats_tests + vars: + tests: + # Yes, this is horrible duplication, but trying to refactor in ansible + # yields even more horrible unreadable code. This is the lesser evil. + - name: podman root cgroupsv{{ want_cgroups }} + package: podman + environment: + PODMAN: /usr/bin/podman + QUADLET: /usr/libexec/podman/quadlet + - name: podman rootless cgroupsv{{ want_cgroups }} + package: podman + environment: + PODMAN: /usr/bin/podman + QUADLET: /usr/libexec/podman/quadlet + become: true diff --git a/tests/test_podman_remote.yml b/tests/test_podman_remote.yml new file mode 100644 index 0000000..204d137 --- /dev/null +++ b/tests/test_podman_remote.yml @@ -0,0 +1,19 @@ +--- +- name: "podman-remote | install" + dnf: name="podman-remote" state=installed + +- include_role: + name: run_bats_tests + vars: + tests: + - name: podman-remote root + package: podman + environment: + PODMAN: /usr/bin/podman-remote + QUADLET: /usr/libexec/podman/quadlet + - name: podman-remote rootless + package: podman + environment: + PODMAN: /usr/bin/podman-remote + QUADLET: /usr/libexec/podman/quadlet + become: true diff --git a/tests/test_toolbox.yml b/tests/test_toolbox.yml new file mode 100644 index 0000000..9b0859c --- /dev/null +++ b/tests/test_toolbox.yml @@ -0,0 +1,10 @@ +--- +- include_role: + name: run_bats_tests + vars: + tests: + - name: toolbox + package: toolbox + become: true + environment: + XDG_RUNTIME_DIR: /run/user/{{ rootless_uid }} diff --git a/tests/tests.yml b/tests/tests.yml new file mode 100644 index 0000000..80caee7 --- /dev/null +++ b/tests/tests.yml @@ -0,0 +1 @@ +- import_playbook: test_podman.yml