Compare commits

...
Sign in to create a new pull request.

35 commits

Author SHA1 Message Date
Packit
189463c8a2 Update to 5.6.2 upstream release
Upstream tag: v5.6.2
Upstream commit: 9dd5e1ed

Commit authored by Packit automation (https://packit.dev/)
2025-09-30 19:45:45 +00:00
Packit
88a9f727d9 Update to 5.6.1 upstream release
Upstream tag: v5.6.1
Upstream commit: 1e2b2315

Commit authored by Packit automation (https://packit.dev/)
2025-09-04 20:58:27 +00:00
Packit
e5e96ca8e8 Update to 5.6.0 upstream release
Upstream tag: v5.6.0
Upstream commit: da671ef6

Commit authored by Packit automation (https://packit.dev/)
2025-08-15 16:02:20 +00:00
Packit
a5825b663a Update to 5.6.0-rc2 upstream release
Upstream tag: v5.6.0-rc2
Upstream commit: ec0652f4

Commit authored by Packit automation (https://packit.dev/)
2025-08-08 17:28:50 +00:00
Packit
5fc35ba7bc Update to 5.6.0-rc1 upstream release
Upstream tag: v5.6.0-rc1
Upstream commit: a3a6d9cc

Commit authored by Packit automation (https://packit.dev/)
2025-07-25 19:02:33 +00:00
Packit
1f4b9fd1c2 Update to 5.5.2 upstream release
Upstream tag: v5.5.2
Upstream commit: e7d82267

Commit authored by Packit automation (https://packit.dev/)
2025-06-24 17:26:49 +00:00
Packit
d67eac2233 Update to 5.5.1 upstream release
Upstream tag: v5.5.1
Upstream commit: 850db76d

Commit authored by Packit automation (https://packit.dev/)
2025-06-05 21:58:23 +00:00
Packit
085b89f11b Update to 5.5.0 upstream release
Upstream tag: v5.5.0
Upstream commit: 0dbcb514

Commit authored by Packit automation (https://packit.dev/)
2025-05-14 15:52:54 +00:00
Lokesh Mandvekar
5fea0d4476
TMT: system tests: Load null_blk kernel module to have /dev/nullb0
This also depends on patches in https://github.com/containers/podman/pull/26022
which will be present in final v5.5.0.

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
(cherry picked from commit 9d09cecc7b)
2025-05-02 20:30:32 +05:30
Lokesh Mandvekar
5db7b0e33d
fix setup to test tmt itself
do not enable on CentOS-Stream-10 and RHEL-10 as TMT is not yet present
on EPEL10.

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
(cherry picked from commit cfd03ba656)
2025-05-02 20:30:28 +05:30
Lokesh Mandvekar
baea03d269
cleanup: no plugins binaries built in rpm
Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
(cherry picked from commit 16af8ff967)
2025-05-02 20:30:22 +05:30
Lokesh Mandvekar
c3e65236c3
TMT: fix hardware provisioning for toolbox test
Only enable toolbox tests on fedora bodhi updates.

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
(cherry picked from commit c65ae60225)
2025-05-02 20:30:12 +05:30
Packit
1eec1e0289 Update to 5.5.0-rc2 upstream release
Upstream tag: v5.5.0-rc2
Upstream commit: 3c4cf521

Commit authored by Packit automation (https://packit.dev/)
2025-05-01 12:41:33 +00:00
Packit
26e9cc29af Update to 5.5.0-rc1 upstream release
Upstream tag: v5.5.0-rc1
Upstream commit: 6a597e0e

Commit authored by Packit automation (https://packit.dev/)
2025-04-24 17:03:04 +00:00
Packit
c1c9d32c75 Update to 5.4.2 upstream release
Upstream tag: v5.4.2
Upstream commit: be85287f

Commit authored by Packit automation (https://packit.dev/)
2025-04-02 16:29:51 +00:00
Packit
5113b7ae4e Update to 5.4.1 upstream release
Upstream tag: v5.4.1
Upstream commit: b79bc8af

Commit authored by Packit automation (https://packit.dev/)
2025-03-11 18:37:06 +00:00
Packit
171e2918e4 Update to 5.4.0 upstream release
Upstream tag: v5.4.0
Upstream commit: f9f7d48b

Commit authored by Packit automation (https://packit.dev/)
2025-02-11 18:26:28 +00:00
Packit
f9ee55f7d1 Update to 5.4.0-rc3 upstream release
Upstream tag: v5.4.0-rc3
Upstream commit: ad54787b

Commit authored by Packit automation (https://packit.dev/)
2025-02-05 19:02:58 +00:00
Lokesh Mandvekar
96cccde7ec
TMT: initial enablement
Remove STI test triggers in favor of TMT.

The upstream TMT enablement PR is at https://github.com/containers/podman/pull/24369 .
The Fedora PR can be merged independently of upstream so we can get rid
of STI asap.

Toolbox tests are fetched from its own dist-git.

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
(cherry picked from commit 3713b0f068)
2025-02-04 19:16:22 +05:30
Packit
8d500ea8d7 Update to 5.4.0-rc2 upstream release
Upstream tag: v5.4.0-rc2
Upstream commit: 14f6a69d

Commit authored by Packit automation (https://packit.dev/)
2025-01-30 13:36:04 +00:00
Packit
ecc67b3649 Update to 5.3.2 upstream release
Upstream tag: v5.3.2
Upstream commit: 85043bb1

Commit authored by Packit automation (https://packit.dev/)
2025-01-22 13:39:00 +00:00
Lokesh Mandvekar
c992a9be95
remove patch merged in upcoming upstream release
Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
(cherry picked from commit 37f545e12b2098dd8fead41433c4e45e8c4fa65c)
2025-01-22 19:04:04 +05:30
Mikhail Gavrilov
bfab5b4d23
apply MR https://github.com/containers/storage/pull/2193
(cherry picked from commit 6889e09310)
2025-01-17 15:10:12 +05:30
Lokesh Mandvekar
f7b3145d7a
remove unused patch
Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
(cherry picked from commit 89aed9941f)
2024-11-27 20:49:40 +05:30
Packit
e8d93fc647 Update to 5.3.1 upstream release
Upstream tag: v5.3.1
Upstream commit: 4cbdfde5

Commit authored by Packit automation (https://packit.dev/)
2024-11-21 15:40:56 +00:00
Packit
63688d6d96 Update to 5.3.0 upstream release
Upstream tag: v5.3.0
Upstream commit: 874bf2c3

Commit authored by Packit automation (https://packit.dev/)
2024-11-13 13:16:46 +00:00
Packit
c09cb57396 Update to 5.3.0-rc3 upstream release
Upstream tag: v5.3.0-rc3
Upstream commit: 8469dcc4

Commit authored by Packit automation (https://packit.dev/)
2024-11-06 19:17:11 +00:00
Packit
d9c7ad9b9d Update to 5.3.0-rc2 upstream release
Upstream tag: v5.3.0-rc2
Upstream commit: ffad01fb

Commit authored by Packit automation (https://packit.dev/)
2024-10-31 13:53:45 +00:00
Packit
2b660a3e4b Update to 5.3.0-rc1 upstream release
Upstream tag: v5.3.0-rc1
Upstream commit: d306e801

Commit authored by Packit automation (https://packit.dev/)
2024-10-22 15:59:32 +00:00
Lokesh Mandvekar
80365a70ae
bump to v5.2.5
Fixes: #2317464 - Security fix for CVE-2024-9675
Fixes: #2319019 - Security fix for CVE-2024-9676
Fixes: #2318511 - Security fix for CVE-2024-9341

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
(cherry picked from commit 5f0570428b)
2024-10-18 23:15:43 +05:30
Lokesh Mandvekar
def5ade19a
c/common pr 2194
(cherry picked from commit 7d7eeff1c6)
2024-10-15 13:26:29 +05:30
Packit
3fc3014baf Update to 5.2.4 upstream release
Upstream tag: v5.2.4
Upstream commit: 76d0859d

Commit authored by Packit automation (https://packit.dev/)
2024-10-07 16:07:27 +00:00
Packit
71054c4a70 Update to 5.2.3 upstream release
Upstream tag: v5.2.3
Upstream commit: c5366a30

Commit authored by Packit automation (https://packit.dev/)
2024-09-24 15:19:31 +00:00
Packit
ff0dbe4943 Update to 5.2.2 upstream release
Upstream tag: v5.2.2
Upstream commit: fcee4810

Commit authored by Packit automation (https://packit.dev/)
2024-08-21 20:00:19 +00:00
Packit
965a4ea76e Update to 5.2.1 upstream release
Upstream tag: v5.2.1
Upstream commit: d0582c9e

Commit authored by Packit automation (https://packit.dev/)
2024-08-14 18:08:58 +00:00
26 changed files with 440 additions and 443 deletions

1
.fmf/version Normal file
View file

@ -0,0 +1 @@
1

26
.gitignore vendored
View file

@ -1864,3 +1864,29 @@
/v5.2.0-rc1.tar.gz
/v5.2.0-rc2.tar.gz
/v5.2.0.tar.gz
/v5.2.1.tar.gz
/v5.2.2.tar.gz
/v5.2.3.tar.gz
/v5.2.4.tar.gz
/v5.2.5.tar.gz
/v5.3.0-rc1.tar.gz
/v5.3.0-rc2.tar.gz
/v5.3.0-rc3.tar.gz
/v5.3.0.tar.gz
/v5.3.1.tar.gz
/v5.3.2.tar.gz
/v5.4.0-rc2.tar.gz
/v5.4.0-rc3.tar.gz
/v5.4.0.tar.gz
/v5.4.1.tar.gz
/v5.4.2.tar.gz
/v5.5.0-rc1.tar.gz
/v5.5.0-rc2.tar.gz
/v5.5.0.tar.gz
/v5.5.1.tar.gz
/v5.5.2.tar.gz
/v5.6.0-rc1.tar.gz
/v5.6.0-rc2.tar.gz
/v5.6.0.tar.gz
/v5.6.1.tar.gz
/v5.6.2.tar.gz

View file

@ -5,6 +5,27 @@
downstream_package_name: podman
upstream_tag_template: v{version}
# These files get synced from upstream to downstream (Fedora / CentOS Stream) on every
# propose-downstream job. This is done so tests maintained upstream can be run
# downstream in Zuul CI and Bodhi.
# Ref: https://packit.dev/docs/configuration#files_to_sync
files_to_sync:
- src: rpm/gating.yaml
dest: gating.yaml
delete: true
- src: plans/
dest: plans/
delete: true
mkpath: true
- src: test/tmt/
dest: test/tmt/
delete: true
mkpath: true
- src: .fmf/
dest: .fmf/
delete: true
- .packit.yaml
packages:
podman-fedora:
pkg_tool: fedpkg
@ -12,28 +33,42 @@ packages:
podman-centos:
pkg_tool: centpkg
specfile_path: rpm/podman.spec
podman-rhel:
podman-eln:
specfile_path: rpm/podman.spec
# Disable automatic merging for Copr builds (and subsequent Testing Farm)
merge_pr_in_ci: false
srpm_build_deps:
- git-archive-all
- make
actions:
fix-spec-file:
- "bash .packit.sh"
fix-spec-file: "bash .packit-copr-rpm.sh"
pre-sync: "bash .packit-rpm-git-commit.sh"
jobs:
- job: copr_build
trigger: pull_request
packages: [podman-fedora]
notifications: &packit_build_failure_notification
notifications: &packit_generic_failure_notification
failure_comment:
message: "Ephemeral COPR build failed. @containers/packit-build please check."
message: "[NON-BLOCKING] Packit jobs failed. @containers/packit-build please check. Everyone else, feel free to ignore."
enable_net: true
targets:
- fedora-all-x86_64
- fedora-all-aarch64
# Re-enable these scans if OpenScanHub starts scanning go packages
# https://packit.dev/posts/openscanhub-prototype
osh_diff_scan_after_copr_build: false
# Ignore until golang is updated in distro buildroot to go 1.23.3+
- job: copr_build
trigger: ignore
packages: [podman-eln]
notifications: *packit_generic_failure_notification
enable_net: true
targets:
fedora-all-x86_64: {}
fedora-all-aarch64: {}
fedora-eln-x86_64:
additional_repos:
- "https://kojipkgs.fedoraproject.org/repos/eln-build/latest/x86_64/"
@ -41,10 +76,11 @@ jobs:
additional_repos:
- "https://kojipkgs.fedoraproject.org/repos/eln-build/latest/aarch64/"
# Ignore until golang is updated in distro buildroot to go 1.23.3+
- job: copr_build
trigger: pull_request
trigger: ignore
packages: [podman-centos]
notifications: *packit_build_failure_notification
notifications: *packit_generic_failure_notification
enable_net: true
targets:
- centos-stream-9-x86_64
@ -52,15 +88,6 @@ jobs:
- centos-stream-10-x86_64
- centos-stream-10-aarch64
- job: copr_build
trigger: pull_request
packages: [podman-rhel]
notifications: *packit_build_failure_notification
enable_net: true
targets:
- epel-9-x86_64
- epel-9-aarch64
# Run on commit to main branch
- job: copr_build
trigger: commit
@ -73,6 +100,20 @@ jobs:
project: podman-next
enable_net: true
# Tests on Fedora
- job: tests
trigger: pull_request
packages: [podman-fedora]
notifications: *packit_generic_failure_notification
targets:
- fedora-all
tmt_plan: "/plans/system/*"
tf_extra_params:
environments:
- artifacts:
- type: repository-file
id: https://copr.fedorainfracloud.org/coprs/rhcontainerbot/podman-next/repo/fedora-$releasever/rhcontainerbot-podman-next-fedora-$releasever.repo
- job: tests
identifier: cockpit-revdeps
trigger: pull_request
@ -98,25 +139,24 @@ jobs:
trigger: release
update_release: false
packages: [podman-fedora]
dist_git_branches:
- fedora-development
- fedora-latest
- job: propose_downstream
trigger: release
update_release: false
packages: [podman-centos]
dist_git_branches:
- c10s
dist_git_branches: &fedora_targets
- fedora-all
- job: koji_build
trigger: commit
packages: [podman-fedora]
dist_git_branches:
- fedora-all
sidetag_group: podman-releases
dist_git_branches: *fedora_targets
- job: bodhi_update
trigger: commit
trigger: koji_build
packages: [podman-fedora]
dist_git_branches:
- fedora-branched # rawhide updates are created automatically
sidetag_group: podman-releases
# Dependencies are not rpm dependencies, but packages that should go in the
# same bodhi update
# Ref: https://packit.dev/docs/fedora-releases-guide/releasing-multiple-packages
dependencies:
- buildah
- containers-common
- skopeo
dist_git_branches: *fedora_targets

View file

@ -1,3 +1,3 @@
This repository is maintained by packit.
https://packit.dev/
The file was generated using packit 0.99.0.post1.dev29+g2e75e6ff.
The file was generated using packit 1.11.0.post1.dev7+gfdcdf3a32.

View file

@ -7,3 +7,11 @@ decision_contexts:
subject_type: koji_build
rules:
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.tier0.functional}
# recipients: jnovy, lsm5, santiago
--- !Policy
product_versions:
- rhel-*
decision_context: osci_compose_gate
rules:
- !PassingTestCaseRule {test_case_name: osci.brew-build.tier0.functional}

37
plans/cockpit-podman.fmf Normal file
View file

@ -0,0 +1,37 @@
# reverse dependency test for https://github.com/cockpit-project/cockpit-podman/
# packit should automatically notify the cockpit maintainers on failures.
# For questions, please contact @martinpitt, @jelly, @mvollmer
enabled: false
adjust+:
when: revdeps == yes
enabled: true
discover:
how: fmf
url: https://github.com/cockpit-project/cockpit-podman
ref: "main"
execute:
how: tmt
# not relevant for testing podman
environment:
TEST_AUDIT_NO_SELINUX: 1
TEST_ALLOW_JOURNAL_MESSAGES: ".*"
# This has to duplicate cockpit-podman's plan structure; see https://github.com/teemtee/tmt/issues/1770
/podman-system:
summary: Run cockpit-podman system tests
discover+:
test: /test/browser/system
/podman-user:
summary: Run cockpit-podman user tests
discover+:
test: /test/browser/user
/podman-misc:
summary: Run other cockpit-podman tests
discover+:
test: /test/browser/other

59
plans/system.fmf Normal file
View file

@ -0,0 +1,59 @@
discover:
how: fmf
execute:
how: tmt
prepare:
- how: shell
script: modprobe null_blk nr_devices=1
order: 5
- when: distro == centos-stream or distro == rhel
how: shell
script: |
dnf -y install https://dl.fedoraproject.org/pub/epel/epel-release-latest-$(rpm --eval '%{?rhel}').noarch.rpm
dnf -y config-manager --set-enabled epel
order: 10
- when: initiator == packit
how: shell
script: |
COPR_REPO_FILE="/etc/yum.repos.d/*podman-next*.repo"
if compgen -G $COPR_REPO_FILE > /dev/null; then
sed -i -n '/^priority=/!p;$apriority=1' $COPR_REPO_FILE
fi
dnf -y upgrade --allowerasing
order: 20
adjust+:
- enabled: false
when: revdeps == yes
provision:
how: artemis
hardware:
memory: ">= 16 GB"
cpu:
cores: ">= 4"
threads: ">=8"
disk:
- size: ">= 512 GB"
/local-root:
summary: Local rootful tests
discover+:
filter: 'tag:local & tag:root'
/local-rootless:
summary: Local rootless tests
discover+:
filter: 'tag:local & tag:rootless'
/remote-root:
summary: Remote rootful tests
discover+:
filter: 'tag:remote & tag:root'
/remote-rootless:
summary: Remote rootless tests
discover+:
filter: 'tag:remote & tag:rootless'

21
plans/tmt.fmf Normal file
View file

@ -0,0 +1,21 @@
summary: Run tmt container provision test (downstream only)
enabled: false
adjust+:
- enabled: true
when: initiator != packit and distro != rhel
discover:
how: fmf
filter: 'tag:tmt & tag:downstream'
execute:
how: tmt
prepare:
- when: distro == centos-stream or distro == rhel
how: shell
script: |
dnf -y install https://dl.fedoraproject.org/pub/epel/epel-release-latest-$(rpm --eval '%{?rhel}').noarch.rpm
dnf -y config-manager --set-enabled epel
order: 10

29
plans/toolbox.fmf Normal file
View file

@ -0,0 +1,29 @@
summary: Run toolbox tests (downstream only)
enabled: false
adjust+:
- enabled: true
when: initiator != packit and distro == fedora
provision:
how: artemis
hardware:
memory: ">= 16 GB"
cpu:
cores: ">= 4"
threads: ">=8"
disk:
- size: ">= 512 GB"
prepare:
- name: packages
how: install
package: [toolbox-tests]
discover:
how: fmf
url: https://src.fedoraproject.org/rpms/toolbox
ref: "rawhide"
execute:
how: tmt

View file

@ -7,27 +7,26 @@
%global debug_package %{nil}
%endif
# RHEL's default %%gobuild macro doesn't account for the BUILDTAGS variable, so we
# set it separately here and do not depend on RHEL's go-[s]rpm-macros package
# until that's fixed.
# c9s bz: https://bugzilla.redhat.com/show_bug.cgi?id=2227328
%if %{defined rhel} && 0%{?rhel} < 10
%define gobuild(o:) go build -buildmode pie -compiler gc -tags="rpm_crashtraceback libtrust_openssl ${BUILDTAGS:-}" -ldflags "-linkmode=external -compressdwarf=false ${LDFLAGS:-} -B 0x$(head -c20 /dev/urandom|od -An -tx1|tr -d ' \\n') -extldflags '%__global_ldflags'" -a -v -x %{?**};
%endif
%global gomodulesmode GO111MODULE=on
%if %{defined rhel}
# _user_tmpfiles.d currently undefined on rhel
%global _user_tmpfilesdir %{_datadir}/user-tmpfiles.d
%endif
%if %{defined fedora}
%define build_with_btrfs 1
# qemu-system* isn't packageed for CentOS Stream / RHEL
%define qemu 1
# bats is included in the default repos (No epel/copr etc.)
%define distro_bats 1
%endif
%if %{defined copr_username}
%define copr_build 1
%if "%{copr_username}" == "rhcontainerbot" && "%{copr_projectname}" == "podman-next"
%define next_build 1
%endif
%endif
# Only RHEL and CentOS Stream rpms are built with fips-enabled go compiler
%if %{defined rhel}
%define fips_enabled 1
%endif
%global container_base_path github.com/containers
@ -40,8 +39,17 @@
# %%{name}
%global git0 %{container_base_url}/%{name}
Name: podman
# podman-machine subpackage will be present only on these architectures
%global machine_arches x86_64 aarch64
%if %{defined copr_build}
%define build_origin Copr: %{?copr_username}/%{?copr_projectname}
%else
%define build_origin %{?packager}
%endif
Name: podman
%if %{defined next_build}
Epoch: 102
%else
Epoch: 5
@ -52,14 +60,14 @@ Epoch: 5
# If that's what you're reading, Version must be 0, and will be updated by Packit for
# copr and koji builds.
# If you're reading this on dist-git, the version is automatically filled in by Packit.
Version: 5.2.0
Version: 5.6.2
# The `AND` needs to be uppercase in the License for SPDX compatibility
License: Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND ISC AND MIT AND MPL-2.0
Release: %autorelease
%if %{defined golang_arches_future}
ExclusiveArch: %{golang_arches_future}
%else
ExclusiveArch: aarch64 ppc64le s390x x86_64
ExclusiveArch: aarch64 ppc64le s390x x86_64 riscv64
%endif
Summary: Manage Pods, Containers and Container Images
URL: https://%{name}.io/
@ -88,7 +96,7 @@ BuildRequires: shadow-utils-subid-devel
BuildRequires: pkgconfig
BuildRequires: make
BuildRequires: man-db
BuildRequires: ostree-devel
BuildRequires: sqlite-devel
BuildRequires: systemd
BuildRequires: systemd-devel
Requires: catatonit
@ -101,7 +109,6 @@ Requires: containers-common-extra >= 5:0.58.0-1
%else
Requires: containers-common-extra
%endif
Provides: %{name}-quadlet
Obsoletes: %{name}-quadlet <= 5:4.4.0-1
Provides: %{name}-quadlet = %{epoch}:%{version}-%{release}
@ -137,22 +144,26 @@ pages and %{name}.
Summary: Tests for %{name}
Requires: %{name} = %{epoch}:%{version}-%{release}
%if %{defined fedora}
%if %{defined distro_bats}
Requires: bats
%endif
Requires: attr
Requires: jq
Requires: skopeo
Requires: nmap-ncat
Requires: httpd-tools
Requires: openssl
Requires: socat
Requires: slirp4netns
Requires: buildah
Requires: gnupg
Requires: xfsprogs
%description tests
%{summary}
This package contains system tests for %{name}
This package contains system tests for %{name}. Only intended to be used for
gating tests. Not supported for end users / customers.
%package remote
Summary: (Experimental) Remote client for managing %{name} containers
@ -180,16 +191,29 @@ capabilities specified in user quadlets.
It is a symlink to %{_bindir}/%{name} and execs into the `%{name}sh` container
when `%{_bindir}/%{name}sh` is set as a login shell or set as os.Args[0].
%ifarch %{machine_arches}
%package machine
Summary: Metapackage for setting up %{name} machine
Requires: %{name} = %{epoch}:%{version}-%{release}
Requires: gvisor-tap-vsock
Requires: qemu
%if %{defined qemu}
%ifarch aarch64
Requires: qemu-system-aarch64-core
%endif
%ifarch x86_64
Requires: qemu-system-x86-core
%endif
%else
Requires: qemu-kvm
%endif
Requires: qemu-img
Requires: virtiofsd
ExclusiveArch: x86_64 aarch64
%description machine
This subpackage installs the dependencies for %{name} machine, for more see:
https://docs.podman.io/en/latest/markdown/podman-machine.1.html
%endif
%prep
%autosetup -Sgit -n %{name}-%{version_no_tilde}
@ -200,14 +224,6 @@ sed -i 's;@@PODMAN@@\;$(BINDIR);@@PODMAN@@\;%{_bindir};' Makefile
sed -i '/DELETE ON RHEL9/,/DELETE ON RHEL9/d' libpod/runtime.go
%endif
# These changes are only meant for copr builds
%if %{defined copr_build}
# podman --version should show short sha
sed -i "s/^const RawVersion = .*/const RawVersion = \"##VERSION##-##SHORT_SHA##\"/" version/rawversion/version.go
# use ParseTolerant to allow short sha in version
sed -i "s/^var Version.*/var Version, err = semver.ParseTolerant(rawversion.RawVersion)/" version/version.go
%endif
%build
%set_build_flags
export CGO_CFLAGS=$CFLAGS
@ -224,29 +240,43 @@ export CGO_CFLAGS+=" -m64 -mtune=generic -fcf-protection=full"
export GOPROXY=direct
LDFLAGS="-X %{ld_libpod}/define.buildInfo=${SOURCE_DATE_EPOCH:-$(date +%s)} \
-X \"%{ld_libpod}/define.buildOrigin=%{build_origin}\" \
-X %{ld_libpod}/config._installPrefix=%{_prefix} \
-X %{ld_libpod}/config._etcDir=%{_sysconfdir} \
-X %{ld_project}/pkg/systemd/quadlet._binDir=%{_bindir}"
# This variable will be set by Packit actions. See .packit.yaml in the root dir
# of the repo (upstream as well as Fedora dist-git).
GIT_COMMIT="9dd5e1ed33830612bc200d7a13db00af6ab865a4"
LDFLAGS="$LDFLAGS -X %{ld_libpod}/define.gitCommit=$GIT_COMMIT"
# build rootlessport first
%gobuild -o bin/rootlessport ./cmd/rootlessport
export BASEBUILDTAGS="seccomp exclude_graphdriver_devicemapper $(hack/systemd_tag.sh) $(hack/libsubid_tag.sh)"
export BASEBUILDTAGS="seccomp $(hack/systemd_tag.sh) $(hack/libsubid_tag.sh) libsqlite3 grpcnotrace"
# libtrust_openssl buildtag switches to using the FIPS-compatible func
# `ecdsa.HashSign`.
# Ref 1: https://github.com/golang-fips/go/blob/main/patches/015-add-hash-sign-verify.patch#L22
# Ref 2: https://github.com/containers/libtrust/blob/main/ec_key_openssl.go#L23
%if %{defined fips_enabled}
export BASEBUILDTAGS="$BASEBUILDTAGS libtrust_openssl"
%endif
# build %%{name}
export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh) $(hack/btrfs_tag.sh) $(hack/libdm_tag.sh)"
export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh)"
%gobuild -o bin/%{name} ./cmd/%{name}
# build %%{name}-remote
export BUILDTAGS="$BASEBUILDTAGS exclude_graphdriver_btrfs btrfs_noversion remote"
export BUILDTAGS="$BASEBUILDTAGS exclude_graphdriver_btrfs remote"
%gobuild -o bin/%{name}-remote ./cmd/%{name}
# build quadlet
export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh) $(hack/btrfs_tag.sh)"
export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh)"
%gobuild -o bin/quadlet ./cmd/quadlet
# build %%{name}-testing
export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh) $(hack/btrfs_tag.sh)"
export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh)"
%gobuild -o bin/podman-testing ./cmd/podman-testing
# reset LDFLAGS for plugins binaries
@ -266,15 +296,10 @@ PODMAN_VERSION=%{version} %{__make} DESTDIR=%{buildroot} PREFIX=%{_prefix} ETCDI
install.remote \
install.testing
# Only need this on Fedora until nftables becomes the default
%if %{defined fedora}
%{__make} DESTDIR=%{buildroot} MODULESLOADDIR=%{_modulesloaddir} install.modules-load
%endif
sed -i 's;%{buildroot};;g' %{buildroot}%{_bindir}/docker
# do not include docker and podman-remote man pages in main package
for file in `find %{buildroot}%{_mandir}/man[15] -type f | sed "s,%{buildroot},," | grep -v -e %{name}sh.1 -e remote -e docker`; do
for file in `find %{buildroot}%{_mandir}/man[157] -type f | sed "s,%{buildroot},," | grep -v -e %{name}sh.1 -e remote -e docker`; do
echo "$file*" >> %{name}.file-list
done
@ -283,12 +308,17 @@ rm -f %{buildroot}%{_mandir}/man5/docker*.5
install -d -p %{buildroot}%{_datadir}/%{name}/test/system
cp -pav test/system %{buildroot}%{_datadir}/%{name}/test/
%ifarch %{machine_arches}
# symlink virtiofsd in %%{name} libexecdir for machine subpackage
ln -s ../virtiofsd %{buildroot}%{_libexecdir}/%{name}
%endif
#define license tag if not already defined
%{!?_licensedir:%global license %doc}
# Include empty check to silence rpmlint warning
%check
%files -f %{name}.file-list
%license LICENSE vendor/modules.txt
%doc README.md CONTRIBUTING.md install.md transfer.md
@ -307,7 +337,10 @@ ln -s ../virtiofsd %{buildroot}%{_libexecdir}/%{name}
%{_tmpfilesdir}/%{name}.conf
%{_systemdgeneratordir}/%{name}-system-generator
%{_systemdusergeneratordir}/%{name}-user-generator
%if %{defined fedora}
# iptables modules are only needed with iptables-legacy,
# as of f41 netavark will default to nftables so do not load unessary modules
# https://fedoraproject.org/wiki/Changes/NetavarkNftablesDefault
%if %{defined fedora} && 0%{?fedora} < 41
%{_modulesloaddir}/%{name}-iptables.conf
%endif
@ -336,14 +369,11 @@ ln -s ../virtiofsd %{buildroot}%{_libexecdir}/%{name}
%{_bindir}/%{name}sh
%{_mandir}/man1/%{name}sh.1*
%ifarch %{machine_arches}
%files machine
%dir %{_libexecdir}/%{name}
%{_libexecdir}/%{name}/virtiofsd
%endif
%changelog
%if %{defined autochangelog}
%autochangelog
%else
* Mon May 01 2023 RH Container Bot <rhcontainerbot@fedoraproject.org>
- Placeholder changelog for envs that are not autochangelog-ready
%endif

View file

@ -1 +1 @@
SHA512 (v5.2.0.tar.gz) = cc5ac92ebeaac03074c1221fa4cbc3ea62af95d0d444208b88368208089e146ff2693281033caaecd909a5f01fe4a3f8a199fef8c6c9901c281431011e19f729
SHA512 (v5.6.2.tar.gz) = 89f819da18a95b2f7d4d3dce1c34ee3e133a42ef87a78bd3a15cb5e8affed1671a2ce134518e37ca952ddb0ce086d47ed9a84ff98b941c6d55753c402e156b95

51
test/tmt/system.fmf Normal file
View file

@ -0,0 +1,51 @@
require:
- podman-tests
- psmisc
environment:
# PODMAN_TESTING envvar is set in system.sh
PODMAN: /usr/bin/podman
QUADLET: /usr/libexec/podman/quadlet
ROOTLESS_USER: "fedora"
adjust+:
- when: distro == centos-stream
environment+:
ROOTLESS_USER: "ec2-user"
- when: distro == rhel
environment+:
ROOTLESS_USER: "cloud-user"
- when: initiator != "packit"
environment+:
RELEASE_TESTING: true
/local-root:
tag: [ local, root ]
summary: local rootful test
test: bash ./system.sh
duration: 30m
/local-rootless:
tag: [ local, rootless ]
summary: rootless test
test: bash ./system.sh rootless
duration: 30m
/remote-root:
tag: [ remote, root ]
summary: remote rootful test
test: bash ./system.sh
duration: 30m
environment+:
PODMAN: /usr/bin/podman-remote
require+:
- podman-remote
/remote-rootless:
tag: [ remote, rootless ]
summary: remote rootless test
test: bash ./system.sh rootless
duration: 30m
environment+:
PODMAN: /usr/bin/podman-remote
require+:
- podman-remote

44
test/tmt/system.sh Normal file
View file

@ -0,0 +1,44 @@
#!/usr/bin/env bash
set -exo pipefail
uname -r
loginctl enable-linger "$ROOTLESS_USER"
rpm -q \
aardvark-dns \
buildah \
conmon \
container-selinux \
containers-common \
criu \
crun \
netavark \
passt \
podman \
podman-tests \
skopeo \
slirp4netns \
systemd
export system_service_cmd="/usr/bin/podman system service --timeout=0 &"
export test_cmd="whoami && cd /usr/share/podman/test/system && PODMAN_TESTING=/usr/bin/podman-testing bats ."
if [[ -z $1 ]]; then
if [[ $PODMAN == "/usr/bin/podman-remote" ]]; then
eval "$system_service_cmd"
fi
eval "$test_cmd"
elif [[ $1 == "rootless" ]]; then
if [[ $PODMAN == "/usr/bin/podman-remote" ]]; then
su - "$ROOTLESS_USER" -c "eval $system_service_cmd"
fi
su - "$ROOTLESS_USER" -c "eval $test_cmd"
fi
# Kill all podman processes for remote tests
if [[ $PODMAN == "/usr/bin/podman-remote" ]]; then
killall -q podman
fi
exit 0

13
test/tmt/tmt.fmf Normal file
View file

@ -0,0 +1,13 @@
enabled: false
adjust:
enabled: true
when: initiator != packit && distro != rhel
summary: Make sure that TMT container provision works
tag: [downstream]
require:
- tmt+provision-container
test:
tmt run --verbose --remove
provision --how container --image fedora
login --command 'cat /etc/os-release'
finish

View file

@ -1,18 +0,0 @@
I'm sorry. The playbooks here are a much-too-complicated way of saying:
- test podman (root and rootless)
- same, with podman-remote
The starting point is tests.yml . From there:
tests.yml
\- test_podman.yml
|- roles/rootless_user_ready/
\- run_podman_tests.yml (once for local, once for remote)
\- roles/run_bats_tests/ (runs tests: root, rootless)
Principal result is the file 'artifacts/test.log'. It will contain
one line for each test run, format will be '(PASS|FAIL|ERROR) <test name>'
For each completed test there will also be a 'test.<name>.bats.log'
containing some setup blurbs (RPMs, environment) and the full BATS log.

View file

@ -1,36 +0,0 @@
---
# Copied from standard-test-basic
# ...and, 2020-05-13, updated, looks like they changed the whole thing around
- name: Check the results
local_action:
module: shell
cmd: |
log="{{ artifacts }}/test.log"
if [ ! -f "$log" ]; then
echo ERROR
echo "Test results not found." 1>&2
elif grep ^ERROR "$log" 1>&2; then
echo ERROR
elif grep ^FAIL "$log" 1>&2; then
echo FAIL
elif grep -q ^PASS "$log"; then
echo PASS
else
echo ERROR
echo "No test results found." 1>&2
fi
register: test_results
- name: Set role result
set_fact:
role_result: "{{ test_results.stdout }}"
role_message: "{{ test_results.stderr|d('test execution error.') }}"
- name: display results
vars:
msg: |
role_result: {{ role_result|d('Undefined') }}
{{ role_message|d('[No error messages found]') }}
debug:
msg: "{{ msg.split('\n') }}"
failed_when: role_message|d("") != ""

View file

@ -1,41 +0,0 @@
#!/bin/bash
#
# Excerpted from https://github.com/containers/automation_images/blob/main/systemd_banish.sh
#
# Early 2023: https://github.com/containers/podman/issues/16973
#
# We see countless instances of "lookup cdn03.quay.io" flakes.
# Disabling the systemd resolver has completely resolved those,
# from multiple flakes per day to zero in a month.
#
# Opinions differ on the merits of systemd-resolve, but the fact is
# it breaks our CI testing. Kill it.
nsswitch=/etc/authselect/nsswitch.conf
if [[ -e $nsswitch ]]; then
if grep -q -E 'hosts:.*resolve' $nsswitch; then
echo "Disabling systemd-resolved"
sed -i -e 's/^\(hosts: *\).*/\1files dns myhostname/' $nsswitch
systemctl disable --now systemd-resolved
rm -f /etc/resolv.conf
# NetworkManager may already be running, or it may not....
systemctl start NetworkManager
sleep 1
systemctl restart NetworkManager
# ...and it may create resolv.conf upon start/restart, or it
# may not. Keep restarting until it does. (Yes, I realize
# this is cargocult thinking. Don't care. Not worth the effort
# to diagnose and solve properly.)
retries=10
while ! test -e /etc/resolv.conf;do
retries=$((retries - 1))
if [[ $retries -eq 0 ]]; then
echo "Timed out waiting for resolv.conf" >&2
echo "...gonna try continuing. Expect failures." >&2
fi
systemctl restart NetworkManager
sleep 5
done
fi
fi

View file

@ -1,3 +0,0 @@
---
- name: disable systemd resolved
script: ./disable_systemd_resolved.sh

View file

@ -1,14 +0,0 @@
---
- name: make sure rootless account exists
user: name={{ rootless_user }}
- name: rootless account | enable linger
shell: loginctl enable-linger {{ rootless_user }}
- name: rootless account | get uid
getent:
database: passwd
key: "{{ rootless_user }}"
- name: rootless account | preserve uid
set_fact: rootless_uid="{{ getent_passwd[rootless_user][1] }}"

View file

@ -1,73 +0,0 @@
#!/bin/bash
#
# Run bats tests for a given $TEST_PACKAGE, e.g. buildah, podman
#
# This is invoked by the 'run_bats_tests' role; we assume that
# the package foo has a foo-tests subpackage which provides the
# directory /usr/share/foo/test/system, containing one or more .bats
# test files.
#
# We create two files:
#
# /tmp/test.summary.log - one-liner with FAIL, PASS, ERROR and a blurb
# /tmp/test.bats.log - full log of this script, plus the BATS run
#
export PATH=/usr/local/bin:/usr/sbin:/usr/bin
FULL_LOG=/tmp/test.bats.log
rm -f $FULL_LOG
touch $FULL_LOG
# Preserve output to a log file, but also emit on stdout. This covers
# RHEL (which preserves logfiles but runs ansible without --verbose)
# and Fedora (which hides logfiles but runs ansible --verbose).
exec &> >(tee -a $FULL_LOG)
# Log program versions
echo "Packages:"
echo " Kernel: $(uname -r)"
rpm -qa |\
grep -E 'buildah|skopeo|toolbox|podman|conmon|containers-common|crun|runc|iptable|slirp|aardvark|netavark|containernetworking-plugins|systemd|container-selinux|passt' |\
sort |\
sed -e 's/^/ /'
divider='------------------------------------------------------------------'
echo $divider
printenv | sort
echo $divider
echo "ip addr:"
ip addr
echo $divider
testdir=/usr/share/${TEST_PACKAGE}/test/system
if ! cd $testdir; then
echo "FAIL ${TEST_NAME} : cd $testdir" > /tmp/test.summary.log
exit 0
fi
if [[ $PODMAN =~ remote ]]; then
${PODMAN%%-remote} system service -t0 &>/dev/null &
PODMAN_SERVER_PID=$!
fi
echo "\$ bats ."
bats .
rc=$?
if [[ -n "$PODMAN_SERVER_PID" ]]; then
kill $PODMAN_SERVER_PID
fi
echo $divider
echo "bats completed with status $rc"
status=PASS
if [ $rc -ne 0 ]; then
status=FAIL
fi
echo "${status} ${TEST_NAME}" > /tmp/test.summary.log
# FIXME: for CI purposes, always exit 0. This allows subsequent tests.
exit 0

View file

@ -1,10 +0,0 @@
---
# Create empty results file, world-writable
- name: initialize test.log file
copy: dest=/tmp/test.log content='' force=yes mode=0666
- name: execute tests
include_tasks: run_one_test.yml
with_items: "{{ tests }}"
loop_control:
loop_var: test

View file

@ -1,87 +0,0 @@
---
- name: "{{ test.name }} | install test packages"
dnf: name="{{ test.package }}-tests" state=installed
- name: "{{ test.name }} | define helper variables"
set_fact:
test_name_oneword: "{{ test.name | replace(' ','-') }}"
# UGH. This is necessary because our caller sets some environment variables
# and we need to set a few more based on other caller variables; then we
# need to combine the two dicts when running the test. This seems to be
# the only way to do it in ansible.
- name: "{{ test.name }} | define local environment"
set_fact:
local_environment:
TEST_NAME: "{{ test.name }}"
TEST_PACKAGE: "{{ test.package }}"
TEST_ENV: "{{ test.environment }}"
- name: "{{ test.name }} | setup/teardown helper | see if exists"
local_action: stat path={{ role_path }}/files/helper.{{ test_name_oneword }}.sh
register: helper
- name: "{{ test.name }} | setup/teardown helper | install"
copy: src=helper.{{ test_name_oneword }}.sh dest=/tmp/helper.sh
when: helper.stat.exists
# This is what runs the BATS tests.
- name: "{{ test.name }} | run test"
script: ./run_bats_tests.sh
args:
chdir: /usr/share/{{ test.package }}/test/system
become: "{{ true if test.become is defined else false }}"
become_user: "{{ rootless_user }}"
environment: "{{ local_environment | combine(test.environment) }}"
# BATS tests will always exit zero and should leave behind two files:
# a full log (test.bats.log) and a one-line PASS/FAIL file (.summary.log)
- name: "{{ test.name }} | pull logs"
fetch:
src: "/tmp/test.{{ item }}.log"
dest: "{{ artifacts }}/test.{{ test_name_oneword }}.{{ item }}.log"
flat: yes
with_items:
- bats
- summary
# Collect all the one-line PASS/FAIL results in one file, test.log
# Write the same thing, in a different format, to results.yml
# https://docs.fedoraproject.org/en-US/ci/standard-test-interface/
- name: "{{ test.name }} | keep running tally of test results"
local_action:
module: shell
cmd: |
cd {{ artifacts }}
cat "test.{{ test_name_oneword }}.summary.log" >>test.log
status=$(awk '{print $1}' <test.{{ test_name_oneword }}.summary.log | tr A-Z a-z)
echo "- test: {{ test.name }}" >>results.yml
echo " result: $status" >>results.yml
echo " logs: test.{{ test_name_oneword }}.bats.log" >>results.yml
# delete the oneliner file, to keep artifacts dir clean
rm -f test.{{ test_name_oneword }}.summary.log
- name: "{{ test.name }} | remove remote logs and helpers"
file:
dest=/tmp/{{ item }}
state=absent
with_items:
- test.bats.log
- test.summary.log
- helper.sh
# AAAAARGH!
#
# Fedora gating tests are failing, because str-common-final/tasks/main.yml
# tries to pull test.log and other logs from $remote_host:/tmp/artifacts .
# Those don't exist, because I track status and artifacts locally, because
# with the reboot I can't rely on /tmp being preserved.
# I see no way to tell str-common-final to skip this step; so let's just
# push logs over upon completion of each subtest.
- name: keep remote artifacts synced
synchronize:
src: "{{ artifacts }}/"
dest: "{{ remote_artifacts|d('/tmp/artifacts') }}/"
mode: push

View file

@ -1,29 +0,0 @@
---
- name: "podman-remote | install"
dnf: name="podman-remote" state=installed
when: podman_bin == "podman-remote"
# As of podman 5.0, slirp is a soft dependency. Until/unless it is
# actually deprecated, we continue to test with it.
- name: "slirp4netns | install"
dnf: name="slirp4netns" state=installed
- include_role:
name: run_bats_tests
vars:
tests:
# Yes, this is horrible duplication, but trying to refactor in ansible
# yields even more horrible unreadable code. This is the lesser evil.
- name: "{{ podman_bin }} root"
package: podman
environment:
PODMAN: /usr/bin/{{ podman_bin }}
PODMAN_TESTING: /usr/bin/podman-testing
QUADLET: /usr/libexec/podman/quadlet
- name: "{{ podman_bin }} rootless"
package: podman
environment:
PODMAN: /usr/bin/{{ podman_bin }}
PODMAN_TESTING: /usr/bin/podman-testing
QUADLET: /usr/libexec/podman/quadlet
become: true

View file

@ -1,39 +0,0 @@
---
- hosts: localhost
tags:
- classic
- container
vars:
- artifacts: ./artifacts
rootless_user: testuser
roles:
- role: disable_systemd_resolved
- role: rootless_user_ready
tasks:
# At the start of a run, clean up state. Useful for test reruns.
- name: local artifacts directory exists
local_action: file path="{{ artifacts }}" state=directory
- name: remove stale log files
local_action: shell rm -f {{ artifacts }}/test*.log
- name: clear test results (test.log)
local_action: command truncate --size=0 {{ artifacts }}/test.log
- name: clear test results (results.yml)
local_action: copy content="results:\n" dest={{ artifacts }}/results.yml
# These are the actual tests.
- name: test podman
include_tasks: run_podman_tests.yml
loop: [ podman, podman-remote ]
loop_control:
loop_var: podman_bin
- name: test toolbx
include_tasks: test_toolbx.yml
# Postprocessing: check for FAIL or ERROR in any test, exit 1 if so
- name: check results
include_tasks: check_results.yml

View file

@ -1,11 +0,0 @@
---
- include_role:
name: run_bats_tests
vars:
tests:
- name: toolbx
package: toolbox
become: true
environment:
TMPDIR: /var/tmp
XDG_RUNTIME_DIR: /run/user/{{ rootless_uid }}

View file

@ -1 +0,0 @@
- import_playbook: test_podman.yml