Compare commits

..

41 commits

Author SHA1 Message Date
Packit
d96e581a46 Update to 5.4.2 upstream release
Upstream tag: v5.4.2
Upstream commit: be85287f

Commit authored by Packit automation (https://packit.dev/)
2025-04-02 16:28:37 +00:00
Packit
26aee3045b Update to 5.4.1 upstream release
Upstream tag: v5.4.1
Upstream commit: b79bc8af

Commit authored by Packit automation (https://packit.dev/)
2025-03-11 18:38:15 +00:00
Packit
700c36629d Update to 5.4.0 upstream release
Upstream tag: v5.4.0
Upstream commit: f9f7d48b

Commit authored by Packit automation (https://packit.dev/)
2025-02-11 18:27:01 +00:00
Packit
3a2977e3e3 Update to 5.3.2 upstream release
Upstream tag: v5.3.2
Upstream commit: 85043bb1

Commit authored by Packit automation (https://packit.dev/)
2025-01-22 13:38:19 +00:00
Lokesh Mandvekar
50840bc5f0
remove patch merged in upcoming upstream release
Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
(cherry picked from commit 37f545e12b2098dd8fead41433c4e45e8c4fa65c)
2025-01-22 19:04:09 +05:30
Mikhail Gavrilov
e7b25177b7
apply MR https://github.com/containers/storage/pull/2193
(cherry picked from commit 6889e09310)
2025-01-17 15:10:21 +05:30
Lokesh Mandvekar
931c45a7b9
remove unused patch
Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
(cherry picked from commit 89aed9941f)
2024-11-27 20:50:16 +05:30
Packit
9a52167206 Update to 5.3.1 upstream release
Upstream tag: v5.3.1
Upstream commit: 4cbdfde5

Commit authored by Packit automation (https://packit.dev/)
2024-11-21 15:41:39 +00:00
Packit
094278c841 Update to 5.3.0 upstream release
Upstream tag: v5.3.0
Upstream commit: 874bf2c3

Commit authored by Packit automation (https://packit.dev/)
2024-11-13 13:16:09 +00:00
Lokesh Mandvekar
0ddcc0cdee
rebuild 2024-10-25 16:59:56 +05:30
Lokesh Mandvekar
f28b34c70f
bump to v5.2.5
Fixes: #2317464 - Security fix for CVE-2024-9675
Fixes: #2319019 - Security fix for CVE-2024-9676
Fixes: #2318511 - Security fix for CVE-2024-9341

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
(cherry picked from commit 5f0570428b)
2024-10-18 23:17:32 +05:30
Lokesh Mandvekar
1f78e0a89f
c/common pr 2194
(cherry picked from commit 7d7eeff1c6)
2024-10-18 23:17:24 +05:30
Packit
5ffbaec905 Update to 5.2.4 upstream release
Upstream tag: v5.2.4
Upstream commit: 76d0859d

Commit authored by Packit automation (https://packit.dev/)
2024-10-07 16:06:19 +00:00
Packit
cdc399082d Update to 5.2.3 upstream release
Upstream tag: v5.2.3
Upstream commit: c5366a30

Commit authored by Packit automation (https://packit.dev/)
2024-09-24 15:19:02 +00:00
Packit
67c6f79e58 Update to 5.2.2 upstream release
Upstream tag: v5.2.2
Upstream commit: fcee4810

Commit authored by Packit automation (https://packit.dev/)
2024-08-21 20:01:27 +00:00
Packit
e40e4c7c79
Update to 5.2.1 upstream release
Upstream tag: v5.2.1
Upstream commit: d0582c9e

Commit authored by Packit automation (https://packit.dev/)

(cherry picked from commit 199ebc87b2e8c8b63c28a86a426348307319b5a2)
2024-08-14 14:23:04 -04:00
Packit
1a4c4bcadb
Update to 5.2.0 upstream release
Upstream tag: v5.2.0
Upstream commit: b22d5c61

Commit authored by Packit automation (https://packit.dev/)
2024-08-02 09:44:27 -04:00
Lokesh Mandvekar
dd59a9527e
check buildah and skopeo version in tests
(cherry picked from commit 44c5587573)
2024-08-01 10:45:05 -04:00
Packit
b2d12e74a3 Update to 5.2.0-rc2 upstream release
Upstream tag: v5.2.0-rc2
Upstream commit: 716874f4

Commit authored by Packit automation (https://packit.dev/)
2024-07-23 12:02:56 +00:00
Lokesh Mandvekar
d2272dd186
fix podman-testing binary
(cherry picked from commit f605ca3f0c)
2024-07-17 08:31:17 -04:00
Lokesh Mandvekar
6f11ee553f
Add PODMAN_TESTING var
(cherry picked from commit 1ed846a4ae)
2024-07-16 13:42:52 -04:00
Packit
0d410b9752 Update to 5.1.2 upstream release
Upstream tag: v5.1.2
Upstream commit: 94a24974

Commit authored by Packit automation (https://packit.dev/)
2024-07-10 14:56:54 +00:00
Packit
4542276b9b Update to 5.1.1 upstream release
Upstream tag: v5.1.1
Upstream commit: bda6eb03

Commit authored by Packit automation (https://packit.dev/)
2024-06-04 21:13:40 +00:00
Packit
71ec61cee5 Update to 5.1.0 upstream release
Upstream tag: v5.1.0
Upstream commit: 4e9486db

Commit authored by Packit automation (https://packit.dev/)
2024-05-29 20:27:17 +00:00
Packit
cb4b5fa9f9 Update to 5.1.0-rc1 upstream release
Upstream tag: v5.1.0-rc1
Upstream commit: 6a8f2e7f

Commit authored by Packit automation (https://packit.dev/)
2024-05-16 12:43:43 +00:00
Packit
767fe1e455
Update to 5.0.3 upstream release
Upstream tag: v5.0.3
Upstream commit: d08315df

Commit authored by Packit automation (https://packit.dev/)

(cherry picked from commit 2a0a1fc671)
2024-05-10 14:13:48 -04:00
Packit
3900c84dda Update to 5.0.2 upstream release
Upstream tag: v5.0.2
Upstream commit: 3304dd95

Commit authored by Packit automation (https://packit.dev/)
2024-04-17 19:14:49 +00:00
Packit
c838401773 [packit] 5.0.1 upstream release
Upstream tag: v5.0.1
Upstream commit: 946d055d
2024-04-01 14:07:30 +00:00
Ed Santiago
b15c24aa87
Podman tests: force-install slirp4netns
As of podman 5.0, slirp4 is no longer an RPM Requirement. It
is not deprecated, though, so we should continue to test it.

Signed-off-by: Ed Santiago <santiago@redhat.com>
(cherry picked from commit 9667d0f5b5)
2024-03-27 17:18:05 +05:30
Packit
7b00c4e46f [packit] 5.0.0 upstream release
Upstream tag: v5.0.0
Upstream commit: e71ec6f1
2024-03-19 17:26:37 +00:00
Packit
43df44e272 [packit] 5.0.0-rc7 upstream release
Upstream tag: v5.0.0-rc7
Upstream commit: f8888a13
2024-03-15 13:25:29 +00:00
Lokesh Mandvekar
495a037489
Resolves: #2269148 - make passt a hard dep
Signed-off-by: Lokesh Mandvekar <lsm5@redhat.com>
(cherry picked from commit c837778125)
2024-03-13 17:45:12 +05:30
Packit
480d655ed9 [packit] 5.0.0-rc6 upstream release
Upstream tag: v5.0.0-rc6
Upstream commit: d26113ca
2024-03-11 19:05:20 +00:00
Packit
a433181a4b [packit] 5.0.0-rc5 upstream release
Upstream tag: v5.0.0-rc5
Upstream commit: bbad09bb
2024-03-08 02:48:49 +00:00
Packit
81be0854d2 [packit] 5.0.0-rc4 upstream release
Upstream tag: v5.0.0-rc4
Upstream commit: cfc5b8e0
2024-03-05 10:42:03 +00:00
Debarshi Ray
46b5dceb08 Show the toolbox RPMs used to run the tests
This will make it easier to debug test failures by confirming if they
are caused by old buggy toolbox RPMs or if the fixes don't work as
intended.

https://src.fedoraproject.org/rpms/podman/pull-request/134
https://src.fedoraproject.org/rpms/podman/pull-request/133
(cherry picked from commit 5a89a85665)
2024-03-01 11:04:40 +01:00
Debarshi Ray
c616ef6581 Avoid running out of storage space when running the Toolbx tests
Toolbx's system tests download several images when setting up the test
suite, and cache them for later use by the tests [1].  This saves time
and avoids hitting rate limits imposed by OCI registries by not
downloading the same images repeatedly for several tests, but at the
cost of increased use of storage space to cache the images.

The images are cached under BATS_TMPDIR.  It defaults to the TMPDIR
environment variable, and if that's not set then to /tmp [2].  Normally,
TMPDIR isn't set, and the images end up getting cached under /tmp.  Now,
/tmp is typically on tmpfs backed by RAM or swap, which means that it
should be used for smaller size-bounded files only, and /var/tmp should
be used for everything else [3].

The images are big enough that a collection of them can't be described
as smaller and size-bounded, and it led to:
  1..306
  # test suite: Set up
  # test suite: Tear down
  not ok 1 setup_suite
  # (from function `setup_suite' in test file ./setup_suite.bash, line
      55)
  #   `_pull_and_cache_distro_image fedora "$((system_version-1))" ||
      false' failed
  # Failed to cache image registry.fedoraproject.org/fedora-toolbox:40
      to /tmp/bats-run-IPz4Cn/image-cache/fedora-toolbox-40
  # time="2024-02-19T11:41:43Z" level=fatal msg="copying system image
      from manifest list: writing blob: write
      /tmp/bats-run-IPz4Cn/image-cache/fedora-toolbox-40/dir-put-blob607392514:
      no space left on device"
  # bats warning: Executed 1 instead of expected 306 tests

So, change the default location of the BATS_TMPDIR environment variable
to /var/tmp by setting TMPDIR.

[1] Toolbx commit 50683c9d9a78adc9
    50683c9d9a
    https://github.com/containers/toolbox/pull/375

[2] https://bats-core.readthedocs.io/en/stable/writing-tests.html

[3] https://systemd.io/TEMPORARY_DIRECTORIES/

https://src.fedoraproject.org/rpms/podman/pull-request/134
https://src.fedoraproject.org/rpms/podman/pull-request/128
(cherry picked from commit c2712c6a6b)
2024-03-01 11:04:40 +01:00
Debarshi Ray
864ae2707f Silence warnings about deprecated grep(1) use in test logs
The egrep command was deprecated in 2007 as part of Grep 2.5.3, and
since Grep 3.8 it actually warns about it [1].  The warning shows up in
the test logs as:
  egrep: warning: egrep is obsolescent; using grep -E

[1] Grep commit a9515624709865d4
    https://git.savannah.gnu.org/cgit/grep.git/commit/?id=a9515624709865d4

https://src.fedoraproject.org/rpms/podman/pull-request/134
https://src.fedoraproject.org/rpms/podman/pull-request/125
(cherry picked from commit 89acf13e05)
2024-03-01 11:04:40 +01:00
Debarshi Ray
d5ceaea206 Update how Toolbx is spelt
This is meant to make the project more searchable on the Internet.  More
and more people have been pointing out that "toolbox" is terribly
difficult to search for, and it's impossible to find any decent
Internet real estate by that name.

Some exceptions:

  * The code repository is still https://github.com/containers/toolbox.
    It will be renamed after giving a heads-up to other contributors.

  * The name of the binary is still 'toolbox'.  The name is embedded
    into existing Toolbx containers as their entry point, which is bind
    mounted from the host operating system when the containers are
    started.  Trivially renaming the binary will prevent these
    containers from starting.

  * The name of the Fedora package is still 'toolbox'.

https://src.fedoraproject.org/rpms/podman/pull-request/134
https://src.fedoraproject.org/rpms/podman/pull-request/122
(cherry picked from commit 7bff8d08f6)
2024-03-01 11:04:32 +01:00
Packit
a39a897583 [packit] 5.0.0-rc3 upstream release
Upstream tag: v5.0.0-rc3
Upstream commit: 54795efe
2024-02-22 21:07:43 +00:00
Packit
261067f5cd [packit] 5.0.0-rc2 upstream release
Upstream tag: v5.0.0-rc2
Upstream commit: f620aa0f
2024-02-16 16:46:16 +00:00
26 changed files with 394 additions and 360 deletions

View file

@ -1 +0,0 @@
1

20
.gitignore vendored
View file

@ -1861,7 +1861,6 @@
/v5.1.0.tar.gz
/v5.1.1.tar.gz
/v5.1.2.tar.gz
/v5.2.0-rc1.tar.gz
/v5.2.0-rc2.tar.gz
/v5.2.0.tar.gz
/v5.2.1.tar.gz
@ -1869,28 +1868,9 @@
/v5.2.3.tar.gz
/v5.2.4.tar.gz
/v5.2.5.tar.gz
/v5.3.0-rc1.tar.gz
/v5.3.0-rc2.tar.gz
/v5.3.0-rc3.tar.gz
/v5.3.0.tar.gz
/v5.3.1.tar.gz
/v5.3.2.tar.gz
/v5.4.0-rc2.tar.gz
/v5.4.0-rc3.tar.gz
/v5.4.0.tar.gz
/v5.4.1.tar.gz
/v5.4.2.tar.gz
/v5.5.0-rc1.tar.gz
/v5.5.0-rc2.tar.gz
/v5.5.0.tar.gz
/v5.5.1.tar.gz
/v5.5.2.tar.gz
/v5.6.0-rc1.tar.gz
/v5.6.0-rc2.tar.gz
/v5.6.0.tar.gz
/v5.6.1.tar.gz
/v5.6.2.tar.gz
/v5.7.0-rc1.tar.gz
/v5.7.0-rc2.tar.gz
/v5.7.0.tar.gz
/v5.7.1.tar.gz

View file

@ -5,27 +5,6 @@
downstream_package_name: podman
upstream_tag_template: v{version}
# These files get synced from upstream to downstream (Fedora / CentOS Stream) on every
# propose-downstream job. This is done so tests maintained upstream can be run
# downstream in Zuul CI and Bodhi.
# Ref: https://packit.dev/docs/configuration#files_to_sync
files_to_sync:
- src: rpm/gating.yaml
dest: gating.yaml
delete: true
- src: plans/
dest: plans/
delete: true
mkpath: true
- src: test/tmt/
dest: test/tmt/
delete: true
mkpath: true
- src: .fmf/
dest: .fmf/
delete: true
- .packit.yaml
packages:
podman-fedora:
pkg_tool: fedpkg
@ -36,9 +15,6 @@ packages:
podman-eln:
specfile_path: rpm/podman.spec
# Disable automatic merging for Copr builds (and subsequent Testing Farm)
merge_pr_in_ci: false
srpm_build_deps:
- git-archive-all
- make
@ -58,13 +34,9 @@ jobs:
targets:
- fedora-all-x86_64
- fedora-all-aarch64
# Re-enable these scans if OpenScanHub starts scanning go packages
# https://packit.dev/posts/openscanhub-prototype
osh_diff_scan_after_copr_build: false
# Ignore until golang is updated in distro buildroot to go 1.23.3+
- job: copr_build
trigger: ignore
trigger: pull_request
packages: [podman-eln]
notifications: *packit_generic_failure_notification
enable_net: true
@ -76,9 +48,8 @@ jobs:
additional_repos:
- "https://kojipkgs.fedoraproject.org/repos/eln-build/latest/aarch64/"
# Ignore until golang is updated in distro buildroot to go 1.23.3+
- job: copr_build
trigger: ignore
trigger: pull_request
packages: [podman-centos]
notifications: *packit_generic_failure_notification
enable_net: true
@ -92,20 +63,14 @@ jobs:
- job: copr_build
trigger: commit
packages: [podman-fedora]
notifications:
failure_comment:
message: "podman-next COPR build failed. @containers/packit-build please check."
branch: main
owner: rhcontainerbot
project: podman-next
enable_net: true
# Tests on Fedora
- job: tests
trigger: pull_request
packages: [podman-fedora]
notifications: *packit_generic_failure_notification
targets:
- fedora-all
tmt_plan: "/plans/system/*"
- job: tests
identifier: cockpit-revdeps
trigger: pull_request
@ -121,24 +86,12 @@ jobs:
- artifacts:
- type: repository-file
id: https://copr.fedorainfracloud.org/coprs/g/cockpit/main-builds/repo/fedora-$releasever/group_cockpit-main-builds-fedora-$releasever.repo
- type: repository-file
id: https://copr.fedorainfracloud.org/coprs/rhcontainerbot/podman-next/repo/fedora-$releasever/rhcontainerbot-podman-next-fedora-$releasever.repo
tmt:
context:
revdeps: "yes"
- job: tests
identifier: tmt-revdeps
trigger: pull_request
packages: [podman-fedora]
notifications:
failure_comment:
message: "tmt tests failed for commit {commit_sha}. @lsm5, @psss, @thrix please check."
targets:
- fedora-latest
fmf_url: https://github.com/teemtee/tmt
fmf_path: /plans/friends
fmf_ref: main
tmt_plan: "/podman"
- job: propose_downstream
trigger: release
update_release: false
@ -146,6 +99,13 @@ jobs:
dist_git_branches: &fedora_targets
- fedora-all
- job: propose_downstream
trigger: release
update_release: false
packages: [podman-centos]
dist_git_branches:
- c10s
- job: koji_build
trigger: commit
packages: [podman-fedora]

View file

@ -1,3 +1,3 @@
This repository is maintained by packit.
https://packit.dev/
The file was generated using packit 1.12.0.post1.dev22+gfe66fd850.
The file was generated using packit 1.4.0.post1.dev4+g043c5fde.

View file

@ -7,11 +7,3 @@ decision_contexts:
subject_type: koji_build
rules:
- !PassingTestCaseRule {test_case_name: fedora-ci.koji-build.tier0.functional}
# recipients: jnovy, lsm5, santiago
--- !Policy
product_versions:
- rhel-*
decision_context: osci_compose_gate
rules:
- !PassingTestCaseRule {test_case_name: osci.brew-build.tier0.functional}

View file

@ -1,37 +0,0 @@
# reverse dependency test for https://github.com/cockpit-project/cockpit-podman/
# packit should automatically notify the cockpit maintainers on failures.
# For questions, please contact @martinpitt, @jelly, @mvollmer
enabled: false
adjust+:
when: revdeps == yes
enabled: true
discover:
how: fmf
url: https://github.com/cockpit-project/cockpit-podman
ref: "main"
execute:
how: tmt
# not relevant for testing podman
environment:
TEST_AUDIT_NO_SELINUX: 1
TEST_ALLOW_JOURNAL_MESSAGES: ".*"
# This has to duplicate cockpit-podman's plan structure; see https://github.com/teemtee/tmt/issues/1770
/podman-system:
summary: Run cockpit-podman system tests
discover+:
test: /test/browser/system
/podman-user:
summary: Run cockpit-podman user tests
discover+:
test: /test/browser/user
/podman-misc:
summary: Run other cockpit-podman tests
discover+:
test: /test/browser/other

View file

@ -1,50 +0,0 @@
discover:
how: fmf
execute:
how: tmt
prepare:
- how: shell
script: modprobe null_blk nr_devices=1
order: 5
- when: distro == centos-stream or distro == rhel
how: shell
script: |
dnf -y install https://dl.fedoraproject.org/pub/epel/epel-release-latest-$(rpm --eval '%{?rhel}').noarch.rpm
dnf -y config-manager --set-enabled epel
order: 10
adjust+:
- enabled: false
when: revdeps == yes
provision:
how: artemis
hardware:
memory: ">= 16 GB"
cpu:
cores: ">= 4"
threads: ">=8"
disk:
- size: ">= 512 GB"
/local-root:
summary: Local rootful tests
discover+:
filter: 'tag:local & tag:root'
/local-rootless:
summary: Local rootless tests
discover+:
filter: 'tag:local & tag:rootless'
/remote-root:
summary: Remote rootful tests
discover+:
filter: 'tag:remote & tag:root'
/remote-rootless:
summary: Remote rootless tests
discover+:
filter: 'tag:remote & tag:rootless'

View file

@ -1,21 +0,0 @@
summary: Run tmt container provision test (downstream only)
enabled: false
adjust+:
- enabled: true
when: initiator != packit and distro != rhel
discover:
how: fmf
filter: 'tag:tmt & tag:downstream'
execute:
how: tmt
prepare:
- when: distro == centos-stream or distro == rhel
how: shell
script: |
dnf -y install https://dl.fedoraproject.org/pub/epel/epel-release-latest-$(rpm --eval '%{?rhel}').noarch.rpm
dnf -y config-manager --set-enabled epel
order: 10

View file

@ -1,29 +0,0 @@
summary: Run toolbox tests (downstream only)
enabled: false
adjust+:
- enabled: true
when: initiator != packit and distro == fedora
provision:
how: artemis
hardware:
memory: ">= 16 GB"
cpu:
cores: ">= 4"
threads: ">=8"
disk:
- size: ">= 512 GB"
prepare:
- name: packages
how: install
package: [toolbox-tests]
discover:
how: fmf
url: https://src.fedoraproject.org/rpms/toolbox
ref: "rawhide"
execute:
how: tmt

View file

@ -13,18 +13,10 @@
%define build_with_btrfs 1
# qemu-system* isn't packageed for CentOS Stream / RHEL
%define qemu 1
# bats is included in the default repos (No epel/copr etc.)
%define distro_bats 1
%if %{?fedora} >= 43
%define sequoia 1
%endif
%endif
%if %{defined copr_username}
%define copr_build 1
%if "%{copr_username}" == "rhcontainerbot" && "%{copr_projectname}" == "podman-next"
%define next_build 1
%endif
%endif
# Only RHEL and CentOS Stream rpms are built with fips-enabled go compiler
@ -52,7 +44,7 @@
%endif
Name: podman
%if %{defined next_build}
%if %{defined copr_build}
Epoch: 102
%else
Epoch: 5
@ -63,7 +55,7 @@ Epoch: 5
# If that's what you're reading, Version must be 0, and will be updated by Packit for
# copr and koji builds.
# If you're reading this on dist-git, the version is automatically filled in by Packit.
Version: 5.7.1
Version: 5.4.2
# The `AND` needs to be uppercase in the License for SPDX compatibility
License: Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND ISC AND MIT AND MPL-2.0
Release: %autorelease
@ -99,7 +91,7 @@ BuildRequires: shadow-utils-subid-devel
BuildRequires: pkgconfig
BuildRequires: make
BuildRequires: man-db
BuildRequires: sqlite-devel
BuildRequires: ostree-devel
BuildRequires: systemd
BuildRequires: systemd-devel
Requires: catatonit
@ -112,10 +104,6 @@ Requires: containers-common-extra >= 5:0.58.0-1
%else
Requires: containers-common-extra
%endif
%if %{defined sequoia}
Requires: podman-sequoia
%endif
Obsoletes: %{name}-quadlet <= 5:4.4.0-1
Provides: %{name}-quadlet = %{epoch}:%{version}-%{release}
@ -151,7 +139,7 @@ pages and %{name}.
Summary: Tests for %{name}
Requires: %{name} = %{epoch}:%{version}-%{release}
%if %{defined distro_bats}
%if %{defined fedora}
Requires: bats
%endif
Requires: attr
@ -161,7 +149,6 @@ Requires: nmap-ncat
Requires: httpd-tools
Requires: openssl
Requires: socat
Requires: slirp4netns
Requires: buildah
Requires: gnupg
Requires: xfsprogs
@ -169,8 +156,7 @@ Requires: xfsprogs
%description tests
%{summary}
This package contains system tests for %{name}. Only intended to be used for
gating tests. Not supported for end users / customers.
This package contains system tests for %{name}
%package remote
Summary: (Experimental) Remote client for managing %{name} containers
@ -254,13 +240,13 @@ LDFLAGS="-X %{ld_libpod}/define.buildInfo=${SOURCE_DATE_EPOCH:-$(date +%s)} \
# This variable will be set by Packit actions. See .packit.yaml in the root dir
# of the repo (upstream as well as Fedora dist-git).
GIT_COMMIT="f845d14e941889ba4c071f35233d09b29d363c75"
GIT_COMMIT="be85287fcf4590961614ee37be65eeb315e5d9ff"
LDFLAGS="$LDFLAGS -X %{ld_libpod}/define.gitCommit=$GIT_COMMIT"
# build rootlessport first
%gobuild -o bin/rootlessport ./cmd/rootlessport
export BASEBUILDTAGS="seccomp $(hack/systemd_tag.sh) $(hack/libsubid_tag.sh) libsqlite3 grpcnotrace"
export BASEBUILDTAGS="seccomp exclude_graphdriver_devicemapper $(hack/systemd_tag.sh) $(hack/libsubid_tag.sh)"
# libtrust_openssl buildtag switches to using the FIPS-compatible func
# `ecdsa.HashSign`.
@ -271,24 +257,19 @@ export BASEBUILDTAGS="$BASEBUILDTAGS libtrust_openssl"
%endif
# build %%{name}
export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh)"
%if %{defined sequoia}
export BUILDTAGS="$BUILDTAGS containers_image_sequoia"
%endif
export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh) $(hack/btrfs_tag.sh) $(hack/libdm_tag.sh)"
%gobuild -o bin/%{name} ./cmd/%{name}
# build %%{name}-remote
export BUILDTAGS="$BASEBUILDTAGS exclude_graphdriver_btrfs remote"
export BUILDTAGS="$BASEBUILDTAGS exclude_graphdriver_btrfs btrfs_noversion remote"
%gobuild -o bin/%{name}-remote ./cmd/%{name}
# build quadlet
export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh)"
export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh) $(hack/btrfs_tag.sh)"
%gobuild -o bin/quadlet ./cmd/quadlet
# build %%{name}-testing
export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh)"
export BUILDTAGS="$BASEBUILDTAGS $(hack/btrfs_installed_tag.sh) $(hack/btrfs_tag.sh)"
%gobuild -o bin/podman-testing ./cmd/podman-testing
# reset LDFLAGS for plugins binaries
@ -308,6 +289,11 @@ PODMAN_VERSION=%{version} %{__make} DESTDIR=%{buildroot} PREFIX=%{_prefix} ETCDI
install.remote \
install.testing
# See above for the iptables.conf declaration
%if %{defined fedora} && 0%{?fedora} < 41
%{__make} DESTDIR=%{buildroot} MODULESLOADDIR=%{_modulesloaddir} install.modules-load
%endif
sed -i 's;%{buildroot};;g' %{buildroot}%{_bindir}/docker
# do not include docker and podman-remote man pages in main package

View file

@ -1 +1 @@
SHA512 (v5.7.1.tar.gz) = 81fd4c27ff1d16dcb85229d4e4fd2cb06943ddfe966b5324fa8a8a957b2d2ec2aed7c5da05d6c009148f53b76545b27b0cba506622c8861f70bf7cad6c214a08
SHA512 (v5.4.2.tar.gz) = 482fde529766ca1b509a08bab4beb59a5935ebc6b27bc886c33597183258631e8c8db03ebb521baefd7989305aa76fad14c1359e211a0fe75c855c14bbaca960

View file

@ -1,51 +0,0 @@
require:
- podman-tests
- psmisc
environment:
# PODMAN_TESTING envvar is set in system.sh
PODMAN: /usr/bin/podman
QUADLET: /usr/libexec/podman/quadlet
ROOTLESS_USER: "fedora"
adjust+:
- when: distro == centos-stream
environment+:
ROOTLESS_USER: "ec2-user"
- when: distro == rhel
environment+:
ROOTLESS_USER: "cloud-user"
- when: initiator != "packit"
environment+:
RELEASE_TESTING: true
/local-root:
tag: [ local, root ]
summary: local rootful test
test: bash ./system.sh
duration: 30m
/local-rootless:
tag: [ local, rootless ]
summary: rootless test
test: bash ./system.sh rootless
duration: 30m
/remote-root:
tag: [ remote, root ]
summary: remote rootful test
test: bash ./system.sh
duration: 30m
environment+:
PODMAN: /usr/bin/podman-remote
require+:
- podman-remote
/remote-rootless:
tag: [ remote, rootless ]
summary: remote rootless test
test: bash ./system.sh rootless
duration: 30m
environment+:
PODMAN: /usr/bin/podman-remote
require+:
- podman-remote

View file

@ -1,44 +0,0 @@
#!/usr/bin/env bash
set -exo pipefail
uname -r
loginctl enable-linger "$ROOTLESS_USER"
rpm -q \
aardvark-dns \
buildah \
conmon \
container-selinux \
containers-common \
criu \
crun \
netavark \
passt \
podman \
podman-tests \
skopeo \
slirp4netns \
systemd
export system_service_cmd="/usr/bin/podman system service --timeout=0 &"
export test_cmd="whoami && cd /usr/share/podman/test/system && PODMAN_TESTING=/usr/bin/podman-testing bats ."
if [[ -z $1 ]]; then
if [[ $PODMAN == "/usr/bin/podman-remote" ]]; then
eval "$system_service_cmd"
fi
eval "$test_cmd"
elif [[ $1 == "rootless" ]]; then
if [[ $PODMAN == "/usr/bin/podman-remote" ]]; then
su - "$ROOTLESS_USER" -c "eval $system_service_cmd"
fi
su - "$ROOTLESS_USER" -c "eval $test_cmd"
fi
# Kill all podman processes for remote tests
if [[ $PODMAN == "/usr/bin/podman-remote" ]]; then
killall -q podman
fi
exit 0

View file

@ -1,13 +0,0 @@
enabled: false
adjust:
enabled: true
when: initiator != packit && distro != rhel
summary: Make sure that TMT container provision works
tag: [downstream]
require:
- tmt+provision-container
test:
tmt run --verbose --remove
provision --how container --image fedora
login --command 'cat /etc/os-release'
finish

18
tests/README Normal file
View file

@ -0,0 +1,18 @@
I'm sorry. The playbooks here are a much-too-complicated way of saying:
- test podman (root and rootless)
- same, with podman-remote
The starting point is tests.yml . From there:
tests.yml
\- test_podman.yml
|- roles/rootless_user_ready/
\- run_podman_tests.yml (once for local, once for remote)
\- roles/run_bats_tests/ (runs tests: root, rootless)
Principal result is the file 'artifacts/test.log'. It will contain
one line for each test run, format will be '(PASS|FAIL|ERROR) <test name>'
For each completed test there will also be a 'test.<name>.bats.log'
containing some setup blurbs (RPMs, environment) and the full BATS log.

36
tests/check_results.yml Normal file
View file

@ -0,0 +1,36 @@
---
# Copied from standard-test-basic
# ...and, 2020-05-13, updated, looks like they changed the whole thing around
- name: Check the results
local_action:
module: shell
cmd: |
log="{{ artifacts }}/test.log"
if [ ! -f "$log" ]; then
echo ERROR
echo "Test results not found." 1>&2
elif grep ^ERROR "$log" 1>&2; then
echo ERROR
elif grep ^FAIL "$log" 1>&2; then
echo FAIL
elif grep -q ^PASS "$log"; then
echo PASS
else
echo ERROR
echo "No test results found." 1>&2
fi
register: test_results
- name: Set role result
set_fact:
role_result: "{{ test_results.stdout }}"
role_message: "{{ test_results.stderr|d('test execution error.') }}"
- name: display results
vars:
msg: |
role_result: {{ role_result|d('Undefined') }}
{{ role_message|d('[No error messages found]') }}
debug:
msg: "{{ msg.split('\n') }}"
failed_when: role_message|d("") != ""

View file

@ -0,0 +1,41 @@
#!/bin/bash
#
# Excerpted from https://github.com/containers/automation_images/blob/main/systemd_banish.sh
#
# Early 2023: https://github.com/containers/podman/issues/16973
#
# We see countless instances of "lookup cdn03.quay.io" flakes.
# Disabling the systemd resolver has completely resolved those,
# from multiple flakes per day to zero in a month.
#
# Opinions differ on the merits of systemd-resolve, but the fact is
# it breaks our CI testing. Kill it.
nsswitch=/etc/authselect/nsswitch.conf
if [[ -e $nsswitch ]]; then
if grep -q -E 'hosts:.*resolve' $nsswitch; then
echo "Disabling systemd-resolved"
sed -i -e 's/^\(hosts: *\).*/\1files dns myhostname/' $nsswitch
systemctl disable --now systemd-resolved
rm -f /etc/resolv.conf
# NetworkManager may already be running, or it may not....
systemctl start NetworkManager
sleep 1
systemctl restart NetworkManager
# ...and it may create resolv.conf upon start/restart, or it
# may not. Keep restarting until it does. (Yes, I realize
# this is cargocult thinking. Don't care. Not worth the effort
# to diagnose and solve properly.)
retries=10
while ! test -e /etc/resolv.conf;do
retries=$((retries - 1))
if [[ $retries -eq 0 ]]; then
echo "Timed out waiting for resolv.conf" >&2
echo "...gonna try continuing. Expect failures." >&2
fi
systemctl restart NetworkManager
sleep 5
done
fi
fi

View file

@ -0,0 +1,3 @@
---
- name: disable systemd resolved
script: ./disable_systemd_resolved.sh

View file

@ -0,0 +1,14 @@
---
- name: make sure rootless account exists
user: name={{ rootless_user }}
- name: rootless account | enable linger
shell: loginctl enable-linger {{ rootless_user }}
- name: rootless account | get uid
getent:
database: passwd
key: "{{ rootless_user }}"
- name: rootless account | preserve uid
set_fact: rootless_uid="{{ getent_passwd[rootless_user][1] }}"

View file

@ -0,0 +1,73 @@
#!/bin/bash
#
# Run bats tests for a given $TEST_PACKAGE, e.g. buildah, podman
#
# This is invoked by the 'run_bats_tests' role; we assume that
# the package foo has a foo-tests subpackage which provides the
# directory /usr/share/foo/test/system, containing one or more .bats
# test files.
#
# We create two files:
#
# /tmp/test.summary.log - one-liner with FAIL, PASS, ERROR and a blurb
# /tmp/test.bats.log - full log of this script, plus the BATS run
#
export PATH=/usr/local/bin:/usr/sbin:/usr/bin
FULL_LOG=/tmp/test.bats.log
rm -f $FULL_LOG
touch $FULL_LOG
# Preserve output to a log file, but also emit on stdout. This covers
# RHEL (which preserves logfiles but runs ansible without --verbose)
# and Fedora (which hides logfiles but runs ansible --verbose).
exec &> >(tee -a $FULL_LOG)
# Log program versions
echo "Packages:"
echo " Kernel: $(uname -r)"
rpm -qa |\
grep -E 'buildah|skopeo|toolbox|podman|conmon|containers-common|crun|runc|iptable|slirp|aardvark|netavark|containernetworking-plugins|systemd|container-selinux|passt' |\
sort |\
sed -e 's/^/ /'
divider='------------------------------------------------------------------'
echo $divider
printenv | sort
echo $divider
echo "ip addr:"
ip addr
echo $divider
testdir=/usr/share/${TEST_PACKAGE}/test/system
if ! cd $testdir; then
echo "FAIL ${TEST_NAME} : cd $testdir" > /tmp/test.summary.log
exit 0
fi
if [[ $PODMAN =~ remote ]]; then
${PODMAN%%-remote} system service -t0 &>/dev/null &
PODMAN_SERVER_PID=$!
fi
echo "\$ bats ."
bats .
rc=$?
if [[ -n "$PODMAN_SERVER_PID" ]]; then
kill $PODMAN_SERVER_PID
fi
echo $divider
echo "bats completed with status $rc"
status=PASS
if [ $rc -ne 0 ]; then
status=FAIL
fi
echo "${status} ${TEST_NAME}" > /tmp/test.summary.log
# FIXME: for CI purposes, always exit 0. This allows subsequent tests.
exit 0

View file

@ -0,0 +1,10 @@
---
# Create empty results file, world-writable
- name: initialize test.log file
copy: dest=/tmp/test.log content='' force=yes mode=0666
- name: execute tests
include_tasks: run_one_test.yml
with_items: "{{ tests }}"
loop_control:
loop_var: test

View file

@ -0,0 +1,87 @@
---
- name: "{{ test.name }} | install test packages"
dnf: name="{{ test.package }}-tests" state=installed
- name: "{{ test.name }} | define helper variables"
set_fact:
test_name_oneword: "{{ test.name | replace(' ','-') }}"
# UGH. This is necessary because our caller sets some environment variables
# and we need to set a few more based on other caller variables; then we
# need to combine the two dicts when running the test. This seems to be
# the only way to do it in ansible.
- name: "{{ test.name }} | define local environment"
set_fact:
local_environment:
TEST_NAME: "{{ test.name }}"
TEST_PACKAGE: "{{ test.package }}"
TEST_ENV: "{{ test.environment }}"
- name: "{{ test.name }} | setup/teardown helper | see if exists"
local_action: stat path={{ role_path }}/files/helper.{{ test_name_oneword }}.sh
register: helper
- name: "{{ test.name }} | setup/teardown helper | install"
copy: src=helper.{{ test_name_oneword }}.sh dest=/tmp/helper.sh
when: helper.stat.exists
# This is what runs the BATS tests.
- name: "{{ test.name }} | run test"
script: ./run_bats_tests.sh
args:
chdir: /usr/share/{{ test.package }}/test/system
become: "{{ true if test.become is defined else false }}"
become_user: "{{ rootless_user }}"
environment: "{{ local_environment | combine(test.environment) }}"
# BATS tests will always exit zero and should leave behind two files:
# a full log (test.bats.log) and a one-line PASS/FAIL file (.summary.log)
- name: "{{ test.name }} | pull logs"
fetch:
src: "/tmp/test.{{ item }}.log"
dest: "{{ artifacts }}/test.{{ test_name_oneword }}.{{ item }}.log"
flat: yes
with_items:
- bats
- summary
# Collect all the one-line PASS/FAIL results in one file, test.log
# Write the same thing, in a different format, to results.yml
# https://docs.fedoraproject.org/en-US/ci/standard-test-interface/
- name: "{{ test.name }} | keep running tally of test results"
local_action:
module: shell
cmd: |
cd {{ artifacts }}
cat "test.{{ test_name_oneword }}.summary.log" >>test.log
status=$(awk '{print $1}' <test.{{ test_name_oneword }}.summary.log | tr A-Z a-z)
echo "- test: {{ test.name }}" >>results.yml
echo " result: $status" >>results.yml
echo " logs: test.{{ test_name_oneword }}.bats.log" >>results.yml
# delete the oneliner file, to keep artifacts dir clean
rm -f test.{{ test_name_oneword }}.summary.log
- name: "{{ test.name }} | remove remote logs and helpers"
file:
dest=/tmp/{{ item }}
state=absent
with_items:
- test.bats.log
- test.summary.log
- helper.sh
# AAAAARGH!
#
# Fedora gating tests are failing, because str-common-final/tasks/main.yml
# tries to pull test.log and other logs from $remote_host:/tmp/artifacts .
# Those don't exist, because I track status and artifacts locally, because
# with the reboot I can't rely on /tmp being preserved.
# I see no way to tell str-common-final to skip this step; so let's just
# push logs over upon completion of each subtest.
- name: keep remote artifacts synced
synchronize:
src: "{{ artifacts }}/"
dest: "{{ remote_artifacts|d('/tmp/artifacts') }}/"
mode: push

View file

@ -0,0 +1,29 @@
---
- name: "podman-remote | install"
dnf: name="podman-remote" state=installed
when: podman_bin == "podman-remote"
# As of podman 5.0, slirp is a soft dependency. Until/unless it is
# actually deprecated, we continue to test with it.
- name: "slirp4netns | install"
dnf: name="slirp4netns" state=installed
- include_role:
name: run_bats_tests
vars:
tests:
# Yes, this is horrible duplication, but trying to refactor in ansible
# yields even more horrible unreadable code. This is the lesser evil.
- name: "{{ podman_bin }} root"
package: podman
environment:
PODMAN: /usr/bin/{{ podman_bin }}
PODMAN_TESTING: /usr/bin/podman-testing
QUADLET: /usr/libexec/podman/quadlet
- name: "{{ podman_bin }} rootless"
package: podman
environment:
PODMAN: /usr/bin/{{ podman_bin }}
PODMAN_TESTING: /usr/bin/podman-testing
QUADLET: /usr/libexec/podman/quadlet
become: true

39
tests/test_podman.yml Normal file
View file

@ -0,0 +1,39 @@
---
- hosts: localhost
tags:
- classic
- container
vars:
- artifacts: ./artifacts
rootless_user: testuser
roles:
- role: disable_systemd_resolved
- role: rootless_user_ready
tasks:
# At the start of a run, clean up state. Useful for test reruns.
- name: local artifacts directory exists
local_action: file path="{{ artifacts }}" state=directory
- name: remove stale log files
local_action: shell rm -f {{ artifacts }}/test*.log
- name: clear test results (test.log)
local_action: command truncate --size=0 {{ artifacts }}/test.log
- name: clear test results (results.yml)
local_action: copy content="results:\n" dest={{ artifacts }}/results.yml
# These are the actual tests.
- name: test podman
include_tasks: run_podman_tests.yml
loop: [ podman, podman-remote ]
loop_control:
loop_var: podman_bin
- name: test toolbx
include_tasks: test_toolbx.yml
# Postprocessing: check for FAIL or ERROR in any test, exit 1 if so
- name: check results
include_tasks: check_results.yml

11
tests/test_toolbx.yml Normal file
View file

@ -0,0 +1,11 @@
---
- include_role:
name: run_bats_tests
vars:
tests:
- name: toolbx
package: toolbox
become: true
environment:
TMPDIR: /var/tmp
XDG_RUNTIME_DIR: /run/user/{{ rootless_uid }}

1
tests/tests.yml Normal file
View file

@ -0,0 +1 @@
- import_playbook: test_podman.yml