Commit graph

170 commits

Author SHA1 Message Date
Alejandro Sáez
edd2298769 rebuild 2025-10-10 15:13:52 +02:00
Debarshi Ray
0f5c4c381d Unify the build with RHEL 9
There's no need to do a build just for this.
2025-10-07 15:13:09 +02:00
Debarshi Ray
a2c786de0b Update to 0.3
... and update the BuildRequires on golang to reflect reality.

https://src.fedoraproject.org/rpms/toolbox/pull-request/39
2025-09-18 12:24:19 +02:00
Debarshi Ray
f46fb3ba3c tests: Don't needlessly preserve environment variables in su(1) sessions
The TMT namespaced environment variables are not referenced anywhere
else and were recently removed from Podman too [1].  It's confusing to
have a long list of variables, which are either unused or don't need to
be explicitly preserved within the child session started by su(1).

ROOTLESS_USER is used when invoking su(1) and there's no need for it
within the child session started by su(1).

[1] Fedora podman commit b972298be7d228f4
    https://src.fedoraproject.org/rpms/podman/c/b972298be7d228f4

https://src.fedoraproject.org/rpms/toolbox/pull-request/36
2025-09-17 20:44:25 +02:00
Maxwell G
94a6775aac Rebuild for golang-1.25.0 2025-08-15 18:43:04 -05:00
Debarshi Ray
1ba0b4876e Update to 0.2
... and fix CVE-2025-23266, CVE-2025-23267, and GHSA-fv92-fjc5-jj9h or
GO-2025-3787.

The following rpmlint warning was silenced:
  toolbox.spec: W: no-%check-section

The timeout for the CI was increased to prevent it from timing out.  The
upstream CI runs the test suite in three parallel batches, with each
batch having a timeout of 2 hours.  The downstream CI doesn't run
parallelly, so a timeout of 4 hours was chosen.

https://src.fedoraproject.org/rpms/toolbox/pull-request/33
2025-08-09 23:29:50 +02:00
Fedora Release Engineering
db0197b744 Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-25 19:26:32 +00:00
Lokesh Mandvekar
63c067cd19 TMT: Prevent Bats from hanging when tearing down the test suite
The CI needs to be run without 'p11-kit server' because the lingering
singleton process causes Bats to hang when tearing down the suite of
system tests [1].  To terminate the 'p11-kit server' instance run by the
system tests, it needs to be distinguishable from the instance run by
'normal' use of Toolbx by the user.  One way to do this is to isolate
the host operating system's XDG_RUNTIME_DIR from the system tests.
Unfortunately, this is easier said than done [2].  So, this workaround
has to suffice until the problem is solved.

With the recent expansion of the test suite, it's necessary to increase
the timeout to prevent the CI from timing out.

[1] https://bats-core.readthedocs.io/en/stable/writing-tests.html

[2] https://github.com/containers/toolbox/pull/1652

https://src.fedoraproject.org/rpms/toolbox/pull-request/30
2025-06-17 01:01:31 +02:00
Debarshi Ray
3a4c4677a1 Unify the build with RHEL
There's no need to do a build just for this.
2025-06-16 22:29:28 +02:00
Debarshi Ray
07f1db2b0d Revert "Don't 'Requires: flatpak-session-helper' on RHEL"
The org.freedesktop.Flatpak D-Bus service provided by the
flatpak-session-helper RPM is not just needed to use containers created
by Toolbx < 0.0.97 [1,2].

It's needed on the host when toolbox(1) invocations inside a container
are forwarded to the host with 'flatpak-spawn --host ...'.  This has
been true since Toolbx >= 0.0.6 [3], and, hence, flatpak-session-helper
is needed on RHEL.

There's no need to do a build just for this.

This reverts commit a8b4975b5c.

[1] Upstream commit 82c32bea742621a3
    82c32bea74
    https://github.com/containers/toolbox/pull/591
    https://github.com/containers/toolbox/issues/267

[2] Upstream commit 71b5c8c0a235249b
    71b5c8c0a2
    https://github.com/containers/toolbox/pull/591
    https://github.com/containers/toolbox/issues/267

[3] Upstream commit 5b3d234c9e9ef45f
    5b3d234c9e
    https://github.com/containers/toolbox/pull/54
2025-06-16 20:51:53 +02:00
Debarshi Ray
cf4d77aa24 Update the BuildRequires on golang for Fedora and ELN to reflect reality
There's no need to do a build just for this.
2025-06-16 16:21:06 +02:00
Debarshi Ray
23a91e7031 Update the baseline BuildRequires on golang
... to match what Toolbx 0.1.2 actually needs [1].

There's no need to do a build just for this.

Fallout from a3506a3263

[1] Upstream commit 82e85bac9f5e69a5
    82e85bac9f
    https://github.com/containers/toolbox/pull/1614
2025-06-16 16:14:37 +02:00
Debarshi Ray
a3506a3263 Update to 0.1.2
Switch to vendored dependencies on Fedora because the package for
github.com/spf13/viper (ie., golang-github-spf13-viper) currently has
broken dependencies because a number of Go packages were recently
orphaned and retired.  Hopefully, this is aligned with the direction the
Go ecosystem in Fedora is taking [1], and won't lead to too many
problems.

This further unifies Fedora with RHEL, which was already using vendored
dependencies.

Now that all the Go dependencies are in the src/vendor directory,
there's no need to mess around with the GO111MODULE (ie., gomodulesmode)
and GOPATH environment variables.  Those were probably already not
needed on RHEL.

[1] https://fedoraproject.org/wiki/Changes/GolangPackagesVendoredByDefault

https://bugzilla.redhat.com/show_bug.cgi?id=2370151
2025-06-04 13:08:45 +02:00
Lokesh Mandvekar
0cbcff3ba4 TMT: Initial enablement
This PR will enable test runs using TMT. These tests can be maintained
here for starters and fetched and reused in the podman rpm for toolbox
tests on bodhi updates.

https://src.fedoraproject.org/rpms/toolbox/pull-request/24
2025-01-23 12:37:37 +01:00
Debarshi Ray
d6c4d7c587 Use RPM macros for shell completions and clean up directory ownership
... as recommended by the Fedora packaging guidelines [1,2].

This was made possible by two recent developments.

First, the parent directories for shell completions are now owned by the
filesystem RPM [3,4].  So, there won't be any unowned directories, if
the toolbox RPM doesn't own them without depending on some other package
that owns those directories.

Second, there are now RPM macros for the parent directories for shell
completions [5].

[1] https://docs.fedoraproject.org/es/packaging-guidelines/ShellCompletions/

[2] https://docs.fedoraproject.org/es/packaging-guidelines/UnownedDirectories/

[3] Fedora filesystem commit 47d37ac94192f792
    https://src.fedoraproject.org/rpms/filesystem/c/47d37ac94192f792
    https://bugzilla.redhat.com/show_bug.cgi?id=1312594

[4] Fedora filesystem commit 4c45982cd067557e
    https://src.fedoraproject.org/rpms/filesystem/c/4c45982cd067557e
    https://bugzilla.redhat.com/show_bug.cgi?id=1504616

[5] Fedora redhat-rpm-config commit 483a3b89d74c6f0b
    https://src.fedoraproject.org/rpms/redhat-rpm-config/c/483a3b89d74c6f0b
2025-01-22 20:01:59 +01:00
Fedora Release Engineering
d61e4b81c9 Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild 2025-01-19 13:06:21 +00:00
Debarshi Ray
8ec06e58ca Update to 0.1.1
https://bugzilla.redhat.com/show_bug.cgi?id=2323150
2024-11-04 16:22:58 +01:00
Debarshi Ray
6f1c1c4052 Update to 0.1.0
... and update the BuildRequires on golang to reflect reality.
2024-10-23 19:05:53 +02:00
Debarshi Ray
120a6ce1a6 Recommend fuse-overlayfs because old containers created with it need it
... and:

  * containers-common removed fuse-overlayfs as even a weak
    dependency [1]
  * there are still several such containers out there in the wild [2,3]

This should be removed once Toolbx can detect the situation and offer
users a migration path.

[1] Fedora containers-common commit 447945e59a01cb67
    https://src.fedoraproject.org/rpms/containers-common/c/447945e59a01cb67

[2] https://discussion.fedoraproject.org/t/rpm-ostree-update-breaks-toolbox-fedora-40

[3] https://github.com/containers/toolbox/issues/1512

https://bugzilla.redhat.com/show_bug.cgi?id=2319121
2024-10-16 12:35:50 +02:00
Yaakov Selkowitz
8805e4b239 Fix ELN build
Otherwise, it fails with:
  Processing files: toolbox-debugsource-0.0.99.6-5.eln143.x86_64
  RPM build errors:
  error: Empty %files file
    /builddir/build/BUILD/toolbox-0.0.99.6-build/toolbox-0.0.99.6/debugsourcefiles.list
      Empty %files file
        /builddir/build/BUILD/toolbox-0.0.99.6-build/toolbox-0.0.99.6/debugsourcefiles.list
  Child return code was: 1

https://src.fedoraproject.org/rpms/toolbox/pull-request/23
2024-10-08 17:50:10 +02:00
Debarshi Ray
d91d2c8523 Don't use slirp4netns(1) in tests to work around bug in pasta(1) 2024-10-07 16:42:34 +02:00
Debarshi Ray
1d3597789e Unify the build with RHEL
There's no need to do a build just for this.
2024-10-07 16:42:34 +02:00
Debarshi Ray
ea36bd0bb0 Unify the build with RHEL
There's no need to do a build just for this.
2024-10-07 16:42:34 +02:00
Debarshi Ray
2334d4ee5f Unify the build with RHEL 9
There's no need to do a build just for this.
2024-10-07 16:42:34 +02:00
Debarshi Ray
5ff63e6c80 Use the fedora-toolbox:40 image for Fedora Asahi Remix hosts
https://bugzilla.redhat.com/show_bug.cgi?id=2316312
2024-10-04 15:08:39 +02:00
Debarshi Ray
8da835d84a Unbreak the downstream Fedora CI
Fallout from e447d41208
2024-10-03 14:56:46 +02:00
Debarshi Ray
f81e991c0a Silence 'rpminspect --tests=elf'
With Toolbx 0.0.99.6, 'rpminspect --tests=elf', run by the Fedora CI,
fails with:
  /usr/bin/toolbox lost full GNU_RELRO security protection

This is because from version 0.0.99.6 onwards, toolbox(1) is only built
with the '-z relro' linker flag, but not '-z now' [1].

Fallout from e447d41208

[1] Upstream commit 83f28c52e47c2d44
    83f28c52e4
    https://github.com/containers/toolbox/pull/1548
2024-10-02 21:48:17 +02:00
Debarshi Ray
e447d41208 Update to 0.0.99.6
Start using the golang-ipath(...) virtual Provides for BuildRequires
because they use the top-level import paths and are closer to what is
listed in the upstream go.mod.  The golang(...) virtual Provides mention
each individual Go package within a Go module, and bigger modules can
have several packages in them.  It is noisy and tedious to keep up with
the list of packages that are currently in use, by looking at all the Go
source files, and then to list them as BuildRequires.

Update the compiler and linker flags for Fedora by incorporating some of
the changes to the distribution's defaults up to Fedora 39, which is the
oldest supported Fedora.  Switch to using the GO_BUILDTAGS and
GO_LDFLAGS environment variables, because their unprefixed counterparts
have been deprecated [1], and start annotating the toolbox(1) binary
with an ELF note that identifies the RPM for which it was built [2].

However, the change to use the RPM's %{name}, %{version}, %{release} and
the SOURCE_DATE_EPOCH environment variable [3], instead of /dev/urandom,
to generate the build ID annotation for the toolbox(1) binary [4] was
left out.  It will need more work to propagate the RPM's %{name},
%{version} and %{release} to Meson.

Stop carrying the downstream patch for the compiler and linker flags for
PPC64.  The architecture was already discontinued from Fedora 29 [5],
even before the patch was added [6].  It was added purely for the sake
of completeness, and in the last four years since it was introduced, it
hasn't been tested or used.  At this point it's becoming too much of a
maintenance burden, and removing it silences the %ifarch-applied-patch
warning from rpmlint.

Fill in some of the missing Requires for the toolbox-tests sub-package.

[1] go-rpm-macros commit bc7e5cc55c4709e8
    https://pagure.io/go-rpm-macros/c/bc7e5cc55c4709e8

[2] Fedora redhat-rpm-config commit 57edf0cad7b089ed
    https://src.fedoraproject.org/rpms/redhat-rpm-config/c/57edf0cad7b089ed
    https://fedoraproject.org/wiki/Changes/Package_information_on_ELF_objects

[3] https://reproducible-builds.org/docs/source-date-epoch/

[4] go-rpm-macros commit 1980932bf3a21890
    https://pagure.io/go-rpm-macros/c/1980932bf3a21890
    https://fedoraproject.org/wiki/Changes/ReproduciblePackageBuilds

[5] https://fedoraproject.org/wiki/Changes/DiscontinuePPC64

[6] Commit ba60453d21

https://src.fedoraproject.org/rpms/toolbox/pull-request/22
2024-09-30 15:42:31 +02:00
Debarshi Ray
bba451ece1 Rebuild against shadow-utils-subid ABI version 5.0.0
The runtime dependency on shadow-utils-subid should have already been
part of commit 95d6ea8689 to ensure that Toolbx >= 0.0.99.4 would
be able to dlopen(3) the library.  It only worked in practice because
the podman RPM also required it.
2024-09-12 18:06:08 +02:00
Debarshi Ray
c4f11e9887 Unify the build with RHEL
There's no need to do a build just for this.
2024-08-09 18:46:57 +02:00
Debarshi Ray
1f9f142ef1 Remove stray newline
There's no need to do a build just for this.

Fallout from 8598325132
2024-08-09 18:42:08 +02:00
Debarshi Ray
adcdf19861 tests: Silence deprecation warning
Otherwise, Ansible in Fedora CI would complain:
  # STDERR:
  ---v---v---v---v---v---
  [DEPRECATION WARNING]: "include" is deprecated, use
  include_tasks/import_tasks instead.  See
  https://docs.ansible.com/ansible-core/2.14/user_guide/playbooks_reuse_includes.html
  for details.  This feature will be removed in version 2.16.
  Deprecation warnings can be disabled by setting
  deprecation_warnings=False in ansible.cfg.

https://src.fedoraproject.org/rpms/toolbox/pull-request/21
2024-08-08 17:55:45 +02:00
Adam Williamson
ee2fa0eab4 tests: Ensure slirp4netns(1) is installed
Podman 5.0 switched to using pasta(1), instead of slirp4netns(1), by
default for rootless containers.  This change has led to a regression
causing 'skopeo copy' to get stuck uploading an OCI image to the local
temporary Docker registry run by the tests as a Podman container [1],
which breaks the test suite on Fedora 40 onwards.

This was worked around by forcing the use of slirp4netns(1).

The slirp4nets package needs to be explicitly installed on Fedora 40
onwards, because the dependency in containers-common-extra changed from
Recommends to Suggests [2].  Otherwise, it led to:
  1..320
  # test suite: Set up
  # test suite: Tear down
  not ok 1 setup_suite
  # (from function `assert_success' in file
       ./libs/bats-assert/src/assert.bash, line 114,
  #  from function `_setup_docker_registry' in file ./libs/helpers.bash,
       line 208,
  #  from function `setup_suite' in test file ./setup_suite.bash, line
       59)
  #   `_setup_docker_registry' failed
  #
  # -- command failed --
  # status : 127
  # output : Error: could not find slirp4netns, the network namespace
      can't be configured: exec: "slirp4netns": executable file not
      found in $PATH
  # --
  #
  # Untagged: quay.io/toolbox_tests/registry:latest
  # Deleted: fea5a12cde107bb407bc44ede6dd9edea1d2b4171cd8e52b0cb330bf45e517e1
  # bats warning: Executed 1 instead of expected 320 tests

The missing dependency on the slirp4netns package in toolbox-tests
doesn't affect Podman's downstream Fedora CI, which runs toolbox-tests,
because it separately installs slirp4netns for other tests [3].

Fallout from d8388da39e

[1] https://github.com/containers/podman/issues/22575

[2] Fedora containers-common commit 17934d87b2686ab5
    Fedora containers-common commit 13c232f064113860
    https://src.fedoraproject.org/rpms/containers-common/c/17934d87b2686ab5
    https://src.fedoraproject.org/rpms/containers-common/c/13c232f064113860

[3] Fedora podman commit 9667d0f5b5069acb
    https://src.fedoraproject.org/rpms/podman/c/9667d0f5b5069acb

https://src.fedoraproject.org/rpms/toolbox/pull-request/20

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2024-08-08 17:00:12 +02:00
Adam Williamson
8598325132 tests: Avoid running out of storage space
Toolbx's system tests download several images when setting up the test
suite, and cache them for later use by the tests [1].  This saves time
and avoids hitting rate limits imposed by OCI registries by not
downloading the same images repeatedly for several tests, but at the
cost of increased use of storage space to cache the images.

The images are cached under BATS_TMPDIR.  It defaults to the TMPDIR
environment variable, and if that's not set then to /tmp [2].  Normally,
TMPDIR isn't set, and the images end up getting cached under /tmp.  Now,
/tmp is typically on tmpfs backed by RAM or swap, which means that it
should be used for smaller size-bounded files only, and /var/tmp should
be used for everything else [3].

The images are big enough that a collection of them can't be described
as smaller and size-bounded, and it led to:
  1..306
  # test suite: Set up
  # test suite: Tear down
  not ok 1 setup_suite
  # (from function `setup_suite' in test file ./setup_suite.bash, line
      55)
  #   `_pull_and_cache_distro_image fedora "$((system_version-1))" ||
      false' failed
  # Failed to cache image registry.fedoraproject.org/fedora-toolbox:40
      to /tmp/bats-run-IPz4Cn/image-cache/fedora-toolbox-40
  # time="2024-02-19T11:41:43Z" level=fatal msg="copying system image
      from manifest list: writing blob: write
      /tmp/bats-run-IPz4Cn/image-cache/fedora-toolbox-40/dir-put-blob607392514:
      no space left on device"
  # bats warning: Executed 1 instead of expected 306 tests

So, change the default location of the BATS_TMPDIR environment variable
to /var/tmp by setting TMPDIR.

[1] Toolbx commit 50683c9d9a78adc9
    50683c9d9a
    https://github.com/containers/toolbox/pull/375

[2] https://bats-core.readthedocs.io/en/stable/writing-tests.html

[3] https://systemd.io/TEMPORARY_DIRECTORIES/

https://src.fedoraproject.org/rpms/toolbox/pull-request/20

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2024-07-31 14:44:35 +02:00
Adam Williamson
c8c1f44f2e tests: Don't use undefined variable
The test.environment variable was removed from the variables defined in
tests.yml in commit 1b207227f3, but it's still used, which causes
Ansible to break:
  The task includes an option with an undefined variable. The error was:
  'dict object' has no attribute 'environment'. 'dict object' has no
  attribute 'environment'

https://src.fedoraproject.org/rpms/toolbox/pull-request/19
2024-07-29 18:13:52 +02:00
Fedora Release Engineering
ad7ceee60d Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild 2024-07-20 07:41:42 +00:00
Debarshi Ray
c262e4e417 Silence 'rpminspect --tests=stack-prot'
The stack-prot test [1] currently fails with:
  Hardened: /usr/bin/toolbox: FAIL: stack-prot test because stack
      protection not enabled (lto:_cgo_6f668e16310a_Cfunc_mygetgrnam_r)

According to the documentation [1], the test is supposed to pass if the
C compiler is GCC and it was used with the -fstack-protector-strong
option.  That's definitely the case, since Fedora uses GCC by default,
and its default build flags (including %optflags) include
-fstack-protector-strong.

There's also no function called mygetgrnam() in neither Toolbx nor its
chain of dependencies.

Therefore, temporarily disable the stack-prot test to prevent the Fedora
CI from failing.

[1] https://sourceware.org/annobin/annobin.html/Test-stack-prot.html
2024-07-11 10:58:36 +02:00
Debarshi Ray
58b0af2d6b Silence 'rpminspect --tests=annocheck' (part 2)
In recent times, 'rpminspect --tests=annocheck', run by the Fedora CI,
has been failing because of the intentional DT_RPATH or DT_RUNPATH value
of /run/host%{_libdir} that's present in %{_bindir}/toolbox [1].  It's
not clear if they started failing again only recently due to changes in
rpminspect(1), or if the previous attempt at silencing it was broken and
never actually worked [2].

[1] Upstream commit 6063eb27b9893994
    6063eb27b9
    https://github.com/containers/toolbox/issues/821

[2] Commit 12fabacd03

https://github.com/rpminspect/rpminspect/issues/1296
2024-07-11 10:16:29 +02:00
Debarshi Ray
d8388da39e Unbreak the tests with Podman 5.0
... and make them show the Bats version.
2024-05-07 00:45:50 +02:00
Debarshi Ray
fd1d76c601 Specify the golang versions for RHEL 9 and 10 2024-03-26 18:06:02 +01:00
Debarshi Ray
6dfd366e61 Conditionalize the BuildRequires on golang
The OpenSSL FIPS patches in Fedora ELN's golang makes it lag behind its
Fedora counterpart at times.

Spotted by Yaakov Selkowitz.

Fallout from 32b32e42f3

https://src.fedoraproject.org/rpms/toolbox/pull-request/18
2024-03-05 19:25:54 +01:00
Debarshi Ray
72a3fb0bb0 Unbreak Podman's downstream Fedora CI (part 2)
... and backport some new upstream tests.

https://bugzilla.redhat.com/show_bug.cgi?id=2263968
2024-02-27 16:12:07 +01:00
Debarshi Ray
32b32e42f3 Unbreak Podman's downstream Fedora CI
... and update the BuildRequires on golang to reflect reality.

https://bugzilla.redhat.com/show_bug.cgi?id=2263968
2024-02-13 22:58:07 +01:00
Maxwell G
85becd3dde
Rebuild for golang 1.22.0 2024-02-11 23:40:44 +00:00
Debarshi Ray
5aea389aab Migrate to SPDX license 2024-02-07 14:45:03 +01:00
Fedora Release Engineering
78a3000c62 Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-27 06:33:04 +00:00
Maxwell G
25a9050dd0
Remove deprecated %patchN syntax
[skip changelog]

Relates: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/5YUJWTUJK4JA26YP2VD46HOCQ6UZXMQD/
2024-01-12 21:09:56 +00:00
Debarshi Ray
f79961c521 Drop 'Recommends: subscription-manager'
... because subscription-manager requires python3-dnf, which contains
%{_bindir}/dnf-3 and %{_bindir}/dnf4 [1].   This is a problem on Fedora
Silverblue, because they shouldn't be present on OSTree based variants
of Fedora.

This reverts parts of commit 6682165143.

[1] https://github.com/fedora-silverblue/issue-tracker/issues/521
2024-01-11 19:04:31 +01:00
Debarshi Ray
57ae69592c Drop the experience and support subpackages
The only known user of the toolbox-experience and toolbox-support
packages was: https://github.com/AICoE/tf-in-container

... which was declared dead in February 2022.

Hence, there's no need to keep offering these subpackages.  Especially,
since the cost of keeping them updated to match the content of the
fedora-toolbox images is quite high.  If someone really needs these
subpackages, then they can be reinstated.
2023-12-19 14:09:03 +01:00
Debarshi Ray
6682165143 Update to 0.0.99.5
Start using Toolbx as the name of the project, instead of Toolbox; and
recommend subscription-manager, as requested by the Fedora Workstation
Working Group [1], to make it easier to have gratis, self-supported Red Hat
Enterprise Linux containers on Fedora.

[1] https://pagure.io/fedora-workstation/issue/391
2023-12-19 13:28:45 +01:00