Simon McVittie [Mon, 30 Jul 2018 15:51:01 +0000 (16:51 +0100)]
Skip test-pull-repeated during CI
This test is expected to fail a small proportion of the time. During
the build of ostree 2018.7-1 in Debian, it seems we were unlucky on
s390x. Non-deterministic tests are also problematic for autopkgtest,
where they can gate migration of our dependencies like GLib, so skip
this test unless the caller has opted-in to non-deterministic tests.
It would be appropriate to enable this test in environments where
failures can easily be retried and are not disruptive to other
packages.
Signed-off-by: Simon McVittie <smcv@debian.org>
Gbp-Pq: Topic debian
Gbp-Pq: Name Skip-test-pull-repeated-during-CI.patch
generator: Fix soft-reboot for var, sysroot, and boot
A bare `systemctl soft-reboot` on ostree/bootc systems was broken in
several ways because the generator and prepare-root were not accounting
for the fact that soft-reboot does not re-run the initramfs.
The var.mount unit had DefaultDependencies=yes, which pulled in implicit
After= dependencies on device units. After soft-reboot, these device
units get stuck in 'tentative' state while udev restarts, causing
var.mount to stall indefinitely. Fix this by setting
DefaultDependencies=no with explicit ordering After=local-fs-pre.target
sysroot.mount.
For /sysroot, systemd auto-generates the mount unit from mountinfo with
Conflicts=umount.target, causing it to be unmounted during soft-reboot
shutdown. Generate a drop-in with DefaultDependencies=no to prevent this.
We use a drop-in because the generator does not know the What= device
parameter — systemd gets that from mountinfo.
For /boot on same-partition setups, move the bind-mount from
ostree-prepare-root into the generator as a full boot.mount unit with
DefaultDependencies=no. This handles normal boot, bare soft-reboot, and
staged deployment soft-reboot uniformly. The static (non-systemd) path
in ostree-prepare-root-static.c retains its own bind-mount since the
generator does not run there.
Validated with plain disk and RAID1 kola tests on FCOS 43.
Fixes: https://issues.redhat.com/browse/RHEL-154075 Assisted-by: OpenCode (Claude Opus 4.6) Signed-off-by: Joseph Marrero Corchado <jmarrero@redhat.com>
Xiaofeng Wang [Thu, 2 Apr 2026 03:36:20 +0000 (11:36 +0800)]
ci: Make fuse and libfuse-dev conditional for Debian Testing
The libfuse-dev and fuse (FUSE 2) packages have been removed from
Debian Testing (forky/sid). Move them out of the unconditional package
list and only install them on older Debian/Ubuntu versions that still
provide FUSE 2. FUSE 3 support is already handled via the libfuse3-dev
argument logic.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Xiaofeng Wang <henrywangxf@me.com>
Xiaofeng Wang [Thu, 2 Apr 2026 02:40:04 +0000 (10:40 +0800)]
ci: Install ca-certificates in Debian Testing pre-checkout setup
The debian:testing-slim image no longer includes ca-certificates by
default, causing the GitHub Actions checkout step to fail with an SSL
CA cert error when fetching the repository over HTTPS.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Xiaofeng Wang <henrywangxf@me.com>
bootconfig: Preserve extension BLS keys across staged deployments
When a deployment is staged via ostree_sysroot_stage_tree_with_options(),
the deployment metadata is serialized to /run/ostree/staged-deployment
as a GVariant. During finalization at shutdown,
_ostree_sysroot_reload_staged() creates a fresh OstreeBootconfigParser
and only restores the "options" key from the serialized kargs. Any
additional BLS keys that were set on the bootconfig are silently dropped.
The parse/write/clone paths in OstreeBootconfigParser already handle
unknown keys generically (the "Write unknown fields" loop in
write_at()), so keys survive direct deployments and in-memory
operations. The gap is exclusively in the staged deployment roundtrip,
where a fresh bootconfig is rebuilt from just the kargs strv.
This matters for the upcoming bootc `loader-entries set-options-for-source`
feature, which stores kernel argument ownership as extension BLS keys
(e.g. `x-options-source-tuned nohz=full isolcpus=1-3`). On bootc
systems with transient /etc, tools like TuneD lose track of which kargs
they own because their state files are wiped on reboot. Tracking
ownership directly in the BLS config on /boot solves this, but only if
the keys survive staging. systemd-boot, GRUB, and zipl all ignore
unknown BLS keys, so extension keys are safe.
Fix this by following the same pattern used for overlay-initrds:
1. Add _ostree_bootconfig_parser_get_extra_keys_variant() which returns
all non-standard BLS keys as an a{ss} GVariant. Standard keys
(title, version, options, linux, initrd, devicetree) are excluded
since they are rebuilt from scratch during finalization. All other
keys are preserved, trusting the caller.
2. In ostree_sysroot_stage_tree_with_options(), serialize any extra
keys as "bootconfig-extra" in the staged GVariant dict. Since
_ostree_deployment_set_bootconfig_from_kargs() creates a fresh
bootconfig with only the "options" key, the code falls back to
the merge deployment's bootconfig for extra keys. This ensures
keys are inherited across staged deployments without the caller
needing to re-set them.
3. In _ostree_sysroot_reload_staged(), restore extra keys from the
"bootconfig-extra" dict onto the deployment's bootconfig via
ostree_bootconfig_parser_set().
The function is private (_ostree_ prefix) since only ostree's own
staging code uses it. No new public API, no changes to .sym files,
no changes to GIR or Rust bindings.
Backwards compatibility:
- Old ostree ignores the unknown "bootconfig-extra" key in the a{sv}
dict (extension keys silently lost, same as before this patch).
- New ostree gracefully handles the absence of "bootconfig-extra" in
staged data written by older versions (g_variant_dict_lookup returns
FALSE, no restoration attempted).
Assisted-by: OpenCode (Claude claude-opus-4-6) Signed-off-by: Joseph Marrero Corchado <jmarrero@redhat.com>
Xiaofeng Wang [Tue, 31 Mar 2026 07:31:32 +0000 (15:31 +0800)]
ci: Use Justfile targets in GitHub workflow and add missing v2024_7 feature
- Replace inline cargo fmt/clippy commands in rust.yml with just
cargo-fmt-check and just cargo-clippy for consistency with local dev
- Make Justfile cargo-clippy use CARGO_PROJECT_FEATURES env var
(defaults to v2022_6) so CI and local use share the same config
- Add missing v2024_7 feature to Cargo.toml to fix cargo doc failure
caused by unexpected cfg condition
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Xiaofeng Wang <henrywangxf@me.com>
Xiaofeng Wang [Tue, 31 Mar 2026 07:15:30 +0000 (15:15 +0800)]
ci: Add Rust validate targets to Justfile for local development
Add just targets mirroring the CI Rust checks so developers can run
them locally before pushing:
- validate: runs both fmt and clippy checks
- cargo-fmt-check: checks formatting across all crates
- cargo-clippy: runs clippy with the same lint config as CI
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Xiaofeng Wang <henrywangxf@me.com>
Xiaofeng Wang [Tue, 31 Mar 2026 03:39:04 +0000 (11:39 +0800)]
ci: Sync Rust linting checks from bootc-dev/bootc
Align with bootc's validate target:
- Make cargo clippy gating (was "non-gating") with the same lint config
as bootc (-A clippy::all -D clippy::correctness -D clippy::suspicious
-Dunused_imports -Ddead_code)
- Extend clippy to cover test crates (tests/inst, tests/bootc-integration,
tests/xtask)
- Add cargo doc with -D warnings to catch rustdoc issues
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Xiaofeng Wang <henrywangxf@me.com>
Xiaofeng Wang [Tue, 31 Mar 2026 03:30:08 +0000 (11:30 +0800)]
ci: Extend cargo fmt check to cover all Rust crates
The existing cargo fmt check only covered the ostree workspace package.
Add fmt checks for the standalone test crates (tests/inst,
tests/bootc-integration, tests/xtask) which are separate workspaces.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Xiaofeng Wang <henrywangxf@me.com>
Xiaofeng Wang [Mon, 30 Mar 2026 12:22:10 +0000 (20:22 +0800)]
ci: Fix cargo build failure on Fedora 43/44 in Containerfile.packit
Set CARGO_HOME=/var/tmp/.cargo to avoid conflict with /root/.cargo
which exists as a non-directory on Fedora 43/44 base images, causing
"failed to create directory: File exists (os error 17)".
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Xiaofeng Wang <henrywangxf@me.com>
Xiaofeng Wang [Mon, 30 Mar 2026 08:29:10 +0000 (16:29 +0800)]
ci: Replace test-tmt shell script with Rust xtask
Replace the inline bash script in the Justfile test-tmt target with a
Rust xtask crate (tests/xtask/) that handles TMT plan discovery, bcvk
VM lifecycle, SSH readiness polling, and tmt invocation. This follows
the bootc-dev/bootc cargo xtask run-tmt pattern.
Also fix tests.fmf to pass test names individually with --exact, since
libtest_mimic only accepts a single filter argument.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Xiaofeng Wang <henrywangxf@me.com>
Xiaofeng Wang [Mon, 23 Mar 2026 08:55:56 +0000 (16:55 +0800)]
tests: Remove bcvk VM dispatch from Rust integration tests
VM deployment is now handled externally by `just test-tmt` (bcvk + tmt)
or `just integration-container` (bcvk direct SSH). The Rust test binary
runs inside the VM as root, so the require_root/RunMode dispatch logic
is no longer needed.
- Remove require_root(), RunMode enum, and bcvk dispatch code
- Simplify booted_test! and privileged_test! macros to just register
and run tests directly
- Remove rustix dependency (no longer checking getuid)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Xiaofeng Wang <henrywangxf@me.com>
Xiaofeng Wang [Fri, 20 Mar 2026 08:50:58 +0000 (16:50 +0800)]
ci: Add Packit CI with RPM builds and TMT integration tests
Add Packit-based CI pipeline that builds RPMs via COPR and runs TMT
integration tests on bootc image-mode systems. This follows the
bootc-dev/bootc pattern of per-plan VM isolation using bcvk.
Key changes:
- Dockerfile: Add rpmbuild stage, use RPM overlay for rootfs, run
provision-derived.sh for VM provisioning (cloud-init, rsync, etc.)
- Justfile: Add package target, test-tmt target with bcvk per-plan VMs,
longer SSH wait for cloud-init first boot
- .github/workflows/bootc.yaml: Split into unit-tests and integration
jobs, archive TMT logs with PR number in artifact name
- .packit.yaml: COPR builds + TMT tests for centos-stream-9/10 and
fedora-43/44 on x86_64/aarch64
- tmt/: FMF test plans and shell-based tests (booted verification,
privileged ostree tests) translated from Rust integration tests
- hack/: Packit provisioning scripts to convert package-mode VMs to
image-mode via bootc install to-filesystem
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> Signed-off-by: Xiaofeng Wang <henrywangxf@me.com>
Colin Walters [Tue, 17 Mar 2026 21:00:34 +0000 (21:00 +0000)]
ci: Revamp bootc integration test suite with bcvk VM support
the old privtest CI job with a new tests/bootc-integration
Rust crate that runs inside a bcvk VM. The old tests/inst crate is
preserved for tests not yet ported.
Tests are split into two tiers based on what they need:
- booted_test!: needs a fully deployed ostree system. Dispatches via
`bcvk libvirt run` which does `bootc install to-disk`.
- privileged_test!: just needs root. Dispatches via the faster
`bcvk ephemeral run-ssh`.
The Justfile provides `integration-container` (full suite) and
`integration-ephemeral` (fast privileged-only path). JUnit XML output
is supported via the JUNIT_OUTPUT env var using quick-junit;
integration-container captures results to target/integration-results.xml.
Drop the vendored bootc-ubuntu-setup action in favor of the upstream
bootc-dev/actions/bootc-ubuntu-setup@main.
Assisted-by: OpenCode (Claude claude-opus-4-6) Signed-off-by: Colin Walters <walters@verbum.org>
Igor Opaniuk [Mon, 9 Mar 2026 11:04:07 +0000 (12:04 +0100)]
tests: Respect TEST_TMPDIR for temporary directories
Several C tests hardcoded /var/tmp as the base path for temporary
working directories, ignoring the TEST_TMPDIR environment variable
used by the shell test suite.
This caused tests to create their ostree repos on the overlayfs
filesystem even when TEST_TMPDIR points to a real filesystem,
bypassing the intended workaround for overlayfs's inaccurate
free-space reporting. As a result, ostree's min-free-space-percent
check (default 3%) would fire when writing content objects, making
tests fail in containerized environments where the rootfs is overlayfs.
Fix by reading TEST_TMPDIR at runtime and falling back to /var/tmp
when it is not set, consistent with how the shell test suite handles
this. Affected tests:
- tests/test-libarchive-import.c
- tests/test-basic-c.c
Signed-off-by: Igor Opaniuk <igor.opaniuk@foundries.io>
Pavel Valena [Fri, 6 Mar 2026 12:09:32 +0000 (13:09 +0100)]
boot/dracut: use systemdsystemunitdir instead of systemdsystemconfdir
since dracut-109 [*], the systemdsystemconfdir exists only in hostonly mode, which leads to unbootable system; as documented here:
https://src.fedoraproject.org/rpms/dracut/pull-request/90
Simon McVittie [Mon, 30 Jul 2018 15:51:01 +0000 (16:51 +0100)]
Skip test-pull-repeated during CI
This test is expected to fail a small proportion of the time. During
the build of ostree 2018.7-1 in Debian, it seems we were unlucky on
s390x. Non-deterministic tests are also problematic for autopkgtest,
where they can gate migration of our dependencies like GLib, so skip
this test unless the caller has opted-in to non-deterministic tests.
It would be appropriate to enable this test in environments where
failures can easily be retried and are not disruptive to other
packages.
Signed-off-by: Simon McVittie <smcv@debian.org>
Gbp-Pq: Topic debian
Gbp-Pq: Name Skip-test-pull-repeated-during-CI.patch
Colin Walters [Thu, 8 Jan 2026 21:24:14 +0000 (16:24 -0500)]
libarchive: Handle UTF-8 filenames without locale dependency
When importing archives (including OCI container layers), libarchive
attempts to convert filenames from UTF-8 to the current locale charset.
In POSIX/C locale (which uses ASCII), this conversion fails for any
non-ASCII UTF-8 characters, returning ARCHIVE_WARN.
This is triggered by Python 3.14 which creates a "𝜋thon" symlink in
venvs, and affects bootc installations in environments where LANG is
not set (defaulting to POSIX locale).
Fix this by:
1. Using archive_entry_pathname_utf8() and archive_entry_symlink_utf8()
which return UTF-8 directly without locale conversion
2. Falling back to the regular accessors with explicit UTF-8 validation
when the _utf8 variants return NULL
3. Accepting ARCHIVE_WARN from archive_read_next_header() since we now
validate UTF-8 ourselves rather than relying on libarchive charset
conversion
This matches the behavior of GNU tar which treats filenames as opaque
bytes without charset conversion.
Dusty Mabe [Fri, 16 Jan 2026 02:48:43 +0000 (21:48 -0500)]
ci: drop running COSA as UID 0
With some changes made upstream to COSA [1] and a few fixups here
to make sure the directory tree for our built software doesn't have
setgid files we shouldn't need to runAsUser: 0 any longer.
ci: Sync bootc-ubuntu-setup action from bootc-dev/infra
The CI was failing because we were pulling podman/crun/skopeo
from Debian testing which has become unreliable. The bootc-dev/infra
repository maintains a reusable action that uses Ubuntu's plucky
repository instead, which is more appropriate for ubuntu-24.04 runners.
This also brings in additional improvements from the shared action:
- Disk space cleanup on the runner
- Unprivileged /dev/kvm access setup
- Optional libvirt stack support
state-overlay: Fix ENODATA handling for GLib < 2.74
The state overlay feature fails on first boot with:
error: lgetxattr(user.ostree.deploymentcsum): No data available
This happens because `lgetxattrat_allow_noent()` checks for
`G_IO_ERROR_INVALID_DATA` to detect when an xattr doesn't exist.
However, GLib's `g_io_error_from_errno()` only maps `ENODATA` to
`G_IO_ERROR_INVALID_DATA` since GLib 2.74. Older versions (such as
GLib 2.68 shipped in CentOS Stream 9) return `G_IO_ERROR_FAILED`
instead, causing the check to fail and the error to propagate.
This creates a chicken-and-egg problem: the code tries to read the
`user.ostree.deploymentcsum` xattr before it can set it, but the read
fails on fresh overlay directories where the xattr hasn't been set yet.
Fix this by checking `errno == ENODATA` directly after the failed call,
which is portable across all GLib versions. Also rename the function
from `lgetxattrat_allow_noent` to `lgetxattrat_allow_nodata` to more
accurately reflect its purpose (ENODATA vs ENOENT).
This bug has existed since the state overlay feature was introduced in
v2024.1 but was masked on systems with GLib >= 2.74 (e.g., Fedora,
CentOS Stream 10) where the mapping happens to exist.
Assisted-by: Claude Code (Opus 4.5) Signed-off-by: Joseph Marrero Corchado <jmarrero@redhat.com>
Simon McVittie [Mon, 30 Jul 2018 15:51:01 +0000 (16:51 +0100)]
Skip test-pull-repeated during CI
This test is expected to fail a small proportion of the time. During
the build of ostree 2018.7-1 in Debian, it seems we were unlucky on
s390x. Non-deterministic tests are also problematic for autopkgtest,
where they can gate migration of our dependencies like GLib, so skip
this test unless the caller has opted-in to non-deterministic tests.
It would be appropriate to enable this test in environments where
failures can easily be retried and are not disruptive to other
packages.
Signed-off-by: Simon McVittie <smcv@debian.org>
Gbp-Pq: Topic debian
Gbp-Pq: Name Skip-test-pull-repeated-during-CI.patch
Colin Walters [Thu, 6 Nov 2025 19:35:04 +0000 (14:35 -0500)]
Add missing `:` to the gtk-doc in a few places
This is SUCH a giant trap. I am not totally sure why it's
working for me in a fedora-42 build env, but it seems like
it may have broken in a different build environment in
https://github.com/ostreedev/ostree/pull/3548#discussion_r2500278890
I used Sonnet to audit for similar instances beyond
`read_blob` and it found some, fix those too.
We didn't set error if there were zero valid signatures, which caused
a crash prefixing the error. While fixing this, the error messages were
slightly reworded to make it nicer.
rust-binding: Extend bindings to support composefs and signing
This adds GLib.VariantDict, which is needed for
ostree_repo_commit_add_composefs_metadata(), and OSTree.BlobReader
which are needed for ostree_sign_read_sk().
With these we can sign ostree commits with composefs digests in them.
gir: Add (nullable) to ostree_blob_reader_read_blob return value
This adds api docs to ostree_blob_reader_read_blob() so that we
can mark the return value as nullable. This is needed, because
this function can return NULL without setting error, and this
needs to be handled in bindings (such as the rust ones).
ostree-sign.ed25519/spki: Fix double free in set_sk()
When the gvariant is G_VARIANT_TYPE_BYTESTRING we need to duplicate
the data we get from g_variant_get_fixed_array(), otherwise we will
double-free it when we later free sign->secret_key.