Jonathan Lebon [Wed, 14 Mar 2018 14:36:48 +0000 (10:36 -0400)]
lib/fetcher: Allow clients to append to User-Agent
We do already have `http-headers`, which potentially could be used to
allow clients to completely override the field, but it seems like the
more common use case is simply to append.
Closes: #1496
Approved by: cgwalters
Jonathan Lebon [Fri, 16 Mar 2018 18:19:28 +0000 (14:19 -0400)]
lib/core: Support <remote>: syntax when listing refs
Allow users to pass `<remote>:` to list all refs we have locally
belonging to `<remote>`. Also (re-)allow the similar `<remote>:.` syntax
for backwards compatibility with flatpak.
Closes: #1500
Approved by: cgwalters
Colin Walters [Fri, 9 Mar 2018 18:26:07 +0000 (13:26 -0500)]
tests/str: Rework invocation
Let's make our `run.sh` generically support any playbook. This is prep for
writing further tests in Ansible. Along with that, rework the Ansible so that
`tests.yml` is a playbook, and then the other bits are just task lists. It's
easier to read.
I also started to add a `use_git_build` variable with the idea that we'll be
able to run these same tests against an upstream image by setting that variable
off.
Closes: #1493
Approved by: jlebon
Colin Walters [Mon, 12 Mar 2018 18:55:51 +0000 (13:55 -0500)]
sysroot: Rework how we find booted deployment
I was looking at this code in prep for "staging" deployments,
and there are several cleanups to be made here. The first
thing I noticed is that we look for the `ostree=` kernel argument,
but the presence of that should be exactly equivalent to having
`/run/ostree-booted` exist. We just added a member variable for
that, so let's make use of it.
Related to this, we were erroring out if we had the karg but
didn't find a deployment. But this can happen if e.g. one is
using `ostree admin --sysroot` from an ostree-booted system! It's
actually a bit surprising no one has reported this so far; I guess
in the end people are either using non-ostree systems or running
from containers.
Let's add a member variable `root_is_sysroot` that we can use
to determine if we're looking at `/`. Then, our more precise
"should find a booted deployment" state is when both `ostree_booted`
and `root_is_sysroot` are TRUE.
Next, rather than walking all of the deployments after parsing,
we can inline the `fstatat()` while parsing. The mild ugly
thing about this is assigning to the sysroot member variable while
parsing, but I will likely clean that up later, just wanted to avoid
rewriting everything in one go.
Closes: #1497
Approved by: jlebon
Colin Walters [Mon, 12 Mar 2018 17:24:09 +0000 (13:24 -0400)]
sysroot: Track whether /run/ostree-booted exists
Prep for further work around deployment staging.
Closes: #1497
Approved by: jlebon
Colin Walters [Mon, 12 Mar 2018 17:16:43 +0000 (13:16 -0400)]
lib/deploy: Port deployment checkout func to new style
Not sure how we missed this one before. No functional changes,
just prep for further work.
Closes: #1497
Approved by: jlebon
Rasmus Thomsen [Thu, 8 Mar 2018 16:20:11 +0000 (17:20 +0100)]
configure: add option for libsystemd
Until now ostree checked for libsystemd and enabled
support for it if it found it. This commit changes that
behavior by adding an option to enable/disable libsystemd.
This is especially useful if one uses a source based distro
(like Gentoo/Exherbo), where one wants to avoid such automagic
detection of dependencies and prefers switches for that instead.
Closes: #1490
Approved by: cgwalters
Colin Walters [Mon, 12 Mar 2018 22:02:04 +0000 (18:02 -0400)]
tests: Avoid generating lots of output in itest-payload-link
We noticed this in a recent PR. While I'm here, also only do
the `find` once, add `-type l` for good measure, and use our
built in `libtest.sh` assertion functions.
Closes: #1494
Approved by: giuseppe
Joaquim Rocha [Mon, 12 Mar 2018 12:24:22 +0000 (13:24 +0100)]
pull: Ignore the cancellable when aborting a transaction
In ostree_repo_abort_transaction, if we pass a cancellable and it gets
canceled, then the function may fail to fully clean up the transaction
state. This was happening e.g. when the ostree_repo_pull_with_options
call got cancelled.
To fix this, as suggested by Colin Walters, we set the passed
cancellable as NULL, in order for it to be ignored.
https://github.com/ostreedev/ostree/issues/1491
Closes: #1492
Approved by: jlebon
Colin Walters [Thu, 22 Feb 2018 19:16:33 +0000 (14:16 -0500)]
ci: Rework installed tests to use Fedora Standard Test interface
Reusing the way `standard-test-roles` has support for booting
a qcow2 actually gets us to the "VM-in-container" flow. Plus
Ansible over shell script is sometimes nicer.
https://fedoraproject.org/wiki/CI/Tests#Testing_an_Atomic_Host
It's better than what we were doing before for installed tests,
and moreover using Ansible more broadly for testing is going
to align us better with Fedora's CI.
As part of this I split off a "libpaprci" which I intend to maintain
as a "copylib" for a little bit between ostree/rpm-ostree, and then
we'll figure out how to expand from there (maybe some of the patterns
get "baked in" to PAPR for example).
Note the `FAH27-insttests` context moves to the top since it's now
of primary importance, and I expect that we start expanding it.
Closes: #1462
Approved by: jlebon
Jeremy Hiatt [Thu, 8 Mar 2018 01:44:43 +0000 (01:44 +0000)]
lib/repo: Fix multi-signature support when generating summary files
Ensure that the metadata object is built up with the signatures from all keys
passed to ostree_repo_add_gpg_signature_summary(). Previously only the signature
from the last key would end up in the metadata.
Closes: #1488
Closes: #1489
Approved by: jlebon
Giuseppe Scrivano [Fri, 2 Feb 2018 13:01:08 +0000 (14:01 +0100)]
commit: add logic for .payload-link
When a new object is added to the repository, create a
$PAYLOAD-SHA256.payload-link symlink file as well. The target of the
symlink is the checksum of the object that was added the repository.
Whenever we add a new object file, in addition to lookup if the file is
already present with the same checksum we also check if an object with
the same payload is in the repository.
If a file with the same payload is already present in the repository, we
copy it with `glnx_regfile_copy_bytes` that internally attempts to
create a reflink (ioctl (..., FICLONE, ..)) to the target file if the
file system supports it. This enables to have objects that share the
payload but have a different inode and xattrs.
By default the payload-link-threshold value is G_MAXUINT64 that disables
the feature.
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
Closes: #1443
Approved by: cgwalters
Giuseppe Scrivano [Fri, 2 Feb 2018 12:58:40 +0000 (13:58 +0100)]
ostree: introduce PAYLOAD_LINK object type
It will be used by successive commits to keep track of the payload
checksum for objects stored in the repository.
The goal is that files having the same payload but different xattrs can
take advantage of reflinks where supported.
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
Closes: #1443
Approved by: cgwalters
Giuseppe Scrivano [Wed, 14 Feb 2018 12:24:43 +0000 (13:24 +0100)]
ostree-repo-private: remove declaration for _ostree_repo_find_object
it was removed with:
commit
8609cb036b935ce942214e9fdee6d90de0a210af
Author: Colin Walters <walters@verbum.org>
Date: Thu Apr 21 15:14:51 2016 -0400
repo: Simplify internal has_object() lookup code
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
Closes: #1443
Approved by: cgwalters
Colin Walters [Mon, 5 Mar 2018 22:18:54 +0000 (17:18 -0500)]
docs/prune: Document that --static-deltas-only isn't that useful
This is the documentation followup to: https://github.com/ostreedev/ostree/pull/1482
See also https://github.com/ostreedev/ostree/issues/1481
Closes: #1484
Approved by: jlebon
Colin Walters [Mon, 5 Mar 2018 22:31:12 +0000 (17:31 -0500)]
repo/refs: Clean up error prefixing
Add some "function global" prefixing in line with what we do in
other places now, and drop the "manual filename" prefixing that
is no longer necessary since
https://github.com/GNOME/libglnx/commit/
23f7df15006f14ddc3bc2ddee690f7f8604c3ebe
Closes: https://github.com/ostreedev/ostree/issues/1467
Closes: #1485
Approved by: jlebon
Matthew Leeds [Sat, 3 Mar 2018 20:57:12 +0000 (12:57 -0800)]
lib: Fix memory leaks of OstreeRemote
The _ostree_repo_get_remote() and _ostree_repo_get_remote_inherited()
methods transfer ownership of the returned OstreeRemote to the caller,
so this commit fixes a few call sites that weren't properly freeing it.
Closes: #1478
Approved by: cgwalters
Colin Walters [Mon, 5 Mar 2018 15:42:19 +0000 (10:42 -0500)]
prune: Error if --static-deltas-only without --delete-commit
The original changes here apparently had the *idea* that `--static-deltas-only`
would be useful in general, but we never implemented that. The current
situation where it's ignored unless `--delete-commit` is specified is
very misleading and I can easily see it leading to data loss for people.
Let's error out until we have a chance to make it actually useful.
Related: https://github.com/ostreedev/ostree/issues/1479
Closes: #1482
Approved by: giuseppe
Colin Walters [Mon, 5 Mar 2018 15:56:45 +0000 (10:56 -0500)]
lib/repo: Do account for size with prune --no-prune
I think this got changed in a refactor. We definitely want
to total up the amount of space that *would* be freed even
with `--no-prune` AKA `OSTREE_REPO_PRUNE_FLAGS_NO_PRUNE`.
It's actually a bit terrifying this is apparently the first test case for
the `--no-prune` option...
Closes: https://github.com/ostreedev/ostree/issues/1480
Closes: #1483
Approved by: jlebon
Matthew Leeds [Thu, 1 Mar 2018 23:43:38 +0000 (15:43 -0800)]
lib/repo-finder-mount: Improve debug message
This makes it easier to tell which mount is being checked when repos are
found.
Closes: #1477
Approved by: cgwalters
Matthew Leeds [Thu, 1 Mar 2018 23:44:42 +0000 (15:44 -0800)]
lib/remote: Fix memory leak
Closes: #1476
Approved by: cgwalters
Matthew Leeds [Wed, 28 Feb 2018 23:58:41 +0000 (15:58 -0800)]
lib/repo-finder-mount: Update comment about paths
This updates the gtk-doc comment for OstreeRepoFinderMount to match the
correct flatpak repo path, which was fixed in commit
6db6268df.
Closes: #1473
Approved by: cgwalters
Matthew Leeds [Thu, 1 Mar 2018 00:06:31 +0000 (16:06 -0800)]
lib/repo-pull: Fix free function for hash table
The "ref_original_commits" hash table uses string values, not variants,
so fix the free function passed to g_hash_table_new_full (). Since
g_variant_unref isn't NULL safe, this prevents an assertion failure when
a NULL value is inserted.
Dan Nicholson suggested this patch; I'm just submitting it because he's
busy.
Fixes https://github.com/ostreedev/ostree/issues/1433
Closes: #1474
Approved by: cgwalters
Jonathan Lebon [Wed, 28 Feb 2018 17:30:18 +0000 (17:30 +0000)]
lib/sysroot: Fix retrieving non-booted pending deployment
If we're booted into a deployment, then any queries for the pending
merge deployment of a non-booted OS will fail due all of them being
considered rollback.
Fix this by filtering by `osname` *before* determining if we've crossed
the booted deployment yet.
Closes: #1472
Approved by: cgwalters
Matthew Leeds [Tue, 27 Feb 2018 02:54:54 +0000 (18:54 -0800)]
lib/repo-finder-mount: Fix path to flatpak repo
OstreeRepoFinderMount checks mounts for a few well-known directories
such as "ostree/repo" and ".ostree/repo" to try to find remotes. One of
the hard-coded directories is "var/lib/flatpak" but that's the flatpak
directory, not the ostree repo used by flatpak, which is at
"var/lib/flatpak/repo". So this commit changes the path so the repo can
be found.
For recent versions of Endless, flatpak uses /ostree/repo as its
repository, so this commit won't make a difference there. But it may
help on other operating systems.
Closes: #1471
Approved by: cgwalters
Colin Walters [Mon, 26 Feb 2018 19:11:00 +0000 (14:11 -0500)]
bash-completion: Remove `admin` completions
The `admin` commandline should be considered a demo; I just added
the `pin` command *mostly* so we could use it for unit tests, although
I can imagine other people using it.
But maintaining completions is a lot of overhead right now, let's not
do it for `admin`.
The other command line options that operate on repos we will definitely maintain
since they're used in releng contexts.
Closes: #1468
Approved by: jlebon
Colin Walters [Fri, 23 Feb 2018 17:46:32 +0000 (12:46 -0500)]
sysroot: Add concept of deployment "pinning" 📌
Example user story: Jane rebases her OS to a new major version N, and wants to
keep around N-1 even after a few upgrades for a while so she can easily roll
back. I plan to add `rpm-ostree rebase --pin` to opt-in to this for example.
Builds on the new `libostree-transient` group to store pinning state there.
Closes: https://github.com/ostreedev/ostree/issues/1460
Closes: #1464
Approved by: jlebon
Colin Walters [Fri, 23 Feb 2018 19:23:38 +0000 (14:23 -0500)]
sysroot: Add API to clean up transient keys in origin files
The `origin/unlocked` and `origin/override-commit` keys are examples of state
that's really transient; we don't want to maintain them across upgrades. Right
now there are bits for this in both `ostree admin upgrade` as well as in
rpm-ostree.
This new API will slightly clean up both cases, but it's really prep for adding
a concept of deployment "pinning" that will live in the new
`libostree-transient` group.
Closes: #1464
Approved by: jlebon
Colin Walters [Mon, 26 Feb 2018 17:26:32 +0000 (12:26 -0500)]
sysroot: Bump mtime when writing an origin file
This ensures that e.g. `rpm-ostreed` will get notified of the changes.
Closes: #1464
Approved by: jlebon
Simon McVittie [Wed, 17 Jan 2018 14:07:32 +0000 (14:07 +0000)]
Use Python 3 for tests
Signed-off-by: Simon McVittie <smcv@debian.org>
Closes: #1463
Approved by: cgwalters
Simon McVittie [Wed, 17 Jan 2018 15:19:12 +0000 (15:19 +0000)]
tests/bootloader-entries-crosscheck: Use Python 3-friendly sorting
This is a little clearer than a strcmp()-style negative/zero/positive
return, and also works in Python 2.
Signed-off-by: Simon McVittie <smcv@debian.org>
Closes: #1457
Approved by: cgwalters
Simon McVittie [Wed, 17 Jan 2018 15:03:59 +0000 (15:03 +0000)]
test-concurrency: Explicitly use floor division
Python 3 is pickier about this. Python 2.7 has Python 3-compatible
semantics for division when the division feature is imported from the
future.
Signed-off-by: Simon McVittie <smcv@debian.org>
Closes: #1457
Approved by: cgwalters
Simon McVittie [Wed, 17 Jan 2018 14:42:20 +0000 (14:42 +0000)]
test-concurrency: Replace range with xrange
range in Python 3 does what xrange did in Python 2. This still works in
Python 2, it just uses a bit more memory.
Signed-off-by: Simon McVittie <smcv@debian.org>
Closes: #1457
Approved by: cgwalters
Simon McVittie [Wed, 17 Jan 2018 14:25:26 +0000 (14:25 +0000)]
test-concurrency: Use Python 3 syntax for octal
This also works in Python 2.7, and is a little clearer.
Signed-off-by: Simon McVittie <smcv@debian.org>
Closes: #1457
Approved by: cgwalters
Colin Walters [Thu, 15 Feb 2018 13:55:40 +0000 (08:55 -0500)]
build-sys: Post-release version bump
Closes: #1455
Approved by: jlebon
Colin Walters [Thu, 15 Feb 2018 13:53:39 +0000 (08:53 -0500)]
Release 2018.2
There are enough fixes here, and there are some potentially larger patches
incoming like wmanley's checkout speedups and the payload link that will need
soak time in master.
Closes: #1455
Approved by: jlebon
Colin Walters [Wed, 14 Feb 2018 20:28:17 +0000 (15:28 -0500)]
fetcher: Drop max queue size assertion in libsoup/libcurl backends
Since
f4d1334e19ce3ab2f8872b1e28da52044f559401 the primary pull code maintains a
maximum queue. In that commit message I said `Note that I kept an assertion.`.
But I think this is wrong since while it covers a lot of the normal cases, if
one is e.g. trying to fetch a ton of refs, the primary pull code doesn't yet
queue those. While it'd be nice to queue those, it isn't worth carrying
extra assertions in the backends that can still trigger.
Closes: https://github.com/ostreedev/ostree/issues/1451
Closes: #1453
Approved by: dbnicholson
Alex Kiernan [Wed, 14 Feb 2018 21:03:18 +0000 (21:03 +0000)]
Fix static-compiler when CC includes args
Ensure arguments are quoted so that if you include args in CC that
they're handled as a whole.
Closes: #1454
Approved by: cgwalters
Colin Walters [Thu, 8 Feb 2018 21:33:18 +0000 (16:33 -0500)]
core: Add API (and standard concept for) content checksum
There are a few cases for knowing whether a commit has identical
content to another commit. Some people want to do a "promotion workflow",
where the content of a commit on a tesitng branch is then "promoted"
to a production branch with `ostree commit --tree=ref`.
Another use case I just hit in rpm-ostree deals with
[jigdo](https://github.com/projectatomic/rpm-ostree/issues/1081) where we're
importing RPMs on both the client and server, and will be using the
content checksum, since the client/server cases inject different metadata
into the commit object.
Closes: https://github.com/ostreedev/ostree/issues/1315
Closes: #1449
Approved by: jlebon
Matthew Leeds [Thu, 8 Feb 2018 22:13:45 +0000 (14:13 -0800)]
lib/pull: Properly remove temporary remotes
For P2P pulls ostree adds temporary remotes and removes them in
find_remotes_cb(). However, if an OstreeRepoFinderResult gets freed
during the course of that function, the OstreeRemote in the result is
freed but a pointer to it remains in the remotes_to_remove array. This
means that when _ostree_repo_remove_remote() gets called on it at the
end of the function it will fail. In my case the resulting error was
"OSTree-CRITICAL **: _ostree_repo_remove_remote: assertion 'remote->name
!= NULL' failed" but I think it could also seg fault.
This commit adds a reference to the remote so it can be properly removed
when we're finished with it.
Closes: #1450
Approved by: giuseppe
Colin Walters [Tue, 6 Feb 2018 15:13:46 +0000 (10:13 -0500)]
repo: Create uncompressed-object-cache dir dynamically
Having the `uncompressed-object-cache` directory in `archive` repos by default
is clutter; the functionality should be considered deprecated.
Now we only create the directory if we're doing a checkout with the cache
enabled.
Closes: #1446
Approved by: jlebon
Jonathan Lebon [Thu, 1 Feb 2018 22:32:32 +0000 (22:32 +0000)]
lib/checkout: add filter API to skip over files
This is analogous to the filtering support for the commit API: we allow
library users to skip over checking out specific files. This is useful
in some tricky situations where we *know* that the files to be checked
out will conflict with existing files in subtle ways.
One such example is in rpm-ostree support for multilib. There, we want
to allow checking out a package onto an existing tree, but skipping over
files that are not coloured to our preferred value (e.g. not overwriting
an i686 version of `ldconfig` if we already have the `x86_64` version).
See https://github.com/projectatomic/rpm-ostree/pull/1227 for details.
Closes: #1441
Approved by: cgwalters
Alex Kiernan [Sun, 4 Feb 2018 12:08:29 +0000 (12:08 +0000)]
switchroot: Fix split source/build directory
If you have split source and build directories, then building
static ostree-prepare-root fails to find the source files.
https://github.com/ostreedev/ostree/issues/1429
Closes: #1445
Approved by: cgwalters
Colin Walters [Thu, 25 Jan 2018 10:57:56 +0000 (11:57 +0100)]
docs: Dual license under CC BY-SA and the GFDL
This will allow the text to be used in Wikipedia for example; it
also just makes more sense for documentation than the LGPLv2+.
Closes: #1431
Closes: #1432
Approved by: jlebon
Jonathan Lebon [Thu, 1 Feb 2018 22:10:47 +0000 (22:10 +0000)]
bin/checkout: add --selinux-policy switch
This was already supported by the underlying API. Expose it so that we
can test it.
Closes: #1442
Approved by: cgwalters
Jonathan Lebon [Thu, 1 Feb 2018 22:07:36 +0000 (22:07 +0000)]
tests/installed: support TESTS filter
Lifted from rpm-ostree. Makes iterating on a single test much faster.
Example use:
TESTS=label-selinux ./ostree/tests/installed/run.sh
Closes: #1442
Approved by: cgwalters
Jonathan Lebon [Thu, 1 Feb 2018 22:06:50 +0000 (22:06 +0000)]
libotutil: factor out utility to parse file by line
This will be used in the checkout CLI as well.
Closes: #1442
Approved by: cgwalters
Colin Walters [Fri, 2 Feb 2018 18:46:15 +0000 (13:46 -0500)]
deploy: SELinux-relabel installed kernel/initramfs data
When we changed around the kernel location in rpm-ostree, we
started installing the kernel into `/boot` as `modules_object_t`,
and the current policy didn't permit that. For maximum compatibility,
relabel installed kernel/initramfs/dtb as `boot_t`.
https://bugzilla.redhat.com/show_bug.cgi?id=
1536991
Closes: #1444
Approved by: jlebon
Marcus Folkesson [Tue, 30 Jan 2018 19:26:26 +0000 (20:26 +0100)]
Add SPDX-License-Identifier to source files
SPDX License List is a list of (common) open source
licenses that can be referred to by a “short identifier”.
It has several advantages compared to the common "license header texts"
usually found in source files.
Some of the advantages:
* It is precise; there is no ambiguity due to variations in license header
text
* It is language neutral
* It is easy to machine process
* It is concise
* It is simple and can be used without much cost in interpreted
environments like java Script, etc.
* An SPDX license identifier is immutable.
* It provides simple guidance for developers who want to make sure the
license for their code is respected
See http://spdx.org for further reading.
Signed-off-by: Marcus Folkesson <marcus.folkesson@gmail.com>
Closes: #1439
Approved by: cgwalters
Colin Walters [Mon, 29 Jan 2018 12:48:02 +0000 (13:48 +0100)]
switchroot: Ensure /sysroot is set to "private" propagation
Downstream BZ: https://bugzilla.redhat.com/show_bug.cgi?id=
1498281
This came up as a problem with `oci-umount` which was trying to ensure some host
mounts like `/var/lib/containers` don't leak into privileged containers. But
since our `/sysroot` mount wasn't private we also got a copy there.
We should have done this from the very start - it makes `findmnt` way, way less
ugly and is just the obviously right thing to do, will possibly create world
peace etc.
Closes: #1438
Approved by: rhvgoyal
Philip Withnall [Mon, 29 Jan 2018 14:14:29 +0000 (14:14 +0000)]
lib/core: Expand documentation for ostree_parse_refspec()
The old documentation had outdated and incomplete annotations, and
didn’t make it very clear that out_remote could legitimately return
NULL.
Signed-off-by: Philip Withnall <withnall@endlessm.com>
Closes: #1437
Approved by: cgwalters
Colin Walters [Tue, 9 Jan 2018 18:01:47 +0000 (13:01 -0500)]
ci: Bump flatpak version (and build to f27)
Just keeping this updated.
Closes: #1400
Approved by: jlebon
Matthew Leeds [Thu, 18 Jan 2018 08:32:05 +0000 (00:32 -0800)]
lib/pull: Allow specific commits in P2P updates
Currently users of the find_remotes_async()/pull_from_remotes_async()
functions have no way to specify a commit hash to use instead of the
latest one available. This commit implements an "override-commit-ids"
option analogous to the one used by ostree_repo_pull_with_options().
It's accomplished by returning OstreeRepoFinderResult objects pointing
to the given commit checksum(s) regardless of which ones were available
from the remotes, but in the future this implementation could be
improved to take into account the commits advertised by the remotes.
One effect of this is that flatpak will have the ability to downgrade
apps that use collection IDs
(https://github.com/flatpak/flatpak/issues/1309).
Closes: #1425
Approved by: pwithnall
Colin Walters [Thu, 18 Jan 2018 14:19:21 +0000 (09:19 -0500)]
bin/delta: Fix compilation with relative subdirs --filename
Currently we were parsing `opt_filename` twice...I dug through
the history a bit and it looks like it may have been an accident
from refactoring.
What we're fixing here concretely is that using relative subdirectories
like `--filename somesubdir/foo` broke because we were incorrectly
passing the `somesubdir/` again.
Closes: #1423
Closes: #1427
Approved by: jlebon
Colin Walters [Tue, 9 Jan 2018 18:20:24 +0000 (13:20 -0500)]
ci: Run a subset ⊂ of rpm-ostree's tests
This is a quick hack to get us more than unit testing, albeit indirectly.
See: https://github.com/projectatomic/rpm-ostree/issues/662
Closes: #771
Approved by: jlebon
Colin Walters [Thu, 18 Jan 2018 14:01:27 +0000 (09:01 -0500)]
ci/papr: Update most contexts to f27
Many of them actually already *were* because they
were inherting.
An exception is flatpak which is being worked on in
https://github.com/ostreedev/ostree/pull/1400
Closes: #1426
Approved by: jlebon
Colin Walters [Wed, 17 Jan 2018 14:18:45 +0000 (09:18 -0500)]
lib/pull: Port a few functions to new style
Prep for further work here. This diff is a bit noisy for the delta bits because
the identation was off originally as well.
Closes: #1424
Approved by: jlebon
William Manley [Tue, 9 Jan 2018 19:40:07 +0000 (19:40 +0000)]
Add support for devicetree files alongside the kernel and initramfs
Much like the (optional) initramfs at
`/usr/lib/ostree-boot/initramfs-<SHA256>` or
`/usr/lib/modules/$kver/initramfs` you can now optionally include a
flattened devicetree (.dtb) file alongside the kernel at
`/usr/lib/ostree-boot/devicetree-<SHA256>` or
`/usr/lib/modules/$kver/devicetree`.
This is useful for embedded ARM systems which need the devicetree file
loaded by the bootloader for the kernel to discover and initialise
hardware. See https://en.wikipedia.org/wiki/Device_tree for more
information.
This patch was mostly produced by copy-pasting code for initramfs handling
and renaming `s/initramfs/devicetree/g`. It's not beautiful, but it is
fairly straightforward.
It may be useful to extend device-tree support in a number ways in the
future. Device trees dependant on many details of the hardware they
support. This makes them unlike kernels, which may support many different
hardware variants as long as the instruction-set matches. This means that
a ostree tree created with a device-tree in this manner will only boot on
a single model of hardware. This is sufficient for my purposes, but may
not be for others'.
I've tested this on my NVidia Tegra TK1 device which has u-boot running
in syslinux-compatible mode.
Closes: #1411
Approved by: cgwalters
William Manley [Mon, 6 Mar 2017 19:41:46 +0000 (19:41 +0000)]
syslinux: Add support for DEVICETREE from bootloader spec
The bootloader spec says:
> `devicetree` refers to the binary device tree to use when executing the
> kernel. This also shall be a path relative to the `$BOOT` directory. This
> key is optional. Example:
> `
6a9857a393724b7a981ebb5b8495b9ea/3.8.0-2.fc19.armv7hl/tegra20-paz00.dtb`
This is necessary for booting my NVidia Tegra TK1 device. It uses u-boot
with syslinux compatibility. In the syslinux files that come with the
device this is called `FDT`, but u-boot treats `FDT and `DEVICETREE` as
synonyms.
See also: [
f43c401 in u-boot].
[
f43c401 in u-boot]: http://git.denx.de/?p=u-boot.git;a=commit;h=
f43c401b72bb0db43ab0b55c4a79e1f4889d3aa2
Closes: #1411
Approved by: cgwalters
William Manley [Mon, 15 Jan 2018 20:53:54 +0000 (20:53 +0000)]
ostree admin deploy: Add --no-prune option
If you want cleanup, but don't want to prune the repo. Pruning can
be quite expensive so ostree admin deploy can be much faster without
pruning.
Closes: #1418
Approved by: cgwalters
William Manley [Sat, 13 Jan 2018 15:30:17 +0000 (15:30 +0000)]
ostree admin deploy: Refactor bringing cleaning into `main`
In the next commit I will add --no-prune which will affect cleaning. By
doing this refactor we avoid having to add a NO_PRUNE flag.
Closes: #1418
Approved by: cgwalters
Matthew Leeds [Sat, 13 Jan 2018 00:32:09 +0000 (16:32 -0800)]
find-remotes: Minor fixes to --finders code
This introduces no functional changes, only cleanups.
Closes: #1414
Approved by: jlebon
Matthew Leeds [Thu, 11 Jan 2018 22:04:08 +0000 (14:04 -0800)]
man: Add man page for find-remotes
Closes: #1410
Approved by: pwithnall
Matthew Leeds [Sat, 13 Jan 2018 06:22:50 +0000 (22:22 -0800)]
man: Update ostree-summary.xml
Update the man page for the summary command to add the undocumented
options, make the syntax clear, and add examples.
Closes: #1416
Approved by: pwithnall
Colin Walters [Mon, 15 Jan 2018 14:34:45 +0000 (09:34 -0500)]
build-sys: Post-release version bump
I'm still doing release, then versionbump as separate PRs to ensure
the release commit is tested by itself.
Closes: #1417
Approved by: pwithnall
Colin Walters [Fri, 12 Jan 2018 20:27:44 +0000 (15:27 -0500)]
Release 2018.1
In particular I'd like to get the `--copyup` changes out for an rpm-ostree
release that will use them. But there are other good changes here, and let's
keep up a regular release train 🚄 in general.
Closes: #1413
Approved by: jlebon
Colin Walters [Fri, 12 Jan 2018 14:15:21 +0000 (09:15 -0500)]
lib: Validate metadata structure more consistently during pull
Previously we were doing e.g. `ot_util_filename_validate()` specifically inline
in dirtree objects, but only *after* writing them into the staging directory (by
default). In (non-default) cases such as not using a transaction, such an object
could be written directly into the repo.
A notable gap here is that `pull-local --untrusted` was *not* doing
this verification, just checksums. We harden that (and also the
static delta writing path, really *everything* that calls
`ostree_repo_write_metadata()` to also do "structure" validation
which includes path traversal checks. Basically, let's try hard
to avoid having badly structured objects even in the repo.
One thing that sucks in this patch is that we need to allocate a "bounce buffer"
for metadata in the static delta path, because GVariant imposes alignment
requirements, which I screwed up and didn't fulfill when designing deltas. It
actually didn't matter before because we weren't parsing them, but now we are.
In theory we could check alignment but ...eh, not worth it, at least not until
we change the delta compiler to emit aligned metadata which actually may be
quite tricky. (Big picture I doubt this really matters much right now
but I'm not going to pull out a profiler yet for this)
The pull test was extended to check we didn't even write a dirtree
with path traversal into the staging directory.
There's a bit of code motion in extracting
`_ostree_validate_structureof_metadata()` from `fsck_metadata_object()`.
Then `_ostree_verify_metadata_object()` builds on that to do checksum
verification too.
Closes: #1412
Approved by: jlebon
Colin Walters [Fri, 12 Jan 2018 15:40:36 +0000 (10:40 -0500)]
lib/checkout: Validate pathnames during checkout
While we do protect against path traversal during pull, let's also validate
during checkout; it's a cheap operation and provides good last-mile protection.
Closes: #1412
Approved by: jlebon
Colin Walters [Fri, 12 Jan 2018 14:01:52 +0000 (09:01 -0500)]
tests: Add a test case for path traversal in a dirtree
I was reading about a recent security issue with both EMC and VMWare:
https://arstechnica.com/information-technology/2018/01/emc-vmware-security-bugs-throw-gasoline-on-cloud-security-fire/
It's a classic path traversal problem, and that made me think more about our
handling of this in libostree. Fortunately of course, not being new to
this rodeo, long ago I *did* consider path traversal. Inside the pull
code, we call `ot_util_filename_validate()`. Also, `fsck` does this too.
I have further followups here, but let's add some test cases for this. I crafted
a repository with a `../` in a dirtree object by patching libostree to inject
it, and that's included as a tarball.
This patch covers the two cases where we do already have checks; pulling
via HTTP, and in `fsck`.
Closes: #1412
Approved by: jlebon
Jonathan Lebon [Thu, 11 Jan 2018 20:54:26 +0000 (20:54 +0000)]
tests/libtest-core: support multiple literal checks
`grep` supports checking multiple fixed strings separated by newlines,
but it's mostly just easier to pass them as separate arguments, so let's
support that. This is now at parity with the similar
`assert_file_has_content`.
Closes: #1409
Approved by: cgwalters
Colin Walters [Wed, 10 Jan 2018 21:02:59 +0000 (16:02 -0500)]
lib/fetcher: Add version to USER_AGENT string
This came up in allowing Fedora infrastructure to work around a libcurl bug with
HTTP2: https://pagure.io/atomic-wg/issue/405
Closes: https://github.com/ostreedev/ostree/issues/1405
Closes: #1406
Approved by: jlebon
Matthew Leeds [Wed, 10 Jan 2018 07:42:49 +0000 (23:42 -0800)]
tests: Use --finders option for find-remotes
All the current uses of the find-remotes command in the tests use it to
find configured remotes or mounted (USB) remotes, so using
--finders=config and --finders=mount in the tests respectively shouldn't
affect the correctness of the tests. It does however allow the tests to
be run in an environment that doesn't have an Avahi daemon.
Closes: #1407
Approved by: cgwalters
Matthew Leeds [Wed, 10 Jan 2018 07:36:40 +0000 (23:36 -0800)]
find-remotes: Add --finders option
It can be helpful to be able to choose which OstreeRepoFinder instances
to use when using the find-remotes command. For example, if the tests
need to run in an environment that can't have an Avahi daemon, this
allows you to disable the Avahi (LAN) finder. This commit adds the
--finders option for this purpose.
Closes: #1407
Approved by: cgwalters
William Manley [Tue, 7 Mar 2017 12:57:26 +0000 (12:57 +0000)]
Tests: test-no-initramfs: Test both legacy and new kernel locations
Closes: #1401
Approved by: cgwalters
Gatis Paeglis [Wed, 24 Aug 2016 12:02:18 +0000 (14:02 +0200)]
ostree-grub-generator: update outdated comment
Closes: #1401
Approved by: cgwalters
Gatis Paeglis [Wed, 24 Aug 2016 11:26:47 +0000 (13:26 +0200)]
Support for booting without initramfs
Previously when initramfs-* was not found in a deployment's
boot directory, it was assumed that rootfs is prepared for
ostree booting by a kernel patch.
With this patch, the behaviour changes to be - if initramfs-*
is not found, assume that system is using a static
ostree-prepare-root as init process. Booting without initramfs
is a common use case on embedded systems. This approach is
also more convenient, than having to patch the kernel.
Closes: #1401
Approved by: cgwalters
Gatis Paeglis [Fri, 12 Aug 2016 09:51:04 +0000 (11:51 +0200)]
deploy: add --karg-none argument
If the current deployment has "rootwait root=/dev/sda2",
but the new deployment does not need "rootwait" anymore,
there is no way to clear this arg at the moment (as opposed
to "karg=root=", which overrides any earlier argument with
the same name). With "--karg-none" users can now clear all
the previous args and set new "root=":
ostree admin deploy --karg-none --karg=root=LABEL=rootfs
Closes: #1401
Approved by: cgwalters
Gatis Paeglis [Fri, 12 Aug 2016 06:50:29 +0000 (08:50 +0200)]
ostree-prepare-root: enabler for simpler kernel arg
With the current approach, when ostree-prepare-root is used
on the kernel command line as init=, it always assumes that
the next value in the argument list is a path to the sysroot.
The code for falling back to a default path (if none is provided),
would only work if init= is the last arg in the argument list.
We can not rely on that and have to explicitly provide the
path to the sysroot. Which defeats the purpose of a default
path selection code.
To keep command line neater assume that sysroot is on / when
using ostree-prepare-root as init. This probably is what most
people want anyways. Also _ostree_kernel_args* API assumes
that args are space separated list. Which is problematic for:
"init=${ostree}/usr/lib/ostree/ostree-prepare-root /" as it
gets split in two.
Closes: #1401
Approved by: cgwalters
Jonathan Lebon [Tue, 9 Jan 2018 21:08:09 +0000 (21:08 +0000)]
bash/ostree: add missing --add-metadata option
Closes: #1402
Approved by: cgwalters
Jonathan Lebon [Tue, 9 Jan 2018 20:29:22 +0000 (20:29 +0000)]
bin/commit: add --keep-metadata option
Clients of libostree such as rpm-ostree make extensive use of the
`ostree commit -b foo --tree=ref=foo` pattern in their tests, e.g. to
simulate an update.
What I'm trying to solve here is that it's often the case that we want
to keep metadata from the previous commit without having to be too
verbose (i.e. reading from the parent, then passing it as an argument).
The new `--keep-metadata` switch makes this really easy. I intend to use
this in the rpm-ostree testsuite to make sure we always carry over the
`source-title` metadata as well as during set up for tests that require
`rpmostree.rpmdb.pkglist` metadata.
I initially implemented this in a small wrapper script that uses the API
directly, though we make use of so many other `ostree commit` functions
that it'd require re-implementing a lot of it.
Closes: #1402
Approved by: cgwalters
Jonathan Lebon [Tue, 9 Jan 2018 20:00:24 +0000 (20:00 +0000)]
bin/commit: move parent checking code higher up
No functional change. Prep for the next commit.
Closes: #1402
Approved by: cgwalters
Colin Walters [Tue, 9 Jan 2018 15:22:50 +0000 (10:22 -0500)]
grub2: Exit gracefully if there's no system ostree repository
Apparently there testing systems that literally install *all*
packages. Having `ostree-grub2` currently causes grub2 to fail
on a non-ostree managed system. Let's just gracefully exit
if there's no system repository.
https://bugzilla.redhat.com/show_bug.cgi?id=
1532668
Closes: #1399
Approved by: jlebon
Will Thompson [Tue, 9 Jan 2018 11:51:04 +0000 (11:51 +0000)]
ostree-grub-generator: fix typo in comment
Closes: #1398
Approved by: jlebon
Anton Gerasimov [Mon, 8 Jan 2018 13:53:46 +0000 (14:53 +0100)]
build-sys: Allow building with curl, but without libsoup
Some people (particularly embedded) may find it simpler to
drop libsoup from the build dependency side, but still use libcurl.
Note though this currently neuters almost all of the tests.
Signed-off-by: Anton Gerasimov <anton.gerasimov@openmailbox.org>
Closes: #1397
Approved by: cgwalters
Colin Walters [Mon, 8 Jan 2018 14:28:47 +0000 (09:28 -0500)]
bin: Fix cookie builtin build with curl but no soup
Prep for supporting `--with-curl --without-soup`.
Closes: #1397
Approved by: cgwalters
Colin Walters [Fri, 5 Jan 2018 21:02:58 +0000 (16:02 -0500)]
rofiles: Fix --copyup when creating a new file
This tripped up the `docbook-dtds` `%post` in my experiments
with doing rpm-ostree for buildroots.
I cloned and built [xfstests](https://git.kernel.org/pub/scm/fs/xfs/xfstests-dev.git)
but haven't yet investigated actually running it.
In the meantime let's do the obvious fix here; we need to distinguish
between "copyup enabled" and "actually did a copyup" in the open path
at least, since if we didn't do a copyup we don't need to re-open.
Closes: #1396
Approved by: jlebon
Colin Walters [Thu, 14 Dec 2017 16:05:00 +0000 (11:05 -0500)]
rofiles: Add --copyup option
Sadly https://sourceware.org/bugzilla/show_bug.cgi?id=22089 is I think going to
actually force us to cave here. Even if we got the glibc patch in today, we need
to support the RHEL glibc. See also discussion about fish as part of the general
Fedora tracker.
This is basically needed to unblock rpm-ostree unified core 🌐:
https://github.com/projectatomic/rpm-ostree/issues/729
Closes: https://github.com/ostreedev/ostree/issues/1377
Closes: #1382
Approved by: jlebon
Simon McVittie [Wed, 3 Jan 2018 08:23:10 +0000 (08:23 +0000)]
tests: Assert that byte-order is swapped on LE but not BE CPUs
Closes: #1392
Signed-off-by: Simon McVittie <smcv@collabora.com>
Closes: #1393
Approved by: cgwalters
Colin Walters [Tue, 2 Jan 2018 15:00:17 +0000 (10:00 -0500)]
Revert "ci: Make rust build nonblocking for now"
This reverts commit
8ef18fd850d53fa01e7a3d8fe47fdd069b276b85.
Closes: #1391
Approved by: smcv
Colin Walters [Tue, 2 Jan 2018 14:54:52 +0000 (09:54 -0500)]
build-sys: Link with -ldl for rust build
I didn't dive into this too much, it looks like something in rust changed that
broke our build. Probably libstd gained a dependency on `-ldl` or so, and that's
handled by cargo? Anyways linking against it isn't going to hurt.
Closes: #1391
Approved by: smcv
Simon McVittie [Sun, 10 Dec 2017 19:39:38 +0000 (19:39 +0000)]
tests: Don't assume uid == primary gid
Nothing guarantees that each user has a group containing only
themselves. Even if they do, nothing guarantees that its group ID
equals the user ID, particularly if another user earlier in the same
range was created without a corresponding group or vice versa.
Signed-off-by: Simon McVittie <smcv@collabora.com>
Closes: #1390
Approved by: cgwalters
Marcus Folkesson [Thu, 21 Dec 2017 09:25:45 +0000 (10:25 +0100)]
lib/pull: allways include ostree-repo-pull-private.h
Allways include ostree-repo-pull-private.h to get rid of the following
build error when HAVE_LIBCURL_OR_LIBSOUP is not defined:
src/libostree/ostree-repo-pull.c:1493:1: error: no previous prototype
for '_ostree_repo_verify_bindings' [-Werror=missing-prototypes]
Signed-off-by: Marcus Folkesson <marcus.folkesson@gmail.com>
Closes: #1389
Approved by: cgwalters
Philip Withnall [Thu, 21 Dec 2017 18:01:44 +0000 (18:01 +0000)]
build: Fix typo in -Wparentheses warning
GCC supports -Wparentheses, not -Wparenthesis.
https://gcc.gnu.org/onlinedocs/gcc/Warning-Options.html#index-Wno-parentheses
Signed-off-by: Philip Withnall <withnall@endlessm.com>
Closes: #1388
Approved by: jlebon
Colin Walters [Wed, 20 Dec 2017 09:15:10 +0000 (10:15 +0100)]
build-sys: Post-release version bump
Closes: #1387
Approved by: jlebon
Colin Walters [Thu, 21 Dec 2017 21:31:18 +0000 (22:31 +0100)]
ci: Make rust build nonblocking for now
Will debug at some point but for now let's
unblock other things.
```
/usr/bin/ld: /var/tmp/checkout/target/release/libbupsplit_rs.a(bupsplit_rs-
db7d02fa07221ce3.bupsplit_rs0.rust-cgu.o): undefined reference to symbol 'dladdr@@GLIBC_2.2.5'
```
Closes: #1387
Approved by: jlebon
Colin Walters [Tue, 19 Dec 2017 14:54:01 +0000 (15:54 +0100)]
Release 2017.15
Let's do a new release with the locking preview, the http2 disable options and
other misc bugfixes to close out the year.
Closes: #1386
Approved by: jlebon
Colin Walters [Fri, 15 Dec 2017 02:42:54 +0000 (21:42 -0500)]
Bump libglnx, use "n items" progress for fsck
Sooo much nicer. See also
https://github.com/projectatomic/rpm-ostree/pull/1143
Update submodule: libglnx
Closes: #1383
Approved by: jlebon
Colin Walters [Fri, 15 Dec 2017 14:20:58 +0000 (09:20 -0500)]
build-sys: Use -fno-strict-aliasing by default
See discussion in https://bugzilla.gnome.org/show_bug.cgi?id=791622
This is what e.g. systemd, the Linux kernel, and lots of other projects do. It's
astonishingly hard to reliably get right; the optimization IMO only really
matters for truly high performance inner loops, but if you're doing
that kind of stuff today you're probably doing it on a GPU anyways.
Closes: #1384
Approved by: pwithnall
Colin Walters [Thu, 14 Dec 2017 18:13:42 +0000 (13:13 -0500)]
bin/refs: Disallow aliases to remote refs
It can't really work in general; the client and server would
have to agree on the name of the remote.
Closes: https://github.com/ostreedev/ostree/issues/1342
Closes: #1381
Approved by: jlebon
Colin Walters [Thu, 14 Dec 2017 17:54:24 +0000 (12:54 -0500)]
bin/commit: Support creating "unbound" commits
We had this basically forced on in the CLI; down the line I'd really like to
make this an API option to commit or so, but given that we found a use case in
the rpm-ostree test suite for "unbound" commits, let's support creating them
from the cmdline.
See: https://github.com/ostreedev/ostree/pull/1379
Closes: #1380
Approved by: jlebon