From e070839bff11c43236679c3baee0cb30a0ef5d52 Mon Sep 17 00:00:00 2001 From: Paul Whalen Date: Mon, 19 Aug 2024 09:27:50 -0400 Subject: [PATCH 1/4] Branching Fedora 41 from Rawhide Signed-off-by: Paul Whalen --- Containerfile | 2 +- fedora-bootc-config.json | 2 +- fedora-bootc.yaml | 4 +-- fedora-tier-0.yaml | 4 +-- fedora.repo | 67 ++-------------------------------------- 5 files changed, 8 insertions(+), 71 deletions(-) diff --git a/Containerfile b/Containerfile index 87a31ed..f7db6ac 100644 --- a/Containerfile +++ b/Containerfile @@ -23,7 +23,7 @@ # Because it's generating a base image and uses containerbuildcontextization features itself. # In the future some of this can be lifted. -FROM quay.io/fedora/fedora:rawhide as repos +FROM quay.io/fedora/fedora:41 as repos FROM quay.io/centos-bootc/bootc-image-builder:latest as builder ARG MANIFEST=fedora-bootc.yaml diff --git a/fedora-bootc-config.json b/fedora-bootc-config.json index 3a53fe1..04a990f 100644 --- a/fedora-bootc-config.json +++ b/fedora-bootc-config.json @@ -3,7 +3,7 @@ "containers.bootc": "1", "bootc.diskimage-builder": "quay.io/centos-bootc/bootc-image-builder", "redhat.id": "fedora", - "redhat.version-id": "rawhide" + "redhat.version-id": "41" }, "StopSignal": "SIGRTMIN+3", "Env": [ diff --git a/fedora-bootc.yaml b/fedora-bootc.yaml index 9b61e19..7d7e217 100644 --- a/fedora-bootc.yaml +++ b/fedora-bootc.yaml @@ -1,6 +1,6 @@ -releasever: rawhide +releasever: 41 repos: - - rawhide + - fedora metadata: name: fedora-boot-tier1 diff --git a/fedora-tier-0.yaml b/fedora-tier-0.yaml index c24d5c4..6fed456 100644 --- a/fedora-tier-0.yaml +++ b/fedora-tier-0.yaml @@ -1,6 +1,6 @@ -releasever: rawhide +releasever: 41 repos: - - rawhide + - fedora metadata: name: fedora-boot-tier0 diff --git a/fedora.repo b/fedora.repo index 373d78c..b472ab5 100644 --- a/fedora.repo +++ b/fedora.repo @@ -3,8 +3,8 @@ [fedora] name=Fedora $releasever - $basearch -baseurl=https://dl.fedoraproject.org/pub/fedora/linux/releases/$releasever/Everything/$basearch/os/ - https://dl.fedoraproject.org/pub/fedora-secondary/releases/$releasever/Everything/$basearch/os/ +# using the Latest Fedora 41 repository from Koji until GA +baseurl=https://kojipkgs.fedoraproject.org/compose/branched/latest-Fedora-41/compose/Everything/$basearch/os/ #metalink=https://mirrors.fedoraproject.org/metalink?repo=fedora-$releasever&arch=$basearch enabled=1 #metadata_expire=7d @@ -37,66 +37,3 @@ gpgcheck=1 metadata_expire=6h gpgkey=file:///usr/share/distribution-gpg-keys/fedora/RPM-GPG-KEY-fedora-$releasever-primary skip_if_unavailable=False - -[fedora-modular] -name=Fedora Modular $releasever - $basearch -baseurl=https://dl.fedoraproject.org/pub/fedora/linux/releases/$releasever/Modular/$basearch/os/ - https://dl.fedoraproject.org/pub/fedora-secondary/releases/$releasever/Modular/$basearch/os/ -#metalink=https://mirrors.fedoraproject.org/metalink?repo=fedora-modular-$releasever&arch=$basearch -enabled=1 -#metadata_expire=7d -repo_gpgcheck=0 -type=rpm -gpgcheck=1 -gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch -skip_if_unavailable=False - -[fedora-updates-modular] -name=Fedora Modular $releasever - $basearch - Updates -baseurl=https://dl.fedoraproject.org/pub/fedora/linux/updates/$releasever/Modular/$basearch/ - https://dl.fedoraproject.org/pub/fedora-secondary/updates/$releasever/Modular/$basearch/ -#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-released-modular-f$releasever&arch=$basearch -enabled=1 -repo_gpgcheck=0 -type=rpm -gpgcheck=1 -metadata_expire=6h -gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-$releasever-$basearch -skip_if_unavailable=False - -[fedora-updates-testing-modular] -name=Fedora Modular $releasever - $basearch - Test Updates -baseurl=https://dl.fedoraproject.org/pub/fedora/linux/updates/testing/$releasever/Modular/$basearch/ - https://dl.fedoraproject.org/pub/fedora-secondary/updates/testing/$releasever/Modular/$basearch/ -#metalink=https://mirrors.fedoraproject.org/metalink?repo=updates-testing-f$releasever&arch=$basearch -enabled=1 -gpgcheck=1 -metadata_expire=6h -gpgkey=file:///usr/share/distribution-gpg-keys/fedora/RPM-GPG-KEY-fedora-$releasever-primary -skip_if_unavailable=False - -[rawhide] -name=Fedora - Rawhide - Developmental packages for the next Fedora release -baseurl=https://dl.fedoraproject.org/pub/fedora/linux/development/$releasever/Everything/$basearch/os/ - https://dl.fedoraproject.org/pub/fedora-secondary/development/$releasever/Everything/$basearch/os/ -#metalink=https://mirrors.fedoraproject.org/metalink?repo=fedora-$releasever&arch=$basearch -enabled=1 -#metadata_expire=7d -repo_gpgcheck=0 -type=rpm -gpgcheck=1 -gpgkey=file:///usr/share/distribution-gpg-keys/fedora/RPM-GPG-KEY-fedora-$releasever-primary -skip_if_unavailable=False - -[fedora-devel] -name=Fedora $releasever - $basearch -baseurl=https://dl.fedoraproject.org/pub/fedora/linux/development/$releasever/Everything/$basearch/os/ - https://dl.fedoraproject.org/pub/fedora-secondary/development/$releasever/Everything/$basearch/os/ -#metalink=https://mirrors.fedoraproject.org/metalink?repo=fedora-$releasever&arch=$basearch -enabled=1 -#metadata_expire=7d -repo_gpgcheck=0 -type=rpm -gpgcheck=1 -gpgkey=file:///usr/share/distribution-gpg-keys/fedora/RPM-GPG-KEY-fedora-$releasever-primary -skip_if_unavailable=False From 7d31fac720bb056f9afaa8f037fc985d9a645429 Mon Sep 17 00:00:00 2001 From: Colin Walters Date: Thu, 22 Aug 2024 09:38:07 -0400 Subject: [PATCH 2/4] initramfs: Switch to `add_dracutmodules` Per discussion in https://github.com/rhkdump/kdump-utils/pull/29#issuecomment-2303932537 This would have avoided kdump breakage, and the original motivation of avoiding dracut error spam from missing things is gone now that Fedora is using dracut-ng which has https://github.com/dracut-ng/dracut-ng/commit/d73cc24e112c01aa701a96a7b8a58adce78409e7 (cherry picked from commit 0da319f566f1eb6bc34269914d766b028e2ef376) --- tier-0/initramfs.yaml | 6 +++--- tier-1/initramfs-full.yaml | 2 +- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/tier-0/initramfs.yaml b/tier-0/initramfs.yaml index de65333..353524c 100644 --- a/tier-0/initramfs.yaml +++ b/tier-0/initramfs.yaml @@ -6,13 +6,13 @@ postprocess: cat > /usr/lib/dracut/dracut.conf.d/20-bootc-base.conf << 'EOF' # We want a generic image; hostonly makes no sense as part of a server side build hostonly=no - dracutmodules+=" kernel-modules dracut-systemd systemd-initrd base ostree " + add_dracutmodules+=" kernel-modules dracut-systemd systemd-initrd base ostree " EOF cat > /usr/lib/dracut/dracut.conf.d/22-bootc-generic.conf << 'EOF' # Extra modules that we want by default that are known to exist in the kernel - dracutmodules+=" virtiofs " + add_dracutmodules+=" virtiofs " EOF cat > /usr/lib/dracut/dracut.conf.d/49-bootc-tpm2-tss.conf << 'EOF' # We want this for systemd-cryptsetup tpm2 locking - dracutmodules+=" tpm2-tss " + add_dracutmodules+=" tpm2-tss " EOF diff --git a/tier-1/initramfs-full.yaml b/tier-1/initramfs-full.yaml index 29e91ee..2c55a83 100644 --- a/tier-1/initramfs-full.yaml +++ b/tier-1/initramfs-full.yaml @@ -4,5 +4,5 @@ postprocess: #!/usr/bin/env bash mkdir -p /usr/lib/dracut/dracut.conf.d cat > /usr/lib/dracut/dracut.conf.d/30-bootc-tier-1.conf << 'EOF' - dracutmodules+=" lvm crypt fips " + add_dracutmodules+=" lvm crypt fips " EOF From 92545d027d6bd96930ad95936be5b06a16657b36 Mon Sep 17 00:00:00 2001 From: Micah Abbott Date: Thu, 29 Aug 2024 09:15:45 -0400 Subject: [PATCH 3/4] tier-0: add systemd-cryptsetup to initrd dracut modules Fedora 41 appears to require the inclusion of `systemd-cryptsetup` in the initrd in order to unlock LUKS devices at boot. See: #17 Signed-off-by: Micah Abbott (cherry picked from commit 7109132dd61ca65ef0d08e1c7a8b4127d03fd93a) --- tier-0/initramfs.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tier-0/initramfs.yaml b/tier-0/initramfs.yaml index 353524c..95146e2 100644 --- a/tier-0/initramfs.yaml +++ b/tier-0/initramfs.yaml @@ -14,5 +14,5 @@ postprocess: EOF cat > /usr/lib/dracut/dracut.conf.d/49-bootc-tpm2-tss.conf << 'EOF' # We want this for systemd-cryptsetup tpm2 locking - add_dracutmodules+=" tpm2-tss " + add_dracutmodules+=" systemd-cryptsetup tpm2-tss " EOF From e6ebee84748559d272881cf155e49e2f53ca62cb Mon Sep 17 00:00:00 2001 From: Platform Engineering Bot Date: Thu, 5 Jun 2025 09:10:50 +0000 Subject: [PATCH 4/4] chore(deps): update pre-commit hook pre-commit/pre-commit-hooks to v5 Signed-off-by: Platform Engineering Bot --- .pre-commit-config.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 0934aaf..e955059 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -1,7 +1,7 @@ --- repos: - repo: https://github.com/pre-commit/pre-commit-hooks - rev: v4.6.0 + rev: v5.0.0 hooks: - id: end-of-file-fixer - id: trailing-whitespace