Compare commits

...
Sign in to create a new pull request.

28 commits

Author SHA1 Message Date
Paul Whalen
87eaa6a42b Update gpgkey path in fedora-46.repo, drop unused fedora-45.repo
Update gpgkey path in fedora-46.repo from /etc/pki/rpm-gpg/ to
/usr/share/pki/rpm-gpg/ for the F45 GPG key relocation.

See: https://discussion.fedoraproject.org/t/f45-change-proposal-relocate-rpm-repo-configs-to-usr-selfcontained/188916

Remove fedora-45.repo from main (rawhide) - it belongs on f45-branch.

Assisted-by: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2026-08-17 14:41:53 -04:00
Paul Whalen
f570c87de9 Bump rawhide to Fedora 46 2026-08-12 10:17:54 -04:00
Paul Whalen
63d2e9c3f5 Update workstation-ostree-config references to Forge
- bootupd.yaml: Update comment URL to atomic-desktops/config on Forge
- treecompose-post.sh: Update comment URL to atomic-desktops/config on Forge

Assisted-by: Claude Opus 4.6 <noreply@anthropic.com>
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2026-07-28 16:15:56 -04:00
Kenneth Giusti
3738d4889f
fix: use kmscon as default VT console
The kernel console fbcon has been replaced with the userspace console
kmscon in Fedora 45.

See: https://github.com/fedora-iot/iot-distro/issues/137

Signed-off-by: Kenneth Giusti <kgiusti@redhat.com>
2026-06-15 12:56:47 -04:00
ce42103746
Remove ignition package
Since [1], the ignition-edge subpackage requires ignition, so it's no
longer needed to require ignition explicitly here.

[1] https://src.fedoraproject.org/rpms/ignition/c/3ccce9fe2c0462f4a17923937933ab9c26db0aa5?branch=rawhide
2026-03-12 09:46:51 +01:00
Paul Whalen
e49d841a84 fix: drop sshd-authorized-keys workaround
Openssh config snippet now shipped with ignition.

See: https://src.fedoraproject.org/rpms/ignition/pull-request/143

Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2026-02-26 15:07:19 -05:00
Paul Whalen
1b3ede31d9 fix: use 90- prefix for authorized-keys-file.conf
Updates the config file numbering to ensure crypto policies(40)
and security configs(50) are applied before user keys are sourced.

Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2026-02-24 17:04:31 -05:00
Paul Whalen
7a121ed5e7 fix: do not create etc/ssh/sshd_config.d
Do not create etc/ssh/sshd_config.d, it should already exist and is
owned by openssh-clients and systemd.

Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2026-02-24 15:52:24 -05:00
Paul Whalen
e0898e8a38 fix: restore SSH key management for Ignition
Configures OpenSSH to read keys from ~/.ssh/authorized_keys.d/* in
addition to authorized_keys, restoring functionality lost when
ssh-key-dir was removed.

Follows the same approach as CoreOS:
https://github.com/coreos/fedora-coreos-config/pull/3885

Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2026-02-24 15:36:39 -05:00
Paul Whalen
240bff70e7 fix: add systemd-pam to fix rootless podman
In Fedora 44 systemd changed systemd-pam to recommends and it
was dropped from the compose.

See: https://github.com/fedora-iot/iot-distro/issues/127

Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2026-02-10 15:44:02 -05:00
Paul Whalen
dccd3a2e18 IoT: Update rawhide for F-45
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2026-02-06 11:22:08 -05:00
Paul Whalen
fc7be03512 fix: drop ssh-key-dir
Package has been deprecated in F44.

See: https://github.com/coreos/ssh-key-dir/issues/188

Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2026-02-04 11:07:52 -05:00
Paul Whalen
cc96761b13 IoT: Update rawhide for F-44
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2025-08-11 14:25:38 -04:00
Paul Whalen
c7f2ffe7cb Default root config to mount sysroot as read only
See: https://github.com/fedora-iot/iot-distro/issues/81
     https://gitlab.com/fedora/bootc/base-images/-/blob/main/tier-0/ostree.yaml

Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2025-03-17 13:19:32 -04:00
465d88c040 Add a justfile with common commands 2025-03-07 13:50:20 +01:00
ce81f37ea5 ci: Add a script to help validate manifest syntax 2025-03-07 13:50:20 +01:00
e4bd292f1a Whitespace & indentation cleanup 2025-03-07 13:50:19 +01:00
6b92bbcbbc Remove fedora-bootc-base
Now moved to https://github.com/fedora-iot/fedora-iot-bootc
2025-03-07 13:50:10 +01:00
Paul Whalen
2fda060e85 Remove grub2-workaround
Remove grub2-workaround, bug has been fixed.

See: https://bugzilla.redhat.com/show_bug.cgi?id=2305291

Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2025-03-06 14:02:39 -05:00
6529ca201d iot: drop kernel-tools
It too should be layered, not included in the base image.

Signed-off-by: Peter Robinson <pbrobinson@gmail.com>
2025-02-28 17:09:28 +00:00
Paul Whalen
c739a8c05a Enable composefs by default
See: https://pagure.io/workstation-ostree-config/pull-request/591
     https://fedoraproject.org/wiki/Changes/ComposefsAtomicCoreOSIoT
     https://fedoraproject.org/wiki/Changes/ComposefsAtomicDesktops

Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2025-02-27 11:02:20 -05:00
Paul Whalen
a6e7212b56 Migrate systems to a static GRUB config
See: https://pagure.io/workstation-ostree-config/pull-request/591
     https://fedoraproject.org/wiki/Changes/ComposefsAtomicCoreOSIoT
     https://fedoraproject.org/wiki/Changes/ComposefsAtomicDesktops

Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2025-02-27 10:58:35 -05:00
Paul Whalen
b3fd2930a9 Disable ima in ostree due to ongoing compose issues
See: https://bugzilla.redhat.com/show_bug.cgi?id=2346265

Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2025-02-24 10:43:18 -05:00
ce25ead8e5 drop policycoreutils-python-utils in base
The policycoreutils-python-utils pulls in a bunch of extra
SELinux utils which aren't used in day to day, it pulls in
a bunch of python packages, it can easily be layered and
isn't generally needed.

Signed-off-by: Peter Robinson <pbrobinson@gmail.com>
2025-02-19 15:34:27 +00:00
Paul Whalen
17d9d31eb8 Drop parsec no longer supported upstream
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2025-02-19 15:17:54 +00:00
Paul Whalen
b799fe0c9d Remove Zezere and enable systemd-firstboot
Remove Zezere and enable systemd-firstboot for local configuration.

See: https://fedoraproject.org/wiki/Changes/Retire_Zezere

Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2025-02-19 15:17:42 +00:00
625d763195 Replace basesystem with filesystem
See https://src.fedoraproject.org/rpms/filesystem/c/3f741bf2a89c9e1bb685943c41fd298e6683dd50?branch=rawhide

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2025-02-07 09:34:26 -08:00
Paul Whalen
d6ec8e0b0e IoT: Update rawhide for F-43
Signed-off-by: Paul Whalen <pwhalen@fedoraproject.org>
2025-02-04 15:29:24 -05:00
23 changed files with 272 additions and 440 deletions

View file

@ -1,7 +1,7 @@
# KEEP THIS IN SYNC WITH https://github.com/coreos/fedora-coreos-config/blob/testing-devel/manifests/bootupd.yaml
# See also: https://pagure.io/workstation-ostree-config/blob/main/f/bootupd.yaml
# See also: https://forge.fedoraproject.org/atomic-desktops/config/src/branch/main/bootupd.yaml
#
#Integration with https://github.com/coreos/bootupd
# Integration with https://github.com/coreos/bootupd
packages:
- bootupd
@ -9,24 +9,18 @@ postprocess:
- |
#!/bin/bash
set -xeuo pipefail
# Transforms /usr/lib/ostree-boot into a bootupd-compatible update payload
/usr/bin/bootupctl backend generate-update-metadata
# Trigger a bootloader update on boot
cat > /usr/lib/systemd/system/bootloader-update.service << 'EOF'
[Unit]
Description=Update bootloader on boot
Documentation=https://github.com/coreos/bootupd
ConditionFirmware=uefi
# Enable migration to a static GRUB config
install -dm0755 /usr/lib/systemd/system/bootloader-update.service.d
cat > /usr/lib/systemd/system/bootloader-update.service.d/migrate-static-grub-config.conf << 'EOF'
[Service]
Type=oneshot
ExecStart=/usr/bin/bootupctl update
RemainAfterExit=yes
MountFlags=slave
[Install]
WantedBy=multi-user.target
ExecStart=/usr/bin/bootupctl migrate-static-grub-config
EOF
chmod 644 /usr/lib/systemd/system/bootloader-update.service
echo "enable bootloader-update.service" > /usr/lib/systemd/system-preset/81-iot.preset
echo "enable bootloader-update.service" >> /usr/lib/systemd/system-preset/80-iot.preset
# Turn permissive mode on for bootupd until all SELinux issues are fixed
semanage permissive --noreload --add bootupd_t

57
ci/validate Executable file
View file

@ -0,0 +1,57 @@
#!/usr/bin/python3
# Validate basic syntax of shell script and yaml.
import os
import stat
import subprocess
import yaml
validated=0
def openat(dirfd, name, mode='r'):
def opener(path, flags):
return os.open(path, flags, dir_fd=dirfd)
return open(name, mode, opener=opener)
def validate_shell(rootfd, name):
subprocess.check_call(['bash', '-n', name], preexec_fn=lambda: os.fchdir(rootfd))
global validated
validated +=1
for root, dirs, files, rootfd in os.fwalk('.'):
# Skip folders that do not include content to validate
for d in ['.git', '.github', 'repo', 'cache', 'tmp', 'logs', 'fedora-comps']:
if d in dirs:
dirs.remove(d)
for f in ['.gitlab-ci.yml']:
if f in files:
files.remove(f)
for name in files:
if name.endswith(('.yaml', '.yml')):
print("Validating:", name)
with open(os.open(name, dir_fd=rootfd, flags=os.O_RDONLY)) as f:
yaml.safe_load(f)
result = subprocess.run(['grep', '-RniEv', '^( )*[a-z#/-]|^( )*\\[|^$|^#', name], encoding='UTF-8',
preexec_fn=lambda: os.fchdir(rootfd))
if result.returncode == 0:
raise Exception("Found likely invalid indentation in YAML file: {}".format(name))
validated +=1
continue
elif name.endswith('.sh'):
print("Validating:", name)
validate_shell(rootfd, name)
continue
stbuf = os.lstat(name, dir_fd=rootfd)
if not stat.S_ISREG(stbuf.st_mode):
continue
if not stbuf.st_mode & stat.S_IXUSR:
continue
mimetype = subprocess.check_output(['file', '-b', '--mime-type', name], encoding='UTF-8',
preexec_fn=lambda: os.fchdir(rootfd)).strip()
if mimetype == 'text/x-shellscript':
print("Validating:", name)
validate_shell(rootfd, name)
print(f"Validated {validated} files")

12
composefs.yaml Normal file
View file

@ -0,0 +1,12 @@
# Enable composefs
# See: https://fedoraproject.org/wiki/Changes/ComposefsAtomicDesktops
# https://fedoraproject.org/wiki/Changes/ComposefsAtomicCoreOSIoT
postprocess:
- |
#!/usr/bin/env bash
set -xeuo pipefail
cat >> /usr/lib/ostree/prepare-root.conf << 'EOF'
[composefs]
enabled = yes
EOF

View file

@ -10,7 +10,7 @@ os_pretty_name = Fedora IoT
tree_name = docker-host
tree_file = %(os_name)s-%(tree_name)s.json
arch = x86_64
release = f42
release = f46
ref = %(os_name)s/rawhide/%(arch)s/%(tree_name)s
yum_baseurl = http://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/%(arch)s/os/
# lorax_additional_repos = http://127.0.0.1/fedora-iot/local-overrides

View file

@ -1,12 +1,12 @@
[fedora-42]
name=Fedora 42 - $basearch
[fedora-46]
name=Fedora 46 - $basearch
failovermethod=priority
#baseurl=http://download.fedoraproject.org/pub/fedora/linux/releases/42/Everything/$basearch/os/
metalink=https://mirrors.fedoraproject.org/metalink?repo=fedora-42&arch=$basearch
#baseurl=http://download.fedoraproject.org/pub/fedora/linux/releases/46/Everything/$basearch/os/
metalink=https://mirrors.fedoraproject.org/metalink?repo=fedora-46&arch=$basearch
enabled=1
#metadata_expire=7d
repo_gpgcheck=0
type=rpm
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-42-$basearch
gpgkey=file:///usr/share/pki/rpm-gpg/RPM-GPG-KEY-fedora-46-$basearch
skip_if_unavailable=False

View file

@ -1,29 +0,0 @@
# Fix general bugs
postprocess:
# See also https://github.com/openshift/os/blob/f6cde963ee140c02364674db378b2bc4ac42675b/common.yaml#L156
# This one is undoes the effect of
# # RHEL-only: Disable /tmp on tmpfs.
#Wants=tmp.mount
# in /usr/lib/systemd/system/basic.target
# We absolutely must have tmpfs-on-tmp for multiple reasons,
# but the biggest is that when we have composefs for / it's read-only,
# and for units with ProtectSystem=full systemd clones / but needs
# a writable place.
- |
#!/usr/bin/env bash
set -xeuo pipefail
mkdir -p /usr/lib/systemd/system/local-fs.target.wants
if test '!' -f /usr/lib/systemd/system/local-fs.target.wants/tmp.mount; then
ln -sf ../tmp.mount /usr/lib/systemd/system/local-fs.target.wants
fi
# See https://github.com/containers/bootc/issues/358
# basically systemd-tmpfiles doesn't follow symlinks; ordinarily our
# tmpfiles.d unit for `/var/roothome` is fine, but this actually doesn't
# work if we want to use tmpfiles.d to write to `/root/.ssh` because
# tmpfiles gives up on that before getting to `/var/roothome`.
sed -ie 's, /root, /var/roothome,' /usr/lib/tmpfiles.d/provision.conf
# Because /var/roothome is also defined in rpm-ostree-0-integration.conf
# we need to delete /var/roothome
sed -ie '/^d- \/var\/roothome /d' /usr/lib/tmpfiles.d/provision.conf

View file

@ -1,16 +0,0 @@
# The bootc components.
packages:
- systemd
- bootc
# bootc pulls in podman, which pulls in containers-common, which wants
# `iptables`. Currently that pulls in iptables-legacy. Let's explicitly name
# iptables-nft instead to satisfy it.
- iptables-nft
# Required by bootc install today, though we'll likely switch bootc to use a Rust crate instead of sgdisk
- gdisk xfsprogs e2fsprogs dosfstools
exclude-packages:
# Exclude kernel-debug-core to make sure that it doesn't somehow get
# chosen as the package to satisfy the `kernel-core` dependency from
# the kernel package.
- kernel-debug-core

View file

@ -1,31 +0,0 @@
# Integration with https://github.com/coreos/bootupd and bootloader logic
# xref https://github.com/coreos/fedora-coreos-tracker/issues/510
packages:
- bootupd
# bootloader
packages-aarch64:
- grub2-efi-aa64 efibootmgr shim
packages-ppc64le:
- grub2 ostree-grub2
packages-s390x:
# On Fedora, this is provided by s390utils-core. on RHEL, this is for now
# provided by s390utils-base, but soon will be -core too.
- /usr/sbin/zipl
packages-x86_64:
- grub2-efi-x64 efibootmgr shim
- microcode_ctl
conditional-include:
- if: basearch != "s390x"
# And remove some cruft from grub2
include: grub2-removals.yaml
postprocess:
- |
#!/bin/bash
set -xeuo pipefail
# Until we have https://github.com/coreos/rpm-ostree/pull/2275
mkdir -p /run
# Transforms /usr/lib/ostree-boot into a bootupd-compatible update payload
/usr/bin/bootupctl backend generate-update-metadata

View file

@ -1,46 +0,0 @@
root:x:0:
bin:x:1:
daemon:x:2:
sys:x:3:
adm:x:4:
tty:x:5:
disk:x:6:
lp:x:7:
mem:x:8:
kmem:x:9:
wheel:x:10:
cdrom:x:11:
mail:x:12:
man:x:15:
sudo:x:16:
dialout:x:18:
floppy:x:19:
games:x:20:
tape:x:33:
video:x:39:
ftp:x:50:
lock:x:54:
audio:x:63:
nobody:x:99:
users:x:100:
ssh_keys:x:999:
systemd-journal:x:190:
polkitd:x:998:
etcd:x:997:
dip:x:40:
cgred:x:996:
avahi-autoipd:x:170:
sssd:x:993:
dockerroot:x:986:
rpcuser:x:29:
nfsnobody:x:65534:
kube:x:994:
chrony:x:992:
tcpdump:x:72:
ceph:x:167:
input:x:104:
systemd-timesync:x:991:
systemd-network:x:990:
systemd-resolve:x:989:
systemd-bus-proxy:x:988:
cockpit-ws:x:987:

View file

@ -1,8 +0,0 @@
remove-from-packages:
# The grub bits are mainly designed for desktops, and IMO haven't seen
# enough testing in concert with ostree. At some point we'll flesh out
# the full plan in https://github.com/coreos/fedora-coreos-tracker/issues/47
- [grub2-tools, /etc/grub.d/08_fallback_counting,
/etc/grub.d/10_reset_boot_success,
/etc/grub.d/12_menu_auto_hide,
/usr/lib/systemd/.*]

View file

@ -1,24 +0,0 @@
# Configuration for the initramfs
postprocess:
- |
#!/usr/bin/env bash
mkdir -p /usr/lib/dracut/dracut.conf.d
cat > /usr/lib/dracut/dracut.conf.d/20-bootc-base.conf << 'EOF'
# We want a generic image; hostonly makes no sense as part of a server side build
hostonly=no
add_dracutmodules+=" kernel-modules dracut-systemd systemd-initrd base ostree "
EOF
cat > /usr/lib/dracut/dracut.conf.d/22-bootc-generic.conf << 'EOF'
# Extra modules that we want by default that are known to exist in the kernel
add_dracutmodules+=" virtiofs "
EOF
cat > /usr/lib/dracut/dracut.conf.d/49-bootc-tpm2-tss.conf << 'EOF'
# We want this for systemd-cryptsetup tpm2 locking
add_dracutmodules+=" tpm2-tss "
EOF
cat > /usr/lib/dracut/dracut.conf.d/59-altfiles.conf << 'EOF'
# https://issues.redhat.com/browse/RHEL-49590
# On image mode systems we use nss-altfiles for passwd and group,
# this makes sure dracut uses them which also fixes kdump writing to NFS.
install_items+=" /usr/lib/passwd /usr/lib/group "
EOF

View file

@ -1,100 +0,0 @@
# Fedora IoT specific packages
packages:
- fedora-release-iot
- aardvark-dns
- atheros-firmware
- attr
- authselect
- basesystem
- bash
- bash-completion
- brcmfmac-firmware
- chrony
- clevis
- clevis-dracut
- clevis-luks
- clevis-pin-tpm2
- containernetworking-plugins
- coreutils
- cracklib-dicts
- criu
- criu-libs
- cryptsetup
- curl
- dbus-parsec
- dnf5-plugins
- dracut-config-generic
- dracut-network
- efibootmgr
- fdo-client
- firewalld
- fwupd
- fwupd-efi
- fwupd-plugin-modem-manager
- fwupd-plugin-uefi-capsule-data
- glibc
- glibc-minimal-langpack
- gnupg2
- greenboot
- greenboot-default-health-checks
- gzip
- hostname
- ignition
- ima-evm-utils
- iproute
- iputils
- iwd
- iwlwifi-mvm-firmware
- kernel-tools
- keyutils
- less
- libsss_sudo
- linux-firmware
- lvm2
- netavark
- NetworkManager
- NetworkManager-wifi
- NetworkManager-wwan
- nss-altfiles
- openssl
- openssh-clients
- openssh-server
- passt
- passt-selinux
- parsec
- pinentry
- podman
- policycoreutils
- policycoreutils-python-utils
- polkit
- procps-ng
- realtek-firmware
- rootfiles
- rpm
- screen
- setools-console
- setup
- shadow-utils
- skopeo
- slirp4netns
- sssd-client
- sudo
- systemd-resolved
- tar
- tmux
- tpm2-pkcs11
- traceroute
- usbguard
- util-linux
- vim-minimal
- wpa_supplicant
- wireless-regdb
- xz
- zezere-ignition
- zram-generator
- zram-generator-defaults
packages-aarch64:
- arm-image-installer
- bcm283x-firmware
- optee_client
- uboot-images-armv8

View file

@ -1,6 +0,0 @@
# Enable the Linux kernel; see also kernel-rt.
packages:
- kernel
exclude-packages:
- kernel-debug

View file

@ -1,65 +0,0 @@
# Modern defaults we want
boot-location: modules
tmp-is-dir: true
# https://github.com/CentOS/centos-bootc/issues/167
machineid-compat: true
# Be minimal
recommends: false
ignore-removed-users:
- root
ignore-removed-groups:
- root
etc-group-members:
- wheel
- sudo
- systemd-journal
- adm
# Default to `bash` in our container, the same as other containers we ship.
container-cmd:
- /sbin/init
# Note that the default for c9s+ is sqlite; we can't rely on rpm being
# in the target (it isn't in tier-0!) so turn this to host here. This
# does break the "hermetic build" aspect a bit. Maybe eventually
# what we should do is special case this and actually install RPM temporarily
# and then remove it...
rpmdb: host
check-passwd:
type: "file"
filename: "passwd"
check-groups:
type: "file"
filename: "group"
automatic-version-prefix: "${releasever}.<date:%Y%m%d>"
mutate-os-release: "${releasever}"
remove-from-packages:
# Generally we expect other tools to do this (e.g. Ignition or cloud-init)
- [systemd, /usr/lib/systemd/system/sysinit.target.wants/systemd-firstboot.service]
# We don't want auto-generated mount units. See also
# https://github.com/systemd/systemd/issues/13099
- [systemd-udev, /usr/lib/systemd/system-generators/systemd-gpt-auto-generator]
include:
- bootc.yaml
- bootupd.yaml
- ostree.yaml
- initramfs.yaml
- basic-fixes.yaml
- iot.yaml
packages:
# needed for building derived container images
- dnf5
# Even in tier-0, we have this. If you don't want SELinux today, you'll need
# to build a custom image.
- selinux-policy-targeted
# And we want container-selinux because trying to layer it on later currently causes issues.
- container-selinux
# Needed for tpm2 bound luks
- tpm2-tools

View file

@ -1,17 +0,0 @@
packages:
- ostree nss-altfiles
# We want content lifecycled with the image
opt-usrlocal: "root"
postprocess:
# Set up default root config
- |
#!/usr/bin/env bash
mkdir -p /usr/lib/ostree
cat > /usr/lib/ostree/prepare-root.conf << EOF
[composefs]
enabled = yes
[sysroot]
readonly = true
EOF

View file

@ -1,32 +0,0 @@
adm:x:3:4:adm:/var/adm:/usr/sbin/nologin
avahi-autoipd:x:170:170:Avahi IPv4LL Stack:/var/lib/avahi-autoipd:/usr/sbin/nologin
bin:x:1:1:bin:/bin:/usr/sbin/nologin
ceph:x:167:167:Ceph daemons:/var/lib/ceph:/usr/sbin/nologin
chrony:x:994:992::/var/lib/chrony:/usr/sbin/nologin
cockpit-ws:x:988:987:User for cockpit-ws:/:/usr/sbin/nologin
daemon:x:2:2:daemon:/sbin:/usr/sbin/nologin
dbus:x:81:81:System Message Bus:/:/usr/sbin/nologin
dockerroot:x:997:986:Docker User:/var/lib/docker:/usr/sbin/nologin
etcd:x:998:997:etcd user:/var/lib/etcd:/usr/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/usr/sbin/nologin
games:x:12:100:games:/usr/games:/usr/sbin/nologin
halt:x:7:0:halt:/sbin:/sbin/halt
kube:x:996:994:Kubernetes user:/:/usr/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:12:mail:/var/spool/mail:/usr/sbin/nologin
nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/usr/sbin/nologin
nobody:x:99:99:Kernel Overflow User:/:/usr/sbin/nologin
operator:x:11:0:operator:/root:/usr/sbin/nologin
polkitd:x:999:998:User for polkitd:/:/usr/sbin/nologin
root:x:0:0:Super User:/root:/bin/bash
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/usr/sbin/nologin
rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/usr/sbin/nologin
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/usr/sbin/nologin
sssd:x:995:993:User for sssd:/:/usr/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
systemd-bus-proxy:x:989:988:systemd Bus Proxy:/:/usr/sbin/nologin
systemd-network:x:991:990:systemd Network Management:/:/usr/sbin/nologin
systemd-resolve:x:990:989:systemd Resolver:/:/usr/sbin/nologin
systemd-timesync:x:993:991:systemd Time Synchronization:/:/usr/sbin/nologin
tcpdump:x:72:72::/:/usr/sbin/nologin

View file

@ -1,16 +1,17 @@
include:
include:
- bootupd.yaml
# Workaround for https://bugzilla.redhat.com/show_bug.cgi?id=2305291
- grub2-workaround.yaml
# Enable composefs
- composefs.yaml
# Read only sysroot
- sysroot-ro.yaml
ref: fedora/rawhide/${basearch}/iot
repos: []
selinux: true
ima: true
tmp-is-dir: true
recommends: false
documentation: false
automatic_version_prefix: '42'
mutate-os-release: '42'
automatic_version_prefix: '46'
mutate-os-release: '46'
initramfs-args:
- "--no-hostonly"
- "--add"
@ -82,7 +83,6 @@ packages:
- atheros-firmware
- attr
- authselect
- basesystem
- bash
- bash-completion
- bootc
@ -100,7 +100,6 @@ packages:
- criu-libs
- cryptsetup
- curl
- dbus-parsec
- dnf5
- dnf5-plugins
- dosfstools
@ -110,6 +109,7 @@ packages:
- efibootmgr
- fdo-client
- fdo-owner-cli
- filesystem
- firewalld
- fwupd
- fwupd-efi
@ -122,7 +122,6 @@ packages:
- greenboot-default-health-checks
- gzip
- hostname
- ignition
- ignition-edge
- ima-evm-utils
- iproute
@ -130,8 +129,8 @@ packages:
- iwd
- iwlwifi-mvm-firmware
- kernel
- kernel-tools
- keyutils
- kmscon
- less
- libsss_sudo
- linux-firmware
@ -146,11 +145,9 @@ packages:
- openssh-server
- passt
- passt-selinux
- parsec
- pinentry
- podman
- policycoreutils
- policycoreutils-python-utils
- polkit
- procps-ng
- realtek-firmware
@ -163,10 +160,10 @@ packages:
- shadow-utils
- skopeo
- slirp4netns
- ssh-key-dir
- sssd-client
- sudo
- systemd
- systemd-pam
- systemd-resolved
- tar
- tmux
@ -179,7 +176,6 @@ packages:
- wireless-regdb
- xfsprogs
- xz
- zezere-ignition
- zram-generator
- zram-generator-defaults
packages-aarch64:
@ -200,13 +196,10 @@ units:
- fedora-iot-config-remote-fix.service
- firewalld.service
- sshd.service
- systemd-firstboot.service
- greenboot-grub2-set-counter.service
- greenboot-grub2-set-success.service
- greenboot-healthcheck.service
- greenboot-rpm-ostree-grub2-check-fallback.service
- greenboot-status.service
- greenboot-task-runner.service
- parsec.service
- dbus-parsec.service
- zezere_ignition.timer
- zezere_ignition_banner.service

View file

@ -1,4 +1,5 @@
include: fedora-iot-base.yaml
ref: fedora/rawhide/${basearch}/iot
repos:
- fedora-42
- fedora-46

View file

@ -1,22 +0,0 @@
# Temporarily disable new GRUB2 config options until we can ensure that we
# have an updated bootloader via bootupd.
# This is workaround for: https://bugzilla.redhat.com/show_bug.cgi?id=2305291
# See: https://github.com/fedora-silverblue/issue-tracker/issues/587
postprocess:
- |
#!/usr/bin/env bash
set -xeuo pipefail
# Completely disable this module
sed -i '2i exit 0' /etc/grub.d/25_bli
# Skip check that was not performed in previous Fedora versions
sed -i '/fwsetup --is-supported/d' /etc/grub.d/30_uefi-firmware
sed -i '/\tif/d' /etc/grub.d/30_uefi-firmware
sed -i '/\tfi/d' /etc/grub.d/30_uefi-firmware
sed -i 's/\t\t/\t/' /etc/grub.d/30_uefi-firmware
# Verify that the content matches what we expect the file to look like.
# This will fail the build here instead of breaking users' systems.
hash="5a77a16c6a94e664e2e96a870f4531b9a0b4e63be1f46751d01e774629a8c84b"
echo "$hash /etc/grub.d/30_uefi-firmware" | sha256sum -c

156
justfile Normal file
View file

@ -0,0 +1,156 @@
# This is a justfile. See https://github.com/casey/just
# This is only used for local development. The builds made on the Fedora
# infrastructure are run via Pungi in a Koji runroot.
# Set a default for some recipes
default_variant := "fedora-iot"
default_arch := "default"
# Current default in Pungi
force_nocache := "true"
# Just doesn't have a native dict type, but quoted bash dictionary works fine
pretty_names := '(
[fedora-iot]="IoT"
)'
# Default is to only validate the manifests
all: validate
# Basic validation to make sure the manifests are not completely broken
validate:
./ci/validate
# Output the processed manifest for a given variant (defaults to Silverblue)
manifest variant=default_variant:
#!/bin/bash
set -euo pipefail
rpm-ostree compose tree --print-only --repo=repo {{variant}}.yaml
# Perform dependency resolution for a given variant (defaults to Silverblue)
compose-dry-run variant=default_variant:
#!/bin/bash
set -euxo pipefail
mkdir -p repo cache logs
if [[ ! -f "repo/config" ]]; then
pushd repo > /dev/null || exit 1
ostree init --repo . --mode=bare-user
popd > /dev/null || exit 1
fi
rpm-ostree compose tree --unified-core --repo=repo --dry-run {{variant}}.yaml
# Alias/shortcut for compose-image command
compose variant=default_variant: (compose-image variant)
# Compose a variant using the legacy non container path (defaults to Silverblue)
compose-legacy variant=default_variant:
#!/bin/bash
set -euxo pipefail
declare -A pretty_names={{pretty_names}}
variant={{variant}}
variant_pretty=${pretty_names[$variant]-}
if [[ -z $variant_pretty ]]; then
echo "Unknown variant"
exit 1
fi
./ci/validate > /dev/null || (echo "Failed manifest validation" && exit 1)
mkdir -p repo cache logs
if [[ ! -f "repo/config" ]]; then
pushd repo > /dev/null || exit 1
ostree init --repo . --mode=bare-user
popd > /dev/null || exit 1
fi
# Set option to reduce fsync for transient builds
ostree --repo=repo config set 'core.fsync' 'false'
buildid="$(date '+%Y%m%d.0')"
timestamp="$(date --iso-8601=sec)"
echo "${buildid}" > .buildid
version="$(rpm-ostree compose tree --print-only --repo=repo ${variant}.yaml | jq -r '."mutate-os-release"')"
echo "Composing ${variant_pretty} ${version}.${buildid} ..."
ARGS="--repo=repo --cachedir=cache"
ARGS+=" --unified-core"
if [[ {{force_nocache}} == "true" ]]; then
ARGS+=" --force-nocache"
fi
CMD="rpm-ostree"
if [[ ${EUID} -ne 0 ]]; then
CMD="sudo rpm-ostree"
fi
${CMD} compose tree ${ARGS} \
--add-metadata-string="version=${variant_pretty} ${version}.${buildid}" \
"${variant}.yaml" \
|& tee "logs/${variant}_${version}_${buildid}.${timestamp}.log"
if [[ ${EUID} -ne 0 ]]; then
sudo chown --recursive "$(id --user --name):$(id --group --name)" repo cache
fi
ostree summary --repo=repo --update
# Compose an Ostree Native Container OCI image
compose-image variant=default_variant:
#!/bin/bash
set -euxo pipefail
declare -A pretty_names={{pretty_names}}
variant={{variant}}
variant_pretty=${pretty_names[$variant]-}
if [[ -z $variant_pretty ]]; then
echo "Unknown variant"
exit 1
fi
./ci/validate > /dev/null || (echo "Failed manifest validation" && exit 1)
mkdir -p repo cache
if [[ ! -f "repo/config" ]]; then
pushd repo > /dev/null || exit 1
ostree init --repo . --mode=bare-user
popd > /dev/null || exit 1
fi
# Set option to reduce fsync for transient builds
ostree --repo=repo config set 'core.fsync' 'false'
buildid="$(date '+%Y%m%d.0')"
timestamp="$(date --iso-8601=sec)"
echo "${buildid}" > .buildid
version="$(rpm-ostree compose tree --print-only --repo=repo ${variant}.yaml | jq -r '."mutate-os-release"')"
echo "Composing ${variant_pretty} ${version}.${buildid} ..."
ARGS="--cachedir=cache --initialize"
if [[ {{force_nocache}} == "true" ]]; then
ARGS+=" --force-nocache"
fi
# To debug with gdb, use: gdb --args ...
CMD="rpm-ostree"
if [[ ${EUID} -ne 0 ]]; then
CMD="sudo rpm-ostree"
fi
${CMD} compose image ${ARGS} \
--label="quay.expires-after=4w" \
"${variant}.yaml" \
"${variant}.ociarchive"
# Clean up everything
clean-all:
just clean-repo
just clean-cache
# Only clean the ostree repo
clean-repo:
rm -rf ./repo
# Only clean the package and repo caches
clean-cache:
rm -rf ./cache

15
sysroot-ro.yaml Normal file
View file

@ -0,0 +1,15 @@
# Set up default root config to mount sysroot as read only
# https://fedoraproject.org/wiki/Changes/Silverblue_Kinoite_readonly_sysroot
# See: https://gitlab.com/fedora/bootc/base-images/-/blob/main/tier-0/ostree.yaml
# See: https://github.com/fedora-iot/iot-distro/issues/81
postprocess:
- |
#!/usr/bin/env bash
set -xeuo pipefail
install -dm 0755 -o 0 -g 0 /usr/lib/ostree
cat >> /usr/lib/ostree/prepare-root.conf << 'EOF'
[sysroot]
readonly = true
EOF

View file

@ -18,7 +18,7 @@ done
# Remove loader directory causing issues in Anaconda in unified core mode
# Will be obsolete once we start using bootupd
# See - https://pagure.io/workstation-ostree-config/pull-request/344
# See - https://forge.fedoraproject.org/atomic-desktops/config/pulls/344
rm -rf /usr/lib/ostree-boot/loader
# Undo RPM scripts enabling units; we want the presets to be canonical