No description
Find a file
Tomas Hozza bce603586e image-info: changes related to reading SELinux labels unknown to host
When `image-info` inspects ostree images, the `/usr/etc` is bind-mounted
to `/etc`. This results in conflicting SELinux policy specification for
these files and makes the outcome dependent on the `setfiles` build.
All the files in `/etc` have mismatch in the expected vs. actual SELinux
context.

Exclude `/etc` from the check of SELinux ctx mismatches in case the
analysed tree is from an ostree-based image.

Sort the list returned `read_selinux_ctx_mismatch()` based on the item's
`filename` key, to make the result consistent across runs.

`image-info` can not read SELinux labels from the images, which are not
known to the host. This makes the report content depend on the host
environment. As a temporary workaround, relabel the image-info script with
osbuild_exec_t label to allow it to read unknown SELinux labels.

Modify documentation in `test/README.md` to explain the issue with
`image-info` and unknown SELinux labels.

Modify the `generate-all-test-cases` to relabel `image-info` before
generating test cases.

Modify the `image_tests.sh` to relabel `image-info` before running image
test cases.

Add 'tar' image for 'rhel-8' on 's390x' back to the matrix of generated
test cases, as it was removed by mistake. Regenerate the image test
case. Remove 'tar' image from 'rhel-84' on 's390x' from the matrix of
generated test cases, as it is not supported.

Regenerate all affected image test cases.

Signed-off-by: Tomas Hozza <thozza@redhat.com>
2021-06-22 13:25:59 +03:00
.github Disable Shutzbot in favor of GitLab CI 2021-05-31 11:44:37 +02:00
cmd kojiapi: include image type exports in Koji job args 2021-06-18 14:02:09 +01:00
containers/osbuild-composer containers: Specify port for the composer-api as argument 2020-12-23 17:31:29 +01:00
distribution distribution: The composer-api listens on 9196 2021-06-21 17:31:15 +02:00
docs docs/news: add news item for change 2021-06-18 14:02:09 +01:00
image-types image-types: Update RHEL8 Amazon EC2 image information 2021-01-15 17:48:19 +01:00
internal rpm_ostree_stage: Minor fixes to comments 2021-06-21 12:11:09 +02:00
repositories distro: add fedora 34 and 35 aliases to f33 2021-06-05 20:31:45 +02:00
schutzbot CI: Store .repo file as artifacts. Fixes #1458 2021-06-15 11:43:42 +03:00
test image-info: changes related to reading SELinux labels unknown to host 2021-06-22 13:25:59 +03:00
tools image-info: changes related to reading SELinux labels unknown to host 2021-06-22 13:25:59 +03:00
vendor worker: add azure image upload target 2021-03-06 15:40:48 +00:00
.gitignore gitignore: add config and OSX metadata 2021-02-20 14:53:49 +01:00
.gitlab-ci.yml Remove Fedora32 from CI matrix - already EOL 2021-06-21 16:15:53 +03:00
.golangci.yml ci/lint: add integration tag 2020-03-17 20:36:58 +01:00
codecov.yml codevoc: fix threshold 2020-05-17 10:12:06 +02:00
CONTRIBUTING.md rcm: drop sub-package 2020-07-17 19:13:15 +01:00
DEPLOYING.md Add DEPLOYING.md 2020-10-20 15:43:30 +02:00
dnf-json dnf-json: don't initialize dnf plugins 2020-08-23 16:08:25 +02:00
go.mod worker: add azure image upload target 2021-03-06 15:40:48 +00:00
go.sum internal/upload: Add support for upload to GCP and CLI tool using it 2021-02-25 18:44:21 +00:00
HACKING.md HACKING: Typo fixes 2021-02-11 09:37:36 +01:00
krb5.conf upload/koji: add support for GSSAPI/Kerberos auth 2020-08-27 17:29:57 +01:00
LICENSE Revert "Fill in the license template" 2019-11-15 15:26:51 +01:00
Makefile Makefile: build osbuild-upload-gcp as part of build target 2021-03-12 12:17:02 +01:00
NEWS.md 30 2021-06-10 14:59:08 +02:00
osbuild-composer.spec 30 2021-06-10 14:59:08 +02:00
README.md readme: add IRC 2021-06-04 18:19:42 +01:00
Schutzfile schutzfile: remove osbuild pins for Fedora 2021-06-10 14:59:08 +02:00

OSBuild Composer

Operating System Image Composition Services

The composer project is a set of HTTP services for composing operating system images. It builds on the pipeline execution engine of osbuild and defines its own class of images that it supports building.

Multiple APIs are available to access a composer service. This includes support for the lorax-composer API, and as such can serve as drop-in replacement for lorax-composer.

You can control a composer instance either directly via the provided APIs, or through higher-level user-interfaces from external projects. This, for instance, includes a Cockpit Module or using the composer-cli command-line tool.

Project

About

Composer is a middleman between the workhorses from osbuild and the user-interfaces like cockpit-composer, composer-cli, or others. It defines a set of high-level image compositions that it supports building. Builds of these compositions can be requested via the different APIs of Composer, which will then translate the requests into pipeline-descriptions for osbuild. The pipeline output is then either provided back to the user, or uploaded to a user specified target.

The following image visualizes the overall architecture of the OSBuild infrastructure and the place that Composer takes:

overview

Consult the osbuild-composer(7) man-page for an introduction into composer, information on running your own composer instance, as well as details on the provided infrastructure and services.

Requirements

The requirements for this project are:

  • osbuild >= 26
  • systemd >= 244

At build-time, the following software is required:

  • go >= 1.14
  • python-docutils >= 0.13

Build

The standard go package system is used. Consult upstream documentation for detailed help. In most situations the following commands are sufficient to build and install from source:

mkdir build
go build -o build ./...

The man-pages require python-docutils and can be built via:

make man

Repository:

Pull request gating

Each pull request against osbuild-composer starts a series of automated tests. Tests run via GitHub Actions and Jenkins. Each push to the pull request will launch theses tests automatically.

Jenkins only tests pull requests from members of the osbuild organization in GitHub. A member of the osbuild organization must say ok to test in a pull request comment to approve testing. Anyone can ask for testing to run by saying the bot's favorite word, schutzbot, in a pull request comment. Testing will begin shortly after the comment is posted.

Test results in Jenkins are available by clicking the Details link on the right side of the Schutzbot check in the pull request page.

License:

  • Apache-2.0
  • See LICENSE file for details.