Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 0 additions & 2 deletions .github/workflows/run-kola-tests.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -182,7 +182,6 @@ jobs:

PARALLEL_ARCH=5

cat > sdk_container/.env <<EOF
# export the QEMU_IMAGE_NAME to avoid to download it.
export QEMU_IMAGE_NAME="/work/flatcar_production_image.bin"
export QEMU_UEFI_FIRMWARE="/work/flatcar_production_qemu_uefi_efi_code.qcow2"
Expand All @@ -194,7 +193,6 @@ jobs:
# The runner uses lxc containers for kola, and can't use loopback devices to
# prepare the serial console setting - this means that kola may miss some errors
export QEMU_KOLA_SKIP_MANGLE=true
EOF

export MAX_RETRIES=5
export SKIP_COPY_TO_BINCACHE=1
Expand Down
4 changes: 1 addition & 3 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -12,9 +12,7 @@
# Flatcar SDK tarballs
*.tar.bz2

# SDK container env passing helpers
sdk_container/.env
sdk_container/.sdkenv
# SDK container files
ci-cleanup.sh

# build cache / artefacts directories
Expand Down
2 changes: 1 addition & 1 deletion build_packages
Original file line number Diff line number Diff line change
Expand Up @@ -276,7 +276,7 @@ if [[ "${FLAGS_usepkgonly}" -eq "${FLAGS_FALSE}" ]]; then
# dropping USE=pam from sys-apps/systemd requires dropping
# USE=systemd from sys-auth/pambase
# sys-auth/pambase[sssd] -> sys-auth/sssd -> sys-apps/shadow[pam] -> sys-auth/pambase
break_dep_loop sys-apps/util-linux cryptsetup,pam,systemd,udev \
break_dep_loop sys-apps/util-linux cryptsetup,pam,su,systemd,udev \
sys-fs/cryptsetup udev \
sys-fs/lvm2 systemd,udev \
sys-apps/systemd audit,cryptsetup,pam,selinux,tpm \
Expand Down
2 changes: 1 addition & 1 deletion build_sdk_container_image
Original file line number Diff line number Diff line change
Expand Up @@ -229,7 +229,7 @@ else
docker_build -t "${sdk_build_image}" \
--build-arg VERSION="${docker_vernum}" \
--build-arg BINHOST="http://${binhost}" \
--build-arg OFFICIAL="${official}" \
--build-arg COREOS_OFFICIAL="${official}" \
-f sdk_lib/Dockerfile.sdk-build \
.

Expand Down
1 change: 1 addition & 0 deletions changelog/changes/2026-10-02-su.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- Switched from shadow's su implementation to util-linux's, as the former is deprecated upstream.
17 changes: 3 additions & 14 deletions ci-automation/ci-config.env
Original file line number Diff line number Diff line change
Expand Up @@ -40,11 +40,6 @@ CONTAINER_IMAGE_ROOT="/home/sdk/trunk/src/build/images"

# NOTE that these settings are evaluated by the vendor-tests script inside the
# SDK container. To override, new values must be passed into the container.
# Use something like
# echo "export [VAR]=\"${[VALUE]}\\"" > sdk_container/.env
# in your CI to override, e.g.
# echo "export PARALLEL_TESTS=\"5\"" > sdk_container/.env
# to override the number of test cases to be run in parallel.

# -- General --

Expand Down Expand Up @@ -81,10 +76,6 @@ QEMU_DEVCONTAINER_URL="${QEMU_DEVCONTAINER_URL:-}"
QEMU_DEVCONTAINER_BINHOST_URL="${QEMU_DEVCONTAINER_BINHOST_URL:-}"
QEMU_DEVCONTAINER_FILE="${QEMU_DEVCONTAINER_FILE:-}"

# -- PXE --
PXE_KERNEL_NAME="flatcar_production_pxe.vmlinuz"
PXE_IMAGE_NAME="flatcar_production_pxe_image.cpio.gz"

GCE_IMAGE_NAME="flatcar_production_gce.tar.gz"
GCE_GCS_IMAGE_UPLOAD="gs://flatcar-jenkins/developer/gce-ci"
GCE_MACHINE_TYPE="${GCE_MACHINE_TYPE:-n1-standard-2}"
Expand All @@ -99,13 +90,13 @@ GCE_PARALLEL="${PARALLEL_TESTS:-4}"
: ${DIGITALOCEAN_MACHINE_SIZE:='s-2vcpu-2gb'}
DIGITALOCEAN_PARALLEL="${PARALLEL_TESTS:-8}"
# DIGITALOCEAN_TOKEN_JSON env var is used for credentials, and should
# come from sdk_container/.env. It must be base64-encoded.
# come from the caller. It must be base64-encoded.

# -- VMware ESX --

: ${VMWARE_ESX_IMAGE_NAME:='flatcar_production_vmware_ova.ova'}
VMWARE_ESX_PARALLEL="${PARALLEL_TESTS:-4}"
# VMWARE_ESX_CREDS should come from sdk_container/.env and must be
# VMWARE_ESX_CREDS should come from the caller and must be
# base64-encoded.

# -- AWS --
Expand All @@ -122,8 +113,7 @@ VMWARE_ESX_PARALLEL="${PARALLEL_TESTS:-4}"
: ${AWS_REGION:="us-east-1"}
: ${AWS_AMI_ID:=""}
AWS_PARALLEL="${PARALLEL_TESTS:-8}"
# AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY should come from
# sdk_container/.env
# AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY should come from the caller.

# -- Azure --
: ${AZURE_IMAGE_NAME:="flatcar_production_azure_image.vhd"}
Expand All @@ -132,7 +122,6 @@ AWS_PARALLEL="${PARALLEL_TESTS:-8}"
: ${AZURE_USE_GALLERY:=""}
: ${AZURE_KOLA_VNET:=""}
: ${AZURE_USE_PRIVATE_IPS:=true}
: ${AZURE_VNET_SUBNET_NAME:="jenkins-vnet-westeurope"}
AZURE_PARALLEL="${PARALLEL_TESTS:-20}"
AZURE_LOCATION="${AZURE_LOCATION:-westeurope}"

Expand Down
16 changes: 1 addition & 15 deletions ci-automation/garbage_collect.sh
Original file line number Diff line number Diff line change
Expand Up @@ -255,21 +255,7 @@ function _garbage_collect_impl() {

local mantle_ref
mantle_ref=$(cat sdk_container/.repo/manifests/mantle-container)
docker run --pull always --rm --net host \
--env AWS_ACCESS_KEY_ID --env AWS_SECRET_ACCESS_KEY \
--env AWS_CREDENTIALS \
--env DIGITALOCEAN_TOKEN_JSON \
--env GCP_JSON_KEY \
--env VMWARE_ESX_CREDS \
--env BRIGHTBOX_CLIENT_ID --env BRIGHTBOX_CLIENT_SECRET \
--env AKAMAI_TOKEN \
--env STACKIT_SERVICE_ACCOUNT \
--env STACKIT_PROJECT_ID \
--env ORACLECLOUD_TENANCY \
--env ORACLECLOUD_USER \
--env ORACLECLOUD_FINGERPRINT \
--env ORACLECLOUD_PRIVATE_KEY \
--env ORACLECLOUD_COMPARTMENT_ID \
docker run --pull always --rm --net host --env-file="sdk_lib/env_mantle.txt" \
-w /work -v "$PWD":/work "${mantle_ref}" /work/ci-automation/garbage_collect_cloud.sh

echo
Expand Down
6 changes: 3 additions & 3 deletions ci-automation/garbage_collect_cloud.sh
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,14 @@
set -euo pipefail
source ci-automation/ci_automation_common.sh
timeout --signal=SIGQUIT 60m ore aws gc --access-id "${AWS_ACCESS_KEY_ID}" --secret-key "${AWS_SECRET_ACCESS_KEY}"
timeout --signal=SIGQUIT 60m ore gcloud gc --json-key <(echo "${GCP_JSON_KEY}" | base64 --decode)
timeout --signal=SIGQUIT 60m ore gcloud gc --json-key <(base64 --decode <<< "${GCP_JSON_KEY}")
timeout --signal=SIGQUIT 60m ore azure gc --duration 6h
timeout --signal=SIGQUIT 60m ore brightbox gc --duration 6h \
--brightbox-client-id="${BRIGHTBOX_CLIENT_ID}" --brightbox-client-secret="${BRIGHTBOX_CLIENT_SECRET}"
timeout --signal=SIGQUIT 60m ore akamai gc --duration 6h \
--akamai-token="${AKAMAI_TOKEN}"
timeout --signal=SIGQUIT 60m ore stackit gc --duration 6h \
--stackit-service-account-key-path=<(echo "${STACKIT_SERVICE_ACCOUNT}" | base64 --decode) \
--stackit-service-account-key-path=<(base64 --decode <<< "${STACKIT_SERVICE_ACCOUNT}") \
--stackit-project-id="${STACKIT_PROJECT_ID}"
secret_to_file aws_credentials_config_file "${AWS_CREDENTIALS}"
for channel in alpha beta stable lts; do
Expand All @@ -29,5 +29,5 @@ timeout --signal=SIGQUIT 60m ore oraclecloud gc --duration 6h \
--oraclecloud-tenancy="${ORACLECLOUD_TENANCY}" \
--oraclecloud-user="${ORACLECLOUD_USER}" \
--oraclecloud-fingerprint="${ORACLECLOUD_FINGERPRINT}" \
--oraclecloud-private-key="$(echo "${ORACLECLOUD_PRIVATE_KEY}" | base64 --decode)" \
--oraclecloud-private-key="$(base64 --decode <<< "${ORACLECLOUD_PRIVATE_KEY}")" \
--oraclecloud-compartment-id="${ORACLECLOUD_COMPARTMENT_ID}"
8 changes: 2 additions & 6 deletions ci-automation/release.sh
Original file line number Diff line number Diff line change
Expand Up @@ -75,8 +75,6 @@ function _inside_mantle() {
source sdk_lib/sdk_container_common.sh
source ci-automation/ci_automation_common.sh
source sdk_container/.repo/manifests/version.txt
# Needed because we are not the SDK container here
source sdk_container/.env
CHANNEL="$(get_git_channel)"
VERSION="${FLATCAR_VERSION}"
aws_credentials_config_file=""
Expand Down Expand Up @@ -240,8 +238,6 @@ function _release_build_impl() {
source ci-automation/gpg_setup.sh

source sdk_container/.repo/manifests/version.txt
# Needed because we are not the SDK container here
source sdk_container/.env
local sdk_version="${FLATCAR_SDK_VERSION}"
local docker_sdk_vernum=""
docker_sdk_vernum="$(vernum_to_docker_image_version "${sdk_version}")"
Expand All @@ -257,9 +253,9 @@ function _release_build_impl() {
# A job on each worker prunes old mantle images (docker image prune), no need to do it here
echo "docker rm -f '${container_name}'" >> ./ci-cleanup.sh

touch sdk_container/.env # This file should already contain the required credentials as env vars
docker run --pull always --rm --name="${container_name}" --net host \
-w /work -v "$PWD":/work "${mantle_ref}" bash -c "git config --global --add safe.directory /work && source ci-automation/release.sh && _inside_mantle"
-w /work -v "$PWD":/work --env-file="sdk_lib/env_mantle.txt" "${mantle_ref}" \
bash -c "git config --global --add safe.directory /work && source ci-automation/release.sh && _inside_mantle"
# Push flatcar_production_ami_*txt and flatcar_production_ami_*json to the right bincache folder
for arch in amd64 arm64; do
sudo chown -R "$USER:$USER" "aws-${arch}"
Expand Down
10 changes: 5 additions & 5 deletions ci-automation/release/azure_marketplace.sh
Original file line number Diff line number Diff line change
Expand Up @@ -37,17 +37,17 @@ function _release_azure_marketplace_impl() {
# A job on each worker prunes old mantle images (docker image prune), no need to do it here
echo "docker rm -f '${container_name}'" >> ./ci-cleanup.sh

source sdk_container/.env
AZ_STORAGE_KEY=$(secret_from_base64 "AZ_STORAGE_KEY" "${AZ_MARKETPLACE_PUBLISH}")
AZ_TENANT_ID=$(secret_from_base64 "AZ_TENANT_ID" "${AZ_MARKETPLACE_PUBLISH}")
AZ_CLIENT_ID=$(secret_from_base64 "AZ_CLIENT_ID" "${AZ_MARKETPLACE_PUBLISH}")
AZ_SECRET_VALUE=$(secret_from_base64 "AZ_SECRET_VALUE" "${AZ_MARKETPLACE_PUBLISH}")
export AZ_STORAGE_KEY AZ_TENANT_ID AZ_CLIENT_ID AZ_SECRET_VALUE

docker run --pull always --rm --name="${container_name}" --net host \
-e AZ_STORAGE_KEY="${AZ_STORAGE_KEY}" \
-e AZ_TENANT_ID="${AZ_TENANT_ID}" \
-e AZ_CLIENT_ID="${AZ_CLIENT_ID}" \
-e AZ_SECRET_VALUE="${AZ_SECRET_VALUE}" \
-e AZ_STORAGE_KEY \
-e AZ_TENANT_ID \
-e AZ_CLIENT_ID \
-e AZ_SECRET_VALUE \
-v "${PWD}"/ci-automation/release/azure_marketplace_publish.py:/app/azure_marketplace_publish.py \
-w /app \
ghcr.io/flatcar/uv:alpine \
Expand Down
40 changes: 9 additions & 31 deletions ci-automation/test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,7 @@
#
# 3. List of tests / test patterns. Defaults to "*" (all tests).
# All positional arguments after the first 2 (see above) are tests / patterns of tests to run.
# 4. Standard input. Use this to run arbitrary commands inside container before starting the tests.
#
# MAX_RETRIES. Environment variable. Number of re-runs to overcome transient failures. Defaults to 20.
# PARALLEL_TESTS. Environment variable. Number of test cases to run in parallel.
Expand Down Expand Up @@ -72,21 +73,6 @@
# script would need to make anyway. For more information, please refer
# to the vendor_test.sh file.

function __escape_multiple() {
local out_array_arg_name="${1}"; shift
# rest are args to be escape and appended into the array named
# after the first arg
local -n out_array_arg_ref="${out_array_arg_name}"
local arg arg_escaped

out_array_arg_ref=()
for arg; do
printf -v arg_escaped '%q' "${arg}"
out_array_arg_ref+=( "${arg_escaped}" )
done
}
# --

function test_run() {
# Run a subshell, so the traps, environment changes and global
# variables are not spilled into the caller.
Expand Down Expand Up @@ -143,38 +129,30 @@ function _test_run_impl() {
# A job on each worker prunes old mantle images (docker image prune)
echo "docker rm -f '${container_name}'" >> ./ci-cleanup.sh

local image_escaped
printf -v image_escaped '%q' "${image}"
local common_test_args=(
"${work_dir}"
"${tests_dir}"
"${arch}"
"${vernum}"
)
local common_test_args_escaped=()
__escape_multiple common_test_args_escaped "${common_test_args[@]}"

local tests_escaped=()
__escape_multiple tests_escaped "${@}"
local stdin=""
[[ ! -t 0 ]] && stdin=$(< /dev/stdin)

# Vendor tests may need to know if it is a first run or a rerun
touch "${work_dir}/first_run"
for retry in $(seq "${retries}"); do
local tapfile="results-run-${retry}.tap"
local failfile="failed-run-${retry}.txt"
local tapfile_escaped
printf -v tapfile_escaped '%q' "${tapfile}"

# Ignore retcode since tests are flaky. We'll re-run failed tests and
# determine success based on test results (tapfile).
set +e
touch sdk_container/.env
docker run --pull always --rm --name="${container_name}" --privileged --net host -v /dev:/dev \
-w /work -v "$PWD":/work "${MANTLE_REF}" \
bash -c "git config --global --add safe.directory /work && \
source sdk_container/.env && \
ci-automation/vendor-testing/${image_escaped}.sh ${common_test_args_escaped[*]} ${tapfile_escaped} ${tests_escaped[*]}"
set -e
-w /work -v "$PWD":/work --env-file="sdk_lib/env_mantle.txt" -i "${MANTLE_REF}" bash -ec \
'git config --global --add safe.directory /work
source /dev/stdin
ci-automation/vendor-testing/"${1}".sh "${@:2}"' \
-- "${image}" "${common_test_args[@]}" "${tapfile}" "${@}" <<< "${stdin}" || :
rm -f "${work_dir}/first_run"

# Note: git safe.directory is not set in this run as it does not use git
Expand Down Expand Up @@ -208,7 +186,7 @@ function _test_run_impl() {
echo "Failed tests:"
printf '%s\n' "${failed_tests[@]}"
echo "-----------"
__escape_multiple tests_escaped "${failed_tests[@]}"
set -- "${failed_tests[@]}"
done

if ${print_give_up}; then
Expand Down
2 changes: 1 addition & 1 deletion ci-automation/vendor-testing/brightbox.sh
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ if [[ "${CIA_ARCH}" == "arm64" ]]; then
exit 1
fi

# BRIGHTBOX_CLIENT_ID, BRIGHTBOX_CLIENT_SECRET should be provided by sdk_container/.env
# BRIGHTBOX_CLIENT_ID, BRIGHTBOX_CLIENT_SECRET should be provided by the caller.

# Upload the image on Brightbox.
IMAGE_ID=$(ore brightbox create-image \
Expand Down
2 changes: 1 addition & 1 deletion ci-automation/vendor-testing/hetzner.sh
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ hetzner_instance_type="${!hetzner_instance_type_var}"
hetzner_location_var="HETZNER_${CIA_ARCH}_LOCATION"
hetzner_location="${!hetzner_location_var}"

# HETZNER_TPS_TOKEN should be provided by sdk_container/.env
# HETZNER_TPS_TOKEN should be provided by the caller.

# We first need to create a temporary project using HETZNER_TPS_TOKEN
# When the project is created it returns a regular HETZNER_TOKEN that can be used
Expand Down
2 changes: 1 addition & 1 deletion ci-automation/vendor-testing/openstack.sh
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ if [[ "${CIA_ARCH}" == "arm64" ]]; then
exit 1
fi

# OPENSTACK_CREDS, OPENSTACK_USER, OPENSTACK_HOST, OPENSTACK_KEYFILE should be provided by sdk_container/.env
# OPENSTACK_CREDS, OPENSTACK_USER, OPENSTACK_HOST, OPENSTACK_KEYFILE should be provided by the caller.
config_file=''
secret_to_file config_file "${OPENSTACK_CREDS}"

Expand Down
4 changes: 2 additions & 2 deletions ci-automation/vendor-testing/stackit.sh
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ kola_test_basename="ci-${CIA_VERNUM//[+.]/-}"

# Upload the image on STACKIT.
IMAGE_ID=$(ore stackit \
--stackit-service-account-key-path=<(echo "${STACKIT_SERVICE_ACCOUNT}" | base64 --decode) \
--stackit-service-account-key-path=<(base64 --decode <<< "${STACKIT_SERVICE_ACCOUNT}") \
--stackit-project-id="${STACKIT_PROJECT_ID}" \
create-image \
--board "${CIA_ARCH}-usr" \
Expand All @@ -39,7 +39,7 @@ timeout --signal=SIGQUIT 2h kola run \
--channel="${CIA_CHANNEL}" \
--basename="${kola_test_basename}" \
--platform=stackit \
--stackit-service-account-key-path=<(echo "${STACKIT_SERVICE_ACCOUNT}" | base64 --decode) \
--stackit-service-account-key-path=<(base64 --decode <<< "${STACKIT_SERVICE_ACCOUNT}") \
--stackit-project-id="${STACKIT_PROJECT_ID}" \
--stackit-image-id="${IMAGE_ID}" \
--stackit-type="${stackit_instance_type}" \
Expand Down
26 changes: 0 additions & 26 deletions common.sh
Original file line number Diff line number Diff line change
Expand Up @@ -256,32 +256,6 @@ get_gclient_root() {
fi
}

# Populate the ENVIRONMENT_ALLOWLIST array.
load_environment_allowlist() {
ENVIRONMENT_ALLOWLIST=(
COREOS_OFFICIAL
FLATCAR_BUILD_ID
FORCE_STAGES
GIT_AUTHOR_EMAIL
GIT_AUTHOR_NAME
GIT_COMMITTER_EMAIL
GIT_COMMITTER_NAME
GIT_PROXY_COMMAND
GIT_SSH
RSYNC_PROXY
GNUPGHOME
GPG_AGENT_INFO
SSH_AGENT_PID
SSH_AUTH_SOCK
USE
all_proxy
ftp_proxy
http_proxy
https_proxy
no_proxy
)
}

load_environment_var() {
local file="$1"; shift
unset "${@}"
Expand Down
Loading
Loading