Daan De Meyer [Thu, 12 Oct 2023 12:34:12 +0000 (14:34 +0200)]
Run qemu as the invoking user again
This commit also reworks InvokingUser to calculate all its members
on module import (when we haven't yet unshared the user namespace).
become_root() is also changed to modify the InvokingUser object
instead of returning the new uid, gid. Finally, we stop passing
around uid, gid everywhere and just use the InvokingUser object
directly as a singleton.
We also stop dropping privileges in mkosi itself. Instead, we prefer
running ssh, qemu and the embedded web server unprivileged. This
allows us to get rid of the logic to not unmount the last tools tree
as we will now always still have enough privileges to do so.
We also start passing file descriptors to swtpm and virtiofsd to avoid
race conditions where the socket hasn't been created yet before we
pass it to qemu or before we try to chown it.
Daan De Meyer [Fri, 13 Oct 2023 07:54:39 +0000 (09:54 +0200)]
Add WithRecommends=
While this can already be configured using dropins. The concept of
recommended packages seems widespread enough that we can provide an
option to enable/disable it via the configuration file.
Do not remount build root as ro in build chroot
The PR #1970 added an additional volatile overlay to the buildroot, which
currently can only be used from the host, i.e. without mkosi-chroot.
Once mkosi-chroot is run, the build overlay is readonly again.
Fixes https://github.com/systemd/mkosi/issues/1974.
Daan De Meyer [Wed, 11 Oct 2023 11:33:00 +0000 (13:33 +0200)]
Mount volatile overlay when running build scripts
When building multiple projects, it might be needed to make the
header files produced by an earlier build available to later builds.
Let's make this possible by not making the root directory read-only
but instead mounting a writable overlay on top of it so that all
changes made while running the build scripts are thrown away at the
end.
Daan De Meyer [Wed, 11 Oct 2023 09:27:30 +0000 (11:27 +0200)]
Run scripts with ".chroot" extension inside the image
Our current approach to running scripts inside the image is only
really applicable to shell scripts. Let's make it easier to run
scripts written in arbitrary languages inside the image by running
scripts with the ".chroot" extension inside the image.
Daan De Meyer [Tue, 10 Oct 2023 09:48:01 +0000 (11:48 +0200)]
Add RHEL support
To make RHEL work, we have to look up the necessary certificates and
add them to the generated repo files. This requires the image build to
be done from a system with a RHEL subscription.
Daan De Meyer [Tue, 10 Oct 2023 12:02:46 +0000 (14:02 +0200)]
Get rid of config_default_mirror()
The only advantage of having it in the config object is that we can
show it in the summary. If we're fine with just showing "default"
instead, we can inline the default mirror into the installer classes,
which is important for the next commit.
Daan De Meyer [Wed, 4 Oct 2023 19:02:10 +0000 (21:02 +0200)]
Don't leak cwd into MkosiConfig
Storing Path.cwd() in MkosiConfig makes it complicated to figure
out if a MkosiConfig instance is equal to MkosiConfig.default() as
that one executes after changing directory to a temporary directory,
so let's remove our default factories for the output and workspace
directory and add two methods on the MkosiConfig class instead that
replicate the functionality.
Daan De Meyer [Wed, 4 Oct 2023 11:30:19 +0000 (13:30 +0200)]
Parse setting paths before parsing main config file
Currently, paths either configure default values or append to a
list (When path_default is False, it's always a list based setting).
When paths are configuring default values, it makes more sense for
default values set in the mkosi.conf file to override path based
default values.
When appending to a list, (e.g. ExtraTrees=), it makes more sense
for the trees configured in the mkosi.conf to come after the tree
from the path (mkosi.extra).
Both these goals are achieved by parsing the path based values before
parsing the main mkosi.conf file.
Daan De Meyer [Wed, 4 Oct 2023 08:46:39 +0000 (10:46 +0200)]
Stop explicitly setting distribution in tests
We now default to "custom" when we can't figure out the host
distribution instead of failing so let's stop explicitly setting
the distribution in tests.
Joerg Behrmann [Wed, 4 Oct 2023 07:52:24 +0000 (09:52 +0200)]
config: factor out settings_lookup_by* and match_lookup from parse_config
All three (settings_lookup_by_name, settings_lookup_by_dest, and match_lookup)
only repackage global variables. Moving them outside makes them usable in other
places and only calculates them once instead of on every invocation of
parse_config.
json: add alternative default constructors to MkosiArgs and MkosiConfig
These can be used to get a default MkosiArgs/MkosiConfig just have if mkosi had
been called in an empty directory with no cmdline without adding defaults to
the attributes and allowing instances of MkosiArgs/MkosiConfig to be made with
missing keys.
- reformat overly long lines
- remove typing.Type in favour of type
- import Iterablefrom collections.abc instead of typing
- compare singletons with is
- don't use "ambiguous variable name: l"
Daan De Meyer [Tue, 3 Oct 2023 08:08:41 +0000 (10:08 +0200)]
Always set the ttyS0 credentials
Even when booting with GUI, we might still have a serial terminal,
so let's always set the serial terminal specific size credentials
as these don't affect the GUI terminals at all.
Daan De Meyer [Mon, 2 Oct 2023 08:24:19 +0000 (10:24 +0200)]
Only add console=ttyS0 and tty sizes when QemuGui= is disabled
With console=ttyS0, we don't get any boot logs when running qemu
in GUI mode. The tty sizes don't matter either when booting in GUI
mode as Linux can figure it out itself in that scenario.
Daan De Meyer [Sun, 1 Oct 2023 18:20:12 +0000 (20:20 +0200)]
Add RuntimeSize= setting
Currently we unconditionally grow disk images to 8G before booting
them in systemd-nspawn or qemu. Let's do better here by making the
size configurable and not growing the disk images by default.
We also move format_bytes() to config.py as most other formatting
functions are located there.
Instead, let's show individual tools tree packages in the summary.
This makes things a bit more consistent as we don't show default
initrd presets in the summary either (and making that happen is no
trivial task so we opt to do the reverse and not show default tools
trees either).
We also add a table to the documentation showing which packages are
in the default tools tree for which distributions.
Daan De Meyer [Sun, 1 Oct 2023 08:26:12 +0000 (10:26 +0200)]
Don't reuse unprivileged cache when building as root
When using --incremental and first building an image unprivileged,
followed by building it as root, we can't reuse the cache as the
ownership will be wrong. So let's make sure we don't reuse the
cache when that's the case.
This makes it easier to print a message from the installer referring
to the distro by the proper name.
I looked at the home pages of the distros and took the spelling used
there. In particular Fedora is making a concious effort to use "Fedora"
for the whole project, and "Fedora Linux" for the distro. OTOH, Ubuntu
is known for not using "linux" anywhere where users could see it.
distributions: use a generator to reduce list boilerplate
When the list of repos to return is conditionalized, we can use yield instead
of concatenating lists. Iterable[Repo] can be satisfied by both the functions
which are generators and the functions which just return a list as before.
It is an optional component. The user would be unhappy when we fail at the end
of a lengthy installation process. So let's check early if we would need it and
refuse to continue.
(When config.bootable == ConfigFeature.auto, we cannot to do the check before
the installation is performed, so let's opt to be strict and do the check.)
Inspired by https://bugzilla.redhat.com/show_bug.cgi?id=2240598.
distributions: rename all installers to "Installer"
We were doing "double namespacing": "centos.CentosInstaller",
"ubuntu.UbuntuInstaller", etc. Let's simplify things by dropping the second
name. This avoids the awkward issue how capitalize the names of distributions
that already have capitals in their name, e.g. CentoOS, or dashes in the name,
e.g. RHEL-UBI. The one call site where we import the right installer becomes
simpler.
In Distribution.installer(), try..except is replaced by assert. If the
installer class for a distro is missing, then it's a programming error and not
not something we should suppress.
Make sure we append the setpgid command after all the options. Let's
also use -- to avoid any potential confusion about whether the following
arguments are options or not.