Skip to content

[pull] stable-f44 from main - #2517

Closed
pull[bot] wants to merge 46 commits into
stable-f44from
main
Closed

[pull] stable-f44 from main#2517
pull[bot] wants to merge 46 commits into
stable-f44from
main

Conversation

@pull

@pull pull Bot commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

ubot-7274 Bot and others added 25 commits July 1, 2026 05:02
…digest to 51c7b27 (#2475)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…t to e7338ae (#2479)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…digest to 9c79b8a (#2481)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…digest to 97ae835 (#2486)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…t to a93e788 (#2488)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…t to 390a9dc (#2490)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
Co-authored-by: inffy <10782843+inffy@users.noreply.github.com>
This didn't break anything in CI, this is why this went unnoticed.

fixup of cfd014f.
…t to c00fc6b (#2494)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…digest to 59c7dc8 (#2500)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
taken from blue-build[1], this also happens to make updates smaller by
100MB. Might fix the following issues like [2] and [3]. I could not
reproduce these issues myself and just using chunkah made it possible
for me to overlay firefox with rpm-ostree.

[1]: blue-build/cli@b6f36bd
[2]: #2209
[3]: #2492

Co-authored-by: Daniel Hast <32797673+HastD@users.noreply.github.com>
If you specified --kernel-pin from cli it will now correctly verify and
donwload the right version (instead of the newest one), if it's
specified in the Justfile and CLI then CLI wins.

The pin that is always set to an empty string would override it.
* feat(ci): rootless CI

26.04 runners use sudo-rs, which does not support this flag. It doesn't
seem to have broken too much, Only thing I could see is the github token
not being passed to the build.

```
sudo: preserving the entire environment is not supported, '-E' is ignored
```

So this is a good time to move over to a rootless CI I guess.

* chore: unset target-dir for container-storage-action

This defaults to the user container storage
* fix(just): disk-image recipe

follow up of: cfd014f

* run recipe as root in CI

* fix: do load-rootful before disk-image
The --retry flags for podman/buildah pull/build do not seem to do
anything on transient network issues. Notably our base image pull from
quay is failing quite often, this should make this less likely to
happen in the future.

fixes: #2381
xref: #2337
* feat(ci): package cache with OCI artifacts

We are hitting a couple limitations in regards to actions/cache [1] with
our new testing branch workflow, as we previously relied on scheduled
builds from the main branch, which we no longer do with this model.

Now we make new cache on merge_group on the first build on Sundays, I
chose Sundays just because. Which means we run only a single build with
no cache per week and use that same build to generate a new fresh cache.

Else we would end up with 3 versions of vscode in our cache.
There is no point uploading cache on *every* PR.

For simplicity sake this has no handling/differentiation for our stable
and main branch. When we bump the fedora version of our main/testing
images then the cache for stable will just get stale.

We are mixing root/rootless usage of oras/cosign, I made it use root or
else we will get premission issues.

[1]: actions/cache#1537

fixes: #2351

* define blessed day

* chore: remove command -v prefixes

not needed, running everything rootless now
…ee15 (#2509)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…digest to 92c80b6 (#2510)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…digest to b85b98e (#2512)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…t to dbcd1f0 (#2515)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…t to 3889933 (#2516)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
@pull pull Bot locked and limited conversation to collaborators Jul 6, 2026
@pull
pull Bot requested review from NiHaiden, inffy and ledif as code owners July 6, 2026 22:49
@pull pull Bot added the stable-promotion label Jul 6, 2026
@pull
pull Bot requested a review from renner0e as a code owner July 6, 2026 22:49
ubot-7274 Bot and others added 21 commits July 7, 2026 04:46
…digest to 050d2dd (#2518)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…digest to 0e3dabc (#2521)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…bc94 (#2525)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
we haven't used this for over a year, might as well remove it.

This used to be needed in a time before we had renovate, before the
bluefin split, we build way less images now in general and also latest
and stable do not build from the main branch anymore.
should help a little bit with the openssf score
We should not rely on external actions if this functionality exists in
official tools.

We are only running this step when it's a stable image build so ommiting
the make_latest thing is fine to my understanding.

xref: #2528
We don't need any credentials after the initial clone.

xref: #2528
…digest to 96488d0 (#2534)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
* chore: be explicit about secrets needed for image build

Instead of inheriting *all* the secrets we are only selectively giving
the called workflows access to the secrets we actually need. Currently
we only have one secret we use for image signing but in the future we
may want to have a separate testing key we use to sign testing builds
only made in PRs and things like that.

We may want to look into setting things up in a way so production keys
are only ever used when we push to ublue-os/aurora.

This also happens to make the experience a little bit nicer in new forks
as the workflow will fail right after the start when the SIGNING_SECRET
wasn't set, as opposed to when signing the image.

xref: #2528

* chore: remove secrets from generate-release parts

I don't know why this exists, we don't need our cosign key in this part
of the workflow.
…digest to 2cb7976 (#2539)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…digest to 5c83c21 (#2541)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…digest to a02038e (#2547)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
…ac64 (#2546)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
* feat(chunkah): use oci-dir instead of tar-roundtrip

/tmp is a tmpfs backed by RAM (8G) on github so this will also be faster
than the current implementation because of that.

See: https://github.com/coreos/chunkah#output-options

xref: #2350

* always delete config and output dir

so we don't fill up /tmp
…digest to b46719a (#2550)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
* feat(ci): setup runner with containers policy

Currently for ublue-os/akmods and kinoite (not pinned by digest), we
verify them and pull them right after. We can't trust the authenticity
of those images, as the tag in the meantime could point to a different,
potentially compromised digest.

To avoid this, we set up our runner so that it will refuse to pull
anything from Universal Blue or quay.io/fedora-ostree-desktops without
first getting verified with the corresponding public key in our repo.

With this, we can completely get rid of our verify-container recipe and
benefit from the retry logic that is implemented in the podman pulls we
already do beforehand.

This would mean that local builds would no longer verify the pulled
images, as the policy is very likely not configured, but I don't think
that is super important.

* fix: install cosign in non-production builds
…digest to 70699ca (#2555)

Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
Co-authored-by: ubot-7274[bot] <217212047+ubot-7274[bot]@users.noreply.github.com>
@inffy

inffy commented Jul 16, 2026

Copy link
Copy Markdown
Member

#2561

@inffy inffy closed this Jul 16, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants