Skip to content

Merge pull request #1164 from Johan-Liebert1/grub-symlink-fix #1887

Merge pull request #1164 from Johan-Liebert1/grub-symlink-fix

Merge pull request #1164 from Johan-Liebert1/grub-symlink-fix #1887

Workflow file for this run

name: CI
permissions:
actions: read
on:
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch: {}
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
CARGO_TERM_COLOR: always
jobs:
bootc-e2e:
if: github.repository == 'coreos/bootupd'
strategy:
matrix:
runner:
- ubuntu-24.04
- ubuntu-24.04-arm
grubcc:
- 0
stream:
- 9
- 10
include:
# grubcc=1 uses Fedora (Dockerfile.bls), no stream variants needed
- runner: ubuntu-24.04
grubcc: 1
- runner: ubuntu-24.04-arm
grubcc: 1
runs-on: [ "${{ matrix.runner }}" ]
steps:
- uses: bootc-dev/actions/bootc-ubuntu-setup@fdfe1dc66edbfa03897ab619a5c037fb8f5339ff
with:
libvirt: ${{ matrix.runner == 'ubuntu-24.04' && 'true' || 'false' }}
- name: Install OVMF for UEFI VM boot tests
if: ${{ matrix.runner == 'ubuntu-24.04' }}
run: sudo apt-get install -y ovmf
- name: Setup env
run: |
if [[ "${{ matrix.grubcc }}" == "1" ]]; then
# grubcc=1 uses Fedora (no stream variants)
IMG_NAME=localhost/bootupd-grubcc-1
OS_ID="fedora"
else
IMG_NAME=localhost/bootupd-grubcc-0-stream${{ matrix.stream }}
OS_ID="centos"
fi
echo "IMG_NAME=${IMG_NAME}" >> "$GITHUB_ENV"
echo "OS_ID=${OS_ID}" >> "$GITHUB_ENV"
- uses: actions/checkout@v7
- name: build with grubcc=${{ matrix.grubcc }}
run: |
if [[ "${{ matrix.grubcc }}" == "1" ]]; then
dockerfile=Dockerfile.bls
build_args=(--build-arg "grubcc=${{ matrix.grubcc }}")
else
dockerfile=Dockerfile
build_args=(--build-arg "base=quay.io/centos-bootc/centos-bootc:stream${{ matrix.stream }}")
fi
sudo podman build "${build_args[@]}" . -t "$IMG_NAME" -f "$dockerfile"
- name: bootupctl status in container
run: |
set -xeuo pipefail
sudo podman run --rm -v $PWD:/run/src -w /run/src --privileged "$IMG_NAME" tests/tests/bootupctl-status-in-bootc.sh
# Make sure grub stuff works with and without grubcc in the container image
# TODO: Test GrubCC installation with composefs after a bootc release includes
# https://github.com/bootc-dev/bootc/pull/2223
- name: bootc install to disk
run: |
set -xeuo pipefail
sudo truncate -s 10G myimage.raw
sudo podman run --rm --privileged -v .:/target --pid=host --security-opt label=disable \
-v /var/lib/containers:/var/lib/containers \
-v /dev:/dev \
"$IMG_NAME" bootc install to-disk --filesystem ext4 --skip-fetch-check \
--disable-selinux --generic-image --via-loopback /target/myimage.raw
# Verify we installed grub.cfg and shim on the disk
sudo losetup -P -f myimage.raw
device=$(losetup -a myimage.raw --output NAME -n)
esp_part=$(sudo sfdisk -l -J "${device}" | jq -r '.partitiontable.partitions[] | select(.type == "C12A7328-F81F-11D2-BA4B-00A0C93EC93B").node')
sudo mount "${esp_part}" /mnt/
arch="$(uname --machine)"
if [[ "${arch}" == "x86_64" ]]; then
shim="shimx64.efi"
else
# Assume aarch64 for now
shim="shimaa64.efi"
fi
sudo ls /mnt/EFI/$OS_ID/{grub.cfg,${shim}}
sudo umount /mnt
# check /boot/grub2/grub.cfg permission
root_part=$(sudo sfdisk -l -J "${device}" | jq -r '.partitiontable.partitions[] | select(.name == "root").node')
sudo mount "${root_part}" /mnt/
sudo ls /mnt/boot/grub2/grub.cfg
for f in /mnt/boot/grub2/grub.cfg /mnt/boot/grub2/bootuuid.cfg /mnt/boot/grub2/grubenv; do
perm=$(sudo stat -c '%a' "$f") || exit 1
[ "$perm" == "600" ] || { echo "$f has permissions $perm (expected 600)"; exit 1; }
done
sudo umount /mnt
sudo losetup -D "${device}"
sudo rm -f myimage.raw
- name: bootc install to filesystem
run: |
set -xeuo pipefail
sudo podman run --rm -ti --privileged -v /:/target --pid=host --security-opt label=disable \
-v /dev:/dev -v /var/lib/containers:/var/lib/containers \
"$IMG_NAME" env BOOTC_BOOTLOADER_DEBUG=1 \
bootc install to-filesystem --skip-fetch-check \
--acknowledge-destructive \
--disable-selinux --replace=alongside /target
# Verify we injected static configs
jq -re '.["static-configs"].version' /boot/bootupd-state.json
for f in /boot/grub2/grub.cfg /boot/grub2/bootuuid.cfg /boot/grub2/grubenv; do
perm=$(sudo stat -c '%a' "$f") || exit 1
[ "$perm" == "600" ] || { echo "$f has permissions $perm (expected 600)"; exit 1; }
done
- name: bootupctl generate-update-metadata
run: |
set -xeuo pipefail
sudo podman run --rm -v $PWD:/run/src -w /run/src --privileged "$IMG_NAME" tests/tests/generate-update-metadata.sh
- name: Test GrubCC and SystemdBoot
run: |
if [[ "${{ matrix.grubcc }}" == "0" ]]; then
exit 0
fi
set -xeuo pipefail
sudo ./scripts/test-bootloader.sh "$IMG_NAME" "grub-cc"
sudo ./scripts/test-bootloader.sh "$IMG_NAME" "systemd"
- name: Test BIOS installs and VM boot
if: ${{ matrix.runner == 'ubuntu-24.04' }}
run: |
set -xeuo pipefail
sudo ./scripts/test-bios-vm-boot.sh "$IMG_NAME"
- name: Test UEFI installs and VM boot
if: ${{ matrix.runner == 'ubuntu-24.04' }}
run: |
set -xeuo pipefail
sudo ./scripts/test-uefi-vm-boot.sh "$IMG_NAME" "ostree"
# TODO: Skip composefs tests for C10S as bootc 1.16.3 uses composefs.digest=
# cmdline, but for some reason that cmdline is not mentioned in
# bootc-root-setup.service
if [[ "${{ matrix.stream }}" != "10" ]]; then
sudo ./scripts/test-uefi-vm-boot.sh "$IMG_NAME" "composefs"
fi