The Ubuntu 26.04 is the new LTS, GitHub Actions have images available. Move our CI and containers to Ubuntu 26.04. Compatibility changes required: - Change the linux-modules-extra to linux-modules only as the extra doesn't exist anymore in 26.04. - Adjust apparmor fix to allow rootless containers. - Make sure we preserve env variables for sudo as the -E is no longer allowed. - Install bsdextrautils as rev is no longer available by default.
Signed-off-by: Ales Musil <[email protected]> --- .ci/linux-util.sh | 13 +++++++++ .github/workflows/containers.yml | 2 +- .../workflows/ovn-fake-multinode-tests.yml | 28 ++++++++++++------- .github/workflows/ovn-kubernetes.yml | 6 ++-- .github/workflows/ovn-upgrade-tests.yml | 11 ++++++-- .github/workflows/test-arm.yml | 11 ++++++-- .github/workflows/test.yml | 15 ++++++---- .readthedocs.yaml | 2 +- Documentation/internals/release-process.rst | 2 +- utilities/containers/ubuntu/Dockerfile | 3 +- 10 files changed, 65 insertions(+), 28 deletions(-) diff --git a/.ci/linux-util.sh b/.ci/linux-util.sh index 3b98bdfc4..e2937f3b4 100755 --- a/.ci/linux-util.sh +++ b/.ci/linux-util.sh @@ -48,6 +48,7 @@ function disable_apparmor() # https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2093797 sudo aa-teardown || true sudo systemctl disable --now apparmor.service + sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 } # XXX This should be removed when the following issue is fixed and the @@ -62,3 +63,15 @@ function fixup_crun() sudo chmod +x /usr/bin/crun echo "New crun version: "$(crun --version) } + +function sudo_preserve_env() +{ + sudo sh -c 'cat > /etc/sudoers.d/ovn-ci-env' << EOF +# ovn-fake-multinode +Defaults env_keep += "RUNC_CMD OS_IMAGE CENTRAL_IMAGE CHASSIS_IMAGE RELAY_IMAGE GW_IMAGE ENABLE_SSL" +# ovn-ci +Defaults env_keep += "ARCH CC DPDK LIBS OPTS TESTSUITE TEST_RANGE SANITIZERS UNSTABLE BASE_VERSION" +EOF + sudo chmod 0440 /etc/sudoers.d/ovn-ci-env + sudo visudo -cf /etc/sudoers.d/ovn-ci-env +} diff --git a/.github/workflows/containers.yml b/.github/workflows/containers.yml index 05875bcaf..42d6027b1 100644 --- a/.github/workflows/containers.yml +++ b/.github/workflows/containers.yml @@ -17,7 +17,7 @@ env: jobs: container: if: github.repository_owner == 'ovn-org' - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 strategy: matrix: distro: [ fedora, ubuntu ] diff --git a/.github/workflows/ovn-fake-multinode-tests.yml b/.github/workflows/ovn-fake-multinode-tests.yml index 05f3b0661..b3ae69752 100644 --- a/.github/workflows/ovn-fake-multinode-tests.yml +++ b/.github/workflows/ovn-fake-multinode-tests.yml @@ -14,7 +14,7 @@ jobs: build: name: Build ovn-fake-multinode image if: github.repository_owner == 'ovn-org' || github.event_name != 'schedule' - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 strategy: matrix: cfg: @@ -25,8 +25,6 @@ jobs: PREINSTALLED_DEPENDENCIES: podman RUNC_CMD: podman OS_IMAGE: "fedora:42" - # https://github.com/actions/runner-images/issues/6282 - XDG_RUNTIME_DIR: '' steps: - name: Check out ovn-fake-multi-node uses: actions/checkout@v6 @@ -83,10 +81,16 @@ jobs: fixup_crun working-directory: ovn-fake-multinode/ovn + - name: Preserve env + run: | + . .ci/linux-util.sh + sudo_preserve_env + working-directory: ovn-fake-multinode/ovn + - name: Build ovn-fake-multi-node ${{ matrix.cfg.branch }} image run: | set -x - sudo -E ./ovn_cluster.sh build + sudo ./ovn_cluster.sh build mkdir -p /tmp/_output sudo podman tag ovn/ovn-multi-node:latest ovn/ovn-multi-node:${{ matrix.cfg.branch }} sudo podman save --format oci-archive ovn/ovn-multi-node:${{ matrix.cfg.branch }} > /tmp/_output/ovn_${{ matrix.cfg.branch }}_image.tar @@ -98,7 +102,7 @@ jobs: path: /tmp/_output/ovn_${{ matrix.cfg.branch }}_image.tar multinode-tests: - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 timeout-minutes: 60 needs: [build] strategy: @@ -132,7 +136,6 @@ jobs: openvswitch-switch libunbound-dev libunwind-dev # https://github.com/actions/runner-images/issues/6282 PREINSTALLED_DEPENDENCIES: podman - XDG_RUNTIME_DIR: '' steps: - name: Check out ovn @@ -149,7 +152,7 @@ jobs: if [ -n "${{ env.DEPENDENCIES }}" ]; then sudo apt install -y ${{ env.DEPENDENCIES }} fi - sudo apt install -y linux-modules-extra-$(uname -r) + sudo apt install -y linux-modules-$(uname -r) - name: Fix /etc/hosts file run: | @@ -166,6 +169,11 @@ jobs: . .ci/linux-util.sh fixup_crun + - name: Preserve env + run: | + . .ci/linux-util.sh + sudo_preserve_env + - name: Free up disk space run: | . .ci/linux-util.sh @@ -203,7 +211,7 @@ jobs: - name: Start basic cluster run: | - sudo -E CHASSIS_COUNT=4 GW_COUNT=4 INLINE_BR_EX=${{ matrix.inline_br_ex }} ./ovn_cluster.sh start + sudo CHASSIS_COUNT=4 GW_COUNT=4 INLINE_BR_EX=${{ matrix.inline_br_ex }} ./ovn_cluster.sh start sudo podman exec -it ovn-central-az1 ovn-nbctl show sudo podman exec -it ovn-central-az1 ovn-appctl -t ovn-northd version sudo podman exec -it ovn-chassis-1 ovn-appctl -t ovn-controller version @@ -240,7 +248,7 @@ jobs: - name: Run fake-multinode system tests run: | - if ! sudo -E make check-multinode TESTSUITEFLAGS="${{ matrix.cfg.testsuiteflags }}"; then + if ! sudo make check-multinode TESTSUITEFLAGS="${{ matrix.cfg.testsuiteflags }}"; then sudo podman exec -it ovn-central-az1 ovn-nbctl show || : sudo podman exec -it ovn-central-az1 ovn-sbctl show || : sudo podman exec -it ovn-chassis-1 ovs-vsctl show || : @@ -274,5 +282,5 @@ jobs: - name: Stop cluster run: | - sudo -E ./ovn_cluster.sh stop + sudo ./ovn_cluster.sh stop working-directory: ovn-fake-multinode diff --git a/.github/workflows/ovn-kubernetes.yml b/.github/workflows/ovn-kubernetes.yml index 025514274..7448a1f37 100644 --- a/.github/workflows/ovn-kubernetes.yml +++ b/.github/workflows/ovn-kubernetes.yml @@ -25,7 +25,7 @@ jobs: build: name: Build if: github.repository_owner == 'ovn-org' || github.event_name != 'schedule' - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 steps: - name: Enable Docker experimental features run: | @@ -69,7 +69,7 @@ jobs: e2e: name: e2e - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 timeout-minutes: 220 strategy: fail-fast: false @@ -139,7 +139,7 @@ jobs: run: | set -x sudo apt update - sudo apt-get install linux-modules-extra-$(uname -r) -y + sudo apt-get install linux-modules-$(uname -r) -y sudo modprobe vrf - name: Free up disk space diff --git a/.github/workflows/ovn-upgrade-tests.yml b/.github/workflows/ovn-upgrade-tests.yml index c03444d54..bffd29b57 100644 --- a/.github/workflows/ovn-upgrade-tests.yml +++ b/.github/workflows/ovn-upgrade-tests.yml @@ -14,7 +14,7 @@ jobs: upgrade-tests: name: upgrade-test ${{ matrix.cfg.base_version }} ${{ matrix.cfg.test_range }} if: (github.repository_owner == 'ovn-org' && github.event_name == 'schedule' && github.ref_name == 'main') || github.event_name == 'workflow_dispatch' - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 timeout-minutes: 120 strategy: @@ -44,7 +44,7 @@ jobs: - name: system-level-dependencies run: | sudo apt update - sudo apt -y install linux-modules-extra-$(uname -r) + sudo apt -y install linux-modules-$(uname -r) - name: checkout uses: actions/checkout@v6 @@ -66,6 +66,11 @@ jobs: . .ci/linux-util.sh fixup_crun + - name: Preserve env + run: | + . .ci/linux-util.sh + sudo_preserve_env + - name: Download container run: sudo podman pull ghcr.io/ovn-org/ovn-tests:ubuntu @@ -81,7 +86,7 @@ jobs: echo "name=logs-upgrade-test-${BRANCH_NAME}-${{ matrix.cfg.test_range }}" >> $GITHUB_OUTPUT - name: build - run: sudo -E ./.ci/ci.sh --archive-logs --timeout=2h + run: sudo ./.ci/ci.sh --archive-logs --timeout=2h - name: upload logs on failure if: failure() || cancelled() diff --git a/.github/workflows/test-arm.yml b/.github/workflows/test-arm.yml index 64bec214f..ed693713b 100644 --- a/.github/workflows/test-arm.yml +++ b/.github/workflows/test-arm.yml @@ -27,7 +27,7 @@ jobs: name: linux ${{ join(matrix.cfg.*, ' ') }} if: (github.repository_owner == 'ovn-org' && github.event_name == 'schedule' && github.ref_name == 'main') || github.event_name == 'workflow_dispatch' - runs-on: ubuntu-24.04-arm + runs-on: ubuntu-26.04-arm strategy: fail-fast: false @@ -74,7 +74,7 @@ jobs: - name: system-level-dependencies if: ${{ startsWith(matrix.cfg.testsuite, 'system-test') }} run: | - sudo apt -y install linux-modules-extra-$(uname -r) + sudo apt -y install linux-modules-$(uname -r) - name: checkout uses: actions/checkout@v6 @@ -96,6 +96,11 @@ jobs: . .ci/linux-util.sh fixup_crun + - name: Preserve env + run: | + . .ci/linux-util.sh + sudo_preserve_env + - name: Download container run: | podman pull ghcr.io/ovn-org/ovn-tests:ubuntu @@ -108,7 +113,7 @@ jobs: - name: build if: ${{ startsWith(matrix.cfg.testsuite, 'system-test') }} - run: sudo -E ./.ci/ci.sh --archive-logs --timeout=2h + run: sudo ./.ci/ci.sh --archive-logs --timeout=2h - name: build if: ${{ !startsWith(matrix.cfg.testsuite, 'system-test') }} diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index f1a2cd1f7..28deb99ba 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -27,7 +27,7 @@ jobs: PREINSTALLED_DEPENDENCIES: podman name: Prepare container if: github.repository_owner == 'ovn-org' || github.event_name != 'schedule' - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 steps: - uses: actions/checkout@v6 @@ -105,7 +105,7 @@ jobs: UNSTABLE: ${{ matrix.cfg.unstable }} name: linux ${{ join(matrix.cfg.*, ' ') }} - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 strategy: fail-fast: false @@ -142,7 +142,7 @@ jobs: if: ${{ startsWith(matrix.cfg.testsuite, 'system-test') }} run: | sudo apt update - sudo apt -y install linux-modules-extra-$(uname -r) + sudo apt -y install linux-modules-$(uname -r) - name: checkout if: github.event_name == 'push' || github.event_name == 'pull_request' @@ -188,6 +188,11 @@ jobs: . .ci/linux-util.sh fixup_crun + - name: Preserve env + run: | + . .ci/linux-util.sh + sudo_preserve_env + - name: image cache id: image_cache uses: actions/cache@v5 @@ -203,7 +208,7 @@ jobs: - name: build if: ${{ startsWith(matrix.cfg.testsuite, 'system-test') }} - run: sudo -E ./.ci/ci.sh --archive-logs --timeout=2h + run: sudo ./.ci/ci.sh --archive-logs --timeout=2h - name: build if: ${{ !startsWith(matrix.cfg.testsuite, 'system-test') }} @@ -278,7 +283,7 @@ jobs: build-linux-rpm: name: linux rpm fedora if: github.repository_owner == 'ovn-org' || github.event_name != 'schedule' - runs-on: ubuntu-24.04 + runs-on: ubuntu-26.04 container: fedora:42 timeout-minutes: 30 diff --git a/.readthedocs.yaml b/.readthedocs.yaml index 8c451663a..9f7b0cbd5 100644 --- a/.readthedocs.yaml +++ b/.readthedocs.yaml @@ -7,7 +7,7 @@ version: 2 # Set the OS, Python version, etc. build: - os: ubuntu-22.04 + os: ubuntu-26.04 tools: python: "3.12" diff --git a/Documentation/internals/release-process.rst b/Documentation/internals/release-process.rst index f5a3ec1fa..79cd94e36 100644 --- a/Documentation/internals/release-process.rst +++ b/Documentation/internals/release-process.rst @@ -67,7 +67,7 @@ Scheduling`_ for the timing of each stage: In order to keep the CI stable on the new release branch, the Ubuntu container should be pinned to the LTS version used by the project's - container Dockerfile, e.g. registry.hub.docker.com/library/ubuntu:24.04. + container Dockerfile, e.g. registry.hub.docker.com/library/ubuntu:26.04. 3. When committers come to rough consensus that the release is ready, they release the .0 release on its branch, e.g. 25.09.0 for branch-25.09. To diff --git a/utilities/containers/ubuntu/Dockerfile b/utilities/containers/ubuntu/Dockerfile index bf64974de..7e9090050 100755 --- a/utilities/containers/ubuntu/Dockerfile +++ b/utilities/containers/ubuntu/Dockerfile @@ -1,4 +1,4 @@ -FROM registry.hub.docker.com/library/ubuntu:24.04 +FROM registry.hub.docker.com/library/ubuntu:26.04 ARG CONTAINERS_PATH @@ -10,6 +10,7 @@ RUN apt update -y \ apt install -y \ automake \ bc \ + bsdextrautils \ clang \ curl \ ethtool \ -- 2.55.0 _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
