Thanks Ales, for both patches

Acked-by: Mark Michelson <[email protected]>

I pushed both patches to main. Should these be backported to other
branches, too?

On Thu, Oct 8, 2026 at 6:41 AM Ales Musil via dev
<[email protected]> wrote:
>
> The Ubuntu 26.04 is the new LTS, GitHub Actions have images
> available. Move our CI and containers to Ubuntu 26.04.
> Compatibility changes required:
> - Change the linux-modules-extra to linux-modules only as the
>   extra doesn't exist anymore in 26.04.
> - Adjust apparmor fix to allow rootless containers.
> - Make sure we preserve env variables for sudo as the -E
>   is no longer allowed.
> - Install bsdextrautils as rev is no longer available by default.
>
> Signed-off-by: Ales Musil <[email protected]>
> ---
>  .ci/linux-util.sh                             | 13 +++++++++
>  .github/workflows/containers.yml              |  2 +-
>  .../workflows/ovn-fake-multinode-tests.yml    | 28 ++++++++++++-------
>  .github/workflows/ovn-kubernetes.yml          |  6 ++--
>  .github/workflows/ovn-upgrade-tests.yml       | 11 ++++++--
>  .github/workflows/test-arm.yml                | 11 ++++++--
>  .github/workflows/test.yml                    | 15 ++++++----
>  .readthedocs.yaml                             |  2 +-
>  Documentation/internals/release-process.rst   |  2 +-
>  utilities/containers/ubuntu/Dockerfile        |  3 +-
>  10 files changed, 65 insertions(+), 28 deletions(-)
>
> diff --git a/.ci/linux-util.sh b/.ci/linux-util.sh
> index 3b98bdfc4..e2937f3b4 100755
> --- a/.ci/linux-util.sh
> +++ b/.ci/linux-util.sh
> @@ -48,6 +48,7 @@ function disable_apparmor()
>      # https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2093797
>      sudo aa-teardown || true
>      sudo systemctl disable --now apparmor.service
> +    sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0
>  }
>
>  # XXX This should be removed when the following issue is fixed and the
> @@ -62,3 +63,15 @@ function fixup_crun()
>      sudo chmod +x /usr/bin/crun
>      echo "New crun version: "$(crun --version)
>  }
> +
> +function sudo_preserve_env()
> +{
> +    sudo sh -c 'cat > /etc/sudoers.d/ovn-ci-env' << EOF
> +# ovn-fake-multinode
> +Defaults env_keep += "RUNC_CMD OS_IMAGE CENTRAL_IMAGE CHASSIS_IMAGE 
> RELAY_IMAGE GW_IMAGE ENABLE_SSL"
> +# ovn-ci
> +Defaults env_keep += "ARCH CC DPDK LIBS OPTS TESTSUITE TEST_RANGE SANITIZERS 
> UNSTABLE BASE_VERSION"
> +EOF
> +    sudo chmod 0440 /etc/sudoers.d/ovn-ci-env
> +    sudo visudo -cf /etc/sudoers.d/ovn-ci-env
> +}
> diff --git a/.github/workflows/containers.yml 
> b/.github/workflows/containers.yml
> index 05875bcaf..42d6027b1 100644
> --- a/.github/workflows/containers.yml
> +++ b/.github/workflows/containers.yml
> @@ -17,7 +17,7 @@ env:
>  jobs:
>    container:
>      if: github.repository_owner == 'ovn-org'
> -    runs-on: ubuntu-24.04
> +    runs-on: ubuntu-26.04
>      strategy:
>        matrix:
>          distro: [ fedora, ubuntu ]
> diff --git a/.github/workflows/ovn-fake-multinode-tests.yml 
> b/.github/workflows/ovn-fake-multinode-tests.yml
> index 05f3b0661..b3ae69752 100644
> --- a/.github/workflows/ovn-fake-multinode-tests.yml
> +++ b/.github/workflows/ovn-fake-multinode-tests.yml
> @@ -14,7 +14,7 @@ jobs:
>    build:
>      name: Build ovn-fake-multinode image
>      if: github.repository_owner == 'ovn-org' || github.event_name != 
> 'schedule'
> -    runs-on: ubuntu-24.04
> +    runs-on: ubuntu-26.04
>      strategy:
>        matrix:
>          cfg:
> @@ -25,8 +25,6 @@ jobs:
>        PREINSTALLED_DEPENDENCIES: podman
>        RUNC_CMD: podman
>        OS_IMAGE: "fedora:42"
> -      # https://github.com/actions/runner-images/issues/6282
> -      XDG_RUNTIME_DIR: ''
>      steps:
>      - name: Check out ovn-fake-multi-node
>        uses: actions/checkout@v6
> @@ -83,10 +81,16 @@ jobs:
>          fixup_crun
>        working-directory: ovn-fake-multinode/ovn
>
> +    - name: Preserve env
> +      run: |
> +        . .ci/linux-util.sh
> +        sudo_preserve_env
> +      working-directory: ovn-fake-multinode/ovn
> +
>      - name: Build ovn-fake-multi-node ${{ matrix.cfg.branch }} image
>        run: |
>          set -x
> -        sudo -E ./ovn_cluster.sh build
> +        sudo ./ovn_cluster.sh build
>          mkdir -p /tmp/_output
>          sudo podman tag ovn/ovn-multi-node:latest ovn/ovn-multi-node:${{ 
> matrix.cfg.branch }}
>          sudo podman save --format oci-archive ovn/ovn-multi-node:${{ 
> matrix.cfg.branch }} > /tmp/_output/ovn_${{ matrix.cfg.branch }}_image.tar
> @@ -98,7 +102,7 @@ jobs:
>          path: /tmp/_output/ovn_${{ matrix.cfg.branch }}_image.tar
>
>    multinode-tests:
> -    runs-on: ubuntu-24.04
> +    runs-on: ubuntu-26.04
>      timeout-minutes: 60
>      needs: [build]
>      strategy:
> @@ -132,7 +136,6 @@ jobs:
>          openvswitch-switch libunbound-dev libunwind-dev
>        # https://github.com/actions/runner-images/issues/6282
>        PREINSTALLED_DEPENDENCIES: podman
> -      XDG_RUNTIME_DIR: ''
>
>      steps:
>      - name: Check out ovn
> @@ -149,7 +152,7 @@ jobs:
>          if [ -n "${{ env.DEPENDENCIES }}" ]; then
>            sudo apt install -y ${{ env.DEPENDENCIES }}
>          fi
> -        sudo apt install -y linux-modules-extra-$(uname -r)
> +        sudo apt install -y linux-modules-$(uname -r)
>
>      - name: Fix /etc/hosts file
>        run: |
> @@ -166,6 +169,11 @@ jobs:
>          . .ci/linux-util.sh
>          fixup_crun
>
> +    - name: Preserve env
> +      run: |
> +        . .ci/linux-util.sh
> +        sudo_preserve_env
> +
>      - name: Free up disk space
>        run: |
>          . .ci/linux-util.sh
> @@ -203,7 +211,7 @@ jobs:
>
>      - name: Start basic cluster
>        run: |
> -        sudo -E CHASSIS_COUNT=4 GW_COUNT=4 INLINE_BR_EX=${{ 
> matrix.inline_br_ex }} ./ovn_cluster.sh start
> +        sudo CHASSIS_COUNT=4 GW_COUNT=4 INLINE_BR_EX=${{ matrix.inline_br_ex 
> }} ./ovn_cluster.sh start
>          sudo podman exec -it ovn-central-az1 ovn-nbctl show
>          sudo podman exec -it ovn-central-az1 ovn-appctl -t ovn-northd version
>          sudo podman exec -it ovn-chassis-1 ovn-appctl -t ovn-controller 
> version
> @@ -240,7 +248,7 @@ jobs:
>
>      - name: Run fake-multinode system tests
>        run: |
> -        if ! sudo -E make check-multinode TESTSUITEFLAGS="${{ 
> matrix.cfg.testsuiteflags }}"; then
> +        if ! sudo make check-multinode TESTSUITEFLAGS="${{ 
> matrix.cfg.testsuiteflags }}"; then
>            sudo podman exec -it ovn-central-az1 ovn-nbctl show || :
>            sudo podman exec -it ovn-central-az1 ovn-sbctl show || :
>            sudo podman exec -it ovn-chassis-1 ovs-vsctl show || :
> @@ -274,5 +282,5 @@ jobs:
>
>      - name: Stop cluster
>        run: |
> -        sudo -E ./ovn_cluster.sh stop
> +        sudo ./ovn_cluster.sh stop
>        working-directory: ovn-fake-multinode
> diff --git a/.github/workflows/ovn-kubernetes.yml 
> b/.github/workflows/ovn-kubernetes.yml
> index 025514274..7448a1f37 100644
> --- a/.github/workflows/ovn-kubernetes.yml
> +++ b/.github/workflows/ovn-kubernetes.yml
> @@ -25,7 +25,7 @@ jobs:
>    build:
>      name: Build
>      if: github.repository_owner == 'ovn-org' || github.event_name != 
> 'schedule'
> -    runs-on: ubuntu-24.04
> +    runs-on: ubuntu-26.04
>      steps:
>      - name: Enable Docker experimental features
>        run: |
> @@ -69,7 +69,7 @@ jobs:
>
>    e2e:
>      name: e2e
> -    runs-on: ubuntu-24.04
> +    runs-on: ubuntu-26.04
>      timeout-minutes: 220
>      strategy:
>        fail-fast: false
> @@ -139,7 +139,7 @@ jobs:
>        run: |
>          set -x
>          sudo apt update
> -        sudo apt-get install linux-modules-extra-$(uname -r) -y
> +        sudo apt-get install linux-modules-$(uname -r) -y
>          sudo modprobe vrf
>
>      - name: Free up disk space
> diff --git a/.github/workflows/ovn-upgrade-tests.yml 
> b/.github/workflows/ovn-upgrade-tests.yml
> index c03444d54..bffd29b57 100644
> --- a/.github/workflows/ovn-upgrade-tests.yml
> +++ b/.github/workflows/ovn-upgrade-tests.yml
> @@ -14,7 +14,7 @@ jobs:
>    upgrade-tests:
>      name: upgrade-test ${{ matrix.cfg.base_version }} ${{ 
> matrix.cfg.test_range }}
>      if: (github.repository_owner == 'ovn-org' && github.event_name == 
> 'schedule' && github.ref_name == 'main') || github.event_name == 
> 'workflow_dispatch'
> -    runs-on: ubuntu-24.04
> +    runs-on: ubuntu-26.04
>      timeout-minutes: 120
>
>      strategy:
> @@ -44,7 +44,7 @@ jobs:
>      - name: system-level-dependencies
>        run: |
>          sudo apt update
> -        sudo apt -y install linux-modules-extra-$(uname -r)
> +        sudo apt -y install linux-modules-$(uname -r)
>
>      - name: checkout
>        uses: actions/checkout@v6
> @@ -66,6 +66,11 @@ jobs:
>          . .ci/linux-util.sh
>          fixup_crun
>
> +    - name: Preserve env
> +      run: |
> +        . .ci/linux-util.sh
> +        sudo_preserve_env
> +
>      - name: Download container
>        run: sudo podman pull ghcr.io/ovn-org/ovn-tests:ubuntu
>
> @@ -81,7 +86,7 @@ jobs:
>          echo "name=logs-upgrade-test-${BRANCH_NAME}-${{ 
> matrix.cfg.test_range }}" >> $GITHUB_OUTPUT
>
>      - name: build
> -      run: sudo -E ./.ci/ci.sh --archive-logs --timeout=2h
> +      run: sudo ./.ci/ci.sh --archive-logs --timeout=2h
>
>      - name: upload logs on failure
>        if: failure() || cancelled()
> diff --git a/.github/workflows/test-arm.yml b/.github/workflows/test-arm.yml
> index 64bec214f..ed693713b 100644
> --- a/.github/workflows/test-arm.yml
> +++ b/.github/workflows/test-arm.yml
> @@ -27,7 +27,7 @@ jobs:
>
>      name: linux ${{ join(matrix.cfg.*, ' ') }}
>      if: (github.repository_owner == 'ovn-org' && github.event_name == 
> 'schedule' && github.ref_name == 'main') || github.event_name == 
> 'workflow_dispatch'
> -    runs-on: ubuntu-24.04-arm
> +    runs-on: ubuntu-26.04-arm
>
>      strategy:
>        fail-fast: false
> @@ -74,7 +74,7 @@ jobs:
>        - name: system-level-dependencies
>          if: ${{ startsWith(matrix.cfg.testsuite, 'system-test') }}
>          run: |
> -          sudo apt -y install linux-modules-extra-$(uname -r)
> +          sudo apt -y install linux-modules-$(uname -r)
>
>        - name: checkout
>          uses: actions/checkout@v6
> @@ -96,6 +96,11 @@ jobs:
>            . .ci/linux-util.sh
>            fixup_crun
>
> +      - name: Preserve env
> +        run: |
> +          . .ci/linux-util.sh
> +          sudo_preserve_env
> +
>        - name: Download container
>          run: |
>            podman pull ghcr.io/ovn-org/ovn-tests:ubuntu
> @@ -108,7 +113,7 @@ jobs:
>
>        - name: build
>          if: ${{ startsWith(matrix.cfg.testsuite, 'system-test') }}
> -        run: sudo -E ./.ci/ci.sh --archive-logs --timeout=2h
> +        run: sudo ./.ci/ci.sh --archive-logs --timeout=2h
>
>        - name: build
>          if: ${{ !startsWith(matrix.cfg.testsuite, 'system-test') }}
> diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml
> index f1a2cd1f7..28deb99ba 100644
> --- a/.github/workflows/test.yml
> +++ b/.github/workflows/test.yml
> @@ -27,7 +27,7 @@ jobs:
>        PREINSTALLED_DEPENDENCIES: podman
>      name: Prepare container
>      if: github.repository_owner == 'ovn-org' || github.event_name != 
> 'schedule'
> -    runs-on: ubuntu-24.04
> +    runs-on: ubuntu-26.04
>
>      steps:
>        - uses: actions/checkout@v6
> @@ -105,7 +105,7 @@ jobs:
>        UNSTABLE:    ${{ matrix.cfg.unstable }}
>
>      name: linux ${{ join(matrix.cfg.*, ' ') }}
> -    runs-on: ubuntu-24.04
> +    runs-on: ubuntu-26.04
>
>      strategy:
>        fail-fast: false
> @@ -142,7 +142,7 @@ jobs:
>        if: ${{ startsWith(matrix.cfg.testsuite, 'system-test') }}
>        run: |
>          sudo apt update
> -        sudo apt -y install linux-modules-extra-$(uname -r)
> +        sudo apt -y install linux-modules-$(uname -r)
>
>      - name: checkout
>        if: github.event_name == 'push' || github.event_name == 'pull_request'
> @@ -188,6 +188,11 @@ jobs:
>          . .ci/linux-util.sh
>          fixup_crun
>
> +    - name: Preserve env
> +      run: |
> +        . .ci/linux-util.sh
> +        sudo_preserve_env
> +
>      - name: image cache
>        id: image_cache
>        uses: actions/cache@v5
> @@ -203,7 +208,7 @@ jobs:
>
>      - name: build
>        if: ${{ startsWith(matrix.cfg.testsuite, 'system-test') }}
> -      run: sudo -E ./.ci/ci.sh --archive-logs --timeout=2h
> +      run: sudo ./.ci/ci.sh --archive-logs --timeout=2h
>
>      - name: build
>        if: ${{ !startsWith(matrix.cfg.testsuite, 'system-test') }}
> @@ -278,7 +283,7 @@ jobs:
>    build-linux-rpm:
>      name: linux rpm fedora
>      if: github.repository_owner == 'ovn-org' || github.event_name != 
> 'schedule'
> -    runs-on: ubuntu-24.04
> +    runs-on: ubuntu-26.04
>      container: fedora:42
>      timeout-minutes: 30
>
> diff --git a/.readthedocs.yaml b/.readthedocs.yaml
> index 8c451663a..9f7b0cbd5 100644
> --- a/.readthedocs.yaml
> +++ b/.readthedocs.yaml
> @@ -7,7 +7,7 @@ version: 2
>
>  # Set the OS, Python version, etc.
>  build:
> -  os: ubuntu-22.04
> +  os: ubuntu-26.04
>    tools:
>      python: "3.12"
>
> diff --git a/Documentation/internals/release-process.rst 
> b/Documentation/internals/release-process.rst
> index f5a3ec1fa..79cd94e36 100644
> --- a/Documentation/internals/release-process.rst
> +++ b/Documentation/internals/release-process.rst
> @@ -67,7 +67,7 @@ Scheduling`_ for the timing of each stage:
>
>     In order to keep the CI stable on the new release branch, the Ubuntu
>     container should be pinned to the LTS version used by the project's
> -   container Dockerfile, e.g. registry.hub.docker.com/library/ubuntu:24.04.
> +   container Dockerfile, e.g. registry.hub.docker.com/library/ubuntu:26.04.
>
>  3. When committers come to rough consensus that the release is ready, they
>     release the .0 release on its branch, e.g. 25.09.0 for branch-25.09.  To
> diff --git a/utilities/containers/ubuntu/Dockerfile 
> b/utilities/containers/ubuntu/Dockerfile
> index bf64974de..7e9090050 100755
> --- a/utilities/containers/ubuntu/Dockerfile
> +++ b/utilities/containers/ubuntu/Dockerfile
> @@ -1,4 +1,4 @@
> -FROM registry.hub.docker.com/library/ubuntu:24.04
> +FROM registry.hub.docker.com/library/ubuntu:26.04
>
>  ARG CONTAINERS_PATH
>
> @@ -10,6 +10,7 @@ RUN apt update -y \
>      apt install -y \
>          automake \
>          bc \
> +        bsdextrautils \
>          clang \
>          curl \
>          ethtool \
> --
> 2.55.0
>
> _______________________________________________
> dev mailing list
> [email protected]
> https://mail.openvswitch.org/mailman/listinfo/ovs-dev
>

_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to