Thanks Ales, for both patches Acked-by: Mark Michelson <[email protected]>
I pushed both patches to main. Should these be backported to other branches, too? On Thu, Oct 8, 2026 at 6:41 AM Ales Musil via dev <[email protected]> wrote: > > The Ubuntu 26.04 is the new LTS, GitHub Actions have images > available. Move our CI and containers to Ubuntu 26.04. > Compatibility changes required: > - Change the linux-modules-extra to linux-modules only as the > extra doesn't exist anymore in 26.04. > - Adjust apparmor fix to allow rootless containers. > - Make sure we preserve env variables for sudo as the -E > is no longer allowed. > - Install bsdextrautils as rev is no longer available by default. > > Signed-off-by: Ales Musil <[email protected]> > --- > .ci/linux-util.sh | 13 +++++++++ > .github/workflows/containers.yml | 2 +- > .../workflows/ovn-fake-multinode-tests.yml | 28 ++++++++++++------- > .github/workflows/ovn-kubernetes.yml | 6 ++-- > .github/workflows/ovn-upgrade-tests.yml | 11 ++++++-- > .github/workflows/test-arm.yml | 11 ++++++-- > .github/workflows/test.yml | 15 ++++++---- > .readthedocs.yaml | 2 +- > Documentation/internals/release-process.rst | 2 +- > utilities/containers/ubuntu/Dockerfile | 3 +- > 10 files changed, 65 insertions(+), 28 deletions(-) > > diff --git a/.ci/linux-util.sh b/.ci/linux-util.sh > index 3b98bdfc4..e2937f3b4 100755 > --- a/.ci/linux-util.sh > +++ b/.ci/linux-util.sh > @@ -48,6 +48,7 @@ function disable_apparmor() > # https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/2093797 > sudo aa-teardown || true > sudo systemctl disable --now apparmor.service > + sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 > } > > # XXX This should be removed when the following issue is fixed and the > @@ -62,3 +63,15 @@ function fixup_crun() > sudo chmod +x /usr/bin/crun > echo "New crun version: "$(crun --version) > } > + > +function sudo_preserve_env() > +{ > + sudo sh -c 'cat > /etc/sudoers.d/ovn-ci-env' << EOF > +# ovn-fake-multinode > +Defaults env_keep += "RUNC_CMD OS_IMAGE CENTRAL_IMAGE CHASSIS_IMAGE > RELAY_IMAGE GW_IMAGE ENABLE_SSL" > +# ovn-ci > +Defaults env_keep += "ARCH CC DPDK LIBS OPTS TESTSUITE TEST_RANGE SANITIZERS > UNSTABLE BASE_VERSION" > +EOF > + sudo chmod 0440 /etc/sudoers.d/ovn-ci-env > + sudo visudo -cf /etc/sudoers.d/ovn-ci-env > +} > diff --git a/.github/workflows/containers.yml > b/.github/workflows/containers.yml > index 05875bcaf..42d6027b1 100644 > --- a/.github/workflows/containers.yml > +++ b/.github/workflows/containers.yml > @@ -17,7 +17,7 @@ env: > jobs: > container: > if: github.repository_owner == 'ovn-org' > - runs-on: ubuntu-24.04 > + runs-on: ubuntu-26.04 > strategy: > matrix: > distro: [ fedora, ubuntu ] > diff --git a/.github/workflows/ovn-fake-multinode-tests.yml > b/.github/workflows/ovn-fake-multinode-tests.yml > index 05f3b0661..b3ae69752 100644 > --- a/.github/workflows/ovn-fake-multinode-tests.yml > +++ b/.github/workflows/ovn-fake-multinode-tests.yml > @@ -14,7 +14,7 @@ jobs: > build: > name: Build ovn-fake-multinode image > if: github.repository_owner == 'ovn-org' || github.event_name != > 'schedule' > - runs-on: ubuntu-24.04 > + runs-on: ubuntu-26.04 > strategy: > matrix: > cfg: > @@ -25,8 +25,6 @@ jobs: > PREINSTALLED_DEPENDENCIES: podman > RUNC_CMD: podman > OS_IMAGE: "fedora:42" > - # https://github.com/actions/runner-images/issues/6282 > - XDG_RUNTIME_DIR: '' > steps: > - name: Check out ovn-fake-multi-node > uses: actions/checkout@v6 > @@ -83,10 +81,16 @@ jobs: > fixup_crun > working-directory: ovn-fake-multinode/ovn > > + - name: Preserve env > + run: | > + . .ci/linux-util.sh > + sudo_preserve_env > + working-directory: ovn-fake-multinode/ovn > + > - name: Build ovn-fake-multi-node ${{ matrix.cfg.branch }} image > run: | > set -x > - sudo -E ./ovn_cluster.sh build > + sudo ./ovn_cluster.sh build > mkdir -p /tmp/_output > sudo podman tag ovn/ovn-multi-node:latest ovn/ovn-multi-node:${{ > matrix.cfg.branch }} > sudo podman save --format oci-archive ovn/ovn-multi-node:${{ > matrix.cfg.branch }} > /tmp/_output/ovn_${{ matrix.cfg.branch }}_image.tar > @@ -98,7 +102,7 @@ jobs: > path: /tmp/_output/ovn_${{ matrix.cfg.branch }}_image.tar > > multinode-tests: > - runs-on: ubuntu-24.04 > + runs-on: ubuntu-26.04 > timeout-minutes: 60 > needs: [build] > strategy: > @@ -132,7 +136,6 @@ jobs: > openvswitch-switch libunbound-dev libunwind-dev > # https://github.com/actions/runner-images/issues/6282 > PREINSTALLED_DEPENDENCIES: podman > - XDG_RUNTIME_DIR: '' > > steps: > - name: Check out ovn > @@ -149,7 +152,7 @@ jobs: > if [ -n "${{ env.DEPENDENCIES }}" ]; then > sudo apt install -y ${{ env.DEPENDENCIES }} > fi > - sudo apt install -y linux-modules-extra-$(uname -r) > + sudo apt install -y linux-modules-$(uname -r) > > - name: Fix /etc/hosts file > run: | > @@ -166,6 +169,11 @@ jobs: > . .ci/linux-util.sh > fixup_crun > > + - name: Preserve env > + run: | > + . .ci/linux-util.sh > + sudo_preserve_env > + > - name: Free up disk space > run: | > . .ci/linux-util.sh > @@ -203,7 +211,7 @@ jobs: > > - name: Start basic cluster > run: | > - sudo -E CHASSIS_COUNT=4 GW_COUNT=4 INLINE_BR_EX=${{ > matrix.inline_br_ex }} ./ovn_cluster.sh start > + sudo CHASSIS_COUNT=4 GW_COUNT=4 INLINE_BR_EX=${{ matrix.inline_br_ex > }} ./ovn_cluster.sh start > sudo podman exec -it ovn-central-az1 ovn-nbctl show > sudo podman exec -it ovn-central-az1 ovn-appctl -t ovn-northd version > sudo podman exec -it ovn-chassis-1 ovn-appctl -t ovn-controller > version > @@ -240,7 +248,7 @@ jobs: > > - name: Run fake-multinode system tests > run: | > - if ! sudo -E make check-multinode TESTSUITEFLAGS="${{ > matrix.cfg.testsuiteflags }}"; then > + if ! sudo make check-multinode TESTSUITEFLAGS="${{ > matrix.cfg.testsuiteflags }}"; then > sudo podman exec -it ovn-central-az1 ovn-nbctl show || : > sudo podman exec -it ovn-central-az1 ovn-sbctl show || : > sudo podman exec -it ovn-chassis-1 ovs-vsctl show || : > @@ -274,5 +282,5 @@ jobs: > > - name: Stop cluster > run: | > - sudo -E ./ovn_cluster.sh stop > + sudo ./ovn_cluster.sh stop > working-directory: ovn-fake-multinode > diff --git a/.github/workflows/ovn-kubernetes.yml > b/.github/workflows/ovn-kubernetes.yml > index 025514274..7448a1f37 100644 > --- a/.github/workflows/ovn-kubernetes.yml > +++ b/.github/workflows/ovn-kubernetes.yml > @@ -25,7 +25,7 @@ jobs: > build: > name: Build > if: github.repository_owner == 'ovn-org' || github.event_name != > 'schedule' > - runs-on: ubuntu-24.04 > + runs-on: ubuntu-26.04 > steps: > - name: Enable Docker experimental features > run: | > @@ -69,7 +69,7 @@ jobs: > > e2e: > name: e2e > - runs-on: ubuntu-24.04 > + runs-on: ubuntu-26.04 > timeout-minutes: 220 > strategy: > fail-fast: false > @@ -139,7 +139,7 @@ jobs: > run: | > set -x > sudo apt update > - sudo apt-get install linux-modules-extra-$(uname -r) -y > + sudo apt-get install linux-modules-$(uname -r) -y > sudo modprobe vrf > > - name: Free up disk space > diff --git a/.github/workflows/ovn-upgrade-tests.yml > b/.github/workflows/ovn-upgrade-tests.yml > index c03444d54..bffd29b57 100644 > --- a/.github/workflows/ovn-upgrade-tests.yml > +++ b/.github/workflows/ovn-upgrade-tests.yml > @@ -14,7 +14,7 @@ jobs: > upgrade-tests: > name: upgrade-test ${{ matrix.cfg.base_version }} ${{ > matrix.cfg.test_range }} > if: (github.repository_owner == 'ovn-org' && github.event_name == > 'schedule' && github.ref_name == 'main') || github.event_name == > 'workflow_dispatch' > - runs-on: ubuntu-24.04 > + runs-on: ubuntu-26.04 > timeout-minutes: 120 > > strategy: > @@ -44,7 +44,7 @@ jobs: > - name: system-level-dependencies > run: | > sudo apt update > - sudo apt -y install linux-modules-extra-$(uname -r) > + sudo apt -y install linux-modules-$(uname -r) > > - name: checkout > uses: actions/checkout@v6 > @@ -66,6 +66,11 @@ jobs: > . .ci/linux-util.sh > fixup_crun > > + - name: Preserve env > + run: | > + . .ci/linux-util.sh > + sudo_preserve_env > + > - name: Download container > run: sudo podman pull ghcr.io/ovn-org/ovn-tests:ubuntu > > @@ -81,7 +86,7 @@ jobs: > echo "name=logs-upgrade-test-${BRANCH_NAME}-${{ > matrix.cfg.test_range }}" >> $GITHUB_OUTPUT > > - name: build > - run: sudo -E ./.ci/ci.sh --archive-logs --timeout=2h > + run: sudo ./.ci/ci.sh --archive-logs --timeout=2h > > - name: upload logs on failure > if: failure() || cancelled() > diff --git a/.github/workflows/test-arm.yml b/.github/workflows/test-arm.yml > index 64bec214f..ed693713b 100644 > --- a/.github/workflows/test-arm.yml > +++ b/.github/workflows/test-arm.yml > @@ -27,7 +27,7 @@ jobs: > > name: linux ${{ join(matrix.cfg.*, ' ') }} > if: (github.repository_owner == 'ovn-org' && github.event_name == > 'schedule' && github.ref_name == 'main') || github.event_name == > 'workflow_dispatch' > - runs-on: ubuntu-24.04-arm > + runs-on: ubuntu-26.04-arm > > strategy: > fail-fast: false > @@ -74,7 +74,7 @@ jobs: > - name: system-level-dependencies > if: ${{ startsWith(matrix.cfg.testsuite, 'system-test') }} > run: | > - sudo apt -y install linux-modules-extra-$(uname -r) > + sudo apt -y install linux-modules-$(uname -r) > > - name: checkout > uses: actions/checkout@v6 > @@ -96,6 +96,11 @@ jobs: > . .ci/linux-util.sh > fixup_crun > > + - name: Preserve env > + run: | > + . .ci/linux-util.sh > + sudo_preserve_env > + > - name: Download container > run: | > podman pull ghcr.io/ovn-org/ovn-tests:ubuntu > @@ -108,7 +113,7 @@ jobs: > > - name: build > if: ${{ startsWith(matrix.cfg.testsuite, 'system-test') }} > - run: sudo -E ./.ci/ci.sh --archive-logs --timeout=2h > + run: sudo ./.ci/ci.sh --archive-logs --timeout=2h > > - name: build > if: ${{ !startsWith(matrix.cfg.testsuite, 'system-test') }} > diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml > index f1a2cd1f7..28deb99ba 100644 > --- a/.github/workflows/test.yml > +++ b/.github/workflows/test.yml > @@ -27,7 +27,7 @@ jobs: > PREINSTALLED_DEPENDENCIES: podman > name: Prepare container > if: github.repository_owner == 'ovn-org' || github.event_name != > 'schedule' > - runs-on: ubuntu-24.04 > + runs-on: ubuntu-26.04 > > steps: > - uses: actions/checkout@v6 > @@ -105,7 +105,7 @@ jobs: > UNSTABLE: ${{ matrix.cfg.unstable }} > > name: linux ${{ join(matrix.cfg.*, ' ') }} > - runs-on: ubuntu-24.04 > + runs-on: ubuntu-26.04 > > strategy: > fail-fast: false > @@ -142,7 +142,7 @@ jobs: > if: ${{ startsWith(matrix.cfg.testsuite, 'system-test') }} > run: | > sudo apt update > - sudo apt -y install linux-modules-extra-$(uname -r) > + sudo apt -y install linux-modules-$(uname -r) > > - name: checkout > if: github.event_name == 'push' || github.event_name == 'pull_request' > @@ -188,6 +188,11 @@ jobs: > . .ci/linux-util.sh > fixup_crun > > + - name: Preserve env > + run: | > + . .ci/linux-util.sh > + sudo_preserve_env > + > - name: image cache > id: image_cache > uses: actions/cache@v5 > @@ -203,7 +208,7 @@ jobs: > > - name: build > if: ${{ startsWith(matrix.cfg.testsuite, 'system-test') }} > - run: sudo -E ./.ci/ci.sh --archive-logs --timeout=2h > + run: sudo ./.ci/ci.sh --archive-logs --timeout=2h > > - name: build > if: ${{ !startsWith(matrix.cfg.testsuite, 'system-test') }} > @@ -278,7 +283,7 @@ jobs: > build-linux-rpm: > name: linux rpm fedora > if: github.repository_owner == 'ovn-org' || github.event_name != > 'schedule' > - runs-on: ubuntu-24.04 > + runs-on: ubuntu-26.04 > container: fedora:42 > timeout-minutes: 30 > > diff --git a/.readthedocs.yaml b/.readthedocs.yaml > index 8c451663a..9f7b0cbd5 100644 > --- a/.readthedocs.yaml > +++ b/.readthedocs.yaml > @@ -7,7 +7,7 @@ version: 2 > > # Set the OS, Python version, etc. > build: > - os: ubuntu-22.04 > + os: ubuntu-26.04 > tools: > python: "3.12" > > diff --git a/Documentation/internals/release-process.rst > b/Documentation/internals/release-process.rst > index f5a3ec1fa..79cd94e36 100644 > --- a/Documentation/internals/release-process.rst > +++ b/Documentation/internals/release-process.rst > @@ -67,7 +67,7 @@ Scheduling`_ for the timing of each stage: > > In order to keep the CI stable on the new release branch, the Ubuntu > container should be pinned to the LTS version used by the project's > - container Dockerfile, e.g. registry.hub.docker.com/library/ubuntu:24.04. > + container Dockerfile, e.g. registry.hub.docker.com/library/ubuntu:26.04. > > 3. When committers come to rough consensus that the release is ready, they > release the .0 release on its branch, e.g. 25.09.0 for branch-25.09. To > diff --git a/utilities/containers/ubuntu/Dockerfile > b/utilities/containers/ubuntu/Dockerfile > index bf64974de..7e9090050 100755 > --- a/utilities/containers/ubuntu/Dockerfile > +++ b/utilities/containers/ubuntu/Dockerfile > @@ -1,4 +1,4 @@ > -FROM registry.hub.docker.com/library/ubuntu:24.04 > +FROM registry.hub.docker.com/library/ubuntu:26.04 > > ARG CONTAINERS_PATH > > @@ -10,6 +10,7 @@ RUN apt update -y \ > apt install -y \ > automake \ > bc \ > + bsdextrautils \ > clang \ > curl \ > ethtool \ > -- > 2.55.0 > > _______________________________________________ > dev mailing list > [email protected] > https://mail.openvswitch.org/mailman/listinfo/ovs-dev > _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
