From nobody Thu Oct 9 10:47:42 2025 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4cj65p2GRBz6BhcL; Thu, 09 Oct 2025 10:47:42 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4cj65p1k7Hz3FFN; Thu, 09 Oct 2025 10:47:42 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1760006862; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=dPOfM9xYw1Vbdmy6BV1EZRYO4g4eROrk7xwEux8/NwE=; b=KjB9PagTDhJ7xfbSlMhw1t5UOgvU0/PMPllU16arUWGwFoY3jw8uc6z2JDFrv+7u/KQKHO TIY7v8glOgog9Vzllgs6SjFthaeoii8hYZOscXvcYBp2xnp6Z94FRwF19OVACWnktENTHg Npt1DKycGU/rUzY0IpeWGfU8lAWhtubJF49bbwxKIzffC6DrzSZJwMK8yU+1b6Flcdr14W pPNWScffxT93oXteuWOxYmNrcsHXhcanbE4xLrID/s/Q7prGjVnw616GhM88NZu5facn0S 6kw6T9xM5B/8AucRaj6a+Z9FHQMSzkAJ+RwqU3meX1gafjHVvhA3Df+g9go6yw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1760006862; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=dPOfM9xYw1Vbdmy6BV1EZRYO4g4eROrk7xwEux8/NwE=; b=f8tEh4VWJy1sdP+oQrSZBGVNRtxZ7N3w800j/j24MHbVMEXWjUS15mQ0ob1tahwJnlvJgD T5PaRVnZYx2J9olJsjJyC5NwD1CPwy6RGWGqjojw9FcoeWoPlKx3W/fB3LVIJENHwuVwhC 0PAZA6Q0R6mdilisbUrOc1jfWeXmTACNjS+ne+KdTlG0A+mMAhTSkNzNmNVz8ubVewqQxE ZI9tty6AjVO0DTyukeDy+g1oOZFP4UeUs8u78EAs+tRfx14/EqUh4Ea6U7xP7kyZpnkuUG 18FBhTmAWj1pEFKxFVtdEY4VipjsKOE24RUqk7Ut61mLotHVy2lAehPdFZFl5w== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1760006862; a=rsa-sha256; cv=none; b=VtE9vHxWCpz7vPOhlQVKb8oCf51J9OjrdBZkKwz+7znebTri0roG92DdJ4fKLOy6Eo1K7N uBoOQuYeWZaArVlvnGAyoXYWdahoqUitYVDqVh8ERHwr9Cg1xRcF0dV5J2/qw9nvx+Ko1i my7r62xKgMuM3Iq/JLkB1PZLzOP8/FxLVVLS9Iiza8SpgVgF2PefZMo29sf8b/WY3sJy/Q d3Cbpwf4gYafgJ9dnOLvc2yuhC6zMQICsIBrlsJdFnyX7PMl9G1J67tuY5ZtCgJFBNFMGd qrXlTc7XB83Ih9VNdiDDhvGehitKEatObsTNoaO386933Rnrs70ENdg2CukXXA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4cj65p12W3z1CT9; Thu, 09 Oct 2025 10:47:42 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 599AlgOY062379; Thu, 9 Oct 2025 10:47:42 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 599AlgKD062376; Thu, 9 Oct 2025 10:47:42 GMT (envelope-from git) Date: Thu, 9 Oct 2025 10:47:42 GMT Message-Id: <202510091047.599AlgKD062376@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Doug Rabson Subject: git: e5c0b4f03692 - stable/15 - release: Avoid generating .pkgsave files in OCI images List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: dfr X-Git-Repository: src X-Git-Refname: refs/heads/stable/15 X-Git-Reftype: branch X-Git-Commit: e5c0b4f03692513261f40253d5ad26794c085991 Auto-Submitted: auto-generated The branch stable/15 has been updated by dfr: URL: https://cgit.FreeBSD.org/src/commit/?id=e5c0b4f03692513261f40253d5ad26794c085991 commit e5c0b4f03692513261f40253d5ad26794c085991 Author: Doug Rabson AuthorDate: 2025-05-28 13:32:36 +0000 Commit: Doug Rabson CommitDate: 2025-10-09 10:47:07 +0000 release: Avoid generating .pkgsave files in OCI images This also installs the pkg key from the current source tree instead of using the one currently installed on the host. Reviewed by: dch MFC after: 1 day Differential Revision: https://reviews.freebsd.org/D52615 (cherry picked from commit e21e6e96b662dcbb2f0e37ab356c9dded62a586e) --- release/scripts/make-oci-image.sh | 10 +++++++++- release/tools/oci-image-runtime.conf | 4 ++++ 2 files changed, 13 insertions(+), 1 deletion(-) diff --git a/release/scripts/make-oci-image.sh b/release/scripts/make-oci-image.sh index 6e5ad69741f7..f8ea679bfd18 100644 --- a/release/scripts/make-oci-image.sh +++ b/release/scripts/make-oci-image.sh @@ -39,10 +39,18 @@ install_packages() { local abi=$1; shift local workdir=$1; shift local rootdir=${workdir}/rootfs + + # Make sure we have the keys needed for verifying package integrity if + # not already added by a parent image. if [ ! -d ${rootdir}/usr/share/keys/pkg/trusted ]; then mkdir -p ${rootdir}/usr/share/keys/pkg/trusted fi - cp /usr/share/keys/pkg/trusted/* ${rootdir}/usr/share/keys/pkg/trusted + for i in ${curdir}/../share/keys/pkg/trusted/pkg.*; do + if [ ! -f ${rootdir}/usr/share/keys/pkg/trusted/$(basename $i) ]; then + cp $i ${rootdir}/usr/share/keys/pkg/trusted + fi + done + # We install the packages and then remove repository metadata (keeping the # metadata for what was installed). This trims more than 40Mb from the # resulting image. diff --git a/release/tools/oci-image-runtime.conf b/release/tools/oci-image-runtime.conf index 93aad1e39250..db99e5640040 100644 --- a/release/tools/oci-image-runtime.conf +++ b/release/tools/oci-image-runtime.conf @@ -9,6 +9,10 @@ OCI_BASE_IMAGE=dynamic oci_image_build() { set_cmd ${workdir} /bin/sh + # The static image installed termcap.small into /usr/share/misc/termcap + # and we are replacing it with the full termcap file. We remove the + # small one first to avoid creating a .pkgsave file. + rm ${workdir}/rootfs/usr/share/misc/termcap install_packages ${abi} ${workdir} \ FreeBSD-runtime \ FreeBSD-certctl \