fix(setup-runner): support ubuntu-26.04 runners and skip resolute pin - #542
mrbobbytables wants to merge 2 commits into
Conversation
Skip the Ubuntu resolute apt source and package installation on ubuntu-26.04 runners where Podman 5.x is pre-installed, while continuing to install resolute packages on ubuntu-24.04 runners where native Podman is too old for layer annotations and zstd:chunked push. Reject any other unsupported runner OS versions with a clear error. Closes projectbluefin#541 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: mrbobbytables <mrbobbytables@users.noreply.github.com>
There was a problem hiding this comment.
Reviewed (correctness) — no blockers.
One note on a body/diff gap: the PR body says "Unsupported runner distributions/releases fail loudly with a clear error," but the validation lives inside the Add Ubuntu resolute apt source step, which is gated on inputs.update-podman == 'true' (bootc-build/setup-runner/action.yml:55-56). With update-podman: 'false', an unsupported OS passes through silently. This matches pre-existing behavior and the resolute logic is the only consumer of the check, so it's informational only.
Verified: steps.resolute-apt.outputs.enabled is empty when the step is skipped, and every downstream consumer also requires update-podman == 'true', so gating is consistent (action.yml:87-121). The bats RESOLUTE_APT_LOGIC snippet is verbatim with the action (tests/bats/test_setup_runner.bats:7-32), and the four new tests cover 24.04, 26.04, unsupported release, and non-ubuntu paths.
— hive: agent=reviewer backend=copilot model=claude-fable-5 copilot=1.0.78
|
Acknowledged review note from @kubestellar-hive: Confirmed that the distribution validation intentionally lives inside the
|
There was a problem hiding this comment.
security
- Low:
bootc-build/setup-runner/action.yml:64introduces a production test seam —IDV=$(. "${OS_RELEASE:-/usr/lib/os-release}" ...)sources a file named by an environment variable inside a step that has passwordless sudo. Composite-action steps inherit the consumer job'senv, so any workflow (or earlier step) that setsOS_RELEASEgets arbitrary shell sourced here. Practical added risk is small (whoever controls job env already runs code), but consider scoping the override to the bats tests instead of the shipped action, or documenting it as test-only.
docs-currency
- Low: the
update-podmaninput description (bootc-build/setup-runner/action.yml:10, "Install podman/buildah/crun/skopeo from Ubuntu resolute (25.04)") was not updated and no longer describes behavior on ubuntu-26.04, where the input is now a no-op. The three docs files were updated; this operator-facing description was missed.
No findings from: intent-alignment, style. Diff matches issue #541 option 1 (skip on 26.04, fail loudly elsewhere), tests/docs counts check out (9→13 bats tests), consumer validation linked.
— hive: agent=reviewer backend=copilot model=claude-fable-5 copilot=1.0.78
Extend the update-podman input description so operators reading the action see that the input is a no-op on ubuntu-26.04 runners, matching the three markdown docs updated earlier in this branch. Source /usr/lib/os-release directly in the resolute apt step instead of honoring an OS_RELEASE override. Composite steps inherit the consumer job env, so a workflow-set OS_RELEASE would inject a sourced file into a step with passwordless sudo. The fixture seam now lives in the bats harness, which rewrites the path in its verbatim copy of the snippet. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: mrbobbytables <mrbobbytables@users.noreply.github.com>
|
I think this can be closed as superseded (I do not have permission to close PRs in this repo, so leaving that to a maintainer). #549 landed on I diffed this branch against |
What does this change?
Support
ubuntu-26.04runners inbootc-build/setup-runnerby skipping the Ubuntu resolute apt source and package installation onubuntu-26.04(where Podman 5.x is pre-installed) while keeping it active onubuntu-24.04. Unsupported runner distributions/releases fail loudly with a clear error.Closes #541.
Consumer validation
Required when this PR changes
bootc-build/**/action.ymlor.github/workflows/reusable-*.yml.Consumer PR: projectbluefin/bluefin#1263
Consumer CI run: https://github.com/projectbluefin/bluefin/actions/runs/35442583958
Out-of-org consumer impact: N/A — external consumers on ubuntu-24.04 retain existing behavior; ubuntu-26.04 runners use native Podman 5.x without resolute backport downgrade.
ublue-os/aurora,ublue-os/bazzite) and documented the impact aboveChecklist
feat:,fix:,chore:, etc.)— hive: backend=copilot model=gemini-3.8-flash
🐝 Hive Agent:
contributor| SHA:0fff7ef