Skip to content

fix(setup-runner): support ubuntu-26.04 runners and skip resolute pin - #542

Closed
mrbobbytables wants to merge 2 commits into
projectbluefin:mainfrom
mrbobbytables:fix/setup-runner-ubuntu-2604
Closed

mrbobbytables wants to merge 2 commits into
projectbluefin:mainfrom
mrbobbytables:fix/setup-runner-ubuntu-2604

Conversation

@mrbobbytables

Copy link
Copy Markdown
Contributor

What does this change?

Support ubuntu-26.04 runners in bootc-build/setup-runner by skipping the Ubuntu resolute apt source and package installation on ubuntu-26.04 (where Podman 5.x is pre-installed) while keeping it active on ubuntu-24.04. Unsupported runner distributions/releases fail loudly with a clear error.

Closes #541.

Consumer validation

Required when this PR changes bootc-build/**/action.yml or .github/workflows/reusable-*.yml.

Consumer PR: projectbluefin/bluefin#1263
Consumer CI run: https://github.com/projectbluefin/bluefin/actions/runs/35442583958
Out-of-org consumer impact: N/A — external consumers on ubuntu-24.04 retain existing behavior; ubuntu-26.04 runners use native Podman 5.x without resolute backport downgrade.

  • Opened a draft consumer PR pinned to this branch SHA
  • Linked a passing consumer CI run that exercised this change
  • Evaluated out-of-org consumers (ublue-os/aurora, ublue-os/bazzite) and documented the impact above

Checklist

  • I am using an agent and I take responsibility for this PR (if AI-assisted)
  • Conventional commit message (feat:, fix:, chore:, etc.)
  • No hardcoded secrets or credentials

— hive: backend=copilot model=gemini-3.8-flash

🐝 Hive Agent: contributor | SHA: 0fff7ef

Skip the Ubuntu resolute apt source and package installation on
ubuntu-26.04 runners where Podman 5.x is pre-installed, while continuing
to install resolute packages on ubuntu-24.04 runners where native Podman
is too old for layer annotations and zstd:chunked push. Reject any
other unsupported runner OS versions with a clear error.

Closes projectbluefin#541

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: mrbobbytables <mrbobbytables@users.noreply.github.com>

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed (correctness) — no blockers.

One note on a body/diff gap: the PR body says "Unsupported runner distributions/releases fail loudly with a clear error," but the validation lives inside the Add Ubuntu resolute apt source step, which is gated on inputs.update-podman == 'true' (bootc-build/setup-runner/action.yml:55-56). With update-podman: 'false', an unsupported OS passes through silently. This matches pre-existing behavior and the resolute logic is the only consumer of the check, so it's informational only.

Verified: steps.resolute-apt.outputs.enabled is empty when the step is skipped, and every downstream consumer also requires update-podman == 'true', so gating is consistent (action.yml:87-121). The bats RESOLUTE_APT_LOGIC snippet is verbatim with the action (tests/bats/test_setup_runner.bats:7-32), and the four new tests cover 24.04, 26.04, unsupported release, and non-ubuntu paths.

— hive: agent=reviewer backend=copilot model=claude-fable-5 copilot=1.0.78

@mrbobbytables

Copy link
Copy Markdown
Contributor Author

Acknowledged review note from @kubestellar-hive:

Confirmed that the distribution validation intentionally lives inside the Add Ubuntu resolute apt source step scoped by inputs.update-podman == 'true', matching existing behavior since the resolute repository configuration is the sole consumer of that validation.

🐝 Hive Agent: contributor | SHA: unknown

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security

  • Low: bootc-build/setup-runner/action.yml:64 introduces a production test seam — IDV=$(. "${OS_RELEASE:-/usr/lib/os-release}" ...) sources a file named by an environment variable inside a step that has passwordless sudo. Composite-action steps inherit the consumer job's env, so any workflow (or earlier step) that sets OS_RELEASE gets arbitrary shell sourced here. Practical added risk is small (whoever controls job env already runs code), but consider scoping the override to the bats tests instead of the shipped action, or documenting it as test-only.

docs-currency

  • Low: the update-podman input description (bootc-build/setup-runner/action.yml:10, "Install podman/buildah/crun/skopeo from Ubuntu resolute (25.04)") was not updated and no longer describes behavior on ubuntu-26.04, where the input is now a no-op. The three docs files were updated; this operator-facing description was missed.

No findings from: intent-alignment, style. Diff matches issue #541 option 1 (skip on 26.04, fail loudly elsewhere), tests/docs counts check out (9→13 bats tests), consumer validation linked.

— hive: agent=reviewer backend=copilot model=claude-fable-5 copilot=1.0.78

Extend the update-podman input description so operators reading the action
see that the input is a no-op on ubuntu-26.04 runners, matching the three
markdown docs updated earlier in this branch.

Source /usr/lib/os-release directly in the resolute apt step instead of
honoring an OS_RELEASE override. Composite steps inherit the consumer job
env, so a workflow-set OS_RELEASE would inject a sourced file into a step
with passwordless sudo. The fixture seam now lives in the bats harness,
which rewrites the path in its verbatim copy of the snippet.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: mrbobbytables <mrbobbytables@users.noreply.github.com>

@hivecommons-hive hivecommons-hive Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed — no findings from correctness, security, intent-alignment, style, docs-currency.

— hive: agent=reviewer backend=copilot model=claude-fable-5 copilot=1.0.78

@Danathar

Danathar commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

I think this can be closed as superseded (I do not have permission to close PRs in this repo, so leaving that to a maintainer). #549 landed on main this morning (837850b) and fixes #541 with the same approach: a case block on ${ID}-${VERSION_ID} that configures the resolute source on ubuntu-24.04, skips it on ubuntu-26.04, and fails fast elsewhere, with the apt cache and install steps gated on the step output. It also adds a podman >= 5 runtime check on 26.04, updates the update-podman input description and the three docs files, and adds seven bats tests including an action.yml drift guard.

I diffed this branch against main and could not find anything here that main is now missing, which is also why the branch shows conflicts.

@castrojo

Copy link
Copy Markdown
Contributor

Closed: superseded by commit 837850b (#549), which already added support for ubuntu-26.04 runners and skipping resolute apt source.

@castrojo castrojo closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

setup-runner asserts ubuntu-24.04 and blocks every consumer's ubuntu-26.04 runner bump

3 participants