|
|
@ -6,8 +6,8 @@ sys.path.append(os.path.dirname(__file__) + '/lib')
|
|
|
|
|
|
|
|
|
|
|
|
import tamarin, system, rkt
|
|
|
|
import tamarin, system, rkt
|
|
|
|
|
|
|
|
|
|
|
|
def configure_args_parser():
|
|
|
|
def create_args_parser():
|
|
|
|
|
|
|
|
'''Return a new configured ArgumentParser'''
|
|
|
|
profile_names = tamarin.get_available_profile_names()
|
|
|
|
profile_names = tamarin.get_available_profile_names()
|
|
|
|
|
|
|
|
|
|
|
|
parser = argparse.ArgumentParser(description="Generate packages for various GNU/Linux distributions")
|
|
|
|
parser = argparse.ArgumentParser(description="Generate packages for various GNU/Linux distributions")
|
|
|
@ -21,11 +21,87 @@ def configure_args_parser():
|
|
|
|
|
|
|
|
|
|
|
|
return parser
|
|
|
|
return parser
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def download_and_extract_rkt(dest_dir, verbose=True):
|
|
|
|
|
|
|
|
'''Download and extract rkt to the given destination directory'''
|
|
|
|
|
|
|
|
rkt_archive_path = tamarin.download_rkt()
|
|
|
|
|
|
|
|
system.extract_tar(rkt_archive_path, workspace_tmp)
|
|
|
|
|
|
|
|
rkt_archive_dir = tamarin.get_rkt_achive_dest_dir()
|
|
|
|
|
|
|
|
shutil.rmtree(local_rkt_dir, ignore_errors=True)
|
|
|
|
|
|
|
|
os.rename(rkt_archive_dir, dest_dir)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def download_and_extract_acbuild(dest_dir, verbose=True):
|
|
|
|
|
|
|
|
'''Download and extract acbuild to the given destination directory'''
|
|
|
|
|
|
|
|
acbuild_archive_path = tamarin.download_acbuild()
|
|
|
|
|
|
|
|
system.extract_tar(acbuild_archive_path, workspace_tmp)
|
|
|
|
|
|
|
|
acbuild_archive_dir = tamarin.get_acbuild_achive_dest_dir()
|
|
|
|
|
|
|
|
shutil.rmtree(local_acbuild_dir, ignore_errors=True)
|
|
|
|
|
|
|
|
os.rename(acbuild_archive_dir, dest_dir)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def get_cached_image_path(profile):
|
|
|
|
|
|
|
|
'''Compute and return the path for an hypothetic cached image for the given profile'''
|
|
|
|
|
|
|
|
containerbuild_hooks = profile['containerbuild']['hooks']
|
|
|
|
|
|
|
|
hasher = hashlib.sha1()
|
|
|
|
|
|
|
|
hasher.update(base_image.encode())
|
|
|
|
|
|
|
|
hasher.update(containerbuild_hooks.encode())
|
|
|
|
|
|
|
|
image_hash = hasher.hexdigest()
|
|
|
|
|
|
|
|
cache_dir = tamarin.get_workspace_subdir('cache')
|
|
|
|
|
|
|
|
return os.path.join(os.sep, cache_dir, '{:s}.aci'.format(image_hash[:12]));
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def build_image(build_workspace, aci_file, base_image, profile):
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
acbuild_flags = ["--modify", aci_file, "--work-path", build_workspace]
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# Find and export base image from rkt' store
|
|
|
|
|
|
|
|
name_pattern = base_image.split('/')[-1] + '$'
|
|
|
|
|
|
|
|
image = rkt.find_image_by_name(name_pattern, rkt_flags=rkt_flags)
|
|
|
|
|
|
|
|
rkt.export_image(image['id'], aci_file, rkt_flags=rkt_flags);
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# Build image
|
|
|
|
|
|
|
|
tamarin.run_acbuild(acbuild_flags+["set-name", "image_{:d}".format(pid)])
|
|
|
|
|
|
|
|
tamarin.run_acbuild(acbuild_flags+["mount", "add", "src", "/src", "--read-only"])
|
|
|
|
|
|
|
|
tamarin.run_acbuild(acbuild_flags+["mount", "add", "dist", "/dist"])
|
|
|
|
|
|
|
|
tamarin.run_acbuild(acbuild_flags+["mount", "add", "tamarin-hooks", "/tamarin/hooks", "--read-only"])
|
|
|
|
|
|
|
|
tamarin.run_acbuild(acbuild_flags+["mount", "add", "tamarin-lib", "/tamarin/lib", "--read-only"])
|
|
|
|
|
|
|
|
tamarin.run_acbuild(acbuild_flags+["mount", "add", "tamarin-profiles", "/tamarin/profiles", "--read-only"])
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# Configure "containerbuild" hooks environment
|
|
|
|
|
|
|
|
hooks_env = os.environ.copy()
|
|
|
|
|
|
|
|
hooks_env["PATH"] = os.environ['PATH'] + ':' + tamarin.get_workspace_subdir('acbuild')
|
|
|
|
|
|
|
|
hooks_env["TAMARIN_ACBUILD"] = " ".join([system.which('acbuild', local_acbuild_dir)]+acbuild_flags)
|
|
|
|
|
|
|
|
hooks_env["TAMARIN_ACBUILD_ENGINE"] = "chroot" if not system.which('systemctl') else "systemd-nspawn"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# Run hooks
|
|
|
|
|
|
|
|
tamarin.run_profile_hooks(profile, 'containerbuild', cwd=build_workspace, env=hooks_env)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
return aci_file
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def cleanup(build_workspace, rkt_flags):
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# Nettoyage des conteneurs
|
|
|
|
|
|
|
|
rkt.run([
|
|
|
|
|
|
|
|
"gc",
|
|
|
|
|
|
|
|
"--grace-period=0"
|
|
|
|
|
|
|
|
] + rkt_flags, as_root=True)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# Nettoyage des images obsolètes du store
|
|
|
|
|
|
|
|
rkt.run([
|
|
|
|
|
|
|
|
"image",
|
|
|
|
|
|
|
|
"gc"
|
|
|
|
|
|
|
|
] + rkt_flags, as_root=True)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# Suppression de l'espace de travail de build
|
|
|
|
|
|
|
|
shutil.rmtree(build_workspace, ignore_errors=True)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def validate_args(args):
|
|
|
|
|
|
|
|
'''TODO'''
|
|
|
|
|
|
|
|
|
|
|
|
if __name__ == "__main__":
|
|
|
|
if __name__ == "__main__":
|
|
|
|
|
|
|
|
|
|
|
|
parser = configure_args_parser()
|
|
|
|
parser = create_args_parser()
|
|
|
|
args = parser.parse_args()
|
|
|
|
args = parser.parse_args()
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
validate_args(args)
|
|
|
|
|
|
|
|
|
|
|
|
# Verify project directory
|
|
|
|
# Verify project directory
|
|
|
|
project_dir = os.path.abspath(args.project_directory)
|
|
|
|
project_dir = os.path.abspath(args.project_directory)
|
|
|
|
output_dir = os.path.abspath(args.output)
|
|
|
|
output_dir = os.path.abspath(args.output)
|
|
|
@ -38,21 +114,11 @@ if __name__ == "__main__":
|
|
|
|
|
|
|
|
|
|
|
|
local_rkt_dir = tamarin.get_workspace_subdir('rkt')
|
|
|
|
local_rkt_dir = tamarin.get_workspace_subdir('rkt')
|
|
|
|
if not system.which('rkt', local_rkt_dir):
|
|
|
|
if not system.which('rkt', local_rkt_dir):
|
|
|
|
# Download and extract rkt
|
|
|
|
download_and_extract_rkt(local_rkt_dir)
|
|
|
|
rkt_archive_path = tamarin.download_rkt()
|
|
|
|
|
|
|
|
system.extract_tar(rkt_archive_path, workspace_tmp)
|
|
|
|
|
|
|
|
rkt_archive_dir = tamarin.get_rkt_achive_dest_dir()
|
|
|
|
|
|
|
|
shutil.rmtree(local_rkt_dir, ignore_errors=True)
|
|
|
|
|
|
|
|
os.rename(rkt_archive_dir, local_rkt_dir)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
local_acbuild_dir = tamarin.get_workspace_subdir('acbuild')
|
|
|
|
local_acbuild_dir = tamarin.get_workspace_subdir('acbuild')
|
|
|
|
if not system.which('acbuild', local_acbuild_dir):
|
|
|
|
if not system.which('acbuild', local_acbuild_dir):
|
|
|
|
# Download and extract acbuild
|
|
|
|
download_and_extract_acbuild(local_acbuild_dir)
|
|
|
|
acbuild_archive_path = tamarin.download_acbuild()
|
|
|
|
|
|
|
|
system.extract_tar(acbuild_archive_path, workspace_tmp)
|
|
|
|
|
|
|
|
acbuild_archive_dir = tamarin.get_acbuild_achive_dest_dir()
|
|
|
|
|
|
|
|
shutil.rmtree(local_acbuild_dir, ignore_errors=True)
|
|
|
|
|
|
|
|
os.rename(acbuild_archive_dir, local_acbuild_dir)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
pid = os.getpid()
|
|
|
|
pid = os.getpid()
|
|
|
|
build_workspace = tamarin.get_workspace_subdir('tmp/build_{:d}'.format(pid))
|
|
|
|
build_workspace = tamarin.get_workspace_subdir('tmp/build_{:d}'.format(pid))
|
|
|
@ -61,7 +127,8 @@ if __name__ == "__main__":
|
|
|
|
rkt_flags = ["--dir={:s}".format(rkt_store)]
|
|
|
|
rkt_flags = ["--dir={:s}".format(rkt_store)]
|
|
|
|
|
|
|
|
|
|
|
|
base_image = profile['profile']['default_image']
|
|
|
|
base_image = profile['profile']['default_image']
|
|
|
|
# If the base image is Docker-based, preload it and get its name from the store
|
|
|
|
|
|
|
|
|
|
|
|
# If the base image is Docker-based, download it
|
|
|
|
if base_image.startswith('docker://'):
|
|
|
|
if base_image.startswith('docker://'):
|
|
|
|
rkt.run([
|
|
|
|
rkt.run([
|
|
|
|
"fetch",
|
|
|
|
"fetch",
|
|
|
@ -70,44 +137,15 @@ if __name__ == "__main__":
|
|
|
|
] + rkt_flags)
|
|
|
|
] + rkt_flags)
|
|
|
|
|
|
|
|
|
|
|
|
aci_file = os.path.join(os.sep, build_workspace, 'image.aci')
|
|
|
|
aci_file = os.path.join(os.sep, build_workspace, 'image.aci')
|
|
|
|
acbuild_flags = ["--modify", aci_file, "--work-path", build_workspace]
|
|
|
|
cached_image_file = get_cached_image_path(profile)
|
|
|
|
|
|
|
|
|
|
|
|
# Use cached image base on base_image and containerbuild hooks
|
|
|
|
|
|
|
|
containerbuild_hooks = profile['containerbuild']['hooks']
|
|
|
|
|
|
|
|
hasher = hashlib.sha1()
|
|
|
|
|
|
|
|
hasher.update(base_image.encode())
|
|
|
|
|
|
|
|
hasher.update(containerbuild_hooks.encode())
|
|
|
|
|
|
|
|
image_hash = hasher.hexdigest()
|
|
|
|
|
|
|
|
cache_dir = tamarin.get_workspace_subdir('cache')
|
|
|
|
|
|
|
|
cached_image_file = os.path.join(os.sep, cache_dir, '{:s}.aci'.format(image_hash[:12]));
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
if not args.rebuild and os.path.exists(cached_image_file):
|
|
|
|
if not args.rebuild and os.path.exists(cached_image_file):
|
|
|
|
# Copy cached image
|
|
|
|
# Copy cached image
|
|
|
|
shutil.copyfile(cached_image_file, aci_file)
|
|
|
|
shutil.copyfile(cached_image_file, aci_file)
|
|
|
|
else:
|
|
|
|
else:
|
|
|
|
# Find and export base image from rkt' store
|
|
|
|
build_image(build_workspace, aci_file, base_image, profile)
|
|
|
|
name_pattern = base_image.split('/')[-1] + '$'
|
|
|
|
# Cache image
|
|
|
|
image = rkt.find_image_by_name(name_pattern, rkt_flags=rkt_flags)
|
|
|
|
shutil.copyfile(aci_file, cached_image_file)
|
|
|
|
rkt.export_image(image['id'], aci_file, rkt_flags=rkt_flags);
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# Build image
|
|
|
|
|
|
|
|
tamarin.run_acbuild(acbuild_flags+["set-name", "image_{:d}".format(pid)])
|
|
|
|
|
|
|
|
tamarin.run_acbuild(acbuild_flags+["mount", "add", "src", "/src", "--read-only"])
|
|
|
|
|
|
|
|
tamarin.run_acbuild(acbuild_flags+["mount", "add", "dist", "/dist"])
|
|
|
|
|
|
|
|
tamarin.run_acbuild(acbuild_flags+["mount", "add", "tamarin-hooks", "/tamarin/hooks", "--read-only"])
|
|
|
|
|
|
|
|
tamarin.run_acbuild(acbuild_flags+["mount", "add", "tamarin-lib", "/tamarin/lib", "--read-only"])
|
|
|
|
|
|
|
|
tamarin.run_acbuild(acbuild_flags+["mount", "add", "tamarin-profiles", "/tamarin/profiles", "--read-only"])
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# Execute containerbuild hooks
|
|
|
|
|
|
|
|
cb_hooks_env = os.environ.copy()
|
|
|
|
|
|
|
|
cb_hooks_env["PATH"] = os.environ['PATH'] + ':' + local_acbuild_dir
|
|
|
|
|
|
|
|
cb_hooks_env["TAMARIN_ACBUILD"] = " ".join([system.which('acbuild', local_acbuild_dir)]+acbuild_flags)
|
|
|
|
|
|
|
|
cb_hooks_env["TAMARIN_ACBUILD_ENGINE"] = "chroot" if not system.which('systemctl') else "systemd-nspawn"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
tamarin.run_profile_hooks(profile, 'containerbuild', cwd=build_workspace, env=cb_hooks_env)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# Cache image
|
|
|
|
|
|
|
|
shutil.copyfile(aci_file, cached_image_file)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# Start container
|
|
|
|
# Start container
|
|
|
|
rkt.run(rkt_flags+[
|
|
|
|
rkt.run(rkt_flags+[
|
|
|
@ -128,15 +166,4 @@ if __name__ == "__main__":
|
|
|
|
], as_root=True)
|
|
|
|
], as_root=True)
|
|
|
|
|
|
|
|
|
|
|
|
# Cleanup
|
|
|
|
# Cleanup
|
|
|
|
|
|
|
|
cleanup(build_workspace, rkt_flags)
|
|
|
|
rkt.run([
|
|
|
|
|
|
|
|
"gc",
|
|
|
|
|
|
|
|
"--grace-period=0"
|
|
|
|
|
|
|
|
] + rkt_flags, as_root=True)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
rkt.run([
|
|
|
|
|
|
|
|
"image",
|
|
|
|
|
|
|
|
"gc"
|
|
|
|
|
|
|
|
] + rkt_flags, as_root=True)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
shutil.rmtree(build_workspace, ignore_errors=True)
|
|
|
|
|
|
|
|