Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
149 commits
Select commit Hold shift + click to select a range
be902ad
app-admin/sudo: Sync with Gentoo
Nov 17, 2025
4ac6ea7
app-arch/libarchive: Sync with Gentoo
Nov 17, 2025
7ebd653
app-arch/pigz: Sync with Gentoo
Nov 17, 2025
db40f1b
app-arch/zstd: Sync with Gentoo
Nov 17, 2025
5d2441d
app-containers/aardvark-dns: Sync with Gentoo
Nov 17, 2025
fd57f9c
app-containers/containerd: Sync with Gentoo
Nov 17, 2025
4317f3a
app-containers/incus: Sync with Gentoo
Nov 17, 2025
3f6f439
app-containers/podman: Sync with Gentoo
Nov 17, 2025
65fc80a
app-containers/runc: Sync with Gentoo
Nov 17, 2025
304271f
app-crypt/gnupg: Sync with Gentoo
Nov 17, 2025
869fb83
app-editors/nano: Sync with Gentoo
Nov 17, 2025
7505fb9
app-editors/vim: Sync with Gentoo
Nov 17, 2025
bf898ba
app-editors/vim-core: Sync with Gentoo
Nov 17, 2025
a92d70a
app-emulation/qemu: Sync with Gentoo
Nov 17, 2025
d2471d3
app-misc/pax-utils: Sync with Gentoo
Nov 17, 2025
0338b66
app-portage/gentoolkit: Sync with Gentoo
Nov 17, 2025
05b5a85
app-portage/portage-utils: Sync with Gentoo
Nov 17, 2025
81d6da5
app-shells/bash: Sync with Gentoo
Nov 17, 2025
b73a48c
app-text/mandoc: Sync with Gentoo
Nov 17, 2025
8a856d9
app-text/scdoc: Sync with Gentoo
Nov 17, 2025
f0298ee
dev-build/cmake: Sync with Gentoo
Nov 17, 2025
6bcf6e0
dev-build/make: Sync with Gentoo
Nov 17, 2025
dfd19cc
dev-build/meson: Sync with Gentoo
Nov 17, 2025
c439f20
dev-db/sqlite: Sync with Gentoo
Nov 17, 2025
3ffcfaa
dev-debug/gdb: Sync with Gentoo
Nov 17, 2025
dc25531
dev-debug/strace: Sync with Gentoo
Nov 17, 2025
78fc8dd
dev-go/go-md2man: Sync with Gentoo
Nov 17, 2025
fe2a1d1
dev-lang/go: Sync with Gentoo
Nov 17, 2025
fd6d41f
dev-lang/nasm: Sync with Gentoo
Nov 17, 2025
e1086aa
dev-lang/perl: Sync with Gentoo
Nov 17, 2025
7094f2d
dev-lang/python: Sync with Gentoo
Nov 17, 2025
3cea51b
dev-lang/rust: Sync with Gentoo
Nov 17, 2025
be35575
dev-lang/swig: Sync with Gentoo
Nov 17, 2025
b1f02fb
dev-lang/tcl: Sync with Gentoo
Nov 17, 2025
d6a5eb4
dev-libs/elfutils: Sync with Gentoo
Nov 17, 2025
1c28482
dev-libs/glib: Sync with Gentoo
Nov 17, 2025
5d9cc3a
dev-libs/jsoncpp: Sync with Gentoo
Nov 17, 2025
bfa1094
dev-libs/libgpg-error: Sync with Gentoo
Nov 17, 2025
e0e9411
dev-libs/libpcre2: Sync with Gentoo
Nov 17, 2025
1795800
dev-libs/libxml2: Sync with Gentoo
Nov 17, 2025
c560039
dev-libs/nspr: Sync with Gentoo
Nov 17, 2025
f4cd88d
dev-libs/opensc: Sync with Gentoo
Nov 17, 2025
bd71e59
dev-libs/openssl: Sync with Gentoo
Nov 17, 2025
536561d
dev-libs/protobuf: Sync with Gentoo
Nov 17, 2025
ae36261
dev-perl/File-Slurper: Sync with Gentoo
Nov 17, 2025
368eb89
dev-python/cryptography: Sync with Gentoo
Nov 17, 2025
333c816
dev-python/cython: Sync with Gentoo
Nov 17, 2025
cfa5011
dev-python/docutils: Sync with Gentoo
Nov 17, 2025
159e847
dev-python/lxml: Sync with Gentoo
Nov 17, 2025
684b53e
dev-python/markupsafe: Sync with Gentoo
Nov 17, 2025
b00c0f3
dev-python/pillow: Sync with Gentoo
Nov 17, 2025
c3b2a51
dev-python/platformdirs: Sync with Gentoo
Nov 17, 2025
190eaf5
dev-python/resolvelib: Sync with Gentoo
Nov 17, 2025
6b65b35
dev-python/rich: Sync with Gentoo
Nov 17, 2025
3104109
dev-python/tomli: Sync with Gentoo
Nov 17, 2025
65fbe7f
dev-python/trove-classifiers: Sync with Gentoo
Nov 17, 2025
385cc82
dev-util/bpftool: Sync with Gentoo
Nov 17, 2025
9ed0543
dev-util/gdbus-codegen: Sync with Gentoo
Nov 17, 2025
537ba66
dev-util/glib-utils: Sync with Gentoo
Nov 17, 2025
0a45037
dev-util/maturin: Sync with Gentoo
Nov 17, 2025
6e256f0
dev-util/pahole: Sync with Gentoo
Nov 17, 2025
dde0d2e
dev-util/perf: Sync with Gentoo
Nov 17, 2025
deee272
dev-util/xdelta: Sync with Gentoo
Nov 17, 2025
4c10ec1
dev-vcs/git: Sync with Gentoo
Nov 17, 2025
8548ced
eclass/cmake: Sync with Gentoo
Nov 17, 2025
07cbdbd
eclass/guile-utils: Sync with Gentoo
Nov 17, 2025
2694c6f
eclass/meson: Sync with Gentoo
Nov 17, 2025
65fd181
eclass/ninja-utils: Sync with Gentoo
Nov 17, 2025
7696440
eclass/toolchain: Sync with Gentoo
Nov 17, 2025
bf26081
media-libs/libpng: Sync with Gentoo
Nov 17, 2025
5860005
net-dns/bind: Sync with Gentoo
Nov 17, 2025
d1e7b89
net-fs/cifs-utils: Sync with Gentoo
Nov 17, 2025
1c795d5
net-fs/samba: Sync with Gentoo
Nov 17, 2025
324a10a
net-libs/gnutls: Sync with Gentoo
Nov 17, 2025
0ad1c4c
net-libs/libpsl: Sync with Gentoo
Nov 17, 2025
74f3448
net-libs/libtirpc: Sync with Gentoo
Nov 17, 2025
e46ab6d
net-libs/nghttp2: Sync with Gentoo
Nov 17, 2025
e1c1695
net-misc/curl: Sync with Gentoo
Nov 17, 2025
07b5146
net-misc/iperf: Sync with Gentoo
Nov 17, 2025
3ab87bf
net-misc/ntp: Sync with Gentoo
Nov 17, 2025
1c8162b
net-misc/openssh: Sync with Gentoo
Nov 17, 2025
26402f9
net-misc/rsync: Sync with Gentoo
Nov 17, 2025
2a2bde7
net-misc/wget: Sync with Gentoo
Nov 17, 2025
e681df8
profiles: Sync with Gentoo
Nov 17, 2025
fd8f583
scripts: Sync with Gentoo
Nov 17, 2025
64c4661
sec-keys/openpgp-keys-gentoo-release: Sync with Gentoo
Nov 17, 2025
15c8a78
sys-apps/coreutils: Sync with Gentoo
Nov 17, 2025
e933d4e
sys-apps/dbus: Sync with Gentoo
Nov 17, 2025
f2b16ad
sys-apps/file: Sync with Gentoo
Nov 17, 2025
23759a6
sys-apps/hwdata: Sync with Gentoo
Nov 17, 2025
09d1a67
sys-apps/i2c-tools: Sync with Gentoo
Nov 17, 2025
b08ed02
sys-apps/iproute2: Sync with Gentoo
Nov 17, 2025
e277e7a
sys-apps/kbd: Sync with Gentoo
Nov 17, 2025
37ec603
sys-apps/kexec-tools: Sync with Gentoo
Nov 17, 2025
dcdebc0
sys-apps/kmod: Sync with Gentoo
Nov 17, 2025
57e898d
sys-apps/less: Sync with Gentoo
Nov 17, 2025
a35b704
sys-apps/locale-gen: Sync with Gentoo
Nov 17, 2025
4da2ea4
sys-apps/man-db: Sync with Gentoo
Nov 17, 2025
24436dc
sys-apps/nvme-cli: Sync with Gentoo
Nov 17, 2025
c5a6160
sys-apps/pciutils: Sync with Gentoo
Nov 17, 2025
55efb2a
sys-apps/portage: Sync with Gentoo
Nov 17, 2025
7591fa5
sys-apps/pv: Sync with Gentoo
Nov 17, 2025
5cb3dac
sys-apps/shadow: Sync with Gentoo
Nov 17, 2025
e5ca3e1
sys-apps/systemd: Sync with Gentoo
Nov 17, 2025
f98af79
sys-apps/texinfo: Sync with Gentoo
Nov 17, 2025
ac58f17
sys-apps/util-linux: Sync with Gentoo
Nov 17, 2025
82eb844
sys-auth/pambase: Sync with Gentoo
Nov 17, 2025
004bd48
sys-block/thin-provisioning-tools: Sync with Gentoo
Nov 17, 2025
5b79c16
sys-boot/grub: Sync with Gentoo
Nov 17, 2025
e20aef6
sys-devel/binutils: Sync with Gentoo
Nov 17, 2025
bb944bd
sys-devel/crossdev: Sync with Gentoo
Nov 17, 2025
2daf811
sys-devel/gcc: Sync with Gentoo
Nov 17, 2025
cb09e06
sys-firmware/intel-microcode: Sync with Gentoo
Nov 17, 2025
3fd3e15
sys-fs/btrfs-progs: Sync with Gentoo
Nov 17, 2025
3161f51
sys-fs/inotify-tools: Sync with Gentoo
Nov 17, 2025
dde4435
sys-fs/squashfs-tools: Sync with Gentoo
Nov 17, 2025
d21610e
sys-fs/squashfs-tools-ng: Sync with Gentoo
Nov 17, 2025
cbae819
sys-fs/zfs: Sync with Gentoo
Nov 17, 2025
e0ed9f4
sys-kernel/dracut: Sync with Gentoo
Nov 17, 2025
f29cf7f
sys-libs/binutils-libs: Sync with Gentoo
Nov 17, 2025
b3c59a5
sys-libs/cracklib: Sync with Gentoo
Nov 17, 2025
3c198d3
sys-libs/glibc: Sync with Gentoo
Nov 17, 2025
2a7840d
sys-libs/libnvme: Sync with Gentoo
Nov 17, 2025
26c2d0c
sys-libs/libunwind: Sync with Gentoo
Nov 17, 2025
c618b62
sys-libs/pam: Sync with Gentoo
Nov 17, 2025
6d5f5dc
sys-libs/readline: Sync with Gentoo
Nov 17, 2025
0e6a1db
sys-libs/talloc: Sync with Gentoo
Nov 17, 2025
a5a8d79
sys-libs/tdb: Sync with Gentoo
Nov 17, 2025
9534069
sys-libs/tevent: Sync with Gentoo
Nov 17, 2025
7a5e4f3
x11-drivers/nvidia-drivers: Sync with Gentoo
Nov 17, 2025
910f1ba
acct-group/shadow: Add from Gentoo
krnowak Nov 17, 2025
8a4b08a
.github: Add acct-group/shadow to automation
krnowak Nov 17, 2025
90a61d2
overlay profiles: Skip clang
krnowak Nov 17, 2025
529b598
overlay profiles: Unmask thin-provisioning-tools, add accept keywords…
krnowak Nov 25, 2025
fbb0d0c
overlay coreos/{user-patches,config}: Overrides for thin-provisioning…
krnowak Nov 17, 2025
3d70da0
overlay profiles: Provide app-doc/info-manual
krnowak Nov 17, 2025
2ed022e
app-containers/containerd: Add 2.1.5
krnowak Nov 7, 2025
69490f0
overlay profiles: Drop accept keywords for app-editors/vim{,-core}
krnowak Nov 20, 2025
d9e1477
overlay profiles: Enable USE=static-libs for virtual/zlib
krnowak Nov 21, 2025
758d54b
overlay profiles: Drop accept keywords for net-misc/curl
krnowak Nov 21, 2025
1768ba6
overlay dev-libs/jose: Move to portage-stable
krnowak Nov 21, 2025
1afb85b
dev-libs/jose: Sync with Gentoo
krnowak Nov 21, 2025
6c4f176
.github: Add dev-libs/jose to automation
krnowak Nov 21, 2025
97fbc23
overlay profiles: Update accept keywords for dev-libs/jose
krnowak Nov 21, 2025
25acd75
overlay sys-fs/overlaybd: Depend on virtual/zlib instead of sys-libs/…
krnowak Nov 21, 2025
0c21b66
overlay profiles: Drop accept keywords for sys-apps/coreutils
krnowak Nov 21, 2025
257a3c6
build_library: Add a hack for shadow group ownership
krnowak Nov 28, 2025
b5994ce
overlay sys-apps/baselayout: Pull in shadow group fixes
krnowak Nov 28, 2025
bb5bbf9
changelog: Add entries
krnowak Nov 24, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 2 additions & 0 deletions .github/workflows/portage-stable-packages-list
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,7 @@ acct-group/portage
acct-group/render
acct-group/root
acct-group/sgx
acct-group/shadow
acct-group/sshd
acct-group/systemd-coredump
acct-group/systemd-journal
Expand Down Expand Up @@ -246,6 +247,7 @@ dev-libs/gmp
dev-libs/gobject-introspection-common
dev-libs/inih
dev-libs/jansson
dev-libs/jose
dev-libs/json-c
dev-libs/jsoncpp
dev-libs/libaio
Expand Down
11 changes: 11 additions & 0 deletions build_library/build_image_util.sh
Original file line number Diff line number Diff line change
Expand Up @@ -728,6 +728,17 @@ EOF
sudo setfiles -Dv -r "${root_fs_dir}" "${root_fs_dir}"/etc/selinux/mcs/contexts/files/file_contexts "${root_fs_dir}"/etc
fi

# Temporary hack: set group ownership of /etc/{g,}shadow to the
# shadow group, that way unix_chkpwd, chage and expiry can act on
# those files.
#
# This permissions setting should likely be done in some ebuild, but
# currently files in /usr/share/baselayout are installed by the
# baselayout package, we don't want to add more deps to it.
sudo chgrp \
--reference="${root_fs_dir}/usr/bin/chage" \
"${root_fs_dir}"/{etc,usr/share/baselayout}/{g,}shadow

# Backup the /etc contents to /usr/share/flatcar/etc to serve as
# source for creating missing files. Make sure that the preexisting
# /usr/share/flatcar/etc does not have any meaningful (non-empty)
Expand Down
1 change: 1 addition & 0 deletions changelog/changes/2025-11-28-weekly-updates.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- `/etc/shadow`, `/etc/gshadow` are now owned by the `shadow` group, `/usr/bin/unix_chkpwd`, `/usr/bin/chage` and `/usr/bin/expiry` are now also owned by the `shadow` group with a sticky bit enabled.
13 changes: 13 additions & 0 deletions changelog/updates/2025-11-24-weekly-updates.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
- SDK: meson ([1.9.1](https://mesonbuild.com/Release-notes-for-1-9-0.html) (includes [1.8.0](https://mesonbuild.com/Release-notes-for-1-8-0.html)))
- SDK: nasm ([3.01](https://www.nasm.us/docs/3.01/nasmac.html) (includes [3.00](https://www.nasm.us/docs/3.00/nasmac.html)))
- base, dev: hwdata ([0.400](https://github.com/vcrhonek/hwdata/releases/tag/v0.400))
- base, dev: intel-microcode ([20251111_p20251112](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20251111))
- base, dev: jose ([14](https://github.com/latchset/jose/releases/tag/v14) (includes [13](https://github.com/latchset/jose/releases/tag/v13)))
- base, dev: less ([685](https://greenwoodsoftware.com/less/news.685.html))
- base, dev: libgpg-error ([1.56](https://github.com/gpg/libgpg-error/releases/tag/libgpg-error-1.56))
- base, dev: openssl ([3.5.4](https://github.com/openssl/openssl/releases/tag/openssl-3.5.4) (includes [3.5.3](https://github.com/openssl/openssl/releases/tag/openssl-3.5.3), [3.5.2](https://github.com/openssl/openssl/releases/tag/openssl-3.5.2), [3.5.1](https://github.com/openssl/openssl/releases/tag/openssl-3.5.1), [3.5.0](https://github.com/openssl/openssl/releases/tag/openssl-3.5.0)))
- base, dev: thin-provisioning-tools ([1.3.0](https://raw.githubusercontent.com/device-mapper-utils/thin-provisioning-tools/refs/tags/v1.3.0/CHANGES) (includes [1.2.2](https://raw.githubusercontent.com/device-mapper-utils/thin-provisioning-tools/refs/tags/v1.2.2/CHANGES), [1.2.1](https://raw.githubusercontent.com/device-mapper-utils/thin-provisioning-tools/refs/tags/v1.2.1/CHANGES), [1.2.0](https://raw.githubusercontent.com/device-mapper-utils/thin-provisioning-tools/refs/tags/v1.2.0/CHANGES), [1.1.0](https://raw.githubusercontent.com/device-mapper-utils/thin-provisioning-tools/refs/tags/v1.1.0/CHANGES), [1.0.14](https://raw.githubusercontent.com/device-mapper-utils/thin-provisioning-tools/refs/tags/v1.0.14/CHANGES), [1.0.13](https://raw.githubusercontent.com/device-mapper-utils/thin-provisioning-tools/refs/tags/v1.0.13/CHANGES), [1.0.12](https://raw.githubusercontent.com/device-mapper-utils/thin-provisioning-tools/refs/tags/v1.0.12/CHANGES), [1.0.11](https://raw.githubusercontent.com/device-mapper-utils/thin-provisioning-tools/refs/tags/v1.0.11/CHANGES)))
- sysext-podman: aardvark-dns ([1.15.0](https://github.com/containers/aardvark-dns/releases/tag/v1.15.0))
- sysext-python: platformdirs ([4.5.0](https://github.com/tox-dev/platformdirs/releases/tag/4.5.0))
- sysext-python: resolvelib ([1.2.1](https://raw.githubusercontent.com/sarugaku/resolvelib/refs/tags/1.2.1/CHANGELOG.rst))
- sysext-python: rich ([14.2.0](https://github.com/Textualize/rich/releases/tag/v14.2.0))
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
# This is to disable building thin_migrate tool.
export ECARGO_EXTRA_ARGS=--no-default-features
Original file line number Diff line number Diff line change
@@ -0,0 +1,81 @@
From c5fbb32be0509e4368268a79e7aacc6b5e34d28e Mon Sep 17 00:00:00 2001
From: Krzesimir Nowak <knowak@microsoft.com>
Date: Thu, 20 Nov 2025 13:16:09 +0100
Subject: [PATCH 1/2] [build] Simplify installation of symlinks and manpages

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
---
Makefile | 52 ++++++++--------------------------------------------
1 file changed, 8 insertions(+), 44 deletions(-)

diff --git a/Makefile b/Makefile
index b04937aa..44c99c99 100644
--- a/Makefile
+++ b/Makefile
@@ -55,55 +55,19 @@ TOOLS:=\
era_invalidate \
era_restore

+# This must be two empty lines to get a newline.
+define NEWLINE
+
+
+endef
+
MANPAGES:=$(patsubst %,man8/%.8,$(TOOLS))

install: $(MANPAGES)
$(INSTALL_DIR) $(BINDIR)
$(INSTALL_PROGRAM) $(PDATA_TOOLS) $(BINDIR)
- ln -s -f pdata_tools $(BINDIR)/cache_check
- ln -s -f pdata_tools $(BINDIR)/cache_dump
- ln -s -f pdata_tools $(BINDIR)/cache_metadata_size
- ln -s -f pdata_tools $(BINDIR)/cache_repair
- ln -s -f pdata_tools $(BINDIR)/cache_restore
- ln -s -f pdata_tools $(BINDIR)/cache_writeback
- ln -s -f pdata_tools $(BINDIR)/thin_check
- ln -s -f pdata_tools $(BINDIR)/thin_delta
- ln -s -f pdata_tools $(BINDIR)/thin_dump
- ln -s -f pdata_tools $(BINDIR)/thin_ls
- ln -s -f pdata_tools $(BINDIR)/thin_repair
- ln -s -f pdata_tools $(BINDIR)/thin_restore
- ln -s -f pdata_tools $(BINDIR)/thin_rmap
- ln -s -f pdata_tools $(BINDIR)/thin_metadata_size
- ln -s -f pdata_tools $(BINDIR)/thin_metadata_pack
- ln -s -f pdata_tools $(BINDIR)/thin_metadata_unpack
- ln -s -f pdata_tools $(BINDIR)/thin_migrate
- ln -s -f pdata_tools $(BINDIR)/thin_trim
- ln -s -f pdata_tools $(BINDIR)/era_check
- ln -s -f pdata_tools $(BINDIR)/era_dump
- ln -s -f pdata_tools $(BINDIR)/era_invalidate
- ln -s -f pdata_tools $(BINDIR)/era_restore
+ $(foreach tool, $(TOOLS), ln -s -f pdata_tools $(BINDIR)/$(tool); $(NEWLINE))
$(INSTALL_DIR) $(MANPATH)/man8
- $(INSTALL_DATA) man8/cache_check.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/cache_dump.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/cache_metadata_size.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/cache_repair.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/cache_restore.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/cache_writeback.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/thin_check.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/thin_delta.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/thin_dump.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/thin_ls.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/thin_repair.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/thin_restore.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/thin_rmap.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/thin_metadata_size.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/thin_metadata_pack.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/thin_metadata_unpack.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/thin_migrate.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/era_check.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/era_dump.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/era_restore.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/era_invalidate.8 $(MANPATH)/man8
- $(INSTALL_DATA) man8/thin_trim.8 $(MANPATH)/man8
+ $(foreach tool, $(TOOLS), $(INSTALL_DATA) man8/$(tool).8 $(MANPATH)/man8; $(NEWLINE))

.PHONY: install
--
2.51.2

Original file line number Diff line number Diff line change
@@ -0,0 +1,135 @@
From 74215dade7bbddbfc0a46e1903fc289a56df3915 Mon Sep 17 00:00:00 2001
From: Krzesimir Nowak <knowak@microsoft.com>
Date: Thu, 20 Nov 2025 13:17:36 +0100
Subject: [PATCH 2/2] [all] Make thin_migrate tool optional

The tool pulls in, indirectly through the devicemapper crate, a
dependency on libclang. Make it possible to skip the tool to avoid the
dependency, but keep it enabled by default.

Signed-off-by: Krzesimir Nowak <knowak@microsoft.com>
---
Cargo.toml | 4 +++-
Makefile | 20 ++++++++++++++++++--
src/bin/pdata_tools.rs | 1 +
src/commands/mod.rs | 1 +
src/thin/mod.rs | 1 +
5 files changed, 24 insertions(+), 3 deletions(-)

diff --git a/Cargo.toml b/Cargo.toml
index 8594c6ba..155285a8 100644
--- a/Cargo.toml
+++ b/Cargo.toml
@@ -18,7 +18,7 @@ clap = { version = "4.5", default-features = false, features = [
] }
crc32c = "0.6"
data-encoding = "2.9"
-devicemapper = "0.34"
+devicemapper ={ version = "0.34", optional = true }
exitcode = "1.1.2"
fixedbitset = "0.5"
flate2 = "1.1"
@@ -51,9 +51,11 @@ tempfile = "3.23"
thinp = { path = ".", features = ["devtools"] }

[features]
+default = ["thin_migrate"]
devtools = ["ratatui", "termion"]
io_uring = ["dep:io-uring"]
no_cleanup = []
+thin_migrate = ["dep:devicemapper"]

[profile.release]
debug = true
diff --git a/Makefile b/Makefile
index 44c99c99..a2dd51a4 100644
--- a/Makefile
+++ b/Makefile
@@ -2,9 +2,10 @@ V=@

PDATA_TOOLS:=\
target/release/pdata_tools
+CARGO_FLAGS:=$(if $(DISABLE_THIN_MIGRATE),--no-default-features)

$(PDATA_TOOLS):
- $(V) cargo build --release
+ $(V) cargo build --release $(CARGO_FLAGS)

PREFIX:=/usr
BINDIR:=$(DESTDIR)$(PREFIX)/sbin
@@ -31,6 +32,21 @@ clean:
cargo clean
$(RM) man8/*.8

+HAS_PDATA_TOOLS_BINARY:=$(shell if [ -f $(PDATA_TOOLS) ]; then echo 1; fi)
+ifneq ($(HAS_PDATA_TOOLS_BINARY),)
+
+HAS_THIN_MIGRATE:=$(shell grep -qF thin_migrate.rs $(PDATA_TOOLS).d && echo 1)
+
+ifneq ($(DISABLE_THIN_MIGRATE),)
+$(warning DISABLE_THIN_MIGRATE variable is ignored, the pdata_tools binary exists and it has $(if $(HAS_THIN_MIGRATE),,no )thin_migrate tool built in)
+endif
+
+else
+
+HAS_THIN_MIGRATE:=$(if $(DISABLE_THIN_MIGRATE),,1)
+
+endif
+
TOOLS:=\
cache_check \
cache_dump \
@@ -42,13 +58,13 @@ TOOLS:=\
thin_delta \
thin_dump \
thin_ls \
+ $(if $(HAS_THIN_MIGRATE),thin_migrate) \
thin_repair \
thin_restore \
thin_rmap \
thin_metadata_size \
thin_metadata_pack \
thin_metadata_unpack \
- thin_migrate \
thin_trim \
era_check \
era_dump \
diff --git a/src/bin/pdata_tools.rs b/src/bin/pdata_tools.rs
index c288fe03..67ef0d7d 100644
--- a/src/bin/pdata_tools.rs
+++ b/src/bin/pdata_tools.rs
@@ -29,6 +29,7 @@ fn register_commands<'a>() -> Vec<Box<dyn Command<'a>>> {
Box::new(thin_metadata_pack::ThinMetadataPackCommand),
Box::new(thin_metadata_size::ThinMetadataSizeCommand),
Box::new(thin_metadata_unpack::ThinMetadataUnpackCommand),
+ #[cfg(feature = "thin_migrate")]
Box::new(thin_migrate::ThinMigrateCommand),
Box::new(thin_repair::ThinRepairCommand),
Box::new(thin_restore::ThinRestoreCommand),
diff --git a/src/commands/mod.rs b/src/commands/mod.rs
index 5eeb66ab..72481eba 100644
--- a/src/commands/mod.rs
+++ b/src/commands/mod.rs
@@ -17,6 +17,7 @@ pub mod thin_ls;
pub mod thin_metadata_pack;
pub mod thin_metadata_size;
pub mod thin_metadata_unpack;
+#[cfg(feature = "thin_migrate")]
pub mod thin_migrate;
pub mod thin_repair;
pub mod thin_restore;
diff --git a/src/thin/mod.rs b/src/thin/mod.rs
index 1ef0e1be..eeed031e 100644
--- a/src/thin/mod.rs
+++ b/src/thin/mod.rs
@@ -10,6 +10,7 @@ pub mod ls;
pub mod metadata;
pub mod metadata_repair;
pub mod metadata_size;
+#[cfg(feature = "thin_migrate")]
pub mod migrate;
pub mod repair;
pub mod restore;
--
2.51.2

Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
The patches make the thin_migrate tool optional, as this seems to be
the thing that pulls in devicemapper crate, which in order requires
bindgen crate, which in turn depends on libclang. Since thin_migrate
tools was never a part of Flatcar yet, we can skip building it for
now. If users will need the tool, we can think about adding it at a
cost of building clang in SDK builds.

The patches were filed to upstream:

https://github.com/device-mapper-utils/thin-provisioning-tools/pull/1

If they get accepted, we can try convincing Gentoo to add
"USE=+migrate" to the ebuild and hide the clang dependency behind the
flag. On Flatcar side we could then disable it.

Until that happens, these patches should be accompanied by a hook
function that will do "export ECARGO_EXTRA_ARGS=--no-default-features"
and "export MAKEOPTS=THIN_MIGRATE_EXCLUDE=x".

This file was deleted.

This file was deleted.

This file was deleted.

Original file line number Diff line number Diff line change
Expand Up @@ -32,10 +32,6 @@ app-crypt/azure-keyvault-pkcs11
# The only available ebuild (from GURU) has ~amd64 and no keyword for arm64 yet.
=app-crypt/clevis-19-r1 **

# Needed to address the ever-growing list of CVEs
=app-editors/vim-9.1.1652 ~amd64 ~arm64
=app-editors/vim-core-9.1.1652 ~amd64 ~arm64

# Needed by arm64-native SDK.
=app-emulation/open-vmdk-1.0 *

Expand All @@ -56,8 +52,8 @@ dev-cpp/azure-security-keyvault-keys
=dev-libs/cowsql-1.15.9 ~arm64
=dev-libs/ding-libs-0.6.2-r1 ~arm64

# The only available ebuild (from GURU) has ~amd64 and no keyword for arm64 yet.
=dev-libs/jose-12 **
# The only available ebuild has ~amd64 and no keyword for arm64 yet.
=dev-libs/jose-14 **

# The only available ebuild (from GURU) has ~amd64 and no keyword for arm64 yet.
=dev-libs/luksmeta-9-r1 **
Expand All @@ -78,9 +74,6 @@ dev-cpp/azure-security-keyvault-keys
=net-libs/libnetfilter_cthelper-1.0.1-r1 ~arm64
=net-libs/libnetfilter_cttimeout-1.0.1 ~arm64

# CVE-2025-9086, CVE-2025-10148
=net-misc/curl-8.16.0-r1 ~arm64

# CVE-2025-61984, CVE-2025-61985
=net-misc/openssh-10.2_p1 ~amd64 ~arm64

Expand All @@ -90,9 +83,14 @@ dev-cpp/azure-security-keyvault-keys
sys-apps/azure-vm-utils

# Keep versions on both arches in sync.
=sys-apps/coreutils-9.8-r1 ~amd64
=sys-apps/zram-generator-1.2.1 ~arm64
=sys-auth/sssd-2.9.7 ~arm64

# So it builds with rust provided by SDK without pulling some older
# version of rust-bin, that does not support aarch64 for some reason.
=sys-block/thin-provisioning-tools-1.3.0 ~amd64 ~arm64

# Keep versions on both arches in sync.
=sys-boot/mokutil-0.7.2 **

# Enable ipvsadm for arm64.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,3 @@

# Update engine needs updating to use a newer version of protobuf.
>=dev-libs/protobuf-22.0

# Pulls in LLVM and clang.
>=sys-block/thin-provisioning-tools-1.0.14
Original file line number Diff line number Diff line change
Expand Up @@ -23,3 +23,14 @@ dev-perl/Locale-gettext-1.70.0_p20181130
# fails with "Failed to resolve typeattributeset statement at
# /var/lib/selinux/mcs/tmp/modules/400/ntp/cil:120"
sec-policy/selinux-ntp-2.20250618-r1

# The sys-block/thin-provisioning-tools package depends on it, because
# of the thin_migrate tool using devicemapper crate that indirectly
# depends on clang (through bindgen). We disable the tool anyway with
# patches, but the dependency in the ebuild still need to be taken
# care of.
llvm-core/clang-9999

# Pulled in by sys-apps/texinfo, contains only an info file, which
# will get masked anyway during installation.
app-doc/info-manual-9999
Loading
Loading