diff --git a/.github/scripts/install-podman.sh b/.github/scripts/install-podman.sh new file mode 100755 index 0000000000..c9532af47d --- /dev/null +++ b/.github/scripts/install-podman.sh @@ -0,0 +1,35 @@ +#!/usr/bin/env bash +# Pin and install podman, working around a crun incompatibility on some +# runner images. +# +# Runner images occasionally pre-install podman 5.x paired with a crun too +# old to support it, breaking sandbox creation with "crun: unknown version +# specified". Pin to the 4.x series, which matches the crun shipped on these +# images, until GitHub Actions runner images ship a compatible crun pairing. +# `apt-get install -y podman` alone does not downgrade an already-installed +# newer version, so the pin's Pin-Priority authorizes the downgrade and +# --allow-downgrades permits apt to execute it. +# +# See #5733. Remove this pin once runner images ship crun >= 1.15 +# (podman 5.x's requirement) as standard. +# +# Usage: +# .github/scripts/install-podman.sh +set -euo pipefail + +sudo install -d /etc/apt/preferences.d +printf 'Package: podman\nPin: version 4.*\nPin-Priority: 1001\n' \ + | sudo tee /etc/apt/preferences.d/podman-pin >/dev/null +sudo apt-get update +sudo apt-get install -y --allow-downgrades podman + +installed_version="$(podman --version)" +case "${installed_version}" in + *"version 4."*) ;; + *) + echo "::error::Failed to pin podman to the 4.x series (see #5733); got: ${installed_version}" + exit 1 + ;; +esac + +echo "${installed_version}" diff --git a/.github/workflows/functional-tests.yml b/.github/workflows/functional-tests.yml index ebd4d32327..da32f932f7 100644 --- a/.github/workflows/functional-tests.yml +++ b/.github/workflows/functional-tests.yml @@ -185,9 +185,7 @@ jobs: - name: Install Podman if: steps.changes.outputs.relevant != 'false' - run: | - sudo apt-get update - sudo apt-get install -y podman + run: .github/scripts/install-podman.sh - name: Configure rootless Podman if: steps.changes.outputs.relevant != 'false' diff --git a/action.yml b/action.yml index 0d123894b9..8c2ef3dfb7 100644 --- a/action.yml +++ b/action.yml @@ -257,10 +257,7 @@ runs: - name: Install Podman shell: bash - run: | - sudo apt-get update - sudo apt-get install -y podman - podman --version + run: "$GITHUB_ACTION_PATH/.github/scripts/install-podman.sh" - name: Configure rootless Podman shell: bash diff --git a/internal/scaffold/vendormanifest.go b/internal/scaffold/vendormanifest.go index 5c0d506b44..da0798c639 100644 --- a/internal/scaffold/vendormanifest.go +++ b/internal/scaffold/vendormanifest.go @@ -153,6 +153,7 @@ var vendoredDefaultsInfraPaths = []string{ ".github/actions/setup-gcp/action.yml", ".github/actions/validate-enrollment/action.yml", ".github/scripts/install-openshell.sh", + ".github/scripts/install-podman.sh", ".github/scripts/openshell-version.sh", }