mirror of
https://github.com/flatcar/scripts.git
synced 2025-08-21 14:31:02 +02:00
Merge pull request #3005 from dm0-/docker
Upgrade Docker to 18.01, and bump LTS to 17.12
This commit is contained in:
commit
80eb4039b9
@ -4,7 +4,7 @@
|
|||||||
"images": [
|
"images": [
|
||||||
{
|
{
|
||||||
"name": "docker",
|
"name": "docker",
|
||||||
"reference": "17.12"
|
"reference": "18.01"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
@ -1,4 +1,3 @@
|
|||||||
DIST containerd-0.2.5.tar.gz 1003500 SHA256 88e099af66b50abe7f2159f13bdab793fa5199d8d5b9a9ef7a68171abb4359be SHA512 ba1e074bb7556a7c4be4d68dc62aa2fa4b823682c209d1609c1f11518a7b7167139ea159d31e0b21ba190d83115a67e5e45b54b6a4770742d49e9e561309551f WHIRLPOOL eb3622ba99c4d4806bda9a45853422a5b0b884869ed3be4c3caec4c20f49027e8db78b9885eca7bc83a0f3b08e9a66eca950390f0eda1ef2535fd3ab41623bf4
|
DIST containerd-0.2.5.tar.gz 1003500 SHA256 88e099af66b50abe7f2159f13bdab793fa5199d8d5b9a9ef7a68171abb4359be SHA512 ba1e074bb7556a7c4be4d68dc62aa2fa4b823682c209d1609c1f11518a7b7167139ea159d31e0b21ba190d83115a67e5e45b54b6a4770742d49e9e561309551f WHIRLPOOL eb3622ba99c4d4806bda9a45853422a5b0b884869ed3be4c3caec4c20f49027e8db78b9885eca7bc83a0f3b08e9a66eca950390f0eda1ef2535fd3ab41623bf4
|
||||||
DIST containerd-0.2.6.tar.gz 1020572 SHA256 a67c4153ac5ae26b9d11daac133b90cba059ba16de7579e39c3e82bcda856493 SHA512 41018bda556a3ddfb1bd3a16e642548ba06f413b13fd1488e731896e277ba6c84a393ebd5de067ecaeccc695297a2b74edf22e5a3fe8f2e3eadf78d080bdeff6 WHIRLPOOL 98f64c888ea580074e51b91311ab186291cb2d3ecc9f178d828687dbb60b35104237041699b6125cf026edd245459a052fda1801ac3cd7e1efe34606c3d9a4eb
|
DIST containerd-0.2.6.tar.gz 1020572 SHA256 a67c4153ac5ae26b9d11daac133b90cba059ba16de7579e39c3e82bcda856493 SHA512 41018bda556a3ddfb1bd3a16e642548ba06f413b13fd1488e731896e277ba6c84a393ebd5de067ecaeccc695297a2b74edf22e5a3fe8f2e3eadf78d080bdeff6 WHIRLPOOL 98f64c888ea580074e51b91311ab186291cb2d3ecc9f178d828687dbb60b35104237041699b6125cf026edd245459a052fda1801ac3cd7e1efe34606c3d9a4eb
|
||||||
DIST containerd-0.2.9_p27.tar.gz 1140788 SHA256 4d2b6e30bcc6c4bb901d6b9f19b5ac1d4a2d9b17075a9b1f110102920d01f64a SHA512 c749bda691197ec8a7603db9ad92f2800a3f065143430a660333b7862518deb4c158a1c1fd01671dff438b40988d4a64d8f06bab05496b8728c6e2f57cd7da0a WHIRLPOOL 75cb3467a94af50bef52377f309d7c85386475789fab3d2758679f022b516735728a1ac2c54307954a14100c4f84059d8fd5e8376270fdd69e572cff43453fa0
|
|
||||||
DIST containerd-1.0.0.tar.gz 3763785 SHA256 874720e68140cf57c7a4997cdab0b8177ad2ddb89e6332bb4f0ba23699a321fd SHA512 8c1a03de7f30976675e4482b4f18f4b87da56108de4d92f2e33b4cb4f8c188af5b3fad87971a294eac8442a0fb6ddae48cda81334c363203a8c8bdfc09176a7a WHIRLPOOL 73ec169ed5529bbc7963e859f1a19497fd45d80352be94fef678a51066689c877a82bc97179aa53cc75bb363d251c3d09e5ce43a693522f08cc19b11bf9b7db1
|
DIST containerd-1.0.0.tar.gz 3763785 SHA256 874720e68140cf57c7a4997cdab0b8177ad2ddb89e6332bb4f0ba23699a321fd SHA512 8c1a03de7f30976675e4482b4f18f4b87da56108de4d92f2e33b4cb4f8c188af5b3fad87971a294eac8442a0fb6ddae48cda81334c363203a8c8bdfc09176a7a WHIRLPOOL 73ec169ed5529bbc7963e859f1a19497fd45d80352be94fef678a51066689c877a82bc97179aa53cc75bb363d251c3d09e5ce43a693522f08cc19b11bf9b7db1
|
||||||
|
@ -1,55 +0,0 @@
|
|||||||
# Copyright 1999-2017 Gentoo Foundation
|
|
||||||
# Distributed under the terms of the GNU General Public License v2
|
|
||||||
|
|
||||||
EAPI=6
|
|
||||||
|
|
||||||
GITHUB_URI="github.com/containerd/containerd"
|
|
||||||
COREOS_GO_PACKAGE="${GITHUB_URI}"
|
|
||||||
COREOS_GO_VERSION="go1.8"
|
|
||||||
|
|
||||||
if [[ ${PV} == *9999 ]]; then
|
|
||||||
EGIT_REPO_URI="https://${GITHUB_URI}.git"
|
|
||||||
inherit git-r3
|
|
||||||
else
|
|
||||||
# Update the patch number when setting commit.
|
|
||||||
# The patch number is arbitrarily chosen as the number of commits since the
|
|
||||||
# tagged version.
|
|
||||||
# e.g. git log --oneline v0.2.9..${EGIT_COMMIT} | wc -l
|
|
||||||
EGIT_COMMIT="06b9cb35161009dcb7123345749fef02f7cea8e0"
|
|
||||||
SRC_URI="https://${GITHUB_URI}/archive/${EGIT_COMMIT}.tar.gz -> ${P}.tar.gz"
|
|
||||||
KEYWORDS="amd64 arm64"
|
|
||||||
inherit vcs-snapshot
|
|
||||||
fi
|
|
||||||
|
|
||||||
inherit coreos-go systemd
|
|
||||||
|
|
||||||
DESCRIPTION="A daemon to control runC"
|
|
||||||
HOMEPAGE="https://containerd.tools"
|
|
||||||
|
|
||||||
LICENSE="Apache-2.0"
|
|
||||||
SLOT="0"
|
|
||||||
IUSE="hardened +seccomp"
|
|
||||||
|
|
||||||
DEPEND=""
|
|
||||||
RDEPEND=">=app-emulation/docker-runc-1.0.0_rc4
|
|
||||||
seccomp? ( sys-libs/libseccomp )"
|
|
||||||
|
|
||||||
S=${WORKDIR}/${P}/src/${COREOS_GO_PACKAGE}
|
|
||||||
|
|
||||||
RESTRICT="test"
|
|
||||||
|
|
||||||
src_unpack() {
|
|
||||||
mkdir -p "${S}"
|
|
||||||
tar --strip-components=1 -C "${S}" -xf "${DISTDIR}/${A}"
|
|
||||||
}
|
|
||||||
|
|
||||||
src_compile() {
|
|
||||||
local options=( $(usex seccomp "seccomp" '') )
|
|
||||||
export GOPATH="${WORKDIR}/${P}" # ${PWD}/vendor
|
|
||||||
LDFLAGS=$(usex hardened '-extldflags -fno-PIC' '') emake GIT_COMMIT="$EGIT_COMMIT" BUILDTAGS="${options[@]}"
|
|
||||||
}
|
|
||||||
|
|
||||||
src_install() {
|
|
||||||
dobin bin/containerd* bin/ctr
|
|
||||||
systemd_dounit "${FILESDIR}/containerd.service"
|
|
||||||
}
|
|
@ -1,3 +1,2 @@
|
|||||||
DIST docker-runc-1.0.0_rc2_p136.tar.gz 561705 SHA256 2954cb6b468b3806a08c45656acc2019035bc9994c2a9b4249cfde4d9b3a7c93 SHA512 6052b95042082c3345caf25d3646f47b82c151ff3aca2ca4510dbf72ee80056d8c4077f2a1b48a9f4178c41185835ff51461e52ad47969534ea6febf7cac74f1 WHIRLPOOL ede821987006a54e7a87f88d9a5104d4a4ecc05a614e111fefa669f5ae436c11004debfe919bec0808194f2d96442775718a0208a1a374a9dd56a896f7dd8640
|
DIST docker-runc-1.0.0_rc2_p136.tar.gz 561705 SHA256 2954cb6b468b3806a08c45656acc2019035bc9994c2a9b4249cfde4d9b3a7c93 SHA512 6052b95042082c3345caf25d3646f47b82c151ff3aca2ca4510dbf72ee80056d8c4077f2a1b48a9f4178c41185835ff51461e52ad47969534ea6febf7cac74f1 WHIRLPOOL ede821987006a54e7a87f88d9a5104d4a4ecc05a614e111fefa669f5ae436c11004debfe919bec0808194f2d96442775718a0208a1a374a9dd56a896f7dd8640
|
||||||
DIST docker-runc-1.0.0_rc4_p171.tar.gz 1189298 SHA256 0838504b63fe8c2055c8307cd9f9d5e79d96c03ac86069fba3b9bc7fa459502b SHA512 a5bf97ce284317e03e63ee0e39228d77848fcde2f6322de06eebc2536978b5d87fd8c3fbccb2e74ef8c80fbaa28f3d0b24074cb9fde01e268593332aacd57695 WHIRLPOOL f0264dc7e5319ed1cd44db3ee2d7f37fe1476f1827f71fc3ee5e9fb45ef139f5e72b31a1f7e402c2e3a595524b1fd96d6a5175c379f78130c54d53a1e26a0bca
|
DIST docker-runc-1.0.0_rc4_p171.tar.gz 1189298 SHA256 0838504b63fe8c2055c8307cd9f9d5e79d96c03ac86069fba3b9bc7fa459502b SHA512 a5bf97ce284317e03e63ee0e39228d77848fcde2f6322de06eebc2536978b5d87fd8c3fbccb2e74ef8c80fbaa28f3d0b24074cb9fde01e268593332aacd57695 WHIRLPOOL f0264dc7e5319ed1cd44db3ee2d7f37fe1476f1827f71fc3ee5e9fb45ef139f5e72b31a1f7e402c2e3a595524b1fd96d6a5175c379f78130c54d53a1e26a0bca
|
||||||
DIST docker-runc-1.0.0_rc4_p25.tar.gz 1094599 SHA256 d5820f1c655061be79441bd57efea4e5b60b25b6a451214b64172395b9fda383 SHA512 0cb0748812296294a87dda257dbf0947897a1ada2aa861ff3e65309a6bbecebbe798929845fca6f23b66fd0dc019bca0a032737c7192fe20618d8e1849866f3d WHIRLPOOL ed34894a3878c0cae50888c936eba1dad8d58da8d7042d5e421f06e4e98c1d7701a5c877baaba14a46d588b2ee3354e19d72bb141d5d8e7f6c0bed2d3a6b71b6
|
|
||||||
|
@ -1,73 +0,0 @@
|
|||||||
# Copyright 1999-2017 Gentoo Foundation
|
|
||||||
# Distributed under the terms of the GNU General Public License v2
|
|
||||||
|
|
||||||
EAPI=6
|
|
||||||
|
|
||||||
GITHUB_URI="github.com/opencontainers/runc"
|
|
||||||
COREOS_GO_PACKAGE="${GITHUB_URI}"
|
|
||||||
COREOS_GO_VERSION="go1.8"
|
|
||||||
# the commit of runc that docker uses.
|
|
||||||
# see https://github.com/docker/docker-ce/blob/v17.09.1-ce/components/engine/hack/dockerfile/binaries-commits#L6
|
|
||||||
# Note: this commit is only really present in the `docker/runc` repository.
|
|
||||||
# Update the patch number when this commit is changed (i.e. the _p in the ebuild).
|
|
||||||
# The patch version is arbitrarily the number of commits since the tag version
|
|
||||||
# spcified in the ebuild name. For example:
|
|
||||||
# $ git log --oneline v1.0.0-rc4..${COMMIT_ID} | wc -l
|
|
||||||
COMMIT_ID="3f2f8b84a77f73d38244dd690525642a72156c64"
|
|
||||||
|
|
||||||
inherit eutils flag-o-matic coreos-go vcs-snapshot
|
|
||||||
|
|
||||||
SRC_URI="https://${GITHUB_URI}/archive/${COMMIT_ID}.tar.gz -> ${P}.tar.gz"
|
|
||||||
KEYWORDS="amd64 arm64"
|
|
||||||
|
|
||||||
DESCRIPTION="runc container cli tools (docker fork)"
|
|
||||||
HOMEPAGE="http://runc.io"
|
|
||||||
|
|
||||||
LICENSE="Apache-2.0"
|
|
||||||
SLOT="0"
|
|
||||||
IUSE="ambient apparmor hardened +seccomp selinux"
|
|
||||||
|
|
||||||
RDEPEND="
|
|
||||||
apparmor? ( sys-libs/libapparmor )
|
|
||||||
seccomp? ( sys-libs/libseccomp )
|
|
||||||
!app-emulation/runc
|
|
||||||
"
|
|
||||||
|
|
||||||
S=${WORKDIR}/${P}/src/${COREOS_GO_PACKAGE}
|
|
||||||
|
|
||||||
RESTRICT="test"
|
|
||||||
|
|
||||||
src_unpack() {
|
|
||||||
mkdir -p "${S}"
|
|
||||||
tar --strip-components=1 -C "${S}" -xf "${DISTDIR}/${A}"
|
|
||||||
}
|
|
||||||
|
|
||||||
PATCHES=(
|
|
||||||
"${FILESDIR}/0001-Delay-unshare-of-clone-newipc-for-selinux.patch"
|
|
||||||
"${FILESDIR}/0002-libcontainer-default-mount-propagation-correctly.patch"
|
|
||||||
)
|
|
||||||
|
|
||||||
src_compile() {
|
|
||||||
# Taken from app-emulation/docker-1.7.0-r1
|
|
||||||
export CGO_CFLAGS="-I${ROOT}/usr/include"
|
|
||||||
export CGO_LDFLAGS="$(usex hardened '-fno-PIC ' '')
|
|
||||||
-L${ROOT}/usr/$(get_libdir)"
|
|
||||||
|
|
||||||
# build up optional flags
|
|
||||||
local options=(
|
|
||||||
$(usex ambient 'ambient' '')
|
|
||||||
$(usex apparmor 'apparmor' '')
|
|
||||||
$(usex seccomp 'seccomp' '')
|
|
||||||
$(usex selinux 'selinux' '')
|
|
||||||
)
|
|
||||||
|
|
||||||
# CoreOS: Don't try to install dependencies.
|
|
||||||
sed -i 's/go build -i /go build /' Makefile
|
|
||||||
|
|
||||||
GOPATH="${WORKDIR}/${P}" emake BUILDTAGS="${options[*]}" \
|
|
||||||
COMMIT="${COMMIT_ID}"
|
|
||||||
}
|
|
||||||
|
|
||||||
src_install() {
|
|
||||||
dobin runc
|
|
||||||
}
|
|
@ -1,41 +0,0 @@
|
|||||||
From db55cd4f29298ae08b20f92b8953735723ee2167 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Euan Kemp <euan.kemp@coreos.com>
|
|
||||||
Date: Fri, 22 Sep 2017 02:31:17 -0700
|
|
||||||
Subject: [PATCH] libcontainer: default mount propagation correctly
|
|
||||||
|
|
||||||
The code in prepareRoot (https://github.com/opencontainers/runc/blob/e385f67a0e45fa1d8ef8154e2aea5128ea1d331b/libcontainer/rootfs_linux.go#L599-L605)
|
|
||||||
attempts to default the rootfs mount to `rslave`. However, since the spec
|
|
||||||
conversion has already defaulted it to `rprivate`, that code doesn't
|
|
||||||
actually ever do anything.
|
|
||||||
|
|
||||||
This changes the spec conversion code to accept "" and treat it as 0.
|
|
||||||
|
|
||||||
Implicitly, this makes rootfs propagation default to `rslave`, which is
|
|
||||||
a part of fixing the moby bug https://github.com/moby/moby/issues/34672
|
|
||||||
|
|
||||||
Alternate implementatoins include changing this defaulting to be
|
|
||||||
`rslave` and removing the defaulting code in prepareRoot, or skipping
|
|
||||||
the mapping entirely for "", but I think this change is the cleanest of
|
|
||||||
those options.
|
|
||||||
|
|
||||||
Signed-off-by: Euan Kemp <euan.kemp@coreos.com>
|
|
||||||
---
|
|
||||||
libcontainer/specconv/spec_linux.go | 2 +-
|
|
||||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
||||||
|
|
||||||
diff --git a/libcontainer/specconv/spec_linux.go b/libcontainer/specconv/spec_linux.go
|
|
||||||
index 1575ae03..8a2947f6 100644
|
|
||||||
--- a/libcontainer/specconv/spec_linux.go
|
|
||||||
+++ b/libcontainer/specconv/spec_linux.go
|
|
||||||
@@ -37,7 +37,7 @@ var mountPropagationMapping = map[string]int{
|
|
||||||
"slave": unix.MS_SLAVE,
|
|
||||||
"rshared": unix.MS_SHARED | unix.MS_REC,
|
|
||||||
"shared": unix.MS_SHARED,
|
|
||||||
- "": unix.MS_PRIVATE | unix.MS_REC,
|
|
||||||
+ "": 0,
|
|
||||||
}
|
|
||||||
|
|
||||||
var allowedDevices = []*configs.Device{
|
|
||||||
--
|
|
||||||
2.13.5
|
|
||||||
|
|
@ -1,2 +1,2 @@
|
|||||||
DIST docker-17.09.1.tar.gz 10135978 SHA256 ac9b1688583c5167fb8d0237da6d6abb3cfa6bc05b2c05590b3bba62eb344d13 SHA512 e968ced32c379b74602053d1e9fe9ee5abe595078bb8d5f0d994c7eafd1557158d58fa48489ca8d7d578dbc7a5241182288b3ab37885b53abb8364d7aa9d2a4f WHIRLPOOL 9cf6949e1f397c2b92c1a2945354cb093daa6715b074ceb3a0cf6828d8a23f9dd5906e6e5a964d39179739990cf49df7f1c1bef014169e0e5cc4519796a93a71
|
|
||||||
DIST docker-17.12.0.tar.gz 11011208 SHA256 945e3eb62e35e9399983a956299bbbf878442c5a164262ed82b7aa7366731a83 SHA512 1a4dfc86dc6c85c78d2abf4f559e5efe0fb22d915997f047fa6641e2aefb3e2fc6cb0124b6a0fc69abfc09ac8b261ebbd4d80b380cf9eb4304d3e1a423957b67 WHIRLPOOL 07df0042eeeaac87ca2ffed7c37a6add5826d37cd20b1cb081b00f6ae30d6e310923492b6369f738ef55233b8a15a8e20250aeb402fb3f5865336a70f30ae91e
|
DIST docker-17.12.0.tar.gz 11011208 SHA256 945e3eb62e35e9399983a956299bbbf878442c5a164262ed82b7aa7366731a83 SHA512 1a4dfc86dc6c85c78d2abf4f559e5efe0fb22d915997f047fa6641e2aefb3e2fc6cb0124b6a0fc69abfc09ac8b261ebbd4d80b380cf9eb4304d3e1a423957b67 WHIRLPOOL 07df0042eeeaac87ca2ffed7c37a6add5826d37cd20b1cb081b00f6ae30d6e310923492b6369f738ef55233b8a15a8e20250aeb402fb3f5865336a70f30ae91e
|
||||||
|
DIST docker-18.01.0.tar.gz 12530532 SHA256 e1c16f0857ed74420e670fdbeb53b7daaa9f5b29ded50c63226941f6b356a4b0 SHA512 e58b23200df811549d8c2ba4b915458b3496b982b264f0aa0ff8c6406e0deb20af2180ea20ac1eaab35cc2a14bea98d6d14d197fdeb54f8c7949dc1b6a336872 WHIRLPOOL ce6f84db6e8ef9ecd25bf3647a0190804b487f91c40afbe4c8455a7da4e0257c609e65bc1e44c4e595a2b9a54289e9f7fcf6428ea895a0e938b74e58cf8dfec7
|
||||||
|
@ -1,334 +0,0 @@
|
|||||||
# Copyright 1999-2017 Gentoo Foundation
|
|
||||||
# Distributed under the terms of the GNU General Public License v2
|
|
||||||
|
|
||||||
EAPI=6
|
|
||||||
|
|
||||||
COREOS_GO_PACKAGE="github.com/docker/docker-ce"
|
|
||||||
COREOS_GO_VERSION="go1.8"
|
|
||||||
|
|
||||||
if [[ ${PV} = *9999* ]]; then
|
|
||||||
# Docker cannot be fetched via "go get", thanks to autogenerated code
|
|
||||||
EGIT_REPO_URI="https://${COREOS_GO_PACKAGE}.git"
|
|
||||||
EGIT_CHECKOUT_DIR="${WORKDIR}/${P}/src/${COREOS_GO_PACKAGE}"
|
|
||||||
inherit git-r3
|
|
||||||
KEYWORDS="~amd64 ~arm64"
|
|
||||||
else
|
|
||||||
inherit versionator
|
|
||||||
if [ "$(get_version_component_count)" = 4 ]; then
|
|
||||||
MY_PV="$(replace_version_separator 3 '-ce-')"
|
|
||||||
else
|
|
||||||
MY_PV="$PV-ce"
|
|
||||||
fi
|
|
||||||
DOCKER_GITCOMMIT="19e2cf6"
|
|
||||||
SRC_URI="https://${COREOS_GO_PACKAGE}/archive/v${MY_PV}.tar.gz -> ${P}.tar.gz"
|
|
||||||
KEYWORDS="amd64 arm64"
|
|
||||||
[ "$DOCKER_GITCOMMIT" ] || die "DOCKER_GITCOMMIT must be added manually for each bump!"
|
|
||||||
fi
|
|
||||||
inherit bash-completion-r1 coreos-go-depend linux-info systemd udev user
|
|
||||||
|
|
||||||
DESCRIPTION="The core functions you need to create Docker images and run Docker containers"
|
|
||||||
HOMEPAGE="https://dockerproject.org"
|
|
||||||
LICENSE="Apache-2.0"
|
|
||||||
SLOT="0"
|
|
||||||
IUSE="apparmor aufs +btrfs +container-init +device-mapper hardened +overlay pkcs11 seccomp +journald +selinux"
|
|
||||||
|
|
||||||
# https://github.com/docker/docker/blob/master/project/PACKAGERS.md#build-dependencies
|
|
||||||
CDEPEND="
|
|
||||||
>=dev-db/sqlite-3.7.9:3
|
|
||||||
device-mapper? (
|
|
||||||
>=sys-fs/lvm2-2.02.89[thin]
|
|
||||||
)
|
|
||||||
seccomp? ( >=sys-libs/libseccomp-2.2.1[static-libs] )
|
|
||||||
apparmor? ( sys-libs/libapparmor )
|
|
||||||
"
|
|
||||||
|
|
||||||
DEPEND="
|
|
||||||
${CDEPEND}
|
|
||||||
|
|
||||||
btrfs? (
|
|
||||||
>=sys-fs/btrfs-progs-3.16.1
|
|
||||||
)
|
|
||||||
"
|
|
||||||
|
|
||||||
# For CoreOS builds coreos-kernel must be installed because this ebuild
|
|
||||||
# checks the kernel config. The kernel config is left by the kernel compile
|
|
||||||
# or an explicit copy when installing binary packages. See coreos-kernel.eclass
|
|
||||||
DEPEND+="sys-kernel/coreos-kernel"
|
|
||||||
|
|
||||||
# https://github.com/docker/docker/blob/master/project/PACKAGERS.md#runtime-dependencies
|
|
||||||
# https://github.com/docker/docker/blob/master/project/PACKAGERS.md#optional-dependencies
|
|
||||||
RDEPEND="
|
|
||||||
${CDEPEND}
|
|
||||||
>=net-firewall/iptables-1.4
|
|
||||||
sys-process/procps
|
|
||||||
>=dev-vcs/git-1.7
|
|
||||||
>=app-arch/xz-utils-4.9
|
|
||||||
|
|
||||||
=app-emulation/containerd-0.2.9_p27[seccomp?]
|
|
||||||
=app-emulation/docker-runc-1.0.0_rc4_p25[apparmor?,seccomp?]
|
|
||||||
app-emulation/docker-proxy
|
|
||||||
container-init? ( >=sys-process/tini-0.13.1 )
|
|
||||||
"
|
|
||||||
|
|
||||||
RESTRICT="installsources strip"
|
|
||||||
|
|
||||||
S="${WORKDIR}/${P}/src/${COREOS_GO_PACKAGE}"
|
|
||||||
|
|
||||||
ENGINE_PATCHES=()
|
|
||||||
|
|
||||||
# see "contrib/check-config.sh" from upstream's sources
|
|
||||||
CONFIG_CHECK="
|
|
||||||
~NAMESPACES ~NET_NS ~PID_NS ~IPC_NS ~UTS_NS
|
|
||||||
~CGROUPS ~CGROUP_CPUACCT ~CGROUP_DEVICE ~CGROUP_FREEZER ~CGROUP_SCHED ~CPUSETS ~MEMCG
|
|
||||||
~KEYS
|
|
||||||
~VETH ~BRIDGE ~BRIDGE_NETFILTER
|
|
||||||
~NF_NAT_IPV4 ~IP_NF_FILTER ~IP_NF_TARGET_MASQUERADE
|
|
||||||
~NETFILTER_XT_MATCH_ADDRTYPE ~NETFILTER_XT_MATCH_CONNTRACK
|
|
||||||
~NF_NAT ~NF_NAT_NEEDED
|
|
||||||
~POSIX_MQUEUE
|
|
||||||
|
|
||||||
~USER_NS
|
|
||||||
~SECCOMP
|
|
||||||
~CGROUP_PIDS
|
|
||||||
~MEMCG_SWAP ~MEMCG_SWAP_ENABLED
|
|
||||||
|
|
||||||
~BLK_CGROUP ~BLK_DEV_THROTTLING ~IOSCHED_CFQ ~CFQ_GROUP_IOSCHED
|
|
||||||
~CGROUP_PERF
|
|
||||||
~CGROUP_HUGETLB
|
|
||||||
~NET_CLS_CGROUP
|
|
||||||
~CFS_BANDWIDTH ~FAIR_GROUP_SCHED ~RT_GROUP_SCHED
|
|
||||||
~IP_VS ~IP_VS_PROTO_TCP ~IP_VS_PROTO_UDP ~IP_VS_NFCT ~IP_VS_RR
|
|
||||||
|
|
||||||
~VXLAN
|
|
||||||
~XFRM_ALGO ~XFRM_USER
|
|
||||||
~IPVLAN
|
|
||||||
~MACVLAN ~DUMMY
|
|
||||||
"
|
|
||||||
|
|
||||||
ERROR_KEYS="CONFIG_KEYS: is mandatory"
|
|
||||||
ERROR_MEMCG_SWAP="CONFIG_MEMCG_SWAP: is required if you wish to limit swap usage of containers"
|
|
||||||
ERROR_RESOURCE_COUNTERS="CONFIG_RESOURCE_COUNTERS: is optional for container statistics gathering"
|
|
||||||
|
|
||||||
ERROR_BLK_CGROUP="CONFIG_BLK_CGROUP: is optional for container statistics gathering"
|
|
||||||
ERROR_IOSCHED_CFQ="CONFIG_IOSCHED_CFQ: is optional for container statistics gathering"
|
|
||||||
ERROR_CGROUP_PERF="CONFIG_CGROUP_PERF: is optional for container statistics gathering"
|
|
||||||
ERROR_CFS_BANDWIDTH="CONFIG_CFS_BANDWIDTH: is optional for container statistics gathering"
|
|
||||||
ERROR_XFRM_ALGO="CONFIG_XFRM_ALGO: is optional for secure networks"
|
|
||||||
ERROR_XFRM_USER="CONFIG_XFRM_USER: is optional for secure networks"
|
|
||||||
|
|
||||||
pkg_setup() {
|
|
||||||
if kernel_is lt 3 10; then
|
|
||||||
ewarn ""
|
|
||||||
ewarn "Using Docker with kernels older than 3.10 is unstable and unsupported."
|
|
||||||
ewarn " - http://docs.docker.com/engine/installation/binaries/#check-kernel-dependencies"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# for where these kernel versions come from, see:
|
|
||||||
# https://www.google.com/search?q=945b2b2d259d1a4364a2799e80e8ff32f8c6ee6f+site%3Akernel.org%2Fpub%2Flinux%2Fkernel+file%3AChangeLog*
|
|
||||||
if ! {
|
|
||||||
kernel_is ge 3 16 \
|
|
||||||
|| { kernel_is 3 15 && kernel_is ge 3 15 5; } \
|
|
||||||
|| { kernel_is 3 14 && kernel_is ge 3 14 12; } \
|
|
||||||
|| { kernel_is 3 12 && kernel_is ge 3 12 25; }
|
|
||||||
}; then
|
|
||||||
ewarn ""
|
|
||||||
ewarn "There is a serious Docker-related kernel panic that has been fixed in 3.16+"
|
|
||||||
ewarn " (and was backported to 3.15.5+, 3.14.12+, and 3.12.25+)"
|
|
||||||
ewarn ""
|
|
||||||
ewarn "See also https://github.com/docker/docker/issues/2960"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if kernel_is le 3 18; then
|
|
||||||
CONFIG_CHECK+="
|
|
||||||
~RESOURCE_COUNTERS
|
|
||||||
"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if kernel_is le 3 13; then
|
|
||||||
CONFIG_CHECK+="
|
|
||||||
~NETPRIO_CGROUP
|
|
||||||
"
|
|
||||||
else
|
|
||||||
CONFIG_CHECK+="
|
|
||||||
~CGROUP_NET_PRIO
|
|
||||||
"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if kernel_is lt 4 5; then
|
|
||||||
CONFIG_CHECK+="
|
|
||||||
~MEMCG_KMEM
|
|
||||||
"
|
|
||||||
ERROR_MEMCG_KMEM="CONFIG_MEMCG_KMEM: is optional"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if kernel_is lt 4 7; then
|
|
||||||
CONFIG_CHECK+="
|
|
||||||
~DEVPTS_MULTIPLE_INSTANCES
|
|
||||||
"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if use aufs; then
|
|
||||||
CONFIG_CHECK+="
|
|
||||||
~AUFS_FS
|
|
||||||
~EXT4_FS_POSIX_ACL ~EXT4_FS_SECURITY
|
|
||||||
"
|
|
||||||
ERROR_AUFS_FS="CONFIG_AUFS_FS: is required to be set if and only if aufs-sources are used instead of aufs4/aufs3"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if use btrfs; then
|
|
||||||
CONFIG_CHECK+="
|
|
||||||
~BTRFS_FS
|
|
||||||
~BTRFS_FS_POSIX_ACL
|
|
||||||
"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if use device-mapper; then
|
|
||||||
CONFIG_CHECK+="
|
|
||||||
~BLK_DEV_DM ~DM_THIN_PROVISIONING ~EXT4_FS ~EXT4_FS_POSIX_ACL ~EXT4_FS_SECURITY
|
|
||||||
"
|
|
||||||
fi
|
|
||||||
|
|
||||||
if use overlay; then
|
|
||||||
CONFIG_CHECK+="
|
|
||||||
~OVERLAY_FS ~EXT4_FS_SECURITY ~EXT4_FS_POSIX_ACL
|
|
||||||
"
|
|
||||||
fi
|
|
||||||
|
|
||||||
linux-info_pkg_setup
|
|
||||||
|
|
||||||
# create docker group for the code checking for it in /etc/group
|
|
||||||
enewgroup docker
|
|
||||||
}
|
|
||||||
|
|
||||||
src_unpack() {
|
|
||||||
if [ -n "$DOCKER_GITCOMMIT" ]; then
|
|
||||||
mkdir -p "${S}"
|
|
||||||
tar --strip-components=1 -C "${S}" -xf "${DISTDIR}/${A}"
|
|
||||||
DOCKER_BUILD_DATE=$(date --reference="${S}/VERSION" +%s)
|
|
||||||
else
|
|
||||||
git-r3_src_unpack
|
|
||||||
DOCKER_GITCOMMIT=$(git -C "${S}" rev-parse HEAD | head -c 7)
|
|
||||||
DOCKER_BUILD_DATE=$(git -C "${S}" log -1 --format="%ct")
|
|
||||||
fi
|
|
||||||
[ "${#ENGINE_PATCHES[@]}" -gt 0 ] && eapply -d"${S}"/components/engine "${ENGINE_PATCHES[@]}"
|
|
||||||
}
|
|
||||||
|
|
||||||
src_compile() {
|
|
||||||
go_export
|
|
||||||
export GOPATH="${WORKDIR}/${P}"
|
|
||||||
|
|
||||||
# setup CFLAGS and LDFLAGS for separate build target
|
|
||||||
# see https://github.com/tianon/docker-overlay/pull/10
|
|
||||||
export CGO_CFLAGS="${CGO_CFLAGS} -I${ROOT}/usr/include"
|
|
||||||
export CGO_LDFLAGS="${CGO_LDFLAGS} -L${ROOT}/usr/$(get_libdir)"
|
|
||||||
|
|
||||||
# if we're building from a tarball, we need the GITCOMMIT value
|
|
||||||
[ "$DOCKER_GITCOMMIT" ] && export DOCKER_GITCOMMIT
|
|
||||||
|
|
||||||
# fake golang layout
|
|
||||||
ln -s docker-ce/components/engine ../docker || die
|
|
||||||
ln -s docker-ce/components/cli ../cli || die
|
|
||||||
|
|
||||||
# let's set up some optional features :)
|
|
||||||
export DOCKER_BUILDTAGS=''
|
|
||||||
for gd in aufs btrfs device-mapper overlay; do
|
|
||||||
if ! use $gd; then
|
|
||||||
DOCKER_BUILDTAGS+=" exclude_graphdriver_${gd//-/}"
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
|
|
||||||
for tag in apparmor pkcs11 seccomp selinux journald; do
|
|
||||||
if use $tag; then
|
|
||||||
DOCKER_BUILDTAGS+=" $tag"
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
|
|
||||||
pushd components/engine || die
|
|
||||||
|
|
||||||
if use hardened; then
|
|
||||||
sed -i "s#EXTLDFLAGS_STATIC='#&-fno-PIC $LDFLAGS #" hack/make.sh || die
|
|
||||||
grep -q -- '-fno-PIC' hack/make.sh || die 'hardened sed failed'
|
|
||||||
sed "s#LDFLAGS_STATIC_DOCKER='#&-extldflags \"-fno-PIC $LDFLAGS\" #" \
|
|
||||||
-i hack/make/dynbinary-daemon || die
|
|
||||||
grep -q -- '-fno-PIC' hack/make/dynbinary-daemon || die 'hardened sed failed'
|
|
||||||
fi
|
|
||||||
|
|
||||||
# build daemon
|
|
||||||
SOURCE_DATE_EPOCH="${DOCKER_BUILD_DATE}" \
|
|
||||||
./hack/make.sh dynbinary || die 'dynbinary failed'
|
|
||||||
|
|
||||||
popd || die # components/engine
|
|
||||||
|
|
||||||
pushd components/cli || die
|
|
||||||
|
|
||||||
# Imitating https://github.com/docker/docker-ce/blob/v17.09.1-ce/components/cli/scripts/build/.variables#L6
|
|
||||||
CLI_BUILDTIME="$(date -d "@${DOCKER_BUILD_DATE}" --utc --rfc-3339 ns 2> /dev/null | sed -e 's/ /T/')"
|
|
||||||
# build cli
|
|
||||||
emake \
|
|
||||||
BUILDTIME="${CLI_BUILDTIME}" \
|
|
||||||
LDFLAGS="$(usex hardened "-extldflags \"-fno-PIC $LDFLAGS\"" '')" \
|
|
||||||
VERSION="$(cat ../../VERSION)" \
|
|
||||||
GITCOMMIT="${DOCKER_GITCOMMIT}" \
|
|
||||||
DISABLE_WARN_OUTSIDE_CONTAINER=1 \
|
|
||||||
dynbinary || die
|
|
||||||
|
|
||||||
popd || die # components/cli
|
|
||||||
}
|
|
||||||
|
|
||||||
src_install() {
|
|
||||||
dosym containerd /usr/bin/docker-containerd
|
|
||||||
dosym containerd-shim /usr/bin/docker-containerd-shim
|
|
||||||
dosym runc /usr/bin/docker-runc
|
|
||||||
use container-init && dosym tini /usr/bin/docker-init
|
|
||||||
|
|
||||||
pushd components/engine || die
|
|
||||||
newbin "$(readlink -f bundles/latest/dynbinary-daemon/dockerd)" dockerd
|
|
||||||
|
|
||||||
newinitd contrib/init/openrc/docker.initd docker
|
|
||||||
newconfd contrib/init/openrc/docker.confd docker
|
|
||||||
|
|
||||||
exeinto /usr/lib/coreos
|
|
||||||
# Create /usr/lib/coreos/dockerd for backwards compatibility
|
|
||||||
doexe "${FILESDIR}/dockerd"
|
|
||||||
|
|
||||||
systemd_dounit "${FILESDIR}/docker.service"
|
|
||||||
systemd_dounit "${FILESDIR}/docker.socket"
|
|
||||||
|
|
||||||
insinto /usr/lib/systemd/network
|
|
||||||
doins "${FILESDIR}"/50-docker.network
|
|
||||||
doins "${FILESDIR}"/90-docker-veth.network
|
|
||||||
|
|
||||||
udev_dorules contrib/udev/*.rules
|
|
||||||
|
|
||||||
dodoc AUTHORS CONTRIBUTING.md CHANGELOG.md NOTICE README.md
|
|
||||||
dodoc -r docs/*
|
|
||||||
|
|
||||||
insinto /usr/share/vim/vimfiles
|
|
||||||
doins -r contrib/syntax/vim/ftdetect
|
|
||||||
doins -r contrib/syntax/vim/syntax
|
|
||||||
popd || die # components/engine
|
|
||||||
|
|
||||||
pushd components/cli || die
|
|
||||||
|
|
||||||
newbin build/docker-* docker
|
|
||||||
|
|
||||||
dobashcomp contrib/completion/bash/*
|
|
||||||
insinto /usr/share/zsh/site-functions
|
|
||||||
doins contrib/completion/zsh/_*
|
|
||||||
popd || die # components/cli
|
|
||||||
}
|
|
||||||
|
|
||||||
pkg_postinst() {
|
|
||||||
udev_reload
|
|
||||||
|
|
||||||
elog
|
|
||||||
elog "To use Docker, the Docker daemon must be running as root. To automatically"
|
|
||||||
elog "start the Docker daemon at boot, add Docker to the default runlevel:"
|
|
||||||
elog " rc-update add docker default"
|
|
||||||
elog "Similarly for systemd:"
|
|
||||||
elog " systemctl enable docker.service"
|
|
||||||
elog
|
|
||||||
elog "To use Docker as a non-root user, add yourself to the 'docker' group:"
|
|
||||||
elog " usermod -aG docker youruser"
|
|
||||||
elog
|
|
||||||
}
|
|
@ -1 +0,0 @@
|
|||||||
docker-9999.ebuild
|
|
338
sdk_container/src/third_party/coreos-overlay/app-emulation/docker/docker-17.12.0.ebuild
vendored
Normal file
338
sdk_container/src/third_party/coreos-overlay/app-emulation/docker/docker-17.12.0.ebuild
vendored
Normal file
@ -0,0 +1,338 @@
|
|||||||
|
# Copyright 1999-2018 Gentoo Foundation
|
||||||
|
# Distributed under the terms of the GNU General Public License v2
|
||||||
|
|
||||||
|
EAPI=6
|
||||||
|
|
||||||
|
COREOS_GO_PACKAGE="github.com/docker/docker-ce"
|
||||||
|
COREOS_GO_VERSION="go1.9"
|
||||||
|
|
||||||
|
if [[ ${PV} = *9999* ]]; then
|
||||||
|
# Docker cannot be fetched via "go get", thanks to autogenerated code
|
||||||
|
EGIT_REPO_URI="https://${COREOS_GO_PACKAGE}.git"
|
||||||
|
EGIT_CHECKOUT_DIR="${WORKDIR}/${P}/src/${COREOS_GO_PACKAGE}"
|
||||||
|
inherit git-r3
|
||||||
|
KEYWORDS="~amd64 ~arm64"
|
||||||
|
else
|
||||||
|
inherit versionator
|
||||||
|
if [ "$(get_version_component_count)" = 4 ]; then
|
||||||
|
MY_PV="$(replace_version_separator 3 '-ce-')"
|
||||||
|
else
|
||||||
|
MY_PV="$PV-ce"
|
||||||
|
fi
|
||||||
|
DOCKER_GITCOMMIT="486a48d"
|
||||||
|
SRC_URI="https://${COREOS_GO_PACKAGE}/archive/v${MY_PV}.tar.gz -> ${P}.tar.gz"
|
||||||
|
KEYWORDS="amd64 arm64"
|
||||||
|
[ "$DOCKER_GITCOMMIT" ] || die "DOCKER_GITCOMMIT must be added manually for each bump!"
|
||||||
|
fi
|
||||||
|
inherit bash-completion-r1 coreos-go-depend linux-info systemd udev user
|
||||||
|
|
||||||
|
DESCRIPTION="The core functions you need to create Docker images and run Docker containers"
|
||||||
|
HOMEPAGE="https://dockerproject.org"
|
||||||
|
LICENSE="Apache-2.0"
|
||||||
|
SLOT="0"
|
||||||
|
IUSE="apparmor aufs +btrfs +container-init +device-mapper hardened +overlay pkcs11 seccomp +journald +selinux"
|
||||||
|
|
||||||
|
# https://github.com/docker/docker/blob/master/project/PACKAGERS.md#build-dependencies
|
||||||
|
CDEPEND="
|
||||||
|
>=dev-db/sqlite-3.7.9:3
|
||||||
|
device-mapper? (
|
||||||
|
>=sys-fs/lvm2-2.02.89[thin]
|
||||||
|
)
|
||||||
|
seccomp? ( >=sys-libs/libseccomp-2.2.1[static-libs] )
|
||||||
|
apparmor? ( sys-libs/libapparmor )
|
||||||
|
"
|
||||||
|
|
||||||
|
DEPEND="
|
||||||
|
${CDEPEND}
|
||||||
|
|
||||||
|
btrfs? (
|
||||||
|
>=sys-fs/btrfs-progs-3.16.1
|
||||||
|
)
|
||||||
|
"
|
||||||
|
|
||||||
|
# For CoreOS builds coreos-kernel must be installed because this ebuild
|
||||||
|
# checks the kernel config. The kernel config is left by the kernel compile
|
||||||
|
# or an explicit copy when installing binary packages. See coreos-kernel.eclass
|
||||||
|
DEPEND+="sys-kernel/coreos-kernel"
|
||||||
|
|
||||||
|
# https://github.com/docker/docker/blob/master/project/PACKAGERS.md#runtime-dependencies
|
||||||
|
# https://github.com/docker/docker/blob/master/project/PACKAGERS.md#optional-dependencies
|
||||||
|
RDEPEND="
|
||||||
|
${CDEPEND}
|
||||||
|
>=net-firewall/iptables-1.4
|
||||||
|
sys-process/procps
|
||||||
|
>=dev-vcs/git-1.7
|
||||||
|
>=app-arch/xz-utils-4.9
|
||||||
|
dev-libs/libltdl
|
||||||
|
=app-emulation/containerd-1.0.0[seccomp?]
|
||||||
|
=app-emulation/docker-runc-1.0.0_rc4_p171[apparmor?,seccomp?]
|
||||||
|
app-emulation/docker-proxy
|
||||||
|
container-init? ( >=sys-process/tini-0.13.1 )
|
||||||
|
"
|
||||||
|
|
||||||
|
RESTRICT="installsources strip"
|
||||||
|
|
||||||
|
S="${WORKDIR}/${P}/src/${COREOS_GO_PACKAGE}"
|
||||||
|
|
||||||
|
ENGINE_PATCHES=()
|
||||||
|
|
||||||
|
# see "contrib/check-config.sh" from upstream's sources
|
||||||
|
CONFIG_CHECK="
|
||||||
|
~NAMESPACES ~NET_NS ~PID_NS ~IPC_NS ~UTS_NS
|
||||||
|
~CGROUPS ~CGROUP_CPUACCT ~CGROUP_DEVICE ~CGROUP_FREEZER ~CGROUP_SCHED ~CPUSETS ~MEMCG
|
||||||
|
~KEYS
|
||||||
|
~VETH ~BRIDGE ~BRIDGE_NETFILTER
|
||||||
|
~NF_NAT_IPV4 ~IP_NF_FILTER ~IP_NF_TARGET_MASQUERADE
|
||||||
|
~NETFILTER_XT_MATCH_ADDRTYPE ~NETFILTER_XT_MATCH_CONNTRACK
|
||||||
|
~NF_NAT ~NF_NAT_NEEDED
|
||||||
|
~POSIX_MQUEUE
|
||||||
|
|
||||||
|
~USER_NS
|
||||||
|
~SECCOMP
|
||||||
|
~CGROUP_PIDS
|
||||||
|
~MEMCG_SWAP ~MEMCG_SWAP_ENABLED
|
||||||
|
|
||||||
|
~BLK_CGROUP ~BLK_DEV_THROTTLING ~IOSCHED_CFQ ~CFQ_GROUP_IOSCHED
|
||||||
|
~CGROUP_PERF
|
||||||
|
~CGROUP_HUGETLB
|
||||||
|
~NET_CLS_CGROUP
|
||||||
|
~CFS_BANDWIDTH ~FAIR_GROUP_SCHED ~RT_GROUP_SCHED
|
||||||
|
~IP_VS ~IP_VS_PROTO_TCP ~IP_VS_PROTO_UDP ~IP_VS_NFCT ~IP_VS_RR
|
||||||
|
|
||||||
|
~VXLAN
|
||||||
|
~XFRM_ALGO ~XFRM_USER
|
||||||
|
~IPVLAN
|
||||||
|
~MACVLAN ~DUMMY
|
||||||
|
"
|
||||||
|
|
||||||
|
ERROR_KEYS="CONFIG_KEYS: is mandatory"
|
||||||
|
ERROR_MEMCG_SWAP="CONFIG_MEMCG_SWAP: is required if you wish to limit swap usage of containers"
|
||||||
|
ERROR_RESOURCE_COUNTERS="CONFIG_RESOURCE_COUNTERS: is optional for container statistics gathering"
|
||||||
|
|
||||||
|
ERROR_BLK_CGROUP="CONFIG_BLK_CGROUP: is optional for container statistics gathering"
|
||||||
|
ERROR_IOSCHED_CFQ="CONFIG_IOSCHED_CFQ: is optional for container statistics gathering"
|
||||||
|
ERROR_CGROUP_PERF="CONFIG_CGROUP_PERF: is optional for container statistics gathering"
|
||||||
|
ERROR_CFS_BANDWIDTH="CONFIG_CFS_BANDWIDTH: is optional for container statistics gathering"
|
||||||
|
ERROR_XFRM_ALGO="CONFIG_XFRM_ALGO: is optional for secure networks"
|
||||||
|
ERROR_XFRM_USER="CONFIG_XFRM_USER: is optional for secure networks"
|
||||||
|
|
||||||
|
pkg_setup() {
|
||||||
|
if kernel_is lt 3 10; then
|
||||||
|
ewarn ""
|
||||||
|
ewarn "Using Docker with kernels older than 3.10 is unstable and unsupported."
|
||||||
|
ewarn " - http://docs.docker.com/engine/installation/binaries/#check-kernel-dependencies"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# for where these kernel versions come from, see:
|
||||||
|
# https://www.google.com/search?q=945b2b2d259d1a4364a2799e80e8ff32f8c6ee6f+site%3Akernel.org%2Fpub%2Flinux%2Fkernel+file%3AChangeLog*
|
||||||
|
if ! {
|
||||||
|
kernel_is ge 3 16 \
|
||||||
|
|| { kernel_is 3 15 && kernel_is ge 3 15 5; } \
|
||||||
|
|| { kernel_is 3 14 && kernel_is ge 3 14 12; } \
|
||||||
|
|| { kernel_is 3 12 && kernel_is ge 3 12 25; }
|
||||||
|
}; then
|
||||||
|
ewarn ""
|
||||||
|
ewarn "There is a serious Docker-related kernel panic that has been fixed in 3.16+"
|
||||||
|
ewarn " (and was backported to 3.15.5+, 3.14.12+, and 3.12.25+)"
|
||||||
|
ewarn ""
|
||||||
|
ewarn "See also https://github.com/docker/docker/issues/2960"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if kernel_is le 3 18; then
|
||||||
|
CONFIG_CHECK+="
|
||||||
|
~RESOURCE_COUNTERS
|
||||||
|
"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if kernel_is le 3 13; then
|
||||||
|
CONFIG_CHECK+="
|
||||||
|
~NETPRIO_CGROUP
|
||||||
|
"
|
||||||
|
else
|
||||||
|
CONFIG_CHECK+="
|
||||||
|
~CGROUP_NET_PRIO
|
||||||
|
"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if kernel_is lt 4 5; then
|
||||||
|
CONFIG_CHECK+="
|
||||||
|
~MEMCG_KMEM
|
||||||
|
"
|
||||||
|
ERROR_MEMCG_KMEM="CONFIG_MEMCG_KMEM: is optional"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if kernel_is lt 4 7; then
|
||||||
|
CONFIG_CHECK+="
|
||||||
|
~DEVPTS_MULTIPLE_INSTANCES
|
||||||
|
"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if use aufs; then
|
||||||
|
CONFIG_CHECK+="
|
||||||
|
~AUFS_FS
|
||||||
|
~EXT4_FS_POSIX_ACL ~EXT4_FS_SECURITY
|
||||||
|
"
|
||||||
|
ERROR_AUFS_FS="CONFIG_AUFS_FS: is required to be set if and only if aufs-sources are used instead of aufs4/aufs3"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if use btrfs; then
|
||||||
|
CONFIG_CHECK+="
|
||||||
|
~BTRFS_FS
|
||||||
|
~BTRFS_FS_POSIX_ACL
|
||||||
|
"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if use device-mapper; then
|
||||||
|
CONFIG_CHECK+="
|
||||||
|
~BLK_DEV_DM ~DM_THIN_PROVISIONING ~EXT4_FS ~EXT4_FS_POSIX_ACL ~EXT4_FS_SECURITY
|
||||||
|
"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if use overlay; then
|
||||||
|
CONFIG_CHECK+="
|
||||||
|
~OVERLAY_FS ~EXT4_FS_SECURITY ~EXT4_FS_POSIX_ACL
|
||||||
|
"
|
||||||
|
fi
|
||||||
|
|
||||||
|
linux-info_pkg_setup
|
||||||
|
|
||||||
|
# create docker group for the code checking for it in /etc/group
|
||||||
|
enewgroup docker
|
||||||
|
}
|
||||||
|
|
||||||
|
src_unpack() {
|
||||||
|
if [ -n "$DOCKER_GITCOMMIT" ]; then
|
||||||
|
mkdir -p "${S}"
|
||||||
|
tar --strip-components=1 -C "${S}" -xf "${DISTDIR}/${A}"
|
||||||
|
DOCKER_BUILD_DATE=$(date --reference="${S}/VERSION" +%s)
|
||||||
|
else
|
||||||
|
git-r3_src_unpack
|
||||||
|
DOCKER_GITCOMMIT=$(git -C "${S}" rev-parse HEAD | head -c 7)
|
||||||
|
DOCKER_BUILD_DATE=$(git -C "${S}" log -1 --format="%ct")
|
||||||
|
fi
|
||||||
|
[ "${#ENGINE_PATCHES[@]}" -gt 0 ] && eapply -d"${S}"/components/engine "${ENGINE_PATCHES[@]}"
|
||||||
|
# XXX: fix the insane version in the 17.12.0 tag -- DELETE THIS ON UPDATE
|
||||||
|
[ "x${PV}-ce" = "x$(<${S}/VERSION)" ] && die || echo "${PV}-ce" > "${S}/VERSION"
|
||||||
|
}
|
||||||
|
|
||||||
|
src_compile() {
|
||||||
|
local -x DISABLE_WARN_OUTSIDE_CONTAINER=1
|
||||||
|
go_export
|
||||||
|
export GOPATH="${WORKDIR}/${P}"
|
||||||
|
|
||||||
|
# setup CFLAGS and LDFLAGS for separate build target
|
||||||
|
# see https://github.com/tianon/docker-overlay/pull/10
|
||||||
|
export CGO_CFLAGS="${CGO_CFLAGS} -I${ROOT}/usr/include"
|
||||||
|
export CGO_LDFLAGS="${CGO_LDFLAGS} -L${ROOT}/usr/$(get_libdir)"
|
||||||
|
|
||||||
|
# if we're building from a tarball, we need the GITCOMMIT value
|
||||||
|
[ "$DOCKER_GITCOMMIT" ] && export DOCKER_GITCOMMIT
|
||||||
|
|
||||||
|
# fake golang layout
|
||||||
|
ln -s docker-ce/components/engine ../docker || die
|
||||||
|
ln -s docker-ce/components/cli ../cli || die
|
||||||
|
|
||||||
|
# let's set up some optional features :)
|
||||||
|
export DOCKER_BUILDTAGS=''
|
||||||
|
for gd in aufs btrfs device-mapper overlay; do
|
||||||
|
if ! use $gd; then
|
||||||
|
DOCKER_BUILDTAGS+=" exclude_graphdriver_${gd//-/}"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
for tag in apparmor pkcs11 seccomp selinux journald; do
|
||||||
|
if use $tag; then
|
||||||
|
DOCKER_BUILDTAGS+=" $tag"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
pushd components/engine || die
|
||||||
|
|
||||||
|
if use hardened; then
|
||||||
|
sed -i "s#EXTLDFLAGS_STATIC='#&-fno-PIC $LDFLAGS #" hack/make.sh || die
|
||||||
|
grep -q -- '-fno-PIC' hack/make.sh || die 'hardened sed failed'
|
||||||
|
sed "s#LDFLAGS_STATIC_DOCKER='#&-extldflags \"-fno-PIC $LDFLAGS\" #" \
|
||||||
|
-i hack/make/dynbinary-daemon || die
|
||||||
|
grep -q -- '-fno-PIC' hack/make/dynbinary-daemon || die 'hardened sed failed'
|
||||||
|
fi
|
||||||
|
|
||||||
|
# build daemon
|
||||||
|
SOURCE_DATE_EPOCH="${DOCKER_BUILD_DATE}" \
|
||||||
|
VERSION="$(<../../VERSION)" \
|
||||||
|
./hack/make.sh dynbinary || die 'dynbinary failed'
|
||||||
|
|
||||||
|
popd || die # components/engine
|
||||||
|
|
||||||
|
pushd components/cli || die
|
||||||
|
|
||||||
|
# Imitating https://github.com/docker/docker-ce/blob/v17.12.0-ce/components/cli/scripts/build/.variables#L7
|
||||||
|
CLI_BUILDTIME="$(date -d "@${DOCKER_BUILD_DATE}" --utc --rfc-3339 ns 2> /dev/null | sed -e 's/ /T/')"
|
||||||
|
# build cli
|
||||||
|
emake \
|
||||||
|
BUILDTIME="${CLI_BUILDTIME}" \
|
||||||
|
LDFLAGS="$(usex hardened "-extldflags \"-fno-PIC $LDFLAGS\"" '')" \
|
||||||
|
VERSION="$(cat ../../VERSION)" \
|
||||||
|
GITCOMMIT="${DOCKER_GITCOMMIT}" \
|
||||||
|
DISABLE_WARN_OUTSIDE_CONTAINER=1 \
|
||||||
|
dynbinary || die
|
||||||
|
|
||||||
|
popd || die # components/cli
|
||||||
|
}
|
||||||
|
|
||||||
|
src_install() {
|
||||||
|
dosym containerd /usr/bin/docker-containerd
|
||||||
|
dosym containerd-shim /usr/bin/docker-containerd-shim
|
||||||
|
dosym runc /usr/bin/docker-runc
|
||||||
|
use container-init && dosym tini /usr/bin/docker-init
|
||||||
|
|
||||||
|
pushd components/engine || die
|
||||||
|
newbin "$(readlink -f bundles/latest/dynbinary-daemon/dockerd)" dockerd
|
||||||
|
|
||||||
|
newinitd contrib/init/openrc/docker.initd docker
|
||||||
|
newconfd contrib/init/openrc/docker.confd docker
|
||||||
|
|
||||||
|
exeinto /usr/lib/coreos
|
||||||
|
# Create /usr/lib/coreos/dockerd for backwards compatibility
|
||||||
|
doexe "${FILESDIR}/dockerd"
|
||||||
|
|
||||||
|
systemd_dounit "${FILESDIR}/docker.service"
|
||||||
|
systemd_dounit "${FILESDIR}/docker.socket"
|
||||||
|
|
||||||
|
insinto /usr/lib/systemd/network
|
||||||
|
doins "${FILESDIR}"/50-docker.network
|
||||||
|
doins "${FILESDIR}"/90-docker-veth.network
|
||||||
|
|
||||||
|
udev_dorules contrib/udev/*.rules
|
||||||
|
|
||||||
|
dodoc AUTHORS CONTRIBUTING.md CHANGELOG.md NOTICE README.md
|
||||||
|
dodoc -r docs/*
|
||||||
|
|
||||||
|
insinto /usr/share/vim/vimfiles
|
||||||
|
doins -r contrib/syntax/vim/ftdetect
|
||||||
|
doins -r contrib/syntax/vim/syntax
|
||||||
|
popd || die # components/engine
|
||||||
|
|
||||||
|
pushd components/cli || die
|
||||||
|
|
||||||
|
newbin build/docker-* docker
|
||||||
|
|
||||||
|
dobashcomp contrib/completion/bash/*
|
||||||
|
insinto /usr/share/zsh/site-functions
|
||||||
|
doins contrib/completion/zsh/_*
|
||||||
|
popd || die # components/cli
|
||||||
|
}
|
||||||
|
|
||||||
|
pkg_postinst() {
|
||||||
|
udev_reload
|
||||||
|
|
||||||
|
elog
|
||||||
|
elog "To use Docker, the Docker daemon must be running as root. To automatically"
|
||||||
|
elog "start the Docker daemon at boot, add Docker to the default runlevel:"
|
||||||
|
elog " rc-update add docker default"
|
||||||
|
elog "Similarly for systemd:"
|
||||||
|
elog " systemctl enable docker.service"
|
||||||
|
elog
|
||||||
|
elog "To use Docker as a non-root user, add yourself to the 'docker' group:"
|
||||||
|
elog " usermod -aG docker youruser"
|
||||||
|
elog
|
||||||
|
}
|
1
sdk_container/src/third_party/coreos-overlay/app-emulation/docker/docker-18.01.0.ebuild
vendored
Symbolic link
1
sdk_container/src/third_party/coreos-overlay/app-emulation/docker/docker-18.01.0.ebuild
vendored
Symbolic link
@ -0,0 +1 @@
|
|||||||
|
docker-9999.ebuild
|
@ -19,7 +19,7 @@ else
|
|||||||
else
|
else
|
||||||
MY_PV="$PV-ce"
|
MY_PV="$PV-ce"
|
||||||
fi
|
fi
|
||||||
DOCKER_GITCOMMIT="486a48d"
|
DOCKER_GITCOMMIT="03596f5"
|
||||||
SRC_URI="https://${COREOS_GO_PACKAGE}/archive/v${MY_PV}.tar.gz -> ${P}.tar.gz"
|
SRC_URI="https://${COREOS_GO_PACKAGE}/archive/v${MY_PV}.tar.gz -> ${P}.tar.gz"
|
||||||
KEYWORDS="amd64 arm64"
|
KEYWORDS="amd64 arm64"
|
||||||
[ "$DOCKER_GITCOMMIT" ] || die "DOCKER_GITCOMMIT must be added manually for each bump!"
|
[ "$DOCKER_GITCOMMIT" ] || die "DOCKER_GITCOMMIT must be added manually for each bump!"
|
||||||
@ -211,8 +211,6 @@ src_unpack() {
|
|||||||
DOCKER_BUILD_DATE=$(git -C "${S}" log -1 --format="%ct")
|
DOCKER_BUILD_DATE=$(git -C "${S}" log -1 --format="%ct")
|
||||||
fi
|
fi
|
||||||
[ "${#ENGINE_PATCHES[@]}" -gt 0 ] && eapply -d"${S}"/components/engine "${ENGINE_PATCHES[@]}"
|
[ "${#ENGINE_PATCHES[@]}" -gt 0 ] && eapply -d"${S}"/components/engine "${ENGINE_PATCHES[@]}"
|
||||||
# XXX: fix the insane version in the 17.12.0 tag -- DELETE THIS ON UPDATE
|
|
||||||
[ "x${PV}-ce" = "x$(<${S}/VERSION)" ] && die || echo "${PV}-ce" > "${S}/VERSION"
|
|
||||||
}
|
}
|
||||||
|
|
||||||
src_compile() {
|
src_compile() {
|
||||||
@ -265,7 +263,7 @@ src_compile() {
|
|||||||
|
|
||||||
pushd components/cli || die
|
pushd components/cli || die
|
||||||
|
|
||||||
# Imitating https://github.com/docker/docker-ce/blob/v17.12.0-ce/components/cli/scripts/build/.variables#L7
|
# Imitating https://github.com/docker/docker-ce/blob/v18.01.0-ce/components/cli/scripts/build/.variables#L7
|
||||||
CLI_BUILDTIME="$(date -d "@${DOCKER_BUILD_DATE}" --utc --rfc-3339 ns 2> /dev/null | sed -e 's/ /T/')"
|
CLI_BUILDTIME="$(date -d "@${DOCKER_BUILD_DATE}" --utc --rfc-3339 ns 2> /dev/null | sed -e 's/ /T/')"
|
||||||
# build cli
|
# build cli
|
||||||
emake \
|
emake \
|
||||||
|
@ -1,4 +1,4 @@
|
|||||||
# Copyright (c) 2017 CoreOS, Inc.. All rights reserved.
|
# Copyright (c) 2017-2018 CoreOS, Inc.. All rights reserved.
|
||||||
# Distributed under the terms of the GNU General Public License v2
|
# Distributed under the terms of the GNU General Public License v2
|
||||||
|
|
||||||
EAPI=2
|
EAPI=2
|
||||||
@ -11,17 +11,17 @@ KEYWORDS="amd64 arm64"
|
|||||||
|
|
||||||
# Explicitly list all packages that will be built into the image.
|
# Explicitly list all packages that will be built into the image.
|
||||||
RDEPEND="
|
RDEPEND="
|
||||||
=app-emulation/docker-17.09.1
|
=app-emulation/docker-18.01.0
|
||||||
=app-emulation/containerd-0.2.9_p27
|
=app-emulation/containerd-1.0.0
|
||||||
=app-emulation/docker-proxy-0.8.0_p20170917
|
=app-emulation/docker-proxy-0.8.0_p20170917
|
||||||
=app-emulation/docker-runc-1.0.0_rc4_p25
|
=app-emulation/docker-runc-1.0.0_rc4_p171
|
||||||
=dev-libs/libltdl-2.4.6
|
=dev-libs/libltdl-2.4.6
|
||||||
=sys-process/tini-0.13.2
|
=sys-process/tini-0.13.2
|
||||||
"
|
"
|
||||||
|
|
||||||
src_install() {
|
src_install() {
|
||||||
insinto /.torcx
|
insinto /.torcx
|
||||||
newins "${FILESDIR}/${PN}-${PV}-manifest.json" manifest.json
|
newins "${FILESDIR}/${P}-manifest.json" manifest.json
|
||||||
|
|
||||||
# Enable the Docker socket by default.
|
# Enable the Docker socket by default.
|
||||||
local unitdir=/usr/lib/systemd/system
|
local unitdir=/usr/lib/systemd/system
|
@ -1,15 +0,0 @@
|
|||||||
DEFINED_PHASES=compile install prepare unpack
|
|
||||||
DEPEND=dev-lang/go:1.8= virtual/pkgconfig
|
|
||||||
DESCRIPTION=A daemon to control runC
|
|
||||||
EAPI=6
|
|
||||||
HOMEPAGE=https://containerd.tools
|
|
||||||
IUSE=hardened +seccomp +go_version_go1_8
|
|
||||||
KEYWORDS=amd64 arm64
|
|
||||||
LICENSE=Apache-2.0
|
|
||||||
RDEPEND=>=app-emulation/docker-runc-1.0.0_rc4 seccomp? ( sys-libs/libseccomp )
|
|
||||||
REQUIRED_USE=go_version_go1_8
|
|
||||||
RESTRICT=test
|
|
||||||
SLOT=0
|
|
||||||
SRC_URI=https://github.com/containerd/containerd/archive/06b9cb35161009dcb7123345749fef02f7cea8e0.tar.gz -> containerd-0.2.9_p27.tar.gz
|
|
||||||
_eclasses_=coreos-go 1b5f6ac7749b16d9f26b8b2813f6d09c coreos-go-depend 14c6f09b2aaca3f3965f1895f1566f7c coreos-go-utils c34072f13165bb85e5106cc6e082a4e1 epatch 8233751dc5105a6ae8fcd86ce2bb0247 estack 43ddf5aaffa7a8d0482df54d25a66a1f eutils 227b041a120d309fdefbebb3b8c1dfa9 flag-o-matic 2274fcc1e7ef6affaff5bcd636275417 ltprune 2770eed66a9b8ef944714cd0e968182e multilib 97f470f374f2e94ccab04a2fb21d811e multiprocessing 6f5991c7101863d0b29df63990ad852e systemd 34815d3b76e745c5ca33eec9f95074c2 toolchain-funcs 185a06792159ca143528e7010368e8af vcs-snapshot 03289f51c769cf409d200d2d628cdd6e
|
|
||||||
_md5_=685dd0e7d5dec8965635664ed748005b
|
|
@ -1,15 +0,0 @@
|
|||||||
DEFINED_PHASES=compile install postinst setup unpack
|
|
||||||
DEPEND=>=dev-db/sqlite-3.7.9:3 device-mapper? ( >=sys-fs/lvm2-2.02.89[thin] ) seccomp? ( >=sys-libs/libseccomp-2.2.1[static-libs] ) apparmor? ( sys-libs/libapparmor ) btrfs? ( >=sys-fs/btrfs-progs-3.16.1 ) sys-kernel/coreos-kernel dev-lang/go:1.8= virtual/pkgconfig virtual/pkgconfig
|
|
||||||
DESCRIPTION=The core functions you need to create Docker images and run Docker containers
|
|
||||||
EAPI=6
|
|
||||||
HOMEPAGE=https://dockerproject.org
|
|
||||||
IUSE=apparmor aufs +btrfs +container-init +device-mapper hardened +overlay pkcs11 seccomp +journald +selinux +go_version_go1_8
|
|
||||||
KEYWORDS=amd64 arm64
|
|
||||||
LICENSE=Apache-2.0
|
|
||||||
RDEPEND=>=dev-db/sqlite-3.7.9:3 device-mapper? ( >=sys-fs/lvm2-2.02.89[thin] ) seccomp? ( >=sys-libs/libseccomp-2.2.1[static-libs] ) apparmor? ( sys-libs/libapparmor ) >=net-firewall/iptables-1.4 sys-process/procps >=dev-vcs/git-1.7 >=app-arch/xz-utils-4.9 =app-emulation/containerd-0.2.9_p27[seccomp?] =app-emulation/docker-runc-1.0.0_rc4_p25[apparmor?,seccomp?] app-emulation/docker-proxy container-init? ( >=sys-process/tini-0.13.1 )
|
|
||||||
REQUIRED_USE=go_version_go1_8
|
|
||||||
RESTRICT=installsources strip
|
|
||||||
SLOT=0
|
|
||||||
SRC_URI=https://github.com/docker/docker-ce/archive/v17.09.1-ce.tar.gz -> docker-17.09.1.tar.gz
|
|
||||||
_eclasses_=bash-completion-r1 8e447753aaf658afa609fbf961d80ab7 coreos-go-depend 14c6f09b2aaca3f3965f1895f1566f7c coreos-go-utils c34072f13165bb85e5106cc6e082a4e1 epatch 8233751dc5105a6ae8fcd86ce2bb0247 estack 43ddf5aaffa7a8d0482df54d25a66a1f eutils 227b041a120d309fdefbebb3b8c1dfa9 flag-o-matic 2274fcc1e7ef6affaff5bcd636275417 linux-info ca370deef9d44125d829f2eb6ebc83e0 ltprune 2770eed66a9b8ef944714cd0e968182e multilib 97f470f374f2e94ccab04a2fb21d811e systemd 34815d3b76e745c5ca33eec9f95074c2 toolchain-funcs 185a06792159ca143528e7010368e8af udev d91cac2c73b94629cad2daea66e0d182 user e4b567c44272a719fabf53f0f885d3f7 versionator c80ccf29e90adea7c5cae94b42eb76d0
|
|
||||||
_md5_=d0cea6f01df1804f62aab1df46036f86
|
|
@ -1,15 +0,0 @@
|
|||||||
DEFINED_PHASES=compile install prepare unpack
|
|
||||||
DEPEND=dev-lang/go:1.8=
|
|
||||||
DESCRIPTION=runc container cli tools (docker fork)
|
|
||||||
EAPI=6
|
|
||||||
HOMEPAGE=http://runc.io
|
|
||||||
IUSE=ambient apparmor hardened +seccomp selinux +go_version_go1_8
|
|
||||||
KEYWORDS=amd64 arm64
|
|
||||||
LICENSE=Apache-2.0
|
|
||||||
RDEPEND=apparmor? ( sys-libs/libapparmor ) seccomp? ( sys-libs/libseccomp ) !app-emulation/runc
|
|
||||||
REQUIRED_USE=go_version_go1_8
|
|
||||||
RESTRICT=test
|
|
||||||
SLOT=0
|
|
||||||
SRC_URI=https://github.com/opencontainers/runc/archive/3f2f8b84a77f73d38244dd690525642a72156c64.tar.gz -> docker-runc-1.0.0_rc4_p25.tar.gz
|
|
||||||
_eclasses_=coreos-go 1b5f6ac7749b16d9f26b8b2813f6d09c coreos-go-depend 14c6f09b2aaca3f3965f1895f1566f7c coreos-go-utils c34072f13165bb85e5106cc6e082a4e1 epatch 8233751dc5105a6ae8fcd86ce2bb0247 estack 43ddf5aaffa7a8d0482df54d25a66a1f eutils 227b041a120d309fdefbebb3b8c1dfa9 flag-o-matic 2274fcc1e7ef6affaff5bcd636275417 ltprune 2770eed66a9b8ef944714cd0e968182e multilib 97f470f374f2e94ccab04a2fb21d811e multiprocessing 6f5991c7101863d0b29df63990ad852e toolchain-funcs 185a06792159ca143528e7010368e8af vcs-snapshot 03289f51c769cf409d200d2d628cdd6e
|
|
||||||
_md5_=1ebfb58563729852441808f97e0089eb
|
|
@ -1,8 +0,0 @@
|
|||||||
DEFINED_PHASES=install
|
|
||||||
DESCRIPTION=Packages to be installed in a torcx image for Docker
|
|
||||||
EAPI=2
|
|
||||||
KEYWORDS=amd64 arm64
|
|
||||||
LICENSE=GPL-2
|
|
||||||
RDEPEND==app-emulation/docker-17.09.1 =app-emulation/containerd-0.2.9_p27 =app-emulation/docker-proxy-0.8.0_p20170917 =app-emulation/docker-runc-1.0.0_rc4_p25 =dev-libs/libltdl-2.4.6 =sys-process/tini-0.13.2
|
|
||||||
SLOT=0
|
|
||||||
_md5_=46b5aa81912ee9697e282bd0af1e841c
|
|
Loading…
x
Reference in New Issue
Block a user