Installation
docker pull code.tilo.so/tilo/tilo-ci:main-79835b2-x86_64-46712-2sha256:f74a310cac598b222d2b08e1331c96475394263ce40786272e58bfb592020c87About this package
desktop environment, OS, pain in the ass to work on
Image layers
| ostree export of commit 3e10e9e11e2977f1051b9ef2b4e76a88455fce144911901324c3dae406928fcb |
| python3-botocore-1.43.52-1.fc44.noarch |
| nvidia-gpu-firmware-20260622-1.fc44.noarch |
| kernel-modules-7.1.5-201.fc44.x86_64 |
| kernel-modules-core-7.1.5-201.fc44.x86_64 |
| podman-5:5.8.4-1.fc44.x86_64 |
| linux-firmware-20260622-1.fc44.noarch |
| atheros-firmware-20260622-1.fc44.noarch |
| python3-libs-3.14.6-1.fc44.x86_64 |
| libicu-77.1-3.fc44.x86_64 |
| rpm-6.0.2-1.fc44.x86_64 |
| mt7xxx-firmware-20260622-1.fc44.noarch |
| qemu-user-static-mips-2:10.2.2-1.fc44.x86_64 |
| kernel-core-7.1.5-201.fc44.x86_64 |
| amd-gpu-firmware-20260622-1.fc44.noarch |
| skopeo-1:1.22.2-2.fc44.x86_64 |
| bootc-1.16.4-1.fc44.x86_64 |
| qemu-user-static-ppc-2:10.2.2-1.fc44.x86_64 |
| glib2-2.88.2-1.fc44.x86_64 |
| qemu-user-static-aarch64-2:10.2.2-1.fc44.x86_64 |
| microcode_ctl-2:2.1-74.fc44.x86_64 |
| qemu-user-static-xtensa-2:10.2.2-1.fc44.x86_64 |
| rpm-ostree-2026.2-1.fc44.x86_64 |
| systemd-udev-259.8-1.fc44.x86_64 |
| qemu-user-static-sparc-2:10.2.2-1.fc44.x86_64 |
| systemd-259.8-1.fc44.x86_64 |
| toolbox-0.3-4.fc44.x86_64 |
| intel-gpu-firmware-20260622-1.fc44.noarch |
| file-libs-5.46-10.fc44.x86_64 |
| fwupd-2.1.7-1.fc44.x86_64 |
| samba-client-libs-2:4.24.4-1.fc44.x86_64 |
| qemu-user-static-riscv-2:10.2.2-1.fc44.x86_64 |
| qemu-user-static-arm-2:10.2.2-1.fc44.x86_64 |
| coreutils-common-9.10-4.fc44.x86_64 |
| NetworkManager-libnm-1:1.56.1-2.fc44.x86_64 |
| hwdata-0.409-1.fc44.noarch |
| python3-libdnf5-5.4.2.1-1.fc44.x86_64 |
| 182 components |
| systemd-resolved-259.8-1.fc44.x86_64 |
| vim-minimal-2:9.2.843-1.fc44.x86_64 and systemd-shared-259.8-1.fc44.x86_64 and systemd-libs-259.8-1.fc44.x86_64 and systemd-pam-259.8-1.fc44.x86_64 and python3-boto3-1.43.52-1.fc44.noarch |
| 12 components |
| glibc-gconv-extra-2.43-7.fc44.x86_64 and glibc-2.43-7.fc44.x86_64 |
| 12 components |
| 12 components |
| 12 components |
| 7 components |
| 12 components |
| 12 components |
| 12 components |
| samba-ndr-libs-2:4.24.4-1.fc44.x86_64 and samba-core-libs-2:4.24.4-1.fc44.x86_64 |
| 8 components |
| 12 components |
| 12 components |
| 12 components |
| 12 components |
| 12 components |
| 24 components |
| 24 components |
| 24 components |
| 24 components |
| 16 components |
| 24 components |
| dracut-108-7.fc44.x86_64 and python-pip-wheel-26.0.1-2.fc44.noarch |
| initramfs (kernel 7.1.5-201.fc44.x86_64) and rpmostree-unpackaged-content |
| Reserved for new packages |
| COPY --chmod=0755 os/scripts/finalize-rpmdb.sh /usr/libexec/tilo/finalize-rpmdb # buildkit |
| ARG FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo mesa-dri-drivers mesa-vulkan-drivers libglvnd-egl harfbuzz-icu libatomic at-spi2-core plymouth plymouth-plugin-script plymouth-scripts && dnf clean all && ${FINALIZE_RPMDB} # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo pipewire pipewire-pulseaudio pipewire-utils wireplumber v4l-utils sane-backends sane-backends-drivers-scanners tesseract tesseract-langpack-eng libcanberra-gtk3 sound-theme-freedesktop && dnf clean all && ${FINALIZE_RPMDB} # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo gstreamer1 gstreamer1-plugins-base gstreamer1-plugins-good gstreamer1-plugins-bad-free gstreamer1-plugin-libav gstreamer1-plugin-dav1d ffmpeg-free python3 && dnf clean all && ${FINALIZE_RPMDB} && gst-inspect-1.0 vp9enc >/dev/null && gst-inspect-1.0 vp9dec >/dev/null && gst-inspect-1.0 av1enc >/dev/null && gst-inspect-1.0 dav1ddec >/dev/null && gst-inspect-1.0 h264parse >/dev/null && gst-inspect-1.0 rtph264pay >/dev/null && gst-inspect-1.0 rtponviftimestamp >/dev/null && gst-inspect-1.0 rtpstreampay >/dev/null # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo greetd fprintd fprintd-pam gnome-keyring gnome-keyring-pam polkit && dnf clean all && ${FINALIZE_RPMDB} # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo bubblewrap flatpak dbus-tools xdg-dbus-proxy distrobox cups cups-ipptool podman foot wl-clipboard NetworkManager NetworkManager-wifi wireless-regdb ModemManager fwupd fuse3 cage && dnf clean all && ${FINALIZE_RPMDB} && ln -sfn ../run/NetworkManager/resolv.conf /etc/resolv.conf && installed="$(rpm -qa --qf '%{NAME}\n')" && printf '%s\n' "$installed" | awk '/^systemd-(coredump|networkd|resolved)$/' | xargs -r dnf --disablerepo='*' remove -y && test "$(readlink /etc/resolv.conf)" = ../run/NetworkManager/resolv.conf && installed="$(rpm -qa --qf '%{NAME}\n')" && ! printf '%s\n' "$installed" | grep -Eq '^systemd-(coredump|networkd|resolved)$' && dnf clean all && ${FINALIZE_RPMDB} # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo xdg-desktop-portal && dnf clean all && ${FINALIZE_RPMDB} # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo chrony zram-generator glibc-langpack-ar glibc-langpack-cs glibc-langpack-da glibc-langpack-de glibc-langpack-en glibc-langpack-es glibc-langpack-fi glibc-langpack-fr glibc-langpack-it glibc-langpack-ja glibc-langpack-ko glibc-langpack-nb glibc-langpack-nl glibc-langpack-pl glibc-langpack-pt glibc-langpack-ru glibc-langpack-sv glibc-langpack-tr glibc-langpack-uk glibc-langpack-zh firewalld bluez power-profiles-daemon && dnf clean all && ${FINALIZE_RPMDB} # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo hunspell hunspell-en hunspell-de hunspell-es hunspell-fr hunspell-it hunspell-nl hunspell-pl hunspell-pt hunspell-ru && dnf clean all && ${FINALIZE_RPMDB} # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo cups cups-ipptool && dnf clean all && ${FINALIZE_RPMDB} # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c grep -q '^video:' /etc/group || echo "video:x:39:greetd" >> /etc/group; grep -q '^input:' /etc/group || echo "input:x:104:greetd" >> /etc/group; sed -i 's/^video:x:39:$/video:x:39:greetd/' /etc/group; sed -i 's/^input:x:104:$/input:x:104:greetd/' /etc/group; grep -q '^video:x:39:.*greetd' /etc/group; grep -q '^input:x:104:.*greetd' /etc/group # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo fontconfig adwaita-sans-fonts && dnf clean all && ${FINALIZE_RPMDB} && python3 /tilo-src/tools/font-catalog.py stage /tilo-src/crates/sdk/ui-core/assets/fonts /usr/share/fonts/tilo --scope product && install -D -m 0644 /tilo-src/57-tilo-fonts.conf /usr/share/fontconfig/conf.avail/57-tilo-fonts.conf && ln -s ../../../usr/share/fontconfig/conf.avail/57-tilo-fonts.conf /etc/fonts/conf.d/57-tilo-fonts.conf && fc-cache -s && for generic in 'Noto Sans CJK SC' serif monospace emoji; do case "$(fc-match -f '%{file}' "$generic")" in /usr/share/fonts/tilo/*) ;; *) echo "fontconfig does not resolve $generic from the catalog" >&2; exit 1 ;; esac; done # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo wayland-devel libxkbcommon-devel libinput-devel && rpm -e --nodeps wayland-devel libxkbcommon-devel libinput-devel && installed="$(rpm -qa --qf '%{NAME}\n')" && printf '%s\n' "$installed" | awk '/^(pkgconf-pkg-config|pkgconf|pkgconf-m4|libpkgconf)$/' | xargs -r rpm -e --nodeps && installed="$(rpm -qa --qf '%{NAME}\n')" && ! printf '%s\n' "$installed" | grep -Eq '^(wayland-devel|libxkbcommon-devel|libinput-devel|pkgconf-pkg-config|pkgconf|pkgconf-m4|libpkgconf)$' && dnf clean all && ${FINALIZE_RPMDB} # buildkit |
| COPY /wpe/ / # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo libepoxy libsoup3 enchant2 hyphen woff2 lcms2 libjxl flite openjpeg2 libavif libwebp libgcrypt libtasn1 libsecret atk at-spi2-atk libmanette libxslt && dnf clean all && ${FINALIZE_RPMDB} && ldconfig && gst-inspect-1.0 h264parse >/dev/null && gst-inspect-1.0 hlssink2 >/dev/null && gst-inspect-1.0 pulsesrc >/dev/null && gst-inspect-1.0 avenc_aac >/dev/null && gst-inspect-1.0 aacparse >/dev/null && bash /run/tilo-check-wpe-runtime.sh "the rootfs WPE WebKit runtime dnf list above" # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo systemd-boot-unsigned && rpm -qa | grep -E '^(shim-(x64|aa64)|grub2-)' | xargs -r rpm -e --nodeps && rpm -e --nodeps bootupd && rm -rf /usr/lib/bootupd /usr/lib/ostree-boot && dnf clean all && ${FINALIZE_RPMDB} # buildkit |
| COPY os/usr/share/plymouth/themes/tilo/ /usr/share/plymouth/themes/tilo/ # buildkit |
| COPY os/dev/make-plymouth-assets.py os/scripts/verify-runtime-crypto-packages.sh /usr/local/bin/ # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo systemd-ukify && python3 /usr/local/bin/make-plymouth-assets.py /usr/share/plymouth/themes/tilo && plymouth-set-default-theme tilo && test "$(plymouth-set-default-theme)" = tilo && dnf --disablerepo='*' remove -y systemd-ukify python3-pillow && installed="$(rpm -qa --qf '%{NAME}\n')" && printf '%s\n' "$installed" | awk '/^(systemd-ukify|openssl|sbsigntools|efitools|mokutil|pesign|nss-tools|gnutls-utils|git|git-core|openvpn|NetworkManager-openvpn|openssh-server)$/' | xargs -r dnf --disablerepo='*' remove -y && installed="$(rpm -qa --qf '%{NAME}\n')" && ! printf '%s\n' "$installed" | grep -Eq '^(python3-pillow|systemd-ukify|openssl|sbsigntools|efitools|mokutil|pesign|nss-tools|gnutls-utils|git|git-core|openvpn|NetworkManager-openvpn|openssh-server)$' && rpm -q openssh openssh-clients && dnf clean all && ${FINALIZE_RPMDB} # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo tpm2-tools && dnf clean all && ${FINALIZE_RPMDB} && rm -rf /var/cache/dnf /var/log/dnf* /var/lib/dnf # buildkit |
| RUN |1 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb /bin/sh -c dnf install -y --setopt=reposdir=/repo compiler-rt && scudo="$(find /usr/lib /usr/lib64 -name 'libclang_rt.scudo_standalone.so' 2>/dev/null | head -1)" && test -n "$scudo" && install -D -m 0755 "$scudo" /usr/lib/tilo/libclang_rt.scudo_standalone.so && rpm -e --nodeps compiler-rt clang-resource-filesystem && ! rpm -q compiler-rt clang-resource-filesystem >/dev/null 2>&1 && test -s /usr/lib/tilo/libclang_rt.scudo_standalone.so && dnf clean all && ${FINALIZE_RPMDB} && scudo=/usr/lib/tilo/libclang_rt.scudo_standalone.so && mkdir -p /usr/lib/systemd/system/fs.service.d && printf '[Service]\n# Hardened userspace allocator; path resolved at image build.\nEnvironment=LD_PRELOAD=%s\n# Hardware shadow stacks. The ELF marking alone does not enable them.\nEnvironment=GLIBC_TUNABLES=glibc.cpu.hwcaps=SHSTK\n' "$scudo" > /usr/lib/systemd/system/fs.service.d/10-hardened-malloc.conf && echo "scudo wired: $scudo" # buildkit |
| ARG TILO_WINDOWS_ARCH |
| RUN |2 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 /bin/sh -c test "$(uname -m)" = "$TILO_WINDOWS_ARCH" && case "$(uname -m)" in x86_64) vm_firmware=edk2-ovmf; windows_packages='wine wine-dxvk' ;; aarch64) vm_firmware=edk2-aarch64; windows_packages='glibc libgcc libstdc++ libglvnd-glx libglvnd-opengl libglvnd-egl qt6-qtbase qt6-qtbase-gui qt6-qtdeclarative alsa-lib libdrm libwayland-client vulkan-loader' ;; *) echo 'unsupported Windows VM firmware architecture' >&2; exit 1 ;; esac && dnf install -y --setopt=reposdir=/repo --exclude=dosbox-staging $windows_packages qemu-kvm libvirt-client libvirt-daemon-kvm libvirt-daemon-config-nwfilter swtpm swtpm-tools "$vm_firmware" freerdp xwayland-satellite virt-viewer xorriso genisoimage udftools && dnf clean all && ${FINALIZE_RPMDB} # buildkit |
| COPY os/usr/share/tilo/selinux/tilo-base.cil /usr/share/tilo/selinux/tilo-base.cil # buildkit |
| COPY os/usr/lib/systemd/system/fs.service.d/20-selinux.conf /usr/lib/systemd/system/fs.service.d/20-selinux.conf # buildkit |
| RUN |2 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 /bin/sh -c cp -a /etc/selinux/targeted /var/tmp/tilo-sestore && rm -rf /etc/selinux/targeted && mv /var/tmp/tilo-sestore /etc/selinux/targeted && rm -rf /etc/selinux/targeted/tmp && find /usr/share/selinux/packages -type f \( -name '*.pp' -o -name '*.pp.bz2' \) -print | sort | while IFS= read -r policy; do semodule -n -s targeted -X 200 -i "$policy" || exit 1; done && semodule -i /usr/share/tilo/selinux/tilo-base.cil && semodule -s targeted -lfull > /var/tmp/tilo-active-selinux-modules && find /usr/share/selinux/packages -type f \( -name '*.pp' -o -name '*.pp.bz2' \) -print | sort | while IFS= read -r policy; do module="$(basename "$policy")"; module="${module%.bz2}"; module="${module%.pp}"; awk -v module="$module" '$1 == "200" && $2 == module { found=1 } END { exit !found }' /var/tmp/tilo-active-selinux-modules || exit 1; done && semodule -s targeted -lfull | grep -Eq '^400[[:space:]]+tilo-base[[:space:]]' && rm -f /var/tmp/tilo-active-selinux-modules && echo "all packaged add-on and tilo-base SELinux modules loaded" # buildkit |
| COPY / / # buildkit |
| COPY os/usr/lib/systemd/user/tilo-models.service os/usr/lib/systemd/user/tilo-models.socket os/usr/lib/systemd/user/tilo-model-gateway.service os/usr/lib/systemd/user/tilo-model-gateway.socket os/usr/lib/systemd/user/tilo-app-host.service os/usr/lib/systemd/user/tilo-app-host.socket /usr/lib/systemd/user/ # buildkit |
| COPY os/usr/lib/systemd/system/tilo-relay.service os/usr/lib/systemd/system/tilo-fs-replica.service os/usr/lib/systemd/system/tilo-relay-firstboot.service os/usr/lib/systemd/system/tilo-network-start.timer os/usr/lib/systemd/system/tilo-network-start.target /usr/lib/systemd/system/ # buildkit |
| COPY os/usr/lib/systemd/system/NetworkManager.service.d/20-tilo-firewall-first.conf /usr/lib/systemd/system/NetworkManager.service.d/20-tilo-firewall-first.conf # buildkit |
| COPY os/usr/libexec/tilo-relay-firstboot /usr/libexec/tilo-relay-firstboot # buildkit |
| COPY os/usr/share/polkit-1/actions/org.tilo.home-peer.policy /usr/share/polkit-1/actions/org.tilo.home-peer.policy # buildkit |
| COPY os/etc/polkit-1/rules.d/49-tilo-home-peer.rules os/etc/polkit-1/rules.d/49-tilo-greeter-power.rules os/etc/polkit-1/rules.d/49-tilo-greeter-fingerprint.rules /etc/polkit-1/rules.d/ # buildkit |
| RUN |2 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 /bin/sh -c chmod 0755 /usr/bin/tilo-relay /usr/bin/tilo-relay-admin /usr/bin/tilo-enroll /usr/libexec/tilo-home-peer-control /usr/libexec/tilo-relay-firstboot # buildkit |
| COPY os/usr/libexec/tilo-fluxcast /usr/libexec/tilo-fluxcast # buildkit |
| RUN |2 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 /bin/sh -c install -D -m 0644 /tilo-assets/doubletake-ae06722-LICENSE /usr/share/licenses/tilo-doubletake/LICENSE && install -D -m 0644 /tilo-assets/fluxcast-a74f39f-LICENSE /usr/share/licenses/tilo-fluxcast/LICENSE # buildkit |
| RUN |2 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 /bin/sh -c bash /tmp/install-pdfium.sh /tilo-assets /usr /tmp/tilo-assets.tsv # buildkit |
| COPY os/usr/share/dbus-1/system.d/zz-tilo-projector-wifi-direct.conf /usr/share/dbus-1/system.d/zz-tilo-projector-wifi-direct.conf # buildkit |
| COPY os/usr/lib/systemd/user/tilo-ush.service os/usr/lib/systemd/user/tilo-ush.socket os/usr/lib/systemd/user/tilo-fs-recipient.service os/usr/lib/systemd/user/tilo-fs-recipient.socket /usr/lib/systemd/user/ # buildkit |
| COPY os/tests/airplay-encrypted-session.sh /usr/libexec/tilo/airplay-encrypted-session-test.sh # buildkit |
| COPY os/tests/projection-boot-check.sh /usr/libexec/tilo/projection-boot-check.sh # buildkit |
| RUN |2 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 /bin/sh -c chmod 0755 /usr/libexec/tilo/airplay-encrypted-session-test.sh /usr/libexec/tilo/projection-boot-check.sh # buildkit |
| RUN |2 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 /bin/sh -c chmod 755 /usr/bin/shell /usr/bin/fs /usr/bin/terminal /usr/bin/file-explorer /usr/bin/tilo-greeter /usr/bin/tilo-installer /usr/bin/tilo-launcher /usr/bin/tilo-runtime-bundle /usr/bin/tilo-install /usr/bin/tilo-app-package /usr/libexec/tilo-cli-shim /usr/libexec/tilo-unlock-helper /usr/libexec/tilo-ush /usr/libexec/tilo-projector /usr/libexec/tilo-doubletake /usr/libexec/tilo-doubletake-test-receiver /usr/libexec/tilo-fluxcast && { [ ! -e /usr/bin/browser ] || chmod 755 /usr/bin/browser; } && missing="$(ldd /usr/bin/shell | awk '/not found/ { print $1 }')" && { if [ -n "$missing" ]; then printf 'shell has unresolved runtime libraries:\n%s\n' "$missing" >&2; exit 1; fi; } && { /usr/libexec/tilo-doubletake -h >/dev/null || { echo 'doubletake help smoke test failed' >&2; exit 1; }; } && { /usr/libexec/tilo-fluxcast --help >/dev/null || { echo 'fluxcast help smoke test failed' >&2; exit 1; }; } # buildkit |
| COPY /usr/lib/tilo-runtime/ /usr/lib/tilo-runtime/ # buildkit |
| COPY /out/runtime-bundle-publisher.hex /out/browser-runtime-publisher.hex /usr/share/tilo/ # buildkit |
| RUN |2 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 /bin/sh -c mkdir -p /etc/tilo && cat /usr/share/tilo/runtime-bundle-publisher.hex > /etc/tilo/runtime-bundle-trusted-publishers.txt && cat /usr/share/tilo/browser-runtime-publisher.hex >> /etc/tilo/runtime-bundle-trusted-publishers.txt # buildkit |
| COPY /usr/share/tilo-apps/ /usr/share/tilo-apps/ # buildkit |
| COPY /out/app-publisher.hex /usr/share/tilo/app-publisher.hex # buildkit |
| COPY os/etc/profile.d/tilo-apps.sh /etc/profile.d/tilo-apps.sh # buildkit |
| COPY os/usr/lib/systemd/system/fs.service os/usr/lib/systemd/system/tilo-store-volume.service os/usr/lib/systemd/system/tilo-store-loop.service os/usr/lib/systemd/system/tilo-fs-start.timer os/usr/lib/systemd/system/fs-identity.path os/usr/lib/systemd/system/tilo-device-key-init.service os/usr/lib/systemd/system/tilo-growfs-sysroot.service os/usr/lib/systemd/system/tilo-growfs-sysroot.timer /usr/lib/systemd/system/ # buildkit |
| COPY os/usr/lib/systemd/system/systemd-tpm2-setup.service.d/10-tilo-live-installer.conf /usr/lib/systemd/system/systemd-tpm2-setup.service.d/10-tilo-live-installer.conf # buildkit |
| COPY os/usr/lib/systemd/system/systemd-tpm2-setup-early.service.d/10-tilo-live-installer.conf /usr/lib/systemd/system/systemd-tpm2-setup-early.service.d/10-tilo-live-installer.conf # buildkit |
| COPY os/usr/share/tilo/fs-capabilities.json /usr/share/tilo/fs-capabilities.json # buildkit |
| COPY os/usr/share/tilo/git/synced-worktree.gitconfig /usr/share/tilo/git/synced-worktree.gitconfig # buildkit |
| COPY os/etc/gitconfig /etc/gitconfig # buildkit |
| COPY os/usr/share/wayland-sessions/shell.desktop os/usr/share/wayland-sessions/shell-peer-sync.desktop /usr/share/wayland-sessions/ # buildkit |
| COPY --chmod=0755 os/usr/libexec/tilo-session os/usr/libexec/tilo-security-audit /usr/libexec/ # buildkit |
| COPY os/usr/lib/systemd/user/tilo-graphical-session.target /usr/lib/systemd/user/tilo-graphical-session.target # buildkit |
| COPY / / # buildkit |
| COPY os/etc/greetd/config.toml /etc/greetd/config.toml # buildkit |
| COPY os/etc/pam.d/greetd os/etc/pam.d/tilo-unlock /etc/pam.d/ # buildkit |
| COPY os/usr/lib/udev/rules.d/90-tilo-backlight.rules os/usr/lib/udev/rules.d/60-tilo-io-scheduler.rules os/usr/lib/udev/rules.d/70-tilo-console.rules /usr/lib/udev/rules.d/ # buildkit |
| COPY os/usr/lib/systemd/system/systemd-growfs-root.service.d/10-tilo-composefs.conf /usr/lib/systemd/system/systemd-growfs-root.service.d/10-tilo-composefs.conf # buildkit |
| COPY os/usr/lib/tmpfiles.d/tilo.conf /usr/lib/tmpfiles.d/tilo.conf # buildkit |
| COPY os/usr/lib/user-tmpfiles.d/tilo-model-manager.conf /usr/lib/user-tmpfiles.d/tilo-model-manager.conf # buildkit |
| COPY os/usr/lib/sysusers.d/tilo-local-model.conf os/usr/lib/sysusers.d/tilo-identity.conf /usr/lib/sysusers.d/ # buildkit |
| RUN |2 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 /bin/sh -c systemd-sysusers /usr/lib/sysusers.d/tilo-identity.conf && systemd-sysusers /usr/lib/sysusers.d/tilo-local-model.conf # buildkit |
| COPY os/usr/lib/systemd/user/tilo-identity.service /usr/lib/systemd/user/tilo-identity.service # buildkit |
| COPY os/usr/share/xdg-desktop-portal/portals/tilo.portal /usr/share/xdg-desktop-portal/portals/tilo.portal # buildkit |
| COPY os/usr/share/xdg-desktop-portal/tilo-portals.conf /usr/share/xdg-desktop-portal/tilo-portals.conf # buildkit |
| COPY os/usr/lib/systemd/user/shell-peer-sync.service /usr/lib/systemd/user/shell-peer-sync.service # buildkit |
| COPY os/etc/systemd/ /etc/systemd/ # buildkit |
| COPY os/etc/locale.conf /etc/locale.conf # buildkit |
| COPY os/etc/chrony.conf /etc/chrony.conf # buildkit |
| COPY os/usr/share/tilo/installer-locales.txt /usr/share/tilo/installer-locales.txt # buildkit |
| COPY os/docs/peer-sync.md docs/security/boot-chain.md docs/security/rollback.md /usr/share/doc/tilo/ # buildkit |
| COPY os/usr/lib/bootc/install/40-tilo.toml /usr/lib/bootc/install/40-tilo.toml # buildkit |
| COPY os/usr/lib/bootc/kargs.d/01-hardening.toml os/usr/lib/bootc/kargs.d/00-root.toml os/usr/lib/bootc/kargs.d/03-boot.toml os/usr/lib/bootc/kargs.d/04-mode.toml os/usr/lib/bootc/kargs.d/05-credentials.toml /usr/lib/bootc/kargs.d/ # buildkit |
| COPY --chmod=0755 os/usr/libexec/tilo-disk-encrypt os/usr/libexec/tilo-store-volume os/usr/libexec/tilo-verified-boot-install-preflight /usr/libexec/ # buildkit |
| COPY os/usr/libexec/tilo-secureboot /usr/libexec/tilo-secureboot # buildkit |
| COPY --chmod=0755 os/usr/libexec/tilo-image-trust-staged os/usr/libexec/tilo-verified-update /usr/libexec/ # buildkit |
| COPY os/usr/lib/systemd/system/tilo-secureboot-sign.service os/usr/lib/systemd/system/tilo-secureboot-sign.timer os/usr/lib/systemd/system/tilo-secureboot-sign.path os/usr/lib/systemd/system/tilo-secureboot-sign-shutdown.service /usr/lib/systemd/system/ # buildkit |
| RUN |2 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 /bin/sh -c chmod 0755 /usr/libexec/tilo-secureboot && systemctl enable tilo-secureboot-sign.timer tilo-secureboot-sign.path tilo-secureboot-sign-shutdown.service # buildkit |
| COPY os/usr/lib/sysctl.d/60-tilo-hardening.conf /usr/lib/sysctl.d/60-tilo-hardening.conf # buildkit |
| COPY os/usr/lib/sysctl.d/70-tilo-performance.conf /usr/lib/sysctl.d/70-tilo-performance.conf # buildkit |
| COPY os/usr/lib/tilo/untrusted-parsers.conf os/usr/lib/tilo/jit-entitled.conf /usr/lib/tilo/ # buildkit |
| COPY os/usr/lib/systemd/system/tilo-security-audit.service os/usr/lib/systemd/system/tilo-security-audit.timer os/usr/lib/systemd/system/tilo-hidepid.service /usr/lib/systemd/system/ # buildkit |
| COPY / / # buildkit |
| RUN |2 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 /bin/sh -c chmod 0755 /usr/libexec/tilo-rollback-common /usr/libexec/tilo-rollback-confirm /usr/libexec/tilo-rollback-initrd-unlock /usr/libexec/tilo-root-discover /usr/lib/systemd/system-generators/tilo-rollback-unlock-generator /usr/lib/systemd/system-generators/tilo-root-generator /usr/lib/dracut/modules.d/91tilo-rollback/module-setup.sh /usr/libexec/tilo-rollback-harden /usr/libexec/tilo-rollback-boot-check && install -d -m 0755 /usr/share/tilo/pcr-predictions # buildkit |
| COPY / / # buildkit |
| COPY / / # buildkit |
| ARG TILO_WITH_WINDOWS |
| LABEL org.tilo.with-windows=1 |
| COPY /out/usr/ /usr/ # buildkit |
| RUN |3 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 /bin/sh -c python3 /tilo-windows-provider.py host --manifest /usr/share/tilo/windows/provider.json # buildkit |
| COPY /out/virtio-win.iso /usr/share/virtio-win/virtio-win.iso # buildkit |
| COPY /out/installer/virtio-win-guest-tools.exe /usr/share/virtio-win/installer/virtio-win-guest-tools.exe # buildkit |
| COPY /out/bin/umu-run /usr/libexec/tilo-umu-run # buildkit |
| COPY /out/bin/umu_run.py /usr/libexec/umu_run.py # buildkit |
| COPY /out/proton/ /usr/lib/tilo/windows-runners/proton/ # buildkit |
| COPY /out/steam-runtime/ /usr/lib/tilo/windows-runners/steam-runtime/ # buildkit |
| COPY /out/catalogues/ /usr/share/tilo/windows/catalogues/ # buildkit |
| COPY os/usr/share/tilo/windows/fex-emulator.json os/usr/share/tilo/windows/fex-graphics-provider.json /usr/share/tilo/windows/ # buildkit |
| COPY os/usr/libexec/tilo-windows-vm-network os/usr/libexec/tilo-windows-provision os/usr/libexec/tilo-windows-owner os/usr/libexec/tilo-windows-recovery-console /usr/libexec/ # buildkit |
| COPY /image/windows/ / # buildkit |
| COPY os/usr/share/tilo/windows/ /usr/share/tilo/windows/ # buildkit |
| COPY os/usr/share/polkit-1/actions/org.tilo.windows.policy /usr/share/polkit-1/actions/org.tilo.windows.policy # buildkit |
| COPY os/etc/polkit-1/rules.d/49-tilo-windows.rules /etc/polkit-1/rules.d/49-tilo-windows.rules # buildkit |
| COPY os/usr/lib/systemd/system/tilo-windows-vm-network.service os/usr/lib/systemd/system/tilo-windows-vm-egress-reaper.service os/usr/lib/systemd/system/tilo-windows-vm-egress-reaper.timer /usr/lib/systemd/system/ # buildkit |
| COPY docs/windows-vm.md docs/windows-presentation.md /usr/share/doc/tilo/ # buildkit |
| RUN |3 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 /bin/sh -c chmod 0755 /usr/libexec/tilo-windows-vm-network /usr/libexec/tilo-windows-provision /usr/libexec/tilo-windows-owner /usr/libexec/tilo-windows-recovery-console /usr/libexec/tilo-windows-vm-control /usr/libexec/tilo-windows-rail && systemctl enable tilo-windows-vm-egress-reaper.timer # buildkit |
| RUN |3 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 /bin/sh -c systemctl enable greetd.service && restorecon -v /usr/lib/systemd/user/tilo-graphical-session.target && systemctl disable NetworkManager.service firewalld.service chronyd.service && systemctl enable tilo-device-key-init.service && systemctl set-default graphical.target && systemctl enable tilo-growfs-sysroot.timer && systemctl enable tilo-fs-start.timer fs-identity.path && systemctl enable tilo-system-extension-dispatcher.socket && systemctl enable tilo-system-extension-boot-pack-status.timer && systemctl enable tilo-system-extension-boot-pack-stage.path && systemctl --global enable tilo-identity.service && systemctl --global enable tilo-models.socket && systemctl --global enable tilo-model-gateway.socket && systemctl --global enable tilo-app-host.socket && systemctl --global enable tilo-ush.socket && systemctl --global enable tilo-fs-recipient.socket && systemctl --global enable pipewire.socket pipewire-pulse.socket wireplumber.service && systemctl enable cups.socket && systemctl enable tilo-hidepid.service && systemctl enable tilo-security-audit.timer && systemctl enable tilo-rollback-harden.timer && systemctl enable tilo-rollback-confirm.timer && systemctl enable tilo-boot-entries.timer tilo-boot-health.service && systemctl enable bootc-fetch-apply-updates.timer && systemctl enable tilo-network-start.timer && systemctl enable tilo-codec-pack-guard.service tilo-codec-pack-refresh.timer && systemctl enable NetworkManager-dispatcher.service # buildkit |
| RUN |3 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 /bin/sh -c for u in NetworkManager-wait-online.service systemd-networkd-wait-online.service systemd-network-generator.service systemd-timesyncd.service systemd-coredump.socket systemd-coredump@.service systemd-binfmt.service systemd-pstore.service systemd-pcrlock-file-system.service systemd-pcrlock-firmware-code.service systemd-pcrlock-firmware-config.service systemd-pcrlock-machine-id.service systemd-pcrlock-make-policy.service systemd-pcrlock-secureboot-authority.service systemd-pcrlock-secureboot-policy.service man-db-cache-update.timer man-db-cache-update.service systemd-update-utmp.service ; do systemctl mask "$u" || true; done && systemctl mask systemd-sysext.service systemd-confext.service systemd-sysext.socket && for u in systemd-sysext.service systemd-confext.service systemd-sysext.socket; do test "$(readlink "/etc/systemd/system/$u")" = /dev/null; done # buildkit |
| RUN |3 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 /bin/sh -c firewall-offline-cmd --set-default-zone=FedoraWorkstation # buildkit |
| ARG TILO_PUBLIC_TRUST_MODE=production |
| ARG TILO_PUBLIC_TRUST_MANIFEST_SHA256 |
| ARG TILO_TARGET_IMGREF |
| ARG TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY |
| COPY / /run/tilo-public-trust/ # buildkit |
| COPY keys/cosign.pub keys/tpm2-pcr-signing.public.pem os/dev/development-trust.py os/dev/install-public-trust.py os/dev/hardware_profile.py os/etc/containers/policy.json os/etc/containers/registries.d/code.podesta.ai.yaml os/etc/containers/registries.d/code.tilo.so.yaml os/etc/containers/registries.d/registry.tilo.so.yaml /run/tilo-trust-inputs/ # buildkit |
| RUN |7 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 TILO_PUBLIC_TRUST_MODE=production TILO_PUBLIC_TRUST_MANIFEST_SHA256= TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 /bin/sh -c mkdir -p /run/tilo-official-trust /run/tilo-trust-tools /etc/containers/registries.d && cp -a /run/tilo-trust-inputs/cosign.pub /run/tilo-trust-inputs/tpm2-pcr-signing.public.pem /run/tilo-official-trust/ && cp -a /run/tilo-trust-inputs/*.py /run/tilo-trust-tools/ && cp -a /run/tilo-trust-inputs/policy.json /etc/containers/policy.json && cp -a /run/tilo-trust-inputs/code.podesta.ai.yaml /etc/containers/registries.d/code.podesta.ai.yaml && cp -a /run/tilo-trust-inputs/code.tilo.so.yaml /etc/containers/registries.d/code.tilo.so.yaml && cp -a /run/tilo-trust-inputs/registry.tilo.so.yaml /etc/containers/registries.d/registry.tilo.so.yaml && PATH="/run/tilo-build-tools:$PATH" python3 /run/tilo-trust-tools/install-public-trust.py --source /run/tilo-public-trust --official /run/tilo-official-trust --destination /usr/share/tilo --mode "$TILO_PUBLIC_TRUST_MODE" --manifest-sha256 "$TILO_PUBLIC_TRUST_MANIFEST_SHA256" --registry-owner "$TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY" --target-ref "$TILO_TARGET_IMGREF" --image-root / && rm -rf /run/tilo-public-trust /run/tilo-official-trust /run/tilo-trust-tools /run/tilo-trust-inputs # buildkit |
| ARG TILO_HARDWARE_PROFILE=generic |
| ARG TILO_TARGET_IMGREF= |
| RUN |9 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 TILO_PUBLIC_TRUST_MODE=production TILO_PUBLIC_TRUST_MANIFEST_SHA256= TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 TILO_HARDWARE_PROFILE=generic TILO_TARGET_IMGREF= /bin/sh -c set -eux; mkdir -p /etc/tilo-swap.d; printf '[frozen]\nname=frozen\nbaseurl=file:///frozen-repo\ngpgcheck=0\nenabled=1\n' > /etc/tilo-swap.d/frozen.repo; printf '[tilo-kernel]\nname=tilo-kernel\nbaseurl=file:///qkernel-repo\ngpgcheck=0\nenabled=1\n' > /etc/tilo-swap.d/tilo-kernel.repo; dnf swap -y --setopt=reposdir=/etc/tilo-swap.d --nogpgcheck --allowerasing kernel-core tilo-kernel-core; rm -rf /etc/tilo-swap.d; kver=""; n=0; for d in /usr/lib/modules/*/; do k="$(basename "$d")"; if [ -f "$d/vmlinuz" ] || [ -f "/boot/vmlinuz-$k" ]; then kver="$k"; n=$((n+1)); fi; done; if [ "$n" -ne 1 ]; then echo "expected exactly one kernel image after the kernel swap, found $n" >&2; ls -la /usr/lib/modules/ /boot >&2 || true; exit 1; fi; if [ -f "/boot/vmlinuz-$kver" ] && [ ! -f "/usr/lib/modules/$kver/vmlinuz" ]; then mv "/boot/vmlinuz-$kver" "/usr/lib/modules/$kver/vmlinuz"; fi; test -f "/usr/lib/modules/$kver/vmlinuz"; for d in /usr/lib/modules/*; do [ "$d" = "/usr/lib/modules/$kver" ] || rm -rf "$d"; done; install -Dm0644 /run/hardware_profile.py /usr/lib/tilo/hardware_profile.py; python3 /run/tilo-prepare-hardware-profile.py --profile "$TILO_HARDWARE_PROFILE" --root / --kernel-version "$kver" --profiles-dir /run/tilo-hardware-profiles --firmware-dir "/run/tilo-hardware-firmware/$TILO_HARDWARE_PROFILE" --target-update-ref "$TILO_TARGET_IMGREF"; find "/usr/lib/modules/$kver" -type f -path '*/fs/ext4/ext4.ko*' -print -quit | grep -q . || { echo 'signed Ext4 rescue module is missing' >&2; exit 1; }; find "/usr/lib/modules/$kver" -type f -path '*/fs/xfs/xfs.ko*' -print -quit | grep -q . || { echo 'signed XFS rescue module is missing' >&2; exit 1; }; dracut --force --reproducible --compress zstd -v --kver "$kver" --omit "network network-legacy network-manager nfs iscsi nvmf nbd fcoe fcoe-uefi nbde clevis clevis-pin-null clevis-pin-sss clevis-pin-tang clevis-pin-tpm2 crypt-ssh" --omit-drivers "ext4 xfs" --add "crypt systemd-cryptsetup tpm2-tss plymouth tilo-rollback" "/usr/lib/modules/$kver/initramfs.img" > /tmp/dracut.log 2>&1 || { cat /tmp/dracut.log >&2; exit 1; }; test -s "/usr/lib/modules/$kver/initramfs.img"; mkdir -p /usr/lib/tilo; sed -n 's/.*Including module: \([a-z0-9_-]*\).*/\1/p' /tmp/dracut.log | sort -u > /usr/lib/tilo/initramfs-modules.txt; printf '%s\n' ext4 xfs > /usr/lib/tilo/initramfs-omitted-drivers.txt; for m in crypt systemd-cryptsetup tpm2-tss plymouth tilo-rollback; do grep -qx "$m" /usr/lib/tilo/initramfs-modules.txt || { echo "dracut did not include the $m module; an encrypted root could not be opened" >&2; cat /usr/lib/tilo/initramfs-modules.txt >&2; exit 1; }; done; for m in network network-legacy network-manager nfs iscsi nvmf nbd fcoe fcoe-uefi nbde clevis clevis-pin-null clevis-pin-sss clevis-pin-tang clevis-pin-tpm2 crypt-ssh; do ! grep -qx "$m" /usr/lib/tilo/initramfs-modules.txt || { echo "unsupported initramfs module $m was included" >&2; exit 1; }; done; rm -f /tmp/dracut.log; rm -f /boot/vmlinuz-* /boot/initramfs-* /boot/System.map-* /boot/config-*; dnf clean all && ${FINALIZE_RPMDB} # buildkit |
| RUN |9 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 TILO_PUBLIC_TRUST_MODE=production TILO_PUBLIC_TRUST_MANIFEST_SHA256= TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 TILO_HARDWARE_PROFILE=generic TILO_TARGET_IMGREF= /bin/sh -c owner="$(rpm -qf /usr/bin/basename 2>&1 || true)" && case "$owner" in coreutils-*) echo "rpmdb file index intact: /usr/bin/basename -> $owner" ;; *) echo "rpmdb file index is corrupt: /usr/bin/basename -> $owner" >&2; exit 1 ;; esac && rpm --verifydb && rm -f /usr/lib/sysimage/rpm/rpmdb.sqlite-wal /usr/lib/sysimage/rpm/rpmdb.sqlite-shm && ( test ! -e /usr/lib/sysimage/rpm/rpmdb.sqlite-wal || { echo "rpmdb.sqlite-wal is in the image; see FINALIZE_RPMDB" >&2; exit 1; } ) && ( test ! -e /usr/lib/sysimage/rpm/rpmdb.sqlite-shm || { echo "rpmdb.sqlite-shm is in the image; see FINALIZE_RPMDB" >&2; exit 1; } ) # buildkit |
| COPY os/tests/boot_chain_invariants.sh /usr/libexec/tilo/boot-chain-test.sh # buildkit |
| COPY os/tests/boot_performance_gate.sh /usr/libexec/tilo/boot-performance-gate.sh # buildkit |
| RUN |9 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 TILO_PUBLIC_TRUST_MODE=production TILO_PUBLIC_TRUST_MANIFEST_SHA256= TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 TILO_HARDWARE_PROFILE=generic TILO_TARGET_IMGREF= /bin/sh -c chmod 0755 /usr/libexec/tilo/boot-chain-test.sh /usr/libexec/tilo/boot-performance-gate.sh && OS_ROOT=/ bash /usr/libexec/tilo/boot-chain-test.sh # buildkit |
| ARG TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY |
| RUN |10 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 TILO_PUBLIC_TRUST_MODE=production TILO_PUBLIC_TRUST_MANIFEST_SHA256= TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 TILO_HARDWARE_PROFILE=generic TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 /bin/sh -c if ! printf '%s\n' "$TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY" | grep -Eq '^[0-9a-fA-F]{64}$' || [ "$TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY" = 0000000000000000000000000000000000000000000000000000000000000000 ]; then echo "TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY must be a non-placeholder 32-byte hex key" >&2; exit 1; fi && install -d -m 0755 /usr/share/tilo/trust && printf '%s\n' "$TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY" > /usr/share/tilo/trust/tilo-main-registry-owner.pub && chmod 0644 /usr/share/tilo/trust/tilo-main-registry-owner.pub # buildkit |
| COPY os/tests/collaborative-files-image-contract.sh /usr/libexec/tilo/collaborative-files-image-contract.sh # buildkit |
| COPY apps/file-explorer/tests/atspi_smoke.sh /usr/libexec/tilo/files-atspi-smoke.sh # buildkit |
| COPY crates/session/shell/tests/native_atspi_smoke.sh /usr/libexec/tilo/native-atspi-smoke.sh # buildkit |
| COPY tools/atspi_external_client.py /usr/libexec/tilo/atspi-external-client.py # buildkit |
| COPY os/tests/installed_atspi_apps.sh /usr/libexec/tilo/installed-atspi-apps.sh # buildkit |
| RUN |10 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 TILO_PUBLIC_TRUST_MODE=production TILO_PUBLIC_TRUST_MANIFEST_SHA256= TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 TILO_HARDWARE_PROFILE=generic TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 /bin/sh -c chmod 0755 /usr/libexec/tilo/collaborative-files-image-contract.sh /usr/libexec/tilo/files-atspi-smoke.sh /usr/libexec/tilo/native-atspi-smoke.sh /usr/libexec/tilo/atspi-external-client.py /usr/libexec/tilo/installed-atspi-apps.sh && OS_ROOT=/ /usr/libexec/tilo/collaborative-files-image-contract.sh image # buildkit |
| COPY os/tests/luks_enrolment.sh /usr/libexec/tilo/luks-enrolment-test.sh # buildkit |
| RUN |10 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 TILO_PUBLIC_TRUST_MODE=production TILO_PUBLIC_TRUST_MANIFEST_SHA256= TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 TILO_HARDWARE_PROFILE=generic TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 /bin/sh -c chmod 0755 /usr/libexec/tilo/luks-enrolment-test.sh && bash /usr/libexec/tilo/luks-enrolment-test.sh # buildkit |
| ARG TILO_GENERATION |
| RUN |11 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 TILO_PUBLIC_TRUST_MODE=production TILO_PUBLIC_TRUST_MANIFEST_SHA256= TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 TILO_HARDWARE_PROFILE=generic TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 TILO_GENERATION=1 /bin/sh -c case "${TILO_GENERATION}" in ''|*[!0-9]*) echo "TILO_GENERATION must be a decimal integer; got '${TILO_GENERATION}'." >&2; echo "It is the generation this image carries: +1 per published image, sealed" >&2; echo "onto the UKI command line. os/dev/build-image.sh resolves it from the" >&2; echo "published series; pass TILO_GENERATION=<N> to build one by hand." >&2; exit 1 ;; esac && install -d -m 0755 /usr/lib/tilo && printf '%s\n' "${TILO_GENERATION}" > /usr/lib/tilo/generation && printf '# Written by the image build from the TILO_GENERATION build argument.\nkargs = ["tilo.generation=%s"]\n' "${TILO_GENERATION}" > /usr/lib/bootc/kargs.d/02-generation.toml && echo "generation ${TILO_GENERATION}: sealed via kargs.d, readable at /usr/lib/tilo/generation" # buildkit |
| RUN |11 FINALIZE_RPMDB=/usr/libexec/tilo/finalize-rpmdb TILO_WINDOWS_ARCH=x86_64 TILO_WITH_WINDOWS=1 TILO_PUBLIC_TRUST_MODE=production TILO_PUBLIC_TRUST_MANIFEST_SHA256= TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 TILO_HARDWARE_PROFILE=generic TILO_TARGET_IMGREF= TILO_OFFICIAL_REGISTRY_OWNER_PUBKEY=55d9a9c748bcfe34200832c18c5f0cf7932f17571612321eaa542474fa2abe06 TILO_GENERATION=1 /bin/sh -c find /usr/lib /usr/lib64 \( -path '*/ossl-modules/legacy.so' -o -path '*/engines-3/*.so' -o -name 'libshout.so*' -o -name 'libevent_openssl.so*' -o -path '*/gstreamer-1.0/libgstdtls.so' -o -path '*/gstreamer-1.0/libgstcurl.so' -o -path '*/gstreamer-1.0/libgstshout2.so' -o -path '*/gstreamer-1.0/libgstwebrtc.so' -o -path '*/gstreamer-1.0/libgstnice.so' -o -path '*/gstreamer-1.0/libgstsrtp.so' -o -path '*/qt6/plugins/tls/libqopensslbackend.so' \) \( -type f -o -type l \) -delete && rpm -e --nodeps libshout && rpm -qa --qf '%{NAME}\n' perl-IO-Socket-SSL perl-Net-SSLeay qatlib-service qatlib | xargs -r rpm -e --nodeps && ! find /usr/lib /usr/lib64 \( -path '*/ossl-modules/legacy.so' -o -path '*/engines-3/*.so' -o -name 'libshout.so*' -o -name 'libevent_openssl.so*' -o -path '*/gstreamer-1.0/libgstdtls.so' -o -path '*/gstreamer-1.0/libgstcurl.so' -o -path '*/gstreamer-1.0/libgstshout2.so' -o -path '*/gstreamer-1.0/libgstwebrtc.so' -o -path '*/gstreamer-1.0/libgstnice.so' -o -path '*/gstreamer-1.0/libgstsrtp.so' -o -path '*/qt6/plugins/tls/libqopensslbackend.so' \) \( -type f -o -type l \) -print -quit | grep -q . && bash /usr/local/bin/verify-runtime-crypto-packages.sh && rm -f /usr/local/bin/verify-runtime-crypto-packages.sh && bootc container lint # buildkit |
| RUN /bin/sh -c mkdir /kernel && bootc container split-kernel-and-rootfs --rootfs / --output /kernel # buildkit |
| COPY /out/*.efi /boot/EFI/Linux/ # buildkit |
| ARG TILO_RUST_LTO=thin |
| LABEL org.tilo.rust-lto=thin |
Labels
| Key | Value |
|---|---|
| containers.bootc | 1 |
| org.opencontainers.image.created | 2026-09-26T07:37:51.047Z |
| org.opencontainers.image.description | desktop environment, OS, pain in the ass to work on |
| org.opencontainers.image.licenses | |
| org.opencontainers.image.revision | 79835b23382d5e4ddc7616404a4bd1ceccf58e55 |
| org.opencontainers.image.source | https://code.tilo.so/tilo/tilo |
| org.opencontainers.image.title | tilo |
| org.opencontainers.image.url | https://code.tilo.so/tilo/tilo |
| org.opencontainers.image.version | latest |
| org.tilo.rust-lto | thin |
| org.tilo.with-windows | 1 |
| ostree.bootable | true |
| ostree.commit | 3e10e9e11e2977f1051b9ef2b4e76a88455fce144911901324c3dae406928fcb |
| ostree.final-diffid | sha256:12787d84fa137cd5649a9005efe98ec9d05ea46245fdc50aecb7dd007f2035b1 |
| ostree.linux | 7.1.5-201.fc44.x86_64 |
| rpmostree.inputhash | 7b5b9c69a54eb2cfc02572e0e1ac38769cadf96d538ec0febe41189b2581547d |
Details
2026-09-26 09:28:21 +00:00
Versions (18)
View all
Container
0
OCI / Docker
linux/amd64
4.9 GiB
main-9aa147e-aarch64-47700-1
2026-09-26
main-9aa147e-aarch64
2026-09-26
main-79835b2-x86_64-46712-2
2026-09-26
main-79835b2-x86_64
2026-09-26
main-ab0ef8d-x86_64
2026-09-26