Point the RHEL upgrade-matrix legs at images that exist
Summary
-
rockylinux-9andalmalinux-9had never started a container: jrei publishes nosystemd-rockylinuxorsystemd-almalinuxrepository at all, sodocker runfailed withpull access denied ... repository does not exist(exit 125) before the installer was ever copied. Point them at each distro's own systemd-enabled init image instead, which also removes the dependency on a third-party account that prunes tags. -
jrei/systemd-fedora:40fails separately withmanifest unknown— that tag was pruned upstream (41, 42, 43, 44, latestremain). Bumped to41. - Two further fixes were needed for the new images to get past steps the old ones never reached:
- The UBI-based Rocky/Alma images ship
curl-minimal, which conflicts with thecurlpackage (conflicting requests, dnf exits non-zero) even though it already provides/usr/bin/curl. Added--allowerasing. - Fedora 41's systemd (256) activates
tmp.mount, so/tmpis a tmpfs that shadows whateverdocker cpwrote into the image layer — the copy reports success and the file is then invisible tobash. Staged under/rootinstead. el9's systemd 252 leaves/tmpalone, which is why only the newer distro hit it.
- The UBI-based Rocky/Alma images ship
Why this matters more than three red checks
Those three legs were exactly the pkg_mgr: dnf legs, so the installer's RPM branch has never executed once — including the test -f /etc/yum.repos.d/squid-tentacle.repo assertion. Every passing leg was apt. The RPM install path was shipping with zero verified coverage behind a check that had been red on every run since 2026-05-03.
Test plan
Verified locally against real containers (--platform linux/amd64, the workflow's exact docker run flags) on all three distros:
-
systemd reaches degraded— Rocky/Alma systemd 252, Fedora 41 systemd 256 -
prerequisite dnf installexits 0 on all three -
install-tentacle.shcompletes (installedsquid-tentacle-1.9.4-1.x86_64from the real RPM repo) -
Assertion 1 — squid-tentacle versionrunnable -
Assertion 2 — /etc/yum.repos.d/squid-tentacle.repowritten -
Assertion 3 — sudoers rule present and visudo -cvalid -
Assertion 4 — sudo -U squid-tentacle -nlenumerates the package-manager rule -
CI confirmation on ubuntu-latestrunners
The RPM path turned out not to be broken — only never run.
Notes
- The
fedora-40→fedora-41rename changes that leg's check name. OnlyWindows Lifecycle Smoke (PR gate)andLinux Lifecycle Smoke (PR gate)are required checks, so nothing in branch protection references it. - The Alpine leg still stages under
/tmp; Alpine runs no systemd, sotmp.mountcannot shadow it. Left unchanged.