Name: conch
Version: 0.1.0
Release: 7%{?dist}
Summary: Agent Sandbox Engine based on containers
License: MulanPSL2
URL: https://atomgit.com/openeuler/Conch
Source0: Conch.tar.gz
# Go vendor tree for the go.mod in Source0, so the build works offline
Source1: conch-vendor.tar.xz
# SDK dep wheels, kept with the sources but not installed: the target python
# environment is expected to provide them
Source2: conch-python-deps-x86_64.tar.gz
Source3: conch-python-deps-aarch64.tar.gz
ExclusiveArch: x86_64 aarch64
# Disable debug packages
%global debug_package %{nil}
# Disable Python byte compilation
%define __brp_python_bytecompile %{nil}
# systemd provides %%{_unitdir} and the %%systemd_* scriptlet macros
BuildRequires: git-core systemd python3-devel xz wget cpio gzip
# Build deps for the SDK wheel
BuildRequires: python3-pip python3-setuptools python3-wheel
# Guest kernel build deps (Linux 6.6.0, config/oe-kernel/*/.config).
# No dwarves needed: the config does not enable CONFIG_DEBUG_INFO_BTF.
BuildRequires: gcc make bc bison flex elfutils-libelf-devel openssl-devel openssl
%{?systemd_requires}
Requires: iptables kmod containernetworking-plugins virtiofsd
Recommends: containerd >= 2.2.1
Recommends: stratovirt
%description
Conch is a container sandbox engine based on Go, designed for Agent
scenarios requiring high startup performance, high elasticity,
high I/O performance, and high-density deployment.
Key features:
- Lightweight security isolation using virtual sandboxes
- Snapshot acceleration for sub-second sandbox startup
- Simplified container networking with veth and NAT
The Python SDK is not installed into the system interpreter. Its wheel ships
under %{_datadir}/conch/wheels, to be installed with pip into whichever
interpreter or virtualenv suits the deployment:
pip install %{_datadir}/conch/wheels/conch-*.whl
%prep
%autosetup -n Conch
# Replace any vendor tree in the source with the one matching go.mod
rm -rf vendor
tar -xf %{SOURCE1}
%build
# go.mod requires go >= 1.26.2, which is not in the openEuler stable repos yet,
# so fetch golang + golang-devel (they share GOROOT and go together) from the
# mainline EulerMaker repo instead of BuildRequires.
GO_BASEURL="https://eulermaker.openeuler.openatom.cn/api/ems4/repositories/openEuler-master:everything/openEuler%%3Amainline/%{_arch}/Packages"
GOROOT_FETCH="$PWD/.goroot-fetch"
rm -rf "$GOROOT_FETCH"
mkdir -p "$GOROOT_FETCH"
# That repo rolls builds (-47 -> -48), so resolve the current names from its
# index rather than pinning a release that later 404s
GO_INDEX="$(wget -q -O - "${GO_BASEURL}/")"
GO_RPM="$(printf '%s' "$GO_INDEX" | grep -oE "golang-1\\.26\\.[0-9]+-[0-9]+\\.oe[0-9]+\\.%{_arch}\\.rpm" | sort -V | uniq | tail -1)"
GO_DEVEL_RPM="$(printf '%s' "$GO_INDEX" | grep -oE "golang-devel-1\\.26\\.[0-9]+-[0-9]+\\.oe[0-9]+\\.noarch\\.rpm" | sort -V | uniq | tail -1)"
if [ -z "$GO_RPM" ] || [ -z "$GO_DEVEL_RPM" ]; then
echo "ERROR: could not resolve golang 1.26 rpm from ${GO_BASEURL}/" >&2
exit 1
fi
for rpmfile in "$GO_RPM" "$GO_DEVEL_RPM"; do
echo "Fetching ${rpmfile}..."
wget -q --tries=3 --timeout=60 "${GO_BASEURL}/${rpmfile}" -O "$GOROOT_FETCH/${rpmfile}"
( cd "$GOROOT_FETCH" && rpm2cpio "${rpmfile}" | cpio -idm --quiet )
done
export GOROOT="$GOROOT_FETCH/usr/lib/golang"
export PATH="$GOROOT/bin:$PATH"
go version
# Set Go environment
export GOTOOLCHAIN=local
export CGO_ENABLED=0
export GOFLAGS=-mod=vendor
export GOCACHE="$PWD/.gocache"
export GOPATH="$PWD/.gopath"
mkdir -p bin
# Build the conch-init initramfs; the static bin/conch-init it produces is
# overwritten by the regular build below, so only the initramfs uses it
make build-conch-init-initramfs
# Build binaries using containers_image_openpgp build tag to avoid gpgme dependency
for cmd in conch conchd conch-init; do
echo "Building cmd/$cmd..."
go build -tags containers_image_openpgp -o bin/$cmd ./cmd/$cmd
done
# Build the Python SDK wheel; --no-build-isolation --no-index keep it offline
%{__python3} -m pip wheel --no-deps --no-build-isolation --no-index -w dist ./sdk
# Build the guest kernel (Linux 6.6.0): read the revision from
# src-openeuler/kernel SOURCE, then fetch it from openeuler/kernel
KMETA="%{_builddir}/Conch/kernel-meta"
KBUILD="%{_builddir}/Conch/kernel-build"
rm -rf "$KMETA" "$KBUILD"
git clone --depth 1 --branch master \
https://atomgit.com/src-openeuler/kernel.git "$KMETA"
KREV="$(tr -d '[:space:]' < "$KMETA/SOURCE")"
echo "Kernel revision from SOURCE: ${KREV}"
# SOURCE holds a tag on some branches and a bare commit id on others; fetch
# takes both, "clone --branch" would not
mkdir -p "$KBUILD/linux"
git init -q "$KBUILD/linux"
git -C "$KBUILD/linux" remote add origin https://atomgit.com/openeuler/kernel.git
git -C "$KBUILD/linux" fetch -q --depth 1 origin "${KREV}"
git -C "$KBUILD/linux" checkout -q FETCH_HEAD
cd "$KBUILD/linux"
%ifarch x86_64
cp %{_builddir}/Conch/config/oe-kernel/x86/.config .config
KIMG_TARGET=bzImage
%endif
%ifarch aarch64
cp %{_builddir}/Conch/config/oe-kernel/aarch/.config .config
KIMG_TARGET=Image
%endif
make olddefconfig
# Image only, no modules: Conch ships no /lib/modules, and building them was
# OOM-killing the gate builder
make %{?_smp_mflags} "$KIMG_TARGET"
%install
rm -rf %{buildroot}
# Install Go binaries
install -d %{buildroot}%{_bindir}
install -m 0755 bin/conch %{buildroot}%{_bindir}/
install -m 0755 bin/conchd %{buildroot}%{_bindir}/
install -m 0755 bin/conch-init %{buildroot}%{_bindir}/
# Guest kernel into /var/lib/conch, as kata does under /var/lib/kata
install -d %{buildroot}/var/lib/conch
%ifarch x86_64
install -p -m 0644 %{_builddir}/Conch/kernel-build/linux/arch/x86/boot/bzImage %{buildroot}/var/lib/conch/kernel
%endif
%ifarch aarch64
install -p -m 0644 %{_builddir}/Conch/kernel-build/linux/arch/arm64/boot/Image %{buildroot}/var/lib/conch/kernel
%endif
# The conch-init initramfs, alongside the kernel
install -p -m 0644 %{_builddir}/Conch/build-artifacts/conch-init-initramfs.cpio.gz %{buildroot}/var/lib/conch/conch.initrd
# conchd defaults to /etc/conch/config.yaml (internal/config FindConfigFile)
install -d %{buildroot}%{_sysconfdir}/conch
# conchd requires Perm()&0o037 == 0 on its config, hence 0640
install -m 0640 config/config.yaml %{buildroot}%{_sysconfdir}/conch/config.yaml
# Default CNI config; the /etc/conch/cni/net.d path is built into conchd
# (internal/netstack DefaultCNIPluginConfDir), not read from config.yaml
install -d %{buildroot}%{_sysconfdir}/conch/cni/net.d
install -m 0644 config/cni/net.d/10-conch.conf %{buildroot}%{_sysconfdir}/conch/cni/net.d/10-conch.conf
# Install the systemd unit shipped with the sources
install -d %{buildroot}%{_unitdir}
install -m 0644 scripts/conchd.service %{buildroot}%{_unitdir}/conchd.service
# The SDK is not installed into python3_sitelib; its wheel ships here for pip
install -d %{buildroot}%{_datadir}/conch/wheels
install -m 0644 dist/conch-*.whl %{buildroot}%{_datadir}/conch/wheels/
# Remove all pycache and compiled files BEFORE finishing install
find %{buildroot} -type d -name __pycache__ -exec rm -rf {} + 2>/dev/null || true
find %{buildroot} -type f -name "*.pyc" -delete 2>/dev/null || true
find %{buildroot} -type f -name "*.pyo" -delete 2>/dev/null || true
%clean
rm -rf %{buildroot}
%post
%systemd_post conchd.service
%preun
%systemd_preun conchd.service
%postun
# Restart a running conchd on upgrade so the new binary takes effect.
# KillMode=process leaves the sandbox VMM processes running across the restart,
# but conchd does not re-adopt them (see the warning in conchd.service), so
# active sandboxes should be deleted before upgrading.
%systemd_postun_with_restart conchd.service
%files
%{_bindir}/conch
%{_bindir}/conchd
%{_bindir}/conch-init
%dir /var/lib/conch
/var/lib/conch/kernel
/var/lib/conch/conch.initrd
%dir %{_sysconfdir}/conch
%config(noreplace) %{_sysconfdir}/conch/config.yaml
%dir %{_sysconfdir}/conch/cni
%dir %{_sysconfdir}/conch/cni/net.d
%config(noreplace) %{_sysconfdir}/conch/cni/net.d/10-conch.conf
%{_unitdir}/conchd.service
%dir %{_datadir}/conch
%dir %{_datadir}/conch/wheels
%{_datadir}/conch/wheels/*.whl
%changelog
* Tue Aug 25 2026 wangzicheng <wangzicheng15@huawei.com> - 0.1.0-7
- Take the guest kernel revision from the master branch of src-openeuler/kernel
instead of the 24.03-LTS-SP4 branch, matching this branch's release.
* Mon Aug 17 2026 wangzicheng <wangzicheng15@huawei.com> - 0.1.0-6
- Update Conch.tar.gz to the latest upstream source: conchd serves its API over
the unix socket only, sandboxes are destroyed when their virtiofsd exits, and
config.yaml drops the fields conchd fills in itself.
- Regenerate conch-vendor.tar.xz for the new go.mod, which no longer requires
go-cni, k8s.io/utils, go-deadlock and goid.
- Stop installing the Python SDK into python3_sitelib; ship its wheel as
/usr/share/conch/wheels/conch-*.whl instead, to install with pip. conch itself
now pulls in no python runtime dependencies.
- Drop /etc/conch/sdk-config.yaml and conch-sdk-init-config, which the SDK no
longer uses.
- Recommend stratovirt instead of cloud-hypervisor, matching the backend the
shipped config.yaml selects.
- Take the guest kernel revision from the SP4 branch of src-openeuler/kernel.
* Mon Aug 10 2026 wangzicheng <wangzicheng15@huawei.com> - 0.1.0-5
- Build Conch (conch, conchd, conch-init) from the latest upstream source
with a bundled Go vendor tree (Source1) and -mod=vendor, plus the
conch-init initramfs and the guest kernel (Linux 6.6.0); install them
under /var/lib/conch.
- Single rpm: merge the Python SDK in and bundle its runtime deps
(connectrpc, protobuf-py, pyqwest, opentelemetry-api) as per-arch wheel
tarballs (Source2/Source3) so build and install work fully offline.
- Ship /etc/conch config (config.yaml and sdk-config.yaml as 0640, CNI
10-conch.conf) and the conchd systemd unit; require
containernetworking-plugins and virtiofsd.
* Mon Jun 15 2026 wangzicheng <wangzicheng15@huawei.com> - 0.1.0-4
- Add 2 upstream patches (commits adb3079, b064372) on top of the tarball baseline:
add lock to ensure sandbox cleanup under race, and cleanup prepared snapshots
on create failure
* Wed Jun 10 2026 wangzicheng <wangzicheng15@huawei.com> - 0.1.0-3
- Add 13 upstream patches (commits c3e0c4a..dc6cadb) on top of the tarball baseline:
CID allocator hardening, vsock/VMM startup refactor, network pool fixes,
config field validations, sandbox cleanup on signal shutdown, and docs updates
* Sat May 16 2026 wangzicheng <wangzicheng15@huawei.com> - 0.1.0-2
- fix spec only make on arm and golang version
* Sat May 16 2026 wangzicheng <wangzicheng15@huawei.com> - 0.1.0-1
- Initial package
- Add python3-conch subpackage for Python SDK