ostree-commit - Man Page

Commit a new revision


ostree commit [Options...] --branch= {BRANCH} [PATH]


This allows you to commit changes to a branch. The specification of the branch is required. The command will print the checksum of a successful commit.


--subject,  -s="SUBJECT"

One line subject. (optional)

--body,  -m="BODY"

Full description. (optional)

--body-file,  -F="FILE"

Full commit description from a file. (optional)

--editor,  -e

Open a text editor for the commit description. It will use OSTREE_EDITOR, VISUAL, EDITOR, or vi, in descending order of preference. The commit will be aborted if the message is left empty.

--branch,  -b="BRANCH"

Branch. Required, unless --orphan is given.


Parent checksum or "none" to explicitly use no parent. If not specified, BRANCH is used as parent (no parent in case BRANCH does not exist).

--tree="dir=PATH" or "tar=TARFILE" or "ref=COMMIT"

Overlay the given argument as a tree. When committing an archive, the TARFILE can be specified as - to read the archive from standard input.


Start from the content in a commit. This differs from --tree=ref=REV in that no commit modifiers are applied. This is usually what you want when creating a derived commit. This is also used for --selinux-policy-from-base.


Add a key/value pair to metadata. Can be specified multiple times.


Add a key/value pair to metadata, where the KEY is a string, and VALUE is g_variant_parse() formatted. Can be specified multiple times.


Keep metadata KEY and its associated VALUE from parent. Can be specified multiple times.


Add a key/value pair to detached metadata.


Set file ownership user id.


Set file ownership group id.


Do not import extended attributes.

--selinux-labeling-epoch0 | 1

When SELinux labeling is enabled, epoch 1 ensures that /usr/etc is labeled as if it was /etc.


Inject standard metadata for a bootable Linux filesystem tree.


Optimize for commits of trees composed of hardlinks into the repository.


When loading tar archives, automatically create parent directories as needed.


If the contents are unchanged from previous commit, do nothing.


When committing from a local directory (i.e. not an archive or --tree=ref), assume ownership of the content. This may simply involve deleting it, but if possible, the content may simply be rename()ed into the repository rather than creating a new copy.


File containing list of modifications to make permissions (file mode in decimal, followed by space, followed by file path). The specified mode is ORed with the file's original mode unless preceded by "=".


File containing list of file paths to skip (one path per line).


Output more information in a KEY: VALUE format.


Generate size information along with commit metadata.


GPG Key ID with which to sign the commit (if have GPGME - GNU Privacy Guard Made Easy).


GPG home directory to use when looking for keyrings (if have GPGME - GNU Privacy Guard Made Easy).


Override the timestamp of the commit to TIMESTAMP.


Create a commit without writing to a ref (branch)


POLICY is a boolean which specifies whether fsync should be used or not. Default to true.

-s,  --sign-type

Use particular signature engine. Currently available ed25519 and dummy signature types. The default is ed25519.


This will read a key (corresponding to the provided --sign-type from the provided path. The key should be base64 encoded.


In new code, avoid using this because passing private keys via command line arguments are prone to leakage in logs and process listings.

The KEY-ID is:

for ed25519:

base64-encoded secret key for commit signing.

for dummy:

ASCII-string used as secret key.


$ ostree commit --branch=my-branch --subject="Initial commit"


