2
0
mirror of https://github.com/xcat2/xcat-core.git synced 2026-09-30 14:55:16 +00:00
Files
xcat-core/xCAT-test/unit/genesis_base_spec_buildrequires.t
T
Daniel Hilst 084d776d26 test(xcat-core): capture the el10 Genesis image shipping no openssl
The legacy Genesis image built on el10 carries no openssl command. getcert waits for one
with no bound, so the node reports no destiny and never boots. Nothing in the build or in
the suite sees the hole.

genesis_base_spec_buildrequires.t reads the spec and requires an unconditional
BuildRequires on openssl, and requires that no %{_target_cpu} is read after
BuildArch: noarch, where rpm has already set it to noarch.

genesis_payload_verification.t drives verify-genesis-payload with a dracut module and a
payload, and requires every command the module installs at the top level of install() to be
present. A name installed under a condition is not required, and a module the verifier
reads no names from is a usage error.

genesis_getcert_missing_openssl.t runs getcert with a PATH that holds stubs and no openssl,
under a harness timeout. Ten assertions fail on this commit: getcert never stops, and the
verifier and the spec do not know about openssl.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-04 23:50:46 -03:00

43 lines
1.7 KiB
Perl

#!/usr/bin/env perl
# The genesis spec is the build root manifest: what it does not build-require, the buildroot
# only holds by accident, and dracut_install then installs nothing.
use strict;
use warnings;
use FindBin;
use lib "$FindBin::Bin/../lib";
use Test::More;
use XCAT::Test::File qw(repo_path slurp_repo_file);
my $relative = 'xCAT-genesis-builder/xCAT-genesis-base.spec';
plan skip_all => "$relative not found" unless -f repo_path($relative);
plan tests => 4;
my @lines = split /\n/, slurp_repo_file($relative);
# getcert, getdestiny, getipmi and getadapter all run the openssl command. el8 and el9
# held it in the buildroot as a dependency of something else; el10 does not.
my @openssl = grep { /^BuildRequires:\s*openssl\s*$/ } @lines;
is(scalar(@openssl), 1, 'the spec build-requires openssl');
my ($buildarch) = grep { $lines[$_] =~ /^BuildArch:\s*noarch/ } 0 .. $#lines;
ok(defined $buildarch, 'the spec sets BuildArch: noarch');
# rpm reads the spec a second time with the target set to noarch, so %{_target_cpu} is
# "noarch" from BuildArch onwards. %{tarch} keeps the real architecture.
my @late_target_cpu = grep { $lines[$_] =~ /_target_cpu/ } ($buildarch + 1) .. $#lines;
is(scalar(@late_target_cpu), 0,
'%{_target_cpu} is not read after BuildArch: noarch')
or diag(join "\n", map { ($_ + 1) . ": $lines[$_]" } @late_target_cpu);
my ($openssl_line) = grep { $lines[$_] =~ /^BuildRequires:\s*openssl\s*$/ } 0 .. $#lines;
my $guarded = 0;
if (defined $openssl_line) {
for my $i (reverse 0 .. $openssl_line - 1) {
last if $lines[$i] =~ /^%endif/;
$guarded = 1, last if $lines[$i] =~ /^%if/;
}
}
is($guarded, 0, 'openssl is build-required on every release');