mirror of
https://github.com/xcat2/xcat-dep.git
synced 2026-09-30 14:55:17 +00:00
Fix openEuler repository finalization and manifest selection
Exclude native cells from cross-architecture Genesis finalization. Add the missing 24.03 SP1 manifest and expose repository signing for direct validation.
This commit is contained in:
+63
-5
@@ -1,8 +1,5 @@
|
||||
package MockBuildUtils;
|
||||
# Reusable, unit-testable helpers factored out of mockbuild-all.pl. Kept free of that script's
|
||||
# globals so t/mockbuild-all.t can exercise them directly. The two orchestration helpers that
|
||||
# need signing / re-indexing (cross_copy_genesis, finalize_xcat_dep) take those as injected
|
||||
# callbacks instead of reaching for gpg/createrepo state, so they stay pure and testable.
|
||||
# Build helpers use explicit settings and callbacks instead of script globals.
|
||||
use strict;
|
||||
use warnings;
|
||||
use Exporter 'import';
|
||||
@@ -26,6 +23,7 @@ our @EXPORT_OK = qw(
|
||||
parse_evr evr_cmp evr_constraint_ok parse_pin rpmkeys_checksig_problem
|
||||
rpm_version rpm_release rpm_sigmd5 rpm_is_signed restamp_release_line
|
||||
cross_copy_genesis finalize_xcat_dep bump_dep_release_suffix
|
||||
createrepo_c_cmd sign_and_index_repo
|
||||
build_mock_uniqueext rpm_in_cell resolve_mock_cfg
|
||||
openeuler_build_target openeuler_repo_subdir
|
||||
recover_common_repository
|
||||
@@ -521,6 +519,53 @@ sub read_manifest {
|
||||
return %m;
|
||||
}
|
||||
|
||||
sub createrepo_c_cmd {
|
||||
my ($dir, $epoch) = @_;
|
||||
return 'createrepo_c --update '
|
||||
. '--revision ' . sh_quote($epoch) . ' --set-timestamp-to-revision '
|
||||
. sh_quote($dir);
|
||||
}
|
||||
|
||||
sub sign_and_index_repo {
|
||||
my ($dir, $native, %options) = @_;
|
||||
my $run = $options{run} // die "Repository signing requires a command runner\n";
|
||||
my @rpms = grep { !/\.src\.rpm$/ } bsd_glob("$dir/*.rpm");
|
||||
if ($native) {
|
||||
require XCAT::NativeInputs;
|
||||
require XCAT::BuildUtils;
|
||||
my @built;
|
||||
for my $rpm (@rpms) {
|
||||
my $id = XCAT::NativeInputs::rpm_identity($rpm);
|
||||
my $owner = $native->{outputs}{$id->{name}} // die "Undeclared native output: $id->{name}\n";
|
||||
my $node = $native->{nodes}{$owner};
|
||||
if ($node->{type} eq 'publisher') {
|
||||
die "Publisher input changed before signing: $rpm\n"
|
||||
unless XCAT::BuildUtils::digest_file($rpm) eq $node->{sha256};
|
||||
} else {
|
||||
push @built, $rpm;
|
||||
}
|
||||
}
|
||||
@rpms = @built;
|
||||
}
|
||||
if ($options{gpg_sign} && @rpms) {
|
||||
local $ENV{GNUPGHOME} = $options{gpg_home} if $options{gpg_home};
|
||||
$run->('rpmsign --define ' . sh_quote("%_gpg_name $options{gpg_key_name}")
|
||||
. ' --define ' . sh_quote("%__gpg $options{gpg_program}") . ' --addsign '
|
||||
. join(' ', map { sh_quote($_) } @rpms));
|
||||
}
|
||||
$run->(createrepo_c_cmd($dir, $options{source_date_epoch}));
|
||||
if ($options{gpg_sign}) {
|
||||
local $ENV{GNUPGHOME} = $options{gpg_home} if $options{gpg_home};
|
||||
my $repomd = "$dir/repodata/repomd.xml";
|
||||
unlink "$repomd.asc" if -f "$repomd.asc";
|
||||
$run->("gpg -a --detach-sign --default-key " . sh_quote($options{gpg_key_name}) . ' ' . sh_quote($repomd));
|
||||
$run->("gpg -a --export " . sh_quote($options{gpg_key_name}) . " > " . sh_quote("$repomd.key"));
|
||||
if ($native) {
|
||||
$run->('cat ' . sh_quote($native->{publisher_key}) . ' >> ' . sh_quote("$repomd.key"));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
# cross_copy_genesis: copy the noarch xCAT-genesis-base-<tarch>-*.rpm from $from into $to, dropping
|
||||
# any stale foreign-arch genesis already in $to so the repo ends with exactly the fresh set.
|
||||
# Returns the count of rpms newly copied (0 = already up to date, so the caller can skip
|
||||
@@ -606,10 +651,23 @@ sub finalize_xcat_dep {
|
||||
# <os> built for only the OTHER arch slip through unseen -- finalize then never cross-populated
|
||||
# that cell and still exited 0 (PR #62 review). Every discovered <os> must carry every arch below.
|
||||
my %os;
|
||||
my $native_cells = 0;
|
||||
for my $a (@GENESIS_ARCHES) {
|
||||
my $root = $repo{ $a->{arch} }
|
||||
// die "FATAL: [finalize] no repo root configured for arch '$a->{arch}' (wire it in %repo)\n";
|
||||
$os{ basename($_) } = 1 for grep { -d "$_/$a->{arch}" } glob("$root/*");
|
||||
for my $dir (grep { -d "$_/$a->{arch}" } glob("$root/*")) {
|
||||
my $name = basename($dir);
|
||||
if ($name =~ /^openeuler/) {
|
||||
$native_cells++;
|
||||
next;
|
||||
}
|
||||
$os{$name} = 1;
|
||||
}
|
||||
}
|
||||
|
||||
if (!%os && $native_cells) {
|
||||
print "[finalize] openEuler repositories do not use cross-arch Genesis; skipping\n";
|
||||
return;
|
||||
}
|
||||
|
||||
my $pairs = 0;
|
||||
|
||||
+9
-36
@@ -271,7 +271,10 @@ if ($finalize_xcat_dep) {
|
||||
@finalize_arch = qw(x86_64 ppc64le) unless @finalize_arch;
|
||||
my %cell;
|
||||
for my $root ($x86, $ppc) {
|
||||
$cell{ abs_path($_) } = 1 for grep { -d } map { glob("$root/*/$_") } @finalize_arch;
|
||||
my @os = grep { -d && basename($_) !~ /^openeuler/ } glob("$root/*");
|
||||
for my $os (@os) {
|
||||
$cell{ abs_path($_) } = 1 for grep { -d } map { "$os/$_" } @finalize_arch;
|
||||
}
|
||||
}
|
||||
take_lock(cell_lock_path($_), 'repository cell lock') for sort keys %cell;
|
||||
# Inject the per-rpm gpg re-sign and the repo re-index as callbacks so the finalize logic in
|
||||
@@ -1541,45 +1544,15 @@ sub publish_file {
|
||||
# zypper read the XML.
|
||||
sub createrepo_c_cmd {
|
||||
my ($dir) = @_;
|
||||
return 'createrepo_c --update '
|
||||
. '--revision ' . shell_quote($SOURCE_DATE_EPOCH) . ' --set-timestamp-to-revision '
|
||||
. shell_quote($dir);
|
||||
return MockBuildUtils::createrepo_c_cmd($dir, $SOURCE_DATE_EPOCH);
|
||||
}
|
||||
|
||||
sub sign_and_index_repo {
|
||||
my ($dir, $native) = @_;
|
||||
my @rpms = grep { !/\.src\.rpm$/ } bsd_glob("$dir/*.rpm");
|
||||
if ($native) {
|
||||
my @built;
|
||||
for my $rpm (@rpms) {
|
||||
my $id = rpm_identity($rpm);
|
||||
my $owner = $native->{outputs}{$id->{name}} // die "Undeclared native output: $id->{name}\n";
|
||||
my $node = $native->{nodes}{$owner};
|
||||
if ($node->{type} eq 'publisher') {
|
||||
die "Publisher input changed before signing: $rpm\n" unless digest_file($rpm) eq $node->{sha256};
|
||||
} else {
|
||||
push @built, $rpm;
|
||||
}
|
||||
}
|
||||
@rpms = @built;
|
||||
}
|
||||
if ($gpg_sign && @rpms) {
|
||||
local $ENV{GNUPGHOME} = $gpg_home if $gpg_home;
|
||||
run_simple('rpmsign --define ' . shell_quote("%_gpg_name $gpg_key_name")
|
||||
. ' --define ' . shell_quote("%__gpg $gpg_program") . ' --addsign '
|
||||
. join(' ', map { shell_quote($_) } @rpms));
|
||||
}
|
||||
run_simple(createrepo_c_cmd($dir));
|
||||
if ($gpg_sign) {
|
||||
local $ENV{GNUPGHOME} = $gpg_home if $gpg_home;
|
||||
my $repomd = "$dir/repodata/repomd.xml";
|
||||
unlink "$repomd.asc" if -f "$repomd.asc";
|
||||
run_simple("gpg -a --detach-sign --default-key " . sh_quote($gpg_key_name) . ' ' . sh_quote($repomd));
|
||||
run_simple("gpg -a --export " . sh_quote($gpg_key_name) . " > " . sh_quote("$repomd.key"));
|
||||
if ($native) {
|
||||
run_simple('cat ' . sh_quote($native->{publisher_key}) . ' >> ' . sh_quote("$repomd.key"));
|
||||
}
|
||||
}
|
||||
return MockBuildUtils::sign_and_index_repo($dir, $native,
|
||||
gpg_sign => $gpg_sign, gpg_home => $gpg_home,
|
||||
gpg_key_name => $gpg_key_name, gpg_program => $gpg_program,
|
||||
source_date_epoch => $SOURCE_DATE_EPOCH, run => \&run_simple);
|
||||
}
|
||||
|
||||
sub write_dep_repo_metadata {
|
||||
|
||||
@@ -214,6 +214,20 @@ perl-Net-HTTPS-NB=>= 0.14-3
|
||||
perl-Net-Telnet=3.04
|
||||
xCAT-genesis-base=>= 2:2.18.0
|
||||
|
||||
[openeuler-24.03sp1-x86_64]
|
||||
goconserver=>= 0.3.3-snap202011021058
|
||||
grub2-xcat=1.0
|
||||
ipmitool-xcat=>= 1.8.18-4
|
||||
syslinux-xcat=>= 6.03-1
|
||||
xnba-undi=>= 1.21.1-1
|
||||
perl-Crypt-Rijndael=1.13
|
||||
perl-Crypt-SSLeay=0.72
|
||||
perl-HTTP-Async=>= 0.30-3
|
||||
perl-IO-Stty=>= 0.04-5
|
||||
perl-Net-HTTPS-NB=>= 0.14-3
|
||||
perl-Net-Telnet=3.04
|
||||
xCAT-genesis-base=>= 2:2.18.0
|
||||
|
||||
[openeuler-24.03sp3-x86_64]
|
||||
goconserver=>= 0.3.3-snap202011021058
|
||||
grub2-xcat=1.0
|
||||
|
||||
Reference in New Issue
Block a user