2
0
mirror of https://github.com/xcat2/xcat-dep.git synced 2026-09-30 14:55:17 +00:00

Fix openEuler repository finalization and manifest selection

Exclude native cells from cross-architecture Genesis finalization. Add the missing 24.03 SP1 manifest and expose repository signing for direct validation.
This commit is contained in:
Vinícius Ferrão
2026-09-29 00:03:57 -03:00
parent 5a625e94dd
commit 882ca33693
3 changed files with 86 additions and 41 deletions
+63 -5
View File
@@ -1,8 +1,5 @@
package MockBuildUtils;
# Reusable, unit-testable helpers factored out of mockbuild-all.pl. Kept free of that script's
# globals so t/mockbuild-all.t can exercise them directly. The two orchestration helpers that
# need signing / re-indexing (cross_copy_genesis, finalize_xcat_dep) take those as injected
# callbacks instead of reaching for gpg/createrepo state, so they stay pure and testable.
# Build helpers use explicit settings and callbacks instead of script globals.
use strict;
use warnings;
use Exporter 'import';
@@ -26,6 +23,7 @@ our @EXPORT_OK = qw(
parse_evr evr_cmp evr_constraint_ok parse_pin rpmkeys_checksig_problem
rpm_version rpm_release rpm_sigmd5 rpm_is_signed restamp_release_line
cross_copy_genesis finalize_xcat_dep bump_dep_release_suffix
createrepo_c_cmd sign_and_index_repo
build_mock_uniqueext rpm_in_cell resolve_mock_cfg
openeuler_build_target openeuler_repo_subdir
recover_common_repository
@@ -521,6 +519,53 @@ sub read_manifest {
return %m;
}
sub createrepo_c_cmd {
my ($dir, $epoch) = @_;
return 'createrepo_c --update '
. '--revision ' . sh_quote($epoch) . ' --set-timestamp-to-revision '
. sh_quote($dir);
}
sub sign_and_index_repo {
my ($dir, $native, %options) = @_;
my $run = $options{run} // die "Repository signing requires a command runner\n";
my @rpms = grep { !/\.src\.rpm$/ } bsd_glob("$dir/*.rpm");
if ($native) {
require XCAT::NativeInputs;
require XCAT::BuildUtils;
my @built;
for my $rpm (@rpms) {
my $id = XCAT::NativeInputs::rpm_identity($rpm);
my $owner = $native->{outputs}{$id->{name}} // die "Undeclared native output: $id->{name}\n";
my $node = $native->{nodes}{$owner};
if ($node->{type} eq 'publisher') {
die "Publisher input changed before signing: $rpm\n"
unless XCAT::BuildUtils::digest_file($rpm) eq $node->{sha256};
} else {
push @built, $rpm;
}
}
@rpms = @built;
}
if ($options{gpg_sign} && @rpms) {
local $ENV{GNUPGHOME} = $options{gpg_home} if $options{gpg_home};
$run->('rpmsign --define ' . sh_quote("%_gpg_name $options{gpg_key_name}")
. ' --define ' . sh_quote("%__gpg $options{gpg_program}") . ' --addsign '
. join(' ', map { sh_quote($_) } @rpms));
}
$run->(createrepo_c_cmd($dir, $options{source_date_epoch}));
if ($options{gpg_sign}) {
local $ENV{GNUPGHOME} = $options{gpg_home} if $options{gpg_home};
my $repomd = "$dir/repodata/repomd.xml";
unlink "$repomd.asc" if -f "$repomd.asc";
$run->("gpg -a --detach-sign --default-key " . sh_quote($options{gpg_key_name}) . ' ' . sh_quote($repomd));
$run->("gpg -a --export " . sh_quote($options{gpg_key_name}) . " > " . sh_quote("$repomd.key"));
if ($native) {
$run->('cat ' . sh_quote($native->{publisher_key}) . ' >> ' . sh_quote("$repomd.key"));
}
}
}
# cross_copy_genesis: copy the noarch xCAT-genesis-base-<tarch>-*.rpm from $from into $to, dropping
# any stale foreign-arch genesis already in $to so the repo ends with exactly the fresh set.
# Returns the count of rpms newly copied (0 = already up to date, so the caller can skip
@@ -606,10 +651,23 @@ sub finalize_xcat_dep {
# <os> built for only the OTHER arch slip through unseen -- finalize then never cross-populated
# that cell and still exited 0 (PR #62 review). Every discovered <os> must carry every arch below.
my %os;
my $native_cells = 0;
for my $a (@GENESIS_ARCHES) {
my $root = $repo{ $a->{arch} }
// die "FATAL: [finalize] no repo root configured for arch '$a->{arch}' (wire it in %repo)\n";
$os{ basename($_) } = 1 for grep { -d "$_/$a->{arch}" } glob("$root/*");
for my $dir (grep { -d "$_/$a->{arch}" } glob("$root/*")) {
my $name = basename($dir);
if ($name =~ /^openeuler/) {
$native_cells++;
next;
}
$os{$name} = 1;
}
}
if (!%os && $native_cells) {
print "[finalize] openEuler repositories do not use cross-arch Genesis; skipping\n";
return;
}
my $pairs = 0;
+9 -36
View File
@@ -271,7 +271,10 @@ if ($finalize_xcat_dep) {
@finalize_arch = qw(x86_64 ppc64le) unless @finalize_arch;
my %cell;
for my $root ($x86, $ppc) {
$cell{ abs_path($_) } = 1 for grep { -d } map { glob("$root/*/$_") } @finalize_arch;
my @os = grep { -d && basename($_) !~ /^openeuler/ } glob("$root/*");
for my $os (@os) {
$cell{ abs_path($_) } = 1 for grep { -d } map { "$os/$_" } @finalize_arch;
}
}
take_lock(cell_lock_path($_), 'repository cell lock') for sort keys %cell;
# Inject the per-rpm gpg re-sign and the repo re-index as callbacks so the finalize logic in
@@ -1541,45 +1544,15 @@ sub publish_file {
# zypper read the XML.
sub createrepo_c_cmd {
my ($dir) = @_;
return 'createrepo_c --update '
. '--revision ' . shell_quote($SOURCE_DATE_EPOCH) . ' --set-timestamp-to-revision '
. shell_quote($dir);
return MockBuildUtils::createrepo_c_cmd($dir, $SOURCE_DATE_EPOCH);
}
sub sign_and_index_repo {
my ($dir, $native) = @_;
my @rpms = grep { !/\.src\.rpm$/ } bsd_glob("$dir/*.rpm");
if ($native) {
my @built;
for my $rpm (@rpms) {
my $id = rpm_identity($rpm);
my $owner = $native->{outputs}{$id->{name}} // die "Undeclared native output: $id->{name}\n";
my $node = $native->{nodes}{$owner};
if ($node->{type} eq 'publisher') {
die "Publisher input changed before signing: $rpm\n" unless digest_file($rpm) eq $node->{sha256};
} else {
push @built, $rpm;
}
}
@rpms = @built;
}
if ($gpg_sign && @rpms) {
local $ENV{GNUPGHOME} = $gpg_home if $gpg_home;
run_simple('rpmsign --define ' . shell_quote("%_gpg_name $gpg_key_name")
. ' --define ' . shell_quote("%__gpg $gpg_program") . ' --addsign '
. join(' ', map { shell_quote($_) } @rpms));
}
run_simple(createrepo_c_cmd($dir));
if ($gpg_sign) {
local $ENV{GNUPGHOME} = $gpg_home if $gpg_home;
my $repomd = "$dir/repodata/repomd.xml";
unlink "$repomd.asc" if -f "$repomd.asc";
run_simple("gpg -a --detach-sign --default-key " . sh_quote($gpg_key_name) . ' ' . sh_quote($repomd));
run_simple("gpg -a --export " . sh_quote($gpg_key_name) . " > " . sh_quote("$repomd.key"));
if ($native) {
run_simple('cat ' . sh_quote($native->{publisher_key}) . ' >> ' . sh_quote("$repomd.key"));
}
}
return MockBuildUtils::sign_and_index_repo($dir, $native,
gpg_sign => $gpg_sign, gpg_home => $gpg_home,
gpg_key_name => $gpg_key_name, gpg_program => $gpg_program,
source_date_epoch => $SOURCE_DATE_EPOCH, run => \&run_simple);
}
sub write_dep_repo_metadata {
+14
View File
@@ -214,6 +214,20 @@ perl-Net-HTTPS-NB=>= 0.14-3
perl-Net-Telnet=3.04
xCAT-genesis-base=>= 2:2.18.0
[openeuler-24.03sp1-x86_64]
goconserver=>= 0.3.3-snap202011021058
grub2-xcat=1.0
ipmitool-xcat=>= 1.8.18-4
syslinux-xcat=>= 6.03-1
xnba-undi=>= 1.21.1-1
perl-Crypt-Rijndael=1.13
perl-Crypt-SSLeay=0.72
perl-HTTP-Async=>= 0.30-3
perl-IO-Stty=>= 0.04-5
perl-Net-HTTPS-NB=>= 0.14-3
perl-Net-Telnet=3.04
xCAT-genesis-base=>= 2:2.18.0
[openeuler-24.03sp3-x86_64]
goconserver=>= 0.3.3-snap202011021058
grub2-xcat=1.0