From face1c83280f01a45832a9dc25e9f56005b35998 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vin=C3=ADcius=20Ferr=C3=A3o?= <2031761+viniciusferrao@users.noreply.github.com> Date: Mon, 21 Sep 2026 18:24:49 -0300 Subject: [PATCH] docs(openeuler): describe native dependency inputs --- goconserver/toolchains/README.md | 12 ++++ openeuler/Build-notes | 102 +++++++++++++++++++++++++++++++ postgresql/Build-notes | 52 ++++++++++++++++ python-scp/SOURCE.md | 13 ++++ 4 files changed, 179 insertions(+) create mode 100644 goconserver/toolchains/README.md create mode 100644 openeuler/Build-notes create mode 100644 postgresql/Build-notes create mode 100644 python-scp/SOURCE.md diff --git a/goconserver/toolchains/README.md b/goconserver/toolchains/README.md new file mode 100644 index 0000000..73c7e48 --- /dev/null +++ b/goconserver/toolchains/README.md @@ -0,0 +1,12 @@ +# Native openEuler Go build input + +The native openEuler RPM build uses Go 1.25.12 inside the exact target mock root. +The committed module graph requires this version. The build retains GOTOOLCHAIN=local and CGO_ENABLED=0. + +The checksums in go1.25.12.sha256 come from the [official Go release list](https://go.dev/dl/#go1.25.12). +The builder verifies the archive before including it as Source3, and the generated spec verifies it again before extraction. +The toolchain stays in the RPM build directory and is excluded from the goconserver binary package. +The source RPM contains the exact compiler archive, including its Go sources and license, for subsequent rebuilds. + +Build x86_64 and ppc64le packages on matching native architecture builders. The package release retains the native empty dist suffix. +Existing EL compilation and cross-build paths retain their original toolchain selection. diff --git a/openeuler/Build-notes b/openeuler/Build-notes new file mode 100644 index 0000000..553c6b9 --- /dev/null +++ b/openeuler/Build-notes @@ -0,0 +1,102 @@ +openEuler 24.03 LTS POWER inputs + +This GA target is a functional build profile. It does not establish maintained +POWER service-pack support or physical platform qualification. + +The 24.03-ppc64le.inputs.json catalog pins the native source RPMs, publisher +noarch RPMs, public key, spec patch, and spec definitions used by this target. +Its outputs are RPM package names. The packages-manifest.conf POWER section +selects the required runtime outputs; needs selects their build prerequisites. +The build_inputs group supplies the additional same-GA noarch build packages. +No binary package from another service pack or architecture is admitted. + +Use an exact native ppc64le openEuler 24.03 LTS builder. The target configuration +uses the published OS repository, native vendor macros, and Mock simple +isolation. POWER GA has no published Everything, update, or EPOL architecture +repository. Individual GA noarch inputs are pinned from the publisher's other +architecture repositories. Each must have a noarch header, a GA release suffix, +a valid publisher signature, and no ELF file anywhere in its RPM payload. +They retain their original bytes and signatures in the resulting repository. + +Run the existing owner through actual sudo from UID1000. The native Mock 2.2 +entry at /usr/libexec/mock/mock must precede consolehelper's /usr/bin/mock in +sudo's PATH. The target fixes chrootuid and chrootgid at 1000. Do not synthesize +SUDO_UID or USERHELPER_UID. Preserve the actual Mock build logs and confirm +UID1000 for compiled packages. Genesis assembles a root filesystem as UID0; +xNBA packages existing boot artifacts as UID0 and has no compilation or check +section. These are the two packaging exceptions. + + sudo perl mockbuild-all.pl --target openeuler-24.03-ppc64le \ + --xcat-source /path/to/frozen/xcat-core \ + --output /path/to/private/output --max-parallel 1 \ + --gpg-sign --gpg-home /path/to/signing-home \ + --gpg-key-name SIGNING_FINGERPRINT --build-timestamp SOURCE_EPOCH + +Freeze both source trees and record their hashes before running the owner. +Use a fresh output/run identity. Do not modify input files while a build runs. +The owner validates the complete graph and output ownership before starting +Mock. It fetches all selected inputs, verifies them in a private publisher +RPM database, and preserves the signed originals under native-inputs. + +The source RPM path in mockbuild-all.pl builds the prerequisites in dependency +order. Publisher inputs precede source builds; existing owners run afterward. +Dependencies on an existing owner and publisher dependency edges are rejected +before acquisition because those phases cannot honor them. Patches and +definitions use that same source path. Native results remain +unsigned under native-results; signed copies populate native-prerequisites. +Private configuration overlays bind that repository into subsequent Mock +roots. Their paths and hashes are recorded in native-overlays.json. Publisher +RPMs retain their publisher signatures; generated RPMs require the selected +build signing key. Repository metadata is signed by the build key and exports +both public keys. Neither key is imported into the builder's system RPMDB. + +Native Mock's procenv plugin requires a procenv package that GA OS lacks. +The procenv source is therefore built first with only that diagnostic plugin +disabled in a recorded private overlay. Its normal vendor checks and UID1000 +build remain enabled. All subsequent roots enable the plugin and obtain the +newly signed native procenv package. No package feature or test is disabled. + +The final repository collects the manifest-selected native/publisher outputs +and the established script-owner outputs. PostgreSQL and its source helper +chain remain in the private prerequisite repository; the normal xCAT/xCATsn +closure does not select a PostgreSQL server. Native perl-DBD-Pg is required by +the service image profiles. Its unchanged vendor check needs PostgreSQL. +The PostgreSQL patch and vendor options are described in ../postgresql/Build-notes. +Those options preserve normal SQL, authentication, backup, and reconnect +features. Runtime backend validation is a separate gate from package builds. + +Bootstrapping the build tools + +The catalog's bootstrap_inputs records the native source chain needed when +Mock and the owner Perl modules are absent. It includes the unchanged official +24.03 SP3 File-Slurper source RPM because GA publishes no such source package. +Rebuild that source on GA; do not install its SP3 binary RPM. + +The input verifier uses only core Perl modules. It can fetch and verify these +inputs before Mock is installed: + + perl -Ilib -MXCAT::NativeInputs=load_inputs,stage_inputs -e ' + my ($root, $stage) = @ARGV; + my %required = map { $_ => "*" } qw(mock perl-Params-Util + python3-psutil python3-pyroute2 perl-PerlIO-utf8_strict + perl-File-Slurper procenv); + stage_inputs(load_inputs($root, \%required), $stage); + ' "$PWD" /path/to/new/private/input-stage + +Use a disposable exact-GA installroot for bootstrap builds. Install rpm-build, +dnf-plugins-core, gcc, make, and each source's full BuildRequires through strict +signed native repositories. Extract the verified source with rpm -i and a +private _topdir; use dnf builddep on the extracted spec. Run normal rpmbuild -ba +as UID1000 without changing the vendor spec or disabling its check section. +Build native perl-Params-Util before users of perl-Module-Build; build +perl-PerlIO-utf8_strict before perl-File-Slurper. Build python-psutil and +python-pyroute2 before installing Mock. Build procenv for Mock diagnostics. +The pinned noarch group supplies the missing pure Perl/Python prerequisites. +Retain unsigned outputs, vendor check logs, native architecture, full RPM +Provides/Requires, and the original-source and output hashes. Sign copies and +verify them against a private RPMDB before making them available to DNF. + +Install the resulting native Mock, its runtime prerequisites, and the owner +Perl modules inside the disposable builder. Use the existing mockbuild-all.pl +owner for subsequent target/package builds. The bootstrap instructions do not +replace its scheduler, collector, signature gate, or repository layout. diff --git a/postgresql/Build-notes b/postgresql/Build-notes new file mode 100644 index 0000000..37cf0c1 --- /dev/null +++ b/postgresql/Build-notes @@ -0,0 +1,52 @@ +openEuler 24.03 LTS native build inputs + +This source supplies a build prerequisite for the native perl-DBD-Pg checks. +The dependency repository does not select a PostgreSQL server for the normal +xCAT/xCATsn closure. PostgreSQL backend runtime qualification is separate. + +Source RPM: +https://repo.openeuler.org/openEuler-24.03-LTS/source/Packages/postgresql-15.6-1.oe2403.src.rpm +SHA256: 0e1dd792cccf353f7a0d7f3f9d13b1a22a7ace0a428f4b197193b99c58081960 + +Publisher key: +https://repo.openeuler.org/openEuler-24.03-LTS/source/RPM-GPG-KEY-openEuler +Fingerprint: 8AA16BF9F2CA5244010DCA963B477C60B675600B + +Verify the source RPM checksum, signature, and payload digests before extraction. +Apply postgresql-15.6-openeuler-llvmjit-buildrequires.patch with patch -p1 +from the directory containing the extracted postgresql.spec. + +The patch makes the clang BuildRequires follow the existing llvmjit option. +PostgreSQL uses clang to generate LLVM bitcode. Its normal C compiler selection +uses gcc or cc, and its LLVM build paths are disabled when llvmjit is zero. +JIT-enabled BuildRequires remain unchanged. + +Use the native openEuler build environment and these existing vendor options: + + --define 'llvmjit 0' --define 'external_libpq 0' + --define 'runselftest 1' --define 'test 1' + +Keep the other vendor feature defaults, including SSL, GSSAPI, LDAP, PAM, +SELinux, ICU, UUID, and procedural languages. Build as an unprivileged user; +the regression tests require this. Retain the regression, contrib, procedural +language, and postgresql-setup tests. Resolve all remaining BuildRequires from +signed native packages before building. + +Use the vendor-default private libpq build. Its libraries have private SONAMEs. +The external_libpq=1 branch in this SRPM has a stale patch that fails during +normal preparation. Build DBD-Pg with the vendor libpq-devel package; +postgresql-private-devel declares a conflict with that package. + +On ppc64le, use mock-configs/openeuler-24.03-ppc64le.cfg when invoking the +existing mock build owner. The downloaded source RPM and generated packages +are external build artifacts. This directory does not add a package builder. + +After building, verify package Provides/Requires, native architecture, and +libpq linkage. Build the matching native DBD-Pg source RPM without changes: + +https://repo.openeuler.org/openEuler-24.03-LTS/source/Packages/perl-DBD-Pg-3.18.0-1.oe2403.src.rpm +SHA256: 5bb91b28459ee5754c031cf62471c86a887392587c261c8df61ab44e4c8caf09 + +Retain its make test check. Validate xCAT schema initialization, SQL +transactions, authentication, backup/restore, and reconnect behavior before +using the resulting packages for management or service nodes. diff --git a/python-scp/SOURCE.md b/python-scp/SOURCE.md new file mode 100644 index 0000000..5e3cf7c --- /dev/null +++ b/python-scp/SOURCE.md @@ -0,0 +1,13 @@ +`python-scp-0.14.5-1.oe2403.src.rpm` is the unchanged openEuler 24.03 LTS +source package, rebuilt for openEuler 20.03 LTS SP4, whose native repositories +do not provide `python3-scp`. + +- Source: https://repo.openeuler.org/openEuler-24.03-LTS/source/Packages/python-scp-0.14.5-1.oe2403.src.rpm +- SHA256: `3461d2a3fe0122cac2893d8465ad1271ae21e5570a31d4402e3f887ef545a0e8` +- Upstream signing key: `8AA16BF9F2CA5244010DCA963B477C60B675600B` +- License: LGPL-2.1-or-later + +The upstream spec disables its SSH-dependent `%check`. Native validation must +include authenticated SCP uploads and downloads, recursive paths, mode and time +preservation, and rejection of incorrect client and server keys. The build uses +the target's native Python and Paramiko packages.