The debs land in staging before the smoke runs, and the publish gate checks
names and versions only. A deb whose binary could not run therefore stayed in
staging and was eligible for publication, which is the case the smoke exists to
catch. The failure now removes the debs it rejected and says so.
The worker spawned the builder with system(), so the builder, its schroot
session and qemu were in the worker's process group but owned by nobody: a
cancelled worker died and left them running, holding the chroot and writing
into staging. Only the build inside the builder was protected, and nothing
signalled the builder.
The builder now runs through run_bounded, which gives it its own process group
and forwards the signal, so one cancellation unwinds the whole chain. The
wall-clock bound stays with the builder, which derives it from the chroot arch.
A forked worker also drops the parent's forwarder, whose copy names siblings the
parent already signals.
Two real processes stand in for a worker and the build it runs. The probe fails
when the handler forwards to nobody, which is what the orchestrators did.
Both orchestrators fork a worker per codename or per build step, so a signal
sent to the orchestrator never reached the builds: run_bounded's forwarding
covers the build inside one worker, not the workers themselves. The
orchestrator exited and released its locks while its workers kept building,
and the next run raced processes it could not see.
One handler now passes INT, TERM and HUP to the live workers, waits for them
and re-raises the signal, shared by the sbuild loop and both ForkManager pools.
With no deadline the helper called system(), which leaves the build in the
orchestrator's process group and installs no signal handler. A cancellation
then killed the orchestrator, which released its locks while the build kept
writing into staging, and a build killed by a signal was reported as rc=0.
Both paths now fork; a timeout of 0 removes the deadline, nothing else.
BUILD.md covered the EL10 riscv64 cross-build but said nothing about the apt
side, which now builds riscv64 too. Record the binfmt prerequisite, the ports
mirror, what each package does on that arch, the post-build smoke and the
measured build times.
The package declared libc6 and libssl by hand and never used
${shlibs:Depends}, so it named neither readline nor ncurses. The riscv64 deb
installed and then failed with "error while loading shared libraries:
libreadline.so.8". dpkg-shlibdeps now supplies the list from the built binary,
and the manifest pins follow the new revision.
Six of the assertions fail against the previous build_deb_in_chroot, which
accepted a smoke argument it never acted on: a wrong version, a binary that
exits non-zero, and a smoke naming a deb the build never produced all passed.
A cross-built deb links against the target's loader and libraries, neither of
which exists on the build host, so a binary that cannot run still produces a
green build. The rpm side installs the package into the mock chroot and runs -V
there; the deb side had no smoke at all.
build_deb_in_chroot now takes an optional smoke: it installs the produced deb
with apt-get inside the chroot that built it, runs the named command and matches
its output. apt-get rather than dpkg -i, so a wrong or missing Depends fails
here instead of on a node. --skip-install drops the smoke.
The two assertions fail against the previous package list and pass with it,
so a later edit cannot drop the binfmt handler that a foreign chroot needs.
--install-deps named no qemu-user-static and no binfmt-support, so on a host
without them the mode reported success and the next command still refused to
create the riscv64 chroot. The message tells the operator to install those two
packages, which the mode meant to do.
The command records its own pid and sleeps well inside the budget, so the
bound cannot be what ends it; the wrapper is then terminated and the pid
probed. Without the forwarding the build survives.
The bounded build ran in its own process group, but a signal to the
orchestrator was not forwarded to it. On cancellation the orchestrator
exited and released its locks while schroot, mock and qemu kept running and
writing into staging, so the next run raced an orphan it could not see.
INT, TERM and HUP now reap the group before the process dies by the same
signal, which keeps the exit status honest.
Drives the check extracted from sbuild-all.pl with the handler node
redirected into a temporary tree, covering the native case, a foreign
target with no handler, and the same target once one is registered.
A chroot for another architecture is bootstrapped and built through
qemu-user: debootstrap's second stage and every later build run the
target's own binaries. Without a registered handler that failed deep inside
debootstrap, on a builder that had never been prepared for the new riscv64
target. The handler is now checked before the chroot is created, and the
message names what to install. The release recipe in the manual gains the
riscv64 staging run and names the architecture where it publishes and
verifies, because an explicit --expect-arch bypasses staged discovery.
The build timeout helper was imported at compile time, and it pulls in
XCAT::BuildUtils, which needs File::Slurper. The Ubuntu build hosts do not
all carry that module, so every caller began to depend on it -- including
--install-deps, whose whole job is to install it on a host that lacks it.
The helper is now loaded where it is used.
The build guides published with --expect-arch "amd64 ppc64el". An explicit
set bypasses staged-architecture discovery, and the assembly writes the
Packages indexes and Release metadata only for that set, so following them
produced a repository with no riscv64 index even when the build staged it.
The legacy Genesis deb is named per target in the manifest, and riscv64
does not name it: its Genesis is the OpenEmbedded package published once
into the shared pool. The phase ran for every architecture regardless, so
a plain --arch riscv64 run died asking for a --genesis-deb it can never
have, and only after the dependency builds had finished. The phase is now
taken from the manifest, so it runs exactly where a Genesis deb is
expected. --skip-genesis still skips it everywhere.
Drives the scan extracted from sbuild-all.pl against a staged tree holding
every supported architecture plus an unsupported one, so the assertions
read the set publish would carry forward rather than a copy of the rule.
In publish mode with no --expect-arch, the expected set is discovered by
scanning the staged tree, and that scan admitted a hardcoded amd64 or
ppc64el. A staged riscv64 tree was therefore dropped, and only expected
architectures get a binary-<arch> index written and named in the Release
file, so the packages built for riscv64 never reached the repository. The
scan and the verification probe now use the architecture set the rest of
the script already reads from supported_arches().
Every per-package build ran through a bare system() call with no wall-clock
bound. Under qemu-user a build can deadlock -- a riscv64 goconserver `go build`
held both Go pids in futex_wait for 26 minutes with no CPU ticks and no open
socket -- and the step then never returns. The pipeline does not go red; it
stops, and a stopped run reads as "still running".
XCAT::BuildUtils::run_bounded runs the command in its own process group, kills
that group when a budget expires, and prints first what the manual
investigation had to collect by hand: the process tree, each pid's kernel wchan
and stack, its open socket count, and the CPU ticks the group used across a
20-second sample. Zero ticks names a deadlock; ticks name a build that is only
slow. BuildUtils::build_deb_in_chroot bounds every Ubuntu package build, and
mockbuild-all.pl bounds the dep and perl steps of a forcearch target.
The budget is 900 seconds for a native build and ten times that for a foreign
architecture, because qemu-user under TCG runs at roughly a tenth of native
speed. Both sit about five times above the slowest build measured on
xcat-master-ub: 3 minutes native, and 26 minutes for riscv64 ipmitool-xcat on
resolute with four codenames building at once. Native mock steps stay unbounded
-- no measurement of them exists, and a guessed budget would turn a trusted
cell red. sbuild-all.pl --build-timeout and mockbuild-all.pl --build-timeout
override the default; 0 removes the bound.
t/build_timeout.t fails without this change: run_bounded never returns and the
test reports the hang instead of blocking.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
A riscv64 goconserver `go build` sat 26 minutes with zero CPU ticks across a
20-second sample, both Go pids in futex_wait and no socket open. Nothing bounds
a build step, so the cell did not fail -- it hung, and a hung run reads as
"still running" rather than as a defect.
t/build_timeout.t drives the bounded path with a command that hangs and asserts
that the call returns, reports a timeout, and prints the process tree, each
pid's wchan, the open socket count and a CPU-tick sample. A second case drives a
spinning command and asserts the report calls it slow, not deadlocked, so the
sample means something.
Each call under test runs in a forked child whose stdio is detached to a file,
and the parent bounds that child. An unbounded run must fail this test, not
block prove.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
Every Ubuntu build fails its manifest validation:
[noble-amd64] grub2-xcat: built 2.12-2, manifest pins 2.12-1
Adding the EL10 riscv64 grub2 UEFI image bumped grub2-xcat/debian/changelog to
2.12-2 and left debs-manifest.conf pinning 2.12-1, in all twelve sections. The
package builds; only the pin is wrong.
t/sbuild-all.t compares every non-glob pin with its changelog, and fails on this
one without the change.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
The Ubuntu build fails at the end, after compiling every package:
FATAL: manifest validation failed:
[noble-amd64] grub2-xcat: built 2.12-2, manifest pins 2.12-1
debs-manifest.conf pins the exact deb version each package must produce, and that
version comes from the package's own debian/changelog. Bumping the changelog
without the pin costs a whole build to discover a one-line edit.
The test compares every non-glob pin with the first line of that package's
debian/changelog. Globbed pins are deliberate -- goconserver's revision is the CD
stamp and xcat-genesis-base is not versioned by xcat-dep -- and are skipped. It
fails on grub2-xcat today.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
The architecture-coverage block was appended at the end of t/sbuild-all.t, past
done_testing. Test::More had already declared the plan, so the run ended with
"planned 194 tests but ran 197" and the three assertions counted for nothing.
Move the block above done_testing.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
The 2.19 release needs riscv64 debs, and sbuild-all.pl accepted only amd64 and
ppc64el, so no target produced them.
The supported architecture set moves into BuildUtils as one source of truth
(supported_arches/is_supported_arch), which --arch, --target and --expect-arch now
consult; the mirror rule becomes "anything but amd64 is on ubuntu-ports", which is
what ppc64el already needed and riscv64 needs too; and the genesis control remap
stops naming ppc64el.
ipmitool-xcat also could not build there. Its debian/control names architectures
explicitly and omitted riscv64, so debhelper reported "No packages to build.
Possible architecture mismatch" and the build died at ./configure. conserver and
goconserver say Architecture: any and needed nothing.
debs-manifest.conf gains a [<codename>-riscv64] section for each codename. It
lists neither the x86 boot loaders -- a riscv64 node netboots UEFI grub2 -- nor
xcat-genesis-base, whose riscv64 flavour is the OpenEmbedded one in the shared
pool.
t/sbuild-all.t covers the control-file defect: it fails on ipmitool without this
change.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
ipmitool-xcat fails to build on riscv64:
dh: warning: No packages to build. Possible architecture mismatch:
riscv64, want: i386 amd64 ia64 ppc64el
make: ./configure: No such file or directory
Its debian/control names architectures explicitly, and riscv64 is not in the
list, so debhelper builds nothing and the build dies at configure. conserver and
goconserver say Architecture: any and are unaffected.
The test reads each compiled dep's debian/control and asserts that an explicit
architecture list covers every arch BuildUtils::supported_arches names. It fails
on ipmitool today.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
Master gained the EL10 riscv64 forcearch target (PR #66) and the Perl Ubuntu
build (PR #63). Both touch the files this branch rewrites, so the merge is
resolved per file:
mockbuild-all.pl, mockbuild-perl-packages.pl keep the forcearch target profile,
the noarch chroot and --epel-gap from master, and this branch's manifest gate,
atomic per-cell deploy and per-package chroot scrub. assert_required_deps is
dropped: verify_target_repo replaced it. The post-join bootstrap scrub now reads
the uniqueext and the config recorded when the chroot was made, because the wave
loop of master no longer numbers packages in @packages order.
packages-manifest.conf gains a [rocky-10-riscv64-xcat] section. A target with no
section is fatal, so without it the riscv64 target cannot run.
goconserver/mockbuild.pl builds in the mock chroot for the host arch and cross-
compiles on the host for a foreign --target-arch. A forcearch chroot would run
the Go toolchain under qemu. Both paths overlay the pinned go.mod/go.sum and
ship server.conf as YAML.
The host-install smoke stays removed (it corrupts the build host rpm database).
The checks that do not install on the host are kept: the chroot install of a
cross-built ipmitool-xcat and XS perl module, and the binfmt run of the cross-
built goconserver binaries.
goconserver/gomod/ takes the pin of master, whose `go` directive is the lower of
the two, so both the EL10 chroot and the Ubuntu sbuild toolchain accept it.
t/genesis_openembedded_consumer.t: the skip count of the RPM block is 64, the
number of tests it runs. Both sides carried a stale number.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
A CD run died at compile time inside XCAT::BuildUtils because xcat-master-ub was
missing File::Slurper: "Can't locate File/Slurper.pm in @INC", in the middle of a
build. It was fixed by hand, so the next unprovisioned host fails the same way
and the documented install line can drift from what the code actually loads.
--install-deps installs this host's prerequisites and exits: the sbuild/schroot
toolchain plus the modules. It then LOADS each module and fails naming any that
is still missing, rather than trusting apt's exit code.
That probe earned its place immediately: the first list named libipc-cmd-perl,
which does not exist on Ubuntu -- IPC::Cmd is core there -- and apt failed the
whole install over it. The package is gone from the list and the module is
asserted by loading instead, with a test that pins both halves of that reasoning.
The list and the command are pure functions in BuildUtils, so the decision is
unit-tested and the side effect stays in the caller. Run on xcat-master-ub and
xcat-master-ub-ppc: both report every module present.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
Two CD runs died at compile time inside XCAT::BuildUtils because a builder was
missing a Perl module the script loads: perl-File-Slurper on xcat-master-ub and
perl-IPC-Cmd on xcat-master-ppc. Both surfaced as "Can't locate ... in @INC" in
the middle of a build, and both were fixed by hand -- so the next unprovisioned
host fails the same way, and BUILD.md's install line can drift from what the code
actually requires.
--install-deps installs this host's prerequisites and exits: the toolchain plus
the modules, through dnf or zypper as the host's ID dictates. It then LOADS each
module and fails naming any that is still missing, rather than trusting the
package manager's exit code -- a package that installs cleanly but leaves the
module unusable is exactly the failure this exists to prevent.
The list and the command are pure functions in MockBuildUtils, so the decision is
unit-tested (package sets per family, the right installer non-interactively, and
the probe reporting only what genuinely cannot be loaded); the side effect stays
in the caller. Run on xcat-master and xcat-master-ppc: both report every module
present. xcat-master-suse is unreachable and still needs it.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
Every package in a suite pool is gated against debs-manifest.conf, but the
OpenEmbedded Genesis release is published into pool/main/xcat-genesis-openembedded
-- one pool every suite indexes, described by no [<codename>-<arch>] section. So
nothing asserted the published pool was complete: its packages were checked only
as they were copied, against the release checksums, and a pool that lost one
afterwards would publish quietly.
[shared] describes that pool -- all seven architectures, pinned '2.*' like
xcat-genesis-base, because they are built FROM xcat-core and their version walks
with it. A glob rather than an EVR floor: pins in this manifest are exact-or-glob
(version_matches), and the '>= epoch:version-release' form is an EL-side feature
of packages-manifest.conf. verify_shared_pool runs on the side tree before the
swap, so an incomplete pool is never published.
[shared] is not a build target, so the manifest now has two kinds of section. No
code iterates sections blindly, but t/sbuild-all.t did -- twice -- so it now
selects <codename>-<arch> sections and asserts the shared-pool section is not
treated as a target. The consumer fixtures carry the shipped [shared] section
verbatim: publishing a release against a manifest that lacks it is refused, not
silently ungated.
Verified the gate fails when removed, and when [shared] and the pool disagree.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
Every package in the per-EL cells is gated against packages-manifest.conf, but
the OpenEmbedded Genesis release is published into xcat-dep/common, which sits
BESIDE those cells and is described by no [<target>] section. Nothing asserted
the published shared repository was complete: its packages were checked only as
they were copied, against the release checksums, so a repository that lost one
afterwards would publish quietly.
[common] describes that repository -- all seven architectures, floored at the
paired xcat-core version (>= 2.18.0; these carry no Epoch, unlike
xCAT-genesis-base). verify_common_repo runs on the STAGE, before the atomic swap,
so an incomplete shared repo is never published. Completeness only: the release
checksums cover the bytes and the deploy asserts every signature.
[common] is not a build target, so the manifest now has two kinds of section.
No code iterates sections blindly, but t/mockbuild-all.t did, and asserted
conserver-xcat in every one; it now selects target-named sections and asserts
the shared-repo section is NOT treated as a target.
t/common-repo-gate.t drives the real publish path and asserts on the repository
left behind. Verified it fails without the gate, and that dropping an
architecture from [common] is caught.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
The manifest pinned most packages by %{VERSION} alone, so the gate accepted an
rpm with the right Version and a Release older than xCAT will install against --
xCAT states several of these as ">= version-release" Requires (PR #62 review).
Converted, in every section, to the floors taken verbatim from xcat-core's specs:
goconserver >= 0.3.3-snap202011021058, xnba-undi >= 1.21.1-1,
syslinux-xcat >= 6.03-1, ipmitool-xcat >= 1.8.18-4 (xCAT.spec / xCATsn.spec),
perl-HTTP-Async >= 0.30-3, perl-Net-HTTPS-NB >= 0.14-3 (xCAT-server.spec). Where
two specs disagree the stronger floor is used. Each was checked against the EVR
this repository actually builds, using the gate's own comparator, so none of them
reds a build that is in fact correct.
grub2-xcat is deliberately left on its Version pin. xCAT-server asks for
'>= 2.02-0.76.el7.1.snap201905160255', but the grub2-xcat built here -- and shipped
by both published channels today -- is 1.0-2, which cannot satisfy it. Encoding
that Requires would fail every build over a discrepancy that lives in xcat-core,
so it is documented in the manifest header and reported upstream instead.
t/mockbuild-all.t now guards the shipped manifest: every release-sensitive
package keeps an EVR floor in every section, and grub2-xcat stays the documented
exception. Verified the guard fails when a floor is regressed to a bare version.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
verify_target_repo filtered the manifest through required_pkgs() with the
invocation's --skip-genesis / --skip-perl / --skip-xcat-dep, so the flags that
describe what a run BUILT also decided what the verified repository was allowed
to lack: a repo with no xCAT-genesis-base passed whenever the verifying run
carried --skip-genesis (PR #62 review). Those flags mean "this invocation did not
build it", never "the repository may ship without it" -- a package an earlier run
produced is still expected to be present. The gate now takes the manifest whole.
No change for the CD pipeline, which passes no package-selection skips; it closes
the hole for the documented skip-mode and finalize invocations.
The Genesis-release consumer fixtures now pass --no-verify-repo. Their dependency
packages are copies of a single rpm, so no manifest describes them the way a real
one describes a real build -- with the gate honest, a fixture manifest could only
be satisfied by lying about what the cell contains. The gate is covered instead
against purpose-built rpms in t/verify-repo-el.t, and those runs still need a
manifest SECTION to exist, which is all they ever needed.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
verify_target_repo filters the manifest through required_pkgs() with the
invocation's --skip-genesis / --skip-perl / --skip-xcat-dep, so the flags that
say what THIS run built also decide what the verified repository is allowed to
be missing. A repo with no xCAT-genesis-base passes when the verifying run was
given --skip-genesis (PR #62 review).
Drives the real `mockbuild-all.pl --verify-repo` over fixture repos built from
two minimal rpms, so the gate reads real header names. The assertions are on the
reported problems rather than the exit code: a standalone --verify-repo demands a
repomd signature by contract and these fixtures are unsigned, so it exits
non-zero either way -- what separates a working gate from a broken one is
whether the missing package is NAMED. The complete-repo baseline is asserted too,
so the test cannot pass by the gate simply always complaining.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
verify_assembled_repo filtered the manifest through required_pkgs() with this
invocation's --skip-genesis / --skip-xcat-dep. Since the documented publish-only
run IS `--skip-build --skip-genesis --publish`, the flags that describe what this
invocation built were also deciding what the published repository was allowed to
lack -- so a repository with no xcat-genesis-base passed its own publication
gate (PR #63 review).
Those flags mean "this invocation did not build it", never "the repository may
ship without it": a package built by an earlier run is still expected in the
tree, which the side tree is seeded from. The gate now takes the manifest whole.
The other two required_pkgs() call sites are unchanged and correct -- they choose
what to BUILD and what to validate in THIS arch's staging.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
The documented publish-only invocation is
`sbuild-all.pl --skip-build --skip-genesis --publish`, and verify_assembled_repo
passes those same flags to required_pkgs() when deciding what the PUBLISHED
repository must contain. So the flags that say what this INVOCATION built also
decide what the repository is allowed to be missing, and a repo carrying no
xcat-genesis-base passes its own publication gate.
Assert the gate on a repo missing Genesis (with --skip-genesis) and on one
missing a compiled dep (with --skip-xcat-dep). Both fixtures keep native stanzas
for the arch, so the failure under test is the missing PACKAGE and not the arch
reading as absent. Both fail on the current gate.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
A CI run of this branch died on resolute/ppc64el with a 404 fetching
libssl-dev_3.5.5-1ubuntu3.4_ppc64el.deb: a development suite rolled openssl and
dropped that version from the pool while the chroot's index still named it.
mk-build-deps was the one apt operation in the in-chroot script NOT wrapped in
apt_retry, so a single transient mirror inconsistency failed the package -- and,
with the matrix running failFast, took the other architecture's in-flight builds
down with it.
Retry it the same way the rest of the script retries apt, refreshing the index
between attempts, since a stale index is precisely what produces this. It stays
FATAL once the attempts are spent: a package must never build against whatever
the chroot happens to carry. The refresh goes through apt_retry, so every
apt-get in the script still runs under the fatal helper.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
Record what differs from the EPEL-fed x86_64 repo (perl-Net-DNS stays at the
EPEL-free 0.80 noarch build; newer XS-free Net-DNS is a follow-up), how the
cross-built goconserver is stripped, and that the per-package mock chroots of
a riscv64 run add up under /var/lib/mock so --max-parallel also bounds disk.
For a native build rpm's brp-strip strips the Go binaries; for a cross build
(--target-arch riscv64 on x86_64) the host strip cannot handle the foreign
ELF and the rpm shipped unstripped 19 MB binaries. Pass -s -w to the Go
linker for cross builds only, so the riscv64 rpm is stripped like the
native ones; native builds are unchanged.
A riscv64 run lost perl-Crypt-SSLeay to a transient mirror problem: the
bootstrap chroot's dnf got HTTP 404 for BaseOS primary.xml.gz on every Rocky
mirror (metadata mid-sync) and mock exited 30 (YumError) from --buildsrpm,
which the builder treated as a hard failure. Give the mock-driven builders --
mockbuild-perl-packages.pl, ipmitool, grub2-xcat and conserver -- a small
run_mock wrapper that reruns the same mock command once when it exits 30
(the package-manager failure code; build failures exit 10 and are not
retried), and use it for their --buildsrpm/--rebuild invocations.
mockbuild-all.pl only knew the mock-core-configs targets <os>+epel-<rel>-<arch>
and only ever built the host arch. Teach it the forcearch targets shipped in
mock-configs/ (today rocky-10-riscv64-xcat), selected with --target, so an
x86_64 host cross-builds and deploys rh10/riscv64 exactly like the native
per-EL repos (rh<rel>/<arch> layout, xcat-dep.repo with the xcat.org baseurl,
mklocalrepo.sh, buildinfo.txt, optional signing).
A target now has a profile (target_profile): EL release, arch of the rpms,
the mock config for its noarch deps, the dep builders to run and the required
set asserted after deploy. The native targets keep today's profile (every
builder, host arch, the full required set). The riscv64 profile:
- builds ipmitool-xcat, conserver-xcat and goconserver for riscv64
(--target-arch riscv64 to the builders: emulated mock rebuilds for the C
ones, GOARCH cross-compile + rpmbuild --target for goconserver);
- builds grub2-xcat, a noarch packaging, in the native EPEL-free
rocky-10-<host arch> chroot rather than the emulated one;
- does not build the x86 bootloaders (elilo-xcat, syslinux-xcat, xnba-undi)
and does not require them;
- runs mockbuild-perl-packages.pl with --target-arch riscv64,
--noarch-mock-cfg rocky-10-<host arch> and --epel-gap, since riscv64 has
no EPEL to take xCAT's other perl deps from;
- installs mock-configs/<target>.cfg into /etc/mock/ when it is missing there
(mock and the builders' include('/etc/mock/<target>.cfg') overlays need
it); a host copy that differs from the shipped one is an error, never
silently used.
$arch is now the arch of the target being built (set per target), $host_arch
the uname -m one used to pick the default rh8/rh9/rh10 targets; the deploy and
the repo metadata take the arch from the target profile. --scrub-all-chroots
also scrubs the noarch chroot. BUILD.md documents the riscv64 build, what it
produces and the known exclusions (perl-DB_File, perl-SOAP-Lite).
EL10 x86_64/ppc64le take these perl deps of xCAT from EPEL; riscv64 has no EPEL
and Rocky Linux 10 riscv64 BaseOS/AppStream/CRB do not carry them, so xcat-dep
builds them for that arch. Add them to mockbuild-perl-packages.pl's package
table, and a --epel-gap switch that appends them to the build list (the
default list6 build is unchanged):
perl-Crypt-Blowfish EPEL 10 src.rpm (2.14-25.el10_0, vendored now; the spec
in the dir is a SUSE one); its optional tests need
Crypt::CBC, so it 'needs' our perl-Crypt-CBC
perl-Crypt-CBC perl-Crypt-CBC.spec + Crypt-CBC-2.33.tar.gz: the spec
is now the Fedora one of the vendored fc29 src.rpm
(release 21) with the BuildRequires an EL10 buildroot
lacks (make, perl-interpreter); it replaces the SUSE
spec (perl-macros) that could not build on EL (noarch)
perl-Crypt-Rijndael perl-Crypt-Rijndael-1.13-10.fc29.src.rpm
perl-Digest-SHA1 perl-Digest-SHA1-2.13-23.fc28.src.rpm
perl-Expect perl-Expect-1.35-6.fc29.src.rpm (noarch)
perl-Mail-Sender perl-Mail-Sender-0.903-7.fc29.src.rpm (noarch)
perl-Net-DNS Net-DNS.spec + Net-DNS-0.80.tar.gz, now built with
--noxs as noarch (the cpan2rpm spec hard-coded
buildarch x86_64 for the XS dn_expand) and with the
BuildRequires cpan2rpm specs never carry; release 2
perl-Net-IP perl-Net-IP-1.26-30.el10_0.src.rpm (noarch)
perl-Path-Class new dir, EPEL 10 src.rpm (0.37-24.el10_0, noarch): only
a build dep -- Crypt-SSLeay's Makefile.PL needs it --
so perl-Crypt-SSLeay 'needs' it; on x86_64 EPEL still
provides it and nothing changes there
Two EPEL-only deps of xCAT are deliberately not built: perl-SOAP-Lite
(1.27-3.fc29 src.rpm is in the table for completeness, but its BuildRequires
IO::SessionData, MIME::Lite, XML::Parser::Lite and Test::XML are EPEL-only as
well, so it can neither be built nor installed without EPEL; xCAT uses it for
HP blade/VirtualBox support only) and perl-DB_File (needs libdb, which EL10
dropped and Rocky Linux 10 riscv64 does not have at all; only xCAT-server's
Confluent client uses it and xCAT-server merely recommends the package).
The per-package builders take the arch of what they build from 'uname -m', which
is wrong for a forcearch mock config such as rocky-10-riscv64-xcat built on an
x86_64 host: the chroot produces riscv64 rpms and the scripts then reject them
("Unexpected RPM arch"). Give every arch-producing builder a --target-arch
option (default: uname -m, so nothing changes for native builds):
- ipmitool/mockbuild.pl, conserver/mockbuild.pl: look for and verify
<target-arch> rpms. ipmitool's install smoke test cannot install a foreign
rpm on the host, so for a cross build it installs the rpm into the build
chroot with mock --install and runs ipmitool-xcat -V there (conserver already
smoke-tests in the chroot).
- goconserver/mockbuild.pl: the binaries are built on the host, so cross-compile
with GOARCH (x86_64 amd64, aarch64 arm64, riscv64 riscv64, ...) and package
with rpmbuild --target <arch>; rpm refuses 'BuildArch: <foreign arch>' on
this host ("No compatible architectures found for build"), so that line is
only emitted for native builds. A cross build cannot install its rpm on the
host either, so the smoke test unpacks it and runs goconserver and congo
through the binfmt handler (qemu-user-static) the forcearch mock builds of
the other deps need anyway.
- mockbuild-perl-packages.pl: --target-arch for the 'native' rpm check and the
default result/log dirs; the 'native' (XS) packages of a cross build are
smoke-tested inside the build chroot (mock --install, then perl -M<module>
there) instead of on the host; --noarch-mock-cfg to build the noarch
packages in a native chroot of the same release instead of the emulated one
(the rpms are identical for every arch, and an emulated perl build is an
order of magnitude slower); and a 'needs' key in the package table: a
package that needs others is built after them, in waves, with their rpms
installed into its chroot via mock --additional-package. Needs outside the
selected set are ignored, so the default list6 build is unchanged (the
chroot provides the module, e.g. from EPEL). This is what lets an EPEL-free
chroot build perl-Crypt-Blowfish on top of our own perl-Crypt-CBC, or
perl-Crypt-SSLeay with perl-Path-Class.