2
0
mirror of https://github.com/xcat2/xcat-dep.git synced 2026-09-30 14:55:17 +00:00
Commit Graph

1104 Commits

Author SHA1 Message Date
Daniel Hilst e125f6f79f fix(xcat-dep): the riscv64 Net::DNS carries CVE-2026-64193 and CVE-2026-64194
perl-Net-DNS built Net::DNS 1.47 without patches. That release decodes
the EDNS EXTENDED-ERROR text with a string eval (CVE-2026-64193) and
follows compression pointer chains of any depth (CVE-2026-64194).
Net::DNS 1.56 fixes both, and 1.57 also stops an unbounded recursion on
a misplaced TSIG.

Build Net::DNS 1.57. The tarball, the spec, the Buildnote and the
riscv64 manifest pin move together. The build requirements of 1.57 are
the same as those of 1.47.

t/net_dns_rr_types.t decodes a reply with a 200-pointer chain and fails
on 1.47.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-29 08:46:22 -03:00
Daniel Hilst 398f3703f3 test(xcat-dep): capture CVE-2026-64194 in the shipped Net::DNS
perl-Net-DNS builds Net::DNS 1.47. That release decodes a reply whose
owner name is a chain of 200 compression pointers, one recursion per
pointer (CVE-2026-64194). Net::DNS 1.56 stops the chain with "deep
compression recursion".

The test decodes such a reply with the Net::DNS from the shipped tarball
and expects that error. It fails on 1.47.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-29 08:45:03 -03:00
Daniel Hilst 14b97879c6 Merge master into fix/riscv64-net-dns-key-record
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-28 13:15:45 -03:00
Daniel Hilst 4bb240a502 Merge pull request #75 from VersatusHPC/fix/repo-lock-force-unlock-race
fix(xcat-dep): per-arch dep builds share one repository lock
2026-09-28 13:05:17 -03:00
Daniel Hilst 38301490fa fix(xcat-dep): print the lock log line without changing autoflush
_log set $| on the caller's selected handle for each line. The caller
owns its buffering, so the lock log only prints the line.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-28 11:39:21 -03:00
Daniel Hilst f9b9f1ac46 feat(xcat-dep): log each NFS lock event to the build log
A build log did not show when a lock was taken, waited on, taken over
or released, so the lock order of the parallel dep builds could not be
read from their logs.

XCAT::NFSLock now prints one line per event to the selected output
handle, with the UTC time in milliseconds, the host, the pid, the event,
the label and the lock path. The events are acquired, took-over, wait,
released and release-skipped. quiet => 1 turns the log off for a lock.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-28 11:38:30 -03:00
Daniel Hilst 8823065ed9 fix(xcat-dep): publish and finalize take locks of cells they do not own
The apt publish took only the run lock of the host arch, and then read
the staging of every expected arch. A ppc64el run could refill its
staging while the publish assembled from it.

Finalize ran on one host and took the cell locks of both arches. If it
died, only that host could reclaim the locks of the other arch's cells,
and the next builds of those cells waited on them and failed.

A publish now takes the run lock of every expected arch, in name order,
before the publish lock, and waits for them up to --publish-lock-wait.
--finalize-arch limits finalize to the cells of one arch: it writes,
locks, re-indexes and verifies only those, and reads the other arches.
Without the option, finalize writes both arches as before.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-28 11:33:20 -03:00
Daniel Hilst 56631f8f36 test(xcat-dep): publish and finalize take locks of cells they do not own
The apt publish reads staging/<codename>/<arch> of every expected arch,
but takes only the run lock of the host arch. A ppc64el run can refill
its staging while the publish assembles from it.

Finalize runs on one host and takes the cell locks of both arches. If it
dies, only that host can reclaim the locks of the other arch's cells,
and the builds that own those cells wait on them and fail.

These tests fail until the fix: the publish must refuse while any
expected arch holds its run lock, and finalize --finalize-arch must
write and lock only the cells of that arch.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-28 11:28:47 -03:00
Daniel Hilst f23a4e8786 fix(xcat-dep): lock takeover relies on rename and on lock.break
XCAT::NFSLock recovered a dead owner's lock under a second lock,
lock.break. A process that died after it created lock.break left it in
place, and every later acquire timed out even when both processes were
dead. The lock and its record were also put in place with rename, which
replaces an empty directory, so acquire took over a lock.d that had no
owner record.

The lock now follows the NFS lock protocol at the top of NFSLock.pm. It
uses mkdir, rmdir, unlink and plain writes, and no rename. lock.d/metadata
holds the owner identity and a hash, and invalid metadata only causes a
retry. Takeover and release both hold lock.borrow, beside lock.d. Only a
process on the owner's machine takes over a lock, after it reads the
same identity twice and proves that owner dead. acquire retries R times
with a wait of T +/- jitter, and --try-unlock-timeout maps to R.

Records written by the previous format are invalid metadata and are not
taken over. A process that dies while it holds lock.borrow still blocks
the lock. The protocol assumes that this does not happen.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-28 10:06:35 -03:00
Daniel Hilst bd7312690d Merge master into fix/repo-lock-force-unlock-race
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-28 08:41:19 -03:00
Vinícius Ferrão 1d071b75aa Merge pull request #78 from VersatusHPC/feat/ipxeboot
feat(ipxe-xcat): package the upstream iPXE release binaries
2026-09-27 18:27:17 -03:00
Vinícius Ferrão a35bb1037b test(ipxe-xcat): check the payload with the shims in place
payload.sha256 differs from the bare release tree in the two shims, and
matches the tree once the committed ipxe/shim shims replace them, as the
builders install them. SHA256SUMS covers the shims with the archives.
2026-09-27 12:01:46 -03:00
Vinícius Ferrão 9d944ee3c7 build(ipxe-xcat): install the shims signed by both UEFI CAs
The rpm and the deb install ipxe-shimx64.efi and ipxe-shimaa64.efi over
x86_64-sb/shimx64.efi and arm64-sb/shimaa64.efi of the release tree, so
firmware that trusts only the Microsoft UEFI CA 2023 loads the shim
with Secure Boot on. The ipxe-shim.efi and snponly-shim.efi links keep
their targets, and every other file of the tree is unchanged.
payload.sha256 lists the digests of the new shims, which both builders
check. The README says how to update them.
2026-09-27 12:01:19 -03:00
Vinícius Ferrão 0ff70ab9a6 test(ipxe-xcat): stop comparing the payload with the bare release tree
The next commit installs the ipxe/shim 16.1 shims over the shims of the
release tree, so payload.sha256 no longer describes the bare tree. The
commit after it checks the tree with the shims in place.
2026-09-27 12:01:19 -03:00
Vinícius Ferrão 4b5e9d1e51 build(ipxe-xcat): add the ipxe/shim 16.1 shims signed by both UEFI CAs
The shims in the iPXE v2.0.0 release tree carry only the Microsoft UEFI
CA 2011 signature, so firmware that trusts only the UEFI CA 2023 refuses
them with Secure Boot on. ipxe-shimx64.efi and ipxe-shimaa64.efi are the
ipxe/shim ipxe-16.1 release assets that ipxe replaced on 2026-05-27 with
a build signed by both CAs. SHA256SUMS holds the digests that GitHub
publishes for them.
2026-09-27 11:59:36 -03:00
Daniel Hilst 429c573626 fix(xcat-dep): per-arch dep builds share one repository lock
The per-arch runs of one dep build share --repo-dep and each took
<repo-dep>/.lock. The first run won and the others died, so the
pipeline passed --force-unlock. That option removed any lock it found:
a rerun of the same refs could take a cell from a run still writing it,
and common recovery could remove the staging tree of a live publisher.

mockbuild-all.pl now takes XCAT::NFSLock locks: <output>/.lock, one
<repo-dep>/rh<N>/.<arch>.lock per target, and .common-publish.lock while
it recovers or publishes common. --finalize-xcat-dep locks the cells it
rewrites. --try-unlock-timeout N replaces --force-unlock. A run that is
not a dry run recovers an interrupted common publication when no other
run holds the common lock.

sbuild-all.pl takes its per-arch run lock and its apt publish lock as
XCAT::NFSLock locks instead of flock, which fails on the shared tree.

createrepo_c runs without --database. SQLite needs locks, which a client
of an NFS re-export cannot take.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-26 08:39:49 -03:00
Daniel Hilst e2bc5493de feat(xcat-dep): add XCAT::NFSLock, a lock for the shared NFS tree
The dep builds lock trees on a shared NFS tree that the hypervisors
re-export. The kernel refuses flock and fcntl locks to clients of a
re-export, so every such lock fails with errno 524.

XCAT::NFSLock builds a lock as a directory under a private name, with an
owner record and the caller's metadata, and renames it into place. The
record holds the machine id, boot id, pid, process start time and a
random token. The owner removes the lock, or a process on the owner's
host that proves the owner dead: another boot, no such pid, or a pid
with another start time. That process takes a breaker lock and proves
the owner dead again before it removes the lock. Removal renames the
lock away first. Any other acquire waits up to a timeout, retrying every
3 s by default, then fails with the mv command that moves the lock away.
A lock left by mockbuild-all.pl before this module is taken when its
pid is gone on this host.

t/nfslock.t covers each rule without NFS.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-26 08:39:49 -03:00
Vinícius Ferrão b92423c9c0 docs(BUILD): list ipxe-xcat with the x86 boot loaders
Name the ipxe-xcat builder and add ipxe-xcat where the EL and Debian
sections list the noarch x86 boot loaders.
2026-09-25 13:15:50 -03:00
Vinícius Ferrão 35ffbd5c21 test(xcat-dep): expect ipxe-xcat with the x86 boot loaders
Require ipxe-xcat in every EL target that lists xnba-undi, at the same pin
on riscv64 as on ppc64le, and on every Debian target. Hold its Debian pin
to its changelog, and check that its control file keeps it an
Architecture: all package built on amd64 only.
2026-09-25 13:15:50 -03:00
Vinícius Ferrão 99c4120161 build(xcat-dep): build and publish ipxe-xcat with the x86 boot loaders
mockbuild-all.pl builds ipxe-xcat in every EL profile, riscv64 included,
in the noarch chroot like the other x86 loaders. sbuild-all.pl maps it to
its builder and builds it once on amd64, as an Architecture: all package.

Both manifests list ipxe-xcat wherever they list xnba-undi, so the
repository gate requires it in every EL and Debian repository that
carries the x86 boot loaders. A riscv64 or ppc64le management node serves
those loaders to the x86 nodes of a mixed cluster.
2026-09-25 13:15:50 -03:00
Vinícius Ferrão 9de804526c build(ci): check and test the ipxe-xcat package
Compile the ipxe-xcat builders and payload check, parse the spec, run
perlcritic on the new scripts and test, and run the payload test.
2026-09-25 13:15:50 -03:00
Vinícius Ferrão 6d37819cec test(ipxe-xcat): cover the payload check
Damage a copy of a fixture tree one way at a time: a changed byte, a
missing file, an extra file or directory, a symlink with another target,
and a symlink replaced by a copy of its target. Each must fail the check
and name the path. Also hold the committed payload.sha256 and SHA256SUMS
to the committed archives.
2026-09-25 13:15:50 -03:00
Vinícius Ferrão c56e943dc3 build(ipxe-xcat): package the upstream binaries for EL and Debian
ipxe-xcat installs the release tree under /tftpboot/xcat/ipxe as it
is, with its relative symlinks, and installs the source archive and the
licence texts with the documentation. It is a noarch RPM and an
Architecture: all deb.

Both builders check the archives against SHA256SUMS before the build.
After the build they unpack the RPM or deb and compare its tree with
payload.sha256, entry for entry, before the package reaches the result
directory. The spec and the Debian rules do not strip or compress the
tree, so the signed EFI files keep their signatures.

The package does not obsolete, provide or conflict with xnba-undi.
2026-09-25 13:15:50 -03:00
Vinícius Ferrão 0e8e044fa3 build(ipxe-xcat): add the iPXE v2.0.0 release and source archives
ipxeboot-2.0.0.tar.gz is the ipxeboot.tar.gz asset of the iPXE v2.0.0
release, renamed, with the SHA-256 that the release publishes.
ipxe-2.0.0-source.tar.gz is the source archive of tag v2.0.0 (commit
12798ec). The loaders xCAT uses are GPLv2+ as a whole, so their source
ships with them.

licenses/ holds the iPXE licences from v2.0.0 and the notices of the
signed shim: its COPYRIGHT from ipxe/shim ipxe-16.1, the OpenSSL
1.0.2k licence, and gnu-efi README.efilib at the commit that tag pins.
2026-09-25 13:15:49 -03:00
Daniel Hilst 7aa0ae858f fix(xcat-dep): a bail-out in one test file stops the whole suite
BAIL_OUT stops prove for every test file, not only the one that calls
it. Twelve calls in five test files now use die, which fails only its
own file.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-25 11:40:39 -03:00
Daniel Hilst 2a47e63cdd fix(xcat-dep): riscv64 ships a Net::DNS without the KEY record
Net::DNS 0.80 leaves the KEY record to Net::DNS::SEC, which xcat-dep
does not build. On riscv64, makedns fails when ddns.pm builds its
update key.

perl-Net-DNS now builds 1.47, the release EPEL 10 ships, and the
riscv64 manifest pins it. The spec drops --noxs, which 1.47 rejects,
passes --noonline-tests, and excludes the false perl(OS_CONF) Requires.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-25 11:40:39 -03:00
Daniel Hilst d7acc0b13c test(xcat-dep): capture the missing KEY record in the riscv64 Net::DNS
The ddns plugin builds its update key with Net::DNS::RR->new(... IN KEY
...). The Net::DNS 0.80 that xcat-dep builds for riscv64 has no KEY
record, so the call dies and makedns returns non-zero.

t/net_dns_rr_types.t loads Net::DNS from the shipped tarball and builds
the KEY records that xCAT builds. It also requires the manifest pin to
be an exact version at 1.01 or newer. The package-tests workflow runs
the test.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-25 11:40:39 -03:00
Vinícius Ferrão 0ba9df8dc8 test(xcat-dep): cover the shared mock config resolver
An AlmaLinux host resolves to the alma config file, an id that names its
file resolves to it, the os-release id wins when both files exist, and a
release with no config file is an error that names the files it tried.
2026-09-25 02:25:44 -03:00
Vinícius Ferrão f8f77db1d6 refactor(xcat-dep): share the mock config resolver
mockbuild-all.pl finds the mock config by its file in /etc/mock, and
knows that /etc/os-release says almalinux where mock names the file
alma. Move that resolver into MockBuildUtils, with the config directory
as an optional argument, so a per-package builder can use it. The
behavior of mockbuild-all.pl does not change.
2026-09-25 02:24:42 -03:00
Daniel Hilst 329856a6cd Merge pull request #76 from VersatusHPC/fix/riscv64-goconserver-cross-build
fix(xcat-dep): the riscv64 goconserver build deadlocks running the Go compiler under emulation
2026-09-24 15:26:00 -03:00
Daniel Hilst 8816b1cfba Merge pull request #73 from VersatusHPC/fix/ubuntu-genesis-native-deb
fix(xcat-dep): the Ubuntu Genesis image is converted from the EL rpm
2026-09-24 15:19:31 -03:00
Daniel Hilst 2a4551f05c fix(xcat-dep): the riscv64 goconserver build never finishes
xcat-dep-ubuntu-cd build 83 failed in its riscv64 branch. The goconserver build for
jammy, noble and resolute each ran the full 9000s budget and produced no deb. The stall
report found the Go processes parked in futex_wait, two of the three cells with no CPU
ticks at all during the sample.

riscv64 has no build host, so its chroot runs on the amd64 agent under qemu-user.
goconserver/sbuild.pl installed the Go toolchain for the chroot architecture, so the
compiler itself ran emulated, and `go build` did not return. The EL builder already avoids
this: goconserver/mockbuild.pl cross-compiles for a forcearch target rather than running
the toolchain in the emulated chroot.

sbuild.pl now stamps the build host architecture into the build script and fetches the
toolchain for that architecture, then sets GOARCH to the chroot architecture. A Go
toolchain is statically linked, so the host one runs inside the foreign chroot, and
goconserver is CGO-free, so it cross-compiles. The toolchain also unpacks into the build
tree instead of overwriting /usr/local/go. A native cell is unchanged: host and target
agree, and GOARCH names the architecture it already used.

t/goconserver_cross_build.t covers this and fails without the change: the toolchain was
fetched for riscv64 and `go build` ran with GOARCH unset.

Measured on xcat-master-ub, jammy riscv64: 380s, against a 9000s budget the emulated
build exhausted. The deb carries statically linked RISC-V binaries that run under binfmt.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-15 07:09:48 -03:00
Daniel Hilst 8e2fbbf277 test(goconserver): cover the Go toolchain the Ubuntu build installs
The riscv64 goconserver build never finished. It installs a Go toolchain built FOR the
chroot architecture, so on riscv64 the compiler itself runs under qemu-user: three
xcat-dep-ubuntu-cd cells (jammy, noble, resolute) each burned the full 9000s budget, two
of them with no CPU ticks at all in the stall sample.

Nothing asserted which toolchain the build fetches, or which architecture it compiles for.

This test lifts the build shell out of goconserver/sbuild.pl and runs it with the commands
it calls shadowed, then asserts on what the run asked for: the toolchain tarball must name
the build host, and the real debian/rules must reach `go build` with GOARCH set to the
chroot architecture. The recorders refuse any write outside the scratch tree and report it,
so the build's `rm -rf /usr/local/go` is an assertion here rather than damage to the host.

It fails on the current builder: the toolchain is fetched for riscv64, GOARCH is unset and
two writes escape the build tree.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-15 07:09:48 -03:00
Daniel Hilst f4d453dd46 test(xcat-dep): a bail-out in one test file stops the whole suite
Five files under t/ call BAIL_OUT at eleven places: a missing command, a
manifest section that is not there, an extraction that stopped matching,
a run_bounded that never returned. prove stops every remaining file on a
bail-out, not only the file that called it, so one of these hides the
results of every test that would have run after it. die is just as loud
and costs only its own file.

The header of genesis_native_deb.t also retold how an EL image reached an
Ubuntu node. The fallback and its effect are one sentence.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-14 08:38:12 -03:00
Daniel Hilst eae2147a8c fix(xcat-dep): the Ubuntu Genesis image is converted from the EL rpm
convert_genesis_rpm extracted xCAT-genesis-base-<arch>.noarch.rpm with rpm2cpio
and repackaged it as a deb. That rpm carries an EL kernel and EL kernel modules,
so every Ubuntu management node installed an image built for another
distribution. The pipeline took that path on every run, because GENESIS_BASE_RPM
is what it passes.

xcat-core builds the deb natively now, one per Ubuntu codename. Drop
--genesis-rpm, --genesis-rpm-ppc, --require-ppc-genesis, convert_genesis_rpm,
maintained_genesis_control and genesis_deb_control, and --xcat-source with them:
the maintained control and the maintainer scripts come from the real
dpkg-buildpackage now, not from a hand-assembled DEBIAN/control.

The images differ per release, so build_genesis stages each one into the suite it
was built for. genesis_debs_for_codename reads the codename back from the deb
version, and a run that publishes a codename with no image for it stops instead
of serving another release's image.

genesis_native_deb.t fails without this change.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-12 08:50:48 -03:00
Daniel Hilst b38df7e63e test(xcat-dep): the Ubuntu Genesis image is converted from the EL rpm
sbuild-all.pl gets its Genesis deb one of two ways. --genesis-deb ingests a
native deb. --genesis-rpm and --genesis-rpm-ppc convert the EL rpm with rpm2cpio,
and that is the path the pipeline takes, so an Ubuntu management node installs an
image built from an EL kernel.

xcat-core now builds one Genesis deb per Ubuntu codename, each carrying that
release's kernel, with the codename in the version. build_genesis stages every
Genesis deb it holds into every suite, so three images would land in each one and
apt would serve the newest, which belongs to another release.

genesis_native_deb.t asserts the deb each suite takes, and that the three rpm
options are gone. It fails on this commit.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-12 08:47:57 -03:00
Daniel Hilst fc5c6d0375 Merge pull request #71 from VersatusHPC/fix/mockbuild-skip-perl-gate
fix(mockbuild-all): keep the published rpms of a skipped builder
2026-09-11 19:20:49 -03:00
Daniel Hilst 9fcfa467f6 Merge pull request #69 from VersatusHPC/fix/riscv64-perl-html-form
Pin perl-HTML-Form in the riscv64 dependency cell
2026-09-11 19:19:46 -03:00
Daniel Hilst 5ebc570288 Merge branch 'master' of xcat2/xcat-dep into fix/riscv64-perl-html-form
master added the common repository gate to the workflow and rewrote the
riscv64 comment of packages-manifest.conf after this branch started.

The workflow keeps both new prove lines. The two tests are unrelated.

The riscv64 comment takes master's text. This branch said the x86 boot
components are not built for riscv64; master then listed elilo-xcat,
syslinux-xcat and xnba-undi in the cell, because a riscv64 management
node serves the x86 nodes of a mixed cluster, so the branch sentence is
no longer true. The last line keeps this branch's statement: the perl
set is the EL10 one plus perl-HTML-Form. The pin itself merged without
a conflict, and t/riscv64_perl_cell.t passes on the merged cell.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-11 19:15:33 -03:00
Daniel Hilst 1d95b31285 Merge branch 'master' of xcat2/xcat-dep into fix/mockbuild-skip-perl-gate
master added the per-cell architecture rule (rpm_arch, rpm_in_cell) after
this branch started, so the two sides collide in three places.

The MockBuildUtils and t/mockbuild-all.t import lists take both sets of
names. Neither side removes a name the other needs.

MockBuildUtils.pm now held two definitions of rpm_arch, one from each
side, and Perl kept the later one. master's definition stands: it reads
the header of a file and falls back to the name suffix otherwise, which
is what its own tests and rpm_in_cell need. The branch definition is
removed. carry_over_rpms takes rpm_arch as an argument, so it keeps its
own architecture gate and its own message.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-11 19:13:42 -03:00
Daniel Hilst 201a6b1a6d Merge pull request #70 from VersatusHPC/fix/riscv64-deb-loaders
fix(xcat-dep): carry the x86 boot loaders in the riscv64 repositories
2026-09-11 18:57:58 -03:00
Daniel Hilst acb7311d0b Merge pull request #68 from VersatusHPC/feat/genesis-s390x
feat(genesis): package s390x images
2026-09-11 18:52:19 -03:00
Vinícius Ferrão b4578999f6 build(ci): run the mockbuild-all unit tests
t/mockbuild-all.t covers the manifest gate and the skip-run carry-over and
was not in the package test job. Its rpm fixtures skip where rpmbuild is
absent.

Signed-off-by: Vinícius Ferrão <2031761+viniciusferrao@users.noreply.github.com>
2026-09-10 01:12:20 -03:00
Vinícius Ferrão 25388ecdc2 docs(BUILD): skip runs keep the published rpms they did not build
Signed-off-by: Vinícius Ferrão <2031761+viniciusferrao@users.noreply.github.com>
2026-09-10 01:12:20 -03:00
Vinícius Ferrão 5ee949cc9a test(mockbuild-all): cover the skipped package carry-over
skipped_builder must place a source package with the builder required_pkgs
would skip and never claim the OpenEmbedded Genesis. carry_over_rpms must
keep every binary rpm of a skipped build whose source package the target
manifest still names, leave out whole any build the run already carries a
member of, and
die on an unreadable header, an unsigned or foreign-architecture member of
a selected build, or a package published at two versions. Paths with
spaces are covered. Both fail to import against the previous module.

Signed-off-by: Vinícius Ferrão <2031761+viniciusferrao@users.noreply.github.com>
2026-09-10 01:12:20 -03:00
Vinícius Ferrão 81205a1c81 fix(mockbuild-all): keep the published rpms of a skipped builder
Each run collects the rpms it built into its run repository, and deploy
stages the cell from that repository and gates it on the whole manifest,
which a skip run cannot satisfy: with --skip-perl there are no perl
packages, the gate reports them missing, and the deploy fails after the
build succeeded. The gate is right to check the whole manifest, since the
flags describe what this invocation built and not what the cell may lack.

After collection, the run repository now takes the binary rpms a skipped
builder published in the cell: whole builds, so subpackages the manifest
does not name stay too; only builds whose source package the target
manifest still names, so a dropped package is not republished; and only
builds of which the run carries no member yet, so generations of one build
never mix. The bump check, createrepo, the tarball and the deploy gate
then see the same complete set. The carry-over stops the run rather than
publish a partial or doubtful set: an rpm in the cell whose header cannot
be read, apart from the OpenEmbedded Genesis family that is pruned by
name, a member of a selected build the signing key did not sign, by signer
id and by rpmkeys --checksig, or whose digests do not verify when no key
is configured, a member of another architecture than the cell or noarch,
or a package published at more than one version. A package that was never
published is still reported missing, and a full run is unchanged. The
zero-artifact check applies only when a builder ran, so a run that skips
both package builders reaches the deploy.

Signed-off-by: Vinícius Ferrão <2031761+viniciusferrao@users.noreply.github.com>
2026-09-10 01:12:20 -03:00
Vinícius Ferrão 86a2aac183 refactor(mockbuild-all): split the rpmkeys keyring setup from the per-rpm check
verify_rpms_checksig built the isolated keyring and ran rpmkeys on every
rpm in one body. The keyring setup and the per-rpm verdict are now their
own helpers, so another caller can verify a single rpm against the signing
key. The gate behaves as before.

Signed-off-by: Vinícius Ferrão <2031761+viniciusferrao@users.noreply.github.com>
2026-09-09 23:42:47 -03:00
Vinícius Ferrão fbf7a5be2a docs(BUILD): riscv64 repositories carry the x86 boot loaders 2026-09-08 17:19:41 -03:00
Vinícius Ferrão a7c122b113 fix(mockbuild-all): scrub the chroot a noarch step built in
A noarch builder of a forcearch target runs in the native chroot of the
release, but its cleanup step was registered against the target
configuration. The step scrubbed a chroot that did not exist and left the
native bootstrap behind on every run, one per noarch step.

Compute the configuration once per step and scrub the same one it built in.
2026-09-08 17:19:40 -03:00
Vinícius Ferrão a17df594c9 test(mockbuild-all): cover the per-cell rpm architecture rule 2026-09-08 17:19:40 -03:00