OpenEmbedded Genesis packages
xCAT builds the Genesis image in xcat-core. This directory turns those build
outputs into packages and feeds them into the xcat-dep repositories.
Run the release builder on a host that can build the OpenEmbedded layer. The
xcat-core checkout must be clean. --xcat-ref checks that the checkout points
to the intended commit; it does not change the checkout for you.
The packaging scripts use File::Slurper and IPC::Cmd. Install
libfile-slurper-perl on Ubuntu. On EL, install perl-File-Slurper and
perl-IPC-Cmd from EPEL and AppStream.
./genesis-openembedded/build \
--xcat-source /path/to/xcat-core \
--xcat-ref <tag-or-commit> \
--all \
--work-dir /path/to/oe-work \
--output-dir /path/to/xcat-genesis-release
The default format is all, which produces RPM, SRPM, and DEB packages. Use
--format rpm or --format deb when only one package family is needed. The
supported image architectures are x86, x86_64, ppc64, ppc64le,
armv7hf, aarch64, and riscv64.
Use --architecture for development builds. Repository publication requires a
complete release built with --all.
Each package installs one exact-architecture export under
/opt/xcat/share/xcat/netboot/genesis-openembedded/<architecture>/. The package
and install namespaces are separate from the old Genesis packages, so both
generations can be published and installed without replacing one another. The
packages are noarch or all because they are installed on the management
node, not run on the target node.
--work-dir keeps the OpenEmbedded downloads and build state between release
builds. Without it, the builder uses a temporary directory and removes it when
the command finishes.
The release directory contains:
rpm/,srpm/, anddeb/package directoriesrelease.manifest, including the xcat-core commitSHA256SUMS
Validate the directory before publishing it:
./genesis-openembedded/verify-release --complete /path/to/xcat-genesis-release
The checksum file detects incomplete or changed output. It does not authenticate the release, so only accept a directory produced by a trusted build host.
verify-release also checks the identity of each package, including a fixed
build host and a build time taken from the source epoch. Those are reproduced
by rpm 4.14.3, 4.16.1.3, 4.19.1.1, and 6.0.2. An EL8 or later builder, or a
current Fedora builder, produces a release the verifier accepts.
Pass that same directory to the repository builders:
perl ./mockbuild-all.pl \
--genesis-release /path/to/xcat-genesis-release \
[other build options]
./build-apt-repo.sh \
--genesis-release /path/to/xcat-genesis-release
The RPM builder publishes the binary packages once under xcat-dep/common.
The per-EL repositories keep the old Genesis packages and contain no copies of
the OpenEmbedded packages. Source RPMs stay in the verified release directory.
The publisher locks the shared repository and replaces common only after the
new package set, metadata, signatures, and local setup files are ready.
The APT builder publishes the DEBs once under
pool/main/xcat-genesis-openembedded. Every suite indexes those same files.
Genesis publication updates all suites together, so do not pass a DIST
argument with --genesis-release. The input directories for every configured
suite must already exist. Later suite rebuilds keep using the shared pool. Pass
a new release only when replacing the Genesis packages.
APT metadata is generated in a temporary tree. New packages are copied into
place before the metadata directories are replaced, and old packages are
removed only after the new metadata is active. Rebuilt packages may keep the
same filename; the previous files, signing key, and indexes are restored if
publication fails. Use --force-unlock after an interrupted publisher to
recover its saved repository and remove abandoned staging files.
Both consumers require all seven architectures and verify package identities and checksums before publication. A management node can install an image for a different target architecture.
Without --genesis-release, both builders keep their existing behavior. The
new packages do not provide, replace, or obsolete the old package names.
xcat-core selects the OpenEmbedded install namespace when an image package is
present and falls back to the old Genesis image otherwise. Package installation
or update runs mknb for that package's architecture on nodes with local TFTP
storage. With site.sharedtftp=0, update service nodes before the management
node so they can serve the exact architecture name immediately. Removing an
image package retires its published files and rebuilds any legacy fallback that
is still installed. Generated images and packages belong in release storage,
not in Git.
The per-target RPM tarballs do not include xcat-dep/common. Mirror that
repository separately, including its metadata, when preparing an offline
installation.
Run the package tests on a Linux builder with RPM, DEB, and repository tools:
prove t/build_utils.t
prove -It/lib t/genesis_openembedded_release.t
sudo -E prove -It/lib t/genesis_openembedded_consumer.t