From efb3143609db2c4cdc2380d8751a8864658a117d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vin=C3=ADcius=20Ferr=C3=A3o?= <2031761+viniciusferrao@users.noreply.github.com> Date: Mon, 14 Sep 2026 23:46:00 -0300 Subject: [PATCH] feat(openeuler): enforce native postscript repository policy Use signed, available DNF repositories for openEuler package postscripts. Scope normal transactions to generated repositories. Preserve explicit keeprepo behavior. Fail unresolved native packages before direct RPM fallback. --- xCAT/postscripts/ospkgs | 15 +++++++++-- xCAT/postscripts/otherpkgs | 46 +++++++++++++++++++++++--------- xCAT/postscripts/xcatpkgutils.sh | 23 ++++++++++++++++ 3 files changed, 70 insertions(+), 14 deletions(-) diff --git a/xCAT/postscripts/ospkgs b/xCAT/postscripts/ospkgs index 712be9738..a9c411fde 100755 --- a/xCAT/postscripts/ospkgs +++ b/xCAT/postscripts/ospkgs @@ -896,6 +896,13 @@ else echo "Please install yum or dnf on $NODE." exit 1; fi + if pmatch "$OSVER" "openeuler*"; then + if [ "$yumcmd" != dnf ]; then + echo "ospkgs: openEuler package installation requires dnf" >&2 + exit 1 + fi + yumcmd=xcat_dnf_strict + fi if [ $keeprepo -ne 1 ]; then #remove old repo files @@ -926,12 +933,16 @@ else echo "baseurl=file://$OSPKGDIR" >> $REPOFILE fi echo "enabled=1" >> $REPOFILE - echo "gpgcheck=0" >> $REPOFILE - echo "skip_if_unavailable=True" >> $REPOFILE + xcat_rpm_repository_policy "$OSVER" >> "$REPOFILE" fi i=$((i+1)) done + if pmatch "$OSVER" "openeuler*" && [ "$keeprepo" -ne 1 ]; then + xcat_dnf_repositories="xCAT-$OSVER-path*" + yumcmd=xcat_dnf_scoped + fi + #import the release key? #my $key = "$installDIR/$os/$arch/RPM-GPG-KEY-redhat-release"; #my $tmp = "/tmp/RPM-GPG-KEY-redhat-release"; diff --git a/xCAT/postscripts/otherpkgs b/xCAT/postscripts/otherpkgs index f252fc393..f8f1c0e27 100755 --- a/xCAT/postscripts/otherpkgs +++ b/xCAT/postscripts/otherpkgs @@ -261,8 +261,8 @@ if [ -z "$UPDATENODE" ] || [ $UPDATENODE -ne 1 ]; then fi fi -if ! pmatch $OSVER "rhel*" && [ "$repoonly" -eq 1 ]; then - echo "$0: the option \"repoonly\" only support rhel right now" +if ! pmatch "$OSVER" "rhel*" && ! pmatch "$OSVER" "openeuler*" && [ "$repoonly" -eq 1 ]; then + echo "$0: the option \"repoonly\" only supports rhel and openEuler" exit 0 fi @@ -270,6 +270,9 @@ if [ -z "$OTHERPKGS_INDEX" ] && [ "$repoonly" -ne 1 ]; then echo "$(basename $0): no extra rpms to install" exit 0 fi +if pmatch "$OSVER" "openeuler*" && [ "$repoonly" -eq 1 ]; then + OTHERPKGS_INDEX=${OTHERPKGS_INDEX:-0} +fi if [ -z "$NFSSERVER" ]; then NFSSERVER=$MASTER @@ -505,6 +508,15 @@ fi +if pmatch "$OSVER" "openeuler*"; then + if [ "$yumcmd" != dnf ]; then + echo "otherpkgs: openEuler package installation requires dnf" >&2 + exit 1 + fi + yumcmd=xcat_dnf_strict +fi +cleancmd=$yumcmd + ########### ##start generating the os pkg repositories if ( ! ( pmatch "$OSVER" "sles10*" ) && [ $haszypper -eq 1 ] ); then @@ -589,7 +601,7 @@ if ( ! ( pmatch "$OSVER" "sles10*" ) && [ $haszypper -eq 1 ] ); then result=`zypper --non-interactive --no-gpg-checks refresh 2>&1` -elif ( is_el_yum_distro && [ $hasyum -eq 1 ] ); then +elif ( { is_el_yum_distro || pmatch "$OSVER" "openeuler*"; } && [ $hasyum -eq 1 ] ); then #remove old repo files mkdir -p /etc/yum.repos.d if [ `ls -1 /etc/yum.repos.d/local-repository*.repo 2>/dev/null | wc -l` -gt 0 ]; then @@ -599,7 +611,7 @@ elif ( is_el_yum_distro && [ $hasyum -eq 1 ] ); then result=`rm /etc/yum.repos.d/xCAT-$OSVER-path*.repo 2>&1` result=`rm /etc/yum.repos.d/xCAT-otherpkgs*.repo 2>&1` - result=`$yumcmd clean all` + result=`$cleancmd clean all` SUM=$(array_get_size os_path) i=0 @@ -618,8 +630,7 @@ elif ( is_el_yum_distro && [ $hasyum -eq 1 ] ); then echo "baseurl=file://$OSPKGDIR" >> $REPOFILE fi echo "enabled=1" >> $REPOFILE - echo "gpgcheck=0" >> $REPOFILE - echo "skip_if_unavailable=True" >> $REPOFILE + xcat_rpm_repository_policy "$OSVER" >> "$REPOFILE" fi i=$((i+1)) done @@ -628,6 +639,11 @@ fi ##end generating the os pkg repositories ########### +if pmatch "$OSVER" "openeuler*"; then + xcat_dnf_repositories="xCAT-$OSVER-path*,xcat-otherpkgs*" + yumcmd=xcat_dnf_scoped +fi + ########### @@ -645,7 +661,7 @@ while [ $op_index -le $OTHERPKGS_INDEX ]; do if [ $hasyum -eq 1 ]; then mkdir -p /etc/yum.repos.d result=`rm /etc/yum.repos.d/xCAT-otherpkgs*.repo 2>&1` - result=`$yumcmd clean all` + result=`$cleancmd clean all` repo_base="/etc/yum.repos.d" elif [ $haszypper -eq 1 ]; then #remove old repo @@ -683,8 +699,7 @@ while [ $op_index -le $OTHERPKGS_INDEX ]; do echo "name=xcat-otherpkgs$urlrepoindex" >> $REPOFILE echo "baseurl=$url" >> $REPOFILE echo "enabled=1" >> $REPOFILE - echo "gpgcheck=0" >> $REPOFILE - echo "skip_if_unavailable=True" >> $REPOFILE + xcat_rpm_repository_policy "$OSVER" "${url%/}/repodata/repomd.xml.key" >> "$REPOFILE" elif [ $hasapt -eq 1 ] ; then REPOFILE="$repo_base/xCAT-otherpkgs${urlrepoindex}.list" @@ -788,10 +803,13 @@ while [ $op_index -le $OTHERPKGS_INDEX ]; do echo "baseurl=file://$whole_path" >> $REPOFILE fi echo "enabled=1" >> $REPOFILE - echo "gpgcheck=0" >> $REPOFILE - echo "skip_if_unavailable=True" >> $REPOFILE + if [ $mounted -eq 0 ]; then + xcat_rpm_repository_policy "$OSVER" "http://$whole_path/repodata/repomd.xml.key" >> "$REPOFILE" + else + xcat_rpm_repository_policy "$OSVER" "file://$whole_path/repodata/repomd.xml.key" >> "$REPOFILE" + fi if [ $hasyum -eq 1 ]; then - $yumcmd clean all + $cleancmd clean all fi if [ $haszypper -eq 1 ]; then result=`zypper --non-interactive refresh 2>&1` @@ -859,6 +877,10 @@ EOF` if [ $rc -eq 0 ]; then repo_pkgs="$repo_pkgs $fn" else + if pmatch "$OSVER" "openeuler*"; then + echo "otherpkgs: required native package $fn could not be resolved: $result" >&2 + exit 1 + fi #now no hope we have to use rpm command plain_pkgs="$plain_pkgs $x*" fi diff --git a/xCAT/postscripts/xcatpkgutils.sh b/xCAT/postscripts/xcatpkgutils.sh index 766f98ac7..c20734916 100755 --- a/xCAT/postscripts/xcatpkgutils.sh +++ b/xCAT/postscripts/xcatpkgutils.sh @@ -30,5 +30,28 @@ xcat_is_el_modular_pkgdir() return 1 } +xcat_rpm_repository_policy() +{ + case "$1" in + openeuler*) + printf '%s\n' 'gpgcheck=1' 'skip_if_unavailable=False' + printf 'gpgkey=%s\n' "${2:-file:///etc/pki/rpm-gpg/RPM-GPG-KEY-openEuler}" + ;; + *) + printf '%s\n' 'gpgcheck=0' 'skip_if_unavailable=True' + ;; + esac +} + +xcat_dnf_strict() +{ + dnf --setopt=strict=1 '--setopt=*.skip_if_unavailable=False' '--setopt=*.gpgcheck=1' "$@" +} + +xcat_dnf_scoped() +{ + xcat_dnf_strict '--disablerepo=*' "--enablerepo=$xcat_dnf_repositories" "$@" +} + # shellcheck disable=SC2034 XCATPKGUTILS_LOADED=1