xCAT-test/debian/install did not list lib/xCAT/Test/OS.pm, so the
Debian package shipped xcattest without the module it loads, and
xcattest stopped at startup with "Can't locate xCAT/Test/OS.pm in @INC".
Install the module to opt/xcat/lib/perl/xCAT/Test, as the RPM spec does.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
xcattest loads xCAT::Test::OS from /opt/xcat/lib/perl. xCAT-test.spec
installs it, but xCAT-test/debian/install does not, so xcattest on an
Ubuntu management node dies at startup with "Can't locate
xCAT/Test/OS.pm in @INC".
Check that the RPM spec and the Debian install list both ship every
module under xCAT-test/lib/xCAT. The Debian check fails.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
xcattest reports "Test case <name> has an invalid OS option - Linux" and then
"There is no valid case to run", so every case is skipped on openEuler.
Recorded on an openEuler 24.03 LTS SP4 management node with xCAT 2.20.0: both
flat provisioning cases were rejected and the run measured nothing.
Two causes, both in the os: comparison in xCAT-test/xcattest. get_current_os
takes the /etc/os-release branch, finds no sles, and falls off the end of that
branch, so it returns the exit status of the failed grep, 256, which names no
distribution. And a case marked os:Linux expands to exactly rhels, sles and
ubuntu, so openEuler would be rejected even by a correct get_current_os.
Both halves move into xCAT::Test::OS. xcattest finds it beside itself and the
package installs it at <prefix>/lib/perl. current_os takes a path prefix, so a
test describes a system by writing release files into a scratch tree. openEuler
is named in both halves and nothing else changes.
xCAT-test/unit/xcattest_os_selection.t covers it. Removing openeuler from
linux_aliases fails two checks, and removing the openEuler branch from
current_os fails three. A further case gives a root both /etc/redhat-release
and an openEuler /etc/os-release and asserts rhels10, so the precedence is
named: openEuler ships neither that file nor /etc/lsb-release.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
wget asks for the root image as //install/..., so the leading slash repeats.
The path filter matched a single leading slash and did not count those
requests. A service node that served only the root image would therefore read
as having served no boot payload.
The filter now accepts a repeated leading slash. The bats cases come from
fix/service-node-ub, where a real Ubuntu service node logged one //install
request beside 272 /install and 8 /tftpboot ones. Both new cases fail with the
single-slash filter.
This brings the file level with fix/service-node-ub, so the two branches no
longer carry different versions of the same check.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
fix/service-node-el fixed the management-node guard as commit 0f708b96a, with the same
correction this branch made: the log must hold lines, not gain them. The two differ
only in the comment and in the error message, so the file no longer merges as one
change.
The wording here now matches fix/service-node-el. The remaining difference in this file
is the doubled-slash path filter, which that branch does not carry.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
local_logs added XCAT_HTTPD_ACCESS_LOG to the list of candidate logs and then
read the system paths as well. On a build host that runs apache, the check
counted the host's own /var/log/apache2/access.log beside the file the test
pointed at, so a test could not control what it measured. The empty-log case
read 64 lines it did not write.
An explicit XCAT_HTTPD_ACCESS_LOG now replaces the search instead of extending
it. Production behaviour is unchanged: nothing sets that variable there.
Without this change the bats case for an empty management-node log fails on a
host that serves apache, and passes on one that does not.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
(cherry picked from commit bcb4a77f1a)
check_provisioning_source.sh --baseline wrote one message for two conditions:
"no access log to baseline on ${MN_BASE:+$SN}${MN_BASE:-$MN}". When the management
node has a log and the service node does not, the second expansion returns the
management node's baseline spec, not a host name. On xcat42 the message read "no
access log to baseline on nosuchnode-xyz/var/log/httpd/access_log:881". That is the
message an operator reads when xdsh cannot reach the service node, so it has to name
the host that has no log.
Each condition now has its own test and its own message.
check_provisioning_source.bats covers the service-node condition. The case also
asserts the management node's log path is absent from the message, because the node
name alone matches the old text as a substring.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
(cherry picked from commit 89ac4558a0)
local_logs added XCAT_HTTPD_ACCESS_LOG to the list of candidate logs and then
read the system paths as well. On a build host that runs apache, the check
counted the host's own /var/log/apache2/access.log beside the file the test
pointed at, so a test could not control what it measured. The empty-log case
read 64 lines it did not write.
An explicit XCAT_HTTPD_ACCESS_LOG now replaces the search instead of extending
it. Production behaviour is unchanged: nothing sets that variable there.
Without this change the bats case for an empty management-node log fails on a
host that serves apache, and passes on one that does not.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
check_provisioning_source.sh --baseline wrote one message for two conditions:
"no access log to baseline on ${MN_BASE:+$SN}${MN_BASE:-$MN}". When the management
node has a log and the service node does not, the second expansion returns the
management node's baseline spec, not a host name. On xcat42 the message read "no
access log to baseline on nosuchnode-xyz/var/log/httpd/access_log:881". That is the
message an operator reads when xdsh cannot reach the service node, so it has to name
the host that has no log.
Each condition now has its own test and its own message.
check_provisioning_source.bats covers the service-node condition. The case also
asserts the management node's log path is absent from the message, because the node
name alone matches the old text as a substring.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
check_provisioning_source.sh required the management node's httpd access log to gain
lines after the baseline. The three hierarchy cases take the baseline after
SN_setup_case has provisioned the service node. After that point a correct hierarchical
provision leaves the management node serving nothing, so its log does not grow. On the
xcat42 EL9 cell the service node served the compute node 252 boot-payload requests and
the management node served 0, and the check still reported "no httpd access log with
new entries could be read on xcat42-mn-dhilst".
reg_linux_diskless_installation_hierarchy failed for that message.
The guard now requires the log to hold lines, not to hold new ones. An empty log still
fails, because it makes "the management node served nothing" a property of the file
instead of a measurement.
check_provisioning_source.bats asserted the removed behavior in "a management node log
with nothing new fails the check instead of reading as silence". That case now asserts
the opposite, and a second case covers the empty log. Both fail against the unfixed
script.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
On a new Kea management node, makedhcp -n defers DDNS until makedns -n
writes the key. makedhcp -a then applied the D2 settings to the fresh
intents, but saved the loaded configurations, which had no dhcp-ddns.
It also wrote no kea-dhcp-ddns.conf, so DNS updates stayed off.
When DDNS is on and the loaded DHCPv4 configuration has no dhcp-ddns,
makedhcp -a now copies the D2 settings into the loaded DHCPv4 and DHCPv6
configurations, writes the D2 configuration and, when enabled, the
Control Agent configuration. It then enables and restarts the Kea
services.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
On a new Kea management node, makedhcp -n defers DDNS because no key
exists. After makedns -n writes the key, makedhcp -a keeps the DHCPv4
configuration without dhcp-ddns and writes no kea-dhcp-ddns.conf, so
DNS updates stay off.
The test runs makedhcp -n without a key, adds the key, runs
makedhcp -a, and checks the rendered DHCPv4 and D2 configurations.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
enable_repo_commands chose subscription-manager from the vendor id and the presence of the
binary. An unregistered RHEL node has both, so the postscript ran
`subscription-manager repos --enable`, the command failed for want of a registration, and only
the fallback to `dnf config-manager` enabled the builder repository. The log named the
repository, not the registration.
The decision now takes the registration state. registered_with_subscription_manager reads the
exit status and the output of `subscription-manager identity`, which the postscript runs, and
enable_repo_commands emits the subscription-manager command only for a registered node. A
Foreman, Katello or Red Hat Satellite client registers through subscription-manager, so the same
path covers it, and the vendor id no longer decides. uses_subscription_manager is removed with
its caller.
service_node_artifacts_el.t asserts the probe against the registered and the unregistered output
of subscription-manager 1.30.12, against a missing binary, and against a call without root
privilege. It also asserts that an unregistered node runs no subscription-manager command.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
On the Ubuntu 24.04 hierarchy cell the check reported the right counts and then
failed: "xcat22-sn served xcat22-cn 277 boot-payload request(s)", "xcat22-mn-dhilst
served xcat22-cn 0", and then "no httpd access log with new entries could be read on
xcat22-mn-dhilst". The guard required the management node log to gain lines after the
baseline. It does not: the management node provisions the service node in
SN_setup_case, before the baseline the hierarchy case takes, and it is then idle. Its
silence is the result the check exists to find.
The guard now asks that the log hold at least one line, which is what makes a count of
0 mean something, and no longer asks for activity in the measured window.
The path filter also missed a doubled leading slash. The compute node fetches the root
image with wget as //install/netboot/<os>/<arch>/compute/rootimg.cpio.gz, which the
service node logged and the filter did not count.
check_provisioning_source.bats covers both. The four cases added in the commit before
this one fail without this change.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
check_provisioning_source.bats held a case that required the check to FAIL when the
management node logs nothing after the baseline. That is the hierarchical result, not
a broken log: the management node provisions the service node before the baseline and
then serves the compute node nothing. The suite passed 14 of 14 while the check could
not pass on a real cluster.
Two more cases cover the path filter. The compute node fetches the root image with
wget from a URL that carries a double slash, so the path reaches the log as
//install/netboot/..., and the filter matched neither direction: the request counted
as no boot payload on the service node, and a flat provision that served it went
unreported.
All four cases fail against the current script.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
check_provisioning_source.sh counted every request the compute node had ever
made, for any path. Both directions were wrong. A flat run left
management-node requests for the same address, so a later hierarchical run
read them as its own and failed. A service-node entry from an earlier run, or
a 404 for /favicon.ico, satisfied the positive check without any boot payload
being served.
The script now takes a baseline. --baseline records how many lines each access
log holds on the management node and on the service node, before provisioning,
and the check counts only lines after that point. It counts only requests
under /install or /tftpboot, which are the trees httpd serves a boot payload
from. A log shorter than its baseline was rotated, so it is read from its
first line. Without a baseline the check refuses to answer instead of reading
the whole log. The three hierarchy cases call --baseline before nodeset.
check_provisioning_source.bats covers both regressions: a management-node
request before the baseline no longer fails the run, a service-node request
before the baseline no longer satisfies it, and a request that carries no boot
payload does neither. Removing the baseline comparison fails the first two.
Removing the path filter fails the other two.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
(cherry picked from commit d6f25640b1)
check_provisioning_source.sh counted every request the compute node had ever
made, for any path. Both directions were wrong. A flat run left
management-node requests for the same address, so a later hierarchical run
read them as its own and failed. A service-node entry from an earlier run, or
a 404 for /favicon.ico, satisfied the positive check without any boot payload
being served.
The script now takes a baseline. --baseline records how many lines each access
log holds on the management node and on the service node, before provisioning,
and the check counts only lines after that point. It counts only requests
under /install or /tftpboot, which are the trees httpd serves a boot payload
from. A log shorter than its baseline was rotated, so it is read from its
first line. Without a baseline the check refuses to answer instead of reading
the whole log. The three hierarchy cases call --baseline before nodeset.
check_provisioning_source.bats covers both regressions: a management-node
request before the baseline no longer fails the run, a service-node request
before the baseline no longer satisfies it, and a request that carries no boot
payload does neither. Removing the baseline comparison fails the first two.
Removing the path filter fails the other two.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
The servicenode postscript enabled the builder repository with dnf
config-manager on every vendor. On RHEL that repository is defined in
/etc/yum.repos.d/redhat.repo, which subscription-manager owns and
regenerates, so the enabled flag does not survive the next refresh. The
builder repository turns off again and dnf install xCATsn stops resolving
perl-IO-Tty, perl-Crypt-CBC, perl-Crypt-Rijndael and perl(Expect).
ELBuilderRepo::enable_repo_commands returns the commands to try in order.
uses_subscription_manager names the vendors whose repository file
subscription-manager owns, beside builder_repo_ids which already names the
repository per vendor. RHEL asks subscription-manager first and keeps
config-manager as the fallback. Every other vendor gets config-manager
alone, which is what it had before.
service_node_artifacts_el.t asserts the command order per vendor. Without
the subscription-manager branch, the order assertion fails and no other
assertion does.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
kea_build_ddns_intent returned the deferral under a deferred key. No other
xCAT code uses that key: dhcp.pm reports through error, warning, node and
data, and makedhcp already passed this message to the callback as a warning.
The intent hash now carries the message under warning, so one name describes
it from the hash to the callback. Behaviour does not change.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
The comment stated the xcatconfig default and then repeated the reason for the
change, which the commit message already carries. Keep the condition only.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
kea_makedhcp_without_ddns_key covers the same decision as
dhcp_kea_ddns_deferral.t, and no suite runs it: the GitHub workflow runs
prove -r xCAT-test/unit, and no CD bundle names the case.
Delta debugging at commit scope dropped it. The unit test still fails on the
unfixed tree, so the defect stays captured.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
makedhcp -n fails on a new management node that uses the Kea backend:
Error: Unable to find DDNS key material for Kea D2. Run makedns with
dnshandler=ddns first.
xcatconfig writes site.dnshandler=ddns on every new installation, so
kea_ddns_enabled reports DDNS on, and kea_build_ddns_intent then requires
/etc/xcat/ddns.key. Only makedns -n writes that file. The ISC backend reads no
key, so an ISC management node runs makedhcp -n without one. The Kea backend
plan states that basic DHCP and PXE support must not depend on DDNS.
kea_build_ddns_intent now reports a deferral instead of an error when it finds
no key material. kea_apply_ddns_intent attaches the D2 connection only when a
key exists, and returns the deferral for makedhcp to print as a warning. A
management node with key material gets the same configuration as before.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
kea_build_ddns_intent returns an error when no DDNS key material exists, and
makedhcp -n reports it instead of configuring Kea. No unit test reads that
decision, so the error path and the D2 path are both unmeasured.
dhcp_kea_ddns_deferral.t drives kea_build_ddns_intent with and without key
material, and drives the sub that attaches the D2 connection to the DHCPv4 and
DHCPv6 configurations. It also holds down the two boundaries the change must
keep: a management node whose site.dnshandler is not ddns asks for no D2
configuration, and an unreadable networks table stays an error.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
makedhcp -n fails on a new management node that uses the Kea backend:
Error: Unable to find DDNS key material for Kea D2. Run makedns with
dnshandler=ddns first.
xcatconfig writes site.dnshandler=ddns on every new installation, so the Kea
backend asks for the DDNS key, and only makedns -n creates it. No case covers
that order.
kea_makedhcp_without_ddns_key removes both places the Kea backend reads the key
from, runs makedhcp -n, and reads the rendered kea-dhcp4.conf. It then restores
the key material and runs makedhcp -n again, so the case also holds down the
configuration that a management node with a key must keep.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
The comments added with the Ubuntu fixes carried the bug report and its
consequences: what a compute node stops at, what named answers to every query
once its working directory is unwritable, and that a failed export does not fail
the service node. The comment rules keep the invariant in the source and put the
symptom and the chain in the commit.
Each is cut to the fact the code cannot show: that the resolv.conf a
systemd-resolved host publishes holds a stub pointing back at this named, that
named must be able to write the directory it drops privileges into, that apt
refuses an unsigned repository, and that re-exporting a mount needs an fsid.
service.subiquity.tmpl keeps its header, which is identical to the sibling
compute template and should stay that way.
No executable line changes.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
The comments added with the EL service node fixes carried the bug report: the
symptom on a named cell, the causal chain down to what the compute node sees,
and a claim that a step cannot fail the node. The comment rules put the symptom
and the chain in the commit and leave the invariant in the source.
Each one is cut to the fact the code cannot show: that EPEL and the builder
repository are both off on a fresh EL install, that exportfs refuses an NFS
mount without an explicit fsid, and that everything below a point in the
postscript runs commands on the node.
No executable line changes. The fast oracle passes.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
After nodepurge removes a Subiquity node, /install/autoinst/<node> is still on
disk with meta-data, user-data and vendor-data in it. user-data carries the root
password hash of a node that no longer exists.
remove_node_config_files removed each path with unlink. unlink cannot remove a
directory, and mkinstall in debian.pm calls mkpath for a Subiquity node, so the
node configuration is a directory there and a plain file on the preseed and
kickstart paths. The routine now removes a directory with rmtree.
nodepurge_autoinst_cleanup.t fails without this change and passes with it.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
nodepurge removes the autoinstall configuration of each node it deletes. The
cleanup loop was inline in the nodepurge sub of profilednodes.pm, which no test
can load, so the loop moves to xCAT::ProfiledNodeUtils->remove_node_config_files
with its behaviour unchanged.
nodepurge_autoinst_cleanup.t drives that routine against a scratch directory. It
fails here: the Subiquity node keeps its directory, and the preseed file and the
.pre and .post scripts are removed.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
Every service node defect in this change set was a generated artifact that was
already wrong before any node booted: a repository file that enabled no builder
repo, a template that resolved to the wrong installer, an exports line that was
never written. The tests that caught them are one file per fix, so each knows
one defect and together they know no defect class. A fix nobody has made yet is
covered by none of them.
service_node_artifacts_el.t renders the artifacts an EL service node needs from
one fixture and asserts each: the builder repository per release and vendor,
including that EL8 is powertools and not crb; the template the service profile
resolves, which must not be a Subiquity one; and the export line for a local
directory and for a re-exported mount, where an absent fsid is what made a
service node export nothing.
A missing module or sub fails rather than skips, and the file reports every gap
instead of dying at the first, because on an unfixed tree this test is the gap
report. Measured: 17 assertions pass on the branch, and the base fails two of
them by name.
It does not cover the boot half -- the lease, the tftp handover, the mount the
installer performs -- so it replaces no end-to-end run. It replaces the 45 to
90 minutes those runs cost in the ROUNDS of a minimization.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
The service node work landed seven tests, one per fix, and running them meant
knowing which are Perl and which are shell and typing two commands with seven
paths. Delta debugging the change set runs that suite once per candidate, so
the alternative was the end-to-end suite at 45 to 90 minutes a round.
quick.sh runs a named set, sending .t files to prove and .bats files to bats,
and with no argument runs the whole fast suite, which is what CI runs. A named
file that the tree does not have is an error rather than a skip: reporting PASS
for a tree containing none of the tests is how a minimization drops the commit
that adds one.
quick-servicenode.txt names this change set's seven, with what each covers and
what none of them covers.
Measured: 2.6 seconds for the seven against 45 to 90 minutes for one end-to-end
cell. The list passes on the full branch and fails on the base with these same
test files, which is what makes it usable as an oracle.
Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>