2
0
mirror of https://github.com/xcat2/xcat-core.git synced 2026-10-01 16:31:41 +00:00
Commit Graph

2216 Commits

Author SHA1 Message Date
Daniel Hilst 056a57f087 Merge branch 'master' into feature/openeuler-lts 2026-09-30 17:50:25 -03:00
Daniel Hilst 31c9f3bd26 Merge pull request #7824 from VersatusHPC/feat/support-matrix-distro-versions
docs(xcat-core): Specify distro vs arch versions in support matrix
2026-09-29 11:50:42 -03:00
Vinícius Ferrão 63cf366b96 Merge master into feature/openeuler-lts 2026-09-29 00:01:05 -03:00
Daniel Hilst 2c7a6f0786 docs(xcat-core): the release table stops at 2.18.0
The release information page lists every release up to 2.18.0. 2.18.2,
2.19.0 and 2.19.1 are published and absent from it, so a reader cannot
tell from the documentation which releases exist, when each one shipped,
or where its notes are.

docs/source/overview/_files/2.19.x.csv is new and holds the 2.19.0 and
2.19.1 rows, xcat2_release.rst gains its section above 2.18.x, and
2.18.x.csv gains the 2.18.2 row. Each date is the date of that release
on GitHub. 2.18.1 has no GitHub release of its own, so it has no row.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-25 18:15:17 -03:00
Daniel Hilst 4fa1f2545a docs(developers): published .repo files name their series
The release checklist said that the published .repo files point at
latest. latest is a link into the newest series, so a file that names
it gives the next series to users of this one as soon as that series
ships. Each file under repos/yum/X.Y/ now names repos/yum/X.Y/, and the
installation check uses the files as published.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-25 18:15:17 -03:00
Daniel Hilst 733bc3219c docs(xcat-core): the documentation title names 2.17.0
Read the Docs takes the version in the title of each page from release
in docs/source/conf.py, which was last set for 2.17.0. Every build
since, 2.18.x and 2.19.0 included, is titled "xCAT 2.17.0
documentation". Set it to 2.20.0, the Version of master.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-25 18:15:17 -03:00
Daniel Hilst ba8233a605 docs(xcat-core): the support matrix omits openEuler
xcat2/xcat-core#7864 adds openEuler 20.03 LTS SP4, 22.03 LTS SP4 and
24.03 LTS SP4 on x86_64, for the management node, service nodes and
stateful and stateless compute nodes. The support matrix does not list
openEuler at all.

Add one row per release, x86_64 only, and say which node roles the
support covers. Widen the Version column to fit the release names.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-25 08:44:02 -03:00
Vinícius Ferrão 463eca19e5 Merge master into feature/openeuler-lts 2026-09-25 01:41:02 -03:00
Daniel Hilst 4ed029ffce Merge pull request #7835 from VersatusHPC/fix/ubuntu-genesis-native-sbuild
fix(xcat-core): the Ubuntu Genesis image is built from the build host kernel
2026-09-24 19:24:23 -03:00
Daniel Hilst b72fd46366 Merge pull request #7851 from VersatusHPC/fix/updatenode-xcatpost-cleanup
fix(xcatdsklspost): updatenode leaves /xcatpost populated when site.cleanupdiskfullxcatpost is set
2026-09-24 10:21:49 -03:00
Vinícius Ferrão e654de5c4a docs(developers): describe branches, backports and the release checklist
The project had no written release process, and the 2.18 and 2.19
releases missed steps: the release table in the documentation, the
docs version, signed tags, and the wiki and website index pages.

A new Releases section describes the branch and version model, the
label and milestone that each pull request needs, and a checklist for
release candidates, publishing, the signed tag, the GitHub release, the
release notes, the website and the announcement. The build hosts, the
signing key and the publish procedure stay in the private repository of
the maintainers.
2026-09-23 18:40:49 -03:00
Vinícius Ferrão 16b6acf620 fix(openeuler): integrate current Genesis and installer changes
Merge current master into the openEuler support branch. Keep native
kernel, DHCP, locale and timezone requirements with the upstream payload
verifier and EL10 package paths. Preserve signed openEuler installation.

Update the native fixtures to check the merged payload contract.
2026-09-22 19:45:05 -03:00
Vinícius Ferrão 880b10216e docs(openeuler): record qualified network settings 2026-09-22 02:51:34 -03:00
Vinícius Ferrão d9d8a0d809 docs(openeuler): finish qualified deployment profiles 2026-09-21 21:36:08 -03:00
Vinícius Ferrão c0c8456ef1 docs(openeuler): define the delivery qualification baseline 2026-09-21 18:46:14 -03:00
Vinícius Ferrão 4f0ef5ef96 docs(openeuler): describe native deployment profiles 2026-09-19 05:45:09 -03:00
Daniel Hilst 646b57c123 Merge master into fix/ubuntu-genesis-native-sbuild
master changed the same three files this branch changes, so the pull request could not
merge. Conflicts and how each was resolved:

xCAT-genesis-builder/builddeb-genesis-base. Both sides teach the build root to cope with
a package whose name moved between releases. master added optional_packages(), which
keeps a package only where apt has a candidate, and called it for util-linux-extra. This
branch added add_first_available(), which takes the first name apt carries and fails when
it carries none, and calls it for bind9-dnsutils/dnsutils and util-linux-extra/util-linux,
plus add_if_available() for tzdata-legacy. The branch covers master's case and two more,
so its helpers are kept and optional_packages() goes with its only caller. Every other
master change to this file, including the DHCP client fix, is preserved.

xCAT-test/unit/genesis_payload_verification.t. master has four assertions this branch does
not: two payloads missing an absolute path. Its version is kept. The branch replaced
plan skip_all with a fail(), because skipping covers nothing when the file under test is
the gate itself, and that change is applied to master's version.

xCAT-test/unit/genesis_ubuntu_build_root.t. master's added assertions drive
optional_packages() directly, which the resolved builder no longer has. This branch's
version matches the implementation that survives, and it already dies rather than skipping
when the builder is missing, so it is kept whole.

prove -j4 -r xCAT-test/unit passes: 212 files, 5892 tests.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-18 07:56:24 -03:00
Daniel Hilst 873ad1d41c fix(xcatdsklspost): updatenode leaves /xcatpost populated when site.cleanupdiskfullxcatpost is set
An administrator sets site.cleanupdiskfullxcatpost, deploys a diskfull node, and
/xcatpost is empty. The next updatenode run downloads the postscripts again and
leaves them there. /xcatpost is mode 0755 and most of what lands in it is
world-readable, so material the administrator was told is gone comes back on
every maintenance run and on every reboot.

xcatdsklspost is the script that repopulates /xcatpost on all of those paths, and
it reads only CLEANUPXCATPOST. CLEANUPDISKFULLXCATPOST reaches the node in the
same mypostscript, exported by the site table, and no code reads it. Only
xcatinstallpost does, and that runs once, at install.

Read it in append_xcatpost_cleanup with the rule xcatinstallpost uses: remove the
postscripts when the run returns 0, keep updateflag.awk, and leave everything in
place after a failed run so the node can be examined.

xCAT-test/bats/xcatdsklspost_xcatpost_cleanup.bats captures this. Three of its
six tests fail on the previous commit.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-14 15:46:38 -03:00
Daniel Hilst 915d8364b5 fix(xcat-core): two Genesis builds in different chroots share one directory
The sbuild chroots bind-mount /var/lib/sbuild/build on /build, so every session
of every chroot sees the same directory. Staging the builder there let two builds
running at once overwrite each other's copy: one of them read a half-written
script and stopped with "-get: command not found". The output of an earlier run
stayed in it too, so a build collected another codename's deb and left 1.9 GB on
the build host.

Stage under /xcat-genesis-build instead. It lives in the session overlay and goes
away with the session.

26.04 also moved the backward-compatibility zone names out of tzdata into
tzdata-legacy, and the dracut module names 106 of them. Install it where apt has
it.

The three images (jammy 180 MB, noble 328 MB, resolute 432 MB) build with no
error in any log.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-12 09:54:53 -03:00
Daniel Hilst e362e70b4d Merge remote-tracking branch 'upstream/master' into HEAD
# Conflicts:
#	docs/source/overview/support_matrix.rst
2026-09-11 21:08:30 -03:00
Daniel Hilst a5df79078d docs(xcat-core): the support matrix names hypervisors where it must name architectures
The Operating System & Hardware Support Matrix carried eight hardware columns:
Power, Power LE, zVM, Power KVM, x86_64, x86_64 KVM, x86_64 Esxi and riscv64.
Six of them name a platform or a hypervisor, not a build target. xCAT builds and
ships one set of packages per architecture, so a reader cannot tell from the old
table which artifact serves a cell, and the same artifact appears under three
headings.

Reduce the columns to the three architectures xCAT builds for: x86_64, ppc64le
and riscv64. The x86_64, x86_64 KVM and x86_64 Esxi cells collapse into x86_64,
and Power, Power LE and Power KVM collapse into ppc64le. Every collapsed group
held one value per row, so no row changes meaning. The zVM column is removed:
s390x is not a built architecture.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-11 21:07:45 -03:00
Daniel Hilst a25e89772d Update docs/source/overview/support_matrix.rst
Co-authored-by: Vinícius Ferrão <vinicius@ferrao.net.br>
2026-09-11 21:07:45 -03:00
Daniel Hilst 2f0b59b21e Update docs/source/overview/support_matrix.rst
Co-authored-by: Vinícius Ferrão <vinicius@ferrao.net.br>
2026-09-11 21:07:45 -03:00
Daniel Hilst 1f14c843e0 feat(xcat-core): remove aarch64 from support matrix
The aarch64 column advertises three EL targets that are outside the xCAT 2.19 campaign scope and creates unsupported campaign obligations. Remove the column so the documentation remains the exact source of truth for the release qualification backlog.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-11 21:07:45 -03:00
Daniel Hilst 63fded7f0f feat(xcat-core): keep support scope in the matrix
The standalone riscv64 paragraph duplicated a version restriction that the versioned matrix now expresses directly and described only compute-node behavior. Keeping it would leave two sources for the same support claim.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-11 21:07:45 -03:00
Daniel Hilst 49f41f6074 feat(xcat-core): specify distro versions in support matrix
The operating-system support table named distro families without defining which releases the claim covered, and it kept separate legacy CentOS and Windows rows that are outside the xCAT 2.19 CI target contract. This made the release matrix ambiguous and impossible to translate into a finite CI backlog.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-11 21:07:44 -03:00
Daniel Hilst 24e22671b4 Merge branch 'master' of https://github.com/xcat2/xcat-core into release/2.19-rc1
master moved 149 commits ahead of the branch point and four files needed a
decision.

xCAT/debian/control and xCATsn/debian/control: master moved nmap and
ipmitool-xcat into Depends, raised the ipmitool version and added the s390x
OpenEmbedded Genesis recommendation. The branch made the genesis-scripts
dependency per architecture. Both are kept, so the ppc64el metapackage depends
on xcat-genesis-scripts-ppc64el and no longer on the amd64 package.

build-utils/lib/XCAT/BuildUtils.pm and xCAT-test/unit/build_utils.t: master
replaced @DEB_ARCHES plus the branch's %NO_RISCV64 exception list with
%ARCH_PACKAGES, which carries the architecture list per package.
deb_package_arches returns the same answer for every package, so master's form
is kept and %NO_RISCV64 is dropped.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-11 15:59:58 -03:00
Vinícius Ferrão 0b6478453c docs(deployment): the pkglist installs during a Subiquity autoinstall
Signed-off-by: Vinícius Ferrão <2031761+viniciusferrao@users.noreply.github.com>
2026-09-11 11:38:16 -03:00
Vinícius Ferrão 79cddca53e docs(riscv64): document Ubuntu 24.04 and 26.04 support
The guides said riscv64 covered EL10 only, and the riscv64 page listed
Ubuntu as unsupported. Both support matrices now carry the architecture for
Ubuntu, and the riscv64 page describes the Ubuntu paths: the loader copycd
builds from the media, the installer needing none of the accommodations
EL10 requires, the ports archive the packages come from, and a management
node running on riscv64. The 26.04 media need the RVA23 profile, which is
recorded as a limitation.

Signed-off-by: Vinícius Ferrão <2031761+viniciusferrao@users.noreply.github.com>
2026-09-08 22:01:31 -03:00
Daniel Hilst 8a77a645af Merge pull request #7816 from VersatusHPC/fix/sudoer-postscript-password
fix(sudoer): take the password from the passwd table
2026-09-08 10:29:50 -03:00
Vinícius Ferrão 1d6c373a86 docs(genesis): clarify virtual s390x discovery 2026-09-06 04:03:35 -03:00
Vinícius Ferrão 17ca2c9c79 docs(genesis): clarify s390x discovery 2026-09-06 03:36:22 -03:00
Vinícius Ferrão 20234cdacf docs(genesis): clarify physical qeth limits 2026-09-06 02:03:16 -03:00
Vinícius Ferrão d62cf52290 docs(genesis): describe s390x qeth setup 2026-09-06 00:26:57 -03:00
Daniel Hilst 6798db5fb7 fix(xcat-core): the Debian genesis dependency ignores the node architecture
A ppc64el or riscv64 management node installs the amd64 Genesis. xCAT and
xCATsn declare Architecture: amd64 ppc64el riscv64 and one unrestricted
Depends: xcat-genesis-scripts-amd64, so every architecture gets it. That
package is Architecture: all, so apt reports no error. It lays down
/opt/xcat/share/xcat/netboot/genesis/x86_64 and pulls the 128 MB
xcat-genesis-base-amd64, and the node receives no Genesis for its own
architecture. xcat-genesis-scripts-ppc64, the package that would carry it, is
uninstallable: it depends on xcat-genesis-base-ppc64, and builddeb-genesis-base
names the ppc64el base deb xcat-genesis-base-ppc64el.

xCAT/debian/control and xCATsn/debian/control now restrict the dependency by
architecture, the way xCAT.spec does with
%{?genesistarch:Requires: xCAT-genesis-scripts-%{genesistarch}}. amd64 gets
xcat-genesis-scripts-amd64, ppc64el gets xcat-genesis-scripts-ppc64el, and
riscv64 gets neither, because its Genesis is the OpenEmbedded image.
xCAT-genesis-scripts/debian/control-ppc64el builds xcat-genesis-scripts-ppc64el
and depends on xcat-genesis-base-ppc64el. It conflicts with and replaces the
old name, which shares the same files.

debian_control_arch_coverage.t asserts the genesis scripts an architecture
receives are that architecture's own, and that control-<arch> builds
xcat-genesis-scripts-<arch> against xcat-genesis-base-<arch>. Eight of its
assertions fail without this change.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-04 19:51:18 -03:00
Vinícius Ferrão c31d270e30 docs(genesis): fix DHCP option wording 2026-09-04 18:22:16 -03:00
Vinícius Ferrão 34abff1ae9 docs(genesis): state s390x validation limits 2026-09-04 18:03:05 -03:00
Vinícius Ferrão ecbafb4a2e docs(genesis): explain s390x config lookup 2026-09-04 17:15:24 -03:00
Vinícius Ferrão b7f9864528 docs(genesis): clarify s390x support 2026-09-04 16:20:38 -03:00
Vinícius Ferrão bc366dde81 docs(genesis): narrow s390x support 2026-09-04 15:31:34 -03:00
Vinícius Ferrão 582a361145 docs(genesis): define s390x validation limits 2026-09-04 14:43:41 -03:00
Vinícius Ferrão 75b162af9a docs(genesis): clarify s390x network boot 2026-09-04 13:21:28 -03:00
Vinícius Ferrão 1fe530431c docs(genesis): document s390x target 2026-09-04 12:48:32 -03:00
Daniel Hilst 1a5192d053 fix(xcat-core): build-ubunturepo is dead code that still looks buildable
builddebs.pl replaced build-ubunturepo, and both CD pipelines prefer it: the
fallback to build-ubunturepo fires only for refs that predate builddebs.pl, and
such a ref carries its own copy. Nothing on this branch runs the script, so its
presence only invites edits that never reach a build. The developer guide said
it was kept as a differential oracle until the CD pipelines moved over. They
have.

Remove the script, and record the removal in the build guide beside the
buildcore.sh, makerpm and buildlocal.sh entries.

xcat_probe_package_payload.t asserted the Debian staging by matching a `cp -f`
line in build-ubunturepo. builddebs.pl stages the helpers through
XCAT::BuildUtils::stage_probe_helpers, so the test now calls that function and
checks the files it produced. Verified by making stage_probe_helpers skip a
helper: the assertion fails.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-04 12:24:48 -03:00
Vinícius Ferrão dcea21cd76 docs(security): describe the sudoer postscript password source 2026-09-03 20:39:09 -03:00
Daniel Hilst 362bf5eb9f Merge pull request #7760 from VersatusHPC/fix/ubuntu-mn-ntp-daemon
fix(xcat-core): makentp fails on a stock Ubuntu MN (timesyncd cannot serve time)
2026-09-03 17:54:02 -03:00
Daniel Hilst 7003e0c0b6 Merge pull request #7761 from VersatusHPC/fix/ubuntu-subiquity-diskful-install
fix(xcat-core): the Ubuntu Subiquity diskful install never completes
2026-09-03 17:51:50 -03:00
Daniel Hilst 3249298cbd fix(xcat-core): site.ntpbackend is not documented anywhere
makentp reads site.ntpbackend to select the NTP daemon, and setupntp takes the same value as
--backend, but no help text names the attribute. An admin who needs ntpd on a host that has
chrony has no way to find out the attribute exists. site.dhcpbackend, which selects the DHCP
implementation the same way, is documented in the site table help.

The site table description in xCAT::Schema now carries ntpbackend beside ntpservers, with its
valid values and the auto default. The makentp man page lists it with the other site attributes
the command honors, and names the setupntp --backend option that carries the value to the nodes.

ntp_backend_selection.t reads the site help from the loaded schema and the makentp pod. Five
assertions fail without this change.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-03 14:41:32 -03:00
Daniel Hilst 1160214ce3 refactor(build): merge the two BuildUtils modules into one
The rebase onto master left the repository with two modules named
BuildUtils.pm: the shared build helpers at the root, package BuildUtils, and
the target architecture parser at build-utils/lib/XCAT/BuildUtils.pm, package
XCAT::BuildUtils. buildrpms.pl loaded both, one through `@INC` and one through a
path require. A reader cannot tell which module a BuildUtils reference names,
and the test sandbox staged the wrong one.

Move the shared helpers into build-utils/lib/XCAT/BuildUtils.pm as
XCAT::BuildUtils, and export targetarch_from_target beside them. Both builders
and the four tests now put build-utils/lib on `@INC` and import from the one
module. targetarch_from_target keeps its behaviour: it returns the same
architecture as before for suffixed targets, empty and undefined input, mixed
case and every architecture token.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-02 13:51:41 -03:00
Daniel Hilst 5abd4327c4 fix(build): keep build-ubunturepo as an oracle, and fix what running it found
builddebs.pl was written against build-ubunturepo but never run beside it. Keeping
the old script in the tree for one more cycle makes the comparison repeatable, and
running the two on xcat-master-ub found four defects that no unit test would have.

  * builddebs.pl was not executable. github_action_xcat_test.pl runs
    `sudo ./builddebs.pl`, so CI would have failed with Permission denied.

  * .deb files were collected after every ARCHITECTURE. dpkg-genbuildinfo reads
    the sibling artifacts of the source package it is building, so moving the
    amd64 .deb away before ppc64el ran killed the second build with
      dpkg-genbuildinfo: error: cannot fstat file ../xcat_..._amd64.deb
    Collection now happens once a package's last architecture is done.

  * A checkout dirtied by an aborted run poisoned the next one: a leftover
    .changes made dpkg-genbuildinfo name an architecture the run had not reached.
    The dpkg output is now cleared at start.

  * The maintainer was xcat@xcat.org where build-ubunturepo uses
    xcat-build@xcat.org, and a Release file in the tree was ignored.
    buildrpms.pl WRITES Release, so a pipeline building both would have stamped
    its debs with a different release from its rpms. Both corrected.

Equivalence, measured rather than assumed. Both builders were run on
xcat-master-ub from the same tree:

  package set      identical, 14/14, same names
  control metadata identical, 14/14
  payload contents identical, 14/14
  changelog.Debian differs, 2 packages -- deliberately, see below

Byte-identity is NOT the criterion, because neither implementation has it: two
consecutive runs of build-ubunturepo on the same tree agree on 0 of 14 packages.
A .deb records the build wall-clock time in its ar member mtimes and
SOURCE_DATE_EPOCH does not reach dpkg-deb here, so every run differs from every
other. That is a pre-existing property of the Debian build, not a regression, and
worth fixing separately.

The changelog difference is build-ubunturepo being wrong. Its

    sed -i "s/^ -- .*/ -- $DEBFULLNAME <$DEBEMAIL>  $deterministic_date/"

carries no line address, so it rewrites EVERY trailer in debian/changelog:
"OCF xCAT <xcat@ocf.co.uk>  Mon, 25 Oct 2010" ships as "xCAT Build
<xcat-build@xcat.org>  Tue, 01 Sep 2026". It falsifies the authorship and dates of
the 2008 and 2010 releases. builddebs.pl rewrites only the top stanza. Matching
byte-for-byte would mean reproducing the defect, so this difference stays.

(xcat-vlan appeared to differ under `diff -r`; that was diff reporting dangling
symlinks in both trees. Its member listing is identical.)

build-ubunturepo is documented as retained-for-comparison and not to be extended.
It goes once the Ubuntu CD pipelines call builddebs.pl.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-02 12:39:43 -03:00