2
0
mirror of https://github.com/xcat2/xcat-core.git synced 2026-10-02 08:51:44 +00:00
Commit Graph

28247 Commits

Author SHA1 Message Date
Vinícius Ferrão 8bc5bb4611 test(syslog): cover expanded configuration cleanup 2026-09-25 01:29:35 -03:00
Vinícius Ferrão 29ff3ab3f2 fix(syslog): guard expanded configuration cleanup 2026-09-25 01:29:34 -03:00
Vinícius Ferrão 4900bd2808 docs: document native test entry points 2026-09-22 23:15:54 -03:00
Vinícius Ferrão 85899df5d6 test: cover archive extraction in all dracut variants 2026-09-22 23:15:54 -03:00
Vinícius Ferrão 93b8399757 fix: guard optional localdisk hooks in dracut 105 2026-09-22 23:15:54 -03:00
Vinícius Ferrão f49941fb62 test: separate native openEuler checks from unit tests 2026-09-22 23:15:42 -03:00
Vinícius Ferrão 16b6acf620 fix(openeuler): integrate current Genesis and installer changes
Merge current master into the openEuler support branch. Keep native
kernel, DHCP, locale and timezone requirements with the upstream payload
verifier and EL10 package paths. Preserve signed openEuler installation.

Update the native fixtures to check the merged payload contract.
2026-09-22 19:45:05 -03:00
Vinícius Ferrão c20f05968e chore(openeuler): shorten package and setup comments 2026-09-22 18:07:02 -03:00
Vinícius Ferrão 56b593e99e test(build): cover native openEuler repository signing entry points 2026-09-22 02:57:08 -03:00
Vinícius Ferrão c50711aa87 fix(build): require signing for native openEuler core repositories 2026-09-22 02:57:08 -03:00
Vinícius Ferrão 880b10216e docs(openeuler): record qualified network settings 2026-09-22 02:51:34 -03:00
Vinícius Ferrão d9d8a0d809 docs(openeuler): finish qualified deployment profiles 2026-09-21 21:36:08 -03:00
Vinícius Ferrão 741511aa40 test(openeuler): locate installed package postscripts 2026-09-21 19:04:34 -03:00
Vinícius Ferrão c0c8456ef1 docs(openeuler): define the delivery qualification baseline 2026-09-21 18:46:14 -03:00
Vinícius Ferrão 4f24188b85 test(genesis): cover the openEuler mktemp dependency 2026-09-21 16:19:27 -03:00
Vinícius Ferrão 5bc548b3ca fix(genesis): include mktemp in openEuler images 2026-09-21 16:19:18 -03:00
Vinícius Ferrão 4f0ef5ef96 docs(openeuler): describe native deployment profiles 2026-09-19 05:45:09 -03:00
Vinícius Ferrão 43a45fe832 test(genesis): cover openEuler locale packaging
Exercise native locale requests and missing or failed inputs through the
dracut module. Retain timezone failure checks and legacy build and module
comparisons.
2026-09-19 05:26:14 -03:00
Vinícius Ferrão 2837826c6d fix(genesis): include UTF-8 locale data in openEuler images
Require glibc-common. Copy its C.utf8 locale into the initramfs so tmux can
start. If locale data is missing or cannot be copied, fail the build.
2026-09-19 05:25:59 -03:00
Vinícius Ferrão 96c97392b6 test(xnba): cover service-node ownership at the request boundary 2026-09-19 04:18:28 -03:00
Vinícius Ferrão 63e80a3734 fix(xnba): correct ownership checks in disjoint DHCP mode 2026-09-19 04:18:18 -03:00
Daniel Hilst 2f715ac371 Merge pull request #7818 from VersatusHPC/release/2.19-rc1
ci(xcat-core): Fixes to get CI running for all 2.19 targets
2.19.0
2026-09-17 18:18:48 -03:00
Daniel Hilst 52fd332180 Merge pull request #7838 from VersatusHPC/fix/riscv64-diskless-flat-machine-type
fix(xcat-core): the diskless flat case clears the machine type on riscv64
2026-09-17 18:12:50 -03:00
Daniel Hilst 2e6ca07172 Merge pull request #7841 from VersatusHPC/fix/ubuntu-power-diskful-installer-loop
fix(xcat-core): the Ubuntu POWER diskful install never leaves the installer
2026-09-17 12:38:17 -03:00
Daniel Hilst d694456244 Merge pull request #7855 from VersatusHPC/fix/ddns-tsig-algorithm-downgrade
fix(xcat-core): makedns leaves records behind because named cannot verify its own TSIG key
2026-09-17 11:39:44 -03:00
Daniel Hilst 03376eb150 Merge pull request #7842 from VersatusHPC/fix/ubuntu-ppc64el-netboot-dig
fix(xcat-core): the Ubuntu ppc64el netboot image has no dig
2026-09-17 11:38:29 -03:00
Daniel Hilst 6531f77277 Merge pull request #7839 from VersatusHPC/fix/ubuntu-node-netplan-search-domain
fix(xcat-core): a compute node cannot resolve the management node by short name
2026-09-17 11:37:01 -03:00
Daniel Hilst 007a38867b Merge pull request #7837 from VersatusHPC/fix/genesis-deb-release-placeholder
fix(xcat-core): the Genesis deb version never advances past snap000000000000
2026-09-17 11:36:48 -03:00
Daniel Hilst a891e8f741 Merge pull request #7832 from VersatusHPC/fix/ci-ubuntu-genesis-dhclient
fix(xcat-core): the Ubuntu Genesis image ships without a DHCP client
2026-09-17 11:36:37 -03:00
Daniel Hilst 782a2a57b0 Merge pull request #7831 from VersatusHPC/fix/ci-ubuntu-ppc-boot-files
fix(xcat-core): nodeset cannot boot an Ubuntu POWER install from live media
2026-09-17 11:36:27 -03:00
Daniel Hilst 23de8a92e0 fix(xcat-core): the flat case leaves the machine type on the node on ppc64
reg_linux_diskless_installation_flat corrupts the KVM machine type, proves the
node fails to boot, restores the machine type and then removes it again. On
ppc64 the two ladders name different machine types: the restore writes
machine:pseries-rhel7.6.0 and the cleanup removes machine:pseries-7.6.0. The sed
matches nothing, so the node keeps machine:pseries-rhel7.6.0 after the case ends
and the next case runs against a node the previous one changed.

The cleanup ladder now names the machine type the restore ladder writes.

diskless_flat_vmothersetting_machine.bats covers it: the ppc64le cleanup cases
are red on the commit before this one.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-17 07:36:10 -03:00
Daniel Hilst b4735e10e2 test(xcat-core): the machine-type test accepts a cleanup that removes nothing
diskless_flat_vmothersetting_machine.bats checked the restore with a substring
match and checked the cleanup only for the absence of "unary operator
expected". A cleanup that writes the machine type back, or leaves it in place,
passed both.

The test now reads the value chdef receives. The restore must write exactly
machine:<type>, and must keep a setting the node already carries. The cleanup
must write an empty value when the machine type is all there is, and must leave
the other setting behind when there is one. The chdef stub brackets its
arguments so an empty value is not the same as no call.

ppc64le is red on the cleanup: the restore ladder writes
machine:pseries-rhel7.6.0 and the cleanup ladder removes machine:pseries-7.6.0,
so the node keeps the machine type. x86_64 and riscv64 pass.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-17 07:35:51 -03:00
Daniel Hilst af2a4c08d5 Merge pull request #7840 from VersatusHPC/fix/gettimezone-error-sentence-as-timezone
fix(xcat-core): gettimezone returns an error sentence as a timezone name
2026-09-16 20:07:40 -03:00
Daniel Hilst eb37cd6e20 fix(xcat-core): naming util-linux-extra stops the Genesis build on jammy
REQUIRED_PACKAGES named util-linux-extra for every release. focal and jammy
have no such package -- apt reports "Candidate: (none)" -- so apt-get install
exits non-zero and, under set -euo pipefail, the build stops before dracut
runs. hwclock is in util-linux there, which is essential and already present.

optional_packages() keeps a package only where apt has a candidate for it, and
util-linux-extra goes through it. The unconditional list keeps isc-dhcp-client
and ifenslave, which every release has and neither of which the build root
carries by itself.

The call to verify-genesis-payload goes with it. That script is added by the
genesis payload branch, not this one, so the line stopped the build at the
point it was meant to guard.

Also corrects the plan count and a dereference in the test committed before
this one.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-16 18:03:52 -03:00
Daniel Hilst ea2b86adef test(xcat-core): naming util-linux-extra stops the Genesis build on jammy
builddeb-genesis-base names util-linux-extra in REQUIRED_PACKAGES for every
release. Measured on the four Ubuntu management nodes: focal and jammy report
"Candidate: (none)" for that package and carry hwclock in util-linux, which is
essential and already in the build root; noble and resolute carry it in
util-linux-extra. apt-get install with a package it cannot locate exits
non-zero, and the script runs under set -euo pipefail, so the build stops on
two supported targets before dracut runs.

util-linux only Suggests util-linux-extra, and the install passes
--no-install-recommends, so a release that split the package has to name it.

The test asserts the unconditional list does not name it, and drives the
selector that decides, with apt-cache shadowed for a release that has the
package and one that does not.

It also drops the assertion that matched "verify-genesis-payload" against the
text of the build script. That proved the string was present, not that the
verifier ran, ran before packaging, or stopped the build -- and the script it
names does not exist on this branch.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-16 18:02:47 -03:00
Daniel Hilst 75c0af5373 fix(xcat-core): debian_install_prescript.t passes when the file it reads is missing
debian_install_prescript.t called plan skip_all when xCAT-server/lib/xcat/plugins/debian.pm was absent, so a checkout that lost
the file reported 0 tests and exit 0. A test that cannot fail measures nothing.

Die instead, which is what makentp_ntp_deps.t already does for setupntp.

With xCAT-server/lib/xcat/plugins/debian.pm moved aside the file now exits 2 and prints "debian.pm not found";
before this change it exited 0 and printed "1..0 # SKIP debian.pm not found". With the file
present the test passes either way.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-15 21:11:00 -03:00
Daniel Hilst bc4ddbe34e fix(xcat-core): builddebs_release_placeholder.t passes when the file it reads is missing
builddebs_release_placeholder.t called plan skip_all when builddebs.pl was absent, so a checkout that lost
the file reported 0 tests and exit 0. A test that cannot fail measures nothing.

Die instead, which is what makentp_ntp_deps.t already does for setupntp.

With builddebs.pl moved aside the file now exits 2 and prints "builddebs.pl not found";
before this change it exited 0 and printed "1..0 # SKIP builddebs.pl not found". With the file
present the test passes either way.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-15 21:10:56 -03:00
Daniel Hilst 6a41acf2db fix(xcat-core): the retried DNS update carries two TSIG records
makedns reports "error was FORMERR" for an update that named rejected with
NOTAUTH. The FORMERR is the answer to the retry, not to the first attempt.

send_ddns_update in ddns.pm signs the packet the caller built, and signs that
same packet again on each attempt. Net::DNS::Packet::sign_tsig appends the TSIG
to the additional section, so the second attempt sends two TSIG records and
named answers FORMERR. FORMERR is neither NOTAUTH nor SERVFAIL, so the routine
stops and reports it. The NOTAUTH and SERVFAIL retry can never be accepted, on
any algorithm.

Each attempt now signs a request of its own. A packet cannot be unsigned again,
so ddns_update_request copies the prerequisite and update records into a new
Net::DNS::Update instead, and the caller keeps the unsigned original.

ddns_update_retry.t fails before this change: the second attempt carries two
TSIG records, and an update that the retry answers with NOERROR still reports
failure.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-15 20:43:58 -03:00
Daniel Hilst 69be7872f2 test(xcat-core): capture the DNS update retry sending two TSIG records
send_ddns_update signs the same packet on every attempt. Net::DNS appends the
TSIG to the additional section, so the second attempt carries two TSIG records.
named answers FORMERR to that message, which is neither NOTAUTH nor SERVFAIL, so
the routine stops and reports FORMERR. The retry path can never be accepted.

ddns_update_retry.t drives send_ddns_update with a resolver that answers FORMERR
to a message with more than one TSIG record, as named does, and otherwise
answers a scripted rcode. It asserts that every attempt carries exactly one TSIG
record and the same update records, and that a retry answered NOERROR reports
success. Both subtests fail before the fix.

The header of each new test records that XCATROOT must name the tree under test,
because xCAT::Table adds the installed /opt/xcat/lib/perl to @INC.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-15 20:43:58 -03:00
Daniel Hilst 4eb9718548 fix(xcat-core): makedns rewrites its own TSIG key and then fails against it
makedns exits 1 on a management node that has Net::DNS below 1.36 and an
hmac-sha256 key, and reports "Failure encountered updating <zone> with entry
'', error was FORMERR".

update_namedconf in ddns.pm rewrites the named.conf key stanza to hmac-md5
whenever Net::DNS is below 1.36, and ddns_tsig_algorithm returns hmac-md5 for
the same reason. ddns_sign_update signs with site.dhcpomapialgorithm, which
xcatconfig sets to hmac-sha256 on EL9 and later. named matches a TSIG key by
name and by algorithm, so it answers NOTAUTH. The retry signs the same packet
a second time, and named answers FORMERR to the two signatures.

The version test protected the two-argument sign_tsig($name, $secret), which
produces an HMAC-MD5 signature only. ddns_sign_update signs every other
algorithm through a KEY RR, so the Net::DNS version no longer selects the
algorithm. This change deletes the rewrite and the version test, and signs with
the algorithm the key stanza declares. OmapiPolicy->algorithm_rr_type maps that
algorithm to its KEY RR number.

ddns_named_key_algorithm.t fails before this change: it reads the stanza as
hmac-md5 where the key was hmac-sha256.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-15 20:43:58 -03:00
Daniel Hilst b9b66aab14 test(xcat-core): capture makedns rewriting its own TSIG key algorithm
On a management node with Net::DNS below 1.36, makedns rewrites the named.conf
key stanza to hmac-md5. It then signs the update with the algorithm the site
table selects. named matches a TSIG key by name and by algorithm, so it rejects
every update and makedns exits 1.

ddns_named_key_algorithm.t drives update_namedconf over a scratch named.conf and
then signs one update with the context that run produced. It asserts that the
stanza keeps the algorithm the key was generated with, that the signature uses
that algorithm, and that named is not restarted. Two of its five subtests fail
before the fix.

ddns_omapi_policy.t pinned the rewrite as correct, so its expectations move to
the algorithm the key already has.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-15 20:43:58 -03:00
Vinícius Ferrão a3811b9bcb docs(openeuler): identify media fixture sources 2026-09-15 01:13:33 -03:00
Vinícius Ferrão b5fe3abded test(openeuler): cover image creation and boot artifacts
Exercise native profile registration and interrupted reimport recovery
with SQLite. Render installer templates. Check image command failures and
archive extraction. Retain installed and diskless compute and service
cases and legacy boundaries.
2026-09-15 01:12:53 -03:00
Vinícius Ferrão c0e66721d7 feat(openeuler): provision installed and diskless images
Add native compute and service profiles, installer dispatch and partition
defaults. Use strict DNF image creation. Check stateless boot-file and
archive publication. Preserve native image customizations on reimport.
Restore missing image records during reimport.
2026-09-15 01:12:21 -03:00
Vinícius Ferrão e8229fd52c feat(openeuler): apply management SELinux setup
Include the native release file in the existing initial and forced
management setup guard. Retain the current SELinux configuration policy.
2026-09-15 01:01:59 -03:00
Vinícius Ferrão aff8b1191e test(genesis): cover native build inputs and release checks
Evaluate native and EL RPM requirements. Exercise complete dracut module
requests. Run the spec install phase against generated release fixtures.
Cover missing identity fields and timezone failures.
2026-09-15 00:59:50 -03:00
Vinícius Ferrão 4a19444cd1 feat(genesis): build Genesis with native openEuler inputs
Use the native kernel package and target architecture. Install native
release and timezone files. Require the generated image to retain its
release identity and kernel modules. Keep the existing EL requirements and
module requests.
2026-09-15 00:59:23 -03:00
Vinícius Ferrão f8aa1587bd test(openeuler): cover localized repository rendering 2026-09-15 00:40:55 -03:00
Vinícius Ferrão ac8fe0275f feat(openeuler): render repositories from configured install root 2026-09-15 00:40:55 -03:00
Vinícius Ferrão f2805433c1 test(openeuler): exercise logging and host-key postscripts 2026-09-15 00:33:39 -03:00