fix(autopatch): Replaced obsolete static pesign_name_0 define block with two runtime shell-variable replacements targeting the new get_p #13
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "agent-fix/a10-20261002-125207"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Automated fix by autopatch agent.
Summary: Replaced obsolete static pesign_name_0 define block with two runtime shell-variable replacements targeting the new get_pesign_name() pattern, adapting the fix from the a10s reference branch.
Root cause
The upstream c10 spec refactored how the SecureBoot pesign certificate name is resolved (RHEL-169468):
%define pesign_name_0/%define pesign_name_uki_0macro block (with per-archcentossecureboot201/redhatsecureboot801etc. values) was removed.get_pesign_name()shell function at build time:pesign_name_0=$(get_pesign_name %{secureboot_key_0})andpesign_name_uki_0=$(get_pesign_name %{secureboot_key_uki_0}).The
a10config'sReplaceActionwas still looking for the old static macro block, which no longer exists, causingActionNotAppliedError.The reference branch (
a10s) already contained the correct fix. The two old actions (one for%define pesign_name_0, one for the UKIUKI_secureboot_nameblock) were replaced with:find: " pesign_name_0=$(get_pesign_name %{secureboot_key_0})"→replace: " pesign_name_0=almalinuxsecureboot0"find: " pesign_name_uki_0=$(get_pesign_name %{secureboot_key_uki_0})"→replace: " pesign_name_uki_0=almalinuxsecureboot0"This pins
almalinuxsecureboot0for both kernel and UKI signing, preserving SecureBoot functionality sincealmalinux-sb-certsdoes not ship distro-named symlinks thatget_pesign_name()can auto-discover.Original error
Type:
ActionNotAppliedErrorPackage:
kernel| Webhook branch:c10