fix(autopatch): Replaced obsolete static pesign_name_0 define block with two runtime shell-variable replacements targeting the new get_p #13

Merged
alukoshko merged 1 commit from agent-fix/a10-20261002-125207 into a10 2026-10-02 12:54:38 +00:00

Automated fix by autopatch agent.

Summary: Replaced obsolete static pesign_name_0 define block with two runtime shell-variable replacements targeting the new get_pesign_name() pattern, adapting the fix from the a10s reference branch.

Root cause

The upstream c10 spec refactored how the SecureBoot pesign certificate name is resolved (RHEL-169468):

  • The old static %define pesign_name_0 / %define pesign_name_uki_0 macro block (with per-arch centossecureboot201 / redhatsecureboot801 etc. values) was removed.
  • In its place, the spec now calls a get_pesign_name() shell function at build time: pesign_name_0=$(get_pesign_name %{secureboot_key_0}) and pesign_name_uki_0=$(get_pesign_name %{secureboot_key_uki_0}).

The a10 config's ReplaceAction was still looking for the old static macro block, which no longer exists, causing ActionNotAppliedError.

The reference branch (a10s) already contained the correct fix. The two old actions (one for %define pesign_name_0, one for the UKI UKI_secureboot_name block) were replaced with:

  • find: " pesign_name_0=$(get_pesign_name %{secureboot_key_0})" → replace: " pesign_name_0=almalinuxsecureboot0"
  • find: " pesign_name_uki_0=$(get_pesign_name %{secureboot_key_uki_0})" → replace: " pesign_name_uki_0=almalinuxsecureboot0"

This pins almalinuxsecureboot0 for both kernel and UKI signing, preserving SecureBoot functionality since almalinux-sb-certs does not ship distro-named symlinks that get_pesign_name() can auto-discover.

Original error

Type: ActionNotAppliedError

Traceback (most recent call last):
  File "/root/autopatch-tool/src/webserv.py", line 95, in debrand_packages
    result = apply_modifications(
  File "/root/autopatch-tool/src/debranding.py", line 138, in apply_modifications
    config.apply_actions(rpms_working_dir + f"/{package}")
  File "/root/autopatch-tool/src/actions_handler.py", line 938, in apply_actions
    action.execute(Path(package_path))
  File "/root/autopatch-tool/src/actions_handler.py", line 477, in execute
    process_lines(
  File "/root/autopatch-tool/src/actions_handler.py", line 238, in process_lines
    raise ActionNotAppliedError(
actions_handler.ActionNotAppliedError: Action 'ReplaceAction' was not applied successfully: No changes made for '['%if 0%{?centos}', '%define pesign_name_0 centossecureboot201', '%else', '%ifarch x86_64 aarch64', '%define pesign_name_0 redhatsecureboot801', '%endif', '%ifarch s390x', '%define pesign_name_0 redhatsecureboot302', '%endif', '%ifarch ppc64le', '%define pesign_name_0 redhatsecureboot701', '%endif', '%endif']' in /root/autopatch-tool/src/autopatch-kernel-9u41h_g3/rpms-namespace/kernel/kernel.spec

Package: kernel | Webhook branch: c10

Automated fix by autopatch agent. **Summary:** Replaced obsolete static pesign_name_0 define block with two runtime shell-variable replacements targeting the new get_pesign_name() pattern, adapting the fix from the a10s reference branch. ### Root cause The upstream c10 spec refactored how the SecureBoot pesign certificate name is resolved (RHEL-169468): - The old static `%define pesign_name_0` / `%define pesign_name_uki_0` macro block (with per-arch `centossecureboot201` / `redhatsecureboot801` etc. values) was removed. - In its place, the spec now calls a `get_pesign_name()` shell function at build time: `pesign_name_0=$(get_pesign_name %{secureboot_key_0})` and `pesign_name_uki_0=$(get_pesign_name %{secureboot_key_uki_0})`. The `a10` config's `ReplaceAction` was still looking for the old static macro block, which no longer exists, causing `ActionNotAppliedError`. The reference branch (`a10s`) already contained the correct fix. The two old actions (one for `%define pesign_name_0`, one for the UKI `UKI_secureboot_name` block) were replaced with: - `find: " pesign_name_0=$(get_pesign_name %{secureboot_key_0})"` → `replace: " pesign_name_0=almalinuxsecureboot0"` - `find: " pesign_name_uki_0=$(get_pesign_name %{secureboot_key_uki_0})"` → `replace: " pesign_name_uki_0=almalinuxsecureboot0"` This pins `almalinuxsecureboot0` for both kernel and UKI signing, preserving SecureBoot functionality since `almalinux-sb-certs` does not ship distro-named symlinks that `get_pesign_name()` can auto-discover. ### Original error **Type:** `ActionNotAppliedError` ``` Traceback (most recent call last): File "/root/autopatch-tool/src/webserv.py", line 95, in debrand_packages result = apply_modifications( File "/root/autopatch-tool/src/debranding.py", line 138, in apply_modifications config.apply_actions(rpms_working_dir + f"/{package}") File "/root/autopatch-tool/src/actions_handler.py", line 938, in apply_actions action.execute(Path(package_path)) File "/root/autopatch-tool/src/actions_handler.py", line 477, in execute process_lines( File "/root/autopatch-tool/src/actions_handler.py", line 238, in process_lines raise ActionNotAppliedError( actions_handler.ActionNotAppliedError: Action 'ReplaceAction' was not applied successfully: No changes made for '['%if 0%{?centos}', '%define pesign_name_0 centossecureboot201', '%else', '%ifarch x86_64 aarch64', '%define pesign_name_0 redhatsecureboot801', '%endif', '%ifarch s390x', '%define pesign_name_0 redhatsecureboot302', '%endif', '%ifarch ppc64le', '%define pesign_name_0 redhatsecureboot701', '%endif', '%endif']' in /root/autopatch-tool/src/autopatch-kernel-9u41h_g3/rpms-namespace/kernel/kernel.spec ``` --- Package: `kernel` | Webhook branch: `c10`
Replaced obsolete static pesign_name_0 define block with two runtime shell-variable replacements targeting the new get_pesign_name() pattern, adapting the fix from the a10s reference branch.
alukoshko deleted branch agent-fix/a10-20261002-125207 2026-10-02 12:54:51 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
autopatch/kernel!13
No description provided.