fix(autopatch): Replaced the stale %define-based pesign_name_0 block with two new shell-variable assignments targeting the upstream RHEL #14

Closed
almalinux-automation wants to merge 1 commit from agent-fix/a10-20261002-125635 into a10

Automated fix by autopatch agent.

Summary: Replaced the stale %define-based pesign_name_0 block with two new shell-variable assignments targeting the upstream RHEL-169468 refactoring.

Root cause

The upstream kernel spec (RHEL-169468 / RHEL-169478) replaced the old %if 0%{?centos} / %define pesign_name_0 static-macro approach with a dynamic shell function get_pesign_name() that discovers the cert name at build time.

This caused two actions in config.yaml to become stale:

  • The replace action whose find was the %if 0%{?centos} … %define pesign_name_0 … block — this is the action that failed with ActionNotAppliedError, because that entire block no longer exists in the spec.
  • The replace action targeting UKI_secureboot_name= inside a %if 0%{?centos} block — also stale; that variable and block are both gone.

The fix (already present in the a10s stream branch) replaces both stale actions with two new ones that pin the AlmaLinux secure-boot key name at the shell-variable assignment sites:

  • pesign_name_0=$(get_pesign_name %{secureboot_key_0}) → pesign_name_0=almalinuxsecureboot0
  • pesign_name_uki_0=$(get_pesign_name %{secureboot_key_uki_0}) → pesign_name_uki_0=almalinuxsecureboot0

This is necessary because almalinux-sb-certs ships only the generic secureboot-kernel-<arch>.cer names; the get_pesign_name discovery logic would otherwise fall back to secureboot-kernel-<arch>, which the sign node does not recognise, breaking SecureBoot signing on x86_64, aarch64, ppc64le, and s390x.

Original error

Type: ActionNotAppliedError

Traceback (most recent call last):
  File "/root/autopatch-tool/src/webserv.py", line 95, in debrand_packages
    result = apply_modifications(
  File "/root/autopatch-tool/src/debranding.py", line 138, in apply_modifications
    config.apply_actions(rpms_working_dir + f"/{package}")
  File "/root/autopatch-tool/src/actions_handler.py", line 938, in apply_actions
    action.execute(Path(package_path))
  File "/root/autopatch-tool/src/actions_handler.py", line 477, in execute
    process_lines(
  File "/root/autopatch-tool/src/actions_handler.py", line 238, in process_lines
    raise ActionNotAppliedError(
actions_handler.ActionNotAppliedError: Action 'ReplaceAction' was not applied successfully: No changes made for '['%if 0%{?centos}', '%define pesign_name_0 centossecureboot201', '%else', '%ifarch x86_64 aarch64', '%define pesign_name_0 redhatsecureboot801', '%endif', '%ifarch s390x', '%define pesign_name_0 redhatsecureboot302', '%endif', '%ifarch ppc64le', '%define pesign_name_0 redhatsecureboot701', '%endif', '%endif']' in /root/autopatch-tool/src/autopatch-kernel-cz1v_zi6/rpms-namespace/kernel/kernel.spec

Package: kernel | Webhook branch: c10

Automated fix by autopatch agent. **Summary:** Replaced the stale %define-based pesign_name_0 block with two new shell-variable assignments targeting the upstream RHEL-169468 refactoring. ### Root cause The upstream kernel spec (RHEL-169468 / RHEL-169478) replaced the old `%if 0%{?centos}` / `%define pesign_name_0` static-macro approach with a dynamic shell function `get_pesign_name()` that discovers the cert name at build time. This caused two actions in `config.yaml` to become stale: - The `replace` action whose `find` was the `%if 0%{?centos} … %define pesign_name_0 …` block — **this is the action that failed** with `ActionNotAppliedError`, because that entire block no longer exists in the spec. - The `replace` action targeting `UKI_secureboot_name=` inside a `%if 0%{?centos}` block — also stale; that variable and block are both gone. The fix (already present in the `a10s` stream branch) replaces both stale actions with two new ones that pin the AlmaLinux secure-boot key name at the shell-variable assignment sites: - `pesign_name_0=$(get_pesign_name %{secureboot_key_0})` → `pesign_name_0=almalinuxsecureboot0` - `pesign_name_uki_0=$(get_pesign_name %{secureboot_key_uki_0})` → `pesign_name_uki_0=almalinuxsecureboot0` This is necessary because `almalinux-sb-certs` ships only the generic `secureboot-kernel-<arch>.cer` names; the `get_pesign_name` discovery logic would otherwise fall back to `secureboot-kernel-<arch>`, which the sign node does not recognise, breaking SecureBoot signing on x86_64, aarch64, ppc64le, and s390x. ### Original error **Type:** `ActionNotAppliedError` ``` Traceback (most recent call last): File "/root/autopatch-tool/src/webserv.py", line 95, in debrand_packages result = apply_modifications( File "/root/autopatch-tool/src/debranding.py", line 138, in apply_modifications config.apply_actions(rpms_working_dir + f"/{package}") File "/root/autopatch-tool/src/actions_handler.py", line 938, in apply_actions action.execute(Path(package_path)) File "/root/autopatch-tool/src/actions_handler.py", line 477, in execute process_lines( File "/root/autopatch-tool/src/actions_handler.py", line 238, in process_lines raise ActionNotAppliedError( actions_handler.ActionNotAppliedError: Action 'ReplaceAction' was not applied successfully: No changes made for '['%if 0%{?centos}', '%define pesign_name_0 centossecureboot201', '%else', '%ifarch x86_64 aarch64', '%define pesign_name_0 redhatsecureboot801', '%endif', '%ifarch s390x', '%define pesign_name_0 redhatsecureboot302', '%endif', '%ifarch ppc64le', '%define pesign_name_0 redhatsecureboot701', '%endif', '%endif']' in /root/autopatch-tool/src/autopatch-kernel-cz1v_zi6/rpms-namespace/kernel/kernel.spec ``` --- Package: `kernel` | Webhook branch: `c10`
Replaced the stale %define-based pesign_name_0 block with two new shell-variable assignments targeting the upstream RHEL-169468 refactoring.
Owner

duplicate

duplicate
alukoshko closed this pull request 2026-10-02 12:57:07 +00:00
alukoshko deleted branch agent-fix/a10-20261002-125635 2026-10-02 12:57:13 +00:00

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
autopatch/kernel!14
No description provided.