fix(autopatch): Replaced the stale %define-based pesign_name_0 block with two new shell-variable assignments targeting the upstream RHEL #14
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "agent-fix/a10-20261002-125635"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Automated fix by autopatch agent.
Summary: Replaced the stale %define-based pesign_name_0 block with two new shell-variable assignments targeting the upstream RHEL-169468 refactoring.
Root cause
The upstream kernel spec (RHEL-169468 / RHEL-169478) replaced the old
%if 0%{?centos}/%define pesign_name_0static-macro approach with a dynamic shell functionget_pesign_name()that discovers the cert name at build time.This caused two actions in
config.yamlto become stale:replaceaction whosefindwas the%if 0%{?centos} … %define pesign_name_0 …block — this is the action that failed withActionNotAppliedError, because that entire block no longer exists in the spec.replaceaction targetingUKI_secureboot_name=inside a%if 0%{?centos}block — also stale; that variable and block are both gone.The fix (already present in the
a10sstream branch) replaces both stale actions with two new ones that pin the AlmaLinux secure-boot key name at the shell-variable assignment sites:pesign_name_0=$(get_pesign_name %{secureboot_key_0})→pesign_name_0=almalinuxsecureboot0pesign_name_uki_0=$(get_pesign_name %{secureboot_key_uki_0})→pesign_name_uki_0=almalinuxsecureboot0This is necessary because
almalinux-sb-certsships only the genericsecureboot-kernel-<arch>.cernames; theget_pesign_namediscovery logic would otherwise fall back tosecureboot-kernel-<arch>, which the sign node does not recognise, breaking SecureBoot signing on x86_64, aarch64, ppc64le, and s390x.Original error
Type:
ActionNotAppliedErrorPackage:
kernel| Webhook branch:c10duplicate
Pull request closed