[Packaging] Fix #34131: Enable Fedora 44 RPM build and validation - #34132
Aditya Pujara (a0x1ab) wants to merge 8 commits into
Conversation
…ld and validation
|
Hi Aditya Pujara (@a0x1ab), |
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Critical Fedora build, verification, and test-contract issues remain unresolved, along with missing CI matrix integration.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 4
Open (5)
Install python-pip-wheel in the Fedora 44 build image · New Mount and export PIP_INDEX_URL for Fedora RPM builds · New Fix legacy branch exit-status handling or update the test · New Query only azure-cli when checking preinstalled packages · New Add Fedora 44 build and validation jobs to the pipeline · New
What changed in this PR
Enables Fedora 44 RPM packaging and adds repository verification, validation tests, and documentation.
Changes:
- Adds Fedora 44 build configuration and smoke checks.
- Adds RPM package and repository verification tests.
- Documents build, testing, and acceptance workflows.
| File | Summary | Review status |
|---|---|---|
scripts/release/rpm/verify_rpm_in_docker.sh |
Strict repository verification | Changes required |
scripts/release/rpm/tests/test_verify_rpm.py |
Verifier contract tests | Changes required |
scripts/release/rpm/tests/test_rpm_package.py |
RPM validation tests | No blocking comment |
scripts/release/rpm/test_rpm_package.py |
RPM installation validation | No blocking comment |
scripts/release/rpm/test_rpm_in_docker.sh |
Container test guidance | No blocking comment |
scripts/release/rpm/README.md |
Fedora build and acceptance documentation | Changes required |
scripts/release/rpm/fedora.dockerfile |
Fedora 44 build configuration | Changes required |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| ARG python_cmd=${python_package} | ||
|
|
||
| RUN dnf update -y | ||
| RUN dnf install -y wget rpm-build gcc libffi-devel ${python_package}-devel openssl-devel make bash coreutils diffutils patch dos2unix perl |
| RUN dos2unix ./scripts/release/rpm/azure-cli.spec && \ | ||
| REPO_PATH=$(pwd) CLI_VERSION=$cli_version PYTHON_PACKAGE=$python_package PYTHON_CMD=python3 \ | ||
| REPO_PATH=$(pwd) CLI_VERSION=$cli_version PYTHON_PACKAGE=$python_package PYTHON_CMD=$python_cmd \ |
| _, commands = self.run_script(success=False, RPM_REPOSITORY_ID=None, STUB_CLI_VERSION=version) | ||
| self.assertEqual(commands.count(("yum", "install", "azure-cli", "-y")), attempts) | ||
| self.assertEqual(commands.count(("sleep", "300")), 4 if version == "" else 0) | ||
| self.run_script(RPM_REPOSITORY_ID=None, STUB_FAIL="legacy-install") |
| fi | ||
|
|
||
| # Unlike a failed rpm -q, an empty successful query is unambiguously absent. | ||
| preinstalled=$(rpm -qa azure-cli --queryformat '%{NAME}\n') |
| The main `azure-pipelines.yml` currently has no Fedora 44 entry in either | ||
| `BuildRpmPackages` or `TestRpmPackage`. The Dockerfile change alone does not add | ||
| those jobs. After release-owner approval, the paired entries under the existing | ||
| architecture loops must use the same image, artifact and Python selection: |
|
/azp run |
|
Azure Pipelines: Successfully started running 3 pipeline(s). |
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
|
🔔 Routing this PR to @Azure/act-platform-engineering-squad. |
This comment has been minimized.
This comment has been minimized.
|
Please fix CI issues |
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
Live test results — changed test files only⏭️ SKIPPED — this PR changes no test files ( PR head ref: Workflow run: https://github.com/Azure/issue-sentinel/actions/runs/36520594971 Posted by the X Engineering Agent live-test workflow. |
az --version: Enable Fedora 44 RPM build and validationThere was a problem hiding this comment.
Review
No actionable code findings were confirmed at c8ab1768440496a38fcada67e51e8c92f03100fc. This revision is ready for human review within its documented local-build and package-verification scope; this is not approval of Fedora 44 production publication.
Upstream CI
All 50 reported checks completed successfully for the reviewed revision, with no failed, pending or canceled validation checks. This supersedes the earlier failed-CI assessment.
Code and author-provided evidence
The Fedora Dockerfile now selects Fedora 44 and carries the selected Python executable through the RPM specification. The shared package runner checks artifact identity, native architecture, CLI version and the declared Python dependency while retaining development-version and existing UBI/Azure Linux caller behavior.
The added regression files, scripts/release/rpm/tests/test_rpm_package.py and scripts/release/rpm/tests/test_verify_rpm.py, exercise mismatched versions/architectures, missing dependencies, command failures, repository origin, executable ownership, signature-policy arguments and the unset-selector legacy path. The shell tests use isolated command stubs: they substantiate the script contract, not an actual Fedora installation or a published package. The PR's testing guide is author-provided evidence and is distinct from the Agent workflow result below.
Scope and release handoff
scripts/release/rpm/README.md explicitly leaves the Fedora build/test matrix entries, native-architecture container acceptance, signing and production-feed onboarding to release-owner approval. No pipeline matrix is changed here. The opt-in repository verifier fails closed on an empty selector or mismatched package and leaves the generic-yum path unchanged when the selector is unset. Neither green checks nor local unsigned installation establish Fedora 44 production availability or support; the documented release-owner gates still apply.
Test validation
- Live test: Passed. Workflow run
- Regression coverage: Not applicable to the changed files.
Risk assessment
0/100 · Low · Low confidence
The Low rating reflects the detected change scope with no elevated security, reliability, customer, operational, dependency, sovereign-cloud, generated-output, or cross-component signal.
- Change scope: 7 changed files, 799 changed lines (
+760/-39), including 0 production files. - Affected components: No production component was identified.
- Risk drivers: No elevated risk signal was detected.
- Regression evidence: No production-code regression-test signal applies.
- Confidence: Low because no production changed-line evidence was available.
- Required review: No additional owning-squad review signal was detected.
Posted by x-engineering-agent (Reviewer)


🤖 PR Validation — ️✔️ All clear
Related command
az --versionDescription
Fixes #34131.
Enable Fedora 44 RPM build and validation.
Testing Guide
az --version.scripts/release/rpm/tests/test_rpm_package.py,scripts/release/rpm/tests/test_verify_rpm.py.History Notes
[Packaging] Enable Fedora 44 RPM build and validation
This checklist is used to make sure that common guidelines for a pull request are followed.
The PR title and description has followed the guideline in Submitting Pull Requests.
I adhere to the Command Guidelines.
I adhere to the Error Handling Guidelines.