From bba59c2e632a82152c459800bc415913634d6c07 Mon Sep 17 00:00:00 2001 From: Johnathan Corgan Date: Thu, 1 Oct 2026 14:32:08 +0000 Subject: [PATCH] Correct stale comments in the deb install test The lead line above start_unit described the non-blocking start the function replaced, contradicting both the body and the paragraph that follows; drop it. The build banner still named the Debian 12 builder image the suite stopped using; name the shared container script and the file that sets its image instead. The header and the install check also called /etc/fips/fips.yaml a conffile. It is not one: the package ships fips.yaml.example and postinst seeds fips.yaml from it when absent, while the declared conffiles are hosts and fips.nft. Name fips.nft as the conffile the suite checks, and say the check sees a postinst-seeded file. Comment and message text only; no check changes. --- testing/deb-install/test.sh | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/testing/deb-install/test.sh b/testing/deb-install/test.sh index c43aad94..63977bd4 100755 --- a/testing/deb-install/test.sh +++ b/testing/deb-install/test.sh @@ -15,7 +15,8 @@ # # This is the most thorough test surface — it exercises: # - cargo deb packaging (binary stripping, dependency declaration) -# - dpkg conffile placement (/etc/fips/fips.yaml) +# - dpkg conffile placement (/etc/fips/fips.nft) and postinst seeding +# of /etc/fips/fips.yaml # - postinst maintainer scripts (systemd unit enablement, # fips-dns.service running fips-dns-setup) # - postrm purge (removing the DNS routing fips-dns-setup wrote) @@ -141,8 +142,6 @@ wait_for_systemd() { return 1 } -# Start a unit without waiting for its start job to finish. -# # Start a unit and wait for its start job, under a bound. # # Blocking is the right default and the call returning is what synchronises the @@ -194,8 +193,9 @@ container_systemd_version() { } # ───────────────────────────────────────────────────────────────────── -# Build the .deb once in a Debian 12 cargo-deb builder image (cached -# between runs). Output cached at testing/deb-install/.cache/deb/. +# Build the .deb once through packaging/debian/build-deb-container.sh, +# whose image is set in packaging/build-floor.env (cached between +# runs). Output cached at testing/deb-install/.cache/deb/. # Rebuilt if any source/Cargo/packaging file is newer than the cached # .deb, or if the .deb is missing. # ───────────────────────────────────────────────────────────────────── @@ -542,9 +542,9 @@ DOCKERFILE fail "/usr/bin/fips-gateway missing" fi if docker exec "$name" test -f /etc/fips/fips.yaml; then - pass "/etc/fips/fips.yaml conffile installed" + pass "/etc/fips/fips.yaml seeded by postinst" else - fail "/etc/fips/fips.yaml conffile missing" + fail "/etc/fips/fips.yaml missing" fi # Verify fips.service is enabled (postinst enables but does not @@ -670,7 +670,7 @@ DOCKERFILE fi # Get the daemon's npub via fipsctl. Works for both ephemeral - # and persistent identity (no need to override the conffile). + # and persistent identity (no need to override /etc/fips/fips.yaml). local npub npub=$(docker exec "$name" fipsctl show status 2>/dev/null \ | grep -oE 'npub1[a-z0-9]+' | head -1)