Files
fips/testing/openwrt/maintainer-scripts-test.sh
T
Johnathan Corgan 7d97d0d9ad Fix stale fixtures, pins and comments in the packaging tests
The OpenWrt upgrade fixture was the fips.yaml from the commit before the
gateway's DNS port moved, not one any release shipped. Replace it with the
v0.5.1 bytes and say which releases it stands for, since v0.3.0 to v0.4.2
shipped an older file with the same legacy listen line.

busybox:1.37 moves with every 1.37.x rebuild, so the pin did not keep the
shell under test fixed as its comment said. Pin the multi-arch index
digest instead, as the tree does for its other third-party images.

The comment describing run_ci_parity had drifted above
run_openwrt_scripts; move it back to its function. The deb-install header
named `apt install` where the script runs
`apt-get install -y --no-install-recommends`, and its usage line omitted
the --deb option the script accepts.

Nothing in the tree read the package's Recommends: the Depends check
compares Depends only, and the install test installs with
--no-install-recommends. check-deb-depends.sh now compares each package's
Recommends with the recommends Cargo.toml declares, in any order, and
refuses to pass when that declaration cannot be read.
2026-10-01 14:20:06 +00:00

68 lines
3.1 KiB
Bash
Executable File

#!/bin/bash
# ── OpenWrt maintainer-script scenarios ─────────────────────────────────────
# Runs testing/openwrt/scenarios.sh inside a busybox container, so the package
# scripts and the fips-gateway init script are interpreted by ash rather than
# by the host's bash or dash. The scripts ship to routers and are only ever run
# under ash there; a construct bash accepts and ash does not would otherwise
# surface on a router.
#
# The container is the only reason docker is needed: the scenarios touch no
# network and no FIPS binary, and they do not use the shared test image.
#
# Exit 0 = every scenario passed. Exit 1 = at least one failed. Exit 2 = the
# harness could not run; never treated as a pass.
# ─────────────────────────────────────────────────────────────────────────────
set -uo pipefail
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
PROJECT_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
# Pinned by digest so the shell under test does not change under a run: the
# 1.37 tag moves with every 1.37.x rebuild. This is the multi-arch index digest
# of busybox:1.37.0 as of 2026-10-01. Bump it deliberately, reading the new
# digest with `docker buildx imagetools inspect busybox:<version>`.
# Overridable for trying another ash build.
IMAGE="${OPENWRT_ASH_IMAGE:-busybox:1.37.0@sha256:bdf57e528e45e4433820e045b29b4597825a1c9e38353532d90a01445013f82e}"
if ! command -v docker >/dev/null 2>&1; then
echo "openwrt-scripts: docker not found; cannot run the ash scenarios" >&2
exit 2
fi
if [[ ! -f "$SCRIPT_DIR/scenarios.sh" ]]; then
echo "openwrt-scripts: missing $SCRIPT_DIR/scenarios.sh" >&2
exit 2
fi
# The .apk wraps the shared bodies for its upgrade path. package-test.sh builds
# the package on the host with the real build-apk.sh, checks what it registers,
# and leaves the four scripts here so the scenarios run exactly what ships.
# The directory is bind-mounted into the container, so it must be one the docker
# daemon can see: under the checkout, not /tmp, which a service running with a
# private /tmp (as the CI workers do) does not share with the daemon.
mkdir -p "$PROJECT_ROOT/target" || { echo "openwrt-scripts: cannot create target/" >&2; exit 2; }
APK_DIR="$(mktemp -d "$PROJECT_ROOT/target/openwrt-apk.XXXXXX")" || { echo "openwrt-scripts: mktemp failed" >&2; exit 2; }
trap 'rm -rf "$APK_DIR"' EXIT
bash "$SCRIPT_DIR/package-test.sh" --keep "$APK_DIR"
rc=$?
if [[ $rc -ne 0 ]]; then
echo "openwrt-scripts: package-test.sh exited $rc" >&2
exit $rc
fi
docker run --rm --network none \
-v "$PROJECT_ROOT:/src:ro" \
-v "$APK_DIR:/apk:ro" \
-e REPO=/src \
-e APK_SCRIPTS=/apk \
-e "POSTINST=${POSTINST:-}" \
-e "PRERM=${PRERM:-}" \
"$IMAGE" sh /src/testing/openwrt/scenarios.sh
rc=$?
if [[ $rc -ne 0 && $rc -ne 1 ]]; then
echo "openwrt-scripts: the container exited $rc, so the scenarios did not report" >&2
exit 2
fi
exit $rc