mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
apk-tools v3 runs only the incoming package's pre-upgrade and post-upgrade scripts on an upgrade, and the .apk registered neither. An upgrade replaced the binaries and init scripts on disk but left procd running the old fips and fips-gateway processes until a reboot or a manual restart. The .apk now registers pre-upgrade and post-upgrade as thin wrappers around the same prerm and postinst bodies the .ipk ships. One header line gives each body the opkg upgrade contract it already handles: pre-upgrade rewrites apk's "<new> <old>" arguments to "upgrade <new>", so prerm stops both services without disabling them and leaves its marker, and post-upgrade exports PKG_UPGRADE=1, as OpenWrt's own package-pack.mk does, so postinst starts fips and starts the gateway only if it was enabled. Registering post-upgrade alone would not have been enough: procd ignores a start of a running instance whose command line is unchanged, so the services have to be stopped first. testing/openwrt/package-test.sh runs the real build-apk.sh on the host against a stub apk and checks the registered phases, the #! lines, that the install and removal scripts are the shipped bodies, and, by executing each wrapper's header with apk's argv and environment, that the upgrade pair hands the bodies the right arguments. The ash harness runs it first and then runs the captured scripts in three new apk scenarios, and the packaging workflow's apk structural check now requires all four scripts in the adbdump. An upgrade onto a package built this way was run on OpenWrt 25.12.2 with its apk-tools 3.0.5: apk ran both pre-upgrade and post-upgrade, and both came from the incoming package. The adbdump key format the workflow check matches, each script as a "<phase>:" key under scripts:, was read from the apk-tools v3.0.5 source (src/serialize_yaml.c), the tag the packaging workflow builds from source. It matches the dump that source-built 3.0.5 printed for this change in the packaging workflow, where all four scripts appeared under scripts: and passed the check on both architectures. OpenWrt's own apk-tools 3.0.5 is built without mkpkg, and on a router adbdump cannot read the installed database and info has no --scripts, so which scripts an installed package registered cannot be read back on a device. The check covers the built package only.
61 lines
2.4 KiB
Bash
Executable File
61 lines
2.4 KiB
Bash
Executable File
#!/bin/bash
|
|
# ── OpenWrt maintainer-script scenarios ─────────────────────────────────────
|
|
# Runs testing/openwrt/scenarios.sh inside a busybox container, so the package
|
|
# scripts and the fips-gateway init script are interpreted by ash rather than
|
|
# by the host's bash or dash. The scripts ship to routers and are only ever run
|
|
# under ash there; a construct bash accepts and ash does not would otherwise
|
|
# surface on a router.
|
|
#
|
|
# The container is the only reason docker is needed: the scenarios touch no
|
|
# network and no FIPS binary, and they do not use the shared test image.
|
|
#
|
|
# Exit 0 = every scenario passed. Exit 1 = at least one failed. Exit 2 = the
|
|
# harness could not run; never treated as a pass.
|
|
# ─────────────────────────────────────────────────────────────────────────────
|
|
set -uo pipefail
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
|
PROJECT_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
|
|
|
|
# Pinned rather than :latest so the shell under test does not change under a
|
|
# run. Overridable for trying another ash build.
|
|
IMAGE="${OPENWRT_ASH_IMAGE:-busybox:1.37}"
|
|
|
|
if ! command -v docker >/dev/null 2>&1; then
|
|
echo "openwrt-scripts: docker not found; cannot run the ash scenarios" >&2
|
|
exit 2
|
|
fi
|
|
|
|
if [[ ! -f "$SCRIPT_DIR/scenarios.sh" ]]; then
|
|
echo "openwrt-scripts: missing $SCRIPT_DIR/scenarios.sh" >&2
|
|
exit 2
|
|
fi
|
|
|
|
# The .apk wraps the shared bodies for its upgrade path. package-test.sh builds
|
|
# the package on the host with the real build-apk.sh, checks what it registers,
|
|
# and leaves the four scripts here so the scenarios run exactly what ships.
|
|
APK_DIR="$(mktemp -d)" || { echo "openwrt-scripts: mktemp failed" >&2; exit 2; }
|
|
trap 'rm -rf "$APK_DIR"' EXIT
|
|
bash "$SCRIPT_DIR/package-test.sh" --keep "$APK_DIR"
|
|
rc=$?
|
|
if [[ $rc -ne 0 ]]; then
|
|
echo "openwrt-scripts: package-test.sh exited $rc" >&2
|
|
exit $rc
|
|
fi
|
|
|
|
docker run --rm --network none \
|
|
-v "$PROJECT_ROOT:/src:ro" \
|
|
-v "$APK_DIR:/apk:ro" \
|
|
-e REPO=/src \
|
|
-e APK_SCRIPTS=/apk \
|
|
-e "POSTINST=${POSTINST:-}" \
|
|
-e "PRERM=${PRERM:-}" \
|
|
"$IMAGE" sh /src/testing/openwrt/scenarios.sh
|
|
rc=$?
|
|
|
|
if [[ $rc -ne 0 && $rc -ne 1 ]]; then
|
|
echo "openwrt-scripts: the container exited $rc, so the scenarios did not report" >&2
|
|
exit 2
|
|
fi
|
|
exit $rc
|