Files
fips/testing/glibc-floor
Johnathan Corgan 888d393f8b Report inputs the glibc floor check could not examine as unchecked
check-glibc-floor.sh counted a missing path, a file that is not an ELF
object and a .deb with no ELF executables as floor failures, so each
exited 1 with "A binary above the floor installs cleanly and then fails
to start" and the advice to rebuild in the container. Passing a release
tarball, which is the usual mistake, therefore read as a broken release
when nothing had been examined. A .deb that dpkg-deb could not unpack
killed the script under set -e with no summary, leaving later arguments
unexamined.

Those inputs are now recorded as "could not check" with the reason, and
listed at the end. A tarball's reason says to unpack it and pass its
binaries. Exit status is 1 only when a binary is above the floor (still
listing anything unchecked), 2 when anything could not be examined, and
0 only when every input was examined and passed. Neither caller branches
on the status, and both stop on 1 or 2 as before.

Two setup failures also exited 1: a missing packaging/build-floor.env
ended the run through set -e when it was sourced, and an empty
FIPS_GLIBC_FLOOR ended it through the ":?" expansion. The env file is
now read only after a readable-file check, and an empty floor is caught
by an explicit test; both exit 2 with a message saying there is no
floor to check against. The file's shellcheck source directive now
resolves from the script's directory, so shellcheck -x run from the
repository root no longer reports SC1091.

The floor check runs only at release time, so a regression in how it
reports would surface on a release day. testing/glibc-floor/test.sh
builds its inputs at run time from the host's own true executable (a
text file, a tarball holding the binary, a missing path, an unreadable
file, a corrupt .deb, a .deb holding only a script, and a .deb holding
the binary), sets the floor explicitly in every case, and asserts the
exit status, the "could not check" listing and the presence or absence
of the rebuild advice. Scratch copies of the check cover a missing
build-floor.env, an empty floor, a file that declares none, and one
whose file supplies a floor. The test exits 2 rather than passing when
readelf, dpkg-deb or a dynamic true is missing. ci-local.sh runs it
beside the Debian version check, and ci.yml's static job runs the same
script.
2026-10-01 22:40:40 +00:00
..