mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
The OpenWrt upgrade fixture was the fips.yaml from the commit before the gateway's DNS port moved, not one any release shipped. Replace it with the v0.5.1 bytes and say which releases it stands for, since v0.3.0 to v0.4.2 shipped an older file with the same legacy listen line. busybox:1.37 moves with every 1.37.x rebuild, so the pin did not keep the shell under test fixed as its comment said. Pin the multi-arch index digest instead, as the tree does for its other third-party images. The comment describing run_ci_parity had drifted above run_openwrt_scripts; move it back to its function. The deb-install header named `apt install` where the script runs `apt-get install -y --no-install-recommends`, and its usage line omitted the --deb option the script accepts. Nothing in the tree read the package's Recommends: the Depends check compares Depends only, and the install test installs with --no-install-recommends. check-deb-depends.sh now compares each package's Recommends with the recommends Cargo.toml declares, in any order, and refuses to pass when that declaration cannot be read.