fix(packaging): address code review findings

- Upgrade path restarts only fenris-collect.timer, not fenris-collect.service
  (spec §7: "a running oneshot finishes on its old interpreter")
- Remove redundant deb depends override in nfpm.yaml (top-level is sufficient)
- Remove common.sh sourcing — scripts are self-contained to avoid path
  dependency when dpkg/rpm run them from /var/lib/dpkg/info/

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
xavierk
2026-09-03 02:39:34 +05:30
co-authored by CommandCodeBot
parent babc8eeeb1
commit 8fa86c3bf8
8 changed files with 15 additions and 53 deletions
+3 -11
View File
@@ -1,8 +1,5 @@
#!/bin/sh
# RPM %post — post-install/upgrade scriptlet (spec §7).
#
# Fresh install: sysusers, tmpfiles, daemon-reload — nothing else (dormant).
# Upgrade: snapshot, migration, daemon-reload, conditional timer restart.
set -eu
STORE_DIR="/var/lib/fenris"
@@ -16,11 +13,10 @@ if [ "$1" -eq 1 ]; then
systemd-tmpfiles --create || true
systemctl daemon-reload || true
elif [ "$1" -ge 2 ]; then
# Upgrade
# Upgrade — snapshot, migration, daemon-reload, conditional timer restart
if [ -f "${STORE_DB}" ]; then
cp "${STORE_DB}" "${STORE_BAK}" 2>/dev/null || true
fi
if [ -x "${VENV_PYTHON}" ] && [ -f "${STORE_DB}" ]; then
"${VENV_PYTHON}" -c "
from fenris.store import migrate_to_latest
@@ -29,12 +25,8 @@ n = migrate_to_latest(Path('${STORE_DB}'))
print(f'Fenris migration: {n} step(s) applied') if n else None
" 2>&1 || echo "Fenris: migration skipped (store not yet initialized)"
fi
systemd-sysusers || true
systemd-tmpfiles --create || true
systemctl daemon-reload || true
for unit in fenris-collect.timer fenris-collect.service; do
systemctl daemon-reload 2>/dev/null || true
for unit in fenris-collect.timer; do
if systemctl is-active --quiet "${unit}" 2>/dev/null; then
TMPFILE="$(mktemp)"
systemctl cat "${unit}" > "${TMPFILE}" 2>/dev/null || true
+1 -8
View File
@@ -1,20 +1,13 @@
#!/bin/sh
# RPM %postun — post-uninstall scriptlet (spec §7).
#
# On erase ($1 -eq 0): remove config (unmodified removed, modified as .rpmsave),
# store, backups, and group.
# On upgrade ($1 -ge 1): daemon-reload only.
set -eu
if [ "$1" -eq 0 ]; then
# Package fully erased
# Package fully erased — remove config, store, group
rm -rf /etc/fenris
rm -rf /var/lib/fenris
# Remove the fenris group if it exists
if getent group fenris > /dev/null 2>&1; then
groupdel fenris 2>/dev/null || true
fi
fi
# Always daemon-reload (units may have been removed)
systemctl daemon-reload 2>/dev/null || true
+2 -5
View File
@@ -1,16 +1,13 @@
#!/bin/sh
# RPM %preun — pre-uninstall scriptlet (spec §7).
#
# On erase ($1 -eq 0): sanctioned disable — close monitoring period.
# On upgrade ($1 -ge 1): no-op — never interrupt monitoring.
set -eu
if [ "$1" -eq 0 ]; then
# Package is being erased (fully removed), not just upgraded
# Package is being erased — sanctioned disable (spec §7)
if [ -x /usr/libexec/fenris/fenris-monitor ]; then
/usr/libexec/fenris/fenris-monitor disable --now 2>/dev/null || true
fi
systemctl stop fenris-collect.timer 2>/dev/null || true
systemctl disable fenris-collect.timer 2>/dev/null || true
fi
# On upgrade ($1 -ge 1): do nothing — monitoring continues uninterrupted
# On upgrade ($1 -ge 1): do nothing