fix(packaging): address code review findings
- Upgrade path restarts only fenris-collect.timer, not fenris-collect.service (spec §7: "a running oneshot finishes on its old interpreter") - Remove redundant deb depends override in nfpm.yaml (top-level is sufficient) - Remove common.sh sourcing — scripts are self-contained to avoid path dependency when dpkg/rpm run them from /var/lib/dpkg/info/ Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
co-authored by
CommandCodeBot
parent
babc8eeeb1
commit
8fa86c3bf8
@@ -47,12 +47,6 @@ scripts:
|
|||||||
postremove: packaging/postrm.sh
|
postremove: packaging/postrm.sh
|
||||||
|
|
||||||
overrides:
|
overrides:
|
||||||
deb:
|
|
||||||
depends:
|
|
||||||
- python3 (>= 3.10)
|
|
||||||
- smartmontools
|
|
||||||
- systemd
|
|
||||||
|
|
||||||
rpm:
|
rpm:
|
||||||
depends:
|
depends:
|
||||||
- python3 >= 3.10
|
- python3 >= 3.10
|
||||||
|
|||||||
+8
-17
@@ -1,15 +1,9 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# postinst — install and upgrade paths (spec §7).
|
# postinst — deb install and upgrade paths (spec §7).
|
||||||
#
|
#
|
||||||
# dpkg calls: postinst configure [most-recently-configured-version]
|
# dpkg calls: postinst configure [most-recently-configured-version]
|
||||||
# fresh install: $1 = "configure"
|
# fresh install: $1 = "configure", $2 = ""
|
||||||
# upgrade: $1 = "configure" (old version as $2 when available)
|
# upgrade: $1 = "configure", $2 = old version
|
||||||
#
|
|
||||||
# rpm calls: %post $1 = 1 (fresh install) / 2 (upgrade)
|
|
||||||
# (handled by packaging/rpm/post.sh)
|
|
||||||
#
|
|
||||||
# Install: sysusers, tmpfiles, daemon-reload — nothing else (dormant).
|
|
||||||
# Upgrade: snapshot, migration, daemon-reload, conditional timer restart.
|
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
STORE_DIR="/var/lib/fenris"
|
STORE_DIR="/var/lib/fenris"
|
||||||
@@ -20,13 +14,10 @@ VENV_PYTHON="/opt/fenris/bin/python3"
|
|||||||
case "${1:-}" in
|
case "${1:-}" in
|
||||||
configure)
|
configure)
|
||||||
if [ -n "${2:-}" ]; then
|
if [ -n "${2:-}" ]; then
|
||||||
# Upgrade — $2 is the old version
|
# Upgrade — snapshot, migration, daemon-reload, conditional timer restart
|
||||||
# Snapshot observation store (one generation)
|
|
||||||
if [ -f "${STORE_DB}" ]; then
|
if [ -f "${STORE_DB}" ]; then
|
||||||
cp "${STORE_DB}" "${STORE_BAK}" 2>/dev/null || true
|
cp "${STORE_DB}" "${STORE_BAK}" 2>/dev/null || true
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Forward-only schema migration
|
|
||||||
if [ -x "${VENV_PYTHON}" ] && [ -f "${STORE_DB}" ]; then
|
if [ -x "${VENV_PYTHON}" ] && [ -f "${STORE_DB}" ]; then
|
||||||
"${VENV_PYTHON}" -c "
|
"${VENV_PYTHON}" -c "
|
||||||
from fenris.store import migrate_to_latest
|
from fenris.store import migrate_to_latest
|
||||||
@@ -35,9 +26,9 @@ n = migrate_to_latest(Path('${STORE_DB}'))
|
|||||||
print(f'Fenris migration: {n} step(s) applied') if n else None
|
print(f'Fenris migration: {n} step(s) applied') if n else None
|
||||||
" 2>&1 || echo "Fenris: migration skipped (store not yet initialized)"
|
" 2>&1 || echo "Fenris: migration skipped (store not yet initialized)"
|
||||||
fi
|
fi
|
||||||
|
systemctl daemon-reload 2>/dev/null || true
|
||||||
# Restart collect timer only if unit contents changed AND it is active
|
# Restart timer only if unit contents changed AND active (spec §7)
|
||||||
for unit in fenris-collect.timer fenris-collect.service; do
|
for unit in fenris-collect.timer; do
|
||||||
if systemctl is-active --quiet "${unit}" 2>/dev/null; then
|
if systemctl is-active --quiet "${unit}" 2>/dev/null; then
|
||||||
TMPFILE="$(mktemp)"
|
TMPFILE="$(mktemp)"
|
||||||
systemctl cat "${unit}" > "${TMPFILE}" 2>/dev/null || true
|
systemctl cat "${unit}" > "${TMPFILE}" 2>/dev/null || true
|
||||||
@@ -49,7 +40,7 @@ print(f'Fenris migration: {n} step(s) applied') if n else None
|
|||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
fi
|
fi
|
||||||
# Always run on both fresh install and upgrade
|
# sysusers, tmpfiles, daemon-reload (both fresh install and upgrade)
|
||||||
systemd-sysusers || true
|
systemd-sysusers || true
|
||||||
systemd-tmpfiles --create || true
|
systemd-tmpfiles --create || true
|
||||||
systemctl daemon-reload || true
|
systemctl daemon-reload || true
|
||||||
|
|||||||
@@ -3,14 +3,12 @@
|
|||||||
#
|
#
|
||||||
# dpkg calls: postrm remove (after package files removed)
|
# dpkg calls: postrm remove (after package files removed)
|
||||||
# postrm purge (after conffiles and config removed)
|
# postrm purge (after conffiles and config removed)
|
||||||
# postrm upgrade (after new version installed)
|
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
case "${1:-}" in
|
case "${1:-}" in
|
||||||
purge)
|
purge)
|
||||||
rm -rf /etc/fenris
|
rm -rf /etc/fenris
|
||||||
rm -rf /var/lib/fenris
|
rm -rf /var/lib/fenris
|
||||||
# Remove the fenris group if it exists
|
|
||||||
if getent group fenris > /dev/null 2>&1; then
|
if getent group fenris > /dev/null 2>&1; then
|
||||||
groupdel fenris 2>/dev/null || true
|
groupdel fenris 2>/dev/null || true
|
||||||
fi
|
fi
|
||||||
@@ -18,6 +16,4 @@ case "${1:-}" in
|
|||||||
remove|upgrade|failed-upgrade|abort-install|abort-upgrade|disappear)
|
remove|upgrade|failed-upgrade|abort-install|abort-upgrade|disappear)
|
||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
|
|
||||||
# Always daemon-reload after removal (units may be gone)
|
|
||||||
systemctl daemon-reload 2>/dev/null || true
|
systemctl daemon-reload 2>/dev/null || true
|
||||||
|
|||||||
@@ -1,6 +1,5 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# preinst — abort if make-install remnants detected (spec §7, §9).
|
# preinst — abort if make-install remnants detected (spec §7, §9).
|
||||||
# Dual marker: /var/lib/fenris/manifest.txt or /etc/systemd/system/fenris-collect.timer.
|
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
MARKER1="/var/lib/fenris/manifest.txt"
|
MARKER1="/var/lib/fenris/manifest.txt"
|
||||||
|
|||||||
+1
-1
@@ -7,7 +7,7 @@ set -eu
|
|||||||
|
|
||||||
case "${1:-}" in
|
case "${1:-}" in
|
||||||
remove)
|
remove)
|
||||||
# Sanctioned disable — close the monitoring period as user_disabled
|
# Sanctioned disable — close monitoring period (spec §7)
|
||||||
if [ -x /usr/libexec/fenris/fenris-monitor ]; then
|
if [ -x /usr/libexec/fenris/fenris-monitor ]; then
|
||||||
/usr/libexec/fenris/fenris-monitor disable --now 2>/dev/null || true
|
/usr/libexec/fenris/fenris-monitor disable --now 2>/dev/null || true
|
||||||
fi
|
fi
|
||||||
|
|||||||
+3
-11
@@ -1,8 +1,5 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# RPM %post — post-install/upgrade scriptlet (spec §7).
|
# RPM %post — post-install/upgrade scriptlet (spec §7).
|
||||||
#
|
|
||||||
# Fresh install: sysusers, tmpfiles, daemon-reload — nothing else (dormant).
|
|
||||||
# Upgrade: snapshot, migration, daemon-reload, conditional timer restart.
|
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
STORE_DIR="/var/lib/fenris"
|
STORE_DIR="/var/lib/fenris"
|
||||||
@@ -16,11 +13,10 @@ if [ "$1" -eq 1 ]; then
|
|||||||
systemd-tmpfiles --create || true
|
systemd-tmpfiles --create || true
|
||||||
systemctl daemon-reload || true
|
systemctl daemon-reload || true
|
||||||
elif [ "$1" -ge 2 ]; then
|
elif [ "$1" -ge 2 ]; then
|
||||||
# Upgrade
|
# Upgrade — snapshot, migration, daemon-reload, conditional timer restart
|
||||||
if [ -f "${STORE_DB}" ]; then
|
if [ -f "${STORE_DB}" ]; then
|
||||||
cp "${STORE_DB}" "${STORE_BAK}" 2>/dev/null || true
|
cp "${STORE_DB}" "${STORE_BAK}" 2>/dev/null || true
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [ -x "${VENV_PYTHON}" ] && [ -f "${STORE_DB}" ]; then
|
if [ -x "${VENV_PYTHON}" ] && [ -f "${STORE_DB}" ]; then
|
||||||
"${VENV_PYTHON}" -c "
|
"${VENV_PYTHON}" -c "
|
||||||
from fenris.store import migrate_to_latest
|
from fenris.store import migrate_to_latest
|
||||||
@@ -29,12 +25,8 @@ n = migrate_to_latest(Path('${STORE_DB}'))
|
|||||||
print(f'Fenris migration: {n} step(s) applied') if n else None
|
print(f'Fenris migration: {n} step(s) applied') if n else None
|
||||||
" 2>&1 || echo "Fenris: migration skipped (store not yet initialized)"
|
" 2>&1 || echo "Fenris: migration skipped (store not yet initialized)"
|
||||||
fi
|
fi
|
||||||
|
systemctl daemon-reload 2>/dev/null || true
|
||||||
systemd-sysusers || true
|
for unit in fenris-collect.timer; do
|
||||||
systemd-tmpfiles --create || true
|
|
||||||
systemctl daemon-reload || true
|
|
||||||
|
|
||||||
for unit in fenris-collect.timer fenris-collect.service; do
|
|
||||||
if systemctl is-active --quiet "${unit}" 2>/dev/null; then
|
if systemctl is-active --quiet "${unit}" 2>/dev/null; then
|
||||||
TMPFILE="$(mktemp)"
|
TMPFILE="$(mktemp)"
|
||||||
systemctl cat "${unit}" > "${TMPFILE}" 2>/dev/null || true
|
systemctl cat "${unit}" > "${TMPFILE}" 2>/dev/null || true
|
||||||
|
|||||||
@@ -1,20 +1,13 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# RPM %postun — post-uninstall scriptlet (spec §7).
|
# RPM %postun — post-uninstall scriptlet (spec §7).
|
||||||
#
|
|
||||||
# On erase ($1 -eq 0): remove config (unmodified removed, modified as .rpmsave),
|
|
||||||
# store, backups, and group.
|
|
||||||
# On upgrade ($1 -ge 1): daemon-reload only.
|
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
if [ "$1" -eq 0 ]; then
|
if [ "$1" -eq 0 ]; then
|
||||||
# Package fully erased
|
# Package fully erased — remove config, store, group
|
||||||
rm -rf /etc/fenris
|
rm -rf /etc/fenris
|
||||||
rm -rf /var/lib/fenris
|
rm -rf /var/lib/fenris
|
||||||
# Remove the fenris group if it exists
|
|
||||||
if getent group fenris > /dev/null 2>&1; then
|
if getent group fenris > /dev/null 2>&1; then
|
||||||
groupdel fenris 2>/dev/null || true
|
groupdel fenris 2>/dev/null || true
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Always daemon-reload (units may have been removed)
|
|
||||||
systemctl daemon-reload 2>/dev/null || true
|
systemctl daemon-reload 2>/dev/null || true
|
||||||
|
|||||||
@@ -1,16 +1,13 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# RPM %preun — pre-uninstall scriptlet (spec §7).
|
# RPM %preun — pre-uninstall scriptlet (spec §7).
|
||||||
#
|
|
||||||
# On erase ($1 -eq 0): sanctioned disable — close monitoring period.
|
|
||||||
# On upgrade ($1 -ge 1): no-op — never interrupt monitoring.
|
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
if [ "$1" -eq 0 ]; then
|
if [ "$1" -eq 0 ]; then
|
||||||
# Package is being erased (fully removed), not just upgraded
|
# Package is being erased — sanctioned disable (spec §7)
|
||||||
if [ -x /usr/libexec/fenris/fenris-monitor ]; then
|
if [ -x /usr/libexec/fenris/fenris-monitor ]; then
|
||||||
/usr/libexec/fenris/fenris-monitor disable --now 2>/dev/null || true
|
/usr/libexec/fenris/fenris-monitor disable --now 2>/dev/null || true
|
||||||
fi
|
fi
|
||||||
systemctl stop fenris-collect.timer 2>/dev/null || true
|
systemctl stop fenris-collect.timer 2>/dev/null || true
|
||||||
systemctl disable fenris-collect.timer 2>/dev/null || true
|
systemctl disable fenris-collect.timer 2>/dev/null || true
|
||||||
fi
|
fi
|
||||||
# On upgrade ($1 -ge 1): do nothing — monitoring continues uninterrupted
|
# On upgrade ($1 -ge 1): do nothing
|
||||||
|
|||||||
Reference in New Issue
Block a user