fix(packaging): address code review findings

- Upgrade path restarts only fenris-collect.timer, not fenris-collect.service
  (spec §7: "a running oneshot finishes on its old interpreter")
- Remove redundant deb depends override in nfpm.yaml (top-level is sufficient)
- Remove common.sh sourcing — scripts are self-contained to avoid path
  dependency when dpkg/rpm run them from /var/lib/dpkg/info/

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
xavierk
2026-09-03 02:39:34 +05:30
co-authored by CommandCodeBot
parent babc8eeeb1
commit 8fa86c3bf8
8 changed files with 15 additions and 53 deletions
-6
View File
@@ -47,12 +47,6 @@ scripts:
postremove: packaging/postrm.sh
overrides:
deb:
depends:
- python3 (>= 3.10)
- smartmontools
- systemd
rpm:
depends:
- python3 >= 3.10
+8 -17
View File
@@ -1,15 +1,9 @@
#!/bin/sh
# postinst — install and upgrade paths (spec §7).
# postinst — deb install and upgrade paths (spec §7).
#
# dpkg calls: postinst configure [most-recently-configured-version]
# fresh install: $1 = "configure"
# upgrade: $1 = "configure" (old version as $2 when available)
#
# rpm calls: %post $1 = 1 (fresh install) / 2 (upgrade)
# (handled by packaging/rpm/post.sh)
#
# Install: sysusers, tmpfiles, daemon-reload — nothing else (dormant).
# Upgrade: snapshot, migration, daemon-reload, conditional timer restart.
# fresh install: $1 = "configure", $2 = ""
# upgrade: $1 = "configure", $2 = old version
set -eu
STORE_DIR="/var/lib/fenris"
@@ -20,13 +14,10 @@ VENV_PYTHON="/opt/fenris/bin/python3"
case "${1:-}" in
configure)
if [ -n "${2:-}" ]; then
# Upgrade — $2 is the old version
# Snapshot observation store (one generation)
# Upgrade — snapshot, migration, daemon-reload, conditional timer restart
if [ -f "${STORE_DB}" ]; then
cp "${STORE_DB}" "${STORE_BAK}" 2>/dev/null || true
fi
# Forward-only schema migration
if [ -x "${VENV_PYTHON}" ] && [ -f "${STORE_DB}" ]; then
"${VENV_PYTHON}" -c "
from fenris.store import migrate_to_latest
@@ -35,9 +26,9 @@ n = migrate_to_latest(Path('${STORE_DB}'))
print(f'Fenris migration: {n} step(s) applied') if n else None
" 2>&1 || echo "Fenris: migration skipped (store not yet initialized)"
fi
# Restart collect timer only if unit contents changed AND it is active
for unit in fenris-collect.timer fenris-collect.service; do
systemctl daemon-reload 2>/dev/null || true
# Restart timer only if unit contents changed AND active (spec §7)
for unit in fenris-collect.timer; do
if systemctl is-active --quiet "${unit}" 2>/dev/null; then
TMPFILE="$(mktemp)"
systemctl cat "${unit}" > "${TMPFILE}" 2>/dev/null || true
@@ -49,7 +40,7 @@ print(f'Fenris migration: {n} step(s) applied') if n else None
fi
done
fi
# Always run on both fresh install and upgrade
# sysusers, tmpfiles, daemon-reload (both fresh install and upgrade)
systemd-sysusers || true
systemd-tmpfiles --create || true
systemctl daemon-reload || true
-4
View File
@@ -3,14 +3,12 @@
#
# dpkg calls: postrm remove (after package files removed)
# postrm purge (after conffiles and config removed)
# postrm upgrade (after new version installed)
set -eu
case "${1:-}" in
purge)
rm -rf /etc/fenris
rm -rf /var/lib/fenris
# Remove the fenris group if it exists
if getent group fenris > /dev/null 2>&1; then
groupdel fenris 2>/dev/null || true
fi
@@ -18,6 +16,4 @@ case "${1:-}" in
remove|upgrade|failed-upgrade|abort-install|abort-upgrade|disappear)
;;
esac
# Always daemon-reload after removal (units may be gone)
systemctl daemon-reload 2>/dev/null || true
-1
View File
@@ -1,6 +1,5 @@
#!/bin/sh
# preinst — abort if make-install remnants detected (spec §7, §9).
# Dual marker: /var/lib/fenris/manifest.txt or /etc/systemd/system/fenris-collect.timer.
set -eu
MARKER1="/var/lib/fenris/manifest.txt"
+1 -1
View File
@@ -7,7 +7,7 @@ set -eu
case "${1:-}" in
remove)
# Sanctioned disable — close the monitoring period as user_disabled
# Sanctioned disable — close monitoring period (spec §7)
if [ -x /usr/libexec/fenris/fenris-monitor ]; then
/usr/libexec/fenris/fenris-monitor disable --now 2>/dev/null || true
fi
+3 -11
View File
@@ -1,8 +1,5 @@
#!/bin/sh
# RPM %post — post-install/upgrade scriptlet (spec §7).
#
# Fresh install: sysusers, tmpfiles, daemon-reload — nothing else (dormant).
# Upgrade: snapshot, migration, daemon-reload, conditional timer restart.
set -eu
STORE_DIR="/var/lib/fenris"
@@ -16,11 +13,10 @@ if [ "$1" -eq 1 ]; then
systemd-tmpfiles --create || true
systemctl daemon-reload || true
elif [ "$1" -ge 2 ]; then
# Upgrade
# Upgrade — snapshot, migration, daemon-reload, conditional timer restart
if [ -f "${STORE_DB}" ]; then
cp "${STORE_DB}" "${STORE_BAK}" 2>/dev/null || true
fi
if [ -x "${VENV_PYTHON}" ] && [ -f "${STORE_DB}" ]; then
"${VENV_PYTHON}" -c "
from fenris.store import migrate_to_latest
@@ -29,12 +25,8 @@ n = migrate_to_latest(Path('${STORE_DB}'))
print(f'Fenris migration: {n} step(s) applied') if n else None
" 2>&1 || echo "Fenris: migration skipped (store not yet initialized)"
fi
systemd-sysusers || true
systemd-tmpfiles --create || true
systemctl daemon-reload || true
for unit in fenris-collect.timer fenris-collect.service; do
systemctl daemon-reload 2>/dev/null || true
for unit in fenris-collect.timer; do
if systemctl is-active --quiet "${unit}" 2>/dev/null; then
TMPFILE="$(mktemp)"
systemctl cat "${unit}" > "${TMPFILE}" 2>/dev/null || true
+1 -8
View File
@@ -1,20 +1,13 @@
#!/bin/sh
# RPM %postun — post-uninstall scriptlet (spec §7).
#
# On erase ($1 -eq 0): remove config (unmodified removed, modified as .rpmsave),
# store, backups, and group.
# On upgrade ($1 -ge 1): daemon-reload only.
set -eu
if [ "$1" -eq 0 ]; then
# Package fully erased
# Package fully erased — remove config, store, group
rm -rf /etc/fenris
rm -rf /var/lib/fenris
# Remove the fenris group if it exists
if getent group fenris > /dev/null 2>&1; then
groupdel fenris 2>/dev/null || true
fi
fi
# Always daemon-reload (units may have been removed)
systemctl daemon-reload 2>/dev/null || true
+2 -5
View File
@@ -1,16 +1,13 @@
#!/bin/sh
# RPM %preun — pre-uninstall scriptlet (spec §7).
#
# On erase ($1 -eq 0): sanctioned disable — close monitoring period.
# On upgrade ($1 -ge 1): no-op — never interrupt monitoring.
set -eu
if [ "$1" -eq 0 ]; then
# Package is being erased (fully removed), not just upgraded
# Package is being erased — sanctioned disable (spec §7)
if [ -x /usr/libexec/fenris/fenris-monitor ]; then
/usr/libexec/fenris/fenris-monitor disable --now 2>/dev/null || true
fi
systemctl stop fenris-collect.timer 2>/dev/null || true
systemctl disable fenris-collect.timer 2>/dev/null || true
fi
# On upgrade ($1 -ge 1): do nothing — monitoring continues uninterrupted
# On upgrade ($1 -ge 1): do nothing