fix(packaging): add RPM ownership assertions, ghost group fix, and conffile check for #46

- Fix nfpm.yaml ghost directory to include `group: fenris` so RPM metadata
  matches the tmpfiles.d-created ownership (root:fenris 2750)
- Add RPM-native ownership assertions: store dir reported as package-owned
  via `rpm -qf`, store contents verified as never owned by the package
- Add RPM conffile assertion: `rpm -qc` verifies fenris.conf is listed
- Unify store dir stat assertion across both formats (deb and rpm both
  assert mode 2750 root:fenris)
- Remove unused `distro` parameter from `_find_package()`

All 16 packaging tests pass across the full matrix (3 deb + 1 rpm × 4 scenarios).
All 289 non-packaging tests pass.

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
xavierk
2026-09-03 10:18:04 +05:30
co-authored by CommandCodeBot
parent f1e1c0eebc
commit b2243a85f7
2 changed files with 37 additions and 12 deletions
+36 -12
View File
@@ -55,7 +55,7 @@ def _container_exec(container: str, cmd: str) -> tuple[int, str]:
return r.returncode, r.stdout + r.stderr
def _find_package(fmt: str, distro: str | None = None) -> Path:
def _find_package(fmt: str) -> Path:
"""Locate the built package artifact."""
version = _get_version()
if fmt == "deb":
@@ -184,22 +184,46 @@ def _assert_dormant_layout(container: str, fmt: str, version: str) -> None:
assert "device" in out.lower() or "devices" in out.lower() or "#" in out, \
"Config does not appear to be placeholder-commented"
if fmt == "rpm":
# rpm-native: config marked noreplace (not replaced on upgrade)
rc, out = _container_exec(
container,
"rpm -qc fenris 2>/dev/null | grep fenris.conf || true",
)
assert "fenris.conf" in out, "fenris.conf not listed as conffile by RPM"
# fenris group exists
rc, out = _container_exec(container, "getent group fenris")
assert rc == 0, "fenris group not created"
# Observation store directory
if fmt == "deb":
rc, out = _container_exec(container, "stat -c '%a %U %G' /var/lib/fenris")
assert rc == 0, "Observation store directory not created"
parts = out.strip().split()
assert parts[0] == "2750", f"Store dir mode: expected 2750, got {parts[0]}"
assert parts[1] == "root", f"Store dir owner: expected root, got {parts[1]}"
assert parts[2] == "fenris", f"Store dir group: expected fenris, got {parts[2]}"
else:
# rpm: directory owned by package (ghost)
rc, _ = _container_exec(container, "test -d /var/lib/fenris")
assert rc == 0, "Observation store directory not found"
rc, out = _container_exec(container, "stat -c '%a %U %G' /var/lib/fenris")
assert rc == 0, "Observation store directory not created"
parts = out.strip().split()
assert parts[0] == "2750", f"Store dir mode: expected 2750, got {parts[0]}"
assert parts[1] == "root", f"Store dir owner: expected root, got {parts[1]}"
assert parts[2] == "fenris", f"Store dir group: expected fenris, got {parts[2]}"
if fmt == "rpm":
# rpm-native: store dir reported as package-owned (ghost),
# but no contents are owned by the package
rc, out = _container_exec(container, "rpm -qf /var/lib/fenris 2>/dev/null")
assert rc == 0, "Store dir not reported as package-owned by RPM"
assert "fenris" in out.lower(), f"Store dir not owned by fenris package: {out}"
# No files inside the store should be package-owned
rc, out = _container_exec(
container,
"find /var/lib/fenris -mindepth 1 -type f -exec rpm -qf {} \\; 2>&1",
)
# rpm -qf exits 1 for unowned files; we expect all to be unowned
owned = [
line for line in out.strip().splitlines()
if not line.startswith("not owned by any package")
and "is not owned by any package" not in line
and rc == 0
]
assert not owned, f"Store contents owned by RPM (should not be): {owned}"
# Timer is disabled and inactive (dormant)
rc, out = _container_exec(