feat: ship fenris-monitor helper, polkit policy, and systemd units (#29)

This commit is contained in:
xavierk
2026-09-02 10:27:56 +05:30
parent a2f7b6232b
commit bc9b2f8940
8 changed files with 1106 additions and 0 deletions
+162
View File
@@ -0,0 +1,162 @@
# Fenris Makefile
# Spec: §10.1-10.6
SHELL := /bin/bash
PYTHON := python3
VENV_DIR := /opt/fenris
BIN_DIR := /usr/local/bin
LIBEXEC_DIR := /usr/libexec/fenris
UNIT_DIR := /etc/systemd/system
POLKIT_DIR := /usr/share/polkit-1/actions
CONF_DIR := /etc/fenris
DATA_DIR := /var/lib/fenris
# Placement manifest
MANIFEST := manifest.txt
.PHONY: help install upgrade uninstall purge update-deps test lint
help:
@echo "Fenris NVMe endurance monitor"
@echo ""
@echo "Targets:"
@echo " install - Install Fenris (builds wheel, installs to /opt/fenris)"
@echo " upgrade - Upgrade Fenris (reinstall wheel, sync units)"
@echo " uninstall - Uninstall Fenris (preserves config and store)"
@echo " purge - Remove everything including config and store"
@echo " test - Run tests"
@echo " lint - Run linter"
@echo " update-deps - Update dependency pins"
# ─── Build ──────────────────────────────────────────────────────────────────
dist/fenris-*.whl: pyproject.toml src/fenris/*.py
@mkdir -p dist
$(PYTHON) -m build --wheel -o dist
# ─── Install ────────────────────────────────────────────────────────────────
install: dist/fenris-*.whl
@echo "=== Verifying prerequisites ==="
@$(PYTHON) --version 2>/dev/null || (echo "Error: python3 not found"; exit 1)
@smartctl --version 2>/dev/null | head -1 || (echo "Error: smartctl not found"; exit 1)
@echo "=== Creating directories ==="
@sudo mkdir -p $(LIBEXEC_DIR)
@sudo mkdir -p $(CONF_DIR)
@sudo mkdir -p $(DATA_DIR)
@sudo mkdir -p $(POLKIT_DIR)
@echo "=== Creating data directory ==="
@sudo install -d -o root -g fenris -m 2750 $(DATA_DIR) 2>/dev/null || sudo groupadd -f fenris && sudo install -d -o root -g fenris -m 2750 $(DATA_DIR)
@echo "=== Installing venv ==="
@sudo rm -rf $(VENV_DIR)
@sudo $(PYTHON) -m venv $(VENV_DIR)
@sudo $(VENV_DIR)/bin/pip install --upgrade pip
@sudo $(VENV_DIR)/bin/pip install dist/fenris-*.whl
@echo "=== Installing wrapper ==="
@sudo install -m 0755 scripts/fenris $(BIN_DIR)/fenris
@echo "=== Installing helpers ==="
@sudo install -m 0755 src/fenris/monitor.py $(LIBEXEC_DIR)/fenris-monitor
@sudo install -m 0755 src/fenris/collect.py $(LIBEXEC_DIR)/fenris-collect
@echo "=== Installing systemd units ==="
@sudo install -m 0644 units/fenris-collect.timer $(UNIT_DIR)/
@sudo install -m 0644 units/fenris-collect.service $(UNIT_DIR)/
@sudo systemctl daemon-reload
@echo "=== Installing polkit policy ==="
@sudo install -m 0644 polkit/com.bongbetic.fenris.monitor.policy $(POLKIT_DIR)/
@echo "=== Creating manifest ==="
@echo "# Fenris placement manifest - do not edit" > $(MANIFEST)
@echo "# Generated by install target" >> $(MANIFEST)
@echo "$(BIN_DIR)/fenris" >> $(MANIFEST)
@echo "$(LIBEXEC_DIR)/fenris-monitor" >> $(MANIFEST)
@echo "$(LIBEXEC_DIR)/fenris-collect" >> $(MANIFEST)
@echo "$(UNIT_DIR)/fenris-collect.timer" >> $(MANIFEST)
@echo "$(UNIT_DIR)/fenris-collect.service" >> $(MANIFEST)
@echo "$(POLKIT_DIR)/com.bongbetic.fenris.monitor.policy" >> $(MANIFEST)
@echo "$(VENV_DIR)" >> $(MANIFEST)
@echo "$(DATA_DIR)" >> $(MANIFEST)
@echo "=== Install complete ==="
@echo "Units installed but NOT enabled or started."
@echo "To start monitoring: fenris monitor resume"
# ─── Upgrade ────────────────────────────────────────────────────────────────
upgrade: dist/fenris-*.whl
@echo "=== Upgrading Fenris ==="
@echo "=== Installing new wheel ==="
@sudo $(VENV_DIR)/bin/pip install dist/fenris-*.whl
@echo "=== Syncing units ==="
@sudo install -m 0644 units/fenris-collect.timer $(UNIT_DIR)/
@sudo install -m 0644 units/fenris-collect.service $(UNIT_DIR)/
@sudo install -m 0644 polkit/com.bongbetic.fenris.monitor.policy $(POLKIT_DIR)/
@sudo install -m 0755 scripts/fenris $(BIN_DIR)/fenris
@sudo install -m 0755 src/fenris/monitor.py $(LIBEXEC_DIR)/fenris-monitor
@sudo install -m 0755 src/fenris/collect.py $(LIBEXEC_DIR)/fenris-collect
@sudo systemctl daemon-reload
# Restart timer only if active and contents changed
@if systemctl is-active --quiet fenris-collect.timer; then echo "=== Restarting timer (active) ==="; sudo systemctl restart fenris-collect.timer; fi
@echo "=== Upgrade complete ==="
# ─── Uninstall ──────────────────────────────────────────────────────────────
uninstall:
@echo "=== Uninstalling Fenris ==="
# Sanctioned disable first (§10.4)
@if [ -x $(LIBEXEC_DIR)/fenris-monitor ]; then echo "=== Performing sanctioned disable ==="; sudo $(LIBEXEC_DIR)/fenris-monitor disable --now || true; fi
# Stop and disable units
@echo "=== Stopping units ==="
@sudo systemctl stop fenris-collect.timer 2>/dev/null || true
@sudo systemctl disable fenris-collect.timer 2>/dev/null || true
@sudo systemctl daemon-reload
# Remove installed files (preserving /etc/fenris and /var/lib/fenris)
@echo "=== Removing files ==="
@-rm -f $(BIN_DIR)/fenris
@-rm -f $(LIBEXEC_DIR)/fenris-monitor
@-rm -f $(LIBEXEC_DIR)/fenris-collect
@-rmdir $(LIBEXEC_DIR) 2>/dev/null || true
@-rm -f $(UNIT_DIR)/fenris-collect.timer
@-rm -f $(UNIT_DIR)/fenris-collect.service
@-rm -f $(POLKIT_DIR)/com.bongbetic.fenris.monitor.policy
@sudo rm -rf $(VENV_DIR)
@-rm -f $(MANIFEST)
@echo "=== Uninstall complete ==="
@echo "Config preserved at $(CONF_DIR)"
@echo "Store preserved at $(DATA_DIR)"
# ─── Purge ──────────────────────────────────────────────────────────────────
purge: uninstall
@echo "=== Purging Fenris ==="
@-sudo rm -rf $(CONF_DIR)
@-sudo rm -rf $(DATA_DIR)
@echo "=== Purge complete ==="
# ─── Test ───────────────────────────────────────────────────────────────────
test:
$(PYTHON) -m pytest tests/ -v
# ─── Lint ───────────────────────────────────────────────────────────────────
lint:
$(PYTHON) -m ruff check src/ tests/
# ─── Dependencies ───────────────────────────────────────────────────────────
update-deps:
$(PYTHON) -m pip compile pyproject.toml -o requirements.txt
@@ -0,0 +1,21 @@
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE policyconfig PUBLIC
"-//freedesktop//DTD PolicyKit Policy Configuration 1.0//EN"
"http://www.freedesktop.org/standards/PolicyKit/1/policyconfig.dtd">
<policyconfig>
<vendor>bongbetic</vendor>
<vendor_url>https://bongbetic.com</vendor_url>
<action id="com.bongbetic.fenris.monitor">
<description>Fenris Monitor Helper</description>
<message>Authentication is required to manage Fenris monitoring.</message>
<defaults>
<allow_any>no</allow_any>
<allow_inactive>no</allow_inactive>
<allow_active>auth_admin</allow_active>
</defaults>
<annotate key="org.freedesktop.policykit.imply">org.freedesktop.systemd1.manage-units</annotate>
</action>
</policyconfig>
Executable
+178
View File
@@ -0,0 +1,178 @@
#!/usr/bin/env python3
"""fenris: unprivileged entry point for the Fenris TUI and CLI.
With no arguments, opens the TUI.
Subcommands route through fenris-monitor for privileged operations.
Spec: §1.2, §8.4
"""
import argparse
import os
import subprocess
import sys
def is_root() -> bool:
"""Check if running as root."""
return os.geteuid() == 0
def run_monitor(*args: str) -> None:
"""Run fenris-monitor with the given arguments.
If not root, re-exec under pkexec.
"""
monitor_cmd = "/usr/libexec/fenris/fenris-monitor"
if is_root():
result = subprocess.run([monitor_cmd] + list(args))
sys.exit(result.returncode)
else:
# Use pkexec to elevate
pkexec = subprocess.run(
["which", "pkexec"], capture_output=True
)
if pkexec.returncode != 0:
print(
"Error: No polkit agent available. "
"Run as root: sudo fenris-monitor ...",
file=sys.stderr,
)
sys.exit(1)
result = subprocess.run(["pkexec", monitor_cmd] + list(args))
sys.exit(result.returncode)
def cmd_tui(args: argparse.Namespace) -> None:
"""Open the TUI."""
from fenris.tui import run_tui
run_tui()
def cmd_status(args: argparse.Namespace) -> None:
"""Show status."""
from fenris.status import print_status
print_status()
def cmd_sample(args: argparse.Namespace) -> None:
"""Trigger on-demand collection."""
run_monitor("collect")
def cmd_monitor_pause(args: argparse.Namespace) -> None:
"""Pause monitoring."""
# Pause asks confirmation (§7.4)
if not args.yes:
response = input("Pause monitoring? [y/N] ")
if response.lower() not in ("y", "yes"):
print("Aborted.")
return
run_monitor("disable", "--now")
def cmd_monitor_resume(args: argparse.Namespace) -> None:
"""Resume monitoring."""
# Resume does not ask confirmation (§7.4)
run_monitor("enable", "--now")
def cmd_baseline_set(args: argparse.Namespace) -> None:
"""Set baseline."""
run_monitor("baseline", "set", args.baseline_json)
def cmd_baseline_clear(args: argparse.Namespace) -> None:
"""Clear baseline."""
run_monitor("baseline", "clear")
def cmd_import(args: argparse.Namespace) -> None:
"""Import legacy history."""
# This is a one-off migration, not a privileged operation
print("Legacy import: use fenris-import directly")
def main() -> None:
parser = argparse.ArgumentParser(
prog="fenris",
description="Fenris NVMe endurance monitor",
)
parser.add_argument(
"--version", action="version", version="%(prog)s 0.3.0"
)
subparsers = parser.add_subparsers(dest="command")
# Default: TUI (no subcommand)
subparsers.add_parser("tui", help="Open the TUI (default)")
# Status
subparsers.add_parser("status", help="Show status")
# Sample (on-demand collection)
subparsers.add_parser("sample", help="Trigger on-demand collection")
# Monitor subcommand
monitor_parser = subparsers.add_parser("monitor", help="Monitor control")
monitor_sub = monitor_parser.add_subparsers(dest="monitor_action")
# monitor pause
pause_parser = monitor_sub.add_parser("pause", help="Pause monitoring")
pause_parser.add_argument(
"-y", "--yes", action="store_true", help="Skip confirmation"
)
pause_parser.set_defaults(func=cmd_monitor_pause)
# monitor resume
resume_parser = monitor_sub.add_parser("resume", help="Resume monitoring")
resume_parser.set_defaults(func=cmd_monitor_resume)
# Baseline subcommand
baseline_parser = subparsers.add_parser("baseline", help="Baseline operations")
baseline_sub = baseline_parser.add_subparsers(dest="baseline_action")
baseline_set = baseline_sub.add_parser("set", help="Set baseline")
baseline_set.add_argument("baseline_json", help="Baseline JSON data")
baseline_set.set_defaults(func=cmd_baseline_set)
baseline_clear = baseline_sub.add_parser("clear", help="Clear baseline")
baseline_clear.set_defaults(func=cmd_baseline_clear)
# Import
import_parser = subparsers.add_parser("import", help="Import legacy history")
import_parser.add_argument("path", help="Path to history.jsonl")
import_parser.set_defaults(func=cmd_import)
# Rejected commands
for cmd in ["start", "stop", "run"]:
reject_parser = subparsers.add_parser(cmd, help=argparse.SUPPRESS)
reject_parser.set_defaults(func=lambda a: print(
f"'{cmd}' is not a valid command. "
f"Use 'fenris monitor resume' instead.",
file=sys.stderr,
))
args = parser.parse_args()
if args.command is None or args.command == "tui":
cmd_tui(args)
elif args.command == "status":
cmd_status(args)
elif args.command == "sample":
cmd_sample(args)
elif args.command == "monitor":
if args.monitor_action is None:
monitor_parser.error("a subcommand is required")
args.func(args)
elif args.command == "baseline":
if args.baseline_action is None:
baseline_parser.error("a subcommand is required")
args.func(args)
elif args.command == "import":
cmd_import(args)
if __name__ == "__main__":
main()
+132
View File
@@ -0,0 +1,132 @@
#!/usr/bin/env python3
"""fenris-collect: device interrogation and store writes.
This is the root oneshot unit's ExecStart. It reads the device selector
from /etc/fenris/fenris.conf, interrogates the drive via smartctl and sysfs,
and writes the sample to the observation store.
Spec: §8.4, §8.5
When run as a script, uses the fenris package from the installed wheel.
"""
import json
import subprocess
import sys
from datetime import datetime, timezone
from pathlib import Path
# Add the venv to path if running from the installed location
VENV_DIR = Path("/opt/fenris")
if VENV_DIR.exists():
site_packages = next((VENV_DIR / "lib").glob("python*/site-packages"), None)
if site_packages:
sys.path.insert(0, str(site_packages))
from fenris.store import init_store, get_store_path
from fenris.collector import run_collection
CONFIG_PATH = Path("/etc/fenris/fenris.conf")
def load_config() -> dict:
"""Load configuration from /etc/fenris/fenris.conf.
The file holds exactly one key: the device selector.
Spec §8.3: re-read every run; no reload path.
"""
if not CONFIG_PATH.exists():
raise RuntimeError(f"Configuration file not found: {CONFIG_PATH}")
config = {}
try:
with open(CONFIG_PATH, "r") as f:
for line in f:
line = line.strip()
if not line or line.startswith("#"):
continue
if "=" in line:
key, value = line.split("=", 1)
config[key.strip()] = value.strip()
except Exception as e:
raise RuntimeError(f"Failed to read configuration: {e}")
if "device" not in config:
raise RuntimeError("Configuration error: missing 'device' key")
return config
def interrogate_drive(device: str) -> dict:
"""Interrogate the drive via smartctl.
Returns the smartctl JSON output.
Raises RuntimeError on failure.
"""
result = subprocess.run(
["smartctl", "-a", "-j", device],
capture_output=True,
text=True,
)
if result.returncode != 0:
raise RuntimeError(
f"smartctl failed for {device}: {result.stderr}"
)
try:
return json.loads(result.stdout)
except json.JSONDecodeError as e:
raise RuntimeError(f"Failed to parse smartctl output: {e}")
def find_nvme_sysfs() -> Path | None:
"""Find the NVMe controller sysfs path."""
nvme_ctrl = Path("/sys/class/nvme")
if not nvme_ctrl.exists():
return None
for ctrl in sorted(nvme_ctrl.iterdir()):
if ctrl.name.startswith("nvme"):
return ctrl
return None
def main() -> None:
"""Run one collection cycle."""
try:
config = load_config()
device = config["device"]
# Interrogate the drive
smartctl_data = interrogate_drive(device)
# Find sysfs path
sysfs_path = find_nvme_sysfs()
if sysfs_path is None:
raise RuntimeError("No NVMe controller found in sysfs")
# Inject a simple clock
class SimpleClock:
def utcnow(self):
return datetime.now(timezone.utc)
clock = SimpleClock()
# Run collection
result = run_collection(smartctl_data, sysfs_path, config, clock)
if result["ok"]:
print(f"Collection successful: {result['sample_count']} sample(s)")
sys.exit(0)
else:
print(f"Collection failed: {result['error']}", file=sys.stderr)
sys.exit(1)
except Exception as e:
print(f"Collection error: {e}", file=sys.stderr)
sys.exit(1)
if __name__ == "__main__":
main()
+282
View File
@@ -0,0 +1,282 @@
#!/usr/bin/env python3
"""fenris-monitor: privileged helper for toggle, collect, and baseline operations.
This binary is the ONLY sanctioned control path for:
- enable/disable (toggle) with monitoring-period bookkeeping
- on-demand collection trigger
- baseline set/clear persistence
Polkit authorizes this binary under com.bongbetic.fenris.monitor (auth_admin).
Spec: §8.4, §8.5, §8.6, §8.7
When run as a script, uses the fenris package from the installed wheel.
"""
import argparse
import json
import os
import subprocess
import sys
import sqlite3
from datetime import datetime, timezone
from pathlib import Path
# Add the venv to path if running from the installed location
VENV_DIR = Path("/opt/fenris")
if VENV_DIR.exists():
site_packages = next((VENV_DIR / "lib").glob("python*/site-packages"), None)
if site_packages:
sys.path.insert(0, str(site_packages))
from fenris.store import init_store, get_store_path
from fenris.monitoring_periods import (
ensure_period_open,
close_period,
get_open_period,
)
DEFAULT_STORE_PATH = Path("/var/lib/fenris/observations.db")
def is_root() -> bool:
"""Check if running as root."""
return os.geteuid() == 0
def cmd_enable(args: argparse.Namespace) -> None:
"""Enable monitoring: enable timer + open monitoring period.
Idempotent matrix (§8.6):
- First-ever enable: opens a period at the enable moment
- Resume with open period: no-op (gap stays inside as unknown)
- Resume with no open period: opens a new row
"""
store_path = getattr(args, 'store_path', DEFAULT_STORE_PATH)
if not store_path.exists():
print("Error: Observation store not found at", store_path, file=sys.stderr)
sys.exit(1)
conn = init_store(store_path)
now = datetime.now(timezone.utc)
try:
# Open monitoring period if none exists (§8.6)
open_period = get_open_period(conn)
if open_period is None:
ensure_period_open(conn, now)
print("Monitoring period opened at", now.isoformat())
else:
print("Monitoring period already open (id=%d)" % open_period["id"])
# Enable and start the timer
if args.now:
result = subprocess.run(
["systemctl", "enable", "--now", "fenris-collect.timer"],
capture_output=True,
text=True,
)
else:
result = subprocess.run(
["systemctl", "enable", "fenris-collect.timer"],
capture_output=True,
text=True,
)
if result.returncode != 0:
print("Error enabling timer:", result.stderr, file=sys.stderr)
sys.exit(1)
print("Timer enabled" + (" and started" if args.now else ""))
finally:
conn.close()
def cmd_disable(args: argparse.Namespace) -> None:
"""Disable monitoring: disable timer + close monitoring period.
Idempotent matrix (§8.6):
- Pause with open period: closes it user_disabled
- Pause otherwise: no-op
"""
store_path = getattr(args, 'store_path', DEFAULT_STORE_PATH)
if not store_path.exists():
print("Error: Observation store not found at", store_path, file=sys.stderr)
sys.exit(1)
conn = init_store(store_path)
now = datetime.now(timezone.utc)
try:
# Close monitoring period if open (§8.6)
open_period = get_open_period(conn)
if open_period is not None:
close_period(conn, now, "user_disabled")
print("Monitoring period closed (id=%d)" % open_period["id"])
else:
print("No open monitoring period (no-op)")
# Disable and stop the timer
if args.now:
result = subprocess.run(
["systemctl", "disable", "--now", "fenris-collect.timer"],
capture_output=True,
text=True,
)
else:
result = subprocess.run(
["systemctl", "disable", "fenris-collect.timer"],
capture_output=True,
text=True,
)
if result.returncode != 0:
print("Error disabling timer:", result.stderr, file=sys.stderr)
sys.exit(1)
print("Timer disabled" + (" and stopped" if args.now else ""))
finally:
conn.close()
def cmd_collect(args: argparse.Namespace) -> None:
"""Trigger on-demand collection.
Starts fenris-collect.service, blocks until exit, reports outcome.
Spec §8.7: fenris sample routes through fenris-monitor → systemctl start,
which blocks until the oneshot exits; outcome reported synchronously.
"""
result = subprocess.run(
["systemctl", "start", "fenris-collect.service"],
capture_output=True,
text=True,
)
if result.returncode == 0:
print("Collection completed successfully")
else:
print("Collection failed:", result.stderr, file=sys.stderr)
sys.exit(1)
def cmd_baseline_set(args: argparse.Namespace) -> None:
"""Persist a baseline row after CLI-side validation.
Spec §8.4: fenris-monitor persists CLI-validated baseline rows.
Spec PR-14: baseline set persists through polkit-guarded helper.
"""
store_path = getattr(args, 'store_path', DEFAULT_STORE_PATH)
if not store_path.exists():
print("Error: Observation store not found at", store_path, file=sys.stderr)
sys.exit(1)
conn = init_store(store_path)
now = datetime.now(timezone.utc)
try:
# Parse and validate baseline data
data = json.loads(args.baseline_json)
required_fields = [
"tbw_terabytes",
"source_url",
"document_revision",
"entry_date",
"model_string",
"nominal_capacity_bytes",
]
for field in required_fields:
if field not in data:
print(f"Error: Missing required field: {field}", file=sys.stderr)
sys.exit(1)
# One active row replaced on edit (§6.2)
conn.execute("DELETE FROM endurance_baseline")
conn.execute(
"""
INSERT INTO endurance_baseline (
tbw_terabytes, source_url, document_revision,
entry_date, model_string, nominal_capacity_bytes,
validated_by, verified, created_at, updated_at
) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
""",
(
data["tbw_terabytes"],
data["source_url"],
data["document_revision"],
data["entry_date"],
data["model_string"],
data["nominal_capacity_bytes"],
data.get("validated_by", "user"),
data.get("verified", False),
now.isoformat(),
now.isoformat(),
),
)
conn.commit()
print("Baseline persisted")
finally:
conn.close()
def cmd_baseline_clear(args: argparse.Namespace) -> None:
"""Clear the endurance baseline.
Spec PR-14: baseline clear persists through polkit-guarded helper.
"""
store_path = getattr(args, 'store_path', DEFAULT_STORE_PATH)
if not store_path.exists():
print("Error: Observation store not found at", store_path, file=sys.stderr)
sys.exit(1)
conn = init_store(store_path)
try:
conn.execute("DELETE FROM endurance_baseline")
conn.commit()
print("Baseline cleared")
finally:
conn.close()
def main() -> None:
parser = argparse.ArgumentParser(
prog="fenris-monitor",
description="Fenris privileged helper for toggle, collect, and baseline operations.",
)
subparsers = parser.add_subparsers(dest="command", required=True)
# enable/disable
enable_parser = subparsers.add_parser("enable", help="Enable monitoring")
enable_parser.add_argument(
"--now", action="store_true", help="Also start the timer immediately"
)
enable_parser.set_defaults(func=cmd_enable)
disable_parser = subparsers.add_parser("disable", help="Disable monitoring")
disable_parser.add_argument(
"--now", action="store_true", help="Also stop the timer immediately"
)
disable_parser.set_defaults(func=cmd_disable)
# collect
collect_parser = subparsers.add_parser("collect", help="Trigger on-demand collection")
collect_parser.set_defaults(func=cmd_collect)
# baseline
baseline_parser = subparsers.add_parser("baseline", help="Baseline operations")
baseline_sub = baseline_parser.add_subparsers(dest="baseline_action", required=True)
baseline_set = baseline_sub.add_parser("set", help="Persist baseline")
baseline_set.add_argument("baseline_json", help="Baseline JSON data")
baseline_set.set_defaults(func=cmd_baseline_set)
baseline_clear = baseline_sub.add_parser("clear", help="Clear baseline")
baseline_clear.set_defaults(func=cmd_baseline_clear)
args = parser.parse_args()
args.func(args)
if __name__ == "__main__":
main()
+310
View File
@@ -0,0 +1,310 @@
"""Tests for fenris-monitor helper.
Spec: §8.4, §8.5, §8.6, §8.7
"""
import json
import sqlite3
from datetime import datetime, timezone
from pathlib import Path
from unittest.mock import patch, MagicMock
import pytest
import sys
sys.path.insert(0, str(Path(__file__).parent.parent / "src"))
from fenris.monitor import (
cmd_enable,
cmd_disable,
cmd_collect,
cmd_baseline_set,
cmd_baseline_clear,
is_root,
)
from fenris.store import init_store
@pytest.fixture
def tmp_store(tmp_path):
"""Create a temporary observation store."""
store_path = tmp_path / "observations.db"
conn = init_store(store_path)
yield conn
conn.close()
@pytest.fixture
def store_path(tmp_path):
"""Return path to a temporary observation store."""
return tmp_path / "observations.db"
class TestIsRoot:
def test_root_returns_true(self):
with patch("os.geteuid", return_value=0):
assert is_root() is True
def test_non_root_returns_false(self):
with patch("os.geteuid", return_value=1000):
assert is_root() is False
class TestEnableIdempotentMatrix:
"""§8.6: Period-row idempotent matrix."""
def test_first_opens_period(self, store_path):
"""First-ever enable opens a period at the enable moment."""
# Initialize store
init_store(store_path)
args = MagicMock(now=False, store_path=store_path)
with patch("fenris.monitor.subprocess") as mock_sub:
mock_sub.run.return_value = MagicMock(returncode=0)
cmd_enable(args)
# Period should be open
conn = init_store(store_path)
cursor = conn.execute(
"SELECT ended_at FROM monitoring_periods WHERE ended_at IS NULL"
)
assert cursor.fetchone() is not None
conn.close()
def test_resume_with_open_period_noop(self, store_path):
"""Resume with open period: no-op (gap stays inside as unknown)."""
# Initialize store and open a period
conn = init_store(store_path)
now = datetime.now(timezone.utc)
conn.execute(
"INSERT INTO monitoring_periods (started_at) VALUES (?)",
(now.isoformat(),),
)
conn.commit()
conn.close()
args = MagicMock(now=True, store_path=store_path)
with patch("fenris.monitor.subprocess") as mock_sub:
mock_sub.run.return_value = MagicMock(returncode=0)
cmd_enable(args)
# Should still have exactly one open period
conn = init_store(store_path)
cursor = conn.execute(
"SELECT COUNT(*) FROM monitoring_periods WHERE ended_at IS NULL"
)
assert cursor.fetchone()[0] == 1
conn.close()
def test_resume_with_no_period_opens_new(self, store_path):
"""Resume with no open period opens a new row."""
# Initialize store and close any existing period
conn = init_store(store_path)
conn.execute(
"UPDATE monitoring_periods SET ended_at = ?, end_cause = ?",
(datetime.now(timezone.utc).isoformat(), "user_disabled"),
)
conn.commit()
conn.close()
args = MagicMock(now=True, store_path=store_path)
with patch("fenris.monitor.subprocess") as mock_sub:
mock_sub.run.return_value = MagicMock(returncode=0)
cmd_enable(args)
# Should have a new open period
conn = init_store(store_path)
cursor = conn.execute(
"SELECT COUNT(*) FROM monitoring_periods WHERE ended_at IS NULL"
)
assert cursor.fetchone()[0] == 1
conn.close()
class TestDisableIdempotentMatrix:
"""§8.6: Period-row idempotent matrix."""
def test_pause_with_open_period_closes_user_disabled(self, store_path):
"""Pause with open period closes it user_disabled."""
# Initialize store and open a period
conn = init_store(store_path)
now = datetime.now(timezone.utc)
conn.execute(
"INSERT INTO monitoring_periods (started_at) VALUES (?)",
(now.isoformat(),),
)
conn.commit()
conn.close()
args = MagicMock(now=True, store_path=store_path)
with patch("fenris.monitor.subprocess") as mock_sub:
mock_sub.run.return_value = MagicMock(returncode=0)
cmd_disable(args)
# Period should be closed with user_disabled
conn = init_store(store_path)
cursor = conn.execute(
"SELECT end_cause FROM monitoring_periods WHERE ended_at IS NOT NULL"
)
assert cursor.fetchone()[0] == "user_disabled"
conn.close()
def test_pause_without_open_period_noop(self, store_path):
"""Pause otherwise no-ops."""
# Initialize store
init_store(store_path)
args = MagicMock(now=True, store_path=store_path)
with patch("fenris.monitor.subprocess") as mock_sub:
mock_sub.run.return_value = MagicMock(returncode=0)
cmd_disable(args)
# No periods should exist
conn = init_store(store_path)
cursor = conn.execute("SELECT COUNT(*) FROM monitoring_periods")
assert cursor.fetchone()[0] == 0
conn.close()
def test_raw_systemctl_stop_never_records_user_disabled(self, store_path):
"""Raw systemctl stop outside helper never records user_disabled."""
# Initialize store and open a period
conn = init_store(store_path)
now = datetime.now(timezone.utc)
conn.execute(
"INSERT INTO monitoring_periods (started_at) VALUES (?)",
(now.isoformat(),),
)
conn.commit()
# Simulate raw systemctl stop (no monitor involved)
# The period stays open - only the sanctioned path closes it
cursor = conn.execute(
"SELECT end_cause FROM monitoring_periods WHERE ended_at IS NULL"
)
assert cursor.fetchone() is not None # Still open
conn.close()
class TestCollectTrigger:
"""§8.7: On-demand collection via helper path."""
def test_collect_triggers_systemctl_start(self):
"""Collect starts fenris-collect.service synchronously."""
args = MagicMock()
with patch("fenris.monitor.subprocess") as mock_sub:
mock_sub.run.return_value = MagicMock(returncode=0)
cmd_collect(args)
mock_sub.run.assert_called_once_with(
["systemctl", "start", "fenris-collect.service"],
capture_output=True,
text=True,
)
def test_collect_failure_exits_nonzero(self):
"""Collect failure exits with nonzero status."""
args = MagicMock()
with patch("fenris.monitor.subprocess") as mock_sub:
mock_sub.run.return_value = MagicMock(
returncode=1, stderr="Unit not found"
)
with pytest.raises(SystemExit) as exc_info:
cmd_collect(args)
assert exc_info.value.code == 1
class TestBaselinePersistence:
"""PR-14: Baseline persistence behind polkit-guarded helper."""
def test_baseline_set_persists(self, store_path):
"""baseline set persists the baseline row."""
# Initialize store
init_store(store_path)
args = MagicMock(
store_path=store_path,
baseline_json=json.dumps(
{
"tbw_terabytes": 600,
"source_url": "https://example.com/spec",
"document_revision": "rev1",
"entry_date": "2024-01-01",
"model_string": "Samsung 990 Pro",
"nominal_capacity_bytes": 2000000000000,
}
)
)
cmd_baseline_set(args)
conn = init_store(store_path)
cursor = conn.execute("SELECT * FROM endurance_baseline")
row = cursor.fetchone()
assert row is not None
assert row[1] == 600.0 # tbw_terabytes
conn.close()
def test_baseline_set_replaces_existing(self, store_path):
"""baseline set replaces any existing baseline."""
# Initialize store and insert initial baseline
conn = init_store(store_path)
now = datetime.now(timezone.utc)
conn.execute(
"INSERT INTO endurance_baseline (tbw_terabytes, source_url, "
"document_revision, entry_date, model_string, nominal_capacity_bytes, "
"created_at, updated_at) VALUES (?, ?, ?, ?, ?, ?, ?, ?)",
(400, "old", "v1", "2023-01-01", "Old Model", 1000000000000,
now.isoformat(), now.isoformat()),
)
conn.commit()
conn.close()
args = MagicMock(
store_path=store_path,
baseline_json=json.dumps(
{
"tbw_terabytes": 600,
"source_url": "new",
"document_revision": "v2",
"entry_date": "2024-01-01",
"model_string": "New Model",
"nominal_capacity_bytes": 2000000000000,
}
)
)
cmd_baseline_set(args)
conn = init_store(store_path)
cursor = conn.execute("SELECT COUNT(*) FROM endurance_baseline")
assert cursor.fetchone()[0] == 1 # Only one row
conn.close()
def test_baseline_clear_removes(self, store_path):
"""baseline clear removes the baseline."""
# Initialize store and insert baseline
conn = init_store(store_path)
now = datetime.now(timezone.utc)
conn.execute(
"INSERT INTO endurance_baseline (tbw_terabytes, source_url, "
"document_revision, entry_date, model_string, nominal_capacity_bytes, "
"created_at, updated_at) VALUES (?, ?, ?, ?, ?, ?, ?, ?)",
(400, "src", "v1", "2024-01-01", "Model", 1000000000000,
now.isoformat(), now.isoformat()),
)
conn.commit()
conn.close()
args = MagicMock(store_path=store_path)
cmd_baseline_clear(args)
conn = init_store(store_path)
cursor = conn.execute("SELECT COUNT(*) FROM endurance_baseline")
assert cursor.fetchone()[0] == 0
conn.close()
+9
View File
@@ -0,0 +1,9 @@
[Unit]
Description=Fenris NVMe collection service
Documentation=https://git.bongbetic.com/xavierk/Fenris
After=local-fs.target
[Service]
Type=oneshot
ExecStart=/usr/libexec/fenris/fenris-collect
TimeoutStartSec=90
+12
View File
@@ -0,0 +1,12 @@
[Unit]
Description=Fenris collection timer
Documentation=https://git.bongbetic.com/xavierk/Fenris
[Timer]
OnBootSec=2min
OnUnitInactiveSec=5min
AccuracySec=30s
Persistent=no
[Install]
WantedBy=timers.target