Migration runbook at docs/install/migrate-from-makeinstall.md covers the
mandatory remove-then-install path, why over-install is forbidden, no-move
continuity guarantees, and reset-to-dormant expectations.
Acceptance criteria MG-1 through MG-4 added to the install criteria section.
Containerized tests verify no-move continuity: existing group makes sysusers
a no-op, existing store dir makes tmpfiles a no-op, hand-edited config
survives as a non-database file, and store schema is caught up by the
upgrade-path migration. Dead code from a prior merge removed.
Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Replace the thin test_removal_semantics with comprehensive per-operation
tests covering all five acceptance criteria:
- deb remove keeps config, store (DB + WAL sidecars + backup), and group
- deb purge removes config, store, backup, and group
- rpm erase preserves modified config as .rpmsave
- rpm erase removes unmodified config
- store files never deleted except by purge
- dedicated test: sanctioned disable never runs on upgrade (parametrized
across all deb + rpm targets)
Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Add comprehensive test coverage for upgrade semantics:
- 12 Python unit tests for store migration (forward-only, downgrade
refusal, idempotent behavior) across migrate_to_latest, init_store,
and open_store_readonly
- Enhanced packaging upgrade test to verify all five acceptance
criteria: snapshot before migration, store not rebuilt, config
survival, timer/removal no-ops during upgrade
- RPM-specific test for config file preservation (noreplace conffile)
Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
Add test_python_floor to the containerized packaging matrix:
- Sub-check 1: Ubuntu 22.04 (Python 3.10) installs successfully,
confirming the floor is met on the oldest supported deb target.
- Sub-check 2: Debian 11 (Python 3.9) fails to configure due to
unmet python3 (>= 3.10) dependency, verifying clean failure below floor.
Fix Makefile check-python gate to enforce Python >= 3.10, matching the
nfpm depends declaration.
Full compatibility matrix is now green: 17 packaging tests (dormant
install, migration guard, upgrade semantics, removal semantics, and
Python floor) pass across all four targets (Debian 12, Ubuntu 22.04,
Ubuntu 24.04, Fedora 40).
Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
- Fix nfpm.yaml ghost directory to include `group: fenris` so RPM metadata
matches the tmpfiles.d-created ownership (root:fenris 2750)
- Add RPM-native ownership assertions: store dir reported as package-owned
via `rpm -qf`, store contents verified as never owned by the package
- Add RPM conffile assertion: `rpm -qc` verifies fenris.conf is listed
- Unify store dir stat assertion across both formats (deb and rpm both
assert mode 2750 root:fenris)
- Remove unused `distro` parameter from `_find_package()`
All 16 packaging tests pass across the full matrix (3 deb + 1 rpm × 4 scenarios).
All 289 non-packaging tests pass.
Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
- Copy packages to /pkg/ instead of /tmp/ to avoid tmpfs masking in
docker run --tmpfs /tmp, which hid packages needed at runtime by the
migration guard and upgrade tests
- Add version faking for deb upgrade test: sed the dpkg status to show
version 0.2.0 so dpkg -i treats the reinstall as an upgrade and
postinst receives the old-version argument
- For RPM upgrade test: extract and manually invoke the post scriptlet
with $1=2 (upgrade arguments), since faking a different version in
the binary RPM database is not practical
- Parameterize migration guard and upgrade assertions with pkg_name
(and version) instead of hardcoding filenames
All 16 packaging tests now pass across debian:bookworm, ubuntu:22.04,
ubuntu:24.04, and fedora:40.
Co-authored-by: CommandCodeBot <noreply@commandcode.ai>