Grilling: Migration path from make-install systems to packages #41

Closed
opened 2026-09-02 18:31:24 +00:00 by xavierk · 1 comment
Owner

Parent map: Fenris deb + rpm release plan

Question

How do existing Makefile/manifest-installed Fenris systems move to package-managed installs? Detect the old manifest, avoid double ownership of /opt/fenris and /var/lib/fenris, preserve the observation store, and pick ordering (remove-then-install vs upgrade-in-place).

Parent map: [Fenris deb + rpm release plan](https://git.bongbetic.com/xavierk/Fenris/issues/33) ## Question How do existing Makefile/manifest-installed Fenris systems move to package-managed installs? Detect the old manifest, avoid double ownership of /opt/fenris and /var/lib/fenris, preserve the observation store, and pick ordering (remove-then-install vs upgrade-in-place).
xavierk added this to the Wayfinder: Fenris deb + rpm release plan milestone 2026-09-02 18:31:24 +00:00
xavierk added the wayfinder:grilling label 2026-09-02 18:31:24 +00:00
xavierk added a new dependency 2026-09-02 18:34:09 +00:00
xavierk added a new dependency 2026-09-02 18:34:11 +00:00
xavierk self-assigned this 2026-09-02 20:01:37 +00:00
Author
Owner

Resolution

All 6 recommendations accepted. Migration path from make-install systems to packages:

  1. Runbook only, no migration script. Population = author machines + a couple of testers; store/config survive by path continuity; a script adds no value.
  2. Remove-then-install, mandatory. sudo make uninstall (preserves store + /etc/fenris) → apt install fenris / dnf install fenris. Over-install forbidden: stale /etc/systemd/system/fenris-collect.* silently shadows vendor units in /usr/lib/systemd/system (systemd precedence), /usr/local/bin/fenris shadows /usr/bin/fenris on PATH, manifest.txt lingers.
  3. preinst/%pre guard: abort with pointer to runbook if /var/lib/fenris/manifest.txt OR /etc/systemd/system/fenris-collect.timer exists (dual marker covers pre-manifest installs). No auto-clean — maintainer scripts never delete files the package DB doesn't own (same principle as the manifest retirement in #40).
  4. No-move continuity (ratified facts for spec composition #42): /var/lib/fenris untouched (same path both worlds); existing fenris group → sysusers.d no-op; existing dir → tmpfiles no-op (make install already set 2750 root:fenris); user's hand-written fenris.conf survives as a non-DB file (dpkg ships package default as .dpkg-new; rpm %config(noreplace) → .rpmnew); store schema caught up by postinst forward-only migration. Leftover .bak/WAL sidecars left alone — package never owns store contents.
  5. Reset-to-dormant accepted. make uninstall's sanctioned disable closes the user_disabled period; after migration the user runs fenris monitor resume. Cost = one 15-min sample gap, honest against the endurance timeline. No reaching behind the sanctioned-toggle model.
  6. Mutual exclusion: package and make install never on the same machine. make install stays fallback for machines without packages; the real dev loop is checkout + make test. Dev-local install mode (venv in checkout, user-level units) deferred to map fog.

Input to "Task: Compose release spec + ADR amending 0004" (#42): migration runbook section + preinst/%pre abort check.

## Resolution All 6 recommendations accepted. Migration path from make-install systems to packages: 1. **Runbook only, no migration script.** Population = author machines + a couple of testers; store/config survive by path continuity; a script adds no value. 2. **Remove-then-install, mandatory.** `sudo make uninstall` (preserves store + `/etc/fenris`) → `apt install fenris` / `dnf install fenris`. Over-install forbidden: stale `/etc/systemd/system/fenris-collect.*` silently shadows vendor units in `/usr/lib/systemd/system` (systemd precedence), `/usr/local/bin/fenris` shadows `/usr/bin/fenris` on PATH, `manifest.txt` lingers. 3. **preinst/%pre guard: abort with pointer to runbook** if `/var/lib/fenris/manifest.txt` OR `/etc/systemd/system/fenris-collect.timer` exists (dual marker covers pre-manifest installs). No auto-clean — maintainer scripts never delete files the package DB doesn't own (same principle as the manifest retirement in #40). 4. **No-move continuity (ratified facts for spec composition #42):** `/var/lib/fenris` untouched (same path both worlds); existing `fenris` group → sysusers.d no-op; existing dir → tmpfiles no-op (make install already set 2750 root:fenris); user's hand-written `fenris.conf` survives as a non-DB file (dpkg ships package default as `.dpkg-new`; rpm `%config(noreplace)` → `.rpmnew`); store schema caught up by postinst forward-only migration. Leftover `.bak`/WAL sidecars left alone — package never owns store contents. 5. **Reset-to-dormant accepted.** `make uninstall`'s sanctioned disable closes the `user_disabled` period; after migration the user runs `fenris monitor resume`. Cost = one 15-min sample gap, honest against the endurance timeline. No reaching behind the sanctioned-toggle model. 6. **Mutual exclusion: package and `make install` never on the same machine.** `make install` stays fallback for machines without packages; the real dev loop is checkout + `make test`. Dev-local install mode (venv in checkout, user-level units) deferred to map fog. Input to "Task: Compose release spec + ADR amending 0004" (#42): migration runbook section + preinst/%pre abort check.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Reference: xavierk/Fenris#41