Packaging tracer bullet: build the deb and install it dormant in a container #45
Notifications
Due Date
No due date set.
Blocks
Reference: xavierk/Fenris#45
Reference in New Issue
Block a user
Parent
Ship Fenris as native deb + rpm packages (execute the release plan)
What to build
The tracer bullet for packaged delivery: the maintainer runs one build command and gets a deb; installing that deb on a clean Debian 12 system (a throwaway container) yields a complete, dormant Fenris — the unprivileged CLI/TUI works from PATH, the units are present but disabled, the service group and observation-store directory exist with the documented permissions, a placeholder-commented configuration file is in place, and every placed file is owned by the package database. This slice also delivers the test seam itself: the containerized harness through which every later packaging ticket is verified.
Acceptance criteria
fenris, version<project version>-1, architecture x86_64, declaring exactlypython3 (>= 3.10),smartmontools,systemdas dependencies — the UI framework and all Python dependencies vendored in the bundled venv at the fixed install root, no distro Python package dependency declaredfenrisgroup exists, the observation-store directory exists with root ownership, the service group, and the documented access mode,daemon-reloadhas run, and the timer is disabled and inactive — nothing started (dormant install)Blocked by
None (can start immediately).
Resolution
All six acceptance criteria verified:
Build command:
make package-debproducesdist/fenris_0.3.0_amd64.debwith correct dependencies (python3 >= 3.10, smartmontools, systemd) and vendored venv at /opt/fenris.File placement: Container tests confirm venv, wrapper (/usr/bin/fenris), helpers (/usr/libexec/fenris/), units (vendor placement), polkit policy, sysusers/tmpfiles fragments, and placeholder conffile are all present and correct.
Dormant install: Timer is disabled and inactive, fenris group exists, observation-store directory has correct ownership (root:fenris, mode 2750), daemon-reload runs, nothing starts.
Package database ownership: Every placed file owned by package; store directory owned but contents never owned (ghost type); no hand-rolled manifest.
Migration guard: preinst.sh aborts with pointer to migration runbook when make-install remnants detected (manifest.txt or admin unit file).
Container harness: 16 parametrized tests across 4 distros (debian:bookworm, ubuntu:22.04, ubuntu:24.04, fedora:40) run through
pytest tests/test_packaging.py— no network, no registry, no signing key.Bugs fixed during implementation
--tmpfs /tmphid packages COPYed to /tmp during Docker build. Fixed by copying to /pkg/ instead.dpkg -isame version = reinstall, not upgrade. Fixed by faking older version in dpkg status for deb, and manually invoking post scriptlet with upgrade args for RPM.