Rpm from the same packaging config, dormant install in a Fedora container #46

Closed
opened 2026-09-02 20:21:28 +00:00 by xavierk · 1 comment
Owner

Parent

Ship Fenris as native deb + rpm packages (execute the release plan)

What to build

The second format from the same source of truth: the same packaging configuration, extended only with per-format overrides, produces an rpm; installing it in a throwaway Fedora 40 container yields exactly the same dormant-install contract as the deb — same layout, same ownership, same do-nothing-beyond-reload scriptlet behavior, with rpm-native scriptlet equivalents.

Acceptance criteria

  • The same packaging configuration produces the rpm via a second invocation; the only deb/rpm differences live in per-format overrides (conffile marking, dependency syntax) — no duplicated file list, no separate spec
  • Installing in a throwaway Fedora 40 container places the same layout as the deb: bundled venv, wrapper on PATH, the two helpers, units in vendor placement, polkit policy, sysusers/tmpfiles applied, placeholder conffile marked no-replace
  • The install-case scriptlet behaves identically to the deb: sysusers, tmpfiles, daemon-reload — never enable, never preset, never start; no preset file ships
  • The pre-install guard aborts with a runbook pointer on make-install remnants, same as the deb
  • rpm-native ownership queries show the store directory owned and store contents never owned or ghosted
  • The container harness covers the fedora target with the same assertions parametrized across both formats

Blocked by

## Parent [Ship Fenris as native deb + rpm packages (execute the release plan)](https://git.bongbetic.com/xavierk/Fenris/issues/44) ## What to build The second format from the same source of truth: the same packaging configuration, extended only with per-format overrides, produces an rpm; installing it in a throwaway Fedora 40 container yields exactly the same dormant-install contract as the deb — same layout, same ownership, same do-nothing-beyond-reload scriptlet behavior, with rpm-native scriptlet equivalents. ## Acceptance criteria - [ ] The same packaging configuration produces the rpm via a second invocation; the only deb/rpm differences live in per-format overrides (conffile marking, dependency syntax) — no duplicated file list, no separate spec - [ ] Installing in a throwaway Fedora 40 container places the same layout as the deb: bundled venv, wrapper on PATH, the two helpers, units in vendor placement, polkit policy, sysusers/tmpfiles applied, placeholder conffile marked no-replace - [ ] The install-case scriptlet behaves identically to the deb: sysusers, tmpfiles, `daemon-reload` — never enable, never preset, never start; no preset file ships - [ ] The pre-install guard aborts with a runbook pointer on make-install remnants, same as the deb - [ ] rpm-native ownership queries show the store directory owned and store contents never owned or ghosted - [ ] The container harness covers the fedora target with the same assertions parametrized across both formats ## Blocked by - [Packaging tracer bullet: build the deb and install it dormant in a container](https://git.bongbetic.com/xavierk/Fenris/issues/45)
xavierk added the ready-for-agent label 2026-09-02 20:21:29 +00:00
Author
Owner

Resolved — all acceptance criteria verified:

  1. ✅ Same packaging/nfpm.yaml produces both deb and rpm via per-format overrides only
  2. ✅ Fedora 40 container dormant install matches deb layout (venv, wrapper, helpers, units, polkit, sysusers/tmpfiles, config)
  3. ✅ RPM %post scriptlet: sysusers, tmpfiles, daemon-reload on fresh install; no enable/preset/start
  4. ✅ Shared preinst.sh aborts with runbook pointer on make-install remnants
  5. ✅ RPM-native ownership: store dir owned (ghost, root:fenris 2750), contents verified never owned; ghost group fix applied
  6. ✅ Container harness parametrizes all 4 targets × 4 scenarios (16 tests total, all green)

Changes:

  • packaging/nfpm.yaml: added group: fenris to ghost directory
  • tests/test_packaging.py: unified store dir stat assertion, added RPM ownership + conffile assertions, removed unused parameter

Test results: 16/16 packaging tests pass, 289/289 non-packaging tests pass.

**Resolved** — all acceptance criteria verified: 1. ✅ Same `packaging/nfpm.yaml` produces both deb and rpm via per-format overrides only 2. ✅ Fedora 40 container dormant install matches deb layout (venv, wrapper, helpers, units, polkit, sysusers/tmpfiles, config) 3. ✅ RPM `%post` scriptlet: sysusers, tmpfiles, daemon-reload on fresh install; no enable/preset/start 4. ✅ Shared `preinst.sh` aborts with runbook pointer on make-install remnants 5. ✅ RPM-native ownership: store dir owned (ghost, root:fenris 2750), contents verified never owned; ghost group fix applied 6. ✅ Container harness parametrizes all 4 targets × 4 scenarios (16 tests total, all green) Changes: - `packaging/nfpm.yaml`: added `group: fenris` to ghost directory - `tests/test_packaging.py`: unified store dir stat assertion, added RPM ownership + conffile assertions, removed unused parameter Test results: 16/16 packaging tests pass, 289/289 non-packaging tests pass.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Reference: xavierk/Fenris#46