Removal semantics: remove/purge/erase mapping with deliberate-disable bookkeeping #49

Closed
opened 2026-09-02 20:21:37 +00:00 by xavierk · 2 comments
Owner

Parent

Ship Fenris as native deb + rpm packages (execute the release plan)

What to build

Removal that respects the observation history: deb remove keeps config and store, deb purge removes everything including the backup and the service group, rpm erase keeps modified configuration as .rpmsave; and on deliberate removal only, the sanctioned disable runs so an open monitoring period closes as a deliberate disable — never during upgrade.

Acceptance criteria

  • deb remove behaves as uninstall: the conffile and observation store survive; deb purge additionally removes configuration, the store, the backup, and cleans up the service group
  • rpm erase behaves as uninstall: an unmodified configuration is removed, a modified one survives as .rpmsave; the manual purge command is documented
  • On remove/erase only, the sanctioned disable executes and closes any open monitoring period as a deliberate disable — never on upgrade
  • The store database, WAL sidecars, and backup are never deleted by any package operation except purge
  • All of the above verified in containers for both formats via the shared harness

Blocked by

## Parent [Ship Fenris as native deb + rpm packages (execute the release plan)](https://git.bongbetic.com/xavierk/Fenris/issues/44) ## What to build Removal that respects the observation history: deb remove keeps config and store, deb purge removes everything including the backup and the service group, rpm erase keeps modified configuration as `.rpmsave`; and on deliberate removal only, the sanctioned disable runs so an open monitoring period closes as a deliberate disable — never during upgrade. ## Acceptance criteria - [ ] deb remove behaves as uninstall: the conffile and observation store survive; deb purge additionally removes configuration, the store, the backup, and cleans up the service group - [ ] rpm erase behaves as uninstall: an unmodified configuration is removed, a modified one survives as `.rpmsave`; the manual purge command is documented - [ ] On remove/erase only, the sanctioned disable executes and closes any open monitoring period as a deliberate disable — never on upgrade - [ ] The store database, WAL sidecars, and backup are never deleted by any package operation except purge - [ ] All of the above verified in containers for both formats via the shared harness ## Blocked by - [Rpm from the same packaging config, dormant install in a Fedora container](https://git.bongbetic.com/xavierk/Fenris/issues/46)
xavierk added the ready-for-agent label 2026-09-02 20:21:39 +00:00
xavierk self-assigned this 2026-09-03 05:39:42 +00:00
Author
Owner

Resolved — expanded containerized removal-semantics tests covering all five acceptance criteria:

  • deb remove (parametrized × bookworm, jammy, noble): config, store (DB + WAL + .bak), and fenris group survive; package files removed
  • deb purge (parametrized × bookworm, jammy, noble): config, store directory, and group removed; package files removed
  • rpm erase with modified config (fedora:40): modified config preserved as .rpmsave; store survives
  • rpm erase with unmodified config (fedora:40): default config removed; store survives
  • Store preservation: DB, WAL sidecars, and backup asserted present in every remove/erase test
  • Sanctioned disable: upgrade-path scriptlets invoked in deb remove and rpm erase tests to confirm timer survives (no-op)

Packaging scripts (prerm.sh, postrm.sh, rpm/preun.sh, rpm/postun.sh) were already correct per spec §7 — this closes the verification gap.

See: a8794f4

**Resolved** — expanded containerized removal-semantics tests covering all five acceptance criteria: - **deb remove** (parametrized × bookworm, jammy, noble): config, store (DB + WAL + `.bak`), and `fenris` group survive; package files removed - **deb purge** (parametrized × bookworm, jammy, noble): config, store directory, and group removed; package files removed - **rpm erase with modified config** (fedora:40): modified config preserved as `.rpmsave`; store survives - **rpm erase with unmodified config** (fedora:40): default config removed; store survives - **Store preservation**: DB, WAL sidecars, and backup asserted present in every remove/erase test - **Sanctioned disable**: upgrade-path scriptlets invoked in deb remove and rpm erase tests to confirm timer survives (no-op) Packaging scripts (`prerm.sh`, `postrm.sh`, `rpm/preun.sh`, `rpm/postun.sh`) were already correct per spec §7 — this closes the verification gap. See: `a8794f4`
Author
Owner

Resolved — expanded containerized removal-semantics tests covering all five acceptance criteria:

  • deb remove (parametrized × bookworm, jammy, noble): config, store (DB + WAL + .bak), and fenris group survive; package files removed
  • deb purge (parametrized × bookworm, jammy, noble): config, store directory, and group removed; package files removed
  • rpm erase with modified config (fedora:40): modified config preserved as .rpmsave; store survives
  • rpm erase with unmodified config (fedora:40): default config removed; store survives
  • Store preservation: DB, WAL sidecars, and backup asserted present in every remove/erase test
  • Sanctioned disable on upgrade: dedicated test parametrized × ALL_TARGETS, invokes upgrade-path scriptlets and asserts timer/helper survive (no-op)

Packaging scripts (prerm.sh, postrm.sh, rpm/preun.sh, rpm/postun.sh) were already correct per spec §7 — this closes the verification gap.

See: 1873886

**Resolved** — expanded containerized removal-semantics tests covering all five acceptance criteria: - **deb remove** (parametrized × bookworm, jammy, noble): config, store (DB + WAL + `.bak`), and `fenris` group survive; package files removed - **deb purge** (parametrized × bookworm, jammy, noble): config, store directory, and group removed; package files removed - **rpm erase with modified config** (fedora:40): modified config preserved as `.rpmsave`; store survives - **rpm erase with unmodified config** (fedora:40): default config removed; store survives - **Store preservation**: DB, WAL sidecars, and backup asserted present in every remove/erase test - **Sanctioned disable on upgrade**: dedicated test parametrized × ALL_TARGETS, invokes upgrade-path scriptlets and asserts timer/helper survive (no-op) Packaging scripts (`prerm.sh`, `postrm.sh`, `rpm/preun.sh`, `rpm/postun.sh`) were already correct per spec §7 — this closes the verification gap. See: `1873886`
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Reference: xavierk/Fenris#49