fix: preserve machine-readable installer output for alpha.17 #54
4 changed files with 22 additions and 10 deletions
|
|
@ -3,7 +3,7 @@ set -Eeuo pipefail
|
||||||
IFS=$'\n\t'
|
IFS=$'\n\t'
|
||||||
|
|
||||||
readonly PROGRAM_NAME="smm-setup"
|
readonly PROGRAM_NAME="smm-setup"
|
||||||
readonly DEFAULT_RELEASE_TAG="v0.1.0-alpha.16"
|
readonly DEFAULT_RELEASE_TAG="v0.1.0-alpha.17"
|
||||||
readonly DEFAULT_REPOSITORY="ochenstarik-ui/server-monitor-manager"
|
readonly DEFAULT_REPOSITORY="ochenstarik-ui/server-monitor-manager"
|
||||||
readonly INNER_ASSET="ochenstarik-server-monitor-manager.sh"
|
readonly INNER_ASSET="ochenstarik-server-monitor-manager.sh"
|
||||||
|
|
||||||
|
|
@ -27,7 +27,7 @@ force pass-through. Common bootstrap commands:
|
||||||
backup-create | backup-restore | version
|
backup-create | backup-restore | version
|
||||||
|
|
||||||
Environment overrides:
|
Environment overrides:
|
||||||
SMM_TAG Release tag (default: v0.1.0-alpha.16)
|
SMM_TAG Release tag (default: v0.1.0-alpha.17)
|
||||||
SMM_REPOSITORY GitHub repository (default: ochenstarik-ui/server-monitor-manager)
|
SMM_REPOSITORY GitHub repository (default: ochenstarik-ui/server-monitor-manager)
|
||||||
SMM_CACHE_DIR Verified-download cache directory
|
SMM_CACHE_DIR Verified-download cache directory
|
||||||
USAGE
|
USAGE
|
||||||
|
|
@ -114,7 +114,7 @@ curl -fsSL "$release_base/$INNER_ASSET.sha256" -o "$temporary_directory/$INNER_A
|
||||||
|
|
||||||
(
|
(
|
||||||
cd "$temporary_directory"
|
cd "$temporary_directory"
|
||||||
sha256sum -c "$INNER_ASSET.sha256"
|
sha256sum -c "$INNER_ASSET.sha256" >/dev/null
|
||||||
) || die "checksum verification failed for $RELEASE_TAG/$INNER_ASSET"
|
) || die "checksum verification failed for $RELEASE_TAG/$INNER_ASSET"
|
||||||
|
|
||||||
install -m 0755 "$temporary_directory/$INNER_ASSET" "$cached_script"
|
install -m 0755 "$temporary_directory/$INNER_ASSET" "$cached_script"
|
||||||
|
|
|
||||||
|
|
@ -6,11 +6,11 @@ Server Monitor Manager устанавливает Control (Hub) и Agent (Node)
|
||||||
|
|
||||||
## Быстрая установка
|
## Быстрая установка
|
||||||
|
|
||||||
Скачайте и проверьте convenience installer из `v0.1.0-alpha.16`:
|
Скачайте и проверьте convenience installer из `v0.1.0-alpha.17`:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
curl -fsSLO https://github.com/ochenstarik-ui/server-monitor-manager/releases/download/v0.1.0-alpha.16/smm-setup.sh
|
curl -fsSLO https://github.com/ochenstarik-ui/server-monitor-manager/releases/download/v0.1.0-alpha.17/smm-setup.sh
|
||||||
curl -fsSLO https://github.com/ochenstarik-ui/server-monitor-manager/releases/download/v0.1.0-alpha.16/smm-setup.sh.sha256
|
curl -fsSLO https://github.com/ochenstarik-ui/server-monitor-manager/releases/download/v0.1.0-alpha.17/smm-setup.sh.sha256
|
||||||
sha256sum -c smm-setup.sh.sha256
|
sha256sum -c smm-setup.sh.sha256
|
||||||
chmod 700 smm-setup.sh
|
chmod 700 smm-setup.sh
|
||||||
```
|
```
|
||||||
|
|
|
||||||
|
|
@ -17,6 +17,7 @@ Known release history:
|
||||||
- `v0.1.0-alpha.13` corrected the checksum portability defect, but it was also published with a keyless manifest signature and without the Fulcio signing certificate required by production consumers. The immutable release remains published as historical evidence; the producer/consumer certificate contract is corrected under a higher version.
|
- `v0.1.0-alpha.13` corrected the checksum portability defect, but it was also published with a keyless manifest signature and without the Fulcio signing certificate required by production consumers. The immutable release remains published as historical evidence; the producer/consumer certificate contract is corrected under a higher version.
|
||||||
- `v0.1.0-alpha.14` is the first release with the complete manifest, keyless signature, and Fulcio certificate set, so its published assets can be verified. A clean host cannot install it because the release does not provision cosign. Preserve it for verification and historical evidence; do not use it for installation.
|
- `v0.1.0-alpha.14` is the first release with the complete manifest, keyless signature, and Fulcio certificate set, so its published assets can be verified. A clean host cannot install it because the release does not provision cosign. Preserve it for verification and historical evidence; do not use it for installation.
|
||||||
- `v0.1.0-alpha.15` is the first release that provisions a pinned, checksum-verified cosign binary. Its automatically triggered Release Verification proved the clean-host Hub installation and manifest verification, then stopped before the clean-host Node installation because the acceptance script retained the deliberately removed cosign path in Bash's command hash. The immutable release and failed verification remain as evidence; the acceptance harness is corrected in the next version.
|
- `v0.1.0-alpha.15` is the first release that provisions a pinned, checksum-verified cosign binary. Its automatically triggered Release Verification proved the clean-host Hub installation and manifest verification, then stopped before the clean-host Node installation because the acceptance script retained the deliberately removed cosign path in Bash's command hash. The immutable release and failed verification remain as evidence; the acceptance harness is corrected in the next version.
|
||||||
- `v0.1.0-alpha.16` clears the acceptance shell's command hash after removing its test-provisioned cosign, so both `install-hub` and `install-node` are exercised from a clean host. It is the first release required to complete both automatic `workflow_run` verification and manual `workflow_dispatch` re-verification.
|
- `v0.1.0-alpha.16` clears the acceptance shell's command hash after removing its test-provisioned cosign. Its automatic verification proved clean-host Hub installation, but the convenience installer wrote the bootstrap checksum success line to stdout before the machine-readable `SMMNODE2` enrollment code. Node installation therefore rejected the contaminated value. The immutable release and failed verification remain as evidence; stdout isolation is corrected in the next version.
|
||||||
|
- `v0.1.0-alpha.17` keeps checksum verification fail-closed while suppressing its success line, so pass-through commands such as `node-code` return only their machine-readable bootstrap output. It is the first release required to complete both automatic `workflow_run` verification and manual `workflow_dispatch` re-verification.
|
||||||
|
|
||||||
Every release candidate must pass a branch `workflow_dispatch` run of the Release pipeline before its immutable version tag is created. The release owner has sole write ownership of version sources, `deploy/**`, `tests/bootstrap/**`, release workflows, the root README release status, and translated README release statuses. Other contributors request changes to those paths in their report; they do not edit or bump them directly. One pull request covers one release topic and may merge only after required CI is green.
|
Every release candidate must pass a branch `workflow_dispatch` run of the Release pipeline before its immutable version tag is created. The release owner has sole write ownership of version sources, `deploy/**`, `tests/bootstrap/**`, release workflows, the root README release status, and translated README release statuses. Other contributors request changes to those paths in their report; they do not edit or bump them directly. One pull request covers one release topic and may merge only after required CI is green.
|
||||||
|
|
|
||||||
|
|
@ -18,7 +18,7 @@ v1_fixture="$root/tests/fixtures/alpha8-v1-release"
|
||||||
exit 1
|
exit 1
|
||||||
}
|
}
|
||||||
bash -n "$setup"
|
bash -n "$setup"
|
||||||
grep -Fq 'readonly DEFAULT_RELEASE_TAG="v0.1.0-alpha.16"' "$setup"
|
grep -Fq 'readonly DEFAULT_RELEASE_TAG="v0.1.0-alpha.17"' "$setup"
|
||||||
grep -Fq 'install-hub PUBLIC_HOST [HTTPS_PORT] [WG_PORT]' "$setup"
|
grep -Fq 'install-hub PUBLIC_HOST [HTTPS_PORT] [WG_PORT]' "$setup"
|
||||||
grep -Fxq ' install-node' "$setup"
|
grep -Fxq ' install-node' "$setup"
|
||||||
if grep -Fq 'validate_control_url' "$setup" || grep -Fq '${CONTROL_URL%/}/control' "$setup"; then
|
if grep -Fq 'validate_control_url' "$setup" || grep -Fq '${CONTROL_URL%/}/control' "$setup"; then
|
||||||
|
|
@ -61,6 +61,7 @@ grep -Fq 'v0.1.0-alpha.13' "$policy"
|
||||||
grep -Fq 'v0.1.0-alpha.14' "$policy"
|
grep -Fq 'v0.1.0-alpha.14' "$policy"
|
||||||
grep -Fq 'v0.1.0-alpha.15' "$policy"
|
grep -Fq 'v0.1.0-alpha.15' "$policy"
|
||||||
grep -Fq 'v0.1.0-alpha.16' "$policy"
|
grep -Fq 'v0.1.0-alpha.16' "$policy"
|
||||||
|
grep -Fq 'v0.1.0-alpha.17' "$policy"
|
||||||
grep -Fq 'hash -r' "$root/tests/release-verification/run-positive-installation.sh"
|
grep -Fq 'hash -r' "$root/tests/release-verification/run-positive-installation.sh"
|
||||||
grep -Fq 'readonly COSIGN_VERSION="v3.1.3"' "$bootstrap"
|
grep -Fq 'readonly COSIGN_VERSION="v3.1.3"' "$bootstrap"
|
||||||
grep -Fq 'readonly COSIGN_SHA256_AMD64="4629c757b7618056f8ddd7e2625ae9fdd94c0372a65049520bc7d9df9efc7f71"' "$bootstrap"
|
grep -Fq 'readonly COSIGN_SHA256_AMD64="4629c757b7618056f8ddd7e2625ae9fdd94c0372a65049520bc7d9df9efc7f71"' "$bootstrap"
|
||||||
|
|
@ -109,6 +110,10 @@ mkdir -p "$work/bin" "$work/home"
|
||||||
cat >"$work/inner.sh" <<'INNER'
|
cat >"$work/inner.sh" <<'INNER'
|
||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
set -Eeuo pipefail
|
set -Eeuo pipefail
|
||||||
|
if [[ "${1:-}" == "node-code" ]]; then
|
||||||
|
printf '%s\n' 'SMMNODE1.fixture'
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
printf 'INNER_ARGS='
|
printf 'INNER_ARGS='
|
||||||
printf '%s ' "$@"
|
printf '%s ' "$@"
|
||||||
printf '\n'
|
printf '\n'
|
||||||
|
|
@ -185,8 +190,14 @@ chmod +x "$work/bin/uname"
|
||||||
|
|
||||||
HOME="$work/home" PATH="$work/bin:$PATH" bash "$setup" version >"$work/output"
|
HOME="$work/home" PATH="$work/bin:$PATH" bash "$setup" version >"$work/output"
|
||||||
grep -Fq 'INNER_ARGS=version ' "$work/output"
|
grep -Fq 'INNER_ARGS=version ' "$work/output"
|
||||||
grep -Fq '/releases/download/v0.1.0-alpha.16/ochenstarik-server-monitor-manager.sh' "$work/urls"
|
grep -Fq '/releases/download/v0.1.0-alpha.17/ochenstarik-server-monitor-manager.sh' "$work/urls"
|
||||||
grep -Fq '/releases/download/v0.1.0-alpha.16/ochenstarik-server-monitor-manager.sh.sha256' "$work/urls"
|
grep -Fq '/releases/download/v0.1.0-alpha.17/ochenstarik-server-monitor-manager.sh.sha256' "$work/urls"
|
||||||
|
|
||||||
|
node_code="$(HOME="$work/home" PATH="$work/bin:$PATH" bash "$setup" node-code fixture-node)"
|
||||||
|
[[ "$node_code" == 'SMMNODE1.fixture' ]] || {
|
||||||
|
printf 'machine-readable node-code output was contaminated: %q\n' "$node_code" >&2
|
||||||
|
exit 1
|
||||||
|
}
|
||||||
|
|
||||||
if HOME="$work/home" PATH="$work/bin:$PATH" bash "$setup" install-hub >"$work/invalid.out" 2>&1; then
|
if HOME="$work/home" PATH="$work/bin:$PATH" bash "$setup" install-hub >"$work/invalid.out" 2>&1; then
|
||||||
printf '%s\n' 'install-hub accepted a missing PUBLIC_HOST' >&2
|
printf '%s\n' 'install-hub accepted a missing PUBLIC_HOST' >&2
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue