hub v0.137.0 source + burn-down round 2 in felhom.eu: R-277 R-581 R-600 R-544 R-855 R-134 R-92 R-292 R-599 R-725 R-728 (hub), R-819 R-857 R-555 R-364 R-587 (gates/tools), R-571 R-129 R-124-runbook (docs); 28 rows closed incl. catalog + agent v0.147.0 rows, R-350 merged into R-132, R-888 opened, R-887 mechanism (249 -> 222)
gates / gates (push) Successful in 2m3s
gates / gates (push) Successful in 2m3s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
================================================
|
||||
Felhom — a doboz össze van kötve. ✔
|
||||
Felhom — a doboz össze van kötve.
|
||||
|
||||
A beállítás magától folytatódik, ez néhány percig tart.
|
||||
A vezérlőpult címét az e-mailben kapott levél tartalmazza.
|
||||
|
||||
@@ -0,0 +1,58 @@
|
||||
#!/usr/bin/env python3
|
||||
# -*- coding: utf-8 -*-
|
||||
"""R-725: every console banner felhom-bootstrap.sh paints uses only glyphs the console font draws.
|
||||
|
||||
The box console loads a Latin-2 font (Lat2-Terminus16 and friends, set_console_font). A glyph outside it is
|
||||
drawn as something else: the linked banner ended in "✔", and the household saw "a doboz össze van kötve. V".
|
||||
This test reads every printf literal in the script and the banner goldens the ISO harness compares against,
|
||||
and refuses any character outside ASCII + the Hungarian letters + the em dash (which the banners already use
|
||||
and which renders). Pure file reads: runs on the BusyBox CI runner.
|
||||
Run: python3 scripts/iso/test/test_console_glyphs.py"""
|
||||
import os
|
||||
import re
|
||||
import sys
|
||||
|
||||
HERE = os.path.dirname(os.path.abspath(__file__))
|
||||
ISO = os.path.dirname(HERE)
|
||||
ALLOWED_NON_ASCII = set("áéíóöőúüűÁÉÍÓÖŐÚÜŰ—")
|
||||
PRINTF = re.compile(r"""printf\s+(?:'([^']*)'|"([^"]*)")""")
|
||||
|
||||
|
||||
def bad_glyphs(text):
|
||||
return sorted({c for c in text if ord(c) > 127 and c not in ALLOWED_NON_ASCII})
|
||||
|
||||
|
||||
def main():
|
||||
failures, checked = [], 0
|
||||
script = os.path.join(ISO, "felhom-bootstrap.sh")
|
||||
with open(script, encoding="utf-8") as fh:
|
||||
for n, line in enumerate(fh, 1):
|
||||
for m in PRINTF.finditer(line):
|
||||
checked += 1
|
||||
bad = bad_glyphs(m.group(1) or m.group(2) or "")
|
||||
if bad:
|
||||
failures.append("felhom-bootstrap.sh:%d: %s" % (n, " ".join(bad)))
|
||||
gdir = os.path.join(HERE, "golden")
|
||||
goldens = sorted(f for f in os.listdir(gdir) if f.endswith(".txt"))
|
||||
for g in goldens:
|
||||
with open(os.path.join(gdir, g), encoding="utf-8") as fh:
|
||||
bad = bad_glyphs(fh.read())
|
||||
if bad:
|
||||
failures.append("golden/%s: %s" % (g, " ".join(bad)))
|
||||
# Scope is a fact: a reader that found no banners checked nothing.
|
||||
if checked < 20 or not goldens:
|
||||
print("FAIL: read only %d printf literals and %d goldens — the scope is wrong" % (checked, len(goldens)))
|
||||
return 1
|
||||
# Positive control: the checker convicts the glyph that started this row.
|
||||
if bad_glyphs("a doboz össze van kötve. ✔") != ["✔"]:
|
||||
print("FAIL: the checker does not convict the check-mark glyph")
|
||||
return 1
|
||||
if failures:
|
||||
print("FAIL: console glyphs the Latin-2 font cannot draw (R-725):\n " + "\n ".join(failures))
|
||||
return 1
|
||||
print("OK: %d printf literals + %d goldens use only console-safe glyphs" % (checked, len(goldens)))
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
@@ -0,0 +1,76 @@
|
||||
#!/usr/bin/env python3
|
||||
# -*- coding: utf-8 -*-
|
||||
"""R-587: a RELEASE ISO build refuses to start while a *.rootpw.txt sits in its out directory.
|
||||
|
||||
The out directory is the public bucket's publish source; a root-password file there was kept off the
|
||||
bucket only by the publish command's --include pattern, by an accident of naming.
|
||||
|
||||
HOW IT RUNS ANYWHERE. The build script is bash and needs docker; the CI runner has neither (Alpine +
|
||||
BusyBox + python3 + git). So this test lifts the `rootpw_guard` function out of build-felhom-iso.sh
|
||||
VERBATIM and runs it under `sh` with a stub `die` — the function is written in POSIX sh for exactly
|
||||
this. It also checks, statically, that the script CALLS the guard before the build does anything else
|
||||
of consequence (the clean-tree gate and the docker preflight), because a guard that is defined and not
|
||||
called is the seam-built-never-wired shape.
|
||||
Run: python3 scripts/iso/test/test_rootpw_guard.py"""
|
||||
import os
|
||||
import re
|
||||
import shutil
|
||||
import subprocess
|
||||
import sys
|
||||
import tempfile
|
||||
|
||||
HERE = os.path.dirname(os.path.abspath(__file__))
|
||||
BUILD = os.path.join(os.path.dirname(HERE), "build-felhom-iso.sh")
|
||||
|
||||
|
||||
def guard_source():
|
||||
text = open(BUILD, encoding="utf-8").read()
|
||||
m = re.search(r"^rootpw_guard\(\) \{\n.*?^\}\n", text, re.S | re.M)
|
||||
if not m:
|
||||
raise SystemExit("FAIL: rootpw_guard() not found in build-felhom-iso.sh")
|
||||
return text, m.group(0)
|
||||
|
||||
|
||||
def run_guard(func, release, out_dir):
|
||||
script = ('die() { echo "DIE: $1"; exit 1; }\nRELEASE=%s\nOUT_DIR=%s\n%s\nrootpw_guard\necho PROCEEDED\n'
|
||||
% ("true" if release else "false", out_dir, func))
|
||||
p = subprocess.run(["sh", "-c", script], capture_output=True, text=True)
|
||||
return p.returncode, p.stdout + p.stderr
|
||||
|
||||
|
||||
def main():
|
||||
fails = []
|
||||
text, func = guard_source()
|
||||
tmp = tempfile.mkdtemp(prefix="rootpw-guard-")
|
||||
try:
|
||||
open(os.path.join(tmp, "felhom-installer-9.9.9-pve9.2-1.iso"), "w").close()
|
||||
# 1 — the genuine article: a release with a clean out dir proceeds.
|
||||
rc, out = run_guard(func, True, tmp)
|
||||
if rc != 0 or "PROCEEDED" not in out:
|
||||
fails.append("clean out dir: a release build was refused (rc=%d): %s" % (rc, out))
|
||||
# 2 — the decoy: a stray rootpw file (named so the publish --include would MISS it) refuses.
|
||||
stray = os.path.join(tmp, "felhom-pve-9.2-1-v1.24.0-nested.iso.rootpw.txt")
|
||||
open(stray, "w").close()
|
||||
rc, out = run_guard(func, True, tmp)
|
||||
if rc == 0 or "PROCEEDED" in out or "rootpw.txt" not in out:
|
||||
fails.append("stray rootpw file: the release build was NOT refused (rc=%d): %s" % (rc, out))
|
||||
# 3 — a non-release build in the same dir proceeds (it is the producer of these files, not a publish).
|
||||
rc, out = run_guard(func, False, tmp)
|
||||
if rc != 0 or "PROCEEDED" not in out:
|
||||
fails.append("non-release build was refused (rc=%d): %s" % (rc, out))
|
||||
finally:
|
||||
shutil.rmtree(tmp, ignore_errors=True)
|
||||
# 4 — wired: the guard is CALLED, and before the clean-tree gate and the docker preflight.
|
||||
call = re.search(r"^rootpw_guard\s*$", text, re.M)
|
||||
later = [re.search(r"^clean_tree_gate\s*$", text, re.M), re.search(r"^command -v docker", text, re.M)]
|
||||
if not call or any(m is None or m.start() < call.start() for m in later):
|
||||
fails.append("rootpw_guard is not called before clean_tree_gate and the docker preflight")
|
||||
if fails:
|
||||
print("FAIL (R-587):\n " + "\n ".join(fails))
|
||||
return 1
|
||||
print("OK: a release build refuses a *.rootpw.txt in its out dir; a clean dir and a non-release build proceed")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
Reference in New Issue
Block a user