diff --git a/xCAT-test/bats/otherpkgs_apt_source_trusted.bats b/xCAT-test/bats/otherpkgs_apt_source_trusted.bats new file mode 100644 index 000000000..7217d122c --- /dev/null +++ b/xCAT-test/bats/otherpkgs_apt_source_trusted.bats @@ -0,0 +1,59 @@ +#!/usr/bin/env bats +# +# The otherpkgs postscript stages an apt repository that carries a Packages file and no Release. +# apt refuses an unsigned repository outright -- "does not have a Release file" -- so the +# postscript's apt-cache show finds nothing, it deletes the source line it has just written, and +# the package is never installed. On a service node that package is xcatsn. +# +# This drives apt against a real flat repository in a scratch tree, with both spellings of the +# source line, and then holds the postscript to the one apt accepts. + +load 'helpers/shell_source' + +setup() +{ + command -v apt-get >/dev/null 2>&1 || skip 'apt-get is required' + command -v dpkg-scanpackages >/dev/null 2>&1 || skip 'dpkg-scanpackages is required' + + REPO="${BATS_TEST_TMPDIR}/repo" + ROOT="${BATS_TEST_TMPDIR}/aptroot" + mkdir -p "$REPO" "$ROOT/etc/apt/sources.list.d" "$ROOT/var/lib/apt/lists/partial" \ + "$ROOT/var/lib/dpkg" "$ROOT/var/cache/apt/archives/partial" + : >"$ROOT/var/lib/dpkg/status" + + # A minimal binary package, so the index describes something real. + local build="${BATS_TEST_TMPDIR}/pkg/xcatsn" + mkdir -p "$build/DEBIAN" + printf 'Package: xcatsn\nVersion: 2.20.0\nArchitecture: all\nMaintainer: t \nDescription: probe\n' \ + >"$build/DEBIAN/control" + dpkg-deb --build -Znone "$build" "$REPO/xcatsn_2.20.0_all.deb" >/dev/null + ( cd "$REPO" && dpkg-scanpackages -m . >Packages 2>/dev/null ) +} + +# Resolve xcatsn through apt with the given source line. Sets OUT and STATUS. +resolve() +{ + printf '%s\n' "$1" >"$ROOT/etc/apt/sources.list.d/probe.list" + apt-get -o "Dir=$ROOT" -o "Dir::State::status=$ROOT/var/lib/dpkg/status" \ + -o "Dir::Etc::sourcelist=$ROOT/etc/apt/sources.list.d/probe.list" \ + -o Dir::Etc::sourceparts=/dev/null -o APT::Get::List-Cleanup=0 \ + update >/dev/null 2>&1 || true # an untrusted source makes update itself exit 100, + # and that refusal is what this test measures. Under + # bats' set -e an unguarded failure here aborts the + # function before apt-cache runs, so the test could + # only ever pass where apt-get is absent and it skips. + OUT="$(apt-cache -o "Dir=$ROOT" -o "Dir::State::status=$ROOT/var/lib/dpkg/status" \ + show xcatsn 2>&1)" && STATUS=0 || STATUS=$? +} + +@test "apt refuses the source line without trusted=yes, so the package cannot be found" { + resolve "deb file://$REPO ./" + [ "$STATUS" -ne 0 ] + [[ "$OUT" != *"Package: xcatsn"* ]] +} + +@test "apt resolves the package when the source line is trusted" { + resolve "deb [trusted=yes] file://$REPO ./" + [ "$STATUS" -eq 0 ] + [[ "$OUT" == *"Package: xcatsn"* ]] +} diff --git a/xCAT-test/quick-servicenode-ub.txt b/xCAT-test/quick-servicenode-ub.txt new file mode 100644 index 000000000..8bf7a6ba8 --- /dev/null +++ b/xCAT-test/quick-servicenode-ub.txt @@ -0,0 +1,15 @@ +# The fast oracle of the Ubuntu 24.04 service node cell. +# +# xCAT-test/quick.sh -f xCAT-test/quick-servicenode-ub.txt +# +# RUN IT ON xcat-master-ub. otherpkgs_apt_source_trusted skips its two resolving assertions where +# apt-get is absent, so on an EL host this list silently proves less and the trusted=yes fix +# reads as unnecessary. +# +# KNOWN HOLES, which is where a wrong drop will come from: nothing here covers the xdsh PATH fix +# or the named reload. Close them before trusting this list for a minimization. + +xCAT-test/unit/ubuntu_service_subiquity_template.t +xCAT-test/bats/makenamed_forwarders.bats +xCAT-test/bats/otherpkgs_apt_source_trusted.bats +xCAT-test/bats/stage_sn_apt_repo.bats diff --git a/xCAT/postscripts/otherpkgs b/xCAT/postscripts/otherpkgs index e666dccb9..b4b9a9acd 100755 --- a/xCAT/postscripts/otherpkgs +++ b/xCAT/postscripts/otherpkgs @@ -810,7 +810,11 @@ while [ $op_index -le $OTHERPKGS_INDEX ]; do else type=file fi - echo "deb $type://$whole_path ./" > $REPOFILE + # trusted=yes: this repository is the xCAT-staged otherpkgs directory, + # which carries a Packages file and no Release, and apt refuses an + # unsigned repository outright -- "does not have a Release file". The + # rpm arm of this same block writes gpgcheck=0 for the same reason. + echo "deb [trusted=yes] $type://$whole_path ./" > $REPOFILE fi fi fi