Allow matched Debian 12 native Asterisk packages for nonproduction tests
This commit is contained in:
@@ -108,7 +108,7 @@
|
||||
## 运行环境、诊断与开发门禁
|
||||
|
||||
- 项目是独立 Go module,工具链 Go **1.27.1**;普通构建、测试、运行不读取父项目业务模块、数据库、env 或夹具。标准库和成熟官方 SDK 优先,Cobra 显式 `agent`/`dispatcher`,单制品分角色/权限/目录。禁止自行重写 SIP/ARI、RTP/RTCP/G.711、WebSocket、AMQP、SQLite 驱动、OSS 签名及 SDK 已覆盖的 AI 协议;核验现有依赖能力后再新增库。生产原生 Asterisk 仍由独立 Cell 的 systemd 统一管理,不声称当前 Mock 已完成真实媒体或 1000 路容量验收。
|
||||
- ECS 优先 Debian 13(Trixie)minimal;只有阿里云北京无可用镜像时允许 Ubuntu 24.04 LTS。Asterisk 直接安装在承载 ECS 主机,由 systemd 启用自启动并核对 `enabled+active`;不得以前台进程或容器入口代替。
|
||||
- 生产 ECS 优先 Debian 13(Trixie)minimal;只有阿里云北京无可用镜像时允许 Ubuntu 24.04 LTS。Debian 12 仅供明确标记的非生产测试:必须在 Debian 12 原生构建 Asterisk,不得部署 Debian 13 编译的制品,也不得据此批准生产发布。Asterisk 直接安装在承载 ECS 主机,由 systemd 启用自启动并核对 `enabled+active`;不得以前台进程或容器入口代替。
|
||||
- 开发、Mock、mixed、real 的**非生产主机**部署与诊断步骤默认强制,不因时间/旧环境/调用方参数跳过或静默降级;显式关闭即失败。每次新主机/版本/Cell 至少留存脱敏 ECS/EIP/网络只读核验、Debian/架构/磁盘/权限、`rogee` SSH 与加固、发布包/依赖 SHA-256、Asterisk/systemd `enabled+active`、ARI/PJSIP endpoint/contact、媒体 profile/端口及运行版本。
|
||||
- 非生产 mixed/real 呼叫必须先通过上述真实时间门禁;**拨号前**启动受限 SIP/RTP 抓包和 Asterisk PJSIP logger,结束后采集 SIP 响应/INVITE–BYE 时间线、SDP codec/媒体地址端口、RTP 包/字节、录音与 ASR/LLM/TTS 事实及 SHA-256。失败通话也保存状态和抓包;tcpdump/CAP_NET_RAW、PJSIP logger 或 ARI/PJSIP 状态任一不可用须失败关闭。原始抓包/日志/录音只写受限证据目录,聊天、提交与长期证据只存脱敏摘要/计数/状态码/hash,不含完整用户音频/对话或凭据。统一入口见 [`deploys/test/nonprod-call-evidence.sh`](deploys/test/nonprod-call-evidence.sh);本地 `make check` 与 `make release-check-local` **不能代签主机诊断或生产门禁**。
|
||||
- 当前完成前至少检查格式、当前合同和 Proto 来源/hash、`go vet ./...`、`go test -race ./...`、构建、确实运行的隔离 RabbitMQ/HTTPS/双向 TLS 端到端测试、业务单元覆盖率 ≥65% 及 A01–A12/K01–K16 对照。真实 SaaS/management/OSS/AI/Asterisk/ECS、第二节点/Cell/租户、多 D 额度、容量/N+1及生产切换必须另有事实与授权,任何本机 Mock 通过不得写成其签收。
|
||||
|
||||
@@ -10,11 +10,15 @@ DEPS="$PKG/asterisk-$VERSION-deps"
|
||||
OUT=${OUT_DIR:-"$PKG/asterisk-$VERSION-native"}
|
||||
JOBS=${JOBS:-1}
|
||||
WORK=${WORK_DIR:-"$ROOT/.local/asterisk-build-$VERSION"}
|
||||
NONPROD=${NONPROD:-0}
|
||||
. /etc/os-release
|
||||
source "$ROOT/deploys/cell/native-platform.sh"
|
||||
require_native_platform "$ID" "$VERSION_ID" "$(uname -m)" "debian:$VERSION_ID:x86_64" "$NONPROD"
|
||||
|
||||
[[ -f "$SRC_ARCHIVE" && -f "$SRC_SHA" ]] || { echo 'Asterisk source archive/checksum missing' >&2; exit 1; }
|
||||
[[ -d "$DEPS" ]] || { echo 'Asterisk dependency cache missing' >&2; exit 1; }
|
||||
command -v make >/dev/null || { echo 'make is required; install deploys/cell/debian-build-packages.lock' >&2; exit 1; }
|
||||
sha256sum -c "$SRC_SHA"
|
||||
(cd "$PKG" && sha256sum -c "$(basename "$SRC_SHA")")
|
||||
rm -rf -- "$WORK" "$OUT"
|
||||
mkdir -p "$WORK" "$OUT/cache"
|
||||
cp "$DEPS"/*.tar.bz2 "$OUT/cache/"
|
||||
@@ -33,6 +37,8 @@ rm -rf -- "$STAGE/etc/asterisk"
|
||||
tar -C "$STAGE" -cpf "$OUT/asterisk-$VERSION-native-stage.tar" .
|
||||
cp "$ROOT/deploys/cell/asterisk.service" "$OUT/asterisk.service"
|
||||
cp "$ROOT/deploys/cell/install-asterisk-native.sh" "$OUT/install-asterisk-native.sh"
|
||||
cp "$ROOT/deploys/cell/native-platform.sh" "$OUT/native-platform.sh"
|
||||
printf 'debian:%s:x86_64\n' "$VERSION_ID" > "$OUT/build-platform"
|
||||
chmod 0755 "$OUT/install-asterisk-native.sh"
|
||||
(
|
||||
cd "$OUT"
|
||||
|
||||
@@ -3,9 +3,11 @@ set -euo pipefail
|
||||
|
||||
[[ ${EUID} -eq 0 ]] || { echo 'install-asterisk-native.sh must run as root' >&2; exit 1; }
|
||||
START=false
|
||||
NONPROD=0
|
||||
for arg in "$@"; do
|
||||
case "$arg" in
|
||||
--start) START=true ;;
|
||||
--nonprod) NONPROD=1 ;;
|
||||
*) echo "unknown option: $arg" >&2; exit 2 ;;
|
||||
esac
|
||||
done
|
||||
@@ -13,8 +15,9 @@ done
|
||||
PACKAGE_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)
|
||||
cd -- "$PACKAGE_DIR"
|
||||
. /etc/os-release
|
||||
[[ ${ID:-} == debian && ${VERSION_ID:-} == 13 ]] || { echo 'Debian 13 is required' >&2; exit 1; }
|
||||
[[ $(uname -m) == x86_64 ]] || { echo 'amd64 host is required' >&2; exit 1; }
|
||||
[[ -f native-platform.sh && -f build-platform ]] || { echo 'native build platform metadata is missing' >&2; exit 1; }
|
||||
source ./native-platform.sh
|
||||
require_native_platform "$ID" "$VERSION_ID" "$(uname -m)" "$(<build-platform)" "$NONPROD"
|
||||
STAGE=asterisk-22.10.1-native-stage.tar
|
||||
sha256sum -c "$STAGE.sha256"
|
||||
[[ -f asterisk.service ]] || { echo 'asterisk.service is missing' >&2; exit 1; }
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
#!/usr/bin/env bash
|
||||
# A Debian 13 build must never be installed on Debian 12: its GLIBC symbols
|
||||
# exceed the older host's libc. Debian 12 is restricted to nonproduction.
|
||||
require_native_platform() {
|
||||
local os=$1 version=$2 arch=$3 built_for=$4 nonprod=$5
|
||||
if [[ $arch == x86_64 && $os == debian && $built_for == "debian:$version:x86_64" ]]; then
|
||||
if [[ $version == 13 || ( $version == 12 && $nonprod == 1 ) ]]; then
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
printf 'native Asterisk package/host mismatch or unsupported production platform: host=%s:%s:%s package=%s nonprod=%s\n' \
|
||||
"$os" "$version" "$arch" "$built_for" "$nonprod" >&2
|
||||
return 1
|
||||
}
|
||||
@@ -0,0 +1,19 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
source "$(dirname "$0")/native-platform.sh"
|
||||
check() {
|
||||
local want=$1; shift
|
||||
if require_native_platform "$@" >/dev/null 2>&1; then
|
||||
[[ $want == pass ]] || { echo "unexpected pass: $*" >&2; exit 1; }
|
||||
else
|
||||
[[ $want == fail ]] || { echo "unexpected reject: $*" >&2; exit 1; }
|
||||
fi
|
||||
}
|
||||
check pass debian 13 x86_64 debian:13:x86_64 0
|
||||
check pass debian 12 x86_64 debian:12:x86_64 1
|
||||
check fail debian 12 x86_64 debian:12:x86_64 0
|
||||
check fail debian 12 x86_64 debian:13:x86_64 1
|
||||
check fail debian 13 x86_64 debian:12:x86_64 1
|
||||
check fail debian 12 aarch64 debian:12:aarch64 1
|
||||
check fail ubuntu 24.04 x86_64 ubuntu:24.04:x86_64 1
|
||||
printf 'native Asterisk platform checks passed\n'
|
||||
@@ -2,7 +2,13 @@
|
||||
|
||||
This is the **target host layout**, not an approved deployment of the current binary. The current business commands are isolated Mock-only and reject mixed/real before opening resources; the local release manifest has `production_approval=false`. Neither the steps below nor a local package/check authorize real services or calls. Native Asterisk loading and required non-production diagnostics still need separate evidence.
|
||||
|
||||
Production is a small systemd installation on Debian 13 amd64:
|
||||
Debian 12 amd64 is supported only for explicitly marked non-production test hosts.
|
||||
Build the native Asterisk archive **on Debian 12** with `NONPROD=1`; the
|
||||
installer requires its matching `build-platform` marker and `--nonprod`.
|
||||
The existing Debian 13 binary requires newer glibc and must never be copied
|
||||
to Debian 12. This exception does not approve production deployment or real calls.
|
||||
|
||||
Production remains a small systemd installation on Debian 13 amd64:
|
||||
|
||||
1. native Asterisk Cell (`asterisk.service`), owned by the approved SIP
|
||||
management release;
|
||||
|
||||
Reference in New Issue
Block a user