Allow matched Debian 12 native Asterisk packages for nonproduction tests

This commit is contained in:
2026-10-01 20:45:23 +08:00
parent fabfbf71c6
commit b91016511c
6 changed files with 53 additions and 5 deletions
+7 -1
View File
@@ -10,11 +10,15 @@ DEPS="$PKG/asterisk-$VERSION-deps"
OUT=${OUT_DIR:-"$PKG/asterisk-$VERSION-native"}
JOBS=${JOBS:-1}
WORK=${WORK_DIR:-"$ROOT/.local/asterisk-build-$VERSION"}
NONPROD=${NONPROD:-0}
. /etc/os-release
source "$ROOT/deploys/cell/native-platform.sh"
require_native_platform "$ID" "$VERSION_ID" "$(uname -m)" "debian:$VERSION_ID:x86_64" "$NONPROD"
[[ -f "$SRC_ARCHIVE" && -f "$SRC_SHA" ]] || { echo 'Asterisk source archive/checksum missing' >&2; exit 1; }
[[ -d "$DEPS" ]] || { echo 'Asterisk dependency cache missing' >&2; exit 1; }
command -v make >/dev/null || { echo 'make is required; install deploys/cell/debian-build-packages.lock' >&2; exit 1; }
sha256sum -c "$SRC_SHA"
(cd "$PKG" && sha256sum -c "$(basename "$SRC_SHA")")
rm -rf -- "$WORK" "$OUT"
mkdir -p "$WORK" "$OUT/cache"
cp "$DEPS"/*.tar.bz2 "$OUT/cache/"
@@ -33,6 +37,8 @@ rm -rf -- "$STAGE/etc/asterisk"
tar -C "$STAGE" -cpf "$OUT/asterisk-$VERSION-native-stage.tar" .
cp "$ROOT/deploys/cell/asterisk.service" "$OUT/asterisk.service"
cp "$ROOT/deploys/cell/install-asterisk-native.sh" "$OUT/install-asterisk-native.sh"
cp "$ROOT/deploys/cell/native-platform.sh" "$OUT/native-platform.sh"
printf 'debian:%s:x86_64\n' "$VERSION_ID" > "$OUT/build-platform"
chmod 0755 "$OUT/install-asterisk-native.sh"
(
cd "$OUT"
+5 -2
View File
@@ -3,9 +3,11 @@ set -euo pipefail
[[ ${EUID} -eq 0 ]] || { echo 'install-asterisk-native.sh must run as root' >&2; exit 1; }
START=false
NONPROD=0
for arg in "$@"; do
case "$arg" in
--start) START=true ;;
--nonprod) NONPROD=1 ;;
*) echo "unknown option: $arg" >&2; exit 2 ;;
esac
done
@@ -13,8 +15,9 @@ done
PACKAGE_DIR=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)
cd -- "$PACKAGE_DIR"
. /etc/os-release
[[ ${ID:-} == debian && ${VERSION_ID:-} == 13 ]] || { echo 'Debian 13 is required' >&2; exit 1; }
[[ $(uname -m) == x86_64 ]] || { echo 'amd64 host is required' >&2; exit 1; }
[[ -f native-platform.sh && -f build-platform ]] || { echo 'native build platform metadata is missing' >&2; exit 1; }
source ./native-platform.sh
require_native_platform "$ID" "$VERSION_ID" "$(uname -m)" "$(<build-platform)" "$NONPROD"
STAGE=asterisk-22.10.1-native-stage.tar
sha256sum -c "$STAGE.sha256"
[[ -f asterisk.service ]] || { echo 'asterisk.service is missing' >&2; exit 1; }
+14
View File
@@ -0,0 +1,14 @@
#!/usr/bin/env bash
# A Debian 13 build must never be installed on Debian 12: its GLIBC symbols
# exceed the older host's libc. Debian 12 is restricted to nonproduction.
require_native_platform() {
local os=$1 version=$2 arch=$3 built_for=$4 nonprod=$5
if [[ $arch == x86_64 && $os == debian && $built_for == "debian:$version:x86_64" ]]; then
if [[ $version == 13 || ( $version == 12 && $nonprod == 1 ) ]]; then
return 0
fi
fi
printf 'native Asterisk package/host mismatch or unsupported production platform: host=%s:%s:%s package=%s nonprod=%s\n' \
"$os" "$version" "$arch" "$built_for" "$nonprod" >&2
return 1
}
+19
View File
@@ -0,0 +1,19 @@
#!/usr/bin/env bash
set -euo pipefail
source "$(dirname "$0")/native-platform.sh"
check() {
local want=$1; shift
if require_native_platform "$@" >/dev/null 2>&1; then
[[ $want == pass ]] || { echo "unexpected pass: $*" >&2; exit 1; }
else
[[ $want == fail ]] || { echo "unexpected reject: $*" >&2; exit 1; }
fi
}
check pass debian 13 x86_64 debian:13:x86_64 0
check pass debian 12 x86_64 debian:12:x86_64 1
check fail debian 12 x86_64 debian:12:x86_64 0
check fail debian 12 x86_64 debian:13:x86_64 1
check fail debian 13 x86_64 debian:12:x86_64 1
check fail debian 12 aarch64 debian:12:aarch64 1
check fail ubuntu 24.04 x86_64 ubuntu:24.04:x86_64 1
printf 'native Asterisk platform checks passed\n'
+7 -1
View File
@@ -2,7 +2,13 @@
This is the **target host layout**, not an approved deployment of the current binary. The current business commands are isolated Mock-only and reject mixed/real before opening resources; the local release manifest has `production_approval=false`. Neither the steps below nor a local package/check authorize real services or calls. Native Asterisk loading and required non-production diagnostics still need separate evidence.
Production is a small systemd installation on Debian 13 amd64:
Debian 12 amd64 is supported only for explicitly marked non-production test hosts.
Build the native Asterisk archive **on Debian 12** with `NONPROD=1`; the
installer requires its matching `build-platform` marker and `--nonprod`.
The existing Debian 13 binary requires newer glibc and must never be copied
to Debian 12. This exception does not approve production deployment or real calls.
Production remains a small systemd installation on Debian 13 amd64:
1. native Asterisk Cell (`asterisk.service`), owned by the approved SIP
management release;