#!/usr/bin/env bash # Root installer tests use fake package commands in a network-disabled container. set -euo pipefail ROOT=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")/.." && pwd) helper="$ROOT/deploys/cell/install-diagnostics.sh" [[ -f "$helper" ]] || { echo 'diagnostic installer missing' >&2; exit 1; } tmp=$(mktemp -d) trap 'rm -rf "$tmp"' EXIT mkdir "$tmp/bin" cat > "$tmp/bin/apt-get" <<'SH' #!/bin/sh printf '%s frontend=%s\n' "$*" "${DEBIAN_FRONTEND:-}" >> /fixture/apt.log if [ "$*" = update ] && [ "${FAIL_UPDATE:-0}" = 1 ]; then exit 41; fi if [ "${1:-}" = install ] && [ "${FAIL_INSTALL:-0}" = 1 ]; then exit 42; fi SH cat > "$tmp/bin/tcpdump" <<'SH' #!/bin/sh [ "${FAIL_TCPDUMP:-0}" = 0 ] || exit 43 printf 'tcpdump version fixture\n' SH cat > "$tmp/bin/tshark" <<'SH' #!/bin/sh [ "${FAIL_TSHARK:-0}" = 0 ] || exit 44 case "$*" in --version) printf 'TShark fixture\n' ;; '-G protocols') printf 'Session Initiation Protocol\tSIP\tsip\n' [ "${MISSING_RTP:-0}" = 0 ] && printf 'Real-Time Transport Protocol\tRTP\trtp\n' exit 0 ;; *) exit 45 ;; esac SH chmod 755 "$tmp/bin/"* cat > "$tmp/check.sh" <<'SH' #!/bin/bash set -euo pipefail export PATH=/fixture/bin:/usr/bin:/bin for environment in production development test; do rm -f /fixture/apt.log AGENT_ENVIRONMENT="$environment" /bin/bash /install-diagnostics.sh grep -Fx 'update frontend=noninteractive' /fixture/apt.log grep -Fx 'install -y --no-install-recommends tcpdump tshark frontend=noninteractive' /fixture/apt.log done for failure in FAIL_UPDATE FAIL_INSTALL FAIL_TCPDUMP FAIL_TSHARK MISSING_RTP; do if env "$failure=1" /bin/bash /install-diagnostics.sh; then echo "installer swallowed failure: $failure" >&2; exit 1 fi done if /bin/bash /install-diagnostics.sh --nonprod; then echo 'installer accepted environment switch' >&2; exit 1; fi printf 'diagnostic installer root checks passed\n' SH chmod 755 "$tmp/check.sh" docker run --rm --network none -v "$tmp:/fixture" -v "$helper:/install-diagnostics.sh:ro" debian:13-slim /bin/bash /fixture/check.sh if [[ $EUID != 0 ]] && bash "$helper"; then echo 'installer accepted unprivileged execution' >&2; exit 1; fi python3 - "$ROOT" <<'PY' import pathlib, sys root=pathlib.Path(sys.argv[1]) production=(root/'deploys/install.sh').read_text() native=(root/'deploys/cell/install-asterisk-user.sh').read_text() package=(root/'deploys/build-package.sh').read_text() build=(root/'deploys/cell/build-asterisk-native.sh').read_text() assert 'cell/install-diagnostics.sh' in production, 'production installer does not provision diagnostics' assert 'install-diagnostics.sh' in native and native.index('install-diagnostics.sh') < native.index('mkdir -p "$(dirname "$prefix")"'), 'native installer must provision diagnostics before changing Asterisk' assert 'cell/install-diagnostics.sh' in package, 'production package omits helper' assert 'install-diagnostics.sh' in build, 'native package omits helper' print('both installation paths include unconditional diagnostic provisioning') PY