Files
go-sip/scripts/check-install-diagnostics.sh
T

68 lines
2.9 KiB
Bash
Executable File

#!/usr/bin/env bash
# Root installer tests use fake package commands in a network-disabled container.
set -euo pipefail
ROOT=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")/.." && pwd)
helper="$ROOT/deploys/cell/install-diagnostics.sh"
[[ -f "$helper" ]] || { echo 'diagnostic installer missing' >&2; exit 1; }
tmp=$(mktemp -d)
trap 'rm -rf "$tmp"' EXIT
mkdir "$tmp/bin"
cat > "$tmp/bin/apt-get" <<'SH'
#!/bin/sh
printf '%s frontend=%s\n' "$*" "${DEBIAN_FRONTEND:-}" >> /fixture/apt.log
if [ "$*" = update ] && [ "${FAIL_UPDATE:-0}" = 1 ]; then exit 41; fi
if [ "${1:-}" = install ] && [ "${FAIL_INSTALL:-0}" = 1 ]; then exit 42; fi
SH
cat > "$tmp/bin/tcpdump" <<'SH'
#!/bin/sh
[ "${FAIL_TCPDUMP:-0}" = 0 ] || exit 43
printf 'tcpdump version fixture\n'
SH
cat > "$tmp/bin/tshark" <<'SH'
#!/bin/sh
[ "${FAIL_TSHARK:-0}" = 0 ] || exit 44
case "$*" in
--version) printf 'TShark fixture\n' ;;
'-G protocols')
printf 'Session Initiation Protocol\tSIP\tsip\n'
[ "${MISSING_RTP:-0}" = 0 ] && printf 'Real-Time Transport Protocol\tRTP\trtp\n'
exit 0 ;;
*) exit 45 ;;
esac
SH
chmod 755 "$tmp/bin/"*
cat > "$tmp/check.sh" <<'SH'
#!/bin/bash
set -euo pipefail
export PATH=/fixture/bin:/usr/bin:/bin
for environment in production development test; do
rm -f /fixture/apt.log
AGENT_ENVIRONMENT="$environment" /bin/bash /install-diagnostics.sh
grep -Fx 'update frontend=noninteractive' /fixture/apt.log
grep -Fx 'install -y --no-install-recommends tcpdump tshark frontend=noninteractive' /fixture/apt.log
done
for failure in FAIL_UPDATE FAIL_INSTALL FAIL_TCPDUMP FAIL_TSHARK MISSING_RTP; do
if env "$failure=1" /bin/bash /install-diagnostics.sh; then
echo "installer swallowed failure: $failure" >&2; exit 1
fi
done
if /bin/bash /install-diagnostics.sh --nonprod; then echo 'installer accepted environment switch' >&2; exit 1; fi
printf 'diagnostic installer root checks passed\n'
SH
chmod 755 "$tmp/check.sh"
docker run --rm --network none -v "$tmp:/fixture" -v "$helper:/install-diagnostics.sh:ro" debian:13-slim /bin/bash /fixture/check.sh
if [[ $EUID != 0 ]] && bash "$helper"; then echo 'installer accepted unprivileged execution' >&2; exit 1; fi
python3 - "$ROOT" <<'PY'
import pathlib, sys
root=pathlib.Path(sys.argv[1])
production=(root/'deploys/install.sh').read_text()
native=(root/'deploys/cell/install-asterisk-user.sh').read_text()
package=(root/'deploys/build-package.sh').read_text()
build=(root/'deploys/cell/build-asterisk-native.sh').read_text()
assert 'cell/install-diagnostics.sh' in production, 'production installer does not provision diagnostics'
assert 'install-diagnostics.sh' in native and native.index('install-diagnostics.sh') < native.index('mkdir -p "$(dirname "$prefix")"'), 'native installer must provision diagnostics before changing Asterisk'
assert 'cell/install-diagnostics.sh' in package, 'production package omits helper'
assert 'install-diagnostics.sh' in build, 'native package omits helper'
print('both installation paths include unconditional diagnostic provisioning')
PY