test(termux): install from the signed APT repository before publishing

This commit is contained in:
ethernet
2026-09-06 15:56:35 -04:00
parent e9dfe6f7d8
commit f73ae58f5f
2 changed files with 46 additions and 0 deletions

View File

@@ -1049,6 +1049,16 @@ jobs:
--suite "hermes-$CHANNEL" \
--gpg-key-file "$RUNNER_TEMP/termux-apt-gpg.asc"
debs=(termux-build/deb/*.deb)
test "${#debs[@]}" -eq 1
version=$(dpkg-deb --field "${debs[0]}" Version)
digest=$(python3 -c 'from pm.lock import termux_docker_digest; print(termux_docker_digest())')
docker run --rm --platform linux/arm64 --user 1000:1000 --network none \
-v "$PWD/termux-build/apt:/apt:ro" \
-v "$PWD/scripts/termux/check_apt.sh:/tmp/check-apt.sh:ro" \
-v "$PWD/scripts/termux/validate_installed.py:/tmp/validate_installed.py:ro" \
"termux/termux-docker@$digest" bash /tmp/check-apt.sh "hermes-$CHANNEL" "$version"
# --key-is-full is MANDATORY on every feed-dir upload: without it
# r2-release.mjs re-prefixes the key into the tag archive
# (releases/tag/<tag>/) and the APT feed never lands at

36
scripts/termux/check_apt.sh Executable file
View File

@@ -0,0 +1,36 @@
#!/data/data/com.termux/files/usr/bin/bash
# Verify the signed repository with the same non-root APT used on a phone.
set -euo pipefail
export PREFIX=/data/data/com.termux/files/usr
export PATH="$PREFIX/bin:$PATH"
suite="${1:?APT suite required}"
expected="${2:?expected package version required}"
work="$(mktemp -d "$PREFIX/tmp/hermes-apt-proof.XXXXXX")"
trap 'rm -rf "$work"' EXIT
mkdir -p "$work/lists/partial" "$work/archives/partial"
printf 'deb [signed-by=/apt/key.asc] file:/apt %s main\n' "$suite" > "$work/sources.list"
apt_options=(
-o "Dir::Etc::sourcelist=$work/sources.list"
-o "Dir::Etc::sourceparts=-"
-o "Dir::State::lists=$work/lists"
-o "Dir::Cache::archives=$work/archives"
-o "DPkg::Options::=--force-not-root"
-o "DPkg::Options::=--force-script-chrootless"
)
if [ -f /previous.deb ]; then
dpkg --force-not-root --force-script-chrootless --install /previous.deb
previous="$(dpkg-query -W -f='${Version}' hermes-agent)"
dpkg --compare-versions "$expected" gt "$previous"
fi
apt-get "${apt_options[@]}" update
apt-get "${apt_options[@]}" --yes install hermes-agent
actual="$(dpkg-query -W -f='${Version}' hermes-agent)"
[ "$actual" = "$expected" ]
root="$PREFIX/lib/hermes-agent"
export LD_LIBRARY_PATH="$root/tools/python$PREFIX/lib:$root/tools/node$PREFIX/lib:$root/tools/ffmpeg$PREFIX/lib:$root/runtime-libs/lib:$PREFIX/lib"
export PYTHONPATH="$root/app"
"$root/venv/bin/python" /tmp/validate_installed.py
printf 'SIGNED_APT_INSTALL_OK %s\n' "$actual"
if [ -f /previous.deb ]; then
printf 'SIGNED_APT_UPGRADE_OK %s -> %s\n' "$previous" "$actual"
fi