- check_no_tmp_literals: resolve scratch via tempfile/os.tmpdir; the termux container mount point is one marked variable per script - ruff TID251: desktop E2E fixtures may reach PM internals like tests do; the pm.runtime_stage ban message no longer names a module that never existed - auth_codex: build the capped httpx stream subclass on first use so importing hermes_cli.auth_codex no longer forces httpx (the lazy proxy in auth_constants was defeated by a module-scope base class; broke lanes without httpx) - desktop-smoke: launchApp is a parameter; the bundle-env test substitutes a refusing launcher instead of letting Playwright spawn a dying binary (3 unhandled rejections failed the tests-js lane)
43 lines
1.9 KiB
Bash
Executable File
43 lines
1.9 KiB
Bash
Executable File
#!/data/data/com.termux/files/usr/bin/bash
|
|
# Verify the signed repository with the same non-root APT used on a phone.
|
|
set -euo pipefail
|
|
export PREFIX=/data/data/com.termux/files/usr
|
|
export PATH="$PREFIX/bin:$PATH"
|
|
suite="${1:?APT suite required}"
|
|
expected="${2:?expected package version required}"
|
|
repository="${3:-file:/apt}"
|
|
ctmp=/tmp # no-tmp: ok — where the caller mounts validate_installed.py inside this container
|
|
work="$(mktemp -d "$PREFIX/tmp/hermes-apt-proof.XXXXXX")"
|
|
trap 'rm -rf "$work"' EXIT
|
|
mkdir -p "$work/lists/partial" "$work/archives/partial"
|
|
printf 'deb [signed-by=/apt/key.asc by-hash=force] %s %s main\n' "$repository" "$suite" > "$work/sources.list"
|
|
apt_options=(
|
|
-o "Dir::Etc::sourcelist=$work/sources.list"
|
|
-o "Dir::Etc::sourceparts=-"
|
|
-o "Dir::State::lists=$work/lists"
|
|
-o "Dir::Cache::archives=$work/archives"
|
|
-o "DPkg::Options::=--force-not-root"
|
|
-o "DPkg::Options::=--force-script-chrootless"
|
|
)
|
|
mkdir -p "$work/state"
|
|
printf 'user data survives package replacement\n' > "$work/state/sentinel"
|
|
export HERMES_HOME="$work/state"
|
|
if [ -f /previous.deb ]; then
|
|
dpkg --force-not-root --force-script-chrootless --install /previous.deb
|
|
previous="$(dpkg-query -W -f='${Version}' hermes-agent)"
|
|
dpkg --compare-versions "$expected" gt "$previous"
|
|
fi
|
|
apt-get "${apt_options[@]}" update
|
|
apt-get "${apt_options[@]}" --yes install hermes-agent
|
|
actual="$(dpkg-query -W -f='${Version}' hermes-agent)"
|
|
[ "$actual" = "$expected" ]
|
|
[ "$(cat "$work/state/sentinel")" = 'user data survives package replacement' ]
|
|
root="$PREFIX/lib/hermes-agent"
|
|
export LD_LIBRARY_PATH="$root/tools/python$PREFIX/lib:$root/tools/node$PREFIX/lib:$root/tools/ffmpeg$PREFIX/lib:$root/runtime-libs/lib:$PREFIX/lib"
|
|
export PYTHONPATH="$root/app"
|
|
"$root/venv/bin/python" "$ctmp/validate_installed.py"
|
|
printf 'SIGNED_APT_INSTALL_OK %s\n' "$actual"
|
|
if [ -f /previous.deb ]; then
|
|
printf 'SIGNED_APT_UPGRADE_OK %s -> %s\n' "$previous" "$actual"
|
|
fi
|