Files
hermes-agent/scripts/termux/check_apt.sh
ethernet 9214174e07 fix(ci): lint legs after the main merge
- check_no_tmp_literals: resolve scratch via tempfile/os.tmpdir; the termux
  container mount point is one marked variable per script
- ruff TID251: desktop E2E fixtures may reach PM internals like tests do;
  the pm.runtime_stage ban message no longer names a module that never existed
- auth_codex: build the capped httpx stream subclass on first use so importing
  hermes_cli.auth_codex no longer forces httpx (the lazy proxy in auth_constants
  was defeated by a module-scope base class; broke lanes without httpx)
- desktop-smoke: launchApp is a parameter; the bundle-env test substitutes a
  refusing launcher instead of letting Playwright spawn a dying binary
  (3 unhandled rejections failed the tests-js lane)
2026-09-19 23:25:18 -04:00

43 lines
1.9 KiB
Bash
Executable File

#!/data/data/com.termux/files/usr/bin/bash
# Verify the signed repository with the same non-root APT used on a phone.
set -euo pipefail
export PREFIX=/data/data/com.termux/files/usr
export PATH="$PREFIX/bin:$PATH"
suite="${1:?APT suite required}"
expected="${2:?expected package version required}"
repository="${3:-file:/apt}"
ctmp=/tmp # no-tmp: ok — where the caller mounts validate_installed.py inside this container
work="$(mktemp -d "$PREFIX/tmp/hermes-apt-proof.XXXXXX")"
trap 'rm -rf "$work"' EXIT
mkdir -p "$work/lists/partial" "$work/archives/partial"
printf 'deb [signed-by=/apt/key.asc by-hash=force] %s %s main\n' "$repository" "$suite" > "$work/sources.list"
apt_options=(
-o "Dir::Etc::sourcelist=$work/sources.list"
-o "Dir::Etc::sourceparts=-"
-o "Dir::State::lists=$work/lists"
-o "Dir::Cache::archives=$work/archives"
-o "DPkg::Options::=--force-not-root"
-o "DPkg::Options::=--force-script-chrootless"
)
mkdir -p "$work/state"
printf 'user data survives package replacement\n' > "$work/state/sentinel"
export HERMES_HOME="$work/state"
if [ -f /previous.deb ]; then
dpkg --force-not-root --force-script-chrootless --install /previous.deb
previous="$(dpkg-query -W -f='${Version}' hermes-agent)"
dpkg --compare-versions "$expected" gt "$previous"
fi
apt-get "${apt_options[@]}" update
apt-get "${apt_options[@]}" --yes install hermes-agent
actual="$(dpkg-query -W -f='${Version}' hermes-agent)"
[ "$actual" = "$expected" ]
[ "$(cat "$work/state/sentinel")" = 'user data survives package replacement' ]
root="$PREFIX/lib/hermes-agent"
export LD_LIBRARY_PATH="$root/tools/python$PREFIX/lib:$root/tools/node$PREFIX/lib:$root/tools/ffmpeg$PREFIX/lib:$root/runtime-libs/lib:$PREFIX/lib"
export PYTHONPATH="$root/app"
"$root/venv/bin/python" "$ctmp/validate_installed.py"
printf 'SIGNED_APT_INSTALL_OK %s\n' "$actual"
if [ -f /previous.deb ]; then
printf 'SIGNED_APT_UPGRADE_OK %s -> %s\n' "$previous" "$actual"
fi