Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
33 changes: 33 additions & 0 deletions conf/bootstrap_apt
Original file line number Diff line number Diff line change
Expand Up @@ -195,6 +195,39 @@ Enabled: $debian_backports_enabled
Signed-By: $DEBIAN_KEYRING
EOF

# Keel: the archive every Keel package comes from, in the bootstrap too, so
# that the plan installs keel-archive-keyring, inithooks and the rest from it.
# The key is the armored public key mk/turnkey.mk copied into the bootstrap
# from common's keys/, which apt reads as it is; the package later installs
# the same key as a binary keyring, and overlays/turnkey.d/keel-apt replaces
# this file with the one an installed machine keeps. KEEL_APT_TRACK says which
# track the build installs from (handbook decision 0043): stable, the default,
# reads trixie alone; testing also enables trixie-testing, where a package
# lands first, for an image of the testing channel.
KEEL_KEYRING=/usr/share/keyrings/keel-archive-keyring.asc
case "${KEEL_APT_TRACK:-stable}" in
stable) keel_testing_enabled=no ;;
testing) keel_testing_enabled=yes ;;
*) fatal "KEEL_APT_TRACK must be 'stable' or 'testing', got '$KEEL_APT_TRACK'" ;;
esac
[[ -f "$KEEL_KEYRING" ]] \
|| fatal "'$KEEL_KEYRING' is missing - mk/turnkey.mk copies it into the bootstrap from common's keys/"
cat > $SOURCES_LIST/keel.sources <<EOF
Types: deb
URIs: https://archive.keellinux.org
Suites: $CODENAME
Components: main
Enabled: yes
Signed-By: $KEEL_KEYRING

Types: deb
URIs: https://archive.keellinux.org
Suites: $CODENAME-testing
Components: main
Enabled: $keel_testing_enabled
Signed-By: $KEEL_KEYRING
EOF

if [[ -n "$PHP_VERSION" ]]; then
# Use 3rd party sury.org repo
# install support for https repo & wget (to download gpg key)
Expand Down
16 changes: 16 additions & 0 deletions conf/turnkey.d/keel-apt
Original file line number Diff line number Diff line change
Expand Up @@ -86,6 +86,22 @@ bad="$(grep -v ": $KEEL_PIN_PRIORITY\$" <<< "$pins" || true)"
[ -z "$bad" ] \
|| fatal "the Keel pin must be Pin-Priority $KEEL_PIN_PRIORITY (tracker#23): $(tr '\n' ' ' <<< "$bad")"

# --- the track the image follows (KEEL_APT_TRACK, as conf/bootstrap_apt read it)

case "${KEEL_APT_TRACK:-stable}" in
stable) : ;;
testing)
# an image built from the testing track follows it: the stanza the
# overlay ships off is turned on, nothing else in the file changes
sed -i '/^Suites: trixie-testing$/,/^$/ s/^Enabled: no$/Enabled: yes/' "$sources/keel.sources"
grep -qx 'Enabled: yes' <(sed -n '/^Suites: trixie-testing$/,/^$/p' "$sources/keel.sources") \
|| fatal "KEEL_APT_TRACK=testing, but '$sources/keel.sources' has no trixie-testing stanza to enable" ;;
*) fatal "KEEL_APT_TRACK must be 'stable' or 'testing', got '$KEEL_APT_TRACK'" ;;
esac
# the armored copy conf/bootstrap_apt named is the bootstrap's; the package's
# binary keyring, checked above, is what keel.sources names from here on
rm -f "$keyrings/keel-archive-keyring.asc"

# --- what a parent layer from before this change left

read -r state _ <<< "$(pkg_state turnkey-keys)"
Expand Down
26 changes: 26 additions & 0 deletions keys/keel-archive-keyring.asc
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----

mDMEard8WxYJKwYBBAHaRw8BAQdA9+WYo5j6Ox/HFXYnBMMNhW1mN1J7jr76XcMF
ZiuRNqa0NktlZWwgTGludXggQXJjaGl2ZSBTaWduaW5nIEtleSA8cmVsZWFzZUBr
ZWVsbGludXgub3JnPoiQBBMWCgA4FiEErQlkvj8J3tRpo7ayFI6VExRwMYAFAmq3
fFsCGwEFCwkIBwIGFQoJCAsCBBYCAwECHgECF4AACgkQFI6VExRwMYCktwD+M5dn
CbEKzw/gNTPjBv09saHYooTShTIsyhKKdPiQ+DQBAOSAx9HInw46e4p77ogKsLQe
qBvAYWNwS1Nt5hL3B38BuDMEard8XBYJKwYBBAHaRw8BAQdAImTSVj5gRL0b+Cvg
v+jVPLaI0cRZ+KkmcmQBxITyaeuIxAQoFgoAbBYhBK0JZL4/Cd7UaaO2shSOlRMU
cDGABQJquG/1Th0CU2VjcmV0IHRyYW5zbWl0dGVkIHRocm91Z2ggYSBjaGF0IGNo
YW5uZWwgb24gMjAyNi0wOS0yNDsgbmV2ZXIgdXNlZCB0byBzaWduLgAKCRAUjpUT
FHAxgBnNAQDp91Xj5iMNwOpplDZ9hYGwe1dx1TTrJLXWJckxl1IHdQD/Wwv/842B
PhRvW8FB/Uzqpw4u3Uc+ejtegJe+Uv11vQOI9QQYFgoAJhYhBK0JZL4/Cd7UaaO2
shSOlRMUcDGABQJqt3xcAhsCBQkDwmcAAIEJEBSOlRMUcDGAdiAEGRYKAB0WIQRp
TeXowXvx+bc+rivSdrYsK9FvTgUCard8XAAKCRDSdrYsK9FvTqj4AQCn9qJiwOYD
krjEAoA6h5mRjN7t6PDU/hyiJsEJqGSBdgD9G9AXerdrqcikhr+EV5/70xPep07J
rRmF4vZRCx7xOg0NBAEA8ml+sIVCs0VbyQp82U1dmZEOQJm7Au71/sy1kYMuKMYA
/2JKAsT6YKpSfSGYVu00Ax1ACFLmnJJW2dBriyEz6gQNuDMEarhv9RYJKwYBBAHa
Rw8BAQdAIVoj1q0l6icHQw/fM9Rr/yTqaCCCXpZSBcrop4McoEGI9QQYFgoAJhYh
BK0JZL4/Cd7UaaO2shSOlRMUcDGABQJquG/1AhsCBQkDwmcAAIEJEBSOlRMUcDGA
diAEGRYKAB0WIQQDBBAk9LLAwvQt3eoEkG6rd1EzEAUCarhv9QAKCRAEkG6rd1Ez
EDC3AP478Ip4Xq5xxW87WwxUlo4+QGPzThBHlQxYXNPddiPGEAEA6Yo8HO+5m0JQ
b1Xm5mDVWWaMUizKwwc4NX4GBxjKnATVUwD9G+Le8EF8TyXpsL4rZn2kp4TToKGi
5SdE8+BrPe0qNOQBANwjQV4bVpvtxdSNgjSmita5QX386vN4ffWTQ5A2vWAA
=erap
-----END PGP PUBLIC KEY BLOCK-----
16 changes: 12 additions & 4 deletions mk/turnkey.mk
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,9 @@ HOSTNAME ?= $(shell basename "$(shell pwd)")

# general TKL vars
CONF_VARS += HOSTNAME ROOT_PASS NONFREE BACKPORTS_NONFREE TKL_TESTING BACKPORTS
# the Keel archive track a build installs from and the image follows:
# stable (default) or testing (conf/bootstrap_apt, conf/turnkey.d/keel-apt)
CONF_VARS += KEEL_APT_TRACK
# set specific software versions
CONF_VARS += PHP_VERSION RUBY_VER NODE_VER
# Webmin/firewall related
Expand Down Expand Up @@ -39,13 +42,21 @@ define _bootstrap/post
mkdir -p $O/bootstrap/usr/local/share/ca-certificates/;
# temporarily allow cert to not exist
cp /usr/local/share/ca-certificates/squid_proxyCA.crt $O/bootstrap/usr/local/share/ca-certificates/ || true;
# the key of archive.keellinux.org, which bootstrap_apt's keel.sources
# names, so the plan can install Keel's packages (keys/, the public
# half published at the archive root; the package installs the same key)
mkdir -p $O/bootstrap/usr/share/keyrings;
cp $(COMMON_CONF_PATH)/../keys/keel-archive-keyring.asc $O/bootstrap/usr/share/keyrings/keel-archive-keyring.asc;
fab-chroot $O/bootstrap --script $(COMMON_CONF_PATH)/bootstrap_apt;
endef
bootstrap/post += $(_bootstrap/post)

# tag package management system with release package
# set /etc/turnkey_version
#
# fab's release meta package (turnkey-<app>-<version>) is no longer built:
# keel-core is the meta package of a Keel image (handbook decision 0047),
# and the compatibility file is written on its own.
#
# The apt User-Agent is no longer written here. It used to carry the appliance
# and its version to every archive the machine ever contacted; it is now a
# fixed header naming the distribution and nothing else, shipped by
Expand All @@ -54,12 +65,9 @@ bootstrap/post += $(_bootstrap/post)
define _root.patched/post

#
# tagging package management system with release package
# setting /etc/turnkey_version
#
@if [ -f ./changelog ]; then \
echo $(FAB_SHARE_PATH)/make-release-deb.py ./changelog $O/root.patched; \
$(FAB_SHARE_PATH)/make-release-deb.py ./changelog $O/root.patched; \
turnkey_version=$$($(FAB_SHARE_PATH)/turnkey-version.py --dist=$(CODENAME) --tag=$(VERSION_TAG) ./changelog $(FAB_ARCH)); \
echo $$turnkey_version > $O/root.patched/etc/turnkey_version; \
else \
Expand Down
7 changes: 3 additions & 4 deletions plans/turnkey/base
Original file line number Diff line number Diff line change
Expand Up @@ -35,9 +35,9 @@ dbus /* dbus installed by default since v18.x */
// in early boot (especially useful when live booting).
jitterentropy-rngd

tklbam /* depends on pypy2 for now */

hubdns
/* tklbam, hubdns and webmin-tklbam are not installed: backup is Keel Backup
(handbook decision 0040) and DNS registration is Keel Cloud, and neither
turnkey-pypy2 nor py3curl-wrapper, which only they pulled in, is wanted */
inithooks
turnkey-sysinfo
turnkey-version
Expand Down Expand Up @@ -70,7 +70,6 @@ webmin-custom
webmin-fdisk
webmin-raid
webmin-lvm
webmin-tklbam
webmin-updown
webmin-filemin
webmin-logviewer
Expand Down
92 changes: 90 additions & 2 deletions tests/apt-sources.bats
Original file line number Diff line number Diff line change
Expand Up @@ -72,11 +72,24 @@ render() {
local debian_backports_enabled=no
local debian_components=(main non-free-firmware)
local DEBIAN_KEYRING=/usr/share/keyrings/debian-archive-keyring.pgp
local KEEL_KEYRING=/usr/share/keyrings/keel-archive-keyring.asc
local keel_testing_enabled="${KEEL_TESTING_ENABLED:-no}"
eval "cat <<EOF
$body
EOF"
}

# what conf/bootstrap_apt decides from KEEL_APT_TRACK: the case block, run
# with the variable set as a build would set it, prints keel_testing_enabled
track_decision() {
local block
block="$(sed -n '/^case "\${KEEL_APT_TRACK:-stable}" in$/,/^esac$/p' "$BOOTSTRAP")"
[ -n "$block" ] || { echo "no KEEL_APT_TRACK case in $BOOTSTRAP" >&2; return 1; }
KEEL_APT_TRACK="$1" bash -c "fatal() { echo \"fatal: \$*\" >&2; exit 1; }
$block
echo \"\$keel_testing_enabled\""
}

# the names of the files conf/bootstrap_apt writes into sources.list.d,
# but Sury's PHP source, which it writes only for a recipe that sets
# PHP_VERSION. The \$ is sed's, not the shell's.
Expand Down Expand Up @@ -110,10 +123,35 @@ fetch_hosts() {

# ------------------------------------------------- what the image fetches

@test "the bootstrap writes debian, security and backports, and no TurnKey file" {
@test "the bootstrap writes debian, security, backports and keel, and no TurnKey file" {
run bootstrap_files
[ "$status" -eq 0 ]
[ "$output" = "$(printf 'debian.sources\nsecurity.sources\ndebian-backports.sources')" ]
[ "$output" = "$(printf 'debian.sources\nsecurity.sources\ndebian-backports.sources\nkeel.sources')" ]
}

@test "the bootstrap gives the plan the Keel archive, stable on and testing off by default" {
run render keel.sources
[ "$status" -eq 0 ]
[ "$(awk '/^URIs:/ { print $2 }' <<< "$output" | sort -u)" = https://archive.keellinux.org ]
[ "$(awk '/^Suites:/ { print $2 }' <<< "$output" | tr '\n' ' ')" = "trixie trixie-testing " ]
[ "$(awk '/^Enabled:/ { print $2 }' <<< "$output" | tr '\n' ' ')" = "yes no " ]
[ "$(awk '/^Signed-By:/ { print $2 }' <<< "$output" | sort -u)" = /usr/share/keyrings/keel-archive-keyring.asc ]
# the key that file names is the one mk/turnkey.mk copies in from keys/
grep -q 'keys/keel-archive-keyring.asc \$O/bootstrap/usr/share/keyrings/keel-archive-keyring.asc' "$REPO/mk/turnkey.mk"
gpg --batch --quiet --show-keys --with-colons "$REPO/keys/keel-archive-keyring.asc" \
| grep -q '^fpr:::::::::AD0964BE3F09DED469A3B6B2148E951314703180:'
grep -q '^CONF_VARS += KEEL_APT_TRACK$' "$REPO/mk/turnkey.mk"
}

@test "KEEL_APT_TRACK picks the track: stable or unset keeps testing off, testing turns it on, anything else stops the build" {
[ "$(track_decision "")" = no ]
[ "$(track_decision stable)" = no ]
[ "$(track_decision testing)" = yes ]
run track_decision nightly
[ "$status" -ne 0 ]
[[ "$output" == *"KEEL_APT_TRACK must be 'stable' or 'testing', got 'nightly'"* ]]
KEEL_TESTING_ENABLED=yes run render keel.sources
[ "$(awk '/^Enabled:/ { print $2 }' <<< "$output" | tr '\n' ' ')" = "yes yes " ]
}

# the \$ in the patterns are grep's, not the shell's
Expand Down Expand Up @@ -192,6 +230,17 @@ fetch_hosts() {
run ! grep -qE '^turnkey-keys' "$REPO/plans/turnkey/base"
}

@test "the base plan installs none of TurnKey's backup and DNS services, and no release meta package is built" {
local name
for name in tklbam hubdns webmin-tklbam turnkey-pypy2 py3curl-wrapper; do
run ! grep -qE "^$name([[:space:]]|\$)" "$REPO/plans/turnkey/base"
done
run ! grep -q 'make-release-deb' "$REPO/mk/turnkey.mk"
# the compatibility file is still written (decision 0014)
grep -q 'turnkey_version=.*turnkey-version.py' "$REPO/mk/turnkey.mk"
grep -q '> \$O/root.patched/etc/turnkey_version' "$REPO/mk/turnkey.mk"
}

# ------------------------------------------------ the security-only upgrade

@test "security.sources alone, as the upgrade reads it, is Debian security only" {
Expand Down Expand Up @@ -365,6 +414,45 @@ run_conf() {
[ ! -e "$BATS_TEST_TMPDIR/dpkg.calls" ]
}

@test "the conf script leaves the stable track alone by default and drops the bootstrap's key copy" {
conf_tree
echo "armored copy" > "$APTROOT/usr/share/keyrings/keel-archive-keyring.asc"
local before
before="$(cat "$SOURCES/keel.sources")"
run_conf
[ "$status" -eq 0 ]
[ "$(cat "$SOURCES/keel.sources")" = "$before" ]
[ "$(sed -n '/^Suites: trixie-testing$/,/^$/p' "$SOURCES/keel.sources" | awk '/^Enabled:/ { print $2 }')" = no ]
[ ! -e "$APTROOT/usr/share/keyrings/keel-archive-keyring.asc" ]
[ -f "$APTROOT/usr/share/keyrings/keel-archive-keyring.gpg" ]
}

@test "KEEL_APT_TRACK=testing makes the image follow the testing track, and changes nothing else" {
conf_tree
local before
before="$(grep -v '^Enabled:' "$SOURCES/keel.sources")"
KEEL_APT_TRACK=testing run_conf
[ "$status" -eq 0 ]
[ "$(grep -v '^Enabled:' "$SOURCES/keel.sources")" = "$before" ]
[ "$(sed -n '/^Suites: trixie$/,/^$/p' "$SOURCES/keel.sources" | awk '/^Enabled:/ { print $2 }')" = yes ]
[ "$(sed -n '/^Suites: trixie-testing$/,/^$/p' "$SOURCES/keel.sources" | awk '/^Enabled:/ { print $2 }')" = yes ]
run fetch_uris
grep -q '^https://archive\.keellinux\.org/dists/trixie-testing/main/' <<< "$output"
grep -q '^https://archive\.keellinux\.org/dists/trixie/main/' <<< "$output"
}

@test "the conf script refuses an unknown KEEL_APT_TRACK, and testing without a stanza to enable" {
conf_tree
KEEL_APT_TRACK=nightly run_conf
[ "$status" -eq 1 ]
[[ "$output" == *"KEEL_APT_TRACK must be 'stable' or 'testing', got 'nightly'"* ]]
conf_tree
sed -i '/^Suites: trixie-testing$/,/^$/d' "$SOURCES/keel.sources"
KEEL_APT_TRACK=testing run_conf
[ "$status" -eq 1 ]
[[ "$output" == *"no trixie-testing stanza to enable"* ]]
}

@test "the conf script refuses an image without the Keel keyring" {
conf_tree
rm "$APTROOT/usr/share/keyrings/keel-archive-keyring.gpg"
Expand Down
Loading