Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 4 additions & 3 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -29,9 +29,10 @@ include $(FAB_PATH)/common/mk/turnkey.mk
# is installed as a keyring, the source entry names it through signed-by,
# nothing in the tree says trusted=yes, and apt runs with --error-on=any, so a
# signature that cannot be checked fails the build instead of warning about it
# and carrying on. conf.d/main removes the copy of the archive, the source
# entry and the keyring from the image and leaves the future apt.keellinux.org
# entry in place, disabled.
# and carrying on. conf.d/main pins the archive for the build only and
# removes the copy of the archive, the source entry, the pin and the keyring
# from the image. The appliance's own Keel source and pin are common's
# (overlays/turnkey.d/keel-apt).
#
# None of the three build time files is for an installed appliance, because
# the staging key signs whatever the build host produced. The removelist at
Expand Down
16 changes: 16 additions & 0 deletions changelog
Original file line number Diff line number Diff line change
@@ -1,3 +1,19 @@
turnkey-postgresql-19.0 (5) turnkey; urgency=low

* The overlay no longer ships /etc/apt/sources.list.d/keel.sources
(apt.keellinux.org, disabled) or /etc/apt/preferences.d/keel (the Keel
origin at 1001). At 1001 apt downgraded every package newer than the
archive's (tracker#23), and both files, at the paths common uses, would
override the source and the 990 pin Keel-Linux/common#30 ships. The
build time archive still wins over TurnKey's 999 pin during the build:
conf.d/main pins it by its Label, l=Keel Linux staging, at 1001 before
the upgrade and removes that pin with the build time source. The build
then fails if any apt source or pin of the image still names the build
time archive, in place of the check that keel.sources was disabled.
tests/apt-files.bats checks the recipe.

-- Marcos Mendez <mendez.foto@gmail.com> Fri, 02 Oct 2026 17:00:00 +0000

turnkey-postgresql-19.0 (4) turnkey; urgency=low

* bin/keel-archive-check refuses a trusted=yes on the project archive rather
Expand Down
29 changes: 22 additions & 7 deletions conf.d/main
Original file line number Diff line number Diff line change
Expand Up @@ -86,6 +86,15 @@ dpkg-query -W -f '${Status}' webmin-postgresql | grep -qx 'install ok installed'
# to do with it. The conf script runs with stdin closed, dpkg reads end of
# file at the prompt and leaves confconsole "install ok unpacked", which
# fails this script. Keep the overlay's file without asking.
#
# The build time archive has to win over every other source here: a
# bootstrap from before Keel-Linux/common#30 pins TurnKey's archive at 999.
# It used to win through the overlay's /etc/apt/preferences.d/keel at 1001,
# which then shipped in the image and downgraded every package newer than the
# archive's (tracker#23). This pin names the staging distribution by its
# Label, exists only during the build and goes with the build time source.
printf 'Package: *\nPin: release l=Keel Linux staging\nPin-Priority: 1001\n' \
> /etc/apt/preferences.d/keel-staging
export DEBIAN_FRONTEND=noninteractive
apt-get install -y --only-upgrade \
-o Dpkg::Options::=--force-confdef \
Expand Down Expand Up @@ -114,14 +123,20 @@ EOF
dpkg-query -W -f '${Package} ${Version} ${Status}\n' inithooks confconsole keel

# The build time package source is not for appliances: remove the source
# entry, the copy of the archive it names and the keyring the build verified
# that archive with, and keep the documented, disabled entry for the future
# signed repository (overlay). The staging key signs whatever the build host
# produced, so an image that kept it would carry trust in a nightly
# (tracker#7). common/removelists-final/turnkey removes the same three paths
# at the end of the build, whatever a recipe does.
# entry, its build time pin, the copy of the archive it names and the keyring
# the build verified that archive with. The staging key signs whatever the
# build host produced, so an image that kept it would carry trust in a
# nightly (tracker#7). common/removelists-final/turnkey removes the same
# paths at the end of the build, whatever a recipe does. The appliance's own
# Keel source and its 990 pin are common's (overlays/turnkey.d/keel-apt), so
# nothing the image keeps may still name the build time archive.
rm -f /etc/apt/sources.list.d/keel-staging.list
rm -f /etc/apt/preferences.d/keel-staging
rm -f /etc/apt/keyrings/keel-staging-keyring.asc
rm -rf /srv/keel-apt
rm -rf /var/lib/apt/lists/*
grep -q '^Enabled: no' /etc/apt/sources.list.d/keel.sources
if grep -rlsE 'trixie-staging|/srv/keel-apt|l=Keel Linux staging' /etc/apt/sources.list \
/etc/apt/sources.list.d /etc/apt/preferences /etc/apt/preferences.d; then
echo "the apt files above still name the build time archive" >&2
exit 1
fi
5 changes: 0 additions & 5 deletions overlay/etc/apt/preferences.d/keel

This file was deleted.

17 changes: 0 additions & 17 deletions overlay/etc/apt/sources.list.d/keel.sources

This file was deleted.

58 changes: 58 additions & 0 deletions tests/apt-files.bats
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
#!/usr/bin/env bats
# The apt files this recipe leaves in the image (Keel-Linux/common#30,
# tracker#23). Common ships the appliance's Keel source and its pin at 990
# (overlays/turnkey.d/keel-apt); a recipe overlay at the same paths would win
# over them, so this recipe ships neither. The build time archive still has
# to win over TurnKey's 999 pin while the recipe upgrades the project
# packages, so conf.d/main pins it by its Label for the build only.
#
# conf.d/main runs inside a chroot during the build; what it leaves is proved
# on the booted machine by the boot test. These check the recipe itself.

bats_require_minimum_version 1.5.0

setup() {
REPO="$(cd "$BATS_TEST_DIRNAME/.." && pwd)"
MAIN="$REPO/conf.d/main"
}

# line LITERAL: the line number of the first line of conf.d/main equal to it
line() {
grep -nxF -- "$1" "$MAIN" | head -n 1 | cut -d: -f1
}

@test "the overlay ships no Keel source and no Keel pin" {
[ ! -e "$REPO/overlay/etc/apt/sources.list.d/keel.sources" ]
[ ! -e "$REPO/overlay/etc/apt/preferences.d/keel" ]
run ! grep -rlsE 'Pin-Priority: *1001' "$REPO/overlay"
}

@test "the build time pin names the staging Label, and is written before the upgrade" {
local pin upgrade
pin="$(line "printf 'Package: *\nPin: release l=Keel Linux staging\nPin-Priority: 1001\n' \\")"
# the backslash is the script's line continuation, matched literally
# shellcheck disable=SC1003
upgrade="$(line 'apt-get install -y --only-upgrade \')"
[ -n "$pin" ]
[ -n "$upgrade" ]
[ "$pin" -lt "$upgrade" ]
grep -qxF ' > /etc/apt/preferences.d/keel-staging' "$MAIN"
}

@test "the build time pin goes with the build time source" {
local list pin
list="$(line 'rm -f /etc/apt/sources.list.d/keel-staging.list')"
pin="$(line 'rm -f /etc/apt/preferences.d/keel-staging')"
[ -n "$list" ]
[ -n "$pin" ]
[ "$pin" -eq $((list + 1)) ]
}

@test "the build fails when an apt file still names the build time archive" {
grep -qF "grep -rlsE 'trixie-staging|/srv/keel-apt|l=Keel Linux staging'" "$MAIN"
run ! grep -q "Enabled: no' /etc/apt/sources.list.d/keel.sources" "$MAIN"
}

@test "conf.d/main parses" {
bash -n "$MAIN"
}
Loading