Skip to content

fix: drop the overlay's Keel source and 1001 pin; 990 everywhere - #16

Open
marcos-mendez wants to merge 3 commits into
masterfrom
fix/drop-keel-apt-overlay
Open

marcos-mendez wants to merge 3 commits into
masterfrom
fix/drop-keel-apt-overlay

Conversation

@marcos-mendez

Copy link
Copy Markdown
Collaborator

Summary

Same change as the other six recipes, plus what is specific to this one, which ships its Keel source enabled.

  • Overlay files dropped. The overlay no longer ships /etc/apt/sources.list.d/keel.sources or /etc/apt/preferences.d/keel (Pin-Priority 1001). At 1001, apt downgrades every package newer than the archive's (tracker#23). COVERAGE.md had already measured keel-archive-keyring 0.1.1 going back to 0.1.0. At those paths, the overlay also wins over the source and the 990 pin that fix: images take packages from Debian and the Keel repository only common#30 ships.
  • conf.d/zzz-keel-archive now:
    • verifies common's source and pin and changes nothing;
    • writes the same two files on a bootstrap from before common#30 (stable enabled, trixie-testing disabled, pin 990);
    • refuses any pin priority but 990;
    • no longer runs sed 's/^Enabled: no$/Enabled: yes/' over the file, which on common's file would have enabled the testing track.
  • Build-only staging pin. conf.d/main writes /etc/apt/preferences.d/keel-staging (l=Keel Linux staging, 1001) before its upgrade, so the staging archive still wins over TurnKey's 999 pin during the build. conf.d/zz-project-packages removes it with the staging source, then fails if any apt file still names the build-time archive.
  • Boot test.
    • It expects the archive at 990.
    • It reads only the stable stanza of keel.sources.
    • bt_policy_verdict also passes when apt keeps an installed project package that is newer than the archive's and comes from no other source. This is the no-downgrade case: at 1001 the candidate was the archive's older version.

PR #15 conflict: a local test merge of fix/configtest-at-first-boot into this branch conflicts in COVERAGE.md only (the coverage table and the totals). changelog, conf.d/main, tests/boot-test.bats and tests/lib/boot-test-lib.sh merge cleanly.

Merge order: the seven recipes, then the pool, then common#30 together with inithooks#34.

Test plan

  • bats tests/: 239 tests pass. The new and changed tests were RED first.
    • keel-archive.bats: 17 tests
    • project-packages.bats: 16 tests
    • boot-test.bats: 79 tests (4 new: common's two-stanza file, newer installed kept, older refused, newer from another source refused)
    • apt-files.bats: 3 tests
  • tests/coverage.sh 97: zzz-keel-archive 100 (37/37), zz-project-packages 100 (35/35), boot-test-lib.sh 99.32 (292/294)
  • CI green
  • Boot gate on the next published layer (test-appliance)

navigator added 2 commits October 2, 2026 15:03
The overlay shipped /etc/apt/sources.list.d/keel.sources and
/etc/apt/preferences.d/keel at 1001. At 1001 apt downgrades every package
newer than the archive's (tracker#23), and at those paths both files
override the source and the 990 pin Keel-Linux/common#30 ships.

conf.d/zzz-keel-archive verifies common's two files and changes nothing,
or writes the same ones on a bootstrap from before common shipped them,
and refuses any pin but 990; it no longer turns every Enabled: no into
yes, which would enable the testing track. The build time archive is
pinned by its Label for the build only, removed by zz-project-packages,
which fails if any apt file still names it. The boot test expects 990,
reads the stable stanza only, and accepts a newer installed version apt
keeps instead of downgrading.
require-changelog wants a new top entry, not a bullet in the base branch's.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant