fix(installer): verify release files without --ignore-missing - #16
Merged
Merged
Conversation
CentOS 7 ships coreutils 8.22, where sha256sum rejects --ignore-missing (added in 8.25), so a real install failed before verifying anything. Compare each downloaded Compose file against its listed digest directly; a missing entry or a mismatch still fails the install. Co-authored-by: multica-agent <github@multica.ai>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
目标
修复
deploy/install.sh在 CentOS 7.6(coreutils 8.22)上无法一键安装的问题:sha256sum --check --ignore-missing的--ignore-missing需要 coreutils ≥ 8.25,实跑直接sha256sum: unrecognized option '--ignore-missing'并 exit 1。改动
deploy/install.sh:移除sha256sum --check --ignore-missing --quiet,改为逐文件比对。新增verify_sha256:从compose-sha256sums.txt取出该文件的期望摘要(兼容文本/二进制*前缀与 CRLF),与sha256sum <file>计算值比较;摘要条目缺失或非法、或摘要不匹配都返回非零并输出明确错误。compose.yaml、ports.yaml仍逐一对照compose-sha256sums.txt,且现在要求两者都必须在清单中有合法条目。sha256sum <file>、awk、[[ =~ ]],不再传任何 sha256sum 选项。deploy/test_install.py:测试桩的sha256sum模拟 8.22 行为(收到--*选项即报错退出),并让curl桩写出真实格式的校验清单;新增 3 个用例:摘要不匹配必须失败、清单缺少条目必须失败、清单中未下载文件的条目可忽略(等价于原--ignore-missing的容忍度)。验证
命令与结果(worktree
oac-install-coreutils,baseorigin/main@5423a68d):bash -n deploy/install.sh→ 通过PYTHONDONTWRITEBYTECODE=1 python3 deploy/test_install.py→Ran 11 tests ... OK--ignore-missing加回sha256sum调用 → 同一测试集FAILED (failures=9),证明测试桩能捕获该可移植性问题;随后还原sha256sum(非桩)逐文件比对,覆盖文本/二进制*前缀、CRLF、摘要不匹配、清单缺条目四种情形 → 全部符合预期make check-names→OpenAgentCore name guard passed.python3 scripts/ci_plan.py plan --base origin/main --head HEAD→hygiene+distribution(符合预期)make check-distribution中与本改动无关的项在本机存在既存环境失败(base 同样失败,非本 PR 引入):deploy/node的test_node_proxy依赖 openssl 生成证书失败;scripts/core-distribution-manifest.test.py依赖缺失的pigz。其余 Python 检查(deploy/compose、scripts/acceptance、scripts/publish-core-release.test.py)、node --test scripts/build-native-catalog.test.mjs、bash -n全部通过。已知限制
make check-distribution的go test ./services/web与./scripts/build-web.sh未在本机运行(缺少 node_modules/网络);改动不涉及这两者。约束