Skip to content

fix(installer): verify release files without --ignore-missing - #16

Merged
sunyalou merged 1 commit into
mainfrom
fix/oac-16-install-sha256-portable
Oct 3, 2026
Merged

sunyalou merged 1 commit into
mainfrom
fix/oac-16-install-sha256-portable

Conversation

@sunyalou

@sunyalou sunyalou commented Oct 3, 2026

Copy link
Copy Markdown
Owner

目标

修复 deploy/install.sh 在 CentOS 7.6(coreutils 8.22)上无法一键安装的问题:sha256sum --check --ignore-missing 的 --ignore-missing 需要 coreutils ≥ 8.25,实跑直接 sha256sum: unrecognized option '--ignore-missing' 并 exit 1。

改动

  • deploy/install.sh:移除 sha256sum --check --ignore-missing --quiet,改为逐文件比对。新增 verify_sha256:从 compose-sha256sums.txt 取出该文件的期望摘要(兼容文本/二进制 * 前缀与 CRLF),与 sha256sum <file> 计算值比较;摘要条目缺失或非法、或摘要不匹配都返回非零并输出明确错误。
    • 校验强度不降:compose.yaml、ports.yaml 仍逐一对照 compose-sha256sums.txt,且现在要求两者都必须在清单中有合法条目。
    • 只使用 coreutils 8.22 / bash 4.2 已有的 sha256sum <file>、awk、[[ =~ ]],不再传任何 sha256sum 选项。
  • deploy/test_install.py:测试桩的 sha256sum 模拟 8.22 行为(收到 --* 选项即报错退出),并让 curl 桩写出真实格式的校验清单;新增 3 个用例:摘要不匹配必须失败、清单缺少条目必须失败、清单中未下载文件的条目可忽略(等价于原 --ignore-missing 的容忍度)。

验证

命令与结果(worktree oac-install-coreutils,base origin/main @ 5423a68d):

  • bash -n deploy/install.sh → 通过
  • PYTHONDONTWRITEBYTECODE=1 python3 deploy/test_install.py → Ran 11 tests ... OK
  • 回归验证:临时把 --ignore-missing 加回 sha256sum 调用 → 同一测试集 FAILED (failures=9),证明测试桩能捕获该可移植性问题;随后还原
  • 真实 sha256sum(非桩)逐文件比对,覆盖文本/二进制 * 前缀、CRLF、摘要不匹配、清单缺条目四种情形 → 全部符合预期
  • make check-names → OpenAgentCore name guard passed.
  • python3 scripts/ci_plan.py plan --base origin/main --head HEAD → hygiene + distribution(符合预期)

make check-distribution 中与本改动无关的项在本机存在既存环境失败(base 同样失败,非本 PR 引入):deploy/node 的 test_node_proxy 依赖 openssl 生成证书失败;scripts/core-distribution-manifest.test.py 依赖缺失的 pigz。其余 Python 检查(deploy/compose、scripts/acceptance、scripts/publish-core-release.test.py)、node --test scripts/build-native-catalog.test.mjs、bash -n 全部通过。

已知限制

  • 未在真实 CentOS 7.6/coreutils 8.22 主机上执行完整安装(需要 Docker 与发布产物);可移植性通过“不向 sha256sum 传选项 + 模拟 8.22 选项拒绝”覆盖。
  • make check-distribution 的 go test ./services/web 与 ./scripts/build-web.sh 未在本机运行(缺少 node_modules/网络);改动不涉及这两者。

约束

  • 未修改生成物、迁移;未改 main;仅 fork 分支 + PR。
  • 无密钥、令牌或测试库连接串进入源码/日志/PR。

CentOS 7 ships coreutils 8.22, where sha256sum rejects --ignore-missing
(added in 8.25), so a real install failed before verifying anything.
Compare each downloaded Compose file against its listed digest directly;
a missing entry or a mismatch still fails the install.

Co-authored-by: multica-agent <github@multica.ai>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@sunyalou
sunyalou merged commit ee22bfa into main Oct 3, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant