mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-04 06:15:09 +00:00
* docs: add ARCHITECTURE and PERMISSIONS guides ARCHITECTURE.md maps the processes, the state the display and web services share through the cache, the display loop, the plugin system, the web UI and the update path, with links into the code and a where-to-start table. PERMISSIONS.md lists who owns what after install, both sudoers files (and why iptables is not granted), the polkit rule, and which scripts/fix_perms script to run as which user. Both are linked from the docs index, along with the MQTT bridge README and src/common/README.md. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs: correct stale setup, service and troubleshooting claims - README: quick actions run systemctl on ledmatrix.service (run.py), not display_controller.py; use_short_date_format has no effect; the installer uses system pip with --break-system-packages, not a venv. - CONFIG_DEBUGGING: LEDMATRIX_DEBUG must be "true"; logs are in journald. - GETTING_STARTED, WEB_INTERFACE_GUIDE, TROUBLESHOOTING: enabling a plugin, plugin settings, brightness and Vegas settings apply without a restart; matrix hardware settings still need one. - TROUBLESHOOTING: install dependencies with sudo so the root service sees them; point permission problems at PERMISSIONS.md instead of a project-wide chown. - ADVANCED_FEATURES: real BackgroundDataService stats keys; Vegas hooks return VegasDisplayMode and None falls back to capture; cache files are 0660; fix_web_permissions.sh runs as the web user and does not touch sudoers. - STARLARK_APPS_GUIDE: only the linux-arm64 pixlet binary is downloaded. - HOW_TO_RUN_TESTS: test class examples that exist. - CLAUDE.md: PluginStoreManager, plugin_dirs.py, monorepo installs via the Trees API with ZIP fallback, requirements.txt is optional. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs: mark deprecated plugin APIs and state manifest fields once Methods @deprecated("3.7.0") (the set pinned in test_deprecation.py) were shown as current API in the quick reference, API reference, advanced guide, development guide and FONT_MANAGER. Each is now marked deprecated with its replacement. FONT_MANAGER is rewritten around the current API; the override editor is gone and override methods are deprecated. Required manifest fields were stated three different ways. The API reference now has one section: the 7 schema-required fields, the 4 the store refuses without, class_name for the loader, and the 8 to set. The other guides link to it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs: document every src/common module and every widget - src/common/README.md covered 7 of 17 modules. It now has a table of all of them (purpose, whether plugins import it, release to floor on), a short entry each, and logging advice that matches the code. - SPORTS_UNIFICATION listed two shared modules and called sports_helpers the first; it now lists all six. - The widgets README lists all 28 registered widgets plus the support files, and absorbs the parts that only docs/widget-guide.md had (x-options.labels, x-advanced, x-display hidden, plugin-file-manager). docs/widget-guide.md is now a pointer to it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(security): fix_web_permissions.sh re-hardens the root sudo helpers The script chowns the whole project to the web user. That included scripts/fix_perms/safe_plugin_rm.sh and safe_pip_install.sh -- the two helpers /etc/sudoers.d/ledmatrix_web lets the web user run as root -- so running it turned both into a root shell for whoever can edit them. It also re-grouped config_secrets.json away from ledmatrix. After the chown it now does what first_time_install.sh's Steps 11 and 11.1 do: helpers back to root:root 755, and config_secrets.json back to the web unit's User=:ledmatrix 640. Each step is non-fatal and prints the manual command if it fails. Also fixes what the script and its docs claimed: it never configured sudoers, its closing hint pointed at ./configure_web_sudo.sh (wrong path), and the README and ADVANCED_FEATURES.md said to run it with sudo, which it refuses. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(security): validate and harden every sudoers drop-in the scripts write configure_wifi_permissions.sh copied its rules into /etc/sudoers.d/ledmatrix_wifi without `visudo -c`. A malformed drop-in makes sudo refuse every command for every user, which on a headless Pi leaves no way back in. It now checks first and leaves the installed file alone when the rules do not parse, as the other two writers do. (It already used mktemp, so that part of the review did not apply.) It also grants the two literal commands wifi_manager.py runs for NetworkManager's shared-mode dnsmasq drop-in -- `cp /tmp/ledmatrix-nm-dnsmasq.conf .../dnsmasq-shared.d/ledmatrix-captive.conf` and `rm -f` of that file. The directory's mkdir was granted, the file was not. Both are pinned in test_sudo_allowlist_covers_calls.py. configure_web_sudo.sh wrote its rules to /tmp/ledmatrix_web_sudoers_$$, a predictable name in a world-writable directory; it now uses mktemp with an EXIT trap, as first_time_install.sh does. It sets mode 440 on the installed file instead of leaving the temp file's mode, and finds visudo in /usr/sbin when that is not on the user's PATH, which skipped the check silently. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(install): escape the project path in the DNS-fix and MQTT unit renderers install_dns_fix.sh and install_mqtt_bridge.sh substituted __PROJECT_ROOT_DIR__ with the raw path, while the other three renderers go through sed_escape_replacement from lib_systemd_render.sh. A checkout under a path containing `&`, `\` or `|` rendered a corrupted unit from these two only. Both now source the helper and use it, and a test checks that every placeholder substitution in scripts/install uses an escaped value. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(install): stop the installer scripts reporting things that are not true - first_time_install.sh printed "Password: ledmatrix123" for the setup access point. wifi_manager creates it as an open network ("No password" on the panel), so it now says so. - Step 10.1 printed "✓ WiFi management permissions configured" straight after its own failure message; install_wifi_monitor.sh printed "✓ Package installation completed" after a failed apt install. The tick now only follows success. - Step 7 printed "Web dependencies already installed ... in Step 5" in the one branch that runs because Step 5 did not install them, then created .web_deps_installed on that basis. It now warns and leaves the marker off so the next run retries, as the comment below it intends. - check_system_compatibility.sh called Debian 12 Bookworm "full compatibility confirmed" while first_time_install.sh refuses anything but Debian 13. Bookworm, older Debian and non-Debian systems are now errors. Its counters used ((X++)), which under `set -e` exits the script at the first warning or error (the expression is 0), so the check never reached its summary on any system with one. - configure_web_sudo.sh and configure_wifi_permissions.sh finished by testing `sudo -n test -f ...` and `sudo -n nmcli device status`, neither of which is granted, so they always reported a failure. They now ask `sudo -n -l` about commands the new rules do grant, which checks the rule without running anything. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(install): print the completion summary before rebooting With -y -- and so for every one-shot `curl | bash` install, which always passes -y -- first_time_install.sh ran `reboot` about 180 lines before its "Installation Complete / Web UI Access" summary. reboot returns at once, so the summary printed while the Pi was going down and the SSH session usually dropped before the web UI address could be read. The reboot block moves, unchanged, to the very end of the script. The interactive prompt now also follows the summary. Because the summary now runs before the -y reboot, its one command that could fail under `set -Eeuo pipefail` (the SSID lookup, when nmcli reports a connected device but no active network line) gets `|| true`; a missing SSID was already handled as "SSID unknown". one-shot-install.sh prints its "Next steps" after the installer returns, by which time the reboot is under way, so it now says so, and README's Quick Install mentions the automatic reboot. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * chore(scripts): correct wrong comments and messages, drop dead code No behaviour change except the output text noted below. - 2775 is setgid, not the sticky bit (first_time_install.sh Step 3.1, fix_plugin_permissions.sh), and root needs no "PWM hardware access" to plugin files. - The 777 comments in first_time_install.sh Step 3's fallback and fix_assets_permissions.sh said root needs it to write. Root ignores mode bits; the comments now say what 777 actually opens. The 777 itself is unchanged. - apt_remove ends in `|| true`, so Step 12's "Some packages could not be removed" branch could never run; it is gone and the helper stays non-fatal. - detect_web_service_user's comment named Step 8 for the web unit (install_service.sh installs it in Step 7.5) and now says which branch actually runs. - Step 5 described an "already installed" check that does not exist; the ACTUAL_USER comment described the re-exec backwards. - on_error printed a literal "\n" before "Common fixes:". - Dead code: one-shot-install.sh's uncalled fix_tmp_permissions, LEDMATRIX_ELEVATED=1 (never read) on the sudo re-exec, and configure_web_sudo.sh's unused PYTHON_PATH, which also made a missing python3 fatal for rules that never mention it. - start_display.sh / stop_display.sh said "for user: <you>"; the service runs as root. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * refactor(fix_perms): fix_cache_permissions.sh uses setup_cache.sh's model There were two models for /var/cache/ledmatrix. setup_cache.sh (the installer's Step 2) and install_web_service.sh share it through the ledmatrix group: root:ledmatrix, 2775, files 660, which is also what DiskCache relies on to give files the directory's group. fix_cache_permissions.sh instead made it 777 and re-grouped it to the invoking user's group, undoing that. It now runs setup_cache.sh for /var/cache/ledmatrix and keeps its own handling of ~/.ledmatrix_cache. Dropped: /var/cache/ledmatrix/ placeholder_logos (nothing reads it) and the checks against the `daemon` user (no service runs as daemon). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * ci: pin actions/checkout in the Claude workflows, drop template comments claude.yml and claude-code-review.yml used actions/checkout@v4 while test.yml and release-version-check.yml pin the v4.2.2 commit SHA; they now pin the same SHA. The commented-out starter-template settings (prompt, claude_args, paths, author filter) are removed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(scripts): index every script and list removal candidates New scripts/README.md gives one line per top-level script and scripts directory, marked keep, dev-only or diagnostic, and lists the eight scripts nothing in the repo refers to as candidates for removal (kept for now). The install, utils and dev READMEs now list the files they were missing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test: tighten two checks that mutation testing showed were too loose - The wifi sudoers check matched `visudo -c -f "$TEMP_SUDOERS"` in the error report too, so replacing the check with `if false` still passed. It now requires the command as the condition. - The summary test never had the setup access point up, so reinstating the bogus "Password: ledmatrix123" line went unnoticed. A case with hostapd active now checks the AP is described as open. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(permissions): describe the repaired fix_perms scripts and new WiFi grants Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(changelog): docs-scripts Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
293 lines
13 KiB
Python
293 lines
13 KiB
Python
"""An installed unit that no longer matches the repo's must be reported.
|
|
|
|
Nothing re-applies systemd units after the first install. `git pull` -- what
|
|
the web UI's update button runs -- brings a new template into the checkout, but
|
|
no code in web_interface/ or src/ copies it to /etc/systemd/system or runs
|
|
`systemctl daemon-reload`. The unit that actually runs is whatever
|
|
first_time_install.sh wrote on day one.
|
|
|
|
So every hardening added to a unit is inert on existing installs. Measured on a
|
|
live rig: the installed unit was dated 2026-08-06 and the repo's 2026-08-19,
|
|
and they differed -- with the result that a MemoryMax=85% present in the repo's
|
|
template was not being enforced at all. `systemctl show` reported
|
|
MemoryMax=infinity.
|
|
|
|
This is a warning, not an error, and deliberately not a silent rewrite:
|
|
editing files under /etc and restarting services is the installer's job, not
|
|
something a display process should do to a machine while it boots.
|
|
"""
|
|
import logging
|
|
import re
|
|
import shlex
|
|
import subprocess
|
|
from pathlib import Path
|
|
from unittest.mock import MagicMock
|
|
|
|
import pytest
|
|
|
|
from src.startup_validator import StartupValidator
|
|
|
|
|
|
@pytest.fixture
|
|
def validator():
|
|
v = StartupValidator(config_manager=MagicMock())
|
|
v.logger = logging.getLogger("test")
|
|
v.warnings = []
|
|
v.errors = []
|
|
return v
|
|
|
|
|
|
def test_a_matching_unit_produces_no_warning(validator, tmp_path):
|
|
"""The installed unit, substituted exactly as the installer would."""
|
|
project_root = Path("src/startup_validator.py").resolve().parent.parent
|
|
template_rel = "systemd/ledmatrix.service"
|
|
template = project_root / template_rel
|
|
if not template.is_file():
|
|
pytest.skip("repo unit template not present")
|
|
|
|
installed = tmp_path / "ledmatrix.service"
|
|
installed.write_text(
|
|
template.read_text(encoding="utf-8")
|
|
.replace("__PROJECT_ROOT_DIR__", str(project_root))
|
|
.replace("__USER__", "root"),
|
|
encoding="utf-8")
|
|
|
|
validator._UNITS = ((template_rel, str(installed)),)
|
|
validator._validate_systemd_units()
|
|
assert not validator.warnings, f"a matching unit warned: {validator.warnings}"
|
|
assert not validator.errors
|
|
|
|
|
|
def test_comments_and_blank_lines_are_not_drift():
|
|
"""Otherwise every comment the repo adds would look like a changed unit."""
|
|
a = "[Service]\n# explains a setting\nExecStart=/x\nRestart=always\n"
|
|
b = "[Service]\nExecStart=/x\n\nRestart=always\n"
|
|
assert StartupValidator._unit_body(a) == StartupValidator._unit_body(b)
|
|
|
|
|
|
def test_a_changed_directive_is_drift():
|
|
a = "[Service]\nExecStart=/x\nMemoryMax=85%\n"
|
|
b = "[Service]\nExecStart=/x\n"
|
|
assert StartupValidator._unit_body(a) != StartupValidator._unit_body(b)
|
|
|
|
|
|
def test_reordered_directives_are_drift():
|
|
"""Order is not noise in a systemd unit.
|
|
|
|
Repeated directives -- ExecStartPre=, ExecStartPost= -- run in the order
|
|
they appear, and a directive that moves between [Unit], [Service] and
|
|
[Install] means something different, or nothing, where it lands. This
|
|
check used to sort the lines before comparing, which reported no drift for
|
|
a unit that had genuinely changed.
|
|
"""
|
|
a = "[Service]\nExecStartPre=/first\nExecStartPre=/second\n"
|
|
b = "[Service]\nExecStartPre=/second\nExecStartPre=/first\n"
|
|
assert StartupValidator._unit_body(a) != StartupValidator._unit_body(b), (
|
|
"swapping two ExecStartPre= lines changes what runs first, and was "
|
|
"being normalised away")
|
|
|
|
|
|
def test_a_directive_moved_between_sections_is_drift():
|
|
a = "[Unit]\nDescription=x\n[Service]\nExecStart=/x\n"
|
|
b = "[Unit]\nDescription=x\nExecStart=/x\n[Service]\n"
|
|
assert StartupValidator._unit_body(a) != StartupValidator._unit_body(b), (
|
|
"ExecStart= in [Unit] is not the same unit, and sorting hid it")
|
|
|
|
|
|
def test_cosmetic_differences_do_not_warn(validator, tmp_path):
|
|
"""Through the real comparison, not the helper.
|
|
|
|
The repo's template carries explanatory comments the installed copy may not
|
|
have, and the installer does not preserve ordering or blank lines. If those
|
|
counted as drift, every boot would warn and the warning would be ignored.
|
|
Asserting this on _unit_body alone would not catch a comparison that stopped
|
|
calling it -- which is exactly what a careless edit does.
|
|
"""
|
|
project_root = Path("src/startup_validator.py").resolve().parent.parent
|
|
template_rel = "systemd/ledmatrix.service"
|
|
template = project_root / template_rel
|
|
if not template.is_file():
|
|
pytest.skip("repo unit template not present")
|
|
|
|
substituted = (template.read_text(encoding="utf-8")
|
|
.replace("__PROJECT_ROOT_DIR__", str(project_root))
|
|
.replace("__USER__", "root"))
|
|
# Cosmetic means comments, blank lines and stray indentation -- the things
|
|
# the installer really does drop. Not reordering: that changes the unit,
|
|
# and is asserted as drift above.
|
|
directives = [line.strip() for line in substituted.splitlines()
|
|
if line.strip() and not line.strip().startswith("#")]
|
|
installed = tmp_path / "ledmatrix.service"
|
|
installed.write_text(
|
|
"\n\n".join(" " + d for d in directives) + "\n", encoding="utf-8")
|
|
|
|
validator._UNITS = ((template_rel, str(installed)),)
|
|
validator._validate_systemd_units()
|
|
assert not validator.warnings, (
|
|
f"cosmetic-only difference reported as drift: {validator.warnings}")
|
|
|
|
|
|
def test_drift_is_reported_as_a_warning(validator, tmp_path):
|
|
"""The whole point: a real difference must surface, and only as a warning."""
|
|
installed = tmp_path / "ledmatrix.service"
|
|
installed.write_text("[Service]\nExecStart=/usr/bin/python3 /x/run.py\n")
|
|
|
|
project_root = Path("src/startup_validator.py").resolve().parent.parent
|
|
template_rel = "systemd/ledmatrix.service"
|
|
template = project_root / template_rel
|
|
if not template.is_file():
|
|
pytest.skip("repo unit template not present")
|
|
|
|
validator._UNITS = ((template_rel, str(installed)),)
|
|
validator._validate_systemd_units()
|
|
|
|
assert validator.warnings, "a differing unit produced no warning"
|
|
assert "install_service.sh" in validator.warnings[0], (
|
|
"the warning does not tell the user how to fix it")
|
|
assert not validator.errors, "drift must not be fatal at startup"
|
|
|
|
|
|
def test_a_missing_installed_unit_is_silent(validator, tmp_path):
|
|
"""Development checkouts have no /etc/systemd unit; that is not drift."""
|
|
validator._UNITS = (("systemd/ledmatrix.service", str(tmp_path / "absent.service")),)
|
|
validator._validate_systemd_units()
|
|
assert not validator.warnings
|
|
assert not validator.errors
|
|
|
|
|
|
# --- the web unit: one template, three copies, and a warning that never cleared ---
|
|
#
|
|
# install_service.sh and install_web_service.sh each carried their own inline
|
|
# heredoc of ledmatrix-web.service. install_service.sh's had drifted -- no
|
|
# Wants=network-online.target, RestartSec, SyslogIdentifier or CacheDirectory --
|
|
# and that is what was installed on real rigs. The validator correctly reported
|
|
# the drift and told the user to re-run install_service.sh, which reinstalled the
|
|
# same stale copy, so the warning could never clear. Separately, the template
|
|
# hardcoded User=root while the installers write whoever ran them, so even the
|
|
# *correct* installer produced a permanent warning on any non-root install.
|
|
|
|
|
|
def _render(template_text, project_root, user):
|
|
"""Exactly what the installers' sed does."""
|
|
return (template_text
|
|
.replace("__PROJECT_ROOT_DIR__", str(project_root))
|
|
.replace("__USER__", user))
|
|
|
|
|
|
def test_the_web_unit_installed_as_a_non_root_user_is_not_drift(validator, tmp_path):
|
|
"""The web interface runs as whoever installed it, not as root.
|
|
|
|
This is the case that warned forever: nothing the user could do would make
|
|
an installed `User=pi` match a template that said `User=root`.
|
|
"""
|
|
project_root = Path("src/startup_validator.py").resolve().parent.parent
|
|
template_rel = "systemd/ledmatrix-web.service"
|
|
template = project_root / template_rel
|
|
if not template.is_file():
|
|
pytest.skip("repo unit template not present")
|
|
|
|
installed = tmp_path / "ledmatrix-web.service"
|
|
installed.write_text(
|
|
_render(template.read_text(encoding="utf-8"), project_root, "hdpi"),
|
|
encoding="utf-8")
|
|
|
|
validator._UNITS = ((template_rel, str(installed)),)
|
|
validator._validate_systemd_units()
|
|
assert not validator.warnings, (
|
|
f"a correctly installed non-root web unit warned: {validator.warnings}")
|
|
|
|
|
|
def test_the_web_unit_still_reports_a_real_changed_directive(validator, tmp_path):
|
|
"""Ignoring User= must not make the check blind to everything else."""
|
|
project_root = Path("src/startup_validator.py").resolve().parent.parent
|
|
template_rel = "systemd/ledmatrix-web.service"
|
|
template = project_root / template_rel
|
|
if not template.is_file():
|
|
pytest.skip("repo unit template not present")
|
|
|
|
rendered = _render(template.read_text(encoding="utf-8"), project_root, "hdpi")
|
|
# Drop RestartSec -- one of the directives the stale heredoc was missing.
|
|
stale = "\n".join(line for line in rendered.splitlines() if not line.startswith("RestartSec="))
|
|
installed = tmp_path / "ledmatrix-web.service"
|
|
installed.write_text(stale + "\n", encoding="utf-8")
|
|
|
|
validator._UNITS = ((template_rel, str(installed)),)
|
|
validator._validate_systemd_units()
|
|
assert validator.warnings, "a web unit missing RestartSec= produced no warning"
|
|
assert not validator.errors
|
|
|
|
|
|
def test_installed_user_falls_back_to_root():
|
|
"""systemd defaults a system unit with no User= to root, so we must too."""
|
|
assert StartupValidator._installed_user("[Service]\nExecStart=/x\n") == "root"
|
|
assert StartupValidator._installed_user("[Service]\nUser=pi\n") == "pi"
|
|
assert StartupValidator._installed_user("[Service]\n User=hdpi \n") == "hdpi"
|
|
|
|
|
|
def test_sed_escape_replacement_preserves_special_characters():
|
|
"""A project path or username containing sed-special characters must render literally.
|
|
|
|
The installers build their sed expression by interpolating a shell
|
|
variable into the replacement side of `sed s|pattern|replacement|`.
|
|
Unescaped, sed treats `&` as "insert the whole match" and `\\` as an
|
|
escape character, so a path like `/opt/led&matrix` would corrupt the
|
|
rendered unit instead of being substituted as-is. lib_systemd_render.sh's
|
|
sed_escape_replacement exists to prevent exactly that.
|
|
"""
|
|
project_root = Path("src/startup_validator.py").resolve().parent.parent
|
|
helper = project_root / "scripts" / "install" / "lib_systemd_render.sh"
|
|
if not helper.is_file():
|
|
pytest.skip("install helper not present")
|
|
|
|
value = "/opt/led&matrix\\pi|two"
|
|
escape_cmd = f'source {shlex.quote(str(helper))}; sed_escape_replacement {shlex.quote(value)}'
|
|
escaped = subprocess.run(
|
|
["bash", "-c", escape_cmd], capture_output=True, text=True, check=True
|
|
).stdout
|
|
|
|
rendered = subprocess.run(
|
|
["sed", f"s|__X__|{escaped}|g"],
|
|
input="path=__X__\n", capture_output=True, text=True, check=True,
|
|
).stdout
|
|
|
|
assert rendered == f"path={value}\n", (
|
|
"a sed-special character in the replacement was not preserved literally")
|
|
|
|
|
|
def test_every_unit_renderer_escapes_its_replacement():
|
|
"""Each `sed s|__PLACEHOLDER__|$VALUE|` in an install script uses an escaped value.
|
|
|
|
install_dns_fix.sh and install_mqtt_bridge.sh interpolated the raw project
|
|
path while the other three renderers went through sed_escape_replacement,
|
|
so a checkout under a path containing `&` rendered a broken unit from
|
|
those two only.
|
|
"""
|
|
project_root = Path("src/startup_validator.py").resolve().parent.parent
|
|
offenders = []
|
|
for script in sorted((project_root / "scripts" / "install").glob("*.sh")):
|
|
text = script.read_text(encoding="utf-8")
|
|
for m in re.finditer(r"s\|__[A-Z_]+__\|\$\{?([A-Za-z_][A-Za-z0-9_]*)\}?\|", text):
|
|
if not m.group(1).startswith("ESCAPED_") and m.group(1) != "root":
|
|
offenders.append(f"{script.name}: ${m.group(1)}")
|
|
assert not offenders, "unescaped sed replacement(s): " + ", ".join(offenders)
|
|
|
|
|
|
def test_no_installer_carries_its_own_copy_of_a_unit():
|
|
"""The regression guard.
|
|
|
|
Both installers used to inline the unit as a heredoc, and the two copies
|
|
drifted from the template and from each other. A unit body in a shell script
|
|
is the bug, so assert there isn't one rather than asserting the current
|
|
contents match -- matching contents is exactly what silently stops being
|
|
true.
|
|
"""
|
|
project_root = Path("src/startup_validator.py").resolve().parent.parent
|
|
offenders = []
|
|
for script in sorted((project_root / "scripts" / "install").glob("*.sh")):
|
|
text = script.read_text(encoding="utf-8", errors="replace")
|
|
if "[Unit]" in text and "Description=" in text:
|
|
offenders.append(script.name)
|
|
assert not offenders, (
|
|
f"{offenders} contain an inline systemd unit; render "
|
|
f"systemd/*.service instead so there is one source of truth")
|