git mirror - github.com/owenewans/holy - branch master
clone: https://src.holypkg.eu/holy/

file tests/image-source.sh

#!/bin/sh
set -eu
bin=$(realpath "$1")
tmp=$(mktemp -d)
trap 'rm -rf "$tmp"' EXIT HUP INT TERM
mkdir -p "$tmp/repo" "$tmp/tree/HOLY" "$tmp/tree/DATA" \
    "$tmp/source-input" "$tmp/identity-root" "$tmp/image-root" \
    "$tmp/image/inputs" "$tmp/image/packages" "$tmp/image/work" "$tmp/fetched"
printf 'format holy-package-1\nname fixture\nversion 1\nrelease 1\nos linux\narch noarch\nlibc nolibc\n' > "$tmp/tree/HOLY/meta"
for member in files deps provides hooks origin transform; do
    : > "$tmp/tree/HOLY/$member"
done
printf 'require helper-1 fixture package helper any any any - helper metadata\n' > "$tmp/tree/HOLY/deps"
tar -cf "$tmp/fixture.tar" -C "$tmp/tree" HOLY DATA
lz4 -q "$tmp/fixture.tar" "$tmp/repo/fixture.holy"
sed 's/name fixture/name helper/' "$tmp/tree/HOLY/meta" > "$tmp/tree/HOLY/helper-meta"
mv "$tmp/tree/HOLY/helper-meta" "$tmp/tree/HOLY/meta"
: > "$tmp/tree/HOLY/deps"
tar -cf "$tmp/helper.tar" -C "$tmp/tree" HOLY DATA
lz4 -q "$tmp/helper.tar" "$tmp/repo/helper.holy"
sed -e 's/name helper/name busybox/' -e 's/arch noarch/arch x86/' \
    "$tmp/tree/HOLY/meta" > "$tmp/tree/HOLY/busybox-meta"
mv "$tmp/tree/HOLY/busybox-meta" "$tmp/tree/HOLY/meta"
tar -cf "$tmp/busybox.tar" -C "$tmp/tree" HOLY DATA
lz4 -q "$tmp/busybox.tar" "$tmp/repo/busybox.holy"
"$bin" repo index "$tmp/repo" > "$tmp/result"
"$bin" repo seal "$tmp/repo" > "$tmp/result"
index=$(sed -n 's/^sha256 //p' "$tmp/repo/current")
test "${#index}" -eq 64
printf '[source fixture]\ntype holy-http\nurl "https://fixture.example/holy/"\n' > "$tmp/source-input/sources.conf"
printf 'fixture\n' > "$tmp/source-input/aliases"
printf '%s\n' "$index" > "$tmp/source-input/fixture.index"
printf '%s\n' "$tmp/repo" > "$tmp/source-input/fixture.mirror"
printf 'yes\n' > "$tmp/source-input/fixture.embed"
mkdir "$tmp/limine" "$tmp/config-parts"
for input in kernel static-holypkg static-holyinstall static-cc busybox dinit mdevd; do
    : > "$tmp/$input"
done
cat > "$tmp/config-parts/image.conf" <<EOF
[image]
arch x86_64
output "../output"
kernel-image "../kernel"
kernel-version fixture
limine-dir "../limine"
static-holypkg "../static-holypkg"
static-holyinstall "../static-holyinstall"
static-cc "../static-cc"
profile static-core
root-storage ram
boot-test build-only
EOF
cat > "$tmp/image.conf" <<EOF
include "config-parts/image.conf"

[packages]
busybox "$tmp/busybox"
dinit "$tmp/dinit"
mdevd "$tmp/mdevd"
add fixture:fixture

[source fixture]
type holy-http
url "https://fixture.example/holy/"
index-sha256 "$index"
mirror "$tmp/repo"
embed-mirror yes

[docs]
include installed-man-pages
output "/usr/share/holy/llm.txt"
EOF
./holygetiso --check "$tmp/image.conf" > "$tmp/result"
grep -qx "source fixture index $index" "$tmp/result"
grep -qx 'add fixture:fixture' "$tmp/result"
config_hash=$(sed -n 's/^config-sha256 //p' "$tmp/result")
sed "s@busybox \"$tmp/busybox\"@busybox fixture:busybox@" "$tmp/image.conf" > "$tmp/core-image.conf"
./holygetiso --check "$tmp/core-image.conf" > "$tmp/result"
grep -qx 'core busybox fixture:busybox' "$tmp/result"
grep -Fxq "output $tmp/config-parts/../output" "$tmp/result"
sed 's@kernel-image "../kernel"@kernel-package fixture:busybox@' \
    "$tmp/config-parts/image.conf" > "$tmp/config-parts/kernel-image.conf"
sed 's@config-parts/image.conf@config-parts/kernel-image.conf@' \
    "$tmp/image.conf" > "$tmp/kernel-image.conf"
./holygetiso --check "$tmp/kernel-image.conf" > "$tmp/result"
grep -qx 'kernel-package fixture:busybox' "$tmp/result"
printf 'kernel-image "../kernel"\n' >> "$tmp/config-parts/kernel-image.conf"
if ./holygetiso --check "$tmp/kernel-image.conf" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi
grep -q 'choose exactly one kernel-image or kernel-package' "$tmp/error"
sed 's/boot-test build-only/boot-test required/' "$tmp/config-parts/image.conf" \
    > "$tmp/config-parts/changed.conf"
mv "$tmp/config-parts/changed.conf" "$tmp/config-parts/image.conf"
./holygetiso --check "$tmp/image.conf" > "$tmp/result"
changed_hash=$(sed -n 's/^config-sha256 //p' "$tmp/result")
test "$config_hash" != "$changed_hash"
sed 's/boot-test required/boot-test build-only/' "$tmp/config-parts/image.conf" \
    > "$tmp/config-parts/restored.conf"
mv "$tmp/config-parts/restored.conf" "$tmp/config-parts/image.conf"
printf 'format holy-answers-1\n' > "$tmp/image-answers"
answer_hash=$(sha256sum "$tmp/image-answers")
cp "$tmp/image.conf" "$tmp/answer-image.conf"
printf '\n[resolver]\nanswers "%s"\nanswers-sha256 %s\n' \
    "$tmp/image-answers" "${answer_hash%% *}" >> "$tmp/answer-image.conf"
./holygetiso --check "$tmp/answer-image.conf" > "$tmp/result"
printf '#changed\n' >> "$tmp/image-answers"
if ./holygetiso --check "$tmp/answer-image.conf" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi
grep -q 'matching SHA-256 pin' "$tmp/error"
printf 'include "config-parts/cycle.conf"\n' > "$tmp/cycle.conf"
printf 'include "../cycle.conf"\n' > "$tmp/config-parts/cycle.conf"
if ./holygetiso --check "$tmp/cycle.conf" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi
grep -q 'include cycle' "$tmp/error"
"$bin" db init --root "$tmp/identity-root" > "$tmp/result"
"$bin" source plan --config "$tmp/source-input/sources.conf" --root "$tmp/identity-root" > "$tmp/identity.plan"
identity_plan=$(sha256sum "$tmp/identity.plan")
identity_plan=${identity_plan%% *}
"$bin" source apply "$tmp/identity.plan" --sha256 "$identity_plan" --root "$tmp/identity-root" > "$tmp/result"
"$bin" source list --root "$tmp/identity-root" > "$tmp/result"
source_id=$(awk '$1 == "source" && $3 == "\"fixture\"" && $4 == "active" {print $2}' "$tmp/result")
test "${#source_id}" -eq 64
printf 'format holy-mirror-1\nurl "https://fixture.example/holy/"\nindex-sha256 %s\nverification digest-pinned-unsigned\nsource-id %s\n' \
    "$index" "$source_id" > "$tmp/repo/mirror-origin"
"$bin" db init --root "$tmp/image-root" > "$tmp/result"
: > "$tmp/image/build.record"
sh tools/image-source-stage.sh "$bin" "$tmp/image-root" "$tmp/image" "$tmp/source-input"
grep -qx "source fixture $source_id index $index" "$tmp/image/build.record"
sh tools/image-package-stage.sh "$bin" "$tmp/image" x86_64 \
    --source fixture fixture --source fixture fixture
test "$(wc -w < "$tmp/image/work/additional-packages")" -eq 2
test "$(wc -l < "$tmp/image/work/add-sources")" -eq 2
grep -q " $source_id$" "$tmp/image/work/add-sources"
"$bin" info "local:$tmp/image/inputs/add-0001.holy" > "$tmp/first-info"
"$bin" info "local:$tmp/image/inputs/add-0002.holy" > "$tmp/second-info"
sed -n 's/^name //p' "$tmp/first-info" "$tmp/second-info" | sort > "$tmp/names"
printf 'fixture\nhelper\n' > "$tmp/expected-names"
cmp "$tmp/names" "$tmp/expected-names"
printf '[install]\nroot "%s"\n' "$tmp/image-root" > "$tmp/image-install.conf"
for label in add-0001 add-0002; do
    artifact="$tmp/image/packages/$label.holy"
    digest=$(sha256sum "$artifact")
    digest=${digest%% *}
    "$bin" cache stage "local:$artifact" --root "$tmp/image-root" > "$tmp/result"
    printf 'artifact %s\nsource %s %s\n' "$digest" "$digest" "$source_id" \
        >> "$tmp/image-install.conf"
done
./holyinstall --config "$tmp/image-install.conf" --plan "$tmp/image-install.plan" \
    --holypkg "$bin" > "$tmp/result"
./holyinstall --apply "$tmp/image-install.plan" --holypkg "$bin" > "$tmp/result"
"$bin" db check --all --root "$tmp/image-root" > "$tmp/result"
mkdir -p "$tmp/core-root" "$tmp/core-image/inputs" "$tmp/core-image/packages" "$tmp/core-image/work"
: > "$tmp/core-image/build.record"
"$bin" db init --root "$tmp/core-root" > "$tmp/result"
sh tools/image-source-stage.sh "$bin" "$tmp/core-root" "$tmp/core-image" "$tmp/source-input"
sh tools/image-package-stage.sh "$bin" "$tmp/core-image" i686 \
    --core busybox fixture busybox --source fixture fixture
test -f "$tmp/core-image/work/core-busybox.holy"
cmp "$tmp/core-image/work/core-busybox.holy" "$tmp/repo/busybox.holy"
test "$(wc -w < "$tmp/core-image/work/additional-packages")" -eq 2
grep -qx "busybox $source_id" "$tmp/core-image/work/add-sources"
grep -q '^resolver-architecture image i686 artifact .* accepted$' \
    "$tmp/core-image/build.record"
test ! -f "$tmp/core-image/packages/add-0003.holy"
mkdir -p "$tmp/cross-fixture" "$tmp/cross-other" "$tmp/cross-root" \
    "$tmp/cross-image/work" "$tmp/cross-image/inputs" \
    "$tmp/cross-image/packages" "$tmp/cross-image/mirrors"
cp "$tmp/repo/fixture.holy" "$tmp/cross-fixture/"
cp "$tmp/repo/helper.holy" "$tmp/cross-other/"
"$bin" repo index "$tmp/cross-fixture" > "$tmp/result"
"$bin" repo seal "$tmp/cross-fixture" > "$tmp/result"
"$bin" repo index "$tmp/cross-other" > "$tmp/result"
"$bin" repo seal "$tmp/cross-other" > "$tmp/result"
fixture_index=$(sed -n 's/^sha256 //p' "$tmp/cross-fixture/current")
other_index=$(sed -n 's/^sha256 //p' "$tmp/cross-other/current")
printf '[source fixture]\ntype holy-http\nurl "https://fixture.example/holy/"\n[source other]\ntype holy-http\nurl "https://other.example/holy/"\n' > "$tmp/cross-sources.conf"
"$bin" db init --root "$tmp/cross-root" > "$tmp/result"
"$bin" source plan --config "$tmp/cross-sources.conf" --root "$tmp/cross-root" > "$tmp/cross-source.plan"
cross_plan=$(sha256sum "$tmp/cross-source.plan")
"$bin" source apply "$tmp/cross-source.plan" --sha256 "${cross_plan%% *}" \
    --root "$tmp/cross-root" > "$tmp/result"
"$bin" source list --root "$tmp/cross-root" > "$tmp/cross-image/work/source-list"
other_id=$(sed -n 's/^source \([0-9a-f]*\) "other" active$/\1/p' "$tmp/cross-image/work/source-list")
test "${#other_id}" -eq 64
printf 'format holy-mirror-1\nurl "https://fixture.example/holy/"\nindex-sha256 %s\nverification digest-pinned-unsigned\nsource-id %s\n' \
    "$fixture_index" "$source_id" > "$tmp/cross-fixture/mirror-origin"
printf 'format holy-mirror-1\nurl "https://other.example/holy/"\nindex-sha256 %s\nverification digest-pinned-unsigned\nsource-id %s\n' \
    "$other_index" "$other_id" > "$tmp/cross-other/mirror-origin"
cp -R "$tmp/cross-fixture" "$tmp/cross-image/mirrors/fixture"
cp -R "$tmp/cross-other" "$tmp/cross-image/mirrors/other"
cp "$tmp/cross-sources.conf" "$tmp/cross-image/inputs/sources.conf"
printf 'fixture\nother\n' > "$tmp/cross-image/inputs/source-aliases"
: > "$tmp/cross-image/build.record"
sh tools/image-package-stage.sh "$bin" "$tmp/cross-image" x86_64 \
    --source fixture fixture
test "$(wc -l < "$tmp/cross-image/work/add-sources")" -eq 2
grep -q " $other_id$" "$tmp/cross-image/work/add-sources"
grep -q '^selected ' "$tmp/cross-image/work/solve-fixture-fixture.record"
test ! -e "$tmp/cross-image/work/resolver-root/var/lib/holypkg/installed"/*/meta
fixture_label=
for label in add-0001 add-0002; do
    "$bin" info "local:$tmp/cross-image/inputs/$label.holy" > "$tmp/result"
    if grep -qx 'name fixture' "$tmp/result"; then fixture_label=$label; fi
done
test -n "$fixture_label"
if "$bin" solve "local:$tmp/cross-image/inputs/$fixture_label.holy" \
    > "$tmp/result" 2> "$tmp/error"; then exit 1; else test "$?" -eq 4; fi
printf '[install]\nroot "%s"\n' "$tmp/cross-root" > "$tmp/cross-install.conf"
for label in add-0001 add-0002; do
    artifact="$tmp/cross-image/packages/$label.holy"
    digest=$(sha256sum "$artifact")
    digest=${digest%% *}
    "$bin" cache stage "local:$artifact" --root "$tmp/cross-root" > "$tmp/result"
    source=$(awk -v label="$label" '$1 == label {print $2}' "$tmp/cross-image/work/add-sources")
    printf 'artifact %s\nsource %s %s\n' "$digest" "$digest" "$source" \
        >> "$tmp/cross-install.conf"
done
./holyinstall --config "$tmp/cross-install.conf" --plan "$tmp/cross-install.plan" \
    --holypkg "$bin" > "$tmp/result"
./holyinstall --apply "$tmp/cross-install.plan" --holypkg "$bin" > "$tmp/result"
"$bin" db check --all --root "$tmp/cross-root" > "$tmp/result"
mkdir -p "$tmp/explicit-image/inputs" "$tmp/explicit-image/packages" "$tmp/explicit-image/work"
cp -R "$tmp/cross-image/mirrors" "$tmp/explicit-image/mirrors"
cp "$tmp/cross-image/inputs/sources.conf" "$tmp/cross-image/inputs/source-aliases" \
    "$tmp/explicit-image/inputs/"
cp "$tmp/cross-image/work/source-list" "$tmp/explicit-image/work/source-list"
: > "$tmp/explicit-image/build.record"
sh tools/image-package-stage.sh "$bin" "$tmp/explicit-image" x86_64 \
    --source fixture fixture --source other helper
test "$(wc -w < "$tmp/explicit-image/work/additional-packages")" -eq 2
test "$(wc -l < "$tmp/explicit-image/work/add-sources")" -eq 2
mkdir -p "$tmp/ambiguous-root" "$tmp/ambiguous-image/inputs" \
    "$tmp/ambiguous-image/packages" "$tmp/ambiguous-image/work"
cp -R "$tmp/cross-image/mirrors" "$tmp/ambiguous-image/mirrors"
cp -R "$tmp/cross-other" "$tmp/ambiguous-image/mirrors/third"
printf '[source third]\ntype holy-http\nurl "https://third.example/holy/"\n' \
    >> "$tmp/cross-sources.conf"
cp "$tmp/cross-sources.conf" "$tmp/ambiguous-image/inputs/sources.conf"
printf 'fixture\nother\nthird\n' > "$tmp/ambiguous-image/inputs/source-aliases"
"$bin" db init --root "$tmp/ambiguous-root" > "$tmp/result"
"$bin" source plan --config "$tmp/cross-sources.conf" --root "$tmp/ambiguous-root" \
    > "$tmp/ambiguous-source.plan"
ambiguous_plan=$(sha256sum "$tmp/ambiguous-source.plan")
"$bin" source apply "$tmp/ambiguous-source.plan" --sha256 "${ambiguous_plan%% *}" \
    --root "$tmp/ambiguous-root" > "$tmp/result"
"$bin" source list --root "$tmp/ambiguous-root" \
    > "$tmp/ambiguous-image/work/source-list"
third_id=$(sed -n 's/^source \([0-9a-f]*\) "third" active$/\1/p' \
    "$tmp/ambiguous-image/work/source-list")
test "${#third_id}" -eq 64
printf 'format holy-mirror-1\nurl "https://third.example/holy/"\nindex-sha256 %s\nverification digest-pinned-unsigned\nsource-id %s\n' \
    "$other_index" "$third_id" > "$tmp/ambiguous-image/mirrors/third/mirror-origin"
: > "$tmp/ambiguous-image/build.record"
if sh tools/image-package-stage.sh "$bin" "$tmp/ambiguous-image" x86_64 \
    --source fixture fixture > "$tmp/result" 2> "$tmp/error"; then exit 1; else
    test "$?" -eq 3
fi
grep -q 'decision-required' "$tmp/error"
fixture_hash=$(sha256sum "$tmp/cross-fixture/fixture.holy")
printf 'format holy-answers-1\nsource %s helper-1 other\n' \
    "${fixture_hash%% *}" > "$tmp/ambiguous-answers"
cp "$tmp/ambiguous-answers" "$tmp/ambiguous-image/inputs/resolver-answers"
mkdir -p "$tmp/answered-image/inputs" "$tmp/answered-image/packages" "$tmp/answered-image/work"
cp -R "$tmp/ambiguous-image/mirrors" "$tmp/answered-image/mirrors"
cp "$tmp/ambiguous-image/inputs/sources.conf" \
    "$tmp/ambiguous-image/inputs/source-aliases" \
    "$tmp/ambiguous-image/inputs/resolver-answers" "$tmp/answered-image/inputs/"
cp "$tmp/ambiguous-image/work/source-list" "$tmp/answered-image/work/source-list"
: > "$tmp/answered-image/build.record"
sh tools/image-package-stage.sh "$bin" "$tmp/answered-image" x86_64 \
    --source fixture fixture
test "$(wc -l < "$tmp/answered-image/work/add-sources")" -eq 2
grep -q " $other_id$" "$tmp/answered-image/work/add-sources"
if grep -q " $third_id$" "$tmp/answered-image/work/add-sources"; then exit 1; fi
printf 'fixture build plan\n' > "$tmp/image/plan"
printf 'fixture install plan\n' > "$tmp/image/install.plan"
python3 tools/image-host-tools.py "$tmp/image/host-tools.jsonl" sh python3
tools_hash=$(sha256sum "$tmp/image/host-tools.jsonl")
printf 'host-tools-sha256 %s\n' "${tools_hash%% *}" >> "$tmp/image/build.record"
plan_hash=$(sha256sum "$tmp/image/plan")
printf '%s\n' "${plan_hash%% *}" > "$tmp/image/boot-plan"
install_hash=$(sha256sum "$tmp/image/install.plan")
printf 'install-plan-file-sha256 %s\n' "${install_hash%% *}" >> "$tmp/image/build.record"
(
    cd "$tmp/image"
    find inputs packages mirrors -type f -print0 | sort -z | xargs -0 sha256sum > input-lock.sha256
)
lock=$(sha256sum "$tmp/image/input-lock.sha256")
printf 'input-lock-sha256 %s\n' "${lock%% *}" >> "$tmp/image/build.record"
./holygetiso --export-inputs "$tmp/image" "$tmp/export" > "$tmp/result"
test "$(cat "$tmp/result")" = "$tmp/export"
(cd "$tmp/export" && sha256sum -c SHA256SUMS > /dev/null)
cmp "$tmp/image/inputs/add-0001.holy" "$tmp/export/inputs/add-0001.holy"
cmp "$tmp/image/mirrors/fixture/current" "$tmp/export/mirrors/fixture/current"
if ./holygetiso --export-inputs "$tmp/image" "$tmp/export" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi
printf 'changed\n' >> "$tmp/image/inputs/add-0001.holy"
if ./holygetiso --export-inputs "$tmp/image" "$tmp/changed-export" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi
test ! -e "$tmp/changed-export"
cp "$tmp/export/inputs/add-0001.holy" "$tmp/image/inputs/add-0001.holy"
printf '{}\n' >> "$tmp/image/host-tools.jsonl"
if ./holygetiso --export-inputs "$tmp/image" "$tmp/changed-tools" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi
test ! -e "$tmp/changed-tools"
"$bin" fetch fixture:fixture --catalog "$tmp/image/mirrors/fixture" \
    --root "$tmp/image-root" --output "$tmp/fetched" > "$tmp/result"
test -f "$tmp/fetched/$(sha256sum "$tmp/repo/fixture.holy" | cut -d ' ' -f 1).holy"
"$bin" source list --root "$tmp/image-root" > "$tmp/result"
grep -qx "source $source_id \"fixture\" active" "$tmp/result"
grep -q '^root-path "/var/cache/holypkg/image-mirrors/fixture"$' \
    "$tmp/image-root/var/lib/holypkg/catalogs/$source_id"
mv "$tmp/image-root" "$tmp/relocated-root"
mkdir "$tmp/relocated-fetch"
"$bin" db check --all --root "$tmp/relocated-root" > "$tmp/result"
"$bin" fetch fixture:fixture --root "$tmp/relocated-root" \
    --output "$tmp/relocated-fetch" > "$tmp/result"
test -f "$tmp/relocated-fetch/$(sha256sum "$tmp/repo/fixture.holy" | cut -d ' ' -f 1).holy"
mkdir "$tmp/wrong-root" "$tmp/wrong-image"
mkdir "$tmp/wrong-image/inputs" "$tmp/wrong-image/work"
: > "$tmp/wrong-image/build.record"
"$bin" db init --root "$tmp/wrong-root" > "$tmp/result"
printf '%064d\n' 0 > "$tmp/source-input/fixture.index"
if sh tools/image-source-stage.sh "$bin" "$tmp/wrong-root" "$tmp/wrong-image" \
    "$tmp/source-input" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi
test ! -e "$tmp/wrong-image/mirrors/fixture/current"
printf '%s\n' "$index" > "$tmp/source-input/fixture.index"
rm "$tmp/source-input/fixture.embed"
mkdir "$tmp/minimal-root" "$tmp/minimal-image"
mkdir "$tmp/minimal-image/inputs" "$tmp/minimal-image/packages" "$tmp/minimal-image/work"
: > "$tmp/minimal-image/build.record"
"$bin" db init --root "$tmp/minimal-root" > "$tmp/result"
sh tools/image-source-stage.sh "$bin" "$tmp/minimal-root" "$tmp/minimal-image" "$tmp/source-input"
test ! -e "$tmp/minimal-root/var/cache/holypkg/image-mirrors"
sh tools/image-package-stage.sh "$bin" "$tmp/minimal-image" x86_64 \
    --source fixture fixture
test "$(wc -w < "$tmp/minimal-image/work/additional-packages")" -eq 2
openssl genpkey -algorithm ED25519 -out "$tmp/signer.pem" > "$tmp/result" 2> "$tmp/error"
openssl pkey -in "$tmp/signer.pem" -pubout -out "$tmp/public.pem" > "$tmp/result" 2> "$tmp/error"
"$bin" repo seal "$tmp/repo" --key "$tmp/signer.pem" > "$tmp/result"
openssl pkey -pubin -in "$tmp/public.pem" -outform DER -out "$tmp/public.der"
raw=$(python3 - "$tmp/public.der" <<'PY'
import pathlib, sys
print(pathlib.Path(sys.argv[1]).read_bytes()[-32:].hex())
PY
)
test "${#raw}" -eq 64
key_hash=$(python3 - "$raw" <<'PY'
import hashlib, sys
print(hashlib.sha256(bytes.fromhex(sys.argv[1])).hexdigest())
PY
)
printf 'format holy-mirror-1\nurl "https://fixture.example/holy/"\nindex-sha256 %s\nverification ed25519-pinned-key\npublic-key-sha256 %s\nsource-id %s\n' \
    "$index" "$key_hash" "$source_id" > "$tmp/repo/mirror-origin"
python3 - "$tmp/image.conf" "$tmp/signed-image.conf" "$tmp/public.pem" <<'PY'
import pathlib, sys
text = pathlib.Path(sys.argv[1]).read_text()
text = text.replace('embed-mirror yes\n', 'embed-mirror yes\ntrust require\npublic-key "' + sys.argv[3] + '"\n')
pathlib.Path(sys.argv[2]).write_text(text)
PY
./holygetiso --check "$tmp/signed-image.conf" > "$tmp/result"
signed_hash=$(sed -n 's/^config-sha256 //p' "$tmp/result")
test "${#signed_hash}" -eq 64
test "$signed_hash" != "$config_hash"
cp "$tmp/public.pem" "$tmp/public-original.pem"
openssl genpkey -algorithm ED25519 -out "$tmp/other-signer.pem" > "$tmp/result" 2> "$tmp/error"
openssl pkey -in "$tmp/other-signer.pem" -pubout -out "$tmp/public.pem" > "$tmp/result" 2> "$tmp/error"
./holygetiso --check "$tmp/signed-image.conf" > "$tmp/result"
other_hash=$(sed -n 's/^config-sha256 //p' "$tmp/result")
test "$other_hash" != "$signed_hash"
cp "$tmp/public-original.pem" "$tmp/public.pem"
mkdir -p "$tmp/signed-input" "$tmp/signed-root" "$tmp/signed-image/inputs" "$tmp/signed-image/work"
printf '[source fixture]\ntype holy-http\nurl "https://fixture.example/holy/"\ntrust require\npublic-key-ed25519 %s\n' \
    "$raw" > "$tmp/signed-input/sources.conf"
printf 'fixture\n' > "$tmp/signed-input/aliases"
printf '%s\n' "$index" > "$tmp/signed-input/fixture.index"
printf '%s\n' "$tmp/repo" > "$tmp/signed-input/fixture.mirror"
printf 'yes\n' > "$tmp/signed-input/fixture.embed"
: > "$tmp/signed-image/build.record"
"$bin" db init --root "$tmp/signed-root" > "$tmp/result"
sh tools/image-source-stage.sh "$bin" "$tmp/signed-root" "$tmp/signed-image" "$tmp/signed-input"
"$bin" search fixture --source fixture --root "$tmp/signed-root" > "$tmp/result"
grep -qx 'listed 1 packages' "$tmp/result"
printf '\001' | dd of="$tmp/signed-root/var/cache/holypkg/image-mirrors/fixture/signature.$index" bs=1 seek=0 conv=notrunc status=none
if "$bin" search fixture --source fixture --root "$tmp/signed-root" > "$tmp/result" 2> "$tmp/error"; then exit 1; else test "$?" -eq 6; fi
printf 'image source staging passed\n'