#!/bin/sh set -eu bin=$(realpath "$1") tmp=$(mktemp -d) trap 'rm -rf "$tmp"' EXIT HUP INT TERM mkdir -p "$tmp/repo" "$tmp/tree/HOLY" "$tmp/tree/DATA" \ "$tmp/source-input" "$tmp/identity-root" "$tmp/image-root" \ "$tmp/image/inputs" "$tmp/image/packages" "$tmp/image/work" "$tmp/fetched" printf 'format holy-package-1\nname fixture\nversion 1\nrelease 1\nos linux\narch noarch\nlibc nolibc\n' > "$tmp/tree/HOLY/meta" for member in files deps provides hooks origin transform; do : > "$tmp/tree/HOLY/$member" done printf 'require helper-1 fixture package helper any any any - helper metadata\n' > "$tmp/tree/HOLY/deps" tar -cf "$tmp/fixture.tar" -C "$tmp/tree" HOLY DATA lz4 -q "$tmp/fixture.tar" "$tmp/repo/fixture.holy" sed 's/name fixture/name helper/' "$tmp/tree/HOLY/meta" > "$tmp/tree/HOLY/helper-meta" mv "$tmp/tree/HOLY/helper-meta" "$tmp/tree/HOLY/meta" : > "$tmp/tree/HOLY/deps" tar -cf "$tmp/helper.tar" -C "$tmp/tree" HOLY DATA lz4 -q "$tmp/helper.tar" "$tmp/repo/helper.holy" sed -e 's/name helper/name busybox/' -e 's/arch noarch/arch x86/' \ "$tmp/tree/HOLY/meta" > "$tmp/tree/HOLY/busybox-meta" mv "$tmp/tree/HOLY/busybox-meta" "$tmp/tree/HOLY/meta" tar -cf "$tmp/busybox.tar" -C "$tmp/tree" HOLY DATA lz4 -q "$tmp/busybox.tar" "$tmp/repo/busybox.holy" "$bin" repo index "$tmp/repo" > "$tmp/result" "$bin" repo seal "$tmp/repo" > "$tmp/result" index=$(sed -n 's/^sha256 //p' "$tmp/repo/current") test "${#index}" -eq 64 printf '[source fixture]\ntype holy-http\nurl "https://fixture.example/holy/"\n' > "$tmp/source-input/sources.conf" printf 'fixture\n' > "$tmp/source-input/aliases" printf '%s\n' "$index" > "$tmp/source-input/fixture.index" printf '%s\n' "$tmp/repo" > "$tmp/source-input/fixture.mirror" printf 'yes\n' > "$tmp/source-input/fixture.embed" mkdir "$tmp/limine" "$tmp/config-parts" for input in kernel static-holypkg static-holyinstall static-cc busybox dinit mdevd; do : > "$tmp/$input" done cat > "$tmp/config-parts/image.conf" < "$tmp/image.conf" < "$tmp/result" grep -qx "source fixture index $index" "$tmp/result" grep -qx 'add fixture:fixture' "$tmp/result" config_hash=$(sed -n 's/^config-sha256 //p' "$tmp/result") sed "s@busybox \"$tmp/busybox\"@busybox fixture:busybox@" "$tmp/image.conf" > "$tmp/core-image.conf" ./holygetiso --check "$tmp/core-image.conf" > "$tmp/result" grep -qx 'core busybox fixture:busybox' "$tmp/result" grep -Fxq "output $tmp/config-parts/../output" "$tmp/result" sed 's@kernel-image "../kernel"@kernel-package fixture:busybox@' \ "$tmp/config-parts/image.conf" > "$tmp/config-parts/kernel-image.conf" sed 's@config-parts/image.conf@config-parts/kernel-image.conf@' \ "$tmp/image.conf" > "$tmp/kernel-image.conf" ./holygetiso --check "$tmp/kernel-image.conf" > "$tmp/result" grep -qx 'kernel-package fixture:busybox' "$tmp/result" printf 'kernel-image "../kernel"\n' >> "$tmp/config-parts/kernel-image.conf" if ./holygetiso --check "$tmp/kernel-image.conf" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi grep -q 'choose exactly one kernel-image or kernel-package' "$tmp/error" sed 's/boot-test build-only/boot-test required/' "$tmp/config-parts/image.conf" \ > "$tmp/config-parts/changed.conf" mv "$tmp/config-parts/changed.conf" "$tmp/config-parts/image.conf" ./holygetiso --check "$tmp/image.conf" > "$tmp/result" changed_hash=$(sed -n 's/^config-sha256 //p' "$tmp/result") test "$config_hash" != "$changed_hash" sed 's/boot-test required/boot-test build-only/' "$tmp/config-parts/image.conf" \ > "$tmp/config-parts/restored.conf" mv "$tmp/config-parts/restored.conf" "$tmp/config-parts/image.conf" printf 'format holy-answers-1\n' > "$tmp/image-answers" answer_hash=$(sha256sum "$tmp/image-answers") cp "$tmp/image.conf" "$tmp/answer-image.conf" printf '\n[resolver]\nanswers "%s"\nanswers-sha256 %s\n' \ "$tmp/image-answers" "${answer_hash%% *}" >> "$tmp/answer-image.conf" ./holygetiso --check "$tmp/answer-image.conf" > "$tmp/result" printf '#changed\n' >> "$tmp/image-answers" if ./holygetiso --check "$tmp/answer-image.conf" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi grep -q 'matching SHA-256 pin' "$tmp/error" printf 'include "config-parts/cycle.conf"\n' > "$tmp/cycle.conf" printf 'include "../cycle.conf"\n' > "$tmp/config-parts/cycle.conf" if ./holygetiso --check "$tmp/cycle.conf" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi grep -q 'include cycle' "$tmp/error" "$bin" db init --root "$tmp/identity-root" > "$tmp/result" "$bin" source plan --config "$tmp/source-input/sources.conf" --root "$tmp/identity-root" > "$tmp/identity.plan" identity_plan=$(sha256sum "$tmp/identity.plan") identity_plan=${identity_plan%% *} "$bin" source apply "$tmp/identity.plan" --sha256 "$identity_plan" --root "$tmp/identity-root" > "$tmp/result" "$bin" source list --root "$tmp/identity-root" > "$tmp/result" source_id=$(awk '$1 == "source" && $3 == "\"fixture\"" && $4 == "active" {print $2}' "$tmp/result") test "${#source_id}" -eq 64 printf 'format holy-mirror-1\nurl "https://fixture.example/holy/"\nindex-sha256 %s\nverification digest-pinned-unsigned\nsource-id %s\n' \ "$index" "$source_id" > "$tmp/repo/mirror-origin" "$bin" db init --root "$tmp/image-root" > "$tmp/result" : > "$tmp/image/build.record" sh tools/image-source-stage.sh "$bin" "$tmp/image-root" "$tmp/image" "$tmp/source-input" grep -qx "source fixture $source_id index $index" "$tmp/image/build.record" sh tools/image-package-stage.sh "$bin" "$tmp/image" x86_64 \ --source fixture fixture --source fixture fixture test "$(wc -w < "$tmp/image/work/additional-packages")" -eq 2 test "$(wc -l < "$tmp/image/work/add-sources")" -eq 2 grep -q " $source_id$" "$tmp/image/work/add-sources" "$bin" info "local:$tmp/image/inputs/add-0001.holy" > "$tmp/first-info" "$bin" info "local:$tmp/image/inputs/add-0002.holy" > "$tmp/second-info" sed -n 's/^name //p' "$tmp/first-info" "$tmp/second-info" | sort > "$tmp/names" printf 'fixture\nhelper\n' > "$tmp/expected-names" cmp "$tmp/names" "$tmp/expected-names" printf '[install]\nroot "%s"\n' "$tmp/image-root" > "$tmp/image-install.conf" for label in add-0001 add-0002; do artifact="$tmp/image/packages/$label.holy" digest=$(sha256sum "$artifact") digest=${digest%% *} "$bin" cache stage "local:$artifact" --root "$tmp/image-root" > "$tmp/result" printf 'artifact %s\nsource %s %s\n' "$digest" "$digest" "$source_id" \ >> "$tmp/image-install.conf" done ./holyinstall --config "$tmp/image-install.conf" --plan "$tmp/image-install.plan" \ --holypkg "$bin" > "$tmp/result" ./holyinstall --apply "$tmp/image-install.plan" --holypkg "$bin" > "$tmp/result" "$bin" db check --all --root "$tmp/image-root" > "$tmp/result" mkdir -p "$tmp/core-root" "$tmp/core-image/inputs" "$tmp/core-image/packages" "$tmp/core-image/work" : > "$tmp/core-image/build.record" "$bin" db init --root "$tmp/core-root" > "$tmp/result" sh tools/image-source-stage.sh "$bin" "$tmp/core-root" "$tmp/core-image" "$tmp/source-input" sh tools/image-package-stage.sh "$bin" "$tmp/core-image" i686 \ --core busybox fixture busybox --source fixture fixture test -f "$tmp/core-image/work/core-busybox.holy" cmp "$tmp/core-image/work/core-busybox.holy" "$tmp/repo/busybox.holy" test "$(wc -w < "$tmp/core-image/work/additional-packages")" -eq 2 grep -qx "busybox $source_id" "$tmp/core-image/work/add-sources" grep -q '^resolver-architecture image i686 artifact .* accepted$' \ "$tmp/core-image/build.record" test ! -f "$tmp/core-image/packages/add-0003.holy" mkdir -p "$tmp/cross-fixture" "$tmp/cross-other" "$tmp/cross-root" \ "$tmp/cross-image/work" "$tmp/cross-image/inputs" \ "$tmp/cross-image/packages" "$tmp/cross-image/mirrors" cp "$tmp/repo/fixture.holy" "$tmp/cross-fixture/" cp "$tmp/repo/helper.holy" "$tmp/cross-other/" "$bin" repo index "$tmp/cross-fixture" > "$tmp/result" "$bin" repo seal "$tmp/cross-fixture" > "$tmp/result" "$bin" repo index "$tmp/cross-other" > "$tmp/result" "$bin" repo seal "$tmp/cross-other" > "$tmp/result" fixture_index=$(sed -n 's/^sha256 //p' "$tmp/cross-fixture/current") other_index=$(sed -n 's/^sha256 //p' "$tmp/cross-other/current") printf '[source fixture]\ntype holy-http\nurl "https://fixture.example/holy/"\n[source other]\ntype holy-http\nurl "https://other.example/holy/"\n' > "$tmp/cross-sources.conf" "$bin" db init --root "$tmp/cross-root" > "$tmp/result" "$bin" source plan --config "$tmp/cross-sources.conf" --root "$tmp/cross-root" > "$tmp/cross-source.plan" cross_plan=$(sha256sum "$tmp/cross-source.plan") "$bin" source apply "$tmp/cross-source.plan" --sha256 "${cross_plan%% *}" \ --root "$tmp/cross-root" > "$tmp/result" "$bin" source list --root "$tmp/cross-root" > "$tmp/cross-image/work/source-list" other_id=$(sed -n 's/^source \([0-9a-f]*\) "other" active$/\1/p' "$tmp/cross-image/work/source-list") test "${#other_id}" -eq 64 printf 'format holy-mirror-1\nurl "https://fixture.example/holy/"\nindex-sha256 %s\nverification digest-pinned-unsigned\nsource-id %s\n' \ "$fixture_index" "$source_id" > "$tmp/cross-fixture/mirror-origin" printf 'format holy-mirror-1\nurl "https://other.example/holy/"\nindex-sha256 %s\nverification digest-pinned-unsigned\nsource-id %s\n' \ "$other_index" "$other_id" > "$tmp/cross-other/mirror-origin" cp -R "$tmp/cross-fixture" "$tmp/cross-image/mirrors/fixture" cp -R "$tmp/cross-other" "$tmp/cross-image/mirrors/other" cp "$tmp/cross-sources.conf" "$tmp/cross-image/inputs/sources.conf" printf 'fixture\nother\n' > "$tmp/cross-image/inputs/source-aliases" : > "$tmp/cross-image/build.record" sh tools/image-package-stage.sh "$bin" "$tmp/cross-image" x86_64 \ --source fixture fixture test "$(wc -l < "$tmp/cross-image/work/add-sources")" -eq 2 grep -q " $other_id$" "$tmp/cross-image/work/add-sources" grep -q '^selected ' "$tmp/cross-image/work/solve-fixture-fixture.record" test ! -e "$tmp/cross-image/work/resolver-root/var/lib/holypkg/installed"/*/meta fixture_label= for label in add-0001 add-0002; do "$bin" info "local:$tmp/cross-image/inputs/$label.holy" > "$tmp/result" if grep -qx 'name fixture' "$tmp/result"; then fixture_label=$label; fi done test -n "$fixture_label" if "$bin" solve "local:$tmp/cross-image/inputs/$fixture_label.holy" \ > "$tmp/result" 2> "$tmp/error"; then exit 1; else test "$?" -eq 4; fi printf '[install]\nroot "%s"\n' "$tmp/cross-root" > "$tmp/cross-install.conf" for label in add-0001 add-0002; do artifact="$tmp/cross-image/packages/$label.holy" digest=$(sha256sum "$artifact") digest=${digest%% *} "$bin" cache stage "local:$artifact" --root "$tmp/cross-root" > "$tmp/result" source=$(awk -v label="$label" '$1 == label {print $2}' "$tmp/cross-image/work/add-sources") printf 'artifact %s\nsource %s %s\n' "$digest" "$digest" "$source" \ >> "$tmp/cross-install.conf" done ./holyinstall --config "$tmp/cross-install.conf" --plan "$tmp/cross-install.plan" \ --holypkg "$bin" > "$tmp/result" ./holyinstall --apply "$tmp/cross-install.plan" --holypkg "$bin" > "$tmp/result" "$bin" db check --all --root "$tmp/cross-root" > "$tmp/result" mkdir -p "$tmp/explicit-image/inputs" "$tmp/explicit-image/packages" "$tmp/explicit-image/work" cp -R "$tmp/cross-image/mirrors" "$tmp/explicit-image/mirrors" cp "$tmp/cross-image/inputs/sources.conf" "$tmp/cross-image/inputs/source-aliases" \ "$tmp/explicit-image/inputs/" cp "$tmp/cross-image/work/source-list" "$tmp/explicit-image/work/source-list" : > "$tmp/explicit-image/build.record" sh tools/image-package-stage.sh "$bin" "$tmp/explicit-image" x86_64 \ --source fixture fixture --source other helper test "$(wc -w < "$tmp/explicit-image/work/additional-packages")" -eq 2 test "$(wc -l < "$tmp/explicit-image/work/add-sources")" -eq 2 mkdir -p "$tmp/ambiguous-root" "$tmp/ambiguous-image/inputs" \ "$tmp/ambiguous-image/packages" "$tmp/ambiguous-image/work" cp -R "$tmp/cross-image/mirrors" "$tmp/ambiguous-image/mirrors" cp -R "$tmp/cross-other" "$tmp/ambiguous-image/mirrors/third" printf '[source third]\ntype holy-http\nurl "https://third.example/holy/"\n' \ >> "$tmp/cross-sources.conf" cp "$tmp/cross-sources.conf" "$tmp/ambiguous-image/inputs/sources.conf" printf 'fixture\nother\nthird\n' > "$tmp/ambiguous-image/inputs/source-aliases" "$bin" db init --root "$tmp/ambiguous-root" > "$tmp/result" "$bin" source plan --config "$tmp/cross-sources.conf" --root "$tmp/ambiguous-root" \ > "$tmp/ambiguous-source.plan" ambiguous_plan=$(sha256sum "$tmp/ambiguous-source.plan") "$bin" source apply "$tmp/ambiguous-source.plan" --sha256 "${ambiguous_plan%% *}" \ --root "$tmp/ambiguous-root" > "$tmp/result" "$bin" source list --root "$tmp/ambiguous-root" \ > "$tmp/ambiguous-image/work/source-list" third_id=$(sed -n 's/^source \([0-9a-f]*\) "third" active$/\1/p' \ "$tmp/ambiguous-image/work/source-list") test "${#third_id}" -eq 64 printf 'format holy-mirror-1\nurl "https://third.example/holy/"\nindex-sha256 %s\nverification digest-pinned-unsigned\nsource-id %s\n' \ "$other_index" "$third_id" > "$tmp/ambiguous-image/mirrors/third/mirror-origin" : > "$tmp/ambiguous-image/build.record" if sh tools/image-package-stage.sh "$bin" "$tmp/ambiguous-image" x86_64 \ --source fixture fixture > "$tmp/result" 2> "$tmp/error"; then exit 1; else test "$?" -eq 3 fi grep -q 'decision-required' "$tmp/error" fixture_hash=$(sha256sum "$tmp/cross-fixture/fixture.holy") printf 'format holy-answers-1\nsource %s helper-1 other\n' \ "${fixture_hash%% *}" > "$tmp/ambiguous-answers" cp "$tmp/ambiguous-answers" "$tmp/ambiguous-image/inputs/resolver-answers" mkdir -p "$tmp/answered-image/inputs" "$tmp/answered-image/packages" "$tmp/answered-image/work" cp -R "$tmp/ambiguous-image/mirrors" "$tmp/answered-image/mirrors" cp "$tmp/ambiguous-image/inputs/sources.conf" \ "$tmp/ambiguous-image/inputs/source-aliases" \ "$tmp/ambiguous-image/inputs/resolver-answers" "$tmp/answered-image/inputs/" cp "$tmp/ambiguous-image/work/source-list" "$tmp/answered-image/work/source-list" : > "$tmp/answered-image/build.record" sh tools/image-package-stage.sh "$bin" "$tmp/answered-image" x86_64 \ --source fixture fixture test "$(wc -l < "$tmp/answered-image/work/add-sources")" -eq 2 grep -q " $other_id$" "$tmp/answered-image/work/add-sources" if grep -q " $third_id$" "$tmp/answered-image/work/add-sources"; then exit 1; fi printf 'fixture build plan\n' > "$tmp/image/plan" printf 'fixture install plan\n' > "$tmp/image/install.plan" python3 tools/image-host-tools.py "$tmp/image/host-tools.jsonl" sh python3 tools_hash=$(sha256sum "$tmp/image/host-tools.jsonl") printf 'host-tools-sha256 %s\n' "${tools_hash%% *}" >> "$tmp/image/build.record" plan_hash=$(sha256sum "$tmp/image/plan") printf '%s\n' "${plan_hash%% *}" > "$tmp/image/boot-plan" install_hash=$(sha256sum "$tmp/image/install.plan") printf 'install-plan-file-sha256 %s\n' "${install_hash%% *}" >> "$tmp/image/build.record" ( cd "$tmp/image" find inputs packages mirrors -type f -print0 | sort -z | xargs -0 sha256sum > input-lock.sha256 ) lock=$(sha256sum "$tmp/image/input-lock.sha256") printf 'input-lock-sha256 %s\n' "${lock%% *}" >> "$tmp/image/build.record" ./holygetiso --export-inputs "$tmp/image" "$tmp/export" > "$tmp/result" test "$(cat "$tmp/result")" = "$tmp/export" (cd "$tmp/export" && sha256sum -c SHA256SUMS > /dev/null) cmp "$tmp/image/inputs/add-0001.holy" "$tmp/export/inputs/add-0001.holy" cmp "$tmp/image/mirrors/fixture/current" "$tmp/export/mirrors/fixture/current" if ./holygetiso --export-inputs "$tmp/image" "$tmp/export" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi printf 'changed\n' >> "$tmp/image/inputs/add-0001.holy" if ./holygetiso --export-inputs "$tmp/image" "$tmp/changed-export" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi test ! -e "$tmp/changed-export" cp "$tmp/export/inputs/add-0001.holy" "$tmp/image/inputs/add-0001.holy" printf '{}\n' >> "$tmp/image/host-tools.jsonl" if ./holygetiso --export-inputs "$tmp/image" "$tmp/changed-tools" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi test ! -e "$tmp/changed-tools" "$bin" fetch fixture:fixture --catalog "$tmp/image/mirrors/fixture" \ --root "$tmp/image-root" --output "$tmp/fetched" > "$tmp/result" test -f "$tmp/fetched/$(sha256sum "$tmp/repo/fixture.holy" | cut -d ' ' -f 1).holy" "$bin" source list --root "$tmp/image-root" > "$tmp/result" grep -qx "source $source_id \"fixture\" active" "$tmp/result" grep -q '^root-path "/var/cache/holypkg/image-mirrors/fixture"$' \ "$tmp/image-root/var/lib/holypkg/catalogs/$source_id" mv "$tmp/image-root" "$tmp/relocated-root" mkdir "$tmp/relocated-fetch" "$bin" db check --all --root "$tmp/relocated-root" > "$tmp/result" "$bin" fetch fixture:fixture --root "$tmp/relocated-root" \ --output "$tmp/relocated-fetch" > "$tmp/result" test -f "$tmp/relocated-fetch/$(sha256sum "$tmp/repo/fixture.holy" | cut -d ' ' -f 1).holy" mkdir "$tmp/wrong-root" "$tmp/wrong-image" mkdir "$tmp/wrong-image/inputs" "$tmp/wrong-image/work" : > "$tmp/wrong-image/build.record" "$bin" db init --root "$tmp/wrong-root" > "$tmp/result" printf '%064d\n' 0 > "$tmp/source-input/fixture.index" if sh tools/image-source-stage.sh "$bin" "$tmp/wrong-root" "$tmp/wrong-image" \ "$tmp/source-input" > "$tmp/result" 2> "$tmp/error"; then exit 1; fi test ! -e "$tmp/wrong-image/mirrors/fixture/current" printf '%s\n' "$index" > "$tmp/source-input/fixture.index" rm "$tmp/source-input/fixture.embed" mkdir "$tmp/minimal-root" "$tmp/minimal-image" mkdir "$tmp/minimal-image/inputs" "$tmp/minimal-image/packages" "$tmp/minimal-image/work" : > "$tmp/minimal-image/build.record" "$bin" db init --root "$tmp/minimal-root" > "$tmp/result" sh tools/image-source-stage.sh "$bin" "$tmp/minimal-root" "$tmp/minimal-image" "$tmp/source-input" test ! -e "$tmp/minimal-root/var/cache/holypkg/image-mirrors" sh tools/image-package-stage.sh "$bin" "$tmp/minimal-image" x86_64 \ --source fixture fixture test "$(wc -w < "$tmp/minimal-image/work/additional-packages")" -eq 2 openssl genpkey -algorithm ED25519 -out "$tmp/signer.pem" > "$tmp/result" 2> "$tmp/error" openssl pkey -in "$tmp/signer.pem" -pubout -out "$tmp/public.pem" > "$tmp/result" 2> "$tmp/error" "$bin" repo seal "$tmp/repo" --key "$tmp/signer.pem" > "$tmp/result" openssl pkey -pubin -in "$tmp/public.pem" -outform DER -out "$tmp/public.der" raw=$(python3 - "$tmp/public.der" <<'PY' import pathlib, sys print(pathlib.Path(sys.argv[1]).read_bytes()[-32:].hex()) PY ) test "${#raw}" -eq 64 key_hash=$(python3 - "$raw" <<'PY' import hashlib, sys print(hashlib.sha256(bytes.fromhex(sys.argv[1])).hexdigest()) PY ) printf 'format holy-mirror-1\nurl "https://fixture.example/holy/"\nindex-sha256 %s\nverification ed25519-pinned-key\npublic-key-sha256 %s\nsource-id %s\n' \ "$index" "$key_hash" "$source_id" > "$tmp/repo/mirror-origin" python3 - "$tmp/image.conf" "$tmp/signed-image.conf" "$tmp/public.pem" <<'PY' import pathlib, sys text = pathlib.Path(sys.argv[1]).read_text() text = text.replace('embed-mirror yes\n', 'embed-mirror yes\ntrust require\npublic-key "' + sys.argv[3] + '"\n') pathlib.Path(sys.argv[2]).write_text(text) PY ./holygetiso --check "$tmp/signed-image.conf" > "$tmp/result" signed_hash=$(sed -n 's/^config-sha256 //p' "$tmp/result") test "${#signed_hash}" -eq 64 test "$signed_hash" != "$config_hash" cp "$tmp/public.pem" "$tmp/public-original.pem" openssl genpkey -algorithm ED25519 -out "$tmp/other-signer.pem" > "$tmp/result" 2> "$tmp/error" openssl pkey -in "$tmp/other-signer.pem" -pubout -out "$tmp/public.pem" > "$tmp/result" 2> "$tmp/error" ./holygetiso --check "$tmp/signed-image.conf" > "$tmp/result" other_hash=$(sed -n 's/^config-sha256 //p' "$tmp/result") test "$other_hash" != "$signed_hash" cp "$tmp/public-original.pem" "$tmp/public.pem" mkdir -p "$tmp/signed-input" "$tmp/signed-root" "$tmp/signed-image/inputs" "$tmp/signed-image/work" printf '[source fixture]\ntype holy-http\nurl "https://fixture.example/holy/"\ntrust require\npublic-key-ed25519 %s\n' \ "$raw" > "$tmp/signed-input/sources.conf" printf 'fixture\n' > "$tmp/signed-input/aliases" printf '%s\n' "$index" > "$tmp/signed-input/fixture.index" printf '%s\n' "$tmp/repo" > "$tmp/signed-input/fixture.mirror" printf 'yes\n' > "$tmp/signed-input/fixture.embed" : > "$tmp/signed-image/build.record" "$bin" db init --root "$tmp/signed-root" > "$tmp/result" sh tools/image-source-stage.sh "$bin" "$tmp/signed-root" "$tmp/signed-image" "$tmp/signed-input" "$bin" search fixture --source fixture --root "$tmp/signed-root" > "$tmp/result" grep -qx 'listed 1 packages' "$tmp/result" printf '\001' | dd of="$tmp/signed-root/var/cache/holypkg/image-mirrors/fixture/signature.$index" bs=1 seek=0 conv=notrunc status=none if "$bin" search fixture --source fixture --root "$tmp/signed-root" > "$tmp/result" 2> "$tmp/error"; then exit 1; else test "$?" -eq 6; fi printf 'image source staging passed\n'