fix: support panel-managed deployment safely
Release / release (push) Canceled after 0s

This commit is contained in:
Qiufeng
2026-08-18 00:02:45 +08:00
parent c35ef3d383
commit 2c73ad7eb0
13 changed files with 265 additions and 22 deletions
+33
View File
@@ -178,7 +178,9 @@ build_release() {
printf '<!doctype html><title>new</title>\n' > "$stage/public/index.html"
printf '%s\n' "$version" > "$stage/VERSION"
printf '#!/bin/sh\nprintf "new updater\\n"\n' > "$stage/ops/update.sh"
printf '#!/usr/bin/env bash\nexit 0\n' > "$stage/ops/baota-start.sh"
chmod 0755 "$stage/ops/update.sh"
chmod 0755 "$stage/ops/baota-start.sh"
for name in kaidi-finance.service kaidi-update.service kaidi-update.path; do
printf '%s %s\n' "$unit_prefix" "$name" > "$stage/ops/$name"
done
@@ -364,6 +366,10 @@ assert_success_case() {
[ ! -e "$fixture/state/processing/request.json" ] \
|| fail 'success case left a claimed request behind'
grep -qx 'daemon-reload' "$fixture/systemctl.log" || fail 'systemd units were not reloaded'
grep -qx 'restart kaidi-finance.service' "$fixture/systemctl.log" \
|| fail 'success case did not restart the application after the atomic switch'
! grep -qx 'stop kaidi-finance.service' "$fixture/systemctl.log" \
|| fail 'success case stopped the application before switching releases'
! grep -qi nginx "$fixture/systemctl.log" || fail 'updater unexpectedly managed Nginx'
[ "$(mode_of "$fixture/app")" = 750 ] || fail 'application root is not traversable by the service group'
[ "$(mode_of "$fixture/app/releases/$version")" = 750 ] || fail 'release root mode is not 0750'
@@ -426,6 +432,10 @@ assert_rollback_case() {
|| fail 'rollback case did not restore the previous updater'
grep -qx 'old kaidi-update.path' "$fixture/systemd/kaidi-update.path" \
|| fail 'rollback case did not restore the previous path unit'
! grep -qx 'stop kaidi-finance.service' "$fixture/systemctl.log" \
|| fail 'rollback case stopped the application before restoring the previous release'
[ "$(grep -c '^restart kaidi-finance.service$' "$fixture/systemctl.log")" -ge 2 ] \
|| fail 'rollback case did not restart both the candidate and restored releases'
[ "$(jq -r '.state' "$fixture/state/status.json")" = FAILED ] \
|| fail 'rollback case did not persist FAILED'
[ ! -e "$fixture/app/releases/$version" ] \
@@ -434,6 +444,28 @@ assert_rollback_case() {
|| fail 'rollback case did not archive the failed request'
}
assert_incomplete_rollback_requires_manual_recovery_case() {
local fixture="$WORK/incomplete-rollback"
local version='1.0.0-preview.2'
mkdir -p "$fixture"
write_mock_commands "$fixture/mock-bin"
build_release "$fixture" "$version"
prepare_installation "$fixture" "$version"
download_and_prepare_install "$fixture" "$version"
if run_update "$fixture" fail > "$fixture/update.log" 2>&1; then
fail 'incomplete rollback case unexpectedly succeeded'
fi
grep -Fq 'manual recovery is required' "$fixture/update.log" \
|| fail 'incomplete rollback case did not require explicit recovery'
[ ! -e "$fixture/state/processing/request.json" ] \
|| fail 'incomplete rollback case left an automatically retriggered processing request'
[ -d "$fixture/state/transactions/active" ] \
|| fail 'incomplete rollback case did not preserve transaction evidence'
find "$fixture/state/failed" -type f -name 'request-*.json' -print -quit | grep -q . \
|| fail 'incomplete rollback case did not archive its claimed request'
}
assert_download_failure_case() {
local fixture="$WORK/download-failure"
local version='1.0.0-preview.2'
@@ -521,6 +553,7 @@ assert_success_case
assert_identical_systemd_operations_case
assert_update_path_failure_keeps_application_case
assert_rollback_case
assert_incomplete_rollback_requires_manual_recovery_case
assert_download_failure_case
assert_database_failure_case
assert_symlink_request_rejected