release: harden plugin deployment and recovery
Business Plugins CI / check (plugin-admin) (push) Successful in 1m37s
Business Plugins CI / check (subscription-admin) (push) Successful in 1m31s

This commit is contained in:
Qiufeng
2026-08-30 13:14:22 +08:00
parent ada4ab3c21
commit d3ff9be315
16 changed files with 259 additions and 50 deletions
+54
View File
@@ -0,0 +1,54 @@
#!/usr/bin/env bash
set -Eeuo pipefail
ROOT=$(CDPATH=; cd -- "$(dirname -- "${BASH_SOURCE[0]}")/.." && pwd)
TMP=$(mktemp -d)
trap 'rm -rf "$TMP"' EXIT
expect_fail() {
local label=$1; shift
if "$@" >"$TMP/stdout" 2>"$TMP/stderr"; then
printf 'FAIL: %s unexpectedly succeeded\n' "$label" >&2
return 1
fi
printf 'ok: %s\n' "$label"
}
mkdir -p "$TMP/real" "$TMP/bin"
ln -s "$TMP/real" "$TMP/path-link"
# deploy/install.sh must reject an existing symlink component and a missing
# parent before git clone can create or write the checkout.
expect_fail 'deploy install rejects symlink component' \
env PLUGIN_SOURCE_DIR="$TMP/path-link/sub2api-add" PLUGIN_ALLOW_CUSTOM_PATHS=true \
bash "$ROOT/deploy/install.sh"
expect_fail 'deploy install rejects missing parent' \
env PLUGIN_SOURCE_DIR="$TMP/missing/sub2api-add" PLUGIN_ALLOW_CUSTOM_PATHS=true \
bash "$ROOT/deploy/install.sh"
# Stub host tools so install-local reaches path validation without requiring
# Go or a running systemd instance.
cat >"$TMP/bin/go" <<'EOF'
#!/usr/bin/env bash
if [[ ${1:-} == version ]]; then printf 'go version go1.23.0 linux/amd64\n'; else exit 0; fi
EOF
cat >"$TMP/bin/systemctl" <<'EOF'
#!/usr/bin/env bash
exit 0
EOF
chmod +x "$TMP/bin/go" "$TMP/bin/systemctl"
expect_fail 'install-local rejects symlink component' \
env PATH="$TMP/bin:/usr/bin:/bin" PLUGIN_ALLOW_CUSTOM_PATHS=true \
PLUGIN_INSTALL_PREFIX="$TMP/path-link/sub2api-add" \
PLUGIN_ETC_DIR="$TMP/etc/sub2api-add" PLUGIN_VAR_DIR="$TMP/var/sub2api-add" \
bash "$ROOT/scripts/install-local.sh" --plugin plugin-admin
expect_fail 'uninstall rejects symlink component' \
env PATH="$TMP/bin:/usr/bin:/bin" PLUGIN_ALLOW_CUSTOM_PATHS=true \
PLUGIN_INSTALL_PREFIX="$TMP/path-link/sub2api-add" \
PLUGIN_ETC_DIR="$TMP/etc/sub2api-add" PLUGIN_VAR_DIR="$TMP/var/sub2api-add" \
PLUGIN_SOURCE_DIR="$TMP/source/sub2api-add" \
bash "$ROOT/deploy/uninstall.sh" --plugin plugin-admin --yes
printf '%s\n' 'deploy path safety checks passed'