Package workstation tools, reuse emulator sessions, and derive build versions

This commit is contained in:
2026-09-23 03:45:48 +08:00
parent 6bfcce8070
commit f5d9f96409
79 changed files with 878 additions and 132 deletions
+11 -2
View File
@@ -33,7 +33,9 @@ def invoke(prefix, arguments, ok=True):
def check_all(directory, key, ok=True):
for label, command in commands:
result = invoke(command, ['verify', directory, '--key', key], ok)
if ok: assert 'VERIFIED FDS/OS 0.1.0' in result
if ok:
expected=json.loads((directory/'manifest.json').read_text())['version']
assert f'VERIFIED FDS/OS {expected}' in result
key_prefix = work / 'test-key'
invoke([str(host)], ['keygen', key_prefix])
@@ -55,6 +57,13 @@ manifest = {'format': 1, 'version': '0.1.0', 'source_epoch': 1,
invoke([str(host)], ['sign', release, '--key', private])
check_all(release, public)
invoke([str(host)], ['sign', release, '--key', private], False)
# Keep the historical release fixture, and also sign the current Git-derived identity.
current = work / 'current-version'; current.mkdir()
shutil.copy2(release / 'image.img', current / 'image.img')
current_manifest = dict(manifest, version=subprocess.check_output([str(project/'tools/version')], text=True).strip())
(current / 'manifest.json').write_text(json.dumps(current_manifest))
invoke([str(host)], ['sign', current, '--key', private])
check_all(current, public)
# Independent standard Ed25519 verification/signing over the exact domain prefix
# and raw manifest bytes. Test-only DER files are private and never printed.
@@ -111,7 +120,7 @@ for name in ['traversal', 'duplicate', 'unknown', 'wrong-version', 'unbounded']:
if name == 'traversal': value['files'][0]['name'] = '../image.img'
elif name == 'duplicate': value['files'].append(copy.deepcopy(value['files'][0]))
elif name == 'unknown': value['execute'] = 'sh'
elif name == 'wrong-version': value['version'] = '999'
elif name == 'wrong-version': value['version'] = '../invalid'
(bad / 'manifest.json').write_text(json.dumps(value) + (' ' * (1024 * 1024) if name == 'unbounded' else ''))
(bad / 'manifest.sig').write_bytes((release / 'manifest.sig').read_bytes())
check_all(bad, public, False)