Skip to content

test(packaging): run the engine/corpus pairing scenarios under noscripts - #885

Merged
remyluslosius merged 1 commit into
mainfrom
fix/ow-081-rpm-noscripts
Sep 28, 2026
Merged

remyluslosius merged 1 commit into
mainfrom
fix/ow-081-rpm-noscripts

Conversation

@remyluslosius

Copy link
Copy Markdown
Contributor

Summary

Closes the open tsflags=noscripts item on the #882 acceptance list (CP bugs/OW-081). #882 switched the RPM container transactions from noscripts to scriptlets. That removed the noscripts case instead of adding scriptlets beside it. A pass with scriptlets is not evidence for the noscripts case.

  • kensa-rules-compat-container-test.sh takes a mode: scripts (default, unchanged) or noscripts (RPM only).
  • In noscripts mode, every dnf install and dnf upgrade carries --setopt=tsflags=noscripts, and every rpm -U and rpm -Uvh carries --noscripts.
  • Every scenario runs, and each step still checks package-manager state and the corpus digest separately.
  • The scriptlet check is inverted. It asserts that no identity keys were provisioned, which proves the mode took effect.
  • package-smoke gains a job, kensa-rules compat rockylinux:9 noscripts. The existing kensa-rules compat rockylinux:9 and kensa-rules compat ubuntu:24.04 names are unchanged.

No package, spec or product code changes.

Evidence (local, before push)

Packages: main's package-smoke artifact from ab68f303 (run 36367957565) as new, and the published v0.7.1 RPMs as old, on rockylinux:9.

Run Result
noscripts 39 of 39 pass
scripts 39 of 39 pass
noscripts label with the flags removed (mutant) 1 fail: identity keys exist, so a scriptlet ran despite noscripts

The two passing runs differ only in the inverted scriptlet check.

Not covered

  • Only RPM. DEB has no equivalent of noscripts.
  • Hosted runs here test the packages this tree builds. The candidate's own packages are a separate gate (OW-081 criterion 2).

🤖 Generated with Claude Code

CP bugs/OW-081, the #882 acceptance list. The container test switched
its RPM transactions from tsflags=noscripts to scriptlets, which dropped
the noscripts case instead of adding scriptlets beside it. A pass with
scriptlets is not evidence that the refusals hold on dependency
resolution alone.

The container test takes a mode: scripts (the default, unchanged) or
noscripts (RPM only). In noscripts mode every dnf transaction carries
--setopt=tsflags=noscripts and every rpm -U and rpm -Uvh carries
--noscripts. All scenarios and both separate checks, package-manager
state and corpus digest, run as before. The scriptlet check is inverted:
it asserts no identity keys were provisioned, which proves the mode
took effect. package-smoke gains a third job,
"kensa-rules compat rockylinux:9 noscripts"; the two existing job names
are unchanged.

Local run against main's packages from ab68f30 and the v0.7.1 GA:
noscripts 39 of 39, scripts 39 of 39, the only difference the inverted
scriptlet check. A copy with the noscripts flags removed failed on that
check alone.
@remyluslosius
remyluslosius merged commit fc1117d into main Sep 28, 2026
32 checks passed
@remyluslosius
remyluslosius deleted the fix/ow-081-rpm-noscripts branch September 28, 2026 13:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant