49 lines
2.4 KiB
Python
49 lines
2.4 KiB
Python
#!/usr/bin/env python3
|
|
"""Verify, relocate and run a locally generated development package with sandboxing intact."""
|
|
import argparse
|
|
import json
|
|
import os
|
|
from pathlib import Path
|
|
import subprocess
|
|
import shlex
|
|
import sys
|
|
import tempfile
|
|
|
|
ROOT = Path(__file__).resolve().parents[1]
|
|
sys.path.insert(0, str(ROOT / 'tools'))
|
|
from collect_linux_dependencies import sha256
|
|
from package_linux_development import verify_and_extract
|
|
|
|
|
|
def main():
|
|
parser = argparse.ArgumentParser(description=__doc__)
|
|
parser.add_argument('--archive', required=True, type=Path)
|
|
parser.add_argument('--output', required=True, type=Path)
|
|
args = parser.parse_args()
|
|
args.output.mkdir(parents=True, exist_ok=True)
|
|
# Invalidate earlier success even if environment/archive validation fails.
|
|
for name in ('results.json', 'package-smoke.json'):
|
|
(args.output / name).unlink(missing_ok=True)
|
|
flags = shlex.split(os.environ.get('QTWEBENGINE_CHROMIUM_FLAGS', ''))
|
|
if (os.environ.get('QTWEBENGINE_DISABLE_SANDBOX', '') not in ('', '0') or
|
|
any(flag.split('=', 1)[0] in ('--no-sandbox', '--disable-setuid-sandbox',
|
|
'--disable-seccomp-filter-sandbox') for flag in flags)):
|
|
raise SystemExit('Refusing package smoke with Chromium sandbox disabled')
|
|
archive = args.archive.resolve(strict=True)
|
|
with tempfile.TemporaryDirectory(prefix='docview-relocated-') as directory:
|
|
prefix = verify_and_extract(archive, Path(directory))
|
|
subprocess.run([sys.executable, str(ROOT / 'tests/smoke.py'), '--binary', str(prefix / 'bin/docview'),
|
|
'--output', str(args.output.resolve())], check=True, timeout=210)
|
|
report = {'archive': archive.name, 'archiveSha256': sha256(archive),
|
|
'payloadVerified': True, 'relocatedExtraction': True,
|
|
'scope': 'Same Arch development host; system Qt and other dependencies; not clean OS acceptance',
|
|
'chromiumSandboxDisabledByTest': False, 'workerSandboxDisabledByTest': False,
|
|
'cases': json.loads((args.output / 'results.json').read_text())}
|
|
report['temporaryExtractionRemoved'] = not Path(directory).exists()
|
|
(args.output / 'package-smoke.json').write_text(json.dumps(report, ensure_ascii=False, indent=2) + '\n')
|
|
print('Verified relocated package: 6 GUI smoke conditions; temporary extraction removed')
|
|
|
|
|
|
if __name__ == '__main__':
|
|
main()
|