test(Linux): Phase 12.L.E.12 — E13.h pin BuildScript ↔️ env-var URL propagation
Summary
Fills a coverage gap that would let air-gap operator deployments silently regress.
Coverage gap before this PR
| Layer | Pinned | What it tests |
|---|---|---|
| Unit |
BuildDownloadUrl(version, rid) returns env-var URL when set |
|
| Unit |
DownloadBaseUrlEnvVar constant name pinned literal (Rule 8) |
|
| E2E |
LocalReleaseMirror + manual placeholder substitution drives upgrade |
|
| Integration | env var → BuildScript → rendered DOWNLOAD_URL= line |
The full chain is:
env var → ResolveDownloadBaseUrl → BuildDownloadUrl → BuildScript
→ template substitution → rendered DOWNLOAD_URL= line
If ANY link breaks (e.g. BuildScript adds caching that bypasses BuildDownloadUrl on the substitution path, or someone introduces a new substitution site that uses DefaultDownloadBaseUrl directly), air-gap operators silently see github.com URLs in their rendered script — exit-6 download fail on every upgrade.
What this PR adds
Two paired tests:
BuildScript_EnvOverride_RenderedDownloadUrlPointsAtOperatorMirror
- Sets
SQUID_TARGET_LINUX_TENTACLE_DOWNLOAD_BASE_URL=https://mirror.acme.internal/squid - Asserts rendered
.shcontains the FULLDOWNLOAD_URL="<mirror>/<version>/...-$RID.tar.gz"assignment line (surgical match — not just URL substring, because the.shhas unrelatedgithub.commentions in a firewall-hint comment + apt-rollback URL) - Reverse-asserts the DOWNLOAD_URL line does NOT contain
github.com
BuildScript_NoEnvOverride_RenderedDownloadUrlDefaultsToGitHub
Counterpart pin: when env var is unset, rendered DOWNLOAD_URL defaults to public github.com release path. Without this dual pin, the override test alone could pass while the default path silently broke (e.g. someone hardcoded the operator mirror as the new default, breaking non-air-gap deployments).
Why unit-level, not E2E
BuildScript hardcodes INSTALL_DIR / SERVICE_NAME from Default* fields, conflicting with our test fixtures' GUID-suffixed paths. The existing LinuxLifecycleContext.RenderProductionScriptForVersion does manual substitution as a workaround — which is precisely what bypasses the env-var path. So the env-var → BuildScript chain is best pinned at the unit/integration tier.
Tier:
Test plan
-
CI passes (no E2E workflow trigger needed — unit-only change) -
Local: 86/86 LinuxTentacleUpgradeStrategy tests pass