Skip to content

feat(LinuxTentacleE2E): Phase 12.L.E.15 — exit-3 missing-binary-in-archive guard

Summary

Pins the .sh's Phase A line 458 existence check: after extracting the downloaded tarball, if Squid.Tentacle binary is absent, exit 3 + FAILED status with operator-actionable detail.

Production scenarios protected

  • Release pipeline regression: tarball published with .sh and version.txt but missing the compiled binary (e.g. dotnet publish failed silently and only static files got tar'd).
  • Mirror corruption: tarball decompresses to fewer entries than expected (transport truncation mid-stream, but enough header read to extract leading entries).

Why SHA verify alone doesn't cover this

If the build pipeline computed the SHA over a NEW broken tarball, both SHA and contents are self-consistently wrong. The line-458 existence check is the last-line-of-defence diagnostic.

What a regression looks like

Without this pin, a regression that drops the existence check (someone refactors Phase A and removes the guard thinking it's redundant with SHA verify) ships silently. Operators would see a confusing "command not found: $INSTALL_DIR/Squid.Tentacle" mid-Phase-B instead of the early exit + clear "Missing binary after extraction" diagnostic.

Test mechanism

BuildV2BundleTarGz(targetVersion, omitSquidTentacleBinary: true) produces a tarball with version.txt + test service script BUT no Squid.Tentacle entry. Phase A's extract succeeds; line 458's [ -f $NEW_BIN ] check fails; exit 3 fires.

Assertions

  • exitCode == 3 (per .sh line 458)
  • last-upgrade.json.Status == "FAILED"
  • last-upgrade.json.Detail contains "Missing binary after extraction"
  • stdout contains "Extracted archive missing Squid.Tentacle binary" (operators tailing journalctl)
  • Marker stays at "1.0.0" (Phase B never ran — exit 3 is pre-swap)
  • .bak directory does NOT exist (mv-swap never executed)

Infrastructure additions

BuildV2BundleTarGz: omitSquidTentacleBinary parameter (default false, backward-compatible).

Fidelity tier

🟢 High (Rule 12.4): real prod .sh + real tar+gzip + real [ -f ... ] bash test against the extracted file tree.

Expected runtime: ~3-5s (Phase A download + extract + binary check; exits before Phase B).

Test plan

  • Linux E2E workflow runs (manual workflow_dispatch after merge)
  • E1uMissingBinary_TarballMissingSquidTentacle_ExitsThreeWithFailedStatus passes within ~5s
  • No regression on existing 15 Linux E2E tests

🤖 Generated with Claude Code

Merge request reports

Loading