feat(LinuxTentacleE2E): Phase 12.M.L.A.4 — install-tentacle.sh idempotent re-run E2E
Summary
Pins the .sh's idempotency contract: re-running install-tentacle.sh on already-installed state MUST succeed silently.
Why critical
Re-runs are a critical operator workflow in two real-world scenarios:
| Scenario | Frequency |
|---|---|
| Fleet automation (cloud-init / Ansible / Salt re-invokes installer on every boot for self-healing) | High — every boot, every machine |
| Operator manual re-run (refresh, post-failure repair, version verification) | Medium |
Without this pin, regressions in idempotency ship silently:
- Future polish adds
"already installed, error"check → fleet automation breaks on every machine after the first boot -
tar xzffails with EEXIST on a non-empty INSTALL_DIR → re-runs to repair partial installs become impossible -
ln -sfregression to plainln→ second run fails on existing symlink target -
mkdir -pregression → second run errors on existing/etc/squid-tentacle -
install_runtime_deps'sldconfigshort-circuit removed →apt-get updateruns on every re-invocation (not broken, but slows fleet boots significantly)
The .sh's design IS idempotent today
Per code inspection:
-
mkdir -p(idempotent) -
tar xzf(overwrites existing files) -
chmod +x(overwrites) -
ln -sf(overwrites symlink) -
install_runtime_deps(ldconfig pre-check short-circuits) -
install -m 0755 -d /etc/apt/keyrings(idempotent)
This test PINS the contract end-to-end so any future change that accidentally breaks an idempotency invariant fires CI immediately.
Test mechanism
Stage tarball, run install twice in succession with NO cleanup between runs, assert both succeed + final state matches single-install + no spurious "already installed" errors.
Assertions
| Assertion | Pins |
|---|---|
| Run 1 exit 0 + verification log | Sanity baseline |
| Run 2 exit 0 | The idempotency assertion |
Run 2 logs "Verified: squid-tentacle executable"
|
Binary still runnable after re-extract |
Run 2 stdout does NOT contain "already installed"
|
No regression to error-on-existing-state |
Run 2 stdout does NOT contain "Error: install dir not empty"
|
No regression to fail-if-not-empty |
| Final binary + symlinks + dirs | Match single-install state |
Fidelity tier
.sh + real bash + real curl + real LocalReleaseMirror + real sudo orchestration. No mocks.
Test class is in LinuxTentacleHostStateCollection (serializes against upgrade + service-fixture tests on shared host state).
Expected runtime: ~2× single-install (~1-2s on warm cache).
Test plan
-
Linux E2E workflow runs (manual workflow_dispatchafter merge) -
A8h_RerunInstaller_IdempotentlySucceedspasses within ~5s -
No regression on existing 23 Linux E2E tests