Skip to content

Pin service uninstall --purge contract boundary (B6h preserves, B7h removes)

Summary

  • B6h — service uninstall (no --purge) preserves config + cert dir. Pins the historical default that lets operators re-install over the existing identity without losing their cert thumbprint (and breaking the server-side trust list).
  • B7h — service uninstall --purge removes config file + instance dir (containing certs) + instance-registry entry. Pins all three operator-tailed log lines ("Removed config file:", "Removed instance directory:", "Removed 'Default' from instance registry") and reverse-asserts no warnings on the happy path.
  • Both tests reuse the existing FullWorkflowTestContext (register against LinuxStubSquidServer + service install) so they exercise the real filesystem state PurgeInstanceArtefacts has to walk through (/etc/squid-tentacle/instances/Default.config.json + /etc/squid-tentacle/instances/Default/).
  • New LinuxInstallScriptContext.SudoDirectoryExists helper for the same permission-boundary reason SudoFileExists already exists — Directory.Exists returns false-negatives under root-owned 0750 dirs.

Test plan

  • dotnet build green (0 errors, only pre-existing nullable/SYSLIB warnings)
  • CI tentacle-linux-e2e workflow passes B6h_FullWorkflow_ServiceUninstall_PreservesConfigAndCerts and B7h_FullWorkflow_ServiceUninstallPurge_RemovesConfigAndCertsAndRegistry
  • B6h asserts: service unit gone + config file STILL present + instance dir STILL present + stdout did NOT log purge-only messages
  • B7h asserts: service unit gone + config file gone + instance dir gone + stdout logged all three purge messages + no warnings
  • Existing 38 Linux E2E tests still pass (no regression)

🤖 Generated with Claude Code

Merge request reports

Loading