Repository navigation
chore: remove the appliance code that moved to cryptos-appliance - #350
Conversation
The image build (build/), the QEMU suites (test/image, test/integration), the image CI workflows (ci-image.yml, ci-e2e-image.yml), cryptos-switchroot, cryptos-sbkey, and the Secure Boot and image upgrade docs moved to CryptOS-PKI/cryptos-appliance, which pins this module and builds init, cryptosctl and the console by import path. task build's BUILDINFO var shelled out to build/ci/buildinfo.sh, which moved with build/. Relocate it to scripts/buildinfo.sh (unchanged apart from its root-relative path) so `task build` keeps stamping the binaries that stay here; cryptos-appliance carries its own copy for the image it builds. Removes 22 Go tests that now live in cryptos-appliance: - internal/switchroot: TestRun_Sequence, TestRun_LoopFailureStopsBeforePivot, TestRun_SquashFSMountFailure, TestRun_ExistingDirsAreOK - cmd/cryptos-sbkey: TestRun_WritesAllOutputs, TestRun_RefusesOverwrite, TestRun_InvalidCN, TestRun_KeyBits - internal/secureboot: TestGenerate_KeyAndEncodings, TestGenerate_CertProperties, TestGenerate_SelfSigned, TestGenerate_DefaultValidity, TestGenerate_UniqueSerials, TestGenerate_Validation, TestGenerate_KeyBits - test/integration: TestImageSuite, TestPhase1CeremonyEndToEnd, TestConfigPersistsAcrossReboot, TestFirstBootFromESPStage, TestNodeIDNoTPMBootAndCeremony, TestResetWipesAndReprovisions, TestParseSectorSize Closes #349 Signed-off-by: Bugs5382 <12115015+Bugs5382@users.noreply.github.com>
|
Removed |
What and why
The OS layer moved to CryptOS-PKI/cryptos-appliance (cryptos-appliance#1, ported in
cryptos-appliance#8-#11 from cryptos-node@442b136). The image built there matches this
repo's build of the same commit, and its QEMU suite passes. This PR removes the moved
parts from cryptos-node:
build/(kernel, cryptsetup, e2fsprogs, gptfdisk, dosfstools, squashfs, uki, iso, ci)test/image/,test/integration/cmd/cryptos-switchroot+internal/switchrootcmd/cryptos-sbkey+internal/secureboot.github/workflows/ci-image.yml,.github/workflows/ci-e2e-image.ymldocs/secure-boot.md,docs/image-upgrade.mdkernel:buildthroughqemu:run,iso*,image*,uki:*,rootfs:build,e2e:image,test:integration)cmd/init,cmd/cryptos-install,cmd/cryptos-console,cryptosctland the engine stayhere; cryptos-appliance builds them by import path.
task build'sBUILDINFOvar shelled out tobuild/ci/buildinfo.sh, which moves withbuild/. Relocated it toscripts/buildinfo.sh(unchanged apart from its root-relativepath) so
task buildkeeps stamping the binaries that stay in this repo; cryptos-appliancecarries its own copy for the image it builds.
README now points at cryptos-appliance for the boot image, Secure Boot and the QEMU suites.
.gitignoredrops the stray-binary and build-artifact entries for the removed pieces.ci-go.ymldrops its now-deadbuild/**paths-ignore entry. A handful of comments infiles that stay (
cmd/cryptosctl/image.go,image_test.go,internal/init/resolv.go,internal/release/release.go,cmd/init/coverflush_e2ecover_linux.go) now namecryptos-appliance instead of a local
build//test/imagepath that no longer exists here.Removed tests (now in cryptos-appliance)
internal/switchroot:TestRun_Sequence,TestRun_LoopFailureStopsBeforePivot,TestRun_SquashFSMountFailure,TestRun_ExistingDirsAreOKcmd/cryptos-sbkey:TestRun_WritesAllOutputs,TestRun_RefusesOverwrite,TestRun_InvalidCN,TestRun_KeyBitsinternal/secureboot:TestGenerate_KeyAndEncodings,TestGenerate_CertProperties,TestGenerate_SelfSigned,TestGenerate_DefaultValidity,TestGenerate_UniqueSerials,TestGenerate_Validation,TestGenerate_KeyBitstest/integration:TestImageSuite,TestPhase1CeremonyEndToEnd,TestConfigPersistsAcrossReboot,TestFirstBootFromESPStage,TestNodeIDNoTPMBootAndCeremony,TestResetWipesAndReprovisions,TestParseSectorSizeci-image.ymlalso built and attachedcryptosctl-*binaries andSHA256SUMSto thisrepo's tagged GitHub Releases, alongside the image assets. cryptos-appliance's ported copy
of that workflow (CryptOS-PKI/cryptos-appliance#10) still builds
cryptosctlfromcryptos-nodeby import path and publishes it the same way, so the release-asset set isunchanged at the system level; it now ships under cryptos-appliance's tags instead of
cryptos-node's.
Merge order: this PR, then the website and cryptos-release companion PRs (Refs
#349).
Closes #349
Verification
How this was verified
task fmt,task proto:lint,task generate:verify,task lint(golangci-lint, 0 issues),task vet,go test ./...under the memory-cappedsystemd-run/flockwrapper (allpackages pass),
task build(producesbin/init,bin/cryptosctl,bin/cryptos-install),task license(0/398 changed),actionlint -shellcheck=on the changed workflows.Before merging: add a closing comment summarizing what was actually done in this PR
(not just the checked boxes).