feat: dist upgrade --latest downloads and verifies the release from the feed, --expect pins the version (#161)
CI / verify (push) Successful in 1m42s
Release / release (push) Successful in 38s

Files changed:
- CHANGES.md
- INSTALL.md
- VERSION
- instructions/upgrade-instance.md
- tools/CONTRACT.md
- tools/chemenu/commands/dist_cmd.py
- tools/chemenu/commands/version_cmd.py
- tools/chemenu/tests/test_cli.py
- tools/chemenu/tests/test_dist_upgrade.py
- tools/chemenu/version.py
This commit is contained in:
torben committed 2026-09-29 22:08:00 +02:00
1 parent dd885db625
commit cf892315e6
10 files changed
+888 -62

No files matched your search

+17 -6
View File
@@ -81,14 +81,25 @@ fresh clone ([bootstrap.md](bootstrap.md)), and not for the clone-with-upstream
step 12's, run against the migration documents this instance already has. An `offered` upgrade
listed separately blocks nothing and is decided later, in step 12.
4. **Fetch the tarball and verify it.** `dist upgrade` downloads nothing; the file has to be
there already. Take the `.tar.gz` and its `.sha256` from the release page found in step 2 and
check them before unpacking. A tarball must unpack to exactly one top-level directory.
4. **Nothing to fetch by hand.** `dist upgrade --latest` asks the release feed for the latest
release, downloads its `.tar.gz` and `.sha256` into a scratch directory, checks the archive
against the checksum and removes both again - all inside the calls of steps 5 to 7. Note the
version step 2's `version notes` printed: steps 5 to 7 pass it as `--expect`, so a release that
appeared in the meantime is refused before anything is downloaded, rather than applied unread.
The offline alternative is the tarball path: with the feed unreachable, or an archive the
operator supplies, take the `.tar.gz` and its `.sha256` from the release page named in step 2,
check the archive against the checksum before unpacking, and pass the file as `<tarball>`
where the steps below say `--latest --expect <version>`. A tarball must unpack to exactly one
top-level directory. The checksum comes from the same host as the archive, so it catches a
damaged transfer, not a compromised host - who is trusted to publish releases is the
operator's decision, made before this file starts ([INSTALL.md](../INSTALL.md) § "Version und
Updates").
5. **Dry-run the swap and read all four counts:**
```bash
tools/wikitool dist upgrade <tarball> --dry-run
tools/wikitool dist upgrade --latest --expect <version from step 2> --dry-run
```
`unchanged` / `new` / `locally changed` / `removed from the release`. `unchanged` needs no
@@ -115,7 +126,7 @@ fresh clone ([bootstrap.md](bootstrap.md)), and not for the clone-with-upstream
file reset and another kept. Preview it before it writes:
```bash
tools/wikitool dist upgrade <tarball> --dry-run --take-release <path> [--take-release <path>]
tools/wikitool dist upgrade --latest --expect <version from step 2> --dry-run --take-release <path> [--take-release <path>]
```
The preview marks every named path as one it would overwrite from the release, and a path that
@@ -134,7 +145,7 @@ fresh clone ([bootstrap.md](bootstrap.md)), and not for the clone-with-upstream
```bash
git rev-parse --short HEAD # the pre-swap commit; keep it
tools/wikitool dist upgrade <tarball> [--take-release <path>] [--keep-local]
tools/wikitool dist upgrade --latest --expect <version from step 2> [--take-release <path>] [--keep-local]
```
It writes, and commits nothing.