Skip to content

fix: fail-closed rollback verification with apply→compare tests - #13

Merged
MarcinDudekDev merged 4 commits into
mainfrom
feat/rollback-verification
Sep 13, 2026
Merged

MarcinDudekDev merged 4 commits into
mainfrom
feat/rollback-verification

Conversation

@MarcinDudekDev

Copy link
Copy Markdown
Owner

Fixes #12

Rollback verification is now fail-closed.

  • verify_restored_files returns non-zero on missing dest files, checksum mismatch, or failed nginx -t (skipped if nginx is not on PATH).
  • restore_backup no longer prints success / exits 0 when verification failed.
  • Empty dir_pairs no longer crashes bash 3.2 + set -u.

Tests: fake HOME + stub nginx (does not touch /etc/nginx or real ~/.wp-test). Assertions fail on main. 116/116. shellcheck --severity=warning clean.

MarcinDudekDev and others added 4 commits September 13, 2026 20:44
verify_restored_files warned on drift but always returned 0, and
restore_backup printed success regardless. New section drives both
functions against fixtures under a fake HOME with a stub nginx, so
nothing touches /etc/nginx or the real ~/.wp-test: checksum stability,
match/mismatch/missing dest, failing and absent nginx -t, plus two
end-to-end restore_backup runs (drift repaired; no-op restore.sh must
not report success).

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
verify_restored_files counted missing/mismatched files but always
returned 0, and a failed nginx -t only logged an error, so
restore_backup printed "Backup restored successfully!" after a bad
restore. Now a missing dest dir, a checksum mismatch, or a failing
nginx -t (when nginx is on PATH) all make the verifier return 1, and
restore_backup propagates that instead of claiming success. The empty
dir_pairs case is also guarded so bash 3.2 + set -u cannot crash on
"${dir_pairs[@]}" expansion.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
The "nginx -t skipped when nginx is absent" assertion used PATH
/usr/bin:/bin:/sbin:/usr/sbin. GitHub ubuntu-latest can have nginx in
/usr/sbin, so the verifier ran a real nginx -t and failed closed.
Build a fixture bin dir with find/hash tools only.
@MarcinDudekDev
MarcinDudekDev force-pushed the feat/rollback-verification branch from 0d9fd5c to 0813247 Compare September 13, 2026 18:45
@MarcinDudekDev
MarcinDudekDev merged commit 58c12cf into main Sep 13, 2026
4 checks passed
@MarcinDudekDev
MarcinDudekDev deleted the feat/rollback-verification branch September 13, 2026 18:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Rollback verification must fail closed (apply → rollback → compare tests)

1 participant