[REM] qemu : abandonner Debian 11
Son LTS est terminé, et sa suite de sécurité n'est ni servie ni archivée : security.debian.org publie encore un index qui nomme des paquets dont le pool ne porte plus le fichier, et archive.debian.org ne connaît pas bullseye. apt s'arrête donc avant d'installer git, sur une version qui ne recevra plus rien. Elle quitte le catalogue de déploiement et le script de dépendances, où la variable qui la distinguait n'a plus d'usage. Debian 12 et 13 restent, et l'image de la 13 est toujours le dernier point de version — sans rien à changer ici quand le suivant paraît. Vérifié : plus aucune trace de bullseye dans script/, hors la base des conteneurs, traitée à part. --- EN --- Its LTS has ended, and its security suite is neither served nor archived: security.debian.org still publishes an index naming packages whose pool no longer holds the file, and archive.debian.org does not know bullseye. apt therefore stops before installing git, on a version that will receive nothing more. It leaves the deployment catalogue and the dependency script, where the variable telling it apart has no use left. Debian 12 and 13 stay, and 13's image is always the latest point release — with nothing to change here when the next one appears. Checked: no trace of bullseye left in script/, beyond the container base, handled separately. Assisted-by: Claude Opus 5
This commit is contained in:
parent
1342117e25
commit
e39221af01
7 changed files with 32 additions and 42 deletions
|
|
@ -160,6 +160,7 @@ au [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
|||
- `.venv.erplibre` on an incompatible Python is DELETED and rebuilt; whatever was installed in it by hand goes with it. Odoo's venv is kept when it merely differs in version, and rebuilt only when it is unusable: rebuilding it redoes a whole Poetry install. A directory without `pyvenv.cfg` is never deleted
|
||||
- `make` and `make todo` go through `install.sh`, which picks an interpreter able to READ the code before running it: `.venv.erplibre` on the right version, else a recent enough system `python3`, else the install. A system older than `conf/python-erplibre-version` would otherwise stop on a syntax error raised before any guard could name the command to type. TODO then relaunches itself in `.venv.erplibre`, or offers to run `install_erplibre.sh` in a terminal
|
||||
- The production Docker image builds `.venv.erplibre` on Odoo's Python and stops when that Python cannot parse `script/`
|
||||
- Debian 11 is dropped from the deployment catalogue: its LTS ended, and its security suite is neither served nor archived — the index it still publishes names packages whose pool no longer holds the file, so apt stops before installing git. Debian 13 takes its place, its cloud image always being the latest point release
|
||||
- The PATCH bounds only Odoo's venv, whose pyproject requires `>=3.12.10,<3.13`. For the tooling one, the major.minor is enough: requiring the patch turned away a distribution's Python one step behind — NixOS 25.11 ships 3.14.2 where conf asks 3.14.7 — and made pyenv COMPILE CPython for a difference nothing needs
|
||||
- `make format` picks the formatter from each file's context: an Odoo module keeps isort and black on `py37`, the series still supported going down that far, while this repository's own tooling goes through ruff, configured once in `.ruff.toml`. ruff follows CPython's versions, where black 24.8.0 stops at `py313`, and its import sorting replaces isort; it is also what the OCA standard uses since it left black
|
||||
- The repositories that Google Repo checks out under `script/` are excluded from that formatting, a named path included: reformatting them would write in someone else's history. `target-version` stays at `py310` there, because the git hooks carry `#!/usr/bin/env python3` and a distribution still ships 3.10 — from 3.14 on, ruff would write `except A, B:` without parentheses
|
||||
|
|
@ -183,6 +184,7 @@ au [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
|||
- `.venv.erplibre` sur un Python incompatible est SUPPRIMÉ puis rebâti ; ce qu'on y avait posé à la main part avec lui. Le venv d'Odoo est conservé quand seule sa version diffère, et rebâti seulement s'il est hors service : le rebâtir refait une installation Poetry entière. Un répertoire sans `pyvenv.cfg` n'est jamais effacé
|
||||
- `make` et `make todo` passent par `install.sh`, qui choisit un interpréteur capable de LIRE le code avant de le lancer : `.venv.erplibre` s'il porte la bonne version, sinon le `python3` du système s'il est assez récent, sinon l'installation. Un système plus ancien que `conf/python-erplibre-version` s'arrêterait autrement sur une erreur de syntaxe levée avant qu'aucun garde puisse nommer la commande à taper. TODO se relance ensuite dans `.venv.erplibre`, ou propose de lancer `install_erplibre.sh` en terminal
|
||||
- L'image Docker de production bâtit `.venv.erplibre` sur le Python d'Odoo et s'arrête quand ce Python ne sait pas lire `script/`
|
||||
- Debian 11 quitte le catalogue de déploiement : son LTS est terminé, et sa suite de sécurité n'est ni servie ni archivée — l'index qu'elle publie encore nomme des paquets dont le pool ne porte plus le fichier, et apt s'arrête avant d'installer git. Debian 13 la remplace, son image cloud étant toujours le dernier point de version
|
||||
- Le PATCH ne borne que le venv d'Odoo, dont le pyproject exige `>=3.12.10,<3.13`. Pour celui de l'outillage, la majeure.mineure suffit : exiger le patch écartait le Python d'une distribution d'un cran en retard — NixOS 25.11 livre 3.14.2 quand conf demande 3.14.7 — et faisait COMPILER CPython à pyenv pour une différence que rien ne réclame
|
||||
- `make format` choisit le formateur d'après le contexte de chaque fichier : un module Odoo garde isort et black en `py37`, la série la plus ancienne encore supportée, quand l'outillage de ce dépôt passe par ruff, réglé une fois dans `.ruff.toml`. ruff suit les versions de CPython, là où black 24.8.0 s'arrête à `py313`, et son tri d'imports remplace isort ; c'est aussi ce qu'emploie la norme OCA depuis qu'elle a quitté black
|
||||
- Les dépôts que Google Repo rapatrie sous `script/` sont écartés de ce formatage, chemin nommé compris : les reformater écrirait dans l'historique d'autrui. `target-version` y reste à `py310`, parce que les hooks git portent `#!/usr/bin/env python3` et qu'une distribution livre encore 3.10 — à partir de 3.14, ruff écrirait `except A, B:` sans parenthèses
|
||||
|
|
|
|||
|
|
@ -82,6 +82,7 @@ au [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
|||
- `.venv.erplibre` sur un Python incompatible est SUPPRIMÉ puis rebâti ; ce qu'on y avait posé à la main part avec lui. Le venv d'Odoo est conservé quand seule sa version diffère, et rebâti seulement s'il est hors service : le rebâtir refait une installation Poetry entière. Un répertoire sans `pyvenv.cfg` n'est jamais effacé
|
||||
- `make` et `make todo` passent par `install.sh`, qui choisit un interpréteur capable de LIRE le code avant de le lancer : `.venv.erplibre` s'il porte la bonne version, sinon le `python3` du système s'il est assez récent, sinon l'installation. Un système plus ancien que `conf/python-erplibre-version` s'arrêterait autrement sur une erreur de syntaxe levée avant qu'aucun garde puisse nommer la commande à taper. TODO se relance ensuite dans `.venv.erplibre`, ou propose de lancer `install_erplibre.sh` en terminal
|
||||
- L'image Docker de production bâtit `.venv.erplibre` sur le Python d'Odoo et s'arrête quand ce Python ne sait pas lire `script/`
|
||||
- Debian 11 quitte le catalogue de déploiement : son LTS est terminé, et sa suite de sécurité n'est ni servie ni archivée — l'index qu'elle publie encore nomme des paquets dont le pool ne porte plus le fichier, et apt s'arrête avant d'installer git. Debian 13 la remplace, son image cloud étant toujours le dernier point de version
|
||||
- Le PATCH ne borne que le venv d'Odoo, dont le pyproject exige `>=3.12.10,<3.13`. Pour celui de l'outillage, la majeure.mineure suffit : exiger le patch écartait le Python d'une distribution d'un cran en retard — NixOS 25.11 livre 3.14.2 quand conf demande 3.14.7 — et faisait COMPILER CPython à pyenv pour une différence que rien ne réclame
|
||||
- `make format` choisit le formateur d'après le contexte de chaque fichier : un module Odoo garde isort et black en `py37`, la série la plus ancienne encore supportée, quand l'outillage de ce dépôt passe par ruff, réglé une fois dans `.ruff.toml`. ruff suit les versions de CPython, là où black 24.8.0 s'arrête à `py313`, et son tri d'imports remplace isort ; c'est aussi ce qu'emploie la norme OCA depuis qu'elle a quitté black
|
||||
- Les dépôts que Google Repo rapatrie sous `script/` sont écartés de ce formatage, chemin nommé compris : les reformater écrirait dans l'historique d'autrui. `target-version` y reste à `py310`, parce que les hooks git portent `#!/usr/bin/env python3` et qu'une distribution livre encore 3.10 — à partir de 3.14, ruff écrirait `except A, B:` sans parenthèses
|
||||
|
|
|
|||
|
|
@ -82,6 +82,7 @@ to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
|||
- `.venv.erplibre` on an incompatible Python is DELETED and rebuilt; whatever was installed in it by hand goes with it. Odoo's venv is kept when it merely differs in version, and rebuilt only when it is unusable: rebuilding it redoes a whole Poetry install. A directory without `pyvenv.cfg` is never deleted
|
||||
- `make` and `make todo` go through `install.sh`, which picks an interpreter able to READ the code before running it: `.venv.erplibre` on the right version, else a recent enough system `python3`, else the install. A system older than `conf/python-erplibre-version` would otherwise stop on a syntax error raised before any guard could name the command to type. TODO then relaunches itself in `.venv.erplibre`, or offers to run `install_erplibre.sh` in a terminal
|
||||
- The production Docker image builds `.venv.erplibre` on Odoo's Python and stops when that Python cannot parse `script/`
|
||||
- Debian 11 is dropped from the deployment catalogue: its LTS ended, and its security suite is neither served nor archived — the index it still publishes names packages whose pool no longer holds the file, so apt stops before installing git. Debian 13 takes its place, its cloud image always being the latest point release
|
||||
- The PATCH bounds only Odoo's venv, whose pyproject requires `>=3.12.10,<3.13`. For the tooling one, the major.minor is enough: requiring the patch turned away a distribution's Python one step behind — NixOS 25.11 ships 3.14.2 where conf asks 3.14.7 — and made pyenv COMPILE CPython for a difference nothing needs
|
||||
- `make format` picks the formatter from each file's context: an Odoo module keeps isort and black on `py37`, the series still supported going down that far, while this repository's own tooling goes through ruff, configured once in `.ruff.toml`. ruff follows CPython's versions, where black 24.8.0 stops at `py313`, and its import sorting replaces isort; it is also what the OCA standard uses since it left black
|
||||
- The repositories that Google Repo checks out under `script/` are excluded from that formatting, a named path included: reformatting them would write in someone else's history. `target-version` stays at `py310` there, because the git hooks carry `#!/usr/bin/env python3` and a distribution still ships 3.10 — from 3.14 on, ruff would write `except A, B:` without parentheses
|
||||
|
|
|
|||
|
|
@ -33,14 +33,12 @@ if [[ -r /etc/os-release ]]; then
|
|||
# Sous-shell : « source » importerait NAME, PRETTY_NAME et le reste dans
|
||||
# un script qui n'en veut pas.
|
||||
UBUNTU_VERSION=$(. /etc/os-release && echo "${VERSION_ID}")
|
||||
DEBIAN_VERSION=$(. /etc/os-release && echo "${VERSION_CODENAME}")
|
||||
OS=$(. /etc/os-release && echo "${ID}")
|
||||
# lsb_release rend « Ubuntu » et « Debian » ; os-release rend « ubuntu » et
|
||||
# « debian ». Les comparaisons plus bas attendent la première forme.
|
||||
OS="${OS^}"
|
||||
else
|
||||
UBUNTU_VERSION=$(lsb_release -rs)
|
||||
DEBIAN_VERSION=$(lsb_release -cs)
|
||||
OS=$(lsb_release -si)
|
||||
fi
|
||||
|
||||
|
|
@ -73,15 +71,9 @@ elif [[ "${OS}" == "Linuxmint" ]]; then
|
|||
# gdebi etait appele sans fichier. Mint 22.x repose sur noble : meme .deb.
|
||||
WKHTMLTOX_X64=https://github.com/wkhtmltopdf/packaging/releases/download/0.12.6.1-3/wkhtmltox_0.12.6.1-3.jammy_amd64.deb
|
||||
elif [[ "${OS}" == "Debian" ]]; then
|
||||
if [ "bullseye" == "${DEBIAN_VERSION}" ]; then
|
||||
WKHTMLTOX_X64=https://github.com/wkhtmltopdf/packaging/releases/download/0.12.6.1-3/wkhtmltox_0.12.6.1-3.bullseye_amd64.deb
|
||||
else
|
||||
# bookworm (12), trixie (13) et au-delà : wkhtmltopdf ne publie pas de
|
||||
# build au-delà de « bookworm » -> on prend bookworm (le plus récent).
|
||||
# Le build « bullseye » (Debian 11) échouait à s'installer sur trixie
|
||||
# (gdebi : dépendances incompatibles).
|
||||
WKHTMLTOX_X64=https://github.com/wkhtmltopdf/packaging/releases/download/0.12.6.1-3/wkhtmltox_0.12.6.1-3.bookworm_amd64.deb
|
||||
fi
|
||||
# bookworm (12), trixie (13) et au-delà : wkhtmltopdf ne publie pas de build
|
||||
# au-delà de « bookworm » -> on prend bookworm, le plus récent.
|
||||
WKHTMLTOX_X64=https://github.com/wkhtmltopdf/packaging/releases/download/0.12.6.1-3/wkhtmltox_0.12.6.1-3.bookworm_amd64.deb
|
||||
elif [[ "${OS}" == *"Ubuntu"* ]]; then
|
||||
echo "Your version of Ubuntu is not supported, only support 24.04, 25.10 and 26.04"
|
||||
WKHTMLTOX_X64=https://github.com/wkhtmltopdf/packaging/releases/download/0.12.6.1-3/wkhtmltox_0.12.6.1-3.jammy_amd64.deb
|
||||
|
|
|
|||
|
|
@ -43,6 +43,7 @@ Exemples
|
|||
|
||||
sudo ./script/qemu/deploy_qemu.py /var/lib/libvirt/images/iso/noble.img --name test-vm --memory 8192 --vcpus 8 --disk-size 120G --ask-password --force
|
||||
"""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
|
|
@ -100,7 +101,6 @@ UBUNTU_VERSIONS: dict[str, tuple[str, str, int, str]] = {
|
|||
"26.04": ("resolute", "ubuntu26.04", 3072, "20G"),
|
||||
}
|
||||
DEBIAN_VERSIONS: dict[str, tuple[str, str, int, str]] = {
|
||||
"11": ("bullseye", "debian11", 1024, "20G"),
|
||||
"12": ("bookworm", "debian12", 1024, "20G"),
|
||||
"13": ("trixie", "debian13", 1024, "20G"),
|
||||
}
|
||||
|
|
@ -238,8 +238,7 @@ S390X_DISTROS: tuple[str, ...] = (
|
|||
# miroirs tiers. Seule la 43 est servie par dl.fedoraproject.org — vérifié.
|
||||
ARCH_ONLY_VERSIONS: dict[str, dict[str, tuple[str, ...]]] = {
|
||||
# Debian sur s390x passe par debian-installer, dont les images sont
|
||||
# publiées pour bookworm et trixie — vérifié. bullseye est écartée : elle
|
||||
# est en fin de vie et son installateur n'a pas été éprouvé ici.
|
||||
# publiées pour bookworm et trixie — vérifié.
|
||||
"s390x": {"fedora": ("43",), "debian": ("12", "13")},
|
||||
}
|
||||
|
||||
|
|
@ -596,9 +595,7 @@ def resolve_fedora_url(version: str, arch: str, dry_run: bool) -> str:
|
|||
for base in bases:
|
||||
index = f"{base}/{version}/Cloud/{a}/images/"
|
||||
try:
|
||||
with urllib.request.urlopen(
|
||||
index, timeout=30
|
||||
) as resp: # noqa: S310
|
||||
with urllib.request.urlopen(index, timeout=30) as resp: # noqa: S310
|
||||
html = resp.read().decode(errors="replace")
|
||||
except Exception as exc: # pragma: no cover - dépend du réseau
|
||||
last_err = str(exc)
|
||||
|
|
@ -1128,8 +1125,7 @@ def ensure_libvirt_service(runner: Runner) -> None:
|
|||
return
|
||||
if shutil.which("systemctl"):
|
||||
print(
|
||||
" Démarrage du démon libvirt"
|
||||
" (systemctl enable --now libvirtd)…"
|
||||
" Démarrage du démon libvirt (systemctl enable --now libvirtd)…"
|
||||
)
|
||||
runner.run(
|
||||
["systemctl", "enable", "--now", "libvirtd"],
|
||||
|
|
@ -1547,16 +1543,26 @@ class TelechargementTronque(OSError):
|
|||
|
||||
def _download_one(url: str, tmp: Path, timeout: int, depuis: int = 0) -> None:
|
||||
"""Télécharge url -> tmp en streaming, avec timeout et barre de %.
|
||||
Lève une exception en cas d'échec réseau (miroir suivant à essayer)."""
|
||||
|
||||
`depuis` reprend un .part laissé par une coupure. Lève une exception en
|
||||
cas d'échec réseau (miroir suivant à essayer)."""
|
||||
is_tty = sys.stdout.isatty()
|
||||
last_pct = -1
|
||||
req = urllib.request.Request(
|
||||
url, headers={"User-Agent": "erplibre-qemu-deploy"}
|
||||
)
|
||||
entetes = {"User-Agent": "erplibre-qemu-deploy"}
|
||||
if depuis > 0:
|
||||
entetes["Range"] = f"bytes={depuis}-"
|
||||
req = urllib.request.Request(url, headers=entetes)
|
||||
with urllib.request.urlopen(req, timeout=timeout) as resp: # noqa: S310
|
||||
# Un serveur qui IGNORE le Range rend 200 et le fichier ENTIER : on
|
||||
# repart alors de zéro, sans quoi les octets déjà là seraient doublés
|
||||
# et l'image illisible.
|
||||
reprise = depuis > 0 and getattr(resp, "status", 200) == 206
|
||||
done = depuis if reprise else 0
|
||||
total = int(resp.headers.get("Content-Length", 0) or 0)
|
||||
done = 0
|
||||
with open(tmp, "wb") as fh:
|
||||
if total > 0:
|
||||
# En reprise, l'en-tête ne compte que ce qui RESTE.
|
||||
total += done
|
||||
with open(tmp, "ab" if reprise else "wb") as fh:
|
||||
while True:
|
||||
chunk = resp.read(1 << 16)
|
||||
if not chunk:
|
||||
|
|
|
|||
|
|
@ -160,7 +160,8 @@ class QemuDeployMixin:
|
|||
chain.append(f"{{ {after_cmd} }}")
|
||||
install_chain = " && ".join(chain)
|
||||
return (
|
||||
"set -e; " + self._qemu_cloud_init_wait()
|
||||
"set -e; "
|
||||
+ self._qemu_cloud_init_wait()
|
||||
# Coupé AVANT les apt-get ci-dessous : sinon apt-daily peut reprendre
|
||||
# le verrou entre l'attente cloud-init et l'installation.
|
||||
+ no_auto_upgrade
|
||||
|
|
@ -187,17 +188,6 @@ class QemuDeployMixin:
|
|||
# retarderait le démarrage sans laisser de trace dans le suivi.
|
||||
f"PKGS='curl git make{self._qemu_editor_suffix()}'; "
|
||||
"if command -v apt-get >/dev/null 2>&1; then "
|
||||
# Au 1er boot, cloud-init (install qemu-guest-agent) et/ou
|
||||
# apt-daily.service tiennent le verrou apt. IMPORTANT :
|
||||
# « DPkg::Lock::Timeout » NE couvre PAS le verrou
|
||||
# /var/lib/apt/lists/lock -> « apt-get update » échouait AUSSITÔT
|
||||
# (« Could not get lock … lists/lock ») -> lists vides -> « Unable
|
||||
# to locate package git ». On RÉESSAIE donc update jusqu'à ce que
|
||||
# le verrou se libère (et les lists soient peuplées), borné à ~5 min.
|
||||
# Bornée par le TEMPS : trente essais valent cinq minutes quand
|
||||
# chacun échoue en une seconde sur un verrou, mais des heures
|
||||
# quand le cache répond 504 sur chaque index et qu'un essai dure
|
||||
# des minutes.
|
||||
"fin=$(( $(date +%s) + 300 )); "
|
||||
"until sudo apt-get -o DPkg::Lock::Timeout=120 update -qq; do "
|
||||
'[ "$(date +%s)" -ge "$fin" ] && break; '
|
||||
|
|
@ -276,7 +266,7 @@ class QemuDeployMixin:
|
|||
# peu : l'installation choisit ensuite le Python d'Odoo, que le
|
||||
# module déclare et que le profil du système porte, cherché avant
|
||||
# celui de l'utilisateur.
|
||||
+ "elif command -v nix-env >/dev/null 2>&1; then "
|
||||
+ "elif command -v nix-env >/dev/null 2>&1; then "
|
||||
"nix-env -f '<nixpkgs>' -iA git gnumake curl python3"
|
||||
f"{self._qemu_editor_suffix()}; "
|
||||
# Le PATH de cette commande distante a été figé à l'ouverture du
|
||||
|
|
@ -585,9 +575,7 @@ class QemuDeployMixin:
|
|||
"-o ConnectTimeout=15"
|
||||
)
|
||||
cmd = f"ssh {ssh_opts} erplibre@{ip} {shlex.quote(remote)}"
|
||||
print(
|
||||
f"\n 📦 {name} ({ip}): {t('installing ERPLibre')} " f"({branch})"
|
||||
)
|
||||
print(f"\n 📦 {name} ({ip}): {t('installing ERPLibre')} ({branch})")
|
||||
print(f" {t('Will execute:')} {cmd}")
|
||||
self.execute.exec_command_live(cmd, source_erplibre=False)
|
||||
|
||||
|
|
|
|||
|
|
@ -37,7 +37,7 @@ class QemuMenuMixin:
|
|||
# deploy_qemu.py ; ceci ne sert qu'au sélecteur interactif.
|
||||
_QEMU_DISTROS = {
|
||||
"ubuntu": (["24.04", "25.10", "26.04"], "24.04"),
|
||||
"debian": (["11", "12", "13"], "12"),
|
||||
"debian": (["12", "13"], "12"),
|
||||
"fedora": (["41", "42", "43", "44"], "42"),
|
||||
"almalinux": (["9", "10"], "9"),
|
||||
"rocky": (["9", "10"], "10"),
|
||||
|
|
|
|||
Loading…
Reference in a new issue