style: apply ruff format across the tree; refresh moved-module doc refs

Bring 14 files that predated the ruff-format run into line with the configured
formatter (line-length 100); provably formatting-only (ruff format of HEAD ==
working tree, and ruff format is semantics-preserving). Also refresh two
lim.image.tor._KEYGEN_SCRIPT doc references in tor_harness.py to
lim.image.initramfs.keygen after the module moved.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Kevin Veen-Birkenbach
2026-07-22 17:47:32 +02:00
parent dc823e06c3
commit b68daa96ef
15 changed files with 88 additions and 117 deletions

View File

@@ -59,14 +59,12 @@ COMMANDS: dict[str, Command] = {
),
"mount": Command(
single_drive.mount,
"Mount Encrypted Storage:\n"
" - Unlocks a LUKS partition and mounts it.",
"Mount Encrypted Storage:\n - Unlocks a LUKS partition and mounts it.",
needs_root=True,
),
"umount": Command(
single_drive.umount,
"Unmount Encrypted Storage:\n"
" - Unmounts a LUKS partition and closes the mapper.",
"Unmount Encrypted Storage:\n - Unmounts a LUKS partition and closes the mapper.",
needs_root=True,
),
"single-boot": Command(
@@ -83,26 +81,22 @@ COMMANDS: dict[str, Command] = {
),
"unlock": Command(
crypt.unlock,
"Unlock Data:\n"
" - Decrypts the encfs data store into the decrypted folder.",
"Unlock Data:\n - Decrypts the encfs data store into the decrypted folder.",
needs_root=False,
),
"lock": Command(
crypt.lock,
"Lock Data:\n"
" - Unmounts the decrypted encfs folder.",
"Lock Data:\n - Unmounts the decrypted encfs folder.",
needs_root=False,
),
"import": Command(
sync.import_from_system,
"Import Data:\n"
" - Copies personal data from the system into the encrypted store.",
"Import Data:\n - Copies personal data from the system into the encrypted store.",
needs_root=False,
),
"export": Command(
sync.export_to_system,
"Export Data:\n"
" - Copies personal data from the encrypted store back to the system.",
"Export Data:\n - Copies personal data from the encrypted store back to the system.",
needs_root=False,
),
}

View File

@@ -90,31 +90,22 @@ def execute_sync_plan(operations: list[SyncOperation]) -> None:
if not operation.is_directory and Path(operation.destination).is_file():
ui.info("The destination file already exists!")
ui.info("Difference:")
runner.run(
["diff", operation.destination, operation.source], check=False
)
runner.run(["diff", operation.destination, operation.source], check=False)
runner.run(rsync_command(operation))
def ensure_unlocked() -> None:
mounts = runner.output(["mount"], check=False)
if str(config.DECRYPTED_PATH) not in mounts:
ui.info(
f"The decrypted folder {config.DECRYPTED_PATH} is locked. "
"You need to unlock it!"
)
ui.info(f"The decrypted folder {config.DECRYPTED_PATH} is locked. You need to unlock it!")
crypt.unlock()
def import_from_system(mode: str = "import") -> None:
ensure_unlocked()
backup_folder = (
config.BACKUP_PATH / mode / time.strftime("%Y%m%d%H%M%S")
)
backup_folder = config.BACKUP_PATH / mode / time.strftime("%Y%m%d%H%M%S")
backup_folder.mkdir(parents=True, exist_ok=True)
operations = build_sync_plan(
mode, system.real_home(), config.DATA_PATH, backup_folder
)
operations = build_sync_plan(mode, system.real_home(), config.DATA_PATH, backup_folder)
execute_sync_plan(operations)

View File

@@ -119,9 +119,7 @@ def overwrite_device(device: Device) -> None:
def blkid_value(path: str, tag: str) -> str:
"""Return a blkid tag value ("TYPE", "UUID", ...) or "" when unavailable."""
return runner.output(
["blkid", path, "-s", tag, "-o", "value"], sudo=True, check=False
)
return runner.output(["blkid", path, "-s", tag, "-o", "value"], sudo=True, check=False)
def is_mounted(path_fragment: str) -> bool:

View File

@@ -44,9 +44,7 @@ def choose_manjaro(plan: ImagePlan) -> None:
def choose_moode(plan: ImagePlan) -> None:
plan.boot_size = "+200M"
plan.image_checksum = "185cbc9a4994534bb7a4bc2744c78197"
plan.base_download_url = (
"https://github.com/moode-player/moode/releases/download/r651prod/"
)
plan.base_download_url = "https://github.com/moode-player/moode/releases/download/r651prod/"
plan.image_name = "moode-r651-iso.zip"
@@ -57,9 +55,7 @@ def choose_retropie(plan: ImagePlan) -> None:
if entry is None:
raise LimError(f"Version {version} isn't supported.")
plan.raspberry_pi_version = version
plan.base_download_url = (
"https://github.com/RetroPie/RetroPie-Setup/releases/download/4.8/"
)
plan.base_download_url = "https://github.com/RetroPie/RetroPie-Setup/releases/download/4.8/"
plan.image_checksum = entry["checksum"]
plan.image_name = entry["image"]
@@ -67,9 +63,7 @@ def choose_retropie(plan: ImagePlan) -> None:
def choose_torbox(plan: ImagePlan) -> None:
plan.base_download_url = "https://www.torbox.ch/data/"
plan.image_name = "torbox-20220102-v050.gz"
plan.image_checksum = (
"0E1BA7FFD14AAAE5F0462C8293D95B62C3BF1D9E726E26977BD04772C55680D3"
)
plan.image_checksum = "0E1BA7FFD14AAAE5F0462C8293D95B62C3BF1D9E726E26977BD04772C55680D3"
plan.boot_size = "+200M"
@@ -78,9 +72,7 @@ def choose_android_x86(plan: ImagePlan) -> None:
"https://www.fosshub.com/Android-x86.html?dwl=android-x86_64-9.0-r2.iso"
)
plan.image_name = "android-x86_64-9.0-r2.iso"
plan.image_checksum = (
"f7eb8fc56f29ad5432335dc054183acf086c539f3990f0b6e9ff58bd6df4604e"
)
plan.image_checksum = "f7eb8fc56f29ad5432335dc054183acf086c539f3990f0b6e9ff58bd6df4604e"
plan.boot_size = "+500M"

View File

@@ -36,8 +36,7 @@ def _select_unmounted_device() -> device_module.Device:
device = device_module.select_device()
if device_module.is_mounted(device.path):
raise LimError(
f'Device {device.path} is allready mounted. '
f'Umount with "umount {device.path}*".'
f'Device {device.path} is allready mounted. Umount with "umount {device.path}*".'
)
return device
@@ -83,9 +82,7 @@ def run_setup() -> None:
session.make_working_folder()
session.make_mount_folders()
plan.root_filesystem = ui.ask(
"Which filesystem should be used? E.g.:btrfs,ext4... (none):"
)
plan.root_filesystem = ui.ask("Which filesystem should be used? E.g.:btrfs,ext4... (none):")
if ui.confirm(f"Should the image be transfered to {device.path}?"):
transfer.transfer_image(plan, session)

View File

@@ -15,10 +15,7 @@ def download_image(plan: ImagePlan) -> None:
ui.info(f"Removing image {plan.image_path}.")
plan.image_path.unlink()
else:
ui.info(
"Forcing download wasn't neccessary. "
f"File {plan.image_path} doesn't exist."
)
ui.info(f"Forcing download wasn't neccessary. File {plan.image_path} doesn't exist.")
ui.info("Start Download procedure...")
if plan.image_path.is_file():
@@ -61,9 +58,18 @@ def decompress_command(image_path: Path) -> list[str]:
def _luks_format_root(plan: ImagePlan, session: ImageSession) -> None:
luks_format = [
"cryptsetup", "-v", "luksFormat",
"-c", "aes-xts-plain64", "-s", "512", "-h", "sha512",
"--use-random", "-i", "1000",
"cryptsetup",
"-v",
"luksFormat",
"-c",
"aes-xts-plain64",
"-s",
"512",
"-h",
"sha512",
"--use-random",
"-i",
"1000",
]
if plan.luks_memory_cost:
ui.info(

View File

@@ -24,8 +24,7 @@ def resolve_checksum(download_url: str) -> str | None:
for extension in ("sha1", "sha512", "md5"):
checksum_url = f"{download_url}.{extension}"
ui.info(
"Image Checksum is not defined. "
f"Try to download image signature from {checksum_url}."
f"Image Checksum is not defined. Try to download image signature from {checksum_url}."
)
if url_exists(checksum_url):
content = runner.output(["wget", checksum_url, "-q", "-O", "-"])
@@ -62,8 +61,7 @@ def verify_signature(download_url: str, image_path: str | Path, image_folder: Pa
"""Best-effort GPG signature verification of the downloaded image."""
ui.info("Note: Checksums verify integrity but do not confirm authenticity.")
ui.info(
"Proceeding to signature verification, "
"which ensures the file comes from a trusted source."
"Proceeding to signature verification, which ensures the file comes from a trusted source."
)
signature_url = f"{download_url}.sig"
ui.info(f"Attempting to download the image signature from: {signature_url}")

View File

@@ -40,14 +40,10 @@ def create_luks_key_and_update_crypttab(
runner.sync_disks()
ui.info("Opening and closing device to verify that everything works fine...")
closed = runner.run(
["cryptsetup", "-v", "luksClose", mapper_name], sudo=True, check=False
)
closed = runner.run(["cryptsetup", "-v", "luksClose", mapper_name], sudo=True, check=False)
if closed.returncode != 0:
ui.info(f"No need to luksClose {mapper_name}. Device isn't open.")
runner.run(
["cryptsetup", "luksAddKey", partition_path, str(secret_key_path)], sudo=True
)
runner.run(["cryptsetup", "luksAddKey", partition_path, str(secret_key_path)], sudo=True)
runner.run(
[
"cryptsetup",
@@ -70,9 +66,7 @@ def create_luks_key_and_update_crypttab(
print(crypttab_path.read_text())
def update_fstab(
mapper_path: str, mount_path: str, *, fstab_path: Path = FSTAB_PATH
) -> None:
def update_fstab(mapper_path: str, mount_path: str, *, fstab_path: Path = FSTAB_PATH) -> None:
entry = f"{mapper_path} {mount_path} btrfs defaults 0 2"
ui.info("Adding fstab entry...")
fsutil.ensure_line_in_file(entry, fstab_path)

View File

@@ -50,8 +50,7 @@ def run(
return subprocess.CompletedProcess(cmd, COMMAND_NOT_FOUND)
if check and result.returncode != 0:
raise LimError(
error_msg
or f"Command failed with code {result.returncode}: {shlex.join(cmd)}"
error_msg or f"Command failed with code {result.returncode}: {shlex.join(cmd)}"
)
return result
@@ -98,8 +97,7 @@ def pipeline(
) -> None:
"""Run commands as a shell-style pipeline (cmd1 | cmd2 | ...)."""
prepared = [
_with_sudo(cmd, sudo=sudo_last and index == len(cmds) - 1)
for index, cmd in enumerate(cmds)
_with_sudo(cmd, sudo=sudo_last and index == len(cmds) - 1) for index, cmd in enumerate(cmds)
]
pretty = " | ".join(shlex.join(cmd) for cmd in prepared)
ui.info(f"Running: {pretty}")

View File

@@ -25,9 +25,7 @@ def setup() -> None:
runner.run(["cryptsetup", "luksFormat", second.device.path], sudo=True)
runner.run(["cryptsetup", "luksOpen", first.device.path, first.mapper_name], sudo=True)
runner.run(
["cryptsetup", "luksOpen", second.device.path, second.mapper_name], sudo=True
)
runner.run(["cryptsetup", "luksOpen", second.device.path, second.mapper_name], sudo=True)
runner.run(["cryptsetup", "status", first.mapper_path], sudo=True)
runner.run(["cryptsetup", "status", second.mapper_path], sudo=True)

View File

@@ -32,9 +32,7 @@ def setup() -> None:
runner.run(["cryptsetup", "-v", "-y", "luksFormat", target.partition_path], sudo=True)
ui.info("Unlock partition...")
runner.run(
["cryptsetup", "luksOpen", target.partition_path, target.mapper_name], sudo=True
)
runner.run(["cryptsetup", "luksOpen", target.partition_path, target.mapper_name], sudo=True)
ui.info("Create btrfs file system...")
runner.run(["mkfs.btrfs", target.mapper_path], sudo=True)
@@ -57,9 +55,7 @@ def mount() -> None:
target = select_storage_target()
ui.info("Unlock partition...")
runner.run(
["cryptsetup", "luksOpen", target.partition_path, target.mapper_name], sudo=True
)
runner.run(["cryptsetup", "luksOpen", target.partition_path, target.mapper_name], sudo=True)
ui.info("Mount partition...")
runner.run(["mount", target.mapper_path, target.mount_path], sudo=True)

View File

@@ -13,7 +13,7 @@ import threading
import time
from pathlib import Path
# Matches lim.image.tor._KEYGEN_SCRIPT: an empty -f torrc keeps the host's
# Matches lim.image.initramfs.keygen._KEYGEN_SCRIPT: an empty -f torrc keeps the host's
# /etc/tor/torrc out of the run, --DisableNetwork 1 makes the keys appear
# without ever touching the network.
KEYGEN_TIMEOUT = 30
@@ -30,7 +30,7 @@ def free_port() -> int:
def generate_onion_keys(onion_dir: Path, data_dir: Path) -> str:
"""Create v3 onion keys offline; return the .onion hostname.
Mirrors lim.image.tor._KEYGEN_SCRIPT, run directly on the host instead
Mirrors lim.image.initramfs.keygen._KEYGEN_SCRIPT, run directly on the host instead
of inside the image chroot (the tor invocation is identical).
"""
onion_dir.mkdir(parents=True, exist_ok=True)
@@ -39,11 +39,23 @@ def generate_onion_keys(onion_dir: Path, data_dir: Path) -> str:
empty_torrc.write_text("")
process = subprocess.Popen(
[
"tor", "-f", str(empty_torrc), "--DisableNetwork", "1",
"--DataDirectory", str(data_dir),
"--HiddenServiceDir", str(onion_dir),
"--HiddenServicePort", "22 127.0.0.1:22",
"--SocksPort", "0", "--RunAsDaemon", "0", "--Log", "notice stderr",
"tor",
"-f",
str(empty_torrc),
"--DisableNetwork",
"1",
"--DataDirectory",
str(data_dir),
"--HiddenServiceDir",
str(onion_dir),
"--HiddenServicePort",
"22 127.0.0.1:22",
"--SocksPort",
"0",
"--RunAsDaemon",
"0",
"--Log",
"notice stderr",
],
stderr=subprocess.DEVNULL,
)
@@ -62,9 +74,7 @@ def generate_onion_keys(onion_dir: Path, data_dir: Path) -> str:
return hostname.read_text().strip()
def start_onion_service(
torrc_path: Path, socks_port: int, log_path: Path
) -> subprocess.Popen:
def start_onion_service(torrc_path: Path, socks_port: int, log_path: Path) -> subprocess.Popen:
"""Start Tor with the given torrc (service side) plus a SOCKS port.
The torrc carries the HiddenServiceDir/HiddenServicePort just like the
@@ -73,9 +83,13 @@ def start_onion_service(
"""
return subprocess.Popen(
[
"tor", "-f", str(torrc_path),
"--SocksPort", str(socks_port),
"--Log", f"notice file {log_path}",
"tor",
"-f",
str(torrc_path),
"--SocksPort",
str(socks_port),
"--Log",
f"notice file {log_path}",
],
stdout=subprocess.DEVNULL,
stderr=subprocess.DEVNULL,
@@ -98,11 +112,7 @@ def _socks5_handshake(sock: socket.socket, onion_host: str, onion_port: int) ->
if sock.recv(2) != b"\x05\x00":
raise RuntimeError("SOCKS5 handshake rejected.")
host = onion_host.encode()
request = (
b"\x05\x01\x00\x03"
+ bytes([len(host)]) + host
+ struct.pack(">H", onion_port)
)
request = b"\x05\x01\x00\x03" + bytes([len(host)]) + host + struct.pack(">H", onion_port)
sock.settimeout(ONION_CONNECT_TIMEOUT)
sock.sendall(request)
header = sock.recv(4)

View File

@@ -24,9 +24,7 @@ def test_every_command_dispatches_to_its_function(monkeypatch):
def test_needs_root_command_requests_root(monkeypatch):
escalated = []
monkeypatch.setattr(system, "ensure_root", lambda: escalated.append(True))
monkeypatch.setitem(
cli.COMMANDS, "backup", Command(lambda: None, "d", needs_root=True)
)
monkeypatch.setitem(cli.COMMANDS, "backup", Command(lambda: None, "d", needs_root=True))
cli.main(["--type", "backup", "--auto-confirm"])
assert escalated == [True]

View File

@@ -20,9 +20,7 @@ def test_storage_target_derives_all_paths():
assert target.partition_path == "/dev/sdb1"
def test_single_drive_setup_command_sequence(
fake_runner, answers, block_devices, monkeypatch
):
def test_single_drive_setup_command_sequence(fake_runner, answers, block_devices, monkeypatch):
monkeypatch.setattr("lim.system.real_user", lambda: "kevin")
answers("sdb", "N") # device name, skip overwrite

View File

@@ -58,10 +58,19 @@ def test_rsync_command_uses_delete_only_for_directories():
directory_op = sync.SyncOperation("src/", "dst/", "backup", is_directory=True)
file_op = sync.SyncOperation("src", "dst", "backup", is_directory=False)
assert sync.rsync_command(directory_op) == [
"rsync", "-abcEPuvW", "--delete", "--backup-dir=backup", "src/", "dst/"
"rsync",
"-abcEPuvW",
"--delete",
"--backup-dir=backup",
"src/",
"dst/",
]
assert sync.rsync_command(file_op) == [
"rsync", "-abcEPuvW", "--backup-dir=backup", "src", "dst"
"rsync",
"-abcEPuvW",
"--backup-dir=backup",
"src",
"dst",
]
@@ -95,18 +104,12 @@ def test_export_chowns_real_home_without_sudo(tmp_path, fake_runner, monkeypatch
sync.export_to_system()
chown_calls = [
(cmd, sudo) for cmd, sudo in fake_runner.sudo_log if cmd[0] == "chown"
]
assert chown_calls == [
(["chown", "-R", "kevin:kevin", str(real_home)], False)
]
chown_calls = [(cmd, sudo) for cmd, sudo in fake_runner.sudo_log if cmd[0] == "chown"]
assert chown_calls == [(["chown", "-R", "kevin:kevin", str(real_home)], False)]
assert (real_home / ".ssh/id_rsa").stat().st_mode & 0o777 == 0o600
def test_execute_sync_plan_creates_folders_and_runs_rsync(
tmp_path, fake_runner
):
def test_execute_sync_plan_creates_folders_and_runs_rsync(tmp_path, fake_runner):
operation = sync.SyncOperation(
source=str(tmp_path / "src.txt"),
destination=str(tmp_path / "deep/nested/dst.txt"),