X-Git-Url: https://git.saurik.com/apt.git/blobdiff_plain/caa8a9f1e777f351b911dc8c30a858a5f026fca3..2906182db398419a9c59a928b7ae73cf7c7aa307:/test/integration/framework?ds=inline

diff --git a/test/integration/framework b/test/integration/framework
index eda3cebad..9a114ae69 100644
--- a/test/integration/framework
+++ b/test/integration/framework
@@ -2,14 +2,37 @@
 
 EXIT_CODE=0
 
+while [ -n "$1" ]; do
+	if [ "$1" = "-q" ]; then
+		export MSGLEVEL=2
+	elif [ "$1" = "-qq" ]; then
+		export MSGLEVEL=1
+	elif [ "$1" = "-v" ]; then
+		export MSGLEVEL=4
+	elif [ "$1" = '--color=no' ]; then
+		export MSGCOLOR='NO'
+	elif [ "$1" = '--color=yes' ]; then
+		export MSGCOLOR='YES'
+	elif [ "$1" = '--color' ]; then
+		export MSGCOLOR="$(echo "$2" | tr 'a-z' 'A-Z')"
+		shift
+	elif [ "$1" = '--level' ]; then
+		export MSGLEVEL=$2
+		shift
+	else
+		echo >&2 "WARNING: Unknown parameter »$1« will be ignored"
+	fi
+	shift
+done
+export MSGLEVEL="${MSGLEVEL:-3}"
+
 # we all like colorful messages
-if [ "$MSGCOLOR" != 'NO' ]; then
-	if ! expr match "$(readlink -f /proc/$$/fd/1)" '/dev/pts/[0-9]\+' > /dev/null; then
+if [ "${MSGCOLOR:-YES}" = 'YES' ]; then
+	if [ ! -t 1 ]; then # but check that we output to a terminal
 		export MSGCOLOR='NO'
 	fi
 fi
 
-
 if [ "$MSGCOLOR" != 'NO' ]; then
 	CERROR="\033[1;31m" # red
 	CWARNING="\033[1;33m" # yellow
@@ -23,35 +46,76 @@ if [ "$MSGCOLOR" != 'NO' ]; then
 	CCMD="\033[1;35m" # pink
 fi
 
-msgdie() { echo "${CERROR}E: $1${CNORMAL}" >&2; exit 1; }
-msgwarn() { echo "${CWARNING}W: $1${CNORMAL}" >&2; }
-msgmsg() { echo "${CMSG}$1${CNORMAL}"; }
-msginfo() { echo "${CINFO}I: $1${CNORMAL}"; }
-msgdebug() { echo "${CDEBUG}D: $1${CNORMAL}"; }
-msgdone() { echo "${CDONE}DONE${CNORMAL}"; }
-msgnwarn() { echo -n "${CWARNING}W: $1${CNORMAL}" >&2; }
-msgnmsg() { echo -n "${CMSG}$1${CNORMAL}"; }
-msgninfo() { echo -n "${CINFO}I: $1${CNORMAL}"; }
-msgndebug() { echo -n "${CDEBUG}D: $1${CNORMAL}"; }
-msgtest() {
-	while [ -n "$1" ]; do
-		echo -n "${CINFO}$1${CCMD} "
-		echo -n "$(echo "$2" | sed -e 's/^aptc/apt-c/' -e 's/^aptg/apt-g/' -e 's/^aptf/apt-f/')${CINFO} "
+msgprintf() {
+	local START="$1"
+	local MIDDLE="$2"
+	local END="$3"
+	shift 3
+	if [ -n "$1" ]; then
+		printf "$START " "$1"
 		shift
-		if [ -n "$1" ]; then shift; else break; fi
-	done
-	echo -n "…${CNORMAL} "
+		while [ -n "$1" ]; do
+			printf "$MIDDLE " "$(echo "$1" | sed -e 's#^apt\([cfghks]\)#apt-\1#')"
+			shift
+		done
+	fi
+	printf "${END}"
+}
+msgdie() { msgprintf "${CERROR}E: %s" '%s' "${CNORMAL}\n" "$@" >&2; exit 1; }
+msgwarn() { msgprintf "${CWARNING}W: %s" '%s' "${CNORMAL}\n" "$@" >&2; }
+msgmsg() { msgprintf "${CMSG}%s" '%s' "${CNORMAL}\n" "$@"; }
+msginfo() { msgprintf "${CINFO}I: %s" '%s' "${CNORMAL}\n" "$@"; }
+msgdebug() { msgprintf "${CDEBUG}D: %s" '%s' "${CNORMAL}\n" "$@"; }
+msgdone() { msgprintf "${CDONE}DONE" '%s' "${CNORMAL}\n" "$@"; }
+msgnwarn() { msgprintf "${CWARNING}W: %s" '%s' "${CNORMAL}" "$@" >&2; }
+msgnmsg() { msgprintf "${CMSG}%s" '%s' "${CNORMAL}" "$@"; }
+msgninfo() { msgprintf "${CINFO}I: %s" '%s' "${CNORMAL}" "$@"; }
+msgndebug() { msgprintf "${CDEBUG}D: %s" '%s' "${CNORMAL}" "$@"; }
+msgtest() { msgprintf "${CINFO}%s" "${CCMD}%s${CINFO}" "…${CNORMAL} " "$@"; }
+msgpass() { printf "${CPASS}PASS${CNORMAL}\n"; }
+msgreportheader() {
+	if [ -n "$MSGTEST_MSG" ]; then
+		test "$1" != 'msgfailoutput' || echo
+		if [ -n "$MSGTEST_MSGMSG" ]; then
+			echo "$MSGTEST_MSGMSG"
+		fi
+		if [ -n "$MSGTEST_GRP" ] && [ "$MSGTEST_GRP" != 'NEXT' ] && [ "$MSGTEST_GRP" != "$MSGTEST_MSG" ]; then
+			echo "${CFAIL}Part of the test group: $MSGTEST_GRP"
+		fi
+		echo -n "$MSGTEST_MSG"
+		unset MSGTEST_MSG
+	fi
+}
+msgskip() {
+	msgreportheader 'msgskip'
+	if [ $# -gt 0 ]; then printf "${CWARNING}SKIP: $*${CNORMAL}\n" >&2;
+	else printf "${CWARNING}SKIP${CNORMAL}\n" >&2; fi
 }
-msgpass() { echo "${CPASS}PASS${CNORMAL}"; }
-msgskip() { echo "${CWARNING}SKIP${CNORMAL}" >&2; }
 msgfail() {
-	if [ $# -gt 0 ]; then echo "${CFAIL}FAIL: $*${CNORMAL}" >&2;
-	else echo "${CFAIL}FAIL${CNORMAL}" >&2; fi
+	msgreportheader 'msgfail'
+	if [ $# -gt 0 ] && [ -n "$1" ]; then printf "${CFAIL}FAIL: $*${CNORMAL}\n" >&2;
+	else printf "${CFAIL}FAIL${CNORMAL}\n" >&2; fi
+	if [ -n "$APT_DEBUG_TESTS" ]; then
+		runapt $SHELL
+	fi
 	EXIT_CODE=$((EXIT_CODE+1));
 }
+MSGGROUP_LEVEL=0
+msggroup() {
+	if [ -n "$1" ]; then
+		if [ $MSGGROUP_LEVEL = 0 ]; then
+			MSGTEST_GRP='NEXT'
+		fi
+		MSGGROUP_LEVEL=$((MSGGROUP_LEVEL+1));
+	else
+		MSGGROUP_LEVEL=$((MSGGROUP_LEVEL-1));
+		if [ $MSGGROUP_LEVEL = 0 ]; then
+			unset MSGTEST_GRP
+		fi
+	fi
+}
 
 # enable / disable Debugging
-MSGLEVEL=${MSGLEVEL:-3}
 if [ $MSGLEVEL -le 0 ]; then
 	msgdie() { true; }
 fi
@@ -60,16 +124,17 @@ if [ $MSGLEVEL -le 1 ]; then
 	msgnwarn() { true; }
 fi
 if [ $MSGLEVEL -le 2 ]; then
-	msgmsg() { true; }
+	msgmsg() {
+		MSGTEST_MSGMSG="$(msgprintf "${CMSG}%s" '%s' "${CNORMAL}" "$@")"
+	}
 	msgnmsg() { true; }
-	msgtest() { true; }
-	msgpass() { echo -n " ${CPASS}P${CNORMAL}"; }
-	msgskip() { echo -n " ${CWARNING}S${CNORMAL}" >&2; }
-	if [ -n "$CFAIL" ]; then
-		msgfail() { echo -n " ${CFAIL}FAIL${CNORMAL}" >&2; EXIT_CODE=$((EXIT_CODE+1)); }
-	else
-		msgfail() { echo -n " ###FAILED###" >&2; EXIT_CODE=$((EXIT_CODE+1)); }
-	fi
+	msgtest() {
+		MSGTEST_MSG="$(msgprintf "${CINFO}%s" "${CCMD}%s${CINFO}" "…${CNORMAL} " "$@")"
+		if [ "$MSGTEST_GRP" = 'NEXT' ]; then
+			MSGTEST_GRP="$MSGTEST_MSG"
+		fi
+	}
+	msgpass() { printf " ${CPASS}P${CNORMAL}"; }
 fi
 if [ $MSGLEVEL -le 3 ]; then
 	msginfo() { true; }
@@ -79,6 +144,9 @@ if [ $MSGLEVEL -le 4 ]; then
 	msgdebug() { true; }
 	msgndebug() { true; }
 fi
+if [ $MSGLEVEL -le 1 ]; then
+	msgpass() { true; }
+fi
 msgdone() {
 	if [ "$1" = "debug" -a $MSGLEVEL -le 4 ] ||
 	   [ "$1" = "info" -a $MSGLEVEL -le 3 ] ||
@@ -87,58 +155,81 @@ msgdone() {
 	   [ "$1" = "die" -a $MSGLEVEL -le 0 ]; then
 		true;
 	else
-		echo "${CDONE}DONE${CNORMAL}";
+		printf "${CDONE}DONE${CNORMAL}\n";
 	fi
 }
 getaptconfig() {
 	if [ -f ./aptconfig.conf ]; then
-            echo "./aptconfig.conf"
+		echo "$(readlink -f ./aptconfig.conf)"
 	elif [ -f ../aptconfig.conf ]; then
-            echo "../aptconfig.conf"
-        fi
+		echo "$(readlink -f ../aptconfig.conf)"
+	elif [ -f ../../aptconfig.conf ]; then
+		echo "$(readlink -f ../../aptconfig.conf)"
+	elif [ -f "${TMPWORKINGDIRECTORY}/aptconfig.conf" ]; then
+		echo "$(readlink -f "${TMPWORKINGDIRECTORY}/aptconfig.conf")"
+	fi
 }
 runapt() {
 	msgdebug "Executing: ${CCMD}$*${CDEBUG} "
 	local CMD="$1"
 	shift
-	case $CMD in
-	sh|aptitude|*/*) ;;
+	case "$CMD" in
+	sh|aptitude|*/*|command) ;;
 	*) CMD="${BUILDDIRECTORY}/$CMD";;
 	esac
-	MALLOC_PERTURB_=21 MALLOC_CHECK_=2 APT_CONFIG="$(getaptconfig)" LD_LIBRARY_PATH=${BUILDDIRECTORY} $CMD "$@"
+	MALLOC_PERTURB_=21 MALLOC_CHECK_=2 APT_CONFIG="$(getaptconfig)" LD_LIBRARY_PATH="${LIBRARYPATH}:${LD_LIBRARY_PATH}" "$CMD" "$@"
 }
+runpython3() { runapt command python3 "$@"; }
 aptconfig() { runapt apt-config "$@"; }
 aptcache() { runapt apt-cache "$@"; }
 aptcdrom() { runapt apt-cdrom "$@"; }
 aptget() { runapt apt-get "$@"; }
-aptftparchive() { runapt apt-ftparchive "$@"; }
+aptftparchive() { runapt "${APTFTPARCHIVEBINDIR}/apt-ftparchive" "$@"; }
 aptkey() { runapt apt-key "$@"; }
 aptmark() { runapt apt-mark "$@"; }
+aptsortpkgs() { runapt apt-sortpkgs "$@"; }
 apt() { runapt apt "$@"; }
 apthelper() { runapt "${APTHELPERBINDIR}/apt-helper" "$@"; }
-aptwebserver() { runapt "${APTWEBSERVERBINDIR}/aptwebserver" "$@"; }
+aptwebserver() { runapt "${APTTESTHELPERSBINDIR}/aptwebserver" "$@"; }
 aptitude() { runapt aptitude "$@"; }
 aptextracttemplates() { runapt apt-extracttemplates "$@"; }
+aptinternalsolver() { runapt "${APTINTERNALSOLVER}" "$@"; }
+aptdumpsolver() { runapt "${APTDUMPSOLVER}" "$@"; }
+aptinternalplanner() { runapt "${APTINTERNALPLANNER}" "$@"; }
 
 dpkg() {
-	command dpkg --root=${TMPWORKINGDIRECTORY}/rootdir --force-not-root --force-bad-path --log=${TMPWORKINGDIRECTORY}/rootdir/var/log/dpkg.log "$@"
+	"${TMPWORKINGDIRECTORY}/rootdir/usr/bin/dpkg" "$@"
+}
+dpkg_version() {
+	command perl -MDpkg -E 'say $Dpkg::PROGVERSION'
 }
 dpkgcheckbuilddeps() {
-	command dpkg-checkbuilddeps --admindir=${TMPWORKINGDIRECTORY}/rootdir/var/lib/dpkg "$@"
+	command dpkg-checkbuilddeps --admindir="${TMPWORKINGDIRECTORY}/rootdir/var/lib/dpkg" "$@"
 }
 gdb() {
-	echo "gdb: run »$*«"
-	CMD="$1"
+	local CMD
+	case "$1" in
+	aptget) CMD="apt-get";;
+	aptcache) CMD="apt-cache";;
+	aptcdrom) CMD="apt-cdrom";;
+	aptconfig) CMD="apt-config";;
+	aptmark) CMD="apt-mark";;
+	apthelper) CMD="apt-helper";;
+	aptftparchive) CMD="apt-ftparchive";;
+	dpkg) shift; runapt "${TMPWORKINGDIRECTORY}/rootdir/usr/bin/gdb-dpkg" "$@"; return;;
+	*) CMD="$1";;
+	esac
 	shift
-
-	APT_CONFIG=aptconfig.conf LD_LIBRARY_PATH=${LIBRARYPATH} command gdb ${BUILDDIRECTORY}/$CMD --args ${BUILDDIRECTORY}/$CMD "$@"
+	if [ "${CMD##*/}" = "$CMD" ]; then
+		CMD="${BUILDDIRECTORY}/${CMD}"
+	fi
+	runapt command gdb --quiet -ex "directory '$SOURCEDIRECTORY'" -ex run "$CMD" --args "$CMD" "$@"
+}
+lastmodification() {
+	date -u -d "@$(stat -c '%Y' "${TMPWORKINGDIRECTORY}/$1")" -R
 }
-gpg() {
-	# see apt-key for the whole trickery. Setup is done in setupenvironment
-	command gpg --ignore-time-conflict --no-options --no-default-keyring \
-		--homedir "${TMPWORKINGDIRECTORY}/gnupghome" \
-		--no-auto-check-trustdb --trust-model always \
-		"$@"
+releasefiledate() {
+	grep "^${2:-Date}:" "$1" | cut -d' ' -f 2-
 }
 
 exitwithstatus() {
@@ -153,7 +244,7 @@ exitwithstatus() {
 shellsetedetector() {
 	local exit_status=$?
 	if [ "$exit_status" != '0' ]; then
-		echo >&2 "${CERROR}E: Looks like the testcases ended prematurely with exitcode: ${exit_status}${CNORMAL}"
+		printf >&2 "${CERROR}E: Looks like the testcases ended prematurely with exitcode: ${exit_status}${CNORMAL}\n"
 		if [ "$EXIT_CODE" = '0' ]; then
 			EXIT_CODE="$exit_status"
 		fi
@@ -169,85 +260,229 @@ addtrap() {
 	trap "shellsetedetector; $CURRENTTRAP exitwithstatus;" 0 HUP INT QUIT ILL ABRT FPE SEGV PIPE TERM
 }
 
+escape_shell() {
+    echo "$@" | sed -e "s#'#'\"'\"'#g"
+}
+
+find_project_binary_dir() {
+	local TESTDIRECTORY="$(readlink -f "$(dirname $0)")"
+	if [ -z "$PROJECT_BINARY_DIR" ]; then
+		PROJECT_BINARY_DIR=
+		for dir in ${TESTDIRECTORY}/../../ ${TESTDIRECTORY}/../../*; do
+			test -e "$dir/CMakeCache.txt"  || continue
+			if [ -z "$PROJECT_BINARY_DIR" ] ||
+			   [ "$dir/CMakeCache.txt" -nt "$PROJECT_BINARY_DIR/CMakeCache.txt" ]; then
+				PROJECT_BINARY_DIR="$dir"
+			fi
+		done
+		if [ -z "$PROJECT_BINARY_DIR" ]; then
+			echo "Cannot find build directory, you might want to set PROJECT_BINARY_DIR" >&2
+			exit 1
+		fi
+		export PROJECT_BINARY_DIR
+	fi
+}
 setupenvironment() {
-	TMPWORKINGDIRECTORY=$(mktemp -d)
-	TESTDIRECTORY=$(readlink -f $(dirname $0))
-	msgninfo "Preparing environment for ${CCMD}$(basename $0)${CINFO} in ${TMPWORKINGDIRECTORY}… "
+	# Next check needs a gnu stat, let's figure that out early.
+	stat=stat
+	if command -v gnustat >/dev/null 2>&1; then
+		stat=gnustat
+	fi
+	# privilege dropping and testing doesn't work if /tmp isn't world-writeable (as e.g. with libpam-tmpdir)
+	if [ -n "$TMPDIR" ] && [ "$(id -u)" = '0' ] && [ "$($stat --format '%a' "$TMPDIR")" != '1777' ]; then
+		unset TMPDIR
+	fi
+	TMPWORKINGDIRECTORY="$(mktemp -d)"
+	addtrap "cd /; rm -rf '$(escape_shell "$TMPWORKINGDIRECTORY")';"
+	if [ -n "$TMPDIR_ADD" ]; then
+		TMPWORKINGDIRECTORY="${TMPWORKINGDIRECTORY}/${TMPDIR_ADD}"
+		mkdir -p "$TMPWORKINGDIRECTORY"
+		unset TMPDIR_ADD
+		export TMPDIR="$TMPWORKINGDIRECTORY"
+	fi
+	msgninfo "Preparing environment for ${0##*/} in ${TMPWORKINGDIRECTORY}…"
+
+	# Setup coreutils on BSD systems
+	mkdir "${TMPWORKINGDIRECTORY}/bin"
+	for prefix in gnu g; do
+			for command in stat touch sed cp tr sha1sum sha256sum md5sum sha512sum grep date wc chmod head readlink tar expr base64; do
+					if command -v $prefix$command 2>/dev/null >/dev/null; then
+							[ -e "${TMPWORKINGDIRECTORY}/bin/$command" ] || ln -sf $(command -v $prefix$command)  "${TMPWORKINGDIRECTORY}/bin/$command"
+					fi
+			done
+	done
+	export PATH="${TMPWORKINGDIRECTORY}/bin/:$PATH"
+
 
+	mkdir -m 700 "${TMPWORKINGDIRECTORY}/downloaded"
+	if [ "$(id -u)" = '0' ]; then
+		# relax permissions so that running as root with user switching works
+		umask 022
+		chmod 711 "$TMPWORKINGDIRECTORY"
+		chown _apt:$(id -gn) "${TMPWORKINGDIRECTORY}/downloaded"
+	fi
+
+	TESTDIRECTORY="$(readlink -f "$(dirname $0)")"
+	# Find the newest build directory (sets PROJECT_BINARY_DIR)
+	find_project_binary_dir
         # allow overriding the default BUILDDIR location
-	BUILDDIRECTORY=${APT_INTEGRATION_TESTS_BUILD_DIR:-"${TESTDIRECTORY}/../../build/bin"}
-	LIBRARYPATH=${APT_INTEGRATION_TESTS_LIBRARY_PATH:-"${BUILDDIRECTORY}"}
-        METHODSDIR=${APT_INTEGRATION_TESTS_METHODS_DIR:-"${BUILDDIRECTORY}/methods"}
-        APTHELPERBINDIR=${APT_INTEGRATION_TESTS_LIBEXEC_DIR:-"${BUILDDIRECTORY}"}
-        APTWEBSERVERBINDIR=${APT_INTEGRATION_TESTS_WEBSERVER_BIN_DIR:-"${BUILDDIRECTORY}"}
+	SOURCEDIRECTORY="${APT_INTEGRATION_TESTS_SOURCE_DIR:-"${TESTDIRECTORY}/../../"}"
+	BUILDDIRECTORY="${APT_INTEGRATION_TESTS_BUILD_DIR:-"${PROJECT_BINARY_DIR}/cmdline"}"
+	LIBRARYPATH="${APT_INTEGRATION_TESTS_LIBRARY_PATH:-"${BUILDDIRECTORY}/../apt-pkg"}"
+        METHODSDIR="${APT_INTEGRATION_TESTS_METHODS_DIR:-"${BUILDDIRECTORY}/../methods"}"
+        APTHELPERBINDIR="${APT_INTEGRATION_TESTS_LIBEXEC_DIR:-"${BUILDDIRECTORY}"}"
+        APTTESTHELPERSBINDIR="${APT_INTEGRATION_TESTS_HELPERS_BIN_DIR:-"${BUILDDIRECTORY}/../test/interactive-helper"}"
+        APTFTPARCHIVEBINDIR="${APT_INTEGRATION_TESTS_FTPARCHIVE_BIN_DIR:-"${BUILDDIRECTORY}/../ftparchive"}"
+        APTINTERNALSOLVER="${APT_INTEGRATION_TESTS_INTERNAL_SOLVER:-"${BUILDDIRECTORY}/solvers/apt"}"
+	APTDUMPSOLVER="${APT_INTEGRATION_TESTS_DUMP_SOLVER:-"${BUILDDIRECTORY}/solvers/dump"}"
+	APTINTERNALPLANNER="${APT_INTEGRATION_TESTS_INTERNAL_PLANNER:-"${BUILDDIRECTORY}/planners/apt"}"
 	test -x "${BUILDDIRECTORY}/apt-get" || msgdie "You need to build tree first"
         # -----
 
-	addtrap "cd /; rm -rf $TMPWORKINGDIRECTORY;"
-	cd $TMPWORKINGDIRECTORY
+	cd "$TMPWORKINGDIRECTORY"
 	mkdir rootdir aptarchive keys
 	cd rootdir
 	mkdir -p etc/apt/apt.conf.d etc/apt/sources.list.d etc/apt/trusted.gpg.d etc/apt/preferences.d
-	mkdir -p var/cache var/lib/apt var/log tmp
+	mkdir -p usr/bin var/cache var/lib var/log var/crash tmp
 	mkdir -p var/lib/dpkg/info var/lib/dpkg/updates var/lib/dpkg/triggers
+	mkdir -p usr/lib/apt/solvers usr/lib/apt/planners
 	touch var/lib/dpkg/available
-	mkdir -p usr/lib/apt
-	ln -s ${METHODSDIR} usr/lib/apt/methods
+	ln -s "${METHODSDIR}" usr/lib/apt/methods
+	ln -s "${APTDUMPSOLVER}" usr/lib/apt/solvers/dump
+	ln -s "${APTDUMPSOLVER}" usr/lib/apt/planners/dump
+	ln -s "${APTINTERNALSOLVER}" usr/lib/apt/solvers/apt
+	ln -s "${APTINTERNALPLANNER}" usr/lib/apt/planners/apt
+	echo "Dir::Bin::Solvers \"${TMPWORKINGDIRECTORY}/rootdir/usr/lib/apt/solvers\";" >> ../aptconfig.conf
+	echo "Dir::Bin::Planners \"${TMPWORKINGDIRECTORY}/rootdir/usr/lib/apt/planners\";" >> ../aptconfig.conf
         # use the autoremove from the BUILDDIRECTORY if its there, otherwise
         # system
-        if [ -e ${BUILDDIRECTORY}/../../debian/apt.conf.autoremove ]; then
-	    ln -s ${BUILDDIRECTORY}/../../debian/apt.conf.autoremove etc/apt/apt.conf.d/01autoremove
+        if [ -z "${APT_INTEGRATION_TESTS_SOURCE_DIR}" ]; then
+	    ln -s "${SOURCEDIRECTORY}/debian/apt.conf.autoremove" etc/apt/apt.conf.d/01autoremove
         else
 	    ln -s /etc/apt/apt.conf.d/01autoremove etc/apt/apt.conf.d/01autoremove
         fi
 	cd ..
-	local PACKAGESFILE=$(echo "$(basename $0)" | sed -e 's/^test-/Packages-/' -e 's/^skip-/Packages-/')
+	local BASENAME="${0##*/}"
+	local PACKAGESFILE="Packages-${BASENAME#*-}"
 	if [ -f "${TESTDIRECTORY}/${PACKAGESFILE}" ]; then
 		cp "${TESTDIRECTORY}/${PACKAGESFILE}" aptarchive/Packages
 	fi
-	local SOURCESSFILE=$(echo "$(basename $0)" | sed -e 's/^test-/Sources-/' -e 's/^skip-/Sources-/')
+	local SOURCESSFILE="Sources-${BASENAME#*-}"
 	if [ -f "${TESTDIRECTORY}/${SOURCESSFILE}" ]; then
 		cp "${TESTDIRECTORY}/${SOURCESSFILE}" aptarchive/Sources
 	fi
-	cp $(find $TESTDIRECTORY -name '*.pub' -o -name '*.sec') keys/
-	ln -s ${TMPWORKINGDIRECTORY}/keys/joesixpack.pub rootdir/etc/apt/trusted.gpg.d/joesixpack.gpg
-	echo "Dir \"${TMPWORKINGDIRECTORY}/rootdir\";" > aptconfig.conf
-	echo "Dir::state::status \"${TMPWORKINGDIRECTORY}/rootdir/var/lib/dpkg/status\";" >> aptconfig.conf
-	echo "Debug::NoLocking \"true\";" >> aptconfig.conf
+	find "$TESTDIRECTORY" \( -name '*.pub' -o -name '*.sec' \) -exec cp '{}' keys/ \;
+	chmod 644 keys/*
+	ln -s "${TMPWORKINGDIRECTORY}/keys/joesixpack.pub" rootdir/etc/apt/trusted.gpg.d/joesixpack.gpg
+
+	echo "Dir \"${TMPWORKINGDIRECTORY}/rootdir\";" >> aptconfig.conf
+	echo "Dir::Etc \"etc\";" >> aptconfig.conf
+	echo "Dir::State \"var/lib/apt\";" >> aptconfig.conf
+	echo "Dir::Cache \"var/cache/apt\";" >> aptconfig.conf
+	echo "Dir::Etc \"etc/apt\";" >> aptconfig.conf
+	echo "Dir::Log \"var/log/apt\";" >> aptconfig.conf
 	echo "APT::Get::Show-User-Simulation-Note \"false\";" >> aptconfig.conf
-	echo "Dir::Bin::Methods \"${METHODSDIR}\";" >> aptconfig.conf
-	echo "Dir::Bin::dpkg \"fakeroot\";" >> aptconfig.conf
-	echo "DPKG::options:: \"dpkg\";" >> aptconfig.conf
-	echo "DPKG::options:: \"--root=${TMPWORKINGDIRECTORY}/rootdir\";" >> aptconfig.conf
-	echo "DPKG::options:: \"--force-not-root\";" >> aptconfig.conf
-	echo "DPKG::options:: \"--force-bad-path\";" >> aptconfig.conf
-	if ! command dpkg --assert-multi-arch >/dev/null 2>&1; then
-		echo "DPKG::options:: \"--force-architecture\";" >> aptconfig.conf # Added to test multiarch before dpkg is ready for it…
-	fi
-	echo "DPKG::options:: \"--log=${TMPWORKINGDIRECTORY}/rootdir/var/log/dpkg.log\";" >> aptconfig.conf
-	echo 'quiet::NoUpdate "true";' >> aptconfig.conf
-	echo "Acquire::https::CaInfo \"${TESTDIR}/apt.pem\";" > rootdir/etc/apt/apt.conf.d/99https
-        echo "Apt::Cmd::Disable-Script-Warning \"1\";" > rootdir/etc/apt/apt.conf.d/apt-binary
+	echo "Dir::Bin::Methods \"${TMPWORKINGDIRECTORY}/rootdir/usr/lib/apt/methods\";" >> aptconfig.conf
+	# either store apt-key were we can access it, even if we run it as a different user
+	#cp "${BUILDDIRECTORY}/apt-key" "${TMPWORKINGDIRECTORY}/rootdir/usr/bin/"
+	#chmod o+rx "${TMPWORKINGDIRECTORY}/rootdir/usr/bin/apt-key"
+	#echo "Dir::Bin::apt-key \"${TMPWORKINGDIRECTORY}/rootdir/usr/bin/apt-key\";" >> aptconfig.conf
+	# destroys coverage reporting though, so we disable changing user for the calling gpgv
+	echo "Dir::Bin::apt-key \"${BUILDDIRECTORY}/apt-key\";" >> aptconfig.conf
+	if [ "$(id -u)" = '0' ]; then
+		echo 'Binary::gpgv::APT::Sandbox::User "root";' >> aptconfig.conf
+		# same for the solver executables
+		echo 'APT::Solver::RunAsUser "root";' >> aptconfig.conf
+		echo 'APT::Planner::RunAsUser "root";' >> aptconfig.conf
+	fi
+
+	cat > "${TMPWORKINGDIRECTORY}/rootdir/usr/bin/dpkg" <<EOF
+#!/bin/sh
+set -e
+if [ -r '${TMPWORKINGDIRECTORY}/noopchroot.so' ]; then
+	if [ -n "\$LD_LIBRARY_PATH" ]; then
+		export LD_LIBRARY_PATH='${TMPWORKINGDIRECTORY}:'"\${LD_LIBRARY_PATH}"
+	else
+		export LD_LIBRARY_PATH='${TMPWORKINGDIRECTORY}'
+	fi
+	if [ -n "\$LD_PRELOAD" ]; then
+		export LD_PRELOAD="noopchroot.so \${LD_PRELOAD}"
+	else
+		export LD_PRELOAD="noopchroot.so"
+	fi
+fi
+EOF
+	cp "${TMPWORKINGDIRECTORY}/rootdir/usr/bin/dpkg" "${TMPWORKINGDIRECTORY}/rootdir/usr/bin/gdb-dpkg"
+	cat >> "${TMPWORKINGDIRECTORY}/rootdir/usr/bin/dpkg" <<EOF
+exec fakeroot '${DPKG:-dpkg}' --root='${TMPWORKINGDIRECTORY}/rootdir' \\
+	--admindir="${TMPWORKINGDIRECTORY}/rootdir/var/lib/dpkg" \\
+	--log='${TMPWORKINGDIRECTORY}/rootdir/var/log/dpkg.log' \\
+	--force-not-root --force-bad-path "\$@"
+EOF
+	cat >> "${TMPWORKINGDIRECTORY}/rootdir/usr/bin/gdb-dpkg" <<EOF
+exec fakeroot gdb --quiet -ex run '${DPKG:-dpkg}' --args '${DPKG:-dpkg}' --root='${TMPWORKINGDIRECTORY}/rootdir' \\
+	--admindir="${TMPWORKINGDIRECTORY}/rootdir/var/lib/dpkg" \\
+	--log='${TMPWORKINGDIRECTORY}/rootdir/var/log/dpkg.log' \\
+	--force-not-root --force-bad-path "\$@"
+EOF
+	chmod +x "${TMPWORKINGDIRECTORY}/rootdir/usr/bin/dpkg" "${TMPWORKINGDIRECTORY}/rootdir/usr/bin/gdb-dpkg"
+	echo "Dir::Bin::dpkg \"${TMPWORKINGDIRECTORY}/rootdir/usr/bin/dpkg\";" > rootdir/etc/apt/apt.conf.d/99dpkg
+
+	{
+		if ! command dpkg --assert-multi-arch >/dev/null 2>&1; then
+			echo "DPKG::options:: \"--force-architecture\";" # Added to test multiarch before dpkg is ready for it…
+		fi
+		echo 'quiet "0";'
+		echo 'quiet::NoUpdate "true";'
+		echo 'quiet::NoStatistic "true";'
+		# too distracting for users, but helpful to detect changes
+		echo 'Acquire::Progress::Ignore::ShowErrorText "true";'
+		echo 'Acquire::Progress::Diffpercent "true";'
+		# in testcases, it can appear as if localhost has a rotation setup,
+		# hide this as we can't really deal with it properly
+		echo 'Acquire::Failure::ShowIP "false";'
+		# randomess and tests don't play well together
+		echo 'Acquire::IndexTargets::Randomized "false";'
+		# fakeroot can't fake everything, so disabled in production but good for tests
+		echo 'APT::Sandbox::Verify "true";'
+	} >> aptconfig.conf
+
+	cp "${TESTDIRECTORY}/apt.pem" "${TMPWORKINGDIRECTORY}/rootdir/etc/webserver.pem"
+	if [ "$(id -u)" = '0' ]; then
+		chown _apt:$(id -gn) "${TMPWORKINGDIRECTORY}/rootdir/etc/webserver.pem"
+	fi
+	echo "Acquire::https::CaInfo \"${TMPWORKINGDIRECTORY}/rootdir/etc/webserver.pem\";" > rootdir/etc/apt/apt.conf.d/99https
+	echo "Apt::Cmd::Disable-Script-Warning \"1\";" > rootdir/etc/apt/apt.conf.d/apt-binary
+	export APT_KEY_DONT_WARN_ON_DANGEROUS_USAGE=no
+	echo 'Acquire::Connect::AddrConfig "false";' > rootdir/etc/apt/apt.conf.d/connect-addrconfig
+
 	configcompression '.' 'gz' #'bz2' 'lzma' 'xz'
+	confighashes 'SHA256' # these are tests, not security best-practices
 
-	# gpg needs a trustdb to function, but it can't be invalid (not even empty)
-	# see also apt-key where this trickery comes from:
-	local TRUSTDBDIR="${TMPWORKINGDIRECTORY}/gnupghome"
-	mkdir "$TRUSTDBDIR"
-	chmod 700 "$TRUSTDBDIR"
-	# We also don't use a secret keyring, of course, but gpg panics and
-	# implodes if there isn't one available - and writeable for imports
-	local SECRETKEYRING="${TRUSTDBDIR}/secring.gpg"
-	touch $SECRETKEYRING
-	# now create the trustdb with an (empty) dummy keyring
-	# newer gpg versions are fine without it, but play it safe for now
-	gpg --quiet --check-trustdb --secret-keyring $SECRETKEYRING --keyring $SECRETKEYRING >/dev/null 2>&1
+	# create some files in /tmp and look at user/group to get what this means
+	TEST_DEFAULT_USER="$(id -un)"
+	touch "${TMPWORKINGDIRECTORY}/test-file"
+	TEST_DEFAULT_GROUP=$(stat --format '%G'  "${TMPWORKINGDIRECTORY}/test-file")
 
 	# cleanup the environment a bit
-	export PATH="${PATH}:/usr/local/sbin:/usr/sbin:/sbin"
-	export LC_ALL=C.UTF-8
+	# prefer our apt binaries over the system apt binaries
+	export PATH="${BUILDDIRECTORY}:${PATH}:/usr/local/sbin:/usr/sbin:/sbin"
+	export LC_ALL=C
 	unset LANGUAGE APT_CONFIG
 	unset GREP_OPTIONS DEB_BUILD_PROFILES
+	unset http_proxy HTTP_PROXY https_proxy HTTPS_PROXY no_proxy
+
+	# If gpgv supports --weak-digest, pass it to make sure we can disable SHA1
+	if aptkey verify --weak-digest SHA1 --help 2>/dev/null >/dev/null; then
+		echo 'Acquire::gpgv::Options { "--weak-digest"; "sha1"; };' > rootdir/etc/apt/apt.conf.d/no-sha1
+	fi
+
+	# most tests just need one signed Release file, not both
+	export APT_DONT_SIGN='Release.gpg'
+
+	if [ -r "${TESTDIRECTORY}/extra-environment" ]; then
+		. "${TESTDIRECTORY}/extra-environment"
+	fi
 
 	msgdone "info"
 }
@@ -266,7 +501,7 @@ getarchitecture() {
 }
 
 getarchitectures() {
-	echo "$(aptconfig dump | grep APT::Architecture | cut -d'"' -f 2 | sed '/^$/ d' | sort | uniq | tr '\n' ' ')"
+	aptconfig dump --no-empty --format '%v%n' APT::Architecture APT::Architectures | sort -u | tr '\n' ' '
 }
 
 getarchitecturesfromcommalist() {
@@ -286,98 +521,220 @@ configarchitecture() {
 
 configdpkg() {
 	if [ ! -e rootdir/var/lib/dpkg/status ]; then
-		local STATUSFILE=$(echo "$(basename $0)" | sed -e 's/^test-/status-/' -e 's/^skip-/status-/')
+		local BASENAME="${0##*/}"
+		local STATUSFILE="status-${BASENAME#*-}"
 		if [ -f "${TESTDIRECTORY}/${STATUSFILE}" ]; then
 			cp "${TESTDIRECTORY}/${STATUSFILE}" rootdir/var/lib/dpkg/status
+			# Add an empty line to the end if there is none
+			if tail -1 rootdir/var/lib/dpkg/status | grep -q .; then
+				echo >> rootdir/var/lib/dpkg/status
+			fi
 		else
 			echo -n > rootdir/var/lib/dpkg/status
 		fi
 	fi
 	rm -f rootdir/etc/apt/apt.conf.d/00foreigndpkg
-	if command dpkg --assert-multi-arch >/dev/null 2>&1 ; then
+	# make sure dpkg can detect itself as capable of it
+	if [ "0" = "$(dpkg -l dpkg 2> /dev/null | grep '^i' | wc -l)" ]; then
+		# dpkg doesn't really check the version as long as it is fully installed,
+		# but just to be sure we choose one above the required version
+		insertinstalledpackage 'dpkg' "all" '1.16.2+fake'
+	fi
+	if dpkg --assert-multi-arch >/dev/null 2>&1 ; then
 		local ARCHS="$(getarchitectures)"
-		if echo "$ARCHS" | grep -E -q '[^ ]+ [^ ]+'; then
-			DPKGARCH="$(dpkg --print-architecture)"
-			for ARCH in ${ARCHS}; do
-				if [ "${ARCH}" != "${DPKGARCH}" ]; then
-					if ! dpkg --add-architecture ${ARCH} >/dev/null 2>&1; then
-						# old-style used e.g. in Ubuntu-P – and as it seems travis
-						echo "DPKG::options:: \"--foreign-architecture\";" >> rootdir/etc/apt/apt.conf.d/00foreigndpkg
-						echo "DPKG::options:: \"${ARCH}\";"  >> rootdir/etc/apt/apt.conf.d/00foreigndpkg
-					fi
+		local DPKGARCH="$(dpkg --print-architecture)"
+		# this ensures that even if multi-arch isn't active in the view
+		# of apt, given that dpkg can't be told which arch is native
+		# the arch apt treats as native might be foreign for dpkg
+		for ARCH in ${ARCHS}; do
+			if [ "${ARCH}" != "${DPKGARCH}" ]; then
+				if ! dpkg --add-architecture ${ARCH} >/dev/null 2>&1; then
+					# old-style used e.g. in Ubuntu-P – and as it seems travis
+					echo "DPKG::options:: \"--foreign-architecture\";" >> rootdir/etc/apt/apt.conf.d/00foreigndpkg
+					echo "DPKG::options:: \"${ARCH}\";"  >> rootdir/etc/apt/apt.conf.d/00foreigndpkg
 				fi
-			done
-			if [ "0" = "$(dpkg -l dpkg 2> /dev/null | grep '^i' | wc -l)" ]; then
-				# dpkg doesn't really check the version as long as it is fully installed,
-				# but just to be sure we choose one above the required version
-				insertinstalledpackage 'dpkg' "all" '1.16.2+fake'
 			fi
-		fi
+		done
 	fi
 }
 
+configdpkgnoopchroot() {
+	# create a library to noop chroot() and rewrite maintainer script executions
+	# via execvp() as used by dpkg as we don't want our rootdir to be a fullblown
+	# chroot directory dpkg could chroot into to execute the maintainer scripts
+	msgtest 'Building library to preload to make maintainerscript work in' 'dpkg'
+	cat > noopchroot.c << EOF
+#define _GNU_SOURCE
+#include <stdio.h>
+#include <stdlib.h>
+#include <string.h>
+#include <dlfcn.h>
+
+static char * chrootdir = NULL;
+
+int chroot(const char *path) {
+	printf("WARNING: CHROOTing to %s was ignored!\n", path);
+	free(chrootdir);
+	chrootdir = strdup(path);
+	return 0;
+}
+int execvp(const char *file, char *const argv[]) {
+	static int (*func_execvp) (const char *, char * const []) = NULL;
+	if (func_execvp == NULL)
+		func_execvp = (int (*) (const char *, char * const [])) dlsym(RTLD_NEXT, "execvp");
+	if (chrootdir == NULL || strncmp(file, "/var/lib/dpkg/", strlen("/var/lib/dpkg/")) != 0)
+		return func_execvp(file, argv);
+	printf("REWRITE execvp call %s into %s\n", file, chrootdir);
+	char *newfile;
+	if (asprintf(&newfile, "%s%s", chrootdir, file) == -1) {
+		perror("asprintf");
+		return -1;
+	}
+	char const * const baseadmindir = "/var/lib/dpkg";
+	char *admindir;
+	if (asprintf(&admindir, "%s%s", chrootdir, baseadmindir) == -1) {
+		perror("asprintf");
+		return -1;
+	}
+	setenv("DPKG_ADMINDIR", admindir, 1);
+	return func_execvp(newfile, argv);
+}
+EOF
+	if cc -ldl 2>&1 | grep -q dl; then
+		testempty --nomsg cc -Wall -Wextra -fPIC -shared -o noopchroot.so noopchroot.c
+	else
+		testempty --nomsg cc -Wall -Wextra -fPIC -shared -o noopchroot.so noopchroot.c -ldl
+	fi
+}
 configcompression() {
+	if [ "$1" = 'ALL' ]; then
+		configcompression '.' $(aptconfig dump APT::Compressor --format '%t %v%n' | sed -n 's#^Extension \.\(.*\)$#\1#p')
+		return
+	fi
+	local CMD='apthelper cat-file -C'
 	while [ -n "$1" ]; do
 		case "$1" in
-		'.') echo ".\t.\tcat";;
-		'gz') echo "gzip\tgz\tgzip";;
-		'bz2') echo "bzip2\tbz2\tbzip2";;
-		'lzma') echo "lzma\tlzma\txz --format=lzma";;
-		'xz') echo "xz\txz\txz";;
-		*) echo "$1\t$1\t$1";;
+		'.') printf ".\t.\tcat\n";;
+		'gz') printf "gzip\tgz\t$CMD $1\n";;
+		'bz2') printf "bzip2\tbz2\t$CMD $1\n";;
+		*) printf "$1\t$1\t$CMD $1\n";;
 		esac
 		shift
-	done > ${TMPWORKINGDIRECTORY}/rootdir/etc/testcase-compressor.conf
+	done > "${TMPWORKINGDIRECTORY}/rootdir/etc/testcase-compressor.conf"
+}
+confighashes() {
+	{
+		echo 'APT::FTPArchive {'
+		{
+			while [ -n "$1" ]; do
+				printf "$1" | tr 'a-z' 'A-Z'
+				printf "\t\"true\";\n"
+				shift
+			done
+			for h in 'MD5' 'SHA1' 'SHA256' 'SHA512'; do
+				printf "$h\t\"false\";\n"
+			done
+		} | awk '!x[$1]++'
+		echo '};'
+	} >> "${TMPWORKINGDIRECTORY}/rootdir/etc/apt/apt.conf.d/ftparchive-hashes.conf"
+}
+forcecompressor() {
+	COMPRESSOR="$1"
+	COMPRESS="$1"
+	COMPRESSOR_CMD="apthelper cat-file -C $1"
+	case $COMPRESSOR in
+	gzip) COMPRESS='gz';;
+	bzip2) COMPRESS='bz2';;
+	esac
+	local CONFFILE="${TMPWORKINGDIRECTORY}/rootdir/etc/apt/apt.conf.d/00force-compressor"
+	echo "Acquire::CompressionTypes::Order { \"${COMPRESS}\"; };
+Dir::Bin::uncompressed \"/does/not/exist\";" > "$CONFFILE"
+	for COMP in $(aptconfig dump 'APT::Compressor' --format '%f%n' | cut -d':' -f 5 | uniq); do
+		if [ -z "$COMP" -o "$COMP" = '.' -o "$COMP" = "$COMPRESSOR" ]; then continue; fi
+		echo "Dir::Bin::${COMP} \"/does/not/exist\";" >> "$CONFFILE"
+		echo "APT::Compressor::${COMP}::Name \"${COMP}-disabled\";" >> "$CONFFILE"
+	done
 }
 
-setupsimplenativepackage() {
+_setupsimplenativepackage() {
 	local NAME="$1"
 	local ARCH="$2"
 	local VERSION="$3"
 	local RELEASE="${4:-unstable}"
 	local DEPENDENCIES="$5"
-	local DESCRIPTION="${6:-"an autogenerated dummy ${NAME}=${VERSION}/${RELEASE}
+	local DESCRIPTION="${6:-an autogenerated dummy ${NAME}=${VERSION}/${RELEASE}
  If you find such a package installed on your system,
  something went horribly wrong! They are autogenerated
- und used only by testcases and surf no other propose…"}"
+ und used only by testcases and serve no other purpose…}"
 
 	local SECTION="${7:-others}"
+	local PRIORITY="${8:-optional}"
+	local FILE_TREE="$9"
+	local COMPRESS_TYPE="${10:-gzip}"
 	local DISTSECTION
-	if [ "$SECTION" = "$(echo "$SECTION" | cut -d'/' -f 2)" ]; then
+	if [ "$SECTION" = "${SECTION#*/}" ]; then
 		DISTSECTION="main"
 	else
-		DISTSECTION="$(echo "$SECTION" | cut -d'/' -f 1)"
+		DISTSECTION="${SECTION%/*}"
 	fi
-	local BUILDDIR=incoming/${NAME}-${VERSION}
-	mkdir -p ${BUILDDIR}/debian/source
-	cd ${BUILDDIR}
-	echo "* most suckless software product ever" > FEATURES
-	test -e debian/copyright || echo "Copyleft by Joe Sixpack $(date +%Y)" > debian/copyright
-	test -e debian/changelog || echo "$NAME ($VERSION) $RELEASE; urgency=low
+	local BUILDDIR="${TMPWORKINGDIRECTORY}/incoming/${NAME}-${VERSION}"
+
+	mkdir -p "$BUILDDIR/debian/source"
+	echo "* most suckless software product ever" > "${BUILDDIR}/FEATURES"
+	echo "#!/bin/sh
+echo '$NAME says \"Hello!\"'" > "${BUILDDIR}/${NAME}"
+
+	echo "Copyleft by Joe Sixpack $(date -u +%Y)" > "${BUILDDIR}/debian/copyright"
+	echo "$NAME ($VERSION) $RELEASE; urgency=low
 
   * Initial release
 
- -- Joe Sixpack <joe@example.org>  $(date -R)" > debian/changelog
-	test -e debian/control || echo "Source: $NAME
-Section: $SECTION
-Priority: optional
+ -- Joe Sixpack <joe@example.org>  $(date -u -R)" > "${BUILDDIR}/debian/changelog"
+	{
+		echo "Source: $NAME
+Priority: $PRIORITY
 Maintainer: Joe Sixpack <joe@example.org>
-Build-Depends: debhelper (>= 7)
-Standards-Version: 3.9.1
+Standards-Version: 3.9.3"
+		if [ "$SECTION" != '<none>' ]; then
+			echo "Section: $SECTION"
+		fi
+		local BUILDDEPS="$(printf "%b\n" "$DEPENDENCIES" | grep '^Build-')"
+		test -z "$BUILDDEPS" || echo "$BUILDDEPS"
+		echo "
+Package: $NAME"
 
-Package: $NAME" > debian/control
-	if [ "$ARCH" = 'all' ]; then
-		echo "Architecture: all" >> debian/control
+		if [ "$ARCH" = 'all' ]; then
+			echo "Architecture: all"
+		else
+			echo "Architecture: any"
+		fi
+		local DEPS="$(printf "%b\n" "$DEPENDENCIES" | grep -v '^Build-')"
+		test -z "$DEPS" || echo "$DEPS"
+		printf "%b\n" "Description: $DESCRIPTION"
+	} > "${BUILDDIR}/debian/control"
+
+	echo '3.0 (native)' > "${BUILDDIR}/debian/source/format"
+}
+
+make_tiny_rules() {
+	local OUT="$1"
+	if command -v gmake >/dev/null 2>&1; then
+		[ -e ${TMPWORKINGDIRECTORY}/bin/make ] || ln -s $(command -v gmake) ${TMPWORKINGDIRECTORY}/bin/make
+		echo "#!${TMPWORKINGDIRECTORY}/bin/make -f" > "$OUT"
 	else
-		echo "Architecture: any" >> debian/control
+		echo '#!/usr/bin/make -f' > "$OUT"
 	fi
-	test -z "$DEPENDENCIES" || echo "$DEPENDENCIES" >> debian/control
-	echo "Description: $DESCRIPTION" >> debian/control
+	echo '%:' >> "$OUT"
+	echo '	dh $@' >> "$OUT"
+}
 
-	test -e debian/compat || echo "7" > debian/compat
-	test -e debian/source/format || echo "3.0 (native)" > debian/source/format
-	test -e debian/rules || cp /usr/share/doc/debhelper/examples/rules.tiny debian/rules
-	cd - > /dev/null
+setupsimplenativepackage() {
+	_setupsimplenativepackage "$@"
+	local NAME="$1"
+	local VERSION="$3"
+	local BUILDDIR="${TMPWORKINGDIRECTORY}/incoming/${NAME}-${VERSION}"
+	test -e "${BUILDDIR}/debian/compat" || echo '7' > "${BUILDDIR}/debian/compat"
+	test -e  "${BUILDDIR}/debian/rules" || make_tiny_rules "${BUILDDIR}/debian/rules"
 }
 
 buildsimplenativepackage() {
@@ -386,91 +743,62 @@ buildsimplenativepackage() {
 	local VERSION="$3"
 	local RELEASE="${4:-unstable}"
 	local DEPENDENCIES="$5"
-	local DESCRIPTION="${6:-"an autogenerated dummy ${NAME}=${VERSION}/${RELEASE}
- If you find such a package installed on your system,
- something went horribly wrong! They are autogenerated
- und used only by testcases and surf no other propose…"}"
-
+	local DESCRIPTION="$6"
 	local SECTION="${7:-others}"
 	local PRIORITY="${8:-optional}"
-        local FILE_TREE="$9"
-        local COMPRESS_TYPE="${10:-gzip}"
+	local FILE_TREE="$9"
+	local COMPRESS_TYPE="${10:-gzip}"
 	local DISTSECTION
-	if [ "$SECTION" = "$(echo "$SECTION" | cut -d'/' -f 2)" ]; then
+	if [ "$SECTION" = "${SECTION#*/}" ]; then
 		DISTSECTION="main"
 	else
-		DISTSECTION="$(echo "$SECTION" | cut -d'/' -f 1)"
+		DISTSECTION="${SECTION%/*}"
 	fi
-	local BUILDDIR=${TMPWORKINGDIRECTORY}/incoming/${NAME}-${VERSION}
-
-	msgninfo "Build package ${NAME} in ${VERSION} for ${RELEASE} in ${DISTSECTION}… "
-	mkdir -p $BUILDDIR/debian/source
-	echo "* most suckless software product ever" > ${BUILDDIR}/FEATURES
-	echo "#!/bin/sh
-echo '$NAME says \"Hello!\"'" > ${BUILDDIR}/${NAME}
-
-	echo "Copyleft by Joe Sixpack $(date +%Y)" > ${BUILDDIR}/debian/copyright
-	echo "$NAME ($VERSION) $RELEASE; urgency=low
-
-  * Initial release
-
- -- Joe Sixpack <joe@example.org>  $(date -R)" > ${BUILDDIR}/debian/changelog
-	echo "Source: $NAME
-Section: $SECTION
-Priority: $PRIORITY
-Maintainer: Joe Sixpack <joe@example.org>
-Standards-Version: 3.9.3" > ${BUILDDIR}/debian/control
-	local BUILDDEPS="$(echo "$DEPENDENCIES" | grep '^Build-')"
-	test -z "$BUILDDEPS" || echo "$BUILDDEPS" >> ${BUILDDIR}/debian/control
-	echo "
-Package: $NAME" >> ${BUILDDIR}/debian/control
-
-	if [ "$ARCH" = 'all' ]; then
-		echo "Architecture: all" >> ${BUILDDIR}/debian/control
-	else
-		echo "Architecture: any" >> ${BUILDDIR}/debian/control
-	fi
-	local DEPS="$(echo "$DEPENDENCIES" | grep -v '^Build-')"
-	test -z "$DEPS" || echo "$DEPS" >> ${BUILDDIR}/debian/control
-	echo "Description: $DESCRIPTION" >> ${BUILDDIR}/debian/control
-
-	echo '3.0 (native)' > ${BUILDDIR}/debian/source/format
-	(cd ${BUILDDIR}/..; dpkg-source -b ${NAME}-${VERSION} 2>&1) | sed -n 's#^dpkg-source: info: building [^ ]\+ in ##p' \
+	local BUILDDIR="${TMPWORKINGDIRECTORY}/incoming/${NAME}-${VERSION}"
+	msgtest "Build source package in version ${VERSION} for ${RELEASE} in ${DISTSECTION}" "$NAME"
+	_setupsimplenativepackage "$@"
+	cd "${BUILDDIR}/.."
+	testsuccess --nomsg dpkg-source -b ${NAME}-${VERSION}
+	cd - >/dev/null
+	sed -n 's#^dpkg-source: info: building [^ ]\+ in ##p' "${TMPWORKINGDIRECTORY}/rootdir/tmp/testsuccess.output" \
 		| while read SRC; do
-		echo "pool/${SRC}" >> ${BUILDDIR}/../${RELEASE}.${DISTSECTION}.srclist
+		echo "pool/${SRC}" >> "${BUILDDIR}/../${RELEASE}.${DISTSECTION}.srclist"
 #		if expr match "${SRC}" '.*\.dsc' >/dev/null 2>&1; then
-#			gpg --yes --secret-keyring ./keys/joesixpack.sec \
-#				--keyring ./keys/joesixpack.pub --default-key 'Joe Sixpack' \
+#			aptkey --keyring ./keys/joesixpack.pub --secret-keyring ./keys/joesixpack.sec --quiet --readonly \
+#				adv --yes --default-key 'Joe Sixpack' \
 #				--clearsign -o "${BUILDDIR}/../${SRC}.sign" "${BUILDDIR}/../$SRC"
 #			mv "${BUILDDIR}/../${SRC}.sign" "${BUILDDIR}/../$SRC"
 #		fi
 	done
 
 	for arch in $(getarchitecturesfromcommalist "$ARCH"); do
-		rm -rf ${BUILDDIR}/debian/tmp
-		mkdir -p ${BUILDDIR}/debian/tmp/DEBIAN ${BUILDDIR}/debian/tmp/usr/share/doc/${NAME} ${BUILDDIR}/debian/tmp/usr/bin
-		cp ${BUILDDIR}/debian/copyright ${BUILDDIR}/debian/changelog ${BUILDDIR}/FEATURES ${BUILDDIR}/debian/tmp/usr/share/doc/${NAME}
-		cp ${BUILDDIR}/${NAME} ${BUILDDIR}/debian/tmp/usr/bin/${NAME}-${arch}
+		msgtest "Build binary package for ${RELEASE} in ${SECTION}" "$NAME"
+		rm -rf "${BUILDDIR}/debian/tmp"
+		mkdir -p "${BUILDDIR}/debian/tmp/DEBIAN" "${BUILDDIR}/debian/tmp/usr/share/doc/${NAME}" "${BUILDDIR}/debian/tmp/usr/bin"
+		cp "${BUILDDIR}/debian/copyright" "${BUILDDIR}/debian/changelog" "${BUILDDIR}/FEATURES" "${BUILDDIR}/debian/tmp/usr/share/doc/${NAME}"
+		cp "${BUILDDIR}/${NAME}" "${BUILDDIR}/debian/tmp/usr/bin/${NAME}-${arch}"
                 if [ -n "$FILE_TREE" ]; then
-                    cp -ar "$FILE_TREE" ${BUILDDIR}/debian/tmp
+                    cp -ar "$FILE_TREE" "${BUILDDIR}/debian/tmp"
                 fi
 
-		(cd ${BUILDDIR}; dpkg-gencontrol -DArchitecture=$arch)
-		(cd ${BUILDDIR}/debian/tmp; md5sum $(find usr/ -type f) > DEBIAN/md5sums)
+		(cd "${BUILDDIR}"; dpkg-gencontrol -DArchitecture=$arch)
+		(cd "${BUILDDIR}/debian/tmp"; md5sum $(find usr/ -type f) > DEBIAN/md5sums)
 		local LOG="${BUILDDIR}/../${NAME}_${VERSION}_${arch}.dpkg-deb.log"
-		# ensure the right permissions as dpkg-deb ensists
-		chmod 755 ${BUILDDIR}/debian/tmp/DEBIAN
-		if ! dpkg-deb -Z${COMPRESS_TYPE} --build ${BUILDDIR}/debian/tmp ${BUILDDIR}/.. >$LOG 2>&1; then
-			cat $LOG
-			false
-		fi
-		rm $LOG
-		echo "pool/${NAME}_${VERSION}_${arch}.deb" >> ${BUILDDIR}/../${RELEASE}.${DISTSECTION}.pkglist
+		# ensure the right permissions as dpkg-deb insists
+		chmod 755 "${BUILDDIR}/debian/tmp/DEBIAN"
+		testsuccess --nomsg dpkg-deb -Z${COMPRESS_TYPE} --build "${BUILDDIR}/debian/tmp" "${BUILDDIR}/.."
+		echo "pool/${NAME}_${VERSION}_${arch}.deb" >> "${BUILDDIR}/../${RELEASE}.${DISTSECTION}.pkglist"
 	done
 
-	mkdir -p ${BUILDDIR}/../${NAME}_${VERSION}
-	cp ${BUILDDIR}/debian/changelog ${BUILDDIR}/../${NAME}_${VERSION}/
-	cp ${BUILDDIR}/debian/changelog ${BUILDDIR}/../${NAME}_${VERSION}.changelog
+	local NM
+	if [ "$(echo "$NAME" | cut -c 1-3)" = 'lib' ]; then
+		NM="$(echo "$NAME" | cut -c 1-4)"
+	else
+		NM="$(echo "$NAME" | cut -c 1)"
+	fi
+	local CHANGEPATH="${BUILDDIR}/../${DISTSECTION}/${NM}/${NAME}/${NAME}_${VERSION}"
+	mkdir -p "$CHANGEPATH"
+	cp "${BUILDDIR}/debian/changelog" "$CHANGEPATH"
 	rm -rf "${BUILDDIR}"
 	msgdone "info"
 }
@@ -482,25 +810,22 @@ buildpackage() {
 	local ARCH=$(getarchitecture $4)
 	local PKGNAME="$(echo "$BUILDDIR" | grep -o '[^/]*$')"
 	local BUILDLOG="$(readlink -f "${BUILDDIR}/../${PKGNAME}_${RELEASE}_${SECTION}.dpkg-bp.log")"
-	msgninfo "Build package ${PKGNAME} for ${RELEASE} in ${SECTION}… "
-	cd $BUILDDIR
+	msgtest "Build package for ${RELEASE} in ${SECTION}" "$PKGNAME"
+	cd "$BUILDDIR"
 	if [ "$ARCH" = "all" ]; then
 		ARCH="$(dpkg-architecture -qDEB_HOST_ARCH 2> /dev/null)"
 	fi
-	if ! dpkg-buildpackage -uc -us -a$ARCH >$BUILDLOG 2>&1 ; then
-		cat $BUILDLOG
-		false
-	fi
-	local PKGS="$(grep '^dpkg-deb: building package' $BUILDLOG | cut -d'/' -f 2 | sed -e "s#'\.##")"
-	local SRCS="$(grep '^dpkg-source: info: building' $BUILDLOG | grep -o '[a-z0-9._+~-]*$')"
+	testsuccess --nomsg dpkg-buildpackage -uc -us -a$ARCH -d
+	cp "${TMPWORKINGDIRECTORY}/rootdir/tmp/testsuccess.output" "$BUILDLOG"
+	local PKGS="$(grep '^dpkg-deb: building package' "$BUILDLOG" | cut -d'/' -f 2 | sed -e "s#'\.##")"
+	local SRCS="$(grep '^dpkg-source: info: building' "$BUILDLOG" | grep -o '[a-z0-9._+~-]*$')"
 	cd - > /dev/null
 	for PKG in $PKGS; do
-		echo "pool/${PKG}" >> ${TMPWORKINGDIRECTORY}/incoming/${RELEASE}.${SECTION}.pkglist
+		echo "pool/${PKG}" >> "${TMPWORKINGDIRECTORY}/incoming/${RELEASE}.${SECTION}.pkglist"
 	done
 	for SRC in $SRCS; do
-		echo "pool/${SRC}" >> ${TMPWORKINGDIRECTORY}/incoming/${RELEASE}.${SECTION}.srclist
+		echo "pool/${SRC}" >> "${TMPWORKINGDIRECTORY}/incoming/${RELEASE}.${SECTION}.srclist"
 	done
-	msgdone "info"
 }
 
 buildaptarchive() {
@@ -512,66 +837,37 @@ buildaptarchive() {
 }
 
 createaptftparchiveconfig() {
-	local COMPRESSORS="$(cut -d'	' -f 1 ${TMPWORKINGDIRECTORY}/rootdir/etc/testcase-compressor.conf | tr '\n' ' ')"
-	COMPRESSORS="${COMPRESSORS%* }"
-	local ARCHS="$(find pool/ -name '*.deb' | grep -oE '_[a-z0-9-]+\.deb$' | sort | uniq | sed -e '/^_all.deb$/ d' -e 's#^_\([a-z0-9-]*\)\.deb$#\1#' | tr '\n' ' ')"
-	if [ -z "$ARCHS" ]; then
-		# the pool is empty, so we will operate on faked packages - let us use the configured archs
-		ARCHS="$(getarchitectures)"
-	fi
-	echo -n 'Dir {
-	ArchiveDir "' >> ftparchive.conf
-	echo -n $(readlink -f .) >> ftparchive.conf
-	echo -n '";
-	CacheDir "' >> ftparchive.conf
-	echo -n $(readlink -f ..) >> ftparchive.conf
-	echo -n '";
-	FileListDir "' >> ftparchive.conf
-	echo -n $(readlink -f pool/) >> ftparchive.conf
-	echo -n '";
+	local COMPRESSORS="$(cut -d'	' -f 1 "${TMPWORKINGDIRECTORY}/rootdir/etc/testcase-compressor.conf" | tr '\n' ' ')"
+	local COMPRESSORS="${COMPRESSORS%* }"
+	local ARCHS="$(getarchitectures)"
+	cat > ftparchive.conf <<EOF
+Dir {
+	ArchiveDir "$(readlink -f .)";
+	CacheDir "$(readlink -f ..)";
+	FileListDir "$(readlink -f pool/)";
 };
 Default {
-	Packages::Compress "'"$COMPRESSORS"'";
-	Sources::Compress "'"$COMPRESSORS"'";
-	Contents::Compress "'"$COMPRESSORS"'";
-	Translation::Compress "'"$COMPRESSORS"'";
+	Packages::Compress "$COMPRESSORS";
+	Sources::Compress "$COMPRESSORS";
+	Contents::Compress "$COMPRESSORS";
+	Translation::Compress "$COMPRESSORS";
 	LongDescription "false";
 };
 TreeDefault {
 	Directory "pool/";
 	SrcDirectory "pool/";
 };
-APT {
-	FTPArchive {
-		Release {
-			Origin "joesixpack";
-			Label "apttestcases";
-			Suite "unstable";
-			Description "repository with dummy packages";
-			Architectures "' >> ftparchive.conf
-	echo -n "$ARCHS" >> ftparchive.conf
-	echo 'source";
-		};
-	};
-};' >> ftparchive.conf
+EOF
 	for DIST in $(find ./pool/ -maxdepth 1 -name '*.pkglist' -type f | cut -d'/' -f 3 | cut -d'.' -f 1 | sort | uniq); do
-		echo -n 'tree "dists/' >> ftparchive.conf
-		echo -n "$DIST" >> ftparchive.conf
-		echo -n '" {
-	Architectures "' >> ftparchive.conf
-		echo -n "$ARCHS" >> ftparchive.conf
-		echo -n 'source";
-	FileList "' >> ftparchive.conf
-		echo -n "${DIST}.\$(SECTION).pkglist" >> ftparchive.conf
-		echo -n '";
-	SourceFileList "' >> ftparchive.conf
-		echo -n "${DIST}.\$(SECTION).srclist" >> ftparchive.conf
-		echo -n '";
-	Sections "' >> ftparchive.conf
-		echo -n "$(find ./pool/ -maxdepth 1 -name "${DIST}.*.pkglist" -type f | cut -d'/' -f 3 | cut -d'.' -f 2 | sort | uniq | tr '\n' ' ')" >> ftparchive.conf
-		echo '";
-};' >> ftparchive.conf
-	done
+		cat <<EOF
+tree "dists/$DIST" {
+	Architectures "$ARCHS all source";
+	FileList "${DIST}.\$(SECTION).pkglist";
+	SourceFileList "${DIST}.\$(SECTION).srclist";
+	Sections "$(find ./pool/ -maxdepth 1 -name "${DIST}.*.pkglist" -type f | cut -d'/' -f 3 | cut -d'.' -f 2 | sort | uniq | tr '\n' ' ')";
+};
+EOF
+	done >> ftparchive.conf
 }
 
 buildaptftparchivedirectorystructure() {
@@ -581,72 +877,94 @@ buildaptftparchivedirectorystructure() {
 		for SECTION in $SECTIONS; do
 			local ARCHS="$(grep -A 5 "dists/$DIST" ftparchive.conf | grep Architectures | cut -d'"' -f 2 | sed -e 's#source##')"
 			for ARCH in $ARCHS; do
-				mkdir -p dists/${DIST}/${SECTION}/binary-${ARCH}
+				mkdir -p "dists/${DIST}/${SECTION}/binary-${ARCH}"
 			done
-			mkdir -p dists/${DIST}/${SECTION}/source
-			mkdir -p dists/${DIST}/${SECTION}/i18n
+			mkdir -p "dists/${DIST}/${SECTION}/source"
+			mkdir -p "dists/${DIST}/${SECTION}/i18n"
 		done
 	done
 }
 
 insertpackage() {
-	local RELEASE="$1"
+	local RELEASES="$1"
 	local NAME="$2"
 	local ARCH="$3"
 	local VERSION="$4"
 	local DEPENDENCIES="$5"
 	local PRIORITY="${6:-optional}"
-	local DESCRIPTION="${7:-"an autogenerated dummy ${NAME}=${VERSION}/${RELEASE}
+	local DESCRIPTION="${7:-an autogenerated dummy ${NAME}=${VERSION}/${RELEASES}
  If you find such a package installed on your system,
  something went horribly wrong! They are autogenerated
- und used only by testcases and surf no other propose…"}"
+ und used only by testcases and serve no other purpose…}"
 	local ARCHS=""
-	for arch in $(getarchitecturesfromcommalist "$ARCH"); do
-		if [ "$arch" = 'all' -o "$arch" = 'none' ]; then
-			ARCHS="$(getarchitectures)"
-		else
-			ARCHS="$arch"
+	for RELEASE in $(printf '%s' "$RELEASES" | tr ',' '\n'); do
+		if [ "$RELEASE" = 'installed' ]; then
+			insertinstalledpackage "$2" "$3" "$4" "$5" "$6" "$7"
+			continue
 		fi
-		for BUILDARCH in $ARCHS; do
-			local PPATH="aptarchive/dists/${RELEASE}/main/binary-${BUILDARCH}"
-			mkdir -p $PPATH aptarchive/dists/${RELEASE}/main/source
-			touch aptarchive/dists/${RELEASE}/main/source/Sources
-			local FILE="${PPATH}/Packages"
-			echo "Package: $NAME
+		for arch in $(getarchitecturesfromcommalist "$ARCH"); do
+			if [ "$arch" = 'none' ]; then
+				ARCHS="$(getarchitectures)"
+			else
+				ARCHS="$arch"
+			fi
+			for BUILDARCH in $ARCHS; do
+				local PPATH="aptarchive/dists/${RELEASE}/main/binary-${BUILDARCH}"
+				mkdir -p "$PPATH"
+				{
+					echo "Package: $NAME
 Priority: $PRIORITY
 Section: other
 Installed-Size: 42
-Maintainer: Joe Sixpack <joe@example.org>" >> $FILE
-			test "$arch" = 'none' || echo "Architecture: $arch" >> $FILE
-			echo "Version: $VERSION
-Filename: pool/main/${NAME}/${NAME}_${VERSION}_${arch}.deb" >> $FILE
-			test -z "$DEPENDENCIES" || echo "$DEPENDENCIES" >> $FILE
-			echo "Description: $DESCRIPTION" >> $FILE
-			echo >> $FILE
+Maintainer: Joe Sixpack <joe@example.org>"
+					test "$arch" = 'none' || echo "Architecture: $arch"
+					echo "Version: $VERSION
+Filename: pool/main/${NAME}/${NAME}_${VERSION}_${arch}.deb"
+					test -z "$DEPENDENCIES" || printf "%b\n" "$DEPENDENCIES"
+					echo "Description: $(printf '%s' "$DESCRIPTION" | head -n 1)"
+					echo "Description-md5: $(printf '%s' "$DESCRIPTION" | md5sum | cut -d' ' -f 1)"
+					echo "SHA256: 0000000000000000000000000000000000000000000000000000000000000000"
+					echo
+				} >> "${PPATH}/Packages"
+			done
 		done
+		mkdir -p "aptarchive/dists/${RELEASE}/main/source" "aptarchive/dists/${RELEASE}/main/i18n"
+		touch "aptarchive/dists/${RELEASE}/main/source/Sources"
+		echo "Package: $NAME
+Description-md5: $(printf '%s' "$DESCRIPTION" | md5sum | cut -d' ' -f 1)
+Description-en: $DESCRIPTION
+" >> "aptarchive/dists/${RELEASE}/main/i18n/Translation-en"
 	done
 }
 
 insertsource() {
-	local RELEASE="$1"
+	local RELEASES="$1"
 	local NAME="$2"
 	local ARCH="$3"
 	local VERSION="$4"
 	local DEPENDENCIES="$5"
+	local BINARY="${6:-$NAME}"
 	local ARCHS=""
-	local SPATH="aptarchive/dists/${RELEASE}/main/source"
-	mkdir -p $SPATH
-	local FILE="${SPATH}/Sources"
-	echo "Package: $NAME
-Binary: $NAME
+	for RELEASE in $(printf '%s' "$RELEASES" | tr ',' '\n'); do
+		local SPATH="aptarchive/dists/${RELEASE}/main/source"
+		mkdir -p $SPATH
+		local FILE="${SPATH}/Sources"
+		local DSCFILE="${NAME}_${VERSION}.dsc"
+		local TARFILE="${NAME}_${VERSION}.tar.gz"
+		echo "Package: $NAME
+Binary: $BINARY
 Version: $VERSION
 Maintainer: Joe Sixpack <joe@example.org>
 Architecture: $ARCH" >> $FILE
-	test -z "$DEPENDENCIES" || echo "$DEPENDENCIES" >> $FILE
-	echo "Files:
- d41d8cd98f00b204e9800998ecf8427e 0 ${NAME}_${VERSION}.dsc
- d41d8cd98f00b204e9800998ecf8427e 0 ${NAME}_${VERSION}.tar.gz
-" >> $FILE
+		test -z "$DEPENDENCIES" || printf "%b\n" "$DEPENDENCIES" >> "$FILE"
+		echo "Files:
+ $(echo -n "$DSCFILE" | md5sum | cut -d' ' -f 1) $(echo -n "$DSCFILE" | wc -c) "$DSCFILE"
+ $(echo -n "$TARFILE" | md5sum | cut -d' ' -f 1) $(echo -n "$TARFILE" | wc -c) "$TARFILE"
+Checksums-Sha256:
+ $(echo -n "$DSCFILE" | sha256sum | cut -d' ' -f 1) $(echo -n "$DSCFILE" | wc -c) "$DSCFILE"
+ $(echo -n "$TARFILE" | sha256sum | cut -d' ' -f 1) $(echo -n "$TARFILE" | wc -c) "$TARFILE"
+" >> "$FILE"
+	done
 }
 
 insertinstalledpackage() {
@@ -656,10 +974,10 @@ insertinstalledpackage() {
 	local DEPENDENCIES="$4"
 	local PRIORITY="${5:-optional}"
 	local STATUS="${6:-install ok installed}"
-	local DESCRIPTION="${7:-"an autogenerated dummy ${NAME}=${VERSION}/installed
+	local DESCRIPTION="${7:-an autogenerated dummy ${NAME}=${VERSION}/installed
  If you find such a package installed on your system,
  something went horribly wrong! They are autogenerated
- und used only by testcases and surf no other propose…"}"
+ und used only by testcases and serve no other purpose…}"
 
 	local FILE='rootdir/var/lib/dpkg/status'
 	local INFO='rootdir/var/lib/dpkg/info'
@@ -670,36 +988,38 @@ Priority: $PRIORITY
 Section: other
 Installed-Size: 42
 Maintainer: Joe Sixpack <joe@example.org>
-Version: $VERSION" >> $FILE
-		test "$arch" = 'none' || echo "Architecture: $arch" >> $FILE
-		test -z "$DEPENDENCIES" || echo "$DEPENDENCIES" >> $FILE
-		echo "Description: $DESCRIPTION" >> $FILE
-		echo >> $FILE
+Version: $VERSION" >> "$FILE"
+		test "$arch" = 'none' || echo "Architecture: $arch" >> "$FILE"
+		test -z "$DEPENDENCIES" || printf "%b\n" "$DEPENDENCIES" >> "$FILE"
+		printf "%b\n" "Description: $DESCRIPTION" >> "$FILE"
+		echo >> "$FILE"
 		if [ "$(dpkg-query -W --showformat='${Multi-Arch}')" = 'same' ]; then
-			echo -n > ${INFO}/${NAME}:${arch}.list
+			echo -n > "${INFO}/${NAME}:${arch}.list"
 		else
-			echo -n > ${INFO}/${NAME}.list
+			echo -n > "${INFO}/${NAME}.list"
 		fi
 	done
 }
 
 
 buildaptarchivefromincoming() {
-	msginfo "Build APT archive for ${CCMD}$(basename $0)${CINFO} based on incoming packages…"
+	msginfo "Build APT archive for ${CCMD}${0##*/}${CINFO} based on incoming packages…"
 	cd aptarchive
 	[ -e pool ] || ln -s ../incoming pool
 	[ -e ftparchive.conf ] || createaptftparchiveconfig
 	[ -e dists ] || buildaptftparchivedirectorystructure
 	msgninfo "\tGenerate Packages, Sources and Contents files… "
-	aptftparchive -qq generate ftparchive.conf
+	testsuccess aptftparchive generate ftparchive.conf
 	cd - > /dev/null
 	msgdone "info"
-	generatereleasefiles
+	generatereleasefiles "$@"
 }
 
 buildaptarchivefromfiles() {
-	msginfo "Build APT archive for ${CCMD}$(basename $0)${CINFO} based on prebuild files…"
-	find aptarchive -name 'Packages' -o -name 'Sources' | while read line; do
+	msginfo "Build APT archive for ${CCMD}${0##*/}${CINFO} based on prebuild files…"
+	local DIR='aptarchive'
+	if [ -d "${DIR}/dists" ]; then DIR="${DIR}/dists"; fi
+	find "$DIR" -name 'Packages' -o -name 'Sources' -o -name 'Translation-*' | while read line; do
 		msgninfo "\t${line} file… "
 		compressfile "$line" "$1"
 		msgdone "info"
@@ -708,7 +1028,7 @@ buildaptarchivefromfiles() {
 }
 
 compressfile() {
-	cat ${TMPWORKINGDIRECTORY}/rootdir/etc/testcase-compressor.conf | while read compressor extension command; do
+	while read compressor extension command; do
 		if [ "$compressor" = '.' ]; then
 			if [ -n "$2" ]; then
 				touch -d "$2" "$1"
@@ -719,7 +1039,7 @@ compressfile() {
 		if [ -n "$2" ]; then
 			touch -d "$2" "${1}.${extension}"
 		fi
-	done
+	done < "${TMPWORKINGDIRECTORY}/rootdir/etc/testcase-compressor.conf"
 }
 
 # can be overridden by testcases for their pleasure
@@ -731,160 +1051,233 @@ getcodenamefromsuite() {
 }
 getreleaseversionfromsuite() { true; }
 getlabelfromsuite() { true; }
+getoriginfromsuite() { true; }
+getarchitecturesfromreleasefile() { echo "all $(getarchitectures)"; }
+getnotautomaticfromsuite() {
+	case "$1" in
+	experimental|experimental2) echo "yes";;
+	esac
+}
+getbutautomaticupgradesfromsuite() { true; }
 
+aptftparchiverelease() {
+	aptftparchive -qq release "$@" | sed -e '/0 Release$/ d' # remove the self reference
+}
 generatereleasefiles() {
 	# $1 is the Date header and $2 is the ValidUntil header to be set
 	# both should be given in notation date/touch can understand
-	msgninfo "\tGenerate Release files… "
+	local DATE="$1"
+	local VALIDUNTIL="$2"
 	if [ -e aptarchive/dists ]; then
+		msgninfo "\tGenerate Release files for dists… "
 		for dir in $(find ./aptarchive/dists -mindepth 1 -maxdepth 1 -type d); do
+			local ARCHITECTURES="$(getarchitecturesfromreleasefile "$dir")"
 			local SUITE="$(echo "$dir" | cut -d'/' -f 4)"
 			local CODENAME="$(getcodenamefromsuite $SUITE)"
 			local VERSION="$(getreleaseversionfromsuite $SUITE)"
 			local LABEL="$(getlabelfromsuite $SUITE)"
-			if [ -n "$VERSION" ]; then
-				VERSION="-o APT::FTPArchive::Release::Version=${VERSION}"
-			fi
-			if [ -n "$LABEL" ]; then
-				LABEL="-o APT::FTPArchive::Release::Label=${LABEL}"
-			fi
-			aptftparchive -qq release $dir \
+			local ORIGIN="$(getoriginfromsuite $SUITE)"
+			local NOTAUTOMATIC="$(getnotautomaticfromsuite $SUITE)"
+			local BUTAUTOMATICUPGRADES="$(getbutautomaticupgradesfromsuite $SUITE)"
+			aptftparchiverelease "$dir" \
 				-o APT::FTPArchive::Release::Suite="${SUITE}" \
 				-o APT::FTPArchive::Release::Codename="${CODENAME}" \
-				${LABEL} \
-				${VERSION} \
-					| sed -e '/0 Release$/ d' > $dir/Release # remove the self reference
-			if [ "$SUITE" = "experimental" -o "$SUITE" = "experimental2" ]; then
-				sed -i '/^Date: / a\
-NotAutomatic: yes' $dir/Release
-			fi
-			if [ -n "$1" -a "$1" != "now" ]; then
-				sed -i "s/^Date: .*$/Date: $(date -d "$1" '+%a, %d %b %Y %H:%M:%S %Z')/" $dir/Release
-			fi
-			if [ -n "$2" ]; then
-				sed -i "/^Date: / a\
-Valid-Until: $(date -d "$2" '+%a, %d %b %Y %H:%M:%S %Z')" $dir/Release
-			fi
+				-o APT::FTPArchive::Release::Architectures="${ARCHITECTURES}" \
+				-o APT::FTPArchive::Release::Label="${LABEL}" \
+				-o APT::FTPArchive::Release::Origin="${ORIGIN}" \
+				-o APT::FTPArchive::Release::Version="${VERSION}" \
+				-o APT::FTPArchive::Release::NotAutomatic="${NOTAUTOMATIC}" \
+				-o APT::FTPArchive::Release::ButAutomaticUpgrades="${BUTAUTOMATICUPGRADES}" \
+				> "$dir/Release"
 		done
 	else
-		aptftparchive -qq release ./aptarchive | sed -e '/0 Release$/ d' > aptarchive/Release # remove the self reference
+		msgninfo "\tGenerate Release files for flat… "
+		aptftparchiverelease ./aptarchive > aptarchive/Release
 	fi
-	if [ -n "$1" -a "$1" != "now" ]; then
+	if [ -n "$DATE" -a "$DATE" != "now" ]; then
 		for release in $(find ./aptarchive -name 'Release'); do
-			touch -d "$1" $release
+			sed -i "s/^Date: .*$/Date: $(date -u -d "$DATE" -R)/" "$release"
+			touch -d "$DATE" "$release"
 		done
 	fi
+	if [ -n "$VALIDUNTIL" ]; then
+		sed -i "/^Date: / a\
+Valid-Until: $(date -u -d "$VALIDUNTIL" -R)" $(find ./aptarchive -name 'Release')
+	fi
 	msgdone "info"
 }
 
 setupdistsaptarchive() {
-	local APTARCHIVE=$(readlink -f ./aptarchive)
+	local APTARCHIVE="$(readlink -f ./aptarchive | sed 's# #%20#g')"
 	rm -f root/etc/apt/sources.list.d/apt-test-*-deb.list
 	rm -f root/etc/apt/sources.list.d/apt-test-*-deb-src.list
 	for DISTS in $(find ./aptarchive/dists/ -mindepth 1 -maxdepth 1 -type d | cut -d'/' -f 4); do
-		SECTIONS=$(find ./aptarchive/dists/${DISTS}/ -mindepth 1 -maxdepth 1 -type d | cut -d'/' -f 5 | tr '\n' ' ')
+		SECTIONS=$(find "./aptarchive/dists/${DISTS}/" -mindepth 1 -maxdepth 1 -type d | cut -d'/' -f 5 | tr '\n' ' ')
 		msgninfo "\tadd deb and deb-src sources.list lines for ${CCMD}${DISTS} ${SECTIONS}${CINFO}… "
-		echo "deb file://$APTARCHIVE $DISTS $SECTIONS" > rootdir/etc/apt/sources.list.d/apt-test-${DISTS}-deb.list
-		echo "deb-src file://$APTARCHIVE $DISTS $SECTIONS" > rootdir/etc/apt/sources.list.d/apt-test-${DISTS}-deb-src.list
+		echo "deb file://$APTARCHIVE $DISTS $SECTIONS" > "rootdir/etc/apt/sources.list.d/apt-test-${DISTS}-deb.list"
+		echo "deb-src file://$APTARCHIVE $DISTS $SECTIONS" > "rootdir/etc/apt/sources.list.d/apt-test-${DISTS}-deb-src.list"
 		msgdone "info"
 	done
 }
 
 setupflataptarchive() {
-	local APTARCHIVE=$(readlink -f ./aptarchive)
-	if [ -f ${APTARCHIVE}/Packages ]; then
+	local APTARCHIVE="$(readlink -f ./aptarchive)"
+	local APTARCHIVEURI="$(readlink -f ./aptarchive | sed 's# #%20#g')"
+	if [ -f "${APTARCHIVE}/Packages" ]; then
 		msgninfo "\tadd deb sources.list line… "
-		echo "deb file://$APTARCHIVE /" > rootdir/etc/apt/sources.list.d/apt-test-archive-deb.list
-		msgdone "info"
+		echo "deb file://$APTARCHIVEURI /" > 'rootdir/etc/apt/sources.list.d/apt-test-archive-deb.list'
+		msgdone 'info'
 	else
-		rm -f rootdir/etc/apt/sources.list.d/apt-test-archive-deb.list
+		rm -f 'rootdir/etc/apt/sources.list.d/apt-test-archive-deb.list'
 	fi
-	if [ -f ${APTARCHIVE}/Sources ]; then
+	if [ -f "${APTARCHIVE}/Sources" ]; then
 		msgninfo "\tadd deb-src sources.list line… "
-		echo "deb-src file://$APTARCHIVE /" > rootdir/etc/apt/sources.list.d/apt-test-archive-deb-src.list
-		msgdone "info"
+		echo "deb-src file://$APTARCHIVEURI /" > 'rootdir/etc/apt/sources.list.d/apt-test-archive-deb-src.list'
+		msgdone 'info'
 	else
-		rm -f rootdir/etc/apt/sources.list.d/apt-test-archive-deb-src.list
+		rm -f 'rootdir/etc/apt/sources.list.d/apt-test-archive-deb-src.list'
 	fi
 }
 
 setupaptarchive() {
-	buildaptarchive
+	local NOUPDATE=0
+	if [ "$1" = '--no-update' ]; then
+		NOUPDATE=1
+		shift
+	fi
+	buildaptarchive "$@"
 	if [ -e aptarchive/dists ]; then
 		setupdistsaptarchive
 	else
 		setupflataptarchive
 	fi
-	signreleasefiles
-	if [ "$1" != '--no-update' ]; then
-		msgninfo "\tSync APT's cache with the archive… "
-		aptget update -qq
-		msgdone "info"
+	signreleasefiles 'Joe Sixpack'
+	if [ "1" != "$NOUPDATE" ]; then
+		testsuccess aptget update -o Debug::pkgAcquire::Worker=true -o Debug::Acquire::gpgv=true
 	fi
 }
 
 signreleasefiles() {
-	local SIGNER="${1:-Joe Sixpack}"
-	local GPG="gpg --batch --yes"
-	msgninfo "\tSign archive with $SIGNER key… "
+	local SIGNERS="${1:-Joe Sixpack}"
+	local REPODIR="${2:-aptarchive}"
+	if [ -n "$1" ]; then shift; fi
+	if [ -n "$1" ]; then shift; fi
+	local KEY="keys/$(echo "$SIGNERS" | tr 'A-Z' 'a-z' | tr -d ' ,')"
+	msgninfo "\tSign archive with $SIGNERS key $KEY… "
 	local REXKEY='keys/rexexpired'
 	local SECEXPIREBAK="${REXKEY}.sec.bak"
 	local PUBEXPIREBAK="${REXKEY}.pub.bak"
-	if [ "${SIGNER}" = 'Rex Expired' ]; then
-		# the key is expired, so gpg doesn't allow to sign with and the --faked-system-time
-		# option doesn't exist anymore (and using faketime would add a new obscure dependency)
-		# therefore we 'temporary' make the key not expired and restore a backup after signing
-		cp ${REXKEY}.sec $SECEXPIREBAK
-		cp ${REXKEY}.pub $PUBEXPIREBAK
-		local SECUNEXPIRED="${REXKEY}.sec.unexpired"
-		local PUBUNEXPIRED="${REXKEY}.pub.unexpired"
-		if [ -f "$SECUNEXPIRED" ] && [ -f "$PUBUNEXPIRED" ]; then
-			cp $SECUNEXPIRED ${REXKEY}.sec
-			cp $PUBUNEXPIRED ${REXKEY}.pub
-		else
-			printf "expire\n1w\nsave\n" | $GPG --keyring ${REXKEY}.pub --secret-keyring ${REXKEY}.sec --command-fd 0 --edit-key "${SIGNER}" >/dev/null 2>&1 || true
-			cp ${REXKEY}.sec $SECUNEXPIRED
-			cp ${REXKEY}.pub $PUBUNEXPIRED
+	local SIGUSERS=""
+	while [ -n "${SIGNERS%%,*}" ]; do
+		local SIGNER="${SIGNERS%%,*}"
+		if [ "${SIGNERS}" = "${SIGNER}" ]; then
+			SIGNERS=""
+		fi
+		SIGNERS="${SIGNERS#*,}"
+		# FIXME: This should be the full name, but we can't encode the space properly currently
+		SIGUSERS="${SIGUSERS} -u ${SIGNER#* }"
+		if [ "${SIGNER}" = 'Rex Expired' ]; then
+			# the key is expired, so gpg doesn't allow to sign with and the --faked-system-time
+			# option doesn't exist anymore (and using faketime would add a new obscure dependency)
+			# therefore we 'temporary' make the key not expired and restore a backup after signing
+			cp "${REXKEY}.sec" "$SECEXPIREBAK"
+			cp "${REXKEY}.pub" "$PUBEXPIREBAK"
+			local SECUNEXPIRED="${REXKEY}.sec.unexpired"
+			local PUBUNEXPIRED="${REXKEY}.pub.unexpired"
+			if [ -f "$SECUNEXPIRED" ] && [ -f "$PUBUNEXPIRED" ]; then
+				cp "$SECUNEXPIRED" "${REXKEY}.sec"
+				cp "$PUBUNEXPIRED" "${REXKEY}.pub"
+			else
+				if ! printf "expire\n1w\nsave\n" | aptkey --quiet --keyring "${REXKEY}.pub" --secret-keyring "${REXKEY}.sec" \
+					--readonly adv --batch --yes --digest-algo "${APT_TESTS_DIGEST_ALGO:-SHA512}" \
+					--default-key "$SIGNER" --command-fd 0 --edit-key "${SIGNER}" >setexpire.gpg 2>&1; then
+					cat setexpire.gpg
+					exit 1
+				fi
+				cp "${REXKEY}.sec" "$SECUNEXPIRED"
+				cp "${REXKEY}.pub" "$PUBUNEXPIRED"
+			fi
+		fi
+		if [ ! -e "${KEY}.pub" ]; then
+			local K="keys/$(echo "$SIGNER" | tr 'A-Z' 'a-z' | tr -d ' ,')"
+			cat "${K}.pub" >> "${KEY}.new.pub"
+			cat "${K}.sec" >> "${KEY}.new.sec"
 		fi
-	fi
-	for KEY in $(find keys/ -name '*.sec'); do
-		GPG="$GPG --secret-keyring $KEY"
-	done
-	for KEY in $(find keys/ -name '*.pub'); do
-		GPG="$GPG --keyring $KEY"
 	done
-	for RELEASE in $(find aptarchive/ -name Release); do
-		$GPG --default-key "$SIGNER" --armor --detach-sign --sign --output ${RELEASE}.gpg ${RELEASE}
-		local INRELEASE="$(echo "${RELEASE}" | sed 's#/Release$#/InRelease#')"
-		$GPG --default-key "$SIGNER" --clearsign --output $INRELEASE $RELEASE
+	if [ ! -e "${KEY}.pub" ]; then
+		mv "${KEY}.new.pub" "${KEY}.pub"
+		mv "${KEY}.new.sec" "${KEY}.sec"
+	fi
+	local GPG="aptkey --quiet --keyring ${KEY}.pub --secret-keyring ${KEY}.sec --readonly adv --batch --yes --digest-algo ${APT_TESTS_DIGEST_ALGO:-SHA512}"
+	for RELEASE in $(find "${REPODIR}/" -name Release); do
 		# we might have set a specific date for the Release file, so copy it
-		touch -d "$(stat --format "%y" ${RELEASE})" ${RELEASE}.gpg ${INRELEASE}
+		local DATE="$(stat --format "%y" "${RELEASE}")"
+		if [ "$APT_DONT_SIGN" = 'Release.gpg' ]; then
+			rm -f "${RELEASE}.gpg"
+		else
+			testsuccess $GPG "$@" $SIGUSERS --armor --detach-sign --sign --output "${RELEASE}.gpg" "${RELEASE}"
+			touch -d "$DATE" "${RELEASE}.gpg"
+		fi
+		local INRELEASE="${RELEASE%/*}/InRelease"
+		if [ "$APT_DONT_SIGN" = 'InRelease' ]; then
+			rm -f "$INRELEASE"
+		else
+			testsuccess $GPG "$@" $SIGUSERS --clearsign --output "$INRELEASE" "$RELEASE"
+			touch -d "$DATE" "${INRELEASE}"
+		fi
 	done
 	if [ -f "$SECEXPIREBAK" ] && [ -f "$PUBEXPIREBAK" ]; then
-		mv -f $SECEXPIREBAK ${REXKEY}.sec
-		mv -f $PUBEXPIREBAK ${REXKEY}.pub
+		mv -f "$SECEXPIREBAK" "${REXKEY}.sec"
+		mv -f "$PUBEXPIREBAK" "${REXKEY}.pub"
 	fi
-	msgdone "info"
+	msgdone 'info'
+}
+
+redatereleasefiles() {
+	local DATE="$(date -u -d "$1" -R)"
+	for release in $(find aptarchive/ -name 'Release'); do
+		sed -i "s/^Date: .*$/Date: ${DATE}/" "$release"
+		touch -d "$DATE" "$release"
+	done
+	signreleasefiles "${2:-Joe Sixpack}"
 }
 
 webserverconfig() {
-	msgtest "Set webserver config option '${1}' to" "$2"
+	local WEBSERVER="${3:-http://localhost:${APTHTTPPORT}}"
+	local NOCHECK=false
+	if [ "$1" = '--no-check' ]; then
+		NOCHECK=true
+		shift
+	fi
 	local DOWNLOG='rootdir/tmp/download-testfile.log'
-	local STATUS='rootdir/tmp/webserverconfig.status'
+	local STATUS='downloaded/webserverconfig.status'
 	rm -f "$STATUS" "$DOWNLOG"
-	if downloadfile "http://localhost:8080/_config/set/${1}/${2}" "$STATUS" > "$DOWNLOG"; then
+	# very very basic URI encoding
+	local URI
+	if [ -n "$2" ]; then
+		msgtest "Set webserver config option '${1}' to" "$2"
+		URI="${WEBSERVER}/_config/set/$(echo "${1}" | sed -e 's/\//%2f/g')/$(echo "${2}" | sed -e 's/\//%2f/g')"
+	else
+		msgtest 'Clear webserver config option' "${1}"
+		URI="${WEBSERVER}/_config/clear/$(echo "${1}" | sed -e 's/\//%2f/g')"
+	fi
+	if downloadfile "$URI" "$STATUS" > "$DOWNLOG"; then
 		msgpass
 	else
-		cat "$DOWNLOG" "$STATUS"
-		msgfail
+		local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/webserverconfig.output"
+		cat "$DOWNLOG" "$STATUS" >"$OUTPUT" 2>&1 || true
+		msgfailoutput '' "$OUTPUT"
 	fi
-	testwebserverlaststatuscode '200'
+	$NOCHECK || testwebserverlaststatuscode '200'
 }
 
 rewritesourceslist() {
-	local APTARCHIVE="file://$(readlink -f "${TMPWORKINGDIRECTORY}/aptarchive")"
+	local APTARCHIVE="file://$(readlink -f "${TMPWORKINGDIRECTORY}/aptarchive" | sed 's# #%20#g')"
+	local APTARCHIVE2="copy://$(readlink -f "${TMPWORKINGDIRECTORY}/aptarchive" | sed 's# #%20#g')"
 	for LIST in $(find rootdir/etc/apt/sources.list.d/ -name 'apt-test-*.list'); do
-		sed -i $LIST -e "s#$APTARCHIVE#${1}#" -e "s#http://localhost:8080/#${1}#" -e "s#http://localhost:4433/#${1}#"
+		sed -i $LIST -e "s#$APTARCHIVE#${1}#" -e "s#$APTARCHIVE2#${1}#" \
+			-e "s#http://[^@]*@\?localhost:${APTHTTPPORT}/\?#${1}#" \
+			-e "s#https://[^@]*@\?localhost:${APTHTTPSPORT}/\?#${1}#"
 	done
 }
 
@@ -903,83 +1296,103 @@ waitforpidfile() {
 }
 
 changetowebserver() {
+	local REWRITE='no'
 	if [ "$1" != '--no-rewrite' ]; then
-		rewritesourceslist 'http://localhost:8080/'
+		REWRITE='yes'
 	else
 		shift
 	fi
-	if test -x ${APTWEBSERVERBINDIR}/aptwebserver; then
+	if test -x "${APTTESTHELPERSBINDIR}/aptwebserver"; then
 		cd aptarchive
 		local LOG="webserver.log"
-		if ! aptwebserver -o aptwebserver::fork=1 "$@" >$LOG 2>&1 ; then
-			cat $LOG
+		if ! aptwebserver --port 0 -o aptwebserver::fork=1 -o aptwebserver::portfile='aptwebserver.port' "$@" >$LOG 2>&1 ; then
+			cat "$LOG"
 			false
 		fi
-                waitforpidfile aptwebserver.pid
+		waitforpidfile aptwebserver.pid
 		local PID="$(cat aptwebserver.pid)"
 		if [ -z "$PID" ]; then
 			msgdie 'Could not fork aptwebserver successfully'
 		fi
 		addtrap "kill $PID;"
+		waitforpidfile aptwebserver.port
+		APTHTTPPORT="$(cat aptwebserver.port)"
+		if [ -z "$APTHTTPPORT" ]; then
+			msgdie 'Could not get port for aptwebserver successfully'
+		fi
 		cd - > /dev/null
 	else
-		msgdie 'You have to build aptwerbserver or install a webserver'
+		msgdie 'You have to build apt from source to have test/interactive-helper/aptwebserver available for tests requiring a webserver'
+	fi
+	if [ "$REWRTE" != 'yes' ]; then
+		rewritesourceslist "http://localhost:${APTHTTPPORT}/"
 	fi
 }
 
 changetohttpswebserver() {
-	if ! which stunnel4 >/dev/null; then
+	local stunnel4
+	if command -v stunnel4 >/dev/null 2>&1; then
+		stunnel4=stunnel4
+	elif command -v stunnel >/dev/null 2>&1; then
+		stunnel4=stunnel
+	else
 		msgdie 'You need to install stunnel4 for https testcases'
 	fi
 	if [ ! -e "${TMPWORKINGDIRECTORY}/aptarchive/aptwebserver.pid" ]; then
 		changetowebserver --no-rewrite "$@"
 	fi
 	echo "pid = ${TMPWORKINGDIRECTORY}/aptarchive/stunnel.pid
-cert = ${TESTDIRECTORY}/apt.pem
+cert = ${TMPWORKINGDIRECTORY}/rootdir/etc/webserver.pem
 output = /dev/null
 
 [https]
-accept = 4433
-connect = 8080
-" > ${TMPWORKINGDIRECTORY}/stunnel.conf
-	stunnel4 "${TMPWORKINGDIRECTORY}/stunnel.conf"
+accept = 0
+connect = $APTHTTPPORT
+" > "${TMPWORKINGDIRECTORY}/stunnel.conf"
+	$stunnel4 "${TMPWORKINGDIRECTORY}/stunnel.conf"
         waitforpidfile "${TMPWORKINGDIRECTORY}/aptarchive/stunnel.pid"
-	local PID="$(cat ${TMPWORKINGDIRECTORY}/aptarchive/stunnel.pid)"
+	local PID="$(cat "${TMPWORKINGDIRECTORY}/aptarchive/stunnel.pid")"
         if [ -z "$PID" ]; then
-		msgdie 'Could not fork stunnel4 successfully'
+		msgdie 'Could not fork $stunnel4 successfully'
 	fi
 	addtrap 'prefix' "kill ${PID};"
-	rewritesourceslist 'https://localhost:4433/'
+	APTHTTPSPORT="$(lsof -i -n | awk "/^$stunnel4 / && \$2 == \"${PID}\" {print \$9; exit; }" | cut -d':' -f 2)"
+	webserverconfig 'aptwebserver::port::https' "$APTHTTPSPORT" "https://localhost:${APTHTTPSPORT}"
+	rewritesourceslist "https://localhost:${APTHTTPSPORT}/"
 }
 
 changetocdrom() {
 	mkdir -p rootdir/media/cdrom/.disk
 	local CD="$(readlink -f rootdir/media/cdrom)"
-	echo "acquire::cdrom::mount \"${CD}\";
-acquire::cdrom::${CD}/::mount \"mv ${CD}-unmounted ${CD}\";
-acquire::cdrom::${CD}/::umount \"mv ${CD} ${CD}-unmounted\";
-acquire::cdrom::autodetect 0;" > rootdir/etc/apt/apt.conf.d/00cdrom
-	echo -n "$1" > ${CD}/.disk/info
+	cat > rootdir/etc/apt/apt.conf.d/00cdrom <<EOF
+acquire::cdrom::mount "${CD}";
+acquire::cdrom::"${CD}/"::mount "mv ${CD}-unmounted ${CD}";
+acquire::cdrom::"${CD}/"::umount "mv ${CD} ${CD}-unmounted";
+acquire::cdrom::autodetect 0;
+EOF
+	echo -n "$1" > "${CD}/.disk/info"
 	if [ ! -d aptarchive/dists ]; then
 		msgdie 'Flat file archive cdroms can not be created currently'
 		return 1
 	fi
 	mv aptarchive/dists "$CD"
-	ln -s "$(readlink -f ./incoming)" $CD/pool
+	ln -s "$(readlink -f ./incoming)" "$CD/pool"
 	find rootdir/etc/apt/sources.list.d/ -name 'apt-test-*.list' -delete
 	# start with an unmounted disk
 	mv "${CD}" "${CD}-unmounted"
 	# we don't want the disk to be modifiable
-	addtrap 'prefix' "chmod -f -R +w $PWD/rootdir/media/cdrom/dists/ $PWD/rootdir/media/cdrom-unmounted/dists/ || true;"
-	chmod -R -w rootdir/media/cdrom-unmounted/dists
+	addtrap 'prefix' "chmod -f -R +w '$(escape_shell "$PWD/rootdir/media/cdrom/dists/")' '$(escape_shell "$PWD/rootdir/media/cdrom-unmounted/dists/")' || true;"
+	chmod -R 555 rootdir/media/cdrom-unmounted/dists
 }
 
 downloadfile() {
-	local PROTO="$(echo "$1" | cut -d':' -f 1 )"
-	apthelper -o Debug::Acquire::${PROTO}=1 \
-		download-file "$1" "$2" 2>&1 || true
+	local PROTO="${1%%:*}"
+	if ! apthelper -o Debug::Acquire::${PROTO}=1 -o Debug::pkgAcquire::Worker=1 \
+		download-file "$1" "$2" "$3" 2>&1 ; then
+		return 1
+	fi
 	# only if the file exists the download was successful
-	if [ -e "$2" ]; then
+	if [ -r "$2" ]; then
 		return 0
 	else
 		return 1
@@ -987,7 +1400,20 @@ downloadfile() {
 }
 
 checkdiff() {
-	local DIFFTEXT="$(command diff -u "$@" | sed -e '/^---/ d' -e '/^+++/ d' -e '/^@@/ d')"
+	local TMPFILE1="${TMPWORKINGDIRECTORY}/rootdir/tmp/checkdiff.1.tmp"
+	local TMPFILE2="${TMPWORKINGDIRECTORY}/rootdir/tmp/checkdiff.2.tmp"
+	touch "$TMPFILE1" "$TMPFILE2"
+	if [ "$1" != '-' ]; then
+		sed -e '/^profiling:/ d' < "$1" >"$TMPFILE1"
+	else
+		TMPFILE1='-'
+	fi
+	if [ "$2" != '-' ]; then
+		sed -e '/^profiling:/ d' < "$2" >"$TMPFILE2"
+	else
+		TMPFILE2='-'
+	fi
+	local DIFFTEXT="$(command diff -u "$TMPFILE1" "$TMPFILE2" 2>&1 | sed -e '/^---/ d' -e '/^+++/ d' -e '/^@@/ d')"
 	if [ -n "$DIFFTEXT" ]; then
 		echo >&2
 		echo >&2 "$DIFFTEXT"
@@ -997,23 +1423,71 @@ checkdiff() {
 	fi
 }
 
+testoutputequal() {
+	local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/testoutputequal.output"
+	local COMPAREFILE="$1"
+	shift
+	if "$@" 2>&1 | checkdiff "$COMPAREFILE" - >"$OUTPUT" 2>&1; then
+		msgpass
+	else
+		echo "=== content of file we compared with (${COMPAREFILE}) ===" >>"${OUTPUT}"
+		cat "$COMPAREFILE" >>"${OUTPUT}"
+		msgfailoutput '' "$OUTPUT" "$@"
+	fi
+}
+
 testfileequal() {
+	msggroup 'testfileequal'
+	local MSG='Test for correctness of file'
+	if [ "$1" = '--nomsg' ]; then
+		MSG=''
+		shift
+	fi
 	local FILE="$1"
 	shift
-	msgtest "Test for correctness of file" "$FILE"
+	if [ -n "$MSG" ]; then
+		msgtest "$MSG" "$FILE"
+	fi
+	local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/testfileequal.output"
 	if [ -z "$*" ]; then
-		echo -n "" | checkdiff $FILE - && msgpass || msgfail
+		testoutputequal "$FILE" echo -n ''
 	else
-		echo "$*" | checkdiff $FILE - && msgpass || msgfail
+		testoutputequal "$FILE" echo "$*"
 	fi
+	msggroup
 }
 
 testempty() {
-	msgtest "Test for no output of" "$*"
-	test -z "$($* 2>&1)" && msgpass || msgfail
+	msggroup 'testempty'
+	if [ "$1" = '--nomsg' ]; then
+		shift
+	else
+		msgtest "Test for no output of" "$*"
+	fi
+	local COMPAREFILE="${TMPWORKINGDIRECTORY}/rootdir/tmp/testempty.comparefile"
+	if "$@" >"$COMPAREFILE" 2>&1 && test ! -s "$COMPAREFILE"; then
+		msgpass
+	else
+		msgfailoutput '' "$COMPAREFILE" "$@"
+	fi
+	aptautotest 'testempty' "$@"
+	msggroup
+}
+testnotempty() {
+	msggroup 'testnotempty'
+	msgtest "Test for some output of" "$*"
+	local COMPAREFILE="${TMPWORKINGDIRECTORY}/rootdir/tmp/testnotempty.comparefile"
+	if ("$@" >"$COMPAREFILE" 2>&1 || true) && test -s "$COMPAREFILE"; then
+		msgpass
+	else
+		msgfailoutput '' "$COMPAREFILE" "$@"
+	fi
+	aptautotest 'testnotempty' "$@"
+	msggroup
 }
 
 testequal() {
+	msggroup 'testequal'
 	local MSG='Test of equality of'
 	if [ "$1" = '--nomsg' ]; then
 		MSG=''
@@ -1021,38 +1495,45 @@ testequal() {
 	fi
 
 	local COMPAREFILE="${TMPWORKINGDIRECTORY}/rootdir/tmp/testequal.comparefile"
-	echo "$1" > $COMPAREFILE
+	echo "$1" > "$COMPAREFILE"
 	shift
 
 	if [ -n "$MSG" ]; then
 		msgtest "$MSG" "$*"
 	fi
-	$* 2>&1 | checkdiff $COMPAREFILE - && msgpass || msgfail
+	testoutputequal "$COMPAREFILE" "$@"
+	aptautotest 'testequal' "$@"
+	msggroup
 }
 
 testequalor2() {
+	msggroup 'testequalor2'
 	local COMPAREFILE1="${TMPWORKINGDIRECTORY}/rootdir/tmp/testequalor2.comparefile1"
 	local COMPAREFILE2="${TMPWORKINGDIRECTORY}/rootdir/tmp/testequalor2.comparefile2"
 	local COMPAREAGAINST="${TMPWORKINGDIRECTORY}/rootdir/tmp/testequalor2.compareagainst"
-	echo "$1" > $COMPAREFILE1
-	echo "$2" > $COMPAREFILE2
+	echo "$1" > "$COMPAREFILE1"
+	echo "$2" > "$COMPAREFILE2"
 	shift 2
 	msgtest "Test for equality OR of" "$*"
-	$* >$COMPAREAGAINST 2>&1 || true
-	if checkdiff $COMPAREFILE1 $COMPAREAGAINST >/dev/null 2>&1 || \
-		checkdiff $COMPAREFILE2 $COMPAREAGAINST >/dev/null 2>&1
+	"$@" >"$COMPAREAGAINST" 2>&1 || true
+	if checkdiff "$COMPAREFILE1" "$COMPAREAGAINST" >/dev/null 2>&1 || \
+		checkdiff "$COMPAREFILE2" "$COMPAREAGAINST" >/dev/null 2>&1
 	then
 		msgpass
 	else
-		echo -n "\n${CINFO}Diff against OR 1${CNORMAL}"
-		checkdiff $COMPAREFILE1 $COMPAREAGAINST || true
-		echo -n "${CINFO}Diff against OR 2${CNORMAL}"
-		checkdiff $COMPAREFILE2 $COMPAREAGAINST || true
-		msgfail
+		local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/testequal.output"
+		echo -n "\n${CINFO}Diff against OR 1${CNORMAL}" >"$OUTPUT" 2>&1
+		checkdiff "$COMPAREFILE1" "$COMPAREAGAINST" >"$OUTPUT" 2>&1 || true
+		echo -n "${CINFO}Diff against OR 2${CNORMAL}" >"$OUTPUT" 2>&1
+		checkdiff "$COMPAREFILE2" "$COMPAREAGAINST" >"$OUTPUT" 2>&1 || true
+		msgfailoutput '' "$OUTPUT"
 	fi
+	aptautotest 'testequalor2' "$@"
+	msggroup
 }
 
 testshowvirtual() {
+	msggroup 'testshowvirtual'
 	local VIRTUAL="N: Can't select versions from package '$1' as it is purely virtual"
 	local PACKAGE="$1"
 	shift
@@ -1067,109 +1548,405 @@ N: Can't select versions from package '$1' as it is purely virtual"
 N: No packages found"
 	local COMPAREFILE="${TMPWORKINGDIRECTORY}/rootdir/tmp/testshowvirtual.comparefile"
 	local ARCH="$(getarchitecture 'native')"
-	echo "$VIRTUAL" | sed -e "s/:$ARCH//" -e 's/:all//' > $COMPAREFILE
-	aptcache show -q=0 $PACKAGE 2>&1 | checkdiff $COMPAREFILE - && msgpass || msgfail
+	echo "$VIRTUAL" | sed -e "s/:$ARCH//" -e 's/:all//' >"$COMPAREFILE"
+	local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/testshowvirtual.output"
+	testoutputequal "$COMPAREFILE" aptcache show "$PACKAGE"
+	msggroup
 }
 
 testnopackage() {
+	msggroup 'testnopackage'
 	msgtest "Test for non-existent packages" "apt-cache show $*"
 	local SHOWPKG="$(aptcache show "$@" 2>&1 | grep '^Package: ')"
 	if [ -n "$SHOWPKG" ]; then
-		echo >&2
-		echo >&2 "$SHOWPKG"
-		msgfail
+		local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/testnopackage.output"
+		echo "$SHOWPKG" >"$OUTPUT"
+		msgfailoutput '' "$OUTPUT"
 	else
 		msgpass
 	fi
+	msggroup
 }
-
-testdpkginstalled() {
-	msgtest "Test for correctly installed package(s) with" "dpkg -l $*"
-	local PKGS="$(dpkg -l "$@" 2>/dev/null | grep '^i' | wc -l)"
-	if [ "$PKGS" != $# ]; then
-		echo >&2 $PKGS
-		dpkg -l "$@" | grep '^[a-z]' >&2
-		msgfail
+testnosrcpackage() {
+	msggroup 'testnosrcpackage'
+	msgtest "Test for non-existent source packages" "apt-cache showsrc $*"
+	local SHOWPKG="$(aptcache showsrc "$@" 2>&1 | grep '^Package: ')"
+	if [ -n "$SHOWPKG" ]; then
+		local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/testnosrcpackage.output"
+		echo "$SHOWPKG" >"$OUTPUT"
+		msgfailoutput '' "$OUTPUT"
 	else
 		msgpass
 	fi
+	msggroup
 }
 
-testdpkgnotinstalled() {
-	msgtest "Test for correctly not-installed package(s) with" "dpkg -l $*"
-	local PKGS="$(dpkg -l "$@" 2> /dev/null | grep '^i' | wc -l)"
-	if [ "$PKGS" != 0 ]; then
-		echo
-		dpkg -l "$@" | grep '^[a-z]' >&2
-		msgfail
+testdpkgstatus() {
+	msggroup 'testdpkgstatus'
+	local STATE="$1"
+	local NR="$2"
+	shift 2
+	msgtest "Test that $NR package(s) are in state $STATE with" "dpkg -l $*"
+	local PKGS="$(dpkg -l "$@" 2>/dev/null | grep "^${STATE}" | wc -l)"
+	if [ "$PKGS" != $NR ]; then
+		local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/testnopackage.output"
+		echo "$PKGS" >"$OUTPUT"
+		dpkg -l "$@" | grep '^[a-z]' >"$OUTPUT" >&2 || true
+		msgfailoutput '' "$OUTPUT"
 	else
 		msgpass
 	fi
+	msggroup
+}
+
+testdpkginstalled() {
+	msggroup 'testdpkginstalled'
+	testdpkgstatus 'ii' "$#" "$@"
+	msggroup
+}
+
+testdpkgnotinstalled() {
+	msggroup 'testdpkgnotinstalled'
+	testdpkgstatus 'ii' '0' "$@"
+	msggroup
 }
 
 testmarkedauto() {
+	msggroup 'testmarkedauto'
 	local COMPAREFILE="${TMPWORKINGDIRECTORY}/rootdir/tmp/testmarkedauto.comparefile"
 	if [ -n "$1" ]; then
 		msgtest 'Test for correctly marked as auto-installed' "$*"
-		while [ -n "$1" ]; do echo "$1"; shift; done | sort > $COMPAREFILE
+		while [ -n "$1" ]; do echo "$1"; shift; done | sort > "$COMPAREFILE"
 	else
 		msgtest 'Test for correctly marked as auto-installed' 'no package'
-		echo -n > $COMPAREFILE
+		echo -n > "$COMPAREFILE"
+	fi
+	testoutputequal "$COMPAREFILE" aptmark showauto
+	msggroup
+}
+testmarkedmanual() {
+	msggroup 'testmarkedmanual'
+	local COMPAREFILE="${TMPWORKINGDIRECTORY}/rootdir/tmp/testmarkedmanual.comparefile"
+	if [ -n "$1" ]; then
+		msgtest 'Test for correctly marked as manually installed' "$*"
+		while [ -n "$1" ]; do echo "$1"; shift; done | sort > "$COMPAREFILE"
+	else
+		msgtest 'Test for correctly marked as manually installed' 'no package'
+		echo -n > "$COMPAREFILE"
 	fi
-	aptmark showauto 2>&1 | checkdiff $COMPAREFILE - && msgpass || msgfail
+	testoutputequal "$COMPAREFILE" aptmark showmanual
+	msggroup
 }
 
-testsuccess() {
+catfile() {
+	if [ "${1##*.}" = 'deb' ]; then
+		stat >&2 "$1" || true
+		file >&2 "$1" || true
+	else
+		cat >&2 "$1" || true
+	fi
+}
+msgfailoutput() {
+	msgreportheader 'msgfailoutput'
+	local MSG="$1"
+	local OUTPUT="$2"
+	shift 2
+	local CMD="$1"
+	if [ "$1" = 'grep' -o "$1" = 'tail' -o "$1" = 'head' ]; then
+		echo >&2
+		while [ -n "$2" ]; do shift; done
+		echo "#### Complete file: $1 ####"
+		catfile "$1"
+		echo "#### $CMD output ####"
+	elif [ "$1" = 'test' ]; then
+		echo >&2
+		# doesn't support ! or non-file flags
+		msgfailoutputstatfile() {
+			local FILEFLAGS='^-[bcdefgGhkLOprsStuwx]$'
+			if expr match "$1" "$FILEFLAGS" >/dev/null; then
+				echo "#### stat(2) of file: $2 ####"
+				stat "$2" || true
+				if test -d "$2"; then
+					echo "#### The directory contains: $2 ####"
+					ls >&2 "$2" || true
+				elif test -e "$2"; then
+					echo "#### Complete file: $2 ####"
+					catfile "$2"
+				fi
+			fi
+		}
+		msgfailoutputstatfile "$2" "$3"
+		while [ -n "$5" ] && [ "$4" = '-o' -o "$4" = '-a' ]; do
+			shift 3
+			msgfailoutputstatfile "$2" "$3"
+		done
+		echo '#### test output ####'
+	elif [ "$1" = 'cmp' ]; then
+		echo >&2
+		while [ -n "$2" ]; do
+			echo "#### Complete file: $2 ####"
+			catfile "$2"
+			shift
+		done
+		echo '#### cmp output ####'
+	fi
+	catfile "$OUTPUT"
+	msgfail "$MSG"
+}
+
+testsuccesswithglobalerror() {
+	local TYPE="$1"
+	local ERRORS="$2"
+	shift 2
+	msggroup "$TYPE"
 	if [ "$1" = '--nomsg' ]; then
 		shift
 	else
 		msgtest 'Test for successful execution of' "$*"
 	fi
-	local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/testsuccess.output"
-	if $@ >${OUTPUT} 2>&1; then
-		msgpass
+	local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/${TYPE}.output"
+	if "$@" >"${OUTPUT}" 2>&1; then
+		if expr match "$1" '^apt.*' >/dev/null; then
+			if grep -q -E ' runtime error: ' "$OUTPUT"; then
+				msgfailoutput 'compiler detected undefined behavior' "$OUTPUT" "$@"
+			elif grep -E "^[${ERRORS}]: " "$OUTPUT" > "${TMPWORKINGDIRECTORY}/rootdir/tmp/checkforwarnings.output" 2>&1; then
+				if [ "$IGNORE_PTY_NOT_MOUNTED" = '1' ]; then
+					if echo 'E: Can not write log (Is /dev/pts mounted?) - posix_openpt (2: No such file or directory)' \
+						| cmp - "${TMPWORKINGDIRECTORY}/rootdir/tmp/checkforwarnings.output" >/dev/null 2>&1; then
+						msgpass
+					else
+						msgfailoutput 'successful run, but output contains warnings/errors' "$OUTPUT" "$@"
+					fi
+				else
+					msgfailoutput 'successful run, but output contains warnings/errors' "$OUTPUT" "$@"
+				fi
+			elif [ "$TYPE" = 'testsuccesswithnotice' ]; then
+				if grep -q -E "^N: " "$OUTPUT"; then
+					msgpass
+				else
+					msgfailoutput 'successful run, but output had no notices' "$OUTPUT" "$@"
+				fi
+			else
+				msgpass
+			fi
+		else
+			msgpass
+		fi
 	else
-		echo >&2
-		cat >&2 $OUTPUT
-		msgfail
+		local EXITCODE=$?
+		msgfailoutput "exitcode $EXITCODE" "$OUTPUT" "$@"
 	fi
+	aptautotest "$TYPE" "$@"
+	msggroup
+}
+testsuccesswithnotice() {
+	testsuccesswithglobalerror 'testsuccesswithnotice' 'WE' "$@"
+}
+testsuccess() {
+	testsuccesswithglobalerror 'testsuccess' 'NWE' "$@"
+}
+testwarning() {
+	msggroup 'testwarning'
+	if [ "$1" = '--nomsg' ]; then
+		shift
+	else
+		msgtest 'Test for successful execution with warnings of' "$*"
+	fi
+	local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/testwarning.output"
+	if "$@" >"${OUTPUT}" 2>&1; then
+		if expr match "$1" '^apt.*' >/dev/null; then
+			if grep -q -E ' runtime error: ' "$OUTPUT"; then
+				msgfailoutput 'compiler detected undefined behavior' "$OUTPUT" "$@"
+			elif grep -q -E '^E: ' "$OUTPUT"; then
+				msgfailoutput 'successful run, but output contains errors' "$OUTPUT" "$@"
+			elif ! grep -q -E '^W: ' "$OUTPUT"; then
+				msgfailoutput 'successful run, but output contains no warnings' "$OUTPUT" "$@"
+			else
+				msgpass
+			fi
+		else
+			msgpass
+		fi
+	else
+		local EXITCODE=$?
+		msgfailoutput "exitcode $EXITCODE" "$OUTPUT" "$@"
+	fi
+	aptautotest 'testwarning' "$@"
+	msggroup
 }
-
 testfailure() {
+	msggroup 'testfailure'
 	if [ "$1" = '--nomsg' ]; then
 		shift
 	else
 		msgtest 'Test for failure in execution of' "$*"
 	fi
 	local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/testfailure.output"
-	if $@ >${OUTPUT} 2>&1; then
-		echo >&2
-		cat >&2 $OUTPUT
-		msgfail
+	if "$@" >"${OUTPUT}" 2>&1; then
+		local EXITCODE=$?
+		msgfailoutput "exitcode $EXITCODE" "$OUTPUT" "$@"
+	else
+		local EXITCODE=$?
+		if expr match "$1" '^apt.*' >/dev/null; then
+			if [ "$1" = 'aptkey' ]; then
+				if grep -q " Can't check signature: 
+ BAD signature from 
+ signature could not be verified" "$OUTPUT"; then
+					msgpass
+				else
+					msgfailoutput "run failed with exitcode ${EXITCODE}, but no signature error" "$OUTPUT" "$@"
+				fi
+			else
+				if grep -q -E ' runtime error: ' "$OUTPUT"; then
+					msgfailoutput 'compiler detected undefined behavior' "$OUTPUT" "$@"
+				elif grep -q -E '==ERROR' "$OUTPUT"; then
+					msgfailoutput 'compiler sanitizers reported errors' "$OUTPUT" "$@"
+				elif ! grep -q -E '^E: ' "$OUTPUT"; then
+					msgfailoutput "run failed with exitcode ${EXITCODE}, but with no errors" "$OUTPUT" "$@"
+				else
+					msgpass
+				fi
+			fi
+		else
+			msgpass
+		fi
+	fi
+	aptautotest 'testfailure' "$@"
+	msggroup
+}
+
+testreturnstateequal() {
+	local STATE="$1"
+	if [ "$STATE" = 'testsuccesswithglobalerror' ]; then
+		local STATE="$2"
+		local TYPE="$3"
+		shift 3
+		msggroup "${STATE}equal"
+		if [ "$1" != '--nomsg' ]; then
+			local CMP="$1"
+			shift
+			testsuccesswithglobalerror "$STATE" "$TYPE" "$@"
+			testfileequal "${TMPWORKINGDIRECTORY}/rootdir/tmp/${STATE}.output" "$CMP"
+		else
+			local CMP="$2"
+			shift 2
+			testsuccesswithglobalerror "$STATE" "$TYPE" "$@"
+			testfileequal "${TMPWORKINGDIRECTORY}/rootdir/tmp/${STATE}.output" "$CMP"
+		fi
 	else
+		msggroup "${STATE}equal"
+		if [ "$2" != '--nomsg' ]; then
+			local CMP="$2"
+			shift 2
+			"$STATE" "$@"
+			testfileequal "${TMPWORKINGDIRECTORY}/rootdir/tmp/${STATE}.output" "$CMP"
+		else
+			local CMP="$3"
+			shift 3
+			"$STATE" --nomsg "$@"
+			testfileequal "${TMPWORKINGDIRECTORY}/rootdir/tmp/${STATE}.output" "$CMP"
+		fi
+	fi
+	msggroup
+}
+testsuccessequal() {
+	# we compare output, so we know perfectly well about N:
+	testreturnstateequal 'testsuccesswithglobalerror' 'testsuccess' 'WE' "$@"
+}
+testwarningequal() {
+	testreturnstateequal 'testwarning' "$@"
+}
+testfailureequal() {
+	testreturnstateequal 'testfailure' "$@"
+}
+
+testfailuremsg() {
+	msggroup 'testfailuremsg'
+	local CMP="$1"
+	shift
+	testfailure "$@"
+	msgtest 'Check that the output of the previous failed command has expected' 'failures and warnings'
+	local COMPAREFILE="${TMPWORKINGDIRECTORY}/rootdir/tmp/testfailuremsg.comparefile"
+	grep '^\(W\|E\|N\):' "${TMPWORKINGDIRECTORY}/rootdir/tmp/testfailure.output" > "$COMPAREFILE" 2>&1 || true
+	testoutputequal "$COMPAREFILE" echo "$CMP"
+	msggroup
+}
+testwarningmsg() {
+	msggroup 'testwarningmsg'
+	local CMP="$1"
+	shift
+	testwarning "$@"
+	msgtest 'Check that the output of the previous warned command has expected' 'warnings'
+	local COMPAREFILE="${TMPWORKINGDIRECTORY}/rootdir/tmp/testwarningmsg.comparefile"
+	grep '^\(W\|E\|N\):' "${TMPWORKINGDIRECTORY}/rootdir/tmp/testwarning.output" > "$COMPAREFILE" 2>&1 || true
+	testoutputequal "$COMPAREFILE" echo "$CMP"
+	msggroup
+}
+
+testfilestats() {
+	msggroup 'testfilestats'
+	msgtest "Test that file $1 has $2 $3" "$4"
+	if [ "$4" "$3" "$(stat --format "$2" "$1")" ]; then
 		msgpass
+	else
+		local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/testfilestats.output"
+		{
+			ls -ld "$1" || true
+			echo -n "stat(1) reports for $2: "
+			stat --format "$2" "$1" || true
+		} >"$OUTPUT" 2>&1
+		msgfailoutput '' "$OUTPUT"
 	fi
+	msggroup
+}
+testaccessrights() {
+	msggroup 'testaccessrights'
+	testfilestats "$1" '%a' '=' "$2"
+	msggroup
 }
 
 testwebserverlaststatuscode() {
+	msggroup 'testwebserverlaststatuscode'
 	local DOWNLOG='rootdir/tmp/webserverstatus-testfile.log'
-	local STATUS='rootdir/tmp/webserverstatus-statusfile.log'
+	local STATUS='downloaded/webserverstatus-statusfile.log'
 	rm -f "$DOWNLOG" "$STATUS"
 	msgtest 'Test last status code from the webserver was' "$1"
-	downloadfile "http://localhost:8080/_config/find/aptwebserver::last-status-code" "$STATUS" > "$DOWNLOG"
-	if [ "$(cat "$STATUS")" = "$1" ]; then
+	if downloadfile "http://localhost:${APTHTTPPORT}/_config/find/aptwebserver::last-status-code" "$STATUS" > "$DOWNLOG" && [ "$(cat "$STATUS")" = "$1" ]; then
 		msgpass
 	else
-		echo >&2
-		if [ -n "$2" ]; then
-			shift
-			echo >&2 '#### Additionally provided output files contain:'
-			cat >&2 "$@"
-		fi
-		echo >&2 '#### Download log of the status code:'
-		cat >&2 "$DOWNLOG"
-		msgfail "Status was $(cat "$STATUS")"
+		local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/testwebserverlaststatuscode.output"
+		{
+			if [ -n "$2" ]; then
+				shift
+				echo >&2 '#### Additionally provided output files contain:'
+				cat >&2 "$@"
+			fi
+			echo >&2 '#### Download log of the status code:'
+			cat >&2 "$DOWNLOG"
+		} >"$OUTPUT" 2>&1
+		msgfailoutput "Status was $(cat "$STATUS")" "$OUTPUT"
 	fi
+	msggroup
+}
+
+mapkeynametokeyid() {
+	while [ -n "$1" ]; do
+		case "$1" in
+			*Joe*|*Sixpack*|newarchive) echo '5A90D141DBAC8DAE';;
+			*Rex*|*Expired*) echo '4BC0A39C27CE74F9';;
+			*Marvin*|*Paranoid*) echo 'E8525D47528144E2';;
+			oldarchive) echo 'FDD2DB85F68C85A3';;
+			*) echo 'UNKNOWN KEY';;
+		esac
+		shift
+	done
+}
+testaptkeys() {
+	local OUTPUT="${TMPWORKINGDIRECTORY}/rootdir/tmp/aptkeylist.output"
+	if ! aptkey list --with-colon | grep '^pub' | cut -d':' -f 5 > "$OUTPUT"; then
+		echo -n > "$OUTPUT"
+	fi
+	testfileequal "$OUTPUT" "$(mapkeynametokeyid "$@")"
 }
 
 pause() {
@@ -1177,3 +1954,127 @@ pause() {
 	local IGNORE
 	read IGNORE
 }
+
+logcurrentarchivedirectory() {
+	find "${TMPWORKINGDIRECTORY}/aptarchive/dists" -type f | while read line; do
+		stat --format '%U:%G:%a:%n' "$line"
+	done | sort > "${TMPWORKINGDIRECTORY}/rootdir/var/log/aptgetupdate.before.lst"
+}
+listcurrentlistsdirectory() {
+	{
+		find rootdir/var/lib/apt/lists -maxdepth 1 -type d | while read line; do
+			stat --format '%U:%G:%a:%n' "$line"
+		done
+		find rootdir/var/lib/apt/lists -maxdepth 1 \! -type d | while read line; do
+			stat --format '%U:%G:%a:%s:%y:%n' "$line"
+		done
+	} | sort
+}
+forallsupportedcompressors() {
+	rm -f "${TMPWORKINGDIRECTORY}/rootdir/etc/apt/apt.conf.d/00force-compressor"
+	for COMP in $(aptconfig dump 'APT::Compressor' --format '%f%n' | cut -d':' -f 5 | uniq); do
+		if [ -z "$COMP" -o "$COMP" = '.' ]; then continue; fi
+		"$@" "$COMP"
+	done
+}
+
+### convenience hacks ###
+mkdir() {
+	# creating some directories by hand is a tedious task, so make it look simple
+	local PARAMS="$*"
+	if [ "$PARAMS" != "${PARAMS#*rootdir/var/lib/apt/lists}" ]; then
+		# only the last directory created by mkdir is effected by the -m !
+		command mkdir -m 755 -p "${TMPWORKINGDIRECTORY}/rootdir/var/lib/apt"
+		command mkdir -m 755 -p "${TMPWORKINGDIRECTORY}/rootdir/var/lib/apt/lists"
+		command mkdir -m 700 -p "${TMPWORKINGDIRECTORY}/rootdir/var/lib/apt/lists/partial"
+		touch "${TMPWORKINGDIRECTORY}/rootdir/var/lib/apt/lists/lock"
+		if [ "$(id -u)" = '0' ]; then
+			chown _apt:$(id -gn) "${TMPWORKINGDIRECTORY}/rootdir/var/lib/apt/lists/partial"
+		fi
+	else
+		command mkdir "$@"
+	fi
+}
+
+### The following tests are run by most test methods automatically to check
+### general things about commands executed without writing the test every time.
+
+aptautotest() {
+	if [ $# -lt 3 ]; then return; fi
+	local TESTCALL="$1"
+	local CMD="$2"
+	local FIRSTOPT="$3"
+	shift 2
+	for i in "$@"; do
+		if ! expr match "$i" '^-' >/dev/null 2>&1; then
+			FIRSTOPT="$i"
+			break
+		fi
+	done
+	shift
+	local AUTOTEST="aptautotest_$(echo "${CMD##*/}_${FIRSTOPT}" | tr -d -c 'A-za-z0-9')"
+	if command -v $AUTOTEST >/dev/null; then
+		# save and restore the *.output files from other tests
+		# as we might otherwise override them in these automatic tests
+		rm -rf "${TMPWORKINGDIRECTORY}/rootdir/tmp-before"
+		mv "${TMPWORKINGDIRECTORY}/rootdir/tmp" "${TMPWORKINGDIRECTORY}/rootdir/tmp-before"
+		mkdir "${TMPWORKINGDIRECTORY}/rootdir/tmp"
+		$AUTOTEST "$TESTCALL" "$@"
+		rm -rf "${TMPWORKINGDIRECTORY}/rootdir/tmp-aptautotest"
+		mv "${TMPWORKINGDIRECTORY}/rootdir/tmp" "${TMPWORKINGDIRECTORY}/rootdir/tmp-aptautotest"
+		mv "${TMPWORKINGDIRECTORY}/rootdir/tmp-before" "${TMPWORKINGDIRECTORY}/rootdir/tmp"
+	fi
+}
+
+aptautotest_aptget_update() {
+	local TESTCALL="$1"
+	while [ -n "$2" ]; do
+		if [ "$2" = '--print-uris' ]; then return; fi # simulation mode
+		shift
+	done
+	if ! test -d "${TMPWORKINGDIRECTORY}/rootdir/var/lib/apt/lists"; then return; fi
+	testfilestats "${TMPWORKINGDIRECTORY}/rootdir/var/lib/apt" '%U:%G:%a' '=' "${TEST_DEFAULT_USER}:${TEST_DEFAULT_GROUP}:755"
+	testfilestats "${TMPWORKINGDIRECTORY}/rootdir/var/lib/apt/lists" '%U:%G:%a' '=' "${TEST_DEFAULT_USER}:${TEST_DEFAULT_GROUP}:755"
+	# all copied files are properly chmodded
+	local backupIFS="$IFS"
+	IFS="$(printf "\n\b")"
+	for file in $(find "${TMPWORKINGDIRECTORY}/rootdir/var/lib/apt/lists" -type f ! -name 'lock'); do
+		testfilestats "$file" '%U:%G:%a' '=' "${TEST_DEFAULT_USER}:${TEST_DEFAULT_GROUP}:644"
+	done
+	IFS="$backupIFS"
+	if [ "$TESTCALL" = 'testsuccess' ]; then
+		# failure cases can retain partial files and such
+		testempty find "${TMPWORKINGDIRECTORY}/rootdir/var/lib/apt/lists/partial" -mindepth 1 ! \( -name 'lock' -o -name '*.FAILED' \)
+	fi
+	if [ -s "${TMPWORKINGDIRECTORY}/rootdir/var/log/aptgetupdate.before.lst" ]; then
+		testfileequal "${TMPWORKINGDIRECTORY}/rootdir/var/log/aptgetupdate.before.lst" \
+			"$(find "${TMPWORKINGDIRECTORY}/aptarchive/dists" -type f | while read line; do stat --format '%U:%G:%a:%n' "$line"; done | sort)"
+	fi
+}
+aptautotest_apt_update() { aptautotest_aptget_update "$@"; }
+aptautotest_aptcdrom_add() { aptautotest_aptget_update "$@"; }
+
+testaptautotestnodpkgwarning() {
+	local TESTCALL="$1"
+	while [ -n "$2" ]; do
+		if expr match "$2" '^-[a-z]*s' >/dev/null 2>&1; then return; fi # simulation mode
+		if expr match "$2" '^-dy\?' >/dev/null 2>&1; then return; fi # download-only mode
+		shift
+	done
+	testfailure grep '^dpkg: warning:.*\(ignor\|unknown\).*' "${TMPWORKINGDIRECTORY}/rootdir/tmp-before/${TESTCALL}.output"
+}
+
+aptautotest_aptget_install() { testaptautotestnodpkgwarning "$@"; }
+aptautotest_aptget_remove() { testaptautotestnodpkgwarning "$@"; }
+aptautotest_aptget_purge() { testaptautotestnodpkgwarning "$@"; }
+aptautotest_apt_install() { testaptautotestnodpkgwarning "$@"; }
+aptautotest_apt_remove() { testaptautotestnodpkgwarning "$@"; }
+aptautotest_apt_purge() { testaptautotestnodpkgwarning "$@"; }
+
+testaptmarknodefaultsections() {
+	testfailure grep '^Auto-Installed: 0$' "${TMPWORKINGDIRECTORY}/rootdir/var/lib/apt/extended_states"
+}
+aptautotest_aptmark_auto() { testaptmarknodefaultsections "$@"; }
+aptautotest_aptmark_manual() { testaptmarknodefaultsections "$@"; }
+aptautotest_aptget_markauto() { testaptmarknodefaultsections "$@"; }
+aptautotest_aptget_markmanual() { testaptmarknodefaultsections "$@"; }