mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
Fail the dns-resolver teardown checks when the container cannot be inspected
The teardown checks negated `docker exec <name> test -f <path>`. When `docker exec` itself failed, for example because teardown had taken the container down, it returned non-zero just as a missing file does, so the negation read the failure as a clean teardown and the check passed. The checks now go through one helper that passes only on a confirmed absence (`test ! -f` inside a reachable container). If the check cannot run, it fails and names the container that is no longer running as the reason, rather than reporting the file as still present. Output on a healthy run is unchanged line for line.
This commit is contained in:
@@ -221,6 +221,22 @@ file_contains() {
|
|||||||
docker exec "$name" grep -qF "$needle" "$path" 2>/dev/null
|
docker exec "$name" grep -qF "$needle" "$path" 2>/dev/null
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# Pass only when the file is confirmed absent after teardown. Negating
|
||||||
|
# file_exists fails open: `docker exec` exits non-zero for a container
|
||||||
|
# that is gone just as `test -f` does for a missing file, so a teardown
|
||||||
|
# that took the container down would read as clean. When the check
|
||||||
|
# cannot run, name the unreachable container rather than the file.
|
||||||
|
check_removed() {
|
||||||
|
local name="$1" path="$2" okmsg="$3" badmsg="$4"
|
||||||
|
if docker exec "$name" test ! -f "$path" 2>/dev/null; then
|
||||||
|
pass "$okmsg"
|
||||||
|
elif [ "$(docker inspect -f '{{.State.Running}}' "$name" 2>/dev/null)" != true ]; then
|
||||||
|
fail "could not check $path after teardown: container $name is not running"
|
||||||
|
else
|
||||||
|
fail "$badmsg"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
# Get the major systemd version inside a container.
|
# Get the major systemd version inside a container.
|
||||||
container_systemd_version() {
|
container_systemd_version() {
|
||||||
local name="$1"
|
local name="$1"
|
||||||
@@ -287,16 +303,12 @@ verify_resolved_backend() {
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
run_teardown "$name" >/dev/null 2>&1
|
run_teardown "$name" >/dev/null 2>&1
|
||||||
if ! file_exists "$name" "$expected_path"; then
|
check_removed "$name" "$expected_path" \
|
||||||
pass "teardown removed config file"
|
"teardown removed config file" \
|
||||||
else
|
"config file still exists after teardown"
|
||||||
fail "config file still exists after teardown"
|
check_removed "$name" /run/fips/dns-backend \
|
||||||
fi
|
"teardown cleaned state file" \
|
||||||
if ! file_exists "$name" /run/fips/dns-backend; then
|
"state file still exists after teardown"
|
||||||
pass "teardown cleaned state file"
|
|
||||||
else
|
|
||||||
fail "state file still exists after teardown"
|
|
||||||
fi
|
|
||||||
}
|
}
|
||||||
|
|
||||||
# ─────────────────────────────────────────────────────────────────────
|
# ─────────────────────────────────────────────────────────────────────
|
||||||
@@ -594,16 +606,12 @@ DOCKERFILE
|
|||||||
|
|
||||||
# Teardown
|
# Teardown
|
||||||
run_teardown "$name" >/dev/null 2>&1
|
run_teardown "$name" >/dev/null 2>&1
|
||||||
if ! file_exists "$name" /etc/dnsmasq.d/fips.conf; then
|
check_removed "$name" /etc/dnsmasq.d/fips.conf \
|
||||||
pass "teardown removed dnsmasq config"
|
"teardown removed dnsmasq config" \
|
||||||
else
|
"dnsmasq config still exists after teardown"
|
||||||
fail "dnsmasq config still exists after teardown"
|
check_removed "$name" /run/fips/dns-backend \
|
||||||
fi
|
"teardown cleaned state file" \
|
||||||
if ! file_exists "$name" /run/fips/dns-backend; then
|
"state file still exists after teardown"
|
||||||
pass "teardown cleaned state file"
|
|
||||||
else
|
|
||||||
fail "state file still exists after teardown"
|
|
||||||
fi
|
|
||||||
|
|
||||||
cleanup_container "$name"
|
cleanup_container "$name"
|
||||||
}
|
}
|
||||||
@@ -657,16 +665,12 @@ DOCKERFILE
|
|||||||
|
|
||||||
# Teardown
|
# Teardown
|
||||||
run_teardown "$name" >/dev/null 2>&1
|
run_teardown "$name" >/dev/null 2>&1
|
||||||
if ! file_exists "$name" /etc/NetworkManager/dnsmasq.d/fips.conf; then
|
check_removed "$name" /etc/NetworkManager/dnsmasq.d/fips.conf \
|
||||||
pass "teardown removed NM dnsmasq config"
|
"teardown removed NM dnsmasq config" \
|
||||||
else
|
"NM dnsmasq config still exists after teardown"
|
||||||
fail "NM dnsmasq config still exists after teardown"
|
check_removed "$name" /run/fips/dns-backend \
|
||||||
fi
|
"teardown cleaned state file" \
|
||||||
if ! file_exists "$name" /run/fips/dns-backend; then
|
"state file still exists after teardown"
|
||||||
pass "teardown cleaned state file"
|
|
||||||
else
|
|
||||||
fail "state file still exists after teardown"
|
|
||||||
fi
|
|
||||||
|
|
||||||
cleanup_container "$name"
|
cleanup_container "$name"
|
||||||
}
|
}
|
||||||
@@ -710,11 +714,9 @@ DOCKERFILE
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
run_teardown "$name" >/dev/null 2>&1
|
run_teardown "$name" >/dev/null 2>&1
|
||||||
if ! file_exists "$name" /run/fips/dns-backend; then
|
check_removed "$name" /run/fips/dns-backend \
|
||||||
pass "teardown cleaned state file"
|
"teardown cleaned state file" \
|
||||||
else
|
"state file still exists after teardown"
|
||||||
fail "state file still exists after teardown"
|
|
||||||
fi
|
|
||||||
|
|
||||||
cleanup_container "$name"
|
cleanup_container "$name"
|
||||||
}
|
}
|
||||||
@@ -955,11 +957,9 @@ EOF'
|
|||||||
teardown_path="/etc/systemd/resolved.conf.d/fips.conf"
|
teardown_path="/etc/systemd/resolved.conf.d/fips.conf"
|
||||||
fi
|
fi
|
||||||
run_teardown "$name" >/dev/null 2>&1
|
run_teardown "$name" >/dev/null 2>&1
|
||||||
if ! file_exists "$name" "$teardown_path"; then
|
check_removed "$name" "$teardown_path" \
|
||||||
pass "teardown removed $expected_backend config at $teardown_path"
|
"teardown removed $expected_backend config at $teardown_path" \
|
||||||
else
|
"$expected_backend config still present after teardown at $teardown_path"
|
||||||
fail "$expected_backend config still present after teardown at $teardown_path"
|
|
||||||
fi
|
|
||||||
|
|
||||||
cleanup_container "$name"
|
cleanup_container "$name"
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user