Fail the dns-resolver teardown checks when the container cannot be inspected

The teardown checks negated `docker exec <name> test -f <path>`. When
`docker exec` itself failed, for example because teardown had taken the
container down, it returned non-zero just as a missing file does, so the
negation read the failure as a clean teardown and the check passed.

The checks now go through one helper that passes only on a confirmed
absence (`test ! -f` inside a reachable container). If the check cannot
run, it fails and names the container that is no longer running as the
reason, rather than reporting the file as still present. Output on a
healthy run is unchanged line for line.
This commit is contained in:
Johnathan Corgan
2026-09-19 00:41:14 +00:00
parent 5df2ddd724
commit 1c709a87e8
+40 -40
View File
@@ -221,6 +221,22 @@ file_contains() {
docker exec "$name" grep -qF "$needle" "$path" 2>/dev/null docker exec "$name" grep -qF "$needle" "$path" 2>/dev/null
} }
# Pass only when the file is confirmed absent after teardown. Negating
# file_exists fails open: `docker exec` exits non-zero for a container
# that is gone just as `test -f` does for a missing file, so a teardown
# that took the container down would read as clean. When the check
# cannot run, name the unreachable container rather than the file.
check_removed() {
local name="$1" path="$2" okmsg="$3" badmsg="$4"
if docker exec "$name" test ! -f "$path" 2>/dev/null; then
pass "$okmsg"
elif [ "$(docker inspect -f '{{.State.Running}}' "$name" 2>/dev/null)" != true ]; then
fail "could not check $path after teardown: container $name is not running"
else
fail "$badmsg"
fi
}
# Get the major systemd version inside a container. # Get the major systemd version inside a container.
container_systemd_version() { container_systemd_version() {
local name="$1" local name="$1"
@@ -287,16 +303,12 @@ verify_resolved_backend() {
fi fi
run_teardown "$name" >/dev/null 2>&1 run_teardown "$name" >/dev/null 2>&1
if ! file_exists "$name" "$expected_path"; then check_removed "$name" "$expected_path" \
pass "teardown removed config file" "teardown removed config file" \
else "config file still exists after teardown"
fail "config file still exists after teardown" check_removed "$name" /run/fips/dns-backend \
fi "teardown cleaned state file" \
if ! file_exists "$name" /run/fips/dns-backend; then "state file still exists after teardown"
pass "teardown cleaned state file"
else
fail "state file still exists after teardown"
fi
} }
# ───────────────────────────────────────────────────────────────────── # ─────────────────────────────────────────────────────────────────────
@@ -594,16 +606,12 @@ DOCKERFILE
# Teardown # Teardown
run_teardown "$name" >/dev/null 2>&1 run_teardown "$name" >/dev/null 2>&1
if ! file_exists "$name" /etc/dnsmasq.d/fips.conf; then check_removed "$name" /etc/dnsmasq.d/fips.conf \
pass "teardown removed dnsmasq config" "teardown removed dnsmasq config" \
else "dnsmasq config still exists after teardown"
fail "dnsmasq config still exists after teardown" check_removed "$name" /run/fips/dns-backend \
fi "teardown cleaned state file" \
if ! file_exists "$name" /run/fips/dns-backend; then "state file still exists after teardown"
pass "teardown cleaned state file"
else
fail "state file still exists after teardown"
fi
cleanup_container "$name" cleanup_container "$name"
} }
@@ -657,16 +665,12 @@ DOCKERFILE
# Teardown # Teardown
run_teardown "$name" >/dev/null 2>&1 run_teardown "$name" >/dev/null 2>&1
if ! file_exists "$name" /etc/NetworkManager/dnsmasq.d/fips.conf; then check_removed "$name" /etc/NetworkManager/dnsmasq.d/fips.conf \
pass "teardown removed NM dnsmasq config" "teardown removed NM dnsmasq config" \
else "NM dnsmasq config still exists after teardown"
fail "NM dnsmasq config still exists after teardown" check_removed "$name" /run/fips/dns-backend \
fi "teardown cleaned state file" \
if ! file_exists "$name" /run/fips/dns-backend; then "state file still exists after teardown"
pass "teardown cleaned state file"
else
fail "state file still exists after teardown"
fi
cleanup_container "$name" cleanup_container "$name"
} }
@@ -710,11 +714,9 @@ DOCKERFILE
fi fi
run_teardown "$name" >/dev/null 2>&1 run_teardown "$name" >/dev/null 2>&1
if ! file_exists "$name" /run/fips/dns-backend; then check_removed "$name" /run/fips/dns-backend \
pass "teardown cleaned state file" "teardown cleaned state file" \
else "state file still exists after teardown"
fail "state file still exists after teardown"
fi
cleanup_container "$name" cleanup_container "$name"
} }
@@ -955,11 +957,9 @@ EOF'
teardown_path="/etc/systemd/resolved.conf.d/fips.conf" teardown_path="/etc/systemd/resolved.conf.d/fips.conf"
fi fi
run_teardown "$name" >/dev/null 2>&1 run_teardown "$name" >/dev/null 2>&1
if ! file_exists "$name" "$teardown_path"; then check_removed "$name" "$teardown_path" \
pass "teardown removed $expected_backend config at $teardown_path" "teardown removed $expected_backend config at $teardown_path" \
else "$expected_backend config still present after teardown at $teardown_path"
fail "$expected_backend config still present after teardown at $teardown_path"
fi
cleanup_container "$name" cleanup_container "$name"
} }