mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-30 19:46:15 +00:00
Add nostr-publish-consume integration suite
Cover the previously untested overlay advert publish/relay/consume
round-trip. The bilateral publish/subscribe path was a v0.3.0 release
gap: malformed adverts could panic consumers, broken signatures could
go undetected, and reverse-direction subscription was unverified.
Adds testing/nat/scripts/nostr-relay-test.sh (290 lines):
Phase 1+2 (combined): wait_for_peers on both nodes; pass on
bidirectional advert publish/subscribe round-trip + dial completed;
ping6 both directions confirms TUN-level reachability.
Phase 3 (malformed advert resilience): stdlib-only Python WebSocket
client publishes a syntactically valid Schnorr-signed Kind-37195
event whose `content` is gibberish (cannot deserialize as
OverlayAdvert). The relay enforces BIP-340 signature validity, so the
event reaches the consumers (rather than being dropped at the relay)
— a trivially-junk content payload is the right adversarial input.
Required ~80 lines of stdlib-only secp256k1 + BIP-340 in the script
(no new container deps). Asserts pidof fips on both nodes after the
publish, scans logs for panic markers, re-pings to prove the existing
peer link survives.
testing/nat/docker-compose.yml: new profile nostr-publish-consume
with two daemon services (nostr-pub-a 172.31.10.20, nostr-pub-b
172.31.10.21) on shared-lan, reusing the existing strfry relay
(172.31.10.30:7777) and STUN service (172.31.10.40:3478).
testing/nat/scripts/generate-configs.sh: 2-line allowlist update so
the new scenario flows through the existing config generator (rather
than forking a parallel one). Generated node-{a,b}.yaml + npubs.env
smoke-tested cleanly.
testing/ci-local.sh: NOSTR_RELAY_SUITES=(nostr-publish-consume)
array, run_nostr_publish_consume runner, dispatch in run_integration
and run_suite. Mirrors existing run_nat shape.
.github/workflows/ci.yml: one matrix row + 3 steps in the integration
job, gated on matrix.type == 'nostr-publish-consume'. Consumes the
same fips-linux artifact and fips-test:latest image as the existing
NAT suites.
Tor/TCP transport variants kept out of v0.3.0 scope; the structure
leaves room for nostr-publish-consume-tcp/-tor siblings later without
disturbing this baseline.
This commit is contained in:
@@ -376,6 +376,13 @@ jobs:
|
||||
- suite: nat-lan
|
||||
type: nat
|
||||
scenario: lan
|
||||
# ── Nostr overlay advert publish/consume round-trip ─────────────
|
||||
# Two FIPS daemons + the existing strfry relay; covers Phase 1
|
||||
# (A→B publish/consume), Phase 2 (B→A reverse), and Phase 3
|
||||
# (malformed advert injected to relay; consumers must reject
|
||||
# without crashing). UDP transport baseline for v0.3.0.
|
||||
- suite: nostr-publish-consume
|
||||
type: nostr-publish-consume
|
||||
# ── Real-deb install across target distros ─────────────────────
|
||||
# Boots a privileged systemd container per distro, runs
|
||||
# `apt install ./fips_*.deb` with the locally-built package,
|
||||
@@ -617,6 +624,23 @@ jobs:
|
||||
--profile cone --profile symmetric --profile lan \
|
||||
down --volumes --remove-orphans
|
||||
|
||||
# ── Nostr overlay advert publish/consume ───────────────────────────
|
||||
- name: Run Nostr publish/consume test
|
||||
if: matrix.type == 'nostr-publish-consume'
|
||||
run: bash testing/nat/scripts/nostr-relay-test.sh
|
||||
|
||||
- name: Collect logs on failure (nostr-publish-consume)
|
||||
if: matrix.type == 'nostr-publish-consume' && failure()
|
||||
run: |
|
||||
docker compose -f testing/nat/docker-compose.yml \
|
||||
--profile nostr-publish-consume logs --no-color | tail -300
|
||||
|
||||
- name: Stop containers (nostr-publish-consume)
|
||||
if: matrix.type == 'nostr-publish-consume' && always()
|
||||
run: |
|
||||
docker compose -f testing/nat/docker-compose.yml \
|
||||
--profile nostr-publish-consume down --volumes --remove-orphans
|
||||
|
||||
# ── Outbound LAN gateway integration test ──────────────────────────
|
||||
- name: Generate configs (gateway)
|
||||
if: matrix.type == 'gateway'
|
||||
|
||||
Reference in New Issue
Block a user