diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index daf8c116..c57cf625 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -106,6 +106,11 @@ jobs: # reports. Kept in step with ci-local.sh's run_nextest_flaky by hand. - name: Check the flaky-test reporter against its fixtures run: bash testing/nextest-flaky/test.sh + # The glibc floor check's cases, built from the host's own true + # executable. Not a matrix suite, so it is kept in step with + # ci-local.sh's run_glibc_floor by hand. + - name: Check the glibc floor check against its cases + run: bash testing/glibc-floor/test.sh fmt: name: Format check diff --git a/testing/check-glibc-floor.sh b/testing/check-glibc-floor.sh index 1ca81deb..cdce9506 100755 --- a/testing/check-glibc-floor.sh +++ b/testing/check-glibc-floor.sh @@ -16,17 +16,37 @@ # Anything else is treated as a single ELF binary. # # Reads the floor from packaging/build-floor.env unless FIPS_GLIBC_FLOOR is set. +# +# Exit 0 = every input was examined and none is above the floor. Exit 1 = a +# binary needs a newer glibc than the floor. Exit 2 = an input could not be +# examined (missing, not an ELF object, a .deb that would not unpack or holds +# no binaries), or the check could not run at all; never treated as a pass, +# and never reported as a binary above the floor. set -euo pipefail SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)" REPO_ROOT="$(cd "$SCRIPT_DIR/.." && pwd)" +# A missing or empty floor means the check cannot run, so it exits 2 here +# rather than letting `set -e` or a `:?` expansion end the run with status 1, +# which callers would read as a binary above the floor. +FLOOR_ENV="$REPO_ROOT/packaging/build-floor.env" if [ -z "${FIPS_GLIBC_FLOOR:-}" ]; then - # shellcheck source=../packaging/build-floor.env - . "$REPO_ROOT/packaging/build-floor.env" + [ -r "$FLOOR_ENV" ] || { + echo "check-glibc-floor: cannot read $FLOOR_ENV and FIPS_GLIBC_FLOOR is not set;" >&2 + echo " there is no floor to check against." >&2 + exit 2 + } + # shellcheck source-path=SCRIPTDIR source=../packaging/build-floor.env + . "$FLOOR_ENV" fi -FLOOR="${FIPS_GLIBC_FLOOR:?no floor declared}" +if [ -z "${FIPS_GLIBC_FLOOR:-}" ]; then + echo "check-glibc-floor: $FLOOR_ENV declares no FIPS_GLIBC_FLOOR;" >&2 + echo " there is no floor to check against." >&2 + exit 2 +fi +FLOOR="$FIPS_GLIBC_FLOOR" for tool in readelf dpkg dpkg-deb; do command -v "$tool" >/dev/null 2>&1 || { @@ -65,6 +85,18 @@ max_glibc_need() { FAILED=0 CHECKED=0 +UNCHECKED=0 +UNCHECKED_LIST=() + +# unchecked