From 9213cce6c47a6e9255407ec1bbd3919e5e403aef Mon Sep 17 00:00:00 2001 From: Johnathan Corgan Date: Fri, 24 Jul 2026 03:51:13 +0000 Subject: [PATCH] Retire the rekey Docker suites; timing, continuity and variants are in-process The three rekey integration suites (rekey, rekey-accept-off, rekey-outbound-only) are dropped from both runners. Their coverage now lives in fast, deterministic in-process tests: - rekey timing and choreography (trigger, K-bit cutover, drain, jitter, guards) in the sans-IO poll_rekey tests (proto/fsp, proto/fmp); - data-plane continuity across a real cutover in rekey_cutover_preserves_data_plane (a real IK rekey over loopback); - the accept-off dual-init regression and the udp.outbound_only rekey loop in the should_admit_msg1 and dual-init characterization tests. Drop them from both runners in lockstep so the parity guard stays green, and record the retirement in the deliberately-not-run block with a pointer to the standalone runner. The rekey-test.sh script stays on disk. --- .github/workflows/ci.yml | 109 ---------------------------------- testing/ci-local.sh | 124 +++++---------------------------------- 2 files changed, 14 insertions(+), 219 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 2899e92..15d65f3 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -414,16 +414,6 @@ jobs: - suite: static-chain type: static topology: chain - # ── Rekey integration test ────────────────────────────────────────── - - suite: rekey - type: rekey - topology: rekey - - suite: rekey-accept-off - type: rekey-accept-off - topology: rekey-accept-off - - suite: rekey-outbound-only - type: rekey-outbound-only - topology: rekey-outbound-only # ── Firewall baseline (fips0 nftables default-deny) ──────────── - suite: firewall type: firewall @@ -563,105 +553,6 @@ jobs: docker compose -f testing/static/docker-compose.yml \ --profile ${{ matrix.topology }} down --volumes --remove-orphans - # ── Rekey integration test ────────────────────────────────────────────── - - name: Generate and inject configs (rekey) - if: matrix.type == 'rekey' - run: | - bash testing/static/scripts/generate-configs.sh rekey - bash testing/static/scripts/rekey-test.sh inject-config - - - name: Start containers (rekey) - if: matrix.type == 'rekey' - run: | - docker compose -f testing/static/docker-compose.yml \ - --profile rekey up -d - - - name: Run rekey test - if: matrix.type == 'rekey' - run: bash testing/static/scripts/rekey-test.sh - - - name: Collect logs on failure (rekey) - if: matrix.type == 'rekey' && failure() - run: | - docker compose -f testing/static/docker-compose.yml \ - --profile rekey logs --no-color - - - name: Stop containers (rekey) - if: matrix.type == 'rekey' && always() - run: | - docker compose -f testing/static/docker-compose.yml \ - --profile rekey down --volumes --remove-orphans - - # ── Rekey + accept_connections=false variant ────────────────────────── - - name: Generate and inject configs (rekey-accept-off) - if: matrix.type == 'rekey-accept-off' - env: - REKEY_TOPOLOGY: rekey-accept-off - REKEY_ACCEPT_OFF_NODES: b - run: | - bash testing/static/scripts/generate-configs.sh rekey-accept-off - bash testing/static/scripts/rekey-test.sh inject-config - - - name: Start containers (rekey-accept-off) - if: matrix.type == 'rekey-accept-off' - run: | - docker compose -f testing/static/docker-compose.yml \ - --profile rekey-accept-off up -d - - - name: Run rekey test (accept-off variant) - if: matrix.type == 'rekey-accept-off' - env: - REKEY_TOPOLOGY: rekey-accept-off - REKEY_ACCEPT_OFF_NODES: b - run: bash testing/static/scripts/rekey-test.sh - - - name: Collect logs on failure (rekey-accept-off) - if: matrix.type == 'rekey-accept-off' && failure() - run: | - docker compose -f testing/static/docker-compose.yml \ - --profile rekey-accept-off logs --no-color | tail -300 - - - name: Stop containers (rekey-accept-off) - if: matrix.type == 'rekey-accept-off' && always() - run: | - docker compose -f testing/static/docker-compose.yml \ - --profile rekey-accept-off down --volumes --remove-orphans - - # ── Rekey + udp.outbound_only=true variant ───────────────────────────── - - name: Generate and inject configs (rekey-outbound-only) - if: matrix.type == 'rekey-outbound-only' - env: - REKEY_TOPOLOGY: rekey-outbound-only - REKEY_OUTBOUND_ONLY_NODES: b - run: | - bash testing/static/scripts/generate-configs.sh rekey-outbound-only - bash testing/static/scripts/rekey-test.sh inject-config - - - name: Start containers (rekey-outbound-only) - if: matrix.type == 'rekey-outbound-only' - run: | - docker compose -f testing/static/docker-compose.yml \ - --profile rekey-outbound-only up -d - - - name: Run rekey test (outbound-only variant) - if: matrix.type == 'rekey-outbound-only' - env: - REKEY_TOPOLOGY: rekey-outbound-only - REKEY_OUTBOUND_ONLY_NODES: b - run: bash testing/static/scripts/rekey-test.sh - - - name: Collect logs on failure (rekey-outbound-only) - if: matrix.type == 'rekey-outbound-only' && failure() - run: | - docker compose -f testing/static/docker-compose.yml \ - --profile rekey-outbound-only logs --no-color | tail -300 - - - name: Stop containers (rekey-outbound-only) - if: matrix.type == 'rekey-outbound-only' && always() - run: | - docker compose -f testing/static/docker-compose.yml \ - --profile rekey-outbound-only down --volumes --remove-orphans - # ── Firewall baseline integration test ───────────────────────────────── - name: Run firewall baseline integration test if: matrix.type == 'firewall' diff --git a/testing/ci-local.sh b/testing/ci-local.sh index f879ff4..9ca36a1 100755 --- a/testing/ci-local.sh +++ b/testing/ci-local.sh @@ -26,8 +26,7 @@ # -h, --help Show this help # # Integration suites (default coverage): -# static-mesh, static-chain, rekey, rekey-accept-off, -# rekey-outbound-only, gateway, +# static-mesh, static-chain, gateway, # firewall, nat-cone, nat-symmetric, # nat-lan, nostr-publish-consume, stun-faults, # chaos-churn-mixed-10, chaos-ethernet-mesh, @@ -74,6 +73,19 @@ # discriminator the Docker tcpdump used — plus a sibling # test for the existing-peer bypass. Still runnable by hand: # bash testing/static/scripts/admission-cap-test.sh +# rekey, rekey-accept-off, rekey-outbound-only +# Retired from CI 2026-07-24 as redundant, not unrunnable. +# The rekey timing/choreography decision (trigger, K-bit +# cutover, drain, jitter, guards) is covered by the sans-IO +# poll_rekey tests (src/proto/fsp/tests/core.rs, +# src/proto/fmp/tests/core.rs); the data-plane continuity +# across a real cutover by rekey_cutover_preserves_data_plane +# (src/node/tests/session.rs, a real IK rekey over loopback); +# the accept-off dual-init regression and the +# udp.outbound_only rekey loop by the should_admit_msg1 and +# dual-init chartests (src/node/tests/handshake.rs, +# establish_chartests.rs). Still runnable by hand: +# bash testing/static/scripts/rekey-test.sh # ecn-ab-on, ecn-ab-off, maelstrom, maelstrom-sparse # Chaos scenarios excluded from CHAOS_SUITES. The two # ecn-ab ones are halves of the manual comparison above. @@ -133,7 +145,6 @@ ONLY_SUITE="" # All integration suites matching ci.yml STATIC_SUITES=(static-mesh static-chain) -REKEY_SUITES=(rekey rekey-accept-off rekey-outbound-only) # Each entry: "display-name scenario [--flag value ...]" CHAOS_SUITES=( "churn-mixed-10 churn-mixed --nodes 10 --duration 120" @@ -198,9 +209,6 @@ list_suites() { echo " Static topologies:" for s in "${STATIC_SUITES[@]}"; do echo " $s"; done echo "" - echo " Rekey:" - for s in "${REKEY_SUITES[@]}"; do echo " $s"; done - echo "" echo " Gateway:" for s in "${GATEWAY_SUITES[@]}"; do echo " $s"; done echo "" @@ -548,32 +556,6 @@ run_static() { record "static-$topology" $rc } -# Run the rekey integration test -run_rekey() { - local compose="testing/static/docker-compose.yml" - local rc=0 - export COMPOSE_PROJECT_NAME="$(ci_project static)" - - info "[rekey] Generating configs" - bash testing/static/scripts/generate-configs.sh rekey || { record "rekey" 1; return; } - bash testing/static/scripts/rekey-test.sh inject-config || { record "rekey" 1; return; } - - info "[rekey] Starting containers" - docker compose -f "$compose" --profile rekey up -d || { record "rekey" 1; return; } - - info "[rekey] Running rekey test" - if bash testing/static/scripts/rekey-test.sh; then - rc=0 - else - rc=1 - info "[rekey] Collecting failure logs" - docker compose -f "$compose" --profile rekey logs --no-color 2>&1 | tail -100 - fi - - docker compose -f "$compose" --profile rekey down --volumes --remove-orphans 2>/dev/null - record "rekey" $rc -} - # Run a chaos scenario run_chaos() { local name="$1" @@ -701,73 +683,6 @@ run_sidecar() { record "sidecar" $rc } -# Run the rekey-accept-off integration variant. Same harness as run_rekey -# but on a 2-node topology with udp.accept_connections=false on node-b. -run_rekey_accept_off() { - local compose="testing/static/docker-compose.yml" - local rc=0 - export COMPOSE_PROJECT_NAME="$(ci_project static)" - - info "[rekey-accept-off] Generating configs" - bash testing/static/scripts/generate-configs.sh rekey-accept-off || \ - { record "rekey-accept-off" 1; return; } - REKEY_TOPOLOGY=rekey-accept-off REKEY_ACCEPT_OFF_NODES=b \ - bash testing/static/scripts/rekey-test.sh inject-config || \ - { record "rekey-accept-off" 1; return; } - - info "[rekey-accept-off] Starting containers" - docker compose -f "$compose" --profile rekey-accept-off up -d || \ - { record "rekey-accept-off" 1; return; } - - info "[rekey-accept-off] Running rekey test" - if REKEY_TOPOLOGY=rekey-accept-off REKEY_ACCEPT_OFF_NODES=b \ - bash testing/static/scripts/rekey-test.sh; then - rc=0 - else - rc=1 - info "[rekey-accept-off] Collecting failure logs" - docker compose -f "$compose" --profile rekey-accept-off logs --no-color 2>&1 | tail -100 - fi - - docker compose -f "$compose" --profile rekey-accept-off down --volumes --remove-orphans 2>/dev/null - record "rekey-accept-off" $rc -} - -# Run the rekey-outbound-only integration variant. Same harness as -# run_rekey but with udp.outbound_only=true on node-b plus its peer -# addrs rewritten from numeric docker IPs to docker hostnames so the -# addr_to_link key form mismatches inbound packet source addrs (the -# production trigger for the rekey-msg1 carve-out gap). -run_rekey_outbound_only() { - local compose="testing/static/docker-compose.yml" - local rc=0 - export COMPOSE_PROJECT_NAME="$(ci_project static)" - - info "[rekey-outbound-only] Generating configs" - bash testing/static/scripts/generate-configs.sh rekey-outbound-only || \ - { record "rekey-outbound-only" 1; return; } - REKEY_TOPOLOGY=rekey-outbound-only REKEY_OUTBOUND_ONLY_NODES=b \ - bash testing/static/scripts/rekey-test.sh inject-config || \ - { record "rekey-outbound-only" 1; return; } - - info "[rekey-outbound-only] Starting containers" - docker compose -f "$compose" --profile rekey-outbound-only up -d || \ - { record "rekey-outbound-only" 1; return; } - - info "[rekey-outbound-only] Running rekey test" - if REKEY_TOPOLOGY=rekey-outbound-only REKEY_OUTBOUND_ONLY_NODES=b \ - bash testing/static/scripts/rekey-test.sh; then - rc=0 - else - rc=1 - info "[rekey-outbound-only] Collecting failure logs" - docker compose -f "$compose" --profile rekey-outbound-only logs --no-color 2>&1 | tail -100 - fi - - docker compose -f "$compose" --profile rekey-outbound-only down --volumes --remove-orphans 2>/dev/null - record "rekey-outbound-only" $rc -} - # Run firewall baseline integration test run_firewall() { export COMPOSE_PROJECT_NAME="$(ci_project firewall)" @@ -897,11 +812,6 @@ run_integration() { run_static "$topology" done - # Rekey + rekey-accept-off + rekey-outbound-only variants - run_rekey - run_rekey_accept_off - run_rekey_outbound_only - # Gateway run_gateway @@ -1009,12 +919,6 @@ run_suite() { case "$suite" in static-mesh|static-chain) run_static "${suite#static-}" ;; - rekey) - run_rekey ;; - rekey-accept-off) - run_rekey_accept_off ;; - rekey-outbound-only) - run_rekey_outbound_only ;; gateway) run_gateway ;; firewall)