mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-30 19:46:15 +00:00
Retire the rekey Docker suites; timing, continuity and variants are in-process
The three rekey integration suites (rekey, rekey-accept-off, rekey-outbound-only) are dropped from both runners. Their coverage now lives in fast, deterministic in-process tests: - rekey timing and choreography (trigger, K-bit cutover, drain, jitter, guards) in the sans-IO poll_rekey tests (proto/fsp, proto/fmp); - data-plane continuity across a real cutover in rekey_cutover_preserves_data_plane (a real IK rekey over loopback); - the accept-off dual-init regression and the udp.outbound_only rekey loop in the should_admit_msg1 and dual-init characterization tests. Drop them from both runners in lockstep so the parity guard stays green, and record the retirement in the deliberately-not-run block with a pointer to the standalone runner. The rekey-test.sh script stays on disk.
This commit is contained in:
@@ -414,16 +414,6 @@ jobs:
|
|||||||
- suite: static-chain
|
- suite: static-chain
|
||||||
type: static
|
type: static
|
||||||
topology: chain
|
topology: chain
|
||||||
# ── Rekey integration test ──────────────────────────────────────────
|
|
||||||
- suite: rekey
|
|
||||||
type: rekey
|
|
||||||
topology: rekey
|
|
||||||
- suite: rekey-accept-off
|
|
||||||
type: rekey-accept-off
|
|
||||||
topology: rekey-accept-off
|
|
||||||
- suite: rekey-outbound-only
|
|
||||||
type: rekey-outbound-only
|
|
||||||
topology: rekey-outbound-only
|
|
||||||
# ── Firewall baseline (fips0 nftables default-deny) ────────────
|
# ── Firewall baseline (fips0 nftables default-deny) ────────────
|
||||||
- suite: firewall
|
- suite: firewall
|
||||||
type: firewall
|
type: firewall
|
||||||
@@ -563,105 +553,6 @@ jobs:
|
|||||||
docker compose -f testing/static/docker-compose.yml \
|
docker compose -f testing/static/docker-compose.yml \
|
||||||
--profile ${{ matrix.topology }} down --volumes --remove-orphans
|
--profile ${{ matrix.topology }} down --volumes --remove-orphans
|
||||||
|
|
||||||
# ── Rekey integration test ──────────────────────────────────────────────
|
|
||||||
- name: Generate and inject configs (rekey)
|
|
||||||
if: matrix.type == 'rekey'
|
|
||||||
run: |
|
|
||||||
bash testing/static/scripts/generate-configs.sh rekey
|
|
||||||
bash testing/static/scripts/rekey-test.sh inject-config
|
|
||||||
|
|
||||||
- name: Start containers (rekey)
|
|
||||||
if: matrix.type == 'rekey'
|
|
||||||
run: |
|
|
||||||
docker compose -f testing/static/docker-compose.yml \
|
|
||||||
--profile rekey up -d
|
|
||||||
|
|
||||||
- name: Run rekey test
|
|
||||||
if: matrix.type == 'rekey'
|
|
||||||
run: bash testing/static/scripts/rekey-test.sh
|
|
||||||
|
|
||||||
- name: Collect logs on failure (rekey)
|
|
||||||
if: matrix.type == 'rekey' && failure()
|
|
||||||
run: |
|
|
||||||
docker compose -f testing/static/docker-compose.yml \
|
|
||||||
--profile rekey logs --no-color
|
|
||||||
|
|
||||||
- name: Stop containers (rekey)
|
|
||||||
if: matrix.type == 'rekey' && always()
|
|
||||||
run: |
|
|
||||||
docker compose -f testing/static/docker-compose.yml \
|
|
||||||
--profile rekey down --volumes --remove-orphans
|
|
||||||
|
|
||||||
# ── Rekey + accept_connections=false variant ──────────────────────────
|
|
||||||
- name: Generate and inject configs (rekey-accept-off)
|
|
||||||
if: matrix.type == 'rekey-accept-off'
|
|
||||||
env:
|
|
||||||
REKEY_TOPOLOGY: rekey-accept-off
|
|
||||||
REKEY_ACCEPT_OFF_NODES: b
|
|
||||||
run: |
|
|
||||||
bash testing/static/scripts/generate-configs.sh rekey-accept-off
|
|
||||||
bash testing/static/scripts/rekey-test.sh inject-config
|
|
||||||
|
|
||||||
- name: Start containers (rekey-accept-off)
|
|
||||||
if: matrix.type == 'rekey-accept-off'
|
|
||||||
run: |
|
|
||||||
docker compose -f testing/static/docker-compose.yml \
|
|
||||||
--profile rekey-accept-off up -d
|
|
||||||
|
|
||||||
- name: Run rekey test (accept-off variant)
|
|
||||||
if: matrix.type == 'rekey-accept-off'
|
|
||||||
env:
|
|
||||||
REKEY_TOPOLOGY: rekey-accept-off
|
|
||||||
REKEY_ACCEPT_OFF_NODES: b
|
|
||||||
run: bash testing/static/scripts/rekey-test.sh
|
|
||||||
|
|
||||||
- name: Collect logs on failure (rekey-accept-off)
|
|
||||||
if: matrix.type == 'rekey-accept-off' && failure()
|
|
||||||
run: |
|
|
||||||
docker compose -f testing/static/docker-compose.yml \
|
|
||||||
--profile rekey-accept-off logs --no-color | tail -300
|
|
||||||
|
|
||||||
- name: Stop containers (rekey-accept-off)
|
|
||||||
if: matrix.type == 'rekey-accept-off' && always()
|
|
||||||
run: |
|
|
||||||
docker compose -f testing/static/docker-compose.yml \
|
|
||||||
--profile rekey-accept-off down --volumes --remove-orphans
|
|
||||||
|
|
||||||
# ── Rekey + udp.outbound_only=true variant ─────────────────────────────
|
|
||||||
- name: Generate and inject configs (rekey-outbound-only)
|
|
||||||
if: matrix.type == 'rekey-outbound-only'
|
|
||||||
env:
|
|
||||||
REKEY_TOPOLOGY: rekey-outbound-only
|
|
||||||
REKEY_OUTBOUND_ONLY_NODES: b
|
|
||||||
run: |
|
|
||||||
bash testing/static/scripts/generate-configs.sh rekey-outbound-only
|
|
||||||
bash testing/static/scripts/rekey-test.sh inject-config
|
|
||||||
|
|
||||||
- name: Start containers (rekey-outbound-only)
|
|
||||||
if: matrix.type == 'rekey-outbound-only'
|
|
||||||
run: |
|
|
||||||
docker compose -f testing/static/docker-compose.yml \
|
|
||||||
--profile rekey-outbound-only up -d
|
|
||||||
|
|
||||||
- name: Run rekey test (outbound-only variant)
|
|
||||||
if: matrix.type == 'rekey-outbound-only'
|
|
||||||
env:
|
|
||||||
REKEY_TOPOLOGY: rekey-outbound-only
|
|
||||||
REKEY_OUTBOUND_ONLY_NODES: b
|
|
||||||
run: bash testing/static/scripts/rekey-test.sh
|
|
||||||
|
|
||||||
- name: Collect logs on failure (rekey-outbound-only)
|
|
||||||
if: matrix.type == 'rekey-outbound-only' && failure()
|
|
||||||
run: |
|
|
||||||
docker compose -f testing/static/docker-compose.yml \
|
|
||||||
--profile rekey-outbound-only logs --no-color | tail -300
|
|
||||||
|
|
||||||
- name: Stop containers (rekey-outbound-only)
|
|
||||||
if: matrix.type == 'rekey-outbound-only' && always()
|
|
||||||
run: |
|
|
||||||
docker compose -f testing/static/docker-compose.yml \
|
|
||||||
--profile rekey-outbound-only down --volumes --remove-orphans
|
|
||||||
|
|
||||||
# ── Firewall baseline integration test ─────────────────────────────────
|
# ── Firewall baseline integration test ─────────────────────────────────
|
||||||
- name: Run firewall baseline integration test
|
- name: Run firewall baseline integration test
|
||||||
if: matrix.type == 'firewall'
|
if: matrix.type == 'firewall'
|
||||||
|
|||||||
+14
-110
@@ -26,8 +26,7 @@
|
|||||||
# -h, --help Show this help
|
# -h, --help Show this help
|
||||||
#
|
#
|
||||||
# Integration suites (default coverage):
|
# Integration suites (default coverage):
|
||||||
# static-mesh, static-chain, rekey, rekey-accept-off,
|
# static-mesh, static-chain, gateway,
|
||||||
# rekey-outbound-only, gateway,
|
|
||||||
# firewall, nat-cone, nat-symmetric,
|
# firewall, nat-cone, nat-symmetric,
|
||||||
# nat-lan, nostr-publish-consume, stun-faults,
|
# nat-lan, nostr-publish-consume, stun-faults,
|
||||||
# chaos-churn-mixed-10, chaos-ethernet-mesh,
|
# chaos-churn-mixed-10, chaos-ethernet-mesh,
|
||||||
@@ -74,6 +73,19 @@
|
|||||||
# discriminator the Docker tcpdump used — plus a sibling
|
# discriminator the Docker tcpdump used — plus a sibling
|
||||||
# test for the existing-peer bypass. Still runnable by hand:
|
# test for the existing-peer bypass. Still runnable by hand:
|
||||||
# bash testing/static/scripts/admission-cap-test.sh
|
# bash testing/static/scripts/admission-cap-test.sh
|
||||||
|
# rekey, rekey-accept-off, rekey-outbound-only
|
||||||
|
# Retired from CI 2026-07-24 as redundant, not unrunnable.
|
||||||
|
# The rekey timing/choreography decision (trigger, K-bit
|
||||||
|
# cutover, drain, jitter, guards) is covered by the sans-IO
|
||||||
|
# poll_rekey tests (src/proto/fsp/tests/core.rs,
|
||||||
|
# src/proto/fmp/tests/core.rs); the data-plane continuity
|
||||||
|
# across a real cutover by rekey_cutover_preserves_data_plane
|
||||||
|
# (src/node/tests/session.rs, a real IK rekey over loopback);
|
||||||
|
# the accept-off dual-init regression and the
|
||||||
|
# udp.outbound_only rekey loop by the should_admit_msg1 and
|
||||||
|
# dual-init chartests (src/node/tests/handshake.rs,
|
||||||
|
# establish_chartests.rs). Still runnable by hand:
|
||||||
|
# bash testing/static/scripts/rekey-test.sh
|
||||||
# ecn-ab-on, ecn-ab-off, maelstrom, maelstrom-sparse
|
# ecn-ab-on, ecn-ab-off, maelstrom, maelstrom-sparse
|
||||||
# Chaos scenarios excluded from CHAOS_SUITES. The two
|
# Chaos scenarios excluded from CHAOS_SUITES. The two
|
||||||
# ecn-ab ones are halves of the manual comparison above.
|
# ecn-ab ones are halves of the manual comparison above.
|
||||||
@@ -133,7 +145,6 @@ ONLY_SUITE=""
|
|||||||
|
|
||||||
# All integration suites matching ci.yml
|
# All integration suites matching ci.yml
|
||||||
STATIC_SUITES=(static-mesh static-chain)
|
STATIC_SUITES=(static-mesh static-chain)
|
||||||
REKEY_SUITES=(rekey rekey-accept-off rekey-outbound-only)
|
|
||||||
# Each entry: "display-name scenario [--flag value ...]"
|
# Each entry: "display-name scenario [--flag value ...]"
|
||||||
CHAOS_SUITES=(
|
CHAOS_SUITES=(
|
||||||
"churn-mixed-10 churn-mixed --nodes 10 --duration 120"
|
"churn-mixed-10 churn-mixed --nodes 10 --duration 120"
|
||||||
@@ -198,9 +209,6 @@ list_suites() {
|
|||||||
echo " Static topologies:"
|
echo " Static topologies:"
|
||||||
for s in "${STATIC_SUITES[@]}"; do echo " $s"; done
|
for s in "${STATIC_SUITES[@]}"; do echo " $s"; done
|
||||||
echo ""
|
echo ""
|
||||||
echo " Rekey:"
|
|
||||||
for s in "${REKEY_SUITES[@]}"; do echo " $s"; done
|
|
||||||
echo ""
|
|
||||||
echo " Gateway:"
|
echo " Gateway:"
|
||||||
for s in "${GATEWAY_SUITES[@]}"; do echo " $s"; done
|
for s in "${GATEWAY_SUITES[@]}"; do echo " $s"; done
|
||||||
echo ""
|
echo ""
|
||||||
@@ -548,32 +556,6 @@ run_static() {
|
|||||||
record "static-$topology" $rc
|
record "static-$topology" $rc
|
||||||
}
|
}
|
||||||
|
|
||||||
# Run the rekey integration test
|
|
||||||
run_rekey() {
|
|
||||||
local compose="testing/static/docker-compose.yml"
|
|
||||||
local rc=0
|
|
||||||
export COMPOSE_PROJECT_NAME="$(ci_project static)"
|
|
||||||
|
|
||||||
info "[rekey] Generating configs"
|
|
||||||
bash testing/static/scripts/generate-configs.sh rekey || { record "rekey" 1; return; }
|
|
||||||
bash testing/static/scripts/rekey-test.sh inject-config || { record "rekey" 1; return; }
|
|
||||||
|
|
||||||
info "[rekey] Starting containers"
|
|
||||||
docker compose -f "$compose" --profile rekey up -d || { record "rekey" 1; return; }
|
|
||||||
|
|
||||||
info "[rekey] Running rekey test"
|
|
||||||
if bash testing/static/scripts/rekey-test.sh; then
|
|
||||||
rc=0
|
|
||||||
else
|
|
||||||
rc=1
|
|
||||||
info "[rekey] Collecting failure logs"
|
|
||||||
docker compose -f "$compose" --profile rekey logs --no-color 2>&1 | tail -100
|
|
||||||
fi
|
|
||||||
|
|
||||||
docker compose -f "$compose" --profile rekey down --volumes --remove-orphans 2>/dev/null
|
|
||||||
record "rekey" $rc
|
|
||||||
}
|
|
||||||
|
|
||||||
# Run a chaos scenario
|
# Run a chaos scenario
|
||||||
run_chaos() {
|
run_chaos() {
|
||||||
local name="$1"
|
local name="$1"
|
||||||
@@ -701,73 +683,6 @@ run_sidecar() {
|
|||||||
record "sidecar" $rc
|
record "sidecar" $rc
|
||||||
}
|
}
|
||||||
|
|
||||||
# Run the rekey-accept-off integration variant. Same harness as run_rekey
|
|
||||||
# but on a 2-node topology with udp.accept_connections=false on node-b.
|
|
||||||
run_rekey_accept_off() {
|
|
||||||
local compose="testing/static/docker-compose.yml"
|
|
||||||
local rc=0
|
|
||||||
export COMPOSE_PROJECT_NAME="$(ci_project static)"
|
|
||||||
|
|
||||||
info "[rekey-accept-off] Generating configs"
|
|
||||||
bash testing/static/scripts/generate-configs.sh rekey-accept-off || \
|
|
||||||
{ record "rekey-accept-off" 1; return; }
|
|
||||||
REKEY_TOPOLOGY=rekey-accept-off REKEY_ACCEPT_OFF_NODES=b \
|
|
||||||
bash testing/static/scripts/rekey-test.sh inject-config || \
|
|
||||||
{ record "rekey-accept-off" 1; return; }
|
|
||||||
|
|
||||||
info "[rekey-accept-off] Starting containers"
|
|
||||||
docker compose -f "$compose" --profile rekey-accept-off up -d || \
|
|
||||||
{ record "rekey-accept-off" 1; return; }
|
|
||||||
|
|
||||||
info "[rekey-accept-off] Running rekey test"
|
|
||||||
if REKEY_TOPOLOGY=rekey-accept-off REKEY_ACCEPT_OFF_NODES=b \
|
|
||||||
bash testing/static/scripts/rekey-test.sh; then
|
|
||||||
rc=0
|
|
||||||
else
|
|
||||||
rc=1
|
|
||||||
info "[rekey-accept-off] Collecting failure logs"
|
|
||||||
docker compose -f "$compose" --profile rekey-accept-off logs --no-color 2>&1 | tail -100
|
|
||||||
fi
|
|
||||||
|
|
||||||
docker compose -f "$compose" --profile rekey-accept-off down --volumes --remove-orphans 2>/dev/null
|
|
||||||
record "rekey-accept-off" $rc
|
|
||||||
}
|
|
||||||
|
|
||||||
# Run the rekey-outbound-only integration variant. Same harness as
|
|
||||||
# run_rekey but with udp.outbound_only=true on node-b plus its peer
|
|
||||||
# addrs rewritten from numeric docker IPs to docker hostnames so the
|
|
||||||
# addr_to_link key form mismatches inbound packet source addrs (the
|
|
||||||
# production trigger for the rekey-msg1 carve-out gap).
|
|
||||||
run_rekey_outbound_only() {
|
|
||||||
local compose="testing/static/docker-compose.yml"
|
|
||||||
local rc=0
|
|
||||||
export COMPOSE_PROJECT_NAME="$(ci_project static)"
|
|
||||||
|
|
||||||
info "[rekey-outbound-only] Generating configs"
|
|
||||||
bash testing/static/scripts/generate-configs.sh rekey-outbound-only || \
|
|
||||||
{ record "rekey-outbound-only" 1; return; }
|
|
||||||
REKEY_TOPOLOGY=rekey-outbound-only REKEY_OUTBOUND_ONLY_NODES=b \
|
|
||||||
bash testing/static/scripts/rekey-test.sh inject-config || \
|
|
||||||
{ record "rekey-outbound-only" 1; return; }
|
|
||||||
|
|
||||||
info "[rekey-outbound-only] Starting containers"
|
|
||||||
docker compose -f "$compose" --profile rekey-outbound-only up -d || \
|
|
||||||
{ record "rekey-outbound-only" 1; return; }
|
|
||||||
|
|
||||||
info "[rekey-outbound-only] Running rekey test"
|
|
||||||
if REKEY_TOPOLOGY=rekey-outbound-only REKEY_OUTBOUND_ONLY_NODES=b \
|
|
||||||
bash testing/static/scripts/rekey-test.sh; then
|
|
||||||
rc=0
|
|
||||||
else
|
|
||||||
rc=1
|
|
||||||
info "[rekey-outbound-only] Collecting failure logs"
|
|
||||||
docker compose -f "$compose" --profile rekey-outbound-only logs --no-color 2>&1 | tail -100
|
|
||||||
fi
|
|
||||||
|
|
||||||
docker compose -f "$compose" --profile rekey-outbound-only down --volumes --remove-orphans 2>/dev/null
|
|
||||||
record "rekey-outbound-only" $rc
|
|
||||||
}
|
|
||||||
|
|
||||||
# Run firewall baseline integration test
|
# Run firewall baseline integration test
|
||||||
run_firewall() {
|
run_firewall() {
|
||||||
export COMPOSE_PROJECT_NAME="$(ci_project firewall)"
|
export COMPOSE_PROJECT_NAME="$(ci_project firewall)"
|
||||||
@@ -897,11 +812,6 @@ run_integration() {
|
|||||||
run_static "$topology"
|
run_static "$topology"
|
||||||
done
|
done
|
||||||
|
|
||||||
# Rekey + rekey-accept-off + rekey-outbound-only variants
|
|
||||||
run_rekey
|
|
||||||
run_rekey_accept_off
|
|
||||||
run_rekey_outbound_only
|
|
||||||
|
|
||||||
# Gateway
|
# Gateway
|
||||||
run_gateway
|
run_gateway
|
||||||
|
|
||||||
@@ -1009,12 +919,6 @@ run_suite() {
|
|||||||
case "$suite" in
|
case "$suite" in
|
||||||
static-mesh|static-chain)
|
static-mesh|static-chain)
|
||||||
run_static "${suite#static-}" ;;
|
run_static "${suite#static-}" ;;
|
||||||
rekey)
|
|
||||||
run_rekey ;;
|
|
||||||
rekey-accept-off)
|
|
||||||
run_rekey_accept_off ;;
|
|
||||||
rekey-outbound-only)
|
|
||||||
run_rekey_outbound_only ;;
|
|
||||||
gateway)
|
gateway)
|
||||||
run_gateway ;;
|
run_gateway ;;
|
||||||
firewall)
|
firewall)
|
||||||
|
|||||||
Reference in New Issue
Block a user