Retire the rekey Docker suites; timing, continuity and variants are in-process

The three rekey integration suites (rekey, rekey-accept-off,
rekey-outbound-only) are dropped from both runners. Their coverage now
lives in fast, deterministic in-process tests:

- rekey timing and choreography (trigger, K-bit cutover, drain, jitter,
  guards) in the sans-IO poll_rekey tests (proto/fsp, proto/fmp);
- data-plane continuity across a real cutover in
  rekey_cutover_preserves_data_plane (a real IK rekey over loopback);
- the accept-off dual-init regression and the udp.outbound_only rekey
  loop in the should_admit_msg1 and dual-init characterization tests.

Drop them from both runners in lockstep so the parity guard stays green,
and record the retirement in the deliberately-not-run block with a pointer
to the standalone runner. The rekey-test.sh script stays on disk.
This commit is contained in:
Johnathan Corgan
2026-07-24 03:51:13 +00:00
parent f44de56fd8
commit 9213cce6c4
2 changed files with 14 additions and 219 deletions
-109
View File
@@ -414,16 +414,6 @@ jobs:
- suite: static-chain - suite: static-chain
type: static type: static
topology: chain topology: chain
# ── Rekey integration test ──────────────────────────────────────────
- suite: rekey
type: rekey
topology: rekey
- suite: rekey-accept-off
type: rekey-accept-off
topology: rekey-accept-off
- suite: rekey-outbound-only
type: rekey-outbound-only
topology: rekey-outbound-only
# ── Firewall baseline (fips0 nftables default-deny) ──────────── # ── Firewall baseline (fips0 nftables default-deny) ────────────
- suite: firewall - suite: firewall
type: firewall type: firewall
@@ -563,105 +553,6 @@ jobs:
docker compose -f testing/static/docker-compose.yml \ docker compose -f testing/static/docker-compose.yml \
--profile ${{ matrix.topology }} down --volumes --remove-orphans --profile ${{ matrix.topology }} down --volumes --remove-orphans
# ── Rekey integration test ──────────────────────────────────────────────
- name: Generate and inject configs (rekey)
if: matrix.type == 'rekey'
run: |
bash testing/static/scripts/generate-configs.sh rekey
bash testing/static/scripts/rekey-test.sh inject-config
- name: Start containers (rekey)
if: matrix.type == 'rekey'
run: |
docker compose -f testing/static/docker-compose.yml \
--profile rekey up -d
- name: Run rekey test
if: matrix.type == 'rekey'
run: bash testing/static/scripts/rekey-test.sh
- name: Collect logs on failure (rekey)
if: matrix.type == 'rekey' && failure()
run: |
docker compose -f testing/static/docker-compose.yml \
--profile rekey logs --no-color
- name: Stop containers (rekey)
if: matrix.type == 'rekey' && always()
run: |
docker compose -f testing/static/docker-compose.yml \
--profile rekey down --volumes --remove-orphans
# ── Rekey + accept_connections=false variant ──────────────────────────
- name: Generate and inject configs (rekey-accept-off)
if: matrix.type == 'rekey-accept-off'
env:
REKEY_TOPOLOGY: rekey-accept-off
REKEY_ACCEPT_OFF_NODES: b
run: |
bash testing/static/scripts/generate-configs.sh rekey-accept-off
bash testing/static/scripts/rekey-test.sh inject-config
- name: Start containers (rekey-accept-off)
if: matrix.type == 'rekey-accept-off'
run: |
docker compose -f testing/static/docker-compose.yml \
--profile rekey-accept-off up -d
- name: Run rekey test (accept-off variant)
if: matrix.type == 'rekey-accept-off'
env:
REKEY_TOPOLOGY: rekey-accept-off
REKEY_ACCEPT_OFF_NODES: b
run: bash testing/static/scripts/rekey-test.sh
- name: Collect logs on failure (rekey-accept-off)
if: matrix.type == 'rekey-accept-off' && failure()
run: |
docker compose -f testing/static/docker-compose.yml \
--profile rekey-accept-off logs --no-color | tail -300
- name: Stop containers (rekey-accept-off)
if: matrix.type == 'rekey-accept-off' && always()
run: |
docker compose -f testing/static/docker-compose.yml \
--profile rekey-accept-off down --volumes --remove-orphans
# ── Rekey + udp.outbound_only=true variant ─────────────────────────────
- name: Generate and inject configs (rekey-outbound-only)
if: matrix.type == 'rekey-outbound-only'
env:
REKEY_TOPOLOGY: rekey-outbound-only
REKEY_OUTBOUND_ONLY_NODES: b
run: |
bash testing/static/scripts/generate-configs.sh rekey-outbound-only
bash testing/static/scripts/rekey-test.sh inject-config
- name: Start containers (rekey-outbound-only)
if: matrix.type == 'rekey-outbound-only'
run: |
docker compose -f testing/static/docker-compose.yml \
--profile rekey-outbound-only up -d
- name: Run rekey test (outbound-only variant)
if: matrix.type == 'rekey-outbound-only'
env:
REKEY_TOPOLOGY: rekey-outbound-only
REKEY_OUTBOUND_ONLY_NODES: b
run: bash testing/static/scripts/rekey-test.sh
- name: Collect logs on failure (rekey-outbound-only)
if: matrix.type == 'rekey-outbound-only' && failure()
run: |
docker compose -f testing/static/docker-compose.yml \
--profile rekey-outbound-only logs --no-color | tail -300
- name: Stop containers (rekey-outbound-only)
if: matrix.type == 'rekey-outbound-only' && always()
run: |
docker compose -f testing/static/docker-compose.yml \
--profile rekey-outbound-only down --volumes --remove-orphans
# ── Firewall baseline integration test ───────────────────────────────── # ── Firewall baseline integration test ─────────────────────────────────
- name: Run firewall baseline integration test - name: Run firewall baseline integration test
if: matrix.type == 'firewall' if: matrix.type == 'firewall'
+14 -110
View File
@@ -26,8 +26,7 @@
# -h, --help Show this help # -h, --help Show this help
# #
# Integration suites (default coverage): # Integration suites (default coverage):
# static-mesh, static-chain, rekey, rekey-accept-off, # static-mesh, static-chain, gateway,
# rekey-outbound-only, gateway,
# firewall, nat-cone, nat-symmetric, # firewall, nat-cone, nat-symmetric,
# nat-lan, nostr-publish-consume, stun-faults, # nat-lan, nostr-publish-consume, stun-faults,
# chaos-churn-mixed-10, chaos-ethernet-mesh, # chaos-churn-mixed-10, chaos-ethernet-mesh,
@@ -74,6 +73,19 @@
# discriminator the Docker tcpdump used — plus a sibling # discriminator the Docker tcpdump used — plus a sibling
# test for the existing-peer bypass. Still runnable by hand: # test for the existing-peer bypass. Still runnable by hand:
# bash testing/static/scripts/admission-cap-test.sh # bash testing/static/scripts/admission-cap-test.sh
# rekey, rekey-accept-off, rekey-outbound-only
# Retired from CI 2026-07-24 as redundant, not unrunnable.
# The rekey timing/choreography decision (trigger, K-bit
# cutover, drain, jitter, guards) is covered by the sans-IO
# poll_rekey tests (src/proto/fsp/tests/core.rs,
# src/proto/fmp/tests/core.rs); the data-plane continuity
# across a real cutover by rekey_cutover_preserves_data_plane
# (src/node/tests/session.rs, a real IK rekey over loopback);
# the accept-off dual-init regression and the
# udp.outbound_only rekey loop by the should_admit_msg1 and
# dual-init chartests (src/node/tests/handshake.rs,
# establish_chartests.rs). Still runnable by hand:
# bash testing/static/scripts/rekey-test.sh
# ecn-ab-on, ecn-ab-off, maelstrom, maelstrom-sparse # ecn-ab-on, ecn-ab-off, maelstrom, maelstrom-sparse
# Chaos scenarios excluded from CHAOS_SUITES. The two # Chaos scenarios excluded from CHAOS_SUITES. The two
# ecn-ab ones are halves of the manual comparison above. # ecn-ab ones are halves of the manual comparison above.
@@ -133,7 +145,6 @@ ONLY_SUITE=""
# All integration suites matching ci.yml # All integration suites matching ci.yml
STATIC_SUITES=(static-mesh static-chain) STATIC_SUITES=(static-mesh static-chain)
REKEY_SUITES=(rekey rekey-accept-off rekey-outbound-only)
# Each entry: "display-name scenario [--flag value ...]" # Each entry: "display-name scenario [--flag value ...]"
CHAOS_SUITES=( CHAOS_SUITES=(
"churn-mixed-10 churn-mixed --nodes 10 --duration 120" "churn-mixed-10 churn-mixed --nodes 10 --duration 120"
@@ -198,9 +209,6 @@ list_suites() {
echo " Static topologies:" echo " Static topologies:"
for s in "${STATIC_SUITES[@]}"; do echo " $s"; done for s in "${STATIC_SUITES[@]}"; do echo " $s"; done
echo "" echo ""
echo " Rekey:"
for s in "${REKEY_SUITES[@]}"; do echo " $s"; done
echo ""
echo " Gateway:" echo " Gateway:"
for s in "${GATEWAY_SUITES[@]}"; do echo " $s"; done for s in "${GATEWAY_SUITES[@]}"; do echo " $s"; done
echo "" echo ""
@@ -548,32 +556,6 @@ run_static() {
record "static-$topology" $rc record "static-$topology" $rc
} }
# Run the rekey integration test
run_rekey() {
local compose="testing/static/docker-compose.yml"
local rc=0
export COMPOSE_PROJECT_NAME="$(ci_project static)"
info "[rekey] Generating configs"
bash testing/static/scripts/generate-configs.sh rekey || { record "rekey" 1; return; }
bash testing/static/scripts/rekey-test.sh inject-config || { record "rekey" 1; return; }
info "[rekey] Starting containers"
docker compose -f "$compose" --profile rekey up -d || { record "rekey" 1; return; }
info "[rekey] Running rekey test"
if bash testing/static/scripts/rekey-test.sh; then
rc=0
else
rc=1
info "[rekey] Collecting failure logs"
docker compose -f "$compose" --profile rekey logs --no-color 2>&1 | tail -100
fi
docker compose -f "$compose" --profile rekey down --volumes --remove-orphans 2>/dev/null
record "rekey" $rc
}
# Run a chaos scenario # Run a chaos scenario
run_chaos() { run_chaos() {
local name="$1" local name="$1"
@@ -701,73 +683,6 @@ run_sidecar() {
record "sidecar" $rc record "sidecar" $rc
} }
# Run the rekey-accept-off integration variant. Same harness as run_rekey
# but on a 2-node topology with udp.accept_connections=false on node-b.
run_rekey_accept_off() {
local compose="testing/static/docker-compose.yml"
local rc=0
export COMPOSE_PROJECT_NAME="$(ci_project static)"
info "[rekey-accept-off] Generating configs"
bash testing/static/scripts/generate-configs.sh rekey-accept-off || \
{ record "rekey-accept-off" 1; return; }
REKEY_TOPOLOGY=rekey-accept-off REKEY_ACCEPT_OFF_NODES=b \
bash testing/static/scripts/rekey-test.sh inject-config || \
{ record "rekey-accept-off" 1; return; }
info "[rekey-accept-off] Starting containers"
docker compose -f "$compose" --profile rekey-accept-off up -d || \
{ record "rekey-accept-off" 1; return; }
info "[rekey-accept-off] Running rekey test"
if REKEY_TOPOLOGY=rekey-accept-off REKEY_ACCEPT_OFF_NODES=b \
bash testing/static/scripts/rekey-test.sh; then
rc=0
else
rc=1
info "[rekey-accept-off] Collecting failure logs"
docker compose -f "$compose" --profile rekey-accept-off logs --no-color 2>&1 | tail -100
fi
docker compose -f "$compose" --profile rekey-accept-off down --volumes --remove-orphans 2>/dev/null
record "rekey-accept-off" $rc
}
# Run the rekey-outbound-only integration variant. Same harness as
# run_rekey but with udp.outbound_only=true on node-b plus its peer
# addrs rewritten from numeric docker IPs to docker hostnames so the
# addr_to_link key form mismatches inbound packet source addrs (the
# production trigger for the rekey-msg1 carve-out gap).
run_rekey_outbound_only() {
local compose="testing/static/docker-compose.yml"
local rc=0
export COMPOSE_PROJECT_NAME="$(ci_project static)"
info "[rekey-outbound-only] Generating configs"
bash testing/static/scripts/generate-configs.sh rekey-outbound-only || \
{ record "rekey-outbound-only" 1; return; }
REKEY_TOPOLOGY=rekey-outbound-only REKEY_OUTBOUND_ONLY_NODES=b \
bash testing/static/scripts/rekey-test.sh inject-config || \
{ record "rekey-outbound-only" 1; return; }
info "[rekey-outbound-only] Starting containers"
docker compose -f "$compose" --profile rekey-outbound-only up -d || \
{ record "rekey-outbound-only" 1; return; }
info "[rekey-outbound-only] Running rekey test"
if REKEY_TOPOLOGY=rekey-outbound-only REKEY_OUTBOUND_ONLY_NODES=b \
bash testing/static/scripts/rekey-test.sh; then
rc=0
else
rc=1
info "[rekey-outbound-only] Collecting failure logs"
docker compose -f "$compose" --profile rekey-outbound-only logs --no-color 2>&1 | tail -100
fi
docker compose -f "$compose" --profile rekey-outbound-only down --volumes --remove-orphans 2>/dev/null
record "rekey-outbound-only" $rc
}
# Run firewall baseline integration test # Run firewall baseline integration test
run_firewall() { run_firewall() {
export COMPOSE_PROJECT_NAME="$(ci_project firewall)" export COMPOSE_PROJECT_NAME="$(ci_project firewall)"
@@ -897,11 +812,6 @@ run_integration() {
run_static "$topology" run_static "$topology"
done done
# Rekey + rekey-accept-off + rekey-outbound-only variants
run_rekey
run_rekey_accept_off
run_rekey_outbound_only
# Gateway # Gateway
run_gateway run_gateway
@@ -1009,12 +919,6 @@ run_suite() {
case "$suite" in case "$suite" in
static-mesh|static-chain) static-mesh|static-chain)
run_static "${suite#static-}" ;; run_static "${suite#static-}" ;;
rekey)
run_rekey ;;
rekey-accept-off)
run_rekey_accept_off ;;
rekey-outbound-only)
run_rekey_outbound_only ;;
gateway) gateway)
run_gateway ;; run_gateway ;;
firewall) firewall)