mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-30 19:46:15 +00:00
Retire the rekey Docker suites; timing, continuity and variants are in-process
The three rekey integration suites (rekey, rekey-accept-off, rekey-outbound-only) are dropped from both runners. Their coverage now lives in fast, deterministic in-process tests: - rekey timing and choreography (trigger, K-bit cutover, drain, jitter, guards) in the sans-IO poll_rekey tests (proto/fsp, proto/fmp); - data-plane continuity across a real cutover in rekey_cutover_preserves_data_plane (a real IK rekey over loopback); - the accept-off dual-init regression and the udp.outbound_only rekey loop in the should_admit_msg1 and dual-init characterization tests. Drop them from both runners in lockstep so the parity guard stays green, and record the retirement in the deliberately-not-run block with a pointer to the standalone runner. The rekey-test.sh script stays on disk.
This commit is contained in:
@@ -414,16 +414,6 @@ jobs:
|
||||
- suite: static-chain
|
||||
type: static
|
||||
topology: chain
|
||||
# ── Rekey integration test ──────────────────────────────────────────
|
||||
- suite: rekey
|
||||
type: rekey
|
||||
topology: rekey
|
||||
- suite: rekey-accept-off
|
||||
type: rekey-accept-off
|
||||
topology: rekey-accept-off
|
||||
- suite: rekey-outbound-only
|
||||
type: rekey-outbound-only
|
||||
topology: rekey-outbound-only
|
||||
# ── Firewall baseline (fips0 nftables default-deny) ────────────
|
||||
- suite: firewall
|
||||
type: firewall
|
||||
@@ -563,105 +553,6 @@ jobs:
|
||||
docker compose -f testing/static/docker-compose.yml \
|
||||
--profile ${{ matrix.topology }} down --volumes --remove-orphans
|
||||
|
||||
# ── Rekey integration test ──────────────────────────────────────────────
|
||||
- name: Generate and inject configs (rekey)
|
||||
if: matrix.type == 'rekey'
|
||||
run: |
|
||||
bash testing/static/scripts/generate-configs.sh rekey
|
||||
bash testing/static/scripts/rekey-test.sh inject-config
|
||||
|
||||
- name: Start containers (rekey)
|
||||
if: matrix.type == 'rekey'
|
||||
run: |
|
||||
docker compose -f testing/static/docker-compose.yml \
|
||||
--profile rekey up -d
|
||||
|
||||
- name: Run rekey test
|
||||
if: matrix.type == 'rekey'
|
||||
run: bash testing/static/scripts/rekey-test.sh
|
||||
|
||||
- name: Collect logs on failure (rekey)
|
||||
if: matrix.type == 'rekey' && failure()
|
||||
run: |
|
||||
docker compose -f testing/static/docker-compose.yml \
|
||||
--profile rekey logs --no-color
|
||||
|
||||
- name: Stop containers (rekey)
|
||||
if: matrix.type == 'rekey' && always()
|
||||
run: |
|
||||
docker compose -f testing/static/docker-compose.yml \
|
||||
--profile rekey down --volumes --remove-orphans
|
||||
|
||||
# ── Rekey + accept_connections=false variant ──────────────────────────
|
||||
- name: Generate and inject configs (rekey-accept-off)
|
||||
if: matrix.type == 'rekey-accept-off'
|
||||
env:
|
||||
REKEY_TOPOLOGY: rekey-accept-off
|
||||
REKEY_ACCEPT_OFF_NODES: b
|
||||
run: |
|
||||
bash testing/static/scripts/generate-configs.sh rekey-accept-off
|
||||
bash testing/static/scripts/rekey-test.sh inject-config
|
||||
|
||||
- name: Start containers (rekey-accept-off)
|
||||
if: matrix.type == 'rekey-accept-off'
|
||||
run: |
|
||||
docker compose -f testing/static/docker-compose.yml \
|
||||
--profile rekey-accept-off up -d
|
||||
|
||||
- name: Run rekey test (accept-off variant)
|
||||
if: matrix.type == 'rekey-accept-off'
|
||||
env:
|
||||
REKEY_TOPOLOGY: rekey-accept-off
|
||||
REKEY_ACCEPT_OFF_NODES: b
|
||||
run: bash testing/static/scripts/rekey-test.sh
|
||||
|
||||
- name: Collect logs on failure (rekey-accept-off)
|
||||
if: matrix.type == 'rekey-accept-off' && failure()
|
||||
run: |
|
||||
docker compose -f testing/static/docker-compose.yml \
|
||||
--profile rekey-accept-off logs --no-color | tail -300
|
||||
|
||||
- name: Stop containers (rekey-accept-off)
|
||||
if: matrix.type == 'rekey-accept-off' && always()
|
||||
run: |
|
||||
docker compose -f testing/static/docker-compose.yml \
|
||||
--profile rekey-accept-off down --volumes --remove-orphans
|
||||
|
||||
# ── Rekey + udp.outbound_only=true variant ─────────────────────────────
|
||||
- name: Generate and inject configs (rekey-outbound-only)
|
||||
if: matrix.type == 'rekey-outbound-only'
|
||||
env:
|
||||
REKEY_TOPOLOGY: rekey-outbound-only
|
||||
REKEY_OUTBOUND_ONLY_NODES: b
|
||||
run: |
|
||||
bash testing/static/scripts/generate-configs.sh rekey-outbound-only
|
||||
bash testing/static/scripts/rekey-test.sh inject-config
|
||||
|
||||
- name: Start containers (rekey-outbound-only)
|
||||
if: matrix.type == 'rekey-outbound-only'
|
||||
run: |
|
||||
docker compose -f testing/static/docker-compose.yml \
|
||||
--profile rekey-outbound-only up -d
|
||||
|
||||
- name: Run rekey test (outbound-only variant)
|
||||
if: matrix.type == 'rekey-outbound-only'
|
||||
env:
|
||||
REKEY_TOPOLOGY: rekey-outbound-only
|
||||
REKEY_OUTBOUND_ONLY_NODES: b
|
||||
run: bash testing/static/scripts/rekey-test.sh
|
||||
|
||||
- name: Collect logs on failure (rekey-outbound-only)
|
||||
if: matrix.type == 'rekey-outbound-only' && failure()
|
||||
run: |
|
||||
docker compose -f testing/static/docker-compose.yml \
|
||||
--profile rekey-outbound-only logs --no-color | tail -300
|
||||
|
||||
- name: Stop containers (rekey-outbound-only)
|
||||
if: matrix.type == 'rekey-outbound-only' && always()
|
||||
run: |
|
||||
docker compose -f testing/static/docker-compose.yml \
|
||||
--profile rekey-outbound-only down --volumes --remove-orphans
|
||||
|
||||
# ── Firewall baseline integration test ─────────────────────────────────
|
||||
- name: Run firewall baseline integration test
|
||||
if: matrix.type == 'firewall'
|
||||
|
||||
+14
-110
@@ -26,8 +26,7 @@
|
||||
# -h, --help Show this help
|
||||
#
|
||||
# Integration suites (default coverage):
|
||||
# static-mesh, static-chain, rekey, rekey-accept-off,
|
||||
# rekey-outbound-only, gateway,
|
||||
# static-mesh, static-chain, gateway,
|
||||
# firewall, nat-cone, nat-symmetric,
|
||||
# nat-lan, nostr-publish-consume, stun-faults,
|
||||
# chaos-churn-mixed-10, chaos-ethernet-mesh,
|
||||
@@ -74,6 +73,19 @@
|
||||
# discriminator the Docker tcpdump used — plus a sibling
|
||||
# test for the existing-peer bypass. Still runnable by hand:
|
||||
# bash testing/static/scripts/admission-cap-test.sh
|
||||
# rekey, rekey-accept-off, rekey-outbound-only
|
||||
# Retired from CI 2026-07-24 as redundant, not unrunnable.
|
||||
# The rekey timing/choreography decision (trigger, K-bit
|
||||
# cutover, drain, jitter, guards) is covered by the sans-IO
|
||||
# poll_rekey tests (src/proto/fsp/tests/core.rs,
|
||||
# src/proto/fmp/tests/core.rs); the data-plane continuity
|
||||
# across a real cutover by rekey_cutover_preserves_data_plane
|
||||
# (src/node/tests/session.rs, a real IK rekey over loopback);
|
||||
# the accept-off dual-init regression and the
|
||||
# udp.outbound_only rekey loop by the should_admit_msg1 and
|
||||
# dual-init chartests (src/node/tests/handshake.rs,
|
||||
# establish_chartests.rs). Still runnable by hand:
|
||||
# bash testing/static/scripts/rekey-test.sh
|
||||
# ecn-ab-on, ecn-ab-off, maelstrom, maelstrom-sparse
|
||||
# Chaos scenarios excluded from CHAOS_SUITES. The two
|
||||
# ecn-ab ones are halves of the manual comparison above.
|
||||
@@ -133,7 +145,6 @@ ONLY_SUITE=""
|
||||
|
||||
# All integration suites matching ci.yml
|
||||
STATIC_SUITES=(static-mesh static-chain)
|
||||
REKEY_SUITES=(rekey rekey-accept-off rekey-outbound-only)
|
||||
# Each entry: "display-name scenario [--flag value ...]"
|
||||
CHAOS_SUITES=(
|
||||
"churn-mixed-10 churn-mixed --nodes 10 --duration 120"
|
||||
@@ -198,9 +209,6 @@ list_suites() {
|
||||
echo " Static topologies:"
|
||||
for s in "${STATIC_SUITES[@]}"; do echo " $s"; done
|
||||
echo ""
|
||||
echo " Rekey:"
|
||||
for s in "${REKEY_SUITES[@]}"; do echo " $s"; done
|
||||
echo ""
|
||||
echo " Gateway:"
|
||||
for s in "${GATEWAY_SUITES[@]}"; do echo " $s"; done
|
||||
echo ""
|
||||
@@ -548,32 +556,6 @@ run_static() {
|
||||
record "static-$topology" $rc
|
||||
}
|
||||
|
||||
# Run the rekey integration test
|
||||
run_rekey() {
|
||||
local compose="testing/static/docker-compose.yml"
|
||||
local rc=0
|
||||
export COMPOSE_PROJECT_NAME="$(ci_project static)"
|
||||
|
||||
info "[rekey] Generating configs"
|
||||
bash testing/static/scripts/generate-configs.sh rekey || { record "rekey" 1; return; }
|
||||
bash testing/static/scripts/rekey-test.sh inject-config || { record "rekey" 1; return; }
|
||||
|
||||
info "[rekey] Starting containers"
|
||||
docker compose -f "$compose" --profile rekey up -d || { record "rekey" 1; return; }
|
||||
|
||||
info "[rekey] Running rekey test"
|
||||
if bash testing/static/scripts/rekey-test.sh; then
|
||||
rc=0
|
||||
else
|
||||
rc=1
|
||||
info "[rekey] Collecting failure logs"
|
||||
docker compose -f "$compose" --profile rekey logs --no-color 2>&1 | tail -100
|
||||
fi
|
||||
|
||||
docker compose -f "$compose" --profile rekey down --volumes --remove-orphans 2>/dev/null
|
||||
record "rekey" $rc
|
||||
}
|
||||
|
||||
# Run a chaos scenario
|
||||
run_chaos() {
|
||||
local name="$1"
|
||||
@@ -701,73 +683,6 @@ run_sidecar() {
|
||||
record "sidecar" $rc
|
||||
}
|
||||
|
||||
# Run the rekey-accept-off integration variant. Same harness as run_rekey
|
||||
# but on a 2-node topology with udp.accept_connections=false on node-b.
|
||||
run_rekey_accept_off() {
|
||||
local compose="testing/static/docker-compose.yml"
|
||||
local rc=0
|
||||
export COMPOSE_PROJECT_NAME="$(ci_project static)"
|
||||
|
||||
info "[rekey-accept-off] Generating configs"
|
||||
bash testing/static/scripts/generate-configs.sh rekey-accept-off || \
|
||||
{ record "rekey-accept-off" 1; return; }
|
||||
REKEY_TOPOLOGY=rekey-accept-off REKEY_ACCEPT_OFF_NODES=b \
|
||||
bash testing/static/scripts/rekey-test.sh inject-config || \
|
||||
{ record "rekey-accept-off" 1; return; }
|
||||
|
||||
info "[rekey-accept-off] Starting containers"
|
||||
docker compose -f "$compose" --profile rekey-accept-off up -d || \
|
||||
{ record "rekey-accept-off" 1; return; }
|
||||
|
||||
info "[rekey-accept-off] Running rekey test"
|
||||
if REKEY_TOPOLOGY=rekey-accept-off REKEY_ACCEPT_OFF_NODES=b \
|
||||
bash testing/static/scripts/rekey-test.sh; then
|
||||
rc=0
|
||||
else
|
||||
rc=1
|
||||
info "[rekey-accept-off] Collecting failure logs"
|
||||
docker compose -f "$compose" --profile rekey-accept-off logs --no-color 2>&1 | tail -100
|
||||
fi
|
||||
|
||||
docker compose -f "$compose" --profile rekey-accept-off down --volumes --remove-orphans 2>/dev/null
|
||||
record "rekey-accept-off" $rc
|
||||
}
|
||||
|
||||
# Run the rekey-outbound-only integration variant. Same harness as
|
||||
# run_rekey but with udp.outbound_only=true on node-b plus its peer
|
||||
# addrs rewritten from numeric docker IPs to docker hostnames so the
|
||||
# addr_to_link key form mismatches inbound packet source addrs (the
|
||||
# production trigger for the rekey-msg1 carve-out gap).
|
||||
run_rekey_outbound_only() {
|
||||
local compose="testing/static/docker-compose.yml"
|
||||
local rc=0
|
||||
export COMPOSE_PROJECT_NAME="$(ci_project static)"
|
||||
|
||||
info "[rekey-outbound-only] Generating configs"
|
||||
bash testing/static/scripts/generate-configs.sh rekey-outbound-only || \
|
||||
{ record "rekey-outbound-only" 1; return; }
|
||||
REKEY_TOPOLOGY=rekey-outbound-only REKEY_OUTBOUND_ONLY_NODES=b \
|
||||
bash testing/static/scripts/rekey-test.sh inject-config || \
|
||||
{ record "rekey-outbound-only" 1; return; }
|
||||
|
||||
info "[rekey-outbound-only] Starting containers"
|
||||
docker compose -f "$compose" --profile rekey-outbound-only up -d || \
|
||||
{ record "rekey-outbound-only" 1; return; }
|
||||
|
||||
info "[rekey-outbound-only] Running rekey test"
|
||||
if REKEY_TOPOLOGY=rekey-outbound-only REKEY_OUTBOUND_ONLY_NODES=b \
|
||||
bash testing/static/scripts/rekey-test.sh; then
|
||||
rc=0
|
||||
else
|
||||
rc=1
|
||||
info "[rekey-outbound-only] Collecting failure logs"
|
||||
docker compose -f "$compose" --profile rekey-outbound-only logs --no-color 2>&1 | tail -100
|
||||
fi
|
||||
|
||||
docker compose -f "$compose" --profile rekey-outbound-only down --volumes --remove-orphans 2>/dev/null
|
||||
record "rekey-outbound-only" $rc
|
||||
}
|
||||
|
||||
# Run firewall baseline integration test
|
||||
run_firewall() {
|
||||
export COMPOSE_PROJECT_NAME="$(ci_project firewall)"
|
||||
@@ -897,11 +812,6 @@ run_integration() {
|
||||
run_static "$topology"
|
||||
done
|
||||
|
||||
# Rekey + rekey-accept-off + rekey-outbound-only variants
|
||||
run_rekey
|
||||
run_rekey_accept_off
|
||||
run_rekey_outbound_only
|
||||
|
||||
# Gateway
|
||||
run_gateway
|
||||
|
||||
@@ -1009,12 +919,6 @@ run_suite() {
|
||||
case "$suite" in
|
||||
static-mesh|static-chain)
|
||||
run_static "${suite#static-}" ;;
|
||||
rekey)
|
||||
run_rekey ;;
|
||||
rekey-accept-off)
|
||||
run_rekey_accept_off ;;
|
||||
rekey-outbound-only)
|
||||
run_rekey_outbound_only ;;
|
||||
gateway)
|
||||
run_gateway ;;
|
||||
firewall)
|
||||
|
||||
Reference in New Issue
Block a user