mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-30 19:46:15 +00:00
New testing/boringtun/ harness runs two Cloudflare BoringTun userspace WireGuard containers with iperf3 between them, giving a single-hop userspace tunnel baseline for comparison against FIPS throughput numbers. Local WG key generation runs through the harness image so the host needs no wireguard-tools. New testing/static/scripts/iperf-compare-refs.sh builds two git refs into separate fips-test:* images via git worktree and runs the same static iperf topology against both, with RUNS-based repetition and aggregate avg/min/max reporting. testing/static/scripts/iperf-test.sh gains DURATION, PARALLEL, SETTLE_SECONDS, IPERF_TIMEOUT env knobs and a per-path iperf timeout. testing/static/docker-compose.yml selects the image under test via FIPS_TEST_IMAGE; testing/scripts/build.sh respects CARGO_TARGET_DIR. Author benchmark on aarch64 Docker Desktop: boringtun bob -> alice : 1000.13 Mbits/sec
41 lines
1.1 KiB
Bash
Executable File
41 lines
1.1 KiB
Bash
Executable File
#!/bin/bash
|
|
# Generate WG keypairs for alice and bob and write the
|
|
# generated/peers.env file the docker-compose.yml reads.
|
|
# Idempotent: skips if file already exists.
|
|
set -e
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
OUT_DIR="$SCRIPT_DIR/../generated"
|
|
ENV_FILE="$OUT_DIR/peers.env"
|
|
|
|
if [ -f "$ENV_FILE" ]; then
|
|
echo "$ENV_FILE already exists; reusing keys"
|
|
exit 0
|
|
fi
|
|
|
|
mkdir -p "$OUT_DIR"
|
|
|
|
# Use the built boringtun-test image to generate keys — host may
|
|
# not have wireguard-tools installed. The `pubkey` step needs `-i`
|
|
# so stdin is piped through; `genkey` doesn't need it but matching
|
|
# flags keeps the two calls symmetric.
|
|
GEN_CMD="docker run --rm --entrypoint wg boringtun-test:latest"
|
|
PUB_CMD="docker run --rm -i --entrypoint wg boringtun-test:latest"
|
|
|
|
ALICE_PRIV=$($GEN_CMD genkey)
|
|
ALICE_PUB=$(printf '%s' "$ALICE_PRIV" | $PUB_CMD pubkey)
|
|
BOB_PRIV=$($GEN_CMD genkey)
|
|
BOB_PUB=$(printf '%s' "$BOB_PRIV" | $PUB_CMD pubkey)
|
|
|
|
cat >"$ENV_FILE" <<EOF
|
|
ALICE_PRIV=$ALICE_PRIV
|
|
ALICE_PUB=$ALICE_PUB
|
|
BOB_PRIV=$BOB_PRIV
|
|
BOB_PUB=$BOB_PUB
|
|
ALICE_WG_IP=10.99.0.1/24
|
|
BOB_WG_IP=10.99.0.2/24
|
|
PEER_PORT=51820
|
|
EOF
|
|
chmod 600 "$ENV_FILE"
|
|
echo "wrote $ENV_FILE"
|