Files
fips/testing/chaos/sim/config_gen.py
T
Arjen 6485271ef5 test(iface-binding): cover the presence machine end to end
Two daemons whose only transports are interface-bound, run against a veth
pair the harness creates, downs, deletes and recreates underneath them.

Asserts the boot race (a daemon whose only interface is missing starts,
reports the transport absent and the node Degraded, rather than exiting on
NoTransports or skipping the transport for the life of the process), the
late attach and discovery over it, the flap in both directions,
destroy-and-recreate, and that an optional interface which never appears
never moves node health.

Also the log policy, which is the half that is easy to regress silently:
absence is logged once on the edge and not once per retry; a required
interface still absent past the ten-second bring-up window errors exactly
once, while the optional one — absent just as long — stays silent; and that
error is not repeated on a schedule. The detach edge is checked not to
error, guarded by how long detection actually took, so a slow runner skips
the check rather than failing on the harness's own latency.

The containers run FIPS_TEST_MODE=default, not chaos. The chaos entrypoint
waits up to 30 s for every configured Ethernet interface before starting the
daemon, which is precisely the workaround under test — the daemon has to do
its own waiting here or the suite proves nothing.

Host-namespace ip(8) runs in a short-lived privileged container sharing the
host network and PID namespaces, for the reason chaos/sim/veth.py documents:
on macOS the containers live in the Docker VM, so ip(8) run on the macOS
host could never reach them.

Chaos ethernet transports are marked optional: true. In that harness a
neighbour's interface disappearing is the scenario, not a fault — node_churn
stops a container, which destroys its netns and with it both ends of every
veth it held, so a surviving node watches a required interface vanish for
the 30-90 s the neighbour is down, once per churn event. Reporting that at
error is right for a deployment and wrong for a harness that tears the
interface down on purpose; the mesh-wide zero-ERROR ceiling would have
failed on injected chaos rather than on a defect.
2026-09-01 09:54:36 +01:00

218 lines
7.4 KiB
Python

"""FIPS node config generation from template + topology."""
from __future__ import annotations
import os
from copy import deepcopy
import yaml
from .topology import SimTopology
def _deep_merge(base: dict, override: dict) -> dict:
"""Recursively merge override into base (override wins on conflicts)."""
result = deepcopy(base)
for key, value in override.items():
if key in result and isinstance(result[key], dict) and isinstance(value, dict):
result[key] = _deep_merge(result[key], value)
else:
result[key] = deepcopy(value)
return result
# Path to the shared node config template
_TEMPLATE_PATH = os.path.join(
os.path.dirname(__file__), "..", "configs", "node.template.yaml"
)
def _load_template() -> str:
with open(_TEMPLATE_PATH) as f:
return f.read()
_TRANSPORT_PORTS = {
"udp": 2121,
"tcp": 443,
}
def generate_peers_block(
topology: SimTopology, node_id: str, outbound_peers: list[str]
) -> str:
"""Generate the YAML peers block for a node.
Only includes peers that this node is responsible for connecting to
(outbound direction). The link is still bidirectional once established.
Transport type and port are determined per-edge from the topology.
"""
if not outbound_peers:
return " []"
lines = []
for peer_id in sorted(outbound_peers):
peer = topology.nodes[peer_id]
transport = topology.transport_for_edge(node_id, peer_id)
port = _TRANSPORT_PORTS.get(transport, 2121)
lines.append(f' - npub: "{peer.npub}"')
lines.append(f' alias: "{peer_id}"')
lines.append(f" addresses:")
lines.append(f" - transport: {transport}")
lines.append(f' addr: "{peer.docker_ip}:{port}"')
lines.append(f" connect_policy: auto_connect")
return "\n".join(lines)
def _build_ethernet_config(iface: str) -> dict:
"""Build an Ethernet transport config dict for a single interface.
``optional: True`` because in this harness a neighbour's interface
disappearing is the scenario, not a fault. ``node_churn`` stops a
container, which destroys its netns and with it both ends of every veth
pair it held (see ``nodes.py``: the veths are recreated on restart), so a
surviving node watches a *required* interface vanish for the 30-90s the
neighbour is down -- once per churn event, on every neighbour. The daemon
reports a required interface absent past its bring-up window at ERROR,
which is correct for a deployment and wrong for a harness that tears the
interface down on purpose; the mesh-wide zero-ERROR ceiling would fail on
injected chaos rather than on a defect.
Absence behaviour itself is asserted in ``testing/iface-binding/``, which
exists for it and drives both policies deliberately.
"""
return {
"interface": iface,
"listen": True,
"announce": True,
"auto_connect": True,
"accept_connections": True,
"beacon_interval_secs": 10,
"optional": True,
}
def _inject_ethernet_transports(parsed: dict, eth_ifaces: list[str]):
"""Inject Ethernet transport config into a parsed FIPS config.
For a single interface, uses the single-instance format.
For multiple interfaces, uses the named-instances format.
Pure-Ethernet nodes (no UDP peers) have their UDP transport removed.
"""
if not eth_ifaces:
return
transports = parsed.setdefault("transports", {})
if len(eth_ifaces) == 1:
transports["ethernet"] = _build_ethernet_config(eth_ifaces[0])
else:
transports["ethernet"] = {
iface: _build_ethernet_config(iface) for iface in eth_ifaces
}
def _inject_tcp_transport(parsed: dict):
"""Inject TCP transport config into a parsed FIPS config."""
transports = parsed.setdefault("transports", {})
transports["tcp"] = {
"bind_addr": "0.0.0.0:443",
}
def generate_node_config(
topology: SimTopology,
node_id: str,
outbound_peers: list[str],
fips_overrides: dict | None = None,
ephemeral: bool = False,
) -> str:
"""Generate a complete FIPS config YAML for one node.
If ephemeral is True, the nsec is omitted from the config so the
daemon generates a fresh keypair on each restart.
"""
template = _load_template()
node = topology.nodes[node_id]
peers_yaml = generate_peers_block(topology, node_id, outbound_peers)
config = template
config = config.replace("{{NODE_NAME}}", node_id.upper())
config = config.replace("{{TOPOLOGY}}", "sim")
config = config.replace("{{NPUB}}", node.npub)
config = config.replace("{{NSEC}}", node.nsec)
config = config.replace("{{PEERS}}", peers_yaml)
# Ephemeral nodes: remove nsec so daemon generates fresh keys on restart
if ephemeral:
parsed = yaml.safe_load(config)
identity = parsed.get("node", {}).get("identity", {})
identity.pop("nsec", None)
config = yaml.dump(parsed, default_flow_style=False, sort_keys=False)
# Determine which transports this node participates in
eth_ifaces = topology.ethernet_interfaces(node_id)
has_tcp = bool(topology.tcp_peers(node_id))
has_udp = _has_transport_peers(topology, node_id, "udp")
# Inject non-UDP transport configs and handle pure-transport nodes
needs_yaml_rewrite = eth_ifaces or has_tcp or not has_udp or fips_overrides
if needs_yaml_rewrite:
parsed = yaml.safe_load(config)
if fips_overrides:
parsed = _deep_merge(parsed, fips_overrides)
if eth_ifaces:
_inject_ethernet_transports(parsed, eth_ifaces)
if has_tcp:
_inject_tcp_transport(parsed)
if not has_udp:
# No UDP edges: remove UDP transport
transports = parsed.get("transports", {})
transports.pop("udp", None)
config = yaml.dump(parsed, default_flow_style=False, sort_keys=False)
return config
def _has_transport_peers(topology: SimTopology, node_id: str, transport: str) -> bool:
"""Check if a node has any edges (inbound or outbound) using the given transport."""
for peer_id in topology.nodes[node_id].peers:
edge = (min(node_id, peer_id), max(node_id, peer_id))
if topology.edge_transport.get(edge, "udp") == transport:
return True
return False
def generate_npubs_env(topology: SimTopology) -> str:
"""Generate npubs.env content mapping NPUB_<ID>=<npub> for all nodes."""
lines = []
for node_id in sorted(topology.nodes):
node = topology.nodes[node_id]
env_name = f"NPUB_{node_id.upper()}"
lines.append(f"{env_name}={node.npub}")
return "\n".join(lines) + "\n"
def write_configs(
topology: SimTopology,
output_dir: str,
fips_overrides: dict | None = None,
ephemeral_nodes: set[str] | None = None,
):
"""Write all node configs and npubs.env to the output directory."""
os.makedirs(output_dir, exist_ok=True)
ephemeral_nodes = ephemeral_nodes or set()
outbound = topology.directed_outbound()
for node_id in topology.nodes:
config = generate_node_config(
topology, node_id, outbound[node_id], fips_overrides,
ephemeral=(node_id in ephemeral_nodes),
)
path = os.path.join(output_dir, f"{node_id}.yaml")
with open(path, "w") as f:
f.write(config)
env_path = os.path.join(output_dir, "npubs.env")
with open(env_path, "w") as f:
f.write(generate_npubs_env(topology))