mirror of
https://github.com/jmcorgan/fips.git
synced 2026-08-09 16:24:45 +00:00
Single combined commit covering five interlocking pieces of test and CI work that landed during the v0.3.0-prep cycle. ## fips-gateway robustness - src/bin/fips-gateway.rs DNS upstream probe converted from a 3-second hard-fail to a bounded retry loop (5 attempts × 1s timeout, 1s sleep between attempts; ~10s worst case). Covers the cold-boot race where the daemon's TUN is up but the DNS responder at [::1]:5354 is still binding. Each failed attempt logs at INFO. In production the binary's retry is the live recovery mechanism; with retry it recovers silently instead of relying on Restart=on-failure (~5s blip + spurious ERROR per cycle). - packaging/debian/fips-gateway.service `ExecStartPre` now waits up to 30 seconds for the daemon's `fips0` TUN to appear before exec'ing the gateway binary. Eliminates the cold-boot race where the gateway exits with `fips0 interface not found` and recovers via `Restart=on-failure`, producing a 5-second blip and a spurious error log per restart cycle. - testing/docker/entrypoint.sh gateway-mode waits up to 30s for the daemon's DNS responder to bind [::1]:5354 (probes once per second with `dig @::1 -p 5354 ... test.fips`) before exec'ing fips-gateway. Belt-and-suspenders with the binary's own retry: in CI we want deterministic startup ordering. On timeout, fall through so the binary's probe reports the definitive error. ## Test infrastructure DNS bind migration to ::1 After session 359's daemon DNS-bind default flipped from `127.0.0.1` to `::1` (the production fix for ISSUE-2026-0002), the static-test infrastructure was carrying a stale workaround that overrode the default back to IPv4 loopback. The fips-gateway integration test exposed the divergence: the gateway probes its DNS upstream at `[::1]:5354` (production default) while the daemon was binding `127.0.0.1:5354` from the template override — IPv6-explicit sockets do not accept v4-mapped traffic, so the upstream probe exhausted retries and the gateway exited. - Drop the explicit `bind_addr: "127.0.0.1"` line from every test config that emits it: testing/static/configs/node.template.yaml, testing/chaos/configs/node.template.yaml, the sidecar heredoc in testing/docker/entrypoint.sh, testing/acl-allowlist/generate-configs.sh (six per-node blocks), testing/nat/scripts/generate-configs.sh, and the four tor templates under testing/tor/. Daemon picks up its production `::1` default. - Flip the dnsmasq forwarder for `.fips` in testing/docker/Dockerfile from `127.0.0.1#5354` to `::1#5354` so dnsmasq on the shared test image continues to reach the daemon. Template and Dockerfile must move together since most static suites resolve `<npub>.fips` via the test-image dnsmasq. ## rekey-accept-off integration variant + UDP unit test - New `rekey-accept-off` topology and docker-compose profile under testing/static/. 2-node variant where node-b runs with `udp.accept_connections: false`. Pins the regression class that ISSUE-2026-0004 fixed (cross-connection winner's rekey msg1 was being filtered by the accept_connections gate, breaking rekey). - testing/static/scripts/rekey-test.sh accepts REKEY_TOPOLOGY and REKEY_ACCEPT_OFF_NODES env vars; its inject-config subcommand applies the per-node `udp.accept_connections: false` edit, and the test asserts no sustained "Dual rekey initiation" log lines. - New UDP variant of `should_admit_msg1` admit-rekey unit test in src/node/tests/handshake.rs. ## ci-local.sh full integration coverage - New runner functions and dispatcher entries for `acl-allowlist`, `nat-cone` / `nat-symmetric` / `nat-lan`, `rekey-accept-off`, `dns-resolver`, `deb-install`. Each integrates with the existing summary tracking via `record`. - New `--with-tor` flag (off by default) gates `tor-socks5-outbound` and `tor-directory-mode` runners. Tor stays opt-in because both harnesses depend on the live Tor network and would introduce a flake source unrelated to the FIPS code. - New suite arrays (`ACL_SUITES`, `NAT_SUITES`, `DNS_RESOLVER_SUITES`, `DEB_INSTALL_SUITES`, `TOR_SUITES`) drive both the default sweep and `--list` output. - `run_suite` extended to accept the new suite names for `--only` invocations. ## GitHub CI matrix expansions - `gateway` matrix entry runs testing/static/scripts/gateway-test.sh against the existing docker-compose `gateway` profile. - `rekey-accept-off` matrix entry exercises the new topology with REKEY_ACCEPT_OFF_NODES=b. - `deb-install` matrix (debian12 + ubuntu24 + ubuntu26) runs testing/deb-install/test.sh with privileged systemd containers. ~5-7 min cold cache, ~2 min warm per distro. Self-contained: builds its own .deb in a Debian 12 cargo-deb builder image; does not depend on the build job's pre-built artifact. - `dns-resolver` matrix entry runs the full 13-scenario harness (per-distro systemd resolver-backend tests + real-fips end-to-end scenarios) in a single job. Pins the production DNS bind path that ISSUE-2026-0002 lived in. ~7-12 min warm, ~12-15 min cold. Verified locally: full `bash testing/ci-local.sh` sweep passes, including 5/5 deb-install distros and all 13 dns-resolver scenarios. Tor-inclusive sweep (`--with-tor`) verified in a follow-up run.
453 lines
13 KiB
YAML
453 lines
13 KiB
YAML
networks:
|
|
fips-net:
|
|
driver: bridge
|
|
ipam:
|
|
config:
|
|
- subnet: 172.20.0.0/24
|
|
gateway-lan:
|
|
driver: bridge
|
|
enable_ipv6: true
|
|
ipam:
|
|
config:
|
|
- subnet: 172.20.1.0/24
|
|
- subnet: fd02::/64
|
|
|
|
x-fips-common: &fips-common
|
|
image: fips-test:latest
|
|
cap_add:
|
|
- NET_ADMIN
|
|
devices:
|
|
- /dev/net/tun:/dev/net/tun
|
|
sysctls:
|
|
- net.ipv6.conf.all.disable_ipv6=0
|
|
restart: "no"
|
|
env_file:
|
|
- ./generated-configs/npubs.env
|
|
environment:
|
|
- RUST_LOG=info
|
|
|
|
services:
|
|
# ── Mesh topology ──────────────────────────────────────────────
|
|
node-a:
|
|
<<: *fips-common
|
|
profiles: ["mesh"]
|
|
container_name: fips-node-a
|
|
hostname: node-a
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/mesh/node-a.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.10
|
|
|
|
node-b:
|
|
<<: *fips-common
|
|
profiles: ["mesh"]
|
|
container_name: fips-node-b
|
|
hostname: node-b
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/mesh/node-b.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.11
|
|
|
|
node-c:
|
|
<<: *fips-common
|
|
profiles: ["mesh"]
|
|
container_name: fips-node-c
|
|
hostname: node-c
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/mesh/node-c.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.12
|
|
|
|
node-d:
|
|
<<: *fips-common
|
|
profiles: ["mesh"]
|
|
container_name: fips-node-d
|
|
hostname: node-d
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/mesh/node-d.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.13
|
|
|
|
node-e:
|
|
<<: *fips-common
|
|
profiles: ["mesh"]
|
|
container_name: fips-node-e
|
|
hostname: node-e
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/mesh/node-e.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.14
|
|
|
|
# ── Mesh-public topology (mesh + external public node) ────────
|
|
pub-a:
|
|
<<: *fips-common
|
|
profiles: ["mesh-public"]
|
|
container_name: fips-node-a
|
|
hostname: node-a
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/mesh-public/node-a.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.10
|
|
|
|
pub-b:
|
|
<<: *fips-common
|
|
profiles: ["mesh-public"]
|
|
container_name: fips-node-b
|
|
hostname: node-b
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/mesh-public/node-b.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.11
|
|
|
|
pub-c:
|
|
<<: *fips-common
|
|
profiles: ["mesh-public"]
|
|
container_name: fips-node-c
|
|
hostname: node-c
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/mesh-public/node-c.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.12
|
|
|
|
pub-d:
|
|
<<: *fips-common
|
|
profiles: ["mesh-public"]
|
|
container_name: fips-node-d
|
|
hostname: node-d
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/mesh-public/node-d.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.13
|
|
|
|
pub-e:
|
|
<<: *fips-common
|
|
profiles: ["mesh-public"]
|
|
container_name: fips-node-e
|
|
hostname: node-e
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/mesh-public/node-e.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.14
|
|
|
|
# ── Chain topology (A-B-C-D-E) ────────────────────────────────
|
|
chain-a:
|
|
<<: *fips-common
|
|
profiles: ["chain"]
|
|
container_name: fips-node-a
|
|
hostname: node-a
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/chain/node-a.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.10
|
|
|
|
chain-b:
|
|
<<: *fips-common
|
|
profiles: ["chain"]
|
|
container_name: fips-node-b
|
|
hostname: node-b
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/chain/node-b.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.11
|
|
|
|
chain-c:
|
|
<<: *fips-common
|
|
profiles: ["chain"]
|
|
container_name: fips-node-c
|
|
hostname: node-c
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/chain/node-c.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.12
|
|
|
|
chain-d:
|
|
<<: *fips-common
|
|
profiles: ["chain"]
|
|
container_name: fips-node-d
|
|
hostname: node-d
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/chain/node-d.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.13
|
|
|
|
chain-e:
|
|
<<: *fips-common
|
|
profiles: ["chain"]
|
|
container_name: fips-node-e
|
|
hostname: node-e
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/chain/node-e.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.14
|
|
|
|
# ── Rekey integration test (mesh + aggressive rekey timers) ──
|
|
rekey-a:
|
|
<<: *fips-common
|
|
profiles: ["rekey"]
|
|
container_name: fips-node-a
|
|
hostname: node-a
|
|
environment:
|
|
- RUST_LOG=info,fips::node::handlers::rekey=debug
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/rekey/node-a.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.10
|
|
|
|
rekey-b:
|
|
<<: *fips-common
|
|
profiles: ["rekey"]
|
|
container_name: fips-node-b
|
|
hostname: node-b
|
|
environment:
|
|
- RUST_LOG=info,fips::node::handlers::rekey=debug
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/rekey/node-b.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.11
|
|
|
|
rekey-c:
|
|
<<: *fips-common
|
|
profiles: ["rekey"]
|
|
container_name: fips-node-c
|
|
hostname: node-c
|
|
environment:
|
|
- RUST_LOG=info,fips::node::handlers::rekey=debug
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/rekey/node-c.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.12
|
|
|
|
rekey-d:
|
|
<<: *fips-common
|
|
profiles: ["rekey"]
|
|
container_name: fips-node-d
|
|
hostname: node-d
|
|
environment:
|
|
- RUST_LOG=info,fips::node::handlers::rekey=debug
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/rekey/node-d.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.13
|
|
|
|
rekey-e:
|
|
<<: *fips-common
|
|
profiles: ["rekey"]
|
|
container_name: fips-node-e
|
|
hostname: node-e
|
|
environment:
|
|
- RUST_LOG=info,fips::node::handlers::rekey=debug
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/rekey/node-e.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.14
|
|
|
|
# ── Rekey + accept_connections=false on node b ──────────────────
|
|
# Exercises the auto_connect-initiator-with-accept-off regression
|
|
# class. Same 5-node mesh, but node b's generated config has
|
|
# `transports.udp.accept_connections: false` (injected by
|
|
# rekey-test.sh's inject-config when REKEY_ACCEPT_OFF_NODES=b).
|
|
rekey-accept-off-a:
|
|
<<: *fips-common
|
|
profiles: ["rekey-accept-off"]
|
|
container_name: fips-node-a
|
|
hostname: node-a
|
|
environment:
|
|
- RUST_LOG=info,fips::node::handlers::rekey=debug,fips::node::handlers::handshake=debug
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/rekey-accept-off/node-a.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.10
|
|
|
|
rekey-accept-off-b:
|
|
<<: *fips-common
|
|
profiles: ["rekey-accept-off"]
|
|
container_name: fips-node-b
|
|
hostname: node-b
|
|
environment:
|
|
- RUST_LOG=info,fips::node::handlers::rekey=debug,fips::node::handlers::handshake=debug
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/rekey-accept-off/node-b.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.11
|
|
|
|
rekey-accept-off-c:
|
|
<<: *fips-common
|
|
profiles: ["rekey-accept-off"]
|
|
container_name: fips-node-c
|
|
hostname: node-c
|
|
environment:
|
|
- RUST_LOG=info,fips::node::handlers::rekey=debug,fips::node::handlers::handshake=debug
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/rekey-accept-off/node-c.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.12
|
|
|
|
rekey-accept-off-d:
|
|
<<: *fips-common
|
|
profiles: ["rekey-accept-off"]
|
|
container_name: fips-node-d
|
|
hostname: node-d
|
|
environment:
|
|
- RUST_LOG=info,fips::node::handlers::rekey=debug,fips::node::handlers::handshake=debug
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/rekey-accept-off/node-d.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.13
|
|
|
|
rekey-accept-off-e:
|
|
<<: *fips-common
|
|
profiles: ["rekey-accept-off"]
|
|
container_name: fips-node-e
|
|
hostname: node-e
|
|
environment:
|
|
- RUST_LOG=info,fips::node::handlers::rekey=debug,fips::node::handlers::handshake=debug
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/rekey-accept-off/node-e.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.14
|
|
|
|
# ── TCP chain topology (A-B-C) ───────────────────────────────
|
|
tcp-a:
|
|
<<: *fips-common
|
|
profiles: ["tcp-chain"]
|
|
container_name: fips-node-a
|
|
hostname: node-a
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/tcp-chain/node-a.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.10
|
|
|
|
tcp-b:
|
|
<<: *fips-common
|
|
profiles: ["tcp-chain"]
|
|
container_name: fips-node-b
|
|
hostname: node-b
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/tcp-chain/node-b.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.11
|
|
|
|
tcp-c:
|
|
<<: *fips-common
|
|
profiles: ["tcp-chain"]
|
|
container_name: fips-node-c
|
|
hostname: node-c
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/tcp-chain/node-c.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.12
|
|
|
|
# ── Gateway integration test (gateway + server + non-FIPS client) ─
|
|
gw-gateway:
|
|
<<: *fips-common
|
|
profiles: ["gateway"]
|
|
container_name: fips-gw-gateway
|
|
hostname: gw-gateway
|
|
# Privileged required: gateway must enable IPv6 on eth1 (second network,
|
|
# attached after container start) and manage nftables NAT rules.
|
|
privileged: true
|
|
environment:
|
|
- RUST_LOG=info
|
|
- FIPS_TEST_MODE=gateway
|
|
sysctls:
|
|
- net.ipv6.conf.all.disable_ipv6=0
|
|
- net.ipv6.conf.default.disable_ipv6=0
|
|
- net.ipv6.conf.all.forwarding=1
|
|
- net.ipv6.conf.all.proxy_ndp=1
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/gateway/node-a.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.10
|
|
gateway-lan:
|
|
ipv4_address: 172.20.1.10
|
|
ipv6_address: fd02::10
|
|
|
|
gw-server:
|
|
<<: *fips-common
|
|
profiles: ["gateway"]
|
|
container_name: fips-gw-server
|
|
hostname: gw-server
|
|
volumes:
|
|
- ../docker/resolv.conf:/etc/resolv.conf:ro
|
|
- ./generated-configs/gateway/node-b.yaml:/etc/fips/fips.yaml:ro
|
|
networks:
|
|
fips-net:
|
|
ipv4_address: 172.20.0.11
|
|
|
|
gw-client:
|
|
image: fips-test-app:latest
|
|
profiles: ["gateway"]
|
|
container_name: fips-gw-client
|
|
hostname: gw-client
|
|
cap_add:
|
|
- NET_ADMIN
|
|
sysctls:
|
|
- net.ipv6.conf.all.disable_ipv6=0
|
|
volumes:
|
|
- ./configs/gateway-resolv.conf:/etc/resolv.conf:ro
|
|
networks:
|
|
gateway-lan:
|
|
ipv4_address: 172.20.1.20
|
|
ipv6_address: fd02::20
|
|
restart: "no"
|
|
env_file:
|
|
- ./generated-configs/npubs.env
|