Isolate backend tests from live node wallets and services
This commit is contained in:
@@ -112,10 +112,9 @@ VERSION="$(grep -m1 '^version' core/archipelago/Cargo.toml | sed 's/.*"\(.*\)".*
|
||||
if [ "$SKIP_GATES" = "0" ]; then
|
||||
stage "release-gate-harness" bash tests/release/run.sh
|
||||
stage "catalog-drift-strict" python3 scripts/check-app-catalog-drift.py --release --strict
|
||||
# Full Rust suite — the release harness only runs a 6-module slice;
|
||||
# ~1000 tests otherwise go unverified at ISO time (hardening plan §H).
|
||||
stage "cargo-test-full" timeout 5400 env CARGO_INCREMENTAL=0 \
|
||||
nice -n 10 cargo test --manifest-path core/Cargo.toml -p archipelago --bin archipelago
|
||||
# The release harness runs the full backend suite inside namespaces.
|
||||
# Never execute unrestricted tests on a node with live wallets/services.
|
||||
|
||||
else
|
||||
echo; echo "═══ [gates] SKIPPED (--skip-gates)"
|
||||
fi
|
||||
|
||||
Executable
+47
@@ -0,0 +1,47 @@
|
||||
#!/usr/bin/env bash
|
||||
# Compile normally; execute unit tests away from real wallets, service buses,
|
||||
# container storage, processes and networking. Never silently fall back to host.
|
||||
set -euo pipefail
|
||||
REPO=$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)
|
||||
command -v systemd-run >/dev/null
|
||||
command -v unshare >/dev/null
|
||||
command -v setpriv >/dev/null
|
||||
sudo -n true || { echo 'Isolated backend tests require noninteractive sudo for systemd namespaces.' >&2; exit 1; }
|
||||
metadata=$(mktemp)
|
||||
trap 'rm -f "$metadata"' EXIT
|
||||
if ! cargo test --manifest-path "$REPO/core/Cargo.toml" -p archipelago --bin archipelago \
|
||||
--locked --no-run --message-format=json --config 'profile.test.package.archipelago.opt-level=0' > "$metadata"; then
|
||||
python3 - "$metadata" <<'PYDIAG'
|
||||
import json,sys
|
||||
for line in open(sys.argv[1]):
|
||||
try: item=json.loads(line)
|
||||
except json.JSONDecodeError: continue
|
||||
rendered=item.get('message',{}).get('rendered') if item.get('reason')=='compiler-message' else None
|
||||
if rendered: print(rendered,file=sys.stderr,end='')
|
||||
PYDIAG
|
||||
exit 1
|
||||
fi
|
||||
executable=$(python3 - "$metadata" <<'PY'
|
||||
import json,sys
|
||||
found=[]
|
||||
for line in open(sys.argv[1]):
|
||||
try: item=json.loads(line)
|
||||
except json.JSONDecodeError: continue
|
||||
if item.get('reason')=='compiler-artifact' and item.get('profile',{}).get('test') and item.get('executable'):
|
||||
found.append(item['executable'])
|
||||
assert len(found)==1, f'Expected one unit test executable, got {len(found)}'
|
||||
print(found[0])
|
||||
PY
|
||||
)
|
||||
[[ -x "$executable" ]]
|
||||
unit="archy-isolated-tests-$(date +%s)-$$"
|
||||
sudo -n systemd-run --unit="$unit" --wait --pipe --collect \
|
||||
--property="WorkingDirectory=$REPO/core" \
|
||||
--property=PrivateNetwork=yes --property=PrivateTmp=yes --property=PrivateDevices=yes \
|
||||
--property=ProtectSystem=strict --property=ProtectHome=read-only \
|
||||
--property=NoNewPrivileges=yes \
|
||||
--property='TemporaryFileSystem=/run:rw /var/lib/archipelago:rw /var/lib/containers:rw /root:rw' \
|
||||
--setenv=ARCHY_TEST_ISOLATED=1 \
|
||||
/usr/bin/unshare --pid --fork --mount-proc --kill-child \
|
||||
/usr/bin/setpriv --bounding-set=-all,+chown,+dac_override,+fowner,+setuid,+setgid,+kill \
|
||||
"$executable" --test-threads=4 "$@"
|
||||
Reference in New Issue
Block a user