diff options
| author | Ophestra <cat@gensokyo.uk> | 2026-10-04 01:05:10 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2026-10-06 19:41:06 +0900 |
| commit | a7383510fb05abc98b992240cb76ad4b6c598956 (patch) | |
| tree | 90881e9d6952e050128f1378d66452c7d733d012 /test/sandbox/tool | |
| parent | b452e1047ccd3e1826da16416430e6638270155b (diff) | |
test/sandbox: migrate tests
This significantly improves performance, removing overhead of nix,
python, and virtualisation. Running this in an unprivileged container
required patching the kernel, but since special runner setup was already
needed, that was an acceptable tradeoff.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'test/sandbox/tool')
| -rw-r--r-- | test/sandbox/tool/main.go | 106 | ||||
| -rw-r--r-- | test/sandbox/tool/package.nix | 32 |
2 files changed, 0 insertions, 138 deletions
diff --git a/test/sandbox/tool/main.go b/test/sandbox/tool/main.go deleted file mode 100644 index 889142d4..00000000 --- a/test/sandbox/tool/main.go +++ /dev/null @@ -1,106 +0,0 @@ -//go:build testtool - -package main - -import ( - "flag" - "fmt" - "log" - "os" - "os/signal" - "strconv" - "strings" - "syscall" - - "hakurei.app/test/internal/sandbox" -) - -var ( - flagMarkerPath string - flagTestCase string - flagBpfHash string -) - -func init() { - flag.StringVar(&flagMarkerPath, "p", "/tmp/sandbox-ok", "Pathname of completion marker") - flag.StringVar(&flagTestCase, "t", "", "Nix store path to test case file") - flag.StringVar(&flagBpfHash, "s", "", "String representation of expected bpf sha512 hash") -} - -func main() { - log.SetFlags(0) - log.SetPrefix("test: ") - flag.Parse() - - args := flag.Args() - if len(args) < 1 { - s := make(chan os.Signal, 1) - signal.Notify(s, syscall.SIGINT) - go func() { <-s; log.Println("exiting on signal (likely from verifier)"); os.Exit(0) }() - - (&sandbox.T{FS: os.DirFS("/")}).MustCheckFile(flagTestCase) - if _, err := os.Create(flagMarkerPath); err != nil { - log.Fatalf("cannot create success marker: %v", err) - } - log.Printf("blocking for seccomp check (%s)", flagMarkerPath) - select {} - return - } - - switch args[0] { - case "filter": - if len(args) != 2 { - log.Fatal("invalid argument") - } - - if pid, err := strconv.Atoi(strings.TrimSpace(args[1])); err != nil { - log.Fatalf("%s", err) - } else if pid < 1 { - log.Fatalf("%d out of range", pid) - } else { - sandbox.MustCheckFilter(pid, flagBpfHash) - if err = syscall.Kill(pid, syscall.SIGINT); err != nil { - log.Fatalf("cannot signal check process: %v", err) - } - } - - case "hash": // this eases the pain of passing the hash to python - fmt.Print(flagBpfHash) - - case "fd": - if len(args) != 2 { - log.Fatal("invalid argument") - } - prefix := fmt.Sprintf("/proc/%s/fd/", args[1]) - - var fail bool - if entries, err := os.ReadDir(prefix); err != nil { - log.Fatal(err.Error()) - } else { - for _, ent := range entries { - var fd int - if fd, err = strconv.Atoi(ent.Name()); err != nil { - log.Fatal(err.Error()) - } - - // skip standard streams - if fd <= 2 { - continue - } - fail = true - - var d string - if d, err = os.Readlink(prefix + ent.Name()); err != nil { - log.Fatal(err.Error()) - } - log.Printf("[FAIL] extra fd %d -> %s", fd, d) - } - } - if fail { - log.Fatal("[FAIL] file descriptors leaked") - } - - default: - log.Fatal("invalid argument") - } -} diff --git a/test/sandbox/tool/package.nix b/test/sandbox/tool/package.nix deleted file mode 100644 index bd57b432..00000000 --- a/test/sandbox/tool/package.nix +++ /dev/null @@ -1,32 +0,0 @@ -{ - lib, - buildGoModule, - pkg-config, - util-linux, - - version, -}: -buildGoModule rec { - pname = "check-sandbox"; - inherit version; - - src = builtins.path { - name = "${pname}-src"; - path = lib.cleanSource ../../.; - filter = path: type: (type == "directory") || (type == "regular" && lib.hasSuffix ".go" path); - }; - vendorHash = null; - - tags = [ "testtool" "tester" ]; - - buildInputs = [ util-linux ]; - nativeBuildInputs = [ pkg-config ]; - - preBuild = '' - go mod init hakurei.app/test >& /dev/null - ''; - - postInstall = '' - mv $out/bin/tool $out/bin/hakurei-test - ''; -} |
