From 0b35a10afbe1fdcae99b4049b3327d065764ff5f Mon Sep 17 00:00:00 2001 From: DevomB Date: Wed, 7 Oct 2026 13:24:03 -0700 Subject: [PATCH] The zones suite's comments are shorter, with their reasons kept: cleanup-held's cut of tools/image/zones-test.sh, redone on main by hand, comments only Three comments are taken from 65a6fbb: the 3 GB guest, the console copy of each suite's result, and the accepted launcher gaps, whose reasons the pass message beside them already names. The header stays main's, since --help prints lines 2-15 of it; the cut's mapper check conflicted with main's and is dropped. --- tools/image/zones-test.sh | 10 +++------- 1 file changed, 3 insertions(+), 7 deletions(-) diff --git a/tools/image/zones-test.sh b/tools/image/zones-test.sh index 7118396b..e63cbf87 100755 --- a/tools/image/zones-test.sh +++ b/tools/image/zones-test.sh @@ -49,8 +49,7 @@ install_disk zones-install "$USB" --vars clean && green "installed" || { red "in # ----------------------------------------------------------------- step 2 -- step "step 2: the guest-side zone, network and storage checks (as root)" -# 3 GB, not the default 2: ephemeral-size-bound fills untrusted's 2G tmpfs, -# which is RAM, until ENOSPC. +# 3 GB, not 2: ephemeral-size-bound fills untrusted's 2G tmpfs, which is RAM, until ENOSPC. start_vm zones-p2 --net user --mem 3072 drive 900 "expect:KRYPTIK_SMOKE: END" "seen:kryptik-firstboot: created user '${TUSER}'" "login:${TUSER}:${TPASS}" \ "$(ROOTSH 'bash /usr/lib/kryptik/guest-tests/zones-check.sh 2>&1 | tee /var/log/kryptik/zones-check.log; echo ZCHECK-DONE')" \ @@ -77,8 +76,7 @@ done # ----------------------------------------------------------------- step 3 -- if [[ "$SUITES" -eq 1 ]]; then step "step 3: the compartment suites on the target kernel (as root)" -# Suites log on the guest, whose disk acceptance does not keep, so the console -# also gets each exit code, summary tail and FAIL row with context. +# The guest's disk is not kept, so the console also gets each exit code, summary tail and FAIL row. suite_cmd() { # suite_cmd TAG TAIL_LINES COMMAND -> the guest command line printf '%s > /var/log/kryptik/%s-suite.log 2>&1; echo %s-RC=$?; tail -%s /var/log/kryptik/%s-suite.log; grep -n -A3 "^ *FAIL" /var/log/kryptik/%s-suite.log | sed "s/^/%s-FAIL: /" | head -80' \ "$3" "${1,,}" "$1" "$2" "${1,,}" "${1,,}" "$1" @@ -100,9 +98,7 @@ for s in LAUNCHER ADVERSARIAL BOUNDARY CLI; do grep "^${s}-FAIL: " <<<"$T3" | sed "s/^${s}-FAIL: / /" fi done -# The launcher gaps accepted here; any other is a failure. NETR: the real net -# zone holds the NIC (zones-check covers it). LC15/LC16: unprivileged-only. -# H1c: zone 0 has no interface here. +# Only the launcher gaps named below are accepted here; any other is a failure. if grep -q 'LAUNCHER SUITE PASSED$' <<<"$T3"; then green "launcher suite passed with no gaps" elif grep -q 'LAUNCHER SUITE PASSED WITH GAPS' <<<"$T3"; then