Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 3 additions & 7 deletions tools/image/zones-test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -49,8 +49,7 @@ install_disk zones-install "$USB" --vars clean && green "installed" || { red "in

# ----------------------------------------------------------------- step 2 --
step "step 2: the guest-side zone, network and storage checks (as root)"
# 3 GB, not the default 2: ephemeral-size-bound fills untrusted's 2G tmpfs,
# which is RAM, until ENOSPC.
# 3 GB, not 2: ephemeral-size-bound fills untrusted's 2G tmpfs, which is RAM, until ENOSPC.
start_vm zones-p2 --net user --mem 3072
drive 900 "expect:KRYPTIK_SMOKE: END" "seen:kryptik-firstboot: created user '${TUSER}'" "login:${TUSER}:${TPASS}" \
"$(ROOTSH 'bash /usr/lib/kryptik/guest-tests/zones-check.sh 2>&1 | tee /var/log/kryptik/zones-check.log; echo ZCHECK-DONE')" \
Expand All @@ -77,8 +76,7 @@ done
# ----------------------------------------------------------------- step 3 --
if [[ "$SUITES" -eq 1 ]]; then
step "step 3: the compartment suites on the target kernel (as root)"
# Suites log on the guest, whose disk acceptance does not keep, so the console
# also gets each exit code, summary tail and FAIL row with context.
# The guest's disk is not kept, so the console also gets each exit code, summary tail and FAIL row.
suite_cmd() { # suite_cmd TAG TAIL_LINES COMMAND -> the guest command line
printf '%s > /var/log/kryptik/%s-suite.log 2>&1; echo %s-RC=$?; tail -%s /var/log/kryptik/%s-suite.log; grep -n -A3 "^ *FAIL" /var/log/kryptik/%s-suite.log | sed "s/^/%s-FAIL: /" | head -80' \
"$3" "${1,,}" "$1" "$2" "${1,,}" "${1,,}" "$1"
Expand All @@ -100,9 +98,7 @@ for s in LAUNCHER ADVERSARIAL BOUNDARY CLI; do
grep "^${s}-FAIL: " <<<"$T3" | sed "s/^${s}-FAIL: / /"
fi
done
# The launcher gaps accepted here; any other is a failure. NETR: the real net
# zone holds the NIC (zones-check covers it). LC15/LC16: unprivileged-only.
# H1c: zone 0 has no interface here.
# Only the launcher gaps named below are accepted here; any other is a failure.
if grep -q 'LAUNCHER SUITE PASSED$' <<<"$T3"; then
green "launcher suite passed with no gaps"
elif grep -q 'LAUNCHER SUITE PASSED WITH GAPS' <<<"$T3"; then
Expand Down
Loading