Repository navigation
fix: test hygiene and one CRL regeneration path - #58
Merged
Merged
Conversation
vulture is at zero findings, so it now blocks. The ProcessManager tests restore the signal handlers they install, and the TLS-floor test puts the handler's auth token back and stops its server, so it no longer fails whatever runs after it. The download handler now treats a client that hangs up as routine. A TLS 1.3 server writes its session tickets on its first read, so a client that closed straight after the handshake hit a broken pipe there and socketserver printed a traceback to stderr. update-crl now regenerates through lib.pki, the function the refresh loop already runs. The library takes the command's explicit EASYRSA and EASYRSA_BATCH, and puts Easy-RSA's full stderr in the error message, because the console log format does not show fields.
Contributor
|
Released in v2.1.17 -- https://github.com/hyperi-io/culvert/releases/tag/v2.1.17 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Five follow-ups from the first real scan of scripts/ in #57.
blocking(quality.python.vulture). We are at zero findings, so new dead code fails CI.TestProcessManageruses the existingmanagerfixture, so the SIGTERM, SIGINT and SIGHUP handlers each test installs are put back afterwards.ClientDownloadHandler.auth_tokenandclients_dirand shuts its server down. Run first, it used to fail 9 later tests with 401.BrokenPipeErrorandConnectionResetErroras a client hanging up. TLS 1.3 writes session tickets on the server's first read, so a client that closed straight after the handshake hit a broken pipe and socketserver printed a traceback. A new test covers it.start_client_download_servernow returns the server so a caller can stop it.update-crlcallslib.pki._regenerate_local_crlinstead of carrying its own copy.CRL behaviour, old against new:
easyrsa gen-crl, same PKI dir, same arguments (none), same exit codes (1 for a missing PKI dir, a missing CA or a failed gen-crl), same success lines.EASYRSAandEASYRSA_BATCH=1itself, as the command did. Before, the refresh loop only had them when the PKI was initialised in that same process.CRL regeneration failed: <stderr>where the command saidFailed to update CRL: <stderr>. Same content, the library's wording.Checked in the v2.1.16 image against Easy-RSA 3.2.5. The old command, old library, new command and new library each wrote a CRL with the same issuer, revoked serials, 180-day validity and signature algorithm, and each verifies against the CA.
/entrypoint.py update-crlwith the new code in the image's own layout exits 0 and lists the revoked client.