Skip to content

fix: test hygiene and one CRL regeneration path - #58

Merged
catinspace-au merged 1 commit into
mainfrom
fix/test-hygiene-crl-dedupe
Oct 1, 2026
Merged

catinspace-au merged 1 commit into
mainfrom
fix/test-hygiene-crl-dedupe

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

Five follow-ups from the first real scan of scripts/ in #57.

  • vulture is now blocking (quality.python.vulture). We are at zero findings, so new dead code fails CI.
  • TestProcessManager uses the existing manager fixture, so the SIGTERM, SIGINT and SIGHUP handlers each test installs are put back afterwards.
  • The TLS-floor fixture restores ClientDownloadHandler.auth_token and clients_dir and shuts its server down. Run first, it used to fail 9 later tests with 401.
  • The download handler treats BrokenPipeError and ConnectionResetError as a client hanging up. TLS 1.3 writes session tickets on the server's first read, so a client that closed straight after the handshake hit a broken pipe and socketserver printed a traceback. A new test covers it. start_client_download_server now returns the server so a caller can stop it.
  • update-crl calls lib.pki._regenerate_local_crl instead of carrying its own copy.

CRL behaviour, old against new:

  • Same easyrsa gen-crl, same PKI dir, same arguments (none), same exit codes (1 for a missing PKI dir, a missing CA or a failed gen-crl), same success lines.
  • The library now sets EASYRSA and EASYRSA_BATCH=1 itself, as the command did. Before, the refresh loop only had them when the PKI was initialised in that same process.
  • The library now logs Easy-RSA's full stderr in the error message, as the command did. It was cut to 200 characters and held in a field the console log format does not show.
  • The failure line now reads CRL regeneration failed: <stderr> where the command said Failed to update CRL: <stderr>. Same content, the library's wording.
  • The PKI and Easy-RSA paths are now shell-quoted.

Checked in the v2.1.16 image against Easy-RSA 3.2.5. The old command, old library, new command and new library each wrote a CRL with the same issuer, revoked serials, 180-day validity and signature algorithm, and each verifies against the CA. /entrypoint.py update-crl with the new code in the image's own layout exits 0 and lists the revoked client.

vulture is at zero findings, so it now blocks. The ProcessManager tests restore the signal handlers they install, and the TLS-floor test puts the handler's auth token back and stops its server, so it no longer fails whatever runs after it.

The download handler now treats a client that hangs up as routine. A TLS 1.3 server writes its session tickets on its first read, so a client that closed straight after the handshake hit a broken pipe there and socketserver printed a traceback to stderr.

update-crl now regenerates through lib.pki, the function the refresh loop already runs. The library takes the command's explicit EASYRSA and EASYRSA_BATCH, and puts Easy-RSA's full stderr in the error message, because the console log format does not show fields.
@catinspace-au
catinspace-au requested a review from a team as a code owner October 1, 2026 10:17
@catinspace-au
catinspace-au merged commit 91ad85e into main Oct 1, 2026
13 checks passed
@catinspace-au
catinspace-au deleted the fix/test-hygiene-crl-dedupe branch October 1, 2026 10:23
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Released in v2.1.17 -- https://github.com/hyperi-io/culvert/releases/tag/v2.1.17

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant