Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
41078f1997 |
@@ -26,8 +26,8 @@ Bring the repo into policy compliance in one commit:
|
|||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
- 2026-10-02: A plain `docker build .` builds again: the size tests
|
- 2026-10-02: A plain `docker build .` builds again: the size tests
|
||||||
skip a case that needs more locked memory than the process can
|
skip a case that needs more locked memory than the limit allows,
|
||||||
lock, and run every case under `script/cibuild`. The image stamps the
|
and run every case under `script/cibuild`. The image stamps the
|
||||||
`VERSION` build argument, else `git describe --tags --always`, into
|
`VERSION` build argument, else `git describe --tags --always`, into
|
||||||
`Version`, and fails if `.git` is present but yields no version;
|
`Version`, and fails if `.git` is present but yields no version;
|
||||||
`make build` stamps `git describe` too, not a fixed `0.1.0`.
|
`make build` stamps `git describe` too, not a fixed `0.1.0`.
|
||||||
|
|||||||
@@ -28,37 +28,24 @@ const testVaultName = "test-vault"
|
|||||||
// size, and they are then copied into one more buffer of its size.
|
// size, and they are then copied into one more buffer of its size.
|
||||||
const lockedBytesPerSecretByte = 3
|
const lockedBytesPerSecretByte = 3
|
||||||
|
|
||||||
// skipIfLockedMemoryTooLow skips the test when this process cannot lock
|
// skipIfLockedMemoryTooLow skips the test when the locked-memory limit
|
||||||
// the memory a secret of size bytes needs, found by locking a buffer of
|
// (RLIMIT_MEMLOCK) cannot hold a secret of size bytes. memguard panics,
|
||||||
// that size and releasing it. memguard panics, ending the whole test run,
|
// ending the whole test run, when it cannot lock a buffer, and a plain
|
||||||
// when it cannot lock a buffer, and a plain `docker build .` runs the
|
// `docker build .` runs the tests under an 8 MiB limit.
|
||||||
// tests under an 8 MiB locked-memory limit (RLIMIT_MEMLOCK). A process
|
|
||||||
// allowed to lock past that limit runs every case.
|
|
||||||
func skipIfLockedMemoryTooLow(t *testing.T, size int) {
|
func skipIfLockedMemoryTooLow(t *testing.T, size int) {
|
||||||
t.Helper()
|
t.Helper()
|
||||||
|
|
||||||
need := lockedBytesPerSecretByte * size
|
|
||||||
|
|
||||||
buf, err := unix.Mmap(-1, 0, need,
|
|
||||||
unix.PROT_READ|unix.PROT_WRITE, unix.MAP_PRIVATE|unix.MAP_ANON)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
lockErr := unix.Mlock(buf)
|
|
||||||
|
|
||||||
// Unmapping the buffer also unlocks it.
|
|
||||||
err = unix.Munmap(buf)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
if lockErr != nil {
|
|
||||||
var limit unix.Rlimit
|
var limit unix.Rlimit
|
||||||
|
|
||||||
err = unix.Getrlimit(unix.RLIMIT_MEMLOCK, &limit)
|
err := unix.Getrlimit(unix.RLIMIT_MEMLOCK, &limit)
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
//nolint:gosec // test sizes are never negative
|
||||||
|
need := lockedBytesPerSecretByte * uint64(size)
|
||||||
|
if limit.Cur < need {
|
||||||
t.Skipf("a %d-byte secret needs up to %d bytes of locked memory, "+
|
t.Skipf("a %d-byte secret needs up to %d bytes of locked memory, "+
|
||||||
"which could not be locked under the locked-memory limit "+
|
"more than the locked-memory limit (RLIMIT_MEMLOCK) of %d bytes",
|
||||||
"(RLIMIT_MEMLOCK) of %d bytes: %v",
|
size, need, limit.Cur)
|
||||||
size, need, limit.Cur, lockErr)
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user