aboutsummaryrefslogtreecommitdiff
path: root/tests/unit
diff options
context:
space:
mode:
authorCraig Jennings <c@cjennings.net>2026-08-14 11:51:27 -0500
committerCraig Jennings <c@cjennings.net>2026-08-14 11:51:27 -0500
commite9f82d19c75ac8602f5840794d6bd62e30576c30 (patch)
treede8d6f412254e9d19adf83a39665265d0035d668 /tests/unit
parent1a900e50433b0fcd3a192eed1c7989233a6928cf (diff)
downloadarchangel-e9f82d19c75ac8602f5840794d6bd62e30576c30.tar.gz
archangel-e9f82d19c75ac8602f5840794d6bd62e30576c30.zip
fix(install): refuse out-of-range passphrases before the disk is wiped
The unattended path only checked that a passphrase was non-empty, while zpool create enforces 8-512 characters, so a short passphrase failed after partitioning had already destroyed the old pool. The velox reinstall hit exactly that: its profile shipped a 7-char placeholder, and run 1 died post-wipe. validate_encryption_passphrase now takes min/max bounds. ZFS gets 8-512 pre-flight, and LUKS gets the same 8 minimum the interactive prompt enforces. Two adjacent gaps close with it: SWAP_SIZE now rejects zero sizes, which previously passed validation and died at sgdisk after the wipe. validate_config warns when the swap partition lands next to an encrypted root, since a hibernate image is a full RAM dump with keys included. The tracked example profiles' 7-char placeholders are now 8 characters.
Diffstat (limited to 'tests/unit')
-rw-r--r--tests/unit/test_config.bats75
1 files changed, 75 insertions, 0 deletions
diff --git a/tests/unit/test_config.bats b/tests/unit/test_config.bats
index 554c0c7..26d9e0a 100644
--- a/tests/unit/test_config.bats
+++ b/tests/unit/test_config.bats
@@ -303,6 +303,51 @@ EOF
! [[ "$output" == *"ZFS_PASSPHRASE"* ]]
}
+@test "validate_encryption_passphrase rejects a passphrase under the minimum length" {
+ NO_ENCRYPT=no
+ ZFS_PASSPHRASE="welcome"
+ run validate_encryption_passphrase ZFS_PASSPHRASE 8
+ [ "$status" -eq 1 ]
+ [[ "$output" == *"at least 8"* ]]
+ [[ "$output" == *"ZFS_PASSPHRASE"* ]]
+}
+
+@test "validate_encryption_passphrase accepts a passphrase at exactly the minimum length" {
+ NO_ENCRYPT=no
+ ZFS_PASSPHRASE="welcome1"
+ run validate_encryption_passphrase ZFS_PASSPHRASE 8
+ [ "$status" -eq 0 ]
+}
+
+@test "validate_encryption_passphrase without a minimum keeps the empty-only check" {
+ NO_ENCRYPT=no
+ LUKS_PASSPHRASE="hunter2"
+ run validate_encryption_passphrase LUKS_PASSPHRASE
+ [ "$status" -eq 0 ]
+}
+
+@test "validate_encryption_passphrase skips the length check when NO_ENCRYPT=yes" {
+ NO_ENCRYPT=yes
+ ZFS_PASSPHRASE="short"
+ run validate_encryption_passphrase ZFS_PASSPHRASE 8
+ [ "$status" -eq 0 ]
+}
+
+@test "validate_encryption_passphrase rejects a passphrase over the maximum length" {
+ NO_ENCRYPT=no
+ ZFS_PASSPHRASE=$(printf 'a%.0s' {1..513})
+ run validate_encryption_passphrase ZFS_PASSPHRASE 8 512
+ [ "$status" -eq 1 ]
+ [[ "$output" == *"at most 512"* ]]
+}
+
+@test "validate_encryption_passphrase accepts a passphrase at exactly the maximum length" {
+ NO_ENCRYPT=no
+ ZFS_PASSPHRASE=$(printf 'a%.0s' {1..512})
+ run validate_encryption_passphrase ZFS_PASSPHRASE 8 512
+ [ "$status" -eq 0 ]
+}
+
#############################
# SWAP_SIZE validation
#############################
@@ -338,6 +383,36 @@ EOF
[[ "$output" == *"Invalid SWAP_SIZE"* ]]
}
+@test "validate_config rejects a zero SWAP_SIZE" {
+ HOSTNAME=h; TIMEZONE=UTC; ROOT_PASSWORD=x
+ SELECTED_DISKS=(/dev/sda); RAID_LEVEL=""; SWAP_SIZE=0G
+ run validate_config
+ [ "$status" -eq 1 ]
+ [[ "$output" == *"Invalid SWAP_SIZE"* ]]
+}
+
+@test "validate_config rejects a leading-zero SWAP_SIZE" {
+ HOSTNAME=h; TIMEZONE=UTC; ROOT_PASSWORD=x
+ SELECTED_DISKS=(/dev/sda); RAID_LEVEL=""; SWAP_SIZE=00G
+ run validate_config
+ [ "$status" -eq 1 ]
+ [[ "$output" == *"Invalid SWAP_SIZE"* ]]
+}
+
+@test "validate_config warns that swap is unencrypted when encryption is on" {
+ HOSTNAME=h; TIMEZONE=UTC; ROOT_PASSWORD=x
+ SELECTED_DISKS=(/dev/sda); RAID_LEVEL=""; SWAP_SIZE=100G; NO_ENCRYPT=no
+ run validate_config
+ [[ "$output" == *"unencrypted"* ]]
+}
+
+@test "validate_config does not warn about swap encryption when NO_ENCRYPT=yes" {
+ HOSTNAME=h; TIMEZONE=UTC; ROOT_PASSWORD=x
+ SELECTED_DISKS=(/dev/sda); RAID_LEVEL=""; SWAP_SIZE=100G; NO_ENCRYPT=yes
+ run validate_config
+ [[ "$output" != *"unencrypted"* ]]
+}
+
@test "validate_config rejects SWAP_SIZE on a multi-disk layout" {
HOSTNAME=h; TIMEZONE=UTC; ROOT_PASSWORD=x
SELECTED_DISKS=(/dev/sda /dev/sdb); RAID_LEVEL=mirror; SWAP_SIZE=100G