diff options
| author | Craig Jennings <c@cjennings.net> | 2026-08-14 11:51:27 -0500 |
|---|---|---|
| committer | Craig Jennings <c@cjennings.net> | 2026-08-14 11:51:27 -0500 |
| commit | e9f82d19c75ac8602f5840794d6bd62e30576c30 (patch) | |
| tree | de8d6f412254e9d19adf83a39665265d0035d668 /tests | |
| parent | 1a900e50433b0fcd3a192eed1c7989233a6928cf (diff) | |
| download | archangel-e9f82d19c75ac8602f5840794d6bd62e30576c30.tar.gz archangel-e9f82d19c75ac8602f5840794d6bd62e30576c30.zip | |
fix(install): refuse out-of-range passphrases before the disk is wiped
The unattended path only checked that a passphrase was non-empty, while zpool create enforces 8-512 characters, so a short passphrase failed after partitioning had already destroyed the old pool. The velox reinstall hit exactly that: its profile shipped a 7-char placeholder, and run 1 died post-wipe. validate_encryption_passphrase now takes min/max bounds. ZFS gets 8-512 pre-flight, and LUKS gets the same 8 minimum the interactive prompt enforces.
Two adjacent gaps close with it: SWAP_SIZE now rejects zero sizes, which previously passed validation and died at sgdisk after the wipe. validate_config warns when the swap partition lands next to an encrypted root, since a hibernate image is a full RAM dump with keys included. The tracked example profiles' 7-char placeholders are now 8 characters.
Diffstat (limited to 'tests')
| -rw-r--r-- | tests/unit/test_config.bats | 75 |
1 files changed, 75 insertions, 0 deletions
diff --git a/tests/unit/test_config.bats b/tests/unit/test_config.bats index 554c0c7..26d9e0a 100644 --- a/tests/unit/test_config.bats +++ b/tests/unit/test_config.bats @@ -303,6 +303,51 @@ EOF ! [[ "$output" == *"ZFS_PASSPHRASE"* ]] } +@test "validate_encryption_passphrase rejects a passphrase under the minimum length" { + NO_ENCRYPT=no + ZFS_PASSPHRASE="welcome" + run validate_encryption_passphrase ZFS_PASSPHRASE 8 + [ "$status" -eq 1 ] + [[ "$output" == *"at least 8"* ]] + [[ "$output" == *"ZFS_PASSPHRASE"* ]] +} + +@test "validate_encryption_passphrase accepts a passphrase at exactly the minimum length" { + NO_ENCRYPT=no + ZFS_PASSPHRASE="welcome1" + run validate_encryption_passphrase ZFS_PASSPHRASE 8 + [ "$status" -eq 0 ] +} + +@test "validate_encryption_passphrase without a minimum keeps the empty-only check" { + NO_ENCRYPT=no + LUKS_PASSPHRASE="hunter2" + run validate_encryption_passphrase LUKS_PASSPHRASE + [ "$status" -eq 0 ] +} + +@test "validate_encryption_passphrase skips the length check when NO_ENCRYPT=yes" { + NO_ENCRYPT=yes + ZFS_PASSPHRASE="short" + run validate_encryption_passphrase ZFS_PASSPHRASE 8 + [ "$status" -eq 0 ] +} + +@test "validate_encryption_passphrase rejects a passphrase over the maximum length" { + NO_ENCRYPT=no + ZFS_PASSPHRASE=$(printf 'a%.0s' {1..513}) + run validate_encryption_passphrase ZFS_PASSPHRASE 8 512 + [ "$status" -eq 1 ] + [[ "$output" == *"at most 512"* ]] +} + +@test "validate_encryption_passphrase accepts a passphrase at exactly the maximum length" { + NO_ENCRYPT=no + ZFS_PASSPHRASE=$(printf 'a%.0s' {1..512}) + run validate_encryption_passphrase ZFS_PASSPHRASE 8 512 + [ "$status" -eq 0 ] +} + ############################# # SWAP_SIZE validation ############################# @@ -338,6 +383,36 @@ EOF [[ "$output" == *"Invalid SWAP_SIZE"* ]] } +@test "validate_config rejects a zero SWAP_SIZE" { + HOSTNAME=h; TIMEZONE=UTC; ROOT_PASSWORD=x + SELECTED_DISKS=(/dev/sda); RAID_LEVEL=""; SWAP_SIZE=0G + run validate_config + [ "$status" -eq 1 ] + [[ "$output" == *"Invalid SWAP_SIZE"* ]] +} + +@test "validate_config rejects a leading-zero SWAP_SIZE" { + HOSTNAME=h; TIMEZONE=UTC; ROOT_PASSWORD=x + SELECTED_DISKS=(/dev/sda); RAID_LEVEL=""; SWAP_SIZE=00G + run validate_config + [ "$status" -eq 1 ] + [[ "$output" == *"Invalid SWAP_SIZE"* ]] +} + +@test "validate_config warns that swap is unencrypted when encryption is on" { + HOSTNAME=h; TIMEZONE=UTC; ROOT_PASSWORD=x + SELECTED_DISKS=(/dev/sda); RAID_LEVEL=""; SWAP_SIZE=100G; NO_ENCRYPT=no + run validate_config + [[ "$output" == *"unencrypted"* ]] +} + +@test "validate_config does not warn about swap encryption when NO_ENCRYPT=yes" { + HOSTNAME=h; TIMEZONE=UTC; ROOT_PASSWORD=x + SELECTED_DISKS=(/dev/sda); RAID_LEVEL=""; SWAP_SIZE=100G; NO_ENCRYPT=yes + run validate_config + [[ "$output" != *"unencrypted"* ]] +} + @test "validate_config rejects SWAP_SIZE on a multi-disk layout" { HOSTNAME=h; TIMEZONE=UTC; ROOT_PASSWORD=x SELECTED_DISKS=(/dev/sda /dev/sdb); RAID_LEVEL=mirror; SWAP_SIZE=100G |
