aboutsummaryrefslogtreecommitdiff
path: root/scripts/testing/tests/test_hardening.py
diff options
context:
space:
mode:
authorCraig Jennings <c@cjennings.net>2026-07-20 23:40:56 -0500
committerCraig Jennings <c@cjennings.net>2026-07-20 23:40:56 -0500
commit866d327f0bad3a0730801a22654bac45e02ee14b (patch)
tree4e73da36583178812fc7c36622ae3f6ec161606d /scripts/testing/tests/test_hardening.py
parentc076a79dddecf5680d738477402e50ee2ac09c0f (diff)
downloadarchsetup-866d327f0bad3a0730801a22654bac45e02ee14b.tar.gz
archsetup-866d327f0bad3a0730801a22654bac45e02ee14b.zip
fix(test): harden four VM-framework paths from the S5 audit
init_vm_paths suffixed the disk and NVRAM by FS_PROFILE but left PID_FILE, MONITOR_SOCK, and SERIAL_LOG shared. A concurrent btrfs and zfs run read each other's PID file, so the second run's stop logic could kill the first run's VM. All runtime paths now carry the suffix. kill_qemu sent kill -9 and returned without waiting, so the force-kill fallback could run qemu-img snapshot against a qcow2 the dying qemu still held locked (the restore failed silently behind || true, leaving the base image dirty). It now reaps or polls the process to death before returning. debug-vm.sh hardcoded the btrfs base-disk name, so FS_PROFILE=zfs booted the wrong base or fatalled. It now takes DISK_PATH from init_vm_paths. Both runners reported a completion-marker grep as "ArchSetup Exit Code," but the installer runs detached with set -e off, so its real exit status was never captured -- a run that errored mid-way and still reached its last line reported exit 0. The flag is now ARCHSETUP_COMPLETED with the report labeled honestly; Testinfra stays the pass/fail authority.
Diffstat (limited to 'scripts/testing/tests/test_hardening.py')
0 files changed, 0 insertions, 0 deletions