fix: kernel AppArmor 2-pass olddefconfig and QEMU test direct kernel boot
The stock TinyCore kernel config has "# CONFIG_SECURITY is not set" which caused make olddefconfig to silently revert all security configs in a single pass. Fix by applying security configs (AppArmor, Audit, LSM) after the first olddefconfig resolves base dependencies, then running a second pass. Added mandatory verification that exits on missing critical configs. All QEMU test scripts converted from broken -cdrom + -append pattern to direct kernel boot (-kernel + -initrd) via shared test/lib/qemu-helpers.sh helper library. The -append flag only works with -kernel, not -cdrom. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -5,19 +5,26 @@
|
||||
set -euo pipefail
|
||||
|
||||
ISO="${1:?Usage: $0 <path-to-iso>}"
|
||||
TIMEOUT_BOOT=120
|
||||
TIMEOUT_K8S=300
|
||||
TIMEOUT_POD=120
|
||||
TIMEOUT_K8S=${TIMEOUT_K8S:-300}
|
||||
TIMEOUT_POD=${TIMEOUT_POD:-120}
|
||||
API_PORT=6443
|
||||
SERIAL_LOG=$(mktemp /tmp/kubesolo-workload-XXXXXX.log)
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
PROJECT_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
|
||||
. "$SCRIPT_DIR/../lib/qemu-helpers.sh"
|
||||
|
||||
DATA_DISK=$(mktemp /tmp/kubesolo-data-XXXXXX.img)
|
||||
dd if=/dev/zero of="$DATA_DISK" bs=1M count=1024 2>/dev/null
|
||||
mkfs.ext4 -q -L KSOLODATA "$DATA_DISK" 2>/dev/null
|
||||
|
||||
QEMU_PID=""
|
||||
EXTRACT_DIR=""
|
||||
|
||||
cleanup() {
|
||||
kill "$QEMU_PID" 2>/dev/null || true
|
||||
[ -n "$QEMU_PID" ] && kill "$QEMU_PID" 2>/dev/null || true
|
||||
rm -f "$DATA_DISK" "$SERIAL_LOG"
|
||||
[ -n "$EXTRACT_DIR" ] && rm -rf "$EXTRACT_DIR"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
@@ -25,14 +32,22 @@ KUBECTL="kubectl --server=https://localhost:${API_PORT} --insecure-skip-tls-veri
|
||||
|
||||
echo "==> Workload deployment test: $ISO"
|
||||
|
||||
# Extract kernel from ISO
|
||||
EXTRACT_DIR="$(mktemp -d /tmp/kubesolo-extract-XXXXXX)"
|
||||
extract_kernel_from_iso "$ISO" "$EXTRACT_DIR"
|
||||
|
||||
KVM_FLAG=$(detect_kvm)
|
||||
|
||||
# Launch QEMU
|
||||
# shellcheck disable=SC2086
|
||||
qemu-system-x86_64 \
|
||||
-m 2048 -smp 2 \
|
||||
-nographic \
|
||||
-cdrom "$ISO" \
|
||||
-boot d \
|
||||
$KVM_FLAG \
|
||||
-kernel "$VMLINUZ" \
|
||||
-initrd "$INITRAMFS" \
|
||||
-drive "file=$DATA_DISK,format=raw,if=virtio" \
|
||||
-net nic,model=virtio \
|
||||
-net "nic,model=virtio" \
|
||||
-net "user,hostfwd=tcp::${API_PORT}-:6443" \
|
||||
-serial "file:$SERIAL_LOG" \
|
||||
-append "console=ttyS0,115200n8 kubesolo.data=/dev/vda" \
|
||||
@@ -71,6 +86,7 @@ $KUBECTL run test-nginx --image=nginx:alpine --restart=Never 2>/dev/null || {
|
||||
echo " Waiting for pod to reach Running..."
|
||||
ELAPSED=0
|
||||
POD_RUNNING=0
|
||||
STATUS=""
|
||||
while [ "$ELAPSED" -lt "$TIMEOUT_POD" ]; do
|
||||
STATUS=$($KUBECTL get pod test-nginx -o jsonpath='{.status.phase}' 2>/dev/null || echo "")
|
||||
if [ "$STATUS" = "Running" ]; then
|
||||
|
||||
@@ -5,31 +5,47 @@
|
||||
set -euo pipefail
|
||||
|
||||
ISO="${1:?Usage: $0 <path-to-iso>}"
|
||||
TIMEOUT_BOOT=120
|
||||
TIMEOUT_K8S=300
|
||||
TIMEOUT_K8S=${TIMEOUT_K8S:-300}
|
||||
API_PORT=6443
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
PROJECT_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
|
||||
. "$SCRIPT_DIR/../lib/qemu-helpers.sh"
|
||||
|
||||
DATA_DISK=$(mktemp /tmp/kubesolo-data-XXXXXX.img)
|
||||
dd if=/dev/zero of="$DATA_DISK" bs=1M count=1024 2>/dev/null
|
||||
mkfs.ext4 -q -L KSOLODATA "$DATA_DISK" 2>/dev/null
|
||||
|
||||
QEMU_PID=""
|
||||
EXTRACT_DIR=""
|
||||
|
||||
cleanup() {
|
||||
kill "$QEMU_PID" 2>/dev/null || true
|
||||
[ -n "$QEMU_PID" ] && kill "$QEMU_PID" 2>/dev/null || true
|
||||
rm -f "$DATA_DISK"
|
||||
[ -n "$EXTRACT_DIR" ] && rm -rf "$EXTRACT_DIR"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
echo "==> K8s readiness test: $ISO"
|
||||
|
||||
# Extract kernel from ISO
|
||||
EXTRACT_DIR="$(mktemp -d /tmp/kubesolo-extract-XXXXXX)"
|
||||
extract_kernel_from_iso "$ISO" "$EXTRACT_DIR"
|
||||
|
||||
KVM_FLAG=$(detect_kvm)
|
||||
[ -n "$KVM_FLAG" ] && echo " KVM acceleration: enabled"
|
||||
|
||||
# Launch QEMU with API port forwarded
|
||||
# shellcheck disable=SC2086
|
||||
qemu-system-x86_64 \
|
||||
-m 2048 -smp 2 \
|
||||
-nographic \
|
||||
-cdrom "$ISO" \
|
||||
-boot d \
|
||||
$KVM_FLAG \
|
||||
-kernel "$VMLINUZ" \
|
||||
-initrd "$INITRAMFS" \
|
||||
-drive "file=$DATA_DISK,format=raw,if=virtio" \
|
||||
-net nic,model=virtio \
|
||||
-net user,hostfwd=tcp::${API_PORT}-:6443 \
|
||||
-net "nic,model=virtio" \
|
||||
-net "user,hostfwd=tcp::${API_PORT}-:6443" \
|
||||
-append "console=ttyS0,115200n8 kubesolo.data=/dev/vda" \
|
||||
&
|
||||
QEMU_PID=$!
|
||||
|
||||
@@ -5,37 +5,52 @@
|
||||
set -euo pipefail
|
||||
|
||||
ISO="${1:?Usage: $0 <path-to-iso>}"
|
||||
TIMEOUT_K8S=300
|
||||
TIMEOUT_PVC=120
|
||||
TIMEOUT_K8S=${TIMEOUT_K8S:-300}
|
||||
TIMEOUT_PVC=${TIMEOUT_PVC:-120}
|
||||
API_PORT=6443
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
PROJECT_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
|
||||
. "$SCRIPT_DIR/../lib/qemu-helpers.sh"
|
||||
|
||||
DATA_DISK=$(mktemp /tmp/kubesolo-data-XXXXXX.img)
|
||||
dd if=/dev/zero of="$DATA_DISK" bs=1M count=2048 2>/dev/null
|
||||
mkfs.ext4 -q -L KSOLODATA "$DATA_DISK" 2>/dev/null
|
||||
|
||||
SERIAL_LOG=$(mktemp /tmp/kubesolo-storage-XXXXXX.log)
|
||||
|
||||
QEMU_PID=""
|
||||
EXTRACT_DIR=""
|
||||
KUBECTL="kubectl --server=https://localhost:${API_PORT} --insecure-skip-tls-verify"
|
||||
|
||||
cleanup() {
|
||||
# Clean up K8s resources
|
||||
$KUBECTL delete pod test-storage --grace-period=0 --force 2>/dev/null || true
|
||||
$KUBECTL delete pvc test-pvc 2>/dev/null || true
|
||||
kill "$QEMU_PID" 2>/dev/null || true
|
||||
[ -n "$QEMU_PID" ] && kill "$QEMU_PID" 2>/dev/null || true
|
||||
rm -f "$DATA_DISK" "$SERIAL_LOG"
|
||||
[ -n "$EXTRACT_DIR" ] && rm -rf "$EXTRACT_DIR"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
KUBECTL="kubectl --server=https://localhost:${API_PORT} --insecure-skip-tls-verify"
|
||||
|
||||
echo "==> Local storage test: $ISO"
|
||||
|
||||
# Extract kernel from ISO
|
||||
EXTRACT_DIR="$(mktemp -d /tmp/kubesolo-extract-XXXXXX)"
|
||||
extract_kernel_from_iso "$ISO" "$EXTRACT_DIR"
|
||||
|
||||
KVM_FLAG=$(detect_kvm)
|
||||
|
||||
# Launch QEMU
|
||||
# shellcheck disable=SC2086
|
||||
qemu-system-x86_64 \
|
||||
-m 2048 -smp 2 \
|
||||
-nographic \
|
||||
-cdrom "$ISO" \
|
||||
-boot d \
|
||||
$KVM_FLAG \
|
||||
-kernel "$VMLINUZ" \
|
||||
-initrd "$INITRAMFS" \
|
||||
-drive "file=$DATA_DISK,format=raw,if=virtio" \
|
||||
-net nic,model=virtio \
|
||||
-net "nic,model=virtio" \
|
||||
-net "user,hostfwd=tcp::${API_PORT}-:6443" \
|
||||
-serial "file:$SERIAL_LOG" \
|
||||
-append "console=ttyS0,115200n8 kubesolo.data=/dev/vda" \
|
||||
@@ -98,6 +113,7 @@ YAML
|
||||
# Wait for pod Running
|
||||
echo " Waiting for storage pod..."
|
||||
ELAPSED=0
|
||||
STATUS=""
|
||||
while [ "$ELAPSED" -lt "$TIMEOUT_PVC" ]; do
|
||||
STATUS=$($KUBECTL get pod test-storage -o jsonpath='{.status.phase}' 2>/dev/null || echo "")
|
||||
if [ "$STATUS" = "Running" ]; then
|
||||
|
||||
@@ -6,35 +6,50 @@
|
||||
set -euo pipefail
|
||||
|
||||
ISO="${1:?Usage: $0 <path-to-iso>}"
|
||||
TIMEOUT_K8S=300
|
||||
TIMEOUT_POD=120
|
||||
TIMEOUT_K8S=${TIMEOUT_K8S:-300}
|
||||
TIMEOUT_POD=${TIMEOUT_POD:-120}
|
||||
API_PORT=6443
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
PROJECT_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
|
||||
. "$SCRIPT_DIR/../lib/qemu-helpers.sh"
|
||||
|
||||
DATA_DISK=$(mktemp /tmp/kubesolo-data-XXXXXX.img)
|
||||
dd if=/dev/zero of="$DATA_DISK" bs=1M count=1024 2>/dev/null
|
||||
mkfs.ext4 -q -L KSOLODATA "$DATA_DISK" 2>/dev/null
|
||||
|
||||
SERIAL_LOG=$(mktemp /tmp/kubesolo-netpol-XXXXXX.log)
|
||||
|
||||
QEMU_PID=""
|
||||
EXTRACT_DIR=""
|
||||
KUBECTL="kubectl --server=https://localhost:${API_PORT} --insecure-skip-tls-verify"
|
||||
|
||||
cleanup() {
|
||||
$KUBECTL delete namespace netpol-test 2>/dev/null || true
|
||||
kill "$QEMU_PID" 2>/dev/null || true
|
||||
[ -n "$QEMU_PID" ] && kill "$QEMU_PID" 2>/dev/null || true
|
||||
rm -f "$DATA_DISK" "$SERIAL_LOG"
|
||||
[ -n "$EXTRACT_DIR" ] && rm -rf "$EXTRACT_DIR"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
KUBECTL="kubectl --server=https://localhost:${API_PORT} --insecure-skip-tls-verify"
|
||||
|
||||
echo "==> Network policy test: $ISO"
|
||||
|
||||
# Extract kernel from ISO
|
||||
EXTRACT_DIR="$(mktemp -d /tmp/kubesolo-extract-XXXXXX)"
|
||||
extract_kernel_from_iso "$ISO" "$EXTRACT_DIR"
|
||||
|
||||
KVM_FLAG=$(detect_kvm)
|
||||
|
||||
# Launch QEMU
|
||||
# shellcheck disable=SC2086
|
||||
qemu-system-x86_64 \
|
||||
-m 2048 -smp 2 \
|
||||
-nographic \
|
||||
-cdrom "$ISO" \
|
||||
-boot d \
|
||||
$KVM_FLAG \
|
||||
-kernel "$VMLINUZ" \
|
||||
-initrd "$INITRAMFS" \
|
||||
-drive "file=$DATA_DISK,format=raw,if=virtio" \
|
||||
-net nic,model=virtio \
|
||||
-net "nic,model=virtio" \
|
||||
-net "user,hostfwd=tcp::${API_PORT}-:6443" \
|
||||
-serial "file:$SERIAL_LOG" \
|
||||
-append "console=ttyS0,115200n8 kubesolo.data=/dev/vda" \
|
||||
@@ -81,6 +96,7 @@ YAML
|
||||
|
||||
# Wait for pod
|
||||
ELAPSED=0
|
||||
STATUS=""
|
||||
while [ "$ELAPSED" -lt "$TIMEOUT_POD" ]; do
|
||||
STATUS=$($KUBECTL get pod -n netpol-test web -o jsonpath='{.status.phase}' 2>/dev/null || echo "")
|
||||
[ "$STATUS" = "Running" ] && break
|
||||
|
||||
@@ -12,9 +12,13 @@
|
||||
set -euo pipefail
|
||||
|
||||
ISO="${1:?Usage: $0 <path-to-iso>}"
|
||||
TIMEOUT_BOOT=180 # seconds to wait for boot
|
||||
TIMEOUT_BOOT=${TIMEOUT_BOOT:-180} # seconds to wait for boot
|
||||
SERIAL_LOG=$(mktemp /tmp/kubesolo-security-test-XXXXXX.log)
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
PROJECT_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
|
||||
. "$SCRIPT_DIR/../lib/qemu-helpers.sh"
|
||||
|
||||
# Temp data disk
|
||||
DATA_DISK=$(mktemp /tmp/kubesolo-security-data-XXXXXX.img)
|
||||
dd if=/dev/zero of="$DATA_DISK" bs=1M count=1024 2>/dev/null
|
||||
@@ -22,6 +26,7 @@ mkfs.ext4 -q -L KSOLODATA "$DATA_DISK" 2>/dev/null
|
||||
|
||||
QEMU_PID=""
|
||||
EXTRACT_DIR=""
|
||||
|
||||
cleanup() {
|
||||
[ -n "$QEMU_PID" ] && kill "$QEMU_PID" 2>/dev/null || true
|
||||
rm -f "$DATA_DISK" "$SERIAL_LOG"
|
||||
@@ -33,68 +38,12 @@ echo "==> Security Hardening Test: $ISO"
|
||||
echo " Timeout: ${TIMEOUT_BOOT}s"
|
||||
echo " Serial log: $SERIAL_LOG"
|
||||
|
||||
# Extract kernel from ISO
|
||||
EXTRACT_DIR="$(mktemp -d /tmp/kubesolo-extract-XXXXXX)"
|
||||
extract_kernel_from_iso "$ISO" "$EXTRACT_DIR"
|
||||
|
||||
# Detect KVM
|
||||
KVM_FLAG=""
|
||||
[ -w /dev/kvm ] 2>/dev/null && KVM_FLAG="-enable-kvm"
|
||||
|
||||
# Extract kernel + initramfs from ISO (direct kernel boot required for -append)
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
PROJECT_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
|
||||
ROOTFS_DIR="${ROOTFS_DIR:-$PROJECT_ROOT/build/rootfs-work}"
|
||||
EXTRACT_DIR=""
|
||||
|
||||
VMLINUZ=""
|
||||
INITRAMFS=""
|
||||
|
||||
if [ -f "$ROOTFS_DIR/vmlinuz" ] && [ -f "$ROOTFS_DIR/kubesolo-os.gz" ]; then
|
||||
VMLINUZ="$ROOTFS_DIR/vmlinuz"
|
||||
INITRAMFS="$ROOTFS_DIR/kubesolo-os.gz"
|
||||
echo " Using kernel/initramfs from build directory"
|
||||
else
|
||||
EXTRACT_DIR="$(mktemp -d /tmp/kubesolo-extract-XXXXXX)"
|
||||
EXTRACTED=0
|
||||
|
||||
echo " Extracting kernel/initramfs from ISO..."
|
||||
|
||||
if [ $EXTRACTED -eq 0 ] && command -v bsdtar >/dev/null 2>&1; then
|
||||
if bsdtar -xf "$ISO" -C "$EXTRACT_DIR" boot/vmlinuz boot/kubesolo-os.gz 2>/dev/null; then
|
||||
EXTRACTED=1
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ $EXTRACTED -eq 0 ] && command -v isoinfo >/dev/null 2>&1; then
|
||||
mkdir -p "$EXTRACT_DIR/boot"
|
||||
isoinfo -i "$ISO" -x "/BOOT/VMLINUZ;1" > "$EXTRACT_DIR/boot/vmlinuz" 2>/dev/null || true
|
||||
isoinfo -i "$ISO" -x "/BOOT/KUBESOLO-OS.GZ;1" > "$EXTRACT_DIR/boot/kubesolo-os.gz" 2>/dev/null || true
|
||||
if [ -s "$EXTRACT_DIR/boot/vmlinuz" ] && [ -s "$EXTRACT_DIR/boot/kubesolo-os.gz" ]; then
|
||||
EXTRACTED=1
|
||||
else
|
||||
rm -f "$EXTRACT_DIR/boot/vmlinuz" "$EXTRACT_DIR/boot/kubesolo-os.gz"
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ $EXTRACTED -eq 0 ] && [ "$(uname)" = "Linux" ]; then
|
||||
ISO_MOUNT="$EXTRACT_DIR/mnt"
|
||||
mkdir -p "$ISO_MOUNT"
|
||||
if mount -o loop,ro "$ISO" "$ISO_MOUNT" 2>/dev/null; then
|
||||
mkdir -p "$EXTRACT_DIR/boot"
|
||||
cp "$ISO_MOUNT/boot/vmlinuz" "$EXTRACT_DIR/boot/" 2>/dev/null || true
|
||||
cp "$ISO_MOUNT/boot/kubesolo-os.gz" "$EXTRACT_DIR/boot/" 2>/dev/null || true
|
||||
umount "$ISO_MOUNT" 2>/dev/null || true
|
||||
if [ -f "$EXTRACT_DIR/boot/vmlinuz" ] && [ -f "$EXTRACT_DIR/boot/kubesolo-os.gz" ]; then
|
||||
EXTRACTED=1
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ $EXTRACTED -eq 0 ]; then
|
||||
echo "ERROR: Failed to extract kernel/initramfs from ISO."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
VMLINUZ="$EXTRACT_DIR/boot/vmlinuz"
|
||||
INITRAMFS="$EXTRACT_DIR/boot/kubesolo-os.gz"
|
||||
fi
|
||||
KVM_FLAG=$(detect_kvm)
|
||||
|
||||
# Launch QEMU in background with direct kernel boot
|
||||
# shellcheck disable=SC2086
|
||||
@@ -171,7 +120,7 @@ fi
|
||||
|
||||
echo ""
|
||||
echo "--- Test 2: AppArmor ---"
|
||||
if grep -q "AppArmor profiles loaded" "$SERIAL_LOG" 2>/dev/null; then
|
||||
if grep -q "AppArmor.*loaded.*profiles" "$SERIAL_LOG" 2>/dev/null; then
|
||||
check_pass "AppArmor profiles loaded"
|
||||
elif grep -q "AppArmor not available" "$SERIAL_LOG" 2>/dev/null; then
|
||||
check_skip "AppArmor not in kernel (expected before kernel rebuild)"
|
||||
|
||||
Reference in New Issue
Block a user