test(e2e): add reusable QEMU infrastructure for E2E tests - #2471
Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
a9988d0 to
41f2720
Compare
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
4f528ef to
52cb5e1
Compare
drew
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Validation: This maintainer-authored PR is project-valid as reusable QEMU/Nix test infrastructure for the release and E2E stack.
Head SHA: 52cb5e1b90ababfdf89a4ee95a37bb111509263f
Review findings:
- Warning: the OCI cache path pulls and boots a full guest disk from a mutable repository reference. Metadata and disk checksums protect transfer integrity, but not provenance. Before wiring this into trusted CI, require an org-controlled immutable registry policy or artifact signing/verification; otherwise the cache repository becomes a supply-chain execution surface.
- Three line-specific warnings are inline.
Docs: Fern docs/navigation are not required for this contributor/test infrastructure change; nix/test-guest/README.md and architecture/build.md cover the new workflow.
Next state: gator:in-review
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
drew
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Validation: This maintainer-authored PR remains project-valid as reusable Nix/QEMU test guest infrastructure for release and E2E follow-on work.
Head SHA: 49ae902c28f3c514535434e65bc4dc2c640be5da
Review findings:
- Warning: package verification coverage regressed when the Debian package smoke-test block was removed before an equivalent VM-backed CI replacement exists.
- Warning: OCI prepared-disk cache pulls still verify integrity but not publisher provenance; trusted CI use needs an immutable org-controlled reference or signature/manifest verification.
- Suggestion:
nix/test-guest/run.shshould use the same explicit option-value validation pattern ascache.shfor a cleaner CLI failure mode.
Docs: Fern docs/navigation are not required for this contributor/test infrastructure change; nix/test-guest/README.md and architecture/build.md cover the workflow.
Checks: DCO and gate-status publication passed; Branch Checks and Helm Lint are still pending on /ok to test mirror validation. I am not triggering CI while review warnings remain unresolved.
Next state: gator:in-review
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
039537a to
9f24004
Compare
|
/ok to test 9f24004 |
drew
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Validation: This maintainer-authored PR remains project-valid as reusable Nix/QEMU test guest infrastructure for release and E2E follow-on work.
Head SHA: 9f240044655387561c88b4b305e8770f88042765
Review findings:
- Warning: the SSH control socket path can exceed Unix socket path limits during cache builds because
TMPDIRmay be a deep cache staging path. - Warning: local prepared-disk cache hits still trust existing metadata without revalidating the disk checksum or QCOW2 structure.
Docs: Fern docs/navigation are not required for this contributor/test infrastructure change; nix/test-guest/README.md and architecture/build.md cover the workflow.
Checks: DCO and gate-status publication passed; Branch Checks and Helm Lint are still pending on /ok to test mirror validation. I am not triggering CI while review warnings remain unresolved.
Next state: gator:in-review
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
drew
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Validation: This maintainer-authored PR remains project-valid as reusable Nix/QEMU test guest infrastructure for release and E2E follow-on work.
Head SHA: 7f365efb813777575f291f6e48230913aa287303
Review findings:
- Warning: removing the Debian package smoke block drops existing package verification coverage before the VM-backed replacement lands.
- Suggestion: the runner option parser should validate required option values before
shift 2for cleaner CLI failures.
Docs: Fern docs/navigation are not required for this contributor/test infrastructure change; nix/test-guest/README.md and architecture/build.md cover the workflow.
Checks: DCO and gate-status publication passed; Branch Checks and Helm Lint are still pending on /ok to test mirror validation. I am not moving to pipeline watch while the review warning remains unresolved.
Next state: gator:in-review
drew
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Validation: This maintainer-authored PR remains project-valid as reusable Nix/QEMU test guest infrastructure for release and E2E follow-on work.
Head SHA: 418b2605f9404612b71674c2fd225d2312f5a879
Review findings:
- Warning: the new README documents E2E wrapper paths and a mise task that are not present in this PR/current tree.
- Warning: Debian package smoke verification is removed before equivalent VM-backed coverage lands.
- Warning: the OCI cache push path accepts an existing remote tag without validating the artifact contents against the local cache key.
- Warning: SSH/SCP should force the generated key with
IdentitiesOnly=yesto avoid agent-key authentication failures. - Suggestion: align the runner option parser with
cache.shvalue validation for cleaner CLI failures.
Docs: Fern docs/navigation are not required for this internal contributor/test infrastructure change; nix/test-guest/README.md and architecture/build.md cover the intended workflow, but the README includes stale future entry points that need correction.
Checks: DCO and gate-status publication passed; Branch Checks and Helm Lint remain pending on /ok to test mirror validation. I am not moving to pipeline watch while review findings remain unresolved.
Next state: gator:in-review
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
drew
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Validation: This maintainer-authored PR remains project-valid as reusable Nix/QEMU test guest infrastructure for release and E2E follow-on work.
Head SHA: 86cf640591154b8934db8e85483f20dd3c623c37
Review findings:
- No blocking findings remain. The independent reviewer re-checked the current head and found no line-specific actionable findings.
Trusted author/maintainer feedback: Thanks @drew, I checked your current-head replies about the prior cache validation, OCI tag verification, SSH identity, parser validation, stale README, and Debian package-smoke concerns. The code changes address the actionable review items, and the Debian package-smoke removal is covered by the release-canary path you called out.
Docs: Fern docs/navigation are not required for this internal contributor/test infrastructure change; nix/test-guest/README.md and architecture/build.md cover the workflow.
Tests: Applying test:e2e because this adds VM-backed runtime/test infrastructure and package execution paths.
Checks: DCO and gate-status publication are passing. Branch Checks and Helm Lint are pending current-head /ok to test mirror validation.
Next state: gator:watch-pipeline
|
/ok to test 86cf640 |
|
Label |
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
drew
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
Validation: This maintainer-authored PR remains project-valid as reusable Nix/QEMU test infrastructure for release and E2E work.
Head SHA: 3d48a73ab33a8f9554e13d8b320bfe79088d17ea
Review findings:
- Three line-specific warnings are inline: host-side
scpoption injection, Podman relay readiness, and mutable runtime-image inputs. - Suggestion: add focused mocked shell tests for hostile argument shapes and cache metadata/checksum/digest rejection paths; keep full QEMU integration coverage in the stacked child PRs.
Durable feedback: Prior trusted maintainer resolutions and waivers remain honored. These findings are new or materially distinct: the scp concern is host-side option parsing rather than the resolved guest-destination quoting issue, and the two Podman findings arise from this head's new hook.
Docs: Fern docs/navigation are not required for this contributor/test infrastructure; nix/test-guest/README.md and architecture/build.md cover the workflow.
Checks: DCO and required-gate publication pass. Branch Checks, Helm Lint, and E2E remain pending, but author changes are needed before pipeline watch resumes.
Next state: gator:in-review
| fi | ||
| remote_package="/home/openshell/${package_name}" | ||
| echo "==> Installing package: ${package_name}" | ||
| scp "${scp_args[@]}" "${package}" "openshell@127.0.0.1:${remote_package}" |
There was a problem hiding this comment.
gator-agent
Warning: User-controlled --install paths are passed directly to scp; line 563 does the same for --copy. A valid path beginning with an option such as -S... can alter host-side scp behavior (CWE-88). Resolve validated sources to absolute paths with realpath -- before basename/scp, use an end-of-options marker where supported, and add a leading-hyphen regression case.
| TCP-LISTEN:8080,bind=0.0.0.0,reuseaddr,fork \ | ||
| "UNIX-CONNECT:${relay_socket}" | ||
| for _ in $(seq 1 50); do | ||
| if systemctl --user is-active --quiet "${network_relay_unit}.service"; then |
There was a problem hiding this comment.
gator-agent
Warning: systemctl is-active only proves that systemd launched this default Type=simple unit; it does not prove socat has bound port 8080 inside the rootless network namespace. Poll the actual listener from podman unshare --rootless-netns while also checking that the unit remains active, so the hook cannot return before the relay is ready.
|
|
||
| install -m 0555 "${supervisor_bin}" "${build_context}/openshell-sandbox" | ||
| cat >"${build_context}/Containerfile" <<'EOF' | ||
| FROM alpine:3.22 |
There was a problem hiding this comment.
gator-agent
Warning: This post-cache hook resolves mutable alpine:3.22 and mutable APK packages on every fresh test guest. That makes E2E behavior depend on current registry contents and lets an upstream compromise alter the supervisor enforcement environment (CWE-494). Pin the multi-architecture base digest and reproducible package inputs, or consume a trusted digest-qualified supervisor base.
Summary
Add reusable Nix and QEMU infrastructure for running OpenShell tests in disposable Linux VMs. The harness provides pinned native-architecture cloud guests, composable runtime and security configurations, artifact installation, predictable cleanup, and retained diagnostics for failures.
This is the base infrastructure PR for the VM-backed release and E2E test integrations in the child PRs below.
Stack
This is the parent PR.
Related Issue
Changes
nix run .#test-vminterface with disposable QCOW2 overlays, cloud-init SSH bootstrap, hardware acceleration where available, cleanup, and retained debug statedpkgto the Nix development shell and keep Debian package creation artifact-onlyTesting
bash -n nix/vm/run.sh tasks/scripts/package-deb.shshellcheck nix/vm/run.sh tasks/scripts/package-deb.shnix fmtreports no changesaarch64-darwin,aarch64-linux, andx86_64-linuxmise run pre-commitpassesChecklist