This commit is contained in:
+30
-16
@@ -209,26 +209,34 @@ assert_processes_return_to_baseline() {
|
||||
|
||||
assert_loopback_cdp_listener() {
|
||||
local container="$1"
|
||||
local artifact="$2"
|
||||
docker exec "$container" cat /proc/net/tcp > "$artifact"
|
||||
local tcp_artifact="$2"
|
||||
local tcp6_artifact="$3"
|
||||
docker exec "$container" cat /proc/net/tcp > "$tcp_artifact"
|
||||
docker exec "$container" cat /proc/net/tcp6 > "$tcp6_artifact"
|
||||
docker exec -i "$container" python3 - <<'PY'
|
||||
expected = f"0100007F:{9222:04X}"
|
||||
wildcard = f"00000000:{9222:04X}"
|
||||
if expected != "0100007F:2406":
|
||||
raise SystemExit(f"unexpected 9222 hexadecimal encoding: {expected}")
|
||||
|
||||
listeners = set()
|
||||
with open("/proc/net/tcp", encoding="ascii") as handle:
|
||||
next(handle)
|
||||
for line in handle:
|
||||
fields = line.split()
|
||||
if len(fields) >= 4 and fields[3] == "0A":
|
||||
listeners.add(fields[1].upper())
|
||||
listeners = {"/proc/net/tcp": set(), "/proc/net/tcp6": set()}
|
||||
for table in ("/proc/net/tcp", "/proc/net/tcp6"):
|
||||
with open(table, encoding="ascii") as handle:
|
||||
next(handle)
|
||||
for line in handle:
|
||||
fields = line.split()
|
||||
if len(fields) < 4 or fields[3] != "0A":
|
||||
continue
|
||||
local_address = fields[1].upper()
|
||||
if local_address.rsplit(":", 1)[-1] != "2406":
|
||||
continue
|
||||
listeners[table].add(local_address)
|
||||
if table == "/proc/net/tcp6":
|
||||
raise SystemExit(f"IPv6 CDP listener present: {local_address}")
|
||||
|
||||
if expected not in listeners:
|
||||
raise SystemExit(f"missing loopback CDP listener {expected}: {sorted(listeners)}")
|
||||
if wildcard in listeners:
|
||||
raise SystemExit(f"wildcard CDP listener present: {wildcard}")
|
||||
if listeners["/proc/net/tcp"] != {expected}:
|
||||
raise SystemExit(
|
||||
f"IPv4 CDP listeners = {sorted(listeners['/proc/net/tcp'])}, want [{expected}]"
|
||||
)
|
||||
PY
|
||||
}
|
||||
|
||||
@@ -370,7 +378,10 @@ first_port="$(host_port "$first_container")"
|
||||
wait_ready "$first_container" "$first_port"
|
||||
first_baseline="$(capture_process_baseline "$first_container")"
|
||||
assert_no_9222_mapping "$first_container"
|
||||
assert_loopback_cdp_listener "$first_container" "${artifacts_dir}/runtime-proc-net-tcp.txt"
|
||||
assert_loopback_cdp_listener \
|
||||
"$first_container" \
|
||||
"${artifacts_dir}/runtime-proc-net-tcp.txt" \
|
||||
"${artifacts_dir}/runtime-proc-net-tcp6.txt"
|
||||
probe_and_close_cdp "$first_container"
|
||||
assert_processes_return_to_baseline "$first_container" "$first_baseline"
|
||||
post_invalid_worker "$first_port" "${artifacts_dir}/runtime-invalid-worker-response.json"
|
||||
@@ -383,7 +394,10 @@ second_port="$(host_port "$second_container")"
|
||||
wait_ready "$second_container" "$second_port"
|
||||
second_baseline="$(capture_process_baseline "$second_container")"
|
||||
assert_no_9222_mapping "$second_container"
|
||||
assert_loopback_cdp_listener "$second_container" "${artifacts_dir}/runtime-restart-proc-net-tcp.txt"
|
||||
assert_loopback_cdp_listener \
|
||||
"$second_container" \
|
||||
"${artifacts_dir}/runtime-restart-proc-net-tcp.txt" \
|
||||
"${artifacts_dir}/runtime-restart-proc-net-tcp6.txt"
|
||||
probe_and_close_cdp "$second_container"
|
||||
assert_processes_return_to_baseline "$second_container" "$second_baseline"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user