systemd 260 introduces some new linkConfig options to configure ethernet
devices and a new [MobileNetwork] section (and options) to configure
cellular network connections using a new integration with ModemManager.
- https://github.com/systemd/systemd/releases/tag/v260
For backwards-compat reason it's legal to do
runTest {
nodes.foo = { /* ... */ };
testScript = ''
machine.start()
# do your thing
'';
}
This makes several places in the codebase unnecessarily complex and is
something people shouldn't be using anyways. Additionally, I was
reminded by people that this can actually be confusing when you expect
the variable to be named differently.
Hence, deprecate this behavior and kill it in a few releases down the
road.
`vhost-device-vsock`[1] is a custom implementation of AF_VSOCK, but the
application on the host-side uses a UNIX domain-socket. This gives us
the following nice properties:
* We don't need to do `--arg sandbox-paths /dev/vhost-vsock` anymore for
debugging builds within the sandbox. That means, untrusted users can
also debug these kinds of tests now.
* This prevents CID conflicts on the host-side, i.e. there's no need for
using `sshBackdoor.vsockOffset` for tests anymore.
A big shout-out goes to Allison Karlitskaya, the developer of test.thing[2]
who talked about this approach to do AF_VSOCK on All Systems Go 2025.
This patch requires systemd 258[3] because this contains `vhost-mux` in
its SSH config which is needed to connect to the VMs from now on.
To not blow up the patches even more, this only uses AF_VSOCK for the
debugger. A potential follow-up for the future would be a removal of the
current `backdoor.service` and replace it entirely by this
functionality.
The internal implementation tries to be consistent with how VLANs and
machines are handled, i.e. the processes are started when the Driver's
context is entered and cleaned up in __exit__().
I decided to push the process management and creation of sockets for
vhost-device-vsock into its own class, that's an implementation detail
and not a concern for the test-driver. In fact, `vhost-device-vsock` is
something we can drop once QEMU implements native support for using
AF_UNIX on the host-side[4]. `VsockPair` is its own class since
returning e.g. a triple of `(Path, Path, Int)` would be ambiguous in
what is the guest and what the host path (and frankly, I found it hard
to distinguish the two when reading the docs of `vhost-device-vsock`
initially).
Finally, now that we can do the SSH backdoor without adding additional
devices to the sandbox, I figured, it's time to write a test-case for
it.
[1] https://github.com/rust-vmm/vhost-device/blob/main/vhost-device-vsock/README.md
[2] https://codeberg.org/lis/test.thing
[3] https://github.com/NixOS/nixpkgs/pull/427968
[4] https://gitlab.com/qemu-project/qemu/-/issues/2095
The context manager's purpose is to allocate its resources in `__enter__` and
release them again in `__exit__`.
Right now, the approach is merely a hack since we allocate everything in
the constructor, but use the context-manager protocol as way to reliably
terminate everything.
This isn't a functional change, but merely a correctness change by using
the methods the way they were intended.
This function is used to convert an ordered list of rules into an
attrset of rules with reasonable 'order' values. This reduces
boilerplate to define 'order' and makes it simple to switch how ordering
is managed in the future.
This always returns a QemuMachine, which may need to have
QEMU-specific methods called on it.
Fixes: 23f1e6370d ("nixos/test-driver: add support for nspawn containers")
Fixes: 799cafcc23 ("nixos/test-driver: refactor Machine to BaseMachine and QemuMachine")
The nspawn container support (23f1e6370d) added a `containers`
argument to the testScript caller. This breaks tests whose testScript
uses strict pattern matching without ellipsis, e.g. `{ nodes }:`,
since Nix rejects unexpected arguments.
Use `builtins.intersectAttrs` to only pass arguments the function
actually expects, making the caller forward-compatible with future
argument additions.
Fixes: 23f1e6370d ("nixos/test-driver: add support for nspawn containers")
By default it will look for the cred names supported by the upstream package, but alternate cred names can be chosen to produce a rename on the ImportCredential.