From a645a09bbaede831263bf6b58ccf75e9f018c96b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Old=C5=99ich=20Jedli=C4=8Dka?= Date: Mon, 1 Jun 2026 00:28:42 +0200 Subject: [PATCH] luks: skip ext-token test when the keyring is unusable MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Runners that call the test scripts directly, without Meson (e.g. Debian autopkgtest), bypass the configure-time keyctl check and the test fails where the keyring is unusable. Move the check into the test itself. Co-Authored-By: Claude Opus 5.5 (1M context) Signed-off-by: Oldřich Jedlička --- src/luks/tests/bind-luks2-ext-token | 6 +++++- src/luks/tests/meson.build | 10 ++-------- 2 files changed, 7 insertions(+), 9 deletions(-) diff --git a/src/luks/tests/bind-luks2-ext-token b/src/luks/tests/bind-luks2-ext-token index 114be310..b2ed523a 100755 --- a/src/luks/tests/bind-luks2-ext-token +++ b/src/luks/tests/bind-luks2-ext-token @@ -42,10 +42,14 @@ if ! luks2_supported; then skip_test "${TEST}: LUKS2 is not supported." fi -if ! luks2_existing_token_id_supported; then +if ! luks2_existing_token_id_supported; then skip_test "${TEST}: Existing token ID not supported" fi +if ! keyctl session - /bin/true >/dev/null 2>&1; then + skip_test "${TEST}: Session keyring is not usable (running in a container?)" +fi + trap 'on_exit' EXIT trap 'exit' ERR diff --git a/src/luks/tests/meson.build b/src/luks/tests/meson.build index aebc4816..92df21e1 100644 --- a/src/luks/tests/meson.build +++ b/src/luks/tests/meson.build @@ -8,14 +8,8 @@ cryptsetup = find_program('cryptsetup', required: true) # Use keyctl to check an existing token id can be created from # kernel keyring password keyutils = find_program('keyctl', required: false) -keyutils_usable = false if keyutils.found() - keyutils_usable = run_command(keyutils, 'session', '-', '/bin/true', capture: false, check: false).returncode() == 0 - if keyutils_usable - message('keyutils installed') - else - warning('keyutils installed, but running fails (are you inside Docker?), unable to test existing token id binding') - endif + message('keyutils installed') else warning('keyutils not installed, unable to test existing token id binding') endif @@ -93,7 +87,7 @@ if luksmeta_data.get('OLD_CRYPTSETUP') == '0' test('unbind-unbound-slot-luks2', find_program('unbind-unbound-slot-luks2'), env: env) test('unbind-luks2', find_program('unbind-luks2'), env: env, timeout: 60) - if keyutils.found() and keyutils_usable and luksmeta_data.get('OLD_CRYPTSETUP_EXISTING_TOKEN_ID') == '0' + if keyutils.found() and luksmeta_data.get('OLD_CRYPTSETUP_EXISTING_TOKEN_ID') == '0' test('bind-luks2-ext-token', find_program('bind-luks2-ext-token'), env: env, timeout: 60) endif