nixos/wireguard: test against multiple kernel versions

When testing WireGuard updates, I usually run the VM-tests with
different kernels to make sure we're not introducing accidental
regressions for e.g. older kernels.

I figured that we should automate this process to ensure continuously
that WireGuard works fine on several kernels.

For now I decided to test the latest LTS version (5.4) and
the latest kernel (currently 5.6). We can add more kernels in the
future, however this seems to significantly slow down evaluation and
time.

The list can be customized by running a command like this:

nix-build nixos/tests/wireguard --arg kernelVersionsToTest '["4.19"]'

The `kernelPackages` argument in the tests is null by default to make
sure that it's still possible to invoke the test-files directly. In that
case the default kernel of NixOS (currently 5.4) is used.

Changed files
+113 -75
nixos
pkgs
tools
networking
wireguard-tools
-3
nixos/tests/all-tests.nix
···
vault = handleTest ./vault.nix {};
victoriametrics = handleTest ./victoriametrics.nix {};
virtualbox = handleTestOn ["x86_64-linux"] ./virtualbox.nix {};
-
wg-quick = handleTest ./wireguard/wg-quick.nix {};
wireguard = handleTest ./wireguard {};
-
wireguard-generated = handleTest ./wireguard/generated.nix {};
-
wireguard-namespaces = handleTest ./wireguard/namespaces.nix {};
wordpress = handleTest ./wordpress.nix {};
xandikos = handleTest ./xandikos.nix {};
xautolock = handleTest ./xautolock.nix {};
···
vault = handleTest ./vault.nix {};
victoriametrics = handleTest ./victoriametrics.nix {};
virtualbox = handleTestOn ["x86_64-linux"] ./virtualbox.nix {};
wireguard = handleTest ./wireguard {};
wordpress = handleTest ./wordpress.nix {};
xandikos = handleTest ./xandikos.nix {};
xautolock = handleTest ./xautolock.nix {};
+74
nixos/tests/wireguard/basic.nix
···
···
+
{ kernelPackages ? null }:
+
import ../make-test-python.nix ({ pkgs, lib, ...} :
+
let
+
wg-snakeoil-keys = import ./snakeoil-keys.nix;
+
peer = (import ./make-peer.nix) { inherit lib; };
+
in
+
{
+
name = "wireguard";
+
meta = with pkgs.stdenv.lib.maintainers; {
+
maintainers = [ ma27 ];
+
};
+
+
nodes = {
+
peer0 = peer {
+
ip4 = "192.168.0.1";
+
ip6 = "fd00::1";
+
extraConfig = {
+
boot = lib.mkIf (kernelPackages != null) { inherit kernelPackages; };
+
networking.firewall.allowedUDPPorts = [ 23542 ];
+
networking.wireguard.interfaces.wg0 = {
+
ips = [ "10.23.42.1/32" "fc00::1/128" ];
+
listenPort = 23542;
+
+
inherit (wg-snakeoil-keys.peer0) privateKey;
+
+
peers = lib.singleton {
+
allowedIPs = [ "10.23.42.2/32" "fc00::2/128" ];
+
+
inherit (wg-snakeoil-keys.peer1) publicKey;
+
};
+
};
+
};
+
};
+
+
peer1 = peer {
+
ip4 = "192.168.0.2";
+
ip6 = "fd00::2";
+
extraConfig = {
+
boot = lib.mkIf (kernelPackages != null) { inherit kernelPackages; };
+
networking.wireguard.interfaces.wg0 = {
+
ips = [ "10.23.42.2/32" "fc00::2/128" ];
+
listenPort = 23542;
+
allowedIPsAsRoutes = false;
+
+
inherit (wg-snakeoil-keys.peer1) privateKey;
+
+
peers = lib.singleton {
+
allowedIPs = [ "0.0.0.0/0" "::/0" ];
+
endpoint = "192.168.0.1:23542";
+
persistentKeepalive = 25;
+
+
inherit (wg-snakeoil-keys.peer0) publicKey;
+
};
+
+
postSetup = let inherit (pkgs) iproute; in ''
+
${iproute}/bin/ip route replace 10.23.42.1/32 dev wg0
+
${iproute}/bin/ip route replace fc00::1/128 dev wg0
+
'';
+
};
+
};
+
};
+
};
+
+
testScript = ''
+
start_all()
+
+
peer0.wait_for_unit("wireguard-wg0.service")
+
peer1.wait_for_unit("wireguard-wg0.service")
+
+
peer1.succeed("ping -c5 fc00::1")
+
peer1.succeed("ping -c5 10.23.42.1")
+
'';
+
}
+
)
+23 -67
nixos/tests/wireguard/default.nix
···
-
import ../make-test-python.nix ({ pkgs, lib, ...} :
-
let
-
wg-snakeoil-keys = import ./snakeoil-keys.nix;
-
peer = (import ./make-peer.nix) { inherit lib; };
-
in
-
{
-
name = "wireguard";
-
meta = with pkgs.stdenv.lib.maintainers; {
-
maintainers = [ ma27 ];
-
};
-
-
nodes = {
-
peer0 = peer {
-
ip4 = "192.168.0.1";
-
ip6 = "fd00::1";
-
extraConfig = {
-
networking.firewall.allowedUDPPorts = [ 23542 ];
-
networking.wireguard.interfaces.wg0 = {
-
ips = [ "10.23.42.1/32" "fc00::1/128" ];
-
listenPort = 23542;
-
-
inherit (wg-snakeoil-keys.peer0) privateKey;
-
-
peers = lib.singleton {
-
allowedIPs = [ "10.23.42.2/32" "fc00::2/128" ];
-
-
inherit (wg-snakeoil-keys.peer1) publicKey;
-
};
-
};
-
};
-
};
-
-
peer1 = peer {
-
ip4 = "192.168.0.2";
-
ip6 = "fd00::2";
-
extraConfig = {
-
networking.wireguard.interfaces.wg0 = {
-
ips = [ "10.23.42.2/32" "fc00::2/128" ];
-
listenPort = 23542;
-
allowedIPsAsRoutes = false;
-
-
inherit (wg-snakeoil-keys.peer1) privateKey;
-
-
peers = lib.singleton {
-
allowedIPs = [ "0.0.0.0/0" "::/0" ];
-
endpoint = "192.168.0.1:23542";
-
persistentKeepalive = 25;
-
inherit (wg-snakeoil-keys.peer0) publicKey;
-
};
-
postSetup = let inherit (pkgs) iproute; in ''
-
${iproute}/bin/ip route replace 10.23.42.1/32 dev wg0
-
${iproute}/bin/ip route replace fc00::1/128 dev wg0
-
'';
-
};
-
};
-
};
-
};
-
testScript = ''
-
start_all()
-
-
peer0.wait_for_unit("wireguard-wg0.service")
-
peer1.wait_for_unit("wireguard-wg0.service")
-
-
peer1.succeed("ping -c5 fc00::1")
-
peer1.succeed("ping -c5 10.23.42.1")
-
'';
-
}
)
···
+
{ system ? builtins.currentSystem
+
, config ? { }
+
, pkgs ? import ../../.. { inherit system config; }
+
, kernelVersionsToTest ? [ "5.4" "latest" ]
+
}:
+
with pkgs.lib;
+
let
+
tests = let callTest = p: flip (import p) { inherit system pkgs; }; in {
+
basic = callTest ./basic.nix;
+
namespaces = callTest ./namespaces.nix;
+
wg-quick = callTest ./wg-quick.nix;
+
generated = callTest ./generated.nix;
+
};
+
in
+
listToAttrs (
+
flip concatMap kernelVersionsToTest (version:
+
let
+
v' = replaceStrings [ "." ] [ "_" ] version;
+
in
+
flip mapAttrsToList tests (name: test:
+
nameValuePair "wireguard-${name}-linux-${v'}" (test { kernelPackages = pkgs."linuxPackages_${v'}"; })
+
)
+
)
)
+4 -1
nixos/tests/wireguard/generated.nix
···
-
import ../make-test-python.nix ({ pkgs, ...} : {
name = "wireguard-generated";
meta = with pkgs.stdenv.lib.maintainers; {
maintainers = [ ma27 grahamc ];
···
nodes = {
peer1 = {
networking.firewall.allowedUDPPorts = [ 12345 ];
networking.wireguard.interfaces.wg0 = {
ips = [ "10.10.10.1/24" ];
···
};
peer2 = {
networking.firewall.allowedUDPPorts = [ 12345 ];
networking.wireguard.interfaces.wg0 = {
ips = [ "10.10.10.2/24" ];
···
+
{ kernelPackages ? null }:
+
import ../make-test-python.nix ({ pkgs, lib, ... } : {
name = "wireguard-generated";
meta = with pkgs.stdenv.lib.maintainers; {
maintainers = [ ma27 grahamc ];
···
nodes = {
peer1 = {
+
boot = lib.mkIf (kernelPackages != null) { inherit kernelPackages; };
networking.firewall.allowedUDPPorts = [ 12345 ];
networking.wireguard.interfaces.wg0 = {
ips = [ "10.10.10.1/24" ];
···
};
peer2 = {
+
boot = lib.mkIf (kernelPackages != null) { inherit kernelPackages; };
networking.firewall.allowedUDPPorts = [ 12345 ];
networking.wireguard.interfaces.wg0 = {
ips = [ "10.10.10.2/24" ];
+7 -1
nixos/tests/wireguard/namespaces.nix
···
let
listenPort = 12345;
socketNamespace = "foo";
···
in
-
import ../make-test-python.nix ({ pkgs, ...} : {
name = "wireguard-with-namespaces";
meta = with pkgs.stdenv.lib.maintainers; {
maintainers = [ asymmetric ];
···
# interface should be created in the socketNamespace
# and not moved from there
peer0 = pkgs.lib.attrsets.recursiveUpdate node {
networking.wireguard.interfaces.wg0 = {
preSetup = ''
ip netns add ${socketNamespace}
···
# interface should be created in the init namespace
# and moved to the interfaceNamespace
peer1 = pkgs.lib.attrsets.recursiveUpdate node {
networking.wireguard.interfaces.wg0 = {
preSetup = ''
ip netns add ${interfaceNamespace}
···
# interface should be created in the socketNamespace
# and moved to the interfaceNamespace
peer2 = pkgs.lib.attrsets.recursiveUpdate node {
networking.wireguard.interfaces.wg0 = {
preSetup = ''
ip netns add ${socketNamespace}
···
# interface should be created in the socketNamespace
# and moved to the init namespace
peer3 = pkgs.lib.attrsets.recursiveUpdate node {
networking.wireguard.interfaces.wg0 = {
preSetup = ''
ip netns add ${socketNamespace}
···
+
{ kernelPackages ? null }:
+
let
listenPort = 12345;
socketNamespace = "foo";
···
in
+
import ../make-test-python.nix ({ pkgs, lib, ... } : {
name = "wireguard-with-namespaces";
meta = with pkgs.stdenv.lib.maintainers; {
maintainers = [ asymmetric ];
···
# interface should be created in the socketNamespace
# and not moved from there
peer0 = pkgs.lib.attrsets.recursiveUpdate node {
+
boot = lib.mkIf (kernelPackages != null) { inherit kernelPackages; };
networking.wireguard.interfaces.wg0 = {
preSetup = ''
ip netns add ${socketNamespace}
···
# interface should be created in the init namespace
# and moved to the interfaceNamespace
peer1 = pkgs.lib.attrsets.recursiveUpdate node {
+
boot = lib.mkIf (kernelPackages != null) { inherit kernelPackages; };
networking.wireguard.interfaces.wg0 = {
preSetup = ''
ip netns add ${interfaceNamespace}
···
# interface should be created in the socketNamespace
# and moved to the interfaceNamespace
peer2 = pkgs.lib.attrsets.recursiveUpdate node {
+
boot = lib.mkIf (kernelPackages != null) { inherit kernelPackages; };
networking.wireguard.interfaces.wg0 = {
preSetup = ''
ip netns add ${socketNamespace}
···
# interface should be created in the socketNamespace
# and moved to the init namespace
peer3 = pkgs.lib.attrsets.recursiveUpdate node {
+
boot = lib.mkIf (kernelPackages != null) { inherit kernelPackages; };
networking.wireguard.interfaces.wg0 = {
preSetup = ''
ip netns add ${socketNamespace}
+4
nixos/tests/wireguard/wg-quick.nix
···
import ../make-test-python.nix ({ pkgs, lib, ... }:
let
wg-snakeoil-keys = import ./snakeoil-keys.nix;
···
ip4 = "192.168.0.1";
ip6 = "fd00::1";
extraConfig = {
networking.firewall.allowedUDPPorts = [ 23542 ];
networking.wg-quick.interfaces.wg0 = {
address = [ "10.23.42.1/32" "fc00::1/128" ];
···
ip4 = "192.168.0.2";
ip6 = "fd00::2";
extraConfig = {
networking.wg-quick.interfaces.wg0 = {
address = [ "10.23.42.2/32" "fc00::2/128" ];
inherit (wg-snakeoil-keys.peer1) privateKey;
···
+
{ kernelPackages ? null }:
+
import ../make-test-python.nix ({ pkgs, lib, ... }:
let
wg-snakeoil-keys = import ./snakeoil-keys.nix;
···
ip4 = "192.168.0.1";
ip6 = "fd00::1";
extraConfig = {
+
boot = lib.mkIf (kernelPackages != null) { inherit kernelPackages; };
networking.firewall.allowedUDPPorts = [ 23542 ];
networking.wg-quick.interfaces.wg0 = {
address = [ "10.23.42.1/32" "fc00::1/128" ];
···
ip4 = "192.168.0.2";
ip6 = "fd00::2";
extraConfig = {
+
boot = lib.mkIf (kernelPackages != null) { inherit kernelPackages; };
networking.wg-quick.interfaces.wg0 = {
address = [ "10.23.42.2/32" "fc00::2/128" ];
inherit (wg-snakeoil-keys.peer1) privateKey;
+1 -3
pkgs/tools/networking/wireguard-tools/default.nix
···
passthru = {
updateScript = ./update.sh;
-
tests = {
-
inherit (nixosTests) wireguard wg-quick wireguard-generated wireguard-namespaces;
-
};
};
meta = {
···
passthru = {
updateScript = ./update.sh;
+
tests = nixosTests.wireguard;
};
meta = {