feat: implement C.4 — hermetic container e2e gate + native release build

Separate test/e2e Go module drives the shipped deploy/docker-compose.yml
(plus a test-only override: self-signed cert, low ports, isolated compose
project) against a fake DNS zone (CoreDNS) and an smtp-sink MX, exactly as
an administrator and their applications would over HTTP/SMTP — covering the
class of failure unit tests can't see (container wiring). Positive path:
setup -> login -> domain -> DKIM record published into the fake zone ->
application -> SMTP AUTH send -> DKIM verified against the DNS-published
key -> send-log queued->sent. Negative: no-AUTH/unauthenticated relay,
sender/login mismatch, L1 (anvil) and L2 (panel) rate limits, journal-milter
fail-open, SELFPOST_HOSTNAME gate, session survives docker restart.

release.yml moves off qemu to a native per-arch build (amd64/arm64), each
gated by this suite before its tag is pushed and merged into the version
manifest.

Verified green on selfpost.mixfed.ru via `make e2e`; go vet/gofmt clean in
both modules.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-03 00:29:14 +03:00
parent 3b0a71cf11
commit c8b067a686
21 changed files with 1674 additions and 17 deletions
+86
View File
@@ -0,0 +1,86 @@
package e2e
import (
"crypto/rand"
"crypto/rsa"
"crypto/x509"
"crypto/x509/pkix"
"encoding/pem"
"fmt"
"math/big"
"os"
"path/filepath"
"time"
)
// selfpostHostname is SELFPOST_HOSTNAME for the whole e2e stand: the
// certificate's CN/SAN, the panel's SASL realm and Postfix's myhostname/HELO
// all have to agree on it (plan B.3), so it is defined once here.
const selfpostHostname = "mail.e2e.test"
// prepareStage (re)creates the scratch directory compose.override.yml mounts
// everything from: /data, the TLS cert Postfix serves on 465, the DNS zone
// CoreDNS is authoritative for, and the sink-MX's dump directory. Called once
// per run before `docker compose up`, so every run starts from a clean slate.
func prepareStage(s *stack) error {
if err := os.RemoveAll(s.stageDir); err != nil {
return fmt.Errorf("clean stage dir: %w", err)
}
dirs := []string{"data", "certs", "dns-stage", "mail-stage"}
for _, d := range dirs {
if err := os.MkdirAll(filepath.Join(s.stageDir, d), 0o755); err != nil {
return fmt.Errorf("mkdir %s: %w", d, err)
}
}
if err := writeSelfSignedCert(
filepath.Join(s.stageDir, "certs", "fullchain.pem"),
filepath.Join(s.stageDir, "certs", "privkey.pem"),
); err != nil {
return err
}
corefile, err := os.ReadFile(filepath.Join("dns", "Corefile"))
if err != nil {
return fmt.Errorf("read Corefile: %w", err)
}
if err := os.WriteFile(filepath.Join(s.stageDir, "dns-stage", "Corefile"), corefile, 0o644); err != nil {
return fmt.Errorf("write Corefile: %w", err)
}
return writeZone(s.stageDir, nil)
}
// writeSelfSignedCert generates a throwaway RSA key + self-signed certificate
// for selfpostHostname, valid for a day — this stand never outlives that.
// Postfix's smtpd_tls_security_level is "may" (opportunistic), not enforced,
// so the e2e SMTP client simply skips verification of it (plan C.4: "test
// dependencies... zero new dependencies" — no need for a real CA here).
func writeSelfSignedCert(certPath, keyPath string) error {
key, err := rsa.GenerateKey(rand.Reader, 2048)
if err != nil {
return fmt.Errorf("generate TLS key: %w", err)
}
serial, err := rand.Int(rand.Reader, new(big.Int).Lsh(big.NewInt(1), 128))
if err != nil {
return err
}
tmpl := &x509.Certificate{
SerialNumber: serial,
Subject: pkix.Name{CommonName: selfpostHostname},
DNSNames: []string{selfpostHostname},
NotBefore: time.Now().Add(-time.Hour),
NotAfter: time.Now().Add(24 * time.Hour),
KeyUsage: x509.KeyUsageKeyEncipherment | x509.KeyUsageDigitalSignature | x509.KeyUsageCertSign,
ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth},
BasicConstraintsValid: true,
IsCA: true,
}
der, err := x509.CreateCertificate(rand.Reader, tmpl, tmpl, &key.PublicKey, key)
if err != nil {
return fmt.Errorf("create certificate: %w", err)
}
certPEM := pem.EncodeToMemory(&pem.Block{Type: "CERTIFICATE", Bytes: der})
if err := os.WriteFile(certPath, certPEM, 0o644); err != nil {
return err
}
keyPEM := pem.EncodeToMemory(&pem.Block{Type: "RSA PRIVATE KEY", Bytes: x509.MarshalPKCS1PrivateKey(key)})
return os.WriteFile(keyPath, keyPEM, 0o600)
}