feat: initial wipe implementation - block device safety, HDD overwrite, NVMe/secure-discard, verification
This commit is contained in:
Executable
+118
@@ -0,0 +1,118 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
export PATH="$HOME/.cargo/bin:$PATH"
|
||||
|
||||
# Loop device integration test per spec #40
|
||||
# Creates 128 MiB image, attaches loop device, writes marker, wipes, verifies
|
||||
|
||||
set -x
|
||||
|
||||
IMAGE_SIZE_MB=128
|
||||
IMAGE_FILE=$(mktemp /tmp/wipe-test-XXXX.img)
|
||||
LOOP_DEV=""
|
||||
|
||||
cleanup() {
|
||||
set +e
|
||||
echo "Cleaning up..."
|
||||
if mount | grep -q "$LOOP_DEV" 2>/dev/null; then
|
||||
umount "$LOOP_DEV" 2>/dev/null || true
|
||||
fi
|
||||
# Check for mounted filesystems on loop device partitions
|
||||
if [ -n "$LOOP_DEV" ]; then
|
||||
# Unmount any partitions?
|
||||
for mp in $(lsblk -ln -o MOUNTPOINTS "$LOOP_DEV" 2>/dev/null | grep -v "^$" || true); do
|
||||
umount "$mp" 2>/dev/null || true
|
||||
done
|
||||
losetup -d "$LOOP_DEV" 2>/dev/null || true
|
||||
fi
|
||||
rm -f "$IMAGE_FILE"
|
||||
# Also cleanup any leftover loop devices attached to our image
|
||||
losetup -j "$IMAGE_FILE" 2>/dev/null | cut -d: -f1 | xargs -r losetup -d 2>/dev/null || true
|
||||
echo "Cleanup done"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
echo "Creating ${IMAGE_SIZE_MB}MiB image at $IMAGE_FILE"
|
||||
dd if=/dev/zero of="$IMAGE_FILE" bs=1M count="$IMAGE_SIZE_MB" status=none
|
||||
|
||||
echo "Attaching loop device"
|
||||
LOOP_DEV=$(losetup --find --show "$IMAGE_FILE")
|
||||
echo "Loop device: $LOOP_DEV"
|
||||
|
||||
if [ ! -b "$LOOP_DEV" ]; then
|
||||
echo "Failed to create loop device"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Verify block device
|
||||
if [ ! -b "$LOOP_DEV" ]; then
|
||||
echo "Not a block device: $LOOP_DEV"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Create filesystem and mount to test mount detection
|
||||
echo "Creating ext4 filesystem on $LOOP_DEV"
|
||||
mkfs.ext4 -F "$LOOP_DEV" >/dev/null 2>&1
|
||||
|
||||
MNT_DIR=$(mktemp -d /tmp/wipe-mnt-XXXX)
|
||||
echo "Mounting $LOOP_DEV to $MNT_DIR"
|
||||
mount "$LOOP_DEV" "$MNT_DIR"
|
||||
|
||||
echo "Writing marker data"
|
||||
echo "WIPE_TEST_MARKER_$(date +%s)" > "$MNT_DIR/marker.txt"
|
||||
echo "Additional data" >> "$MNT_DIR/marker.txt"
|
||||
dd if=/dev/urandom of="$MNT_DIR/random.dat" bs=1K count=100 status=none 2>/dev/null || true
|
||||
sync
|
||||
|
||||
echo "Unmounting before wipe"
|
||||
umount "$MNT_DIR"
|
||||
rmdir "$MNT_DIR"
|
||||
|
||||
# Ensure device is not mounted
|
||||
if mount | grep -q "$LOOP_DEV"; then
|
||||
echo "Device still mounted after umount"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Build wipe binary if not exists
|
||||
if [ ! -x "target/release/wipe" ]; then
|
||||
echo "Building wipe release binary"
|
||||
cargo build --release
|
||||
fi
|
||||
|
||||
echo "Running wipe zero on $LOOP_DEV"
|
||||
# For loop device, it is considered whole-disk, need --whole-disk
|
||||
# Use buffer size small for speed
|
||||
set +e
|
||||
sudo target/release/wipe "$LOOP_DEV" --whole-disk --method zero --yes --buffer-size 4M --verbose
|
||||
WIPE_EXIT=$?
|
||||
set -e
|
||||
|
||||
if [ $WIPE_EXIT -ne 0 ]; then
|
||||
echo "wipe failed with exit $WIPE_EXIT"
|
||||
# If it's loop device and fails due to safety, try with --force? But loop should not be system device
|
||||
echo "STDOUT/STDERR from wipe:"
|
||||
sudo target/release/wipe "$LOOP_DEV" --whole-disk --method zero --yes --buffer-size 4M --dry-run || true
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "Verifying zero"
|
||||
# Read first 1M and check all zeros using od -v to avoid compression
|
||||
if dd if="$LOOP_DEV" bs=1M count=1 status=none 2>/dev/null | od -An -v -t x1 | tr -d ' \n' | grep -q -v "^00*$"; then
|
||||
echo "Verification failed: device not zeroed"
|
||||
exit 1
|
||||
else
|
||||
echo "First 1M is all zeros: PASS"
|
||||
fi
|
||||
|
||||
# Full verify using our --verify flag: wipe again with verify
|
||||
echo "Testing wipe with --verify"
|
||||
# Re-create marker
|
||||
echo "marker" | dd of="$LOOP_DEV" bs=1K count=1 status=none 2>/dev/null || true
|
||||
sync
|
||||
sudo target/release/wipe "$LOOP_DEV" --whole-disk --method zero --yes --buffer-size 4M --verify
|
||||
echo "Verify wipe passed"
|
||||
|
||||
echo "Loop integration test PASSED"
|
||||
echo "Device: $LOOP_DEV"
|
||||
echo "Image: $IMAGE_FILE"
|
||||
Reference in New Issue
Block a user