mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-22 07:48:26 +00:00
New testing/boringtun/ harness runs two Cloudflare BoringTun userspace WireGuard containers with iperf3 between them, giving a single-hop userspace tunnel baseline for comparison against FIPS throughput numbers. Local WG key generation runs through the harness image so the host needs no wireguard-tools. New testing/static/scripts/iperf-compare-refs.sh builds two git refs into separate fips-test:* images via git worktree and runs the same static iperf topology against both, with RUNS-based repetition and aggregate avg/min/max reporting. testing/static/scripts/iperf-test.sh gains DURATION, PARALLEL, SETTLE_SECONDS, IPERF_TIMEOUT env knobs and a per-path iperf timeout. testing/static/docker-compose.yml selects the image under test via FIPS_TEST_IMAGE; testing/scripts/build.sh respects CARGO_TARGET_DIR. Author benchmark on aarch64 Docker Desktop: boringtun bob -> alice : 1000.13 Mbits/sec
26 lines
878 B
Bash
Executable File
26 lines
878 B
Bash
Executable File
#!/bin/bash
|
|
# End-to-end iperf3 bandwidth test between two boringtun containers.
|
|
# Output mirrors testing/static/scripts/iperf-test.sh so the FIPS
|
|
# numbers are directly comparable.
|
|
set -euo pipefail
|
|
|
|
DURATION="${DURATION:-10}"
|
|
PARALLEL="${PARALLEL:-1}"
|
|
|
|
echo "=== boringtun iperf3 throughput (single TCP stream, ${DURATION}s) ==="
|
|
|
|
# Run iperf3 server on alice (background), client on bob.
|
|
docker exec -d bt-alice iperf3 -s -1 -B 10.99.0.1 -p 5201
|
|
sleep 1
|
|
|
|
# wait for tun handshake to settle (boringtun + WG keepalive)
|
|
sleep 2
|
|
|
|
# Client: bob → alice over WG (10.99.0.1)
|
|
OUT=$(docker exec bt-bob iperf3 -c 10.99.0.1 -p 5201 -t "$DURATION" -P "$PARALLEL" -J)
|
|
|
|
# Pull SUM bps.
|
|
MBPS=$(echo "$OUT" | python3 -c "import json,sys; d=json.load(sys.stdin); print(f\"{d['end']['sum_received']['bits_per_second'] / 1_000_000:.2f}\")")
|
|
|
|
echo "boringtun bob -> alice : ${MBPS} Mbits/sec"
|