package main // Against a real server, when one is named — skipped otherwise. A throwaway one: // // docker run -d --rm --name pg-test -e POSTGRES_PASSWORD=admin -p 55432:5432 pgvector/pgvector:pg17 // MESH_POSTGRES_LIVE=postgres://postgres:admin@127.0.0.1:55432/postgres?sslmode=disable go test ./... // // It proves what the fakes cannot: an untrusted extension is installed by the superuser in a fresh // consumer database and a second pass is a no-op; the consumer then holds; a withdrawn login cannot // log in and its data is still there; the reader cannot write, even past a COMMIT. import ( "net/url" "os" "testing" ) func TestLive(t *testing.T) { raw := os.Getenv("MESH_POSTGRES_LIVE") if raw == "" { t.Skip("MESH_POSTGRES_LIVE names no server") } u, _ := url.Parse(raw) pw, _ := u.User.Password() env := map[string]string{"MESH_PROVISION_POSTGRES": raw, "MESH_POSTGRES_PASSWORD": pw, "MESH_POSTGRES_READER_PASSWORD": "reader-pw"} c, err := ClientFromEnv(func(k string) string { return env[k] }) if err != nil { t.Fatal(err) } a := provisioner{pg: c, announce: func(string, map[string]string) {}} p := Provision{As: "mesh_test_letta", Password: "consumer-pw", Values: map[string]any{"name": "letta", "extensions": []any{"vector"}}} // vector is not trusted: the consumer cannot install it itself. if err := c.CreateDatabaseAndRole(ctx, p.As, p.As, p.Password); err != nil { t.Fatal(err) } if _, err := c.as(ctx, Login{Database: p.As, User: p.As, Password: p.Password}, "CREATE EXTENSION IF NOT EXISTS vector"); err == nil { t.Log("note: the consumer could install vector itself on this server") } for pass := 0; pass < 2; pass++ { if err := a.Create(ctx, p); err != nil { t.Fatalf("pass %d: %v", pass, err) } } if ok, err := a.Holds(ctx, p); err != nil || !ok { t.Fatal("not held after create:", ok, err) } if _, err := c.as(ctx, Login{Database: p.As, User: p.As, Password: p.Password}, "CREATE TABLE IF NOT EXISTS kept (v vector(3)); INSERT INTO kept VALUES ('[1,2,3]')"); err != nil { t.Fatal("the consumer cannot use the type:", err) } bad := p bad.Values = map[string]any{"extensions": []any{"no_such_extension"}} if err := a.Create(ctx, bad); err == nil { t.Fatal("an unknown extension was accepted") } r, err := c.ReadOnlyQuery(ctx, p.As, "COMMIT; DROP TABLE kept") if err == nil { t.Fatalf("the reader dropped a table: %+v", r) } r, err = c.ReadOnlyQuery(ctx, p.As, "SELECT count(*) AS n FROM kept") if err != nil || r.Maps()[0]["n"] == nil { t.Fatal(r, err) } if err := a.Remove(ctx, p.As, nil); err != nil { t.Fatal(err) } if ok, err := a.Holds(ctx, p); err != nil || ok { t.Fatal("a withdrawn login still logs in:", ok, err) } r, err = c.Query(ctx, p.As, "SELECT count(*) FROM kept") if err != nil || len(r.Rows) != 1 { t.Fatal("withdrawing lost the data:", err) } // Coming back is given the same database. if err := a.Create(ctx, p); err != nil { t.Fatal(err) } if ok, _ := a.Holds(ctx, p); !ok { t.Fatal("not held after coming back") } }