Files
mesh-catalog/modules/postgres/cmd/postgres-provider/live_test.go
T
jochen e68ef88333 Retire a consumer the mesh stops asking for, and delete only on a person's word (hq ADR 0230)
The hourly release of ADR 0229's brake still ended in the mesh acting alone on
a mistake. A consumer now stays active until the same unasked set holds for
five passes, waits for a person past three or half of those held, is disabled
and marked rather than withdrawn, comes back as it was when asked again, and is
deleted only through the provider's delete tool. The backend keeps the mark, so
a restart forgets nothing and finds what was withdrawn before.
2026-10-06 13:54:10 +02:00

164 lines
5.8 KiB
Go

package main
// Against a real server, when one is named — skipped otherwise. A throwaway one:
//
// docker run -d --rm --name pg-test -e POSTGRES_PASSWORD=admin -p 55432:5432 pgvector/pgvector:pg17
// MESH_POSTGRES_LIVE=postgres://postgres:admin@127.0.0.1:55432/postgres?sslmode=disable go test ./...
//
// It proves what the fakes cannot: an untrusted extension is installed by the superuser in a fresh
// consumer database and a second pass is a no-op; the consumer then holds; a retired login cannot
// log in, its data is still there and the backend lists it retired with when and why; asked for again
// it is enabled as it was; only a deletion drops it, and only it; the reader cannot write, even past a
// COMMIT (novox/hq ADR 0230).
import (
"net/url"
"os"
"testing"
"time"
)
func TestLive(t *testing.T) {
raw := os.Getenv("MESH_POSTGRES_LIVE")
if raw == "" {
t.Skip("MESH_POSTGRES_LIVE names no server")
}
u, _ := url.Parse(raw)
pw, _ := u.User.Password()
env := map[string]string{"MESH_PROVISION_POSTGRES": raw, "MESH_POSTGRES_PASSWORD": pw, "MESH_POSTGRES_READER_PASSWORD": "reader-pw"}
c, err := ClientFromEnv(func(k string) string { return env[k] })
if err != nil {
t.Fatal(err)
}
a := provisioner{pg: c, announce: func(string, map[string]string) {}}
p := Provision{As: "mesh_test_letta", Password: "consumer-pw", Values: map[string]any{"name": "letta", "extensions": []any{"vector"}}}
// vector is not trusted: the consumer cannot install it itself.
if err := c.CreateDatabaseAndRole(ctx, p.As, p.As, p.Password); err != nil {
t.Fatal(err)
}
if _, err := c.as(ctx, Login{Database: p.As, User: p.As, Password: p.Password}, "CREATE EXTENSION IF NOT EXISTS vector"); err == nil {
t.Log("note: the consumer could install vector itself on this server")
}
for pass := 0; pass < 2; pass++ {
if err := a.Create(ctx, p); err != nil {
t.Fatalf("pass %d: %v", pass, err)
}
}
if ok, err := a.Holds(ctx, p); err != nil || !ok {
t.Fatal("not held after create:", ok, err)
}
if _, err := c.as(ctx, Login{Database: p.As, User: p.As, Password: p.Password},
"CREATE TABLE IF NOT EXISTS kept (v vector(3)); INSERT INTO kept VALUES ('[1,2,3]')"); err != nil {
t.Fatal("the consumer cannot use the type:", err)
}
bad := p
bad.Values = map[string]any{"extensions": []any{"no_such_extension"}}
if err := a.Create(ctx, bad); err == nil {
t.Fatal("an unknown extension was accepted")
}
r, err := c.ReadOnlyQuery(ctx, p.As, "COMMIT; DROP TABLE kept")
if err == nil {
t.Fatalf("the reader dropped a table: %+v", r)
}
r, err = c.ReadOnlyQuery(ctx, p.As, "SELECT count(*) AS n FROM kept")
if err != nil || r.Maps()[0]["n"] == nil {
t.Fatal(r, err)
}
// A neighbour that must survive everything below untouched.
other := Provision{As: "mesh_test_other", Password: "other-pw"}
if err := a.Create(ctx, other); err != nil {
t.Fatal(err)
}
defer c.DeleteRetired(ctx, Retired{Consumer: other.As}) //nolint — best effort, after a retire below
at := time.Date(2026, 10, 6, 12, 0, 0, 0, time.UTC)
if err := a.Retire(ctx, p.As, nil, "the mesh stopped asking for it", at); err != nil {
t.Fatal(err)
}
if ok, err := a.Holds(ctx, p); err != nil || ok {
t.Fatal("a retired login still logs in:", ok, err)
}
r, err = c.Query(ctx, p.As, "SELECT count(*) FROM kept")
if err != nil || len(r.Rows) != 1 || cell(r.Rows[0], 0) != "1" {
t.Fatal("retiring lost the data:", r, err)
}
inv, err := a.Inventory(ctx)
if err != nil {
t.Fatal(err)
}
var found *Retired
for i := range inv.Retired {
if inv.Retired[i].Consumer == p.As {
found = &inv.Retired[i]
}
}
if found == nil || !found.RetiredAt.Equal(at) || found.Why != "the mesh stopped asking for it" || found.SizeBytes <= 0 {
t.Fatalf("not listed retired with when, why and size: %+v", inv)
}
if !listHas(inv.Active, other.As) || listHas(inv.Active, p.As) {
t.Fatalf("%+v", inv)
}
// An active consumer is never deleted, whatever is asked.
if _, err := c.DeleteRetired(ctx, Retired{Consumer: other.As}); err == nil {
t.Fatal("deleted an active consumer")
}
// Asked for again: the same database, the same rows, the mark active.
if err := a.Create(ctx, p); err != nil {
t.Fatal(err)
}
if ok, _ := a.Holds(ctx, p); !ok {
t.Fatal("not held after coming back")
}
if r, err := c.as(ctx, Login{Database: p.As, User: p.As, Password: p.Password}, "SELECT count(*) FROM kept"); err != nil ||
cell(r.Rows[0], 0) != "1" {
t.Fatal("re-enabled without its data:", err)
}
if inv, _ := a.Inventory(ctx); !listHas(inv.Active, p.As) {
t.Fatalf("not active again: %+v", inv)
}
// Retired again and deleted: that database and role go; the neighbour stays.
if err := a.Retire(ctx, p.As, nil, "again", at); err != nil {
t.Fatal(err)
}
freed, err := a.Delete(ctx, Retired{Consumer: p.As, Kind: KindConsumer})
if err != nil || freed <= 0 {
t.Fatal(freed, err)
}
if has, _ := c.exists(ctx, "SELECT 1 FROM pg_database WHERE datname = "+Literal(p.As)); has {
t.Fatal("the database is still there")
}
if has, _ := c.exists(ctx, "SELECT 1 FROM pg_roles WHERE rolname = "+Literal(p.As)); has {
t.Fatal("the role is still there")
}
if ok, err := a.Holds(ctx, other); err != nil || !ok {
t.Fatal("the neighbour was touched:", ok, err)
}
// A database set aside by hand is listed since its date and can be deleted, alone.
aside, err := c.RetireDatabase(ctx, other.As, at)
if err != nil {
t.Fatal(err)
}
inv, _ = a.Inventory(ctx)
var setAside *Retired
for i := range inv.Retired {
if inv.Retired[i].Consumer == aside {
setAside = &inv.Retired[i]
}
}
if setAside == nil || setAside.Kind != KindSetAside || setAside.RetiredAt.Format("20060102") != "20261006" {
t.Fatalf("%+v", inv.Retired)
}
if _, err := a.Delete(ctx, *setAside); err != nil {
t.Fatal(err)
}
if has, _ := c.exists(ctx, "SELECT 1 FROM pg_database WHERE datname = "+Literal(aside)); has {
t.Fatal("the set-aside database is still there")
}
}