Test the licence store, and name an unknown licence rather than a constraint
Its own store, its own test database, the same shape every other context has. Five properties: a key with nobody to seal it to is refused rather than kept readably; a key is sealed once per holder and the blobs differ because they are sealed to different machines; a holder recorded afterwards has none and the existing ones keep theirs; releasing a consumer takes its key; and a licence nobody recorded is refused by name. The last was the only one whose message mattered and whose message was not checked — the database's own foreign-key error is true and mentions a constraint, which sends somebody to read a schema instead of typing the name they meant. Partial sealing now says how far it got. The person holding the key is the only one who can finish, and running it again knowing what it will do is different from running it hoping.
This commit is contained in:
@@ -204,6 +204,15 @@ func licenceKey(ctx context.Context, args []string) error {
|
||||
return inv.SealingKeyOf(ctx, node)
|
||||
})
|
||||
if err != nil {
|
||||
if sealed > 0 {
|
||||
// Some holders got it and some did not, and the person holding the key is the only
|
||||
// one who can finish the job. Saying how far it got is the difference between running
|
||||
// this again knowing what it will do and running it hoping.
|
||||
return fmt.Errorf(
|
||||
"%w\n\n%d holder(s) were sealed before this. Running `licence key %s` again "+
|
||||
"with the same key seals the rest and changes nothing for those already done",
|
||||
err, sealed, name)
|
||||
}
|
||||
return err
|
||||
}
|
||||
// Not echoed back, ever. What is stored is unreadable by whoever holds it, the mesh included,
|
||||
|
||||
Reference in New Issue
Block a user