Record whether a node is adopted and which modules were taken on it (hq ADR 0100)

This commit is contained in:
2026-09-22 17:14:05 +02:00
parent 0a39b7df82
commit 1c32af6a22
13 changed files with 559 additions and 46 deletions
+5
View File
@@ -50,6 +50,11 @@ type Token struct {
// Secret is the one-time right to join. Useless once used, useless after it expires.
Secret string `json:"secret"`
// Adopted says the node joins adopted (novox/hq ADR 0100): the host checks, before enrolling,
// that it speaks the firewall found on the machine, because an adopted node keeps that firewall
// in force. Absent for a converged node, so a converged token is byte for byte what it was.
Adopted bool `json:"adopted,omitempty"`
}
// Missing names the parts that are not filled in.
+16
View File
@@ -140,6 +140,22 @@ func TestTheWireFormatIsExactlyTheseFieldNames(t *testing.T) {
if len(fields) != 6 {
t.Errorf("the token has %d fields, expected 6: %v", len(fields), fields)
}
// An adopted node's token says so, under exactly this name, and a converged one does not
// carry it at all (novox/hq ADR 0100).
adopted := complete(t)
adopted.Adopted = true
raw, err = json.Marshal(adopted)
if err != nil {
t.Fatal(err)
}
fields = nil
if err := json.Unmarshal(raw, &fields); err != nil {
t.Fatal(err)
}
if fields["adopted"] != true || len(fields) != 7 {
t.Errorf("an adopted token does not carry \"adopted\": true: %v", fields)
}
}
func TestATokenWithNoNameIsRefused(t *testing.T) {