A grant secret belongs to whoever provisions, and the sweep skips what it will not address
Issue 225. The mesh seals one credential per consumer beside the provider's contributions file, and wrote it root-owned. That was right while a module's own code ran in a container as root; ADR 0198 moved that code under the node's runtime, as the node's account, and the secret stayed root's. On the control machine two consumers went unprovisioned for three hours and the only sign was a line reading 'secret not readable yet', 4330 times. The same sentence is already written for a module's own secrets a few hundred lines above — 'a root-owned 0600 file is one that process cannot read'. This is that rule reaching the other kind of secret the mesh writes for a module. Issue 226. The sweep met a reference recorded with the store's old address, read 'I will not address this' as 'the store refuses everything', and collected none of the 1681 it had found. Two changes: references from build records are read through Recorded, where the provenance is known — not in LetGo, which cannot tell one registry host from another and must stay strict — and a reference the sweep will not address is now ErrNotOurs, skipped, never a reason to stop. Only the store refusing ends a sweep. make check: the two failures both fail on main as well — the resolver test (hq 202/203) and the service-manager test, which reads this machine's own shell environment.
This commit is contained in:
@@ -92,3 +92,26 @@ func TestAReferenceThatIsNotTheMeshsOwnIsNeverAsked(t *testing.T) {
|
||||
t.Fatalf("the store was asked about %v", *asked)
|
||||
}
|
||||
}
|
||||
|
||||
// A reference this sweep will not address says so as ErrNotOurs, which is a fact about the
|
||||
// record and not about the store (novox/hq issue 226).
|
||||
//
|
||||
// The sweep skips one and abandons itself for the other, so they cannot be the same error. The
|
||||
// first live run met a reference recorded with the store's old address, read the refusal as "the
|
||||
// store refuses everything", and collected none of the 1681 it had found.
|
||||
func TestAReferenceThisSweepWillNotAddressIsToldApartFromAStoreRefusing(t *testing.T) {
|
||||
store, asked := fakeStore(t, http.StatusAccepted)
|
||||
for _, reference := range []string{
|
||||
"docker.io/library/registry@sha256:abc123",
|
||||
"127.0.0.1:5100/mesh-tools/build@sha256:abc123",
|
||||
"1.4.2",
|
||||
} {
|
||||
err := store.LetGo(context.Background(), reference)
|
||||
if !errors.Is(err, ErrNotOurs) {
|
||||
t.Errorf("%s answered %v; a sweep must be able to skip it and go on", reference, err)
|
||||
}
|
||||
}
|
||||
if len(*asked) != 0 {
|
||||
t.Fatalf("the store was asked about %v", *asked)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user