contributes: a module's grant carries no value where it contributed several times
ContributionsFrom settled to whichever of a module's several contributions to one requirement sorted first, arbitrarily — the grant minted for it then carried that contribution's label and port under a credential the OTHER contribution's consumer never sees, and collided with that same contribution's own entry from contributions() besides. Confirmed live: minio's two route contributions (files-api, files) produced three entries in route-adapter's received file — files-api twice, once credentialed and once not, files not credentialed at all. Every single-contribution module (gitea, keycloak, umami) already mints an unused credential for `route` too — route never needs one, by its own documentation — but with exactly one contribution to match there was nothing to collide with, so it never surfaced. Where a module contributes more than once, there is no single value to settle on. The module still asks, still gets its one credential — a pair credential is not a place for a label or a port anyway — and each named contribution reaches the provider on its own, unchanged. No cleanup needed for the secret already minted live for minio+route: the sealed blob is a random pair credential unrelated to Values, which is recomputed fresh on every plan/push regardless.
This commit is contained in:
@@ -122,3 +122,46 @@ func TestASingleRouteStillResolvesTheOrdinaryWay(t *testing.T) {
|
||||
t.Fatalf("the plain shape regressed: %+v", given)
|
||||
}
|
||||
}
|
||||
|
||||
// ContributionsFrom is what mints the ONE pair credential a requiring module is granted
|
||||
// (cmd/mesh-controller/plan.go's grantsFor) — a separate path from Declaration()'s raw file, and
|
||||
// the one the two-routes test above never exercised. Where a module contributes several times,
|
||||
// there is no single "the" value: settling to whichever sorts first would both misrepresent the
|
||||
// grant and collide with that same contribution's own entry from contributions(), which is
|
||||
// exactly the duplicate a live plan against minio surfaced (files-api appearing once with a
|
||||
// credential, once without, while files got neither).
|
||||
func TestContributionsFromHasNoSingleValueWhenAModuleContributesSeveralTimes(t *testing.T) {
|
||||
minio, err := ParseManifest([]byte(twoRoutes))
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
got, err := Resolve(shelf(minimalRouteProxy(), minio), []string{"route-proxy", "minio"}, workstation(), World{})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
values, asks, err := got.ContributionsFrom("route", "minio", nil)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if !asks {
|
||||
t.Fatal("minio still requires route, so it still asks")
|
||||
}
|
||||
if len(values) != 0 {
|
||||
t.Fatalf("no single value represents two contributions, got %+v", values)
|
||||
}
|
||||
}
|
||||
|
||||
// The ordinary, single-contribution case is unchanged: exactly one match still settles to it.
|
||||
func TestContributionsFromReturnsTheOneValueForAnOrdinaryContribution(t *testing.T) {
|
||||
got, err := Resolve(shelf(proxy(), published("board", "board", 8080)), []string{"board"}, workstation(), World{})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
values, asks, err := got.ContributionsFrom("reverse-proxy", "board", nil)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if !asks || values["host"] != "board" {
|
||||
t.Fatalf("the ordinary single contribution should still settle to its own value: %+v", values)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user