Refuse token issue --adopted for a converged node and point to adopt, rather than flip it quietly (hq ADR 0100)
This commit is contained in:
@@ -279,13 +279,20 @@ func issueFor(ctx context.Context, inv *inventory.Inventory, existing, fresh str
|
|||||||
}
|
}
|
||||||
name = node.Name
|
name = node.Name
|
||||||
}
|
}
|
||||||
// Saying adopted makes the node adopted. Not saying it leaves the node as it is: re-issuing a
|
// Not saying adopted leaves the node as it is: re-issuing a token for an adopted node does not
|
||||||
// token for an adopted node does not converge it — converging is its own act, previewed
|
// converge it — converging is its own act, previewed (novox/hq ADR 0100). And saying it for a
|
||||||
// (novox/hq ADR 0100).
|
// node already converged is refused rather than done quietly: returning a node to adopted is
|
||||||
if adopted {
|
// its own act too, which unloads the mesh's filter and enables the found firewall again.
|
||||||
if err := inv.SetAdopted(ctx, name, true); err != nil {
|
if adopted && fresh == "" {
|
||||||
|
node, err := inv.NodeByName(ctx, name)
|
||||||
|
if err != nil {
|
||||||
return inventory.Issued{}, err
|
return inventory.Issued{}, err
|
||||||
}
|
}
|
||||||
|
if !node.Adopted {
|
||||||
|
return inventory.Issued{}, fmt.Errorf("%s is converged, and a token does not change "+
|
||||||
|
"that: run `adopt %s` to return it to adopted, then issue the token without "+
|
||||||
|
"--adopted", name, name)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
return inv.IssueToken(ctx, name, validFor)
|
return inv.IssueToken(ctx, name, validFor)
|
||||||
|
|||||||
@@ -139,11 +139,16 @@ func TestATokenIssuedAdoptedSaysSoAndReissuingDoesNotConverge(t *testing.T) {
|
|||||||
if !again.Node.Adopted {
|
if !again.Node.Adopted {
|
||||||
t.Fatal("re-issuing without --adopted converged the node; converging is its own act")
|
t.Fatal("re-issuing without --adopted converged the node; converging is its own act")
|
||||||
}
|
}
|
||||||
existing, err := issueFor(ctx, open.inventory, "laptop", "", true, time.Hour)
|
// --adopted for a node already converged is refused, and points at the act that does it.
|
||||||
if err != nil {
|
if _, err := issueFor(ctx, open.inventory, "laptop", "", true, time.Hour); err == nil ||
|
||||||
|
!strings.Contains(err.Error(), "adopt laptop") {
|
||||||
|
t.Fatalf("--adopted on a converged node was not refused: %v", err)
|
||||||
|
}
|
||||||
|
if n, _ := open.inventory.NodeByName(ctx, "laptop"); n.Adopted {
|
||||||
|
t.Fatal("a refused token flipped the node to adopted")
|
||||||
|
}
|
||||||
|
// And said for a node that is adopted already, it is the ordinary re-issue.
|
||||||
|
if _, err := issueFor(ctx, open.inventory, "joiner", "", true, time.Hour); err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
if !existing.Node.Adopted {
|
|
||||||
t.Fatal("--adopted on an existing record did not make it adopted")
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user