Seats are a closed set, a seat's holder answers for what it delivers, and a build source may live on the git seat
Implements novox/hq ADR 0110 and 0111. The seat set lives in internal/catalogue/seats.go: fourteen seats, each with a scope, what occupying it delivers, and the record that made it one. A test asserts the count and a decision per entry, so changing the set means finding the argument, as the host's vocabulary test does. The first set is every seat already claimed — including the-private-network, which the network module claims from a manifest composed in this repository's code, not from any module.json — plus npm-package-registry (ADR 0109) and git (ADR 0111). A test parses every catalogue manifest and this repository's own and fails on any refused claim, so closing the set refuses nothing in use. ParseManifest now refuses a claim on a seat the mesh does not define, a seat claimed at another scope, and a delivering seat claimed by a module that does not provide what it delivers. A malformed claim is refused once, for being malformed. Resolution: among several providers of a mesh provision, a pin still wins; then the holder of the seat that delivers it; then the only provider; otherwise refused as before. ADR 0009's "never guessed" holds — the seat is the choice made once, mesh-wide, rather than a pin per consumer node. A provider now carries the module it came from, because a provider is a (node, module) pair and the pair is what tells a holder from a neighbour on the same machine. The planner's second pass is now given the first pass's holdings. Without them, a node consuming a seat-delivered provision was refused there, and a refused node's own claims dropped out of what the mesh holds — letting a second holder of one of its seats pass unrefused. `seats [--json]` lists every seat, what it delivers, and each holder, derived from assignments every time and never stored. Unheld seats are listed. A stored claim outside the set — possible for a manifest registered before the set closed, since stored manifests are not re-validated — is shown rather than hidden. `build --self <owner>/<repo>` builds from a repository on the git seat's holder. The clone URL is composed at build time from the holder's node and what it serves for git; the recorded source is the path and the seat (migration 0032), never an address, so a moved forge changes nothing recorded. Nobody holding the seat refuses self-hosted builds and says so; external URLs are unchanged. An address passed with --self is refused rather than recorded as a path. Replaces three foundation tests that defended the builder's carried package binding. The catalogue removed that binding when the builder began requiring the registry through a real grant, so the tests were already failing on main; they now assert the builder requires what the npm seat delivers and carries no copy of its own, and that the forge holds the npm and git seats. Verified: go vet clean; the whole suite passes against a throwaway Postgres (make postgres), the new inventory tests included; gofmt clean apart from cmd/mesh-builder/stdout_test.go, which fails on main too.
This commit is contained in:
@@ -46,25 +46,35 @@ func buildCommand(ctx context.Context, args []string) error {
|
||||
// retype each repository is asking them to be the loop. Naming a repository and asking which
|
||||
// ones need building are different requests, so they are not combined.
|
||||
behind := set.Bool("behind", false, "every module the mesh holds older than its source has")
|
||||
// A repository on the mesh's own forge, named by its path there (novox/hq ADR 0111). Without it
|
||||
// the repository is external, cloned exactly as given — see source.go.
|
||||
self := set.Bool("self", false, "the repository is a path on the forge holding the git seat")
|
||||
positionals, err := parseAround(set, args)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if *behind {
|
||||
if len(positionals) != 0 {
|
||||
if len(positionals) != 0 || *self {
|
||||
return errors.New("build <repository> or build --behind, not both: one names a " +
|
||||
"repository and the other asks which need building")
|
||||
}
|
||||
return buildBehind(ctx, *wait)
|
||||
}
|
||||
if len(positionals) != 1 {
|
||||
return errors.New("build <repository> [--ref R] [--wait D] [--dry-run]")
|
||||
return errors.New("build <repository> [--self] [--path P] [--ref R] [--wait D] [--dry-run]")
|
||||
}
|
||||
source := buildSource{Repository: positionals[0]}
|
||||
if *self {
|
||||
if err := onASeat(source.Repository); err != nil {
|
||||
return err
|
||||
}
|
||||
source.Seat = gitSeat
|
||||
}
|
||||
|
||||
if *dryRun {
|
||||
return buildAndShow(ctx, positionals[0], *path, *ref, *wait)
|
||||
return buildAndShow(ctx, source, *path, *ref, *wait)
|
||||
}
|
||||
return buildOne(ctx, positionals[0], *path, *ref, *wait)
|
||||
return buildOne(ctx, source, *path, *ref, *wait)
|
||||
}
|
||||
|
||||
// buildFrom turns what a builder said into what the mesh keeps.
|
||||
@@ -325,7 +335,8 @@ func buildBehind(ctx context.Context, wait time.Duration) error {
|
||||
// Its own recorded ref, not its head commit: a module tracking a branch should be built
|
||||
// from that branch, and pinning to the commit the mesh happened to notice would quietly
|
||||
// turn a tracked branch into a pin.
|
||||
if err := buildOne(ctx, e.Source.Repository, e.Source.Path, e.Source.Ref, wait); err != nil {
|
||||
source := buildSource{Repository: e.Source.Repository, Seat: e.Source.Seat}
|
||||
if err := buildOne(ctx, source, e.Source.Path, e.Source.Ref, wait); err != nil {
|
||||
fmt.Printf(" %v\n", err)
|
||||
failed = append(failed, e.Manifest.Module)
|
||||
}
|
||||
@@ -343,7 +354,14 @@ func buildBehind(ctx context.Context, wait time.Duration) error {
|
||||
// buildOne asks a build machine for one repository and records everything that came back.
|
||||
//
|
||||
// Separated from the command so `--behind` can walk a list without a second path to the same act.
|
||||
func buildOne(ctx context.Context, repository, path, ref string, wait time.Duration) error {
|
||||
func buildOne(ctx context.Context, source buildSource, path, ref string, wait time.Duration) error {
|
||||
// Before anything is asked of a builder: a source on a seat nobody holds is refused here, with
|
||||
// the reason, rather than sent to a machine to fail at `git clone`.
|
||||
repository, err := cloneFrom(ctx, source)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
ident, err := openIdentity(ctx)
|
||||
if err != nil {
|
||||
return err
|
||||
@@ -365,7 +383,10 @@ func buildOne(ctx context.Context, repository, path, ref string, wait time.Durat
|
||||
Ref: ref,
|
||||
Held: heldBy(ctx),
|
||||
}
|
||||
fmt.Printf("asked for %s", request.Repository)
|
||||
fmt.Printf("asked for %s", source)
|
||||
if source.Seat != "" {
|
||||
fmt.Printf(" (%s)", repository)
|
||||
}
|
||||
if path != "" {
|
||||
fmt.Printf(" at %s", path)
|
||||
}
|
||||
@@ -414,11 +435,18 @@ func buildOne(ctx context.Context, repository, path, ref string, wait time.Durat
|
||||
}
|
||||
|
||||
// Recorded with where it came from, so "is this current?" is answerable without building it
|
||||
// again (novox/hq ADR 0009).
|
||||
if err := inv.RegisterModule(ctx, manifest, inventory.Source{
|
||||
// again (novox/hq ADR 0009). **For a source on a seat, as the path and the seat, never the URL
|
||||
// just cloned** (ADR 0111): the URL is where the forge runs today, and recording it would put
|
||||
// the forge's address back into every module built from it. The build log above keeps the URL,
|
||||
// because that is what was cloned.
|
||||
recorded := inventory.Source{
|
||||
Repository: result.Repository, Path: result.Path, Ref: result.Ref,
|
||||
BuiltFrom: result.Commit, Head: result.Commit,
|
||||
}); err != nil {
|
||||
}
|
||||
if source.Seat != "" {
|
||||
recorded.Repository, recorded.Seat = source.Repository, source.Seat
|
||||
}
|
||||
if err := inv.RegisterModule(ctx, manifest, recorded); err != nil {
|
||||
return err
|
||||
}
|
||||
fmt.Printf("\n%s %s, built on %s from %s\n",
|
||||
@@ -428,7 +456,11 @@ func buildOne(ctx context.Context, repository, path, ref string, wait time.Durat
|
||||
}
|
||||
|
||||
// buildAndShow builds and prints the manifest without recording anything.
|
||||
func buildAndShow(ctx context.Context, repository, path, ref string, wait time.Duration) error {
|
||||
func buildAndShow(ctx context.Context, source buildSource, path, ref string, wait time.Duration) error {
|
||||
repository, err := cloneFrom(ctx, source)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
ident, err := openIdentity(ctx)
|
||||
if err != nil {
|
||||
return err
|
||||
|
||||
@@ -114,6 +114,8 @@ func run() error {
|
||||
return planCommand(ctx, args[1:])
|
||||
case "push":
|
||||
return pushCommand(ctx, args[1:])
|
||||
case "seats":
|
||||
return seatsCommand(ctx, args[1:])
|
||||
case "status":
|
||||
return statusCommand(ctx, args[1:])
|
||||
case "version":
|
||||
@@ -157,6 +159,7 @@ func usage() {
|
||||
upgrade <name> roll-out [--together] ...send it to the machines running it
|
||||
upgrade <name> record ...record that they are behind, and send nothing
|
||||
status [--json] what is wrong, what is quiet, and what is out of date
|
||||
seats [--json] every seat this mesh defines, what it delivers, and who holds it
|
||||
board [--listen ADDR] the same three questions, as a page that holds nothing
|
||||
api --issuer URL [--listen A] assign and unassign over http, for a surface that is not here
|
||||
assign <node> <module> put a module on a node
|
||||
|
||||
@@ -217,6 +217,7 @@ func theRestOfTheMesh(ctx context.Context, inv *inventory.Inventory,
|
||||
}
|
||||
|
||||
offered := map[string][]catalogue.Provider{}
|
||||
var firstHeld []catalogue.Held
|
||||
for _, o := range others {
|
||||
got, err := catalogue.Resolve(shelf, o.assigned, o.node, catalogue.World{Unchecked: true})
|
||||
if err != nil {
|
||||
@@ -224,6 +225,7 @@ func theRestOfTheMesh(ctx context.Context, inv *inventory.Inventory,
|
||||
// report, and nothing of theirs is running, so it offers nothing.
|
||||
continue
|
||||
}
|
||||
firstHeld = append(firstHeld, got.Claims...)
|
||||
for _, m := range got.Modules {
|
||||
for _, name := range m.OffersAt(catalogue.ScopeMesh) {
|
||||
// What that module says a consumer needs to know, with that node's settings on
|
||||
@@ -234,7 +236,7 @@ func theRestOfTheMesh(ctx context.Context, inv *inventory.Inventory,
|
||||
return catalogue.World{}, err
|
||||
}
|
||||
offered[name] = append(offered[name], catalogue.Provider{
|
||||
Node: o.node.Name, At: o.node.At, Serves: serves})
|
||||
Node: o.node.Name, At: o.node.At, Serves: serves, Module: m.Module})
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -244,14 +246,20 @@ func theRestOfTheMesh(ctx context.Context, inv *inventory.Inventory,
|
||||
})
|
||||
}
|
||||
|
||||
world := catalogue.World{Offered: offered}
|
||||
// **The second pass is given the first pass's holdings.** A seat's holder answers a requirement
|
||||
// with several providers (novox/hq ADR 0110), so a node consuming one resolves only once the
|
||||
// holder is known. Without them its set is refused here, and a refused node's own claims drop
|
||||
// out of what the mesh holds — so a second holder of one of its seats would pass unrefused.
|
||||
world := catalogue.World{Offered: offered, Held: firstHeld}
|
||||
var held []catalogue.Held
|
||||
for _, o := range others {
|
||||
got, err := catalogue.Resolve(shelf, o.assigned, o.node, world)
|
||||
if err != nil {
|
||||
continue
|
||||
}
|
||||
world.Held = append(world.Held, got.Claims...)
|
||||
held = append(held, got.Claims...)
|
||||
}
|
||||
world.Held = held
|
||||
return world, nil
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,150 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"flag"
|
||||
"fmt"
|
||||
"os"
|
||||
"sort"
|
||||
"strings"
|
||||
"text/tabwriter"
|
||||
|
||||
"github.com/novox/mesh-controller/internal/catalogue"
|
||||
)
|
||||
|
||||
// What this mesh can have one of, and who fills each (novox/hq ADR 0110).
|
||||
//
|
||||
// **Derived every time, never stored.** A seat is held by a module assignment, so the answer is
|
||||
// computed from assignments by the same resolution that decides what every machine runs. A table
|
||||
// of holders kept beside the assignments would be a second copy of one fact, and the first thing
|
||||
// to be wrong about it.
|
||||
|
||||
// seatHolder is one assignment holding a seat.
|
||||
type seatHolder struct {
|
||||
Node string `json:"node"`
|
||||
Module string `json:"module"`
|
||||
}
|
||||
|
||||
// seatRow is one seat and who holds it. Unheld is an answer — "this mesh has no X" — not a fault.
|
||||
type seatRow struct {
|
||||
Seat string `json:"seat"`
|
||||
Scope string `json:"scope"`
|
||||
Delivers string `json:"delivers,omitempty"`
|
||||
Decision string `json:"decision"`
|
||||
Holders []seatHolder `json:"holders"`
|
||||
}
|
||||
|
||||
// seatsHeld is every seat the mesh defines with its holders, and every claim held that names no
|
||||
// seat in the set.
|
||||
//
|
||||
// **The second list is not empty by construction.** Manifests are held to the set when they are
|
||||
// registered, and a mesh can hold one registered before the set closed. Leaving its claim out of the
|
||||
// overview would make the one thing the overview is for — what does this mesh have — quietly
|
||||
// incomplete.
|
||||
func seatsHeld(seats []catalogue.Seat, held []catalogue.Held) ([]seatRow, []catalogue.Held) {
|
||||
defined := map[string]bool{}
|
||||
rows := make([]seatRow, 0, len(seats))
|
||||
for _, s := range seats {
|
||||
defined[s.Name] = true
|
||||
row := seatRow{Seat: s.Name, Scope: s.Scope, Delivers: s.Delivers, Decision: s.Decision,
|
||||
Holders: []seatHolder{}}
|
||||
seen := map[seatHolder]bool{}
|
||||
for _, h := range held {
|
||||
if h.Claim != s.Name || h.Scope != s.Scope {
|
||||
continue
|
||||
}
|
||||
holder := seatHolder{Node: h.Node, Module: h.Module}
|
||||
if !seen[holder] {
|
||||
seen[holder] = true
|
||||
row.Holders = append(row.Holders, holder)
|
||||
}
|
||||
}
|
||||
sort.Slice(row.Holders, func(i, j int) bool {
|
||||
if row.Holders[i].Node != row.Holders[j].Node {
|
||||
return row.Holders[i].Node < row.Holders[j].Node
|
||||
}
|
||||
return row.Holders[i].Module < row.Holders[j].Module
|
||||
})
|
||||
rows = append(rows, row)
|
||||
}
|
||||
var outside []catalogue.Held
|
||||
for _, h := range held {
|
||||
if !defined[h.Claim] {
|
||||
outside = append(outside, h)
|
||||
}
|
||||
}
|
||||
sort.Slice(outside, func(i, j int) bool {
|
||||
if outside[i].Claim != outside[j].Claim {
|
||||
return outside[i].Claim < outside[j].Claim
|
||||
}
|
||||
return outside[i].Node < outside[j].Node
|
||||
})
|
||||
return rows, outside
|
||||
}
|
||||
|
||||
func seatsCommand(ctx context.Context, args []string) error {
|
||||
set := flag.NewFlagSet("seats", flag.ContinueOnError)
|
||||
asJSON := set.Bool("json", false, "the same, as JSON")
|
||||
if err := set.Parse(args); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
open, err := openStores(ctx)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer open.Close()
|
||||
inv := open.inventory
|
||||
shelf, err := inv.Catalogue(ctx)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
// Every node, none excluded: the same view of what each machine holds that planning uses.
|
||||
world, err := theRestOfTheMesh(ctx, inv, shelf, "")
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
rows, outside := seatsHeld(catalogue.Seats(), world.Held)
|
||||
|
||||
if *asJSON {
|
||||
out := struct {
|
||||
Seats []seatRow `json:"seats"`
|
||||
Outside []catalogue.Held `json:"outside,omitempty"`
|
||||
}{rows, outside}
|
||||
body, err := json.MarshalIndent(out, "", " ")
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
fmt.Println(string(body))
|
||||
return nil
|
||||
}
|
||||
|
||||
w := tabwriter.NewWriter(os.Stdout, 0, 0, 2, ' ', 0)
|
||||
fmt.Fprintln(w, "SEAT\tSCOPE\tDELIVERS\tHELD BY")
|
||||
for _, r := range rows {
|
||||
delivers := r.Delivers
|
||||
if delivers == "" {
|
||||
delivers = "—"
|
||||
}
|
||||
holders := "unheld"
|
||||
if len(r.Holders) > 0 {
|
||||
parts := make([]string, 0, len(r.Holders))
|
||||
for _, h := range r.Holders {
|
||||
parts = append(parts, h.Module+" on "+h.Node)
|
||||
}
|
||||
holders = strings.Join(parts, ", ")
|
||||
}
|
||||
fmt.Fprintf(w, "%s\t%s\t%s\t%s\n", r.Seat, r.Scope, delivers, holders)
|
||||
}
|
||||
if err := w.Flush(); err != nil {
|
||||
return err
|
||||
}
|
||||
if len(outside) > 0 {
|
||||
fmt.Println("\nheld, and not a seat this mesh defines (registered before the set closed — novox/hq ADR 0110):")
|
||||
for _, h := range outside {
|
||||
fmt.Printf(" %s %s on %s\n", h.Claim, h.Module, h.Node)
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
@@ -0,0 +1,64 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/novox/mesh-controller/internal/catalogue"
|
||||
)
|
||||
|
||||
// The overview of what a mesh has (novox/hq ADR 0110).
|
||||
|
||||
func TestEverySeatIsListedIncludingTheOnesNobodyHolds(t *testing.T) {
|
||||
// An unheld seat is an answer — "this mesh has no forge" — so it is listed rather than omitted.
|
||||
rows, _ := seatsHeld(catalogue.Seats(), []catalogue.Held{
|
||||
{Claim: "mesh-store", Scope: catalogue.ScopeMesh, Node: "anchor", Module: "postgres"},
|
||||
})
|
||||
if len(rows) != len(catalogue.Seats()) {
|
||||
t.Fatalf("%d seats listed of %d", len(rows), len(catalogue.Seats()))
|
||||
}
|
||||
for _, r := range rows {
|
||||
switch r.Seat {
|
||||
case "mesh-store":
|
||||
if len(r.Holders) != 1 || r.Holders[0].Module != "postgres" || r.Holders[0].Node != "anchor" {
|
||||
t.Errorf("mesh-store is held by %+v", r.Holders)
|
||||
}
|
||||
if r.Delivers != "postgres-database" {
|
||||
t.Errorf("mesh-store does not say what it delivers: %q", r.Delivers)
|
||||
}
|
||||
case "git":
|
||||
if len(r.Holders) != 0 {
|
||||
t.Errorf("git is held by %+v in a mesh with no forge", r.Holders)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestANodeSeatListsEveryMachineHoldingIt(t *testing.T) {
|
||||
rows, _ := seatsHeld(catalogue.Seats(), []catalogue.Held{
|
||||
{Claim: "the-packet-filter", Scope: catalogue.ScopeNode, Node: "node2", Module: "nftables"},
|
||||
{Claim: "the-packet-filter", Scope: catalogue.ScopeNode, Node: "anchor", Module: "nftables"},
|
||||
// Resolved twice, reported once: a machine is one holder however many passes saw it.
|
||||
{Claim: "the-packet-filter", Scope: catalogue.ScopeNode, Node: "anchor", Module: "nftables"},
|
||||
})
|
||||
for _, r := range rows {
|
||||
if r.Seat != "the-packet-filter" {
|
||||
continue
|
||||
}
|
||||
if len(r.Holders) != 2 || r.Holders[0].Node != "anchor" || r.Holders[1].Node != "node2" {
|
||||
t.Fatalf("the packet filter is held by %+v", r.Holders)
|
||||
}
|
||||
return
|
||||
}
|
||||
t.Fatal("the packet filter is not listed")
|
||||
}
|
||||
|
||||
func TestAClaimOutsideTheSetIsShownNotHidden(t *testing.T) {
|
||||
// A manifest registered before the set closed can still hold one. Leaving it out would make
|
||||
// the overview quietly incomplete, which is the one thing it may not be.
|
||||
_, outside := seatsHeld(catalogue.Seats(), []catalogue.Held{
|
||||
{Claim: "the-controller", Scope: catalogue.ScopeMesh, Node: "anchor", Module: "mesh-controller"},
|
||||
})
|
||||
if len(outside) != 1 || outside[0].Claim != "the-controller" {
|
||||
t.Fatalf("a claim outside the set was not shown: %+v", outside)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,136 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"strconv"
|
||||
"strings"
|
||||
|
||||
"github.com/novox/mesh-controller/internal/catalogue"
|
||||
)
|
||||
|
||||
// where a build's repository is (novox/hq ADR 0111).
|
||||
//
|
||||
// A repository is on the mesh's own forge, or it is anywhere else. The first is recorded as its path
|
||||
// on the forge holding the git seat, and cloned from wherever that forge runs at the moment of
|
||||
// building; the second is a URL, recorded and cloned exactly as given. The build machine is not told
|
||||
// the difference — it is handed a URL either way — because only the control plane knows where the
|
||||
// seat's holder runs.
|
||||
|
||||
// gitSeat is the seat a self-hosted repository lives on.
|
||||
const gitSeat = "git"
|
||||
|
||||
// buildSource is where a build's repository is: a URL, or a path on a seat's holder.
|
||||
type buildSource struct {
|
||||
Repository string
|
||||
Seat string
|
||||
}
|
||||
|
||||
// String is the source as a person reads it, which for one on a seat is not the URL: the URL is a
|
||||
// fact about where the forge happens to run today.
|
||||
func (s buildSource) String() string {
|
||||
if s.Seat == "" {
|
||||
return s.Repository
|
||||
}
|
||||
return fmt.Sprintf("%s on the %s seat", s.Repository, s.Seat)
|
||||
}
|
||||
|
||||
// onASeat refuses an address given as a path on the forge.
|
||||
//
|
||||
// **A URL here would be recorded as a path**, and then composed onto the forge's address as one —
|
||||
// cloning `http://forge:3000/https://github.com/…`. Refused by what an address plainly looks like,
|
||||
// not repaired: `--self` promises a path, and something that is not one is a mistake to name.
|
||||
func onASeat(repository string) error {
|
||||
if strings.Contains(repository, ":") || strings.HasPrefix(repository, "/") ||
|
||||
strings.Trim(repository, "/") == "" {
|
||||
return fmt.Errorf("--self takes the repository's path on the forge, such as novox/mesh-catalog, "+
|
||||
"and %q is not one — without --self it is built from exactly what is given", repository)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// cloneFrom is the URL a build machine clones for a source.
|
||||
//
|
||||
// A URL is itself. A path on a seat is composed from the seat's holder as the mesh sees it now —
|
||||
// the same view planning takes of every machine, so the forge a build clones from is the forge the
|
||||
// mesh says holds the seat.
|
||||
func cloneFrom(ctx context.Context, source buildSource) (string, error) {
|
||||
if source.Seat == "" {
|
||||
return source.Repository, nil
|
||||
}
|
||||
open, err := openStores(ctx)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
defer open.Close()
|
||||
shelf, err := open.inventory.Catalogue(ctx)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
world, err := theRestOfTheMesh(ctx, open.inventory, shelf, "")
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
return clonedFromSeat(world, source.Seat, source.Repository)
|
||||
}
|
||||
|
||||
// clonedFromSeat composes the clone URL for a repository on a seat's holder.
|
||||
//
|
||||
// **Refused, never defaulted, at every step that has no answer.** Nobody holding the seat is a mesh
|
||||
// without a forge of its own: it builds from external repositories and must say so rather than fail
|
||||
// to clone. A holder off the private network cannot be reached by any build machine. A holder that
|
||||
// serves no scheme or port has nothing to compose from — a default port here would be the forge's
|
||||
// address guessed, which is the thing this exists to stop.
|
||||
func clonedFromSeat(world catalogue.World, seatName, repository string) (string, error) {
|
||||
seat, known := catalogue.SeatNamed(seatName)
|
||||
if !known || seat.Delivers == "" {
|
||||
return "", fmt.Errorf("%q is not a seat a repository can live on", seatName)
|
||||
}
|
||||
var holder *catalogue.Held
|
||||
for i, h := range world.Held {
|
||||
if h.Claim == seat.Name && h.Scope == seat.Scope {
|
||||
holder = &world.Held[i]
|
||||
break
|
||||
}
|
||||
}
|
||||
if holder == nil {
|
||||
return "", fmt.Errorf("nobody holds the %s seat, so %s cannot be cloned from this mesh's "+
|
||||
"forge — assign a module that claims it, or build from the repository's URL without --self",
|
||||
seat.Name, repository)
|
||||
}
|
||||
var provider *catalogue.Provider
|
||||
for i, p := range world.Offered[seat.Delivers] {
|
||||
if p.Node == holder.Node && p.Module == holder.Module {
|
||||
provider = &world.Offered[seat.Delivers][i]
|
||||
}
|
||||
}
|
||||
if provider == nil {
|
||||
return "", fmt.Errorf("%s on %s holds the %s seat and offers no %q to clone from",
|
||||
holder.Module, holder.Node, seat.Name, seat.Delivers)
|
||||
}
|
||||
if provider.At == "" {
|
||||
return "", fmt.Errorf("%s on %s holds the %s seat and is not on the private network, so no "+
|
||||
"build machine can reach it", holder.Module, holder.Node, seat.Name)
|
||||
}
|
||||
scheme, _ := provider.Serves["scheme"].(string)
|
||||
port := servedPort(provider.Serves["port"])
|
||||
if scheme == "" || port == "" {
|
||||
return "", fmt.Errorf("%s on %s holds the %s seat and does not serve a scheme and a port for %q",
|
||||
holder.Module, holder.Node, seat.Name, seat.Delivers)
|
||||
}
|
||||
path := strings.TrimSuffix(strings.Trim(repository, "/"), ".git")
|
||||
return fmt.Sprintf("%s://%s:%s/%s.git", scheme, provider.At, port, path), nil
|
||||
}
|
||||
|
||||
// servedPort is a served port as text, however the manifest and the node's settings carried it.
|
||||
func servedPort(v any) string {
|
||||
switch p := v.(type) {
|
||||
case float64:
|
||||
return strconv.Itoa(int(p))
|
||||
case int:
|
||||
return strconv.Itoa(p)
|
||||
case string:
|
||||
return p
|
||||
}
|
||||
return ""
|
||||
}
|
||||
@@ -0,0 +1,108 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/novox/mesh-controller/internal/catalogue"
|
||||
)
|
||||
|
||||
// Defends novox/hq ADR 0111: a build source is on the git seat, or it is external.
|
||||
|
||||
func forgeHolding(port any) catalogue.World {
|
||||
return catalogue.World{
|
||||
Held: []catalogue.Held{{Claim: "git", Scope: catalogue.ScopeMesh, Node: "anchor", Module: "gitea"}},
|
||||
Offered: map[string][]catalogue.Provider{"git": {
|
||||
// A second forge that does not hold the seat, so taking the first one found would be wrong.
|
||||
{Node: "archive", At: "archive.internal", Module: "gitea-mirror",
|
||||
Serves: map[string]any{"scheme": "http", "port": float64(3000)}},
|
||||
{Node: "anchor", At: "anchor.internal", Module: "gitea",
|
||||
Serves: map[string]any{"scheme": "http", "port": port}},
|
||||
}},
|
||||
}
|
||||
}
|
||||
|
||||
func TestARepositoryOnTheSeatIsClonedFromItsHolder(t *testing.T) {
|
||||
got, err := clonedFromSeat(forgeHolding(float64(3000)), "git", "novox/mesh-catalog")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got != "http://anchor.internal:3000/novox/mesh-catalog.git" {
|
||||
t.Fatalf("cloned from %s", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAMovedForgeIsFollowedWithoutRewritingAnything(t *testing.T) {
|
||||
// The whole point: the node gave the forge another port, and the same recorded path clones
|
||||
// from the new one. Nothing recorded contained the old one to be wrong.
|
||||
got, err := clonedFromSeat(forgeHolding(float64(3100)), "git", "novox/mesh-catalog")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if !strings.Contains(got, ":3100/") {
|
||||
t.Fatalf("the moved port was not followed: %s", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWithNobodyHoldingTheSeatASelfHostedBuildIsRefusedAndSaysWhy(t *testing.T) {
|
||||
_, err := clonedFromSeat(catalogue.World{}, "git", "novox/mesh-catalog")
|
||||
if err == nil {
|
||||
t.Fatal("a repository was cloned from a forge the mesh does not have")
|
||||
}
|
||||
for _, want := range []string{"nobody holds the git seat", "without --self"} {
|
||||
if !strings.Contains(err.Error(), want) {
|
||||
t.Fatalf("the refusal does not say %q: %v", want, err)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestAnExternalRepositoryIsClonedExactlyAsGiven(t *testing.T) {
|
||||
// Unaffected by the seat, held or not: GitHub and GitLab are the ordinary cases.
|
||||
given := "https://github.com/someone/something.git"
|
||||
got, err := cloneFrom(t.Context(), buildSource{Repository: given})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got != given {
|
||||
t.Fatalf("an external repository became %s", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAHolderOffThePrivateNetworkIsRefused(t *testing.T) {
|
||||
world := forgeHolding(float64(3000))
|
||||
world.Offered["git"][1].At = ""
|
||||
if _, err := clonedFromSeat(world, "git", "novox/mesh-catalog"); err == nil ||
|
||||
!strings.Contains(err.Error(), "private network") {
|
||||
t.Fatalf("a forge nothing can reach was cloned from: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAHolderServingNoPortIsRefusedRatherThanGuessed(t *testing.T) {
|
||||
// A default port would be the forge's address guessed, which is what this exists to stop.
|
||||
if _, err := clonedFromSeat(forgeHolding(nil), "git", "novox/mesh-catalog"); err == nil {
|
||||
t.Fatal("a port was guessed for a forge that serves none")
|
||||
}
|
||||
}
|
||||
|
||||
func TestAnAddressGivenAsAPathOnTheForgeIsRefused(t *testing.T) {
|
||||
for _, bad := range []string{
|
||||
"https://github.com/someone/something.git",
|
||||
"git@anchor:novox/mesh-catalog.git",
|
||||
"/srv/git/mesh-catalog",
|
||||
"",
|
||||
} {
|
||||
if err := onASeat(bad); err == nil {
|
||||
t.Errorf("--self accepted %q as a path on the forge", bad)
|
||||
}
|
||||
}
|
||||
if err := onASeat("novox/mesh-catalog"); err != nil {
|
||||
t.Errorf("a path on the forge was refused: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestASourceOnTheSeatReadsAsAPathNotAnAddress(t *testing.T) {
|
||||
s := buildSource{Repository: "novox/mesh-catalog", Seat: "git"}
|
||||
if got := s.String(); got != "novox/mesh-catalog on the git seat" {
|
||||
t.Fatalf("read as %q", got)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user