diff --git a/internal/catalogue/manifest.go b/internal/catalogue/manifest.go index 5ce6543..cefe1b3 100644 --- a/internal/catalogue/manifest.go +++ b/internal/catalogue/manifest.go @@ -1769,6 +1769,8 @@ func (m Manifest) MachineSide(port int) (at int, mayAssign bool) { var facilitiesOf = map[string][]string{ // Both spellings: /var/run is a link to /run on every machine the mesh runs on. "container-runtime": {"/var/run/docker.sock", "/run/docker.sock"}, + // The virtualisation daemon's socket, for the lab (novox/hq ADR 0172): it raises machines there. + "virtualisation": {"/var/lib/incus/unix.socket"}, } // undeclaredMounts is every bind-mount source no declaration covers — see the check above. diff --git a/internal/catalogue/resolver_manifests_test.go b/internal/catalogue/resolver_manifests_test.go index e6daf22..234e0ce 100644 --- a/internal/catalogue/resolver_manifests_test.go +++ b/internal/catalogue/resolver_manifests_test.go @@ -48,7 +48,9 @@ func TestTheResolverForwardsToFixedUpstreamsAndNeverReadsResolvConf(t *testing.T } for _, want := range []string{ "\nno-resolv\n", "\nserver=1.1.1.1\n", "\nserver=8.8.8.8\n", - "\nlisten-address=127.0.0.1\n", "\nlisten-address=${machine:address}\n", "\nbind-dynamic\n", + // Loopback is the mesh-wide setting's default; a machine answering its own LAN adds its + // address there (novox/hq issue 198). + "\nlisten-address=${setting:listen-addresses}\n", "\nlisten-address=${machine:address}\n", "\nbind-dynamic\n", "\ndomain-needed\n", "\nbogus-priv\n", "\nconf-file=" + m.Facts["node-zones"].Path + "\n", } { @@ -113,7 +115,8 @@ func TestTheResolverAndWhatAsksItComposeOnOneMachine(t *testing.T) { // issue 111) — the resolver's zones read only the second, and in this scenario the two // happen to be the same map, since nothing routed is part of it. Names: twoMachines, Machines: twoMachines, Suffix: "internal", - Needed: map[string]map[string]string{"dnsmasq": {"broker": "sealed"}}, + Needed: map[string]map[string]string{"dnsmasq": {"broker": "sealed"}}, + Settings: SettingsBy{"dnsmasq": {{From: "the mesh", Values: map[string]any{"listen-addresses": "127.0.0.1"}}}}, }) if err != nil { t.Fatal(err) @@ -207,9 +210,16 @@ func TestTheResolverOnAMachineOffTheNetworkIsRefused(t *testing.T) { if err != nil { t.Fatal(err) } - _, err = got.Declaration(Rendering{Names: twoMachines, Suffix: "internal", - Needed: map[string]map[string]string{"dnsmasq": {"broker": "sealed"}}}) - if err == nil || !strings.Contains(err.Error(), "${machine:address}") { - t.Fatalf("a machine off the network was composed a resolver, or refused for another reason: %v", err) + // Left out of the declaration and said, rather than composed listening nowhere: a module that + // cannot compose on a machine is kept as it is there, with the reason (hq ADR 0163). + composed, err := got.Compose(Rendering{Names: twoMachines, Suffix: "internal", + Needed: map[string]map[string]string{"dnsmasq": {"broker": "sealed"}}, + Settings: SettingsBy{"dnsmasq": {{From: "the mesh", Values: map[string]any{"listen-addresses": "127.0.0.1"}}}}}) + if err == nil && !strings.Contains(composed.LeftOut["dnsmasq"], "${machine:address}") { + t.Fatalf("a machine off the network was composed a resolver, or left out for another reason: %v", + composed.LeftOut) + } + if err != nil && !strings.Contains(err.Error(), "${machine:address}") { + t.Fatalf("a machine off the network was refused for another reason: %v", err) } }