Check that what a node says when it joins is what this mesh reads

The enrolment request is a struct in each repository. A node now reports
a third key — the one its secrets are sealed to — and that wiring had
unit tests on each side and had never been run across the join. A field
renamed on one side fails silently: enrolment succeeds, the key is
absent, and the node looks joined until the first thing sealed to it
cannot be opened, by which point nobody is looking at enrolment.

So the host's suite writes a real request and this one reads it, the same
way the declaration check already runs in the other direction. Both skip
with a reason when the neighbour is not checked out.

It does more than compare shapes: it seals something to the key that
arrived and opens it with the private half the host kept. Confirmed to
fail three ways — a renamed field, a value that is not a key, and a key
that is present, correctly named and simply somebody else's. Only the
last needs the sealing step, and it is the one a shape check would pass.

Also `inventory.ForTest`, because the check lives beside the link and a
second copy of the throwaway-database helper would be a second thing to
keep true.
This commit is contained in:
2026-08-30 02:20:28 +02:00
parent c3046dcf56
commit b9aac2b700
4 changed files with 216 additions and 52 deletions
+26
View File
@@ -165,6 +165,32 @@ the fake behaves as expected.
Every test here has been confirmed to fail when the behaviour it defends is removed. Two did not,
when first written, and both are now commented with what they were missing.
## Checks that cross into the host's repository
Two things are agreed between this repository and `novox/mesh-host`, and each is a separate struct
on each side. A field renamed on one of them fails **silently** — the crossing succeeds and
something is simply absent — so both are checked by handing one side's real output to the other's
real parser. Neither runs by default; each skips with a reason, because a repository that fails
without its neighbour checked out is a repository nobody can build.
**What this mesh sends, read by the host that receives it:**
```
mesh-control: ./build/mesh-control plan <node> --json > /tmp/d.json
mesh-host: MESH_EMITTED=/tmp/d.json go test ./internal/declaration/ -v
```
**What a node says when it joins, read by this mesh:**
```
mesh-host: MESH_ENROL_OUT=/tmp/enrol.json go test ./internal/link/
mesh-control: MESH_ENROL=/tmp/enrol.json make check
```
The second does more than compare shapes: it seals something to the key that arrived and opens it
with the private half the host kept. A key that is present, correctly named and simply *wrong*
passes every check that only looks at the message.
## The image
`FROM scratch`, holding one statically linked binary and nothing else — no shell, no package