From c3ae3f3e098f7c1586225e4cc7072eac50f68aa6 Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 9 Oct 2026 01:37:43 +0200 Subject: [PATCH] Refuse a file that asks for a setting without saying whether it is trusted from 2026-10-10 The operator's date (hq issue 339). A test holds the warning before it and the refusal from it. --- cmd/mesh-controller/health_check_test.go | 28 ++++++++++++++++++++++++ internal/catalogue/terminal_keys.go | 2 +- 2 files changed, 29 insertions(+), 1 deletion(-) diff --git a/cmd/mesh-controller/health_check_test.go b/cmd/mesh-controller/health_check_test.go index 6f3f2351..4b835017 100644 --- a/cmd/mesh-controller/health_check_test.go +++ b/cmd/mesh-controller/health_check_test.go @@ -45,3 +45,31 @@ func TestModuleCheckCountsTheUndeclaredAndRefusesThemFromTheDate(t *testing.T) { t.Errorf("the refusal does not name the resource:\n%s", out.String()) } } + +// A file that asks for a setting says whether it is trusted (novox/hq issue 339): `module check` warns and counts +// it before the date, and refuses it from the date; a file that says so passes either way. +func TestModuleCheckCountsUnsaidTrustAndRefusesItFromTheDate(t *testing.T) { + dir := t.TempDir() + path := filepath.Join(dir, "module.json") + os.WriteFile(path, []byte(`{"module":"power","resources":[ + {"id":"logind","type":"file","path":"/etc/systemd/logind.conf.d/power.conf","mode":"0644","trusted":true, + "content":"HandleLidSwitch=${setting:lid}\n"}, + {"id":"note","type":"file","path":"/var/lib/power/note","mode":"0644","content":"${setting:greeting}\n"}]}`), 0o600) + defer func() { checkNow = time.Now }() + + checkNow = func() time.Time { return catalogue.TrustRequiredFrom.Add(-time.Hour) } + var out bytes.Buffer + if err := moduleCheck([]string{path}, &out); err != nil { + t.Fatalf("refused before the date: %v\n%s", err, out.String()) + } + for _, want := range []string{"WARNING: note ask(s) for a setting", UnsaidTrustLine + " 1"} { + if !strings.Contains(out.String(), want) { + t.Errorf("the check does not say %q:\n%s", want, out.String()) + } + } + checkNow = func() time.Time { return catalogue.TrustRequiredFrom } + out.Reset() + if err := moduleCheck([]string{path}, &out); err == nil || !strings.Contains(out.String(), "power: the file note asks for a setting") { + t.Fatalf("an unsaid file passed after the date: %v\n%s", err, out.String()) + } +} diff --git a/internal/catalogue/terminal_keys.go b/internal/catalogue/terminal_keys.go index cd294c0c..a08dfa26 100644 --- a/internal/catalogue/terminal_keys.go +++ b/internal/catalogue/terminal_keys.go @@ -33,7 +33,7 @@ const TrustedField = "trusted" // TrustRequiredFrom is when `module check` refuses a file that asks for a setting and does not say whether it is // trusted. Until then it is warned and counted: the catalogue's files get the field in their own change, which // can only land once a controller that takes the field out of the declaration runs. -var TrustRequiredFrom = time.Date(2026, 10, 30, 0, 0, 0, 0, time.UTC) +var TrustRequiredFrom = time.Date(2026, 10, 10, 0, 0, 0, 0, time.UTC) // TerminalKeys are the settings keys of a module that are set at the controller's terminal alone: places and // accesses, every key its provisions serve and every setting a served value asks for, and every setting a file