Refuse a file that asks for a setting without saying whether it is trusted from 2026-10-10
mesh/delivery superseded: a newer head of the same pull request
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed

The operator's date (hq issue 339). A test holds the warning before it and the
refusal from it.
This commit is contained in:
jochen
2026-10-09 01:37:43 +02:00
parent b9fc09c375
commit c3ae3f3e09
2 changed files with 29 additions and 1 deletions
+28
View File
@@ -45,3 +45,31 @@ func TestModuleCheckCountsTheUndeclaredAndRefusesThemFromTheDate(t *testing.T) {
t.Errorf("the refusal does not name the resource:\n%s", out.String())
}
}
// A file that asks for a setting says whether it is trusted (novox/hq issue 339): `module check` warns and counts
// it before the date, and refuses it from the date; a file that says so passes either way.
func TestModuleCheckCountsUnsaidTrustAndRefusesItFromTheDate(t *testing.T) {
dir := t.TempDir()
path := filepath.Join(dir, "module.json")
os.WriteFile(path, []byte(`{"module":"power","resources":[
{"id":"logind","type":"file","path":"/etc/systemd/logind.conf.d/power.conf","mode":"0644","trusted":true,
"content":"HandleLidSwitch=${setting:lid}\n"},
{"id":"note","type":"file","path":"/var/lib/power/note","mode":"0644","content":"${setting:greeting}\n"}]}`), 0o600)
defer func() { checkNow = time.Now }()
checkNow = func() time.Time { return catalogue.TrustRequiredFrom.Add(-time.Hour) }
var out bytes.Buffer
if err := moduleCheck([]string{path}, &out); err != nil {
t.Fatalf("refused before the date: %v\n%s", err, out.String())
}
for _, want := range []string{"WARNING: note ask(s) for a setting", UnsaidTrustLine + " 1"} {
if !strings.Contains(out.String(), want) {
t.Errorf("the check does not say %q:\n%s", want, out.String())
}
}
checkNow = func() time.Time { return catalogue.TrustRequiredFrom }
out.Reset()
if err := moduleCheck([]string{path}, &out); err == nil || !strings.Contains(out.String(), "power: the file note asks for a setting") {
t.Fatalf("an unsaid file passed after the date: %v\n%s", err, out.String())
}
}