Merge main (hq ADR 0266) into the mesh-cli answer, and close what the confirmation review found
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery covered: a later merge that contains it was delivered: novox/mesh-controller@14ab2ddd9b49 (merged as 63e85b25 into main, walk plan-17915459…
mesh/merge-gate pass: builds build-agent, mesh-controller, route-proxy → ace, g14, novox, shanks; no bus step; every machine composes with the change as it…
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery covered: a later merge that contains it was delivered: novox/mesh-controller@14ab2ddd9b49 (merged as 63e85b25 into main, walk plan-17915459…
- The generic command verb only reads now (commandReads) and terminal-only commands are refused through any verb (terminalOnly). mesh-cli's ordinary line made neither check: `node account`, `token issue` and `secret export` from another node would have run. It now meets both, in the one function the command verb shares. - The serving controller marks itself and its children never the terminal (ADR 0266); a line mesh-cli runs as the terminal drops that mark and carries MESH_CLI_TERMINAL, so it reads as the terminal it is. - Two withholding tests searched the answer's text while JSON writes bytes as base64, so they held nothing. They search both now, each proved by disabling what it guards (Shown, the bus withholding, `calls` via Get). - The control-node refusal is tested through the assign and unassign acts.
This commit is contained in:
@@ -2,6 +2,7 @@ package link
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"sort"
|
||||
"strings"
|
||||
@@ -203,13 +204,13 @@ func TestAMeshCLIRecordKeepsNeitherItsLineNorItsAnswerOnTheBus(t *testing.T) {
|
||||
asked, _ := json.Marshal(CLIAsked{Line: []string{"settings", "set", "x", `{"password":"s3cret"}`}, Account: "op"})
|
||||
l.serveCall(CLISeat, "laptop", asked, "_INBOX.node.laptop.abcdefghijklmnopqrstuv",
|
||||
func(context.Context, json.RawMessage) (any, error) {
|
||||
return CLIAnswer{Stdout: []byte("token s3cret-join")}, nil
|
||||
return CLIAnswer{Stdout: []byte("s3cret-join")}, nil
|
||||
},
|
||||
a.respond, nil)
|
||||
_ = a.only()
|
||||
close(writes)
|
||||
for c := range writes {
|
||||
if strings.Contains(string(c.Args), "s3cret") || strings.Contains(string(c.Answer), "s3cret") {
|
||||
if carries(c.Args, "s3cret") || carries(c.Answer, "s3cret-join") {
|
||||
t.Fatalf("the bus was sent %s / %s", c.Args, c.Answer)
|
||||
}
|
||||
if !strings.Contains(string(c.Args), "settings") || !strings.Contains(string(c.Args), `"op"`) {
|
||||
@@ -234,7 +235,7 @@ func TestCallsNeverShowsAMeshCLILinesAnswer(t *testing.T) {
|
||||
if err != nil || !found {
|
||||
t.Fatalf("the line is not shown at all: %v %v", found, err)
|
||||
}
|
||||
if strings.Contains(string(shown.Answer), "s3cret-join") {
|
||||
if carries(shown.Answer, "s3cret-join") {
|
||||
t.Fatalf("calls shows a mesh-cli line's answer: %s", shown.Answer)
|
||||
}
|
||||
b := newAnswers(t)
|
||||
@@ -246,3 +247,19 @@ func TestCallsNeverShowsAMeshCLILinesAnswer(t *testing.T) {
|
||||
t.Fatalf("another call's answer is withheld: %s", shown.Answer)
|
||||
}
|
||||
}
|
||||
|
||||
// carries says whether a record holds a secret as text or as the base64 JSON writes bytes in: a line's output is
|
||||
// bytes, so a search for its text alone finds nothing whatever the record keeps (review of ADR 0272).
|
||||
func carries(body []byte, secret string) bool {
|
||||
return strings.Contains(string(body), secret) ||
|
||||
strings.Contains(string(body), base64.StdEncoding.EncodeToString([]byte(secret)))
|
||||
}
|
||||
|
||||
// The two tests above hold what they claim: each fails when the protection it names is taken away.
|
||||
func TestTheWithholdingTestsHoldSomething(t *testing.T) {
|
||||
// The answer as a mesh-cli line's record would carry it, were it kept: the search finds it.
|
||||
body, _ := json.Marshal(map[string]any{"result": CLIAnswer{Stdout: []byte("s3cret-join")}})
|
||||
if !carries(body, "s3cret-join") {
|
||||
t.Fatalf("a record carrying the answer is not found carrying it: %s", body)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user