Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
22845a5296 |
@@ -46,13 +46,6 @@ func assign(ctx context.Context, open *stores, node, module string) (string, err
|
||||
return "", err
|
||||
}
|
||||
defer release()
|
||||
// **Before the new assignment can unsettle a seat somebody holds only by being alone**
|
||||
// (novox/hq 04-ISSUES/170): what the mesh derived so far is written down, and then the
|
||||
// assignment resolves against a record rather than against a coincidence.
|
||||
settled, err := recordDerivedHolders(ctx, open)
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
fresh, err := open.inventory.Assign(ctx, node, module)
|
||||
if err != nil {
|
||||
return "", err
|
||||
@@ -64,9 +57,6 @@ func assign(ctx context.Context, open *stores, node, module string) (string, err
|
||||
node, module), nil
|
||||
}
|
||||
said := fmt.Sprintf("%s is assigned %s", node, module)
|
||||
for _, line := range settled {
|
||||
said += "\n " + line
|
||||
}
|
||||
plan, _, err := planFor(ctx, open, node)
|
||||
if err != nil {
|
||||
// Kept, and still refused. Both halves are the answer, and the rest of the mesh is still
|
||||
|
||||
@@ -556,16 +556,6 @@ type answers struct {
|
||||
// a consequence of the refusals above: a node that does not resolve is not on the network, and
|
||||
// a mesh whose hub is that node has no hub.
|
||||
network string
|
||||
// untaken is, per machine, each assigned module whose resources the machine is holding as it
|
||||
// found them, and how many — a module that was assigned, sent, and is running none of what it
|
||||
// declares because nothing has taken it (novox/hq ADR 0100, 04-ISSUES/125).
|
||||
//
|
||||
// **Its absence cost an outage.** The module was assigned, the push reported success, this
|
||||
// command said the machine was doing everything it was told, and the module's three containers
|
||||
// did not exist. On the strength of those reports the predecessor's proxy was stopped and every
|
||||
// public name on the machine went dark. The holds were correct; they were recorded only in the
|
||||
// machine's own state file, and the one visible symptom was a count that did not add up.
|
||||
untaken map[string]map[string]int
|
||||
}
|
||||
|
||||
// heldBy is every artifact this mesh has built, for a build that may need one as its base.
|
||||
|
||||
@@ -1,92 +0,0 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"sort"
|
||||
|
||||
"github.com/novox/mesh-controller/internal/catalogue"
|
||||
)
|
||||
|
||||
// recordDerivedHolders writes down who holds each mesh-scoped seat that nobody was ever recorded
|
||||
// as holding.
|
||||
//
|
||||
// **A seat held by derivation is a seat held by accident of being alone** (novox/hq
|
||||
// 04-ISSUES/170). ADR 0131 lets a holder on record settle a seat, and lets any other assignment
|
||||
// whose module could hold it stand beside the holder, eligible and silent. But a seat nobody
|
||||
// ever handed over has no record, so its holder is whichever assignment happened to be the sole
|
||||
// claimant — and the day a second one is assigned, both claim, both are refused, and the first
|
||||
// one's whole machine stops resolving. That is what assigning a second postgres did to the
|
||||
// control plane's own store.
|
||||
//
|
||||
// So the mesh writes the derived answer down before it acts on an assignment: for every
|
||||
// mesh-scoped seat with exactly one resolved holder and nothing on record, that holder is
|
||||
// recorded as the standing one — the same record `seat <name> --to <node>/<module>` makes by
|
||||
// hand, made from what the mesh already resolved. A seat with two derived claimants is left
|
||||
// alone: that is the ambiguity a person settles, and recording either would be guessing.
|
||||
//
|
||||
// Node-scoped seats are untouched: a record is one holder per seat, and a node-scoped seat has
|
||||
// one holder per machine (ADR 0121), so there is nothing for a record to settle there.
|
||||
func recordDerivedHolders(ctx context.Context, open *stores) ([]string, error) {
|
||||
inv := open.inventory
|
||||
shelf, err := inv.Catalogue(ctx)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
// exclude nobody: every node's claims, resolved with the holdings on record.
|
||||
world, err := theRestOfTheMesh(ctx, inv, shelf, "")
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
recorded, err := inv.Holdings(ctx)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
// A record is a row against a seat the store knows. A seat it does not — a mesh whose seats
|
||||
// were never seeded, a seat a module declares for itself — stays held by derivation, as it
|
||||
// always was; a missing row is not a reason an assignment fails.
|
||||
known, err := inv.Seats(ctx)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
recordable := map[string]bool{}
|
||||
for _, s := range known {
|
||||
recordable[s.Name] = true
|
||||
}
|
||||
onRecord := map[string]bool{}
|
||||
for _, h := range recorded {
|
||||
if s, ok := catalogue.SeatNamed(h.Claim); ok {
|
||||
onRecord[s.Name] = true
|
||||
}
|
||||
}
|
||||
holders := map[string][]catalogue.Held{}
|
||||
for _, h := range world.Held {
|
||||
if h.Scope != catalogue.ScopeMesh {
|
||||
continue
|
||||
}
|
||||
s, ok := catalogue.SeatNamed(h.Claim)
|
||||
if !ok || onRecord[s.Name] || !recordable[s.Name] {
|
||||
continue
|
||||
}
|
||||
holders[s.Name] = append(holders[s.Name], h)
|
||||
}
|
||||
names := make([]string, 0, len(holders))
|
||||
for name := range holders {
|
||||
names = append(names, name)
|
||||
}
|
||||
sort.Strings(names)
|
||||
var said []string
|
||||
for _, name := range names {
|
||||
if len(holders[name]) != 1 {
|
||||
continue
|
||||
}
|
||||
h := holders[name][0]
|
||||
if err := inv.HoldSeat(ctx, name, catalogue.ScopeMesh, h.Node, h.Module); err != nil {
|
||||
return said, err
|
||||
}
|
||||
said = append(said, fmt.Sprintf(
|
||||
"recorded %s on %s as the standing holder of %s, which it held only by being alone",
|
||||
h.Module, h.Node, name))
|
||||
}
|
||||
return said, nil
|
||||
}
|
||||
@@ -1,110 +0,0 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/novox/mesh-controller/internal/catalogue"
|
||||
)
|
||||
|
||||
// A seat nobody ever handed over is held by whichever assignment happened to be alone — and the
|
||||
// day a second module able to hold it is assigned, both claimed, both were refused, and the first
|
||||
// one's machine stopped resolving (novox/hq 04-ISSUES/170). The mesh now writes the derived holder
|
||||
// down before it acts, so the second assignment stands beside the holder on record.
|
||||
|
||||
func aSeatedStore() catalogue.Manifest {
|
||||
return catalogue.Manifest{Module: "store", Version: "1",
|
||||
Provides: []catalogue.Offer{{Name: "postgres-database", Scope: catalogue.ScopeMesh}},
|
||||
Serves: map[string]map[string]any{"postgres-database": {"port": 5432}},
|
||||
Claims: []catalogue.Claim{{Name: "mesh-store", Scope: catalogue.ScopeMesh}}}
|
||||
}
|
||||
|
||||
func TestASecondEligibleHolderStandsBesideTheOneHeldByBeingAlone(t *testing.T) {
|
||||
open := aMesh(t)
|
||||
ctx := t.Context()
|
||||
// Every deploy seeds the mesh's own seats; a record is a row against one of them.
|
||||
if _, err := open.inventory.SeedSeats(ctx, catalogue.DefaultSeats()); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
register(t, open, aSeatedStore())
|
||||
|
||||
if _, err := assign(ctx, open, "anchor", "store"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
said, err := assign(ctx, open, "laptop", "store")
|
||||
if err != nil {
|
||||
t.Fatalf("a second store, eligible for the seat, was refused:\n%s\n%v", said, err)
|
||||
}
|
||||
if strings.Contains(said, "cannot be worked out") {
|
||||
t.Fatalf("assigning a second store unsettled the first one's machine:\n%s", said)
|
||||
}
|
||||
if !strings.Contains(said, "recorded store on anchor as the standing holder of mesh-store") {
|
||||
t.Fatalf("the holder by derivation was not written down:\n%s", said)
|
||||
}
|
||||
|
||||
holdings, err := open.inventory.Holdings(ctx)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
var found bool
|
||||
for _, h := range holdings {
|
||||
if h.Claim == "mesh-store" {
|
||||
found = true
|
||||
if h.Node != "anchor" || h.Module != "store" {
|
||||
t.Fatalf("mesh-store is recorded on %s/%s, not on the one that held it", h.Node, h.Module)
|
||||
}
|
||||
}
|
||||
}
|
||||
if !found {
|
||||
t.Fatalf("mesh-store has no holder on record after assigning: %v", holdings)
|
||||
}
|
||||
|
||||
// And the record decides from here: the anchor's plan holds the seat, the laptop's does not.
|
||||
for node, holds := range map[string]bool{"anchor": true, "laptop": false} {
|
||||
plan, _, err := planFor(ctx, open, node)
|
||||
if err != nil {
|
||||
t.Fatalf("%s no longer resolves: %v", node, err)
|
||||
}
|
||||
var claimed bool
|
||||
for _, c := range plan.Claims {
|
||||
if c.Claim == "mesh-store" {
|
||||
claimed = true
|
||||
}
|
||||
}
|
||||
if claimed != holds {
|
||||
t.Fatalf("%s holds mesh-store: %v, want %v", node, claimed, holds)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestAHolderOnRecordIsNotRewrittenByDerivation(t *testing.T) {
|
||||
open := aMesh(t)
|
||||
ctx := t.Context()
|
||||
if _, err := open.inventory.SeedSeats(ctx, catalogue.DefaultSeats()); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
register(t, open, aSeatedStore())
|
||||
for _, node := range []string{"anchor", "laptop"} {
|
||||
if _, err := assign(ctx, open, node, "store"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
// A person hands the seat to the laptop. From here the record decides, and what the mesh
|
||||
// derives must never write over it.
|
||||
if err := open.inventory.HoldSeat(ctx, "mesh-store", catalogue.ScopeMesh, "laptop", "store"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
said, err := recordDerivedHolders(ctx, open)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(said) != 0 {
|
||||
t.Fatalf("a seat on record was written again from derivation: %v", said)
|
||||
}
|
||||
holdings, _ := open.inventory.Holdings(ctx)
|
||||
for _, h := range holdings {
|
||||
if h.Claim == "mesh-store" && h.Node != "laptop" {
|
||||
t.Fatalf("the record moved to %s", h.Node)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1,111 +0,0 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/novox/mesh-controller/internal/inventory"
|
||||
)
|
||||
|
||||
// A host refuses a declaration carrying a field it does not know, and refuses it whole — so every new
|
||||
// field is a flag day, and the mesh had no record of which host any machine ran (novox/hq
|
||||
// 04-ISSUES/087). The order was kept by somebody remembering it.
|
||||
|
||||
func TestTheMeshNamesWhichMachinesRunWhichHost(t *testing.T) {
|
||||
split := hostSplit([]inventory.Node{
|
||||
{Name: "anchor", HostVersion: "04a27ca"},
|
||||
{Name: "laptop", HostVersion: "ced54d4"},
|
||||
{Name: "spare", HostVersion: "04a27ca"},
|
||||
})
|
||||
if len(split) != 2 {
|
||||
t.Fatalf("two versions were reported and the split has %d: %v", len(split), split)
|
||||
}
|
||||
if got := strings.Join(split["04a27ca"], ","); got != "anchor,spare" && got != "spare,anchor" {
|
||||
t.Fatalf("04a27ca is held by %q", got)
|
||||
}
|
||||
if got := strings.Join(split["ced54d4"], ","); got != "laptop" {
|
||||
t.Fatalf("ced54d4 is held by %q", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestTheMeshDoesNotClaimWhichHostIsNewer(t *testing.T) {
|
||||
// **The fault this replaced.** A host reports its version as a commit, and commits have no order.
|
||||
// The first version compared them as strings and, on the live mesh, named the three machines
|
||||
// running the NEWER host as the ones behind: `ced54d4` sorts above `04a27ca` and means nothing.
|
||||
//
|
||||
// There is no assertion to make about which is newer, and that is the point — the type says so.
|
||||
// hostSplit returns who runs what, and nothing that could be read as an ordering.
|
||||
split := hostSplit([]inventory.Node{
|
||||
{Name: "old-but-sorts-high", HostVersion: "ced54d4"},
|
||||
{Name: "new-but-sorts-low", HostVersion: "04a27ca"},
|
||||
})
|
||||
for version, machines := range split {
|
||||
if len(machines) != 1 {
|
||||
t.Fatalf("%s is held by %v", version, machines)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestAMachineThatHasNotSaidIsNotAVersion(t *testing.T) {
|
||||
// It may be running anything. Counting it as a version would invent a disagreement; `node show`
|
||||
// says per machine that it has not said.
|
||||
split := hostSplit([]inventory.Node{
|
||||
{Name: "anchor", HostVersion: "04a27ca"},
|
||||
{Name: "quiet"},
|
||||
})
|
||||
if split != nil {
|
||||
t.Fatalf("one reported version and one silence read as a disagreement: %v", split)
|
||||
}
|
||||
}
|
||||
|
||||
func TestMachinesAgreeingOnTheirHostAreNotADisagreement(t *testing.T) {
|
||||
if split := hostSplit([]inventory.Node{
|
||||
{Name: "anchor", HostVersion: "v2"},
|
||||
{Name: "laptop", HostVersion: "v2"},
|
||||
}); split != nil {
|
||||
t.Fatalf("machines agreeing reported a split: %v", split)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAMeshWhereNothingReportedAHostStatesNoDisagreement(t *testing.T) {
|
||||
if split := hostSplit([]inventory.Node{{Name: "anchor"}, {Name: "laptop"}}); split != nil {
|
||||
t.Fatalf("a mesh told no host version reported a split: %v", split)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAReportedHostVersionIsKeptAndReadBack(t *testing.T) {
|
||||
// The machine has sent this since ADR 0141 and the controller's own copy of the report did not
|
||||
// have the field, so it was unmarshalled into nothing. End to end through the store, because the
|
||||
// fault was a field that existed on one side of the wire only.
|
||||
open := aMesh(t)
|
||||
record, err := open.inventory.NodeByName(t.Context(), "anchor")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if record.HostVersion != "" {
|
||||
t.Fatalf("a machine that never reported one has host version %q", record.HostVersion)
|
||||
}
|
||||
if err := open.inventory.RecordHostVersion(t.Context(), record.ID, "ced54d4"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
again, err := open.inventory.NodeByName(t.Context(), "anchor")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if again.HostVersion != "ced54d4" {
|
||||
t.Fatalf("the reported host version read back as %q", again.HostVersion)
|
||||
}
|
||||
// An empty report never clears what a machine last said: a bare word that the node is there says
|
||||
// nothing about its host.
|
||||
if err := open.inventory.RecordHostVersion(t.Context(), record.ID, " "); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
kept, err := open.inventory.NodeByName(t.Context(), "anchor")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if kept.HostVersion != "ced54d4" {
|
||||
t.Fatalf("a report carrying no host version cleared what the machine had said: %q",
|
||||
kept.HostVersion)
|
||||
}
|
||||
}
|
||||
@@ -436,12 +436,6 @@ func showNode(ctx context.Context, inv *inventory.Inventory, name string) error
|
||||
}
|
||||
fmt.Printf("%s\n", node.Name)
|
||||
fmt.Printf(" last heard from %s\n", heardFrom(node))
|
||||
// Which host runs it, as it reported (novox/hq 04-ISSUES/087). Said whenever known, because a
|
||||
// host refuses a declaration carrying a field it does not understand and refuses it WHOLE — so
|
||||
// which host a machine runs is what decides whether the mesh can send it anything new, and
|
||||
// nothing could say it. "not reported" rather than blank: a machine that has not said is a
|
||||
// different thing from one running nothing.
|
||||
fmt.Printf(" host %s\n", orNotReported(node.HostVersion))
|
||||
if err := showMode(ctx, inv, node); err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -492,11 +486,3 @@ func showNode(ctx context.Context, inv *inventory.Inventory, name string) error
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// orNotReported is a fact a machine states about itself, or the fact that it has not.
|
||||
func orNotReported(s string) string {
|
||||
if strings.TrimSpace(s) == "" {
|
||||
return "not reported — this machine has not said since the mesh began keeping it"
|
||||
}
|
||||
return s
|
||||
}
|
||||
|
||||
@@ -338,12 +338,6 @@ func pushCommand(ctx context.Context, args []string) error {
|
||||
sentDigest := map[string]string{}
|
||||
defer release()
|
||||
for _, s := range sending {
|
||||
// Numbered under the hold, one higher than the last, before the body exists — the number is
|
||||
// inside the signed bytes, so a replayed older declaration cannot borrow a newer one's
|
||||
// (novox/hq 04-ISSUES/107).
|
||||
if err := number(ctx, inv, &s); err != nil {
|
||||
return err
|
||||
}
|
||||
body, err := s.declared.Body()
|
||||
if err != nil {
|
||||
return err
|
||||
@@ -570,9 +564,6 @@ func sendRound(ctx context.Context, open *stores, names []string,
|
||||
return compose(held, node)
|
||||
})
|
||||
for _, s := range sending {
|
||||
if err := number(ctx, open.inventory, &s); err != nil {
|
||||
return refused, err
|
||||
}
|
||||
body, err := s.declared.Body()
|
||||
if err != nil {
|
||||
return refused, err
|
||||
@@ -654,9 +645,6 @@ func sendTo(ctx context.Context, open *stores, names []string) error {
|
||||
defer server.Close()
|
||||
|
||||
for _, s := range sending {
|
||||
if err := number(ctx, inv, &s); err != nil {
|
||||
return err
|
||||
}
|
||||
body, err := s.declared.Body()
|
||||
if err != nil {
|
||||
return err
|
||||
@@ -706,12 +694,6 @@ func wouldSend(ctx context.Context, open *stores,
|
||||
if err != nil {
|
||||
continue
|
||||
}
|
||||
// Composed with the number the machine was LAST sent, so this is byte for byte what it was
|
||||
// sent when nothing else changed. A fresh number here would make every machine read as
|
||||
// behind for ever (novox/hq 04-ISSUES/107).
|
||||
if declared.Sequence, err = open.inventory.Sequence(ctx, n.ID); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
body, err := declared.Body()
|
||||
if err != nil {
|
||||
return nil, err
|
||||
@@ -845,17 +827,3 @@ func seatHolders(ctx context.Context, inv *inventory.Inventory) (map[string]brok
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// number gives one send the next sequence for its node (novox/hq 04-ISSUES/107).
|
||||
func number(ctx context.Context, inv *inventory.Inventory, s *readyNode) error {
|
||||
record, err := inv.NodeByName(ctx, s.node)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
seq, err := inv.NextSequence(ctx, record.ID)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
s.declared.Sequence = seq
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -56,23 +56,6 @@ type meshStatus struct {
|
||||
Machines int `json:"machines"`
|
||||
// Adopted is every node still adopted (novox/hq ADR 0100); absent when none is.
|
||||
Adopted []string `json:"adopted,omitempty"`
|
||||
// Untaken is every module assigned to a machine that is holding what it found rather than
|
||||
// running what the module declares, because nothing took it (novox/hq 04-ISSUES/125). Absent
|
||||
// when nothing is held.
|
||||
//
|
||||
// **A document without this said an outage was a well mesh.** Read from what each machine
|
||||
// reported, so it is the machine's account and not the mesh's take-time listing.
|
||||
Untaken []machineUntaken `json:"untaken,omitempty"`
|
||||
}
|
||||
|
||||
// machineUntaken is one module a machine is holding rather than running, and how many resources of
|
||||
// it are held.
|
||||
type machineUntaken struct {
|
||||
Node string `json:"node"`
|
||||
Module string `json:"module"`
|
||||
// Held is how many of the module's resources the machine is keeping as it found them. Zero is
|
||||
// impossible here: a module with nothing held is not in this list.
|
||||
Held int `json:"held"`
|
||||
}
|
||||
|
||||
type machineUnresolved struct {
|
||||
@@ -153,23 +136,6 @@ func statusAsJSON(asked answers) ([]byte, error) {
|
||||
Quiet: []machineQuiet{}, Behind: []moduleBehind{}, Waiting: []machineWaiting{},
|
||||
Reported: []machineReported{}, Unresolved: []machineUnresolved{},
|
||||
Network: asked.network, Adopted: adoptedNodes(nodes)}
|
||||
// In a stated order, so two readings of an unchanged mesh are the same document.
|
||||
untakenNodes := make([]string, 0, len(asked.untaken))
|
||||
for name := range asked.untaken {
|
||||
untakenNodes = append(untakenNodes, name)
|
||||
}
|
||||
sort.Strings(untakenNodes)
|
||||
for _, name := range untakenNodes {
|
||||
modules := make([]string, 0, len(asked.untaken[name]))
|
||||
for m := range asked.untaken[name] {
|
||||
modules = append(modules, m)
|
||||
}
|
||||
sort.Strings(modules)
|
||||
for _, m := range modules {
|
||||
out.Untaken = append(out.Untaken,
|
||||
machineUntaken{Node: name, Module: m, Held: asked.untaken[name][m]})
|
||||
}
|
||||
}
|
||||
for name := range asked.refused {
|
||||
out.Unresolved = append(out.Unresolved, machineUnresolved{
|
||||
Node: name, Problem: asked.refused[name]})
|
||||
|
||||
@@ -18,10 +18,6 @@ import (
|
||||
// make a machine look out of date for ever, or send something `plan` never showed.
|
||||
type sendable struct {
|
||||
Resources []map[string]any
|
||||
// Sequence orders this send against every other to the same node: one higher each time, taken
|
||||
// under the node's hold just before the body is made (novox/hq 04-ISSUES/107). Zero is not sent
|
||||
// at all, which a host reads as "no order claimed" — the shape of every declaration before this.
|
||||
Sequence int64
|
||||
// Adoption is nil for a converged node, and then the body is byte for byte what it was before
|
||||
// adoption existed: an older host parses the envelope strictly and would refuse the key.
|
||||
Adoption *adoptionEnvelope
|
||||
@@ -42,9 +38,6 @@ func (s sendable) Body() ([]byte, error) {
|
||||
if s.Adoption != nil {
|
||||
envelope["adoption"] = s.Adoption
|
||||
}
|
||||
if s.Sequence > 0 {
|
||||
envelope["sequence"] = s.Sequence
|
||||
}
|
||||
// An empty declaration is deliberate here — the node owns nothing the mesh put there
|
||||
// (novox/hq issue 127) — and the host refuses an empty body unless it is told the emptiness
|
||||
// is meant, so a truncated or mis-composed body is never mistaken for "own nothing".
|
||||
|
||||
@@ -1,77 +0,0 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// A declaration's only identity was the digest of its bytes; the controller already held a per-node
|
||||
// lock and recorded each send, so the order existed and was thrown away at the wire (novox/hq
|
||||
// 04-ISSUES/107).
|
||||
|
||||
func TestASendCarriesItsNumberInsideTheSignedBytes(t *testing.T) {
|
||||
body, err := sendable{Resources: []map[string]any{{"id": "x", "type": "file"}}, Sequence: 7}.Body()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
var env map[string]any
|
||||
if err := json.Unmarshal(body, &env); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got, _ := env["sequence"].(float64); got != 7 {
|
||||
t.Fatalf("the body carries sequence %v, wanted 7", env["sequence"])
|
||||
}
|
||||
}
|
||||
|
||||
func TestAnUnnumberedSendIsByteForByteWhatItWasBefore(t *testing.T) {
|
||||
// Zero is not sent at all. A host reads absence as "no order claimed" — the shape of every
|
||||
// declaration before this — so an older host, or the read-only comparison against a machine
|
||||
// sent nothing since sends were numbered, sees exactly the bytes it always saw.
|
||||
body, err := sendable{Resources: []map[string]any{{"id": "x", "type": "file"}}}.Body()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
var env map[string]any
|
||||
if err := json.Unmarshal(body, &env); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, present := env["sequence"]; present {
|
||||
t.Fatalf("a send numbered zero put a sequence on the wire: %s", body)
|
||||
}
|
||||
}
|
||||
|
||||
func TestEachSendToANodeIsOneHigherAndReadable(t *testing.T) {
|
||||
open := aMesh(t)
|
||||
record, err := open.inventory.NodeByName(t.Context(), "anchor")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
// Sent nothing since numbering existed: what it would be sent is composed with zero, which is
|
||||
// not on the wire, which is what it was actually sent.
|
||||
if n, err := open.inventory.Sequence(t.Context(), record.ID); err != nil || n != 0 {
|
||||
t.Fatalf("a fresh node reads sequence %d, %v", n, err)
|
||||
}
|
||||
first, err := open.inventory.NextSequence(t.Context(), record.ID)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
second, err := open.inventory.NextSequence(t.Context(), record.ID)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if first != 1 || second != 2 {
|
||||
t.Fatalf("two sends were numbered %d and %d", first, second)
|
||||
}
|
||||
// And the read path sees the last one taken, so the comparison composes what was sent.
|
||||
if n, err := open.inventory.Sequence(t.Context(), record.ID); err != nil || n != 2 {
|
||||
t.Fatalf("after two sends the node reads sequence %d, %v", n, err)
|
||||
}
|
||||
// Another node counts on its own.
|
||||
other, err := open.inventory.NodeByName(t.Context(), "laptop")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if n, err := open.inventory.NextSequence(t.Context(), other.ID); err != nil || n != 1 {
|
||||
t.Fatalf("a second node's first send was numbered %d, %v", n, err)
|
||||
}
|
||||
}
|
||||
@@ -46,21 +46,15 @@ func statusCommand(ctx context.Context, args []string) error {
|
||||
return err
|
||||
}
|
||||
defer open.Close()
|
||||
return statusFor(ctx, open, *asJSON)
|
||||
}
|
||||
|
||||
// statusFor asks and answers, against stores somebody else opened.
|
||||
//
|
||||
// Split from the command so what it prints can be read by a test. The sentence it prints when nothing
|
||||
// is wrong has been acted on and been misleading (novox/hq 04-ISSUES/145, 125), which makes its exact
|
||||
// words the thing worth holding still.
|
||||
func statusFor(ctx context.Context, open *stores, asJSON bool) error {
|
||||
asked, err := theThreeQuestions(ctx, open)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
wrong, nodes, quiet := asked.wrong, asked.nodes, asked.quiet
|
||||
behind, sources := asked.behind, asked.sources
|
||||
|
||||
if asJSON {
|
||||
if *asJSON {
|
||||
body, err := statusAsJSON(asked)
|
||||
if err != nil {
|
||||
return err
|
||||
@@ -68,18 +62,6 @@ func statusFor(ctx context.Context, open *stores, asJSON bool) error {
|
||||
fmt.Println(string(body))
|
||||
return nil
|
||||
}
|
||||
return printStatus(asked)
|
||||
}
|
||||
|
||||
// printStatus is the words, separated from the questions.
|
||||
//
|
||||
// **Its exact sentences have been acted on and been misleading twice** — a held module reading as a
|
||||
// machine doing what it was told (novox/hq 04-ISSUES/125), and "all doing what they were told" being
|
||||
// true of a mesh in which no module could reach another (04-ISSUES/145). So they are written where a
|
||||
// test can read them without a store, a bus or a machine.
|
||||
func printStatus(asked answers) error {
|
||||
wrong, nodes, quiet := asked.wrong, asked.nodes, asked.quiet
|
||||
behind, sources := asked.behind, asked.sources
|
||||
|
||||
if len(asked.refused) > 0 {
|
||||
// First, above everything else. A machine that cannot be worked out is not running an old
|
||||
@@ -189,65 +171,6 @@ func printStatus(asked answers) error {
|
||||
fmt.Printf("\n `push --behind` sends them\n\n")
|
||||
}
|
||||
|
||||
if split := hostSplit(nodes); len(split) > 1 {
|
||||
// **Before a declaration gains a field, every machine has to understand it** (novox/hq
|
||||
// 04-ISSUES/087). A host refuses a declaration carrying a field it does not know, and refuses
|
||||
// it whole, so every new field is a flag day: hosts first, then the controller. The mesh had
|
||||
// no record of which host any machine ran, so that order was kept by somebody remembering it.
|
||||
//
|
||||
// **Disagreement, and deliberately not "behind".** A host reports its version as a commit, and
|
||||
// commits have no order — the first version of this said "N machines run an older host" and
|
||||
// named the three that were newer, because it compared two hashes as strings. What the mesh
|
||||
// can say truthfully is that the machines do not all run the same host, and which machines
|
||||
// hold which. Ordering needs a version that is ordered, and that is the host's to report.
|
||||
versions := make([]string, 0, len(split))
|
||||
for v := range split {
|
||||
versions = append(versions, v)
|
||||
}
|
||||
sort.Strings(versions)
|
||||
fmt.Printf("%d machine(s) do not all run the same host:\n", len(nodes))
|
||||
for _, v := range versions {
|
||||
sort.Strings(split[v])
|
||||
fmt.Printf(" %-12s %s\n", v, strings.Join(split[v], ", "))
|
||||
}
|
||||
fmt.Printf("\n a host refuses a declaration carrying a field it does not know, whole — so the\n" +
|
||||
" mesh may send only what every one of these understands. Which of them is newer is\n" +
|
||||
" not readable from a commit; that needs a version the host reports as ordered\n\n")
|
||||
}
|
||||
|
||||
if len(asked.untaken) > 0 {
|
||||
// **Before the adopted line, and it breaks "all well".** An adopted machine is a state
|
||||
// somebody chose and can leave alone; a module assigned to one and never taken is work
|
||||
// outstanding that reads exactly like work finished. That reading is what stopped a
|
||||
// predecessor's proxy on the strength of four green surfaces (novox/hq 04-ISSUES/125).
|
||||
machines := make([]string, 0, len(asked.untaken))
|
||||
for name := range asked.untaken {
|
||||
machines = append(machines, name)
|
||||
}
|
||||
sort.Strings(machines)
|
||||
total := 0
|
||||
for _, held := range asked.untaken {
|
||||
for _, n := range held {
|
||||
total += n
|
||||
}
|
||||
}
|
||||
fmt.Printf("%d resource(s) are held as found, because their module was assigned and never "+
|
||||
"taken — so it is running none of what it declares:\n", total)
|
||||
for _, name := range machines {
|
||||
modules := make([]string, 0, len(asked.untaken[name]))
|
||||
for m := range asked.untaken[name] {
|
||||
modules = append(modules, m)
|
||||
}
|
||||
sort.Strings(modules)
|
||||
parts := make([]string, 0, len(modules))
|
||||
for _, m := range modules {
|
||||
parts = append(parts, fmt.Sprintf("%s (%d)", m, asked.untaken[name][m]))
|
||||
}
|
||||
fmt.Printf(" %-12s %s\n", name, strings.Join(parts, ", "))
|
||||
}
|
||||
fmt.Printf("\n `take <node> <module>` compares what runs against what it declares, and runs it\n\n")
|
||||
}
|
||||
|
||||
if adopted := adoptedNodes(nodes); len(adopted) > 0 {
|
||||
// Said, because nothing forces the flip: a node left adopted is visible here rather than
|
||||
// read as converged (novox/hq ADR 0100). Not a fault, so it does not break "all well".
|
||||
@@ -255,23 +178,12 @@ func printStatus(asked answers) error {
|
||||
fmt.Printf("\n `converge <node>` previews the flip\n\n")
|
||||
}
|
||||
|
||||
if asked.well() {
|
||||
if len(wrong) == 0 && len(quiet) == 0 && len(behind) == 0 && len(asked.waiting) == 0 &&
|
||||
len(asked.refused) == 0 && asked.network == "" {
|
||||
// Said plainly. "Nothing to report" and "nothing was checked" must never look the same,
|
||||
// and getting here means every question was asked and answered.
|
||||
fmt.Printf("%d machine(s), all doing what they were told, all heard from, running what "+
|
||||
"the mesh would send them, and every module current with its source\n", len(nodes))
|
||||
// **And what that sentence does not cover**, because for eleven hours it was true of a mesh
|
||||
// in which no module could reach another (novox/hq 04-ISSUES/145). Every question above is
|
||||
// about the relationship between the mesh and a machine — applied what it was sent, matches
|
||||
// what would be sent, built from what the source has. None of them asks whether a module can
|
||||
// reach what it requires, and the mesh composes every one of those grants itself.
|
||||
//
|
||||
// Said here rather than left to be inferred. A reader who acts on the line above is acting on
|
||||
// "the machines are as the mesh described them", and the distance between that and "it works"
|
||||
// is where the eleven hours went.
|
||||
fmt.Printf("\n That is the mesh and the machines agreeing. Nothing here dials a provision:\n" +
|
||||
" no grant the mesh composed has been tested, so a module unable to reach what it\n" +
|
||||
" requires would not appear above (04-ISSUES/145)\n")
|
||||
}
|
||||
return nil
|
||||
}
|
||||
@@ -335,13 +247,6 @@ func theThreeQuestions(ctx context.Context, open *stores) (answers, error) {
|
||||
if err != nil {
|
||||
return answers{}, err
|
||||
}
|
||||
// And what each machine is holding rather than running, by the module that would run it. Read
|
||||
// from what the machine itself last reported, not from what take-time computed: the machine is
|
||||
// the only thing that knows what it found (novox/hq 04-ISSUES/125).
|
||||
out.untaken, err = untakenModules(ctx, inv, out.nodes)
|
||||
if err != nil {
|
||||
return answers{}, err
|
||||
}
|
||||
|
||||
// And which machines are not running what the mesh would send them. The same question as a
|
||||
// module being behind its source, one level down: that one says the catalogue is out of date,
|
||||
@@ -376,82 +281,3 @@ func theThreeQuestions(ctx context.Context, open *stores) (answers, error) {
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// untakenModules is, per machine, each module whose resources that machine is holding as found, and
|
||||
// how many.
|
||||
//
|
||||
// **The machine's own account, not the mesh's.** An adopted node decides at apply time what it found
|
||||
// and reports it; the mesh's take-time listing is a different thing and was the one this command used
|
||||
// to have, which is why a module assigned after the listing showed nothing at all
|
||||
// (novox/hq 04-ISSUES/125).
|
||||
//
|
||||
// A machine that reports no holds contributes nothing, so a converged mesh answers an empty map and
|
||||
// the caller prints nothing.
|
||||
func untakenModules(ctx context.Context, inv *inventory.Inventory, nodes []inventory.Node) (
|
||||
map[string]map[string]int, error) {
|
||||
|
||||
out := map[string]map[string]int{}
|
||||
for _, n := range nodes {
|
||||
said, err := inv.AdoptionOf(ctx, n.Name)
|
||||
if err != nil {
|
||||
// A machine whose record cannot be read is not a machine holding nothing. Said, because
|
||||
// answering "nothing held" from a failed read is the shape this whole issue is about.
|
||||
return nil, fmt.Errorf("what %s is holding cannot be read: %w", n.Name, err)
|
||||
}
|
||||
for _, h := range said.Held {
|
||||
if h.Module == "" {
|
||||
continue // a hold the mesh cannot attribute to a module has nothing to take
|
||||
}
|
||||
if out[n.Name] == nil {
|
||||
out[n.Name] = map[string]int{}
|
||||
}
|
||||
out[n.Name][h.Module]++
|
||||
}
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// well is whether every question this command asks came back with nothing to say.
|
||||
//
|
||||
// Named, and in one place, because it is the sentence an operator acts on and it has been wrong
|
||||
// twice. It is deliberately NOT "nothing is broken": a machine holding what it found is not broken
|
||||
// and is not doing what it was told either.
|
||||
//
|
||||
// **A hold suppresses it; being adopted does not.** Adopted is a mode somebody chose and can leave
|
||||
// alone. A module assigned to a machine and never taken is a half-finished action with nothing left
|
||||
// to finish it — it runs none of what it declares, and "all doing what they were told" was true and
|
||||
// read as success for the whole of the edge cut-over outage (novox/hq 04-ISSUES/125).
|
||||
func (a answers) well() bool {
|
||||
return len(a.wrong) == 0 && len(a.quiet) == 0 && len(a.behind) == 0 &&
|
||||
len(a.waiting) == 0 && len(a.refused) == 0 && a.network == "" && len(a.untaken) == 0
|
||||
}
|
||||
|
||||
// hostSplit is which machines report which host version, for every version more than one machine
|
||||
// could disagree about.
|
||||
//
|
||||
// **It does not say which is newer, because it cannot.** A host reports its version as a commit, and
|
||||
// commits have no order. The first version of this returned "the machines behind the newest" by
|
||||
// comparing versions as strings, and on the live mesh it named the three machines running the NEWER
|
||||
// host as the ones behind — an arbitrary lexicographic result presented as a fact
|
||||
// (novox/hq 04-ISSUES/087). A report that confidently says the opposite of the truth is worse than one
|
||||
// that says less, which is the whole subject of 04-ISSUES/145.
|
||||
//
|
||||
// So this answers what is checkable: who runs what. The reader sees the split and the mesh claims no
|
||||
// ordering. Ordering wants an ordered version, and that is the host's to report rather than this
|
||||
// function's to infer.
|
||||
//
|
||||
// Machines that have not reported a version are left out entirely: they are not a version, and
|
||||
// counting them as one would invent a disagreement. `node show` says per machine that it has not said.
|
||||
func hostSplit(nodes []inventory.Node) map[string][]string {
|
||||
out := map[string][]string{}
|
||||
for _, n := range nodes {
|
||||
if n.HostVersion == "" {
|
||||
continue
|
||||
}
|
||||
out[n.HostVersion] = append(out[n.HostVersion], n.Name)
|
||||
}
|
||||
if len(out) < 2 {
|
||||
return nil // one version, or none reported: nothing to disagree about
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
@@ -1,122 +0,0 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/novox/mesh-controller/internal/inventory"
|
||||
)
|
||||
|
||||
// A module assigned to an adopted machine and never taken runs none of what it declares, and every
|
||||
// surface called that success — a push reporting sent, a journal reporting applied, status reporting
|
||||
// a machine doing what it was told (novox/hq 04-ISSUES/125). The holds were only ever in the
|
||||
// machine's own state file.
|
||||
|
||||
// heldOn makes a machine report that it is holding resources for a module, the way an adopted node
|
||||
// does after an apply.
|
||||
func heldOn(t *testing.T, open *stores, node, module string, ids ...string) {
|
||||
t.Helper()
|
||||
record, err := open.inventory.NodeByName(t.Context(), node)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
held := make([]inventory.Held, 0, len(ids))
|
||||
for _, id := range ids {
|
||||
held = append(held, inventory.Held{ID: id, Module: module, Kind: "container", Target: id})
|
||||
}
|
||||
if err := open.inventory.RecordAdoption(t.Context(), record.ID, held, "ufw", nil); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestStatusNamesAModuleHeldBecauseNothingTookIt(t *testing.T) {
|
||||
open := aMesh(t)
|
||||
heldOn(t, open, "anchor", "route-proxy", "ca", "certs", "server")
|
||||
|
||||
asked, err := theThreeQuestions(t.Context(), open)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got := asked.untaken["anchor"]["route-proxy"]; got != 3 {
|
||||
t.Fatalf("status counted %d resources held for route-proxy, wanted 3", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAHeldModuleStopsTheMeshReadingAsWell(t *testing.T) {
|
||||
// The whole of the fault. "all doing what they were told" was true throughout the outage, and
|
||||
// true is not the same as safe to act on: the machine was doing what it was told, and what it
|
||||
// was told had not started. Asserted against the production condition, not a copy of it.
|
||||
quiet := answers{}
|
||||
if !quiet.well() {
|
||||
t.Fatal("a mesh with nothing to say does not read as well, so nothing below means anything")
|
||||
}
|
||||
holding := answers{untaken: map[string]map[string]int{"anchor": {"route-proxy": 3}}}
|
||||
if holding.well() {
|
||||
t.Fatal("a machine holding a module's resources still reads as doing what it was told, " +
|
||||
"which is the sentence that cost every public name on the machine")
|
||||
}
|
||||
// And being adopted does not suppress it: that is a mode somebody chose, not work outstanding.
|
||||
// Kept as an assertion so the difference between the two is deliberate rather than incidental.
|
||||
if !quiet.well() {
|
||||
t.Fatal("the well condition is not stable")
|
||||
}
|
||||
}
|
||||
|
||||
func TestAHeldModuleIsFoundFromWhatTheMachineReported(t *testing.T) {
|
||||
// End to end through the store, so the condition above is reached by real data and not only by
|
||||
// a constructed value: the machine reports, the mesh records, status asks.
|
||||
open := aMesh(t)
|
||||
heldOn(t, open, "anchor", "route-proxy", "ca", "server")
|
||||
|
||||
asked, err := theThreeQuestions(t.Context(), open)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(asked.untaken) == 0 {
|
||||
t.Fatal("what the machine reported holding did not reach status")
|
||||
}
|
||||
if asked.well() {
|
||||
t.Fatal("a mesh whose machine reported holds reads as well")
|
||||
}
|
||||
}
|
||||
|
||||
func TestTheJSONStatusCarriesWhatIsHeldAndForWhichModule(t *testing.T) {
|
||||
open := aMesh(t)
|
||||
heldOn(t, open, "anchor", "route-proxy", "ca", "certs")
|
||||
|
||||
asked, err := theThreeQuestions(t.Context(), open)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
body, err := statusAsJSON(asked)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
var doc struct {
|
||||
Untaken []struct {
|
||||
Node string `json:"node"`
|
||||
Module string `json:"module"`
|
||||
Held int `json:"held"`
|
||||
} `json:"untaken"`
|
||||
}
|
||||
if err := json.Unmarshal(body, &doc); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(doc.Untaken) != 1 {
|
||||
t.Fatalf("the document carries %d untaken rows, wanted 1: %s", len(doc.Untaken), body)
|
||||
}
|
||||
row := doc.Untaken[0]
|
||||
if row.Node != "anchor" || row.Module != "route-proxy" || row.Held != 2 {
|
||||
t.Fatalf("the row is %+v, wanted anchor/route-proxy/2", row)
|
||||
}
|
||||
// Absent rather than empty when nothing is held, so a well mesh's document does not carry a
|
||||
// field a reader has to interpret.
|
||||
clean, err := statusAsJSON(answers{})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if strings.Contains(string(clean), "untaken") {
|
||||
t.Fatalf("a mesh holding nothing still names untaken: %s", clean)
|
||||
}
|
||||
}
|
||||
@@ -1,75 +0,0 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"io"
|
||||
"os"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/novox/mesh-controller/internal/inventory"
|
||||
)
|
||||
|
||||
// "4 machine(s), all doing what they were told, all heard from, running what the mesh would send
|
||||
// them, and every module current with its source" was true for eleven hours of a mesh in which no
|
||||
// module could reach another (novox/hq 04-ISSUES/145). Every question it answers is about the mesh
|
||||
// and a machine agreeing; none of them dials anything.
|
||||
|
||||
// printed captures what a function writes to stdout.
|
||||
func printed(t *testing.T, f func() error) string {
|
||||
t.Helper()
|
||||
old := os.Stdout
|
||||
r, w, err := os.Pipe()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
os.Stdout = w
|
||||
runErr := f()
|
||||
_ = w.Close()
|
||||
os.Stdout = old
|
||||
var buf bytes.Buffer
|
||||
if _, err := io.Copy(&buf, r); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if runErr != nil {
|
||||
t.Fatal(runErr)
|
||||
}
|
||||
return buf.String()
|
||||
}
|
||||
|
||||
func TestTheAllWellSentenceSaysWhatItDoesNotCover(t *testing.T) {
|
||||
// A mesh with nothing to say. The sentence below was true of a mesh in which no module could
|
||||
// reach another, for eleven hours.
|
||||
got := printed(t, func() error {
|
||||
return printStatus(answers{nodes: []inventory.Node{{Name: "anchor"}, {Name: "laptop"}}})
|
||||
})
|
||||
if !strings.Contains(got, "all doing what they were told") {
|
||||
t.Fatalf("a mesh with nothing to say did not print the all-well sentence:\n%s", got)
|
||||
}
|
||||
// And now says what it is not a claim about.
|
||||
for _, want := range []string{"Nothing here dials a provision", "04-ISSUES/145"} {
|
||||
if !strings.Contains(got, want) {
|
||||
t.Fatalf("the all-well sentence does not say %q:\n%s", want, got)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestAMeshWithSomethingToSayDoesNotPrintTheScopeLine(t *testing.T) {
|
||||
// The scope belongs to the all-well sentence. A mesh with something wrong has specific things to
|
||||
// read, and appending a caveat to those is noise.
|
||||
got := printed(t, func() error {
|
||||
return printStatus(answers{
|
||||
nodes: []inventory.Node{{Name: "anchor"}},
|
||||
untaken: map[string]map[string]int{"anchor": {"route-proxy": 3}},
|
||||
})
|
||||
})
|
||||
if strings.Contains(got, "Nothing here dials a provision") {
|
||||
t.Fatalf("a mesh with a held module printed the all-well scope line:\n%s", got)
|
||||
}
|
||||
if strings.Contains(got, "all doing what they were told") {
|
||||
t.Fatalf("a mesh with a held module printed the all-well sentence:\n%s", got)
|
||||
}
|
||||
if !strings.Contains(got, "route-proxy") {
|
||||
t.Fatalf("the held module is not named:\n%s", got)
|
||||
}
|
||||
}
|
||||
@@ -1,44 +0,0 @@
|
||||
package builder
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/novox/mesh-controller/internal/catalogue"
|
||||
)
|
||||
|
||||
// The name a machine runs a binary by is not always the name of the package that built it. The host's
|
||||
// command is cmd/mesh-host and every machine runs it as nox-mesh-host — the path it is installed at,
|
||||
// the name in its unit, and the name its launcher looks for inside a delivered version.
|
||||
//
|
||||
// A bundle carrying the package's name was delivered to a machine correctly, reported "created … 1
|
||||
// file(s)", and was invisible to the launcher (novox/hq 04-ISSUES/142). Found by reading the delivered
|
||||
// directory rather than by trusting the line that said it worked.
|
||||
|
||||
func TestACompiledArtifactNamesTheBinaryAMachineWillRun(t *testing.T) {
|
||||
got := binaryName(catalogue.Artifact{
|
||||
Name: "host-arch", From: "cmd/mesh-host", Binary: "nox-mesh-host",
|
||||
})
|
||||
if got != "nox-mesh-host" {
|
||||
t.Fatalf("the binary is named %q, and the launcher looks for nox-mesh-host", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSayingNothingKeepsWhatTheCompilerWouldHaveChosen(t *testing.T) {
|
||||
// go build names its output after the package, so an artifact that says nothing gets the same
|
||||
// thing it got before this existed.
|
||||
if got := binaryName(catalogue.Artifact{Name: "host-arch", From: "cmd/mesh-host"}); got != "mesh-host" {
|
||||
t.Fatalf("an artifact naming no binary produced %q", got)
|
||||
}
|
||||
if got := binaryName(catalogue.Artifact{Name: "host-arch", From: "./cmd/agent/"}); got != "agent" {
|
||||
t.Fatalf("a from with slashes produced %q", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestABundleBuiltFromTheModuleRootFallsBackToItsArtifactName(t *testing.T) {
|
||||
// A single-command repository names no package, and `go build -o <dir>` would then write a file
|
||||
// named after the module directory — which is not something the manifest states. The artifact's
|
||||
// own name is what the manifest does state.
|
||||
if got := binaryName(catalogue.Artifact{Name: "tool"}); got != "tool" {
|
||||
t.Fatalf("a bundle built from the root produced %q", got)
|
||||
}
|
||||
}
|
||||
@@ -861,15 +861,6 @@ func compile(ctx context.Context, run Runner, tree string, chain Toolchain,
|
||||
// each other and then be packed together, so each bundle compiles and packs alone.
|
||||
out := Out(a.Name)
|
||||
|
||||
// **The output directory exists before the compiler is told about it.** `tsc --outDir` makes
|
||||
// one; `go build -o` writes a file into a directory and does not create it, failing with a
|
||||
// message about a path rather than about a build. Made here for every toolchain, because which
|
||||
// compilers happen to be forgiving is not a thing a reader should have to know
|
||||
// (novox/hq 04-ISSUES/142).
|
||||
if err := os.MkdirAll(filepath.Join(tree, out), 0o755); err != nil {
|
||||
return "", fmt.Errorf("making the output directory for %s: %w", a.Name, err)
|
||||
}
|
||||
|
||||
invocation := []string{
|
||||
"run", "--rm",
|
||||
"--volume", tree + ":" + within,
|
||||
@@ -877,43 +868,13 @@ func compile(ctx context.Context, run Runner, tree string, chain Toolchain,
|
||||
base,
|
||||
}
|
||||
invocation = append(invocation, chain.Compile...)
|
||||
// **One `-ldflags`, composed here.** A repeated flag is not a merged one: the Go command takes
|
||||
// the last and drops the first, so passing the toolchain's flags and then the system stamp as a
|
||||
// second `-ldflags` produced a binary that knew its system and had lost `-s -w` — half again the
|
||||
// size, with its debug info (novox/hq 04-ISSUES/161).
|
||||
//
|
||||
// What it was built for is the one thing taken from the artifact, and ADR 0142 says why: the
|
||||
// target is a property of the artifact rather than of the recipe. A host with no system refuses
|
||||
// every declaration before it applies anything.
|
||||
linker := append([]string(nil), chain.LinkerFlags...)
|
||||
if chain.SystemStamp != "" && strings.TrimSpace(a.System) != "" {
|
||||
linker = append(linker, "-X", chain.SystemStamp+"="+strings.TrimSpace(a.System))
|
||||
}
|
||||
if len(linker) > 0 {
|
||||
invocation = append(invocation, "-ldflags", strings.Join(linker, " "))
|
||||
}
|
||||
if chain.OutputFlag != "" {
|
||||
// A compiler pointed at a package is told the file to write, not the directory: the name a
|
||||
// machine runs it by is not always the name of the package that built it. The host's command
|
||||
// is `cmd/mesh-host` and every machine runs it as `nox-mesh-host` — so a bundle carrying the
|
||||
// package's name lands correctly, reports success, and is invisible to whatever looks for it
|
||||
// (novox/hq 04-ISSUES/142).
|
||||
target := out
|
||||
if chain.Unit == UnitPackage {
|
||||
target = filepath.Join(out, binaryName(a))
|
||||
}
|
||||
invocation = append(invocation, chain.OutputFlag, target)
|
||||
invocation = append(invocation, chain.OutputFlag, out)
|
||||
}
|
||||
// What to compile. Named by the module rather than discovered, so adding a file does not
|
||||
// silently change what a build produces.
|
||||
switch {
|
||||
case chain.Unit == UnitPackage:
|
||||
// One directory, compiled whole: the thing the artifact is built `from`. Relative, because
|
||||
// the compiler runs with the module's own root as its working directory and a package path
|
||||
// that looked absolute would name one inside the toolchain image.
|
||||
invocation = append(invocation, "./"+strings.Trim(a.From, "./"))
|
||||
case len(a.Entrypoints) > 0:
|
||||
invocation = append(invocation, sourcesFor(a.Entrypoints, out, chain.SourceExt)...)
|
||||
if len(a.Entrypoints) > 0 {
|
||||
invocation = append(invocation, sourcesFor(a.Entrypoints, out)...)
|
||||
}
|
||||
if _, err := run(ctx, tree, "docker", invocation...); err != nil {
|
||||
return "", err
|
||||
@@ -926,16 +887,14 @@ func compile(ctx context.Context, run Runner, tree string, chain Toolchain,
|
||||
// A module names what a tool host should LOAD — compiled paths under the bundle's root — because
|
||||
// that is the thing anything else needs to know. What to compile is the same list with the
|
||||
// language's own extension, which is the toolchain's business rather than the module's.
|
||||
func sourcesFor(entrypoints []string, out, ext string) []string {
|
||||
func sourcesFor(entrypoints []string, out string) []string {
|
||||
sources := make([]string, 0, len(entrypoints))
|
||||
for _, e := range entrypoints {
|
||||
// An entrypoint is named as it will be FOUND — a path inside the unpacked bundle — so the
|
||||
// source is the same path with the output directory taken off the front and the language's
|
||||
// own extension on the end. **The extension is the toolchain's**, where it used to be the
|
||||
// literal `.ts`: one language's file extension written into the code that serves every
|
||||
// language is a wall the next one hits (novox/hq 04-ISSUES/142).
|
||||
// own extension on the end.
|
||||
at := strings.TrimPrefix(strings.TrimPrefix(e, out), "/")
|
||||
sources = append(sources, strings.TrimSuffix(at, filepath.Ext(at))+ext)
|
||||
sources = append(sources, strings.TrimSuffix(at, filepath.Ext(at))+".ts")
|
||||
}
|
||||
return sources
|
||||
}
|
||||
@@ -1091,15 +1050,3 @@ func readBy(manifest catalogue.Manifest) []catalogue.ArtifactContext {
|
||||
})
|
||||
return out
|
||||
}
|
||||
|
||||
// binaryName is what a compiled bundle's executable is called: what the artifact says, or the name of
|
||||
// the package it is built from, which is what a compiler would have chosen anyway.
|
||||
func binaryName(a catalogue.Artifact) string {
|
||||
if name := strings.TrimSpace(a.Binary); name != "" {
|
||||
return name
|
||||
}
|
||||
if from := strings.Trim(a.From, "./"); from != "" {
|
||||
return filepath.Base(from)
|
||||
}
|
||||
return a.Name
|
||||
}
|
||||
|
||||
@@ -1,71 +0,0 @@
|
||||
package builder
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// Nothing could compile the mesh's own components, which is why nothing delivers the host
|
||||
// (novox/hq 04-ISSUES/142, and ADR 0141's own insight naming it). The toolchain list was a closed
|
||||
// set of typescript and python, and two things in the path beyond it assumed TypeScript.
|
||||
|
||||
func TestTheMeshCanCompileGo(t *testing.T) {
|
||||
chain, err := ToolchainFor("go")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
// Named, not pinned: the mesh answers with the copy it holds, so moving compiler is a build
|
||||
// rather than an edit to this source (ADR 0044, 0142).
|
||||
if chain.Base != "mesh-tools-go" || chain.Artifact != "build" {
|
||||
t.Fatalf("the go toolchain is based on %s/%s", chain.Base, chain.Artifact)
|
||||
}
|
||||
joined := strings.Join(chain.Compile, " ")
|
||||
// Static, because what a machine holds is a file and not a container: a binary needing a libc
|
||||
// it did not bring is a delivery that works until a machine differs.
|
||||
if !strings.Contains(joined, "CGO_ENABLED=0") {
|
||||
t.Fatalf("the go toolchain does not build statically: %q", joined)
|
||||
}
|
||||
// Reproducible: a version comes from where a component sits, not from its linker (ADR 0142),
|
||||
// so two builds of one commit should produce the same bytes.
|
||||
if !strings.Contains(joined, "-trimpath") {
|
||||
t.Fatalf("the go toolchain leaves build paths in the binary: %q", joined)
|
||||
}
|
||||
if chain.Unit != UnitPackage {
|
||||
t.Fatalf("the go toolchain compiles %q, wanted a package", chain.Unit)
|
||||
}
|
||||
}
|
||||
|
||||
func TestEveryToolchainSaysWhatItIsPointedAt(t *testing.T) {
|
||||
// The field exists because the compile path used to assume one language. A toolchain that says
|
||||
// nothing would fall through to the entrypoint branch and compile a file list, which for a
|
||||
// compiled language builds a program out of exactly those files and ignores the rest of the
|
||||
// package — a missing symbol rather than a legible refusal.
|
||||
for _, chain := range toolchains {
|
||||
switch chain.Unit {
|
||||
case UnitPackage:
|
||||
case UnitSources:
|
||||
if chain.SourceExt == "" {
|
||||
t.Fatalf("%s compiles a file list and names no source extension", chain.Language)
|
||||
}
|
||||
if !strings.HasPrefix(chain.SourceExt, ".") {
|
||||
t.Fatalf("%s's source extension %q is not an extension", chain.Language, chain.SourceExt)
|
||||
}
|
||||
default:
|
||||
t.Fatalf("%s says it is pointed at %q, which is neither sources nor a package",
|
||||
chain.Language, chain.Unit)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestAnEntrypointBecomesASourceInItsOwnLanguage(t *testing.T) {
|
||||
// It used to become a `.ts` whatever the language was.
|
||||
out := Out("build")
|
||||
got := sourcesFor([]string{out + "/tools/index.js"}, out, ".ts")
|
||||
if len(got) != 1 || got[0] != "tools/index.ts" {
|
||||
t.Fatalf("a typescript entrypoint became %v", got)
|
||||
}
|
||||
got = sourcesFor([]string{out + "/tools/index.js"}, out, ".py")
|
||||
if len(got) != 1 || got[0] != "tools/index.py" {
|
||||
t.Fatalf("a python entrypoint became %v", got)
|
||||
}
|
||||
}
|
||||
@@ -1,76 +0,0 @@
|
||||
package builder
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// A host built without knowing its system refuses every declaration before applying anything —
|
||||
// safely, totally, and with nothing reporting it. The mesh built one, delivered it, started it, and
|
||||
// it would have refused the first thing it was asked to do (novox/hq 04-ISSUES/161).
|
||||
|
||||
func TestTheGoToolchainStampsTheArtifactsSystem(t *testing.T) {
|
||||
chain, err := ToolchainFor("go")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if chain.SystemStamp != "main.builtFor" {
|
||||
t.Fatalf("the go toolchain fills %q", chain.SystemStamp)
|
||||
}
|
||||
}
|
||||
|
||||
func TestALanguageWithNoPinnedSystemStampsNothing(t *testing.T) {
|
||||
// Interpreted output is not pinned to a system, and a manifest declaring one for it is already
|
||||
// refused. Nothing to fill.
|
||||
for _, language := range []string{"typescript", "python"} {
|
||||
chain, err := ToolchainFor(language)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if chain.SystemStamp != "" {
|
||||
t.Fatalf("%s fills %q, and its output is not pinned to a system",
|
||||
language, chain.SystemStamp)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestTheStampIsTheOneThingTakenFromTheArtifact(t *testing.T) {
|
||||
// The toolchain accepts nothing else from the module — anything it could override it would be
|
||||
// writing a Dockerfile to override. The system is the stated exception, because a compiled
|
||||
// binary is per system and the artifact is what declares one (ADR 0142).
|
||||
chain, err := ToolchainFor("go")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
joined := strings.Join(chain.Compile, " ")
|
||||
if strings.Contains(joined, "${") || strings.Contains(joined, "%s") {
|
||||
t.Fatalf("the compile line takes something from the module: %q", joined)
|
||||
}
|
||||
}
|
||||
|
||||
func TestTheLinkerIsToldOnceNotTwice(t *testing.T) {
|
||||
// A repeated flag is not a merged one: the Go command takes the last -ldflags and drops the
|
||||
// first. Passing the toolchain's flags and then the stamp separately produced a binary that knew
|
||||
// its system and had lost -s -w — 12.2MB against 8.5MB, with its debug info (04-ISSUES/161).
|
||||
chain, err := ToolchainFor("go")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
for _, arg := range chain.Compile {
|
||||
if arg == "-ldflags" {
|
||||
t.Fatal("the compile line carries -ldflags, so composing one here makes two")
|
||||
}
|
||||
}
|
||||
if len(chain.LinkerFlags) == 0 {
|
||||
t.Fatal("the go toolchain passes no linker flags, so the binary keeps its debug info")
|
||||
}
|
||||
var stripped bool
|
||||
for _, f := range chain.LinkerFlags {
|
||||
if f == "-s" {
|
||||
stripped = true
|
||||
}
|
||||
}
|
||||
if !stripped {
|
||||
t.Fatalf("the go toolchain does not strip: %v", chain.LinkerFlags)
|
||||
}
|
||||
}
|
||||
@@ -35,50 +35,8 @@ type Toolchain struct {
|
||||
Compile []string
|
||||
// OutputFlag is how this compiler is told where to put its output.
|
||||
OutputFlag string
|
||||
// Unit is what this compiler is pointed at: UnitSources, the entrypoint files the module named,
|
||||
// or UnitPackage, the one directory the artifact is built `from`.
|
||||
//
|
||||
// **The difference is the language and not the module.** A TypeScript bundle is a set of files
|
||||
// compiled into a set of files, so what to compile is the module's entrypoints with their source
|
||||
// extension. A Go bundle is a package compiled into one binary, and there is no per-file
|
||||
// compilation to name — pointing `go build` at a file list builds a program out of exactly those
|
||||
// files and ignores the rest of the package, which fails as a missing symbol rather than as a
|
||||
// wrong instruction.
|
||||
Unit string
|
||||
// SourceExt is the extension an entrypoint has in the repository, for UnitSources. An entrypoint
|
||||
// is named as it will be FOUND, inside the unpacked bundle, so the source is the same path with
|
||||
// the output directory taken off the front and this on the end.
|
||||
SourceExt string
|
||||
// LinkerFlags are passed to the linker as one flag, together with the system stamp below.
|
||||
//
|
||||
// **Separate from Compile because a repeated flag is not a merged one.** They were in the compile
|
||||
// line, and appending the stamp as a second `-ldflags` meant the Go command took the last and
|
||||
// dropped the first — so the binary gained its system and lost `-s -w`, growing by half and
|
||||
// carrying its debug info. The mistake was believing a comment rather than reading the file it
|
||||
// produced (novox/hq 04-ISSUES/161).
|
||||
LinkerFlags []string
|
||||
// SystemStamp is the variable this language's linker fills with the artifact's declared system,
|
||||
// for a language whose binaries are pinned to one at link time (novox/hq ADR 0005).
|
||||
//
|
||||
// **The one thing a toolchain takes from the artifact, and 0142 says why**: the target is a
|
||||
// property of the artifact rather than of the recipe, because a compiled binary is per system
|
||||
// and a toolchain that accepted it from the module would be accepting a build instruction. This
|
||||
// is the narrow exception, named here rather than inferred.
|
||||
//
|
||||
// Empty for a language that compiles to nothing pinned. A host built without it refuses every
|
||||
// declaration before applying anything — safely, totally, and with nothing reporting it
|
||||
// (novox/hq 04-ISSUES/161).
|
||||
SystemStamp string
|
||||
}
|
||||
|
||||
// What a toolchain is pointed at.
|
||||
const (
|
||||
// UnitSources is a list of files, derived from the module's entrypoints.
|
||||
UnitSources = "sources"
|
||||
// UnitPackage is the single directory the artifact is built `from`, compiled whole.
|
||||
UnitPackage = "package"
|
||||
)
|
||||
|
||||
// Out is where one artifact's compiled output lands, inside the module's own directory.
|
||||
//
|
||||
// **Per artifact, never per toolchain.** A module is one piece of software and may still be
|
||||
@@ -113,41 +71,6 @@ var toolchains = []Toolchain{
|
||||
"--target", "ES2022",
|
||||
},
|
||||
OutputFlag: "--outDir",
|
||||
Unit: UnitSources,
|
||||
SourceExt: ".ts",
|
||||
},
|
||||
{
|
||||
Language: "go",
|
||||
Base: "mesh-tools-go",
|
||||
Artifact: "build",
|
||||
// **The mesh's own components, and not modules.** The warning above this list — that every
|
||||
// language is another implementation of the contracts modules share, so adding one commits
|
||||
// to keeping N implementations in step — does not attach here. Go is how the host, the
|
||||
// control plane and the builder are written, and none of them is a module in that sense:
|
||||
// the host is what APPLIES modules. So there is no SDK obligation, and the reason this
|
||||
// entry did not exist was that nothing needed to compile the mesh itself
|
||||
// (novox/hq ADR 0142, and 04-ISSUES/142 where that is why nothing delivers the host).
|
||||
//
|
||||
// Static, because what a machine ends up holding is a file rather than a container, and a
|
||||
// binary that needs a libc it did not bring is a delivery that works until a machine
|
||||
// differs. Trimmed of its own paths for the same reason a version comes from where it sits
|
||||
// rather than from the linker: two builds of one commit produce the same bytes.
|
||||
Compile: []string{
|
||||
"env", "CGO_ENABLED=0", "GOFLAGS=-trimpath",
|
||||
"go", "build",
|
||||
},
|
||||
// Stripped of symbols and debug info: what a machine holds is a file it runs, not one it
|
||||
// debugs, and the difference measured 12.2MB against 8.5MB.
|
||||
LinkerFlags: []string{"-s", "-w"},
|
||||
OutputFlag: "-o",
|
||||
// Pointed at the package the artifact is built `from`, compiled whole. Go writes the binary
|
||||
// into the output directory, named after the package — so the bundle a machine unpacks is a
|
||||
// directory holding one executable, which is what the delivery mechanism expects
|
||||
// (novox/hq ADR 0141).
|
||||
Unit: UnitPackage,
|
||||
// The mesh's own Go components read the system they were built for from this variable, and
|
||||
// refuse to touch a machine without one.
|
||||
SystemStamp: "main.builtFor",
|
||||
},
|
||||
{
|
||||
Language: "python",
|
||||
@@ -159,8 +82,6 @@ var toolchains = []Toolchain{
|
||||
// each actually does.
|
||||
Compile: []string{"python", "-m", "pip", "install", "--no-compile", "--target"},
|
||||
OutputFlag: "",
|
||||
Unit: UnitSources,
|
||||
SourceExt: ".py",
|
||||
},
|
||||
}
|
||||
|
||||
|
||||
@@ -70,6 +70,27 @@ func knownFor(m Manifest, needs []Needed, node string) map[string]map[string]str
|
||||
return out
|
||||
}
|
||||
|
||||
// withOwnNames adds a module's own composed names to what it may name from one binding:
|
||||
// `${bound:<provision>:name}` and `:internal-name`, and for several contributions to one requirement
|
||||
// `:name-<local>` / `:internal-name-<local>`. Set over anything the provider serves under those keys:
|
||||
// what the module is called is the mesh's statement, not the provider's.
|
||||
func withOwnNames(values map[string]string, own map[string]any) {
|
||||
for _, key := range []string{"name", "internal-name"} {
|
||||
if v, ok := own[key].(string); ok {
|
||||
values[key] = v
|
||||
}
|
||||
}
|
||||
many, _ := own["names"].(map[string]any)
|
||||
for local, raw := range many {
|
||||
names, _ := raw.(map[string]any)
|
||||
for _, key := range []string{"name", "internal-name"} {
|
||||
if v, ok := names[key].(string); ok {
|
||||
values[key+"-"+local] = v
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// plainly renders a served value as a program would expect to read it.
|
||||
func plainly(value any) string {
|
||||
switch v := value.(type) {
|
||||
|
||||
@@ -94,43 +94,12 @@ func (m Manifest) Resolve(built []Built) (Manifest, error) {
|
||||
m.Module, r["id"], named)
|
||||
case ArtifactImage, ArtifactUpstream:
|
||||
filled["image"] = artifact.Reference
|
||||
// An image is not unpacked anywhere, so it has no directory to be named for its
|
||||
// version and `${version}` has nothing to mean. Refused rather than left as literal
|
||||
// text in a path, which is how it would reach a machine and be created as a directory
|
||||
// called `${version}`.
|
||||
for key, value := range filled {
|
||||
if text, isText := value.(string); isText && strings.Contains(text, versionRef) {
|
||||
return Manifest{}, fmt.Errorf(
|
||||
"%s: %v says %s in %q, and %q is an image — an image is not unpacked, so "+
|
||||
"it has no versioned place. %s is for an archive or a bundle",
|
||||
m.Module, r["id"], versionRef, key, named, versionRef)
|
||||
}
|
||||
}
|
||||
case ArtifactArchive, ArtifactBundle:
|
||||
// The same on the wire: both are bytes fetched by digest and unpacked. They differ in
|
||||
// how they were made — one packed as it stood, the other compiled first — and a
|
||||
// machine has no reason to care which.
|
||||
filled["source"] = artifact.Reference
|
||||
filled["digest"] = artifact.Digest
|
||||
// **And `${version}`, so a resource can name a place that is this build's alone**
|
||||
// (novox/hq ADR 0141, 04-ISSUES/142). A component is unpacked into a directory named
|
||||
// for its version so it can read its own version from its path — and until this,
|
||||
// nothing could compose that path: an archive named a fixed one in the manifest and
|
||||
// nothing interpolated the build into it, so nothing could ask for
|
||||
// `…/versions/<version>/` and every machine took a hand-placed fallback.
|
||||
//
|
||||
// The version is the artifact's own digest, short. Not the commit: two builds of one
|
||||
// commit are meant to be the same bytes (the toolchains are `-trimpath` for this), and
|
||||
// a content-addressed version means an unchanged build resolves to the path it already
|
||||
// had — so re-composing a declaration moves nothing, where a commit would move the
|
||||
// path of an identical binary and recreate everything that reads it.
|
||||
for key, value := range filled {
|
||||
text, isText := value.(string)
|
||||
if !isText || !strings.Contains(text, versionRef) {
|
||||
continue
|
||||
}
|
||||
filled[key] = strings.ReplaceAll(text, versionRef, versionOf(artifact.Digest))
|
||||
}
|
||||
default:
|
||||
return Manifest{}, fmt.Errorf("%s: %q is a %q, and an artifact is %q, %q, %q or %q",
|
||||
m.Module, named, artifact.Kind, ArtifactImage, ArtifactArchive, ArtifactUpstream,
|
||||
@@ -173,14 +142,7 @@ func (b *Build) problems(module string) []string {
|
||||
// is which compiler — because the mesh chooses that, and cannot choose for a module that
|
||||
// has not said.
|
||||
if a.Kind == ArtifactBundle || a.Kind == ArtifactPackage {
|
||||
// **Except for a language that compiles to a binary, where it names which one**
|
||||
// (novox/hq 04-ISSUES/142). A bundle in an interpreted language is the module's own
|
||||
// directory compiled whole, and naming a source would be describing its own build. A
|
||||
// repository written in a compiled language holds several commands — the host and its
|
||||
// bootstrap live in one, and the mesh needs the host — and "the module's own directory"
|
||||
// is then not a package at all. So the compiled case may say which package, and says
|
||||
// the module root by saying nothing.
|
||||
if a.From != "" && !compilesToABinary(a.Language) {
|
||||
if a.From != "" {
|
||||
problems = append(problems, fmt.Sprintf(
|
||||
"%s: %q is a bundle and names what it is built from (%q). A bundle is built "+
|
||||
"from the module's own directory; what it says is the language",
|
||||
@@ -290,28 +252,3 @@ func compilesToABinary(language string) bool {
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
// versionRef is how a resource names the version of the artifact it uses: ${version}.
|
||||
//
|
||||
// No artifact name in it, because the resource already says which artifact it is for — a second
|
||||
// name would be a second thing to keep in step with the first.
|
||||
const versionRef = "${version}"
|
||||
|
||||
// versionOf is an artifact's version as a path names it: its digest, short.
|
||||
//
|
||||
// **Content-addressed on purpose.** The alternative is the commit a build came from, and two builds
|
||||
// of one commit are meant to produce the same bytes — every toolchain here is `-trimpath` for that
|
||||
// reason. A commit-named path would move for an identical binary, and everything reading that path
|
||||
// would be recreated for a change that is not one. A digest-named path moves exactly when the bytes
|
||||
// do.
|
||||
//
|
||||
// Twelve hex characters: enough that two of this mesh's builds will not collide, short enough to
|
||||
// read in a path and in a journal line. The `sha256:` prefix goes, because a directory name carrying
|
||||
// a colon is a directory name people quote wrong.
|
||||
func versionOf(digest string) string {
|
||||
hex := strings.TrimPrefix(strings.TrimSpace(digest), "sha256:")
|
||||
if len(hex) > 12 {
|
||||
return hex[:12]
|
||||
}
|
||||
return hex
|
||||
}
|
||||
|
||||
@@ -574,7 +574,11 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
|
||||
}
|
||||
found = here
|
||||
}
|
||||
file, err := boundFile(*found, m.Binds[to], ConsumerIdentity(r.Node, IdentitySource(m.Slug, m.Module)))
|
||||
own, err := r.ownNames(m, to, with.Settings[m.Module])
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
file, err := boundFile(*found, m.Binds[to], ConsumerIdentity(r.Node, IdentitySource(m.Slug, m.Module)), own)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -618,15 +622,17 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
|
||||
// merging earlier would throw away the files it still needs.
|
||||
resources = append(append([]map[string]any{}, first...), resources...)
|
||||
|
||||
// No container is given the mesh's names (novox/hq ADR 0148). It used to be: every
|
||||
// container got the whole roster as `--add-host` entries at creation, and a name that
|
||||
// moved afterwards was wrong inside it for as long as it ran (issues 109, 135) — and once
|
||||
// the roster was made part of a container's identity so that could be caught, one name
|
||||
// moving anywhere replaced every container in the mesh (issue 151). A container resolves a
|
||||
// mesh name through its machine's resolver at the moment it asks, which the runtime is
|
||||
// told once per machine, as a file, by the resolver's own module. The names a module
|
||||
// declares for itself are its own and stay exactly as written: they are part of what the
|
||||
// module is, and the mesh does not know what they mean.
|
||||
// Every container is given the mesh's names. Not a choice a module makes: a module that
|
||||
// listed them would go stale the day a machine joins, and one that did not would be a
|
||||
// module whose containers cannot reach anything by name.
|
||||
//
|
||||
// A container that was given names of its own keeps them and gets the mesh's beside them:
|
||||
// the mesh does not know what else a workload needs to reach, and taking something away
|
||||
// to add something is not what "also" means.
|
||||
if len(with.Names) > 0 {
|
||||
resources = withMeshNames(resources, with.Names)
|
||||
}
|
||||
|
||||
// What this module may name from inside one of its own files. Gathered once per module
|
||||
// rather than per file, because it is a fact about the module.
|
||||
sealed, err := sealedFor(m, r.Needs, with)
|
||||
@@ -635,6 +641,35 @@ func (r Resolution) compose(with Rendering, owner map[string]string) ([]map[stri
|
||||
}
|
||||
// And what its bindings say, for the half of a connection that is not secret.
|
||||
known := knownFor(m, r.Needs, r.Node)
|
||||
// A requirement answered on this same machine is not in r.Needs — its binding file is
|
||||
// written from `here` (above) — and so `${bound:…}` could not name it, though the file
|
||||
// beside it said the same facts. Filled from the same answer, so the two cannot disagree.
|
||||
for _, want := range m.Wants() {
|
||||
if _, has := known[want]; has {
|
||||
continue
|
||||
}
|
||||
answered, err := here(r, want, with)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if answered == nil {
|
||||
continue
|
||||
}
|
||||
local := *answered
|
||||
local.For = m.Module
|
||||
for provision, values := range knownFor(m, []Needed{local}, r.Node) {
|
||||
known[provision] = values
|
||||
}
|
||||
}
|
||||
// And what the module is called through each requirement it contributes to (novox/hq
|
||||
// 04-ISSUES/122) — the same composition its binding file carries.
|
||||
for provision, values := range known {
|
||||
own, err := r.ownNames(m, provision, with.Settings[m.Module])
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
withOwnNames(values, own)
|
||||
}
|
||||
// And where this node places the directories the module declared without a path
|
||||
// (novox/hq ADR 0112) — resolved once per module, named by ${dir:…} from any resource.
|
||||
dirs := dirsFor(m, with)
|
||||
@@ -1087,21 +1122,11 @@ func (r Resolution) contributions(settings SettingsBy, grants []Grant,
|
||||
// Settings reach a contribution the same way they reach a file. A route's hostname is
|
||||
// exactly the kind of thing that differs between one mesh and the next, and a module
|
||||
// that could not have it set would have to be edited to be reused.
|
||||
values, err := settle(m.Contributes[to], settings[m.Module], nil,
|
||||
values, err := r.composed(m, m.Contributes[to], settings[m.Module],
|
||||
m.Module+" contributing to "+to)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("%s contributing to %s: %w", m.Module, to, err)
|
||||
return nil, err
|
||||
}
|
||||
reaches, err := Reaches(m, settings[m.Module])
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("%s contributing to %s: %w", m.Module, to, err)
|
||||
}
|
||||
blocks, err := Endpoints(m, settings[m.Module])
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("%s contributing to %s: %w", m.Module, to, err)
|
||||
}
|
||||
portOfEndpoint(values, endpointPorts(m))
|
||||
composeName(values, r.PublicDomain, servingAt(r, to), reaches, endpointPorts(m), blocks)
|
||||
out[to] = append(out[to], Contribution{From: m.Module, Values: values})
|
||||
}
|
||||
// Several contributions to one requirement (ADR 0094's sibling for `contributes`): an
|
||||
@@ -1110,21 +1135,11 @@ func (r Resolution) contributions(settings SettingsBy, grants []Grant,
|
||||
// name always reaches the provider from here.
|
||||
for _, to := range sortedKeys(m.ContributesMany) {
|
||||
for _, local := range sortedKeys(m.ContributesMany[to]) {
|
||||
values, err := settle(m.ContributesMany[to][local], settings[m.Module], nil,
|
||||
values, err := r.composed(m, m.ContributesMany[to][local], settings[m.Module],
|
||||
m.Module+" contributing "+local+" to "+to)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("%s contributing %s to %s: %w", m.Module, local, to, err)
|
||||
return nil, err
|
||||
}
|
||||
reaches, err := Reaches(m, settings[m.Module])
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("%s contributing %s to %s: %w", m.Module, local, to, err)
|
||||
}
|
||||
blocks, err := Endpoints(m, settings[m.Module])
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("%s contributing %s to %s: %w", m.Module, local, to, err)
|
||||
}
|
||||
portOfEndpoint(values, endpointPorts(m))
|
||||
composeName(values, r.PublicDomain, servingAt(r, to), reaches, endpointPorts(m), blocks)
|
||||
out[to] = append(out[to], Contribution{From: m.Module, Values: values})
|
||||
}
|
||||
}
|
||||
@@ -1132,6 +1147,82 @@ func (r Resolution) contributions(settings SettingsBy, grants []Grant,
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// composed is one contribution as its provider receives it: settled with this node's settings, its
|
||||
// endpoint's port filled in, and its names composed from the label.
|
||||
//
|
||||
// **One function, because two readers must agree.** The provider is told the names in its received
|
||||
// file; the contributing module is told the same names in its own binding (novox/hq 04-ISSUES/122).
|
||||
// Composing them twice, in two places, is how the proxy would come to serve one name while the
|
||||
// module wrote another into its configuration.
|
||||
func (r Resolution) composed(m Manifest, raw map[string]any, layers []Layer, what string) (
|
||||
map[string]any, error) {
|
||||
values, err := settle(raw, layers, nil, what)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("%s: %w", what, err)
|
||||
}
|
||||
reaches, err := Reaches(m, layers)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("%s: %w", what, err)
|
||||
}
|
||||
blocks, err := Endpoints(m, layers)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("%s: %w", what, err)
|
||||
}
|
||||
portOfEndpoint(values, endpointPorts(m))
|
||||
composeName(values, r.PublicDomain, r.At, reaches, endpointPorts(m), blocks)
|
||||
return values, nil
|
||||
}
|
||||
|
||||
// ownNames is what a module is known by through what it contributes to one requirement — the names
|
||||
// the mesh composed for it, and nothing else of the contribution.
|
||||
//
|
||||
// **The half a module could not learn** (novox/hq 04-ISSUES/122). A module contributes a label, the
|
||||
// mesh joins it with this node's domains, and the provider serves the result — and the module itself
|
||||
// was never told. Software that must know its own address (a login redirect, a canonical URL, an
|
||||
// issuer) had it written into the manifest as a literal, which is a domain in a definition and wrong
|
||||
// on every other machine. `${bound:<requirement>:name}` is the answer, from the same composition the
|
||||
// provider receives.
|
||||
//
|
||||
// Several contributions to one requirement are keyed by their local name under `names`.
|
||||
func (r Resolution) ownNames(m Manifest, to string, layers []Layer) (map[string]any, error) {
|
||||
pick := func(values map[string]any) map[string]any {
|
||||
names := map[string]any{}
|
||||
for _, key := range []string{"name", "internal-name"} {
|
||||
if v, ok := values[key].(string); ok && v != "" {
|
||||
names[key] = v
|
||||
}
|
||||
}
|
||||
return names
|
||||
}
|
||||
out := map[string]any{}
|
||||
if raw, ok := m.Contributes[to]; ok {
|
||||
values, err := r.composed(m, raw, layers, m.Module+" contributing to "+to)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
for k, v := range pick(values) {
|
||||
out[k] = v
|
||||
}
|
||||
}
|
||||
if locals := m.ContributesMany[to]; len(locals) > 0 {
|
||||
many := map[string]any{}
|
||||
for _, local := range sortedKeys(locals) {
|
||||
values, err := r.composed(m, locals[local], layers,
|
||||
m.Module+" contributing "+local+" to "+to)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if names := pick(values); len(names) > 0 {
|
||||
many[local] = names
|
||||
}
|
||||
}
|
||||
if len(many) > 0 {
|
||||
out["names"] = many
|
||||
}
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// composeName joins a contribution's label with a node's public domain, and separately with its
|
||||
// private one, in place (novox/hq ADR 0056).
|
||||
//
|
||||
@@ -1224,24 +1315,6 @@ func composeName(values map[string]any, publicDomain, internalDomain string, rea
|
||||
}
|
||||
}
|
||||
|
||||
// servingAt is the private-network name of the node a contribution to `to` arrives at: the
|
||||
// provider's, when the provision is answered elsewhere, and this machine's own when it is answered
|
||||
// here or not yet settled.
|
||||
//
|
||||
// A route's internal name is composed under it (novox/hq ADR 0151, issue 139). `<label>.<node>.internal`
|
||||
// is answered by every machine's resolver as *anything under that node's name goes to that node* —
|
||||
// so the node in the name has to be the one whose proxy answers, or the name sends a client to a
|
||||
// machine with nothing listening while the public name, published at the serving node's address,
|
||||
// works. Where the proxy runs beside the module the two are the same machine and nothing changes.
|
||||
func servingAt(r Resolution, to string) string {
|
||||
for _, n := range r.Needs {
|
||||
if n.Name == to && n.At != "" {
|
||||
return n.At
|
||||
}
|
||||
}
|
||||
return r.At
|
||||
}
|
||||
|
||||
// receivedFile is the file a provider is given its consumers' contributions in.
|
||||
func receivedFile(requirement, path string, given []Contribution) (map[string]any, error) {
|
||||
if given == nil {
|
||||
@@ -1346,14 +1419,14 @@ func sortedKeys[V any](m map[string]V) []string {
|
||||
// Where it is and what the providing module said about using it. **No credential**, and the file
|
||||
// says so rather than leaving a reader to wonder whether one was meant to be there — a missing
|
||||
// field looks like a bug, and a stated absence looks like a boundary.
|
||||
func boundFile(n Needed, path, as string) (map[string]any, error) {
|
||||
func boundFile(n Needed, path, as string, own map[string]any) (map[string]any, error) {
|
||||
// A record has no machine and no address. Saying so is the difference between a reader
|
||||
// concluding "somewhere with no address" and concluding the mesh failed to fill something in.
|
||||
where := any(n.At)
|
||||
if n.ByRecord {
|
||||
where = "a record in this mesh, not a machine"
|
||||
}
|
||||
body, err := json.MarshalIndent(map[string]any{
|
||||
doc := map[string]any{
|
||||
"binding": 1,
|
||||
"provision": n.Name,
|
||||
"from": n.From,
|
||||
@@ -1369,7 +1442,14 @@ func boundFile(n Needed, path, as string) (map[string]any, error) {
|
||||
"generated": "by the mesh — do not edit; replaced whenever this changes. " +
|
||||
"The credential is not here: it is sealed, in the file this module's manifest " +
|
||||
"names under `secrets`",
|
||||
}, "", " ")
|
||||
}
|
||||
// **What this module is called through what it contributes here** (novox/hq 04-ISSUES/122):
|
||||
// `name`, `internal-name`, or `names` by local name — composed exactly as the provider receives
|
||||
// them. Absent when the module contributes nothing named, rather than written empty.
|
||||
for key, value := range own {
|
||||
doc[key] = value
|
||||
}
|
||||
body, err := json.MarshalIndent(doc, "", " ")
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -1498,6 +1578,43 @@ func (r Resolution) servedOnThisMachine(provision string, with Rendering) (map[s
|
||||
return nil, false, nil
|
||||
}
|
||||
|
||||
// withMeshNames gives every container in a set the mesh's names.
|
||||
//
|
||||
// Copied rather than edited in place: these maps come from a module's manifest, and mutating one
|
||||
// would change what the catalogue holds for every other machine running that module.
|
||||
//
|
||||
// A host-network container gets the names too. It was once skipped, on the belief that it "shares
|
||||
// the machine's hosts file already" — but it does not: `docker run --network host` still gives the
|
||||
// container its own /etc/hosts (localhost and its own id only), so every `<node>.internal` name the
|
||||
// mesh wrote for the machine is invisible inside it, and a client that dials one gets EAI_AGAIN. The
|
||||
// remedy is the same `--add-host` every other container gets — the runtime accepts it with
|
||||
// `--network host` (verified), and without it a host-network consumer cannot reach a provider by the
|
||||
// `.internal` address the mesh hands it as `${bound:...:at}`.
|
||||
func withMeshNames(resources []map[string]any, names map[string]string) []map[string]any {
|
||||
out := make([]map[string]any, 0, len(resources))
|
||||
for _, r := range resources {
|
||||
if r["type"] != "container" {
|
||||
out = append(out, r)
|
||||
continue
|
||||
}
|
||||
|
||||
copied := map[string]any{}
|
||||
for k, v := range r {
|
||||
copied[k] = v
|
||||
}
|
||||
var given []any
|
||||
if already, ok := copied["hosts"].([]any); ok {
|
||||
given = append(given, already...)
|
||||
}
|
||||
for _, name := range sortedKeys(names) {
|
||||
given = append(given, name+":"+names[name])
|
||||
}
|
||||
copied["hosts"] = given
|
||||
out = append(out, copied)
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// pinned refuses an image that is not really pinned, on its way to a machine.
|
||||
//
|
||||
// **Here and not at parse** (novox/hq 04-ISSUES/025). A manifest in a repository names artifacts
|
||||
|
||||
@@ -1,37 +0,0 @@
|
||||
package catalogue
|
||||
|
||||
import "testing"
|
||||
|
||||
// A bundle is the module's own directory compiled whole, and naming a source would be describing its
|
||||
// own build. That holds for an interpreted language and cannot hold for a compiled one: a repository
|
||||
// written in Go carries several commands — the host and its bootstrap live in one — and "the module's
|
||||
// own directory" is then not a package at all (novox/hq 04-ISSUES/142).
|
||||
|
||||
func TestAGoBundleMayNameItsCommand(t *testing.T) {
|
||||
b := &Build{Artifacts: []Artifact{{
|
||||
Name: "host-arch", Kind: ArtifactBundle, Language: "go", System: "arch",
|
||||
From: "cmd/mesh-host",
|
||||
}}}
|
||||
if p := b.problems("mesh-host"); len(p) != 0 {
|
||||
t.Fatalf("a go bundle naming its command was refused: %v", p)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAnInterpretedBundleStillMayNotNameASource(t *testing.T) {
|
||||
b := &Build{Artifacts: []Artifact{{
|
||||
Name: "tools", Kind: ArtifactBundle, Language: "typescript", From: "src",
|
||||
}}}
|
||||
p := b.problems("something")
|
||||
if len(p) == 0 {
|
||||
t.Fatal("an interpreted bundle naming what it is built from was accepted")
|
||||
}
|
||||
}
|
||||
|
||||
func TestACompiledBundleStillMustSayItsSystem(t *testing.T) {
|
||||
b := &Build{Artifacts: []Artifact{{
|
||||
Name: "host", Kind: ArtifactBundle, Language: "go", From: "cmd/mesh-host",
|
||||
}}}
|
||||
if len(b.problems("mesh-host")) == 0 {
|
||||
t.Fatal("a compiled bundle with no system was accepted")
|
||||
}
|
||||
}
|
||||
@@ -158,16 +158,3 @@ func TestAStoreRowWithoutAProtocolKeepsTheCompiledOne(t *testing.T) {
|
||||
t.Fatalf("the store's own columns were not kept: %+v", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestARefusalWithNothingOnRecordNamesTheHandover(t *testing.T) {
|
||||
busSeatDelivering(t, "mesh-bus")
|
||||
elsewhere := []Held{{Claim: "mesh-broker", Scope: ScopeMesh, Node: "anchor", Module: "old-broker"}}
|
||||
|
||||
_, problems := checkClaims([]Manifest{newBroker()}, Node{Name: "laptop"}, elsewhere, nil)
|
||||
if len(problems) != 1 {
|
||||
t.Fatalf("two derived claimants across machines were not refused: %v", problems)
|
||||
}
|
||||
if !strings.Contains(problems[0], "`seat mesh-broker --to anchor/old-broker`") {
|
||||
t.Fatalf("the refusal does not name the handover that records the holder: %s", problems[0])
|
||||
}
|
||||
}
|
||||
|
||||
@@ -597,16 +597,6 @@ type Artifact struct {
|
||||
// Empty for every other kind, which do not compile.
|
||||
Language string `json:"language,omitempty"`
|
||||
|
||||
// Binary is what the compiled executable is called, for a bundle in a language that compiles to
|
||||
// one. Empty means the package's own name, which is what a compiler does by default.
|
||||
//
|
||||
// **Because the name a machine runs it by is not always the name of the package that built it.**
|
||||
// The host's command is `cmd/mesh-host` and every machine runs it as `nox-mesh-host` — the path
|
||||
// it is installed at, the name in its unit, and the name its launcher looks for inside a
|
||||
// delivered version. A bundle that carried the package's name was delivered correctly, reported
|
||||
// success, and was invisible to the launcher (novox/hq 04-ISSUES/142).
|
||||
Binary string `json:"binary,omitempty"`
|
||||
|
||||
// Entrypoints are the compiled files a tool host should load from this module, relative to the
|
||||
// bundle's root.
|
||||
//
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
package catalogue
|
||||
|
||||
import (
|
||||
"reflect"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
@@ -31,38 +30,36 @@ func namesOf(r map[string]any) []string {
|
||||
return out
|
||||
}
|
||||
|
||||
// No mesh name is written into a container (novox/hq ADR 0148). It resolves them through its
|
||||
// machine's resolver at the moment it asks, so a name that moves is answered differently by the
|
||||
// next lookup, in every container, with nothing recreated.
|
||||
// A container does not inherit the machine's names, so the mesh gives them to it.
|
||||
//
|
||||
// Checked the way the record says: the declaration a container gets does not move when the mesh's
|
||||
// roster does. A roster with one machine and a roster with three produce the same container, byte
|
||||
// for byte, so the digest a host computes from it cannot move either — which is what stopped one
|
||||
// name moving from replacing every container in the mesh (issue 151).
|
||||
func TestAContainerIsTheSameWhateverTheMeshsRosterSays(t *testing.T) {
|
||||
module := Manifest{Module: "app", Resources: []map[string]any{{"id": "web", "type": "container",
|
||||
"name": "web", "image": "registry.example/web@sha256:" + strings.Repeat("a", 64)}}}
|
||||
one := containersOf(t, Resolution{Node: "laptop", Modules: []Manifest{module}},
|
||||
Rendering{Names: map[string]string{"laptop.internal": "10.42.0.2"}})
|
||||
three := containersOf(t, Resolution{Node: "laptop", Modules: []Manifest{module}},
|
||||
Rendering{Names: map[string]string{
|
||||
"anchor.internal": "10.42.0.1", "laptop.internal": "10.42.0.2", "git.example.tld": "10.42.0.1",
|
||||
}})
|
||||
if len(one) != 1 || len(three) != 1 {
|
||||
t.Fatalf("expected one container each, got %d and %d", len(one), len(three))
|
||||
// It gets its own hosts file holding only its own hostname — every internal name the mesh wrote
|
||||
// for the machine is invisible to what the machine runs. A database client on one node could not
|
||||
// resolve another node, on a mesh where both names were correct and present on both machines.
|
||||
func TestEveryContainerIsGivenTheMeshsNames(t *testing.T) {
|
||||
got := containersOf(t, Resolution{Node: "laptop", Modules: []Manifest{{
|
||||
Module: "app",
|
||||
Resources: []map[string]any{{"id": "web", "type": "container", "name": "web",
|
||||
"image": "registry.example/web@sha256:" + strings.Repeat("a", 64)}},
|
||||
}}}, Rendering{Names: map[string]string{
|
||||
"anchor.internal": "10.42.0.1", "laptop.internal": "10.42.0.2",
|
||||
}})
|
||||
if len(got) != 1 {
|
||||
t.Fatalf("expected one container, got %d", len(got))
|
||||
}
|
||||
if given := namesOf(three[0]); len(given) != 0 {
|
||||
t.Fatalf("the mesh's names were copied into the container: %v", given)
|
||||
given := namesOf(got[0])
|
||||
if len(given) != 2 {
|
||||
t.Fatalf("the container was given %d name(s): %v", len(given), given)
|
||||
}
|
||||
if !reflect.DeepEqual(one[0], three[0]) {
|
||||
t.Fatalf("the container moved with the roster:\n%v\n%v", one[0], three[0])
|
||||
if given[0] != "anchor.internal:10.42.0.1" {
|
||||
t.Fatalf("the name is not in the form a runtime writes: %v", given)
|
||||
}
|
||||
}
|
||||
|
||||
// The names a module declares for itself are its own: part of what the module is, kept exactly as
|
||||
// written, and the mesh does not know what they mean. They are the one thing in a container's
|
||||
// hosts that does move its identity, because they do not move when the mesh's roster does.
|
||||
func TestAContainersOwnNamesAreKeptAsWritten(t *testing.T) {
|
||||
// A container that named its own keeps them and gets the mesh's beside them.
|
||||
//
|
||||
// The mesh does not know what else a workload needs to reach, and taking something away in order
|
||||
// to add something is not what "also" means.
|
||||
func TestAContainersOwnNamesAreKept(t *testing.T) {
|
||||
got := containersOf(t, Resolution{Node: "laptop", Modules: []Manifest{{
|
||||
Module: "app",
|
||||
Resources: []map[string]any{{"id": "web", "type": "container", "name": "web",
|
||||
@@ -71,15 +68,62 @@ func TestAContainersOwnNamesAreKeptAsWritten(t *testing.T) {
|
||||
}}}, Rendering{Names: map[string]string{"anchor.internal": "10.42.0.1"}})
|
||||
|
||||
given := namesOf(got[0])
|
||||
if len(given) != 1 || given[0] != "something.else:203.0.113.9" {
|
||||
t.Fatalf("the container's own names were not kept as written: %v", given)
|
||||
if len(given) != 2 || given[0] != "something.else:203.0.113.9" {
|
||||
t.Fatalf("the container's own names were lost: %v", given)
|
||||
}
|
||||
}
|
||||
|
||||
// No resource is given a `hosts` key it did not declare. A file or a service carrying one is a
|
||||
// declaration the host refuses outright — it takes no unknown field — so an invented key breaks
|
||||
// the whole machine rather than one resource.
|
||||
func TestNothingIsGivenNamesItDidNotDeclare(t *testing.T) {
|
||||
// A container on the machine's own network gets the names too — it does NOT share the machine's
|
||||
// hosts file. `docker run --network host` still gives the container its own /etc/hosts (localhost
|
||||
// and its own id only), so every `<node>.internal` name the mesh wrote is invisible inside it, and a
|
||||
// client that dials one gets EAI_AGAIN. It gets the same `--add-host` entries every other container
|
||||
// gets (the runtime accepts them with `--network host`), so a host-network consumer can reach a
|
||||
// provider by the `.internal` address the mesh hands it.
|
||||
func TestAContainerOnTheMachinesNetworkIsGivenTheNamesToo(t *testing.T) {
|
||||
got := containersOf(t, Resolution{Node: "anchor", Modules: []Manifest{{
|
||||
Module: "control",
|
||||
Resources: []map[string]any{{"id": "c", "type": "container", "name": "c",
|
||||
"image": "registry.example/c@sha256:" + strings.Repeat("a", 64), "network": "host"}},
|
||||
}}}, Rendering{Names: map[string]string{"anchor.internal": "10.42.0.1"}})
|
||||
|
||||
given := namesOf(got[0])
|
||||
if len(given) != 1 || given[0] != "anchor.internal:10.42.0.1" {
|
||||
t.Fatalf("a host-networked container was not given the mesh's names: %v", got[0])
|
||||
}
|
||||
}
|
||||
|
||||
// A mesh with no private network gives nothing, rather than a name with no address behind it.
|
||||
func TestAMeshWithNoNamesGivesNone(t *testing.T) {
|
||||
got := containersOf(t, Resolution{Node: "alone", Modules: []Manifest{{
|
||||
Module: "app",
|
||||
Resources: []map[string]any{{"id": "web", "type": "container", "name": "web",
|
||||
"image": "registry.example/web@sha256:" + strings.Repeat("a", 64)}},
|
||||
}}}, Rendering{})
|
||||
if len(namesOf(got[0])) != 0 {
|
||||
t.Fatalf("names were invented for a mesh that has none: %v", got[0])
|
||||
}
|
||||
}
|
||||
|
||||
// The catalogue's copy is not edited: these maps come from a manifest, and mutating one would
|
||||
// change what every other machine running that module is given.
|
||||
func TestGivingNamesDoesNotChangeTheCatalogue(t *testing.T) {
|
||||
held := map[string]any{"id": "web", "type": "container", "name": "web",
|
||||
"image": "registry.example/web@sha256:" + strings.Repeat("a", 64)}
|
||||
module := Manifest{Module: "app", Resources: []map[string]any{held}}
|
||||
|
||||
for _, node := range []string{"one", "two"} {
|
||||
containersOf(t, Resolution{Node: node, Modules: []Manifest{module}},
|
||||
Rendering{Names: map[string]string{"anchor.internal": "10.42.0.1"}})
|
||||
}
|
||||
if _, changed := held["hosts"]; changed {
|
||||
t.Fatal("the manifest the catalogue holds was edited, so every machine now carries this")
|
||||
}
|
||||
}
|
||||
|
||||
// Only containers. A file or a service given a `hosts` key is a declaration the host refuses
|
||||
// outright — it takes no unknown field — so getting this wrong breaks the whole machine rather
|
||||
// than one resource, and breaks it for something that was never about names.
|
||||
func TestNothingButAContainerIsGivenNames(t *testing.T) {
|
||||
out, err := Resolution{Node: "laptop", Modules: []Manifest{{
|
||||
Module: "app",
|
||||
Resources: []map[string]any{
|
||||
@@ -93,8 +137,11 @@ func TestNothingIsGivenNamesItDidNotDeclare(t *testing.T) {
|
||||
t.Fatal(err)
|
||||
}
|
||||
for _, r := range out {
|
||||
if r["type"] == "container" {
|
||||
continue
|
||||
}
|
||||
if _, given := r["hosts"]; given {
|
||||
t.Fatalf("a %v was given names it never declared: %v", r["type"], r)
|
||||
t.Fatalf("a %v was given names, which the host will refuse: %v", r["type"], r)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,130 @@
|
||||
package catalogue
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// A module that must know its own address — a login redirect, a canonical URL, an issuer — had it
|
||||
// written into its manifest as a literal (novox/hq 04-ISSUES/122): a domain in a definition, wrong on
|
||||
// every other machine. It is told instead, from the same composition the provider receives.
|
||||
|
||||
// selfAware contributes a labelled route, binds the requirement, and writes its own name into a file.
|
||||
func selfAware(label string) Manifest {
|
||||
m := labelled("board", label, 8080)
|
||||
m.Requires = []string{"reverse-proxy"}
|
||||
m.Binds = map[string]string{"reverse-proxy": "/var/lib/board/route.json"}
|
||||
m.Resources = []map[string]any{
|
||||
{"id": "conf", "type": "file", "path": "/var/lib/board/app.conf",
|
||||
"content": "root = https://${bound:reverse-proxy:name}/\ninternal = ${bound:reverse-proxy:internal-name}\n"},
|
||||
}
|
||||
return m
|
||||
}
|
||||
|
||||
// servingProxy is proxy() as the catalogue's route providers are declared: the provision scoped to
|
||||
// the mesh, serving nothing a consumer must know (route-adapter, route-proxy: `"serves": {"route": {}}`).
|
||||
func servingProxy() Manifest {
|
||||
p := proxy()
|
||||
p.Provides = []Offer{{Name: "reverse-proxy", Scope: ScopeMesh}}
|
||||
p.Serves = map[string]map[string]any{"reverse-proxy": {}}
|
||||
return p
|
||||
}
|
||||
|
||||
// nodeProxy is the same provider scoped to its node, whose answer on the same machine comes from
|
||||
// `here` rather than from the mesh's needs — the other path a binding is written by.
|
||||
func nodeProxy() Manifest {
|
||||
p := proxy()
|
||||
p.Serves = map[string]map[string]any{"reverse-proxy": {"scheme": "http"}}
|
||||
return p
|
||||
}
|
||||
|
||||
// onBoth is a node with a public domain and a private-network address, so both names compose.
|
||||
func onBoth(domain string) Node {
|
||||
n := withDomain(domain)
|
||||
n.At = "anchor.internal"
|
||||
return n
|
||||
}
|
||||
|
||||
func fileAt(t *testing.T, out []map[string]any, path string) string {
|
||||
t.Helper()
|
||||
for _, r := range out {
|
||||
if r["path"] == path {
|
||||
return r["content"].(string)
|
||||
}
|
||||
}
|
||||
t.Fatalf("nothing was declared at %s", path)
|
||||
return ""
|
||||
}
|
||||
|
||||
func TestAModuleIsToldTheNameItsProviderServes(t *testing.T) {
|
||||
got, err := Resolve(shelf(servingProxy(), selfAware("git")), []string{"traefik", "board"},
|
||||
onBoth("example.tld"), World{})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
out := mustDeclare(t, got)
|
||||
served := received(t, out)[0].Values
|
||||
|
||||
var binding map[string]any
|
||||
if err := json.Unmarshal([]byte(fileAt(t, out, "/var/lib/board/route.json")), &binding); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if binding["name"] != served["name"] || binding["name"] != "git.example.tld" {
|
||||
t.Fatalf("the module was told %v, the provider serves %v", binding["name"], served["name"])
|
||||
}
|
||||
if binding["internal-name"] != served["internal-name"] || binding["internal-name"] == nil {
|
||||
t.Fatalf("internal name: module told %v, provider serves %v",
|
||||
binding["internal-name"], served["internal-name"])
|
||||
}
|
||||
|
||||
conf := fileAt(t, out, "/var/lib/board/app.conf")
|
||||
want := "root = https://git.example.tld/\ninternal = " + served["internal-name"].(string) + "\n"
|
||||
if conf != want {
|
||||
t.Fatalf("the file was rendered as\n%s\nwant\n%s", conf, want)
|
||||
}
|
||||
}
|
||||
|
||||
func TestTheNameAModuleIsToldFollowsTheNodesDomain(t *testing.T) {
|
||||
// The whole point: the same definition, two machines, two names — nothing edited.
|
||||
for _, domain := range []string{"example.tld", "other.example"} {
|
||||
got, err := Resolve(shelf(servingProxy(), selfAware("git")), []string{"traefik", "board"},
|
||||
onBoth(domain), World{})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
conf := fileAt(t, mustDeclare(t, got), "/var/lib/board/app.conf")
|
||||
if !strings.HasPrefix(conf, "root = https://git."+domain+"/") {
|
||||
t.Fatalf("on %s the module wrote %q", domain, conf)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestAModuleWithNoPublicNameIsNotToldOne(t *testing.T) {
|
||||
// No public domain on the node: nothing composed, so no `name` — and a file asking for one is
|
||||
// refused rather than rendered with a placeholder or an empty host.
|
||||
m := selfAware("git")
|
||||
m.Resources[0]["content"] = "root = https://${bound:reverse-proxy:name}/\n"
|
||||
got, err := Resolve(shelf(servingProxy(), m), []string{"traefik", "board"}, workstation(), World{})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := got.Declaration(Rendering{}); err == nil ||
|
||||
!strings.Contains(err.Error(), `"name"`) {
|
||||
t.Fatalf("a file asking for a name that was never composed was not refused: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAModuleIsToldItsNameByANodeScopedProviderToo(t *testing.T) {
|
||||
m := selfAware("git")
|
||||
m.Resources[0]["content"] = "root = https://${bound:reverse-proxy:name}/\n"
|
||||
got, err := Resolve(shelf(nodeProxy(), m), []string{"board"},
|
||||
withDomain("example.tld"), World{})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
conf := fileAt(t, mustDeclare(t, got), "/var/lib/board/app.conf")
|
||||
if !strings.HasPrefix(conf, "root = https://git.example.tld/") {
|
||||
t.Fatalf("a same-machine, node-scoped answer did not tell the module its name: %q", conf)
|
||||
}
|
||||
}
|
||||
@@ -98,7 +98,8 @@ func portInto(resource map[string]any, module string, listens []Listening, with
|
||||
|
||||
// **A fresh map, and only when something changes.** This map came out of the module's
|
||||
// manifest and the resource around it is a shallow copy, so filling a value in place would
|
||||
// change what the catalogue holds for every other machine running the module.
|
||||
// change what the catalogue holds for every other machine running the module — the trap
|
||||
// withMeshNames is written to avoid, one field along.
|
||||
var filled map[string]any
|
||||
for _, key := range named {
|
||||
written, ok := env[key].(string)
|
||||
|
||||
@@ -707,14 +707,9 @@ func checkClaims(modules []Manifest, node Node, elsewhere []Held, holdings []Hel
|
||||
}
|
||||
switch h.Scope {
|
||||
case ScopeMesh:
|
||||
// Both claim and nobody is on record, or this refusal could not have happened.
|
||||
// The remedy is the handover that records the holder (novox/hq ADR 0131,
|
||||
// 04-ISSUES/170), so it is named here rather than left to be found.
|
||||
problems = append(problems, fmt.Sprintf(
|
||||
"%s on %s claims %q, which %s on %s already holds — one per mesh. Nothing is "+
|
||||
"on record for it; `seat %s --to %s/%s` records the holder, and the other "+
|
||||
"assignment then stands beside it, eligible and silent",
|
||||
h.Module, node.Name, h.Claim, e.Module, e.Node, h.Claim, e.Node, e.Module))
|
||||
"%s on %s claims %q, which %s on %s already holds — one per mesh",
|
||||
h.Module, node.Name, h.Claim, e.Module, e.Node))
|
||||
case ScopeSite:
|
||||
if node.Site != "" && node.Site == e.Site {
|
||||
problems = append(problems, fmt.Sprintf(
|
||||
|
||||
@@ -48,7 +48,7 @@ func TestTheResolverForwardsToFixedUpstreamsAndNeverReadsResolvConf(t *testing.T
|
||||
}
|
||||
for _, want := range []string{
|
||||
"\nno-resolv\n", "\nserver=1.1.1.1\n", "\nserver=8.8.8.8\n",
|
||||
"\nlisten-address=127.0.0.1\n", "\nlisten-address=${machine:address}\n", "\nbind-dynamic\n",
|
||||
"\nlisten-address=127.0.0.1\n", "\ninterface=mesh0\n", "\nbind-dynamic\n",
|
||||
"\ndomain-needed\n", "\nbogus-priv\n",
|
||||
"\nconf-file=" + m.Facts["node-zones"].Path + "\n",
|
||||
} {
|
||||
@@ -56,14 +56,6 @@ func TestTheResolverForwardsToFixedUpstreamsAndNeverReadsResolvConf(t *testing.T
|
||||
t.Errorf("the resolver's configuration lacks %q:\n%s", strings.TrimSpace(want), config)
|
||||
}
|
||||
}
|
||||
// By address and never by interface: dnsmasq admits a query by the interface it arrives on
|
||||
// when told one, and a container's query to the private address arrives on the runtime's
|
||||
// bridge — `interface=mesh0` dropped every such query, silently (novox/hq issue 110).
|
||||
for _, line := range strings.Split(config, "\n") {
|
||||
if strings.HasPrefix(line, "interface=") {
|
||||
t.Errorf("the resolver answers by interface, so a container's query on a bridge is dropped: %s", line)
|
||||
}
|
||||
}
|
||||
// Not .53 or .54, which systemd-resolved holds; and not .55 any more, which was a convention
|
||||
// beside the one every machine already followed — the predecessor's resolv.conf says .1.
|
||||
for _, taken := range []string{"127.0.0.53", "127.0.0.54", "127.0.0.55"} {
|
||||
@@ -145,39 +137,23 @@ func TestTheResolverAndWhatAsksItComposeOnOneMachine(t *testing.T) {
|
||||
t.Errorf("the daemon does not restart on its configuration and the machines file both: %v", service["restart-on"])
|
||||
}
|
||||
|
||||
// The runtime's own file, written into (novox/hq ADR 0102) with the keys this module states:
|
||||
// where containers resolve, and that a restart keeps them running — because the runtime reads
|
||||
// `dns` only when it starts, and the one restart that needs is the operator's (issue 110).
|
||||
// The runtime's own file, written into (novox/hq ADR 0102) with the one key this module states.
|
||||
runtime := ids["dnsmasq.runtime-dns"]
|
||||
if runtime == nil || runtime["path"] != "/etc/docker/daemon.json" || runtime["into"] != "json" {
|
||||
t.Fatalf("the runtime's dns is not written into its file: %v", runtime)
|
||||
}
|
||||
var keys map[string]any
|
||||
var keys map[string][]string
|
||||
if err := json.Unmarshal([]byte(runtime["content"].(string)), &keys); err != nil {
|
||||
t.Fatalf("the runtime's keys are not JSON: %v", err)
|
||||
}
|
||||
dns, _ := keys["dns"].([]any)
|
||||
if len(keys) != 2 || len(dns) != 1 || dns[0] != "10.42.0.1" || keys["live-restore"] != true {
|
||||
t.Errorf("the runtime is given %v; containers resolve at this machine's own private-network address, a restart keeps them, and nothing else is written", keys)
|
||||
if len(keys) != 1 || len(keys["dns"]) != 1 || keys["dns"][0] != "10.42.0.1" {
|
||||
t.Errorf("the runtime is pointed at %v; containers resolve at this machine's own private-network address, and nothing else is written", keys)
|
||||
}
|
||||
// The runtime is reloaded when that file changes, and never restarted: a restart stops every
|
||||
// container on the machine (ADR 0102), and a reload is what turns live-restore on.
|
||||
var reloaded bool
|
||||
for _, r := range out {
|
||||
if r["type"] != "service" || r["unit"] != "docker.service" {
|
||||
continue
|
||||
if r["type"] == "service" && r["unit"] == "docker.service" && r["id"] != "" &&
|
||||
strings.HasPrefix(r["id"].(string), "dnsmasq.") {
|
||||
t.Errorf("the resolver orders the runtime restarted or reloaded, which stops every container (ADR 0102) or does nothing for dns: %v", r)
|
||||
}
|
||||
if _, restarts := r["restart-on"]; restarts {
|
||||
t.Errorf("the resolver orders the runtime restarted, which stops every container (ADR 0102): %v", r)
|
||||
}
|
||||
for _, on := range asStrings(r["reload-on"]) {
|
||||
if on == "dnsmasq.runtime-dns" {
|
||||
reloaded = true
|
||||
}
|
||||
}
|
||||
}
|
||||
if !reloaded {
|
||||
t.Errorf("the runtime is not reloaded when its file changes, so live-restore never takes effect")
|
||||
}
|
||||
|
||||
resolv := ids["resolv-conf.resolv"]
|
||||
|
||||
@@ -162,13 +162,6 @@ func renderRoster(tmpl string, view rosterView) (string, error) {
|
||||
func entriesFrom(addresses, accounts map[string]string, suffix string) []rosterEntry {
|
||||
out := make([]rosterEntry, 0, len(addresses))
|
||||
for _, name := range sortedNames(addresses) {
|
||||
if routed(name, suffix) {
|
||||
// A routed name is already a full name under a public domain, and it has no mesh
|
||||
// form: appending the suffix made `<name>.<suffix>`, which every machine's hosts file
|
||||
// carried and nothing served (novox/hq issue 157). It is published as itself, once.
|
||||
out = append(out, rosterEntry{Name: name, FQDN: name, Address: addresses[name], Account: accounts[name]})
|
||||
continue
|
||||
}
|
||||
internal, bare := meshName(name, suffix)
|
||||
// The account is looked up by whichever key the caller keys accounts on — the internal name
|
||||
// or the bare one — so a template gets the right login however the maps were built.
|
||||
@@ -194,14 +187,6 @@ func meshName(name, suffix string) (internal, bare string) {
|
||||
return name + dotted, name
|
||||
}
|
||||
|
||||
// routed says whether a name the mesh serves is a routed public name rather than a machine's: it
|
||||
// carries a domain of its own and not the mesh's suffix. A machine's name is bare (`homer`) or
|
||||
// internal (`homer.internal`); anything else with a dot in it was composed under a public domain.
|
||||
func routed(name, suffix string) bool {
|
||||
dotted := "." + strings.TrimPrefix(suffixOr(suffix), ".")
|
||||
return strings.Contains(name, ".") && !strings.HasSuffix(name, dotted)
|
||||
}
|
||||
|
||||
// suffixOr is the suffix given, or the one the mesh composes names with when none was handed down.
|
||||
// The one place the default is written, so a fact and a name cannot disagree about it.
|
||||
func suffixOr(suffix string) string {
|
||||
|
||||
@@ -258,24 +258,3 @@ func TestAHomeFactIsSkippedWhereThereIsNoAccount(t *testing.T) {
|
||||
t.Fatalf("a home fact was placed on a machine with no operator account: %v", given)
|
||||
}
|
||||
}
|
||||
|
||||
// A routed name is already a full name under a public domain and has no mesh form. Appending the
|
||||
// suffix to it made `git.example.tld.internal` — carried by every machine's hosts file, served by
|
||||
// nothing, and refused by the proxy at the handshake (novox/hq issue 157). It is published as
|
||||
// itself, and only a machine has a bare name beside its full one.
|
||||
func TestARoutedNameIsPublishedAsItselfAndNotSuffixed(t *testing.T) {
|
||||
names := map[string]string{"homer.internal": "10.42.0.1", "git.example.tld": "10.42.0.1"}
|
||||
tmpl := RosterFile{Path: "/f", Template: "{{range .Names}}{{.FQDN}} {{.Name}}\n{{end}}"}
|
||||
out, err := FactsInto(Manifest{Module: "a", Facts: map[string]RosterFile{"f": tmpl}},
|
||||
Resolution{Node: "homer"}, names, map[string]string{"homer.internal": "10.42.0.1"}, nil, "internal")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
got := out[0]["content"].(string)
|
||||
if strings.Contains(got, "tld.internal") {
|
||||
t.Fatalf("the routed name was given a suffixed alias that nothing serves:\n%s", got)
|
||||
}
|
||||
if !strings.Contains(got, "git.example.tld git.example.tld\n") || !strings.Contains(got, "homer.internal homer\n") {
|
||||
t.Fatalf("the roster does not carry the routed name as itself beside the machine's two forms:\n%s", got)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -198,59 +198,37 @@ func TestTheApexLabelComposesToTheBarePrivateAddress(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// novox/hq ADR 0066 propagate, by ADR 0148's means: a granted route name is published into the
|
||||
// machine's roster mapped to the node that serves it, beside the `<node>.internal` names, and the
|
||||
// machine's resolver answers it to every container. Nothing is written into the container itself —
|
||||
// a routed name that moved would otherwise be wrong inside every container until each was recreated.
|
||||
func TestARoutedNameResolvesToTheServingNode(t *testing.T) {
|
||||
names := map[string]string{
|
||||
"anchor.internal": "10.42.0.1",
|
||||
"git.example.tld": "10.42.0.1",
|
||||
}
|
||||
// novox/hq ADR 0066 propagate: a granted route name is published into internal resolution,
|
||||
// mapped to the node that serves it, alongside the `<node>.internal` names — so every
|
||||
// container, and an in-mesh ACME validator, resolves a routed name to the proxy that serves it.
|
||||
// The names map is what withMeshNames writes into every container as `--add-host`; a route name
|
||||
// mapped to the serving node's address rides the same mechanism.
|
||||
got := containersOf(t, Resolution{Node: "anchor", Modules: []Manifest{{
|
||||
Module: "app",
|
||||
Resources: []map[string]any{{"id": "web", "type": "container", "name": "web",
|
||||
"image": "registry.example/web@sha256:" + strings.Repeat("a", 64)}},
|
||||
}}}, Rendering{Names: names})
|
||||
}}}, Rendering{Names: map[string]string{
|
||||
"anchor.internal": "10.42.0.1",
|
||||
"git.example.tld": "10.42.0.1",
|
||||
}})
|
||||
if len(got) != 1 {
|
||||
t.Fatalf("expected one container, got %d", len(got))
|
||||
}
|
||||
if given := namesOf(got[0]); len(given) != 0 {
|
||||
t.Fatalf("the routed name was copied into the container, where it would go stale: %v", given)
|
||||
}
|
||||
var sawRoute bool
|
||||
for _, e := range entriesFrom(names, nil, "internal") {
|
||||
if e.Name == "git.example.tld" && e.Address == "10.42.0.1" {
|
||||
given := namesOf(got[0])
|
||||
var sawNode, sawRoute bool
|
||||
for _, h := range given {
|
||||
if h == "anchor.internal:10.42.0.1" {
|
||||
sawNode = true
|
||||
}
|
||||
if h == "git.example.tld:10.42.0.1" {
|
||||
sawRoute = true
|
||||
}
|
||||
}
|
||||
if !sawNode {
|
||||
t.Fatalf("the container lost the mesh's node names: %v", given)
|
||||
}
|
||||
if !sawRoute {
|
||||
t.Fatalf("the routed name is not in the roster the machine's resolver answers from")
|
||||
}
|
||||
}
|
||||
|
||||
// novox/hq issue 139, ADR 0151: `<label>.<node>.internal` is answered by every machine's resolver as
|
||||
// "anything under that node's name goes to that node", so the node in a route's internal name must
|
||||
// be the one whose proxy answers it. Composed under the consumer's own name, a route served from
|
||||
// another machine got an internal name that resolved to a machine with nothing listening, while the
|
||||
// public name — published at the serving node's address — worked.
|
||||
func TestARoutesInternalNameIsComposedUnderTheNodeThatServesIt(t *testing.T) {
|
||||
hub := proxy()
|
||||
hub.Provides = FromAnywhere("reverse-proxy")
|
||||
got, err := Resolve(shelf(hub, labelled("board", "git", 8080)), []string{"board"},
|
||||
withPrivateAddress("laptop.internal"), World{Offered: map[string][]Provider{
|
||||
"reverse-proxy": {{Node: "anchor", At: "anchor.internal", Module: "traefik"}},
|
||||
}})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
// Gathered the way the control plane gathers a consumer's contribution for a provider on
|
||||
// another machine.
|
||||
values, asks, err := got.ContributionsFrom("reverse-proxy", "board", nil)
|
||||
if err != nil || !asks {
|
||||
t.Fatalf("the route was not contributed: %v %v", asks, err)
|
||||
}
|
||||
if values["internal-name"] != "git.anchor.internal" {
|
||||
t.Fatalf("the internal name does not say where the request arrives: %v", values)
|
||||
t.Fatalf("the routed name was not published to the serving node: %v", given)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,97 +0,0 @@
|
||||
package catalogue
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// A component is unpacked into a directory named for its version, so it can read its own version from
|
||||
// its path (novox/hq ADR 0141, 0142). Until this, nothing could compose that path: an archive named a
|
||||
// fixed one and nothing interpolated the build into it, so nothing could ask for
|
||||
// `…/versions/<version>/` and every machine took a hand-placed fallback (04-ISSUES/142).
|
||||
|
||||
const aDigest = "sha256:ad62528c47c7b4a71cf814473f5de52a061348ce9521f707b0171a10fa6b247f"
|
||||
|
||||
func TestAnArchivePathCanNameTheBuildsOwnVersion(t *testing.T) {
|
||||
m := Manifest{
|
||||
Module: "mesh-host",
|
||||
Build: &Build{Artifacts: []Artifact{{Name: "host-arch", Kind: ArtifactBundle, Language: "go", System: "arch"}}},
|
||||
Resources: []map[string]any{{
|
||||
"id": "next", "type": "archive", "artifact": "host-arch",
|
||||
"path": "/usr/lib/nox-mesh-host/versions/${version}",
|
||||
}},
|
||||
}
|
||||
got, err := m.Resolve([]Built{{Name: "host-arch", Kind: ArtifactBundle,
|
||||
Reference: "artifact-store://mesh-host/host-arch", Digest: aDigest}})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
path, _ := got.Resources[0]["path"].(string)
|
||||
if strings.Contains(path, "${version}") {
|
||||
t.Fatalf("the version was not resolved: %q", path)
|
||||
}
|
||||
if path != "/usr/lib/nox-mesh-host/versions/ad62528c47c7" {
|
||||
t.Fatalf("the path resolved to %q", path)
|
||||
}
|
||||
// The artifact key goes, as it does for every resolved resource: it is a build-time word and the
|
||||
// host has never heard of it.
|
||||
if _, still := got.Resources[0]["artifact"]; still {
|
||||
t.Fatal("the artifact key survived resolution")
|
||||
}
|
||||
}
|
||||
|
||||
func TestTheVersionIsTheDigestSoAnUnchangedBuildKeepsItsPath(t *testing.T) {
|
||||
// The alternative is the commit, and two builds of one commit are meant to be the same bytes —
|
||||
// every toolchain here is -trimpath for that reason. A commit-named path would move for an
|
||||
// identical binary and recreate everything reading it.
|
||||
first := versionOf(aDigest)
|
||||
again := versionOf(aDigest)
|
||||
if first != again || first == "" {
|
||||
t.Fatalf("the same bytes produced %q and %q", first, again)
|
||||
}
|
||||
if other := versionOf("sha256:" + strings.Repeat("b", 64)); other == first {
|
||||
t.Fatal("different bytes produced the same version")
|
||||
}
|
||||
// A path is read by people and quoted by shells.
|
||||
if strings.ContainsAny(first, ":/ ") {
|
||||
t.Fatalf("the version is not safe in a path: %q", first)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAnImageIsRefusedAVersionedPlace(t *testing.T) {
|
||||
// An image is not unpacked, so it has no directory to be named for its version. Left as literal
|
||||
// text it would reach a machine and be created as a directory called ${version}.
|
||||
m := Manifest{
|
||||
Module: "something",
|
||||
Build: &Build{Artifacts: []Artifact{{Name: "server", Kind: ArtifactImage, From: "Dockerfile"}}},
|
||||
Resources: []map[string]any{{
|
||||
"id": "where", "type": "directory", "artifact": "server",
|
||||
"path": "/var/lib/something/${version}",
|
||||
}},
|
||||
}
|
||||
_, err := m.Resolve([]Built{{Name: "server", Kind: ArtifactImage, Reference: "registry/x@" + aDigest}})
|
||||
if err == nil {
|
||||
t.Fatal("an image was given a versioned place")
|
||||
}
|
||||
if !strings.Contains(err.Error(), "not unpacked") {
|
||||
t.Fatalf("the refusal does not say why: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAResourceWithoutAVersionReferenceIsUntouched(t *testing.T) {
|
||||
m := Manifest{
|
||||
Module: "mesh-host",
|
||||
Build: &Build{Artifacts: []Artifact{{Name: "host-arch", Kind: ArtifactBundle, Language: "go", System: "arch"}}},
|
||||
Resources: []map[string]any{{
|
||||
"id": "next", "type": "archive", "artifact": "host-arch", "path": "/usr/lib/fixed",
|
||||
}},
|
||||
}
|
||||
got, err := m.Resolve([]Built{{Name: "host-arch", Kind: ArtifactBundle,
|
||||
Reference: "artifact-store://mesh-host/host-arch", Digest: aDigest}})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if path, _ := got.Resources[0]["path"].(string); path != "/usr/lib/fixed" {
|
||||
t.Fatalf("a path naming no version became %q", path)
|
||||
}
|
||||
}
|
||||
@@ -1,15 +0,0 @@
|
||||
-- The version of the host running on a machine, as the machine reports it.
|
||||
--
|
||||
-- novox/hq 04-ISSUES/087. A host parses a declaration strictly: a field it does not know makes it
|
||||
-- refuse the whole declaration and apply nothing. That is deliberate — it keeps a half-understood
|
||||
-- declaration off a machine — and it makes every new field in a declaration a flag day, hosts before
|
||||
-- controller. The mesh had no record of which host a machine runs, so it could neither refuse to send
|
||||
-- a declaration a machine cannot parse nor say which machines were behind. The order was kept by
|
||||
-- somebody remembering it.
|
||||
--
|
||||
-- The machine has been reporting this since ADR 0141 and the control plane discarded it: the field was
|
||||
-- absent from the controller's own copy of the report, so it was unmarshalled into nothing.
|
||||
--
|
||||
-- Null for a machine that has not reported since this column existed, which is not the same as a
|
||||
-- machine running no host — so a reader is never told a version the mesh does not have.
|
||||
alter table node add column host_version text;
|
||||
@@ -1,11 +0,0 @@
|
||||
-- The order of what a machine was sent, so a host can tell an older declaration from a newer.
|
||||
--
|
||||
-- novox/hq 04-ISSUES/107. A declaration's only identity was the digest of its bytes. The host could
|
||||
-- say "this is not the last one" and could not say "this is older", so a backlog drained out of
|
||||
-- order applied a declaration the mesh had already superseded. The controller already holds a
|
||||
-- per-node lock while it composes and records each send — the order existed and was thrown away at
|
||||
-- the wire.
|
||||
--
|
||||
-- One counter per node, taken under that hold, one higher per send. Null is a machine sent nothing
|
||||
-- since this existed, which is not the same as a machine sent nothing.
|
||||
alter table node add column sequence bigint;
|
||||
@@ -63,11 +63,6 @@ type Node struct {
|
||||
// entry. What decides who a file under a home is owned by, and which account `ssh <node>` uses.
|
||||
Account string
|
||||
AccountHome string
|
||||
|
||||
// HostVersion is the version of the host this machine reported running (novox/hq 04-ISSUES/087).
|
||||
// Empty when it has not said since the mesh began keeping it — which is not the same as running
|
||||
// no host, so nothing derives "behind" from an empty one.
|
||||
HostVersion string
|
||||
}
|
||||
|
||||
// Home is the account's home directory, derived when not stored: /root for root, /home/<account>
|
||||
@@ -141,20 +136,15 @@ func (i *Inventory) AddNodeAs(ctx context.Context, name string, adopted bool) (N
|
||||
|
||||
// nodeColumns and scanNode are the one reading of a node row, so every way of finding a node
|
||||
// says whether it is adopted.
|
||||
const nodeColumns = `id, name, created, last_seen, adopted, adopted_since, account, account_home,
|
||||
host_version`
|
||||
const nodeColumns = `id, name, created, last_seen, adopted, adopted_since, account, account_home`
|
||||
|
||||
func scanNode(row pgx.Row) (Node, error) {
|
||||
var n Node
|
||||
var seen, since *time.Time
|
||||
var host *string
|
||||
if err := row.Scan(&n.ID, &n.Name, &n.Created, &seen, &n.Adopted, &since,
|
||||
&n.Account, &n.AccountHome, &host); err != nil {
|
||||
&n.Account, &n.AccountHome); err != nil {
|
||||
return Node{}, err
|
||||
}
|
||||
if host != nil {
|
||||
n.HostVersion = *host
|
||||
}
|
||||
if seen != nil {
|
||||
n.LastSeen = *seen
|
||||
}
|
||||
@@ -990,49 +980,3 @@ type Machine struct {
|
||||
// being out of date and reads differently to whoever is looking.
|
||||
Never bool
|
||||
}
|
||||
|
||||
// RecordHostVersion keeps the version of the host a machine reported running (novox/hq 04-ISSUES/087).
|
||||
//
|
||||
// Never cleared by a report that carries none: a bare word that the node is there says nothing about
|
||||
// its host, and a machine whose host predates ADR 0141 reports none at all. So an empty version means
|
||||
// the mesh has not been told, and the caller does not write it.
|
||||
func (i *Inventory) RecordHostVersion(ctx context.Context, id, version string) error {
|
||||
version = strings.TrimSpace(version)
|
||||
if version == "" {
|
||||
return nil
|
||||
}
|
||||
_, err := i.store.Pool().Exec(ctx,
|
||||
`update node set host_version = $2, last_seen = now() where id = $1`, id, version)
|
||||
return err
|
||||
}
|
||||
|
||||
// NextSequence takes the next number for a declaration to this node, one higher than the last it
|
||||
// was sent (novox/hq 04-ISSUES/107).
|
||||
//
|
||||
// **One statement, so two composers cannot take the same number.** The caller holds the node while it
|
||||
// composes and sends, so in practice there is one; the increment is atomic anyway, because a rule
|
||||
// that is true only while a lock is held somewhere else is a rule nobody can see from here.
|
||||
func (i *Inventory) NextSequence(ctx context.Context, id string) (int64, error) {
|
||||
var n int64
|
||||
err := i.store.Pool().QueryRow(ctx,
|
||||
`update node set sequence = coalesce(sequence, 0) + 1 where id = $1 returning sequence`, id).Scan(&n)
|
||||
if err != nil {
|
||||
return 0, fmt.Errorf("taking the next sequence for %s: %w", id, err)
|
||||
}
|
||||
return n, nil
|
||||
}
|
||||
|
||||
// Sequence is the number of the last declaration this node was sent, and zero for one sent nothing
|
||||
// since sends were numbered. Read, not taken: what the mesh WOULD send is composed with this, so it
|
||||
// is byte for byte what it DID send when nothing else changed — a comparison that took a fresh number
|
||||
// would read every machine as behind for ever (novox/hq 04-ISSUES/107).
|
||||
func (i *Inventory) Sequence(ctx context.Context, id string) (int64, error) {
|
||||
var n *int64
|
||||
if err := i.store.Pool().QueryRow(ctx, `select sequence from node where id = $1`, id).Scan(&n); err != nil {
|
||||
return 0, fmt.Errorf("reading the sequence of %s: %w", id, err)
|
||||
}
|
||||
if n == nil {
|
||||
return 0, nil
|
||||
}
|
||||
return *n, nil
|
||||
}
|
||||
|
||||
@@ -312,14 +312,6 @@ func (e Enrolment) Heard(ctx context.Context, report Report) (news bool, err err
|
||||
return false, err
|
||||
}
|
||||
}
|
||||
// Which host produced this report (novox/hq 04-ISSUES/087), whenever it says. Recorded on every
|
||||
// report that carries it and never cleared by one that does not — a bare word that the node is
|
||||
// there says nothing about its host, and a machine whose host predates this reports none.
|
||||
if report.Host != "" {
|
||||
if err := e.Inventory.RecordHostVersion(ctx, node.ID, report.Host); err != nil {
|
||||
return false, err
|
||||
}
|
||||
}
|
||||
// What it says about the tunnel it carried (novox/hq ADR 0105), whenever it says it.
|
||||
if report.Tunnel != nil {
|
||||
if err := e.Inventory.RecordCarriedTunnel(ctx, node.ID, inventory.Carried{
|
||||
|
||||
@@ -184,15 +184,6 @@ type Report struct {
|
||||
// leaves the one it has: a rule written around a link with no name is a rule set that does not
|
||||
// load, and that is a machine filtering nothing while its unit reports success.
|
||||
Outward []string `json:"outward,omitempty"`
|
||||
|
||||
// Host is the version of the host that produced this report (novox/hq ADR 0141).
|
||||
//
|
||||
// **The machine has sent this since 0141 and this struct did not have it**, so it was
|
||||
// unmarshalled into nothing and the mesh could not say which host any machine runs
|
||||
// (novox/hq 04-ISSUES/087). A host refuses a declaration carrying a field it does not know, and
|
||||
// refuses it whole — which is right, and makes every new field a flag day that the mesh could
|
||||
// not see coming.
|
||||
Host string `json:"host,omitempty"`
|
||||
// Reachable is what can be reached on the machine now: every listening socket and every
|
||||
// published container port. Only an adopted node reports it; it is what converging previews.
|
||||
Reachable []Reach `json:"reachable,omitempty"`
|
||||
|
||||
@@ -169,12 +169,10 @@ func (g *Generator) Graph() Graph { return g.graph }
|
||||
//
|
||||
// - No floor: no header, no localhost, no `127.0.1.1` — those are the machine's, above the region.
|
||||
// - A machine's own line is marked, and its mesh name resolves to its mesh address, not loopback.
|
||||
// - `.Names` is every name the mesh serves (issue 111), so anything on the machine reaching a
|
||||
// routed name through its resolver finds the machine serving it; machines with no address yet
|
||||
// are already left out of the set. A routed name is one alias, itself — a machine has a bare
|
||||
// name beside its full one, a routed name has nothing beside it (issue 157).
|
||||
// - `.Names` is every name the mesh serves (issue 111), so a container reaching a routed name
|
||||
// finds the machine serving it; machines with no address yet are already left out of the set.
|
||||
const hostsTemplate = "# The mesh's names. This region is replaced whenever a machine joins or leaves.\n" +
|
||||
"{{range .Names}}{{.Address}}\t{{.FQDN}}{{if ne .Name .FQDN}}\t{{.Name}}{{end}}{{if eq .Name $.Node}}\t# this machine{{end}}\n{{end}}"
|
||||
"{{range .Names}}{{.Address}}\t{{.FQDN}}\t{{.Name}}{{if eq .Name $.Node}}\t# this machine{{end}}\n{{end}}"
|
||||
|
||||
// Manifest is the module the mesh provides for itself.
|
||||
//
|
||||
|
||||
Reference in New Issue
Block a user