The mesh makes the bus's certificate itself #145
@@ -0,0 +1,71 @@
|
|||||||
|
package catalogue
|
||||||
|
|
||||||
|
import (
|
||||||
|
"os"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// **A machine trusts the mesh's authority because a module put its root there** (novox/hq ADR
|
||||||
|
// 0147, issue 129). The module carries a shell script and a unit, and both are worthless unless
|
||||||
|
// the mesh fills in where the authority is — which is the one thing about it the manifest cannot
|
||||||
|
// state, because the authority's address is a fact about the mesh and not about the module.
|
||||||
|
//
|
||||||
|
// So what is checked here is the rendering, not the parsing: the script the machine will run
|
||||||
|
// names the authority it was bound to, and the unit runs that script both ways. The verification
|
||||||
|
// itself — a plain client trusting an internal name on a machine holding this, and failing on one
|
||||||
|
// that does not — is the lab's, and cannot be had here.
|
||||||
|
func TestCaTrustRendersTheAuthorityItWasBoundTo(t *testing.T) {
|
||||||
|
raw, err := os.ReadFile("../../../mesh-catalog/modules/ca-trust/module.json")
|
||||||
|
if err != nil {
|
||||||
|
t.Skipf("the catalogue is not beside this checkout: %v", err)
|
||||||
|
}
|
||||||
|
m, err := ParseManifest(raw)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("the trust module does not parse:\n%v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
r := Resolution{
|
||||||
|
Node: "workstation",
|
||||||
|
Modules: []Manifest{m},
|
||||||
|
Needs: []Needed{{
|
||||||
|
Name: "internal-acme-ca", From: "anchor", At: "anchor.internal", For: "ca-trust",
|
||||||
|
Serves: map[string]any{
|
||||||
|
"port": float64(9000), "path": "/acme/acme/directory", "roots": "/roots.pem",
|
||||||
|
},
|
||||||
|
}},
|
||||||
|
}
|
||||||
|
out, err := r.Declaration(Rendering{})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("the trust module could not be composed for a machine: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
script := fileNamed(out, "ca-trust.anchor")
|
||||||
|
if script == nil {
|
||||||
|
t.Fatalf("nothing writes the script the unit runs: %v", out)
|
||||||
|
}
|
||||||
|
body, _ := script["content"].(string)
|
||||||
|
if !strings.Contains(body, "https://anchor.internal:9000/roots.pem") {
|
||||||
|
t.Errorf("the script does not fetch from the authority it was bound to:\n%s", body)
|
||||||
|
}
|
||||||
|
if script["mode"] != "0755" {
|
||||||
|
t.Errorf("the script is written %v, which systemd cannot execute", script["mode"])
|
||||||
|
}
|
||||||
|
|
||||||
|
unit := fileNamed(out, "ca-trust.unit")
|
||||||
|
if unit == nil {
|
||||||
|
t.Fatalf("no unit: %v", out)
|
||||||
|
}
|
||||||
|
text, _ := unit["content"].(string)
|
||||||
|
// Both halves. A unit that only installs the anchor leaves a machine trusting an authority
|
||||||
|
// nobody assigned it to any more, which is the half issue 129 asked for by name.
|
||||||
|
for _, want := range []string{
|
||||||
|
"ExecStart=" + script["path"].(string) + " install",
|
||||||
|
"ExecStop=" + script["path"].(string) + " remove",
|
||||||
|
"RemainAfterExit=yes",
|
||||||
|
} {
|
||||||
|
if !strings.Contains(text, want) {
|
||||||
|
t.Errorf("the unit does not say %q:\n%s", want, text)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user