diff --git a/cmd/mesh-controller/adopting_test.go b/cmd/mesh-controller/adopting_test.go index d023ab6..a517214 100644 --- a/cmd/mesh-controller/adopting_test.go +++ b/cmd/mesh-controller/adopting_test.go @@ -91,6 +91,10 @@ func reportsReaching(t *testing.T, open *stores, reachable []link.Reach, held .. if _, err := (link.Enrolment{Inventory: open.inventory}).Heard(ctx, link.Report{ Node: "anchor", Applied: []string{"hello-web.x"}, Declared: digestOf(body), Firewall: "ufw", Held: held, Reachable: reachable, + // A machine says which of its links face outside on every apply (novox/hq ADR 0140), and a + // filter is not sent to one that has not. The anchor reports one, as a real host does; this + // fixture lacked it from 2026-09-28 and nothing ran the test (issue 177). + Outward: []string{"eth0"}, }); err != nil { t.Fatal(err) } diff --git a/cmd/mesh-controller/sendable_test.go b/cmd/mesh-controller/sendable_test.go index 73ce86c..8eb0e18 100644 --- a/cmd/mesh-controller/sendable_test.go +++ b/cmd/mesh-controller/sendable_test.go @@ -47,7 +47,12 @@ func composed(t *testing.T, open *stores, node string) sendable { // aMesh's laptop with the private network taken off it, so nothing in the declaration is random: // what changes this string is a change to what a converged machine is sent, which is the thing an // older host would refuse. -const convergedBefore = `{"declaration":1,"resources":[{"content":"hello","id":"hello-web.page","path":"/var/lib/hello-web/index.html","type":"file"},{"hosts":["anchor.internal:10.77.0.1"],"id":"hello-web.server","image":"registry.example/hello@sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa","name":"hello-web","type":"container"},{"id":"hello-web.served","path":"/var/lib/hello-web","type":"directory"}]}` +// +// Re-captured 2026-10-01 (novox/hq issue 177): c978aa7 took `hosts` off every container — a +// machine's own resolver knows the mesh's names now — and left this string carrying it, so the +// guard failed for a day and nothing ran it. A field an older host never sees is the one change +// this guard permits; a field it would refuse is the one it exists to catch. +const convergedBefore = `{"declaration":1,"resources":[{"content":"hello","id":"hello-web.page","path":"/var/lib/hello-web/index.html","type":"file"},{"id":"hello-web.server","image":"registry.example/hello@sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa","name":"hello-web","type":"container"},{"id":"hello-web.served","path":"/var/lib/hello-web","type":"directory"}]}` func TestAConvergedDeclarationIsByteForByteWhatItWas(t *testing.T) { open := aMesh(t)