package link import ( "context" "crypto/ed25519" "encoding/json" "strings" "testing" "time" "github.com/nats-io/nats.go" "github.com/novox/mesh-controller/internal/broker" "github.com/novox/mesh-controller/internal/testbus" ) // The hand-over's ask and answer hold these field names; the engine's side holds the same list (mesh-host // internal/link, TestTheHandOverAskAndAnswerKeepTheirFieldNames). func TestTheHandOverAskAndAnswerKeepTheirFieldNames(t *testing.T) { body, _ := json.Marshal(HandOverAsk{Node: "laptop", Path: "/srv/notes", By: "jo through mesh-cli on anchor", Expires: time.Now(), Nonce: "n"}) if got := keysIn(t, body); got != "by expires node nonce path" { t.Fatalf("the ask's fields are %q", got) } body, _ = json.Marshal(SignedHandOver{Ask: []byte("{}"), Signature: []byte("s")}) if got := keysIn(t, body); got != "ask signature" { t.Fatalf("the signed ask's fields are %q", got) } body, _ = json.Marshal(HandOverAnswer{Said: "s", Refused: "r"}) if got := keysIn(t, body); got != "refused said" { t.Fatalf("the answer's fields are %q", got) } if broker.AskHandOverSubject("laptop") != "mesh.node.laptop.ask.hand-over" { t.Fatalf("the subject is %q", broker.AskHandOverSubject("laptop")) } if HandOverContext != "novox-mesh hand-over v1\n" { t.Fatalf("the signing context is %q; the engine holds the same words", HandOverContext) } } // keySigner signs with one key, as the controller's identity does. type keySigner struct{ key ed25519.PrivateKey } func (k keySigner) Sign(_ context.Context, message []byte) ([]byte, error) { return ed25519.Sign(k.key, message), nil } func testSigner(t *testing.T) (keySigner, ed25519.PublicKey) { t.Helper() public, private, err := ed25519.GenerateKey(nil) if err != nil { t.Fatal(err) } return keySigner{private}, public } // **The ask is signed over the context and its bytes, with a fresh nonce and a short expiry** (review of issue // 356): the signature verifies over HandOverContext and the ask's bytes, and not over the bytes alone — so it is // never a declaration's — and two asks never share a nonce. func TestAHandOverIsSignedWithAContextANonceAndAnExpiry(t *testing.T) { signer, public := testSigner(t) body, err := SignHandOver(context.Background(), signer, HandOverAsk{Node: "laptop", Path: "/srv/notes", By: "jo"}) if err != nil { t.Fatal(err) } var signed SignedHandOver if err := json.Unmarshal(body, &signed); err != nil { t.Fatal(err) } if !ed25519.Verify(public, append([]byte(HandOverContext), signed.Ask...), signed.Signature) { t.Fatal("the signature does not verify over the context and the ask") } if ed25519.Verify(public, signed.Ask, signed.Signature) { t.Fatal("the signature verifies over the ask's bytes alone, as a declaration's would") } var ask HandOverAsk if err := json.Unmarshal(signed.Ask, &ask); err != nil { t.Fatal(err) } if ask.Node != "laptop" || ask.Path != "/srv/notes" || ask.By != "jo" || len(ask.Nonce) != 32 { t.Fatalf("signed %+v", ask) } if left := time.Until(ask.Expires); left <= 0 || left > HandOverGood { t.Fatalf("the ask is good for %s", left) } again, _ := SignHandOver(context.Background(), signer, HandOverAsk{Node: "laptop", Path: "/srv/notes", By: "jo"}) var other SignedHandOver _ = json.Unmarshal(again, &other) var second HandOverAsk _ = json.Unmarshal(other.Ask, &second) if second.Nonce == ask.Nonce { t.Fatal("two asks share a nonce") } if _, err := SignHandOver(context.Background(), nil, HandOverAsk{}); err == nil { t.Fatal("an ask was made with no key") } } // The ask reaches the machine's engine on its own subject and its answer comes back whole: what it recorded, or // its refusal as the engine worded it. A machine with no engine listening is said as not answering, and an // answer that is neither is refused rather than read as a record. func TestAHandOverIsAskedOfTheMachineAndItsAnswerComesBack(t *testing.T) { url := testbus.URL(t) conn, err := nats.Connect(url) if err != nil { t.Fatal(err) } t.Cleanup(conn.Close) signer, public := testSigner(t) var heard HandOverAsk engine, err := conn.Subscribe(broker.AskHandOverSubject("laptop"), func(msg *nats.Msg) { var signed SignedHandOver _ = json.Unmarshal(msg.Data, &signed) if !ed25519.Verify(public, append([]byte(HandOverContext), signed.Ask...), signed.Signature) { _ = msg.Respond([]byte(`{"refused":"not the mesh's signature"}`)) return } _ = json.Unmarshal(signed.Ask, &heard) switch heard.Path { case "/srv/notes": body, _ := json.Marshal(HandOverAnswer{Said: "/srv/notes (notes.data) is handed to the mesh by " + heard.By}) _ = msg.Respond(body) case "/srv/empty": _ = msg.Respond([]byte(`{}`)) default: body, _ := json.Marshal(HandOverAnswer{Refused: heard.Path + " is not a directory this machine uses as found; nothing was handed over"}) _ = msg.Respond(body) } }) if err != nil { t.Fatal(err) } t.Cleanup(func() { _ = engine.Unsubscribe() }) ctx := context.Background() a, err := AskHandOver(ctx, conn, signer, "laptop", "/srv/notes", "jo through mesh-cli on anchor", 5*time.Second) if err != nil || a.Refused != "" || !strings.Contains(a.Said, "handed to the mesh by jo through mesh-cli on anchor") { t.Fatalf("answered %+v, %v", a, err) } if heard.Node != "laptop" || heard.Path != "/srv/notes" || heard.By != "jo through mesh-cli on anchor" { t.Fatalf("the engine heard %+v", heard) } a, err = AskHandOver(ctx, conn, signer, "laptop", "/srv/other", "jo", 5*time.Second) if err != nil || a.Said != "" || !strings.Contains(a.Refused, "nothing was handed over") { t.Fatalf("a refusal came back as %+v, %v", a, err) } if _, err := AskHandOver(ctx, conn, signer, "laptop", "/srv/empty", "jo", 5*time.Second); err == nil || !strings.Contains(err.Error(), "neither") { t.Fatalf("an empty answer was taken: %v", err) } if _, err := AskHandOver(ctx, conn, signer, "anchor", "/srv/notes", "jo", 5*time.Second); err == nil || !strings.Contains(err.Error(), "node-engine") { t.Fatalf("a machine with no engine listening: %v", err) } if _, err := AskHandOver(ctx, nil, signer, "anchor", "/srv/notes", "jo", time.Second); err == nil { t.Fatal("asked with no bus") } } // A machine's grant hears its own hand-over ask and nobody else's, and may answer it: the one request a node is // asked (novox/hq issue 356). func TestAMachineHearsItsOwnHandOverAskAndMayAnswerIt(t *testing.T) { perms, err := broker.PermissionsFor(broker.Principal{Kind: broker.KindNode, Node: "laptop", PasswordHash: "x"}) if err != nil { t.Fatal(err) } var hears, other bool for _, s := range perms.Subscribe { hears = hears || s == "mesh.node.laptop.ask.hand-over" other = other || s == "mesh.node.anchor.ask.hand-over" } if !hears || other || !perms.AllowResponses { t.Fatalf("a machine's grant: hears its own %v, another's %v, answers %v (%v)", hears, other, perms.AllowResponses, perms.Subscribe) } }