package overlay import ( "strings" "testing" ) // Names are their own module. // // They used to arrive inside the WireGuard declaration, on the argument that a machine with peers // and no names is half on the network. True, and the wrong place to fix it: names would be // identical over a different private network, so bundling them made one module out of two things. func TestAMachineNotOnTheNetworkGetsNoNames(t *testing.T) { // Names resolve to addresses on the private wire. Giving them to a machine that is not on it // would point every lookup somewhere it cannot reach — worse than having no names at all. g := NamesFor([]Node{at("anchor", "dc", "10.42.0.1", "198.51.100.10:51820", true)}) _, part, err := g.Resources("laptop") if err != nil { t.Fatal(err) } if part { t.Fatal("a machine that is not on the private network was given the mesh's names") } } func TestTheNamesAreOneFileAndSayWhoIsAsking(t *testing.T) { g := NamesFor([]Node{ at("anchor", "dc", "10.42.0.1", "198.51.100.10:51820", true), at("workstation", "house", "10.42.0.2", "", false), }) out, part, err := g.Resources("workstation") if err != nil || !part { t.Fatalf("part=%v err=%v", part, err) } if len(out) != 1 || out[0]["path"] != HostsPath { t.Fatalf("got %v", out) } content := out[0]["content"].(string) if !strings.Contains(content, "anchor.internal") { t.Fatalf("another machine on the network has no name here:\n%s", content) } if !strings.Contains(content, "this machine") { t.Fatalf("the file does not say which machine it is on:\n%s", content) } } func TestTheWireGuardDeclarationNoLongerCarriesTheNames(t *testing.T) { // The split, asserted. Two modules, so a machine can have the peers from one and the names // from another — which is what makes a second VPN possible at all. raw, err := Declaration( at("workstation", "house", "10.42.0.2", "", false), []Peer{{Name: "anchor", Key: "PUB", Allowed: "10.42.0.0/16", Endpoint: "198.51.100.10:51820"}}, "") if err != nil { t.Fatal(err) } if strings.Contains(string(raw), HostsPath) { t.Fatalf("the WireGuard declaration still writes %s", HostsPath) } }