Files
mesh-controller/internal/builder/builder_test.go
T
jschoubben 4b9bc50aad The builder resolves the SDK from the mesh registry, and can publish packages
A new 'package' artifact kind builds a module's own code on a public base image
and publishes it to the mesh's package registry by version (hq ADR 0076) — the
SDK above all, which the toolchain is built from and so cannot be built in the
toolchain. The credential a build needs to resolve or publish packages is
rendered as an .npmrc (basic auth, hq ADR 0048) and given to an image build as a
buildkit secret, never a layer, so a token is not baked into the toolchain image.

Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
2026-09-16 10:27:26 +02:00

334 lines
13 KiB
Go

package builder
import (
"context"
"os"
"path/filepath"
"strings"
"testing"
"time"
"github.com/novox/mesh-control/internal/catalogue"
)
// A repository becoming artifacts the mesh can pin.
//
// git and docker are injected rather than run, because what is under test is the ORDER and the
// refusals — that nothing is published until everything is built, that a build reads only its own
// tree, that two builds of one commit produce one digest. Running docker here would test docker.
type recorded struct {
ran []string
images map[string]string
archives map[string]string
failPush bool
// contents is what a clone of this repository lands, so the fake clone can restore the tree
// Build deliberately removes first.
contents map[string]string
// stamped is the modification time the clone gives every file. Set differently between two
// builds of one commit, because otherwise both land in the same second and a packer that
// carried timestamps would still produce one digest — which is a test that passes for a
// reason that has nothing to do with what it claims.
stamped time.Time
}
func (r *recorded) run(_ context.Context, dir, name string, args ...string) (string, error) {
line := name + " " + strings.Join(args, " ")
r.ran = append(r.ran, line)
switch {
case name == "git" && len(args) > 0 && args[0] == "clone":
tree := args[len(args)-1]
if err := os.MkdirAll(tree, 0o755); err != nil {
return "", err
}
for path, body := range r.contents {
full := filepath.Join(tree, path)
if err := os.MkdirAll(filepath.Dir(full), 0o755); err != nil {
return "", err
}
if err := os.WriteFile(full, []byte(body), 0o644); err != nil {
return "", err
}
if !r.stamped.IsZero() {
if err := os.Chtimes(full, r.stamped, r.stamped); err != nil {
return "", err
}
}
}
return "", nil
case name == "git" && len(args) > 0 && args[0] == "rev-parse":
return "c0ffeec0ffeec0ffeec0ffeec0ffeec0ffeec0ff\n", nil
}
_ = dir
return "", nil
}
func (r *recorded) PublishImage(_ context.Context, localTag, repository string) (string, error) {
if r.failPush {
return "", os.ErrPermission
}
if r.images == nil {
r.images = map[string]string{}
}
r.images[repository] = localTag
return "registry.invalid/" + repository + "@sha256:" + strings.Repeat("a", 64), nil
}
func (r *recorded) PublishArchive(_ context.Context, repository string, body []byte, digest string) (string, error) {
if r.failPush {
return "", os.ErrPermission
}
if r.archives == nil {
r.archives = map[string]string{}
}
r.archives[repository] = digest
_ = body
return "https://store.invalid/" + repository, nil
}
// aRepository is a workspace whose clone lands a manifest and some files.
func aRepository(t *testing.T, manifest string, files map[string]string) (*recorded, string) {
t.Helper()
contents := map[string]string{ManifestName: manifest}
for name, body := range files {
contents[name] = body
}
return &recorded{contents: contents}, t.TempDir()
}
const withBoth = `{"module":"meshboard","version":"1",
"build":{"artifacts":[
{"name":"server","kind":"image","from":"Dockerfile"},
{"name":"look","kind":"archive","from":"files"}]},
"resources":[
{"id":"svc","type":"container","name":"meshboard","artifact":"server"},
{"id":"theme","type":"archive","path":"/opt/meshboard","artifact":"look"}]}`
func TestABuildProducesAManifestThePinsAreIn(t *testing.T) {
r, workspace := aRepository(t, withBoth, map[string]string{
"Dockerfile": "FROM scratch", "files/theme.conf": "dark",
})
got, err := Build(context.Background(), r.run, r, "https://forge.invalid/meshboard.git", "", "", workspace, nil, Npmrc{}, nil)
if err != nil {
t.Fatal(err)
}
if got.Commit != "c0ffeec0ffeec0ffeec0ffeec0ffeec0ffeec0ff" {
t.Fatalf("the commit was not recorded: %q", got.Commit)
}
if got.Manifest.Resources[0]["image"] == nil {
t.Fatalf("the image was not pinned: %v", got.Manifest.Resources[0])
}
digest, _ := got.Manifest.Resources[1]["digest"].(string)
if !strings.HasPrefix(digest, "sha256:") {
t.Fatalf("the archive was not pinned: %v", got.Manifest.Resources[1])
}
}
func TestTwoBuildsOfOneCommitProduceOneDigest(t *testing.T) {
// Or nothing downstream can tell "this changed" from "this was built again", and every
// rebuild looks like a change to every machine holding it.
var digests []string
for i := 0; i < 2; i++ {
r, workspace := aRepository(t, withBoth, map[string]string{
"Dockerfile": "FROM scratch", "files/a.conf": "one", "files/b.conf": "two",
})
// A year apart, so a packer carrying timestamps cannot accidentally agree.
r.stamped = time.Date(2020+i, time.March, 3, 4, 5, 6, 0, time.UTC)
got, err := Build(context.Background(), r.run, r, "https://forge.invalid/x.git", "", "", workspace, nil, Npmrc{}, nil)
if err != nil {
t.Fatal(err)
}
for _, b := range got.Built {
if b.Kind == catalogue.ArtifactArchive {
digests = append(digests, b.Digest)
}
}
}
if digests[0] != digests[1] {
t.Fatalf("two builds of one commit produced %s and %s", digests[0], digests[1])
}
}
func TestNothingIsPublishedUntilEverythingIsBuilt(t *testing.T) {
// Half a module in the store under a digest the mesh never records is reachable,
// unreferenced, and indistinguishable from something in use.
r, workspace := aRepository(t, withBoth, map[string]string{"Dockerfile": "FROM scratch"})
// `files` is missing, so packing the archive fails — after the image would have been pushed.
_, err := Build(context.Background(), r.run, r, "https://forge.invalid/x.git", "", "", workspace, nil, Npmrc{}, nil)
if err == nil {
t.Fatal("a build with a missing input succeeded")
}
if len(r.archives) != 0 {
t.Fatalf("an archive was published by a failed build: %v", r.archives)
}
}
func TestARepositoryWithNoManifestSaysSo(t *testing.T) {
workspace := t.TempDir()
r := &recorded{contents: map[string]string{"README.md": "nothing to see"}}
_, err := Build(context.Background(), r.run, r, "https://forge.invalid/x.git", "", "", workspace, nil, Npmrc{}, nil)
if err == nil {
t.Fatal("a repository with nothing saying what it is was built")
}
if !strings.Contains(err.Error(), ManifestName) {
t.Fatalf("the failure does not name what is missing: %v", err)
}
}
func TestAModuleThatBuildsNothingStillProducesAManifest(t *testing.T) {
// Most of what a person installs is configuration.
r, workspace := aRepository(t, `{"module":"shell","version":"1","resources":[
{"id":"rc","type":"file","path":"/etc/zsh/zshrc","content":"setopt"}]}`, nil)
got, err := Build(context.Background(), r.run, r, "https://forge.invalid/shell.git", "", "", workspace, nil, Npmrc{}, nil)
if err != nil {
t.Fatal(err)
}
if len(got.Built) != 0 {
t.Fatalf("something was built: %v", got.Built)
}
if got.Manifest.Module != "shell" || len(got.Manifest.Resources) != 1 {
t.Fatalf("got %+v", got.Manifest)
}
for _, line := range r.ran {
if strings.HasPrefix(line, "docker") {
t.Fatalf("docker was run for a module that builds nothing: %q", line)
}
}
}
func TestTheTreeIsFreshEveryTime(t *testing.T) {
// A build that reuses a working tree can succeed because of something a previous build left
// behind, and that is a build nobody can reproduce.
r, workspace := aRepository(t, withBoth, map[string]string{
"Dockerfile": "FROM scratch", "files/a": "b",
})
leftover := filepath.Join(workspace, "source", "files", "from-last-time")
if err := os.MkdirAll(filepath.Dir(leftover), 0o755); err != nil {
t.Fatal(err)
}
if err := os.WriteFile(leftover, []byte("stale"), 0o644); err != nil {
t.Fatal(err)
}
if _, err := Build(context.Background(), r.run, r, "https://forge.invalid/x.git", "", "", workspace, nil, Npmrc{}, nil); err != nil {
t.Fatal(err)
}
if _, err := os.Stat(leftover); err == nil {
t.Fatal("a previous build's file survived into this one")
}
}
func TestABuildThatCannotPushFails(t *testing.T) {
r, workspace := aRepository(t, withBoth, map[string]string{
"Dockerfile": "FROM scratch", "files/a": "b",
})
r.failPush = true
if _, err := Build(context.Background(), r.run, r, "https://forge.invalid/x.git", "", "", workspace, nil, Npmrc{}, nil); err == nil {
t.Fatal("a build that could publish nothing reported success")
}
}
func TestAnUpstreamImageIsMirroredRatherThanBuilt(t *testing.T) {
// A module usually runs software it did not write. Naming the upstream reference directly
// would need every machine to reach a public registry, and would pin to a tag somebody else
// can move.
const mirrors = `{"module":"postgres","version":"1",
"build":{"artifacts":[{"name":"store","kind":"upstream","from":"postgres:17-alpine"}]},
"resources":[{"id":"db","type":"container","name":"mesh-postgres","artifact":"store"}]}`
r, workspace := aRepository(t, mirrors, nil)
got, err := Build(context.Background(), r.run, r, "https://forge.invalid/postgres.git", "", "", workspace, nil, Npmrc{}, nil)
if err != nil {
t.Fatal(err)
}
// Pulled, not built.
var pulled, built bool
for _, line := range r.ran {
if strings.HasPrefix(line, "docker pull postgres:17-alpine") {
pulled = true
}
if strings.HasPrefix(line, "docker build") {
built = true
}
}
if !pulled {
t.Fatalf("the upstream image was not fetched: %v", r.ran)
}
if built {
t.Fatalf("something was built for an image that is mirrored: %v", r.ran)
}
// And the resource names what this registry serves, pinned by the digest it assigned.
image, _ := got.Manifest.Resources[0]["image"].(string)
if !strings.Contains(image, "@sha256:") {
t.Fatalf("the mirrored image is not pinned by digest: %q", image)
}
if strings.Contains(image, "17-alpine") {
t.Fatalf("the resource still names the upstream tag: %q", image)
}
}
func TestAnUpstreamImageWithNoTagIsRefused(t *testing.T) {
// What gets mirrored would be whatever `latest` means today, and a module pinned to that is
// not pinned.
_, err := catalogue.ParseManifest([]byte(`{"module":"a","version":"1","build":{"artifacts":[
{"name":"x","kind":"upstream","from":"postgres"}]}}`))
if err == nil {
t.Fatal("an untagged upstream reference was accepted")
}
if !strings.Contains(err.Error(), "no tag or digest") {
t.Fatalf("unhelpful refusal: %v", err)
}
}
func TestAnUpstreamReferenceIsNotAPathInTheRepository(t *testing.T) {
// The rule that a build reads only its own repository must not refuse every reference with a
// registry host in it.
if _, err := catalogue.ParseManifest([]byte(`{"module":"a","version":"1","build":{"artifacts":[
{"name":"x","kind":"upstream","from":"registry.example/library/postgres:17"}]}}`)); err != nil {
t.Fatalf("a perfectly ordinary upstream reference was refused: %v", err)
}
}
// **A module is a repository and a path within it** (novox/hq ADR 0069). The catalogue holds its
// modules one to a directory and the system this replaces has always built one that way, so a
// builder that could only read a repository's root could build none of what exists.
func TestAModuleIsBuiltFromItsPathWithinTheRepository(t *testing.T) {
r := &recorded{contents: map[string]string{
"README.md": "this repository holds several modules",
"modules/shell/" + ManifestName: withBoth,
"modules/shell/Dockerfile": "FROM scratch",
"modules/shell/files/theme.conf": "dark",
// A second module beside it, so what is built is chosen by the path rather than by
// happening to be the only manifest in the clone.
"modules/other/" + ManifestName: `{"module":"other","version":"1"}`,
}}
got, err := Build(context.Background(), r.run, r,
"https://forge.invalid/catalogue.git", "modules/shell", "", t.TempDir(), nil, Npmrc{}, nil)
if err != nil {
t.Fatal(err)
}
if got.Manifest.Module != "meshboard" {
t.Fatalf("built %q, which is not the module at the path asked for", got.Manifest.Module)
}
if got.Manifest.Resources[0]["image"] == nil {
t.Fatalf("the image was not pinned: %v", got.Manifest.Resources[0])
}
}
// A build reads only its own tree. A path climbing out of the clone would otherwise let a build
// read — and an archive artifact publish — whatever the build machine happens to hold, which is
// the one thing a machine that builds other people's repositories must not do.
func TestAPathThatLeavesTheRepositoryIsRefused(t *testing.T) {
for _, escaping := range []string{"../../etc", "/etc"} {
r := &recorded{contents: map[string]string{ManifestName: withBoth}}
_, err := Build(context.Background(), r.run, r,
"https://forge.invalid/x.git", escaping, "", t.TempDir(), nil, Npmrc{}, nil)
if err == nil {
t.Fatalf("%q was accepted as a module's path", escaping)
}
if !strings.Contains(err.Error(), "leaves the repository") &&
!strings.Contains(err.Error(), "absolute path") {
t.Fatalf("the refusal of %q does not say why: %v", escaping, err)
}
}
}