Brought back from 53eb000, withdrawn because it refused the builder's mount of the
container runtime's socket. A path is declared as the module's own (a directory or
file resource, or where a secret, grant or contribution lands), as the operator's
(an accesses entry, ADR 0051), or as the machine's (a facility a declared capability
grants: container-runtime grants its socket). Every catalogue manifest passes, and
a test says so (novox/hq 04-ISSUES/026, ADR 0091).
87 lines
3.7 KiB
Go
87 lines
3.7 KiB
Go
package catalogue
|
|
|
|
import (
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// A bind mount the module never declared is refused where it is written (novox/hq 04-ISSUES/026,
|
|
// ADR 0091). The container runtime creates a missing bind source itself, as root, with a mode it
|
|
// picks, so the module's own owner and mode never reach the directory holding its data, and the
|
|
// rule that keeps data when a module goes away (ADR 0030) does not cover it.
|
|
|
|
const aContainerMounting = `{"id":"server","type":"container","name":"store","image":"x@sha256:` +
|
|
`0000000000000000000000000000000000000000000000000000000000000000","volumes":["%s:/inside"]}`
|
|
|
|
func manifestMounting(from string, beside string) []byte {
|
|
res := aContainerMounting
|
|
if beside != "" {
|
|
res = beside + "," + res
|
|
}
|
|
return []byte(`{"module":"store","resources":[` + strings.Replace(res, "%s", from, 1) + `]}`)
|
|
}
|
|
|
|
func TestAMountNothingDeclaresIsRefused(t *testing.T) {
|
|
_, err := ParseManifest(manifestMounting("/services/store/data", ""))
|
|
if err == nil {
|
|
t.Fatal("a container mounting a path no resource declares was accepted; the runtime " +
|
|
"would create it as root and the module's owner and mode would never apply")
|
|
}
|
|
if !strings.Contains(err.Error(), "/services/store/data") {
|
|
t.Fatalf("refused without naming the path, which leaves the author guessing: %v", err)
|
|
}
|
|
}
|
|
|
|
// Declaring it is enough — including declaring the directory above it.
|
|
func TestAMountUnderADeclaredDirectoryIsAccepted(t *testing.T) {
|
|
_, err := ParseManifest(manifestMounting("/services/store/data",
|
|
`{"id":"state","type":"directory","path":"/services/store","mode":"0700"}`))
|
|
if err != nil {
|
|
t.Fatalf("a module that said where its data lives was refused anyway: %v", err)
|
|
}
|
|
}
|
|
|
|
// The operator's path, granted for use (ADR 0051), is declared by `accesses`, not by a directory the
|
|
// module would then own.
|
|
func TestAMountOfAnAccessedPathIsAccepted(t *testing.T) {
|
|
_, err := ParseManifest([]byte(`{"module":"store","accesses":[{"path":"/services/media/movies","mode":"read"}],` +
|
|
`"resources":[` + strings.Replace(aContainerMounting, "%s", "/services/media/movies", 1) + `]}`))
|
|
if err != nil {
|
|
t.Fatalf("a mount of a path the module declares it accesses was refused: %v", err)
|
|
}
|
|
}
|
|
|
|
// The machine's facility — the container runtime's socket — is granted by the capability that names
|
|
// it, and declaring it as the module's own directory would be a lie the host would act on. This is
|
|
// the case the first version of this check refused, and was withdrawn for: the builder.
|
|
func TestTheRuntimeSocketIsGrantedByTheCapabilityAndNotOtherwise(t *testing.T) {
|
|
granted := `{"module":"builder","capabilities":["container-runtime"],"resources":[` +
|
|
strings.Replace(aContainerMounting, "%s", "/var/run/docker.sock", 1) + `]}`
|
|
if _, err := ParseManifest([]byte(granted)); err != nil {
|
|
t.Fatalf("a module with the container-runtime capability may mount its socket: %v", err)
|
|
}
|
|
if _, err := ParseManifest(manifestMounting("/var/run/docker.sock", "")); err == nil {
|
|
t.Fatal("a module mounted the container runtime's socket without declaring the capability, and was accepted")
|
|
}
|
|
}
|
|
|
|
// **Every manifest in the catalogue beside this checkout passes**, so the rule is not one the
|
|
// catalogue is already breaking. Skipped, aloud, where the catalogue is not there.
|
|
func TestEveryCatalogueManifestDeclaresWhatItMounts(t *testing.T) {
|
|
files, _ := filepath.Glob("../../../mesh-catalog/modules/*/module.json")
|
|
if len(files) == 0 {
|
|
t.Skip("the catalogue is not beside this checkout")
|
|
}
|
|
for _, file := range files {
|
|
raw, err := os.ReadFile(file)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if _, err := ParseManifest(raw); err != nil {
|
|
t.Errorf("%s: %v", filepath.Base(filepath.Dir(file)), err)
|
|
}
|
|
}
|
|
}
|