networking required mesh-wireguard and nothing else; machines are assigned the network directly. module forget refuses a provided module, so a retired one is removed at start once no machine has it. Guard route-proxy's public account directory against a reissue.
272 lines
11 KiB
Go
272 lines
11 KiB
Go
package catalogue
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// The mesh has two resolvers (novox/hq ADR 0223): `mesh-dns-resolver` is replicated, held on the
|
|
// anchor and on the home server, each answering the same names; every machine's resolver file lists
|
|
// every holder — its own first when it is one — and no public resolver. ADR 0196 listed the mesh's
|
|
// resolver then a public one, and musl asks both at once and takes the first reply: from the home
|
|
// server the public "no such name" for the anchor's mesh name won, every time, in every Alpine build.
|
|
// The file is written by the module holding the machine's uplink (ADR 0223 part 2).
|
|
|
|
// resolverMachines is the anchor and the home server holding the resolver, and a laptop holding nothing.
|
|
var resolverMachines = map[string]string{
|
|
"anchor.internal": "10.42.0.1", "laptop.internal": "10.42.0.2", "home.internal": "10.42.0.3"}
|
|
|
|
// bothResolvers is the two holders on record, as `seat mesh-dns-resolver --add` leaves them.
|
|
var bothResolvers = []Held{
|
|
{Claim: "mesh-dns-resolver", Scope: ScopeMesh, Node: "anchor", Module: "dnsmasq"},
|
|
{Claim: "mesh-dns-resolver", Scope: ScopeMesh, Node: "home", Module: "dnsmasq"},
|
|
}
|
|
|
|
// uplinks is every module in the catalogue holding node-uplink, and so writing the machine's resolver
|
|
// file (novox/hq ADR 0223 part 2): the program that would otherwise rewrite it is the one that writes it.
|
|
// dhcpcd's left the catalogue with ADR 0226, held by no machine.
|
|
var uplinks = []string{"networkmanager", "systemd-networkd"}
|
|
|
|
// managing is a machine as each uplink module needs it: able to install, run a service and run the
|
|
// manager that module is for.
|
|
func managing(node string) Node {
|
|
caps := map[string]bool{"package-manager": true, "service-manager": true}
|
|
for _, u := range uplinks {
|
|
caps["uplink-"+u] = true
|
|
}
|
|
return Node{Name: node, At: node + ".internal", Capabilities: caps}
|
|
}
|
|
|
|
// twoResolverShelf is the resolver, the uplink modules that write what a machine asks, and a stand-in
|
|
// answering `mesh-addressing`.
|
|
func twoResolverShelf(t *testing.T) map[string]Manifest {
|
|
t.Helper()
|
|
out := map[string]Manifest{
|
|
"net": {Module: "net", Version: "1", Provides: []Offer{{Name: "mesh-addressing"}}},
|
|
"dnsmasq": catalogueManifest(t, "dnsmasq"),
|
|
}
|
|
for _, u := range uplinks {
|
|
out[u] = catalogueManifest(t, u)
|
|
}
|
|
return out
|
|
}
|
|
|
|
// worldWithout is the rest of the mesh as a plan for one machine sees it: every other holder's claim
|
|
// and offer, and both holders on record.
|
|
func worldWithout(node string) World {
|
|
w := World{Holdings: bothResolvers, Offered: map[string][]Provider{}}
|
|
for _, h := range bothResolvers {
|
|
if h.Node == node {
|
|
continue
|
|
}
|
|
w.Held = append(w.Held, h)
|
|
w.Offered["wildcard-resolution"] = append(w.Offered["wildcard-resolution"],
|
|
Provider{Node: h.Node, At: h.Node + ".internal", Module: h.Module})
|
|
}
|
|
return w
|
|
}
|
|
|
|
// resolvConfOn resolves and composes one machine and answers with the nameservers its resolver file
|
|
// lists, in order, and the file. The file is the uplink's — `uplink` is one of the assigned modules —
|
|
// and nothing else on the machine declares that path.
|
|
func resolvConfOn(t *testing.T, node, uplink string, assigned []string) ([]string, string) {
|
|
t.Helper()
|
|
got, err := Resolve(twoResolverShelf(t), assigned, managing(node), worldWithout(node))
|
|
if err != nil {
|
|
t.Fatalf("%s with %s does not resolve with two resolvers on record: %v", node, uplink, err)
|
|
}
|
|
out, err := got.Declaration(Rendering{
|
|
Names: resolverMachines, Machines: resolverMachines, Suffix: "internal",
|
|
Holders: map[string]map[string]string{"mesh-dns-resolver": {
|
|
"anchor.internal": "10.42.0.1", "home.internal": "10.42.0.3"}},
|
|
Needed: map[string]map[string]string{"dnsmasq": {"broker": "sealed"}},
|
|
})
|
|
if err != nil {
|
|
t.Fatalf("%s with %s does not compose: %v", node, uplink, err)
|
|
}
|
|
var file map[string]any
|
|
for _, r := range out {
|
|
if r["path"] != "/etc/resolv.conf" {
|
|
continue
|
|
}
|
|
if file != nil {
|
|
t.Fatalf("%s declares /etc/resolv.conf twice: %v and %v", node, file["id"], r["id"])
|
|
}
|
|
file = r
|
|
}
|
|
if file == nil || file["id"] != uplink+".fact-resolvers" {
|
|
t.Fatalf("%s's resolver file is not %s's: %v", node, uplink, file)
|
|
}
|
|
content, _ := file["content"].(string)
|
|
var servers []string
|
|
for _, line := range strings.Split(content, "\n") {
|
|
if strings.HasPrefix(line, "nameserver ") {
|
|
servers = append(servers, strings.TrimPrefix(line, "nameserver "))
|
|
}
|
|
}
|
|
return servers, content
|
|
}
|
|
|
|
// Per uplink module: each writes a resolver file listing both holders, the machine's own first on a
|
|
// holder, and only the holders on a machine that is none.
|
|
func TestEveryUplinkListsBothResolversItsOwnFirst(t *testing.T) {
|
|
for _, uplink := range uplinks {
|
|
for node, want := range map[string][]string{
|
|
"anchor": {"10.42.0.1", "10.42.0.3"},
|
|
"home": {"10.42.0.3", "10.42.0.1"},
|
|
"laptop": {"10.42.0.1", "10.42.0.3"},
|
|
} {
|
|
assigned := []string{uplink}
|
|
if node != "laptop" {
|
|
assigned = append(assigned, "dnsmasq")
|
|
}
|
|
servers, content := resolvConfOn(t, node, uplink, assigned)
|
|
if strings.Join(servers, " ") != strings.Join(want, " ") {
|
|
t.Errorf("%s on %s lists %v; want %v\n%s", uplink, node, servers, want, content)
|
|
}
|
|
for _, public := range []string{"1.1.1.1", "8.8.8.8", "9.9.9.9"} {
|
|
if strings.Contains(content, public) {
|
|
t.Errorf("%s on %s lists a public resolver beside the mesh's (ADR 0223):\n%s", uplink, node, content)
|
|
}
|
|
}
|
|
if !strings.HasSuffix(content, "\noptions timeout:1 attempts:2 edns0\n") {
|
|
t.Errorf("%s on %s does not end with two short attempts:\n%s", uplink, node, content)
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
// One file, whichever manager the machine runs: the three modules carry the same template, so a
|
|
// machine changing its manager changes nothing in what it asks, and a fix made to one is made to all.
|
|
func TestEveryUplinkWritesTheSameResolverFile(t *testing.T) {
|
|
var first, firstOf string
|
|
for _, uplink := range uplinks {
|
|
fact, ok := catalogueManifest(t, uplink).Facts["resolvers"]
|
|
if !ok || fact.Path != "/etc/resolv.conf" || fact.Shared || fact.Home {
|
|
t.Fatalf("%s does not write the machine's resolver file whole: %+v", uplink, fact)
|
|
}
|
|
if first == "" {
|
|
first, firstOf = fact.Template, uplink
|
|
continue
|
|
}
|
|
if fact.Template != first {
|
|
t.Errorf("%s's resolver file differs from %s's; the three are kept identical", uplink, firstOf)
|
|
}
|
|
}
|
|
}
|
|
|
|
// The requirement stays with what writes the file (ADR 0223 part 1): a machine is refused when nothing
|
|
// in the mesh resolves, rather than given a file listing nothing.
|
|
func TestEveryUplinkRequiresTheMeshsResolver(t *testing.T) {
|
|
for _, uplink := range uplinks {
|
|
found := false
|
|
for _, r := range catalogueManifest(t, uplink).Requires {
|
|
found = found || r == "wildcard-resolution"
|
|
}
|
|
if !found {
|
|
t.Errorf("%s writes the resolver file and does not require wildcard-resolution", uplink)
|
|
}
|
|
}
|
|
_, err := Resolve(twoResolverShelf(t), []string{"networkmanager"}, managing("laptop"), World{})
|
|
if err == nil || !strings.Contains(err.Error(), "wildcard-resolution") {
|
|
t.Errorf("an uplink was composed on a mesh with no resolver: %v", err)
|
|
}
|
|
}
|
|
|
|
// A holder answers its own requirement, even though the other holder sorts first (issue 258 kept).
|
|
func TestAHolderAnswersItsOwnRequirement(t *testing.T) {
|
|
got, err := Resolve(twoResolverShelf(t), []string{"dnsmasq", "networkmanager"},
|
|
managing("home"), worldWithout("home"))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
for _, n := range got.Needs {
|
|
if n.Name == "wildcard-resolution" && n.From != "home" {
|
|
t.Errorf("the home server's uplink is bound to %s; it holds the seat itself", n.From)
|
|
}
|
|
}
|
|
}
|
|
|
|
// A seat held once is still held once: a second claimant on another machine is refused while
|
|
// nothing is on record, and a store recording two holders of it is refused, naming the seat.
|
|
func TestASingleHolderMeshSeatStillRefusesASecondHolder(t *testing.T) {
|
|
store := shelf(mod("postgres", nil, nil, nil, Claim{Name: "mesh-store", Scope: ScopeMesh}))
|
|
other := Held{Claim: "mesh-store", Scope: ScopeMesh, Node: "anchor", Module: "postgres"}
|
|
if _, err := Resolve(store, []string{"postgres"}, workstation(), World{Held: []Held{other}}); err == nil ||
|
|
!strings.Contains(err.Error(), "one per mesh") {
|
|
t.Errorf("a second claimant of a seat held once was not refused: %v", err)
|
|
}
|
|
here := Held{Claim: "mesh-store", Scope: ScopeMesh, Node: workstation().Name, Module: "postgres"}
|
|
_, err := Resolve(store, []string{"postgres"}, workstation(),
|
|
World{Held: []Held{other}, Holdings: []Held{other, here}})
|
|
if err == nil || !strings.Contains(err.Error(), "on record as held by 2") {
|
|
t.Errorf("two holders on record for a seat held once were not refused: %v", err)
|
|
}
|
|
}
|
|
|
|
// Replicated is not "whoever is assigned": two claimants with nothing on record are refused, as for
|
|
// any mesh seat, and each holder is added by an act.
|
|
func TestTwoUnrecordedClaimantsOfTheReplicatedSeatAreRefused(t *testing.T) {
|
|
w := worldWithout("home")
|
|
w.Holdings = nil
|
|
_, err := Resolve(twoResolverShelf(t), []string{"dnsmasq"}, Node{Name: "home", At: "home.internal"}, w)
|
|
if err == nil || !strings.Contains(err.Error(), "seat mesh-dns-resolver --to") {
|
|
t.Errorf("a second resolver with nothing on record was not refused, naming the handover: %v", err)
|
|
}
|
|
}
|
|
|
|
// Only the mesh's resolver is replicated: a seat being replicated is a decision, recorded.
|
|
func TestOnlyTheResolverIsReplicated(t *testing.T) {
|
|
for _, s := range Seats() {
|
|
if s.Replicated != (s.Name == "mesh-dns-resolver") {
|
|
t.Errorf("%s replicated = %v; only mesh-dns-resolver is (ADR 0223)", s.Name, s.Replicated)
|
|
}
|
|
}
|
|
UseSeats([]Seat{{Name: "mesh-dns-resolver", Scope: ScopeMesh, Delivers: "wildcard-resolution"}})
|
|
defer UseSeats(DefaultSeats())
|
|
if s, _ := SeatNamed("mesh-dns-resolver"); !s.Replicated {
|
|
t.Error("loading the set from the store, which has no column for it, lost the resolver's replication")
|
|
}
|
|
}
|
|
|
|
// Every consumer is bound to the same holder whatever order the mesh resolved its machines in.
|
|
func TestTheFirstHolderIsTheFirstProvider(t *testing.T) {
|
|
providers := []Provider{{Node: "anchor", Module: "dnsmasq"}, {Node: "home", Module: "dnsmasq"}}
|
|
for _, held := range [][]Held{bothResolvers, {bothResolvers[1], bothResolvers[0]}} {
|
|
if p, ok := HolderAmong("wildcard-resolution", providers, held); !ok || p.Node != "anchor" {
|
|
t.Errorf("held in order %v answered %v", held, p)
|
|
}
|
|
}
|
|
}
|
|
|
|
// One host record per machine, beside its wildcard (novox/hq issue 262): a name with a host record
|
|
// says it exists and has no IPv6 address, where the wildcard alone said there is no such name, and
|
|
// musl reads that as final.
|
|
func TestTheResolverHasOneHostRecordPerMachine(t *testing.T) {
|
|
got, err := Resolve(twoResolverShelf(t), []string{"dnsmasq"}, Node{Name: "anchor", At: "anchor.internal"},
|
|
World{})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
out, err := got.Declaration(Rendering{Names: resolverMachines, Machines: resolverMachines, Suffix: "internal",
|
|
Needed: map[string]map[string]string{"dnsmasq": {"broker": "sealed"}}})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
content, _ := byID(out)["dnsmasq.fact-node-zones"]["content"].(string)
|
|
records := map[string]int{}
|
|
for _, line := range strings.Split(content, "\n") {
|
|
if strings.HasPrefix(line, "host-record=") {
|
|
records[strings.TrimPrefix(line, "host-record=")]++
|
|
}
|
|
}
|
|
for name, at := range resolverMachines {
|
|
if records[name+","+at] != 1 {
|
|
t.Errorf("%s has %d host records at %s, and has one:\n%s", name, records[name+","+at], at, content)
|
|
}
|
|
}
|
|
if len(records) != len(resolverMachines) {
|
|
t.Errorf("%d host records for %d machines:\n%s", len(records), len(resolverMachines), content)
|
|
}
|
|
}
|