A container may be marked `run-once: true` — a step the host runs to completion, gating whatever the declaration places after it. The control plane's part is small: the field is carried to the host unchanged (containers pass through as maps), and the step keeps its author-order position ahead of the container it gates, because the gate is declaration order, not a resolved dependency (ADR 0005). The manifest parser refuses a run-once that is not a boolean and the pair run-once + restart-on (contradictory lifecycles) — near the manifest rather than far away on the machine, the same lesson the action ban records. Three unit tests; go build ./... and go test ./... green. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
94 lines
3.7 KiB
Go
94 lines
3.7 KiB
Go
package catalogue
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// A run-once container is a step the host runs to completion (novox/hq ADR 0052). The control
|
|
// plane's part is small and exact: carry the field to the host unchanged, keep the step ahead of
|
|
// the container it gates in author order, and refuse a malformed run-once near its cause rather
|
|
// than on the machine. These tests defend that.
|
|
|
|
// indexOfID returns the position of the resource with the given (module-prefixed) id, or -1.
|
|
func indexOfID(out []map[string]any, id string) int {
|
|
for i, r := range out {
|
|
if r["id"] == id {
|
|
return i
|
|
}
|
|
}
|
|
return -1
|
|
}
|
|
|
|
func TestARunOnceContainerRendersBeforeTheContainerItGates(t *testing.T) {
|
|
// The gate is declaration order, not a resolved dependency: the step is written before the
|
|
// container that needs it, and the host applies in order and stops at a step that did not
|
|
// complete. So the control plane must carry run-once through untouched and must not reorder the
|
|
// two containers.
|
|
digest := "@sha256:" + strings.Repeat("a", 64)
|
|
r := Resolution{Node: "laptop", Modules: []Manifest{{
|
|
Module: "mosquitto",
|
|
Resources: []map[string]any{
|
|
{"id": "seed", "type": "container", "name": "seed",
|
|
"image": "registry.example/runtime" + digest, "run-once": true},
|
|
{"id": "server", "type": "container", "name": "broker",
|
|
"image": "registry.example/broker" + digest},
|
|
},
|
|
}}}
|
|
out, err := r.Declaration(Rendering{})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
|
|
seed := indexOfID(out, "mosquitto.seed")
|
|
server := indexOfID(out, "mosquitto.server")
|
|
if seed == -1 || server == -1 {
|
|
t.Fatalf("a container was lost in rendering: seed=%d server=%d", seed, server)
|
|
}
|
|
if seed >= server {
|
|
t.Errorf("the run-once step rendered after the container it gates (seed=%d server=%d)", seed, server)
|
|
}
|
|
if once, _ := out[seed]["run-once"].(bool); !once {
|
|
t.Errorf("run-once did not reach the host declaration: %+v", out[seed])
|
|
}
|
|
if _, present := out[server]["run-once"]; present {
|
|
t.Errorf("run-once leaked onto the container that is not a step: %+v", out[server])
|
|
}
|
|
}
|
|
|
|
func TestARunOnceMustBeABoolean(t *testing.T) {
|
|
// A value that is not true or false is refused here, not sent to a machine that would then have
|
|
// to guess what a string means.
|
|
digest := "@sha256:" + strings.Repeat("a", 64)
|
|
bad := []byte(`{"module":"m","resources":[
|
|
{"id":"seed","type":"container","name":"seed","image":"registry.example/x` + digest + `","run-once":"yes"}
|
|
]}`)
|
|
if _, err := ParseManifest(bad); err == nil {
|
|
t.Error("a run-once that is not a boolean was accepted")
|
|
} else if !strings.Contains(err.Error(), "run-once") {
|
|
t.Errorf("refused for the wrong reason: %v", err)
|
|
}
|
|
|
|
good := []byte(`{"module":"m","resources":[
|
|
{"id":"seed","type":"container","name":"seed","image":"registry.example/x` + digest + `","run-once":true}
|
|
]}`)
|
|
if _, err := ParseManifest(good); err != nil {
|
|
t.Errorf("a valid run-once container was refused: %v", err)
|
|
}
|
|
}
|
|
|
|
func TestARunOnceContainerCannotAlsoDeclareRestartOn(t *testing.T) {
|
|
// restart-on brings a running container back; a run-once step does not stay running. The pair
|
|
// is a contradiction, refused at the manifest rather than surfacing far away on the host.
|
|
digest := "@sha256:" + strings.Repeat("a", 64)
|
|
bad := []byte(`{"module":"m","resources":[
|
|
{"id":"conf","type":"file","path":"/x","content":"y"},
|
|
{"id":"seed","type":"container","name":"seed","image":"registry.example/x` + digest + `","run-once":true,"restart-on":["conf"]}
|
|
]}`)
|
|
if _, err := ParseManifest(bad); err == nil {
|
|
t.Error("a run-once container that also declared restart-on was accepted")
|
|
} else if !strings.Contains(err.Error(), "restart-on") {
|
|
t.Errorf("refused for the wrong reason: %v", err)
|
|
}
|
|
}
|