Every check the mesh had ran after a merge, on a machine: a manifest the node-engine refused (236), an identity a real machine's name made too long (263). merge-gate raises the mesh as the facts snapshot says it is and the mesh with the change, each in a throwaway store through the controller's own records, composes every machine twice and validates it with the node-engine's validator, and fails what the change breaks, naming the machine's roles and the module - plus a manifest the judging controller cannot read, a consumer left out of its grant, a module removed while a machine runs it, a new module the node-engine would refuse; it warns on a wide rebuild. The forge's new head of a pull request becomes a check the controller asks of the build seat: the head and, beside it, the controller the mesh runs, the catalogue, the host and the lab; a throwaway store and bus of the versions the mesh runs; the repository's merge-check.sh in the mesh's Go toolchain with no container runtime socket; then mesh-lab's replays. The verdict is said as checked, an error never a pass, and nothing is recorded or registered.
209 lines
8.8 KiB
Go
209 lines
8.8 KiB
Go
package main
|
|
|
|
import (
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/novox/mesh-controller/internal/catalogue"
|
|
snapshot "github.com/novox/mesh-controller/internal/facts"
|
|
"github.com/novox/mesh-controller/internal/inventory"
|
|
)
|
|
|
|
// The merge gate (novox/hq to-be 45 §9): a change judged against every machine of the snapshot, by the
|
|
// incidents it is written from. Each case raises a mesh, takes its snapshot, and judges a pull request's
|
|
// tree against it in throwaway stores of its own.
|
|
|
|
// catalogueMesh is two machines and a catalogue repository: a resolver and an object store on the
|
|
// anchor, and on the laptop a network manager requiring the resolver, an album requiring the object
|
|
// store, and a login manager. Every module is registered from novox/mesh-catalog, as the mesh's are.
|
|
func catalogueMesh(t *testing.T) (snapshot.Facts, map[string]string) {
|
|
t.Helper()
|
|
open := aMesh(t)
|
|
ctx := t.Context()
|
|
manifests := map[string]string{
|
|
"objects": `{"module":"objects","version":"1",
|
|
"provides":[{"name":"s3-bucket","scope":"mesh","identity":{"max":20,"in":"an S3 access key"}}],
|
|
"receives":{"s3-bucket":"/var/lib/mesh/objects/mesh.json"}}`,
|
|
"resolver": `{"module":"resolver","version":"1",
|
|
"provides":[{"name":"wildcard-resolution","scope":"mesh","identity":false}]}`,
|
|
"networkmanager": `{"module":"networkmanager","version":"1","requires":["wildcard-resolution"]}`,
|
|
"album": `{"module":"album","version":"1","requires":["s3-bucket"]}`,
|
|
"lemurs": `{"module":"lemurs","version":"1","capabilities":["systemd"],
|
|
"resources":[{"id":"service","type":"service","unit":"lemurs.service","state":"running","boot":"enabled"}]}`,
|
|
}
|
|
for name, raw := range manifests {
|
|
m, err := catalogue.ParseManifest([]byte(raw))
|
|
if err != nil {
|
|
t.Fatalf("%s: %v", name, err)
|
|
}
|
|
if err := open.inventory.RegisterModule(ctx, m, inventory.Source{Repository: "novox/mesh-catalog",
|
|
Path: "modules/" + name, BuiltFrom: "c0ffee"}); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
}
|
|
for _, a := range [][2]string{{"anchor", "objects"}, {"anchor", "resolver"}, {"laptop", "networkmanager"},
|
|
{"laptop", "album"}, {"laptop", "lemurs"}} {
|
|
if _, err := assign(ctx, open, a[0], a[1]); err != nil {
|
|
t.Fatalf("assign %s %s: %v", a[0], a[1], err)
|
|
}
|
|
}
|
|
f, err := gatherFacts(ctx, open, "2.11.17")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
return f, manifests
|
|
}
|
|
|
|
// aTree is a checkout of the catalogue repository holding these manifests.
|
|
func aTree(t *testing.T, manifests map[string]string) string {
|
|
t.Helper()
|
|
dir := t.TempDir()
|
|
for name, raw := range manifests {
|
|
at := filepath.Join(dir, "modules", name)
|
|
if err := os.MkdirAll(at, 0o755); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if err := os.WriteFile(filepath.Join(at, "module.json"), []byte(raw), 0o644); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
}
|
|
return dir
|
|
}
|
|
|
|
func gateJudged(t *testing.T, f snapshot.Facts, tree string, changed ...string) mergeVerdict {
|
|
t.Helper()
|
|
admin := os.Getenv("MESH_TEST_POSTGRES")
|
|
in := mergeCheckInput{facts: f, admin: admin, changed: changed}
|
|
if tree != "" {
|
|
in.repository, in.tree = "novox/mesh-catalog", tree
|
|
}
|
|
v, err := judgeChange(t.Context(), in)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
return v
|
|
}
|
|
|
|
func withEdit(manifests map[string]string, name, raw string) map[string]string {
|
|
out := map[string]string{}
|
|
for k, v := range manifests {
|
|
out[k] = v
|
|
}
|
|
if raw == "" {
|
|
delete(out, name)
|
|
} else {
|
|
out[name] = raw
|
|
}
|
|
return out
|
|
}
|
|
|
|
// The mesh as it is passes: every machine composes in the gate's store as the controller composed it.
|
|
func TestTheMeshAsItIsPassesTheGate(t *testing.T) {
|
|
f, manifests := catalogueMesh(t)
|
|
for _, m := range f.Machines {
|
|
if !m.Declaration.Composes {
|
|
t.Fatalf("the mesh itself does not compose: %+v", m.Declaration)
|
|
}
|
|
}
|
|
v := gateJudged(t, f, aTree(t, manifests))
|
|
if v.Verdict != "pass" {
|
|
t.Fatalf("an unchanged catalogue does not pass:\n%s", v.Report())
|
|
}
|
|
for _, m := range v.Machines {
|
|
if !m.Base.Composes || !m.Change.Composes {
|
|
t.Errorf("%s does not compose in the gate's store as it does on the mesh: %+v / %+v", m.Described, m.Base, m.Change)
|
|
}
|
|
}
|
|
}
|
|
|
|
// **Issue 263**: a change makes the network manager require the object store's provision; on a machine
|
|
// whose name is six characters its identity is 26 against a bound of 20. Refused in the pull request,
|
|
// naming the module, and not on the anchor after it merged.
|
|
func TestIssue263AnIdentityARealMachineNameOverflowsFailsThePullRequest(t *testing.T) {
|
|
f, manifests := catalogueMesh(t)
|
|
tree := aTree(t, withEdit(manifests, "networkmanager",
|
|
`{"module":"networkmanager","version":"1","requires":["wildcard-resolution","s3-bucket"]}`))
|
|
v := gateJudged(t, f, tree)
|
|
if v.Verdict != "fail" {
|
|
t.Fatalf("the overflow passed the gate:\n%s", v.Report())
|
|
}
|
|
report := v.Report()
|
|
if !strings.Contains(report, "networkmanager") || !strings.Contains(report, "s3-bucket") {
|
|
t.Errorf("the refusal does not name the module and the provision:\n%s", report)
|
|
}
|
|
}
|
|
|
|
// **Issue 236**: a login manager's service that omits its state passed the catalogue check and was
|
|
// refused whole by the node-engine on the first machine. A change to a module a machine runs, and a
|
|
// module nobody runs yet, are both refused before merge, naming the machine and the module.
|
|
func TestIssue236AManifestTheNodeEngineRefusesFailsThePullRequest(t *testing.T) {
|
|
f, manifests := catalogueMesh(t)
|
|
broken := `{"module":"lemurs","version":"1","capabilities":["systemd"],
|
|
"resources":[{"id":"service","type":"service","unit":"lemurs.service","boot":"enabled"}]}`
|
|
v := gateJudged(t, f, aTree(t, withEdit(manifests, "lemurs", broken)))
|
|
if v.Verdict != "fail" || !strings.Contains(v.Report(), "lemurs") {
|
|
t.Fatalf("a service the node-engine refuses passed the gate:\n%s", v.Report())
|
|
}
|
|
laptop := snapshot.Pseudonym("machine", "laptop")
|
|
if !strings.Contains(v.Report(), laptop) {
|
|
t.Errorf("the refusal does not name the machine it would be refused on:\n%s", v.Report())
|
|
}
|
|
|
|
// And as a new module, which no machine runs: tried on one that could.
|
|
newcomer := strings.ReplaceAll(broken, `"lemurs"`, `"greeter"`)
|
|
newcomer = strings.ReplaceAll(newcomer, "lemurs.service", "greeter.service")
|
|
v = gateJudged(t, f, aTree(t, withEdit(manifests, "greeter", newcomer)))
|
|
if v.Verdict != "fail" || !strings.Contains(v.Report(), "greeter, assigned to") {
|
|
t.Fatalf("a new module the node-engine would refuse passed the gate:\n%s", v.Report())
|
|
}
|
|
}
|
|
|
|
// **Version skew**: a manifest the controller judging it cannot read — the one the mesh runs, for a
|
|
// catalogue change — fails here, not at registration after the merge.
|
|
func TestAManifestTheRunningControllerCannotReadFailsThePullRequest(t *testing.T) {
|
|
f, manifests := catalogueMesh(t)
|
|
v := gateJudged(t, f, aTree(t, withEdit(manifests, "album",
|
|
`{"module":"album","version":"1","requires":["s3-bucket"],"a-field-of-a-newer-controller":true}`)))
|
|
if v.Verdict != "fail" || !strings.Contains(v.Report(), "refuses it") {
|
|
t.Fatalf("a manifest this controller cannot read passed:\n%s", v.Report())
|
|
}
|
|
}
|
|
|
|
// A module a machine runs, removed from its source, fails until it is unassigned (ADR 0236).
|
|
func TestAModuleAMachineRunsRemovedFromItsSourceFails(t *testing.T) {
|
|
f, manifests := catalogueMesh(t)
|
|
v := gateJudged(t, f, aTree(t, withEdit(manifests, "album", "")))
|
|
if v.Verdict != "fail" || !strings.Contains(v.Report(), "album is removed") {
|
|
t.Fatalf("removing a module a machine runs passed:\n%s", v.Report())
|
|
}
|
|
}
|
|
|
|
// **Issue 278**: a file of a module nobody holds read as shared code, and the merge rebuilt the
|
|
// catalogue. The gate says how wide a merge's rebuild is, and warns when shared code makes it wide.
|
|
func TestIssue278AWideRebuildIsSaidBeforeTheMerge(t *testing.T) {
|
|
f, manifests := catalogueMesh(t)
|
|
was := wideRebuild
|
|
wideRebuild = 2
|
|
t.Cleanup(func() { wideRebuild = was })
|
|
v := gateJudged(t, f, aTree(t, manifests), "modules/showcase/index.ts")
|
|
if v.Width == nil || len(v.Width.Modules) < 5 || len(v.Width.Shared) != 1 {
|
|
t.Fatalf("the width reads %+v", v.Width)
|
|
}
|
|
if v.Verdict != "warning" || !strings.Contains(v.Report(), "shared") {
|
|
t.Fatalf("a rebuild of everything for one shared file is not said:\n%s", v.Report())
|
|
}
|
|
// The same file, with the reference module's definition in the tree: its directory is a module, held
|
|
// or not, and the file is its business alone (the fix of 278, read from the tree as the announcer does).
|
|
withShowcase := withEdit(manifests, "showcase", `{"module":"showcase","version":"1"}`)
|
|
v = gateJudged(t, f, aTree(t, withShowcase), "modules/showcase/index.ts")
|
|
if v.Width == nil || len(v.Width.Modules) != 0 || len(v.Width.Shared) != 0 {
|
|
t.Fatalf("a file of a module nobody holds still reads as shared: %+v", v.Width)
|
|
}
|
|
v = gateJudged(t, f, aTree(t, manifests), "modules/album/module.json")
|
|
if v.Width == nil || strings.Join(v.Width.Modules, ",") != "album" || v.Verdict != "pass" {
|
|
t.Fatalf("a change to one module's directory reads %+v, %s", v.Width, v.Verdict)
|
|
}
|
|
}
|