Tests that read ../../../mesh-catalog or ../../../mesh-host gave a verdict that depended on what sat beside the checkout: a stale or dirty sibling failed them on a desktop, and a missing one skipped them unseen. They now read the clone the build seat puts in MESH_CHECK_BESIDE, failing when it is absent there, and elsewhere a copy captured at a named commit. The skip had hidden that the builder test read a module retired by ADR 0190. The systemd reading test no longer counts the machine's own environment.d.
75 lines
2.6 KiB
Go
75 lines
2.6 KiB
Go
package catalogue
|
|
|
|
import (
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/novox/mesh-controller/internal/beside"
|
|
)
|
|
|
|
// **A machine trusts the mesh's authority because a module put its root there** (novox/hq ADR
|
|
// 0147, issue 129). The module carries a shell script and a unit, and both are worthless unless
|
|
// the mesh fills in where the authority is — which is the one thing about it the manifest cannot
|
|
// state, because the authority's address is a fact about the mesh and not about the module.
|
|
//
|
|
// So what is checked here is the rendering, not the parsing: the script the machine will run
|
|
// names the authority it was bound to, and the unit runs that script both ways. The verification
|
|
// itself — a plain client trusting an internal name on a machine holding this, and failing on one
|
|
// that does not — is the lab's, and cannot be had here.
|
|
func TestCaTrustRendersTheAuthorityItWasBoundTo(t *testing.T) {
|
|
raw, err := os.ReadFile(filepath.Join(beside.Catalogue(t), "ca-trust", "module.json"))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
m, err := ParseManifest(raw)
|
|
if err != nil {
|
|
t.Fatalf("the trust module does not parse:\n%v", err)
|
|
}
|
|
|
|
r := Resolution{
|
|
Node: "workstation",
|
|
Modules: []Manifest{m},
|
|
Needs: []Needed{{
|
|
Name: "internal-acme-ca", From: "anchor", At: "anchor.internal", For: "ca-trust",
|
|
Serves: map[string]any{
|
|
"port": float64(9000), "path": "/acme/acme/directory", "roots": "/roots.pem",
|
|
},
|
|
}},
|
|
}
|
|
out, err := r.Declaration(Rendering{})
|
|
if err != nil {
|
|
t.Fatalf("the trust module could not be composed for a machine: %v", err)
|
|
}
|
|
|
|
script := fileNamed(out, "ca-trust.anchor")
|
|
if script == nil {
|
|
t.Fatalf("nothing writes the script the unit runs: %v", out)
|
|
}
|
|
body, _ := script["content"].(string)
|
|
if !strings.Contains(body, "https://anchor.internal:9000/roots.pem") {
|
|
t.Errorf("the script does not fetch from the authority it was bound to:\n%s", body)
|
|
}
|
|
if script["mode"] != "0755" {
|
|
t.Errorf("the script is written %v, which systemd cannot execute", script["mode"])
|
|
}
|
|
|
|
unit := fileNamed(out, "ca-trust.unit")
|
|
if unit == nil {
|
|
t.Fatalf("no unit: %v", out)
|
|
}
|
|
text, _ := unit["content"].(string)
|
|
// Both halves. A unit that only installs the anchor leaves a machine trusting an authority
|
|
// nobody assigned it to any more, which is the half issue 129 asked for by name.
|
|
for _, want := range []string{
|
|
"ExecStart=" + script["path"].(string) + " install",
|
|
"ExecStop=" + script["path"].(string) + " remove",
|
|
"RemainAfterExit=yes",
|
|
} {
|
|
if !strings.Contains(text, want) {
|
|
t.Errorf("the unit does not say %q:\n%s", want, text)
|
|
}
|
|
}
|
|
}
|