ContributionsFrom settled to whichever of a module's several contributions to one requirement sorted first, arbitrarily — the grant minted for it then carried that contribution's label and port under a credential the OTHER contribution's consumer never sees, and collided with that same contribution's own entry from contributions() besides. Confirmed live: minio's two route contributions (files-api, files) produced three entries in route-adapter's received file — files-api twice, once credentialed and once not, files not credentialed at all. Every single-contribution module (gitea, keycloak, umami) already mints an unused credential for `route` too — route never needs one, by its own documentation — but with exactly one contribution to match there was nothing to collide with, so it never surfaced. Where a module contributes more than once, there is no single value to settle on. The module still asks, still gets its one credential — a pair credential is not a place for a label or a port anyway — and each named contribution reaches the provider on its own, unchanged. No cleanup needed for the secret already minted live for minio+route: the sealed blob is a random pair credential unrelated to Values, which is recomputed fresh on every plan/push regardless.
168 lines
5.9 KiB
Go
168 lines
5.9 KiB
Go
package catalogue
|
|
|
|
import (
|
|
"encoding/json"
|
|
"testing"
|
|
)
|
|
|
|
// A module may answer one requirement more than once, the sibling of ADR 0094 for `contributes`
|
|
// rather than `secrets`: an object store's data API and its console are two different public
|
|
// names, not one. `contributes` maps a requirement to several sets of values under local names,
|
|
// each reaching the provider as its own entry — the same "several from one" shape ADR 0094 gave
|
|
// `secrets`, applied to the other half of an edge.
|
|
|
|
const twoRoutes = `{"module":"minio","version":"1","requires":["route"],
|
|
"contributes":{"route":{"api":{"label":"files-api","port":9000},"console":{"label":"files","port":9001}}}}`
|
|
|
|
func TestContributesReadsBothShapesAndWritesThemBack(t *testing.T) {
|
|
m, err := ParseManifest([]byte(twoRoutes))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
locals := m.ContributesMany["route"]
|
|
if len(locals) != 2 || locals["api"]["label"] != "files-api" || locals["console"]["port"] != float64(9001) {
|
|
t.Fatalf("two contributions under local names: %+v", locals)
|
|
}
|
|
plain, err := ParseManifest([]byte(`{"module":"board","version":"1","requires":["route"],
|
|
"contributes":{"route":{"label":"board","port":8080}}}`))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if got := plain.Contributes["route"]; got["label"] != "board" || len(plain.ContributesMany) != 0 {
|
|
t.Fatalf("the plain shape is one contribution with no local names: %+v / %+v", got, plain.ContributesMany)
|
|
}
|
|
// Written back in the shape it was read, so a built manifest keeps its local names.
|
|
raw, err := json.Marshal(m)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
again, err := ParseManifest(raw)
|
|
if err != nil {
|
|
t.Fatalf("what was written does not read: %v\n%s", err, raw)
|
|
}
|
|
if len(again.ContributesMany["route"]) != 2 {
|
|
t.Fatalf("the local names did not survive a round trip:\n%s", raw)
|
|
}
|
|
}
|
|
|
|
func TestAContributionLocalNameMustBeUsable(t *testing.T) {
|
|
for _, bad := range []string{
|
|
// Not a usable name.
|
|
`{"module":"minio","version":"1","requires":["route"],
|
|
"contributes":{"route":{"Not OK":{"label":"files","port":9000}}}}`,
|
|
// A local contribution with nothing in it.
|
|
`{"module":"minio","version":"1","requires":["route"],
|
|
"contributes":{"route":{"api":{}}}}`,
|
|
} {
|
|
if _, err := ParseManifest([]byte(bad)); err == nil {
|
|
t.Errorf("accepted:\n%s", bad)
|
|
}
|
|
}
|
|
}
|
|
|
|
func minimalRouteProxy() Manifest {
|
|
return Manifest{Module: "route-proxy", Version: "1",
|
|
Provides: FromAnywhere("route"),
|
|
Receives: map[string]string{"route": "/var/lib/route-proxy/routes/mesh.json"},
|
|
}
|
|
}
|
|
|
|
func TestAModuleWithTwoRoutesGivesTheProviderTwoContributions(t *testing.T) {
|
|
minio, err := ParseManifest([]byte(twoRoutes))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
got, err := Resolve(shelf(minimalRouteProxy(), minio), []string{"route-proxy", "minio"}, workstation(), World{})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
out, err := got.Declaration(Rendering{})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
var given []Contribution
|
|
for _, r := range out {
|
|
if r["path"] != "/var/lib/route-proxy/routes/mesh.json" {
|
|
continue
|
|
}
|
|
var parsed struct {
|
|
Given []Contribution `json:"given"`
|
|
}
|
|
if err := json.Unmarshal([]byte(r["content"].(string)), &parsed); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
given = parsed.Given
|
|
}
|
|
if len(given) != 2 {
|
|
t.Fatalf("two named routes from one module are two contributions: %+v", given)
|
|
}
|
|
byPort := map[float64]string{}
|
|
for _, g := range given {
|
|
if g.From != "minio" {
|
|
t.Fatalf("both contributions are minio's: %+v", g)
|
|
}
|
|
port, _ := g.Values["port"].(float64)
|
|
label, _ := g.Values["label"].(string)
|
|
byPort[port] = label
|
|
}
|
|
if byPort[9000] != "files-api" || byPort[9001] != "files" {
|
|
t.Fatalf("the two routes did not both survive: %+v", given)
|
|
}
|
|
}
|
|
|
|
// A module with the ordinary, single-contribution shape resolves exactly as it did before —
|
|
// ContributesMany being empty must change nothing about it.
|
|
func TestASingleRouteStillResolvesTheOrdinaryWay(t *testing.T) {
|
|
got, err := Resolve(shelf(proxy(), published("board", "board", 8080)), []string{"board"}, workstation(), World{})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
given := received(t, mustDeclare(t, got))
|
|
if len(given) != 1 || given[0].From != "board" {
|
|
t.Fatalf("the plain shape regressed: %+v", given)
|
|
}
|
|
}
|
|
|
|
// ContributionsFrom is what mints the ONE pair credential a requiring module is granted
|
|
// (cmd/mesh-controller/plan.go's grantsFor) — a separate path from Declaration()'s raw file, and
|
|
// the one the two-routes test above never exercised. Where a module contributes several times,
|
|
// there is no single "the" value: settling to whichever sorts first would both misrepresent the
|
|
// grant and collide with that same contribution's own entry from contributions(), which is
|
|
// exactly the duplicate a live plan against minio surfaced (files-api appearing once with a
|
|
// credential, once without, while files got neither).
|
|
func TestContributionsFromHasNoSingleValueWhenAModuleContributesSeveralTimes(t *testing.T) {
|
|
minio, err := ParseManifest([]byte(twoRoutes))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
got, err := Resolve(shelf(minimalRouteProxy(), minio), []string{"route-proxy", "minio"}, workstation(), World{})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
values, asks, err := got.ContributionsFrom("route", "minio", nil)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if !asks {
|
|
t.Fatal("minio still requires route, so it still asks")
|
|
}
|
|
if len(values) != 0 {
|
|
t.Fatalf("no single value represents two contributions, got %+v", values)
|
|
}
|
|
}
|
|
|
|
// The ordinary, single-contribution case is unchanged: exactly one match still settles to it.
|
|
func TestContributionsFromReturnsTheOneValueForAnOrdinaryContribution(t *testing.T) {
|
|
got, err := Resolve(shelf(proxy(), published("board", "board", 8080)), []string{"board"}, workstation(), World{})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
values, asks, err := got.ContributionsFrom("reverse-proxy", "board", nil)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if !asks || values["host"] != "board" {
|
|
t.Fatalf("the ordinary single contribution should still settle to its own value: %+v", values)
|
|
}
|
|
}
|