A build that reported applied was sent everywhere; one that then did nothing, served no tools or broke its machine's word reached every machine. Now the first machine is judged by the component's health (the core's definitions, as doctor probes H-*, or a module's own) three times over two minutes within ten; a failing gate puts the previous build back there once, marks the build, and says it as a condition and an event. Upgrades roll out by default; the bus is a planned step; a module deleted at its source is not built (the public-acme plan failure).
55 lines
2.5 KiB
Go
55 lines
2.5 KiB
Go
package broker_test
|
|
|
|
import (
|
|
"slices"
|
|
"testing"
|
|
|
|
"github.com/novox/mesh-controller/internal/broker"
|
|
"github.com/novox/mesh-controller/internal/catalogue"
|
|
"github.com/novox/mesh-controller/internal/conditions"
|
|
"github.com/novox/mesh-controller/internal/link"
|
|
)
|
|
|
|
// The facts the control plane states are named twice — in the grant that permits them and in the code
|
|
// that states them — because `link` imports `broker` and the dependency cannot go the other way. So a
|
|
// test keeps them agreeing: a subject the grant omits is refused at the moment the mesh has something
|
|
// to say, and one the grant adds that nothing states is authority nobody uses.
|
|
//
|
|
// An external test package, because it may import both while neither imports the other.
|
|
func TestTheFactsTheGrantPermitsAreTheFactsTheMeshStates(t *testing.T) {
|
|
if broker.ControllerSeat != link.MeshControllerSeat {
|
|
t.Fatalf("the grant is written for the %q seat and the mesh states its facts under %q",
|
|
broker.ControllerSeat, link.MeshControllerSeat)
|
|
}
|
|
// And what is wrong, as it changes, and the self-check's heartbeat (novox/hq to-be 45 §2, §4).
|
|
states := append([]string{link.KeyApplied, link.KeyRefused, link.KeyBuiltBefore}, conditions.Events...)
|
|
states = append(states, conditions.HeartbeatEvent)
|
|
// And a value given by hand, replaced after its module's first good start (novox/hq ADR 0228).
|
|
states = append(states, link.KeySecretReplaced)
|
|
// And every act a healer takes (novox/hq to-be 45 §7).
|
|
states = append(states, link.KeyHealerActed)
|
|
// And a build put back after its gate failed (novox/hq ADR 0235).
|
|
states = append(states, link.KeyRolledBack)
|
|
for _, event := range states {
|
|
if !slices.Contains(broker.ControllerStates, event) {
|
|
t.Errorf("the mesh states %q and its account may not publish it", event)
|
|
}
|
|
}
|
|
if len(broker.ControllerStates) != len(states) {
|
|
t.Errorf("the grant permits %v, which is more than the mesh states", broker.ControllerStates)
|
|
}
|
|
// **And the seat says it.** A seat carries the protocol of its role (novox/hq ADR 0129), so the
|
|
// facts the control plane states are the seat's `emits` — which is what lets anything else declare
|
|
// that it consumes them, and what the subject-agreement check reads to know they have an owner.
|
|
var declared []string
|
|
for _, seat := range catalogue.SeatsWithAProtocol() {
|
|
if seat.Name == broker.ControllerSeat {
|
|
declared = seat.Emits
|
|
}
|
|
}
|
|
if !slices.Equal(declared, broker.ControllerStates) {
|
|
t.Errorf("the %s seat emits %v and the grant permits %v", broker.ControllerSeat,
|
|
declared, broker.ControllerStates)
|
|
}
|
|
}
|