Enrolling ace applied adoption.opening-tcp-5671-incoming to it, opening 5671 from anywhere (v4+v6) where nothing listens — the ace session caught it. foundation ports widen the broker's from:mesh port to from-anywhere so a machine that is not yet on the mesh can make its first dial; that belongs on the broker's host alone. foundationPortsFor keeps the port only when a module resolved onto this node listens on it, so novox opens 5671 and a node that merely dials out opens nothing. Two tests, both directions.
34 lines
1.2 KiB
Go
34 lines
1.2 KiB
Go
package main
|
|
|
|
// The broker opening belongs only on the node that listens on it (novox/hq: it leaked onto
|
|
// every enrolled node's declaration, opening a from-anywhere hole for a port nothing there
|
|
// serves). foundationPortsFor is the scope.
|
|
|
|
import (
|
|
"testing"
|
|
|
|
"github.com/novox/mesh-controller/internal/catalogue"
|
|
)
|
|
|
|
func TestTheBrokerHostGetsTheFoundationOpening(t *testing.T) {
|
|
broker := catalogue.Manifest{Module: "lavinmq", Listens: []catalogue.Listening{
|
|
{Port: 5671, Protocol: "tcp", From: "mesh"},
|
|
{Port: 5672, Protocol: "tcp", From: "mesh"},
|
|
}}
|
|
got := foundationPortsFor(5671, []catalogue.Manifest{broker})
|
|
if len(got) != 1 || got[0] != 5671 {
|
|
t.Fatalf("the node that listens on the broker port keeps it; got %v", got)
|
|
}
|
|
}
|
|
|
|
func TestANodeThatOnlyDialsTheBrokerGetsNoOpening(t *testing.T) {
|
|
// ace's set: things that reach the broker as a client, none listening on 5671.
|
|
ace := []catalogue.Manifest{
|
|
{Module: "plex", Listens: []catalogue.Listening{{Port: 32400, Protocol: "tcp", From: "anywhere"}}},
|
|
{Module: "postgres", Listens: []catalogue.Listening{{Port: 5432, Protocol: "tcp", From: "mesh"}}},
|
|
}
|
|
if got := foundationPortsFor(5671, ace); got != nil {
|
|
t.Fatalf("a node that only dials out opens nothing for the broker; got %v", got)
|
|
}
|
|
}
|