Read an adopted or converged node's mode from its state on a re-run of genesis, and refuse a flag that disagrees (hq ADR 0103)
This commit is contained in:
@@ -120,3 +120,46 @@ func TestAFreshlyInstalledMachineAsMeasuredIsNotInUse(t *testing.T) {
|
||||
t.Errorf("a fresh machine read as in use: containers %v, listeners %v", containers, listeners)
|
||||
}
|
||||
}
|
||||
|
||||
// Defends novox/hq ADR 0103: a machine raised adopted stays adopted if genesis is run again. The
|
||||
// installer reads the mode from what the machine records, and refuses a flag that disagrees.
|
||||
func TestARerunWithoutTheFlagOnAnAdoptedMachineIsRefused(t *testing.T) {
|
||||
o := Options{State: filepath.Join(t.TempDir(), "state.json")}
|
||||
adoptedState := store.State{Resources: []store.Applied{
|
||||
{ID: "store", Type: "container", Target: "mesh-store", Origin: store.OriginCarried},
|
||||
{ID: "adoption.guard", Type: "file", Target: "/etc/mesh/guard.nft", Origin: store.OriginCarried},
|
||||
}}
|
||||
if err := store.Save(o.State, adoptedState); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
m := inUseRunner{ss: inUseSockets}
|
||||
err := RefuseAMachineInUse(context.Background(), o, m.run, quietly)
|
||||
if err == nil || !strings.Contains(err.Error(), "pass --adopted") {
|
||||
t.Fatalf("a re-run without --adopted on an adopted machine was not refused: %v", err)
|
||||
}
|
||||
o.Adopted = true
|
||||
if err := RefuseAMachineInUse(context.Background(), o, m.run, quietly); err != nil {
|
||||
t.Errorf("a re-run with --adopted on an adopted machine was refused: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestARerunWithTheFlagOnAConvergedMachineIsRefused(t *testing.T) {
|
||||
o := Options{State: filepath.Join(t.TempDir(), "state.json"), Adopted: true}
|
||||
converged := store.State{Resources: []store.Applied{
|
||||
{ID: "store", Type: "container", Target: "mesh-store", Origin: store.OriginCarried},
|
||||
{ID: "base-filter", Type: "file", Target: "/etc/nftables.conf", Origin: store.OriginCarried},
|
||||
},
|
||||
// Converged by the controller from adopted: the firewall it found is still recorded.
|
||||
Firewall: &store.FoundFirewall{Kind: "ufw", WasActive: true, DisabledByMesh: true}}
|
||||
if err := store.Save(o.State, converged); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
err := RefuseAMachineInUse(context.Background(), o, inUseRunner{ss: inUseSockets}.run, quietly)
|
||||
if err == nil || !strings.Contains(err.Error(), "without --adopted") {
|
||||
t.Fatalf("a re-run with --adopted on a converged machine was not refused: %v", err)
|
||||
}
|
||||
o.Adopted = false
|
||||
if err := RefuseAMachineInUse(context.Background(), o, inUseRunner{ss: inUseSockets}.run, quietly); err != nil {
|
||||
t.Errorf("a converged re-run of a converged machine was refused: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user