Keep the originals the carried bundle writes over beside the node's state (hq ADR 0100)

This commit is contained in:
2026-09-22 19:53:50 +02:00
parent eb2f4fcf53
commit 5f126021b7
2 changed files with 46 additions and 2 deletions
+38
View File
@@ -3,8 +3,13 @@ package bootstrap
import (
"context"
"errors"
"os"
"path/filepath"
"strings"
"testing"
"github.com/novox/mesh-host/internal/declaration"
"github.com/novox/mesh-host/internal/system"
)
// `mesh-host` is built for one operating system and pins it at link time. An installer run by hand
@@ -89,3 +94,36 @@ func TestASealedFileInAFoundationIsRefusedWithAReason(t *testing.T) {
t.Errorf("the refusal does not say why there is no key: %v", err)
}
}
// Defends novox/hq ADR 0100: the carried bundle keeps the original of a file it writes over that
// the host has no record of — the distribution's own ruleset, say.
func TestTheBundleKeepsTheOriginalOfWhatItWritesOver(t *testing.T) {
dir := t.TempDir()
conf := filepath.Join(dir, "nftables.conf")
if err := os.WriteFile(conf, []byte("# the distribution's own\n"), 0o644); err != nil {
t.Fatal(err)
}
d, err := declaration.ParseFileTrusted([]byte(`{"declaration":1,"resources":[
{"id":"base-filter","type":"file","path":"` + conf + `","content":"table inet mesh {}\n"}]}`))
if err != nil {
t.Fatal(err)
}
sys, err := system.For("arch")
if err != nil {
t.Fatal(err)
}
o := Options{State: filepath.Join(dir, "state.json")}
report, err := ApplyBundle(context.Background(), o, sys, d, nil, quietly)
if err != nil {
t.Fatal(err)
}
detail := report.Outcomes[0].Detail
at := strings.Index(detail, "kept at ")
if at < 0 {
t.Fatalf("the bundle wrote over a file it had no record of and kept nothing: %q", detail)
}
if got, err := os.ReadFile(detail[at+len("kept at "):]); err != nil ||
string(got) != "# the distribution's own\n" {
t.Errorf("the kept original is %q (%v)", got, err)
}
}