Take a key or list member the host may have written itself as the mesh's, so undeclaring gives the file back (hq ADR 0102)

This commit is contained in:
2026-09-22 19:57:15 +02:00
parent 0bd22e50f2
commit 7beb752be0
2 changed files with 59 additions and 9 deletions
+40 -2
View File
@@ -217,9 +217,15 @@ func TestAListIsAddedToNeverReplaced(t *testing.T) {
// takes back only what it added (novox/hq ADR 0102).
path := filepath.Join(t.TempDir(), "daemon.json")
_ = os.WriteFile(path, []byte(`{"insecure-registries":["192.0.2.7:5000","10.42.0.9:5000"]}`), 0o644)
// 10.42.0.9 is declared too, and was already the machine's: it is never the mesh's to remove.
// First the mesh's own member alone, so there is a record of this file.
first := parse(t, intoDecl(t, path, `{"insecure-registries":["10.42.0.1:5000"]}`))
_, state, err := Apply(context.Background(), archHost(t), first, store.State{}, store.OriginDeclared, nil, nil, nil)
if err != nil {
t.Fatal(err)
}
// Now 10.42.0.9 is declared too, and was already the machine's: it is never the mesh's to remove.
d := parse(t, intoDecl(t, path, `{"insecure-registries":["10.42.0.1:5000","10.42.0.9:5000"]}`))
_, state, err := Apply(context.Background(), archHost(t), d, store.State{}, store.OriginDeclared, nil, nil, nil)
_, state, err = Apply(context.Background(), archHost(t), d, state, store.OriginDeclared, nil, nil, nil)
if err != nil {
t.Fatal(err)
}
@@ -302,3 +308,35 @@ func TestAHoldFromAWholeFileDoesNotKeepOutAnIntoWrite(t *testing.T) {
t.Errorf("the mesh's member was not written in: %v", readObject(t, path))
}
}
func TestAWriteWithNoRecordOfItIsTheMeshsOwn(t *testing.T) {
// A host that wrote into the file and died before saving its state comes back with no record
// of it. What is there is then exactly what the mesh declares — and remembered as the
// machine's it would never be given back (novox/hq ADR 0102).
path := filepath.Join(t.TempDir(), "daemon.json")
_ = os.WriteFile(path, []byte(`{"data-root":"/srv/docker","insecure-registries":["192.0.2.7:5000"]}`), 0o644)
d := parse(t, intoDecl(t, path, `{"live-restore":true,"insecure-registries":["10.42.0.1:5000"]}`))
if _, _, err := Apply(context.Background(), archHost(t), d, store.State{}, store.OriginDeclared, nil, nil, nil); err != nil {
t.Fatal(err)
}
// The crash: the state was never saved, so the next apply knows nothing of this file.
_, state, err := Apply(context.Background(), archHost(t), d, store.State{}, store.OriginDeclared, nil, nil, nil)
if err != nil {
t.Fatal(err)
}
rec, _ := state.Find("networking.registry-trust")
if _, asTheMachines := rec.Into.Before["live-restore"]; asTheMachines {
t.Error("the mesh's own key was remembered as the machine's")
}
if _, _, err := Apply(context.Background(), archHost(t), somethingElse(t), state, store.OriginDeclared, nil, nil, nil); err != nil {
t.Fatal(err)
}
o := readObject(t, path)
if _, still := o["live-restore"]; still {
t.Errorf("undeclaring left the mesh's key behind: %v", o)
}
if fmt.Sprint(o["insecure-registries"]) != "[192.0.2.7:5000]" || o["data-root"] != "/srv/docker" {
t.Errorf("the machine did not get its file back: %v", o)
}
}