Name the decisions these tests defend, and check the bundle at all
From auditing the decision records: of 28, only 12 were named by any test, so "which decisions are defended" could not be answered without reading everything. ADR 0017 says a test names the decision it defends — that rule was itself unenforced. Most of the gap was citation, not coverage. Drift detection was tested in several places without naming ADR 0011; the archive refusal without naming 0012; forged declarations without naming 0002. Named now, so the question is answerable by grep. The bundle was the real gap: nothing tested substrate-first-node.lock at all. It is what a machine becomes when there is no mesh to ask — the one declaration applied with nothing to verify it against — and it was edited by hand and read by nothing but a running host. Two tests now assert what it carries: exactly postgres, lavinmq and the control plane. That defends ADR 0028, which removed the object store from the substrate after it had been a member for months on the strength of "it cannot grant itself a bucket" — true, and the answer to only half the test. Nothing counted what the bundle held. Fault-injected, and the first attempt did not bite: the injection landed on a comment line, which stripComments discards. Injecting into the image field fails as it should.
This commit is contained in:
@@ -57,6 +57,10 @@ func TestApplyingTwiceChangesNothingTheSecondTime(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// Defends novox/hq ADR 0011: a managed file is generated onto a node and never edited there.
|
||||
//
|
||||
// Not by overwriting silently — by noticing. An edit that vanishes without a word is how somebody
|
||||
// spends an afternoon re-fixing a bug they already fixed.
|
||||
func TestADriftedMachineIsReturned(t *testing.T) {
|
||||
// The other half of idempotence, and the half that matters: converging is not "do nothing
|
||||
// if the state file says it was done". The machine is read, not the record.
|
||||
|
||||
Reference in New Issue
Block a user