Refuse an endpoint whose port is not the one the private network's hub binds (hq ADR 0100)

This commit is contained in:
2026-09-22 19:58:37 +02:00
parent 04665d36c8
commit c7ff0b9026
2 changed files with 51 additions and 1 deletions
+22 -1
View File
@@ -1,6 +1,9 @@
package bootstrap
import "testing"
import (
"strings"
"testing"
)
// The endpoint other machines dial defaults to the host they already dial — the broker's — on
// WireGuard's port. One fact, not two that drift.
@@ -23,3 +26,21 @@ func TestOnlyAManifestWithArtifactsBuilds(t *testing.T) {
t.Fatal("a manifest with nothing to build was built anyway")
}
}
// Defends novox/hq ADR 0100: the hub's port is the node's, and the endpoint other machines dial
// must name it — an endpoint on another port is an address nothing answers on.
func TestTheEndpointAgreesWithTheHubsPort(t *testing.T) {
if got, err := endpointAgrees("192.0.2.10:51820", 51820); err != nil || got != "192.0.2.10:51820" {
t.Errorf("an endpoint on the hub's port: %q %v", got, err)
}
if got, err := endpointAgrees("192.0.2.10", 51821); err != nil || got != "192.0.2.10:51821" {
t.Errorf("a host alone did not take the hub's port: %q %v", got, err)
}
_, err := endpointAgrees("192.0.2.10:51820", 51821)
if err == nil || !strings.Contains(err.Error(), "--hub-port") {
t.Errorf("two ports for one hub were accepted: %v", err)
}
if _, err := endpointAgrees("192.0.2.10:not-a-port", 51820); err == nil {
t.Error("an endpoint whose port is not a number was accepted")
}
}