package declaration import ( "strings" "testing" ) // Defends novox/hq issue 128: a file written into a block carries only its lines, in content, // never a line the host keeps as its own marker, and says where a new region goes only as a block. func TestAFileWrittenIntoABlockIsRefusedUnlessItIsOnlyItsLines(t *testing.T) { for name, c := range map[string]struct{ resource, refusal string }{ "a begin marker in content": {`{"id":"f","type":"file","path":"/etc/hosts","into":"block","content":"a\n# BEGIN mesh f\nb\n"}`, "# BEGIN mesh f"}, "an end marker in content": {`{"id":"f","type":"file","path":"/etc/hosts","into":"block","content":"a\n# END mesh other\n"}`, "# END mesh other"}, "a marker with a CR": {`{"id":"f","type":"file","path":"/etc/hosts","into":"block","content":"# BEGIN mesh x\r\n"}`, "marker"}, "sealed": {`{"id":"f","type":"file","path":"/etc/hosts","into":"block","sealed":"abc"}`, "not sealed"}, "bytes": {`{"id":"f","type":"file","path":"/etc/hosts","into":"block","bytes":"YQ=="}`, "not sealed, bytes"}, "secrets": {`{"id":"f","type":"file","path":"/etc/hosts","into":"block","content":"${secret:s}","secrets":{"s":"abc"}}`, "secrets"}, "create-once": {`{"id":"f","type":"file","path":"/etc/hosts","into":"block","content":"a","create-once":true}`, "create-once"}, "at on a whole file": {`{"id":"f","type":"file","path":"/etc/hosts","content":"a","at":"start"}`, `at "start"`}, "at on a JSON file": {`{"id":"f","type":"file","path":"/etc/x.json","into":"json","content":"{}","at":"end"}`, `at "end"`}, "at somewhere else": {`{"id":"f","type":"file","path":"/etc/hosts","into":"block","content":"a","at":"middle"}`, `"start" or "end"`}, "an unknown format": {`{"id":"f","type":"file","path":"/etc/hosts","into":"lines","content":"a"}`, `"json" or "block"`}, } { _, err := Parse([]byte(`{"declaration":1,"resources":[` + c.resource + `]}`)) if err == nil || !strings.Contains(err.Error(), c.refusal) { t.Errorf("%s: want a refusal naming %q, got %v", name, c.refusal, err) } } } func TestAFileWrittenIntoABlockIsRead(t *testing.T) { d, err := Parse([]byte(`{"declaration":1,"resources":[ {"id":"mesh-wireguard.fact-node-names","type":"file","path":"/etc/hosts","into":"block","content":"10.42.0.1 ace\n# BEGIN devtool x\n"}, {"id":"dhcpcd.options","type":"file","path":"/etc/dhcpcd.conf","into":"block","content":"nohook resolv.conf\n","at":"start"}, {"id":"empty","type":"file","path":"/etc/x","into":"block","content":"","at":"end"} ]}`)) if err != nil { t.Fatal(err) } if f := d.Resources[0].(*File); f.Into != IntoBlock || f.At != "" { t.Errorf("read as into %q at %q", f.Into, f.At) } if f := d.Resources[1].(*File); f.At != AtStart { t.Errorf("at was read as %q", f.At) } if begin, end := BlockMarkers("mesh-wireguard.fact-node-names"); begin != "# BEGIN mesh mesh-wireguard.fact-node-names" || end != "# END mesh mesh-wireguard.fact-node-names" { t.Errorf("the markers are %q and %q", begin, end) } }