Files
mesh-host/internal/bootstrap/apply_test.go
T
jschoubben b82ab95f74 mesh-bootstrap: the first-node procedure, as a program rather than a test
The only complete written-down copy of how a mesh is stood up was an integration
test in the lab. That is why every bootstrap gap kept being found late: an install
procedure that lives as a test fixture is exercised by whoever writes tests, never
by whoever installs. This is that procedure.

A separate binary, not a mesh-host subcommand. mesh-host says of itself that it
connects to nothing and listens on nothing and that what it applies comes from a
file, and that sentence is what makes an always-running root daemon auditable. An
installer loads images and interrogates a control plane. Same tier, different
program.

The control plane's image is carried, not built and not fetched. The forge that
holds its source runs on the mesh, so a bootstrap that had to fetch it would need
a mesh in order to raise one. Embedding breaks that cycle the way the carried
bundle breaks "copy it onto a machine and run it". The image id is read out of the
saved tar before the runtime is asked anything, which is what makes the load
idempotent: the installer can ask whether the machine already holds exactly this.

Five steps, each idempotent and each saying whether it found or changed something,
because this is run over and over by somebody getting a machine working. It stops
at a running substrate with a control plane that replies — enrolment, the module
catalogue and assignment are the next stage and are deliberately absent.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
2026-09-10 23:17:30 +02:00

92 lines
3.3 KiB
Go

package bootstrap
import (
"context"
"errors"
"strings"
"testing"
)
// `mesh-host` is built for one operating system and pins it at link time. An installer run by hand
// has no link time, so it asks — and it does not guess: each system already knows how to prove it
// is the one it claims to be, by asking its package database about a package that is certainly
// there. Getting this wrong installs with the wrong package manager and the wrong unit names.
func TestTheMachineIsAskedWhichSystemItIs(t *testing.T) {
// Only pacman answers, so this is the arch host and nothing had to be told so.
onlyPacman := func(_ context.Context, name string, _ ...string) (string, error) {
if name == "pacman" {
return "pacman 7.0.0-1\n", nil
}
return "", errors.New("command not found")
}
chosen, err := WorkOutSystem(context.Background(), onlyPacman, "")
if err != nil {
t.Fatal(err)
}
if chosen.Name() != "arch" {
t.Errorf("this machine was worked out to be %q", chosen.Name())
}
}
// A machine that is none of them is refused with what each of them said. "Unsupported system" is
// a sentence nobody can act on; "pacman does not answer here" is.
func TestAMachineThatIsNoneOfThemIsRefusedWithWhatEachSaid(t *testing.T) {
nothing := func(context.Context, string, ...string) (string, error) {
return "", errors.New("command not found")
}
_, err := WorkOutSystem(context.Background(), nothing, "")
if err == nil {
t.Fatal("a machine that answers as no known system was accepted")
}
for _, wanted := range []string{"arch:", "alpine:", "--system"} {
if !strings.Contains(err.Error(), wanted) {
t.Errorf("the refusal does not mention %q:\n%v", wanted, err)
}
}
}
// And a machine that was TOLD what it is still has to prove it. Installing the arch half of the
// host on Alpine must say so once, at the start, rather than failing later inside pacman.
func TestASystemThatWasNamedIsStillProved(t *testing.T) {
onlyApk := func(_ context.Context, name string, _ ...string) (string, error) {
if name == "apk" {
return "apk-tools-2.14.0\n", nil
}
return "", errors.New("command not found")
}
if _, err := WorkOutSystem(context.Background(), onlyApk, "arch"); err == nil {
t.Fatal("--system arch was believed on a machine where pacman does not answer")
}
if _, err := WorkOutSystem(context.Background(), onlyApk, "alpine"); err != nil {
t.Errorf("--system alpine was refused on a machine where apk answers: %v", err)
}
}
func TestASystemNobodyHasBuiltIsRefusedByName(t *testing.T) {
anything := func(context.Context, string, ...string) (string, error) { return "", nil }
_, err := WorkOutSystem(context.Background(), anything, "debian")
if err == nil {
t.Fatal("--system debian was accepted, and no debian host is built")
}
if !strings.Contains(err.Error(), "arch") {
t.Errorf("the refusal does not say which systems exist: %v", err)
}
}
// A substrate is applied before any mesh exists, so it can carry no secret the mesh sealed — there
// is no key to open one with. Refused with a sentence rather than a nil dereference.
func TestASealedFileInASubstrateIsRefusedWithAReason(t *testing.T) {
_, err := refuseSealed("anything")
if err == nil {
t.Fatal("a sealed file in a substrate bundle was accepted")
}
if !strings.Contains(err.Error(), "has not enrolled") {
t.Errorf("the refusal does not say why there is no key: %v", err)
}
}