Disconnection is an ordinary situation and not a failure, and until now the host treated it as the end: the link dropped and the process returned. A laptop shut for a week would have come back needing somebody to start it again. Now it reconnects, with a backoff that starts at two seconds and slows to two minutes. The two common reasons differ in how long they last -- a broker restarting is back in seconds, a machine that has moved to a network with no route may be hours -- so it starts fast and slows down, and resets once a connection has actually held for thirty seconds. Without that reset, a node that reconnects and immediately drops climbs to the maximum and stays there long after the cause is gone. A wrong certificate is said in full every time rather than folded into a retry count. That does not mean the network is down; it means what answered is not the mesh this node joined, and no waiting fixes it. And it says when it gets back in. It logged every failure and nothing on success, so a log full of "trying again" followed by silence read as still broken when it meant the opposite. The other half: a node now keeps what it was told, not only what it applied. The record of what was applied holds an id, a type and a target -- what removal needs, not what creation needs -- so it could not be re-applied. The declaration is kept whole, signed, and verified again every time it is read back, so the file on disk is trusted for the same reason the message was rather than for being local. A tampered one is refused, and so is one signed by another mesh. With both, the host reconciles against what it was last told every five minutes, connected or not. That is not polling for changes -- changes are pushed -- it is the answer to a machine drifting: a file edited by hand, a container somebody stopped, a service that died. Verified in the lab. The broker was stopped: the node retried at 2s, 4s, 8s, saying why each time, and kept its overlay up throughout. The broker came back and the node rejoined without being touched. A declaration published while a node was away was waiting on the broker and applied the moment it connected, which is the buffer ADR 0006 describes doing its job.
137 lines
4.2 KiB
Go
137 lines
4.2 KiB
Go
package link
|
|
|
|
import (
|
|
"context"
|
|
"crypto/ed25519"
|
|
"encoding/json"
|
|
"testing"
|
|
)
|
|
|
|
// verified runs what Run does to a delivery body, without a broker: unmarshal, check the
|
|
// signature, and only then apply. Isolating it keeps this test about the check rather than about
|
|
// AMQP, which is tested against a real broker in the lab.
|
|
func verified(t *testing.T, signer ed25519.PublicKey, body []byte) (Report, bool) {
|
|
t.Helper()
|
|
applied := false
|
|
report := handleBody(context.Background(), Membership{Node: "anchor", Signer: signer}, body,
|
|
func(context.Context, []byte, []byte) Report {
|
|
applied = true
|
|
return Report{Applied: []string{"something"}}
|
|
})
|
|
return report, applied
|
|
}
|
|
|
|
func signedBody(t *testing.T, private ed25519.PrivateKey, declaration string) []byte {
|
|
t.Helper()
|
|
raw, err := json.Marshal(Signed{
|
|
Declaration: []byte(declaration),
|
|
Signature: ed25519.Sign(private, []byte(declaration)),
|
|
})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
return raw
|
|
}
|
|
|
|
func TestTheMeshsOwnDeclarationIsApplied(t *testing.T) {
|
|
public, private, err := ed25519.GenerateKey(nil)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
report, applied := verified(t, public, signedBody(t, private, `{"declaration":1}`))
|
|
if !applied {
|
|
t.Fatalf("a declaration the mesh signed was not applied: %s", report.Refused)
|
|
}
|
|
}
|
|
|
|
func TestAForgedDeclarationIsNeverApplied(t *testing.T) {
|
|
// The check that stands between "the mesh changes this machine" and "anybody does". The host
|
|
// applies whatever the link delivers, so a forged declaration is the whole machine.
|
|
public, _, err := ed25519.GenerateKey(nil)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
_, other, err := ed25519.GenerateKey(nil)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
|
|
report, applied := verified(t, public, signedBody(t, other, `{"declaration":1}`))
|
|
if applied {
|
|
t.Fatal("a declaration signed by another key was applied")
|
|
}
|
|
if report.Refused != ErrForged.Error() {
|
|
t.Errorf("refused, but not as a forgery: %q", report.Refused)
|
|
}
|
|
}
|
|
|
|
func TestATamperedDeclarationIsNeverApplied(t *testing.T) {
|
|
// A broker that changed the declaration in flight, keeping the signature. This is what makes
|
|
// pinning the transport insufficient on its own.
|
|
public, private, err := ed25519.GenerateKey(nil)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
raw, err := json.Marshal(Signed{
|
|
Declaration: []byte(`{"declaration":1,"resources":["something else entirely"]}`),
|
|
Signature: ed25519.Sign(private, []byte(`{"declaration":1}`)),
|
|
})
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
|
|
report, applied := verified(t, public, raw)
|
|
if applied {
|
|
t.Fatal("a declaration altered after signing was applied")
|
|
}
|
|
if report.Refused != ErrForged.Error() {
|
|
t.Errorf("refused, but not as a forgery: %q", report.Refused)
|
|
}
|
|
}
|
|
|
|
func TestAMalformedMessageIsToldApartFromAForgery(t *testing.T) {
|
|
// novox/hq ADR 0004 requires these to be distinguishable: one means somebody is trying, the
|
|
// other means something is broken, and they need different responses from a person.
|
|
public, _, err := ed25519.GenerateKey(nil)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
report, applied := verified(t, public, []byte("this is not a message"))
|
|
if applied {
|
|
t.Fatal("something unparseable was applied")
|
|
}
|
|
if report.Refused == ErrForged.Error() {
|
|
t.Error("a malformed message was reported as a forgery; those must be distinguishable")
|
|
}
|
|
}
|
|
|
|
func TestTheWireFormatIsExactlyTheseFieldNames(t *testing.T) {
|
|
// The contract with the control plane, which defines these separately. A matching test lives
|
|
// there; rename a field on either side and both fail.
|
|
for _, c := range []struct {
|
|
value any
|
|
expect []string
|
|
}{
|
|
{Signed{Declaration: []byte("{}"), Signature: []byte("x")}, []string{"declaration", "signature"}},
|
|
{Report{Node: "n", Applied: []string{"a"}, Failed: map[string]string{"k": "v"}, Refused: "r"},
|
|
[]string{"node", "applied", "failed", "refused"}},
|
|
} {
|
|
raw, err := json.Marshal(c.value)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
var fields map[string]any
|
|
if err := json.Unmarshal(raw, &fields); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
for _, want := range c.expect {
|
|
if _, ok := fields[want]; !ok {
|
|
t.Errorf("%T has no %q field; the control plane uses that name", c.value, want)
|
|
}
|
|
}
|
|
if len(fields) != len(c.expect) {
|
|
t.Errorf("%T has %d fields, expected %d: %v", c.value, len(fields), len(c.expect), fields)
|
|
}
|
|
}
|
|
}
|