ADR 0061. Recovery was the most systemd-specific part of the host, and it is the part that must work on a machine where nothing else does -- which made unit-file syntax a poor place for it, because syntax cannot be tested and the one time it runs is the one time nobody can afford it wrong. So StartLimitBurst and OnFailure move into a launcher script that init starts instead of the host. The unit drops to start-at-boot and restart-on-exit, which OpenRC, runit, s6 and an Android init.rc can all express. Everything 0059 decided is kept: two watchdogs, roll back once, recovery is local, the rollback shares no code with the host. The counter is the whole mechanism, so it is what the tests are mostly about. Three real problems came out of writing them: A counter file holding "1 2" became "12" -- `tr -d [:space:]` concatenates rather than rejecting -- which is past the limit, so a HEALTHY node rolled itself back. Now it reads the first field and insists on a plain integer. The corrupt-counter test used "not-a-number", which shell arithmetic happens to evaluate to 0, so it passed with the guard removed and proved nothing. Replaced with values that discriminate: "5x" errors under set -e and kills the launcher, and "0x10" is read as HEX 16 -- past the limit, so again a healthy node rolls back. And the test harness itself was wrong. With `set -e` and a bare launcher call, removing a guard killed the script at the first corrupt case and silently skipped everything after -- reporting a full pass over tests that never ran. Every launcher call now records its failure instead of aborting. Same class as the placebo assertion found last time, and the reason to keep injecting faults rather than trusting green. Both scripts run in `make check`. 27 launcher tests, 9 rollback tests, all confirmed to bite.
46 lines
1.6 KiB
Makefile
46 lines
1.6 KiB
Makefile
# The gate. Green is the definition of done (novox/hq how-we-build §5).
|
|
VERSION ?= $(shell git describe --tags --always --dirty 2>/dev/null || echo development)
|
|
LDFLAGS := -s -w -X main.version=$(VERSION)
|
|
|
|
# The bundle a host carries is built INTO it (novox/hq ADR 0038, ADR 0041): a host that needed
|
|
# a second file to arrive with it is not "copy it and run it".
|
|
BUNDLE ?=
|
|
|
|
.PHONY: check test vet fmt build clean host
|
|
|
|
check: fmt vet test packaging-test build
|
|
|
|
packaging-test:
|
|
@./packaging/rollback_test.sh
|
|
@./packaging/launch_test.sh
|
|
|
|
fmt:
|
|
@test -z "$$(gofmt -l . )" || { echo "unformatted:"; gofmt -l . ; exit 1; }
|
|
|
|
vet:
|
|
go vet ./...
|
|
|
|
# Structure and logic, and the same checks against this machine. The boundary is never mocked.
|
|
test:
|
|
go test ./... -count=1
|
|
|
|
# A default build carries no bundle and refuses to reconcile, which is the honest state for a
|
|
# host nobody has told what a substrate is.
|
|
build:
|
|
CGO_ENABLED=0 go build -ldflags="$(LDFLAGS)" -o mesh-host ./cmd/mesh-host
|
|
|
|
# A host for a real machine, carrying a real bundle: make host BUNDLE=path/to/substrate.lock
|
|
host:
|
|
@test -n "$(BUNDLE)" || { echo "BUNDLE= is required; a host with no bundle cannot raise a first node"; exit 1; }
|
|
@test -f "$(BUNDLE)" || { echo "no such bundle: $(BUNDLE)"; exit 1; }
|
|
@cp internal/bundle/substrate.lock internal/bundle/substrate.lock.default
|
|
@cp "$(BUNDLE)" internal/bundle/substrate.lock
|
|
@CGO_ENABLED=0 go build -ldflags="$(LDFLAGS)" -o mesh-host ./cmd/mesh-host; \
|
|
status=$$?; \
|
|
mv internal/bundle/substrate.lock.default internal/bundle/substrate.lock; \
|
|
exit $$status
|
|
@echo "built carrying $(BUNDLE)"
|
|
|
|
clean:
|
|
rm -f mesh-host
|