Files
mesh-host/internal/profile/profile_system_test.go
T
jschoubben 73c010e7ef Stage 1 — the host reports what a machine is and can do
Tier 0's first slice, per novox/hq 03-DESIGN/01-to-be/05-the-node-host.md. It
applies nothing, connects to nothing, listens on nothing. 2.9 MB, static, no
dynamic dependencies: copy it onto a machine and run it is the whole install,
which is the property ADR 0041 rests on.

A capability is detected, never assumed. Every detector runs something that only
succeeds if the thing FUNCTIONS — the daemon is asked for its version, the
package database is queried, the firewall is asked to list a ruleset, which
needs the privilege as well as the tool. 04-ISSUES/007 is the fault this
prevents: a client on disk with its daemon down looks exactly like a working
runtime, and a node assigned work on that basis fails when the work arrives.

Every verdict carries the reason and the method. A capability reported absent
with no reason is the same fault in a new place: something nobody can act on.

Two bugs found by running rather than reasoning, both silent:

systemctl is-system-running exits non-zero for every state except `running` —
including `degraded`, which means units failed and the init is emphatically
there. Reading the exit code reported NO service manager on a machine whose init
it was. That is 007 in the mirror, and both directions place work wrongly. A
verdict now reads what a tool says about itself, not only how it exited.

And `mesh-host inventory --json` printed text: the standard library stops
parsing at the first non-flag argument, so the flag sat unread and the command
exited 0 having ignored what was asked. The parser now takes the subcommand off
the front, and a stray or mistyped argument is refused rather than dropped.

Detection deliberately does NOT follow ADR 0008. That rule governs applying
state, where a failed step means the machine is not what was asked for. A failed
probe is a finding — "absent, because the probe failed" — and aborting would
replace one legible absence with total ignorance of the rest.

25 tests: structure and logic with a fake runner, and the same detectors against
this machine, because a test that fakes the system under detection asserts only
that the fake behaves as expected.
2026-08-26 00:25:08 +02:00

91 lines
3.3 KiB
Go

package profile
import (
"context"
"os/exec"
"strings"
"testing"
"time"
)
// Against the real machine. novox/hq ADR 0034: structure and logic are tested first, behaviour
// against a real system alongside, and mocking the boundary is forbidden — a test that fakes
// the system under detection asserts that the fake behaves as expected.
//
// These do not assert WHICH capabilities this machine has; that varies per machine and is the
// point of detecting. They assert that detection tells the truth about whatever is here.
func TestAgainstThisMachine_detectionAgreesWithReality(t *testing.T) {
got := Detect(context.Background(), Default(nil), 10*time.Second)
if got.Architecture == "" || got.Kernel == "" {
t.Fatal("the machine did not report its own architecture or kernel")
}
if len(got.Capabilities) == 0 {
t.Fatal("no capability was reported at all")
}
// The claim is checkable independently: a capability reported present must have a command
// that is actually on this machine. The reverse is deliberately NOT asserted — a command
// being present while the capability is absent is exactly the fault 04-ISSUES/007 records,
// and this suite exists partly to let that state be observed rather than assumed away.
commands := map[string]string{
CapContainerRuntime: "docker",
CapPackageManager: "pacman",
CapServiceManager: "systemctl",
CapFirewall: "nft",
CapOverlay: "wg",
}
for name, command := range commands {
if !got.Has(name) {
continue
}
if _, err := exec.LookPath(command); err != nil {
t.Errorf("%s reported present, but %q is not on this machine: %v", name, command, err)
}
}
for _, v := range got.Capabilities {
t.Logf(" %-20s present=%-5v %s", v.Name, v.Present, v.Detail)
}
}
func TestAgainstThisMachine_privilegeIsReportedHonestly(t *testing.T) {
// The host changes machines, so whether it can is the capability that decides what the
// rest of it may attempt. Reporting it wrongly in either direction is worse than not
// reporting it: claimed-and-absent means work is accepted and fails, and absent-when-held
// means a capable node refuses work.
var verdict Verdict
for _, v := range Detect(context.Background(), Default(nil), 5*time.Second).Capabilities {
if v.Name == CapPrivileged {
verdict = v
}
}
if verdict.Name == "" {
t.Fatal("privilege was not reported at all")
}
// Checked against the process's own view rather than against the detector's.
root := isRoot()
if verdict.Present != root {
t.Errorf("privilege reported %v; this process is root=%v", verdict.Present, root)
}
if !strings.Contains(verdict.Detail, "uid") {
t.Errorf("privilege detail does not say what it observed: %q", verdict.Detail)
}
}
func TestAgainstThisMachine_detectionIsBounded(t *testing.T) {
// Every probe runs a command on a real machine. If any of them can block, the host has a
// startup that sometimes never finishes — the least debuggable failure there is.
start := time.Now()
Detect(context.Background(), Default(nil), 2*time.Second)
elapsed := time.Since(start)
budget := 2 * time.Second * time.Duration(len(Default(nil)))
if elapsed > budget {
t.Fatalf("detection took %s, past its own %s budget", elapsed, budget)
}
t.Logf("detected %d capabilities in %s", len(Default(nil)), elapsed)
}