Prove a machine filters what it was told to and nothing else
Written and loaded are different things, and loaded and enforcing are different again. The test opens two ports on a machine, declares one of them, and checks from the other machine that the declared one answers and the undeclared one does not — then removes the module and checks the port closes with nobody editing a rule. The base image gains nftables, read back through `nft --version` like the other three: a machine that cannot load a rule set applies the mesh's filtering, reports success and filters nothing, which is the exact fault the derivation exists to remove. Two earlier tests were asking for things that are not there. The lab's registry drops tags when it stocks, so `registry:2` is not served and the mirror test failed with "not found" — it now uses the pinned digest, which is what a declaration carries anyway.
This commit is contained in:
@@ -71,6 +71,13 @@ export async function buildBaseImage(
|
||||
log(" installing git, so a machine can build modules");
|
||||
await incus(["exec", BUILDER, "--", "pacman", "-S", "--noconfirm", "git"], 600_000);
|
||||
|
||||
// And nftables, because the mesh computes a machine's filtering and delivers it as a file
|
||||
// that a service reflects — and neither the file nor the service can install what loads it.
|
||||
// Installed and NOT enabled: whether a machine filters is the mesh's decision, and a lab that
|
||||
// turned it on itself would be testing its own setup.
|
||||
log(" installing nftables, so a machine can enforce what the mesh computed");
|
||||
await incus(["exec", BUILDER, "--", "pacman", "-S", "--noconfirm", "nftables"], 600_000);
|
||||
|
||||
// Trust the documentation ranges as plain-HTTP registries.
|
||||
//
|
||||
// A scenario's registry is scenery inside the scenario, serving over HTTP, and a runtime
|
||||
@@ -108,6 +115,18 @@ export async function buildBaseImage(
|
||||
}
|
||||
log(` ${git.trim()}`);
|
||||
|
||||
// The same again, for nftables. A machine that cannot load a rule set applies the mesh's
|
||||
// filtering, reports success, and filters nothing — which is precisely the fault the whole
|
||||
// derivation exists to remove, reappearing in the lab.
|
||||
const nft = await incusOk(["exec", BUILDER, "--", "nft", "--version"], 60_000);
|
||||
if (!nft?.trim()) {
|
||||
throw new BaseImageError(
|
||||
`nftables was installed in ${BUILDER} and \`nft\` does not answer. Publishing this would ` +
|
||||
`give every scenario a machine that cannot enforce what the mesh computed for it.`,
|
||||
);
|
||||
}
|
||||
log(` ${nft.trim()}`);
|
||||
|
||||
// Read back from the runtime, not from the package manager. An installed package is not a
|
||||
// capability (novox/hq 04-ISSUES/007), and this is the one place to catch that — after
|
||||
// publishing, every scenario pays for it instead.
|
||||
|
||||
Reference in New Issue
Block a user