From 35000a236c34e71fb573e8a0cf8bd25e75272aac Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 31 Aug 2026 00:55:33 +0200 Subject: [PATCH] Assert the builder can reach the broker, not merely that it is running MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit A builder that cannot connect sits there, and every outward sign — container up, credential on disk — says it is working. The failure surfaced five minutes later as nothing consuming the build queue, which names no cause at all. --- test/integration/mesh.test.ts | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/test/integration/mesh.test.ts b/test/integration/mesh.test.ts index 3522d55..9819fe7 100644 --- a/test/integration/mesh.test.ts +++ b/test/integration/mesh.test.ts @@ -676,13 +676,25 @@ test("the builder is a module the mesh assigns, with a credential the mesh deliv `the builder was assigned and is not running:\n${running}\n` + `${(await on("anchor", `tail -30 /var/log/mesh-host.log`)).out}`); + // Running is not connected. A builder that cannot reach the broker sits there, and every + // outward sign — the container is up, the credential is on disk — says it is working. + await new Promise((r) => setTimeout(r, 5000)); + const said = await on("anchor", `docker logs mesh-builder 2>&1 | tail -20`); + assert.doesNotMatch(said.out, /cannot reach the broker/, + `the builder is running and cannot reach the broker:\n${said.out}`); + // The credential arrived, is readable only by the machine, and is the scoped account rather // than the broker's own. assert.match(await must("anchor", `stat -c %a /var/lib/mesh/builder/broker`), /^600/); const credential = await must("anchor", `cat /var/lib/mesh/builder/broker`); - assert.match(credential, /^amqps:\/\/lab-builder:/, + assert.match(credential, /"url":"amqps:\/\/lab-builder:/, "the builder is using an account that is not its own"); assert.doesNotMatch(credential, /guest:guest/, "the builder holds the broker's own account"); + // And what to check the broker against. A mesh's broker presents a certificate of the mesh's + // own, so a URL alone reaches only a broker some public authority vouches for — which is no + // mesh broker at all, and fails at TLS with an error about an unknown authority. + assert.match(credential, /"fingerprint":"[0-9a-f]{64}"/, + `the builder was given nothing to verify the broker with:\n${credential}`); // And it works: the mesh asks this builder to build something, and it does. Answering is the // only proof that the delivered credential authenticates — a container that is up with a