From 73bd086193a4be3d9e7692277bfd93a6834554a4 Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 6 Sep 2026 16:09:01 +0200 Subject: [PATCH] lavinmq-bed: reproduces a credential-mint gap for require-only consumers of a parameterless provision MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The lavinmq AMQP provider comes up and serves, but its receives file has given:[] — the consumer amqp-ping (requires amqp, contributes nothing, as a parameterless provision like redis-cache takes no per-consumer payload) is never minted a credential, so the provisioner creates no vhost. Diagnostic in the test dumps the empty grants file + the provisioner log. This is the resolve/plan mint path (grantsFor -> SecretsFrom), ADR 0048 territory, and it likely affects redis-cache consumers the same way. Preserved for a focused fix; not merged. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF --- test/integration/lavinmq-bed.test.ts | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/test/integration/lavinmq-bed.test.ts b/test/integration/lavinmq-bed.test.ts index 44a2ab8..af37b7b 100644 --- a/test/integration/lavinmq-bed.test.ts +++ b/test/integration/lavinmq-bed.test.ts @@ -379,6 +379,15 @@ test("the lavinmq provider and its consumer ride laptop while the substrate brok // local control socket needs no auth); the admin authenticating to the management API is implicit, // because the vhost could not exist otherwise. // ================================================================================================ + // DIAG: the provisioner logged no create — is the grant in its receives file, and is the management + // API it must reach actually up? (A stuck waitReady logs neither a create nor an error.) + { + const grants = (await on(NODE, `cat /var/lib/lavinmq-module/grants/mesh.json 2>&1 || echo MISSING`)).out; + const api = (await on(NODE, `docker exec lavinmq sh -c 'wget -qO- http://127.0.0.1:15672/api/overview 2>&1 | head -c 200 || curl -s http://127.0.0.1:15672/api/overview 2>&1 | head -c 200' 2>&1`)).out; + const full = (await on(NODE, `docker logs mesh-lavinmq 2>&1`)).out; + console.log(`\n=== LAVINMQ DIAG ===\ngrants mesh.json:\n${grants}\n--- mgmt API (lavinmq:15672/api/overview) ---\n${api}\n--- mesh-lavinmq full log ---\n${full}\n=== END LAVINMQ DIAG ===\n`); + } + let vhosts = { out: "", ok: false }; const untilVhost = Date.now() + 90_000; while (Date.now() < untilVhost) {