diff --git a/test/integration/mesh.test.ts b/test/integration/mesh.test.ts index 1d682ab..42c5dc4 100644 --- a/test/integration/mesh.test.ts +++ b/test/integration/mesh.test.ts @@ -813,10 +813,13 @@ test("rotating a credential moves both ends, and the old one stops working", { // A real login from the consumer's machine, over the private network — not over loopback, where // pg_hba trusts anything and every password looks correct. That was done here once and the test // passed for an afternoon while verifying nothing: a deliberately wrong password returned a row. + // As the role the provisioner made, into the database it made. The provisioner names a role + // after the machine and a database after what the module asked for — which is the contract, and + // getting it wrong here made the test fail against a provisioner that had done its job. const login = async (password: string) => await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` + - `${pinned("postgres")} psql -h anchor.internal -p 5433 -U realapp ` + - `-d postgres -qAt -c "select 1"`, 120_000); + `${pinned("postgres")} psql -h anchor.internal -p 5433 -U mesh_laptop ` + + `-d realapp -qAt -c "select 1"`, 120_000); const diagnostics = async () => `provisioner:\n${(await on("anchor", `docker logs real-provisioner 2>&1 | tail -20`)).out}\n` + @@ -957,15 +960,19 @@ test("model access is answered by a record, and the key the mesh took is one it `> /tmp/assistant.json`); await must("anchor", `docker cp /tmp/assistant.json mesh-control:/assistant.json`); await mesh("module add /assistant.json"); - await mesh("assign laptop assistant"); + // The licences first. With none recorded at all the honest answer is that nothing provides + // model-access — correct, and a different refusal from the one being tested. await mesh(`licence add anthropic personal --serves '{"model":"a-model"}'`); await mesh(`licence add anthropic the-organisation --serves '{"model":"a-model"}'`); - // Refused until somebody says which, and the refusal names both candidates and the command. - // ADR 0024 warns this will be felt — which is correct, and correct is not the same as usable. - const refused = await on("anchor", `docker exec mesh-control /mesh-control plan laptop`); - assert.ok(!refused.ok, `a consumer was given model access without anybody saying which:\n${refused.out}`); + // Refused at the earliest point somebody could meet it: assigning records the assignment and + // then says the machine's set cannot be applied. The refusal names both candidates and the + // command. ADR 0024 warns this will be felt — which is correct, and correct is not the same as + // usable. + const refused = await on("anchor", `docker exec mesh-control /mesh-control assign laptop assistant`); + assert.ok(!refused.ok, + `a consumer was given model access without anybody saying which:\n${refused.out}`); for (const want of ["personal", "the-organisation", "licence use"]) { assert.match(refused.out, new RegExp(want), `the refusal does not name ${want}:\n${refused.out}`);