Log in as the role the provisioner made, and record the licences first
Two setup faults, each of which read as the mesh failing. The provisioner names a role after the machine and a database after what the module asked for. The rotation test logged in as the module's name into the wrong database, so a provisioner that had done its job exactly looked like one that had not. And the licence test assigned before recording any licence, so the refusal it got was "nothing provides model-access" — correct, and a different refusal from the one being tested. Assigning is also the earliest point a person meets it, so that is where it is now checked.
This commit is contained in:
@@ -813,10 +813,13 @@ test("rotating a credential moves both ends, and the old one stops working", {
|
||||
// A real login from the consumer's machine, over the private network — not over loopback, where
|
||||
// pg_hba trusts anything and every password looks correct. That was done here once and the test
|
||||
// passed for an afternoon while verifying nothing: a deliberately wrong password returned a row.
|
||||
// As the role the provisioner made, into the database it made. The provisioner names a role
|
||||
// after the machine and a database after what the module asked for — which is the contract, and
|
||||
// getting it wrong here made the test fail against a provisioner that had done its job.
|
||||
const login = async (password: string) =>
|
||||
await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` +
|
||||
`${pinned("postgres")} psql -h anchor.internal -p 5433 -U realapp ` +
|
||||
`-d postgres -qAt -c "select 1"`, 120_000);
|
||||
`${pinned("postgres")} psql -h anchor.internal -p 5433 -U mesh_laptop ` +
|
||||
`-d realapp -qAt -c "select 1"`, 120_000);
|
||||
|
||||
const diagnostics = async () =>
|
||||
`provisioner:\n${(await on("anchor", `docker logs real-provisioner 2>&1 | tail -20`)).out}\n` +
|
||||
@@ -957,15 +960,19 @@ test("model access is answered by a record, and the key the mesh took is one it
|
||||
`> /tmp/assistant.json`);
|
||||
await must("anchor", `docker cp /tmp/assistant.json mesh-control:/assistant.json`);
|
||||
await mesh("module add /assistant.json");
|
||||
await mesh("assign laptop assistant");
|
||||
|
||||
// The licences first. With none recorded at all the honest answer is that nothing provides
|
||||
// model-access — correct, and a different refusal from the one being tested.
|
||||
await mesh(`licence add anthropic personal --serves '{"model":"a-model"}'`);
|
||||
await mesh(`licence add anthropic the-organisation --serves '{"model":"a-model"}'`);
|
||||
|
||||
// Refused until somebody says which, and the refusal names both candidates and the command.
|
||||
// ADR 0024 warns this will be felt — which is correct, and correct is not the same as usable.
|
||||
const refused = await on("anchor", `docker exec mesh-control /mesh-control plan laptop`);
|
||||
assert.ok(!refused.ok, `a consumer was given model access without anybody saying which:\n${refused.out}`);
|
||||
// Refused at the earliest point somebody could meet it: assigning records the assignment and
|
||||
// then says the machine's set cannot be applied. The refusal names both candidates and the
|
||||
// command. ADR 0024 warns this will be felt — which is correct, and correct is not the same as
|
||||
// usable.
|
||||
const refused = await on("anchor", `docker exec mesh-control /mesh-control assign laptop assistant`);
|
||||
assert.ok(!refused.ok,
|
||||
`a consumer was given model access without anybody saying which:\n${refused.out}`);
|
||||
for (const want of ["personal", "the-organisation", "licence use"]) {
|
||||
assert.match(refused.out, new RegExp(want),
|
||||
`the refusal does not name ${want}:\n${refused.out}`);
|
||||
|
||||
Reference in New Issue
Block a user