The two-node bed stocks the packet filter's seat runtime
The filter module now serves its verbs from a runtime the mesh builds (novox/hq ADR 0170), and a bed registered its raw manifest, which the mesh refuses as unbuilt. The bed stocks mesh-runtime-nftables and the filter helper registers the module through the stocked image.
This commit is contained in:
@@ -37,6 +37,9 @@ machines:
|
|||||||
images: []
|
images: []
|
||||||
|
|
||||||
images:
|
images:
|
||||||
|
# The packet filter's seat runtime (novox/hq ADR 0170): the filter module now serves its verbs from
|
||||||
|
# a runtime the mesh builds, so a bed that installs the filter stocks it.
|
||||||
|
- mesh-runtime-nftables:development
|
||||||
- mesh-controller:development
|
- mesh-controller:development
|
||||||
# And the builder, because it is a module the mesh assigns rather than a program somebody
|
# And the builder, because it is a module the mesh assigns rather than a program somebody
|
||||||
# starts by hand — which is the only way its credential can be one the mesh delivered.
|
# starts by hand — which is the only way its credential can be one the mesh delivered.
|
||||||
|
|||||||
@@ -376,11 +376,15 @@ function shellQuote(s: string): string {
|
|||||||
*/
|
*/
|
||||||
export async function deriveTheFilterOn(o: {
|
export async function deriveTheFilterOn(o: {
|
||||||
machine: string; node: string; hubPort: number;
|
machine: string; node: string; hubPort: number;
|
||||||
|
/** The images the machines hold. Given, the filter module's runtime — the packet-filter seat's,
|
||||||
|
* which the mesh would build (novox/hq ADR 0170) — is the stocked one, as for any catalogue
|
||||||
|
* module a bed installs; the scenario must then stock `mesh-runtime-nftables:development`. */
|
||||||
|
held?: HeldImage[];
|
||||||
must: (machine: string, command: string, timeoutMs?: number) => Promise<string>;
|
must: (machine: string, command: string, timeoutMs?: number) => Promise<string>;
|
||||||
mesh: (command: string, timeoutMs?: number) => Promise<string>;
|
mesh: (command: string, timeoutMs?: number) => Promise<string>;
|
||||||
on: (machine: string, command: string, timeoutMs?: number) => Promise<{ out: string; ok: boolean }>;
|
on: (machine: string, command: string, timeoutMs?: number) => Promise<{ out: string; ok: boolean }>;
|
||||||
}): Promise<string> {
|
}): Promise<string> {
|
||||||
const manifest = readFileSync(catalogueManifest(FILTER_MODULE), "utf8");
|
const manifest = o.held ? catalogueModule(FILTER_MODULE, o.held) : readFileSync(catalogueManifest(FILTER_MODULE), "utf8");
|
||||||
await o.must(o.machine,
|
await o.must(o.machine,
|
||||||
`printf %s ${shellQuote(manifest)} > /tmp/${FILTER_MODULE}.json && docker cp /tmp/${FILTER_MODULE}.json mesh-controller:/${FILTER_MODULE}.json`);
|
`printf %s ${shellQuote(manifest)} > /tmp/${FILTER_MODULE}.json && docker cp /tmp/${FILTER_MODULE}.json mesh-controller:/${FILTER_MODULE}.json`);
|
||||||
await o.mesh(`module add /${FILTER_MODULE}.json`);
|
await o.mesh(`module add /${FILTER_MODULE}.json`);
|
||||||
|
|||||||
@@ -346,7 +346,7 @@ test("both machines join it, and the token is all they need", { skip, timeout: 9
|
|||||||
await new Promise((r) => setTimeout(r, 3000));
|
await new Promise((r) => setTimeout(r, 3000));
|
||||||
}
|
}
|
||||||
await new Promise((r) => setTimeout(r, 5000));
|
await new Promise((r) => setTimeout(r, 5000));
|
||||||
await deriveTheFilterOn({ machine: "anchor", node: "anchor", hubPort: 51820, must, mesh, on });
|
await deriveTheFilterOn({ machine: "anchor", node: "anchor", hubPort: 51820, held, must, mesh, on });
|
||||||
|
|
||||||
// **The laptop makes its tunnel key, and the token is issued for it.** The hub is told the key
|
// **The laptop makes its tunnel key, and the token is issued for it.** The hub is told the key
|
||||||
// before the token is shown, so the tunnel answers the first time the laptop knocks.
|
// before the token is shown, so the tunnel answers the first time the laptop knocks.
|
||||||
@@ -409,7 +409,7 @@ test("a credential reaches both ends and the mesh holds neither", { skip, timeou
|
|||||||
// The anchor's derived filter, admitting the hub's port — what genesis does on the control-node,
|
// The anchor's derived filter, admitting the hub's port — what genesis does on the control-node,
|
||||||
// and what a bed raised from the bundle must do itself (ADR 0088). Until it is, the base filter
|
// and what a bed raised from the bundle must do itself (ADR 0088). Until it is, the base filter
|
||||||
// keeps the hub closed and nothing on the laptop reaches anchor over the private network.
|
// keeps the hub closed and nothing on the laptop reaches anchor over the private network.
|
||||||
await deriveTheFilterOn({ machine: "anchor", node: "anchor", hubPort: 51820, must, mesh, on });
|
await deriveTheFilterOn({ machine: "anchor", node: "anchor", hubPort: 51820, held, must, mesh, on });
|
||||||
|
|
||||||
const onConsumer = (await must("laptop", `cat /etc/meshboard/database.password`)).trim();
|
const onConsumer = (await must("laptop", `cat /etc/meshboard/database.password`)).trim();
|
||||||
// Named after the machine *and* the module, because a consumer is both (novox/hq
|
// Named after the machine *and* the module, because a consumer is both (novox/hq
|
||||||
|
|||||||
Reference in New Issue
Block a user