From a65115fc81a34edea8c51157d19c5a0e8085f21e Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 1 Sep 2026 23:20:38 +0200 Subject: [PATCH] The forge poll covers both halves, and the cache failure names the container MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The provisioner makes the role and then the database; a poll that waited for the first and checked the second once was racing the gap between two statements, and lost it once, eighteen seconds into a run. The cache test's provisioner could not resolve the store's name, which usually means the store's container never registered it — and the diagnostics showed only the provisioner's side of that conversation. A grant that never arrives now prints the container states, the store's log and the provisioner's, so the next failure names the half that actually fell over. --- test/integration/mesh.test.ts | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/test/integration/mesh.test.ts b/test/integration/mesh.test.ts index b755f80..bf3d477 100644 --- a/test/integration/mesh.test.ts +++ b/test/integration/mesh.test.ts @@ -1972,15 +1972,17 @@ test("the forge runs, on a database the mesh gave it", { skip, timeout: 900_000 (await on("anchor", `docker exec postgres psql -U postgres -qAt -c ${quote(q)}`, 60_000)).out.trim(); + // Both halves in one poll. The provisioner makes the role and then the database, and a test + // that waited for the first and checked the second once was racing the gap between two + // statements — it lost, once, eighteen seconds into a run. let made = ""; for (let i = 0; i < 40 && made !== "t"; i++) { - made = await psql("select true from pg_roles where rolname = 'mesh_anchor_gitea'"); + made = await psql("select true from pg_roles where rolname = 'mesh_anchor_gitea'" + + " and exists (select from pg_database where datname = 'gitea')"); if (made !== "t") await new Promise((r) => setTimeout(r, 3000)); } assert.equal(made, "t", `no login was created for the forge:\n${(await on("anchor", "docker logs mesh-provision-postgres 2>&1 | tail -20")).out}`); - assert.equal(await psql("select true from pg_database where datname = 'gitea'"), "t", - "the login exists and the database it owns does not"); // And the forge itself, answering. Not that its container exists — that it serves. // @@ -2073,7 +2075,9 @@ test("a consumer's cache grant means exactly its own keys", { skip, timeout: 600 } assert.ok(granted, `no user was created for the consumer: ` + - `${(await on("anchor", "docker logs mesh-provision-redis 2>&1 | tail -20")).out}`); + `containers:\n${(await on("anchor", "docker ps -a --format '{{.Names}} {{.Status}}' | head -20")).out}\n` + + `the store:\n${(await on("anchor", "docker logs redis 2>&1 | tail -15")).out}\n` + + `the provisioner:\n${(await on("anchor", "docker logs mesh-provision-redis 2>&1 | tail -15")).out}`); const asConsumer = (command: string) => on("anchor", `docker exec redis redis-cli --no-auth-warning ` +