From cb0edcee8d2b16d21040c251e1fe32d3c922877d Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 1 Sep 2026 02:48:24 +0200 Subject: [PATCH] The end-to-end test reads the grant where the mesh now writes it MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two assertions in the full-mesh test encoded the old naming: the grant file read back from the provider, and the PostgreSQL role the real application logs in as. Both are named after the consumer now, and a consumer is a module on a machine. These are the two that matter most in this file — it is the only place where a real application authenticates against a real database with a password the mesh delivered and cannot read, so they are what would have caught the naming going wrong end to end. --- test/integration/mesh.test.ts | 9 +++++++-- test/integration/provisioner.test.ts | 2 +- 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/test/integration/mesh.test.ts b/test/integration/mesh.test.ts index e62cac4..c11cba9 100644 --- a/test/integration/mesh.test.ts +++ b/test/integration/mesh.test.ts @@ -270,7 +270,10 @@ test("a credential reaches both ends and the mesh holds neither", { skip, timeou await new Promise((r) => setTimeout(r, 8000)); const onConsumer = (await must("laptop", `cat /etc/meshboard/database.password`)).trim(); - const onProvider = (await must("anchor", `cat /var/lib/mesh-host/grants/laptop.secret`)).trim(); + // Named after the machine *and* the module, because a consumer is both (novox/hq + // 04-ISSUES/022) — a node routinely runs several modules wanting one database. + const onProvider = (await must("anchor", + `cat /var/lib/mesh-host/grants/laptop.meshboard.secret`)).trim(); assert.ok(onConsumer.length >= 40, `the consumer's credential is ${onConsumer.length} characters`); assert.equal(onConsumer, onProvider, "the two ends hold different passwords, so nothing could ever authenticate"); @@ -890,7 +893,9 @@ test("rotating a credential moves both ends, and the old one stops working", { const login = async (password: string) => await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` + - `${pinned("postgres")} psql -h ${where} -p 5433 -U mesh_laptop ` + + // The role the provisioner made: mesh__, because a consumer is a module on + // a machine (novox/hq 04-ISSUES/022). + `${pinned("postgres")} psql -h ${where} -p 5433 -U mesh_laptop_realapp ` + `-d realapp -qAt -c "select 1"`, 120_000); const diagnostics = async () => diff --git a/test/integration/provisioner.test.ts b/test/integration/provisioner.test.ts index e6d0177..715fd42 100644 --- a/test/integration/provisioner.test.ts +++ b/test/integration/provisioner.test.ts @@ -253,6 +253,6 @@ test("a manifest naming a credential that was never written is refused", { skip, ); const { out, ok } = await provision(); assert.equal(ok, false, "it carried on past a missing credential"); - assert.match(out, /should be at .*ghost\.secret/); + assert.match(out, /should be at .*ghost\.meshboard\.secret/); assert.equal(await sql(`select count(*) from pg_roles where rolname = 'mesh_ghost_meshboard'`), "0"); });