The end-to-end test reads the grant where the mesh now writes it

Two assertions in the full-mesh test encoded the old naming: the grant
file read back from the provider, and the PostgreSQL role the real
application logs in as. Both are named after the consumer now, and a
consumer is a module on a machine.

These are the two that matter most in this file — it is the only place
where a real application authenticates against a real database with a
password the mesh delivered and cannot read, so they are what would have
caught the naming going wrong end to end.
This commit is contained in:
2026-09-01 02:48:24 +02:00
parent e7f4a49e40
commit cb0edcee8d
2 changed files with 8 additions and 3 deletions
+7 -2
View File
@@ -270,7 +270,10 @@ test("a credential reaches both ends and the mesh holds neither", { skip, timeou
await new Promise((r) => setTimeout(r, 8000));
const onConsumer = (await must("laptop", `cat /etc/meshboard/database.password`)).trim();
const onProvider = (await must("anchor", `cat /var/lib/mesh-host/grants/laptop.secret`)).trim();
// Named after the machine *and* the module, because a consumer is both (novox/hq
// 04-ISSUES/022) — a node routinely runs several modules wanting one database.
const onProvider = (await must("anchor",
`cat /var/lib/mesh-host/grants/laptop.meshboard.secret`)).trim();
assert.ok(onConsumer.length >= 40, `the consumer's credential is ${onConsumer.length} characters`);
assert.equal(onConsumer, onProvider,
"the two ends hold different passwords, so nothing could ever authenticate");
@@ -890,7 +893,9 @@ test("rotating a credential moves both ends, and the old one stops working", {
const login = async (password: string) =>
await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` +
`${pinned("postgres")} psql -h ${where} -p 5433 -U mesh_laptop ` +
// The role the provisioner made: mesh_<node>_<module>, because a consumer is a module on
// a machine (novox/hq 04-ISSUES/022).
`${pinned("postgres")} psql -h ${where} -p 5433 -U mesh_laptop_realapp ` +
`-d realapp -qAt -c "select 1"`, 120_000);
const diagnostics = async () =>