The trust wait dumps mesh-host's log and the declaration on failure

Run 11 failed with node2's daemon.json never written and nothing to say
whether the declaration lacked the trust or never applied. The dump now
answers that, and the push output is printed so a compose that refused
is visible in the run log.
This commit is contained in:
2026-09-18 00:15:16 +02:00
parent ca263d2a8b
commit cb353f9881
@@ -242,7 +242,7 @@ test("a joined node's consumers open the store and broker the mesh built and ado
// first build finishes. Pushed and WAITED for, because the restart bounces the runtime and an // first build finishes. Pushed and WAITED for, because the restart bounces the runtime and an
// apply in flight retries. // apply in flight retries.
for (const machine of [CONTROL, NODE]) { for (const machine of [CONTROL, NODE]) {
await mesh(`push ${machine}`, 600_000); console.log(await mesh(`push ${machine}`, 600_000));
const deadline = Date.now() + 300_000; const deadline = Date.now() + 300_000;
let trusted = false; let trusted = false;
while (Date.now() < deadline) { while (Date.now() < deadline) {
@@ -250,8 +250,15 @@ test("a joined node's consumers open the store and broker the mesh built and ado
if (/TRUSTED/.test(got.out)) { trusted = true; break; } if (/TRUSTED/.test(got.out)) { trusted = true; break; }
await new Promise((r) => setTimeout(r, 5_000)); await new Promise((r) => setTimeout(r, 5_000));
} }
// A failure here has two distinguishable shapes, so the dump carries both: a declaration that
// never named the trust (the controller composed without it — issues 042/048 as a race), and
// one that named it and was never applied (delivery or apply). mesh-host's log says which.
assert.ok(trusted, `${machine}'s runtime never learned the registry trust:\n` + assert.ok(trusted, `${machine}'s runtime never learned the registry trust:\n` +
(await on(machine, `cat /etc/docker/daemon.json 2>&1; docker info 2>&1 | tail -20`)).out); (await on(machine, `cat /etc/docker/daemon.json 2>&1; docker info 2>&1 | tail -20`)).out +
`\n--- ${machine} mesh-host.log ---\n` +
(await on(machine, `tail -60 /var/log/mesh-host.log 2>&1`)).out +
`\n--- ${machine} declared registry-trust? ---\n` +
(await on(machine, `base64 -d < /var/lib/mesh-host/declared.json 2>/dev/null | grep -c registry-trust; python3 -c "import json,base64; d=json.load(open('/var/lib/mesh-host/declared.json')); print('registry-trust' in base64.b64decode(d['declaration']).decode())" 2>&1`)).out);
} }
// The shared base first — every module with code of its own stands on it. // The shared base first — every module with code of its own stands on it.