diff --git a/test/integration/minio-grant-end-to-end.test.ts b/test/integration/minio-grant-end-to-end.test.ts index 4adcf50..fbc860f 100644 --- a/test/integration/minio-grant-end-to-end.test.ts +++ b/test/integration/minio-grant-end-to-end.test.ts @@ -27,21 +27,16 @@ const capability = await labIsUsable(); const binary = hostBinaryPath(); const bundle = process.env["MESH_LAB_BUNDLE"] ?? ""; -// Blocked on novox/hq 04-ISSUES/010: the mesh derives `as` = mesh__ (e.g. -// `mesh_anchor_bucketuser`, 22 chars), and an S3 access key is capped at 20 — minio refuses to -// create the service account under it. This test is correct and will pass once the mesh's login -// fits S3's identifier rules; skipped (before hook and test both) until that is decided, rather than -// made to pass by working around the derivation. Remove `blocked ||` to run it once 010 is fixed. -const blocked = "blocked on 04-ISSUES/010 — the mesh's `as` exceeds minio's S3 access-key limit (3–20)"; - -const skip = blocked - || (!capability.usable - ? `lab not usable: ${capability.why}` - : !binary || !existsSync(binary) - ? "MESH_LAB_HOST_BINARY is not set to a built mesh-host" - : !bundle || !existsSync(bundle) - ? "MESH_LAB_BUNDLE is not set to a substrate bundle (mesh-host examples/)" - : false); +// 04-ISSUES/010 is fixed by ADR 0054: an S3 access key is capped at 20, and the mesh derives +// `mesh__`, so `bucketuser` on `anchor` (22) would overflow — but a consumer declares a +// short `slug` and its identity fits. This bed's consumer does exactly that. +const skip = !capability.usable + ? `lab not usable: ${capability.why}` + : !binary || !existsSync(binary) + ? "MESH_LAB_HOST_BINARY is not set to a built mesh-host" + : !bundle || !existsSync(bundle) + ? "MESH_LAB_BUNDLE is not set to a substrate bundle (mesh-host examples/)" + : false; const SCENARIO = "minio-node"; const MACHINE = "anchor"; @@ -204,6 +199,9 @@ test("the mesh grants a consumer an S3 bucket, and the credential it delivers re const consumerManifest = JSON.stringify({ module: "bucketuser", version: "1", + // A short slug, so the derived identity `mesh_anchor_bkt` fits an S3 access key's 20 chars where + // `mesh_anchor_bucketuser` (22) would not (novox/hq ADR 0054, 04-ISSUES/010). + slug: "bkt", requires: ["s3-bucket"], contributes: { "s3-bucket": { name: "bucketuser" } }, binds: { "s3-bucket": "/var/lib/bucketuser/s3.json" },