From cbd9b647eceacaf9d851e848d5565a042be54da3 Mon Sep 17 00:00:00 2001 From: jochen Date: Sat, 5 Sep 2026 02:51:53 +0200 Subject: [PATCH] =?UTF-8?q?e2e:=20unblock=20the=20minio=20grant=20?= =?UTF-8?q?=E2=80=94=20the=20consumer=20declares=20a=20slug=20(ADR=200054)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Issue 010 fixed: bucketuser declares slug `bkt`, so its identity mesh_anchor_bkt (15) fits an S3 access key where mesh_anchor_bucketuser (22) did not. Unskips the test. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF --- .../minio-grant-end-to-end.test.ts | 28 +++++++++---------- 1 file changed, 13 insertions(+), 15 deletions(-) diff --git a/test/integration/minio-grant-end-to-end.test.ts b/test/integration/minio-grant-end-to-end.test.ts index 4adcf50..fbc860f 100644 --- a/test/integration/minio-grant-end-to-end.test.ts +++ b/test/integration/minio-grant-end-to-end.test.ts @@ -27,21 +27,16 @@ const capability = await labIsUsable(); const binary = hostBinaryPath(); const bundle = process.env["MESH_LAB_BUNDLE"] ?? ""; -// Blocked on novox/hq 04-ISSUES/010: the mesh derives `as` = mesh__ (e.g. -// `mesh_anchor_bucketuser`, 22 chars), and an S3 access key is capped at 20 — minio refuses to -// create the service account under it. This test is correct and will pass once the mesh's login -// fits S3's identifier rules; skipped (before hook and test both) until that is decided, rather than -// made to pass by working around the derivation. Remove `blocked ||` to run it once 010 is fixed. -const blocked = "blocked on 04-ISSUES/010 — the mesh's `as` exceeds minio's S3 access-key limit (3–20)"; - -const skip = blocked - || (!capability.usable - ? `lab not usable: ${capability.why}` - : !binary || !existsSync(binary) - ? "MESH_LAB_HOST_BINARY is not set to a built mesh-host" - : !bundle || !existsSync(bundle) - ? "MESH_LAB_BUNDLE is not set to a substrate bundle (mesh-host examples/)" - : false); +// 04-ISSUES/010 is fixed by ADR 0054: an S3 access key is capped at 20, and the mesh derives +// `mesh__`, so `bucketuser` on `anchor` (22) would overflow — but a consumer declares a +// short `slug` and its identity fits. This bed's consumer does exactly that. +const skip = !capability.usable + ? `lab not usable: ${capability.why}` + : !binary || !existsSync(binary) + ? "MESH_LAB_HOST_BINARY is not set to a built mesh-host" + : !bundle || !existsSync(bundle) + ? "MESH_LAB_BUNDLE is not set to a substrate bundle (mesh-host examples/)" + : false; const SCENARIO = "minio-node"; const MACHINE = "anchor"; @@ -204,6 +199,9 @@ test("the mesh grants a consumer an S3 bucket, and the credential it delivers re const consumerManifest = JSON.stringify({ module: "bucketuser", version: "1", + // A short slug, so the derived identity `mesh_anchor_bkt` fits an S3 access key's 20 chars where + // `mesh_anchor_bucketuser` (22) would not (novox/hq ADR 0054, 04-ISSUES/010). + slug: "bkt", requires: ["s3-bucket"], contributes: { "s3-bucket": { name: "bucketuser" } }, binds: { "s3-bucket": "/var/lib/bucketuser/s3.json" },