Unify trunk on main: initialization → main #3
@@ -816,9 +816,17 @@ test("rotating a credential moves both ends, and the old one stops working", {
|
||||
// As the role the provisioner made, into the database it made. The provisioner names a role
|
||||
// after the machine and a database after what the module asked for — which is the contract, and
|
||||
// getting it wrong here made the test fail against a provisioner that had done its job.
|
||||
// By address, resolved on the machine itself. A container does not inherit its host's
|
||||
// /etc/hosts, so a name the mesh wrote there resolves for the machine and not for anything it
|
||||
// runs — which fails as "could not translate host name" and reads like a mesh that never wrote
|
||||
// the name.
|
||||
const where = (await must("laptop",
|
||||
`getent hosts anchor.internal | head -1 | cut -d' ' -f1`)).trim();
|
||||
assert.match(where, /^[0-9.]+$/, `the mesh's name for anchor does not resolve here: ${where}`);
|
||||
|
||||
const login = async (password: string) =>
|
||||
await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` +
|
||||
`${pinned("postgres")} psql -h anchor.internal -p 5433 -U mesh_laptop ` +
|
||||
`${pinned("postgres")} psql -h ${where} -p 5433 -U mesh_laptop ` +
|
||||
`-d realapp -qAt -c "select 1"`, 120_000);
|
||||
|
||||
const diagnostics = async () =>
|
||||
@@ -832,7 +840,8 @@ test("rotating a credential moves both ends, and the old one stops working", {
|
||||
works = (await login(first)).ok;
|
||||
if (!works) await new Promise((r) => setTimeout(r, 5000));
|
||||
}
|
||||
assert.ok(works, `the delivered credential does not authenticate:\n${await diagnostics()}`);
|
||||
assert.ok(works, `the delivered credential does not authenticate:\n` +
|
||||
`${(await login(first)).out}\n${await diagnostics()}`);
|
||||
|
||||
// Now rotate. One command: the record changes AND both ends are sent, because leaving the
|
||||
// sending to a later command is the fault above, exactly.
|
||||
@@ -1020,8 +1029,11 @@ test("model access is answered by a record, and the key the mesh took is one it
|
||||
|
||||
// Nor is it anywhere it could have been read on the way.
|
||||
for (const where of ["/var/lib/mesh-host/declared.json", "/var/lib/mesh-host/state.json"]) {
|
||||
const held = await on("laptop", `grep -c ${quote(secret)} ${where} 2>/dev/null || echo 0`);
|
||||
assert.equal(held.out.trim(), "0", `the key is in the open in ${where}`);
|
||||
// Whether grep found it, not how many times. `grep -c` prints 0 and exits non-zero when it
|
||||
// finds nothing, so the obvious `|| echo 0` prints a second one and the count is never what
|
||||
// it looks like.
|
||||
const found = await on("laptop", `grep -q ${quote(secret)} ${where}`);
|
||||
assert.ok(!found.ok, `the key is in the open in ${where}`);
|
||||
}
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user