Unify trunk on main: initialization → main #3
@@ -816,9 +816,17 @@ test("rotating a credential moves both ends, and the old one stops working", {
|
|||||||
// As the role the provisioner made, into the database it made. The provisioner names a role
|
// As the role the provisioner made, into the database it made. The provisioner names a role
|
||||||
// after the machine and a database after what the module asked for — which is the contract, and
|
// after the machine and a database after what the module asked for — which is the contract, and
|
||||||
// getting it wrong here made the test fail against a provisioner that had done its job.
|
// getting it wrong here made the test fail against a provisioner that had done its job.
|
||||||
|
// By address, resolved on the machine itself. A container does not inherit its host's
|
||||||
|
// /etc/hosts, so a name the mesh wrote there resolves for the machine and not for anything it
|
||||||
|
// runs — which fails as "could not translate host name" and reads like a mesh that never wrote
|
||||||
|
// the name.
|
||||||
|
const where = (await must("laptop",
|
||||||
|
`getent hosts anchor.internal | head -1 | cut -d' ' -f1`)).trim();
|
||||||
|
assert.match(where, /^[0-9.]+$/, `the mesh's name for anchor does not resolve here: ${where}`);
|
||||||
|
|
||||||
const login = async (password: string) =>
|
const login = async (password: string) =>
|
||||||
await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` +
|
await on("laptop", `docker run --rm -e PGPASSWORD=${quote(password)} ` +
|
||||||
`${pinned("postgres")} psql -h anchor.internal -p 5433 -U mesh_laptop ` +
|
`${pinned("postgres")} psql -h ${where} -p 5433 -U mesh_laptop ` +
|
||||||
`-d realapp -qAt -c "select 1"`, 120_000);
|
`-d realapp -qAt -c "select 1"`, 120_000);
|
||||||
|
|
||||||
const diagnostics = async () =>
|
const diagnostics = async () =>
|
||||||
@@ -832,7 +840,8 @@ test("rotating a credential moves both ends, and the old one stops working", {
|
|||||||
works = (await login(first)).ok;
|
works = (await login(first)).ok;
|
||||||
if (!works) await new Promise((r) => setTimeout(r, 5000));
|
if (!works) await new Promise((r) => setTimeout(r, 5000));
|
||||||
}
|
}
|
||||||
assert.ok(works, `the delivered credential does not authenticate:\n${await diagnostics()}`);
|
assert.ok(works, `the delivered credential does not authenticate:\n` +
|
||||||
|
`${(await login(first)).out}\n${await diagnostics()}`);
|
||||||
|
|
||||||
// Now rotate. One command: the record changes AND both ends are sent, because leaving the
|
// Now rotate. One command: the record changes AND both ends are sent, because leaving the
|
||||||
// sending to a later command is the fault above, exactly.
|
// sending to a later command is the fault above, exactly.
|
||||||
@@ -1020,8 +1029,11 @@ test("model access is answered by a record, and the key the mesh took is one it
|
|||||||
|
|
||||||
// Nor is it anywhere it could have been read on the way.
|
// Nor is it anywhere it could have been read on the way.
|
||||||
for (const where of ["/var/lib/mesh-host/declared.json", "/var/lib/mesh-host/state.json"]) {
|
for (const where of ["/var/lib/mesh-host/declared.json", "/var/lib/mesh-host/state.json"]) {
|
||||||
const held = await on("laptop", `grep -c ${quote(secret)} ${where} 2>/dev/null || echo 0`);
|
// Whether grep found it, not how many times. `grep -c` prints 0 and exits non-zero when it
|
||||||
assert.equal(held.out.trim(), "0", `the key is in the open in ${where}`);
|
// finds nothing, so the obvious `|| echo 0` prints a second one and the count is never what
|
||||||
|
// it looks like.
|
||||||
|
const found = await on("laptop", `grep -q ${quote(secret)} ${where}`);
|
||||||
|
assert.ok(!found.ok, `the key is in the open in ${where}`);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user