The no-fake multi-node gate: built-store-cross-node #34

Merged
jschoubben merged 12 commits from bed/built-store-cross-node into main 2026-09-17 23:00:49 +00:00
Showing only changes of commit cb353f9881 - Show all commits
@@ -242,7 +242,7 @@ test("a joined node's consumers open the store and broker the mesh built and ado
// first build finishes. Pushed and WAITED for, because the restart bounces the runtime and an
// apply in flight retries.
for (const machine of [CONTROL, NODE]) {
await mesh(`push ${machine}`, 600_000);
console.log(await mesh(`push ${machine}`, 600_000));
const deadline = Date.now() + 300_000;
let trusted = false;
while (Date.now() < deadline) {
@@ -250,8 +250,15 @@ test("a joined node's consumers open the store and broker the mesh built and ado
if (/TRUSTED/.test(got.out)) { trusted = true; break; }
await new Promise((r) => setTimeout(r, 5_000));
}
// A failure here has two distinguishable shapes, so the dump carries both: a declaration that
// never named the trust (the controller composed without it — issues 042/048 as a race), and
// one that named it and was never applied (delivery or apply). mesh-host's log says which.
assert.ok(trusted, `${machine}'s runtime never learned the registry trust:\n` +
(await on(machine, `cat /etc/docker/daemon.json 2>&1; docker info 2>&1 | tail -20`)).out);
(await on(machine, `cat /etc/docker/daemon.json 2>&1; docker info 2>&1 | tail -20`)).out +
`\n--- ${machine} mesh-host.log ---\n` +
(await on(machine, `tail -60 /var/log/mesh-host.log 2>&1`)).out +
`\n--- ${machine} declared registry-trust? ---\n` +
(await on(machine, `base64 -d < /var/lib/mesh-host/declared.json 2>/dev/null | grep -c registry-trust; python3 -c "import json,base64; d=json.load(open('/var/lib/mesh-host/declared.json')); print('registry-trust' in base64.b64decode(d['declaration']).decode())" 2>&1`)).out);
}
// The shared base first — every module with code of its own stands on it.