The lab raised an underlay and put nothing on it: correct, and useless, because the thing it exists to test did not exist. Tier 0 now does, so `place: [host]` works and a raised scenario finally contains something. The refusal narrows rather than disappearing. A scenario placing a host and a substrate is told which half is missing, by name — not that `place:` is unsupported when half of it now works. Placement reads back rather than assuming. A file arriving is not a host working, so the binary is run before it is trusted to answer questions, and what it reports is read from the machine (ADR 0035). The binary comes from an explicit path, because the declaration design leaves where artifacts come from open and a search would harden into the answer by accident. The integration test that matters is the one asserting the host reports the MACHINE and not the workstation that placed it. A raised VM and this workstation differ in every capability — root versus uid 1000, a clean init versus a degraded one, no docker versus docker, no wireguard versus wg0 — so a host reporting the wrong machine is obvious here and invisible anywhere else. And the placed host independently confirms ADR 0031: overlay absent on a freshly raised machine. The underlay suite already asserted that by looking for wireguard interfaces; this is a second witness rather than the same check twice. Two tests failed the moment placement worked, which is what they were for. They defended "there is nothing to place yet" while that was true; the decision changed, so they change with it rather than being deleted. Gate: 75 unit, 20 integration.
87 lines
3.8 KiB
TypeScript
87 lines
3.8 KiB
TypeScript
import { test } from "node:test";
|
|
import assert from "node:assert/strict";
|
|
import { parseScenario } from "../src/declaration/parse.ts";
|
|
import { assertSupported, UnsupportedError } from "../src/lifecycle/supported.ts";
|
|
|
|
/**
|
|
* A declaration the runtime silently ignores is the fault this lab exists to catch —
|
|
* novox/hq 04-ISSUES/003, where a firewall key is declared in five manifests and read by no
|
|
* code. These tests exist so the lab never commits it, and they move as the runtime catches
|
|
* up with the model.
|
|
*/
|
|
|
|
const withGateway = `scenario: x
|
|
segments:
|
|
pub: { kind: public, cidr: [192.0.2.0/24] }
|
|
home: { kind: private, cidr: [192.168.1.0/24], gateway: { to: pub, address: [192.0.2.5], nat: [v4] } }
|
|
machines: { a: { at: { segment: home, address: [192.168.1.9] } } }`;
|
|
|
|
test("a plain scenario is raisable", () => {
|
|
const scenario = parseScenario(`scenario: x
|
|
segments: { net: { kind: public, cidr: [192.0.2.0/24] } }
|
|
machines: { a: { at: { segment: net, address: [192.0.2.1] } } }`);
|
|
assert.doesNotThrow(() => assertSupported(scenario));
|
|
});
|
|
|
|
test("gateways are implemented — a router is materialised for them", () => {
|
|
assert.doesNotThrow(() => assertSupported(parseScenario(withGateway)));
|
|
});
|
|
|
|
test("published ports and policy are implemented", () => {
|
|
const scenario = parseScenario(`scenario: x
|
|
segments:
|
|
pub: { kind: public, cidr: [192.0.2.0/24] }
|
|
home: { kind: private, cidr: [192.168.1.0/24], gateway: { to: pub, address: [192.0.2.5], nat: [v4] } }
|
|
iot: { kind: private, cidr: [192.168.30.0/24], gateway: { to: pub, address: [192.0.2.5], nat: [v4] } }
|
|
policy: [{ from: iot, to: home, allow: false }]
|
|
machines:
|
|
a:
|
|
at: { segment: home, address: [192.168.1.9] }
|
|
published: [{ port: 443, on: home }]`);
|
|
assert.doesNotThrow(() => assertSupported(scenario));
|
|
});
|
|
|
|
test("inbound: deny is implemented — a host firewall is applied and read back", () => {
|
|
const scenario = parseScenario(`scenario: x
|
|
segments: { net: { kind: public, cidr: [192.0.2.0/24] } }
|
|
machines: { a: { at: { segment: net, address: [192.0.2.1] }, inbound: deny } }`);
|
|
assert.doesNotThrow(() => assertSupported(scenario));
|
|
});
|
|
|
|
test("the host is placeable — it used to be refused, and tier 0 now exists", () => {
|
|
// These two tests failed the moment placement worked, which is what they were for. They
|
|
// defended "there is nothing to place yet" while that was true; the decision changed, so
|
|
// they change with it rather than being deleted (novox/hq ADR 0034).
|
|
const scenario = parseScenario(`scenario: x
|
|
segments: { net: { kind: public, cidr: [192.0.2.0/24] } }
|
|
machines: { a: { at: { segment: net, address: [192.0.2.1] } } }
|
|
place: { all: [host] }`);
|
|
assert.doesNotThrow(() => assertSupported(scenario));
|
|
});
|
|
|
|
test("a tier above 0 is still refused, and named", () => {
|
|
// The refusal narrowed rather than disappearing. A scenario placing a host AND a substrate
|
|
// must be told which half is missing — not that `place:` is unsupported, when half of it
|
|
// now works.
|
|
const scenario = parseScenario(`scenario: x
|
|
segments: { net: { kind: public, cidr: [192.0.2.0/24] } }
|
|
machines: { a: { at: { segment: net, address: [192.0.2.1] } } }
|
|
place: { all: [host, substrate] }`);
|
|
try {
|
|
assertSupported(scenario);
|
|
assert.fail("should have refused");
|
|
} catch (err) {
|
|
assert.ok(err instanceof UnsupportedError);
|
|
assert.equal(err.missing.length, 1, `expected only the substrate: ${err.missing.join(", ")}`);
|
|
assert.match(err.missing[0] ?? "", /substrate/);
|
|
assert.match(err instanceof Error ? err.message : "", /silently lacks them/);
|
|
}
|
|
});
|
|
|
|
test("inbound: allow is not a gap — only deny needs enforcing", () => {
|
|
const scenario = parseScenario(`scenario: x
|
|
segments: { net: { kind: public, cidr: [192.0.2.0/24] } }
|
|
machines: { a: { at: { segment: net, address: [192.0.2.1] }, inbound: allow } }`);
|
|
assert.doesNotThrow(() => assertSupported(scenario));
|
|
});
|