mesh/merge-gate pass: builds mesh-tools, node-tools → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of …
mesh/repo-check pass: THE CHANGE ALTERS ITS OWN CHECK (merge-check.sh): main's version judged it; the change's judges the pull requests after it merges; it…
mesh/delivery delivered
mesh/delivery-group group feat/asks-answered-on-any-channel stopped: a member was stopped
57 lines
2.5 KiB
Go
57 lines
2.5 KiB
Go
package runtime
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/novox/mesh-tools/node-tools/internal/bus"
|
|
)
|
|
|
|
// novox/hq ADR 0259 §8: a runtime on a module's own account serves that module alone, and the machine's
|
|
// runtime never serves itself.
|
|
func TestARuntimeOnAModulesOwnAccountServesThatModuleAlone(t *testing.T) {
|
|
if got, err := ServedModulesFrom("telegram=/b/telegram/tools/telegram", "telegram"); err != nil || len(got) != 1 {
|
|
t.Fatalf("a module's own runtime could not serve it: %v", err)
|
|
}
|
|
if _, err := ServedModulesFrom("telegram=/b/t,dunst=/b/d", "telegram"); err == nil || !strings.Contains(err.Error(), "serves telegram alone") {
|
|
t.Errorf("a module's own runtime served another: %v", err)
|
|
}
|
|
if _, err := ServedModulesFrom("node-tools=/b/n", "node-tools"); err == nil {
|
|
t.Error("the machine's runtime served itself")
|
|
}
|
|
}
|
|
|
|
// No bus word reaches a bundle (security review of 2026-10-08), not even one its module's words name.
|
|
func TestNoBusWordReachesABundle(t *testing.T) {
|
|
base := []string{"MESH_BROKER_FILE=/etc/mesh/broker", "MESH_BROKER_URL=nats://x", "MESH_TOOL_ENV={}",
|
|
"MESH_TOOL_MODULES=a=/b", "MESH_CONSOLE_LISTEN=127.0.0.1:1", "PATH=/usr/bin"}
|
|
env := strings.Join(BundleEnv(base, map[string]string{"MESH_BROKER_FILE": "/again", "OWN": "1"}, "telegram", "anchor"), "\n")
|
|
for _, never := range []string{"MESH_BROKER_FILE", "MESH_BROKER_URL", "MESH_TOOL_ENV", "MESH_TOOL_MODULES", "MESH_CONSOLE_LISTEN"} {
|
|
if strings.Contains(env, never+"=") {
|
|
t.Errorf("%s reached the bundle", never)
|
|
}
|
|
}
|
|
for _, want := range []string{"PATH=/usr/bin", "OWN=1", "MESH_MODULE=telegram", "MESH_NODE=anchor"} {
|
|
if !strings.Contains(env, want) {
|
|
t.Errorf("%s did not reach the bundle", want)
|
|
}
|
|
}
|
|
}
|
|
|
|
// A tool call reaches only a tool's subject: whatever key a caller names, it is never a seat's event, accept
|
|
// or proof — so no tool call says a choice, a link or a code, or submits an ask, in anybody's name.
|
|
func TestAToolCallNeverReachesASeatsEventAcceptOrProof(t *testing.T) {
|
|
for _, key := range []string{"seat:intake.event.choice.telegram", "seat:intake.proof.code.telegram",
|
|
"seat:operator-channel.accept.ask.mesh-delivery", "intake.event", "seat:operator-channel.event.decided.x@anchor",
|
|
"telegram.anything", "x"} {
|
|
subject, err := bus.ToolSubject(key, "node-tools")
|
|
if err != nil {
|
|
continue
|
|
}
|
|
tokens := strings.Split(subject, ".")
|
|
if len(tokens) < 4 || tokens[3] != "tool" {
|
|
t.Errorf("%q reaches %s, which is not a tool's subject", key, subject)
|
|
}
|
|
}
|
|
}
|