package hub import ( "encoding/json" "os" "testing" ) // The os_update block is a cross-repo contract: testdata/desired-state-osupdate.golden.json is byte-identical with // felhom.eu/hub/internal/api/testdata (the hub's TestOSUpdate_DesiredBlockMatchesTheGolden proves the hub SERVES // it). Here: the agent DECODES every field. A renamed json tag on either side fails one of the two tests. func TestOSUpdateGolden_Decodes(t *testing.T) { raw, err := os.ReadFile("testdata/desired-state-osupdate.golden.json") if err != nil { t.Fatal(err) } var resp DesiredStateResponse if err := json.Unmarshal(raw, &resp); err != nil { t.Fatal(err) } o := resp.DesiredState.OSUpdate if o == nil || o.Ring != 1 || !o.Enabled || o.Release == nil { t.Fatalf("os_update = %+v", o) } r := o.Release if r.ID != "os-guest-20261004-120000" || r.Snapshot != "20261004T120000Z" || len(r.Packages) != 2 || r.Packages[1].Name != "openssl" || r.Packages[1].Version != "3.5.7-1~deb13u3" || r.Packages[1].Origin != "Debian-Security" { t.Fatalf("release = %+v", r) } // v0.141.0: the host layer's own approved set (`11` ยง8 step 3). h := o.HostRelease if h == nil || h.ID != "os-host-20261004-120000" || h.Snapshot != "20261004T120000Z" || len(h.Packages) != 1 || h.Packages[0].Name != "libssl3t64" || h.Packages[0].Origin != "Debian-Security" { t.Fatalf("host_release = %+v", h) } }