package proxmox import ( "context" "net/http" "testing" "time" "gitea.dooplex.hu/admin/felhom-agent/internal/pvegate" ) // R-812 option A: while a Proxmox package step holds the gate, a non-GET API call waits and a GET does not. // // COMPANION RED-PROOF (observed): delete the pvegate.Write block in doBody → this fails with "a PUT reached the API // while the Proxmox step held the gate". Restored. (audits/day-2026-10-07/B/red-pvegate-chokepoints.txt) func TestPVEGate_ClientWriteWaitsGetDoesNot(t *testing.T) { d := &mockDoer{fn: func(*http.Request) (*http.Response, error) { return jsonResp(200, `{"data":null}`), nil }} c := newTestClient(d) end, err := pvegate.Step(context.Background()) if err != nil { t.Fatal(err) } if err := c.get(context.Background(), "/nodes", nil); err != nil { t.Fatalf("a GET must not wait on the gate: %v", err) } if d.calls != 1 { t.Fatalf("the GET must reach the API, calls=%d", d.calls) } ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond) defer cancel() err = c.postForm(ctx, http.MethodPut, "/nodes/x/lxc/9201/config", nil, nil) if d.calls != 1 { end() t.Fatal("a PUT reached the API while the Proxmox step held the gate") } if err == nil { end() t.Fatal("a PUT held back past its deadline must fail") } end() if err := c.postForm(context.Background(), http.MethodPut, "/nodes/x/lxc/9201/config", nil, nil); err != nil || d.calls != 2 { t.Fatalf("after the step the PUT must go through (err=%v calls=%d)", err, d.calls) } } // A root `pct set` waits on the gate; `pct exec` does not. // // COMPANION RED-PROOF (observed): delete the WritesEtcPVE block in RunStdin → this fails with "pct set ran while the // Proxmox step held the gate". Restored. func TestPVEGate_ExecRunnerPctSetWaits(t *testing.T) { r := &ExecRunner{Mode: RunnerDirect} end, err := pvegate.Step(context.Background()) if err != nil { t.Fatal(err) } defer end() ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond) defer cancel() start := time.Now() _, _, err = r.Run(ctx, "/nonexistent/pct", "set", "9201", "-mp8", "/x") if err == nil || time.Since(start) < 90*time.Millisecond { t.Fatalf("pct set ran while the Proxmox step held the gate (err=%v after %s)", err, time.Since(start)) } start = time.Now() _, _, _ = r.Run(context.Background(), "/nonexistent/pct", "exec", "9201", "--", "true") if time.Since(start) > 80*time.Millisecond { t.Fatal("pct exec must not wait on the gate") } } func TestWritesEtcPVE(t *testing.T) { for _, c := range []struct { name string args []string want bool }{ {"pct", []string{"set", "9201", "-mp8", "x"}, true}, {"/usr/sbin/pct", []string{"create", "9201"}, true}, {"pct", []string{"exec", "9201", "--", "true"}, false}, {"pct", []string{"status", "9201"}, false}, {"pvesm", []string{"add", "dir", "x"}, true}, {"pveum", []string{"acl", "modify"}, true}, {"/usr/local/sbin/felhom-pbs-apply", []string{"reconcile"}, true}, {"/usr/local/sbin/felhom-pbs-apply", []string{"read"}, false}, {"/usr/local/sbin/felhom-os-apply", []string{"--plan", "x"}, false}, {"pct", nil, false}, } { if got := WritesEtcPVE(c.name, c.args); got != c.want { t.Errorf("WritesEtcPVE(%s %v) = %v, want %v", c.name, c.args, got, c.want) } } }