25024d9dda
New internal/capability: Manifest of required sudo -n grants + Prober that LISTS each via 'sudo -n -l' (never executes) + binary-exists check → ok/degraded snapshot on the hub report. Build-time test asserts manifest⊆sudoers (red-proof: dropping lxc-info FAILs the gate). Startup logs N/N ok + ERROR per degraded. Serve-degraded; no allowlist change. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPZ4GJ8L5Jqf8UiPwbn1kt
69 lines
2.4 KiB
Go
69 lines
2.4 KiB
Go
package hub
|
|
|
|
import (
|
|
"encoding/json"
|
|
"strings"
|
|
"testing"
|
|
|
|
"gitea.dooplex.hu/admin/felhom-agent/internal/capability"
|
|
)
|
|
|
|
func TestHostReport_FieldNamesAndEmptyCollections(t *testing.T) {
|
|
r := &HostReport{
|
|
HostID: "demo-host-01",
|
|
ReportedAt: "2026-06-08T12:00:00Z",
|
|
AgentVersion: "0.3.0",
|
|
Host: HostMetrics{
|
|
Node: "demo-felhom", CPUPercent: 3.2,
|
|
MemoryTotalBytes: 16777216000, MemoryUsedBytes: 4194304000, MemoryPercent: 25.0,
|
|
DiskTotalBytes: 152000000000, DiskUsedBytes: 30000000000, DiskPercent: 19.7,
|
|
LoadAvg: []string{"0.10", "0.20", "0.15"}, UptimeSeconds: 86400,
|
|
CPUTempC: intp(47), // nullable scalar — set here so the "no null" invariant stays meaningful
|
|
},
|
|
Guests: []Guest{{
|
|
VMID: 100, Name: "felhom-cust-acme", Status: "running", ControllerVersion: "",
|
|
Spec: &GuestSpec{Cores: 2, MemoryBytes: 2147483648, DiskBytes: 21474836480},
|
|
}},
|
|
StorageTargets: []StorageTarget{},
|
|
Backups: []Backup{},
|
|
RestoreTests: []RestoreTest{},
|
|
PBSSnapshots: []PBSSnapshot{},
|
|
AuditTail: []AuditEntry{},
|
|
Cloudflared: Cloudflared{Status: "active"},
|
|
Capabilities: []capability.Status{},
|
|
}
|
|
// dr_recipe is always set on the real path (Collect); set it here too so the "no null" invariant
|
|
// covers it (empty pbs is omitempty → omitted, never null).
|
|
r.DRRecipe = BuildDRRecipeHostHalf(r.Guests, r.StorageTargets, r.PBSSnapshots)
|
|
b, err := json.Marshal(r)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
got := string(b)
|
|
|
|
for _, field := range []string{
|
|
`"host_id":"demo-host-01"`, `"reported_at":`, `"agent_version":"0.3.0"`,
|
|
`"cpu_percent":3.2`, `"memory_total_bytes":16777216000`, `"loadavg":["0.10","0.20","0.15"]`,
|
|
`"disk_percent":19.7`, `"uptime_seconds":86400`, `"cpu_temp_c":47`,
|
|
`"vmid":100`, `"controller_version":""`, `"memory_bytes":2147483648`,
|
|
`"cloudflared":{"status":"active"}`,
|
|
// empty collections must be [] not null
|
|
`"storage_targets":[]`, `"backups":[]`, `"restore_tests":[]`, `"pbs_snapshots":[]`, `"audit_tail":[]`,
|
|
`"capabilities":[]`,
|
|
} {
|
|
if !strings.Contains(got, field) {
|
|
t.Errorf("report JSON missing %s\n got: %s", field, got)
|
|
}
|
|
}
|
|
if strings.Contains(got, "null") {
|
|
t.Errorf("report JSON must not contain null (empty collections should be []): %s", got)
|
|
}
|
|
}
|
|
|
|
func TestGuest_SpecOmittedWhenUnknown(t *testing.T) {
|
|
b, _ := json.Marshal(Guest{VMID: 9, Name: "g", Status: "unknown"})
|
|
if strings.Contains(string(b), "spec") {
|
|
t.Errorf("unknown guest should omit spec, got %s", b)
|
|
}
|
|
}
|