ce1a4b4758
The wrapper gains layer "pve" (slow lane): the host's Proxmox userspace packages only — origin "Proxmox Debian Repository", never a kernel / boot / firmware / microcode name (R14), no removal, no undo, a new package only from an allow-list; authority = a signed os_pve_step or the root-owned ring-0 mark. The night leg runs it in ring 0 after a healthy host step; ring 1 only by a signed job (PVEStepExecutor). While it runs, the agent's own /etc/pve writes (every non-GET API call, pct config verbs, pvesm, pveum, felhom-pbs-apply) wait on internal/pvegate. Health = the host rule + unchanged container ids + pveversion reads the installed pve-manager. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
93 lines
3.2 KiB
Go
93 lines
3.2 KiB
Go
package proxmox
|
|
|
|
import (
|
|
"context"
|
|
"net/http"
|
|
"testing"
|
|
"time"
|
|
|
|
"gitea.dooplex.hu/admin/felhom-agent/internal/pvegate"
|
|
)
|
|
|
|
// R-812 option A: while a Proxmox package step holds the gate, a non-GET API call waits and a GET does not.
|
|
//
|
|
// COMPANION RED-PROOF (observed): delete the pvegate.Write block in doBody → this fails with "a PUT reached the API
|
|
// while the Proxmox step held the gate". Restored. (audits/day-2026-10-07/B/red-pvegate-chokepoints.txt)
|
|
func TestPVEGate_ClientWriteWaitsGetDoesNot(t *testing.T) {
|
|
d := &mockDoer{fn: func(*http.Request) (*http.Response, error) { return jsonResp(200, `{"data":null}`), nil }}
|
|
c := newTestClient(d)
|
|
end, err := pvegate.Step(context.Background())
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if err := c.get(context.Background(), "/nodes", nil); err != nil {
|
|
t.Fatalf("a GET must not wait on the gate: %v", err)
|
|
}
|
|
if d.calls != 1 {
|
|
t.Fatalf("the GET must reach the API, calls=%d", d.calls)
|
|
}
|
|
ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond)
|
|
defer cancel()
|
|
err = c.postForm(ctx, http.MethodPut, "/nodes/x/lxc/9201/config", nil, nil)
|
|
if d.calls != 1 {
|
|
end()
|
|
t.Fatal("a PUT reached the API while the Proxmox step held the gate")
|
|
}
|
|
if err == nil {
|
|
end()
|
|
t.Fatal("a PUT held back past its deadline must fail")
|
|
}
|
|
end()
|
|
if err := c.postForm(context.Background(), http.MethodPut, "/nodes/x/lxc/9201/config", nil, nil); err != nil || d.calls != 2 {
|
|
t.Fatalf("after the step the PUT must go through (err=%v calls=%d)", err, d.calls)
|
|
}
|
|
}
|
|
|
|
// A root `pct set` waits on the gate; `pct exec` does not.
|
|
//
|
|
// COMPANION RED-PROOF (observed): delete the WritesEtcPVE block in RunStdin → this fails with "pct set ran while the
|
|
// Proxmox step held the gate". Restored.
|
|
func TestPVEGate_ExecRunnerPctSetWaits(t *testing.T) {
|
|
r := &ExecRunner{Mode: RunnerDirect}
|
|
end, err := pvegate.Step(context.Background())
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
defer end()
|
|
ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond)
|
|
defer cancel()
|
|
start := time.Now()
|
|
_, _, err = r.Run(ctx, "/nonexistent/pct", "set", "9201", "-mp8", "/x")
|
|
if err == nil || time.Since(start) < 90*time.Millisecond {
|
|
t.Fatalf("pct set ran while the Proxmox step held the gate (err=%v after %s)", err, time.Since(start))
|
|
}
|
|
start = time.Now()
|
|
_, _, _ = r.Run(context.Background(), "/nonexistent/pct", "exec", "9201", "--", "true")
|
|
if time.Since(start) > 80*time.Millisecond {
|
|
t.Fatal("pct exec must not wait on the gate")
|
|
}
|
|
}
|
|
|
|
func TestWritesEtcPVE(t *testing.T) {
|
|
for _, c := range []struct {
|
|
name string
|
|
args []string
|
|
want bool
|
|
}{
|
|
{"pct", []string{"set", "9201", "-mp8", "x"}, true},
|
|
{"/usr/sbin/pct", []string{"create", "9201"}, true},
|
|
{"pct", []string{"exec", "9201", "--", "true"}, false},
|
|
{"pct", []string{"status", "9201"}, false},
|
|
{"pvesm", []string{"add", "dir", "x"}, true},
|
|
{"pveum", []string{"acl", "modify"}, true},
|
|
{"/usr/local/sbin/felhom-pbs-apply", []string{"reconcile"}, true},
|
|
{"/usr/local/sbin/felhom-pbs-apply", []string{"read"}, false},
|
|
{"/usr/local/sbin/felhom-os-apply", []string{"--plan", "x"}, false},
|
|
{"pct", nil, false},
|
|
} {
|
|
if got := WritesEtcPVE(c.name, c.args); got != c.want {
|
|
t.Errorf("WritesEtcPVE(%s %v) = %v, want %v", c.name, c.args, got, c.want)
|
|
}
|
|
}
|
|
}
|