6ab1e7c56c
gates / gates (push) Successful in 20s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
86 lines
3.1 KiB
Go
86 lines
3.1 KiB
Go
package localapi
|
|
|
|
import (
|
|
"context"
|
|
"io"
|
|
"os"
|
|
"path/filepath"
|
|
"testing"
|
|
)
|
|
|
|
// R-861 (agent v0.146.0): the shared-parent boot script and unit arrive with the signed config bundle; the agent never
|
|
// installs them. It checks them and enables the unit when nothing has.
|
|
//
|
|
// RED-PROOF (audits/hub-safety-2026-10-05/partF/red-proof.txt): put the old installSharedParentUnit call back (an
|
|
// `install` of a /tmp file) → TestSharedParentBoot_NeverInstalls fails.
|
|
|
|
type callRecorder struct{ calls [][]string }
|
|
|
|
func (r *callRecorder) Run(_ context.Context, name string, args ...string) ([]byte, []byte, error) {
|
|
r.calls = append(r.calls, append([]string{name}, args...))
|
|
return nil, nil, nil
|
|
}
|
|
|
|
func (r *callRecorder) RunStdin(ctx context.Context, _ io.Reader, name string, args ...string) ([]byte, []byte, error) {
|
|
return r.Run(ctx, name, args...)
|
|
}
|
|
|
|
func bootFiles(t *testing.T, script, unit string) (string, string, string) {
|
|
t.Helper()
|
|
d := t.TempDir()
|
|
sp, up := filepath.Join(d, "felhom-shared-parent.sh"), filepath.Join(d, "felhom-shared-parent.service")
|
|
if script != "" {
|
|
_ = os.WriteFile(sp, []byte(script), 0o755)
|
|
}
|
|
if unit != "" {
|
|
_ = os.WriteFile(up, []byte(unit), 0o644)
|
|
}
|
|
return sp, up, filepath.Join(d, "wants-link")
|
|
}
|
|
|
|
func TestSharedParentBoot_NeverInstalls(t *testing.T) {
|
|
for _, c := range []struct{ name, script, unit string }{
|
|
{"both missing", "", ""},
|
|
{"script differs", "#!/bin/sh\necho old\n", sharedParentUnit},
|
|
{"unit missing", sharedParentScript, ""},
|
|
} {
|
|
r := &callRecorder{}
|
|
b := NewGuestBinder(r, nil)
|
|
sp, up, link := bootFiles(t, c.script, c.unit)
|
|
if err := b.ensureSharedParentBoot(context.Background(), up, sp, link); err == nil {
|
|
t.Errorf("%s: no error — the operator would not learn the bundle is missing", c.name)
|
|
}
|
|
if len(r.calls) != 0 {
|
|
t.Errorf("%s: the agent ran %v — it must install nothing (R-861)", c.name, r.calls)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestSharedParentBoot_EnablesOnceTheBundleBroughtTheFiles(t *testing.T) {
|
|
r := &callRecorder{}
|
|
b := NewGuestBinder(r, nil)
|
|
sp, up, link := bootFiles(t, sharedParentScript, sharedParentUnit)
|
|
if err := b.ensureSharedParentBoot(context.Background(), up, sp, link); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if len(r.calls) != 1 || len(r.calls[0]) != 3 || r.calls[0][0] != "systemctl" || r.calls[0][1] != "enable" ||
|
|
r.calls[0][2] != "felhom-shared-parent.service" {
|
|
t.Fatalf("want exactly `systemctl enable felhom-shared-parent.service`, got %v", r.calls)
|
|
}
|
|
_ = os.Symlink(up, link)
|
|
r.calls = nil
|
|
if err := b.ensureSharedParentBoot(context.Background(), up, sp, link); err != nil || len(r.calls) != 0 {
|
|
t.Fatalf("already enabled: want no calls, got %v (%v)", r.calls, err)
|
|
}
|
|
}
|
|
|
|
// The bundle's copies are byte-identical to the constants the agent compares against.
|
|
func TestSharedParentFilesEqualTheBundle(t *testing.T) {
|
|
for file, want := range map[string]string{"felhom-shared-parent.sh": sharedParentScript, "felhom-shared-parent.service": sharedParentUnit} {
|
|
got, err := os.ReadFile(filepath.Join("..", "..", "configs", file))
|
|
if err != nil || string(got) != want {
|
|
t.Errorf("configs/%s differs from the agent's constant (err %v)", file, err)
|
|
}
|
|
}
|
|
}
|