package stacks import ( "context" "go/ast" "go/parser" "go/token" "io" "log" "os" "path/filepath" "strings" "testing" "gitea.dooplex.hu/admin/felhom-controller/internal/config" "gopkg.in/yaml.v3" ) // Slice 3 (v0.235.0) — the pin, the stored definition, and adoption. const pinTplOld = "services:\n web:\n image: nextcloud:31.0.14-apache\n" const pinTplNew = "services:\n web:\n image: nextcloud:34.0.1-apache\n" // newPinManager builds a Manager with one deployed stack and a catalog cache. func newPinManager(t *testing.T, liveCompose, catalogCompose, appYAML string) (*Manager, string) { t.Helper() root := t.TempDir() cfg := &config.Config{} cfg.Paths.StacksDir = filepath.Join(root, "stacks") cfg.Paths.DataDir = filepath.Join(root, "data") stackDir := filepath.Join(cfg.Paths.StacksDir, "nextcloud") catDir := filepath.Join(cfg.Paths.DataDir, "catalog-cache", "templates", "nextcloud") for _, d := range []string{stackDir, catDir} { if err := os.MkdirAll(d, 0o755); err != nil { t.Fatal(err) } } mustWrite(t, filepath.Join(stackDir, "docker-compose.yml"), liveCompose) if catalogCompose != "" { mustWrite(t, filepath.Join(catDir, "docker-compose.yml"), catalogCompose) } mustWrite(t, filepath.Join(stackDir, "app.yaml"), appYAML) m := &Manager{ cfg: cfg, logger: log.New(io.Discard, "", 0), composeCmd: "docker compose", encKey: []byte("0123456789abcdef0123456789abcdef"), stacks: map[string]*Stack{}, } m.stacks["nextcloud"] = &Stack{ Name: "nextcloud", Deployed: true, ComposePath: filepath.Join(stackDir, "docker-compose.yml"), AppConfig: LoadAppConfig(stackDir), } return m, stackDir } func mustWrite(t *testing.T, path, body string) { t.Helper() if err := os.WriteFile(path, []byte(body), 0o644); err != nil { t.Fatal(err) } } func readPin(t *testing.T, dir string) *AppConfig { t.Helper() b, err := os.ReadFile(filepath.Join(dir, "app.yaml")) if err != nil { t.Fatal(err) } cfg := &AppConfig{} if err := yaml.Unmarshal(b, cfg); err != nil { t.Fatal(err) } return cfg } // --- GROUP D: the Update button advances the pin, BEFORE the pull --- // TestGroupD_UpdateAdvancesThePinAndRendersTheNewDefinition. // // The ordering is the assertion that matters: `compose pull` and `up -d` act on the file on disk, so // the catalog's definition has to BE that file before either runs. A pin set afterwards would pull // the frozen version and report success — a button that lies. func TestGroupD_UpdateAdvancesThePinAndRendersTheNewDefinition(t *testing.T) { m, stackDir := newPinManager(t, pinTplOld, pinTplNew, "deployed: true\nenv: {}\npinned_images:\n web: nextcloud:31.0.14-apache\n") mustWrite(t, AppliedComposePath(stackDir), pinTplOld) if err := m.advancePinToCatalog("nextcloud", stackDir); err != nil { t.Fatal(err) } if got := readPin(t, stackDir).PinnedImages["web"]; got != "nextcloud:34.0.1-apache" { t.Fatalf("pin = %q, want the catalog's current ref", got) } live, _ := os.ReadFile(filepath.Join(stackDir, "docker-compose.yml")) if !strings.Contains(string(live), "34.0.1-apache") { t.Fatalf("the LIVE compose file must carry the new definition BEFORE the pull:\n%s", live) } applied, _ := os.ReadFile(AppliedComposePath(stackDir)) if !strings.Contains(string(applied), "34.0.1-apache") { t.Fatalf("the new definition must be stored as the applied one:\n%s", applied) } } // TestGroupD_UpdateRefusesWhenTheCatalogCannotBeRead — a no-op reported as success is worse than a // refusal. An UNPINNED app is untouched and returns nil: that is pre-v0.235.0 behaviour. func TestGroupD_UpdateRefusesWhenTheCatalogCannotBeRead(t *testing.T) { m, stackDir := newPinManager(t, pinTplOld, "", // no catalog template at all "deployed: true\nenv: {}\npinned_images:\n web: nextcloud:31.0.14-apache\n") err := m.advancePinToCatalog("nextcloud", stackDir) if err == nil { t.Fatal("a pinned app whose catalog definition cannot be read must REFUSE, not silently no-op") } if !strings.Contains(err.Error(), "catalog") { t.Errorf("the refusal must name the cause, got: %v", err) } m2, dir2 := newPinManager(t, pinTplOld, "", "deployed: true\nenv: {}\n") // unpinned if err := m2.advancePinToCatalog("nextcloud", dir2); err != nil { t.Fatalf("an UNPINNED app must be left alone and succeed: %v", err) } } // --- GROUP E: adoption never guesses --- // TestGroupE_AdoptionSkipsWhatItCannotPinConfidently. // // COMPANION RED-PROOF 2 (run 2026-09-06): delete the observationCoversTemplate guard from AdoptPins // so it pins from whatever it observed. The "incomplete observation" sub-test then fails with a pin // written from a partial reading. Reverted. func TestGroupE_AdoptionSkipsWhatItCannotPinConfidently(t *testing.T) { twoSvc := "services:\n web:\n image: nextcloud:31.0.14-apache\n db:\n image: postgres:16-alpine\n" t.Run("incomplete observation", func(t *testing.T) { m, stackDir := newPinManager(t, twoSvc, twoSvc, `deployed: true env: {} installed_images: web: ref: nextcloud:31.0.14-apache digest: sha256:a at: "2026-09-01T00:00:00Z" `) m.stacks["nextcloud"].AppConfig = LoadAppConfig(stackDir) if n := m.AdoptPins(); n != 0 { t.Fatalf("pinned %d, want 0 — only 1 of 2 services was observed", n) } if got := readPin(t, stackDir).PinnedImages; len(got) != 0 { t.Fatalf("no pin may be synthesised from a partial observation, got %+v", got) } }) t.Run("complete but running something the template no longer offers", func(t *testing.T) { m, stackDir := newPinManager(t, pinTplNew, pinTplNew, `deployed: true env: {} installed_images: web: ref: nextcloud:31.0.14-apache digest: sha256:a at: "2026-09-01T00:00:00Z" `) m.stacks["nextcloud"].AppConfig = LoadAppConfig(stackDir) if n := m.AdoptPins(); n != 0 { t.Fatalf("pinned %d, want 0 — we have no stored definition for what it runs", n) } if got := readPin(t, stackDir).PinnedImages; len(got) != 0 { t.Fatalf("no pin may be invented here, got %+v", got) } if _, err := os.Stat(AppliedComposePath(stackDir)); err == nil { t.Fatal("no applied definition may be manufactured by substituting refs into a newer template") } }) t.Run("complete and matching — pinned, with the definition stored", func(t *testing.T) { m, stackDir := newPinManager(t, pinTplOld, pinTplOld, `deployed: true env: {} installed_images: web: ref: nextcloud:31.0.14-apache digest: sha256:a at: "2026-09-01T00:00:00Z" `) m.stacks["nextcloud"].AppConfig = LoadAppConfig(stackDir) if n := m.AdoptPins(); n != 1 { t.Fatalf("pinned %d, want 1", n) } if got := readPin(t, stackDir).PinnedImages["web"]; got != "nextcloud:31.0.14-apache" { t.Fatalf("pin = %q", got) } stored, err := LoadAppliedDefinition(stackDir) if err != nil || !strings.Contains(string(stored), "31.0.14-apache") { t.Fatalf("the running definition must be stored: %v %s", err, stored) } // Idempotent: a second pass must not re-pin. if n := m.AdoptPins(); n != 0 { t.Errorf("a second adoption pass pinned %d, want 0", n) } }) } // TestGroupE_AdoptionTouchesNoContainer — it reads and writes files only. func TestGroupE_AdoptionTouchesNoContainer(t *testing.T) { m, stackDir := newPinManager(t, pinTplOld, pinTplOld, `deployed: true env: {} installed_images: web: ref: nextcloud:31.0.14-apache digest: sha256:a at: "2026-09-01T00:00:00Z" `) m.stacks["nextcloud"].AppConfig = LoadAppConfig(stackDir) m.installedExecFn = func(context.Context, string, []string, string, ...string) (string, error) { t.Fatal("adoption must not run any docker command") return "", nil } m.execFn = func(string, ...string) (string, error) { t.Fatal("adoption must not run any docker command") return "", nil } m.AdoptPins() } // --- GROUP F: a restore's pin survives, and RenderPlanFor reports it --- // TestGroupF_RestorePinIsReportedToTheSyncer is the unit half of R-441. The live half is the // measurement in the report; this pins the contract the syncer relies on. func TestGroupF_RestorePinIsReportedToTheSyncer(t *testing.T) { m, stackDir := newPinManager(t, pinTplOld, pinTplNew, "deployed: true\nenv: {}\n") // What RecreateStackDefinitionFromUnit does: the unit's compose is already in the stack dir. pin, data, err := PinFromCompose(ComposePathIn(stackDir)) if err != nil { t.Fatal(err) } if err := m.SetPin("nextcloud", stackDir, pin, data); err != nil { t.Fatal(err) } plan := m.RenderPlanFor("nextcloud") if !plan.Deployed || len(plan.Pinned) == 0 { t.Fatalf("the syncer must be told the app is deployed and pinned: %+v", plan) } if plan.Pinned["web"] != "nextcloud:31.0.14-apache" { t.Errorf("pin = %q, want the unit's captured image", plan.Pinned["web"]) } if plan.AppliedPath == "" { t.Fatal("the stored definition must be reported, or the syncer cannot freeze and the catalog wins in 15 minutes (R-441)") } } // TestSetPin_EmptyPinAndMissingAppYAMLAreRefusedOrNoOps. func TestSetPin_EmptyPinAndMissingAppYAMLAreRefusedOrNoOps(t *testing.T) { m, stackDir := newPinManager(t, pinTplOld, pinTplOld, "deployed: true\nenv: {}\n") if err := m.SetPin("nextcloud", stackDir, map[string]string{}, []byte(pinTplOld)); err == nil { t.Error("an empty pin must be refused — it would read as UNPINNED and silently unfreeze the app") } if err := StoreAppliedDefinition(stackDir, nil); err == nil { t.Error("an empty applied definition must be refused") } } // TestSetPin_UnchangedPinDoesNotRewriteAppYAML — app.yaml holds encrypted secrets. func TestSetPin_UnchangedPinDoesNotRewriteAppYAML(t *testing.T) { m, stackDir := newPinManager(t, pinTplOld, pinTplOld, "deployed: true\nenv: {}\npinned_images:\n web: nextcloud:31.0.14-apache\n") p := filepath.Join(stackDir, "app.yaml") st0, _ := os.Stat(p) if err := m.SetPin("nextcloud", stackDir, map[string]string{"web": "nextcloud:31.0.14-apache"}, []byte(pinTplOld)); err != nil { t.Fatal(err) } st1, _ := os.Stat(p) if !st0.ModTime().Equal(st1.ModTime()) || st0.Size() != st1.Size() { t.Error("an unchanged pin must not rewrite app.yaml") } } // --- GROUP H: the wiring --- // TestGroupH_RenderSeamAndAdoptionAreWiredAtStartup. // // The render is INERT unless main.go passes the function, and adoption is inert unless it is called. // An AST walk, NOT a strings.Contains: a commented-out call still contains the string, which is the // exact shape of the seam-built-but-never-wired class this project has shipped four times. // // It also asserts the ORDER, which is load-bearing: syncer.Start() fires an immediate sync, and if // that runs before adoption every app is still unpinned, so the first sync of every boot would copy // the catalog verbatim over a deployed app — the behaviour this release removes, once per boot. func TestGroupH_RenderSeamAndAdoptionAreWiredAtStartup(t *testing.T) { src := filepath.Join("..", "..", "cmd", "controller", "main.go") fset := token.NewFileSet() f, err := parser.ParseFile(fset, src, nil, 0) if err != nil { t.Skipf("cmd/controller is gitignored in some checkouts: %v", err) } var seamLine, adoptLine, startLine, backfillLine int ast.Inspect(f, func(n ast.Node) bool { call, ok := n.(*ast.CallExpr) if !ok { return true } sel, ok := call.Fun.(*ast.SelectorExpr) if !ok { return true } line := fset.Position(call.Pos()).Line switch sel.Sel.Name { case "SetRenderPlanFn": seamLine = line case "AdoptPins": adoptLine = line case "BackfillInstalledImages": backfillLine = line case "Start": if id, ok := sel.X.(*ast.Ident); ok && id.Name == "syncer" { startLine = line } } return true }) if seamLine == 0 { t.Fatal("SetRenderPlanFn is never called from cmd/controller — the render is INERT and the syncer copies verbatim") } if adoptLine == 0 { t.Fatal("AdoptPins is never called from cmd/controller — nothing would ever be pinned") } if backfillLine != 0 && adoptLine < backfillLine { t.Errorf("adoption (line %d) must run AFTER the installed-images backfill (line %d) — it needs that observation", adoptLine, backfillLine) } if startLine == 0 { t.Fatal("syncer.Start() is never called") } if startLine < adoptLine { t.Errorf("syncer.Start() (line %d) must come AFTER AdoptPins (line %d): the initial sync would otherwise run while every app is unpinned and overwrite a deployed app's version once per boot", startLine, adoptLine) } }