package agentapi import ( "context" "errors" "net/http" "net/http/httptest" "strings" "testing" ) // R-856: GET /host/crash-guard decodes the crash guard's fields, and an agent that predates the route // surfaces as a typed 404 (the caller reads it as unknown → the normal boot grace). func TestR856_CrashGuardDecodesAndAnOlderAgentIs404(t *testing.T) { mux := http.NewServeMux() mux.HandleFunc("GET /host/crash-guard", func(w http.ResponseWriter, r *http.Request) { _, _ = w.Write([]byte(`{"ok":true,"data":{"present":true,"last_boot_at":"2026-10-04T12:00:00Z","last_boot_unclean":true,"tripped":false}}`)) }) s := httptest.NewTLSServer(mux) defer s.Close() c := clientFor(t, s, strings.TrimPrefix(s.URL, "https://")) st, err := c.CrashGuard(context.Background()) if err != nil { t.Fatal(err) } if !st.Present || !st.LastBootUnclean || st.LastBootAt != "2026-10-04T12:00:00Z" || st.Tripped { t.Fatalf("state = %+v", st) } old := httptest.NewTLSServer(http.NewServeMux()) defer old.Close() _, err = clientFor(t, old, strings.TrimPrefix(old.URL, "https://")).CrashGuard(context.Background()) var se *StatusError if !errors.As(err, &se) || se.Code != http.StatusNotFound { t.Fatalf("an older agent must answer a typed 404, got %v", err) } }