8a0e0a59ad
gates / gates (push) Successful in 12s
Slice 3. R-447 was BLOCKED because R-438 established that RestartStack's use of up -d to pick up template changes was CHOSEN and written down in its own comment. The operator ruled Option 1, and this implements it. The rule: while the catalog offers the same version you run, its fixes flow to you; the moment it moves to a newer version you are frozen until you update. NOTHING was added to any of the thirteen compose up -d call sites. Most of them are repairs - the boot reconciler, the drive-return gate, the app-stop guard - and a repair path that refuses to repair leaves a customer's app down, which is worse than the problem. They are made safe by removing the reason. app.yaml gains pinned_images: what the app is SUPPOSED to run. It is NOT installed_images, which is an observation; letting a reading become a deployment is the R-166 category error one field over. Four writers, each also storing the exact definition as applied-compose.yml. UpdateStack advances the pin and re-renders BEFORE the pull, because pull and up -d act on the file on disk, and a pin set afterwards would pull the frozen version and report success. The syncer renders instead of copying, through one nil-safe seam. Catalog images equal the pin -> verbatim, so fixes and self-healing both survive; they differ -> the WHOLE stored definition, never a substitution of refs into a newer template (wger 2.6 needs a DB config the older template cannot supply). This is deliberately not 'skip deployed apps', which was option B and was rejected. AdoptPins runs once at boot after the backfill, files only, and skips loudly rather than inventing a pin. syncer.Start() moved to after it: the initial sync would otherwise run while every app was unpinned and overwrite a deployed app's version once per boot. THE BADGE HAD TO CHANGE OR SLICE 2 WOULD HAVE INVERTED SILENTLY. TemplateImages reads the LIVE compose file, which is now the frozen one, so the comparison would have answered Naprakesz on exactly the apps that are behind - with every test green, because the new field has the same type. It now reads CatalogImages. +16 tests (1729 -> 1745), 28 packages green. Three red-proofs run and reverted. A test also caught the syncer writing an empty compose file over a live app.
335 lines
12 KiB
Go
335 lines
12 KiB
Go
package stacks
|
|
|
|
import (
|
|
"context"
|
|
"go/ast"
|
|
"go/parser"
|
|
"go/token"
|
|
"io"
|
|
"log"
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
"testing"
|
|
|
|
"gitea.dooplex.hu/admin/felhom-controller/internal/config"
|
|
"gopkg.in/yaml.v3"
|
|
)
|
|
|
|
// Slice 3 (v0.235.0) — the pin, the stored definition, and adoption.
|
|
|
|
const pinTplOld = "services:\n web:\n image: nextcloud:31.0.14-apache\n"
|
|
const pinTplNew = "services:\n web:\n image: nextcloud:34.0.1-apache\n"
|
|
|
|
// newPinManager builds a Manager with one deployed stack and a catalog cache.
|
|
func newPinManager(t *testing.T, liveCompose, catalogCompose, appYAML string) (*Manager, string) {
|
|
t.Helper()
|
|
root := t.TempDir()
|
|
cfg := &config.Config{}
|
|
cfg.Paths.StacksDir = filepath.Join(root, "stacks")
|
|
cfg.Paths.DataDir = filepath.Join(root, "data")
|
|
stackDir := filepath.Join(cfg.Paths.StacksDir, "nextcloud")
|
|
catDir := filepath.Join(cfg.Paths.DataDir, "catalog-cache", "templates", "nextcloud")
|
|
for _, d := range []string{stackDir, catDir} {
|
|
if err := os.MkdirAll(d, 0o755); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
}
|
|
mustWrite(t, filepath.Join(stackDir, "docker-compose.yml"), liveCompose)
|
|
if catalogCompose != "" {
|
|
mustWrite(t, filepath.Join(catDir, "docker-compose.yml"), catalogCompose)
|
|
}
|
|
mustWrite(t, filepath.Join(stackDir, "app.yaml"), appYAML)
|
|
|
|
m := &Manager{
|
|
cfg: cfg, logger: log.New(io.Discard, "", 0), composeCmd: "docker compose",
|
|
encKey: []byte("0123456789abcdef0123456789abcdef"),
|
|
stacks: map[string]*Stack{},
|
|
}
|
|
m.stacks["nextcloud"] = &Stack{
|
|
Name: "nextcloud", Deployed: true,
|
|
ComposePath: filepath.Join(stackDir, "docker-compose.yml"),
|
|
AppConfig: LoadAppConfig(stackDir),
|
|
}
|
|
return m, stackDir
|
|
}
|
|
|
|
func mustWrite(t *testing.T, path, body string) {
|
|
t.Helper()
|
|
if err := os.WriteFile(path, []byte(body), 0o644); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
}
|
|
|
|
func readPin(t *testing.T, dir string) *AppConfig {
|
|
t.Helper()
|
|
b, err := os.ReadFile(filepath.Join(dir, "app.yaml"))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
cfg := &AppConfig{}
|
|
if err := yaml.Unmarshal(b, cfg); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
return cfg
|
|
}
|
|
|
|
// --- GROUP D: the Update button advances the pin, BEFORE the pull ---
|
|
|
|
// TestGroupD_UpdateAdvancesThePinAndRendersTheNewDefinition.
|
|
//
|
|
// The ordering is the assertion that matters: `compose pull` and `up -d` act on the file on disk, so
|
|
// the catalog's definition has to BE that file before either runs. A pin set afterwards would pull
|
|
// the frozen version and report success — a button that lies.
|
|
func TestGroupD_UpdateAdvancesThePinAndRendersTheNewDefinition(t *testing.T) {
|
|
m, stackDir := newPinManager(t, pinTplOld, pinTplNew,
|
|
"deployed: true\nenv: {}\npinned_images:\n web: nextcloud:31.0.14-apache\n")
|
|
mustWrite(t, AppliedComposePath(stackDir), pinTplOld)
|
|
|
|
if err := m.advancePinToCatalog("nextcloud", stackDir); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if got := readPin(t, stackDir).PinnedImages["web"]; got != "nextcloud:34.0.1-apache" {
|
|
t.Fatalf("pin = %q, want the catalog's current ref", got)
|
|
}
|
|
live, _ := os.ReadFile(filepath.Join(stackDir, "docker-compose.yml"))
|
|
if !strings.Contains(string(live), "34.0.1-apache") {
|
|
t.Fatalf("the LIVE compose file must carry the new definition BEFORE the pull:\n%s", live)
|
|
}
|
|
applied, _ := os.ReadFile(AppliedComposePath(stackDir))
|
|
if !strings.Contains(string(applied), "34.0.1-apache") {
|
|
t.Fatalf("the new definition must be stored as the applied one:\n%s", applied)
|
|
}
|
|
}
|
|
|
|
// TestGroupD_UpdateRefusesWhenTheCatalogCannotBeRead — a no-op reported as success is worse than a
|
|
// refusal. An UNPINNED app is untouched and returns nil: that is pre-v0.235.0 behaviour.
|
|
func TestGroupD_UpdateRefusesWhenTheCatalogCannotBeRead(t *testing.T) {
|
|
m, stackDir := newPinManager(t, pinTplOld, "", // no catalog template at all
|
|
"deployed: true\nenv: {}\npinned_images:\n web: nextcloud:31.0.14-apache\n")
|
|
err := m.advancePinToCatalog("nextcloud", stackDir)
|
|
if err == nil {
|
|
t.Fatal("a pinned app whose catalog definition cannot be read must REFUSE, not silently no-op")
|
|
}
|
|
if !strings.Contains(err.Error(), "catalog") {
|
|
t.Errorf("the refusal must name the cause, got: %v", err)
|
|
}
|
|
|
|
m2, dir2 := newPinManager(t, pinTplOld, "", "deployed: true\nenv: {}\n") // unpinned
|
|
if err := m2.advancePinToCatalog("nextcloud", dir2); err != nil {
|
|
t.Fatalf("an UNPINNED app must be left alone and succeed: %v", err)
|
|
}
|
|
}
|
|
|
|
// --- GROUP E: adoption never guesses ---
|
|
|
|
// TestGroupE_AdoptionSkipsWhatItCannotPinConfidently.
|
|
//
|
|
// COMPANION RED-PROOF 2 (run 2026-09-06): delete the observationCoversTemplate guard from AdoptPins
|
|
// so it pins from whatever it observed. The "incomplete observation" sub-test then fails with a pin
|
|
// written from a partial reading. Reverted.
|
|
func TestGroupE_AdoptionSkipsWhatItCannotPinConfidently(t *testing.T) {
|
|
twoSvc := "services:\n web:\n image: nextcloud:31.0.14-apache\n db:\n image: postgres:16-alpine\n"
|
|
|
|
t.Run("incomplete observation", func(t *testing.T) {
|
|
m, stackDir := newPinManager(t, twoSvc, twoSvc, `deployed: true
|
|
env: {}
|
|
installed_images:
|
|
web:
|
|
ref: nextcloud:31.0.14-apache
|
|
digest: sha256:a
|
|
at: "2026-09-01T00:00:00Z"
|
|
`)
|
|
m.stacks["nextcloud"].AppConfig = LoadAppConfig(stackDir)
|
|
if n := m.AdoptPins(); n != 0 {
|
|
t.Fatalf("pinned %d, want 0 — only 1 of 2 services was observed", n)
|
|
}
|
|
if got := readPin(t, stackDir).PinnedImages; len(got) != 0 {
|
|
t.Fatalf("no pin may be synthesised from a partial observation, got %+v", got)
|
|
}
|
|
})
|
|
|
|
t.Run("complete but running something the template no longer offers", func(t *testing.T) {
|
|
m, stackDir := newPinManager(t, pinTplNew, pinTplNew, `deployed: true
|
|
env: {}
|
|
installed_images:
|
|
web:
|
|
ref: nextcloud:31.0.14-apache
|
|
digest: sha256:a
|
|
at: "2026-09-01T00:00:00Z"
|
|
`)
|
|
m.stacks["nextcloud"].AppConfig = LoadAppConfig(stackDir)
|
|
if n := m.AdoptPins(); n != 0 {
|
|
t.Fatalf("pinned %d, want 0 — we have no stored definition for what it runs", n)
|
|
}
|
|
if got := readPin(t, stackDir).PinnedImages; len(got) != 0 {
|
|
t.Fatalf("no pin may be invented here, got %+v", got)
|
|
}
|
|
if _, err := os.Stat(AppliedComposePath(stackDir)); err == nil {
|
|
t.Fatal("no applied definition may be manufactured by substituting refs into a newer template")
|
|
}
|
|
})
|
|
|
|
t.Run("complete and matching — pinned, with the definition stored", func(t *testing.T) {
|
|
m, stackDir := newPinManager(t, pinTplOld, pinTplOld, `deployed: true
|
|
env: {}
|
|
installed_images:
|
|
web:
|
|
ref: nextcloud:31.0.14-apache
|
|
digest: sha256:a
|
|
at: "2026-09-01T00:00:00Z"
|
|
`)
|
|
m.stacks["nextcloud"].AppConfig = LoadAppConfig(stackDir)
|
|
if n := m.AdoptPins(); n != 1 {
|
|
t.Fatalf("pinned %d, want 1", n)
|
|
}
|
|
if got := readPin(t, stackDir).PinnedImages["web"]; got != "nextcloud:31.0.14-apache" {
|
|
t.Fatalf("pin = %q", got)
|
|
}
|
|
stored, err := LoadAppliedDefinition(stackDir)
|
|
if err != nil || !strings.Contains(string(stored), "31.0.14-apache") {
|
|
t.Fatalf("the running definition must be stored: %v %s", err, stored)
|
|
}
|
|
// Idempotent: a second pass must not re-pin.
|
|
if n := m.AdoptPins(); n != 0 {
|
|
t.Errorf("a second adoption pass pinned %d, want 0", n)
|
|
}
|
|
})
|
|
}
|
|
|
|
// TestGroupE_AdoptionTouchesNoContainer — it reads and writes files only.
|
|
func TestGroupE_AdoptionTouchesNoContainer(t *testing.T) {
|
|
m, stackDir := newPinManager(t, pinTplOld, pinTplOld, `deployed: true
|
|
env: {}
|
|
installed_images:
|
|
web:
|
|
ref: nextcloud:31.0.14-apache
|
|
digest: sha256:a
|
|
at: "2026-09-01T00:00:00Z"
|
|
`)
|
|
m.stacks["nextcloud"].AppConfig = LoadAppConfig(stackDir)
|
|
m.installedExecFn = func(context.Context, string, []string, string, ...string) (string, error) {
|
|
t.Fatal("adoption must not run any docker command")
|
|
return "", nil
|
|
}
|
|
m.execFn = func(string, ...string) (string, error) {
|
|
t.Fatal("adoption must not run any docker command")
|
|
return "", nil
|
|
}
|
|
m.AdoptPins()
|
|
}
|
|
|
|
// --- GROUP F: a restore's pin survives, and RenderPlanFor reports it ---
|
|
|
|
// TestGroupF_RestorePinIsReportedToTheSyncer is the unit half of R-441. The live half is the
|
|
// measurement in the report; this pins the contract the syncer relies on.
|
|
func TestGroupF_RestorePinIsReportedToTheSyncer(t *testing.T) {
|
|
m, stackDir := newPinManager(t, pinTplOld, pinTplNew, "deployed: true\nenv: {}\n")
|
|
|
|
// What RecreateStackDefinitionFromUnit does: the unit's compose is already in the stack dir.
|
|
pin, data, err := PinFromCompose(ComposePathIn(stackDir))
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if err := m.SetPin("nextcloud", stackDir, pin, data); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
|
|
plan := m.RenderPlanFor("nextcloud")
|
|
if !plan.Deployed || len(plan.Pinned) == 0 {
|
|
t.Fatalf("the syncer must be told the app is deployed and pinned: %+v", plan)
|
|
}
|
|
if plan.Pinned["web"] != "nextcloud:31.0.14-apache" {
|
|
t.Errorf("pin = %q, want the unit's captured image", plan.Pinned["web"])
|
|
}
|
|
if plan.AppliedPath == "" {
|
|
t.Fatal("the stored definition must be reported, or the syncer cannot freeze and the catalog wins in 15 minutes (R-441)")
|
|
}
|
|
}
|
|
|
|
// TestSetPin_EmptyPinAndMissingAppYAMLAreRefusedOrNoOps.
|
|
func TestSetPin_EmptyPinAndMissingAppYAMLAreRefusedOrNoOps(t *testing.T) {
|
|
m, stackDir := newPinManager(t, pinTplOld, pinTplOld, "deployed: true\nenv: {}\n")
|
|
if err := m.SetPin("nextcloud", stackDir, map[string]string{}, []byte(pinTplOld)); err == nil {
|
|
t.Error("an empty pin must be refused — it would read as UNPINNED and silently unfreeze the app")
|
|
}
|
|
if err := StoreAppliedDefinition(stackDir, nil); err == nil {
|
|
t.Error("an empty applied definition must be refused")
|
|
}
|
|
}
|
|
|
|
// TestSetPin_UnchangedPinDoesNotRewriteAppYAML — app.yaml holds encrypted secrets.
|
|
func TestSetPin_UnchangedPinDoesNotRewriteAppYAML(t *testing.T) {
|
|
m, stackDir := newPinManager(t, pinTplOld, pinTplOld,
|
|
"deployed: true\nenv: {}\npinned_images:\n web: nextcloud:31.0.14-apache\n")
|
|
p := filepath.Join(stackDir, "app.yaml")
|
|
st0, _ := os.Stat(p)
|
|
if err := m.SetPin("nextcloud", stackDir, map[string]string{"web": "nextcloud:31.0.14-apache"}, []byte(pinTplOld)); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
st1, _ := os.Stat(p)
|
|
if !st0.ModTime().Equal(st1.ModTime()) || st0.Size() != st1.Size() {
|
|
t.Error("an unchanged pin must not rewrite app.yaml")
|
|
}
|
|
}
|
|
|
|
// --- GROUP H: the wiring ---
|
|
|
|
// TestGroupH_RenderSeamAndAdoptionAreWiredAtStartup.
|
|
//
|
|
// The render is INERT unless main.go passes the function, and adoption is inert unless it is called.
|
|
// An AST walk, NOT a strings.Contains: a commented-out call still contains the string, which is the
|
|
// exact shape of the seam-built-but-never-wired class this project has shipped four times.
|
|
//
|
|
// It also asserts the ORDER, which is load-bearing: syncer.Start() fires an immediate sync, and if
|
|
// that runs before adoption every app is still unpinned, so the first sync of every boot would copy
|
|
// the catalog verbatim over a deployed app — the behaviour this release removes, once per boot.
|
|
func TestGroupH_RenderSeamAndAdoptionAreWiredAtStartup(t *testing.T) {
|
|
src := filepath.Join("..", "..", "cmd", "controller", "main.go")
|
|
fset := token.NewFileSet()
|
|
f, err := parser.ParseFile(fset, src, nil, 0)
|
|
if err != nil {
|
|
t.Skipf("cmd/controller is gitignored in some checkouts: %v", err)
|
|
}
|
|
var seamLine, adoptLine, startLine, backfillLine int
|
|
ast.Inspect(f, func(n ast.Node) bool {
|
|
call, ok := n.(*ast.CallExpr)
|
|
if !ok {
|
|
return true
|
|
}
|
|
sel, ok := call.Fun.(*ast.SelectorExpr)
|
|
if !ok {
|
|
return true
|
|
}
|
|
line := fset.Position(call.Pos()).Line
|
|
switch sel.Sel.Name {
|
|
case "SetRenderPlanFn":
|
|
seamLine = line
|
|
case "AdoptPins":
|
|
adoptLine = line
|
|
case "BackfillInstalledImages":
|
|
backfillLine = line
|
|
case "Start":
|
|
if id, ok := sel.X.(*ast.Ident); ok && id.Name == "syncer" {
|
|
startLine = line
|
|
}
|
|
}
|
|
return true
|
|
})
|
|
if seamLine == 0 {
|
|
t.Fatal("SetRenderPlanFn is never called from cmd/controller — the render is INERT and the syncer copies verbatim")
|
|
}
|
|
if adoptLine == 0 {
|
|
t.Fatal("AdoptPins is never called from cmd/controller — nothing would ever be pinned")
|
|
}
|
|
if backfillLine != 0 && adoptLine < backfillLine {
|
|
t.Errorf("adoption (line %d) must run AFTER the installed-images backfill (line %d) — it needs that observation", adoptLine, backfillLine)
|
|
}
|
|
if startLine == 0 {
|
|
t.Fatal("syncer.Start() is never called")
|
|
}
|
|
if startLine < adoptLine {
|
|
t.Errorf("syncer.Start() (line %d) must come AFTER AdoptPins (line %d): the initial sync would otherwise run while every app is unpinned and overwrite a deployed app's version once per boot", startLine, adoptLine)
|
|
}
|
|
}
|