7465713a2f
v0.129.0: CAMPAIGN-4 fixes — rate-limiter key (F-B) + volume-blind estimate (F-A) + no-op claim status (F-C) F-B (MED, security): shared clientIP(r) helper (XFF first-hop, else SplitHostPort host, else raw) replaces requestIP + the duplicated inline derivation in handleLogin, so login AND escrow re-auth key on the port-stripped host IP — distinct direct connections no longer evade the failed-attempt counter. XFF-trust out of scope (commented). F-A (MED, honesty): volumeSizer seam reads volume size from a container view (docker run --rm -v vol:/vol:ro alpine du -sb /vol), replacing the host-path du that returned 0 inside the containerized controller. Failed read -> size_unknown + fits_on_dest forced false (never "fits"). Export pre-flight hard-aborts only on a KNOWN doesn.t-fit. HDD branch unchanged. F-C (LOW-MED): escrowClaimAPIHandler relays agent 404 -> clean 404 and 409 -> 409; 410 and genuine-unreachable 502 unchanged (was: 404 fell through to 502). Tests + red-proofs: ratelimit_ip_test.go (F-B x6), estimate_volsize_test.go (F-A x3), TestEscrowClaim_ProxySemantics +3 (F-C). Alpine busybox du -sb verified prod-valid. Claude-Session: https://claude.ai/code/session_01LbMm4T7Ayzs1unB9pN6Uqd @
98 lines
3.3 KiB
Go
98 lines
3.3 KiB
Go
package appexport
|
|
|
|
import (
|
|
"errors"
|
|
"io"
|
|
"log"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// hddProvider is an rtProvider that reports an HDD-backed stack (for the regression scenario H).
|
|
type hddProvider struct {
|
|
*rtProvider
|
|
mounts []string
|
|
}
|
|
|
|
func (p *hddProvider) GetStackNeedsHDD(string) bool { return true }
|
|
func (p *hddProvider) GetStackHDDMounts(string) []string { return p.mounts }
|
|
|
|
func newEstimator(t *testing.T, provider ExportStackProvider) *Exporter {
|
|
t.Helper()
|
|
return NewExporter(provider, log.New(io.Discard, "", 0), "test")
|
|
}
|
|
|
|
// Scenario F (the F-A fix): a volume-only app with a >1 GiB volume reports the REAL size via the
|
|
// container-view sizer — not 0/"3.6 KB". This is the F-A red-proof anchor (revert EstimateExport to
|
|
// dockerVolumeSize → reads 0).
|
|
func TestEstimate_VolumeSize_RealNotZero(t *testing.T) {
|
|
const twoGiB = int64(2) << 30
|
|
orig := volumeSizer
|
|
volumeSizer = func(vol string) (int64, error) { return twoGiB, nil }
|
|
defer func() { volumeSizer = orig }()
|
|
|
|
e := newEstimator(t, &rtProvider{stackDir: t.TempDir(), volumes: []string{"app_data"}})
|
|
est, err := e.EstimateExport("app", t.TempDir())
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if est.SizeUnknown {
|
|
t.Fatalf("size must be known when the sizer succeeds")
|
|
}
|
|
if est.DataSizeBytes != twoGiB {
|
|
t.Fatalf("DataSizeBytes = %d, want %d (WRONG would be 0 — the F-A bug)", est.DataSizeBytes, twoGiB)
|
|
}
|
|
if !strings.Contains(est.DataSizeHuman, "GB") {
|
|
t.Fatalf("DataSizeHuman = %q, want GB-scale (WRONG would be \"3.6 KB\")", est.DataSizeHuman)
|
|
}
|
|
}
|
|
|
|
// Scenario G: a failed volume read must never render as "fits". Size is marked unknown, the human
|
|
// string says so, and FitsOnDest is forced false.
|
|
func TestEstimate_VolumeSize_FailureNeverFits(t *testing.T) {
|
|
orig := volumeSizer
|
|
volumeSizer = func(vol string) (int64, error) { return 0, errors.New("docker: no such image") }
|
|
defer func() { volumeSizer = orig }()
|
|
|
|
e := newEstimator(t, &rtProvider{stackDir: t.TempDir(), volumes: []string{"app_data"}})
|
|
est, err := e.EstimateExport("app", t.TempDir())
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if !est.SizeUnknown {
|
|
t.Fatalf("a failed volume read must set SizeUnknown")
|
|
}
|
|
if est.FitsOnDest {
|
|
t.Fatalf("an unknown size must NEVER render as fits_on_dest:true")
|
|
}
|
|
if est.DataSizeHuman != "ismeretlen méret" {
|
|
t.Fatalf("DataSizeHuman = %q, want \"ismeretlen méret\"", est.DataSizeHuman)
|
|
}
|
|
if est.DataSizeBytes != 0 {
|
|
t.Fatalf("no successful read → DataSizeBytes should be 0, got %d", est.DataSizeBytes)
|
|
}
|
|
}
|
|
|
|
// Scenario H (regression): an HDD-backed stack must NOT touch the new volume sizer — the HDD branch
|
|
// (duBytes on the mounted /mnt path) is unchanged. Platform-independent: assert the seam is not
|
|
// invoked and SizeUnknown stays false.
|
|
func TestEstimate_HDDPath_DoesNotUseVolumeSizer(t *testing.T) {
|
|
called := false
|
|
orig := volumeSizer
|
|
volumeSizer = func(vol string) (int64, error) { called = true; return 0, nil }
|
|
defer func() { volumeSizer = orig }()
|
|
|
|
p := &hddProvider{rtProvider: &rtProvider{stackDir: t.TempDir()}, mounts: []string{t.TempDir()}}
|
|
e := newEstimator(t, p)
|
|
est, err := e.EstimateExport("app", t.TempDir())
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if called {
|
|
t.Fatalf("HDD-backed stack must not call the docker volume sizer")
|
|
}
|
|
if est.SizeUnknown {
|
|
t.Fatalf("HDD branch must not set SizeUnknown")
|
|
}
|
|
}
|