Off-site lock live: Parts D/E/F evidence, ep0 copy runbook, 06/07 facts, register (R-820/R-821/R-342 closed, R-825 opened+closed, R-95/R-822 narrowed, R-823/R-824/R-826/R-827/R-828/R-830 opened; 327 -> 330); hub window-sweep test (test-only)
gates / gates (push) Successful in 41s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-03 21:21:04 +02:00
parent cdfcc47b15
commit 207ad19746
22 changed files with 370 additions and 15 deletions
+35
View File
@@ -92,3 +92,38 @@ func TestWindow_NoConfirmedKeyRefused(t *testing.T) {
t.Fatal("granted without a confirmed key")
}
}
// A window the box never closes is closed by the hub at its bound: the deleting line goes, the ledger
// row closes with reason "timeout", and the operator hears offsite_window_failed.
func TestWindow_LeftOpenIsClosedByTheSweep(t *testing.T) {
s, fs, events := svcFixture(t)
ctx := context.Background()
pub, fp := newKey(t)
if _, err := s.RegisterKey(ctx, "c1", pub); err != nil {
t.Fatal(err)
}
if _, err := s.ConfirmKey(ctx, "c1", fp); err != nil {
t.Fatal(err)
}
_ = s.Store.GrantOffsiteWindowOnce("c1")
g, err := s.OpenWindowFor(ctx, "c1", 10)
if err != nil || !g.Granted {
t.Fatalf("%+v %v", g, err)
}
// Make it overdue: the box crashed and never reported.
if err := s.Store.ForceOffsiteWindowDueForTest(g.WindowID); err != nil {
t.Fatal(err)
}
s.SweepExpiredWindows(ctx)
if a := audit(fs.files[".ssh/authorized_keys"], "/home/felhom-repo", false); len(a.Findings) != 0 {
t.Fatalf("the sweep left the deleting line: %+v", a)
}
w, _ := s.Store.GetOffsiteWindow(g.WindowID)
if w == nil || w.ClosedAt.IsZero() || w.CloseReason != "timeout" {
t.Fatalf("ledger = %+v", w)
}
last := (*events)[len(*events)-1]
if last != EventWindowFailed {
t.Fatalf("last event = %s", last)
}
}
+6
View File
@@ -175,3 +175,9 @@ func (s *Store) TakeOffsiteWindowGrant(customerID string) bool {
_ = s.setSetting(k, "")
return true
}
// ForceOffsiteWindowDueForTest back-dates a window's closes_by. TEST-ONLY.
func (s *Store) ForceOffsiteWindowDueForTest(id int64) error {
_, err := s.db.Exec(`UPDATE offsite_windows SET closes_by = datetime('now', '-1 minute') WHERE id = ?`, id)
return err
}