module-eval: read the services-leaf narrowing off a forge host

`checks.module-eval-core-toggle` is red on main: "a gateway's services
leaf asks for only the swarm names that host fronts" read its leaf
request off `bare`, on the premise that `bare` fronts forge. That was
true where the property was written, before 978164dc (#4705) defaulted
`deploy.forgejo.enable` to false. The two merged in sequence, and on main
`bare` renders only the `_` and `h1.t.local` vhosts, so its
`localServiceDomains` is [] and the script carries `alt_names=''`,
never `alt_names=forge.t.local`.

The narrowing itself is right: a host that runs no forge fronts no
swarm name and asks for no services leaf. Only the fixture was stale.
The property now reads a hive with `deploy.forgejo.enable = true`,
whose request is `common_name=forge.t.local alt_names=forge.t.local`
while `auth.t.local` stays in the swarm-wide set.

The renewal timer from 0649673e is not involved: the check's derivation
is identical at 0649673e and at its parent, and ed2ec52f replayed onto
978164dc^ holds while replayed onto 978164dc it fails.

Refs #4587
This commit is contained in:
atlas 2026-09-26 00:57:42 +02:00 • committed by mara
commit 1948e7ad23

View file

@ -205,15 +205,16 @@ let
} }
{ {
# A leaf is a key that can SERVE every name in it, so the names it # A leaf is a key that can SERVE every name in it, so the names it
# asks for are that key's blast radius. `bare` fronts forge and # asks for are that key's blast radius. The forge's host fronts forge
# nothing else; the last conjunct is the control, since `auth.t.local` # and nothing else; the last conjunct is the control, since
# is in the swarm's set and an unnarrowed request would carry it here # `auth.t.local` is in the swarm's set and an unnarrowed request would
# too. # carry it here too.
name = "a gateway's services leaf asks for only the swarm names that host fronts"; name = "a gateway's services leaf asks for only the swarm names that host fronts";
ok = ok =
let let
s = bare.services.hyperhive.swarm.serviceDomains; forgeHere = hive { deploy.forgejo.enable = true; };
u = bare.systemd.services.swarm-services-cert.script; s = forgeHere.services.hyperhive.swarm.serviceDomains;
u = forgeHere.systemd.services.swarm-services-cert.script;
in in
lib.hasInfix "alt_names=forge.t.local" u lib.hasInfix "alt_names=forge.t.local" u
&& !(lib.hasInfix "auth.t.local" u) && !(lib.hasInfix "auth.t.local" u)