Watch
0
0
Fork
You've already forked hyperhive
0

checks: run the agent bao-fetch unit scripts against a stub bao

`script-test-agent-bao-fetch` executes the rendered `ExecStart` of
`hive-agent-forge-token` and `hive-agent-queue-credential` under
`umask 0377`, with a stub `bao` first on the unit's own PATH. It covers
every error branch, the happy path, forge rotation/unchanged, and 0400
files already in place: the redirect failure #4736 fixed, whose live
symptom was `bao.err: Permission denied` reported as a refused
certificate. The TLS-alert fixture is the `unknown certificate
authority` error h-atlas's identity check got from the store.

#4736 claimed this test but never committed it; the two module-eval
suites for these units only evaluate the config.

Closes #4748
This commit is contained in:
atlas 2026-09-29 00:10:35 +02:00 • committed by mara
commit 202f7f7c83
3 changed files with 346 additions and 0 deletions

View file

@ -120,6 +120,12 @@ in
inherit pkgs self nixosSystem;
inherit (pkgs) lib;
};
# Executes what the two `module-eval-agent-*-bao` suites above only
# evaluate: both fetch units' rendered scripts, against a stub `bao`.
script-test-agent-bao-fetch = import ./script-tests/agent-bao-fetch.nix {
inherit pkgs self nixosSystem;
inherit (pkgs) lib;
};
module-eval-agent-memory = import ./module-eval/agent-memory.nix {
inherit pkgs self nixosSystem;
inherit (pkgs) lib;