Watch
0
0
Fork
You've already forked hyperhive
0

checks: run the agent bao-fetch unit scripts against a stub bao

`script-test-agent-bao-fetch` executes the rendered `ExecStart` of
`hive-agent-forge-token` and `hive-agent-queue-credential` under
`umask 0377`, with a stub `bao` first on the unit's own PATH. It covers
every error branch, the happy path, forge rotation/unchanged, and 0400
files already in place: the redirect failure #4736 fixed, whose live
symptom was `bao.err: Permission denied` reported as a refused
certificate. The TLS-alert fixture is the `unknown certificate
authority` error h-atlas's identity check got from the store.

#4736 claimed this test but never committed it; the two module-eval
suites for these units only evaluate the config.

Closes #4748
This commit is contained in:
atlas 2026-09-29 00:10:35 +02:00 • committed by mara
commit 202f7f7c83
3 changed files with 346 additions and 0 deletions

View file

@ -0,0 +1,82 @@
# `checks.script-test-agent-bao-fetch` — runs the two agent units that log in
# to the swarm secret store and fetch a secret, ../agent-modules/forge-token.nix
# and ../agent-modules/queue-identity.nix, against a stub `bao`. The cases are
# in ./agent-bao-fetch.sh.
#
# What runs is each unit's rendered `ExecStart`, on the unit's own `PATH` with
# the stub in front. The one edit is the unit's `/run/<unit>/` prefix, moved
# under the build directory because the sandbox has no writable `/run`.
{
pkgs,
lib,
self,
nixosSystem,
}:
let
inherit
(import ../module-eval/lib.nix {
inherit
pkgs
lib
self
nixosSystem
;
})
agentWith
;
machine = agentWith { services.hyperhive.agent.bao.addr = "https://bao.t.local:8200"; };
unitEnv =
prefix: name:
let
u = machine.systemd.services.${name};
in
{
"${prefix}_UNIT" = name;
# `removeSuffix`, not `trim`: `trim` drops the string context, and with it
# the script's store path from this check's inputs.
"${prefix}_SCRIPT" = lib.removeSuffix " " u.serviceConfig.ExecStart;
"${prefix}_PATH" = u.environment.PATH;
"${prefix}_BAO_ADDR" = u.environment.BAO_ADDR;
};
# Answers `login` and `kv get` from `FAKE_BAO_*` variables and logs every
# call. A `kv` call without the token `login` printed fails, so a script that
# drops `BAO_TOKEN` between the two cannot pass.
fakeBao = pkgs.writeShellScriptBin "bao" ''
echo "$*" >> "$FAKE_BAO_LOG"
case "$1" in
login)
printf '%s' "$FAKE_BAO_LOGIN_ERR" >&2
printf '%s' "$FAKE_BAO_LOGIN_OUT"
exit "$FAKE_BAO_LOGIN_RC"
;;
kv)
if [ "''${BAO_TOKEN-}" != "$FAKE_BAO_LOGIN_OUT" ]; then
echo "fake bao: kv called without the login's token" >&2
exit 97
fi
printf '%s' "$FAKE_BAO_KV_ERR" >&2
printf '%s' "$FAKE_BAO_KV_OUT"
exit "$FAKE_BAO_KV_RC"
;;
*)
echo "fake bao: unexpected call: $*" >&2
exit 98
;;
esac
'';
in
pkgs.runCommand "hyperhive-script-test-agent-bao-fetch"
(
unitEnv "FORGE" "hive-agent-forge-token"
// unitEnv "QUEUE" "hive-agent-queue-credential"
// {
FAKE_BAO_BIN = "${fakeBao}/bin";
}
)
''
${pkgs.bash}/bin/bash ${./agent-bao-fetch.sh}
touch "$out"
''