checks: run the agent bao-fetch unit scripts against a stub bao
`script-test-agent-bao-fetch` executes the rendered `ExecStart` of `hive-agent-forge-token` and `hive-agent-queue-credential` under `umask 0377`, with a stub `bao` first on the unit's own PATH. It covers every error branch, the happy path, forge rotation/unchanged, and 0400 files already in place: the redirect failure #4736 fixed, whose live symptom was `bao.err: Permission denied` reported as a refused certificate. The TLS-alert fixture is the `unknown certificate authority` error h-atlas's identity check got from the store. #4736 claimed this test but never committed it; the two module-eval suites for these units only evaluate the config. Closes #4748
This commit is contained in:
parent
916c441e82
commit
202f7f7c83
3 changed files with 346 additions and 0 deletions
82
nix/script-tests/agent-bao-fetch.nix
Normal file
82
nix/script-tests/agent-bao-fetch.nix
Normal file
|
|
@ -0,0 +1,82 @@
|
|||
# `checks.script-test-agent-bao-fetch` — runs the two agent units that log in
|
||||
# to the swarm secret store and fetch a secret, ../agent-modules/forge-token.nix
|
||||
# and ../agent-modules/queue-identity.nix, against a stub `bao`. The cases are
|
||||
# in ./agent-bao-fetch.sh.
|
||||
#
|
||||
# What runs is each unit's rendered `ExecStart`, on the unit's own `PATH` with
|
||||
# the stub in front. The one edit is the unit's `/run/<unit>/` prefix, moved
|
||||
# under the build directory because the sandbox has no writable `/run`.
|
||||
{
|
||||
pkgs,
|
||||
lib,
|
||||
self,
|
||||
nixosSystem,
|
||||
}:
|
||||
let
|
||||
inherit
|
||||
(import ../module-eval/lib.nix {
|
||||
inherit
|
||||
pkgs
|
||||
lib
|
||||
self
|
||||
nixosSystem
|
||||
;
|
||||
})
|
||||
agentWith
|
||||
;
|
||||
|
||||
machine = agentWith { services.hyperhive.agent.bao.addr = "https://bao.t.local:8200"; };
|
||||
|
||||
unitEnv =
|
||||
prefix: name:
|
||||
let
|
||||
u = machine.systemd.services.${name};
|
||||
in
|
||||
{
|
||||
"${prefix}_UNIT" = name;
|
||||
# `removeSuffix`, not `trim`: `trim` drops the string context, and with it
|
||||
# the script's store path from this check's inputs.
|
||||
"${prefix}_SCRIPT" = lib.removeSuffix " " u.serviceConfig.ExecStart;
|
||||
"${prefix}_PATH" = u.environment.PATH;
|
||||
"${prefix}_BAO_ADDR" = u.environment.BAO_ADDR;
|
||||
};
|
||||
|
||||
# Answers `login` and `kv get` from `FAKE_BAO_*` variables and logs every
|
||||
# call. A `kv` call without the token `login` printed fails, so a script that
|
||||
# drops `BAO_TOKEN` between the two cannot pass.
|
||||
fakeBao = pkgs.writeShellScriptBin "bao" ''
|
||||
echo "$*" >> "$FAKE_BAO_LOG"
|
||||
case "$1" in
|
||||
login)
|
||||
printf '%s' "$FAKE_BAO_LOGIN_ERR" >&2
|
||||
printf '%s' "$FAKE_BAO_LOGIN_OUT"
|
||||
exit "$FAKE_BAO_LOGIN_RC"
|
||||
;;
|
||||
kv)
|
||||
if [ "''${BAO_TOKEN-}" != "$FAKE_BAO_LOGIN_OUT" ]; then
|
||||
echo "fake bao: kv called without the login's token" >&2
|
||||
exit 97
|
||||
fi
|
||||
printf '%s' "$FAKE_BAO_KV_ERR" >&2
|
||||
printf '%s' "$FAKE_BAO_KV_OUT"
|
||||
exit "$FAKE_BAO_KV_RC"
|
||||
;;
|
||||
*)
|
||||
echo "fake bao: unexpected call: $*" >&2
|
||||
exit 98
|
||||
;;
|
||||
esac
|
||||
'';
|
||||
in
|
||||
pkgs.runCommand "hyperhive-script-test-agent-bao-fetch"
|
||||
(
|
||||
unitEnv "FORGE" "hive-agent-forge-token"
|
||||
// unitEnv "QUEUE" "hive-agent-queue-credential"
|
||||
// {
|
||||
FAKE_BAO_BIN = "${fakeBao}/bin";
|
||||
}
|
||||
)
|
||||
''
|
||||
${pkgs.bash}/bin/bash ${./agent-bao-fetch.sh}
|
||||
touch "$out"
|
||||
''
|
||||
Loading…
Reference in a new issue