swarm-controller: guard the lockdown PATCH against a forge name collision
disable_repo_creation now reads the account once before PATCHing max_repo_creation/source_id, and fails the node if the email isn't the {agent}@hyperhive.local marker create_agent_user itself sets. The 409/422 create-fold (#4681) only proves some account with that name exists, not that this node created it, so a pre-existing non-agent account sharing an agent's chosen name could otherwise get locked onto local auth with repo creation disabled. Leaves the fold untouched (Option B, per atlas/argus on #4693); the read moves into disable_repo_creation instead. Also fixes the nix-sandboxed cargo-test check: forgejo_api::Forgejo::new builds a reqwest client that eagerly resolves TLS roots via rustls-native-certs even for the tests' plain-http loopback stub server, which panics with "No CA certificates were loaded from the system" in the CA-less build sandbox. Gives that check's nativeBuildInputs pkgs.cacert and sets SSL_CERT_FILE, same pattern this repo's runtime deployment already uses for the same reqwest/rustls resolution.
This commit is contained in:
parent
04d5bf5f3e
commit
58f50ed506
2 changed files with 144 additions and 12 deletions
|
|
@ -156,7 +156,24 @@ in
|
|||
# per-container toplevels stay fully cached.
|
||||
cargo-test = craneLib.cargoTest {
|
||||
src = cleanSrc;
|
||||
inherit cargoArtifacts nativeBuildInputs;
|
||||
inherit cargoArtifacts;
|
||||
# `swarm-controller`'s forge tests build a real `forgejo_api::Forgejo`
|
||||
# (hence a real `reqwest::Client`) against a loopback stub server, never
|
||||
# the real forge — but `reqwest`/`rustls` still resolves roots through
|
||||
# `rustls-native-certs` at *client-build* time, unconditionally, even
|
||||
# though every request that client ever sends is plain `http://` to
|
||||
# `127.0.0.1`. The nix build sandbox has no system CA store, so that
|
||||
# resolution finds zero certs and `ClientBuilder::build()` itself fails
|
||||
# with "No CA certificates were loaded from the system" — the tests
|
||||
# never get as far as making a request. Same root cause the runtime
|
||||
# deployment already works around (see `nix/host-modules/swarm-
|
||||
# controller.nix`'s `caTrust` comment) and the same fix: give
|
||||
# `rustls-native-certs` something to find via `SSL_CERT_FILE`. The
|
||||
# bundle's actual contents don't matter here — nothing in these tests
|
||||
# ever presents or verifies a real certificate — only that the store is
|
||||
# non-empty.
|
||||
nativeBuildInputs = nativeBuildInputs ++ [ pkgs.cacert ];
|
||||
SSL_CERT_FILE = "${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt";
|
||||
pname = "hyperhive-workspace";
|
||||
version = "0.1.0";
|
||||
cargoTestExtraArgs = "--workspace";
|
||||
|
|
|
|||
Loading…
Reference in a new issue