Derive queue path from agent_client_path in render_agent_with_queue
Make render_agent_with_queue derive the queue credential path from
agent_client_path() rather than re-interpolating Kind::Hive and the
queue/agent segment. This enforces path agreement through code reuse
instead of two hand-written spellings that can diverge.
The policy stanza needs the policy form (secret/data/...) while
agent_client_path returns the client form (swarm/hives/...). Bridge
this by wrapping agent_client_path's result with {MOUNT}/data/, the
same mechanism render_agent uses for agent paths.
Update tests to derive expected paths from agent_client_path instead
of hard-coding them, so a future divergence fails the test rather
than passing silently.
Refs #4386
This commit is contained in:
parent
68cf67423f
commit
f4b7a1e357
1 changed files with 9 additions and 7 deletions
|
|
@ -214,15 +214,12 @@ pub fn render_agent(agent: &str) -> Result<String, Error> {
|
||||||
/// could close a stanza could grant itself anything.
|
/// could close a stanza could grant itself anything.
|
||||||
pub fn render_agent_with_queue(agent: &str, hive: &str) -> Result<String, Error> {
|
pub fn render_agent_with_queue(agent: &str, hive: &str) -> Result<String, Error> {
|
||||||
checked_segment("agent", agent)?;
|
checked_segment("agent", agent)?;
|
||||||
checked_segment("hive", hive)?;
|
|
||||||
let agent_stanza = read_stanza(&format!(
|
let agent_stanza = read_stanza(&format!(
|
||||||
"{MOUNT}/data/{ROOT}/{}/{agent}/*",
|
"{MOUNT}/data/{ROOT}/{}/{agent}/*",
|
||||||
<&str>::from(Kind::Agent)
|
<&str>::from(Kind::Agent)
|
||||||
));
|
));
|
||||||
let queue_stanza = read_stanza(&format!(
|
let queue_path = crate::queue::agent_client_path(hive)?;
|
||||||
"{MOUNT}/data/{ROOT}/{}/{hive}/queue/agent",
|
let queue_stanza = read_stanza(&format!("{MOUNT}/data/{queue_path}"));
|
||||||
<&str>::from(Kind::Hive)
|
|
||||||
));
|
|
||||||
Ok(format!("{agent_stanza}{queue_stanza}"))
|
Ok(format!("{agent_stanza}{queue_stanza}"))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
@ -458,8 +455,12 @@ mod tests {
|
||||||
p.contains("path \"secret/data/swarm/agents/atlas/*\""),
|
p.contains("path \"secret/data/swarm/agents/atlas/*\""),
|
||||||
"must grant the agent's own path: {p}"
|
"must grant the agent's own path: {p}"
|
||||||
);
|
);
|
||||||
|
let expected_queue_path = format!(
|
||||||
|
"path \"{MOUNT}/data/{}\"",
|
||||||
|
crate::queue::agent_client_path("pr1ma").expect("legal")
|
||||||
|
);
|
||||||
assert!(
|
assert!(
|
||||||
p.contains("path \"secret/data/swarm/hives/pr1ma/queue/agent\""),
|
p.contains(&expected_queue_path),
|
||||||
"must grant the hive's queue credential: {p}"
|
"must grant the hive's queue credential: {p}"
|
||||||
);
|
);
|
||||||
assert_eq!(
|
assert_eq!(
|
||||||
|
|
@ -537,6 +538,7 @@ mod tests {
|
||||||
!p.contains("swarm/hives/pr1ma/*"),
|
!p.contains("swarm/hives/pr1ma/*"),
|
||||||
"must not grant the hive's whole path: {p}"
|
"must not grant the hive's whole path: {p}"
|
||||||
);
|
);
|
||||||
assert!(p.contains("swarm/hives/pr1ma/queue/agent"));
|
let expected_queue_path = crate::queue::agent_client_path("pr1ma").expect("legal");
|
||||||
|
assert!(p.contains(&expected_queue_path));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue