refactor: give business commands and deployment config domain names

This commit is contained in:
2026-09-30 17:33:58 +08:00
parent 04b66c4c4c
commit 1647aefd5b
22 changed files with 135 additions and 55 deletions
@@ -18,7 +18,7 @@ import (
"google.golang.org/grpc/credentials"
)
func newCurrentAgentCommand() *cobra.Command {
func newAgentCommand() *cobra.Command {
var mode string
command := &cobra.Command{
Use: "agent", Short: "Run the isolated Agent", Args: cobra.NoArgs,
@@ -61,7 +61,7 @@ func newCurrentAgentCommand() *cobra.Command {
return errors.New("Agent cannot create pinned Dispatcher connection")
}
defer connection.Close()
handler, err := newCurrentAgentServer(cmd.Context(), settings, scenario, applied, agentpb.NewAgentControlServiceClient(connection))
handler, err := newAgentServer(cmd.Context(), settings, scenario, applied, agentpb.NewAgentControlServiceClient(connection))
if err != nil {
return err
}
@@ -18,7 +18,7 @@ import (
"google.golang.org/grpc/status"
)
func TestCurrentAgentCommandRejectsRealModesAndObsoleteCallEntry(t *testing.T) {
func TestAgentCommandRejectsRealModesAndObsoleteCallEntry(t *testing.T) {
for _, tc := range []struct {
name string
args []string
@@ -33,7 +33,7 @@ func TestCurrentAgentCommandRejectsRealModesAndObsoleteCallEntry(t *testing.T) {
state := filepath.Join(t.TempDir(), "session.json")
t.Setenv("AGENT_ID", "")
t.Setenv("AGENT_SESSION_PATH", state)
command := newCurrentAgentCommand()
command := newAgentCommand()
command.SetOut(io.Discard)
command.SetErr(io.Discard)
command.SetArgs(tc.args)
@@ -73,7 +73,7 @@ func TestLoadMockAppliedSIPAcceptsOnlyExplicitLocalFacts(t *testing.T) {
}
}
func TestCurrentAgentCommandServesPinnedMutualTLSOnly(t *testing.T) {
func TestAgentCommandServesPinnedMutualTLSOnly(t *testing.T) {
ca, agentCert, agentKey, dispatcherCert, dispatcherKey, dispatcherLeaf := localCommandCertificates(t)
settings, _ := currentAgentSetupFixture(t)
for path, body := range map[string][]byte{
@@ -112,7 +112,7 @@ func TestCurrentAgentCommandServesPinnedMutualTLSOnly(t *testing.T) {
t.Setenv(name, value)
}
process, cancel := context.WithCancel(context.Background())
command := newCurrentAgentCommand()
command := newAgentCommand()
command.SetOut(io.Discard)
command.SetErr(io.Discard)
command.SetContext(process)
@@ -26,38 +26,38 @@ import (
"github.com/google/uuid"
)
// newCurrentAgentServer binds the authenticated Agent session, task controls
// newAgentServer binds the authenticated Agent session, task controls
// and per-call Mock recording delivery. Serving the returned server requires
// a separately verified mutual-TLS listener and a pinned local D connection.
func newCurrentAgentServer(ctx context.Context, settings config.AgentEnvironment, scenario approvedMockScenario, appliedSIP map[string]int64, dispatcher agentpb.AgentControlServiceClient) (*rpc.Server, error) {
func newAgentServer(ctx context.Context, settings config.AgentEnvironment, scenario approvedMockScenario, appliedSIP map[string]int64, dispatcher agentpb.AgentControlServiceClient) (*rpc.Server, error) {
if ctx == nil || ctx.Err() != nil || settings.AgentID == "" || settings.CellID == "" || settings.SessionPath == "" ||
settings.RecoveryRoot == "" || len(settings.PeerFingerprints) == 0 || len(appliedSIP) == 0 ||
scenario.MaxWAVBytes <= 44 || len(scenario.Script.Turns) == 0 || strings.TrimSpace(scenario.ReasonMessage) == "" {
return nil, errors.New("current Agent requires an active process, explicit Mock media and deployment identity")
return nil, errors.New("Mock Agent requires an active process, explicit Mock media and deployment identity")
}
if tenant.ValidateDispatcherID(settings.DispatcherID) != nil {
return nil, errors.New("current Agent requires an approved Dispatcher UUID v4")
return nil, errors.New("Mock Agent requires an approved Dispatcher UUID v4")
}
if dispatcher == nil {
return nil, errors.New("current Agent requires a pinned Dispatcher transport")
return nil, errors.New("Mock Agent requires a pinned Dispatcher transport")
}
value := reflect.ValueOf(dispatcher)
switch value.Kind() {
case reflect.Chan, reflect.Func, reflect.Interface, reflect.Map, reflect.Pointer, reflect.Slice:
if value.IsNil() {
return nil, errors.New("current Agent requires a pinned Dispatcher transport")
return nil, errors.New("Mock Agent requires a pinned Dispatcher transport")
}
}
root, err := os.Stat(settings.RecoveryRoot)
if err != nil || !root.IsDir() || root.Mode().Perm() != 0700 {
return nil, errors.New("current Agent requires an existing private 0700 recovery directory")
return nil, errors.New("Mock Agent requires an existing private 0700 recovery directory")
}
if err := rejectLegacyAgentSpool(settings.RecoveryRoot); err != nil {
return nil, err
}
for trunk, revision := range appliedSIP {
if strings.TrimSpace(trunk) == "" || revision <= 0 {
return nil, errors.New("current Agent requires explicit applied Mock SIP revisions")
return nil, errors.New("Mock Agent requires explicit applied Mock SIP revisions")
}
}
loaded := maps.Clone(appliedSIP)
@@ -122,7 +122,7 @@ func newCurrentAgentServer(ctx context.Context, settings config.AgentEnvironment
}
// Old spool files may contain unreported execution or upload outcomes. Never
// start the current Agent on the same root without an explicit disposition.
// start another Agent on the same root without an explicit disposition.
func rejectLegacyAgentSpool(root string) error {
entries, err := os.ReadDir(root)
if err != nil {
@@ -47,9 +47,9 @@ func currentAgentSetupFixture(t *testing.T) (config.AgentEnvironment, approvedMo
return settings, scenario
}
func TestNewCurrentAgentServerBindsMockCallsToOneSessionAndRecoveryRoot(t *testing.T) {
func TestNewAgentServerBindsMockCallsToOneSessionAndRecoveryRoot(t *testing.T) {
settings, scenario := currentAgentSetupFixture(t)
server, err := newCurrentAgentServer(context.Background(), settings, scenario, map[string]int64{"trunk-mock": 8}, &isolatedAgentRecordingClient{})
server, err := newAgentServer(context.Background(), settings, scenario, map[string]int64{"trunk-mock": 8}, &isolatedAgentRecordingClient{})
if err != nil || server == nil {
t.Fatalf("valid isolated Agent could not be assembled: %v", err)
}
@@ -58,7 +58,7 @@ func TestNewCurrentAgentServerBindsMockCallsToOneSessionAndRecoveryRoot(t *testi
}
}
func TestNewCurrentAgentServerRefusesLegacySpoolWithoutChangingIt(t *testing.T) {
func TestNewAgentServerRefusesLegacySpoolWithoutChangingIt(t *testing.T) {
for _, tc := range []struct {
name string
marker string
@@ -83,7 +83,7 @@ func TestNewCurrentAgentServerRefusesLegacySpoolWithoutChangingIt(t *testing.T)
t.Fatal(err)
}
}
server, err := newCurrentAgentServer(context.Background(), settings, scenario, map[string]int64{"trunk-mock": 8}, &isolatedAgentRecordingClient{})
server, err := newAgentServer(context.Background(), settings, scenario, map[string]int64{"trunk-mock": 8}, &isolatedAgentRecordingClient{})
if err == nil || server != nil {
t.Fatalf("legacy spool was admitted: %v", err)
}
@@ -97,7 +97,7 @@ func TestNewCurrentAgentServerRefusesLegacySpoolWithoutChangingIt(t *testing.T)
}
}
func TestNewCurrentAgentServerRefusesUnsafeAdaptersBeforeResources(t *testing.T) {
func TestNewAgentServerRefusesUnsafeAdaptersBeforeResources(t *testing.T) {
settings, scenario := currentAgentSetupFixture(t)
for _, tc := range []struct {
name string
@@ -134,7 +134,7 @@ func TestNewCurrentAgentServerRefusesUnsafeAdaptersBeforeResources(t *testing.T)
loaded := map[string]int64{"trunk-mock": 8}
var client agentpb.AgentControlServiceClient = &isolatedAgentRecordingClient{}
tc.change(&cfg, &media, &loaded, &client)
if server, err := newCurrentAgentServer(context.Background(), cfg, media, loaded, client); err == nil || server != nil {
if server, err := newAgentServer(context.Background(), cfg, media, loaded, client); err == nil || server != nil {
t.Fatalf("unsafe current Agent assembly was accepted: %v", err)
}
if _, err := os.Stat(settings.SessionPath); !os.IsNotExist(err) {
@@ -21,31 +21,31 @@ import (
"google.golang.org/grpc/credentials"
)
func newCurrentDispatcherCommand() *cobra.Command {
func newDispatcherCommand() *cobra.Command {
var mode string
command := &cobra.Command{
Use: "dispatcher", Short: "Run the isolated Dispatcher", Args: cobra.NoArgs,
SilenceUsage: true,
RunE: func(cmd *cobra.Command, _ []string) error {
return runCurrentDispatcher(cmd.Context(), mode)
return runDispatcher(cmd.Context(), mode)
},
}
command.Flags().StringVar(&mode, "mode", "mock", "isolated Mock mode only")
return command
}
// runCurrentDispatcher does not publish or consume until the predeclared MQ
// runDispatcher does not publish or consume until the predeclared MQ
// topology, Agent session and approved SIP load have all been verified.
func runCurrentDispatcher(ctx context.Context, mode string) (result error) {
func runDispatcher(ctx context.Context, mode string) (result error) {
settings, err := config.LoadDispatcherRuntimeEnvironment(mode)
if err != nil {
return err
}
agentEndpoint, err := config.LoadCurrentMockAgentEndpoint(settings.AgentEndpointsFile)
agentEndpoint, err := config.LoadMockAgentEndpoint(settings.AgentEndpointsFile)
if err != nil {
return err
}
ossConfiguration, err := config.LoadCurrentOSSConfig(settings.OSSConfigFile, settings.DispatcherID)
ossConfiguration, err := config.LoadOSSConfig(settings.OSSConfigFile, settings.DispatcherID)
if err != nil {
return err
}
@@ -8,7 +8,7 @@ import (
"testing"
)
func TestCurrentDispatcherCommandRejectsOldFlagsAndModesBeforeResources(t *testing.T) {
func TestDispatcherCommandRejectsOldFlagsAndModesBeforeResources(t *testing.T) {
for _, tc := range []struct {
name string
args []string
@@ -21,7 +21,7 @@ func TestCurrentDispatcherCommandRejectsOldFlagsAndModesBeforeResources(t *testi
t.Run(tc.name, func(t *testing.T) {
database := filepath.Join(t.TempDir(), "dispatcher.sqlite")
t.Setenv("DISPATCHER_SQLITE_PATH", database)
command := newCurrentDispatcherCommand()
command := newDispatcherCommand()
command.SetOut(io.Discard)
command.SetErr(io.Discard)
command.SetArgs(tc.args)
@@ -35,7 +35,7 @@ func TestCurrentDispatcherCommandRejectsOldFlagsAndModesBeforeResources(t *testi
}
}
func TestCurrentDispatcherCommandValidatesDeploymentBeforeOpeningSQLite(t *testing.T) {
func TestDispatcherCommandValidatesDeploymentBeforeOpeningSQLite(t *testing.T) {
root := t.TempDir()
endpointFile := filepath.Join(root, "agent-endpoints.json")
ossFile := filepath.Join(root, "oss.json")
@@ -64,7 +64,7 @@ func TestCurrentDispatcherCommandValidatesDeploymentBeforeOpeningSQLite(t *testi
}
check := func(want string) {
t.Helper()
command := newCurrentDispatcherCommand()
command := newDispatcherCommand()
command.SetOut(io.Discard)
command.SetErr(io.Discard)
command.SetArgs([]string{"--mode", "mock"})
+1 -1
View File
@@ -9,7 +9,7 @@ import (
)
func TestDispatcherHasNoBusinessHTTPFlags(t *testing.T) {
command := newCurrentDispatcherCommand()
command := newDispatcherCommand()
for _, name := range []string{"control-listen", "control-token", "config", "db"} {
if command.Flags().Lookup(name) != nil {
t.Fatalf("obsolete Dispatcher flag remains: --%s", name)
@@ -32,7 +32,7 @@ import (
"google.golang.org/grpc/credentials"
)
func TestCurrentDispatcherCommandStartsWithIsolatedMQHTTPAndAgent(t *testing.T) {
func TestDispatcherCommandStartsWithIsolatedMQHTTPAndAgent(t *testing.T) {
brokerURL, adminURL := os.Getenv("RABBITMQ_URL"), os.Getenv("RABBITMQ_PROVISIONER_URL")
if brokerURL == "" || adminURL == "" {
t.Skip("requires the isolated RabbitMQ mock provisioner")
@@ -165,7 +165,7 @@ func TestCurrentDispatcherCommandStartsWithIsolatedMQHTTPAndAgent(t *testing.T)
defer agentConnection.Close()
agentContext, stopAgent := context.WithCancel(context.Background())
defer stopAgent()
agentServer, err := newCurrentAgentServer(agentContext, settings, scenario, map[string]int64{"trunk-mock": 8}, agentpb.NewAgentControlServiceClient(agentConnection))
agentServer, err := newAgentServer(agentContext, settings, scenario, map[string]int64{"trunk-mock": 8}, agentpb.NewAgentControlServiceClient(agentConnection))
if err != nil {
t.Fatal(err)
}
+1 -1
View File
@@ -21,6 +21,6 @@ func newRootCommand() *cobra.Command {
SilenceUsage: true,
SilenceErrors: true,
}
root.AddCommand(newCurrentAgentCommand(), newCurrentDispatcherCommand())
root.AddCommand(newAgentCommand(), newDispatcherCommand())
return root
}
+39
View File
@@ -0,0 +1,39 @@
package main
import (
"go/ast"
"go/parser"
"go/token"
"os"
"strings"
"testing"
)
func TestBusinessCommandsUseDomainNames(t *testing.T) {
files, err := os.ReadDir(".")
if err != nil {
t.Fatal(err)
}
for _, file := range files {
name := file.Name()
if file.IsDir() || !strings.HasSuffix(name, ".go") {
continue
}
if strings.HasPrefix(name, "current_") {
t.Errorf("%s retains an implementation-generation filename", name)
}
if strings.HasSuffix(name, "_test.go") {
continue
}
parsed, err := parser.ParseFile(token.NewFileSet(), name, nil, 0)
if err != nil {
t.Fatal(err)
}
ast.Inspect(parsed, func(node ast.Node) bool {
if declaration, ok := node.(*ast.FuncDecl); ok && strings.Contains(declaration.Name.Name, "Current") {
t.Errorf("%s retains an implementation-generation function %s", name, declaration.Name.Name)
}
return true
})
}
}
@@ -150,6 +150,8 @@
- 退役 AI 部署夹具:`TestDeploymentHasOneCanonicalDirectory` 先在旧 `deploys/test/ai-dental-meiba-v1.json` 上预期失败;逐字节移至 `docs/archive/deployment-examples/ai-dental-meiba-v1.json`,迁移前后 SHA-256 均为 `ae6f94045719e838c943e6c5ff9170ebc7fedb5991958cc64bbbffc229ba07b4`。运行入口、安装包和脚本无调用者,`deploys/test/README.md` 改指归档,历史证据中仍记录的原路径是**当时运行的输入事实**而不是现在的可执行路径;归档 README 列出原路径与当前位置,未改写旧证据 JSON。本机布局测试、当前文档链接/哈希、`make check`(含三项真实隔离 MQ PASS)与 `make release-check-local` 全部通过;不能因此宣称旧配置或真实供应商有效。P07 尚待自有 `Current` 命名及最终残留分类。
- 唯一业务入口与部署配置的自有 `Current` 代次命名:新增 `TestBusinessCommandsUseDomainNames` 与 `TestDeploymentConfigUsesDomainNames`,先在旧 `current_*.go` 与 `newCurrentAgentCommand`/`LoadCurrentOSSConfig` 等名称上预期失败;12 个业务命令及测试文件、4 个部署配置及测试文件改为 Agent、Dispatcher、Mock Endpoint 和 OSS 的职责名称,6 个构造/读取函数及调用方同步更名。`scripts/check-current-mq-mock.sh` 的第三项必跑集成测试筛选式同步改为现行测试名,错误提示也不再使用“current Agent”指代 Mock 模式。Agent/Dispatcher 行为无变化;两个命名测试、受影响模块 `go test -race -count=1`、全仓 `make check`(三项 MQ 集成测试实际 `PASS`)及 `make release-check-local` 均通过。`contracts.ReadCurrent`/`contract.ValidateCurrent` 表示**当前合同校验与历史源区分**、`SessionRegistry.CurrentMeta` 表示**当前有效会话**,不是并行代次业务入口,暂按语义例外保留,后续总账复核。P07 尚未提交最终残留总账,不代签 P08 或真实外部验收。
## 验收台账
P01–P06 的项目内隔离证据见上;P07 全仓命名与唯一入口尚在清理,A01–A12 和 K01–K16 的最终对照仍待 P08。不得用本地 Mock 冒充外部签收。
@@ -5,9 +5,9 @@ import (
"strings"
)
// LoadCurrentMockAgentEndpoint accepts exactly the one deployment-owned local
// LoadMockAgentEndpoint accepts exactly the one deployment-owned local
// Agent assigned to the isolated Dispatcher. SaaS task data cannot override it.
func LoadCurrentMockAgentEndpoint(filename string) (AgentEndpoint, error) {
func LoadMockAgentEndpoint(filename string) (AgentEndpoint, error) {
if strings.TrimSpace(filename) == "" {
return AgentEndpoint{}, errors.New("DISPATCHER_AGENT_ENDPOINTS_FILE is required")
}
@@ -16,10 +16,10 @@ func LoadCurrentMockAgentEndpoint(filename string) (AgentEndpoint, error) {
return AgentEndpoint{}, err
}
if len(endpoints) != 1 {
return AgentEndpoint{}, errors.New("current Mock Dispatcher requires exactly one assigned Agent endpoint")
return AgentEndpoint{}, errors.New("Mock Dispatcher requires exactly one assigned Agent endpoint")
}
if !localGRPCAddress(endpoints[0].Address, false) {
return AgentEndpoint{}, errors.New("current Mock Agent endpoint must be local with an explicit port")
return AgentEndpoint{}, errors.New("Mock Agent endpoint must be local with an explicit port")
}
return endpoints[0], nil
}
@@ -18,21 +18,21 @@ func writeMockAgentEndpoints(t *testing.T, body string) string {
return filename
}
func TestBundledAgentEndpointExampleIsValidForCurrentMock(t *testing.T) {
func TestBundledAgentEndpointExampleIsValidForMock(t *testing.T) {
filename := filepath.Join("..", "..", "deploys", "config", "agent-endpoints.example.json")
endpoint, err := LoadCurrentMockAgentEndpoint(filename)
endpoint, err := LoadMockAgentEndpoint(filename)
if err != nil || endpoint.AgentID != "agent-cell-a" || endpoint.CellID != "cell-a" || endpoint.Address != "127.0.0.1:19090" {
t.Fatalf("bundled Agent endpoint example cannot start the current Mock: endpoint=%+v err=%v", endpoint, err)
}
}
func TestLoadCurrentMockAgentEndpointRequiresOneLocalDeploymentTarget(t *testing.T) {
endpoint, err := LoadCurrentMockAgentEndpoint(writeMockAgentEndpoints(t, mockAgentEndpoint))
func TestLoadMockAgentEndpointRequiresOneLocalDeploymentTarget(t *testing.T) {
endpoint, err := LoadMockAgentEndpoint(writeMockAgentEndpoints(t, mockAgentEndpoint))
if err != nil || endpoint.AgentID != "agent-mock" || endpoint.CellID != "cell-mock" ||
endpoint.Address != "127.0.0.1:19090" || endpoint.ServerName != "agent.local" {
t.Fatalf("approved local Agent target was changed: %v", err)
}
if _, err := LoadCurrentMockAgentEndpoint(""); err == nil {
if _, err := LoadMockAgentEndpoint(""); err == nil {
t.Fatal("missing target inventory was defaulted")
}
for _, tc := range []struct {
@@ -45,7 +45,7 @@ func TestLoadCurrentMockAgentEndpointRequiresOneLocalDeploymentTarget(t *testing
{"oversized inventory", strings.Repeat(" ", 65<<10) + mockAgentEndpoint},
} {
t.Run(tc.name, func(t *testing.T) {
if _, err := LoadCurrentMockAgentEndpoint(writeMockAgentEndpoints(t, tc.body)); err == nil || strings.Contains(err.Error(), "saas.example.invalid") {
if _, err := LoadMockAgentEndpoint(writeMockAgentEndpoints(t, tc.body)); err == nil || strings.Contains(err.Error(), "saas.example.invalid") {
t.Fatalf("unapproved Agent target accepted or echoed: %v", err)
}
})
+39
View File
@@ -0,0 +1,39 @@
package config
import (
"go/ast"
"go/parser"
"go/token"
"os"
"strings"
"testing"
)
func TestDeploymentConfigUsesDomainNames(t *testing.T) {
files, err := os.ReadDir(".")
if err != nil {
t.Fatal(err)
}
for _, file := range files {
name := file.Name()
if file.IsDir() || !strings.HasSuffix(name, ".go") {
continue
}
if strings.HasPrefix(name, "current_") {
t.Errorf("%s retains an implementation-generation filename", name)
}
if strings.HasSuffix(name, "_test.go") {
continue
}
parsed, err := parser.ParseFile(token.NewFileSet(), name, nil, 0)
if err != nil {
t.Fatal(err)
}
ast.Inspect(parsed, func(node ast.Node) bool {
if declaration, ok := node.(*ast.FuncDecl); ok && strings.Contains(declaration.Name.Name, "Current") {
t.Errorf("%s retains an implementation-generation function %s", name, declaration.Name.Name)
}
return true
})
}
}
@@ -16,10 +16,10 @@ import (
"git.ipao.vip/rogee/go-sip/internal/tenant"
)
// LoadCurrentOSSConfig reads only the deployment-owned OSS settings for this
// LoadOSSConfig reads only the deployment-owned OSS settings for this
// Dispatcher. Credentials are resolved from explicit environment references;
// the file, its contents and secrets are never echoed in errors.
func LoadCurrentOSSConfig(filename, dispatcherID string) (oss.Config, error) {
func LoadOSSConfig(filename, dispatcherID string) (oss.Config, error) {
if strings.TrimSpace(filename) == "" || tenant.ValidateDispatcherID(dispatcherID) != nil {
return oss.Config{}, errors.New("DISPATCHER_OSS_CONFIG_FILE and canonical Dispatcher ID are required")
}
@@ -19,10 +19,10 @@ func writeMockOSSDeployment(t *testing.T, body string) string {
return path
}
func TestLoadCurrentOSSConfigRequiresBoundLocalHTTPSAndExplicitCredentials(t *testing.T) {
func TestLoadOSSConfigRequiresBoundLocalHTTPSAndExplicitCredentials(t *testing.T) {
t.Setenv("MOCK_OSS_KEY_ID", "isolated-id")
t.Setenv("MOCK_OSS_KEY_SECRET", "isolated-secret")
configuration, err := LoadCurrentOSSConfig(writeMockOSSDeployment(t, mockOSSDeployment), dispatcherFixtureID)
configuration, err := LoadOSSConfig(writeMockOSSDeployment(t, mockOSSDeployment), dispatcherFixtureID)
if err != nil {
t.Fatal(err)
}
@@ -33,13 +33,13 @@ func TestLoadCurrentOSSConfigRequiresBoundLocalHTTPSAndExplicitCredentials(t *te
}
}
func TestLoadCurrentOSSConfigIgnoresLegacyOSSEnvironment(t *testing.T) {
func TestLoadOSSConfigIgnoresLegacyOSSEnvironment(t *testing.T) {
for _, key := range []string{"DISPATCHER_OSS_REGION", "DISPATCHER_OSS_ENDPOINT", "DISPATCHER_OSS_BUCKET", "DISPATCHER_OSS_ACCESS_KEY_ID", "DISPATCHER_OSS_ACCESS_KEY_SECRET", "DISPATCHER_OSS_KEY_PREFIX", "DISPATCHER_OSS_GRANT_TTL_SECONDS"} {
t.Setenv(key, "legacy-value")
}
t.Setenv("MOCK_OSS_KEY_ID", "isolated-id")
t.Setenv("MOCK_OSS_KEY_SECRET", "isolated-secret")
configuration, err := LoadCurrentOSSConfig(writeMockOSSDeployment(t, mockOSSDeployment), dispatcherFixtureID)
configuration, err := LoadOSSConfig(writeMockOSSDeployment(t, mockOSSDeployment), dispatcherFixtureID)
if err != nil {
t.Fatal(err)
}
@@ -48,7 +48,7 @@ func TestLoadCurrentOSSConfigIgnoresLegacyOSSEnvironment(t *testing.T) {
}
}
func TestLoadCurrentOSSConfigRejectsUnapprovedDeploymentWithoutLeakingCredentials(t *testing.T) {
func TestLoadOSSConfigRejectsUnapprovedDeploymentWithoutLeakingCredentials(t *testing.T) {
t.Setenv("MOCK_OSS_KEY_ID", "isolated-id")
t.Setenv("MOCK_OSS_KEY_SECRET", "isolated-secret")
for _, tc := range []struct {
@@ -65,13 +65,13 @@ func TestLoadCurrentOSSConfigRejectsUnapprovedDeploymentWithoutLeakingCredential
{"oversized", strings.Repeat(" ", 65<<10) + mockOSSDeployment},
} {
t.Run(tc.name, func(t *testing.T) {
if _, err := LoadCurrentOSSConfig(writeMockOSSDeployment(t, tc.body), dispatcherFixtureID); err == nil || strings.Contains(err.Error(), "isolated-secret") {
if _, err := LoadOSSConfig(writeMockOSSDeployment(t, tc.body), dispatcherFixtureID); err == nil || strings.Contains(err.Error(), "isolated-secret") {
t.Fatalf("unapproved deployment admitted or exposed credential: %v", err)
}
})
}
t.Setenv("MOCK_OSS_KEY_SECRET", "")
if _, err := LoadCurrentOSSConfig(writeMockOSSDeployment(t, mockOSSDeployment), dispatcherFixtureID); err == nil || strings.Contains(err.Error(), "isolated-id") {
if _, err := LoadOSSConfig(writeMockOSSDeployment(t, mockOSSDeployment), dispatcherFixtureID); err == nil || strings.Contains(err.Error(), "isolated-id") {
t.Fatalf("unavailable credential was defaulted or exposed: %v", err)
}
}
+1 -1
View File
@@ -65,4 +65,4 @@ run_required_test() {
}
run_required_test ./internal/mq TestBrokerSharedResultQueueAndNoConfigure
run_required_test ./internal/dispatcher TestRuntimeIsolatedControlBacklogExecuteAndSharedResult
run_required_test ./cmd/sip-go-agent TestCurrentDispatcherCommandStartsWithIsolatedMQHTTPAndAgent
run_required_test ./cmd/sip-go-agent TestDispatcherCommandStartsWithIsolatedMQHTTPAndAgent