Compare commits
52 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| dd81eedcd9 | |||
| fc94326b0e | |||
| 40b5e781ce | |||
| 7315916fbc | |||
| e9f1073954 | |||
| 3c0ac65dc6 | |||
| 8631a698ce | |||
| 642a79f604 | |||
| e008c53966 | |||
| 8b19c9ab68 | |||
| 70c5718505 | |||
| 46bd07c792 | |||
| b6d514ee21 | |||
| 7bd8e47241 | |||
| 016039d1a3 | |||
| fc2b020423 | |||
| f4192be5d1 | |||
| 11da458883 | |||
| d66b3b9a0a | |||
| 2dcb14377a | |||
| 13e6762f0f | |||
| 325a5662f4 | |||
| 8b0cbe10ae | |||
| bd17e6e114 | |||
| 7cb12c52ce | |||
| 08481d35ce | |||
| 00869c6f5b | |||
| aa3462826b | |||
| dea358d40b | |||
| 367a338a72 | |||
| 2ce6622055 | |||
| 6408342a7f | |||
| 2d47cd9135 | |||
| 9727edf4df | |||
| e45232f395 | |||
| 82f3bcacfd | |||
| 7a834357ec | |||
| 40906a0697 | |||
| 16e4f8a1f2 | |||
| 2786de166d | |||
| 97a10353da | |||
| a288eb93ea | |||
| 285ffee863 | |||
| a0b3b7439d | |||
| a052bf20f1 | |||
| 7bb533c2fb | |||
| d7d6961261 | |||
| afcd15cde4 | |||
| 0b58286ca2 | |||
| f8b135e7a8 | |||
| d9d0beda3b | |||
| 007d3a12e8 |
@@ -79,6 +79,8 @@ and a **dispatcher** for multi-node job execution.
|
|||||||
|
|
||||||
### 2. Daemon Layer (`internal/daemon`)
|
### 2. Daemon Layer (`internal/daemon`)
|
||||||
|
|
||||||
|
> **⚠️ DEPRECATED in v0.9**: This section describes the v0.8 architecture, superseded by the v0.9 re-architecture. See the "v0.9 Architecture" section at the bottom of this file and `.ciagent/PRD_v0.9.md`.
|
||||||
|
|
||||||
- **Server**: `net/http` with `http.ServeMux` (no external router)
|
- **Server**: `net/http` with `http.ServeMux` (no external router)
|
||||||
- **TLS (P01)**: `crypto/tls` with `MinVersion=tls.VersionTLS13` and
|
- **TLS (P01)**: `crypto/tls` with `MinVersion=tls.VersionTLS13` and
|
||||||
AEAD cipher allowlist
|
AEAD cipher allowlist
|
||||||
@@ -93,6 +95,8 @@ and a **dispatcher** for multi-node job execution.
|
|||||||
|
|
||||||
### 3. Transport Layer (`internal/transport`, NEW in P01/P02)
|
### 3. Transport Layer (`internal/transport`, NEW in P01/P02)
|
||||||
|
|
||||||
|
> **⚠️ DEPRECATED in v0.9**: This section describes the v0.8 architecture, superseded by the v0.9 re-architecture. See the "v0.9 Architecture" section at the bottom of this file and `.ciagent/PRD_v0.9.md`.
|
||||||
|
|
||||||
- **Client**: `http.Client` with `http.Transport.TLSClientConfig` populated
|
- **Client**: `http.Client` with `http.Transport.TLSClientConfig` populated
|
||||||
from `internal/security.NewClientTLSConfig`
|
from `internal/security.NewClientTLSConfig`
|
||||||
- **Server**: `http.Server.TLSConfig` populated from
|
- **Server**: `http.Server.TLSConfig` populated from
|
||||||
@@ -108,6 +112,8 @@ and a **dispatcher** for multi-node job execution.
|
|||||||
|
|
||||||
### 4. Core Engine (`internal/engine`)
|
### 4. Core Engine (`internal/engine`)
|
||||||
|
|
||||||
|
> **⚠️ DEPRECATED in v0.9**: This section describes the v0.8 architecture, superseded by the v0.9 re-architecture. The Dispatcher and PeerRegistry peer-dispatch path is replaced by a CLI-side scheduler + SSH-push (R-001). See the "v0.9 Architecture" section at the bottom of this file and `.ciagent/PRD_v0.9.md`.
|
||||||
|
|
||||||
- **Node Registry**: In-memory map of node IDs → metadata, persisted to SQLite
|
- **Node Registry**: In-memory map of node IDs → metadata, persisted to SQLite
|
||||||
(CPU/memory capacity, available slots, last-seen)
|
(CPU/memory capacity, available slots, last-seen)
|
||||||
- **Task Executor**: `os/exec.CommandContext` with `WaitDelay` (Go 1.25+) for
|
- **Task Executor**: `os/exec.CommandContext` with `WaitDelay` (Go 1.25+) for
|
||||||
@@ -423,6 +429,8 @@ as a function that takes a `yield func(Job) bool` callback.
|
|||||||
|
|
||||||
## Security Architecture
|
## Security Architecture
|
||||||
|
|
||||||
|
> **⚠️ DEPRECATED in v0.9**: This section describes the v0.8 internal-CA architecture, superseded by the v0.9 re-architecture (step-ca, D-101/REQ-076). See the "v0.9 Architecture" section at the bottom of this file and `.ciagent/PRD_v0.9.md`.
|
||||||
|
|
||||||
### Authentication
|
### Authentication
|
||||||
- **v0.1**: mTLS for all API endpoints (self-signed CA)
|
- **v0.1**: mTLS for all API endpoints (self-signed CA)
|
||||||
- **v0.2 P01**: Internal CA with CSR join (see Flow 1 + 2)
|
- **v0.2 P01**: Internal CA with CSR join (see Flow 1 + 2)
|
||||||
@@ -449,6 +457,8 @@ as a function that takes a `yield func(Job) bool` callback.
|
|||||||
|
|
||||||
## Key Architectural Decisions (v0.1 + v0.2)
|
## Key Architectural Decisions (v0.1 + v0.2)
|
||||||
|
|
||||||
|
> **⚠️ DEPRECATED in v0.9**: AD-007 (HCL canonical for jobspecs) below is superseded by R-013/R-014 (Markdown with YAML frontmatter canonical; HCL legacy). See the "v0.9 Architecture" section at the bottom of this file and `.ciagent/PRD_v0.9.md`.
|
||||||
|
|
||||||
| ID | Decision | Rationale |
|
| ID | Decision | Rationale |
|
||||||
|----|----------|-----------|
|
|----|----------|-----------|
|
||||||
| AD-001 | Single binary with subcommands | Simpler distribution, aligns with simplicity pillar |
|
| AD-001 | Single binary with subcommands | Simpler distribution, aligns with simplicity pillar |
|
||||||
@@ -638,3 +648,83 @@ heredoc).
|
|||||||
| AD-019 | `orca@pam` realm (not `orca@pve`) | SSH creates a Linux system user; PAM realm maps it to PVE RBAC without a separate PVE password. `@pve` requires interactive password prompt over non-PTY SSH (hangs). |
|
| AD-019 | `orca@pam` realm (not `orca@pve`) | SSH creates a Linux system user; PAM realm maps it to PVE RBAC without a separate PVE password. `@pve` requires interactive password prompt over non-PTY SSH (hangs). |
|
||||||
| AD-020 | Exclude `pvesh` from sudoers; NOEXEC on `pct`/`qm` | `pvesh` can trigger API execute endpoint bypassing NOEXEC. `pct`/`qm` are Perl scripts via dynamically-linked perl → NOEXEC effective. `apt-get`/`dpkg` need exec for maintainer scripts → no NOEXEC. |
|
| AD-020 | Exclude `pvesh` from sudoers; NOEXEC on `pct`/`qm` | `pvesh` can trigger API execute endpoint bypassing NOEXEC. `pct`/`qm` are Perl scripts via dynamically-linked perl → NOEXEC effective. `apt-get`/`dpkg` need exec for maintainer scripts → no NOEXEC. |
|
||||||
| AD-021 | TOFU host-key via `knownhosts.New` | Avoids deprecated `ssh.InsecureIgnoreHostKey`. Capture-on-first-connect, verify-on-subsequent. Fail closed on mismatch (operator runs key-reset). |
|
| AD-021 | TOFU host-key via `knownhosts.New` | Avoids deprecated `ssh.InsecureIgnoreHostKey`. Capture-on-first-connect, verify-on-subsequent. Fail closed on mismatch (operator runs key-reset). |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# v0.9 Architecture (Supersedes v0.8)
|
||||||
|
|
||||||
|
> **⚠️ v0.9 DIRECTION CHANGE**: This section supersedes the v0.1–v0.8
|
||||||
|
> architecture described above. The re-architecture is justified by a
|
||||||
|
> six-part evidence basis recorded in `PROJECT.md` (Supersession Table).
|
||||||
|
> The v0.8 sections above are retained for historical context but are
|
||||||
|
> **deprecated**. The 16 load-bearing rules (R-001…R-016) in
|
||||||
|
> `PRD_v0.9.md` are now the canonical invariants.
|
||||||
|
|
||||||
|
## Superseded Decisions (AD-series reversals)
|
||||||
|
|
||||||
|
| Old decision | Was | Superseded by | Evidence basis |
|
||||||
|
|---|---|---|---|
|
||||||
|
| AD-010 (line 463 above) | step-ca/cfssl/vault-pki "too heavyweight" | **D-101** (step-ca) | External PKI mandate (override ground 2) |
|
||||||
|
| SPIFFE rejection (line 94, PROJECT.md) | internal CA chosen over SPIFFE | **D-068** (SPIFFE SVIDs) | Multi-tenancy requires per-workload identity (override ground 3) |
|
||||||
|
| No-container-runtime (line 477 above) | explicit anti-pattern | **D-088** (5 runtimes; wasmtime primary) | WASM is the workload profile (override ground 4) |
|
||||||
|
| No-multi-tenancy (line 478 above) | explicit anti-pattern | **D-158 / R-002** (multi-namespace) | Hard multi-tenant product req (override ground 3) |
|
||||||
|
| AD-007 (HCL canonical) | HCL for jobspec | **R-013 / R-014** (Markdown canonical; HCL legacy) | PRD §8 operator-facing format |
|
||||||
|
| Daemon-on-every-node | `orca daemon` on all peers | **R-001** (no orca binary on any server) | Daemon operationally failing + SSH-push only viable target (override grounds 1 + 5) |
|
||||||
|
|
||||||
|
## The Five-Layer CLI (v0.9)
|
||||||
|
|
||||||
|
The `orca` binary is one Go program, structured internally as five layers:
|
||||||
|
|
||||||
|
1. **CLI subcommand tree** (cobra) — `internal/cli/`
|
||||||
|
2. **Jobspec + config parsers** — `internal/spec/` (Markdown frontmatter
|
||||||
|
canonical, `.md`/`.yaml`/`.hcl` dispatcher per R-013/R-014)
|
||||||
|
3. **Cluster-state store** — `internal/store/` + `internal/paths/`
|
||||||
|
(per-namespace modernc/sqlite DBs + CLI-side `orca_cache` DB per R-002/R-008)
|
||||||
|
4. **Server-side config emitters** — `internal/emitter/` (pure string
|
||||||
|
templates → systemd units, Traefik YAML, sudoers, syncthing config;
|
||||||
|
SCP via SSH per R-001)
|
||||||
|
5. **Workflow orchestrators** — `internal/orch/` (compose SSH + local FS
|
||||||
|
writes into multi-step commands)
|
||||||
|
|
||||||
|
## The Server Side (R-001 — no Orca binary on any server)
|
||||||
|
|
||||||
|
Servers hold only: rendered config in `/etc/orca/actual/<txn-id>/`,
|
||||||
|
systemd units, Traefik dynamic config, sudoers, sshd_config snippets,
|
||||||
|
`step-ca`/`traefik`/`syncthing`/`podman`/`wasmtime`/`age`/`auditd`
|
||||||
|
(installed via apt), and bash scripts in `scripts/` (orca-pull.sh,
|
||||||
|
orca-drift.sh, orca-collect.sh, orca-aggregate.sh, orca-apply-render.sh,
|
||||||
|
orca-verify-render.sh, orca-rollback-render.sh, orca-cleanup-credentials.sh).
|
||||||
|
Nothing on any server is "Orca software" — Orca is the CLI plus a tree of
|
||||||
|
files.
|
||||||
|
|
||||||
|
## Multi-namespace Layout (R-002)
|
||||||
|
|
||||||
|
```
|
||||||
|
$ORCA_HOME/
|
||||||
|
├── cluster/ # cluster-wide (NOT a workload namespace)
|
||||||
|
│ ├── ca.crt, ca.key # step-ca root (R-006, D-101)
|
||||||
|
│ ├── master.key # AES-256-GCM root (R-011, mode 0600)
|
||||||
|
│ ├── config.md # Markdown frontmatter (R-014)
|
||||||
|
│ ├── peers/<host>/
|
||||||
|
│ ├── pve/<endpoint>/
|
||||||
|
│ ├── txns/{desired,applied,refused}/<txn-id>/
|
||||||
|
│ ├── txn.sqlite
|
||||||
|
│ └── state/
|
||||||
|
├── _defaults/ # implicit root namespace (always exists)
|
||||||
|
│ ├── ns.md
|
||||||
|
│ ├── .env, .env.secrets
|
||||||
|
│ ├── db/orca.db
|
||||||
|
│ ├── jobs/, alloc/
|
||||||
|
│ └── syncthing/
|
||||||
|
├── <explicit-namespace>/ # operator-created
|
||||||
|
└── orca_cache.db # CLI-side cache (R-008)
|
||||||
|
```
|
||||||
|
|
||||||
|
## Execution gates (from GRILL_v0.9.md)
|
||||||
|
|
||||||
|
The 19 binding conditions (C-01..C-19) and 10 phase challenges
|
||||||
|
(PC-01..PC-10) gate specific phases. See `GRILL_v0.9.md` for the full
|
||||||
|
list. Key gates: C-01 (wasmtime/CGO before P07b), C-07 (CA migration
|
||||||
|
spec before P14a), C-08 (SPIFFE mint spike before P02), C-09
|
||||||
|
(orida-pull.sh failure contract before P10), C-19 (threat model before
|
||||||
|
P15.5).
|
||||||
|
|||||||
@@ -0,0 +1,60 @@
|
|||||||
|
# Phase 4 Audit — v0.8 Coverage & Trust Hardening (Final Phase)
|
||||||
|
|
||||||
|
**Milestone**: v0.8 — Coverage & Trust Hardening
|
||||||
|
**Date**: 2026-08-04
|
||||||
|
**Branch**: `phase/04-final-review-ship`
|
||||||
|
**Result**: ✅ PASS (with P1 branch-hygiene finding — pre-existing, non-blocking for v0.8)
|
||||||
|
|
||||||
|
## Step 1 — Reconstruction Test ✅
|
||||||
|
|
||||||
|
- Latest `---ci---` block (HEAD of milestone/v0.8): `project: orca, phase: 3, milestone: v0.8, status: verify, requirements: covered: [REQ-060]` — matches CHECKPOINT.json (`phase: 2, stage: verify` — note: checkpoint is one phase behind because the P03 verify commit didn't update it to phase 3; the git log `---ci---` block is authoritative and correct).
|
||||||
|
- config.json `milestone: v0.8` — matches.
|
||||||
|
- `make verify-reqs` → `✓ 60 requirements consistent with roadmap` — ROADMAP ↔ REQUIREMENTS consistent.
|
||||||
|
- All 35 v0.8 commits have `---ci---` blocks (100% commit discipline).
|
||||||
|
|
||||||
|
## Step 2 — .ciagent/ File Discipline ✅
|
||||||
|
|
||||||
|
- `config.json`: valid JSON, `milestone: v0.8`, `phase: 0` (stale — should be 3 post-P03; minor, will be corrected at milestone-complete), `milestone_type: nfr`, `active_projects: ["orca"]` — all required fields present.
|
||||||
|
- `PROJECT.md`: has v0.8 scope summary + D-043..D-047 + the vision/constraints/decisions sections — complete.
|
||||||
|
- `ROADMAP.md`: v0.8 milestone section present with 4 phases (P0-P4), phases P0-P3 marked `[x]` (shipped tags v0.7.0..v0.7.3), P4 pending — matches git branches + tags. v0.8 milestone header NOT yet marked COMPLETE (milestone ship step will add this).
|
||||||
|
- `REQUIREMENTS.md`: REQ-057..060 present, status `Pending` (milestone ship step will mark `Complete`). All 56 prior REQs (REQ-001..056) `Complete`. Traceability matrix complete.
|
||||||
|
- `ARCHITECTURE.md`: not updated for v0.8 (no new components — verify-reqs is a `cmd/` program, not an architecture component; the trust-surface changes refine existing proxmox/doctor/cli packages). Acceptable — v0.8 is NFR, no architecture changes.
|
||||||
|
- `PERSONAS.md`: v0.8 roster at top (lead/backend/data active; frontend/security/cli-engineer deactivated with reasons), v0.7 baseline preserved — complete.
|
||||||
|
- `RESEARCH_v0.8.md`, `PLAN_v0.8.md`, `GRILL_v0.8.md`, `REVIEW_v0.8.md`, `PHASE1..3_VERIFICATION_v0.8.md` — all present.
|
||||||
|
|
||||||
|
## Step 3 — Branch Hygiene ⚠️ P1 (pre-existing, non-blocking)
|
||||||
|
|
||||||
|
**Stale merged local branches** (should have been deleted by prior ship workflows — v0.6 + v0.7 milestones):
|
||||||
|
- `milestone/v0.6-node-bootstrap-proxmox` (merged to main via v0.6 ship)
|
||||||
|
- `milestone/v0.7-hardening-completion` (merged to main via v0.7 ship)
|
||||||
|
- `phase/01-cert-register`, `phase/02-config-parser`, `phase/03-coverage-uplift`, `phase/04-pprof-daemon`, `phase/05-final-review-ship` (all v0.7 phase branches, merged to v0.7 milestone)
|
||||||
|
|
||||||
|
**Stale remote branches** (same set + older v0.6-era branches): `origin/milestone/v0.6-*`, `origin/milestone/v0.7-*`, `origin/phase/01-init-bootstrap`, `origin/phase/02-proxmox-join`, `origin/phase/03-doctor-extensions`, `origin/phase/04-final-review-ship`, etc.
|
||||||
|
|
||||||
|
**v0.8 branches** (`phase/01-coverage-round2`, `phase/02-ssh-trust-hardening`, `phase/03-requirements-hygiene-gate`, `phase/04-final-review-ship`, `milestone/v0.8-coverage-trust-hardening`) are all active or just-merged — NOT stale.
|
||||||
|
|
||||||
|
**Finding**: The ship workflow's branch-cleanup step (audit.md:46-49 "Step 6.5") is not running for prior milestones. This is a P1 process gap (recurring across v0.6 + v0.7) but does NOT block v0.8 ship. **Recommendation**: after v0.8 milestone ship, delete the stale v0.6/v0.7 local + remote branches (tags preserve the history). Defer to post-ship cleanup; do NOT block the milestone release.
|
||||||
|
|
||||||
|
## Step 4 — Commit Discipline ✅
|
||||||
|
|
||||||
|
- All 35 v0.8 commits have `---ci---` blocks (100%).
|
||||||
|
- No stale decisions: D-043..D-047 are all reflected in code (T02.3 flag per D-044, T02.5 callback per D-045, T02.8 local-only per D-046, T01.6 tiered floor per D-047, T02.6 bugfix per D-043 chore classification).
|
||||||
|
- No unresolved escalations (the only escalation was P0's `release_pending` from GITEA_TOKEN unset — auto-resolved, local-only fallback, pipeline not halted).
|
||||||
|
- All 4 GRILL binding conditions satisfied (verified in REVIEW_v0.8.md).
|
||||||
|
|
||||||
|
## Step 5 — Run Audit Checks ✅
|
||||||
|
|
||||||
|
- `go build ./...` PASS
|
||||||
|
- `go vet ./...` PASS
|
||||||
|
- `go test ./...` PASS (16 packages)
|
||||||
|
- `make verify-reqs` PASS (60 consistent)
|
||||||
|
- `make build` PASS
|
||||||
|
- `gofmt -l .` clean
|
||||||
|
|
||||||
|
## Overall Verdict
|
||||||
|
|
||||||
|
✅ **PASS** — v0.8 is shippable. The P1 branch-hygiene finding (stale v0.6/v0.7 branches) is pre-existing, non-blocking, and recommended for post-ship cleanup. The checkpoint phase-staleness (config.json `phase: 0` vs actual phase 3) is a minor bookkeeping gap corrected at milestone-complete.
|
||||||
|
|
||||||
|
## Recommendation
|
||||||
|
|
||||||
|
Proceed to milestone ship: mark REQ-057..060 `Complete` in REQUIREMENTS.md, mark v0.8 `COMPLETE` in ROADMAP.md, update config.json `phase: 4`, merge `phase/04-final-review-ship` → `milestone/v0.8` → `main`, tag `v0.7.4` (= milestone release), push, then delete stale v0.6/v0.7 branches as post-ship cleanup.
|
||||||
@@ -0,0 +1,32 @@
|
|||||||
|
# Bash Capability Map — v0.9 (grill C-18)
|
||||||
|
|
||||||
|
Maps every capability in the shipped `internal/transport` package to its
|
||||||
|
bash-side equivalent (or accepted drop with recorded rationale) in the v0.9
|
||||||
|
re-architecture. The grill (C-18) required this mapping so capability
|
||||||
|
regressions are visible, not silent.
|
||||||
|
|
||||||
|
| Shipped capability (internal/transport) | Bash-side equivalent | Status | Rationale |
|
||||||
|
|---|---|---|---|
|
||||||
|
| Retry with exponential backoff (`retry.go`: 100ms start, ×2, cap 5s, max 5 attempts) | `orca-retry()` function in `scripts/lib/orca-retry.sh` (to be written in v0.9-P01 SSH-push transport phase, REQ-073) | **planned** (v0.9-P01) | SSH dial/exec failures need the same bounded retry. The pattern is transport-agnostic; the Go retry logic is extracted into the new `internal/sshpush/` package and a bash-side helper mirrors it for the lead-applier scripts. |
|
||||||
|
| Idempotency keys (`idempotency.go`: in-memory `sync.Map` of keys, `X-Orca-Idempotency-Key` header) | Content-addressed filenames — skip SCP if the target hash already exists on the peer | **planned** (v0.9-P01) | SSH-push doesn't have HTTP headers; idempotency is achieved by content-addressing the rendered file (`<hash>.unit`) and skipping if the peer already has it. The bash applier checks `test -f /run/orca/<hash>` before applying. |
|
||||||
|
| Structured mTLS failure logging (`handshake_log.go`: slog JSON per mTLS failure) | `orca_log_error` via `scripts/lib/orca-log.sh` (C-17, shipped in this phase P00) | **dropped (mTLS removed by R-001)** | The v0.9 re-architecture removes mTLS daemon-to-daemon transport entirely (R-001). SSH failures are logged via the new `orca_log_*` functions which emit the same slog-compatible JSON field set (ts, level, actor, action, resource, result, error) to syslog. The mTLS-specific handshake-log fields (cipher suite, TLS version, cert SAN) have no SSH equivalent and are dropped — the SSH error message is captured in the `error` field instead. |
|
||||||
|
| TLS 1.3 + AEAD cipher allowlist (`mtls.go`: MinVersion=tls.VersionTLS13, CipherSuites limited) | SSH's own cipher config (`/etc/ssh/sshd_config` `Ciphers`, `MACs`, `KexAlgorithms`) managed by the operator | **dropped (transport replaced)** | R-001 replaces mTLS HTTP with SSH. SSH's transport security is governed by the peer's sshd_config, not the orca binary. The CLI's SSH client (`golang.org/x/crypto/ssh`, already a dep) uses Go's default modern SSH cipher set. The PRD does not require orca to manage sshd_config cipher policy in v0.9. |
|
||||||
|
| mTLS client/server handshake (`mtls.go`: `MTLSClient`, daemon-side `SubmitHandler`) | `ssh.Dial` + `ssh.PublicKeys` auth (CLI-side `internal/sshpush/`, REQ-073) | **replaced** (v0.9-P01) | The daemon-to-daemon mTLS handshake is replaced by CLI-to-server SSH. The CLI holds an Ed25519 key (`cluster/orca_ssh_key`, D-037) and authenticates to each peer's sshd. TOFU host-key handling (`proxmox.TOFUHostKeyCallback`, v0.8 REQ-058) is reused for all peers, not just Proxmox. |
|
||||||
|
|
||||||
|
## Net-new capabilities in v0.9 (no shipped equivalent)
|
||||||
|
|
||||||
|
| Net-new capability | Bash-side | Status |
|
||||||
|
|---|---|---|
|
||||||
|
| Transaction bundle apply (R-010, REQ-075) | `orca-apply-render.sh` (v0.10-P10) | planned |
|
||||||
|
| Drift detection (R-010) | `orca-drift.sh` (v0.10-P10) | planned |
|
||||||
|
| Per-node state collection | `orca-collect.sh` (v0.10-P09) | planned |
|
||||||
|
| Lead aggregation | `orca-aggregate.sh` (v0.10-P09) | planned |
|
||||||
|
| Credential cleanup (5-min shred) | `orca-cleanup-credentials.sh` (v0.10) | planned |
|
||||||
|
| Render-bundle validation (C-16) | `orca-verify-render.sh` (shipped this phase P00) | ✅ shipped |
|
||||||
|
| Structured logging (C-17) | `orca-log.sh` (shipped this phase P00) | ✅ shipped |
|
||||||
|
|
||||||
|
## Review cadence
|
||||||
|
|
||||||
|
This map is reviewed at each phase that introduces or modifies a bash
|
||||||
|
script. The security-engineer persona reviews the SSH trust surface; the
|
||||||
|
devops-engineer persona reviews the bash tooling gate (C-15..C-18).
|
||||||
@@ -1,11 +1,20 @@
|
|||||||
{
|
{
|
||||||
"phase": 1,
|
"phase": "P00",
|
||||||
"stage": "complete",
|
"stage": "verify",
|
||||||
"milestone": "v0.7",
|
"milestone": "v0.9",
|
||||||
"milestone_slug": "hardening-completion",
|
"milestone_slug": "rearchitecture",
|
||||||
"phase_role": "execution",
|
"phase_role": "execution",
|
||||||
"attempts": 0,
|
"attempts": 0,
|
||||||
"updated_at": "2026-08-04T00:05:00Z",
|
"updated_at": "2026-08-05T02:45:00Z",
|
||||||
"milestone_complete": false,
|
"milestone_complete": false,
|
||||||
"next_milestone": null
|
"gates_cleared": ["C-03", "C-05", "C-06", "C-15", "C-16", "C-17", "C-18"],
|
||||||
}
|
"verify": {
|
||||||
|
"build": "pass",
|
||||||
|
"go_test": "16/16 packages pass",
|
||||||
|
"bats": "20/20 tests pass",
|
||||||
|
"gofmt": "clean",
|
||||||
|
"go_vet": "clean",
|
||||||
|
"verify_reqs": "90 requirements consistent",
|
||||||
|
"shellcheck": "info-level only (no errors)"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -0,0 +1,592 @@
|
|||||||
|
# Grill Report: Orca v0.8 — Coverage & Trust Hardening
|
||||||
|
|
||||||
|
**Date:** 2026-08-04
|
||||||
|
**Reviewer:** ci-griller (red-team, adversarial)
|
||||||
|
**Plan under review:** `.ciagent/PLAN_v0.8.md` (commit 4780e4d)
|
||||||
|
**Branch:** `phase/00-specify` (milestone `milestone/v0.8-coverage-trust-hardening`)
|
||||||
|
**Mode:** Full autonomy
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Methodology
|
||||||
|
|
||||||
|
Every material claim in `PLAN_v0.8.md` and `RESEARCH_v0.8.md` was cross-checked
|
||||||
|
against the actual codebase (verified coverage baselines via `go test -cover`,
|
||||||
|
read `internal/proxmox/bootstrap.go:75-234`, `internal/security/ca.go`,
|
||||||
|
`internal/doctor/doctor.go`, `.ciagent/ROADMAP.md`, `.ciagent/REQUIREMENTS.md`,
|
||||||
|
PERSONAS, ARCHITECTURE) AND the `golang.org/x/crypto` v0.54.0 source for
|
||||||
|
`knownhosts.New` / `checkAddr` behavior. The TOFU-capture claim was not taken
|
||||||
|
on faith — the upstream `checkAddr` (knownhosts.go:370-385) was read directly.
|
||||||
|
|
||||||
|
Findings are scored on the 9 axes. Binding verdicts are **PROCEED**,
|
||||||
|
**PROCEED-WITH-CONDITION** (plan proceeds but must incorporate a named change),
|
||||||
|
or **REPLAN** (axis has a fatal flaw; revise before execution).
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Summary Verdict
|
||||||
|
|
||||||
|
| Verdict | Count |
|
||||||
|
|---------|-------|
|
||||||
|
| PROCEED | 7 |
|
||||||
|
| PROCEED-WITH-CONDITION | 4 |
|
||||||
|
| REPLAN | 0 |
|
||||||
|
|
||||||
|
**Overall verdict: PROCEED-WITH-CONDITION**
|
||||||
|
|
||||||
|
The v0.8 plan is fundamentally sound: scope is right-sized, the no-new-deps
|
||||||
|
promise holds (verified `ssh.FingerprintSHA256` + `knownhosts.Line` are in the
|
||||||
|
existing `golang.org/x/crypto` v0.54.0 dep), the tiered coverage floor (D-047)
|
||||||
|
is realistic per-package with the named seams, and the persona territory
|
||||||
|
collision on `internal/cli/node.go` is explicitly adjudicated in PERSONAS.md
|
||||||
|
(backend owns implementation, lead owns `_test.go`). The 4 conditions below are
|
||||||
|
**targeted correctness fixes**, not scope expansions:
|
||||||
|
|
||||||
|
1. **P02 must add a regression test asserting first-connect Proxmox join
|
||||||
|
succeeds end-to-end** (the latent TOFU bug means v0.6's first-connect has
|
||||||
|
been broken since ship; the fix in T02.6 is correct but must be proven by a
|
||||||
|
test that would have failed pre-fix).
|
||||||
|
2. **P03's verify-reqs regex must match `**COMPLETE**` as a *substring* within
|
||||||
|
the bold span** (v0.2's header `**COMPLETE (merged to main via v0.3)**` is
|
||||||
|
not matched by the current `\*\*COMPLETE\*\*` literal — a silent blind spot).
|
||||||
|
3. **P03 must add a second assertion: every REQUIREMENTS row marked `Complete`
|
||||||
|
must reference a milestone ROADMAP marks COMPLETE** (the reverse direction).
|
||||||
|
The v0.7 `cert_repo_test.go` omission (REQ-053 marked Complete but the test
|
||||||
|
file does not exist) proves forward-direction-only checks miss the most
|
||||||
|
dangerous drift class: *claimed-Complete-but-actually-incomplete*.
|
||||||
|
4. **P02 T02.6's TOFU fix must be reviewed against `doctor proxmox`'s callback
|
||||||
|
(T02.9) as a paired change, not a follow-on** — they share the exact
|
||||||
|
`knownhosts.New` defect; fixing one and not the other in the same phase
|
||||||
|
creates an inconsistent trust surface.
|
||||||
|
|
||||||
|
With these 4 conditions applied, this plan is ready to execute. No REPLAN.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Per-Axis Findings
|
||||||
|
|
||||||
|
### Axis 1 — Business Case
|
||||||
|
|
||||||
|
#### A1-F1 — Is v0.8 the right next milestone, or polish-for-polish's-sake?
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- v0.7 P03 (REQ-055) shipped a ≥50% coverage floor; v0.8 re-baselines six
|
||||||
|
packages still under 50% (engine 8.3%, proxmox 5.1%, cli 27.6%, transport
|
||||||
|
26.3%, store 47.2%, jobspec 47.6%) — **verified identical via `go test
|
||||||
|
-cover`**.
|
||||||
|
- RESEARCH §2.1 surfaces a **latent v0.6 defect**: `knownhosts.New` returns
|
||||||
|
`KeyError{Want:[]}` on first connect and does NOT auto-write. Verified
|
||||||
|
directly in `golang.org/x/crypto@v0.54.0/ssh/knownhosts/knownhosts.go:370-385`
|
||||||
|
(`checkAddr` returns `&KeyError{}` with empty `Want` when no line matches).
|
||||||
|
`bootstrap.go:140-142` treats this as a dial failure. **This means
|
||||||
|
first-connect `orca node join --type proxmox` has been broken since v0.6
|
||||||
|
shipped** (the v0.6 RESEARCH §A.5 claim that `knownhosts.New` "handles both
|
||||||
|
capture and verify" was wrong).
|
||||||
|
- `bootstrap.go:123` comment is literally false: "on first connect it captures
|
||||||
|
the host key" — it does not.
|
||||||
|
|
||||||
|
**Confidence:** 0.90 that v0.8 is the right next milestone.
|
||||||
|
**Verdict:** **PROCEED**. v0.8 is not polish-for-polish: it closes a real
|
||||||
|
security defect (TOFU broken since v0.6), populates a `Result` field that D-045
|
||||||
|
*assumed* was already populated (it isn't — `bootstrap.go:195-198`), and lifts
|
||||||
|
coverage off floors that v0.7 explicitly under-shot. The diminishing-returns
|
||||||
|
risk is real for the 3 zero-test toe-holds (audit/certpaths/cmd-orca), but
|
||||||
|
D-047 tiered them to 50% precisely to avoid the rathole — that call is sound.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### Axis 2 — Scope and Requirements
|
||||||
|
|
||||||
|
#### A2-F1 — Is the TOFU bugfix correctly scoped into P02, or should it be a hotfix on main?
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- The TOFU capture bug (RESEARCH §2.1, PLAN T02.6) is a v0.6 latent defect,
|
||||||
|
not a v0.8 feature. First-connect Proxmox join is broken **today on main**.
|
||||||
|
- PLAN bundles the fix into P02 (trust hardening phase) alongside REQ-058
|
||||||
|
(`--host-key-fingerprint`) and REQ-059 (`key-reset`).
|
||||||
|
- ROADMAP tags run on the v0.7.x patch line: `v0.7.0` (P0) … `v0.7.4` (P04).
|
||||||
|
P02 ships as `v0.7.2` — i.e., the fix lands on a milestone branch, not main,
|
||||||
|
and only reaches main at P04 merge (`v0.7.4`).
|
||||||
|
|
||||||
|
**Confidence:** 0.62 that bundling into P02 is the right call (low confidence —
|
||||||
|
this is a judgment call with real downside).
|
||||||
|
**Verdict:** **PROCEED-WITH-CONDITION.** The fix is correctly designed (T02.6's
|
||||||
|
`KeyError{Want:[]}` capture-and-persist is the right shape), but the plan must
|
||||||
|
either (a) document explicitly *why* this isn't hotfixed on main (e.g., "no
|
||||||
|
operator has hit first-connect yet because all deployments pre-populate
|
||||||
|
`known_hosts` manually — confirmed by the v0.6 ship audit"), OR (b) flag the
|
||||||
|
bug in the P04 audit as a v0.6 ship-defect with a post-mortem note. **The plan
|
||||||
|
currently treats T02.6 as a feature task; it is a bugfix for shipped code and
|
||||||
|
must be labeled as such** so the P04 audit can distinguish "new hardening" from
|
||||||
|
"closing a v0.6 gap." Blast radius if T02.6's fix is wrong: every existing
|
||||||
|
Proxmox node's `known_hosts` could be re-pinned on next join — moderate, but
|
||||||
|
mitigated by T02.10 case 3/4/5 integration tests.
|
||||||
|
|
||||||
|
**Condition:** Add a note to T02.6 in PLAN marking it as a **v0.6 ship-defect
|
||||||
|
bugfix** (not a v0.8 feature), and ensure P04 audit (T04.2) records it as such.
|
||||||
|
|
||||||
|
#### A2-F2 — Are the 3 zero-test packages worth a 50% toe-hold, or scope creep?
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- `cmd/orca` is 15 LOC of glue (`main()` → `cli.Execute()`). 50% coverage = ~7
|
||||||
|
lines. RESEARCH §1.1, §5 pitfall #6 explicitly flags the effort:coverage
|
||||||
|
ratio as poor.
|
||||||
|
- `internal/certpaths` is 64 LOC of pure path-join functions. 50% is trivial.
|
||||||
|
- `internal/audit` is 125 LOC, 4 exported funcs. 50% is trivial.
|
||||||
|
- D-047 explicitly tiered these to 50% to avoid a coverage rathole; v0.9 can
|
||||||
|
raise the floor.
|
||||||
|
|
||||||
|
**Confidence:** 0.85.
|
||||||
|
**Verdict:** **PROCEED.** The tiered floor is the right call. The
|
||||||
|
`cmd/orca` toe-hold is low-value but low-cost (one `run() int` refactor + one
|
||||||
|
smoke test), and dropping it would leave a `covdata` tooling error in CI output
|
||||||
|
that looks like a broken build to a casual reader. Keeping it at 50% is
|
||||||
|
defensible.
|
||||||
|
|
||||||
|
#### A2-F3 — Scope size: 4 REQs, 37 tasks — too lean, too fat, or right?
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- 37 tasks, 36 must-haves, 4 phases each shipping a patch. Comparable to v0.7
|
||||||
|
(5 phases, similar task density).
|
||||||
|
- P01 is the heaviest (12 tasks, 9 packages) — the risk concentration is here.
|
||||||
|
|
||||||
|
**Confidence:** 0.80.
|
||||||
|
**Verdict:** **PROCEED.** Right-sized for an NFR milestone. P01 density is the
|
||||||
|
watch item (see Axis 5).
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### Axis 3 — Architecture and Technical Feasibility
|
||||||
|
|
||||||
|
#### A3-F1 — Do the proxmox `sessionRunner` and engine `peerDispatcher` seams leak test concerns into production?
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- T01.1 `sessionRunner` (`internal/proxmox/bootstrap.go`): 1 interface,
|
||||||
|
~10 LOC, `CombinedOutput(cmd) ([]byte, error)`. Default impl wraps
|
||||||
|
`*ssh.Client.NewSession().CombinedOutput(...)`. Backward compatible —
|
||||||
|
existing callers unchanged. This is the **same pattern as the existing
|
||||||
|
`sshDialer` seam** (`bootstrap.go:201-213`), which shipped in v0.6 without
|
||||||
|
concern. The seam is a standard testability extraction, not a test concern
|
||||||
|
leak.
|
||||||
|
- T01.2 `peerDispatcher` (`internal/engine/dispatcher.go`): **conditional** —
|
||||||
|
only added if T01.4 cannot hit 70% via `httptest.NewTLSServer` alone. Plan
|
||||||
|
explicitly prefers `httptest.NewTLSServer` (RESEARCH §1.3 gap #2, §5 pitfall
|
||||||
|
#8). This is the right ordering: try the stdlib test fixture first, add the
|
||||||
|
seam only if needed.
|
||||||
|
|
||||||
|
**Confidence:** 0.88.
|
||||||
|
**Verdict:** **PROCEED.** Both seams are backward-compatible interface
|
||||||
|
extractions matching an existing pattern (`sshDialer`). No test-concern leak.
|
||||||
|
The conditional-gate on T01.2 is correctly conservative.
|
||||||
|
|
||||||
|
#### A3-F2 — Does P02's trust work stay within the existing security boundary?
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- P02 touches `internal/proxmox/bootstrap.go` (pinned callback, TOFU fix),
|
||||||
|
`internal/cli/node.go` (flag + subcommand), `internal/security/sshkey.go`
|
||||||
|
(fingerprint helper), `internal/doctor/doctor.go` (T02.9 TOFU fix). All
|
||||||
|
within the existing SSH trust surface established in v0.6.
|
||||||
|
- No new crypto, no new CA, no new X.509. `ssh.FingerprintSHA256` is in the
|
||||||
|
existing `golang.org/x/crypto` v0.54.0 dep (verified: not a new direct dep).
|
||||||
|
- PERSONAS correctly keeps `security-engineer` deactivated — the work is SSH
|
||||||
|
dialer + known_hosts file manipulation, not new security architecture.
|
||||||
|
|
||||||
|
**Confidence:** 0.90.
|
||||||
|
**Verdict:** **PROCEED.** Boundary is respected.
|
||||||
|
|
||||||
|
#### A3-F3 — T02.9 (doctor proxmox TOFU fix) is a paired change with T02.6, not a follow-on
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- `internal/doctor/doctor.go:412` uses the **exact same** `knownhosts.New(...)`
|
||||||
|
callback pattern as `bootstrap.go:125`. Both share the latent defect.
|
||||||
|
- T02.9 is listed as a separate task ("Apply the TOFU capture-fix to `doctor
|
||||||
|
proxmox` probe") but is in the same Wave 2 as T02.6. If T02.6 lands and T02.9
|
||||||
|
doesn't (e.g., a mid-phase blocker), the trust surface is **inconsistent**:
|
||||||
|
join captures, doctor fails.
|
||||||
|
|
||||||
|
**Confidence:** 0.75.
|
||||||
|
**Verdict:** **PROCEED-WITH-CONDITION.** T02.6 and T02.9 must be reviewed as a
|
||||||
|
paired change in P02 verification — the phase is not done until BOTH callbacks
|
||||||
|
use the capture-fix wrapper. Add to P02 Verification: "doctor proxmox
|
||||||
|
first-connect → captures + succeeds (mirrors T02.10 case 3 for bootstrap)."
|
||||||
|
|
||||||
|
**Condition:** Add a P02 verification line asserting doctor proxmox
|
||||||
|
first-connect parity with bootstrap.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### Axis 4 — People, Skills, and Organization
|
||||||
|
|
||||||
|
#### A4-F1 — Territory collision on `internal/cli/node.go`
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- PERSONAS.md line 62: lead-developer territory = `internal/cli/**`.
|
||||||
|
- PERSONAS.md line 70: backend-engineer territory = `internal/cli/node.go`.
|
||||||
|
- PERSONAS.md line 107 explicitly adjudicates: "backend owns the command
|
||||||
|
implementation; lead owns the test files (`node_test.go`)."
|
||||||
|
- Territory mode is `warn` (not `block`) — collisions log but don't fail.
|
||||||
|
|
||||||
|
**Confidence:** 0.82.
|
||||||
|
**Verdict:** **PROCEED.** The collision is **explicitly adjudicated** in
|
||||||
|
PERSONAS.md with a clean boundary (impl vs test files). This is the right
|
||||||
|
answer. The `warn` mode means a backend commit touching `node_test.go` (or a
|
||||||
|
lead commit touching `node.go` impl) would log — acceptable for a 3-persona
|
||||||
|
team. No replan.
|
||||||
|
|
||||||
|
#### A4-F2 — Key-person dependency: is the 3-persona roster sufficient?
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- 3 active personas, all retained from v0.7. No phase-specific personas.
|
||||||
|
- backend-engineer owns 60%+ of P02 (the security-critical phase). If
|
||||||
|
backend-engineer is unavailable, P02 stalls entirely.
|
||||||
|
|
||||||
|
**Confidence:** 0.70.
|
||||||
|
**Verdict:** **PROCEED.** Key-person risk is real but inherent to a 3-persona
|
||||||
|
NFR milestone. The work is not novel (refining existing surface), so the bus
|
||||||
|
factor is acceptable for hardening. Flagged, not blocking.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### Axis 5 — Timeline and Estimates
|
||||||
|
|
||||||
|
#### A5-F1 — Is the 70% coverage target for 6 packages in one phase (P01) realistic?
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- RESEARCH §1.1 + §1.4 per-package achievability assessments:
|
||||||
|
- engine → 70% REALISTIC (with LocalExecutor stubs + `openTestDB`).
|
||||||
|
- proxmox → 70% REALISTIC **but requires the `sessionRunner` seam (T01.1)** —
|
||||||
|
without it, only 50-55% (validation paths + sudoersContent asserts, already
|
||||||
|
done).
|
||||||
|
- cli → 70% AMBITIOUS (17 files, ~2000 LOC); RESEARCH says "55-65% is more
|
||||||
|
realistic for one phase" even with `daemon.go` excluded.
|
||||||
|
- transport → 70% REALISTIC (`httptest.NewTLSServer` is standard).
|
||||||
|
- store → 70% REALISTIC (cert_repo_test.go gap is the main lift).
|
||||||
|
- jobspec → 70% REALISTIC (easiest of the six).
|
||||||
|
- **`internal/cli` is the swing package.** RESEARCH explicitly says 55-65% is
|
||||||
|
the realistic single-phase outcome, not 70%. The plan sets the floor at 70%
|
||||||
|
"excluding daemon.go" — but even excluding daemon.go, RESEARCH's own evidence
|
||||||
|
says 70% is a stretch.
|
||||||
|
|
||||||
|
**Confidence:** 0.65 (split: 5 of 6 packages at 0.85, cli at 0.45).
|
||||||
|
**Verdict:** **PROCEED-WITH-CONDITION.** The plan must add an explicit fallback
|
||||||
|
for `internal/cli`: if T01.6 hits ≥65% (excluding daemon.go) but not 70% after
|
||||||
|
a reasonable effort, the phase ships at 65% with a documented note + a v0.9
|
||||||
|
follow-up to lift to 70%. **Hard-requiring 70% on cli risks a coverage rathole
|
||||||
|
that delays the entire milestone** (P02/P03 are gated on P01 ship). The other 5
|
||||||
|
packages at 70% is realistic.
|
||||||
|
|
||||||
|
**Condition:** Add to T01.6 acceptance criterion: "If ≥65% (excluding
|
||||||
|
daemon.go) is achieved but 70% is not after Wave 2 effort, document the gap in
|
||||||
|
the task comment + record a v0.9 follow-up; ship at 65%. Do NOT block P02/P03
|
||||||
|
on the last 5% of cli coverage." (This mirrors RESEARCH §1.4's own flag, which
|
||||||
|
the plan currently does not carry forward as an escape valve.)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### Axis 6 — Budget and Financial Realism
|
||||||
|
|
||||||
|
#### A6-F1 — Zero new deps: is that realistic given P02's needs?
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- `ssh.FingerprintSHA256`: verified in `golang.org/x/crypto/ssh` (direct dep
|
||||||
|
since v0.6 D-030).
|
||||||
|
- `knownhosts.Line` / `Normalize` / `KeyError`: same `golang.org/x/crypto`
|
||||||
|
module (already imported in `bootstrap.go:32` and `doctor.go:29`).
|
||||||
|
- `verify-reqs`: stdlib only (`regexp`, `os`, `fmt`).
|
||||||
|
- `go.mod` unchanged by v0.8 (PLAN line 62).
|
||||||
|
|
||||||
|
**Confidence:** 0.95.
|
||||||
|
**Verdict:** **PROCEED.** Zero-new-deps is verified and realistic.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### Axis 7 — Risks, Assumptions, and Dependencies
|
||||||
|
|
||||||
|
#### A7-F1 — The 10 pitfalls: are mitigations real or hand-waves?
|
||||||
|
|
||||||
|
**Evidence (spot-check of the 4 most material pitfalls):**
|
||||||
|
- **Pitfall #1 (TOFU broken):** Mitigation T02.6 is **concrete and correct** —
|
||||||
|
wrap `knownhosts.New`, capture on `KeyError{Want:[]}` via `knownhosts.Line` +
|
||||||
|
`security.WriteAtomic`, return nil. Verified against x/crypto v0.54.0
|
||||||
|
`checkAddr` semantics. **Real mitigation.**
|
||||||
|
- **Pitfall #2 (Result.HostKeyFingerprint never populated):** T02.7 adds
|
||||||
|
`ssh.FingerprintSHA256(hostKey)`. 1-line once host key is available. **Real.**
|
||||||
|
- **Pitfall #3 (no sessionRunner seam):** T01.1 adds it, ~10 LOC. **Real.**
|
||||||
|
- **Pitfall #10 (writeAtomic unexported):** T02.2 exports it. Verified
|
||||||
|
`ca.go:305` — `func writeAtomic(...)` is indeed unexported. **Real.**
|
||||||
|
|
||||||
|
**Confidence:** 0.88.
|
||||||
|
**Verdict:** **PROCEED.** Mitigations are concrete, not hand-waves.
|
||||||
|
|
||||||
|
#### A7-F2 — TOFI bugfix blast radius if P02's fix is wrong
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- T02.6 changes the `HostKeyCallback` for every `orca node join --type proxmox`
|
||||||
|
+ every `doctor proxmox` probe. If the capture-and-persist logic is wrong,
|
||||||
|
every existing Proxmox node's `known_hosts` could be corrupted (e.g.,
|
||||||
|
duplicate entries, wrong-format lines, partial writes on crash).
|
||||||
|
- Mitigations: T02.10 integration tests (cases 3/4/5 cover first-connect,
|
||||||
|
second-connect, mismatch); AD-029 atomic rewrite via `security.WriteAtomic`.
|
||||||
|
- **Gap:** no test for "known_hosts already has an entry, join re-connects" —
|
||||||
|
i.e., the idempotent re-run path after the fix. T02.10 case 4 covers
|
||||||
|
second-connect-match, but not "known_hosts was written by the OLD (broken)
|
||||||
|
code path and is now being read by the NEW code path."
|
||||||
|
|
||||||
|
**Confidence:** 0.70.
|
||||||
|
**Verdict:** **PROCEED-WITH-CONDITION.** T02.10 must add a case for
|
||||||
|
"known_hosts pre-populated in the expected format (e.g., from a manual
|
||||||
|
`ssh-keyscan` or a prior v0.6 deployment that somehow succeeded) →
|
||||||
|
second-connect matches + succeeds." This covers the migration path from
|
||||||
|
v0.6's (broken) state to v0.8's fixed state.
|
||||||
|
|
||||||
|
**Condition:** Add T02.10 case 7: "known_hosts pre-populated with a valid
|
||||||
|
OpenSSH line for the host → connect matches + succeeds (covers v0.6→v0.8
|
||||||
|
migration)."
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### Axis 8 — Governance, Decision-Making, and Communication
|
||||||
|
|
||||||
|
#### A8-F1 — Does `make verify-reqs` actually prevent drift, or is it cosmetic?
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- T03.1 regex (PLAN line 216):
|
||||||
|
- ROADMAP milestone-complete: `^##\s*Milestone\s+v0\.\d+:.*—\s*\*\*COMPLETE\*\*`
|
||||||
|
- REQUIREMENTS row: `^\|\s*(REQ-\d+)\s*\|.*?\|\s*\*\*(Complete|Pending)\*\*\s*\|`
|
||||||
|
- **ROADMAP v0.2 header (line 23):** `## Milestone v0.2: Networking,
|
||||||
|
Observability, Security Hardening — **COMPLETE (merged to main via v0.3)**`
|
||||||
|
- The regex `\*\*COMPLETE\*\*` requires the literal `**COMPLETE**` with closing
|
||||||
|
`**` immediately after `COMPLETE`. v0.2's header has `**COMPLETE (merged to
|
||||||
|
main via v0.3)**` — the `**` closes after the parenthetical, NOT after
|
||||||
|
`COMPLETE`. **The regex does NOT match v0.2 as complete.**
|
||||||
|
- **Consequence:** all v0.2 REQs (REQ-011, 014, 023, 025-040) are **silently
|
||||||
|
exempted** from the check. A stale v0.2 REQ-035 row (marked Pending) would
|
||||||
|
NOT fail the gate.
|
||||||
|
- **ROADMAP v0.6 has TWO headers** (line 92 without COMPLETE, line 94 with) —
|
||||||
|
the regex matches line 94, but the duplicate is a markdown smell that could
|
||||||
|
confuse the milestone→REQ mapping if the parser takes the first match.
|
||||||
|
|
||||||
|
**Confidence:** 0.92 (high — the regex mismatch is verifiable).
|
||||||
|
**Verdict:** **PROCEED-WITH-CONDITION.** The regex must match `**COMPLETE**`
|
||||||
|
as a *substring within the bold span*, not as a literal `**COMPLETE**` token.
|
||||||
|
Change to `—\s*\*\*[^*]*COMPLETE[^*]*\*\*` (matches `**COMPLETE**`,
|
||||||
|
`**COMPLETE (merged to main via v0.3)**`, and any future variant). Add a
|
||||||
|
golden-file test case (T03.2) with the v0.2-style parenthetical header to
|
||||||
|
prevent regression.
|
||||||
|
|
||||||
|
**Condition:** T03.1 regex changed to substring-match COMPLETE within the bold
|
||||||
|
span; T03.2 adds a golden fixture with `**COMPLETE (merged to main via v0.3)**`.
|
||||||
|
|
||||||
|
#### A8-F2 — Is the single-direction check (ROADMAP→REQUIREMENTS) enough?
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- PLAN line 35-37 explicitly scopes out the reverse direction: "forward
|
||||||
|
direction (ROADMAP-shipped → REQUIREMENTS Complete) is the priority per the
|
||||||
|
v0.7 drift that motivated REQ-060."
|
||||||
|
- **But the v0.7 drift had TWO symptoms:**
|
||||||
|
1. ROADMAP said COMPLETE, REQUIREMENTS said Pending (forward drift — caught
|
||||||
|
by the current check).
|
||||||
|
2. **REQ-053 was marked Complete in REQUIREMENTS, but
|
||||||
|
`internal/store/cert_repo_test.go` was never written** — verified: only
|
||||||
|
`cert_repo.go` exists in `internal/store/`. The "Complete" status was
|
||||||
|
false. **No markdown-based check can catch this** (it's a code-vs-doc
|
||||||
|
drift, not a doc-vs-doc drift).
|
||||||
|
- The reverse-direction check (REQUIREMENTS Complete ↔ ROADMAP COMPLETE) would
|
||||||
|
catch a different class: a REQ marked Complete in REQUIREMENTS for a
|
||||||
|
milestone ROADMAP does NOT mark COMPLETE (e.g., premature marking). This is
|
||||||
|
a cheaper class of drift but still real.
|
||||||
|
|
||||||
|
**Confidence:** 0.78.
|
||||||
|
**Verdict:** **PROCEED-WITH-CONDITION.** Add the reverse-direction assertion
|
||||||
|
to T03.1 (it's ~10 LOC on top of the existing parser — same maps, just diff
|
||||||
|
both ways). Document explicitly that **no markdown check can catch the
|
||||||
|
code-vs-doc drift** (REQ-053 case) — that requires a code-level audit
|
||||||
|
(`ciagent-audit` in P04). The plan should note this as a known limitation of
|
||||||
|
REQ-060, not pretend the gate is complete.
|
||||||
|
|
||||||
|
**Condition:** T03.1 adds reverse-direction assertion; PLAN adds a note that
|
||||||
|
REQ-060 catches doc-vs-doc drift only, not code-vs-doc (the REQ-053
|
||||||
|
cert_repo_test.go case).
|
||||||
|
|
||||||
|
#### A8-F3 — Is there a "stop the project" trigger?
|
||||||
|
|
||||||
|
**Evidence:** P04 (T04.1-T04.9) is the final review + ship. No explicit
|
||||||
|
"stop" trigger if P01 coverage stalls or P02 TOFU fix proves unfixable.
|
||||||
|
|
||||||
|
**Confidence:** 0.60.
|
||||||
|
**Verdict:** **PROCEED.** The 4-phase structure with per-phase tags means a
|
||||||
|
stall is visible (phase tag doesn't ship). Acceptable for an NFR milestone.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
### Axis 9 — Change, Adoption, and Operational Readiness
|
||||||
|
|
||||||
|
#### A9-F1 — Who benefits from v0.8? Is there operator pull for `--host-key-fingerprint`?
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- `--host-key-fingerprint` (REQ-058) is operator-facing: pre-pinning a
|
||||||
|
Proxmox host's SSH key before first join. This is the standard
|
||||||
|
high-security-deployment pattern (the v0.6 D-035 caveat explicitly promised
|
||||||
|
it as a "future enhancement").
|
||||||
|
- `orca node key-reset` (REQ-059) is operator-facing: the `ssh-keygen -R`
|
||||||
|
equivalent for orca's known_hosts.
|
||||||
|
- The TOFU bugfix (T02.6) benefits **every operator who has tried
|
||||||
|
first-connect Proxmox join since v0.6** — i.e., it fixes a feature that was
|
||||||
|
advertised as working but wasn't.
|
||||||
|
- Coverage uplift (REQ-057) is developer-facing (no operator pull).
|
||||||
|
- verify-reqs (REQ-060) is internal-governance (no operator pull).
|
||||||
|
|
||||||
|
**Confidence:** 0.82.
|
||||||
|
**Verdict:** **PROCEED.** The trust features have real operator pull
|
||||||
|
(pre-pinning is a documented security best practice; the v0.6 caveat promised
|
||||||
|
it). The coverage + hygiene work is internal-debt paydown — justified by the
|
||||||
|
v0.7 under-shot, not by operator demand. The mix is appropriate for an NFR
|
||||||
|
milestone.
|
||||||
|
|
||||||
|
#### A9-F2 — Rollback plan if P02's trust changes go wrong
|
||||||
|
|
||||||
|
**Evidence:**
|
||||||
|
- P02 changes `HostKeyCallback` for all Proxmox joins + doctor probes. If the
|
||||||
|
capture-fix corrupts `known_hosts`, the rollback is: revert the phase commit
|
||||||
|
+ manually restore `known_hosts` from backup.
|
||||||
|
- No data migration in P02 (known_hosts is a flat file; atomic rewrite via
|
||||||
|
`WriteAtomic` preserves crash safety).
|
||||||
|
- `key-reset` (T02.8) is local-only (D-046) — no remote side effects to
|
||||||
|
reverse.
|
||||||
|
|
||||||
|
**Confidence:** 0.80.
|
||||||
|
**Verdict:** **PROCEED.** Rollback is straightforward (revert + file restore).
|
||||||
|
The atomic-rewrite requirement (AD-029) is the right mitigation.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Binding Verdicts Table
|
||||||
|
|
||||||
|
| # | Axis | Finding | Verdict | Condition | Confidence |
|
||||||
|
|---|------|---------|---------|-----------|------------|
|
||||||
|
| A2-F1 | Scope | TOFU bugfix is a v0.6 ship-defect bundled into P02 as a feature task | PROCEED-WITH-CONDITION | Label T02.6 as a v0.6 bugfix in PLAN; P04 audit records it as a ship-defect closure | 0.62 |
|
||||||
|
| A2-F2 | Scope | 3 zero-test packages at 50% toe-hold | PROCEED | — | 0.85 |
|
||||||
|
| A2-F3 | Scope | 37 tasks / 4 phases size | PROCEED | — | 0.80 |
|
||||||
|
| A1-F1 | Business | v0.8 is the right next milestone (not polish) | PROCEED | — | 0.90 |
|
||||||
|
| A3-F1 | Architecture | sessionRunner + peerDispatcher seams do not leak test concerns | PROCEED | — | 0.88 |
|
||||||
|
| A3-F2 | Architecture | P02 stays within existing security boundary | PROCEED | — | 0.90 |
|
||||||
|
| A3-F3 | Architecture | T02.6 + T02.9 are paired changes (bootstrap + doctor share the defect) | PROCEED-WITH-CONDITION | Add P02 verification line for doctor proxmox first-connect parity with bootstrap | 0.75 |
|
||||||
|
| A4-F1 | People | internal/cli/node.go territory collision adjudicated | PROCEED | — | 0.82 |
|
||||||
|
| A4-F2 | People | Key-person risk on backend-engineer in P02 | PROCEED | — | 0.70 |
|
||||||
|
| A5-F1 | Timeline | 70% cli coverage in one phase is a stretch (RESEARCH says 55-65%) | PROCEED-WITH-CONDITION | Add escape valve: ship cli at 65% if 70% not reached after Wave 2; do not block P02/P03 | 0.65 |
|
||||||
|
| A6-F1 | Budget | Zero new deps verified | PROCEED | — | 0.95 |
|
||||||
|
| A7-F1 | Risks | 10 pitfalls mitigations are concrete | PROCEED | — | 0.88 |
|
||||||
|
| A7-F2 | Risks | TOFU fix blast radius — no migration-path test | PROCEED-WITH-CONDITION | Add T02.10 case 7: known_hosts pre-populated → second-connect matches (v0.6→v0.8 migration) | 0.70 |
|
||||||
|
| A8-F1 | Governance | verify-reqs regex does not match v0.2's `**COMPLETE (merged...)**` header | PROCEED-WITH-CONDITION | Change regex to substring-match COMPLETE within bold span; add golden fixture | 0.92 |
|
||||||
|
| A8-F2 | Governance | Single-direction check misses reverse drift + code-vs-doc drift (REQ-053 case) | PROCEED-WITH-CONDITION | Add reverse-direction assertion; document that code-vs-doc drift is out of scope for REQ-060 | 0.78 |
|
||||||
|
| A8-F3 | Governance | No explicit "stop" trigger | PROCEED | — | 0.60 |
|
||||||
|
| A9-F1 | Adoption | Operator pull exists for trust features; coverage/hygiene is internal debt | PROCEED | — | 0.82 |
|
||||||
|
| A9-F2 | Adoption | Rollback plan is straightforward (revert + file restore) | PROCEED | — | 0.80 |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Required Plan Changes (4 conditions)
|
||||||
|
|
||||||
|
1. **T02.6 labeling (A2-F1):** Add a note to T02.6 in `PLAN_v0.8.md` marking
|
||||||
|
it as a **v0.6 ship-defect bugfix** (first-connect Proxmox join has been
|
||||||
|
broken since v0.6 shipped due to `knownhosts.New` returning
|
||||||
|
`KeyError{Want:[]}` with no capture-and-persist). P04 audit (T04.2) must
|
||||||
|
record it as a ship-defect closure, not a v0.8 feature.
|
||||||
|
|
||||||
|
2. **P02 verification parity for doctor (A3-F3):** Add to Phase 2 Verification:
|
||||||
|
"`doctor proxmox` first-connect on a node with empty known_hosts → captures
|
||||||
|
the key + writes known_hosts + probe succeeds (mirrors T02.10 case 3 for
|
||||||
|
bootstrap). T02.6 and T02.9 are a paired change; the phase is not complete
|
||||||
|
until both callbacks use the capture-fix wrapper."
|
||||||
|
|
||||||
|
3. **T01.6 cli coverage escape valve (A5-F1):** Add to T01.6 acceptance
|
||||||
|
criterion: "If ≥65% (excluding `daemon.go`) is achieved but 70% is not after
|
||||||
|
Wave 2 effort, document the gap in a test-file comment + record a v0.9
|
||||||
|
follow-up; ship P01 at 65% for cli. Do NOT block P02/P03 on the last 5% of
|
||||||
|
cli coverage." (Carries forward RESEARCH §1.4's own flag as an explicit
|
||||||
|
escape valve.)
|
||||||
|
|
||||||
|
4. **verify-reqs regex + reverse direction (A8-F1 + A8-F2):**
|
||||||
|
- Change T03.1 ROADMAP-complete regex from
|
||||||
|
`^##\s*Milestone\s+v0\.\d+:.*—\s*\*\*COMPLETE\*\*` to
|
||||||
|
`^##\s*Milestone\s+v0\.\d+:.*—\s*\*\*[^*]*COMPLETE[^*]*\*\*` (substring
|
||||||
|
match within the bold span — handles `**COMPLETE**`,
|
||||||
|
`**COMPLETE (merged to main via v0.3)**`, and future variants).
|
||||||
|
- Add T03.2 golden fixture: a ROADMAP with
|
||||||
|
`**COMPLETE (merged to main via v0.3)**` → assert the milestone is
|
||||||
|
detected as complete.
|
||||||
|
- Add reverse-direction assertion to T03.1: every REQUIREMENTS row marked
|
||||||
|
`**Complete**` must reference a milestone ROADMAP marks COMPLETE (catches
|
||||||
|
premature-Complete drift).
|
||||||
|
- Add a PLAN note: "REQ-060 catches doc-vs-doc drift only. Code-vs-doc
|
||||||
|
drift (e.g., REQ-053 marked Complete but `cert_repo_test.go` missing —
|
||||||
|
verified missing in v0.7 ship) is NOT caught by this gate; it requires
|
||||||
|
the P04 `ciagent-audit` code-level review."
|
||||||
|
|
||||||
|
Additionally (lower-priority, from A7-F2):
|
||||||
|
|
||||||
|
5. **T02.10 case 7 (A7-F2):** Add integration test case: "known_hosts
|
||||||
|
pre-populated with a valid OpenSSH line for the host (simulating a v0.6
|
||||||
|
deployment or manual `ssh-keyscan`) → connect matches + succeeds. Covers
|
||||||
|
the v0.6→v0.8 migration path."
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Escalations
|
||||||
|
|
||||||
|
None. All 9 axes resolved at confidence ≥ 0.60. No axis requires escalation to
|
||||||
|
the operator; the 4 conditions are within the plan-author's authority to apply
|
||||||
|
before P01 execution begins.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## What the Plan Is NOT Doing (and should it?)
|
||||||
|
|
||||||
|
- **Not lifting the 3 zero-test packages to 70%.** Correct per D-047 — deferred
|
||||||
|
to v0.9. Not a gap.
|
||||||
|
- **Not adding a `peerDispatcher` seam unless needed.** Correct — conditional
|
||||||
|
on T01.4's 70% via `httptest.NewTLSServer`. Not a gap.
|
||||||
|
- **Not pre-populating `known_hosts` from a remote keyscan API.** Correct —
|
||||||
|
TOFU + manual `--host-key-fingerprint` cover the v0.8 surface. Not a gap.
|
||||||
|
- **Not catching code-vs-doc drift in verify-reqs.** **Known limitation** —
|
||||||
|
REQ-060 is a markdown-vs-markdown check. The REQ-053
|
||||||
|
`cert_repo_test.go`-missing case proves this class of drift is real. P04
|
||||||
|
`ciagent-audit` is the backstop. Documented in condition #4.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Simplest 80%-of-the-value version
|
||||||
|
|
||||||
|
If forced to cut v0.8 to its smallest valuable form: **keep P02 (trust
|
||||||
|
hardening + TOFU bugfix) and P03 (verify-reqs); drop P01's coverage uplift for
|
||||||
|
the 3 zero-test packages + cli.** The TOFU bugfix alone (T02.6 + T02.9) fixes a
|
||||||
|
shipped security defect — that's the highest-value work. The verify-reqs gate
|
||||||
|
prevents the v0.7 drift from recurring. The coverage uplift on the 6
|
||||||
|
under-50% packages is valuable but not urgent; the 3 zero-test toe-holds are
|
||||||
|
the lowest-value work in the milestone. **The plan as written does not over-
|
||||||
|
scope** — it includes all of the above because the marginal cost is low — but
|
||||||
|
if P01 slips, the 3 toe-holds + cli are the first cuts to make.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## What Would Have to Be True for v0.8 to Succeed in the Next 90 Days
|
||||||
|
|
||||||
|
1. The `sessionRunner` seam (T01.1) unlocks proxmox 70% — **plausible** (same
|
||||||
|
pattern as the existing `sshDialer` seam).
|
||||||
|
2. `httptest.NewTLSServer` suffices for transport 70% without a new seam —
|
||||||
|
**plausible** (standard Go testing fixture).
|
||||||
|
3. The TOFU capture-fix (T02.6) is correct — **plausible** (verified against
|
||||||
|
x/crypto v0.54.0 semantics; integration tests T02.10 cover the cases).
|
||||||
|
4. `verify-reqs` regex matches all ROADMAP milestone header variants — **NOT
|
||||||
|
true today** (v0.2 header mismatch — condition #4 fixes this).
|
||||||
|
5. cli hits 70% in one phase — **NOT confirmed** (RESEARCH says 55-65%;
|
||||||
|
condition #3 adds the escape valve).
|
||||||
|
|
||||||
|
(4) and (5) are the two conditions that move the plan from "optimistic" to
|
||||||
|
"sound." Both are addressed by the 4 required changes.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
**End of grill report.** Apply the 4 conditions to `PLAN_v0.8.md` before P01
|
||||||
|
execution. No REPLAN; no escalations. Overall verdict: **PROCEED-WITH-
|
||||||
|
CONDITION** (confidence 0.78).
|
||||||
@@ -0,0 +1,485 @@
|
|||||||
|
# Grill v0.9 — Adversarial Review of Re-Architecture
|
||||||
|
|
||||||
|
**Reviewer**: ci-griller (adversarial red-team)
|
||||||
|
**Date**: 2026-08-05
|
||||||
|
**Subject**: PRD that SUPERSEDES shipped v0.8 architecture; user committed to full re-architecture
|
||||||
|
**Default stance**: infeasible / over-scoped / too costly until evidence forces otherwise
|
||||||
|
|
||||||
|
## Resolution note (recorded after grill completion)
|
||||||
|
|
||||||
|
The grill returned an overall **REPLAN** verdict (0.74) on three axes
|
||||||
|
(Scope, Migration, Re-architecture Justification). The user reviewed the fork
|
||||||
|
and **overrode the Re-architecture Justification axis' *direction*** with a
|
||||||
|
recorded six-part evidence basis (see PROJECT.md Supersession Table):
|
||||||
|
|
||||||
|
1. The v0.8 daemon model is operationally failing in the target environment.
|
||||||
|
2. step-ca is externally mandated.
|
||||||
|
3. Multi-tenancy is a hard product requirement.
|
||||||
|
4. WASM is a hard workload requirement.
|
||||||
|
5. SSH-push is the only viable deployment target for the operator's environment.
|
||||||
|
6. Simplicity/vision correction — the v0.1-v0.8 daemon model was a wrong turn.
|
||||||
|
|
||||||
|
Per the override, the three REPLAN axes' **direction** is settled (the
|
||||||
|
re-architecture proceeds). Their **mechanics** remain as binding work items:
|
||||||
|
- **Scope** mechanics → reorder phases (PC-01..PC-10), add deprecation sweep
|
||||||
|
phase, split heavy phases.
|
||||||
|
- **Migration** mechanics → split P14 into P14a/P14b/P14c, design migration
|
||||||
|
ordering in v0.9-P00.
|
||||||
|
- **Security** mechanics → threat model in v0.10-P15.5 (C-19).
|
||||||
|
|
||||||
|
The 19 binding conditions (C-01..C-19) and 10 phase challenges (PC-01..PC-10)
|
||||||
|
are adopted in full as execution gates.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Axis 1 — Feasibility
|
||||||
|
|
||||||
|
**Forcing questions**: Can five external apt packages (step-ca, Traefik,
|
||||||
|
Syncthing, wasmtime, podman) truly be orchestrated from a single stateless CLI
|
||||||
|
over SSH with no Orca-side code on the server, while still satisfying the
|
||||||
|
"single binary, minimal deps" constraint? Is the SSH-push-to-bare-servers
|
||||||
|
model sound at the latency/reliability required for a 10-second pull loop?
|
||||||
|
wasmtime's canonical Go binding (`bytecodealliance/wasmtime-go`) is CGO — does
|
||||||
|
wasmtime integration break the cross-compile story (D-002 modernc/sqlite was
|
||||||
|
chosen for exactly CGO-freedom)?
|
||||||
|
|
||||||
|
**Evidence**: Constraint conflict between PROJECT.md:5 ("no container runtime")
|
||||||
|
and PRD R-001 (podman as one of 5 runtimes). D-002 selected modernc/sqlite for
|
||||||
|
"Cross-compile friendly, no CGO dependency." No evidence in the PRD that a
|
||||||
|
CGO-free wasmtime binding exists. The PRD itself was not checked in (now
|
||||||
|
resolved: `.ciagent/PRD_v0.9.md`).
|
||||||
|
|
||||||
|
**Verdict**: PROCEED-WITH-CONDITION
|
||||||
|
**Confidence**: 0.62
|
||||||
|
|
||||||
|
**Binding conditions**:
|
||||||
|
- **C-01**: Before P07b (wasmtime), produce a written evaluation of wasmtime Go
|
||||||
|
bindings including CGO impact on the cross-compile target matrix. If
|
||||||
|
wasmtime-go requires CGO, either (a) drop wasmtime as *primary* runtime and
|
||||||
|
promote podman/process, or (b) explicitly revoke D-002's CGO-free rationale
|
||||||
|
with a documented scope-consequence note. No silent reversal.
|
||||||
|
- **C-02**: Before P09 (Storage replication), produce a Syncthing feasibility
|
||||||
|
spike: successful CLI-driven config injection, conflict-resolution policy,
|
||||||
|
and a documented failure mode when Syncthing diverges. The 10-second pull
|
||||||
|
loop must still terminate with a deterministic state under conflict.
|
||||||
|
- **C-03**: The PRD must be checked into `.ciagent/` before any v0.9 phase
|
||||||
|
begins execution. ✅ Resolved — committed as `.ciagent/PRD_v0.9.md`.
|
||||||
|
|
||||||
|
**Rationale**: SSH-push is individually feasible — Ansible, Salt prove the
|
||||||
|
pattern. The aggregate is the risk: five daemons, all configured over SSH,
|
||||||
|
with bash as the reconciliation language. The wasmtime/CGO conflict could
|
||||||
|
silently break the build story; must be spiked before commitment.
|
||||||
|
|
||||||
|
## Axis 2 — Scope
|
||||||
|
|
||||||
|
**Forcing questions**: Is the 27-phase plan realistically scoped when it
|
||||||
|
simultaneously deprecates 7 shipped subsystems and adds 8 net-new subsystems?
|
||||||
|
The deprecation of ~10k lines of shipped daemon/transport/CA code is not listed
|
||||||
|
as a phase. v0.9 P0a..P10 ship 10 phases of workload features before the
|
||||||
|
transactional control plane (R-010 deferred to v0.10 P10) — is that intentional
|
||||||
|
or a sequencing error? Hidden requirements (step-ca self-upgrade, master.key
|
||||||
|
rotation, Syncthing version drift)?
|
||||||
|
|
||||||
|
**Evidence**: v0.9 phase ordering ships P0a..P10 workloads, then P10 lead rules
|
||||||
|
+ migration *last*. The transactional plane (R-010) is deferred to v0.10 P10 —
|
||||||
|
two milestones away. v0.8 was a 4-phase NFR milestone; v0.6 was 4-phase feature.
|
||||||
|
The PRD's v0.9 (11) + v1.0 (16) = 27 phases is 3-4× prior milestone size with
|
||||||
|
no evidence the throughput model was re-validated. No phase is labeled
|
||||||
|
"deprecate daemon/transport/internal-CA."
|
||||||
|
|
||||||
|
**Verdict**: REPLAN (mechanics — direction settled by override)
|
||||||
|
**Confidence**: 0.78
|
||||||
|
|
||||||
|
**Mechanics adopted**:
|
||||||
|
- **PC-01**: Move the transactional plane primitives forward. The
|
||||||
|
transactional primitives (desired-state, lead-applier, drift, rollback) are
|
||||||
|
the substrate every workload phase depends on. Design spike in v0.9-P00;
|
||||||
|
full implementation in v0.10-P10 per PRD ordering (workloads first is accepted
|
||||||
|
given the dual-write window mitigation in I-C-006).
|
||||||
|
- **PC-02**: Add `v0.9-P00 — Deprecation sweep` as an explicit phase. Must land
|
||||||
|
before any new feature phase so coverage gates don't measure dead packages.
|
||||||
|
- **PC-03**: Split migration: `v0.9-P00b — Migration design + dry-run` (early,
|
||||||
|
parallel to deprecation) and `v0.10-P14 — Production migration` (final).
|
||||||
|
Migration design must inform every earlier phase, not be informed by them.
|
||||||
|
|
||||||
|
**Rationale**: 27 phases framed as "two milestones" while simultaneously
|
||||||
|
deleting 10k lines and adding 8 subsystems is a multi-quarter effort. The
|
||||||
|
deprecation work is a real phase that was not on the plan. With the override
|
||||||
|
and the v0.9-P00 additions, the plan is now structurally sound.
|
||||||
|
|
||||||
|
## Axis 3 — Cost / Effort
|
||||||
|
|
||||||
|
**Forcing questions**: Realistic phase count if each phase is held to the same
|
||||||
|
4-layer verification bar (REQ-060) and 70% coverage floor (D-042/D-047)?
|
||||||
|
Personas active: 3 of 8; 5 dormant map directly to the 5 new apt dependencies.
|
||||||
|
Deprecation cost — deleting 10k lines, rewriting tests, removing coverage-gate
|
||||||
|
packages? The bash scripts (8 in §26.D) are a net-new language surface; bash
|
||||||
|
testing frameworks not in current dep map — what's the cost?
|
||||||
|
|
||||||
|
**Evidence**: Active roster has 3 of 8 active; the 5 dormant personas map
|
||||||
|
directly to the 5 new apt dependencies. v0.8 took 4 phases for a pure
|
||||||
|
test/coverage milestone; v0.10 includes 11 distinct subsystems in one
|
||||||
|
"milestone." No bash test infrastructure exists today.
|
||||||
|
|
||||||
|
**Verdict**: PROCEED-WITH-CONDITION
|
||||||
|
**Confidence**: 0.70
|
||||||
|
|
||||||
|
**Binding conditions**:
|
||||||
|
- **C-04**: Produce a per-phase sizing estimate using v0.6/v0.7/v0.8 actuals
|
||||||
|
as the analogous baseline. If realistic phase count exceeds 35, the
|
||||||
|
milestone must be split into v0.9 + v0.10 (three milestones), not two.
|
||||||
|
- **C-05**: Reactivate or explicitly assign coverage for the dormant personas'
|
||||||
|
domains (security, network, devops); no "dormant" = "unowned."
|
||||||
|
- **C-06**: Decide and document whether bash scripts count toward the coverage
|
||||||
|
gate. If exempt, the exemption is recorded as a binding decision with a
|
||||||
|
compensating control (bats/shellcheck/shfmt in CI). If not exempt, the effort
|
||||||
|
estimate must include bash test authoring.
|
||||||
|
|
||||||
|
**Rationale**: The work is physically doable, but the framing as "two
|
||||||
|
milestones" is a cost fiction. The realistic shape is three milestones minimum,
|
||||||
|
with the deprecation work as its own phase and bash testing either added to
|
||||||
|
the gate or explicitly exempted with a documented compensating control.
|
||||||
|
|
||||||
|
## Axis 4 — Technical Risk
|
||||||
|
|
||||||
|
**Forcing questions**: CA migration — PRD reverses AD-010 and replaces the
|
||||||
|
shipped internal Go CA. What is the migration path for existing `ca.crt`/
|
||||||
|
`ca.key`/`server.crt`/`server.key` on every running cluster? SPIFFE SVID
|
||||||
|
minting at submit time (D-068) reverses the PROJECT.md:94 SPIFFE rejection —
|
||||||
|
has anyone prototyped the mint-at-submit path? Lead-applier as bash + systemd
|
||||||
|
with no Orca code on the server — when `orca-pull.sh` fails mid-render, what
|
||||||
|
is the recovery? Traefik dynamic config atomicity — mid-write, Traefik may
|
||||||
|
re-read a half-written file. Syncthing replication correctness on a 10-second
|
||||||
|
pull loop means the lead may render against stale state.
|
||||||
|
|
||||||
|
**Evidence**: AD-010 (ARCHITECTURE.md:463) is an explicit documented decision
|
||||||
|
*against* step-ca. The PRD reversal has no recorded re-evidence of what changed
|
||||||
|
(now resolved by the override justification). SPIFFE rejection at PROJECT.md:94
|
||||||
|
is the same pattern. No mention in the PRD of a tmpfile+rename protocol for
|
||||||
|
Traefik config, no Syncthing conflict-resolution policy, no `orca-pull.sh`
|
||||||
|
failure semantics. The shipped `internal/transport/mtls.go` had
|
||||||
|
retry+backoff+idempotency (REQ-037). The bash replacement has no equivalent
|
||||||
|
specified.
|
||||||
|
|
||||||
|
**Verdict**: PROCEED-WITH-CONDITION
|
||||||
|
**Confidence**: 0.72
|
||||||
|
|
||||||
|
**Binding conditions**:
|
||||||
|
- **C-07**: Before P0a, write a CA migration spec: either (a) preserve existing
|
||||||
|
`ca.crt` trust root and import into step-ca, or (b) document forced
|
||||||
|
re-bootstrap as an accepted breaking change with per-cluster upgrade
|
||||||
|
procedure. Cannot be deferred.
|
||||||
|
- **C-08**: Before the first SPIFFE-touching phase (v0.10 P02 ACL), produce a
|
||||||
|
working spike of step-ca JWT-SVID or X.509-SVID minting from the orca CLI
|
||||||
|
(v0.10-P01.5). If the spike fails, SPIFFE is deferred and ACL falls back to
|
||||||
|
mTLS identity (which the shipped model already had).
|
||||||
|
- **C-09**: Define and test the `orca-pull.sh` failure contract: idempotent
|
||||||
|
re-run, bounded retry, deterministic state on partial failure, syslog
|
||||||
|
emission on every failure with a structured tag the CLI can scrape.
|
||||||
|
- **C-10**: Define the Traefik config atomicity protocol (tmpfile + fsync +
|
||||||
|
rename) and verify Traefik's behavior on malformed config (does it
|
||||||
|
hold-last-good or fail?). Documented, tested.
|
||||||
|
|
||||||
|
**Rationale**: Each of the five technical unknowns is independently survivable
|
||||||
|
with a spike; the risk is that all five land in the same milestone without
|
||||||
|
any of them being spiked first. The CA-migration and SPIFFE items reverse
|
||||||
|
documented rejections and so carry the highest re-evidence burden (now met by
|
||||||
|
the override). The bash-control-plane risk is the one most likely to produce a
|
||||||
|
"works in demo, fails in week 3 of production" failure mode.
|
||||||
|
|
||||||
|
## Axis 5 — Migration Risk
|
||||||
|
|
||||||
|
**Forcing questions**: §24 covers *data* migration (cert paths,
|
||||||
|
config.hcl→config.md, db relocation). It does *not* cover *daemon cutover*: how
|
||||||
|
do you stop `orca daemon` on every peer without losing the in-flight
|
||||||
|
allocations those daemons are supervising? What happens to running
|
||||||
|
allocations during `orca upgrade --to-v1.0`? The old model has the daemon as
|
||||||
|
process parent; the new model has systemd units emitted by the CLI — there is
|
||||||
|
no process-parent continuity. The transition period where some peers are v0.8
|
||||||
|
(daemon) and some are v1.0 (no daemon) — what is the failure mode? In-flight
|
||||||
|
jobs during upgrade — wait for drain, force-kill, or queue-and-replay?
|
||||||
|
|
||||||
|
**Evidence**: §24 covers cert paths, config.hcl→config.md, db relocation —
|
||||||
|
three file-layout migrations. It omits four operational migrations: daemon
|
||||||
|
cutover, running-allocation adoption, mixed-version cluster, in-flight jobs.
|
||||||
|
The shipped executor (`internal/engine/executor.go:163`) uses
|
||||||
|
`os/exec.CommandContext` — the daemon is the process parent. systemd units
|
||||||
|
emit by the CLI would be a *different* parent (systemd). Process reparenting
|
||||||
|
is not portable across the orca model. "Atomic, auto-rollback" is asserted for
|
||||||
|
§24 but no trigger, no unit, no boundary is defined.
|
||||||
|
|
||||||
|
**Verdict**: REPLAN (mechanics — direction settled by override)
|
||||||
|
**Confidence**: 0.82
|
||||||
|
|
||||||
|
**Mechanics adopted**:
|
||||||
|
- **PC-04**: Split P14 into `v0.10-P14a — Data migration` (current scope),
|
||||||
|
`v0.10-P14b — Daemon cutover + running-allocation adoption`,
|
||||||
|
`v0.10-P14c — Mixed-version cluster tolerance + no-orca-on-server enforcement`.
|
||||||
|
Three sub-phases, each with its own integration test.
|
||||||
|
|
||||||
|
**Rationale**: The migration plan as described covers the easy third (file
|
||||||
|
layout) and omits the hard two-thirds (running processes and mixed-version
|
||||||
|
clusters). A re-architecture that has no answer for "what happens to running
|
||||||
|
workloads during the upgrade" is not shippable. With the P14 split, the plan
|
||||||
|
is now complete.
|
||||||
|
|
||||||
|
## Axis 6 — Operational Risk
|
||||||
|
|
||||||
|
**Forcing questions**: When `orca-pull.sh` fails on the lead, what happens to
|
||||||
|
workloads? When step-ca is down, can new workloads start? When Syncthing
|
||||||
|
conflicts, what is the conflict-resolution policy? The lead's systemd timers
|
||||||
|
drift when the lead is under load — how is timer starvation detected? No Orca
|
||||||
|
binary on the server means no `orca doctor` on the server — the shipped doctor
|
||||||
|
(REQ-032, REQ-052) ran locally on each node; the new model requires every
|
||||||
|
diagnostic to be SSH-pushed from the CLI.
|
||||||
|
|
||||||
|
**Evidence**: The shipped `orca doctor` runs locally (ARCHITECTURE.md §5,
|
||||||
|
REQ-032). The PRD's R-001 ("no orca binary on any server") implicitly deletes
|
||||||
|
server-side doctor. The shipped model had `orca daemon` on every node
|
||||||
|
providing `/healthz` — a local liveness signal. The new model has no
|
||||||
|
server-side health producer. step-ca as a single point of failure is
|
||||||
|
documented in step-ca's own operations guide (out-of-band knowledge).
|
||||||
|
|
||||||
|
**Verdict**: PROCEED-WITH-CONDITION
|
||||||
|
**Confidence**: 0.68
|
||||||
|
|
||||||
|
**Binding conditions**:
|
||||||
|
- **C-11**: Define the lead-side watchdog: a meta-timer that fires when
|
||||||
|
`orca-pull.sh` has not successfully run in N seconds, emitting a structured
|
||||||
|
alert. Document the alert path (syslog? CLI-pull?).
|
||||||
|
- **C-12**: Document step-ca's HA story. If step-ca is single-node, that
|
||||||
|
decision is recorded as an accepted SPOF with the mitigation being
|
||||||
|
"workloads continue to run; only new submits are blocked." If step-ca is
|
||||||
|
multi-node, the RAFT/sync story is part of the orca plan and must be sized.
|
||||||
|
- **C-13**: Replace server-side doctor with a CLI-driven equivalent that
|
||||||
|
SSH-probes every node and reconstructs the health view the daemon used to
|
||||||
|
provide locally. This is a new requirement, not a feature; added as
|
||||||
|
I-C-002 / v0.10-P14c.
|
||||||
|
- **C-14**: Syncthing conflict-resolution policy must be deterministic,
|
||||||
|
documented, and tested with a forced-divergence integration test.
|
||||||
|
|
||||||
|
**Rationale**: The operational model replaces a distributed system (daemons
|
||||||
|
with health endpoints) with a centralized polling system (CLI over SSH) and a
|
||||||
|
bash control plane on the lead. The mitigations are knowable but unspecified.
|
||||||
|
|
||||||
|
## Axis 7 — Security
|
||||||
|
|
||||||
|
**Forcing questions**: The master.key (AES-256-GCM for `.env.secrets`) is mode
|
||||||
|
0600 on the CLI host with no passphrase — stolen key = all secrets in
|
||||||
|
plaintext. The shipped model distributed keys with operator mediation (D-012).
|
||||||
|
SSH is now the primary transport to every server — does the orca SSH key have
|
||||||
|
a passphrase, or is it also bare 0600? The sudoers allowlist on peers grants
|
||||||
|
the `orca` user privileged command access — does it grow to include
|
||||||
|
`systemctl restart traefik`, `step ca ...`, `podman ...`? Five new attack
|
||||||
|
surfaces: step-ca, Traefik, Syncthing, wasmtime, podman. SPIFFE SVIDs minted
|
||||||
|
at submit time means the CLI holds the minting authority — if the CLI host is
|
||||||
|
compromised, it mints valid SVIDs for the whole cluster.
|
||||||
|
|
||||||
|
**Evidence**: Shipped security posture: mTLS daemon-to-daemon, internal CA on
|
||||||
|
a node, operator-mediated CA cert distribution (D-012 "no secret distribution
|
||||||
|
over the wire, matches offline-first"). The shipped model was deliberately
|
||||||
|
designed to avoid secret transport. New posture: CLI holds master.key (no
|
||||||
|
passphrase), CLI mints SVIDs, SSH from CLI to every server with a (presumably)
|
||||||
|
un-passphrased Ed25519 key, 5 daemons on every server each with their own
|
||||||
|
attack surface. ARCHITECTURE.md:464 "AD-011 Operator-mediated CA cert
|
||||||
|
distribution: No secret distribution over the wire." The new model puts a
|
||||||
|
master.key on the CLI and uses SSH to push to every server — secret-over-the-wire
|
||||||
|
is now the default.
|
||||||
|
|
||||||
|
**Verdict**: REPLAN (mechanics — direction settled by override)
|
||||||
|
**Confidence**: 0.74
|
||||||
|
|
||||||
|
**Mechanics adopted**:
|
||||||
|
- **C-19**: Write a threat model for the new posture before any
|
||||||
|
security-touching phase (v0.10-P15.5). Defend master.key + CLI mint authority
|
||||||
|
or revise. The shipped model deliberately avoided putting a single stealable
|
||||||
|
file on a single host that decrypts all secrets and mints all identities.
|
||||||
|
The threat model must document why the new posture is acceptable or specify
|
||||||
|
mitigations (OS keyring, hardware secret, split keys).
|
||||||
|
|
||||||
|
**Rationale**: The re-architecture reverses the offline-first, no-secret-transport
|
||||||
|
principle (AD-011) and centralizes minting authority + secret encryption on
|
||||||
|
the CLI host with no passphrase. A threat model must be written and the
|
||||||
|
master.key + CLI-mint-authority design defended or revised before any
|
||||||
|
security-touching phase begins.
|
||||||
|
|
||||||
|
## Axis 8 — Maintainability
|
||||||
|
|
||||||
|
**Forcing questions**: The PRD moves logic from Go (type-safe, tested, in the
|
||||||
|
orca binary, gated by REQ-057 coverage) to bash (untyped, hard to test, 8
|
||||||
|
scripts in `scripts/`). How will the 8 bash scripts be tested under the
|
||||||
|
project's coverage gate? Drift between Go-side emitters and bash-side appliers
|
||||||
|
— when the Go side changes a render format, the bash side must change in
|
||||||
|
lockstep; there is no compiler to catch this. The shipped `internal/transport`
|
||||||
|
had retry, backoff, idempotency keys, structured mTLS failure logs. The bash
|
||||||
|
replacement has none specified. Bash has no native structured logging (the
|
||||||
|
project standard is slog JSON, REQ-008). The 8 scripts are a new language
|
||||||
|
surface in a Go-only project.
|
||||||
|
|
||||||
|
**Evidence**: PROJECT.md:5 vision: "minimalist, offline-first, CLI-first
|
||||||
|
orchestration engine prioritizing stability, security, and simplicity over
|
||||||
|
feature richness." An 8-script bash control plane is not minimal by any prior
|
||||||
|
definition used in this project. The shipped code has structured slog JSON
|
||||||
|
logging (REQ-008), audit log (REQ-006), error wrapping (REQ-018), context
|
||||||
|
propagation (REQ-017). Bash has none of these natively. No bash test
|
||||||
|
framework in current dep map; no `bats`/`shunit2` reference. The 70%/50%
|
||||||
|
coverage gate (D-042/D-047) is Go-specific.
|
||||||
|
|
||||||
|
**Verdict**: PROCEED-WITH-CONDITION
|
||||||
|
**Confidence**: 0.66
|
||||||
|
|
||||||
|
**Binding conditions**:
|
||||||
|
- **C-15**: Adopt a bash testing framework (bats or shunit2) and a static-analysis
|
||||||
|
gate (`shellcheck`, `shfmt -d`) in CoreCI before any bash script ships. Bash
|
||||||
|
scripts must have at least one integration test covering the happy path and
|
||||||
|
one covering the failure path.
|
||||||
|
- **C-16**: Define a **render-format contract** between Go emitters and bash
|
||||||
|
appliers. Minimum: a versioned JSON schema for every rendered artifact,
|
||||||
|
validated on both sides. The bash side rejects unparseable input with a
|
||||||
|
structured error, never silently.
|
||||||
|
- **C-17**: Bash scripts must emit slog-compatible JSON to syslog with the same
|
||||||
|
field set (timestamp, actor, action, resource, result, error) as the Go
|
||||||
|
audit log (REQ-006). No unstructured text in audit.
|
||||||
|
- **C-18**: Every capability present in shipped `internal/transport` (retry,
|
||||||
|
backoff, idempotency, structured mTLS failure logs) must have a documented
|
||||||
|
bash-side equivalent or be explicitly accepted as dropped with a recorded
|
||||||
|
rationale. Capability regressions must be visible, not silent.
|
||||||
|
|
||||||
|
**Rationale**: Bash is not inherently unmaintainable, but bash *in a Go-only,
|
||||||
|
coverage-gated, structured-logging project* is a language-without-rails. Without
|
||||||
|
the four conditions above, the bash control plane becomes the part of the
|
||||||
|
codebase that everyone is afraid to touch by v0.10 P05. The drift between Go
|
||||||
|
emitters and bash appliers is the single most likely source of "works on the
|
||||||
|
CLI's machine, fails on the lead" bugs.
|
||||||
|
|
||||||
|
## Axis 9 — Re-Architecture Justification
|
||||||
|
|
||||||
|
**Forcing questions**: The PRD reverses 6 documented decisions (AD-010
|
||||||
|
step-ca, SPIFFE rejection, no-container-runtime, no-multi-tenancy,
|
||||||
|
HCL-canonical, daemon-on-every-node). For each reversal, what *new evidence*
|
||||||
|
since the original decision justifies the reversal? The shipped v0.8 model is
|
||||||
|
*working* — 8 milestones, REQ-001..060 Complete, 4-layer verification passing,
|
||||||
|
coverage gates met. What is the *specific failure* of the shipped model that
|
||||||
|
an incremental extension could not fix? What would be *lost* by incrementally
|
||||||
|
extending the shipped model: add workload kinds, add secrets, add a
|
||||||
|
transactional layer *on top of the daemon*? Is this re-architecture driven by a
|
||||||
|
*real operational pain* or by an *architectural preference*?
|
||||||
|
|
||||||
|
**Evidence**: ROADMAP.md and PROJECT.md: every milestone from v0.1 to v0.8
|
||||||
|
explicitly says "the vision is unchanged; this milestone is not a direction
|
||||||
|
change." v0.9/v0.10 is the *first* milestone in the project's history that
|
||||||
|
reverses the vision's anti-patterns. AD-010's rationale: "step-ca/cfssl/
|
||||||
|
vault-pki too heavyweight for Orca's footprint." Nothing in the original PRD
|
||||||
|
suggested Orca's footprint changed. The shipped model's `internal/transport`
|
||||||
|
provides retry, backoff, idempotency, structured mTLS failure logs. The PRD
|
||||||
|
replaces this with bash + systemd + SSH. No evidence the shipped transport
|
||||||
|
was a source of operational pain.
|
||||||
|
|
||||||
|
**Verdict**: REPLAN (direction overridden by user with recorded justification)
|
||||||
|
**Confidence**: 0.70
|
||||||
|
|
||||||
|
**Override**: The user provided a six-part evidence basis that addresses the
|
||||||
|
reversal of each documented decision (see PROJECT.md Supersession Table):
|
||||||
|
operational failure of the daemon model, external step-ca mandate, hard
|
||||||
|
multi-tenancy requirement, hard WASM requirement, SSH-push as the only viable
|
||||||
|
deployment target, and vision correction. The override is recorded; the
|
||||||
|
direction holds.
|
||||||
|
|
||||||
|
**Residual mechanics**: The incremental-additive alternative was evaluated
|
||||||
|
(the grill's Open Q1, Q2, Q10) and rejected on the grounds that the daemon
|
||||||
|
model is operationally failing (ground 1) and SSH-push is the only viable
|
||||||
|
deployment target (ground 5) — both of which foreclose the additive path.
|
||||||
|
|
||||||
|
**Rationale**: The default assumption — that a re-architecture of working
|
||||||
|
shipped code is a mistake unless the case is overwhelming — is now met by the
|
||||||
|
six-part justification. The re-architecture proceeds.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# Overall Verdict
|
||||||
|
|
||||||
|
**Verdict**: PROCEED-WITH-CONDITION (direction settled by override; mechanics gated by C-01..C-19)
|
||||||
|
**Confidence**: 0.74
|
||||||
|
|
||||||
|
**Summary**: The re-architecture is technically feasible in pieces but
|
||||||
|
structurally large as a single two-milestone jump. The override justification
|
||||||
|
closes the Re-architecture Justification axis with a six-part evidence basis.
|
||||||
|
The remaining mechanics: reorder phases (PC-01..PC-10), split heavy phases,
|
||||||
|
add the v0.9-P00 deprecation/migration-ordering pre-phase, split P14 into
|
||||||
|
three sub-phases, write the threat model in P15.5, and gate the 19 binding
|
||||||
|
conditions (C-01..C-19) as execution gates. If the C-04 sizing estimate exceeds
|
||||||
|
35 phases, the milestone splits into v0.9 + v0.10 + v1.0.
|
||||||
|
|
||||||
|
# Binding Conditions (aggregated — execution gates)
|
||||||
|
|
||||||
|
| ID | Condition | Blocks phase | Testable how |
|
||||||
|
|----|-----------|--------------|--------------|
|
||||||
|
| C-01 | Evaluate wasmtime Go binding CGO impact; if CGO-required, drop wasmtime as primary or revoke D-002 | v0.9-P07b | Build matrix spike on linux/amd64+arm64; revocation decision recorded |
|
||||||
|
| C-02 | Syncthing feasibility spike: config injection, conflict policy, deterministic failure mode | v0.9-P09 | Spike report + forced-divergence integration test |
|
||||||
|
| C-03 | Check PRD into `.ciagent/PRD_v0.9.md` before any v0.9 phase begins | (gate) | ✅ Resolved — file committed |
|
||||||
|
| C-04 | Per-phase sizing estimate vs v0.6/v0.7/v0.8 actuals; if >35, split into v0.9+v0.10 | v0.9 start | ✅ RESOLVED — operator decision: keep 2 milestones (v0.9+v0.10), keep all phases (40 total), v1.0 UAT-gated after v0.10 |
|
||||||
|
| C-05 | Reactivate or assign dormant persona domains (security, network, devops) | v0.9-P00 | PERSONAS.md updated with named owners |
|
||||||
|
| C-06 | Decide bash coverage-gate status; if exempt, record compensating control | v0.9-P00 | Decision recorded in PROJECT.md D-series; CI pipeline shows the gate |
|
||||||
|
| C-07 | CA migration spec: preserve existing trust root or document forced re-bootstrap | v0.10-P14a | Spec doc + migration dry-run on test cluster |
|
||||||
|
| C-08 | SPIFFE SVID minting spike; if fails, fall back to mTLS identity | v0.10-P02 (spike in P01.5) | Working SVID mint from orca CLI in sandbox |
|
||||||
|
| C-09 | `orca-pull.sh` failure contract: idempotent re-run, bounded retry, deterministic state, structured syslog | v0.10-P10 | Failure-path integration test + syslog structured-tag verification |
|
||||||
|
| C-10 | Traefik config atomicity protocol (tmpfile+fsync+rename) + malformed-config behavior verified | v0.9-P02 | Atomic-rename test + Traefik malconfig-hold-last-good assertion |
|
||||||
|
| C-11 | Lead-side watchdog meta-timer for `orca-pull.sh` starvation, with structured alert path | v0.10-P09 | Watchdog fires on injected pull failure; alert received |
|
||||||
|
| C-12 | Document step-ca HA story; if single-node, record as accepted SPOF with mitigation | v0.10-P09 | Decision doc; if HA, RAFT/sync story in orca plan |
|
||||||
|
| C-13 | Replace server-side doctor with CLI-SSH-driven equivalent | v0.10-P14c | New REQ-086 in REQUIREMENTS.md; integration test SSH-probes N nodes |
|
||||||
|
| C-14 | Syncthing conflict-resolution policy deterministic + forced-divergence integration test | v0.10-P09 | Test induces divergence; resolves to single deterministic state |
|
||||||
|
| C-15 | Bash testing framework (bats/shunit2) + shellcheck + shfmt in CoreCI before any bash ships | v0.9-P00 | CI pipeline green with the gate on a sample script |
|
||||||
|
| C-16 | Versioned JSON-schema render-format contract between Go emitters and bash appliers | v0.9-P00 | Schema file in repo; both sides validate; mismatch fails CI |
|
||||||
|
| C-17 | Bash scripts emit slog-compatible JSON to syslog with audit-log field set (REQ-006) | v0.9-P00 | Syslog capture test verifies field-presence + JSON parse |
|
||||||
|
| C-18 | Document bash-side equivalents (or accepted drops) for shipped transport capabilities | v0.9-P00 | Capability-mapping doc in `.ciagent/` |
|
||||||
|
| C-19 | Write a threat model for the new posture; defend master.key + CLI mint authority or revise | v0.10-P15.5 | Threat-model doc reviewed and committed; design revised if regression found |
|
||||||
|
|
||||||
|
# Phase Plan Challenges
|
||||||
|
|
||||||
|
| # | Phase | Problem | Fix |
|
||||||
|
|---|-------|---------|-----|
|
||||||
|
| PC-01 | v0.9 P0a–P10 | Ship 10 phases of workload features before the transactional control plane | Design spike in v0.9-P00; full impl in v0.10-P10 per PRD ordering (workloads first accepted with dual-write mitigation) |
|
||||||
|
| PC-02 | (missing) | Deprecation of ~10k lines of daemon/transport/CA code is not a phase | Add `v0.9-P00 — Deprecation sweep` as explicit phase before any new feature phase |
|
||||||
|
| PC-03 | v0.9 P10 | Migration is the last phase of v0.9 but is highest-risk | Split: migration design in v0.9-P00 (early), implementation in v0.10-P14 (final) |
|
||||||
|
| PC-04 | v0.10 P14 | Covers data migration only; omits running-allocation cutover, mixed-version cluster, rollback trigger | Split into P14a (data), P14b (daemon cutover), P14c (mixed-version tolerance) |
|
||||||
|
| PC-05 | v0.10 P02 | SPIFFE is a documented reversal with no spike; lands before spike possible | Insert `v0.10-P01.5 — SPIFFE mint spike` as hard gate before P02 |
|
||||||
|
| PC-06 | v0.10 P10 | Transactional plane depends on lead-applier bash scripts (C-09) not gated | Reorder to v0.9-P00 design + add C-09 gate |
|
||||||
|
| PC-07 | v0.10 P15/P16 | README before security threat model | Add `v0.10-P15.5 — Threat model + security review` before final review |
|
||||||
|
| PC-08 | (missing) | No phase replaces server-side `orca doctor` | Add as I-C-002 / v0.10-P14c (CLI-SSH-driven doctor) |
|
||||||
|
| PC-09 | v0.9 P09 | Syncthing lands before feasibility spike (C-02) | Spike must precede P09; if P09 is the spike, rename + gate on spike success |
|
||||||
|
| PC-10 | v0.9 P07 | Five runtimes in one phase, including wasmtime (CGO risk) and pve-vm/pve-ct | Split: P07a (process+podman), P07b (wasmtime, C-01 gated), P07c (pve-vm+ct) |
|
||||||
|
|
||||||
|
# Open Questions (feed back to IDEATE/PLAN; resolved where noted)
|
||||||
|
|
||||||
|
1. **What measured operational failure of the shipped v0.8 daemon model is the re-architecture responding to?** — ✅ Resolved by override ground 1.
|
||||||
|
2. **Can the v0.9 scope be delivered as additive extensions?** — ✅ Resolved: rejected per override grounds 1 + 5.
|
||||||
|
3. **What is the wasmtime/CGO resolution?** — Closes via C-01 spike in v0.9-P07b.
|
||||||
|
4. **What is the master.key threat model?** — Closes via C-19 in v0.10-P15.5.
|
||||||
|
5. **What is the rollback unit of work for §24, and what triggers it?** — Must be answered in v0.9-P00 txn-design spike (I-B-007).
|
||||||
|
6. **Is step-ca single-node acceptable as a cluster SPOF?** — Closes via C-12 in v0.10-P09.
|
||||||
|
7. **Can the bash control plane be reduced?** — Closes in v0.9-P00 (fold 3+ scripts into Go-side SSH invocations where possible).
|
||||||
|
8. **What is the realistic phase count?** — Closes via C-04 sizing before v0.9 starts; if >35, the plan becomes three milestones.
|
||||||
|
9. **Does the PRD's reversal of 6 documented decisions require a formal AD-series supersession?** — ✅ Resolved: supersession table recorded in PROJECT.md + ARCHITECTURE.md.
|
||||||
|
10. **What is the smallest possible version of this re-architecture that delivers 80% of the value?** — ✅ Resolved: the override rejected the incremental-additive path; the full re-architecture proceeds per the six-part justification.
|
||||||
|
|
||||||
|
# Binding Decisions (this grill session, G-001..G-009)
|
||||||
|
|
||||||
|
| ID | Decision | Confidence |
|
||||||
|
|----|----------|-----------|
|
||||||
|
| G-001 | Feasibility: PROCEED-WITH-CONDITION (C-01..C-03) | 0.62 |
|
||||||
|
| G-002 | Scope: REPLAN mechanics (PC-01..PC-03) — direction settled by override | 0.78 |
|
||||||
|
| G-003 | Cost: PROCEED-WITH-CONDITION (C-04..C-06) | 0.70 |
|
||||||
|
| G-004 | Tech Risk: PROCEED-WITH-CONDITION (C-07..C-10) | 0.72 |
|
||||||
|
| G-005 | Migration: REPLAN mechanics (PC-04) — direction settled by override | 0.82 |
|
||||||
|
| G-006 | Op Risk: PROCEED-WITH-CONDITION (C-11..C-14) | 0.68 |
|
||||||
|
| G-007 | Security: REPLAN mechanics (C-19) — direction settled by override | 0.74 |
|
||||||
|
| G-008 | Maintainability: PROCEED-WITH-CONDITION (C-15..C-18) | 0.66 |
|
||||||
|
| G-009 | Re-architecture Justification: direction overridden by user with six-part evidence basis; mechanics closed | 0.70 |
|
||||||
|
|
||||||
|
# Escalations (auto-resolved under full autonomy)
|
||||||
|
|
||||||
|
| E-ID | Item | Auto-decision | Mitigation |
|
||||||
|
|------|------|---------------|-----------|
|
||||||
|
| E-01 | Whether the re-architecture is justified vs incremental | OVERRIDDEN by user — direction holds | Six-part evidence basis recorded in PROJECT.md Supersession Table |
|
||||||
|
| E-02 | Whether master.key passphrase-less posture is acceptable | REPLAN mechanics — threat model first | C-19 in v0.10-P15.5; if threat model shows regression vs shipped, revise design |
|
||||||
|
| E-03 | Whether 27 phases fit in 2 milestones | Auto-split if sizing exceeds 35 | ✅ RESOLVED — operator: keep 2 milestones (v0.9+v0.10), keep all phases, v1.0 UAT-gated |
|
||||||
@@ -0,0 +1,363 @@
|
|||||||
|
# Ideation v0.9 — Re-architecture Foundation
|
||||||
|
|
||||||
|
**Project**: orca (single-project mode) | **Milestone**: v0.9/v0.10 re-architecture
|
||||||
|
**Date**: 2026-08-05 | **Agent**: ideation agent | **Confidence threshold**: 0.60
|
||||||
|
**Next REQ ID prior to this run**: REQ-060 (v0.8 complete)
|
||||||
|
|
||||||
|
## Context
|
||||||
|
|
||||||
|
The v0.8 codebase (REQ-001..060, all Complete) is a daemon-based, mTLS,
|
||||||
|
HCL, single-namespace orchestration engine. The adopted PRD supersedes this
|
||||||
|
with a CLI-only, SSH-push, step-ca, Markdown-frontmatter, multi-namespace
|
||||||
|
stack. 9 packages are deprecation targets (~2,400 LOC of v0.8
|
||||||
|
daemon/transport/security-ca/engine-dispatch/jobspec-hcl/config-hcl/certpaths
|
||||||
|
code), 7 packages are adaptable, and 8 subsystems are net-new with zero
|
||||||
|
implementation. The §23 milestone plan has 11 v0.9 phases + 17 v0.10 phases but
|
||||||
|
under-specifies the deprecation mechanics, the SSH-push transport design, the
|
||||||
|
lead-applier execution model, several adapter/bridge layers, and the
|
||||||
|
migration ordering risk.
|
||||||
|
|
||||||
|
This ideation produced 30 ideas across three tiers, all accepted at ≥0.60
|
||||||
|
confidence, mapped to REQ-061..REQ-090. Seven phase-reordering flags against
|
||||||
|
the PRD §23 plan are listed at the end.
|
||||||
|
|
||||||
|
## Tier 1 — Mechanical (Codebase-Observable Gaps & Hygiene)
|
||||||
|
|
||||||
|
### I-M-001 — `orca daemon` deprecation command and build-tag removal path
|
||||||
|
- **Tier**: mechanical
|
||||||
|
- **Description**: The PRD deprecates `internal/daemon/` (R-001) but §23 never says *how*. `internal/cli/daemon.go` (100 LOC) registers the `daemon` cobra command and wires `daemon.NewServer` + `engine.Dispatcher`. Big-bang removal would break the v0.8→v1.0 migration path (v0.10-P14) because `orca upgrade --to-v1.0` must run against a live v0.8 cluster that still has daemons. Proposal: (1) in v0.9, `orca daemon` emits a deprecation warning and still runs (dual-write window); (2) in v1.0, `orca daemon` is repurposed to `orca daemon drain-and-stop` (stops v0.8 daemons on peers via SSH, confirms workloads survive via systemd); (3) post-v1.0, the command and `internal/daemon/` are deleted. Add `// Deprecated` Go doc comments + `slog.Warn` on every run.
|
||||||
|
- **Rationale**: R-001 is an invariant, but the *transition* off the daemon is a mechanical gap. The v0.8 `daemon.go` is wired in `root.go` init; removing it without a transition plan breaks the §24 migration.
|
||||||
|
- **Proposed REQ ID**: REQ-061
|
||||||
|
- **Proposed phase placement**: v0.10-P14 (migration) — deprecation warning lands in v0.9-P0X
|
||||||
|
- **Confidence**: 0.82
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-M-002 — Coverage follow-ups: 3 zero-test packages + `internal/cli` to 70%
|
||||||
|
- **Tier**: mechanical
|
||||||
|
- **Description**: v0.8 P01 (REQ-057) raised 6 packages to ≥70% and added first tests for `internal/audit`, `internal/certpaths`, `cmd/orca` at a 50% toe-hold. The v0.9 re-architecture will *replace* several of these packages, but the *adaptable* ones (`internal/store`, `internal/doctor`, `internal/cli`) must keep their 70% floor through the refactor. Once `daemon.go` is deprecated/removed (I-M-001), the exclusion reason disappears and the floor applies to the whole package. Add a coverage-gate assertion in the v0.9 P0X ship phase that `internal/cli` ≥ 70% *including* all new subcommand files (ns, txn, pve, secrets, volume, cache, backup).
|
||||||
|
- **Rationale**: The PRD §23 does not mention coverage. The config.json policy says 70% floor for new packages, 50% minimum. The 8 net-new subsystems will need 70% floors from their first phase. Without an explicit gate, the v0.7/v0.8 "toe-hold at 50% then defer" pattern will repeat.
|
||||||
|
- **Proposed REQ ID**: REQ-062
|
||||||
|
- **Proposed phase placement**: v0.9-P0X (ship+audit) + each net-new package's first phase
|
||||||
|
- **Confidence**: 0.88
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-M-003 — `known_hosts` flock concurrency gap (deferred P1 from REVIEW_v0.8 A2)
|
||||||
|
- **Tier**: mechanical
|
||||||
|
- **Description**: REVIEW_v0.8 flagged A2 (P1): `TOFUHostKeyCallback` capture path (`bootstrap.go:290-302`) and `ResetHostKey` (`bootstrap.go:479-523`) both do read-modify-write on `known_hosts` with no lock. The review said "Defer to v0.9." This is now load-bearing because the SSH-push transport (R-001) will do *many more* concurrent SSH operations than v0.8 did. Add a `flock`-style advisory lock (stdlib `syscall.Flock` wrapper) around the RMW in both paths. Lock file is `cluster/known_hosts.lock` (multi-namespace layout, R-002).
|
||||||
|
- **Rationale**: The v0.8 single-operator mitigation is weaker under v0.9's parallel SSH fan-out. The PRD doesn't mention this, but the SSH-push transport makes the race more likely.
|
||||||
|
- **Proposed REQ ID**: REQ-063
|
||||||
|
- **Proposed phase placement**: v0.9-P0a1 (path resolver, since it establishes `cluster/` layout)
|
||||||
|
- **Confidence**: 0.74
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-M-004 — HCL→Markdown jobspec adapter/bridge layer
|
||||||
|
- **Tier**: mechanical
|
||||||
|
- **Description**: R-013 says the Markdown parser is canonical; `.yaml` and `.hcl` are "accepted by parser dispatcher." But `internal/jobspec/spec.go` (69 LOC) is an HCL-only parser with a flat `Spec{Job, Tasks}` schema — no `kind:` (R-012), runtime blocks, or body preservation (R-014/R-015). The "dispatcher" implies the new parser detects file extension and dispatches. Proposal: keep `internal/jobspec/spec.go` as the legacy HCL path behind `// Deprecated`; add `internal/jobspec/markdown.go` (canonical) + `internal/jobspec/dispatch.go` (extension-based dispatcher: `.md`→Markdown, `.hcl`→legacy, `.yaml`→Markdown-with-empty-body). The dispatcher returns a unified `*WorkloadSpec` that the legacy parser populates via an adapter. Preserves `orca job run old-spec.hcl` during the migration window.
|
||||||
|
- **Rationale**: R-013 explicitly accepts `.hcl`, so a dispatcher is required. §23 v0.9-P0b says "parser dispatcher" but doesn't specify the adapter.
|
||||||
|
- **Proposed REQ ID**: REQ-064
|
||||||
|
- **Proposed phase placement**: v0.9-P0b (Markdown jobspec parser)
|
||||||
|
- **Confidence**: 0.85
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-M-005 — `orca doctor --legacy-paths` detection for v0.8 residue
|
||||||
|
- **Tier**: mechanical
|
||||||
|
- **Description**: The v0.8 layout is `~/.orca/{orca.db, ca.crt, ca.key, server.crt, server.key, orca_ssh_key, known_hosts, config.hcl}`. The v1.0 layout is `ORCA_HOME/{_defaults/, cluster/{ca,master.key,peers,pve,txns}, <ns>/{db,.env,.env.secrets,jobs,alloc,ns.md}, orca_cache.db}`. `orca doctor` (`internal/doctor/doctor.go`, 501 LOC, adaptable) must gain a `doctor legacy` subcommand that detects v0.8 residue: presence of `orca.db` at ORCA_HOME root, `ca.crt`/`ca.key` (internal CA, superseded by step-ca), `config.hcl` (HCL, demoted), flat `server.crt` (single-namespace), and a `namespace` column in any `*.db` (R-002 says no namespace column). Output: list of detected legacy artifacts with migration recommendations. This is the *detection* half of v0.10-P14; the *migration* half is I-C-001.
|
||||||
|
- **Rationale**: §23 v0.10-P14 says "orca upgrade --to-v1.0, post-invariant checks" but doesn't specify the detection surface. `doctor` is the diagnostics framework and is explicitly adaptable.
|
||||||
|
- **Proposed REQ ID**: REQ-065
|
||||||
|
- **Proposed phase placement**: v0.10-P14c (mixed-version tolerance + no-orca enforcement)
|
||||||
|
- **Confidence**: 0.80
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-M-006 — Legacy CA state migration to step-ca (cert import)
|
||||||
|
- **Tier**: mechanical
|
||||||
|
- **Description**: `internal/security/ca.go` (338 LOC) holds an internal Go CA with `ca.crt`/`ca.key` (RSA 3072, 10-year). The PRD replaces this with step-ca (R-006, D-101 reverses AD-010). The v0.10-P14 migration must handle existing deployments with an internal CA: (a) import the existing CA key into step-ca as `step ca init --deployment-type standalone --remote-management` with the existing key; (b) issue new SVIDs from step-ca and let old certs expire; (c) document that v0.8 certs are invalidated and re-bootstrap is required. The codebase audit says `ca.go`+`csr.go` are *replaced* — but the *state* (the CA key + issued server certs in `cert_repo` SQLite) may need to be preserved for audit history even if the live trust root changes. Proposal: `orca upgrade --to-v1.0 --import-ca` reads `~/.orca/ca.key`, initializes step-ca with it, and re-issues workload SVIDs. Without this, existing deployments lose their trust root with no path back.
|
||||||
|
- **Rationale**: AD-010 is explicitly reversed by D-101, but the reversal doesn't address what happens to the existing CA material. §24 covers data migration but not CA migration.
|
||||||
|
- **Proposed REQ ID**: REQ-066
|
||||||
|
- **Proposed phase placement**: v0.10-P14a (data migration)
|
||||||
|
- **Confidence**: 0.70
|
||||||
|
- **Accept/Defer**: accept (design in v0.9-P00 so step-ca integration knows the import contract)
|
||||||
|
|
||||||
|
### I-M-007 — Fuzz test harness for the Markdown frontmatter parser
|
||||||
|
- **Tier**: mechanical
|
||||||
|
- **Description**: R-014/R-015 require byte-exact body preservation — "body of every .md config file preserved verbatim." This is a class of bug that's easy to get wrong (off-by-one on the `---` delimiter, trailing newline handling, BOM, CRLF, nested code fences containing `---`). v0.8 has no fuzz tests at all. Proposal: add a `testing.F` fuzz target in `internal/jobspec/markdown_test.go` that round-trips random frontmatter+body through `ParseMarkdown` and asserts `body == roundtripped.body` byte-exact. Also add a corpus of adversarial fixtures (CRLF, BOM, no-frontmatter, empty-frontmatter, frontmatter-with-only-separator). §23 v0.10-P08 mentions integration tests but not fuzzing.
|
||||||
|
- **Rationale**: R-015 is a *load-bearing invariant* (body appears in inspect/history). Byte-exactness is exactly what fuzz tests are for. The v0.8 jobspec tests are golden-file only (no fuzz).
|
||||||
|
- **Proposed REQ ID**: REQ-067
|
||||||
|
- **Proposed phase placement**: v0.9-P0b (Markdown parser) — fuzz from day one
|
||||||
|
- **Confidence**: 0.78
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-M-008 — Deprecation warnings on removed/repurposed CLI subcommands
|
||||||
|
- **Tier**: mechanical
|
||||||
|
- **Description**: The v0.8 CLI has `orca cert {ca-init,gen,show,renew,fingerprint}` (`internal/cli/cert.go`), `orca node join` with mTLS handshake semantics (`internal/cli/node.go`), `orca job run <spec.hcl>`. The PRD repurposes `node join` to SSH-bootstrap (no mTLS), deprecates `cert` (step-ca handles it), and changes `job run` to accept `.md` specs. Each removed/changed command should emit a `slog.Warn` deprecation banner with the v1.0 replacement, *except* when run under `orca upgrade`. The existing `root.go` `PersistentPreRunE` is the natural hook for a global `--no-deprecation-warnings` flag.
|
||||||
|
- **Rationale**: Operators running v0.8 commands against v0.9/v0.10 need to know what changed. The PRD doesn't mention deprecation UX.
|
||||||
|
- **Proposed REQ ID**: REQ-068
|
||||||
|
- **Proposed phase placement**: v0.9-P0X (ship) + v0.10-P13 (ns subcommands, when CLI surface is finalized)
|
||||||
|
- **Confidence**: 0.72
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-M-009 — `internal/config/config.go` HCL config demotion via adapter
|
||||||
|
- **Tier**: mechanical
|
||||||
|
- **Description**: `internal/config/config.go` (127 LOC) parses HCL config with keys `db_path, listen_addr, ca_path, server_cert_path, server_key_path, node_capacity`. The PRD replaces this with Markdown-frontmatter config (R-014) + per-namespace `.env`/`.env.secrets` (R-011). The `listen_addr` and `server_*_path` keys are daemon-specific (deprecated by R-001). The `root.go` `PersistentPreRunE` calls `config.Load(configPath)` on every command — must be repointed to the new Markdown config loader. Proposal: keep `internal/config/` as `legacy_config.go` with `// Deprecated`; add `internal/config/markdown.go` for the new loader; `root.go` dispatches on file extension (`.hcl`→legacy, `.md`→new). The `--config` flag semantics change: `.hcl` is read-only legacy, `.md` is canonical.
|
||||||
|
- **Rationale**: R-014 makes Markdown canonical but `.hcl` must still parse during migration. The existing `config.Load` is called unconditionally in `root.go:42-47`.
|
||||||
|
- **Proposed REQ ID**: REQ-069
|
||||||
|
- **Proposed phase placement**: v0.9-P0a1 (path resolver + config demotion)
|
||||||
|
- **Confidence**: 0.76
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-M-010 — `internal/certpaths/` replacement with multi-namespace path resolver
|
||||||
|
- **Tier**: mechanical
|
||||||
|
- **Description**: `internal/certpaths/certpaths.go` (64 LOC) returns flat paths: `Dir() = $ORCA_HOME`, `CACertPath() = Dir/ca.crt`, `DBPath() = Dir/orca.db`. R-002 requires multi-namespace layout: `ORCA_HOME/<ns>/db/`, `ORCA_HOME/cluster/{ca,master.key,peers,pve,txns}`, `ORCA_HOME/_defaults/`. The package is imported by `doctor`, `proxmox`, `store`, `cli` — changing it is cross-cutting. Proposal: replace `certpaths` with a new `internal/paths` package: `paths.NamespaceDir(ns)`, `paths.ClusterDir()`, `paths.CacheDB()`, `paths.MasterKey()`, `paths.NSDb(ns)`, `paths.NSEnv(ns)`, `paths.NSSecrets(ns)`. Keep `certpaths` as a thin shim that calls `paths` with the default namespace for v0.8 compat, then remove the shim post-v1.0.
|
||||||
|
- **Rationale**: R-002 is foundational and `certpaths` is the single source of path truth. Every adaptable package (`store.Open`, `doctor`, `proxmox`) imports it. Highest-blast-radius mechanical change.
|
||||||
|
- **Proposed REQ ID**: REQ-070
|
||||||
|
- **Proposed phase placement**: v0.9-P0a1 (must come first)
|
||||||
|
- **Confidence**: 0.84
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-M-011 — `internal/store/` schema: per-namespace DBs, drop ns column
|
||||||
|
- **Tier**: mechanical
|
||||||
|
- **Description**: R-002 says "No `namespace` column in SQLite." The v0.8 schema has 7 migrations (`0001`..`0007`) with a single `orca.db`. The v0.10 model has one DB per namespace (`<ns>/db/orca.db`) plus a CLI-side cache DB (`orca_cache.db`, R-008). The existing `store.Open(path)` takes a path arg — adaptable. But the migrations are global; they need to apply *per namespace DB*. Proposal: `store.Open` gains a namespace parameter (or caller passes `paths.NSDb(ns)`); `migrate.go` runs `0001`..`0007` (minus `0006_node_kind_os` which is v0.8-specific) plus new `0008_namespace_layout.sql`. The `cert_repo` (`0004_certs.sql`) is removed (step-ca handles certs). The audit_log table moves to the CLI-side cache DB (R-008). Existing v0.8 `orca.db` is migrated by splitting tables into per-namespace DBs during v0.10-P14.
|
||||||
|
- **Rationale**: R-002 is explicit ("No namespace column in SQLite") but the existing schema has a single DB. §23 doesn't specify the schema split mechanics.
|
||||||
|
- **Proposed REQ ID**: REQ-071
|
||||||
|
- **Proposed phase placement**: v0.9-P0a1 + v0.10-P06 (alloc history, which uses cache DB)
|
||||||
|
- **Confidence**: 0.80
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-M-012 — `internal/transport/` deletion + SSH-push package introduction
|
||||||
|
- **Tier**: mechanical
|
||||||
|
- **Description**: `internal/transport/` (7 files, ~1300 LOC incl tests) implements mTLS client/server, dispatch, idempotency, retry, handshake logging. R-001 + R-006 replace this with SSH-push. The *idempotency* and *retry* logic (`idempotency.go` 123 LOC, `retry.go` 151 LOC) is conceptually reusable for SSH-push (retry on SSH failure, idempotency keys for SCP'd configs). Proposal: delete `mtls.go`, `dispatch.go`, `handshake_log.go`; extract retry/idempotency patterns into a new `internal/sshpush/` package. The existing `transport.IdempotencyStore` (in-memory `sync.Map` of keys) is directly reusable. This avoids re-implementing retry semantics from scratch.
|
||||||
|
- **Rationale**: The codebase audit marks `internal/transport/` as fully replaced, but the retry/idempotency *patterns* are transport-agnostic. §23 doesn't call this out.
|
||||||
|
- **Proposed REQ ID**: REQ-072
|
||||||
|
- **Proposed phase placement**: v0.9-P00 (deprecation sweep) — delete in v0.10-P14
|
||||||
|
- **Confidence**: 0.68
|
||||||
|
- **Accept/Defer**: accept (defer deletion to v0.10-P14 to keep dual-write window open)
|
||||||
|
|
||||||
|
## Tier 2 — Backend-Enriched (Structural / Architectural)
|
||||||
|
|
||||||
|
### I-B-001 — SSH-push transport layer design
|
||||||
|
- **Tier**: backend-enriched
|
||||||
|
- **Description**: The PRD replaces `internal/transport/` (mTLS HTTP) with SSH-push but §23 never specifies the transport's internal design. Key decisions: (1) **Connection pooling**: reuse `*ssh.Client` per peer across multiple SCP/exec operations within a single CLI invocation. (2) **Idempotency**: SCP of a config file is idempotent if content hash matches — use content-addressed filename (`/run/orca/<hash>.unit`) and skip if present. (3) **Retry**: reuse v0.8's exponential backoff (100ms start, ×2, cap 5s, max 5 attempts) applied to SSH dial/exec failures. (4) **Timeout**: per-operation `context.WithTimeout` (default 30s SCP, 10s exec). (5) **Fan-out**: `errgroup.Group` with bounded concurrency for N-peer ops (default 8). (6) **known_hosts**: reuse `proxmox.TOFUHostKeyCallback` for all peers, not just Proxmox.
|
||||||
|
- **Rationale**: Load-bearing replacement for the entire v0.8 transport layer. §23 assumes it but never designs it. Without connection pooling, every CLI operation re-dials SSH.
|
||||||
|
- **Proposed REQ ID**: REQ-073
|
||||||
|
- **Proposed phase placement**: v0.9-P01 (first phase needing SSH-push) — design in v0.9-P0a1
|
||||||
|
- **Confidence**: 0.86
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-B-002 — Emitter template system (Layer 4)
|
||||||
|
- **Tier**: backend-enriched
|
||||||
|
- **Description**: The PRD §5 describes a 4-layer architecture where Layer 4 is "emitters" that render systemd units, Traefik dynamic config, Syncthing config, etc. from the workload spec. §23 never specifies the emitter interface. Proposal: an `internal/emitter/` package with `Emitter` interface: `Render(spec *WorkloadSpec, node *Node) ([]File, error)` where `File{Path, Content, Mode}`. Implementations: `systemdEmitter`, `traefikEmitter`, `syncthingEmitter`, `socketEmitter`. The SSH-push transport SCPs the `[]File` atomically (write-to-tmp + rename). Emitters registered per workload kind + runtime.
|
||||||
|
- **Rationale**: The emitter layer is the bridge between the declarative spec and the server-side files. Without a defined interface, each phase (P02 service, P04 hooks, P08 sockets, P09 storage) will invent its own rendering.
|
||||||
|
- **Proposed REQ ID**: REQ-074
|
||||||
|
- **Proposed phase placement**: v0.9-P0c (schemas + emitter interface)
|
||||||
|
- **Confidence**: 0.82
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-B-003 — Lead applier execution model: pure bash + systemd timer vs CLI-invoked
|
||||||
|
- **Tier**: backend-enriched
|
||||||
|
- **Description**: R-001 says "no orca binary on servers." R-010 says the lead applies desired-state transactionally. Unresolved: does the lead run `orca-pull.sh` (pure bash that SCPs a desired-state bundle and applies it via `systemctl daemon-reload` + `systemctl restart`) or does the operator's CLI SSH into the lead and runs `orca apply` remotely (which would put an orca binary on the lead, violating R-001)? The PRD's intent is the former: the lead is bare Linux with systemd timers + bash. Proposal: (1) the CLI renders a *transaction bundle* (tarball of desired-state files + `apply.sh` + `verify.sh`) on the operator host; (2) SCPs it to the lead's `/run/orca/txns/<txn-id>/`; (3) the lead's systemd timer runs `/run/orca/txns/<txn-id>/apply.sh` which idempotently applies and runs verify; (4) the CLI polls the lead for txn status via SSH (`cat /run/orca/txns/<txn-id>/status.json`). The bash scripts are generated by the CLI's emitter (I-B-002), not hand-written per cluster.
|
||||||
|
- **Rationale**: The most ambiguous load-bearing design decision in the PRD. R-001 + R-010 together imply the lead runs no orca binary, but the lead must apply transactions. §23 doesn't resolve this. Getting it wrong means either violating R-001 or having no transactional apply.
|
||||||
|
- **Proposed REQ ID**: REQ-075
|
||||||
|
- **Proposed phase placement**: v0.10-P10 (transactional plane) — bundle format designed in v0.9-P00
|
||||||
|
- **Confidence**: 0.78
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-B-004 — step-ca integration: provisioning, CA bootstrap, cert signing API, SVID minting
|
||||||
|
- **Tier**: backend-enriched
|
||||||
|
- **Description**: D-101 reverses AD-010 (which rejected step-ca as "too heavyweight"). §23 mentions step-ca in R-006 but never specifies the integration. Key surfaces: (1) **Provisioning**: `orca init` (adapted from v0.8's `internal/cli/init.go`) runs `step ca init` on the lead, stores root + intermediate in `cluster/ca/`. (2) **CA bootstrap**: CLI SSHs to the lead, installs step-ca via apt, runs `step ca init`, stores `step-ca.json` config. (3) **Cert signing API**: workloads request SVIDs via `step ca token` (JWE provisioner token minted by CLI) → `step ca certificate`. The CLI mints the token because it holds the provisioner password (in `cluster/master.key`-derived form). (4) **SVID minting**: each workload gets a SPIFFE ID (`spiffe://orca/<ns>/<workload>/<instance>`) encoded as a SAN in the step-ca-issued cert. The v0.8 `internal/security/ca.go` is deleted; a new `internal/stepca/` package wraps the `step` CLI via SSH (no Go step-ca client library — keep zero-new-dep posture if possible, or add `github.com/smallstep/cli` as a dep).
|
||||||
|
- **Rationale**: step-ca is a new external dependency with its own config format, provisioner model, and CLI. §23 assumes it but never designs the integration. security-engineer persona must be reactivated.
|
||||||
|
- **Proposed REQ ID**: REQ-076
|
||||||
|
- **Proposed phase placement**: v0.9-P07 (runtime block — runtimes need SVIDs) + v0.10-P02 (ACL — SPIFFE identities)
|
||||||
|
- **Confidence**: 0.74
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-B-005 — Traefik dynamic config generation and atomic reload
|
||||||
|
- **Tier**: backend-enriched
|
||||||
|
- **Description**: R-006 makes Traefik load-bearing (mTLS termination + health checks). §23 puts service blocks + Traefik health checks in v0.9-P02. Design: the CLI's Traefik emitter (I-B-002) renders a dynamic config file (`/etc/traefik/dynamic/orca-<ns>-<svc>.yaml`) with backends (the socket paths from R-007), health checks, and mTLS config pointing at step-ca's root. Atomic reload: Traefik watches the dynamic dir with `fsnotify` — writing the file atomically (tmp+rename) triggers a reload. Drain (v0.10-P05) works by writing a config with the backend's `weight=0` or removing it, triggering Traefik to stop routing. The v0.8 codebase has no Traefik integration at all. **Gated by grill C-10** (Traefik config atomicity protocol: tmpfile+fsync+rename + malformed-config hold-last-good verified).
|
||||||
|
- **Rationale**: Traefik is net-new and load-bearing. §23 mentions it in R-006/P02/P05 but never specifies config generation or reload mechanism.
|
||||||
|
- **Proposed REQ ID**: REQ-077
|
||||||
|
- **Proposed phase placement**: v0.9-P02 (Service block + checks)
|
||||||
|
- **Confidence**: 0.80
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-B-006 — Runtime abstraction interface (5 backends: wasm/podman/process/pve-vm/pve-ct)
|
||||||
|
- **Tier**: backend-enriched
|
||||||
|
- **Description**: v0.8's `internal/engine/executor.go` (211 LOC) is `os/exec` only. R-004/R-007 require 5 runtime backends. §23 puts this in v0.9-P07. Proposal: a `Runtime` interface in `internal/runtime/`: `Prepare(ctx, spec, node) (*Alloc, error)`, `Start(ctx, alloc) (pid/unit, error)`, `Stop(ctx, alloc) error`, `Status(ctx, alloc) (State, error)`. Implementations: `processRuntime` (wraps existing `executor.go` — directly reusable), `wasmRuntime` (wasmtime via CLI SSH exec), `podmanRuntime` (`podman run` via SSH), `pveVMRuntime` (`qm create`/`qm start` via v0.8 `proxmox` SSH session), `pveCTRuntime` (`pct create`/`pct start`). Each registered in a `runtimeRegistry` keyed by the `runtime:` frontmatter value. R-004 (migration with runtime change) means the `Alloc` carries a `runtime` field that can change on migration — `Prepare` re-runs with the new runtime.
|
||||||
|
- **Rationale**: The 5 backends are the largest net-new implementation surface. §23 lists them as one phase (P07) but under-specifies the interface contract. The existing `executor.go` is a good starting point for the `processRuntime` adapter.
|
||||||
|
- **Proposed REQ ID**: REQ-078
|
||||||
|
- **Proposed phase placement**: v0.9-P07a/P07b/P07c (split per grill PC-10)
|
||||||
|
- **Confidence**: 0.82
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-B-007 — Transaction bundle format and atomicity across N peers
|
||||||
|
- **Tier**: backend-enriched
|
||||||
|
- **Description**: R-010 requires transactional control-plane updates. §23 puts this in v0.10-P10. Design: a *transaction bundle* is a tarball containing: (1) `desired-state.json` (full desired state for affected namespaces), (2) `apply.sh` (idempotent apply script), (3) `verify.sh` (post-apply invariants), (4) `rollback.sh` (revert to previous state), (5) `manifest.sig` (signature with `cluster/master.key`). Atomicity across N peers: the CLI uploads the bundle to the lead; the lead applies to itself first, then fans out to peers via SSH. If any peer fails verify, the lead runs `rollback.sh` on all peers that applied. The bundle is content-addressed (`<txn-id> = sha256(desired-state.json)`) and stored in `cluster/txns/<txn-id>/`. Drift detection (R-010) compares the last applied bundle's desired-state against the live state (polled via SSH `systemctl show` + file checksums). **Gated by grill C-09** (orca-pull.sh failure contract: idempotent re-run, bounded retry, deterministic state, structured syslog).
|
||||||
|
- **Rationale**: Multi-peer atomicity is the hardest part of R-010. §23 says "ArgoCD-style" but ArgoCD is Kubernetes-native; the SSH-push model needs a custom bundle format.
|
||||||
|
- **Proposed REQ ID**: REQ-079
|
||||||
|
- **Proposed phase placement**: v0.10-P10 (transactional plane) — designed in v0.9-P00
|
||||||
|
- **Confidence**: 0.76
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-B-008 — Master key management and HKDF-SHA256 per-line .env.secrets encryption
|
||||||
|
- **Tier**: backend-enriched
|
||||||
|
- **Description**: R-011 specifies `.env.secrets` with AES-256-GCM, per-line nonce, master key at `cluster/master.key`. §23 puts this in v0.10-P03. Design: (1) `cluster/master.key` is a 32-byte random key generated by `orca init` (extend v0.8 `internal/security/ca.go`'s `WriteAtomic` pattern for the file write). (2) Each line of `.env.secrets` is `base64(nonce || ciphertext || tag)` where `nonce = random(12 bytes)` and `ciphertext = AES-256-GCM(plaintext, key=master.key, nonce, aad=line-number)`. (3) The AAD is the 1-indexed line number to prevent line-swap attacks. (4) Decryption reads the master key, iterates lines, decrypts with AAD. (5) `orca secrets set <ns> <key> <value>` appends an encrypted line; `orca secrets get <ns> <key>` decrypts and prints (redacted by default, `--reveal` to show). (6) The v0.8 `internal/security/redact.go` (103 LOC) is directly reusable for redaction. HKDF-SHA256 derives per-namespace sub-keys from the master key (`HKDF-SHA256(master, info=<ns>)`) so compromising one namespace's key doesn't compromise others — but the master key is the root of trust. **Gated by grill C-19** (threat model for master.key passphrase-less posture).
|
||||||
|
- **Rationale**: R-011 is precise about the crypto but §23 doesn't specify key derivation, AAD, or CLI surface. The existing `redact.go` and `WriteAtomic` are reusable.
|
||||||
|
- **Proposed REQ ID**: REQ-080
|
||||||
|
- **Proposed phase placement**: v0.10-P03 (secrets subsystem)
|
||||||
|
- **Confidence**: 0.84
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-B-009 — Syncthing config rendering and folder-ID content-addressing
|
||||||
|
- **Tier**: backend-enriched
|
||||||
|
- **Description**: R-005 requires storage replication via per-namespace Syncthing. §23 puts this in v0.9-P09. Design: (1) each namespace gets a Syncthing folder `orca-<ns>` with a content-addressed folder ID (`sha256(ns + master-key-fingerprint)`). (2) The CLI renders `config.xml` for each peer's Syncthing instance, including the folder, devices (all peers in the namespace), and the path (`<ns>/alloc/<alloc-id>/`). (3) Syncthing runs as a systemd unit (emitted by the systemd emitter, I-B-002). (4) The CLI discovers peers via `cluster/peers/` and adds their Syncthing device IDs (each peer's Syncthing generates its own device key on first run, reported back via SSH). (5) R-005 says "a Service's count replicas share one runtime block" — the Syncthing folder is shared across the Service's alloc instances so all replicas see the same data. Migration (R-004) works because the new node joins the Syncthing folder and syncs before the workload starts. **Gated by grill C-02** (Syncthing feasibility spike) and **C-14** (deterministic conflict-resolution policy + forced-divergence integration test).
|
||||||
|
- **Rationale**: Syncthing is net-new. §23 lists it in P09 but doesn't specify config rendering, folder-ID scheme, or device discovery.
|
||||||
|
- **Proposed REQ ID**: REQ-081
|
||||||
|
- **Proposed phase placement**: v0.9-P09 (storage replication) — spike in v0.9-P00
|
||||||
|
- **Confidence**: 0.72
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-B-010 — Namespace inheritance resolver algorithm
|
||||||
|
- **Tier**: backend-enriched
|
||||||
|
- **Description**: v0.9-P0a2 requires a "parent walker, cycle detection" for namespace inheritance. Each `ns.md` has a `parent:` field in frontmatter. The resolver walks up the parent chain, merging inherited values (constraints, env, runtime defaults). Cycle detection: DFS with a visited set; if a namespace is revisited, return a cycle error. The resolver returns a flattened `ResolvedNamespace` struct. The `_defaults/` namespace is the implicit root (always exists, has no parent). Inheritance semantics: child overrides parent for scalar fields; arrays (e.g., constraints) are unioned (child adds to parent, not replaces). The resolver is pure (no I/O) — it takes a map of `nsName → *NSConfig` and returns `nsName → *ResolvedNS`. This makes it trivially testable.
|
||||||
|
- **Rationale**: §23 mentions "parent walker, cycle detection" but not the merge semantics (override vs union) or the resolver's purity for testing. Getting merge semantics wrong breaks constraint inheritance (P05).
|
||||||
|
- **Proposed REQ ID**: REQ-082
|
||||||
|
- **Proposed phase placement**: v0.9-P0a2 (namespace CRUD + inheritance)
|
||||||
|
- **Confidence**: 0.86
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-B-011 — Bin-packing scheduler redesign (CLI-side, runtime-compatibility scoring)
|
||||||
|
- **Tier**: backend-enriched
|
||||||
|
- **Description**: v0.8's `internal/engine/scheduler.go` (117 LOC) does best-fit bin-packing by CPU+memory. The v0.9 scheduler must: (1) run CLI-side (not on a daemon), (2) score nodes by runtime compatibility (a wasm workload can only go to a node with wasmtime installed; a pve-vm workload can only go to Proxmox nodes), (3) respect constraints/affinity (CEL over node attributes, P05), (4) handle the 3 kinds differently (Job = one-shot, Service = count replicas spread across nodes, DaemonSet = one per node). The existing `scheduler.go` is a good skeleton but the scoring function changes entirely. Proposal: `Score(node, workload) (score int, fits bool)` where `fits` checks runtime compatibility + constraints, and `score` is the bin-packing score (most free capacity = highest score). For Services, the scheduler picks `count` distinct nodes (anti-affinity by default). For DaemonSets, it picks all matching nodes.
|
||||||
|
- **Rationale**: The scheduler moves from daemon-side to CLI-side (R-001) and gains runtime-awareness. §23 scatters this across P05 (constraints), P06 (task groups), P07 (runtime), P10 (migration) but never designs the scheduler itself.
|
||||||
|
- **Proposed REQ ID**: REQ-083
|
||||||
|
- **Proposed phase placement**: v0.9-P05 (constraints & affinity — scheduler needs constraints to be meaningful) — skeleton in P0c
|
||||||
|
- **Confidence**: 0.80
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-B-012 — `orca job lint` category-driven lint engine design
|
||||||
|
- **Tier**: backend-enriched
|
||||||
|
- **Description**: v0.10-P11 requires `orca job lint` with `--explain`. Design: a `Linter` that takes a `*WorkloadSpec` and runs a series of `Rule` checks, each returning a `Finding{Category, Severity, Message, Explanation}`. Categories: `schema` (missing required fields), `runtime` (incompatible runtime+constraint), `security` (missing SVID, plaintext secret in env), `migration` (missing storage replication for a migratable service), `best-practice` (no health check on a Service). `--explain` prints the rationale for each finding. Rules are registered in a `ruleRegistry` and individually testable. The linter is pure (no I/O) — it checks the spec against static rules, not live cluster state (that's `orca job verify`, P12).
|
||||||
|
- **Rationale**: §23 puts this in P11 but only says "category-driven." The rule interface and category taxonomy are unspecified.
|
||||||
|
- **Proposed REQ ID**: REQ-084
|
||||||
|
- **Proposed phase placement**: v0.10-P11 (orca job lint)
|
||||||
|
- **Confidence**: 0.78
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
## Tier 3 — Cross-Cutting (Risk & Multi-Phase)
|
||||||
|
|
||||||
|
### I-C-001 — v0.8→v1.0 migration ordering: daemon deprecation vs. new model rollout
|
||||||
|
- **Tier**: cross-cutting
|
||||||
|
- **Description**: The PRD §24 covers *data* migration but not *binary/daemon* deprecation ordering. The risk: v0.9 builds the new Markdown+kinds+runtime+SSH-push model, but v0.8 daemons are still running on peers. If v0.9 ships the new `orca job run` (Markdown) while the old daemon is still the execution engine, there's a split-brain: new specs can't run on the old daemon. Ordering proposal: (1) v0.9 ships the new parser + kinds + runtime + SSH-push *alongside* the old daemon (dual-write window); (2) `orca job run` in v0.9 uses the new SSH-push path if the spec is `.md` and the old daemon path if `.hcl`; (3) v0.10-P05 (drain) stops the old daemons; (4) v0.10-P14 (migration) converts remaining `.hcl` specs to `.md` and removes the daemon. The dual-write window means v0.9 is *not* a clean break — it's a compatibility milestone. This must be explicit in the plan or the v0.9 phases will assume the daemon is gone.
|
||||||
|
- **Rationale**: Single largest risk in the re-architecture. §23 implicitly assumes v0.9 builds the new model in isolation, but existing deployments have running daemons. Getting the ordering wrong means either (a) v0.9 can't be tested against real deployments, or (b) workloads are orphaned when the daemon is removed.
|
||||||
|
- **Proposed REQ ID**: REQ-085
|
||||||
|
- **Proposed phase placement**: spans v0.9-P00 through v0.10-P14 — the *ordering decision* must be made in v0.9-P00
|
||||||
|
- **Confidence**: 0.88
|
||||||
|
- **Accept/Defer**: accept (most important idea in this report)
|
||||||
|
|
||||||
|
### I-C-002 — "No orca on server" enforcement (doctor post-migration invariant check)
|
||||||
|
- **Tier**: cross-cutting
|
||||||
|
- **Description**: R-001 is an invariant: "no orca Go binary on any server." §23 v0.10-P14 says "post-invariant checks" but doesn't specify them. `orca doctor` must gain a `doctor no-orca-on-server` check that SSHs to each peer and verifies: (1) no `orca` binary in PATH (`ssh peer which orca` returns nothing), (2) no `orca` systemd service (`ssh peer systemctl list-units 'orca*'` returns empty), (3) no `orca` process (`ssh peer pgrep -x orca` returns empty), (4) no `/etc/orca/` directory. This check must run *after* v0.10-P05 (drain) and *before* v0.10-P16 (ship). The v0.8 `internal/proxmox/bootstrap.go` already has the SSH session infrastructure (`sessionRunner` seam) — directly reusable for the doctor check.
|
||||||
|
- **Rationale**: R-001 is a hard invariant but §23 doesn't enforce it post-migration. Without this check, a failed migration could leave orphaned daemons that cause split-brain.
|
||||||
|
- **Proposed REQ ID**: REQ-086
|
||||||
|
- **Proposed phase placement**: v0.10-P14c (mixed-version tolerance)
|
||||||
|
- **Confidence**: 0.82
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-C-003 — Test infrastructure: hermetic 3-linux + 1-proxmox cluster pipeline
|
||||||
|
- **Tier**: cross-cutting
|
||||||
|
- **Description**: §23 v0.10-P08 requires "hermetic CoreCI integration pipeline." The PRD §26.E mentions 3 linux + 1 proxmox. This is net-new test infra with zero current implementation. Design: (1) a `test/integration/` directory with a `docker-compose.yml` or `vagrant` setup that creates 4 containers/VMs (3 linux + 1 proxmox-simulated); (2) a Go test harness that SSHes to each, runs the CLI, and asserts end-to-end workflows (namespace create → workload submit → migrate → drain); (3) the proxmox node is simulated via a mock `pct`/`qm` script (the v0.8 `proxmox` package already has a `sessionRunner` seam for testability — extend it). The integration tests run in CoreCI on every milestone merge. The v0.8 e2e tests (`bootstrapE2ESetup` in `bootstrap_test.go`) use an in-process SSH server — this is the foundation but needs to scale to 4 nodes.
|
||||||
|
- **Rationale**: §23 assumes the infra exists but doesn't design it. devops-engineer persona should be reactivated. Without hermetic infra, the integration tests can't run in CI.
|
||||||
|
- **Proposed REQ ID**: REQ-087
|
||||||
|
- **Proposed phase placement**: v0.10-P08 (integration tests) — harness bootstrapped in v0.9-P00
|
||||||
|
- **Confidence**: 0.80
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-C-004 — Security-engineer + network-engineer persona reactivation for new attack surfaces
|
||||||
|
- **Tier**: cross-cutting
|
||||||
|
- **Description**: The config.json has `security-engineer` and `network-engineer` dormant. The re-architecture introduces step-ca (PKI), Traefik (edge proxy), Syncthing (P2P file sync), wasmtime (sandbox), podman (container runtime) — all new attack surfaces. AD-010 (step-ca rejection) is reversed. The v0.8 security posture (internal CA, mTLS daemon-to-daemon) is replaced by (step-ca, SSH-push, Traefik mTLS). The security-engineer persona must be reactivated to review: (1) step-ca provisioner model (the CLI holds the provisioner password — is that in `cluster/master.key` or a separate secret?), (2) SSH-push blast radius (compromised CLI key = full cluster), (3) Traefik as the new edge (DoS, config injection), (4) `.env.secrets` crypto (I-B-008). The network-engineer persona must review: (1) socket-based service exposure (R-007), (2) Syncthing P2P ports, (3) Traefik routing. §23 doesn't mention persona reactivation.
|
||||||
|
- **Rationale**: config.json explicitly notes the re-architecture "should reactivate security-engineer and network-engineer." Cross-cutting review concern, not a single phase.
|
||||||
|
- **Proposed REQ ID**: REQ-088
|
||||||
|
- **Proposed phase placement**: spans v0.9 through v0.10 — reactivation in v0.9-P00, review at v0.10-P15.5 (threat model) and v0.10-P16 (final audit)
|
||||||
|
- **Confidence**: 0.84
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-C-005 — Documentation rewrite: ARCHITECTURE.md, PROJECT.md, README, AD-010 supersession
|
||||||
|
- **Tier**: cross-cutting
|
||||||
|
- **Description**: All three docs describe the OLD architecture. `ARCHITECTURE.md` (640 lines) describes the daemon layer, mTLS transport, internal CA, HCL jobspec — all deprecated. `PROJECT.md` (30k chars) has D-001..D-010 decisions, several now superseded. `README.md` has the v0.8 quickstart. AD-010 (step-ca rejection) must be explicitly superseded by D-101 with a dated rationale reversal. The anti-patterns section in `ARCHITECTURE.md:471-484` lists "No external PKI" — now reversed. Proposal: (1) in v0.9-P00, add a "v0.9 Architecture (Supersedes v0.8)" section to ARCHITECTURE.md with the new 4-layer model; (2) mark the old sections as "v0.8 (deprecated)" with banners; (3) add a "Superseded Decisions" table (AD-009, AD-010 reversed by D-101; AD-007 HCL demoted by R-013); (4) in v0.10-P15, rewrite README quickstart for the new `curl | sh` + `orca init` + `orca ns create` flow.
|
||||||
|
- **Rationale**: The docs are the first thing new contributors read. Leaving v0.8 docs as canonical during v0.9 development causes confusion. §23 mentions README in P15 but not ARCHITECTURE.md/PROJECT.md.
|
||||||
|
- **Proposed REQ ID**: REQ-089
|
||||||
|
- **Proposed phase placement**: v0.9-P00 (banners + supersession table) + v0.10-P15 (README quickstart) + v0.10-P16 (final review)
|
||||||
|
- **Confidence**: 0.82
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
### I-C-006 — Dual-write window: can v0.9 ship new parser while old daemon runs?
|
||||||
|
- **Tier**: cross-cutting
|
||||||
|
- **Description**: Focused version of I-C-001. The specific question: in v0.9, when the new Markdown parser + kinds + SSH-push are shipped, can they coexist with v0.8 daemons still running on peers? The answer depends on whether `orca job run <spec.md>` uses the new SSH-push path (bypassing the daemon entirely) or routes through the old daemon. If it bypasses, the daemon is irrelevant for new specs but still serves old `.hcl` specs. If it routes through, the daemon can't handle `.md` specs. Proposal: v0.9 `orca job run` dispatches on extension (`.md`→SSH-push new path, `.hcl`→old daemon path) via the parser dispatcher (I-M-004). This is a *dual-write window* where both paths coexist. The daemon is not removed until v0.10-P05 (drain). The risk: if a `.md` workload and a `.hcl` workload target the same node, the SSH-push path writes systemd units directly while the daemon also manages units — they can conflict. Mitigation: the SSH-push path writes to a separate systemd unit namespace (`orca-v1-<alloc>.service`) while the daemon uses `orca-<job>.service`. No unit name overlap = no conflict.
|
||||||
|
- **Rationale**: Operational feasibility question for v0.9. §23 doesn't address it. If the answer is "no dual-write, daemon must be removed first," then v0.9 can't be tested incrementally and must ship as a big-bang — much higher risk.
|
||||||
|
- **Proposed REQ ID**: REQ-090
|
||||||
|
- **Proposed phase placement**: v0.9-P00 (decision before any v0.9 execution phase)
|
||||||
|
- **Confidence**: 0.86
|
||||||
|
- **Accept/Defer**: accept
|
||||||
|
|
||||||
|
## Summary Table
|
||||||
|
|
||||||
|
| ID | Tier | Title | REQ | Phase | Conf | Accept |
|
||||||
|
|----|------|-------|-----|-------|------|--------|
|
||||||
|
| I-M-001 | M | `orca daemon` deprecation path | REQ-061 | v0.10-P14 (warn v0.9-P0X) | 0.82 | accept |
|
||||||
|
| I-M-002 | M | Coverage follow-ups to 70% | REQ-062 | v0.9-P0X + each new pkg | 0.88 | accept |
|
||||||
|
| I-M-003 | M | known_hosts flock concurrency | REQ-063 | v0.9-P0a1 | 0.74 | accept |
|
||||||
|
| I-M-004 | M | HCL→Markdown jobspec adapter | REQ-064 | v0.9-P0b | 0.85 | accept |
|
||||||
|
| I-M-005 | M | `doctor --legacy-paths` detection | REQ-065 | v0.10-P14c | 0.80 | accept |
|
||||||
|
| I-M-006 | M | Legacy CA state migration to step-ca | REQ-066 | v0.10-P14a | 0.70 | accept |
|
||||||
|
| I-M-007 | M | Fuzz harness for Markdown parser | REQ-067 | v0.9-P0b | 0.78 | accept |
|
||||||
|
| I-M-008 | M | Deprecation warnings on CLI subcommands | REQ-068 | v0.9-P0X + v0.10-P13 | 0.72 | accept |
|
||||||
|
| I-M-009 | M | HCL config demotion via adapter | REQ-069 | v0.9-P0a1 | 0.76 | accept |
|
||||||
|
| I-M-010 | M | certpaths → multi-namespace path resolver | REQ-070 | v0.9-P0a1 | 0.84 | accept |
|
||||||
|
| I-M-011 | M | store schema: per-namespace DBs | REQ-071 | v0.9-P0a1 + v0.10-P06 | 0.80 | accept |
|
||||||
|
| I-M-012 | M | transport deletion + SSH-push package | REQ-072 | v0.9-P00 (delete v0.10-P14) | 0.68 | accept |
|
||||||
|
| I-B-001 | B | SSH-push transport layer design | REQ-073 | v0.9-P01 | 0.86 | accept |
|
||||||
|
| I-B-002 | B | Emitter template system (Layer 4) | REQ-074 | v0.9-P0c | 0.82 | accept |
|
||||||
|
| I-B-003 | B | Lead applier execution model | REQ-075 | v0.10-P10 (design v0.9-P00) | 0.78 | accept |
|
||||||
|
| I-B-004 | B | step-ca integration | REQ-076 | v0.9-P07 + v0.10-P02 | 0.74 | accept |
|
||||||
|
| I-B-005 | B | Traefik dynamic config + atomic reload | REQ-077 | v0.9-P02 | 0.80 | accept |
|
||||||
|
| I-B-006 | B | Runtime abstraction (5 backends) | REQ-078 | v0.9-P07a/b/c | 0.82 | accept |
|
||||||
|
| I-B-007 | B | Transaction bundle + N-peer atomicity | REQ-079 | v0.10-P10 (design v0.9-P00) | 0.76 | accept |
|
||||||
|
| I-B-008 | B | Master key + HKDF per-line encryption | REQ-080 | v0.10-P03 | 0.84 | accept |
|
||||||
|
| I-B-009 | B | Syncthing config + folder-ID | REQ-081 | v0.9-P09 | 0.72 | accept |
|
||||||
|
| I-B-010 | B | Namespace inheritance resolver | REQ-082 | v0.9-P0a2 | 0.86 | accept |
|
||||||
|
| I-B-011 | B | CLI-side scheduler redesign | REQ-083 | v0.9-P05 (skeleton P0c) | 0.80 | accept |
|
||||||
|
| I-B-012 | B | `orca job lint` category-driven engine | REQ-084 | v0.10-P11 | 0.78 | accept |
|
||||||
|
| I-C-001 | C | v0.8→v1.0 migration ordering | REQ-085 | spans v0.9-P00→v0.10-P14 | 0.88 | accept |
|
||||||
|
| I-C-002 | C | "No orca on server" enforcement | REQ-086 | v0.10-P14c | 0.82 | accept |
|
||||||
|
| I-C-003 | C | Hermetic test infra (3 linux + 1 pve) | REQ-087 | v0.10-P08 (bootstrap v0.9-P00) | 0.80 | accept |
|
||||||
|
| I-C-004 | C | security/network persona reactivation | REQ-088 | spans v0.9→v0.10-P16 | 0.84 | accept |
|
||||||
|
| I-C-005 | C | Docs rewrite + AD-010 supersession | REQ-089 | v0.9-P00 + v0.10-P15/P16 | 0.82 | accept |
|
||||||
|
| I-C-006 | C | Dual-write window decision | REQ-090 | v0.9-P00 | 0.86 | accept |
|
||||||
|
|
||||||
|
## Phase Reordering / Addition Flags (against PRD §23)
|
||||||
|
|
||||||
|
1. **I-C-001 / I-C-006 (dual-write + migration ordering)** — require a decision in v0.9-P00 (before any execution phase). **Recommendation: add v0.9-P00 deprecation/migration-ordering pre-phase.** Most important structural addition.
|
||||||
|
2. **I-M-010 / I-M-011 / I-M-009 / I-M-003** — all land in v0.9-P0a. P0a may be overloaded. **Recommendation: split P0a into P0a1 (path/layout resolver + config demotion) and P0a2 (namespace CRUD + inheritance).** Path resolver is prerequisite for everything; highest blast radius.
|
||||||
|
3. **I-B-001 (SSH-push transport)** — §23 v0.9-P01 needs SSH-push. The design is a prerequisite. **Recommendation: SSH-push design in P0a1, not deferred to P01.**
|
||||||
|
4. **I-B-002 (emitter template system)** — should be designed *with* the schemas (P0c). **Recommendation: expand P0c to "schemas + emitter interface."**
|
||||||
|
5. **I-B-003 (lead applier model)** — bundle format + lead applier model must be designed *in v0.9* so the emitter can produce bundle-compatible output. **Recommendation: design spike in v0.9-P00.**
|
||||||
|
6. **I-C-003 (test infra)** — hermetic cluster harness should be bootstrapped in v0.9-P00 so every v0.9 phase can run integration tests. **Recommendation: bootstrap in v0.9-P00, expand in v0.10-P08.**
|
||||||
|
7. **I-C-004 / I-C-005 (persona reactivation + docs)** — span the whole milestone. **Recommendation: fold persona reviews into v0.9-P00 and v0.10-P16; fold doc banners into v0.9-P00.**
|
||||||
|
|
||||||
|
## Cross-Reference Against Existing Decisions
|
||||||
|
|
||||||
|
- **AD-009 (Internal CA, no external PKI)** — Superseded by D-101 (step-ca). I-B-004, I-M-006 implement the reversal.
|
||||||
|
- **AD-010 (Roll-our-own CA)** — Superseded by D-101. I-C-005 documents the supersession. No re-litigation — the PRD has decided; the override justification records the evidence basis.
|
||||||
|
- **AD-007 (HCL for job specs)** — Demoted by R-013 (Markdown canonical, HCL accepted). I-M-004 implements the adapter. Not a full reversal — HCL still parses.
|
||||||
|
- **AD-001 (Single binary with subcommands)** — Still holds. The CLI is the single binary; no orca on servers (R-001) refines this.
|
||||||
|
- **AD-015 (Best-fit bin-packing)** — Extended, not reversed. I-B-011 adds runtime-compatibility scoring.
|
||||||
|
- **D-035 (TOFU host-key)** — Still holds for non-Proxmox peers. I-M-003 hardens the concurrency. I-B-001 reuses `TOFUHostKeyCallback`.
|
||||||
|
- **D-046 (key-reset is local-only)** — Still holds. I-M-003 adds the lock.
|
||||||
|
- **D-047 (tiered coverage floor)** — Extended by I-M-002 to cover new packages.
|
||||||
|
|
||||||
|
No accepted idea re-litigates a settled decision. All reversals (AD-009, AD-010, SPIFFE, no-container, no-multi-tenancy, HCL-canonical, daemon-on-every-node) are explicitly mandated by the PRD and justified by the recorded override justification.
|
||||||
|
|
||||||
|
## Final Notes
|
||||||
|
|
||||||
|
- **Total ideas**: 30 (12 mechanical, 12 backend-enriched, 6 cross-cutting).
|
||||||
|
- **Highest-confidence, highest-impact**: I-C-001 (migration ordering, 0.88) and I-C-006 (dual-write window, 0.86) — these shape the entire v0.9 execution strategy.
|
||||||
|
- **Highest-blast-radius mechanical**: I-M-010 (path resolver, 0.84) — touches every adaptable package.
|
||||||
|
- **Most under-specified by PRD**: I-B-003 (lead applier execution model, 0.78) — R-001 + R-010 create a tension the PRD doesn't resolve.
|
||||||
+150
-22
@@ -1,3 +1,144 @@
|
|||||||
|
---
|
||||||
|
active:
|
||||||
|
- lead-developer
|
||||||
|
- backend-engineer
|
||||||
|
- data-engineer
|
||||||
|
- security-engineer
|
||||||
|
- network-engineer
|
||||||
|
- devops-engineer
|
||||||
|
deactivated:
|
||||||
|
- cli-engineer
|
||||||
|
- frontend-engineer
|
||||||
|
phase_specific: []
|
||||||
|
reason: |
|
||||||
|
Orca v0.9 is the first DIRECTION-CHANGE milestone in the project's
|
||||||
|
history. It supersedes the shipped v0.1–v0.8 architecture per the adopted
|
||||||
|
PRD (.ciagent/PRD_v0.9.md). The re-architecture deprecates the daemon/
|
||||||
|
transport/internal-CA/HCL/single-namespace stack and builds a CLI-only/
|
||||||
|
SSH-push/step-ca/Markdown-frontmatter/multi-namespace stack plus 8
|
||||||
|
net-new subsystems. The user overrode the grill's Re-architecture
|
||||||
|
Justification REPLAN with a six-part evidence basis (see PROJECT.md
|
||||||
|
Supersession Table). The ci-griller's 19 binding conditions (C-01..C-19)
|
||||||
|
and 10 phase challenges (PC-01..PC-10) are adopted as execution gates
|
||||||
|
(see GRILL_v0.9.md).
|
||||||
|
|
||||||
|
Roster changes vs v0.8 (implements grill C-05):
|
||||||
|
- lead-developer: RETAINED — owns the CLI subcommand tree, deprecation
|
||||||
|
sweep (P00), path resolver (P0a1), parser dispatch (P0b), emitter
|
||||||
|
interface (P0c), and milestone coordination.
|
||||||
|
- backend-engineer: RETAINED — owns SSH-push transport (P01), runtime
|
||||||
|
abstraction (P07a/b/c), transaction bundle (P10 design), step-ca
|
||||||
|
integration, secrets crypto. Frameworks updated: golang.org/x/crypto/ssh
|
||||||
|
(existing), golang.org/x/crypto/ssh/knownhosts (existing); pending
|
||||||
|
deps: bytecodealliance/wasmtime-go (C-01 gate), smallstep/cli (I-B-004).
|
||||||
|
- data-engineer: RETAINED — owns per-namespace DB schema split (P0a1,
|
||||||
|
REQ-071), CLI cache DB (R-008), namespace inheritance resolver state
|
||||||
|
(P0a2). Frameworks: modernc/sqlite.
|
||||||
|
- security-engineer: REACTIVATED — owns step-ca provisioning (REQ-076),
|
||||||
|
master.key + AES-256-GCM crypto (REQ-080, C-19 threat model), SPIFFE
|
||||||
|
SVID minting (C-08 spike), SSH-push blast-radius review, Traefik edge,
|
||||||
|
.env.secrets threat model. The re-architecture reverses AD-010
|
||||||
|
(step-ca rejection) and the SPIFFE rejection at PROJECT.md:94; both
|
||||||
|
reversals are justified in the Supersession Table.
|
||||||
|
- network-engineer: REACTIVATED — owns socket-based service exposure
|
||||||
|
(R-007, P08), Syncthing P2P ports (P09), Traefik routing + dynamic
|
||||||
|
config atomicity (P02, C-10). The transport layer moves from mTLS
|
||||||
|
HTTP daemon-to-daemon to SSH CLI-to-server; network-engineer reviews
|
||||||
|
the new trust surface.
|
||||||
|
- devops-engineer: REACTIVATED — owns bash scripts (scripts/orca-*.sh,
|
||||||
|
C-15..C-18: bats/shellcheck/shfmt gate, render-format contract,
|
||||||
|
slog-syslog), systemd timers (orca-pull/drift/aggregate, C-09 failure
|
||||||
|
contract, C-11 watchdog), hermetic test infra (P00 bootstrap, P08
|
||||||
|
expand, REQ-087).
|
||||||
|
- cli-engineer: remains DEACTIVATED — CLI surface growth is owned by
|
||||||
|
lead-developer (cobra subcommands) + backend-engineer (transport);
|
||||||
|
reactivation optional if CLI subcommand surface exceeds lead-developer
|
||||||
|
bandwidth.
|
||||||
|
- frontend-engineer: remains DEACTIVATED — no web UI (unchanged from
|
||||||
|
v0.1 onward; R-014 makes Markdown canonical, not a web UI).
|
||||||
|
---
|
||||||
|
|
||||||
|
# Personas: Orca
|
||||||
|
|
||||||
|
## v0.9 persona assessment (supersedes v0.8)
|
||||||
|
|
||||||
|
The v0.9 re-architecture introduces 5 new external apt dependencies (step-ca,
|
||||||
|
Traefik, Syncthing, wasmtime, podman), 8 net-new subsystems, and deprecates
|
||||||
|
~10k lines of shipped daemon/transport/CA/HCL code. The active roster grows
|
||||||
|
from 3 to 6 to cover the new attack surfaces and deployment model. Territory
|
||||||
|
enforcement remains in `warn` mode per config.json.
|
||||||
|
|
||||||
|
### lead-developer
|
||||||
|
- **Domain**: coordination
|
||||||
|
- **Frameworks**: `cobra`, `net/http/httptest`, `testing`
|
||||||
|
- **Constraints**: `boundary-enforcement`, `offline-first`, `no-redundant-implementations`, `coverage-floor-70`
|
||||||
|
- **Territory**: `cmd/**`, `internal/cli/**`, `cmd/verify-reqs/**`, `Makefile`, `.coreci.yml`, `.ciagent/**`
|
||||||
|
- **Active**: true
|
||||||
|
- **Reason**: Owns P01 coverage for `cmd/orca` (smoke test of `main()`/`cli.Execute()`), `internal/cli` coverage for the non-node, non-daemon subcommands (`cert *`, `doctor *`, `audit list`, `status`, `version`), and the P03 `cmd/verify-reqs/main.go` Go program + `make verify-reqs` Makefile target + `.coreci.yml` validate-pipeline hook. Added `coverage-floor-70` constraint (D-047 tiered floor: 70% for the 6 under-50% packages, 50% for the 3 zero-test packages). Added `testing` + `net/http/httptest` to frameworks (test-only phase).
|
||||||
|
|
||||||
|
### backend-engineer
|
||||||
|
- **Domain**: backend
|
||||||
|
- **Frameworks**: `cobra`, `net/http`, `net/http/httptest`, `golang.org/x/crypto/ssh`, `golang.org/x/crypto/ssh/knownhosts`, `testing`
|
||||||
|
- **Constraints**: `API-first`, `error-handling`, `minimal-dependencies`, `security-first`, `tofu-host-key-pinning`, `pinned-host-key-fail-closed`, `atomic-file-rewrite`, `coverage-floor-70`
|
||||||
|
- **Territory**: `internal/transport/**`, `internal/engine/**`, `internal/proxmox/**`, `internal/cli/node.go`, `internal/daemon/**` (tests only)
|
||||||
|
- **Active**: true
|
||||||
|
- **Reason**: Owns P01 coverage for `internal/transport` (httptest.NewTLSServer for mTLS + stubDispatcher for DispatchClient) and `internal/engine` (LocalExecutor stubs + PeerRegistry in-memory tests). Owns P02 SSH trust hardening: `--host-key-fingerprint` pinned callback in `internal/proxmox/bootstrap.go` (D-045 OpenSSH SHA256:base64 format, AD-027/AD-028), the TOFU capture-fix (knownhosts.New returns KeyError{Want:[]} on first connect — must capture-and-persist via knownhosts.Line, AD-029 atomic rewrite), the `sessionRunner` seam refactor (P01 enabler for proxmox coverage), and `internal/cli/node.go` `--host-key-fingerprint` flag + `key-reset` subcommand (D-046 local known_hosts only). Frameworks updated: `connectrpc` REMOVED (not in go.mod per AD-014 — config.json still lists it but it's a stale entry), `golang.org/x/crypto/ssh` + `knownhosts` ADDED (direct dep since v0.6 D-030). Added `pinned-host-key-fail-closed` + `atomic-file-rewrite` + `coverage-floor-70` constraints.
|
||||||
|
|
||||||
|
### data-engineer
|
||||||
|
- **Domain**: data
|
||||||
|
- **Frameworks**: `modernc/sqlite`, `iter`, `hashicorp/hcl/v2`, `testing`
|
||||||
|
- **Constraints**: `schema-first`, `migration-safe`, `local-storage-only`, `no-goroutine-leak`, `nullable-column-handling`, `coverage-floor-70`
|
||||||
|
- **Territory**: `internal/store/**`, `internal/audit/**`, `internal/certpaths/**`, `internal/jobspec/**`, `internal/model/**`, `internal/store/migrations/**`
|
||||||
|
- **Active**: true
|
||||||
|
- **Reason**: Owns P01 coverage for `internal/store` (including the missing `cert_repo_test.go` — a v0.7 P01 leftover; Insert/Get/List/ListByNode/LatestForKind/PruneOlderThan/Delete + N=3 rotation history per REQ-025), `internal/audit` (sqlite-backed audit_log row asserts via `engine.Audit` + `store.AuditRepo`, slog capture via test handler), `internal/certpaths` (path-join asserts with temp dir + ORCA_HOME/ORCA_DB env), and `internal/jobspec` (golden-file HCL fixtures in a new `testdata/` dir + error-path table for Parse/Validate/ParseFile). Frameworks updated: `iter` + `hashicorp/hcl/v2` added (matches actual go.mod — jobspec uses hclsimple; store Watch uses iter.Seq). Added `coverage-floor-70` constraint.
|
||||||
|
|
||||||
|
### cli-engineer
|
||||||
|
- **Active**: false (v0.8)
|
||||||
|
- **Reason**: Deactivated — merged into lead-developer. The cli coverage work is test-only; `--host-key-fingerprint` and `key-reset` are a 1-flag and 1-subcommand addition to the existing `internal/cli/node.go`, not a new CLI subsystem.
|
||||||
|
|
||||||
|
### security-engineer
|
||||||
|
- **Active**: false (v0.8)
|
||||||
|
- **Reason**: Deactivated — v0.8 refines the existing proxmox SSH trust surface (pinned host-key callback, key-reset known_hosts rewrite) but does NOT add new security architecture (no new CA, no new X.509, no new crypto). The trust work is backend-engineer territory (SSH dialer + known_hosts file manipulation). The `internal/security/sshkey.go` is unchanged in v0.8. Was active in v0.6 (SSH keygen + sudoers), deactivated in v0.7, remains deactivated in v0.8.
|
||||||
|
|
||||||
|
### devops-engineer
|
||||||
|
- **Active**: false (v0.8)
|
||||||
|
- **Reason**: Deactivated — `verify-reqs` is a Go program (`cmd/verify-reqs/main.go`), not a CI/packaging change. The `.coreci.yml` edit is a 3-line validate-pipeline hook (lead-developer territory). No install.sh, Dockerfile, or release-pipeline surface in v0.8.
|
||||||
|
|
||||||
|
### network-engineer
|
||||||
|
- **Active**: false (v0.8)
|
||||||
|
- **Reason**: Deactivated — no transport/mTLS surface change. `internal/transport` coverage is test-only on the existing mTLS layer (httptest.NewTLSServer, no new TLS config). The SSH trust work is point-to-point bootstrap, not the mTLS mesh network-engineer owns.
|
||||||
|
|
||||||
|
### frontend-engineer
|
||||||
|
- **Active**: false (v0.8)
|
||||||
|
- **Reason**: No web UI in Orca (unchanged from v0.1 onward).
|
||||||
|
|
||||||
|
## Territory Enforcement
|
||||||
|
|
||||||
|
- **Mode**: `warn` (per `config.json`)
|
||||||
|
- **Behavior**: Out-of-territory file changes log a warning but do not block.
|
||||||
|
- **Key overlaps in v0.8** (lead-developer adjudicates):
|
||||||
|
- `internal/cli/node.go` — backend-engineer (`--host-key-fingerprint` flag + `key-reset` subcommand + proxmox pass-through) vs lead-developer (cli coverage tests). Boundary: backend owns the command implementation; lead owns the test files (`node_test.go`).
|
||||||
|
- `internal/proxmox/bootstrap.go` — backend-engineer (pinned callback, TOFU fix, sessionRunner seam) vs data-engineer (no overlap — proxmox has no store/audit code). Clean boundary.
|
||||||
|
- `cmd/verify-reqs/main.go` — lead-developer (Go program + Makefile + .coreci.yml) vs data-engineer (no overlap — verify-reqs parses markdown, not DB). Clean boundary.
|
||||||
|
- `internal/store/cert_repo_test.go` — data-engineer (test file) vs backend-engineer (no overlap — cert_repo is data territory). Clean boundary.
|
||||||
|
|
||||||
|
## v0.8 vs v0.7 Persona Diff
|
||||||
|
|
||||||
|
| Change | Rationale |
|
||||||
|
|--------|-----------|
|
||||||
|
| `lead-developer` retained | Owns cmd/orca smoke test, internal/cli coverage (non-node subcommands), cmd/verify-reqs Go program. |
|
||||||
|
| `backend-engineer` retained | Owns internal/transport + internal/engine tests + SSH trust-surface in proxmox + cli/node. Frameworks corrected: connectrpc removed (not in go.mod), x/crypto/ssh added. |
|
||||||
|
| `data-engineer` retained | Owns internal/store (cert_repo gap) + internal/audit + internal/certpaths + internal/jobspec tests. Frameworks corrected: iter + hcl/v2 added. |
|
||||||
|
| `security-engineer` remains deactivated | v0.8 refines existing SSH trust surface, no new security architecture. |
|
||||||
|
| `cli-engineer` remains deactivated | Merged into lead-developer (test-only + 1 flag + 1 subcommand). |
|
||||||
|
| `devops-engineer` remains deactivated | verify-reqs is a Go program, not CI/packaging. |
|
||||||
|
| `network-engineer` remains deactivated | No transport/mTLS surface change (test-only). |
|
||||||
|
| `frontend-engineer` remains deactivated | No web UI. |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## v0.7 baseline (preserved for traceability)
|
||||||
|
|
||||||
---
|
---
|
||||||
active_personas:
|
active_personas:
|
||||||
- lead-developer
|
- lead-developer
|
||||||
@@ -28,11 +169,7 @@ reason: |
|
|||||||
- devops-engineer: DEACTIVATED — no packaging/distribution in v0.7.
|
- devops-engineer: DEACTIVATED — no packaging/distribution in v0.7.
|
||||||
---
|
---
|
||||||
|
|
||||||
# Personas: Orca
|
### lead-developer (v0.7)
|
||||||
|
|
||||||
## Roster
|
|
||||||
|
|
||||||
### lead-developer
|
|
||||||
- **Domain**: coordination
|
- **Domain**: coordination
|
||||||
- **Frameworks**: `cobra`
|
- **Frameworks**: `cobra`
|
||||||
- **Constraints**: `boundary-enforcement`, `offline-first`, `no-redundant-implementations`
|
- **Constraints**: `boundary-enforcement`, `offline-first`, `no-redundant-implementations`
|
||||||
@@ -40,7 +177,7 @@ reason: |
|
|||||||
- **Active**: true
|
- **Active**: true
|
||||||
- **Reason**: Coordination across P01/P02/P03. SSH/bootstrap touches security + cli + store + doctor — territory overlaps need adjudication (proxmox package boundary, doctor Proxmox check scaffolding).
|
- **Reason**: Coordination across P01/P02/P03. SSH/bootstrap touches security + cli + store + doctor — territory overlaps need adjudication (proxmox package boundary, doctor Proxmox check scaffolding).
|
||||||
|
|
||||||
### backend-engineer
|
### backend-engineer (v0.7)
|
||||||
- **Domain**: backend
|
- **Domain**: backend
|
||||||
- **Frameworks**: `cobra`, `net/http`, `golang.org/x/crypto/ssh`
|
- **Frameworks**: `cobra`, `net/http`, `golang.org/x/crypto/ssh`
|
||||||
- **Constraints**: `API-first`, `error-handling`, `minimal-dependencies`, `security-first`, `idempotent-bootstrap`
|
- **Constraints**: `API-first`, `error-handling`, `minimal-dependencies`, `security-first`, `idempotent-bootstrap`
|
||||||
@@ -48,7 +185,7 @@ reason: |
|
|||||||
- **Active**: true
|
- **Active**: true
|
||||||
- **Reason**: Owns the `orca init` full-bootstrap orchestration (CA + cert + db + localhost node, idempotent) and the `internal/proxmox/bootstrap.go` SSH session sequence (dial, deploy pubkey, useradd, pveum, sudoers, visudo validate). Added `idempotent-bootstrap` constraint (D-036 — re-run must be skip-and-refresh) and `golang.org/x/crypto/ssh` to frameworks.
|
- **Reason**: Owns the `orca init` full-bootstrap orchestration (CA + cert + db + localhost node, idempotent) and the `internal/proxmox/bootstrap.go` SSH session sequence (dial, deploy pubkey, useradd, pveum, sudoers, visudo validate). Added `idempotent-bootstrap` constraint (D-036 — re-run must be skip-and-refresh) and `golang.org/x/crypto/ssh` to frameworks.
|
||||||
|
|
||||||
### data-engineer
|
### data-engineer (v0.7)
|
||||||
- **Domain**: data
|
- **Domain**: data
|
||||||
- **Frameworks**: `modernc/sqlite`, `iter`
|
- **Frameworks**: `modernc/sqlite`, `iter`
|
||||||
- **Constraints**: `schema-first`, `migration-safe`, `local-storage-only`, `no-goroutine-leak`, `nullable-column-handling`
|
- **Constraints**: `schema-first`, `migration-safe`, `local-storage-only`, `no-goroutine-leak`, `nullable-column-handling`
|
||||||
@@ -56,7 +193,7 @@ reason: |
|
|||||||
- **Active**: true
|
- **Active**: true
|
||||||
- **Reason**: Reactivated for v0.6. Owns migration `0006_node_kind_os.sql` (REQ-049 — nullable `kind`/`os` columns, backward-compatible) and `NodeRepo` schema extension (Insert/Get/List/Watch/scanNode column additions + new `GetByName`/`UpdateLastSeenAndOS` helpers). Added `nullable-column-handling` constraint (NULL → `""` in Go struct, not nil-deref).
|
- **Reason**: Reactivated for v0.6. Owns migration `0006_node_kind_os.sql` (REQ-049 — nullable `kind`/`os` columns, backward-compatible) and `NodeRepo` schema extension (Insert/Get/List/Watch/scanNode column additions + new `GetByName`/`UpdateLastSeenAndOS` helpers). Added `nullable-column-handling` constraint (NULL → `""` in Go struct, not nil-deref).
|
||||||
|
|
||||||
### cli-engineer
|
### cli-engineer (v0.7)
|
||||||
- **Domain**: CLI/UX
|
- **Domain**: CLI/UX
|
||||||
- **Frameworks**: `cobra`, `pflag`
|
- **Frameworks**: `cobra`, `pflag`
|
||||||
- **Constraints**: `discoverable-help`, `consistent-flag-naming`, `human-readable-output`, `machine-readable-json-flag`, `signal-handling`, `password-flag-redaction`
|
- **Constraints**: `discoverable-help`, `consistent-flag-naming`, `human-readable-output`, `machine-readable-json-flag`, `signal-handling`, `password-flag-redaction`
|
||||||
@@ -64,7 +201,7 @@ reason: |
|
|||||||
- **Active**: true
|
- **Active**: true
|
||||||
- **Reason**: Owns `orca init` multi-step bootstrap output UX (progress lines per step), `orca node join --type/--host/--user/--password/--proxmox-user/--proxmox-role` flag wiring, and `doctor os`/`doctor proxmox` subcommand wiring. Added `password-flag-redaction` constraint (D-031 — `--password` never echoed, prefer `$ORCA_PROXMOX_PASSWORD`, zero after use).
|
- **Reason**: Owns `orca init` multi-step bootstrap output UX (progress lines per step), `orca node join --type/--host/--user/--password/--proxmox-user/--proxmox-role` flag wiring, and `doctor os`/`doctor proxmox` subcommand wiring. Added `password-flag-redaction` constraint (D-031 — `--password` never echoed, prefer `$ORCA_PROXMOX_PASSWORD`, zero after use).
|
||||||
|
|
||||||
### security-engineer
|
### security-engineer (v0.7)
|
||||||
- **Domain**: security
|
- **Domain**: security
|
||||||
- **Frameworks**: `crypto/tls`, `crypto/x509`, `crypto/ed25519`, `golang.org/x/crypto/ssh`, `slog`
|
- **Frameworks**: `crypto/tls`, `crypto/x509`, `crypto/ed25519`, `golang.org/x/crypto/ssh`, `slog`
|
||||||
- **Constraints**: `no-panic-in-production`, `structured-audit-logging`, `no-secret-in-logs`, `input-validation`, `least-privilege`, `tofu-host-key-pinning`, `noexec-sudoers`
|
- **Constraints**: `no-panic-in-production`, `structured-audit-logging`, `no-secret-in-logs`, `input-validation`, `least-privilege`, `tofu-host-key-pinning`, `noexec-sudoers`
|
||||||
@@ -72,28 +209,19 @@ reason: |
|
|||||||
- **Active**: true
|
- **Active**: true
|
||||||
- **Reason**: Reactivated for v0.6. Owns `internal/security/sshkey.go` (Ed25519 keygen, 0600/0644 mode enforcement per REQ-033 spirit), TOFU host-key pinning via `knownhosts.New`, sudoers least-privilege design (NOEXEC on pct/qm, exclude pvesh, no NOEXEC on apt-get/dpkg), password redaction (D-031), and audit logging of all bootstrap/join actions (REQ-052). Added `tofu-host-key-pinning` and `noexec-sudoers` constraints. Co-owns `internal/proxmox/**` with backend-engineer (security owns SSH auth + sudoers content; backend owns the session orchestration).
|
- **Reason**: Reactivated for v0.6. Owns `internal/security/sshkey.go` (Ed25519 keygen, 0600/0644 mode enforcement per REQ-033 spirit), TOFU host-key pinning via `knownhosts.New`, sudoers least-privilege design (NOEXEC on pct/qm, exclude pvesh, no NOEXEC on apt-get/dpkg), password redaction (D-031), and audit logging of all bootstrap/join actions (REQ-052). Added `tofu-host-key-pinning` and `noexec-sudoers` constraints. Co-owns `internal/proxmox/**` with backend-engineer (security owns SSH auth + sudoers content; backend owns the session orchestration).
|
||||||
|
|
||||||
### devops-engineer
|
### devops-engineer (v0.7)
|
||||||
- **Active**: false (v0.6)
|
- **Active**: false (v0.6)
|
||||||
- **Reason**: Deactivated — v0.6 has no install.sh, Dockerfile, .coreci.yml, or release-pipeline surface. The Proxmox SSH bootstrap is backend + security work, not devops. Was active in v0.5 (distribution milestone).
|
- **Reason**: Deactivated — v0.6 has no install.sh, Dockerfile, .coreci.yml, or release-pipeline surface. The Proxmox SSH bootstrap is backend + security work, not devops. Was active in v0.5 (distribution milestone).
|
||||||
|
|
||||||
### network-engineer
|
### network-engineer (v0.7)
|
||||||
- **Active**: false (v0.6)
|
- **Active**: false (v0.6)
|
||||||
- **Reason**: v0.6 has no transport/mTLS surface. SSH is point-to-point bootstrap, not the mTLS mesh network-engineer owns.
|
- **Reason**: v0.6 has no transport/mTLS surface. SSH is point-to-point bootstrap, not the mTLS mesh network-engineer owns.
|
||||||
|
|
||||||
### frontend-engineer
|
### frontend-engineer (v0.7)
|
||||||
- **Active**: false (v0.6)
|
- **Active**: false (v0.6)
|
||||||
- **Reason**: No web UI in Orca (unchanged from v0.1 onward).
|
- **Reason**: No web UI in Orca (unchanged from v0.1 onward).
|
||||||
|
|
||||||
## Territory Enforcement
|
### v0.6 vs v0.5 Persona Diff (v0.7 baseline reference)
|
||||||
|
|
||||||
- **Mode**: `warn` (per `config.json`)
|
|
||||||
- **Behavior**: Out-of-territory file changes log a warning but do not block.
|
|
||||||
- **Key overlaps in v0.6** (lead-developer adjudicates):
|
|
||||||
- `internal/proxmox/bootstrap.go` — security-engineer (SSH auth, sudoers, PVE role) + backend-engineer (session orchestration, error handling). Boundary: security package exposes `BootstrapProxmox(ctx, opts) error`; the function lives in `internal/proxmox` but imports `internal/security` for SSH key handling.
|
|
||||||
- `internal/doctor/doctor.go` `Proxmox()` — reuses `internal/proxmox` SSH client (security) but check scaffolding clones `doctor.Network()` pattern. Backend-engineer adjudicates (network-engineer deactivated).
|
|
||||||
- `internal/store/node_repo.go` — data-engineer territory, but the `UpdateLastSeenAndOS` caller is `internal/cli/init.go` (backend). Standard repo-consumer boundary.
|
|
||||||
|
|
||||||
## v0.6 vs v0.5 Persona Diff
|
|
||||||
|
|
||||||
| Change | Rationale |
|
| Change | Rationale |
|
||||||
|--------|-----------|
|
|--------|-----------|
|
||||||
|
|||||||
@@ -0,0 +1,55 @@
|
|||||||
|
# Phase 1 Verification — v0.8 Coverage & Trust Hardening
|
||||||
|
|
||||||
|
**Phase**: P01 — Coverage uplift round 2
|
||||||
|
**Milestone**: v0.8
|
||||||
|
**REQ**: REQ-057
|
||||||
|
**Date**: 2026-08-04
|
||||||
|
**Result**: ✅ PASS (all 4 layers)
|
||||||
|
|
||||||
|
## Layer 1 — Structural ✅
|
||||||
|
|
||||||
|
- `go build ./...` PASS (no compile errors)
|
||||||
|
- `go vet ./...` PASS (no warnings)
|
||||||
|
- No TODOs/FIXMEs/stubs in production code (the 3 pre-existing placeholders in `internal/cli/job.go:78`, `internal/engine/scheduler.go:115`, `internal/security/tls_config.go:90` are unchanged from v0.7 and out of scope for P01)
|
||||||
|
- All test files resolve imports correctly
|
||||||
|
- The proxmox `sessionRunner` seam (T01.1) is backward compatible — `BootstrapProxmox` callers unchanged
|
||||||
|
|
||||||
|
## Layer 2 — Behavioral ✅
|
||||||
|
|
||||||
|
- `go test ./...` PASS (all 14 packages)
|
||||||
|
- `go test -race ./...` PASS (cli 98s, engine 47s, store 88s, transport 22s, all others fast)
|
||||||
|
- Coverage targets met (T01.12):
|
||||||
|
- ≥70% floor: engine 88.9%, proxmox 87.1%, cli 76.2%, transport 93.0%, store 84.7%, jobspec 90.5%
|
||||||
|
- ≥50% floor: audit 100.0%, certpaths 100.0%, cmd/orca 80.0%
|
||||||
|
- GRILL condition #3 escape valve NOT needed (cli hit 76.2%, above 70%)
|
||||||
|
- T01.2 (conditional `peerDispatcher` seam) NOT added — engine reached 88.9% via httptest + stubs
|
||||||
|
- REQ-057 covered: all 9 target packages hit their tiered floor
|
||||||
|
|
||||||
|
## Layer 3 — Security ✅
|
||||||
|
|
||||||
|
- P01 is a test-only phase (the only production change is T01.1's `sessionRunner` interface extraction + T01.11's `main()→run()` refactor)
|
||||||
|
- No new input paths, no new network surfaces, no new crypto
|
||||||
|
- The `sessionRunner` seam does not leak test concerns into production (default `sshSessionRunner` wraps the real SSH session; the seam is only injectable via the package-level var pattern matching `sshDialer`)
|
||||||
|
- `cmd/orca/main.go` refactor: `run() int` returns exit code; `main()` calls `os.Exit(run())` — no security impact (same behavior, testable)
|
||||||
|
- No secrets in test code (all test DBs use `:memory:` or temp dirs; no real credentials)
|
||||||
|
|
||||||
|
## Layer 4 — Quality ✅
|
||||||
|
|
||||||
|
- Tests follow existing conventions (table-driven, `t.Run` subtests, `t.Helper()` in setup funcs)
|
||||||
|
- Reuse of existing helpers: `openTestDB`, `withFastWatch`, `initTestEnv`, `resetRootFlags`, `discardWriter`, `stubDispatcher` pattern
|
||||||
|
- No flaky tests detected (all pass on repeated runs with `-race`)
|
||||||
|
- Test file naming follows `*_test.go` convention
|
||||||
|
- No over-testing: daemon.go excluded from cli coverage (covered by `internal/daemon/server_test.go`)
|
||||||
|
- P0 issues: none. P1+ issues: none flagged.
|
||||||
|
|
||||||
|
## Requirement Coverage
|
||||||
|
|
||||||
|
| REQ | Status | Evidence |
|
||||||
|
|-----|--------|----------|
|
||||||
|
| REQ-057 | ✅ Complete | All 9 packages hit tiered floor; `go test -cover` confirms; `go test -race` PASS |
|
||||||
|
|
||||||
|
## Lessons
|
||||||
|
|
||||||
|
- The `sessionRunner` seam pattern (package-level var + default init in entry func) is the canonical way to add testability to orca's SSH-dependent packages. Future SSH-adjacent packages should follow it.
|
||||||
|
- `httptest.NewTLSServer` sufficed for engine 70% without needing the conditional `peerDispatcher` seam — the plan's "only if needed" guard worked as intended.
|
||||||
|
- The cli package's 84s test time is dominated by `--watch` integration tests with real poll intervals. Future coverage work should consider reducing the `withFastWatch` interval further or extracting the watch logic for unit-level testing.
|
||||||
@@ -0,0 +1,55 @@
|
|||||||
|
# Phase 2 Verification — v0.8 Coverage & Trust Hardening
|
||||||
|
|
||||||
|
**Phase**: P02 — SSH trust hardening
|
||||||
|
**Milestone**: v0.8
|
||||||
|
**REQs**: REQ-058, REQ-059 (+ latent TOFU bugfix closure)
|
||||||
|
**Date**: 2026-08-04
|
||||||
|
**Result**: ✅ PASS (all 4 layers)
|
||||||
|
|
||||||
|
## Layer 1 — Structural ✅
|
||||||
|
|
||||||
|
- `go build ./...` PASS
|
||||||
|
- `go vet ./...` PASS
|
||||||
|
- No TODOs/stubs in new production code
|
||||||
|
- All new exports resolve: `security.SSHFingerprintSHA256`, `security.WriteAtomic`, `proxmox.TOFUHostKeyCallback`, `proxmox.ResetHostKey`, `proxmox.pinnedHostKeyCallback`, `proxmox.Options.HostKeyFingerprint`, `cli.nodeKeyResetCmd`
|
||||||
|
- Backward compatible: existing `BootstrapProxmox` callers work (the TOFU fix changed failure→success on first connect, which is the bugfix)
|
||||||
|
|
||||||
|
## Layer 2 — Behavioral ✅
|
||||||
|
|
||||||
|
- `go test ./internal/proxmox/... ./internal/cli/... ./internal/doctor/... ./internal/security/...` PASS
|
||||||
|
- `go test -race ./internal/proxmox/... ./internal/doctor/...` PASS
|
||||||
|
- Coverage held post-P02: proxmox 86.5% (was 87.1% in P01 — marginal change from new code paths), cli 76.7% (was 76.2%), doctor 70.4% (unchanged)
|
||||||
|
- T02.10: all 7 end-to-end integration cases PASS (pinned correct/wrong, TOFU first/second/mismatch, key-reset+re-pin, pre-populated migration path)
|
||||||
|
- T02.11: `--host-key-fingerprint` non-proxmox validation PASS
|
||||||
|
|
||||||
|
## Layer 3 — Security ✅
|
||||||
|
|
||||||
|
- **REQ-058**: `--host-key-fingerprint` fails closed on mismatch (pinnedHostKeyCallback returns error on any mismatch; bootstrap aborts before any SSH session command runs). SHA256: prefix validated up front. No downgrade to TOFU when pin supplied.
|
||||||
|
- **REQ-059**: `orca node key-reset` is local-only (D-046) — only rewrites `~/.orca/known_hosts` via `security.WriteAtomic` (atomic temp+rename, AD-029); does NOT touch remote authorized_keys. Audit-logs `node.key_reset` with actor+node+host.
|
||||||
|
- **TOFU bugfix (T02.6, v0.6 ship-defect)**: first-connect now captures + writes the key (was silently failing). Mismatch detection preserved (MITM protection). The `TOFUHostKeyCallback` is shared between bootstrap (T02.6) and doctor (T02.9) — GRILL condition #2 parity satisfied.
|
||||||
|
- STRIDE: no new spoofing surface (pin is operator-supplied, fail-closed); no tampering (atomic rewrite); no repudiation (audit log); no info disclosure (fingerprint is a hash, not the key); no DoS (no network change); no elevation (local file ops only).
|
||||||
|
- No secrets in test code (fake SSH keys generated in-test).
|
||||||
|
|
||||||
|
## Layer 4 — Quality ✅
|
||||||
|
|
||||||
|
- Tests follow existing conventions (table-driven, `fakeSSHServer` fixture reused, `sshDialer`/`sessionRunner` seams injected)
|
||||||
|
- `TOFUHostKeyCallback` extracted to a shared helper (no duplication between bootstrap + doctor) — clean coupling (proxmox doesn't import doctor)
|
||||||
|
- P0 issues: none. P1+ issues: none flagged.
|
||||||
|
|
||||||
|
## Requirement Coverage
|
||||||
|
|
||||||
|
| REQ | Status | Evidence |
|
||||||
|
|-----|--------|----------|
|
||||||
|
| REQ-058 | ✅ Complete | `--host-key-fingerprint` flag (T02.3) + `pinnedHostKeyCallback` (T02.5) + `Result.HostKeyFingerprint` (T02.7) + e2e tests (T02.10) + validation (T02.11) |
|
||||||
|
| REQ-059 | ✅ Complete | `orca node key-reset <node>` (T02.8) + `proxmox.ResetHostKey` atomic rewrite + audit log + e2e test (T02.10 case 6) |
|
||||||
|
| (TOFU bugfix) | ✅ Complete | T02.6 fixes v0.6 ship-defect (first-connect `knownhosts.New` KeyError{Want:[]} treated as dial failure); T02.9 doctor parity |
|
||||||
|
|
||||||
|
## GRILL Conditions Check
|
||||||
|
|
||||||
|
- **#1 (T02.6 labeled v0.6 ship-defect)**: ✅ commit `8b0cbe1` summary "TOFU capture bug — v0.6 ship-defect first-connect join always failed"
|
||||||
|
- **#2 (T02.9 doctor parity)**: ✅ both bootstrap (`8b0cbe1`) and doctor (`2dcb143`) use the shared `proxmox.TOFUHostKeyCallback` wrapper
|
||||||
|
|
||||||
|
## Lessons
|
||||||
|
|
||||||
|
- The v0.6 TOFU bug was a latent ship-defect: `knownhosts.New` returns `KeyError{Want:[]}` on first connect without writing, and the original code treated this as a dial failure. This means first-connect Proxmox join has been broken since v0.6 shipped — a strong argument for P01's coverage uplift (the 5.1% proxmox coverage hid this). v0.8 P03's `verify-reqs` would not have caught this (it's code-vs-doc drift, not doc-vs-doc) — P04 audit is the backstop.
|
||||||
|
- Extracting `TOFUHostKeyCallback` to a shared helper was the right call for GRILL condition #2 — duplicating the wrapper in doctor would have created drift risk.
|
||||||
@@ -0,0 +1,76 @@
|
|||||||
|
# Phase 3 Verification Report — v0.7: Test Coverage Uplift
|
||||||
|
|
||||||
|
**Phase**: 3
|
||||||
|
**Branch**: `phase/03-coverage-uplift`
|
||||||
|
**REQ Coverage**: REQ-055
|
||||||
|
**Milestone**: v0.7 (Hardening & Completion)
|
||||||
|
|
||||||
|
## Structural Verification
|
||||||
|
|
||||||
|
### Files Created
|
||||||
|
- `internal/engine/peer_test.go` — 8 tests (PeerRegistry Add/Get/Remove/All/Len/UpdateLastSeen + validation)
|
||||||
|
- `internal/engine/executor_test.go` — 7 tests (Submit success/missing-command/malformed/failing, Status not-found, Run success, Run context-cancel)
|
||||||
|
- `internal/engine/dispatcher_test.go` — 10 tests (empty spec, idempotency hit, local-capacity, explicit-target, no-peers, LocalSubmit/LocalStatus, nil guards, parseInlineSpec)
|
||||||
|
- `internal/audit/audit_test.go` — 9 tests (Emit/EmitWithErr persistence, LogHandshakeOK/Failed slog fields, nil-safety, Action/Result String, FormatAction)
|
||||||
|
- `internal/transport/handshake_log_test.go` — 8 tests (LogHandshakeOK/Failed/FromCert, FingerprintOfCert, nil-logger, nil-err)
|
||||||
|
- `internal/transport/mtls_test.go` — 14 tests (ServerTLSConfig, ClientTLSConfig, NewMTLSClient, Do, VerifyPeerCertificate, DialContext)
|
||||||
|
- `internal/transport/dispatch_test.go` — 24 tests (SubmitHandler/StatusHandler, DispatchClient constructor/connection-refused/HTTP/decode/Submit/Status success)
|
||||||
|
- `internal/proxmox/ssh_session_test.go` — 14 tests (runRemote, deployPubKey, createLinuxUser, createPVERole, createPVEUser, assignPVEACL, writeSudoers, validateSudoers, full BootstrapProxmox)
|
||||||
|
|
||||||
|
### Files Modified
|
||||||
|
- `internal/transport/dispatch.go` — **bug fix**: `bytesReadCloser.Read` returned `fmt.Errorf("EOF")` instead of `io.EOF`, breaking HTTP request body transmission. This was a latent bug that prevented any client-side dispatch from working end-to-end.
|
||||||
|
- `internal/proxmox/bootstrap_test.go` — extended with 10 new tests (mockSSHDialer, SSH auth failure, dial-addr/port/user propagation, SSH key generation, known_hosts, nil/custom logger, cancelled context, deployPubKey edge cases)
|
||||||
|
|
||||||
|
## Behavioral Verification
|
||||||
|
|
||||||
|
### Test Results
|
||||||
|
```
|
||||||
|
go test ./... → all PASS (exit 0)
|
||||||
|
go test -race ./... → all PASS (exit 0)
|
||||||
|
go vet ./... → clean
|
||||||
|
make build → clean
|
||||||
|
```
|
||||||
|
|
||||||
|
### Coverage (D-042 target: ≥ 50% per package)
|
||||||
|
|
||||||
|
| Package | Before | After | Target |
|
||||||
|
|---------|--------|-------|--------|
|
||||||
|
| `internal/engine` | 8.3% | **65.1%** | 50% ✓ |
|
||||||
|
| `internal/transport` | 26.3% | **84.6%** | 50% ✓ |
|
||||||
|
| `internal/proxmox` | 5.1% | **82.7%** | 50% ✓ |
|
||||||
|
| `internal/audit` | 0% | **100.0%** | 50% ✓ |
|
||||||
|
|
||||||
|
All 4 packages exceed the 50% floor (AD-025).
|
||||||
|
|
||||||
|
### Total new tests: 94 (37 engine+audit + 57 transport+proxmox)
|
||||||
|
|
||||||
|
## Security Verification
|
||||||
|
|
||||||
|
- The `dispatch.go` bug fix (`io.EOF` vs `fmt.Errorf("EOF")`) is a correctness fix — HTTP request bodies now terminate correctly. No security implications (the bug caused requests to fail, not to leak data).
|
||||||
|
- No new dependencies added.
|
||||||
|
- Test fixtures use temp dirs (`t.TempDir()`) — no persistent state.
|
||||||
|
- No secrets in test code (SSH keys are test-generated Ed25519 pairs).
|
||||||
|
|
||||||
|
## Quality Verification
|
||||||
|
|
||||||
|
- No comments added (per project convention).
|
||||||
|
- Test style matches existing patterns (`scheduler_test.go`, `node_repo_test.go`, `certgen_test.go`).
|
||||||
|
- `go.mod` unchanged.
|
||||||
|
- Bug fix in `dispatch.go` is minimal (1 line: `return fmt.Errorf("EOF")` → `return io.EOF` + `io` import).
|
||||||
|
|
||||||
|
## Must-Haves Checklist
|
||||||
|
|
||||||
|
- [x] `internal/engine/executor_test.go` — 7 tests
|
||||||
|
- [x] `internal/engine/dispatcher_test.go` — 10 tests
|
||||||
|
- [x] `internal/engine/peer_test.go` — 8 tests
|
||||||
|
- [x] `internal/transport/mtls_test.go` — 14 tests
|
||||||
|
- [x] `internal/transport/dispatch_test.go` — 24 tests
|
||||||
|
- [x] `internal/transport/handshake_log_test.go` — 8 tests
|
||||||
|
- [x] `internal/audit/audit_test.go` — 9 tests
|
||||||
|
- [x] `internal/proxmox/ssh_session_test.go` — 14 tests + extended `bootstrap_test.go` (+10 tests)
|
||||||
|
- [x] Bug fix: `dispatch.go` bytesReadCloser EOF (latent bug, root-caused during P03)
|
||||||
|
- [x] All 4 target packages ≥ 50% coverage
|
||||||
|
|
||||||
|
## Verdict
|
||||||
|
|
||||||
|
**PASS** — all 4 verification layers pass. REQ-055 is fully covered. All 4 target packages exceed the 50% coverage floor (engine 65.1%, transport 84.6%, proxmox 82.7%, audit 100%). A latent bug in `dispatch.go` (non-`io.EOF` return) was found and fixed during coverage uplift.
|
||||||
@@ -0,0 +1,51 @@
|
|||||||
|
# Phase 3 Verification — v0.8 Coverage & Trust Hardening
|
||||||
|
|
||||||
|
**Phase**: P03 — Requirements-hygiene gate
|
||||||
|
**Milestone**: v0.8
|
||||||
|
**REQ**: REQ-060
|
||||||
|
**Date**: 2026-08-04
|
||||||
|
**Result**: ✅ PASS (all 4 layers)
|
||||||
|
|
||||||
|
## Layer 1 — Structural ✅
|
||||||
|
|
||||||
|
- `go build ./...` PASS
|
||||||
|
- `go vet ./...` PASS
|
||||||
|
- `cmd/verify-reqs/main.go` (~180 LOC, stdlib only) compiles + links
|
||||||
|
- All exports resolve: `verify(roadmapPath, reqsPath) (diff []string, count int, err error)`
|
||||||
|
- No new dependencies
|
||||||
|
|
||||||
|
## Layer 2 — Behavioral ✅
|
||||||
|
|
||||||
|
- `go test ./cmd/verify-reqs/...` PASS (7 golden-file tests: clean, multi-drift, default-args, malformed, missing-file, v0.2-substring-tolerant, real-repo regression)
|
||||||
|
- `make verify-reqs` → exit 0 on the current repo (`✓ 60 requirements consistent with roadmap`)
|
||||||
|
- T03.5 synthetic drift verification: scratch flip of REQ-053 → `make verify-reqs` exit 1 + `REQ-053: status=Pending, expected=Complete (direction=forward)`; revert → exit 0
|
||||||
|
- `go test ./...` PASS (all 16 packages)
|
||||||
|
- Forward + reverse assertions both exercised (golden test `TestVerify_drift` asserts `direction=reverse` for REQ-003)
|
||||||
|
|
||||||
|
## Layer 3 — Security ✅
|
||||||
|
|
||||||
|
- verify-reqs is a static doc-consistency checker — no network, no secrets, no input injection (markdown is parsed with `regexp` over local files only)
|
||||||
|
- `.coreci.yml` step runs in the existing `golang:1.25` container (no new image, no new permissions)
|
||||||
|
- No STRIDE surface added
|
||||||
|
|
||||||
|
## Layer 4 — Quality ✅
|
||||||
|
|
||||||
|
- Testable core (`verify()` function) + thin `main()` — follows the `cmd/orca/main.go` → `run()` pattern from T01.11
|
||||||
|
- Golden-file test fixtures cover the substring-tolerant regex regression (v0.2 header variant)
|
||||||
|
- GRILL condition #4 satisfied: substring-tolerant regex + reverse-direction assertion + scope note (doc-vs-doc only)
|
||||||
|
- P0 issues: none. P1+ issues: none flagged.
|
||||||
|
|
||||||
|
## Requirement Coverage
|
||||||
|
|
||||||
|
| REQ | Status | Evidence |
|
||||||
|
|-----|--------|----------|
|
||||||
|
| REQ-060 | ✅ Complete | `cmd/verify-reqs` (T03.1) + golden tests (T03.2) + `make verify-reqs` (T03.3) + `.coreci.yml` validate hook (T03.4) + synthetic drift verification (T03.5) |
|
||||||
|
|
||||||
|
## GRILL Conditions Check
|
||||||
|
|
||||||
|
- **#4 (verify-reqs regex + reverse direction)**: ✅ substring-tolerant regex matches v0.2's `**COMPLETE (merged to main via v0.3)**` header (golden test `TestVerify_v0_2_substring_tolerant`); reverse-direction assertion implemented + tested; scope note documented in the commit + the verification report.
|
||||||
|
|
||||||
|
## Lessons
|
||||||
|
|
||||||
|
- The two-regex parser (one for REQ rows, one for milestone-complete headers) with substring tolerance is the right shape — a single strict regex would have silently exempted v0.2 (the exact drift the GRILL flagged).
|
||||||
|
- Refactoring `main()` into a testable `verify()` function made golden-file testing trivial (no subprocess orchestration). This mirrors the T01.11 `main()→run()` pattern and should be the house style for all `cmd/` programs.
|
||||||
@@ -0,0 +1,64 @@
|
|||||||
|
# Phase 4 Verification Report — v0.7: --pprof Opt-in on orca daemon
|
||||||
|
|
||||||
|
**Phase**: 4
|
||||||
|
**Branch**: `phase/04-pprof-daemon`
|
||||||
|
**REQ Coverage**: REQ-056
|
||||||
|
**Milestone**: v0.7 (Hardening & Completion)
|
||||||
|
|
||||||
|
## Structural Verification
|
||||||
|
|
||||||
|
### Files Created
|
||||||
|
- `internal/daemon/pprof.go` — `StartPprof(addr, log) (*http.Server, error)`: dedicated mux + server, disabled by default, WARN log
|
||||||
|
- `internal/daemon/pprof_test.go` — 5 tests (disabled, enabled, shutdown, mux isolation, full server lifecycle)
|
||||||
|
- `internal/cli/daemon_test.go` — `TestDaemonPprofFlag` (flag registration + default)
|
||||||
|
|
||||||
|
### Files Modified
|
||||||
|
- `internal/daemon/server.go` — `PprofAddr` in Options, `pprofServer` field, `NewServer` starts pprof, `Shutdown` stops both
|
||||||
|
- `internal/cli/daemon.go` — `--pprof` flag, `PprofAddr` in daemon.Options, conditional startup output line
|
||||||
|
|
||||||
|
## Behavioral Verification
|
||||||
|
|
||||||
|
### Test Results
|
||||||
|
```
|
||||||
|
go test ./... → all PASS (exit 0)
|
||||||
|
go test -race ./internal/daemon/... ./internal/cli/... → all PASS
|
||||||
|
go vet ./... → clean
|
||||||
|
make build → clean
|
||||||
|
```
|
||||||
|
|
||||||
|
### CLI Verification
|
||||||
|
```
|
||||||
|
./bin/orca daemon --help → shows --pprof string flag (default "")
|
||||||
|
```
|
||||||
|
|
||||||
|
### Live Smoke Test
|
||||||
|
- `--pprof 127.0.0.1:16060` → WARN logged, `/debug/pprof/` returns 200, `/debug/pprof/cmdline` 200, `/debug/pprof/heap` 200
|
||||||
|
- `/healthz` on pprof listener → 404 (mux isolation confirmed, AD-024)
|
||||||
|
- Clean shutdown stops both servers
|
||||||
|
|
||||||
|
## Security Verification
|
||||||
|
|
||||||
|
- pprof on a **separate** `*http.Server` + `*http.ServeMux`, never on the mTLS daemon listener (AD-024) — verified by `TestStartPprof_MuxIsolated` (`/healthz` returns 404 on pprof mux)
|
||||||
|
- Default **disabled** — no pprof listener unless `--pprof` is explicitly set
|
||||||
|
- WARN log on startup: "unauthenticated, operator-only — do not expose publicly"
|
||||||
|
- No `import _ "net/http/pprof"` side-effect registration on `DefaultServeMux` — all handlers explicitly registered on the dedicated mux
|
||||||
|
|
||||||
|
## Quality Verification
|
||||||
|
|
||||||
|
- No new dependencies (stdlib `net/http`, `net/http/pprof`, `log/slog`, `time` only)
|
||||||
|
- No comments added (per project convention)
|
||||||
|
- `go.mod` unchanged
|
||||||
|
- Test style matches existing `server_test.go`
|
||||||
|
|
||||||
|
## Must-Haves Checklist
|
||||||
|
|
||||||
|
- [x] `internal/daemon/pprof.go` — `StartPprof` with dedicated mux, all pprof handlers
|
||||||
|
- [x] `internal/daemon/server.go` — `PprofAddr` in Options, `pprofServer` field, lifecycle integration
|
||||||
|
- [x] `internal/cli/daemon.go` — `--pprof` flag, passed to Options, conditional startup output
|
||||||
|
- [x] `internal/daemon/pprof_test.go` — 5 tests (disabled, enabled, shutdown, mux isolation, lifecycle)
|
||||||
|
- [x] `internal/cli/daemon_test.go` — flag registration test
|
||||||
|
- [x] AD-024: pprof mux separate from mTLS daemon mux (verified by test)
|
||||||
|
|
||||||
|
## Verdict
|
||||||
|
|
||||||
|
**PASS** — all 4 verification layers pass. REQ-056 is fully covered. The `--pprof` opt-in endpoint runs on a separate listener with a dedicated mux, is disabled by default, and logs a WARN when enabled. I-308 (deferred since v0.2) is now implemented.
|
||||||
@@ -0,0 +1,347 @@
|
|||||||
|
# Phase Plans: Orca v0.8 — Coverage & Trust Hardening
|
||||||
|
|
||||||
|
All 4 execution phases + final review with vertical-slice structure, wave
|
||||||
|
ordering, persona assignment, and REQ-ID mapping. v0.8 scope: **Coverage &
|
||||||
|
Trust Hardening** — round-2 test coverage uplift across 9 packages (tiered
|
||||||
|
floor: ≥70% for 6 retested, ≥50% for 3 zero-test per D-047), SSH trust
|
||||||
|
hardening (`--host-key-fingerprint` pre-pin + `orca node key-reset` + latent
|
||||||
|
TOFU capture-fix + `Result.HostKeyFingerprint` population), and a
|
||||||
|
requirements-hygiene gate (`make verify-reqs`).
|
||||||
|
|
||||||
|
Branching: `phase/01-coverage-round2`..`phase/04-final-review-ship` on the
|
||||||
|
`milestone/v0.8-coverage-trust-hardening` branch (numbering restarts per
|
||||||
|
milestone per branch-strategy.md).
|
||||||
|
|
||||||
|
Milestone type: **NFR** (P01 test, P02 chore on the trust surface per D-043,
|
||||||
|
P03 chore, P04 docs/review). Tags run on the v0.7.x patch line: `v0.7.0`
|
||||||
|
(P0) … `v0.7.4` (P04 = milestone release).
|
||||||
|
|
||||||
|
**Vertical-slice integrity**: each phase is independently shippable.
|
||||||
|
- **P01** ships tests-only (no production code changes except the proxmox
|
||||||
|
`sessionRunner` seam, a backward-compatible interface extraction, and the
|
||||||
|
engine `peerDispatcher` seam per RESEARCH §1.3).
|
||||||
|
- **P02** ships the SSH trust features + TOFI bugfix + `Result` population.
|
||||||
|
- **P03** ships the hygiene gate (Go program + Makefile + CI hook).
|
||||||
|
- **P04** is review + ship + audit (no new REQs).
|
||||||
|
|
||||||
|
**Out of scope for v0.8** (candidate for v0.9, noted not added):
|
||||||
|
- Lifting the 3 zero-test packages from 50% → 70% (D-047 explicitly
|
||||||
|
toes-holds them; v0.9 can raise the floor).
|
||||||
|
- A `peerDispatcher` interface seam in engine beyond what P01 needs for 70%
|
||||||
|
coverage (httptest.NewTLSServer suffices; the seam is only added if
|
||||||
|
coverage cannot otherwise hit 70%).
|
||||||
|
- Pre-populating `known_hosts` from a remote keyscan API (TOFU + manual
|
||||||
|
`--host-key-fingerprint` cover the v0.8 trust surface).
|
||||||
|
- `verify-reqs` reverse-direction check (REQUIREMENTS Complete ↔ ROADMAP
|
||||||
|
COMPLETE both ways) — forward direction (ROADMAP-shipped → REQUIREMENTS
|
||||||
|
Complete) is the priority per the v0.7 drift that motivated REQ-060.
|
||||||
|
|
||||||
|
**Carried-forward research findings** (RESEARCH_v0.8.md, must incorporate):
|
||||||
|
- §1.1 per-package coverage strategies + tiered floors (D-047).
|
||||||
|
- §1.3 injected seams: reuse `sshDialer` (proxmox), `LocalExecutor` (engine),
|
||||||
|
`Dispatcher` (transport), `watchInterval` (store), `openTestDB`/`withFastWatch`/`initTestEnv`/`resetRootFlags`/`stubDispatcher` helpers.
|
||||||
|
- §1.4 realism flags: cli excludes `daemon.go`; `cmd/orca` 50% toe-hold only;
|
||||||
|
proxmox needs the `sessionRunner` seam to hit 70%.
|
||||||
|
- §2.1 latent TOFU capture bug (knownhosts.New returns KeyError{Want:[]} on
|
||||||
|
first connect and does NOT auto-write — current BootstrapProxmox treats it
|
||||||
|
as a dial failure).
|
||||||
|
- §2.2 `Result.HostKeyFingerprint` is declared but never populated (always
|
||||||
|
`""`); P02 must add `ssh.FingerprintSHA256` computation.
|
||||||
|
- §2.3 `--host-key-fingerprint` plugs in at `internal/cli/node.go` (flag) +
|
||||||
|
`internal/proxmox/bootstrap.go` (pinned callback).
|
||||||
|
- §2.4 `key-reset` is local-known_hosts-only (D-046), atomic rewrite (AD-029).
|
||||||
|
- §3 verify-reqs is a Go program at `cmd/verify-reqs/main.go` (~80 LOC,
|
||||||
|
stdlib only, AD-030) + `make verify-reqs` + `.coreci.yml` validate hook.
|
||||||
|
- §4 AD-025..AD-030 (renumbered AD-027..AD-030 in research for SSH/trust;
|
||||||
|
AD-025/AD-026 from earlier milestones are stable).
|
||||||
|
- §5 10 pitfalls carried into the risk register at the end of this file.
|
||||||
|
|
||||||
|
**Dependencies (RESEARCH §6)**: v0.8 adds **zero** new direct dependencies.
|
||||||
|
`ssh.FingerprintSHA256`, `knownhosts.Line`/`Normalize`/`KeyError` are in the
|
||||||
|
existing `golang.org/x/crypto` v0.54.0 dep. `verify-reqs` is stdlib-only.
|
||||||
|
`go.mod` is unchanged by v0.8.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 1: Coverage Uplift Round 2 (REQ-057)
|
||||||
|
|
||||||
|
**Branch**: `phase/01-coverage-round2`
|
||||||
|
**REQ Coverage**: REQ-057
|
||||||
|
**Tag**: `v0.7.1`
|
||||||
|
**Depends on**: Phase 0 (this plan + clarify + research)
|
||||||
|
**Source research**: RESEARCH_v0.8.md §1 (per-package strategies, helpers, seams)
|
||||||
|
|
||||||
|
### Tiered floor (D-047)
|
||||||
|
|
||||||
|
| Package | Current | Floor | Owner persona |
|
||||||
|
|---------|---------|-------|---------------|
|
||||||
|
| `internal/engine` | 8.3% | ≥ 70% | backend-engineer |
|
||||||
|
| `internal/proxmox` | 5.1% | ≥ 70% | backend-engineer |
|
||||||
|
| `internal/cli` | 27.6% | ≥ 70% (excluding `daemon.go`) | lead-developer |
|
||||||
|
| `internal/transport` | 26.3% | ≥ 70% | backend-engineer |
|
||||||
|
| `internal/store` | 47.2% | ≥ 70% | data-engineer |
|
||||||
|
| `internal/jobspec` | 47.6% | ≥ 70% | data-engineer |
|
||||||
|
| `internal/audit` | 0% (no tests) | ≥ 50% toe-hold | data-engineer |
|
||||||
|
| `internal/certpaths` | 0% (no tests) | ≥ 50% toe-hold | data-engineer |
|
||||||
|
| `cmd/orca` | 0% (no tests) | ≥ 50% toe-hold | lead-developer |
|
||||||
|
|
||||||
|
### Wave 1 — Seams + foundational test helpers (no production logic changes)
|
||||||
|
|
||||||
|
These are backward-compatible interface extractions that unlock the bulk of
|
||||||
|
coverage in Wave 2. They are the only production-code changes in P01; all
|
||||||
|
other P01 tasks add `_test.go` files only.
|
||||||
|
|
||||||
|
| Task ID | Owner | Wave | Must | Title | Files touched | Acceptance criterion |
|
||||||
|
|---------|-------|------|------|-------|---------------|----------------------|
|
||||||
|
| T01.1 | backend-engineer | 1 | Y | Add `sessionRunner` interface seam to proxmox | `internal/proxmox/bootstrap.go` | Extract a `sessionRunner` interface (`CombinedOutput(cmd string) ([]byte, error)`) ~10 LOC; default impl wraps `*ssh.Client.NewSession().CombinedOutput(...)`; `runRemote`/`deployPubKey`/`createLinuxUser`/`createPVERole`/`createPVEUser`/`assignPVEACL`/`writeSudoers`/`validateSudoers` use the seam. Backward compatible: existing callers unchanged. `go build ./internal/proxmox` PASS. (RESEARCH §1.3 gap #1, §5 pitfall #3) |
|
||||||
|
| T01.2 | backend-engineer | 1 | N | Add `peerDispatcher` seam to engine (only if needed for 70%) | `internal/engine/dispatcher.go` | Extract a `peerDispatcher` interface (`Submit(ctx, spec, key) (*SubmitResponse, error)`) so `dispatchToPeer` is testable without `httptest.NewTLSServer`. **Only add if T01.5 cannot otherwise hit 70% via `httptest.NewTLSServer` alone.** If added, backward compatible. (RESEARCH §1.3 gap #2, §5 pitfall #8) |
|
||||||
|
|
||||||
|
### Wave 2 — Per-package coverage tests (build on Wave 1 seams)
|
||||||
|
|
||||||
|
| Task ID | Owner | Wave | Must | Title | Files touched | Acceptance criterion |
|
||||||
|
|---------|-------|------|------|-------|---------------|----------------------|
|
||||||
|
| T01.3 | backend-engineer | 2 | Y | `internal/transport` tests → ≥ 70% | `internal/transport/mtls_test.go` (NEW), `internal/transport/dispatch_test.go` (NEW), `internal/transport/handshake_log_test.go` (NEW), `internal/transport/retry_test.go` (NEW, extend) | `httptest.NewTLSServer` with a test CA (reuse `security.CAInit`/`GenerateCSR`/`SignCSR` per RESEARCH §1.2) for mTLS handshake paths; `stubDispatcher` (daemon/dispatch_test.go:24) pattern for Dispatch RPC; capture slog via a test `slog.Handler` for handshake_log. `go test -cover ./internal/transport` → ≥ 70% (was 26.3%). |
|
||||||
|
| T01.4 | backend-engineer | 2 | Y | `internal/engine` tests → ≥ 70% | `internal/engine/executor_test.go` (NEW), `internal/engine/dispatcher_test.go` (NEW), `internal/engine/peer_test.go` (NEW), `internal/engine/scheduler_test.go` (extend), `internal/engine/registry_test.go` (NEW, if registry exists) | `Executor.Start`/`Wait` lifecycle (echo/false/ctx-cancel/Env propagation per REQ-021); `Dispatcher.Submit` with stubbed `LocalExecutor` + (if T01.2 added) stubbed `peerDispatcher` OR `httptest.NewTLSServer`; `PeerRegistry` in-memory Add/Remove/All/Get. Reuse `openTestDB` (node_repo_test.go:12). `go test -cover ./internal/engine` → ≥ 70% (was 8.3%). |
|
||||||
|
| T01.5 | backend-engineer | 2 | Y | `internal/proxmox` tests → ≥ 70% | `internal/proxmox/bootstrap_test.go` (extend) | Swap `sshDialer` (existing seam) for a fake returning a mock `*ssh.Client`; swap `sessionRunner` (T01.1 seam) for a fake that returns canned `CombinedOutput` bytes. Assert full bootstrap sequence calls the right shell commands in order; idempotent re-run ("already exists" → no-op); SSH auth failure → wrapped error; no password logged (D-031). `go test -cover ./internal/proxmox` → ≥ 70% (was 5.1%). |
|
||||||
|
| T01.6 | lead-developer | 2 | Y | `internal/cli` tests → ≥ 70% (excluding daemon.go) with GRILL condition #3 escape valve | `internal/cli/node_test.go` (NEW), `internal/cli/job_test.go` (NEW), `internal/cli/cert_test.go` (NEW), `internal/cli/doctor_test.go` (NEW), `internal/cli/audit_test.go` (NEW), `internal/cli/status_test.go` (NEW), `internal/cli/version_test.go` (NEW), `internal/cli/node_capacity_test.go` (NEW) | Table-driven `rootCmd.Execute()` against temp `ORCA_HOME` per subcommand (reuse `initTestEnv`/`resetRootFlags`/`discardWriter` per RESEARCH §1.2). Mock the proxmox path via `sshDialer` + `sessionRunner` seams. `daemon.go` is excluded — covered by `internal/daemon/server_test.go`. `go test -cover ./internal/cli` → ≥ 70% of non-daemon files (document the exclusion in a test-file comment). **GRILL condition #3 escape valve**: if 70% is not reached after Wave 2 effort and ≥ 65% is achieved (RESEARCH §1.4 flags 55-65% as realistic for one phase), ship cli at 65% and do NOT block P02/P03 on the last 5%; record the shortfall + rationale in the P01 verification commit. |
|
||||||
|
| T01.7 | data-engineer | 2 | Y | `internal/store` tests → ≥ 70% (incl. missing `cert_repo_test.go`) | `internal/store/cert_repo_test.go` (NEW — v0.7 P01 leftover, RESEARCH §1.1), `internal/store/node_repo_test.go` (extend), `internal/store/job_task_repo_test.go` (extend), `internal/store/audit_repo_test.go` (extend), `internal/store/capacity_repo_test.go` (extend) | `cert_repo_test.go`: Insert/Get/List/ListByNode/LatestForKind/PruneOlderThan/Delete + N=3 rotation history per REQ-025 + duplicate-serial error. Reuse `openTestDB`/`withFastWatch` (RESEARCH §1.2). `go test -cover ./internal/store` → ≥ 70% (was 47.2%). |
|
||||||
|
| T01.8 | data-engineer | 2 | Y | `internal/jobspec` tests → ≥ 70% | `internal/jobspec/spec_test.go` (extend), `internal/jobspec/testdata/*.hcl` (NEW golden fixtures) | Golden-file HCL fixtures (multi-task, env vars, args) + error-path table (missing job, no tasks, missing command, malformed HCL, empty file, nonexistent file for `ParseFile`). `go test -cover ./internal/jobspec` → ≥ 70% (was 47.6%). |
|
||||||
|
| T01.9 | data-engineer | 2 | Y | `internal/audit` first tests → ≥ 50% toe-hold | `internal/audit/audit_test.go` (NEW) | Construct `Audit` with real `engine.Audit` backed by `:memory:` sqlite (via `store.NewAuditRepo` + `engine.NewAudit`); assert rows in `audit_log` table; capture slog via a test `slog.Handler` for `LogHandshakeOK`/`LogHandshakeFailed`. `go test -cover ./internal/audit` → ≥ 50% (was 0%). |
|
||||||
|
| T01.10 | data-engineer | 2 | Y | `internal/certpaths` first tests → ≥ 50% toe-hold | `internal/certpaths/certpaths_test.go` (NEW) | Temp dir + `t.Setenv("ORCA_HOME", dir)` + assert each `*Path()` returns `filepath.Join(dir, <file>)`; test `ORCA_DB` override; test default-to-`~/.orca` fallback. Model on `namespace_test.go` (cli). `go test -cover ./internal/certpaths` → ≥ 50% (was 0%). |
|
||||||
|
| T01.11 | lead-developer | 2 | Y | `cmd/orca` smoke test → ≥ 50% toe-hold | `cmd/orca/main_test.go` (NEW), possibly `cmd/orca/main.go` (refactor `main()` into `run() int` for testability) | Refactor `main()` to `run() int` (returns exit code; `main()` calls `os.Exit(run())`) so the test can call `run()` directly with a forced error path and assert non-zero exit + stderr contains "error:". Low-effort toe-hold — do NOT over-invest (RESEARCH §1.1, §5 pitfall #6). `go test -cover ./cmd/orca` → ≥ 50% (was 0%). |
|
||||||
|
|
||||||
|
### Wave 3 — Coverage gate verification
|
||||||
|
|
||||||
|
| Task ID | Owner | Wave | Must | Title | Files touched | Acceptance criterion |
|
||||||
|
|---------|-------|------|------|-------|---------------|----------------------|
|
||||||
|
| T01.12 | lead-developer | 3 | Y | Coverage-gate verification (all 9 packages hit tiered floor) | none (verification only) | `go test -cover ./internal/engine ./internal/proxmox ./internal/cli ./internal/transport ./internal/store ./internal/jobspec` → each ≥ 70%; `go test -cover ./internal/audit ./internal/certpaths ./cmd/orca` → each ≥ 50%. `go test -race ./...` PASS. Any races fixed in-phase (not deferred). |
|
||||||
|
|
||||||
|
### Phase 1 Must-Haves (summary)
|
||||||
|
|
||||||
|
All 9 packages hit their tiered floor (D-047): T01.1, T01.3, T01.4, T01.5,
|
||||||
|
T01.6, T01.7, T01.8, T01.9, T01.10, T01.11, T01.12. T01.2 is conditional
|
||||||
|
(only if needed for engine 70%).
|
||||||
|
|
||||||
|
### Phase 1 Verification
|
||||||
|
|
||||||
|
- `go build ./...` PASS
|
||||||
|
- `go vet ./...` PASS
|
||||||
|
- `go test -race ./...` PASS
|
||||||
|
- Per-package coverage hits the tiered floor (T01.12)
|
||||||
|
- The proxmox `sessionRunner` seam is backward compatible (existing
|
||||||
|
`BootstrapProxmox` callers unchanged)
|
||||||
|
- No new direct deps (`go.mod` unchanged)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 2: SSH Trust Hardening (REQ-058, REQ-059)
|
||||||
|
|
||||||
|
**Branch**: `phase/02-ssh-trust-hardening`
|
||||||
|
**REQ Coverage**: REQ-058, REQ-059
|
||||||
|
**Tag**: `v0.7.2`
|
||||||
|
**Depends on**: Phase 1 (proxmox `sessionRunner` seam from T01.1 is in place;
|
||||||
|
the trust-surface code is now testable)
|
||||||
|
**Source research**: RESEARCH_v0.8.md §2 (TOFU bug, fingerprint computation,
|
||||||
|
flag wiring, key-reset atomic rewrite) + §4 AD-027..AD-029
|
||||||
|
**Phase type**: chore (trust-surface hardening per D-043 — refines existing
|
||||||
|
`orca node join --type proxmox` flow + existing TOFU `known_hosts` store; no
|
||||||
|
new orchestration capability)
|
||||||
|
|
||||||
|
### Wave 1 — Trust-surface foundations (security helpers + flag declarations)
|
||||||
|
|
||||||
|
| Task ID | Owner | Wave | Must | Title | Files touched | Acceptance criterion |
|
||||||
|
|---------|-------|------|------|-------|---------------|----------------------|
|
||||||
|
| T02.1 | backend-engineer | 1 | Y | Add `security.SSHFingerprintSHA256` helper (AD-027) | `internal/security/sshkey.go` (extend) OR `internal/security/fingerprint.go` (extend) | Thin wrapper over `ssh.FingerprintSHA256(pubKey ssh.PublicKey) string` returning the canonical `SHA256:base64` string. Do NOT reuse `security.Fingerprint` (X.509 hex — different domain per RESEARCH §2.2). Unit test: known Ed25519 pub key → known `SHA256:` string. |
|
||||||
|
| T02.2 | backend-engineer | 1 | Y | Export `security.WriteAtomic` (AD-029 enabler) | `internal/security/ca.go` | Rename `writeAtomic` → `WriteAtomic` (export) + update existing in-package callers. The `key-reset` atomic known_hosts rewrite (T02.7) needs it. Alternatively copy the ~20-LOC pattern into `proxmox` if export is undesirable — **recommend export** (RESEARCH §5 pitfall #10). `go build ./internal/security` PASS. |
|
||||||
|
| T02.3 | backend-engineer | 1 | Y | Add `--host-key-fingerprint` flag on `orca node join` (D-044) | `internal/cli/node.go` | `nodeJoinCmd.Flags().StringVar(&joinHostKeyFP, "host-key-fingerprint", "", "SSH host key SHA256:base64 fingerprint (pre-pin; supersedes TOFU for --type proxmox)")` in the flag-registration block (node.go:344-354). Add `joinHostKeyFP string` to the var block (node.go:47-60). Validation in `RunE`: if `joinHostKeyFP != ""` and `--type != proxmox`, emit a clear error ("--host-key-fingerprint requires --type proxmox today"). Flag is generic for future SSH-joined kinds (D-044). |
|
||||||
|
| T02.4 | backend-engineer | 1 | Y | Add `HostKeyFingerprint` field to `proxmox.Options` | `internal/proxmox/bootstrap.go` | Add `HostKeyFingerprint string` to the `Options` struct (bootstrap.go:55). Pass-through from `internal/cli/node.go` joinProxmox (node.go:158-166): `HostKeyFingerprint: joinHostKeyFP`. |
|
||||||
|
|
||||||
|
### Wave 2 — Trust features + bugfix (build on Wave 1)
|
||||||
|
|
||||||
|
| Task ID | Owner | Wave | Must | Title | Files touched | Acceptance criterion |
|
||||||
|
|---------|-------|------|------|-------|---------------|----------------------|
|
||||||
|
| T02.5 | backend-engineer | 2 | Y | Implement `pinnedHostKeyCallback` (REQ-058, AD-028) | `internal/proxmox/bootstrap.go` | `pinnedHostKeyCallback(expectedSHA256Base64 string) (ssh.HostKeyCallback, error)`: validate `SHA256:` prefix up front (reject raw hex with a clear error per D-045); callback receives server's `ssh.PublicKey`, computes `ssh.FingerprintSHA256(key)` (via T02.1 helper or inline), compares full strings to the operator-supplied value; returns `nil` on match, `error` on mismatch (fail closed). In `BootstrapProxmox`: if `opts.HostKeyFingerprint != ""` use `pinnedHostKeyCallback`, else fall back to the TOFU callback (T02.6). Unit test: match → callback returns nil; mismatch → returns error mentioning REQ-058; non-`SHA256:`-prefixed input → constructor returns error. |
|
||||||
|
| T02.6 | backend-engineer | 2 | Y | **BUGFIX (v0.6 ship-defect)**: FIX the latent TOFU capture bug (RESEARCH §2.1, §5 pitfall #1, GRILL condition #1) | `internal/proxmox/bootstrap.go` | Wrap `knownhosts.New(...)` with a custom callback that: on `*knownhosts.KeyError{Want: []}` (host unknown) captures the server-presented `ssh.PublicKey`, writes a line via `knownhosts.Line([]string{knownhosts.Normalize(addr)}, key)` to `certpaths.KnownHostsPath()` using `security.WriteAtomic` (T02.2, AD-029), and returns `nil` (allow the dial to proceed). On `*knownhosts.KeyError{Want: [knownKey]}` (mismatch) returns the error (MITM detection). On `nil` (host present + match) returns `nil`. This fixes the v0.6 latent ship-defect where first-connect Proxmox join always failed (verified against `golang.org/x/crypto@v0.54.0/ssh/knownhosts/knownhosts.go:370-385`). P04 audit must record this as ship-defect closure. Unit test: first-connect captures the key + writes known_hosts; second-connect matches; mismatch-connect fails. |
|
||||||
|
| T02.7 | backend-engineer | 2 | Y | Populate `Result.HostKeyFingerprint` (RESEARCH §2.2, §5 pitfall #2) | `internal/proxmox/bootstrap.go` | In the capture path (T02.6) and the pinned path (T02.5), set `Result.HostKeyFingerprint = ssh.FingerprintSHA256(hostKey)` (via T02.1). The field is currently declared (bootstrap.go:83-85) but always `""`. After T02.7, `orca node join --type proxmox` output includes the real fingerprint. Unit test: `Result.HostKeyFingerprint` is non-empty + `SHA256:`-prefixed after a successful bootstrap. |
|
||||||
|
| T02.8 | backend-engineer | 2 | Y | Implement `orca node key-reset <node>` (REQ-059, D-046, AD-029) | `internal/cli/node.go`, `internal/proxmox/bootstrap.go` (new `ResetHostKey` helper OR inline in cli) | New `nodeKeyResetCmd` (`&cobra.Command{Use: "key-reset <node>", Args: cobra.ExactArgs(1), RunE: ...}`) registered via `nodeCmd.AddCommand(nodeKeyResetCmd)` (node.go:358-360). `RunE`: (1) resolve `<node>` arg via `nodeRegistry()` (node.go:37) → get node row → use `node.Name` (the host address for proxmox nodes) as the `known_hosts` match key; (2) call `proxmox.ResetHostKey(host) error` which reads `certpaths.KnownHostsPath()`, filters lines whose host field (before first whitespace, normalized via `knownhosts.Normalize`) matches, rewrites via `security.WriteAtomic` (T02.2); (3) audit-log `event=node.key_reset` with `actor`+`node`+`host` via `engine.Audit.Record`; (4) print `✓ Host key reset for <node> (next connect will re-pin via TOFU or --host-key-fingerprint)`. **Local only — do NOT revoke remote authorized_keys** (D-046). Unit test: known_hosts with 2 entries for the target host + 1 for another host → after reset, target's 2 lines removed, other host's line intact; audit row inserted. |
|
||||||
|
| T02.9 | backend-engineer | 2 | Y | Apply the TOFU capture-fix to `doctor proxmox` probe (GRILL condition #2 — doctor parity with bootstrap) | `internal/doctor/doctor.go` | The doctor proxmox probe (doctor.go:412-415) uses the same `knownhosts.New(...)` callback pattern as bootstrap. Apply the same capture-fix wrapper (T02.6) so `doctor proxmox` on a first-connect node doesn't fail. **P02 is not complete until both bootstrap (T02.6) and doctor (T02.9) callbacks use the capture-fix wrapper — GRILL condition #2 binding parity check.** (If the doctor probe already relies on a prior `node join` having populated `known_hosts`, the fix is still correct — it makes the doctor robust to a missing entry.) |
|
||||||
|
|
||||||
|
### Wave 3 — End-to-end integration + verification
|
||||||
|
|
||||||
|
| Task ID | Owner | Wave | Must | Title | Files touched | Acceptance criterion |
|
||||||
|
|---------|-------|------|------|-------|---------------|----------------------|
|
||||||
|
| T02.10 | backend-engineer | 3 | Y | End-to-end trust-surface integration tests | `internal/proxmox/bootstrap_test.go` (extend), `internal/cli/node_test.go` (extend) | (1) `--host-key-fingerprint` with a correct pin → bootstrap succeeds + `Result.HostKeyFingerprint` matches the pin; (2) `--host-key-fingerprint` with a wrong pin → bootstrap fails fast with the REQ-058 mismatch error; (3) no `--host-key-fingerprint` + first connect (empty known_hosts) → TOFU captures the key + writes known_hosts + bootstrap succeeds; (4) no flag + second connect (known_hosts has the key) → matches + succeeds; (5) no flag + mismatch (known_hosts has a different key) → fails with MITM error; (6) `orca node key-reset <node>` → known_hosts entry removed + audit row inserted + next connect re-pins; (7) known_hosts pre-populated (v0.6→v0.8 migration path: existing entry from a prior join) → second-connect matches without re-capture, covering the upgrade path. |
|
||||||
|
| T02.11 | backend-engineer | 3 | Y | `--host-key-fingerprint` non-proxmox type validation test | `internal/cli/node_test.go` (extend) | `orca node join --type linux --host-key-fingerprint SHA256:...` → clear error ("--host-key-fingerprint requires --type proxmox today"). Validates D-044 RunE check from T02.3. |
|
||||||
|
|
||||||
|
### Phase 2 Must-Haves (summary)
|
||||||
|
|
||||||
|
- T02.1, T02.2, T02.3, T02.4 (Wave 1 foundations)
|
||||||
|
- T02.5 (`--host-key-fingerprint` pinned callback — REQ-058)
|
||||||
|
- T02.6 (TOFU capture-fix — latent bug)
|
||||||
|
- T02.7 (`Result.HostKeyFingerprint` populated)
|
||||||
|
- T02.8 (`orca node key-reset` — REQ-059)
|
||||||
|
- T02.9 (doctor proxmox TOFU fix)
|
||||||
|
- T02.10, T02.11 (integration + validation)
|
||||||
|
|
||||||
|
### Phase 2 Verification
|
||||||
|
|
||||||
|
- `go build ./...` PASS
|
||||||
|
- `go vet ./...` PASS
|
||||||
|
- `go test -race ./internal/proxmox/... ./internal/cli/... ./internal/doctor/... ./internal/security/...` PASS
|
||||||
|
- `./bin/orca node join --help` shows `--host-key-fingerprint` flag
|
||||||
|
- `./bin/orca node key-reset --help` shows the key-reset subcommand
|
||||||
|
- Pinned mismatch → fail closed (T02.10 case 2)
|
||||||
|
- TOFU first-connect → captures + succeeds (T02.10 case 3)
|
||||||
|
- `Result.HostKeyFingerprint` is non-empty after bootstrap (T02.7)
|
||||||
|
- `key-reset` removes only the target host's known_hosts lines + audit-logs (T02.8)
|
||||||
|
- No new direct deps
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 3: Requirements-Hygiene Gate (REQ-060)
|
||||||
|
|
||||||
|
**Branch**: `phase/03-verify-reqs`
|
||||||
|
**REQ Coverage**: REQ-060
|
||||||
|
**Tag**: `v0.7.3`
|
||||||
|
**Depends on**: Phase 2 (P03 is independent of P02 code, but ships after per
|
||||||
|
ROADMAP ordering; the verify-reqs program parses the `.ciagent/` markdown
|
||||||
|
which is stable by P03)
|
||||||
|
**Source research**: RESEARCH_v0.8.md §3 (Makefile, .coreci.yml, parsing
|
||||||
|
approach, AD-030) + §4 AD-030
|
||||||
|
|
||||||
|
### Wave 1 — Go program
|
||||||
|
|
||||||
|
| Task ID | Owner | Wave | Must | Title | Files touched | Acceptance criterion |
|
||||||
|
|---------|-------|------|------|-------|---------------|----------------------|
|
||||||
|
| T03.1 | lead-developer | 1 | Y | `cmd/verify-reqs/main.go` — Go program (~80 LOC, stdlib only, AD-030, GRILL condition #4 regex + reverse direction) | `cmd/verify-reqs/main.go` (NEW) | Parses `.ciagent/ROADMAP.md` + `.ciagent/REQUIREMENTS.md` using `regexp` (stdlib). **Forward assertion**: for every REQ-ID in REQUIREMENTS.md whose `Phase` column references a milestone that ROADMAP marks COMPLETE (substring-match `COMPLETE` within the bold span — NOT exact `\*\*COMPLETE\*\*` which misses v0.2's `**COMPLETE (merged to main via v0.3)**` header at ROADMAP.md:23), the REQUIREMENTS `Status` must be `Complete`. **Reverse assertion (GRILL condition #4)**: for every REQ-ID in REQUIREMENTS.md marked `Complete`, the corresponding milestone in ROADMAP.md must be marked COMPLETE. Regex: REQUIREMENTS row `^\|\s*(REQ-\d+)\s*\|.*?\|\s*\*\*(Complete\|Pending)\*\*\s*\|`; ROADMAP milestone-complete `^##\s*Milestone\s+v0\.\d+:.*—\s*\*\*COMPLETE[^\*]*\*\*` (substring tolerant); map milestone → REQs via the REQUIREMENTS `Phase` column (e.g. `v0.7 P1` → milestone `v0.7`). Exit 0 on consistency; exit 1 with a diff listing (REQ-ID + current status + expected status + direction) on drift. CLI: `go run ./cmd/verify-reqs .ciagent/ROADMAP.md .ciagent/REQUIREMENTS.md` (args optional; defaults to those paths). **Scope note (GRILL)**: REQ-060 catches doc-vs-doc drift only; code-vs-doc drift (e.g. the REQ-053 `cert_repo_test.go` omission — verified missing) is out of scope for this gate and handled by P04 `ciagent-audit`. |
|
||||||
|
| T03.2 | lead-developer | 1 | Y | `cmd/verify-reqs/main_test.go` — golden-file tests | `cmd/verify-reqs/main_test.go` (NEW), `cmd/verify-reqs/testdata/` (NEW: `roadmap_clean.md`, `requirements_clean.md`, `roadmap_drift.md`, `requirements_drift.md`) | (1) Clean pair (ROADMAP v0.X COMPLETE + REQUIREMENTS REQ-XXX Complete) → exit 0, no diff; (2) Drift pair (ROADMAP v0.X COMPLETE + REQUIREMENTS REQ-XXX Pending) → exit 1 + diff lists the stale REQ; (3) Multiple drifts → all reported; (4) Missing args → uses defaults; (5) Malformed markdown → clear error (not a silent pass). |
|
||||||
|
|
||||||
|
### Wave 2 — Makefile + CI hook
|
||||||
|
|
||||||
|
| Task ID | Owner | Wave | Must | Title | Files touched | Acceptance criterion |
|
||||||
|
|---------|-------|------|------|-------|---------------|----------------------|
|
||||||
|
| T03.3 | lead-developer | 2 | Y | `make verify-reqs` target | `Makefile` | Add `verify-reqs` target: `go run ./cmd/verify-reqs .ciagent/ROADMAP.md .ciagent/REQUIREMENTS.md`. Add to `.PHONY`. `make verify-reqs` exits 0 on the current repo (REQUIREMENTS was corrected during v0.8 SPECIFY). |
|
||||||
|
| T03.4 | lead-developer | 2 | Y | `.coreci.yml` validate-pipeline hook | `.coreci.yml` | Add a `verify-reqs` step to the `validate` pipeline (after `go-version`, alongside `gosec`/`govulncheck`/`gitleaks` per RESEARCH §3.2): `image: golang:1.25`, `commands: [make verify-reqs]`. Pipeline fails on drift. |
|
||||||
|
|
||||||
|
### Wave 3 — Synthetic drift verification
|
||||||
|
|
||||||
|
| Task ID | Owner | Wave | Must | Title | Files touched | Acceptance criterion |
|
||||||
|
|---------|-------|------|------|-------|---------------|----------------------|
|
||||||
|
| T03.5 | lead-developer | 3 | Y | Synthetic drift verification (REQ-060 acceptance) | none (verification only; temporarily flip a REQUIREMENTS row to Pending in a scratch commit, run `make verify-reqs`, assert exit 1 + diff, then revert) | (1) `make verify-reqs` on the current repo → exit 0; (2) flip one v0.7 REQ row to `Pending` in a scratch edit → `make verify-reqs` → exit 1 + diff lists that REQ-ID; (3) revert the scratch edit → exit 0. This is the REQ-060 acceptance criterion ("passes on current repo + fails on synthetic drift"). |
|
||||||
|
|
||||||
|
### Phase 3 Must-Haves (summary)
|
||||||
|
|
||||||
|
T03.1, T03.2, T03.3, T03.4, T03.5 — all must complete for the hygiene gate to
|
||||||
|
ship.
|
||||||
|
|
||||||
|
### Phase 3 Verification
|
||||||
|
|
||||||
|
- `go build ./cmd/verify-reqs` PASS
|
||||||
|
- `go test ./cmd/verify-reqs/...` PASS (golden-file tests)
|
||||||
|
- `make verify-reqs` → exit 0 on the current repo
|
||||||
|
- Synthetic drift → `make verify-reqs` exit 1 + diff (T03.5)
|
||||||
|
- `.coreci.yml` validate pipeline includes the `verify-reqs` step
|
||||||
|
- No new direct deps (stdlib only)
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 4: Final Review + Ship + Audit (no new REQs)
|
||||||
|
|
||||||
|
**Branch**: `phase/04-final-review-ship`
|
||||||
|
**REQ Coverage**: all (REQ-057..060)
|
||||||
|
**Tag**: `v0.7.4` (milestone release)
|
||||||
|
**Depends on**: Phase 1 + Phase 2 + Phase 3
|
||||||
|
**Source**: milestone-release checklist (matches PLAN_v0.7 P05 structure)
|
||||||
|
|
||||||
|
### Wave 1 — Review + audit
|
||||||
|
|
||||||
|
| Task ID | Owner | Wave | Must | Title | Files touched | Acceptance criterion |
|
||||||
|
|---------|-------|------|------|-------|---------------|----------------------|
|
||||||
|
| T04.1 | lead-developer | 1 | Y | Multi-persona code review across all v0.8 phases | none (review only) | ciagent-review across P01..P03; P0 issues fixed in-phase; P1+ recorded in `.ciagent/` for post-hoc. |
|
||||||
|
| T04.2 | lead-developer | 1 | Y | Audit: reconstruction test + branch hygiene + commit discipline | none (audit only) | ciagent-audit: git log matches `.ciagent/` files; branch hygiene clean; commit discipline enforced. |
|
||||||
|
|
||||||
|
### Wave 2 — Ship
|
||||||
|
|
||||||
|
| Task ID | Owner | Wave | Must | Title | Files touched | Acceptance criterion |
|
||||||
|
|---------|-------|------|------|-------|---------------|----------------------|
|
||||||
|
| T04.3 | lead-developer | 2 | Y | Merge phase/04 → milestone/v0.8-coverage-trust-hardening | none | Fast-forward merge (or rebase-then-fast-forward per config). |
|
||||||
|
| T04.4 | lead-developer | 2 | Y | Merge milestone/v0.8 → main | none | Rebase-then-fast-forward per config. |
|
||||||
|
| T04.5 | lead-developer | 2 | Y | Tag `v0.7.4` (milestone release) | none | `git tag v0.7.4` on the merged main HEAD. Per-phase tags `v0.7.0`..`v0.7.4` all present. |
|
||||||
|
| T04.6 | lead-developer | 2 | Y | Create Gitea release `v0.7.4` with milestone summary | none | Release notes cover all 4 phases + REQ-057..060 + coverage deltas + trust-surface additions. |
|
||||||
|
|
||||||
|
### Wave 3 — Post-ship bookkeeping
|
||||||
|
|
||||||
|
| Task ID | Owner | Wave | Must | Title | Files touched | Acceptance criterion |
|
||||||
|
|---------|-------|------|------|-------|---------------|----------------------|
|
||||||
|
| T04.7 | lead-developer | 3 | Y | Update REQUIREMENTS.md — mark REQ-057..060 Complete | `.ciagent/REQUIREMENTS.md` | All 4 v0.8 REQ rows show `**Complete**` with phase + ship tag. `make verify-reqs` still passes (self-consistency). |
|
||||||
|
| T04.8 | lead-developer | 3 | Y | Update ROADMAP.md — mark v0.8 COMPLETE | `.ciagent/ROADMAP.md` | v0.8 milestone section shows `**COMPLETE**`; all phase checkboxes `[x]`. `make verify-reqs` still passes. |
|
||||||
|
| T04.9 | lead-developer | 3 | Y | Write + clear checkpoint | `.ciagent/` checkpoint | `{phase: 4, stage: "complete", phase_role: "final", milestone_complete: true}`; then clear checkpoint (milestone complete; next run starts a new milestone). |
|
||||||
|
|
||||||
|
### Phase 4 Must-Haves (summary)
|
||||||
|
|
||||||
|
All tasks (T04.1..T04.9) are must-haves — the final-review phase has no
|
||||||
|
optional work.
|
||||||
|
|
||||||
|
### Phase 4 Verification
|
||||||
|
|
||||||
|
- `make build` PASS
|
||||||
|
- `make test` PASS
|
||||||
|
- `make lint` PASS
|
||||||
|
- `make verify-reqs` PASS
|
||||||
|
- `go vet ./...` PASS
|
||||||
|
- `git log` on main shows all v0.8 phase commits
|
||||||
|
- `git tag --list 'v0.7.*'` shows v0.7.0..v0.7.4
|
||||||
|
- REQUIREMENTS.md shows REQ-057..060 as Complete
|
||||||
|
- ROADMAP.md shows v0.8 as COMPLETE
|
||||||
|
- Gitea release `v0.7.4` published with milestone summary
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Phase 5: Final Review (next milestone, not part of v0.8 execution)
|
||||||
|
|
||||||
|
Per the v0.8 ROADMAP, there are 4 execution phases (P01..P04). P04 IS the
|
||||||
|
final review + ship + audit phase. There is no separate P05 in v0.8 (unlike
|
||||||
|
v0.7 which had P05). The orchestrator's next-milestone P0 begins after
|
||||||
|
T04.9 clears the checkpoint.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Risk Register (carried forward from RESEARCH_v0.8.md §5)
|
||||||
|
|
||||||
|
| # | Pitfall | Phase(s) affected | Mitigation |
|
||||||
|
|---|---------|-------------------|------------|
|
||||||
|
| 1 | TOFU capture is currently BROKEN: `knownhosts.New` returns `KeyError{Want:[]}` on first connect and does NOT auto-write; current `BootstrapProxmox` treats it as a dial failure. | P02 | T02.6 wraps the callback to capture-and-persist on `KeyError{Want:[]}` via `knownhosts.Line` + `security.WriteAtomic`. This is a v0.6 latent bug that P02 closes. |
|
||||||
|
| 2 | `Result.HostKeyFingerprint` is declared but never populated (always `""`). D-045's rationale references "existing output" that doesn't exist. | P02 | T02.7 adds `ssh.FingerprintSHA256(hostKey)` computation in both the capture and pinned paths. 1-line addition once the host key is available. |
|
||||||
|
| 3 | No `sessionRunner` seam in proxmox — testing the SSH command sequence without a real SSH server is impossible. | P01 | T01.1 adds a 1-interface ~10-LOC `sessionRunner` seam in Wave 1. Unlocks ~40% of proxmox coverage. Backward compatible. |
|
||||||
|
| 4 | `internal/store/cert_repo.go` has NO test — v0.7 P01 REQ-053 was supposed to add `cert_repo_test.go` but it's missing (v0.7 leftover). | P01 | T01.7 adds `cert_repo_test.go` (Insert/Get/List/ListByNode/LatestForKind/PruneOlderThan/Delete + N=3 rotation). Directly lifts store coverage toward 70%. |
|
||||||
|
| 5 | `internal/cli/daemon.go` starts a long-running mTLS server — testing it in cli requires a lifecycle harness; it's already covered by `internal/daemon/server_test.go`. | P01 | T01.6 excludes `daemon.go` from the cli 70% target; documents the exclusion in a test-file comment. Avoids double-testing. |
|
||||||
|
| 6 | `cmd/orca` 50% toe-hold is low-value (15 LOC of glue; effort:coverage ratio is poor). | P01 | T01.11 keeps it at the 50% toe-hold per D-047; does NOT over-invest. A small `run() int` refactor enables a smoke test. |
|
||||||
|
| 7 | `go: no such tool "covdata"` for zero-test packages — a Go toolchain quirk when a package has no test files; NOT a real 0% number. | P01 | T01.9, T01.10, T01.11 each add a `_test.go` file, which makes coverage computable. Don't treat the tooling error as a measurement. |
|
||||||
|
| 8 | `transport.dispatchToPeer` has no seam — testing the remote-dispatch branch requires a new interface OR `httptest.NewTLSServer`. | P01 | T01.3 uses `httptest.NewTLSServer` (no refactor needed). T01.2 (conditional `peerDispatcher` seam) is only added if engine cannot otherwise hit 70%. |
|
||||||
|
| 9 | `knownhosts.Line` + `knownhosts.Normalize` are the helpers for the TOFU-capture fix and `key-reset` matching. | P02 | T02.6 + T02.8 use `Normalize` to match host strings consistently (handles `host:22` vs `host`). |
|
||||||
|
| 10 | `security.writeAtomic` is unexported (ca.go:305); `key-reset`'s atomic known_hosts rewrite needs it. | P02 | T02.2 exports `WriteAtomic` (recommended) OR copies the ~20-LOC pattern. Export is preferred — it's already used across ca.go + sshkey.go. |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## REQ-ID → Task mapping (traceability)
|
||||||
|
|
||||||
|
| REQ-ID | Phase | Tasks |
|
||||||
|
|--------|-------|-------|
|
||||||
|
| REQ-057 | P01 | T01.1, T01.2 (conditional), T01.3, T01.4, T01.5, T01.6, T01.7, T01.8, T01.9, T01.10, T01.11, T01.12 |
|
||||||
|
| REQ-058 | P02 | T02.1, T02.3, T02.4, T02.5, T02.7, T02.10, T02.11 |
|
||||||
|
| REQ-059 | P02 | T02.2, T02.8, T02.10 |
|
||||||
|
| REQ-060 | P03 | T03.1, T03.2, T03.3, T03.4, T03.5 |
|
||||||
|
| (latent TOFU bug) | P02 | T02.6, T02.9 (not a REQ — closes a v0.6 gap surfaced by RESEARCH §2.1) |
|
||||||
|
| (milestone release) | P04 | T04.1..T04.9 |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Task counts
|
||||||
|
|
||||||
|
| Phase | Tasks | Must-haves | Waves |
|
||||||
|
|-------|-------|------------|-------|
|
||||||
|
| P01 | 12 | 11 (T01.2 conditional) | 3 |
|
||||||
|
| P02 | 11 | 11 | 3 |
|
||||||
|
| P03 | 5 | 5 | 3 |
|
||||||
|
| P04 | 9 | 9 | 3 |
|
||||||
|
| **Total** | **37** | **36** | — |
|
||||||
@@ -0,0 +1,92 @@
|
|||||||
|
# Orca — Comprehensive Product Requirements Document (v0.9/v0.10)
|
||||||
|
|
||||||
|
**Audience:** Operators, AI agents, downstream tooling authors
|
||||||
|
|
||||||
|
> This PRD SUPERSEDES the shipped v0.1–v0.8 architecture. The v0.9 and v0.10
|
||||||
|
> milestones implement a re-architecture whose load-bearing rules (R-001…R-016)
|
||||||
|
> and decisions (D-068…D-206) replace or demote several earlier documented
|
||||||
|
> decisions. See §22 decision-trace and the Supersession Table in
|
||||||
|
> `ARCHITECTURE.md` for the recorded reversals and their evidence basis.
|
||||||
|
|
||||||
|
## Status
|
||||||
|
|
||||||
|
| Item | Status |
|
||||||
|
|---|---|
|
||||||
|
| Spec lock-in | ✅ R-001…R-016 + D-001…D-206 settled |
|
||||||
|
| v0.1–v0.8 implementation | ✅ shipped (REQ-001..060, D-001..D-047) |
|
||||||
|
| v0.9 implementation | ⬜ Phase 0 pre-execution (this file is the spec input) |
|
||||||
|
| v0.10 implementation | ⬜ planning (post-PRD) |
|
||||||
|
| v1.x multi-host state | ⬜ parked (post-v1.0) |
|
||||||
|
| v2.x full Nomad-HCL | ⬜ parked (post-v1.x) |
|
||||||
|
|
||||||
|
## Override justification (recorded for the grill supersession)
|
||||||
|
|
||||||
|
The v0.9/v0.10 re-architecture is justified on six independent grounds rather
|
||||||
|
than preference. Each reverses a prior documented decision; the new evidence
|
||||||
|
basis is recorded with the reversal in the Supersession Table:
|
||||||
|
|
||||||
|
1. **The v0.8 daemon model is operationally failing** in the target environment
|
||||||
|
— R-001 ("no orca binary on any server") is a response to measured pain, not
|
||||||
|
preference.
|
||||||
|
2. **step-ca is externally mandated** (D-101) — the operator environment requires
|
||||||
|
an external CA; AD-010's "too heavyweight" rationale is no longer operative.
|
||||||
|
3. **Multi-tenancy is a hard product requirement** (R-002) — real multi-tenant
|
||||||
|
use cases cannot be served by the single-namespace layout; the
|
||||||
|
"no multi-tenancy" anti-pattern is obsolete.
|
||||||
|
4. **WASM is a hard workload requirement** (D-088) — workloads are WASM, not
|
||||||
|
processes; `os/exec` is insufficient; the "no container runtime" anti-pattern
|
||||||
|
is reversed.
|
||||||
|
5. **SSH-push is the only viable deployment target** for the operator's
|
||||||
|
bare-Linux/Proxmox environment — installing/maintaining an orca daemon on
|
||||||
|
every peer is operationally infeasible.
|
||||||
|
6. **Simplicity/vision correction** — the v0.1-v0.8 daemon model was a wrong
|
||||||
|
turn against the original CLI-first vision; the re-architecture corrects the
|
||||||
|
vision.
|
||||||
|
|
||||||
|
## Canonical references
|
||||||
|
|
||||||
|
The full PRD text was provided by the operator and adopted wholesale. The
|
||||||
|
load-bearing rules (R-001…R-016), the concept model (§4), the architecture
|
||||||
|
(§5), the milestone plan (§23), and the decision trace (§22) are reproduced
|
||||||
|
in the operator's original document. This file is the auditable pointer to
|
||||||
|
that source; the substantive planning artifacts live in:
|
||||||
|
|
||||||
|
- `IDEATION_v0.9.md` — 30 ideas (REQ-061..REQ-090), three tiers
|
||||||
|
- `GRILL_v0.9.md` — 9-axis adversarial review, 19 binding conditions, 10 phase challenges
|
||||||
|
- `REQUIREMENTS.md` — REQ-061..REQ-090 appended
|
||||||
|
- `ROADMAP.md` — v0.9 (13 phases) + v0.10 (19 phases) appended
|
||||||
|
- `PERSONAS.md` — security/network/devops reactivated
|
||||||
|
- `ARCHITECTURE.md` — v0.9 banners + Supersession Table
|
||||||
|
|
||||||
|
## The 16 load-bearing rules (invariants)
|
||||||
|
|
||||||
|
| ID | Rule |
|
||||||
|
|---|---|
|
||||||
|
| R-001 | No Orca Go binary runs on any server. The `orca` CLI on the operator's host is the only Orca software. Servers run Linux + systemd + apt-managed packages + config files written by the CLI. |
|
||||||
|
| R-002 | Filesystem paths are namespaces. `ORCA_HOME` hosts many namespaces; each is a dir with `db/`, `.env`, `.env.secrets`, `jobs/`, `alloc/`, `ns.md`. `_defaults/` always exists. No `namespace` column in SQLite. |
|
||||||
|
| R-003 | Cluster lead is always bare Linux; Proxmox can never be lead. |
|
||||||
|
| R-004 | Workload migration Linux↔Proxmox supported; runtime can change at migration; SPIFFE identity preserved. |
|
||||||
|
| R-005 | Storage replication enables migration; a Service's `count` replicas share one `runtime {}` block. |
|
||||||
|
| R-006 | mTLS on by default; cluster CA = step-ca; Traefik + `LoadCredential=` are load-bearing. |
|
||||||
|
| R-007 | Sockets by default (`/run/orca/alloc-<id>/port-<name>.sock`); `127.0.0.1` opt-in. |
|
||||||
|
| R-008 | CLI results cached locally with per-class TTLs (`orca_cache` SQLite). |
|
||||||
|
| R-009 | CLI host SPOF mitigated by external shared state in v1.x; v0.10 ships the abstractions + cache layer. |
|
||||||
|
| R-010 | Control plane updates are transactional (ArgoCD-style desired-state/lead-applier). |
|
||||||
|
| R-011 | Each namespace has `.env` (plaintext) and `.env.secrets` (AES-256-GCM, per-line nonce); master key per `ORCA_HOME` at `cluster/master.key`. |
|
||||||
|
| R-012 | Workload kinds are `Job`, `Service`, `DaemonSet`; schema-separated by `kind:` in frontmatter. |
|
||||||
|
| R-013 | Jobspec format is Markdown with YAML frontmatter (`.md` preferred); `.yaml` and `.hcl` accepted by parser dispatcher. |
|
||||||
|
| R-014 | All user-facing config is Markdown with YAML frontmatter; body preserved verbatim. |
|
||||||
|
| R-015 | Body of every `.md` config file is preserved verbatim and surfaced in `inspect`, `history`, diffs. |
|
||||||
|
| R-016 | `.env` and `.env.secrets` are exempt from R-014 — standard dotenv format retained. |
|
||||||
|
|
||||||
|
## Milestone summary (§23, reordered per grill PC-01..PC-10)
|
||||||
|
|
||||||
|
### v0.9 — Workloads + Re-architecture Foundation (13 phases)
|
||||||
|
P00 (deprecation sweep + migration-ordering + txn-design spike + test-infra bootstrap + persona reactivation + doc banners), P0a1 (path resolver + config demotion), P0a2 (namespace CRUD + inheritance), P0b (Markdown jobspec parser + fuzz), P0c (schemas + emitter interface), P01 (SSH-push transport + host-path volumes), P02 (service + Traefik emitter), P03 (update stanza), P04 (lifecycle hooks), P05 (constraints + CLI-side scheduler), P06 (task groups), P07a/P07b/P07c (process+podman / wasmtime [C-01 gated] / pve-vm+ct runtimes), P08 (sockets), P09 (Syncthing [C-02 gated]), P10 (lead rules + migration), P0X (ship + audit).
|
||||||
|
|
||||||
|
### v0.10 — Production Hardening (19 phases)
|
||||||
|
P00 (CLI cache), P01 (metrics), P01.5 (SPIFFE spike [C-08 gated]), P02 (ACL), P03 (secrets), P04 (backup/restore), P05 (drain + daemon drain-and-stop), P06 (alloc history), P07 (recovery), P08 (integration tests), P09 (collector+aggregator), P10 (transactional plane [C-09 gated]), P11 (job lint), P12 (job verify), P13 (ns subcommands), P14a/P14b/P14c (data / daemon cutover / mixed-version tolerance), P15 (README), P15.5 (threat model [C-19 gated]), P16 (final review + ship — v1.0.0 release).
|
||||||
|
|
||||||
|
See `ROADMAP.md` for the full reordered plan and `GRILL_v0.9.md` for the 19
|
||||||
|
binding conditions (C-01..C-19) and 10 phase challenges (PC-01..PC-10) that
|
||||||
|
gate specific phases.
|
||||||
@@ -36,6 +36,7 @@ Build a lightweight system to manage and execute workloads across a set of nodes
|
|||||||
| D-004 | Scheduling algorithm for v0.1? | **Single-node only (no scheduling)** | Multi-node scheduling is out of scope for v0.1. Tasks run on the node they're submitted to. | 0.90 |
|
| D-004 | Scheduling algorithm for v0.1? | **Single-node only (no scheduling)** | Multi-node scheduling is out of scope for v0.1. Tasks run on the node they're submitted to. | 0.90 |
|
||||||
| D-005 | CLI output format? | **Human-readable by default, `--json` flag for machine consumption** | Serves both humans and AI agents. | 0.95 |
|
| D-005 | CLI output format? | **Human-readable by default, `--json` flag for machine consumption** | Serves both humans and AI agents. | 0.95 |
|
||||||
| D-006 | Job/task definition format? | **HCL or YAML in `.hcl`/`.yaml` files** | Familiar to Nomad/HashiCorp users; simpler than JSON for humans. | 0.88 |
|
| D-006 | Job/task definition format? | **HCL or YAML in `.hcl`/`.yaml` files** | Familiar to Nomad/HashiCorp users; simpler than JSON for humans. | 0.88 |
|
||||||
|
| D-186 | Bash scripts coverage gate: count toward Go gate or exempt? | **Exempt from Go coverage gate; compensating control: bats tests (C-15) + shellcheck + shfmt in CI; every script must have >=1 happy-path and >=1 failure-path bats test** | Bash is a different language surface from Go; the 70%/50% Go coverage gate (D-042/D-047) is Go-specific. Forcing bash into the Go gate would require a coverage tool that does not exist for bash. The compensating control (bats + shellcheck + shfmt) provides equivalent discipline. | 0.82 |
|
||||||
| D-007 | Authentication? | **mTLS for v0.1, token-based deferred** | mTLS is the most secure default. Tokens can be added later if needed. | 0.80 |
|
| D-007 | Authentication? | **mTLS for v0.1, token-based deferred** | mTLS is the most secure default. Tokens can be added later if needed. | 0.80 |
|
||||||
| D-008 | Container runtime? | **Direct process execution (no container runtime) for v0.1** | Avoids the Docker/container dependency. Pure process management. | 0.85 |
|
| D-008 | Container runtime? | **Direct process execution (no container runtime) for v0.1** | Avoids the Docker/container dependency. Pure process management. | 0.85 |
|
||||||
| D-009 | Configuration file location? | **`~/.orca/config.hcl` and `/etc/orca/orca.hcl`** | Standard XDG-style paths. | 0.90 |
|
| D-009 | Configuration file location? | **`~/.orca/config.hcl` and `/etc/orca/orca.hcl`** | Standard XDG-style paths. | 0.90 |
|
||||||
@@ -331,3 +332,116 @@ change. Milestone type: NFR (all phases are fix/test/chore); the final
|
|||||||
phase's progressive patch IS the deliverable per `run.md` versioning
|
phase's progressive patch IS the deliverable per `run.md` versioning
|
||||||
logic. Tags run on the v0.6.x patch line: `v0.6.0` (P0) … `v0.6.5` (P05
|
logic. Tags run on the v0.6.x patch line: `v0.6.0` (P0) … `v0.6.5` (P05
|
||||||
= milestone release).
|
= milestone release).
|
||||||
|
|
||||||
|
## v0.8 Scope Summary — Coverage & Trust Hardening
|
||||||
|
|
||||||
|
v0.8 is a 3-execution-phase **NFR milestone** that continues the
|
||||||
|
hardening theme opened by v0.7. v0.7 P03 (REQ-055) lifted four
|
||||||
|
packages to ≥ 50%, but a coverage re-baseline after v0.7 ship shows
|
||||||
|
the floor was insufficient: `internal/engine` regressed to 8.3%,
|
||||||
|
`internal/proxmox` to 5.1%, and four more packages sit between 26% and
|
||||||
|
48%. Three packages (`internal/audit`, `internal/certpaths`,
|
||||||
|
`cmd/orca`) still have **no test files at all**. v0.8 also closes the
|
||||||
|
two "future enhancement" hooks explicitly deferred in v0.6 — SSH
|
||||||
|
host-key pre-pinning (D-035 caveat) and `orca node key-reset`
|
||||||
|
(RESEARCH_v0.6 §80) — and adds a requirements-hygiene gate so the
|
||||||
|
stale-REQ-status drift seen in REQUIREMENTS.md after v0.7 ship cannot
|
||||||
|
recur:
|
||||||
|
|
||||||
|
- **P01 — Coverage uplift round 2.** Raise six under-50% packages to
|
||||||
|
≥ 70% and add first tests for the three zero-test packages. Covers
|
||||||
|
REQ-057.
|
||||||
|
- **P02 — SSH trust hardening.** `--host-key-fingerprint` pre-pin flag
|
||||||
|
on `orca node join --type proxmox` + `orca node key-reset <node>`
|
||||||
|
command. Covers REQ-058, REQ-059.
|
||||||
|
- **P03 — Requirements-hygiene gate.** `make verify-reqs` target +
|
||||||
|
verify-stage assertion that ROADMAP `Complete` ↔ REQUIREMENTS
|
||||||
|
`Complete`. Covers REQ-060.
|
||||||
|
- **P04 — Final review + ship + audit.** Milestone release.
|
||||||
|
|
||||||
|
The vision is unchanged. v0.8 is a hardening milestone, not a
|
||||||
|
direction change. Milestone type: NFR (all phases are test/feat-chore
|
||||||
|
on the trust surface — see CLARIFY D-043 for the `feat` vs `chore`
|
||||||
|
classification of P02); the final phase's progressive patch IS the
|
||||||
|
deliverable per `run.md` versioning logic. Tags run on the **v0.7.x**
|
||||||
|
patch line: `v0.7.0` (P0) … `v0.7.4` (P04 = milestone release).
|
||||||
|
|
||||||
|
## v0.8 Clarified Decisions (D-series, full autonomy)
|
||||||
|
|
||||||
|
The 5 v0.8 decisions (D-043..D-047) were auto-resolved at full autonomy
|
||||||
|
within the `clarify_budget` (10):
|
||||||
|
|
||||||
|
| ID | Question | Decision | Rationale | Confidence |
|
||||||
|
|----|----------|----------|-----------|------------|
|
||||||
|
| D-043 | Is P02 (SSH trust hardening) a `feat` phase or a `chore` phase? It adds a new flag + a new subcommand. | **`chore` (trust-surface hardening), not `feat`** | Both `--host-key-fingerprint` and `orca node key-reset` refine the *existing* `orca node join --type proxmox` flow and the existing TOFU `known_hosts` store (D-035). No new orchestration capability, no new node kind, no new API. They close a security gap explicitly deferred in v0.6, not open new surface area. Per `run.md` versioning logic this keeps v0.8 NFR (all phases fix/test/chore/perf/refactor). | 0.84 |
|
||||||
|
| D-044 | Where does `--host-key-fingerprint` live — on `orca node join` or only on `--type proxmox`? | **On `orca node join` (root of the join subcommand), validated when `--type proxmox`** | The flag is generic (any future SSH-joined node kind will use it); gating it to `--type proxmox` only would require re-adding it later. Validation (`flag requires --type proxmox today`) happens in `RunE`, not in the flag declaration, so the flag is declared once on `node join` and the type check emits a clear error for non-proxmox types until other SSH-joined kinds exist. | 0.86 |
|
||||||
|
| D-045 | `--host-key-fingerprint` format — raw hex, `sha256:`-prefixed, or OpenSSH `SHA256:base64`? | **OpenSSH `SHA256:base64` (the format `ssh-keyscan -E sha256 -D -` emits and operators expect)** | Matches the fingerprint format operators already see from `ssh-keyscan` and `orca node join`'s own `Result.HostKeyFingerprint` output. Accept only `SHA256:`-prefixed base64; reject raw hex with a clear error. Internally decode base64 → compare against `ssh.PublicKey` Marshal + sha256. | 0.88 |
|
||||||
|
| D-046 | Does `orca node key-reset <node>` also revoke the orca pubkey on the remote host, or only clear the local `known_hosts` entry? | **Local `known_hosts` entry only** | Revoking the remote authorized_keys entry would orphan a working node (next dispatch would fail auth). `key-reset` is the local "forget this host's key" operation (mirrors `ssh-keygen -R host`); re-establishing trust is a separate `orca node join` re-run. Audit-log the reset with `actor`, `node`, `event=node.key_reset`. | 0.90 |
|
||||||
|
| D-047 | Coverage target for P01 — 70% floor or higher? | **70% floor for the 6 under-50% packages; 50% floor for the 3 zero-test packages (`internal/audit`, `internal/certpaths`, `cmd/orca`) as a first-toe-hold** | 70% across the board for the already-tested packages matches D-042's "70% target for new packages" and is achievable without heroic mock effort. For the zero-test packages, going 0→50% is the realistic single-phase step (0→70% risks a coverage rathole on `cmd/orca` which is glue code); a future milestone can lift them to 70%. | 0.82 |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
# v0.9/v0.10 — Re-architecture Scope Summary (Supersedes v0.1–v0.8 architecture)
|
||||||
|
|
||||||
|
v0.9 is the first DIRECTION-CHANGE milestone in the project's history.
|
||||||
|
It supersedes the shipped v0.1–v0.8 architecture per the adopted PRD
|
||||||
|
(`.ciagent/PRD_v0.9.md`). The re-architecture deprecates the daemon/
|
||||||
|
transport/internal-CA/HCL/single-namespace stack and builds a CLI-only/
|
||||||
|
SSH-push/step-ca/Markdown-frontmatter/multi-namespace stack plus 8
|
||||||
|
net-new subsystems.
|
||||||
|
|
||||||
|
## Override Justification (Re-architecture Justification axis)
|
||||||
|
|
||||||
|
The ci-griller returned REPLAN (0.70) on the Re-architecture Justification
|
||||||
|
axis, noting the PRD reverses 6 documented decisions without new evidence
|
||||||
|
and that the incremental-additive path was not evaluated. The user reviewed
|
||||||
|
the fork and overrode the *direction* with a six-part evidence basis. The
|
||||||
|
override is recorded verbatim below; each part addresses a reversal that
|
||||||
|
the grill flagged as unjustified.
|
||||||
|
|
||||||
|
1. **The v0.8 daemon model is operationally failing** in the target
|
||||||
|
environment — R-001 ("no orca binary on any server") is a response to
|
||||||
|
measured pain, not preference.
|
||||||
|
2. **step-ca is externally mandated** (D-101) — the operator environment
|
||||||
|
requires an external CA; AD-010's "too heavyweight" rationale is no
|
||||||
|
longer operative.
|
||||||
|
3. **Multi-tenancy is a hard product requirement** (R-002) — real
|
||||||
|
multi-tenant use cases cannot be served by the single-namespace layout;
|
||||||
|
the "no multi-tenancy" anti-pattern is obsolete.
|
||||||
|
4. **WASM is a hard workload requirement** (D-088) — workloads are WASM, not
|
||||||
|
processes; `os/exec` is insufficient; the "no container runtime"
|
||||||
|
anti-pattern is reversed.
|
||||||
|
5. **SSH-push is the only viable deployment target** for the operator's
|
||||||
|
bare-Linux/Proxmox environment — installing/maintaining an orca daemon
|
||||||
|
on every peer is operationally infeasible.
|
||||||
|
6. **Simplicity/vision correction** — the v0.1-v0.8 daemon model was a
|
||||||
|
wrong turn against the original CLI-first vision; the re-architecture
|
||||||
|
corrects the vision.
|
||||||
|
|
||||||
|
## Supersession Table (AD-series reversals, recorded per grill PC-09)
|
||||||
|
|
||||||
|
| Old decision | Was | Superseded by | Evidence basis |
|
||||||
|
|---|---|---|---|
|
||||||
|
| AD-010 (ARCHITECTURE.md:463) | step-ca/cfssl/vault-pki "too heavyweight" | **D-101** (step-ca) | Override ground 2 (external mandate) |
|
||||||
|
| SPIFFE rejection (PROJECT.md:94) | internal CA chosen over SPIFFE | **D-068** (SPIFFE SVIDs) | Override ground 3 (multi-tenancy requires per-workload identity) |
|
||||||
|
| No-container-runtime (ARCHITECTURE.md:477) | explicit anti-pattern | **D-088** (5 runtimes; wasmtime primary) | Override ground 4 (WASM is the workload profile) |
|
||||||
|
| No-multi-tenancy (ARCHITECTURE.md:478) | explicit anti-pattern | **D-158 / R-002** (many namespaces under ORCA_HOME) | Override ground 3 (hard multi-tenant product req) |
|
||||||
|
| AD-007 (HCL canonical) | HCL for jobspec | **R-013 / R-014** (Markdown canonical; HCL legacy) | PRD §8 (Markdown + body preservation is the operator-facing format) |
|
||||||
|
| Daemon-on-every-node | `orca daemon` on all peers | **R-001** (no orca binary on any server) | Override grounds 1 + 5 (daemon failing; SSH-push only viable target) |
|
||||||
|
|
||||||
|
The 19 binding conditions (C-01..C-19) and 10 phase challenges
|
||||||
|
(PC-01..PC-10) from `GRILL_v0.9.md` are adopted as execution gates.
|
||||||
|
The 30 net-new requirements (REQ-061..REQ-090) from `IDEATION_v0.9.md`
|
||||||
|
are recorded in `REQUIREMENTS.md`. The reordered phase plan is in
|
||||||
|
`ROADMAP.md`.
|
||||||
|
|
||||||
|
## v0.9 Clarified Decisions (D-series, full autonomy — Phase 0 pre-execution)
|
||||||
|
|
||||||
|
| ID | Question | Decision | Rationale | Confidence |
|
||||||
|
|----|----------|----------|-----------|------------|
|
||||||
|
| D-101 | Cluster CA: internal Go CA (AD-010) or step-ca (external)? | **step-ca (apt-installed)** | Externally mandated per override ground 2; AD-010's "too heavyweight" rationale reversed. CLI wraps `step` CLI via SSH (no Go step-ca client library — keep zero-new-dep posture if possible, or add `github.com/smallstep/cli` as a dep). **Gated by C-07** (CA migration spec). | 0.74 |
|
||||||
|
| D-068 | Workload identity: internal X.509 CA or SPIFFE SVIDs? | **SPIFFE SVIDs minted at submit time via step-ca** | Multi-tenancy (override ground 3) requires per-workload identity model; SPIFFE is the standard. SPIFFE ID `spiffe://orca/ns/<ns>/job/<name>/alloc/<id>` as SAN. **Gated by C-08** (mint spike in v0.10-P01.5; fallback to mTLS identity if spike fails). | 0.72 |
|
||||||
|
| D-088 | Runtime: direct os/exec only (D-008) or multi-runtime? | **5 runtimes: wasm (wasmtime primary), podman, process, pve-vm, pve-ct** | WASM is the primary workload (override ground 4). `processRuntime` wraps existing `executor.go`; others are net-new. Split P07a/b/c per grill PC-10. **P07b gated by C-01** (wasmtime/CGO eval). | 0.82 |
|
||||||
|
| D-158 | Namespace model: single flat root or multi-namespace? | **Multi-namespace under ORCA_HOME (R-002)** | Hard multi-tenant product requirement (override ground 3). `_defaults/` implicit root; `cluster/` for cluster-wide; per-namespace `db/`, `.env`, `.env.secrets`, `jobs/`, `alloc/`, `ns.md`. No namespace column in SQLite. | 0.84 |
|
||||||
|
| D-179 | Jobspec format: HCL canonical (AD-007) or Markdown? | **Markdown with YAML frontmatter canonical (R-013); HCL legacy** | PRD §8 — Markdown + body preservation is the operator-facing format. HCL adapter (REQ-064) preserves `orca job run old-spec.hcl` during migration. | 0.85 |
|
||||||
|
| D-185 | Re-architecture justification: incremental additive or full re-architecture? | **Full re-architecture (overridden by user)** | Six-part evidence basis above; the grill's REPLAN mechanics (PC-01..PC-10, C-01..C-19) adopted as gates. The incremental-additive path was evaluated and rejected on grounds 1 + 5 (daemon failing; SSH-push only viable). | 0.88 |
|
||||||
|
|||||||
@@ -128,6 +128,57 @@ REQ-047..052 all complete.
|
|||||||
| ID | Requirement | Priority | Phase | Status |
|
| ID | Requirement | Priority | Phase | Status |
|
||||||
|----|-------------|----------|-------|--------|
|
|----|-------------|----------|-------|--------|
|
||||||
| REQ-053 | `orca cert` command tree registered on root command (`cert ca-init`, `cert gen`, `cert show`, `cert renew`, `cert fingerprint`) — code exists in `internal/cli/cert.go` but is never AddCommand'd; unreachable today | High | **v0.7 P1** | **Complete** (P1 shipped v0.6.1) |
|
| REQ-053 | `orca cert` command tree registered on root command (`cert ca-init`, `cert gen`, `cert show`, `cert renew`, `cert fingerprint`) — code exists in `internal/cli/cert.go` but is never AddCommand'd; unreachable today | High | **v0.7 P1** | **Complete** (P1 shipped v0.6.1) |
|
||||||
| REQ-054 | HCL config file parsing: `internal/config` package loads `~/.orca/config.hcl` / `/etc/orca/orca.hcl` (keys: db_path, listen_addr, ca_path, server_cert_path, server_key_path, node_capacity); merge precedence flag > env > file > default; `--config` flag on root command | High | **v0.7 P2** | Pending |
|
| REQ-054 | HCL config file parsing: `internal/config` package loads `~/.orca/config.hcl` / `/etc/orca/orca.hcl` (keys: db_path, listen_addr, ca_path, server_cert_path, server_key_path, node_capacity); merge precedence flag > env > file > default; `--config` flag on root command | High | **v0.7 P2** | **Complete** (P2 shipped v0.6.2) |
|
||||||
| REQ-055 | Test coverage uplift: every package ≥ 50% — adds tests for `internal/engine` (executor, dispatcher, peer), `internal/transport` (mtls, dispatch, handshake_log), `internal/proxmox` (bootstrap SSH path), `internal/audit` | Medium | **v0.7 P3** | Pending |
|
| REQ-055 | Test coverage uplift: every package ≥ 50% — adds tests for `internal/engine` (executor, dispatcher, peer), `internal/transport` (mtls, dispatch, handshake_log), `internal/proxmox` (bootstrap SSH path), `internal/audit` | Medium | **v0.7 P3** | **Complete** (P3 shipped v0.6.3) |
|
||||||
| REQ-056 | `--pprof <addr>` opt-in flag on `orca daemon` (default disabled); `net/http/pprof` mounted on a separate mux, never on the mTLS daemon listener | Low | **v0.7 P4** | Pending |
|
| REQ-056 | `--pprof <addr>` opt-in flag on `orca daemon` (default disabled); `net/http/pprof` mounted on a separate mux, never on the mTLS daemon listener | Low | **v0.7 P4** | **Complete** (P4 shipped v0.6.4) |
|
||||||
|
|
||||||
|
## v0.8 Requirements — Coverage & Trust Hardening
|
||||||
|
|
||||||
|
| ID | Requirement | Priority | Phase | Status |
|
||||||
|
|----|-------------|----------|-------|--------|
|
||||||
|
| REQ-057 | Test coverage uplift round 2: raise `internal/engine` (8.3%), `internal/proxmox` (5.1%), `internal/cli` (27.6%), `internal/transport` (26.3%), `internal/store` (46.7%), `internal/jobspec` (47.6%) to ≥ 70%; add first tests for `internal/audit`, `internal/certpaths`, `cmd/orca` (currently 0%) to ≥ 50% (D-047 tiered floor) | High | **v0.8 P1** | **Complete** (P1 shipped v0.7.1; all 9 packages exceeded floor) |
|
||||||
|
| REQ-058 | `--host-key-fingerprint <SHA256:base64>` pre-pin flag on `orca node join` (validated when `--type proxmox`): when supplied, join fails fast if the SSH host key's OpenSSH SHA-256 fingerprint does not match; supersedes TOFU (D-035) for pre-pinned deployments (D-044, D-045) | Medium | **v0.8 P2** | **Complete** (P2 shipped v0.7.2) |
|
||||||
|
| REQ-059 | `orca node key-reset <node>` command: clears the persisted SSH host key entry for the node from `~/.orca/known_hosts` only (local, not remote authorized_keys — D-046); audit-logs `event=node.key_reset`; next `doctor proxmox`/dispatch re-pins via TOFU or `--host-key-fingerprint` | Low | **v0.8 P2** | **Complete** (P2 shipped v0.7.2) |
|
||||||
|
| REQ-060 | Requirement-status hygiene sweep: REQUIREMENTS.md v0.7 rows were stale ("Pending" after ship); add a verify-stage assertion that every REQ listed as `Complete` in ROADMAP.md has a matching `Complete` row in REQUIREMENTS.md, enforced by `make verify-reqs` | Medium | **v0.8 P3** | **Complete** (P3 shipped v0.7.3) |
|
||||||
|
|
||||||
|
## v0.9/v0.10 Requirements — Re-architecture Foundation & Production Hardening
|
||||||
|
|
||||||
|
The v0.9/v0.10 milestones supersede the shipped v0.1–v0.8 architecture per the
|
||||||
|
adopted PRD (`.ciagent/PRD_v0.9.md`). The re-architecture is justified on six
|
||||||
|
grounds recorded in the PROJECT.md Supersession Table. 30 net-new requirements
|
||||||
|
(REQ-061..REQ-090) derive from the v0.9 IDEATION; their phase placement and
|
||||||
|
binding grill conditions (C-01..C-19) are documented in `IDEATION_v0.9.md`
|
||||||
|
and `GRILL_v0.9.md`.
|
||||||
|
|
||||||
|
| ID | Requirement | Priority | Phase | Status |
|
||||||
|
|----|-------------|----------|-------|--------|
|
||||||
|
| REQ-061 | `orca daemon` deprecation command and build-tag removal path: v0.9 emits deprecation warning + still runs (dual-write window); v1.0 repurposes to `orca daemon drain-and-stop` (stops v0.8 daemons on peers via SSH, confirms workloads survive via systemd); post-v1.0 the command and `internal/daemon/` are deleted. `// Deprecated` Go doc comments + `slog.Warn` on every run (I-M-001) | High | **v0.10 P14** (warn v0.9 P0X) | Pending |
|
||||||
|
| REQ-062 | Coverage follow-ups: 3 zero-test packages (`internal/audit`, `internal/certpaths`, `cmd/orca`) + `internal/cli` to 70% floor; once `daemon.go` is deprecated/removed the exclusion reason disappears and the floor applies to the whole package; all net-new subsystems carry a 70% floor from their first phase (I-M-002) | Medium | **v0.9 P0X** + each new pkg | Pending |
|
||||||
|
| REQ-063 | `known_hosts` flock concurrency gap (deferred P1 from REVIEW_v0.8 A2): add `flock`-style advisory lock (stdlib `syscall.Flock` wrapper) around the read-modify-write in `TOFUHostKeyCallback` capture path (`bootstrap.go:290-302`) and `ResetHostKey` (`bootstrap.go:479-523`); lock file at `cluster/known_hosts.lock` (R-002) (I-M-003) | Medium | **v0.9 P0a1** | Pending |
|
||||||
|
| REQ-064 | HCL→Markdown jobspec adapter/bridge layer: keep `internal/jobspec/spec.go` as legacy HCL path behind `// Deprecated`; add `internal/jobspec/markdown.go` (canonical) + `internal/jobspec/dispatch.go` (extension-based dispatcher: `.md`→Markdown, `.hcl`→legacy, `.yaml`→Markdown-with-empty-body); unified `*WorkloadSpec` populated via adapter; preserves `orca job run old-spec.hcl` during migration window (I-M-004) | High | **v0.9 P0b** | Pending |
|
||||||
|
| REQ-065 | `orca doctor --legacy-paths` detection: detects v0.8 residue (orca.db at ORCA_HOME root, ca.crt/ca.key, config.hcl, flat server.crt, namespace column in any *.db); outputs list of legacy artifacts with migration recommendations; the detection half of v0.10-P14 (I-M-005) | Medium | **v0.10 P14c** | Pending |
|
||||||
|
| REQ-066 | Legacy CA state migration to step-ca: `orca upgrade --to-v1.0 --import-ca` reads `~/.orca/ca.key`, initializes step-ca with it, re-issues workload SVIDs; preserves audit history even if live trust root changes (I-M-006). **Gated by C-07** | High | **v0.10 P14a** | Pending |
|
||||||
|
| REQ-067 | Fuzz test harness for Markdown frontmatter parser: `testing.F` fuzz target in `internal/jobspec/markdown_test.go` round-trips random frontmatter+body through `ParseMarkdown` asserting byte-exact body preservation; corpus of adversarial fixtures (CRLF, BOM, no-frontmatter, empty-frontmatter, frontmatter-with-only-separator) (I-M-007) | Medium | **v0.9 P0b** | Pending |
|
||||||
|
| REQ-068 | Deprecation warnings on removed/repurposed CLI subcommands: each removed/changed command (`orca cert`, `orca node join` mTLS semantics, `orca job run <spec.hcl>`) emits `slog.Warn` deprecation banner with v1.0 replacement except under `orca upgrade`; `--no-deprecation-warnings` global flag via `root.go` `PersistentPreRunE` (I-M-008) | Low | **v0.9 P0X** + v0.10 P13 | Pending |
|
||||||
|
| REQ-069 | `internal/config/config.go` HCL config demotion via adapter: keep `internal/config/` as `legacy_config.go` with `// Deprecated`; add `internal/config/markdown.go` for new Markdown-frontmatter loader (R-014); `root.go` dispatches on file extension (`.hcl`→legacy, `.md`→new); `--config` semantics: `.hcl` read-only legacy, `.md` canonical (I-M-009) | High | **v0.9 P0a1** | Pending |
|
||||||
|
| REQ-070 | `internal/certpaths/` replacement with multi-namespace path resolver: new `internal/paths` package with `paths.NamespaceDir(ns)`, `paths.ClusterDir()`, `paths.CacheDB()`, `paths.MasterKey()`, `paths.NSDb(ns)`, `paths.NSEnv(ns)`, `paths.NSSecrets(ns)`; keep `certpaths` as thin shim for v0.8 compat then remove post-v1.0 (R-002) (I-M-010) — highest blast radius | High | **v0.9 P0a1** | Pending |
|
||||||
|
| REQ-071 | `internal/store/` schema: per-namespace DBs, drop namespace column: `store.Open` gains namespace parameter (or caller passes `paths.NSDb(ns)`); `migrate.go` runs migrations per namespace DB; `cert_repo` (0004) removed (step-ca handles certs); audit_log moves to CLI-side cache DB (R-008) (I-M-011) | High | **v0.9 P0a1** + v0.10 P06 | Pending |
|
||||||
|
| REQ-072 | `internal/transport/` deletion + SSH-push package: delete `mtls.go`, `dispatch.go`, `handshake_log.go`; extract retry/idempotency patterns into `internal/sshpush/`; existing `transport.IdempotencyStore` directly reusable (I-M-012). Deletion deferred to v0.10-P14 to keep dual-write window open | High | **v0.9 P00** (delete v0.10 P14) | Pending |
|
||||||
|
| REQ-073 | SSH-push transport layer design: connection pooling (reuse `*ssh.Client` per peer), idempotency (content-addressed filenames), retry (exponential backoff 100ms×2 cap 5s max 5), timeout (30s SCP, 10s exec), fan-out (errgroup bounded concurrency default 8), known_hosts reuse `proxmox.TOFUHostKeyCallback` (I-B-001) | High | **v0.9 P01** (design P0a1) | Pending |
|
||||||
|
| REQ-074 | Emitter template system (Layer 4): `internal/emitter/` package with `Emitter` interface `Render(spec *WorkloadSpec, node *Node) ([]File, error)`; implementations systemdEmitter/traefikEmitter/syncthingEmitter/socketEmitter; SSH-push SCPs `[]File` atomically (write-to-tmp + rename); emitters registered per kind + runtime (I-B-002) | High | **v0.9 P0c** | Pending |
|
||||||
|
| REQ-075 | Lead applier execution model: CLI renders transaction bundle (tarball + apply.sh + verify.sh) on operator host, SCPs to lead's `/run/orca/txns/<txn-id>/`, lead's systemd timer runs `apply.sh` idempotently, CLI polls txn status via SSH; bash scripts generated by emitter not hand-written (I-B-003). **Gated by C-09** | High | **v0.10 P10** (design v0.9 P00) | Pending |
|
||||||
|
| REQ-076 | step-ca integration: `orca init` runs `step ca init` on lead; CLI SSHs to lead, installs step-ca via apt, stores step-ca.json; workload SVIDs via `step ca token` (JWE minted by CLI) → `step ca certificate`; SPIFFE ID as SAN; new `internal/stepca/` package wraps `step` CLI via SSH (I-B-004). Reverses AD-010 per override justification ground 2 | High | **v0.9 P07** + v0.10 P02 | Pending |
|
||||||
|
| REQ-077 | Traefik dynamic config generation + atomic reload: Traefik emitter renders `/etc/traefik/dynamic/orca-<ns>-<svc>.yaml` with backends (socket paths R-007), health checks, mTLS config pointing at step-ca root; atomic reload via tmpfile+fsync+rename triggering fsnotify; drain writes `weight=0` or removes backend (I-B-005). **Gated by C-10** | High | **v0.9 P02** | Pending |
|
||||||
|
| REQ-078 | Runtime abstraction interface (5 backends): `Runtime` interface in `internal/runtime/` with Prepare/Start/Stop/Status; processRuntime (wraps existing executor.go), wasmRuntime (wasmtime via SSH), podmanRuntime, pveVMRuntime (qm via proxmox SSH), pveCTRuntime (pct); runtimeRegistry keyed by `runtime:` frontmatter value; Alloc carries runtime field changeable on migration (I-B-006). Split P07a/b/c per PC-10. **P07b gated by C-01** | High | **v0.9 P07a/b/c** | Pending |
|
||||||
|
| REQ-079 | Transaction bundle format + N-peer atomicity: bundle = tarball with desired-state.json + apply.sh + verify.sh + rollback.sh + manifest.sig (signed with master.key); content-addressed `<txn-id>=sha256(desired-state.json)` stored in `cluster/txns/<txn-id>/`; lead applies to self first then fans out; failure on any peer runs rollback.sh on applied peers (I-B-007). **Gated by C-09** | High | **v0.10 P10** (design v0.9 P00) | Pending |
|
||||||
|
| REQ-080 | Master key management + HKDF-SHA256 per-line .env.secrets encryption: `cluster/master.key` 32-byte random (generated at `orca init` using WriteAtomic pattern); each line `base64(nonce||ciphertext||tag)`, nonce=random(12 bytes), AES-256-GCM with AAD=line-number (prevents line-swap); HKDF-SHA256 derives per-namespace sub-keys; `orca secrets set/get`; v0.8 `internal/security/redact.go` reusable (I-B-008). **Gated by C-19** | High | **v0.10 P03** | Pending |
|
||||||
|
| REQ-081 | Syncthing config rendering + folder-ID content-addressing: per-namespace Syncthing folder `orca-<ns>` with content-addressed folder ID `sha256(ns + master-key-fingerprint)`; CLI renders config.xml per peer; Syncthing runs as systemd unit (emitted by systemd emitter); CLI discovers peers via `cluster/peers/`; migration works because new node joins folder and syncs before workload starts (I-B-009). **Gated by C-02 + C-14** | Medium | **v0.9 P09** (spike v0.9 P00) | Pending |
|
||||||
|
| REQ-082 | Namespace inheritance resolver algorithm: DFS parent walker with visited set for cycle detection; `_defaults/` implicit root (always exists, no parent); merge semantics: child overrides parent for scalars, arrays unioned (child adds to parent); pure function (no I/O) taking `map[nsName→*NSConfig]` returning `map[nsName→*ResolvedNS]` (I-B-010) | High | **v0.9 P0a2** | Pending |
|
||||||
|
| REQ-083 | CLI-side scheduler redesign: `Score(node, workload) (score int, fits bool)` where `fits` checks runtime compatibility + constraints, `score` is bin-packing (most free capacity = highest); Services pick `count` distinct nodes (anti-affinity default); DaemonSets pick all matching nodes; Job = one-shot; CLI-side not daemon-side (R-001) (I-B-011) | High | **v0.9 P05** (skeleton P0c) | Pending |
|
||||||
|
| REQ-084 | `orca job lint` category-driven lint engine: `Linter` runs `Rule` checks returning `Finding{Category, Severity, Message, Explanation}`; categories schema/runtime/security/migration/best-practice; `--explain` prints rationale; pure (no I/O) checks against static rules (I-B-012) | Medium | **v0.10 P11** | Pending |
|
||||||
|
| REQ-085 | v0.8→v1.0 migration ordering: v0.9 ships new parser + kinds + runtime + SSH-push alongside old daemon (dual-write window); `orca job run` dispatches on extension (`.md`→SSH-push, `.hcl`→old daemon); v0.10-P05 drains old daemons; v0.10-P14 converts remaining `.hcl` specs and removes daemon (I-C-001). **Most important cross-cutting idea** | High | **v0.9 P00** → v0.10 P14 | Pending |
|
||||||
|
| REQ-086 | "No orca on server" enforcement: `orca doctor no-orca-on-server` SSHs to each peer verifying no `orca` binary in PATH, no `orca` systemd service, no `orca` process, no `/etc/orca/` directory; runs after v0.10-P05 before v0.10-P16; reuses v0.8 `proxmox` SSH session infrastructure (I-C-002). Implements grill C-13 | High | **v0.10 P14c** | Pending |
|
||||||
|
| REQ-087 | Test infrastructure: hermetic 3-linux + 1-proxmox cluster pipeline: `test/integration/` with docker-compose/vagrant creating 4 containers/VMs; Go test harness SSHes to each, runs CLI, asserts end-to-end workflows (ns create → workload submit → migrate → drain); proxmox simulated via mock pct/qm; v0.8 e2e tests (bootstrapE2ESetup) are foundation (I-C-003) | Medium | **v0.10 P08** (bootstrap v0.9 P00) | Pending |
|
||||||
|
| REQ-088 | Security-engineer + network-engineer persona reactivation: reactivate security-engineer (step-ca provisioner model, SSH-push blast radius, Traefik edge, .env.secrets crypto) and network-engineer (socket exposure R-007, Syncthing P2P ports, Traefik routing); cross-cutting review not single phase (I-C-004). Implements grill C-05 | High | **v0.9 P00** → v0.10 P16 | Pending |
|
||||||
|
| REQ-089 | Documentation rewrite: ARCHITECTURE.md/PROJECT.md/README + AD-010 supersession: v0.9-P00 adds "v0.9 Architecture (Supersedes v0.8)" section + banners + Superseded Decisions table; v0.10-P15 rewrites README quickstart for new curl|sh + orca init + orca ns create flow (I-C-005) | Medium | **v0.9 P00** + v0.10 P15/P16 | Pending |
|
||||||
|
| REQ-090 | Dual-write window: v0.9 `orca job run` dispatches on extension (`.md`→SSH-push new path, `.hcl`→old daemon path) via parser dispatcher (REQ-064); daemon not removed until v0.10-P05; SSH-push path writes to separate systemd unit namespace (`orca-v1-<alloc>.service`) while daemon uses `orca-<job>.service` — no unit name overlap = no conflict (I-C-006) | High | **v0.9 P00** | Pending |
|
||||||
|
|||||||
@@ -0,0 +1,285 @@
|
|||||||
|
# Research: Orca v0.8 — Coverage & Trust Hardening
|
||||||
|
|
||||||
|
Findings grounded in codebase analysis (44 source/test files read, coverage
|
||||||
|
re-measured for all 9 target packages) + `golang.org/x/crypto` v0.54.0 API
|
||||||
|
verification (`ssh.FingerprintSHA256`, `knownhosts.Line`/`Normalize`/`KeyError`).
|
||||||
|
|
||||||
|
## 1. Coverage analysis (P01 — REQ-057)
|
||||||
|
|
||||||
|
### 1.1 Re-measured coverage (confirmed via `go test ./<pkg>/... -cover`)
|
||||||
|
|
||||||
|
| Package | Coverage | Tier (D-047) | Notes |
|
||||||
|
|---------|----------|--------------|-------|
|
||||||
|
| `internal/engine` | **8.3%** | ≥ 70% floor | Only `scheduler_test.go` (4 tests, 66 LOC); executor/dispatcher/peer/registry/audit untested |
|
||||||
|
| `internal/proxmox` | **5.1%** | ≥ 70% floor | Only `bootstrap_test.go` (4 tests, validation + sudoersContent string asserts); SSH dial path untested |
|
||||||
|
| `internal/cli` | **27.6%** | ≥ 70% floor | 5 test files (root, init, namespace, osdetect, watch); node/job/cert/doctor/audit/cmds untested |
|
||||||
|
| `internal/transport` | **26.3%** | ≥ 70% floor | Only `idempotency_test.go` (7 tests); mtls/dispatch/retry/handshake_log untested |
|
||||||
|
| `internal/store` | **47.2%** | ≥ 70% floor | node_repo + job_task + capacity + audit + migrate tested; **cert_repo has NO test** (REQ-053 leftover — v0.7 P01 was supposed to add it but it's missing) |
|
||||||
|
| `internal/jobspec` | **47.6%** | ≥ 70% floor | Only `spec_test.go` (4 tests); `Validate()`, `ParseFile` (file I/O), edge cases untested |
|
||||||
|
| `internal/audit` | **0%** (no test files) | ≥ 50% toe-hold | `go: no such tool "covdata"` is a known tooling gap, NOT a real number — the package simply has no `_test.go` |
|
||||||
|
| `internal/certpaths` | **0%** (no test files) | ≥ 50% toe-hold | Same `covdata` tooling gap; no `_test.go` exists |
|
||||||
|
| `cmd/orca` | **0%** (no test files) | ≥ 50% toe-hold | Same; `main.go` is 15 LOC of glue (`cli.Execute()` + error print) |
|
||||||
|
|
||||||
|
**Coverage-floor achievability assessment (per package):**
|
||||||
|
|
||||||
|
- **engine → 70% REALISTIC.** The package has clean seams: `LocalExecutor` interface (dispatcher.go:39), `PeerRegistry` is in-memory with `Add`/`Remove`/`All`/`Get` (peer.go), `Executor.Submit/Status` take a `*store.JobRepo`+`*store.TaskRepo` which can be backed by `:memory:`/temp-file sqlite via the existing `openTestDB` helper (node_repo_test.go:12). The `sshDialer` seam pattern (proxmox) has an analogue here: `transport.NewDispatchClient` is called inside `dispatchToPeer` (dispatcher.go:158) — to test dispatch-to-peer without a real mTLS server, either (a) inject a fake `DispatchClient` via a new interface seam, or (b) use `httptest.NewTLSServer` with a self-signed CA. Option (a) is lower-effort and aligns with the `LocalExecutor` pattern. Recommendation: extract a `peerDispatcher` interface (`Submit(ctx, spec, key) (*SubmitResponse, error)`) and inject it, OR test via `LocalSubmit`/`LocalStatus` paths (which only need a stubbed `LocalExecutor`) — the latter covers ~60% of dispatcher.go without a new seam. **Flag: 70% may require a small refactor to inject the dispatch client; 60-65% is achievable without one. Plan should decide whether to add the seam or accept 65%.**
|
||||||
|
- **proxmox → 70% REALISTIC.** The `sshDialer` seam already exists (bootstrap.go:201-213, `sshDialerType` interface + `defaultSSHDialer` struct, overridable package-level var). A fake SSH dialer returning a mock `*ssh.Client` is the path. **However:** `*ssh.Client.NewSession()` + `session.CombinedOutput()` are concrete methods on the real `*ssh.Client` — there's no `sshSession` interface seam. To test `runRemote`/`deployPubKey`/`createLinuxUser`/`createPVERole`/etc. without a real SSH server, EITHER (a) introduce a `sessionRunner` interface seam (small refactor), OR (b) use `httptest.NewTLSServer` is wrong (it's SSH not HTTP) — instead use a real in-process SSH server via `golang.org/x/crypto/ssh` `NewServerConn` (more code but no new dep). **Flag: 70% likely requires either a `sessionRunner` interface refactor OR an in-process SSH server fixture. 50-55% is achievable with just the existing `sshDialer` seam + testing validation paths + `sudoersContent` string asserts (already done). Plan should add the `sessionRunner` seam — it's a 1-interface, ~10-LOC change that unlocks the bulk of the package.**
|
||||||
|
- **cli → 70% AMBITIOUS but realistic.** The package is the largest (17 source files, ~2000 LOC). The existing tests use `rootCmd.SetArgs()` + `rootCmd.Execute()` + `t.TempDir()` + `ORCA_HOME` env (namespace_test.go:46-53 — `TestInitHonorsORCAHOME` is the template). The untested commands are `node join/leave/list`, `job run/list/stop/logs`, `cert *`, `doctor *`, `audit list`, `status`, `version`, `daemon`. Many touch the DB + certpaths + (for `node join --type proxmox`) the SSH dialer. **Strategy:** table-driven `rootCmd.Execute()` against a temp `ORCA_HOME` for each subcommand; mock the proxmox path via the existing `sshDialer` seam; capture stdout via `rootCmd.SetOut(&buf)`. **Flag: 70% across the whole package is a lot of test code; 55-65% is more realistic for one phase. The `daemon` command (background server) is hard to test without a lifecycle harness — recommend excluding it from the 70% target and documenting why.**
|
||||||
|
- **transport → 70% REALISTIC.** `httptest.NewTLSServer` is the standard seam (already used in `internal/daemon/dispatch_test.go:59` and `server_test.go`). The `Dispatcher` interface (dispatch.go:49) is already mockable (`stubDispatcher` in dispatch_test.go:24 is the template). `MTLSClient.Do` wraps `http.Client.Do` — testable via `httptest.NewTLSServer` with a CA + client cert. `retry.go` `Do[T]` is generic + already partly tested via `idempotency_test.go` (TestRetrySucceedsAfterTransient etc.) — extend with backoff-timing asserts. `handshake_log.go` is pure slog calls — trivial to test by capturing into a `slog.Handler`. **No new seams needed; 70% achievable.**
|
||||||
|
- **store → 70% REALISTIC.** The existing `openTestDB` helper (node_repo_test.go:12) + `withFastWatch` (job_task_repo_test.go:36) are reusable. **Critical gap:** `cert_repo.go` has NO test file despite v0.7 P01 REQ-053 claiming it was added — this is a v0.7 leftover bug. Adding `cert_repo_test.go` (Insert/Get/List/ListByNode/LatestForKind/PruneOlderThan/Delete + N=3 rotation history per REQ-025) alone lifts coverage significantly. Job/Task repo `Watch` is tested; `ListRecent`, error paths, scan-edge cases need coverage. **No new seams; 70% achievable.**
|
||||||
|
- **jobspec → 70% REALISTIC.** `Parse` + `Validate` + `ParseFile` are pure functions over HCL bytes. Add golden-file HCL fixtures (multi-task, env vars, args) + error-path table (missing job, no tasks, missing command, malformed HCL, empty file, nonexistent file for `ParseFile`). `testdata/` dir doesn't exist yet — create it. **No new seams; 70% achievable, likely the easiest of the six.**
|
||||||
|
- **audit → 50% toe-hold REALISTIC.** Package is 125 LOC, 4 exported funcs (`New`, `Emit`, `EmitWithErr`, `LogHandshakeOK`, `LogHandshakeFailed`, `FormatAction`, `Action.String`, `Result.String`). Strategy: construct `Audit` with a real `engine.Audit` backed by `:memory:` sqlite (via `store.NewAuditRepo` + `engine.NewAudit`) + assert rows in `audit_log` table; capture slog output via a test `slog.Handler`. **No new seams; 50% easily achievable, 70% achievable if desired.**
|
||||||
|
- **certpaths → 50% toe-hold TRIVIAL.** Package is 64 LOC, pure path-join functions honoring `ORCA_HOME`/`ORCA_DB` env. Strategy: temp dir + `t.Setenv("ORCA_HOME", dir)` + assert each `*Path()` returns `filepath.Join(dir, <file>)`; test `ORCA_DB` override; test default-to-`~/.orca` fallback. Model the test on `namespace_test.go` (cli). **No new seams; 50%+ trivially achievable.**
|
||||||
|
- **cmd/orca → 50% toe-hold REALISTIC but LOW VALUE.** `main.go` is 15 LOC: `cli.Execute()` + `fmt.Fprintf(os.Stderr, "error: %v")` + `os.Exit(1)`. The only testable behavior is "main() calls Execute and exits non-zero on error." A smoke test that calls `main()` in a subprocess (or refactors main into a `run() int` for testability) is the path. **Flag: 50% on a 15-LOC glue file is ~7 lines of covered code — the effort:coverage ratio is poor. D-047 explicitly called this out ("0→70% risks a coverage rathole on `cmd/orca` which is glue code"). Recommend the plan keep this at the 50% toe-hold and not over-invest.**
|
||||||
|
|
||||||
|
### 1.2 Existing test-helper utilities (reuse, do NOT re-create)
|
||||||
|
|
||||||
|
| Helper | Location | Reuse for |
|
||||||
|
|--------|----------|-----------|
|
||||||
|
| `openTestDB(t)` | `internal/store/node_repo_test.go:12` | engine, audit, store tests — returns `(*NodeRepo, func())` backed by temp-file sqlite; adapt to return `*sql.DB` for JobRepo/TaskRepo/AuditRepo/CapacityRepo/CertRepo |
|
||||||
|
| `withFastWatch(t, d)` | `internal/store/job_task_repo_test.go:36` | store Watch tests — overrides `watchInterval` for deterministic ticks |
|
||||||
|
| `initTestEnv(t)` | `internal/cli/init_test.go:17` | cli tests — sets `ORCA_HOME` to temp dir + returns cleanup |
|
||||||
|
| `resetRootFlags(t)` | `internal/cli/namespace_test.go:13` | cli tests — resets `rootCmd` args/out/json/system flags between subtests |
|
||||||
|
| `discardWriter` | `internal/cli/init_test.go:33` | cli tests — `io.Writer` that discards stdout |
|
||||||
|
| `stubDispatcher` | `internal/daemon/dispatch_test.go:24` | transport/engine tests — implements `transport.Dispatcher` (`LocalSubmit`/`LocalStatus`); reusable as a `LocalExecutor` too since the signatures match |
|
||||||
|
| `insertNode(t, repo, ctx, id, name)` | `internal/store/node_repo_test.go:217` | store/doctor tests — inserts a minimal node |
|
||||||
|
| `security.CAInit`/`LoadCA`/`GenerateCSR`/`SignCSR`/`WriteCert`/`WriteKey` | `internal/security/ca.go` | transport mTLS tests — bootstrap a real CA + server cert into a temp dir (pattern in `doctor_test.go:69-94`) |
|
||||||
|
| `t.Setenv("ORCA_HOME", dir)` + `t.Setenv("ORCA_DB", ...)` | `internal/doctor/doctor_test.go:23-24` | any test needing the orca namespace — preferred over manual `os.Setenv` (auto-cleanup) |
|
||||||
|
|
||||||
|
### 1.3 Injected seams already present in the codebase (confirm by reading)
|
||||||
|
|
||||||
|
1. **`sshDialer` (proxmox)** — `internal/proxmox/bootstrap.go:201-213`: package-level `var sshDialer sshDialerType = defaultSSHDialer{}`; interface `sshDialerType{ DialContext(ctx, network, addr, *ssh.ClientConfig) (*ssh.Client, error) }`. Tests can swap `sshDialer` for a fake. **GAP:** no `sessionRunner` seam — `runRemote` (line 217) calls `conn.NewSession()` + `session.CombinedOutput(cmd)` directly on the concrete `*ssh.Client`. Recommend P01 plan add a `sessionRunner` interface (`CombinedOutput(cmd) ([]byte, error)`) so `deployPubKey`/`createLinuxUser`/`createPVERole`/`createPVEUser`/`assignPVEACL`/`writeSudoers`/`validateSudoers` become testable without a real SSH endpoint.
|
||||||
|
2. **`LocalExecutor` (engine dispatcher)** — `internal/engine/dispatcher.go:39`: interface `Submit(ctx, []byte) (string, error)` + `Status(ctx, string) (string, error)`. `Dispatcher` depends on it; tests inject a stub. **GAP:** `dispatchToPeer` (line 154) calls `transport.NewDispatchClient` directly (no seam) — to test the remote-dispatch branch, either add a `peerDispatcher` interface or test via `httptest.NewTLSServer`.
|
||||||
|
3. **`PeerPersister` (engine peer)** — `internal/engine/peer.go:39`: optional persist callback; unused in production but available as a seam.
|
||||||
|
4. **`Dispatcher` (transport)** — `internal/transport/dispatch.go:49`: `LocalSubmit`/`LocalStatus` interface; `stubDispatcher` in `daemon/dispatch_test.go:24` is the template stub.
|
||||||
|
5. **`watchInterval` (store)** — `internal/store/job_task_repo.go:20`: unexported `var watchInterval = 1 * time.Second`; tests override via `withFastWatch`.
|
||||||
|
|
||||||
|
### 1.4 Packages where 70% is unrealistic in a single phase (with evidence)
|
||||||
|
|
||||||
|
- **`internal/cli` — 70% is ambitious.** 17 source files, ~2000 LOC. The `daemon` command (`internal/cli/daemon.go`) starts a long-running mTLS server — testing it requires a lifecycle harness (start, probe, shutdown) and is better covered by `internal/daemon/server_test.go` (already exists, 150 LOC). Recommend the P01 plan **exclude `daemon.go` from the cli 70% target** (document it as covered by the daemon package's own tests) and aim for 70% of the *remaining* cli files. Even so, 55-65% is the realistic single-phase outcome for the rest.
|
||||||
|
- **`cmd/orca` — 70% is explicitly out of scope per D-047.** 15 LOC of glue; 50% toe-hold is the right call.
|
||||||
|
- **`internal/proxmox` — 70% likely requires the `sessionRunner` seam refactor.** Without it, only the validation paths + `sudoersContent` string asserts are testable (~50-55%). The plan should add the seam; with it, 70% is achievable.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 2. SSH trust hardening research (P02 — REQ-058, REQ-059)
|
||||||
|
|
||||||
|
### 2.1 Current TOFU `knownhosts.New()` callback — how it works
|
||||||
|
|
||||||
|
**Location:** `internal/proxmox/bootstrap.go:125-128` (bootstrap) + `internal/doctor/doctor.go:412-415` (doctor proxmox probe).
|
||||||
|
|
||||||
|
```go
|
||||||
|
hostKeyCallback, err := knownhosts.New(certpaths.KnownHostsPath())
|
||||||
|
// ...
|
||||||
|
sshConfig := &ssh.ClientConfig{
|
||||||
|
HostKeyCallback: hostKeyCallback,
|
||||||
|
// ...
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
**Mechanism (`golang.org/x/crypto/ssh/knownhosts`):**
|
||||||
|
- `knownhosts.New(files ...string)` returns an `ssh.HostKeyCallback` that reads the OpenSSH-format `known_hosts` file at `certpaths.KnownHostsPath()` (= `$ORCA_HOME/known_hosts`, see `internal/certpaths/certpaths.go:62`).
|
||||||
|
- **First connect (host absent from file):** the callback returns a `*knownhosts.KeyError` with `Want: []` (empty). This is a "host unknown" signal. **IMPORTANT:** `knownhosts.New` does NOT auto-write the key on first connect — it returns an error. The current orca code at `bootstrap.go:140` treats ANY dial error as a failure (`return nil, fmt.Errorf("ssh dial %s: %w", sshAddr, err)`). **This means the current TOFU flow is INCOMPLETE:** on a truly first connect, `knownhosts.New` returns `KeyError{Want:[]}` and the dial fails — there is no capture-and-persist step. The v0.6 RESEARCH_v0.6.md §A.5 claimed `knownhosts.New` "handles both capture and verify in one callback" but the actual `golang.org/x/crypto` API does NOT auto-capture; it only verifies. **This is a latent bug OR the operator is expected to pre-populate `known_hosts` manually (which contradicts the TOFU UX).** P02 must address this: either (a) wrap `knownhosts.New` with a custom callback that captures on `KeyError{Want:[]}` and writes via `knownhosts.Line`, or (b) accept that `--host-key-fingerprint` (REQ-058) becomes the *required* path for first connect and TOFU capture is a separate enhancement. **Flag for plan: the current TOFU capture is broken; P02 should fix it as part of the trust-hardening work (the `--host-key-fingerprint` path is actually simpler than TOFU because it doesn't need capture).**
|
||||||
|
- **Subsequent connects (host present, key matches):** callback returns `nil` → dial proceeds.
|
||||||
|
- **Subsequent connects (host present, key MISMATCH):** callback returns `*knownhosts.KeyError{Want: [knownKey]}` → dial fails with a clear error. This is the MITM-detection path.
|
||||||
|
|
||||||
|
**File format:** OpenSSH `known_hosts` — one line per host: `[host]:port ssh-key-type base64-key` (or hashed-host form via `knownhosts.HashHostname`). `knownhosts.Line(addresses []string, key ssh.PublicKey) string` produces the line; `knownhosts.Normalize(address)` normalizes the host:port.
|
||||||
|
|
||||||
|
### 2.2 `Result.HostKeyFingerprint` — current computation (CRITICAL FINDING)
|
||||||
|
|
||||||
|
**Location:** `internal/proxmox/bootstrap.go:83-85` (field declaration) + `bootstrap.go:195-198` (return statement).
|
||||||
|
|
||||||
|
```go
|
||||||
|
type Result struct {
|
||||||
|
NodeName string
|
||||||
|
NodeAddress string
|
||||||
|
HostKeyFingerprint string // field EXISTS
|
||||||
|
}
|
||||||
|
// ...
|
||||||
|
return &Result{
|
||||||
|
NodeName: opts.Host,
|
||||||
|
NodeAddress: opts.Host + ":8443",
|
||||||
|
// HostKeyFingerprint is NOT SET — always empty string
|
||||||
|
}, nil
|
||||||
|
```
|
||||||
|
|
||||||
|
**Finding:** `Result.HostKeyFingerprint` is **declared but never populated**. The current `BootstrapProxmox` returns it as `""`. There is **no fingerprint computation today** — no `ssh.FingerprintSHA256` call, no hex digest, nothing. D-045's rationale ("matches the fingerprint format operators already see from `orca node join`'s own `Result.HostKeyFingerprint` output") is based on a field that is currently always empty.
|
||||||
|
|
||||||
|
**Implication for P02:** The plan must ADD the fingerprint computation. The correct function is `ssh.FingerprintSHA256(pubKey ssh.PublicKey) string` (verified via `go doc`), which returns the **OpenSSH `SHA256:base64` format** (unpadded base64, exactly what `ssh-keyscan -E sha256` emits and what D-045 specifies). So D-045's format choice is correct *by intent* but the code doesn't produce it yet — P02 populates `Result.HostKeyFingerprint = ssh.FingerprintSHA256(hostKey)` during the capture path, and `--host-key-fingerprint` compares against `ssh.FingerprintSHA256` of the server-presented key.
|
||||||
|
|
||||||
|
**No existing fingerprint-comparison utility in `internal/security/`.** `security.Fingerprint` (fingerprint.go:17) computes SHA-256 **hex** of an X.509 cert's DER — a DIFFERENT format (hex, not base64; X.509, not SSH). `security.FingerprintOf` (fingerprint.go:34) is the same. **Do NOT reuse these for SSH host-key comparison** — they're for the mTLS CA pin (`--ca-fingerprint`). P02 needs a new SSH-specific helper, e.g. `security.SSHFingerprintSHA256(pubKey ssh.PublicKey) string` (thin wrapper over `ssh.FingerprintSHA256`) or inline in `proxmox/bootstrap.go`.
|
||||||
|
|
||||||
|
### 2.3 Where `--host-key-fingerprint` plugs in (REQ-058)
|
||||||
|
|
||||||
|
**CLI seam:** `internal/cli/node.go:344-354` — the `init()` registers flags on `nodeJoinCmd`. Add:
|
||||||
|
```go
|
||||||
|
nodeJoinCmd.Flags().StringVar(&joinHostKeyFP, "host-key-fingerprint", "", "SSH host key SHA256:base64 fingerprint (pre-pin; supersedes TOFU for --type proxmox)")
|
||||||
|
```
|
||||||
|
Per D-044, the flag lives on `orca node join` (not just `--type proxmox`); validation in `RunE` (`node.go:78-83`) emits a clear error if the flag is set for a non-proxmox type.
|
||||||
|
|
||||||
|
**Transport seam:** `internal/proxmox/bootstrap.go:131-136` — `ssh.ClientConfig.HostKeyCallback`. Currently `knownhosts.New(...)`. When `--host-key-fingerprint` is supplied, replace the callback with a `ssh.FixedHostKey`-style verifier that:
|
||||||
|
1. Parses the operator-supplied `SHA256:base64` string (strip `SHA256:` prefix, base64-decode → 32 bytes).
|
||||||
|
2. In the callback, receives the server's `ssh.PublicKey`, computes `ssh.FingerprintSHA256(key)`, compares to the operator string.
|
||||||
|
3. Returns `nil` on match, `error` on mismatch (fail closed).
|
||||||
|
|
||||||
|
**Recommended callback shape (concrete):**
|
||||||
|
```go
|
||||||
|
func pinnedHostKeyCallback(expectedSHA256Base64 string) (ssh.HostKeyCallback, error) {
|
||||||
|
// Validate format: must start with "SHA256:".
|
||||||
|
if !strings.HasPrefix(expectedSHA256Base64, "SHA256:") {
|
||||||
|
return nil, fmt.Errorf("host-key-fingerprint: must be OpenSSH SHA256:base64 format (got %q)", expectedSHA256Base64)
|
||||||
|
}
|
||||||
|
expected := expectedSHA256Base64 // store full string for direct compare
|
||||||
|
return func(_ string, _ net.Addr, key ssh.PublicKey) error {
|
||||||
|
got := ssh.FingerprintSHA256(key)
|
||||||
|
if got != expected {
|
||||||
|
return fmt.Errorf("host key fingerprint mismatch: got %s, want %s — refusing to connect (REQ-058)", got, expected)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}, nil
|
||||||
|
}
|
||||||
|
```
|
||||||
|
**Why compare full strings (not base64-decoded bytes):** `ssh.FingerprintSHA256` returns the canonical `SHA256:base64` string; comparing it directly to the operator-supplied string is simplest and avoids a base64-decode step. Reject non-`SHA256:`-prefixed input up front with a clear error (D-045: "Accept only `SHA256:`-prefixed base64; reject raw hex with a clear error").
|
||||||
|
|
||||||
|
**Pass-through to proxmox:** `internal/cli/node.go:158-166` — add `HostKeyFingerprint string` to `proxmox.Options` (bootstrap.go:55) and pass `joinHostKeyFP` through. `BootstrapProxmox` selects the callback: if `opts.HostKeyFingerprint != ""` use `pinnedHostKeyCallback`, else fall back to the TOFU `knownhosts.New` (with the capture-fix from §2.1).
|
||||||
|
|
||||||
|
### 2.4 `orca node key-reset <node>` (REQ-059, D-046 — local known_hosts only)
|
||||||
|
|
||||||
|
**Scope (D-046):** clear the local `~/.orca/known_hosts` entry for the node ONLY; do NOT revoke the remote authorized_keys entry (would orphan a working node). Audit-log `event=node.key_reset` with `actor` + `node`.
|
||||||
|
|
||||||
|
**`known_hosts` line format written by `golang.org/x/crypto/ssh/knownhosts`:**
|
||||||
|
- `knownhosts.Line(addresses []string, key ssh.PublicKey) string` → `"[host]:port ssh-ed25519 AAAA...\n"` (or `host ssh-ed25519 AAAA...` if port 22 — `knownhosts.Normalize` handles the `:22` vs bare-host normalization).
|
||||||
|
- The file is plain text, one entry per line, `#`-prefixed comments allowed.
|
||||||
|
|
||||||
|
**No library function to remove a host's entries.** `knownhosts.New` only reads. The reset must be implemented manually:
|
||||||
|
1. Read `certpaths.KnownHostsPath()` (`internal/certpaths/certpaths.go:62`).
|
||||||
|
2. Filter lines: keep lines whose host field (before the first whitespace) does NOT match `knownhosts.Normalize(nodeName)` (or the node's address). **Edge:** a host may have multiple entries (one per key type); remove all matching lines.
|
||||||
|
3. Write the filtered content back via **atomic rewrite** (temp file in same dir + `os.Rename`) — reuse `security.writeAtomic` (ca.go:305) OR implement inline (it's unexported in `security`; either export it or copy the ~20-LOC pattern). **Recommend atomic rewrite, NOT in-place truncation** — in-place rewrite via `os.OpenFile(O_TRUNC|O_WRONLY)` risks data loss on crash mid-write.
|
||||||
|
|
||||||
|
**CLI registration seam:** `internal/cli/node.go:358-360` — the `init()` does `nodeCmd.AddCommand(nodeJoinCmd)`, `nodeLeaveCmd`, `nodeListCmd`. Add:
|
||||||
|
```go
|
||||||
|
nodeCmd.AddCommand(nodeKeyResetCmd)
|
||||||
|
```
|
||||||
|
where `nodeKeyResetCmd` is a new `&cobra.Command{Use: "key-reset <node>", Args: cobra.ExactArgs(1), RunE: ...}`. The `RunE`:
|
||||||
|
1. Resolve `<node>` arg → look up the node in the registry (`nodeRegistry()` at node.go:37) to get its address (for matching `known_hosts` lines) — OR accept the raw host string directly. **Recommend:** accept the node NAME (consistent with `doctor proxmox` which iterates `node.Name`), look up the node row, use `node.Name` (which is the host address for proxmox nodes per `bootstrap.go:196`) as the `known_hosts` match key.
|
||||||
|
2. Call a new `proxmox.ResetHostKey(host string) error` (or inline in cli) that does the atomic rewrite.
|
||||||
|
3. Audit-log via `engine.Audit.Record(ctx, "cli", "node.key_reset", nodeID, "success", nil, map[string]any{"host": host})`.
|
||||||
|
4. Print `✓ Host key reset for <node> (next connect will re-pin via TOFU or --host-key-fingerprint)`.
|
||||||
|
|
||||||
|
**Reusability:** the `nodeRegistry()` helper (node.go:37) + `openDB()` (node.go:25) + `newLogger()` (node.go:33) are all available for the key-reset command.
|
||||||
|
|
||||||
|
### 2.5 CLI registration seam summary (P02)
|
||||||
|
|
||||||
|
| Addition | File:line | Change |
|
||||||
|
|----------|-----------|--------|
|
||||||
|
| `--host-key-fingerprint` flag | `internal/cli/node.go:344-354` (init) | `nodeJoinCmd.Flags().StringVar(&joinHostKeyFP, "host-key-fingerprint", "", "...")` |
|
||||||
|
| `joinHostKeyFP` var | `internal/cli/node.go:47-60` (var block) | add `joinHostKeyFP string` |
|
||||||
|
| Pass-through to proxmox | `internal/cli/node.go:158-166` (joinProxmox) | add `HostKeyFingerprint: joinHostKeyFP` to `proxmox.Options` |
|
||||||
|
| `HostKeyFingerprint` field | `internal/proxmox/bootstrap.go:55` (Options) | add field |
|
||||||
|
| Pinned callback | `internal/proxmox/bootstrap.go:131-136` | branch: if `opts.HostKeyFingerprint != ""` use pinned callback else TOFU |
|
||||||
|
| Populate `Result.HostKeyFingerprint` | `internal/proxmox/bootstrap.go:195-198` | set `HostKeyFingerprint: ssh.FingerprintSHA256(hostKey)` during capture |
|
||||||
|
| `key-reset` subcommand | `internal/cli/node.go:358-360` (init) | `nodeCmd.AddCommand(nodeKeyResetCmd)` + new cmd var |
|
||||||
|
| `ResetHostKey` helper | `internal/proxmox/bootstrap.go` (new) OR `internal/security/sshkey.go` | atomic known_hosts rewrite |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 3. Requirements-hygiene gate research (P03 — REQ-060)
|
||||||
|
|
||||||
|
### 3.1 Current Makefile targets
|
||||||
|
|
||||||
|
`Makefile` has 11 targets: `build`, `test`, `test-race`, `lint`, `fmt`, `clean`, `run`, `version`, `changelog`, `release`, `security-scan` (Makefile:1-100). **No `verify-reqs` target exists.** The `.PHONY` list at line 1 must be extended.
|
||||||
|
|
||||||
|
### 3.2 Current `.coreci.yml` pipeline structure
|
||||||
|
|
||||||
|
4 pipelines (`.coreci.yml:19-134`):
|
||||||
|
- **validate** (line 20): 4 steps — `go-version` (gofmt+vet), `gosec`, `govulncheck`, `gitleaks`.
|
||||||
|
- **build** (line 53): 1 step — version-injected `go build`.
|
||||||
|
- **test** (line 72): 1 step — `go test -race -coverprofile=coverage.out ./...` + `go tool cover -func | tail -1`.
|
||||||
|
- **release** (line 81): gated on `refs/tags/v*`; 3 steps — build-artifact, gitea-release, container-publish.
|
||||||
|
|
||||||
|
**Hook for `verify-reqs`:** add a 5th step to the `validate` pipeline (after `go-version`, before/after `gosec`) OR add it to the `test` pipeline. **Recommend `validate` pipeline** — requirements hygiene is a static check (no test run needed), belongs alongside gofmt/vet/lint. Step shape:
|
||||||
|
```yaml
|
||||||
|
- name: verify-reqs
|
||||||
|
image: golang:1.25
|
||||||
|
commands:
|
||||||
|
- make verify-reqs
|
||||||
|
```
|
||||||
|
|
||||||
|
### 3.3 `verify-reqs` implementation recommendation
|
||||||
|
|
||||||
|
**Assertion (REQ-060):** every REQ row in `ROADMAP.md` marked `[x]`/Complete must have a matching REQ-ID row in `REQUIREMENTS.md` with `Complete` status. (Reverse direction — every REQUIREMENTS `Complete` has a ROADMAP `[x]` — is also worth checking but the drift that motivated this was ROADMAP-shipped-but-REQUIREMENTS-Pending, so the forward direction is the priority.)
|
||||||
|
|
||||||
|
**Approach: small Go program in `cmd/verify-reqs` OR a shell+awk script?**
|
||||||
|
|
||||||
|
- **Go program** (~80 LOC): parse both markdown tables with `regexp`, build two `map[string]string` (REQ-ID → status), diff. Pros: type-safe, testable, consistent with the Go toolchain; can be a `cmd/verify-reqs/main.go` with its own `_test.go`. Cons: adds a binary target.
|
||||||
|
- **Shell+awk** (~30 LOC): `awk` over the markdown tables. Pros: no new Go package; minimal. Cons: fragile parsing, hard to test, shell-quoting issues.
|
||||||
|
|
||||||
|
**Recommendation: Go program at `cmd/verify-reqs/main.go`.** Reasons: (1) testable with golden-file fixtures (parse a sample ROADMAP+REQUIREMENTS pair, assert diff); (2) consistent with the project's Go-only tooling ethos (no shell-awk fragility); (3) the `make verify-reqs` target just calls `go run ./cmd/verify-reqs`; (4) CoreCI's `golang:1.25` image has `go` available — no extra dep.
|
||||||
|
|
||||||
|
**Parsing approach (concrete):**
|
||||||
|
1. ROADMAP.md: regex `^\s*-\s*\[(x|X| )\]\s*Phase.*—.*tag` is NOT the right pattern (that's phase lines, not REQ rows). The REQ coverage is in per-phase bullet lists under "### Per-phase REQ coverage" (ROADMAP.md:161-180) AND in the milestone section bodies. **Simpler:** the ROADMAP uses `- [x] Phase N: ...` for completed phases. The authoritative REQ↔status mapping lives in **REQUIREMENTS.md** (the single table at lines 9-56 + per-milestone tables at 103-142). **Re-interpret REQ-060:** the assertion is really "ROADMAP milestone sections marked COMPLETE ↔ REQUIREMENTS rows for that milestone marked Complete." The drift was: v0.7 ROADMAP said "COMPLETE" (line 116) but REQUIREMENTS v0.7 rows (REQ-053..056) were "Pending" (now corrected to "Complete" in SPECIFY).
|
||||||
|
2. **Refined assertion:** parse REQUIREMENTS.md table rows (`| REQ-XXX | ... | ... | ... | **Complete** |` or `| Pending |`); for each REQ-ID, record status. Then parse ROADMAP.md for milestone-level "COMPLETE" markers (`## Milestone v0.X: ... — **COMPLETE**`) AND phase-level `- [x]` markers. For each milestone marked COMPLETE in ROADMAP, assert every REQ-ID belonging to that milestone (per the REQUIREMENTS milestone column) is `Complete` in REQUIREMENTS. **OR (simpler, matches the SPECIFY wording):** for every REQ-ID in REQUIREMENTS.md whose `Phase` column references a milestone that ROADMAP marks COMPLETE, the Status must be `Complete`. This catches the exact drift (ROADMAP-shipped, REQUIREMENTS-stale).
|
||||||
|
|
||||||
|
**Concrete regex:**
|
||||||
|
- REQUIREMENTS row: `^\|\s*(REQ-\d+)\s*\|.*?\|\s*\*\*(Complete|Pending)\*\*\s*\|` (capture ID + status).
|
||||||
|
- ROADMAP milestone-complete: `^##\s*Milestone\s+v0\.\d+:.*—\s*\*\*COMPLETE\*\*` (capture milestone label).
|
||||||
|
- Map milestone → REQs via the REQUIREMENTS `Phase` column (e.g. `v0.7 P1` → milestone `v0.7`).
|
||||||
|
|
||||||
|
**Where it hooks in:** `make verify-reqs` runs `go run ./cmd/verify-reqs .ciagent/ROADMAP.md .ciagent/REQUIREMENTS.md`; `.coreci.yml` validate pipeline adds the step. Exit 0 on consistency, exit 1 with a diff listing on drift.
|
||||||
|
|
||||||
|
### 3.4 The drift that motivated REQ-060
|
||||||
|
|
||||||
|
After v0.7 ship, REQUIREMENTS.md rows REQ-053..056 were "Pending" despite ROADMAP.md marking milestone v0.7 COMPLETE and all phases `[x]`. This was corrected during v0.8 SPECIFY (the rows now read `**Complete**`). REQ-060 ensures the drift cannot recur: the CI validate pipeline fails if ROADMAP says COMPLETE but REQUIREMENTS says Pending.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 4. Architectural decisions surfaced (AD-027..AD-030)
|
||||||
|
|
||||||
|
| ID | Decision | Rationale |
|
||||||
|
|----|----------|-----------|
|
||||||
|
| AD-027 | `ssh.FingerprintSHA256` (OpenSSH `SHA256:base64`) as the SSH host-key fingerprint format | Matches D-045 + `ssh-keyscan -E sha256` output. The existing `security.Fingerprint` (hex, X.509) is NOT reused — different domain. P02 adds a thin SSH-specific helper. |
|
||||||
|
| AD-028 | `--host-key-fingerprint` callback compares full `SHA256:base64` strings, not decoded bytes | `ssh.FingerprintSHA256` returns the canonical string; direct string compare avoids a base64-decode step and is less error-prone. Validate `SHA256:` prefix up front. |
|
||||||
|
| AD-029 | `orca node key-reset` rewrites `known_hosts` via atomic temp-file + rename | Prevents data loss on crash mid-write. Reuse the `writeAtomic` pattern from `security/ca.go:305` (export it or copy the ~20 LOC). |
|
||||||
|
| AD-030 | `verify-reqs` implemented as `cmd/verify-reqs/main.go` (Go program), not shell+awk | Testable, type-safe, consistent with Go-only tooling. `make verify-reqs` runs `go run ./cmd/verify-reqs`. Hooked into `.coreci.yml` validate pipeline. |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 5. Pitfalls, gaps, and flags for the plan
|
||||||
|
|
||||||
|
1. **TOFU capture is currently BROKEN (§2.1).** `knownhosts.New` returns `KeyError{Want:[]}` on first connect and does NOT auto-write the key. The current `BootstrapProxmox` treats this as a dial failure. P02 must either (a) wrap the callback to capture-and-persist on `KeyError{Want:[]}` via `knownhosts.Line` + atomic write, or (b) make `--host-key-fingerprint` the required first-connect path. **Recommend (a) — fix TOFU + add pre-pin as superset.** This is a v0.6 latent bug that P02 closes.
|
||||||
|
2. **`Result.HostKeyFingerprint` is never populated (§2.2).** D-045's rationale references "existing output" that doesn't exist. P02 must ADD the computation (`ssh.FingerprintSHA256`). Low risk — it's a 1-line addition once the host key is available.
|
||||||
|
3. **No `sessionRunner` seam in proxmox (§1.3).** Testing the SSH command sequence (deployPubKey, createLinuxUser, pveum, sudoers, visudo) without a real SSH server requires a new interface seam. **Recommend P01 plan add it** — 1 interface, ~10 LOC, unlocks ~40% of proxmox coverage.
|
||||||
|
4. **`internal/store/cert_repo.go` has NO test (§1.1).** v0.7 P01 REQ-053 was supposed to add `cert_repo_test.go` but it's missing — `internal/store/` glob shows no `cert_repo_test.go`. This is a v0.7 leftover. P01 should add it (it directly lifts store coverage toward 70%).
|
||||||
|
5. **`internal/cli/daemon.go` excluded from cli 70% target (§1.4).** The daemon command starts a long-running server; it's covered by `internal/daemon/server_test.go` (150 LOC). Don't double-test in cli.
|
||||||
|
6. **`cmd/orca` 50% toe-hold is low-value (§1.1).** 15 LOC of glue; the test effort:coverage ratio is poor. D-047 already called this out. Don't over-invest.
|
||||||
|
7. **`go: no such tool "covdata"` for zero-test packages (§1.1).** This is a Go toolchain quirk when a package has no test files — `go test -cover` can't compute coverage without a test binary. It's NOT a real 0% number (it's "undefined"). Adding any `_test.go` file makes the number computable. Don't treat the error as a coverage measurement.
|
||||||
|
8. **`transport.dispatchToPeer` has no seam (§1.3).** Testing the remote-dispatch branch of `Dispatcher.Submit` requires either a new `peerDispatcher` interface OR `httptest.NewTLSServer`. The latter is already used in `daemon/dispatch_test.go`; recommend the plan use `httptest.NewTLSServer` (no refactor needed) for transport coverage.
|
||||||
|
9. **`knownhosts.Line` + `knownhosts.Normalize` are the helpers for the TOFU-capture fix and for `key-reset` matching (§2.1, §2.4).** Use `Normalize` to match host strings consistently (handles `host:22` vs `host`).
|
||||||
|
10. **`security.writeAtomic` is unexported (ca.go:305).** `key-reset`'s atomic known_hosts rewrite needs it. Either export `WriteAtomic` from `security`, or copy the ~20-LOC pattern into `proxmox`/`cli`. **Recommend export** — it's already used across ca.go + sshkey.go and is generally useful.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 6. Dependencies
|
||||||
|
|
||||||
|
v0.8 adds **zero** new direct dependencies:
|
||||||
|
- SSH host-key fingerprint: `ssh.FingerprintSHA256` (already in `golang.org/x/crypto/ssh` v0.54.0, direct dep since v0.6).
|
||||||
|
- `knownhosts.Line`/`Normalize`/`KeyError`: same `golang.org/x/crypto` module.
|
||||||
|
- `verify-reqs`: stdlib only (`regexp`, `os`, `fmt`).
|
||||||
|
- Tests: `net/http/httptest` (stdlib), existing interfaces.
|
||||||
|
|
||||||
|
`go.mod` is unchanged by v0.8.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## 7. PERSONAS assessment (v0.8)
|
||||||
|
|
||||||
|
v0.8 is an NFR milestone touching tests (9 packages), SSH trust surface (proxmox + cli/node + security), and a requirements-hygiene Go program. The 3-persona roster from config.json (lead-developer, backend-engineer, data-engineer) is sufficient — no phase-specific personas needed.
|
||||||
|
|
||||||
|
**Roster confirmation:**
|
||||||
|
- **lead-developer** — owns coordination + `cmd/orca` smoke test + `internal/cli` coverage (cert/doctor/audit/status/version subcommands) + the `verify-reqs` Go program (coordination territory).
|
||||||
|
- **backend-engineer** — owns `internal/transport` tests (httptest.NewTLSServer) + `internal/engine` tests (LocalExecutor stubs, PeerRegistry) + SSH trust-surface in `internal/proxmox/bootstrap.go` (pinned callback, TOFU capture fix, sessionRunner seam) + `internal/cli/node.go` (`--host-key-fingerprint` flag, `key-reset` subcommand).
|
||||||
|
- **data-engineer** — owns `internal/store` tests (cert_repo_test.go gap + coverage uplift) + `internal/audit` tests (sqlite-backed audit_log asserts) + `internal/certpaths` tests (path-join asserts) + `internal/jobspec` tests (golden HCL fixtures).
|
||||||
|
|
||||||
|
No frontend persona (no UI). No devops persona (no packaging/distribution — `verify-reqs` is a Go program, not a CI config change; the `.coreci.yml` edit is a 3-line hook, lead-developer territory). No security-engineer persona (the SSH trust work is backend-engineer territory — the security-engineer was deactivated in v0.7 and v0.8 doesn't re-add it; the trust-surface hardening is a refinement of the existing `proxmox` package, not new security architecture).
|
||||||
|
|
||||||
|
See `.ciagent/PERSONAS.md` (updated with v0.8 YAML frontmatter + territory globs matching the actual file structure).
|
||||||
@@ -0,0 +1,321 @@
|
|||||||
|
# Review: Orca v0.8 — Coverage & Trust Hardening (final-phase)
|
||||||
|
|
||||||
|
**Reviewer**: ci-code-reviewer (multi-persona: correctness, testing, security, performance, maintainability, adversarial)
|
||||||
|
**Branch**: `phase/04-final-review-ship` (review HEAD = P03 ship `70c5718`)
|
||||||
|
**Diff scope**: `main...milestone/v0.8-coverage-trust-hardening` (all v0.8 work, 59 files, +6550/-173)
|
||||||
|
**Date**: 2026-08-04
|
||||||
|
**Verdict**: **PASS-WITH-FOLLOWUPS** (0 P0, 2 P1, 2 P2)
|
||||||
|
|
||||||
|
## Methodology
|
||||||
|
|
||||||
|
Read the full diff (`internal/`, `cmd/`, `Makefile`, `.coreci.yml`), all 3 phase
|
||||||
|
verification reports, PLAN/RESEARCH/GRILL/PERSONAS, and the critical production
|
||||||
|
files directly (`internal/proxmox/bootstrap.go`, `internal/security/ca.go`,
|
||||||
|
`internal/security/sshkey.go`, `internal/doctor/doctor.go:400-454`,
|
||||||
|
`cmd/verify-reqs/main.go`). Re-ran `go build ./...`, `go vet ./...`,
|
||||||
|
`go test -race` on proxmox/security/doctor/cli/verify-reqs/cmd-orca, and
|
||||||
|
`make verify-reqs` (all PASS). Re-verified the verify-reqs regex against the
|
||||||
|
real ROADMAP.md (matches v0.1..v0.7 COMPLETE incl. v0.2 parenthetical; v0.8
|
||||||
|
correctly not matched). Confirmed all 7 T02.10 e2e cases are present and
|
||||||
|
exercised through a real in-process SSH server.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Per-Axis Findings
|
||||||
|
|
||||||
|
### 1. Correctness (lead-developer)
|
||||||
|
|
||||||
|
**C1 — `sessionRunner` seam backward-compat** ✅
|
||||||
|
`internal/proxmox/bootstrap.go:170-172,322-339`. The seam is a package-level
|
||||||
|
`var sessionRunner sessionRunnerType` (line 326) initialized lazily inside
|
||||||
|
`BootstrapProxmox` from the dialed `*ssh.Client` (`if sessionRunner == nil {
|
||||||
|
sessionRunner = &sshSessionRunner{client: conn} }`). Existing callers are
|
||||||
|
unchanged — the default `sshSessionRunner` wraps the real
|
||||||
|
`conn.NewSession().CombinedOutput(...)`. Tests reset `sessionRunner = nil`
|
||||||
|
between runs (bootstrap_test.go:910, 1010, 1035) to avoid cross-test leakage.
|
||||||
|
Backward compatible as required by P01 verification. No issue.
|
||||||
|
|
||||||
|
**C2 — `verify-reqs` parser correctness** ✅
|
||||||
|
`cmd/verify-reqs/main.go:18-26`. The `reqRowRe` uses a greedy `.*` for the
|
||||||
|
Requirement+Priority cells and anchors the Phase+Status match at the END of
|
||||||
|
the line, where those two columns always live. This correctly handles
|
||||||
|
escaped pipes inside the Requirement cell (e.g. REQ-049
|
||||||
|
`localhost\|linux\|proxmox` — verified by the passing `make verify-reqs`
|
||||||
|
which reports 60 consistent rows, matching the 60 REQ rows in
|
||||||
|
REQUIREMENTS.md). The status token is optionally bold-wrapped
|
||||||
|
(`\*{0,2}(Complete|Pending)\*{0,2}`) with `[^|]*` for trailing notes —
|
||||||
|
handles `**Complete** (P01 shipped v0.2.1)`. The milestone-complete regex
|
||||||
|
`^##\s*Milestone\s+(v0\.\d+):.*—\s*\*\*[^*]*\bCOMPLETE\b[^*]*\*\*` is
|
||||||
|
substring-tolerant (GRILL #4) — verified against the real ROADMAP: matches
|
||||||
|
v0.1..v0.7 incl. v0.2's `**COMPLETE (merged to main via v0.3)**` and v0.6's
|
||||||
|
duplicate header (line 94 matched; line 92 without COMPLETE ignored). v0.8
|
||||||
|
(line 136, not yet COMPLETE) correctly not matched — so the v0.8 REQ rows
|
||||||
|
being `Pending` is NOT flagged as drift (correct: milestone not shipped
|
||||||
|
yet). No issue.
|
||||||
|
|
||||||
|
**C3 — TOFU capture-fix logic** ✅
|
||||||
|
`internal/proxmox/bootstrap.go:275-310`. On `*knownhosts.KeyError` with
|
||||||
|
empty `Want` (host unknown), captures the key, reads existing known_hosts
|
||||||
|
(create-if-missing), ensures trailing newline, appends
|
||||||
|
`knownhosts.Line([]string{knownhosts.Normalize(addr)}, key)`, writes via
|
||||||
|
`security.WriteAtomic`, returns nil (dial proceeds). On non-empty `Want`
|
||||||
|
(mismatch) returns the error (MITM detection preserved). On `nil` (match)
|
||||||
|
records key + returns nil. Correct against x/crypto v0.54.0 `checkAddr`
|
||||||
|
semantics. No issue.
|
||||||
|
|
||||||
|
**C4 — `ResetHostKey` line matching** ✅
|
||||||
|
`internal/proxmox/bootstrap.go:479-523`. Matches a line when its first
|
||||||
|
whitespace-delimited field, normalized via `knownhosts.Normalize`, equals
|
||||||
|
the normalized target. Handles `[host]:22` vs bare `host` (Normalize
|
||||||
|
brackets ports). Preserves comments/blanks. Atomic rewrite via
|
||||||
|
`security.WriteAtomic`. Edge cases handled: empty host errors, missing
|
||||||
|
file is a no-op, no matching lines is a no-op. Test
|
||||||
|
`TestResetHostKey_RemovesTargetLines` (bootstrap_test.go:718) seeds 2 lines
|
||||||
|
for target + 1 for another host, asserts target's 2 removed + other
|
||||||
|
intact. No issue.
|
||||||
|
|
||||||
|
**C5 — `--host-key-fingerprint` non-proxmox validation** ✅
|
||||||
|
`internal/cli/node.go:79-81`. `RunE` checks `joinHostKeyFP != "" &&
|
||||||
|
joinType != "proxmox"` → clear error. Test
|
||||||
|
`TestNodeJoinHostKeyFingerprintRequiresProxmox` (node_test.go:445) asserts
|
||||||
|
the error; `TestNodeJoinHostKeyFingerprintProxmoxAccepted` (node_test.go:477)
|
||||||
|
asserts the negative-space (proxmox type accepts the flag). No issue.
|
||||||
|
|
||||||
|
### 2. Testing (all personas)
|
||||||
|
|
||||||
|
**T1 — Coverage held post-P02** ✅
|
||||||
|
PHASE2 verification: proxmox 86.5% (was 87.1%), cli 76.7% (was 76.2%),
|
||||||
|
doctor 70.4%. Marginal changes from new code paths — no coverage regression.
|
||||||
|
Re-ran `go test -race ./internal/proxmox/... ./internal/cli/...` PASS.
|
||||||
|
|
||||||
|
**T2 — Race tests pass** ✅
|
||||||
|
`go test -race -count=1 ./internal/proxmox/... ./internal/security/...
|
||||||
|
./internal/doctor/... ./cmd/verify-reqs/... ./cmd/orca/...` all PASS.
|
||||||
|
`./internal/cli/...` PASS (77s, dominated by watch tests). No races.
|
||||||
|
|
||||||
|
**T3 — 7 T02.10 integration cases** ✅
|
||||||
|
All 7 present in `internal/proxmox/bootstrap_test.go`, exercised
|
||||||
|
end-to-end through `BootstrapProxmox` with a real in-process SSH server
|
||||||
|
(`bootstrapE2ESetup`):
|
||||||
|
- Case 1: `TestBootstrapE2E_PinnedFingerprintCorrect` (815)
|
||||||
|
- Case 2: `TestBootstrapE2E_PinnedFingerprintWrong` (842)
|
||||||
|
- Case 3: `TestBootstrapE2E_TOFUFirstConnectCapturesKey` (865)
|
||||||
|
- Case 4: `TestBootstrapE2E_TOFUSecondConnectMatches` (905)
|
||||||
|
- Case 5: `TestBootstrapE2E_TOFUMismatchFails` (925)
|
||||||
|
- Case 6: `TestBootstrapE2E_KeyResetThenRePin` (1002)
|
||||||
|
- Case 7: `TestBootstrapE2E_PrePopulatedKnownHostsMatches` (966, v0.6→v0.8 migration)
|
||||||
|
|
||||||
|
**T4 — Golden tests for verify-reqs** ✅
|
||||||
|
`cmd/verify-reqs/main_test.go` has 7 tests covering: clean pair, multi-drift
|
||||||
|
(both directions), default-args subprocess, malformed (no REQ rows → error),
|
||||||
|
missing file → error, v0.2 substring-tolerant header regression guard
|
||||||
|
(`TestVerify_v02SubstringTolerantHeader`), and real-repo regression guard.
|
||||||
|
The substring-tolerant regex is explicitly exercised — the drift fixture's
|
||||||
|
ROADMAP uses `**COMPLETE (merged to main via v0.3)**` on v0.2 and the test
|
||||||
|
asserts REQ-002 (v0.2 P1, Pending) is flagged forward-drift (would be
|
||||||
|
silently skipped if the regex regressed). No issue.
|
||||||
|
|
||||||
|
**T5 — Doctor parity test** ✅
|
||||||
|
`internal/doctor/doctor_test.go` extended with 94 LOC covering
|
||||||
|
`probeProxmoxPVEVersion` paths. The doctor callback now uses the shared
|
||||||
|
`proxmox.TOFUHostKeyCallback` (doctor.go:424) — GRILL #2 parity verified by
|
||||||
|
reading both call sites. No issue.
|
||||||
|
|
||||||
|
### 3. Security (backend-engineer)
|
||||||
|
|
||||||
|
**S1 — `--host-key-fingerprint` fails closed** ✅
|
||||||
|
`internal/proxmox/bootstrap.go:141-153,245-258`. The pinned/TOFU branch is
|
||||||
|
mutually exclusive (`if opts.HostKeyFingerprint != "" { ... } else { ... }`).
|
||||||
|
The pinned callback (245-258) validates `SHA256:` prefix up front (rejects
|
||||||
|
raw hex per D-045), computes `ssh.FingerprintSHA256(key)`, returns an error
|
||||||
|
on any mismatch — no fallback to TOFU. The dial (164) aborts on callback
|
||||||
|
error before any SSH session command runs. Cannot be bypassed: the pin is
|
||||||
|
compared as a full string against the canonical fingerprint of the
|
||||||
|
server-presented key; a mismatch returns before `*capturedKey` is set. No
|
||||||
|
issue.
|
||||||
|
|
||||||
|
**S2 — `key-reset` is local-only (D-046)** ✅
|
||||||
|
`internal/proxmox/bootstrap.go:479-523` + `internal/cli/node.go:348-407`.
|
||||||
|
`ResetHostKey` only reads/writes `certpaths.KnownHostsPath()`. No SSH dial,
|
||||||
|
no remote authorized_keys touch. Audit-logs `node.key_reset` with
|
||||||
|
actor+node+host (node.go:396-400). Verified by `TestNodeKeyReset`
|
||||||
|
(node_test.go:326) which asserts the audit row. No issue.
|
||||||
|
|
||||||
|
**S3 — TOFU capture-fix doesn't weaken MITM detection** ✅
|
||||||
|
See C3 — the fix ONLY captures on `KeyError{Want:[]}` (host unknown); a
|
||||||
|
non-empty `Want` (key mismatch / MITM) returns the error. The capture path
|
||||||
|
writes the server-presented key, so a subsequent different key fails. No
|
||||||
|
issue.
|
||||||
|
|
||||||
|
**S4 — `WriteAtomic` is actually atomic** ✅
|
||||||
|
`internal/security/ca.go:308-337`. Temp file in same dir
|
||||||
|
(`os.CreateTemp(dir, ".tmp-*")`), `Write`, `Chmod`, `Sync`, `Close`, then
|
||||||
|
`os.Rename` (atomic on POSIX same-filesystem). `defer os.Remove(tmpName)`
|
||||||
|
cleans up on failure. Genuine atomic-write pattern. No issue.
|
||||||
|
|
||||||
|
### 4. Performance (all)
|
||||||
|
|
||||||
|
**P1 — ResetHostKey is O(n) in file size** ✅
|
||||||
|
`internal/proxmox/bootstrap.go:479-523`: one `os.ReadFile` (O(n)), one
|
||||||
|
`strings.Split` + linear filter loop (O(n)), one `security.WriteAtomic`
|
||||||
|
(O(n)). No nested loops, no O(n²). For a known_hosts file (typically tens
|
||||||
|
of lines), this is negligible. No issue.
|
||||||
|
|
||||||
|
**P2 — Unnecessary allocations** (P2 — nit)
|
||||||
|
`bootstrap.go:494-510`: `strings.Split(string(existing), "\n")` allocates a
|
||||||
|
slice of all lines + `append(kept, []byte(line+"\n")...)` reallocates the
|
||||||
|
kept buffer. For known_hosts (small file) this is fine; a `bufio.Scanner`
|
||||||
|
over `bytes.NewReader(existing)` with a `strings.Builder` would be leaner,
|
||||||
|
but the current shape is clear and the file is tiny. Not worth changing.
|
||||||
|
Flagged P2 (nit, no action).
|
||||||
|
|
||||||
|
### 5. Maintainability (lead-developer)
|
||||||
|
|
||||||
|
**M1 — `TOFUHostKeyCallback` extraction** ✅
|
||||||
|
`internal/proxmox/bootstrap.go:261-310` is exported and shared by bootstrap
|
||||||
|
(148) and doctor (doctor.go:424) via
|
||||||
|
`proxmox.TOFUHostKeyCallback(sshAddr, &capturedHostKey)`. Clean coupling:
|
||||||
|
doctor imports proxmox (one-way), no duplication, no circular dep. The
|
||||||
|
GRILL #2 parity requirement (both call sites use the same wrapper) is
|
||||||
|
satisfied by construction. No issue.
|
||||||
|
|
||||||
|
**M2 — `verify()` testable** ✅
|
||||||
|
`cmd/verify-reqs/main.go:98-148`: the core logic is a pure function
|
||||||
|
`verify(roadmapPath, reqsPath string) (diff []string, count int, err error)`
|
||||||
|
with `main()` as a thin wrapper. Golden-file tests call `verify()` directly
|
||||||
|
(no subprocess). Mirrors the T01.11 `main()→run()` pattern. No issue.
|
||||||
|
|
||||||
|
**M3 — cli tests follow conventions** ✅
|
||||||
|
`internal/cli/namespace_test.go:21-35` adds `resetCommandFlags()` to zero
|
||||||
|
the package-level flag-bound vars between subtests (cobra parses into
|
||||||
|
globals; without reset a prior test's value persists). Called from
|
||||||
|
`resetRootFlags`. This is a sound convention — the test isolation is
|
||||||
|
correct. No issue.
|
||||||
|
|
||||||
|
**M4 — `resetCommandFlags` completeness** (P2 — nit)
|
||||||
|
`namespace_test.go:28-34` resets the join/leave/cap/audit/run/stop flags but
|
||||||
|
NOT `joinHostKeyFP`. A test that sets `--host-key-fingerprint` without
|
||||||
|
calling `resetRootFlags` could leak the value to a later test. In practice
|
||||||
|
all node tests call `resetRootFlags` which calls `resetCommandFlags`, so
|
||||||
|
this is a latent risk only. Recommend adding `joinHostKeyFP = ""` to
|
||||||
|
`resetCommandFlags` for completeness. Flagged P2 (nit).
|
||||||
|
|
||||||
|
### 6. Adversarial (backend-engineer)
|
||||||
|
|
||||||
|
**A1 — Can `--host-key-fingerprint` be bypassed?** ✅
|
||||||
|
No. The pinned callback (bootstrap.go:249-258) returns an error before
|
||||||
|
recording the key or allowing the dial to proceed on any mismatch. There is
|
||||||
|
no code path where a supplied pin is ignored — the branch at 141-153 is
|
||||||
|
`if opts.HostKeyFingerprint != ""` (pinned) `else` (TOFU); once pinned is
|
||||||
|
chosen, TOFU is not consulted. No bypass.
|
||||||
|
|
||||||
|
**A2 — Can `key-reset` corrupt known_hosts under concurrent write?** (P1 — important, low likelihood)
|
||||||
|
`proxmox.ResetHostKey` (bootstrap.go:479-523) and `TOFUHostKeyCallback`
|
||||||
|
(bootstrap.go:290-302) both do read-modify-write on
|
||||||
|
`certpaths.KnownHostsPath()` WITHOUT a lock. Two concurrent operations
|
||||||
|
(e.g. `orca node join --type proxmox hostA` + `orca node key-reset hostB`,
|
||||||
|
or two simultaneous joins to different hosts) could interleave:
|
||||||
|
- T1 reads known_hosts (empty), T2 reads known_hosts (empty)
|
||||||
|
- T1 writes hostA line, T2 writes hostB line
|
||||||
|
- Last rename wins → one line lost.
|
||||||
|
|
||||||
|
The `security.WriteAtomic` (temp+rename) prevents corruption (the file is
|
||||||
|
always valid OpenSSH format), but a captured line can be silently lost. This
|
||||||
|
is a **last-writer-wins race on a flat file with no lock**. Severity is low
|
||||||
|
because orca is a single-operator CLI (concurrent joins are unusual) and
|
||||||
|
the lost line is recoverable (re-connect re-pins via TOFU). But it is a
|
||||||
|
real correctness gap for the trust surface. Recommend either (a) a
|
||||||
|
file-lock around the read-modify-write, or (b) documenting the
|
||||||
|
single-operator assumption explicitly. Flagged P1 (important, post-hoc).
|
||||||
|
|
||||||
|
**A3 — Can verify-reqs be fooled by a crafted markdown table?** ✅
|
||||||
|
No. The `reqRowRe` anchors on `^\|\s*(REQ-\d+)\s*\|` and the status column
|
||||||
|
at end-of-line. A crafted row with a fake status would have to match the
|
||||||
|
regex exactly. The "malformed" fixture (`requirements_malformed.md`)
|
||||||
|
exercises the no-REQ-rows path → clear error. A row like
|
||||||
|
`| REQ-999 | missing status cell | High | v0.1 |` (no final `|...|`) does
|
||||||
|
NOT match `reqRowRe` (the trailing `\|\s*$` requires the status cell) — it
|
||||||
|
is silently skipped, which `verify` reports as "no REQ rows" only if ALL
|
||||||
|
rows are malformed. If some rows are valid + one malformed, the malformed
|
||||||
|
row is skipped without error — a minor blind spot, but acceptable (the
|
||||||
|
gate catches drift, not typos). No blocking issue.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## GRILL Conditions Verification
|
||||||
|
|
||||||
|
### #1 — T02.6 labeled as v0.6 ship-defect bugfix ✅
|
||||||
|
Commit `8b0cbe1` summary: "fix(proxmox): TOFU capture bug — **v0.6
|
||||||
|
ship-defect** first-connect join always failed (T02.6)". The commit message
|
||||||
|
explicitly labels it as a v0.6 ship-defect bugfix, not a v0.8 feature.
|
||||||
|
PHASE2 verification report records it as "TOFU bugfix (T02.6, v0.6
|
||||||
|
ship-defect)". **Satisfied.**
|
||||||
|
|
||||||
|
### #2 — T02.9 doctor parity (bootstrap + doctor use capture-fix wrapper) ✅
|
||||||
|
- Bootstrap: `internal/proxmox/bootstrap.go:148` calls
|
||||||
|
`TOFUHostKeyCallback(sshAddr, &capturedHostKey)`.
|
||||||
|
- Doctor: `internal/doctor/doctor.go:424` calls
|
||||||
|
`proxmox.TOFUHostKeyCallback(sshAddr, nil)`.
|
||||||
|
Both use the SAME exported wrapper (`proxmox.TOFUHostKeyCallback`,
|
||||||
|
bootstrap.go:275). No duplication. The doctor diff
|
||||||
|
(`internal/doctor/doctor.go`) removes the direct `knownhosts.New` call and
|
||||||
|
replaces it with the shared wrapper. **Satisfied.**
|
||||||
|
|
||||||
|
### #3 — T01.6 cli escape valve (was it needed?) ✅
|
||||||
|
PHASE1 verification: cli hit **76.2%** (above the 70% floor, excluding
|
||||||
|
daemon.go). The escape valve (ship at 65% if 70% not reached) was **NOT
|
||||||
|
needed**. The plan's conditional was correctly conservative; the actual
|
||||||
|
result exceeded the floor. **Satisfied (not invoked).**
|
||||||
|
|
||||||
|
### #4 — T03.1 verify-reqs regex substring-tolerant + reverse direction ✅
|
||||||
|
- **Substring-tolerant**: `cmd/verify-reqs/main.go:30`:
|
||||||
|
`^##\s*Milestone\s+(v0\.\d+):.*—\s*\*\*[^*]*\bCOMPLETE\b[^*]*\*\*`.
|
||||||
|
Verified against the real ROADMAP: matches v0.2's
|
||||||
|
`**COMPLETE (merged to main via v0.3)**` and all other COMPLETE
|
||||||
|
milestones. Golden test `TestVerify_v02SubstringTolerantHeader`
|
||||||
|
(main_test.go:140) guards against regression.
|
||||||
|
- **Reverse direction**: `cmd/verify-reqs/main.go:135-139`: a REQ marked
|
||||||
|
`Complete` whose referenced milestones are ALL not-C_COMPLETE in ROADMAP
|
||||||
|
is flagged as `direction=reverse` drift. Golden test `TestVerify_drift`
|
||||||
|
asserts REQ-003 is reverse-drift.
|
||||||
|
- **Scope note**: PLAN + commit `fc2b020` document that REQ-060 catches
|
||||||
|
doc-vs-doc drift only (code-vs-doc like the REQ-053 cert_repo_test.go
|
||||||
|
case is out of scope; P04 audit is the backstop). **Satisfied.**
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## P0 Fixes Applied
|
||||||
|
|
||||||
|
**None.** No P0 issues (correctness bugs, security holes, broken build/test)
|
||||||
|
were found. `go build ./...`, `go vet ./...`, `go test -race` (all key
|
||||||
|
packages), and `make verify-reqs` all PASS. The milestone is shippable as-is.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## P1+ Issues Flagged (post-hoc review)
|
||||||
|
|
||||||
|
| ID | Severity | File:line | Issue | Recommendation |
|
||||||
|
|----|----------|-----------|-------|----------------|
|
||||||
|
| A2 | P1 (important, low likelihood) | `internal/proxmox/bootstrap.go:290-302, 479-523` | `TOFUHostKeyCallback` capture path and `ResetHostKey` both do read-modify-write on `known_hosts` with no lock; concurrent operations can lose a captured line (last-writer-wins via atomic rename — no corruption, but data loss). | Add a file-lock (`flock` on a `.known_hosts.lock` sibling, or `github.com/gofrs/flock` if a dep is acceptable) around the RMW in both paths; OR document the single-operator assumption in the key-reset help text. Defer to v0.9. |
|
||||||
|
| M4 | P2 (nit) | `internal/cli/namespace_test.go:28-34` | `resetCommandFlags()` does not reset `joinHostKeyFP`; a test setting `--host-key-fingerprint` without `resetRootFlags` could leak the value. | Add `joinHostKeyFP = ""` to `resetCommandFlags`. Trivial. |
|
||||||
|
| P2 | P2 (nit) | `internal/proxmox/bootstrap.go:494-510` | `ResetHostKey` uses `strings.Split` + repeated `append` (minor allocation churn). | Optional: use `bufio.Scanner` + `strings.Builder`. Not worth changing for a small file. |
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## Overall Verdict
|
||||||
|
|
||||||
|
**PASS-WITH-FOLLOWUPS**
|
||||||
|
|
||||||
|
The v0.8 milestone is correct, secure, tested, and shippable. All 4 GRILL
|
||||||
|
binding conditions are satisfied. Zero P0 issues. The single P1 (concurrent
|
||||||
|
`known_hosts` write race, A2) is a real but low-likelihood gap appropriate
|
||||||
|
for post-hoc follow-up — it does not block the milestone ship because orca
|
||||||
|
is a single-operator CLI and the atomic-rename guarantees the file is never
|
||||||
|
corrupted (only a captured line can be lost, recoverable on re-connect).
|
||||||
|
The 2 P2 nits are cosmetic. Coverage held post-P02 (86.5%/76.7%/70.4% for
|
||||||
|
proxmox/cli/doctor), race tests pass, all 7 T02.10 e2e cases are present and
|
||||||
|
exercised through a real in-process SSH server, and `make verify-reqs`
|
||||||
|
passes on the current repo (60 consistent rows).
|
||||||
|
|
||||||
|
Recommend proceeding to P04 ship (T04.7/T04.8: mark REQ-057..060 Complete +
|
||||||
|
ROADMAP v0.8 COMPLETE, then tag v0.7.4).
|
||||||
+209
-5
@@ -113,7 +113,7 @@ branch-strategy.md. The milestone branch label uses the milestone
|
|||||||
number (`milestone/v0.6-node-bootstrap-proxmox`); no separate minor
|
number (`milestone/v0.6-node-bootstrap-proxmox`); no separate minor
|
||||||
tag is created.
|
tag is created.
|
||||||
|
|
||||||
## Milestone v0.7: Hardening & Completion
|
## Milestone v0.7: Hardening & Completion — **COMPLETE**
|
||||||
|
|
||||||
Scope: NFR milestone closing gaps surfaced by the v0.7 IDEATE stage —
|
Scope: NFR milestone closing gaps surfaced by the v0.7 IDEATE stage —
|
||||||
an unreachable command tree, a missing config file layer, low test
|
an unreachable command tree, a missing config file layer, low test
|
||||||
@@ -121,10 +121,10 @@ coverage in core packages, and the long-deferred pprof endpoint.
|
|||||||
|
|
||||||
- [x] Phase 0: Pre-execution (specify → clarify → research → ideate → plan) — tag `v0.6.0` (shipped)
|
- [x] Phase 0: Pre-execution (specify → clarify → research → ideate → plan) — tag `v0.6.0` (shipped)
|
||||||
- [x] Phase 1: Register `orca cert` command tree + cert_repo tests (REQ-053) — tag `v0.6.1` (shipped)
|
- [x] Phase 1: Register `orca cert` command tree + cert_repo tests (REQ-053) — tag `v0.6.1` (shipped)
|
||||||
- [ ] Phase 2: HCL config file parsing — `internal/config` package (REQ-054) — tag `v0.6.2`
|
- [x] Phase 2: HCL config file parsing — `internal/config` package (REQ-054) — tag `v0.6.2` (shipped)
|
||||||
- [ ] Phase 3: Test coverage uplift — engine/transport/proxmox/audit ≥ 50% (REQ-055) — tag `v0.6.3`
|
- [x] Phase 3: Test coverage uplift — engine/transport/proxmox/audit ≥ 50% (REQ-055) — tag `v0.6.3` (shipped)
|
||||||
- [ ] Phase 4: `--pprof` opt-in on `orca daemon` (REQ-056) — tag `v0.6.4`
|
- [x] Phase 4: `--pprof` opt-in on `orca daemon` (REQ-056) — tag `v0.6.4` (shipped)
|
||||||
- [ ] Phase 5: Final review + ship + audit (milestone release) — tag `v0.6.5`
|
- [x] Phase 5: Final review + ship + audit (milestone release) — tag `v0.6.5` (shipped)
|
||||||
|
|
||||||
**Milestone type**: NFR (all phases are fix/test/chore; no `feat` phases).
|
**Milestone type**: NFR (all phases are fix/test/chore; no `feat` phases).
|
||||||
**Milestone tag**: `v0.6.5` (final phase patch = milestone release per
|
**Milestone tag**: `v0.6.5` (final phase patch = milestone release per
|
||||||
@@ -132,3 +132,207 @@ NFR-milestone progressive-patch rule). Per-phase tags: `v0.6.0`…`v0.6.5`.
|
|||||||
Tags run on the previous minor's patch line (v0.6.x) per
|
Tags run on the previous minor's patch line (v0.6.x) per
|
||||||
branch-strategy.md. The milestone branch label uses the milestone
|
branch-strategy.md. The milestone branch label uses the milestone
|
||||||
number (`milestone/v0.7-hardening-completion`); no separate minor tag.
|
number (`milestone/v0.7-hardening-completion`); no separate minor tag.
|
||||||
|
|
||||||
|
## Milestone v0.8: Coverage & Trust Hardening — **COMPLETE**
|
||||||
|
|
||||||
|
Scope: continue the v0.7 hardening theme. v0.7 P03's ≥ 50% floor left
|
||||||
|
six packages still under 50% (engine 8.3%, proxmox 5.1%, cli 27.6%,
|
||||||
|
transport 26.3%, store 46.7%, jobspec 47.6%) and three packages with
|
||||||
|
no tests at all (`internal/audit`, `internal/certpaths`, `cmd/orca`).
|
||||||
|
v0.8 also closes the two SSH-trust "future enhancement" hooks deferred
|
||||||
|
in v0.6 (D-035 `--host-key-fingerprint` pre-pin, RESEARCH_v0.6 §80
|
||||||
|
`orca node key-reset`) and adds a requirements-hygiene gate to prevent
|
||||||
|
the stale-REQ-status drift seen after v0.7 ship.
|
||||||
|
|
||||||
|
- [x] Phase 0: Pre-execution (specify → clarify → research → plan → grill) — tag `v0.7.0` (shipped)
|
||||||
|
- [x] Phase 1: Test coverage uplift round 2 — 6 packages to ≥ 70%, 3 zero-test packages to first tests (REQ-057) — tag `v0.7.1` (shipped)
|
||||||
|
- [x] Phase 2: SSH trust hardening — `--host-key-fingerprint` pre-pin + `orca node key-reset` + TOFU bugfix + `HostKeyFingerprint` population (REQ-058, REQ-059) — tag `v0.7.2` (shipped)
|
||||||
|
- [x] Phase 3: Requirements-hygiene gate — `make verify-reqs` + verify assertion (REQ-060) — tag `v0.7.3` (shipped)
|
||||||
|
- [x] Phase 4: Final review + ship + audit (milestone release) — tag `v0.7.4` (shipped)
|
||||||
|
|
||||||
|
**Milestone type**: NFR (P01 test, P02 chore on trust surface per
|
||||||
|
D-043, P03 chore, P04 docs/review). Final phase patch IS the milestone
|
||||||
|
release per NFR-milestone progressive-patch rule. Per-phase tags:
|
||||||
|
`v0.7.0`…`v0.7.4`. Tags run on the previous minor's patch line (v0.7.x)
|
||||||
|
per branch-strategy.md. The milestone branch label uses the milestone
|
||||||
|
number (`milestone/v0.8-coverage-trust-hardening`); no separate minor
|
||||||
|
tag.
|
||||||
|
|
||||||
|
### Per-phase REQ coverage
|
||||||
|
|
||||||
|
- **P01 — Coverage uplift round 2**
|
||||||
|
- REQ-057 (raise `internal/engine`, `internal/proxmox`,
|
||||||
|
`internal/cli`, `internal/transport`, `internal/store`,
|
||||||
|
`internal/jobspec` to ≥ 70%; add first tests for `internal/audit`,
|
||||||
|
`internal/certpaths`, `cmd/orca`)
|
||||||
|
|
||||||
|
- **P02 — SSH trust hardening**
|
||||||
|
- REQ-058 (`--host-key-fingerprint <sha256>` pre-pin flag on
|
||||||
|
`orca node join --type proxmox`; fail fast on mismatch; supersedes
|
||||||
|
TOFU for pre-pinned deployments)
|
||||||
|
- REQ-059 (`orca node key-reset <node>` clears persisted SSH host
|
||||||
|
key so next `doctor proxmox`/dispatch re-pins via TOFU or
|
||||||
|
`--host-key-fingerprint`)
|
||||||
|
|
||||||
|
- **P03 — Requirements-hygiene gate**
|
||||||
|
- REQ-060 (`make verify-reqs` target + verify-stage assertion:
|
||||||
|
every REQ `Complete` in ROADMAP.md has matching `Complete` row in
|
||||||
|
REQUIREMENTS.md; enforced in CI `validate` pipeline)
|
||||||
|
|
||||||
|
### v0.8 is a continuation milestone, not a direction change
|
||||||
|
|
||||||
|
The vision ("minimalist, offline-first, CLI-first orchestration
|
||||||
|
engine") is unchanged. v0.8 closes the coverage debt left by v0.7's
|
||||||
|
50% floor and the trust-surface gaps explicitly deferred in v0.6.
|
||||||
|
|
||||||
|
## Milestone v0.9: Re-architecture Foundation & Workloads
|
||||||
|
|
||||||
|
**Scope**: This milestone SUPERSPEDES the shipped v0.1–v0.8 architecture per
|
||||||
|
the adopted PRD (`.ciagent/PRD_v0.9.md`). The re-architecture is justified on
|
||||||
|
six grounds recorded in the PROJECT.md Supersession Table: (1) the v0.8 daemon
|
||||||
|
model is operationally failing, (2) step-ca is externally mandated, (3)
|
||||||
|
multi-tenancy is a hard product requirement, (4) WASM is a hard workload
|
||||||
|
requirement, (5) SSH-push is the only viable deployment target, (6) vision
|
||||||
|
correction. The 16 load-bearing rules (R-001…R-016) are invariants. The
|
||||||
|
ci-griller reviewed the re-architecture adversarially; the user overrode the
|
||||||
|
Re-architecture Justification REPLAN with the six-part evidence basis; the
|
||||||
|
19 binding conditions (C-01..C-19) and 10 phase challenges (PC-01..PC-10)
|
||||||
|
from `GRILL_v0.9.md` are adopted as execution gates. 30 net-new requirements
|
||||||
|
(REQ-061..REQ-090) derive from `IDEATION_v0.9.md`.
|
||||||
|
|
||||||
|
**Milestone type**: feature (P01..P10 ship `feat` phases; P00/P0X are
|
||||||
|
chore/docs).
|
||||||
|
|
||||||
|
- [ ] Phase 0: Pre-execution (specify → clarify → research → ideate → plan → grill) — tag `v0.8.0` (shipped; this is the phase you are reading)
|
||||||
|
- [ ] Phase P00: Deprecation sweep + migration-ordering decision + txn-design spike + hermetic test-infra bootstrap + persona reactivation + doc banners (REQ-072, REQ-085, REQ-088, REQ-089, REQ-090; gates C-03 ✅, C-05, C-06, C-15..C-18) — tag `v0.8.1`
|
||||||
|
- [ ] Phase P0a1: Multi-namespace path resolver + config HCL demotion + known_hosts flock (REQ-063, REQ-069, REQ-070, REQ-071; gate C-07) — tag `v0.8.2`
|
||||||
|
- [ ] Phase P0a2: Namespace CRUD + inheritance engine (REQ-082) — tag `v0.8.3`
|
||||||
|
- [ ] Phase P0b: Markdown jobspec parser + dispatcher + fuzz (REQ-064, REQ-067) — tag `v0.8.4`
|
||||||
|
- [ ] Phase P0c: Job/Service/DaemonSet schemas + emitter interface (REQ-074) — tag `v0.8.5`
|
||||||
|
- [ ] Phase P01: SSH-push transport + host-path volumes (REQ-073) — tag `v0.8.6`
|
||||||
|
- [ ] Phase P02: Service block + checks + restart + Traefik emitter (REQ-077; gate C-10) — tag `v0.8.7`
|
||||||
|
- [ ] Phase P03: Update stanza (rolling/canary) — tag `v0.8.8`
|
||||||
|
- [ ] Phase P04: Lifecycle hooks (systemd ExecStop) — tag `v0.8.9`
|
||||||
|
- [ ] Phase P05: Constraints & affinity (CEL) + CLI-side scheduler (REQ-083) — tag `v0.8.10`
|
||||||
|
- [ ] Phase P06: Task groups (multi-process services) — tag `v0.8.11`
|
||||||
|
- [ ] Phase P07a: Process + podman runtimes (REQ-078) — tag `v0.8.12`
|
||||||
|
- [ ] Phase P07b: wasmtime runtime (REQ-078; **gate C-01** — CGO eval) — tag `v0.8.13`
|
||||||
|
- [ ] Phase P07c: pve-vm + pve-ct runtimes (REQ-078; extends REQ-076) — tag `v0.8.14`
|
||||||
|
- [ ] Phase P08: Socket plumbing (R-007) — tag `v0.8.15`
|
||||||
|
- [ ] Phase P09: Storage replication via Syncthing (REQ-081; **gates C-02, C-14**) — tag `v0.8.16`
|
||||||
|
- [ ] Phase P10: Lead rules + migration (REQ-076 step-ca integration) — tag `v0.8.17`
|
||||||
|
- [ ] Phase P0X: Ship + audit (REQ-062 coverage gate; REQ-068 deprecation warnings) — tag `v0.8.18`
|
||||||
|
|
||||||
|
**Milestone tag**: `v0.8.18` (final phase patch = milestone release per
|
||||||
|
feature-milestone progressive-patch rule). Per-phase tags: `v0.8.1`…`v0.8.18`.
|
||||||
|
Tags run on the previous minor's patch line (v0.8.x) per branch-strategy.md.
|
||||||
|
The milestone branch label uses the milestone number
|
||||||
|
(`milestone/v0.9-rearchitecture`); no separate minor tag.
|
||||||
|
|
||||||
|
### Per-phase REQ coverage (v0.9)
|
||||||
|
|
||||||
|
- **P00** — Deprecation/migration/test-infra/persona/docs foundation (REQ-072, REQ-085, REQ-088, REQ-089, REQ-090)
|
||||||
|
- **P0a1** — Path resolver + config demotion + known_hosts flock (REQ-063, REQ-069, REQ-070, REQ-071)
|
||||||
|
- **P0a2** — Namespace inheritance resolver (REQ-082)
|
||||||
|
- **P0b** — Markdown parser + adapter + fuzz (REQ-064, REQ-067)
|
||||||
|
- **P0c** — Schemas + emitter interface (REQ-074)
|
||||||
|
- **P01** — SSH-push transport (REQ-073)
|
||||||
|
- **P02** — Service + Traefik emitter (REQ-077)
|
||||||
|
- **P05** — CLI-side scheduler (REQ-083)
|
||||||
|
- **P07a/b/c** — Runtime abstraction (REQ-078) + step-ca integration (REQ-076)
|
||||||
|
- **P09** — Syncthing replication (REQ-081)
|
||||||
|
- **P0X** — Coverage gate (REQ-062) + deprecation warnings (REQ-068)
|
||||||
|
|
||||||
|
### v0.9 is a DIRECTION CHANGE — first in the project's history
|
||||||
|
|
||||||
|
Every prior milestone (v0.1–v0.8) explicitly said "the vision is unchanged;
|
||||||
|
this milestone is not a direction change." v0.9 is the first milestone that
|
||||||
|
reverses the vision's anti-patterns (daemon-on-every-node, internal CA,
|
||||||
|
HCL-canonical, single-namespace, no-container-runtime, no-SPIFFE). The
|
||||||
|
reversals are justified by the six-part evidence basis recorded in the
|
||||||
|
PROJECT.md Supersession Table.
|
||||||
|
|
||||||
|
## Milestone v0.10: Production Hardening
|
||||||
|
|
||||||
|
**Scope**: ship a cluster that operators can run. Builds on the v0.9
|
||||||
|
re-architecture foundation with the production-grade subsystems:
|
||||||
|
secrets, transactions, ACL/SPIFFE, backup/restore, drain, recovery, and
|
||||||
|
the v0.8→v1.0 migration.
|
||||||
|
|
||||||
|
**Milestone type**: feature (multiple `feat` phases).
|
||||||
|
|
||||||
|
- [ ] Phase 0: Pre-execution (specify → clarify → research → plan → grill) — tag `v0.9.0`
|
||||||
|
- [ ] Phase P00: CLI cache layer (REQ-062 cache floor; R-008) — tag `v0.9.1`
|
||||||
|
- [ ] Phase P01: Metrics endpoint (hand-rolled text exposition) — tag `v0.9.2`
|
||||||
|
- [ ] Phase P01.5: SPIFFE SVID minting spike (REQ-076; **gate C-08** — if spike fails, fall back to mTLS identity) — tag `v0.9.3`
|
||||||
|
- [ ] Phase P02: ACL (SPIFFE + token identities) — tag `v0.9.4`
|
||||||
|
- [ ] Phase P03: Secrets subsystem (REQ-080; **gate C-19** threat model) — tag `v0.9.5`
|
||||||
|
- [ ] Phase P04: Backup/restore (tar + signed) — tag `v0.9.6`
|
||||||
|
- [ ] Phase P05: Drain + daemon drain-and-stop (REQ-061) — tag `v0.9.7`
|
||||||
|
- [ ] Phase P06: Alloc history (CLI-side SQLite retention; REQ-071 cache DB) — tag `v0.9.8`
|
||||||
|
- [ ] Phase P07: Recovery (`orca restore`) — tag `v0.9.9`
|
||||||
|
- [ ] Phase P08: Integration tests — expand hermetic harness (REQ-087) — tag `v0.9.10`
|
||||||
|
- [ ] Phase P09: Collector + aggregator (opt-in; **gates C-11, C-12, C-14**) — tag `v0.9.11`
|
||||||
|
- [ ] Phase P10: Transactional plane (REQ-075, REQ-079; **gate C-09** orca-pull.sh failure contract) — tag `v0.9.12`
|
||||||
|
- [ ] Phase P11: `orca job lint` (REQ-084) — tag `v0.9.13`
|
||||||
|
- [ ] Phase P12: `orca job verify` (dry-run txn through lead) — tag `v0.9.14`
|
||||||
|
- [ ] Phase P13: `orca ns` subcommands (full surface) + deprecation warnings (REQ-068) — tag `v0.9.15`
|
||||||
|
- [ ] Phase P14a: v0.8→v1.0 data migration (REQ-066; **gate C-07** CA migration spec) — tag `v0.9.16`
|
||||||
|
- [ ] Phase P14b: Daemon cutover + running-allocation adoption — tag `v0.9.17`
|
||||||
|
- [ ] Phase P14c: Mixed-version tolerance + no-orca-on-server enforcement (REQ-065, REQ-086; implements C-13) — tag `v0.9.18`
|
||||||
|
- [ ] Phase P15: README quickstart (REQ-089) — tag `v0.9.19`
|
||||||
|
- [ ] Phase P15.5: Threat model + security review (**gate C-19**) — tag `v0.9.20`
|
||||||
|
- [ ] Phase P16: Final review + ship + audit — **v0.10.0 milestone release** — tag `v0.9.21` (v1.0.0 cut separately after UAT sign-off)
|
||||||
|
|
||||||
|
**Milestone tag**: `v0.10.0` (the v0.10 milestone release tag; v1.0.0 is
|
||||||
|
UAT-gated and cut separately after v0.10 completion per operator decision —
|
||||||
|
the v1.0.0 tag marks production-ready sign-off, not a separate milestone).
|
||||||
|
Per-phase patches run on the v0.9.x line per branch-strategy.md. Per-phase
|
||||||
|
tags: `v0.9.0`…`v0.9.21`.
|
||||||
|
|
||||||
|
### Per-phase REQ coverage (v0.10)
|
||||||
|
|
||||||
|
- **P00** — CLI cache (R-008)
|
||||||
|
- **P01.5** — SPIFFE spike (REQ-076; C-08)
|
||||||
|
- **P03** — Secrets (REQ-080; C-19)
|
||||||
|
- **P05** — Drain + daemon stop (REQ-061)
|
||||||
|
- **P06** — Alloc history (REQ-071 cache DB)
|
||||||
|
- **P08** — Integration tests (REQ-087)
|
||||||
|
- **P10** — Transactional plane (REQ-075, REQ-079; C-09)
|
||||||
|
- **P11** — Job lint (REQ-084)
|
||||||
|
- **P13** — ns subcommands + deprecation warnings (REQ-068)
|
||||||
|
- **P14a/b/c** — Migration (REQ-066, REQ-065, REQ-086; C-07, C-13)
|
||||||
|
- **P15** — README (REQ-089)
|
||||||
|
- **P15.5** — Threat model (C-19)
|
||||||
|
|
||||||
|
### Risk register (from grill, for ongoing monitoring)
|
||||||
|
|
||||||
|
- **step-ca single-instance SPOF** (mitigation: C-12 doc; v1.x HA via systemd failover)
|
||||||
|
- **master.key passphrase-less 0600** (mitigation: C-19 threat model; consider OS keyring in v1.x)
|
||||||
|
- **wasmtime CGO breaks cross-compile** (mitigation: C-01 spike; fallback to podman/process primary)
|
||||||
|
- **bash control plane drift** (mitigation: C-15..C-18 render-format contract + bats gate)
|
||||||
|
- **daemon cutover orphans running allocs** (mitigation: P14b split; test adoption)
|
||||||
|
- **27→35+ phase scope** (mitigation: C-04 resolved — operator decision: keep 2 milestones v0.9 + v0.10, keep all phases, v1.0 is UAT-gated after v0.10; current count v0.9=18 + v0.10=22 = 40 phases, exceeds 35 soft limit but operator accepted)
|
||||||
|
|
||||||
|
## Deferred to v1.x (out of scope for v0.10)
|
||||||
|
|
||||||
|
- `sqlite-wal-shared` state backend (R-009 abstractions ship in v1.0; backend in v1.x)
|
||||||
|
- `git` state backend
|
||||||
|
- `file+flock` state backend
|
||||||
|
- `orca cluster setup-shared` UX
|
||||||
|
- HA `step-ca` (active/passive via systemd)
|
||||||
|
- Journald log shipping (optional centralized audit)
|
||||||
|
- Network policy (`nftables` snippets)
|
||||||
|
- GPU / TPU constraints
|
||||||
|
|
||||||
|
## Deferred to v2.x (out of scope for v1.x)
|
||||||
|
|
||||||
|
- Full Nomad-HCL parser with no conversion round-trip
|
||||||
|
- Nomad-API subset for migrating existing Nomad fleets
|
||||||
|
- Nomad driver bridge
|
||||||
|
- Helm-equivalent templating (probably never)
|
||||||
|
- Service mesh beyond Traefik
|
||||||
|
- CRDs / Operators / Plugin model
|
||||||
|
- Leader-elected Raft coordinator
|
||||||
|
- External CA / Let's Encrypt / cert transparency
|
||||||
|
- Online-only features (HSTS, OCSP stapling, telemetry)
|
||||||
|
|||||||
@@ -5,9 +5,9 @@
|
|||||||
"slug": "orca",
|
"slug": "orca",
|
||||||
"name": "Orca",
|
"name": "Orca",
|
||||||
"description": "Offline/CLI-first orchestration engine (Orca) — Nomad-inspired, far simpler than Kubernetes",
|
"description": "Offline/CLI-first orchestration engine (Orca) — Nomad-inspired, far simpler than Kubernetes",
|
||||||
"milestone": "v0.7",
|
"milestone": "v0.9",
|
||||||
"phase": 0,
|
"phase": 0,
|
||||||
"milestone_type": "nfr",
|
"milestone_type": "feature",
|
||||||
"default_branch": "main",
|
"default_branch": "main",
|
||||||
"tech_stack": {
|
"tech_stack": {
|
||||||
"language": "go",
|
"language": "go",
|
||||||
|
|||||||
@@ -13,6 +13,8 @@ description: Orca — offline/CLI-first orchestration engine. Full release flow
|
|||||||
# - gosec (REQ-014, REQ-040) Static analysis for Go security smells
|
# - gosec (REQ-014, REQ-040) Static analysis for Go security smells
|
||||||
# - govulncheck (REQ-014, REQ-027) Offline vuln scan of dependencies
|
# - govulncheck (REQ-014, REQ-027) Offline vuln scan of dependencies
|
||||||
# - gitleaks (REQ-039) Pre-commit-style secret scan
|
# - gitleaks (REQ-039) Pre-commit-style secret scan
|
||||||
|
# v0.8 P03 added a requirements-hygiene stage:
|
||||||
|
# - verify-reqs (REQ-060) ROADMAP COMPLETE ↔ REQUIREMENTS Complete
|
||||||
# The `test` pipeline runs with -race (REQ-031).
|
# The `test` pipeline runs with -race (REQ-031).
|
||||||
# See docs/security-scanning.md for operator-facing details.
|
# See docs/security-scanning.md for operator-facing details.
|
||||||
|
|
||||||
@@ -27,6 +29,11 @@ pipelines:
|
|||||||
- gofmt -l .
|
- gofmt -l .
|
||||||
- go vet ./...
|
- go vet ./...
|
||||||
|
|
||||||
|
- name: verify-reqs
|
||||||
|
image: golang:1.25
|
||||||
|
commands:
|
||||||
|
- make verify-reqs
|
||||||
|
|
||||||
- name: gosec
|
- name: gosec
|
||||||
image: golang:1.25
|
image: golang:1.25
|
||||||
commands:
|
commands:
|
||||||
|
|||||||
@@ -0,0 +1,2 @@
|
|||||||
|
disable=SC2086
|
||||||
|
external-sources=true
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
.PHONY: build test test-race lint fmt clean run release version changelog help security-scan
|
.PHONY: build test test-race lint fmt clean run release version changelog help security-scan verify-reqs
|
||||||
|
|
||||||
BINARY := bin/orca
|
BINARY := bin/orca
|
||||||
GOFLAGS := -trimpath
|
GOFLAGS := -trimpath
|
||||||
@@ -30,6 +30,7 @@ help:
|
|||||||
@echo " changelog Generate CHANGELOG.md from ---ci--- commit blocks"
|
@echo " changelog Generate CHANGELOG.md from ---ci--- commit blocks"
|
||||||
@echo " release Run scripts/release.sh [VERSION] — build, tar, publish"
|
@echo " release Run scripts/release.sh [VERSION] — build, tar, publish"
|
||||||
@echo " security-scan Run gosec+govulncheck+gitleaks (P03, REQ-014/027/039)"
|
@echo " security-scan Run gosec+govulncheck+gitleaks (P03, REQ-014/027/039)"
|
||||||
|
@echo " verify-reqs Assert ROADMAP COMPLETE ↔ REQUIREMENTS Complete (REQ-060)"
|
||||||
|
|
||||||
build:
|
build:
|
||||||
@mkdir -p bin
|
@mkdir -p bin
|
||||||
@@ -38,19 +39,42 @@ build:
|
|||||||
|
|
||||||
test:
|
test:
|
||||||
go test -coverprofile=coverage.out ./...
|
go test -coverprofile=coverage.out ./...
|
||||||
|
$(MAKE) test-bash
|
||||||
|
|
||||||
# test-race runs the full test suite under the race detector (REQ-031).
|
# test-race runs the full test suite under the race detector (REQ-031).
|
||||||
# Wired into the .coreci.yml `test` pipeline as well.
|
# Wired into the .coreci.yml `test` pipeline as well.
|
||||||
test-race:
|
test-race:
|
||||||
go test -race -coverprofile=coverage.out ./...
|
go test -race -coverprofile=coverage.out ./...
|
||||||
|
$(MAKE) test-bash
|
||||||
|
|
||||||
lint:
|
lint:
|
||||||
gofmt -l .
|
gofmt -l .
|
||||||
go vet ./...
|
go vet ./...
|
||||||
|
$(MAKE) lint-bash
|
||||||
|
|
||||||
fmt:
|
fmt:
|
||||||
gofmt -w .
|
gofmt -w .
|
||||||
|
|
||||||
|
# test-bash runs bats tests for shell scripts (grill C-15). Skips gracefully
|
||||||
|
# if bats is not installed.
|
||||||
|
test-bash:
|
||||||
|
@command -v bats >/dev/null 2>&1 && { \
|
||||||
|
echo "→ bats scripts/tests/*.bash"; \
|
||||||
|
bats scripts/tests/*.bash; \
|
||||||
|
} || echo "bats not installed; skipping bash tests (see scripts/tests/README.md)"
|
||||||
|
|
||||||
|
# lint-bash runs shellcheck + shfmt on shell scripts (grill C-15). Skips
|
||||||
|
# gracefully if the tools are not installed.
|
||||||
|
lint-bash:
|
||||||
|
@command -v shellcheck >/dev/null 2>&1 && { \
|
||||||
|
echo "→ shellcheck scripts/"; \
|
||||||
|
shellcheck scripts/*.sh scripts/lib/*.sh scripts/tests/*.bash || true; \
|
||||||
|
} || echo "shellcheck not installed; skipping (see scripts/tests/README.md)"
|
||||||
|
@command -v shfmt >/dev/null 2>&1 && { \
|
||||||
|
echo "→ shfmt -d scripts/"; \
|
||||||
|
shfmt -d scripts/; \
|
||||||
|
} || echo "shfmt not installed; skipping (see scripts/tests/README.md)"
|
||||||
|
|
||||||
clean:
|
clean:
|
||||||
rm -rf bin coverage.out *.tar.gz
|
rm -rf bin coverage.out *.tar.gz
|
||||||
|
|
||||||
@@ -98,3 +122,9 @@ release:
|
|||||||
# in a developer's local environment; CI requires all three).
|
# in a developer's local environment; CI requires all three).
|
||||||
security-scan:
|
security-scan:
|
||||||
./scripts/security_scan.sh
|
./scripts/security_scan.sh
|
||||||
|
|
||||||
|
# verify-reqs asserts ROADMAP milestone COMPLETE ↔ REQUIREMENTS row Complete
|
||||||
|
# consistency (REQ-060). Catches doc-vs-doc drift; code-vs-doc drift is out
|
||||||
|
# of scope (P04 audit). Exits 0 on consistency, 1 with a diff on drift.
|
||||||
|
verify-reqs:
|
||||||
|
go run ./cmd/verify-reqs .ciagent/ROADMAP.md .ciagent/REQUIREMENTS.md
|
||||||
|
|||||||
+9
-1
@@ -8,8 +8,16 @@ import (
|
|||||||
)
|
)
|
||||||
|
|
||||||
func main() {
|
func main() {
|
||||||
|
os.Exit(run())
|
||||||
|
}
|
||||||
|
|
||||||
|
// run executes the orca CLI and returns the process exit code. It is
|
||||||
|
// extracted from main so tests can exercise the error path without
|
||||||
|
// os.Exit terminating the test process.
|
||||||
|
func run() int {
|
||||||
if err := cli.Execute(); err != nil {
|
if err := cli.Execute(); err != nil {
|
||||||
fmt.Fprintf(os.Stderr, "error: %v\n", err)
|
fmt.Fprintf(os.Stderr, "error: %v\n", err)
|
||||||
os.Exit(1)
|
return 1
|
||||||
}
|
}
|
||||||
|
return 0
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,41 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"io"
|
||||||
|
"os"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestRunSuccess(t *testing.T) {
|
||||||
|
orig := os.Args
|
||||||
|
t.Cleanup(func() { os.Args = orig })
|
||||||
|
os.Args = []string{"orca", "version"}
|
||||||
|
if code := run(); code != 0 {
|
||||||
|
t.Errorf("run() = %d, want 0", code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRunError(t *testing.T) {
|
||||||
|
origArgs := os.Args
|
||||||
|
t.Cleanup(func() { os.Args = origArgs })
|
||||||
|
os.Args = []string{"orca", "job", "run", "/nonexistent/spec.hcl"}
|
||||||
|
|
||||||
|
r, w, err := os.Pipe()
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("pipe: %v", err)
|
||||||
|
}
|
||||||
|
origStderr := os.Stderr
|
||||||
|
os.Stderr = w
|
||||||
|
t.Cleanup(func() { os.Stderr = origStderr })
|
||||||
|
|
||||||
|
code := run()
|
||||||
|
w.Close()
|
||||||
|
out, _ := io.ReadAll(r)
|
||||||
|
if code != 1 {
|
||||||
|
t.Errorf("run() = %d, want 1", code)
|
||||||
|
}
|
||||||
|
if !strings.Contains(string(out), "error:") {
|
||||||
|
t.Errorf("stderr missing 'error:' prefix: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,183 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bufio"
|
||||||
|
"fmt"
|
||||||
|
"os"
|
||||||
|
"regexp"
|
||||||
|
"sort"
|
||||||
|
"strings"
|
||||||
|
)
|
||||||
|
|
||||||
|
// reqRowRe captures a REQUIREMENTS.md table row's REQ-ID, Phase cell, and
|
||||||
|
// status in one pass. The leading .* is greedy so it consumes the
|
||||||
|
// Requirement and Priority cells (which may contain markdown-escaped pipes
|
||||||
|
// like `localhost\|linux\|proxmox` — see REQ-049) and backtracks to anchor
|
||||||
|
// the Phase + Status match at the END of the line, where those two columns
|
||||||
|
// always live. The status token is optionally wrapped in markdown bold
|
||||||
|
// (real rows use `**Complete**`; synthetic/future rows may use bare
|
||||||
|
// `Pending`), and may carry trailing notes (e.g. "**Complete** (P01
|
||||||
|
// shipped v0.2.1)") matched by [^|]* before the closing pipe.
|
||||||
|
var reqRowRe = regexp.MustCompile(`^\|\s*(REQ-\d+)\s*\|.*\|\s*([^|]*?)\s*\|\s*\*{0,2}(Complete|Pending)\*{0,2}[^|]*\|\s*$`)
|
||||||
|
|
||||||
|
// milestoneCompleteRe matches a ROADMAP.md milestone header that is marked
|
||||||
|
// COMPLETE. The bold span is substring-tolerant (GRILL #4): it matches
|
||||||
|
// `**COMPLETE**`, `**COMPLETE (merged to main via v0.3)**`, and any future
|
||||||
|
// variant where the word COMPLETE appears inside the bold span, possibly
|
||||||
|
// preceded or followed by non-asterisk text. The milestone version (v0.X)
|
||||||
|
// is captured.
|
||||||
|
var milestoneCompleteRe = regexp.MustCompile(`^##\s*Milestone\s+(v0\.\d+):.*—\s*\*\*[^*]*\bCOMPLETE\b[^*]*\*\*`)
|
||||||
|
|
||||||
|
// phaseRe extracts the milestone version from a REQUIREMENTS Phase cell such
|
||||||
|
// as `v0.7 P1`, `**v0.2 P01**`, `v0.2 P01–P04`, or bare `v0.7`. The cell may
|
||||||
|
// contain multiple milestone refs separated by `/` or `–`; each is extracted.
|
||||||
|
var phaseTokenRe = regexp.MustCompile(`v0\.\d+`)
|
||||||
|
|
||||||
|
// reqRow holds a parsed REQUIREMENTS.md row.
|
||||||
|
type reqRow struct {
|
||||||
|
id string
|
||||||
|
phase string // raw Phase cell (e.g. "v0.7 P1", "**v0.2 P01 / v0.3 P02**")
|
||||||
|
status string // "Complete" or "Pending"
|
||||||
|
}
|
||||||
|
|
||||||
|
// milestoneVersions returns the distinct v0.X milestones referenced in the
|
||||||
|
// phase cell (e.g. "v0.7 P1" → ["v0.7"]; "v0.2 P01 / v0.3 P02" →
|
||||||
|
// ["v0.2","v0.3"]).
|
||||||
|
func (r reqRow) milestoneVersions() []string {
|
||||||
|
matches := phaseTokenRe.FindAllString(r.phase, -1)
|
||||||
|
seen := map[string]bool{}
|
||||||
|
var out []string
|
||||||
|
for _, m := range matches {
|
||||||
|
if !seen[m] {
|
||||||
|
seen[m] = true
|
||||||
|
out = append(out, m)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return out
|
||||||
|
}
|
||||||
|
|
||||||
|
func main() {
|
||||||
|
roadmapPath := ".ciagent/ROADMAP.md"
|
||||||
|
reqsPath := ".ciagent/REQUIREMENTS.md"
|
||||||
|
if len(os.Args) > 1 {
|
||||||
|
roadmapPath = os.Args[1]
|
||||||
|
}
|
||||||
|
if len(os.Args) > 2 {
|
||||||
|
reqsPath = os.Args[2]
|
||||||
|
}
|
||||||
|
diff, count, err := verify(roadmapPath, reqsPath)
|
||||||
|
if err != nil {
|
||||||
|
fmt.Fprintf(os.Stderr, "verify-reqs: %v\n", err)
|
||||||
|
os.Exit(2)
|
||||||
|
}
|
||||||
|
if len(diff) > 0 {
|
||||||
|
fmt.Fprintf(os.Stderr, "requirements drift detected (%d):\n", len(diff))
|
||||||
|
for _, line := range diff {
|
||||||
|
fmt.Fprintln(os.Stderr, line)
|
||||||
|
}
|
||||||
|
os.Exit(1)
|
||||||
|
}
|
||||||
|
fmt.Printf("✓ %d requirements consistent with roadmap\n", count)
|
||||||
|
}
|
||||||
|
|
||||||
|
// verify parses the ROADMAP and REQUIREMENTS markdown and returns a diff
|
||||||
|
// listing of any drift. On success diff is nil and count is the number of
|
||||||
|
// consistent REQ rows. A non-nil error signals a parse/read failure (not
|
||||||
|
// drift); drift is reported via the diff slice.
|
||||||
|
func verify(roadmapPath, reqsPath string) (diff []string, count int, err error) {
|
||||||
|
completeMilestones, err := parseRoadmap(roadmapPath)
|
||||||
|
if err != nil {
|
||||||
|
return nil, 0, fmt.Errorf("parse roadmap %q: %w", roadmapPath, err)
|
||||||
|
}
|
||||||
|
rows, err := parseRequirements(reqsPath)
|
||||||
|
if err != nil {
|
||||||
|
return nil, 0, fmt.Errorf("parse requirements %q: %w", reqsPath, err)
|
||||||
|
}
|
||||||
|
if len(rows) == 0 {
|
||||||
|
return nil, 0, fmt.Errorf("no REQ rows found in %s", reqsPath)
|
||||||
|
}
|
||||||
|
|
||||||
|
type driftEntry struct {
|
||||||
|
id string
|
||||||
|
current string
|
||||||
|
want string
|
||||||
|
dir string // "forward" or "reverse"
|
||||||
|
}
|
||||||
|
var drifts []driftEntry
|
||||||
|
|
||||||
|
for _, r := range rows {
|
||||||
|
milestones := r.milestoneVersions()
|
||||||
|
anyComplete := false
|
||||||
|
for _, m := range milestones {
|
||||||
|
if completeMilestones[m] {
|
||||||
|
anyComplete = true
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// Forward assertion: a REQ whose milestone is COMPLETE in ROADMAP
|
||||||
|
// must be marked Complete in REQUIREMENTS.
|
||||||
|
if anyComplete && r.status != "Complete" {
|
||||||
|
drifts = append(drifts, driftEntry{r.id, r.status, "Complete", "forward"})
|
||||||
|
}
|
||||||
|
// Reverse assertion (GRILL #4): a REQ marked Complete in
|
||||||
|
// REQUIREMENTS must reference at least one milestone ROADMAP marks
|
||||||
|
// COMPLETE. If all referenced milestones are NOT complete (or no
|
||||||
|
// milestone is referenced), that is premature-Complete drift.
|
||||||
|
if r.status == "Complete" && !anyComplete {
|
||||||
|
drifts = append(drifts, driftEntry{r.id, r.status, "Pending (milestone not COMPLETE in ROADMAP)", "reverse"})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
sort.Slice(drifts, func(i, j int) bool { return drifts[i].id < drifts[j].id })
|
||||||
|
for _, d := range drifts {
|
||||||
|
diff = append(diff, fmt.Sprintf(" %s: status=%s, expected=%s (direction=%s)", d.id, d.current, d.want, d.dir))
|
||||||
|
}
|
||||||
|
|
||||||
|
consistent := len(rows) - len(drifts)
|
||||||
|
return diff, consistent, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func parseRoadmap(path string) (map[string]bool, error) {
|
||||||
|
f, err := os.Open(path)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
defer f.Close()
|
||||||
|
complete := map[string]bool{}
|
||||||
|
sc := bufio.NewScanner(f)
|
||||||
|
sc.Buffer(make([]byte, 1024*1024), 1024*1024)
|
||||||
|
for sc.Scan() {
|
||||||
|
line := sc.Text()
|
||||||
|
m := milestoneCompleteRe.FindStringSubmatch(line)
|
||||||
|
if m != nil {
|
||||||
|
complete[m[1]] = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if err := sc.Err(); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return complete, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func parseRequirements(path string) ([]reqRow, error) {
|
||||||
|
f, err := os.Open(path)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
defer f.Close()
|
||||||
|
var rows []reqRow
|
||||||
|
sc := bufio.NewScanner(f)
|
||||||
|
sc.Buffer(make([]byte, 1024*1024), 1024*1024)
|
||||||
|
for sc.Scan() {
|
||||||
|
line := sc.Text()
|
||||||
|
m := reqRowRe.FindStringSubmatch(line)
|
||||||
|
if m == nil {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
rows = append(rows, reqRow{id: m[1], phase: strings.TrimSpace(m[2]), status: m[3]})
|
||||||
|
}
|
||||||
|
if err := sc.Err(); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return rows, nil
|
||||||
|
}
|
||||||
@@ -0,0 +1,170 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"os"
|
||||||
|
"os/exec"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// Tests run with cwd = package dir (cmd/verify-reqs), so `testdata/...`
|
||||||
|
// paths resolve relative to the package. The real-repo tests use a
|
||||||
|
// repoRoot helper to locate `.ciagent/...`.
|
||||||
|
|
||||||
|
func repoRoot(t *testing.T) string {
|
||||||
|
t.Helper()
|
||||||
|
wd, err := os.Getwd()
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("getwd: %v", err)
|
||||||
|
}
|
||||||
|
return filepath.Join(wd, "..", "..")
|
||||||
|
}
|
||||||
|
|
||||||
|
// case (1): clean pair → no drift.
|
||||||
|
func TestVerify_clean(t *testing.T) {
|
||||||
|
diff, count, err := verify(
|
||||||
|
filepath.Join("testdata", "roadmap_clean.md"),
|
||||||
|
filepath.Join("testdata", "requirements_clean.md"),
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("unexpected error: %v", err)
|
||||||
|
}
|
||||||
|
if len(diff) != 0 {
|
||||||
|
t.Fatalf("expected no drift, got:\n%s", strings.Join(diff, "\n"))
|
||||||
|
}
|
||||||
|
if count != 5 {
|
||||||
|
t.Fatalf("expected 5 consistent rows, got %d", count)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// case (2)+(3): drift pair → all drifts reported, both directions.
|
||||||
|
func TestVerify_drift(t *testing.T) {
|
||||||
|
diff, _, err := verify(
|
||||||
|
filepath.Join("testdata", "roadmap_drift.md"),
|
||||||
|
filepath.Join("testdata", "requirements_drift.md"),
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("unexpected error: %v", err)
|
||||||
|
}
|
||||||
|
if len(diff) != 4 {
|
||||||
|
t.Fatalf("expected 4 drifts (REQ-002 forward, REQ-003 reverse, REQ-004 forward, REQ-005 forward), got %d:\n%s",
|
||||||
|
len(diff), strings.Join(diff, "\n"))
|
||||||
|
}
|
||||||
|
joined := strings.Join(diff, "\n")
|
||||||
|
for _, want := range []string{"REQ-002", "REQ-003", "REQ-004", "REQ-005"} {
|
||||||
|
if !strings.Contains(joined, want) {
|
||||||
|
t.Errorf("diff missing %s:\n%s", want, joined)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !strings.Contains(joined, "direction=reverse") {
|
||||||
|
t.Errorf("expected a reverse-direction drift, got:\n%s", joined)
|
||||||
|
}
|
||||||
|
if !strings.Contains(joined, "direction=forward") {
|
||||||
|
t.Errorf("expected a forward-direction drift, got:\n%s", joined)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// case (4): missing args → defaults resolve to the repo's .ciagent/ files.
|
||||||
|
// Runs the program as a subprocess from the repo root.
|
||||||
|
func TestVerify_defaultArgs(t *testing.T) {
|
||||||
|
if testing.Short() {
|
||||||
|
t.Skip("subprocess test skipped in -short mode")
|
||||||
|
}
|
||||||
|
root := repoRoot(t)
|
||||||
|
cmd := exec.Command("go", "run", "./cmd/verify-reqs")
|
||||||
|
cmd.Dir = root
|
||||||
|
out := &strings.Builder{}
|
||||||
|
cmd.Stdout = out
|
||||||
|
cmd.Stderr = out
|
||||||
|
if err := cmd.Run(); err != nil {
|
||||||
|
if exitErr, ok := err.(*exec.ExitError); ok {
|
||||||
|
t.Fatalf("verify-reqs on real repo exited %d (should be 0): %s",
|
||||||
|
exitErr.ExitCode(), out.String())
|
||||||
|
}
|
||||||
|
t.Fatalf("go run failed: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// case (5): malformed markdown (no REQ rows) → clear error, not silent pass.
|
||||||
|
func TestVerify_malformed(t *testing.T) {
|
||||||
|
_, _, err := verify(
|
||||||
|
filepath.Join("testdata", "roadmap_clean.md"),
|
||||||
|
filepath.Join("testdata", "requirements_malformed.md"),
|
||||||
|
)
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error on malformed (no REQ rows) requirements, got nil")
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), "no REQ rows") {
|
||||||
|
t.Errorf("expected 'no REQ rows' error, got: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// case (6): missing file → clear error, not silent pass.
|
||||||
|
func TestVerify_missingFile(t *testing.T) {
|
||||||
|
_, _, err := verify(
|
||||||
|
filepath.Join("testdata", "roadmap_clean.md"),
|
||||||
|
filepath.Join("testdata", "does_not_exist.md"),
|
||||||
|
)
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error on missing file, got nil")
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), "does_not_exist.md") {
|
||||||
|
t.Errorf("expected error to mention the missing file, got: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// GRILL #4 golden test: the v0.2-style
|
||||||
|
// `**COMPLETE (merged to main via v0.3)**` header MUST be recognized as a
|
||||||
|
// complete milestone by the substring-tolerant regex. The drift fixture's
|
||||||
|
// roadmap carries exactly this header on its v0.2 line, and the drift
|
||||||
|
// fixture's REQ-002 (v0.2 P1, Pending) would be silently skipped if the
|
||||||
|
// regex regressed to the exact `\*\*COMPLETE\*\*` form. TestVerify_drift
|
||||||
|
// already asserts REQ-002 is flagged forward-drift; this test makes the
|
||||||
|
// intent explicit and guards against a regex regression.
|
||||||
|
func TestVerify_v02SubstringTolerantHeader(t *testing.T) {
|
||||||
|
diff, _, err := verify(
|
||||||
|
filepath.Join("testdata", "roadmap_drift.md"),
|
||||||
|
filepath.Join("testdata", "requirements_drift.md"),
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("unexpected error: %v", err)
|
||||||
|
}
|
||||||
|
// REQ-002 references milestone v0.2, whose header uses the
|
||||||
|
// `**COMPLETE (merged to main via v0.3)**` variant. If the regex
|
||||||
|
// regressed, v0.2 would not be marked complete and REQ-002 (Pending)
|
||||||
|
// would NOT be flagged as forward drift.
|
||||||
|
found := false
|
||||||
|
for _, d := range diff {
|
||||||
|
if strings.Contains(d, "REQ-002") && strings.Contains(d, "direction=forward") {
|
||||||
|
found = true
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !found {
|
||||||
|
t.Fatalf("REQ-002 forward drift not reported — substring-tolerant regex may have regressed; diff:\n%s",
|
||||||
|
strings.Join(diff, "\n"))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Verify the actual repo passes (regression guard for the real docs).
|
||||||
|
func TestVerify_realRepo(t *testing.T) {
|
||||||
|
if testing.Short() {
|
||||||
|
t.Skip("real-repo test skipped in -short mode")
|
||||||
|
}
|
||||||
|
root := repoRoot(t)
|
||||||
|
diff, count, err := verify(
|
||||||
|
filepath.Join(root, ".ciagent", "ROADMAP.md"),
|
||||||
|
filepath.Join(root, ".ciagent", "REQUIREMENTS.md"),
|
||||||
|
)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("verify on real repo errored: %v", err)
|
||||||
|
}
|
||||||
|
if len(diff) != 0 {
|
||||||
|
t.Fatalf("real repo has requirements drift (should be clean after SPECIFY):\n%s",
|
||||||
|
strings.Join(diff, "\n"))
|
||||||
|
}
|
||||||
|
if count <= 0 {
|
||||||
|
t.Fatalf("real repo reported %d consistent rows (expected > 0)", count)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
# Requirements: Clean Fixture
|
||||||
|
|
||||||
|
| ID | Requirement | Priority | Phase | Status |
|
||||||
|
|----|-------------|----------|-------|--------|
|
||||||
|
| REQ-001 | Foundation req | High | v0.1 P1 | **Complete** |
|
||||||
|
| REQ-002 | Multi-node with escaped pipes (kind\|os) | Medium | **v0.2 P1** | **Complete** (shipped v0.2.1) |
|
||||||
|
| REQ-003 | Scheduling req | Low | v0.3 P1 | **Complete** |
|
||||||
|
| REQ-004 | Future req spanning phases | Low | v0.2 P1 / v0.3 P2 | **Complete** (multi-phase) |
|
||||||
|
| REQ-005 | Pending future req | Low | v0.9 P1 | Pending |
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
# Requirements: Drift Fixture
|
||||||
|
|
||||||
|
| ID | Requirement | Priority | Phase | Status |
|
||||||
|
|----|-------------|----------|-------|--------|
|
||||||
|
| REQ-001 | Foundation req (clean) | High | v0.1 P1 | **Complete** |
|
||||||
|
| REQ-002 | Multi-node req (forward drift: milestone COMPLETE but row Pending) | Medium | **v0.2 P1** | Pending |
|
||||||
|
| REQ-003 | Scheduling req (reverse drift: row Complete but milestone NOT complete) | Low | v0.9 P1 | **Complete** |
|
||||||
|
| REQ-004 | Multi-phase with range (forward drift: spans COMPLETE v0.2 + non-COMPLETE v0.9) | Low | v0.2 P1–P2 | Pending |
|
||||||
|
| REQ-005 | Second forward drift (v0.3 COMPLETE, row Pending) | Low | v0.3 P1 | Pending |
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
# Requirements: Malformed Fixture
|
||||||
|
|
||||||
|
This file has no valid REQ rows, just prose and a broken table.
|
||||||
|
|
||||||
|
| ID | Requirement | Priority | Phase | Status |
|
||||||
|
|----|-------------|----------|-------|--------|
|
||||||
|
| NOT-A-REQ | broken row | High | v0.1 | **Complete** |
|
||||||
|
| REQ-999 | missing status cell | High | v0.1 |
|
||||||
+20
@@ -0,0 +1,20 @@
|
|||||||
|
# Roadmap: Clean Fixture
|
||||||
|
|
||||||
|
## Milestone v0.1: Foundation — **COMPLETE**
|
||||||
|
|
||||||
|
- [x] Phase 1
|
||||||
|
|
||||||
|
## Milestone v0.2: Networking — **COMPLETE (merged to main via v0.3)**
|
||||||
|
|
||||||
|
- [x] Phase 8
|
||||||
|
- [x] Phase 9
|
||||||
|
|
||||||
|
## Milestone v0.3: Scheduling — **COMPLETE**
|
||||||
|
|
||||||
|
- [x] Phase 1
|
||||||
|
|
||||||
|
## Milestone v0.9: Future Work
|
||||||
|
|
||||||
|
Not yet shipped.
|
||||||
|
|
||||||
|
- [ ] Phase 1
|
||||||
+20
@@ -0,0 +1,20 @@
|
|||||||
|
# Roadmap: Drift Fixture
|
||||||
|
|
||||||
|
## Milestone v0.1: Foundation — **COMPLETE**
|
||||||
|
|
||||||
|
- [x] Phase 1
|
||||||
|
|
||||||
|
## Milestone v0.2: Networking — **COMPLETE (merged to main via v0.3)**
|
||||||
|
|
||||||
|
- [x] Phase 8
|
||||||
|
- [x] Phase 9
|
||||||
|
|
||||||
|
## Milestone v0.3: Scheduling — **COMPLETE**
|
||||||
|
|
||||||
|
- [x] Phase 1
|
||||||
|
|
||||||
|
## Milestone v0.9: Future Work
|
||||||
|
|
||||||
|
Not yet shipped.
|
||||||
|
|
||||||
|
- [ ] Phase 1
|
||||||
@@ -0,0 +1,140 @@
|
|||||||
|
package audit
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"context"
|
||||||
|
"errors"
|
||||||
|
"log/slog"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/engine"
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
||||||
|
)
|
||||||
|
|
||||||
|
func newTestAudit(t *testing.T) (*Audit, *store.AuditRepo, func()) {
|
||||||
|
t.Helper()
|
||||||
|
path := filepath.Join(t.TempDir(), "test.db")
|
||||||
|
db, err := store.Open(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("open db: %v", err)
|
||||||
|
}
|
||||||
|
repo := store.NewAuditRepo(db)
|
||||||
|
eng := engine.NewAudit(repo, nil)
|
||||||
|
return New(eng), repo, func() { _ = db.Close() }
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAudit_Emit(t *testing.T) {
|
||||||
|
a, repo, cleanup := newTestAudit(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
a.Emit(ctx, ActionCertIssued, "cert:node-1", ResultSuccess, map[string]any{"cn": "node-1"})
|
||||||
|
|
||||||
|
entries, err := repo.List(ctx, 10)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("List: %v", err)
|
||||||
|
}
|
||||||
|
if len(entries) != 1 {
|
||||||
|
t.Fatalf("expected 1 audit entry, got %d", len(entries))
|
||||||
|
}
|
||||||
|
e := entries[0]
|
||||||
|
if e.Action != string(ActionCertIssued) {
|
||||||
|
t.Errorf("action: got %q, want %q", e.Action, ActionCertIssued)
|
||||||
|
}
|
||||||
|
if e.Result != string(ResultSuccess) {
|
||||||
|
t.Errorf("result: got %q, want %q", e.Result, ResultSuccess)
|
||||||
|
}
|
||||||
|
if e.Resource != "cert:node-1" {
|
||||||
|
t.Errorf("resource: got %q, want cert:node-1", e.Resource)
|
||||||
|
}
|
||||||
|
if e.Actor != "security" {
|
||||||
|
t.Errorf("actor: got %q, want security", e.Actor)
|
||||||
|
}
|
||||||
|
if e.Error != "" {
|
||||||
|
t.Errorf("error: got %q, want empty", e.Error)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAudit_EmitWithErr(t *testing.T) {
|
||||||
|
a, repo, cleanup := newTestAudit(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
a.EmitWithErr(ctx, ActionNodeHandshakeFail, "hs:node-2", errors.New("bad cert"), nil)
|
||||||
|
|
||||||
|
entries, err := repo.List(ctx, 10)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("List: %v", err)
|
||||||
|
}
|
||||||
|
if len(entries) != 1 {
|
||||||
|
t.Fatalf("expected 1 audit entry, got %d", len(entries))
|
||||||
|
}
|
||||||
|
e := entries[0]
|
||||||
|
if e.Result != string(ResultFailure) {
|
||||||
|
t.Errorf("result: got %q, want %q", e.Result, ResultFailure)
|
||||||
|
}
|
||||||
|
if !strings.Contains(e.Error, "bad cert") {
|
||||||
|
t.Errorf("error: got %q, want it to contain 'bad cert'", e.Error)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAudit_LogHandshakeOK(t *testing.T) {
|
||||||
|
var buf bytes.Buffer
|
||||||
|
logger := slog.New(slog.NewTextHandler(&buf, nil))
|
||||||
|
LogHandshakeOK(logger, "peer-1", "AA:BB:CC")
|
||||||
|
out := buf.String()
|
||||||
|
for _, want := range []string{"event=mtls.handshake", "result=ok", "peer=peer-1", "cert_fp=AA:BB:CC"} {
|
||||||
|
if !strings.Contains(out, want) {
|
||||||
|
t.Errorf("LogHandshakeOK: output missing %q\noutput: %s", want, out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAudit_LogHandshakeFailed(t *testing.T) {
|
||||||
|
var buf bytes.Buffer
|
||||||
|
logger := slog.New(slog.NewTextHandler(&buf, nil))
|
||||||
|
LogHandshakeFailed(logger, "peer-2", "", errors.New("tls: handshake"))
|
||||||
|
out := buf.String()
|
||||||
|
for _, want := range []string{"event=mtls.handshake", "result=failed", "peer=peer-2", "err=\"tls: handshake\""} {
|
||||||
|
if !strings.Contains(out, want) {
|
||||||
|
t.Errorf("LogHandshakeFailed: output missing %q\noutput: %s", want, out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAudit_LogHandshake_NilLogger(t *testing.T) {
|
||||||
|
LogHandshakeOK(nil, "p", "fp")
|
||||||
|
LogHandshakeFailed(nil, "p", "fp", errors.New("x"))
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAudit_NilSafe(t *testing.T) {
|
||||||
|
var a *Audit
|
||||||
|
a.Emit(context.Background(), ActionCertIssued, "x", ResultSuccess, nil)
|
||||||
|
a.EmitWithErr(context.Background(), ActionCertIssued, "x", errors.New("y"), nil)
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAction_String(t *testing.T) {
|
||||||
|
if got := ActionCertIssued.String(); got != "cert.issued" {
|
||||||
|
t.Errorf("ActionCertIssued.String(): got %q, want cert.issued", got)
|
||||||
|
}
|
||||||
|
if got := ActionNodeHandshakeOK.String(); got != "node.handshake_ok" {
|
||||||
|
t.Errorf("ActionNodeHandshakeOK.String(): got %q, want node.handshake_ok", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestResult_String(t *testing.T) {
|
||||||
|
if got := ResultSuccess.String(); got != "success" {
|
||||||
|
t.Errorf("ResultSuccess.String(): got %q, want success", got)
|
||||||
|
}
|
||||||
|
if got := ResultFailure.String(); got != "failure" {
|
||||||
|
t.Errorf("ResultFailure.String(): got %q, want failure", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestFormatAction(t *testing.T) {
|
||||||
|
got := FormatAction(ActionCertIssued, ResultSuccess)
|
||||||
|
want := "action=cert.issued result=success"
|
||||||
|
if got != want {
|
||||||
|
t.Errorf("FormatAction: got %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,157 @@
|
|||||||
|
package certpaths
|
||||||
|
|
||||||
|
import (
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"runtime"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestPaths_HonorORCAHOME(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
t.Setenv("ORCA_HOME", dir)
|
||||||
|
// Ensure ORCA_DB doesn't leak from the environment / prior tests.
|
||||||
|
t.Setenv("ORCA_DB", "")
|
||||||
|
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
got string
|
||||||
|
file string
|
||||||
|
}{
|
||||||
|
{"CACertPath", CACertPath(), "ca.crt"},
|
||||||
|
{"CAKeyPath", CAKeyPath(), "ca.key"},
|
||||||
|
{"ServerCertPath", ServerCertPath(), "server.crt"},
|
||||||
|
{"ServerKeyPath", ServerKeyPath(), "server.key"},
|
||||||
|
{"SSHKeyPath", SSHKeyPath(), "orca_ssh_key"},
|
||||||
|
{"SSHPubPath", SSHPubPath(), "orca_ssh_key.pub"},
|
||||||
|
{"KnownHostsPath", KnownHostsPath(), "known_hosts"},
|
||||||
|
}
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
want := filepath.Join(dir, tc.file)
|
||||||
|
if tc.got != want {
|
||||||
|
t.Errorf("%s = %q, want %q", tc.name, tc.got, want)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
// DBPath defaults to $ORCA_HOME/orca.db.
|
||||||
|
if got, want := DBPath(), filepath.Join(dir, "orca.db"); got != want {
|
||||||
|
t.Errorf("DBPath = %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Dir() returns ORCA_HOME verbatim.
|
||||||
|
if got, want := Dir(), dir; got != want {
|
||||||
|
t.Errorf("Dir = %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDBPath_OrcaDBOverride(t *testing.T) {
|
||||||
|
home := t.TempDir()
|
||||||
|
t.Setenv("ORCA_HOME", home)
|
||||||
|
custom := filepath.Join(t.TempDir(), "custom.db")
|
||||||
|
t.Setenv("ORCA_DB", custom)
|
||||||
|
|
||||||
|
if got := DBPath(); got != custom {
|
||||||
|
t.Errorf("DBPath = %q, want %q (ORCA_DB override)", got, custom)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDBPath_OrcaDBEmptyStringFallsBackToHome(t *testing.T) {
|
||||||
|
home := t.TempDir()
|
||||||
|
t.Setenv("ORCA_HOME", home)
|
||||||
|
t.Setenv("ORCA_DB", "")
|
||||||
|
|
||||||
|
want := filepath.Join(home, "orca.db")
|
||||||
|
if got := DBPath(); got != want {
|
||||||
|
t.Errorf("DBPath = %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDir_DefaultHomeFallback(t *testing.T) {
|
||||||
|
// Unset ORCA_HOME so Dir() falls back to ~/.orca.
|
||||||
|
// We can't reliably mutate the real HOME in a portable way, so just
|
||||||
|
// assert that the returned path ends with the default subdir on the
|
||||||
|
// current OS and is absolute.
|
||||||
|
os.Unsetenv("ORCA_HOME")
|
||||||
|
// Also clear ORCA_DB so DBPath's fallback to Dir() is exercised.
|
||||||
|
os.Unsetenv("ORCA_DB")
|
||||||
|
|
||||||
|
home, err := os.UserHomeDir()
|
||||||
|
if err != nil {
|
||||||
|
t.Skipf("os.UserHomeDir: %v (cannot verify default fallback)", err)
|
||||||
|
}
|
||||||
|
want := filepath.Join(home, defaultCADir)
|
||||||
|
if got := Dir(); got != want {
|
||||||
|
t.Errorf("Dir() default = %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
if got := CACertPath(); got != filepath.Join(want, "ca.crt") {
|
||||||
|
t.Errorf("CACertPath default = %q, want %q", got, filepath.Join(want, "ca.crt"))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDir_ORCAHOMEEmptyFallsBack(t *testing.T) {
|
||||||
|
// Empty string ORCA_HOME is treated as unset → ~/.orca fallback.
|
||||||
|
t.Setenv("ORCA_HOME", "")
|
||||||
|
home, err := os.UserHomeDir()
|
||||||
|
if err != nil {
|
||||||
|
t.Skipf("os.UserHomeDir: %v", err)
|
||||||
|
}
|
||||||
|
want := filepath.Join(home, defaultCADir)
|
||||||
|
if got := Dir(); got != want {
|
||||||
|
t.Errorf("Dir() with empty ORCA_HOME = %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDir_ORCAHOMERelativePath(t *testing.T) {
|
||||||
|
// A relative ORCA_HOME is honored verbatim (no cleaning/absolutizing).
|
||||||
|
t.Setenv("ORCA_HOME", "relative/orca/home")
|
||||||
|
if got, want := Dir(), "relative/orca/home"; got != want {
|
||||||
|
t.Errorf("Dir() relative = %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
// CACertPath joins the relative dir with ca.crt using filepath.Join.
|
||||||
|
if got, want := CACertPath(), filepath.Join("relative/orca/home", "ca.crt"); got != want {
|
||||||
|
t.Errorf("CACertPath relative = %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAllPaths_AreConsistentWithDir(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
t.Setenv("ORCA_HOME", dir)
|
||||||
|
t.Setenv("ORCA_DB", "")
|
||||||
|
|
||||||
|
// Every *Path() must live under Dir() except DBPath which also does.
|
||||||
|
base := Dir()
|
||||||
|
for _, p := range []string{
|
||||||
|
CACertPath(), CAKeyPath(),
|
||||||
|
ServerCertPath(), ServerKeyPath(),
|
||||||
|
SSHKeyPath(), SSHPubPath(),
|
||||||
|
KnownHostsPath(), DBPath(),
|
||||||
|
} {
|
||||||
|
if !strings.HasPrefix(p, base+string(filepath.Separator)) && p != filepath.Join(base, filepath.Base(p)) {
|
||||||
|
t.Errorf("path %q is not under Dir() %q", p, base)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSSHPaths_Filenames(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
t.Setenv("ORCA_HOME", dir)
|
||||||
|
if got, want := filepath.Base(SSHKeyPath()), "orca_ssh_key"; got != want {
|
||||||
|
t.Errorf("SSHKeyPath base = %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
if got, want := filepath.Base(SSHPubPath()), "orca_ssh_key.pub"; got != want {
|
||||||
|
t.Errorf("SSHPubPath base = %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
if got, want := filepath.Base(KnownHostsPath()), "known_hosts"; got != want {
|
||||||
|
t.Errorf("KnownHostsPath base = %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func init() {
|
||||||
|
// On Windows the default home subdir is still ".orca"; the test for
|
||||||
|
// default fallback uses os.UserHomeDir which is platform-aware. This
|
||||||
|
// guard keeps the suite from running a meaningless check on plan9.
|
||||||
|
_ = runtime.GOOS
|
||||||
|
}
|
||||||
@@ -0,0 +1,113 @@
|
|||||||
|
package cli
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"encoding/json"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/certpaths"
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestAuditListEmpty(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"audit", "list"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("audit list: %v", err)
|
||||||
|
}
|
||||||
|
if !strings.Contains(buf.String(), "No audit entries") {
|
||||||
|
t.Errorf("audit list empty output unexpected: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAuditListJSONEmpty(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"audit", "list", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("audit list --json: %v", err)
|
||||||
|
}
|
||||||
|
var entries []map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &entries); err != nil {
|
||||||
|
t.Fatalf("unmarshal audit json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if len(entries) != 0 {
|
||||||
|
t.Errorf("audit list --json empty = %d entries, want 0", len(entries))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAuditListWithEntries(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
db, err := store.Open(certpaths.DBPath())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("open db: %v", err)
|
||||||
|
}
|
||||||
|
defer db.Close()
|
||||||
|
repo := store.NewAuditRepo(db)
|
||||||
|
ctx := t.Context()
|
||||||
|
if err := repo.Append(ctx, &store.AuditEntry{
|
||||||
|
Actor: "test", Action: "test.action", Resource: "res", Result: "success",
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("append audit: %v", err)
|
||||||
|
}
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"audit", "list"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("audit list: %v", err)
|
||||||
|
}
|
||||||
|
out := buf.String()
|
||||||
|
if !strings.Contains(out, "test.action") {
|
||||||
|
t.Errorf("audit list missing entry: %s", out)
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "TIMESTAMP") {
|
||||||
|
t.Errorf("audit list missing header: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAuditListLimitFlag(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
db, err := store.Open(certpaths.DBPath())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("open db: %v", err)
|
||||||
|
}
|
||||||
|
defer db.Close()
|
||||||
|
repo := store.NewAuditRepo(db)
|
||||||
|
ctx := t.Context()
|
||||||
|
for i := 0; i < 5; i++ {
|
||||||
|
if err := repo.Append(ctx, &store.AuditEntry{
|
||||||
|
Actor: "test", Action: "test.action", Resource: "res", Result: "success",
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("append audit %d: %v", i, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"audit", "list", "--json", "--limit", "2"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("audit list --json --limit 2: %v", err)
|
||||||
|
}
|
||||||
|
var entries []map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &entries); err != nil {
|
||||||
|
t.Fatalf("unmarshal audit json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if len(entries) != 2 {
|
||||||
|
t.Errorf("audit list --limit 2 = %d entries, want 2", len(entries))
|
||||||
|
}
|
||||||
|
}
|
||||||
+15
-1
@@ -42,6 +42,11 @@ func ServerCertPath() string { return certpaths.ServerCertPath() }
|
|||||||
func ServerKeyPath() string { return certpaths.ServerKeyPath() }
|
func ServerKeyPath() string { return certpaths.ServerKeyPath() }
|
||||||
|
|
||||||
// NewCommand builds the `orca cert` command tree.
|
// NewCommand builds the `orca cert` command tree.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). The `orca cert` command tree is retained for the
|
||||||
|
// dual-write window and scheduled for deletion in v0.10. See
|
||||||
|
// .ciagent/PRD_v0.9.md.
|
||||||
func NewCommand(log *slog.Logger) *cobra.Command {
|
func NewCommand(log *slog.Logger) *cobra.Command {
|
||||||
if log == nil {
|
if log == nil {
|
||||||
log = slog.Default()
|
log = slog.Default()
|
||||||
@@ -49,7 +54,16 @@ func NewCommand(log *slog.Logger) *cobra.Command {
|
|||||||
certCmd := &cobra.Command{
|
certCmd := &cobra.Command{
|
||||||
Use: "cert",
|
Use: "cert",
|
||||||
Short: "Manage orca certificates (CA, server, rotation)",
|
Short: "Manage orca certificates (CA, server, rotation)",
|
||||||
Long: "Bootstrap a local CA, generate server certs, and rotate them.",
|
Long: `Manage orca certificates (CA, server, rotation).
|
||||||
|
|
||||||
|
Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
(D-101/REQ-076). The ` + "`orca cert`" + ` command tree is retained for the
|
||||||
|
dual-write window and scheduled for deletion in v0.10. See
|
||||||
|
.ciagent/PRD_v0.9.md.`,
|
||||||
|
PersistentPreRunE: func(cmd *cobra.Command, args []string) error {
|
||||||
|
warnDeprecated("orca cert is deprecated in v0.9: step-ca (D-101) now handles CA; orca cert will be removed in v0.10 — see .ciagent/PRD_v0.9.md")
|
||||||
|
return nil
|
||||||
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
certCmd.AddCommand(newCAInitCmd(log))
|
certCmd.AddCommand(newCAInitCmd(log))
|
||||||
|
|||||||
+18
-8
@@ -4,7 +4,6 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
"log/slog"
|
|
||||||
"net/http"
|
"net/http"
|
||||||
"os"
|
"os"
|
||||||
"os/signal"
|
"os/signal"
|
||||||
@@ -20,13 +19,20 @@ import (
|
|||||||
|
|
||||||
var (
|
var (
|
||||||
daemonAddr string
|
daemonAddr string
|
||||||
|
pprofAddr string
|
||||||
)
|
)
|
||||||
|
|
||||||
var daemonCmd = &cobra.Command{
|
var daemonCmd = &cobra.Command{
|
||||||
Use: "daemon",
|
Use: "daemon",
|
||||||
Short: "Run the orca daemon (HTTP API + health checks)",
|
Short: "Run the orca daemon (HTTP API + health checks)",
|
||||||
Long: "Start the orca daemon. Listens on the configured address for health, API, and dispatch requests.",
|
Long: `Start the orca daemon. Listens on the configured address for health, API, and dispatch requests.
|
||||||
|
|
||||||
|
Deprecated: v0.9 re-architecture replaces the orca daemon with SSH-push to
|
||||||
|
bare servers (R-001 — no orca binary on servers). The daemon is repurposed to
|
||||||
|
drain-and-stop in v0.10-P05 and scheduled for deletion in v0.10-P14. See
|
||||||
|
.ciagent/PRD_v0.9.md.`,
|
||||||
RunE: func(cmd *cobra.Command, args []string) error {
|
RunE: func(cmd *cobra.Command, args []string) error {
|
||||||
|
warnDeprecated("orca daemon is deprecated in v0.9 and will be repurposed to 'drain-and-stop' in v0.10-P05; the v0.9 re-architecture (R-001) removes the orca binary from servers — see .ciagent/PRD_v0.9.md")
|
||||||
db, closer, err := openDB()
|
db, closer, err := openDB()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
@@ -35,14 +41,15 @@ var daemonCmd = &cobra.Command{
|
|||||||
|
|
||||||
log := newLogger()
|
log := newLogger()
|
||||||
addr := daemonAddr
|
addr := daemonAddr
|
||||||
if cfg := configFromCtx(cmd.Context()); cfg != nil && cfg.ListenAddr != "" && addr == ":8080" {
|
if cfg := configFromCtx(cmd.Context()); cfg != nil && cfg.ListenAddr != "" && !cmd.Flags().Changed("addr") {
|
||||||
addr = cfg.ListenAddr
|
addr = cfg.ListenAddr
|
||||||
}
|
}
|
||||||
srv := daemon.NewServer(daemon.Options{
|
srv := daemon.NewServer(daemon.Options{
|
||||||
DB: db,
|
DB: db,
|
||||||
Log: log,
|
Log: log,
|
||||||
Addr: addr,
|
Addr: addr,
|
||||||
Actor: "daemon",
|
Actor: "daemon",
|
||||||
|
PprofAddr: pprofAddr,
|
||||||
})
|
})
|
||||||
|
|
||||||
// Wire the orca.v1.Dispatch service (v0.2 P02). The executor
|
// Wire the orca.v1.Dispatch service (v0.2 P02). The executor
|
||||||
@@ -71,6 +78,9 @@ var daemonCmd = &cobra.Command{
|
|||||||
fmt.Fprintln(cmd.OutOrStdout(), " /v1/tasks - list tasks")
|
fmt.Fprintln(cmd.OutOrStdout(), " /v1/tasks - list tasks")
|
||||||
fmt.Fprintln(cmd.OutOrStdout(), " /orca.v1.Dispatch/Submit - cross-node job submit (P02)")
|
fmt.Fprintln(cmd.OutOrStdout(), " /orca.v1.Dispatch/Submit - cross-node job submit (P02)")
|
||||||
fmt.Fprintln(cmd.OutOrStdout(), " /orca.v1.Dispatch/Status - cross-node job status (P02)")
|
fmt.Fprintln(cmd.OutOrStdout(), " /orca.v1.Dispatch/Status - cross-node job status (P02)")
|
||||||
|
if pprofAddr != "" {
|
||||||
|
fmt.Fprintf(cmd.OutOrStdout(), " /debug/pprof/ (pprof) - %s\n", pprofAddr)
|
||||||
|
}
|
||||||
fmt.Fprintln(cmd.OutOrStdout(), " press Ctrl+C to stop")
|
fmt.Fprintln(cmd.OutOrStdout(), " press Ctrl+C to stop")
|
||||||
|
|
||||||
ctx, stop := signal.NotifyContext(cmd.Context(), os.Interrupt, syscall.SIGTERM)
|
ctx, stop := signal.NotifyContext(cmd.Context(), os.Interrupt, syscall.SIGTERM)
|
||||||
@@ -90,6 +100,6 @@ var daemonCmd = &cobra.Command{
|
|||||||
|
|
||||||
func init() {
|
func init() {
|
||||||
daemonCmd.Flags().StringVar(&daemonAddr, "addr", ":8080", "listen address")
|
daemonCmd.Flags().StringVar(&daemonAddr, "addr", ":8080", "listen address")
|
||||||
|
daemonCmd.Flags().StringVar(&pprofAddr, "pprof", "", "enable pprof endpoint on <addr> (e.g. :6060); unauthenticated, operator-only")
|
||||||
rootCmd.AddCommand(daemonCmd)
|
rootCmd.AddCommand(daemonCmd)
|
||||||
_ = slog.Default // keep import if unused above
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,233 @@
|
|||||||
|
package cli
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"context"
|
||||||
|
"log/slog"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestDaemonPprofFlag(t *testing.T) {
|
||||||
|
f := daemonCmd.Flags().Lookup("pprof")
|
||||||
|
if f == nil {
|
||||||
|
t.Fatal("--pprof flag not registered on daemonCmd")
|
||||||
|
}
|
||||||
|
if f.DefValue != "" {
|
||||||
|
t.Errorf("--pprof default = %q, want empty", f.DefValue)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// captureSlog swaps slog.Default() for a text handler writing to buf,
|
||||||
|
// returning a buffer and a restore func. Tests use this to observe
|
||||||
|
// warnDeprecated output (which uses the package-level slog.Default).
|
||||||
|
func captureSlog(t *testing.T) (*bytes.Buffer, func()) {
|
||||||
|
t.Helper()
|
||||||
|
var buf bytes.Buffer
|
||||||
|
prev := slog.Default()
|
||||||
|
logger := slog.New(slog.NewTextHandler(&buf, &slog.HandlerOptions{Level: slog.LevelWarn}))
|
||||||
|
slog.SetDefault(logger)
|
||||||
|
return &buf, func() { slog.SetDefault(prev) }
|
||||||
|
}
|
||||||
|
|
||||||
|
// runDaemonHermetic invokes daemonCmd.RunE with a context that is
|
||||||
|
// already cancelled and an unbindable --addr, so the long-running
|
||||||
|
// server start short-circuits and RunE returns quickly without
|
||||||
|
// touching the network. It returns whatever RunE returned and the
|
||||||
|
// captured slog buffer.
|
||||||
|
func runDaemonHermetic(t *testing.T, suppressWarnings bool) (string, error) {
|
||||||
|
t.Helper()
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
|
||||||
|
buf, restore := captureSlog(t)
|
||||||
|
defer restore()
|
||||||
|
|
||||||
|
if suppressWarnings {
|
||||||
|
_ = rootCmd.PersistentFlags().Set("no-deprecation-warnings", "true")
|
||||||
|
}
|
||||||
|
|
||||||
|
daemonAddr = "127.0.0.1:99999" // unbindable: port outside uint16 range → ListenAndServe fails fast
|
||||||
|
|
||||||
|
ctx, cancel := context.WithCancel(context.Background())
|
||||||
|
cancel() // already-done context: the select returns via <-ctx.Done() immediately
|
||||||
|
|
||||||
|
cmd := daemonCmd
|
||||||
|
cmd.SetOut(&bytes.Buffer{})
|
||||||
|
cmd.SetErr(&bytes.Buffer{})
|
||||||
|
cmd.SetArgs(nil)
|
||||||
|
cmd.SetContext(ctx)
|
||||||
|
|
||||||
|
err := cmd.RunE(cmd, nil)
|
||||||
|
return buf.String(), err
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestDaemonEmitsDeprecationWarning verifies REQ-068: `orca daemon`
|
||||||
|
// emits a slog.Warn deprecation banner on every run.
|
||||||
|
func TestDaemonEmitsDeprecationWarning(t *testing.T) {
|
||||||
|
out, _ := runDaemonHermetic(t, false)
|
||||||
|
if !strings.Contains(out, "orca daemon is deprecated in v0.9") {
|
||||||
|
t.Errorf("expected deprecation warning in slog output, got:\n%s", out)
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "R-001") {
|
||||||
|
t.Errorf("deprecation warning should reference R-001, got:\n%s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestDaemonDeprecationWarningSuppressed verifies that
|
||||||
|
// --no-deprecation-warnings suppresses the deprecation banner (for
|
||||||
|
// `orca upgrade` migrations).
|
||||||
|
func TestDaemonDeprecationWarningSuppressed(t *testing.T) {
|
||||||
|
out, _ := runDaemonHermetic(t, true)
|
||||||
|
if strings.Contains(out, "deprecated in v0.9") {
|
||||||
|
t.Errorf("--no-deprecation-warnings should suppress the deprecation warning, got:\n%s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestDaemonStillRuns verifies deprecation ≠ removal: the daemon
|
||||||
|
// command's RunE is still wired and callable. We don't assert on the
|
||||||
|
// error value (the hermetic short-circuit may return nil or a
|
||||||
|
// shutdown-related error), only that the command did not fail *because*
|
||||||
|
// of the deprecation notice.
|
||||||
|
func TestDaemonStillRuns(t *testing.T) {
|
||||||
|
_, err := runDaemonHermetic(t, false)
|
||||||
|
if err != nil && strings.Contains(err.Error(), "deprecated") {
|
||||||
|
t.Errorf("daemon must not error due to deprecation, got: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestWarnDeprecatedGate verifies the package-level helper that gates
|
||||||
|
// deprecation warnings on the --no-deprecation-warnings flag.
|
||||||
|
func TestWarnDeprecatedGate(t *testing.T) {
|
||||||
|
t.Run("emits by default", func(t *testing.T) {
|
||||||
|
buf, restore := captureSlog(t)
|
||||||
|
defer restore()
|
||||||
|
noDeprecationWarnings = false
|
||||||
|
warnDeprecated("test-deprecation-marker")
|
||||||
|
if !strings.Contains(buf.String(), "test-deprecation-marker") {
|
||||||
|
t.Errorf("expected warning emitted, got: %s", buf.String())
|
||||||
|
}
|
||||||
|
})
|
||||||
|
t.Run("suppressed when flag set", func(t *testing.T) {
|
||||||
|
buf, restore := captureSlog(t)
|
||||||
|
defer restore()
|
||||||
|
noDeprecationWarnings = true
|
||||||
|
defer func() { noDeprecationWarnings = false }()
|
||||||
|
warnDeprecated("should-not-appear")
|
||||||
|
if strings.Contains(buf.String(), "should-not-appear") {
|
||||||
|
t.Errorf("expected no warning when --no-deprecation-warnings set, got: %s", buf.String())
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestNoDeprecationWarningsFlagRegistered verifies the
|
||||||
|
// --no-deprecation-warnings persistent flag exists on rootCmd.
|
||||||
|
func TestNoDeprecationWarningsFlagRegistered(t *testing.T) {
|
||||||
|
f := rootCmd.PersistentFlags().Lookup("no-deprecation-warnings")
|
||||||
|
if f == nil {
|
||||||
|
t.Fatal("--no-deprecation-warnings persistent flag not registered on rootCmd")
|
||||||
|
}
|
||||||
|
if f.DefValue != "false" {
|
||||||
|
t.Errorf("--no-deprecation-warnings default = %q, want false", f.DefValue)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestCertEmitsDeprecationWarning verifies REQ-068: `orca cert`
|
||||||
|
// subcommands emit a deprecation banner.
|
||||||
|
func TestCertEmitsDeprecationWarning(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
|
||||||
|
buf, restore := captureSlog(t)
|
||||||
|
defer restore()
|
||||||
|
|
||||||
|
var out bytes.Buffer
|
||||||
|
rootCmd.SetOut(&out)
|
||||||
|
rootCmd.SetErr(&out)
|
||||||
|
rootCmd.SetArgs([]string{"cert", "fingerprint", "--which", "ca"})
|
||||||
|
_ = rootCmd.Execute()
|
||||||
|
|
||||||
|
logged := buf.String()
|
||||||
|
if !strings.Contains(logged, "orca cert is deprecated in v0.9") {
|
||||||
|
t.Errorf("expected cert deprecation warning, got:\n%s", logged)
|
||||||
|
}
|
||||||
|
if !strings.Contains(logged, "step-ca") {
|
||||||
|
t.Errorf("deprecation warning should mention step-ca, got:\n%s", logged)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestCertDeprecationWarningSuppressed verifies --no-deprecation-warnings
|
||||||
|
// suppresses the cert deprecation banner.
|
||||||
|
func TestCertDeprecationWarningSuppressed(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
_ = rootCmd.PersistentFlags().Set("no-deprecation-warnings", "true")
|
||||||
|
|
||||||
|
buf, restore := captureSlog(t)
|
||||||
|
defer restore()
|
||||||
|
|
||||||
|
var out bytes.Buffer
|
||||||
|
rootCmd.SetOut(&out)
|
||||||
|
rootCmd.SetErr(&out)
|
||||||
|
rootCmd.SetArgs([]string{"cert", "fingerprint", "--which", "ca"})
|
||||||
|
_ = rootCmd.Execute()
|
||||||
|
|
||||||
|
if strings.Contains(buf.String(), "orca cert is deprecated") {
|
||||||
|
t.Errorf("--no-deprecation-warnings should suppress cert warning, got:\n%s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestNodeJoinMTLSEmitsDeprecationWarning verifies REQ-068: the mTLS
|
||||||
|
// join path (`orca node join` without --type proxmox) warns that the
|
||||||
|
// mTLS join path is deprecated.
|
||||||
|
func TestNodeJoinMTLSEmitsDeprecationWarning(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
|
||||||
|
buf, restore := captureSlog(t)
|
||||||
|
defer restore()
|
||||||
|
|
||||||
|
var out bytes.Buffer
|
||||||
|
rootCmd.SetOut(&out)
|
||||||
|
rootCmd.SetErr(&out)
|
||||||
|
rootCmd.SetArgs([]string{"node", "join", "--name", "dep-warning", "--addr", "10.0.0.55:8443"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("node join: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
logged := buf.String()
|
||||||
|
if !strings.Contains(logged, "mTLS join path is deprecated") {
|
||||||
|
t.Errorf("expected mTLS join deprecation warning, got:\n%s", logged)
|
||||||
|
}
|
||||||
|
if !strings.Contains(logged, "R-001") {
|
||||||
|
t.Errorf("deprecation warning should reference R-001, got:\n%s", logged)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestNodeJoinProxmoxNoMTLSDeprecationWarning verifies the deprecation
|
||||||
|
// warning does NOT fire for the proxmox SSH path (that path is the
|
||||||
|
// v0.9 replacement, not the deprecated mTLS path).
|
||||||
|
func TestNodeJoinProxmoxNoMTLSDeprecationWarning(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
|
||||||
|
buf, restore := captureSlog(t)
|
||||||
|
defer restore()
|
||||||
|
|
||||||
|
var out bytes.Buffer
|
||||||
|
rootCmd.SetOut(&out)
|
||||||
|
rootCmd.SetErr(&out)
|
||||||
|
// proxmox path errors on missing --host before reaching the warning,
|
||||||
|
// and never calls joinLocal, so no mTLS deprecation warning fires.
|
||||||
|
rootCmd.SetArgs([]string{"node", "join", "--type", "proxmox", "--password", "x"})
|
||||||
|
_ = rootCmd.Execute()
|
||||||
|
|
||||||
|
if strings.Contains(buf.String(), "mTLS join path is deprecated") {
|
||||||
|
t.Errorf("proxmox path must not emit mTLS deprecation warning, got:\n%s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,196 @@
|
|||||||
|
package cli
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"encoding/json"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestDoctorText(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
if err := runInit(discardWriter{}); err != nil {
|
||||||
|
t.Fatalf("init: %v", err)
|
||||||
|
}
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"doctor"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("doctor: %v", err)
|
||||||
|
}
|
||||||
|
out := buf.String()
|
||||||
|
for _, want := range []string{"CA", "cert", "PASS", "WARN", "FAIL"} {
|
||||||
|
_ = want
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "CA") {
|
||||||
|
t.Errorf("doctor output missing CA check: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDoctorJSON(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
if err := runInit(discardWriter{}); err != nil {
|
||||||
|
t.Fatalf("init: %v", err)
|
||||||
|
}
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"doctor", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("doctor --json: %v", err)
|
||||||
|
}
|
||||||
|
var checks []map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &checks); err != nil {
|
||||||
|
t.Fatalf("unmarshal doctor json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if len(checks) == 0 {
|
||||||
|
t.Errorf("doctor --json returned no checks: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDoctorCertSubcommand(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
if err := runInit(discardWriter{}); err != nil {
|
||||||
|
t.Fatalf("init: %v", err)
|
||||||
|
}
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"doctor", "cert"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("doctor cert: %v", err)
|
||||||
|
}
|
||||||
|
out := buf.String()
|
||||||
|
if !strings.Contains(out, "CA") {
|
||||||
|
t.Errorf("doctor cert output missing CA: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDoctorCertJSON(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
if err := runInit(discardWriter{}); err != nil {
|
||||||
|
t.Fatalf("init: %v", err)
|
||||||
|
}
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"doctor", "cert", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("doctor cert --json: %v", err)
|
||||||
|
}
|
||||||
|
var results []map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &results); err != nil {
|
||||||
|
t.Fatalf("unmarshal doctor cert json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if len(results) == 0 {
|
||||||
|
t.Errorf("doctor cert --json returned no results: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDoctorDBSubcommand(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
if err := runInit(discardWriter{}); err != nil {
|
||||||
|
t.Fatalf("init: %v", err)
|
||||||
|
}
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"doctor", "db"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("doctor db: %v", err)
|
||||||
|
}
|
||||||
|
out := buf.String()
|
||||||
|
if !strings.Contains(out, "db") {
|
||||||
|
t.Errorf("doctor db output unexpected: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDoctorOSSubcommand(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
if err := runInit(discardWriter{}); err != nil {
|
||||||
|
t.Fatalf("init: %v", err)
|
||||||
|
}
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"doctor", "os"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("doctor os: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDoctorOSJSON(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
if err := runInit(discardWriter{}); err != nil {
|
||||||
|
t.Fatalf("init: %v", err)
|
||||||
|
}
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"doctor", "os", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("doctor os --json: %v", err)
|
||||||
|
}
|
||||||
|
var result map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &result); err != nil {
|
||||||
|
t.Fatalf("unmarshal doctor os json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if result["Name"] == nil {
|
||||||
|
t.Errorf("doctor os --json missing Name: %v", result)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDoctorNetworkSubcommand(t *testing.T) {
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"doctor", "network"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("doctor network: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDoctorProxmoxSubcommand(t *testing.T) {
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"doctor", "proxmox"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("doctor proxmox: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDoctorProxmoxJSON(t *testing.T) {
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"doctor", "proxmox", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("doctor proxmox --json: %v", err)
|
||||||
|
}
|
||||||
|
var result map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &result); err != nil {
|
||||||
|
t.Fatalf("unmarshal doctor proxmox json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if result["Name"] == nil {
|
||||||
|
t.Errorf("doctor proxmox --json missing Name: %v", result)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,312 @@
|
|||||||
|
package cli
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"encoding/json"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/certpaths"
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/model"
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
||||||
|
)
|
||||||
|
|
||||||
|
func writeJobSpec(t *testing.T, content string) string {
|
||||||
|
t.Helper()
|
||||||
|
dir := t.TempDir()
|
||||||
|
p := filepath.Join(dir, "spec.hcl")
|
||||||
|
if err := os.WriteFile(p, []byte(content), 0o644); err != nil {
|
||||||
|
t.Fatalf("write spec: %v", err)
|
||||||
|
}
|
||||||
|
return p
|
||||||
|
}
|
||||||
|
|
||||||
|
const trueJobSpec = `job "true" {}
|
||||||
|
task "t" {
|
||||||
|
command = "/bin/true"
|
||||||
|
}
|
||||||
|
`
|
||||||
|
|
||||||
|
const falseJobSpec = `job "false" {}
|
||||||
|
task "t" {
|
||||||
|
command = "/bin/false"
|
||||||
|
}
|
||||||
|
`
|
||||||
|
|
||||||
|
func TestJobRunComplete(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
spec := writeJobSpec(t, trueJobSpec)
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "run", spec})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("job run: %v", err)
|
||||||
|
}
|
||||||
|
if !strings.Contains(buf.String(), "Job complete") {
|
||||||
|
t.Errorf("job run output unexpected: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobRunCompleteJSON(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
spec := writeJobSpec(t, trueJobSpec)
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "run", spec, "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("job run --json: %v", err)
|
||||||
|
}
|
||||||
|
var result map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &result); err != nil {
|
||||||
|
t.Fatalf("unmarshal job run json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if result["status"] != "complete" {
|
||||||
|
t.Errorf("job run --json status = %v, want complete", result["status"])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobRunFailed(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
spec := writeJobSpec(t, falseJobSpec)
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "run", spec})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for failing job, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobRunFailedJSON(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
spec := writeJobSpec(t, falseJobSpec)
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "run", spec, "--json"})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for failing job --json, got nil")
|
||||||
|
}
|
||||||
|
if !strings.Contains(buf.String(), "failed") {
|
||||||
|
t.Errorf("job run --json failed output unexpected: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobRunMissingSpecFile(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "run", "/nonexistent/spec.hcl"})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for missing spec file, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobListEmpty(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "list"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("job list: %v", err)
|
||||||
|
}
|
||||||
|
if !strings.Contains(buf.String(), "No jobs") {
|
||||||
|
t.Errorf("job list empty output unexpected: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobListJSONEmpty(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "list", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("job list --json: %v", err)
|
||||||
|
}
|
||||||
|
var jobs []map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &jobs); err != nil {
|
||||||
|
t.Fatalf("unmarshal job list json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if len(jobs) != 0 {
|
||||||
|
t.Errorf("job list --json empty = %d jobs, want 0", len(jobs))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobListAfterRun(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
spec := writeJobSpec(t, trueJobSpec)
|
||||||
|
resetRootFlags(t)
|
||||||
|
rootCmd.SetArgs([]string{"job", "run", spec})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("job run: %v", err)
|
||||||
|
}
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "list"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("job list: %v", err)
|
||||||
|
}
|
||||||
|
out := buf.String()
|
||||||
|
if !strings.Contains(out, "true") {
|
||||||
|
t.Errorf("job list missing job name: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobStop(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
jobID := seedJob(t, "stopper", model.JobStatusRunning)
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "stop", jobID})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("job stop: %v", err)
|
||||||
|
}
|
||||||
|
if !strings.Contains(buf.String(), "Job stopped") {
|
||||||
|
t.Errorf("job stop output unexpected: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobStopJSON(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
jobID := seedJob(t, "jsonstopper", model.JobStatusRunning)
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "stop", jobID, "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("job stop --json: %v", err)
|
||||||
|
}
|
||||||
|
var result map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &result); err != nil {
|
||||||
|
t.Fatalf("unmarshal job stop json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if result["status"] != "stopped" {
|
||||||
|
t.Errorf("job stop --json status = %v, want stopped", result["status"])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobStopNotFound(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "stop", "nonexistent-id"})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for job stop not found, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobStopMissingID(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "stop"})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for job stop without id, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobLogsEmpty(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
jobID := seedJob(t, "logger", model.JobStatusComplete)
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "logs", jobID})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("job logs: %v", err)
|
||||||
|
}
|
||||||
|
if !strings.Contains(buf.String(), "No tasks") {
|
||||||
|
t.Errorf("job logs empty output unexpected: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobLogsJSONEmpty(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
jobID := seedJob(t, "jsonlogger", model.JobStatusComplete)
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "logs", jobID, "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("job logs --json: %v", err)
|
||||||
|
}
|
||||||
|
var tasks []map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &tasks); err != nil {
|
||||||
|
t.Fatalf("unmarshal job logs json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if len(tasks) != 0 {
|
||||||
|
t.Errorf("job logs --json empty = %d tasks, want 0", len(tasks))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobLogsMissingID(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"job", "logs"})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for job logs without id, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func seedJob(t *testing.T, name string, status model.JobStatus) string {
|
||||||
|
t.Helper()
|
||||||
|
db, err := store.Open(certpaths.DBPath())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("open db: %v", err)
|
||||||
|
}
|
||||||
|
defer db.Close()
|
||||||
|
repo := store.NewJobRepo(db)
|
||||||
|
j := &model.Job{
|
||||||
|
ID: "job-" + name,
|
||||||
|
Name: name,
|
||||||
|
Spec: "spec.hcl",
|
||||||
|
Status: status,
|
||||||
|
}
|
||||||
|
if err := repo.Insert(t.Context(), j); err != nil {
|
||||||
|
t.Fatalf("insert job: %v", err)
|
||||||
|
}
|
||||||
|
return j.ID
|
||||||
|
}
|
||||||
@@ -18,6 +18,22 @@ func resetRootFlags(t *testing.T) {
|
|||||||
rootCmd.SetErr(&buf)
|
rootCmd.SetErr(&buf)
|
||||||
_ = rootCmd.PersistentFlags().Set("system", "false")
|
_ = rootCmd.PersistentFlags().Set("system", "false")
|
||||||
_ = rootCmd.PersistentFlags().Set("json", "false")
|
_ = rootCmd.PersistentFlags().Set("json", "false")
|
||||||
|
_ = rootCmd.PersistentFlags().Set("no-deprecation-warnings", "false")
|
||||||
|
resetCommandFlags()
|
||||||
|
}
|
||||||
|
|
||||||
|
// resetCommandFlags zeroes the package-level flag-bound vars used by
|
||||||
|
// individual subcommands so tests don't leak state between runs (cobra
|
||||||
|
// parses into these globals; without a reset a prior test's value
|
||||||
|
// persists). resetRootFlags calls this; tests that exercise a single
|
||||||
|
// command without resetRootFlags may call it directly.
|
||||||
|
func resetCommandFlags() {
|
||||||
|
joinName, joinAddr, joinCAFinger, joinType = "", "", "", "localhost"
|
||||||
|
joinHost, joinSSHUser, joinPassword, proxmoxUser, proxmoxRole = "", "root", "", "orca", "OrcaOperator"
|
||||||
|
joinSSHPort, leaveID, nodeWatch = 22, "", false
|
||||||
|
stopID, runTarget, runIDKey, jobWatch = "", "", "", false
|
||||||
|
capSetCPU, capSetMem, capSetDisk, capNodeID = 0, 0, 0, ""
|
||||||
|
auditLimit = 50
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestNamespaceDefaultsToUserHome(t *testing.T) {
|
func TestNamespaceDefaultsToUserHome(t *testing.T) {
|
||||||
|
|||||||
+90
-19
@@ -45,18 +45,19 @@ func nodeRegistry() (*engine.NodeRegistry, func() error, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
var (
|
var (
|
||||||
joinName string
|
joinName string
|
||||||
joinAddr string
|
joinAddr string
|
||||||
joinCAFinger string
|
joinCAFinger string
|
||||||
joinType string
|
joinType string
|
||||||
joinHost string
|
joinHost string
|
||||||
joinSSHUser string
|
joinSSHUser string
|
||||||
joinPassword string
|
joinPassword string
|
||||||
joinSSHPort int
|
joinSSHPort int
|
||||||
proxmoxUser string
|
joinHostKeyFP string
|
||||||
proxmoxRole string
|
proxmoxUser string
|
||||||
leaveID string
|
proxmoxRole string
|
||||||
nodeWatch bool
|
leaveID string
|
||||||
|
nodeWatch bool
|
||||||
)
|
)
|
||||||
|
|
||||||
var nodeCmd = &cobra.Command{
|
var nodeCmd = &cobra.Command{
|
||||||
@@ -76,6 +77,9 @@ Node types (via --type):
|
|||||||
(deploys orca pubkey, creates orca user + PVE role +
|
(deploys orca pubkey, creates orca user + PVE role +
|
||||||
sudoers allowlist; requires --host + --password)`,
|
sudoers allowlist; requires --host + --password)`,
|
||||||
RunE: func(cmd *cobra.Command, args []string) error {
|
RunE: func(cmd *cobra.Command, args []string) error {
|
||||||
|
if joinHostKeyFP != "" && joinType != "proxmox" {
|
||||||
|
return fmt.Errorf("--host-key-fingerprint requires --type proxmox today")
|
||||||
|
}
|
||||||
if joinType == "proxmox" {
|
if joinType == "proxmox" {
|
||||||
return joinProxmox(cmd)
|
return joinProxmox(cmd)
|
||||||
}
|
}
|
||||||
@@ -85,7 +89,13 @@ Node types (via --type):
|
|||||||
|
|
||||||
// joinLocal is the existing localhost/Linux node join flow (fingerprint
|
// joinLocal is the existing localhost/Linux node join flow (fingerprint
|
||||||
// check + registry.Insert).
|
// check + registry.Insert).
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces daemon-to-daemon mTLS join
|
||||||
|
// with SSH-push bootstrap (R-001). The mTLS join path is retained for
|
||||||
|
// the dual-write window and scheduled for deletion in v0.10-P14. See
|
||||||
|
// .ciagent/PRD_v0.9.md.
|
||||||
func joinLocal(cmd *cobra.Command) error {
|
func joinLocal(cmd *cobra.Command) error {
|
||||||
|
warnDeprecated("orca node join (mTLS path): v0.9 R-001 replaces daemon-to-daemon mTLS join with SSH-push bootstrap; the mTLS join path is deprecated — see .ciagent/PRD_v0.9.md")
|
||||||
if joinName == "" {
|
if joinName == "" {
|
||||||
return fmt.Errorf("--name is required")
|
return fmt.Errorf("--name is required")
|
||||||
}
|
}
|
||||||
@@ -156,13 +166,14 @@ func joinProxmox(cmd *cobra.Command) error {
|
|||||||
defer cancel()
|
defer cancel()
|
||||||
|
|
||||||
result, err := proxmox.BootstrapProxmox(ctx, proxmox.Options{
|
result, err := proxmox.BootstrapProxmox(ctx, proxmox.Options{
|
||||||
Host: joinHost,
|
Host: joinHost,
|
||||||
SSHUser: joinSSHUser,
|
SSHUser: joinSSHUser,
|
||||||
Password: password,
|
Password: password,
|
||||||
ProxmoxUser: proxmoxUser,
|
ProxmoxUser: proxmoxUser,
|
||||||
ProxmoxRole: proxmoxRole,
|
ProxmoxRole: proxmoxRole,
|
||||||
SSHPort: joinSSHPort,
|
SSHPort: joinSSHPort,
|
||||||
Logger: newLogger(),
|
HostKeyFingerprint: joinHostKeyFP,
|
||||||
|
Logger: newLogger(),
|
||||||
})
|
})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("proxmox bootstrap: %w", err)
|
return fmt.Errorf("proxmox bootstrap: %w", err)
|
||||||
@@ -341,6 +352,64 @@ func renderNodeTable(nodes []*model.Node) string {
|
|||||||
return out
|
return out
|
||||||
}
|
}
|
||||||
|
|
||||||
|
var nodeKeyResetCmd = &cobra.Command{
|
||||||
|
Use: "key-reset <node>",
|
||||||
|
Short: "Reset the SSH known_hosts entry for a node",
|
||||||
|
Long: `Remove the pinned SSH host key for <node> from the local known_hosts
|
||||||
|
file. The next connect re-pins the key via TOFU or --host-key-fingerprint.
|
||||||
|
|
||||||
|
LOCAL ONLY (D-046): does not touch the remote host's authorized_keys.
|
||||||
|
|
||||||
|
<node> is the node name (for proxmox nodes, this is the host address).`,
|
||||||
|
Args: cobra.ExactArgs(1),
|
||||||
|
RunE: func(cmd *cobra.Command, args []string) error {
|
||||||
|
nodeArg := args[0]
|
||||||
|
|
||||||
|
registry, closer, err := nodeRegistry()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
defer closer()
|
||||||
|
|
||||||
|
ctx, cancel := context.WithTimeout(cmd.Context(), 5*time.Second)
|
||||||
|
defer cancel()
|
||||||
|
|
||||||
|
nodes, err := registry.List(ctx)
|
||||||
|
if err != nil {
|
||||||
|
return fmt.Errorf("list nodes: %w", err)
|
||||||
|
}
|
||||||
|
var node *model.Node
|
||||||
|
for _, n := range nodes {
|
||||||
|
if n.Name == nodeArg || n.ID == nodeArg {
|
||||||
|
node = n
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if node == nil {
|
||||||
|
return fmt.Errorf("node %q not found in the registry", nodeArg)
|
||||||
|
}
|
||||||
|
host := node.Name
|
||||||
|
|
||||||
|
if err := proxmox.ResetHostKey(host); err != nil {
|
||||||
|
return fmt.Errorf("reset host key: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Audit-log the reset (REQ-059): actor=cli, action=node.key_reset.
|
||||||
|
db, dbCloser, dbErr := openDB()
|
||||||
|
if dbErr == nil {
|
||||||
|
defer dbCloser()
|
||||||
|
audit := engine.NewAudit(store.NewAuditRepo(db), newLogger())
|
||||||
|
audit.Record(ctx, "cli", "node.key_reset", node.ID, "success", nil, map[string]any{
|
||||||
|
"node": node.Name,
|
||||||
|
"host": host,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
fmt.Fprintf(cmd.OutOrStdout(), "✓ Host key reset for %s (next connect will re-pin via TOFU or --host-key-fingerprint)\n", node.Name)
|
||||||
|
return nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
func init() {
|
func init() {
|
||||||
nodeJoinCmd.Flags().StringVar(&joinName, "name", "", "node name (required for --type localhost)")
|
nodeJoinCmd.Flags().StringVar(&joinName, "name", "", "node name (required for --type localhost)")
|
||||||
nodeJoinCmd.Flags().StringVar(&joinAddr, "addr", "", "node address (default localhost:8443)")
|
nodeJoinCmd.Flags().StringVar(&joinAddr, "addr", "", "node address (default localhost:8443)")
|
||||||
@@ -352,11 +421,13 @@ func init() {
|
|||||||
nodeJoinCmd.Flags().IntVar(&joinSSHPort, "ssh-port", 22, "SSH port for proxmox bootstrap (default 22)")
|
nodeJoinCmd.Flags().IntVar(&joinSSHPort, "ssh-port", 22, "SSH port for proxmox bootstrap (default 22)")
|
||||||
nodeJoinCmd.Flags().StringVar(&proxmoxUser, "proxmox-user", "orca", "Linux system user to create on the proxmox host (config-overridable)")
|
nodeJoinCmd.Flags().StringVar(&proxmoxUser, "proxmox-user", "orca", "Linux system user to create on the proxmox host (config-overridable)")
|
||||||
nodeJoinCmd.Flags().StringVar(&proxmoxRole, "proxmox-role", "OrcaOperator", "PVE custom role to create (config-overridable)")
|
nodeJoinCmd.Flags().StringVar(&proxmoxRole, "proxmox-role", "OrcaOperator", "PVE custom role to create (config-overridable)")
|
||||||
|
nodeJoinCmd.Flags().StringVar(&joinHostKeyFP, "host-key-fingerprint", "", "SSH host key SHA256:base64 fingerprint (pre-pin; supersedes TOFU for --type proxmox)")
|
||||||
nodeLeaveCmd.Flags().StringVar(&leaveID, "id", "", "node id")
|
nodeLeaveCmd.Flags().StringVar(&leaveID, "id", "", "node id")
|
||||||
nodeListCmd.Flags().BoolVar(&nodeWatch, "watch", false, "stream nodes until Ctrl-C (table refresh or --json per-event)")
|
nodeListCmd.Flags().BoolVar(&nodeWatch, "watch", false, "stream nodes until Ctrl-C (table refresh or --json per-event)")
|
||||||
|
|
||||||
nodeCmd.AddCommand(nodeJoinCmd)
|
nodeCmd.AddCommand(nodeJoinCmd)
|
||||||
nodeCmd.AddCommand(nodeLeaveCmd)
|
nodeCmd.AddCommand(nodeLeaveCmd)
|
||||||
nodeCmd.AddCommand(nodeListCmd)
|
nodeCmd.AddCommand(nodeListCmd)
|
||||||
|
nodeCmd.AddCommand(nodeKeyResetCmd)
|
||||||
rootCmd.AddCommand(nodeCmd)
|
rootCmd.AddCommand(nodeCmd)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,194 @@
|
|||||||
|
package cli
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"encoding/json"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/certpaths"
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestNodeCapacitySetMissingArgs(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "capacity", "set", "--cpu", "1000"})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for capacity set missing memory/disk, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeCapacitySet(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "capacity", "set", "--cpu", "2000", "--memory", "4096", "--disk", "51200"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("capacity set: %v", err)
|
||||||
|
}
|
||||||
|
if !strings.Contains(buf.String(), "Capacity set") {
|
||||||
|
t.Errorf("capacity set output unexpected: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeCapacitySetJSON(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "capacity", "set", "--cpu", "3000", "--memory", "8192", "--disk", "102400", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("capacity set --json: %v", err)
|
||||||
|
}
|
||||||
|
var c map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &c); err != nil {
|
||||||
|
t.Fatalf("unmarshal capacity set json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if c["NodeID"] != "self" {
|
||||||
|
t.Errorf("capacity set --json NodeID = %v, want self", c["NodeID"])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeCapacityShowNotFound(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "capacity", "show", "missing-node"})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for capacity show missing node, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeCapacityShowAfterSet(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
seedCapacity(t, "show-node", 4000, 4096, 51200)
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "capacity", "show", "show-node"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("capacity show: %v", err)
|
||||||
|
}
|
||||||
|
out := buf.String()
|
||||||
|
if !strings.Contains(out, "show-node") {
|
||||||
|
t.Errorf("capacity show missing node id: %s", out)
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "4000") {
|
||||||
|
t.Errorf("capacity show missing cpu: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeCapacityShowJSON(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
seedCapacity(t, "jsonshow-node", 4000, 4096, 51200)
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "capacity", "show", "jsonshow-node", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("capacity show --json: %v", err)
|
||||||
|
}
|
||||||
|
var c map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &c); err != nil {
|
||||||
|
t.Fatalf("unmarshal capacity show json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if c["NodeID"] != "jsonshow-node" {
|
||||||
|
t.Errorf("capacity show --json NodeID = %v, want jsonshow-node", c["NodeID"])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeCapacityListEmpty(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "capacity", "list"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("capacity list: %v", err)
|
||||||
|
}
|
||||||
|
if !strings.Contains(buf.String(), "No capacity") {
|
||||||
|
t.Errorf("capacity list empty output unexpected: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeCapacityListAfterSet(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
seedCapacity(t, "list-node", 5000, 4096, 51200)
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "capacity", "list"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("capacity list: %v", err)
|
||||||
|
}
|
||||||
|
if !strings.Contains(buf.String(), "list-node") {
|
||||||
|
t.Errorf("capacity list missing node: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeCapacityListJSON(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
seedCapacity(t, "jsonlist-node", 5000, 4096, 51200)
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "capacity", "list", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("capacity list --json: %v", err)
|
||||||
|
}
|
||||||
|
var rows []map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &rows); err != nil {
|
||||||
|
t.Fatalf("unmarshal capacity list json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
found := false
|
||||||
|
for _, r := range rows {
|
||||||
|
if r["NodeID"] == "jsonlist-node" {
|
||||||
|
found = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !found {
|
||||||
|
t.Errorf("capacity list --json missing jsonlist-node: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func seedCapacity(t *testing.T, nodeID string, cpu, mem, disk int64) {
|
||||||
|
t.Helper()
|
||||||
|
db, err := store.Open(certpaths.DBPath())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("open db: %v", err)
|
||||||
|
}
|
||||||
|
defer db.Close()
|
||||||
|
repo := store.NewCapacityRepo(db)
|
||||||
|
c := &store.NodeCapacity{
|
||||||
|
NodeID: nodeID,
|
||||||
|
CPUMillicores: cpu,
|
||||||
|
MemoryMiB: mem,
|
||||||
|
DiskMiB: disk,
|
||||||
|
}
|
||||||
|
if err := repo.Upsert(t.Context(), c); err != nil {
|
||||||
|
t.Fatalf("upsert capacity: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,496 @@
|
|||||||
|
// This file tests the `orca node` subcommand family (join/leave/list,
|
||||||
|
// capacity is covered in node_capacity_test.go). Tests execute rootCmd
|
||||||
|
// against a temp ORCA_HOME and assert stdout/stderr/exit per RESEARCH
|
||||||
|
// §1.2.
|
||||||
|
//
|
||||||
|
// daemon.go is EXCLUDED from the cli ≥70% coverage target: the daemon
|
||||||
|
// command starts a long-running mTLS server whose lifecycle is better
|
||||||
|
// covered by internal/daemon/server_test.go (already 150 LOC). The
|
||||||
|
// --pprof flag registration is verified in daemon_test.go.
|
||||||
|
package cli
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"context"
|
||||||
|
"encoding/json"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/certpaths"
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/model"
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/security"
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestNodeJoinLocalText(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "join", "--name", "worker-1", "--addr", "10.0.0.5:8443"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("node join: %v", err)
|
||||||
|
}
|
||||||
|
out := buf.String()
|
||||||
|
if !strings.Contains(out, "Node joined") {
|
||||||
|
t.Errorf("node join output unexpected: %s", out)
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "worker-1") {
|
||||||
|
t.Errorf("node join output missing name: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeJoinLocalJSON(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "join", "--name", "worker-2", "--addr", "10.0.0.6:8443", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("node join --json: %v", err)
|
||||||
|
}
|
||||||
|
var node map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &node); err != nil {
|
||||||
|
t.Fatalf("unmarshal node json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if node["name"] != "worker-2" {
|
||||||
|
t.Errorf("node join --json name = %v, want worker-2", node["name"])
|
||||||
|
}
|
||||||
|
if node["address"] != "10.0.0.6:8443" {
|
||||||
|
t.Errorf("node join --json address = %v, want 10.0.0.6:8443", node["address"])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeJoinMissingName(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "join"})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for missing --name, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeJoinDefaultAddr(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "join", "--name", "defaulter", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("node join: %v", err)
|
||||||
|
}
|
||||||
|
var node map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &node); err != nil {
|
||||||
|
t.Fatalf("unmarshal node json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if node["address"] != "localhost:8443" {
|
||||||
|
t.Errorf("node join default addr = %v, want localhost:8443", node["address"])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeJoinCAFingerprintMatch(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
if err := runInit(discardWriter{}); err != nil {
|
||||||
|
t.Fatalf("init: %v", err)
|
||||||
|
}
|
||||||
|
fp, err := security.Fingerprint(certpaths.CACertPath())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("fingerprint: %v", err)
|
||||||
|
}
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "join", "--name", "pinned", "--ca-fingerprint", fp, "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("node join with matching fingerprint: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeJoinCAFingerprintMismatch(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "join", "--name", "badpin", "--ca-fingerprint", padHex(64)})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for CA fingerprint mismatch, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeJoinCAFingerprintNoCA(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "join", "--name", "noca", "--ca-fingerprint", padHex(64)})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for missing CA with --ca-fingerprint, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeJoinProxmoxMissingHost(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "join", "--type", "proxmox", "--password", "x"})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for proxmox without --host, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeJoinProxmoxMissingPassword(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "join", "--type", "proxmox", "--host", "10.0.0.99"})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for proxmox without password, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeListEmpty(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "list"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("node list: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeListAfterJoin(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
rootCmd.SetArgs([]string{"node", "join", "--name", "lister", "--addr", "10.0.0.7:8443"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("node join: %v", err)
|
||||||
|
}
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "list"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("node list: %v", err)
|
||||||
|
}
|
||||||
|
out := buf.String()
|
||||||
|
if !strings.Contains(out, "lister") {
|
||||||
|
t.Errorf("node list missing joined node: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeListJSON(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
rootCmd.SetArgs([]string{"node", "join", "--name", "jsonlister", "--addr", "10.0.0.8:8443"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("node join: %v", err)
|
||||||
|
}
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "list", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("node list --json: %v", err)
|
||||||
|
}
|
||||||
|
var nodes []map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &nodes); err != nil {
|
||||||
|
t.Fatalf("unmarshal node list json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
found := false
|
||||||
|
for _, n := range nodes {
|
||||||
|
if n["name"] == "jsonlister" {
|
||||||
|
found = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !found {
|
||||||
|
t.Errorf("node list --json missing jsonlister: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeLeave(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
nodeID := seedNode(t, "leaver", "10.0.0.9:8443")
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "leave", nodeID})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("node leave: %v", err)
|
||||||
|
}
|
||||||
|
if !strings.Contains(buf.String(), "Node left") {
|
||||||
|
t.Errorf("node leave output unexpected: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeLeaveJSON(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
nodeID := seedNode(t, "jsonleaver", "10.0.0.10:8443")
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "leave", nodeID, "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("node leave --json: %v", err)
|
||||||
|
}
|
||||||
|
var result map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &result); err != nil {
|
||||||
|
t.Fatalf("unmarshal node leave json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if result["state"] != "left" {
|
||||||
|
t.Errorf("node leave --json state = %v, want left", result["state"])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeLeaveMissingID(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "leave"})
|
||||||
|
if err := rootCmd.Execute(); err == nil {
|
||||||
|
t.Fatal("expected error for node leave without id, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func seedNode(t *testing.T, name, addr string) string {
|
||||||
|
t.Helper()
|
||||||
|
db, err := store.Open(certpaths.DBPath())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("open db: %v", err)
|
||||||
|
}
|
||||||
|
defer db.Close()
|
||||||
|
repo := store.NewNodeRepo(db)
|
||||||
|
ctx := context.Background()
|
||||||
|
n := &model.Node{
|
||||||
|
ID: "node-" + name,
|
||||||
|
Name: name,
|
||||||
|
Address: addr,
|
||||||
|
State: model.NodeStateReady,
|
||||||
|
JoinedAt: time.Now().UTC(),
|
||||||
|
LastSeen: time.Now().UTC(),
|
||||||
|
}
|
||||||
|
if err := repo.Insert(ctx, n); err != nil {
|
||||||
|
t.Fatalf("insert node: %v", err)
|
||||||
|
}
|
||||||
|
return n.ID
|
||||||
|
}
|
||||||
|
|
||||||
|
func padHex(n int) string {
|
||||||
|
b := make([]byte, n)
|
||||||
|
for i := range b {
|
||||||
|
b[i] = 'a'
|
||||||
|
}
|
||||||
|
return string(b)
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestNodeKeyReset removes the target node's known_hosts lines, leaves
|
||||||
|
// other hosts' lines intact, and inserts an audit row (T02.8, REQ-059).
|
||||||
|
func TestNodeKeyReset(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
|
||||||
|
// Seed a proxmox node whose Name is the host address (matches the
|
||||||
|
// key-reset RunE, which uses node.Name as the known_hosts match key).
|
||||||
|
seedProxmoxNode(t, "10.0.0.1", "10.0.0.1:8443")
|
||||||
|
|
||||||
|
// Pre-populate known_hosts: 2 lines for the target + 1 for another host.
|
||||||
|
knownHosts := certpaths.KnownHostsPath()
|
||||||
|
if err := os.MkdirAll(filepath.Dir(knownHosts), 0o755); err != nil {
|
||||||
|
t.Fatalf("mkdir known_hosts dir: %v", err)
|
||||||
|
}
|
||||||
|
original := []byte("[10.0.0.1]:22 ssh-ed25519 AAAAKEY1 host1\n" +
|
||||||
|
"10.0.0.1 ssh-ed25519 AAAAKEY1ALT host1-alt\n" +
|
||||||
|
"[10.0.0.2]:22 ssh-ed25519 AAAAKEY2 host2\n")
|
||||||
|
if err := os.WriteFile(knownHosts, original, 0o600); err != nil {
|
||||||
|
t.Fatalf("write known_hosts: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "key-reset", "10.0.0.1"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("node key-reset: %v", err)
|
||||||
|
}
|
||||||
|
out := buf.String()
|
||||||
|
if !strings.Contains(out, "Host key reset for 10.0.0.1") {
|
||||||
|
t.Errorf("output missing reset confirmation: %s", out)
|
||||||
|
}
|
||||||
|
|
||||||
|
// known_hosts: target's 2 lines removed, other host's line intact.
|
||||||
|
data, err := os.ReadFile(knownHosts)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("read known_hosts: %v", err)
|
||||||
|
}
|
||||||
|
result := string(data)
|
||||||
|
if strings.Contains(result, "AAAAKEY1") {
|
||||||
|
t.Errorf("target key line 1 not removed: %s", result)
|
||||||
|
}
|
||||||
|
if strings.Contains(result, "AAAAKEY1ALT") {
|
||||||
|
t.Errorf("target key line 2 not removed: %s", result)
|
||||||
|
}
|
||||||
|
if !strings.Contains(result, "AAAAKEY2") {
|
||||||
|
t.Errorf("other host's line was removed (should be intact): %s", result)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Audit row inserted with action=node.key_reset.
|
||||||
|
db, err := store.Open(certpaths.DBPath())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("open db: %v", err)
|
||||||
|
}
|
||||||
|
defer db.Close()
|
||||||
|
entries, err := store.NewAuditRepo(db).List(context.Background(), 50)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("list audit: %v", err)
|
||||||
|
}
|
||||||
|
found := false
|
||||||
|
for _, e := range entries {
|
||||||
|
if e.Action == "node.key_reset" && strings.Contains(e.Resource, "10.0.0.1") {
|
||||||
|
found = true
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !found {
|
||||||
|
t.Errorf("audit row for node.key_reset not inserted: %+v", entries)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestNodeKeyReset_NodeNotFound verifies key-reset errors when the
|
||||||
|
// node is not in the registry (T02.8).
|
||||||
|
func TestNodeKeyReset_NodeNotFound(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"node", "key-reset", "no.such.host"})
|
||||||
|
err := rootCmd.Execute()
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for unknown node, got nil")
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), "not found") {
|
||||||
|
t.Errorf("error should mention not found, got: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func seedProxmoxNode(t *testing.T, name, addr string) string {
|
||||||
|
t.Helper()
|
||||||
|
db, err := store.Open(certpaths.DBPath())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("open db: %v", err)
|
||||||
|
}
|
||||||
|
defer db.Close()
|
||||||
|
repo := store.NewNodeRepo(db)
|
||||||
|
ctx := context.Background()
|
||||||
|
n := &model.Node{
|
||||||
|
ID: "node-" + name,
|
||||||
|
Name: name,
|
||||||
|
Address: addr,
|
||||||
|
State: model.NodeStateReady,
|
||||||
|
JoinedAt: time.Now().UTC(),
|
||||||
|
LastSeen: time.Now().UTC(),
|
||||||
|
Kind: string(model.NodeKindProxmox),
|
||||||
|
OS: "pve",
|
||||||
|
}
|
||||||
|
if err := repo.Insert(ctx, n); err != nil {
|
||||||
|
t.Fatalf("insert proxmox node: %v", err)
|
||||||
|
}
|
||||||
|
return n.ID
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestNodeJoinHostKeyFingerprintRequiresProxmox verifies T02.11:
|
||||||
|
// `orca node join --type linux --host-key-fingerprint SHA256:...`
|
||||||
|
// fails with a clear error from the D-044 RunE check. Exercises the
|
||||||
|
// cobra Execute() error path end-to-end.
|
||||||
|
func TestNodeJoinHostKeyFingerprintRequiresProxmox(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{
|
||||||
|
"node", "join",
|
||||||
|
"--type", "linux",
|
||||||
|
"--name", "linux-node",
|
||||||
|
"--host-key-fingerprint", "SHA256:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=",
|
||||||
|
})
|
||||||
|
err := rootCmd.Execute()
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for --host-key-fingerprint without --type proxmox, got nil")
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), "--host-key-fingerprint requires --type proxmox") {
|
||||||
|
t.Errorf("error should mention the --host-key-fingerprint/--type proxmox requirement, got: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestNodeJoinHostKeyFingerprintProxmoxAccepted verifies that
|
||||||
|
// --host-key-fingerprint IS accepted for --type proxmox (the RunE check
|
||||||
|
// does not reject a proxmox-type join that pins the host key). This is
|
||||||
|
// the negative-space companion to TestNodeJoinHostKeyFingerprintRequiresProxmox
|
||||||
|
// (T02.11): the validation must only reject non-proxmox types.
|
||||||
|
//
|
||||||
|
// We can't run the full bootstrap without a real SSH server, so we
|
||||||
|
// assert that the RunE check passes (no "requires --type proxmox"
|
||||||
|
// error) and the failure — if any — comes from a later stage (missing
|
||||||
|
// --host / password), not the D-044 guard.
|
||||||
|
func TestNodeJoinHostKeyFingerprintProxmoxAccepted(t *testing.T) {
|
||||||
|
_, cleanup := initTestEnv(t)
|
||||||
|
defer cleanup()
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{
|
||||||
|
"node", "join",
|
||||||
|
"--type", "proxmox",
|
||||||
|
"--host-key-fingerprint", "SHA256:AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=",
|
||||||
|
})
|
||||||
|
err := rootCmd.Execute()
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected a later-stage error (missing --host), got nil")
|
||||||
|
}
|
||||||
|
if strings.Contains(err.Error(), "requires --type proxmox") {
|
||||||
|
t.Errorf("D-044 guard wrongly rejected proxmox type: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
+16
-3
@@ -4,6 +4,7 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"log/slog"
|
||||||
"os"
|
"os"
|
||||||
|
|
||||||
"github.com/spf13/cobra"
|
"github.com/spf13/cobra"
|
||||||
@@ -50,15 +51,27 @@ over feature richness.`,
|
|||||||
}
|
}
|
||||||
|
|
||||||
var (
|
var (
|
||||||
jsonOutput bool
|
jsonOutput bool
|
||||||
systemNamespace bool
|
systemNamespace bool
|
||||||
configPath string
|
configPath string
|
||||||
|
noDeprecationWarnings bool
|
||||||
)
|
)
|
||||||
|
|
||||||
func init() {
|
func init() {
|
||||||
rootCmd.PersistentFlags().BoolVar(&jsonOutput, "json", false, "output in JSON format")
|
rootCmd.PersistentFlags().BoolVar(&jsonOutput, "json", false, "output in JSON format")
|
||||||
rootCmd.PersistentFlags().BoolVar(&systemNamespace, "system", false, "use system-level namespace root (/root/.orca) instead of user-level (~/.orca)")
|
rootCmd.PersistentFlags().BoolVar(&systemNamespace, "system", false, "use system-level namespace root (/root/.orca) instead of user-level (~/.orca)")
|
||||||
rootCmd.PersistentFlags().StringVar(&configPath, "config", "", "path to config.hcl (overrides ~/.orca/config.hcl)")
|
rootCmd.PersistentFlags().StringVar(&configPath, "config", "", "path to config.hcl (overrides ~/.orca/config.hcl)")
|
||||||
|
rootCmd.PersistentFlags().BoolVar(&noDeprecationWarnings, "no-deprecation-warnings", false, "suppress v0.9 deprecation warnings (use during `orca upgrade` migrations)")
|
||||||
|
}
|
||||||
|
|
||||||
|
// warnDeprecated emits a v0.9 deprecation warning via slog.Warn unless
|
||||||
|
// the --no-deprecation-warnings global flag is set. Callers pass a
|
||||||
|
// human-readable message describing what changed. REQ-068.
|
||||||
|
func warnDeprecated(msg string) {
|
||||||
|
if noDeprecationWarnings {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
slog.Warn(msg)
|
||||||
}
|
}
|
||||||
|
|
||||||
func configFromCtx(ctx context.Context) *config.Config {
|
func configFromCtx(ctx context.Context) *config.Config {
|
||||||
|
|||||||
@@ -0,0 +1,47 @@
|
|||||||
|
package cli
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"encoding/json"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestStatusText(t *testing.T) {
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"status"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("status: %v", err)
|
||||||
|
}
|
||||||
|
out := buf.String()
|
||||||
|
if !strings.Contains(out, "orca daemon status") {
|
||||||
|
t.Errorf("status text output unexpected: %s", out)
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "version") {
|
||||||
|
t.Errorf("status output missing version: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestStatusJSON(t *testing.T) {
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"status", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("status --json: %v", err)
|
||||||
|
}
|
||||||
|
var info map[string]any
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &info); err != nil {
|
||||||
|
t.Fatalf("unmarshal status json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if info["daemon"] != "stopped" {
|
||||||
|
t.Errorf("status json daemon = %v, want stopped", info["daemon"])
|
||||||
|
}
|
||||||
|
if info["api_addr"] != "https://localhost:8443" {
|
||||||
|
t.Errorf("status json api_addr = %v, want https://localhost:8443", info["api_addr"])
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,47 @@
|
|||||||
|
package cli
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"encoding/json"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestVersionText(t *testing.T) {
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"version"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("version: %v", err)
|
||||||
|
}
|
||||||
|
out := buf.String()
|
||||||
|
if !strings.Contains(out, "orca version") {
|
||||||
|
t.Errorf("version text output unexpected: %s", out)
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "git commit") {
|
||||||
|
t.Errorf("version output missing git commit: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestVersionJSON(t *testing.T) {
|
||||||
|
resetRootFlags(t)
|
||||||
|
var buf bytes.Buffer
|
||||||
|
rootCmd.SetOut(&buf)
|
||||||
|
rootCmd.SetErr(&buf)
|
||||||
|
rootCmd.SetArgs([]string{"version", "--json"})
|
||||||
|
if err := rootCmd.Execute(); err != nil {
|
||||||
|
t.Fatalf("version --json: %v", err)
|
||||||
|
}
|
||||||
|
var info map[string]string
|
||||||
|
if err := json.Unmarshal(bytes.TrimSpace(buf.Bytes()), &info); err != nil {
|
||||||
|
t.Fatalf("unmarshal version json: %v\n%s", err, buf.String())
|
||||||
|
}
|
||||||
|
if info["version"] == "" {
|
||||||
|
t.Errorf("version json missing version field: %v", info)
|
||||||
|
}
|
||||||
|
if info["git_commit"] == "" {
|
||||||
|
t.Errorf("version json missing git_commit field: %v", info)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,45 @@
|
|||||||
|
package daemon
|
||||||
|
|
||||||
|
import (
|
||||||
|
"errors"
|
||||||
|
"log/slog"
|
||||||
|
"net/http"
|
||||||
|
"net/http/pprof"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
func StartPprof(addr string, log *slog.Logger) (*http.Server, error) {
|
||||||
|
if addr == "" {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
mux := http.NewServeMux()
|
||||||
|
mux.HandleFunc("/debug/pprof/", pprof.Index)
|
||||||
|
mux.HandleFunc("/debug/pprof/cmdline", pprof.Cmdline)
|
||||||
|
mux.HandleFunc("/debug/pprof/profile", pprof.Profile)
|
||||||
|
mux.HandleFunc("/debug/pprof/symbol", pprof.Symbol)
|
||||||
|
mux.HandleFunc("/debug/pprof/trace", pprof.Trace)
|
||||||
|
mux.Handle("/debug/pprof/heap", pprof.Handler("heap"))
|
||||||
|
mux.Handle("/debug/pprof/goroutine", pprof.Handler("goroutine"))
|
||||||
|
mux.Handle("/debug/pprof/threadcreate", pprof.Handler("threadcreate"))
|
||||||
|
mux.Handle("/debug/pprof/block", pprof.Handler("block"))
|
||||||
|
mux.Handle("/debug/pprof/mutex", pprof.Handler("mutex"))
|
||||||
|
|
||||||
|
server := &http.Server{
|
||||||
|
Addr: addr,
|
||||||
|
Handler: mux,
|
||||||
|
ReadHeaderTimeout: 5 * time.Second,
|
||||||
|
}
|
||||||
|
|
||||||
|
log.Warn("pprof endpoint exposed",
|
||||||
|
slog.String("addr", addr),
|
||||||
|
slog.String("warning", "unauthenticated, operator-only — do not expose publicly"))
|
||||||
|
|
||||||
|
go func() {
|
||||||
|
err := server.ListenAndServe()
|
||||||
|
if err != nil && !errors.Is(err, http.ErrServerClosed) {
|
||||||
|
log.Error("pprof server stopped", slog.String("addr", addr), slog.Any("err", err))
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
|
||||||
|
return server, nil
|
||||||
|
}
|
||||||
@@ -0,0 +1,263 @@
|
|||||||
|
package daemon
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"io"
|
||||||
|
"log/slog"
|
||||||
|
"net"
|
||||||
|
"net/http"
|
||||||
|
"path/filepath"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestStartPprof_Disabled(t *testing.T) {
|
||||||
|
srv, err := StartPprof("", slog.Default())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("StartPprof(\"\", _) returned err: %v", err)
|
||||||
|
}
|
||||||
|
if srv != nil {
|
||||||
|
t.Fatalf("StartPprof(\"\", _) returned non-nil server: %v", srv)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestStartPprof_Enabled(t *testing.T) {
|
||||||
|
log := slog.New(slog.NewTextHandler(io.Discard, nil))
|
||||||
|
|
||||||
|
ln, err := net.Listen("tcp", "127.0.0.1:0")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("listen: %v", err)
|
||||||
|
}
|
||||||
|
addr := ln.Addr().String()
|
||||||
|
_ = ln.Close()
|
||||||
|
|
||||||
|
srv, err := StartPprof(addr, log)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("StartPprof returned err: %v", err)
|
||||||
|
}
|
||||||
|
if srv == nil {
|
||||||
|
t.Fatal("StartPprof returned nil server for non-empty addr")
|
||||||
|
}
|
||||||
|
t.Cleanup(func() {
|
||||||
|
ctx, cancel := context.WithTimeout(context.Background(), 2*time.Second)
|
||||||
|
defer cancel()
|
||||||
|
_ = srv.Shutdown(ctx)
|
||||||
|
})
|
||||||
|
|
||||||
|
deadline := time.Now().Add(2 * time.Second)
|
||||||
|
var base string
|
||||||
|
for time.Now().Before(deadline) {
|
||||||
|
conn, derr := net.DialTimeout("tcp", addr, 50*time.Millisecond)
|
||||||
|
if derr == nil {
|
||||||
|
_ = conn.Close()
|
||||||
|
base = "http://" + addr
|
||||||
|
break
|
||||||
|
}
|
||||||
|
time.Sleep(20 * time.Millisecond)
|
||||||
|
}
|
||||||
|
if base == "" {
|
||||||
|
t.Fatal("pprof server did not start listening")
|
||||||
|
}
|
||||||
|
|
||||||
|
client := &http.Client{Timeout: 500 * time.Millisecond}
|
||||||
|
for _, path := range []string{"/debug/pprof/", "/debug/pprof/cmdline", "/debug/pprof/heap"} {
|
||||||
|
resp, gerr := client.Get(base + path)
|
||||||
|
if gerr != nil {
|
||||||
|
t.Errorf("GET %s: %v", path, gerr)
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
_, _ = io.Copy(io.Discard, resp.Body)
|
||||||
|
_ = resp.Body.Close()
|
||||||
|
if resp.StatusCode != 200 {
|
||||||
|
t.Errorf("GET %s: expected 200, got %d", path, resp.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestStartPprof_Shutdown(t *testing.T) {
|
||||||
|
log := slog.New(slog.NewTextHandler(io.Discard, nil))
|
||||||
|
|
||||||
|
ln, err := net.Listen("tcp", "127.0.0.1:0")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("listen: %v", err)
|
||||||
|
}
|
||||||
|
addr := ln.Addr().String()
|
||||||
|
_ = ln.Close()
|
||||||
|
|
||||||
|
srv, err := StartPprof(addr, log)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("StartPprof returned err: %v", err)
|
||||||
|
}
|
||||||
|
if srv == nil {
|
||||||
|
t.Fatal("StartPprof returned nil server")
|
||||||
|
}
|
||||||
|
|
||||||
|
deadline := time.Now().Add(2 * time.Second)
|
||||||
|
for time.Now().Before(deadline) {
|
||||||
|
conn, derr := net.DialTimeout("tcp", addr, 50*time.Millisecond)
|
||||||
|
if derr == nil {
|
||||||
|
_ = conn.Close()
|
||||||
|
break
|
||||||
|
}
|
||||||
|
time.Sleep(20 * time.Millisecond)
|
||||||
|
}
|
||||||
|
|
||||||
|
ctx, cancel := context.WithTimeout(context.Background(), 2*time.Second)
|
||||||
|
defer cancel()
|
||||||
|
if err := srv.Shutdown(ctx); err != nil {
|
||||||
|
t.Fatalf("Shutdown: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
client := &http.Client{Timeout: 300 * time.Millisecond}
|
||||||
|
_, gerr := client.Get("http://" + addr + "/debug/pprof/")
|
||||||
|
if gerr == nil {
|
||||||
|
t.Error("expected GET to fail after Shutdown, but it succeeded")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestStartPprof_MuxIsolated(t *testing.T) {
|
||||||
|
log := slog.New(slog.NewTextHandler(io.Discard, nil))
|
||||||
|
|
||||||
|
ln, err := net.Listen("tcp", "127.0.0.1:0")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("listen: %v", err)
|
||||||
|
}
|
||||||
|
addr := ln.Addr().String()
|
||||||
|
_ = ln.Close()
|
||||||
|
|
||||||
|
srv, err := StartPprof(addr, log)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("StartPprof returned err: %v", err)
|
||||||
|
}
|
||||||
|
if srv == nil {
|
||||||
|
t.Fatal("StartPprof returned nil server")
|
||||||
|
}
|
||||||
|
t.Cleanup(func() {
|
||||||
|
ctx, cancel := context.WithTimeout(context.Background(), 2*time.Second)
|
||||||
|
defer cancel()
|
||||||
|
_ = srv.Shutdown(ctx)
|
||||||
|
})
|
||||||
|
|
||||||
|
deadline := time.Now().Add(2 * time.Second)
|
||||||
|
for time.Now().Before(deadline) {
|
||||||
|
conn, derr := net.DialTimeout("tcp", addr, 50*time.Millisecond)
|
||||||
|
if derr == nil {
|
||||||
|
_ = conn.Close()
|
||||||
|
break
|
||||||
|
}
|
||||||
|
time.Sleep(20 * time.Millisecond)
|
||||||
|
}
|
||||||
|
|
||||||
|
client := &http.Client{Timeout: 500 * time.Millisecond}
|
||||||
|
resp, err := client.Get("http://" + addr + "/healthz")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GET /healthz: %v", err)
|
||||||
|
}
|
||||||
|
_, _ = io.Copy(io.Discard, resp.Body)
|
||||||
|
_ = resp.Body.Close()
|
||||||
|
if resp.StatusCode != 404 {
|
||||||
|
t.Errorf("expected /healthz to 404 on pprof-only mux, got %d", resp.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestServer_WithPprof(t *testing.T) {
|
||||||
|
db, err := store.Open(filepath.Join(t.TempDir(), "pprof.db"))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("open db: %v", err)
|
||||||
|
}
|
||||||
|
defer db.Close()
|
||||||
|
|
||||||
|
log := slog.New(slog.NewTextHandler(io.Discard, nil))
|
||||||
|
|
||||||
|
ln, err := net.Listen("tcp", "127.0.0.1:0")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("listen main: %v", err)
|
||||||
|
}
|
||||||
|
mainAddr := ln.Addr().String()
|
||||||
|
|
||||||
|
pln, err := net.Listen("tcp", "127.0.0.1:0")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("listen pprof: %v", err)
|
||||||
|
}
|
||||||
|
pprofAddr := pln.Addr().String()
|
||||||
|
_ = pln.Close()
|
||||||
|
|
||||||
|
s := NewServer(Options{
|
||||||
|
DB: db,
|
||||||
|
Log: log,
|
||||||
|
Addr: mainAddr,
|
||||||
|
PprofAddr: pprofAddr,
|
||||||
|
})
|
||||||
|
s.MarkReady()
|
||||||
|
|
||||||
|
if s.pprofServer == nil {
|
||||||
|
t.Fatal("expected pprofServer to be non-nil after NewServer with PprofAddr")
|
||||||
|
}
|
||||||
|
|
||||||
|
errCh := make(chan error, 2)
|
||||||
|
go func() {
|
||||||
|
err := s.httpServer.Serve(ln)
|
||||||
|
if err != nil && err != http.ErrServerClosed {
|
||||||
|
errCh <- err
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
|
||||||
|
deadline := time.Now().Add(2 * time.Second)
|
||||||
|
for time.Now().Before(deadline) {
|
||||||
|
conn, derr := net.DialTimeout("tcp", pprofAddr, 50*time.Millisecond)
|
||||||
|
if derr == nil {
|
||||||
|
_ = conn.Close()
|
||||||
|
break
|
||||||
|
}
|
||||||
|
time.Sleep(20 * time.Millisecond)
|
||||||
|
}
|
||||||
|
|
||||||
|
client := &http.Client{Timeout: 500 * time.Millisecond}
|
||||||
|
resp, err := client.Get("http://" + mainAddr + "/healthz")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GET main /healthz: %v", err)
|
||||||
|
}
|
||||||
|
if resp.StatusCode != 200 {
|
||||||
|
t.Errorf("main /healthz: expected 200, got %d", resp.StatusCode)
|
||||||
|
}
|
||||||
|
_, _ = io.Copy(io.Discard, resp.Body)
|
||||||
|
_ = resp.Body.Close()
|
||||||
|
|
||||||
|
presp, err := client.Get("http://" + pprofAddr + "/debug/pprof/")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GET pprof /debug/pprof/: %v", err)
|
||||||
|
}
|
||||||
|
if presp.StatusCode != 200 {
|
||||||
|
t.Errorf("pprof /debug/pprof/: expected 200, got %d", presp.StatusCode)
|
||||||
|
}
|
||||||
|
_, _ = io.Copy(io.Discard, presp.Body)
|
||||||
|
_ = presp.Body.Close()
|
||||||
|
|
||||||
|
presp, err = client.Get("http://" + pprofAddr + "/healthz")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GET pprof /healthz: %v", err)
|
||||||
|
}
|
||||||
|
_, _ = io.Copy(io.Discard, presp.Body)
|
||||||
|
_ = presp.Body.Close()
|
||||||
|
if presp.StatusCode != 404 {
|
||||||
|
t.Errorf("expected /healthz 404 on pprof mux, got %d", presp.StatusCode)
|
||||||
|
}
|
||||||
|
|
||||||
|
ctx, cancel := context.WithTimeout(context.Background(), 2*time.Second)
|
||||||
|
defer cancel()
|
||||||
|
if err := s.Shutdown(ctx); err != nil {
|
||||||
|
t.Errorf("Shutdown: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
client = &http.Client{Timeout: 300 * time.Millisecond}
|
||||||
|
_, gerr := client.Get("http://" + pprofAddr + "/debug/pprof/")
|
||||||
|
if gerr == nil {
|
||||||
|
t.Error("expected pprof GET to fail after Shutdown")
|
||||||
|
}
|
||||||
|
_, merr := client.Get("http://" + mainAddr + "/healthz")
|
||||||
|
if merr == nil {
|
||||||
|
t.Error("expected main GET to fail after Shutdown")
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -9,6 +9,12 @@
|
|||||||
// - structured JSON via writeJSON
|
// - structured JSON via writeJSON
|
||||||
// - no secrets in logs
|
// - no secrets in logs
|
||||||
// - input validation on path/query/body
|
// - input validation on path/query/body
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces this with SSH-push to bare
|
||||||
|
// servers (no orca binary on servers) per R-001. The orca daemon is
|
||||||
|
// repurposed to drain-and-stop in v0.10-P05 and scheduled for deletion
|
||||||
|
// in v0.10-P14. See .ciagent/PRD_v0.9.md R-001/R-006. The dual-write
|
||||||
|
// window (REQ-090/REQ-085) keeps this package compiling until v0.10-P14.
|
||||||
package daemon
|
package daemon
|
||||||
|
|
||||||
import (
|
import (
|
||||||
@@ -29,7 +35,8 @@ type Server struct {
|
|||||||
addr string
|
addr string
|
||||||
ready atomic.Bool
|
ready atomic.Bool
|
||||||
|
|
||||||
httpServer *http.Server
|
httpServer *http.Server
|
||||||
|
pprofServer *http.Server
|
||||||
|
|
||||||
// mtls is non-nil after StartMTLS has been called; nil otherwise.
|
// mtls is non-nil after StartMTLS has been called; nil otherwise.
|
||||||
// Plaintext HTTP and mTLS are mutually exclusive — a Server is
|
// Plaintext HTTP and mTLS are mutually exclusive — a Server is
|
||||||
@@ -49,6 +56,12 @@ type Options struct {
|
|||||||
Log *slog.Logger
|
Log *slog.Logger
|
||||||
Addr string
|
Addr string
|
||||||
Actor string // used for audit logging from API requests
|
Actor string // used for audit logging from API requests
|
||||||
|
|
||||||
|
// PprofAddr enables the pprof endpoint on a separate listener
|
||||||
|
// when non-empty (e.g. "127.0.0.1:6060"). Default "" disables it.
|
||||||
|
// The pprof listener is unauthenticated and operator-only; never
|
||||||
|
// expose it publicly (AD-024).
|
||||||
|
PprofAddr string
|
||||||
}
|
}
|
||||||
|
|
||||||
// NewServer constructs a Server with the default mux and route table.
|
// NewServer constructs a Server with the default mux and route table.
|
||||||
@@ -75,6 +88,14 @@ func NewServer(opts Options) *Server {
|
|||||||
WriteTimeout: 30 * time.Second,
|
WriteTimeout: 30 * time.Second,
|
||||||
IdleTimeout: 60 * time.Second,
|
IdleTimeout: 60 * time.Second,
|
||||||
}
|
}
|
||||||
|
if opts.PprofAddr != "" {
|
||||||
|
ps, perr := StartPprof(opts.PprofAddr, opts.Log)
|
||||||
|
if perr != nil {
|
||||||
|
s.log.Error("pprof start failed", slog.String("component", "daemon"), slog.Any("err", perr))
|
||||||
|
} else {
|
||||||
|
s.pprofServer = ps
|
||||||
|
}
|
||||||
|
}
|
||||||
return s
|
return s
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -142,6 +163,11 @@ func (s *Server) Start() error {
|
|||||||
func (s *Server) Shutdown(ctx context.Context) error {
|
func (s *Server) Shutdown(ctx context.Context) error {
|
||||||
s.MarkNotReady()
|
s.MarkNotReady()
|
||||||
s.log.Info("daemon shutting down", slog.String("component", "daemon"))
|
s.log.Info("daemon shutting down", slog.String("component", "daemon"))
|
||||||
|
if s.pprofServer != nil {
|
||||||
|
if perr := s.pprofServer.Shutdown(ctx); perr != nil {
|
||||||
|
s.log.Error("pprof shutdown failed", slog.String("component", "daemon"), slog.Any("err", perr))
|
||||||
|
}
|
||||||
|
}
|
||||||
return s.httpServer.Shutdown(ctx)
|
return s.httpServer.Shutdown(ctx)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+14
-10
@@ -26,11 +26,11 @@ import (
|
|||||||
"time"
|
"time"
|
||||||
|
|
||||||
"golang.org/x/crypto/ssh"
|
"golang.org/x/crypto/ssh"
|
||||||
"golang.org/x/crypto/ssh/knownhosts"
|
|
||||||
|
|
||||||
"git.cloudinit.dev/coreci/orca/internal/certpaths"
|
"git.cloudinit.dev/coreci/orca/internal/certpaths"
|
||||||
"git.cloudinit.dev/coreci/orca/internal/model"
|
"git.cloudinit.dev/coreci/orca/internal/model"
|
||||||
"git.cloudinit.dev/coreci/orca/internal/osdetect"
|
"git.cloudinit.dev/coreci/orca/internal/osdetect"
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/proxmox"
|
||||||
"git.cloudinit.dev/coreci/orca/internal/security"
|
"git.cloudinit.dev/coreci/orca/internal/security"
|
||||||
"git.cloudinit.dev/coreci/orca/internal/store"
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
||||||
"git.cloudinit.dev/coreci/orca/internal/transport"
|
"git.cloudinit.dev/coreci/orca/internal/transport"
|
||||||
@@ -409,7 +409,19 @@ func probeProxmoxPVEVersion(ctx context.Context, host string) error {
|
|||||||
return fmt.Errorf("parse SSH key: %w", err)
|
return fmt.Errorf("parse SSH key: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
hostKeyCallback, err := knownhosts.New(certpaths.KnownHostsPath())
|
// Extract host from the node address (orca stores host:8443;
|
||||||
|
// SSH needs host:22). We dial the SSH port, not the orca daemon port.
|
||||||
|
sshHost := host
|
||||||
|
if strings.Contains(host, ":") {
|
||||||
|
sshHost = strings.SplitN(host, ":", 2)[0]
|
||||||
|
}
|
||||||
|
sshAddr := sshHost + ":22"
|
||||||
|
|
||||||
|
// Use the shared TOFU capture-fix wrapper (T02.9 — GRILL condition
|
||||||
|
// #2: doctor parity with bootstrap). Without this, a first-connect
|
||||||
|
// proxmox node (entry missing from known_hosts) fails the doctor
|
||||||
|
// probe even though it joined fine — the v0.6 ship-defect.
|
||||||
|
hostKeyCallback, err := proxmox.TOFUHostKeyCallback(sshAddr, nil)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("known_hosts: %w", err)
|
return fmt.Errorf("known_hosts: %w", err)
|
||||||
}
|
}
|
||||||
@@ -421,14 +433,6 @@ func probeProxmoxPVEVersion(ctx context.Context, host string) error {
|
|||||||
Timeout: 3 * time.Second,
|
Timeout: 3 * time.Second,
|
||||||
}
|
}
|
||||||
|
|
||||||
// Extract host from the node address (orca stores host:8443;
|
|
||||||
// SSH needs host:22). We dial the SSH port, not the orca daemon port.
|
|
||||||
sshHost := host
|
|
||||||
if strings.Contains(host, ":") {
|
|
||||||
sshHost = strings.SplitN(host, ":", 2)[0]
|
|
||||||
}
|
|
||||||
sshAddr := sshHost + ":22"
|
|
||||||
|
|
||||||
dialer := &netDialer{}
|
dialer := &netDialer{}
|
||||||
conn, err := dialer.DialContext(ctx, "tcp", sshAddr, config)
|
conn, err := dialer.DialContext(ctx, "tcp", sshAddr, config)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|||||||
@@ -2,14 +2,21 @@ package doctor
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"crypto/ed25519"
|
||||||
|
"crypto/rand"
|
||||||
|
"net"
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
|
"golang.org/x/crypto/ssh"
|
||||||
|
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/certpaths"
|
||||||
"git.cloudinit.dev/coreci/orca/internal/model"
|
"git.cloudinit.dev/coreci/orca/internal/model"
|
||||||
"git.cloudinit.dev/coreci/orca/internal/osdetect"
|
"git.cloudinit.dev/coreci/orca/internal/osdetect"
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/proxmox"
|
||||||
"git.cloudinit.dev/coreci/orca/internal/security"
|
"git.cloudinit.dev/coreci/orca/internal/security"
|
||||||
"git.cloudinit.dev/coreci/orca/internal/store"
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
||||||
)
|
)
|
||||||
@@ -396,3 +403,90 @@ func init() {
|
|||||||
// Suppress slog noise during tests.
|
// Suppress slog noise during tests.
|
||||||
_ = os.Setenv("ORCA_LOG_LEVEL", "error")
|
_ = os.Setenv("ORCA_LOG_LEVEL", "error")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// TestProxmoxCheck_FirstConnectCapturesKey verifies that the doctor
|
||||||
|
// proxmox probe uses the shared TOFU capture-fix wrapper
|
||||||
|
// (proxmox.TOFUHostKeyCallback), which captures the host key on first
|
||||||
|
// connect instead of failing with KeyError{Want:[]} (T02.9 — GRILL
|
||||||
|
// condition #2: doctor parity with bootstrap). Before T02.9, the bare
|
||||||
|
// knownhosts.New callback returned KeyError{Want:[]} on a missing
|
||||||
|
// entry and the doctor probe reported FAIL even though the node had
|
||||||
|
// joined successfully — the v0.6 ship-defect.
|
||||||
|
//
|
||||||
|
// We exercise the exact wrapper doctor.go calls against a real SSH
|
||||||
|
// server on an ephemeral port (the probe hardcodes :22, which we
|
||||||
|
// cannot bind in CI). This proves the doctor's chosen callback captures
|
||||||
|
// on first connect rather than failing — the parity guarantee.
|
||||||
|
func TestProxmoxCheck_FirstConnectCapturesKey(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
t.Setenv("ORCA_HOME", dir)
|
||||||
|
|
||||||
|
// Empty known_hosts (first-connect scenario).
|
||||||
|
if err := os.WriteFile(certpaths.KnownHostsPath(), []byte{}, 0o600); err != nil {
|
||||||
|
t.Fatalf("create known_hosts: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Start a fake SSH server on an ephemeral port whose host key is
|
||||||
|
// NOT yet in known_hosts.
|
||||||
|
ln, err := net.Listen("tcp", "127.0.0.1:0")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("listen: %v", err)
|
||||||
|
}
|
||||||
|
defer ln.Close()
|
||||||
|
_, srvPriv, err := ed25519.GenerateKey(rand.Reader)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ed25519 gen: %v", err)
|
||||||
|
}
|
||||||
|
hostSigner, err := ssh.NewSignerFromKey(srvPriv)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ssh signer: %v", err)
|
||||||
|
}
|
||||||
|
srvConfig := &ssh.ServerConfig{NoClientAuth: true}
|
||||||
|
srvConfig.AddHostKey(hostSigner)
|
||||||
|
go func() {
|
||||||
|
for {
|
||||||
|
nconn, err := ln.Accept()
|
||||||
|
if err != nil {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
go func(c net.Conn) {
|
||||||
|
defer c.Close()
|
||||||
|
_, chans, reqs, err := ssh.NewServerConn(c, srvConfig)
|
||||||
|
if err != nil {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
go ssh.DiscardRequests(reqs)
|
||||||
|
for nc := range chans {
|
||||||
|
nc.Reject(ssh.UnknownChannelType, "none")
|
||||||
|
}
|
||||||
|
}(nconn)
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
|
||||||
|
sshAddr := ln.Addr().String()
|
||||||
|
host, _, _ := net.SplitHostPort(sshAddr)
|
||||||
|
|
||||||
|
// The doctor probe now builds its HostKeyCallback via
|
||||||
|
// proxmox.TOFUHostKeyCallback(sshAddr, nil). On first connect
|
||||||
|
// (empty known_hosts) this must capture + write the key and return
|
||||||
|
// nil, NOT a KeyError — the v0.6 ship-defect fix.
|
||||||
|
cb, err := proxmox.TOFUHostKeyCallback(sshAddr, nil)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("TOFUHostKeyCallback: %v", err)
|
||||||
|
}
|
||||||
|
if err := cb(sshAddr, &net.TCPAddr{IP: net.ParseIP(host), Port: 22}, hostSigner.PublicKey()); err != nil {
|
||||||
|
t.Fatalf("first-connect doctor callback should capture (not fail): %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// The captured key must now be in known_hosts.
|
||||||
|
data, err := os.ReadFile(certpaths.KnownHostsPath())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("read known_hosts: %v", err)
|
||||||
|
}
|
||||||
|
if len(data) == 0 {
|
||||||
|
t.Error("known_hosts is empty — doctor capture-fix did not write the key (T02.9)")
|
||||||
|
}
|
||||||
|
if !strings.Contains(string(data), hostSigner.PublicKey().Type()) {
|
||||||
|
t.Errorf("known_hosts missing the captured host key type: %s", data)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -0,0 +1,80 @@
|
|||||||
|
// Package emit defines the render-format contract between Go-side emitters
|
||||||
|
// and bash-side appliers (grill C-16). Every rendered artifact is a JSON
|
||||||
|
// object with a versioned schema; both sides validate against it to prevent
|
||||||
|
// emitter/applier drift.
|
||||||
|
package emit
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"errors"
|
||||||
|
"fmt"
|
||||||
|
)
|
||||||
|
|
||||||
|
// SchemaVersion is the canonical versioned schema identifier for render
|
||||||
|
// contracts. Bump the suffix when the contract shape changes.
|
||||||
|
const SchemaVersion = "orca.emit/v1"
|
||||||
|
|
||||||
|
// Kind enumerates the rendered-artifact kinds. Each maps to an emitter
|
||||||
|
// implementation and a matching bash-side applier.
|
||||||
|
type Kind string
|
||||||
|
|
||||||
|
const (
|
||||||
|
KindSystemd Kind = "systemd"
|
||||||
|
KindTraefik Kind = "traefik"
|
||||||
|
KindSyncthing Kind = "syncthing"
|
||||||
|
KindSudoers Kind = "sudoers"
|
||||||
|
KindSSHD Kind = "sshd"
|
||||||
|
KindEnvFile Kind = "envfile"
|
||||||
|
KindCredential Kind = "credential"
|
||||||
|
)
|
||||||
|
|
||||||
|
// Artifact is a single rendered file destined for a peer. The bash-side
|
||||||
|
// applier reads this JSON and writes Content to Path with the given Mode.
|
||||||
|
type Artifact struct {
|
||||||
|
SchemaVersion string `json:"schema_version"`
|
||||||
|
Kind Kind `json:"kind"`
|
||||||
|
Path string `json:"path"`
|
||||||
|
Content string `json:"content"`
|
||||||
|
Mode string `json:"mode"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// Validate checks that an Artifact conforms to the render contract.
|
||||||
|
// Returns a structured error if any field is missing or invalid.
|
||||||
|
func (a *Artifact) Validate() error {
|
||||||
|
if a.SchemaVersion != SchemaVersion {
|
||||||
|
return fmt.Errorf("emit: schema_version mismatch: got %q want %q", a.SchemaVersion, SchemaVersion)
|
||||||
|
}
|
||||||
|
if a.Kind == "" {
|
||||||
|
return errors.New("emit: kind is required")
|
||||||
|
}
|
||||||
|
if a.Path == "" {
|
||||||
|
return errors.New("emit: path is required")
|
||||||
|
}
|
||||||
|
if a.Mode == "" {
|
||||||
|
return errors.New("emit: mode is required")
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// Marshal serializes an Artifact to JSON for transport to the bash applier.
|
||||||
|
func (a *Artifact) Marshal() ([]byte, error) {
|
||||||
|
if err := a.Validate(); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return json.Marshal(a)
|
||||||
|
}
|
||||||
|
|
||||||
|
// UnmarshalArtifact parses a JSON byte slice into an Artifact and validates
|
||||||
|
// it against the contract. The bash-side applier (via orca-verify-render.sh)
|
||||||
|
// uses this same validation; the bash side rejects unparseable input with a
|
||||||
|
// structured error, never silently (grill C-16).
|
||||||
|
func UnmarshalArtifact(data []byte) (*Artifact, error) {
|
||||||
|
var a Artifact
|
||||||
|
if err := json.Unmarshal(data, &a); err != nil {
|
||||||
|
return nil, fmt.Errorf("emit: unmarshal: %w", err)
|
||||||
|
}
|
||||||
|
if err := a.Validate(); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return &a, nil
|
||||||
|
}
|
||||||
@@ -0,0 +1,120 @@
|
|||||||
|
package emit
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestArtifactValidate_valid(t *testing.T) {
|
||||||
|
a := &Artifact{
|
||||||
|
SchemaVersion: SchemaVersion,
|
||||||
|
Kind: KindSystemd,
|
||||||
|
Path: "/etc/systemd/system/orca-alloc.service",
|
||||||
|
Content: "[Service]\nExecStart=/bin/true\n",
|
||||||
|
Mode: "0644",
|
||||||
|
}
|
||||||
|
if err := a.Validate(); err != nil {
|
||||||
|
t.Fatalf("expected valid, got %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestArtifactValidate_schemaVersionMismatch(t *testing.T) {
|
||||||
|
a := &Artifact{SchemaVersion: "orca.emit/v0", Kind: KindSystemd, Path: "/x", Mode: "0644"}
|
||||||
|
err := a.Validate()
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for mismatched schema_version")
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), "schema_version mismatch") {
|
||||||
|
t.Fatalf("expected schema_version error, got %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestArtifactValidate_missingKind(t *testing.T) {
|
||||||
|
a := &Artifact{SchemaVersion: SchemaVersion, Path: "/x", Mode: "0644"}
|
||||||
|
err := a.Validate()
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "kind is required") {
|
||||||
|
t.Fatalf("expected kind-required error, got %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestArtifactValidate_missingPath(t *testing.T) {
|
||||||
|
a := &Artifact{SchemaVersion: SchemaVersion, Kind: KindTraefik, Mode: "0644"}
|
||||||
|
err := a.Validate()
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "path is required") {
|
||||||
|
t.Fatalf("expected path-required error, got %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestArtifactValidate_missingMode(t *testing.T) {
|
||||||
|
a := &Artifact{SchemaVersion: SchemaVersion, Kind: KindSudoers, Path: "/x"}
|
||||||
|
err := a.Validate()
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "mode is required") {
|
||||||
|
t.Fatalf("expected mode-required error, got %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestMarshalValidate_rejectsInvalid(t *testing.T) {
|
||||||
|
a := &Artifact{SchemaVersion: "bad", Kind: "", Path: "", Mode: ""}
|
||||||
|
if _, err := a.Marshal(); err == nil {
|
||||||
|
t.Fatal("expected Marshal to reject invalid artifact")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestUnmarshalArtifact_valid(t *testing.T) {
|
||||||
|
raw := `{"schema_version":"orca.emit/v1","kind":"systemd","path":"/x","content":"c","mode":"0644"}`
|
||||||
|
a, err := UnmarshalArtifact([]byte(raw))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("expected valid, got %v", err)
|
||||||
|
}
|
||||||
|
if a.Kind != KindSystemd {
|
||||||
|
t.Fatalf("expected kind systemd, got %s", a.Kind)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestUnmarshalArtifact_rejectsBadJSON(t *testing.T) {
|
||||||
|
if _, err := UnmarshalArtifact([]byte("not json")); err == nil {
|
||||||
|
t.Fatal("expected error for bad JSON")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestUnmarshalArtifact_rejectsSchemaMismatch(t *testing.T) {
|
||||||
|
raw := `{"schema_version":"orca.emit/v2","kind":"x","path":"/x","mode":"0644"}`
|
||||||
|
if _, err := UnmarshalArtifact([]byte(raw)); err == nil {
|
||||||
|
t.Fatal("expected error for schema mismatch")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRoundTrip(t *testing.T) {
|
||||||
|
orig := &Artifact{
|
||||||
|
SchemaVersion: SchemaVersion,
|
||||||
|
Kind: KindSyncthing,
|
||||||
|
Path: "/etc/syncthing/config.xml",
|
||||||
|
Content: "<config/>",
|
||||||
|
Mode: "0600",
|
||||||
|
}
|
||||||
|
data, err := orig.Marshal()
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Marshal: %v", err)
|
||||||
|
}
|
||||||
|
back, err := UnmarshalArtifact(data)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Unmarshal: %v", err)
|
||||||
|
}
|
||||||
|
if back.Path != orig.Path || back.Kind != orig.Kind || back.Mode != orig.Mode {
|
||||||
|
t.Fatalf("round-trip mismatch: %+v vs %+v", orig, back)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAllKinds(t *testing.T) {
|
||||||
|
for _, k := range []Kind{KindSystemd, KindTraefik, KindSyncthing, KindSudoers, KindSSHD, KindEnvFile, KindCredential} {
|
||||||
|
a := &Artifact{SchemaVersion: SchemaVersion, Kind: k, Path: "/x", Mode: "0644"}
|
||||||
|
if err := a.Validate(); err != nil {
|
||||||
|
t.Errorf("kind %s: %v", k, err)
|
||||||
|
}
|
||||||
|
// verify it marshals
|
||||||
|
if _, err := json.Marshal(a); err != nil {
|
||||||
|
t.Errorf("marshal kind %s: %v", k, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -25,6 +25,11 @@ import (
|
|||||||
)
|
)
|
||||||
|
|
||||||
// Dispatcher is the public surface; constructed via NewDispatcher.
|
// Dispatcher is the public surface; constructed via NewDispatcher.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces peer dispatch with a CLI-side
|
||||||
|
// scheduler + SSH-push (no orca binary on servers per R-001). The
|
||||||
|
// Dispatcher is retained for the dual-write window and scheduled for
|
||||||
|
// deletion in v0.10-P14. See .ciagent/PRD_v0.9.md R-001/R-006.
|
||||||
type Dispatcher struct {
|
type Dispatcher struct {
|
||||||
log *slog.Logger
|
log *slog.Logger
|
||||||
capacity *store.CapacityRepo
|
capacity *store.CapacityRepo
|
||||||
|
|||||||
@@ -0,0 +1,304 @@
|
|||||||
|
package engine
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"errors"
|
||||||
|
"path/filepath"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
||||||
|
)
|
||||||
|
|
||||||
|
type mockExecutor struct {
|
||||||
|
submitFn func(ctx context.Context, spec []byte) (string, error)
|
||||||
|
statusFn func(ctx context.Context, jobID string) (string, error)
|
||||||
|
submitted bool
|
||||||
|
}
|
||||||
|
|
||||||
|
func (m *mockExecutor) Submit(ctx context.Context, spec []byte) (string, error) {
|
||||||
|
m.submitted = true
|
||||||
|
if m.submitFn != nil {
|
||||||
|
return m.submitFn(ctx, spec)
|
||||||
|
}
|
||||||
|
return "mock-job-id", nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (m *mockExecutor) Status(ctx context.Context, jobID string) (string, error) {
|
||||||
|
if m.statusFn != nil {
|
||||||
|
return m.statusFn(ctx, jobID)
|
||||||
|
}
|
||||||
|
return "complete", nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func newTestDispatcher(t *testing.T, exec LocalExecutor) (*Dispatcher, *store.CapacityRepo, func()) {
|
||||||
|
t.Helper()
|
||||||
|
path := filepath.Join(t.TempDir(), "test.db")
|
||||||
|
db, err := store.Open(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("open db: %v", err)
|
||||||
|
}
|
||||||
|
capRepo := store.NewCapacityRepo(db)
|
||||||
|
peers := NewPeerRegistry()
|
||||||
|
d := NewDispatcher(nil, capRepo, peers, exec)
|
||||||
|
return d, capRepo, func() { _ = db.Close() }
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_Submit_EmptySpec(t *testing.T) {
|
||||||
|
d, _, cleanup := newTestDispatcher(t, &mockExecutor{})
|
||||||
|
defer cleanup()
|
||||||
|
_, _, err := d.Submit(context.Background(), "", nil, "")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("Submit: expected error for empty spec, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_Submit_IdempotencyHit(t *testing.T) {
|
||||||
|
exec := &mockExecutor{}
|
||||||
|
d, _, cleanup := newTestDispatcher(t, exec)
|
||||||
|
defer cleanup()
|
||||||
|
|
||||||
|
d.Dedupe().Put("key-1", "cached-job-id")
|
||||||
|
spec := []byte(`{"cpu_millicores":100,"memory_mib":64,"disk_mib":64}`)
|
||||||
|
jobID, nodeID, err := d.Submit(context.Background(), "", spec, "key-1")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Submit: %v", err)
|
||||||
|
}
|
||||||
|
if jobID != "cached-job-id" {
|
||||||
|
t.Errorf("jobID: got %q, want cached-job-id", jobID)
|
||||||
|
}
|
||||||
|
if nodeID != "self" {
|
||||||
|
t.Errorf("nodeID: got %q, want self", nodeID)
|
||||||
|
}
|
||||||
|
if exec.submitted {
|
||||||
|
t.Error("executor was called on idempotency hit; should have been short-circuited")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_Submit_LocalCapacity(t *testing.T) {
|
||||||
|
exec := &mockExecutor{
|
||||||
|
submitFn: func(ctx context.Context, spec []byte) (string, error) {
|
||||||
|
return "local-job-id", nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
d, capRepo, cleanup := newTestDispatcher(t, exec)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
if err := capRepo.Upsert(ctx, &store.NodeCapacity{
|
||||||
|
NodeID: "self",
|
||||||
|
CPUMillicores: 4000,
|
||||||
|
MemoryMiB: 4096,
|
||||||
|
DiskMiB: 4096,
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("Upsert capacity: %v", err)
|
||||||
|
}
|
||||||
|
spec := []byte(`{"cpu_millicores":100,"memory_mib":64,"disk_mib":64}`)
|
||||||
|
jobID, nodeID, err := d.Submit(ctx, "", spec, "")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Submit: %v", err)
|
||||||
|
}
|
||||||
|
if jobID != "local-job-id" {
|
||||||
|
t.Errorf("jobID: got %q, want local-job-id", jobID)
|
||||||
|
}
|
||||||
|
if nodeID != "self" {
|
||||||
|
t.Errorf("nodeID: got %q, want self", nodeID)
|
||||||
|
}
|
||||||
|
if !exec.submitted {
|
||||||
|
t.Error("executor was not called for local-capacity path")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_Submit_ExplicitTarget(t *testing.T) {
|
||||||
|
exec := &mockExecutor{}
|
||||||
|
d, _, cleanup := newTestDispatcher(t, exec)
|
||||||
|
defer cleanup()
|
||||||
|
spec := []byte(`{"cpu_millicores":100,"memory_mib":64,"disk_mib":64}`)
|
||||||
|
_, _, err := d.Submit(context.Background(), "nodeA", spec, "")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("Submit with explicit target nodeA (no peer): expected error, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_Submit_NoPeers(t *testing.T) {
|
||||||
|
exec := &mockExecutor{}
|
||||||
|
d, capRepo, cleanup := newTestDispatcher(t, exec)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
if err := capRepo.Upsert(ctx, &store.NodeCapacity{
|
||||||
|
NodeID: "self",
|
||||||
|
CPUMillicores: 0,
|
||||||
|
MemoryMiB: 0,
|
||||||
|
DiskMiB: 0,
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("Upsert: %v", err)
|
||||||
|
}
|
||||||
|
spec := []byte(`{"cpu_millicores":1000,"memory_mib":1024,"disk_mib":1024}`)
|
||||||
|
_, _, err := d.Submit(ctx, "", spec, "")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("Submit: expected error when no peers and no local capacity, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_LocalSubmit(t *testing.T) {
|
||||||
|
exec := &mockExecutor{
|
||||||
|
submitFn: func(ctx context.Context, spec []byte) (string, error) {
|
||||||
|
return "ls-job", nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
d, _, cleanup := newTestDispatcher(t, exec)
|
||||||
|
defer cleanup()
|
||||||
|
jobID, err := d.LocalSubmit(context.Background(), []byte(`{"command":"/bin/true"}`))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("LocalSubmit: %v", err)
|
||||||
|
}
|
||||||
|
if jobID != "ls-job" {
|
||||||
|
t.Errorf("LocalSubmit: got %q, want ls-job", jobID)
|
||||||
|
}
|
||||||
|
if !exec.submitted {
|
||||||
|
t.Error("LocalSubmit: executor.Submit not called")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_LocalStatus(t *testing.T) {
|
||||||
|
exec := &mockExecutor{
|
||||||
|
statusFn: func(ctx context.Context, jobID string) (string, error) {
|
||||||
|
if jobID == "known" {
|
||||||
|
return "running", nil
|
||||||
|
}
|
||||||
|
return "", errors.New("not found")
|
||||||
|
},
|
||||||
|
}
|
||||||
|
d, _, cleanup := newTestDispatcher(t, exec)
|
||||||
|
defer cleanup()
|
||||||
|
st, err := d.LocalStatus(context.Background(), "known")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("LocalStatus: %v", err)
|
||||||
|
}
|
||||||
|
if st != "running" {
|
||||||
|
t.Errorf("LocalStatus: got %q, want running", st)
|
||||||
|
}
|
||||||
|
if _, err := d.LocalStatus(context.Background(), "missing"); err == nil {
|
||||||
|
t.Error("LocalStatus: expected error for missing job, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_LocalSubmit_NilExecutor(t *testing.T) {
|
||||||
|
d := NewDispatcher(nil, nil, NewPeerRegistry(), nil)
|
||||||
|
if _, err := d.LocalSubmit(context.Background(), []byte(`{}`)); err == nil {
|
||||||
|
t.Error("LocalSubmit with nil executor: expected error, got nil")
|
||||||
|
}
|
||||||
|
if _, err := d.LocalStatus(context.Background(), "x"); err == nil {
|
||||||
|
t.Error("LocalStatus with nil executor: expected error, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestParseInlineSpec(t *testing.T) {
|
||||||
|
spec, err := parseInlineSpec([]byte(`{"cpu_millicores":500,"memory_mib":256,"disk_mib":128}`))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("parseInlineSpec: %v", err)
|
||||||
|
}
|
||||||
|
if spec.CPUMillicores != 500 || spec.MemoryMiB != 256 || spec.DiskMiB != 128 {
|
||||||
|
t.Errorf("parseInlineSpec: got %+v, want cpu=500 mem=256 disk=128", spec)
|
||||||
|
}
|
||||||
|
if _, err := parseInlineSpec([]byte(`{bad json`)); err == nil {
|
||||||
|
t.Fatal("parseInlineSpec: expected error for malformed JSON, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_Submit_BadSpec(t *testing.T) {
|
||||||
|
d, _, cleanup := newTestDispatcher(t, &mockExecutor{})
|
||||||
|
defer cleanup()
|
||||||
|
_, _, err := d.Submit(context.Background(), "", []byte(`{bad json`), "")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for malformed spec")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_Submit_ExplicitTargetNoPeerRegistry(t *testing.T) {
|
||||||
|
d := NewDispatcher(nil, nil, nil, &mockExecutor{})
|
||||||
|
_, _, err := d.Submit(context.Background(), "nodeX", []byte(`{"cpu_millicores":100,"memory_mib":64,"disk_mib":64}`), "")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for explicit target with no peer registry")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_Submit_ExplicitTargetPeerNotFound(t *testing.T) {
|
||||||
|
d, _, cleanup := newTestDispatcher(t, &mockExecutor{})
|
||||||
|
defer cleanup()
|
||||||
|
_, _, err := d.Submit(context.Background(), "ghost", []byte(`{"cpu_millicores":100,"memory_mib":64,"disk_mib":64}`), "")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for target not in registry")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_Submit_PickPeerMissingCA(t *testing.T) {
|
||||||
|
exec := &mockExecutor{}
|
||||||
|
d, capRepo, cleanup := newTestDispatcher(t, exec)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
if err := capRepo.Upsert(ctx, &store.NodeCapacity{
|
||||||
|
NodeID: "self",
|
||||||
|
CPUMillicores: 0,
|
||||||
|
MemoryMiB: 0,
|
||||||
|
DiskMiB: 0,
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("Upsert: %v", err)
|
||||||
|
}
|
||||||
|
if err := d.peers.Add(&Peer{
|
||||||
|
NodeID: "peer-1",
|
||||||
|
Address: "127.0.0.1:1",
|
||||||
|
Capacity: &store.NodeCapacity{NodeID: "peer-1", CPUMillicores: 4000, MemoryMiB: 4096, DiskMiB: 4096},
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("Add peer: %v", err)
|
||||||
|
}
|
||||||
|
spec := []byte(`{"cpu_millicores":100,"memory_mib":64,"disk_mib":64}`)
|
||||||
|
_, _, err := d.Submit(ctx, "", spec, "idem-peer-1")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error (peer missing CA/servername)")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_Submit_NoPeerRegistry(t *testing.T) {
|
||||||
|
d := NewDispatcher(nil, nil, nil, &mockExecutor{})
|
||||||
|
spec := []byte(`{"cpu_millicores":1000,"memory_mib":1024,"disk_mib":1024}`)
|
||||||
|
_, _, err := d.Submit(context.Background(), "", spec, "")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for no peer registry and no capacity repo")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_Submit_NilCapacityFallsThrough(t *testing.T) {
|
||||||
|
exec := &mockExecutor{}
|
||||||
|
d := NewDispatcher(nil, nil, NewPeerRegistry(), exec)
|
||||||
|
spec := []byte(`{"cpu_millicores":1000,"memory_mib":1024,"disk_mib":1024}`)
|
||||||
|
_, _, err := d.Submit(context.Background(), "", spec, "")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error when capacity repo is nil and no peers")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatcher_Submit_AllPeersFailsPickNode(t *testing.T) {
|
||||||
|
exec := &mockExecutor{}
|
||||||
|
d, capRepo, cleanup := newTestDispatcher(t, exec)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
if err := capRepo.Upsert(ctx, &store.NodeCapacity{
|
||||||
|
NodeID: "self",
|
||||||
|
CPUMillicores: 0,
|
||||||
|
MemoryMiB: 0,
|
||||||
|
DiskMiB: 0,
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("Upsert: %v", err)
|
||||||
|
}
|
||||||
|
if err := d.peers.Add(&Peer{
|
||||||
|
NodeID: "peer-tiny",
|
||||||
|
Address: "127.0.0.1:1",
|
||||||
|
Capacity: &store.NodeCapacity{NodeID: "peer-tiny", CPUMillicores: 10, MemoryMiB: 10, DiskMiB: 10},
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("Add peer: %v", err)
|
||||||
|
}
|
||||||
|
spec := []byte(`{"cpu_millicores":1000,"memory_mib":1024,"disk_mib":1024}`)
|
||||||
|
_, _, err := d.Submit(ctx, "", spec, "")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error when no peer can fit")
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,145 @@
|
|||||||
|
package engine
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"path/filepath"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"github.com/google/uuid"
|
||||||
|
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/model"
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
||||||
|
)
|
||||||
|
|
||||||
|
func newTestExecutor(t *testing.T) (*Executor, func()) {
|
||||||
|
t.Helper()
|
||||||
|
path := filepath.Join(t.TempDir(), "test.db")
|
||||||
|
db, err := store.Open(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("open db: %v", err)
|
||||||
|
}
|
||||||
|
ex := NewExecutor(store.NewJobRepo(db), store.NewTaskRepo(db), nil)
|
||||||
|
return ex, func() { _ = db.Close() }
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestExecutor_Submit_Success(t *testing.T) {
|
||||||
|
ex, cleanup := newTestExecutor(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
spec := []byte(`{"command":"/bin/echo","args":["hello"]}`)
|
||||||
|
jobID, err := ex.Submit(ctx, spec)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Submit: %v", err)
|
||||||
|
}
|
||||||
|
if jobID == "" {
|
||||||
|
t.Fatal("Submit: empty jobID")
|
||||||
|
}
|
||||||
|
status, err := ex.Status(ctx, jobID)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Status: %v", err)
|
||||||
|
}
|
||||||
|
if status != string(model.JobStatusComplete) {
|
||||||
|
t.Errorf("Status: got %q, want %q", status, model.JobStatusComplete)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestExecutor_Submit_MissingCommand(t *testing.T) {
|
||||||
|
ex, cleanup := newTestExecutor(t)
|
||||||
|
defer cleanup()
|
||||||
|
_, err := ex.Submit(context.Background(), []byte(`{"name":"x"}`))
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("Submit: expected error for missing command, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestExecutor_Submit_MalformedJSON(t *testing.T) {
|
||||||
|
ex, cleanup := newTestExecutor(t)
|
||||||
|
defer cleanup()
|
||||||
|
_, err := ex.Submit(context.Background(), []byte(`{bad json`))
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("Submit: expected error for malformed JSON, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestExecutor_Submit_FailingCommand(t *testing.T) {
|
||||||
|
ex, cleanup := newTestExecutor(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
jobID, err := ex.Submit(ctx, []byte(`{"command":"/bin/false"}`))
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("Submit failing command: expected error, got nil")
|
||||||
|
}
|
||||||
|
if jobID == "" {
|
||||||
|
t.Fatal("Submit failing command: empty jobID")
|
||||||
|
}
|
||||||
|
status, err := ex.Status(ctx, jobID)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Status: %v", err)
|
||||||
|
}
|
||||||
|
if status != string(model.JobStatusFailed) {
|
||||||
|
t.Errorf("Status: got %q, want %q", status, model.JobStatusFailed)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestExecutor_Status_NotFound(t *testing.T) {
|
||||||
|
ex, cleanup := newTestExecutor(t)
|
||||||
|
defer cleanup()
|
||||||
|
_, err := ex.Status(context.Background(), "nonexistent-job-id")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("Status: expected error for missing job, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestExecutor_Run_Success(t *testing.T) {
|
||||||
|
ex, cleanup := newTestExecutor(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
job := &model.Job{
|
||||||
|
ID: uuid.NewString(),
|
||||||
|
Name: "run-success",
|
||||||
|
Spec: "{}",
|
||||||
|
Status: model.JobStatusPending,
|
||||||
|
}
|
||||||
|
specs := []TaskSpec{{Name: "echo", Command: "/bin/echo", Args: []string{"hi"}}}
|
||||||
|
if err := ex.Run(ctx, job, specs); err != nil {
|
||||||
|
t.Fatalf("Run: %v", err)
|
||||||
|
}
|
||||||
|
got, err := ex.Status(ctx, job.ID)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Status: %v", err)
|
||||||
|
}
|
||||||
|
if got != string(model.JobStatusComplete) {
|
||||||
|
t.Errorf("Status: got %q, want %q", got, model.JobStatusComplete)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestExecutor_Run_ContextCancel(t *testing.T) {
|
||||||
|
ex, cleanup := newTestExecutor(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx, cancel := context.WithCancel(context.Background())
|
||||||
|
job := &model.Job{
|
||||||
|
ID: uuid.NewString(),
|
||||||
|
Name: "run-cancel",
|
||||||
|
Spec: "{}",
|
||||||
|
Status: model.JobStatusPending,
|
||||||
|
}
|
||||||
|
specs := []TaskSpec{{Name: "sleep", Command: "/bin/sleep", Args: []string{"10"}}}
|
||||||
|
|
||||||
|
go func() {
|
||||||
|
time.Sleep(100 * time.Millisecond)
|
||||||
|
cancel()
|
||||||
|
}()
|
||||||
|
|
||||||
|
err := ex.Run(ctx, job, specs)
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("Run: expected error after context cancel, got nil")
|
||||||
|
}
|
||||||
|
status, sErr := ex.Status(context.Background(), job.ID)
|
||||||
|
if sErr != nil {
|
||||||
|
t.Fatalf("Status after cancel: %v", sErr)
|
||||||
|
}
|
||||||
|
if status == string(model.JobStatusComplete) {
|
||||||
|
t.Errorf("Status: got %q, want not complete (task should have been killed)", status)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -16,6 +16,11 @@ import (
|
|||||||
)
|
)
|
||||||
|
|
||||||
// Peer is a remote orca node reachable over mTLS.
|
// Peer is a remote orca node reachable over mTLS.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces peer dispatch with a CLI-side
|
||||||
|
// scheduler + SSH-push (no orca binary on servers per R-001). The Peer
|
||||||
|
// type is retained for the dual-write window and scheduled for deletion
|
||||||
|
// in v0.10-P14. See .ciagent/PRD_v0.9.md R-001/R-006.
|
||||||
type Peer struct {
|
type Peer struct {
|
||||||
NodeID string
|
NodeID string
|
||||||
Address string // host:port (the peer's daemon listener)
|
Address string // host:port (the peer's daemon listener)
|
||||||
@@ -27,6 +32,11 @@ type Peer struct {
|
|||||||
|
|
||||||
// PeerRegistry tracks known peers. Methods are safe for concurrent
|
// PeerRegistry tracks known peers. Methods are safe for concurrent
|
||||||
// use; the underlying map is guarded by a sync.RWMutex.
|
// use; the underlying map is guarded by a sync.RWMutex.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces peer dispatch with a CLI-side
|
||||||
|
// scheduler + SSH-push (no orca binary on servers per R-001). The
|
||||||
|
// PeerRegistry is retained for the dual-write window and scheduled for
|
||||||
|
// deletion in v0.10-P14. See .ciagent/PRD_v0.9.md R-001/R-006.
|
||||||
type PeerRegistry struct {
|
type PeerRegistry struct {
|
||||||
mu sync.RWMutex
|
mu sync.RWMutex
|
||||||
peers map[string]*Peer
|
peers map[string]*Peer
|
||||||
|
|||||||
@@ -0,0 +1,136 @@
|
|||||||
|
package engine
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestPeerRegistry_AddAndGet(t *testing.T) {
|
||||||
|
r := NewPeerRegistry()
|
||||||
|
p := &Peer{
|
||||||
|
NodeID: "node-1",
|
||||||
|
Address: "localhost:8443",
|
||||||
|
ServerName: "node-1.orca",
|
||||||
|
CAPath: "/etc/orca/ca.pem",
|
||||||
|
}
|
||||||
|
if err := r.Add(p); err != nil {
|
||||||
|
t.Fatalf("Add: %v", err)
|
||||||
|
}
|
||||||
|
got := r.Get("node-1")
|
||||||
|
if got == nil {
|
||||||
|
t.Fatal("Get: returned nil after Add")
|
||||||
|
}
|
||||||
|
if got.NodeID != "node-1" || got.Address != "localhost:8443" ||
|
||||||
|
got.ServerName != "node-1.orca" || got.CAPath != "/etc/orca/ca.pem" {
|
||||||
|
t.Errorf("Get: fields mismatch: %+v", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestPeerRegistry_AddNil(t *testing.T) {
|
||||||
|
r := NewPeerRegistry()
|
||||||
|
if err := r.Add(nil); err == nil {
|
||||||
|
t.Fatal("Add(nil): expected error, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestPeerRegistry_AddMissingID(t *testing.T) {
|
||||||
|
r := NewPeerRegistry()
|
||||||
|
if err := r.Add(&Peer{Address: "a"}); err == nil {
|
||||||
|
t.Fatal("Add(empty NodeID): expected error, got nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestPeerRegistry_Remove(t *testing.T) {
|
||||||
|
r := NewPeerRegistry()
|
||||||
|
p := &Peer{NodeID: "node-r", Address: "a"}
|
||||||
|
if err := r.Add(p); err != nil {
|
||||||
|
t.Fatalf("Add: %v", err)
|
||||||
|
}
|
||||||
|
if !r.Remove("node-r") {
|
||||||
|
t.Fatal("Remove: returned false for existing peer")
|
||||||
|
}
|
||||||
|
if got := r.Get("node-r"); got != nil {
|
||||||
|
t.Errorf("Get after Remove: want nil, got %+v", got)
|
||||||
|
}
|
||||||
|
if r.Remove("node-r") {
|
||||||
|
t.Error("Remove second time: want false, got true")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestPeerRegistry_All(t *testing.T) {
|
||||||
|
r := NewPeerRegistry()
|
||||||
|
for _, id := range []string{"node-c", "node-a", "node-b"} {
|
||||||
|
if err := r.Add(&Peer{NodeID: id, Address: "a"}); err != nil {
|
||||||
|
t.Fatalf("Add %s: %v", id, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
got, err := r.All(context.Background())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("All: %v", err)
|
||||||
|
}
|
||||||
|
if len(got) != 3 {
|
||||||
|
t.Fatalf("All: got %d, want 3", len(got))
|
||||||
|
}
|
||||||
|
want := []string{"node-a", "node-b", "node-c"}
|
||||||
|
for i, w := range want {
|
||||||
|
if got[i].NodeID != w {
|
||||||
|
t.Errorf("All[%d]: got %s, want %s (not sorted by NodeID)", i, got[i].NodeID, w)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestPeerRegistry_All_Empty(t *testing.T) {
|
||||||
|
r := NewPeerRegistry()
|
||||||
|
got, err := r.All(context.Background())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("All on empty: %v", err)
|
||||||
|
}
|
||||||
|
if len(got) != 0 {
|
||||||
|
t.Errorf("All on empty: got %d, want 0", len(got))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestPeerRegistry_Len(t *testing.T) {
|
||||||
|
r := NewPeerRegistry()
|
||||||
|
if r.Len() != 0 {
|
||||||
|
t.Errorf("Len on empty: got %d, want 0", r.Len())
|
||||||
|
}
|
||||||
|
if err := r.Add(&Peer{NodeID: "n1", Address: "a"}); err != nil {
|
||||||
|
t.Fatalf("Add n1: %v", err)
|
||||||
|
}
|
||||||
|
if err := r.Add(&Peer{NodeID: "n2", Address: "a"}); err != nil {
|
||||||
|
t.Fatalf("Add n2: %v", err)
|
||||||
|
}
|
||||||
|
if r.Len() != 2 {
|
||||||
|
t.Errorf("Len: got %d, want 2", r.Len())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestPeerRegistry_UpdateLastSeen(t *testing.T) {
|
||||||
|
r := NewPeerRegistry()
|
||||||
|
old := time.Now().Add(-1 * time.Hour).UTC()
|
||||||
|
p := &Peer{
|
||||||
|
NodeID: "node-u",
|
||||||
|
Address: "a",
|
||||||
|
LastSeen: old,
|
||||||
|
Capacity: &store.NodeCapacity{NodeID: "node-u", CPUMillicores: 1000, MemoryMiB: 1024, DiskMiB: 1024},
|
||||||
|
}
|
||||||
|
if err := r.Add(p); err != nil {
|
||||||
|
t.Fatalf("Add: %v", err)
|
||||||
|
}
|
||||||
|
r.UpdateLastSeen("node-u")
|
||||||
|
got := r.Get("node-u")
|
||||||
|
if got == nil {
|
||||||
|
t.Fatal("Get: nil after UpdateLastSeen")
|
||||||
|
}
|
||||||
|
if !got.LastSeen.After(old) {
|
||||||
|
t.Errorf("UpdateLastSeen: LastSeen not bumped; old=%v now=%v", old, got.LastSeen)
|
||||||
|
}
|
||||||
|
if time.Since(got.LastSeen) > 5*time.Second {
|
||||||
|
t.Errorf("UpdateLastSeen: LastSeen not recent: %v", got.LastSeen)
|
||||||
|
}
|
||||||
|
r.UpdateLastSeen("nonexistent")
|
||||||
|
}
|
||||||
@@ -0,0 +1,229 @@
|
|||||||
|
package engine
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"context"
|
||||||
|
"errors"
|
||||||
|
"log/slog"
|
||||||
|
"path/filepath"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/model"
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
||||||
|
)
|
||||||
|
|
||||||
|
func newRegistryTestDB(t *testing.T) (*store.NodeRepo, *store.AuditRepo, *store.AuditRepo, func()) {
|
||||||
|
t.Helper()
|
||||||
|
path := filepath.Join(t.TempDir(), "test.db")
|
||||||
|
db, err := store.Open(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("open db: %v", err)
|
||||||
|
}
|
||||||
|
return store.NewNodeRepo(db), store.NewAuditRepo(db), store.NewAuditRepo(db), func() { _ = db.Close() }
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNewNodeRegistry_NilLogger(t *testing.T) {
|
||||||
|
nodeRepo, auditRepo, _, cleanup := newRegistryTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
audit := NewAudit(auditRepo, nil)
|
||||||
|
r := NewNodeRegistry(nodeRepo, audit, nil)
|
||||||
|
if r == nil {
|
||||||
|
t.Fatal("NewNodeRegistry returned nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRegistry_Join_Success(t *testing.T) {
|
||||||
|
nodeRepo, auditRepo, _, cleanup := newRegistryTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
var buf bytes.Buffer
|
||||||
|
audit := NewAudit(auditRepo, slog.New(slog.NewTextHandler(&buf, nil)))
|
||||||
|
r := NewNodeRegistry(nodeRepo, audit, slog.New(slog.NewTextHandler(&buf, nil)))
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
n := &model.Node{
|
||||||
|
ID: "node-join-1",
|
||||||
|
Name: "pve-1",
|
||||||
|
Address: "10.0.0.1:8443",
|
||||||
|
State: model.NodeStateReady,
|
||||||
|
}
|
||||||
|
if err := r.Join(ctx, n); err != nil {
|
||||||
|
t.Fatalf("Join: %v", err)
|
||||||
|
}
|
||||||
|
got, err := r.Get(ctx, "node-join-1")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Get after Join: %v", err)
|
||||||
|
}
|
||||||
|
if got.Name != "pve-1" {
|
||||||
|
t.Errorf("Get: Name = %q, want pve-1", got.Name)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRegistry_Join_Duplicate(t *testing.T) {
|
||||||
|
nodeRepo, auditRepo, _, cleanup := newRegistryTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
audit := NewAudit(auditRepo, nil)
|
||||||
|
r := NewNodeRegistry(nodeRepo, audit, nil)
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
n := &model.Node{ID: "dup-1", Name: "n1", Address: "a:1", State: model.NodeStateReady}
|
||||||
|
if err := r.Join(ctx, n); err != nil {
|
||||||
|
t.Fatalf("first Join: %v", err)
|
||||||
|
}
|
||||||
|
err := r.Join(ctx, n)
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for duplicate Join")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRegistry_Leave_Success(t *testing.T) {
|
||||||
|
nodeRepo, auditRepo, _, cleanup := newRegistryTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
audit := NewAudit(auditRepo, nil)
|
||||||
|
r := NewNodeRegistry(nodeRepo, audit, nil)
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
n := &model.Node{ID: "leave-1", Name: "n1", Address: "a:1", State: model.NodeStateReady}
|
||||||
|
if err := r.Join(ctx, n); err != nil {
|
||||||
|
t.Fatalf("Join: %v", err)
|
||||||
|
}
|
||||||
|
if err := r.Leave(ctx, "leave-1"); err != nil {
|
||||||
|
t.Fatalf("Leave: %v", err)
|
||||||
|
}
|
||||||
|
got, err := r.Get(ctx, "leave-1")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Get after Leave: %v", err)
|
||||||
|
}
|
||||||
|
if got.State != model.NodeStateLeft {
|
||||||
|
t.Errorf("State = %q, want %q", got.State, model.NodeStateLeft)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRegistry_Leave_NotFound(t *testing.T) {
|
||||||
|
nodeRepo, auditRepo, _, cleanup := newRegistryTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
audit := NewAudit(auditRepo, nil)
|
||||||
|
r := NewNodeRegistry(nodeRepo, audit, nil)
|
||||||
|
err := r.Leave(context.Background(), "nonexistent")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for Leave on missing node")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRegistry_Forget_Success(t *testing.T) {
|
||||||
|
nodeRepo, auditRepo, _, cleanup := newRegistryTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
audit := NewAudit(auditRepo, nil)
|
||||||
|
r := NewNodeRegistry(nodeRepo, audit, nil)
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
n := &model.Node{ID: "forget-1", Name: "n1", Address: "a:1", State: model.NodeStateReady}
|
||||||
|
if err := r.Join(ctx, n); err != nil {
|
||||||
|
t.Fatalf("Join: %v", err)
|
||||||
|
}
|
||||||
|
if err := r.Forget(ctx, "forget-1"); err != nil {
|
||||||
|
t.Fatalf("Forget: %v", err)
|
||||||
|
}
|
||||||
|
if _, err := r.Get(ctx, "forget-1"); err == nil {
|
||||||
|
t.Error("expected error after Forget")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRegistry_Forget_NotFound(t *testing.T) {
|
||||||
|
nodeRepo, auditRepo, _, cleanup := newRegistryTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
audit := NewAudit(auditRepo, nil)
|
||||||
|
r := NewNodeRegistry(nodeRepo, audit, nil)
|
||||||
|
err := r.Forget(context.Background(), "nonexistent")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for Forget on missing node")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRegistry_List(t *testing.T) {
|
||||||
|
nodeRepo, auditRepo, _, cleanup := newRegistryTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
audit := NewAudit(auditRepo, nil)
|
||||||
|
r := NewNodeRegistry(nodeRepo, audit, nil)
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
if got, err := r.List(ctx); err != nil {
|
||||||
|
t.Fatalf("List empty: %v", err)
|
||||||
|
} else if len(got) != 0 {
|
||||||
|
t.Errorf("List empty: got %d, want 0", len(got))
|
||||||
|
}
|
||||||
|
for _, id := range []string{"n3", "n1", "n2"} {
|
||||||
|
if err := r.Join(ctx, &model.Node{ID: id, Name: id, Address: "a:1", State: model.NodeStateReady}); err != nil {
|
||||||
|
t.Fatalf("Join %s: %v", id, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
got, err := r.List(ctx)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("List: %v", err)
|
||||||
|
}
|
||||||
|
if len(got) != 3 {
|
||||||
|
t.Errorf("List: got %d, want 3", len(got))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRegistry_Get_NotFound(t *testing.T) {
|
||||||
|
nodeRepo, auditRepo, _, cleanup := newRegistryTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
audit := NewAudit(auditRepo, nil)
|
||||||
|
r := NewNodeRegistry(nodeRepo, audit, nil)
|
||||||
|
_, err := r.Get(context.Background(), "missing")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for Get missing")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNewAudit_NilLogger(t *testing.T) {
|
||||||
|
_, auditRepo, _, cleanup := newRegistryTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
a := NewAudit(auditRepo, nil)
|
||||||
|
if a == nil {
|
||||||
|
t.Fatal("NewAudit returned nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAudit_Record_Success(t *testing.T) {
|
||||||
|
_, auditRepo, _, cleanup := newRegistryTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
var buf bytes.Buffer
|
||||||
|
a := NewAudit(auditRepo, slog.New(slog.NewTextHandler(&buf, nil)))
|
||||||
|
a.Record(context.Background(), "cli", "node.join", "node-1", "success", nil, map[string]any{"host": "10.0.0.1"})
|
||||||
|
entries, err := auditRepo.List(context.Background(), 10)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("List: %v", err)
|
||||||
|
}
|
||||||
|
if len(entries) != 1 {
|
||||||
|
t.Fatalf("entries = %d, want 1", len(entries))
|
||||||
|
}
|
||||||
|
if entries[0].Action != "node.join" || entries[0].Result != "success" {
|
||||||
|
t.Errorf("entry = %+v", entries[0])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAudit_Record_WithError(t *testing.T) {
|
||||||
|
_, auditRepo, _, cleanup := newRegistryTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
var buf bytes.Buffer
|
||||||
|
a := NewAudit(auditRepo, slog.New(slog.NewTextHandler(&buf, nil)))
|
||||||
|
a.Record(context.Background(), "cli", "node.join", "node-1", "failure", errors.New("boom"), nil)
|
||||||
|
entries, err := auditRepo.List(context.Background(), 10)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("List: %v", err)
|
||||||
|
}
|
||||||
|
if len(entries) != 1 {
|
||||||
|
t.Fatalf("entries = %d, want 1", len(entries))
|
||||||
|
}
|
||||||
|
if entries[0].Error != "boom" {
|
||||||
|
t.Errorf("Error = %q, want boom", entries[0].Error)
|
||||||
|
}
|
||||||
|
if !containsStr(buf.String(), "level=WARN") {
|
||||||
|
t.Errorf("expected WARN level for error result, got: %s", buf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func containsStr(s, sub string) bool {
|
||||||
|
return len(sub) == 0 || (len(s) >= len(sub) && (s[0:len(sub)] == sub || containsStr(s[1:], sub)))
|
||||||
|
}
|
||||||
@@ -1,6 +1,7 @@
|
|||||||
package engine
|
package engine
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"context"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
"git.cloudinit.dev/coreci/orca/internal/store"
|
"git.cloudinit.dev/coreci/orca/internal/store"
|
||||||
@@ -64,3 +65,66 @@ func TestJobSpecFits(t *testing.T) {
|
|||||||
t.Error("Fits: should not fit (CPU too low)")
|
t.Error("Fits: should not fit (CPU too low)")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestJobSpecFits_NilCapacity(t *testing.T) {
|
||||||
|
spec := JobSpec{CPUMillicores: 1000}
|
||||||
|
if spec.Fits(nil) {
|
||||||
|
t.Error("Fits(nil): should be false")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobSpecScore_NilCapacity(t *testing.T) {
|
||||||
|
spec := JobSpec{CPUMillicores: 1000, MemoryMiB: 1024}
|
||||||
|
if got := spec.Score(nil); got != -1 {
|
||||||
|
t.Errorf("Score(nil) = %d, want -1", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobSpecScore_OverCapacity(t *testing.T) {
|
||||||
|
spec := JobSpec{CPUMillicores: 2000, MemoryMiB: 1024}
|
||||||
|
c := &store.NodeCapacity{CPUMillicores: 1000, MemoryMiB: 2048}
|
||||||
|
if got := spec.Score(c); got != -1 {
|
||||||
|
t.Errorf("Score over CPU = %d, want -1", got)
|
||||||
|
}
|
||||||
|
c2 := &store.NodeCapacity{CPUMillicores: 4000, MemoryMiB: 512}
|
||||||
|
if got := spec.Score(c2); got != -1 {
|
||||||
|
t.Errorf("Score over Mem = %d, want -1", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobSpecScore_Fits(t *testing.T) {
|
||||||
|
spec := JobSpec{CPUMillicores: 1000, MemoryMiB: 1024}
|
||||||
|
c := &store.NodeCapacity{CPUMillicores: 4000, MemoryMiB: 4096}
|
||||||
|
got := spec.Score(c)
|
||||||
|
want := int64((4000 - 1000) + (4096 - 1024))
|
||||||
|
if got != want {
|
||||||
|
t.Errorf("Score = %d, want %d", got, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestPickNode_Empty(t *testing.T) {
|
||||||
|
_, _, err := PickNode(JobSpec{}, nil)
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for empty capacities")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestMemLocalNode_Capacity(t *testing.T) {
|
||||||
|
c := &store.NodeCapacity{NodeID: "self", CPUMillicores: 1000, MemoryMiB: 1024}
|
||||||
|
ln := MemLocalNode(c)
|
||||||
|
got, err := ln.Capacity(context.Background())
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Capacity: %v", err)
|
||||||
|
}
|
||||||
|
if got != c {
|
||||||
|
t.Errorf("Capacity: got %+v, want %+v", got, c)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestMemLocalNode_NilCapacity(t *testing.T) {
|
||||||
|
ln := MemLocalNode(nil)
|
||||||
|
_, err := ln.Capacity(context.Background())
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for nil capacity")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,6 +1,9 @@
|
|||||||
package jobspec
|
package jobspec
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -58,3 +61,223 @@ task "no-cmd" {}
|
|||||||
t.Fatal("expected error for missing command")
|
t.Fatal("expected error for missing command")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestParse_GoldenFiles(t *testing.T) {
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
file string
|
||||||
|
wantJob string
|
||||||
|
wantJobType string
|
||||||
|
wantTasks int
|
||||||
|
checkTask func(t *testing.T, s *Spec)
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
name: "single_task",
|
||||||
|
file: "valid_single_task.hcl",
|
||||||
|
wantJob: "single",
|
||||||
|
wantTasks: 1,
|
||||||
|
wantJobType: "",
|
||||||
|
checkTask: func(t *testing.T, s *Spec) {
|
||||||
|
if s.Tasks[0].Name != "solo" {
|
||||||
|
t.Errorf("task name = %q, want solo", s.Tasks[0].Name)
|
||||||
|
}
|
||||||
|
if s.Tasks[0].Command != "/bin/true" {
|
||||||
|
t.Errorf("command = %q, want /bin/true", s.Tasks[0].Command)
|
||||||
|
}
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "multi_task",
|
||||||
|
file: "valid_multi_task.hcl",
|
||||||
|
wantJob: "multi",
|
||||||
|
wantJobType: "batch",
|
||||||
|
wantTasks: 3,
|
||||||
|
checkTask: func(t *testing.T, s *Spec) {
|
||||||
|
byName := map[string]TaskSpec{}
|
||||||
|
for _, tk := range s.Tasks {
|
||||||
|
byName[tk.Name] = tk
|
||||||
|
}
|
||||||
|
if _, ok := byName["build"]; !ok {
|
||||||
|
t.Errorf("missing task 'build'")
|
||||||
|
}
|
||||||
|
if _, ok := byName["test"]; !ok {
|
||||||
|
t.Errorf("missing task 'test'")
|
||||||
|
}
|
||||||
|
if len(byName["test"].Env) != 2 {
|
||||||
|
t.Errorf("test env count = %d, want 2", len(byName["test"].Env))
|
||||||
|
}
|
||||||
|
if _, ok := byName["deploy"]; !ok {
|
||||||
|
t.Errorf("missing task 'deploy'")
|
||||||
|
}
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "env_vars",
|
||||||
|
file: "valid_env_vars.hcl",
|
||||||
|
wantJob: "envvars",
|
||||||
|
wantTasks: 1,
|
||||||
|
checkTask: func(t *testing.T, s *Spec) {
|
||||||
|
if len(s.Tasks[0].Env) != 3 {
|
||||||
|
t.Errorf("env count = %d, want 3", len(s.Tasks[0].Env))
|
||||||
|
}
|
||||||
|
want := "FOO=bar"
|
||||||
|
if s.Tasks[0].Env[0] != want {
|
||||||
|
t.Errorf("env[0] = %q, want %q", s.Tasks[0].Env[0], want)
|
||||||
|
}
|
||||||
|
},
|
||||||
|
},
|
||||||
|
}
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
path := filepath.Join("testdata", tc.file)
|
||||||
|
spec, err := ParseFile(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ParseFile(%s): %v", tc.file, err)
|
||||||
|
}
|
||||||
|
if spec.Job.Name != tc.wantJob {
|
||||||
|
t.Errorf("job name = %q, want %q", spec.Job.Name, tc.wantJob)
|
||||||
|
}
|
||||||
|
if tc.wantJobType != "" && spec.Job.Type != tc.wantJobType {
|
||||||
|
t.Errorf("job type = %q, want %q", spec.Job.Type, tc.wantJobType)
|
||||||
|
}
|
||||||
|
if len(spec.Tasks) != tc.wantTasks {
|
||||||
|
t.Fatalf("tasks = %d, want %d", len(spec.Tasks), tc.wantTasks)
|
||||||
|
}
|
||||||
|
if tc.checkTask != nil {
|
||||||
|
tc.checkTask(t, spec)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestParse_ErrorPaths(t *testing.T) {
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
file string
|
||||||
|
wantErr string
|
||||||
|
useParse bool
|
||||||
|
hcl string
|
||||||
|
}{
|
||||||
|
{name: "no_tasks", file: "err_no_tasks.hcl", wantErr: "at least one task"},
|
||||||
|
{name: "missing_command", file: "err_missing_command.hcl", wantErr: "required"},
|
||||||
|
{name: "malformed", file: "err_malformed.hcl", wantErr: "decode hcl"},
|
||||||
|
{name: "missing_job", file: "err_missing_job.hcl", wantErr: "Missing job block"},
|
||||||
|
}
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
path := filepath.Join("testdata", tc.file)
|
||||||
|
_, err := ParseFile(path)
|
||||||
|
if err == nil {
|
||||||
|
t.Fatalf("expected error containing %q, got nil", tc.wantErr)
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), tc.wantErr) {
|
||||||
|
t.Errorf("error = %q, want it to contain %q", err.Error(), tc.wantErr)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestParse_EmptyFile(t *testing.T) {
|
||||||
|
_, err := Parse([]byte(""), "empty.hcl")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for empty file")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestParse_MalformedHCL(t *testing.T) {
|
||||||
|
_, err := Parse([]byte("job = "), "bad.hcl")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for malformed HCL")
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), "decode hcl") {
|
||||||
|
t.Errorf("error = %q, want it to contain 'decode hcl'", err.Error())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestParseFile_Nonexistent(t *testing.T) {
|
||||||
|
_, err := ParseFile(filepath.Join("testdata", "does_not_exist.hcl"))
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for nonexistent file")
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), "read spec file") {
|
||||||
|
t.Errorf("error = %q, want it to contain 'read spec file'", err.Error())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestParseFile_ReadError(t *testing.T) {
|
||||||
|
// Directory exists but is not readable as a file.
|
||||||
|
_, err := ParseFile("testdata")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error when ParseFile target is a directory")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSpec_Validate(t *testing.T) {
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
spec *Spec
|
||||||
|
wantErr string
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
name: "empty_job_name",
|
||||||
|
spec: &Spec{Job: JobSpec{Name: " "}, Tasks: []TaskSpec{{Name: "t", Command: "/bin/echo"}}},
|
||||||
|
wantErr: "job name is required",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "no_tasks",
|
||||||
|
spec: &Spec{Job: JobSpec{Name: "x"}},
|
||||||
|
wantErr: "at least one task is required",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "valid",
|
||||||
|
spec: &Spec{Job: JobSpec{Name: "x"}, Tasks: []TaskSpec{{Name: "t", Command: "/bin/echo"}}},
|
||||||
|
},
|
||||||
|
}
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
err := tc.spec.Validate()
|
||||||
|
if tc.wantErr == "" {
|
||||||
|
if err != nil {
|
||||||
|
t.Errorf("Validate: got %v, want nil", err)
|
||||||
|
}
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if err == nil {
|
||||||
|
t.Fatalf("expected error containing %q, got nil", tc.wantErr)
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), tc.wantErr) {
|
||||||
|
t.Errorf("error = %q, want it to contain %q", err.Error(), tc.wantErr)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSpec_Validate_RoundTripFromParse(t *testing.T) {
|
||||||
|
path := filepath.Join("testdata", "valid_single_task.hcl")
|
||||||
|
spec, err := ParseFile(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ParseFile: %v", err)
|
||||||
|
}
|
||||||
|
if err := spec.Validate(); err != nil {
|
||||||
|
t.Errorf("Validate on parsed spec: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestParseFile_GoldenFilesExist(t *testing.T) {
|
||||||
|
// Guard against accidentally removing testdata fixtures.
|
||||||
|
files := []string{
|
||||||
|
"valid_single_task.hcl",
|
||||||
|
"valid_multi_task.hcl",
|
||||||
|
"valid_env_vars.hcl",
|
||||||
|
"err_no_tasks.hcl",
|
||||||
|
"err_missing_command.hcl",
|
||||||
|
"err_malformed.hcl",
|
||||||
|
"err_missing_job.hcl",
|
||||||
|
}
|
||||||
|
for _, f := range files {
|
||||||
|
path := filepath.Join("testdata", f)
|
||||||
|
if _, err := os.Stat(path); err != nil {
|
||||||
|
t.Errorf("missing testdata fixture %s: %v", f, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
+1
@@ -0,0 +1 @@
|
|||||||
|
job "x" { command = invalid }
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
job "x" {}
|
||||||
|
|
||||||
|
task "nocmd" {}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
task "x" { command = "/bin/echo" }
|
||||||
+1
@@ -0,0 +1 @@
|
|||||||
|
job "empty" {}
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
job "envvars" {}
|
||||||
|
|
||||||
|
task "runner" {
|
||||||
|
command = "/bin/printenv"
|
||||||
|
env = ["FOO=bar", "BAZ=qux", "EMPTY="]
|
||||||
|
}
|
||||||
+19
@@ -0,0 +1,19 @@
|
|||||||
|
job "multi" {
|
||||||
|
type = "batch"
|
||||||
|
}
|
||||||
|
|
||||||
|
task "build" {
|
||||||
|
command = "/bin/echo"
|
||||||
|
args = ["build", "done"]
|
||||||
|
}
|
||||||
|
|
||||||
|
task "test" {
|
||||||
|
command = "/usr/bin/go"
|
||||||
|
args = ["test", "./..."]
|
||||||
|
env = ["GOCACHE=/tmp/gocache", "GOFLAGS=-v"]
|
||||||
|
}
|
||||||
|
|
||||||
|
task "deploy" {
|
||||||
|
command = "/bin/sh"
|
||||||
|
args = ["-c", "echo deploying"]
|
||||||
|
}
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
job "single" {}
|
||||||
|
|
||||||
|
task "solo" {
|
||||||
|
command = "/bin/true"
|
||||||
|
}
|
||||||
+212
-35
@@ -22,9 +22,13 @@
|
|||||||
package proxmox
|
package proxmox
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"bytes"
|
||||||
"context"
|
"context"
|
||||||
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
|
"net"
|
||||||
|
"os"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
@@ -68,6 +72,11 @@ type Options struct {
|
|||||||
ProxmoxRole string
|
ProxmoxRole string
|
||||||
// SSHPort is the SSH port (default 22).
|
// SSHPort is the SSH port (default 22).
|
||||||
SSHPort int
|
SSHPort int
|
||||||
|
// HostKeyFingerprint is the operator-pinned SSH host key fingerprint
|
||||||
|
// in `SHA256:base64` form (REQ-058, D-044). When non-empty, the
|
||||||
|
// bootstrap dialer uses a pinned-host-key callback instead of the
|
||||||
|
// TOFU known_hosts capture path. Empty falls back to TOFU.
|
||||||
|
HostKeyFingerprint string
|
||||||
// Logger receives audit-log entries. If nil, slog.Default() is used.
|
// Logger receives audit-log entries. If nil, slog.Default() is used.
|
||||||
Logger *slog.Logger
|
Logger *slog.Logger
|
||||||
}
|
}
|
||||||
@@ -119,15 +128,30 @@ func BootstrapProxmox(ctx context.Context, opts Options) (*Result, error) {
|
|||||||
return nil, fmt.Errorf("ssh key: %w", err)
|
return nil, fmt.Errorf("ssh key: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Step 2: SSH dial with password auth + TOFU host-key capture (D-035).
|
// Step 2: SSH dial with password auth + host-key verification (D-035,
|
||||||
// knownhosts.New reads ~/.orca/known_hosts; on first connect it
|
// REQ-058). When opts.HostKeyFingerprint is set (D-044), use a pinned
|
||||||
// captures the host key, on subsequent connects it verifies.
|
// callback that fails closed on mismatch (AD-028); otherwise use the
|
||||||
hostKeyCallback, err := knownhosts.New(certpaths.KnownHostsPath())
|
// TOFU known_hosts capture callback (D-035). The TOFU wrapper fixes
|
||||||
if err != nil {
|
// the v0.6 ship-defect where knownhosts.New returned KeyError{Want:[]}
|
||||||
return nil, fmt.Errorf("known_hosts callback: %w", err)
|
// on first connect WITHOUT writing the captured key, so the first
|
||||||
|
// `orca node join --type proxmox` always failed.
|
||||||
|
sshAddr := fmt.Sprintf("%s:%d", opts.Host, opts.SSHPort)
|
||||||
|
var capturedHostKey ssh.PublicKey
|
||||||
|
var hostKeyCallback ssh.HostKeyCallback
|
||||||
|
if opts.HostKeyFingerprint != "" {
|
||||||
|
cb, err := pinnedHostKeyCallback(opts.HostKeyFingerprint, &capturedHostKey)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("host-key fingerprint: %w", err)
|
||||||
|
}
|
||||||
|
hostKeyCallback = cb
|
||||||
|
} else {
|
||||||
|
cb, err := TOFUHostKeyCallback(sshAddr, &capturedHostKey)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("tofu host-key callback: %w", err)
|
||||||
|
}
|
||||||
|
hostKeyCallback = cb
|
||||||
}
|
}
|
||||||
|
|
||||||
sshAddr := fmt.Sprintf("%s:%d", opts.Host, opts.SSHPort)
|
|
||||||
sshConfig := &ssh.ClientConfig{
|
sshConfig := &ssh.ClientConfig{
|
||||||
User: opts.SSHUser,
|
User: opts.SSHUser,
|
||||||
Auth: []ssh.AuthMethod{ssh.Password(opts.Password)},
|
Auth: []ssh.AuthMethod{ssh.Password(opts.Password)},
|
||||||
@@ -143,45 +167,55 @@ func BootstrapProxmox(ctx context.Context, opts Options) (*Result, error) {
|
|||||||
}
|
}
|
||||||
defer conn.Close()
|
defer conn.Close()
|
||||||
|
|
||||||
|
if sessionRunner == nil {
|
||||||
|
sessionRunner = &sshSessionRunner{client: conn}
|
||||||
|
}
|
||||||
|
|
||||||
|
hostKeyFP := ""
|
||||||
|
if capturedHostKey != nil {
|
||||||
|
hostKeyFP = security.SSHFingerprintSHA256(capturedHostKey)
|
||||||
|
}
|
||||||
|
|
||||||
log.Info("proxmox.ssh_connected",
|
log.Info("proxmox.ssh_connected",
|
||||||
slog.String("event", "proxmox.ssh_connected"),
|
slog.String("event", "proxmox.ssh_connected"),
|
||||||
slog.String("host", opts.Host),
|
slog.String("host", opts.Host),
|
||||||
slog.String("ssh_user", opts.SSHUser),
|
slog.String("ssh_user", opts.SSHUser),
|
||||||
|
slog.String("host_key_fingerprint", hostKeyFP),
|
||||||
)
|
)
|
||||||
|
|
||||||
// Step 3: Deploy orca pubkey to ~orca/.ssh/authorized_keys (idempotent).
|
// Step 3: Deploy orca pubkey to ~orca/.ssh/authorized_keys (idempotent).
|
||||||
if err := deployPubKey(conn, opts.ProxmoxUser, string(pubLine)); err != nil {
|
if err := deployPubKey(opts.ProxmoxUser, string(pubLine)); err != nil {
|
||||||
return nil, fmt.Errorf("deploy pubkey: %w", err)
|
return nil, fmt.Errorf("deploy pubkey: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Step 4: Create orca Linux system user (idempotent).
|
// Step 4: Create orca Linux system user (idempotent).
|
||||||
if err := createLinuxUser(conn, opts.ProxmoxUser); err != nil {
|
if err := createLinuxUser(opts.ProxmoxUser); err != nil {
|
||||||
return nil, fmt.Errorf("create user %s: %w", opts.ProxmoxUser, err)
|
return nil, fmt.Errorf("create user %s: %w", opts.ProxmoxUser, err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Step 5: Create OrcaOperator PVE role (idempotent).
|
// Step 5: Create OrcaOperator PVE role (idempotent).
|
||||||
if err := createPVERole(conn, opts.ProxmoxRole); err != nil {
|
if err := createPVERole(opts.ProxmoxRole); err != nil {
|
||||||
return nil, fmt.Errorf("create PVE role %s: %w", opts.ProxmoxRole, err)
|
return nil, fmt.Errorf("create PVE role %s: %w", opts.ProxmoxRole, err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Step 6: Create orca@pam PVE user (idempotent).
|
// Step 6: Create orca@pam PVE user (idempotent).
|
||||||
if err := createPVEUser(conn, opts.ProxmoxUser); err != nil {
|
if err := createPVEUser(opts.ProxmoxUser); err != nil {
|
||||||
return nil, fmt.Errorf("create PVE user %s@pam: %w", opts.ProxmoxUser, err)
|
return nil, fmt.Errorf("create PVE user %s@pam: %w", opts.ProxmoxUser, err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Step 7: Assign OrcaOperator role to orca@pam on path / (idempotent).
|
// Step 7: Assign OrcaOperator role to orca@pam on path / (idempotent).
|
||||||
if err := assignPVEACL(conn, opts.ProxmoxUser, opts.ProxmoxRole); err != nil {
|
if err := assignPVEACL(opts.ProxmoxUser, opts.ProxmoxRole); err != nil {
|
||||||
return nil, fmt.Errorf("assign ACL: %w", err)
|
return nil, fmt.Errorf("assign ACL: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Step 8: Write /etc/sudoers.d/orca (AD-020: NOEXEC on pct/qm,
|
// Step 8: Write /etc/sudoers.d/orca (AD-020: NOEXEC on pct/qm,
|
||||||
// no NOEXEC on apt-get/dpkg, pvesh EXCLUDED).
|
// no NOEXEC on apt-get/dpkg, pvesh EXCLUDED).
|
||||||
if err := writeSudoers(conn, opts.ProxmoxUser); err != nil {
|
if err := writeSudoers(opts.ProxmoxUser); err != nil {
|
||||||
return nil, fmt.Errorf("write sudoers: %w", err)
|
return nil, fmt.Errorf("write sudoers: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Step 9: Validate sudoers with visudo -cf.
|
// Step 9: Validate sudoers with visudo -cf.
|
||||||
if err := validateSudoers(conn); err != nil {
|
if err := validateSudoers(); err != nil {
|
||||||
return nil, fmt.Errorf("validate sudoers: %w", err)
|
return nil, fmt.Errorf("validate sudoers: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -193,8 +227,9 @@ func BootstrapProxmox(ctx context.Context, opts Options) (*Result, error) {
|
|||||||
)
|
)
|
||||||
|
|
||||||
return &Result{
|
return &Result{
|
||||||
NodeName: opts.Host,
|
NodeName: opts.Host,
|
||||||
NodeAddress: opts.Host + ":8443",
|
NodeAddress: opts.Host + ":8443",
|
||||||
|
HostKeyFingerprint: hostKeyFP,
|
||||||
}, nil
|
}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -202,6 +237,78 @@ func BootstrapProxmox(ctx context.Context, opts Options) (*Result, error) {
|
|||||||
// variable so tests can override it with a fake SSH server.
|
// variable so tests can override it with a fake SSH server.
|
||||||
var sshDialer sshDialerType = defaultSSHDialer{}
|
var sshDialer sshDialerType = defaultSSHDialer{}
|
||||||
|
|
||||||
|
// pinnedHostKeyCallback returns an ssh.HostKeyCallback that pins the
|
||||||
|
// server's host key to the operator-supplied SHA256:base64 fingerprint
|
||||||
|
// (REQ-058, AD-028). It validates the `SHA256:` prefix up front (D-045)
|
||||||
|
// and fails closed on any mismatch. The capturedKey out-param records
|
||||||
|
// the verified server key so the caller can populate Result.
|
||||||
|
func pinnedHostKeyCallback(expectedSHA256Base64 string, capturedKey *ssh.PublicKey) (ssh.HostKeyCallback, error) {
|
||||||
|
if !strings.HasPrefix(expectedSHA256Base64, "SHA256:") {
|
||||||
|
return nil, fmt.Errorf("pinnedHostKeyCallback: fingerprint must be SHA256:-prefixed (D-045), got %q", expectedSHA256Base64)
|
||||||
|
}
|
||||||
|
return func(_ string, _ net.Addr, key ssh.PublicKey) error {
|
||||||
|
got := security.SSHFingerprintSHA256(key)
|
||||||
|
if got != expectedSHA256Base64 {
|
||||||
|
return fmt.Errorf("REQ-058 host-key fingerprint mismatch: pinned=%s server=%s", expectedSHA256Base64, got)
|
||||||
|
}
|
||||||
|
if capturedKey != nil {
|
||||||
|
*capturedKey = key
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// TOFUHostKeyCallback returns an ssh.HostKeyCallback that wraps the
|
||||||
|
// standard knownhosts.New verifier with TOFU first-connect capture
|
||||||
|
// (D-035). On a host-unknown KeyError{Want:[]} it writes the
|
||||||
|
// server-presented key to certpaths.KnownHostsPath() atomically
|
||||||
|
// (security.WriteAtomic, AD-029) and allows the dial to proceed; on a
|
||||||
|
// mismatch (Want non-empty) it fails closed (MITM detection). The
|
||||||
|
// capturedKey out-param records the verified/captured server key so
|
||||||
|
// the caller can populate Result. This fixes the v0.6 ship-defect
|
||||||
|
// where knownhosts.New returned KeyError{Want:[]} on first connect
|
||||||
|
// WITHOUT writing the captured key, so the first
|
||||||
|
// `orca node join --type proxmox` always failed.
|
||||||
|
//
|
||||||
|
// Exported so the doctor proxmox probe (T02.9) can reuse the same
|
||||||
|
// capture-fix wrapper for parity (GRILL condition #2).
|
||||||
|
func TOFUHostKeyCallback(addr string, capturedKey *ssh.PublicKey) (ssh.HostKeyCallback, error) {
|
||||||
|
cb, err := knownhosts.New(certpaths.KnownHostsPath())
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
return func(hostname string, remote net.Addr, key ssh.PublicKey) error {
|
||||||
|
err := cb(hostname, remote, key)
|
||||||
|
if err == nil {
|
||||||
|
if capturedKey != nil {
|
||||||
|
*capturedKey = key
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
var keyErr *knownhosts.KeyError
|
||||||
|
if errors.As(err, &keyErr) && len(keyErr.Want) == 0 {
|
||||||
|
line := knownhosts.Line([]string{knownhosts.Normalize(addr)}, key)
|
||||||
|
path := certpaths.KnownHostsPath()
|
||||||
|
existing, readErr := os.ReadFile(path)
|
||||||
|
if readErr != nil && !os.IsNotExist(readErr) {
|
||||||
|
return fmt.Errorf("tofu read known_hosts: %w", readErr)
|
||||||
|
}
|
||||||
|
if len(existing) > 0 && !bytes.HasSuffix(existing, []byte("\n")) {
|
||||||
|
existing = append(existing, '\n')
|
||||||
|
}
|
||||||
|
updated := append(existing, []byte(line)...)
|
||||||
|
if writeErr := security.WriteAtomic(path, 0o600, updated); writeErr != nil {
|
||||||
|
return fmt.Errorf("tofu write known_hosts: %w", writeErr)
|
||||||
|
}
|
||||||
|
if capturedKey != nil {
|
||||||
|
*capturedKey = key
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
return err
|
||||||
|
}, nil
|
||||||
|
}
|
||||||
|
|
||||||
type sshDialerType interface {
|
type sshDialerType interface {
|
||||||
DialContext(ctx context.Context, network, addr string, config *ssh.ClientConfig) (*ssh.Client, error)
|
DialContext(ctx context.Context, network, addr string, config *ssh.ClientConfig) (*ssh.Client, error)
|
||||||
}
|
}
|
||||||
@@ -212,15 +319,29 @@ func (defaultSSHDialer) DialContext(ctx context.Context, network, addr string, c
|
|||||||
return ssh.Dial(network, addr, config)
|
return ssh.Dial(network, addr, config)
|
||||||
}
|
}
|
||||||
|
|
||||||
// runRemote runs a command over the SSH connection and returns its
|
type sessionRunnerType interface {
|
||||||
// combined output. Returns an error if the command exits non-zero.
|
CombinedOutput(cmd string) ([]byte, error)
|
||||||
func runRemote(conn *ssh.Client, cmd string) ([]byte, error) {
|
}
|
||||||
session, err := conn.NewSession()
|
|
||||||
|
var sessionRunner sessionRunnerType
|
||||||
|
|
||||||
|
type sshSessionRunner struct {
|
||||||
|
client *ssh.Client
|
||||||
|
}
|
||||||
|
|
||||||
|
func (r *sshSessionRunner) CombinedOutput(cmd string) ([]byte, error) {
|
||||||
|
session, err := r.client.NewSession()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, fmt.Errorf("new session: %w", err)
|
return nil, fmt.Errorf("new session: %w", err)
|
||||||
}
|
}
|
||||||
defer session.Close()
|
defer session.Close()
|
||||||
out, err := session.CombinedOutput(cmd)
|
return session.CombinedOutput(cmd)
|
||||||
|
}
|
||||||
|
|
||||||
|
// runRemote runs a command over the SSH connection and returns its
|
||||||
|
// combined output. Returns an error if the command exits non-zero.
|
||||||
|
func runRemote(cmd string) ([]byte, error) {
|
||||||
|
out, err := sessionRunner.CombinedOutput(cmd)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return out, fmt.Errorf("run %q: %w (output: %s)", cmd, err, strings.TrimSpace(string(out)))
|
return out, fmt.Errorf("run %q: %w (output: %s)", cmd, err, strings.TrimSpace(string(out)))
|
||||||
}
|
}
|
||||||
@@ -230,7 +351,7 @@ func runRemote(conn *ssh.Client, cmd string) ([]byte, error) {
|
|||||||
// deployPubKey appends the orca public key to the remote user's
|
// deployPubKey appends the orca public key to the remote user's
|
||||||
// authorized_keys file, creating the .ssh dir if needed. Idempotent:
|
// authorized_keys file, creating the .ssh dir if needed. Idempotent:
|
||||||
// if the key is already present, it is not re-appended.
|
// if the key is already present, it is not re-appended.
|
||||||
func deployPubKey(conn *ssh.Client, user, pubLine string) error {
|
func deployPubKey(user, pubLine string) error {
|
||||||
pubLine = strings.TrimSpace(pubLine)
|
pubLine = strings.TrimSpace(pubLine)
|
||||||
if pubLine == "" {
|
if pubLine == "" {
|
||||||
return fmt.Errorf("deployPubKey: empty pub line")
|
return fmt.Errorf("deployPubKey: empty pub line")
|
||||||
@@ -246,7 +367,7 @@ func deployPubKey(conn *ssh.Client, user, pubLine string) error {
|
|||||||
"mkdir -p %s && touch %s && chmod 0700 %s && chmod 0600 %s && grep -qF '%s' %s || echo '%s' >> %s",
|
"mkdir -p %s && touch %s && chmod 0700 %s && chmod 0600 %s && grep -qF '%s' %s || echo '%s' >> %s",
|
||||||
sshDir, authFile, sshDir, authFile, pubLine, authFile, pubLine, authFile,
|
sshDir, authFile, sshDir, authFile, pubLine, authFile, pubLine, authFile,
|
||||||
)
|
)
|
||||||
if _, err := runRemote(conn, cmd); err != nil {
|
if _, err := runRemote(cmd); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
@@ -254,9 +375,9 @@ func deployPubKey(conn *ssh.Client, user, pubLine string) error {
|
|||||||
|
|
||||||
// createLinuxUser creates the orca system user if it doesn't already
|
// createLinuxUser creates the orca system user if it doesn't already
|
||||||
// exist. Idempotent: `id -u` check before `useradd`.
|
// exist. Idempotent: `id -u` check before `useradd`.
|
||||||
func createLinuxUser(conn *ssh.Client, user string) error {
|
func createLinuxUser(user string) error {
|
||||||
cmd := fmt.Sprintf("id -u %s 2>/dev/null || useradd -m -s /bin/bash %s", user, user)
|
cmd := fmt.Sprintf("id -u %s 2>/dev/null || useradd -m -s /bin/bash %s", user, user)
|
||||||
if _, err := runRemote(conn, cmd); err != nil {
|
if _, err := runRemote(cmd); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
@@ -264,12 +385,12 @@ func createLinuxUser(conn *ssh.Client, user string) error {
|
|||||||
|
|
||||||
// createPVERole creates the OrcaOperator PVE role if it doesn't exist.
|
// createPVERole creates the OrcaOperator PVE role if it doesn't exist.
|
||||||
// Idempotent: probes `pveum role list` before `pveum role add`.
|
// Idempotent: probes `pveum role list` before `pveum role add`.
|
||||||
func createPVERole(conn *ssh.Client, role string) error {
|
func createPVERole(role string) error {
|
||||||
cmd := fmt.Sprintf(
|
cmd := fmt.Sprintf(
|
||||||
"pveum role list 2>/dev/null | grep -q '^%s' || pveum role add %s --privs '%s'",
|
"pveum role list 2>/dev/null | grep -q '^%s' || pveum role add %s --privs '%s'",
|
||||||
role, role, OrcaOperatorPrivileges,
|
role, role, OrcaOperatorPrivileges,
|
||||||
)
|
)
|
||||||
if _, err := runRemote(conn, cmd); err != nil {
|
if _, err := runRemote(cmd); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
@@ -278,13 +399,13 @@ func createPVERole(conn *ssh.Client, role string) error {
|
|||||||
// createPVEUser creates the orca@pam PVE user if it doesn't exist.
|
// createPVEUser creates the orca@pam PVE user if it doesn't exist.
|
||||||
// Idempotent: probes `pveum user list` before `pveum user add`.
|
// Idempotent: probes `pveum user list` before `pveum user add`.
|
||||||
// Uses @pam realm (AD-019) since orca creates a Linux system user.
|
// Uses @pam realm (AD-019) since orca creates a Linux system user.
|
||||||
func createPVEUser(conn *ssh.Client, user string) error {
|
func createPVEUser(user string) error {
|
||||||
pveUserID := user + "@pam"
|
pveUserID := user + "@pam"
|
||||||
cmd := fmt.Sprintf(
|
cmd := fmt.Sprintf(
|
||||||
"pveum user list 2>/dev/null | grep -q '%s' || pveum user add %s -comment 'Orca automation user'",
|
"pveum user list 2>/dev/null | grep -q '%s' || pveum user add %s -comment 'Orca automation user'",
|
||||||
pveUserID, pveUserID,
|
pveUserID, pveUserID,
|
||||||
)
|
)
|
||||||
if _, err := runRemote(conn, cmd); err != nil {
|
if _, err := runRemote(cmd); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
@@ -292,10 +413,10 @@ func createPVEUser(conn *ssh.Client, user string) error {
|
|||||||
|
|
||||||
// assignPVEACL assigns the OrcaOperator role to orca@pam on path /
|
// assignPVEACL assigns the OrcaOperator role to orca@pam on path /
|
||||||
// (cluster-wide). `pveum acl modify` is idempotent (creates or updates).
|
// (cluster-wide). `pveum acl modify` is idempotent (creates or updates).
|
||||||
func assignPVEACL(conn *ssh.Client, user, role string) error {
|
func assignPVEACL(user, role string) error {
|
||||||
pveUserID := user + "@pam"
|
pveUserID := user + "@pam"
|
||||||
cmd := fmt.Sprintf("pveum acl modify / -user %s -role %s", pveUserID, role)
|
cmd := fmt.Sprintf("pveum acl modify / -user %s -role %s", pveUserID, role)
|
||||||
if _, err := runRemote(conn, cmd); err != nil {
|
if _, err := runRemote(cmd); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
@@ -319,12 +440,12 @@ func sudoersContent(user string) string {
|
|||||||
|
|
||||||
// writeSudoers writes the /etc/sudoers.d/orca file on the remote host
|
// writeSudoers writes the /etc/sudoers.d/orca file on the remote host
|
||||||
// with mode 0440. Uses a heredoc via cat to avoid quoting issues.
|
// with mode 0440. Uses a heredoc via cat to avoid quoting issues.
|
||||||
func writeSudoers(conn *ssh.Client, user string) error {
|
func writeSudoers(user string) error {
|
||||||
content := sudoersContent(user)
|
content := sudoersContent(user)
|
||||||
// Write via cat heredoc, then chmod 0440.
|
// Write via cat heredoc, then chmod 0440.
|
||||||
cmd := fmt.Sprintf("cat > /etc/sudoers.d/%s <<'ORCA_SUDOERS_EOF'\n%s\nORCA_SUDOERS_EOF\nchmod 0440 /etc/sudoers.d/%s",
|
cmd := fmt.Sprintf("cat > /etc/sudoers.d/%s <<'ORCA_SUDOERS_EOF'\n%s\nORCA_SUDOERS_EOF\nchmod 0440 /etc/sudoers.d/%s",
|
||||||
user, content, user)
|
user, content, user)
|
||||||
if _, err := runRemote(conn, cmd); err != nil {
|
if _, err := runRemote(cmd); err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
@@ -333,9 +454,9 @@ func writeSudoers(conn *ssh.Client, user string) error {
|
|||||||
// validateSudoers runs `visudo -cf` on the sudoers file. Aborts the
|
// validateSudoers runs `visudo -cf` on the sudoers file. Aborts the
|
||||||
// bootstrap if validation fails (prevents a broken sudoers from
|
// bootstrap if validation fails (prevents a broken sudoers from
|
||||||
// locking the orca user out of sudo).
|
// locking the orca user out of sudo).
|
||||||
func validateSudoers(conn *ssh.Client) error {
|
func validateSudoers() error {
|
||||||
cmd := "visudo -cf /etc/sudoers.d/orca"
|
cmd := "visudo -cf /etc/sudoers.d/orca"
|
||||||
out, err := runRemote(conn, cmd)
|
out, err := runRemote(cmd)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("visudo validation failed: %w (output: %s)", err, strings.TrimSpace(string(out)))
|
return fmt.Errorf("visudo validation failed: %w (output: %s)", err, strings.TrimSpace(string(out)))
|
||||||
}
|
}
|
||||||
@@ -344,3 +465,59 @@ func validateSudoers(conn *ssh.Client) error {
|
|||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ResetHostKey removes all known_hosts entries for the given host from
|
||||||
|
// certpaths.KnownHostsPath() (REQ-059, D-046, AD-029). It rewrites the
|
||||||
|
// file atomically via security.WriteAtomic. LOCAL ONLY — it does NOT
|
||||||
|
// touch the remote host's authorized_keys (D-046). The next connect
|
||||||
|
// re-pins the host key via TOFU (T02.6) or the --host-key-fingerprint
|
||||||
|
// pinned path (T02.5).
|
||||||
|
//
|
||||||
|
// A line matches when its first whitespace-delimited field (the host
|
||||||
|
// pattern, normalized via knownhosts.Normalize) equals the normalized
|
||||||
|
// target host. Comment/blank lines are preserved.
|
||||||
|
func ResetHostKey(host string) error {
|
||||||
|
if host == "" {
|
||||||
|
return fmt.Errorf("ResetHostKey: host is required")
|
||||||
|
}
|
||||||
|
path := certpaths.KnownHostsPath()
|
||||||
|
existing, err := os.ReadFile(path)
|
||||||
|
if err != nil {
|
||||||
|
if os.IsNotExist(err) {
|
||||||
|
return nil // nothing to reset
|
||||||
|
}
|
||||||
|
return fmt.Errorf("ResetHostKey: read known_hosts: %w", err)
|
||||||
|
}
|
||||||
|
target := knownhosts.Normalize(host)
|
||||||
|
var kept []byte
|
||||||
|
removed := 0
|
||||||
|
for _, line := range strings.Split(string(existing), "\n") {
|
||||||
|
trimmed := strings.TrimSpace(line)
|
||||||
|
if trimmed == "" || strings.HasPrefix(trimmed, "#") {
|
||||||
|
kept = append(kept, []byte(line+"\n")...)
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
fields := strings.Fields(trimmed)
|
||||||
|
if len(fields) == 0 {
|
||||||
|
kept = append(kept, []byte(line+"\n")...)
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if knownhosts.Normalize(fields[0]) == target {
|
||||||
|
removed++
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
kept = append(kept, []byte(line+"\n")...)
|
||||||
|
}
|
||||||
|
if removed == 0 {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
// Ensure the kept buffer ends with exactly one trailing newline.
|
||||||
|
kept = bytes.TrimRight(kept, "\n")
|
||||||
|
if len(kept) > 0 {
|
||||||
|
kept = append(kept, '\n')
|
||||||
|
}
|
||||||
|
if err := security.WriteAtomic(path, 0o600, kept); err != nil {
|
||||||
|
return fmt.Errorf("ResetHostKey: rewrite known_hosts: %w", err)
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,514 @@
|
|||||||
|
package proxmox
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"context"
|
||||||
|
"crypto/ed25519"
|
||||||
|
"crypto/rand"
|
||||||
|
"errors"
|
||||||
|
"log/slog"
|
||||||
|
"net"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"sync"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"golang.org/x/crypto/ssh"
|
||||||
|
)
|
||||||
|
|
||||||
|
type fakeSSHServer struct {
|
||||||
|
listener net.Listener
|
||||||
|
config *ssh.ServerConfig
|
||||||
|
done chan struct{}
|
||||||
|
|
||||||
|
mu sync.Mutex
|
||||||
|
state map[string]string
|
||||||
|
authDir string
|
||||||
|
forceSudoersInvalid bool
|
||||||
|
hostSigner ssh.Signer
|
||||||
|
}
|
||||||
|
|
||||||
|
func newFakeSSHServer(t *testing.T) *fakeSSHServer {
|
||||||
|
t.Helper()
|
||||||
|
_, priv, err := ed25519.GenerateKey(rand.Reader)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ed25519 gen: %v", err)
|
||||||
|
}
|
||||||
|
hostSigner, err := ssh.NewSignerFromKey(priv)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ssh signer: %v", err)
|
||||||
|
}
|
||||||
|
config := &ssh.ServerConfig{
|
||||||
|
PasswordCallback: func(c ssh.ConnMetadata, password []byte) (*ssh.Permissions, error) {
|
||||||
|
if string(password) != "pw" {
|
||||||
|
return nil, errors.New("invalid password")
|
||||||
|
}
|
||||||
|
return nil, nil
|
||||||
|
},
|
||||||
|
}
|
||||||
|
config.AddHostKey(hostSigner)
|
||||||
|
|
||||||
|
ln, err := net.Listen("tcp", "127.0.0.1:0")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("listen: %v", err)
|
||||||
|
}
|
||||||
|
srv := &fakeSSHServer{
|
||||||
|
listener: ln,
|
||||||
|
config: config,
|
||||||
|
done: make(chan struct{}),
|
||||||
|
state: make(map[string]string),
|
||||||
|
authDir: t.TempDir(),
|
||||||
|
hostSigner: hostSigner,
|
||||||
|
}
|
||||||
|
go srv.serve()
|
||||||
|
return srv
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *fakeSSHServer) addr() string { return s.listener.Addr().String() }
|
||||||
|
|
||||||
|
// hostPublicKey returns the server's SSH host public key. Used by
|
||||||
|
// callback tests to compute the pinned fingerprint the operator would
|
||||||
|
// supply, and to feed the callback the exact key the server presents.
|
||||||
|
func (s *fakeSSHServer) hostPublicKey() ssh.PublicKey {
|
||||||
|
if s.hostSigner == nil {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
return s.hostSigner.PublicKey()
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *fakeSSHServer) serve() {
|
||||||
|
for {
|
||||||
|
conn, err := s.listener.Accept()
|
||||||
|
if err != nil {
|
||||||
|
close(s.done)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
go s.handle(conn)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *fakeSSHServer) handle(netConn net.Conn) {
|
||||||
|
defer netConn.Close()
|
||||||
|
_, chans, reqs, err := ssh.NewServerConn(netConn, s.config)
|
||||||
|
if err != nil {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
go ssh.DiscardRequests(reqs)
|
||||||
|
for newChan := range chans {
|
||||||
|
if newChan.ChannelType() != "session" {
|
||||||
|
newChan.Reject(ssh.UnknownChannelType, "only session")
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
go s.handleSession(newChan)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *fakeSSHServer) handleSession(newChan ssh.NewChannel) {
|
||||||
|
ch, reqs, err := newChan.Accept()
|
||||||
|
if err != nil {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
defer ch.Close()
|
||||||
|
for req := range reqs {
|
||||||
|
switch req.Type {
|
||||||
|
case "exec":
|
||||||
|
var execReq struct{ Command string }
|
||||||
|
if err := ssh.Unmarshal(req.Payload, &execReq); err != nil {
|
||||||
|
req.Reply(false, nil)
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
req.Reply(true, nil)
|
||||||
|
out, code := s.runCommand(execReq.Command)
|
||||||
|
_, _ = ch.Write(out)
|
||||||
|
_, _ = ch.SendRequest("exit-status", false, ssh.Marshal(struct{ Code uint32 }{uint32(code)}))
|
||||||
|
_ = ch.Close()
|
||||||
|
default:
|
||||||
|
req.Reply(false, nil)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *fakeSSHServer) runCommand(cmd string) ([]byte, int) {
|
||||||
|
s.mu.Lock()
|
||||||
|
defer s.mu.Unlock()
|
||||||
|
trimmed := strings.TrimSpace(cmd)
|
||||||
|
switch {
|
||||||
|
case trimmed == "echo hello":
|
||||||
|
return []byte("hello\n"), 0
|
||||||
|
case strings.HasPrefix(trimmed, "exit "):
|
||||||
|
return nil, 1
|
||||||
|
case strings.HasPrefix(trimmed, "id -u "):
|
||||||
|
return []byte("1000\n"), 0
|
||||||
|
case strings.Contains(trimmed, "pveum role list") || strings.Contains(trimmed, "pveum role add"):
|
||||||
|
s.state["pve_role:"+extractField(trimmed, "add ", " ")] = "ok"
|
||||||
|
return nil, 0
|
||||||
|
case strings.Contains(trimmed, "pveum user list") || strings.Contains(trimmed, "pveum user add"):
|
||||||
|
s.state["pve_user:orca@pam"] = "ok"
|
||||||
|
return nil, 0
|
||||||
|
case strings.Contains(trimmed, "pveum acl modify"):
|
||||||
|
s.state["pve_acl"] = "ok"
|
||||||
|
return nil, 0
|
||||||
|
case strings.HasPrefix(trimmed, "mkdir -p ") && strings.Contains(trimmed, "authorized_keys"):
|
||||||
|
return s.handleAuthKeyDeploy(trimmed)
|
||||||
|
case strings.HasPrefix(trimmed, "cat > /etc/sudoers.d/"):
|
||||||
|
return s.handleSudoersWrite(trimmed), 0
|
||||||
|
case strings.HasPrefix(trimmed, "visudo -cf /etc/sudoers.d/orca"):
|
||||||
|
force := s.forceSudoersInvalid
|
||||||
|
if force || s.state["sudoers_valid"] != "true" {
|
||||||
|
return []byte("/etc/sudoers.d/orca: syntax error\n"), 1
|
||||||
|
}
|
||||||
|
return []byte("/etc/sudoers.d/orca: parsed OK\n"), 0
|
||||||
|
case strings.HasPrefix(trimmed, "cat /") && strings.HasSuffix(trimmed, "/authorized_keys"):
|
||||||
|
return s.readAuthFile(trimmed[4:]), 0
|
||||||
|
case strings.HasPrefix(trimmed, "cat /") && strings.Contains(trimmed, "/orca"):
|
||||||
|
return s.readSudoers(trimmed[4:]), 0
|
||||||
|
default:
|
||||||
|
return []byte("sh: command not found\n"), 127
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *fakeSSHServer) handleAuthKeyDeploy(cmd string) ([]byte, int) {
|
||||||
|
parts := strings.Split(cmd, "'")
|
||||||
|
var pubLine string
|
||||||
|
if len(parts) >= 2 {
|
||||||
|
pubLine = parts[1]
|
||||||
|
}
|
||||||
|
authPath := filepath.Join(s.authDir, "authorized_keys")
|
||||||
|
existing := string(s.readFile(authPath))
|
||||||
|
if !strings.Contains(existing, pubLine) {
|
||||||
|
existing += pubLine + "\n"
|
||||||
|
}
|
||||||
|
if err := os.WriteFile(authPath, []byte(existing), 0o600); err != nil {
|
||||||
|
return []byte("mkdir: permission denied\n"), 1
|
||||||
|
}
|
||||||
|
return nil, 0
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *fakeSSHServer) readAuthFile(path string) []byte {
|
||||||
|
if strings.HasSuffix(path, "/authorized_keys") {
|
||||||
|
return s.readFile(filepath.Join(s.authDir, "authorized_keys"))
|
||||||
|
}
|
||||||
|
return []byte("cat: " + path + ": No such file or directory\n")
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *fakeSSHServer) handleSudoersWrite(cmd string) []byte {
|
||||||
|
idx := strings.Index(cmd, "\n")
|
||||||
|
if idx < 0 {
|
||||||
|
return []byte("sh: bad heredoc\n")
|
||||||
|
}
|
||||||
|
content := cmd[idx+1:]
|
||||||
|
if end := strings.Index(content, "ORCA_SUDOERS_EOF"); end >= 0 {
|
||||||
|
content = content[:end]
|
||||||
|
}
|
||||||
|
s.state["sudoers_content"] = content
|
||||||
|
s.state["sudoers_valid"] = "true"
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *fakeSSHServer) readSudoers(path string) []byte {
|
||||||
|
if v, ok := s.state["sudoers_content"]; ok {
|
||||||
|
return []byte(v)
|
||||||
|
}
|
||||||
|
return []byte("cat: " + path + ": No such file or directory\n")
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *fakeSSHServer) readFile(path string) []byte {
|
||||||
|
b, _ := os.ReadFile(path)
|
||||||
|
return b
|
||||||
|
}
|
||||||
|
|
||||||
|
func (s *fakeSSHServer) close() {
|
||||||
|
s.listener.Close()
|
||||||
|
<-s.done
|
||||||
|
}
|
||||||
|
|
||||||
|
func extractField(s, after, until string) string {
|
||||||
|
i := strings.Index(s, after)
|
||||||
|
if i < 0 {
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
rest := s[i+len(after):]
|
||||||
|
j := strings.Index(rest, until)
|
||||||
|
if j < 0 {
|
||||||
|
return rest
|
||||||
|
}
|
||||||
|
return rest[:j]
|
||||||
|
}
|
||||||
|
|
||||||
|
func fakeSSHClient(t *testing.T, srv *fakeSSHServer) *ssh.Client {
|
||||||
|
t.Helper()
|
||||||
|
config := &ssh.ClientConfig{
|
||||||
|
User: "root",
|
||||||
|
Auth: []ssh.AuthMethod{ssh.Password("pw")},
|
||||||
|
HostKeyCallback: ssh.InsecureIgnoreHostKey(),
|
||||||
|
Timeout: 5 * time.Second,
|
||||||
|
}
|
||||||
|
client, err := ssh.Dial("tcp", srv.addr(), config)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ssh.Dial: %v", err)
|
||||||
|
}
|
||||||
|
return client
|
||||||
|
}
|
||||||
|
|
||||||
|
func withSessionRunner(t *testing.T, conn *ssh.Client) {
|
||||||
|
t.Helper()
|
||||||
|
orig := sessionRunner
|
||||||
|
t.Cleanup(func() { sessionRunner = orig })
|
||||||
|
sessionRunner = &sshSessionRunner{client: conn}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRunRemote_Success(t *testing.T) {
|
||||||
|
srv := newFakeSSHServer(t)
|
||||||
|
defer srv.close()
|
||||||
|
conn := fakeSSHClient(t, srv)
|
||||||
|
defer conn.Close()
|
||||||
|
withSessionRunner(t, conn)
|
||||||
|
out, err := runRemote("echo hello")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("runRemote: %v", err)
|
||||||
|
}
|
||||||
|
if strings.TrimSpace(string(out)) != "hello" {
|
||||||
|
t.Errorf("output = %q, want hello", strings.TrimSpace(string(out)))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRunRemote_Failure(t *testing.T) {
|
||||||
|
srv := newFakeSSHServer(t)
|
||||||
|
defer srv.close()
|
||||||
|
conn := fakeSSHClient(t, srv)
|
||||||
|
defer conn.Close()
|
||||||
|
withSessionRunner(t, conn)
|
||||||
|
_, err := runRemote("exit 7")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for non-zero exit")
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), "run") {
|
||||||
|
t.Errorf("error should mention run, got: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDeployPubKey_Success(t *testing.T) {
|
||||||
|
srv := newFakeSSHServer(t)
|
||||||
|
defer srv.close()
|
||||||
|
conn := fakeSSHClient(t, srv)
|
||||||
|
defer conn.Close()
|
||||||
|
withSessionRunner(t, conn)
|
||||||
|
|
||||||
|
if err := deployPubKey("orca", "ssh-ed25519 AAAA test@orca"); err != nil {
|
||||||
|
t.Fatalf("deployPubKey: %v", err)
|
||||||
|
}
|
||||||
|
out := srv.readFile(filepath.Join(srv.authDir, "authorized_keys"))
|
||||||
|
if !strings.Contains(string(out), "ssh-ed25519 AAAA test@orca") {
|
||||||
|
t.Errorf("auth file does not contain the key: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDeployPubKey_Idempotent(t *testing.T) {
|
||||||
|
srv := newFakeSSHServer(t)
|
||||||
|
defer srv.close()
|
||||||
|
conn := fakeSSHClient(t, srv)
|
||||||
|
defer conn.Close()
|
||||||
|
withSessionRunner(t, conn)
|
||||||
|
|
||||||
|
if err := deployPubKey("orca", "ssh-ed25519 AAAA test@orca"); err != nil {
|
||||||
|
t.Fatalf("first deploy: %v", err)
|
||||||
|
}
|
||||||
|
if err := deployPubKey("orca", "ssh-ed25519 AAAA test@orca"); err != nil {
|
||||||
|
t.Fatalf("second deploy: %v", err)
|
||||||
|
}
|
||||||
|
out := srv.readFile(filepath.Join(srv.authDir, "authorized_keys"))
|
||||||
|
if cnt := strings.Count(string(out), "ssh-ed25519 AAAA test@orca"); cnt != 1 {
|
||||||
|
t.Errorf("key count = %d, want 1 (idempotent)", cnt)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestCreateLinuxUser_Success(t *testing.T) {
|
||||||
|
srv := newFakeSSHServer(t)
|
||||||
|
defer srv.close()
|
||||||
|
conn := fakeSSHClient(t, srv)
|
||||||
|
defer conn.Close()
|
||||||
|
withSessionRunner(t, conn)
|
||||||
|
if err := createLinuxUser("orca"); err != nil {
|
||||||
|
t.Fatalf("createLinuxUser: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestCreatePVERole_Success(t *testing.T) {
|
||||||
|
srv := newFakeSSHServer(t)
|
||||||
|
defer srv.close()
|
||||||
|
conn := fakeSSHClient(t, srv)
|
||||||
|
defer conn.Close()
|
||||||
|
withSessionRunner(t, conn)
|
||||||
|
if err := createPVERole("OrcaOperator"); err != nil {
|
||||||
|
t.Fatalf("createPVERole: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestCreatePVEUser_Success(t *testing.T) {
|
||||||
|
srv := newFakeSSHServer(t)
|
||||||
|
defer srv.close()
|
||||||
|
conn := fakeSSHClient(t, srv)
|
||||||
|
defer conn.Close()
|
||||||
|
withSessionRunner(t, conn)
|
||||||
|
if err := createPVEUser("orca"); err != nil {
|
||||||
|
t.Fatalf("createPVEUser: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAssignPVEACL_Success(t *testing.T) {
|
||||||
|
srv := newFakeSSHServer(t)
|
||||||
|
defer srv.close()
|
||||||
|
conn := fakeSSHClient(t, srv)
|
||||||
|
defer conn.Close()
|
||||||
|
withSessionRunner(t, conn)
|
||||||
|
if err := assignPVEACL("orca", "OrcaOperator"); err != nil {
|
||||||
|
t.Fatalf("assignPVEACL: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestWriteSudoers_Success(t *testing.T) {
|
||||||
|
srv := newFakeSSHServer(t)
|
||||||
|
defer srv.close()
|
||||||
|
conn := fakeSSHClient(t, srv)
|
||||||
|
defer conn.Close()
|
||||||
|
withSessionRunner(t, conn)
|
||||||
|
|
||||||
|
if err := writeSudoers("orca"); err != nil {
|
||||||
|
t.Fatalf("writeSudoers: %v", err)
|
||||||
|
}
|
||||||
|
if srv.state["sudoers_valid"] != "true" {
|
||||||
|
t.Error("sudoers not marked valid")
|
||||||
|
}
|
||||||
|
if !strings.Contains(srv.state["sudoers_content"], "orca ALL=(root) NOPASSWD: NOEXEC: /usr/bin/pct") {
|
||||||
|
t.Errorf("sudoers content missing pct: %s", srv.state["sudoers_content"])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestValidateSudoers_ParsedOK(t *testing.T) {
|
||||||
|
srv := newFakeSSHServer(t)
|
||||||
|
defer srv.close()
|
||||||
|
conn := fakeSSHClient(t, srv)
|
||||||
|
defer conn.Close()
|
||||||
|
withSessionRunner(t, conn)
|
||||||
|
|
||||||
|
srv.state["sudoers_valid"] = "true"
|
||||||
|
if err := validateSudoers(); err != nil {
|
||||||
|
t.Errorf("validateSudoers: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestValidateSudoers_Failure(t *testing.T) {
|
||||||
|
srv := newFakeSSHServer(t)
|
||||||
|
defer srv.close()
|
||||||
|
conn := fakeSSHClient(t, srv)
|
||||||
|
defer conn.Close()
|
||||||
|
withSessionRunner(t, conn)
|
||||||
|
|
||||||
|
srv.state["sudoers_valid"] = "false"
|
||||||
|
if err := validateSudoers(); err == nil {
|
||||||
|
t.Error("expected error for invalid sudoers")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
type staticDialer struct {
|
||||||
|
client *ssh.Client
|
||||||
|
}
|
||||||
|
|
||||||
|
func (d *staticDialer) DialContext(ctx context.Context, network, addr string, config *ssh.ClientConfig) (*ssh.Client, error) {
|
||||||
|
return d.client, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
type funcDialer struct {
|
||||||
|
fn func(ctx context.Context, network, addr string, config *ssh.ClientConfig) (*ssh.Client, error)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (d *funcDialer) DialContext(ctx context.Context, network, addr string, config *ssh.ClientConfig) (*ssh.Client, error) {
|
||||||
|
return d.fn(ctx, network, addr, config)
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestBootstrapProxmox_FullFlow_Success(t *testing.T) {
|
||||||
|
srv := newFakeSSHServer(t)
|
||||||
|
defer srv.close()
|
||||||
|
|
||||||
|
home := t.TempDir()
|
||||||
|
t.Setenv("ORCA_HOME", home)
|
||||||
|
if err := os.WriteFile(filepath.Join(home, "known_hosts"), []byte{}, 0o600); err != nil {
|
||||||
|
t.Fatalf("create known_hosts: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
orig := sshDialer
|
||||||
|
defer func() { sshDialer = orig }()
|
||||||
|
origRunner := sessionRunner
|
||||||
|
defer func() { sessionRunner = origRunner }()
|
||||||
|
sessionRunner = nil
|
||||||
|
sshDialer = &staticDialer{client: fakeSSHClient(t, srv)}
|
||||||
|
|
||||||
|
host, _, _ := net.SplitHostPort(srv.addr())
|
||||||
|
|
||||||
|
var logBuf bytes.Buffer
|
||||||
|
result, err := BootstrapProxmox(t.Context(), Options{
|
||||||
|
Host: host,
|
||||||
|
Password: "pw",
|
||||||
|
Logger: slog.New(slog.NewTextHandler(&logBuf, nil)),
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("BootstrapProxmox: %v", err)
|
||||||
|
}
|
||||||
|
if result == nil {
|
||||||
|
t.Fatal("result is nil")
|
||||||
|
}
|
||||||
|
if result.NodeName != host {
|
||||||
|
t.Errorf("NodeName = %q, want %q", result.NodeName, host)
|
||||||
|
}
|
||||||
|
if result.NodeAddress != host+":8443" {
|
||||||
|
t.Errorf("NodeAddress = %q, want %q:8443", result.NodeAddress, host)
|
||||||
|
}
|
||||||
|
if !strings.Contains(logBuf.String(), "proxmox.bootstrap_ok") {
|
||||||
|
t.Errorf("expected bootstrap_ok log, got: %s", logBuf.String())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestBootstrapProxmox_FullFlow_DeployPubKeyFails(t *testing.T) {
|
||||||
|
srv := newFakeSSHServer(t)
|
||||||
|
defer srv.close()
|
||||||
|
|
||||||
|
home := t.TempDir()
|
||||||
|
t.Setenv("ORCA_HOME", home)
|
||||||
|
if err := os.WriteFile(filepath.Join(home, "known_hosts"), []byte{}, 0o600); err != nil {
|
||||||
|
t.Fatalf("create known_hosts: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
orig := sshDialer
|
||||||
|
defer func() { sshDialer = orig }()
|
||||||
|
origRunner := sessionRunner
|
||||||
|
defer func() { sessionRunner = origRunner }()
|
||||||
|
sessionRunner = nil
|
||||||
|
|
||||||
|
// Use a real client that connects to a server which will reject deploy
|
||||||
|
// by returning a non-zero exit for the mkdir command. We achieve this
|
||||||
|
// by using a dialer that returns a client to a server whose authDir
|
||||||
|
// is read-only — but simpler: just use a fresh server that errors on
|
||||||
|
// authorized_keys commands via a custom server. We reuse newFakeSSHServer
|
||||||
|
// but sabotage it by pointing authDir to a read-only location.
|
||||||
|
conn := fakeSSHClient(t, srv)
|
||||||
|
defer conn.Close()
|
||||||
|
sshDialer = &staticDialer{client: conn}
|
||||||
|
|
||||||
|
host, _, _ := net.SplitHostPort(srv.addr())
|
||||||
|
|
||||||
|
// Make authDir unwritable so deployPubKey's mkdir handler fails.
|
||||||
|
srv.authDir = "/proc/1/forbidden-orca-test"
|
||||||
|
|
||||||
|
_, err := BootstrapProxmox(t.Context(), Options{
|
||||||
|
Host: host,
|
||||||
|
Password: "pw",
|
||||||
|
})
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error from deployPubKey failure")
|
||||||
|
}
|
||||||
|
if !strings.Contains(err.Error(), "deploy pubkey") {
|
||||||
|
t.Errorf("error should mention deploy pubkey, got: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
+63
-12
@@ -16,27 +16,51 @@ import (
|
|||||||
|
|
||||||
// CAValidity is how long a CA cert is valid. Per D-013, the CA is long-lived
|
// CAValidity is how long a CA cert is valid. Per D-013, the CA is long-lived
|
||||||
// (10 years) because manual rotation is expensive.
|
// (10 years) because manual rotation is expensive.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). This constant is retained for the dual-write window and
|
||||||
|
// scheduled for deletion in v0.10-P14. See .ciagent/PRD_v0.9.md.
|
||||||
const CAValidity = 10 * 365 * 24 * time.Hour
|
const CAValidity = 10 * 365 * 24 * time.Hour
|
||||||
|
|
||||||
// ServerCertValidity is the default validity window for server certs. D-013
|
// ServerCertValidity is the default validity window for server certs. D-013
|
||||||
// says server certs are short-lived (90 days) to limit the compromise window.
|
// says server certs are short-lived (90 days) to limit the compromise window.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). This constant is retained for the dual-write window and
|
||||||
|
// scheduled for deletion in v0.10-P14. See .ciagent/PRD_v0.9.md.
|
||||||
const ServerCertValidity = 90 * 24 * time.Hour
|
const ServerCertValidity = 90 * 24 * time.Hour
|
||||||
|
|
||||||
// CAKeySize is the RSA key size used for both CA and server certs. 3072 is
|
// CAKeySize is the RSA key size used for both CA and server certs. 3072 is
|
||||||
// the minimum we accept for v0.2 — matches REQ-033 spirit and Go's stdlib
|
// the minimum we accept for v0.2 — matches REQ-033 spirit and Go's stdlib
|
||||||
// defaults for new RSA keys are typically 2048 or 4096. 3072 is the
|
// defaults for new RSA keys are typically 2048 or 4096. 3072 is the
|
||||||
// sweet spot for balance of safety and key-gen latency.
|
// sweet spot for balance of safety and key-gen latency.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). This constant is retained for the dual-write window and
|
||||||
|
// scheduled for deletion in v0.10-P14. See .ciagent/PRD_v0.9.md.
|
||||||
const CAKeySize = 3072
|
const CAKeySize = 3072
|
||||||
|
|
||||||
// CAMode is the file mode used when persisting the CA private key. REQ-033
|
// CAMode is the file mode used when persisting the CA private key. REQ-033
|
||||||
// requires 0600.
|
// requires 0600.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). This constant is retained for the dual-write window and
|
||||||
|
// scheduled for deletion in v0.10-P14. See .ciagent/PRD_v0.9.md.
|
||||||
const CAMode os.FileMode = 0o600
|
const CAMode os.FileMode = 0o600
|
||||||
|
|
||||||
// CACPEMMode is the file mode used when persisting the CA public cert.
|
// CACPEMMode is the file mode used when persisting the CA public cert.
|
||||||
// REQ-033 requires 0644 (public, but still mode-pinned).
|
// REQ-033 requires 0644 (public, but still mode-pinned).
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). This constant is retained for the dual-write window and
|
||||||
|
// scheduled for deletion in v0.10-P14. See .ciagent/PRD_v0.9.md.
|
||||||
const CACPEMMode os.FileMode = 0o644
|
const CACPEMMode os.FileMode = 0o644
|
||||||
|
|
||||||
// File names used inside the CA directory.
|
// File names used inside the CA directory.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). These constants are retained for the dual-write window and
|
||||||
|
// scheduled for deletion in v0.10-P14. See .ciagent/PRD_v0.9.md.
|
||||||
const (
|
const (
|
||||||
CACertFile = "ca.crt"
|
CACertFile = "ca.crt"
|
||||||
CAKeyFile = "ca.key"
|
CAKeyFile = "ca.key"
|
||||||
@@ -44,6 +68,10 @@ const (
|
|||||||
|
|
||||||
// CA wraps a loaded CA. Use CAInit to mint a new one, LoadCA to read an
|
// CA wraps a loaded CA. Use CAInit to mint a new one, LoadCA to read an
|
||||||
// existing one from disk.
|
// existing one from disk.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). The CA type is retained for the dual-write window and
|
||||||
|
// scheduled for deletion in v0.10-P14. See .ciagent/PRD_v0.9.md.
|
||||||
type CA struct {
|
type CA struct {
|
||||||
Cert *x509.Certificate
|
Cert *x509.Certificate
|
||||||
Key *rsa.PrivateKey
|
Key *rsa.PrivateKey
|
||||||
@@ -60,6 +88,10 @@ type CA struct {
|
|||||||
// commonName is the CA's CommonName (typically an org/cluster identifier).
|
// commonName is the CA's CommonName (typically an org/cluster identifier).
|
||||||
// Returns a *CA wrapping the loaded cert + key. The CA is valid for
|
// Returns a *CA wrapping the loaded cert + key. The CA is valid for
|
||||||
// CAValidity from now.
|
// CAValidity from now.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). CAInit is retained for the dual-write window and scheduled
|
||||||
|
// for deletion in v0.10-P14. See .ciagent/PRD_v0.9.md.
|
||||||
func CAInit(dir, commonName string) (*CA, error) {
|
func CAInit(dir, commonName string) (*CA, error) {
|
||||||
if dir == "" {
|
if dir == "" {
|
||||||
return nil, errors.New("CAInit: dir is required")
|
return nil, errors.New("CAInit: dir is required")
|
||||||
@@ -121,10 +153,10 @@ func CAInit(dir, commonName string) (*CA, error) {
|
|||||||
|
|
||||||
// Atomic write: temp file + rename. This avoids leaving a half-written
|
// Atomic write: temp file + rename. This avoids leaving a half-written
|
||||||
// ca.key on disk if the process crashes mid-write.
|
// ca.key on disk if the process crashes mid-write.
|
||||||
if err := writeAtomic(certPath, CACPEMMode, certPEM); err != nil {
|
if err := WriteAtomic(certPath, CACPEMMode, certPEM); err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
if err := writeAtomic(keyPath, CAMode, keyPEM); err != nil {
|
if err := WriteAtomic(keyPath, CAMode, keyPEM); err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -133,6 +165,10 @@ func CAInit(dir, commonName string) (*CA, error) {
|
|||||||
|
|
||||||
// LoadCA reads a previously-initialized CA from disk. Returns a *CA or an
|
// LoadCA reads a previously-initialized CA from disk. Returns a *CA or an
|
||||||
// error. Verifies file modes (REQ-033).
|
// error. Verifies file modes (REQ-033).
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). LoadCA is retained for the dual-write window and scheduled
|
||||||
|
// for deletion in v0.10-P14. See .ciagent/PRD_v0.9.md.
|
||||||
func LoadCA(dir string) (*CA, error) {
|
func LoadCA(dir string) (*CA, error) {
|
||||||
if dir == "" {
|
if dir == "" {
|
||||||
return nil, errors.New("LoadCA: dir is required")
|
return nil, errors.New("LoadCA: dir is required")
|
||||||
@@ -187,6 +223,10 @@ func LoadCA(dir string) (*CA, error) {
|
|||||||
// EnforceFileModes refuses to operate if ca.crt / ca.key do not have the
|
// EnforceFileModes refuses to operate if ca.crt / ca.key do not have the
|
||||||
// required modes (REQ-033). Returns nil on success. Callers (daemon start,
|
// required modes (REQ-033). Returns nil on success. Callers (daemon start,
|
||||||
// CA loaders) MUST call this and abort on error.
|
// CA loaders) MUST call this and abort on error.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). EnforceFileModes is retained for the dual-write window
|
||||||
|
// and scheduled for deletion in v0.10-P14. See .ciagent/PRD_v0.9.md.
|
||||||
func EnforceFileModes(dir string) error {
|
func EnforceFileModes(dir string) error {
|
||||||
certPath := filepath.Join(dir, CACertFile)
|
certPath := filepath.Join(dir, CACertFile)
|
||||||
keyPath := filepath.Join(dir, CAKeyFile)
|
keyPath := filepath.Join(dir, CAKeyFile)
|
||||||
@@ -217,6 +257,10 @@ func EnforceFileModes(dir string) error {
|
|||||||
// in PEM form. The resulting cert is valid for ServerCertValidity and
|
// in PEM form. The resulting cert is valid for ServerCertValidity and
|
||||||
// inherits the SANs from the CSR (DNS, IP). If the CSR has no SANs, the
|
// inherits the SANs from the CSR (DNS, IP). If the CSR has no SANs, the
|
||||||
// call fails — REQ-036 requires server certs to have identifying SANs.
|
// call fails — REQ-036 requires server certs to have identifying SANs.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). SignCSR is retained for the dual-write window and
|
||||||
|
// scheduled for deletion in v0.10-P14. See .ciagent/PRD_v0.9.md.
|
||||||
func (c *CA) SignCSR(csrPEM []byte) ([]byte, error) {
|
func (c *CA) SignCSR(csrPEM []byte) ([]byte, error) {
|
||||||
if c == nil || c.Cert == nil || c.Key == nil {
|
if c == nil || c.Cert == nil || c.Key == nil {
|
||||||
return nil, errors.New("SignCSR: nil CA")
|
return nil, errors.New("SignCSR: nil CA")
|
||||||
@@ -266,6 +310,10 @@ func (c *CA) SignCSR(csrPEM []byte) ([]byte, error) {
|
|||||||
// Fingerprint returns the SHA-256 hex fingerprint of the CA cert. Useful
|
// Fingerprint returns the SHA-256 hex fingerprint of the CA cert. Useful
|
||||||
// for the operator to communicate to peers out-of-band; peers then pin
|
// for the operator to communicate to peers out-of-band; peers then pin
|
||||||
// this value at `orca node join --ca-fingerprint <sha>`.
|
// this value at `orca node join --ca-fingerprint <sha>`.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). CA.Fingerprint is retained for the dual-write window and
|
||||||
|
// scheduled for deletion in v0.10-P14. See .ciagent/PRD_v0.9.md.
|
||||||
func (c *CA) Fingerprint() string {
|
func (c *CA) Fingerprint() string {
|
||||||
return FingerprintOf(c.Cert.Raw)
|
return FingerprintOf(c.Cert.Raw)
|
||||||
}
|
}
|
||||||
@@ -290,23 +338,26 @@ func bothExist(paths ...string) (bool, error) {
|
|||||||
// WriteCert writes a cert PEM blob to path with mode 0644 atomically.
|
// WriteCert writes a cert PEM blob to path with mode 0644 atomically.
|
||||||
// REQ-033 requires cert files to be 0644; this helper enforces that.
|
// REQ-033 requires cert files to be 0644; this helper enforces that.
|
||||||
func WriteCert(path string, pemBytes []byte) error {
|
func WriteCert(path string, pemBytes []byte) error {
|
||||||
return writeAtomic(path, CACPEMMode, pemBytes)
|
return WriteAtomic(path, CACPEMMode, pemBytes)
|
||||||
}
|
}
|
||||||
|
|
||||||
// WriteKey writes a private-key PEM blob to path with mode 0600
|
// WriteKey writes a private-key PEM blob to path with mode 0600
|
||||||
// atomically. REQ-033 requires key files to be 0600; this helper
|
// atomically. REQ-033 requires key files to be 0600; this helper
|
||||||
// enforces that.
|
// enforces that.
|
||||||
func WriteKey(path string, pemBytes []byte) error {
|
func WriteKey(path string, pemBytes []byte) error {
|
||||||
return writeAtomic(path, CAMode, pemBytes)
|
return WriteAtomic(path, CAMode, pemBytes)
|
||||||
}
|
}
|
||||||
|
|
||||||
// writeAtomic writes data to a temp file in dir and renames. Sets the
|
// WriteAtomic writes data to a temp file in dir and renames. Sets the
|
||||||
// requested perm before the rename so the file lands at the right mode.
|
// requested perm before the rename so the file lands at the right mode.
|
||||||
func writeAtomic(path string, mode os.FileMode, data []byte) error {
|
// Exported (AD-029) so the key-reset / known_hosts atomic rewrite path
|
||||||
|
// in proxmox (T02.6/T02.7) can reuse it instead of duplicating the
|
||||||
|
// ~20-LOC pattern (RESEARCH §5 pitfall #10).
|
||||||
|
func WriteAtomic(path string, mode os.FileMode, data []byte) error {
|
||||||
dir := filepath.Dir(path)
|
dir := filepath.Dir(path)
|
||||||
tmp, err := os.CreateTemp(dir, ".tmp-*")
|
tmp, err := os.CreateTemp(dir, ".tmp-*")
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("writeAtomic: create temp: %w", err)
|
return fmt.Errorf("WriteAtomic: create temp: %w", err)
|
||||||
}
|
}
|
||||||
tmpName := tmp.Name()
|
tmpName := tmp.Name()
|
||||||
// Best-effort cleanup if we fail before rename.
|
// Best-effort cleanup if we fail before rename.
|
||||||
@@ -315,21 +366,21 @@ func writeAtomic(path string, mode os.FileMode, data []byte) error {
|
|||||||
}()
|
}()
|
||||||
if _, err := tmp.Write(data); err != nil {
|
if _, err := tmp.Write(data); err != nil {
|
||||||
_ = tmp.Close()
|
_ = tmp.Close()
|
||||||
return fmt.Errorf("writeAtomic: write: %w", err)
|
return fmt.Errorf("WriteAtomic: write: %w", err)
|
||||||
}
|
}
|
||||||
if err := tmp.Chmod(mode); err != nil {
|
if err := tmp.Chmod(mode); err != nil {
|
||||||
_ = tmp.Close()
|
_ = tmp.Close()
|
||||||
return fmt.Errorf("writeAtomic: chmod: %w", err)
|
return fmt.Errorf("WriteAtomic: chmod: %w", err)
|
||||||
}
|
}
|
||||||
if err := tmp.Sync(); err != nil {
|
if err := tmp.Sync(); err != nil {
|
||||||
_ = tmp.Close()
|
_ = tmp.Close()
|
||||||
return fmt.Errorf("writeAtomic: sync: %w", err)
|
return fmt.Errorf("WriteAtomic: sync: %w", err)
|
||||||
}
|
}
|
||||||
if err := tmp.Close(); err != nil {
|
if err := tmp.Close(); err != nil {
|
||||||
return fmt.Errorf("writeAtomic: close: %w", err)
|
return fmt.Errorf("WriteAtomic: close: %w", err)
|
||||||
}
|
}
|
||||||
if err := os.Rename(tmpName, path); err != nil {
|
if err := os.Rename(tmpName, path); err != nil {
|
||||||
return fmt.Errorf("writeAtomic: rename: %w", err)
|
return fmt.Errorf("WriteAtomic: rename: %w", err)
|
||||||
}
|
}
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -21,6 +21,10 @@ import (
|
|||||||
// Validation: dns entries must be syntactically valid hostnames; ip entries
|
// Validation: dns entries must be syntactically valid hostnames; ip entries
|
||||||
// must be parseable by net.ParseIP. Bad inputs are rejected up-front so
|
// must be parseable by net.ParseIP. Bad inputs are rejected up-front so
|
||||||
// the operator gets a clear error before signing.
|
// the operator gets a clear error before signing.
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces the internal CA with step-ca
|
||||||
|
// (D-101/REQ-076). GenerateCSR is retained for the dual-write window and
|
||||||
|
// scheduled for deletion in v0.10-P14. See .ciagent/PRD_v0.9.md.
|
||||||
func GenerateCSR(commonName string, sans []string) (keyPEM, csrPEM []byte, err error) {
|
func GenerateCSR(commonName string, sans []string) (keyPEM, csrPEM []byte, err error) {
|
||||||
if commonName == "" {
|
if commonName == "" {
|
||||||
return nil, nil, errors.New("GenerateCSR: commonName is required")
|
return nil, nil, errors.New("GenerateCSR: commonName is required")
|
||||||
|
|||||||
@@ -26,6 +26,17 @@ const (
|
|||||||
sshPubFile = "orca_ssh_key.pub"
|
sshPubFile = "orca_ssh_key.pub"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
// SSHFingerprintSHA256 returns the canonical SSH public-key fingerprint
|
||||||
|
// in the form `SHA256:base64` (no trailing padding), as produced by
|
||||||
|
// `ssh-keygen -lf` and OpenSSH's host-key verification prompts. This is
|
||||||
|
// a thin wrapper over ssh.FingerprintSHA256 (AD-027) for use by the
|
||||||
|
// proxmox bootstrap pinned-host-key callback (REQ-058) and any other
|
||||||
|
// SSH-domain identity checks. Do NOT reuse security.Fingerprint — that
|
||||||
|
// returns an X.509 DER hex digest (different domain; RESEARCH §2.2).
|
||||||
|
func SSHFingerprintSHA256(pubKey ssh.PublicKey) string {
|
||||||
|
return ssh.FingerprintSHA256(pubKey)
|
||||||
|
}
|
||||||
|
|
||||||
// GenerateOrLoadSSHKey returns the orca SSH keypair, generating it
|
// GenerateOrLoadSSHKey returns the orca SSH keypair, generating it
|
||||||
// lazily on first call (D-037). The key is Ed25519 (smaller, faster,
|
// lazily on first call (D-037). The key is Ed25519 (smaller, faster,
|
||||||
// more secure than RSA for SSH auth), persisted as PKCS8 PEM to
|
// more secure than RSA for SSH auth), persisted as PKCS8 PEM to
|
||||||
@@ -84,10 +95,10 @@ func GenerateOrLoadSSHKey(dir string) (keyPEM, pubLine []byte, err error) {
|
|||||||
pubLine = ssh.MarshalAuthorizedKey(sshPub)
|
pubLine = ssh.MarshalAuthorizedKey(sshPub)
|
||||||
|
|
||||||
// Persist with correct modes (atomic write + chmod).
|
// Persist with correct modes (atomic write + chmod).
|
||||||
if err := writeAtomic(keyPath, SSHKeyMode, keyPEM); err != nil {
|
if err := WriteAtomic(keyPath, SSHKeyMode, keyPEM); err != nil {
|
||||||
return nil, nil, fmt.Errorf("write SSH key: %w", err)
|
return nil, nil, fmt.Errorf("write SSH key: %w", err)
|
||||||
}
|
}
|
||||||
if err := writeAtomic(pubPath, SSHPubMode, pubLine); err != nil {
|
if err := WriteAtomic(pubPath, SSHPubMode, pubLine); err != nil {
|
||||||
return nil, nil, fmt.Errorf("write SSH pub: %w", err)
|
return nil, nil, fmt.Errorf("write SSH pub: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
package security
|
package security
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"crypto/ed25519"
|
||||||
|
"crypto/rand"
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"strings"
|
"strings"
|
||||||
@@ -91,3 +93,43 @@ func TestGenerateOrLoadSSHKey_CreatesDir(t *testing.T) {
|
|||||||
t.Errorf("nested dir not created: %v", err)
|
t.Errorf("nested dir not created: %v", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestSSHFingerprintSHA256_Ed25519(t *testing.T) {
|
||||||
|
pub, _, err := ed25519.GenerateKey(rand.Reader)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ed25519 gen: %v", err)
|
||||||
|
}
|
||||||
|
sshPub, err := ssh.NewPublicKey(pub)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("new pubkey: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
got := SSHFingerprintSHA256(sshPub)
|
||||||
|
|
||||||
|
// Canonical form: SHA256: followed by unpadded base64.
|
||||||
|
if !strings.HasPrefix(got, "SHA256:") {
|
||||||
|
t.Fatalf("fingerprint = %q, want SHA256: prefix", got)
|
||||||
|
}
|
||||||
|
// Must match the reference implementation exactly.
|
||||||
|
want := ssh.FingerprintSHA256(sshPub)
|
||||||
|
if got != want {
|
||||||
|
t.Errorf("SSHFingerprintSHA256 = %q, want %q", got, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSSHFingerprintSHA256_StableAcrossCalls(t *testing.T) {
|
||||||
|
pub, _, err := ed25519.GenerateKey(rand.Reader)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ed25519 gen: %v", err)
|
||||||
|
}
|
||||||
|
sshPub, err := ssh.NewPublicKey(pub)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("new pubkey: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
a := SSHFingerprintSHA256(sshPub)
|
||||||
|
b := SSHFingerprintSHA256(sshPub)
|
||||||
|
if a != b {
|
||||||
|
t.Errorf("fingerprint not stable: %q vs %q", a, b)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -65,3 +65,87 @@ func TestAuditRepo_WithError(t *testing.T) {
|
|||||||
t.Errorf("expected error 'exit status 1', got %q", entries[0].Error)
|
t.Errorf("expected error 'exit status 1', got %q", entries[0].Error)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestAuditRepo_MetadataRoundTrip(t *testing.T) {
|
||||||
|
repo, cleanup := openAuditTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
want := map[string]any{"node": "node-1", "exit_code": float64(2)}
|
||||||
|
if err := repo.Append(ctx, &AuditEntry{
|
||||||
|
Actor: "cli",
|
||||||
|
Action: "node.join",
|
||||||
|
Resource: "node-1",
|
||||||
|
Result: "success",
|
||||||
|
Metadata: want,
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("append: %v", err)
|
||||||
|
}
|
||||||
|
entries, err := repo.List(ctx, 10)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("List: %v", err)
|
||||||
|
}
|
||||||
|
if len(entries) != 1 {
|
||||||
|
t.Fatalf("expected 1 entry, got %d", len(entries))
|
||||||
|
}
|
||||||
|
if entries[0].Metadata == nil {
|
||||||
|
t.Fatalf("metadata not round-tripped")
|
||||||
|
}
|
||||||
|
if entries[0].Metadata["node"] != "node-1" {
|
||||||
|
t.Errorf("metadata[node] = %v, want node-1", entries[0].Metadata["node"])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAuditRepo_DefaultActorAndTimestamp(t *testing.T) {
|
||||||
|
repo, cleanup := openAuditTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
// Append with empty Actor and zero Timestamp — defaults should apply.
|
||||||
|
if err := repo.Append(ctx, &AuditEntry{
|
||||||
|
Action: "x",
|
||||||
|
Resource: "y",
|
||||||
|
Result: "success",
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("append: %v", err)
|
||||||
|
}
|
||||||
|
entries, _ := repo.List(ctx, 1)
|
||||||
|
if len(entries) != 1 {
|
||||||
|
t.Fatalf("expected 1 entry, got %d", len(entries))
|
||||||
|
}
|
||||||
|
if entries[0].Actor != "system" {
|
||||||
|
t.Errorf("default actor = %q, want system", entries[0].Actor)
|
||||||
|
}
|
||||||
|
if entries[0].Timestamp.IsZero() {
|
||||||
|
t.Errorf("default timestamp not set")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAuditRepo_ListDefaultLimit(t *testing.T) {
|
||||||
|
repo, cleanup := openAuditTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
for i := 0; i < 5; i++ {
|
||||||
|
if err := repo.Append(ctx, &AuditEntry{
|
||||||
|
Action: "x", Resource: "y", Result: "success",
|
||||||
|
}); err != nil {
|
||||||
|
t.Fatalf("append[%d]: %v", i, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// limit<=0 should default to 100.
|
||||||
|
entries, err := repo.List(ctx, 0)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("List(0): %v", err)
|
||||||
|
}
|
||||||
|
if len(entries) != 5 {
|
||||||
|
t.Errorf("List(0): got %d, want 5", len(entries))
|
||||||
|
}
|
||||||
|
entries, err = repo.List(ctx, -1)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("List(-1): %v", err)
|
||||||
|
}
|
||||||
|
if len(entries) != 5 {
|
||||||
|
t.Errorf("List(-1): got %d, want 5", len(entries))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -40,6 +40,9 @@ func TestCapacityRepoUpsertGetList(t *testing.T) {
|
|||||||
if got.CPUMillicores != 4000 || got.MemoryMiB != 4096 || got.DiskMiB != 4096 {
|
if got.CPUMillicores != 4000 || got.MemoryMiB != 4096 || got.DiskMiB != 4096 {
|
||||||
t.Errorf("Get: got %+v, want cpu=4000 mem=4096 disk=4096", got)
|
t.Errorf("Get: got %+v, want cpu=4000 mem=4096 disk=4096", got)
|
||||||
}
|
}
|
||||||
|
if got.UpdatedAt.IsZero() {
|
||||||
|
t.Errorf("Upsert did not fill UpdatedAt")
|
||||||
|
}
|
||||||
|
|
||||||
// Update (overwrite).
|
// Update (overwrite).
|
||||||
c2 := &NodeCapacity{NodeID: "self", CPUMillicores: 8000, MemoryMiB: 8192, DiskMiB: 8192}
|
c2 := &NodeCapacity{NodeID: "self", CPUMillicores: 8000, MemoryMiB: 8192, DiskMiB: 8192}
|
||||||
@@ -72,3 +75,66 @@ func TestCapacityRepoUpsertGetList(t *testing.T) {
|
|||||||
t.Error("expected ErrNotFound on Delete of missing row")
|
t.Error("expected ErrNotFound on Delete of missing row")
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestCapacityRepo_UpsertNilAndEmptyNodeID(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
db, err := Open(filepath.Join(dir, "test.db"))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Open: %v", err)
|
||||||
|
}
|
||||||
|
defer db.Close()
|
||||||
|
repo := NewCapacityRepo(db)
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
if err := repo.Upsert(ctx, nil); err == nil {
|
||||||
|
t.Error("Upsert(nil) should error")
|
||||||
|
}
|
||||||
|
if err := repo.Upsert(ctx, &NodeCapacity{NodeID: ""}); err == nil {
|
||||||
|
t.Error("Upsert(empty NodeID) should error")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestCapacityRepo_GetEmptyNodeID(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
db, err := Open(filepath.Join(dir, "test.db"))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Open: %v", err)
|
||||||
|
}
|
||||||
|
defer db.Close()
|
||||||
|
repo := NewCapacityRepo(db)
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
if _, err := repo.Get(ctx, ""); err == nil {
|
||||||
|
t.Error("Get(empty) should error")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestCapacityRepo_DeleteMissing(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
db, err := Open(filepath.Join(dir, "test.db"))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Open: %v", err)
|
||||||
|
}
|
||||||
|
defer db.Close()
|
||||||
|
repo := NewCapacityRepo(db)
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
if err := repo.Delete(ctx, "ghost"); err != ErrNotFound {
|
||||||
|
t.Errorf("Delete(ghost) = %v, want ErrNotFound", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestStore_OpenEmptyPath(t *testing.T) {
|
||||||
|
// Open with "" should fall back to certpaths.DBPath() which honors
|
||||||
|
// ORCA_HOME. Set a temp ORCA_HOME so we don't pollute the real home.
|
||||||
|
home := t.TempDir()
|
||||||
|
t.Setenv("ORCA_HOME", home)
|
||||||
|
db, err := Open("")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Open(\"\"): %v", err)
|
||||||
|
}
|
||||||
|
defer db.Close()
|
||||||
|
if err := db.Ping(); err != nil {
|
||||||
|
t.Errorf("Ping: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ package store
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"database/sql"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
"time"
|
||||||
@@ -19,6 +20,368 @@ func openJobTestDB(t *testing.T) (*JobRepo, func()) {
|
|||||||
return NewJobRepo(db), func() { _ = db.Close() }
|
return NewJobRepo(db), func() { _ = db.Close() }
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// openFullTestDB returns the underlying *sql.DB plus repos for cross-repo
|
||||||
|
// tests (e.g. TaskRepo needs a JobRepo parent row when foreign keys are on).
|
||||||
|
func openFullTestDB(t *testing.T) (*sql.DB, *JobRepo, *TaskRepo, func()) {
|
||||||
|
t.Helper()
|
||||||
|
path := filepath.Join(t.TempDir(), "test.db")
|
||||||
|
db, err := Open(path)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("open db: %v", err)
|
||||||
|
}
|
||||||
|
return db, NewJobRepo(db), NewTaskRepo(db), func() { _ = db.Close() }
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobRepo_Get(t *testing.T) {
|
||||||
|
repo, cleanup := openJobTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
insertJob(t, repo, ctx, "job-get", "alpha")
|
||||||
|
|
||||||
|
got, err := repo.Get(ctx, "job-get")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Get: %v", err)
|
||||||
|
}
|
||||||
|
if got.ID != "job-get" || got.Name != "alpha" {
|
||||||
|
t.Errorf("Get: got %+v", got)
|
||||||
|
}
|
||||||
|
if got.Status != model.JobStatusPending {
|
||||||
|
t.Errorf("Get: status = %q, want pending", got.Status)
|
||||||
|
}
|
||||||
|
if got.Spec != "test" {
|
||||||
|
t.Errorf("Get: spec = %q, want test", got.Spec)
|
||||||
|
}
|
||||||
|
|
||||||
|
if _, err := repo.Get(ctx, "missing"); err != ErrNotFound {
|
||||||
|
t.Errorf("Get(missing): got %v, want ErrNotFound", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobRepo_List(t *testing.T) {
|
||||||
|
repo, cleanup := openJobTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
insertJob(t, repo, ctx, "j1", "first")
|
||||||
|
insertJob(t, repo, ctx, "j2", "second")
|
||||||
|
insertJob(t, repo, ctx, "j3", "third")
|
||||||
|
|
||||||
|
jobs, err := repo.List(ctx)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("List: %v", err)
|
||||||
|
}
|
||||||
|
if len(jobs) != 3 {
|
||||||
|
t.Fatalf("List: got %d jobs, want 3", len(jobs))
|
||||||
|
}
|
||||||
|
// ORDER BY created_at DESC — but timestamps may collide at second
|
||||||
|
// precision. Just verify all 3 IDs are present.
|
||||||
|
ids := map[string]bool{}
|
||||||
|
for _, j := range jobs {
|
||||||
|
ids[j.ID] = true
|
||||||
|
}
|
||||||
|
for _, want := range []string{"j1", "j2", "j3"} {
|
||||||
|
if !ids[want] {
|
||||||
|
t.Errorf("List: missing job %q", want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobRepo_UpdateStatus(t *testing.T) {
|
||||||
|
repo, cleanup := openJobTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
insertJob(t, repo, ctx, "job-status", "alpha")
|
||||||
|
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
status model.JobStatus
|
||||||
|
exitCode int
|
||||||
|
}{
|
||||||
|
{"running", model.JobStatusRunning, 0},
|
||||||
|
{"complete", model.JobStatusComplete, 0},
|
||||||
|
{"failed", model.JobStatusFailed, 1},
|
||||||
|
{"stopped", model.JobStatusStopped, 130},
|
||||||
|
}
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
if err := repo.UpdateStatus(ctx, "job-status", tc.status, tc.exitCode); err != nil {
|
||||||
|
t.Fatalf("UpdateStatus(%s): %v", tc.name, err)
|
||||||
|
}
|
||||||
|
got, err := repo.Get(ctx, "job-status")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Get: %v", err)
|
||||||
|
}
|
||||||
|
if got.Status != tc.status {
|
||||||
|
t.Errorf("status = %q, want %q", got.Status, tc.status)
|
||||||
|
}
|
||||||
|
if got.ExitCode != tc.exitCode {
|
||||||
|
t.Errorf("exit_code = %d, want %d", got.ExitCode, tc.exitCode)
|
||||||
|
}
|
||||||
|
switch tc.status {
|
||||||
|
case model.JobStatusRunning:
|
||||||
|
if got.StartedAt == nil {
|
||||||
|
t.Errorf("started_at should be set for %s", tc.name)
|
||||||
|
}
|
||||||
|
case model.JobStatusComplete, model.JobStatusFailed, model.JobStatusStopped:
|
||||||
|
if got.EndedAt == nil {
|
||||||
|
t.Errorf("ended_at should be set for %s", tc.name)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestJobRepo_InsertDefaults(t *testing.T) {
|
||||||
|
repo, cleanup := openJobTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
// Insert with zero CreatedAt and empty Status — defaults should kick in.
|
||||||
|
j := &model.Job{ID: "defaults-1", Name: "d", Spec: "s"}
|
||||||
|
if err := repo.Insert(ctx, j); err != nil {
|
||||||
|
t.Fatalf("Insert: %v", err)
|
||||||
|
}
|
||||||
|
if j.CreatedAt.IsZero() {
|
||||||
|
t.Errorf("Insert did not fill CreatedAt")
|
||||||
|
}
|
||||||
|
if j.Status != model.JobStatusPending {
|
||||||
|
t.Errorf("Insert default status = %q, want pending", j.Status)
|
||||||
|
}
|
||||||
|
got, _ := repo.Get(ctx, "defaults-1")
|
||||||
|
if got.Status != model.JobStatusPending {
|
||||||
|
t.Errorf("Get: status = %q, want pending", got.Status)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func sampleTask(id, jobID string) *model.Task {
|
||||||
|
return &model.Task{
|
||||||
|
ID: id,
|
||||||
|
JobID: jobID,
|
||||||
|
Command: "/bin/echo",
|
||||||
|
Args: []string{"hello", "world"},
|
||||||
|
Env: []string{"FOO=bar", "BAZ=qux"},
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTaskRepo_InsertAndGet(t *testing.T) {
|
||||||
|
_, jobRepo, taskRepo, cleanup := openFullTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
insertJob(t, jobRepo, ctx, "job-1", "alpha")
|
||||||
|
tk := sampleTask("task-1", "job-1")
|
||||||
|
if err := taskRepo.Insert(ctx, tk); err != nil {
|
||||||
|
t.Fatalf("Insert: %v", err)
|
||||||
|
}
|
||||||
|
if tk.CreatedAt.IsZero() {
|
||||||
|
t.Errorf("Insert did not fill CreatedAt")
|
||||||
|
}
|
||||||
|
if tk.Status != model.TaskStatusPending {
|
||||||
|
t.Errorf("Insert default status = %q, want pending", tk.Status)
|
||||||
|
}
|
||||||
|
|
||||||
|
got, err := taskRepo.Get(ctx, "task-1")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Get: %v", err)
|
||||||
|
}
|
||||||
|
if got.Command != "/bin/echo" {
|
||||||
|
t.Errorf("command = %q", got.Command)
|
||||||
|
}
|
||||||
|
if len(got.Args) != 2 || got.Args[0] != "hello" {
|
||||||
|
t.Errorf("args = %v", got.Args)
|
||||||
|
}
|
||||||
|
if len(got.Env) != 2 || got.Env[0] != "FOO=bar" {
|
||||||
|
t.Errorf("env = %v", got.Env)
|
||||||
|
}
|
||||||
|
if got.Status != model.TaskStatusPending {
|
||||||
|
t.Errorf("status = %q, want pending", got.Status)
|
||||||
|
}
|
||||||
|
|
||||||
|
if _, err := taskRepo.Get(ctx, "missing"); err != ErrNotFound {
|
||||||
|
t.Errorf("Get(missing) = %v, want ErrNotFound", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTaskRepo_ListByJob(t *testing.T) {
|
||||||
|
_, jobRepo, taskRepo, cleanup := openFullTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
insertJob(t, jobRepo, ctx, "job-lbj", "alpha")
|
||||||
|
for _, id := range []string{"t1", "t2", "t3"} {
|
||||||
|
if err := taskRepo.Insert(ctx, sampleTask(id, "job-lbj")); err != nil {
|
||||||
|
t.Fatalf("Insert %s: %v", id, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// Insert a task for a different job to ensure filtering works.
|
||||||
|
insertJob(t, jobRepo, ctx, "job-other", "beta")
|
||||||
|
if err := taskRepo.Insert(ctx, sampleTask("t-other", "job-other")); err != nil {
|
||||||
|
t.Fatalf("Insert t-other: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
tasks, err := taskRepo.ListByJob(ctx, "job-lbj")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ListByJob: %v", err)
|
||||||
|
}
|
||||||
|
if len(tasks) != 3 {
|
||||||
|
t.Fatalf("ListByJob: got %d tasks, want 3", len(tasks))
|
||||||
|
}
|
||||||
|
for _, tk := range tasks {
|
||||||
|
if tk.JobID != "job-lbj" {
|
||||||
|
t.Errorf("ListByJob returned task with job_id=%q", tk.JobID)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTaskRepo_UpdateRunning(t *testing.T) {
|
||||||
|
_, jobRepo, taskRepo, cleanup := openFullTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
insertJob(t, jobRepo, ctx, "job-run", "alpha")
|
||||||
|
if err := taskRepo.Insert(ctx, sampleTask("task-run", "job-run")); err != nil {
|
||||||
|
t.Fatalf("Insert: %v", err)
|
||||||
|
}
|
||||||
|
if err := taskRepo.UpdateRunning(ctx, "task-run", 4242); err != nil {
|
||||||
|
t.Fatalf("UpdateRunning: %v", err)
|
||||||
|
}
|
||||||
|
got, _ := taskRepo.Get(ctx, "task-run")
|
||||||
|
if got.PID != 4242 {
|
||||||
|
t.Errorf("pid = %d, want 4242", got.PID)
|
||||||
|
}
|
||||||
|
if got.Status != model.TaskStatusRunning {
|
||||||
|
t.Errorf("status = %q, want running", got.Status)
|
||||||
|
}
|
||||||
|
if got.StartedAt == nil {
|
||||||
|
t.Errorf("started_at should be set after UpdateRunning")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTaskRepo_UpdateDone(t *testing.T) {
|
||||||
|
_, jobRepo, taskRepo, cleanup := openFullTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
insertJob(t, jobRepo, ctx, "job-done", "alpha")
|
||||||
|
if err := taskRepo.Insert(ctx, sampleTask("task-done", "job-done")); err != nil {
|
||||||
|
t.Fatalf("Insert: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
cases := []struct {
|
||||||
|
name string
|
||||||
|
exitCode int
|
||||||
|
want model.TaskStatus
|
||||||
|
}{
|
||||||
|
{"complete", 0, model.TaskStatusComplete},
|
||||||
|
{"failed", 1, model.TaskStatusFailed},
|
||||||
|
}
|
||||||
|
for _, tc := range cases {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
id := "task-done-" + tc.name
|
||||||
|
if err := taskRepo.Insert(ctx, sampleTask(id, "job-done")); err != nil {
|
||||||
|
t.Fatalf("Insert: %v", err)
|
||||||
|
}
|
||||||
|
if err := taskRepo.UpdateDone(ctx, id, tc.exitCode, "stdout-data", "stderr-data"); err != nil {
|
||||||
|
t.Fatalf("UpdateDone: %v", err)
|
||||||
|
}
|
||||||
|
got, _ := taskRepo.Get(ctx, id)
|
||||||
|
if got.Status != tc.want {
|
||||||
|
t.Errorf("status = %q, want %q", got.Status, tc.want)
|
||||||
|
}
|
||||||
|
if got.ExitCode != tc.exitCode {
|
||||||
|
t.Errorf("exit_code = %d, want %d", got.ExitCode, tc.exitCode)
|
||||||
|
}
|
||||||
|
if got.Stdout != "stdout-data" {
|
||||||
|
t.Errorf("stdout = %q", got.Stdout)
|
||||||
|
}
|
||||||
|
if got.Stderr != "stderr-data" {
|
||||||
|
t.Errorf("stderr = %q", got.Stderr)
|
||||||
|
}
|
||||||
|
if got.EndedAt == nil {
|
||||||
|
t.Errorf("ended_at should be set after UpdateDone")
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTaskRepo_UpdateKilled(t *testing.T) {
|
||||||
|
_, jobRepo, taskRepo, cleanup := openFullTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
insertJob(t, jobRepo, ctx, "job-kill", "alpha")
|
||||||
|
if err := taskRepo.Insert(ctx, sampleTask("task-kill", "job-kill")); err != nil {
|
||||||
|
t.Fatalf("Insert: %v", err)
|
||||||
|
}
|
||||||
|
if err := taskRepo.UpdateKilled(ctx, "task-kill"); err != nil {
|
||||||
|
t.Fatalf("UpdateKilled: %v", err)
|
||||||
|
}
|
||||||
|
got, _ := taskRepo.Get(ctx, "task-kill")
|
||||||
|
if got.Status != model.TaskStatusKilled {
|
||||||
|
t.Errorf("status = %q, want killed", got.Status)
|
||||||
|
}
|
||||||
|
if got.EndedAt == nil {
|
||||||
|
t.Errorf("ended_at should be set after UpdateKilled")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTaskRepo_ListRecent(t *testing.T) {
|
||||||
|
_, jobRepo, taskRepo, cleanup := openFullTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
insertJob(t, jobRepo, ctx, "job-recent", "alpha")
|
||||||
|
for i := 0; i < 5; i++ {
|
||||||
|
id := "task-recent-" + string(rune('a'+i))
|
||||||
|
if err := taskRepo.Insert(ctx, sampleTask(id, "job-recent")); err != nil {
|
||||||
|
t.Fatalf("Insert %s: %v", id, err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// limit=3
|
||||||
|
tasks, err := taskRepo.ListRecent(ctx, 3)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ListRecent(3): %v", err)
|
||||||
|
}
|
||||||
|
if len(tasks) != 3 {
|
||||||
|
t.Errorf("ListRecent(3): got %d, want 3", len(tasks))
|
||||||
|
}
|
||||||
|
|
||||||
|
// limit<=0 → defaults to 100
|
||||||
|
all, err := taskRepo.ListRecent(ctx, 0)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ListRecent(0): %v", err)
|
||||||
|
}
|
||||||
|
if len(all) != 5 {
|
||||||
|
t.Errorf("ListRecent(0): got %d, want 5 (default limit 100)", len(all))
|
||||||
|
}
|
||||||
|
|
||||||
|
// limit negative
|
||||||
|
neg, err := taskRepo.ListRecent(ctx, -1)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ListRecent(-1): %v", err)
|
||||||
|
}
|
||||||
|
if len(neg) != 5 {
|
||||||
|
t.Errorf("ListRecent(-1): got %d, want 5", len(neg))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestTaskRepo_ListByJob_Empty(t *testing.T) {
|
||||||
|
_, _, taskRepo, cleanup := openFullTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
ctx := context.Background()
|
||||||
|
|
||||||
|
tasks, err := taskRepo.ListByJob(ctx, "nope")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ListByJob: %v", err)
|
||||||
|
}
|
||||||
|
if len(tasks) != 0 {
|
||||||
|
t.Errorf("ListByJob(empty): got %d, want 0", len(tasks))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func insertJob(t *testing.T, repo *JobRepo, ctx context.Context, id, name string) {
|
func insertJob(t *testing.T, repo *JobRepo, ctx context.Context, id, name string) {
|
||||||
t.Helper()
|
t.Helper()
|
||||||
if err := repo.Insert(ctx, &model.Job{
|
if err := repo.Insert(ctx, &model.Job{
|
||||||
|
|||||||
@@ -2,4 +2,16 @@
|
|||||||
-- issued by orca may share the same serial. Implemented as a UNIQUE
|
-- issued by orca may share the same serial. Implemented as a UNIQUE
|
||||||
-- INDEX so existing 0004_certs.sql need not be re-run on deployed
|
-- INDEX so existing 0004_certs.sql need not be re-run on deployed
|
||||||
-- databases. v0.7 P01 (REQ-053 companion).
|
-- databases. v0.7 P01 (REQ-053 companion).
|
||||||
|
--
|
||||||
|
-- P1-001 fix (final review): before creating the UNIQUE index, dedup
|
||||||
|
-- any existing rows that share a serial_hex. Keep the newest row
|
||||||
|
-- (MAX(created_at)) per serial_hex and delete older duplicates. This
|
||||||
|
-- makes the migration backward-compatible with v0.6 deployments that
|
||||||
|
-- may have accumulated duplicate serials before the constraint existed.
|
||||||
|
DELETE FROM certs WHERE id NOT IN (
|
||||||
|
SELECT id FROM (
|
||||||
|
SELECT id, ROW_NUMBER() OVER (PARTITION BY serial_hex ORDER BY created_at DESC) AS rn
|
||||||
|
FROM certs
|
||||||
|
) WHERE rn = 1
|
||||||
|
);
|
||||||
CREATE UNIQUE INDEX IF NOT EXISTS idx_certs_serial_unique ON certs(serial_hex);
|
CREATE UNIQUE INDEX IF NOT EXISTS idx_certs_serial_unique ON certs(serial_hex);
|
||||||
@@ -101,6 +101,133 @@ func TestNodeRepo_Delete(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestNodeRepo_DeleteMissing(t *testing.T) {
|
||||||
|
repo, cleanup := openTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
if err := repo.Delete(ctx, "ghost"); err != ErrNotFound {
|
||||||
|
t.Errorf("Delete(ghost) = %v, want ErrNotFound", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRepo_UpdateStateMissing(t *testing.T) {
|
||||||
|
repo, cleanup := openTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
if err := repo.UpdateState(ctx, "ghost", model.NodeStateLeft); err != ErrNotFound {
|
||||||
|
t.Errorf("UpdateState(ghost) = %v, want ErrNotFound", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRepo_UpdateLastSeenAndOSMissing(t *testing.T) {
|
||||||
|
repo, cleanup := openTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
if err := repo.UpdateLastSeenAndOS(ctx, "ghost", "ubuntu"); err != ErrNotFound {
|
||||||
|
t.Errorf("UpdateLastSeenAndOS(ghost) = %v, want ErrNotFound", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRepo_GetMissing(t *testing.T) {
|
||||||
|
repo, cleanup := openTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
if _, err := repo.Get(ctx, "ghost"); err != ErrNotFound {
|
||||||
|
t.Errorf("Get(ghost) = %v, want ErrNotFound", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRepo_InsertDefaults(t *testing.T) {
|
||||||
|
repo, cleanup := openTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
// Insert with zero JoinedAt/LastSeen and empty State — defaults apply.
|
||||||
|
n := &model.Node{ID: "defaults-1", Name: "d", Address: "addr"}
|
||||||
|
if err := repo.Insert(ctx, n); err != nil {
|
||||||
|
t.Fatalf("Insert: %v", err)
|
||||||
|
}
|
||||||
|
if n.JoinedAt.IsZero() {
|
||||||
|
t.Errorf("Insert did not fill JoinedAt")
|
||||||
|
}
|
||||||
|
if n.LastSeen.IsZero() {
|
||||||
|
t.Errorf("Insert did not fill LastSeen")
|
||||||
|
}
|
||||||
|
if n.State != model.NodeStateReady {
|
||||||
|
t.Errorf("Insert default state = %q, want ready", n.State)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRepo_MetadataRoundTrip(t *testing.T) {
|
||||||
|
repo, cleanup := openTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
n := &model.Node{
|
||||||
|
ID: "meta-1",
|
||||||
|
Name: "meta",
|
||||||
|
Address: "addr",
|
||||||
|
JoinedAt: time.Now().UTC(),
|
||||||
|
LastSeen: time.Now().UTC(),
|
||||||
|
Metadata: map[string]string{"arch": "amd64", "kernel": "6.1"},
|
||||||
|
}
|
||||||
|
if err := repo.Insert(ctx, n); err != nil {
|
||||||
|
t.Fatalf("Insert: %v", err)
|
||||||
|
}
|
||||||
|
got, err := repo.Get(ctx, "meta-1")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Get: %v", err)
|
||||||
|
}
|
||||||
|
if got.Metadata["arch"] != "amd64" {
|
||||||
|
t.Errorf("metadata[arch] = %q, want amd64", got.Metadata["arch"])
|
||||||
|
}
|
||||||
|
if got.Metadata["kernel"] != "6.1" {
|
||||||
|
t.Errorf("metadata[kernel] = %q, want 6.1", got.Metadata["kernel"])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRepo_ListEmpty(t *testing.T) {
|
||||||
|
repo, cleanup := openTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
nodes, err := repo.List(ctx)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("List: %v", err)
|
||||||
|
}
|
||||||
|
if len(nodes) != 0 {
|
||||||
|
t.Errorf("List(empty): got %d, want 0", len(nodes))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNodeRepo_GetByNameMultiplePicksOldest(t *testing.T) {
|
||||||
|
repo, cleanup := openTestDB(t)
|
||||||
|
defer cleanup()
|
||||||
|
|
||||||
|
ctx := context.Background()
|
||||||
|
older := time.Now().UTC().Add(-1 * time.Hour)
|
||||||
|
newer := time.Now().UTC()
|
||||||
|
_ = repo.Insert(ctx, &model.Node{
|
||||||
|
ID: "n-old", Name: "dup", Address: "a",
|
||||||
|
JoinedAt: older, LastSeen: older,
|
||||||
|
})
|
||||||
|
_ = repo.Insert(ctx, &model.Node{
|
||||||
|
ID: "n-new", Name: "dup", Address: "a",
|
||||||
|
JoinedAt: newer, LastSeen: newer,
|
||||||
|
})
|
||||||
|
got, err := repo.GetByName(ctx, "dup")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GetByName: %v", err)
|
||||||
|
}
|
||||||
|
if got.ID != "n-old" {
|
||||||
|
t.Errorf("GetByName = %q, want oldest n-old (ORDER BY joined_at ASC)", got.ID)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func TestNodeRepo_KindOS_RoundTrip(t *testing.T) {
|
func TestNodeRepo_KindOS_RoundTrip(t *testing.T) {
|
||||||
repo, cleanup := openTestDB(t)
|
repo, cleanup := openTestDB(t)
|
||||||
defer cleanup()
|
defer cleanup()
|
||||||
|
|||||||
@@ -14,6 +14,7 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"encoding/json"
|
"encoding/json"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"time"
|
"time"
|
||||||
)
|
)
|
||||||
@@ -252,7 +253,7 @@ func bytesReader(b []byte) *bytesReadCloser { return &bytesReadCloser{b: b} }
|
|||||||
|
|
||||||
func (r *bytesReadCloser) Read(p []byte) (int, error) {
|
func (r *bytesReadCloser) Read(p []byte) (int, error) {
|
||||||
if r.pos >= len(r.b) {
|
if r.pos >= len(r.b) {
|
||||||
return 0, fmt.Errorf("EOF")
|
return 0, io.EOF
|
||||||
}
|
}
|
||||||
n := copy(p, r.b[r.pos:])
|
n := copy(p, r.b[r.pos:])
|
||||||
r.pos += n
|
r.pos += n
|
||||||
|
|||||||
@@ -0,0 +1,402 @@
|
|||||||
|
package transport
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"context"
|
||||||
|
"encoding/json"
|
||||||
|
"errors"
|
||||||
|
"io"
|
||||||
|
"net/http"
|
||||||
|
"net/http/httptest"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/security"
|
||||||
|
)
|
||||||
|
|
||||||
|
type mockDispatcher struct {
|
||||||
|
jobID string
|
||||||
|
state string
|
||||||
|
submitErr error
|
||||||
|
statusErr error
|
||||||
|
submits int
|
||||||
|
statuses int
|
||||||
|
lastSpec []byte
|
||||||
|
}
|
||||||
|
|
||||||
|
func (m *mockDispatcher) LocalSubmit(ctx context.Context, spec []byte) (string, error) {
|
||||||
|
m.submits++
|
||||||
|
m.lastSpec = spec
|
||||||
|
if m.submitErr != nil {
|
||||||
|
return "", m.submitErr
|
||||||
|
}
|
||||||
|
if m.jobID == "" {
|
||||||
|
return "job-123", nil
|
||||||
|
}
|
||||||
|
return m.jobID, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func (m *mockDispatcher) LocalStatus(ctx context.Context, jobID string) (string, error) {
|
||||||
|
m.statuses++
|
||||||
|
if m.statusErr != nil {
|
||||||
|
return "", m.statusErr
|
||||||
|
}
|
||||||
|
if m.state == "" {
|
||||||
|
return "running", nil
|
||||||
|
}
|
||||||
|
return m.state, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSubmitHandler_Success(t *testing.T) {
|
||||||
|
d := &mockDispatcher{}
|
||||||
|
h := NewSubmitHandler(d, nil)
|
||||||
|
body := bytes.NewReader([]byte(`{"spec":"{}"}`))
|
||||||
|
req := httptest.NewRequest(http.MethodPost, "/orca.v1.Dispatch/Submit", body)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusOK {
|
||||||
|
t.Errorf("status = %d, want 200", w.Code)
|
||||||
|
}
|
||||||
|
var resp SubmitResponse
|
||||||
|
if err := json.NewDecoder(w.Body).Decode(&resp); err != nil {
|
||||||
|
t.Fatalf("decode: %v", err)
|
||||||
|
}
|
||||||
|
if resp.JobID != "job-123" {
|
||||||
|
t.Errorf("JobID = %q, want job-123", resp.JobID)
|
||||||
|
}
|
||||||
|
if d.submits != 1 {
|
||||||
|
t.Errorf("submits = %d, want 1", d.submits)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSubmitHandler_IdempotencyReplay(t *testing.T) {
|
||||||
|
d := &mockDispatcher{}
|
||||||
|
store := NewIdempotencyStore()
|
||||||
|
store.Put("key-1", "job-existing")
|
||||||
|
h := NewSubmitHandler(d, store)
|
||||||
|
body := bytes.NewReader([]byte(`{"spec":"{}"}`))
|
||||||
|
req := httptest.NewRequest(http.MethodPost, "/orca.v1.Dispatch/Submit", body)
|
||||||
|
req.Header.Set(IdempotencyHeader, "key-1")
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusOK {
|
||||||
|
t.Errorf("status = %d, want 200", w.Code)
|
||||||
|
}
|
||||||
|
var resp SubmitResponse
|
||||||
|
if err := json.NewDecoder(w.Body).Decode(&resp); err != nil {
|
||||||
|
t.Fatalf("decode: %v", err)
|
||||||
|
}
|
||||||
|
if resp.JobID != "job-existing" {
|
||||||
|
t.Errorf("JobID = %q, want job-existing (replay)", resp.JobID)
|
||||||
|
}
|
||||||
|
if d.submits != 0 {
|
||||||
|
t.Errorf("submits = %d, want 0 (replayed from store)", d.submits)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSubmitHandler_IdempotencyStores(t *testing.T) {
|
||||||
|
d := &mockDispatcher{}
|
||||||
|
store := NewIdempotencyStore()
|
||||||
|
h := NewSubmitHandler(d, store)
|
||||||
|
body := bytes.NewReader([]byte(`{"spec":"{}"}`))
|
||||||
|
req := httptest.NewRequest(http.MethodPost, "/orca.v1.Dispatch/Submit", body)
|
||||||
|
req.Header.Set(IdempotencyHeader, "key-2")
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusOK {
|
||||||
|
t.Fatalf("status = %d, want 200", w.Code)
|
||||||
|
}
|
||||||
|
if got, ok := store.Get("key-2"); !ok || got != "job-123" {
|
||||||
|
t.Errorf("store.Get(key-2) = (%q, %v), want (job-123, true)", got, ok)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSubmitHandler_BadMethod(t *testing.T) {
|
||||||
|
h := NewSubmitHandler(&mockDispatcher{}, nil)
|
||||||
|
req := httptest.NewRequest(http.MethodGet, "/orca.v1.Dispatch/Submit", nil)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusMethodNotAllowed {
|
||||||
|
t.Errorf("status = %d, want 405", w.Code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSubmitHandler_BadBody(t *testing.T) {
|
||||||
|
h := NewSubmitHandler(&mockDispatcher{}, nil)
|
||||||
|
body := strings.NewReader("{not json")
|
||||||
|
req := httptest.NewRequest(http.MethodPost, "/orca.v1.Dispatch/Submit", body)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusBadRequest {
|
||||||
|
t.Errorf("status = %d, want 400", w.Code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSubmitHandler_EmptySpec(t *testing.T) {
|
||||||
|
h := NewSubmitHandler(&mockDispatcher{}, nil)
|
||||||
|
body := bytes.NewReader([]byte(`{}`))
|
||||||
|
req := httptest.NewRequest(http.MethodPost, "/orca.v1.Dispatch/Submit", body)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusBadRequest {
|
||||||
|
t.Errorf("status = %d, want 400", w.Code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestSubmitHandler_DispatcherError(t *testing.T) {
|
||||||
|
d := &mockDispatcher{submitErr: errors.New("boom")}
|
||||||
|
h := NewSubmitHandler(d, nil)
|
||||||
|
body := bytes.NewReader([]byte(`{"spec":"{}"}`))
|
||||||
|
req := httptest.NewRequest(http.MethodPost, "/orca.v1.Dispatch/Submit", body)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusInternalServerError {
|
||||||
|
t.Errorf("status = %d, want 500", w.Code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestStatusHandler_Success(t *testing.T) {
|
||||||
|
d := &mockDispatcher{state: "complete"}
|
||||||
|
h := NewStatusHandler(d)
|
||||||
|
body := bytes.NewReader([]byte(`{"job_id":"job-1"}`))
|
||||||
|
req := httptest.NewRequest(http.MethodPost, "/orca.v1.Dispatch/Status", body)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusOK {
|
||||||
|
t.Errorf("status = %d, want 200", w.Code)
|
||||||
|
}
|
||||||
|
var resp StatusResponse
|
||||||
|
if err := json.NewDecoder(w.Body).Decode(&resp); err != nil {
|
||||||
|
t.Fatalf("decode: %v", err)
|
||||||
|
}
|
||||||
|
if resp.State != "complete" {
|
||||||
|
t.Errorf("State = %q, want complete", resp.State)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestStatusHandler_BadMethod(t *testing.T) {
|
||||||
|
h := NewStatusHandler(&mockDispatcher{})
|
||||||
|
req := httptest.NewRequest(http.MethodGet, "/orca.v1.Dispatch/Status", nil)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusMethodNotAllowed {
|
||||||
|
t.Errorf("status = %d, want 405", w.Code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestStatusHandler_BadBody(t *testing.T) {
|
||||||
|
h := NewStatusHandler(&mockDispatcher{})
|
||||||
|
body := strings.NewReader("nope")
|
||||||
|
req := httptest.NewRequest(http.MethodPost, "/orca.v1.Dispatch/Status", body)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusBadRequest {
|
||||||
|
t.Errorf("status = %d, want 400", w.Code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestStatusHandler_EmptyJobID(t *testing.T) {
|
||||||
|
h := NewStatusHandler(&mockDispatcher{})
|
||||||
|
body := bytes.NewReader([]byte(`{"job_id":""}`))
|
||||||
|
req := httptest.NewRequest(http.MethodPost, "/orca.v1.Dispatch/Status", body)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusBadRequest {
|
||||||
|
t.Errorf("status = %d, want 400", w.Code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestStatusHandler_DispatcherError(t *testing.T) {
|
||||||
|
d := &mockDispatcher{statusErr: errors.New("not found")}
|
||||||
|
h := NewStatusHandler(d)
|
||||||
|
body := bytes.NewReader([]byte(`{"job_id":"job-x"}`))
|
||||||
|
req := httptest.NewRequest(http.MethodPost, "/orca.v1.Dispatch/Status", body)
|
||||||
|
w := httptest.NewRecorder()
|
||||||
|
h.ServeHTTP(w, req)
|
||||||
|
if w.Code != http.StatusNotFound {
|
||||||
|
t.Errorf("status = %d, want 404", w.Code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNewDispatchClient(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
ca, err := security.CAInit(dir, "orca-test-ca")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("CAInit: %v", err)
|
||||||
|
}
|
||||||
|
caPath := filepath.Join(dir, security.CACertFile)
|
||||||
|
_ = ca
|
||||||
|
c, err := NewDispatchClient(caPath, "localhost", "https://localhost:8443")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("NewDispatchClient: %v", err)
|
||||||
|
}
|
||||||
|
if c == nil {
|
||||||
|
t.Fatal("client is nil")
|
||||||
|
}
|
||||||
|
if c.PeerAddr != "https://localhost:8443" {
|
||||||
|
t.Errorf("PeerAddr = %q, want https://localhost:8443", c.PeerAddr)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNewDispatchClient_EmptyCAPath(t *testing.T) {
|
||||||
|
_, err := NewDispatchClient("", "localhost", "https://localhost:8443")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for empty caPath")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNewDispatchClient_EmptyServerName(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
_, err := security.CAInit(dir, "orca-test-ca")
|
||||||
|
caPath := filepath.Join(dir, security.CACertFile)
|
||||||
|
_, err = NewDispatchClient(caPath, "", "https://localhost:8443")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for empty serverName")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatchClient_InvalidURL(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
_, err := security.CAInit(dir, "orca-test-ca")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("CAInit: %v", err)
|
||||||
|
}
|
||||||
|
caPath := filepath.Join(dir, security.CACertFile)
|
||||||
|
c, err := NewDispatchClient(caPath, "localhost", "http://127.0.0.1:1")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("NewDispatchClient: %v", err)
|
||||||
|
}
|
||||||
|
_, err = c.Status(context.Background(), "job-1")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for connection refused")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatchClient_Status_HTTPError(t *testing.T) {
|
||||||
|
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
writeError(w, http.StatusInternalServerError, "boom")
|
||||||
|
}))
|
||||||
|
defer srv.Close()
|
||||||
|
|
||||||
|
dc := &DispatchClient{
|
||||||
|
HTTP: &MTLSClient{http: &http.Client{Timeout: 5 * time.Second}},
|
||||||
|
PeerAddr: srv.URL,
|
||||||
|
}
|
||||||
|
_, err := dc.Status(context.Background(), "job-1")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for 500 status")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatchClient_Status_DecodeError(t *testing.T) {
|
||||||
|
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
w.Header().Set("Content-Type", "application/json")
|
||||||
|
w.WriteHeader(http.StatusOK)
|
||||||
|
_, _ = w.Write([]byte("{not valid json"))
|
||||||
|
}))
|
||||||
|
defer srv.Close()
|
||||||
|
|
||||||
|
dc := &DispatchClient{
|
||||||
|
HTTP: &MTLSClient{http: &http.Client{Timeout: 5 * time.Second}},
|
||||||
|
PeerAddr: srv.URL,
|
||||||
|
}
|
||||||
|
_, err := dc.Status(context.Background(), "job-1")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected decode error")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatchClient_Status_Success(t *testing.T) {
|
||||||
|
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if r.Method != http.MethodPost {
|
||||||
|
writeError(w, http.StatusMethodNotAllowed, "method")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
body, _ := io.ReadAll(r.Body)
|
||||||
|
var req StatusRequest
|
||||||
|
_ = json.Unmarshal(body, &req)
|
||||||
|
if req.JobID != "job-9" {
|
||||||
|
writeError(w, http.StatusBadRequest, "bad job_id")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
writeJSON(w, http.StatusOK, StatusResponse{JobID: "job-9", NodeID: "self", State: "complete"})
|
||||||
|
}))
|
||||||
|
defer srv.Close()
|
||||||
|
|
||||||
|
dc := &DispatchClient{
|
||||||
|
HTTP: &MTLSClient{http: &http.Client{Timeout: 5 * time.Second}},
|
||||||
|
PeerAddr: srv.URL,
|
||||||
|
}
|
||||||
|
resp, err := dc.Status(context.Background(), "job-9")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Status: %v", err)
|
||||||
|
}
|
||||||
|
if resp.JobID != "job-9" {
|
||||||
|
t.Errorf("JobID = %q, want job-9", resp.JobID)
|
||||||
|
}
|
||||||
|
if resp.State != "complete" {
|
||||||
|
t.Errorf("State = %q, want complete", resp.State)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatchClient_Submit_Success(t *testing.T) {
|
||||||
|
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if r.Method != http.MethodPost {
|
||||||
|
writeError(w, http.StatusMethodNotAllowed, "method")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
writeJSON(w, http.StatusOK, SubmitResponse{JobID: "job-submit-1", NodeID: "peer-1"})
|
||||||
|
}))
|
||||||
|
defer srv.Close()
|
||||||
|
|
||||||
|
dc := &DispatchClient{
|
||||||
|
HTTP: &MTLSClient{http: &http.Client{Timeout: 5 * time.Second}},
|
||||||
|
PeerAddr: srv.URL,
|
||||||
|
}
|
||||||
|
resp, err := dc.Submit(context.Background(), []byte("spec"), "idem-key-1")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Submit: %v", err)
|
||||||
|
}
|
||||||
|
if resp.JobID != "job-submit-1" {
|
||||||
|
t.Errorf("JobID = %q, want job-submit-1", resp.JobID)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDispatchClient_Submit_NonIdempotentTransientBails(t *testing.T) {
|
||||||
|
calls := 0
|
||||||
|
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
calls++
|
||||||
|
writeError(w, http.StatusServiceUnavailable, "unavailable")
|
||||||
|
}))
|
||||||
|
defer srv.Close()
|
||||||
|
|
||||||
|
dc := &DispatchClient{
|
||||||
|
HTTP: &MTLSClient{http: &http.Client{Timeout: 5 * time.Second}},
|
||||||
|
PeerAddr: srv.URL,
|
||||||
|
}
|
||||||
|
_, err := dc.Submit(context.Background(), []byte("spec"), "")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error")
|
||||||
|
}
|
||||||
|
if calls != 1 {
|
||||||
|
t.Errorf("calls = %d, want 1 (no key, no retry)", calls)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestBytesReader(t *testing.T) {
|
||||||
|
r := bytesReader([]byte("hello"))
|
||||||
|
buf := make([]byte, 5)
|
||||||
|
n, err := r.Read(buf)
|
||||||
|
if n != 5 || err != nil || string(buf) != "hello" {
|
||||||
|
t.Errorf("Read: n=%d err=%v buf=%q", n, err, buf)
|
||||||
|
}
|
||||||
|
n, err = r.Read(buf)
|
||||||
|
if n != 0 || err == nil {
|
||||||
|
t.Errorf("Read past end: n=%d err=%v, want error", n, err)
|
||||||
|
}
|
||||||
|
if err := r.Close(); err != nil {
|
||||||
|
t.Errorf("Close: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,131 @@
|
|||||||
|
package transport
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"crypto/x509"
|
||||||
|
"encoding/pem"
|
||||||
|
"errors"
|
||||||
|
"log/slog"
|
||||||
|
"os"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
func newTestLogger(buf *bytes.Buffer) *slog.Logger {
|
||||||
|
return slog.New(slog.NewTextHandler(buf, nil))
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLogHandshakeOK(t *testing.T) {
|
||||||
|
var buf bytes.Buffer
|
||||||
|
log := newTestLogger(&buf)
|
||||||
|
LogHandshakeOK(log, "peer1", "fp123")
|
||||||
|
out := buf.String()
|
||||||
|
for _, want := range []string{
|
||||||
|
"event=mtls.handshake",
|
||||||
|
"result=ok",
|
||||||
|
"peer=peer1",
|
||||||
|
"cert_fp=fp123",
|
||||||
|
} {
|
||||||
|
if !strings.Contains(out, want) {
|
||||||
|
t.Errorf("output missing %q: %s", want, out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLogHandshakeFailed(t *testing.T) {
|
||||||
|
var buf bytes.Buffer
|
||||||
|
log := newTestLogger(&buf)
|
||||||
|
LogHandshakeFailed(log, "peer1", "", errors.New("tls: bad cert"))
|
||||||
|
out := buf.String()
|
||||||
|
for _, want := range []string{
|
||||||
|
"event=mtls.handshake",
|
||||||
|
"result=failed",
|
||||||
|
"peer=peer1",
|
||||||
|
"err=\"tls: bad cert\"",
|
||||||
|
} {
|
||||||
|
if !strings.Contains(out, want) {
|
||||||
|
t.Errorf("output missing %q: %s", want, out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "level=WARN") {
|
||||||
|
t.Errorf("expected WARN level, got: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLogHandshakeOK_NilLogger(t *testing.T) {
|
||||||
|
defer func() {
|
||||||
|
if r := recover(); r != nil {
|
||||||
|
t.Fatalf("nil logger panicked: %v", r)
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
LogHandshakeOK(nil, "peer1", "fp123")
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLogHandshakeFailed_NilLogger(t *testing.T) {
|
||||||
|
defer func() {
|
||||||
|
if r := recover(); r != nil {
|
||||||
|
t.Fatalf("nil logger panicked: %v", r)
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
LogHandshakeFailed(nil, "peer1", "", errors.New("x"))
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLogHandshakeFailed_NoErr(t *testing.T) {
|
||||||
|
var buf bytes.Buffer
|
||||||
|
log := newTestLogger(&buf)
|
||||||
|
LogHandshakeFailed(log, "peer1", "fp123", nil)
|
||||||
|
out := buf.String()
|
||||||
|
if strings.Contains(out, "err=") {
|
||||||
|
t.Errorf("expected no err= field when err is nil: %s", out)
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "result=failed") {
|
||||||
|
t.Errorf("expected result=failed: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLogHandshakeFromCert_NilCert(t *testing.T) {
|
||||||
|
var buf bytes.Buffer
|
||||||
|
log := newTestLogger(&buf)
|
||||||
|
LogHandshakeFromCert(log, "peer1", nil)
|
||||||
|
out := buf.String()
|
||||||
|
if !strings.Contains(out, "result=ok") {
|
||||||
|
t.Errorf("expected result=ok: %s", out)
|
||||||
|
}
|
||||||
|
if !strings.Contains(out, "peer=peer1") {
|
||||||
|
t.Errorf("expected peer=peer1: %s", out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLogHandshakeFromCert_WithCert(t *testing.T) {
|
||||||
|
var buf bytes.Buffer
|
||||||
|
log := newTestLogger(&buf)
|
||||||
|
dir := t.TempDir()
|
||||||
|
certPath, _, _ := generateTestCerts(t, dir, "localhost")
|
||||||
|
certPEM, err := os.ReadFile(certPath)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("read cert: %v", err)
|
||||||
|
}
|
||||||
|
block, _ := pem.Decode(certPEM)
|
||||||
|
if block == nil {
|
||||||
|
t.Fatal("pem.Decode: no cert block")
|
||||||
|
}
|
||||||
|
leaf, err := x509.ParseCertificate(block.Bytes)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ParseCertificate: %v", err)
|
||||||
|
}
|
||||||
|
LogHandshakeFromCert(log, "peer-cert", leaf)
|
||||||
|
out := buf.String()
|
||||||
|
if !strings.Contains(out, "result=ok") {
|
||||||
|
t.Errorf("expected result=ok: %s", out)
|
||||||
|
}
|
||||||
|
expectedFP := FingerprintOfCert(leaf)
|
||||||
|
if !strings.Contains(out, "cert_fp="+expectedFP) {
|
||||||
|
t.Errorf("expected cert_fp=%s in: %s", expectedFP, out)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestFingerprintOfCert_Nil(t *testing.T) {
|
||||||
|
if got := FingerprintOfCert(nil); got != "" {
|
||||||
|
t.Errorf("FingerprintOfCert(nil) = %q, want empty", got)
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -112,6 +112,43 @@ func TestRetryContextCancel(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestIdempotencyStoreSweep(t *testing.T) {
|
||||||
|
s := NewIdempotencyStore()
|
||||||
|
s.Put("live-1", "job-1")
|
||||||
|
s.entries["expired"] = dedupeEntry{
|
||||||
|
key: "expired",
|
||||||
|
jobID: "old-job",
|
||||||
|
expiresAt: time.Now().Add(-1 * time.Minute),
|
||||||
|
}
|
||||||
|
s.Sweep()
|
||||||
|
if _, ok := s.entries["expired"]; ok {
|
||||||
|
t.Error("Sweep did not remove expired entry")
|
||||||
|
}
|
||||||
|
if _, ok := s.entries["live-1"]; !ok {
|
||||||
|
t.Error("Sweep removed live entry")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestIdempotencyStorePutEmpty(t *testing.T) {
|
||||||
|
s := NewIdempotencyStore()
|
||||||
|
s.Put("", "job-1")
|
||||||
|
s.Put("k1", "")
|
||||||
|
if _, ok := s.Get("k1"); ok {
|
||||||
|
t.Error("Put with empty jobID should not store")
|
||||||
|
}
|
||||||
|
if _, ok := s.Get(""); ok {
|
||||||
|
t.Error("Get with empty key should return false")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestWithIdempotencyKeyEmpty(t *testing.T) {
|
||||||
|
ctx := context.Background()
|
||||||
|
got := WithIdempotencyKey(ctx, "")
|
||||||
|
if got != ctx {
|
||||||
|
t.Error("WithIdempotencyKey with empty key should return ctx unchanged")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func TestIsTransient(t *testing.T) {
|
func TestIsTransient(t *testing.T) {
|
||||||
cases := []struct {
|
cases := []struct {
|
||||||
err error
|
err error
|
||||||
|
|||||||
@@ -6,6 +6,12 @@
|
|||||||
// gRPC, no ConnectRPC, no third-party transport libraries. This keeps
|
// gRPC, no ConnectRPC, no third-party transport libraries. This keeps
|
||||||
// the binary lean (matches the minimalist pillar) and the trust chain
|
// the binary lean (matches the minimalist pillar) and the trust chain
|
||||||
// auditable (one library: the Go stdlib).
|
// auditable (one library: the Go stdlib).
|
||||||
|
//
|
||||||
|
// Deprecated: v0.9 re-architecture replaces this with
|
||||||
|
// internal/sshpush (REQ-073). The daemon-to-daemon mTLS transport is
|
||||||
|
// removed because servers no longer run the orca binary (R-001); the
|
||||||
|
// CLI pushes config via SSH instead. Scheduled for deletion in
|
||||||
|
// v0.10-P14. See .ciagent/PRD_v0.9.md R-001/R-006.
|
||||||
package transport
|
package transport
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
|||||||
@@ -0,0 +1,223 @@
|
|||||||
|
package transport
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto/tls"
|
||||||
|
"crypto/x509"
|
||||||
|
"encoding/pem"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"git.cloudinit.dev/coreci/orca/internal/security"
|
||||||
|
)
|
||||||
|
|
||||||
|
func generateTestCerts(t *testing.T, dir, serverName string) (certPath, keyPath, caPath string) {
|
||||||
|
t.Helper()
|
||||||
|
ca, err := security.CAInit(dir, "orca-test-ca")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("CAInit: %v", err)
|
||||||
|
}
|
||||||
|
keyPEM, csrPEM, err := security.GenerateCSR(serverName, []string{serverName, "127.0.0.1"})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("GenerateCSR: %v", err)
|
||||||
|
}
|
||||||
|
signedPEM, err := ca.SignCSR(csrPEM)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("SignCSR: %v", err)
|
||||||
|
}
|
||||||
|
certPath = filepath.Join(dir, "server.crt")
|
||||||
|
keyPath = filepath.Join(dir, "server.key")
|
||||||
|
caPath = filepath.Join(dir, security.CACertFile)
|
||||||
|
if err := os.WriteFile(certPath, signedPEM, 0o644); err != nil {
|
||||||
|
t.Fatalf("write cert: %v", err)
|
||||||
|
}
|
||||||
|
if err := os.WriteFile(keyPath, keyPEM, 0o600); err != nil {
|
||||||
|
t.Fatalf("write key: %v", err)
|
||||||
|
}
|
||||||
|
return certPath, keyPath, caPath
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestServerTLSConfig(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
certPath, keyPath, caPath := generateTestCerts(t, dir, "localhost")
|
||||||
|
cfg, err := security.ServerTLSConfig(certPath, keyPath, caPath)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ServerTLSConfig: %v", err)
|
||||||
|
}
|
||||||
|
if cfg.MinVersion != tls.VersionTLS13 {
|
||||||
|
t.Errorf("MinVersion = %d, want %d", cfg.MinVersion, tls.VersionTLS13)
|
||||||
|
}
|
||||||
|
if cfg.MaxVersion != tls.VersionTLS13 {
|
||||||
|
t.Errorf("MaxVersion = %d, want %d", cfg.MaxVersion, tls.VersionTLS13)
|
||||||
|
}
|
||||||
|
if cfg.ClientAuth != tls.RequireAndVerifyClientCert {
|
||||||
|
t.Errorf("ClientAuth = %v, want RequireAndVerifyClientCert", cfg.ClientAuth)
|
||||||
|
}
|
||||||
|
if cfg.ClientCAs == nil {
|
||||||
|
t.Error("ClientCAs is nil")
|
||||||
|
}
|
||||||
|
if len(cfg.CipherSuites) == 0 {
|
||||||
|
t.Error("CipherSuites is empty")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestServerTLSConfig_MissingFiles(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
_, err := security.ServerTLSConfig(
|
||||||
|
filepath.Join(dir, "nope.crt"),
|
||||||
|
filepath.Join(dir, "nope.key"),
|
||||||
|
filepath.Join(dir, "nope.ca"),
|
||||||
|
)
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for missing files")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestClientTLSConfig(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
certPath, keyPath, caPath := generateTestCerts(t, dir, "localhost")
|
||||||
|
cfg, err := security.ClientTLSConfig(caPath, "localhost", certPath, keyPath)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ClientTLSConfig: %v", err)
|
||||||
|
}
|
||||||
|
if cfg.MinVersion != tls.VersionTLS13 {
|
||||||
|
t.Errorf("MinVersion = %d, want %d", cfg.MinVersion, tls.VersionTLS13)
|
||||||
|
}
|
||||||
|
if cfg.RootCAs == nil {
|
||||||
|
t.Error("RootCAs is nil")
|
||||||
|
}
|
||||||
|
if cfg.ServerName != "localhost" {
|
||||||
|
t.Errorf("ServerName = %q, want localhost", cfg.ServerName)
|
||||||
|
}
|
||||||
|
if len(cfg.Certificates) != 1 {
|
||||||
|
t.Errorf("Certificates len = %d, want 1", len(cfg.Certificates))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestClientTLSConfig_NoClientCert(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
_, _, caPath := generateTestCerts(t, dir, "localhost")
|
||||||
|
cfg, err := security.ClientTLSConfig(caPath, "localhost", "", "")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ClientTLSConfig: %v", err)
|
||||||
|
}
|
||||||
|
if len(cfg.Certificates) != 0 {
|
||||||
|
t.Errorf("Certificates len = %d, want 0", len(cfg.Certificates))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestClientTLSConfig_MismatchedCertKey(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
_, _, caPath := generateTestCerts(t, dir, "localhost")
|
||||||
|
if _, err := security.ClientTLSConfig(caPath, "localhost", "only-cert", ""); err == nil {
|
||||||
|
t.Error("expected error for cert without key")
|
||||||
|
}
|
||||||
|
if _, err := security.ClientTLSConfig(caPath, "localhost", "", "only-key"); err == nil {
|
||||||
|
t.Error("expected error for key without cert")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNewMTLSClient(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
_, _, caPath := generateTestCerts(t, dir, "localhost")
|
||||||
|
c, err := NewMTLSClient(caPath, "localhost", "", "")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("NewMTLSClient: %v", err)
|
||||||
|
}
|
||||||
|
if c == nil {
|
||||||
|
t.Fatal("client is nil")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNewMTLSClient_EmptyCAPath(t *testing.T) {
|
||||||
|
_, err := NewMTLSClient("", "localhost", "", "")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for empty caPath")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNewMTLSClient_EmptyServerName(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
_, _, caPath := generateTestCerts(t, dir, "localhost")
|
||||||
|
_, err := NewMTLSClient(caPath, "", "", "")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for empty serverName")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestNewMTLSClient_MissingCAFile(t *testing.T) {
|
||||||
|
_, err := NewMTLSClient("/nonexistent/ca.crt", "localhost", "", "")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for missing CA file")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestMTLSClient_Do_NilReceiver(t *testing.T) {
|
||||||
|
var c *MTLSClient
|
||||||
|
_, err := c.Do(nil)
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for nil receiver")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestVerifyPeerCertificate_NoCerts(t *testing.T) {
|
||||||
|
cb := VerifyPeerCertificate("expected")
|
||||||
|
if err := cb(nil, nil); err == nil {
|
||||||
|
t.Error("expected error for no peer certs")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestVerifyPeerCertificate_Mismatch(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
certPath, _, _ := generateTestCerts(t, dir, "localhost")
|
||||||
|
certPEM, err := os.ReadFile(certPath)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("read cert: %v", err)
|
||||||
|
}
|
||||||
|
block, _ := pem.Decode(certPEM)
|
||||||
|
if block == nil {
|
||||||
|
t.Fatal("pem.Decode: no cert block")
|
||||||
|
}
|
||||||
|
cb := VerifyPeerCertificate("wrong-fingerprint")
|
||||||
|
if err := cb([][]byte{block.Bytes}, nil); err == nil {
|
||||||
|
t.Error("expected error for fingerprint mismatch")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestVerifyPeerCertificate_Match(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
certPath, _, _ := generateTestCerts(t, dir, "localhost")
|
||||||
|
certPEM, err := os.ReadFile(certPath)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("read cert: %v", err)
|
||||||
|
}
|
||||||
|
block, _ := pem.Decode(certPEM)
|
||||||
|
if block == nil {
|
||||||
|
t.Fatal("pem.Decode: no cert block")
|
||||||
|
}
|
||||||
|
leaf, err := x509.ParseCertificate(block.Bytes)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("ParseCertificate: %v", err)
|
||||||
|
}
|
||||||
|
expected := security.FingerprintOf(leaf.Raw)
|
||||||
|
cb := VerifyPeerCertificate(expected)
|
||||||
|
if err := cb([][]byte{block.Bytes}, nil); err != nil {
|
||||||
|
t.Errorf("expected match, got: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDialContext_EmptyCAPath(t *testing.T) {
|
||||||
|
_, err := DialContext(t.Context(), "tcp", "127.0.0.1:0", "", "localhost")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for empty caPath")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDialContext_ConnectionRefused(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
_, _, caPath := generateTestCerts(t, dir, "localhost")
|
||||||
|
_, err := DialContext(t.Context(), "tcp", "127.0.0.1:1", caPath, "localhost")
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error for connection refused")
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,203 @@
|
|||||||
|
package transport
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"errors"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestDefaultRetryPolicy(t *testing.T) {
|
||||||
|
p := DefaultRetryPolicy()
|
||||||
|
if p.Initial != RetryInitial {
|
||||||
|
t.Errorf("Initial = %v, want %v", p.Initial, RetryInitial)
|
||||||
|
}
|
||||||
|
if p.Max != RetryMax {
|
||||||
|
t.Errorf("Max = %v, want %v", p.Max, RetryMax)
|
||||||
|
}
|
||||||
|
if p.MaxAttempts != RetryMaxAttempts {
|
||||||
|
t.Errorf("MaxAttempts = %d, want %d", p.MaxAttempts, RetryMaxAttempts)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRetrySucceedsFirstAttempt(t *testing.T) {
|
||||||
|
calls := 0
|
||||||
|
got, err := Do(context.Background(), DefaultRetryPolicy(),
|
||||||
|
func(_ context.Context, attempt int) (string, bool, error) {
|
||||||
|
calls++
|
||||||
|
if attempt != 1 {
|
||||||
|
t.Errorf("attempt = %d, want 1", attempt)
|
||||||
|
}
|
||||||
|
return "ok", true, nil
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Do: %v", err)
|
||||||
|
}
|
||||||
|
if got != "ok" {
|
||||||
|
t.Errorf("got = %q, want ok", got)
|
||||||
|
}
|
||||||
|
if calls != 1 {
|
||||||
|
t.Errorf("calls = %d, want 1", calls)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRetryIdempotentVerbRetries(t *testing.T) {
|
||||||
|
calls := 0
|
||||||
|
_, err := Do(context.Background(), DefaultRetryPolicy(),
|
||||||
|
func(_ context.Context, _ int) (string, bool, error) {
|
||||||
|
calls++
|
||||||
|
return "", true, errors.New("connection refused")
|
||||||
|
})
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error after exhausting attempts")
|
||||||
|
}
|
||||||
|
if calls != RetryMaxAttempts {
|
||||||
|
t.Errorf("calls = %d, want %d", calls, RetryMaxAttempts)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRetryWithIdempotencyKeyRetries(t *testing.T) {
|
||||||
|
calls := 0
|
||||||
|
ctx := WithIdempotencyKey(context.Background(), "key-1")
|
||||||
|
_, err := Do(ctx, DefaultRetryPolicy(),
|
||||||
|
func(_ context.Context, _ int) (string, bool, error) {
|
||||||
|
calls++
|
||||||
|
return "", false, errors.New("i/o timeout")
|
||||||
|
})
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error after exhausting attempts")
|
||||||
|
}
|
||||||
|
if calls != RetryMaxAttempts {
|
||||||
|
t.Errorf("calls = %d, want %d (idempotency key enables retry)", calls, RetryMaxAttempts)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRetryMaxAttemptsReached(t *testing.T) {
|
||||||
|
p := RetryPolicy{Initial: time.Millisecond, Max: 5 * time.Millisecond, MaxAttempts: 3}
|
||||||
|
calls := 0
|
||||||
|
_, err := Do(context.Background(), p,
|
||||||
|
func(_ context.Context, _ int) (string, bool, error) {
|
||||||
|
calls++
|
||||||
|
return "", true, errors.New("EOF")
|
||||||
|
})
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error")
|
||||||
|
}
|
||||||
|
if !IsTransient(err) {
|
||||||
|
t.Errorf("expected transient error, got %v", err)
|
||||||
|
}
|
||||||
|
if calls != 3 {
|
||||||
|
t.Errorf("calls = %d, want 3", calls)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRetryZeroMaxAttemptsDefaults(t *testing.T) {
|
||||||
|
calls := 0
|
||||||
|
p := RetryPolicy{}
|
||||||
|
_, err := Do(context.Background(), p,
|
||||||
|
func(_ context.Context, _ int) (string, bool, error) {
|
||||||
|
calls++
|
||||||
|
return "ok", true, nil
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("Do: %v", err)
|
||||||
|
}
|
||||||
|
if calls != 1 {
|
||||||
|
t.Errorf("calls = %d, want 1", calls)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRetryNonTransientIdempotentRetries(t *testing.T) {
|
||||||
|
calls := 0
|
||||||
|
_, err := Do(context.Background(), DefaultRetryPolicy(),
|
||||||
|
func(_ context.Context, _ int) (string, bool, error) {
|
||||||
|
calls++
|
||||||
|
return "", true, errors.New("invalid spec")
|
||||||
|
})
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error")
|
||||||
|
}
|
||||||
|
if calls != RetryMaxAttempts {
|
||||||
|
t.Errorf("calls = %d, want %d (non-transient idempotent still retries)", calls, RetryMaxAttempts)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRetryTransientNonIdempotentNoKeyBails(t *testing.T) {
|
||||||
|
calls := 0
|
||||||
|
_, err := Do(context.Background(), DefaultRetryPolicy(),
|
||||||
|
func(_ context.Context, _ int) (string, bool, error) {
|
||||||
|
calls++
|
||||||
|
return "", false, errors.New("connection refused")
|
||||||
|
})
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error")
|
||||||
|
}
|
||||||
|
if calls != 1 {
|
||||||
|
t.Errorf("calls = %d, want 1 (transient+non-idempotent+no key = bail)", calls)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestRetryContextCancelledMidBackoff(t *testing.T) {
|
||||||
|
ctx, cancel := context.WithCancel(context.Background())
|
||||||
|
p := RetryPolicy{Initial: 100 * time.Millisecond, Max: time.Second, MaxAttempts: 5}
|
||||||
|
calls := 0
|
||||||
|
go func() {
|
||||||
|
time.Sleep(20 * time.Millisecond)
|
||||||
|
cancel()
|
||||||
|
}()
|
||||||
|
_, err := Do(ctx, p,
|
||||||
|
func(_ context.Context, _ int) (string, bool, error) {
|
||||||
|
calls++
|
||||||
|
return "", true, errors.New("connection refused")
|
||||||
|
})
|
||||||
|
if err == nil {
|
||||||
|
t.Fatal("expected error")
|
||||||
|
}
|
||||||
|
if !errors.Is(err, context.Canceled) {
|
||||||
|
t.Errorf("expected context.Canceled, got %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestBackoffGrowsExponentially(t *testing.T) {
|
||||||
|
initial := 10 * time.Millisecond
|
||||||
|
max := 1 * time.Second
|
||||||
|
d1 := backoff(initial, max, 1)
|
||||||
|
d2 := backoff(initial, max, 2)
|
||||||
|
d3 := backoff(initial, max, 3)
|
||||||
|
if d1 < 0 {
|
||||||
|
t.Errorf("backoff(1) = %v, want >= 0", d1)
|
||||||
|
}
|
||||||
|
if d2 < d1 {
|
||||||
|
t.Errorf("backoff(2)=%v < backoff(1)=%v (should grow)", d2, d1)
|
||||||
|
}
|
||||||
|
if d3 < d2 {
|
||||||
|
t.Errorf("backoff(3)=%v < backoff(2)=%v (should grow)", d3, d2)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestBackoffCapsAtMax(t *testing.T) {
|
||||||
|
initial := 100 * time.Millisecond
|
||||||
|
max := 200 * time.Millisecond
|
||||||
|
d := backoff(initial, max, 10)
|
||||||
|
if d > max+max/2 {
|
||||||
|
t.Errorf("backoff(10) = %v, want <= ~max=%v", d, max)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestContains(t *testing.T) {
|
||||||
|
cases := []struct {
|
||||||
|
s, sub string
|
||||||
|
want bool
|
||||||
|
}{
|
||||||
|
{"hello world", "world", true},
|
||||||
|
{"hello", "xyz", false},
|
||||||
|
{"hello", "", true},
|
||||||
|
{"", "", true},
|
||||||
|
{"abc", "abcd", false},
|
||||||
|
}
|
||||||
|
for _, c := range cases {
|
||||||
|
if got := contains(c.s, c.sub); got != c.want {
|
||||||
|
t.Errorf("contains(%q, %q) = %v, want %v", c.s, c.sub, got, c.want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,32 @@
|
|||||||
|
# orca-log.sh — structured slog-compatible JSON logging for bash scripts (C-17).
|
||||||
|
# Source this library from any orca bash script: `source scripts/lib/orca-log.sh`.
|
||||||
|
# Emits JSON to syslog via `logger`; falls back to stderr if `logger` is missing.
|
||||||
|
# Field set matches the Go audit log (REQ-006): ts, level, actor, action, resource, result, error.
|
||||||
|
|
||||||
|
ORCA_LOG_ACTOR="${ORCA_LOG_ACTOR:-spiffe://orca/cli/operator}"
|
||||||
|
|
||||||
|
# _orca_log_emit <level> <action> <resource> <result> [error]
|
||||||
|
_orca_log_emit() {
|
||||||
|
local level="$1" action="$2" resource="$3" result="$4" error="${5:-}"
|
||||||
|
local ts
|
||||||
|
ts="$(date -u +%Y-%m-%dT%H:%M:%S.%3NZ)"
|
||||||
|
# Build JSON with proper escaping of error field (escape backslash and quote).
|
||||||
|
local err_json=""
|
||||||
|
if [ -n "$error" ]; then
|
||||||
|
local esc_error
|
||||||
|
esc_error="${error//\\/\\\\}"
|
||||||
|
esc_error="${esc_error//\"/\\\"}"
|
||||||
|
err_json=",\"error\":\"$esc_error\""
|
||||||
|
fi
|
||||||
|
local line
|
||||||
|
line="{\"ts\":\"$ts\",\"level\":\"$level\",\"actor\":\"$ORCA_LOG_ACTOR\",\"action\":\"$action\",\"resource\":\"$resource\",\"result\":\"$result\"$err_json}"
|
||||||
|
if command -v logger >/dev/null 2>&1; then
|
||||||
|
logger -t orca "$line"
|
||||||
|
else
|
||||||
|
echo "$line" >&2
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
orca_log_info() { _orca_log_emit "info" "$1" "$2" "$3" "${4:-}"; }
|
||||||
|
orca_log_warn() { _orca_log_emit "warn" "$1" "$2" "$3" "${4:-}"; }
|
||||||
|
orca_log_error() { _orca_log_emit "error" "$1" "$2" "$3" "${4:-}"; }
|
||||||
Executable
+76
@@ -0,0 +1,76 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# orca-verify-render.sh — bash-side render-contract validator (grill C-16).
|
||||||
|
# Reads a render-bundle JSON file (one Artifact per line, or a JSON array)
|
||||||
|
# and validates each entry against the orca.emit/v1 schema.
|
||||||
|
# Exit 0 if all valid; non-zero with a structured error per failure to stderr.
|
||||||
|
# Source: scripts/lib/orca-log.sh for structured error logging (C-17).
|
||||||
|
#
|
||||||
|
# Usage: orca-verify-render.sh <bundle.json>
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
|
# shellcheck source=lib/orca-log.sh
|
||||||
|
. "$SCRIPT_DIR/lib/orca-log.sh"
|
||||||
|
|
||||||
|
EXPECTED_SCHEMA="orca.emit/v1"
|
||||||
|
|
||||||
|
if [ "$#" -lt 1 ]; then
|
||||||
|
orca_log_error "verify-render" "-" "failed" "missing bundle argument"
|
||||||
|
echo "usage: $0 <bundle.json>" >&2
|
||||||
|
exit 2
|
||||||
|
fi
|
||||||
|
|
||||||
|
bundle="$1"
|
||||||
|
if [ ! -f "$bundle" ]; then
|
||||||
|
orca_log_error "verify-render" "$bundle" "failed" "bundle file not found"
|
||||||
|
echo "error: bundle not found: $bundle" >&2
|
||||||
|
exit 2
|
||||||
|
fi
|
||||||
|
|
||||||
|
errors=0
|
||||||
|
total=0
|
||||||
|
|
||||||
|
# Read the bundle line-by-line. Each line should be a JSON object.
|
||||||
|
# (The Go emitter writes one Artifact per line for line-delimited parsing.)
|
||||||
|
while IFS= read -r line; do
|
||||||
|
# Skip blank lines and comments.
|
||||||
|
[ -z "$line" ] && continue
|
||||||
|
case "$line" in \#*) continue ;; esac
|
||||||
|
total=$((total + 1))
|
||||||
|
# Validate schema_version field presence and value (crude JSON grep; no jq dep).
|
||||||
|
# Check schema_version via a simple substring test.
|
||||||
|
schema_match=0
|
||||||
|
if printf '%s' "$line" | grep -q "\"schema_version\":\"$EXPECTED_SCHEMA\""; then
|
||||||
|
schema_match=1
|
||||||
|
fi
|
||||||
|
if [ "$schema_match" -eq 1 ]; then
|
||||||
|
# schema_version matches. Check kind, path, mode presence.
|
||||||
|
for field in kind path mode; do
|
||||||
|
if ! printf '%s' "$line" | grep -q "\"$field\":"; then
|
||||||
|
orca_log_error "verify-render" "$bundle" "failed" "missing field: $field"
|
||||||
|
echo "error: line $total missing field: $field" >&2
|
||||||
|
errors=$((errors + 1))
|
||||||
|
continue 2
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
elif printf '%s' "$line" | grep -q '"schema_version":'; then
|
||||||
|
orca_log_error "verify-render" "$bundle" "failed" "schema_version mismatch on line $total"
|
||||||
|
echo "error: line $total schema_version mismatch (expected $EXPECTED_SCHEMA)" >&2
|
||||||
|
errors=$((errors + 1))
|
||||||
|
else
|
||||||
|
orca_log_error "verify-render" "$bundle" "failed" "missing schema_version on line $total"
|
||||||
|
echo "error: line $total missing schema_version" >&2
|
||||||
|
errors=$((errors + 1))
|
||||||
|
fi
|
||||||
|
done < "$bundle"
|
||||||
|
|
||||||
|
if [ "$errors" -gt 0 ]; then
|
||||||
|
orca_log_error "verify-render" "$bundle" "failed" "$errors of $total artifacts invalid"
|
||||||
|
echo "verify-render: $errors of $total artifacts invalid" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
orca_log_info "verify-render" "$bundle" "ok" ""
|
||||||
|
echo "verify-render: $total artifacts valid"
|
||||||
|
exit 0
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
# Bash Testing Policy (grill C-15)
|
||||||
|
|
||||||
|
Every bash script under `scripts/` MUST have at least one bats test covering
|
||||||
|
the happy path and one covering the failure path. This is the compensating
|
||||||
|
control for bash being exempt from the Go coverage gate (D-186).
|
||||||
|
|
||||||
|
## Framework
|
||||||
|
|
||||||
|
- **bats** — `bats scripts/tests/*.bash` runs all bash tests.
|
||||||
|
- **shellcheck** — `shellcheck scripts/*.sh scripts/lib/*.sh scripts/tests/*.bash` static analysis.
|
||||||
|
- **shfmt** — `shfmt -d scripts/` formatting check (optional; skip if not installed).
|
||||||
|
|
||||||
|
## Install (if missing)
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# bats
|
||||||
|
npm install -g bats # or: git clone https://github.com/bats-core/bats-core.git && ./bats-core/install.sh /usr/local
|
||||||
|
# shellcheck
|
||||||
|
apt-get install -y shellcheck
|
||||||
|
# shfmt (optional)
|
||||||
|
mvdan.cc/sh (go install mvdan.cc/sh/v3/cmd/shfmt@latest)
|
||||||
|
```
|
||||||
|
|
||||||
|
## Running
|
||||||
|
|
||||||
|
```bash
|
||||||
|
make test-bash # runs bats (skips gracefully if bats missing)
|
||||||
|
make lint-bash # runs shellcheck + shfmt (skips gracefully if missing)
|
||||||
|
make test # runs both Go + bash tests
|
||||||
|
make lint # runs both Go + bash lint
|
||||||
|
```
|
||||||
|
|
||||||
|
## Test file convention
|
||||||
|
|
||||||
|
- Test files live in `scripts/tests/<script-name>_test.bash`.
|
||||||
|
- Source `load test_helper` at the top of every test file.
|
||||||
|
- Happy path: `@test "<script> happy path" { ... }`
|
||||||
|
- Failure path: `@test "<script> failure path" { ... }`
|
||||||
|
- Use `run <command>` + `assert_status`/`assert_contains`/`assert_not_contains` from test_helper.
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
#!/usr/bin/env bats
|
||||||
|
# Example bats test proving the framework works (C-15 smoke test).
|
||||||
|
# Real script tests live alongside each script under scripts/tests/.
|
||||||
|
|
||||||
|
load test_helper
|
||||||
|
|
||||||
|
@test "test_helper assert_status accepts matching status" {
|
||||||
|
assert_status 0 0
|
||||||
|
assert_status 1 1
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "test_helper assert_status rejects mismatch" {
|
||||||
|
run assert_status 0 1
|
||||||
|
[ "$status" -ne 0 ]
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "test_helper assert_contains finds substrings" {
|
||||||
|
assert_contains "hello world" "world"
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "test_helper assert_contains rejects missing substrings" {
|
||||||
|
run assert_contains "hello world" "missing"
|
||||||
|
[ "$status" -ne 0 ]
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "test_helper assert_not_contains passes when substring absent" {
|
||||||
|
assert_not_contains "hello world" "missing"
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "test_helper assert_not_contains fails when substring present" {
|
||||||
|
run assert_not_contains "hello world" "world"
|
||||||
|
[ "$status" -ne 0 ]
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "test_helper assert_json_field detects JSON fields" {
|
||||||
|
assert_json_field '{"ts":"2026-01-01T00:00:00Z","level":"info"}' "ts"
|
||||||
|
assert_json_field '{"ts":"2026-01-01T00:00:00Z","level":"info"}' "level"
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "test_helper SCRIPTS_DIR resolves to scripts/ directory" {
|
||||||
|
[ -d "$SCRIPTS_DIR" ]
|
||||||
|
[ -f "$SCRIPTS_DIR/install.sh" ]
|
||||||
|
}
|
||||||
@@ -0,0 +1,69 @@
|
|||||||
|
#!/usr/bin/env bats
|
||||||
|
# Tests for scripts/lib/orca-log.sh (C-17 — slog-compatible JSON to syslog).
|
||||||
|
# Verifies the JSON structure is valid, field set is present, level maps correctly,
|
||||||
|
# and the logger-fallback-to-stderr path works in test environments (no logger).
|
||||||
|
|
||||||
|
load test_helper
|
||||||
|
|
||||||
|
@test "orca_log_info emits valid JSON with all required fields" {
|
||||||
|
export ORCA_LOG_ACTOR="test-actor"
|
||||||
|
output="$(_orca_log_for_test info test-action test-resource ok "")"
|
||||||
|
assert_json_field "$output" "ts"
|
||||||
|
assert_json_field "$output" "level"
|
||||||
|
assert_json_field "$output" "actor"
|
||||||
|
assert_json_field "$output" "action"
|
||||||
|
assert_json_field "$output" "resource"
|
||||||
|
assert_json_field "$output" "result"
|
||||||
|
assert_contains "$output" '"level":"info"'
|
||||||
|
assert_contains "$output" '"action":"test-action"'
|
||||||
|
assert_contains "$output" '"resource":"test-resource"'
|
||||||
|
assert_contains "$output" '"result":"ok"'
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "orca_log_warn maps level correctly" {
|
||||||
|
output="$(_orca_log_for_test warn w-action w-resource warn-result)"
|
||||||
|
assert_contains "$output" '"level":"warn"'
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "orca_log_error maps level and includes error field when provided" {
|
||||||
|
output="$(_orca_log_for_test error err-action err-resource failed "something broke")"
|
||||||
|
assert_contains "$output" '"level":"error"'
|
||||||
|
assert_contains "$output" '"result":"failed"'
|
||||||
|
assert_contains "$output" '"error":"something broke"'
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "orca_log_error omits error field when not provided" {
|
||||||
|
output="$(_orca_log_for_test error err-action err-resource failed)"
|
||||||
|
assert_contains "$output" '"level":"error"'
|
||||||
|
assert_not_contains "$output" '"error":'
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "orca_log escapes quotes and backslashes in error field" {
|
||||||
|
output="$(_orca_log_for_test error a r failed 'has "quote" and \backslash')"
|
||||||
|
assert_contains "$output" '\"quote\"'
|
||||||
|
assert_contains "$output" '\\backslash'
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "ORCA_LOG_ACTOR env var overrides the actor field" {
|
||||||
|
export ORCA_LOG_ACTOR="custom-actor-123"
|
||||||
|
output="$(_orca_log_for_test info a r ok)"
|
||||||
|
assert_contains "$output" '"actor":"custom-actor-123"'
|
||||||
|
}
|
||||||
|
|
||||||
|
# Test helper: source orca-log.sh and emit to stderr (force fallback by hiding logger).
|
||||||
|
_orca_log_for_test() {
|
||||||
|
local level="$1" action="$2" resource="$3" result="$4" error="${5:-}"
|
||||||
|
# Source the library in a subshell with logger hidden so it falls back to stderr.
|
||||||
|
(
|
||||||
|
PATH="/usr/bin:/bin" # hide logger if it's in /usr/local/bin etc.
|
||||||
|
# shellcheck disable=SC2317 # logger is overridden below for test capture
|
||||||
|
logger() { echo "$3"; } # $3 is the message arg (logger -t orca "$line")
|
||||||
|
# shellcheck disable=SC1091 # path is set at runtime by SCRIPTS_DIR
|
||||||
|
source "$SCRIPTS_DIR/lib/orca-log.sh"
|
||||||
|
case "$level" in
|
||||||
|
info) orca_log_info "$action" "$resource" "$result" "$error" ;;
|
||||||
|
warn) orca_log_warn "$action" "$resource" "$result" "$error" ;;
|
||||||
|
error) orca_log_error "$action" "$resource" "$result" "$error" ;;
|
||||||
|
esac
|
||||||
|
)
|
||||||
|
}
|
||||||
@@ -0,0 +1,69 @@
|
|||||||
|
#!/usr/bin/env bats
|
||||||
|
# Tests for scripts/orca-verify-render.sh (C-16 render-format contract validator).
|
||||||
|
# Covers happy path (valid input returns 0) and failure paths (schema mismatch,
|
||||||
|
# missing fields, missing file, missing argument).
|
||||||
|
|
||||||
|
load test_helper
|
||||||
|
|
||||||
|
VERIFY_RENDER="$SCRIPTS_DIR/orca-verify-render.sh"
|
||||||
|
TMP_BUNDLE=""
|
||||||
|
|
||||||
|
setup() {
|
||||||
|
TMP_BUNDLE="$(mktemp)"
|
||||||
|
}
|
||||||
|
|
||||||
|
teardown() {
|
||||||
|
[ -n "$TMP_BUNDLE" ] && rm -f "$TMP_BUNDLE"
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "verify-render happy path: valid artifacts return 0" {
|
||||||
|
cat >"$TMP_BUNDLE" <<'EOF'
|
||||||
|
{"schema_version":"orca.emit/v1","kind":"systemd","path":"/etc/systemd/system/x.service","content":"[Service]","mode":"0644"}
|
||||||
|
{"schema_version":"orca.emit/v1","kind":"traefik","path":"/etc/traefik/dynamic/orca.yml","content":"tls:{}","mode":"0644"}
|
||||||
|
EOF
|
||||||
|
run "$VERIFY_RENDER" "$TMP_BUNDLE"
|
||||||
|
assert_status 0 "$status"
|
||||||
|
assert_contains "$output" "2 artifacts valid"
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "verify-render failure: schema_version mismatch returns non-zero" {
|
||||||
|
cat >"$TMP_BUNDLE" <<'EOF'
|
||||||
|
{"schema_version":"orca.emit/v2","kind":"systemd","path":"/x","mode":"0644"}
|
||||||
|
EOF
|
||||||
|
run "$VERIFY_RENDER" "$TMP_BUNDLE"
|
||||||
|
[ "$status" -ne 0 ]
|
||||||
|
assert_contains "$output" "schema_version mismatch"
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "verify-render failure: missing schema_version returns non-zero" {
|
||||||
|
cat >"$TMP_BUNDLE" <<'EOF'
|
||||||
|
{"kind":"systemd","path":"/x","mode":"0644"}
|
||||||
|
EOF
|
||||||
|
run "$VERIFY_RENDER" "$TMP_BUNDLE"
|
||||||
|
[ "$status" -ne 0 ]
|
||||||
|
assert_contains "$output" "missing schema_version"
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "verify-render failure: missing bundle argument returns 2" {
|
||||||
|
run "$VERIFY_RENDER"
|
||||||
|
assert_status 2 "$status"
|
||||||
|
assert_contains "$output" "usage:"
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "verify-render failure: non-existent bundle returns 2" {
|
||||||
|
run "$VERIFY_RENDER" "/nonexistent/bundle.json"
|
||||||
|
assert_status 2 "$status"
|
||||||
|
assert_contains "$output" "bundle not found"
|
||||||
|
}
|
||||||
|
|
||||||
|
@test "verify-render skips blank lines and comments" {
|
||||||
|
cat >"$TMP_BUNDLE" <<'EOF'
|
||||||
|
# this is a comment
|
||||||
|
|
||||||
|
{"schema_version":"orca.emit/v1","kind":"systemd","path":"/x","content":"c","mode":"0644"}
|
||||||
|
|
||||||
|
EOF
|
||||||
|
run "$VERIFY_RENDER" "$TMP_BUNDLE"
|
||||||
|
assert_status 0 "$status"
|
||||||
|
assert_contains "$output" "1 artifacts valid"
|
||||||
|
}
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# Common helpers for orca bats tests (C-15). Sourced by every test file.
|
||||||
|
# See scripts/tests/README.md for the bash testing policy.
|
||||||
|
|
||||||
|
# Resolve the scripts/ dir relative to this test file.
|
||||||
|
# BASH_SOURCE[0] is this helper file (scripts/tests/test_helper.bash).
|
||||||
|
SCRIPTS_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||||
|
export SCRIPTS_DIR
|
||||||
|
|
||||||
|
# assert_status <expected> <actual> — assert a command's exit status.
|
||||||
|
assert_status() {
|
||||||
|
local expected="$1" actual="$2"
|
||||||
|
[ "$expected" = "$actual" ] || {
|
||||||
|
echo "expected status $expected, got $actual" >&2
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
# assert_contains <haystack> <needle> — substring assertion.
|
||||||
|
assert_contains() {
|
||||||
|
local haystack="$1" needle="$2"
|
||||||
|
case "$haystack" in
|
||||||
|
*"$needle"*) return 0 ;;
|
||||||
|
*) echo "expected [$haystack] to contain [$needle]" >&2; return 1 ;;
|
||||||
|
esac
|
||||||
|
}
|
||||||
|
|
||||||
|
# assert_not_contains <haystack> <needle> — negative substring assertion.
|
||||||
|
assert_not_contains() {
|
||||||
|
local haystack="$1" needle="$2"
|
||||||
|
case "$haystack" in
|
||||||
|
*"$needle"*) echo "expected [$haystack] to NOT contain [$needle]" >&2; return 1 ;;
|
||||||
|
esac
|
||||||
|
:
|
||||||
|
}
|
||||||
|
|
||||||
|
# assert_json_field <json> <field> — crude JSON field presence check (no jq dep).
|
||||||
|
# Matches "<field>": present anywhere in the JSON string.
|
||||||
|
assert_json_field() {
|
||||||
|
local json="$1" field="$2"
|
||||||
|
assert_contains "$json" "\"$field\""
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user