use super::super::super::ANCHORS;
use super::super::{Act, Plan, hosts, perform};
use crate::wire::material::{ADDRESS, Role};
use tempfile::TempDir;
#[test]
fn it_mints_then_refuses_then_rotates() {
let tmp = TempDir::new().expect("tmp");
let dir = tmp.path().join("wire");
let mut plan = Plan {
dir: dir.clone(),
act: Act::Mint {
hosts: Vec::new(),
port: Some("0".to_owned()),
force: false,
},
};
assert_eq!(perform(&plan), 0, "minted");
let first = std::fs::read(dir.join(ANCHORS)).expect("ca");
assert_eq!(perform(&plan), 1, "refused: material is already here");
assert_eq!(
std::fs::read(dir.join(ANCHORS)).expect("ca"),
first,
"and refused without touching it"
);
plan.act = Act::Mint {
hosts: Vec::new(),
port: Some("0".to_owned()),
force: true,
};
assert_eq!(perform(&plan), 0, "rotated");
assert_ne!(std::fs::read(dir.join(ANCHORS)).expect("ca"), first);
}
#[test]
fn a_mint_that_cannot_run_exits_one() {
let tmp = TempDir::new().expect("tmp");
let blocked = tmp.path().join("file");
std::fs::write(&blocked, b"not a directory").expect("file");
assert_eq!(
perform(&Plan {
dir: blocked,
act: Act::Mint {
hosts: Vec::new(),
port: Some("0".to_owned()),
force: false,
},
}),
1
);
}
#[test]
fn a_stated_host_is_a_list_of_them() {
assert_eq!(hosts(None), Vec::<String>::new());
assert_eq!(hosts(Some("")), Vec::<String>::new());
assert_eq!(hosts(Some(", ,")), Vec::<String>::new());
assert_eq!(hosts(Some("engine.example.com")), ["engine.example.com"]);
assert_eq!(
hosts(Some(" engine.example.com , 192.0.2.7 ,")),
["engine.example.com", "192.0.2.7"]
);
}
#[test]
fn a_stated_host_over_standing_material_re_issues_the_server_leaf() {
let tmp = TempDir::new().expect("tmp");
let dir = tmp.path().join("wire");
let stated = |hosts: &[&str]| Plan {
dir: dir.clone(),
act: Act::Mint {
hosts: hosts.iter().map(|h| (*h).to_owned()).collect(),
port: Some("7737".to_owned()),
force: false,
},
};
assert_eq!(perform(&stated(&[])), 0, "minted");
let ca = std::fs::read(dir.join(ANCHORS)).expect("ca");
let address = std::fs::read(dir.join(ADDRESS)).expect("address");
let client = std::fs::read(dir.join("client.pem")).expect("client leaf");
let server = std::fs::read(dir.join("server.pem")).expect("server leaf");
assert_eq!(
perform(&stated(&["engine.example.com", "192.0.2.7"])),
0,
"re-issued rather than refused"
);
assert_ne!(
std::fs::read(dir.join("server.pem")).expect("server leaf"),
server,
"the one artifact the act replaces"
);
assert_eq!(std::fs::read(dir.join(ANCHORS)).expect("ca"), ca);
assert_eq!(
std::fs::read(dir.join("client.pem")).expect("client leaf"),
client
);
assert_ne!(
std::fs::read(dir.join(ADDRESS)).expect("address"),
address,
"the endpoint is stated, not left behind"
);
assert_eq!(
std::fs::read_to_string(dir.join(ADDRESS)).expect("address"),
"engine.example.com:7737\n",
"the first host stated, on the port stated"
);
assert!(Role::Server.leaf() == "server");
}
#[test]
fn a_stated_endpoint_replaces_a_self_provisioned_request() {
let tmp = TempDir::new().expect("tmp");
let dir = tmp.path().join("wire");
super::super::super::ensure(&dir).expect("the boot's own mint");
assert_eq!(
std::fs::read_to_string(dir.join(ADDRESS)).expect("address"),
"127.0.0.1:0\n",
"what a boot with nothing to read writes"
);
let ca = std::fs::read(dir.join(ANCHORS)).expect("ca");
assert_eq!(
perform(&Plan {
dir: dir.clone(),
act: Act::Mint {
hosts: vec!["127.0.0.1".to_owned()],
port: Some("7752".to_owned()),
force: false,
},
}),
0
);
assert_eq!(
std::fs::read_to_string(dir.join(ADDRESS)).expect("address"),
"127.0.0.1:7752\n"
);
assert_eq!(
std::fs::read(dir.join(ANCHORS)).expect("ca"),
ca,
"and the trust root is untouched, which is what makes it not a rotation"
);
}
#[test]
fn an_unstated_port_keeps_the_standing_endpoint() {
let tmp = TempDir::new().expect("tmp");
let dir = tmp.path().join("wire");
let widen = |hosts: &[&str]| Plan {
dir: dir.clone(),
act: Act::Mint {
hosts: hosts.iter().map(|h| (*h).to_owned()).collect(),
port: None,
force: false,
},
};
assert_eq!(perform(&widen(&[])), 0, "minted at the default port");
super::super::super::state(&dir, "127.0.0.1:7752").expect("an operator's own endpoint");
assert_eq!(perform(&widen(&["127.0.0.1", "192.0.2.7"])), 0);
assert_eq!(
std::fs::read_to_string(dir.join(ADDRESS)).expect("address"),
"127.0.0.1:7752\n",
"the port the operator stated, not the default"
);
super::super::super::state(&dir, "127.0.0.1:0").expect("a self-provisioned request");
assert_eq!(perform(&widen(&["127.0.0.1"])), 0);
assert_eq!(
std::fs::read_to_string(dir.join(ADDRESS)).expect("address"),
"127.0.0.1:7737\n",
"a `:0` names no endpoint to keep"
);
}
#[test]
fn a_re_issue_a_client_box_cannot_perform_exits_one() {
let tmp = TempDir::new().expect("tmp");
std::fs::write(tmp.path().join(ANCHORS), b"an operator's anchors").expect("anchors");
assert_eq!(
perform(&Plan {
dir: tmp.path().to_owned(),
act: Act::Mint {
hosts: vec!["engine.example.com".to_owned()],
port: Some("7737".to_owned()),
force: false,
},
}),
1
);
}