117 lines
5.0 KiB
Go
117 lines
5.0 KiB
Go
package windowsnative
|
|
|
|
import (
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// TestNativeFixtureAssets_HP_HARNESS_20 prevents the host-side controller from
|
|
// drifting back to a PowerShell-only or protocol-stub lane. It intentionally
|
|
// checks only static contracts; the real hierarchy proof remains the documented
|
|
// native VM run.
|
|
func TestNativeFixtureAssets_HP_HARNESS_20(t *testing.T) {
|
|
t.Parallel()
|
|
root := filepath.Clean(filepath.Join("..", ".."))
|
|
read := func(relative string) string {
|
|
t.Helper()
|
|
data, err := os.ReadFile(filepath.Join(root, relative))
|
|
if err != nil {
|
|
t.Fatalf("read %s: %v", relative, err)
|
|
}
|
|
return string(data)
|
|
}
|
|
runner := read("scripts/windows/native-test")
|
|
for _, required := range []string{
|
|
"scripts/windows/build-test-bundle\" --native-fixture",
|
|
"scripts/windows/test-host\" prepare",
|
|
"ACTIVE_USER_ELEVATED,ACTIVE_SYSTEM",
|
|
"assert_context local-service no local-service",
|
|
"assert_stdin_close",
|
|
"assert_signal_term",
|
|
"rvc kill TERM \"$client_id\" \"$issue\"",
|
|
"assert_server_restart_reconnect",
|
|
"compose restart server",
|
|
"rvc append \"$client_id\" \"$issue\" RVBOX_NATIVE_INPUT",
|
|
"rvc close-stdin \"$client_id\" \"$issue\"",
|
|
"clean --purge --yes",
|
|
"RVBOX_NATIVE_ENDPOINT_HOST",
|
|
"test/linux-server/compose.yaml",
|
|
} {
|
|
if !strings.Contains(runner, required) {
|
|
t.Fatalf("native runner is missing %q", required)
|
|
}
|
|
}
|
|
testHost := read("scripts/windows/test-host")
|
|
for _, required := range []string{"xz -T0 -3", "accelerated_stage", "copy_stage_file", "--proxy", "--anyauth", "--continue-at", "rvbox.exe.xz", "retry_limit=4", "ConnectTimeout=10", "bundle transfer did not reach the expected SHA-256 manifest", "verified transfer_sha256", "reset-force-poweroff", "$run_root/.accelerated-stage.XXXXXX", "service-startup.log", "test-logs/rvbox.log"} {
|
|
if !strings.Contains(testHost, required) {
|
|
t.Fatalf("native test-host is missing compressed transfer contract %q", required)
|
|
}
|
|
}
|
|
compose := read("test/linux-server/compose.yaml")
|
|
for _, required := range []string{"../../bin/rvbox-server", "nginx:1.27-alpine", "rvbox.native.run_id", "RVBOX_NATIVE_RUNTIME_DIR", "certgen", "networks: [native]"} {
|
|
if !strings.Contains(compose, required) {
|
|
t.Fatalf("native Compose fixture is missing %q", required)
|
|
}
|
|
}
|
|
defaults := read("internal/client/supervisor/windows/testfaults_default.go")
|
|
fixture := read("internal/client/supervisor/windows/testfaults_fixture.go")
|
|
if !strings.Contains(defaults, "//go:build !rvbox_native_test") || !strings.Contains(fixture, "//go:build rvbox_native_test") {
|
|
t.Fatal("fixture-only context faults are not separated from release builds")
|
|
}
|
|
service := read("cmd/rvbox/service_windows.go")
|
|
if !strings.Contains(service, "applyServiceDiagnosticsACL") || !strings.Contains(service, "D:P(A;;FA;;;SY)(A;;FA;;;BA)") {
|
|
t.Fatal("Windows service diagnostics are not readable by administrators")
|
|
}
|
|
testing := read("docs/testing.md")
|
|
for _, required := range []string{"server-process\nrestart", "new reconciled WSS session", "`logs` is the narrow read-only"} {
|
|
if !strings.Contains(testing, required) {
|
|
t.Fatalf("native workflow documentation is missing %q", required)
|
|
}
|
|
}
|
|
}
|
|
|
|
// TestProductionComposeAssets_HP_OPS_01 guards the deployment properties that
|
|
// a syntax-only Compose check cannot prove: private server reachability through
|
|
// nginx, non-root state initialization, and a repository-local smoke cleanup.
|
|
func TestProductionComposeAssets_HP_OPS_01(t *testing.T) {
|
|
t.Parallel()
|
|
root := filepath.Clean(filepath.Join("..", ".."))
|
|
read := func(relative string) string {
|
|
t.Helper()
|
|
data, err := os.ReadFile(filepath.Join(root, relative))
|
|
if err != nil {
|
|
t.Fatalf("read %s: %v", relative, err)
|
|
}
|
|
return string(data)
|
|
}
|
|
compose := read("deploy/production/compose.yaml")
|
|
for _, required := range []string{
|
|
"RVBOX_SERVER_CONFIG:-./server.toml",
|
|
"RVBOX_HTTPS_BIND:-0.0.0.0",
|
|
"nginx@sha256:65645c7bb6a0661892a8b03b89d0743208a18dd2f3f17a54ef4b76fb8e2f2a10",
|
|
"user: \"65532:65532\"",
|
|
"nofile:", "soft: 65536", "hard: 65536",
|
|
"condition: service_completed_successfully",
|
|
"condition: service_healthy",
|
|
"NET_BIND_SERVICE", "DAC_OVERRIDE", "CHOWN", "SETUID", "SETGID",
|
|
} {
|
|
if !strings.Contains(compose, required) {
|
|
t.Fatalf("production Compose is missing %q", required)
|
|
}
|
|
}
|
|
config := read("deploy/production/server.toml.example")
|
|
for _, required := range []string{"agent_listen = \"0.0.0.0:6899\"", "listen = \"0.0.0.0:6901\"", "enabled = false", "log_file = \"/var/lib/rvbox-server/logs/rvbox-server.log\"", "log_max_bytes = 10485760", "log_max_files = 5"} {
|
|
if !strings.Contains(config, required) {
|
|
t.Fatalf("production server example is missing %q", required)
|
|
}
|
|
}
|
|
runner := read("scripts/test-production-compose")
|
|
for _, required := range []string{".test-runs/$run_id/production-compose", "RVBOX_HTTPS_BIND=127.0.0.1", "curl --fail", "compose exec -T server", "clean --purge --yes"} {
|
|
if !strings.Contains(runner, required) {
|
|
t.Fatalf("production smoke runner is missing %q", required)
|
|
}
|
|
}
|
|
}
|