Repository navigation
Pass bootroot's registration id to service add and info (#140) - #141
Merged
Merged
Conversation
bootroot main splits a registration's namespace key from its SAN label: --registration-id names the state.json entry, AppRole, policy, KV subtree, agent.toml block and fast-poll state, while --service-name is only the SAN's service label. Against that contract service add without --registration-id fails on its prompt (stdin is closed), and service info rejects --service-name, which service_registered read as "not registered" so a re-install re-added every service. ServiceAddSpec now carries the registration id and service_add_args emits both flags first; service_registered queries by registration id. The --secret-id-path comment no longer claims bootroot rejects the flag for remote-bootstrap delivery, which it now accepts. Closes #140
Contributor
Author
|
[Reviewer Round 1] Review verdict: Approve. I found no blocking issues. The change passes the caller’s registration id to The PR body includes |
Contributor
Author
|
[Review Verdict Round 1: APPROVED] |
11 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
bootroot
mainat8b92d250separates a registration's namespace key (--registration-id) from its SAN service label (--service-name). Itsservice infonow accepts only--registration-id. deploy-core's registration primitives still used the 0.2.0 contract. As a result, everyservice addstopped at bootroot's registration-id prompt, which fails because stdin is closed. Everyservice info --service-nameexited non-zero on the unknown flag, so deploy-core treated each registration as unregistered, and bootroot then refused a local-file re-install as a duplicate.Changes, all in
src/registration.rs:ServiceAddSpechas a newregistration_id: &'a strfield, placed beforeservice_name. Its doc calls it bootroot's namespace key: thestate.jsonentry, the AppRole and policy, thebootroot/services/<key>KV subtree, the managedagent.tomlblock and the fast-poll state file. Theservice_namedoc now says it is only the SAN's service label. deploy-core does not derive one from the other and does not validate either one.service_add_argsnow begins withservice add --registration-id <registration_id> --service-name <service_name>. The remaining flags are unchanged and in the same order.service_registeredtakes aregistration_idand runsservice info --registration-id <registration_id>asIdentity::Root. The exit status is still the whole answer: zero means registered, and any non-zero exit means not registered.--secret-id-pathcomment and thesecret_id_pathfield doc no longer say bootroot rejects the flag for remote-bootstrap delivery. bootroot8b92d250accepts it in both modes. The flag is still emitted exactly whensecret_id_pathisSome, and the caller decides when that applies.service infochecks a registration by its registration id.run_service_add,CoreError::ServiceRegistrationandServiceOutcomeare unchanged.New unit tests check the exact
service addargv in both delivery modes, with the optional flags present and absent. They also cover the case where the registration id and the service name are equal. ARecordingExecutortest checks thatservice_registeredrunsservice info --registration-id <id>as root in the runner's state directory, never passes--service-name, and maps exit status 0 and 1 totrueandfalse.bootler picks up this change, and passes a registration id, in aicers/bootler#498. No changelog entry is included because deploy-core has not been released.
Closes #140
Deviations from the issue
None
Test plan
local_file_emits_the_registration_id_and_the_service_name: a local-file spec with registration idroxyd-mgmt, service nameroxyd, andsecret_id_path,cert_group_gidandendpointsall set. Asserts the exact fullservice addvector, so swapping the two values or dropping a flag fails.remote_bootstrap_keeps_the_wrap_ttl_and_endpoints_after_the_new_pair: a remote-bootstrap spec withsecret_id_path,cert_group_gidandendpointsall set. Asserts the exact vector, with--secret-id-wrap-ttl 60mand the endpoint flags in their existing positions after the new pair.local_file_without_optional_fields_emits_none_of_their_flags: a local-file spec withsecret_id_path,cert_group_gidandendpointsallNone. Asserts the exact vector, so the absent flags are proven absent.remote_bootstrap_with_only_endpoints_emits_no_secret_id_path_or_cert_group: a remote-bootstrap spec with onlyendpointsset. Asserts the exact vector, with no--secret-id-pathand no--cert-group.an_equal_registration_id_and_service_name_are_both_emitted: registration id and service name are bothroxyd. Both flags are emitted with that value, each exactly once.service_registered_queries_by_registration_id_and_reads_the_exit_status: usesRecordingExecutor, scripted with exit 0 and then exit 1, and getstrueand thenfalse. Each recordedRecordedCall::RunisshasIdentity::Root. Its arguments contain the runner's state directory and end with<command path> service info --registration-id roxyd-mgmt. No argument is--service-name.cargo fmt -- --check --config group_imports=StdExternalCratecargo clippy --all-targets -- -D warningscargo clippy --all-targets --features test-support -- -D warningsRUSTDOCFLAGS="-D warnings" cargo doc --no-deps --document-private-items --features test-supportcargo testcargo test --features test-support