2
0
mirror of https://github.com/xcat2/xcat-core.git synced 2026-10-06 17:46:55 +00:00

docs(provtest): correct the boot file's provenance and list what is not covered

The dhcp-named-file scenario said its file name came from an observed
DHCP acknowledgement. Nothing here speaks DHCP: the caller spells the
name, dhcptest asserts that xCAT sends it, and this asserts it can be
fetched.

The scenario table had fallen behind four files, and two real gaps were
unwritten anywhere: the x509cert form of getcredentials, whose CSR a
wire test cannot fabricate meaningfully, and the absence of copycds --
the install tree the nodes point at is fabricated.
This commit is contained in:
Daniel Hilst
2026-09-11 12:02:38 -03:00
parent 9c515a596d
commit 69f53644d0
2 changed files with 25 additions and 8 deletions
+21 -4
View File
@@ -204,15 +204,15 @@ something those programs will do.
| `dns-removal.conf` | DNS | `removed-node` | P-08 |
| `tftp-grub2.conf` | TFTP | `grub2-binary`, `grub2-node-config`, `grub2-config-by-mac`, `grub2-kernel-and-initrd`, `tftp-escape`, `dhcp-named-file-must-exist` | P-09, P-11..P-17, P-24, P-70, P-71 |
| `tftp-pxelinux.conf` | TFTP | `pxelinux-node-config`, `pxelinux-boot-from-disk` | P-18..P-20 |
| `tftp-xnba.conf` | TFTP | `xnba-script` | P-21, P-22 |
| `tftp-xnba.conf` | TFTP | `xnba-script`, `xnba-kernel` | P-21, P-22 |
| `tftp-petitboot.conf` | TFTP | `petitboot-config` | P-23 |
| `discovery-artefacts.conf` | TFTP | `grub2-discovery-config`, `pxelinux-discovery-config`, `genesis-kernel-and-initrd` | P-25..P-31 |
| `http.conf` | HTTP | `install-tree`, `tftp-tree-over-http`, `urls-the-node-was-given`, `outside-the-aliases`, `postscripts-listing`, `port-the-node-was-told` | P-32..P-39 |
| `discovery-artefacts.conf` | TFTP | `grub2-discovery-config`, `pxelinux-discovery-config`, `xnba-discovery-config`, `genesis-images-pxelinux`, `genesis-images-grub2` | P-25..P-31 |
| `http.conf` | HTTP | `install-tree`, `tftp-tree-over-http`, `urls-the-node-was-given`, `boot-images-over-http`, `outside-the-aliases`, `postscripts-listing`, `port-the-node-was-told`, `default-port-the-node-was-told` | P-32..P-39 |
| `flowcontrol.conf` | UDP 3001 | `acknowledged`, `granted` | P-40, P-41 |
| `findme.conf` | UDP 3001 | `findme-callbacks`, `findme-plain-xml`, `findme-unprivileged-port`, `findme-foreign-address` | P-42..P-46, P-48, P-73 |
| `xcatd-destiny.conf` | TLS 3001 | `certless-handshake`, `unknown-client`, `known-node`, `chain-advances` | P-49..P-56 |
| `xcatd-postscript.conf` | TLS 3001, TCP 3002 | `postscript-terminated`, `postscript-unknown-client`, `postscript-both-transports` | P-57, P-58, P-67 |
| `xcatd-credentials.conf` | TLS 3001 | `credentials-granted`, `credentials-refused` | P-61..P-63 |
| `xcatd-credentials.conf` | TLS 3001 | `credentials-granted`, `credentials-refused`, `credentials-unprivileged-callback`, `credentials-nameless` | P-61..P-63, P-76 |
| `xcatd-policy.conf` | TLS 3001 | `command-outside-policy`, `malformed-request` | P-59, P-60 |
| `monitor.conf` | TCP 3002 | `monitor-accepts-status`, `monitor-unknown-client`, `monitor-unknown-verb`, `monitor-is-not-tls` | P-64..P-66, P-68, P-69 |
| `ordering.conf` | whole chain | `unreachable-master`, `missing-ptr`, `state-replaced` | P-72, P-74, P-75 |
@@ -221,6 +221,23 @@ A node has exactly one netboot method, so the four `tftp-*.conf` files are
alternatives, not a set: running all four against one node fails three of them.
The fixture selects the one the node is defined with.
### What is deliberately not covered
`getcredentials` has a second form: genesis asks for `x509cert` and encloses a
certificate signing request, and `xcatd` signs it and returns the certificate.
None of these scenarios exercise it. A CSR is not something a wire test can
fabricate meaningfully — a signature over a key that belongs to nothing proves
only that OpenSSL works — and the part of the exchange that decides whether a
node gets a credential at all is the callback on port 300, which is the same for
both forms and is asserted three ways here. A cluster where signing itself is
broken fails at `credentials-granted`; one where the x509 path alone is broken
is not caught, and that is the gap.
Nothing here installs an operating system either. The install tree the nodes
point at is fabricated, not produced by `copycds`: the scenarios fetch the files
a node fetches and assert what they contain, and the media that would have to be
staged to do more is measured in gigabytes.
## What it does to the host
`provtest` itself changes nothing. It opens sockets and spawns `dig`, `curl` and
+4 -4
View File
@@ -150,10 +150,10 @@ description = The boot file DHCP names is fetchable under exactly that name
[step named]
type = tftp
# Supplied by the caller from the DHCP acknowledgement it observed, not from
# anything this file knows. dhcptest asserts that the right name was sent;
# this asserts that the name sent can be fetched. Neither one alone is enough
# to boot a node.
# Spelled by the caller, because nothing here speaks DHCP: this is the name a
# grub2 node's offer carries, and the pair of suites divides the claim -- dhcptest
# asserts that xCAT sends this name, and this asserts that the name sent can be
# fetched. Neither one alone is enough to boot a node.
path = %(bootfile)s
assert =
size > 0