mirror of
https://github.com/xcat2/xcat-core.git
synced 2026-10-06 17:46:55 +00:00
docs(provtest): correct the boot file's provenance and list what is not covered
The dhcp-named-file scenario said its file name came from an observed DHCP acknowledgement. Nothing here speaks DHCP: the caller spells the name, dhcptest asserts that xCAT sends it, and this asserts it can be fetched. The scenario table had fallen behind four files, and two real gaps were unwritten anywhere: the x509cert form of getcredentials, whose CSR a wire test cannot fabricate meaningfully, and the absence of copycds -- the install tree the nodes point at is fabricated.
This commit is contained in:
@@ -204,15 +204,15 @@ something those programs will do.
|
||||
| `dns-removal.conf` | DNS | `removed-node` | P-08 |
|
||||
| `tftp-grub2.conf` | TFTP | `grub2-binary`, `grub2-node-config`, `grub2-config-by-mac`, `grub2-kernel-and-initrd`, `tftp-escape`, `dhcp-named-file-must-exist` | P-09, P-11..P-17, P-24, P-70, P-71 |
|
||||
| `tftp-pxelinux.conf` | TFTP | `pxelinux-node-config`, `pxelinux-boot-from-disk` | P-18..P-20 |
|
||||
| `tftp-xnba.conf` | TFTP | `xnba-script` | P-21, P-22 |
|
||||
| `tftp-xnba.conf` | TFTP | `xnba-script`, `xnba-kernel` | P-21, P-22 |
|
||||
| `tftp-petitboot.conf` | TFTP | `petitboot-config` | P-23 |
|
||||
| `discovery-artefacts.conf` | TFTP | `grub2-discovery-config`, `pxelinux-discovery-config`, `genesis-kernel-and-initrd` | P-25..P-31 |
|
||||
| `http.conf` | HTTP | `install-tree`, `tftp-tree-over-http`, `urls-the-node-was-given`, `outside-the-aliases`, `postscripts-listing`, `port-the-node-was-told` | P-32..P-39 |
|
||||
| `discovery-artefacts.conf` | TFTP | `grub2-discovery-config`, `pxelinux-discovery-config`, `xnba-discovery-config`, `genesis-images-pxelinux`, `genesis-images-grub2` | P-25..P-31 |
|
||||
| `http.conf` | HTTP | `install-tree`, `tftp-tree-over-http`, `urls-the-node-was-given`, `boot-images-over-http`, `outside-the-aliases`, `postscripts-listing`, `port-the-node-was-told`, `default-port-the-node-was-told` | P-32..P-39 |
|
||||
| `flowcontrol.conf` | UDP 3001 | `acknowledged`, `granted` | P-40, P-41 |
|
||||
| `findme.conf` | UDP 3001 | `findme-callbacks`, `findme-plain-xml`, `findme-unprivileged-port`, `findme-foreign-address` | P-42..P-46, P-48, P-73 |
|
||||
| `xcatd-destiny.conf` | TLS 3001 | `certless-handshake`, `unknown-client`, `known-node`, `chain-advances` | P-49..P-56 |
|
||||
| `xcatd-postscript.conf` | TLS 3001, TCP 3002 | `postscript-terminated`, `postscript-unknown-client`, `postscript-both-transports` | P-57, P-58, P-67 |
|
||||
| `xcatd-credentials.conf` | TLS 3001 | `credentials-granted`, `credentials-refused` | P-61..P-63 |
|
||||
| `xcatd-credentials.conf` | TLS 3001 | `credentials-granted`, `credentials-refused`, `credentials-unprivileged-callback`, `credentials-nameless` | P-61..P-63, P-76 |
|
||||
| `xcatd-policy.conf` | TLS 3001 | `command-outside-policy`, `malformed-request` | P-59, P-60 |
|
||||
| `monitor.conf` | TCP 3002 | `monitor-accepts-status`, `monitor-unknown-client`, `monitor-unknown-verb`, `monitor-is-not-tls` | P-64..P-66, P-68, P-69 |
|
||||
| `ordering.conf` | whole chain | `unreachable-master`, `missing-ptr`, `state-replaced` | P-72, P-74, P-75 |
|
||||
@@ -221,6 +221,23 @@ A node has exactly one netboot method, so the four `tftp-*.conf` files are
|
||||
alternatives, not a set: running all four against one node fails three of them.
|
||||
The fixture selects the one the node is defined with.
|
||||
|
||||
### What is deliberately not covered
|
||||
|
||||
`getcredentials` has a second form: genesis asks for `x509cert` and encloses a
|
||||
certificate signing request, and `xcatd` signs it and returns the certificate.
|
||||
None of these scenarios exercise it. A CSR is not something a wire test can
|
||||
fabricate meaningfully — a signature over a key that belongs to nothing proves
|
||||
only that OpenSSL works — and the part of the exchange that decides whether a
|
||||
node gets a credential at all is the callback on port 300, which is the same for
|
||||
both forms and is asserted three ways here. A cluster where signing itself is
|
||||
broken fails at `credentials-granted`; one where the x509 path alone is broken
|
||||
is not caught, and that is the gap.
|
||||
|
||||
Nothing here installs an operating system either. The install tree the nodes
|
||||
point at is fabricated, not produced by `copycds`: the scenarios fetch the files
|
||||
a node fetches and assert what they contain, and the media that would have to be
|
||||
staged to do more is measured in gigabytes.
|
||||
|
||||
## What it does to the host
|
||||
|
||||
`provtest` itself changes nothing. It opens sockets and spawns `dig`, `curl` and
|
||||
|
||||
@@ -150,10 +150,10 @@ description = The boot file DHCP names is fetchable under exactly that name
|
||||
|
||||
[step named]
|
||||
type = tftp
|
||||
# Supplied by the caller from the DHCP acknowledgement it observed, not from
|
||||
# anything this file knows. dhcptest asserts that the right name was sent;
|
||||
# this asserts that the name sent can be fetched. Neither one alone is enough
|
||||
# to boot a node.
|
||||
# Spelled by the caller, because nothing here speaks DHCP: this is the name a
|
||||
# grub2 node's offer carries, and the pair of suites divides the claim -- dhcptest
|
||||
# asserts that xCAT sends this name, and this asserts that the name sent can be
|
||||
# fetched. Neither one alone is enough to boot a node.
|
||||
path = %(bootfile)s
|
||||
assert =
|
||||
size > 0
|
||||
|
||||
Reference in New Issue
Block a user