mirror of
https://github.com/xcat2/xcat-core.git
synced 2026-10-07 10:06:39 +00:00
2efcbcde08
Running the scenarios against a live management node found nine places where they asserted something xCAT does not do. Corrected here, each with the reason in the file: - install configs carry no xcatd= or destiny=; those are written for the genesis states only. - #END OF SCRIPT is plain-transport framing; over TLS a reply ends with <serverdone>. - getcredentials is named in <arg> and answered as <data><content/> <desc/></data>, so both fields are addressable now. - currstate for an install is "install <osimage>", so the operator is starts-with. - bootparams is empty for an ordinary install, so kernel and initrd cannot be asserted from getdestiny. - a server never reached sends no <error>; assert the handshake instead. - an NXDOMAIN answer is the expected result of a removal scenario. - P-75 has to precede P-74: a withdrawn name cannot be nodeset again. Also adds netutil.hex_net: a per-network config is named by as many hex digits as the netmask covers, not by all eight.
97 lines
3.3 KiB
Plaintext
97 lines
3.3 KiB
Plaintext
# Stage 12: getpostscript, on both transports. Spec P-57, P-58, P-67.
|
|
#
|
|
# The node fetches the script it is to run after the installer finishes, and it
|
|
# fetches it over whichever transport it has: TLS 3001 during genesis,
|
|
# plain 3002 from `xcatdsklspost` inside the installed system. Two paths, one
|
|
# script, and two framings for it, which is the thing to keep straight when
|
|
# reading the assertions below. Over 3001 the body arrives as <data> elements
|
|
# and is ended by <serverdone>. Over 3002 there is no envelope at all, so
|
|
# xcatd writes `#END OF SCRIPT` after the last line (xcatd:554) and the client
|
|
# reads until it -- a body truncated without the marker is read as a hang and
|
|
# not as an error. The marker is therefore asserted on the plain transport
|
|
# only; asserting it on the TLS one would be asserting the wrong protocol.
|
|
#
|
|
# provtest run \
|
|
# --set server=10.99.1.1 --set client=10.99.1.11 \
|
|
# --set unknown=10.99.1.201 --set node=provtestcn \
|
|
# --set xcatport=3001 --set monitorport=3002 \
|
|
# conf/xcatd-postscript.conf
|
|
|
|
[defaults]
|
|
server = %(server)s
|
|
bind = %(client)s
|
|
timeout = 30
|
|
retries = 2
|
|
|
|
# --- P-57 -------------------------------------------------------------------
|
|
|
|
[scenario postscript-terminated]
|
|
description = A known node's postscript arrives complete and is ended by the server
|
|
|
|
[step getpostscript]
|
|
type = xcatreq
|
|
port = %(xcatport)s
|
|
command = getpostscript
|
|
assert =
|
|
# The envelope's end marker on this transport. A response without it is a
|
|
# connection the node is still waiting on.
|
|
serverdone == yes
|
|
# And the body is this node's: the script is built per node, and a node
|
|
# that runs somebody else's sets up somebody else's network and keys.
|
|
text contains %(node)s
|
|
|
|
# --- P-58 -------------------------------------------------------------------
|
|
|
|
[scenario postscript-unknown-client]
|
|
description = A client that maps to no node is given no node's script
|
|
|
|
[step leaked]
|
|
type = xcatreq
|
|
port = %(xcatport)s
|
|
command = getpostscript
|
|
bind = %(unknown)s
|
|
expect = any
|
|
# Whether xcatd answers this at all is a policy question; what must not happen
|
|
# is that it answers with somebody else's script. A postscript carries the
|
|
# node's name, its master and the credentials it is to install.
|
|
|
|
[step leak]
|
|
type = extract
|
|
from = $leaked.text
|
|
pattern = %(node)s
|
|
assert =
|
|
matched == no
|
|
|
|
# --- P-67 -------------------------------------------------------------------
|
|
|
|
[scenario postscript-both-transports]
|
|
description = The same node gets the same script on 3001 and on 3002
|
|
|
|
[step overtls]
|
|
type = xcatreq
|
|
port = %(xcatport)s
|
|
command = getpostscript
|
|
assert =
|
|
serverdone == yes
|
|
|
|
[step marker]
|
|
type = extract
|
|
from = $overtls.text
|
|
# An assignment from the body that is specific to this node, used below as the
|
|
# thing the other transport has to agree about. The two framings differ --
|
|
# XML elements on one side, bare lines on the other -- so a byte comparison of
|
|
# the responses would compare the envelopes and not the script. Unanchored for
|
|
# the same reason: on this transport the line is wrapped in <data>.
|
|
pattern = (NODE=\S+)
|
|
assert =
|
|
matched == yes
|
|
|
|
[step overplain]
|
|
type = monitor
|
|
port = %(monitorport)s
|
|
send =
|
|
getpostscript
|
|
assert =
|
|
text contains #END OF SCRIPT
|
|
text contains $marker.value
|