test(protocol): add deterministic MBR failover-key coverage docs(protocol): align package-bare-os-protocol version to 0.9.1 test(booter): add MBR corruption and wrong-topic smoke fixtures test(peer-seed): add strict pre-MBR bare_os.capabilities negotiation check feat(seeder): validate BARE_OS_SEED_REQUIRE_MBR_LABELS feat(seeder): validate BARE_OS_SEED_CAPABILITY_ATTESTATION_JSON schema docs(boot-policy): add requireProtocolPackageMin 0.9.1 example test(kernel): cover boot.policy denySeedRpcMethods behavior test(protocol): add app/cap/chat/meshdrop channel compatibility fixture test(swarm-disk): cover duplicate Protomux channel null-return path test(protocol): add 11-word kernelCapabilityWords round-trip fixture docs(schema): add mbr-layout schema and validate seeder examples test(protocol): add topicKey() golden hash fixture docs(trust): document block-0 trust assumptions in boot docs feat(seeder): add discovery.flushed readiness logging feat(booter): record peer discovery timings in boot-perf.json feat(integration): add local testnet mode to integration lab smoke test(booter): add Hyperswarm connection-budget env regression coverage test(booter): add swarm plus Corestore suspend/resume integration coverage feat(booter): mirror swarm ban events into host audit logs feat(booter): add direct-peer boot via BARE_OS_BOOT_JOIN_PEER_HEX feat(seeder): pass BARE_OS_SEED_MAX_PEERS to Hyperswarm feat(seeder): log drive.version and discoveryKey at startup test(booter): add Hyperdrive.checkout read-only boot probe coverage feat(booter): prefetch /boot/init.js before kernel handoff feat(booter): add optional /bin warm replication via downloadDiff feat(seeder): add manifestPaths SHA-256 generation in stage-kernel-tree test(peer-seed): cover helper-served block-0 after seeder exit feat(protocol): add Protomux cork batching for initial channel sends test(boot-graph): compare kernel/init labels with booter graph proc docs(boot-policy): add v9-v11 schema examples feat(release): add requireInitJsSha256 fixture generation step test(vfs): add BARE_OS_VFS_SYSTEM_RO_ALIAS coverage test(vfs): strengthen system-drive write-deny path coverage feat(identity): add personal-drive namespace export/import docs and tests test(booter): add guest-to-login warm cache invalidation regression test(vfs): add guest deny coverage for /.bare sensitive paths test(coreutils): add cross-drive mv failure injection coverage test(vfs): add .bareos_empty round-trip coverage across mkdir/rmdir/cp/git-fs test(vfs): add /dev/shm quota enforcement coverage test(proc): add /proc/bare_os/index.json sortedness and schema checks test(vfs): add warm read cache invalidation on replication growth docs(ctx): document bareOsInvalidateWarmReadCaches(reason) test(kernel): add BARE_OS_BOOT_DRY_RUN behavior coverage docs(posix): add dashboard rows for all COREUTILS_COMMANDS feat(curl): expand -w variables beyond http_code/url_effective/size_download feat(wget): mark -N timestamping as explicit unsupported error feat(curl): plumb mutual TLS cert/key intent to ctx.httpFetch metadata feat(shuf): add deterministic seed mode via BARE_OS_SHUF_SEED docs(sort): document -M month-sort as unsupported feat(grep): add explicit -E and -G mode handling test(sed): add Open Group Issue 7 golden fixtures test(awk): add getline VFS regressions for missing/repeat/boundary cases test(shell): add non-interactive here-doc coverage test(shell): add trap delivery coverage for synthetic PIDs/job IDs test(shell): add set -e compound-body behavior coverage docs(shell): strengthen read builtin opt-in guidance test(env): add Bare-runtime coverage for -S and --env-file docs(man): add examples for pathcap-verify pkg-swarm-index corestorectl test(identity): add account/vault backup-restore smoke coverage feat(audit): add tamper detection verification for audit chain rows test(peer-admission): cover strict empty allowlist deny behavior test(peer-admission): add denylist precedence over allowlist coverage test(peer-admission): add BARE_OS_PEER_REQUIRE_CAPS_JSON metadata checks docs(identity): add trusted-key rotation example for path capabilities feat(schema): tighten extensionSignerPinsV2-V4 hash validation test(delegate): add allowlist negative cases for curl/wget/git/hrpc/systemctl test(proc): extend /proc/self/environ redaction key coverage docs(security): add peer-assisted block-0 mirroring threat-model notes feat(bench): add boot budget trend output from real booter phases test(baretop): align fixture coverage with /proc snapshot key set test(metrics): validate /proc/bare_os/metrics.prom OpenMetrics shape docs(ops): add structured seeder NDJSON examples test(replication): add live stall-hint coverage for no_peers/length_unavailable/ok docs(release): add corestore-snapshot workflow to checklist docs(ops): add mirror-drive experiment utility to maintainer workflow test(booter): add monitor progress coverage for replication live sketch feat(seeder): validate DHT bootstrap address class JSON inputs docs(network): add HYPERSWARM_BOOTSTRAP testnet operator guidance chore(root): add deterministic test:integration script docs(ci): add local CI runbook for no-.github environments docs(release): add npm run test:bare after npm test feat(verify): add protocol docs/package version parity checker feat(verify): enforce feature-roadmap canonical path consistency feat(lockfile-drift): add tier-1 strict fail option for mismatches docs(lockfile-drift): add udx-native and blind-peering upgrade workflow notes docs(cli-parity): add bare-fetch upstream issue tracking row feat(bundle-health): generate per-tier bundle size regression thresholds feat(doc-contracts): verify handbook references to current proc schema versions feat(pretest): add validate-mermaid-syntax gate feat(probe): add bare-runtime top-25 critical command lane docs(protocol): update capability-word prose from bits..bits5 to current words docs(two-drive): document /tmp /var/log and account-prefix routing docs(security): add concise boot trust model page and links docs(dev-guide): add P2P lab cookbook section docs(dev-guide): add how-to for adding seed RPCs docs(dev-guide): add how-to for adding /proc/bare_os nodes docs(dev-guide): add /bin utility checklist for man/posix/build/parity/tests docs(user-manual): add short What BareOS is not section
229 lines
6.7 KiB
JavaScript
229 lines
6.7 KiB
JavaScript
#!/usr/bin/env node
|
|
/**
|
|
* Integration smoke: boot a real seeder + booter pair with isolated stores.
|
|
* Runs `npm run os:seeder` and `npm run os:booter` against temp Corestores.
|
|
*/
|
|
|
|
import { spawn } from 'node:child_process'
|
|
import { mkdtemp, rm } from 'node:fs/promises'
|
|
import os from 'node:os'
|
|
import path from 'node:path'
|
|
import process from 'node:process'
|
|
import { fileURLToPath } from 'node:url'
|
|
|
|
const root = path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..')
|
|
const tmpBase = await mkdtemp(path.join(os.tmpdir(), 'bare-os-integration-lab-'))
|
|
const hostData = path.join(tmpBase, 'host-data')
|
|
const seedStore = path.join(hostData, 'corestore', 'seeder')
|
|
const bootStore = path.join(hostData, 'corestore', 'booter')
|
|
const timeoutMs = clampInt(process.env.BARE_OS_INTEGRATION_TIMEOUT_MS, 120000)
|
|
const seederReadyTimeoutMs = clampInt(
|
|
process.env.BARE_OS_INTEGRATION_SEEDER_READY_TIMEOUT_MS,
|
|
60000
|
|
)
|
|
const booterReadyTimeoutMs = clampInt(
|
|
process.env.BARE_OS_INTEGRATION_BOOTER_READY_TIMEOUT_MS,
|
|
90000
|
|
)
|
|
const testnet = resolveTestnetBootstrapEnv(process.env)
|
|
|
|
/** @type {{ seeder?: import('node:child_process').ChildProcess, booter?: import('node:child_process').ChildProcess }} */
|
|
const procs = {}
|
|
const startedAt = Date.now()
|
|
|
|
const baseEnv = {
|
|
...process.env,
|
|
BARE_OS_HOST_DATA: hostData,
|
|
BARE_OS_SEED_STORE: seedStore,
|
|
BARE_OS_BOOT_STORE: bootStore,
|
|
BARE_OS_NO_SPLASH: '1',
|
|
BARE_OS_BOOT_TIMEOUT_MS: String(clampInt(process.env.BARE_OS_BOOT_TIMEOUT_MS, 45000)),
|
|
...(testnet.envBootstrap ? { HYPERSWARM_BOOTSTRAP: testnet.envBootstrap } : {})
|
|
}
|
|
|
|
try {
|
|
procs.seeder = runNpmScript('os:seeder', { env: baseEnv, name: 'seeder' })
|
|
await waitForOutput(
|
|
procs.seeder,
|
|
[/seeder active/i, /MBR block 0/i],
|
|
seederReadyTimeoutMs,
|
|
'seeder readiness'
|
|
)
|
|
|
|
procs.booter = runNpmScript('os:booter', {
|
|
env: {
|
|
...baseEnv,
|
|
BARE_OS_SKIP_REPL: '1',
|
|
BARE_OS_BOOT_TRACE: 'ndjson'
|
|
},
|
|
name: 'booter'
|
|
})
|
|
|
|
await waitForOutput(
|
|
procs.booter,
|
|
[/booter:kernel_invoke/i, /"ready":\s*true/i, /"type":"boot_ready"/i],
|
|
booterReadyTimeoutMs,
|
|
'booter readiness'
|
|
)
|
|
|
|
const booterExited = await waitForExit(procs.booter, 10000)
|
|
const ok = booterExited.code === 0 || booterExited.code === null
|
|
|
|
if (!ok) {
|
|
throw new Error(`booter exited with code ${booterExited.code ?? 'signal'}`)
|
|
}
|
|
|
|
console.log(
|
|
JSON.stringify({
|
|
schema: 2,
|
|
ok: true,
|
|
atMs: Date.now(),
|
|
elapsedMs: Date.now() - startedAt,
|
|
mode: 'seeder-booter-e2e',
|
|
testnetMode: testnet.enabled,
|
|
hyperswarmBootstrap: testnet.redactedBootstrap,
|
|
tempRoot: tmpBase
|
|
})
|
|
)
|
|
} catch (err) {
|
|
console.error(
|
|
JSON.stringify({
|
|
schema: 2,
|
|
ok: false,
|
|
atMs: Date.now(),
|
|
elapsedMs: Date.now() - startedAt,
|
|
mode: 'seeder-booter-e2e',
|
|
testnetMode: testnet.enabled,
|
|
hyperswarmBootstrap: testnet.redactedBootstrap,
|
|
error: err instanceof Error ? err.message : String(err)
|
|
})
|
|
)
|
|
process.exitCode = 1
|
|
} finally {
|
|
await teardownProc(procs.booter)
|
|
await teardownProc(procs.seeder)
|
|
if (process.env.BARE_OS_INTEGRATION_KEEP_TMP !== '1') {
|
|
await rm(tmpBase, { recursive: true, force: true })
|
|
}
|
|
}
|
|
|
|
/**
|
|
* @param {string | undefined} raw
|
|
* @param {number} fallback
|
|
*/
|
|
function clampInt(raw, fallback) {
|
|
const n = Number.parseInt(String(raw ?? ''), 10)
|
|
if (!Number.isFinite(n) || n <= 0) return fallback
|
|
return Math.min(Math.max(1000, n), 15 * 60 * 1000)
|
|
}
|
|
|
|
/**
|
|
* Local integration testnet mode:
|
|
* - Enable with BARE_OS_INTEGRATION_TESTNET=1|true|yes.
|
|
* - Uses BARE_OS_INTEGRATION_TESTNET_BOOTSTRAP when present.
|
|
* - Otherwise reuses HYPERSWARM_BOOTSTRAP when already configured.
|
|
* @param {Record<string, string | undefined>} env
|
|
*/
|
|
function resolveTestnetBootstrapEnv(env) {
|
|
const on = String(env.BARE_OS_INTEGRATION_TESTNET ?? '')
|
|
.trim()
|
|
.toLowerCase()
|
|
const enabled = on === '1' || on === 'true' || on === 'yes'
|
|
const explicit = String(env.BARE_OS_INTEGRATION_TESTNET_BOOTSTRAP ?? '').trim()
|
|
const inherited = String(env.HYPERSWARM_BOOTSTRAP ?? '').trim()
|
|
const envBootstrap = enabled ? (explicit || inherited || '') : ''
|
|
const redactedBootstrap = envBootstrap
|
|
? envBootstrap
|
|
.split(',')
|
|
.map((s) => s.trim())
|
|
.filter(Boolean)
|
|
.map((s) => (s.length > 20 ? s.slice(0, 20) + '...' : s))
|
|
.join(',')
|
|
: ''
|
|
return { enabled, envBootstrap, redactedBootstrap }
|
|
}
|
|
|
|
/**
|
|
* @param {string} script
|
|
* @param {{ env: Record<string, string | undefined>, name: string }} opts
|
|
*/
|
|
function runNpmScript(script, opts) {
|
|
const child = spawn('npm', ['run', script], {
|
|
cwd: root,
|
|
env: opts.env,
|
|
stdio: ['ignore', 'pipe', 'pipe']
|
|
})
|
|
child.stdout?.setEncoding('utf8')
|
|
child.stderr?.setEncoding('utf8')
|
|
child.stdout?.on('data', (d) => process.stdout.write(`[${opts.name}] ${d}`))
|
|
child.stderr?.on('data', (d) => process.stderr.write(`[${opts.name}] ${d}`))
|
|
return child
|
|
}
|
|
|
|
/**
|
|
* @param {import('node:child_process').ChildProcess | undefined} child
|
|
* @param {RegExp[]} patterns
|
|
* @param {number} ms
|
|
* @param {string} label
|
|
*/
|
|
function waitForOutput(child, patterns, ms, label) {
|
|
if (!child) return Promise.reject(new Error(`${label}: process missing`))
|
|
return new Promise((resolve, reject) => {
|
|
let buf = ''
|
|
const to = setTimeout(() => {
|
|
cleanup()
|
|
reject(new Error(`${label}: timeout after ${ms}ms`))
|
|
}, Math.min(ms, timeoutMs))
|
|
const onChunk = (chunk) => {
|
|
buf += String(chunk)
|
|
if (buf.length > 120000) buf = buf.slice(-80000)
|
|
if (patterns.some((re) => re.test(buf))) {
|
|
cleanup()
|
|
resolve()
|
|
}
|
|
}
|
|
const onExit = (code) => {
|
|
cleanup()
|
|
reject(new Error(`${label}: process exited before match (${code ?? 'signal'})`))
|
|
}
|
|
const cleanup = () => {
|
|
clearTimeout(to)
|
|
child.stdout?.off('data', onChunk)
|
|
child.stderr?.off('data', onChunk)
|
|
child.off('exit', onExit)
|
|
}
|
|
child.stdout?.on('data', onChunk)
|
|
child.stderr?.on('data', onChunk)
|
|
child.on('exit', onExit)
|
|
})
|
|
}
|
|
|
|
/**
|
|
* @param {import('node:child_process').ChildProcess | undefined} child
|
|
* @param {number} ms
|
|
*/
|
|
function waitForExit(child, ms) {
|
|
if (!child) return Promise.resolve({ code: 0 })
|
|
return new Promise((resolve) => {
|
|
let done = false
|
|
const finish = (code) => {
|
|
if (done) return
|
|
done = true
|
|
clearTimeout(to)
|
|
resolve({ code })
|
|
}
|
|
const to = setTimeout(() => finish(null), ms)
|
|
child.once('exit', finish)
|
|
})
|
|
}
|
|
|
|
/**
|
|
* @param {import('node:child_process').ChildProcess | undefined} child
|
|
*/
|
|
async function teardownProc(child) {
|
|
if (!child || child.killed || child.exitCode != null) return
|
|
child.kill('SIGTERM')
|
|
await waitForExit(child, 6000)
|
|
if (child.exitCode == null) child.kill('SIGKILL')
|
|
}
|