From e69eafcc9fcb53a76309c26e84f9d885ef37ec61 Mon Sep 17 00:00:00 2001 From: Dai Ha Date: Sat, 3 Oct 2026 15:40:52 +0200 Subject: [PATCH] fleetd #650: scope the READ-unreachable javadoc to loopback-trust FleetdAssemblyFleetAppTest's class javadoc stated that /sessions' Authz.Action.READ gate is always refused, and that READ always needs Caller.resolved(). That is true only under auth.mode: loopback-trust, the mode this test runs under because it configures no auth: block. Under auth.mode: token, CallerResolver.resolve() returns before ever consulting Caller.resolved()/scanComplete(), so a valid bearer token resolves to PRIMARY with no pid lookup on that path. Names the two tests that already exercise that path against a real assembly. --- .../fleet/FleetdAssemblyFleetAppTest.java | 39 ++++++++++++------- 1 file changed, 25 insertions(+), 14 deletions(-) diff --git a/fleetd/src/test/java/dev/ltms/fleet/FleetdAssemblyFleetAppTest.java b/fleetd/src/test/java/dev/ltms/fleet/FleetdAssemblyFleetAppTest.java index 52e49bad..89151be3 100644 --- a/fleetd/src/test/java/dev/ltms/fleet/FleetdAssemblyFleetAppTest.java +++ b/fleetd/src/test/java/dev/ltms/fleet/FleetdAssemblyFleetAppTest.java @@ -58,20 +58,31 @@ import static org.junit.jupiter.api.Assertions.assertEquals; * {@code HttpClient} — no accessor needed for this half. * *

{@code GET /sessions} could not be driven the same way, so this class does - * not pin the merge half of the deleted test's javadoc. {@code /sessions} requires - * {@code Authz.Action.READ}, which — through the REAL assembly's real {@code - * CallerResolver}/{@code ConnectionIdentity} (built with a hardcoded {@code - * new LsofPeerPidLookup()}) — needs {@code Caller.resolved()}, i.e. a real positive pid from - * {@code lsof}. {@code LsofPeerPidLookup} excludes its own pid (see its javadoc), and a JUnit - * test's HTTP client and the daemon under test share one JVM pid, so the resolved pid is always - * {@code -1} and every such request is refused as {@code ANONYMOUS} (fleetd #317's fail-closed - * rule) before the route handler — and its {@code memberHerdr} merge — is ever reached. Verified - * directly: driving {@code GET /sessions} here returns {@code 401 unauthenticated}, not the - * merged body. {@code FleetAppTwoDaemonTest} avoids this because it builds {@code FleetApp} with - * {@code callers: null}, which is not what the real assembly passes. The {@code /healthz} pin - * below is what this class relies on for CB-185's {@code FleetApp} half; {@code - * FleetAppTwoDaemonTest} remains the full behavioural proof that {@code FleetApp} itself merges - * {@code /sessions} correctly once handed two clients. + * not pin the merge half of the deleted test's javadoc. This class configures no {@code auth:} + * block, so it runs under the default {@code loopback-trust} mode ({@code FleetConfig}). Under + * that mode, {@code /sessions} requires {@code Authz.Action.READ}, which — through the REAL + * assembly's real {@code CallerResolver}/{@code ConnectionIdentity} (built with a hardcoded + * {@code new LsofPeerPidLookup()}) — needs {@code Caller.resolved()}, i.e. a real positive pid + * from {@code lsof}. {@code LsofPeerPidLookup} excludes its own pid (see its javadoc), and a + * JUnit test's HTTP client and the daemon under test share one JVM pid, so the resolved pid is + * always {@code -1} and every such request is refused as {@code ANONYMOUS} (fleetd #317's + * fail-closed rule) before the route handler — and its {@code memberHerdr} merge — is ever + * reached. Verified directly: driving {@code GET /sessions} here returns {@code 401 + * unauthenticated}, not the merged body. {@code FleetAppTwoDaemonTest} avoids this because it + * builds {@code FleetApp} with {@code callers: null}, which is not what the real assembly + * passes. The {@code /healthz} pin below is what this class relies on for CB-185's {@code + * FleetApp} half; {@code FleetAppTwoDaemonTest} remains the full behavioural proof that + * {@code FleetApp} itself merges {@code /sessions} correctly once handed two clients. + * + *

This refusal is {@code loopback-trust}-specific, not a property of {@code + * CallerResolver} in general. Under {@code auth.mode: token}, {@code + * CallerResolver#resolve} returns before ever consulting {@code Caller.resolved()} or {@code + * Caller.scanComplete()}: a request carrying a valid bearer token in its {@code Authorization} + * header resolves to {@code Role#PRIMARY} with no pid lookup at all, so the same-JVM-pid + * exclusion above never comes into play. {@code FleetdQuarantineOutageDualWindowAssemblyTest} + * and {@code FleetdListReportingSourcesAssemblyTest} both drive {@code Authz.Action.READ} this + * way, over a real {@code McpSyncClient}/{@code HttpClient} against a real {@code + * FleetdAssembly#assembleAndStart}, and both get the real response rather than a refusal. * *

fleetd #629 follow-up. The fix below (see {@link TwoHerdrResourcePorts}) * makes {@link #healthzGoesRedWhenTheLeadDaemonIsDownEvenThoughTheMemberIsUp}'s fake {@code