Tests / Test passed: 581
Host Agent: - One-time local operator account bootstrap (PBKDF2-HMAC-SHA256, atomic 0600-permission write) gating the daemon's first unattended start via a new `setup` CLI subcommand. - Default control-plane URL now https://amcp.home.jerryyan.top (env var override unchanged). - Enrollment no longer requires a pre-issued token; falls back to zero-token self-service enrollment when none is configured. Cloud control plane: - CLOUD_SELF_SERVICE_ENROLLMENT_ENABLED (default false) opt-in flag. - SelfServiceEnrollmentAuthProvider + ChainedEnrollmentAuthProvider: configured tokens still take priority; self-service only applies when no token matches, preserving edge-host-enrollment's token-bound path. - Fixed a latent bug in sql_repository.py::enroll_host: the token-conflict lookup used `== enrollment_token_digest`, which SQLAlchemy compiles to `IS NULL` when the value is None, so every self-service enrollment after the first would have falsely collided with an existing NULL-digest host. Skipped that lookup entirely when the digest is None. Docs/deploy: .env.example, compose.yaml, compose.deploy.yaml, CLOUD_DEPLOYMENT.md, MACOS_IPHONE_SETUP.md updated for the new flag, URL default, and required `device-host-agent setup` step. Verification: 494 non-integration tests pass; openspec validate --strict passes. PostgreSQL-backed contract tests and full manual end-to-end verification were not run (no Postgres/Docker or reachable cloud-api in this environment); noted as unchecked in tasks.md 7.2/7.4.
117 lines
3.6 KiB
Python
117 lines
3.6 KiB
Python
from __future__ import annotations
|
|
|
|
from pathlib import Path
|
|
|
|
import pytest
|
|
|
|
from host_agent.config import (
|
|
HostAgentConfigurationError,
|
|
HostAgentConfig,
|
|
load_host_agent_config,
|
|
)
|
|
|
|
|
|
BASE_ENV = {
|
|
"HOST_AGENT_HOST_ID": "host-a",
|
|
"HOST_AGENT_TOKEN": "secret",
|
|
}
|
|
|
|
|
|
def test_load_host_agent_config_uses_managed_cloud_default() -> None:
|
|
assert load_host_agent_config(BASE_ENV) == HostAgentConfig(
|
|
control_plane_url="https://amcp.home.jerryyan.top",
|
|
host_id="host-a",
|
|
token="secret",
|
|
)
|
|
|
|
|
|
def test_load_host_agent_config_parses_poll_and_retry_values() -> None:
|
|
config = load_host_agent_config(
|
|
{
|
|
**BASE_ENV,
|
|
"HOST_AGENT_CONTROL_PLANE_URL": "https://cloud.example/v1/",
|
|
"HOST_AGENT_HEARTBEAT_INTERVAL_SECONDS": "10",
|
|
"HOST_AGENT_POLL_TIMEOUT_SECONDS": "15",
|
|
"HOST_AGENT_RETRY_BACKOFF_SECONDS": "2",
|
|
"HOST_AGENT_MAX_RETRY_BACKOFF_SECONDS": "20",
|
|
}
|
|
)
|
|
|
|
assert config.control_plane_url == "https://cloud.example/v1"
|
|
assert config.poll_timeout_seconds == 15
|
|
assert config.max_retry_backoff_seconds == 20
|
|
|
|
|
|
def test_load_host_agent_config_supports_managed_enrollment(tmp_path) -> None:
|
|
identity_path = tmp_path / "host_identity.json"
|
|
config = load_host_agent_config(
|
|
{
|
|
"HOST_AGENT_CONTROL_PLANE_URL": "https://cloud.example",
|
|
"HOST_AGENT_ENROLLMENT_TOKEN": "one-time-token",
|
|
"HOST_AGENT_IDENTITY_PATH": str(identity_path),
|
|
"HOST_AGENT_DISPLAY_NAME": "Edge Mac",
|
|
}
|
|
)
|
|
|
|
assert config.host_id == ""
|
|
assert config.token == ""
|
|
assert config.enrollment_token == "one-time-token"
|
|
assert config.identity_path == identity_path
|
|
assert config.enrollment_managed is True
|
|
assert config.display_name == "Edge Mac"
|
|
assert "one-time-token" not in repr(config)
|
|
|
|
|
|
def test_existing_identity_state_allows_restart_without_enrollment_token(
|
|
tmp_path,
|
|
) -> None:
|
|
identity_path = tmp_path / "host_identity.json"
|
|
identity_path.write_text("{}", encoding="utf-8")
|
|
|
|
config = load_host_agent_config({"HOST_AGENT_IDENTITY_PATH": str(identity_path)})
|
|
|
|
assert config.identity_path == Path(identity_path)
|
|
assert config.enrollment_managed is True
|
|
|
|
|
|
def test_fresh_install_with_no_token_is_valid_and_defaults_local_account_path() -> None:
|
|
config = load_host_agent_config({"HOST_AGENT_CONTROL_PLANE_URL": "https://cloud.example"})
|
|
|
|
assert config.host_id == ""
|
|
assert config.enrollment_token == ""
|
|
assert config.enrollment_managed is True
|
|
assert config.local_account_path == Path("tasks/host_local_account.json")
|
|
|
|
|
|
def test_local_account_path_can_be_overridden(tmp_path) -> None:
|
|
account_path = tmp_path / "account.json"
|
|
config = load_host_agent_config(
|
|
{
|
|
"HOST_AGENT_CONTROL_PLANE_URL": "https://cloud.example",
|
|
"HOST_AGENT_LOCAL_ACCOUNT_PATH": str(account_path),
|
|
}
|
|
)
|
|
|
|
assert config.local_account_path == account_path
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
"overrides",
|
|
[
|
|
{"HOST_AGENT_HOST_ID": ""},
|
|
{"HOST_AGENT_TOKEN": ""},
|
|
{"HOST_AGENT_HOST_ID": "host-a", "HOST_AGENT_TOKEN": ""},
|
|
{"HOST_AGENT_CONTROL_PLANE_URL": "ftp://cloud.example"},
|
|
{"HOST_AGENT_POLL_TIMEOUT_SECONDS": "0"},
|
|
{
|
|
"HOST_AGENT_RETRY_BACKOFF_SECONDS": "10",
|
|
"HOST_AGENT_MAX_RETRY_BACKOFF_SECONDS": "5",
|
|
},
|
|
],
|
|
)
|
|
def test_load_host_agent_config_rejects_invalid_values(
|
|
overrides: dict[str, str],
|
|
) -> None:
|
|
with pytest.raises(HostAgentConfigurationError):
|
|
load_host_agent_config({**BASE_ENV, **overrides})
|