fix: retain DWH key output on ambiguous publication

This commit is contained in:
User
2026-08-21 01:29:04 +02:00
parent 055dcabf36
commit b1079bda21
2 changed files with 54 additions and 5 deletions
@@ -359,6 +359,47 @@ func TestCreateCleansOnlyWhenFailedPublicationProvesKeyAbsent(t *testing.T) {
}
}
func TestCreateRetainsOutputWhenSnapshotFindsUnrelatedIntegrityFailure(t *testing.T) {
root := t.TempDir()
output := filepath.Join(t.TempDir(), "corrupt-registry")
addRecord = func(*registry.Store, record.Record) error {
if err := os.WriteFile(filepath.Join(root, "active", "unexpected"), []byte(sentinelSecret), 0o600); err != nil {
t.Fatalf("WriteFile(corrupt entry) error = %v", err)
}
return errors.New("synthetic add failure")
}
t.Cleanup(func() { addRecord = func(store *registry.Store, value record.Record) error { return store.Add(value) } })
stdout, stderr, code := run(t, "--registry-root", root, "key", "create", "--installation-id", "corrupt-client", "--output", output)
if code != 4 || stdout != "" || !strings.Contains(stderr, "publication uncertain path=") || strings.Contains(stderr, sentinelSecret) {
t.Fatalf("corrupt snapshot result = (%d, %q, %q)", code, stdout, stderr)
}
if _, err := os.Stat(output); err != nil {
t.Fatalf("corrupt snapshot output stat error = %v, want retained: %v", err, err)
}
}
func TestCreateRetainsOutputWhenFailedPublicationRecordIsExpired(t *testing.T) {
oldNow := nowUTC
nowUTC = func() time.Time { return time.Date(2020, 1, 1, 0, 0, 0, 0, time.UTC) }
t.Cleanup(func() { nowUTC = oldNow })
root := t.TempDir()
output := filepath.Join(t.TempDir(), "expired-record")
addRecord = func(store *registry.Store, value record.Record) error {
if err := store.Add(value); err != nil {
return err
}
return errors.New("synthetic expired post-publication failure")
}
t.Cleanup(func() { addRecord = func(store *registry.Store, value record.Record) error { return store.Add(value) } })
stdout, stderr, code := run(t, "--registry-root", root, "key", "create", "--installation-id", "expired-client", "--expires-at", "2020-01-01T00:00:01Z", "--output", output)
if code != 4 || stdout != "" || !strings.Contains(stderr, "publication uncertain path=") {
t.Fatalf("expired publication result = (%d, %q, %q)", code, stdout, stderr)
}
if _, err := os.Stat(output); err != nil {
t.Fatalf("expired publication output stat error = %v, want retained: %v", err, err)
}
}
func run(t *testing.T, args ...string) (string, string, int) {
t.Helper()
var stdout, stderr bytes.Buffer