feat: add deployment foundation and cross-device handoff
This commit is contained in:
@@ -0,0 +1,70 @@
|
||||
// Package inspect reports local prerequisite observations without executing
|
||||
// commands, connecting to Docker or altering configuration.
|
||||
package inspect
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"io/fs"
|
||||
"os"
|
||||
"runtime"
|
||||
)
|
||||
|
||||
type Report struct {
|
||||
ProtocolVersion int `json:"protocolVersion"`
|
||||
OS string `json:"os"`
|
||||
Architecture string `json:"architecture"`
|
||||
SupportedPlatform bool `json:"supportedPlatform"`
|
||||
SystemdRuntime string `json:"systemdRuntime"`
|
||||
DockerClient string `json:"dockerClient"`
|
||||
DockerDaemon string `json:"dockerDaemon"`
|
||||
Compose string `json:"compose"`
|
||||
Unchecked []string `json:"unchecked"`
|
||||
DeploymentReady bool `json:"deploymentReady"`
|
||||
}
|
||||
|
||||
func Collect() Report { return Probe(runtime.GOOS, runtime.GOARCH, os.DirFS("/")) }
|
||||
|
||||
// Probe observes filesystem metadata only. "present" is not an assertion that
|
||||
// systemd is responsive or the Docker executable is authentic or operational.
|
||||
func Probe(goos, arch string, files fs.FS) Report {
|
||||
r := Report{ProtocolVersion: 1, OS: goos, Architecture: arch, SupportedPlatform: goos == "linux" && (arch == "amd64" || arch == "arm64"), SystemdRuntime: "not_checked", DockerClient: "not_checked", DockerDaemon: "not_checked", Compose: "not_checked", Unchecked: []string{"docker_daemon", "compose_version", "host_identity", "distribution_support", "permissions", "disk_space", "ports", "dns", "firewall", "gateway"}}
|
||||
if goos != "linux" {
|
||||
return r
|
||||
}
|
||||
r.SystemdRuntime = observe(files, "run/systemd/system", true)
|
||||
r.DockerClient = observe(files, "usr/bin/docker", false)
|
||||
if r.DockerClient != "present" {
|
||||
alternate := observe(files, "usr/local/bin/docker", false)
|
||||
// Either known executable establishes presence. Otherwise retain any
|
||||
// uncertainty instead of reporting absence from an incomplete check.
|
||||
switch {
|
||||
case alternate == "present":
|
||||
r.DockerClient = "present"
|
||||
case r.DockerClient == "unknown" || alternate == "unknown":
|
||||
r.DockerClient = "unknown"
|
||||
case r.DockerClient == "invalid" || alternate == "invalid":
|
||||
r.DockerClient = "invalid"
|
||||
}
|
||||
}
|
||||
return r
|
||||
}
|
||||
|
||||
func observe(files fs.FS, path string, directory bool) string {
|
||||
info, err := fs.Stat(files, path)
|
||||
if errors.Is(err, fs.ErrNotExist) {
|
||||
return "missing"
|
||||
}
|
||||
if err != nil {
|
||||
return "unknown"
|
||||
}
|
||||
if directory {
|
||||
if info.IsDir() {
|
||||
return "present"
|
||||
}
|
||||
return "invalid"
|
||||
}
|
||||
if !info.Mode().IsRegular() || info.Mode().Perm()&0111 == 0 {
|
||||
return "invalid"
|
||||
}
|
||||
return "present"
|
||||
}
|
||||
@@ -0,0 +1,110 @@
|
||||
package inspect
|
||||
|
||||
import (
|
||||
"io/fs"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"testing"
|
||||
|
||||
"testing/fstest"
|
||||
)
|
||||
|
||||
func TestReportsFactsWithoutClaimingDeploymentReadiness(t *testing.T) {
|
||||
files := fstest.MapFS{
|
||||
"run/systemd/system": &fstest.MapFile{Mode: os.ModeDir | 0755},
|
||||
"usr/bin/docker": &fstest.MapFile{Mode: 0755, Data: []byte("not executed")},
|
||||
}
|
||||
r := Probe("linux", "amd64", files)
|
||||
if !r.SupportedPlatform || r.SystemdRuntime != "present" || r.DockerClient != "present" || r.DeploymentReady {
|
||||
t.Fatalf("incorrect report: %+v", r)
|
||||
}
|
||||
if r.DockerDaemon != "not_checked" || r.Compose != "not_checked" {
|
||||
t.Fatal("claimed unperformed checks")
|
||||
}
|
||||
}
|
||||
|
||||
func TestMissingAndUnsupportedEnvironment(t *testing.T) {
|
||||
r := Probe("linux", "amd64", fstest.MapFS{})
|
||||
if r.DockerClient != "missing" || r.SystemdRuntime != "missing" {
|
||||
t.Fatalf("missing prerequisites masked: %+v", r)
|
||||
}
|
||||
r = Probe("windows", "amd64", fstest.MapFS{})
|
||||
if r.SupportedPlatform || r.DeploymentReady || r.DockerClient != "not_checked" {
|
||||
t.Fatal("Windows accepted as deployment target")
|
||||
}
|
||||
r = Probe("linux", "386", fstest.MapFS{})
|
||||
if r.SupportedPlatform {
|
||||
t.Fatal("unsupported architecture accepted")
|
||||
}
|
||||
}
|
||||
|
||||
func TestWrongFileKindsAndPermissions(t *testing.T) {
|
||||
r := Probe("linux", "amd64", fstest.MapFS{
|
||||
"run/systemd/system": &fstest.MapFile{Mode: 0644},
|
||||
"usr/bin/docker": &fstest.MapFile{Mode: 0644},
|
||||
})
|
||||
if r.SystemdRuntime != "invalid" || r.DockerClient != "invalid" {
|
||||
t.Fatalf("wrong file kinds accepted: %+v", r)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRealDirectoryProbeDoesNotWrite(t *testing.T) {
|
||||
dir := t.TempDir()
|
||||
if err := os.MkdirAll(filepath.Join(dir, "run/systemd/system"), 0700); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
r := Probe("linux", "arm64", os.DirFS(dir))
|
||||
if r.SystemdRuntime != "present" || r.DockerClient != "missing" {
|
||||
t.Fatalf("bad real probe: %+v", r)
|
||||
}
|
||||
items, err := os.ReadDir(dir)
|
||||
if err != nil || len(items) != 1 || items[0].Name() != "run" {
|
||||
t.Fatal("probe changed filesystem")
|
||||
}
|
||||
}
|
||||
|
||||
type deniedFS struct{}
|
||||
|
||||
func (deniedFS) Open(string) (fs.File, error) { return nil, fs.ErrPermission }
|
||||
|
||||
func TestPermissionErrorsAreUnknownNotMissing(t *testing.T) {
|
||||
r := Probe("linux", "amd64", deniedFS{})
|
||||
if r.DockerClient != "unknown" || r.SystemdRuntime != "unknown" {
|
||||
t.Fatalf("hid inspection failure: %+v", r)
|
||||
}
|
||||
}
|
||||
|
||||
func TestDockerAlternatePath(t *testing.T) {
|
||||
r := Probe("linux", "amd64", fstest.MapFS{"usr/local/bin/docker": &fstest.MapFile{Mode: 0755}})
|
||||
if r.DockerClient != "present" {
|
||||
t.Fatal("alternate installation not found")
|
||||
}
|
||||
}
|
||||
|
||||
type pathDeniedFS struct{ fs.FS }
|
||||
|
||||
func (f pathDeniedFS) Open(name string) (fs.File, error) {
|
||||
if name == "usr/bin/docker" {
|
||||
return nil, fs.ErrPermission
|
||||
}
|
||||
return f.FS.Open(name)
|
||||
}
|
||||
|
||||
func TestAlternateDockerAfterInvalidOrUnknownPrimary(t *testing.T) {
|
||||
for _, mode := range []fs.FileMode{0644, fs.ModeDir | 0755} {
|
||||
files := fstest.MapFS{
|
||||
"usr/bin/docker": &fstest.MapFile{Mode: mode},
|
||||
"usr/local/bin/docker": &fstest.MapFile{Mode: 0755},
|
||||
}
|
||||
if r := Probe("linux", "amd64", files); r.DockerClient != "present" {
|
||||
t.Errorf("valid alternate overlooked after invalid primary: %+v", r)
|
||||
}
|
||||
}
|
||||
files := pathDeniedFS{fstest.MapFS{"usr/local/bin/docker": &fstest.MapFile{Mode: 0755}}}
|
||||
if r := Probe("linux", "amd64", files); r.DockerClient != "present" {
|
||||
t.Errorf("valid alternate overlooked after inaccessible primary: %+v", r)
|
||||
}
|
||||
if r := Probe("linux", "amd64", pathDeniedFS{fstest.MapFS{}}); r.DockerClient != "unknown" {
|
||||
t.Errorf("missing alternate masked inaccessible primary: %+v", r)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user