mirror of
https://github.com/juanfont/headscale.git
synced 2026-10-10 16:50:07 +09:00
integration: avoid toolchain work and login waits in CI
This commit is contained in:
@@ -938,6 +938,9 @@ func TestOIDCFollowUpUrl(t *testing.T) {
|
||||
_, err = doLoginURL(ts.Hostname(), newUrl)
|
||||
require.NoError(t, err)
|
||||
|
||||
err = ts.WaitForRunning(integrationutil.PeerSyncTimeout())
|
||||
require.NoError(t, err)
|
||||
|
||||
listUsers, err = headscale.ListUsers()
|
||||
require.NoError(t, err)
|
||||
assert.Len(t, listUsers, 1)
|
||||
|
||||
@@ -0,0 +1,171 @@
|
||||
package tsic
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"io"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/juanfont/headscale/hscontrol/util"
|
||||
"github.com/juanfont/headscale/integration/dockertestutil"
|
||||
"github.com/ory/dockertest/v3"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
// Simulate Docker's streamed output without requiring Docker or a shell.
|
||||
func TestLoginReturnsURLBeforeCLIExit(t *testing.T) {
|
||||
const wantURL = "https://headscale.test/register/complete-token"
|
||||
|
||||
for _, stream := range []string{"stdout", "stderr"} {
|
||||
t.Run(stream, func(t *testing.T) {
|
||||
partialWritten := make(chan struct{})
|
||||
completeURL := make(chan struct{})
|
||||
authenticate := make(chan struct{})
|
||||
|
||||
t.Cleanup(func() { close(authenticate) })
|
||||
|
||||
login := startLogin([]string{"tailscale", "up"}, func(_ []string, opts dockertest.ExecOptions) (int, error) {
|
||||
output := opts.StdErr
|
||||
if stream == "stdout" {
|
||||
output = opts.StdOut
|
||||
}
|
||||
|
||||
_, _ = io.WriteString(output, "To authenticate, visit:\n\thttps://headscale.test/reg")
|
||||
|
||||
close(partialWritten)
|
||||
<-completeURL
|
||||
|
||||
_, _ = io.WriteString(output, "ister/complete-token\n\n")
|
||||
|
||||
<-authenticate
|
||||
// A later URL must not block output draining or replace the first.
|
||||
_, _ = io.WriteString(output, "https://headscale.test/register/another-token\nSuccess.\n")
|
||||
|
||||
return 0, nil
|
||||
})
|
||||
|
||||
<-partialWritten
|
||||
|
||||
select {
|
||||
case u := <-login.url:
|
||||
t.Fatalf("returned incomplete URL: %s", u)
|
||||
default:
|
||||
}
|
||||
|
||||
close(completeURL)
|
||||
|
||||
u, err := login.waitForURL(time.Second)
|
||||
require.NoError(t, err)
|
||||
require.Equal(t, wantURL, u.String())
|
||||
|
||||
select {
|
||||
case <-login.done:
|
||||
t.Fatal("CLI exited before authentication")
|
||||
default:
|
||||
}
|
||||
|
||||
// Permit natural completion and verify its exit status is retained.
|
||||
authenticate <- struct{}{}
|
||||
|
||||
select {
|
||||
case <-login.done:
|
||||
require.NoError(t, login.err)
|
||||
assert.Contains(t, login.output.String(), "Success.")
|
||||
case <-time.After(time.Second):
|
||||
t.Fatal("CLI did not complete after authentication")
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestLoginCommandFailure(t *testing.T) {
|
||||
execErr := io.ErrClosedPipe
|
||||
|
||||
for _, tt := range []struct {
|
||||
name string
|
||||
output string
|
||||
exitCode int
|
||||
err error
|
||||
wantErr error
|
||||
}{
|
||||
{name: "exec error", err: execErr, wantErr: execErr},
|
||||
{name: "CLI failure", output: "invalid login option", exitCode: 7, wantErr: dockertestutil.ErrDockertestCommandFailed},
|
||||
{name: "no URL", output: "Success.\n", wantErr: util.ErrNoURLFound},
|
||||
{name: "incomplete URL", output: "https://headscale.test/register/incomplete", wantErr: util.ErrNoURLFound},
|
||||
} {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
login := startLogin(nil, func(_ []string, opts dockertest.ExecOptions) (int, error) {
|
||||
_, _ = io.WriteString(opts.StdErr, tt.output)
|
||||
return tt.exitCode, tt.err
|
||||
})
|
||||
_, err := login.waitForURL(time.Second)
|
||||
require.ErrorIs(t, err, tt.wantErr)
|
||||
assert.Contains(t, err.Error(), tt.output)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestLoginFailureAfterURL(t *testing.T) {
|
||||
finish := make(chan struct{})
|
||||
|
||||
t.Cleanup(func() { close(finish) })
|
||||
|
||||
login := startLogin(nil, func(_ []string, opts dockertest.ExecOptions) (int, error) {
|
||||
_, _ = io.WriteString(opts.StdErr, "https://headscale.test/register/token\n")
|
||||
|
||||
<-finish
|
||||
|
||||
_, _ = io.WriteString(opts.StdErr, "authentication rejected\n")
|
||||
|
||||
return 1, nil
|
||||
})
|
||||
|
||||
_, err := login.waitForURL(time.Second)
|
||||
require.NoError(t, err)
|
||||
|
||||
client := &TailscaleInContainer{hostname: "client", login: login}
|
||||
// A URL alone is not a completed login. The caller's wait stays bounded.
|
||||
require.ErrorIs(t, client.WaitForRunning(0), context.DeadlineExceeded)
|
||||
|
||||
finish <- struct{}{}
|
||||
|
||||
select {
|
||||
case <-login.done:
|
||||
for range 2 {
|
||||
// All observers must see the failure, not just the first channel reader.
|
||||
err = client.WaitForRunning(time.Second)
|
||||
require.ErrorIs(t, err, dockertestutil.ErrDockertestCommandFailed)
|
||||
assert.Contains(t, err.Error(), "authentication rejected")
|
||||
}
|
||||
case <-time.After(time.Second):
|
||||
t.Fatal("CLI did not finish")
|
||||
}
|
||||
}
|
||||
|
||||
func TestLoginURLDeadlineDoesNotStopCLI(t *testing.T) {
|
||||
finish := make(chan struct{})
|
||||
|
||||
t.Cleanup(func() { close(finish) })
|
||||
|
||||
login := startLogin(nil, func(_ []string, opts dockertest.ExecOptions) (int, error) {
|
||||
<-finish
|
||||
|
||||
_, _ = fmt.Fprintln(opts.StdErr, "https://headscale.test/register/token")
|
||||
|
||||
return 0, nil
|
||||
})
|
||||
|
||||
_, err := login.waitForURL(0)
|
||||
require.ErrorIs(t, err, dockertestutil.ErrDockertestCommandTimeout)
|
||||
|
||||
finish <- struct{}{}
|
||||
|
||||
select {
|
||||
case <-login.done:
|
||||
require.NoError(t, login.err)
|
||||
case <-time.After(time.Second):
|
||||
t.Fatal("CLI did not finish after URL deadline")
|
||||
}
|
||||
}
|
||||
+116
-26
@@ -17,6 +17,7 @@ import (
|
||||
"slices"
|
||||
"strconv"
|
||||
"strings"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/cenkalti/backoff/v5"
|
||||
@@ -44,7 +45,9 @@ const (
|
||||
dockerContextPath = "../."
|
||||
caCertRoot = "/usr/local/share/ca-certificates"
|
||||
dockerExecuteTimeout = 60 * time.Second
|
||||
tailscaleBin = "tailscale"
|
||||
// Some OIDC tests deliberately delay authentication for two minutes.
|
||||
loginTimeout = 5 * time.Minute
|
||||
tailscaleBin = "tailscale"
|
||||
)
|
||||
|
||||
// defaultPingTimeoutVal returns the per-attempt timeout for tailscale ping.
|
||||
@@ -59,17 +62,16 @@ func defaultPingTimeoutVal() time.Duration {
|
||||
}
|
||||
|
||||
var (
|
||||
errTailscalePingFailed = errors.New("ping failed")
|
||||
errTailscalePingNotDERP = errors.New("ping not via DERP")
|
||||
errTailscaleNotLoggedIn = errors.New("tailscale not logged in")
|
||||
errTailscaleWrongPeerCount = errors.New("wrong peer count")
|
||||
errTailscaleCannotUpWithoutAuthkey = errors.New("cannot up without authkey")
|
||||
errInvalidClientConfig = errors.New("verifiably invalid client config requested")
|
||||
errInvalidTailscaleImageFormat = errors.New("invalid HEADSCALE_INTEGRATION_TAILSCALE_IMAGE format, expected repository:tag")
|
||||
errTailscaleImageRequiredInCI = errors.New("HEADSCALE_INTEGRATION_TAILSCALE_IMAGE must be set in CI for HEAD version")
|
||||
errContainerNotInitialized = errors.New("container not initialized")
|
||||
errFQDNNotYetAvailable = errors.New("FQDN not yet available")
|
||||
errCurlEmptyResponseBody = errors.New("curl returned empty response body")
|
||||
errTailscalePingFailed = errors.New("ping failed")
|
||||
errTailscalePingNotDERP = errors.New("ping not via DERP")
|
||||
errTailscaleNotLoggedIn = errors.New("tailscale not logged in")
|
||||
errTailscaleWrongPeerCount = errors.New("wrong peer count")
|
||||
errInvalidClientConfig = errors.New("verifiably invalid client config requested")
|
||||
errInvalidTailscaleImageFormat = errors.New("invalid HEADSCALE_INTEGRATION_TAILSCALE_IMAGE format, expected repository:tag")
|
||||
errTailscaleImageRequiredInCI = errors.New("HEADSCALE_INTEGRATION_TAILSCALE_IMAGE must be set in CI for HEAD version")
|
||||
errContainerNotInitialized = errors.New("container not initialized")
|
||||
errFQDNNotYetAvailable = errors.New("FQDN not yet available")
|
||||
errCurlEmptyResponseBody = errors.New("curl returned empty response body")
|
||||
)
|
||||
|
||||
const (
|
||||
@@ -94,6 +96,10 @@ type TailscaleInContainer struct {
|
||||
ips []netip.Addr
|
||||
fqdn string
|
||||
|
||||
// Only the current attempt is checked: earlier logins may be deliberately
|
||||
// abandoned or rejected before the test starts another one.
|
||||
login *loginAttempt
|
||||
|
||||
// optional config
|
||||
caCerts [][]byte
|
||||
headscaleHostname string
|
||||
@@ -718,6 +724,7 @@ func (t *TailscaleInContainer) buildLoginCommand(
|
||||
func (t *TailscaleInContainer) Login(
|
||||
loginServer, authKey string,
|
||||
) error {
|
||||
t.login = nil
|
||||
command := t.buildLoginCommand(loginServer, authKey)
|
||||
|
||||
if _, _, err := t.Execute(command, dockertestutil.ExecuteCommandTimeout(dockerExecuteTimeout)); err != nil { //nolint:noinlineerr
|
||||
@@ -732,34 +739,106 @@ func (t *TailscaleInContainer) Login(
|
||||
return nil
|
||||
}
|
||||
|
||||
// loginAttempt streams the first complete URL line while retaining all output.
|
||||
// done closes only after Docker exec returns; err can then be read repeatedly.
|
||||
type loginAttempt struct {
|
||||
mu sync.Mutex
|
||||
output bytes.Buffer
|
||||
lineStart int
|
||||
foundURL bool
|
||||
url chan *url.URL
|
||||
done chan struct{}
|
||||
err error
|
||||
}
|
||||
|
||||
func (l *loginAttempt) Write(p []byte) (int, error) {
|
||||
l.mu.Lock()
|
||||
defer l.mu.Unlock()
|
||||
|
||||
n, _ := l.output.Write(p)
|
||||
|
||||
for !l.foundURL {
|
||||
line, _, complete := bytes.Cut(l.output.Bytes()[l.lineStart:], []byte{'\n'})
|
||||
if !complete {
|
||||
break
|
||||
}
|
||||
|
||||
l.lineStart += len(line) + 1
|
||||
|
||||
u, err := util.ParseLoginURLFromCLILogin(string(line))
|
||||
if err == nil {
|
||||
l.foundURL = true
|
||||
l.url <- u
|
||||
}
|
||||
}
|
||||
|
||||
return n, nil
|
||||
}
|
||||
|
||||
func startLogin(
|
||||
command []string,
|
||||
exec func([]string, dockertest.ExecOptions) (int, error),
|
||||
) *loginAttempt {
|
||||
l := &loginAttempt{url: make(chan *url.URL, 1), done: make(chan struct{})}
|
||||
|
||||
go func() {
|
||||
defer close(l.done)
|
||||
|
||||
exitCode, err := exec(command, dockertest.ExecOptions{StdOut: l, StdErr: l})
|
||||
log.Printf("%v finished (exit %d): %s", command, exitCode, l.output.String())
|
||||
|
||||
switch {
|
||||
case err != nil:
|
||||
l.err = fmt.Errorf("tailscale up: %s: %w", l.output.String(), err)
|
||||
case exitCode != 0:
|
||||
l.err = fmt.Errorf("tailscale up exited %d: %s: %w", exitCode, l.output.String(), dockertestutil.ErrDockertestCommandFailed)
|
||||
case !l.foundURL:
|
||||
l.err = fmt.Errorf("tailscale up: %s: %w", l.output.String(), util.ErrNoURLFound)
|
||||
}
|
||||
}()
|
||||
|
||||
return l
|
||||
}
|
||||
|
||||
func (l *loginAttempt) waitForURL(timeout time.Duration) (*url.URL, error) {
|
||||
select {
|
||||
case u := <-l.url:
|
||||
return u, nil
|
||||
case <-l.done:
|
||||
if l.err != nil {
|
||||
return nil, l.err
|
||||
}
|
||||
|
||||
return <-l.url, nil
|
||||
case <-time.After(timeout):
|
||||
return nil, dockertestutil.ErrDockertestCommandTimeout
|
||||
}
|
||||
}
|
||||
|
||||
// LoginWithURL runs the login routine on the given Tailscale instance.
|
||||
// This login mechanism uses web + command line flow for authentication.
|
||||
func (t *TailscaleInContainer) LoginWithURL(
|
||||
loginServer string,
|
||||
) (*url.URL, error) {
|
||||
command := t.buildLoginCommand(loginServer, "")
|
||||
command = append(command, "--timeout="+loginTimeout.String())
|
||||
|
||||
stdout, stderr, err := t.Execute(command)
|
||||
if errors.Is(err, errTailscaleNotLoggedIn) {
|
||||
return nil, errTailscaleCannotUpWithoutAuthkey
|
||||
}
|
||||
// Return the URL promptly, but let the CLI finish authentication normally.
|
||||
// Its own timeout bounds abandoned logins; WaitForRunning checks its exit.
|
||||
t.login = startLogin(command, t.container.Exec)
|
||||
|
||||
defer func() {
|
||||
if err != nil {
|
||||
log.Printf("join command: %q", strings.Join(command, " "))
|
||||
}
|
||||
}()
|
||||
|
||||
loginURL, err := util.ParseLoginURLFromCLILogin(stdout + stderr)
|
||||
u, err := t.login.waitForURL(dockerExecuteTimeout)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
return nil, fmt.Errorf("%s fetching login URL: %w", t.hostname, err)
|
||||
}
|
||||
|
||||
return loginURL, nil
|
||||
return u, nil
|
||||
}
|
||||
|
||||
// Logout runs the logout routine on the given Tailscale instance.
|
||||
func (t *TailscaleInContainer) Logout() error {
|
||||
t.login = nil
|
||||
|
||||
_, _, err := t.Execute([]string{tailscaleBin, "logout"})
|
||||
if err != nil {
|
||||
return err
|
||||
@@ -1268,7 +1347,7 @@ func (t *TailscaleInContainer) WaitForNeedsLogin(timeout time.Duration) error {
|
||||
}
|
||||
|
||||
// WaitForRunning blocks until the Tailscale (tailscaled) instance is logged in
|
||||
// and ready to be used.
|
||||
// and ready to be used, and the current web login command has exited successfully.
|
||||
func (t *TailscaleInContainer) WaitForRunning(timeout time.Duration) error {
|
||||
return t.waitForBackendState("Running", timeout)
|
||||
}
|
||||
@@ -1280,6 +1359,17 @@ func (t *TailscaleInContainer) waitForBackendState(state string, timeout time.Du
|
||||
ctx, cancel := context.WithTimeout(context.Background(), timeout)
|
||||
defer cancel()
|
||||
|
||||
if state == "Running" && t.login != nil {
|
||||
select {
|
||||
case <-t.login.done:
|
||||
if t.login.err != nil {
|
||||
return fmt.Errorf("%s login failed: %w", t.hostname, t.login.err)
|
||||
}
|
||||
case <-ctx.Done():
|
||||
return fmt.Errorf("%s waiting for login command: %w", t.hostname, ctx.Err())
|
||||
}
|
||||
}
|
||||
|
||||
for {
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
|
||||
Reference in New Issue
Block a user