mirror of
https://tangled.org/evan.jarrett.net/at-container-registry
synced 2026-09-29 05:25:35 +00:00
remove the runtime test_mode switch; the testmode build tag is the only one
server.test_mode survived the build-tag refactor only to feed five behavioral branches: the registry's fall-back to the default hold when the user's hold is unreachable, backfill warning suppression for external holds, the appview listener close on shutdown, the hold's relay-crawl skip, and the hold's appview-issuer tolerance. Every one of them is a "this is a local development build" decision, which is what the tag already says, and local development has to build with the tag or nothing resolves. So they read atproto.TestModeBuild now, and the flag, SetTestMode, IsTestMode, the middleware option, the backfill constructor parameter, the never-read field on RemoteHoldAuthorizer, the example and template YAML lines, and the docker-compose env vars are gone. The registry keeps the fallback as a field seeded from the constant so the production-path tests can pin it off under the tag. The 24 SetTestMode calls in tests were dead already: stripping them and running the affected packages tagged changed nothing. Tests that resolve a loopback did:web used to t.Fatal naming the tag, which left a bare `go test ./...` permanently red in five packages. They now live under `//go:build testmode`: whole-file constraints where every test needs it, and sibling *_testmode_test.go files holding the moved tests plus their fixtures where a file mixed. The harness carries the constraint too, with its package doc in an untagged doc.go so the package still exists without it. An untagged run compiles those tests out and passes; make test keeps the tag and runs everything. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UwYzaG3Yy7uA8FbZ5qk3tQ
This commit is contained in:
co-authored by
Claude Fable 5.1
parent
d8643ee03a
commit
0080957a21
@@ -185,7 +185,6 @@ shorthand):
|
||||
| `ATCR_AUTH_CERT_PATH` | `auth.cert_path` |
|
||||
| `ATCR_JETSTREAM_BACKFILL_ENABLED` | `jetstream.backfill_enabled` |
|
||||
| `ATCR_LABELER_DID` | `labeler.did` |
|
||||
| `ATCR_SERVER_TEST_MODE` | `server.test_mode` |
|
||||
| `ATCR_LOG_LEVEL` | `log.level` |
|
||||
|
||||
There is **no** `ATCR_DEV_MODE` variable anywhere in the codebase. Likewise
|
||||
|
||||
@@ -125,9 +125,10 @@ forged crew records placing a fake hold in targeted users' member lists. It does
|
||||
defend against a malicious actor running a real hold service — that is inherent to open
|
||||
federation, same as any open-registration hold.
|
||||
|
||||
In test mode (`SetTestMode(true)`), local `did:web` identifiers that the indigo
|
||||
directory cannot resolve (HTTP, IP:port) are trusted, matching the
|
||||
`ResolveHoldDIDToURL` fallback.
|
||||
In a `-tags testmode` build, local `did:web` identifiers (HTTP, IP:port,
|
||||
localhost) resolve through the directory wrapper in `pkg/atproto/indigo_local.go`,
|
||||
so the same verification applies to them. A production build cannot resolve
|
||||
them at all.
|
||||
|
||||
## Data Model
|
||||
|
||||
|
||||
+3
-1
@@ -278,9 +278,11 @@ log_level: debug
|
||||
server:
|
||||
managed_holds:
|
||||
- "did:web:127.0.0.1:8080"
|
||||
test_mode: true # allows HTTP for DID resolution
|
||||
```
|
||||
|
||||
Resolving the loopback `did:web` above needs a `-tags testmode` build; see
|
||||
[DEVELOPMENT.md](DEVELOPMENT.md).
|
||||
|
||||
Run a hold service locally with Minio for S3-compatible storage. See [hold.md](hold.md) for hold setup.
|
||||
|
||||
## Web Interface
|
||||
|
||||
+1
-1
@@ -150,7 +150,7 @@ recover from it, and a proposed automatic fix that is **not implemented**.
|
||||
**1. The hold announces itself once, at boot.**
|
||||
|
||||
`ServeWithListener` fires a single `requestCrawls()` goroutine during startup
|
||||
(`pkg/hold/server.go:400`), skipped entirely when `server.test_mode` is set because local
|
||||
(`pkg/hold/server.go:400`), skipped entirely in a `-tags testmode` build because local
|
||||
dev holds are not reachable by public relays. The implementation
|
||||
(`pkg/hold/server.go:448-483`) builds a deduplicated target list from
|
||||
`atproto.KnownRelays` (`pkg/atproto/relays.go:22`, the hardcoded list also documented in
|
||||
|
||||
Reference in New Issue
Block a user