7fc3b3ce76531995f0978618fbb5c5e1fccf31cf braney Sun Sep 20 06:58:05 2026 -0700 hgcentralregress: a central database that tests may write to Every hgcentral a developer can reach is shared. hgcentraltest holds thousands of rows of other people's sandbox sessions, and the production centrals are not reachable from hgwdev at all, so a test that needs to create a session, a login or an api key has had nowhere to put it. Every test written for #38391 so far only reads, and that is the limit this lifts. makeHgCentralRegress.sh creates the database and its tables, copying each schema from the central the caller's hg.conf already names, so a column added to namedSessionDb reaches it on the next run and there is no second copy of the schema in the tree to forget. It is idempotent and meant to run before a test. ONE GRANT IS STILL MISSING and no test uses the database yet. The account the browser uses for the central has global SELECT, INSERT, CREATE and DROP, but UPDATE and DELETE only on databases it has been granted them on individually. So a test can create rows here and cannot take them down: the delete comes back 1142. The script says what to ask for. Measured rather than assumed, and one guess along the way was wrong: the hgcentraltest prefix carries no wildcard grant, hgcentraltestregress behaves the same as any other new name. hubSpaceKeysTester is written against it and is deliberately NOT in the test target, so nothing here goes red while it waits. It covers the rules an api key lives by -- one key per user, a new key revokes the old, an adopted key from a peer mirror replaces both, a revoked key names nobody -- and the signature a peer checks before accepting a sync. refs #38323. refs #38391 diff --git src/hg/lib/tests/makefile src/hg/lib/tests/makefile index d483b851afb..52fea0e97e0 100644 --- src/hg/lib/tests/makefile +++ src/hg/lib/tests/makefile @@ -130,21 +130,37 @@ sessionDirTest: mkdirs ${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/sessionDirTester sessionDirTester.c ${MYLIBS} $L ${BIN_DIR}/sessionDirTester > output/sessionDirTest diff expected/sessionDirTest output/sessionDirTest # browser.node is set in the conf rather than assumed, since a developer's own hg.conf need # not have one. geoMirrorSelfTest: mkdirs ${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/geoMirrorSelfTester geoMirrorSelfTester.c ${MYLIBS} $L echo "include ${HOME}/.hg.conf" > output/geoNode.conf echo "browser.node=1" >> output/geoNode.conf HGDB_CONF=output/geoNode.conf ${BIN_DIR}/geoMirrorSelfTester > output/geoMirrorSelfTest diff expected/geoMirrorSelfTest output/geoMirrorSelfTest +# NOT in the test target above, and waiting on one grant. This is the one test here that +# WRITES to a central database, so it is pointed at hgcentralregress, +# which exists for tests and which nothing else reads. makeHgCentralRegress.sh creates it and +# is safe to run every time. login.cookieSalt is set because the sync signature is made with +# it; the value is a test value and means nothing outside this run. +hubSpaceKeysTest: mkdirs + ${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/hubSpaceKeysTester hubSpaceKeysTester.c ${MYLIBS} $L + ./makeHgCentralRegress.sh > /dev/null + echo "include ${HOME}/.hg.conf" > output/regress.conf + echo "central.db=hgcentralregress" >> output/regress.conf + echo "login.cookieSalt=testSaltForRegressRuns" >> output/regress.conf + HGDB_CONF=output/regress.conf ${BIN_DIR}/hubSpaceKeysTester > output/hubSpaceKeysTest + diff expected/hubSpaceKeysTest output/hubSpaceKeysTest +# It runs as soon as central.user has UPDATE and DELETE on hgcentralregress; see +# makeHgCentralRegress.sh for the grant. Add it to the test target on that day. + sqlCheck: ${BIN_DIR}/sqlCheck mkdirs ${MAKE} -f sqlCheck.mk test BIN_DIR=${BIN_DIR} OUT_DIR=output clean: rm -rf *.o bin output *.tmp loader udcCache