diff --git a/drill/doctor.sh b/drill/doctor.sh index ee20e23..718c777 100755 --- a/drill/doctor.sh +++ b/drill/doctor.sh @@ -212,23 +212,17 @@ if [ -n "$probe" ] && [ "$FIX" != 1 ]; then inf "probing inside '$probe' — this separates DNS from routing, which is the whole question:" inf "its resolv.conf: $(timeout -k 5 20 incus exec "$probe" -- sh -c 'grep -m2 nameserver /etc/resolv.conf' /dev/null | tr '\n' ' ')" - # Routing is probed by ADDRESS against the public internet, NOT by pinging - # the gateway: claudebox-firewall.sh drops everything from a box to the host - # except DNS/DHCP, so ICMP to 10.87.0.1 fails BY DESIGN on a healthy host. - # A gateway ping here is a check that can only ever lie. - if timeout -k 5 25 incus exec "$probe" -- curl -sS -m 10 -o /dev/null https://1.1.1.1 /dev/null; then - routing=1; ok "reaches 1.1.1.1 by address — egress routing is fine" - else - routing=0; no "cannot reach 1.1.1.1 by address — egress routing is broken (this is not DNS)" - fi + timeout -k 5 20 incus exec "$probe" -- ping -c1 -W2 10.87.0.1 /dev/null 2>&1 \ + && ok "reaches the gateway (10.87.0.1) — routing is fine" \ + || no "cannot even reach the gateway — this is routing, not DNS" if timeout -k 5 25 incus exec "$probe" -- getent hosts deb.debian.org /dev/null 2>&1; then ok "resolves deb.debian.org — DNS works" else no "CANNOT resolve deb.debian.org — this is exactly what kills cloud-init on every cold mint" - # Egress by address was probed above. If it worked, the fault is purely - # name resolution — i.e. the forwarder, i.e. issue #33. - if [ "$routing" = 1 ]; then + # Does the box reach the internet at all WITHOUT DNS? If yes, the fault is + # purely name resolution — i.e. the forwarder, i.e. issue #33. + if timeout -k 5 25 incus exec "$probe" -- curl -sS -m 10 -o /dev/null https://1.1.1.1 /dev/null; then inf "…but it CAN reach 1.1.1.1 by address. So egress works and only NAME RESOLUTION is broken:" inf "the fault is the forwarder the box inherits from the host — issue #33." inf "test the fix: bash drill/doctor.sh --pin-dns then re-run the drill" diff --git a/drill/drill.sh b/drill/drill.sh index 4c5e07f..6b1f000 100755 --- a/drill/drill.sh +++ b/drill/drill.sh @@ -348,8 +348,17 @@ expected="$(cat "$HOME/.local/share/claudebox/VERSION" 2>/dev/null || echo '?')" v="$(claudebox --version 2>&1)" case "$v" in *"$expected"*) ok "claudebox --version → $v" ;; *) no "version mismatch: CLI says '$v', VERSION file says '$expected'" ;; esac -claudebox list >/dev/null 2>&1 && claudebox list 2>&1 | grep -q 'no boxes yet' \ - && ok "empty host: 'no boxes yet', exit 0" || no "empty-host message wrong" +# The drill must not require an empty host: operator boxes tagged +# user.claudebox=1 are legitimate tenants, and the teardown below deliberately +# refuses to touch them. The empty-host message is only TESTABLE when the host +# is actually empty — on a shared host, skip it instead of failing it. +tenants="$(incus list user.claudebox=1 --format csv --columns n 2>/dev/null | tr '\n' ' ')" +if [ -n "${tenants% }" ]; then + inf "host already has claudebox boxes (${tenants% }) — the empty-host message cannot be tested this run" +else + claudebox list >/dev/null 2>&1 && claudebox list 2>&1 | grep -q 'no boxes yet' \ + && ok "empty host: 'no boxes yet', exit 0" || no "empty-host message wrong" +fi printf '\n minting a box (cold, ~10 min)…\n' t0=$SECONDS @@ -603,7 +612,12 @@ if [ "$KEEP" = 1 ]; then else # every name the drill can have left, whatever branch a partial run took for n in drill clone archive peer; do claudebox rm "$n" --force >/dev/null 2>&1; done - claudebox list 2>&1 | grep -q 'no boxes yet' && ok "teardown: no boxes left" || no "a box survived teardown" + # Assert OUR boxes are gone — not that the host is empty. The rm loop above + # already embodies the discipline (only names the drill minted); demanding + # 'no boxes yet' here would flag any pre-existing operator box as a failure. + leftover="$(claudebox list 2>/dev/null | grep -E '^(drill|clone|archive|peer)([[:space:]]|$)' || true)" + [ -z "$leftover" ] && ok "teardown: every box the drill minted is gone" \ + || no "a drill box survived teardown: $(printf '%s' "$leftover" | awk '{print $1}' | tr '\n' ' ')" fi phase "Summary"