From 92f9525bcc1de21404be983ad8d92ff361d1dc01 Mon Sep 17 00:00:00 2001 From: DanConwayDev Date: Tue, 20 Jan 2026 07:44:18 +0000 Subject: [PATCH] docs(issue): add comprehensive testing strategy for ExecStartPre fix --- b454-nixos-module-execstartpre-datadir.md | 94 +++++++++++++++++++++++ 1 file changed, 94 insertions(+) diff --git a/b454-nixos-module-execstartpre-datadir.md b/b454-nixos-module-execstartpre-datadir.md index 49d50b8..67e4b9d 100644 --- a/b454-nixos-module-execstartpre-datadir.md +++ b/b454-nixos-module-execstartpre-datadir.md @@ -54,6 +54,100 @@ serviceConfig = { ## Progress +### 2026-01-20 [Session 09:00] - Testing Strategy Review +- Reviewed: Implementation in commit f93fc0a691544cc3ddda322a7e99d0534d636dcc +- Designed: Comprehensive testing strategy for NixOS deployment + +#### Testing Strategy + +**Approach:** Add a test ngit-grasp instance with `archiveAll = true` to the user's NixOS configuration. This will: +1. Test the ExecStartPre directory creation with a fresh custom dataDir +2. Exercise the git directory creation when archive mode accepts repositories +3. Validate permissions are correct for service operation + +**Test Scenarios:** + +1. **Fresh Install (Primary Test)** + - Add new instance with non-existent custom dataDir (e.g., `/persistent/grasp/test-archive`) + - Run `nixos-rebuild switch` + - Expected: Service starts successfully, directories created with correct ownership + +2. **Existing Directories (Idempotency)** + - Restart the service after initial setup + - Expected: ExecStartPre completes without errors, permissions unchanged + +3. **Permission Correction** + - Manually change directory permissions (e.g., `chmod 777`) + - Restart service + - Expected: Permissions reset to 750 + +4. **Ownership Correction** + - Manually change ownership (e.g., `chown root:root`) + - Restart service + - Expected: Ownership reset to service user:group + +**Recommended Test Configuration:** + +```nix +# Add to NixOS configuration alongside existing ngit-grasp instances +services.ngit-grasp.test-archive = { + enable = true; + domain = "test-archive.localhost"; # Won't be publicly accessible + port = 7335; # Different port from production + dataDir = "/persistent/grasp/test-archive"; # Fresh path that doesn't exist + archiveAll = true; # Enables archive mode for testing git operations + logLevel = "debug"; # Verbose logging for verification +}; +``` + +**Verification Commands:** + +```bash +# 1. Check service status +sudo systemctl status ngit-grasp-test-archive + +# 2. Verify directories exist with correct permissions +ls -la /persistent/grasp/test-archive/ +# Expected: drwxr-x--- ngit-grasp-test-archive ngit-grasp + +ls -la /persistent/grasp/test-archive/git/ +ls -la /persistent/grasp/test-archive/relay/ +# Expected: drwxr-x--- ngit-grasp-test-archive ngit-grasp + +# 3. Check ExecStartPre execution in journal +journalctl -u ngit-grasp-test-archive --no-pager | head -50 + +# 4. Test permission correction +sudo chmod 777 /persistent/grasp/test-archive +sudo systemctl restart ngit-grasp-test-archive +stat /persistent/grasp/test-archive +# Expected: 0750 permissions restored + +# 5. Test ownership correction +sudo chown root:root /persistent/grasp/test-archive +sudo systemctl restart ngit-grasp-test-archive +stat /persistent/grasp/test-archive +# Expected: ngit-grasp-test-archive:ngit-grasp ownership restored +``` + +**Cleanup After Testing:** + +```bash +# Remove test instance from NixOS config, then: +sudo nixos-rebuild switch +sudo rm -rf /persistent/grasp/test-archive +sudo userdel ngit-grasp-test-archive # If user persists +``` + +**Edge Cases to Consider:** + +- Parent directory doesn't exist (e.g., `/persistent/grasp/` doesn't exist) + - `mkdir -p` handles this correctly +- Symlinked dataDir paths + - Should work, but worth verifying +- SELinux/AppArmor contexts (if enabled) + - May need additional testing on hardened systems + ### 2026-01-20 [Session 08:15] - Completed: Implemented ExecStartPre directives in nix/module.nix - Implementation details: