The town: a fake community across the pasture, checked for coherence

tools/pasture/town/ (run through tools/pasture/town.sh) seeds a fake
community across every running peer and checks that all of them, and
PrivaPub, agree on what happened:

- drivers per platform on four dialect bases (Mastodon API, Misskey API,
  Lemmy API, PrivaPub with /clientapi), each with a selftest against
  its own server; what a server holds is read from its database, never
  by making it fetch;
- a deterministic generator (specs/village.json: 23 accounts on seven
  servers, roots with several personas, circles and communities, a
  cross-server follow graph, posts of every kind and visibility, reply
  rounds, likes, boosts, reactions, votes, edits, deletes, blocks,
  mutes and a report) and a seeder that keeps a ledger of what happened;
- a sweep that expects delivery and confinement per server, what each
  account sees, counts, threads, edits, deletes, follows and privacy
  rows (sibling keys, published days, canary root credentials in every
  peer's database, located posts that never leave), with what the peers
  do on purpose modelled (Misskey drops orphan replies, Lemmy keeps only
  community content, edits go to the post's own audience);
- known gaps (gaps.json) turn failures into xfail and passes into xpass;
  a self-contained report.html, and docs/INTEROP-BACKLOG.md.

The pasture moves to a public-looking subnet (peers with no private
address switch can join), takes PASTURE_PORT when 6971 is in use, adds
peers to a running pasture (run.sh add, Caddy recreated with its CA
kept), removes its volumes on down, writes every scenario check to
out/scenarios.jsonl, serves decePub as decepub.test for its e2e tests,
lifts GoToSocial's and Lemmy's own rate limits, trusts Caddy in
Mastodon (TRUSTED_PROXY_IP) and gains Hollo (Fedify), whose one login
owning several accounts is the nearest peer to PrivaPub's personas.

The first village found the four PrivaPub bugs fixed in the commits
before this one; the second run, on the fixed server, passes 2319 checks
with 11 failures left, all between peers or from Lemmy's send worker,
which the seeder now warms up first. ROADMAP records the owner's
decisions of 2026-10-04 (the town, and P9 back from the cut list).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-05 00:32:54 +02:00
1 parent d6131af289
commit 2873344690
46 files changed
+4400 -24

No files matched your search

+9 -4
View File
@@ -1,10 +1,15 @@
# Shared by interop.sh and the scenarios: check helpers, PrivaPub personas and tokens, the statistics check.
P=http://127.0.0.1:6971
P=http://127.0.0.1:${PASTURE_PORT:-6971}
work=$(mktemp -d); trap 'rm -rf "$work"' EXIT
pass=0; fail=0; expected=0
ok() { echo " ok $*"; pass=$((pass+1)); }
ko() { echo " FAIL $*"; fail=$((fail+1)); }
xf() { echo " xf $* (expected to fail until a later phase)"; expected=$((expected+1)); }
# every check is also appended to $INTEROP_JSONL (out/scenarios.jsonl), which the town's report reads next to its own
INTEROP_JSONL=${INTEROP_JSONL:-$here/out/scenarios.jsonl}
mkdir -p "$(dirname "$INTEROP_JSONL")"
record() { python3 -c 'import json,sys,time; print(json.dumps({"source":"scenario","peer":sys.argv[1],"check":sys.argv[2],"status":sys.argv[3],"t":time.strftime("%Y-%m-%dT%H:%M:%SZ",time.gmtime())}))' \
"${INTEROP_PEER:-}" "$1" "$2" >> "$INTEROP_JSONL"; }
ok() { echo " ok $*"; pass=$((pass+1)); record "$*" pass; }
ko() { echo " FAIL $*"; fail=$((fail+1)); record "$*" fail; }
xf() { echo " xf $* (expected to fail until a later phase)"; expected=$((expected+1)); record "$*" xfail; }
j() { python3 -c "import sys,json
try: d=json.load(sys.stdin)
except Exception: d=None
+44 -11
View File
@@ -1,6 +1,10 @@
# Shared by run.sh: the network, Caddy (its CA kept in a volume and copied to .ca/root.crt), Mongo and PrivaPub.
here="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"; repo="$(cd "$here/../.." && pwd)"
port=${PASTURE_PORT:-6971} # PrivaPub straight from the workstation; PASTURE_PORT when 6971 is taken
net=privapub-pasture; publish="$here/.publish"; ca="$here/.ca"
# The network looks public (11.42.0.0/24 is never reached for real from inside the pasture), so peers that refuse private
# addresses with no switch to say otherwise (Pixelfed, Mbin, WordPress, Discourse, Fedify) federate too.
subnet=${PASTURE_SUBNET:-11.42.0.0/24}
site() { curl -k --resolve "$1:6443:127.0.0.1" "${@:2}"; }
@@ -13,21 +17,16 @@ pasture_base_up() {
local dotnet=${DOTNET:-$(command -v dotnet || echo ~/.dotnet/dotnet)}
"$dotnet" publish "$repo/PrivaPub/PrivaPub.csproj" -c Release -r linux-x64 --self-contained true -o "$publish" -v quiet
cp "$here/appsettings.Pasture.json" "$publish/"
podman network exists $net || podman network create $net >/dev/null
podman network exists $net || podman network create --subnet "$subnet" $net >/dev/null
podman volume exists pasture-caddy-data || podman volume create pasture-caddy-data >/dev/null
podman run -d --replace --name pasture-mongo --network $net --network-alias mongo docker.io/library/mongo:8 --quiet >/dev/null
local aliases=""
for site in privapub gts mastodon akkoma misskey sharkey lemmy; do aliases="$aliases --network-alias $site.test"; done
# shellcheck disable=SC2086
podman run -d --replace --name pasture-caddy --network $net $aliases \
-p 127.0.0.1:6443:443 --sysctl net.ipv4.ip_unprivileged_port_start=0 -v "$here/Caddyfile:/etc/caddy/Caddyfile:Z,ro" \
-v pasture-caddy-data:/data docker.io/library/caddy:2 >/dev/null
caddy_up
local extra=()
for setting in ${PRIVAPUB_ENV:-}; do extra+=(-e "$setting"); done
podman run -d --replace --name pasture-privapub --network $net -p 127.0.0.1:6971:80 \
podman run -d --replace --name pasture-privapub --network $net -p "127.0.0.1:$port:80" \
--sysctl net.ipv4.ip_unprivileged_port_start=0 -e ASPNETCORE_ENVIRONMENT=Pasture "${extra[@]}" -w /app -v "$publish:/app:Z,ro" \
mcr.microsoft.com/dotnet/runtime-deps:10.0 /app/PrivaPub >/dev/null
wait_http http://127.0.0.1:6971/build.json
wait_http "http://127.0.0.1:$port/build.json"
rm -rf "$ca"; mkdir -p "$ca"
for _ in $(seq 1 60); do
podman cp pasture-caddy:/data/caddy/pki/authorities/local/root.crt "$ca/root.crt" 2>/dev/null && [ -s "$ca/root.crt" ] && break
@@ -41,9 +40,43 @@ pasture_base_up() {
chmod 644 "$ca/bundle.pem"
}
# Caddy, with every site the Caddyfile serves as a name on the network, so a peer is added with its Caddyfile block alone.
# Its CA lives in the pasture-caddy-data volume, so recreating it (run.sh add, for a new site) keeps every peer's trust.
caddy_up() {
local aliases=""
for site in $(caddy_sites); do aliases="$aliases --network-alias $site"; done
# shellcheck disable=SC2086
podman run -d --replace --name pasture-caddy --network $net $aliases \
-p 127.0.0.1:6443:443 --sysctl net.ipv4.ip_unprivileged_port_start=0 -v "$here/Caddyfile:/etc/caddy/Caddyfile:Z,ro" \
-v pasture-caddy-data:/data docker.io/library/caddy:2 >/dev/null
}
# caddy_current: whether the running Caddy already answers every site of the Caddyfile on the network
caddy_current() {
local have
have=$(podman inspect pasture-caddy --format '{{range .NetworkSettings.Networks}}{{range .Aliases}}{{.}} {{end}}{{end}}' 2>/dev/null)
for site in $(caddy_sites); do case " $have " in *" $site "*) ;; *) return 1 ;; esac; done
}
# the sites the Caddyfile serves: "a.test {" and "a.test, b.test {" lines
caddy_sites() {
grep -E '^[a-z0-9.-]+\.test(, *[a-z0-9.-]+\.test)* *\{' "$here/Caddyfile" | sed 's/ *{.*//; s/,/ /g'
}
# pasture_down [--purge]: removes every pasture container with its anonymous volumes (images declare volumes, and
# without -v each run left them behind), the named volumes and the network. Caddy's CA is kept unless --purge, so a peer
# that was told to trust it still does after the next up.
pasture_down() {
podman ps -a --format '{{.Names}}' | grep '^pasture-' | xargs -r podman rm -f >/dev/null 2>&1 || true
podman volume ls --format '{{.Name}}' | grep '^pasture-' | xargs -r podman volume rm -f >/dev/null 2>&1 || true
podman ps -a --format '{{.Names}}' | grep '^pasture-' | xargs -r podman rm -f -v >/dev/null 2>&1 || true
local keep='^pasture-caddy-data$'
[ "${1:-}" = "--purge" ] && keep='^$'
podman volume ls --format '{{.Name}}' | grep '^pasture-' | grep -v "$keep" | xargs -r podman volume rm -f >/dev/null 2>&1 || true
podman network rm $net >/dev/null 2>&1 || true
rm -rf "$here/.state" "$ca"
}
# pasture_stats: memory and CPU of every pasture container, largest first
pasture_stats() {
podman stats --no-stream --format '{{.Name}}\t{{.MemUsage}}\t{{.CPUPerc}}' $(podman ps --format '{{.Names}}' | grep '^pasture-') 2>/dev/null \
| sort -t$'\t' -k2 -h -r
}