tools/pasture/town/ (run through tools/pasture/town.sh) seeds a fake community across every running peer and checks that all of them, and PrivaPub, agree on what happened: - drivers per platform on four dialect bases (Mastodon API, Misskey API, Lemmy API, PrivaPub with /clientapi), each with a selftest against its own server; what a server holds is read from its database, never by making it fetch; - a deterministic generator (specs/village.json: 23 accounts on seven servers, roots with several personas, circles and communities, a cross-server follow graph, posts of every kind and visibility, reply rounds, likes, boosts, reactions, votes, edits, deletes, blocks, mutes and a report) and a seeder that keeps a ledger of what happened; - a sweep that expects delivery and confinement per server, what each account sees, counts, threads, edits, deletes, follows and privacy rows (sibling keys, published days, canary root credentials in every peer's database, located posts that never leave), with what the peers do on purpose modelled (Misskey drops orphan replies, Lemmy keeps only community content, edits go to the post's own audience); - known gaps (gaps.json) turn failures into xfail and passes into xpass; a self-contained report.html, and docs/INTEROP-BACKLOG.md. The pasture moves to a public-looking subnet (peers with no private address switch can join), takes PASTURE_PORT when 6971 is in use, adds peers to a running pasture (run.sh add, Caddy recreated with its CA kept), removes its volumes on down, writes every scenario check to out/scenarios.jsonl, serves decePub as decepub.test for its e2e tests, lifts GoToSocial's and Lemmy's own rate limits, trusts Caddy in Mastodon (TRUSTED_PROXY_IP) and gains Hollo (Fedify), whose one login owning several accounts is the nearest peer to PrivaPub's personas. The first village found the four PrivaPub bugs fixed in the commits before this one; the second run, on the fixed server, passes 2319 checks with 11 failures left, all between peers or from Lemmy's send worker, which the seeder now warms up first. ROADMAP records the owner's decisions of 2026-10-04 (the town, and P9 back from the cut list). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
104 lines
4.5 KiB
Python
104 lines
4.5 KiB
Python
"""GoToSocial 0.22: accounts made with its admin CLI (then one restart, as the pasture does), tokens through the OAuth
|
|
code flow with a signed-in cookie (it has no password grant), objects read from a copy of its sqlite database."""
|
|
import json
|
|
import re
|
|
import urllib.parse
|
|
|
|
from core import podman
|
|
from dialects.base import Stored
|
|
from dialects.mastodon_api import MastodonApi
|
|
|
|
# gtsmodel.Visibility since 0.20: stored as small integers
|
|
VIS = {2: "public", 3: "unlisted", 4: "followers", 5: "mutuals", 6: "direct"}
|
|
OOB = "urn:ietf:wg:oauth:2.0:oob"
|
|
|
|
|
|
class Gts(MastodonApi):
|
|
platform = "gts"
|
|
|
|
def provision(self, accounts):
|
|
created = False
|
|
existing = {r["username"] for r in self._sqlite("select username from accounts where domain is null")}
|
|
for a in accounts:
|
|
if a.username in existing:
|
|
continue
|
|
podman.exec_("pasture-gts", "/gotosocial/gotosocial", "admin", "account", "create", "--username", a.username,
|
|
"--email", f"{a.username}@gts.test", "--password", a.password)
|
|
podman.exec_("pasture-gts", "/gotosocial/gotosocial", "admin", "account", "confirm", "--username", a.username)
|
|
created = True
|
|
if created:
|
|
# the running server keeps what it has cached about accounts; the pasture restarts it after the CLI too
|
|
podman.run("restart", "pasture-gts")
|
|
self._wait()
|
|
return [self.session_from_token(a, self._token(a)) for a in accounts]
|
|
|
|
def _wait(self):
|
|
import time
|
|
for _ in range(90):
|
|
try:
|
|
if self.http.get(self.base + "/api/v1/instance").status == 200:
|
|
return
|
|
except Exception:
|
|
pass
|
|
time.sleep(1)
|
|
raise TimeoutError("GoToSocial did not come back")
|
|
|
|
def _token(self, a):
|
|
app = self.http.post(self.base + "/api/v1/apps", ok={200}, form={
|
|
"client_name": "pasture-town", "redirect_uris": OOB, "scopes": "read write follow"}).json()
|
|
cookies = {}
|
|
|
|
def send(method, path, **kw):
|
|
# the sign-in pages are HTML: asked for JSON (the client's default) they answer 406 and set no session
|
|
headers = {"Accept": "text/html,*/*"}
|
|
if cookies:
|
|
headers["Cookie"] = "; ".join(f"{k}={v}" for k, v in cookies.items())
|
|
r = self.http.request(method, self.base + path, headers=headers, **kw)
|
|
for k, v in r.headers:
|
|
if k.lower() == "set-cookie":
|
|
name, _, value = v.split(";")[0].partition("=")
|
|
cookies[name.strip()] = value.strip()
|
|
return r
|
|
|
|
query = urllib.parse.urlencode({"client_id": app["client_id"], "redirect_uri": OOB, "response_type": "code",
|
|
"scope": "read write follow"})
|
|
send("GET", f"/oauth/authorize?{query}")
|
|
send("POST", "/auth/sign_in", form={"username": f"{a.username}@gts.test", "password": a.password})
|
|
r = send("POST", "/oauth/authorize")
|
|
location = r.header("Location") or ""
|
|
code = urllib.parse.parse_qs(urllib.parse.urlsplit(location).query).get("code", [None])[0]
|
|
if code is None:
|
|
found = re.search(r"code=([A-Za-z0-9_\-]+)", r.text)
|
|
code = found.group(1) if found else None
|
|
if code is None:
|
|
raise RuntimeError(f"GoToSocial gave {a.username} no authorization code ({r.status})")
|
|
token = self.http.post(self.base + "/oauth/token", ok={200}, form={
|
|
"grant_type": "authorization_code", "code": code, "client_id": app["client_id"],
|
|
"client_secret": app["client_secret"], "redirect_uri": OOB, "scope": "read write follow"}).json()
|
|
return token["access_token"]
|
|
|
|
def _sqlite(self, sql, *params):
|
|
with podman.SqliteCopy("pasture-gts", "/gotosocial/storage/sqlite.db") as db:
|
|
return db.rows(sql, *params)
|
|
|
|
def _rows(self, uris):
|
|
if not uris:
|
|
return {}
|
|
marks = ",".join("?" * len(uris))
|
|
rows = self._sqlite(f"""
|
|
select s.id as local_id, s.uri, s.visibility, s.flags, s.text, s.content, s.content_warning as cw,
|
|
s.edited_at is not null as edited, s.in_reply_to_uri as parent_uri,
|
|
(select count(*) from status_faves f where f.status_id = s.id) as likes,
|
|
(select count(*) from statuses b where b.boost_of_id = s.id) as boosts,
|
|
(select count(*) from statuses r where r.in_reply_to_id = s.id) as replies,
|
|
(select votes from polls p where p.status_id = s.id) as votes
|
|
from statuses s where s.boost_of_id is null and s.uri in ({marks})""", *uris)
|
|
out = {}
|
|
for r in rows:
|
|
votes = json.loads(r["votes"]) if r["votes"] else None
|
|
# 0.22 soft-deletes: flag 2 marks a deleted status (its statuses_deleted_idx), 8 a local one
|
|
out[r["uri"]] = Stored(True, bool(r["flags"] & 2), r["local_id"], VIS.get(r["visibility"], str(r["visibility"])),
|
|
r["text"] or r["content"], r["cw"] or None, bool(r["edited"]), r["parent_uri"],
|
|
r["likes"], r["boosts"], r["replies"], votes, None, r)
|
|
return out
|