Files
echolot/server/internal/control/dscp_test.go
T
mrambossekandClaude Opus 5 8118e213ae server: upstream trains, observed TTL/DSCP/ECN, rate limits, action ids
Types 0x03/0x04/0x05 land with a bounded columnar train buffer (head kept,
truncation declared) and grant-free multi-part reports - a report row is
smaller than the packet it answers, so $3.4 holds without a grant. The
read loop now collects TTL/TOS cmsgs on Linux, replacing the 0xFF stubs in
the observation block with what the kernel saw; downtrain gained a dscp
parameter, so DSCP survival is measurable in both directions.

Rate limiting ($2.5) exists now: per-credential AND per-source buckets,
429 on the control plane, silent drop on the data plane after the HMAC
gate and before the replay window. UDP ceilings default above the largest
legitimate run - a limit that clips a real measurement produces a
confidently wrong number.

Every granted packet carries its action_id at payload[8:16]; overlapping
actions were unattributable before. Canary DNS logs now honor the stated
24h privacy default. /admin/enroll-tokens answers the spec's JSON shape.
protocol_version 1.0.1 (additive).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-02 13:04:54 +02:00

28 lines
774 B
Go

// SPDX-FileCopyrightText: 2026 Echolot contributors
// SPDX-License-Identifier: GPL-3.0-or-later
package control
import "testing"
func TestDscpArg(t *testing.T) {
ptr := func(v int) *int { return &v }
for _, tc := range []struct {
in *int
want int
wantErr bool
}{
{nil, -1, false}, // absent: leave the socket alone
{ptr(0), 0, false}, // explicit best-effort is not the same as absent
{ptr(46), 46, false}, // EF, the value people actually test with
{ptr(63), 63, false},
{ptr(64), 0, true}, // one past the 6-bit field
{ptr(-1), 0, true},
} {
got, err := dscpArg(tc.in)
if (err != nil) != tc.wantErr || got != tc.want {
t.Errorf("dscpArg(%v) = %d, err=%v; want %d, wantErr=%v", tc.in, got, err, tc.want, tc.wantErr)
}
}
}