如何测试多组织业务网络的背书策略及双组织交易背书情况?
Great question! Validating that both your organizations are properly endorsing transactions is critical to ensuring your multi-org deployment works as designed. Here are practical, hands-on ways to test this:
1. Test with a Multi-Peer Chaincode Invoke
The most direct way is to submit a transaction that explicitly requests endorsements from both orgs' peers, then verify the outcome.
First, set up your CLI environment for one of the orgs (e.g., Org1):
export CORE_PEER_MSPCONFIGPATH=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.example.com/users/Admin@org1.example.com/msp export CORE_PEER_ADDRESS=peer0.org1.example.com:7051 export CORE_PEER_LOCALMSPID="Org1MSP" export CORE_PEER_TLS_ROOTCERT_FILE=/opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/peerOrganizations/org1.example.com/peers/peer0.org1.example.com/tls/ca.crtThen invoke the chaincode, specifying peers from both organizations:
peer chaincode invoke -o orderer.example.com:7050 -C mychannel -n mycc -c '{"Args":["invoke","a","b","10"]}' \ --peerAddresses peer0.org1.example.com:7051 \ --peerAddresses peer0.org2.example.com:7051 \ --tls true --cafile /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/ordererOrganizations/example.com/orderers/orderer.example.com/msp/tlscacerts/tlsca.example.com-cert.pemIf the transaction commits successfully, that means both peers endorsed it. If you get an error like
endorsement policy not satisfied, one or both peers didn't endorse correctly.
2. Verify Your Chaincode's Endorsement Policy
First, make sure your chaincode is actually configured to require both orgs' endorsement. If you deployed it with a policy like AND('Org1MSP.peer','Org2MSP.peer'), you can confirm this by:
Querying the installed chaincode details:
peer chaincode list --installed -C mychannelLook for the
Policyfield in the output to confirm it requires both orgs' peers.If your chaincode includes a helper function to query the policy, you can call it directly:
peer chaincode query -C mychannel -n mycc -c '{"Args":["getEndorsementPolicy"]}'
3. Check Peer Node Logs for Endorsement Activity
Each peer logs when it processes an endorsement request. You can inspect these logs to confirm both orgs are participating:
- For Org1's peer:
docker logs peer0.org1.example.com | grep "Endorsing transaction" - For Org2's peer:
Look for log entries matching your transaction ID—if they exist, the peer successfully endorsed that transaction.docker logs peer0.org2.example.com | grep "Endorsing transaction"
4. Test the Failure Scenario (Single Org Endorsement)
To confirm the endorsement policy is enforced, try submitting a transaction with only one org's peer:
peer chaincode invoke -o orderer.example.com:7050 -C mychannel -n mycc -c '{"Args":["invoke","a","b","10"]}' \ --peerAddresses peer0.org1.example.com:7051 \ --tls true --cafile /opt/gopath/src/github.com/hyperledger/fabric/peer/crypto/ordererOrganizations/example.com/orderers/orderer.example.com/msp/tlscacerts/tlsca.example.com-cert.pem
This transaction should fail with an error stating the endorsement policy wasn't met. This confirms that transactions can't proceed without both orgs' approval.
5. Programmatic Testing with SDKs
If you're using a Fabric SDK (Node.js, Java, Go), you can write tests to validate endorsement behavior:
- Create peer objects for both Org1 and Org2.
- Attempt to submit a transaction using only one peer's endorsement: this should fail.
- Collect endorsements from both peers, then submit the transaction: this should succeed.
This approach is great for automated testing in CI/CD pipelines.
内容的提问来源于stack exchange,提问作者rajadilipkolli

