feat(server): activate projected authentication safely
This commit is contained in:
@@ -0,0 +1,56 @@
|
||||
//go:build linux
|
||||
|
||||
package setup
|
||||
|
||||
import (
|
||||
"os"
|
||||
"path/filepath"
|
||||
"syscall"
|
||||
"testing"
|
||||
|
||||
"github.com/aritmolab/thothii/tools/tht/internal/config"
|
||||
)
|
||||
|
||||
func TestEnsureFilesProjectedServerCreatesExactNumericAuthenticationRoots(t *testing.T) {
|
||||
if os.Geteuid() != 0 {
|
||||
t.Skip("requires root to verify numeric projected ownership")
|
||||
}
|
||||
root := newProject(t, "projected server root")
|
||||
for _, name := range []string{"compose.server.yaml", "compose.auth-runtime-projection.yaml"} {
|
||||
if err := os.WriteFile(filepath.Join(root, "deploy", name), []byte("services: {}\n"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
setNonInteractiveAnswers(t, newExternalSecrets(t, root))
|
||||
result, err := EnsureFiles(Request{
|
||||
ProjectRoot: root, InstallationID: "server", Profile: "server", NonInteractive: true,
|
||||
}, nil, ioDiscard{})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
installation, err := config.Load(result.DescriptorPath)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
projection := installation.RuntimeAuthProjection()
|
||||
if projection == nil {
|
||||
t.Fatal("generated server descriptor lacks runtime auth projection")
|
||||
}
|
||||
assertNumericDirectoryMetadata(t, installation.AuthenticationDirectory(), 0, 0, 0o700)
|
||||
assertNumericDirectoryMetadata(t, projection.Directory, 10001, 10001, 0o700)
|
||||
}
|
||||
|
||||
func assertNumericDirectoryMetadata(t *testing.T, path string, uid, gid uint32, mode os.FileMode) {
|
||||
t.Helper()
|
||||
info, err := os.Stat(path)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
metadata, ok := info.Sys().(*syscall.Stat_t)
|
||||
if !ok {
|
||||
t.Fatalf("stat metadata for %s = %T", path, info.Sys())
|
||||
}
|
||||
if metadata.Uid != uid || metadata.Gid != gid || info.Mode().Perm() != mode {
|
||||
t.Fatalf("metadata for %s = uid=%d gid=%d mode=%o, want uid=%d gid=%d mode=%o", path, metadata.Uid, metadata.Gid, info.Mode().Perm(), uid, gid, mode)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user