diff --git a/scripts/unified-deployment-smoke.sh b/scripts/unified-deployment-smoke.sh index 5e5b52b3..78f3eb1c 100755 --- a/scripts/unified-deployment-smoke.sh +++ b/scripts/unified-deployment-smoke.sh @@ -688,7 +688,7 @@ roots: indexes: indexes sessions: sessions EOF - chmod 0600 "$TASK13_SERVER_WORKSPACE_CONFIG" + chmod 0644 "$TASK13_SERVER_WORKSPACE_CONFIG" mkdir -p "$TASK13_SERVER_DATA" "$TASK13_SERVER_PI_STATE" "$TASK13_SERVER_REGISTRY" "$TASK13_ROOT/scripts/prepare-server-pi-state.sh" \ @@ -1564,7 +1564,7 @@ task13_assert_server_runtime() { || task13_fail "server core did not use the smoke-built core image" [[ "$(docker inspect --format '{{.Image}}' "$frontend_id")" == "$expected_frontend_image" ]] \ || task13_fail "server frontend did not use the smoke-built frontend image" - task13_compose exec -T core sh -ceu ' + task13_compose_logged "verify server runtime configuration and secret readability" exec -T core sh -ceu ' test -r /run/thothii-auth/auth.yaml test -d /data/auth test -z "${AUTH_MODE+x}" @@ -2529,7 +2529,7 @@ task13_self_test_source_contract() { local image_evidence_environment image_evidence_initialization local server_auth_projection_override server_auth_projection_descriptor local server_auth_projection_environment server_auth_privileged_configure - local server_fixture_reclamation + local server_fixture_reclamation server_runtime_config_probe server_workspace_config_permission root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)" workflow="$root/.github/workflows/deployment.yml" runner_preparation="$root/scripts/prepare-linux-docker-runner.sh" @@ -2560,6 +2560,8 @@ task13_self_test_source_contract() { server_auth_projection_environment='THT_AUTH_RUNTIME_''ROOT=%s' server_auth_privileged_configure='sudo -n -- "$TASK13_''THT"' server_fixture_reclamation='task13_reclaim_server_fixture_''ownership' + server_runtime_config_probe='task13_compose_''logged "verify server runtime configuration and secret readability"' + server_workspace_config_permission='chmod 0644 "$TASK13_SERVER_''WORKSPACE_CONFIG"' if rg -n 'docker[[:space:]]+(system[[:space:]]+)?prune' \ "$root/scripts/unified-deployment-smoke.sh" \ "$root/scripts/tht-update-smoke.sh" \ @@ -2635,6 +2637,10 @@ task13_self_test_source_contract() { [[ "$(grep -Ec "^${server_fixture_reclamation}\\(\\)|^[[:space:]]+${server_fixture_reclamation}$" \ "$root/scripts/unified-deployment-smoke.sh")" -eq 2 ]] \ || task13_fail "the server smoke must reclaim its root- and core-owned fixture exactly once" + grep -Fq -- "$server_runtime_config_probe" "$root/scripts/unified-deployment-smoke.sh" \ + || task13_fail "the server runtime preconditions must emit a named diagnostic" + grep -Fq -- "$server_workspace_config_permission" "$root/scripts/unified-deployment-smoke.sh" \ + || task13_fail "the server workspace fixture must be readable by the container UID" [[ -x "$runner_preparation" ]] \ || task13_fail "the Linux Docker runner preparation must be executable" for path in /usr/local/lib/android /usr/share/dotnet /opt/ghc /usr/local/.ghcup; do