Keep permission regression probe independent of private checkout paths

This commit is contained in:
archipelago
2026-10-06 01:34:57 -04:00
parent aa10bd1247
commit a2e6138279
+6 -1
View File
@@ -146,6 +146,7 @@ mod tests {
#[test] #[test]
fn unreadable_existing_key_is_not_replaced() { fn unreadable_existing_key_is_not_replaced() {
use std::os::fd::AsRawFd;
use std::os::unix::process::CommandExt; use std::os::unix::process::CommandExt;
let dir = tempfile::tempdir().unwrap(); let dir = tempfile::tempdir().unwrap();
fs::set_permissions(dir.path(), fs::Permissions::from_mode(0o755)).unwrap(); fs::set_permissions(dir.path(), fs::Permissions::from_mode(0o755)).unwrap();
@@ -155,7 +156,11 @@ mod tests {
if unsafe { libc::geteuid() } == 0 { if unsafe { libc::geteuid() } == 0 {
// The isolated runner is root. Probe as an unprivileged child so // The isolated runner is root. Probe as an unprivileged child so
// DAC_OVERRIDE cannot hide the exact production failure. // DAC_OVERRIDE cannot hide the exact production failure.
let status = std::process::Command::new(std::env::current_exe().unwrap()) // Execute an already-open inode: the test checkout may live under
// a private home directory which the probe must not traverse.
let executable = File::open(std::env::current_exe().unwrap()).unwrap();
let status =
std::process::Command::new(format!("/proc/self/fd/{}", executable.as_raw_fd()))
.args([ .args([
"--ignored", "--ignored",
"--exact", "--exact",