Keep permission regression probe independent of private checkout paths
This commit is contained in:
@@ -146,6 +146,7 @@ mod tests {
|
|||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn unreadable_existing_key_is_not_replaced() {
|
fn unreadable_existing_key_is_not_replaced() {
|
||||||
|
use std::os::fd::AsRawFd;
|
||||||
use std::os::unix::process::CommandExt;
|
use std::os::unix::process::CommandExt;
|
||||||
let dir = tempfile::tempdir().unwrap();
|
let dir = tempfile::tempdir().unwrap();
|
||||||
fs::set_permissions(dir.path(), fs::Permissions::from_mode(0o755)).unwrap();
|
fs::set_permissions(dir.path(), fs::Permissions::from_mode(0o755)).unwrap();
|
||||||
@@ -155,17 +156,21 @@ mod tests {
|
|||||||
if unsafe { libc::geteuid() } == 0 {
|
if unsafe { libc::geteuid() } == 0 {
|
||||||
// The isolated runner is root. Probe as an unprivileged child so
|
// The isolated runner is root. Probe as an unprivileged child so
|
||||||
// DAC_OVERRIDE cannot hide the exact production failure.
|
// DAC_OVERRIDE cannot hide the exact production failure.
|
||||||
let status = std::process::Command::new(std::env::current_exe().unwrap())
|
// Execute an already-open inode: the test checkout may live under
|
||||||
.args([
|
// a private home directory which the probe must not traverse.
|
||||||
"--ignored",
|
let executable = File::open(std::env::current_exe().unwrap()).unwrap();
|
||||||
"--exact",
|
let status =
|
||||||
"session::secret_file::tests::permission_denied_child_probe",
|
std::process::Command::new(format!("/proc/self/fd/{}", executable.as_raw_fd()))
|
||||||
])
|
.args([
|
||||||
.env("ARCHY_SESSION_KEY_PERMISSION_PROBE", &path)
|
"--ignored",
|
||||||
.uid(65534)
|
"--exact",
|
||||||
.gid(65534)
|
"session::secret_file::tests::permission_denied_child_probe",
|
||||||
.status()
|
])
|
||||||
.unwrap();
|
.env("ARCHY_SESSION_KEY_PERMISSION_PROBE", &path)
|
||||||
|
.uid(65534)
|
||||||
|
.gid(65534)
|
||||||
|
.status()
|
||||||
|
.unwrap();
|
||||||
assert!(status.success());
|
assert!(status.success());
|
||||||
} else {
|
} else {
|
||||||
fs::set_permissions(&path, fs::Permissions::from_mode(0o000)).unwrap();
|
fs::set_permissions(&path, fs::Permissions::from_mode(0o000)).unwrap();
|
||||||
|
|||||||
Reference in New Issue
Block a user