controllerswap: stdin tee write + narrow FELHOM_CONTROLLERSWAP grants (non-root, v0.45.0)
writeImage drops bash -c/printf for GuestExecStdin(img+\n -> tee /etc/felhom-controller-image); new Runner.RunStdin/GuestExecStdin route stdin through the fenced sudo -n runner. 5 narrow, auditable sudoers grants (no general pct exec, no bash -c) + capability manifest entries (Critical) so the self-probe watches them and the build-test asserts coverage (companion red-proof). No controller change; swap orchestration/rollback/state unchanged. Spike GO. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EPZ4GJ8L5Jqf8UiPwbn1kt
This commit is contained in:
@@ -38,10 +38,10 @@ func TestSystemDisks_FromBootMounts(t *testing.T) {
|
||||
func TestRoleForStorage_DemoMapping(t *testing.T) {
|
||||
sys, ok := SystemDisks(demoHost())
|
||||
cases := []struct {
|
||||
name string
|
||||
typ string
|
||||
device string
|
||||
want DeviceRole
|
||||
name string
|
||||
typ string
|
||||
device string
|
||||
want DeviceRole
|
||||
}{
|
||||
{"builtin local (root fs)", hub.StorageTypeLocal, "", RoleSystem},
|
||||
{"local-lvm (lvmthin)", hub.StorageTypeLVMThin, "", RoleSystem},
|
||||
|
||||
Reference in New Issue
Block a user