R-861 (a) A1 + (b) B2: the image ref goes to a root verb that checks it; the agent's in-guest tee grant is gone; felhom-op's pct lines are exact (09 §3 decision 165)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -0,0 +1,48 @@
|
||||
package localapi
|
||||
|
||||
import (
|
||||
"context"
|
||||
"io"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// stdinRecorder is a proxmox.Runner that records each call and the stdin it was handed.
|
||||
type stdinRecorder struct {
|
||||
name string
|
||||
args []string
|
||||
stdin string
|
||||
}
|
||||
|
||||
func (r *stdinRecorder) Run(_ context.Context, name string, args ...string) ([]byte, []byte, error) {
|
||||
r.name, r.args = name, args
|
||||
return nil, nil, nil
|
||||
}
|
||||
|
||||
func (r *stdinRecorder) RunStdin(_ context.Context, stdin io.Reader, name string, args ...string) ([]byte, []byte, error) {
|
||||
b, _ := io.ReadAll(stdin)
|
||||
r.name, r.args, r.stdin = name, args, string(b)
|
||||
return nil, nil, nil
|
||||
}
|
||||
|
||||
// R-861 (a) A1 (`09` §3 decision 165): the managed controller update writes the guest's image file through the ROOT
|
||||
// verb, never through an in-guest `tee` the agent could feed any image.
|
||||
//
|
||||
// COMPANION RED-PROOF (observed): restore the pre-A1 body (`b.runner.RunStdin(ctx, …, "pct", "exec", vmid, "--",
|
||||
// "tee", controllerImageFile)`) → this fails with "the image write ran pct …, want felhom-priv-apply". Restored.
|
||||
func TestR861_WriteControllerImageUsesTheRootVerb(t *testing.T) {
|
||||
rec := &stdinRecorder{}
|
||||
b := NewGuestBinder(rec, discardLogger())
|
||||
const img = "gitea.dooplex.hu/admin/felhom-controller:0.302.0"
|
||||
if err := b.WriteControllerImage(context.Background(), 9201, img); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if rec.name != privApplyBin {
|
||||
t.Fatalf("the image write ran %s %v, want felhom-priv-apply", rec.name, rec.args)
|
||||
}
|
||||
if len(rec.args) != 2 || rec.args[0] != "controller-image" || rec.args[1] != "9201" {
|
||||
t.Fatalf("argv = %v, want [controller-image 9201] (the sudoers line `^controller-image [0-9]+$`)", rec.args)
|
||||
}
|
||||
if rec.stdin != img+"\n" {
|
||||
t.Fatalf("stdin = %q, want the ref plus one newline", rec.stdin)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user