package felhomsshd import ( "strings" "testing" "gitea.dooplex.hu/admin/felhom-agent/internal/privapplytest" ) // R-861: renderConfig is byte-identical to the checker's template (only the Port varies); a changed line is refused. // RED-PROOF: change one directive in renderConfig → this fails (the two templates drifted). func TestPrivApply_AcceptsTheRenderedConfig(t *testing.T) { for _, port := range []int{2222, 8822, 60022} { conf, err := renderConfig(port) if err != nil { t.Fatal(err) } if got := privapplytest.Check(t, "sshd-config", "", conf); got != "OK" { t.Errorf("port %d: %s", port, got) } } conf, _ := renderConfig(8822) if got := privapplytest.Check(t, "sshd-config", "", conf+"StrictModes no\n"); !strings.HasPrefix(got, "REFUSED") { t.Fatalf("control: an extra directive was not refused: %s", got) } }