package storage import ( "strings" "testing" "gitea.dooplex.hu/admin/felhom-agent/internal/privapplytest" ) // R-861: every unit the agent renders is one the root checker installs — the name it computes, the Where, the // options. RED-PROOF: drop "nosuid","nodev" from mountOptions → the network cases are REFUSED [U5]. func TestPrivApply_AcceptsTheRenderedUnits(t *testing.T) { local := MountSpec{Name: "x", UUID: "91d2dc2d-2d28-4929-9bdd-3e11fa2f41ae", Where: "/mnt/hdd_1", FSType: "ext4"} name, _ := UnitNameForMount(local.Where) if got := privapplytest.Check(t, "unit", name, renderMountUnit(local)); got != "OK" { t.Errorf("local unit %s: %s", name, got) } local.FSType = "" if got := privapplytest.Check(t, "unit", name, renderMountUnit(local)); got != "OK" { t.Errorf("local unit without Type: %s", got) } for _, spec := range []NetworkMountSpec{ {Name: "media", Protocol: ProtocolNFS, Server: "10.0.0.5", Export: "/srv/media", MappedUID: 1000, MappedGID: 1000}, {Name: "photos", Protocol: ProtocolSMB, Server: "nas.lan", Export: "photos", CredsRef: "/etc/felhom/netmount/photos.cred", MappedUID: 1000, MappedGID: 1000}, } { mu, err := UnitNameForMount(spec.Where()) if err != nil { t.Fatal(err) } if got := privapplytest.Check(t, "unit", mu, renderNetworkMountUnit(spec)); got != "OK" { t.Errorf("%s .mount: %s", spec.Name, got) } au := strings.TrimSuffix(mu, ".mount") + ".automount" if got := privapplytest.Check(t, "unit", au, renderNetworkAutomountUnit(spec)); got != "OK" { t.Errorf("%s .automount: %s", spec.Name, got) } } // control: the checker is really looking — a unit over /etc is refused evil := strings.Replace(renderMountUnit(MountSpec{UUID: local.UUID, Where: "/mnt/hdd_1"}), "Where=/mnt/hdd_1", "Where=/etc/sudoers.d", 1) if got := privapplytest.Check(t, "unit", name, evil); !strings.HasPrefix(got, "REFUSED") { t.Fatalf("control: a unit over /etc/sudoers.d was not refused: %s", got) } }