package lanresolver import ( "strings" "testing" "gitea.dooplex.hu/admin/felhom-agent/internal/privapplytest" ) // R-861: both drop-ins the resolver renders are accepted by the root checker; a dhcp-script line is not. func TestPrivApply_AcceptsTheRenderedDropins(t *testing.T) { if got := privapplytest.Check(t, "dnsmasq", BaseDropin, RenderBase("192.168.0.104", []string{"1.1.1.1", "8.8.8.8"})); got != "OK" { t.Errorf("base drop-in: %s", got) } if got := privapplytest.Check(t, "dnsmasq", DropinName("demo-hp"), RenderGuestDropin("demo-hp", "enkisfelhom.hu", "192.168.0.138")); got != "OK" { t.Errorf("guest drop-in: %s", got) } evil := RenderGuestDropin("demo-hp", "enkisfelhom.hu", "192.168.0.138") + "dhcp-script=/var/lib/felhom-agent/x\n" if got := privapplytest.Check(t, "dnsmasq", "felhom-x.conf", evil); !strings.HasPrefix(got, "REFUSED") { t.Fatalf("control: dhcp-script was not refused: %s", got) } }