package localapi import ( "context" "io" "testing" ) // stdinRecorder is a proxmox.Runner that records each call and the stdin it was handed. type stdinRecorder struct { name string args []string stdin string } func (r *stdinRecorder) Run(_ context.Context, name string, args ...string) ([]byte, []byte, error) { r.name, r.args = name, args return nil, nil, nil } func (r *stdinRecorder) RunStdin(_ context.Context, stdin io.Reader, name string, args ...string) ([]byte, []byte, error) { b, _ := io.ReadAll(stdin) r.name, r.args, r.stdin = name, args, string(b) return nil, nil, nil } // R-861 (a) A1 (`09` §3 decision 165): the managed controller update writes the guest's image file through the ROOT // verb, never through an in-guest `tee` the agent could feed any image. // // COMPANION RED-PROOF (observed): restore the pre-A1 body (`b.runner.RunStdin(ctx, …, "pct", "exec", vmid, "--", // "tee", controllerImageFile)`) → this fails with "the image write ran pct …, want felhom-priv-apply". Restored. func TestR861_WriteControllerImageUsesTheRootVerb(t *testing.T) { rec := &stdinRecorder{} b := NewGuestBinder(rec, discardLogger()) const img = "gitea.dooplex.hu/admin/felhom-controller:0.302.0" if err := b.WriteControllerImage(context.Background(), 9201, img); err != nil { t.Fatal(err) } if rec.name != privApplyBin { t.Fatalf("the image write ran %s %v, want felhom-priv-apply", rec.name, rec.args) } if len(rec.args) != 2 || rec.args[0] != "controller-image" || rec.args[1] != "9201" { t.Fatalf("argv = %v, want [controller-image 9201] (the sudoers line `^controller-image [0-9]+$`)", rec.args) } if rec.stdin != img+"\n" { t.Fatalf("stdin = %q, want the ref plus one newline", rec.stdin) } }