// Package privapplytest runs configs/felhom-priv-apply in CHECK-ONLY mode from Go tests (R-861): each renderer's // real output must be accepted by the root checker, so the two can never drift apart unnoticed. Test-only helper. package privapplytest import ( "os" "os/exec" "path/filepath" "runtime" "strings" "testing" ) // Check writes content to a temp file and runs `felhom-priv-apply --check [name] `. It returns the // checker's verdict line ("OK" or "REFUSED [rule] …"). Skips when python3 is absent. func Check(t *testing.T, verb, name, content string) string { t.Helper() py, err := exec.LookPath("python3") if err != nil { t.Skip("python3 not available") } _, here, _, _ := runtime.Caller(0) wrapper := filepath.Join(filepath.Dir(here), "..", "..", "configs", "felhom-priv-apply") f := filepath.Join(t.TempDir(), "staged") if err := os.WriteFile(f, []byte(content), 0o600); err != nil { t.Fatal(err) } args := []string{"-B", wrapper, "--check", verb} if name != "" { args = append(args, name) } out, _ := exec.Command(py, append(args, f)...).CombinedOutput() return strings.TrimSpace(string(out)) }