diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-04-12 10:54:24 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-04-12 10:54:24 +0900 |
| commit | 0d7c1a9a4356614f035225aeb24e66421879a99b (patch) | |
| tree | c490cfd0f75fbf0218045e277812fb5b6173d4e3 /internal/app/setuid/app_test.go | |
| parent | ae6f5ede1928c9d0a2d480b6a924914e8599529f (diff) | |
app: rename app implementation package
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'internal/app/setuid/app_test.go')
| -rw-r--r-- | internal/app/setuid/app_test.go | 148 |
1 files changed, 148 insertions, 0 deletions
diff --git a/internal/app/setuid/app_test.go b/internal/app/setuid/app_test.go new file mode 100644 index 00000000..4454e6ff --- /dev/null +++ b/internal/app/setuid/app_test.go @@ -0,0 +1,148 @@ +package setuid_test + +import ( + "encoding/json" + "io/fs" + "reflect" + "testing" + "time" + + "git.gensokyo.uk/security/fortify/fst" + "git.gensokyo.uk/security/fortify/internal/app/setuid" + "git.gensokyo.uk/security/fortify/internal/sys" + "git.gensokyo.uk/security/fortify/sandbox" + "git.gensokyo.uk/security/fortify/system" +) + +type sealTestCase struct { + name string + os sys.State + config *fst.Config + id fst.ID + wantSys *system.I + wantContainer *sandbox.Params +} + +func TestApp(t *testing.T) { + testCases := append(testCasesPd, testCasesNixos...) + + for _, tc := range testCases { + t.Run(tc.name, func(t *testing.T) { + a := setuid.NewWithID(tc.id, tc.os) + var ( + gotSys *system.I + gotContainer *sandbox.Params + ) + if !t.Run("seal", func(t *testing.T) { + if sa, err := a.Seal(tc.config); err != nil { + t.Errorf("Seal: error = %v", err) + return + } else { + gotSys, gotContainer = setuid.AppIParams(a, sa) + } + }) { + return + } + + t.Run("compare sys", func(t *testing.T) { + if !gotSys.Equal(tc.wantSys) { + t.Errorf("Seal: sys = %#v, want %#v", + gotSys, tc.wantSys) + } + }) + + t.Run("compare params", func(t *testing.T) { + if !reflect.DeepEqual(gotContainer, tc.wantContainer) { + t.Errorf("seal: params =\n%s\n, want\n%s", + mustMarshal(gotContainer), mustMarshal(tc.wantContainer)) + } + }) + }) + } +} + +func mustMarshal(v any) string { + if b, err := json.Marshal(v); err != nil { + panic(err.Error()) + } else { + return string(b) + } +} + +func stubDirEntries(names ...string) (e []fs.DirEntry, err error) { + e = make([]fs.DirEntry, len(names)) + for i, name := range names { + e[i] = stubDirEntryPath(name) + } + return +} + +type stubDirEntryPath string + +func (p stubDirEntryPath) Name() string { + return string(p) +} + +func (p stubDirEntryPath) IsDir() bool { + panic("attempted to call IsDir") +} + +func (p stubDirEntryPath) Type() fs.FileMode { + panic("attempted to call Type") +} + +func (p stubDirEntryPath) Info() (fs.FileInfo, error) { + panic("attempted to call Info") +} + +type stubFileInfoMode fs.FileMode + +func (s stubFileInfoMode) Name() string { + panic("attempted to call Name") +} + +func (s stubFileInfoMode) Size() int64 { + panic("attempted to call Size") +} + +func (s stubFileInfoMode) Mode() fs.FileMode { + return fs.FileMode(s) +} + +func (s stubFileInfoMode) ModTime() time.Time { + panic("attempted to call ModTime") +} + +func (s stubFileInfoMode) IsDir() bool { + panic("attempted to call IsDir") +} + +func (s stubFileInfoMode) Sys() any { + panic("attempted to call Sys") +} + +type stubFileInfoIsDir bool + +func (s stubFileInfoIsDir) Name() string { + panic("attempted to call Name") +} + +func (s stubFileInfoIsDir) Size() int64 { + panic("attempted to call Size") +} + +func (s stubFileInfoIsDir) Mode() fs.FileMode { + panic("attempted to call Mode") +} + +func (s stubFileInfoIsDir) ModTime() time.Time { + panic("attempted to call ModTime") +} + +func (s stubFileInfoIsDir) IsDir() bool { + return bool(s) +} + +func (s stubFileInfoIsDir) Sys() any { + panic("attempted to call Sys") +} |
