diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-02-17 19:00:43 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-02-17 19:00:43 +0900 |
| commit | 90cb01b2748550228d0bc179691a19ebb996fc36 (patch) | |
| tree | 06a2e17b578312c3f0734bf4c476e3c2eb5f6908 /internal/system/acl_test.go | |
| parent | b1e1d5627e6532ec719c761846d7f38fe93fcadd (diff) | |
system: move out of internal
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'internal/system/acl_test.go')
| -rw-r--r-- | internal/system/acl_test.go | 90 |
1 files changed, 0 insertions, 90 deletions
diff --git a/internal/system/acl_test.go b/internal/system/acl_test.go deleted file mode 100644 index ed154ad1..00000000 --- a/internal/system/acl_test.go +++ /dev/null @@ -1,90 +0,0 @@ -package system - -import ( - "testing" - - "git.gensokyo.uk/security/fortify/acl" -) - -func TestUpdatePerm(t *testing.T) { - testCases := []struct { - path string - perms []acl.Perm - }{ - {"/run/user/1971/fortify", []acl.Perm{acl.Execute}}, - {"/tmp/fortify.1971/tmpdir/150", []acl.Perm{acl.Read, acl.Write, acl.Execute}}, - } - - for _, tc := range testCases { - t.Run(tc.path+permSubTestSuffix(tc.perms), func(t *testing.T) { - sys := New(150) - sys.UpdatePerm(tc.path, tc.perms...) - (&tcOp{Process, tc.path}).test(t, sys.ops, []Op{&ACL{Process, tc.path, tc.perms}}, "UpdatePerm") - }) - } -} - -func TestUpdatePermType(t *testing.T) { - testCases := []struct { - perms []acl.Perm - tcOp - }{ - {[]acl.Perm{acl.Execute}, tcOp{User, "/tmp/fortify.1971/tmpdir"}}, - {[]acl.Perm{acl.Read, acl.Write, acl.Execute}, tcOp{User, "/tmp/fortify.1971/tmpdir/150"}}, - {[]acl.Perm{acl.Execute}, tcOp{Process, "/run/user/1971/fortify/fcb8a12f7c482d183ade8288c3de78b5"}}, - {[]acl.Perm{acl.Read}, tcOp{Process, "/tmp/fortify.1971/fcb8a12f7c482d183ade8288c3de78b5/passwd"}}, - {[]acl.Perm{acl.Read}, tcOp{Process, "/tmp/fortify.1971/fcb8a12f7c482d183ade8288c3de78b5/group"}}, - {[]acl.Perm{acl.Read, acl.Write, acl.Execute}, tcOp{EWayland, "/run/user/1971/wayland-0"}}, - } - - for _, tc := range testCases { - t.Run(tc.path+"_"+TypeString(tc.et)+permSubTestSuffix(tc.perms), func(t *testing.T) { - sys := New(150) - sys.UpdatePermType(tc.et, tc.path, tc.perms...) - tc.test(t, sys.ops, []Op{&ACL{tc.et, tc.path, tc.perms}}, "UpdatePermType") - }) - } -} - -func TestACL_String(t *testing.T) { - testCases := []struct { - want string - et Enablement - perms []acl.Perm - }{ - {`--- type: Process path: "/nonexistent"`, Process, []acl.Perm{}}, - {`r-- type: User path: "/nonexistent"`, User, []acl.Perm{acl.Read}}, - {`-w- type: Wayland path: "/nonexistent"`, EWayland, []acl.Perm{acl.Write}}, - {`--x type: X11 path: "/nonexistent"`, EX11, []acl.Perm{acl.Execute}}, - {`rw- type: D-Bus path: "/nonexistent"`, EDBus, []acl.Perm{acl.Read, acl.Write}}, - {`r-x type: PulseAudio path: "/nonexistent"`, EPulse, []acl.Perm{acl.Read, acl.Execute}}, - {`rwx type: User path: "/nonexistent"`, User, []acl.Perm{acl.Read, acl.Write, acl.Execute}}, - {`rwx type: Process path: "/nonexistent"`, Process, []acl.Perm{acl.Read, acl.Write, acl.Write, acl.Execute}}, - } - - for _, tc := range testCases { - t.Run(tc.want, func(t *testing.T) { - a := &ACL{et: tc.et, perms: tc.perms, path: "/nonexistent"} - if got := a.String(); got != tc.want { - t.Errorf("String() = %v, want %v", - got, tc.want) - } - }) - } -} - -func permSubTestSuffix(perms []acl.Perm) (suffix string) { - for _, perm := range perms { - switch perm { - case acl.Read: - suffix += "_read" - case acl.Write: - suffix += "_write" - case acl.Execute: - suffix += "_execute" - default: - panic("unreachable") - } - } - return -} |
