From d5d2c23d5a489bba6be8a75ad4c5d1ac3cda4bb6 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Tue, 6 Oct 2026 21:54:48 +0900 Subject: test/internal/testsuite: directly set credentials There is no reason to keep using sudo here, now that processes are spawned natively. This change removes all use of sudo. Signed-off-by: Ophestra --- test/sandbox/main.go | 57 ++++++++++++++++++++++++++-------------------------- 1 file changed, 28 insertions(+), 29 deletions(-) (limited to 'test/sandbox/main.go') diff --git a/test/sandbox/main.go b/test/sandbox/main.go index 311b9f58..4961c04f 100644 --- a/test/sandbox/main.go +++ b/test/sandbox/main.go @@ -50,12 +50,12 @@ func mustScanFor(f func(ps *testsuite.StatScanner) bool) int { func mustStart( ctx context.Context, serial uint64, - username string, + cred *syscall.Credential, files ...*os.File, ) (pid int, done <-chan error) { _serial := strconv.FormatUint(serial, 10) - _, done = testsuite.MustStartAs( - ctx, username, files, + _, done = testsuite.MustStartWith( + ctx, cred, nil, files, "hakurei", "exec", "sleep", "infinity", _serial, ) @@ -108,11 +108,11 @@ func mustStart( func main() { go testsuite.ReceiveSignals() - username := testsuite.GetUser().Username // the signal handler does not wait for termination ctx := context.Background() + cred := syscall.Credential{Uid: 1000, Gid: 100} if err := os.MkdirAll("/opt/test-helper/bin", 0755); err != nil { log.Fatal(err) } @@ -136,26 +136,26 @@ func main() { var serial atomic.Uint64 newSerial := func() uint64 { serial.Add(1); return serial.Load() } - testsuite.MustRunAs( - username, "-i", + testsuite.MustRun( + &cred, nil, "hakurei", "exec", "capsh", "--print", ) wg.Go(func() { defer log.Println("validated capabilities/securebits in user namespace") - testsuite.MustRunAs( - username, "-i", + testsuite.MustRun( + &cred, nil, "hakurei", "exec", "capsh", "--has-no-new-privs", ) for _, p := range []byte{'a', 'b', 'i', 'p'} { - testsuite.MustFailAs( - username, "-i", + testsuite.MustFail( + &cred, nil, "hakurei", "exec", "capsh", "--has-"+string(p)+"=CAP_SYS_ADMIN", ) } - testsuite.MustFailAs( - username, "-i", + testsuite.MustFail( + &cred, nil, "hakurei", "exec", "umount", "-R", "/dev", ) }) @@ -166,7 +166,7 @@ func main() { c, cancel := context.WithCancel(ctx) defer cancel() - pid, done := mustStart(c, newSerial(), username) + pid, done := mustStart(c, newSerial(), &cred) testsuite.MustCheckFilter(pid, testdata.SumPD) if err := testsuite.FilterTerminated(<-done); err != nil { log.Fatal(err) @@ -179,7 +179,7 @@ func main() { c, cancel := context.WithCancel(ctx) defer cancel() - pid, done := mustStart(c, newSerial(), username, os.Stdin, os.Stdout, os.Stderr) + pid, done := mustStart(c, newSerial(), &cred, os.Stdin, os.Stdout, os.Stderr) prefix := filepath.Join(fhs.Proc, strconv.Itoa(pid), "fd") var fail bool @@ -227,10 +227,10 @@ func main() { var swg sync.WaitGroup defer swg.Wait() - dbusEnv := testsuite.MustStartSessionBus(username) - testsuite.MustStartSway(&swg, username, dbusEnv) - defer testsuite.TerminateSway(username) - testsuite.MustStartPipeWire(username, dbusEnv) + dbusEnv := testsuite.MustStartSessionBus(&cred) + testsuite.MustStartSway(&swg, &cred, dbusEnv) + defer testsuite.TerminateSway(&cred) + testsuite.MustStartPipeWire(&cred, dbusEnv) if err := <-testToolDone; err != nil { log.Fatal(err) @@ -241,16 +241,6 @@ func main() { for name, tc := range testdata.All() { wg.Go(func() { cmd := exec.Command( - "sudo", - "-u", username, - "-C", "6", - "TERM=xterm", - testsuite.XDGRuntimeEnv, - testsuite.WaylandEnv, - "DISPLAY=:0", - dbusEnv, - "--", - "script", "/dev/null", "-E", "always", "-qec", @@ -259,10 +249,19 @@ func main() { " 4 1>&3", ) cmd.SysProcAttr = &syscall.SysProcAttr{ - Pdeathsig: syscall.SIGTERM, + Pdeathsig: syscall.SIGTERM, + Credential: &cred, } var output bytes.Buffer cmd.Stdin, cmd.Stdout, cmd.Stderr = os.Stdin, &output, &output + cmd.Env = []string{ + "PATH=" + os.Getenv("PATH"), + "TERM=xterm", + testsuite.XDGRuntimeEnv, + testsuite.WaylandEnv, + "DISPLAY=:0", + dbusEnv, + } var err error var notify, _notify, _conf, conf, ident, _ident *os.File -- cgit v1.3.1