aboutsummaryrefslogtreecommitdiffhomepage
path: root/system/acl_test.go
blob: 2202d95756272cf414d48d321cc7de99cf5b1a86 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
package system

import (
	"os"
	"syscall"
	"testing"

	"hakurei.app/container/stub"
	"hakurei.app/hst"
	"hakurei.app/system/acl"
)

func TestACLUpdateOp(t *testing.T) {
	t.Parallel()

	checkOpBehaviour(t, []opBehaviourTestCase{
		{"apply aclUpdate", 0xbeef, 0xff,
			&aclUpdateOp{Process, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}, []stub.Call{
				call("verbose", stub.ExpectArgs{[]any{"applying ACL", &aclUpdateOp{Process, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}}}, nil, nil),
				call("aclUpdate", stub.ExpectArgs{"/proc/nonexistent", 0xbeef, []acl.Perm{acl.Read, acl.Write, acl.Execute}}, nil, stub.UniqueError(1)),
			}, &OpError{Op: "acl", Err: stub.UniqueError(1)}, nil, nil},

		{"revert aclUpdate", 0xbeef, 0xff,
			&aclUpdateOp{Process, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}, []stub.Call{
				call("verbose", stub.ExpectArgs{[]any{"applying ACL", &aclUpdateOp{Process, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}}}, nil, nil),
				call("aclUpdate", stub.ExpectArgs{"/proc/nonexistent", 0xbeef, []acl.Perm{acl.Read, acl.Write, acl.Execute}}, nil, nil),
			}, nil, []stub.Call{
				call("verbose", stub.ExpectArgs{[]any{"stripping ACL", &aclUpdateOp{Process, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}}}, nil, nil),
				call("aclUpdate", stub.ExpectArgs{"/proc/nonexistent", 0xbeef, ([]acl.Perm)(nil)}, nil, stub.UniqueError(0)),
			}, &OpError{Op: "acl", Err: stub.UniqueError(0), Revert: true}},

		{"success revert skip", 0xbeef, Process,
			&aclUpdateOp{User, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}, []stub.Call{
				call("verbose", stub.ExpectArgs{[]any{"applying ACL", &aclUpdateOp{User, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}}}, nil, nil),
				call("aclUpdate", stub.ExpectArgs{"/proc/nonexistent", 0xbeef, []acl.Perm{acl.Read, acl.Write, acl.Execute}}, nil, nil),
			}, nil, []stub.Call{
				call("verbose", stub.ExpectArgs{[]any{"skipping ACL", &aclUpdateOp{User, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}}}, nil, nil),
			}, nil},

		{"success revert aclUpdate ENOENT", 0xbeef, 0xff,
			&aclUpdateOp{Process, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}, []stub.Call{
				call("verbose", stub.ExpectArgs{[]any{"applying ACL", &aclUpdateOp{Process, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}}}, nil, nil),
				call("aclUpdate", stub.ExpectArgs{"/proc/nonexistent", 0xbeef, []acl.Perm{acl.Read, acl.Write, acl.Execute}}, nil, nil),
			}, nil, []stub.Call{
				call("verbose", stub.ExpectArgs{[]any{"stripping ACL", &aclUpdateOp{Process, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}}}, nil, nil),
				call("aclUpdate", stub.ExpectArgs{"/proc/nonexistent", 0xbeef, ([]acl.Perm)(nil)}, nil, &os.PathError{Op: "acl_get_file", Path: "/proc/nonexistent", Err: syscall.ENOENT}),
				call("verbosef", stub.ExpectArgs{"target of ACL %s no longer exists", []any{&aclUpdateOp{Process, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}}}, nil, nil),
			}, nil},

		{"success", 0xbeef, 0xff,
			&aclUpdateOp{Process, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}, []stub.Call{
				call("verbose", stub.ExpectArgs{[]any{"applying ACL", &aclUpdateOp{Process, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}}}, nil, nil),
				call("aclUpdate", stub.ExpectArgs{"/proc/nonexistent", 0xbeef, []acl.Perm{acl.Read, acl.Write, acl.Execute}}, nil, nil),
			}, nil, []stub.Call{
				call("verbose", stub.ExpectArgs{[]any{"stripping ACL", &aclUpdateOp{Process, "/proc/nonexistent", []acl.Perm{acl.Read, acl.Write, acl.Execute}}}}, nil, nil),
				call("aclUpdate", stub.ExpectArgs{"/proc/nonexistent", 0xbeef, ([]acl.Perm)(nil)}, nil, nil),
			}, nil},
	})

	checkOpsBuilder(t, "UpdatePermType", []opsBuilderTestCase{
		{"simple",
			0xbeef,
			func(_ *testing.T, sys *I) {
				sys.
					UpdatePerm(m("/run/user/1971/hakurei"), acl.Execute).
					UpdatePerm(m("/tmp/hakurei.0/tmpdir/150"), acl.Read, acl.Write, acl.Execute)
			}, []Op{
				&aclUpdateOp{Process, "/run/user/1971/hakurei", []acl.Perm{acl.Execute}},
				&aclUpdateOp{Process, "/tmp/hakurei.0/tmpdir/150", []acl.Perm{acl.Read, acl.Write, acl.Execute}},
			}, stub.Expect{}},

		{"tmpdirp", 0xbeef, func(_ *testing.T, sys *I) {
			sys.UpdatePermType(User, m("/tmp/hakurei.0/tmpdir"), acl.Execute)
		}, []Op{
			&aclUpdateOp{User, "/tmp/hakurei.0/tmpdir", []acl.Perm{acl.Execute}},
		}, stub.Expect{}},

		{"tmpdir", 0xbeef, func(_ *testing.T, sys *I) {
			sys.UpdatePermType(User, m("/tmp/hakurei.0/tmpdir/150"), acl.Read, acl.Write, acl.Execute)
		}, []Op{
			&aclUpdateOp{User, "/tmp/hakurei.0/tmpdir/150", []acl.Perm{acl.Read, acl.Write, acl.Execute}},
		}, stub.Expect{}},

		{"share", 0xbeef, func(_ *testing.T, sys *I) {
			sys.UpdatePermType(Process, m("/run/user/1971/hakurei/fcb8a12f7c482d183ade8288c3de78b5"), acl.Execute)
		}, []Op{
			&aclUpdateOp{Process, "/run/user/1971/hakurei/fcb8a12f7c482d183ade8288c3de78b5", []acl.Perm{acl.Execute}},
		}, stub.Expect{}},

		{"passwd", 0xbeef, func(_ *testing.T, sys *I) {
			sys.
				UpdatePermType(Process, m("/tmp/hakurei.0/fcb8a12f7c482d183ade8288c3de78b5/passwd"), acl.Read).
				UpdatePermType(Process, m("/tmp/hakurei.0/fcb8a12f7c482d183ade8288c3de78b5/group"), acl.Read)
		}, []Op{
			&aclUpdateOp{Process, "/tmp/hakurei.0/fcb8a12f7c482d183ade8288c3de78b5/passwd", []acl.Perm{acl.Read}},
			&aclUpdateOp{Process, "/tmp/hakurei.0/fcb8a12f7c482d183ade8288c3de78b5/group", []acl.Perm{acl.Read}},
		}, stub.Expect{}},

		{"wayland", 0xbeef, func(_ *testing.T, sys *I) {
			sys.UpdatePermType(hst.EWayland, m("/run/user/1971/wayland-0"), acl.Read, acl.Write, acl.Execute)
		}, []Op{
			&aclUpdateOp{hst.EWayland, "/run/user/1971/wayland-0", []acl.Perm{acl.Read, acl.Write, acl.Execute}},
		}, stub.Expect{}},
	})

	checkOpIs(t, []opIsTestCase{
		{"nil", (*aclUpdateOp)(nil), (*aclUpdateOp)(nil), false},
		{"zero", new(aclUpdateOp), new(aclUpdateOp), true},

		{"et differs",
			&aclUpdateOp{
				hst.EWayland, "/run/user/1971/wayland-0",
				[]acl.Perm{acl.Read, acl.Write, acl.Execute},
			}, &aclUpdateOp{
				hst.EX11, "/run/user/1971/wayland-0",
				[]acl.Perm{acl.Read, acl.Write, acl.Execute},
			}, false},

		{"path differs", &aclUpdateOp{
			hst.EWayland, "/run/user/1971/wayland-0",
			[]acl.Perm{acl.Read, acl.Write, acl.Execute},
		}, &aclUpdateOp{
			hst.EWayland, "/run/user/1971/wayland-1",
			[]acl.Perm{acl.Read, acl.Write, acl.Execute},
		}, false},

		{"perms differs", &aclUpdateOp{
			hst.EWayland, "/run/user/1971/wayland-0",
			[]acl.Perm{acl.Read, acl.Write, acl.Execute},
		}, &aclUpdateOp{
			hst.EWayland, "/run/user/1971/wayland-0",
			[]acl.Perm{acl.Read, acl.Write},
		}, false},

		{"equals", &aclUpdateOp{
			hst.EWayland, "/run/user/1971/wayland-0",
			[]acl.Perm{acl.Read, acl.Write, acl.Execute},
		}, &aclUpdateOp{
			hst.EWayland, "/run/user/1971/wayland-0",
			[]acl.Perm{acl.Read, acl.Write, acl.Execute},
		}, true},
	})

	checkOpMeta(t, []opMetaTestCase{
		{"clear",
			&aclUpdateOp{Process, "/proc/nonexistent", []acl.Perm{}},
			Process, "/proc/nonexistent",
			`--- type: process path: "/proc/nonexistent"`},

		{"read",
			&aclUpdateOp{User, "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/0", []acl.Perm{acl.Read}},
			User, "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/0",
			`r-- type: user path: "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/0"`},

		{"write",
			&aclUpdateOp{User, "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/1", []acl.Perm{acl.Write}},
			User, "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/1",
			`-w- type: user path: "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/1"`},

		{"execute",
			&aclUpdateOp{User, "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/2", []acl.Perm{acl.Execute}},
			User, "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/2",
			`--x type: user path: "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/2"`},

		{"wayland",
			&aclUpdateOp{hst.EWayland, "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/wayland", []acl.Perm{acl.Read, acl.Write}},
			hst.EWayland, "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/wayland",
			`rw- type: wayland path: "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/wayland"`},

		{"x11",
			&aclUpdateOp{hst.EX11, "/tmp/.X11-unix/X0", []acl.Perm{acl.Read, acl.Execute}},
			hst.EX11, "/tmp/.X11-unix/X0",
			`r-x type: x11 path: "/tmp/.X11-unix/X0"`},

		{"dbus",
			&aclUpdateOp{hst.EDBus, "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/bus", []acl.Perm{acl.Write, acl.Execute}},
			hst.EDBus, "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/bus",
			`-wx type: dbus path: "/tmp/hakurei.0/27d81d567f8fae7f33278eec45da9446/bus"`},

		{"pulseaudio",
			&aclUpdateOp{hst.EPulse, "/run/user/1971/hakurei/27d81d567f8fae7f33278eec45da9446/pulse", []acl.Perm{acl.Read, acl.Write, acl.Execute}},
			hst.EPulse, "/run/user/1971/hakurei/27d81d567f8fae7f33278eec45da9446/pulse",
			`rwx type: pulseaudio path: "/run/user/1971/hakurei/27d81d567f8fae7f33278eec45da9446/pulse"`},
	})
}