mirror of
https://github.com/Buriburizaem0n/nezha_domains.git
synced 2026-09-19 09:40:12 +00:00
test(agentcompat): probe credential execution support
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
This commit is contained in:
@@ -41,11 +41,22 @@ func TestSupervisor_RunsChildWithConfiguredCredential(t *testing.T) {
|
|||||||
requireNoError(t, err)
|
requireNoError(t, err)
|
||||||
executablePath := filepath.Join(credentialDirectory, "process-helper")
|
executablePath := filepath.Join(credentialDirectory, "process-helper")
|
||||||
requireNoError(t, os.WriteFile(executablePath, testBinary, 0o755))
|
requireNoError(t, os.WriteFile(executablePath, testBinary, 0o755))
|
||||||
|
uncredentialed := newHelperSupervisor(t.Context(), "credential", []string{helperMarkerEnv + "=" + marker})
|
||||||
|
uncredentialed.spec.Path = executablePath
|
||||||
|
requireNoError(t, uncredentialed.Start())
|
||||||
|
requireNoError(t, uncredentialed.Wait(t.Context()))
|
||||||
|
requireNoError(t, os.Remove(marker))
|
||||||
|
|
||||||
supervisor.spec.Path = executablePath
|
supervisor.spec.Path = executablePath
|
||||||
supervisor.spec.Credential = &syscall.Credential{Uid: 65534, Gid: 65534}
|
supervisor.spec.Credential = &syscall.Credential{Uid: 65534, Gid: 65534}
|
||||||
|
|
||||||
// When
|
// When
|
||||||
requireNoError(t, supervisor.Start())
|
if err := supervisor.Start(); err != nil {
|
||||||
|
if errors.Is(err, syscall.EPERM) {
|
||||||
|
t.Skipf("credentialed helper execution is not permitted: %v", err)
|
||||||
|
}
|
||||||
|
t.Fatalf("start credentialed helper: %v", err)
|
||||||
|
}
|
||||||
requireNoError(t, supervisor.Wait(t.Context()))
|
requireNoError(t, supervisor.Wait(t.Context()))
|
||||||
|
|
||||||
// Then
|
// Then
|
||||||
|
|||||||
Reference in New Issue
Block a user