sudo: declare the operator account's passwordless escalation as a module
Three modules' tools act through `sudo -n` and nothing declared that the account may; each machine said so in a hand-set line in /etc/sudoers. The module owns the package and /etc/sudoers.d/10-mesh-operator (0440), checked by visudo in its manifest test, and serves sudo_rules, sudo_check and sudo_drop_ins from a Go bundle. lab stops declaring the sudo package, which would collide with this module on the node that runs both (hq ADR 0207, to-be 42 Phase 1).
This commit is contained in:
@@ -0,0 +1,65 @@
|
||||
package main
|
||||
|
||||
// The module's shape (novox/hq to-be 42 Phase 1, research 027): it declares the sudo package and one
|
||||
// drop-in, mode 0440, granting the operator account passwordless escalation — and that drop-in is
|
||||
// rendered and checked by visudo here, because a sudoers file that does not parse locks sudo for
|
||||
// every account on the machine, the operator's included.
|
||||
|
||||
import (
|
||||
"os"
|
||||
"os/exec"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestItDeclaresThePackageAndTheDropInSudoReads(t *testing.T) {
|
||||
m := manifest(t)
|
||||
if m.Module != "sudo" || m.Version != "1" {
|
||||
t.Fatalf("%s %s", m.Module, m.Version)
|
||||
}
|
||||
if p := m.resource(t, "package"); p["type"] != "package" || p["package"] != "sudo" {
|
||||
t.Fatalf("package: %v", p)
|
||||
}
|
||||
f := m.resource(t, "operator")
|
||||
if f["path"] != MeshDropIn || f["mode"] != "0440" || f["into"] != nil || f["owner"] != nil {
|
||||
t.Fatalf("the drop-in is root's, whole, 0440: %v", f)
|
||||
}
|
||||
if !ReadBySudo(filepath.Base(MeshDropIn)) {
|
||||
t.Fatal("sudo would skip the drop-in by its name")
|
||||
}
|
||||
if len(m.Resources) != 2 {
|
||||
t.Fatalf("the module declares the package and the drop-in, nothing else: %v", m.Resources)
|
||||
}
|
||||
}
|
||||
|
||||
func TestTheDropInGrantsExactlyTheOperatorAccountAndParses(t *testing.T) {
|
||||
content := manifest(t).resource(t, "operator")["content"].(string)
|
||||
var rules []string
|
||||
for _, l := range strings.Split(content, "\n") {
|
||||
if l = strings.TrimSpace(l); l != "" && !strings.HasPrefix(l, "#") {
|
||||
rules = append(rules, l)
|
||||
}
|
||||
}
|
||||
if len(rules) != 1 || rules[0] != "${machine:account} ALL=(ALL:ALL) NOPASSWD: ALL" {
|
||||
t.Fatalf("rules: %q", rules)
|
||||
}
|
||||
if !strings.HasSuffix(content, "\n") {
|
||||
t.Fatal("sudo requires the last line to end in a newline")
|
||||
}
|
||||
visudo, err := exec.LookPath("visudo")
|
||||
if err != nil {
|
||||
t.Skip("visudo is not installed here; the rendered drop-in is not checked")
|
||||
}
|
||||
for _, account := range []string{"operator", "ace", "jochen-s"} {
|
||||
file := filepath.Join(t.TempDir(), "10-mesh-operator")
|
||||
rendered := strings.ReplaceAll(content, "${machine:account}", account)
|
||||
if err := os.WriteFile(file, []byte(rendered), 0o440); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
out, err := exec.Command(visudo, "-c", "-f", file).CombinedOutput()
|
||||
if err != nil || !strings.Contains(string(out), "parsed OK") {
|
||||
t.Fatalf("visudo refuses the drop-in rendered for %s: %v\n%s", account, err, out)
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user