Three modules' tools act through `sudo -n` and nothing declared that the account may; each machine said so in a hand-set line in /etc/sudoers. The module owns the package and /etc/sudoers.d/10-mesh-operator (0440), checked by visudo in its manifest test, and serves sudo_rules, sudo_check and sudo_drop_ins from a Go bundle. lab stops declaring the sudo package, which would collide with this module on the node that runs both (hq ADR 0207, to-be 42 Phase 1).
66 lines
2.3 KiB
Go
66 lines
2.3 KiB
Go
package main
|
|
|
|
// The module's shape (novox/hq to-be 42 Phase 1, research 027): it declares the sudo package and one
|
|
// drop-in, mode 0440, granting the operator account passwordless escalation — and that drop-in is
|
|
// rendered and checked by visudo here, because a sudoers file that does not parse locks sudo for
|
|
// every account on the machine, the operator's included.
|
|
|
|
import (
|
|
"os"
|
|
"os/exec"
|
|
"path/filepath"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
func TestItDeclaresThePackageAndTheDropInSudoReads(t *testing.T) {
|
|
m := manifest(t)
|
|
if m.Module != "sudo" || m.Version != "1" {
|
|
t.Fatalf("%s %s", m.Module, m.Version)
|
|
}
|
|
if p := m.resource(t, "package"); p["type"] != "package" || p["package"] != "sudo" {
|
|
t.Fatalf("package: %v", p)
|
|
}
|
|
f := m.resource(t, "operator")
|
|
if f["path"] != MeshDropIn || f["mode"] != "0440" || f["into"] != nil || f["owner"] != nil {
|
|
t.Fatalf("the drop-in is root's, whole, 0440: %v", f)
|
|
}
|
|
if !ReadBySudo(filepath.Base(MeshDropIn)) {
|
|
t.Fatal("sudo would skip the drop-in by its name")
|
|
}
|
|
if len(m.Resources) != 2 {
|
|
t.Fatalf("the module declares the package and the drop-in, nothing else: %v", m.Resources)
|
|
}
|
|
}
|
|
|
|
func TestTheDropInGrantsExactlyTheOperatorAccountAndParses(t *testing.T) {
|
|
content := manifest(t).resource(t, "operator")["content"].(string)
|
|
var rules []string
|
|
for _, l := range strings.Split(content, "\n") {
|
|
if l = strings.TrimSpace(l); l != "" && !strings.HasPrefix(l, "#") {
|
|
rules = append(rules, l)
|
|
}
|
|
}
|
|
if len(rules) != 1 || rules[0] != "${machine:account} ALL=(ALL:ALL) NOPASSWD: ALL" {
|
|
t.Fatalf("rules: %q", rules)
|
|
}
|
|
if !strings.HasSuffix(content, "\n") {
|
|
t.Fatal("sudo requires the last line to end in a newline")
|
|
}
|
|
visudo, err := exec.LookPath("visudo")
|
|
if err != nil {
|
|
t.Skip("visudo is not installed here; the rendered drop-in is not checked")
|
|
}
|
|
for _, account := range []string{"operator", "ace", "jochen-s"} {
|
|
file := filepath.Join(t.TempDir(), "10-mesh-operator")
|
|
rendered := strings.ReplaceAll(content, "${machine:account}", account)
|
|
if err := os.WriteFile(file, []byte(rendered), 0o440); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
out, err := exec.Command(visudo, "-c", "-f", file).CombinedOutput()
|
|
if err != nil || !strings.Contains(string(out), "parsed OK") {
|
|
t.Fatalf("visudo refuses the drop-in rendered for %s: %v\n%s", account, err, out)
|
|
}
|
|
}
|
|
}
|