PAM lines written into login and passwd as blocks, so login unlocks the keyring on both workstations; no daemon of its own; gcr's ssh agent named for the session until the environment can say a runtime-directory path. Go tools unlocked, lock, collections and ssh-keys, never reading a secret.
65 lines
2.3 KiB
Go
65 lines
2.3 KiB
Go
package main
|
|
|
|
import (
|
|
"reflect"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// gnome-keyring's shape (novox/hq ADR 0208, ADR 0102): it claims node-secret-service, writes its PAM
|
|
// lines into the login and passwd stacks as marked blocks (never over the files), and starts no daemon
|
|
// of its own: PAM and D-Bus do.
|
|
|
|
func TestItClaimsTheSecretServiceSeat(t *testing.T) {
|
|
m := readManifest(t)
|
|
if m.Module != "gnome-keyring" || m.Seats != nil || m.Requires != nil {
|
|
t.Fatalf("module %q, seats %v, requires %v", m.Module, m.Seats, m.Requires)
|
|
}
|
|
if !reflect.DeepEqual(m.Claims, []claim{{Name: "node-secret-service", Scope: "node"}}) {
|
|
t.Fatalf("claims: %+v", m.Claims)
|
|
}
|
|
if present, absent := m.packages(); !reflect.DeepEqual(present, []string{"gnome-keyring", "libsecret", "seahorse"}) || absent != nil {
|
|
t.Fatalf("packages: %v, absent %v", present, absent)
|
|
}
|
|
}
|
|
|
|
func TestThePAMLinesAreBlocksWrittenIntoTheStacks(t *testing.T) {
|
|
m := readManifest(t)
|
|
for id, want := range map[string]struct{ path, source string }{
|
|
"pam-login": {"/etc/pam.d/login", "files/pam/login"},
|
|
"pam-passwd": {"/etc/pam.d/passwd", "files/pam/passwd"},
|
|
} {
|
|
m.sameAsSource(t, id, want.source)
|
|
r := m.resource(t, id)
|
|
if r["path"] != want.path || r["into"] != "block" || r["at"] != "end" || r["owner"] != nil {
|
|
t.Errorf("%s: %v", id, r)
|
|
}
|
|
}
|
|
login := m.resource(t, "pam-login")["content"].(string)
|
|
if !strings.Contains(login, "\nauth optional pam_gnome_keyring.so\n") ||
|
|
!strings.Contains(login, "\nsession optional pam_gnome_keyring.so auto_start\n") {
|
|
t.Fatalf("%s", login)
|
|
}
|
|
}
|
|
|
|
func TestItStartsNoDaemonAndOnlyNamesTheAgentsSocket(t *testing.T) {
|
|
m := readManifest(t)
|
|
if len(m.Shell) != 1 || m.Shell[0].For != "xinitrc" || m.Shell[0].Slot != "first" {
|
|
t.Fatalf("%+v", m.Shell)
|
|
}
|
|
code := m.Shell[0].Code
|
|
if strings.Contains(code, "gnome-keyring-daemon") || strings.Contains(code, "--unlock") ||
|
|
!strings.Contains(code, `SSH_AUTH_SOCK="${XDG_RUNTIME_DIR:-/run/user/$(id -u)}/gcr/ssh"`) {
|
|
t.Fatalf("%q", code)
|
|
}
|
|
if m.Environment != nil {
|
|
t.Fatal("SSH_AUTH_SOCK needs the runtime directory, which ADR 0203 forbids in a value; it is not an environment contribution yet")
|
|
}
|
|
}
|
|
|
|
func TestTheToolsAgreeWithTheManifest(t *testing.T) {
|
|
m := readManifest(t)
|
|
checkTheToolsAgree(t, m)
|
|
checkNoSecretsOrInstallationNames(t)
|
|
}
|