Files
mesh-catalog/modules/sudo/cmd/sudo-tools/manifest_test.go
T
jochen f015aba34a sudo: declare the operator account's passwordless escalation as a module
Three modules' tools act through `sudo -n` and nothing declared that the
account may; each machine said so in a hand-set line in /etc/sudoers. The
module owns the package and /etc/sudoers.d/10-mesh-operator (0440), checked
by visudo in its manifest test, and serves sudo_rules, sudo_check and
sudo_drop_ins from a Go bundle. lab stops declaring the sudo package, which
would collide with this module on the node that runs both (hq ADR 0207,
to-be 42 Phase 1).
2026-10-04 12:50:20 +02:00

66 lines
2.3 KiB
Go

package main
// The module's shape (novox/hq to-be 42 Phase 1, research 027): it declares the sudo package and one
// drop-in, mode 0440, granting the operator account passwordless escalation — and that drop-in is
// rendered and checked by visudo here, because a sudoers file that does not parse locks sudo for
// every account on the machine, the operator's included.
import (
"os"
"os/exec"
"path/filepath"
"strings"
"testing"
)
func TestItDeclaresThePackageAndTheDropInSudoReads(t *testing.T) {
m := manifest(t)
if m.Module != "sudo" || m.Version != "1" {
t.Fatalf("%s %s", m.Module, m.Version)
}
if p := m.resource(t, "package"); p["type"] != "package" || p["package"] != "sudo" {
t.Fatalf("package: %v", p)
}
f := m.resource(t, "operator")
if f["path"] != MeshDropIn || f["mode"] != "0440" || f["into"] != nil || f["owner"] != nil {
t.Fatalf("the drop-in is root's, whole, 0440: %v", f)
}
if !ReadBySudo(filepath.Base(MeshDropIn)) {
t.Fatal("sudo would skip the drop-in by its name")
}
if len(m.Resources) != 2 {
t.Fatalf("the module declares the package and the drop-in, nothing else: %v", m.Resources)
}
}
func TestTheDropInGrantsExactlyTheOperatorAccountAndParses(t *testing.T) {
content := manifest(t).resource(t, "operator")["content"].(string)
var rules []string
for _, l := range strings.Split(content, "\n") {
if l = strings.TrimSpace(l); l != "" && !strings.HasPrefix(l, "#") {
rules = append(rules, l)
}
}
if len(rules) != 1 || rules[0] != "${machine:account} ALL=(ALL:ALL) NOPASSWD: ALL" {
t.Fatalf("rules: %q", rules)
}
if !strings.HasSuffix(content, "\n") {
t.Fatal("sudo requires the last line to end in a newline")
}
visudo, err := exec.LookPath("visudo")
if err != nil {
t.Skip("visudo is not installed here; the rendered drop-in is not checked")
}
for _, account := range []string{"operator", "ace", "jochen-s"} {
file := filepath.Join(t.TempDir(), "10-mesh-operator")
rendered := strings.ReplaceAll(content, "${machine:account}", account)
if err := os.WriteFile(file, []byte(rendered), 0o440); err != nil {
t.Fatal(err)
}
out, err := exec.Command(visudo, "-c", "-f", file).CombinedOutput()
if err != nil || !strings.Contains(string(out), "parsed OK") {
t.Fatalf("visudo refuses the drop-in rendered for %s: %v\n%s", account, err, out)
}
}
}