Refuse a file that asks for a setting without saying whether it is trusted from 2026-10-10
The operator's date (hq issue 339). A test holds the warning before it and the refusal from it.
This commit is contained in:
@@ -45,3 +45,31 @@ func TestModuleCheckCountsTheUndeclaredAndRefusesThemFromTheDate(t *testing.T) {
|
||||
t.Errorf("the refusal does not name the resource:\n%s", out.String())
|
||||
}
|
||||
}
|
||||
|
||||
// A file that asks for a setting says whether it is trusted (novox/hq issue 339): `module check` warns and counts
|
||||
// it before the date, and refuses it from the date; a file that says so passes either way.
|
||||
func TestModuleCheckCountsUnsaidTrustAndRefusesItFromTheDate(t *testing.T) {
|
||||
dir := t.TempDir()
|
||||
path := filepath.Join(dir, "module.json")
|
||||
os.WriteFile(path, []byte(`{"module":"power","resources":[
|
||||
{"id":"logind","type":"file","path":"/etc/systemd/logind.conf.d/power.conf","mode":"0644","trusted":true,
|
||||
"content":"HandleLidSwitch=${setting:lid}\n"},
|
||||
{"id":"note","type":"file","path":"/var/lib/power/note","mode":"0644","content":"${setting:greeting}\n"}]}`), 0o600)
|
||||
defer func() { checkNow = time.Now }()
|
||||
|
||||
checkNow = func() time.Time { return catalogue.TrustRequiredFrom.Add(-time.Hour) }
|
||||
var out bytes.Buffer
|
||||
if err := moduleCheck([]string{path}, &out); err != nil {
|
||||
t.Fatalf("refused before the date: %v\n%s", err, out.String())
|
||||
}
|
||||
for _, want := range []string{"WARNING: note ask(s) for a setting", UnsaidTrustLine + " 1"} {
|
||||
if !strings.Contains(out.String(), want) {
|
||||
t.Errorf("the check does not say %q:\n%s", want, out.String())
|
||||
}
|
||||
}
|
||||
checkNow = func() time.Time { return catalogue.TrustRequiredFrom }
|
||||
out.Reset()
|
||||
if err := moduleCheck([]string{path}, &out); err == nil || !strings.Contains(out.String(), "power: the file note asks for a setting") {
|
||||
t.Fatalf("an unsaid file passed after the date: %v\n%s", err, out.String())
|
||||
}
|
||||
}
|
||||
|
||||
@@ -33,7 +33,7 @@ const TrustedField = "trusted"
|
||||
// TrustRequiredFrom is when `module check` refuses a file that asks for a setting and does not say whether it is
|
||||
// trusted. Until then it is warned and counted: the catalogue's files get the field in their own change, which
|
||||
// can only land once a controller that takes the field out of the declaration runs.
|
||||
var TrustRequiredFrom = time.Date(2026, 10, 30, 0, 0, 0, 0, time.UTC)
|
||||
var TrustRequiredFrom = time.Date(2026, 10, 10, 0, 0, 0, 0, time.UTC)
|
||||
|
||||
// TerminalKeys are the settings keys of a module that are set at the controller's terminal alone: places and
|
||||
// accesses, every key its provisions serve and every setting a served value asks for, and every setting a file
|
||||
|
||||
Reference in New Issue
Block a user