Count only a record of making something at a path as the mesh's, not an access record (hq ADR 0103)
This commit is contained in:
@@ -1020,3 +1020,24 @@ func TestAHoldLetGoAndFoundAgainKeepsBothOriginals(t *testing.T) {
|
||||
t.Errorf("the file found again was not held: %+v", o)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAPathTheMeshOnlySetAccessOnIsStillFound(t *testing.T) {
|
||||
// An access record says the mesh set permissions on a path it does not own — which is what it
|
||||
// does to somebody else's directory. It is not a record of making it (novox/hq ADR 0103).
|
||||
dir := t.TempDir()
|
||||
data := filepath.Join(dir, "data")
|
||||
if err := os.Mkdir(data, 0o700); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
known := store.State{Resources: []store.Applied{
|
||||
{ID: "hello-web.readable", Type: "access", Target: data, Origin: store.OriginDeclared}}}
|
||||
m := &machine{containers: map[string]*fakeContainer{}}
|
||||
report, _ := applyAdopted(t, adopted(t, untaken("hello-web.data"),
|
||||
`{"id":"hello-web.data","type":"directory","path":"`+data+`","mode":"0755"}`), known, m, dir)
|
||||
if o := outcomeOf(report, "hello-web.data"); o.Action != "held" {
|
||||
t.Errorf("a directory the mesh only has access for was not held: %+v", o)
|
||||
}
|
||||
if info, _ := os.Stat(data); info.Mode().Perm() != 0o700 {
|
||||
t.Errorf("it was re-moded to %o", info.Mode().Perm())
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user