package profile import ( "context" "os/exec" "strings" "testing" "time" ) // Against the real machine. novox/hq ADR 0034: structure and logic are tested first, behaviour // against a real system alongside, and mocking the boundary is forbidden — a test that fakes // the system under detection asserts that the fake behaves as expected. // // These do not assert WHICH capabilities this machine has; that varies per machine and is the // point of detecting. They assert that detection tells the truth about whatever is here. func TestAgainstThisMachine_detectionAgreesWithReality(t *testing.T) { got := Detect(context.Background(), Default(nil), 10*time.Second) if got.Architecture == "" || got.Kernel == "" { t.Fatal("the machine did not report its own architecture or kernel") } if len(got.Capabilities) == 0 { t.Fatal("no capability was reported at all") } // The claim is checkable independently: a capability reported present must have a command // that is actually on this machine. The reverse is deliberately NOT asserted — a command // being present while the capability is absent is exactly the fault 04-ISSUES/007 records, // and this suite exists partly to let that state be observed rather than assumed away. commands := map[string]string{ CapContainerRuntime: "docker", CapPackageManager: "pacman", CapServiceManager: "systemctl", CapFirewall: "nft", CapOverlay: "wg", } for name, command := range commands { if !got.Has(name) { continue } if _, err := exec.LookPath(command); err != nil { t.Errorf("%s reported present, but %q is not on this machine: %v", name, command, err) } } for _, v := range got.Capabilities { t.Logf(" %-20s present=%-5v %s", v.Name, v.Present, v.Detail) } } func TestAgainstThisMachine_privilegeIsReportedHonestly(t *testing.T) { // The host changes machines, so whether it can is the capability that decides what the // rest of it may attempt. Reporting it wrongly in either direction is worse than not // reporting it: claimed-and-absent means work is accepted and fails, and absent-when-held // means a capable node refuses work. var verdict Verdict for _, v := range Detect(context.Background(), Default(nil), 5*time.Second).Capabilities { if v.Name == CapPrivileged { verdict = v } } if verdict.Name == "" { t.Fatal("privilege was not reported at all") } // Checked against the process's own view rather than against the detector's. root := isRoot() if verdict.Present != root { t.Errorf("privilege reported %v; this process is root=%v", verdict.Present, root) } if !strings.Contains(verdict.Detail, "uid") { t.Errorf("privilege detail does not say what it observed: %q", verdict.Detail) } } func TestAgainstThisMachine_detectionIsBounded(t *testing.T) { // Every probe runs a command on a real machine. If any of them can block, the host has a // startup that sometimes never finishes — the least debuggable failure there is. start := time.Now() Detect(context.Background(), Default(nil), 2*time.Second) elapsed := time.Since(start) budget := 2 * time.Second * time.Duration(len(Default(nil))) if elapsed > budget { t.Fatalf("detection took %s, past its own %s budget", elapsed, budget) } t.Logf("detected %d capabilities in %s", len(Default(nil)), elapsed) }